Ubuntu Snap update spoiled my World Cup Final
circusscientist.com
circusscientist.com
The number of times I've been hacked and suffered a data loss is astronomically small compared to the number of times I've had something update and suffered a data loss, or more importantly the number of times I've had something update and cause a regression or break something. Then I have to spend my precious time bringing something that was PREVIOUSLY IN A WORKING STATE back to a working state, which is one of the most infuriating feelings.
Most other software should only update when specifically instructed to.
That's not a sane decision. Sane would be to update on closing.
Same way Windows offers to "Update and Shutdown" (you don't need the PC anymore why don't I under after you walk away) and not "Update on next Start up" (I'll wait until you need me to get in your way).
This presumes that shutting down is never a time-sensitive action. If I had a nickel for every time Windows decided it wants to spend a half hour installing updates when I'm trying to shut down a laptop so that I can put it in my bag and go somewhere with it, I'd be able to actually buy a Windows license instead of resorting to vlmcsd.
Quora always had reputation for being shit but I am impressed by how terrible that page is. I mean there are only two 2 types of answers there: "Window$ is BAD" and stuff that looks like generated by GPT-3( or straight up from those infamous "recipe sites" a.k.a. SEO farms).
Perfect!
Windows does sometimes get it correct.
Though I never seen it on Fedora or Windows, might be some quirks related to Ubuntu packaging.
On Windows, where no standard update mechanism exists, Firefox updates itself, so it does it only when it knows it's fully shut down (before it opens or after you close all windows).
And for Windows there is standard update mechanism - Microsoft Store - which also does the same sane thing.
So it's Ubuntu implementation problem, and not a Firefox one.
Do I understand correctly that it is based on systemd's offline upgrade mode, i.e. installation is done at the following boot? If so, you can do that on Ubuntu too. I'm not sure how (perhaps by invoking apt-offline?), but at least KDE Discover does it on Kubuntu.
Most software does fine, as long as it has already mapped in all of its libraries, those files can be unlinked in the filesystem, but will remain on disk in their current form. You do run into trouble if the software is part way through starting up and hasn't mapped all the libraries, or if you update the files rather than unlinking and copying new ones (at least, FreeBSD lets you update mmaped files and all processes will see the updates, which is usually not what you actually want when the files are code).
Windows makes it very hard to update program files while programs are running, so it's not surprising Firefox endeavors to do updates while it's not running.
This doesn't seem insane to me, but might not be an easy thing to fit in to the large body of code that's already there.
You still have issues if you're starting up during an upgrade, but that's a problem with anything dynamically linked.
I don't think so? As long as the main process is separate from the seed process, and the seed process is forked before specialization.
> It also makes address space layout randomisation less effective, because every forked process starts out with the same base memory layout, doesn't it?
Yeah, I think you're right. Not sure if you could maybe do some randomization post fork, but you're probably right.
Are you sure that originates in the update check? The update itself is downloaded asynchronously while the browser runs. The browser itself checks if an pending update has been downloaded when it is launched.
I don't think this is a fair decision. Virtually nothing requires such a forced update. And the browser should be sandboxed by the OS anyway.
That's not been my experience. I don't know what system you're using, but with Firefox on Ubuntu, I discover that Mozilla has put out another (goddamn) update (again, already, goddamnit!) when all my tabs suddenly crash, forcing me to restart the browser.
Ubuntu doesn't seem to realize (or simply doesn't care that) enterprise servers and user desktops are entirely different beasts.
Eek hard disagree.
Most things I want to auto-update. Preferably at 4am. Somethings I want to disable auto-update.
What I never want is things to update when I’m in the middle of something.
Yes. For user orientated interactive systems it is mad.
But it has its uses, IMO, for IoT devices.
It was the reason I do not use Ubuntu on my personal computer. If I were in the business of building connected devices I would be interested.
When Ubuntu prompts me to restart the system after an update I can dismiss the dialog even for weeks, but at a certain point the cumulative updates start making the system behave erratically and I have to restart. Probably kernel, drivers, libc, other vital stuff get too much disaligned.
Parts of the program were updated and now the program is in a not tested, half-updated, half-old state.
The "other choice" for Mozilla is pretending nothing happened, attempt to open the tab, probably immediatly segfaulting and losing all your current work in a potentially unrecoverable way. Not really a good choice under most circunstances.
Is it very not true? Apt restarts processes and services all the time during upgrades.
I don't think it's true, I had the disable unintended upgrade on Ubuntu because it runs cpu at 100% and make very big noise at night.
