Announcing Sovereign Tech Agency Investment in Flatpak

Announcing Sovereign Tech Agency Investment in Flatpak

宣布德国主权技术基金(Sovereign Tech Agency)对 Flatpak 的投资

By Sebastian, Kateryna, and Cade August 27, 2026 作者:Sebastian, Kateryna, 和 Cade,2026年8月27日

We are excited to announce a significant investment of €508,640 by the German Sovereign Tech Agency, through its Sovereign Tech Fund (STF) initiative, into the development and stewardship of Flatpak. This two-year initiative, co-organized by Modal and with Para-Real Ltd. as supporting organization, will accelerate the evolution of Flatpak as a secure, sandboxed platform for packaging and distributing Linux desktop software. 我们很高兴地宣布,德国主权技术基金(Sovereign Tech Agency)通过其主权技术基金(STF)项目,向 Flatpak 的开发与管理投入了 508,640 欧元的重大资金。这项为期两年的计划由 Modal 共同组织,并由 Para-Real Ltd. 作为支持机构,旨在加速 Flatpak 的演进,使其成为一个用于打包和分发 Linux 桌面软件的安全沙盒平台。

Flatpak serves as the primary application distribution method for image-based operating systems including Fedora Silverblue, openSUSE Aeon, SteamOS, and GNOME OS. It is the preferred format for major ecosystems such as GNOME, KDE, and elementary. By expanding Flatpak’s capabilities, this investment will directly improve the security, robustness, and overall user and developer experience of the Free Software desktop ecosystem. Flatpak 是 Fedora Silverblue、openSUSE Aeon、SteamOS 和 GNOME OS 等基于镜像的操作系统主要的应用分发方式。它也是 GNOME、KDE 和 elementary 等主流生态系统首选的格式。通过扩展 Flatpak 的功能,此次投资将直接提升自由软件桌面生态系统的安全性、稳健性以及整体的用户和开发者体验。

Are We Sandboxed Yet?

我们实现沙盒化了吗?

Flatpak is a mature project and the best option that exists on GNU/Linux today, but its security and sandboxing features still trail behind those of well-funded proprietary platforms such as Android and iOS. Certain technical limitations persist, such as the inability to separate audio output from microphone access—and several critical areas, including networking and VPNs, still lack dedicated Portals. Following significant progress made during the 2023/2024 GNOME STF project, development has slowed in recent years, due to the specialized expertise required for this kind of platform-level work and the limited capacity of the overstretched Flatpak maintainers. This hinders the adoption of secure, image-based operating systems that rely exclusively on Flatpak apps. Flatpak 是一个成熟的项目,也是目前 GNU/Linux 上最好的选择,但其安全和沙盒功能仍落后于 Android 和 iOS 等资金雄厚的专有平台。目前仍存在一些技术限制,例如无法将音频输出与麦克风访问权限分开,且在网络和 VPN 等几个关键领域仍缺乏专门的 Portal(门户接口)。继 2023/2024 年 GNOME STF 项目取得重大进展后,由于此类平台级工作需要专业知识,且 Flatpak 维护者人手不足,近年来开发进度有所放缓。这阻碍了那些完全依赖 Flatpak 应用的、基于镜像的安全操作系统的普及。

A Collaborative Effort

协作努力

For Modal, a robust app sandboxing story is essential to creating a Free Software OS that is competitive with modern mobile platforms. Leveraging our experience co-organizing STF projects for GNOME and systemd, we have partnered with other community members to put together this new initiative to push the ecosystem forward. The project is led on the technical side by Sebastian and Adrian, with organizational support from Kateryna and Cade. While Para-Real Ltd. serves as the supporting organization, we hope to use this investment to build long-term community capacity by growing the pool of people who know this part of the stack, and putting in place more formal structures for the Flatpak project. 对于 Modal 而言,强大的应用沙盒机制对于创建能够与现代移动平台竞争的自由软件操作系统至关重要。利用我们共同组织 GNOME 和 systemd STF 项目的经验,我们与其他社区成员合作发起了这项新计划,以推动生态系统向前发展。该项目在技术层面由 Sebastian 和 Adrian 领导,Kateryna 和 Cade 提供组织支持。虽然 Para-Real Ltd. 作为支持机构,但我们希望利用这笔投资,通过扩大熟悉该技术栈的人才储备,并为 Flatpak 项目建立更正式的结构,来构建长期的社区能力。

