Skip to main content

rufpak

rufpak turns a Flatpak application into a native Arch package. The packaged application does not need Flatpak or its runtime at run time. Building the generated package requires the ostree-dlagent package installed.

Install

pip install rufpak

Or run it without installing, via uv:

uvx rufpak com.github.PintaProject.Pinta --gpg-key publisher-key.asc ...

Build a package

rufpak can download signed OSTree content without Flatpak. Get the application publisher's public OSTree signing key.

rufpak com.github.PintaProject.Pinta \
    --repourl https://dl.flathub.org/repo/ \
    --gpg-key publisher-key.asc \
    --probe 30 \
    --outdir build
cd build
makepkg -si

The default runtime remote is the application remote. Set the runtime remote and key when the application uses a different runtime.

rufpak com.kagi.Orion \
    --repourl https://flatpak.orionbrowser.com/repo/beta/ \
    --gpg-key orion-key.asc \
    --runtime-repourl https://dl.flathub.org/repo/ \
    --runtime-gpg-key flathub-key.asc \
    --outdir build

--gpg-key is required. The generated PKGBUILD pins the key's fingerprint in validpgpkeys and ships the key itself under keys/pgp/, so makepkg verifies the application source during the build — using your own GPG keyring, not rufpak's. Import the key first (gpg --import keys/pgp/*.asc in the output directory) or the build will fail with "PGP key could not be verified". --allow-unverified disables this and is unsafe.

Configuration

Pass a JSON object with --config rufpak.json. rufpak does not search for or load configuration files automatically. JSON keys use long option names with underscores. CLI values override config values.

{
  "appid": "com.github.PintaProject.Pinta",
  "repourl": "https://dl.flathub.org/repo/",
  "gpg_key": "flathub-key.asc",
  "probe": 30
}

How it works

Flatpak applications expect their files at /app. rufpak installs the payload at /opt/rufpak/<appid>. The generated launcher uses bubblewrap to mount that directory at /app.

The generated PKGBUILD fetches the app and, if needed, its runtime through ostree-dlagent, a makepkg DLAGENTS handler that turns a pinned OSTree commit into three sources instead of a hand-rolled ostree pull in prepare(): the commit object (sha256sums-pinned to the commit itself), its detached GPG signature (checked by makepkg against validpgpkeys, using your keyring), and the content as a tar. This also gets normal makepkg source caching for free.

Dependencies

rufpak scans application ELF files for DT_NEEDED libraries. It also scans for library names used with dlopen, P/Invoke, or ctypes. Host libraries are converted to Arch package dependencies.

--probe SECONDS starts the application and reads its loaded libraries. Use it for applications with dynamic runtimes such as .NET. The probe needs a working display. Review its output because drivers and desktop services from the build machine can appear as optional dependencies.

Libraries that Arch does not provide at the required ABI are copied from the Flatpak runtime into the package payload.

Files and desktop integration

The launcher uses the Flatpak [Context] declaration for user directories. --no-confine exposes the whole home directory and should only be used when the application needs it.

--xdg app is the default. It stores XDG configuration, data, and cache under ~/.var/app/<appid>. --xdg host uses the host desktop XDG directories. This applies host GTK styles, which can break libadwaita applications.

Security limits

The launcher is not a replacement for Flatpak. It has no Flatpak seccomp filter or D-Bus proxy. An application can access the real session bus. Do not use rufpak to run an application you do not trust.

Generated files

rufpak writes a PKGBUILD and a bubblewrap launcher to the output directory. The package installs application files under /opt/rufpak/<appid>. The launcher is installed under /usr/bin.

Metadata

Release files for rufpak 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rufpak 1.0.0
File Size Uploaded
rufpak-1.0.0.tar.gz 16.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rufpak 1.0.0
File Interpreter ABI Platform
rufpak-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 32.5 kB

Release files / rufpak-1.0.0.tar.gz

Download URL rufpak-1.0.0.tar.gz
Size 16.1 kB
Tags Source
SHA-256 checksum
How to use checksums
d79b95c9205b93ae1a1c689a6ec74722675c52ddbaf4240e9d96946a545dbd34
BLAKE2b-256 checksum
How to use checksums
1122f30b602336c1977ff4c93ef0aad1d7a6c0bc2b4541ca905c0abf51e2e859
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / rufpak-1.0.0-py3-none-any.whl

Download URL rufpak-1.0.0-py3-none-any.whl
Size 16.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
42d33fb5519ecf80e2ff3668e5078e4cf37e209e4594f99e2356c2a9a32b5654
BLAKE2b-256 checksum
How to use checksums
d9611e421ec8e7afeb874a0b78c7a0f32ed4bccf524f2cc878712480ee906d82
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page