Re: Web of Trust work [Was: kernel.org tooling update]
James Bottomley <[email protected]> Fri, 23 Jan 2026 11:24:33 -0500
| Newsgroups | dev.linux.lists.ksummit |
|---|---|
| Message-ID | <806a695eff99bd2eba935d0d5ada29cc29b31818.camel@HansenPartnership.com> |
On Fri, 2026-01-23 at 10:29 +0100, Greg KH wrote: > On Fri, Jan 23, 2026 at 10:19:56AM +0100, Uwe Kleine-König wrote: > > Hello Konstantin, > > > > On 12/10/25 05:48, Konstantin Ryabitsev wrote: > > > ## Web of Trust work > > > > > > There is an ongoing work to replace our home-grown web of trust > > > solution (that does work but has important bottlenecks and > > > scaling limitations) with something both more distributed and > > > easier to maintain. We're working with OpenSSF to design the > > > framework and I hope to present it to the community in the next > > > few months. > > > > the current home-grown solution is > > https://git.kernel.org/pub/scm/docs/kernel/pgpkeys.git/, right? > > > > I wonder what the bottlenecks and scaling limitations are that you > > mention. > > > > Is there some info available already now about the path you (and > > OpenSSF) intend to propose? > > There will be a presentation about this in February at a conference > and hopefully it will be made public then as the work is still > ongoing. Could you please stop doing this? The Open Source norm is to release early and often and long before you have stable code so you get feedback incorporated *before* you're committed to something. You're making it very hard for those of us engaged in open source advocacy inside various companies because we seem to spend a lot of our time trying to get our engineers not to drop fully polished projects into the public view but engage early on prototypes. It rather undermines our position if they can point to the Linux Foundation and say "but they do it so why shouldn't we?". Regards, James