Meeting Minutes - Office Hours for CTI - 2026-08-28
Zack Weinberg
zack@owlfolio.org
Thu Sep 10 22:47:27 GMT 2026
On Thu, Sep 10, 2026, at 6:02 PM, Siddhesh Poyarekar wrote:
> Does blocking https for git clones count as a critical service failure?
> This had happened some months ago in an attempt (IIRC) to counter AI
> scraper bots. The change was not reverted for a while, arguing that
> git:// was good enough but eventually it was, I don't remember the final
> justification for it all.
Oh, for sure. Loss of anonymous https-based access to the main git server
means anyone with no SSH account, stuck behind a restrictive outbound firewall,
can't clone or pull, so that's going to be a big deal for a lot of people.
And the logic of the change doesn't hold up; I've heard any number of
reports that the bots don't even *try* to clone, they just beat on gitweb.
So now we're actually getting somewhere maybe. This is a concrete example
of a critical service failure on sourceware that would have been prevented
by more disciplined change management procedures. However, disciplined
change management is something volunteer and paid sysadmin staff can do
equally well, so this reduces to a question of how diligent each group
of people is, and in the long run *that's* a matter of organizational
continuity and commitment to self-improvement.
Siddhesh: Can you reach out to your contacts at LF and ask them to summarize
their procedures for change management? Can you also please ask them to
summarize their procedures for *what they do when something goes wrong*,
and to share at least one post-mortem analysis of something that *did*
go wrong, how it was dealt with, and what was done to prevent a similar
failure?
Mark: Same questions for the overseers; additionally, if you know anything
about this specific incident, can you explain what happened from your perspective?
zw
More information about the Libc-alpha
mailing list