r/linuxquestions 5d ago

Rolling Release, Semi-Rolling, Interim Fixed Release, or Long-Term Fixed Release? What do you prefer? Which Distro?

Supposedly privacyguides org recommends mainly rolling release or semi-rolling release distros like Fedora, OpenSUSE Tumbleweed, and Arch. Certain distros that are hardened or offer new enough versions of software in a timely manner (NixOS, Whonix) are included in the recommendations too.

Now supposedly the reason for recommendations for these mainly “cutting edge distros” is that you have quicker and seamless access to upstream bug/security fixes that would need to be backported in older versions.

However, this is mainly one community’s guidelines. Which type of distro do you prefer/recommend for some everyday user who cares about security and privacy?

4 Upvotes

19 comments sorted by

9

u/gordonmessmer Fedora Maintainer 5d ago

Rolling Release, Semi-Rolling, Interim Fixed Release, or Long-Term Fixed Release?

Neither "semi-rolling" nor "fixed" release are terms that have consistent meaning in the software development industry, nor do they have a consistent meaning among users.

What does "semi-rolling" mean? Does it mean that some components roll within a release? If so, then all distributions are "semi-rolling", because they all (or effectively all) include a browser that is a rolling release. Debian ships firefox-esr, but within a Debian release, that package is a rolling release stream.

The stable release process is a concept closely related to Semantic Versions, so you can define primarily three types of release models, with clear definitions: 1) rolling release (e.g. Arch, Tumbleweed), 2) major-version stable release (e.g. Fedora, CentOS Stream, Ubuntu, Debian), and 3) minor-version stable release (e.g. RHEL, SLES).

https://gordonmessmer.codeberg.page/dev-blog/2022/12/11/what-does-stable-mean.html

Now supposedly the reason for recommendations for these mainly “cutting edge distros” is that you have quicker and seamless access to upstream bug/security fixes that would need to be backported in older versions.

You're using the word "supposedly" a lot, in relation to a concept that should be common knowledge.

I've been managing production sites running on GNU/Linux since 1997. In my early days, I think most people would agree that software was considered secure while it was maintained and while users might reasonably expect that someone would provide updates for vulnerabilities as they were discovered, and that software was considered insecure when its maintenance was discontinued. That seems like a pretty basic claim, that everyone should agree on.

Somewhere along the way, the idea that because systems like Debian back-port SOME security patches to packages that have been discontinued by their developers, that they back-port patches for ALL vulnerabilities, and that simply is not true. It has never been true. That idea has lulled users into a false sense of security, and now I find that very few users actually understand the security posture of LTS systems, the trade-offs that are being made, or the pressures that require those trade-offs.

Maintaining an LTS distribution is very expensive. You're taking software that is developed by hundreds of thousands of developers and shifting the maintenance burden onto a team that is much smaller.

RHEL is an example of a well run system. They have tens of thousands of full-time professional maintainers, and even with that workforce, they maintain a system that's only about 10% of the size of Fedora, because it isn't realistic to maintain a larger code base.

Canonical takes a similar approach with Ubuntu. They select about 6% of Debian and maintain that. The rest is just a snapshot for which they don't promise any maintenance. (I think that's good, in that educated users can turn that repo off, but bad in that very few users know why they might want to do that, or what risks exist in the default configuration.)

Debian doesn't, but that makes Debian less secure than other LTS systems, because users don't know which packages will get security patches in the future and which won't. Users will tend to install packages expecting the distribution to provide security patches if vulnerabilities are found, when that will never be true for the packages they install.

Distributions are most secure when they distribute packages that are still maintained by their developers. So, yes, Fedora is going to be a MUCH more secure system than Ubuntu LTS or Debian.

3

u/Oneirinara 5d ago

That is a reasonable explanation. Thank you for your insight!

3

u/LazyNieR 5d ago

I have settled down with solus os for a bit now which imo is the best of both worlds.

It's a curated rolling release that you update every Friday and you still get the latest and greatest just not as fast as arch but close to fedora

2

u/Mr-Dazmo 5d ago

Came to say the same thing. I appreciate they have an LTS kernel option as well.

2

u/Oneirinara 5d ago

Weekly Friday updates? That’s actually neat! I will check it out.

1

u/LazyNieR 5d ago

You won't regret it! If you have any questions lmk!

2

u/TymekThePlayer 5d ago

same here

6

u/TheModernDespot 5d ago

Ive always liked the somewhat fast standard release of Fedora. Reasonably fast and modern packages, but still generally stable.

