What is Silverblue?
fedoramagazine.org
fedoramagazine.org
The article is completely right about this being the future of user OS's - even my half-broke me-ware above has changed how I think about using my laptop - just knowing exactly what is under me is exactly what I have set is ... reassuring.
Being able to know I can try things out and a reboot gets me back to my last known good point is ... well a bit like a video game with savepoints. And there becomes an utter focus on data and non-data. And probably the best advantage is that you ratchet up - every security improvement I think of becomes built in and makes my platform one tiny bit higher
SilverBlue is well worth watching - I say they really are into something
This is exactly with I do with Darch.
It supports Ubuntu/Debian/Arch/VoidLinux.
Here are my recipes: https://github.com/pauldotknopf/darch-recipes
I push my images to Docker Hub, pull them on each of my machines and boot them bare-metal. The same exact bits.
The layers themselves seem to be bash scripts so presumably have RUN xxx put in front of them? The booting from bare metal is cool - never tried that. presumably that won't work on a mac?
Dedicated system volume.
macOS Catalina runs in its own read-only volume, so it’s separate from all other data on your Mac, and nothing can accidentally overwrite your system files. And Gatekeeper ensures that new apps you install have been checked for known security issues before you run them, so you’re always using good software.
Darch. https://godarch.com/
I essentially use Dockerfiles to build my operating systems. I push them to Docker Hub so that each of my machines have access to them. I can boot them bare-metal, read-only, with a tmpfs overlay. I can apt-get install/remove anything, completely break my system, then reboot and everything is fixed!
Here are my recipes: https://github.com/pauldotknopf/darch-recipes
You can easily get it a test-run with a pre-made VM: https://pknopf.com/post/2018-11-09-give-ubuntu-darch-a-quick...
I'd love to hear some feed back. I've been using it personally for the past few years. I wouldn't do it any other way.
I wish someone built an OS based on k8s as a service and application orchestrator. We wouldn't have to reinvent all the config files, the command line tools and we could reuse knowledge between cluster and single-machine administration. Plus k8s already voluntary abstracted the underlying technologies, so it should be simple to reuse it. We would use the same high-availability concepts than from the cloud, such as stateless service, horizontal scaling of services, etc. We could also reuse Istio and all the standards it is built-on to introspect the system. In other words, a microservice based OS.
https://fedoraproject.org/wiki/StatelessLinux
This was imagined a decade ago, but the technology and the market weren't ready then. I am really excited to see it as an actual product.
An even bigger motivator is that flash memory lifetime is more determined by number of writes per block rather than time or reads per block. So to keep your storage both cheap and reliable, it's best to flash it with a single full (compressed) image every time you run a firmware upgrade, and otherwise mount it read-only.
https://pknopf.com/post/2018-11-09-give-ubuntu-darch-a-quick...
Silverblue still uses a single namespace for all libraries (unless you count Flatpaks, which can bring their own dependencies), whereas on NixOS you can have many different versions of the same library in parallel.
In NixOS, the whole system is defined declaratively, including the system configuration, whereas Silverblue uses a mutable /etc.
> What are the benefits of an immutable OS?
> One of the main benefits is security. The base operating system is mounted as read-only, and thus cannot be modified by malicious software. The only way to alter the system is through the rpm-ostree utility.
How is this different from the current experience? "Operating system" files already aren't writable by the user. The only way to alter the system is through the "sudo" utility.
> Another benefit is robustness. It’s nearly impossible for a regular user to get the OS to the state when it doesn’t boot or doesn’t work properly after accidentally or unintentionally removing some system library. Try to think about these kind of experiences from your past, and imagine how Silverblue could help you there.
How often does this happen? I've worked with complete Linux noobies who were "forced" to use Linux in a VM daily and I've never seen this happen.
The sudo utility doesn't really give any guarantees or produces reproducible states. You can mess around with sudo however you like.rpm-ostree transactions are completely reversible.
Silverblue is the equivalent of an accountant having a transparent history of your machine states. Sudo is like grabbing a pencil, a rubber, and a spraycan and gowing to town.
Depends on the noob, and just because you never met a situation like that doesn't mean nobody else experiences too (disclosure: it happens all the time)
I was somewhat a noob, I tried to edit Ubuntu's Yaru theme and I messed up and deleted the corrupted system files. There was nothing to worry since I already made backups of the original files, the distress came when I realized I accidentally deleted my good backup files (was bad regex). I wasn't really worried at that moment cause I hoped there would be some repository out there, I could just fetch my files. There was none, none of the latest Ubuntu version or any close old version. Turns out distribution packages are so big (sensibly) it's not that simple to deploy a remote master repository. That was my "wtf open source" moment. I still somehow managed to fix it without any stackoverflow or AskUbuntu. Anyway that's just one case top off my head.
About the configuration issue, if configurations are transactional, you get transactional properties. And that would be quite significant. If you hose your system with an apt/yum update, you don't have much recourse unless you also took a filesystem snapshot before it (which you can do with zfs/btrfs/lvm-thin etc. and people shoehorn these things for precisely this reason). They are all different means to approximate the same end which is transactional package management.
