43 ms·
Why is Debian the way it is?
- bfrog 3y agoWell certainly part of it is much of the .deb ecosystem still feels like its stuck in the late 90s linux era to me. But maybe I'm alone on that gut feel.
- __float 3y ago"stuck in the late 90s" in what sense? Building them? Distributing them? (Dependencies?)
- Zetobal 3y agoI would say the process on getting "maintainer" status.
- deleted 3y ago[deleted]
- gorjusborg 3y agoThat they work reliably?
- bfrog 3y agoThey work reliably with a lot of unseen work. Debian is a great distro as a user. The .deb packaging tools I found to be a huge hassle and made packaging up missing or updated or custom software a pain in the ass.
- klysm 3y agoExactly, this is why it takes literally years of human effort to get a new version released
- bfrog 3y agoHave you built a .deb with debuild and debhelpers? Can you recall all the goofy rules about what needs to go in each file and what each debhelper does? How do you keep all of it in version control and build downstream packages that depend on the changed one? Have you managed to accidently sneak a local build machine dependency or piece of information by accident into the final .deb only to realize it much later? I found it be a big ball of easily forgettable twine of rules tools and oddities myself that every time I needed to redo something was a hassle. With many foot guns that lead to odd package issues.
- klysm 3y agoCompletely agree with your assessment of the building process. The majority of the complexity involved in the process is not inherent
- cswhnjidd 3y agoBetter being in the 90s than using snappacks or whatever.
- reactordev 3y agoYes but at least I don’t see ads on my Operating System for Viagra. I’ll take 90s boring linux over windoze everyday of the week.
- switch007 3y agoDeb packages just need reinventing by some younger people. I’m thinking: implemented in nodejs with a cli with emojis and animations. The GitHub read me should have a minimum of 80 emojis and a meme or two. The core dependency of the cli should be a 6 month old framework with 92 commits. When that library reaches 1 year old, it should be swapped out for something newer as the sole maintainer will have left their job and/or got bored with the project having spent so long on it
- klysm 3y agoExcellent straw man takedown
- Narann 3y ago> the .deb ecosystem still feels like its stuck in the late 90s linux era to me. Can you elaborate, please? What do you mean by this?
- klysm 3y agoQuirky, clunky tooling with a bunch of arbitrary shit you have to memorize to use correctly. People enjoy that kind of thing after they learn it.
- hyperman1 3y agoI'd like you to explain this a bit deeper. As a user from the '90s I am quite happy with it, but I might be stuck in my ways, who knows? So not saying you're wrong, but what are we missing exactly?
- em-bee 3y agowhat deb and rpm and any similar packaging are missing is true version control of the whole packaging ecosystem. at present it is difficult to track which combination of package versions has been tested, and you can't easily roll back to a tested combination. the current systems assume that versioning is linear and that a newer version of any package is always better than an older version. downgrading any package so that every user of the distribution can benefit from the downgrade is difficult and confusing. there are distributions that provide rollback. but as far as i can tell they require you to keep the old version to roll back to, stored on your computer. you can't roll back otherwise. i really want this to work like revision systems for code, where i can just checkout any old version that was committed. another feature that i would like to see everywhere is stickiness of the packaging source. currently, if i include additional repos they override the main repo, such that always the newest version is picked from any repo. this makes it difficult to include less trusted 3rd party repos. i would like to be able to add 3rd party repos such that only the packages that i explicitly install from that repo will also be updated from that repo, while any other packages in that repo will be ignored unless no other repo has them. in debian it is possible to set priorities for different repos, but that is not easy to manage. the priorities to have each package update stick to the original repo should be default. guix and nix do provide some of this as far as i can tell, but i am not a fan of keeping every package self contained with massive link trees. (i may change my mind on that some time maybe, but that's what i feel for now) conary was/(is?) a packaging system that did have both of these features, although, according to some of the developers the repository was a bit clunky and could have been better. but that was under the hood, not noticeable to users and packagers. i loved working with it and i wish foresight, the distribution using it had become more popular so that it would have had the manpower to keep going.
