Firefox on Ubuntu 22.04 from .deb (not from snap)
balintreczey.hu
balintreczey.hu
> Source?
https://discourse.ubuntu.com/t/feature-freeze-exception-seed...
The reason probably being that for Canonical and Mozilla, it is a pain to support/backport multiple ubuntu versions, so why not just support 1 build.
It makes it simpler for them to release as it's directly integrated in their build system.
Considering how small a percentage linux users are, it isn't an illogical decision.
If offering a Deb is such a major issue for Mozilla, why are they still offering a distro-agnostic one that works just fine?
This whole story just doesn't make sense but fits in perfectly with Canonical's obsession with making snap a success.
Most of that work is done by package maintainers that have an interest in the project and package the update for each release.
The projects that usually do make their own debs/rpms/whatever are usually backed by companies that have a strong interest in making their software easy to access. I guess mozilla should be in that group but they aren't.
MS releases full versions of code, Google Releases Chrome, you can get a terraform deb you can get neovim. Not really sure why FF doesn't release one but the way I understand it, FF is kinda back burner for Mozilla so who knows.
Lots of projects seem to producing DEB files. I think they're the most common shared distribution format except for maybe PKGBUILD files for Arch.
Loads of projects have their own package repositories but cross distro distributions like Flatpak and Snap tend to be recommended before the docs refer to the repositories. The extra two or three clicks necessary to get the repository URL seem to make a big difference in popularity.
https://bugzilla.mozilla.org/show_bug.cgi?id=1523551
> Matthias Versen [:Matti]
> Again, there was never a PPA by Mozilla but rather by the unofficial Mozilla-team and the Mozilla-Team is not Mozilla.
> They are AFAIK a group of people from the Ubuntu community who maintain and provide the Builds for Mozilla.org products for Ubuntu users.
> You have to ask at Ubuntu or ask directly the Members of the Ubuntu Mozilla-Team about the status of those builds and who generates them.
[1] IIRC, it had to do with using the Firefox name even though Debian was lightly modifying sources to remove a couple of things. This was resolved a while ago and the Firefox branding resumed.
If Mozilla was so keen on snaps of their own accord why wouldn’t they be pushing other distros to also pack it up as a snap and/or Flatpak.
Additionally, it is being done by the same folks who drive development of linux-specific features (like wayland support or video decoding acceleration) anyway.
Its so they can screw with it instead of just shipping what Mozilla released.
Building the binaries themselves do. Mozilla does it few days in advance, so at the release they can push everything (and the binaries are available on the ftp.mozilla.org day before, uusually around 16:00 UTC). Other parties can start building their binaries only after the release.
In case of Fedora, it is pushed into the testing stream and only after positive feedback (or few days) it is pushed into the release. If you want it earlier, you can get the tested builds from bodhi (bodhi.fedoraproject.org). You can also see the status of all builds there.
> “This is the result of cooperation and collaboration between the [Ubuntu] Desktop and Snap teams at Canonical and Mozilla developers, and is the first step towards a deb-to-snap transition that will take place during the 22.04 development cycle,” Ubuntu desktop team’s Ken VanDine explains in a Discourse post.
This quote does not in any way support the claim that "Mozilla asked for it". Maybe find better sources for your info.
You're not forced into one method?
My biggest problem with Snap is that trying to install something like Chromium via apt, will, most likely unbeknownst to the user, just install the Snap version instead.
I recently installed Chromium via apt, and it actually installed the snap!
I mean, if I wanted the snap I'll use the snap command. If it's not available via apt just say so and quit. I don't want it to install the snap version when I asked for the apt (.deb) thing.
In this particular case the means to the end matters.
There are alternative solutions: QubesOS uses VMs as the isolation layer, desktop application confinement using firejail with its good selection of profiles tweaked to my liking, systemd-run confinement configured through the vast resource control options made configurable through systemd. There is no reason ~ or even / shouldn't appear completely empty to Firefox the process except for the resources you pass to it (open file, grant download permissions...) or which it needs to run (of course, those would be immutable as far as possible). SELinux and AppArmor are child's play; you don't have a lot of problems of those tools if there are no objects a process could acceess in its namespace to begin with.
macOS I believe is already there in terms of desktop app confinement. Windows is not but at least it has the controlled folder access layer available after they gave up on making store apps meaningfully secure as its own app category (too many escapes/config tweaks possible now). Desktop Linux though has not had squat in that field in the mass market for 2 decades. Basically, you guys run all applications unconfined. Snap is a way to work on changing that.
Not saying though that the current implementation is exceptionally good. It's too slow, and they should have reused systemd or whatever for a thin, tweakable resource control and container layer, not invent a container format from scratch.
It's a container not a vm so I don't think it would help if a package can't be run using the stock kernel.
there is simply too much extra crap launched from systemd (I don't have a problem with systemd, just all the extra ubuntu-specific stuff they've added as new daemons) and too many kinda-ubuntu-proprietary things shipped in xubuntu now.
There's also instructions for converting a running system, but I've had no luck with that. It just resulted in an unbootable system for me as it couldn't fully remove systemd there.
I'm going to try 22.04 before deciding, but I'm eyeing Manjaro or Endeavor OS in case I jump ship. I'm also eyeing Qubes OS, but it looks needy and resource heavy.
They are good for server installations as well, except Docker/containers are almost always a better solution. Although the auto updating features make it a good solution for potentially creating self hosted services.
They’re just a terrible fit for the desktop. Unsurprising because they were never designed for the desktop.
Ubuntu’s aggressive approach with snaps would have been bad enough if snaps were the perfect desktop app solution. It’s a lot more frustrating considering snaps are probably the 3rd best new packaging option behind Flatpak sand appimage.
Why have you chosen OpenSUSE and how has your experience been? I've been eyeing Debian, as it's pretty similar and I already have it on a server. My main concern with switching to a completely different distro would be that the packages are sometimes named differently.
Or I could switch to NixOS if I wanted things to be actually better, but the idea that I'd have to spend time nurturing my system just doesn't sound that appealing in 2022.
As for the experience, I mostly like it. There is some re-learning to do (zypper not apt!), but the vast majority of things are the same. Since the distro isn't as popular, there are fewer asked-and-answered questions out there, but most Ubuntu answers work with minimal adaptation and the OpenSUSE wiki is pretty good.
Another downside of going non-Debian is that proprietary software may be less well-supported. I think I only have Steam and Spotify, and they have worked well so far.
Which is fine, it does what people need it to do for now. Arguably it may fall further and further behind over time though.
it's nuts to wait 20 seconds for a program to start up in 2022
I searched for a previous discussion: https://news.ycombinator.com/item?id=23439326. The linked article is nonsense... and most of the comments are either just as nonsensical or they actually like snap. The one criticism I find is that it is slow. The other seems to be around the idea that Canonical controls it too much for some people to feel comfortable... but other than that, I don't get it.
The other seems to be around the idea that Canonical controls it too much for some people to feel comfortable... but other than that, I don't get it.
Why would we have to accept something semi-privative being shoved down our throats?I'm not going to accept Canonical behaving like Microsoft.
If you want containers, why would you go with a proprietary canonical technology instead of one of the better open source solutions? After all isn't one of the main promises of containers increased compatibility?
Even the ubuntu derivatives are switching away from snap.
Canonical did good work with Ubuntu, bringing the first very good desktop distribution that was usable from a mass audience.
But time has moved on, and Canonical has moved on, too. Snap makes a of of sense for a lot of purposes. But for geeks and their desktops, not so much. Canonical is no longer interested in us.
A breakdown of a relationship is always stressful, but in this case we have just grown apart, and now we both need change.
I wish Canonical all the best in their pursuit of profits in cloud software and systems, and in the IoT world (where snaps are ideal).
I am in another relationship now. We have both moved on
I just wish they had followed a similar approach as Red Hat have, where they're still able to place a significant amount of effort into the desktop side of things thanks to their enterprise offering and specialized focuses, like embedded systems for automobiles, which I believe is where much of the Pipewire work came about for example.
That's not to say Red Hat is perfect or a crowning example of a Linux company "done right". Rather, it's just an example.
As a refresher, here is the announcement.
https://lwn.net/Articles/56947/
For Red-Hat naturally there needs to exist some form of desktop for enterprise customers, but that is as much as they care, which also reflects on GNOME decisions, as they have most of the main developers on their payroll.
The worst offenders were the software which doesn't allow you to install if you aren't running a servrr SKU, oyherwise I haven't any difference between a client or a server SKUs
I consider ubuntu completely unsuitable for server and cloud. I don't think there is any use case they are suitable for anymore. Which is definitely sad.
The fact Snaps are automatically updated in the background, and users have to resort to half-assed workarounds[1], should be an absolute deal breaker for server use, where you want total control over when and if packages should be updated.
[1]: https://forum.snapcraft.io/t/disabling-automatic-refresh-for...
I don't think installing software through snaps or deb packages makes a difference in terms of geek street cred. It's a linux system, you can still do with it whatever you want, they're not locking your machine down. The idea that something can't be for a mass audience and nerds is strange.
Comes down to definition of Computer Geek.
> The idea that something can't be for a mass audience and nerds is strange.
Really? I completely disagree. The requirements of nerds and civilians are different
If I wanted a system that enforces arbitrary mandates on me, I'd use windows.
> Since the package comes from a PPA unattended-upgrades will not upgrade it automatically, unless you enable this origin:
You probably don’t want Firefox to update automatically, without your knowledge. A Firefox upgrade means you must immediately restart the browser. If this happens in the background while you’re doing something important, it can easily ruin your day.
Moving from Arch to Debian I was disappointed not to find a Developer Edition package, but the official Linux release works just fine and I personally enjoy the auto-update mechanism.
about:preferences#general ("Check for updates but let you choose to install them", if English localization)
It happens all time time for me. Literally happened just a few minutes ago. It happens when you open a new tab or window, not when you're browsing within an existing tab.
> Restart to Keep Using Firefox Developer Edition
> An update to Firefox Developer Edition started in the background. You’ll need to restart to finish the update.
> Your windows and tabs will be quickly restored, but private ones will not.
The (only?) downside is less tight distro integration, less reliance on shared libraries which can be updated and bugfixed independent of the browser.
I’m less convinced of that benefit in the face of seamless autoupdate though, here on Arch with the official package which does require me to restart.
No not really?
If I update it here on FreeBSD it stays working and it prompts me to restart the browser when I'm ready so it can start using the latest version which just got installed.
I run into this issue very often. I use private browsing heavily, so the forced restart is very disruptive to my workload. I lose all my tabs and saved state.
I understand the concerns about snaps. Look, if you want control, you have it. Uninstall it and find other installation options including reviewing and building yourself.
What I've realized over time is that for the far majority of things, I just want it to work b/c I have better things to spend my time on. I can appreciate that software devs have the same feeling regarding supporting the various Linux distros. It's less time and troubleshooting to just pick a single target like snap. Many of us want Linux desktops to gain in popularity...I can see how snap (or it's competitors) can help make that come true.
I have my doubts about something like LXC being shipped as a snap, I'm curious to see how things will play out with shipping more server software through snaps. I understand why the push towards snaps would be viewed more negatively for server applications.
I would like software to be heavily sandboxed by default. Why should any software I want to use have access to my ssh agent or all of my files? Firefox should have access to almost nothing except a limited part of the file system and the network, right? I'm not sure we are there yet, but I think this type of software packaging, "containerization", and isolation is a good direction to be heading.
There are things I don't like about snap and I kind of wish one of the alternatives would win. At the very least, hopefully they will challenge snap to be better and the ecosystem itself will benefit.
https://www.mozilla.org/en-US/firefox/all/#product-desktop-r...
Been doing this for years. That way I don't have to wait until the repo or ppa's are updated.
sudo snap remove firefox
sudo snap remove gnome-3-38-2004
sudo snap remove gtk-common-themes
sudo snap remove core20
sudo snap remove bare
sudo snap remove snapd
Remove snap completely: sudo apt purge snapd
Then instead of adding the ppa, use flatpak with flathub (https://flatpak.org/setup/Ubuntu)That being said ricotz has been participating in the Ubuntu community for a very long time, and from a practical standpoint you'll probably be ok.
There's a good reason for Ubuntu to push people away from PPAs as distribution methods for end users and instead use them for what they were original supposed to be used for, make it easy for distro developers to fire up repos for testing/development with the intent of that work making it back into distro and Debian. Snaps have lots of problems but using the distro-staging PPA isn't a good idea either.
Community support is great but without a proper security team and enforced secutiry processes the PPAs are very dangerous.
[1] https://wiki.ubuntu.com/JohnVivirito
[2] https://www.dignitymemorial.com/obituaries/apex-nc/john-vivi...
Debian 7 was the first Linux distro that just worked on my old PC. Believe it or not, only Debian had no screen flicker on my old NVIDIA GeForce MX 440.
Plus, it was the only distro in 2013th that had a non-free driver for that card (96-something-legacy). Imagine how old that card is when they considered it legacy in Debian 7.
With that said their 22.04 isn't out for a while and it sounds like there is a lot more involved for them this time around (just from reading this hn discussion)
I switched to debian instead. Debian packages firefox ESR, which means my config will be stable for longer.
> At least when it's packaged by the distribution someone has reviewed the changes and can flag up and disable any nonsense that mozilla is adding.
For something the size of Fx, that’s probably not happening as much as you think, unless it’s something publicly announced in changelogs. Your distribution maintainers aren’t reviewing every line of code changes between Fx releases, ESR or not.
Yea, I think this is silly.
Apps have the power to update themselves out-of-band from the package manager, so, even if you only install it via the package manager, it can do whatever it wants while short-circuiting the maintainers' oversight.
Isn't that disabled in Ubuntu's Firefox APT package?
They could have latent malicious code which gets packaged and that could download a payload and execute that (or already contains the attack). But a program without such a pre-existing ability won't be able to update itself to a version that does.
This is very different than going through every line of code and patching something they dont like.
I'm not OP, but I too consider Firefox published by my distribution (Fedora) to be more trustworthy than Mozilla's official distribution channel.
I have to use a web browser.
> For something the size of Fx, that’s probably not happening as much as you think, unless it’s something publicly announced in changelogs. Your distribution maintainers aren’t reviewing every line of code changes between Fx releases, ESR or not.
Reading and respoding to the changelogs is substantially better than no review.
No you don't, I suggest getting a different career outside the IT department, if it really bothers you that much. No reason to take the path of most resistance with something that makes you unhappy.
>Reading and respoding to the changelogs is substantially better than no review.
No, not really. The reason this stuff with snap is happening to begin with is because distro maintainers don't have the resources to maintain a ton of patches on top of a giant browser that releases every month, even if they knew there was something objectionable in the changelog there may not be anything they can do about it in a reasonable amount of time.
browsing the web is *dangerous* without them.
Exactly. The distribution maintainers are reviewers, who can remove the unwanted parts: https://pagure.io/fesco/issue/1518
> Your distribution maintainers aren’t reviewing every line of code changes between Fx releases, ESR or not.
Actually, Redhat and SuSE guys are active in the development, especially the linux-specific functionality. However, when they package it, they don't have to follow Mozilla's agenda.
Knife can go both ways here.
Unfortunately, Mozilla has enough power that AFAIK they've pretty much run roughshod over the distributions. Pretty much the only software I know of that can do that. It's mostly through enforcing their trademark.
If you know of a mainstream Linux distribution where the maintainers actually care enough to patch Firefox to remove all advertisements (including Pocket), sponsorships, and other by-default telemetry, I would love to hear about it and would consider switching to such a distribution for that reason alone. (Not because I'm incapable of patching Firefox myself or using LibreWolf, but because this shows that the maintainers care and have the correct priorities.)
Time to switch to a different distro I suppose.
Even if it is run by a trusted community member a PPA will never have the guarantees of the packages in the distro.
The bizarre thing about the Snap performance issue is that it isn't present on other distros. I have heard that Snap is really, uh, snappy on Arch (although I am seriously not bothered to try it myself).
Solutions like flatpack/snap/appimage are great (though I like snap the least) but they are for extra stuff. As much as possible should be handled by the native package manager.
Likely the idea is to let upstream to package once and ship it on all supported platforms. This way there is no constant support/packaging required from distro itself.
As to why snap format specifically, that’s probably allows them to make changes as needed without asking anyone.
Further, if you are tunnel-vision focused on profit, remember that if you lose your end users, you lose your only means to eventual income.
There is now a very nice summary comment from worik elsewhere in the thread, but basically end-users are no longer the same from Canonical’s perspective and so it’s probably wise to thank them for good things they did and move on.
As to Canonical, the only reason I use FF anyways is because it is the lesser evil. They are far from stellar with their constant attempts to inject invasive monetizers into the browser.
Also, the dynamic loader has much better performance if it doesn't need to juggle different versions. I can see the benefit for some packages that are super complex or have really special requirements. But not for every little thing like Ubuntu is doing.
But Canonical doesn't own apt. They own snap and the store can be run only by them. I think they just try to insert their own IP into mainstream linux so that they can eventually charge other distros and/or commercial customers for access. I think they're just looking for ways to monetise. Inserting your IP into the mainstream is a common way to do that when it comes to FOSS. It worked for RedHat though they are a lot more successful at it. I hate this kind of monetisation, though I wouldn't mind paying for a distro if it were made with my interests in mind. Ubuntu is going the complete opposite way though. They're serving their own commercial interests first.
It's not working out at all though because everyone hates snap and even ubuntu-based distros remove it. I hope they will give up soon, just the way they've given up on Unity, UpStart, Mir and Ubuntu Mobile.
I find them horrible from the dev side too. Canonical gate keeps you from publishing your app. Their patches to system components to make snaps work break stuff. Their stack to build snaps like multipassd is buggy beyond belief and adds another daemon i never asked for.
As many problems as AppImages have, they're probably the least insane solution. And AppImages are quite insane, so that sais something about linux packaging.
This isn't something I've heard of before.
This makes RedHat somewhat of an 'authority' on Linux. And indirectly, they have been making it harder to get official versions without paying, like what they did with CentOS.
For anyone still on 18.04 or 20.04 and not yet ready to upgrade or move off of ubuntu, you can add firefox to the "Unattended-Upgrade::Package-Blacklist" list in /etc/apt/apt.conf.d/50unattended-upgrades
https://askubuntu.com/questions/1279041/disabling-firefox-ba...
People that moved away from Ubuntu because of the same crap, what are you using now?
What other distros can I use without getting too crazy on configuring shit? My use case is booting a Linux box to develop Python/Rust apps, maybe a docker/docker compose in there and that's it.
Don't get me wrong, I love what distros like Nix are doing, but I don't have 16 years anymore and all the free time in the world to tweak my environment to oblivion. I just want to boot an environment which is somewhat standard, run Pycharm, VSCode, and code my shit on.
Thanks in advance.
And if you're not a GNOME fan, there's a KDE version of Silverblue called Kinoite or something similar that's basically the same thing but with KDE instead of GNOME.
My reasons weren't necessarily because of Snaps because Fedora has Flatpaks which are the same useless crap from my perspective. It was mostly just because I wanted things to be closer to current releases.
Otherwise its been solid.
(I personally went radical and run Void Linux. It has no systemd, basically every package is just built from upstream sources nightly, etc. Surprisingly, it's about as fiddly as a Debian box.)
I switched to Debian.
The core of my system is now Debian Stable. For the handful of packages that I want to be newer, I either pull from Debian backports or backport the Debian Unstable package myself (just a simple rebuild in most cases).
Flatpak is my last resort for one or two apps that aren't yet available in Debian. Since I don't trust the flathub/pypi/npm "accept software from anyone" model, I try to mitigate the additional risk with a few extra steps: I'm choosy about which flatpaks I'm willing to use, I scrutinize the permissions they try to grant themselves, and I install them only after rebuilding them myself with any unwanted components or overreaching permissions stripped out. (Flatpak's permissions model is broken in my view, but I think it could be fixed, and it is at least a starting place for working toward decent app isolation.)
I'll miss some of Ubuntu's Launchpad services (free multi-architecture build farm, free package hosting, user-friendly bug tracker) but I don't value those conveniences as much as I value the benefits of traditional packaging for my core tools. Overall, I'm happy with the switch.
So it's in the user's interest to use Flatpaks, and on mine, the Flatpak of RetroArch, as an example, works perfectly with zero extra configuration.
They don't specify, but it seems frequent enough in my experience. Here is what the Web site says: "LibreWolf is always built from the latest Firefox stable source, for up-to-date security and features along with stability."
> How does it fight against the duopoly of Google and Apple on the web? It uses Gecko rather than Blink or WebKit if that's what your question is asking. It's just standard Firefox with privacy tweaks and patches applied out of the box.
By not using Firefox, you remove the funds from the WebKit development. And it costs millions. If LibreWolf doesn't present itself as Firefox, it also decreases the visible Firefox usage, helping the duopoly.
I used Firefox until they lost site of their core target, and killed their mobile app's quality and extensions.
It doesn't on my phone.
Last I checked, Mozilla did everything in their power to prevent you from running desktop extensions.
If I may ask:
1. Which version are you using?
2. Where did you get that version?
3. What settings/process did you change/follow to make firefox accept all desktop extensions?
Please be as specific as you can. A link to a Mozilla resources. if you can provide it, would be even better.
Link: https://pine64.org/pinephone. See also: https://puri.sm/products/librem-5.
The Mint Firefox package is more difficult, it needs an override package which breaks Ubuntu, but Chromium is standalone.
Web browsers need to be constantly upgraded mostly because they need constant feature add-ons. They need constant feature add-ons because they want the browser to be able to render all the features of native apps with JavaScript/HTML/CSS, but they can't possibly develop every feature all at once. So they drip, drip, drip out the features. They also can't thoroughly test all the features ahead of time (permutations would require hundreds of millions, if not billions, of tests per release) so they kick the releases out to beta users and collect bug and crash reports, and fix enough of them to call it stable and then kick a release out.
Imagine if cars worked like that. "We know you're driving on the highway, but we need to reboot your car because we have a new feature (radio shuffle mode!)"
I don't really notice the startups for the rest (although I get irritated when lxd auto updates and restarts my containers), but chromium does palpably take several seconds to load vs firefox .deb
Seriously, why does htop need to be a snap??
Unattended-upgrades wasn't part of the default ubuntu install and everything updated at once. When you told it to.
Now to have the same experience you need to understand the difference between snap and apt and why you would want one vs the other. You need to understand ppas. You need to know how ppas interact with unattended-upgrades. You need to understand config files are in etc. You need to know how config file directories work. You need to know how to pin a package. It appears but I'm not sure that you need to know the difference between purge and remove.
Now if you want treestyle tabs to actually hide top tabs you need to figure out the weirdness of firefox profile dirs where its in ~/.mozilla/firefox/my-cat-walked-right-over-my-keyboard-and-had-a-fight-with-my-other-cat. Create a folder called chrome and inside it userChrome.css and either understand css or just blindly paste in some css someone else provided.
Then you need to open up about:config and change an arcane setting to make the above actually do something.
90% of that is actually useful understandings. Hey its not like css is only for themeing firefox and knowing about:config exists exposes useless things out of scope of normal configuration but in no universe should I wish my browser wasn't half as fast as windows and I wish tabs were on the side lead to that exiting 3 hour tour 1.
1 https://youtu.be/cfR7qxtgCgY
We can start having the professor run this ship instead of Gilligan any time now.
Firefox should be a Debian package by default. Installing a package from a PPA shouldn't bear on how its updated. Installing should be via a singular cli. If snap is to be integrated it should be an argument to that cli even if its not apt. Explicitly telling it to install the deb version should simply cause it to prefer that version thereafter. Absolutely none of this should require touching a config file in /etc.
On the firefox they should have found a way for an addon to hide the tabs a while ago and if the user explicitly drops a css file in their profile directory it shouldn't be gated by a setting in about:config. Meanwhile your firefox profile should be something like ~/.config/firefox/default-profile
What the hell is wrong with people.
Also it's not just "understand CSS" - if you want to do it yourself you have to enable a special firefox debug mode to be able to inspect its UI and find the right IDs/etc.
Snaps are horrible for containers because of their moving parts and I don't believe that they are any good for the server either because last time I checked: you could not have your private snap repository.
sudo apt install xdg-desktop-portal-gtk
or the Firefox snap won't be able to save or upload files, 'cos that lets it use the file picker.They included that package on the ISO, so fresh installs work - but they forgot to add it as a dependency for xubuntu-meta.
(Dunno if it's fixed yet, wasn't a few days ago.)
Fun fact: the Jetbrains flatpak images are _not_ packages by Jetbrains. If you ask Jetbrains about them, they will tell you it's a random third party (/enthusiatic community volunteer) who packaged them up. Flatpak is a shitshow and should be avoided until and only if Flathub gets better control over packaging.
I have yet to see any volunteer to refuse handing off maintenance of the flatpak package to upstream.
If they listened to your advice, there would be no flathub at all.