Gentoo Archives: gentoo-user

From: James <wireless@×××××××××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: Gentoo is supporting officially Snap packages?
Date: Thu, 16 Jun 2016 15:27:51
Message-Id: loom.20160616T170339-189@post.gmane.org
In Reply to: [gentoo-user] Gentoo is supporting officially Snap packages? by "José Maldonado"
1 José Maldonado <josemald89 <at> gmail.com> writes:
2
3
4 > The last days, ArsTechnica publish this new:
5
6 >
7 http://arstechnica.com/information-technology/2016/06/goodbye-apt-and-yum-ubuntus-snap-apps-are-coming-to-distros-everywhere/
8 >
9 > "Snaps now work natively on Arch, Debian, Fedora, Kubuntu, Lubuntu,
10 > Ubuntu GNOME, Ubuntu Kylin, Ubuntu MATE, Ubuntu Unity, and Xubuntu,"
11 > Canonical's announcement says. "They are currently being validated on
12 > CentOS, Elementary, Gentoo, Mint, OpenSUSE, OpenWrt and RHEL, and are
13 > easy to enable on other Linux distributions." (Ubuntu will continue to
14 > support deb packages, but developers can choose to package applications
15 > as snaps instead of or in addition to debs.)"
16 >
17 > Gentoo is supporting officially Snap packages? Why not Flatpak?
18 >
19 > Thank you very much for your responses! Bye! :)
20 >
21
22
23 One word SECURITY? Trust but verify does come to mind.
24
25 Containers are not exactly the most secure apparatus, imho.
26 "Clair is an open source project for the static analysis of vulnerabilities
27 in appc and docker containers." [1]. So, I want to hear about the robustness
28 of the security on these 'self containerd packages.
29 What exactly creates the codes necessary for the container ?
30
31 Is their a version that works on gentoo-hardened?
32
33 Suggestions for firewalling off a system for routine, deep examination
34 and profiling of port activities, would be most welcome. Prima facia,
35 I just have no trust in wonderful ideas from the *buntu crowd, ymmv.
36
37 Also, it's a really good idea; now maybe *DALE* can get his security
38 VM, in a snap (snapple?, snapit?, snapper?), that is gentoo-hardened
39 blessed? Maybe the snhap designation for secured (Hardeded) snaps?
40 Maybe if it's a hardened, entertainment (video snap) we call them schnapps?
41
42 I've been bantering about for a couple of years now how clusters (hpc and
43 containers) are going to change everything. Security is the main obstacle
44 now. You know, I'm ready to sip this Kool_aid and ponder the possibilities....
45
46 Were are all the security gurus on at on snaps? Do snaps require systemd
47 or are they PID-1 agnostic?
48
49
50
51 James
52
53
54
55
56
57 [1] https://github.com/coreos/clair

Replies