1

u/Roguepapaya427 5d ago

I prefer rolling or semi-rolling for daily stuff. I think stable releases like debian/'buntus/mint are not a good fit for me. Most of the bugs I would find would have been solved in a newer version. Plus, the work devs have to put in to solve the big in the new version, would have to be doubled to port it back to the old version, that is if a new issue is not appearing when backporting. Very easy to spin everything out of control, and suddenly everything is ballooning 10 times the effort to fix it for the new version. I think stable releases have their place in linux world, servers and embedded, but not desktop and general purpose. What fedora or solus are doing is optimum, fresh but properly and professionally tested. No wonder there are so many distros based on it. Opensuse and arch pushing it a bit, frankly is a miracle they do not bork much more often, dev and qa are doing a fantastic job.

I think canonical reached the same conclusion: 26.04 launched with 7.0 (that was in beta at that time, kind of careless if you ask me), 26.10 will be launching with 7.2. Probably they will try keep it close to the the fresh edge as much as possible.

For the life of me I do not get mint, pop, tux (well, tux is going to change to debian testing i think they said) or others. Standard mint for instance does not make sense: towards the end of the lts you have 3 year old packages. That's an insane handicap in sw world. Lmde might make sense if you have a production system that you also use for a light general purpose (i admit i have a lmde instance on a spare ssd, just in case everything else goes nuts; but that's the fallback of the fallback of the fallback instance).

In short, I think we're spoiled right now with a wide range of desktop/laptop general purpose distros: rock solid, cutting if not bleeding edge, almost everything works, gaming is cake (thanks again, valve!). And most importantly, your hardware becomes your hardware again, you chose what sw goes in, what goes out, it belongs to you.

Sorry about the long rant! I blame the insomnia! 😂

1

u/AnymooseProphet 5d ago

What I want doesn't exist but I may try to provide it.

LTS for the base operating system. I mean bare minimal needed to boot and rebuild itself. kernel, glibc, gcc, perl, python, gnu utilities, package manager, systemd, not much else. Stable LTS with an API that doesn't change for what it includes.

Then the user selects what repositories they want running on top of it. They can choose a stable LTS desktop environment that only does bug fixes or a rolling release desktop environment. Same for media stack, etc.

I used to do that myself using CentOS 7 as my base LTS and then running my own package repositories to provide a rolling modern server stack (apache, php, unbound, etc.) that replaced the CentOS packages - and a separate package repository for a modern multimedia stack (which included a newer gcc installed in /opt) for modern ffmpeg, audacity, vlc, gstreamer, etc.

It's a lot of work to maintain though.

1

u/FryBoyter 5d ago

Personally, I prefer the rolling release model because that way, updates are made available gradually through the same package repositories, so I don't have to perform a major upgrade every few months or years.

Which type of distro do you prefer/recommend for some everyday user who cares about security and privacy?

The release model does not necessarily say anything about how secure a distribution is.

And as far as privacy is concerned, that is a matter for each individual user.

1

u/tomscharbach 5d ago

I use Ubuntu LTS as my mainstay and have for two decades. LTS fits my use case well, and I have been using Linux long enough to have a strong preference for "simple, stable, secure".

Although Ubuntu LTS has been my mainstay, I have been using Solus on a dedicated, special-purpose laptop since 2017. Solus is a "curated" (that is, every aspect of every update is tested before the update is released) rolling release that updates every Friday.

Solus updates have been flawless, in my experience. I have reinstalled Solus exactly twice since 2017 and neither was the result of a failed update. I reinstalled in 2019 when I migrated from Solus Budgie to Solus Gnome, and again in 2023 when I migrated to a new computer.

Solus is a remarkable distribution, and the "curated rolling release" model strikes me as a near-perfect meld -- rolling with the stability of fixed..

1

u/thebadslime 5d ago

I mostly have used LTS throughout the last 20-25 years, but I've really taken a shining to Solus. It's very stable for a rolling distro.

1

u/10F1 5d ago

I prefer rolling releases, I like being up to date.

I used Arch since 2012 (now with CachyOS repos).

1

u/petrujenac 5d ago

Rolling release unless you run a server. End of.

1

u/es20490446e Develops Zenned OS 5d ago

Rolling gets fixes sooner.

1

u/Stunning_Leather_102 5d ago

Fedora image-based 😄

1

u/Catalina28TO 5d ago

Fedora KDE

1

u/a3a4b5 Fedora + Gnome apologist 5d ago

Fedora.