Core Toolchain Infrastructure - Update on glibc service SOW
Siddhesh Poyarekar
siddhesh@gotplt.org
Thu Jul 11 13:00:55 GMT 2024
On 2024-07-11 07:19, Sam James wrote:
>> Going off https://cti.coretoolchain.dev/gov/index.html, I have a few
>> more questions:
>> * How many members are on the GB?
>> * Who is on the GB?
>> * What is the rationale for there being only one TAC member on the GB?
>> (I don't find the explanation you gave compelling enough, because the
>> GB is ultimately authorising the funding -- 1 seat just doesn't feel
>> like there's any real power there. The chair element does act as a
>> useful counterbalance though.)
>> * What is the difference between a "premium" and "non-premium"(?)
>> member?
>> * Why does being a "premium" member get you a TAC seat if the TAC is
>> community-based?
>>
>> It would be easier to understand if the TAC having 1 seat is an issue if
>> I knew how many members the GB had (and who).
I don't know definitive answers to those, so I'll defer to Carlos.
However based on my experience at Linaro (which is a similar structure
to the LF with just a narrower focus), technical/fiscal separation is
typically to ensure a balance of influence.
I don't think premium membership will allow anyone on the CTI TAC, i.e.
the CTI TAC will always be from the community, but again, I'll let
Carlos confirm that.
>>> For a recent anecdote, we've had more than a few instances of git
>>> access being hampered because someone's spamming bugzilla or moinmoin.
>>> The reason why this cannot be addressed in the context of sourceware
>>> is because it's just one machine that hosts everything. With CTI
>>> we're going to scale this out into isolated instances for git,
>>> patchwork, bugzilla and mail handing so that it's not possible to
>>> compromise security (and developer experience) with git if,
>>> e.g. patchwork was somehow compromised.
>>
>> Yeah, I agree this needs to be worked on. It should be easy to start
>> separating it with e.g. systemd-nspawn containers at least.
AFAIK we already use systemd-nspawn, but that isn't enough.
>>> The GB only provides fiscal oversight and consists of sponsors. At
>>> the moment CTI is an affiliated project at OpenSSF, i.e. it's
>>> sponsored directly by the OpenSSF. We don't have big enough funding
>>> requirements at the moment for glibc:
>>>
>>> https://cti.coretoolchain.dev/gov/index.html
>>
>> The TAC is community-led but the CTI has a governing board where I don't
>> understand the details of its membership yet.
>
> ... also, I'd say it's not community-led if membership of the TAC has to
> be approved by the (opaque to me) GB.
>
I don't think it is, but again I need someone else to back me up on that.
Sid
More information about the Libc-alpha
mailing list