Hi pinoaffe! I hope you excuse the harsher tone in my previous email. I also hope you understand.
I see now that me phrasing stuff in a lighter, less official tone may have given the impression that I do these things without giving them enough thought. That was of course not the case. I am not sure I am willing to use super-cereal tones for the work I do here—it just doesn't rock my boat. On Wed, Sep 16, 2026 at 05:01:57PM +0200, pinoaffe wrote: > It is good that the automatic PRs are marked as such, but it would have > been better if that had been described/documented (and communicated) > beforehand. Please excuse the perceived lack of communication/documentation. I was *very* excited to get a first, useful version up and running and telling y'all about it. > Based on your earlier phrasing it sounded like it might do periodic > polling of packages, which would open up many more possibilities for > accidental PR floods. Sorry, probably my bad. This is one possible outlook for the program: to run regularly (say, weekly) for a module or a manifest or something like that. > While this may ultimately be a good way to have the human in the loop, I > don't think this is adequate while GGABS is still "young". I think this > is an especially inadequate approach if you are going to be AFK for a > while in this early phase. Did I say AFK? I was on holidays, but still saw email reaching my inbox; I even had a computer with me for emergencies. But, and I seem to be unable to stress this enough, this was not a rough prototype, but a program I had written (and tested!) during the prior weeks. I was well aware of its capabilities and possible failure modes. > Good that it logs, but this means they are not available. I think > long-term it would be good if logs were to be available - both > per-updater logs and per-package/per-update logs. The latter could even > be linked in the PR, but I understand that this is not part of an "MVP". Absolutely! It is part of my vision to (automatically) publish useful logs, or maybe even open Issues on Codeberg with the build failure logs attached. > As far as I can tell, you did not publicly state them anywhere, hence > they were not well-known. Please excuse. I am happy to answer any and all questions in this regard! > I don't think there's a need to explicitly ask for permission. Great! Me neither! > If I were to introduce something like GGABS, I would personally have > first let it loose on an intentionally outdated fork of guix for a > couple of weeks/months This is *exactly* what I did. > so that: > - we can see what it behaves like in practice > - we can hopefully catch any bugs, > - we can see what it misses compared to manual updates that have landed > on guix proper, > - and so that others can see it and voice any concerns before it is let > loose on guix proper. I think I cordially invited all y'all for collaboration, didn't I? And yes, I did exactly that. Except for doing it by myself. > In other words, I would be very hesitant to unleash something like > GGABS, so that we can first ensure that it will be helpful rather than a > nuisance. Believe me or not, I did exactly that. I mean, honestly: what sense would it make for me to annoy myself? In my own inbox? During my holidays? With a script I wrote that produces garbage? I mean I am not too fond of myself, but I don't hate myself *that* much ;) > I would have hoped that you too had been somewhat more hesitant. Hesitant with what? AFAICT I did everything the way you'd have wanted me to do it. Somehow you just did not expect that? Again, please excuse the missing info before I excused myself to my much needed holidays. I thought informing the list about my experiments and linking to the project (which includes an exhaustive README and not-incredibly-cryptic source code) would be enough. > I wouldn't consider this misbehaviour per sé, as I like to assume you > did so out of excitement and in good faith. I am thankful you consider excitement and good faith. I am a bit concerned about the framing of my work for the project on my personal infrastructure as misbehaviour. Or even the suggestion, for that matter. I understand that my name has taken quite a toll and that my actions currently are under some sort of general suspicion. But I believe that, if you look at my contributions to the project, you get an idea of how serious I take things around here. Not that I can (or intend to) convince anybody of anything. Please just realize how much of a toll it is to *constantly* having to defend my well-intended, IMHO adequately crafted actions against people who seemingly assume bad faith from my side. This is not how things should be. > How the PRs are generated is not relevant to the "spam-iness", the level > of informed consent is, as is the volume. So far, the volume has been > relatively small, but we could not realistically have known what to > expect given the scarce information you gave beforehand. I have some issues bringing these phrases and your assumption of my good faith together. What exactly did you want to "know what to expect"? > [...] my issue was that you did not communicate your expectations as > to the bots behaviour beforehand I think I did. Please excuse if my communication did not match your expectations. But also realize that this were somewhat impossible to achieve. > doing something with relatively high potential for harm Excuse me, again: what high potential for harm? In the worst of cases, one single Codeberg user would have filed a bunch of faulty PRs on Codeberg. This harm could have dealt with by deleting the PRs and/or blocking the offending user. This would have cost a single person with the adequate rights mere seconds to deal with. Are you imagining other harm? Please, if you assume good faith, also assume that I would not do stuff to carelessly jeopardize this project and/or infrastructure. I—as I guess most of us here—am too involved and have invested too much to carelessly destroy anything, lose it all or just give it all up. Thanks you all for trying to understand. I wish splendid evenings! gabriel / gabber
