Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not trying to be lazy (ok maybe a little bit), but can someone please provide like a 3-4 sentence summary of what happened? Everything I've seen on this either assumes you already know, or is very long and rambly, or both.


Many projects joined the .NET Foundation after it was created. It didn't really do anything for them (I think they basically sponsor meetups), but it wasn't harming anyone either.

The .NET Foundation asked for owner access on the author's repository (for a CLA bot). The author declined and a workaround was organized.

Years later the .NET Foundation asked for "owner access" on the author's repository (to allow them enforce Code of Conduct across all repositories). The author declined.

The CLA bot stopped working. The author was told it would work if he gave it owner access. The author was annoyed because they previously had a workaround. They gave in and gave @dnfadmin owner access (temporarily, it was later revoked after the CLA bot was set up, thanks /u/ethbr0 for the correction).

Some time later the author realized that the project had now been silently moved to GitHub Enterprise (likely in the short window @dnfadmin had owner access). The author states that projects in GitHub Enterprise can be entirely controlled by the owner of the account (the .NET Foundation). This transfer happened silently.

Independently, this happened to another project (who had coincidentally had an issue with a Microsoft employee and former contributor force a pull-request into their project: https://github.com/reactiveui/splat/pull/778). The change itself seems innocuous, but the approach bothered people.

People are upset because of how tone-deaf all of this is. They would like the .NET Foundation to stop trying to gain complete control over the member projects. They would especially like for their projects not to have their ownership changed silently.

Edit: For the record, I do not believe this is part of some embrace, extend, extinguish plan on behalf of Microsoft. I think these accusations actually cheapen what has happened here. I suspect this was more of a "can we make this process easier and more convenient for the .NET Foundation"-type thing.

The people involved with this will have to do some soul searching. The .NET Foundation should operate in service of its member projects, not the other way around.


I think this is on point. We once had an issue with open street maps, that caused our routing system to not be capable of directing citizens and employees to the second biggest municipality in our country because a one way street had the wrong direction marked in OSM by mistake.

This had a huge impact on us. With thousands of employees and citizens calling our IT support staff of 5 people every day.

When I used our OSM official “City off X” account to fix it, I was an utter idiot and submitted both a real life picture I took myself as well as a Google maps and a krak maps (Danish map service) screenshots. I didn’t know this wasn’t legal, because I was an idiot, but it resulted in our fix getting reversed and a week long discussion with the OSM community members about fixing the damn street.

We made the street one way. But we couldn’t fix it in an OSS map service because the community wouldn’t let us because we made a stupid mistake.

We’ve now switched our services to Krak. But I can promise you that if we had, had the admin power to force our chance through during those days, we wouldn’t have given any regards to the OSS community.

If an popular tool wasn’t working within the .Net framework CLA I imagine the process would be somewhat similar inside Microsoft.

It’s just one of those things where the OSS community processes and Enterprise process of “get this fixed right now, at any cost by any means, ignoring every standard we may have, just get it fixed, now. Then make sure it never happens again.” that happens every now and then when the beast awakens, clashes. I’m not sure how you can avoid it, as Enterprise will never want to comply with OSS processes when it’s in a hurry.


Regarding the OSM part, how was that illegal? You had 3 different sources for your information. The pictures you took were only your own and you were free to use them for whatever you wanted. Using a copyrighted map to validate that the images were correct is entirely within the use allowed by those maps. The edit was based on the pictures and your real life observation, not those other maps, so you own the edit, which your are well within your right to contribute to OSM.

I get that the OSM community is trying to practice something equivalent to a clean room reimplementation, but that's equivalent to a person in the "cleanroom" being shown a public domain code library and then a file from that same library, but taken out of a ROM dump. Yes, they saw the copyrighted file, but they also saw the public domain file so they're entirely within their right to base their reimplementation either partially or fully on it.



There was no copying. ¯\_(ツ)_/¯


I'm not sure this observation is to the point. Most enterprises do not allow this kind of behavior either, unless you happen to sit at the right place in the hierarchy. If you had violated the terms of service of Google Maps, they would probably have banned you immediately too.

But yes, it may seem a little confusing that even though you can do X, it may not be appropriate.

I think that's also why people are upset in this case. They actually did try to protect themselves from power grabs, only to find themselves cheated.

By the way, there's a Danish mailing list for OSM. I don't know if you explained the issue there, but if you did, I think it's likely someone would have made the correction for you relatively quickly.


> I didn’t know this wasn’t legal, [...]

What was the problem? Why isn't that legal?


The screenshots are evidence of copyright infringement of commercial maps.


... how?

