Re: Building Hell

Alex Butcher <[email protected]> Fri, 11 Mar 2005 14:02:29 +0000 (GMT)
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
On Thu, 10 Mar 2005, Brandon Warhurst wrote:

> Finally, before someone flames me for picking on BitPim (I'm not trying
> to target any particular software, and I don't even dislike BitPim, but
> this one is a great example of everything I've said), try taking a fresh
> install of Fedora Core 3 (or any other fresh install for that matter)
> and after the installation, download the BitPim source and see if it
> runs.

This is a common problem that people cite with FOSS, but this is only
because people are having to deal with the positives AND negatives of having
a level of freedom they've never had before.

I tell people to consider having access to FOSS upstream packages as like
being a member of Microsoft (or Sun, or IBM) staff and having access to all
the goodies that are doubtless being developed behind doors that are closed
to the general user population. If you consider yourself a general user,
then the way you obtain software - FOSS or otherwise - probably shouldn't be
to grab a compiler and start building it yourself; you should probably be
either picking a product/distribution that includes the features you need,
or petitioning the vendor of the product that's closest to your requirements
to include the functionality.

The power of FOSS is that it allows you the opportunity to grab the source
and a compiler and have access to extra functionality if you /choose/ to do
so, and /before/ it might otherwise be available in a boxed product. Just
because you have that freedom doesn't mean to say you /have/ to use it.

> Regardless of whether FC3 is a broken installation (I know some
> will feel it is and they'll want me to switch to Gentoo, or GNU/Linux or
> something else), this "extensionitis"/"build hell"/"extreme dependency
> hell" really needs to end.  It just gets worse with so many supported
> languages and new extensions being added to each.  Its almost another
> Tower of Babel out there.  All the freedom is great, but no one seems to
> want to clean up the mess that's left over in the aftermath of all the
> unconstrained freedom.

The alternatives are far, /far/ worse:

a) application developers start re-inventing wheels in their own (probably
broken and/or incomplete) ways, each mutually incompatible with other
implementations. Application development is slowed as the level of
re-invention rises.

or

b) application start bundling all their pre-requisites a la Windows
applications. This gives rise to horrid auditing and installation problems
when you're trying to find out exactly what is being used on a given system.
This is particularly appropriate when you're trying to patch *all* the
applications that make use of a particular dependency which is discovered to
have a security flaw (cf.
<http://lists.seifried.org/pipermail/security/2004-September/004765.html>
and
<http://www.gzip.org/zlib/advisory-2002-03-11.txt>/
<http://www.gzip.org/zlib/apps.gz.html>.

Best Regards,
Alex.
-- 
Alex Butcher      Brainbench MVP for Internet Security: www.brainbench.com
Bristol, UK                      Need reliable and secure network systems?
PGP/GnuPG ID:0x271fd950                         <http://www.assursys.com/>