From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp0.migadu.com ([2001:41d0:303:e224::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms13.migadu.com with LMTPS id 8DYqJymXdGaYRgAAqHPOHw:P1 (envelope-from ) for ; Thu, 20 Jun 2024 20:55:05 +0000 Received: from aspmx1.migadu.com ([2001:41d0:303:e224::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp0.migadu.com with LMTPS id 8DYqJymXdGaYRgAAqHPOHw (envelope-from ) for ; Thu, 20 Jun 2024 22:55:05 +0200 X-Envelope-To: larch@yhetil.org Authentication-Results: aspmx1.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org" ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1718916905; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post; bh=gpk7EADYA1vNjJGe4hG8aVeRaLFXO9LrN4FzlTxt4mg=; b=i/beJ5f+6866vXdaMpbSjeMNXI8/5dZBfmKEDGQpp2zLMLRwLqJWMAG7tuxZwvYz9OskJg huXhXztG0n1c+vs10PRRNCSM1117XXc8Vqck7ZHtu9m63sYStGUfsBct96JCB+wWg4tK+k ECpTIJuNQJpZWb4qP2F8rkNvSMoMbo8olJyUj4qee2x4AALOUEcCCLu9OnGALOjWlBDPL3 p2UgGywYk59uI/MPGh8jRokznpgoNCk1Eklh2atCBCtEVkhWbidIV5UTd4uL5nzPQPHhhe rO+GV2Kpehqh1yFue5tLkfqVa/YomihL1VYbme11Xz1yCbquTRxnGAKqg8jm+A== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1718916905; a=rsa-sha256; cv=none; b=ph7RWhVwL/7AyHfXlN6agNk8961sBoIsUbPS3WrMxIXKVPLwutmK6M7j3HvJoZDMDdTFLk 8MggDZEiFs/fKpe4BABFv07ekAM90zifYTbODQWTYSJdnwdoyPWZlbLhFjm8x7Vg5gjMW2 JU5BFP5mojJassA6FVLa6rlXhdnWyyc+zIc6cRuDYnrspzBFg6jUVgBExbYAZxhdQ9Qclo PE50rUdb01aXXA8o85D+y9swJaq6XYnSFPFWvki95mN8ot4pKAbQmjbjlG8NThSIAzU24h HVrroyzwHb05LjZQ9tF2StDit12VjbITb+ZvEXReeoJCoDiPIQZAZtsE8Xz8vA== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org" Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 685F96C73C for ; Thu, 20 Jun 2024 22:55:05 +0200 (CEST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1sKOnW-0000YB-CZ; Thu, 20 Jun 2024 16:54:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sKOnT-0000Xv-Pe for guix-devel@gnu.org; Thu, 20 Jun 2024 16:54:19 -0400 Received: from hera.aquilenet.fr ([2a0c:e300::1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sKOnR-0002bC-Aw for guix-devel@gnu.org; Thu, 20 Jun 2024 16:54:19 -0400 Received: from localhost (localhost [127.0.0.1]) by hera.aquilenet.fr (Postfix) with ESMTP id 1541FBD9; Thu, 20 Jun 2024 22:54:13 +0200 (CEST) X-Virus-Scanned: Debian amavisd-new at hera.aquilenet.fr Received: from hera.aquilenet.fr ([127.0.0.1]) by localhost (hera.aquilenet.fr [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XfFSu4UQk42S; Thu, 20 Jun 2024 22:54:12 +0200 (CEST) Received: from jurong (unknown [IPv6:2001:861:c4:f2f0::c64]) by hera.aquilenet.fr (Postfix) with ESMTPSA id 49E8462; Thu, 20 Jun 2024 22:54:12 +0200 (CEST) Date: Thu, 20 Jun 2024 22:54:10 +0200 From: Andreas Enge To: Dale Mellor Cc: guix-devel@gnu.org Subject: Re: Next Steps For the Software Heritage Problem Message-ID: References: <20240618113717.4a6bad2b@fannys.me> <8734pa5mlx.fsf@meson> <077b1a0fdec4d0f30209c28d75dc40811c77a4a9.camel@rdmp.org> <24a0a840a595dfba7c145e5f207fef532ceb16d6.camel@rdmp.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <24a0a840a595dfba7c145e5f207fef532ceb16d6.camel@rdmp.org> Received-SPF: pass client-ip=2a0c:e300::1; envelope-from=andreas@enge.fr; helo=hera.aquilenet.fr X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: guix-devel-bounces+larch=yhetil.org@gnu.org X-Migadu-Flow: FLOW_IN X-Migadu-Country: US X-Migadu-Queue-Id: 685F96C73C X-Migadu-Scanner: mx12.migadu.com X-Migadu-Spam-Score: -5.86 X-Spam-Score: -5.86 X-TUID: X0kR/up1v4jK Am Thu, Jun 20, 2024 at 07:42:44PM +0100 schrieb Dale Mellor: > I'm sure guix lint tried to push my code out to them the last time I tried. Ah indeed, there is this in guix/lint.scm: (define (check-archival package) "Check whether PACKAGE's source code is archived on Software Heritage. If it's not, and if its source code is a VCS snapshot, then send a \"save\" request to Software Heritage. It potentially calls this: (define (save-package-source package) "Attempt to save the source of PACKAGE on SWH. Return a list of warnings." Which calls this from swh.scm: (define* (save-origin url #:optional (type "git")) "Request URL to be saved." (call (swh-url "/api/1/origin/save" type "url" url) json->save-reply http-post*)) So it does not push code, but a URL from which the code can be downloaded. Thus it requires the code to be available from the Internet; local code is "safe" from SWH. Now I do not know what will happen if you save your code as a git repository at a hidden URL. For instance, does SWH check the license? I would hope so. There is documentation of this feature here: https://archive.softwareheritage.org/api/1/origin/save/doc/ which says this: Depending of the provided origin url, the save request can either be: - immediately accepted, for well known code hosting providers like for instance GitHub or GitLab - rejected, in case the url is blacklisted by Software Heritage - put in pending state until a manual check is done in order to determine if it can be loaded or not So I suppose that if you submit a hidden, but publicly available URL pointing to non-free code, the request will be "put in pending state", manually checked and rejected, and maybe the URL added to the blacklist. Andreas