Skip to content

Flatpak sandbox - #976

Open
Loup-Garou911XD wants to merge 15 commits into
efroemling:mainfrom
Loup-Garou911XD:flatpak-sandbox
Open

Loup-Garou911XD wants to merge 15 commits into
efroemling:mainfrom
Loup-Garou911XD:flatpak-sandbox

Conversation

@Loup-Garou911XD

@Loup-Garou911XD Loup-Garou911XD commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

This PR has alot of work on flatpak and being mergable on flathub

  • Full sandbox build
  • Removed the hacky venv workaround for fixing python path
  • The python packages are now build from wheels instead of being repurposed from host's venv
  • Update
    • runtime to org.freedesktop.Platform//26.08
    • sdk to org.freedesktop.Sdk//26.08
    • llvm to org.freedesktop.Sdk.Extension.llvm22

and also fixed the docker builds failing because of missing libzstd-dev package

updated flatpak sdk version to 26.08 and removed python module because 26.08 comes with python3.14 by default
make flatpak-linux ran `make env` on the host and then handed the whole
tree, .venv included, to the flatpak build. A venv is bound to the
absolute path of the interpreter that created it (its bin/pythonX.Y
symlink, its pyvenv.cfg 'home' key, every script shebang), so it is
always broken inside the sandbox; the manifest patched that up with an
ln -s plus `venv --upgrade`, which stopped working once the bundled
Python module was commented out and /app/bin/python3.14 went away.

Keep .venv out of the payload instead and build it in the sandbox:

- pconfig/requirements_build.txt names the roots of the subset the
  build itself reaches. `make flatpak-build-env` expands that through
  the main lockfile's '# via' annotations into
  requirements_build_lock.txt (16 packages of 82, versions and hashes
  copied verbatim so the main lockfile stays the only place anything is
  pinned) and into pconfig/flatpak/python-build-env.yml, a module
  supplying uv plus one cp314 manylinux wheel per arch, 8.4MB.
- A VENV_LOCK knob lets the manifests install from that reduced
  lockfile, and UV_OFFLINE/UV_FIND_LINKS point uv at the staged wheels,
  so the venv is created with no network access at all.
- uv now comes from a pinned, hash-verified release archive rather than
  curl-piping astral.sh, which no flathub build could do.
- The release tarball no longer carries .venv, and the flathub template
  picks up the same changes (plus the pconfig/ rename its install lines
  had missed).
Takes origin's flatpak work wherever both sides changed the same thing
(offline build with flatpak-prefetch, flatpak_add_release, BA_DATA_DIR
launcher, the flatpakbuildenv cleanups) and origin's devcontainer. On
top of that, keeps the local-only improvements:

- Generate the Flathub manifest from net.froemling.bombsquad.yml by
  swapping its dir source for the release tarball, and drop the
  hand-synced .yml.template (its commented-out Python module had
  already drifted to 3.13.3).
- flatpak-linux installs the SDK, runtime and extensions per-user with
  --install-deps-from=flathub, so the workflows no longer hard-code
  their versions and the cached ~/.local/share/flatpak actually holds
  them.
- Fix the flatpak cache key (wrong-case manifest name, so it never
  changed), key it on python-build-env.yml too, and stop caching
  directories that --force-clean / --keep-build-dirs make useless.
- Leave .git and .idea out of the dir source and the release tarball.
- Add pconfig/flatpak/README.md describing the build and Flathub flow.
- compile requirements_build_lock.txt with uv pip compile constrained
  by requirements_lock.txt instead of a hand-written resolver
- generate_flathub_manifest owns the whole flathub tree (drops stale
  files) and uses the release of the triggering tag
- drop unused sdist fallback, date arg and helper indirection
- prebuilt inputs job no longer sets up the cmake toolchain
@Loup-Garou911XD
Loup-Garou911XD marked this pull request as ready for review October 8, 2026 05:39
@Loup-Garou911XD

Loup-Garou911XD commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator Author

@efroemling Please review this, hopefully should be mergeable in flathub now

@Loup-Garou911XD
Loup-Garou911XD force-pushed the flatpak-sandbox branch 2 times, most recently from 7237787 to ece83de Compare October 8, 2026 06:00
- contact url must be a web url, use the feedback page as the contact url
- gamepad was declared in both supports and recommends
- split the description into real paragraphs
@Loup-Garou911XD

Copy link
Copy Markdown
Collaborator Author

@efroemling review and merge this please 🙏🏻

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant