Linus Torvalds on why desktop Linux sucks (2014)

You should be able to use the apps and app stores that you trust without any gate keeping from your operating system. That’s a big part of why we chose to build our app store on @FlatpakApps
Safe app sideloading and alt stores are both supported out of the box on elementary OS and can be installed with a double click. No messy jailbreaking or rooting necessary 🎉
You should be able to use the apps and app stores that you trust without any gate keeping from your operating system. That’s a big part of why we chose to build our app store on @FlatpakApps

Another call out for help in the #Linux and #nixos community!
We REALLY want to get the #nixbook installer to be able to install #flatpak during (or right after) the calamares installation.
Currently its installing on first boot of nixbook, but it's janky, and causing some downstream issues.
I FEEL LIKE this should be fixable.
Again, the issue is that we want to install a handful of flatpaks after the nixos build, but it gets cranky with no DBUS.
Another call out for help in the #Linux and #nixos community!
We REALLY want to get the #nixbook installer to be able to install #flatpak during (or right after) the calamares installation.
Currently its installing on first boot of nixbook, but it's janky, and causing some downstream issues.
I FEEL LIKE this should be fixable.
Again, the issue is that we want to install a handful of flatpaks after the nixos build, but it gets cranky with no DBUS.

This application is crazy good, it has helped me go from Windows to Linux at least on the laptop. It's black magic what it does xD
Upscaler, @TheEvilSkeletonhttps://flathub.org/apps/io.gitlab.theevilskeleton.Upscaler
This application is crazy good, it has helped me go from Windows to Linux at least on the laptop. It's black magic what it does xD
Upscaler, @TheEvilSkeletonhttps://flathub.org/apps/io.gitlab.theevilskeleton.Upscaler
After making Tuta amazingly fast, we focus on convenience. You can now:
✅ Drag & drop emails to label them
✅ Click UNDO if an email was moved by mistake
What would you like to see next? Please comment below!

The state of #Linux packaging seems to be a perpetual mess. There is no standard packaging format among distros (something that I don't think will be resolved any time soon) and I've always viewed third party packaging tools like #snap and #flatpak with skepticism, mainly from a #security perspective.
After reading this, I'd rather deal with the perpetual mess of different package managers than the unraveling security headache that is Flatpak.
The state of #Linux packaging seems to be a perpetual mess. There is no standard packaging format among distros (something that I don't think will be resolved any time soon) and I've always viewed third party packaging tools like #snap and #flatpak with skepticism, mainly from a #security perspective.
After reading this, I'd rather deal with the perpetual mess of different package managers than the unraveling security headache that is Flatpak.
Considering recent events I'd like to believe that projects will start moving away from github (NixOS and Flatpak come to mind) but I have a hard time believing anything is gonna come of this realistically. Oh well, I should move the last few repos I have on github over to Codeberg or Disroot.
#nixos #flatpak #flathub #codeberg #github

Weird request: Does anyone know how to turn off the bubblewrap sandbox for a specific #flatpak app, or even better on how to allow CAP_SYS_RAWIO in the flatpak manifest?
I'm trying to get flashrom working in the fwupd flathub package which is a pretty weird set up already... Thanks!
Weird request: Does anyone know how to turn off the bubblewrap sandbox for a specific #flatpak app, or even better on how to allow CAP_SYS_RAWIO in the flatpak manifest?
I'm trying to get flashrom working in the fwupd flathub package which is a pretty weird set up already... Thanks!

During guadec someone was asking me how do we get flatpak-builder to work inside containers. I can't remember the handle/nickname of who it was, though I do remember the face, but the answer is that we are using a custom seccomp policy that we pass to podman/docker
Something like this:
--cap-drop all --security-opt seccomp=flatpak.seccomp.json
And the file is here: https://github.com/gnome-infra/ansible/blob/master/roles/gitlab-runner/files/flatpak.seccomp.json
During guadec someone was asking me how do we get flatpak-builder to work inside containers. I can't remember the handle/nickname of who it was, though I do remember the face, but the answer is that we are using a custom seccomp policy that we pass to podman/docker
Something like this:
--cap-drop all --security-opt seccomp=flatpak.seccomp.json
And the file is here: https://github.com/gnome-infra/ansible/blob/master/roles/gitlab-runner/files/flatpak.seccomp.json

Why does @flathub not prominently show that a package is severely outdated for an architecture?
Something like "1 month ago" is not helpful if ONLY the ARM64 package has not been updated for four years.
I'll install that on my phone or laptop by accident and immediately have a security risk. Yes, that happened multiple times.
That's why I now read the issue tracker AND build manifest before installing any Flatpak packages.
Also, please cleanup abandonware.
Why does @flathub not prominently show that a package is severely outdated for an architecture?
Something like "1 month ago" is not helpful if ONLY the ARM64 package has not been updated for four years.
I'll install that on my phone or laptop by accident and immediately have a security risk. Yes, that happened multiple times.
That's why I now read the issue tracker AND build manifest before installing any Flatpak packages.
Also, please cleanup abandonware.
