flatpacks falling flat, packing bugs, snaps snapping resources, both suck
flatpacks falling flat, packing bugs, snaps snapping resources, both suck
Posted Mar 15, 2025 1:41 UTC (Sat) by andrejp (guest, #47396)Parent article: Fedora discusses Flatpak priorities
The claim that it's somehow "safer" is also false. Want to sandbox the app? Sandbox it in the system, not in the package.
The very reason linux chose centralized distribution of software ("distros") is that the app software is separate from the dependencies. Ergo if a dependency breaks or has security issues, upgrading the dependencies in the system can fix it. Meaning a distro can fix issues that the app devs either can't or won't, and distros need not wait for upstream to update dependencies in the package, which they might - or might not - after and if they release a new version. Doing so mid-cycle is unlikely as it means more work for them. And until they do, the app is broken/vulnerable, together with the system that the app is installed on - it's a pretty obvious vector of attack, same as it is on wintendo.
Hence a centralized repo is *safer* than an app packaging all the dependencies. It's the very reason *why* distros even exist and *why* distros don't (didn't) want users to install apps together with all the dependencies in a single package. It's also part of the reason *why* linux distros are (were) much more secure than wintendo app distribution.
But now I read how "flatpacks" and "snaps" are somehow better. Better how? What security are you talking about? If an app needs to interoperate with the rest of the system, don't sandbox it. Doing it anyway will probably break it in subtle ways. And if an app requires sandboxing, do it in the *system*, not the package. Why are you even relying on 3rd party package and packager to do it right? They might not even have the skill to do it, or the will, or the resources. They might not even care, or they might break it intentionally. It's stupid beyond explanation, yet y'all are telling me that it's somehow "more secure"?
And don't force multiple copies of packages on the system. Flatpacks and snaps are fscking abominations on the system. Run "snap list --all" and there's two copies of *everything*. Just in case a user might want to... what? Uninstall the last version and install/use the previous one? 'Cause otherwise she can't do that? GTFO. Run "mount" and there's tens of mounts, to the point that the output is basically useless unless what you want to see is the list of installed abominations. Same for df, with systemT ('T' as in "trash") polluting 'df' output with "credentials" and what not. How are "credentials" a fscking block device? And if they're not, why the fsck are they polluting df space to where it's about as useful as "mount" - which is not at all?
I'd uninstall Lennart if I could, together will all the flatfootedpacks and snaps that I'd happily snap a big fat stick on beating them off the system. Heck I'd snap as many sticks as it would take to where not one "snap" or "flatpack" remains. Alas, most - if not all "distros" (as in short for "centralized software distribution repository") these days seem to prefer the wintendo way. Which makes the purpose of these distros even existing questionable. What do you need a "distro" for if every 3rd party package copies half the system with it as bundled dependencies? Multiple times?
