3 ms·
Can't we just link statically but still maintain the list of dependencies as if everything was linked dynamically?
by ttt0 5y ago
Can't we just link statically but still maintain the list of dependencies as if everything was linked dynamically?
- johnny22 5y agosure, some packages in some of the popular distros are indeed like that. If the package is important enough (like firefox) and the required dependencies are a bit out of step with what's currently used by the rest of the distribution you will sometimes see that for at least some of the dependencies. Most distros dislike doing so, and scale it back as soon as it becomes technically possible.
- danShumway 5y agoThis is odd to me, because surely they have to maintain that list anyway so they know which dependent packages need to be tested before releasing bugfixes? Or is that step just not happening? I just feel like, one of the big points of a package manager is that I can look up "what is program X's dependencies, and what packages rely on it?"
- ttt0 5y agoBut they dislike just packages requiring different versions of libraries, right? My point is to do literally everything as it is right now, but simply link it statically. You can still have the same version of a library across all packages, you just build a static library instead of a dynamic one.
- R0b0t1 5y agoProblem if you're not set up to build everything yourself.
- ttt0 5y agoIs it? Just update everything regularly. Actually now that I think about it, building by yourself might put you at a disadvantage here, as you'd have to remember to rebuild everything. I'm kinda lazy when it comes to updates so not sure if I like the idea anymore with having to rebuild all the software I built myself lol, but it probably could be solved by also shipping .so versions of libraries.
- carlhjerpe 5y agoNix will solve this for you in a breeze.
- MereInterest 5y agoAutomatic updates are themselves a security risk, which is something that I rarely hear talked about. For example, the FBI's 2015/2016 dispute with Apple about unlocking phones. The FBI's position relied on the fact that Apple was technically capable of making a modified binary, then pushing it to the phones through automatic updates. If Apple were not capable of doing so (e.g. if updates needed to be approved by a logged-in user), then that vector of the FBI's attack wouldn't be possible. I don't have the best solution for it, but the current trend I see on Hacker News of supporting automatic updates everywhere, sometimes without even giving users an opt-out let alone an opt-in, is rather alarming.
- ttt0 5y agoI don't argue for automatic updates. It's pretty much whatever we already have, but instead of updating a single library, you'd have to update every package that depends on that library. I'm just throwing ideas around so you should definitely take what I'm saying with a grain of salt. It just would be interesting to see a distro like that and see what the downsides of this solution are. Chances are that there probably already is something like this and I'm just not aware of it and I'm reinventing the wheel.
- MereInterest 5y agoAh, got it. Sorry, I misinterpreted "update everything regularly" to imply developers forcing automatic updates on every user. I'm in the same boat, as somebody who isn't in the security field. I try to keep up with it, but will occasionally comment on things that I don't understand.
- ex_amazon_sde 5y ago> Is it? Just update everything regularly. On stable production systems? Never. The CIP project https://www.cip-project.org/ https://www.cip-project.org/ aims to backport security fixes to Linux for *25* years after each CIP release. No sensible organization runs bleeding edge OSes on their airplanes, power plants, payment processors, industrial plants...