Applications
The image is the system’s; people do not install into it. Graphical applications come from Flatpak, and command-line and development tools are meant to live in containers. See ARCHITECTURE.md, “Applications and development”.
Everything on this page is in hideOS Workstation only. The recipes are in recipes/system/apps; ROADMAP H5 tracks what is done.
Flatpak
flatpak.toml, Flatpak 1.18.
- One system-wide installation, in
/var/lib/flatpakon@var, which members ofwheelmay change without a password (Flatpak’s own polkit rules), throughflatpak-system-helperon the system bus. - Flathub is preconfigured with nothing in
/etc. The recipe installsflathub.flatpakrepointo/usr/share/flatpak/remotes.d, and Flatpak applies every file there, with its GPG key, to the system installation the first time it opens it. - Sandboxes are the system’s bubblewrap and xdg-dbus-proxy, with
Wayland’s security-context protocol, which COSMIC supports. bubblewrap is
not setuid: it uses unprivileged user namespaces, so the kernel has
CONFIG_USER_NS. - Applications are kept in libostree’s content-addressed store; ostree is built only for that, with nothing for booting an ostree system.
- What a system without systemd does not use — Flatpak’s systemd units, its
environment generators, the
profile.dscript — is left out; the COSMIC session puts the exported applications inXDG_DATA_DIRSitself.
cargo xtask desktop-test checks that Flathub is configured, that its
signed summary downloads and verifies, and that bubblewrap makes a sandbox
for an unprivileged user. It does not install an application. See
Testing.
The launch helper
flatpak-system-helper is started on demand by dbus-daemon’s setuid launch
helper, which hideOS installs 4755 rather than upstream’s 4750 root:messagebus. Why is in Development notes.
The portals
How a sandboxed application opens a file, takes a screenshot, shares the screen or sends a notification: by asking the desktop, over D-Bus, instead of reaching around its sandbox.
- xdg-desktop-portal 1.22: the desktop-neutral half and the document portal, D-Bus activated on the session bus. Icons and sounds that applications hand it are checked in bubblewrap before they are shown or played. Built without geoclue and gudev, so there is no location or USB portal.
- xdg-desktop-portal-cosmic
(COSMIC epoch 1.9): COSMIC’s dialogs — the file chooser, screenshots,
screen casting through PipeWire, and the settings applications read their
theme from. xdg-desktop-portal picks it from
cosmic-portals.confwhenXDG_CURRENT_DESKTOPisCOSMIC. Built without its systemd feature, whose only use is logging to journald; it logs to stderr.
hide shell (planned)
Not written. The plan is a toolbox-style Podman container sharing the user’s home and display, with any distribution inside it, for compilers, language toolchains and package managers. Podman is not packaged yet. Until then, the hideOS image has no compiler, by design: images ship without one.