But I think their tooling and policies have become outdated, which prevents faster progress.
I wish they would switch to some Nix-like alternative, which was discussed in their developer list long ago. The genius of Nix is that packages do not need to depend on the same dependencies. Hence, the whole package tree does not need to be kept in sync.
Another great advantage are declarative package specifications. I maintain several packages for NixOS, and a bot does auto-updates for me. I just check upstream hasn't introduced any malicious code.
Lastly, shipping many "distributions" becomes trivial with Nix. A distribution is just a package channel plus a declarative setup written in a small half-a-page expression. So you can easily create a minimal Debian, a Debian with a GNOME desktop, a Debian with a Xface desktop, a Debian with a KDE desktop, etc.
It's a blessing, and a curse. In order to ensure the quality for all packages, now you have to keep all versions anything depends on in check. A bug fix applied to the most recent version doesn't automatically affect packages depending on it, so all of them need to be updated too now.
This is similar to the reason that Debian doesn't accept packages which vendor any dependencies (similar to Fedora).
> declarative package specifications
I tried making RPM, .deb, and Nix packages, and I found Nix to be by far the nicest to work with.
In other words, Nix’ approach gives you the choice, while the current approach forces you into a certain direction.
This is untrue. Everytime that a package is updated, thanks to NixOS declarative build system, all packages that depend on it are also rebuild/updated. Unless you're pinning your derivations, it works even on custom packages created by you.
When I was referring to pinning, it is mostly done locally. I do sometimes, for example, pinning a specific package to a specific commit of Nixpkgs, so I can either backport a new version or avoid some change that I don't want to deal at the moment.
Spot on. This creates a burden of work impossible to handle for any distribution.
What really happens with the "everything goes" packaging (like throwing stuff in docker) is that nobody does security updates for most libraries.
Or maybe your FPGA programming software depends on some ancient version of QT from 2016, so you pull that Nixpkgs in for that package only.
Um, you do know that Debian does this already, right? man tasksel
Ubuntu Snap does this. You may even be able to install Snap on Debian. Whats worse is the 'snap' package is unrelated so you may want to look it up before installing something unrelated.
"...and adhocratic it its form,..."
I think it should be:
"...and adhocratic in its form,..."
Can't find a way to edit the wiki. Anybody know how to contact the people behind the project?
When the issue of free software support comes up, too often I see the usual "OUR COMMUNITY IS NOT YOUR FREE TECHNICAL SUPPORT WE OWE YOU NOTHING"... o..okay, fair enough. I can't waltz into your community and demand your time for free... But you _do_ want me to use your system, right? You _do_ think that Free Software is a viable alternative to proprietary software, where the creators literally _owe me_ support for their software because I paid them for it?
That's why it would be nice if they laid out exactly what it is that they are committing themselves to. Not just writing code and putting the thing together, but a certain (of course not unlimited) amount of assistance, so I know I won't be totally left hanging. Maybe some OSes are too much of a hobby or experiment and they don't want to offer that level of support. Totally fine. We should expect that sort of thing in the social contract, so users know what they're getting themselves into, and so that we can all step back and evaluate whether Free Software is a viable alternative to propriety yet.
I appreciate this link, it may be helpful some day.
Have you ever tried asking for this. At best you'll get "you're holding it wrong, get bent", and even that's usually only if you have the expensive enterprise support package.
FWIW I just contacted Google support with help with an issue with their Play Movies on a smart TV. Turns out what I needed to do was in the Smart TV general settings, not even the app per se, and they still helped me with that. The phone support person wasn't able to help but the chat support was.
I go to qubes-os.org. I don't see "A community of hobbyists who put together an operating system. Join in if you'd like, but you're responsible for what happens. Good luck and have fun!". I see "A Reasonably Secure Operating System". I see articles in the press, all the powerful components under the hood. For God's sake I see Edward Snowden endorsing it. It looks like they're selling it.
I go to qubes-os.org/support. I see "They are not your personal, paid support service. No one owes you a reply. No one here is responsible for solving your problems for you.". This sends a mixed message.
Maybe it makes perfect sense to you because you're deep in this world yourself, and it's just "how it works". But then I would argue you're not thinking about the whole goal of Free Software, which is to ultimately replace proprietary software. Free Software was supposed to give you a reasonably replacement of proprietary software. Maybe without all the bells and whistles, but nobody says "and we'll leave you out to dry if nobody feels like helping you".
Imagine, somebody trusted this great, secure operating system. Suddenly something goes wrong. They post on this high volume community support list. Nobody answers. "But I'm in a total jam now. I trusted your operating system." "NOBODY OWES YOU HELP". You're leaving people out to dry with no recourse. I think people are not thinking of this edge case.
Of course you can get paid support, at worst from a third party. That covers my point entirely from a practical standpoint. However this leaves two problems in my mind. 1) Where _is_ the paid technical support option for (for instance) QubesOS? I don't know if it exists. When and if it does, it would be nice for Qubes to at least link to a few options from their support page. 2) The mixed messaging I described above is still a problem in my view. It really sounds like you're telling people "if we find you annoying we will leave you out to dry". You could at least mention the _prospect_ of 3rd party assistance. I think it sends a different message about how this whole ecosystem works.
EDIT: I guess Debian does exactly what I mean: https://www.debian.org/consultants/