This significantly increases my respect for Zed Shaw.
Yes, he wrote an offensive post crying for blood, but after he had a chance to cool down, he used his own fame and audience to exhibit a well-reasoned response from someone who disagreed. That's a very adult thing to do. In some ways, it's actually better than an apology.
He reacted in the right way, but on the whole my impression is negative. I'm a bit disappointed, because most of Zed's previous rants were humorous, amusing and well researched. But in this case he didn't put any effort neither in research nor writing. He'd stumbled upon a dependency bug and, instead of reporting it, he for some reason concluded that it means that Debian is evil and everybody should boycott it. Weird.
PS. Excuse me, there was one amusing paragraph in the rant. The one in which he equaled Debian, the most independent and free software obsessed distribution out there, to Microsoft.
He didn't just stumble upon an overlooked dependency bug — the Debian maintainers intentionally broke their Ruby package years ago because of the legal problems they imagine to exist with using OpenSSL.
I don't think it's so out of bounds to compare Debian, the most copyright-license-obsessed distribution out there, to Microsoft.
Maybe it's a name problem. It was said ruby-full provides the full Ruby language, while ruby provides the export-restricted version Debian has to distribute in order not to have police officers knocking down doors. In Python's case (sorry, I am more familiar with Python) there are python and python-minimal packages. They may or may not mean the same as ruby and ruby-full, but their names communicate a similar intention.
While "police officers knocking down doors" over crypto export restrictions do not exist, that's not what Debian's wankfest over OpenSSL is about.
They think that the advertising clause in the OpenSSL license makes it impossible to use with any GPL programs — despite the fact that the OpenSSL developers think it's fine as a platform library and tons of upstream developers of GPL software choose to link against it. In Debian's world, they'll only allow you to use it if you get every contributor to agree to a special exemption clause appended to the GPL.
Through their absolute fealty to the most draconian interpretation of the letter of the law, Debian does more to further the cause of software patents and non-free licensing than any other organization. They choose to demonstrate how idiotic such ideas about IP are by implementing them to their fullest — by being idiots.
> Debian does more to further the cause of software patents and non-free licensing than any other organization.
Wow. Really?
> They choose to demonstrate how idiotic such ideas about IP are by implementing them to their fullest — by being idiots.
From the guidelines:
> Be civil. Don't say things you wouldn't say in a face to face conversation.
> When disagreeing, please reply to the argument instead of calling names. E.g. "That is an idiotic thing to say; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
I for one do not care at all for your rude name calling.
For what it's worth, I'm not particularly fond of debian-legal either, but it's entirely possible to express that disagreement without calling everyone who does not see the world as you do "idiots".
So who else is out there doing the work of enforcing American software patents on the users of the world? Even the BSA doesn't do that! Apple isn't out there enforcing their patent on the truetype hinting bytecode interpreter, but Debian refuses to ship a full version of freetype. The DVD-CCA gave up years ago, but Debian still won't ship a DeCSS implementation. Fraunhofer/Thomson/MPEG-LA only really care about companies shipping hardware, but Debian cares more about FUD and promoting OGG than actual use.
None of this shit matters at all when shipping source code, and binaries only matter if both parties are in the US. But the Debian project is out there with jackboots on, doing what they can to take useful freely-licensed software out of distribution. What other organization is doing anything like that?
I'm sorry that you find yourself so wrapped up in such an organization, I did not mean to insult you directly, but rather the ideology y'all are applying to make my world a worse place to live. And I would be far more acerbic in a face-to-face conversation.
You didn't understand my line of argument centering around idiocy (should have used fewer anaphora) — my point was that the Debian people know that they're being idiots, and that it's the purpose of their actions in this squabble. We all know that software patents are stupid, but Debian's approach is to show the world just how stupid software patents are by fully respecting them, implementing the letter of the law until it is repealed. I think that's a useless and infuriating course of action.
With regards to the legal stuff, I simply don't know. One of the things that bugged me about debian-legal were all the people convinced that they did know it all. I'm not a lawyer and neither are most people there. Neither are you or the OpenSSL guys either, though, as far as I know. My firm conviction is that most "open source legal debates" are essentially the blind arguing with the blind about various painters. Although, of course, many real lawyers are also so vague and non-commital in what they say that they're not much use either, so I tend to just want to stay as far away as possible from that kind of discussion.
