Nix on the Steam Deck
determinate.systems
determinate.systems
Meanwhile, the Stack Overflow Developer Survey showed a massive jump from 25% of respondents using Linux last year to 40% using it this year. Even if you assume some sampling bias, that's still a huge swing.
Then you have major manufacturers like Dell shipping laptops with Ubuntu, Proton and Wine getting better and better at running Windows games and apps, projects like WSL and the Steam Deck giving more people the opportunity to try Linux out, etc.
Even if there are still flaws and barriers to adoption, those barriers are diminishing and momentum is clearly building in Linux's favor. It will only get easier to run Linux going forward.
It probably won't overtake Windows or become a huge competitor (at least, not in the foreseeable future), but I think in the near future it will become more of a "mainstream niche" like OS X was in the 2000s. Most people won't run it, but they'll probably know someone who does and it will be at least conceivable that they could run it themselves.
Which is all well and good for Google, but that's just not the kind of time horizon that open source projects can work on.
Judging from what I see from my family and people I meet, many homes no longer have any kind of desktop or laptop computers, and rely exclusively on mobile devices of various types.
The era of the 'home computer' will probably turn out to be a "brief" window between the early 80s and this decade. Some people who need specific functionality might have a laptop. But even there, tablets or other restricted mobile-type devices are making inroads.
What's funny, is that for a long time MS Office was one of the reasons why enterprises would stick with Windows. But now, with Office365, the web experience is better than the installed-app, one. I understand "more advanced" features aren't there yet. As someone fairly basic, I have no idea what those are, but from what I see most people do in Excel, it's just basically an easy way to get a table. That works fine on the web version.
There's also the tendency of locking down workstations, by installing all kinds of detection agents, usually billed per node.
With the two combined, I would expect more and more companies to switch to some kind of dumb terminal, that would only show a browser.
Sure, this would probably not work well for everybody, but for many office workers it would likely be perfect. Hell, even for developers, with all the "remote dev" things coming out lately.
For me, that threshold has been shattered.
I'm not even going to talk about ads and similar telemetry crap.
All in all, the Windows desktop is more sluggish and loves, LOVES, to get in my way. And I'm basing this impression on my desktop: 8 core xeon, 64 GB ram, fast pcie3 nvme drive, mid-range gpu (I can comfortably play most games with full settings in FHD). Maybe not the greatest out there, but a comfortable machine still.
It may be due to animations in part, but many, many things just lag. Try to launch some app by clicking the start menu. First, it takes a while to appear, then it waits for ages until it shows my app. I only have a few apps. I know it looks for something on the internet. I don't care. It's on Windows. I never asked it to do that. On win 10, I could jump through some hoops and disable that in between updates. I don't think that's possible anymore.
The freaking control center, or whatever it's called, which pops up when you click on the sound / network icons. One out of three times it will seemingly ignore my click, even though there's an animation. And then jump up three times when I click it multiple times. Same for opening the settings up from said menu. The gear turns, but nothing happens for several seconds.
Speaking of settings, every other update it figures it should reactivate the freaking "use alt-tab to change between edge tabs". No. I don't want that. Please. stop. changing. my. settings.
Then there's the light / dark circus. Sometimes the explorer ends up in some kind of grey color for some reason. It's neither the light nor dark ones.
The task manager has a hard time figuring that my screen is quite big (4k at 100%). So it just chops off the right hand side of the memory info in the performance tab. The graph does take the whole size, though. Also, quite often, when I try to maximize it, it will take the whole screen, and end up with the bottom part behind the taskbar. I don't use any interface tweaks, everything is at its default, with a fresh install of windows when 11-22h2 came out.
Then, you decide you've had enough and what to shut down. For some reason, the task manager doesn't feel like it and will block it. There's also often, but now always, an unnamed process that will delay the shutdown.
Then, there's the whole hardware support question. I've complained about this like a broken record, but my work laptop only got full GPU support a few weeks ago. For a laptop bought in December 2021. With an 11th gen Intel GPU. Same for another similar laptop, whose webcam had only worked intermittently. Both laptops are your usual HP Enterprise fare. Both worked 100% on Linux since day one.
Without fail, every single time I press the Windows key and start typing, the first few letters are dropped.
Without fail, every single time I launch a new Explorer window, the file path has a slow ass green progress bar, my drives (of which I only have 4, and only one is a spinner) are place-holder icons and the available storage icons aren’t there. After very literally 10 seconds or so, Explorer finally looks right.
Meanwhile, Everything search remains blissfully instant, Explorer alternatives such as OneCommander are blazing fast, and even tools like PowerToys search (the one that looks exactly like macOS’s Spotlight search) are fast as hell. I find that one surprising because I’d assume it’s just an alternative GUI for Windows search, but I guess not?
Anyways, the point is, Windows itself isn’t even necessarily the problem (though, yes, it is a mess that I grow less and less able to tolerate). Even Windows’ first party foundational apps are completely broken.
At this point I’ve all but washed my hands of Windows. I just can’t stand it anymore. Life for me from here on out is primarily Apple hardware, as many FOSS apps and services that I can find, and Linux VMs for development.
Im planning on switching my Windows PC over to a NixOS bare metal install, and will run Windows via KVM for the rare moments when I want or need Windows. But even for gaming, which I do far less of nowadays (pretty much Souls games and the odd game of Smash), my PS5 and Switch are more than good enough.
Windows is an absolute train wreck and I have every reason to believe it’s only ever going to get worse, not better. Which sucks because though I prefer the Unix paradigm, there’s still a lot to appreciate about Windows. I wish it weren’t being driven into the ground, but here we are.
Although I've seen Android described as the monkey's paw of Linux phones. (Granted, Android/Linux is Linux even without GNU.)
Android did not start the craze of Linux on devices, they just surfed on it...
https://developer.android.com/ndk/guides/stable_apis
And even if you try to be clever,
"Improving Stability with Private C/C++ Symbol Restrictions in Android N"
https://android-developers.googleblog.com/2016/06/improving-...
"Namespaces for Native Libraries"
https://source.android.com/docs/core/permissions/namespaces_...
Android userspace is Java and Kotlin based, and the NDK officially only allows for Android specific APIs, C and C++ standard library as per ISO, and that is about it.
Nothing else from Linux kernel is considered part of Android's public API.
Google could move to Fucshia on a whim and only OEMs, and people that root their devices would notice, Java/Kotlin apps would work as usual without recompilation from source, while NDK code would suffice a recompile.
My Sony blue ray player and LG smarttv also run the Linux kernel, so what, doesn't change anything for the movies I watch on them, and I doubt they have contributed anything to upstream
A phyrric victory.
EDIT: runs -> dominates
A kernel alone doesn't make an operating system.
A server is an appliance. Just needs a Linux kernel, a container daemon, and a target application binary. The end.
The open source community is in the end just a bunch of developers who share their solutions to help each other out. If other parties copy their stiff, it doesn’t make the open source community’s problems un-solved.
The year of Linux on the desktop would be a total nightmare, can you imagine a bunch of non-technical bug reports and feature requests hitting all these mostly volunteer projects? What a mess.
The people try really hard to get working the systems they are interested in, and then share their results. I mean there are various wikis out there with big lists of printers and wifi dongles (thankfully less of a thing nowadays) that are listed in states of:
* I actually could try this on my side and it works
* This brand usually has drivers, good luck!
* Totally unusable.
Imagine if a company with a customer service relationship, like Microsoft, went around dropping support for reasonably recent hardware! It would be seen as a sure sign that they’d betrayed their customers and dropped all pretense of competence. But the expectations for a community project are happily different.
Android is Linux system in every single way. It's not however a GNU/Linux system. But the comment you originally replied didn't claim that.
What you are missing is that Linux on Android doesn't do what a normal OS is supposed to do:
- multiplex hardware resources
- abstract hardware
- protect software running on it from each other
Last time Android tried to control user resources it led to a gross vulnerability, because it wasn't aware another piece of software was actually managing it.
It's essentially locked in the attic of Android, while everyone else is roleplaying that Linux is still the operating system.
The sooner people realize that the better.
https://wiki.postmarketos.org/wiki/Devices ctrl-f sony
Just a bunch of syscalls for apps, that yes, could be reimplemented (the number of re-implementations in the wild actually says how much Linux is becoming a lingua franca of OSes) or virtualized; the whole security model (users/selinux/seccomp) and the toolset.
And for what, on cloud deployments, what matters are language runtimes and type 1 hypervisors, while GL and Vulkan are completely unrelated to Linux kernel.
(Because it ain't; the "kernel" of a container running on Google Cloud is a userspace application called gVisor. It's just compatible with Linux syscalls. gVisor happens to run on Linux currently, but I don't see why they couldn't port it, you pretty much just need a KVM- or ptrace-like API, and Go platform support.)
If that isn't Linux on the desktop, then yeah, it may never come.
Personally, I would say that Linux lacks two things:
1. Cross platform integrations. The way MacOS can intelligently switch AirPods over or share with your tablet is nice. Linux doesn't really have that.
2. DirectX that's compatible with Windows DirectX. That would slay Windows gaming. For now, there's Proton.
KDEConnect (and its compatible Gnome counterpart) is pretty good, though I understand it's not exactly what you asked
> 2. DirectX that's compatible with Windows DirectX. That would slay Windows gaming. For now, there's Proton.
Well... I'm not sure why you'd want that specifically, or what you mean by that. There's DXVK which is a compatible implementation, and which you can use natively. There's also gallium-nine, and the wine implementation of DX (including VK3D for DX12). All are pretty feature-complete, can be used for native apps, and there are a few more alternatives (like ToGL, which Valve developed a while back).
https://github.com/doitsujin/dxvk/releases/tag/v2.0
gallium-nine can't really be targetted however. While most distribution with AMD or Intel graphics will have it enabled as part of Mesa, it can't be used for nvidia (unless... well, you could theoretically use zink to run that on top of vulkan as well). It's DX9 in any case.