At best it's a breach of GMaps ToS by that user. And in this case the user attached a photo they took. The screenshots are just noise.


I think the google maps screenshot is poison?


But there was also the photo made by the user. I'm trying to understand the legal aspect of this. If Google felt they suffered so much of this, they should bring a (civil) lawsuit against the user that uploaded that photo. Why would OSM care in this situation?


Because OSM wants to be really really sure their data is not tainted and gets them or their users into trouble. As such, anything that suggests that you are using improper sources for editing and is noticed will get you looked at, maybe get someone to double-check your past edits, ...

And since its a community consensus thing, people will wait a few days to reintroduce a change once it has been challenged unless the challenge is obviously unreasonable. It's not like a change being delayed a few days is some unreasonable big punishment, it's just part of QA process to run. Maybe wasn't strictly necessary here, but it's a really obvious warning signal to trip.

(To make a (admittedly stretched) software analogy, if you submit a PR somewhere and show disassembly from the Windows kernel as evidence that it's a good algorithm others also use, it'll also cause some concern, and you would've been better of just showing your solution on its own)


I don't understand. Cannot you create a PR and fork the project (and use your fork in the meantime until the PR is merged)? This is what I do when I use opensource libraries. They being opensource shouldn't mean that you get blocked by them.


OSM is one big online database, like wikipedia. Sure you can fork it, but it's far from trivial to "maintain" that :)


Sorry, but what specifically was illegal? And as in laws, or OSM project governance?


You can't use copyrighted maps as a data source for OSM:

https://www.openstreetmap.org/welcome

"Unless you have special permission, don't copy from online or paper maps."


Thanks.


Legal was probably the wrong word to use. It’s against the policy of OSM. It’s probably not actually illegal as far as the law goes.

I mean, we own the map rights. Google had to seek permission from us to map our area and publish it.


Nice story, dude. :)


> I suspect this was more of a "can we make this process easier and more convenient for the .NET Foundation"-type thing.

I suspect there was also just a different picture on what the .NET Foundation even meant inside and outside of MS. It's different people working on it inside MS than the ones who originally set things up, and the new people may not have even seen their actions as trying to take control of anything because they were under the impression that everyone considered them in charge already.


This issue is really only about the .NET Foundation and not Microsoft. Otherwise, you may very well be correct.

The leadership of the .NET Foundation changed twice since my project joined it. So it is very possible (likely?) norms and expectations did not have flowed from one set of leaders to the next. I don't know. I'm still waiting to hear.


> They gave in and gave @dnfadmin owner access

Temporarily gave @dnfadmin access, is my read.

> "The .NET Foundation had admin access to the WiX Toolset organization for a week, not more than a week ago"


Good catch! I didn't notice that on my read-through. I've updated my post to include this.


Minor nit: the admin access wasn't requested for the CLA bot but getting a non-functional CLA bot fixed was the reason I gave temporary access.

Otherwise, reasonable summary without as much flair and color commentary as the original. ;)


Thanks for the clear summary.

So, the proper, open-source-if-a-bit-dickish way to go about this would have been...

1) Microsoft forks the primary git repository and declares theirs to be "Microsoft-blessed".

2) Microsoft puts a skeleton team in charge of maintaining the Microsoft-blessed version, but mostly they just pull the original maintainer's patches.

3) People slowly migrate to the Microsoft blessed version.

NOT: We flipped this hidden switch under the table and now your repository in GitHub is controlled by us.


The proper way would have been to leave the project alone, notify the maintainers of problems if any turn up and remove the project from the .Net Foundation if the problems persist.

Of course from the issues that came up the last few days it seems that there is literally no point in joining the .Net Foundation and kicking a project out is essentially doing the maintainers a favor.


I don't understand your scenario. Microsoft isn't involved here. I mean Microsoft uses the WiX Toolset (my project) but they have never suggested forking it. I'm confused where you were going with this.


The proper "open-source-if-a-bit-dickish" way would be to do exactly what the .NET Foundation did here, but where the letter said "You will need to add this admin for compliance with our policies" that word policies would be studded with footnotes to policy pages, reams of meeting minutes, and archives of open mailing list discussions.

Apache and Eclipse and others all mandate that they control a lot of minutia of source control like what .NET Foundation seems to want to be doing with their GitHub Enterprise account, but their transparency policies mean all of the discussions of that are open and no one is surprised when changes happen.


As far as I understand the foundation is a distinct entity, it’s not Microsoft doing this.


Even the director of the .NET Foundation is a MS employee (Program Manager), of course in practice it’s a MS entity.


Have you interacted with the .NET Foundation much? Have you seen how the .NET Foundation interacts with Microsoft?


