Fedora Proposes to Use FlatHub in Atomic Editions of the Distribution

Michael Catanzaro, one of the developers of the Epiphany (GNOME Web) web browser and a contributor to the GNOME and Fedora projects, has proposed reconsidering the use of the FlatHub directory in Fedora. LinuxIn the atomically updated edition of Fedora Workstation, it is proposed to use the FlatHub directory by default for flatpak packages installed by users, and to limit the native flatpak package repository to use only for pre-installed packages.

Currently, Fedora offers its own flatpak repository by default, the contents of which are formed based on rebuilding rpm packages. By default, downloading packages from FlatHub can only be enabled after installation by activating the "Enable Third-Party Repositories" option in the GNOME application manager, but even in this case, packages from the Fedora repository have higher priority.

Michael believes that most users would prefer to install packages from the FlatHub catalog, which are built by the main developers of applications, rather than by Fedora maintainers (80% of the participants in the discussion spoke in favor of using FlatHub). The assumption is that application developers are more knowledgeable about the nuances of their projects and build better-performing flatpak packages that have been better tested by the community. At the same time, the maintainers of rpm packages in Fedora show no interest in maintaining variants of flatpak packages and do not pay due attention to error messages in such packages, which leads to the fact that the quality of flatpak packages from Fedora is lower than that of the main projects' FlatHub packages.

Many users are unaware that when installing a flatpak package via the Fedora Application Manager, it is not installed from FlatHub, as in other distributions, but from the Fedora repository, which has different packages than FlatHub. Because of this, issues specific to packages from the Fedora repository are perceived as problems in official FlatHub packages, and complaints are directed to the core developers, not the Fedora maintainers. For example, the delivery of a problematic OBS Studio flatpak package to Fedora, which was a higher priority than the FlatHub package, led to a conflict with the OBS Studio project in February.

It is noted that the future of Fedora Workstation is seen as an atomically updated distribution, so it is better not to delay the issue of switching to FlatHub. The use of a proprietary Flatpak repository is due to the need to build in a trustworthy environment. For packages in FlatHub, even if we consider only verified packages, for the publication of which the main projects are responsible, the build is performed in external infrastructures, the security of which may be questionable.

The benefits of maintaining your own repository in Fedora include guarantees that the package is built from the declared source code and contains only components under open licenses approved for use by Fedora. Packages in the Fedora repository may also include patches that are only available for RPM packages in Fedora and have not yet been accepted into the main project code base.

Michael's proposal boils down to enabling support for installing packages from FlatHub that are in the "free software" category by default in the atomic edition of Fedora Workstation. The ability to install from FlatHub will only affect packages that users install via the GNOME Software application manager. All flatpak packages that are pre-installed by default will continue to be downloaded from Fedora's own repository, but for packages that are not used by default, FlatHub is proposed to be used as a download source.

Before migrating to FlatHub, it is suggested to jointly implement FlatHub's ability to build packages on a trusted infrastructure and to use checks based on reproducible builds. In addition, the issue of using outdated Flatpak Runtime versions in packages, to which vulnerability fixes have already been discontinued, should be addressed. Currently, 994 of 3438 (almost a third) of the checked packages from FlatHub use outdated Runtimes. Security issues also arise due to outdated internal dependencies included in packages and insufficient sandboxing measures (some packages have security modes disabled).

In addition to Michael, Timothée Ravier has also made a similar proposal: Fedora 43 would continue to ship pre-installed flatpak packages from the Fedora repository, but would add a filter that would allow installation of selected, verified applications from FlatHub. The advantages of this proposed solution include reducing confusion for users and developers of the main projects (developers have to sort out error messages specific to Fedora Flatpaks that are sent under the guise of being in the official flatpak). The change would also reduce the workload for maintainers, allowing them to focus on pushing fixes to the main projects and testing the default Flatpaks.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster