4 ms·
I love Rust but I have to agree installing rustup like that feels like a crime to my machine. For some time I would only install rustup when inside an air-tight
by doodlesdev 4y ago
I love Rust but I have to agree installing rustup like that feels like a crime to my machine. For some time I would only install rustup when inside an air-tight virtual machine since I can't really bother to read the sh script every single time I'm going to download it.
It's 2023, we have package managers, we have packages, we have containers, why are we still shipping software like this? Even worse is the fact that you can generally find Rust in your package manager of choice but it will often be outdated and you won't be able to choose your versions the same you would with rustup.
I don't know, I'm not sure I have a solution, but I just wish maintainers would put a little more effort into trying to support package managers as the de-facto way to set up a tool chain such as Rust. Even if you want to keep the meta-package manager such as nvm or rustup, at least let me download _them_ from my distros repositories instead of running a random sh script from the internet.
- UncleEntity 4y agoMaybe the problem is the rust community seems to live on the bleeding edge and always needs to have a ‘nightly’ build to do anything interesting? And distros usually don’t bump versions between releases because they just don’t. Run Debian Sid or Fedora Rawhide or <whatever> if that’s what you’re after.
- dheera 4y agoIt's straightforward to set up an apt-get repository that updates nightly and have users use that. For something as widespread as Rust I expect better than curl | sh scripts.
- FridgeSeal 4y agoWell I guess that solves the issue for one OS/distro. It’s probably not _why_ they did it, but I certainly like that regardless of OS, installation is the same and it’s reliable.
- steveklabnik 4y agoIt is a major part of why we did it. Giving everyone a nice flow for getting up and going matters for adoption.
- FridgeSeal 4y agoThat’s awesome. For what it’s worth, I had a C# dev who’d never dealt with Rust at all before get themselves setup, and then compiling and running the Rust app by themselves in about 10 minutes flat (our internet is slow) and I definitely think the ease of the setup flow contributed to that hugely, so massive thanks for making it so nice.
- UncleEntity 4y agoProbably doesn’t matter for Rust but once you start messing with random system packages that other packages depend on it becomes less than straightforward really quick. One simple version bump can effect hundreds of packages and, if you’re not careful, bork an entire install… ask me how I know that one. —edit— Also should say that I’m fully in the package manager camp. If I want to install something that’s not in the repos I almost always find or make a package and build it locally because I don’t want random orphaned files strewn around my system folders. Unless it’s just some command line program then I usually just use it from the source directory and don’t even bother having it in my path.
- steveklabnik 4y agoMany Rust users are on platforms that apt does not support.
- nindalf 4y ago> rust community seems to live on the bleeding edge and always needs to have a ‘nightly’ build to do anything interesting You have an example of a project that needs nightly to build? I’m sure some exist, but nearly all libraries and projects live on the latest stable release.
- doodlesdev 4y agoThat indeed used to be very common in the early days of Rust, however, I believe stable Rust is what most libraries and projects use nowadays. It's been some time since I saw anything that used Rust beyond 1.60 (release April last year) as a minimum version.
- csomar 4y agoHow come do you trust the package of Rust from Rust but you don't trust the `sh` install script from Rust?
- dheera 4y agoThis specifically isn't an issue of trusting them with my system, it's that a shell script can give a shit all over a system without a good way to undo it, even if it was well-intentioned. Package managers are modern technology, they exist because they can track what files were placed where, and can remove them cleanly when given an uninstall command.
- nicoburns 4y agoWhy do you trust scripts from your package manager more than one from the official upstream Rust project? The Rust project also has a good security track record.
- doodlesdev 4y agoI trust them more because I choose who mantains the repos I use. I trust them more because I already have to trust them: they provide almost every single piece of software I run on my machine. In this case I'm on Fedora which has a good track record for security, stability, and only allowing free software. It's not to say that I don't trust the Rust project, nowadays I kinda have to, but curl sh installation is messy and separated from the rest of the system. If they just packaged rustup into an rpm and set up their own repos I could point dnf to it would make system maintenance so much easier. I just want them to use the tools that already exist instead of reinventing the wheel with an esoteric 700 lines-long sh script. This applies to Rust and any other kind of tooling that does the same installation workflow. I understand the reasoning behind it, but I believe the other options should also be considered and supported.