Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #9378 > unrolled thread

Bug#856139: certspotter: long description advertises commercial service

Started byShengjing Zhu <i@zhsj.me>
First post2017-08-07 20:30 +0200
Last post2017-08-09 23:20 +0200
Articles 6 — 5 participants

Back to article view | Back to linux.debian.project


Contents

  Bug#856139: certspotter: long description advertises commercial service Shengjing Zhu <i@zhsj.me> - 2017-08-07 20:30 +0200
    Re: Bug#856139: certspotter: long description advertises commercial  service "Dr. Bas Wijnen" <wijnen@debian.org> - 2017-08-07 21:00 +0200
      Re: Bug#856139: certspotter: long description advertises commercial  service Don Armstrong <don@debian.org> - 2017-08-08 17:00 +0200
        Re: Bug#856139: certspotter: long description advertises commercial  service "Dr. Bas Wijnen" <wijnen@debian.org> - 2017-08-09 22:00 +0200
          Re: Bug#856139: certspotter: long description advertises commercial service Vincent Bernat <bernat@debian.org> - 2017-08-09 22:30 +0200
            Re: Bug#856139: certspotter: long description advertises commercial service Russ Allbery <rra@debian.org> - 2017-08-09 23:20 +0200

#9378 — Bug#856139: certspotter: long description advertises commercial service

FromShengjing Zhu <i@zhsj.me>
Date2017-08-07 20:30 +0200
SubjectBug#856139: certspotter: long description advertises commercial service
Message-ID<ubUWR-3Xj-21@gated-at.bofh.it>
On Tue, Aug 8, 2017 at 2:12 AM, Dr. Bas Wijnen <wijnen@debian.org> wrote:
>> Example: [s3cmd]
>
> How is this not in contrib?  This software is useless without the non-free
> service (which is also software, and it is not in main) from Amazon.  Policy
> even mentions as an example for things in contrib: wrapper packages or other
> sorts of free accessories for non-free programs.  That's exactly what this is.

Maybe some off topic here.

The description of s3cmd is outdated. It's *not* useless without AWS.
It can be used with self-hosted S3 protocol compatible service, such
as Ceph RGW, minio[1]. Both are free softwares, and Ceph is in our
main archive.

[1] https://github.com/minio/minio


-- 
Best regards,
Shengjing Zhu

[toc] | [next] | [standalone]


#9379 — Re: Bug#856139: certspotter: long description advertises commercial service

From"Dr. Bas Wijnen" <wijnen@debian.org>
Date2017-08-07 21:00 +0200
SubjectRe: Bug#856139: certspotter: long description advertises commercial service
Message-ID<ubVpT-492-1@gated-at.bofh.it>
In reply to#9378

[Multipart message — attachments visible in raw view] — view raw

On Tue, Aug 08, 2017 at 02:25:51AM +0800, Shengjing Zhu wrote:
> The description of s3cmd is outdated. It's *not* useless without AWS.
> It can be used with self-hosted S3 protocol compatible service, such
> as Ceph RGW, minio[1]. Both are free softwares, and Ceph is in our
> main archive.

Ah, that's good then!  Still, I think its description has the same problem as
certspotter, namely that it recommends the use of a non-free service.  In
Debian, I would prefer to see a recommendation for the free alternative, while
the non-free alternative may be mentioned (or not, depending on what users
need).

Thanks,
Bas

[toc] | [prev] | [next] | [standalone]


#9388 — Re: Bug#856139: certspotter: long description advertises commercial service

FromDon Armstrong <don@debian.org>
Date2017-08-08 17:00 +0200
SubjectRe: Bug#856139: certspotter: long description advertises commercial service
Message-ID<uce9c-1st-25@gated-at.bofh.it>
In reply to#9379
On Mon, 07 Aug 2017, Dr. Bas Wijnen wrote:
> Ah, that's good then! Still, I think its description has the same
> problem as certspotter, namely that it recommends the use of a
> non-free service. In Debian, I would prefer to see a recommendation
> for the free alternative, while the non-free alternative may be
> mentioned (or not, depending on what users need).

An important counterpoint is that the long description helps with the
discoverability of a package. Mentioning a famous non-free service helps
users discover the package and also notice that there are free
alternatives.

-- 
Don Armstrong                      https://www.donarmstrong.com

A kiss was mysterious and powerful, fragile and invincible. Like any
spark, a kiss might fizzle into nothing or consume an entire forest.
[...] A kiss could change the entire world.
  -- Scott Westerfeld _The Killing of Worlds_ p336

[toc] | [prev] | [next] | [standalone]


#9389 — Re: Bug#856139: certspotter: long description advertises commercial service

From"Dr. Bas Wijnen" <wijnen@debian.org>
Date2017-08-09 22:00 +0200
SubjectRe: Bug#856139: certspotter: long description advertises commercial service
Message-ID<ucFj4-3lz-15@gated-at.bofh.it>
In reply to#9388

[Multipart message — attachments visible in raw view] — view raw

On Tue, Aug 08, 2017 at 07:58:06AM -0700, Don Armstrong wrote:
> On Mon, 07 Aug 2017, Dr. Bas Wijnen wrote:
> > Ah, that's good then! Still, I think its description has the same
> > problem as certspotter, namely that it recommends the use of a
> > non-free service. In Debian, I would prefer to see a recommendation
> > for the free alternative, while the non-free alternative may be
> > mentioned (or not, depending on what users need).
> 
> An important counterpoint is that the long description helps with the
> discoverability of a package. Mentioning a famous non-free service helps
> users discover the package and also notice that there are free
> alternatives.