If updates were not automatic a large number of people would not upgrade and would not receive important security updates along with various fixes and new features. If a user keeps running into a bug that has already been patched in a newer version that user will just think your software is bad and they will not realize that this poor experience they are having is because they are on an old version.
>The number of times I've been hacked and suffered a data loss is astronomically small
Being hacked even once is a bad thing. It is something that the industry tries to minimize as much as possible.
>the number of times I've had something update and suffered a data loss
Personally I have not experienced this, but it sounds like this would still happen when you update later. This is why doing gradual updates of rollouts and collecting telemetry is important. It is very useful in being able to detect a bad update and stop it from going out. Unfortunately, the Linux ecosystem is still behind the rest of the industry which leads to people having a poor user experience.
The "generic" response is beacuse the complaint is simiarly generic.
My personal experience does not match this at all, so is the explanation there that I'm just lucky?
Because software is never finished. There are always bugs to fix, new platforms to support, new features to be added, more polish to be added, etc. It is the developers goal to have the quality of their software to go up over time.
It is in developers interest for their users to remain secure, not experience bugs, have a good experience, and to solve a problem or need they have. Updates to applications try and address one or more of these things.
If making the user's life better is a cargo cult thing. Then maybe that cargo cult isn't such a bad thing.
If you are specifically talking about why should you care about a chrome 0day patch because you've never visited a shady site that tried to exploit it then the reason is that it's important for the ecosystem to be seen as secure. You want to make it as least financially viable to exploit Chrome as possible, you want to ensure people think of the web as a secure platform they can use without being afraid, as Google you want to avoid bad PR about a big hack. The first point is important. You want to increase the customer acquisition cost for an attacker which is "the cost to get a visitor divided by the chance a user's browser has not gotten the patch yet." (In proctice different demographics may have different patch rates which lowers the CAC my targeting that demographic) Google's lever for increasing an attacker's CAC is to use autoupdates to lower the chance. When CAC > LCV (lifetime customer value) then the attacker does not have a financial incentive to compromise users and this results in a large drop in the rate of attacks. The required updates remove the incentives to use the attacks which is why you feel like you aren't being targeted.
It's like how some management don't understand the value of a system administrator because when a system administrator does their job correctly everything appears to just work. When security updates are properly going out it may feel like they are unneccessary, but that just means that the defenders are doing a good job.
Security wise for most applications there's the oft overlooked possibility of just not connecting to the internet. Though when it comes to my personal experience running antivirusless Windows with updates disabled it has not been a problem for me for a decade now. According to my router I'm not part of a botnet either. It just doesn't seem necessary at all. Your attack surface as an individual on a reasonably well secured network is minuscule and your threat model is basically just the background radiation of bots trying whatever random exploits. Sure, I keep my router patched because it's on the edge, but other than that it doesn't matter.
Though I will give you that browsers are a special case where the tool is specifically used all the time to connect to potentially hostile content and give that content the ability to execute code on your machine. Things on the edge are a scenario where keeping up with security patches actually make sense.
Before we get the point where we are discussing aspects like under what conditions should updates be applied or the priority of which updates should be installed first, desktop Linux needs to show that it can handle the basics.
Upgrading Android apps does not need a reboot of the device either. Again live patching is a separate feature from automatic application updates. If you read the article it shows a case where a Roussel is fruterated with how live patching is broken on desktop Linux. Meanwhile on Android apps don't do that when they are updated.
From my experience the only real work load with Arch was the set up. Once I installed it and configured everything to my liking there has been nearly 0 work with maintaining the system. I've been running my installation of Arch since 2016 and the system didn't break even once.
I'm not philosophically against Snap as an idea. But what I am against is all the absolutely terrible UX decisions and bugs which Canonical evidently considers "acceptable". It makes the whole Linux desktop look like a joke.
Maybe it's time to realise it is a joke. That Linux will remain a programmer OS and an OS for locked-down consumer devices, but not a general consumer desktop-style OS. And maybe we should recognise that in such a world, there is no space for Ubuntu Desktop.
The stability is nice while it lasts, but I've had way too many major things break when upgrading to a new release. The most extreme case was the time Ubuntu 19.10 broke GDM, so anyone with an nvidia card and auto-login enabled had their system bricked. This is even though I reported the issue a long time before the release, and there were very reasonable workarounds proposed in the issue discussion in good time to fix the issues before release. Ubuntu 21.04 released with a nextcloud-desktop application which segfaulted on launch. I also reported this a long time before release, and it was ignored because they had already frozen the packages they import from Debian, so I had to deal with a desktop which couldn't sync my files.
I haven't experienced similar huge issues in Arch, but more importantly, when an issue does occur, I can expect a fix to be out in days, not weeks or months.
1. Applications Menu - for when I forget the name of an app but I know more or less which category it belongs to.
2. Custom Hot Corners - to disable all actions started by moving the pointer to a corner.
3. Dash to Panel - The important one: panel to the bottom, intellihide the bottom bar, show the taskbar, position the date and system menus, background color, windows previews, workspace isolation, ungroup applications, disable gestures,
4. Desktop Icons - this seems to be a system extension, the only two icons I see are the trash bin and a link to my home directory. I'm not using them from the desktop.
5. Extensions - an extensions menu, useful only when I don't have Firefox open, so basically never. I could remove this extension.
6. GSConnect - not related to desktop customization but even more important IMHO. It's the GNOME implementation of KDE Connect.
7. Notification Center - notifications from the bottom right, in a menu, etc.
8. Places Status Indicator - a menu in the bottom bar with the bookmarks defined in the file manager.
9. Recent Items - a menu in the bottom bar with the recently opened documents.
10. Simple net speed - current bandwidth used by my laptop, in the bottom bar.
11. Sound Input & Output Device Chooser - list of sound output and input devices, set volume per device.
12. Start Overlay in Application View - very important one: when I press the super key I get the list of the available applications instead of the outlines of the open windows (what would I use them for? They are already on my screen.)
13. User Themes - to let me install a theme from my disk.
14. Workspace Switch Wraparound - I have one workspace per customer plus a couple for me. They are arranged horizontally. I go to a workspace with a hotkey but I also move with super-alt left/right and if I want to move a window across workspaces I do it with ctrl-super-alt left/right. This extension makes moving leftward work even on the first workspace and moving rightward works in the last one.
15. Workspaces to Dock - The other important one: it completes Dash to Panel at undoing the remaining default choices of GNOME Shell. Intellihide of the bottom bar (again?), no animations, never see workspace thumbnails, hide the workspace switcher.
I'm not missing the irony of throwing a lot of code at undoing the effects of a lot of code written by GNOME in the last decade. At least they still let us do it.
If somebody's asking why I'm not using another DE: I want to stay on the mayor ones (support and maintenance.) Why not KDE? I had bad memories of KDE around 2014: twice as many clicks than GNOME to do the same thing, especially in settings. Somebody told me that it got better but there is little incentive at investing time to only get where I am now. I'll do it if and when I won't be able to bend GNOME to my desires.
Arch has severe problems in my mind especially in stability, but as you say it is easier to fix stuff and that is a huge plus. It's just a trap I try to avoid for my desktop!
Thanks for the explanation makes a lot more sense now!
So if you use the LTS, and the outdated packages isn't an issue for you, it makes sense that you'd be pretty happy with it. And maybe that's a use-case I'm underestimating.
Arch has been nearly maintenance free, and it's been the one distribution where when I did break something, I was able to fix it 100% without nuking and starting over.
I still can't bring myself to run it on servers for some reason, and I go back to Debian stable for those, but honestly, I'm not sure why. I'm starting to feel that a rolling release would make for a lower maintenance server because it's always a PITA when the inevitable end-of-life comes into play and the upgrade inevitably fails and I have to reconfigure everything anyways.
Ubuntu in contrast would ALWAYS find new and bizarre ways to break. ESPECIALLY when snap came into play.
The only reason I reinstall is when I upgrade my box every 2 or 3 years. Years ago Arch was a bit more finicky, but today it's been perfectly stable for me, doing updates every Friday.
This also lets you download and install DEBs manually from projects that support Debian or Ubuntu DEBs but aren't in the official repos yet.
I'm using bspwm no DE, but I'm considering trying Arch+GNOME now that I've been forced to move to Ubuntu for work with my new job.
(Was already leaning towards moving, because a rough monitoring of security updates over several months showed Debian was strangely more trustworthy. Snap making things even worse for some of our systems made the decision easier.)
I fought with a guy in 2015 that believed snap was the future, and this cost me almost my job back then.
Well, Canonical has your back on that with apt installing snap packages.
Upstart worked well for its purpose. It gave me zero problems and a faster boot until systemd came along. It was a good stop gap solution and was adopted by other distros including ChromeOS.
People like to criticize the "different on the block" and although I think most of these complaints are for good reasons, so much is learned from these mistakes that we should not be so avert to them.
