Fedora Forge Usage Policy

Hi @frostyx , sorry for missing this feedback! I have been responding to feedback in the discussion category. I can address your points now, but please use the discussion category if you have any more feedback to share so I dont forget to reply here again :sweat_smile:

  1. open a ticket on the Fedora Infrastructure tracker, detailing the project’s purpose

I am not a member of neither Fedora Infra, Forge team, FESCo, or Fedora Council so this doesn’t particularly affect me, but using Fedora Infra ticket tracker for requesting exceptions, and having Fedora Infra team to triage them sounds a bit weird to me. Especially when new organizations are being requested in the Forge team repository. I’d probably expect the project exceptions to be requested on the same place.

This is intentional. The Fedora Forge team is a dev team mainly, and we do not expect them to make decisions on requests for resources from ‘edge cases’. This is more appropriately decided by infra, who have the highest perms and trust, or if they are unable to/unsure, infra may bounce it to FESCo for final decision.

  • If you are leaving the project, please transfer ownership of any critical tools to a Fedora Organization or an active co-maintainer before your departure.

Since we are not allowed to host projects in our personal namespace and everything needs to be under some organisation, this should never happen?

Technically no, it should not. But this point is mainly referring to if someone is leaving the project that maintains a repo that has critical tools in use by the Fedora Project mainly for releases, and not referring to someone who has a personal namespace that is still doing work for/with Fedora that might not be ‘critical’ to releases. This is my interpretation/understanding of this point. If anyone would like to clarify it further, patch welcome :slight_smile:

  • System Abuse: Engaging in activities that degrade the performance of the Forgejo instance or its runners, such as aggressive network scraping, DDoS attacks, or intentionally triggering infinite CI loops.

I remember GitHub recently had some issues with gigantic AI generated repositories that either had too much code or too much commits, causing some performance problems. I don’t have the exact issues at hand, but I can try to find them if needed.

Would this be covered by “System Abuse”? Should we make it explicit?

Yes, and this falls under ‘Resource Limits’ with the repository size limited to 500mb.

  • Using the Forge or its CI/CD runners to mine cryptocurrency is strictly forbidden and will result in an immediate, permanent ban.

It’s a bit weird that this bullet point explains the punishment, but the others ones don’t.

Youre right. I think we should drop the ‘result in an immediate, permanent ban’ part from that sentence and move it to the start of the paragraph. I will reword that a little in v.3 of the policy.

  • no activity after trying to contact the organization owners.**.

Something got lost from between the asterisks, probably :slight_smile:

I dont even know what they are referring to - deleting from v.3 :sweat_smile:

  • your personal namespace may be archived or removed if your account remains inactive for an extended period

It would be fair to ballpark what “extended period” is - weeks / months / years?

This caused a lot of back and forth in council and others. We eventually agreed to leave off any timeframe from the policy and allow the Fedora Infra team discretion on how long a period of inactivity is.

7. Support and Abuse Reporting

I am missing a bullet point about reporting the Prohibited Activities as described above. Where do I report Fedora unrelated projects, proprietary material, or exposed secrets?

The links might not have stuck when the post was added to this category. Theres links in the original draft in the council wiki on forge Making sure you're not a bot!.

I will be posting v.3 of this policy in the next day or two including your feedback on the post in the discussion category so please follow along there, and thank you for your points, they have been very useful!

1 Like