- pabs3 3y ago
- fsflover 3y ago> what was “free software” was defined by the Free Software Foundation, but in a way that left much to be interpreted I don't understand what the author means here. What is unclear about the four freedoms? To me, Debian's definition looks redundant.
- Brian_K_White 3y agoIt's like the US constitution and the bill of rights. Everything in the bill of rights is technically redundant and covered by principles already expressed in general form in the main constitution. And yet that isn't actually good enough. Those general principles, being general rather than specific, require the key word, interpretation, in each new specific context. And different people with different goals can and do always ALWAYS warp interpretation in infinite ways that are all perfectly reasonable sounding on their face, and yet someone else can always produce a totally different interpretation, which also holds together.
- mcpackieh 3y agoCan you give any examples of software projects or licenses in which there's room for genuine disagreement in interpretation of these rules? I'm having trouble imagining it.
- mjw1007 3y agoDoes a licence that says "you must distribute the source unmodified, but you're allowed to distribute patches with it and a build system that applies them" count as free? The DFSG said yes. Does a licence says "you may modify this and redistribute it as much as you like, but if you put it on a CD then everything else on there must also be free" count as free? The DFSG said no.
- reactordev 3y agoYou would have to compare them at the time. Things have changed. At the time Ian felt it didn’t do enough. Revisions and decades later it’s basically parity.
- dsr_ 3y agoLIW left out one major chunk: because Debian is a volunteer organization, and nobody can make a volunteer do anything that they don't want to do.
- cf100clunk 3y agoLeft out another major chunk: the conflict that arose over the eventual systemd adoption. To me that conflict altered the concept of ''What is Debian'' permanently, for better or worse (depending on who you listen to).
- VancouverMan 3y agoRegardless of whether one likes or dislikes systemd itself, I think that unfortunate debacle can only be seen as causing harm to the entire Debian project. The politics of it certainly generated a lot of distrust and resentment among the users and contributors. The project's reputation was undoubtedly hurt. Perhaps most importantly where the technological impacts. It's one thing when a user can generally ignore the politics surrounding a Linux distro, and the software still does what it needs to do. It's another matter when one routine update after another causes their computer(s) to no longer boot, among other serious problems, all thanks to systemd. Users definitely notice incidents like that, and it decreases, or even eliminates, their trust. So much hard-earned and invaluable goodwill was unnecessarily lost during and after that period of time. If any good did arise from that situation, it was that more people became aware of the BSDs, or tried them again if they'd used them in the past. FreeBSD and OpenBSD saved users who needed the reliability and trustworthiness that Debian used to offer, before systemd negatively affected the quality of Debian.
- Aeolos 3y ago> before systemd negatively affected the quality of Debian Is there any publication quantifying this? I followed the whole debacle with interest, and my personal experience with my servers was the exact opposite: adopting systemd improved reliability and made administration significantly easier. It's sad that this was politicized by a small part of the community, but the end result was worth it.
- happytiger 3y agoDebian is Toyota. Reliable but boring. Except it’s also built by volunteers.
- aiunboxed 3y ago> The historic background for this is that the first Debian project leaders were implicitly all-powerful dictators until they chose to step down What was this about ?
- hnbear 3y agoI assume the Ian Murdock (founder and Ian in DebIAN) transition to Bruce Perens, then Ian Jackson then annual project managers.
- Brian_K_White 3y agoIt simply means what it says. The first few leaders were simply in charge of everything like an owner, they made all major decisions themselves and told everyone else what the plan was, and each one did that job until they decided they didn't want to do it any longer and handed it off to the next leader. They were a dictator only in the literal sense that they dictated, not that they were tyrants. They weren't literally an owner. That's why the "implicitly". Everyone was still only volunteers. But everyone volunteerily let them call all the shots. Then later they developed a formal democratic structure and the leader is more of a coordinator than boss.
