Flatpak Secures 508,000 Euros to Build Stronger Sandboxing
Flatpak has secured 508,000 euros in funding to strengthen its sandboxing. For a project that most of the Linux desktop now depends on for application distribution, and that has spent the year fielding sandbox escape reports, this is well-targeted money.
Why the sandbox needs the work
Flatpak’s security model rests on the idea that an application runs with only the permissions it declares. The gap between that promise and the reality has been the project’s persistent weak point.
The recurring problems are structural rather than a series of unrelated bugs:
Portals are the boundary, and boundaries leak. Anything an application needs from outside the sandbox goes through a portal: file chooser, screenshots, device access, notifications. Each portal is a place where sandbox confinement has to be enforced correctly, and each one is attack surface.
Broad permissions are common. A large number of published Flatpaks request filesystem access wide enough that the sandbox is decorative. --filesystem=home is not confinement in any meaningful sense, and users approving it have no easy way to tell what a reasonable request would have looked like.
The X11 problem. Under X11, any application with display access can read every other window’s input. No sandbox can fix that, which is one of the practical arguments for the Wayland transition that GNOME completed for its default session this year.
We covered the 1.18.1 sandbox escape fixes last month, and 1.18.2 followed as a bug-fix release. The pattern is a project actively hardening something that was designed with a weaker threat model than it now has to withstand.
What funding changes
Flatpak has largely been volunteer-maintained, with contributions from people employed elsewhere to work on adjacent things. That works for feature development and poorly for security engineering, which needs sustained, unglamorous, adversarial attention from someone whose job it is.
Half a million euros buys real developer time against a specific problem. Whether it produces a materially tighter sandbox depends on whether the work goes into the hard structural issues, permission granularity and portal hardening, rather than into fixing the next round of individual escapes.
The wider point
This lands in the same week as a rather pointed demonstration of how open source funding actually works. Flathub, Flatpak’s distribution side, was among the projects whose DigitalOcean sponsorship was cancelled last month, a sponsorship worth about 50 dollars a month.
Infrastructure that a large share of the desktop depends on tends to be funded either by grants like this one or by nothing. Both facts can be true at once: this is good news for Flatpak, and it is a reminder of how thin the margin usually is.