Working together and gaining trust

Siddhesh Poyarekar siddhesh@gotplt.org
Wed Feb 18 16:58:05 GMT 2026


On 2026-02-18 05:34, Alexandre Oliva wrote:
> On Feb 17, 2026, Siddhesh Poyarekar <siddhesh@gotplt.org> wrote:
> 
>> The use of FOSS for all services we use is condition 0 for us
> 
> Does that notion of FOSS exclude SaaSS, that renders software non-free
> for the user that matters, or is that a way to weasel out of Free
> Software principles while pretending to be in line with them?

The trouble with including SaaSS unconditionally is that by nature the 
potential threats posed by SaaSS are more dependent on the parties 
involved and the perceived intent than straight up Free Software 
deployment.  That is why I requested that you build up an argument for 
that if/when we decide to adopt a service (e.g. a forge) that can 
potentially be a SaaSS threat.

>> I don't see any conflicts with our Free Software
>> principles in this.
> 
> You may be right about this limited set of services.
> 
>> As for SaaSS, your definition keeps changing around based on who the
>> parties involved are,
> 
> Now, let's not be dishonest, please.
> 
> The definition has been set in stone for far more than a decade.

The core idea of SaaSS may well be, but the idea itself in practice 
greatly depends on a number of factors involved as you've seen yourself 
in the discussions you've had in this thread.

> The difference you may be observing is in the commitment each party
> displays to actual user freedom.

The difference I observe is the varying standards applied to definition 
of user freedom commitment based on the parties involved and also how it 
varies based on the service involved.  It is inherent to the definition 
of SaaSS, which is why it's a task to consider each service (and take 
pains to make observations party-independent so as to not introduce 
personal biases) and not make a blanket statement about it.  This is 
also why your perception of SaaSS w.r.t. involved services and parties 
may not align with others'.

To repeat my request, please work out a SaaSS argument for a forge, 
independent of a vendor (e.g. what if the FSF gets a generous donor to 
host a forge and as a result the FSF is able to provide those services 
to GNU software?) so that we actually have concrete steps to meet if we 
ever decide to use a forge in glibc, like we have with the GNU Ethical 
Repository Criteria.  Maybe it could be an addendum to the GNU Ethical 
Repository Criteria.

Thanks,
Sid


More information about the Libc-alpha mailing list