Re: The future of commit access policy for core Firefox

Ehsan Akhgari <[email protected]> Fri, 10 Mar 2017 09:39:15 -0500
Newsgroups gmane.comp.mozilla.devel.seamonkey
Message-ID <CANTur_7Qi4hvt0SUJdm_TkZpauL11dzTBJUs7siNjweJ2MJePg@mail.gmail.com>
On Fri, Mar 10, 2017 at 8:49 AM, Mike Hoye <[email protected]> wrote:

>
>
> On 2017-03-10 7:49 AM, Axel Hecht wrote:
>
>> - We want as many people as possible to change the Firefox code base.
>>
>
> For whatever it's worth, I want the Firefox development process to be as
> accessible and participatory as possible to as many people as possible, but
> that's not quite the same as "as many people as possible can change
> codebase".  Automation that removes unnecessary complexity is a big help in
> reducing barriers to participation.
>

Automation that adds unnecessary complexity is a big hindrance in
participation also.  Maybe there is a good reason why we should be doing
that, but the proposal doesn't really mention what problem it's actually
trying to solve besides vague mentions of the stakeholders settings these
four goals.

For example, what problem is the first goal solving? ("Compromising a
single individual's credentials must not be sufficient to land malicious
code into our products.")  Does anyone believe that is the only way you can
put malicious code into Firefox, whereas anyone can submit malicious code
under a pseudonym in Bugzilla and we know from past experience times and
times again that mistakes will remain uncaught during review and testing
due to the nature of software?

-- 
Ehsan