That said, one thing I don't agree with you on is that "well, they probably won't notice / bother us, so it's ok to skirt the letter of the law". I think that's not really the right attitude either. Debian makes some strong commitments to shipping free software that people can use and redistribute as they see fit, so I think they have to be cautious at times.
I am not a part of Debian any more. I moved on to being simply a user (and bug reporter) of Ubuntu, which I think gets some things right that Debian didn't. I just don't like the "you fucking idiots" style of debate.
"ruby-full" did not exist for a long time, nor does it still provide everything in the normal distro. So far as I know, that is, I may be wrong since I stopped paying any attention to what Debian does a few years ago.
Only Debian considers it to be a problem for GPL software to dynamically link with system versions of OpenSSL. They be loud and obnoxious about it, but they really are the only ones who are stirring up shit. It's only possible to be incompatible if the GPL software ships with a bundled version of OpenSSL and doesn't append an exception to the GPL.
The OpenSSL project does not consider it to be a problem at all.
The upstream authors that simultaneously link with OpenSSL and use a GPL license obviously don't think it's a problem.
I did read it and I see that they are aware that their advertising clause causes problems for distribution and I see them recommending against making GPL software that links to OpenSSL. gem is GPL and links to OpenSSL.
I researched it plenty, and since your comment can't point out factual errors in my post, I'll just assume you're a hypocrite.
And yes, they embrace and extend. Embrace is taking the package in the first place. Extend is carving it up and patching it so that other companies that choose Debian are forced to either work around their quirks or accept them. That's the exact classic definition.
Unfortunately this research isn't visible in your rant, and it's not about factual errors. I didn't notice any effort to understand the situation better, for example by speaking with people involved (like the developer in question). But even if you did that, it looks like you intentionally avoided presenting the other point of view, instead of that you assumed upfront that the only reason is pure evilness. This is simply not a very convincing argument.
If you posted this at oppugn.us I wouldn't say a word, but I assumed that sheddingbikes.com is a place for more polished stuff.
PS. Debian is a loosely coupled group of more or less skilled volunteers with very little oversight and no business motivation. Debian has its flaws, but I see nothing in common with Microsoft.
But seriously, all distros patch things, they have to to make them work well together on the platform in question or to get the features/fixes they need. Look at how much RHEL patches the kernel, or Ubuntu patches GNOME.
Red Hat backports new drivers and features to ancient kernels because their customers use binary drivers, and Linux does not maintain a stable ABI. It's a shitty but completely respectable position to be in.
Canonical forks Gnome because Novell and a cadre of adolescents in western europe still technically control the project. Ubuntu will win eventually and this will stop being an issue.
Sane distros patch upstream just enough to make the software build and work. Debian does it to fulfill their ideological goals.
RH ships older kernels because they release relatively infrequently, and they've had time to QA them (the RH kernel test suite is huge and they run considerable stress tests). They backport features and drivers and fixes because their customers want the stability of well QA'd kernels and the support of newer server hardware and the benefits of fixes made later. One of the older RHELs even went so far as to backport entire subsystems from 2.6 into a 2.4 kernel because they felt overall 2.6 stability was insufficient for their needs.
Specific grips with your assertions aside, I think you are too quick to dismiss the ideological goals of FOSS projects - the entire FOSS ecosystem is afterall founded on some pretty seriously ideological goals, particularly Free Software. Open Source exists to dampen these goals and I suspect that a lot of folks now involved in this world are just interested in forking ruby software from github to run on their Mac ;)
Disclaimers: I own a Mac, but Linux has been my desktop/server OS of choice for the last decade, and I work as a sysadmin for a Linux distro company. I also write some software that's packaged in most of the distros now, so I feel self-entitled to see this from several very relevant perspectives ;)
> The one in which he equaled Debian, the most independent and free software obsessed distribution out there, to Microsoft.
Debian fails to do step 3. Microsoft's routine is "embrace, extend and suffocate" while Debian will never go beyond step 2. And they have the license to keep them honest.
