4 ms·
This seems like a good move to me. The only people who really need LTS releases are companies that are able and [should be] willing to pay for LTS support. If
by CiPHPerCoder 7y ago
This seems like a good move to me.
The only people who really need LTS releases are companies that are able and [should be] willing to pay for LTS support.
If you're not willing to fulfill an invoice with 5+ digits, you don't need an LTS release.
- Rochus 7y agoThat's not correct. Me and many other Qt developers known to me still use older versions like Qt 4.8 or 5.4 without any need to upgrade. Upgrading causes a lot of effort and risks. If you don't depend on the new new feature (e.g. all of my projects would still work with Qt 4.4) why should you spend that effort?
- giovannibonetti 7y agoMaybe to reduce the burden of the open source maintainers that have to keep old versions of the app working?
- Rochus 7y agoApplications I've written using Qt twenty years ago still run with Qt 4.4 on all relevant platforms (Windows, Linux, even MacOS under Darwin) without any need for a change. As long as the old Qt version compiles on a specific OS version, there is no need to change and no one has to spend time for maintenance of the Qt version.
- CiPHPerCoder 7y agoIf a customer pays you to do the maintenance and update, I hope you're doing it. But regardless, this is why integration testing is important. "What will break if I update to Qt-latest?" being one click away.
- Rochus 7y agoI go the other way round. The project should not depend on stuff only available with the new new version of the library. Even if I use Qt 5.4 or 5.9 on some projects most of it would still run on Qt 4.4. And these are not only open source spare time projects.
- CiPHPerCoder 7y agoThe same reason I tell people to stop running PHP 5.6: If a security vulnerability is discovered, you always want to be on the latest version. If updating requires a lot of effort and risks, the solution isn't "don't update". The solution is "fix those problems".
- Rochus 7y agoWell, maybe if you have implemented a server in Qt which is accessible to open internet, such as PHP in your example. 99% of the Qt applications I'm aware of are desktop or "embedded". I'm working with Qt since 20 years now and had never a security issue or a known vulnerability relevant to my projects.
- heeen2 7y agoThere is also qtwebkit, the wrappers around ssl which could have issues validating certificates, qml could have issues with untrusted content etc.
- Rochus 7y agoWebKit is a web client library. I'm not even sure why a Qt developer would use it. That's among the first things I delete before compiling the Qt 4.x framework. OpenSSL is yet another third party library which can easily be replaced if need be without affecting Qt. And of course each application is a security risk, but definitely a smaller one than the user in front of the screen.
- JohnFen 7y agoLibrary providers make this really, really hard though. They should do what used to be common practice -- separate security updates from feature updates, so that applications relying on the library don't have to be on the total upgrade treadmill.
- slezyr 7y ago> As for Krita, we’re using Qt 5.12 for our binaries because we carry a lot of patches that would need porting to Qt 5.13 or 5.14 and because Qt 5.13 turned out to be very, very buggy. For Krita, using a stable version of Qt that gets bug fixes is pretty important, and that will be a problem, because we will lose access to those versions. https://valdyas.org/fading/software/about-qt-offering-changes-2020/ https://valdyas.org/fading/software/about-qt-offering-change... You need a LTS of some kind if latest version is buggy as hell.
- royjacobs 7y agoWhy are these patches not being upstreamed, though?
- makomk 7y agoYeah, and I imagine this is only going to get worse from now on. The Qt Company now have much less incentive to make the open source versions reliable and usable, because their commercial customers aren't relying on that code anymore, and something of a financial incentive to make them unsuitable for anything except developing Qt itself in order to force people onto the commercial packages.
- bluGill 7y agoCommercial customers expect a stable version to use eventually. They also are interested in some of the new features that come with version next and so will update once in a while. Some commercial customers stick to LTS releases, but not all do.
- ComputerGuru 7y agoWhere’s the logic in your statement? Say I’m an open source developer writing a Qt app. I have less time to wrangle with updates and api breakage than a company with full-time Qt developers working on their products.
- AnIdiotOnTheNet 7y agoYeah, I mean, why would anyone else want stability in things they rely on?
- JohnFen 7y agoDon't all devs need the LTS release? Why would you want to build something on constantly shifting sand?
- berti 7y agoThe way I read it patches for the LTS versions stop being available to open source consumers when the next minor release occurs. That means open source Qt applications are forced to deal with all the new bugs that come with a new Qt release much more regularly, saving the commercial customers the hassle. That is exactly why they did this, they even say so in the announcement. That makes Qt a lot less attractive to me.