Installing Every Arch Package
ta180m.exozy.me
ta180m.exozy.me
https://aur.archlinux.org/packages/?O=0&SeB=nd&K=bin&SB=p&SO...
One was found in the Ubuntu Snap store at one point though[1]
[0]:https://www.bleepingcomputer.com/news/security/malware-found...
[1]:https://www.bleepingcomputer.com/news/linux/malicious-packag...
It's basically unnecessary to run any sort of anti-malware program on Linux, because not enough people use it for writing viruses for it to be profitable. And because the people who use it as a desktop are generally more knowledgeable and safe with their habits.
These mechanisms for filtering packages are normally not present on systems that are plagued with malware.
As for the security review, I’d agree that no maintainer is verifying the code in every update of the software they’re packaging. This doesn’t mean that, as implied in the comment I replied to, you only have to review the 40 lines. It means that you’re accepting risk or accepting workload in either case (or both!), depending on how deep you look into the supply chain.
I agree with the rest, I'm really talking more about the comparative risk from AUR compared to the repos. The real danger is that someone snuck something malicious in the PKGBUILD and that no one noticed yet. Other than that, the threat is the same as using the repos, assuming you trust the maintainers, which is IMO a reasonable assumption if you're already using it as your distro.
I know AUR package managers are bad juju. Still it sounds fun.
Installing every Arch/AUR package could break some hardware compatibility which we've taken for granted(Story link is not opening as of writing, So not sure whether this case has been covered in it).
[1] https://unix.stackexchange.com/questions/670636/unable-to-us...
Well, at the very least it's a very computationally expensive test that managed to catch a few packaging bugs.
Even today it's kind of a headache to install packages on machines with no Internet access, usually the easiest solution is to download everything and setting up a package repo on the LAN.
If you want real fun, try setting up a nontrivial node.js project without direct Internet access.
Reminds me of one former coworker, which didn't like me introducing FreeBSD. So he started installing all ports packages.. only to say the following morning: Look it's broken! ( disk was obviously full and this plot was irrational to people with some common sense ).
I’m curious about doing the same thing in Ubuntu
It was when things started to disappear from my desktop that I realised something was really wrong. I killed the process and assessed the damage. The only text editor left was vi (not vim). Using the apt log I was able to recover the system by simple reinstalling all packages it had uninstalled. Fun times.
I've been using Pacman for years never had a single problem with conflicts or anything else.
[1] https://wiki.archlinux.org/title/PKGBUILD#Package_relations
> As we used a lot of unsafe hacks (disabling dependency and file conflict checking, for instance) to get this to actually work, I wouldn’t recommend using this system for anything other than proving it’s possible.
> Investigate the file conflicts and file some Arch Linux bugs.
with a link to https://bugs.archlinux.org/task/73574, which is indeed a bug in the packaging script (it fails to consider python version 3.10 because it only globs 3.?).
For clarity, Arch has about 10k packages, AUR has around 60k packages. I believe this post is "just" about the 10k.
> I’d like to see someone do this for Ubuntu, Debian, and NixOS and watch them suffer.
Speaking for NixOS:
I have. I would sometimes do a nixpkgs-review[1] of the mass "rebuild" PRs for Nixpkgs[2]. Hard to know how long it took to build as I would just let it "cook" on my build server while I did other things. The other thing is that nix gives unique names to all built packages and utilizes "maximal sharing" thereof, so everything gets memo-ized[3] on future runs.
The scale of the official nixpkgs repository is 4-6x greater than that of Arch (AUR is the user repository). 9.6k Arch packages vs 59.4k Nixpkgs packages according to repology[4]
Lastly, installing packages in nix is different. Everything goes into the nix store, which is relatively "inert". I don't need to worry about "hooks" or stateful logic being executed affecting my system. "But then how do you create services and other meaningful abstractions needed to make an OS? I thought NixOS was a distribution" It is, and it's down through NixOS modules[5] in the form of a configuration.nix. The NixOS modules can compose the verticals in my system to deliver something coherent and amazing.
Server used:
OS: NixOS 22.05 (Quokka) x86_64
Kernel: 5.10.91
CPU: AMD Ryzen Threadripper 3990X (128) @ 2.900GHz
Memory: 125913MiB / 257687MiB
[0]: https://www.reddit.com/r/linux/comments/shxq12/comment/hv5by...
[1]: https://github.com/Mic92/nixpkgs-review
[2]: https://github.com/NixOS/nixpkgs/pull/144730#pullrequestrevi...
[3]: https://en.wikipedia.org/wiki/Memoization
[4]: https://repology.org/repositories/statistics/newest
[5]: https://nixos.wiki/wiki/ModuleNix has been behaving that way for at least 8 years: https://github.com/NixOS/nix/issues/308
It is very useful seeing how the "pros" do things, which looks substantially easier than when I try to install Arch and end up with a mess only slightly better than in this article ;)
Edit: the channels name is "EF - Linux made simple".
Here are the links for the lazy
[channel] https://www.youtube.com/channel/UCX_WM2O-X96URC5n66G-hvw
[the latest installment of Arch Monthly Install:Jan 2022] https://www.youtube.com/watch?v=7btEUHjECAo
Site was barely loading for me, here is a mirror.
Will be interesting to read about the incident if the author is here.
I'm not sure that would cause any suffering in NixOS other that running out of disk space; one of the big claims of nix is that it happily lets you install whatever you want without conflicts. Although they also have a somewhat different idea of what "install" means; you might have to still put in some work to surface as many programs as possible to a single shell's PATH.
They mount a 1TB volume with all packages preinstalled
If you can make a system work properly with every package installed, then you could in theory get rid of the concept of installation entirely. Use a FUSE file system to make it appear as if every package is installed, and then block any program that opens a non-installed file until the package has been downloaded and installed for real. Now you don't have to know about packages or pacman anymore. Just do ls /usr/bin to see what's available in the index, and then type in what you want and hit enter. Wait a few seconds and the program will start.
However, for this to work, does require that the system be stable with every package "installed" simultaneously, so it'd mean fixing UIs that assume only a few options are available.
[1] This is n=1 data because I can only speak for my own machine, so obviously take this with a grain of salt.
From the weird idea (why would that be interesting) to optimal solutions, np hard, disk issues and then an interesting result.
Also, what theme is this? Looks pretty clean
Thanks for the kind words, I am the author of this theme :)
'The OS: Oh you have three versions of Python, let's use the earliest version and make your program insecure'
Regardless, if you want a nice terminal that isn't retro shaded and has zero UI cruft like tabs, menus, etc. check out Alacritty.
Same note for the website logo: render-small.gif is 4Mb. Still loading...
But this guy? Wow! Having 4MB as a logo that makes up only 38x38 pixels on a 1080p screen is an absolute chad move when it comes to bandwidth. And yes, the website is still loading here, too. I wonder why ... :^)
I'm still in process of saving that one, but I can tell that's a GIF animation.
Update: It's 240 frames of a spinning dodecahedron.
original 3_389_491 B
pngout 2_739_324 B
quantised 256 colours+pngout 636_135 B
webp lossless 2_210_112 B
webp default settings (lossy) 210_452 BPermitting: 1p CSS; denying: everything else, including fonts (in uBlock).
I am glad that my comment improved this website :)