Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Gordon Messmer

@gordonmessmer@fosstodon.org
mastodon 4.7.3
  • Open on fosstodon.org
0 Followers
0 Following
39 Posts
Joined June 28, 2023
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 6d ago

A 95% solution is often worse than a 30% solution.

When you have a 30% solution, you know that you need to mix and layer solutions.

95% solutions often lead teams to waste time and effort trying to close the gap when mixing and layering would be less expensive and less complex. Or they can lead teams to do nothing, expecting that the solution will be finished someday.

1
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 2w ago

Some distributions fight the idea that applications should specifically select compatible components, and it hasn't been working for over 30 years.

https://gordonmessmer.codeberg.page/dev-blog/2026/09/24/let-applications-select-dependencies.html

gordonmessmer.codeberg.page
2
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 1w ago

Due to the linear nature of time, software must exist before other software can depend on it. A shared component must be released before software can be ported. In this way, change flows through code like light or sound through their own mediums. This is the speed of compatibility.

Consequently, the version that is compatible tends to be older as it becomes more indirect. An app that uses a component directly may need a different release than one that uses it indirectly

https://gordonmessmer.codeberg.page/dev-blog/images/png/select-deps-branch-time.drawio.png

gordonmessmer.codeberg.page
1
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 1w ago

One of the biggest drivers of productivity improvements in software development is one of the least discussed: branching.

https://gordonmessmer.codeberg.page/dev-blog/2026/09/27/stable-independent-async.html

gordonmessmer.codeberg.page
1
0
1
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 2w ago

The Free Software concept was created by people who believed that copyright should not apply to functional work. The GPL is best understood as an attempt to use copyright to simulate a world without copyright.

2
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago

I'm a little worried that a generation of admins has been conditioned to believe that a package manager is a substitute for a vulnerability scanner.

No pending updates != No vulnerabilities

3
1
1
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io I've been developing software for GNU/Linux systems and managing production networks of those systems professionally since 1997, and not once in 30 years have I believed that distributions exist because developers are bad at distributing software.
3
27
1
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 7mo ago

Someday I hope to be able to describe technical concepts as clearly as this.

Thank you @samwho@hachyderm.io

https://samwho.dev/memory-allocation/

samwho.dev
5
0
2
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago

It's much more accurate to see a free LTS release as the period during which you can participate, rather than the period during which your system gets support.

Despite the name, free LTS systems come with no support, and you should not assume that the packages you use and care about will be maintained unless you participate in their maintenance.

2
0
1
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago

One of the things I love about Free Software is the pervasive spirit of collaboration and respect.

But at the same time, I think that we are failing our community by never discussing the trade-offs required for development processes like LTS distributions, because it sounds too much like criticism.

2
1
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago

SeaGL is coming up and CfP is open. I don't see any talks in their last 10 years of archives that discuss the difference between LTS and regular release systems from a security point of view. I am finding that far more people than I expected believe that LTS systems offer better security.

Do you think such a talk would be interesting or useful?

