14 ms·
Snaps. Why? Please Stop
- beretguy 3y agoMy concern is that a lot of laptops come with soldered in, non replaceable hard drives and all these sandboxed programs take up a lot of space. So if you buy cheap laptop with 256GB storage and start installing snap/flatpak/appimage eventually you’ll run out of disk storage and won’t be able to upgrade it (storage, that is). And the only solution is to buy upgradable laptop or a laptop with a lot of storage upfront. That’s just one of the things that is messed up and annoys me.
- microtonal 3y agoIt’s fine. I don’t know about Snap, but Flatpack uses shared runtimes. Sure, there is also vendoring, but sharing takes a lot of dependencies out already. This model has been used on phones and Macs for ages, and for most people it’s not an issue. Photos, videos, and game assets are taking up all the space.
- michaelt 3y agoSnap retains multiple versions of each package, following a setting called "refresh.retain" which defaults to 3. Install Blender? That's 3x 323MB. Chromium? 3x 158MB Firefox? 3x 242MB And don't think you're going to get away with just 3 copies of a snap like 'core' or 'gnome' - you're getting three copies of core18 and three copies of core20 and three copies of core22 and three copies of gnome-3-28-1804 and three copies of gnome-3-38-2004 and three copies of gnome-42-2204. At 497MB each. You might think you could avoid that by reducing the setting to 1, but you're not thinking like the creators of snap - they've decided the minimum value of refresh.retain is 2.
- FirmwareBurner 3y ago>is that a lot of laptops come with soldered in, non replaceable hard drives Other than Apples, which are those "a lot of laptops" that come with soldered storage?
- mike_d 3y agoNew Dells are using fixed storage: https://www.youtube.com/watch?v=BPBk9sIK-PQ https://www.youtube.com/watch?v=BPBk9sIK-PQ Most (all?) Chromebooks use eMMC storage attached to the board. Even laptops with M.2 connectors still require a hundred screws, guitar picks, heat guns, and other insane things to "replace" storage.
- FirmwareBurner 3y ago>New Dells are using fixed storage Meh, that's just one model out of dozens form one of a dozen manufacturers. Hardly conclusive to validate the "a lot of laptops" claim. I'm sure someone else in the comments will point out some other obscure laptop from Acer or Lenovo that's thinner than a razor blade and has soldered storage. Fine, but still not "a lot of laptops". Just don't buy those 3 models in the world that solder their storage and you'll be fine. >Most (all?) Chromebooks use eMMC storage attached to the board. Thanks but Chromebooks are just ChromeOS devices akin to your tablet or phone, not actual laptops, nor do I buy garbage laptops with eMMC, nor would I know where to find one even if I did want to buy a laptop with eMMC since I haven't seen one for sale since the Asus EEPC from 2011, so no issue there. >Even laptops with M.2 connectors still require a hundred screws, guitar picks, heat guns, and other insane things to "replace" storage. That's a gross overexaggeration. I fiddled with the innards of several models of laptops from several brands and all of them are easy to replace the M.2 SSDs without special fancy tools and pain, just a screwdriver. Only Microsoft glues their machine together but nobody buys them anyway so don't you do it either and you'll be fine. Conclusion: Myth busted. Most laptops on the market DON'T have soldered storage, and they're also quite easy to replace. Keep calm and carry on.
- justsomehnguy 3y ago> nor would I know where to find one Surface Go is available in eMMC version. https://www.youtube.com/watch?v=dpkT8JwgnAI https://www.youtube.com/watch?v=dpkT8JwgnAI https://www.amazon.com/s?k=laptop+emmc https://www.amazon.com/s?k=laptop+emmc Basically anything under $700 has a chance to be an eMMC laptop. Most? Nope. Many? Yes, especially cheap and not so cheap ones.
- sshine 3y agoYou’re a company and your software actually runs on Linux. You want to reach as many people as possible. So you make a .deb for Ubuntu. Or you go with a package manager that is cross-distro. That’s why.
- tryauuum 3y agoehhhh.... If I want to reach as many people as possible I would build rpm, deb, docker images, provide source code. I would not use snaps because it would imply more effort from the end user -- they first need to install snapd and only then my app.
