A recent comment indicates that this outcome was more like a mistake and less line the skulduggery that the title indicates. Public shaming might be a good tool for this kind of thing in general but maybe in this case it was premature.
Also let's please be careful about creating situations that pressure a maintainer to merge a PR before they're fully comfortable with it. That's how ssh got backdoored via xz (no reason to believe that that's what's happening here). If somebody wants to embrace YOLO with their $$ project and be a bit more cautious with their OSS project, that's ok.
Gitea blocks PR from community, charging $$ for open-source contributions
61–70 of 87 posts
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#62The title is sensationalized. I read the whole thread. Gitea doesn't seem to be "blocking" the PR. They aren't preventing it from going in a release. However, they did pull the in-progress PR into their private repo early, presumably in order to make more money. Not great, but not bad faith. "Blocking" would suggest to me that the PR is rejected but still ends up in the closed-source codebase, which isn't the case at…
That is literally in bad faith.
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#63Earlier quoted context omitted.
I don't see how it gives him the right to critique the maintainers over this specific topic and situation. He clearly has no qualms about profiting from their work himself. So why does he have a problem with them profiting from other contributors' work? Gitea's stance regarding why certain features are Enterprise-only is quite reasonable: "Many features, and enhancements are prevented from being included in the Gitea…
If it’s good enough to merge into the enterprise branch, it’s good enough to merge into the community branch. It may be expensive; that’s why there was a community-funded bounty placed on it. If the complaint is that Gitea is too complex to maintain for free, then great, start a company around it to fund a private fork. But then you shouldn’t be allowed to stop the community from merging their own crap in their own f…
It's not clear yet that the Enterprise version of this feature is the same code as this PR, right? Do you have evidence otherwise?
> It may be expensive; that’s why there was a community-funded bounty placed on it.
How much was the bounty, who funded it, and who receives it? I don't see any information about that on the PR or the linked issue.
> you shouldn’t be allowed to stop the community from merging their own crap in their own fork that they maintain
If the community really maintains it 100%, then they would all be maintainers and by definition they would be able to merge it already. That doesn't appear to be the situation here.
> Since Gitea LTD is the gatekeeper of both repos, that is the conflict of interest.
Do you really think it is accurate to say Gitea LTD is merely gatekeeping and not actually doing a ton of work to steer and maintain this project?
And since the complaining commenter is CTO of a company who benefits from being able to include this feature in his company's own private fork, doesn't he have a conflict of interest as well?
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#64Earlier quoted context omitted.
If it’s good enough to merge into the enterprise branch, it’s good enough to merge into the community branch. It may be expensive; that’s why there was a community-funded bounty placed on it. If the complaint is that Gitea is too complex to maintain for free, then great, start a company around it to fund a private fork. But then you shouldn’t be allowed to stop the community from merging their own crap in their own f…
> If it’s good enough to merge into the enterprise branch, it’s good enough to merge into the community branch. It's not clear yet that the Enterprise version of this feature is the same code as this PR, right? Do you have evidence otherwise? > It may be expensive; that’s why there was a community-funded bounty placed on it. How much was the bounty, who funded it, and who receives it? I don't see any information abou…
Absolutely not, and I never made that claim.
> How much was the bounty, who funded it, and who receives it?
I happen to have some inside knowledge here, that at least Allspice and Copia provided parts of the bounty. Some of that is mentioned in the thread but the transparency could be better.
> Do you have evidence otherwise?
That was the thrust of the submission. I tried to link the fragment but I don't think Hacker News allows that and erased it: "Unfortunately, they have already merged a version of this code into the private gitea repo and are charging $$ for it. So Gitea Ltd. (owners group) has no incentive to review and merge this in an open source repo, even though the open source community has funded and developed it."
As for conflicts of interest, perhaps. Who knows the actual extent of it? Posting here is intended a matter of visibility rather than activism; that's why I'm so surprised that the thread was closed on grounds of brigading, since that was neither the intended nor the actual effect.
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#65Earlier quoted context omitted.
If it’s good enough to merge into the enterprise branch, it’s good enough to merge into the community branch. It may be expensive; that’s why there was a community-funded bounty placed on it. If the complaint is that Gitea is too complex to maintain for free, then great, start a company around it to fund a private fork. But then you shouldn’t be allowed to stop the community from merging their own crap in their own f…
> If it’s good enough to merge into the enterprise branch, it’s good enough to merge into the community branch. It's not clear yet that the Enterprise version of this feature is the same code as this PR, right? Do you have evidence otherwise? > It may be expensive; that’s why there was a community-funded bounty placed on it. How much was the bounty, who funded it, and who receives it? I don't see any information abou…
One does not preclude the other.
> And since the complaining commenter is CTO of a company who benefits from being able to include this feature in his company's own private fork, doesn't he have a conflict of interest as well?
