Software

Install an app

Keep locked There is no Bazaar, GNOME Software, or Discover. That is the product. For Proton/IVPN/Mullvad, use the wizards (ujust install-proton and friends) — not Flathub. For other GUI apps the secure path is verified Flathubflatpak install → leave permission lockdown on → grant in Flatseal.

Secure default. Flathub is off. Homebrew is off. Do not turn on unfiltered Flathub (full) or brew to install a calculator. Browserless still blocks host browsers until ujust set-allow-browsers on ALLOW.

  1. Turn on verified Flathub only

    ujust set-flathub verified

    Same as setup option 2. verified is the stock-like remote filter. full is every Flathub app — a larger set, not the default here.

  2. Install the Flatpak by ID

    flatpak search NAME
    flatpak install flathub org.example.App

    Prefer the official ID from the app’s own site. Avoid random .flatpakref from blogs. Restart is rarely needed.

  3. Leave lockdown on; grant per app

    Overlay lockdown is on (stock ships it as opt-in) and cuts extra xdg folders + host-root that stock’s command does not. Pulse/PipeWire record is a separate lock. Broken portals or missing folders are usually missing grants, not a reason to disable the whole cut.

    flatpak install flathub com.github.tchx84.Flatseal

    In Flatseal, give that one app the filesystem, device, or socket it needs. Speakers often work without touching camera lockdown.

If you must: ujust set-flatpak-lockdown off when an app is unusable even after Flatseal — you opened every Flatpak. Layered RPMs (rpm-ostree install) and brew are last. Toolbox is a pet distro, not an app store — toolbox. Proton Mail/Pass/VPN: Proton wizard (not Flathub). Steam: Steam wizard (asks overlay locks).