11 ms·
Pkg.go.dev is more concerned with Google's interests than good engineering
- warent 6y agoThese are fair criticisms. Still though, there are some pretty sweeping generalizations about Google being made here. The company is as big as a city. Not all of their engineering culture is like this. Take what I'm saying with a grain of salt; slightly biased since I worked there for a bit in the past.
- _-___________-_ 6y agoAll of the parts of the engineering culture that are publicly visible seem like this.
- finnthehuman 6y ago>Not all of their engineering culture is like this. Sure. I'll grant you Junio; he seems like a cool guy. The rest of google though? Google's engineering culture is by and for google. They're not doing the rest of us any favors. Googlers need to admit that. Not to me, but to themselves.
- IfOnlyYouKnew 6y agoI'm seriously astonished by the depth of these Freudian analyses of the dark underbelly that is Google's "engineering culture", and how everything bad with the world can be linked to ... ... a meaningless decision to have a transparent proxy in some network path some free code takes on its way to you?
- finnthehuman 6y ago>a meaningless decision If it's so meaningless, now that Drew has complained they can just make the alterative the default for their software right? Right? It is MEANINGLESS afterall. When faced with a decision, someone chose the option that took extra operational expenses to keep services online. If you're going to call that a meaningless, then you've either a huckster or have got quite a lot to learn my friend.
- IfOnlyYouKnew 6y agoExactly! It's so meaningless they shrugged and flipped a switch when asked to do so in a single blog post. Try that feat with any policy decision google actually does care about!
- juped 6y agoI feel like Junio gets to be exempt from Google engineering culture because of his unique position.
- izacus 6y agoThis is the same author who wrote https://news.ycombinator.com/item?id=23966778 https://news.ycombinator.com/item?id=23966778 and also had some very one-sided things to say about Google. I forecast a lot of HN upvotes :) Personally I don't find the fact, that a corporation built something out of their own interest surprising at all.
- ddevault 6y ago>Personally I don't find the fact, that a corporation built something out of their own interest surprising at all. It's not surprising, but it is concerning given that Google is the steward of the joint interests of all Go users.
- eat_veggies 6y agoI don't understand what this comment is saying about Hacker News or Drew DeVault. Are the points any less valid just because they do not praise Google? And just because something is unsurprising does not mean that it is good or acceptable, or that we should not urge them to do better.
- deleted 6y ago[deleted]
- googthrowaway42 6y agoAs a counter-point, I worked at Google for two years and what the author is describing is completely consistent with my experience with the engineering culture and the systems it produces. Fundamentally there is a hostility towards the philosophical aspect of software engineering which involves a careful consideration of the essential nature of the system as a whole as it relates to some ultimate end and the nature of logical components of the system and how they interact. Note that these considerations can occur prior to any code being written and also as part of an iterative process as the product and understanding of the product develops. I believe this stems from three sources: 1. The criteria and process for getting promoted is very focused on shipping new and complex things which in practice is at the exclusion of all other considerations. This means that improving or maintaining existing systems or producing systems which are well architected at all is not as clearly valued. The promo committee is comprised of people who don't know the specifics of the systems you're working on so the easiest thing to convey is that feature X or product Y was shipped. 2. There is a hyper-rationalist, hyper-modernist, data-driven, anti-intuitionist view which pervades Google which completely discounts any sort of philosophical/qualitative thinking. People get really uncomfortable when you try to start even the most anodyne discussion about the product or service as it relates to some broader goal since those involve qualitative judgements that can't be reduced down a set of metrics. Some of this may be attributed to the CYA culture among management. 3. The interview process doesn't select for software engineering or software architecture skills (aka people who have developed an intuitive understanding of the art of software engineering) so there are many people within Google who lack the ability to effectively evaluate the architecture choices that are being made around them or that they themselves are making. With all that said I did meet and work with many brilliant engineers and others who were very talented and did think deeply about things but those were relatively rare. And yes it is a big company with many different teams and subcultures but what the author and I have described are the patterns that one sees broadly across Google.