- loxias 3y agoYup. This is what's true in my experience (working for companies that sell software that runs on linux distributions). I don't have any gross snaps or unpackaged stuff on my laptop, how could I expect paying customers, with an operations department, to accept anything less.
- sshine 3y ago> they first need to install snapd and only then my app This is a reductive argument. It's not more effort if Snap is already included in the Linux distribution. This argument only applies if Snap is your only distribution channel. Otherwise, you could say that distributing a Linux version of the software implies more effort from the user, because they'd need to install Linux first. We're talking alternatives here.
- HunOL 3y ago> Or you go with a package manager that is cross-distro. > That’s why. So flatpak?
- Alupis 3y agoWell, flatpack still doesn't address the non-gui app/utility part of the equation.
- DiabloD3 3y agoI won't use Snaps. Please stop trying to work around my chosen distro's package maintainers. If I want to use your program and there isn't a package for it, I'll build it from source myself.
- creatonez 3y ago> Please stop trying to work around my chosen distro's package maintainers. Is your chosen distro Ubuntu?
- DiabloD3 3y agoHa ha, don't insult me. I am a Debian user since 1999.
- ratsmack 3y agoHear! hear!... and I will stick with Debian as long as the do not embrace said OS blasphemy.
- xcrunner529 3y agoPlease stop trying to work around the application developers and relying on unaffiliated volunteers for keeping apps updated and secure.
- Aerbil313 3y agoPlease stop trying to put the burden of packaging their software for every platform on application developers. Instead just use nix.
- kazinator 3y agoThe same argumentation applies to npm, cargo, pip, ... Also app auto updates, browser extensions, ...
- tentacleuno 3y agoRe: NPM, how does that work? Do you manually unpack tarballs? I believe some distributions package popular NPM modules, but certainly not all of them -- not using npm doesn't really seem feasible. (Not to mention that, in the case of pnpm at least, everything's installed into a store directory in your HOME. Seems fine to me.)
- loloquwowndueo 3y agoOther than the clickbaity title, the second paragraph begins “ Traditional package managers are perfect” - which is untrue. Then the post ends “ Educate me.” - such a “change my mind” attitude seems rather trollish. I dislike snaps as much as the next person but I wonder if we do need another discussion about it.
- wilkystyle 3y ago> Then the post ends “ Educate me.” - such a “change my mind” attitude seems rather trollish. And later responses by the OP of that thread further convince me that this was not a question asked in earnest.
- dschuetz 3y agoWhy? Because of Dependency Hell. Apt sometimes even tries to solve "circular dependencies". Ridiculous.
- smallerfish 3y agoI haven't run into dependency hell in 15 years of using deb on Ubuntu.
- jacquesm 3y agoLucky you.
- loxias 3y agoI haven't had problems with dependency hell since the early 2000s. And even then, looking back, I'm entirely sure the problem was not in myself. You're possibly using it wrong.
- dschuetz 3y agohttps://en.wikipedia.org/wiki/Dependency_hell https://en.wikipedia.org/wiki/Dependency_hell Seems like I am not alone. If the problem does not affect you much, does not mean it does not exist. Yeah, the usual "works for me" attitude has had never helped anyone. So, good for you.
- jandrese 3y agoDependency issues usually only appear on Ubuntu when you start adding third party repos, especially for software that has a version in the main repo. If you stick to the main repo you will basically never have them.
- MrDresden 3y agoHave plenty of PPAs on my system but also make sure to do propper pinning. Haven't had any major dependency related issue in years.
- gumballindie 3y agoLinux doesnt force either upon you. Life is good. We are free.
- felixhammerl 3y agoThere are so many half baked takes, but this is my favorite: > There will always be a market for stable-over-latest software, especially for businesses. That market is called the nvd.nist.gov at best and 0 day brokers at worst. Why do people stil not accept the fix forward supremacy and patch their mess?
- yjftsjthsd-h 3y agoBecause people aren't fond of things randomly breaking or forcing reconfiguration in order to get their security patches.
- tryauuum 3y agoseriously, I don't understand why would any linux user use them. If I need some bleeding edge software I would install it through docker
- ssl232 3y ago> If I need some bleeding edge software I would install it through docker Or if you use Arch, just install it using pacman or the AUR.
