Review of a secure software development process for glibc.

Sam James sam@gentoo.org
Thu Jun 5 17:41:43 GMT 2025


Siddhesh Poyarekar <siddhesh@gotplt.org> writes:

> On 2025-05-29 10:16, Sam James wrote:
>>> At this point however, I'm not sure that's going to be a viable route
>>> despite you receiving satisfactory answers to those questions because
>> (I guess you mean "when you do", as I don't feel I have, but I am
>> honestly asking in good faith with these -- "despite" implies to me they
>> should be there but I haven't accepted them or something.)
>
> Sorry, yes, I mean "when you do", because while I did respond to you
> in that thread earlier, I didn't do so authoritatively.  I agree that
> those questions need authoritative, public clarification, but I don't
> think that'll change much for the conversation about LF IT usage.

ACK :)

>
>>> Also FWIW, corporate sponsorships and donations are two different
>>> things; expecting corporations to ask for nothing amounts to asking
>>> for a donation.  A sponsorship almost always entails something in
>>> return.
>> Yeah, that's fine with me and understandable. Thanking sponsors in
>> release notes, mentioning them on the website for example would be fine,
>> could discuss other ideas that people have.
>> If we mean membership of the GB, then I don't get what they get out
>> of
>> it if they're not named anyway.
>
> They're not looking for marketing, they're looking for a way to spend
> on supporting open source bits that they're already using because
> they're aware of the risk to their business due to those bits not
> getting the financial support they need.  Direct funding or
> contribution is almost always not an avenue for them due to
> legal/operational reasons, so they prefer to use organizations like LF
> or Linaro.  In a nutshell, it's an engineering cost and not a
> marketing/sales investment, so it tends to be kept at a minimum.
>
> Governing boards and their membership is a way to demonstrate to their
> investors that they are able to influence the spending and not just
> relying on LF/Linaro to do the right thing.  In practice, they're
> simply there to make sure that the thing they're spending on is not
> wasteful. They are not in it to influence the direction of open source
> projects they're spending on beyond what they would need because such
> an influence would require additional investment on their end through,
> e.g. engineering time or resources and that is a deterrent.
>
> The relevant example for this in our context is regulatory
> requirements for secure software supply chain, where they would like
> the infrastructure for upstream projects they consume to adhere to
> standards that allow them to continue consuming that software for
> their business. This is the driver for them to fund GNU toolchain
> infrastructure and with OpenSSF already driving this in the larger
> Open Source ecosystem, that's the natural avenue for them to spend and
> get what they need with minimum overhead.
>
> If they had to open a new, direct channel for funding they would have
> to not only justify why using an organization like LF is not an
> option, they would also have to attest that their funding does in fact
> achieve their objective and that the development team that manages
> Sourceware PLC does meet the standards required for their compliance,
> esp. in comparison to LF IT.  That's a lot more work, especially when
> most of these orgs are pretty ignorant about the FOSS ecosystem, so I
> don't really see them actually doing this.

Thanks Sid. This is a useful perspective and one I hadn't thought of.

I still have some concerns about achieving a better balance for
community representation and also whether the funds could be (perhaps in
part) used for sourceware but this helps explain one part I was kind of
stuck on.

>
> Sid

sam


More information about the Libc-alpha mailing list