Garuda Linux
garudalinux.org
garudalinux.org
The BTRFS by default seems compelling too!
I must have missed something, because every person I've ever heard talk about BTRFS has said something along the lines of "I would never use that in production". Is that view of BTRFS outdated?
Last time I used it for example, I tried out compression only to realize that there's actually no command to see what compression ratio is being applied without installing what I interpreted as a third party tool (compsize).
One thing I will not run is btrfs, aka ENOSPCfs. I saw it fail again, and again, and again, and again, AND AGAIN, and again, and again. Then I saw it fail some more. The promised features never materialized, and the drama and surprising behaviors never ceased. All costs, no benefits? I'll leave that on the shelf, a few spots down from reiserfs (which was plenty sketchy BEFORE you know who did you know what).
For modern systems with normal use cases (i.e. not mine back then), I don't foresee a lot trouble. I went with encrypted ext4 because that was included in the installer during my reinstall, but I wouldn't change the settings if the installer had defaulted to BTRFS.
There's a lot more tooling out there for debugging ext4, but honestly, I never really missed anything when I still used BTRFS. The lack of tools makes data recovery harder in case of a complete failure (always make backups, no matter what file system!) so I wouldn't use it in a production server, but for a desktop or laptop OS I don't really see the problem.
Using Timeshift for snapshot management as a way to sort-of emulate Windows' system restore is kind of neat and got me interested in trying it out again next time I'm reinstalling Linux. Last time I didn't have the space for snapshots, but now I do and it solves a problem I've had before (quick and easy backups after modifying system config) with ext4-based installs.
edit: Think of cars on a racetrack. Street worthiness considered ballast...ROAAARRRR!
https://nvd.nist.gov/vuln/detail/CVE-2017-5754
https://nvd.nist.gov/vuln/detail/CVE-2018-3639
> A ddg site search of "cve" returns zero hits.
What was your search query?
https://garudalinux.org/images/garuda/ss/garuda-boot-options...
I'm not sure whether this is misleading or not given the nature of illustrative screenshots, e.g. the package management one shows VLC installed but not Firefox:
There are only few things running untrusted code on a typical end-user system, most notably the browsers executing javascript. Now that would be attack-able. But then again, it seems unlikely that anybody would launch broadly deployed attacks, as the vast majority of systems would run with mitigations on, so it's just not worth the trouble considering that and considering that you also have to get lucky to actually extract something valuable (and recognize it is valuable). On top of that, browsers also bring a bunch of mitigations that make it harder to exploit these bugs even if system mitigations are disabled.
I'm personally not very concerned about anybody trying to attack me with spectre/meltdown class bugs that can be and are usually mitigated, even with mitigations disabled on my system. If somebody wanted to attack me, either at random (broad attack), or targeting me specifically, they'd have far better ways and targets to try first than hoping I'd visit their website and run without mitigations enabled and have something valuable in my memory.
This is different if it's a shared system, like cloud machines/shared hosting, where this is an class of bugs is far more of a concern. And if you know or have reason to suspect you're a specific target, then you might err on the side of caution as well.
These attacks are being done algorithmically, automatically now.
Seriously, I haven't seen any news of these attacks being used against end-user systems, either broadly or targeted. Have some links?
Context:
I am hearing about Garuda Linux in Manjaro forum where I presume "the developer" talked about it in the "Other OS" discussion section. With the deteriorating community relations Manjaro has been having with their community and with some of the Manjaro folks like old time users/volunteers moving to Garuda because of it, Garuda Linux has a place and an opportunity at hand to outshine Manjaro. If they keep their community relationships in check I guess.
I hope they get through it. Manjaro is my goto for my Pinebook Pro.
It may be that a hacked up kernel is what is needed right now to make it work well. I get 6x the battery life than I did before (seriously), and updates don't totally break my system. Two pretty nice features :-D
Because of this there is essentially two parts to Manjaro. Manjaro the Community and Manjaro the Company. Manjaro the Company has funds from HW deals with Pine, laptop vendors and merch.
Manjaro the Community has community donations through opencollective. These funds are parts of the community funds Phil (founder of Manjaro the Company, and project leader) had collected privately and forwarded to this collective. These funds are used to pay for laptops and merch associated with business expenses to forward the interest of Manjaro the Company.
You can see how this creates some tensions when the boundary between the Community and the Company is blurry at best.
https://opencollective.com/manjaro/
https://archived.forum.manjaro.org/t/change-of-treasurer-for...
OpenCollective and CommunityBridge/LFX were set up after the surprise company announcement to collect community donations from that point (and intended to protect them as independent). The previous privately-collected donations were never forwarded.
