Skip to content

fix: Register with AT-SPI inside a Flatpak sandbox on Unix - #817

Closed
chris-addison wants to merge 1 commit into
AccessKit:mainfrom
Unity-Technologies:fix-flatpak-atspi-bus
Closed

chris-addison wants to merge 1 commit into
AccessKit:mainfrom
Unity-Technologies:fix-flatpak-atspi-bus

Conversation

@chris-addison

@chris-addison chris-addison commented Oct 8, 2026 •

Copy link
Copy Markdown

Inside a Flatpak sandbox, the Unix adapter never activates, so screen readers can't see the app.

The adapter waits for org.a11y.Status.IsEnabled from org.a11y.Bus on the session bus before connecting. Flatpak hides org.a11y.Bus from the sandbox: GetAll, Get and GetAddress all fail with org.freedesktop.DBus.Error.ServiceUnknown, and zbus logs "Property change streams will not produce values". Flatpak instead gives the app its own proxy of the accessibility bus in AT_SPI_BUS_ADDRESS (unix:path=/run/flatpak/at-spi-bus). Bus::new already prefers that address, but the adapter never gets far enough to call it.

This change connects to the provided bus at once, and treats accessibility as enabled, when AT_SPI_BUS_ADDRESS is set and IsEnabled can't be read. GTK and Qt behave the same way inside Flatpak. Where IsEnabled can be read, nothing changes. Granting the app --talk-name=org.a11y.Bus is not a workaround: GetAddress then names the host's socket, which the sandbox can't reach.

Tested on Flatpak 1.16.6 with runtime org.freedesktop.Platform 26.08, using a gpui app built against this patch and run inside its installed sandbox. Before, the app was missing from Atspi.get_desktop(0), even with IsEnabled on. After, it lists its frame and controls. Outside the sandbox, the app still activates only once IsEnabled turns on. Clippy is clean with the default features and with tokio.

Flatpak hides org.a11y.Bus from the sandbox and hands the app its own
proxy of the accessibility bus in AT_SPI_BUS_ADDRESS instead. The
adapter waited for org.a11y.Status.IsEnabled on the session bus before
connecting, so inside a sandbox it never activated and screen readers
never saw the app.

When AT_SPI_BUS_ADDRESS is set and IsEnabled can't be read, connect to
that bus at once and treat accessibility as enabled, as GTK and Qt do.
Bus::new already prefers that address. Where the toggle can be read, it
stays in charge.
@DataTriny

Copy link
Copy Markdown
Member

Hello @chris-addison,

You say:

Granting the app --talk-name=org.a11y.Bus is not a workaround: GetAddress then names the host's socket, which the sandbox can't reach.

Yet as you also point out:

Flatpak instead gives the app its own proxy of the accessibility bus in AT_SPI_BUS_ADDRESS. Bus::new already prefers that address

So you agree that the value returned by GetAddress doesn't matter in this case.

Have you actually tried granting permission for org.a11y.Bus in your manifest?

The changes you propose would force applications to expose an accessibility tree whether it is consumed by an assistive technology or not. AT-SPI adds a significant performance overhead so I really would not want all users to pay the price.

@chris-addison

Copy link
Copy Markdown
Author

Hello @chris-addison,

You say:

Granting the app --talk-name=org.a11y.Bus is not a workaround: GetAddress then names the host's socket, which the sandbox can't reach.

Yet as you also point out:

Flatpak instead gives the app its own proxy of the accessibility bus in AT_SPI_BUS_ADDRESS. Bus::new already prefers that address

So you agree that the value returned by GetAddress doesn't matter in this case.

Have you actually tried granting permission for org.a11y.Bus in your manifest?

The changes you propose would force applications to expose an accessibility tree whether it is consumed by an assistive technology or not. AT-SPI adds a significant performance overhead so I really would not want all users to pay the price.

I ran a test and yes, you're right here! Thanks for the great pointer here 🙇🏻
Apologies for the noob PR here!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants