flatpak: grant filesystem access to ~/.stackwallet
What changed, and why it matters
This change updates the Flatpak packaging for Stack Wallet so the app can read and write files in a folder named .stackwallet inside the user's home directory. Flatpak apps normally run in a sandbox with limited access to the rest of the computer. The commit message only says this is being added to grant filesystem access to that folder; it does not say this fixes a security bug or that any vulnerability was reported.
Review whether ~/.stackwallet access is necessary and whether a narrower permission (for example, a portal or a more specific subdirectory) would suffice. Treat this as a routine packaging change unless independent security context emerges.
Security signals we found
Flatpak sandbox permission expanded to host filesystem path
No commit-level security framing or vulnerability description
No CVE, advisory, or researcher attribution in commit or supplied references
Evidence from the diff
The diff adds one line to flatpak/com.cypherstack.stackwallet.yaml: –filesystem=~/.stackwallet under finish-args. This exposes the host path ~/.stackwallet to the Flatpak sandbox. The change is a sandbox permission expansion, not a code change. There is no indication in the commit or supplied references that this is a security patch, a vulnerability fix, or a response to a security report. It appears to be a packaging/permissions adjustment, likely so the wallet can store its data outside the default per-app sandbox directory.
Changed components
flatpak/com.cypherstack.stackwallet.yamlFlatpak sandbox permissions for Stack WalletInspect captured patch +1 / −0
diff --git a/flatpak/com.cypherstack.stackwallet.yaml b/flatpak/com.cypherstack.stackwallet.yaml
index 3707ccb..f8836e6 100644
--- a/flatpak/com.cypherstack.stackwallet.yaml
+++ b/flatpak/com.cypherstack.stackwallet.yaml
@@ -10,6 +10,7 @@ finish-args:
- --socket=fallback-x11
- --socket=wayland
- --device=dri
+ - --filesystem=~/.stackwallet
- --talk-name=org.freedesktop.secrets
- --talk-name=org.freedesktop.Notifications
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.