- IshKebab 3y ago> Sure, Snaps make it easy to install 3rd party software, but I just find this problematic, causing fragmentation, and just all around a bad idea. He knows the answer, he just doesn't like it for stupid ideological reasons.
- yjftsjthsd-h 3y agoFor reasons, yes, perhaps even ideological reasons, but if you're going to call them stupid you should at least try to give a reason.
- IshKebab 3y agoI would have thought it's obvious, but it's clearly stupid to expect all software vendors to package their software for every distro in existence. That's just not a realistic way to distribute software.
- fragmede 3y ago(2019)
- kalekold 3y agoI use Ubuntu and i'm sick of having snaps forced on me. When I next install, i'm either completely ridding the system of snap or i use another distro. I'm fed up with it. The kicker is sometimes when you use apt to install a package, sometimes it installs a snap! It's madness!
- jstanley 3y agoI recommend Pop!_OS (despite the stupid name). It is basically Ubuntu without the annoying bits.
- mikeywazowski 3y agoPop!_OS is good, but going from Ubuntu to Pop!_OS doesn't really help with the Snaps issue.
- patch_cable 3y agoDoes it not? Pop!_OS uses Flatpak, I believe.
- tehbeard 3y agoUnless I purposely removed it and blanked the memory of it, Pop just deals in deb's and flatpak. Not that I'm entirely jazzed with flatpak.. Poor construction of the permissions can lead to shitty experience that doesn't happen with a deb.
- fgonzag 3y agoAre you sure about that? AFAIK both mint and pop completely purge the base distro of snaps
- MrDresden 3y agoWhat are the programs that you've had to install through snap? Or are you talking about the existence of snap on the system in general? Personally I have not a single snap packge installed, and am usually able to find sources for the programs I use elswhere than in the snap ecosystem.
- TheChaplain 3y agoI think what really put me off when it comes to Snap was when I wanted to use a yubikey with Firefox, but Snap tries it hardest to make it difficult to add a pkcs11 device.
- new_user_final 3y agoI don't hate Snap. I am glad that Snap exists. But docker install using Snap sucks.
- baggy_trough 3y agoSnaps are one of the two main reasons I'm ditching Ubuntu for basic Debian. The other is apt spam berating me to upgrade to their pay security service.
- theshrike79 3y agoSame here, and the fact that it's way too easy to get in "you can't upgrade" -limbo with Ubuntu on servers I haven't touched for a while. Went back to Debian stable and zero issues.
- theshrike79 3y agoSame here, and the fact that it's way too easy to get in "you can't upgrade" -limbo with Ubuntu on servers I haven't touched for a while. Went back to Debian stable and zero issues. The main reason I went to Ubuntu was that stable Debian used to be veritably ancient. But nowadays I run most of my software in Docker anyway, so it doesn't matter.
- drpixie 3y agoI now routinely install fake-ubuntu-advantage-tools.deb to remove Ubuntu "Advantage". It's an empty package that satisfies the dependencies. I also remove some of the crap that Ubuntu put in /etc/update-motd.d. From memory 10-help-text, 50-motd-news, 88-esm-announce, 91-contract-ua-esm-status are pointless and annoying. See https://github.com/Skyedra/UnspamifyUbuntu https://github.com/Skyedra/UnspamifyUbuntu
- apitman 3y agoPackage managers are not a sustainable solution to application distribution. It puts way too much on package maintainers, which is a thankless job. Whether or not you like Flatpaks, Snaps, etc, it's clear that we need some sort of cross distro (and preferably cross platform) application format that's simple for developers to target. Personally I ship static executables, but that doesn't work for GUI apps.
- xet7 3y agoGodot can save GUI app to static executeable, mobile and web.
- apitman 3y agoDo you have a link to instructions on how to do this? I don't think I've ever seen a GUI app on Linux that wasn't dynamically linked to X11 or Wayland.