- qaisjp 3y agoBenevolent dictators
- FuriouslyAdrift 3y agoI worked with Ian Murdock at Purdue in the days of the very first release. He was a sysadmin and devloper while I was a web designer for the libraries. The guy truly believed in the GNU/Linux 'way' and 'free as in speech' software. His initial drive was from the difficulty of packaging and package management and that is probably his biggest contribution. Network-of-Workstations (NOW... think peer-to-peer infratsructure) was his passion that he really never quite got going. Bruce Perens, the guy he handed control over to, is the authoritarian leader being refered to. I like the guy. He's definitely in the old guard, aka Linus Torvalds, style of management. In big complex projects with volunteers that syle works. Anyways, the old days of Linux and Debian were a blast. I never quite go tinto like all these other people, but I miss those old days. There's way too much money people involved today. So it goes. Ian's manifesto explains it all, anyways. https://www.debian.org/doc/manuals/project-history/manifesto.en.html https://www.debian.org/doc/manuals/project-history/manifesto...
- BruceEel 3y agoThank you for sharing this, it all rings so true. Love Debian and still use it.
- Maken 3y agoThe hell happened with Murdock after Debian? His trajectory since he stepped down until his death seems quite erratic.
- layer8 3y agoHow so? https://en.wikipedia.org/wiki/Ian_Murdock#Life_and_career https://en.wikipedia.org/wiki/Ian_Murdock#Life_and_career
- aleph_minus_one 3y agoSee the next section: > https://en.wikipedia.org/w/index.php?title=Ian_Murdock&oldid=1170695012#Death https://en.wikipedia.org/w/index.php?title=Ian_Murdock&oldid...
- talkingtab 3y agoSeveral open source software organizations are remarkable. Not little remarkable, big remarkable. As in they show us how alternative models to the typical corporate business model may well be far superior as a way for people to collaborate. For the most part these remarkable are unknown. I have used Debian for (ahem) a very long time without knowing much about the organization and this article was a very good introduction. I have been aware of the IETF for quite a while. What is most amazing is that the internet today was built (more-or-less) by the IETF. See The Tao of IETF (https://www.ietf.org/about/participate/tao/ https://www.ietf.org/about/participate/tao/). This is an organization with no members. It just works. Hardly anyone really knows about it. Just as interesting is what happened when the corporate world decided to compete with the IETF for control of how the internet worked. Some people call this the protocol wars. (https://en.wikipedia.org/wiki/Protocol_Wars https://en.wikipedia.org/wiki/Protocol_Wars). For a while it seemed like each month the OSI would announce a project to replace parts of the internet, like TCP, with an X.protocol. Of these efforts very few survived and thrived - like X.509. The question that comes to my mind is whether these kind of democratic type collaborative organizations are in fact superior (far superior?) to the traditional corporate model. I personally have watched many corporations act with obvious stupidity. Doing things that can only be described as severely fight-their-way-out-of-a-paper-bag challenged. To put it kindly. Certainly these other-style organizations do not really stack up on an economic basis. The income of most corporations dwarfs that of both the IETF and Debian. And yet as a contributor and creator, I can ask Cuo Bono? Certainly not the contributors, they subsist. And perhaps most interesting to me, and perhaps worth an experiment, is whether it is possible to use an IETF or Debian style model that competes with the corporate model. It did work once with the Protocol Wars, so maybe. (edit to remove markdown syntax, sigh)
- zajio1am 3y ago> Just as interesting is what happened when the corporate world decided to compete with the IETF for control of how the internet worked. Some people call this the protocol wars. (https://en.wikipedia.org/wiki/Protocol_Wars https://en.wikipedia.org/wiki/Protocol_Wars). For a while it seemed like each month the OSI would announce a project to replace parts of the internet, like TCP, with an X.protocol. Of these efforts very few survived and thrived - like X.509. I would not describe it as 'corporate world decided to compete with IETF', than 'governments tried to enforce its power'. IETF working groups are often full of engineers from corporate vendors trying to collaborate to ensure interoperability, while ISO is traditional top-down governments-led organization.
- zee2345 3y ago[flagged]
- Iwan-Zotow 3y agoPaint yourself purple and join Debian - easy...
- zee2345 3y ago[flagged]
- cswhnjidd 3y agoBecause real diversity comes from people who look different.