He isn't controlling what goes into community repo, so that's irrelevant.
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#66Earlier quoted context omitted.
I'm still very much on the fence about Forgejo. I use it, but I don't trust the maintainers after seeing how they handled dissent in appointment of a moderator, and I wouldn't invest time in contributing to it directly at this stage. I added more details here for the curious: https://news.ycombinator.com/item?id=41489578
That kind of stuff is unavoidable with orgs like this (though tbf I've seen it more with European orgs...). Anywhere there's a group of people, there's a smaller group of people who are power hungry psychopaths. Considering the supposed evidence was deleted, I'm not just going to take your word for it (next time, use archive.org or similar). But either way, I don't care. The software works very well for me, and strok…
I'm relatively confident it was on archive.org and has been purged by the Forgejo team. There's only one entry on archive.org and it's a month after the event.
And I agree—the software works and I use it and I'm less sketched out by Forgejo than I am by Gitea. I'm just explaining why I'm not going to sink anytime into contributing to their project.
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#67Earlier quoted context omitted.
> If it’s good enough to merge into the enterprise branch, it’s good enough to merge into the community branch. It's not clear yet that the Enterprise version of this feature is the same code as this PR, right? Do you have evidence otherwise? > It may be expensive; that’s why there was a community-funded bounty placed on it. How much was the bounty, who funded it, and who receives it? I don't see any information abou…
> Do you really think it is accurate to say Gitea LTD is merely gatekeeping and not actually doing a ton of work to steer and maintain this project? Absolutely not, and I never made that claim. > How much was the bounty, who funded it, and who receives it? I happen to have some inside knowledge here, that at least Allspice and Copia provided parts of the bounty. Some of that is mentioned in the thread but the transpa…
Can you please link to whatever part of this bounty is public? I just expanded searched the PR comments for "bounty" and absolutely nothing came up, and likewise on the issue linked from the PR.
In any case, if the bounty is coming from companies other than Gitea Ltd, and it presumably will be paid to the PR submitter (and not to Gitea Ltd), then how does this bounty help compensate for the massive amount of time Gitea Ltd employees spend on code review and long-term maintenance of this huge PR?
> That was the thrust of the submission. I tried to link the fragment
That quote is an unsubstantiated claim from the commenter making the complaint. It might be accurate or it might not. As a neutral third party I have no way of evaluating that, as no evidence has been presented. Personally, I haven't flagged this thread, but I can absolutely understand why others did so, given the complete lack of any concrete evidence of the main thing being claimed here.
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#68The title is sensationalized. I read the whole thread. Gitea doesn't seem to be "blocking" the PR. They aren't preventing it from going in a release. However, they did pull the in-progress PR into their private repo early, presumably in order to make more money. Not great, but not bad faith. "Blocking" would suggest to me that the PR is rejected but still ends up in the closed-source codebase, which isn't the case at…
Brigading? Well I definitely didn’t intend that, although I also don’t see anyone from here having commented on the thread so I don’t see how that is reality. Stall may have been a better word, although this PR has been crawling along for over a year now, with little response from the maintainers. If something is neglected for long enough it’s topologically equivalent to blocking it.
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#69I wonder what the legality of saying "this PR is available under the MIT license upon being merged into this repo" would be. A PR is copyrighted, and I guess it's just implied that a PR is available under the same license as the main repository, but an explicit PR license could override this (maybe?, IANAL). I suppose they could merge it, copy it under the MIT license, and then remove it, which overall seems kind of…
GitHub's TOS include a clause that says you agree your PRs are under the same license as the project ("license in = license out"). I don't know what happens if you assert a specific license that contradicts that. It would be bad to do what you say, because if the PR is never merged, then third parties could never use the PR in forks. A better alternative would be to offer the patch under MIT or GPL at the maintainer'…
My proposed "trick" was just to illustrate that it's futile to make a contribution MIT licensed for some people/purposes and not others. I think we're in agreement on this.
Re: Gitea blocks PR from community, charging $$ for open-source contributions
#70Earlier quoted context omitted.
Yes but the exhaustion was not 100% organic. There was a bit of social engineering towards wearing the maintainer down even further. I'm just pointing it out because I think it's going to be a tricky balance to strike. How can we, as a community of people who care about free and/or open source software tell the difference between: - a good faith effort to inform the wider community of a maintainer who is behaving bad…
I’m actually neither. I’m a big fan of forks. If something isn’t working out well, it should be very easy to create a fork and switch to the fork (i.e. forks should be lightweight just like branches). We can’t rely on everyone to follow our schedules, so if there’s a desire we should take the lead on getting it done instead of dragging each other down. As such, I didn’t post this to shame anyone, mostly to provide an…