- mid-kid 3y agoI think having a standard way to specify exact program dependencies (not package names, but e.g. pkgconfig files, command binaries, deps for specific languages, etc, so they can be translated back to the package name for each distro), as well as allow packagers to check for updates, would go a long way in easing sustainability. We already have other metadata covered by metainfo.xml files. Packaging software is almost automatic these days. If the program uses the standard build system for their language, and the language's build system cooperates with the way of linux (e.g. C, C++, python, perl, ...), packaging software is as easy as telling the package manager what build system to use and giving it a download URL. I figure that if we manage to have some standard like that, you could easily have a set of docker containers build your program for every major distro and publish it in a repository, without much distro-specific fuss. Of course, flatpak is probably better if publishing to all distros is your specific goal, but it'd make the life of distribution developers significantly easier. My biggest fear with regards to flatpak is that people will use it as an excuse to create bespoke and broken build systems that only work on a very specific system, patch all their libraries or require very specific git versions that cannot easily be updated, or etc etc. I've already seen this happen with a few flatpak apps I've tried to package.
- popey 3y agoThis is a four year old thread.
- kkfx 3y agoWhy? Simple: because commercial sw want them, they need something they can made at home without giving ANYTHING to the community, ESPECIALLY if the software is crap, as 99% of commercial sw are, to avoid being depicted for what they are: vendor of crapware. Why all such systems state they add security while they do the contrary? Because they demand to the upstream handling all deps, witch means that a generic student who have write a simple chat client need to take care of new releases of SSL who he/she do not even know much because that's just a deps of some wrapper he/she use. They state "but they are isolated", true, but they need to punch holes here and there because your snappyfied firefox need to download files, let's say pdfs, your external reader can read and so on. That's just playing the Windows game not knowing it and refusing to know what a modern FLOSS system should be, like Guix or Nix. Unfortunately most FLOSS devs see commercial software and try to mimic it without understanding that ideas behind it might be also technical but in general they are economical, and to support a business model they accept technical crap. Much FLOSS devs fails to understand that FLOSS model is superior IF done the FLOSS way, inferior if it try to mimic some other models not knowing why. If only people knew the past, the classic desktop OS with the OS as a single application where anything is just a bit of added code in the hand also of the end users, no commercial software today would be able to compete. But most do not even know the past, do not even know that some modern tech was invented in the past in better ways than today and do not understand that the Conway's law is more generic than it appear, goes beyond Lisp and have a generally valid meaning in paradigmatic terms.
- lxe 3y agoCan confirm, snap / flatpack / appimage has been nothing but slow bulky disjoint nightmare.
- apatheticonion 3y agoIgnoring Snaps - what are Flatpaks like today? Totally understand the value in a distribution model like Flatpaks and am willing to adopt them but I haven't had the smoothest experience with them in the past so I tend to avoid them right now. The last time I tried them was longer than 12 months ago - I installed Discord and it was missing some features at the time due to sandboxing (I don't remember exactly, it was either push-to-talk, hot-mic, or showing what game you were playing that didn't work). I also had some other issues with other Flatpaks - I think there were theming issues. How is it today? Can I install VSCode, Chrome, VLC, Steam, Discord as flatpaks and have no idea they are Flatpaks?
- schmorptron 3y agoIn my experience you'll sadly still run into issues when running apps that weren't designed by the original authors to be used as flatpaks due to the permission issues you mentioned. I see it as a necessary evil since a proper permissions system will make the attack surface for desktop apps much smaller in the long run, and the flatpak portals have the advantage of being much more visible and controllable by ordinary users than AppArmor or selinux (if there were even profiles) before them.
- addicted 3y agoI’ve found using FlatSeal eliminates my issues with flatpak. And that’s despite me running flatpak on an Ubuntu install which I try hard to de-snap (yeah, I should switch to another distro but I’ve been using Ubuntu off and on for 2 decades and old habits die hard). That being said I don’t see FlatSeal as a solution to the permission issues but merely a bandaid until a proper first citizen solution is developed by flatpak.
- notnullorvoid 3y agoI used to have issues with Steam flatpak, but it's been 2-3 years now without any issues. Discord also works, it doesn't support some features, but that has nothing to do with flatpak and everything to do with Discord on Linux in general. I've got a dozen or so other flatpak apps that work flawlessly. One major complaint though is it can keep old unused versions of runtimes around and you manually have to remove them, Nvidia and Mesa runtimes for some reason consistently have this issue. Even running `flatpak uninstall --unused` does not remove them.
