build: export the app icon via --disable-sandbox instead of dropping it
Build and Publish O3DE Flatpak / build (push) Successful in 13m9s

flatpak build-export validates exported icons in a bwrap sandbox that
fails in an unprivileged CI container. The previous workaround stripped
build-dir/export/share/icons entirely, but flatpak exports the host icon
from that tree at install time, so the host menu and the window/alt-tab
icon were left generic on every machine - even ones where validation
would have passed.

Use 'flatpak build-export --disable-sandbox', which runs the same icon
validation in-process (no bwrap/userns) and keeps the icon in the export,
so it reaches the host.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-16 05:32:29 +02:00
parent 70d370e8e2
commit c1393383ba
2 changed files with 13 additions and 11 deletions
+7 -5
View File
@@ -180,11 +180,13 @@ These were confirmed by inspecting and running the v26.05 package (`opt/O3DE/26.
`--regset`. Real project data (projects you create, their caches) lives under `--regset`. Real project data (projects you create, their caches) lives under
your home directory and is fully writable, so actual work is unaffected. your home directory and is fully writable, so actual work is unaffected.
- **Launcher icon.** Shipped as `org.o3de.O3DE.png` (the `.deb` itself has only - **Launcher icon.** Shipped as `org.o3de.O3DE.png` (the `.deb` itself has only
in-editor asset icons). It's kept *inside* the app so the running window/taskbar in-editor asset icons). `flatpak build-export` validates exported icons in a
shows it, but removed from the *exported* set because `flatpak build-export` bwrap sandbox that fails in an unprivileged container ("is not a valid icon:
validates exported icons in a bwrap sandbox that fails in an unprivileged bwrap …"), so the build exports with `--disable-sandbox`: the icon is still
container. Consequence: the host menu launcher icon is generic. A privileged validated, but in-process rather than via bwrap/userns. The icon is now
runner would let us export it properly. exported to the host, so the menu launcher shows it; the window/alt-tab icon
also picks it up as long as the compositor matches the window to the desktop
entry (`StartupWMClass=O3DE` must equal the window's `WM_CLASS`).
- **GPU / drivers:** the renderer needs working GPU access. The manifest grants - **GPU / drivers:** the renderer needs working GPU access. The manifest grants
`--device=dri`/`--device=all`; on some setups you may also want the matching `--device=dri`/`--device=all`; on some setups you may also want the matching
GPU driver extension from Flathub. GPU driver extension from Flathub.
+6 -6
View File
@@ -84,12 +84,12 @@ flatpak build-finish build-dir \
echo ">> export to OSTree repo" echo ">> export to OSTree repo"
# flatpak build-export validates exported app icons in a bwrap sandbox, which # flatpak build-export validates exported app icons in a bwrap sandbox, which
# fails in an unprivileged container ("is not a valid icon: bwrap ..."). The # fails in an unprivileged container ("is not a valid icon: bwrap ..."). Rather
# icon stays inside the app (so the running window/taskbar shows it); we just # than drop the icon from the export (which left the host menu and the window /
# drop it from the *exported* set so export skips validation. Trade-off: the # alt-tab icon generic, because flatpak exports the host icon from this tree at
# host menu launcher icon is generic. (A privileged runner would avoid this.) # install time), --disable-sandbox runs the same icon validation in-process,
rm -rf build-dir/export/share/icons # without bwrap. The icon is still validated; it just no longer needs userns.
flatpak build-export repo build-dir "$BRANCH" flatpak build-export --disable-sandbox repo build-dir "$BRANCH"
flatpak build-update-repo repo --title="O3DE (unofficial Flatpak)" --prune --prune-depth=1 flatpak build-update-repo repo --title="O3DE (unofficial Flatpak)" --prune --prune-depth=1
echo ">> done: ./repo" echo ">> done: ./repo"