Flathub: One million active users and growing
docs.flathub.org
docs.flathub.org
flatpak is like a cross-distro snap that actually works. some of the apps are buggy at the fringes, but i've been opening issues to smooth them out. some of the apps like VS Code claim to be from microsoft, but are... unofficial?
Unless they have a verified checkmark next to the company/owner of the project it will be a 3rd party package of it. The name is mainly intended as a "This is from X" instead of "This is packaged by X" (unless you actually see the verified badge)
You are right. Besides proprietary app store, Snap lacks even basic sandboxing in non-Debian based distros. I can't believe that Canonical engineers thought this was a good idea when designing a cross platform packaging format.
Flatpak got everything right from it's initial design. Multiple repositories, Sandboxing that actually works in any Linux distro, OSTree to reduce disk space usage etc.
A nice permissions interface so the manifest can declare, this app needs x, that you can approve instead of needing secondary apps to change permissions.
I don't mind snaps. I'd like to see better integration to move AppImage downloads to a single location and add them to the apps menu directly.
Alas, today is not that day.
My takeaways:
>"The current solutions involve packaging entire alternate runtimes in containerized environments. Flatpak, Snap, AppImage, Docker, and Steam: these all provide an app packaging mechanism that replaces most or all of the system’s runtime libraries, and they now all use containerization to accomplish this."
[...]
>"All of these technologies are essentially building
an entire OS on top of another OS
just to avoid the challenges of backwards compatibility."
This is basically using containers to replace all system libraries -- to insure that a downloaded binary app always works.
From this point forward, we'll use the term "API" to represent not just Linux kernel syscalls, but the totality of all library calls (system and otherwise!) used by a given downloaded binary application!
Observation: API (in-)consistency (AKA "Stability") one Linux version to another, one Linux distro to another -- is the real problem!
That's the real cause!
Because everything else, everything else, is effect, not cause!
The containerization, the bloated "everything but the kitchen sink" downloads, are the effect of the problem of API (in-)consistency!
Phrased a simpler way -- there is absolutely NO guarantee of consistency between the libraries, system and otherwise, of any two Linux distros!
So if a binary app is to run on all Linux distros -- then it had better damn well better make sure that the exact specific version of all of the libraries that it needs -- are managed by it, not the host operating system!
Containers and bloated library downloads -- are (unfortunately) currently necessary to provide this!
Related:
"Linux Library Mismatch":
https://www.google.com/search?q=linux+library+mismatch
"DLL Hell" (the MS-Windows equivalent)
https://en.wikipedia.org/wiki/DLL_Hell
Software Engineering: Bertrand Meyer, "Design By Contract":
https://en.wikipedia.org/wiki/Design_by_contract
API Contracts: "What is an API Contract?":
https://www.youtube.com/watch?v=-qM__ozdHCU
Eelcho Dolstra: "The Purely Functional Software Deployment Model":
https://edolstra.github.io/pubs/phd-thesis.pdf#page=11
Image-based Linux distributions and associated tools:
https://github.com/castrojo/awesome-immutable
Spencer Baugh: "Managing Dependencies":
Or you can download the .flatpakref and define your own app handler instead of gnome-software. The handler just has to run `flatpak install /path/to/app.flatpakref`. A quick bash script + something like zenity (for gui dialogs) could take care of that.
Keep up the good work Flathub team!