Re: Next steps for a reproducible Fontconfig?

"Keith Packard" <[email protected]> Thu, 31 Jan 2019 00:40:14 -0800
Newsgroups gmane.comp.fonts.fontconfig
Message-ID <[email protected]>
Alexander Larsson <[email protected]> writes:

> We don't want a global salt for everything in the container.

I guess I wonder why not? Salt + dir inside the container will always be
unique. The place where you want to have different salt is for
directories mapped from the host; I think those will always be in
remap-dir clauses, if we have salt there, that should work?

> In
> reality things are more complicated than that. For example, an app may
> bundle fonts, which will be in like /app/share/fonts, in addition to
> the runtime fonts in /usr/share/fonts. These come from different
> places and may individually be different in a different (or updated)
> app, so the directories need to have different salts.

If building the flatpak generates the font caches, then per-flatpak salt
would make those correct.

> Also, it is quite possible that some host font directory is *not*
> remapped, but still visible to the app. For example /opt/fonts for an
> app that has filesystem access. If for whatever reason fontconfig
> looks at this directory it should not apply any salt for it.

Oh, so some host directories may be visible unmapped and unknown to the
flatpak? In that case, we'll need to enumerate all flatpak visible font
directories separately.

I think we need a complete enumeration of the cases; I keep seeing more
options...

-- 
-keith

_______________________________________________
Fontconfig mailing list
[email protected]
https://lists.freedesktop.org/mailman/listinfo/fontconfig
signature.asc (application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEw4O3eCVWE9/bQJ2R2yIaaQAAABEFAlxStG4ACgkQ2yIaaQAA
ABFAvxAAh8pQIak/HYHZxuSEmFyHeGuhoPMvWjMD2IeMNJAK2utVvmj+mrfwshQg
Rlpmaln3xl5JMwYoyVjeIvjUHg8ih8XZ483vsmwSVhkHcuh+tezrxear5a8j3tM/
sEB4Y5SN0C3W3+jvLnfczFk7crWAtalrlVeupA0EyPDf9mu4GoLUosSjHdKIc3Gd
tdw3cndalQGLiybMpn0bsviGMmY3EP5YHTYwG27H6eXcHSUBKoAGRlZPf5PRfs/M
52n+2ugVW3+v+DB0j436l3bG2WJifCPo9Gc1PdHxSaO5VkLvzBrEVXqgh7L0nFTL
i21mdywJVQbH0NnyR0rTJIe4eqx6uBe/AQW3jOVJCiQoKWQ9SVXFgzsXS1NQ6+Rl
vO21AAn55wYObWsytK2HBcLqOOJzHywpBAtQFe0WvRzocxNIoNVCZmbVA7nNoog/
Qtq/iZHXjqyjK5OJYkiuhttcC2KL74vv9tLs12HIynIGy9Qr39AHbBltUhQdMhYk
ysJy1S+qa3YYzOxJrtSpu6FIV5Cf2wMqF4/RZOxTI2Exv1pR6lKTz0ziel47x/qM
io6YzIW1PrgDaU+4myrEHtEuqz42SzIZgnz+FVSeTFV18ub7WAgcNkCq6c/LP41L
etJfQbOfj6pNl0DFxE11e+tADZnkvs3Y69cFYgEHz8OjHeK/RAM=
=C8eC
-----END PGP SIGNATURE-----