I don't think snaps are better than flatpaks, but I'm glad there is an alternative to it under a different management and having a good influence over it (IIUC, "portals" were born in snaps, not in flatpaks).
The 2 key issues with Wayland, the fact that it's a protocol, meaning a lot of stuff needs to be handled by the window manager that was handled by the platform before, and its opinionated design, that made it very hard to port software that wasn't designed exactly how it wanted to be, meant adoption was (and is) very slow, and still kind of ongoing.
Mir didn't have these issues.
It was awful.
Debian is looking attractive.
Abandoning snap is not enough, it's more about respecting users ... but they are obviously under no obligations to me, I'm not paying.
Not because it necessarily made anything harder, but because it was an arrogant change for no goddamned reason.
UX should start with humility -- if you change things that lots of people are used to then you'd better have some damn good reasons.
RIP Unity
(Firefox updates at random time, then kindly asks to reboot by replacing each webpage by a grey one with a restart button, and it doesn't restart tabs in private windows)
It's a very Firefox problem, not snap
(I use PPA and not Snap because snap outright doesn't work when your home isn't /home/uname , and mine is /home/company_domain/uname ) (I can't believe that ubuntu forces you to use a software that isn't production ready)
I understand why they push so storngly to frequent updates and consider that idea mostly as good. However that implementation always makes me furious. I am in some workflow, doing some form of transactional thing and suddenly it decides to stop working without restart, where then half my work is gone. If they'd say "hey, new update ready update in next few hours" I'd be fine and could schedule it (well I would still not like it as I hoard too many open tabs thus restart takes time ... but could tolerate)
I install Firefox in such a manner and can confirm the behavior is what you have heard. I've never seen the "please restart" page.
When I found this out it really pissed me off so I tried to figure out where the restart screen showed up in the source code so I could patch it out. But I'm not familiar with the code base and left off after a bit of digging because I really can't justify the time spent.
In reality I end up holding back Firefox updates with my package manager until I'm ready to restart it. In the end I will thwart developers trying to dictate things to me. The software on my computer works for me, not the other way around. A lot of developers seem to be far too arrogant and forget this basic fact.
So at any point the browser needs to be able to potentially launch a new child process if you open a new tab, or even just browse to a different website on a different domain (origin) – which thanks to site isolation nowadays requires a separate process, too, unless perhaps a page from the same origin is already open in a different tab.
If thanks to an ignorant update service the browser's binaries have been swapped out from underneath it, that now means that you've got an "old" parent process suddenly talking to a "new" child process, which isn't an officially supported configuration.
If you're lucky, there were no breaking changes within the browser and things might work anyway, but there are no guarantees that things always turn out that way, since the API between parent and child processes is a purely internal one and browser developers feel free to rejigger it any time they need to.
While in principle you could try to develop the browser in such a way that a certain amount of forwards/backwards compatibility is preserved between an older parent process talking to an updated child process, I presume that doing so would also significantly complicate development on anything that touches the parent/child process interface, and you could equally claim that it's Linux's package manager behaviour regarding updates (just swap out the files underneath a running process) that's broken.
I'm using a regular Arch installation with Firefox and Pacman. The "please restart" page appears regularly; I just had it yesterday. This occurs when running `pacman -Syu` in some background terminal while Firefox is active.
1: https://wiki.archlinux.org/title/Pacman#Skip_package_from_being_upgradedUsed to be able to also run Fedora distro upgrades while the system is running, now we're back in Windows-like territory, where I have to restart the system and wait for it to re-install 2-3k packages pretty slowly.
The only real workaround for this is systems like NixOS where the previous version is left intact when you do updates.
I was sharing my experience to illustrate that Arch does not have any protection against this problem _by default_. The post I was replying to was comparing Arch's package to a manual installation.
I usually open a new tab when I want to do something in that new tab, which makes the disruption very annoying. (As far as I remember, it also blocks loading of new pages in existing tabs thereafter so the disruption is total.) Then during the restart it loses all info in private tabs.
Regarding the "excuse" that it is the package manager that updated the Firefox in background, I saw it repeated a lot of time to deflect the blame, but it is totally not true in my opinion. On my system, I don't allow automatic updates. I have the notification when updates are available, but the system/packages are never updated without me doing it. And still, I noticed multiple times that Firefox breaks suddenly, like that, when nothing was updated on my system for some weeks and everything was working fine.
For me on arch Firefox has shown the "Need to restart" page every time I have updated it's package while running and not a single other time.
It really is a ubuntu problem.
that happened to me several years ago despite automatic updates being explicitly turned off - I actually have a screenshot of the settings page next to that gray one
Consider going to your settings and changing your update preferences. Firefox only shows the "please restart" page when it's already been updated, in your case (from a PPA) by something else like your OS upgrade service.
It'll also keep your existing tabs working as best it can, only new tabs will show the restart page. You should restart anyway because the underlying libraries have been swapped out from under Firefox while it's running that makes Firefox VERY crash prone for very obvious reasons.
I have uninstalled Snap Firefox and installed PPA Firefox
Suddenly it updates, and when I restart, the PPA Firefox is gone! It is back to the Snap Firefox
Also the Snap Firefox does not start, because I use a user that is not in the snap group. So after each update, I have to uninstall it and reinstall the PPA one
How do I disable the snap updates permanently?
Now if you run 'apt upgrade' and hit 'yes' without looking, you might be updating Firefox while it's running. Or maybe you use unattended-upgrades. Either way, not a Firefox issue.
Found this thread from more than 2 years ago:
https://forum.snapcraft.io/t/x11-connection-rejected-because...
Just find any HN thread (or probably Reddit and Twitter threads) about ubuntu or snaps from the last few years and you'll see.
At this point it's akin to starting smoking today then acting shocked when you get lung cancer.
I've decided to delay my upgrade to 22.04 given Canonical's increasingly aggressive push towards Snap, and now I'm considering moving to Arch or some other distribution.
[1] https://bugs.launchpad.net/ubuntu/+source/snapd/+bug/1575053
Canonical employees in that thread have repeatedly said they basically don't care about the opinion of the people affected. The latest reasoning provided being that they don't have the resources...
But either they have so little resources they shouldn't be pushing snap in its current form at all or they're lying (and the former reason still applies).
Either case it's disappointing and will slowly destroy all the goodwill they had.
They fixed that. But I hit into it's idea of security - being unable to open html files on my local drive, unable to load links from my mutt client, and unable to download and save directly into a specific folder.
And worse, the snap updates just don't function well. They remind you when you are using the program, and they don't seem to update when you're not using it.
Real shame, but these are fixable problems.
On Linux Mint you install Firefox normally through apt and it works fine.
I decide when I update it. As it should be.
(Sure tech like appimage or flatpack has its place but the browser can be handled perfectly fine by the normal package manager of your distribution.)
Debian.
Another alternative with much less change would have been Linux Mint: it still is a fine-tuned Ubuntu, but without the Snap Store.
I'm on Fedora these days, can't see ever leaving it the way things are going. It's rock solid and seems to be driving the state of the art in Linux things...
It's sad that now we have to fight against the OS like on Windows.
And yes I will definitely be re-watching the game after I have finished installing Arch.
I also signed up to Cloudflare due to you all hammering my server last night!
Why can't something be coherent and powerful behind the scenes but slick up front for users who don't want to think too much about the complexities of software managment?
In short they are doing the exact same as Microsoft does with Windows, but the enemy this time is inside the gates.
But no, instead of continuing it will do one of several things:
- show a blank page after entering URL or search term (no feedback, it just does nothing)
- fail to refresh the tab
- crash entirely
- helpfully suggest you restart Firefox in one of those tabs that stopped working earlier.
It is embarrassingly bad, just like the overall UX for Mozilla products is unfortunately, but alas the only other choice is brave and its even worse somehow. (Chrome proper would also be fine but Firefox is the only multi platform* browser that supports custom sync etc)* Firefox is horrific on android too - broken rendering, blank pages until you engage the address bar and hit go again, etc, add-ons basically unavailable...
I don't know a ton about Canonical's business model, but was the idea to get everyone hooked on snap and then force a subscription out of it?
Snap is the antithesis of apt or dnf in regards to what I want out of a package manager.
Also, it is bizarre that they desinged a software delivery system with no option to disable auto-updates... and only adding the option now.
And the fact that Firefox frooze during the update is also strange. Not sure if it's a snap problem or Firefox problem.
As a long-time Firefox and Linux user (started using Firefox when it was alpha version and Linux around 2002), the best decision I made around 3 years ago was move to Windows and Edge.
Mac OS prompts, and that's better than anything else.
Snaps are also abysmally slow. And while I'm complaining, they also occupy my `mount` output so that's annoying.
2006 I remember Italy v France was very exciting.
1954 was supposedly pretty exciting with allegations of doping, blatent fouling, and a very dodgy offside call against Puskas.
