4 ms·
> What exactly do you want gimp to do - request a permission to access whole home dir? then we are back to unsecure world. Author here. That wouldn't be so bad
by ludocode 5y ago
> What exactly do you want gimp to do - request a permission to access whole home dir? then we are back to unsecure world.
Author here. That wouldn't be so bad; it's kind of how it works on Android. An app can just request permission to access the entire external storage. It's not exactly the home dir (there's no potential for auto-starting scripts) but it's similar. The permission prompt is still useful because it's something you can decline; you're not forced to agree implicitly to install the app.
But anyway what I want is to install and run GIMP and Excel and Photoshop completely unsandboxed. I think it's silly to try to sandbox every app. The insecure world is still the world of Windows today and it's the dominant platform by far, in part because of the freedom it provides to software vendors.
I do actually prefer traditional installers, which is why I like GOG so much. Good installers will just put their app data into ~/.local/share/<app>, put an icon in ~/.local/icons and a desktop file in ~/.local/applications, and provide an uninstall mechanism to clean it up. There's no mess here, no root required, no accumulating gunk. Longer term, these installers could automatically write AppStream metadata so that the installed app appears and can be uninstalled through the distribution's Software app, like Add/Remove Programs in Windows.
Regardless of what I prefer, the fact is the biggest software vendors will never allow their software to be sandboxed. Look at how Adobe Creative Suite or Microsoft Office are installed on Windows and macOS. They aren't in the OS app stores. They have their own custom installers that handle login, keep the apps up to date, do DRM checks, etc. I'm sure this is not what you want, but it is what they want, and if they can't get it then they just won't port their software to Linux.