Winelib has been a thing for a veeery long time, I think it was always possible to build a native executable and link against Wine's DX->OGL translation layer.
It works, but in my day2day I Bluetooth with my phone, join meetings on both Android and Linux at the same time.
- Google Drive doesn’t even have a good client and you must resort to 3rd-party tools like OverGrive
- Spotify has had broken shortcuts for more than a year now
- Many of Linux it’s file managers still don’t support file thumbnails
- system sleep is still unreliable (one could say broken?)
- power management on laptops is atrocious without deep manual tweaking
- sound on laptop speakers is atrocious without a Pulse EQ profile
- it often still feels like a hodge-podge of different projects slapped together, which it is. Distros that try to tackle this (Elementary) receive nothing but scorn
I like running Linux, but pretending it’s even halfway as user friendly as macOS or even Windows is just deceitful, either to yourself or, even worse, to others.
Hopefully Valve’s hard push into Linux might get 3rd-party developers to improve their Linux clients, because Steam Deck users will be too big a usergroup to ignore.
The other complaints like not all file managers have thumbnails is like complaining not all windows apps have tabs. There are great file managers in Linux with thumbnails and they are the defaults in not the major window managers.
Spotify shortcut works fine but maybe you were using a broken package?
I never had an issue with Pulse but Pipewire is the new king on the block and works so smooth.
Driver support is hindered by the lack of stable driver ABI, basically forcing drivers to be FOSS and mainlined. Granted, this also has some advantages.
I think the issues you are referring to about compatibility have to do with dynamic compilation and something like glibc, which mostly is a compilation risk that you end up taking but the only times I've encountered it the other packages were already available in my distro and so it was just a matter of updating packages. That is why you should find a distro that is quick to update.
If you don’t think sleep or power management issues on Linux are real you should do a cursory google. You not having the flu doesn’t mean the flu doesn’t exist and isn’t running rampant.
Also, third party support is critical. The majority of user would not want to use Linux if it didn’t have any access to Dropbox, Spotify, Slack, Discord, VLC, or any of the other creature comforts people expect to be able to use these days.
> Spotify shortcut works fine but maybe you were using a broken package?
Ctrl + right and Ctrl + left (next & previous track) are broken and have been for a long while now. Again, do some research.
> I never had an issue with Pulse but Pipewire is the new king on the block and works so smooth.
Pipewire uses PulseEQ. Also, this has nothing to do with what I mentioned (internal speakers not automatically being EQ’d with a ‘small speaker’ EQ). If you ever hear a MacBook, you’ll be flummoxed by how good it sounds in comparison to the tinny sound of your laptop. EQ is king.
It's probably terrible on unsupported hardware. Having used Linux-compatible hardware for a while now though, neither of these are an issue.
> majority of user would not want to use Linux if it didn’t have any access to Dropbox, Spotify, Slack, Discord, VLC
Good thing all of those programs are natively packaged for most distros, then.
> Ctrl + right and Ctrl + left (next & previous track) are broken and have been for a long while now.
...because Spotify migrated it's shortcuts to the more technically-correct MPRIS implementation. If you want shortcuts, set them globally and Spotify will respect it.
I'm not going to make the argument that 'everyone should use Linux', but it makes me sad listening to software developers level outdated complaints against the ecosystem. Linux is fine these days, if you don't edit video or do intensive creative work then I see no reason to avoid it.
Even on supported hardware there are often tons of snags. You either get a ‘blessed’ device (XPS, some Lenovos, System76, Framework) or trouble lurks. And note that many many more devices are considered ‘supported’!
> ...because Spotify migrated it's shortcuts to the more technically-correct MPRIS implementation. If you want shortcuts, set them globally and Spotify will respect it.
And yet most of the other shortcuts work fine. I also don’t want global player control, because it always ends up activating on the program I don’t want it to.
I also don’t want to have to configure shortcuts manually. They should work out of the box.
Imagine how laughable it would be if Davinci or Darktable or Krita asked you to set all shortcuts yourself.
> Good thing all of those programs are natively packaged for most distros, then.
And yet they nearly always have rough edges the other platforms don’t seem to have. See my Dropbox problem. Or Discord running on such an old Electron that it creates problems with Wayland. No, Webcord isn’t a solution as it is missing a bunch of features and in maintenance mode.
> but it makes me sad listening to software developers level outdated complaints against the ecosystem
I’m getting so irate because they’re not outdated problems. You’re plugging your ears and going ‘la la la la’ thinking that if you don’t acknowledge the problems a lot of others are having, they don’t exist.
I can't help notice your post history is just a bunch of Linux bashing without any details about what doesn't work.
I have a laptop with that is specifically designed to support out-of-the box and the first thing I had to do with the stock PopOS was disable sleep and hibernate because it reliably crashed the system. Even "Linux-compatible" hardware is extremely hit-or-miss.
Anyway, in general:
If you like Mac, use Gnome. That is the default in Ubuntu.
If you like Windows, use KDE. That comes default in Kubuntu.
Ubuntu is debian-based, so you need to use packages that support that if you use Ubuntu. Dropbox and Spotify both have installation instructions for using it on Ubuntu and, when I used those instructions, everything worked fine.
There is also Maestral for dropbox: https://maestral.app/
It is an open source dropbox client. Needs less permissions and the performance is good, it works well in linux but I had some issues on arm based Mac. Used it a year or two ago so perhaps it has gotten better.
I’m willing to bet there exists an open source solution that integrates with the Spotify SDK as well.
Sleep, power management, etc all work well for the userfriendly focused Ubuntu distros. It was a major pain point for me for a while many years ago when I started, but I found that KDE Ubuntu distro and it made everything a lot easier for me migrating to linux. Give it a shot.
I do think Valve involvement will help the landscape a lot, I just hope it doesn’t bring must-haves that are proprietary.
I know of Maestral. It uses the public Dropbox API which means any files Dropbox deems ‘grey area’ (think console BIOSes but there is a ton of stuff that gets erroneously flagged) refuse to sync.
I’m not a first time Linux user, and I can somewhat deal with these pain points, but recommending Linux to layman people, especially when telling them “it’ll work smoother and be more bug-free than Windows and macOS” is just setting them up for a world of technical pain.
You are experienced and I share some of the pain, so I won’t beat the point in. But I do think every OS has its pain points and advantages — and linux has a unique adaptability that just about anyone can find their niche in. Nothing is bug free but it might just be smoother, given advertising has infected the major corporate Oses.
In my experience, if it's not made by Apple you can't trust it to handle power management without hands on experience to prove it first.
I got my 80+ grandmother-in-law onto a System76 and she has been having a hoot "learning things." For reference, her tech aptitude has involved phone calls where I remind her to plug things in. And, as a bonus, it makes her completely immune to tech support scams.
Even just on Linux, there are multiple platforms. The big ones are KDE and Gnome. If you want to write the best possible native Linux application, you have to pick one of these and right off the bat you are losing about half of the potential Linux desktops.
I wish KDE and Gnome would merge. I don't really care which one would dominate because (IMHO) they are both excellent. Both give me icons I can double click on to launch an application and that's most of what I need from my desktop environment.
But at least, once I do, I'll be able to roll back to any known-good configuration thanks to NixOS if it ever breaks again!
Proton is actually really great for gaming, I just can't figure out how to get full screen games to render at native resolution without turning off DPI scaling across the entire system
I've got Ubuntu on my home machine and it is an absolute buggy mess.
I tried to right click and format on a flash drive yesterday, the button did nothing.
No errors.
No pop-up messages.
No little spinning wheel.
It did literally nothing. Did not respond, tried to click it multiple times, continued to do nothing.
I have to open up the partition manager and reform at it through there.
I've tried before to drag files from my archives into the window manager, and it doesn't work. The program's not talk to each other so you can't drag and drop between them.
I've tried to use network paths as a folder on tons of different programs, and they rarely handle it well. Best can be a problem on Windows too, but it's so much more common on Linux.
The user experience on Linux is just so incredibly buggy, you have to dig down into the command line at times to fix things, and so much stuff just doesn't work so often, or doesn't work with each other.
Linux on the desktop needs a team of like five people to actually use it every day like a normal user would, but no understanding of the command line, and then constantly complain to the developers so that all of these issues get fixed.
Until that happens Linux on the desktop will not be able to compete with Windows, no matter how many features it has. Because at the end of the day I want my operating system to just work.
On Windows I have never had a button just do nothing. Not for something as simple and common as formatting a flash drive.
I've never had problems dragging and dropping between a popular windows program and the windows operating system.
Maybe it's inherent because Linux is open source and stuff just won't work together because of that, but if that's the case then Linux is doomed to never be able to compete with Windows.
Amusing, given the amount of times ive clicked on a defunct or near-to-failing drive in windows and either had the drive disappear, or just not do anything.
The amount of times I've seen windows do absolutely fucking nothing in response to a USB, at least linux screams into a console about it
-Set a different wallpaper for each monitor -Make the OS remember where I closed a window and reopen it there
On the second one, it's possible for that to happen, but it's the app's responsibility for some reason. So Firefox does behave that way, as long as I haven't messed with my monitor layout and as long as I quit the app rather than closing the windows one after the other. Nicely nicely, Mozilla.
But my VNC app that I use for half an hour every morning? Every morning I have to move it over to the other monitor immediately after launching. There are other apps that I could try, but I haven't mustered the patience to re-solve my VNC problem when I have a lot of other things to think about as well.
