News: 1591128073

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Snapping at Canonical's Snap: Linux Mint team says no to Ubuntu store 'backdoor'

(2020/06/02)


The developers of Linux Mint have expressed concern with Canonical's Snap Store and the way it is forced on Ubuntu users who try to install popular packages like the Chromium web browser.

Linux Mint has editions based on either Ubuntu or Debian, so Canonical's decisions have a direct impact on the open-source operating system. Linux Mint 20, expected this month, is based on Ubuntu 20.04 LTS.

The Snap store is an alternative to traditional deb packages for installing applications, and one which Canonical promotes as superior. The approach is different, using container technology, and you can find a full technical explanation [1]here .

History of Snap

A Snap package is a self-contained application which is sandboxed and signed. Snap updates are transactional so if an update fails, the older version should continue to work. The package will work across many versions of Linux. Snap packages have some overhead both in size and startup time, but also have benefits in ease of use and security for the user, and in allowing developers to build one installation package instead of many.

[2]

Installing Chromium on Mint currently does not require a Snap ... Click to enlarge

In 2019 Canonical said that it was transitioning the Chromium deb package from deb to snap. Chromium, as Reg readers know, is the open-source web browser that is the basis for Google Chrome. Google Chrome itself is distributed separately by Google and is proprietary software that is not affected.

Canonical [3]said that "maintaining a single release of Chromium is a significant time investment for the Ubuntu Desktop Team," thanks to the appearance of a major new version every six weeks, and that "ensuring Chromium even builds (let alone runs) on older releases such as 16.04 can be challenging."

The Snap packaging solves these issues and lets the team build just one package per architecture. Maintaining both Snap and deb versions was too much work so: "In 19.10, the chromium-browser deb package (and related packages) have been made a transitional package that contains only wrapper scripts and a desktop file for backwards compatibility. When upgrading or installing the deb package on 19.10, the snap will be downloaded from the Snap Store and installed."

Mint gets fresh: 'A self-installing Snap Store which overwrites part of our APT package base is a complete NO NO'

The Mint developers are resistant, though, saying Snap comes with too much Canonical baggage, and in particular seems tied to the official Snap store. "When snap was announced it was supposed to be a solution, not a problem. It was supposed to make it possible to run newer apps on top of older libraries and to let 3rd party editors publish their software easily towards multiple distributions, just like Flatpak and AppImage. What we didn't want it to be was for Canonical to control the distribution of software between distributions and 3rd party editors, to prevent direct distribution from editors, to make it so software worked better in Ubuntu than anywhere else and to make its store a requirement," [4]said [5]Clement Lefebvre on behalf of the team.

"I don't think the points we're raising here are well understood by the community. I hope we'll talk with Ubuntu and the Snap project about this. We're very interested in your feedback as well. A self-installing Snap Store which overwrites part of our APT package base is a complete NO NO. It's something we have to stop and it could mean the end of Chromium updates and access to the snap store in Linux Mint."

June's Mint 20 won't ship with snap, will tell you where to get Chromium yourself

Those issues have not gone away. In a post [6]yesterday , the developers said that "in the Ubuntu 20.04 package base, the Chromium package is indeed empty and acting, without your consent, as a backdoor by connecting your computer to the Ubuntu Store. Applications in this store cannot be patched, or pinned. You can't audit them, hold them, modify them or even point snap to a different store. You've as much empowerment with this as if you were using proprietary software, i.e. none."

In Linux Mint 20, APT will forbid snapd from getting installed

Linux Mint 20 – codenamed Ulyana – will not ship with any snap packages or the snapd daemon, and will be tweaked so that the Chromium package will be "an empty package which tells you why it's empty and tells you where to look to get Chromium yourself." Further, "In Linux Mint 20, APT will forbid snapd from getting installed." APT is the standard manager for traditional Linux packages.

Users can still install Snap if they choose, and this will be documented, but it will not happen automatically.

