OpenBSD KDE Plasma Desktop
rsadowski.de
rsadowski.de
EDIT: posted at https://news.ycombinator.com/item?id=38917307
Related someone is porting KDE applications to Haiku https://discuss.kde.org/t/haiku-porting-efforts/9032 and someone else is working on gitlab CI/CD directly to the Microsoft Store https://blogs.kde.org/2023/12/20/gitlab-microsoft-store
It's exactly what the desktop experience, and software in general, should be: there for you when you need it, without making the entire experience about itself.
I don't have to actively think about my desktop environment when I'm browsing Hacker News on Firefox, or writing code, or listening to music -- it looks back empathetically when a program goes wrong, or when my workflow changes and it needs tweaking, and everything else.
You've made something brilliant, and it's definitely positively contributed to Linux's increase in market share.
I hope OpenBSD gets some corporate love one day, because that's probably the only way you're going to get a modern file system written for it.
Also, I don't have sudo installed at all on my system, and everything seems to work fine with doas. YMMV.
Pros: htop only fills half of your terminal, and you know exactly what each process does because you put them there. A few well-written man pages are the complete documentation of the system. The whole thing is run by a handful of shell scripts.
Cons: exactly the same text, but read with a different tone.
... But also when computers wouldn't do anything useful unless you pressed a button. Or a bunch of buttons, more likely.
It was actually ethereal.
The way you describe FreeBSD is how I imagine an OS should be. I'm going to make it a goal this year to get a server up and running. Thanks.
-- Rant
Linux gives me more inferiority complex than any other technology I've ever touched.
Sure, something like a database system, or a moderately large code base or framework is complicated, and intimidating, and it might take many years to get a grip on, and understand, let alone master. But Linux? I just don't get it. I've tried for years, read books about it, etc. etc.
But in the end it's voodoo to me, and I'm always left searching for answers to problems, unable to solve them myself. The answers are always just rote step-by-step; do this and copy this command, problem solved. Why? how? nothing makes sense!!!
I always have the sense that somewhere out there is the holy bible of Linux, the missing piece of the puzzle; read this and it will all make sense.
Admittedly I've never compiled a distro. So in some respect I'm guilty of not going into the deep end. I suspect that if I learnt systems programming, and really go into the thick of it... then somewhere I might start to find my feet.
But it's easier to just believe that I'm stupid, and Linux is beyond my ability to comprehend.
This will give you an overall theoretical idea of how things are laid out - but you have to realise that every new version of something, there's some developer somewhere who wants to exercise their creativity and make something really clever and cool (to them), so it probably won't make any sense to you after the upgrade. That's the point you realise you're on the eternal treadmill of trying to keep your system doing what you need it to do, without freezing in the vulnerabilities.
Linux is a sprawling metropolis, you have everything and its opposite - a lot of it won't make any sense unless you learn who built what, when, and why; and you can have dirty slums right next to well-designed skyscrapers.
Trying to find meaning in such a thing is fundamentally a fool's errand.
I had a fun experience playing with `grml-debootstrap', GRML¹ being a command-line-oriented LiveCD built upon Debian. Once you’ve booted up, that app installs a minimal Debian instance on your computer. I haven't tried using the stock Debian `debootstrap' utility.
If you just need a plain system to drop a statically linked binary onto, Debian minimal install is perfectly usable right out of the box, and (IIRC) ships fewer components than OpenBSD.
Here's a breakdown of some technical differences between the two, but really if you want to explore alternatives to Linux or even Linux alternatives I highly recommend you do so, even OpenBSD, but I respectfully suggest you have a use case in mind first.
https://www.geeksforgeeks.org/difference-between-linux-and-o...
The security first/secure-by-default mindset in OpenBSD means the core distribution is very locked down. By that I mean there's very little in the base OS in terms of services. OpenBSD had a robust "ports" selection for things you may need to add.
My use case for OpenBSD was as a firewall, but it was eventually retired because it just couldn't keep up with my network speeds. It still is a secure unix server for things like radius authentication of wireless clients.
For example, Googling things are easier since the tools don't change much over the years, so an answer from 10-15 years ago still works. Besides that, I could find most of my answers in the very well written man pages. There's also just fewer things happening so there's not much clutter to distract me finding the answers I need.
I'm still a beginner of course, but I feel like OpenBSD is good for any application where you need to run something and then "forget about it" - be it a server or maybe even a "kiosk"/informational screen.
Are you doing over 10Gbps? A lot has been done in this space.
The way I like to explain it is. if you like the unix operating environment, It is hard to do better than openbsd for a desktop system. If you are expecting something more like a mac or windows environment, there are options, but I suspect you would be better off with linux(or mac or windows for that matter).
Openbsd is comfortable in a way that is hard to explain. While largely this is just what what a person is used to. with obsd I have a good feel on how it works and goes together. something I never really felt with linux. however you do lose a lot of the network effect advantages that linux has.
The different BSDs aren't distros, they are different kernels that are developed in parallel. Obviously there's shared history there, and some shared userspace, but FreeBSD and OpenBSD aren't just two different BSD distros of largely the same software.
If you're curious about what unix is and what a bsd is, I would recommend netbsd or openbsd in a vm.
Besides GhostBSD, looks like there's also Lumina, MidnightBSD, FuryBSD, and TrueOS/Project Trident?
yes, i would define them very much as experimental
It was a neat experience and worth doing.
I can't even fathom how many times I've made a mess from my impulses to tidy up my system and it just manages to "fix itself".
There are also a lot of neat things, like being able to use multiple versions of GCC side by side. Not every distro behaves well on that regard.
These days it’s a lot more Linux-y though.
MacOS?
Pfsense is ok, but CE went a year without an update while they worked on other branches. Most recently their switch to kea dhcp broke some minor things like mapping static DHCP addresses to DNS entries. I believe that's fixed now, but need to confirm you can also still specify a DHCP option which some network devices need.
Opnsense is also decent and has the advantage of a regular update cadence, but I believe the UI is less newbie friendly. Fedora has the advantage of a UI to let you quickly review firewall rules, although the cli is perfectly workable once you get the syntax down.
Honestly I like OpenBSD's pf too but it couldn't keep up with a one gigabit network connection on your typical AliExpress firewall appliance, and I couldn't get it there virtually on an HP 360 Gen 8 or Gen 9 with decent Xeon CPUs and network cards. Probably a limitation of the network drivers for the network cards emulated by ESXi. I resisted being nerd sniped by that because my wife needs reliable Internet so there was no time to putter.
What are you using that lets OpenBSD achieve better than gigabit speeds?
tl;dr: For now I'm using PFSense because I have a friend I supply with tech support and he uses whatever I use and it's safe for him to play around in PFSense on his own.
A lot of the security of the default install comes from minimizing the attack surface by having very few services running. So you do not need to be tech-savvy to make it secure, but you might need to be tech-savvy to turn it into a usable system for your use case.
mail, web, routing, tunnels, bgp, dns, hell there is even an ldap server in there for some reason. but no ldap client, which kind of sucks.
Cons: hardware compatibility/drivers (especially for WiFi and GPU) is worse than Linux, finding help online is worse than Linux, software availability and compatibility tends to be worse than Linux, but generally you can get everything you need especially if you're willing to build from source.
Subjective: Lots of Linuxisms that people are used to having aren't present on BSD. For example, no docker, no systemd, no Snap/AppImage/Flatpak, and no eBPF. This is true even on FreeBSD, which is the most Linux-like of the family. BSDs have their own answers to most of the problems that these tools solve, but you'll have to learn those tools and your Linux knowledge and muscle memory will be mostly useless.
Docker is unambiguously a Linuxism. Docker on MacOS and Windows only works by running a lightweight Linux VM under the hood. Docker does not currently run on any of the BSDs, though you can achieve similar process isolation with jails.
Con: Every time you need to upload a file using your browser, you have to move it to this folder first.
2024-01-08 22:34 ubuntu@knope:~$ sudo apparmor_status
apparmor module is loaded.
185 profiles are loaded.
104 profiles are in enforce mode.
(...)
124 processes have profiles defined.
122 processes are in enforce mode.
including firefox and chromiumUltimately, less of a concern for servers that likely have limited scope and use cases, but a significant decrease in usability for workstations.
The workflow is you put a test system to “complain” mode and use your software as intended, and add the required permissions to the profile by looking at the logs to see what your app is doing. Then you put AppArmor to enforcing mode, add the profile to production system and your application is sandboxed. Iteratively refine as necessary.
Debian desktop comes with AppArmor enabled. Nothing has been broken so far.
After two dist upgrades, you realize that this approach isn't workable.
Nah. That's a huge exaggeration. Most software doesn't change its base behavior like that and certainly not with every new release, and certainly browsers don't.
This is without adding the numerous servers which I just install and forget, and they work without any problems for years.
edit: Yes, they're dist-upgraded all the time.
