Introducing Fedora Atomic Desktops - Fedora Magazine (fedoramagazine.org)
from petsoi@discuss.tchncs.de to linux@lemmy.ml on 09 Feb 2024 17:14
https://discuss.tchncs.de/post/10609123

#linux

threaded - newest

brandhout@feddit.nl on 09 Feb 2024 18:26 next collapse

Kinda great! Although Guix and nixos are more my thing these days.

Pantherina@feddit.de on 09 Feb 2024 19:07 next collapse

If you are a modder that wants to do stuff like replace the kernel, add in rust coreutils etc, then I think NixOS is indeed better. Have not used it but really want to try.

Image based Distros are just perfect for people that want to have perfectly reproducible bugs, or in general not many.

It is a good community concept, but tbh a preset of shared Nix config files could do the same thing too, with ease. Just dont deviate from those configs and you will have multiple people with the same systems.

SpeakinTelnet@programming.dev on 09 Feb 2024 21:37 next collapse

Damn, rust really embrace the “Hey, Can I copy your homework?” Meme. I like rust btw, it’s just funny how often I see something along the line of “it’s like X, but in rust!”

Pantherina@feddit.de on 09 Feb 2024 22:30 collapse

I mean coreutils in a memory safe language?

Rust is the currently most adopted C replacement

dan@upvote.au on 10 Feb 2024 09:56 collapse

Rust is the currently most adopted C replacement

Where’s the data you’re using to measure that?

Pantherina@feddit.de on 10 Feb 2024 13:10 collapse

insights.stackoverflow.com/survey/2019#technology

This shows something else. The traditional languages are all more common than Rust.

I suppose Go could be a good competitor, and I read a thread comparing C=Go, C++=Rust.

I just see a lot more rust in many projects, and it is well integrated with GTK for example. I also know of several drivers and modules written in Rust.

At least in Linux, Go seems to be used for WebTech more than for other things.

I am interested in a discussion about that, as I would like to learn one of these languages, but Rust seems to have a better ecosystem with more adaption, ready GUI toolkits, a Linux Desktop, multiple GTK apps etc. in the making, while for example “Fyne”, Go GUI toolkit (that I found in the Flatpak “Rymdport”) doesnt even have Wayland support yet.

drndramrndra@lemmygrad.ml on 10 Feb 2024 14:18 collapse

This shows something else. The traditional languages are all more common than Rust.

It’s a survey from 2019, but in those rust is traditionally the favourite language nobody uses professionally.

I suppose Go could be a good competitor, and I read a thread comparing C=Go, C++=Rust.

Go’s syintax is C inspired, but it’s not made to replace it, nor do they compete in the same space.

Look at zig instead of you’re interested in that.

I am interested in a discussion about that, as I would like to learn one of these languages

Skip rust unless you have years to get good at it.

brandhout@feddit.nl on 09 Feb 2024 21:46 collapse

Exactly. The concept is great, but my Guix system (Nix fork from GNU) is already reproducible and capable of rollbacks and transactional upgrades (and declarative system configuration !)

The learning curve is quite steep tho (the Nix leaning curve is even higher, at least it used to be IMO). If the sway spin of Atomic Fedora was available earlier I probably wouldn’t have switched tbh. Both solutions are great.

Overall I’m quite happy with my Guix configuration. I’ve got roughly the same configuration on all my systems with ease, all config files (also sway for example) in the same language: Guile Scheme (LISP dialect), and the whole thing is in git. I don’t imagine going back to a regular distribution anytime soon.

Neon@lemmy.world on 10 Feb 2024 13:14 collapse

NixOS User here: what made you use Guix over NixOS?

brandhout@feddit.nl on 11 Feb 2024 23:15 collapse

Scheme is a more mature and more expressive language than Nix imo. And you can write your home configs in scheme too.

The differences aren’t that big, nix is great but I find (at least I did two years ago) the documentation a bit confusing. Both are great. I like scheme a lot better than Nix (the language), and the tooling is a bit less confusing to me.

Neon@lemmy.world on 12 Feb 2024 00:03 collapse

And you can write your home configs in scheme too

so you have your own Version of Home-Manager as well?

brandhout@feddit.nl on 12 Feb 2024 08:50 collapse

I didn’t know about home-manager, but it seems like it.

refreeze@lemmy.world on 10 Feb 2024 13:51 collapse

Agreed. I used to use Silverblue and it was very stable but did not solve all the problems that Nix addresses. Once you experience the first reinstall with NixOS you will wonder why we did things any other way. It’s amazing to just run one command and have things set up exactly how you like.

Pantherina@feddit.de on 09 Feb 2024 19:01 next collapse

I like them a lot, switched to Kinoite⏩uBlue: (Kinoite-main, -nokmods (until that got silently dropped), -main again; 37-39)⏩Secureblue kinoite-laptop-userns

The biggest Problem is that Fedoras Images are not usable.

