Live data from Hacker News

Actix project postmortem

github.com

211–220 of 408 posts

Re: Actix project postmortem

#211

For context, this comes after yet another unsoundness bug has been found in Actix-web. Normally people in the Rust community don't get very worked up over these because we know that everyone makes mistakes, but the Actix project has had a consistent history of introducing unsoundness through the use of unsafe for dubious reasons like nebulous performance increases or bypassing Rust's safety guarantees (which is what…

I completely disagree with your last sentence. Think of actix-web as a gift to the world (and judging by its popularity, a very nice gift). Being verbally abused by vocal majority of freeloaders would drive anyone furious.

I think I understand your perspective, though. It would benefit the community to have projects of great importance properly maintained. How to ensure it? Well, by paying people to do it, not necessary developers but active project mantainers. Only then you are entitled to complain about somebody doing a lousy job. To sponsor it, introduce micro-transactions for dependencies.

Re: Actix project postmortem

#212
post #197
post #88

Earlier quoted context omitted.

> If you offer code to the public – and present it as an active, dependable project – professional behavior is exactly what you implicitly promise and signed up for. If you can’t offer that (at any time, and for any reason), then you should immediately make that clear, front-and-center, to any current and future users. As far as I can tell, this project was released under the Apache License 2.0. https://github.com/ac…

> Other popular free software licenses (namely the GLP) have very similar clauses. What the license says and what image the project presents can be very different. Pointing to the license and reasoning that nobody has legally promised anything contractually is not very useful. > Expecting labour from someone without paying them is the very definition of entitlement. That’s a very mercenary view of the world. What abo…

> What the license says and what image the project presents can be very different. Pointing to the license and reasoning that nobody has legally promised anything contractually is not very useful.

It is quite useful, because the license is the legal document that comes included with the software, and that specifies what things you agree to if you use the software. And it explicitly specifies that you cannot assume any contractual obligations from the "image the project presents", or anything of the sort.

> That’s a very mercenary view of the world. What about volunteer charity workers? Is it OK for them to just not show up whenever, just because they aren’t paid?

I would say that if someone promises to do some charity work and doesn't show up without a good reason is breaking a promise, and is thus being a shitty person. People should keep to their word. Open source authors promised us nothing and owe us nothing. More often than not, we owe them.

Re: Actix project postmortem

#213
post #188

Earlier quoted context omitted.

Of course I don't disagree to you, I too think that that reputation is extremely hard to retain. However: 1. It seems that there are/were some language communities noted for their relatively more welcoming atmosphere. If small communities are usually great until it aren't, why don't we see many such communities? There seems to be some truth in this (albeit ultimately fragile) reputation. 2. For this reason, in order…

Re 1, if they're small communities, you don't hear much about them in the first place. And if it's a language community, then the language is probably pitched long before the quality of the community comes into question. That is, I've never heard anything about the communities for zig, D, beef, futhark, pony, Julia, etc. But then, I don't think ever seen any comment on their community... Their supporters are too busy…

Well let me the first to mention Julia’s community. Especially on the julialang slack channel, the community is excellent. It’s incredibly friendly, welcoming and helpful.

Re: Actix project postmortem

#214
post #68
post #23

Earlier quoted context omitted.

> These kind of entitled attitude If you offer code to the public – and present it as an active, dependable project – professional behavior is exactly what you implicitly promise and signed up for . If you can’t offer that (at any time, and for any reason), then you should immediately make that clear, front-and-center, to any current and future users. It isn’t “entitlement” on part of the users – the users are making…

> professional behavior is exactly what you implicitly promise and signed up for. If you can’t offer that (at any time, and for any reason), then you should immediately make that clear, front-and-center, to any current and future users. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AN…

Yeah, that's really the core of the problem, isn't it. People trying to impose an implicit understanding (which is nothing more that 'this is what I want the world to be like') when there's an explicit statement of 'this is how it actually is'.

The attitude baffles me. So many times I've had someone come in all butthurt and say 'I know it was in the contract, but I didn't think they'd actually enforce it'.

Re: Actix project postmortem

#215

For context, this comes after yet another unsoundness bug has been found in Actix-web. Normally people in the Rust community don't get very worked up over these because we know that everyone makes mistakes, but the Actix project has had a consistent history of introducing unsoundness through the use of unsafe for dubious reasons like nebulous performance increases or bypassing Rust's safety guarantees (which is what…

I completely disagree with your last sentence. Think of actix-web as a gift to the world (and judging by its popularity, a very nice gift). Being verbally abused by vocal majority of freeloaders would drive anyone furious. I think I understand your perspective, though. It would benefit the community to have projects of great importance properly maintained. How to ensure it? Well, by paying people to do it, not necess…

Obviously being vocally abused is not OK no matter what the victim has done. This is a big problem and I think Steve's article that is currently on the top page of HN gives a good overview of that part of the situation.