- amscanne 6y agoIt’s pretty uncool to use just two years of experience at a place as a credential to shit on the culture of that place (and through implication, the engineers there). I’ve been at Google for six years, and I’ve never encountered a “hostility towards the philosophical aspect of software engineering”. What a bunch of hooey. There are certainly problems with the promotion system (and incentives it creates), but it’s laughable to say that it rewards shipping “at the exclusion of all other considerations”. In two years, I imagine that you didn’t yet serve on promo committees (or see many successful and failed promotions of colleagues), so I’m not sure your criticisms are coming from a deep understanding of how they work. I’m sorry that you had a bad experience, or that you felt your specific working group had some kind of CYA culture or anti-engineering vibe. But it upsets me to see people indirectly shitting on or commenting about tens of thousands of engineers that they had never worked with or even interacted with. I don’t know why it’s fashionable to do this with Google right now, but it just shouldn’t happen with any company. If you want to describe your specific, concrete experience, I’m sure that would be much more helpful and constructive than saying “the culture is X”, “Google engineers are Y” without any connection to specifics. My 2c.
- arp242 6y agoThey might be if they were true, but they're not: the only thing that was broken about sr.ht was that the links to the source code didn't work, but other than that it worked fine. The other sites mentioned like codeberg.org work just fine today, just without those links (a minor feature I almost never use). The whole "it needs meta tags" thing is also not true, I don't know where he got that from. Quite a few points in this article are highly misleading.
- yencabulator 6y agocodeberg.org only works with `go get` etc because they do have the meta tags set up. The only way for a non-hardcoded host to work would be for the import path to contain ".git", ".hg", etc -- which is so ugly pretty much nobody does that.
- arp242 6y agoAh sorry, you're correct. I checked but forgot about the "?go-get=1" parameter it adds. The entire thing is a bit hacky, but as mentioned in other comments godoc.org started as an independent project outside of Google and pkg.go.dev built on what was already in place. Was that the right decision? I don't know, I haven't looked at the matter and possible problems in-depth; all I do know it's far more nuanced than "Google being bad at engineering".
- thayne 6y agoProbably another instance of someone making a new shiny to get promoted, after which it will be abondoned.
- dingdingdang 6y agoThese two points alone are honestly just bad news for Golang on the whole >> pkg.go.dev fetches the list of modules from proxy.golang.org: a closed-source proxy through which all of your go module fetches are being routed and tracked >> pkg.go.dev hard-codes a list of centralized git hosting services [that are the only allowed ones]
- ergo14 6y agoPython PyPi downloads are also tracked https://pypistats.org/ https://pypistats.org/. The data is public, nothing wrong with that IMO.
- vosper 6y agoI think all the PyPi stats are available in BigQuery, if anyone’s interested in doing some analysis.
- leetrout 6y agoEdit: I had the wrong table. It does have the data https://console.cloud.google.com/bigquery?project=the-psf&p=the-psf&d=pypi&t=downloads20200801&page=table https://console.cloud.google.com/bigquery?project=the-psf&p=...
- X-Istence 6y agoIf I host a package outside of the PyPi eco-system though as a wheel, pip while happily install it if I provide a full path to it, and at that point it's not part of pypistats.org
- LukeShu 6y ago>> pkg.go.dev hard-codes a list of centralized git hosting services [that are the only allowed ones] So how in the world did git.lukeshu.com get to be on that list? https://pkg.go.dev/git.lukeshu.com/go/libfastimport https://pkg.go.dev/git.lukeshu.com/go/libfastimport
- 6y ago
- arghblarg 6y agoRemember, Go is MIT-licensed. If things become too bound to Google, it can and will be forked. People thought it was the end of the world when multiple Java SDKs arose didn't they? (Not to say that didn't hurt Java, but the language survived).