  • Filemanager movie thumbnails dont work
  • Flatpak browsers are not feature-complete and probably not secure (because they can’t create usernamespace-isolated processes for tabs)
  • they have no NVIDIA support
  • powerusers will miss ffmpeg

The idea of immutable images is, to have a base that most people dont need to change. You can, but the moment you add NVIDIA proprietary drivers or full ffmpeg, you are in unprotected territory again.

So I like the Distros for their reproducible bugs and future possibility to be a very secure base (you could just verify the hash of the root system to check for viruses). But they cannot be produced in the US.

Fedora is nice but just like with rpmfusion, ublue is the key part that makes it work. And on immutable images this cannot just be added in a welcome dialog, as you need massive overrides by default.

GravitySpoiled@lemmy.ml on 09 Feb 2024 19:47 collapse

I can’t find an open issue regarding security with flatpaks on librewolf codeberg.org/librewolf/issues/issues it would be nice if you could open one such that it may get adressed.

Just install ffmpeg in a distrobox or layer it if you desire

There’s at least Fedora atomic with nvidia github.com/ublue-os/nvidia

Filemanager thumbnails - I usually don’t use big icons (or thumbnails) hence, I don’t remember it too well but that should depend on the file manager, right? And aren’t there tools for thumbnail creation in case they are missing? (I remember something from my time when I used arch)

Pantherina@feddit.de on 09 Feb 2024 22:35 next collapse

You cant layer ffmpeg, you need to override-remove everything libav and then install everything new from rpmfusion. I did that, its a mess.

If you just want video playback thats just libavcodec-freeworld, thats why I specifically mentioned ffmpeg.

I am not a fan of Distrobox for small tools. For sure possible but unnecessary and the workflow is a pain. And trust me, I use it daily and even ran libvirt in a rootful one, virt-manager in a rootless one, connected over ssh.

There’s at least Fedora atomic with nvidia github.com/ublue-os/nvidia

My point was that Fedoras product is unusable. Ublue is the solution, their main images are basically Fedora Atomic but fixed.

that should depend on the file manager, right?

No thats libavcodec-freeworld and ffmpegthumbs. Most movies you find on the open sea are not in libre Codecs.

Pantherina@feddit.de on 09 Feb 2024 22:42 collapse

And the Flatpak browser thing is complicated.

Chromium uses namespaces. Nowadays unprivileged user namespaces, but the legacy suid namespaces are still integrated.

If you want to run Chromium (and I think all Electron apps too) as Flatpak, you replace those namespaces with zypak, which instead isolates processes using flatpak and its seccomp filters.

These are the seccomp filters for every app though, so they are probably way too unrestricted. Also it has a small performance hit.

That is the reason why no Chromium Browser Flatpak is official.

Now the thing with Firefox is, I have no idea what isolation they use. Everyone says its less secure. And they adopted Flatpak as if it was nothing, without any comment on that topic.

The issue is that Flatpak uses a single seccomp filter for bubblewrap, that is used by every app. But browsers would need a different one, with just the added permission to create user namespaces.

Currently this is not even possible when using a seperate repo. Really, no idea. Bubblejail is an alternative with custom seccomp filters and usernamespace permission. But it is very different, uses system packages and is very alpha.

Pantherina@feddit.de on 09 Feb 2024 19:04 next collapse

Btw, uBlue List of aweome custom Images

randomaside@lemmy.dbzer0.com on 09 Feb 2024 23:17 next collapse

I just want to drop this here

projectbluefin.io

Jorge Castro has been the head of this project and I am excited by his vision. Bluefin aims to be the immutable desktop distro with the most sane defaults that also supports Nvidia.

Give it a whirl!

mmhmm@lemmy.ml on 10 Feb 2024 00:21 collapse

Looks cool but like so fucking weird they gendered an os

Happybara@lemmy.world on 10 Feb 2024 09:01 next collapse

It’s a mascot for brand recognition purposes, just like Tux the penguin. I don’t quite understand what the problem is. I feel like if I were to call anything about it weird, it would be the use of a derpy, chonky dinosaur rather than the gender of said derpasaurus.

FutileRecipe@lemmy.world on 10 Feb 2024 11:09 collapse

if I were to call anything about it weird, it would be the use of a derpy, chonky dinosaur

Bluefin is a Deinonychus antirrhopus, a theropod dinosaur whose name means “terrible claw”. Discovered in the 1960s, she revolutionized our understanding of dinosaurs. Before Deinonychus, dinosaurs were often seen as slow, dim-witted creatures. However, she shattered these misconceptions, offering insight into the dynamic world of hot-blooded, rapidly evolving animals that were masters of their domain. We aim for our desktop to embody a similar nimbleness. Power and adaptability.

Pantherina@feddit.de on 10 Feb 2024 14:15 collapse

And its always female, ships, cars, computers. Fucking weird

[deleted] on 10 Feb 2024 08:28 next collapse

.

