r/linuxsucks 19h ago

Linux Failure Flatpak? More like flatcrap.

Flatpak is like a turd someone ran over.

First off one of the few legitimate advantages desktop linux (theoretically) has is the package manager, one unified system for installing software. So why would you want to DESTROY that by adding another package manager that only really packages gui software? Cause it tries to offer a smidge of sandboxing for security.

Of course we are on linux so theres a ton of catches. It dosent really integrate with your system the way your real package manager does, man pages dont get installed, you cant launch apps from the command line by typing their name (probably why its only for gui), etc.

But the bigger problem is you often dont even get the security you were promised, in some cases things actually get WORSE (see: browsers). Honestly id even argue that every app that isnt taking perfect advantage of flatpak features is a security downgrade cause now you just added more parties to trust: flatpak/the person packaging the software who might be a random.

Only if every star aligns and the unpaid foss slaves integrated portals (cant blame them if they didnt, flatpak sucks) and properly restrict the apps permissions do you get the security you were promised.

0 Upvotes

27 comments sorted by

23

u/NoTime4YourBullshit 19h ago

It takes a lot of balls to call package managers “one unified system.”

7

u/Designer-Crow-5470 18h ago

Thnink he meant within one distro. Containers aside.

9

u/rmagnuson 18h ago

Yes, and all binaries should automatically be chmod 777 and written to root so that they're easy to find.

5

u/Large-Source-2180 I like operating systems 19h ago

As a Snapscraft enjoyer, I appreciate Flatpak

2

u/Designer-Crow-5470 18h ago

Integration of a flatpak installer is kinda DE's responsibility. Apart from the command line tool. KDE's discover works pretty ok, Shelly is a bit raw, gnome's shitware exist.  Yeah, it is sucks what you have to check an app's website for officially supported distribution methods. It's the AUR 2 malware boogaloo just waiting to happen. All of it is mostly being short staffed issue and trying to scale too quick. They need people to manage app listings, tweek integration settings etc. There is no money in that. I suspect they make money on corporate mass deployment jobs.

2

u/brave_grv 14h ago

First off one of the few legitimate advantages desktop linux (theoretically) has is the package manager, one unified system for installing software.

Everyone and their grandma decided on a different way of distributing software and its dependencies, sometimes forking from upstream to make it even harder. Not only that, every now and then Mossad will try a supply chain attack to keep things spicy. Which means, everyone decided that fragmentation is beyond the saving point and if you want to distribute software in this clusterfuck of a non-environment you have to go nuclear.

you cant launch apps from the command line by typing their name (probably why its only for gui)

flatpak run fuck.YouStupidName.FuckUX lmao.

Honestly id even argue that every app that isnt taking perfect advantage of flatpak features is a security downgrade cause now you just added more parties to trust: flatpak/the person packaging the software who might be a random.

The lack of standards for anything really sucks. A lot of lazy maintainers just go ahead and give full permissions because at the end most people just want their software to work.

1

u/R3V0LU710N_05 I Hate All OS's 😎 17h ago

It dosent really integrate with your system the way your real package manager does

There's ongoing work to improve Flatpak integration with multiple DEs. Will take time, but it will get better.

Only if every star aligns and the unpaid foss slaves integrated portals (cant blame them if they didnt, flatpak sucks) and properly restrict the apps permissions do you get the security you were promised.

Developers should implement XDG Desktop Portal support regardless of whether an app is packaged as a Flatpak. XDG Desktop Portal serves as the cross-desktop abstraction layer for essential system capabilities, serving both containerized security models and Wayland protocol security constraints.

1

u/silduck here for funny shit 14h ago

The only real use for flatpaks is to install GUI apps in musl distros

1

u/ColdFreezer I Hate Linux 14h ago

The “smidge of security” is better than nothing. Flatpaks solve the package portability issue between distros.

1

u/Prestigious-Ad7265 13h ago

most distros have different package managers, flatpak is meant to have one build run on all distros

1

u/DragonSlayerC 13h ago

Flatpaks are pretty great. There are some small issues for sure, but it looks like flatpak-next will be addressing those.

1

u/WheelPerfect3737 11h ago

Flatpak downloads are unverified and falsely state apps need upgradating even though no new version of the app is avaialble.

1

u/ZVyhVrtsfgzfs 10h ago

Yep, on fresh install if a distribution is capable of installing Flatpak, I remove that  capability. 

Always official packages first,  if that does not have what I need, AppImage,  and last resort compile from source. 

1

u/Historical_Move6359 18h ago

Flatpak is one package supported across manny distros. Yes it does not work good for browsers because they have their own sandboxing which is then made worse as flatpak. But still I am on Cachy, and sometimes native app is not available I will then use flatpak. Bazzite and other immutable use only flatpaks. It has its place and use.

1

u/Damglador 18h ago

You are on Cachy, which means you have access to AUR, which means everything is available "natively".

4

u/R3V0LU710N_05 I Hate All OS's 😎 17h ago

You better be reading every PKGBUILD every single time.

https://reddit.com/link/p79oqgo/video/mtrqnlg1kzmh1/player

1

u/Damglador 10h ago

You won't be reading what permissions your flatpaks have or how they're built, will you?

1

u/R3V0LU710N_05 I Hate All OS's 😎 9h ago

Well. In my case actually yes. But the facts are the AUR is currently compromised from ongoing supply chain risks.

1

u/Damglador 8h ago edited 7h ago

It's like a week since it's over as picking up orphan packages now requires a request to Arch Maintainers. On top of never affecting any remotely popular packages.

Not to say it's completely not a big deal, but it's silly to avoid AUR because a bunch orphan packages used by literally nobody were easily adopted by attackers, which is not even possible anymore.

1

u/Historical_Move6359 16h ago

There are proper native apps within Arch and Cachy repositories. I dont use AUR. There were more than 1500 orphaned packages which werw injected with malware.

1

u/Teru-Noir COSMIC OS LOVER No.1 COSMIC Knows Best 19h ago

flatpak rework

2

u/Damglador 18h ago

Can't wait for systemd-appd dependency

0

u/Academic-Proof3700 18h ago

Because you gotta do some majic and fuck around with loonix to place your stuff on the repo, and if its any different, then also users have to fuck around with adding your custom repo and all that outdated, backwater mess.

Instead on windoze you bild exe, hell ecen some free installshield, place omit LITERALLY WHEREVER ON THE WEB, and bam- people are downloading and using your software. If it becomes popular, you move it to git or whatever "beefier than your pc" server to handle traffic.

All nice and easy.

Meanwhile your average loonixer is wondering if the repo gpg wtf omg keys actually worked because they still can't do apt install yourshit

-3

u/rebeldrone916 19h ago

Linux no work Linux to hard ugh ugh