Announcement

Collapse
No announcement yet.

Snap Support Available On Fedora 24 And Newer

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #11
    Originally posted by Sesivany View Post

    Flatpak does not use SELinux.
    Maybe you should re-read his post. He said that Flatpak is moving to SELinux, so your post is redundant as he already said it does not use SELinux yet.

    Comment


    • #12
      Hmm... AFAIK, Apparmor and SELinux do pretty same thing with differencies with some corner cases. And they are incompatible each with other, kernel may use one of them at a time. And Snappy already uses Apparmor, while Flatpak just planning to add SELinux support. Therefore if some software vendor requires Apparmor (because it offer snap package only) and another requires SELinux (because of Flatpak), you won't be able to have both on one system.

      I wander, where are all these Unity/Mir haters, who were against Linux fragmentation? Do they whinning on forums, requiring Flatpak team to immediately switch to Apparmor or even stop development of Flatpak and start to contribute to Snappy? Or all this shit about NIH syndrome and fragmentation were just excuses for attacks on Canonical?

      Comment


      • #13
        Originally posted by Vistaus View Post

        Maybe you should re-read his post. He said that Flatpak is moving to SELinux, so your post is redundant as he already said it does not use SELinux yet.
        If I haven't made it clear enough: Flatpak is NOT using SELinux and there are NO current plans to use it in the future. Yes, originally they planned to use SELinux, that's why it's still on their wiki as "currently not used", but that info on the wiki hasn't been changed for a long time, maybe since the beginning.

        Comment


        • #14
          Originally posted by Khrundel View Post
          Hmm... AFAIK, Apparmor and SELinux do pretty same thing with differencies with some corner cases. And they are incompatible each with other, kernel may use one of them at a time. And Snappy already uses Apparmor, while Flatpak just planning to add SELinux support. Therefore if some software vendor requires Apparmor (because it offer snap package only) and another requires SELinux (because of Flatpak), you won't be able to have both on one system.

          I wander, where are all these Unity/Mir haters, who were against Linux fragmentation? Do they whinning on forums, requiring Flatpak team to immediately switch to Apparmor or even stop development of Flatpak and start to contribute to Snappy? Or all this shit about NIH syndrome and fragmentation were just excuses for attacks on Canonical?
          Not sure about AppArmor/SELinux issue, that sucks. I can imagine AppArmor support could be added to Flatpak too if developers decide to go that way. But that would require writing rules for two LSM, so not sure how would that go. I am imagining converting could be done automatically with a tool when making flatpak package.

          In case you don't know flatpak is in development a long time, formerly it was called xdg-app. As far as I know Canonical did not ask if they can help with that, it was just recently that they've announced snap and it was at the same time xdg-app was going stable and changing its name to flatpak so that it could be adopted by wider audience more nicely. Flatpak can not use just AppArmor because that would require underlying distro to use it also, so not sure where are you trying to go with that.

          I did not see Canonical trying to make some changes to flatpak in order to suit its distro better, correct me if I am wrong.

          Comment


          • #15
            Originally posted by srakitnican View Post

            Not sure about AppArmor/SELinux issue, that sucks. I can imagine AppArmor support could be added to Flatpak too if developers decide to go that way. But that would require writing rules for two LSM, so not sure how would that go. I am imagining converting could be done automatically with a tool when making flatpak package.

            In case you don't know flatpak is in development a long time, formerly it was called xdg-app. As far as I know Canonical did not ask if they can help with that, it was just recently that they've announced snap and it was at the same time xdg-app was going stable and changing its name to flatpak so that it could be adopted by wider audience more nicely. Flatpak can not use just AppArmor because that would require underlying distro to use it also, so not sure where are you trying to go with that.

            I did not see Canonical trying to make some changes to flatpak in order to suit its distro better, correct me if I am wrong.
            Correct me if I'm wrong, but couldn't the Flatpak devs just add AppArmor support with a check? e.g. if AppArmor found == use AppArmor for extra security, if AppArmor not found == disable AppArmor support

            Comment


            • #16
              It looks like while talk on flatpack came first, snap was the first to actually produce anything. Also it looks like Snap has receives significantly more contributors.

              Snap: https://github.com/snapcore/snapd/graphs/contributors
              Flatpak: https://github.com/flatpak/flatpak/graphs/contributors

              Comment

              Working...
              X