Skip to content

AppImage fails on Ubuntu 24.04+ (requires manual apt install and use of --no-sandbox) #1482

Description

@ryanshipswell

Ubuntu 24.04+ requires both manual installation of FUSE v2 and the use of --no-sandbox for the AppImage to run.

While these are two separate issues, they appear together in practice on Ubuntu 24.04 (and likely later versions) and effectively prevent the AppImage from running out-of-the-box.

The FUSE issue is due to AppImage/Electron builds depending on FUSE v2, while Ubuntu 24.04 only ships FUSE v3 by default.

The sandbox issue appears related to Electron/Chromium behavior interacting with Ubuntu’s AppArmor restrictions.

I noticed issue #1341, which suggests an installer. While this is helpful and could automate FUSE installation and improve overall setup, it does not resolve the sandbox issue and --no-sandbox would still be required.

Both issues are avoided by shipping either a Flatpak or native package.

Below is a structured breakdown of the issue (partially AI-assisted for clarity):


## Summary

On a clean Ubuntu 24.04 system, the AppImage fails to launch normally and requires both:

- installing legacy FUSE (`libfuse2t64`)
- launching with `--no-sandbox`

This appears to be a broader issue affecting Electron AppImages on modern Ubuntu versions.

---

## Steps to reproduce

    chmod +x T3-Code-*.AppImage
    ./T3-Code-*.AppImage

---

## Actual behavior

### 1. Missing FUSE

    dlopen(): error loading libfuse.so.2

Fix:

    sudo apt install libfuse2t64

---

### 2. Sandbox failure

    FATAL: The SUID sandbox helper binary was found, but is not configured correctly.
    .../tmp/.mount_*/chrome-sandbox must be owned by root and have mode 4755

---

### 3. Works only with

    ./T3-Code-*.AppImage --no-sandbox

---

## Root cause

Ubuntu 24.04 introduced stricter AppArmor restrictions on unprivileged user namespaces.

This prevents Electron/Chromium from initializing its sandbox for apps distributed outside system packaging (including AppImages), especially due to the `/tmp/.mount_*` runtime path.

---

## Why this matters

- Ubuntu 24.04 is the current LTS
- App does not run out-of-the-box  
- `--no-sandbox` disables Chromium sandboxing (not ideal)  
- Likely to persist in future Ubuntu releases  

---

## Relation to #1341

The installer proposed in #1341 improves AppImage UX (desktop integration, updates, FUSE fallback), but does not resolve this sandbox issue.

Even with an installer, the app still fails unless `--no-sandbox` is used.

---

## Suggested solutions

### Best long-term options

- Provide a **Flatpak** build (recommended for Electron apps)
- Provide native packages:
  - `.deb`
  - `.rpm`

---

### Short-term

- Detect Ubuntu 24.04+ and pass `--no-sandbox`, or document it clearly

---

**Note:**  
Rebuilding the AppImage alone likely won’t fix this, as it is caused by OS-level sandbox restrictions.

---

## Additional context

This issue affects many Electron AppImages on Ubuntu 24.04+ due to the same underlying sandbox/AppArmor changes.

Activity

  1. MoralCode commented on Mar 29, 2026

    @MoralCode

    i threw together a super janky flatpak https://github.com/MoralCode/codes.t3.app

    it unpacks the appimage and ships it as a flatpak. havent yet figured out how to get the claude and codex CLIs working in the sandbox just yet though

  2. PolarBearEs commented on May 7, 2026

    @PolarBearEs

    I can confirm that the problem persists on Ubuntu 26.04

  3. PolarBearEs commented on May 7, 2026

    @PolarBearEs

    This worked for me as a workaround.

    ./T3-Code-0.0.22-x86_64.AppImage --appimage-extract
    sudo chown root:root squashfs-root/chrome-sandbox
    sudo chmod 4755 squashfs-root/chrome-sandbox
    ./squashfs-root/AppRun
    
  4. juliusmarminge commented on Oct 6, 2026

    @juliusmarminge
    Member

    Note

    Grok responding on behalf of Julius.

    Fixed by #7765, which just landed on main. Linux AppImages are now built with the static AppImage runtime (toolset 1.0.3), so they no longer need libfuse2/libfuse2t64. The new launcher also only adds --no-sandbox when unprivileged user namespaces are blocked (as on stock Ubuntu 24.04+), so you shouldn't need to pass it by hand. This will ship in the next nightly. If either problem still shows up on a build that includes #7765, please open a new issue with the version and distro.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions