Ubuntu: “How are we improving Firefox snap performance?”
snapcraft.io
snapcraft.io
I used to be indifferent to the whole flatpak vs snap situation, since IMO either one is better than the traditional method of using the system package manager for everything. But now that I've had Firefox snap forced upon me by my distro, I've strongly switched over to the Flatpak camp. Snaps do literally everything worse than Flatpaks, offer a worse user experience, and they use a closed-source server for the backend.
I've been a loyal Ubuntu user for over a decade, but this Snap thing is making me seriously consider jumping ship to another distro.
And while linux mint derived from Ubuntu, the snap service is disabled by default while iirc system utilities (like the software manager) are provided as flatpaks.
I mean, there is a Hannah Montana Linux
If you want a stable and non-bloated Ubtuntu or Debian based distro for your web server/cloud instance, there are many better choices out there than Ubuntu including vanilla Debian.
If you want a batteries-included Ubtuntu-based Windows/MacOS alternative for your PC/laptop with video codecs, proprietary firmware, drivers, and software at your finger tips, then PopOS, ElementaryOS and Mint are much better and saner alternatives for the Average Joe.
Feels like the only thing keeping Ubuntu popular is inertia, brand recognition, lock-in effect and the strong influence of Cannonical, but I just can't recommend it to anyone anymore. It seems like Cannonical is so out of touch, it lost the plot a long time ago with what made Ubuntu the linux distro for over a decade.
It is, sadly, for everyone. Writing Github actions workflow? That's on Ubuntu (and you'll need to use Ubuntu for self-hosted runners for more success). Aiming to install a random package binary for a random project you've found? That's probably for Ubuntu. Need any enterprise/MDM stuff? That's probably Ubuntu.
We need people to start offering (or demanding) alternatives to Ubuntu before we can reasonably move off of it.
It felt like Android on the Pixel compared to the heavily modified and bundled versions everyone else shipped.
Snap would take my machine a minute to launch the calculator app back in 18.04 I think. And I really can't live with apps auto updating whenever the developer releases a new version. Lack of control over updates was what drove me from Windows in the first place.
1. Sometimes it will warn you when uninstalling a snap will break other snaps; most of the time it doesn't. I removed some snap recently, and Firefox stopped launching.
2. The snapcraft CLI is awful. No way to disable colours, no man pages, no proper error codes, etc.
3. Every time you need some non-trivial piece of functionality, you have to go to ask Canonical for permission. The permission is, most of the time, granted relatively easily, but still.
4. The plug (permission, basically) system is confusing. The documentation is sparse and often doesn't actually answer, which plug you need. And you pretty much have to install snappy-debug (using snap, of course!) to find out approximately, which plug you'd need to add. Thru Canonical, of course. See 3.
5. No way to have your own instance of snap store. If you want to find out, why the upload fails or if the plug will work properly, you have to actually upload a snap to the actual Snap™ Store®.
6. Firefox cannot access /tmp/. A truly baffling thing.
The day Mark&co. finally realize that this thing won't work, no matter how many things they force into snap, is the day I will start a three-day party, heh.
More importantly I would ask: why do I have to learn a new cli? For the convenience of canonical?
I don't see how snap is faster than apt/.deb. More importantly, apt would update a running Firefox which you can restart later. With snap, Firefox is not updated until you close Firefox and run `snap refresh`.
And yeah, you could probably fix that by shipping debs with a statically linked Firefox, but that's not how apt packaging is traditionally done.
At least that's my understanding of things.
Sorry for going on a bit of a rant under your post, but I run into this on the regular.
The fact that the latest Firefox is in rolling release distros/channels but not in stable ones does prove the point a bit; you can either get a new Firefox, or you can get a tested Firefox. I generally prefer rolling releases, but I've had Firefox break in weird ways on Arch from time to time. The only way to get a Firefox that's both well-tested and up to date is to use builds from Mozilla where libraries are bundled, such as with a snap or flatpak.
https://neugierig.org/software/chromium/notes/2011/08/zygote...
Worse, they display a misleading pop-up notification telling you Firefox needs to be closed within X days to update. However, closing Firefox doesn't update it, and it doesn't actually tell you how to begin the update or when it will happen automatically. After searching the internet, it turns out you need to open a terminal and run a command to update it manually.
It doesn't seem like Canonical has any kind of UX team, or if they do then they're asleep at the wheel.
I suppose it was always a bit weird, since I shut my desktop down at night so there's never more than a day since Firefox was last restarted.
The same idea applies to all libraries, where the old version of say /usr/lib/firefox/libxul.so can still be referenced by the running firefox process even after apt has replaced it with a new version.
It's not a great system honestly, Firefox will launch new processes sometimes and the IPC system kinda breaks down when the parent process and the child process are from different Firefox versions.
That hasn't been my experience on Ubuntu for a while. Regularly when updating opening new tabs will display a "just one more thing to do" dialog prompting me to restart firefox. On debian 11, if an update took place firefox will sometimes keep working in a kind of degraded mode (inspect tools don't work for instance) until restarted.
edit: at the moment I can't use netflix until restarted but I don't want to restart because I have a private window with tabs I want to read later.. Sigh.
there is plenty to complain about modern software but "random walk without any intention behind it" is neither fitting nor in any way true nor helpful diagnosis
The reason it no longer works is that tabs run in separate processes. This means that if a tab causes the engine to crash, only that crash (or a small number of tabs) crashes, while Firefox itself and all other tabs keep working, and if there's a sandboxing bug, you still have process isolation which prevents one tab from spying on another. But it also means that if you replace the binary without restarting Firefox, the parent process and the content process will be different versions and they can't really talk to each other.
Software engineering is all about trade-offs. We get improved performance, improved security and improved reliability, and we pay with increased memory usage and a less smooth upgrade process. Personally, I'd say that's a clear improvement.
TL;DR: right after launch, Chrome forks off a helper process which is then responsible for forking off child processes, so that all child processes use the same process image as the main Chrome process. It also opens all files it will need right after launch and just re-uses the same file descriptors, so it always keeps references to the old files. This is complicated and brittle and a source of bugs, but when everything works and nobody makes a mistake, it means the old Chrome can keep running without problems even after all its files have been replaced with those from a new Chrome.
At least that's how it worked in 2011 according to Evan Martin.
Snap/flatpak/distro packaging is redundant for this. I do the same with Intellij and a few other things. Annoyingly, chrome does not have arch packages so I'm dependent on some community package.
Firefox (at least in the past) used to break if you updated it while it was running (i.e. replaced / deleted / added files its active runtime depended on). So you had to restart it. In a containerized world, this goes away. i.e. you can replace the firefox "image" with a new one that will be used next time you restart firefox without breaking the existant running one.
with apt/deb you can't do that (besides waiting to update). On a multi user system (less prevelant these days for desktop use, but still existing) this can be really annoying to coordinate.
This doesn't answer if Snap is the right technology to do it, just why apt/deb (and related tech) have issues that they can't really solve.
I've got no problems with my sandboxed Flatpak Firefox.
> Why did we choose to make Firefox a snap?
All pros are shared with Flatpak.
What is the value add for users here, that couldn't be gained by using Flatpak instead? Because it certainly isn't your proprietary app store.
My key problems is that I care less about Firefox being snappy as it not making the rest of my system slow:
- I don't know what bug X has, but application should not be able to commender my mouse cursor. I've seen bugs in Firefox+Ubuntu multiple times that feel like they might have security implications.
- A web page should not be able to use 100% of a CPU. There should be some kind of hard limit, perhaps with burst performance as well
- Related to the above, a background tab shouldn't drain my battery if I'm on a laptop. I don't want to give random web pages 100% of my CPU.
- Firefox should not be able to keep sucking RAM. I have hundreds of GB of swap, primarily so I don't need to worry to Firefox/Chrome/etc. memory usage/leaks. That's crazy.
- Firefox should not be able to suck GPU resources. This is a place I'm convinced there are issues with security implications. GPU drivers are engineered for performance and not stability, and there are edge cases.
- Less relevant to my system, disk usage is an issue on many smaller devices, with offline storage in browsers.
- Bandwidth limits for pages would be nice too, for both 5G bandwidth and battery.
I'd love to see richer benchmarks. Even if not optimized, I'd feel better if Ubuntu / Mozilla were actively aware / looking at these sorts of things.
I'd also like someone to think through concrete ways in which snap helps my security. Firefox can overwrite arbitrary files on my system (save-as -> pick one of your files). That's convenient for me, and for an attacker. An open sandbox doesn't help much.
I'd love to see a holistic mile-high view where someone thinks through resource usage (across different types of resources), convenience, and security). Implementing snap without that type of homework seems premature.
As a footnote, a lot of the issues might be solved with copy-on-write, both with regards to performance and memory.
I agree.
Process sandboxing should be independent from program packaging and distribution. It should be a core feature of your operating system (and it already is!) and not controlled in any way by the people who distribute the software: mozilla, canonical, etc. If you decide to sandbox some program, like firefox, or gimp, or inkscape, it should be easy, and out of control of other people. You get to decide the amount of resources that you want to give the app, and not the app developers themselves! Why this is not obvious to everybody is beyond me.
Unfortunately, both snap and flatpack fail to use this sane approach, and try to shoehorn unrelated stuff like package distribution, dependency packaging, and app stores to this simple problem.
The place where I've always wanted to see this is on my phone. I would like to be able to deny apps network access, location access, contact lists, etc. This should not be a series of continuous pop-us ("let us scrape your data or you can't use our app"), but simply return a sandboxed empty contacts list (which the app can manage), a sandboxed storage for photos (which the app can add / remove photos from), and a random set of GPS coordinates.
Firefox has errors, but no hostile code. Most apps seem to have hostile code. It's almost impossible to tell how hostile that code is for which app. Even when I do want to grant access, it's almost always too much. Many apps which have valid reasons to e.g. take and store photos, but that doesn't mean I want them to be able to copy and analyse my personal photos.
That is no reason to avoid updating. I use the latest Ubuntu and just uninstall snap. It's not needed for anything.
Installing latest LTS Ubuntu involves going through this whole annoying process all over again.
That's not to mention the sketchy app-stores, cross-sells, etc. It's a lot less sketchy than Windows or Android, but it's not a good direction. No, I don't want an app store. No, I don't want to send data to Ubuntu. No, I don't want cloud services, accounts, and whatnot.
Come to think of it, an up-sell I would pay for is an option to download Ubuntu without all this crap. I understand they need to stay in business, and I wish they'd do so without annoying me.
That said, the performance issues aren’t as bad as the fact that it’s unusable on machines with NFS home directories mounted with root_squash (as documented [0] by someone at another institution).
We’re a University CS dept with a few hundred lab machines and have been using Ubuntu for the past decade or so, but fighting against the increasing snapification every LTS is frustrating. Next LTS we’ll probably just switch to another distro. Most of our users don’t really care which distro they use - they just want Linux with NFS home, a browser, JetBrains, VS Code and a Bash shell with access to our standard compiler and tool collection Our HPC team recently switched from Centos to Alma - though I’m more inclined to stay with a Debian derivative (or more likely Debian itself).
[0] https://utcc.utoronto.ca/~cks/space/blog/linux/SnapsVersusNF...
A few weeks ago, my mother (who uses Ubuntu) asked “Why did inkscape just discard every change I did?”. I went and checked what's going on, and apparently the snap version just doesn't open any file dialogue. She hit Ctrl-S to save and (very understandably) assumed it saved it. Well she lost 3 hours of work. Installing the debian package fixed it, and, as a bonus, it started following the system theme and stuff.
Such subtle bugs are everywhere. I don't even know where to begin investigating it, and frankly, I don't care enough. Snap is a bad, overcomplicated piece of technology that deserves to die.
should? no. That takes some time, and noone is obligated to help Canonical with their disastrous project designed to push proprietary app store
(I work on the Firefox install/update system, and previously CI & release systems.)
For example, I installed Ubuntu 22.04 (in a VM) and installed VNC server so I could access it remotely. Surprise! Firefox and Chromium (snaps) don’t work. So one of the things I rely on is broken and I bet it’s going to stay broken for a long time.
It’s been like that for 20 years. VNC is old and boring and the devs creating things like SystemD, Snaps, etc. don’t care if they break it because they think their “progress” is more important than having a working system.
Semi related, why are all the Remote Desktop solutions on Linux so awful?
