5 ms·
that's a silver lining the anti-user attestation will at least be full of security holes, and likely won't work at all
by blibble 8mo ago
that's a silver lining
the anti-user attestation will at least be full of security holes, and likely won't work at all
- sam_lowry_ 8mo agoDunno about the others but Pottering has proven himself to deliver software against the grain.
- deleted 8mo ago[deleted]
- dijit 8mo agoYou think? It took us nearly a decade and a half to unfuck the pulseaudio situation and finally arrive at a simple solution (pipewire). SystemD has a lot more people refining it down but a clean (under the hood) implementation probably won't be witnessed in my lifetime.
- blibble 8mo agoyeah, the fix for pulseaudio was to throw it away entirely for systemd, I don't think I have a single linux system that boots/reboots reliably 100% of the time these days
- dijit 8mo agoThe trick is the same: use a popular linux distribution and don't fight the kinks. The people who had no issues with Pulseaudio; used a mainstream distribution. Those distributions did the heavy lifting of making sure stuff fit together in a cohesive way. SystemD is very opinionated, so you'd assume it wouldn't have the same results, but it does.. if you use a popular distro then they've done a lot of the hard work that makes systemd function smooth. I was today years old when I realised this is true for both bits of poetter-ware. Weird.
- blibble 8mo agoI only use debian pulseaudio I had to fight every single day, with my "exotic" setup of one set of speakers and a headset with pipewire, I've never had to even touch it systemd: yesterday I had a network service on one machine not start up because the IP it was trying to bind to wasn't available yet the dependencies for the .service file didn't/can't express the networking semantics correctly this isn't some hacked up .service file I made, it's that from an extremely popular package from a very popular distro (yeah I know, use a socket activated service......... more tight coupling to the garbage software) the day before that I had a service fail to start because the wall clock was shifted by systemd-timesyncd during startup, and then the startup timeout fired because the clock advanced more than the timeout then the week before that I had a load of stuff start before the time was synced, because chrony has some weird interactions with time-sync.target it's literally a new random problem every other boot because of this non-deterministic startup, which was never a problem with traditional init or /etc/rc for what? to save maybe a second of boot time if the distro maintainers don't understand the systemd dependency model after a decade then it's unfit for purpose
- jacquesm 8mo agoI can totally relate to this, it's gotten to the point that I'm just as scared of rebooting my Linux boxes as I was of rebooting my windows machine a couple of decades ago. And quite probably more scared.
- blibble 8mo agoeveryone attacking Microslop for a bug where Windows won't shut down properly well, systemd's got them beat there!
- direwolf20 8mo agoThe good thing about systemd or any other Linux software is that you don't have to use it, until this company gets off the ground.
- xorcist 8mo agoThere were dozens of other init systems that, like systemd, wasn't a shell script. What set systemd apart is the collection of tightly integrated utilities such as a dns resolver, sntp client, core dump handler, rpc-like api linking to complex libraries in the hot path and so on and so forth that has been a constant stream of security exploits for over a decade now. This is a case where the critics were proven to be right. Complexity increases the cognitive burden.
- jacquesm 8mo agoAs predicted. I thought pulseaudio should have been enough of a lesson. Besides that, any person that works on open source but that joins Microsoft is not in the camp that should have a say in the overall direction of Linux.
- bulatb 8mo ago"People don't learn lessons" is a lesson that people don't learn.
- sam_lowry_ 8mo agoWhat set systemd apart was RedHat, and now Pottering repeats the old trick with Microsoft behind his back. I think he will succeed and we will be worse off, collectively.
