6 ms·
I think the truth is that we don't feel like we need a release. We've never had a security hole, our track record speaks for itself, and I wouldn't really want
by keithwinstein 5y ago
I think the truth is that we don't feel like we need a release. We've never had a security hole, our track record speaks for itself, and I wouldn't really want us to rush anything and blow that. There are some features that it would be really nice to have in a release (like 24-bit color support, and working around a recent MacOS clock bug), but I handed over the maintainership to somebody else about six years ago and that person is currently, I think, dealing with a bunch of stuff (look around the world the last year...). I'm not eager to step back in and bigfoot them -- especially when I'm no longer particularly familiar with the codebase (and recent commits) as I used to be.
Mosh works as advertised and has never had a security hole -- we're pretty proud of that! We'll probably cut a release at some point to add those features (24-bit colors, the MacOS clock workaround) but I'm not feeling like it's urgent enough to upset what I had hoped was a transition plan.
It would feel arrogant to compare Mosh to TeX, but it doesn't seem that crazy to imagine that some software might reach a point where it has accomplished 95% of its goals, and the benefit from adding further features has to be weighed against the risk of introducing a security hole or other regression through further churn. If the TCP specification, or OpenSSH, or TeX, or GNU bash had canonical GitHub repositories, they would probably be full of a bunch of user support issues and inactive PRs too. :-)
- Hnrobert42 5y agoI don’t use mosh myself as I thought the project had been abandoned, but I know several folks that love it. Just want to thank you on their behalf. Also, I appreciate knowing you all are watching PRs and bug reports even if you don’t see the need to take action. Makes me feel the project is just dormant and not abandoned. If you care about continued use and adoption, you might consider posting an update to the website similar to this post you made here. If you aren’t worried about adoption, then no problem and thanks again for your effort.
- goodpoint 5y agoI would not call a working and usable piece of software "abandoned". We should call it "completed".
- WesolyKubeczek 5y agoMaybe once the glaring bugs in it are fixed. The ones where half of my keyboard shortcuts were acting funny (something like https://github.com/mobile-shell/mosh/issues/1147 https://github.com/mobile-shell/mosh/issues/1147), or garbage left from some other screens/commands (https://github.com/mobile-shell/mosh/issues/1079 https://github.com/mobile-shell/mosh/issues/1079). Midnight Commander is also being drawn in a jumpy way. Note that I'm not speaking about new emojis or some novel Unicode stuff, it's the same basic multilingual plane and line drawing characters we've had for decades now.
- goodpoint 5y ago> Maybe once the glaring bugs in it are fixed. Paintings, books, movies... are finished with the bugs in. Vulnerabilities need rapid fixes. Every other bugfix requires additional effort and comes with the risk of introducing vulnerabilities or other bugs. At some point 99.9% of the users are happy and the benefit of fixing another bug becomes marginal.
- WesolyKubeczek 5y agoA tool is a tool, not a work of art. Tools are supposed to be used. Therefore, flaws in them need to be fixed.
- shp0ngle 5y agoMaybe I was wrong about the burnout, I now read the thread and don't see it there. Maybe I remember wrong what I read. Sorry if I mis-represented something.
- arthurcolle 5y agoGreat response - not everything needs to be updated and upgraded every few days. Stability should be praised, not used as evidence of indolence.
- blondin 5y agoOMG amen to that! we have lost the notion of stability in the rise of agile software.
- spockz 5y agoI completely agree with the sentiment! I do wonder whether new releases are required to benefit from fixes and performance enhancements in libraries. Or is everything dynamically linked?
- only_as_i_fall 5y agoExcept that it's a lie. Not accepting new feature requests is one thing, but what actually seems to be happening is that new code has been accepted into the master which then never sees the light of day. Hiding behind "well we don't want to compromise the core software" after stringing other contributors along for years doesn't pass the sniff test.
- eminence32 5y agoIs there anything preventing you from running the latest version from git? Is there something special about a "release" that you're looking for? (I can think of several reasons why someone might want a release and not the latest master branch, but I'm curious about your specific reasons)
- buzzdenver 5y agoI am not OP, but think of it from a contributor's point of view: you work X hours on a new feature that even gets accepted into the master, but then you know that 99.9% of mosh users will not see it because it's not part of a release. I don't know how I would feel about that.
- divbzero 5y agoI’ve used Mosh all these years and never noticed the lack of recent releases. It just works.
- ComodoHacker 5y ago> has never had a security hole -- we're pretty proud of that! With all due respect, you pride on this matter should be no bigger than your userbase is.
- bkanber 5y agoMosh is very popular. Most devs I know personally have used it at one point or another in their careers.
- gspr 5y agoA breath of fresh air!
- dbtc 5y agoThank you for making a really nice thing and for keeping it that way.
- yason 5y agoThanks much and keep the same heading please! I really enjoy using tools that have matured and become good enough that there's no longer any major need for new features — and where nothing is added just for the sake of "improvement". I personally haven't had a single thing in Mosh I would've wanted to add to it, and I'm glad nothing has been added either. A lot of Unix tools are like that. They do what they were written to do and that's the scope they're sticking with. It's fine if, maybe once in five or ten years, some support is added for a thing that grew outside the tool itself, such as interfacing a new system component. This conservative development might be a trait of the less-flashy command-line world. In contrast, the desktop is full of programs that were in that good phase once but then development continued further, adding satellite features that just make the program worse until it's unusable even for the original purpose. Why not write another program to do the new things then, instead of packing everything into a single package? I don't know.
- deleted 5y ago[deleted]
- j1elo 5y agoI concur, but at the same time have a counterpoint. It always trips me how I can user Perl regex for powerful searching in grep, but then these are somehow not available in sed. The Extended syntax it has is not the same, still too verbose in comparison
- radicality 5y agoThanks for the tool! I use it all the time, even just now I’m on a crappy connection via cellular modem that oscillates from few bars LTE, to 3G at <10KB/s, to occasionally fully dropping out for a few seconds, and mosh keeps the session alive. I like the philosophy here, if the software is “done” and there is no immediate need for security fixes, don’t touch it.
- j1elo 5y agoomg I can visualize all those pull requests or feature requests on the TCP repo: "It would be a nice addition if TCP also did ..."
- dspillett 5y ago> I think the truth is that we don't feel like we need a release. Maybe issue a point release where the only change is updating the documentation (man page, output of --version, ...) to state that it is 2021 and you are still here, stable, free of security issues, but not adding/updating features ATM. Then the project doesn't look dead (which can be a security concern) when it is in fact just quietly carrying on with achieving its goals without the need for changes.
- rkangel 5y ago> It would feel arrogant to compare Mosh to TeX, but it doesn't seem that crazy to imagine that some software might reach a point where it has accomplished 95% of its goals The difference that I think makes this comparison invalid is that Mosh is a communication tool, whereas Tex is running locally on files. We (as a community) have learned that any software with a networked attack surface slowly gets less secure over time - you (almost always) need to provide ongoing security fixes to maintain the desired level of security. To be clear - I'm not saying you're wrong. I'm an intermittent user of Mosh and I can believe that no holes have been found that need patching (and that the team would in short order if necessary). It is, however, a signal that users of software look for. I like the idea in a sibling comment of the "documentation" commit just saying "we're still here" to reassure people.
- eminence32 5y agoIf a security issue was discovered in mosh, I feel pretty confident that we would find a way to make a release with that fix (even if it's just a point release that applies the fix on top of the current `1.3.2` tag)
- Crontab 5y ago> we don't feel like we need a release I think a lot of users look at the release history and cadence as a sort of heartbeat; in order to tell if a project is still being maintained. That can be a problem when a program reaches a mature state.
- gadders 5y agoCan it read email? I think that is the acid test for whether software is "done" :-) https://en.wikipedia.org/wiki/Jamie_Zawinski https://en.wikipedia.org/wiki/Jamie_Zawinski
- mattst88 5y ago> I think the truth is that we don't feel like we need a release. We've never had a security hole, our track record speaks for itself, and I wouldn't really want us to rush anything and blow that. There are some features that it would be really nice to have in a release (like 24-bit color support, and working around a recent MacOS clock bug), but I handed over the maintainership to somebody else about six years ago and that person is currently, I think, dealing with a bunch of stuff (look around the world the last year...). I'm not eager to step back in and bigfoot them -- especially when I'm no longer particularly familiar with the codebase (and recent commits) as I used to be. I can appreciate that, but what do you say to e.g. the contributor that added true color support nearly 4 years ago? cgull also hasn't authored or committed anything in mosh in more than two years, so his inactivity predates the pandemic by quite a bit. Everyone loves your software, and that's the reason they want to see another release with the many improvements already in git, most for multiple years. I really don't think you're going to step on any toes by making a new release. Pretty please?
- mrzool 5y agoGreat answer! I'm adding this comment to my favorites.
- hnrj95 5y agomosh has been a pleasure to use. thanks for all the hard work :). i think it’s worth experimenting with blink, too, if someone (like me) has the odd desire to try and be productive from an iphone or ipad
- anthony_barker 5y agoI would love to use it more but: 1) Has there ever been a full security audit? 2) if not and I run it inside a VPN (wireguard) doesn't that remove most of the benefits?
- atatatat 5y agoLess with Wireguard.