Debian has a specific documented process of how their stable releases are produced, and though that can cause problems for some developers because they get bug reports for old versions, that specific documented process is part of what makes Debian special to me.
I sympathize with devs for having to put up with those bug reports, but putting messages into the software to specifically goad the OS package maintainers is just poor form. Surely there's a better way to have handled that.
xscreensaver (5.30-1+deb8u1) jessie-security; urgency=medium
* Add upstream patch for "xscreensaver aborts when unplugging second
monitor" security issue (closes: #802914)
http://www.openwall.com/lists/oss-security/2015/10/24/2
-- Tormod Volden <debian.tormod@gmail.com> Sun, 25 Oct 2015 11:35:52 +0100
Keeping the old version isn't supposed to imply "it has no bugs" - instead, it's based on the idea that "if if works for you now, it will continue to work for you". In other words, you can be reasonably sure distribution point updates won't break anything that you're relying on.What we have in this situation is an engineer–as far as I can tell, an engineer on the short list of "world experts in lockscreen security"–who earnestly believes that our universe operates in exactly this way.
What is a reasonable thing to do–short of warning end users, which apparently is immature in your mind–to prevent what he believes, as a subject matter expert, to be a major and ongoing security vulnerability waiting to happen?
Should he have released under a non-DFSG license so as to prevent Debian from packaging the software at all? Or should he have politely written to the Debian maintainer asking for its removal from Debian? Should he have gotten into the Debian politics and lobbied for the "special exceptions" that iceweasel etc. enjoy to get frequent updates? Should he have taken it upon himself to backport security fixes to Debian, RHEL, etc?
I sympathize with the OS package maintainers, but I sympathize more with someone who found himself trapped between his commitment to software freedom and his commitment to keeping his users secure.
It's more about the spam for already-fixed features than the love of keeping users secure.
jwz also isn't exactly fair in his characterisations in the article. Things like "taking advantage of a creator's work, ignoring their wishes, and giving nothing back in return." when the explicit problem is that they're giving back, just not in the right manner. That's just the way jwz rolls, though...
It would be wrong for debian to remove the warning, though, since it's there specifically for debian users; they're not 'collateral damage' from an unrelated change or similar.
I realize this is the reason presented in the comment, but after I dug into his statements elsewhere, I developed a different picture. Anyway, there's no law that says a comment must present every argument why the code exists.
To step back a minute, I seem to be seeing the same facts very differently. Where some see an immature attempt to annoy users, I see a demonstration that Debian is unable to spot a bug when it has a 50-line comment above it complaining that Debian doesn't fix bugs.
To me, the very existence of this situation itself is a powerful argument against Debian stable as a working concept. Most of the time a bug is introduced it does not announce itself with a preamble. How the hell did this make it all the way to stable?
That's also an unfair characterisation, especially since the original report starts out recognising that exact comment.
Debian stable is there for a reason - not everyone is in a position where they can have the latest'n'greatest rolling distro. Security is not the only thing that's of interest to users; stability is of interest as well. I see people using rolling distros that get caught up by this bug or that bug, and they can fix it because they're technically-minded, but not everyone can do that.
This xscreensaver issue is an edge case that gets caught in the cracks. I'm sure jwz is also well aware of why debian stable does what it does, but as the recipient of the bugspam, he can probably be forgiven for being less than charitable about deb-stable.
What specifically is unfair about it? Is it false?
> especially since the original report starts out recognising that exact comment.
I must be missing the part where a postmortem of this feature getting into stable was conducted and lessons were learned. Can you link me?
> Debian stable is there for a reason - not everyone is in a position where they can have the latest'n'greatest rolling distro.
Yeah, and that's why I run Debian stable. But in light of a visible lapse I'm concerned about invisible ones lurking on my systems.
Are there many software projects that have full peer review of every single commit?
Are there many software projects that have more than one developer?
How is that relevant to anything? Something can be bad without attacking minorities, genders, sexual preferences, Packer fans or Packard drivers.
People who see an annoying xScreensaver popup each time they boot their machine or when their machine wakes up from screensaver...
Worth noticing that the popup mentions xScreensaver's author's email address, which probably doesn't help him getting less bug reports....
[0] https://www.jwz.org/blog/2016/04/i-would-like-debian-to-stop...
http://nullrefer.com/?https://www.jwz.org/blog/2016/04/i-wou...
It would be pretty amusing if HN put in a special case to use this for links to jwz.org.
BTW if you use https, i.e. https://nullrefer.com/?http://www.xhaus.com/headers there won't be any Referer at all, while http://nullrefer.com/?http://www.xhaus.com/headers will show nullrefer.com as the referrer.
(To anyone complaining that they need referrers: Use cases that require the referrer can find another solution. As the jwz.org redirect indicates, referrers leak important information. Do you really want to argue that your use case is so important that it justifies a data leak?)
Instead, JWZ requires users to send him emails, and he makes his email id prominent. At this point, I'd be OK with stripping off his notice, because he's not making life easier for anyone else either. Not that I'm affected by what Debian does; I run Arch and have the latest software already.
Also, i think he got burned on bugtrackers while dealing with Gnome bugs. That lead him to formulate CADT and abandon Linux for OSX.
Closed-source software is no different. Had MS and Apple allowed the public to raise bugs against their software, we would have been subjected to a similar treatment there too. For example, the last time I used iTunes on Windows (10+ years ago), it would simply delete all my ID3 comment tags, and write its incomprehensible garbage. Years of hard work, gone in seconds. They did not even have the decency to warn users before they did that. Having lost all my comments, I tried using iTunes for a few months, until more and more bugs made the software simply unusable. I got rid of iTunes, installed Rockbox on the iPod and enjoyed the device for a few more years.
I know I went off on a tangent, but my point was that CADT-like symptoms are endemic to all rapidly-changing software.
Anyway, how he would administer his project's bug tracker has nothing to do with how Gnome runs theirs. I can come up with easy solutions that makes both Debian users and JWZ happy with his current report-bugs-by-email system. But I don't see the point of making the effort. I don't think JWZ reads HN, and even if he does, he comes across as a stubborn and bitter person, at least as far as this topic is concerned.
When I read this on his XScreenSaver FAQ:
> There aren't any FAQs about the MacOS version because, well, unlike Linux, MacOS just works. Sad but true.
I remembered all the times my Mac-using friends have come to me, asking for help with odd problems on their computers. I turned them all away because I didn't know solutions to any of their problems. If I ever meet JWZ in person, as unlikely as it is, the entire field of software will be on my banned topics list.
how can it be deb stable if the author is getting spammed about issues.
kind of seems to be at odds with the best things about Debian.
Thus often various bugs that are not security related will not get patched because that may well disrupt production installs more than leave it be and have the local admin implement a workaround.
JWZ's definition of stable is more akin to what you get out of the kernel devs or FSF's software. A codebase that has been tweaked and fixed over time.
You can see this in how he laments the rewrite(s) of Netscape Communicator after Mozilla was formed, and CADT. Formulated after Gnome devs invalidated long standing bug reports of his, because the relevant Gnome part was to be rewritten from scratch once more.
Stable is in essence one of those context sensitive terms...
I just tested out XScreenSaver on KDE. As long as I set up the process and keyboard shortcuts correctly, I can still use it (Yay, standard APIs). (Of course, I am limited to keyboard shortcuts and not the 'Lock Screen' buttons in KDE).