11 ms·
I feel like these articles always do a disservice by misrepresenting things about Linux. Just some parts I stumbled over: > [about jails] They are also very ea
by mxey 4y ago
I feel like these articles always do a disservice by misrepresenting things about Linux. Just some parts I stumbled over:
> [about jails] They are also very easy to debug and troubleshoot comparing even to plain Docker – not to even mention Kubernetes which requires whole team of highly skilled people to maintain.
Yeah, of course, a single-node container tool is easier to run than a Kubernetes cluster.
> Can you tell my how many steps (and which ones are required) to rebuild CentOS or Ubuntu for example without Bluetooth support?
Why do I need to rebuild without Bluetooth support?
> When using systemd(1) you never know how the services gonna start because it will be different each time. Zero determinism.
systemd starts services in dependency order. The author makes it sound like systemd just randomly shuffles the services each boot for fun.
- deleted 4y ago[deleted]
- ahoka 4y agoYeah, totally clueless BSD fanboy. I have seen many during the time I was a heavy BSD user.
- nix23 4y ago> Yeah, totally clueless BSD fanboy. I have seen many during the time I was a heavy BSD user. He works at Kyndryl do you know what it is/was?
- bigpeopleareold 4y agoHe might be, but adding some levity to this, it might be that he is just deeply ironic (even if some here complain of things incorrect in his analysis.) :D
- nix23 4y ago>Yeah, of course, a single-node container tool is easier to run than a Kubernetes cluster. >>comparing even to plain Docker – not to even mention Kubernetes >Why do I need to rebuild without Bluetooth support? Because you don't need it? Or you don't want it, but cannot deactivate it in bios? Security and Kernel-size >> services gonna start because it will be different each time Please read and don't make your own interpretation like with docker -> kubernetes
- cassianoleal 4y ago> Because you don't need it? Or you don't want it, but cannot deactivate it in bios? Security and Kernel-size Just blacklist the kernel modules, then. Or even plain delete them from disk.
- A4ET8a8uTh0 4y agoYou don't have to blacklist or delete anything if it is not there to begin with, which is the point of OP.
- nix23 4y agoIt's kind of crazy, people always say bloat here bloat there, but then come up with blacklisting....ahhh the forgotten "art" of just having the code you need on your machine ;)
- mbreese 4y agoI get the sentiment, but there is also something to be said for having a consistent and stable starting configuration. Yes, you might end up removing Bluetooth modules from servers, but you know exactly what the starting kernel config is. When you have completely custom kernels for each server, you’ll spend half of your time just figuring out what the starting configuration is. Compiling kernels is really a lost art that many people have never done. It’s probably best to avoid too much of that in production until it’s absolutely necessary.
- nix23 4y ago>It’s probably best to avoid too much of that in production until it’s absolutely necessary. Well yes, being organized is always important, like a customer of mine wanted all Linux server with GUI and installed all of them as "Desktop-Role" aka preempt-kernel. Gui-Server...bleh..but Customer is King, but i could at least change he's mind about the kernel so Gui-Server-Role it was.
- 4y ago
- sagonar 4y agoI think determinism would be way better than a system with some pseudo random setup. I think hand waving away the specific language used, ie "determinism" without really talking about what it means or why it does (not) matter is dishonest.
- Gwypaas 4y agoCausality and determinism are different, and it honestly makes sense to have it be random to tease out bugs as early as possible. For a prime example see hash maps in Go, which is specifically non-deterministic when iterating over them to prevent users from relying on any kind of implicit behavior. > "When iterating over a map with a range loop, the iteration order is not specified and is not guaranteed to be the same from one iteration to the next." https://go.dev/blog/maps https://go.dev/blog/maps
- jeffparsons 4y ago> [...] prevent users from relying on any kind of implicit behavior. Except now you just _know_ that somebody out there is using hash map iteration order as a source of entropy. ;)
- Gwypaas 4y agoHush! > "Is map iteration sufficiently random for randomly selecting keys?" https://stackoverflow.com/questions/41019703/is-map-iteration-sufficiently-random-for-randomly-selecting-keys https://stackoverflow.com/questions/41019703/is-map-iteratio...
- steeleduncan 4y ago> Why do I need to rebuild without Bluetooth support? I think the point here is that any code on your system is a potential security liability, regardless of whether the relevant feature is active. Removing linked in code removes potential security liabilities and as such it is always a good thing. Regarding the original article's question Can you tell my how many steps . . . Ubuntu for example without Bluetooth support?, its not actually that bad apt-get source linux-image-$(uname -r) edit your options and get compiling.
