Sourceware Open Office, Friday 16:00 UTC
Mark Wielaard <[email protected]>
| Newsgroups | gmane.comp.lib.glibc.alpha,gmane.comp.gcc.devel,gmane.comp.gnu.binutils,gmane.comp.gdb.devel |
|---|---|
| Message-ID | <[email protected]> |
Friday Aug 9, 16:00 UTC
https://bbb.sfconservancy.org/b/mar-aom-dmo-fko
Using #overseers on irc.libera.chat as backup.
To get the right time in your local timezone:
$ date -d "Fri Aug 9 16:00 UTC 2024"
Sourceware relies on cooperation among a broad diversity of core
toolchain and developer tool projects, hackers, organizations, ideas,
and communication styles. The monthly Sourceware Open Office meetings
are one way of coming together as a community and discuss our shared
development infrastructure. For other ways to participate see
https://sourceware.org/mission.html#organization
- Discussion topics:
- Isolation, Quality of Service and banning agressive spiders
Last month we isolated more services using resource control units
so different services cannot starve out each other. There are also
quality of service settings for httpd to limit (and serialize) the
resources agressive spiders can use (we are seeing more and more
spiders that ignore robots.txt and use botnets to concurrently
access as many resources as possible). We also try to block these
spiders (though fail2ban when triggered by these qos
settings). But we don't want to accidentially ban regular
developers. Please let us know if we didn't get the balance
right. Or if you have ideas to better block these agressive
spiders.
- builder.sourceware.org buildbot CI
Thanks to RISC-V International and SOPHGO we got a Milk-V Pioneer
Box. It has 64 cores and 128GB memory, but single core performance
isn't very fast. We are currently running gcc bootstrap plus
checks on it. We already reduced the build time from ~10 hours to
~5 hours. If we can save a little bit more time we can add CI for
other projects.
- Cybersecurity "regulations" FAQ
We are working on a Cybersecurity FAQ. Please ask any questions
you might have and we'll try to answer what impact some of these
"regulations" might have on the infrastructure services and
possible project policies.
Specifically what impact the EU Cyber Resilience Act (EU CRA) and
the US Improving the Nation's Cybersecurity (Executive Order
14028) have. And the ideas behind Zero Trust Architecture (NIST SP
800-207), Secure Software Development Framework (SSDF, NIST SP
800-218), Software Supply Chain Security and CRA compliance that
projects might want to follow. And how Sourceware has prepared and
can help.
We used to have both a BBB meeting room and an irc channel
discussion. But that became a little confusing. So for some previous
meetings we used irc exclusively. But this time we'll try to use the
BBB meeting room exclusively.
https://bbb.sfconservancy.org/b/mar-aom-dmo-fko