My problem with viewing all open source as a gift to the world, take it or leave it, is that when people create open source packages, market them as being ready for production use and as the best option for said production use, and then act unprofessionally towards security issues and reject patches that fix the security issues for no reason other than being "boring" and "not creative enough" people should be able to call them out on it as unacceptable behavior for an open source maintainer. If actix didn't claim to be production ready and instead stated that it was an experimental code base designed to advance the state of the art in web server performance I wouldn't have a problem with how it was managed. However, once you claim that something is production ready I think you need to be ready to take responsibility for it.

Re: Actix project postmortem

#216
post #46

I'll save this link for the next time someone tries to argue that the Rust community is somehow "more welcoming" than some other X community. All internet-based communities contain some assholes. All of them. Sadly some maintainers don't seem to have the werewithal to tell them to go away. I mean, when you get "asked to change coding style", it's the time to put the banhammer down, because there is no way to please t…

I’d argue any community that crosses Reddit and Open Source would cross this issue eventually - it’s not necessarily a Rust issue.

Re: Actix project postmortem

#217
post #112

Earlier quoted context omitted.

The easy way to tell is to remember if you're paying them or not.

Absolutely not. You can get professional (but not necessarily timely) support from me for multiple projects I maintain on GitHub, for free. For many people, their personal interest in open source is writing code for fun and showing it off. For others, it's making a product that people can rely on. The second one is my motivation; don't take that away from me.

That’s fine. It’s even admirable if you to do that. But it isn’t and shouldn’t be mandatory.

Re: Actix project postmortem

#218
post #141

Earlier quoted context omitted.

Making a profit != profiting. I profit from Clojure, Python and the linux kernel. Doesn't mean I habe an income from their existence. Nobody is arguing about professional support, but advertising a project and then deleting the entire thing to spite people is a jerk move. Ready up!

> Making a profit != profiting. Thats exactly what it means. https://dictionary.cambridge.org/dictionary/english/profit I use linux to write python that I sell for a profit, I profit from these things, and I am happy to support these projects with my profits in return for professionalism I need to make a profit. If I use them in a personal project I benefit from them not profit, and I certainly don't expect anything…

From your source:

>> the good result or advantage that can be achieved by a particular action or activity

Re: Actix project postmortem

#219
post #189
post #179

Earlier quoted context omitted.

Yes and pushing the archive button is saying "I won't produce any more packages sorry." What they did was climb through everyones window to get the cardboard box back, just as with the npm leftpad incident. Stop painting the narative like people demand some volunteer to do more free work, when all they do is ask to not be actively sabotaged.

No, he didn't break into people's house, started their computers and started deleting stuff. It's all the same as the day before yesterday.

Except for they didn't simply push a commit which replaces the code with a readme that tells people to go maintain it themselves or fuck off, they emptied it, rewrote their history and did a git push --force.

And frankly I don't buy the story that they wanted to put the code on their own repository anyways, seems more like a concession because the other contributors also hold some copyright.

Re: Actix project postmortem

#220
post #190
post #179

Earlier quoted context omitted.

Yes and pushing the archive button is saying "I won't produce any more packages sorry." What they did was climb through everyones window to get the cardboard box back, just as with the npm leftpad incident. Stop painting the narative like people demand some volunteer to do more free work, when all they do is ask to not be actively sabotaged.

No, he just stopped dropping the package on the street every Monday at 7am. Whoever picked up the package in the past, still has it - or had the option to preserve it. If your workflow relied on a package being delivered every morning, even unchanged, it's your own fault. He never made that guarantee. Stop painting the narrative like people owe you anything, when you're just failing to correctly evaluate the actual r…

Yeah there's this common concept in society called trust, aka a social contract, that people don't advertise their stuff first only to deliberately screw you over.

And yes shockingly people are entitled to be treated fairly and not to be sabotaged. And no, providing them with a library for a limited period of time and then being fed up with it's maintenance doesn't somehow earn you that right. It gives you the right to walk away, but clearly thats wasn't enough for the author.

But hey if you want that to live and bathe in that kind of toxicity, enjoy!

Post reply on HN