I don't mean to dismiss the tension or that jonathon has made an unfair stand, but I am not sure I understand how the schism is warranted. Any software that combines outside funding with donations has a risk of this right? Unless I'm missing something it may just be a personal falling out.
The problem is the intransparency in the way things where handled as well. This is the most recent event. There are more quarrels with FreeOffice Manjaro originally planned to pre-install for some reason, but later backpedaled after pushback.
https://cc.bingj.com/cache.aspx?q=garuda+linux+qtile+install...
I shut down the live USB stick, rebooted, and everything worked fine despite the error. I did the pamac update. Everything was quick including wifi and barrier worked on my existing win/mac/lin setup without fail installed from AUR.
Configured a few things on the desktop and everything I depend on worked out of the box, which is surprising given the Ryzen 4700U that requires a recent kernel to function well. This was 5.10 so good enough. Testing power functions as soon as I can find them.
Chuckle.
The default qtile config doesn't make power easy to find.
Happy so far though.
Terminal config is perfect out of the box.
I just needed to tweak the fonts a bit up for my aging eyes on the 1920x1080@14". Ouch!
Really enjoying Garuda with qtile for the turnkey tiling WM that's almost as good as manjaro i3 or Regolith if you like their Ubuntu build.
Not quite there yet - but close.
Makes you wonder about the underlying plumbing though, if setting an GUI appearance option can lead to data loss in the first place.
Is there a writeup/summary somewhere that explains "the lessons learned"? Otherwise I'd kind-of start to worry about what could happen, if ... say ... I change the Bluetooth output codec, or some other other UI details.
Not that I'm aware of, but I'm sure you could check the GitLab commits and/or ask on their forum if you're interested.
This is a young project (just under a year old) with developers who do this for fun. The developers are going to keep making changes that maintain the fun they have during development.
Mistakes will be made. Things will break. Lessons will be learned. This isn't a decades-old mature distro, so if you're expecting something absolutely bullet-proof then Garuda currently isn't it.
However, I will say that the pace of improvement is pretty stunning. Their direction and what they have achieved in a short space of time is pretty impressive - not just within the distro itself but the surrounding OOB features and infrastructure like ChaoticAUR (prebuilt AUR packages), secure password management (Bitwarden), dotfile sync (NextCloud), a pastebin service for log output (Privatebin), ...
Is it perfect? No. Is it for everyone? No. It is what it is, and doesn't try to be anything else, and I kind of like that approach.
[1] https://en.wikipedia.org/wiki/Javan_hawk-eagle [2] https://en.wikipedia.org/wiki/National_emblem_of_Indonesia
The ||Shree|| at the top is a religious symbol when presented in that way though, as a search for that term will easily demonstrate:
https://www.google.com/search?safe=strict&rlz=1CAUSXU_enUS92...
The only common non-religious context for that word is when it means "Mr." but for that it must precede a name. So I'm not sure why it's there if not as a religious symbol. It would be similar to having "God is great" or "Allahu 'Akbar" up there.
Perhaps projecting their religious identity is important for the developers of this project.
This is not true, ।।श्री।। is not equivalent to "Allahu Akbar". It is commonly used term to denote a start of something, e.g. a notebook or a new project. I would say it falls in a gray area as it doesn't invoke any Indian deity and is pretty open to interpretation. It's functional equivalent in Indian Islamic tradition is 786.
Just because it does not invoke a particular deity doesn't mean it is not religious, and specifically Hindu.
Unlike many other Sanskrit phrases that can be interpreted in secular contexts, that one is quite specifically Hindu, especially of abstract Hinduism that is more a system of philosophy and political identity then an affinity for any particular deity of the Pantheon.
That all said, it's hardly surprising given that Indian culture has long had a tendency to distinctly mark even the most mundane and non-religious aspects of life with religious symbolism, regardless of the religion. The Enlightenment arrived relatively late to India, and with it the secular and religious dualism that is more pronounced in the West, which is why you don't tend to see scientific or technical documentation in the West imbued with religious symbols.
Regarding the other discussion on 786 and Shree, I agree with you. The closest parallel to Allah hu Akbar I can think of would perhaps be something like Aum Namaha Shivaya, but not really.
Maybe something like Jaya Bhagavaan. Of course the amazing thing (to me) about Hinduism is the tendency towards non standardization, and the sheer diversity of symbolism despite the attempts to simplify it down to a single religious identity.
Fair point about the non-standardization. Read somewhere that the Sanatani corpus/philosophy is the Linux of religions, which I thought was quite apt. Namaste.
(NB Yes they are supposed to have improved but 10-20 years ago they had a very bad reputation).