SlideShare a Scribd company logo
1 of 51
Lars Kurth
Community Manager, Xen Project
Chairman, Xen Project Advisory Board
Director, Open Source Business Office, Citrix lars_kurth
Theory: Open Source Flywheel
The demands on what vendors and users want from Xen Project is changing using the Flywheel to illustrate
The project has a recent history of change
Example: The history of the Security Vulnerability Management Process
Other examples of recent and ongoing changes
New demands on the project: New Features/Community Growth vs. Review Process and Review Capacity
New demands on the project: New Features/Community Growth vs. Quality and Security
Feature Lifecycle Management and Documentation
Open Source Flywheel
[1] bit.do/optionvalue
Tragedy of the Commons
(sort of)
Moyan Brenn @ Flickr
snoopsmouse @ Flickr
Source: Ohloh.net
Prior to Heartbleed
Growing Codebase
Static and small contributor base
1 person maintaining 100 KLoC =
Underinvestment
Extremely large user base
Critical infrastructure component
Thus impact of Heartbleed is huge
Heartbleed
Stay vigilant to sustain a
balanced Flywheel
Vinovyn @ Flickr
The Demands on what vendors
and users want from Xen Project
is changing
Vinovyn @ Flickr
External factors are accelerating
the amount of change
Evolution of
Xen Project Security Vulnerability Process
xenproject.org/security-policy.html
2011 2012 2013 2014 2015 2016
Goals:
Allow fixing, packaging and testing;
Allow service providers to prepare (but not deploy) during embargo
Pre-disclosure:
Membership biased towards distros & large service providers
No predefined disclosure time
1.0
2011 2012 2013 2014 2015 2016
July 2012: CVE-2012-0217, Intel SYSRET
Affected FreeBSD, NetBSD, Solaris, Xen and Microsoft Windows
A large pre-disclosure list member put pressure on
key members of the Xen Project Community to get an embargo
extension
They eventually convinced the discoverer to request an extension
1.0
2011 2012 2013 2014 2015 2016
Centered on:
Predetermined disclosure schedule: 1 week to fix, 2 weeks embargo
Who should be allowed on the pre-disclosure list
Fairness issues between small and large service providers
Direct vs. indirect Xen consumers
The risk of larger pre-disclosure list membership
1.0
2011 2012 2013 2014 2015 2016
Strongly recommended disclosure schedule
Inclusive pre-disclosure list membership
Changes to application procedure (based on checkable criteria)
1.0 2.0
2011 2012 2013 2014 2015 2016
Sept 2014: CVE-2014-7118
Leading to the first Cloud Reboot
AWS pre-announced cloud reboot to their customers
Other vendors didn’t.
Policy was interpreted differently by vendors.
This highlighted ambiguities in the project’s security policy
(what can/can’t be said/done during an embargo)
1.0 2.0
2011 2012 2013 2014 2015 2016
Goals:
Allow fixing, packaging and testing
Allow service providers to prepare (and normally to deploy) during embargo
Pre-disclosure:
Clearer application criteria
Public application process (transparency)
Clear information on what is/is not allowed during an embargo (per XSA)
Means for pre-disclosure list members to collaborate
1.0 2.0 3.0
2011 2012 2013 2014 2015 2016
Conducted XSA-133 Retrospective upon request
Process change: Earlier embargoed pre-disclosure without patches
May 2015: CVE-2015-3456
First time we were affected by a branded bug
QEMU bug, which was handled by several security teams: QEMU,
OSS Distro Security, Oracle Security & Xen Project
From a process perspective: were not able to provide a
fix 2 weeks before the embargo date ended
1.0 2.0 3.0
Of other recent changes
And changes under discussion
More focus on design reviews, designs as specs, in-code API docs
• Avoid disagreement later in the review cycle
• Create a “knowledge base” for new developers
Design Reviews
Design Docs
API Docs
Increased Focus on Quality
Share the cost of testing (Past: everyone tested independently)
Test Lab
OSSTEST
Slightly shorter release cycle
Harder freeze dates
Branch master earlier  longer active development period
Release
Management
4.6
Release
Management
4.7
Short and fixed release cycle (June and December)
Even harder freeze dates: no feature freeze exceptions
• Make it easier for consumers of Xen to plan their products
• Decrease the impact of features not making it into Xen x.y
Change Description
• Better understanding of feature maturity for users
• Encourage more testing: only tested features can be “supported”
• Find a way to classify non-core features
Feature
Maturity
Lifecycle
• Not optimized for “process and convention changes”
• Make the process clearer and streamline it
Decision
Making
