Working together and gaining trust
Mark Wielaard
mark@klomp.org
Thu Mar 12 11:55:03 GMT 2026
Hi all,
On Fri, Mar 06, 2026 at 04:56:17PM -0500, Carlos O'Donell wrote:
> On 3/6/26 8:17 AM, Mark Wielaard via Overseers wrote:
> >So the discussion is completely different from five years ago.
> >Ironically Sourceware became so "professional" that some people are
> >now apparently seeing it as "the other" that might control their
> >compute. But in reality the Sourceware PLC, overseers and admins are
> >still just members of the various hosted projects working on our
> >infrastructure together.
>
> Even if Sourceware is different from where it was five years ago, and
> that's good, it still does not meet the requirements for security,
> robustness, isolation and sustainability that the GNU Toolchain or
> glibc need.
So lets build on those improvements and see how we get there together.
And lets make sure those requirements are captured in our plans
https://sourceware.org/sourceware-security-vision.html#plans
so that we keep improving on those issues in a sustainable way.
> >This is 5 years ago, so we might misremember the timeline or what was
> >known to who. All I can say is that I don't remember involving the LF
> >IT really had been part of any of the discussions. And even if I knew
> >I wouldn't be against that because I know Konstantine and would have
> >liked the resources to hire him and working together. We did discuss
> >setting up Sourceware like kernel.org which also is a non-profit
> >getting sponsorship money through the LF. Which is why we reached out
> >to the SFC to help us with that. And it was actually Carlos that
> >suggested we do that so the community could hold assets and enter into
> >contracts, etc.
>
> You were aware early that I was proposing delegating cores services to
> a paid IT team, and that I have always been recommending LF IT from the
> start given their FOSS alignment.
>
> I advised you at the time to seek out additional sources of funding.
>
> You did that by reaching out to the SFC.
Maybe I misremember your preference to do that specifically through
the LF IT, sorry. I believe hiring paid IT staff can be done in
various ways. The main point was that we agreed that even if we could
get corporate funding through the LF as a trade orginization and hire
paid IT staff we would still need community oversight through a public
charity, which you pointed out is how kernel.org is setup, and to
manage the assets and contracts. Secondary it was about long term
continuity, we wanted to setup something that would provide the
Sourceware communities with infrastructure they could trust for the
next 25 years without relying on just corporate goodwill. Funding
certainly is more stable and sustainable having not just corporate
sponsors but also being able to rely on grants and community
donations.
> >Same with the public resource estimates, technical plans and
> >presenting about the infrastructure services at Cauldron. We wanted to
> >let potential sponsors know what the community needed and were working
> >on. We just wanted to make sure that we had the organization and
> >community setup to start working with more corporate sponsors if they
> >would show up. Which I thought the LF plan was all about. So it
> >certainly wasn't against that. The idea was for us to work together
> >not against.
>
> I agree we should work together.
>
> What does that look like to you going forward?
Hopefully we could start public requirements discussions through this
overseers and project specific mailinglists and other public
communication channels the Sourceware Project Leadership Committee
setup https://sourceware.org/mission.html#organization
I must admit I don't realy know what to do about these CTI
proclamations you seem to sent out every 9 to 15 months. Like the one
that started this thread. I really dislike that style of communication.
> >>>>>Which is why it is so important that before this CTI plan proceeds the
> >>>>>FSF as the original fund raising organization for the GNU Toolchain
> >>>>>signs off on it and makes sure that a clear charter and board that
> >>>>>works in the interest of the community and guarantees the money is
> >>>>>spend on Free Software.
> >>>>
> >>>>Nope, you're just inventing new governance rules now and creating
> >>>>friction where none exists.
> >>>
> >>>I am not inventing, the friction is already there. The FSF has real
> >>>issues with this idea [3]. And given that the FSF is legally the
> >>>steward of the GNU Toolchain it is only professional for the LF to
> >>>discuss with the FSF if they want to take over some of that to make
> >>>sure they align on the goals.