- PunchyHamster 8mo agothat on itself is not a problem. The problem is that those work worse. For example, the part of systemd that fills DNS will put them in random order (like actual random, not "code happened to dump it in map order) The previous, while very much NOT perfect, system, put the DNSes in order of one in latest interface, which had useful side-feature that if your VPN had different set of DNSes, it got added in front The systemd one just randomizes it ( https://github.com/systemd/systemd/issues/27543 https://github.com/systemd/systemd/issues/27543 ) which means that using standard openvpn wrapper script for it will need to be reran sometimes few times to "roll" the right address, I pretty much have to run systemctl restart systemd-resolved ; sleep 1 ; cat /etc/resolv.conf half of the time I connect to company's VPN The OTHER problem is pervasive NIH in codebase. Like, they decided to use binary log format. Okay, I can see advantages, it can be indexed or sharded for faster access to app's files... oh wait it isn't, if you want to get last few lines of a service the worst case is "mmap every single journal file for hundreds of MBs of reads" It can be optimized so some long but constant fields like bootid are not repeated... oh wait it doesn't do that either, is massively verbose. I guess I can understand it, at least that would make it less crash-proof... oh wait no, after crash it just spams logs that previous log file is corrupted and it won't be used. So we have a log format that only systemd tools can read, takes few times as much space per line as text or even JSON version would, and it still craps out on unclean shutdown They could've just integrated SQLite. Hell I literally made a lil prototype that took journalctl logs and wrote it to indexed SQLite file and it was not only faster but smaller (as there is no need to write bootid with each line, and log lines can be sharded or indexed so lookup is faster). But nah, Mr. Poettering always wanted to make a binary log format so he did.
- PaulDavisThe1st 8mo agoanyone who thinks that pipewire - pipewire! - is "a simple solution" understands nothing about pipewire. don't get me wrong, i use pipewire all day every day, and wrote one of the APIs (JACK) that it implements (pretty well, too!). but pipewire is an order of magnitude more complex than pulseaudio.
- deleted 8mo ago[deleted]
- herewulf 8mo agoAs an end user hand assembling desktop services on non-Systemd distros (Artix, Devuan, Gentoo, Guix) over the years, and thus had no concern about APIs, Pipewire just works and PulseAudio gave endless trouble. My 0.02 bits.
- account42 8mo agoAs another user on Gentoo, pipewire is a never ending pain in the ass full of "magic" behavior and weird bugs. I mostly skipped pulse though so it may be simple in comparison to that.
- deleted 8mo ago[deleted]
- mariusor 8mo agoIt's baffling to me that anyone can imagine pipewire has been created from scratch without any lessons learned from pulseaudio and the previous issues the audio stack on linux had, and solved, over the years. Nothing is happening in a clean room bubble, every new project stands on the shoulders of giants...
- wang_li 8mo agoI thought he had proven that he leaves before the project is complete and functioning according to all the promises made.
- nacozarina 8mo agoLP is the Thomas Midgley Jr of Computer Science.
- mikkupikku 8mo agoPoettering gas a track record of recognizing good ideas from Apple, then implementing them poorly. He also has a track record of closing bug reports for plain and simple bugs in his software to protect his own ego, and this kind of mentality isn't a great basis for security sensitive software. Audio server for linux: Great idea! Pulseaudio: Genuinely a terrible implementation of it, Pipewire is a drop in replacement that actually works. Launchd but for Linux: Great idea! SystemD: generally works now at least, but packed with insane defaults and every time this is brought up with the devs they say its the distro packagers jobs to wipe SystemD's ass and clean up the mess before users see it. Security bug in SystemD when the user has a digit in their username: Lennart closes the bug and says that SystemD is perfect, the distros erred by permitting such usernames. Insane ego-driven response.
- plagiarist 8mo agoHe really will just close a ticket because he disagrees with how Linux works. I read about systemd sysusers and thought they would be neat for running containerized services. But Poettering doesn't like the /etc/subuid files and refuses to work with them.
- NekkoDroid 8mo agoWell, he specifically doens't like the static allocation of subuids. There is a reason `systemd-nsresourced` exists.
- plagiarist 8mo agoHow do I have nsresourced work in a regular systemd service or quadlet so that I can have an ephemeral user run a container? I am trying to find information and just seeing it as part of nsspawn, that seems to require a container specifically built around a root filesystem. I am not going to struggle with systemd if I have to build containers specifically for it. If I have to rearrange everything I am doing I would just learn to do it on a minimal Kubernetes install instead.
- tonoto 8mo agoagent Smith, the one that don't care at all about conforming to POSIX? "In fact, the way I see things the Linux API has been taking the role of the POSIX API and Linux is the focal point of all Free Software development. Due to that I can only recommend developers to try to hack with only Linux in mind and experience the freedom and the opportunities this offers you. So, get yourself a copy of The Linux Programming Interface, ignore everything it says about POSIX compatibility and hack away your amazing Linux software. It's quite relieving!" -- https://archive.fosdem.org/2011/interview/lennart-poettering.html https://archive.fosdem.org/2011/interview/lennart-poettering...