Skip to content

Fix portal flatpak-spawn environment handling regression - #6721

Merged
swick merged 5 commits into
flatpak:mainfrom
swick:wip/fix-portal-env
Jul 27, 2026
Merged

swick merged 5 commits into
flatpak:mainfrom
swick:wip/fix-portal-env

Conversation

@swick

@swick swick commented Jun 29, 2026

Copy link
Copy Markdown
Collaborator

See #6717

@tnias

tnias commented Jun 29, 2026

Copy link
Copy Markdown

This change fixes the issue for me.

I applied the patches to my system and now everything works as expected. :)

Comment thread portal/flatpak-portal.c Outdated
Comment thread portal/flatpak-portal.c Outdated

@bbhtt bbhtt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me. The test seems to time out for me locally for some reason but clearly works in CI.

@swick
swick force-pushed the wip/fix-portal-env branch from 713b6a6 to 98389ea Compare June 30, 2026 13:35
@swick

swick commented Jun 30, 2026

Copy link
Copy Markdown
Collaborator Author

/cc @smcv could you also please take a quick look?

Comment thread tests/mock-flatpak.c Outdated
Comment thread portal/flatpak-portal.c Outdated
swick added 2 commits July 6, 2026 17:53
This reverts commit a57f6bc.

The run-environ from the calling instance is a host-like environment
(e.g. on NixOS it contains /nix/store paths). Passing it via --env
injects it into the sandbox payload environment where those paths don't
exist.

Revert the commit, so we pass run-environ as the envp for spawning
flatpak run again to let it make host-level decisions (DISPLAY,
FLATPAK_GL_DRIVERS, XDG_RUNTIME_DIR, etc.) without leaking into the
sandbox.

It also passes --clear-env unconditionally, because we'd build up the
environment, but the wrong one. We will implement --clear-env properly
again in the next few commits.

Closes: flatpak#6717
Fixes: a57f6bc ("portal: Clear the environment via flatpak arguments")
@swick
swick force-pushed the wip/fix-portal-env branch from 98389ea to 6d27ccb Compare July 6, 2026 16:01
swick added 3 commits July 6, 2026 18:02
Instead of modifying the host-like run environment to clear the sandbox
environment, we'll use the new --clear-env flag which does the correct
thing.

Assisted-by: Claude:opus-4.6
Closes: flatpak#5271
@swick

swick commented Jul 8, 2026

Copy link
Copy Markdown
Collaborator Author

@smcv up for another round or shall I merge?

algitbot pushed a commit to alpinelinux/aports that referenced this pull request Jul 10, 2026
emma-the-rock pushed a commit to emma-the-rock/nix-dotfiles that referenced this pull request Jul 13, 2026
Flatpak >=1.18.0 leaks the NixOS host environment into the sandbox,
breaking glycin-svg icon loading (e.g. OpenDeck). Pin services.flatpak.package
to a nixpkgs-flatpak input locked to a revision with Flatpak 1.16.6, scoped
to the Flatpak service only, until flatpak/flatpak#6721 lands in nixpkgs.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
@cab404

cab404 commented Jul 19, 2026

Copy link
Copy Markdown

@swick @smcv sorry for pinging, but can you merge it? it's a bit sad to sit without working flatpak in upstream nixpkgs...

@swick
swick added this pull request to the merge queue Jul 27, 2026
Merged via the queue into flatpak:main with commit d82c247 Jul 27, 2026
11 checks passed
@swick
swick deleted the wip/fix-portal-env branch July 27, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants