6 ms·
> The only purpose of sudo is to protect you from yourself, that is, to avoid messing up your system by mistake. This is one reason I increasingly don't like t
by karatestomp 6y ago
> The only purpose of sudo is to protect you from yourself, that is, to avoid messing up your system by mistake.
This is one reason I increasingly don't like the normal Linux distro "system packages, plus everything else under the sun, with one interface and all co-mingled" default package management solution. I big fat "update the system" (or don't) button with my user-installed packages totally separate, as I get with macOS, is nicer. This made worse because, unless you're self-managing the base system and keeping it super minimal (as one might in Gentoo, Arch, or Void) Linux installations are weirdly fragile, I think in part because of this too-large package ecosystem all tied up with the "core" of the OS.
Especially on a single-user system, I should be able to install most software without escalating privileges. I should be able to blanket-update my user-facing software without any risk whatsoever that a kernel update will get thrown in with that (even if I don't read over the list to check—it shouldn't even be possible), nor with privileges to perform such even if it somehow did try to sneak in. I ought to be able to delete the directory with my user-installed packages and the system still boots with no errors or warnings—and yes, with a GUI and audio and networking and all that still working.
I know Nix and even a Homebrew port (with worse package availability, though) are options for achieving something kinda like this but it still feels like swimming against the current.
- elagost 6y ago"user-installed packages totally separate" from the system is more or less how the BSDs work. OpenBSD provides user packages via pkg_add and pkg_delete, and the system updates with syspatch/sysupgrade. FreeBSD uses pkg update/pkg upgrade for user-installed packages, and freebsd-update for system updates. Maybe you'd like those systems better.
- int_19h 6y agoBSD still requires root to install packages, though.
- nerdponx 6y agoOther than tradition, I don't see why a package manager for a GNU/Linux system couldn't operate in a similar fashion.
- karatestomp 6y agoYeah, I'm thinking about trialing FreeBSD for both that and having better man pages (Linux's are so incredibly bad). OpenBSD seems even nicer but I also like having, you know, software and drivers that Just Work™, which already seems like it might be a problem on FreeBSD. I haven't enjoyed using desktop Linux since like 2008 (it is not a coincidence that this is about when Poettering started to influence major distros with his NIH-motivated bloatware) and have puttered along on macOS for the last decade or so—a change is probably due, I'm just not sure there exists what I want, really. We'll see. I'm rocking Void now and it's... fine, I guess. Kinda.
- owenmarshall 6y ago> OpenBSD seems even nicer but I also like having, you know, software and drivers that Just Work™, which already seems like it might be a problem on FreeBSD. It obviously depends on what you're using, but don't discount it without glancing at driver support: I've had it running quite nicely on a handful of laptops – typically older Thinkpads and Dells – and the "just work" factor of the overall OS is through the roof.
- enriquto 6y agoHave you noticed any problems with cpu throttling or hibernation? This is what I'm most afraid about switching to openbsd on my laptop (Dell precision).
- owenmarshall 6y agoJust works on my Thinkpad x220. You should, however, look for a dmesg output referencing your system and see if anyone has reported bugs. Power management is universally evil ;-)
- cabite 6y agoFreeBSD "just works" but you have to enable everything. If you plug a mouse, you'll have to enable usbmod (or whatever kernel module is responsible for this) by hand. Maybe I'm exaggerating with that mouse anecdote, but I remember I regretted not going with PCBSD which is a user friendly distrib of FreeBSD (now renamed TrueOS). If you consider using Freebsd as an everyday desktop computer, you'll save some time with TrueOS. Having said that, configuring FreeBSD, activating kernel modules etc, is really easy, both in terms of googlability and inner clarity. Probably because it's a distrib in itself, as compared to linux and its many subtle differences across distribs.
