RE: [PATCH v3 02/15] xdiff: introduce rust
- From
rsbecker@nexbridge.com <rsbecker@nexbridge.com>
- Date
- Sep 8, 2025, 17:01 UTC
- Message-ID
- <049f01dc20e2$42c75650$c85602f0$@nexbridge.com>
- In-Reply-To
- <CABPp-BHQyQk+Vkzm3RhVXxvNrpLB--bCLYwSCfZBQhB6PGBQQQ@mail.gmail.com>
On September 8, 2025 12:13 PM, Elijah Newren wrote:
Show 47 quoted lines
>On Mon, Sep 8, 2025 at 8:37 AM <rsbecker@nexbridge.com> wrote: >> >> On September 8, 2025 11:31 AM, Elijah Newren wrote: >> >On Sun, Sep 7, 2025 at 9:10 AM <rsbecker@nexbridge.com> wrote: >> >> >> >> On September 7, 2025 12:10 AM, Elijah Newren wrote: > >> >Thanks, Randall, this is useful information. In regards to one point not fully >covered >> >by Phillip: >> > >> >> Also remember that without support from the git team, the code base is >> >> no longer the same, meaning the auditors will not necessarily accept >> >> fixes from third-party sources. >> > >> >Why does it need to be "third-party" sources? Linus years ago blessed having >> >someone else be in charge of providing updates for stable releases of Linux. >Junio >> >could do the same with Git and similarly mark an individual or group of people as >> >the maintainers for the last Rust-optional version of Git, and those individuals >could >> >make official releases of Git with extended security fix support. Then it's not >every >> >platform repeating the backporting work that needs to be done, but rather >> >individuals from the affected platform(s) collaborating on that work and then >> >making official first-party releases. >> >> Linux has one set of rules, and other platforms have others. I do not define the >> audit requirements for PCI, SWIFT, or HIPPA compliance (and other rules outside >> of North America), which apply one way or another to most of my community. >> The audit teams, which are both internal to the companies and at >> governmental regulatory levels, do this. It is 100% out of my control but is a >> reality. Fixes to any code involved in managing financial and health instruments >> must be done by authorized and recognized sources. I am not one of them. > >Perhaps I wasn't clear? Let me try to summarize what I've understood >of the conversation: > >Randall: We need to have official git releases for the last >Rust-optional release. >Elijah: Great! Let's enable interested folks to make official git >releases for the last Rust-optional release. >Randall: We need to have official git releases for the last >Rust-optional release. > >Which makes me just want to repeat what I said last time -- let's >enable some folks to do that.
Ok, what does that look like. When and how? Will I get added to the list of committers for this? How many people? Starting when, ending when? It would be very nice to have some kind of project plan for this with dependencies and milestones - I have been asking. If someone sends me a list, I can start officially tracking it.