4 ms·
I gave NixOS a try recently, and generally liked it. I could get over the arcane packaging language and hit-or-miss documentation. The red flag for me was the
by offmycloud 6y ago
I gave NixOS a try recently, and generally liked it. I could get over the arcane packaging language and hit-or-miss documentation. The red flag for me was the inattention to software freedom. Most other distros like Debian or Fedora have source packages or SRPMs that include everything needed to rebuild a package from scratch. Nix pushes binary packages, and even stores them in S3, but with no matching source packages that I could find. They tout reproducible builds, but really haven't considered to how to deal with the "disapearing sources" problem, including vanishing git repositories. I grabbed some URLs that pointed to sources in the old Nix Tarball Cache and they all returned 404. Nix has no longer term plan to preserve package sources.
- dTal 6y agoI've noticed this seems to be a problem with F-Droid as well. Seemingly half the packages are marked "the source is no longer available", which renders them non-free in practical terms. It's great that they tell you, but why is it a problem at all?
- est31 6y agoF-Droid packager here (gotten inactive though so maybe my knowledge is outdated, beware). F-Droid actually does store source code of the package. A tarball for each published version. Not like what debian's git mirrors have, but already some progress. "The source is no longer available" means that the upstream sources have vanished and no updates can be obtained. The tarballs are still available. The build that F-Droid executes comes in two phases: one to obtain source code, which then gets packaged, the second phase to execute the build. Note however that the build execution phase does have network access and many builds actually do use the network to download dependencies, so its certainly not as advanced as Debian. I'd put what F-Droid is doing to somewhere between Nix OS (which doesn't have source packages at all) and Debian (whose source packages are complete so that no internet is needed). For F-Droid, one could maybe think about running build twice: first with internet enabled but a recording proxy in between, and second with internet disabled but that proxy replaying the recorded file. That file is then published with the sources. There are formats for this, e.g. warc. It would be a partial improvement although it might still download binaries etc instead of source code and patching the source code would be also hard (tools would have to be developed to do this), hurting the FLOSS spirit.
- dTal 6y agoThank you for the detailed explanation of the F-Droid build process. You say it's possible for an application's build scripts to download binaries that don't correspond to any published source for the app, and patch them in - that seems very non-free and indeed dangerous. Is there a way of finding out if an app does this? I also think that believing you have the source code to an app but being unable to build it because of missing, possibly proprietary dependencies is far more damaging to the FLOSS spirit than any amount of format difficulty.
- est31 6y agoThe way you can tell is to run the build and inspect the build log. Usually it prints out if it downloads something. I think it's pretty common that stuff is being downloaded during the build phase, mostly from java package hosts like mvn, jitpack, etc. There are checks in f-droid to ensure those hosts are on a whitelist of FLOSS-policy repos but the checks don't prevent any custom build logic of downloading stuff via http, cloning git repos, etc. Also while maven central does not, some of these hosts also allow takedowns of published artifacts, at least jitpack allows it and it's on the whitelist (also jitpack's policy isn't FLOSS only, only requiring that the package is on public github, which still allows for nonfree "source available" software AND jitpack doesn't have any policy about downloaded binaries during its build).
- MayeulC 6y agoDoesn't "source no longer available only concerns projects that have migrated to a nonfree license? This is a problem on F-droid, as the app you're installing will not get updates, and are out-of-sync with upstream. I was pretty sure F-droid archived the source tarball, but i can't find it now. Disappearing sources are also an issue, as it has every disadvantage proprietary software has, with none of the upsides. It's much harder to patch in case it is needed, for instance. And hard to tell if someone tampered with the binary archives, I guess? (IIRC, the hash in Nix is based on the configuration, not the resulting binary).
- progval 6y ago> but with no matching source packages that I could find. This is also something that bothers me. Even Gentoo (!) gives up on building some applications and just redistributes upstream binaries (eg. Cassandra or Kafka), because it's too hard to actually build them. I mentioned this on the #nixos IRC channel, and they seem open to having a configuration variable to disable packages not built from source (like they currently do for non-free licenses [1]), there is just no one currently working on it. [1] https://nixos.org/nixpkgs/manual/#sec-allow-unfree https://nixos.org/nixpkgs/manual/#sec-allow-unfree > but really haven't considered to how to deal with the "disapearing sources" problem, including vanishing git repositories Guix does [2], and Nix is working on it in a similar way. [2] https://guix.gnu.org/blog/2019/connecting-reproducible-deployment-to-a-long-term-source-code-archive/ https://guix.gnu.org/blog/2019/connecting-reproducible-deplo...
- k__ 6y agoFor free software proponents there is GuixSD
- ubadair 6y agoAren't they dropping support for the Linux kernel? I think guix is cool, but I'm not interested in being force-fed the Hurd.
- onlydnaq 6y agoThat was their April fools joke though.
- aijony 6y agoFor non-free software proponents there is Nonguix and various other repos.
- k__ 6y ago"Please do NOT promote this repository on any official Guix communication channels" Oh lord, but thanks for the info, would probably not have found it otherwise