TheGrandNagus@lemmy.world on 10 Feb 2024 10:32 collapse

Fedora may receive backing from RH, but it’s still community-ran. Similar to how Linux itself is backed by the likes of Google/Meta/Huawei/etc but is isn’t ran by them.

And they didn’t close-source RHEL. I don’t like the license changes they made either, but calling it closed source is inaccurate.

If you’re a customer of theirs, you can see the source code. The license customers agree to is certainly a restriction, but it’s not all of a sudden closed/proprietary software.

And finally, despite that recent move, RH remains probably the biggest contributor to desktop Linux. If you want to avoid their work… good luck. It’s literally everywhere.

FutileRecipe@lemmy.world on 10 Feb 2024 10:55 collapse

If you’re a customer of theirs, you can see the source code.

Are you saying that their source code is not published except to licensees?

You’re basically saying that something isn’t wet, it just has water on it.

drndramrndra@lemmygrad.ml on 10 Feb 2024 13:38 next collapse

TIL GPL is a proprietary licence

TheGrandNagus@lemmy.world on 10 Feb 2024 14:30 collapse

I’m saying their source code is available to its users for auditing, changing, redistributing without risk of being sued for intellectual property violations.

That’s fine as far as the GPL goes. It doesn’t have to be public to non-users.

You’re basically saying that something isn’t wet, it just has water on it.

I’m saying nothing of the sort.

FutileRecipe@lemmy.world on 10 Feb 2024 14:51 collapse

I’m saying their source code is available to its users for auditing, changing, redistributing without risk of being sued for intellectual property violations.

Closed source means computer programs whose source code is not published except to licensees.

We’re saying the same thing, you just refuse to attach “closed source” to its definition. So answer me this: can anyone freely use it? Can only licensees use it? If the answers are no and yes respectively, that’s closed source.

I’m saying nothing of the sort.

You absolutely are. You’re using the word’s definition (source code available only to licensees), but won’t say the actual word (closed source).

TheGrandNagus@lemmy.world on 10 Feb 2024 18:33 collapse

No, we aren’t saying the same thing, because you’re talking nonsense and I am not.

Closed source means computer programs whose source code is not published except to licensees

Nowhere in your link does it actually say that. And amusingly, by that definition, software where the source code isn’t provided to licensees isn’t closed source. What? So software where the code is a total black box that nobody other than the programmer knows isn’t closed source in your mind?

But here’s something it does say:

Proprietary software is software that grants its creator, publisher, or other rightsholder or rightsholder partner a legal monopoly by modern copyright and intellectual property law to exclude the recipient from freely sharing the software or modifying it

Let’s go through the two listed criteria, shall we?

  • Legal monopoly to exclude the user from sharing the software: RHEL doesn’t have this. They can’t sue anybody for sharing the code.

  • Legal monopoly to exclude the user from modifying the code: RHEL doesn’t have this. RHEL users are free to modify the code as they wish.

Saying “if you clone and republish RHEL, taking advantage of our work to undercut us with minimal effort, we reserve the right to not have you as a continued customer” is perhaps against the spirit of many open source licences, on that I agree, but it’s a far cry from being closed source. RHEL isn’t like MacOS or Windows.

FutileRecipe@lemmy.world on 12 Feb 2024 05:27 collapse

Nowhere in your link does it actually say that.

It’s hard for me to take you seriously when it does and I literally copy/pasted from the link. Even if you don’t read the whole page, you can’t even do a CTRL+F correctly.

TheGrandNagus@lemmy.world on 12 Feb 2024 06:25 collapse

It literally doesn’t. Please stop lying. Everybody can see you lying. It just makes you look like even more of an idiot. You don’t want to look like even more of a idiot, do you?

I’ve used your own source to dismiss your argument.

But here’s another, just to drive the point home even more:

en.m.wikipedia.org/wiki/Red_Hat_Enterprise_Linux

Red Hat Enterprise Linux (RHEL) is a commercial open-source Linux distribution developed by Red Hat

Lol

Source model: Open-source

Lmao

We’re done here, kiddie.

FutileRecipe@lemmy.world on 12 Feb 2024 06:36 collapse

It literally doesn’t. Please stop lying. Everybody can see you lying.

<img alt="" src="https://lemmy.world/pictrs/image/323c9ed3-54bb-4f7c-a044-8df8efd08dd3.png">

We’re done here, kiddie.

Calling me a liar (when it’s easily provable I’m not, I even included a screenshot for you) devolving to insults, calling me a kiddie and an idiot? If you can’t even formulate an argument without insults and you fail twice to read a link, yep, we’re done. Enjoy your day/night.

TheGrandNagus@lemmy.world on 12 Feb 2024 06:42 collapse

<img alt="1000070850" src="https://lemmy.world/pictrs/image/22db9b94-9f73-4a94-9c9a-51307758c97b.jpeg">

😂😂😂😂

AnUnusualRelic@lemmy.world on 10 Feb 2024 11:04 collapse

SuSE is releasing one of those as well. It seems to be the trend nowadays.