From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 3C749138334 for ; Fri, 15 Jun 2018 15:31:40 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id BB11BE08F9; Fri, 15 Jun 2018 15:31:38 +0000 (UTC) Received: from mail-pl0-f53.google.com (mail-pl0-f53.google.com [209.85.160.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 74E53E08F5 for ; Fri, 15 Jun 2018 15:31:38 +0000 (UTC) Received: by mail-pl0-f53.google.com with SMTP id 30-v6so5533083pld.13 for ; Fri, 15 Jun 2018 08:31:38 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=41EIGLgxrfxBGIrDEumeLdDWWGGVqojsqWTbB6xWouQ=; b=k1QvByJePkS1mAMXwi0I1vggcLrwwKc8oVqjxTzXvqST3ojKTQ50ZVFKgwS2313eD9 b+52hAjBtSTTqXgSjS0z8QXQbTxJWjZCfodk/kmoNM8mOr3MnTVIKglVFuJe/HBW3hYP ACqotDxe8D3M8nvGANujaDxm5oKg3sDVAqhiFzlK98fqQEuSaXc5ETdZW3gYbB9tGCOH Yaovb2Phgy6Q8KWHVNbrrT1dSB0G37ngEQxuDK6/JTlmSLyRif6GYmYWsZC28J+05iSm LX8tocKV1oye3mb4hKUtGOgU6PHeGjFKEDJsA9eX3MhN52KDXEl3ugcT8Rbj6VxKfvzK 1YuA== X-Gm-Message-State: APt69E2Z4zbueuS2pFcssFpikM1hj6pwByPJ0eJxDge6+b1y29INqjJR AhLhny9vBAr8fFMJB8uI/thf/kQ+t/KMPjlo0orAJ/Rt X-Google-Smtp-Source: ADUXVKIrsBZiB6RolCebfXTKNTWo0wzF96hMiVXhesit8DdoqCS7DT5uAMNvk+3I3/lfYWWhwJZHmbJX70hi/LJ+zvU= X-Received: by 2002:a17:902:8497:: with SMTP id c23-v6mr2648569plo.124.1529076696901; Fri, 15 Jun 2018 08:31:36 -0700 (PDT) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Project discussion list X-BeenThere: gentoo-project@lists.gentoo.org Reply-To: gentoo-project@lists.gentoo.org MIME-Version: 1.0 References: <1528529135.1261.34.camel@gentoo.org> <8185f4b0-9d30-d15c-1f7b-331f2b9fafe3@gmail.com> <72b16227-ad16-eca1-5f35-994fe7e89e2c@gentoo.org> <933a84d7-2dc3-e77a-0444-ccc4aa20eb26@gmail.com> <36a4e0e2-c9b5-7058-6c16-a326bbd73d36@gmail.com> In-Reply-To: <36a4e0e2-c9b5-7058-6c16-a326bbd73d36@gmail.com> From: Rich Freeman Date: Fri, 15 Jun 2018 11:31:25 -0400 Message-ID: Subject: Re: [gentoo-project] Repo mirror & CI: official statement wrt GitHub To: gentoo-project Content-Type: text/plain; charset="UTF-8" X-Archives-Salt: bf938c2d-8577-4deb-a58c-fc243a4eb1a1 X-Archives-Hash: 6d1edb66d11829e14db7476cee7950d4 On Fri, Jun 15, 2018 at 10:55 AM kuzetsa wrote: > > "Gentoo Developer's Certificate of Origin" - shouldn't > the author / contributor themselves be involved in this? > It already requires this. The committer would have to certify: " (4) The contribution was provided directly to me by some other person who certified (1), (2), (3), or (4), and I have not modified it." (or one of the other items in the list, if they did modify it) Ultimately the committer is the person Gentoo has a relationship with, so they need to make the certification when they make the commit, even if it is just certifying that somebody else certified it. This goes along with something Thomas said earlier - ultimately the committers are responsible for what they commit. There really isn't a sane alternative since the whole reason we try to control our committers is to ensure that things don't end up in the repository which shouldn't be there. This isn't diminishing the value of 3rd party contributors - but simply affirming the value-add of having somebody we know actually look at what is being contributed. That includes the copyright/license and not just the code. After all, all this stuff ends up on all our users's systems so we want to protect them as well as ourselves. Users already have the freedom to use any overlays they wish if they value these things differently. -- Rich