815 karma · joined October 28, 2016
No, but they would have covered the protests against it.
It's also enables proprietary extensions, easily enabling companies to make compilers for their proprietary languages, see CUDA. That seems pretty contrary to the mission of free software.
Also, just curious, how many patches have FreeBSD and co. actually received back from Sony and Apple in the past few years? They still seem to be struggling to add features to the point of begging for 802.11ac support.
Sure, there are other distros not based on Ubuntu that technically support snapd, but I have yet to encounter one that does it well; Manjaro's still breaks on many snaps, Fedora's snapd stopped working completely for over 3 months and nobody noticed. Pretty much nobody but Ubuntu users actually care about snaps; Flatpak has way, way more support and penetration than snaps do, and it looks as if that isn't going to change any time soon due to Canonical's refusal to open-source the snap store. I don't think snaps have much of a future as a widely-supported method of package distribution if this doesn't change.
Nobody would do this on a desktop because it is massively inconvenient to go through every single app you want to run and debug which app armor rule that it's violating. Even when running a service with a pre-written app-armor profile you usually have to spend a while to figure out what the hell went wrong.
Flatpak's sandboxing is a complete joke and is entirely voluntary. Snaps have sane and granular permissions interfaces that you can easily toggle on and off. Canonical is actually enforcing auto-connect rules for the more potentially dangerous ones in their store. If you want to get a classic confined app in the store, it actually has to be approved by their security team.
These things are GREAT for security, which, to be quite frank, is a complete fucking disaster on Linux desktop. X11 is a massive security hole, no real mandatory access control, no sandboxing for apps, local privilege escalations out the wazoo, a quadrillion open security bugs in the kernel. Sure, you can try and set these things yourself, but that relies on the USER to properly configure these things, and if you don't know exactly what you're doing and screw it up (and there are no reliable, consistent guides on how to do these things), then you're just as insecure as you were before.
We're just fortunate that Linux on desktops aren't popular enough to be targeted, because we'd just be getting constantly owned thanks to this massively outdated security model. Windows is actually doing the security model a whole lot better these days, but their popularity and their tendency to implement them poorly and with bypasses to preserve backwards compatibility kind of cancels that benefit out.
It's a real shame that snaps have not taken off. If flatpak wins, and they don't massively overhaul the damned thing to actually add some semblance of sandboxing with permissions controlled by the user, then we're doomed.
The one thing that could save it, Servo, doesn't seem to be a priority. Instead, Mozilla seems to be focusing on offering cloud services that nobody wants or cares about, which also don't really respect privacy any more than other cloud services. The only significant revenue stream Mozilla has is through Firefox, which keeps steadily losing users and market share.
And even that is almost entirely dependent on people using Google search with the browser. Given that Google is Mozilla's primary competitor who has intentionally broken their apps on Firefox and is pushing them down in search results, and that Firefox is marketing itself to privacy-conscious people who wouldn't use Google anyway, it doesn't seem wise or sustainable at all.
Unless things seriously change, I have no faith that they'll be able to turn this situation around. We may just have to live with a Blink/WebKit web monoculture until we get some serious anti-trust legislation.