Live data from Hacker News

The OBS Project is threatening Fedora Linux with legal action

gitlab.com

201–210 of 229 posts

Re: The OBS Project is threatening Fedora Linux with legal action

#201
post #196
post #164

Earlier quoted context omitted.

I love Debian but the version of xscreensaver was old and if there were security issues unpatched and getting the blame sent to jwz, that’s not right.

This wasn’t about security issues. Security fixes are regularly applied to Debian stable releases, and have been in the case of xscreensaver.

https://news.ycombinator.com/item?id=43046053 seems to suggest otherwise.

I vaguely remember this happening but I’d need to check.

Re: The OBS Project is threatening Fedora Linux with legal action

#202

Earlier quoted context omitted.

One of the comments in the main thread says that the original vision for the fedora flatpaks was to be mainly for things that fedora wanted to have tight control and be preinstalled in their distros (Firefox, LibreOffice, GNOME and apps, etc...), which makes a lot of sense, but at some point it lost their original vision and started packaging everything under the sun. In another comment someone says that most of the…

it's not exactly a case of 'lost their original vision'. Fedora is generally a fairly permissive project; we let maintainers do stuff. Since the mechanism to build Fedora flatpaks was needed (for the bundled flatpaks for Silverblue), it was normal - in Fedora terms - to say hey, let's just let maintainers use to it build flatpaks of any Fedora package, if they want to. The obs-studio Fedora flatpak exists because the…

> it's not exactly a case of 'lost their original vision'.

Considering that one person that says that he worked at the beginning of the project writes that the original idea wasn't to compete with flathub and given the current state of affairs I would argue that the project today doesn't have the original vision anymore.

As for creating a ton of projects, today with LLMs I'm pretty sure that I can write code that scrapes github repos for installation instructions and use it to create thousands of packages for everything that can run in Linux, doesn't mean that I should because there would be no quality control at all.

It is a noble idea to create packages to help create critical mass, but even with simple packages, seven hundred are more than anyone can use specially when we're talking about software that most likely have a GUI, and if you never really use most of the packages that you create you are bound to create these issues with QA.

All of that could be avoided (or minimized) if the fedora project created two flatpak repos, one for core software and one for contrib software, but that probably would be clear competition to flathub and probably be mostly ignored.

Re: The OBS Project is threatening Fedora Linux with legal action

#203
post #115

Earlier quoted context omitted.

I would differentiate your scenario in five ways. First, the risk is higher. When a vulnerability has a public patch, it means the nature of the vulnerability is also public. Sometimes there is even public exploit code. While attackers sometimes find their own vulnerabilities (zero-days), it makes their job a lot easier if they can just use an already-known vulnerability. Second, if the code was part of the OBS proje…

> First, the risk is higher. When a vulnerability has a public patch, it means the nature of the vulnerability is also public. Sometimes there is even public exploit code. While attackers sometimes find their own vulnerabilities (zero-days), it makes their job a lot easier if they can just use an already-known vulnerability. but.. Qt is only used for the GUI in OBS. It's not doing anything network-related or processi…

"Qt is only used for the GUI in OBS." - I don't think that QObjects : OAuth, TwitchAuth and YoutubeAuth are gui related.

Re: The OBS Project is threatening Fedora Linux with legal action

#205
post #34

Earlier quoted context omitted.

I mean, I think the right fix is just for Fedora to stop packaging their own version. But I think that's about being good people; I don't think there's a strong legal argument here for forcing Fedora to do that.

> I don't think there's a strong legal argument here for forcing Fedora to do that Isn't the argument that by mangling the software, they've created a version that is no longer the original software, and the the trademark owner want them to stop using the trademark to describe this new version? I think OBS would be happy enough if Fedora simply decided to release their own "FBS" package instead that was the same, oth…

I can see court siding with "IT broke because we applied security fix" much more than "it was using insecure library but was working".

Governments dislike insecure.

Re: The OBS Project is threatening Fedora Linux with legal action

#207

Earlier quoted context omitted.

I disagree very hard on this. We mostly talk about the problematic cases, but most of the time when I need some software, I just install it through the package manager and it just works. Compare this to Windows, where you often have to search the Internet, download some sketchy .exe or .msi and don't know if you'll get the software, a virus, or both. It got so bad that it was common to have "cleaners", extra tools th…

> I just install it through the package manager and it just works. It just works if the software you require is not only provided by your speciic distribution but also you require the specific version of the software that is provided by your specific distribution. Good luck if it not the case. For windows or mac, 1 or 2 files each cover all systems from the last 10 years or more. It's not by masochism that people reg…

> It just works if the software you require is not only provided by your speciic distribution but also you require the specific version of the software that is provided by your specific distribution. Good luck if it not the case.

It also just works if you install a Flatpak, which on distros like Fedora, you will be able to do by default through the software store app.

Re: The OBS Project is threatening Fedora Linux with legal action

#208

This seems like a flashback to the xscreensaver fights with Debian of yore, given that the entire fight seems to distill to "OBS is shipping EOL Qt because of unfixed regressions in newer Qt, Fedora views shipping EOL Qt as unjustifiable neglect and repackaged it with newer Qt, which, as described, breaks things." [1] For those who don't have that in their context - jwz got very upset at people reporting bugs against…

Don't link to this guy's site. He has a serious personal problem with every reader of HN (including the vast majority he's never met and knows nothing about) and serves an NSFW image to anybody that has this site in the referrer request header.

Get a better browser that doesn't leak the site you came from all over the place.

Re: The OBS Project is threatening Fedora Linux with legal action

#209

Earlier quoted context omitted.

From what I've read the Fedora project has an interest in providing solely open source and non patent encumbered software like codecs. Which sounds like something OBS may infringe on

I heard it was a Fedora-wide effort to make its own flatpaks, but I don't really know why.

Well, for one, Flatpak is a stupid design where the downloaded software gets to tell the system what if any sandboxing is applied. The way to have it be a security boundary is by enforcing the packaging :-(

Re: The OBS Project is threatening Fedora Linux with legal action

#210

Earlier quoted context omitted.

This thread is giant, but I feel like it could come from here (and further responses): https://pagure.io/fedora-workstation/issue/463#comment-95541...

These two comments stand out to me as inappropriate (directed at OBS). > keeping up with runtime updates is one of the most basic expectations of a maintainer, and I suspect it's a sign there may be other problems as well. > I won't mince words: allowing the runtime to go EOL is unacceptable and indicates terrible maintainership. I don't use Fedora but I do use OBS… on Mac, because OBS is hands-down the most popular…

As person who does not use OBS.

"If OBS isn't good enough for Fedora" - fanboyism is never good. If OBS has issues in development then what? What would you do if it stops updating Qt permanently? Think not let emotions act.

"works great" - doesn't mean it is secure.

You can write application that works great and is swiss cheese from security standpoint. You can write secure application that works like nightmare.

"inappropriate" - why? If it is statement of fact then it can not be inappropriate.

Also mind you OBS blocked the issue about fact that they use EOL qt on github - this does not look to me as good project.

"the Fedora-packaged-flatpak breaks" - is it broken? Because no one even speaks about real state of package! Or by "broken" you mean - does not have functionality I want! Or it uses Qt version which breaks the application!

Because In first case that not breakage - that's loss of functionality and if motivated by legal reasons - I can understand (not approve since US software patents are from my perspective idiocy), if motivated by security I wholeheartedly approve - because you are shooting messenger(fedora) of bad news(OBS bad practices) here.

In second - Qt is broken so send regards to them and their policy: Update it so often to make GPL/LGPL version as miserable as possible. Which they then use to sell companies the LTS versions under proprietary license.

I agree with breaking (it is good feedback about software state) to modernize dependencies - but then again I'm using Arch so…

Post reply on HN