• 5 Posts
  • 1.59K Comments
Joined 3 years ago
cake
Cake day: June 12th, 2023

help-circle

  • I looked at .deb as well and boy are there weird things there.

    There are many similarities between RPM and pkgbuild for Arch, so I could easily copy almost entire pkgbuilds from AUR and merely adapt a few variables but whatever the inventors of .deb concocted is crazy.

    That build method dates back super-far, and probably mirrors unix packaging of the day. This is not a good thing, in that it did miss out on some validation features that RPM and NIX have, and that’s a problem that hasn’t been fixed (in unix or debian) even now (25+ years after we noticed it in the enterprise OS company I worked at, and which invalidated debian even then as a product we wanted to support alongside unix).


  • What I’m trying to say, is that when people said “just use nix”, they probably really mean to use nix as a platform to build other packages withouth doing extra work.

    What you should be saying is something that recognizes that not all systems adhere to FHS. It needs to account for the non-compliant ones, and that includes Lennart’s delightful deviations when he obviously just knew better than the Industry.




  • The user adds the repository to the list of repositories their package manager is using,

    Fun fact: when we were doing devops as config management, we distributed repository configs AS packages … which we updated as required.

    and the packages in that repository appear as normal packages for them to select. When the author publishes a new version of their package it’ll appear as an update in all users package managers.

    So easy.

    These days, with CI, ya berge your patch and the fix is built and sent to testing immediately, ready to be assessed for promotion, which then signs and pushes the artifact into the pipeline for synchronization and application everywhere.

    Aside from the actual smarts to build a good package, the tooling makes every other part of is zero-friction.





  • Just give the source away. Don’t package it at all (or at most, do so for your own distro). If your software is good enough, others will do the packaging for you.

    As someone who’s developed and shipped software you may know, who’s worked in rel/eng, OS security, escalations (we research the fix for the sploit and build the artifact for the update pipeline; everyone calls it something else) before being just an admin to manage hordes of machines; with the knowledge gained in every post I’ve ever held, let me say:

    THIS. ABSOLUTELY THIS.

    If you are a great coder but suck at packaging or hate it, then don’t. You’d produce something sub-par anyway.

    Let the knowledgeable enthusiastic obsessively-detailed people do it for you and you’ll be happier and so will they.


  • So what’s wrong with just releasing a monolithic static binary for each architecture you want to run it on?

    Release engineering works on something that has only recently been codified into a SLSA scale. At the top end is nixos and their very firm validation of code all the way along the supply chain.

    At the bottom of the scale, a SLSA score of 0, is “here’s a monolithic binary I found on the website of someone on the interwebs. Even though we don’t know how it was built, nor can we reproduce it or confirm it’s what he built or look at any of the parts to see whether the statically-linked libraries are now at-risk, let’s just run that.”

    You … do see how irresponsible that is on every level, right?

    Like, 20 years ago I dropped a patch in for Apache, and these days I manage reams of machines using apache, sendmain, winbind, nginx, postfix, etc; to manage those without a proper infrastructure is absolute madness.




  • How it started:

    • “hey portal, call my kids” and it shows up on the fucking TV. That’s the workflow. It lights the TV, switches inputs and starts a call. Boom.
    • microphone array works from everywhere
    • digital-ptz camera was game-changing
    • “hey portal, answer call” when the TV was off would light the TV, select the right HDMI and start the call. The workflow again was a single command.
    • setup: plug in HDMI, plug in power . Use QR to auth the unit to your account.
    • it was loss-leadered at like $100, which is why we outfitted the entire family during covid for the cost of a single tablet.

    How it’s going:

    • the M agent is dead, so its voice control for calling no longer works.
    • the Alexa link is dead, so it no longer works as an Alexa agent for home control
    • the streamer apps are dead, so it can’t do Netflix, britbox, prime, etc
    • zoom is too weird to set up with the remote, so no zoom
    • video works
    • Cam still crushes it
    • sound still rocks
    • poking the remote HDMI-CECs over to the portal still, like what voice commands did

    But it still - and here’s the thing - is a single set-top appliance with an easy UI and controller that puts video chat on the damned TV

    Grandma can no longer use her voice, but she can use the tivo-style remote to start calls. And, again, they’re on this gorgeous big screen so nana can see everyone.

    I simply cannot describe the difference between a phone, even a tablet, and a monster fucking TV image to make you feel really connected with people of normal size. I’d say it again if I thought it’d make a difference.