Skip to content

Register with AT-SPI inside a Flatpak sandbox - #13

Closed
chris-addison wants to merge 2 commits into
unity/HUB-8070-hub-pin-2from
unity/HUB-0000-flatpak-atspi-bus-2
Closed

chris-addison wants to merge 2 commits into
unity/HUB-8070-hub-pin-2from
unity/HUB-0000-flatpak-atspi-bus-2

Conversation

@chris-addison

@chris-addison chris-addison commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Makes a Flatpak app register with AT-SPI, so screen readers can see it, by carrying a patched copy of accesskit_unix 0.24.0 until an AccessKit release handles the case.

Why: accesskit_unix connects to the accessibility bus only after it reads org.a11y.Status.IsEnabled from org.a11y.Bus on the session bus. Flatpak hides org.a11y.Bus from the sandbox (GetAll fails with ServiceUnknown) and hands the app its own proxy of the accessibility bus in AT_SPI_BUS_ADDRESS instead. The property stream never yields, so the adapter never activates. In the native Unity Hub's Flatpak, the app was missing from Atspi.get_desktop(0) even with accessibility on. 0.24.0 is the latest release, and upstream main has the same code.

  • First commit: vendors accesskit_unix 0.24.0 under vendor/, byte for byte as published, plus its upstream licence files and a UNITY.md note. It sits outside the workspace (exclude), and typos skips vendor/, so neither CI lane lints third-party code.
  • Second commit: when AT_SPI_BUS_ADDRESS is set and IsEnabled can't be read, the adapter connects to that bus at once and treats accessibility as enabled, as GTK and Qt do. Bus::new already prefers that address. Where the toggle can be read, it stays in charge.

Verified with the Hub built against this branch and run inside the installed com.unity.UnityHub sandbox: before, the app was missing from the AT-SPI desktop. After, it lists its frame, dialog, heading, buttons and links. A non-sandboxed build behaves as before.

Hub pin: Unity-Technologies/unity-hub#16305. Replaces #12, which sat on unity/HUB-8048-hub-pin-3 before the Hub moved to unity/HUB-8070-hub-pin-2. Upstream: AccessKit/accesskit#817 carries the second commit. Drop vendor/ once a release includes it.

🤖 Generated with Claude Code

gpui_linux now builds against a copy of accesskit_unix 0.24.0 under
vendor/, outside the workspace, so the next commit can patch it. This
commit is the published crate byte for byte, plus its upstream licence
files and a note on why the copy exists. typos skips vendor/.
accesskit_unix connects to the AT-SPI bus only after it reads
org.a11y.Status.IsEnabled from org.a11y.Bus on the session bus. Flatpak
hides org.a11y.Bus from the sandbox (GetAll fails with ServiceUnknown)
and hands the app its own proxy of the accessibility bus in
AT_SPI_BUS_ADDRESS instead. The property change stream then never yields,
so a sandboxed app never registered and screen readers never saw it.

When AT_SPI_BUS_ADDRESS is set and the toggle can't be read, the adapter
now connects to that bus at once and treats accessibility as enabled,
as GTK and Qt do. Bus::new already prefers that address. Where the
toggle can be read, it stays in charge.
@chris-addison

Copy link
Copy Markdown
Collaborator Author

CI fails the same five checks its base, #9, fails, none of them in this change.

Check Cause
❌ clippy, msrv, test-linux, test-windows gpui_media/build.rs can't find bindgen (open in #6)
❌ typos wdth in the Noto Sans font name (open in #10)

No error points into vendor/accesskit_unix. Locally, its clippy is clean with -D warnings on both the default and tokio features.

🤖 Posted by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant