Conill: The long-term consequences of maintainers’ actions
Conill: The long-term consequences of maintainers’ actions
Posted Sep 19, 2021 3:39 UTC (Sun) by ilammy (subscriber, #145312)In reply to: Conill: The long-term consequences of maintainers’ actions by robert_s
Parent article: Conill: The long-term consequences of maintainers’ actions
Is being unwilling to support hostile? It's understandable that upstream does not really want to support the entire combinatorial explosion of their package and all possible dependency versions, focusing on the latest ones where possible. Resources are scarce, their time is better spent elsewhere. From upstream viewpoint, if distro packagers need to support older versions of dependencies for whatever reasons they have, that’s their burden, not a responsibility of upstream.
It’s just that with modern languages it’s not unrealistic to have hundreds of transitive dependencies. In ye olden C dayes, you’d have just a handful of direct dependencies and an occasional transitive one here or there, with exceptions being rare. Now popping libraries like candies is easy, so that’s what everyone’s doing, without much regard over the stable maintenance burden they impose onto packagers by doing this. Developers use the latest version, it’s natural for them. Not so much for consumer users.
The question here is whether the distro packaging process is scalable enough. Arguably it isn’t. You can’t just take existing maintainer and say, “Look, you took care of ${software-package} and its dependencies. Now there are x10 more dependencies, you take care of them too, will ya?” So with the advent of software using more dependencies, you need to increase the maintenance team size too, so that each of those new mini-dependencies gets as much attention as a library got before, for the quality and speed of delivery to remain the same.
