339

cross-posted from: https://infosec.pub/post/15781466

Am I out of touch?

No, it's the forward-thinking generation of software engineers that want elegant, reliable, declarative systems that are wrong.

you are viewing a single comment's thread
view the rest of the comments
[-] lemmyvore@feddit.nl 43 points 3 months ago

Immutable was adopted for Android because Google and the Android vendors wanted to lock down the platform, and because they always distribute their OS images and updates as binary blobs.

It offers no benefits to an open ecosystem like Linux, that you can't already accomplish with existing security measures.

It offers some benefits to distro maintainers who are only willing/able to focus on the core system and delegate the rest of the software to distro-agnostic packages. That's definitely an interesting niche and I look forward to it. But please note that whether the core is immutable is completely irrelevant in this scenario.

Generally speaking, if you want to use distro-agnostic packages you can do that regardless of whether the system is immutable or not.

And since we're on the topic, if we're borrowing things from Android I would love to have the application sandboxing and permissions. I think they'd be a much bigger benefit – to all distros, immutable or not.

[-] zea_64@lemmy.blahaj.zone 12 points 3 months ago

Immutable partitions are amazing for reliability, then you can just OverlayFS your mutable state on top of it

[-] lemmyvore@feddit.nl 1 points 3 months ago

The problem with making the core immutable is that you have to decide where you draw the line between immutable and regular packages.

It sounds nice to be able to always have an immutable blob with some built-in functionality that you can fall back to, but the question is how far do you want to take that blob?

Things that go into the immutable blob don't offer much (if any) choice to the user. I can see it being used for something like the kernel and basic drivers, coreutils, basic networking. It starts getting blurry when you get to things like systemd and over-reaching when it gets to desktop functionality.

Also, you say it's more reliable but you can get bugs in anything. Version x.y.z of the kernel can have bugs whether it's distributed as part of an immutable core or as a package.

I definitely think distributing software as immutable bulk layers can be useful for certain device classes such as embedded, mobile, gaming etc. The Steam Deck for example and other devices where the vendor can predefine the partition table and just image it with a single binary blob.

On the desktop however I struggle to see what problems immutable solves that are not already solved some other way. Desktop machines require some degree of flexibility.

[-] areyouevenreal@lemm.ee 3 points 3 months ago* (last edited 3 months ago)

Also, you say it's more reliable but you can get bugs in anything. Version x.y.z of the kernel can have bugs whether it's distributed as part of an immutable core or as a package.

The whole point is you can roll back if something breaks.

It starts getting blurry when you get to things like systemd and over-reaching when it gets to desktop functionality.

Systemd is a core part of the system as init always has been.

Honestly though I don't think you actually understand the difference between declarative and immutable distros. Unlike what some people think they aren't actually the same thing. It would be nice if people stopped limping them together.

[-] zea_64@lemmy.blahaj.zone 1 points 3 months ago

Most packages are purely additive to to system. If GNOME is part of the base system, I don't care because I can just not use it. For packages that are mutually exclusive, well, usually that's the distro picking it for you anyway, but if you insist on changing them then OverlayFS lets you mask files in the base.

For something like Arch or Gentoo, the read-only partition approach absolutely won't work, but I know Fedora's been working on an OSTree immutable approach, so it's still technically a mutable partition but it's defined declaratively and is still easy to roll back.

[-] F04118F@feddit.nl 8 points 3 months ago

And since we're on the topic, if we're borrowing things from Android I would love to have the application sandboxing and permissions. I think they'd be a much bigger benefit – to all distros, immutable or not.

Flatpaks and Wayland should fill out this part nicely.

[-] michaelmrose@lemmy.world 2 points 3 months ago* (last edited 3 months ago)

This often means unofficial builds that aren't from the developer that sometimes have sandbox specific issues the devs didn't contemplate because they don't actually do flatpaks. If someday the random bob who is neither the original developer nor some trusted individual connected to the distro is hacked they may push out a malware enabled update that pwns all the people who automatically update in short order. This doesn't seem like a security increasing feature.

[-] RmDebArc_5@sh.itjust.works 7 points 3 months ago

I don’t think anyone uses immutable distros for security, the main selling point I believe is that you can rollback when the system breaks due to a update, especially when it’s a rolling release

[-] swab148@lemm.ee 8 points 3 months ago

I can do that with Timeshift on any distro

this post was submitted on 06 Aug 2024
339 points (92.1% liked)

linuxmemes

21197 readers
130 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack members of the community for any reason.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, and wants to interject for a moment. You can stop now.

  • Please report posts and comments that break these rules!

    founded 1 year ago
    MODERATORS