Re: My suggestions on auditing that services are running free software

Carlos O'Donell <[email protected]> Wed, 3 Apr 2024 14:55:09 -0400
Newsgroups org.linuxfoundation.lists.cti-tac
Organization Red Hat
Message-ID <[email protected]>
On 3/22/24 11:57, Konstantin Ryabitsev wrote:
> On Fri, Mar 22, 2024 at 04:35:13AM -0400, Ian Kelling wrote:
>> I suggest that CTI come up with a proposal/plan for how to implement the
>> audit. Eg, checking what software is being run and that users are able
>> to download a copy and that it is free software. The FSF will be
>> available to review the proposal.
> 
> Before we go down that route, please note that LF IT does not provide backend
> access to third parties, so any audit plans will be limited to auditing
> documentation.

I agree, and I would not want any service provider to give backend access to third parties
because it creates an increased security risk to support the audit. The cost of compliance
is relevant here if it creates a security risk. We can achieve compliance without the
additional risk.

For me as a CTI TAC member is reasonable to have a documented list of the versions of the
software that was being run, audit the list, and update the list with versions on the
CTI website.

> We, of course, comply with licensing terms, so any AGPL-licensed software
> (such as public-inbox) is available for download (we run the upstream version
> without any modifications). Any free software without such requirement may
> have basic version info, not necessarily down to the exact patch level. For
> example, I doubt anyone benefits from knowing the exact version of Postfix
> used to send this mailing list message.

The purpose of the audit is to ensure that we meet the ethical repository hosting criteria
and we can meet those obligations by ensuring we run unpacked distro versions or unpatched
upstream versions of the software. Where we deviate from upstream or distro versions we should
do so only briefly to address security issues. Knowing the exact version of Postfix is *less*
important to me than knowing that we are running without any local patches applied and using
the standard distro version or standard upstream release. So it would be a checkbox item for
me to ask "Are we using the distro version? Are we using upstream directly?"

Does that make sense?

-- 
Cheers,
Carlos.