• Contributing to Xen has become harder
• This just happened, without being discussed, and came as a surprise
• Caused issues because of mismatching expectations
Review Process
Review Criteria
Contribution
Reporting
• Find better ways to high-light non-code contributions
• Encourage more code reviews and tests
Change Goals
Conducted a survey in Q3’15: still early days
• Highlighted different expectations by different people
• Have a range of options to improve things
Roles /
Project
Leadership
The project is adapting to a
changing environment
Don’t get caught out by changes
Participate in discussions
Vinovyn @ Flickr
Review Capacity
Review Criteria
New Features
Community Growth
We managed to part-fix
this through training of
new contributors,
process changes,
better co-ordination
Tougher requirements on Quality
gradually happened
There was no discussion about the quality-
contribution trade-off, which led to surprises
and some contributors having wrong
expectations
In fact: we didn’t know this was happening until
recently
Vinovyn @ Flickr
For new contributors contributing up to smaller 10-15 patches per year:
– None
For new contributors planning to contributing complex and 15+ patches per year:
– Reviewers are less willing to review patches without getting something in return
At a minimum:
– Engage with the Roadmap Process : Communicate your priorities
– Submit early in the review process and submit designs early for complex code
– Have realistic expectations
Ideally:
– Observe patch reviews on xen-devel@ and help with patch reviews of other people’s code
– Help with testing (test days, test reports, test code)
– Long term: work towards maintainership of components/features you care about
100 - 500 patches under active review
Patch series A
…
Patch series B
…
Patch series N
…
Reviewer 1
Reviewer 2
Reviewer 3
Reviewers review according
to their own schedule and
own priorities.
There is no centralized
priority list.
You may need to ping
reviewers: overdoing this is
counter-productive (may be
considered as hassling).
Quality, Security
Different use-cases
New Features
Community Growth
Media coverage is just a side-effect.
We care about …
– There are people out there trying to break Xen
– And use exploits against Xen users
This means …
– Code is reviewed with security in mind
– Think about security when designing a feature
– Think about security before submitting a patch
– You may be asked to modify related code that is related to your patch
(often reviewers code “surrounding” your patch)
Fix some Coverity Scan Issues
– You can get access : see xenproject.org/help/contribution-guidelines.html
– Small, bite-size issues to practice contributing to Xen
Proposal @
http://lists.xenproject.org/archives/html/xen-
devel/2015-11/msg00609.html
Preview Part
Experimental Core
Complete (New) Full Yes Yes Yes Yes
Supported (New) Full Yes Yes Yes Yes
Supported-Legacy-Stable Full Yes Yes
Preview Dev* No No
Experimental Dev* No No
Complete (New) Dev* No** No
Supported (New) Yes Yes Yes
Supported-Legacy-Stable Yes Yes Yes
This is a state which has not
existed in the past. It is aimed
at larger new features, which
may only be in use or of interest
to a small number of contributors,
or where not enough expertise
exists in the community to treat
the feature as Supported.
*) At developer(s) discretion
**) At Release Managers discretion
Complete is aimed at non-core use-cases
– Defuse tensions for non-core features
– Cover for the case where we loose the capability to support
Supported requires automated testing or manual testing during RC
phase (otherwise it may be downgraded to Complete)
Supported-Legacy-Stable accounts for the fact that many features that
existed for a long time, may not be documented or automatically tested
– Phase out over time
Too many similar states
– Need to simplify
Some Open Questions
– Templates and Exact Format of Feature Status
– Location of files
– How to handle legacy
Traditionally we treated designs review different to code reviews
– Using PDFs and Text Designs on xen-devel@
– Issues: Agreements and changes are not tracked
Emerging Alternative
– Post designs as patches in xen.git @ docs/… folders
– Example: xen.git @ docs/misc/xsplice.markup with discussion at
lists.xen.org/archives/html/xen-devel/2015-11/msg00244.html
– Using pandoc markdown language and templates
(see pandoc.org/README.html#pandocs-markdown)
– Advantages:
1. ACKs are tracked  It is clear who agreed with the design
2. Design evolves with the code  Change the design doc with patches (include into series)
3. Easy to read and write  Can generate html, pdf’s, etc.

