• 0 Posts
  • 42 Comments
Joined 2 months ago
cake
Cake day: July 7th, 2026

help-circle
  • That depends.

    If this is a Linux guest on a Linux host and both are just your average distros, then it’s fine~ish. It’s not 100% safe as some malware is able to escape a VM, see this for a recent example of this.

    Doing your shady stuff within a disposable air-gapped[1] VM on a RISC-V powered Sculpt OS host should be pretty safe, though.


    1. In this context, I just mean it has only had the least amount of possible privileges/capabilities during its lifetime. ↩︎


  • in general: for my personal daily use pc. I download 🏴‍☠️ files and software for websites around the internet, so it would be nice have an antivirus

    Aight. Understood. Thank you for the clarification!

    So…, now it becomes a question of how paranoid security-sensitive you are 😅. I suppose relying on a distro with pretty decent security defaults (like e.g. Fedora or openSUSE) makes sense for a start. Furthermore, definitely commit to best practices[1]. As for the scanning part, other comments have already touched on that.

    If the PC you’re doing this contains sensitive information OR you’re not satisfied with the provided “probably good enough” solution, then consider going “the extra mile”. Which would involve the use of specialized OSes, relying on VMs and whatnot. But I digress…

    in specific: i want to self host services in my home server, so i want it to be secure and protected

    Unfortunately, I’m not confident talking on servers specifically. It’s simply not something I’ve put serious thoughts to yet. I hope someone else will touch on that 😉.


    1. A lot can be said on this, but it would dominate this text if I’d try to touch on it. ↩︎


  • OP, I’ll be honest with ya: if you’re looking for something akin to M$ Defender but on Desktop Linux (and free), you ain’t gonna find it.

    A quick look at your Lemmy history suggests that you’re security-conscious. In that context, it’s worth noting that ‘Linux’ does provide you. However, depending on your situation and/or threat model, this might come at the cost of expertise.

    If you never download random stuff from the internet, then your average distro might be sufficient as long as you commit to the most basic set of best practices.

    However, if you do download random stuff from the internet OR if your situation and/or threat model warrants a more conscious approach, then things might change substantially.

    But before subjecting you to Qubes OS, we’d have to know more about your situation. So, first of all, could you elaborate on your use case of ClamAV? Or, perhaps even what you intend to do in general?





  • VanillaOS and OpenSUSE immutable ones use BTRFS snapshots dont they?

    For openSUSE’s atomic offerings, you’re correct. Vanilla OS is a bit more nuanced, though. I don’t quite recall how they did it on their original images. But since Orchid, there is a reliance on OCI images for its updates. Note that bootc is also contingent upon OCI images, which is why I made the comparison earlier. They behave so similar to one another, that Vanilla OS’ Vib can be used (without too much trouble) to create Fedora Atomic images.

    As for the usage of Btrfs snapshots on Vanilla OS, I think it doesn’t quite need it because it relies on lvm thin provisioning instead for its ABRoot. However, an attempt to verify this by installing it within a VM failed spectacularly and I don’t think the blame is on me 😅…


  • Sorry, perhaps I should have been more clear.

    It was meant strictly in the sense of how much it burdens the system performance-wise. So, in other words, using nix is easier on your system’s resources than rpm-ostree (or bootc) is; at least, that has been my experience.

    In regards to breaking, I’m not sure whether one outdoes the other. Though, I suppose that nix -by design- would inch this out. But this is basically an ‘internal dispute’ between the crème de la crème; as rpm-ostree/bootc basically outdoes any other distro package manager that’s not named nix or guix.


  • While I absolutely adore everything rpm-ostree/bootc, I do think operations involving it are relatively heavy; at least compared to what else is out there.

    Depending on your (in)tolerance, you might therefore consider opting for something else, instead. Assuming that this list does a considerable job at presenting your options, I’ll try to provide input on some of the more mainstream ones:

    • openSUSE’s offerings. AFAIK, it is lighter. Heck, I’d reckon you might not even be able to distinguish it from its traditional counterpart; Tumbleweed. However, its ecosystem is still very much in its infancy. Hence, I don’t recall any of their offerings that don’t rely on GNOME/KDE-Plasma. There used to be Project Greybeard, but it’s far from lively… As for Aeon (i.e. GNOME version) and Kalpa (i.e. KDE Plasma version), they haven’t had a general availability release yet.
    • NixOS. I have heard good things regarding how well it does on low-end PCs. However, FWIW, my own testing portrays a different story: I once had an update that resulted in a lot of compilation and my machine was struggling quite a bit. The same machine that handles Fedora Atomic quite gracefully*. Perhaps that was a fluke, but I wanted to point it out. I’d argue nix does handle operations more gracefully than rpm-ostree/bootc on average, though.
    • Guix System. Perhaps I’m wrong, but I wouldn’t be surprised if this outdoes NixOS in terms of how gracefully it operates on a low-end system. This is mostly on vibes, though.
    • Endless OS. If you liked Bazzite, but want something lighter, then this might be just that. It relies on ostree only and thus doesn’t have the heavier operations from rpm-ostree/bootc. The goals of the foundation behind it align with enabling low-end hardware. This is reflected in their system reqs. Note that GNOME is still relatively heavy, but you should be served well even on just 4 GB of RAM.
    • ChromeOS Flex. For completeness’ sake, if you’re otherwise okay with this, then I suppose it’s another option worth considering. FWIW, there’s also FydeOS (and perhaps others).
    • VanillaOS. Does something similar to bootc ever since its Orchid release. So, it’s probably not that light. Furthermore, I got many questions regarding the health of its ecosystem. This used to be another serious contender, but I’m afraid it might have missed the boat…
    • GNOME OS and KDE Linux. While not production-ready yet, these will definitely be interesting in the long run.
    • aerynOS. Another project that’s not production-ready yet.
    • Nitrux. Definitely one of the more interesting ones. It has been around for quite a while now, but I’ve yet to come across someone that dailies it.