It is even more aggravating that, according to the googling I have done about this, this is because of the adoption of the supposedly-better Wayland server; if I were to run X instead, apparently my window position remembering would come back. This was a solved problem, and that's apparently why it's de-solved. I have not investigated why Wayland is there, but I assume that it's for the same reasons that Systemd is there, ancient processes that have become detestable to modern programmers and needed something to replace them.
Your USB stick and network mapping issues as well, I have had many aggravated days with that stuff. I especially find that once I format a USB to linux, it requires extraordinary measures to even see it again in windows (one has to load diskpart and clean it first, which is a command line process - big deal to a Windows user). I don't know if there's anyone who could be blamed for this aspect, really, interplatform operability will always be a problem while the profit motive is a factor, and UEFI/Secure Boot makes that a minefield. It's a complex world.
Take this as you will, but I don't find I have many problems with mapped drives anymore, as long as I do it the old-fashioned way with /etc/fstab. Very occasionally I might need to run sudo mount -a in a console but that's when something else has gone wrong, network-wise. Once again, the GUI implementations are indeed troublesome, but there at least is a working solution in this case, but one which involves the console, probably.
It's aggravating, to be sure, but it's also free forever, and I have many choices I could try instead of Ubuntu/Gnome, and at some point I will (I have a lot of personal inertia on this, as many do - I've had KDE installed for weeks, haven't touched it in a good ten years now, but I also haven't had to reboot for weeks so I haven't had occasion to bother logging out). I didn't have to pay for it, I'll never have to pay for it, and at some point either someone will sort these minor irritations out, or I might even take a weekend to learn more about how these desktop environments work, and come up with a solution of my own to share and earn the love and respect of my peers.
It's a world of possibility, rather than endless rent-paying, and that is more valuable to some than this or that minor convenience.
There was an interview recently with someone in Valves steam deck team who mentioned that it’s on their radar but they don’t have the manpower yet to consider it. It does seem like an obvious next step, especially if Steam Controller 2 is released.
https://en.wikipedia.org/wiki/Steam_Link
https://web.archive.org/web/20151008050254/https://store.ste...
I'm not even sure what that would mean practically. By brute market share, possibly not. But I've had Ubuntu as my personal daily driver for many years, and at the moment it's honestly just a much better experience than either Windows or macOS.
Microsoft and Apple seem to have turned their operating systems into advertising platforms for their other products, largely disregarding the basics of what makes a desktop actually work well.
The only trouble is, it's still definitely for power-user Linux folks. There is at least 1 fork trying to put a dent in this problem, though: https://snowflakeos.org/
The corpo world Windows market is still there, and "enthusiast" windows gaming is there, but personal computing for was mostly taken over by mobile / iPad / chromebook competition. And most of gaming of course is on mobile and consoles. The remaining corpo world use supplies mass market PC hardware to run desktop Linux on and we should keep an eye on its viability.
(Linux is of course a completely mainstream platform in the dev / maker / engineering world, windows only slightly ahead eg in stack overflow dev survey, has been working well and steadily improving for less technical users for 2-3 decades)
Edit: I should amend: nixpkgs is already huge, and with flakes you can trivially get packages from anybody you trust (like Arch's AUR but distributed and easier), which covers even more packages.
Flags are a great concept, but basically will exponentially increase the required build cache size, and imo having everything in the binary cache and optionally compile only some specific package is a great tradeoff.
I never saw a sign of them after the initial announcement.
For robots you should not need more than a Linux kernel and a minimal init shim to your own custom runtime binary anyway.
> For robots you should not need more than a Linux kernel and a minimal init shim to your own custom runtime binary anyway.
This might have been true in 2005, but it is IMO not aligned to modern realities, where:
- You have a huge list of dependencies, including painful-to-package stuff like OpenCV, PCL, CUDA, Tensorflow.
- You deal with proprietary things like TensorRT, GPU drivers, and vendor tools for flashing firmware onto sensors, PLCs, and the like.
- You rely on the fault isolation and self-monitoring/healing of a multi-process architecture.
- You need to cgroup portions of the system that are critical vs being more spectulative.
- You have a bunch of asynchronous comms stuff going on, like streaming telemetry, logs, crash reports, and other assets. All of this has to be queued up and prioritized.
- You have to supply a user-ready workflow for updating the entire system down to the kernel and bootloader, with downtime measured in single-digit minutes.
None of these requirements will be met by a single binary and init shim solution.
Operating systems should have a higher standard than random dev libraries. You should be able to trust they already have had a strict cryptographically enforced review process. Distros like Debian and Arch actually have a maintainer application and review process that includes verifying the maintainers cryptographic signing keys. We can cryptographically prove who authored any given package, who approved it, and who approved the approvers.
When your threat model includes supply chain attacks, the only answer is to get really really specific about what you -need- to run your target jobs and ensure it comes from well signed and reviewed sources... then review the edge cases yourself.
As for your other points...
> - You have a huge list of dependencies, including painful-to-package stuff like OpenCV, PCL, CUDA, Tensorflow.