- bityard 6y ago> I big fat "update the system" (or don't) button with my user-installed packages totally separate, as I get with macOS, is nicer. Today we live in the land of plenty. Computer hardware is so cheap, it's practical to put together a respectable lab with gear literally pulled out of a dumpster. The reason Windows and Mac OSes have a sharper line between system software and user software is because modern advances have made computer cheap enough that not only does almost everyone have their own personal computer, almost everybody has more than one. As a result, Windows and Mac have always been mostly single-user systems. Yes, yes, they support having multiple _accounts_ but usually by one person at a time, which limits the number of accounts (as a practical matter) to a handful at best. All of the major Linux distributions were designed in a time where large multi-user systems were the norm. Disk space was limited, memory was small, CPU cycles were few. Unix (and hence Linux) was designed to make efficient use of these limited resources by installing popular software system-wide with shared dynamically-linked libraries because that was the only way to even _fit_ a few hundred users on one system. As a sysadmin, I get cold sweats thinking about what would have happened if every user wanted their own personal copy of Emacs on such a system. > Especially on a single-user system, I should be able to install most software without escalating privileges. I do believe you can, see Snaps and Flatpak. These run on just about everything. But there is a steep price: user-isolated applications can take an order of magnitude more disk space and significantly more memory compared to OS-built packages, see https://www.reddit.com/r/pop_os/comments/gia8s1/flatpak_packages_significantly_larger_than_deb/ https://www.reddit.com/r/pop_os/comments/gia8s1/flatpak_pack... If you're looking for a Linux distro that behaves more like Windows and Mac, you're in luck because Ubuntu is hurtling themselves in that direction as quickly as they can by making snaps compulsory on every desktop install. > I should be able to blanket-update my user-facing software without any risk whatsoever that a kernel update will get thrown in So, I think you have it backwards. Kernel updates generally contain important security or bug fixes and you absolutely _should_ be installing those and rebooting _well_ before even acknowledging the existence of your userland apps.
- dependenttypes 6y ago> Disk space was limited, memory was small, CPU cycles were few With that logic DOS/Windows and even Mac OS (X) should be even worse regarding that then, after all both Mac OS and DOS are older than Linux. Not to mention that servers always had better cpus/more ram compared to personal computers. > Unix (and hence Linux) Mac OS X is officially recognised as a Unix. Just one of the registrations: https://www.opengroup.org/openbrand/register/brand3581.htm https://www.opengroup.org/openbrand/register/brand3581.htm > installing popular software system-wide This is exactly what windows does. Most of the times the installers need admin privileges. > see Snaps and Flatpak Nix (which was mentioned by the person that you are replying to) is an even better solution. In fact you can run it on top of existing distros too. Also, package managers for programming languages (such as Haskell's cabal and even Python's pip I think) have Nix support now. An alternative is to use appimage which is just a single executable per software.
- dependenttypes 6y ago> I big fat "update the system" (or don't) button with my user-installed packages totally separate And have to update each software package manually as in windows/macos? (even worse, have a backdoor updater build-in on packages) > I should be able to blanket-update my user-facing software without any risk whatsoever that a kernel update will get thrown in with that But why? Any and all security updates should be installed as soon as possible, regardless if it is a kernel update or a browser update.
- karatestomp 6y ago> And have to update each software package manually as in windows/macos? (even worse, have a backdoor updater build-in on packages) I only use Windows for gaming so IDK there, but almost everything I use on macOS is installed with Homebrew (a package manager). Even crapware like Slack. Though yes some of those do decide to use their own built-in updaters after that—no helping that, if you must use their software, but being able to script installation of them through one interface is really nice. > But why? It shouldn't be possible to break one's system with the same tool, commands, and privileges one uses to install Tux Racer. Installing normal user-facing packages shouldn't require privileges that even allow for screwing with basic system software. > Any and all security updates should be installed as soon as possible, regardless if it is a kernel update or a browser update. God damn I guess I picked a bad example because folks are really stuck on that. Reverse it then: if I want the latest drivers, xorg, and kernel, including feature updates, what's that got to do with my installation of Tux Racer? Why are those connected in any way whatsoever? Why do the same tools manage installing and updating both? "Build it from source then" yeah but I like package managers except for oddball stuff like dwm, I'm not saying get rid of them. I could use Homebrew or Nix on top of some distro but that's a road full of jank and more fiddling-with-trivia than I have patience for these days. I'll crankily live with Void Linux for now and pine for a robust, small, tested, rock-solid base system built for using one or more complementary and supplementary user-facing package managers on top of. I mean macOS isn't even built for that, exactly, it just suits the case very well. I wish there were a Linux distro that did, too.
- jabirali 6y ago
- em-bee 6y agoyes and no. there is a benefit in having user applications installed as root or as some other system user. they can't be exploited by malicious software that runs with user privileges.
- markosaric 6y agoThere's Fedora Silverblue [1] too. It's immutable so every installation is identical to every other installation of the same version. And then you install your Flatpaks isolated from the rest of the system on top of that. [1]: https://silverblue.fedoraproject.org/ https://silverblue.fedoraproject.org/