fix(flatpak): bundle git so hermit can clone its package registry - #10511
Conversation
Hermit needs git to clone the hermit-packages registry from GitHub when installing MCP extensions. The Flatpak sandbox does not expose git by default, so copy the git binary and git-remote-https helper from the SDK into /app/bin during the Flatpak build. Fixes aaif-goose#10497
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 125fd9d229
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
michaelneale
left a comment
There was a problem hiding this comment.
LGTM. Small, correct fix — hermit needs git to clone its package registry and the Flatpak sandbox doesn't expose it, so bundling git + git-remote-https from the SDK makes sense. Would be good to get a confirmation from a Linux/Flatpak user, but the change is trivial and low-risk.
The copied git binary resolves helper paths from its compiled prefix (/usr/libexec/git-core), which does not exist in the Flatpak Platform runtime. Set GIT_EXEC_PATH to point at the helpers bundled under /app/libexec/git-core so git-remote-https is found at runtime.
* origin/main: (24 commits) fix(session): create inventory tables atomically with schema version (#10586) fix(providers): rewrite oneOf to anyOf in tool schemas for OpenAI-compatible backends (#10571) fix(evals): report cache-aware Harbor costs (#10430) fix(acp): allow custom model as default for non-local providers (#10438) fix(config): require absolute goose path roots (#10454) chore(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.2 (#10541) fix(permissions): scope smart approval by request (#10457) fix(summon): preserve fixed subrecipe values (#10452) chore(deps): bump websocket-driver from 0.7.4 to 0.7.5 in /documentation (#10506) fix(flatpak): bundle git so hermit can clone its package registry (#10511) feat(hooks): pass working_dir to the Stop hook context (#10296) chore(deps): bump actions/setup-java from 5.5.0 to 5.6.0 (#10540) chore(deps): bump actions/setup-node from 6 to 7 (#10539) chore(deps): bump EmbarkStudios/cargo-deny-action from 2.0.20 to 2.1.1 (#10542) chore(deps): bump gradle/actions/setup-gradle from 4.4.3 to 6.2.0 (#10543) Add declarative Sakana AI provider for the OpenAI-compatible Fugu API (#10357) fix(developer): expose AGENT_SESSION_ID to shell commands (#10428) Clean up stale documentation audit findings (#10114) Restore model interactions viewer (#10205) fix(acp): forward image content chunks to client during live session (#10485) ... # Conflicts: # crates/goose/src/session/session_manager.rs
Fixes #10497
Summary
Hermit needs git to clone the hermit-packages registry from GitHub when installing MCP extensions. The Flatpak sandbox does not expose git by default, so copy the git binary and git-remote-https helper from the SDK into /app/bin during the Flatpak build.
Testing
manual - still appreciate testing form a linux user