Sovereign Tech Agency 向 Flatpak 投资 50 万欧元
Sovereign Tech Agency invests €500k in Flatpak

原始链接: https://modal.cx/blog/announcing-flatpak-sta/

德国主权技术基金(STF)宣布投资 508,640 欧元,用于在未来两年内推进 Flatpak 的开发与管理。该计划由 Modal 联合组织,并得到 Para-Real Ltd. 的支持,旨在对 Flatpak 的安全性和沙盒功能进行现代化升级,使其能够媲美 iOS 和 Android 等专有平台。 尽管 Flatpak 已趋于成熟,但在精细化音频权限、网络连接及 VPN 集成等方面仍存在技术差距。本项目旨在通过为音频、网络、VPN、拼写检查和安全密码自动填充实现新的门户(portals)来弥补这些不足。此外,团队还将引入“意图”(intents)系统和增强权限管理等基础设施改进。 通过扩大项目能力并使其结构正规化,该计划旨在支持 Fedora Silverblue 和 SteamOS 等日益依赖 Flatpak 的基于镜像的 Linux 发行版。一支由经验丰富的开发人员和设计师组成的团队将主导此项工作至 2027 年,重点关注项目的长期可持续性并加强整个 Linux 桌面生态系统。社区成员可通过 #flatpak 和 #xdg-desktop-portals Matrix 频道关注进展并参与贡献。

最近的一场 Hacker News 讨论凸显了人们对主权技术基金会(Sovereign Tech Agency)向 Flatpak 投资 50 万欧元这一举措的褒贬不一。 尽管 Flatpak 简化了应用程序的分发,但许多用户对其沙盒实现方式表示不满。批评者认为,当前的系统缺乏透明度,经常导致文件访问、硬件集成(如游戏控制器)和系统互操作性等功能失效。那些渴望更“容器化”方案的用户,更倾向于采用类似移动操作系统模式的沙盒,即作为隔离目录并提供明确的、由用户管理的权限提示,而非 Flatpak 目前的配置方式。 一些贡献者提出了 Podman、Docker 或 Nix 等替代方案,但也指出这些方案存在各自的技术门槛。部分评论者还质疑了该投资的战略价值,认为这些资金本可以更好地分配到科技生态系统的其他领域。总而言之,虽然 Flatpak 的实用性得到了认可,但舆论普遍希望其能提供更精细的权限控制,并为桌面用户提供更友好的集成体验。
相关文章

原文

We are excited to announce a significant investment of €508,640 by the German Sovereign Tech Agency, through its Sovereign Tech Fund (STF) initiative, into the development and stewardship of Flatpak. This two-year initiative, co-organized by Modal and with Para-Real Ltd. as supporting organization, will accelerate the evolution of Flatpak as a secure, sandboxed platform for packaging and distributing Linux desktop software.

Flatpak serves as the primary application distribution method for image-based operating systems including Fedora Silverblue, openSUSE Aeon, SteamOS, and GNOME OS. It is the preferred format for major ecosystems such as GNOME, KDE, and elementary. By expanding Flatpak’s capabilities, this investment will directly improve the security, robustness, and overall user and developer experience of the Free Software desktop ecosystem.

Are We Sandboxed Yet?

Flatpak is a mature project and the best option that exists on GNU/Linux today, but its security and sandboxing features still trail behind those of well-funded proprietary platforms such as Android and iOS. Certain technical limitations persist, such as the inability to separate audio output from microphone access—and several critical areas, including networking and VPNs, still lack dedicated Portals.

Following significant progress made during the 2023/2024 GNOME STF project, development has slowed in recent years, due to the specialized expertise required for this kind of platform-level work and the limited capacity of the overstretched Flatpak maintainers. This hinders the adoption of secure, image-based operating systems that rely exclusively on Flatpak apps.

A Collaborative Effort

For Modal, a robust app sandboxing story is essential to creating a Free Software OS that is competitive with modern mobile platforms. Leveraging our experience co-organizing STF projects for GNOME and systemd, we have partnered with other community members to put together this new initiative to push the ecosystem forward.

The project is led on the technical side by Sebastian and Adrian, with organizational support from Kateryna and Cade. While Para-Real Ltd. serves as the supporting organization, we hope to use this investment to build long-term community capacity by growing the pool of people who know this part of the stack, and putting in place more formal structures for the Flatpak project.

We are proud to bring on board a team of experienced contractors for the technical execution: Philip Withnall, Julian Sparber, and Dhanuka Warusadura from the 2023/2024 GNOME STF project, alongside Zelda Ahmed, Ignacy Kuchciński, Hari Rana, Eva (of Bazaar), and veteran GNOME designer Sam Hewitt. The project will ramp up over the coming months and is expected to run through the end of 2027.

Technical Roadmap

The Sovereign Tech Agency has commissioned work towards closing critical gaps in the sandboxing story, introducing long-requested infrastructure, and ensuring general maintenance.

We’ll focus on the following areas:

New Portals

  • Audio: Implementation of a new static socket permission for PipeWire, a WirePlumber policy to manage device access, and a portal for setting audio permissions (e.g. allowing speaker access without granting microphone access).
  • Network: Isolation of networking from the host with new static permissions for specific scopes (host, local network, internet) and ports, preventing unnecessary exposure of local devices.
  • VPN: A new portal modeled after Android and iOS APIs, enabling third-party VPN apps to manage system-level connections.
  • Writing Assistance: A new portal for spell checking, allowing for all apps on the system to share a dictionary, even when sandboxed. Additionally, this could allow apps like Eloquent to hook into the portal and provide richer editing suggestions, such as grammar corrections.
  • Password Auto-Fill: Research and architectural design for a secure password auto-fill portal to replace current insecure NativeMessaging approaches.

Infrastructure and Maintenance

  • Entitlements: A new system for declaring static permissions for specific portals, allowing app store reviewers to verify capabilities and enabling the introduction of more advanced features like third-party accessibility tools.
  • Intents: An abstract system for apps to declare offered services, facilitating deep-linking to sub-pages or handling specific web URLs natively.
  • Portals Maintenance: Porting to libdex, adding integration tests, and improving system permission dialogs.

Watch This Space

As design and implementation begin, these plans may evolve. We invite the community to follow our progress and engage with us on Matrix in #flatpak:matrix.org and #xdg-desktop-portals:matrix.org.

Stay tuned for more!

联系我们 contact @ memedata.com