Core Toolchain Infrastructure - Update on glibc service SOW

Siddhesh Poyarekar siddhesh@gotplt.org
Thu Jul 11 13:00:55 GMT 2024


On 2024-07-11 07:19, Sam James wrote:
>> Going off https://cti.coretoolchain.dev/gov/index.html, I have a few
>> more questions:
>> * How many members are on the GB?
>> * Who is on the GB?
>> * What is the rationale for there being only one TAC member on the GB?
>>    (I don't find the explanation you gave compelling enough, because the
>>    GB is ultimately authorising the funding -- 1 seat just doesn't feel
>>    like there's any real power there. The chair element does act as a
>>    useful counterbalance though.)
>> * What is the difference between a "premium" and "non-premium"(?)
>> member?
>> * Why does being a "premium" member get you a TAC seat if the TAC is
>> community-based?
>>
>> It would be easier to understand if the TAC having 1 seat is an issue if
>> I knew how many members the GB had (and who).

I don't know definitive answers to those, so I'll defer to Carlos. 
However based on my experience at Linaro (which is a similar structure 
to the LF with just a narrower focus), technical/fiscal separation is 
typically to ensure a balance of influence.

I don't think premium membership will allow anyone on the CTI TAC, i.e. 
the CTI TAC will always be from the community, but again, I'll let 
Carlos confirm that.

>>> For a recent anecdote, we've had more than a few instances of git
>>> access being hampered because someone's spamming bugzilla or moinmoin.
>>> The reason why this cannot be addressed in the context of sourceware
>>> is because it's just one machine that hosts everything.  With CTI
>>> we're going to scale this out into isolated instances for git,
>>> patchwork, bugzilla and mail handing so that it's not possible to
>>> compromise security (and developer experience) with git if,
>>> e.g. patchwork was somehow compromised.
>>
>> Yeah, I agree this needs to be worked on. It should be easy to start
>> separating it with e.g. systemd-nspawn containers at least.

AFAIK we already use systemd-nspawn, but that isn't enough.

>>> The GB only provides fiscal oversight and consists of sponsors.  At
>>> the moment CTI is an affiliated project at OpenSSF, i.e. it's
>>> sponsored directly by the OpenSSF.  We don't have big enough funding
>>> requirements at the moment for glibc:
>>>
>>> https://cti.coretoolchain.dev/gov/index.html
>>
>> The TAC is community-led but the CTI has a governing board where I don't
>> understand the details of its membership yet.
> 
> ... also, I'd say it's not community-led if membership of the TAC has to
> be approved by the (opaque to me) GB.
> 

I don't think it is, but again I need someone else to back me up on that.

Sid


More information about the Libc-alpha mailing list