Gentoo Archives: gentoo-dev

From: Rich Freeman <rich0@g.o>
To: gentoo-dev <gentoo-dev@l.g.o>
Subject: Re: [gentoo-dev] LibreSSL import plan
Date: Wed, 30 Sep 2015 11:51:14
Message-Id: CAGfcS_m_gYEYmj00mVPnXxzBTnv0vpm31wT59-WB7LNu2_U_6A@mail.gmail.com
In Reply to: Re: [gentoo-dev] LibreSSL import plan by Kristian Fiskerstrand
1 On Wed, Sep 30, 2015 at 7:29 AM, Kristian Fiskerstrand <k_f@g.o> wrote:
2 >
3 > The way I see it this is relevant to the discussion at hand.
4
5 Admittedly it is a bit tangential, but it didn't seem worth forking
6 the thread over. Certainly I'm not going to invent my own mailing
7 list and post it there, and then post here to advertise it. I doubt
8 such a discussion will be all that welcome on the upstream mailing
9 list.
10
11 > Or is this just increasing our maintenance, and security tracking, etc
12 > burdens without any strong benefits?
13
14 I don't think that it is necessary to have a cost/benefit analysis
15 anytime somebody wants to introduce a new package in the tree.
16
17 Gentoo tends to be about making new alternatives available to users.
18 As long as hasufell is willing to do the work necessary to add the
19 necessary USE flags and blockers I don't see the harm in having this
20 in the tree. If upstreams switch to requiring this library
21 exclusively and thus become incompatible with other upstreams which do
22 not, that is something that will affect us whether or not we allow
23 libressl in the tree (see ffmpeg/libav).
24
25 I think it was fair to pause to see if somebody could come up with a
26 better solution that allows co-existence, but absent that I don't see
27 any benefit from keeping libressl out of the tree. We'll just
28 experience all the downsides of the fork without the upsides.
29
30 It might very well cost some of hasufell's time to maintain it, but
31 that is time he is freely offering, and it isn't like turning him away
32 is going to encourage him to spend more time on other Gentoo features.
33 Cost/benefit for a volunteer distro isn't a zero-sum game the way it
34 is if you're a manager of a 50-person development team.
35
36 I'd love to see somebody come out with a better solution for this sort
37 of thing, and it probably would need to be bigger than Gentoo to be
38 truly effective. However, until such a solution comes along I don't
39 see the benefit of further delay. That's just my two cents.
40
41 --
42 Rich

Replies

Subject Author
Re: [gentoo-dev] LibreSSL import plan Kristian Fiskerstrand <k_f@g.o>