Open Source Software Community - it's about ethics in Code of Conducts

  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
and the only people bitching are on free accounts
Apart from the fact this isn't true, you have to also consider that not fixing this increases the loss to github for every free account that encounters the issue. $100 of dev time to avoid potentially mid six-figures of pointless expenditure every year is a very simple equation, especially when they also risk losing paying customers if they don't fix it.
 
Guess what happens on a heavily loaded system where you may not run every second...
And all that had to be done was to make it a "less than" operator. And even then this entire function was a weird-ass bodge one would do on their personal machine to just get it working somehow and not run a massive business with financial liabilities. I'm not a programmer but never did I use "not equal" operator in a function where the variable increments. Last time I wrote something with a dynamic numeric variable is a yt-dlp PowerShell menu that looks through an object made from a JSON file to print out it's contents one by one and does an -lt check to stop on the final element. Since I went in mentally that this needs to be dynamic, it's basic logic. != is only ever good for booleans, strings and things like that.

This is just beyond incompetence. It's easy to see why this would went on unnoticed in a gigantic clusterfuck that is modern day Microsoft. No one monitors every single line of code contributed, because there's too much shit on a single plate to deal with. For some reason this piece of shit got merged, but no one realized the weight of this change, because now this code went to the upstream of Microsoft's services, possibly up to the Azure division that also acts as the heavy lifter for the rest of the company, and they pay zero attention to what runs on those. Someone did make a commit that would fix it, but for some reason went under the radar of all maintainers until it got auto-closed. And this faulty loop just kept running and running and Microsoft were none the wiser to the shitfest that's been brewing under their noses, they'll just throw more money for more datacenters if they're running low on cycles, they don't even know what they're running on those nodes.

And only now the real stink of the situation emerged that this one hackjob of a code ended up billing people for CPU cycles that were completely wasted. It's just a trend by this point and I refuse to believe these corporations are capable of planning out Machiavellian plans. This shit, the Cloudflare Rust code incident, the entire show is being ran by idiots. Only stupidity and ignorance can lead to this shit. :stress:

Just to be clear since the classic "Microsoft is a closed off monolith of evil" superstition of the FOSS community keeps blurring the reality:
1765416383558.png
1765416391386.png
1765416420938.png
1765416429628.png
1765416460362.png
The guy that made the faulty commit has barely made any contributions, has zero info on his GitHub profile, and chances are he wasn't paid by Microsoft at all. This was a freelancer coder.
1765416763611.png
1765416923426.png
1765416938806.png
1765416952596.png
This is the guy that merged those shitty commits. Note that there is no info about his "alignment" on his profile when every member of the Actions group has their GitHub/Microsoft credentials. I don't know if he's an ex-employee, but if he was then you'd assume he'd have that on his profile, and also he had very little commits on his profile to begin with.

So, does that basically mean that GitHub has outsourced maintaining a core component of their business that is directly tied to Azure's resources to freelancers that allowed for such a stupid line of code to slip through and generate millions in unneeded expenses for their customers? :stress:
 
Last edited:
It was after this model. Alas, the jeetification of software and hardware is reaching everything.
It gets even worse when you realize this brand name was passed around like a cheap whore, and that more often than not people just stick to the brand names of the "legendary" and "indestructible" products, not realizing it's all cheap crap skinwalking the greats. Like Alpha Industries, Nokia, Dr. Martens and so on.
1765417110177.png
You'll have a similar effect in software, like CCleaner or uTorrent. People stick to the brand name and are unaware of the enshittification that occurred. Or even worse, they'll get defensive when you tell them that this is shit and hasn't been good ever since X and Y because they got that badly brainwashed into brand loyalty.
 
There's been some pushback against anubis (the anime catgirl that validates your session before passing you to a website) and it's resulted in two neat articles that people here might find interesting.

https://fxgn.dev/blog/anubis/ - https://ghostarchive.org/archive/17S6e
https://lock.cmpxchg8b.com/anubis.html - https://ghostarchive.org/archive/X2aY1

kiwiflare is sorta similar if you need a point of reference.

edit; after re-reading i've noticed that one of the articles is penned by Tavis Ormandy, a dude who works at google that's found numerous massive zero days and vulnerabilities. As an example, he broke cloudbleed - the cloudflare issue where due to a buffer overflow they flooded visitors and search engines with private and confidential data. This has no bearing on anything obviously, just interesting that he popped up again.
 