You add more layers with cgroup/AppArmor/SELinux in Linux, Jails in FreeBSD, unveil on OpenBSD, etc.
You harden as much as necessary. Not "drowned by default".
Right. Just set up a separate user for Firefox using a single unprivileged command from your user account or a few clicks in your DE, then launch Firefox as that user using another single command or click. Being subordinate to your main user account, the Firefox user's files and directories can easily be managed from your main user and you can move files between subordinate users using just an (unprivileged) chown or chgrp. Accidentally launching applications as your main user is not possible and the system strongly encourages you to create separate, subordinate users for all your applications and is designed from the ground up to make this simple and it works out of the box.
Oh wait, that's not even remotely how any of this works. On a workstation, the "user account" is an almost completely useless concept (as set up and implemented in reality). That's why we have jails/namespaces/etc. Hacks that are piled on top of the useless mess of "user accounts" (all running as the same user, on workstations) trying to solve the same problems, but ultimately failing at providing any kind of comprehensive solution with a coherent vision. Software cannot take anything for granted anymore. Anything that looks like a writable file could be a read-only bind mount. Any mundane syscall could get it SIGKILLed for no reason other than that somebody forgot to add it to the whitelist. But from the user's perspective, there's no reasonable level of security by default.
Also, namespaces is not solely a security mechanism. Yes it allows isolation, but it allows resource limitation, too. So you can partition your system to slices and show a particular set of resources to an application (I'm sure you're way more knowledgeable than me in that regard).
On the other hand, security starts with application itself. Then you start to add extra containment barriers if you don't trust the software in question.
What I understand is our realities are completely disparate, and this is not how we hold the mechanisms I talk about. This might be due to the environment each of us live in, or due to our requirements, I don't know.
But, what I know is, the state of security is not as bleak as you portray, and necessity is mother of invention. Except SELinux, AppArmor, and FireJail all of the technologies we talk here are essentially built as virtualization, or virtualization-like technologies. They bring additional security as a secondary effect, and they're good at that.
> Software cannot take anything for granted anymore.
This is why we have stat calls, defensive programming, APIs and exception handling. The first rule of system programming is to never take anything for granted.
I have reached to the end of the time I have for today,
Have a nice day and a nice year.
Can you "unveil" more places, without recompiling?
Cons: Lack of available software and software compatibility. Lack of good security options to restrict software and the system.
I heard, that there is something simillar in FreeBSD with zstd compression.
For me cons is that you can't run some programms that depends on Linux kernel insides, like rr debugger, which depends on some specific of linux ptrace(2): https://github.com/rr-debugger/rr?tab=readme-ov-file#system-...
Cons: all the answers to your questions are in the documentation, and not in stack overflow.
I even had chatgpt try to come up with valid reasons and it struggled.
Me:
> Give me a short list of five top things that OpenBSD is superior over Linux for
ChatGPT:
> OpenBSD is known for its strong emphasis on security, simplicity, and code correctness. Here's a brief list of five aspects where OpenBSD is often considered superior to Linux:
> 1. Security by Default: OpenBSD is renowned for its security-oriented design. The system is configured with secure defaults, and security features are integrated directly into the core system, not as add-ons.
> 2. Code Quality and Audit: The OpenBSD project places a high priority on clean, readable, and well-documented code. Regular code audits are conducted to identify and fix security vulnerabilities and bugs.
> 3. Integrated Cryptography: OpenBSD includes various cryptographic tools and libraries as part of its base system, making it easier to implement secure applications.
> 4. Pf (Packet Filter): OpenBSD's native firewall, pf, is highly regarded for its flexibility and efficiency. It's often considered more straightforward and powerful than iptables, commonly used in Linux.
> 5. Documentation and Man Pages: OpenBSD’s documentation, especially its man pages, is extensive and well-maintained. It provides detailed and up-to-date information on system commands, configurations, and daemons.
> It's important to note that while OpenBSD excels in these areas, the choice between OpenBSD and Linux depends on specific use cases and personal preferences.
And then for the cons, flip the question around and ask ChatGPT for a list of five ways in which Linux is superior over OpenBSD. (Left as an exercise for the reader.)
I was hoping the GitHup link was a play on words that would lead to an interesting unix-related project. Alas, it's just a typo. Maybe next time. :)
This has been the 'Wayland story' for 15 years now.
Other people will pick up the slack once the weirdos at Freedesktop formally announce they're finished.
You'll never win. At best you can kill it from Red Shat. I find the snarky, hubristic nature of Wayland boosters to be insufferable. Whole thing's a huge dumpster fire too.