Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

341–350 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#341
post #176

I think the idea this was HUMINT operation by a state sponsored intelligence service is more likely. The twitter thread here was interesting. https://x.com/thegrugq/status/1774392858101039419 Raging about these being inconsiderate people, when they were likely fictional personalities that were part of a long con seems to be a bit foolish to me.

this is going to be impossible to prove or disprove, but given the state-sponsored nature of the attack (which seems fairly likely at this point)... I also wonder if maybe there wasn't some tips pushing Andreas Freund down the path of discovering it too.

like let's say you're the NSA and you know Russia (/china/etc) is trying to do this backdoor. maybe you send Freund an email through one of your cutouts and say hey, I've been looking at the ubuntu RCs and we noticed some performance regression in the postgres tests, etc... do it from some corpo email from a "friend" at some bigtech company that legitimately uses postgres/ubuntu and it's completely 100% deniable and innocuous.

it'd be interesting to see correspondence to/from Freund on his mailing lists too, see if there was anyone that (in retrospect) might have been tipping him down the path of discovery too.

(which is not to diminish in any way what he did... chasing a tiny perf regression in core library functionality back to root-cause is no mean feat. especially when it's code that is actively trying to evade detection - watching for debuggers, etc. Although that heisenbug nature might have also made it more compelling to these sorts of people ;)

Re: Xz: A microcosm of the interactions in open source projects

#342

Earlier quoted context omitted.

> In real life volunteering you don’t get random drive-by input from outsiders. Sure you do: everyone likes to comment on whether your volunteering work is an effective use of time and resources or not.

Not in my experience. People don’t complain about people doing pro-social volunteer work (IME).

I see a lot of people complaining about e.g. working on saving "some stupid animal" instead of solving hunger or similar.

Re: Xz: A microcosm of the interactions in open source projects

#343

Earlier quoted context omitted.

What happens here is inevitably someone puts up $5 and harasses the maintainer for not taking the bounty.

They already do while putting up $0. Nothing really changes there. Also, maybe money should be refunded if maintainer does not accept in a reasonable time after funding goal is reached. Maintainer can always reject sooner. Maintainer has final word.

People feel a lot more justified to harass maintainers if they offer money, and do not usually understand that a small token amount is not really worth taking :(

Re: Xz: A microcosm of the interactions in open source projects

#344
post #279

Earlier quoted context omitted.

The conversation is about trust in software systems, not some code of conduct grievance you want to wedge in here.

as I wrote originally, trust implies discernment which contradicts egalitarianism. Most codes of conduct take egalitarianism for granted. If one does not treat all comers equally, one will eventually be accused of violating someone’s code of conduct. In my book, software quality is much more important than emotions.

I agree that codes of conduct generally promote egalitarianism. I like egalitarianism. I disagree that means that you just have to take everything that anyone throws at you. That's an absurd claim that I'm happy to leave here without further argument, for any readers to make up their minds on.

Re: Xz: A microcosm of the interactions in open source projects

#345
post #344

Earlier quoted context omitted.

as I wrote originally, trust implies discernment which contradicts egalitarianism. Most codes of conduct take egalitarianism for granted. If one does not treat all comers equally, one will eventually be accused of violating someone’s code of conduct. In my book, software quality is much more important than emotions.

I agree that codes of conduct generally promote egalitarianism. I like egalitarianism. I disagree that means that you just have to take everything that anyone throws at you. That's an absurd claim that I'm happy to leave here without further argument, for any readers to make up their minds on.

Software can be judged according to many paramters: runtime performance, correctness, size. In many cases, there is a software which ranks the highest on all parameters. Often this software is the product of one mind.

Because the highest ranked software can be copied everywhere, and because an individual tends to author it, the endeavor of publishing the best software possible tends to contradict the assumption that all people are capable of providing a highly ranked solution.