System recovery from backups is pretty easy and well understood too, so I'm not sure what benefit this would bring.
If you want transactions you can install on btrfs and use apt-btrfs-snapshot to automatically take snapshots. It seems this isn't that well-known though, probably because the problem it solves isn't very serious.
As for Android, it's already a frustrating system on phones, something like that on desktops would be total trash.
The article never mentions speed (or performance) again. Is the OS somehow expected to be faster because it is mounted read-only?
How many libraries are loaded:
$ sudo cat /proc/[0-9]*/maps | grep '\.so' | grep 'r-xp' | tr -s ' ' | cut -d ' ' -f 6 | wc -l
15429
How many unique library names: $ sudo cat /proc/[0-9]*/maps | grep '\.so' | grep 'r-xp' | tr -s ' ' | cut -d ' ' -f 6 | sort | uniq | wc -l
872
Top 10 most shared libraries: sudo cat /proc/[0-9]*/maps | grep '\.so' | grep 'r-xp' | tr -s ' ' | cut -d ' ' -f 6 | awk '{count[$0]++}END{for (i in count) print i, count[i]}' | sort -k 2 -n -r | head -n 10
/lib/x86_64-linux-gnu/libc-2.28.so 299
/lib/x86_64-linux-gnu/ld-2.28.so 299
/lib/x86_64-linux-gnu/libdl-2.28.so 262
/lib/x86_64-linux-gnu/libpthread-2.28.so 237
/lib/x86_64-linux-gnu/librt-2.28.so 227
/lib/x86_64-linux-gnu/libuuid.so.1.3.0 205
/lib/x86_64-linux-gnu/libz.so.1.2.11 200
/lib/x86_64-linux-gnu/libpcre.so.3.13.3 186
/lib/x86_64-linux-gnu/libresolv-2.28.so 170
/lib/x86_64-linux-gnu/libgpg-error.so.0.26.1 169
EDIT: add grep r-xp to count code segment only, values in previous edit were overestimated.The GP did mention the 'big graphical ones,' but the amount of memory that gets saved was a bit stunning the first time I saw it.
It's not easy to share libraries across containers, unless they can be built to share a base layer in a stacked union filesystem approach.
Well, in my original post (GGGP) I've defined "a library" as "a .so file" so what I can say is that the 872 distinct .so files used on my laptop will be shared among the different processes that use them.
If you assume the same library can be duplicated in two different .so files, then 872 is just an upper bound on the number of distinct libraries and further sharing could be done.
Eitherway, that is a significant amount of code sharing, which was the original question in this thread.
If the containerised versions of apps all have different versions of dependencies (quite likely IMO as they'll have the freedom to), there won't be any sharing.
On top of that, ostree does deduplication based on file checksum. So if different packages ship the same binary, it will be only one copy on the disk and again, the mmaped regions will be shared among processes.
I wished something like silverblue existed back then.
A lot of application I use are command line based and are simply not available via flatpak. You have to install these via rpm-ostree but that requires a reboot every time you install anything.
Moreover many GUI applications that are available in the fedora repos are simply not packaged as flatpaks and either require rpm-ostree and a subsequent reboot or adding a third party repository like flathub. I really don't want to give up fedoras mostly excellent repos to rely on some badly packaged, possibly malicious container.
After not being able to find my preffered media player mpv, I settled for VLC from flathub. It installed just fine but video playback was completely broken, VLC installed via rpm-ostree worked.
I also don't understand how you are supposed to install patent encumbered codecs for firefox. Usually this is solved by adding the rpmfusion repos but with firefox being installed via a flatpak from the fedora repos, this obviously does not work.
I'll probably check this out again in ~2 years and see if it's any better.
alias df='df -x squashfs'
Given that squashfs is a read-only filesystem, I don't know why this isn't done by default. No one needs to worry about how much free space is left on an ro volume.
I also go a few steps further and disable udev (-x devtmpfs) and tmpfs (-x tmpfs) as well.
findmnt --df --typesI too look forwards to having to manually updated all security patches for each binary in the system.
The fact that things like flatpak, snap, nix all explicitly try to address this problem with platforms/base layers/grafting etc. is very telling. They are all a trade off of your security vs. the dev's convenience, which might be necessary to succeed.
After Silverblue, when they run in Flatpaks, they can still maintain build scripts that achieve the same thing.
The distribution itself can even maintain a common base image for all flatpaks in the official repos, retaining all of the code sharing of existing systems, but with the benefit of a more robust and modular solution when they need to make exceptions. End users will also be able to more reliably use applications that are not supported by the distribution proper.
Don't "Bill Revues", "Evil Rubles", "Rebels I Luv", "Urb Level I", "I'll Sue Verb", "I Blur Elves", "Be Evil Slur", and "I Serve Bull" qualify as hidden meanings?
(Not to mention "I Beaver's Mullet", "Brutalism Levee", "Album Televiser", "Ever Liable Smut", "Evil Slum Beater", "Melt Bra, Sue Evil", "Be Real Evil Smut", "Evilest Bar Mule", "Leave Stumblier", or "Blames True Evil"...)
I mean, if the system is immutable, do I have to download an install a completely new image? How often do such updates arrive?