- xet7 3y agoThis is discussion at 2019-2021. There are many distros where snapd is not installed by default, including Linux Mint: https://snapcraft.io/docs/installing-snapd https://snapcraft.io/docs/installing-snapd Nobody is forcing you to use distro that includes snapd by default. Snap has advantages for server software that are using Snap strict sandbox: - Strict sandbox does not allow read access outside of /var/snap/APPNAME/common . Only common directory is writeable. - Snap code at /snap/APPNAME is read-only and can not be modified - When new version is released, for example with security fixes, it is automatically updated worldwide, keeping servers secure. Linux Mint has MintUpdate, that has options to enable automatic update of .deb and FlatPak packages, keeping everything up-to-date and secure without any clicking. Windows and Mac does not have that, you need hundreds of clicks to update each software separately, having many apps still vulnerable.
- belval 3y agoI have ~8 self-hosted services with docker-compose and one with snap (nextcloud). While I get that snap gets some flak for how cavalier it can be with your system, ultimately my nextcloud is always up to date and I've had very little effort to put into it in over 7-8 years, which is not something I can say from my running docker containers. It might not be for everyone, but from a security standpoint it's much less fussy than basically everything else that I've tried.
- tapoxi 3y agoWhy not just write something (or use a pre-existing tool) to update your docker containers? I know on Kubernetes there's plenty of tooling around Helm.
- XorNot 3y agoI redid my docker stuff with podman and quadlet recently and it's been great. Quadlet turns the containers into behaving like regular systemd services (i.e. you can trigger them with timers), and "auto update" is just setting Pull=true when the container re-runs (there's a heck of a lot of good reasons to also not do this).
- TriangleEdge 3y agoI feel like this xkcd perfectly encapsulates Snaps: https://xkcd.com/927/ https://xkcd.com/927/
- hurryer 3y agoSnaps move the packaging burden from the distribution to the software maker, which is how it should be. It's the only scalable way. Imagine Microsoft having to package the millions of distinct Windows applications.
- PlutoIsAPlanet 3y agoBut they also move the gatekeeper from the distribution to Canonical, and only Canonical (sideloading does not count when the repo is hard coded and server is closed source).
- idontknowwhynot 3y agosnaps is starting to give me a headache. I installed chromium in my ubuntu and it installed it as a snap (even through apt, it just a transitional package that installs the snap.), and for some reason it has a dependency with cups (printing software). Every time i delete cups it is reinstalled..again and again, i couldn't find any solution.
- mike_hock 3y ago> i couldn't find any solution Ditch Ubuntu.
- pvaldes 3y ago'hold package' option may help. Dunno if is implemented in Ubuntu, but you could take a look
- deleted 3y ago[deleted]
- throw555chip 3y agoFollow the instructions here, works for me: https://gist.github.com/lmmx/0550cfc8867eb1eea04076ec69c95a5a https://gist.github.com/lmmx/0550cfc8867eb1eea04076ec69c95a5... Although cups has a hardwired dependency on libsnapd-glib1 so you can't remove that library, but the nosnap.pref file will prevent snapd from ever being installed again.
- dark-star 3y agoThe thing I hate most about snaps is how they pollute the mount namespace with loop mounts. Install a few apps and 2/3rds of your `mount` output will be /dev/loopX devices. Especially annoying since I often do loop-mounts myself and picking them out from the flood of unrelated snaps is a pain. If they could somehow hide the mounts (in a different mount namespace maybe?) that would be cool. I mean still, I would prefer more open formats such as flatpack and appimage (since with snaps you buy into the Canonical ecosystem with no way to provide alternative appstores) ......
- hackeraccount 3y agoI think that's why I gravitated to Flatpak instead of Snap. That and maybe the store experience - flathub.org - was better.
- jcrben 3y agoYou can pass a flag to the commands to hide them.
- Aerbil313 3y agoI just jumped the ship to Nix.
- HumanOstrich 3y agoYou should rewrite everything in Rust too.
- Aerbil313 3y agoNot a bad idea if I could.
- otabdeveloper4 3y agoNix is the "worse is better" approach, it's just symlinks and environment variables and bash scripts under the hood. (Not even a single container in sight!)
