Re: DCO: Was: Re: Contributing to gdb
Guinevere Larsen via Gdb <[email protected]>
| Newsgroups | gmane.comp.gdb.devel |
|---|---|
| Message-ID | <[email protected]> |
On 1/17/25 10:01 AM, Eli Zaretskii wrote: >> From: Florian Weimer <[email protected]> >> Cc: Andrew Burgess <[email protected]>, Eli Zaretskii <[email protected]>, >> [email protected], [email protected], [email protected], >> [email protected] >> Date: Fri, 17 Jan 2025 11:37:54 +0100 >> >> * Eli Zaretskii via Gdb: >> >>> I mostly fear that by accepting DCOs we will open ourselves to >>> contributions from people who are not authorized to contribute their >>> code (e.g., it was copied from somewhere, or their employment contract >>> makes all their code the property of their employer, or something of >>> that nature). DCO makes it much easier to submit code based on >>> incorrect understanding of what the DCO text says, so the probability >>> for honest mistakes is higher than with CA. >> It is possible that someone signs a copyright assignment without being >> authorized to do so, which is exactly the same problem. As far as I >> know, the FSF doesn't verify that the signer has been authorized by the >> organization that owns the rights. > verification is not the issue here, the issue is whether the > contributor is at all aware of this aspect. > > The copyright assignment process includes the contributor filling a > form, where he/she is asked whether they have an employer that should > be included in the process: > > [Do you have an employer who might have a basis to claim to own > your changes? Do you attend a school which might make such a claim?] > > I think reasonable people will always know to answer those questions, > or at least ask the FSF copyright clerk what is the meaning of "an > employer who might have a basis to claim to own your changes" (and > similarly the meaning of the question about the school). > > By contrast, AFAIK there's no such process in sending the DCO. > We could have a similar process. A way to ensure that a contributor has seen the DCO could be setting up a bot, and whenever an email with an SOB with a never before seen email, the bot sends a boilerplate "Welcome to the project. Before we can accept, please be sure to review the following, and reply in line that you meet the conditions." And after the reply, we can be reasonably sure the contributor knows what a DCO entails. When I mentioned this to Andrew, he had a simpler idea, just to setup some "gdb-dco" list, where contributors who want to contribute with DCO would send the DCO wording with an "OK" or the name or pseudonym they'll be using to contribute. There's less automation and a little more annoyances to end contributors, but it is easier than signing a contract - especially for contributors whose mother tongue isn't english - and has a result immediately, as opposed to waiting for over a month at times. -- Cheers, Guinevere Larsen She/Her/Hers