And what does immutable even mean in practice? Do I have to start from a CD image or some special boot mode every time I want to install system updates?
The details can be found in the ostree documentation: https://ostree.readthedocs.io/en/latest/manual/atomic-upgrad...
ostree supports signing commits and trees with GPG signatures, and like git, all objects are content-addressed by SHA256 hash, so it is possible to verify that the entire root tree and all objects within it have been signed by some trusted party.
It personally made me think of "Silverlight".
I'm about to get a new laptop for work, I usually use Fedora. Should I gamble on using SilverBlue? I'll have to think long about this one.
Of course, ro - great for security, but if something happens with any critical system component like bootloader - I prefer to able patch/fix it myself and don't wait days/weeks for distmakers.
Clear Linux use similar concept, but they allow write access and handle whole fs tree and bundle depends on server side.
There are basically multiple filesystem trees under the hood (shared with hard links to avoid duplicating file data), and at boot time you'll get one of them. These are known as "OSTree deployments", and they're found in /ostree/deploy, and they're actually mutable, it's just the bind mounts into that location that are mounted RO.
Anything in the bootloader configuration is not part of the deployment (from what I remember), and so it's mutable.
See the docs here: https://ostree.readthedocs.io/en/latest/manual/deployment/
All people on Linux really need is an xdg-open standard for opening a package manager / running an install command.
> Flatpak mostly deployed as a convenient library bundling technology early on, with the sandboxing or containerization being phased in over time for most applications.
I don't really know if sandboxing is worth it for me. Running everything inside docker cotnaienrs sounds like an absolute nightmare when it comes to troubleshooting. You might think logs and things would be well defined and put in the right place for the OS to pick up, but if things were so well behaved we wouldn't feel the need for sandboxing now would we.
Applications have vulnerabilities. Sandboxes help as an additional layer of security for trusted applications.
Of course, if applications are trusted and under control, a simpler mechanism like OpenBSD's pledge/unveil may be enough.
https://blogs.gnome.org/mclasen/2019/07/12/settings-in-a-san...
Flatpak is one piece of a broader design to secure Linux workstations. It is also intended to work in conjunction with Wayland and the in-development Pipewire. These lock down video and audio respectively, so that shared resources can't be misused by applications.
If things were so easily automatically updated and maintained we wouldn't need flatpak.
One benefit is that if you have some software in the chain blocking updates others can update.
This may actually improve overall security.
I think I just argued myself out of hating flatpak. :/
Which is cool, because that os-tree switching thing sounds like btrfs snapshot hopping on steroids.
- VLC ships with a slightly older version of ffmpeg (4.1.3) with two known CVEs:
https://github.com/flathub/org.videolan.VLC/blob/f1b27c13b13...
- MakeMKV uses an outdated ffmpeg (4.1.0), which has several known CVEs:
https://github.com/flathub/com.makemkv.MakeMKV/blob/3c44c8bc...
- Openshot uses an outdated ffmpeg (4.0.3) which has several known CVEs:
https://github.com/flathub/org.openshot.OpenShot/blob/ec2077...
This is what you get when every application ships custom dependencies, rather than having a consistent package set.
(I like the idea of Flatpak, but I think it hasn't found its optimum yet in terms of dependency management.)
https://github.com/search?q=org%3Aflathub+%22--filesystem%3D... https://github.com/search?q=org%3Aflathub+%22--filesystem%3D...
So, many applications use it as a distribution mechanism and not so much for sandboxing. Of course, this is bound to get better over time when applications are modified to support sandboxing better and can use portals.
IMO you need both: isolation through e.g. sandboxing and timely security updates of applications and all their dependencies. Flatpak currently provides the former for some applications and the latter is completely dependent on the maintainer of the Flatpak.
So often, a distribution would be held back on an old ffmpeg (perhaps patched with some of the CVE fixes by a distro maintainer who might not be familiar with the codebase) to isolate the churn of upstream.
flatpak lets app maintainers update at their leisure, which actually gets them on a faster update cycle.
> I'm not sure why there is this push for Linux to have the "download and double click" install experience of windows / Mac.
No joke. I seriously don't see desktops running rich applications around anywhere, except the mini-computer / workstation use case.
Generally people are running a glorified thin terminal with a browser or putty connection to a dosbox app. People who actually do things on their own computers generally run laptops now. The exceptions are people who do demanding work loads, and they run workstations that can handle it--more like the mini-computer than the traditional office desktop.
There are public computer terminals in libraries and such, but the only reasons these are not laptops are theft prevention and the need for a large screen, keyboard and mouse.
The exception is things like receptionists, or other areas where multiple employees share a common terminal. But as mentioned before, those computers are basically used as stationary, large-screen browsers or thin clients for cloud applications. Email? Excel? It's been a decade since I've seen people doing that on desktops in office environments.
Plus "putty connection to a dosbox app"? I have never heard of anyone doing that, and don't understand why they would. Or maybe you don't mean "dosbox" [1], but "console"/"terminal"?
I agree that on servers the container runtime makes a lot of sense but not on Desktops where changes happen every day.
As I posted here: https://news.ycombinator.com/item?id=20425615