- mekster 4y ago> I think the point here is that any code on your system is a potential security liability, regardless of whether the relevant feature is active. zzz... Then I guess any binary distro that you don't compile your own kernel with absolute minimum requirement aren't good? Not sure how Red Hat customers are doing their business then.
- BirAdam 4y agoSomething working out well up to the present moment does not mean that it is the best possible solution. Most stuff is garbage and could be improved. If you want the most secure system, you minimize the amount of stuff that’s in it and you increase the quality of that stuff that is there.
- mekster 4y agoTalk is easy. People weigh practicality over theoretical perfection.
- corrral 4y ago> Regarding the original article's question Can you tell my how many steps . . . Ubuntu for example without Bluetooth support?, its not actually that bad Finally. I'm surprised at how many posters here deflected this point, because last I checked it's actually really easy on major distros. I guess that tells us something about how many Linux users on HN have ever compiled their kernel, that most were like "LOL why?" and not "sure, it's easy".
- alxlaz 4y ago> systemd starts services in dependency order. I'm not sure if this is still the case, because I no longer use Linux, and I may be misremembering it. But IIRC a good while back, there was no way to guarantee service start order at boot. You could specify dependencies for some services, but even then, if there was more than one choice of dependency order that satisfied the requirements, systemd did not guarantee that the same one would be used on each startup. Otherwise, services with no dependency specs (or groups of services at the end of the same dependency chain) would get started in parallel. If you really wanted to start a sequence of services in order, doing so by specifying dependencies in separate unit files was really painful and basically impossible to debug, especially since dependencies weren't exactly easily described (various combinations of After=, Requires=, Wants=, BindsTo= that went both ways between targets and service links in the dependency chain). Please note the "I may be misremembering it" part. My life is a lot happier now that I no longer need to care about Linux userspace stuff so I may be repressing some memories :-D. Edit: > Why do I need to rebuild without Bluetooth support? The author chose a lazy example. Yeah, you don't usually need it. A better example: rebuild with `CONFIG_BFQ_GROUP_IOSCHED=y` to enable proportional weight division of disk bandwidth in CFQ.
- danielheath 4y ago> guarantee service start order at boot If the services boot after their dependencies, why do you care what order they boot in? Plus, it's rare to find a CPU with fewer than four cores these days, so 'order' becomes harder to reason about.
- alxlaz 4y agoFirst off, dependencies aren't just other services. You can have "when the network interfaces are up" as a dependency, for example, so this isn't just about how many programs run at once and in what order. Second, you care about it in scenarios where predictability is required. If your customer says they want their smart TV or their POS or whatever to boot in no more than X seconds under normal operating conditions, it's really not cool if the system can take a slightly different way to multi-user.target. Dependencies across separate chains can contend for resources, for example. "But these are embedded systems, you should just run rc.local" I hear you say? Right. These things run like fourty services, from telemetry to user interface and from firmware update to encrypted cloud backup, half of them written in Node.js, on top of a system that's basically built for systemd. It's not something you can extricate yourself out of. I don't know if there are equivalent examples in the server world (not my field), but I wouldn't be surprised if there were.
- ungamed 4y ago> Can you tell my how many steps (and which ones are required) to rebuild CentOS or Ubuntu for example without Bluetooth support? Why would you when you can just disable the kernel module, then nothing bluetooth works. Why rebuild ?
- mxey 4y agoGood point.
- mm007emko 4y ago> Why do I need to rebuild without Bluetooth support? Have you tried Bluetooth on FreeBSD? It's an unstable mess which does not support any newer device. Bluetooth always worked for me out-of-the box on any reasonable Linux-based OS. FreeBSD was like 20 years old memories of Linux Wi-Fi Cards. Remember 'ndiswrapper'? That's how bad Bluetooth on FreeBSD is. So the author probably assumes that Bluetooth is a piece of shite everywhere and want even Linux programs without a support or so.
- WesolyKubeczek 4y agoHah, so there's the problem right there. In Linux, you don't need to disable Bluetooth support, because it just freaking works. Or your hardware doesn't have any Bluetooth and the relevant modules are never inserted. Or you insert the module manually to send it a packet that will open a hole that... wait, to do that you need to have host and root access already. My freaking god, when are fanboys going to grow a clue already?
- nspattak 4y agodamn, i do not know if I am happy for remembering or sad i remembered ndiswrapper...
- mxey 4y agoSo the advantage of FreeBSD over Linux is that a feature that is broken can be disabled?
- dijit 4y ago> systemd starts services in dependency order. The author makes it sound like systemd just randomly shuffles the services each boot for fun. Systemd has a dependency graph which you can influence, but there is no guaranteed execution order and it does change between boots. That's an acceptable thing or a bad thing depending on your use-case.
- deleted 4y ago[deleted]