- deleted 6y ago[deleted]
- marcus_holmes 6y agoIs anyone forking it to remove the Google taint? I'm aware of TinyGo, but not any other forks
- arp242 6y agoWhat Google taint is there in the Go compiler/command?
- justinclift 6y agoTinyGo is more of a "reimplementation, using LLVM" than a fork. That being said, some pieces of the Go standard library have been copied across where it makes sense to (and works).
- htmlproplus 6y agoA little off-topic. I like Go but haven't used it in a while. While offline I remember a couple go command operations were surprisingly giving me proxy.golang.org or network unavailable errors. In the sense that it had no reason to touch the network. Can you refresh my memory what they were? Or if they are still present? I can't for the life of me find or remember the answer. It was what made me discover some of the things the article mentions, like the package index.
- ridv 6y agoIf you download a package that supports go mod and try to build it, it'll automatically try to fetch dependencies through proxy.golang.org You can override the proxy, and there are open source implementations of the module datastore[1], but it's not made clear front and centre to the end user that building software will call a Google owned service. It was a source of contention for some when the default toolchain moved in this direction.[2] [1] https://github.com/gomods/athens https://github.com/gomods/athens [2] https://news.ycombinator.com/item?id=20870264 https://news.ycombinator.com/item?id=20870264
- marcus_holmes 6y agoalso, you can choose not to use the module system entirely, and just `go get` packages the old-skool way.
- hermanradtke 6y agoI understand the complaints, but Go is Google’s language just like Ruby on Rails is Basecamp’s framework. This is not a secret! Also, I think this is fine? If your interests align with the owners, then you can really benefit. If not, then you are better off choosing a different solution.
- throwayws 6y agoI'm thankful they open sourced pkg.dev and that they continue to bring it on par with godoc.org. Keep up the good work!
- zelphirkalt 6y agoThis article names, what I have had as a feeling for a long time: "Oh it created by Google … ah this will suck." Take whatever you want. GMail, YouTube, Google Search, Google's online office products (they are sooo soo basic, so that even the most basic used can handle it, with no way to unlock great functionality), Google Hangout, you name it. It all sucks. You are the product, a used and not a user. Mostly the reason is probably, that this kind of software is only written with the most basic and common used in mind, not with the one, who wants to customize everything to their own personalized needs or a user, who does not require big corp to tell them "what they want". Google targets another group of people. So I think the wording "crapware" pretty much covers it. Of course ethical questions like the ones raised in the article … I guess they don't usually even enter the equation at Google.
- kgraves 6y agoNot surprised at all, what did you expect? it's Google after all. If it were me (or my company), I would refuse to use a programming language created by a surveillance capitalist like Google. What's next? telemetry in the Go language?
- jrockway 6y agoThere is some complexity here. Go is one of the few programming languages with a fully-decentralized module system. I can upload a module to example.com, and you can use a module from example.com with no centralized coordination. This is very different from systems like Node/npm or Perl/CPAN, where if you want to write a module, you have to beg them for permission first. (This is a moneymaking opportunity, too. You can charge people for your package system if they want to keep their code private. And npm does! With Go, you can have private modules for free!) There end up being some problems with this model. Popular modules might be hosted on some server that can't stand the load, and if you can't pull dependencies, the entire module system breaks down. So, you probably actually want the modules on a CDN, because high availability is important for CI systems. Before Go automatically pulled from Google's module proxy, I had my own. I had to, because Github rate-limited our pulls (and when it wasn't rate-limiting us, it was slow). Setting that up was a few hours I had to spend for no good reason -- it didn't make my product better, except by making some incidental step between idea and deployment slightly faster. You can of course vendor your modules (now your git clone is slow), or add caching to your builds (go's caching is very good, but doesn't play well with Docker). All of them take your time and mental energy to do something unimportant. So, Google made a module proxy that Go pulls from by default. It works every time. It probably costs them almost nothing. There is no business value in it. Google doesn't need Go for anything. They just have some employees that want to improve the lives of average programmers. You can turn