Those could be statically and deterministically compiled into your target application binary, or at a minimum the final build artifacts included in the cpio initramfs which in turn can be statically linked into the kernel. You do not need a full package manager, init system, or even a shell.
> - You deal with proprietary things like TensorRT, GPU drivers, and vendor tools for flashing firmware onto sensors, PLCs, and the like. Sure. An init shim can do insmod to load custom kernel modules as needed in your initramfs.
> - You rely on the fault isolation and self-monitoring/healing of a multi-process architecture.
Nobody said you have to have a single process. Your pid1 binary can spin off any other processes or threads you need and run reapers for them. A few lines of code in most languages.
> - You need to cgroup portions of the system that are critical vs being more spectulative. cgroup system calls are very simple to perform in most programming languages
> - You have a bunch of asynchronous comms stuff going on, like streaming telemetry, logs, crash reports, and other assets. All of this has to be queued up and prioritized.
You can include any syslog binary you want for this shipped in your initramfs, or have everything bundle into the kernel stdout over a network where something external does the parsing. I do not know your requirements but there are many many ways to do that. I do not see what NixOS gives you that buildroot, busybox, or a single explicit choice of log collecting daemon cant.
> - You have to supply a user-ready workflow for updating the entire system down to the kernel and bootloader, with downtime measured in single-digit minutes.
If the entire OS is just a lean bzImage with everything you need statically linked into it, then a new one is downloaded to /boot, and then you reboot or kexec pivot. If boot fails roll back. No need for a read/write filesytem other than some fixed directories you can mount in for cache/logs.
I realize a lot of this feels like handwaiving, but I have been doing embedded linux systems for over a decade and have found there is always a path to a super lean, immutable, and deterministic/reproducible unikernels with nothing more than a few easily understood makefiles and dockerfiles.
If you ever want to chat about this stuff feel free to drop in #!:matrix.org
Lot of talk about embedded linux approaches for satellites and hsms in recent weeks.
See the dozens of serious supply chain attacks or massive security oversights in recent years. The overwhelming majority of code in open source is not reviewed by anyone.
Tokio for example is clearly maintained by some of the best people in the world at writing async runtimes. It is extremely unlikely that your peers would be able to do a better job at it than the Tokio team.
As for my peers, I work with some of the best security researchers in the world, and I myself have found and filed critical CVEs in widely depended on and trusted software like gnupg and terraform. I am not an expert by any means, but just a technical person willing to actually read some of the code we all rely on.
No one bothered to carefully review openssl before heartbleed.
Everyone assumes someone else is reviewing critical code with a security lens. It is always a bad assumption and it gives dangerous people that actually -do- review code a massive advantage.
If you ship you copied off the internet for a critical use case without ensuring it receives qualified review, then you are as responsible for any bad outcomes as a chef who failed to identify toxic ingredients.
The current industry standard on software supply chain integrity is about as negligent as the medical industry before the normalization of basic sanitation practices. Yeah, it takes a lot of extra work, but that is the job.
Anyway, as far as robotics in particular, no one worth their salt is treating the computer or ROS as "trusted" for the purposes of last-mile safety— we're using safety-rated lasers, PLCs, and motor controllers for the physical safety part of the equation. The computer is critical in the sense that it's critical to keep the robot driving and therefore critical for business operations, but it's deliberately not in the loop that keeps humans or property from being physically harmed.
It's pretty easy to audit your whole dependency tree with Nix if you want to.
> Lot of talk about embedded linux approaches for satellites and hsms in recent weeks.
There was a talk at this year's NixCon about migrating to NixOS for a weather satellite system: https://youtu.be/RL2xuhU9Nhk
I ended up abandoning the packages when the gig ended. Sorry about that! Pretty cool that a whole ROS environment is well-supported via Nix nowadays. :D
So it's doable for sure, but for most mere mortals, Ubuntu LTSes are definitely still the lowest friction path to working with and deploying ROS.
Can you expand on the issue with code signing?
See rejected RFC for more details: https://github.com/NixOS/rfcs/pull/34
See rejected RFC for more details: https://github.com/NixOS/rfcs/pull/34
I found NixOS (the OS centered around Nix) having similarities, in the way you configure things, with how you configure stuff in the networking world (with options that do some stuff behind the scenes you don't really care about). The difference is that with NixOS, you can dig in if you want to.
Also, once you used NixOS for a little while, it's very hard to go back to, let's say, Debian, Ubuntu, or Archlinux : manually configuring things in multiple configuration files in /etc seems really primitive.
I'd explain "functional package manager" as "package manager where packages are declared as a function of their inputs".
e.g. a package's inputs would be the compiler used to build it, and the source code.
One motivation for doing this is ensuring that a package's behaviour is reproducible.
There are all sorts of neat benefits this ends up allowing.
I hope that basic design continues to propagate. Better-behaved package management for language ecosystems is easier to work with for Linux distros, including NixOS. :)
I don't use nixos, but I use ansible to configure my desktop and homeserver environments. Completely different approach but same result in the end.