An apology to who? I spoke my mind and made what I thought were valid points and I still stand by them. Debian is abusive to developers who create the software they need. It's only a matter of time before the programmers making their supply chain of projects declare enough.
As a good reference for the exact type of behavior I'm talking about, see this:
You spread mistruths about Debian with your various "business" comments. That in and of itself merits an apology. You can't just go making stuff up about people because they irritate you.
Also, from everything I can tell about your original post, you had a (well known) problem with Ruby gems on Debian, not with something you wrote. I can understand being irritated about that (Debian is not blameless, obviously), but there are jerks everywhere, and also an awfully lot of nice people in Debian too. Your lynch-mob mentality (seo tricks, in-person confrontations, etc...) reflects very poorly on you and is extremely unlikely to produce anything approaching positive changes.
If you don't like the freedom others have with open source licenses, why not just go back to making proprietary software where you won't have the problem. Freedom means that people sometimes do things you disagree with (even vehemently so), and if you can't handle it, then perhaps it is simply not worth it.
Debian is not abusive, some DDs are unfriendly some of the time. Some mistakes have been made. This isn't some conspiracy to ruin your rep.
How about users/sysadmins "rise up" against ruby/python/php for having module distribution/loading systems which in no way try actively to be easy to package well?
Tell us about the changes you are going to make such that all gems/eggs are automatically packaged for RHEL/Debian/etc so the overhead for DDs, and consequently their opportunity to confuse things, is near zero. That's the outcome we need. Are the languages prepared to make the changes necessary?
We're not going to cripple our modern programming language environments to suit an outdated system designed around mutually-exclusive soname dependencies, and we sure as hell aren't going to prostrate ourselves as a community before your baroque unnecessary social process.
It's not just us affected whippersnappers causing problems — even the enterprisiest Java communities have given up on your packaging model.
IMHO it's difficult to say "better technically" - for one thing portage is much looser than dpkg. Depending on your goals that may be better or scarier! ;)
So you're not prepared to change anything? Even if distros make changes as well? Why are these two groups not working together to enable magic for their users?
Why would it be so bad, for example, to have something like this in a python script:
Of course this immediately opens up a veritable hydra of questions and corner cases and other considerations that need to be made in designing such a facility, but that's why there are smart programmers and smart distro makers out there :)
I think it's fairly clear that there are grumpy, recalcitrant, belligerent people on all sides of this argument, and the people who lose most are the users that everyone claims to care about. As a user I feel that is deeply tragic and I feel like we have all failed.
Is precisely the feature I love most about rubygems, and would love to have in Python. It's also a feature that Debian goes out of their way to eliminate because it violates their precious FHS, apt can't handle it at all (they get around that for important packages by mangling the names), and superficially overlaps with their 'alternatives' system.
Where did you get the idea that I didn't want it?
Unfortunately there's no implementation path to make it possible on Debian's side, no matter what the language communities do to compromise. apt can't handle it technically, and their release cycle process can't handle it socially.
I got the idea because you seemed to react in a way that suggested you thought any language changes to support better/easier packaging was "crippling".
I'm not a skilled packager, so I can't get into a deep discussion of the parts that are missing on both sides, but it seems fairly clear that parts are missing on both sides. Perhaps it will take the work of, say, the ruby and ubuntu communities to demonstrate the change is possible and hugely beneficial for users, and encourage its adoption in Debian?
Personally, I don't have a fundamental problem with a distribution (even a popular one) refusing to package something for their systems that they think is awful.
Sometimes the easy choice is the wrong choice. If you just step back and say "well, they want to eat every meal at a fast food restaurant I guess I better make it easy for them to do that" then you are an enabler.
All that said, they should get off the fence about it. If they don't want PHP development beyond the web on Debian they should put that in a policy somewhere and direct people to it.
I didn't write it, Ersek, Laszlo did. That's how sheddingbikes works. Rather than comments, people can send responses as a post and if it's good I post it.
Sadly, it's not frequently that people send in a good response.
Yes, he wrote an offensive post crying for blood, but after he had a chance to cool down, he used his own fame and audience to exhibit a well-reasoned response from someone who disagreed. That's a very adult thing to do. In some ways, it's actually better than an apology.