Last edited:
The issue with OpenWRT is that people like Mental Outlaw keep promoting it as some universal solution to keeping old devices alive and breaking away from proprietary software when as you can see, that couldn't be further from the truth. Yes, it's for tinkerers, but rarely is it presented as such. When it comes to networking equipment, you want stability and reliability, which aren't OpenWRT's strong aspects.

And, again, if the solution to that is buying new hardware then you have multiple better choices to make where none of them involve OpenWRT, making it somewhat redundant. You're fine with proprietary software and want something advanced, powerful yet something that won't fail you? MikroTik. You want something open source and you're willing to play a sysadmin to set it all up? OPNsense. You're a lazy nigger cattle that doesn't want to put in any effort into anything? You'll be using your ISP's router anyways so who cares.
OpenWRT is great, if your router uses a mediatek soc it's probably supported and it's a great way to get more life out of something you already own over making more purchases. Most routers will have a way to flash it without opening it up. OpenWRT is completely rock solid unless you go out of your way to break it, just because you have problems with it doesn't mean everybody else does. I have used it on a cheap Asus router for years now and I've even set it up on a friends router and both just work fine.

The issue with Linux is that people like Luke Smith keep promoting it as some universal solution to keeping old devices alive and breaking away from proprietary software when as you can see, that couldn't be further from the truth. Yes, it's for tinkerers, but rarely is it presented as such. When it comes to operating systems, you want stability and reliability, which aren't Linux's strong aspects.
👏👏
 
If Microsoft didn't know how to write Bash then their most lucrative subdivision, Azure, wouldn't be running on their own flavor of Linux. Nor would they be one of the biggest code contributors to the Linux kernel.
or they just vibe coded the bash
That's most definitely what happened given how the GitHub side of things is one of the most thoroughly Pajeetified parts of Microsoft.
I don't think the distinction is that huge. It's the kind of mistake someone might make writing their own personal bash script. Then they could fix it in a few minutes after realizing the shit they wrote isn't working.

Maybe someone working specifically on the wsl, or azyure side of things is a bash god. But I don't feel uncomfortable saying I wouldn't go to most people at Microsoft for bourne shell scripting skills.

And yes I still see it as an us vs them thing. Google contributes quite a lot to the linux kernel. Does that mean I should be pro Google? Because I'm not, and I might hate them more than Microsoft. I see what these companies promote, and I don't know how anyone would be on their side. Besides the slimey way they tend to do business, culuturally I see them as a net negative. Bill Gates for instance.

Maybe some people that work there as developers are fine people. But I'm not talking about them as individuals.
 
Last edited:
anyone running gogs, open source alternative to github is likely getting their shit wrecked by an unfixed 0day.
https://gogs.io/ - https://github.com/gogs/gogs

https://www.theregister.com/2025/12/10/gogs_0day_under_active_exploitation/ - https://ghostarchive.org/archive/W4KAP
https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit - https://ghostarchive.org/archive/9eQfh

the timeline makes it look even worse:

  • July 10, 2025: First indication of exploitation observed by Wiz.
  • July 15, 2025: Discovery of Supershell malware on a vulnerable machine.
  • July 17, 2025: Vulnerability reported to Gogs maintainers.
  • Oct 30, 2025: Acknowledgment of the vulnerability by Gogs maintainers.
  • Nov 1, 2025: A second wave of attacks observed in the wild.
  • Dec 10, 2025: The vulnerability has not yet been fixed.
 
Last edited:
This video in particular was the point when I realized he doesn't know shit about fuck.
I appreciate Mental Outlaw for managing me to take the leap into Linux, but God has his content gotten dumber over the last few years. Maybe I just got smarter at noticing he’s kind of speaking out of his ass or he’s just gotten kind of lazy. Maybe I was just blinded at his constant Gentoo shilling, thinking he’s omega intelligent by compiling everything himself. It was once he really started shilling Rust where I had my doubts.
 
Ooh, OpenWRT. One of my favorite OSS projects.

