5 ms·
> If we're going to be trusting some random guy's binaries, I think we are in the right to demand that it is byte-for-byte reproducible on commodity hardware I
by DisgracePlacard 3y ago
> If we're going to be trusting some random guy's binaries, I think we are in the right to demand that it is byte-for-byte reproducible on commodity hardware
I don't think anyone has a right to demand anything of the project. The MIT license specifically has the whole "THIS SOFTWARE IS PROVIDED AS IS" spiel for a reason. Thinking that you can demand anything of an open source developer who, afaik, has no responsibilities in relationship towards you, is a rather toxic mindset that should be kept out of open source.
- saagarjha 3y agoThat’s not true. I can, for example, demand that an open source project not bundle malware. The maintainer may not listen to me but I reserve the right to demand it and I don’t see how this is toxic at all.
- pessimizer 3y agoThe demands are provided "as is," too, so you have no right to complain about them.
- zer8k 3y ago"No one has any right to complain because muh license agreement" What a tiring argument. Why complain about anything? Why do anything differently? Maybe it's because people have invested time, money, and effort into supporting and using the project and because of your stupid decision they now have to do more work. There were a lot of comments about people showing up that monday to pin+vendor the old SerDe. Others planned to remove it entirely in favor of other libraries. Almost like actions have consequences even if your "license agreement" says otherwise. > is a rather toxic mindset that should be kept out of open source. I wish I lived in your echo chamber where everyone who uses your stuff is just totally, like, accepting of your garbage ideas. The precompiled binary idea was a classic garbage idea. Refusing to make it reproducible was just the corn on top of the cowpie. The author made a major screw up, doubled down, tripled down, and then finally gave in. The author has no idea what scale and scope of project this is used in. They also clearly did no evaluation on potential damage OR ask for feedback before moving it into mainline. For a library with 3M+ downloads this was the what third? Fourth? Classic ego-driven folly. You know what else shouldn't exist in open source? Ego tripping morons.
- DoesntMatter22 3y agoI'm not sure why you are attacking the guy personally and saying he lives in an echo chamber. All he did is say that you can't demand anything of the guy as he has not obligation to do anything. That's in the agreement that you agree to when using the software. He's free to tank his own project and you are free to use it, fork it, or not. He's allowed to be an ego maniac if he wants or do things in ways you disagree with. You got what he made for free, so why you want to demand things of him is beyond me.
- saurik 3y agoI'd say that the core of your point is legally correct, but you are ethically arguing over what is, at best, a grey area. I mean, if the author is explicitly (by you) "allowed to be an ego maniac", then why isn't the user you are replying to allowed to judge them for it? The options available here are not merely to use it or to fork it: people being afforded the same freedoms you believe this maintainer should have also have the option to call them out over the result, no?
- DoesntMatter22 3y agoI'm not here to argue the morality of it. I'm just saying it's silly to complain about something and demand something of him. I mean I can demand a super model will give me a date but that doesn't mean I'm entitled to it or that it's going to happen. It's pretty much pointless. The difference between this guy and the maintainer is that the maintainer did this guy a huge favor by writing this software for the guy where as this guy did nothing except complain about the free meal he's getting.
- howinteresting 3y agoDo we as humans owe anything at all to each other outside of a capitalistic transaction-based framework? I think the burden of open source maintenance often goes too far in the other direction, especially when corporations demand free labor, but I think it's reasonable to expect maintainers of core libraries to not actively cause harm.