This branch is 53 commits behind rosa/hakurei:staging
cat bbb6f349d3 internal/rosa/package/python: reject new setuptools-scm releases
These have become slopware for a long while now. Even before then it was only acting as a stub to cope with the messy python ecosystem. Regardless, these updates do nothing and even occasionally break things, so reject them until the stub package is available for their removal.

Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-09-15 19:06:04 +09:00
2026-07-07 18:56:27 +09:00
2026-09-15 00:06:21 +09:00
2026-06-08 14:58:24 +09:00
2026-09-15 18:42:24 +09:00
2026-06-20 00:20:31 +09:00
2026-08-25 14:53:29 +09:00
2026-06-08 14:58:24 +09:00
2026-09-15 18:42:24 +09:00
2026-06-08 14:58:24 +09:00
2026-09-15 00:06:21 +09:00
2026-05-10 04:15:07 +09:00
2026-08-20 19:05:29 +09:00
2026-09-12 20:40:43 +09:00
2026-05-10 04:15:07 +09:00
2026-08-29 18:58:06 +09:00

Yukari

Go Reference Gitea Workflow Status
Release MIT License Website

Hakurei is a tool for running sandboxed desktop applications as dedicated subordinate users on the Linux kernel. It implements the application container of planterette (WIP), a self-contained Android-like package manager with modern security features.

Interaction with hakurei happens entirely through structures described by package hst. No native API is available due to internal details of uid isolation.

Notable Packages

Package container is general purpose container tooling. It is used by the hakurei shim process running as the target subordinate user to set up the application container. It has a single dependency, libseccomp, to create BPF programs for the system call filter.

Package pkg provides infrastructure for hermetic builds. This replaces the legacy nix-based testing framework and serves as the build system of Rosa OS, currently developed under package internal/rosa.

Dependencies

container depends on:

cmd/hakurei depends on:

cmd/sharefs depends on:

  • fuse to implement the filesystem.

New dependencies will generally not be added. Patches adding new dependencies are very likely to be rejected.

S
Description
A security-focused desktop application container runtime.
Readme MIT
9.8 MiB
Languages
Go 87.7%
Azalea 5.2%
Nix 4.4%
C 1.4%
Python 0.7%
Other 0.4%