• Em Adespoton
    link
    fedilink
    3923 days ago

    They haven’t been removed from the community though — just the maintainers list. Now they need someone else’s review to commit code to the kernel.

    Personally, I think even maintainers should be required to have that — you can be the committer for pre-reviewed code from others, but not just be able to check anything you want in, no matter your reputation (even if you’re Linus). That way a security breach is less likely to cause havoc.

    • Ephera
      link
      fedilink
      1022 days ago

      I find that difficult. Aside from code reviews, often times your job as a maintainer is:

      • getting a refactor or code cleanup in while everyone’s asleep
      • shuffling commits around between branches
      • fixing the CI toolchain
      • rolling back or repairing a broken change
      • unfucking the repo
      • fixing a security vulnerability

      A required review slows all of these tasks to a crawl. I do agree that the kernel is important enough that it might be worth the trade-off.
      But at the same, I do not feel like I could do my (non-kernel) maintainer job without direct commit access…

      • Em Adespoton
        link
        fedilink
        4
        edit-2
        22 days ago

        I feel your pain. I have maintainer roles for a few projects where things could be slowed down by a week or more if I didn’t have direct commit access. And I do use that access to make things run faster and smoother, and am able to step in and just get something fixed up and committed while everyone else is asleep. But. For security critical code paths, I’ve come to realize that much like Debian, sometimes slow and secure IS better, even if it doesn’t feel like it in the moment (like when you’re trying to commit and deploy a critical security patch already being exploited in the wild, and NOBODY is around to do the review, or there’s something upstream that needs to be fixed before your job can go out).

  • @jaybone
    link
    2322 days ago

    It’s like exactly what I said they would do after the original news of the bans from the other day. And I got downvoted for it. Lol

    • @OwlPaste
      link
      English
      10
      edit-2
      22 days ago

      Will we finally get the “Putinix” distribution that mines cryptocurrency for the regime by default? It will have to be a new coin called “RuOil”

    • @[email protected]
      link
      fedilink
      622 days ago

      Especially, because they can chose existing names as there is no Copyright in Russia (afaik, probably a wrong myth but idk)

      • @OwlPaste
        link
        English
        322 days ago

        No there was copyright, it was only relatively enforced between 2000-2015 ish. And then probably only in tourist heavy areas. In the olden days you could find any soft on “black markets” in open stalls

    • monk
      link
      fedilink
      115 days ago

      They already have a dozen, they all suck.

  • Fontasia
    link
    fedilink
    320 days ago

    Sounds like a pretty average day in the Linux community

    • @[email protected]
      link
      fedilink
      922 days ago

      At first I thought you meant it’d be a bad fork, but then I realise you meant it’d be a bad fork.

      As long as it’s open source and vetted by the public, I don’t see how it could go bad tbh

      • @Zangoose
        link
        -121 days ago

        It won’t be open source. Who’s gonna sue Russia for license violation?

        • @[email protected]
          link
          fedilink
          521 days ago

          then it wont be linux, but a shittily maintained private copy that will fall out of disuse quickly unless they merge all upstream changes without too much oversight (in which case, why bother?) to keep feature parity

          • @Zangoose
            link
            2
            edit-2
            21 days ago

            You’re not wrong but it’s not like it’s unprecedented. North Korea already does this with Red Star OS. It’s just Linux with a bunch of spyware and government tracking/surveillance on top (edit: it’s also definitely not open source)

    • Dessalines
      link
      fedilink
      421 days ago

      For sure, stuxnet is just the beginning, who knows what the US will subject the world to next.