Gyroplast

joined 1 year ago
[–] Gyroplast@pawb.social 1 points 11 hours ago

inb4 "Archlinux snobs are gatekeeping packages"

[–] Gyroplast@pawb.social 52 points 11 hours ago (1 children)

TL;DR: Don't think of the AUR as a package source, but as of an only mildly moderated, but ultimately free and open, sharing platform for PKGBUILDs, primarily useful for (self-)packagers, not necessarily non-technical end users.

Before the AUR, you had people individually hosting their PKGBUILDs anywhere, sometimes on GitHub or the BBS (yeah, it's been a while), sometimes along with a repository URL you could add to your pacman.conf to install packages right away, and it was glorious. I didn't have to write a working PKGBUILD myself from scratch, and I could decide if I trusted that particular packager to not screw me sideways with a pre-built package. An officialized "Trusted User" (TU) role emerged from this idea, which has recently been renamed to Package Maintainer (PM). This is fundamentally still how the AUR works, it just became much bigger, and easier to search for particular software. Packagers gift to you their idea of how software should be packaged, for you to expand upon, take inspiration from, or learn, or use as-is if you determine it to be good for your purpose.

The AUR is ultimately a great resource for packagers, and still useful for users, but "true end users" get the extra repository, and community, kind of, before that, and should try to avoid the AUR if they can, or at least be prepared to put in effort to establish trust, or get help.

A handful of Package Maintainers are manually adopting and subsequently vetting for sufficiently popular packages to move them from the AUR to the official extra repository, which is deemed safe to use as-is, on a best-effort basis. Obviously, this is a bottleneck, as it is not feasible for the few volunteering PMs to adopt and maintain 10k+ AUR packages and be held to any quality standard. That's why "you are on your own" with the AUR.

On the positive side, there's a voting system to determine package popularity. AUR packagers have a public list of maintained packages, and a comprehensive git commit history. Establishing trust is still crucial, and I feel hard pressed to name a reasonably popular/useful package that isn't already in extra or has been maintained in the AUR for a long time.

The biggest risk, IMHO, for malware getting slipped into a package is orphaning a popular package, and having it adopted by a malevolent user. This is something I personally look out for. If the maintainer changed, I make sure to check the commit history to see what they did. Most of the time it's genuine fixes, but if anything is changed without a damn good and obvious reason, hit up the AUR mods and ask for help. This is how malware is spotted. Also, typically only the version is bumped in a PKGBUILD on an update, which is a change I feel safe waving through, too. If the download URI changes, or patches are added, I do look at them to determine the reason, and if that isn't explained well enough to understand, that's a red flag. Better ask someone before running this.

source: personal involvement in Arch since 2002

[–] Gyroplast@pawb.social 13 points 6 days ago (1 children)

Haste mal'n Wasser für mich?

Klar, ich bewahr's im Hahn auf, spart Platz.

[–] Gyroplast@pawb.social 1 points 1 week ago

"Read the instructions", he was told, so he read them. And then he did lead Sean to the lead pipe.

[–] Gyroplast@pawb.social 3 points 1 week ago (3 children)

Among the lovely revival of arguing the One True Pronunciation, I personally see lay-tech as a portmanteau of "layout technology". Meaning in German discourse, it's [tɛç], and in English [tɛk]. Simple to remember, easy to derive, and matching the Gospel.

[–] Gyroplast@pawb.social 9 points 1 week ago (31 children)

That nerd would surely pronounce his kink /ˈleɪtɛk/. Also, nobody loves \LaTeX. Unrealistic. 3/10.

[–] Gyroplast@pawb.social 4 points 2 weeks ago

Thanks, that sounds plausible enough for me. Has Arson, Murder, and Jaywalking vibes, bureaucracy would love this, so I shall accept this as fact henceforth, and indulge my confirmation bias!

[–] Gyroplast@pawb.social 9 points 2 weeks ago (3 children)

When I visited the US in 2000 (yep, pre-9/11), everyone was handed a small paper form shortly before landing(!), in the plane, and I distinctly remember that checkbox asking me if I am planning any illegal or terrorist activity after entering the country.

I still do not understand its purpose. I honestly don't.

[–] Gyroplast@pawb.social 10 points 2 weeks ago

Bah, humbug! In my days we used a rubber ducky, IF WE HAD ONE, or just the stick we were beaten with for using too many precious CPU cycles, and we were FINE!

[–] Gyroplast@pawb.social 54 points 2 weeks ago (3 children)

I still have a soft spot for troll physics. Needs more magnets, though.

[–] Gyroplast@pawb.social 10 points 3 weeks ago

Oh my, better watch Felidae next, that one looks cute.

[–] Gyroplast@pawb.social 19 points 3 weeks ago

This reminds me of the tale of the coder tasked to write an input validator for IPv4 addresses. Poor bastard.

Another fun one: 0177.042.017.066

PSA: Don't zero-pad your IPv4 octets. Decimal is for simpletons.

view more: next ›