- _8j50 3y ago[flagged]
- deleted 3y ago[deleted]
- Karellen 3y agoThere's an "anti-sysv-init train"? `sysvinit` is still available in the current version of Debian, Bookworm, released less than 4 months ago: https://tracker.debian.org/pkg/sysvinit https://tracker.debian.org/pkg/sysvinit Note that `runit` is also available: https://tracker.debian.org/pkg/runit https://tracker.debian.org/pkg/runit Also, while it's not the default init system, there are instructions for setting it as the active init system, on the Debian wiki: https://wiki.debian.org/Init https://wiki.debian.org/Init Note that while packages aren't forced to provide native sysv init scripts (or native runit init scripts either), I hear that sysv init scripts are just shell scripts that are incredibly easy to write even for inexperienced sysadmins (much easier than writing systemd unit files apparently?) so cobbling together any that are missing for a sysv-based system shouldn't be much work.
- _8j50 3y agoA .deb package being available is not the same as init scripts maintained or being allowed to select an init system during install. Sysv init scripts for every package already existed since that was the only init system in use by debian until 2014, people volunteered to keep maintaining those but they were overriden in lieu if systemd only approach. It seems you didn't use pre-systemd linux. It felt like you controlled the whole OS. Linux has always been about giving control to users. Systemd works great but it's geared towards corporate users who want better managability. So in a way, by violating the unix modularity philosophy, major distros sold out to corporations. Now systemd manages not just init but dns, logging, cron type scheduled jobs, fs mounting, system time,etc... it forced architectural changes where either you accepted systemd way or the unix way. And a lot of projects caved in. Openrc and sysvinit manage init scripts/services. That's it. You know how they work and they are designed to be compatible with anything else. If you need a schedluled managed for example, sysvinit or openrc have no opinions how to do that, you can use cron or your own thing, you have full control. Systemd on the other hand has timers, they work great, but guess what they don't play nice with? Openrc and sysv init. Guess what plays nice with all 3? Cron and it's many implementations. The modular design of Linux gave users power. The centralized opinionated systemd design gives the few "elite" influential people who work for big corporations power and control because their design does not take into account interoperability with arbitrary services.
- cswhnjidd 3y agoTIL Debian is mostly packaging. Love it, Debian is amazing.
- RetroTechie 3y agoPackaging, and more importantly: package dependencies, are (imho) the essence of building a successful distro. Get this wrong, stuff breaks regularly, and one ad-hoc fix follows another, forever. Get this right, and everything Just Works™ (generally). Debian is very good in this regard (along with the BSDs, I'd say).
- klysm 3y agoDebian is very much one ad hoc fix after another, to an incredible degree really. Go dive into the source and patches and you’ll see how much duct tape there really is holding things together. What’s so great about Debian though is it effectively hides all that pain from you (most of the time).
- jowea 3y agoYeah, that's 90+% of what a Linux distro is, packaging software from a wide variety of projects and trying to make a coherent whole. In Windows/MacOS we have one company making the kernel, basic libraries, desktop manager and some applications, and separate independent software developers making and packaging their own applications (although that changed a bit in the last decade or so).
- chubot 3y agoI just switched to Debian this year after ~13 years of Ubuntu, and I really appreciate it It grew on me after a long time. I always thought it was not the most "technically sound" way of doing things i.e. I don't really like the packaging model of global updates where you don't know what's going on, and sometimes there are version conflicts But I have come to appreciate the stability and good intentions of the Debian project Sometimes it's not technical excellence that matters the most, but the purpose and goals of the project
- dietrichepp 3y agoYeah. I keep coming back to Debian after trying out another distro for a while. There are some specific complaints I have about technical choices for Debian, like the way daemons autostart post install. But these complaints are outweighed by the benefits of using a distro with coherence across packages and upgrades. Apt is also just such a phenomenal package manager. It is fast out of the box, and supports some relatively tricky scenarios—like using stable for your system, but a newer Nginx from backports. Feels like I can get the newer features for the one or two packages that I really care about, and then use something stable and boring for everything else.
- chubot 3y agoYup exactly, I hated the daemon autostart thing. But it's a small issue compared to the mess I see in the rest of software these days ... Alpine Linux seems interesting too, although right now Debian suits me well. I guess the problem is that I still don't make Debian packages myself, while Alpine's APKBUILD seems more approachable -- pure shell, while Debian has an array of tools and formats. But Debian "lagging" a bit can be a feature, not necessarily a bug.
- bostik 3y agoI'm a Debian user since 1998 and have had it as my personal desktop since that time. I'd think that counts for something. > Apt is also just such a phenomenal package manager. It is fast out of the box, This wasn't always the case. There's a good reason almost all guides first written before 2015 specifically instructed everyone to use 'apt-get' directly. For quite some time the more uniform 'apt' frontend really wasn't intuitive or helpful. (Just to be clear: these days it is phenomenal in its simplicity and clarity.) And as someone who has has to dive in to the package managers' code bases, the overall quality of libapt used to be .. questionable. Figuring out code and control flows back in 2010 was like trying to rub chili out of your eyes with an unsanded wooden spoon. But the sheer bullheaded stubbornness Debian imposes on their package universe and its architecture means it's an absolute joy to work with if you're doing any kind of distro customisation work.
- FpUser 3y ago>"Self-contained" I love that whole paragraph. And in general prefer their philosophy.
- pabs3 3y agoDebian doesn't go far enough on that point, the folks at GNU Guix and Bootstrappable Builds are getting to the point where they can build the entire distro from source starting with only ~500B of manually written machine code. https://bootstrappable.org/ https://bootstrappable.org/ https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-building-from-source-all-the-way-down/ https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-...
- FpUser 3y agoDebian is enough for me in this regard. I am not chasing absolute perfection.
- larme 3y agoSometimes I daydream about getting a fuck-it amount of money. During this thought process I always make a plan of what open source software project I should donate, and debian is always one of the first several candidates. Now I just need the money! (meanwhile I donate to debian anyway)
- tarruda 3y agoThis article from 2020 says Debian doesn't need money: https://www.theregister.com/2020/09/10/debian_project_address/ https://www.theregister.com/2020/09/10/debian_project_addres...
- samueloph 3y agoDebian can't really directly pay contributors (there are some rare few cases like lawyers, etc....), so that would be one of the reasons for what the article is talking about. The best thing someone could do in this scenario would to be hire someone to work on/improve Debian directly.
- humanrebar 3y agoSomeone could form a nonprofit org that funds packaging work in Debian. Or maybe even a for-profit one. I'm pretty sure a lot of big consumers would rather pay for expertise instead of having an in-house Debian "upstream" team.
- Karellen 3y agohttps://www.debian.org/donations https://www.debian.org/donations > The easiest method of donating to Debian is via PayPal to Software in the Public Interest, a non-profit organization that holds assets in trust for Debian. https://www.spi-inc.org/ https://www.spi-inc.org/ > Software in the Public Interest (SPI) is a non-profit corporation registered in the state of New York founded to act as a fiscal sponsor for organizations that develop open source software and hardware. Our mission is to help substantial and significant open source projects Edit: But also, freexian https://www.freexian.com/lts/debian/ https://www.freexian.com/lts/debian/ > To achieve the 5 years of support, and properly cover all Debian packages, Freexian organizes a corporate sponsorship campaign with the goal of funding the work of multiple Debian contributors who are established as independent workers. > If you are not yet convinced, here are seven reasons why you should help fund the Debian Long Term Support initiative (LTS):
- talent_deprived 3y agoDebian could be great except for driver support which they only tacitly acknowledge: https://www.reddit.com/r/debian/comments/paxj85/why_debian_with_proprietary_drivers_is_not/ https://www.reddit.com/r/debian/comments/paxj85/why_debian_w... "We acknowledge that some of our users require the use of programs that don't conform to the Debian Free Software Guidelines. We have created "contrib" and "non-free" areas in our FTP archive for this software." I had it running on a couple of my machines about 1 or 2 years ago and an update came in for WiFi that bricked them. I started looking into rolling back or whatever and just decided to switch those to Ubuntu (or Kubuntu actually) and they work great and have has no issues.
- Nextgrid 3y agoThey've now relaxed their (stupid) policy so at least the default ISO includes non-free drivers. When it comes to an already installed system, enabling the non-free repos and installing linux-firmware (or more specific firmware-* package for your hardware) should fix it.
- dartharva 3y agoIf the default ISO already included non-free drivers, why would you have to separately enable the non-free repos to get firmware? My Debian 12 install didn't come with proprietary Nvidia drivers, nor did it ask me if I wanted them during installation. I had to enable the non-free-firmware repo to get them.
- Nextgrid 3y ago> If the default ISO already included non-free drivers, why would you have to separately enable the non-free repos to get firmware? I'm not 100% sure about this but I believe it may enable it for you automatically if non-free firmware was used during the install. I mentioned it just in case. > My Debian 12 install didn't come with proprietary Nvidia drivers The primary problem of the previous non-free driver policy is the lack of network drivers which make it impossible to install nor download the drivers even if you somehow managed to install the OS. This is now resolved. It's not a big deal if the ISO doesn't include every non-free driver out there as long as you can manually install it after the fact.
- arun-mani-j 3y agoI personally love and use Debian exactly for its principles and stability. I have heard users of other distros and a few upstream complaint that Debian "modifies" their packages? Is it so? If yes, there surely must be a good reason. Can someone tell me about it?
- klysm 3y agoApplying patches increases the cost of making changes.
- rlpb 3y agoDebian has a user-first philosophy as well as a focus on integration between packages. When required, that means patching upstreams that don't meet that expectation for whatever reason. The ability to do this is precisely the point of Free Software.
- alphager 3y agoThere's mainly three kinds of patches: * make the software behave like Debian needs it (configuration is stored somewhere in /etc/, no additional downloads at runtime, use the system libraries instead of vendored ones) * security backports. Debian freezes the functionality at release and only provides security updates. Many software nowadays just includes security fixes in new releases bundled with new functionality. In combination these two kinds of patches lead to growing differences between a Debian released version 1.2 and the "real" 1.2, making it harder to handle bug reports (e.g. you get a bug report for version 1.2-Debian, but only support the "real" version 1.4 with a whole set of updated libraries). The third kind of patch has mostly gone out of style; it's when Debian thinks they can improve the software. That lead to things like removing randomness from SSH keys: https://github.com/g0tmi1k/debian-ssh https://github.com/g0tmi1k/debian-ssh
- rlpb 3y agoAnother kind of patch is when a common dependency library is being updated, and laggard upstreams need patching to make their current releases work against the newer library; it's either that or a Debian release with those packages missing. This type is actually really common. Debian packages something like 30k upstreams, and so some are always behind.
- throwkwknskkc 3y ago[dead]
- natebc 3y agoEncourage those sane companies to donate to Debian as well. The more financial stability Debian has the better off we'll all be. https://www.debian.org/donations.html https://www.debian.org/donations.html
- klysm 3y agoI agree it’s probably the most reasonable choice for most, but I’m hoping that changes. I want more immutable infrastructure than what Debian can provide
- Dwedit 3y agoDebian's policies also led to a heavily restricted version of RetroArch being available instead of the real version. Specifically, RetroArch has its own package management functionality built-in through its "Core Updater" feature, which downloads and installs emulators in the form of library files. This is banned by Debian because it sidesteps the whole package manager system. Meanwhile, you can still build the full version of RetroArch from source code by installing the dependencies of Debian's source package, but building the original source code instead.
- cogman10 3y agoDebian is somewhat of a bad fit for a media center PC. I've learned that the hard way trying to get Kodi and retro arch working. It's otherwise a great os.
- LeoPanthera 3y agoRetroArch provides a Flatpak, making this mostly a non-issue.
- Barrin92 3y agono, from a distribution standpoint it's a pretty grave issue. As the name suggests distributions distribute, and if we start to unbundle the OS from the application layer, Debian loses the very thing people chose it for. It's in a sense like a legacy carmaker or newsroom being more concerned with its own control than with the product. Doesn't end well over the long term.
