Re: Mercurial 0.4b vs git patchbomb benchmark
- From
- Tom Lord <lord@emf.net>
- Date
- Apr 29, 2005, 19:22 UTC
- Message-ID
- <200504291922.MAA27053@emf.net>
- In-Reply-To
- <2944.10.10.10.24.1114802002.squirrel@linux1>
> Ahh, you don't believe in the development model that has produced Linux! > Personally I do believe in it, so much so that I question the value of > signatures at the changeset level. To me it doesn't matter where the code > came from just so long as it works.
To me, it doesn't matter where the code came from. It's necessary but not sufficient that it seems to work. It's necessary that it's well understood and has undergone only well understood changes.
On that last necessity, a *lot* of open source projects are quite pathetic. `git'-style use of signatures raises the bar, slightly, for where exploits can happen. They also lower the bar for repudiation of bogus changes.
> Signatures are just a way to > increase the comfort level that the code has passed through a number of > people who have shown themselves to be relatively good auditors. That's > why I trust the code from my distribution of choice. Everything is out in > the open anyway so it's much harder for a con man to do his thing.
Only if the audience is proactively skeptical.
-t