It's admirable that they go for a very wide range to keep these old routers going, and their hardware matrix is comprehensive. I've tried it out on a Linksys - before they started forcing you to use an app to access the admin - and a TP-Link, and it worked great on both, and head and shoulders above the stock firmware. For a junior network administrator like me it's a comfortable leap from the job where a lot of stuff is rigid or solved to applying it to the home network and messing around with a mixed set of devices.

anyone running gogs, open source alternative to github is likely getting their shit wrecked by an unfixed 0day.
mark of the faggot.png
Couldn't have happened to nicer people.
 
For a junior network administrator like me it's a comfortable leap from the job where a lot of stuff is rigid or solved to applying it to the home network and messing around with a mixed set of devices.
Yeah it's a good tinker toy for the poweruser. Like OEM firmware is perfectly fine, but OpenWRT is great if you want better control over things.
 
The issue with Linux is that people like Luke Smith keep promoting it
At this rate Luke will be promoting living in a shed in the mountains with no modern technology around.
1765448526459.png
Maybe I was just blinded at his constant Gentoo shilling
Like Terry A. Davis said: "an idiot admires complexity, a genius admires simplicity". The big allure of distros like Arch or Gentoo isn't the fact that Arch is a rolling release distro that stays on top of software development, or that Gentoo is a perfect choice for purpose built systems like kiosks and whatnot, but because compared to something like Mint or Debian they're more cumbersome to set up as a desktop OS, meaning that it's the go-to choice for Dunning-Kruger types that treat using Linux as proof that they're smarter than everybody else.

Smart people will just go with what's the easiest to set up, and most stable in letting them do their job. The reason Linus Torvalds uses Fedora is because it's easy to set up, stable and also lets him swap the kernel. Most people will be happy with Mint as it's Cinnamon sandbox is fantastically tailored to the average user to just use their computer in peace. People that have the know-how of Linux's inner workings will choose either Debian or Arch and will mindfully maintain their systems without acting like they're better than everybody else due to them having more knowledge about their system they've went past peak of Mt. Stupid. Though you'll find it common with various Linux sysadmins that they'll use Windows/macOS as their desktop OS as they find desktop Linux to be an incoherent mess.
 
anyone running gogs, open source alternative to github is likely getting their shit wrecked by an unfixed 0day.
https://gogs.io/ - https://github.com/gogs/gogs

https://www.theregister.com/2025/12/10/gogs_0day_under_active_exploitation/ - https://ghostarchive.org/archive/W4KAP
https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit - https://ghostarchive.org/archive/9eQfh

the timeline makes it look even worse:

  • July 10, 2025: First indication of exploitation observed by Wiz.
  • July 15, 2025: Discovery of Supershell malware on a vulnerable machine.
  • July 17, 2025: Vulnerability reported to Gogs maintainers.
  • Oct 30, 2025: Acknowledgment of the vulnerability by Gogs maintainers.
  • Nov 1, 2025: A second wave of attacks observed in the wild.
  • Dec 10, 2025: The vulnerability has not yet been fixed.
A couple of hours ago they pushed a new commit: vulnerability reporting fluff
 
People that have the know-how of Linux's inner workings will choose either Debian or Arch and will mindfully maintain their systems without acting like they're better than everybody else
I enjoy both Ubuntu and Arch, simple as. I’ve tried Mint and Manjaro but they’re both just not for me, Manjaro even refused to install.

I always have distaste for anyone finding a certain distro lesser for people. Yeah, I hate Mint, but I’m not going to be chimping out that someone chose Mint as their OS. It’s even worse when they want to just have “One simple distro”, as per the newfaggots. (Nevermind that what you learn in one distro could help you in the other.) I’ve been called a massive retarded faggot for having a distro that wasn’t to their taste. (He wore an Arch Linux shirt in his pictures.) Just use what suits you best.
 
I was reading Phoronix's article on the prior Libreboot release while I wait for the one supposed to drop this month (provided Francis can stop being a lazy NIGGER), and this post caught my eye:

blackiwid said:


I wanted to ask why reporting over this 1 women project that only became more known for 1. steeling a GNU Project from GNU and 2. from a lot of drama.

But it's worse not only do you report of it and risk to make people believe that this would be a libre aka free software Project but you even actively confuse people in believing that this would in any way be free software:

Libreboot 25.06 released this week as the newest version of this Coreboot downstream focused on shipping only with free and open-source components. But due to the strict open-source nature of Libreboot, it continues to primarily see support for long outdated platforms.

You use the word open-source not free but for many they see this as synonyms. And because you basically say because libreboot is different that it's opensource and coreboot is not opensource you put those in 2 strictly different camps while they are more or less identical, even libreboots own websites admits that:
Libreboot is a coreboot distribution, in much the same way Alpine Linux is a Linux distribution!

And coreboot is also opensource from their website the first sentence:

Fast, secure and flexible Open Source firmware

So if both are "opensource" Projects and one is only a distribution of the other, how can this be the reason why it supports less hardware.

You also say it's "strict" open-source. No it's not again it's website clearly states that it's not strict: Libreboot’s policy is to provide as much software freedom as possible to each user.

Generally speaking, common sense is applied. For example, an exception to the minimalization might be if vendor raminit and libre raminit are available, but the libre one is so broken so as to be unusable. In that situation, the vendor one should be used instead, because otherwise the user might switch back to an otherwise fully proprietary system, instead of using coreboot (via libreboot). Some freedom is better than none.

You could paint it that way if this were the only choices "somewhat-free" vs "total practical blob friendly" but because libreboot is not the real free solution and there is a real one, confusing people to think that this is the libre / gnu project is really bad, it's bad enough that the goal of the individual behind that was a vengeful project to create this confusion and because she believes that she was fired because of being trans, even her trans-status was known when she was hired, but helping this confusion is really not that great.

I can see some overwriting journalistic or economic interest because this causa can be political but if you have to report about each libreboot release at least don't make absurd claim that advances this confusion further as if they would be strict "opensource" they are not they are "pragmatic" now you can make the argument that GNU itself is pragmatic by supporting some microcode or roms, that they consider as hardware but that is the most "radical" standard out there, if you make compromises from that then you are not "stict" anymore less than X is never strict...

To reduce the confusion, if coreboot is not free enough for you you still don't get freedom from "libre"-boot, this is the Alternative for people loving freedom: https://www.gnu.org/software/gnuboot

You don't need to agree to that, but then you just can use coreboot, and the only reason to use libreboot over coreboot would be some technical considerations because you like the build tools better or something alike.

Edit: Fatfingered enter, rip. Anyway, my point was: as much as I love the FSF, in any matter relating to the whole libreboot/foss-bios-adjacent drama, I have to give Francis the win. The hair splitting over what constitutes "free" has been a disaster for the foss-bios ecosystem, and the entire shitshow falling out between the GNU Project and Francis over the whole "blob mitigation vs 100% free" thing is kinda dumb (not commenting on the tranny shit, Francis needs to ACK ASAP as soon as someone that can inherit Libreboot comes along). The FSF is supposed to be uncompromisingly free-software-only, but the RYF ruleset when it comes to these BIOS implementations is essentially pointless because the system will ship with closed-source firmware regardless of just the BIOS, a 100% libre system is not currently a real thing. GNUBoot is effectively abandonware and might as well not exist since Libreboot does what it does 200% better, with better support and way better people working on it (not necessraily Francis, but people like Mate Kurki, who's the guy that ported coreboot to the T480). Its kind of like what @Slav Power was saying about Mint et al., a genius admires simplicity. Even if it is voodoo under the covers, Libreboot is the easiest and most ergonomic way to install an open-source BIOS.

Even though I think that Libreboot should still be a de-facto FSF project the same way that Nonguix is de-facto maintained by the same people that work on Guix proper, if they HAD to split, I just wish it would have been more amicable. Francis is an insufferable faggot to be sure, but the benefits of jointly developing something that can free users from proprietary spyware, even if partially, would have been worth the cost of tolerating him. He is 100% to blame for the split, don't get me wrong, but if I were Stallman, I'd extend an olive branch out of purely practical reasons. Now you have AbandoNUBoot and split hairs. Hate to see it.


Also: > 1 woman project GEEEEEG
 
Last edited:
this 1 women project
I just noticed this insane troon has his own thread:
 
I just noticed this insane troon has his own thread:
Thread's dead baby, thread's dead (day 61 of ebegging jannies to grant me an op rewrite/update)
 
day 61 of ebegging jannies to grant me an op rewrite/update
The process is just to fire up a Prospering Grounds thread and when yours is good enough the jannies will hopefully redeem, saar?
 
Back
Top Bottom