xgranade,
@xgranade@wandering.shop avatar

It's really odd and concerning to me to see that Debian rolled out a huge change to their packages for @keepassxc with no clear rationale, no clear governance process, and with snide and insulting comments left on the upstream project by packagers.

That's not a great open source community or governance approach.

https://github.com/keepassxreboot/keepassxc/issues/10725#issuecomment-2105062113

xgranade,
@xgranade@wandering.shop avatar

Trust in open source is key, and making mysterious changes for mysterious reasons is not a great approach to building and maintaining that trust.

glyph,
@glyph@mastodon.social avatar

@xgranade debian has a great track record with their home brewed crypto patches though

glyph,
@glyph@mastodon.social avatar

@xgranade (for the kids in the audience, I am sarcastically referring to https://www.schneier.com/blog/archives/2008/05/random_number_b.html )

glyph,
@glyph@mastodon.social avatar

@xgranade and I realize this is a very old bug, and I'm not aware of any other instances of this pattern that were quite as potentially disastrous, but it annoys me to this day because it points to a rot at the core of the idea of a "distro", where the "package maintainer" is not sufficiently familiar with the software to modify it, but the actual author of the software does not have direct access to ship software in an idiomatically-installable way

SnoopJ,
@SnoopJ@hachyderm.io avatar

@glyph @xgranade

> This will be painful for a year as users annoyingly do not read the NEWS files they should be reading but there's little that can be done about that.
> ...
> Users who need this crap can install the crappy version

I have spent a lot time explaining to people that Debian is a very opinionated distribution when it comes to packaging software, trying to stay short of accusing them of thinking upstreams are necessarily inferior, and this guy just comes out and says it…

glyph,
@glyph@mastodon.social avatar

@SnoopJ @xgranade the quality of debian package maintainers is variable and I try to maintain empathy for what is a necessary and thankless job in a very sub-optimal social construct, but I can say with confidence that every single one that thinks about upstreams in this way is an incompetent buffoon who will inevitably be hoist by their own petard

glyph,
@glyph@mastodon.social avatar

@SnoopJ @xgranade oh wow I didn't even look at what the actual change being debated here was, just the tone; looking at the feature in question this whole discussion is WILD

glyph,
@glyph@mastodon.social avatar

@SnoopJ @xgranade I am completely serious when I say that I believe that projects should seriously consider trademark litigation when distros do shit like this. Breaking the software in this way tarnishes KeePass's reputation and they should sue Debian to prevent them from calling this mangled derivative work "KeePass". (I am sure I am making every lawyer I am friendly with very happy that they are not my lawyer right now, though)

xgranade,
@xgranade@wandering.shop avatar

@glyph @SnoopJ I get there's legitimately tough calls that package maintainers need to make, but this is 1000% someone disagreeing with how KeePassXC is made and, rather than maintaining a fork, just sending users who don't like his changes upstream to yell at the actual KeePassXC. Truly awful.

SnoopJ,
@SnoopJ@hachyderm.io avatar

@glyph @xgranade a lot of my resentment of this attitude comes from the Python analogue of this.

python3 is a fundamentally broken experience for a user who wants to write programs on a Debian system unless they are writing "system programs" explicitly designed to fit Debian's worldview. But all the user frustration ends up on Python's doorstep, and Debian's response is still too close to a scoff

Underappreciated reality that a package named pkg REALLY means "what Debian thinks pkg is"

xgranade,
@xgranade@wandering.shop avatar

And now KeePassXC has gone on and locked the issue, all because a maintainer at Debian decided to turn an upstream repo into his personal soapbox about how software should work.

felix,
@felix@wandering.shop avatar

@xgranade But that's just it: culture in the western world, especially in English-speaking countries, downplays mutual respect, consent and trust in favor of rules-lawyering. Then people wonder why society is so divided.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ethstaker
  • DreamBathrooms
  • thenastyranch
  • ngwrru68w68
  • Durango
  • magazineikmin
  • Youngstown
  • InstantRegret
  • rosin
  • slotface
  • tester
  • kavyap
  • cubers
  • osvaldo12
  • JUstTest
  • khanakhh
  • cisconetworking
  • tacticalgear
  • everett
  • mdbf
  • Leos
  • anitta
  • GTA5RPClips
  • normalnudes
  • modclub
  • provamag3
  • megavids
  • lostlight
  • All magazines