CTI - Making a decision for glibc.
Andrew Pinski
pinskia@gmail.com
Wed Jan 28 17:02:33 GMT 2026
On Tue, Jan 27, 2026 at 8:16 AM Carlos O'Donell <carlos@redhat.com> wrote:
>
> tl;dr The GNU Maintainers for the GNU C Library (glibc) plan to move
> core services to infrastructure hosted by the Core Toolchain
> Infrastructure (CTI) project. As maintainers for the project we do this
> to meet the present and future needs of glibc and the GNU Toolchain. We
> want secure, robust, and sustainable infrastructure, balanced against
> the needs of developers and the community to collaborate and innovate,
> with reliable funding to support the infrastructure in the long term.
Coming back to this with a less frusted mind. I have to say this still
seems forced.
Especially with the following statement on your own projects page for 2025:
`As of 2025-08-11 moving to new infrastructure is on hold as we
discuss the core reasons for the migration.`.
The second thing is the reasons to move are quoted as "to move to an
enterprise based IT service". Does that mean all communication to the
support team will have to go through a ticket and there is no longer
any informal path at getting support for when hosting services and/or
network are broken? What if you can't get into the issue tracker? Also
who will get access to this issue tracker and be able to direct/steer
the issues? This piece seems to be very much missing from all of this
discussions.
Do you need to join the CTI and donate to get steer the direction? Or
is being part of the overall community enough?
There also does NOT seem to be a full thought out plan on which parts
and when will be the transition, rather this is just a statement again
on plan to do it. The FAQ on CTI does not answer this question either.
The frustrating parts is not just about LF IT but the way this whole
thing was handled and the messaging is happening. Especially when your
own FAQ and the messages from previous discussion seems to counter
this email.
Looking at the meeting minutes of CTI meetings, there was a few things
which seems to have done counter this email even.
October 29, 2025
(https://lore.kernel.org/cti-tac/efca566d-6826-44d5-a599-240e0d1353d1@redhat.com/):
* Discussed the GNU Tools Cauldron 2025 glibc BoF discussion and the
use of CTI hardware.
First off that discussion finished off with we should discuss more on
the mailing list. And the slide from BoF mentioned CTI but there was
no discussion in the BoF itself (I watched the video over again)
rather Carlos deflected Mark's question.
* Carlos to post to the glibc mailing list to raise infrastructure move again.
Is that what this email is? This seems a heavy handed way of raising it.
November 26, 2025:
* Discussed if we had enough material discussions for weekly updates?
* Yes, with enough material each week we can make the transition.
Huh? There has been no weekly updates at all to the glibc mailing list.
* Noted that we need to continue to update the community, not every
quarter, but more frequently including weekly updates on CTI progress
to show the project continues to move forward.
This is the most frustrating part it was mentioned in your own meeting
you need to do weekly update but then nothing is done. It is exactly
why we are partly frusted here.
* Suggest collaboration with Sourceware on specific projects?
* Fold it into the main conversation?
* Publicly invite Mark to have a role.
Why was the invite to Mark not done before this email push?
* Carlos to post to the glibc mailing list to raise infrastructure move again.
I see this was again a todo list but again this was just to raise the
issue rather than say "we are moving".
Thanks,
Andrew Pinski
>
> In 2019 leadership from the GNU Toolchain started down a path that led
> to the Core Toolchain Infrastructure project. The project aims to move
> toolchain infrastructure issues forward; to provide a sustainable path
> forward for secure and state of the art infrastructure.
>
> Post-pandemic, since 2022 the GNU Toolchain has continued to move
> forward the state of the current infrastructure by engaging the
> developers, the projects, and a wider set of sponsors that can
> support a sustainable path forward for the toolchain.
>
> Key achievements:
>
> 2022 - Started using infrastructure provided by CTI like BigBlueButton
> for meetings for the GNU Toolchain e.g. Weekly glibc patch
> queue review and Monthly Office hours in two timezones.
