Package Management & Updates

A Flatpak app cannot see a host file

Host filesystem access and portal grants are separate from Unix file modes. Inspect app permissions before enlarging the sandbox’s access.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • A file visible to the desktop file manager is absent inside one app.
  • A portal-selected document opens, while direct navigation to its host path fails.

Relevant environment

Flatpak filesystem sandbox and document portals; app-specific user overrides can differ from system or manifest permissions.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • The sandbox may not expose the host path, even when Unix permissions allow it.
  • A per-app override or revoked document grant may narrow access further.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Replace APP_ID; specify --user or --system when scope is ambiguous. Reads declared permissions without launching the app.

flatpak info --show-permissions APP_ID

Interpret the result: Inspect filesystem entries and read-only suffixes. Declared access does not override the host file’s ordinary permissions or represent every dynamic portal grant.

Check 2

Shows the specified app’s user overrides without changing them; inspect --system separately for system-level overrides.

flatpak override --user --show APP_ID

Interpret the result: A no-filesystem override can explain restricted paths. No user override does not prove unrestricted access because the manifest and portal decisions still apply.

Check 3

Reads portal permission-store entries for this application; does not reset or grant access.

flatpak permission-show APP_ID

Interpret the result: Compare relevant document/portal grants with the intended file. Table formats are portal-specific, so an unrelated permission is not evidence of file access.

Evidence-guided next steps

Open the file through the application’s document portal

If the application supports a portal file chooser, select the needed file through its Open dialog rather than navigating an unexposed host path. This can grant access to that document without granting the whole home directory. Use the app’s supported save/export dialog for output files.

Precautions: A broken portal backend needs its own diagnosis; a broad filesystem grant does not repair the chooser service.

Recovery / rollback: Close the document and revoke only its app-specific document permission in the portal permission store if persistent access was granted; preserve unrelated grants.

Did this solution help you?

Share this solution#

Grant a necessary folder to this app with minimal rights

If the app cannot use portals and genuinely needs a specific folder, save existing overrides and add only that app’s folder permission, preferably read-only with flatpak override --user --filesystem=/absolute/folder:ro APP_ID. Replace the absolute path and ID, and restart the app.

Precautions: Do not grant host or home as a default fix. Restricted/reserved paths and ordinary host permissions still apply.

Recovery / rollback: Restore the saved per-app override file or the prior specific filesystem entry. Do not use an app-wide override reset if other intentional settings exist.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.