F42 Change Proposal: Unprivileged management of system Flatpaks (system-wide)

As this is a SystemWideChange, this is too late for F41: Fedora Linux 41 Schedule: Key

All unprivileged users can already install their own “user” Flatpaks without privileges right now.

There is currently almost no difference for a Flatpak if it’s installed system wide or user wide.

Christian Hergert’s work will make system installed Flatpak different but then we can not grant full control to unprivileged users as that would be equivalent to root access.

So what would be the benefit of this change?

As I wrote in F42 Change Proposal: Unprivileged Disk Management (system-wide) - #7 by siosm, I don’t think adding more groups brings us any closer to the Confined Users goal. Instead, this will create a new “privileged” status for some users which are part of all those groups.

In F41 Change Proposal: Unprivileged updates for Fedora Atomic Desktops (Self-Contained) - #17 by siosm & Allow Flatpak metadata-refresh without password for non-admins?, we were looking at enabling metadata refresh & updates operations only, not full management.

2 Likes