We are proud to bring on board a team of experienced contractors for the technical execution: Philip Withnall, Julian Sparber, and Dhanuka Warusadura from the 2023/2024 GNOME STF project, alongside Zelda Ahmed, Ignacy Kuchciński, Hari Rana, Eva (of Bazaar), and veteran GNOME designer Sam Hewitt. The project will ramp up over the coming months and is expected to run through the end of 2027. 我们很自豪能邀请到一支经验丰富的承包商团队来负责技术执行:包括来自 2023/2024 GNOME STF 项目的 Philip Withnall、Julian Sparber 和 Dhanuka Warusadura,以及 Zelda Ahmed、Ignacy Kuchciński、Hari Rana、Eva(来自 Bazaar)和资深 GNOME 设计师 Sam Hewitt。该项目将在未来几个月内全面展开,预计持续到 2027 年底。

Technical Roadmap

技术路线图

The Sovereign Tech Agency has commissioned work towards closing critical gaps in the sandboxing story, introducing long-requested infrastructure, and ensuring general maintenance. We’ll focus on the following areas: 主权技术基金已委托我们开展工作,旨在填补沙盒机制中的关键空白,引入长期以来备受期待的基础设施,并确保日常维护。我们将重点关注以下领域:

New Portals 新门户接口 (Portals)

  • Audio: Implementation of a new static socket permission for PipeWire, a WirePlumber policy to manage device access, and a portal for setting audio permissions (e.g. allowing speaker access without granting microphone access).
    • 音频: 为 PipeWire 实现新的静态套接字权限,制定用于管理设备访问的 WirePlumber 策略,以及一个用于设置音频权限的门户(例如:允许访问扬声器而不授予麦克风访问权限)。
  • Network: Isolation of networking from the host with new static permissions for specific scopes (host, local network, internet) and ports, preventing unnecessary exposure of local devices.
    • 网络: 通过针对特定范围(主机、本地网络、互联网)和端口的新静态权限,实现网络与主机的隔离,防止本地设备不必要的暴露。
  • VPN: A new portal modeled after Android and iOS APIs, enabling third-party VPN apps to manage system-level connections.
    • VPN: 参考 Android 和 iOS API 设计的新门户,使第三方 VPN 应用能够管理系统级连接。
  • Writing Assistance: A new portal for spell checking, allowing for all apps on the system to share a dictionary, even when sandboxed. Additionally, this could allow apps like Eloquent to hook into the portal and provide richer editing suggestions, such as grammar corrections.
    • 写作辅助: 一个用于拼写检查的新门户,允许系统上的所有应用共享词典,即使在沙盒中也是如此。此外,这还可以让像 Eloquent 这样的应用接入该门户,并提供更丰富的编辑建议,例如语法纠正。
  • Password Auto-Fill: Research and architectural design for a secure password auto-fill portal to replace current insecure NativeMessaging approaches.
    • 密码自动填充: 对安全的密码自动填充门户进行研究和架构设计,以取代当前不安全的 NativeMessaging 方法。

Infrastructure and Maintenance 基础设施与维护

  • Entitlements: A new system for declaring static permissions for specific portals, allowing app store reviewers to verify capabilities and enabling the introduction of more advanced features like third-party accessibility tools.
    • 授权(Entitlements): 一种用于声明特定门户静态权限的新系统,允许应用商店审核员验证功能,并支持引入第三方辅助功能工具等更高级的功能。
  • Intents: An abstract system for apps to declare offered services, facilitating deep-linking to sub-pages or handling specific web URLs natively.
    • 意图(Intents): 一种供应用声明所提供服务的抽象系统,有助于实现子页面的深度链接或原生处理特定的网页 URL。
  • Portals Maintenance: Porting to libdex, adding integration tests, and improving system permission dialogs.
    • 门户维护: 移植到 libdex,增加集成测试,并改进系统权限对话框。

Watch This Space

敬请关注

As design and implementation begin, these plans may evolve. We invite the community to follow our progress and engage with us on Matrix in #flatpak:matrix.org and #xdg-desktop-portals:matrix.org. Stay tuned for more! 随着设计和实施工作的开始,这些计划可能会有所调整。我们诚邀社区关注我们的进展,并通过 Matrix 频道 #flatpak:matrix.org 和 #xdg-desktop-portals:matrix.org 与我们交流。敬请期待更多更新!