2
3
2
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io I know that I'm odd, because I always want to listen to the topic, "how did we get here?" I talk a lot about the importance of process improvements, and the need to understand the purpose of a process in order to improve it. But even acknowledging my oddity, I can't make sense of the idea that "distributions tell developers they are bad" is important enough to be part of how you promote and frame this presentation, but not interesting enough to discuss.
1
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io No, I mean something lower level than Flathub. Flathub isn't general purpose because it's focused on delivering interactive applications to desktop users. If I want to construct a CI workflow that tests my application against the latest upstream release of OpenSSL, that's not a problem that Flahtub solves. I want a package registry for that.
1
1
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io "I agree that distributions has been unkind to developers" implies that I made a statement to that effect, or hold such a belief. That's very much the opposite of what I said.
1
19
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io There are a lot of things that distributions do poorly. And there are a lot of distribution policies that I think were adopted in a world that has significantly changed, and which have not kept pace. But I think that many of the characterizations you are making about distributions are unfounded, and more importantly, unkind.
1
24
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io If there is a finger to be pointed, I think it is in the other direction entirely. The problem is that there is no coherent target platform. Free Software "platforms" are made up of hundreds (at least) of individual components that are terrible at maintaining backward compatibility, don't coordinate their release schedules, and don't even communicate their releases through a common channel. Often they don't have predictable release cadences OR maintenance windows.
1
26
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago
Replying to
@andrewnez@mastodon.social But I can't logically describe how PyPI could offer something more stable than it does. Who would define the release cadence? What is a set? In what way is the registry better suited to defining a set or a cadence than the application developers that pull components from it?
0
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io Trying to release an application that runs on Free Software "platforms" is like trying to step in the same river twice.
0
25
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io The topics you're bringing up are important. I think we should talk about them. I'm glad that you're talking about them. But I also think that attributing motivation to another person who isn't part of that discussion is unfair.
0
23
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io "Goose by itself ships multiple times per week. How does the distribution model scale to delivering this software?" That's a great question, and that's why I think a panel would be a good format!
0
13
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago
Replying to
@andrewnez@mastodon.social Whether we are talking about registries or distributions, a mechanism exists to provide a selector. If you provide a selector, you expect to follow a specific release stream. And if you don't provide a selector, then you will get whatever stream is newest.
0
2
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io I feel like the presentation you've described would make a really good panel, especially if we found specifically developers who have been told that and distribution maintainers who can talk about why they solve problems the way they have.
0
17
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago
Replying to
@andrewnez@mastodon.social The only difference I can logically describe between Debian and a registry is that a stable release of Debian is a *set* of components. So it might make sense for "pip" to have the option to update a venv by installing the newest release of each component's release stream without rebasing anything in the set.
0
2
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io Is your answer to "I think it is unkind to attribute to others a position they do not hold" to attribute to me a position that I do not hold?
0
21
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@gisgeek@floss.social I will also note with amusement that a notable problem in 2012 was that "the touchpad driver which at that point didn’t provide full support and lacked, among other things, palm rejection" Trackpad palm rejection on GNU/Linux systems is still terrible today.
0
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@gisgeek@floss.social I think it's worth recognizing that Dell has been at this since at least 2012! https://www.dell.com/community/en/conversations/developer-blog/dells-developer-line-turns-10-a-decade-of-project-sputnik-the-lessons-learned/647fa24ff4ccf8a8de7c971e
dell.com
0
1
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io Like, in Fedora, we have rolling releases for Firefox and for KDE... Those are rolling releases upstream, and we follow the upstream model.
0
11
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 3w ago

I dropped a long section of that last blog in which I had described the importance of letting people work at their own pace to promote productivity, because I've said it so many times before, and I see now that was a huge mistake.

0
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io It seems odd to reference an edition of a distribution as evidence that distributions are bad?
0
5
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io I think that distributions should work the way that any other package registry works: like PyPI or npm or Crates, etc. So the answer is: a distribution should do what the upstream does. If the upstream provides a stable release series, the distribution should follow it. And if the upstream is a rolling release, the distribution should follow that, too. I think it's bad for distributions to ship software beyond its upstream maintenance window.
0
12
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io In any case, when I say that "distributions should function like any other package registry", I do mean that distributions should let application maintainers handle their business. I think that a general purpose package registry would REALLY help application maintainers handle their own business. I don't think such a thing exists today, but I want it to.
0
4
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@andrewnez However, downstreams *can* pull their deps from VCS if you manage your branches properly. This requires all of the related projects to provide a compatible build definition, and it requires a tool that can coordinate chain builds. Fortunately, those things already exist. You can do this now. You don't need to wait a forge to support it. https://gordonmessmer.codeberg.page/dev-blog/2026/02/01/rpm-ci.html
gordonmessmer.codeberg.page
0
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@swick That is to say that I think I agree with you, at least in part, but there's not enough detail in your comment to tell. Lots of software is actively maintained for long term... "LTS" is not inherently a scam. There are just a lot of free projects that are applying that label incorrectly.
0
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io I think Gentoo gets pretty close to providing that. I think Fedora could do better than it does, with some minor tweaks.
0
0
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago
Replying to
@andrewnez@mastodon.social I don't think that's logically consistent. If I ask a coworker to "install Debian", they will most likely install the latest release of Debian, because I didn't provide a selector of any kind. If I run "podman pull debian" I will get the latest release of Debian. So, if "pip install requests" installing the latest stable release means that the registry is unstable, then the same terminology would classify container registries and distributions as "unstable."
0
3
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 4mo ago

After managing production networks for 30 years, I believe that LTS systems exist to prioritize compatibility with the ecosystem in which they operate, whereas more recent releases will typically have the smallest number of known security flaws.

Apparently there are people who don't believe this?

0
1
0
0
Open post
Gordon Messmer @gordonmessmer@fosstodon.org
· 5mo ago
Replying to
@jorge@hachyderm.io Imagine for a moment that I would like a GNU/Linux host with OpenSSH. But in this case, "the real thing" is only available for OpenBSD. The OpenSSH developers are not interested in GNU/Linux as a platform. What are my options?
0
8
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:58:24 UTC