Re: Xz: A microcosm of the interactions in open source projects

#346
post #31

I do sometimes wonder if by trying to be "nice" to users and try to see the best intentions of commenters, many developers waste huge amounts of mental energy. For context, I've really only worked on "fun" side projects, namely emulators and game remakes, where I've explicitly avoided any mention of donations or similar. Both as it's intended to be a distraction from my job, not become part of it. And generally avoid…

> But it's expected to have a "community" for all such projects, and not exclude non-direct contributors.

By whom? You don't have to accept such expecteations - plenty of projects that just throw code over the wall and do fine.

Re: Xz: A microcosm of the interactions in open source projects

#347
post #247

Earlier quoted context omitted.

My layperson’s opinion is that anything to do with gaming is particularly riddled with people that interact poorly with maintainers. Again, purely my opinion: gamer culture invites a particular sort of Dunning-Kruger-prone ‘power user’ type. Every gamer community carries with it a corpus of baseless, fictitious, technical information. “The developers didn’t do this because x”, “it’s ridiculous that they didn’t just y…

My favorite know-nothing gamer meme these days is "bad optimization". What they mean is that the performance is worse than what they would expect (?) on a given hardware configuration and game settings. They haven't poked around with RenderDoc, they don't have the debug symbols to profile the CPU code, they have zero idea what kind of work the software needs to do, they simply know the lazy devs have failed to "optim…

You say this as if any game is actually as optimized as it could be which if you know anything about game development is an absurd assertion. Games are throwaway software programmed under strict deadlines. "Good enough" is the natural result of that. And yes, I have traced games' GPU and library usage due to bugs and performance issues. It's never a question if performance could be introduced but always just a question of how much effort/time it would take.

Re: Xz: A microcosm of the interactions in open source projects

#348

Earlier quoted context omitted.

> "Mauro, your response is completely unbecoming for a Linux kernel maintainer, and is not in line with the promise of not breaking userspace." This is just PC corporate speak. Linus is an actual human being who says what he really means.

I'm assuming the apology[1] from Linus must have come off on complaints raised to the HR department of companies with active contributions to the Linux kernel. Because this was Linus, this went over relatively smoothly for him, but for another person, this may not have been the case. There is also no telling if the person is interacting in good faith and just doesn't know, in which case the aggression is a bit rude.…

No the apology is just Linus prioritizing the relationship with his daughter over being a slightly more effective maintainer.

Re: Xz: A microcosm of the interactions in open source projects

#349

Earlier quoted context omitted.

The points you make aren't unreasonable. It is necessary to establish clear boundaries of what can and can't be provided by the maintainers. If not done at an earlier stage of the project, the support burden becomes too much to bear at which point the maintainer transfers ownership, and the project suffers from catastrophic consequences such as the xz backdoor we're talking about here, or other cases where the projec…

> "Mauro, your response is completely unbecoming for a Linux kernel maintainer, and is not in line with the promise of not breaking userspace." This is just PC corporate speak. Linus is an actual human being who says what he really means.

Agreed. This is the real power of corporate newspeak - eventually ordinary people will see it as the normal way to communicate and go along with the clownshow without even being beholden to any HR department.

Re: Xz: A microcosm of the interactions in open source projects

#350

Earlier quoted context omitted.

I'm reminded of this recent post about the Redis fork to be maintained by Drew Devault: https://andrewkelley.me/post/redis-renamed-to-redict.html > Redict is a Finished Product > Drew is a controversial person (he's been rude/mean in the past) xz should be pretty much finished as well, major overhauls like the "ifunc" feature to inject alternate function implementations are not really justified. Beware of busybodies…

xz sees continual improvement to e.g. make it faster. ifuncs are an important part of that. If you want to use the garbage slow version of xz that’s up to you but I don’t think most people would want this.

> xz sees continual improvement to e.g. make it faster.

Yes, that makes sense.

> ifuncs are an important part of that.

No, IFUNCs have absolutely zero performance benefit over regular function pointers for internal functions. If anything, they can limit optimization oppertunities the compiler has with other approaches. The only benefit IFUNCs bring is being able to avoid another indirection when replacing already exported library functions in their entirety. That's what they are there for - different optimized implementations for things like memcpy in glibc.

Post reply on HN