I am aware than Nix has so many other benefits but I'm talking about configuration management in particular.
Well if you lock everything down with hashes, maybe in some sense, but other than declaring your configuration in a text file and deploying software with it, it's pretty much different (imperative approach with side effects everywhere, vs functional declarative approach).
* Nix being a real programming language (and thus allows far better composition, and abstraction)
* You can run any configuration you want, and easily jump between configurations (e.g. rollback), advantage of being stateless (well obviously to a degree, as a lot of software itself creates state, but normally you're not jumping between multiple major versions of the same software anyway).
* Great caching as every built derivation is cached in `nix/store`, thus only things get rebuild, that are actually changed
With Ansible you may achieve something similar, but afaik require way more setup and discipline to keep it clean, and the "programming" in Ansible feels rather painful, if you're used to a real (functional) programming language.
Not to mention that templating a language that uses spaces for logic (YAML) is just useless amounts of pain for no good reason.
Also, with Nix you can trivially create image for your configuration (even with slightly different options, e.g. only enable ssh on 0.0.0.0 for a fresh install, but disable it after first config apply) which I find useful when working with a cloud.
It is basically the git of binaries.
I like Nix, a lot. But I'd currently recommend it for a pretty narrow type of user/use case. Like Git.
Also, not sure I can see where would you not recommend git? Is that a typo? It sure has a bad UX, but it is the lingua franca of version management either way, that even junior devs will have to fight to understand to become even remotely useful. And this might well be the case with nix as well.
Git dominates open source, yes, but I wouldn't call it a lingua franca in general. Most companies I've consulted with were doing just fine with something else.
Also never seen Haskell, except for the well known FAANG use cases.
I doubt Symon Peyton Jones is using nix.
Also, Nix (the tool) has always been independent of NixOS, so running it on something else isn’t a stunt at all.
(1) If a build works on any machine, it will work on yours. Package builds are isolated and reproducible. For example, setting up Plasma is as simple as `services.xserver.desktopEnvironment.plasma5.enable = true;`, every time, in every environment.
(2) Environment configurations are declarative. You will always know what a given host or shell has installed because you have to write it down.
(3) Nixpkgs is _by far_ the largest package repository of any package manager, and packages are updated very quickly.
(4) With home-manager, software can also be configured declaratively; my preferred tmux configuration will always stay in sync across all of my machines because it's managed by Nix, not ~/.tmux.conf.
Following (1) and (2), executing[1] $ git clone https://github.com/xyz/nix
$ nixos-rebuild switch --flake ~/nix#host
On a fresh NixOS install will create an environment identical to that given host.[1] Don't quote me on the specific syntax. But it's roughly this simple :)
Addendum: And as a consequence of Nix being separate from NixOS, if a package builds in Nix, it will work on any distro.
While I love the determinism of NixOS, their refusal to mandate strict code review, code signing, and package signing makes it unsuitable for non-hobby use cases.
I do hope to see a fork of NixOS with the supply chain integrity of OpenBSD or at the very least that of Debian or Arch.
Could you expand on those points? Specifically, what do you want to see for code or package signing? Has there been opposition to this before?
It should be trivial to sign a trusted derivation, but the signed artifact is either an out-of-band signature that has to be verified, or a new signed derivation is produced which creates problems for anything consuming the non-signed derivation.
I tried to appeal to fix this in 2018 as a total outsider but it was endless bike shedding. Most would rather have no signing at all than use the well supported tools every other distro uses with success.
https://github.com/NixOS/rfcs/pull/34
As a security engineer I lost all interest in NixOS after that. They want it to be a hobby distro run like a wiki, and that is totally fine. It just means we need to discourage it from being used in high security applications.
NixOS is a massive step forward in Linux distro design, and a massive step backwards in supply chain trust.
Git commits? That doesn't correspond to supply-chain verification, just committer verification, so it's not as big a benefit as package-signing in other distros.
Package sources? All sources in nixpkgs are verified against their content hash, which is committed along with the source. To pull off a supply-chain attack through substituting a malicious upstream, you'd create extremely obvious breakage when the package built by Hydra doesn't have the same output hash that you asked for at build time.
Binary substitutes? Nixpkgs doesn't use a "mirrors" system that is the traditional source of distro supply-chain vulnerabilities. Packages are input-addressed, so nix knows the hash of the output it wants, and all substitutes are signed in nixpkgs. So it is difficult to alter the outputs without breaking the dependency and falling back to source builds, and still more difficult to forge a signature for the altered output.
I agree that distros need to focus on supply-chain security as a core competency. I disagree that NixOS (rather, nixpkgs) needs to use the same mechanisms as other distros to attain it, especially when doing so would impact another core competency: simply having the latest packages available as soon as practicable, because outdated packages are another source of vulnerabilities.
Run it on a steam deck for gaming, sure, but it is only suited for hobby use cases at this stage of development.
