Live data from Hacker News

Sourcehut will blacklist the Go module mirror

sourcehut.org

261–270 of 365 posts

Re: Sourcehut will blacklist the Go module mirror

#261

Earlier quoted context omitted.

Do you really imagine some significant number of Google's search, cloud, etc customers were driven to Google over a competitor because of "good vibes" derived from Go? Google only develops Go because it's a useful internal tool, and I'm pretty sure the marketing team nor the executives spend any meeting minutes discussing Go.

Marketing works in mysterious ways. Yes, I do imagine that people who are really into Go are more likely than average to join or start Go shops, and then pick GCP over competitors because they have to start with something, and being Go people, Google stuff comes first to mind. Lots of companies across lots of industries spend a lot of money to achieve more-less this fuzzy, delayed-action effect.

> Yes, I do imagine that people who are really into Go are more likely than average to join or start Go shops, and then pick GCP over competitors because they have to start with something, and being Go people, Google stuff comes first to mind.

How many such people do you imagine there are? I'm active in the Go community, and I've been a cloud developer for the better part of a decade. It's never occurred to me to pick GCP over AWS because Google develops Go, nor have I ever heard anyone else espouse this temptation. I certainly can't imagine there are so many people out there for whom this is true that it recoups the cost that Google incurs developing Go.

Rather, I'm nearly certain that Google's value proposition RE Go is that developing and operating Go applications is marginally lower cost than for other languages, but that at Google's scale that "marginally lower cost" still dwarfs the cost of Google's sponsorship of the Go language.

Re: Sourcehut will blacklist the Go module mirror

#262
post #209

The Go team has been making progress toward a complete fix to this problem. Go 1.19 added "go mod download -reuse", which lets it be told about the previous download result including the Git commit refs involved and their hashes. If the relevant parts of the server's advertised ref list is unchanged since the previous download, then the refresh will do nothing more than the ref list, which is very cheap. The proxy.go…

Why does the Go team and/or Google think that it's acceptable to not respect robots.txt and instead DDoS git repositories by default, unless they get put on a list of "special case[s] to disable background refreshes"? Why was the author of the post banned without notice from the Go issue tracker, removing what is apparently the only way to get on this list aside from emailing you directly? Do you, personally, find an…

Why should a git client respect an http standard such as robots.txt?

Re: Sourcehut will blacklist the Go module mirror

#263
post #262

Earlier quoted context omitted.

Why does the Go team and/or Google think that it's acceptable to not respect robots.txt and instead DDoS git repositories by default, unless they get put on a list of "special case[s] to disable background refreshes"? Why was the author of the post banned without notice from the Go issue tracker, removing what is apparently the only way to get on this list aside from emailing you directly? Do you, personally, find an…

Why should a git client respect an http standard such as robots.txt?

Read the OP; it's obvious based on the references to robots.txt, the User-Agent header, returning a 429 response, etc, that most (all?) of Google's requests are doing git clones over http(s).

Re: Sourcehut will blacklist the Go module mirror

#264
post #256

Earlier quoted context omitted.

Thanks for the insight, Russ. Would you comment on what the potential consequences of opting out of background refreshes would be? Could there be any adverse effects for users?

Opting out of background refreshes would mean that fetching a module version that (1) no one else had fetched in a few days and (2) does not use a recognized open-source license might not be in the cache, which would make 'go get' take a little extra time while the proxy fetched it on demand. The amount of time would depend on the size of the repo, of course. The background refresh is meant to prefetch for that situa…

Some people today raised concerns about disabling background refreshes (the temporary workaround originally suggested by the Go team) as having possibly unacceptable resulting performance for end users...

...but it sounds like disabling background refreshes would have strictly better end-user performance than what the Sourcehut team had been planning as described in their blog post today (GOPRIVATE and whatnot)?

Re: Sourcehut will blacklist the Go module mirror

#265
post #262

Earlier quoted context omitted.

