forge vs gitolite (Re: CTI - Making a decision for glibc.)

Alexandre Oliva oliva@gnu.org
Wed Feb 11 10:11:24 GMT 2026


Thanks, these were useful questions.

I hope the answers bring more clarity.

On Feb  9, 2026, Gabriel Ravier <gabravier@gmail.com> wrote:

> Let's say that today, there is one s390x machine
> running tests (or arc, csky, or1k, sh or some other esoteric
> architecture - the specifics aren't super important), and that the
> project "relies" on this to make sure random commits don't break on
> s390x. Would this be SaaSS ?

It depends.  If that testing is our computing, and we control it, then
it's not SaaSS, regardless of who offers us the hardware.  If that's
some third party's computing, and that third party controls it, then
it's not SaaSS either.  But if it's our computing, and someone else
controls it, it's SaaSS and it takes our freedom away.  Whereas if it's
someone else's computing, and a third party controls it, it's SaaSS for
that someone else, but it doesn't affect our freedom.

> - Is it SaaSS if we consider that the machine is required for s390x
>   support, and if it is retracted with no replacement, s390x support
>  will be officially dropped ?

No.  That someone else owns the machine and can terminate our access to
it doesn't make it SaaSS.  It's our control over our computing that we
run on it, as long as we have access, that determines whether it's
SaaSS.

We don't even need exclusive access to the machine.  We just need
control over the computing we do there.

> - Is it SaaSS if we consider that the machine is a non-required
>   courtesy

That's not a relevant consideration.  What matters to tell whether it's
SaaSS is whether we control our computing that runs on it, or someone
else does.

> - Is it SaaSS if the machine is of a more common architecture that we
>   could "test ourselves" ?

How common the architecture is makes no difference.  What makes a
difference is whether we control our computing that runs on it.

> - Is it SaaSS depending on *who asked* the machines to run the tests
>   (e.g. because the glibc project kindly asked the owner of the
>  machine to do so, or because the owner of the machine simply decided
> to do so), and if so, does it matter at all how the tests are used
> after someone "independently" (or not) ran the tests ?

The "who asked" could be either that whose computing the machine runs,
or that who commanded the machine to do the computing.  If they're the
same party (individual or group), then it's not SaaSS.

But if you ask some third party (who's not your agent, under your
control as to this process) to do the computing for you, and that third
party asks the machine to do the computing (under their control rather
than yours), then it's SaaSS.

If someone else takes the initiative of running the tests, and
volunteers the results to us, we can use them, and that makes no
difference to our software freedom even if it was SaaS to that someone
else, because that wasn't our computing, so we shoudn't expect to have
control over it.

> Note that in none of these cases we would have direct control over the
> machine

*nod*.  using a VPS, a VM, a container, or even access to a shared
machine doesn't take your freedom away inasmuchas it doesn't take
control of the computing you do there.  If the machine (virtual or not)
follows your commands and instructions towards that computing (therefore
within the boundaries of access you were granted), you have control of
your computing (which is what matters as far as software freedom is
concerned), if you don't fully control the machine on which it runs.


> PS: As to my last question, it seems like an oddly simple structural
> run-around-the-rules to say that the tests are being "run
> independently" if glibc developers regularly consult the tests and use
> them to improve the project

You could frame it that way, and I guess if such a practice is adopted
as a workaround for SaaSS, that's what it would amount to.

But see, GCC has very long had a dedicated mailing list that receives
test results from runs by independent contributors, and we regularly
consult those results.  That definitely doesn't take our freedoms away,
even if it's quite useful for us.

If we chose to do our own testing that way, though, it would be our
computing, and we would be relinquishing control over it => SaaSS.

> would this be SaaSS in either the
> "required for architecture support" or the "courtesy" scenarios ?

The answer to this is question is a little fuzzy.  The more we want,
expect and depend on those results, and the more disruptive not having
them would be to our workflows, the clearer it is that it is our
computing in disguise after all, and so the more it is SaaSS.

I wish we wouldn't try to explore the exact boundary to figure out just
how much we can afford to give up of our freedom.  That would be an
unfortunate outcome for this conversation.  I wish we'd instead strive
to do our computing in freedom, i.e., under our own control.

-- 
Alexandre Oliva, happy hacker            https://blog.lx.oliva.nom.br/
Free Software Activist     FSFLA co-founder     GNU Toolchain Engineer
Learn the truth about Richard Stallman at https://stallmansupport.org/


More information about the Libc-alpha mailing list