- LeoPanthera 3y ago> Debian loses the very thing people chose it for I don't buy this. People don't choose Debian for the third party software in the repo. If they did, it's a bad choice. People choose Debian as a rock solid and stable base OS, and it's perfectly rational to use it as a base for third party software on top from other sources.
- 3y ago
- klysm 3y agoI think the next generation of immutable distros is going to eventually make Debian effectively obsolete for many service workloads.
- rlpb 3y ago"Self-contained" and "No bundled libraries" are two very important concepts that a subset of our ecosystem decided was too much work. Then they re-discovered all the problems that result, and have now coined terms like "software supply chain" to describe them. Meanwhile Debian doesn't suffer from any of this because it's been doing things so as to avoid these issues all along.
- asveikau 3y agoI think either approach makes sense depending on who you are. If your goal is to distribute software across multiple distros and operating systems, bundling dependencies makes sense. If your goal is to maintain a distro, shared libraries that you can apply a security patch to exactly once is obviously better. But these are two different people with either goal.
- bscphil 3y ago> If your goal is to distribute software across multiple distros and operating systems, bundling dependencies makes sense. Of course, an important "exception to the exception" is when you're making software that can easily be distributed by distributions, e.g. because it's end user software and open source. I think the optimal cases for bundled dependencies are (a) large closed source binaries that never change, like games, and (b) self-deployed software, e.g. something like a server written in Go that is compiled and maintained in its running environment by a single developer or company.
- Aerbil313 3y agoThe endgame of dependency management is the Nix model. U believe manually packaged software repositories' era is coming to an end.
- duped 3y ago> is when you're making software that can easily be distributed by distributions, e.g. because it's end user software and open source. I have trouble understanding why this is desirable for either authors or end users. Even for open source end user applications, I want the software that I'm running to be reflective of the software that was authored and not the software that some distro maintainers think it should be.
- barumrho 3y agoI used to choose other distros for more updated dependencies, but now I appreciate the stability at OS level a lot more. Containers also solves the problem for running services.
- codedokode 3y agoWhat I don't like in Debian: - 3rd-party software is not welcome; there is no mechanism for installing it securely because you are supposed to either install software from official repository or compile what you have written yourself. For example, if you want to install Sublime Text, or VS Code, there is no way to do it securely, without giving untrusted software access to your browser history and SSH keys. Of course, you can ignore security and run sudo curl http://script http://script , but it doesn't guarantee that the installer won't break something. It is like we are back in 95 when every second program would replace system DLLs in Windows folder and break other software. - there are third-party repositories, but they can cause conflicts and you better not use them, but there is no other way to install third-party software. Third-party software is very important, I install OS to run it, and it surpises me that Linux is so unfriendly to third-party software, including closed-source software and doesn't provide means to install and run it securely and reliably and without making developers adapt it to every existing distribution. - their bugtracker is email-based and as I don't use email it is completely alien to me. But maybe this is not bad because it stops most of people from posting bugs and saves time to reply to them. I also tried Fedora, and here is what I don't like: - they release a new version every 6 or 12 months and it is incompatible with older version, and you have to use a very weird way to upgrade: first, you need to install non-standard plugin (dnf-plugin-system-upgrade), then you need to download packages, then reboot into a temporary OS, then if everything is ok, it will create a new OS, and reboot into it. It looks complicated, easy to break and probably requires a lot of disk space, while Debian can upgrade everything in place. - if a system component like Gnome is crashing, there will be neither log records nor crash dumps and you will never figure out why it has crashed Also, APT is buggy when dealing with mixed 32-bit/64-bit packages: I wanted to install a package once and it suggested to delete half of the system to do it; luckily I have noticed that the package list is too long before agreeing. Why would package manager delete packages when I ask to install something, I don't understand. As a bugtracker requires using email, I didn't report it, and it would be difficult to reproduce this anyway.
- Karellen 3y ago> For example, if you want to install Sublime Text, or VS Code, there is no way to do it securely, without giving untrusted software access to your browser history and SSH keys. First, if you don't trust a bit of software, why are you installing it? But more importantly - you don't want your text editor to be able to open and edit your browser history files, or your ssh key files? If my text editor wasn't able to open and edit those files, I'd consider it extremely broken!