- Tanoc 3y agoOne of the experiences that formed my hatred of Snap was when trying to install Notepad++ while trying to find a worthwhile editor to migrate to. Running via WINE it was 20.6MB installed, and even WINE itself was 1.2GB, but that 1.2GB was shared by other programs. On one machine due to package conflicts preventing an appropriate Mono install and laziness in sorting my multitude of prefixes I couldn't get Notepad++ to run via WINE and had to install it via Snap. The Snap install of Notepad++ took up 1.3GB all by itself. On a 32GB drive. It hasn't gotten any better in the five years since for total Snap install sizes, because with the way they work they often install every single dependency siloed. Imagine if you had to install a new instance of DirectX12 for every game you had, or install a new instance of Python 3.12 every time you wanted to set up Tensorflow. Firefox when installed via apt is currently 63MB and its total size after being run and configured with things like session data and add-ons is 243MB. If I install via Snap its somewhere around 190MB in size and when actually run and configured jumps up to around 550MB for reasons I don't understand. And that's not even including the /var/ spam which actually managed to fill both the 32GB drive and a later replacement 80GB drive to the point where Linux had 0KB of free space. It happened so often I copied a shell script just to clean /var/ and edited it to run every twelve hours, like cleaning calcium buildup out of a fountain pump before it clogs.
- beretguy 3y agoOpenTyrian game natively is something like maybe 7MB, but a Snap version is more than 1GB.
- Thoreandan 3y agoHear hear. It's really inexcusable — if there's a bug in a shared library, that library should be fixed across the board. That, and the implementation is cartoonishly bad, for example you can't extend a partition while the system is running the way that you could before, because you've got random read-only file systems mounted over root. If the money spent on the salaries of the CADT developers making this were spent on the Debian package maintenance, many problems would vanish.
- phkahler 3y agoAFAICT snaps and flat packs are a way to push package management upstream. That might not have been bad if there weren't more than one such thing to support.
- calamari4065 3y agoThe last time I used Ubuntu, I ended up installing either bitwarden or discord through snap. Some electron app anyway. My system logs bloated into the gigabytes with constant errors about some snap or other having faulty security settings. Absolutely no user-facing indication of any type that there's an error, just endless log messages. I use Arch now. It's still just as miserable, but at least my problems are my own fault this time.
- eternityforest 3y agoSnaps were one of the main reasons I moved from Mint to Ubuntu. Traditional package management is a terrible fit for modern systems and apps. If you have dozens of apps and they each have dozens of dynamically linked dependencies, you'll probably get an occasional compatibility issue. At first I really liked Flatpak, but the ecosystem isn't there. Everything I use is in Snapcraft, with Flatpak I still would occasionally have to hand install something or add a custom deb repo. My only real complaint is the proprietary backend. It doesn't directly affect me much, since it's not like I'd want to use an alternate store when the official one has everything, but it does get in the way of adoption without seeming to benefit canonical that much. Companies are way too afraid of FOSS competitors, they forget how much users like convenience and standardization and sticking with stock settings.
- the_third_wave 3y agoIn my experience - using Linux since 1992, Debian since 1997 - "traditional" package management is quite capable at avoiding compatibility issues related to dynamically linked dependencies. Linux has had library versioning for a very long time - something which made it stand out compared to the 'DLL Hell' Windows users were used to - and it is quite common to have multiple versions of libraries installed and in use. Given these conditions I do not consider package management a "terrible fit" for "modern systems and apps" - whatever those might be. I do see a use for systems like AppImage which come in handy for applications which are only used occasionally (or even only once) where the increased start-up time and reduced integration do not matter.
- eternityforest 3y agoIt does seem to work 99.9% of the time, but when you have a dozen programs with more dependencies than you can count, some are not in the official repos, and you want more up to date stuff, being able to reproduce the whole environment of a package seems like the best option to me. Deb packages are rock solid for the most part if you use standard distro packages, but the moment you want something newer or third party, there's no guarantee it will work well with some other random third party thing you also have. Especially when sometimes apps might even depend on bugs and break when they get fixed. Snaps mostly solve the reduced integration issues(Or at least try to, some stuff isn't perfect yet?) with all their plugs and interfaces and whatnot.
- 28304283409234 3y agoI had Debian installed. Wanted LXC and LXD. And it brought snapd with it. Immediately my server went from a load of 0.3 to 2.5+. Continuously for months. Snapd always in the top cpu. No idea why or what it did. I finally caved and gave up on LXC. Removed it and snapd. Load immediately dropped to 0.5 again. I. Hate. Snapd.