'58 was also supposedly pretty exciting (certainly a lot of goals)
'66 was a great one for me as a Brit, but also interesting because of the stolen trophy, yet more doping. The match itself was also tense, with a last minute free-kick pushing the match to extra time, the first (and only) hat trick every scored in a WC final, the controversial third goal and the final goal scored while the pitch was being invaded.
'90 was interesting because of the sheer dirtiness of play.
'98 is interesting for me because it's the first World cup I really remember following closely, but not particularly noteworthy as these things go.
That said, 2022 was a very exciting final and will go down in World Cup History.
And definitely nothing should kill a browser without explicit user confirmation.
I like watching the WC because soccer is interesting enough to see once per Olympiad on the world stage. The final today had some amazing shows of talent and teamwork, but it is primally revolting to me to watch grown men writhe in faux agony with one eye on the ref, when their opponent's foot whiffed some air past their shin.
If it’s side by side then why does it even affect the old version it force a restart? And if it’s not side by side then who the hell designed it?
https://snapcraft.io/docs/keeping-snaps-up-to-date#:~:text=o...
Just running "snap refresh --hold" should disable snap updates permanently. If you configure your system update script/tooling to unhold the snaps so security fixes can still be installed at the appropriate time, this should mean that no unexpected updates should occur.
You could probably even attach the snap unhold + snap refresh + snap hold flow to the APT hooks somehow, integrating snap updates with apt upgrade.
Compared to bare metal and docker installation that were broken every few months and required maintenance, I have been pretty happy with snap.
Based on this, would say snap is not a bad idea. Sure snaps might be slow, but that’s improving.
I don’t have time to tweak applications. Let canonical package and test all dependencies for their platform, secure and update the apps.
That said, if you run `snap hold firefox`, it will wait indefinitely.
Thus you quit the Firefox, wait a few minutes, assume it has been updated because why shouldn't it, and after two weeks it gets killed mid-session.
Completely inexcusable UX...
Issues like this are present in a lot of highly-opinionated software; they become utterly unusable when used in a way that deviates from the dev's ideal vision, or ways they plain just refuse to support. Configurability and transparency is almost always a good thing in software. It seems that some Devs will have to relearn this lesson the hard way.
cat /etc/systemd/system/upgrade-system.service
[Unit]
After=network-online.target
[Service]
ExecStart=/bin/bash -c '/usr/bin/snap refresh && apt update && apt upgrade -y'
[Install]
WantedBy=default.targetYes this comment has a little malice in it.
I can't wait for Snaps to crash, burn and die.
(snapd, unattended-upgrades, ubuntu-report, whoopsie, ubuntu-advantage-tools, motd and more)
That statement might be true regarding some users.
But for many Linux users and installations, it's false.
Not sure if this is a complete list, but here are some of my reasons:
a) It's common for updates to contain a mix of security-fixes and other stuff. Sometimes that "other stuff" breaks things and/or needs vetting for deployed systems.
b) Sometimes even "security fixes" break stuff. (I don't have the time to find examples, so feel free to take this with a grain of salt.)
c) Sometimes a forced restart of the system or a program is worse than a delayed update. For example, when giving a presentation, or when firefighting a production issue.
d) It's absolutely an attractive attack vector. I want time to hear about problems before installing updates.
And finally, this might not resonate with everyone, but:
e) It's my system. Nobody else gets to override my choices for how it runs. Full stop. I refuse to cede my agency in this area of computing.
So you have no experience with unattended-upgrades. They really don't contain new features, that's not how Debian's model works - they backport security fixes to keep features the same.
> Sometimes a forced restart of the system or a program is worse than a delayed update. For example, when giving a presentation, or when firefighting a production issue.
Again, you have no clue how Debian/APT updates work. Things don't just get forcefully restarted.
> It's absolutely an attractive attack vector. I want time to hear about problems before installing updates.
Unpatched software is significantly more so than attacking your distribution.
> e) It's my system. Nobody else gets to override my choices for how it runs. Full stop. I refuse to cede my agency in this area of computing.
Sure, feel free to do with yours as you please, but don't recommend terrible things to others, especially those not as proficient.
It's bad advice for most end-users and sysadmins to get rid of unattended-upgrades especially for the FUD reasons listed above.
I was talking about Snap, not APT.
Yes every once in a while you see some person on the side of the road who forgot to fill up with gas.
But is the answer to force everyone to pull over and gas up every 4 hours?
(yes, this is an imperfect analogy, but you get the idea)