Live data from Hacker News

The OBS Project is threatening Fedora Linux with legal action

gitlab.com

121–130 of 229 posts

Re: The OBS Project is threatening Fedora Linux with legal action

#121
post #96
post #3

who should do packaging for each distro? - upstream maintainer: too much work. each distro requires certain best practices/convention. - distro: may not meet certain standard set by upstream maintainer.

If distro maintainers are going to futz with packages, for good reasons or bad, then they need to bear the corresponding support burden themselves and ensure it does not fall on the upstream maintainers. This is not really any different from the Debian OpenSSL fiasco, or the Debian cdrecord fiasco, or the Debian xscreensaver fiasco, or...

in this specific case, yes they are responsible for flathub. but Fedora is pushing Fedora Flatpak down to user's throat without user's awareness.

Re: The OBS Project is threatening Fedora Linux with legal action

#122

Earlier quoted context omitted.

Don't link to this guy's site. He has a serious personal problem with every reader of HN (including the vast majority he's never met and knows nothing about) and serves an NSFW image to anybody that has this site in the referrer request header.

You can hate jwz as much as you want but the fact remains that probably 95% of ycombinator funded startups couldn't exist without making extensive use of the gpl, bsd, Apache and similar licensed software produced by a lot of open source curmudgeons and greybeards. Many of whom share his same opinion on VCs and late stage capitalism.

> You can hate jwz as much as you want but the fact remains that probably 95% of ycombinator funded startups couldn't exist

wait, this would be a bad thing?

Re: The OBS Project is threatening Fedora Linux with legal action

#123
post #100

Earlier quoted context omitted.

I don't understand what the big deal was there. Debian has its own bug tracker for all of its packages so the distro maintainers get bothered about bugs in old packages shipped by the stable version of Debian rather than upstream developers. JWZ decided to voluntarily subscribe to the Debian bug tracker for his package and then add a nag screen and start a flame war over them shipping an old version.

Debian users frequently report bugs to upstream and not Debian.

An unfortunate side effect of github being extremely user-friendly, while debian's reportbug tool still greets "novice" users with "please enter your SMTP host" (I dread to think what questions it would have asked me if I'd selected the "expert" mode)

Re: The OBS Project is threatening Fedora Linux with legal action

#124
post #58

Earlier quoted context omitted.

Don't link to this guy's site. He has a serious personal problem with every reader of HN (including the vast majority he's never met and knows nothing about) and serves an NSFW image to anybody that has this site in the referrer request header.

[flagged]

He's not wrong per se, just really hostile to the idea.

Re: The OBS Project is threatening Fedora Linux with legal action

#125
post #115

Earlier quoted context omitted.

> the claim from Fedora is that is that OBS is using an EOL qt. what's amazing with this is that if for instance OBS had written their own toolkit from scratch just for the app, which by a stroke of luck ended up being exactly the same code than the Qt version they're using and which solves the use case they have - maybe it would be OBSObject or OBSString instead of QObject / QString, then this entire issue would not…

I would differentiate your scenario in five ways. First, the risk is higher. When a vulnerability has a public patch, it means the nature of the vulnerability is also public. Sometimes there is even public exploit code. While attackers sometimes find their own vulnerabilities (zero-days), it makes their job a lot easier if they can just use an already-known vulnerability. Second, if the code was part of the OBS proje…

> First, the risk is higher. When a vulnerability has a public patch, it means the nature of the vulnerability is also public. Sometimes there is even public exploit code. While attackers sometimes find their own vulnerabilities (zero-days), it makes their job a lot easier if they can just use an already-known vulnerability.

but.. Qt is only used for the GUI in OBS. It's not doing anything network-related or processing any data stream coming from there, why would any security issue in Qt matter ? Only thing I can think of is a crafted system font causing an issue but if you have a crafted font running on your linux system you are already compromised way beyond repair

Re: The OBS Project is threatening Fedora Linux with legal action

#126

Earlier quoted context omitted.

Don't link to this guy's site. He has a serious personal problem with every reader of HN (including the vast majority he's never met and knows nothing about) and serves an NSFW image to anybody that has this site in the referrer request header.

This is a piece of Internet lore I'm not familiar with! Any good summary or article or anything you'd recommend?

Coders at Work has an interview with a pretty comprehensive backstory of his time in the tech industry. If you want to get more of his vibe, he's also in the documentary Code Rush.

Re: The OBS Project is threatening Fedora Linux with legal action

#127
post #34
post #30

Earlier quoted context omitted.

From the linked comment: > This is a formal request to remove all of our branding, including but not limited to, our name, our logo, any additional IP belonging to the OBS Project Honestly it sounds very reasonable, if you want to fork it's fine, but don't have people report bugs upstream if you're introducing them.

I mean, I think the right fix is just for Fedora to stop packaging their own version. But I think that's about being good people; I don't think there's a strong legal argument here for forcing Fedora to do that.

That's what they were originally asking for three weeks ago. Or that they would at least make it clear to users that their version isn't official. Both options have been going nowhere until the legal threat was made. Now suddenly both are happening

Re: The OBS Project is threatening Fedora Linux with legal action

#128

This seems like a flashback to the xscreensaver fights with Debian of yore, given that the entire fight seems to distill to "OBS is shipping EOL Qt because of unfixed regressions in newer Qt, Fedora views shipping EOL Qt as unjustifiable neglect and repackaged it with newer Qt, which, as described, breaks things." [1] For those who don't have that in their context - jwz got very upset at people reporting bugs against…

> Fedora views shipping EOL Qt as unjustifiable neglect

That's rich, coming from a project very closely tied to Gtk, which has a history of massive breaking changes, and outright removing functionality, leading to many projects continuing to use older versions of gtk for a very long time.

Re: The OBS Project is threatening Fedora Linux with legal action

#129
post #100

This seems like a flashback to the xscreensaver fights with Debian of yore, given that the entire fight seems to distill to "OBS is shipping EOL Qt because of unfixed regressions in newer Qt, Fedora views shipping EOL Qt as unjustifiable neglect and repackaged it with newer Qt, which, as described, breaks things." [1] For those who don't have that in their context - jwz got very upset at people reporting bugs against…

I don't understand what the big deal was there. Debian has its own bug tracker for all of its packages so the distro maintainers get bothered about bugs in old packages shipped by the stable version of Debian rather than upstream developers. JWZ decided to voluntarily subscribe to the Debian bug tracker for his package and then add a nag screen and start a flame war over them shipping an old version.

Distros have neither the knowledge nor the bandwidth to analyze bug reports for upstream projects.

Re: The OBS Project is threatening Fedora Linux with legal action

#130

Earlier quoted context omitted.

Sounds like a sensible and principled fellow.

Considering that Netscape used to have “about:jwz” as an Easter egg URL and he was influential in open sourcing Netscape…

Didn't any unknown about: string just lead to somebody's wwwhome with simple URL rewriting? At least, with some versions?
Post reply on HN