    Having said all of that, the gist is basically that atomic distros are still relatively new. As such, I can only recommend Endless OS, Guix System and NixOS. Note that the latter two are rabbit holes, though.





  • I don’t agree with the sentiment that Linux Mint is underrated either. As you note, it is quite popular and is mentioned a lot in the discourse.

    However, I don’t think that CachyOS and Linux Mint are the most popular distros; that undoubtedly goes to Ubuntu. And, if anything, I’d think that Linux Mint is more popular than CachyOS.

    Yet, if we’d limit it to the distros used by gamers, then CachyOS probably does take the crown for most used distro (aside from SteamOS). At least, there are metrics that suggest as such.


  • Sorry for the late reply

    No worries fam 🙂.

    thank you for taking your time!

    It has been my pleasure 🙂.

    I have “defaulted” back to Artix, having fixed the NIC issue.

    Glad to hear that you were able to return back to your home.

    And I agree, Gentoo is what I dream of being able to handle, but all the USE flags KILLED me when I set it up for the first time a month or so ago. xD I do want to get back to it at some point though.

    Good mindset! I’m sure you’ll manage whenever you get back to it 😉.




  • Others have basically already pointed out how you should go about diagnosing the problem. Which, by itself, is already very valuable.

    Below, I will try to touch upon some tips and tricks that are worth noting in this context, assuming Bazzite*.

    • Pinning a specific deployment to return back to. As we’ll be doing some time traveling in a bit, it’s definitely recommended to pin your latest deployment (just in case) before you do anything else. See this entry in Bazzite’s documentation on that.
    • Rolling back to images from a certain day. So, IIRC, all of the uBlue products keep around 90 days worth of images you can rollback to. See Bazzite’s documentation on brh for more information. With this (and some effort), you can literally pinpoint the exact date from which you started to have problems with gamescope/game mode.
    • Looking into the exact changes between two deployments. So, after you’ve identified the last properly working deployment and the first deployment that started misbehaving, you can invoke the rpm-ostree db diff command to see what has changed between the two deployments. Note two things on this:
      • That the hashes coincide with the ones you actually want to compare.
      • The command catches only changes in packages. However, a config diff applied by Bazzite’s maintainers will not be shown here.
    • Asking help from community channels. You can even start here. But basically, a project’s discord/discourse is undoubtedly better equipped in helping you out. See this entry on Bazzite’s documentation for links.

    Wish ya good luck fam 😉!


  • Alright, excellent. Thank you for the reply!

    So, IIUC, you want a clean slate. Furthermore, you want plenty of tinkerability. And, finally, OpenRC enjoys a preference.

    Still, I want to limit our search (for now) to (relatively) upstream distros on which OpenRC is known to work pretty well. We have to start our search from somewhere and this seems to be the most sensible starting point at this point.

    If you’ve dismissed Artix, that basically leaves us (in alphabetical order) with:

    • Alpine
    • Debian
    • Devuan
    • Gentoo

    IIRC, most (if not all) of these offer very minimal images. So, hopefully you’ll enjoy those.

    Thankfully, these are meaningfully different from eachother (for the most part). So choosing between these shouldn’t be too much to ask.

    FWIW, Gentoo comes undoubtedly with the least amount of defaults and thus behaves the most like a blank slate.


  • I am most fond of Arch

    But what is it that you like about Arch in the first place?

    I found that I’m more comfortable with OpenRC as init and process management.

    Like, do you want to limit your options to distros that are well supported by OpenRC? Or, is this simply a preference kind of thing?

    the Artix forums also seem to house at least some transphobia

    Do you want to engage in distro-specific forums or was your engagement in there mostly out of necessity?

    as opposed to configured by me.

    Excellent, so you’re a builder/tinkerer that prefers a clean slate to work from.


  • Assuming you’re involved with the development on AstrOS, thank you first of all for your efforts and secondly for providing your perspective on the matter!

    Imo it generally does too much.

    Oh, I can definitely see that; probably the consequence of retrofitting an OCI/Docker image into an OS 😅. I suppose that its relation with (rpm-)ostree doesn’t help either.

    Systemd-sysupdate being simple as hell makes it just way more solid.

    That’s some cool insight. Thank you.

    I think it also depends on grub and stuff

    I believe it did, yes. But, AFAIK, systemd-boot has been supported since earlier this year. I believe that change has also been instrumental in the relatively recent activities surrounding so-called sealed images.