it off. You can host your own -- go/x has an example proxy, and there are full-fledged open source projects that add more features (Athens). It's actually a very good situation. You can be as centralized or as decentralized as you desire. Going back to centralized package databases, they do have some really useful features. The main one I use is looking at users of a package that I'm reading documentation for. No example code in the repository? No problem. You can go see how other people are using it. The problem there is getting a list of all possible packages. You can poll common repository hosts for them. You can convince everyone to use a certain proxy that gets the names of the modules you are using so you can go index them. That's what Google does, and the user experience is great. You trade Google the information "the IP address 1.2.3.4 uses github.com/foo/bar" to get the knowledge of every Go module in the world. Seems like a good trade. And you can easily fork go and tell it to use your proxy, and make your own package database. The code is open. The license allows it. Go for it! Would it make more sense for Go to be owned by something like the CNCF instead of Google? Sure. But they did make it, so it's kind of their choice. It is pointless for a large company to make a brand new programming language, but they did it anyway, and it's nice that we have it. They give us lots of free stuff and ask for nothing in return. The fact that your CI system pulled a Go module is not something that advertisers are salivating over. If you want to hurt Google because you don't like them, ask your lawmakers to make advertising illegal. That would show them! But caching Go modules is not a big moneymaker for Google, it's just kind of a nice thing they do because a few employees thought it would be good. I appreciate it. If you don't, set up Athens and forget about them. I am sure you can render godoc just as nicely as pkg.go.dev with only a few hours of work. The thing is, it's boring and nobody would care.
- dpifke 6y agoIs anyone aware of any third-party project which attempts to audit sum.golang.org (and/or sum.golang.google.cn)? Its design is similar to that of certificate transparency, in that changes or deletions (e.g. DMCA takedowns or FISA warrants) are supposed to be detectable; see: https://go.googlesource.com/proposal/+/master/design/25530-sumdb.md https://go.googlesource.com/proposal/+/master/design/25530-s... I'm curious if anyone has actually tried to audit it.
- lenkite 6y agoOne of the reasons that despite Go's several advantages, I still prefer an open language like C++ for native programming. Go is Google's language and people should never forget it.
- amscanne 6y ago> Go is a pretty good programming language. I have long held that this is not attributable to Google’s stewardship, but rather to a small number of language designers and a clear line of influences which is drawn entirely from outside of Google — mostly from Bell Labs. pkg.go.dev provides renewed support for my argument: it has all the hallmarks of Google crapware and none of the deliberate, good engineering work that went into Go’s design. Putting aside the criticisms, I think a new word is needed to describe anti-Google sentiment of this flavor. The idea that Google is incapable of doing anything positive, so anything “good” coming out of Google must be attributable to influences outside of Google. I’d like to think about it as a “no true Googler” argument. The Go team are not true Googlers, because they produce something useful. When they built that module proxy however, they were clearly so doing as Googlers. (As someone who works at Google, I can humorously imagine that when I’m acting as a true Googler, my only goal is to foist new crapware onto the world, get promoted, and kill it off.) Or maybe we recognize that companies are collections of individuals, and all individuals bring their own history and influences. The culture shapes them and they shape it back. Playing semantic games to divide and attribute isn’t useful.
- ddevault 6y agoThis is not a "no true Googler" argument, but a factual statement supported by the history of Go. The design of Go is heavily inspired by Plan 9, Inferno, and Limbo, none of which came from within Google. In fact - name any of the flagship features of Go and I'll draw a line for you from that feature into the historical influences. Goroutines, channels, garbage collection, GOPATH... none of these were invented by Go.
- amscanne 6y agoRight, but Go itself, which builds on those ideas was built within Google. I have no objection to attributing ideas, but you seem to want to attribute some general “quality of engineering” attributes to “not Google”. The people doing things you like are just as much Googlers as all the people doing things you don’t like, and they all have an influence on the company and vice versa. In many cases, it’s even the same people. So the distinctions you are trying to draw are silly. Just let the criticisms stand on their own.