Re: security alerts in busybox

"Roberto A. Foglietta via busybox" <[email protected]> Sun, 26 Apr 2026 11:57:28 +0200
Newsgroups gmane.linux.busybox
Message-ID <CAJGKYO7k-Lgm-oO4nVyVQvSAW=YixWXgqEyi60ye7DtZ-xoj1g@mail.gmail.com>
On Sun, 26 Apr 2026 at 11:22, Emmanuel Deloget via busybox
<[email protected]> wrote:
>
> I understand that this might bother you but...
>
> Today, A guy via busybox
> > On someday, Someone via busybox
> > > On a previous day, Someone lese via busybox
> > > > On another day, Another Person via busybox
> > > >
> > > > Mine is bigger.
> > >
> > > No, mine is bigger
> >
> > You're both wrong.? It's mine that is bigger.
>
> I understand that some of you guys might be hungry for flesh, bones
> and blood, but to *some os us* (i.e. the readers of the mailing list)
> this is supposed to be:
>
> 1) a collaborative community. I have noticed a pattern for the last
> two years where collaboration is more and more difficult. I've seen
> fights that could have been entirely avoided, including with members
> of other communities.

Drop it, bazaar nor cathedral requires this. Bazaar by independence of
agendas and cathedral by fight for the power due to structure
escalation pulsion in human nature.

>
> 2) a safe place. I mean, disagreement on how to do things are of
> course inevitable, but name calling? I'm pretty sure that's not
> related to anything technical. This is beyond unhelpfull.

Safety in human terms is a very subjective aspect as much as
inclusivity (while exclusion is objective, censorship), anarchy
doesn't mean absence of rules but maturity.

>
> 3) a professional place. Busybox is present in many professional or
> semi-professional products, and it's an important part of the open
> source ecosystem. Guys like me are using this mailing list to get a
> better understanding of the project itself, and to generally be aware
> in advance of what's happening in the busybox world.

Wrong, and it is extremely wrong that FOSS should care about business.
Who is paid takes care of those aspects, including dealing with
uncertainty.

Consensus by leadership is a way to fake certainty by slowing down
development and innovation because a project in neverending
"maintenance mode" is dead but profitable due to the apparent low cost
/ low skills needed to cope with it. Which is another business
paradigm: we have integrated the last version without saying that the
last version is just an old release with some patches on top of it,
and refactoring or a sudden change never happens.

>
> Frankly, for the last few monthes, this mailing list failed on all
> these 3 points. It's filled with ego patches, weird reactions, insults
> and sterile debates.

Wrong, it always failed these three points you listed in the last
decade but masquerade its failure by consensus.

The chores in the cathedral is chainting the same liturgy, therefore
everything is fine. Again a business need of certainty for low budget
/ low skilled teams / projects.

Maturity means accepting that "kindergarten safety" ended the first
year of elementary school but we did not get it immediately.

Expecting it for granted after 6yo is wrong. Morally wrong, against
reality wrong, wrong by living always unprepared.