Repository navigation
fix: Register with AT-SPI inside a Flatpak sandbox on Unix - #817
chris-addison wants to merge 1 commit into
Conversation
Flatpak hides org.a11y.Bus from the sandbox and hands the app its own proxy of the accessibility bus in AT_SPI_BUS_ADDRESS instead. The adapter waited for org.a11y.Status.IsEnabled on the session bus before connecting, so inside a sandbox it never activated and screen readers never saw the app. When AT_SPI_BUS_ADDRESS is set and IsEnabled can't be read, connect to that bus at once and treat accessibility as enabled, as GTK and Qt do. Bus::new already prefers that address. Where the toggle can be read, it stays in charge.
|
Hello @chris-addison, You say:
Yet as you also point out:
So you agree that the value returned by Have you actually tried granting permission for The changes you propose would force applications to expose an accessibility tree whether it is consumed by an assistive technology or not. AT-SPI adds a significant performance overhead so I really would not want all users to pay the price. |
I ran a test and yes, you're right here! Thanks for the great pointer here 🙇🏻 |
Inside a Flatpak sandbox, the Unix adapter never activates, so screen readers can't see the app.
The adapter waits for
org.a11y.Status.IsEnabledfromorg.a11y.Buson the session bus before connecting. Flatpak hidesorg.a11y.Busfrom the sandbox:GetAll,GetandGetAddressall fail withorg.freedesktop.DBus.Error.ServiceUnknown, and zbus logs "Property change streams will not produce values". Flatpak instead gives the app its own proxy of the accessibility bus inAT_SPI_BUS_ADDRESS(unix:path=/run/flatpak/at-spi-bus).Bus::newalready prefers that address, but the adapter never gets far enough to call it.This change connects to the provided bus at once, and treats accessibility as enabled, when
AT_SPI_BUS_ADDRESSis set andIsEnabledcan't be read. GTK and Qt behave the same way inside Flatpak. WhereIsEnabledcan be read, nothing changes. Granting the app--talk-name=org.a11y.Busis not a workaround:GetAddressthen names the host's socket, which the sandbox can't reach.Tested on Flatpak 1.16.6 with runtime
org.freedesktop.Platform26.08, using a gpui app built against this patch and run inside its installed sandbox. Before, the app was missing fromAtspi.get_desktop(0), even withIsEnabledon. After, it lists its frame and controls. Outside the sandbox, the app still activates only onceIsEnabledturns on. Clippy is clean with the default features and withtokio.