Major supply chain attacks like this have happened in lots of other package managers and most OS package managers at least learned their lesson and signs everything. Most package managers are blindly used in multi billion dollar applications, so they are a huge target for attack.
* Gentoo: https://archives.gentoo.org/gentoo-announce/message/dc23d48d...
* Debian: https://lists.debian.org/debian-devel-announce/2006/07/msg00...
* NPM: https://eslint.org/blog/2018/07/postmortem-for-malicious-pac...
* PyPi: https://www.reddit.com/r/Python/comments/8hvzja/backdoor_in_...
* Ubuntu Snap: https://github.com/canonical-websites/snapcraft.io/issues/65...
* Arch Linux AUR: https://lists.archlinux.org/pipermail/aur-general/2018-July/...
Which makes it well suited for "put in effort now, to save effort later".
My favourite use case for Nix is using it to declare what tools/libraries a project needs. Nix can make a bunch of packages available on PATH, without conflicting with what's already installed. -- This is like tools like Node Version Manager, or asdf.
Another feature I like is the command "nix run ...", which is similar to "docker run ..." in that it doesn't change what's installed system-wide, but runs the command on the host (and not inside a container).
The nix-based operating system NixOS allows for declaring the system configuration, and safely rolling back from changes to the system configuration.
> Is this something to pay attention to...
Right now, the learning curve is quite steep.
It used to be that threads mentioning Nix would attract many "I tried it, but it's too hard" comments.
NixOS builds in “generations”. This morning I managed to screw up something and it bricked a VM. No worries, just restart the VM, boot into the previous working generation. Fix my Nix config, commit and push, rebuild again. Easy. I love it for managing my personal stuff.
What I don’t like about Nix? The Nix language kind of sucks, has a steep learning curve, and lacks decent language tooling (LSP etc). If you’re on the beaten path everything is rosy, but as soon as you need to configure something or build a package that no one else has done before, it feels like you need to reverse-engineer Nix just to figure out how to do fairly basic tasks.
Or you can forgo /etc/nixos and push from your current machine with
nixos-rebuild switch -v --target-host machine2 --flake .#machine2 boot.binfmt.emulatedSystems = [ "aarch64-linux" ];
With that setting pushing from e.g. laptop to raspberry works. Nix on macOS does not have that setting, but perhaps there's an equivalent.I just use a script to run the command remotely via ssh and point to the flake in git.
- Locally reproducible CI builds and tests
- Sharable developer environments/shells
- Extremely fast and efficient Docker image generation
- Composability with other projects that use Nix. It's trivial to add dependencies.
- Not dealing with VMs like you do with Docker
There is a lot more if you use NixOS and make your whole operating system functional and declarative, but I think that's more of a niche.
Why is it popular now? I'm not sure. It still has a steep learning curve (and rough edges) but over the last 1-2 years it has perhaps gotten to a point where the documentation and examples are plentiful enough that more people are willing to try it out. Also, MacOS support has improved (but still kind of sucks) and the new flake system is more intuitive than the old nix files.
Popular where? On HN, because it's functional, and people around here like functional, just as they like Emacs, for instance. It's not popular in the industry, as far as I can see (also, just like Emacs). For the record, I like Nix (and also Emacs), but I would never introduce it in my team. The learning curve is very steep, and the problems that it solves are mostly handled "good enough" by Docker, which I actually dislike, but everyone and their dog know Docker, there's pretty much zero training for new hires needed, introducing Nix simply does not make any business sense. In a small startup team of like-minded functional programming people, sure, but in a large org? I just don't see it.
Also, I ignore people openly who try to evaluate "business sense" as if technology decisions can be quantified like that. The biggest benefit of these Nix and Haskell shops is it attracts enthusiasts who in turn train and excite other hires. Which is turn adds more Nix and Haskell lifers to the world. One "bad business decision" at a time. That's my MO at least :)
Nix, the package manager, is _amazing_ though, despite the wonky language. I use it for providing hermetic/reproducible environments for my dev projects. You create a shell.nix, auto load it with direnv, and the development environment is 100% replicated for everyone doing dev in that repo. Hook it into your CI too and now you have an identical dev environment everywhere. It's like virtualenv on steroids for any kind of project/tooling.
Recently a new and even bigger advantage to composability has appeared. ChatGPT. If you can think up a configuration of an OS you can ask ChatGPT to create it with Nix (or other frameworks for other relevant cases) and then nearly all the work is already done for you. I find this workflow to be even better than GitHub Copilot.
Steam deck is interesting here because it leaves me wondering about what I could ask Nix to configure on it. I don't know very much about steamos.
NixOS is a more ideal fit for a “steam OS fork”, frankly, than Arch, other than the fact that “Steam on NixOS native” only runs 1/3 of the games in my (large) library that “Steam on Flatpak on NixOS” does (and I wish I had time to help get it there, but I have an 18 month old kid who consumes all available time and energy!)