Yes, I agree.  If the non-free service is famous, I think it makes sense to
mention it.  However, even in that case I think we should still recommend the
free option(s).

If the free options are limited to a point where it does not make sense to
recommend them to our users, that means the non-free service should be
recommended and IMO that means the program should be in contrib.

Thanks,
Bas

[toc] | [prev] | [next] | [standalone]


#9390

FromVincent Bernat <bernat@debian.org>
Date2017-08-09 22:30 +0200
Message-ID<ucFM5-3O1-1@gated-at.bofh.it>
In reply to#9389

[Multipart message — attachments visible in raw view] — view raw

 ❦  9 août 2017 19:57 GMT, "Dr. Bas Wijnen" <wijnen@debian.org> :

> If the free options are limited to a point where it does not make sense to
> recommend them to our users, that means the non-free service should be
> recommended and IMO that means the program should be in contrib.

As a sidenote, I strongly think I should just shut up. This kind of
discussions always lead nowhere and people just forget them. But...

Let's take rclone.

Description: rsync for commercial cloud storage
 Rclone is a program to sync files and directories between the local
 file system and a variety of commercial cloud storage providers:
 .
  - Google Drive
  - Amazon S3
  - Openstack Swift / Rackspace cloud files / Memset Memstore
  - Dropbox
  - Google Cloud Storage
  - Amazon Drive
  - Microsoft One Drive
  - Hubic
  - Backblaze B2
  - Yandex Disk

It says "commercial". Lot of commercial services. But, it would work
with free S3 implementations and it works with Openstack Swift which is
free. So, not in contrib, right?

Now, it is written in Go and it depends on a lot of libraries, notably those:
 - golang-github-aws-aws-sdk-go
 - golang-github-stacktic-dropbox
 - golang-google-api
 - golang-google-cloud

They should be in contrib. But then, rclone would be in contrib
(packages in main cannot depend on packages in contrib). So, our users
would just lose a software which can be used to migrate data from a
commercial service to a free service.

There are other examples and this can become insidious. Some highly used
libraries can depend on libraries only useful with a commercial
service. For example, golang-github-armon-go-metrics depends on
golang-github-datadog-datadog-go, a library only useful for the
commercial service Datadog. Pulling this library in contrib would push
to contrib all software from Hashicorp.
-- 
Use self-identifying input.  Allow defaults.  Echo both on output.
            - The Elements of Programming Style (Kernighan & Plauger)

[toc] | [prev] | [next] | [standalone]


#9391

FromRuss Allbery <rra@debian.org>
Date2017-08-09 23:20 +0200
Message-ID<ucGyt-4l3-1@gated-at.bofh.it>
In reply to#9390
Vincent Bernat <bernat@debian.org> writes:

> As a sidenote, I strongly think I should just shut up. This kind of
> discussions always lead nowhere and people just forget them. But...

Yeah, I've been feeling the same way.  But one message in support of this
point, just to try to balance the expressed opinions a bit.

> Let's take rclone.

> Description: rsync for commercial cloud storage
>  Rclone is a program to sync files and directories between the local
>  file system and a variety of commercial cloud storage providers:
>  .
>   - Google Drive
>   - Amazon S3
>   - Openstack Swift / Rackspace cloud files / Memset Memstore
>   - Dropbox
>   - Google Cloud Storage
>   - Amazon Drive
>   - Microsoft One Drive
>   - Hubic
>   - Backblaze B2
>   - Yandex Disk

> It says "commercial". Lot of commercial services. But, it would work
> with free S3 implementations and it works with Openstack Swift which is
> free. So, not in contrib, right?

> Now, it is written in Go and it depends on a lot of libraries, notably those:
>  - golang-github-aws-aws-sdk-go
>  - golang-github-stacktic-dropbox
>  - golang-google-api
>  - golang-google-cloud

> They should be in contrib. But then, rclone would be in contrib
> (packages in main cannot depend on packages in contrib). So, our users
> would just lose a software which can be used to migrate data from a
> commercial service to a free service.

Indeed.

I think it's a bad idea to push this sort of tool off into contrib.  I
don't think making it harder to use free software with non-free services
is going to achieve our goals as a project; to the contrary, I think
making it easier to get data out of non-free services using free software
can only benefit free software, given the current balance of power in the
ecosystem.

If free software cloud services were overwhelmingly common and non-free
cloud services were an intruder in this space, the calculus might be
different, and it might be tactically better to freeze out the non-free
services and make it more difficult to work with them.  But that's not the
shape of ecosystem that we're dealing with right now.

(Conflict of interest disclosure: I currently work for Dropbox, although
not on the product side.  I think the above opinion is the same I'd hold
if I didn't work for Dropbox, and held before I took that job, but anyone
reading this thread should judge that for themselves.)

-- 
Russ Allbery (rra@debian.org)               <http://www.eyrie.org/~eagle/>

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.project


csiph-web