It is a curious situation, considering the close relationship between Linux Mint and Ubuntu, and it is hard to see how Mint can resist the Snaps tide long-term unless it pivots, perhaps, to focus more on its Debian variant. We have asked Canonical for comment. ®



[1] https://snapcraft.io/blog/a-technical-comparison-between-snaps-and-debs

[2] https://regmedia.co.uk/2020/06/02/mint-chromium.jpg

[3] https://snapcraft.io/blog/chromium-in-ubuntu-deb-to-snap-transition

[4] https://blog.linuxmint.com/?p=3766

[5] https://www.linuxmint.com/teams.php

[6] https://blog.linuxmint.com/?p=3906

Anonymous Coward

Good. Hate snap. It's insidious and a pain to deal with.

Besides running contrary to the principles that lead a lot of people to Linux systems (a closed store that you can't alter...automatic updates you have no control over....run by just the one company) it's an absolute resource hog.

To quote a post I made a while back:

"I managed to remove it myself this morning...apparently it used to get it's hooks in so deep it was very difficult to remove the daemon as it interconnected with ubuntu-desktop for....reasons. But that changed a few months ago. The strangest "quirk" I had was that I couldn't get the web browser to save a file directly to an attached, encrypted drive. Permissions problem. So I had to save to an interim folder then move it across by hand. Utter pain. Plus, have you seen how many loopback mounting points it creates? "df" becomes very hard to use as it buries your actual drives with it's own. One for the daemon, one for GTK, one for Gnome, one for each of the snaps you have installed...."

If we're not careful, it could become the new 'systemd' problem

Amen

Anonymous Coward

Preach it, brother.

Pop!_OS

Youngone

I enjoyed Ubuntu 18.04 as my desktop OS, and installed 20.04 when it became available, without even really thinking much about it, as Ubuntu has been such a good desktop OS for so long now.

However, so many of the tools I use regularly can only be installed as snaps, and the snap experience is such an awful one that I changed to Pop!_OS which is an Ubuntu offshoot, managed by System 76, the PC makers.

It is pretty much what Ubuntu 20.04 could have been, but isn't.

Linux Mint devs have a valid point here

Anonymous Coward

Your PC tied to one single app store with you having no say in how the applications behave, now where have we seen this before ?

Candy Crush installer pushed on your Linux Desktop, anyone ? Because you know you want it! Badly!

Linux Mint team prove to be wise when they kept open the option of moving to a Debian based version

Bad neighbor

Claptrap314

The fact that snap creates ~/snap by itself tells me that the developers are at best extremely arrogant. You do NOT get to claim subdirectories in MY homedir unless they start with a '.'. This has been true since.... Well, since I got onto a Unice in the early 90's, at least.

Now, I find out that this is being driven by Canonical? Again? I moved to Mint to get away from some of their garbage in the first place.

Hey, Mint, team! Switch your upstream to Devuan. Because every week, I'm thinking about switching directly there myself...

If it's not broken, don't fix it.

Barry Rueger

Actually I appreciate the clear and detailed explanation of the reasons why Canonical is choosing to mandate Snap. I can see the logic.

However at the end of the day I'll stick with whatever Mint decides is best for me. Year in and year out I enjoy a stable, reliable, and consistent environment that "just works" and which thankfully shows very little change between versions. I appreciate that I can pick up a new (to me) laptop and have Mint installed and configured to suit my needs in less than fifteen minutes. And that thereafter I can ignore it, let updates install without worries, and trust that it won't suddenly break itself.

Our household includes my two Mint boxes, two Windows 10 laptops, and a shiny new iMac. I'll leave it you to guess which computers have the least issues.

It is spring...

cd

Sounds like the garden needs weeding.

Debian and Debian derivatives

Arbuthnot the Magnificent

If you want a shiny Debian-based distro that's as neat, tidy, fast, well-supported and full-featured as Mint but without Canonical interference there's MX, which also has the bonus of choice between systemd or not. For a purer Debian-but-no-d experience Devuan is getting pretty good these days - I keep an ASCII partition as it's the only way I can get my organisations outdated Pulse Secure VPN client to work.

I've no idea when Linus is going to release 2.0.24, but if he takes
too long Im going to release a 2.0.24unoff and he can sound off all
he likes.
-- Alan Cox