>
> 2023 - Service enumeration for GNU Toolchain projects (gcc, glibc,
> binutils, gdb).
>
> 2024 - Completed pricing and service contract negotiation for migration
> with LF IT.
>
> 2025 - Completed GNU Toolchain and glibc documents to define secure
> development requirements and the infrastructure needs.
>
> These steps were a necessary evolution and resulted in several critical
> milestones, e.g., service enumeration, secure development documents;
> which collectively paved the way for a sustainable path forward.
>
> While it was clear to the GNU Toolchain leadership that requirements
> were coming to improve the toolchain cyber-security posture, these
> requirements were not clear to all project developers. As part of
> receiving this feedback we have worked to document and define a secure
> development policy for glibc and at a higher level the GNU Toolchain.
> While Sourceware has started making some critical technical changes, the
> GNU Toolchain still faces serious, systemic concerns about securing a
> global, highly available service and building a sustainable, diverse
> sponsorship model. At the same time we are freeing up the GNU Toolchain
> developers and volunteers to focus on next-generation work, such as
> Sourceware’s post-commit CI and Forge-based workflows.
>
> The decision to leverage CTI and LF IT is the direct result of seeking a
> comprehensive, long-term solution to these exact challenges, expanding
> our sponsorship base and leveraging existing sponsors like the OpenSSF.
> The CTI TAC’s proposal to use Linux Foundation IT is rooted in the fact
> that they are an existing team in the industry that implements very
> similar functionality for the Linux kernel. The proposal directly
> benefits glibc developers. By partnering with a team that develops and
> understands FOSS tooling (b4, grokmirror and patatt) and large-scale
> kernel infrastructure. This partnership ensures our core infrastructure
> is secure and scalable.
>
> This sustainable path forward for glibc includes:
>
> * A global robust and secure mirrored git repository for public clones
> that supports robust CI/CD workflows for developers and downstream
> distributions.
>
> * A global robust and scalable email system leveraging existing
> production deployments and reputation i.e. subspace.kernel.org.
>
> * A continuous process of review for project requirements, FOSS usage,
> security policy, and cost.
>
> * A sustainable funding model for the infrastructure including a
> diverse collection of sponsors to support various infrastructure
> requirements now and in the future.
>
> While consensus for the move among GNU Maintainers for glibc is not
> unanimous, most of the maintainers endorse the move, and key developers
> have expressed their support in the upstream discussions. Additionally
> CTI has received a lot of feedback over the last 3 years as the project
> worked on infrastructure, and we include some of that feedback here and
> in our CTI FAQ [1] with comments.
>
> Some members of the community have expressed disappointment that funding
> would go to the Linux Foundation. Some members of the community have
> expressed concern that a board structure would allow corporate
> influence. Neither of these concerns are new and exist today with Red
> Hat and IBM, both being for-profit corporate entities. The GNU Toolchain
> leadership has a 30+ year history of successfully navigating the
> dynamics of working with sponsors and providing FOSS solutions,
> including meeting the GNU Ethical Repository hosting criteria.
>
> We invite all members of the glibc and GNU Toolchain community to join
> us in this important transition. Your insights, contributions, and
> feedback are essential to making CTI infrastructure a success that
> benefits everyone. Let's work together to build a more secure and
> sustainable future — reach out on libc-alpha@sourceware.org, participate
> in the weekly office hours, or propose ways to get involved. Let's
> collaborate to build a more resilient and sustainable infrastructure
> foundation for the GNU Toolchain.
>
> Action plan:
>
> * Weekly office hours for CTI to provide an open space for discussion
> of infrastructure improvements
>
> * Work with LF IT to update the CY24 statement of work and discuss with
> the glibc developers
>
> * Work towards migrating glibc git and mailing lists as first priority
> since these match our security priorities.
>
> Cheers,
> Carlos O’Donell
> GNU Maintainer for glibc
> Core Toolchain Infrastructure Project TAC member
> [1] https://cti.coretoolchain.dev/faq/index.html
>
More information about the Libc-alpha
mailing list