• 0 Posts
  • 671 Comments
Joined 2 years ago
cake
Cake day: July 29th, 2023

help-circle

  • zsh was and I think still is technically an extended superset of bash.

    It’s pretty much exactly what you’re looking for if you want bash scripting with fish features and plugin extensibility.

    The downside is you gotta take some time to set up your .zhrc and choose if you want to use a backend like oh-my-zsh.

    I think the reason its on MIT license was because it was essentially just a bunch of scripts bundled together and maintained by a wide variety of people with no intention of making it the default shell like fish or bash is.



  • mlg@lemmy.worldtoSelfhosted@lemmy.worldDocker security
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    edit-2
    7 days ago

    How I sleep knowing Fedora + podman actually uses safe firewalld zones out of box instead of expecting the user to hack around with the clown show that is ufw.

    I could be wrong here but I feel like the answer is in the docs itself:

    If you are running Docker with the iptables or ip6tables options set to true, and firewalld is enabled on your system, in addition to its usual iptables or nftables rules, Docker creates a firewalld zone called docker, with target ACCEPT.

    All bridge network interfaces created by Docker (for example, docker0) are inserted into the docker zone.

    Docker also creates a forwarding policy called docker-forwarding that allows forwarding from ANY zone to the docker zone.

    Modify the zone to your security needs? Or does Docker reset the zone rules ever startup? If this is the same as podman, the docker zone should actually accept traffic from your public zone which has your physical NIC, which would mean you don’t have to do anything since public default is to DROP.


  • Someone I personally knew almost gave up on Linux because their mint install would have screen tearing issues due to an outdated driver module and kernel, since Mint follows close to Ubuntu’s kernel releases which are slow.

    Cutting edge and bleeding edge kernels is one of Linux’s biggest strengths because 99% of driver modules are in the kernel, so keeping it up to date will significantly reduce the chances of issues with your hardware, especially if its anything new.

    You dont need to know the version, but knowing that your updates are based on cutting edge latest stable is what can save you from driver headaches.



  • Do these updates not go through any rigorous testing at all

    Lol no, MSFT infamously dropped their entire Hardware QA team after WIndows 7 and instead relied on the also infamous insider hub to get QA “feedback” from home users instead, leading to the also infamous Windows 8 disaster and slightly less infamous critical CVEs that went unaddressed because MSFT ddidn’t even bother to read the insider hub posts.

    Oh and they didn’t learn anything and kept running with the insider hub well into Windows 10 & 11.









  • Same, I enjoy the classic shared library and package system which I still feel is superior to flatpak versions in most cases, even ignoring the technical aspects of each.

    Tried silverblue once and it just felt more like android to me, and I even found myself using RPM layers almost immediately for core things that dont ship as Flatpak because its infeasible.

    Plus Bazzite has its own release schedule which I feel like slightly removes the benefit of Fedora kernels being cutting edge, with critical packages updated almost as fast as Arch.

    The good thing though is that it’s much more dummy proof, so I would feel comfortable letting anyone use it with zero experience, whereas I only recommend Fedora to those who have an inherent interest in Linux.