> >>
> >>I'm referring to your claim of needing a signoff from the FSF; I
> >>don't think we need any such signoff since we satisfied their demand
> >>of not calling it GNU Toolchain Infrastructure.
> >
> >I don't know if just changing the name suddenly makes it legitimate. I
> >guess the FSF and the LF will have to have a talk about the conditions
> >that would make it so.
>
> You have twice called into question the legitimacy of the GNU Project
> to make decisions on both this mailing list and on the GCC mailing
> list and both times you've been told you are not correct.
I think you are confusing how foundation staff/board work together
with how projects make decissions through a consensus process.
> For reference:
> https://inbox.sourceware.org/gcc/20250616165940.GS30295@gate.crashing.org/
> https://inbox.sourceware.org/libc-alpha/c9ae9bf3-5f18-4493-8367-d613818ec916@redhat.com/
>
> In this case you are also incorrect.
It is never incorrect to support someones idea for a process
improvement if the current process seems stuck or broken. Sometimes
you conclude, collectively, the process can be fixed in a different
way, other times you conclude a change is necessary. That is simply
trying to find community concensus on how we work together. What would
be wrong is to not find a majority for your proposal, having sustained
opposition, and still insisting your proposal will be executed as is.
> >But my main point really is that as a project we shouldn't just ignore
> >the FSF or do things they clearly don't agree with. We have a good
> >working relation now with the FSF and the FSF tech team, they have
> >paid staff which provides various services for some of our hosted
> >projects. Lets work together with them. If they point out issues that
> >concern them then lets make sure we address them together. We aren't
> >adversaries, we all just want to advance Free Software.
>
> I agree we all want to advance Free Software.
>
> We started conversations with the FSF very early to understand the
> foundations position on this topic.
>
> I'll continue to engage with the FSF and the GNU Project.
Lets make sure we do.
> >>I think we've addressed all concerns other than the "I don't like
> >>the LF", which I don't think we can address. The best we can do is
> >>invoke our personal currency in the community as individuals in the
> >>TAC and say that we will ensure that if we're made aware of anything
> >>that goes against the principles of our community (which implicitly
> >>includes Free Software principles) we will do whatever it takes to
> >>remedy that, including moving infrastructure out if needed.
> >
> >The best you could do is fix the charter and board requirements. It is
> >the shaky governance that people don't like. The charter doesn't even
> >talk about Free Software. The board just seems to be about who pays
> >most and then even decides who may "advise" them. Why not add some
> >guardrails to the charter by describing what raised money may be used
> >for. Make sure the board has at least the FSF as a member. It doesn't
> >have to rely on just "personal currency", you can just put down things
> >in writing you agree on.
>
> In general "people" trust the GNU Toolchain leadership to negotiate,
> like we have, for the last 30 years, to have sponsors that are aligned
> with the mission and vision of the GNU Project and support the use of
> FOSS.
And we should thank those individuals who did that in the past. But
when you setup an organization to help with that, then it does make
sense to write that down. So it isn't just the burden of specific
people to guard it, but a collective mission and vision (executed by
the paid staff of the organization).
> Is the CTI charter the biggest concern you have today?
It certainly starts with the proposed charter.
> >But also the LF and OpenSSF could just work directly with the FSF,
> >SFC, Sourceware and the project community so we can improve the
> >infrastructure together.
>
> This is a false dichotomy.
It isn't meant to be a division into two especially mutually exclusive
or contradictory groups or parts (sorry, I had to lookup the
definition of dichotomy). Precisely the opposite. It wasn't always
easy for the FSF/GNU, Sourceware and the SFC to work together, but we
made it work. Now when adding the LF/OpenSSF to the mix lets make sure
there aren't any trust issues between them by making them try to work
directly with each other first. So they can coordinate who does what
and why.
Cheers,
Mark
More information about the Libc-alpha
mailing list