9 ms·
Pollute your mount list and make your software start way slower and take up more space. Also sometimes break or require intervention for basic operation due to
by spanhandler 6y ago
Pollute your mount list and make your software start way slower and take up more space. Also sometimes break or require intervention for basic operation due to security restrictions on it.
The benefits are supposed to be that they're more secure, more portable, and don't junk up your system with files strewn everywhere.
Personally I'm waiting for a better solution than anything we've seen so far for the first of those benefits, and would prefer a cross-platform user-oriented package manager like Homebrew or Nix (but better-supported-on-Linux in the former case and with a UX less like studying for a math exam in the latter) for the other two. IMO every solution to these problems on Linux desktop currently sucks to one degree or another.
- boogies 6y agoI'm curious to try GNU Guix, does it sufffer from the same problems as Nix? (Edit: looking at https://guix.gnu.org/en/videos/everyday-use-of-gnu-guix,-part-one/index.html https://guix.gnu.org/en/videos/everyday-use-of-gnu-guix,-par... from the top of https://guix.gnu.org/ https://guix.gnu.org/, basic installation and removal of packages looks exactly like apt, literally the same command line with 'apt' replaced with 'guix' and 'sudo' unnecessary because you can install packages per user.)
- spanhandler 6y agoI admit I've not checked and have just assumed the package list is both ideologically- and mindshare-crippled, due to the GNU on the name and the seemingly low rate of use, respectively. Nb I think free software goals are great and all but if I need Slack for work or need my proprietary wifi card to work using a binary blob then I f#cking need those things, and it's nice if my package manager can install them for me. It's also nice if it's got enough eyes on it that I essentially never run into a broken package, even when installing kinda-obscure things.
- boogies 6y agoYou can use Guix on distros with impure repos, not just the GNU Guix system, and use the host distro's packages for proprietary software (if you can't just use Slack's web client, or use a laptop with a freedom-respecting wifi card / a little dongle / ethernet).
- glglwty 6y agoYou may find guile easier to read (I don't). In terms of packages and features it's way less useful than nixpkgs.
- AsyncAwait 6y agoWhat's so impressive about Homebrew specifically?
- katbyte 6y agoI dunno exactly but my coming back to Debian for a server recently the apt experience hasn’t been as nice as brew in terms of discovery and use
- AsyncAwait 6y agoI am personally a fan of more lean solutions than apt, but there are several on Linux, like pacman (Arch), apk, (Alpine), Portage etc. Search: pacman -Ss <package> Install: pacman -S <package> Remove: pacman -R <package> Pacman is not tied specifically to Arch either.
- spanhandler 6y agoOddly enough, my favorite package management experiences, by far, have been Homebrew on Mac and Portage on Gentoo. Talk about polar opposites. I do think, unfortunately, that the experience of a very stable base of macOS with Homebrew on top would be nearly impossible to replicate on desktop Linux, because Linux's GUI layer is so intertwined with user software, and is so... uh, "free and libre", I guess, is a nice way to put it. You'd end up with a bunch of copies of KDE and Gnome libs and probably multiple competing IPC buses or god knows what, in no time. Maybe multiple sound daemons stepping on each other. You'd probably have issues like different apps deciding to do scaling or font rendering differently, or who knows what, because lots of "basic features" on macOS are instead choices on Linux.
- kelvie 6y agoAlso curious. I'm waiting, or even begging for something like flatpak on mac os just due to the number of times pip/npm/python in general has broken due to homebrew.
- boogies 6y ago
- zanny 6y agoNote that the sandboxing security theater of flatpak and snap etc is largely just that. You can have very secure deb packages by having default-deny apparmor rules. This is basically how Android works, it just asks you to grant the permissions in real time (and uses a frankenmix of custom Google fu Android Java API and selinux). You can also use cgroups to control kernel feature access like devices, networking, peripherals, etc. It comes from both angles though. Having more software provide an apparmor profile (transpilable to selinux policies, etc) and having GUI-integrated permissions and cgroups control functionality in both software stores (via appstream? it seems to be the common thread) for both at-install and at-runtime permission grants. The problem of course is inertia. Flatpak isn't even compelled to sandbox and its sandbox is not nearly as comprehensive as one would want when running untrusted software, not just potentially exploitable buggy trusted code.
- DoctorNick 6y ago>You can have very secure deb packages by having default-deny apparmor rules. Nobody would do this on a desktop because it is massively inconvenient to go through every single app you want to run and debug which app armor rule that it's violating. Even when running a service with a pre-written app-armor profile you usually have to spend a while to figure out what the hell went wrong. Flatpak's sandboxing is a complete joke and is entirely voluntary. Snaps have sane and granular permissions interfaces that you can easily toggle on and off. Canonical is actually enforcing auto-connect rules for the more potentially dangerous ones in their store. If you want to get a classic confined app in the store, it actually has to be approved by their security team. These things are GREAT for security, which, to be quite frank, is a complete fucking disaster on Linux desktop. X11 is a massive security hole, no real mandatory access control, no sandboxing for apps, local privilege escalations out the wazoo, a quadrillion open security bugs in the kernel. Sure, you can try and set these things yourself, but that relies on the USER to properly configure these things, and if you don't know exactly what you're doing and screw it up (and there are no reliable, consistent guides on how to do these things), then you're just as insecure as you were before. We're just fortunate that Linux on desktops aren't popular enough to be targeted, because we'd just be getting constantly owned thanks to this massively outdated security model. Windows is actually doing the security model a whole lot better these days, but their popularity and their tendency to implement them poorly and with bypasses to preserve backwards compatibility kind of cancels that benefit out. It's a real shame that snaps have not taken off. If flatpak wins, and they don't massively overhaul the damned thing to actually add some semblance of sandboxing with permissions controlled by the user, then we're doomed.