Posted a response to this elsewhere in this thread:

https://news.ycombinator.com/item?id=28796675


Incompetent workers, it's that simple really. MS assigns college degrees to projects, those college degrees understand very little about software, much less the culture of repository ownership and open source relationships. Too many employees, not enough experience heading them.

Microsoft and orgs like it are too big, you cannot trust a massive machine to be efficient, there's little incentive for proper management.


This issue is about the .NET Foundation, not Microsoft.


Au Contraire. From the bylaws posted publicly so far, it seems, they aren't truly independent of each other.

Microsoft is the "Founding Member" of the .NET Foundation. They are entitled to appoint an Exec. Director (ED) and the board has no say in this matter (The current ED is the person who forced a commit on a member project). The ED's tenure has no expiry other than when Microsoft feels the need to change (or they leave). All other board members are elected for a set term.

Lastly, the ED can block any board resolution; aka, the elected board needs Microsoft's blessing to do literally anything.

Source: https://github.com/dotnet-foundation/Home/discussions/39#dis...


I don't think you've seen the .NET Foundation and Microsoft interact then.


I have not. I am not a foundation project maintainer or have had any direct interactions with the foundation. My understanding mostly comes from following the community.

But this is what Rodney Littles is quoted as having said in his interview with The Register

> From Littles' perspective, though, the .NET Foundation is insufficiently independent from Microsoft, does too little to help its member projects, and lacks a strong sense of mission or purpose.


Rodney is closer to many things than I but my experience shows these are the root issues:

> does too little to help its member projects, and lacks a strong sense of mission or purpose.

That's on the .NET Foundation, not Microsoft.


This is definitely not the case. The .Net Foundation is not staffed by Microsoft, nor is it owned by Microsoft. It’s an entirely distinct entity though I believe some board members work for Microsoft.


That’s where the poor & questionable transparency comes in, they try to market it as independent but it was formed and funded by Microsoft with the Executive Director whose performing all the objectionable actions an MS employee who is also the only person that is able to approve all material changes made to the foundation whose position can only be filled by the founding member who is Microsoft, in effect they are the silent hand making all the power moves to its member projects without their consent, wishes or even a courtesy notification. Then to try downplay the bad PR you had the MS VP Director with no visible ties to the foundation willing to jump on a call to disgruntled members so they can downplay their MS foundation employees actions behind close doors.

https://github.com/dotnet-foundation/Home/discussions/39#dis...


But the Github Enterprise admins, and people actually fixing the CLA bot probably are from MS?


No.


> who had coincidentally had an issue with a Microsoft employee and former contributor force a pull-request into their project

It was the head of the .NET Foundation


Fiscal sponsors should never have access to code repositories...


I don't think this applies as a general rule. One could imagine reasons why they should have access (of different kinds), especially when they employ key maintainers and are the driving force behind the project.


Project maintainers had their projects moved from their public GitHub accounts to the DNF's GitHub Enterprise account without notice. Some maintainers only found out about the transfers of their projects because of this[1] discussion.

[1] https://github.com/dotnet-foundation/Home/discussions/38


Technically speaking it wasn't that discussion. That discussion was opened after we started realizing what had (and had not) happened. But your summary is otherwise correct. :)


So nothing changed with the source code or its licensing, only the location on github? That seems a bit inconsequential, tbh. Are there strings attached to the new location? If no, then move on.


Per post, being part of a GitHub Enterprise organization grants the GEO's owners control over any projects contained in that organization.

That's the change.


Thank you. That does seem consequential.


Yeah and is not wrong for the foundation and the projects. It is the absolute lack of community, communication and tone deafness.


Exactly.


You'd not say the same thing if the ownership of a domain changed hands quietly, in the background.


That would be worse though. This is like a subdomain changing hands quietly. E.g. you mypage.github.io.


There were also pull requests that were merged despite maintainers' objections to merging.


That didn't happen to me and there was a pretty comprehensive (IMHO) apology about that issue.


There are strings attached to the new location - the maintainers can (in theory) be kicked out of their own repositories.


I don't really know anything about this stuff but after reading the blog post I feel like I understand. It's a good read.


Thanks, that is good to hear. I wasn't sure I would post it because I was afraid it would actually confuse the issue. Thank you.


Now you know what working with WiX is like.


Hah, hah, hah, that's actually pretty good.


Maybe I should have added a tl;dr at the top?

Writing the whole entry was challenging because there is a lot of detail I wanted to provide to being everyone along the journey. I've seen some people drop in at any isolated point and say, "Why is this a big deal?"

Also I'll be the first to admit that when in story telling mode, I am not particularly terse. :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: