4 ms·
Flatpaking all the things? I'm not sure why there is this push for Linux to have the "download and double click" install experience of windows / Mac. Convenient
by lugg 7y ago
Flatpaking all the things? I'm not sure why there is this push for Linux to have the "download and double click" install experience of windows / Mac. Convenient to install sure, but as a user its a nightmare to maintain/update.
All people on Linux really need is an xdg-open standard for opening a package manager / running an install command.
- saltedshiv 7y agoAre flatpaks not all sandboxed? I thought the concept of flatpak and snap was that it offered sandboxing in a way what was never implemented to normal repo packages
- lugg 7y agoFlatpak uses kernel namespaces (like docker) to run software with a bundled set of libraries. From their FAQ: > Flatpak mostly deployed as a convenient library bundling technology early on, with the sandboxing or containerization being phased in over time for most applications. I don't really know if sandboxing is worth it for me. Running everything inside docker cotnaienrs sounds like an absolute nightmare when it comes to troubleshooting. You might think logs and things would be well defined and put in the right place for the OS to pick up, but if things were so well behaved we wouldn't feel the need for sandboxing now would we.
- curioussavage 7y agoI’ve been running many applications as flatpaks for over a year without issue. Troubleshooting is not too bad either imo.
- lugg 7y agoFlatpak should be ok, I think when it's run inside inaccessible containers it won't be. Are the files sandboxed off from the user running in flatpak?
- techntoke 7y agoNo, these are bind mounted. Most Linux programs have a standard configuration directory. The application files that don't change would probably be sandboxed so that they can be easily upgraded.
- danieldk 7y agowe wouldn't feel the need for sandboxing now would we. Applications have vulnerabilities. Sandboxes help as an additional layer of security for trusted applications. Of course, if applications are trusted and under control, a simpler mechanism like OpenBSD's pledge/unveil may be enough.
- sjellis 7y agoThey are also adding per-application isolation of settings: https://blogs.gnome.org/mclasen/2019/07/12/settings-in-a-sandbox-world/ https://blogs.gnome.org/mclasen/2019/07/12/settings-in-a-san... Flatpak is one piece of a broader design to secure Linux workstations. It is also intended to work in conjunction with Wayland and the in-development Pipewire. These lock down video and audio respectively, so that shared resources can't be misused by applications.
- pkulak 7y agoThey are updated and maintained automatically, even if your distro isn't.
- lugg 7y agoRight up until they're not because they pegged the version of some library. If things were so easily automatically updated and maintained we wouldn't need flatpak. One benefit is that if you have some software in the chain blocking updates others can update. This may actually improve overall security. I think I just argued myself out of hating flatpak. :/ Which is cool, because that os-tree switching thing sounds like btrfs snapshot hopping on steroids.
- danieldk 7y agoWhat do you mean by 'maintained' automatically? Many flatpaks use their own custom compiled dependencies that are outdated. I took a frequently-used dependency used to decode untrusted data (ffmpeg). Many Flatpaks on Flathub use outdated ffmpeg versions. Some examples: - VLC ships with a slightly older version of ffmpeg (4.1.3) with two known CVEs: https://github.com/flathub/org.videolan.VLC/blob/f1b27c13b13b95423813c9ff7b159e88c09caf9b/org.videolan.VLC.json#L608 https://github.com/flathub/org.videolan.VLC/blob/f1b27c13b13... - MakeMKV uses an outdated ffmpeg (4.1.0), which has several known CVEs: https://github.com/flathub/com.makemkv.MakeMKV/blob/3c44c8bc999be61157e822fce3db390728d7c52e/com.makemkv.MakeMKV.json#L81 https://github.com/flathub/com.makemkv.MakeMKV/blob/3c44c8bc... - Openshot uses an outdated ffmpeg (4.0.3) which has several known CVEs: https://github.com/flathub/org.openshot.OpenShot/blob/ec2077f6edee6783db2cef783b7939ad0e1a9b4b/org.openshot.OpenShot.yaml#L234 https://github.com/flathub/org.openshot.OpenShot/blob/ec2077... This is what you get when every application ships custom dependencies, rather than having a consistent package set. (I like the idea of Flatpak, but I think it hasn't found its optimum yet in terms of dependency management.)
- Jasper_ 7y agoBlindly updating ffmpeg without the app being tested for it is a recipe for disaster -- ffmpeg has made API breaks in the past, and that meant that when an ffmpeg system update was required, all projects depending on it would need to upgrade to the new API. So often, a distribution would be held back on an old ffmpeg (perhaps patched with some of the CVE fixes by a distro maintainer who might not be familiar with the codebase) to isolate the churn of upstream. flatpak lets app maintainers update at their leisure, which actually gets them on a faster update cycle.
- pcr910303 7y agoNot trying to be sarcastic, but opinions like this make me sure that the Desktop Linux won’t fly. > I'm not sure why there is this push for Linux to have the "download and double click" install experience of windows / Mac.
- KUcxrAVrtI 7y agoThere isn't a desktop any more, we might as well be trying to make Linux for the mini computer if you're chasing the desktop market.
- meruru 7y agoThat's a meme propagated by the news, but I'm pretty sure the desktop is still a thing.
- garmaine 7y ago...where? No joke. I seriously don't see desktops running rich applications around anywhere, except the mini-computer / workstation use case. Generally people are running a glorified thin terminal with a browser or putty connection to a dosbox app. People who actually do things on their own computers generally run laptops now. The exceptions are people who do demanding work loads, and they run workstations that can handle it--more like the mini-computer than the traditional office desktop. There are public computer terminals in libraries and such, but the only reasons these are not laptops are theft prevention and the need for a large screen, keyboard and mouse.
- danieldk 7y agoWalk into any random company, there will be many desktops. Sure, some applications are web applications, but they will typically also use Microsoft Office and a smattering of more niche applications. We happen to live across an office tower. People sit and work behind desktops.
- 7y ago