Why does the Go team and/or Google think that it's acceptable to not respect robots.txt and instead DDoS git repositories by default, unless they get put on a list of "special case[s] to disable background refreshes"? Why was the author of the post banned without notice from the Go issue tracker, removing what is apparently the only way to get on this list aside from emailing you directly? Do you, personally, find an…

Why should a git client respect an http standard such as robots.txt?

Google began pushing for it to become an Internet standard—explicitly to be applicable to any URI-driven Internet system, not just the Web—in 2019, and it was adopted as an Internet standard in 2022.

https://developers.google.com/search/blog/2019/07/rep-id

Re: Sourcehut will blacklist the Go module mirror

#266
post #262

Earlier quoted context omitted.

Why does the Go team and/or Google think that it's acceptable to not respect robots.txt and instead DDoS git repositories by default, unless they get put on a list of "special case[s] to disable background refreshes"? Why was the author of the post banned without notice from the Go issue tracker, removing what is apparently the only way to get on this list aside from emailing you directly? Do you, personally, find an…

Why should a git client respect an http standard such as robots.txt?

Because it uses HTTP.

Re: Sourcehut will blacklist the Go module mirror

#267

Earlier quoted context omitted.

> I was also taken aback when Peter Bourgon, a great programmer and contributor to the go ecosystem was banned from all go channels. Bourgon was frequently helpful and great, but also frequently rude, condensing, dismissive, and generally just unpleasant. I've seen this countless of times first-hand on Slack, Reddit, and Lobsters. I specifically stopped interacting with him long before he was banned. Whether he's a g…

> Whether he's a great programmer/contributor not isn't really important here. Why not? Why shouldn't we offer more leeway to more valuable contributors?

Why shouldn't better drivers get to ignore speed limits?

Re: Sourcehut will blacklist the Go module mirror

#268

Earlier quoted context omitted.

Here's some evidence: https://news.ycombinator.com/item?id=3803568 https://news.ycombinator.com/item?id=15066518 https://news.ycombinator.com/item?id=19124324 https://news.ycombinator.com/item?id=20826618 https://news.ycombinator.com/item?id=20841586 https://news.ycombinator.com/item?id=21247759 https://news.ycombinator.com/item?id=24791357 https://news.ycombinator.com/item?id=24965432 https://news.ycombinator.com/it…

None of that bears any relation to what happens in the Go community. Google is not a monolithic entity. The Go team operates pretty much independently from gmail and other stuff. Yes, there is a problem with Google randomly disabling accounts, but this doesn't really extend to Go, who make their own decisions on who to ban or not, and which are all manual. Just as you can comment on, say, github.com/facebook/zstd wit…

> Google is not a monolithic entity.

It is, and claiming that a single corporate entity cannot manage itself isn't an excuse, it's an admission of further guilt.

Re: Sourcehut will blacklist the Go module mirror

#269
post #125

Earlier quoted context omitted.

“Good engineering” would be to meticulously develop and standardize a replacement before idealistically purging the world of alleged “bad software”. Since this endeavor has yet to be undertaken, PGP it is. Good engineers understand this reality. Look, you can make solid arguments till you are blue in the face about why PGP is unclean and unfit for modern cryptography. And you can be 100% right. But that doesn't mean…

> rip it out of existence Come the fuck off this "mature personality" shit if you're going to write like this. He proposed freezing a module no one wanted to maintain in a library specifically meant to host stuff with weaker compat guarantees, he didn't hop in a DeLorean and kill Zimmermann's grandpa. Meanwhile, the critical project Drew insisted he keep it for is... deprecated and unmaintained!

[flagged]

Re: Sourcehut will blacklist the Go module mirror

#270

I'll just rehost my git repos on a git host who doesn't mind actually doing their job as a git host by letting git clients clone git repos.

What does your ideal git host do when one of its (non-paying) clients uses bots to clones repos so hard that its (paying) human clients are unable to clone their repos?

Improve infrastructure. Apparently they are trivially DDOSable by anyone renting a few servers and running git clone in a loop? That's a problem they should solve. And no, blocking by user agent is not adequate protection.
Post reply on HN