A generalization too broad, as pretty much no other distro except Ubuntu uses it. If anything, it's more emblematic of Canonical's neverending desire to reinvent the world and the NIH syndrome.
> Semi related, why are all the Remote Desktop solutions on Linux so awful?
I've never had any issues with plain old X forwarding over SSH. As long as you have compression enabled, performance for most applications is fine.
Sure, the Linux kernel is on almost any smart device in the world making it the most popular, but in the PC/laptop space, its market share is still absolutely tiny (<3%).
Right, just like how the Windows Store is the reason Windows will never be mainstream.
It really gives me the impression that the effort is mainly about achieving some sort of theoretical or business goal, with user experience being secondary.
snap app store is proprietary and controlled by Canonical
Instructions to install a .deb and prevent the snap from installing: https://www.omgubuntu.co.uk/2022/04/how-to-install-firefox-d...
I'm going to remove snap from my system and see if things improve, but overall 22.04 is a big disappointment.
A less technical user would never figure this out and Ubuntu would be unusable for them in a work environment (inability to interact with email attachments being a non-starter).
Remove each snap package until there are none left, purge snapd, install Firefox in any other way you feel like. And that's it.
I've since moved to Arch, and I'm much happier. But snap was not the reason.
If anyone knows a more authoritative source of distro popularity, please reply.
Could all be an artefact of the way Google classifies searches into topics, though.
For me it is as bad as when Canonical put ads in start menu ( https://www.howtogeek.com/126995/how-to-disable-the-amazon-s... )
Huh, that was Ubuntu 12.10. I wonder who will appear in Ubuntu 32.
Do other people have the same reaction after trying to live with it?
everything else had bizarre issues caused directly by snap
I have not confirmed that Snap is at fault but that is my bet.
Long story short, Snap said I couldn't have that :(
Kudos to the team working on this.
I just don't like Snap (or Flatpak, but less so, since it actually seems to work without breaking desktop integration).
Whenever I do need to use an Ubuntu desktop, I now install MS Edge or Epiphany instead.
It's win win situation.
They are trying to forcefully push something that no one wants or needs and that is frankly inferior to Flatpak.
here's hoping that, similar to the desktop snafu, Ubuntu/MSFT realize that forced (user-hostile) defaults are not the only possible way forward here.
98 language packs, is it normal Firefox?
Positive things I see:
- It gives much more flexibility to Canonical in terms of introducing changes in the system. It might mean that they can also simplify the maintenance of the distro and focus in other much more important areas.
- It gives the developer much more control over the release and distribution process.
- It allows to use newer versions of the software were before you had to stick in some cases with very old ones provided from the repo or go and spend a couple of hours reading and compiling the new version yourself
- It integrates well with command line apps, thing that Flatpak doesn't do natively.
- The process of creating a Snap is fairly trivial. A simple easy to grasp yaml file pretty much that you can place in your repo.
- It provides better security by sandboxing the app and allows granular permisology via plugs.
Things to refine/improve:
- Speed. It is something I haven't noticed myself, but I heard people complaining about this many times.
- Allow users to pick an specific version from a history of releases for a given app. In an ideal world, newer version would mean always "better" and therefore, upgrading automatically to the most recent one would be desirable, but we all here know that this is not the case and sometimes you just need to use a few releases back one.
- The Snap store. There are two things I don't like:
1. The backend is not open source.
2. It is a central place controlled by Canonical. In my opinion, Canonical should make the backend available for others for allowing them to make their own stores if they want and Canonical should focus in the added value of their own (e.g providing malware scaning, payment processors, CI/CD, stats etc)
Overall, I am not a Ubuntu user myself but I can understand, from a technical point of view why Canonical is trying to push for this. Unfountunatly, they are not Apple and they operating in a comunity of users that do not deal very well with impositions and pretensions from a company (and cheers to that).
Having said that, I would recomend to the comunity in general to try not to be that toxic, negative and argumentative. At this point, I seriously think the worst enemy of the GNU/Linux is the comunity itself. IMHO, we should be more constructive, less arrogant and less ideological. The amount of hate I've seen towards Canonical, Snap, Systemd, Gnome and what not is simply bonkers.
I dunno, I am only slightly inconvenienced by it, not enough to run apt uninstall snap though.
That should amass enough hate for everybody.