More Related Content

Viewers also liked

Xen Project Contributor Training Part 2 - Processes and Conventions v1.0
Xen Project Contributor Training Part 2 - Processes and Conventions v1.0Xen Project Contributor Training Part 2 - Processes and Conventions v1.0
Xen Project Contributor Training Part 2 - Processes and Conventions v1.0The Linux Foundation
 
Xen Project Contributor Training - Part 1 introduction v1.0
Xen Project Contributor Training - Part 1 introduction v1.0Xen Project Contributor Training - Part 1 introduction v1.0
Xen Project Contributor Training - Part 1 introduction v1.0The Linux Foundation
 
XPDS16: A Paravirtualized Interface for Socket Syscalls - Dimitri Stiliadis, ...
XPDS16: A Paravirtualized Interface for Socket Syscalls - Dimitri Stiliadis, ...XPDS16: A Paravirtualized Interface for Socket Syscalls - Dimitri Stiliadis, ...
XPDS16: A Paravirtualized Interface for Socket Syscalls - Dimitri Stiliadis, ...The Linux Foundation
 
LF Collaboration Summit: Xen Project 4 4 Features and Futures
LF Collaboration Summit: Xen Project 4 4 Features and FuturesLF Collaboration Summit: Xen Project 4 4 Features and Futures
LF Collaboration Summit: Xen Project 4 4 Features and FuturesThe Linux Foundation
 
Rootlinux17: An introduction to Xen Project Virtualisation
Rootlinux17:  An introduction to Xen Project VirtualisationRootlinux17:  An introduction to Xen Project Virtualisation
Rootlinux17: An introduction to Xen Project VirtualisationThe Linux Foundation
 

Viewers also liked (6)

Xen Project Contributor Training Part 2 - Processes and Conventions v1.0
Xen Project Contributor Training Part 2 - Processes and Conventions v1.0Xen Project Contributor Training Part 2 - Processes and Conventions v1.0
Xen Project Contributor Training Part 2 - Processes and Conventions v1.0
 
Xen Project Contributor Training - Part 1 introduction v1.0
Xen Project Contributor Training - Part 1 introduction v1.0Xen Project Contributor Training - Part 1 introduction v1.0
Xen Project Contributor Training - Part 1 introduction v1.0
 
XPDS16: A Paravirtualized Interface for Socket Syscalls - Dimitri Stiliadis, ...
XPDS16: A Paravirtualized Interface for Socket Syscalls - Dimitri Stiliadis, ...XPDS16: A Paravirtualized Interface for Socket Syscalls - Dimitri Stiliadis, ...
XPDS16: A Paravirtualized Interface for Socket Syscalls - Dimitri Stiliadis, ...
 
LF Collaboration Summit: Xen Project 4 4 Features and Futures
LF Collaboration Summit: Xen Project 4 4 Features and FuturesLF Collaboration Summit: Xen Project 4 4 Features and Futures
LF Collaboration Summit: Xen Project 4 4 Features and Futures
 
Performance Tuning Xen
Performance Tuning XenPerformance Tuning Xen
Performance Tuning Xen
 
Rootlinux17: An introduction to Xen Project Virtualisation
Rootlinux17:  An introduction to Xen Project VirtualisationRootlinux17:  An introduction to Xen Project Virtualisation
Rootlinux17: An introduction to Xen Project Virtualisation
 

Similar to Managing Change in Open Source Projects

Software Process Models
Software Process ModelsSoftware Process Models
Software Process ModelsHassan A-j
 
XPDDS19 Keynote: Xen Project Weather Report 2019 - Lars Kurth, Director of Op...
XPDDS19 Keynote: Xen Project Weather Report 2019 - Lars Kurth, Director of Op...XPDDS19 Keynote: Xen Project Weather Report 2019 - Lars Kurth, Director of Op...
XPDDS19 Keynote: Xen Project Weather Report 2019 - Lars Kurth, Director of Op...The Linux Foundation
 
Software Development Taxonomy
Software Development TaxonomySoftware Development Taxonomy
Software Development TaxonomyAli Gholami
 
Introduction to Agile Software Development Process
Introduction to Agile Software Development ProcessIntroduction to Agile Software Development Process
Introduction to Agile Software Development ProcessSoftware Park Thailand
 
Introduction to Software Engineering
Introduction to Software EngineeringIntroduction to Software Engineering
Introduction to Software EngineeringSaqib Raza
 
Software development process basic
Software development process basicSoftware development process basic
Software development process basicAnurag Tomar
 
Seminar on Crystal Clear
Seminar on Crystal ClearSeminar on Crystal Clear
Seminar on Crystal ClearPaolo Farina
 
Software Developement Life Cycle ppt.pptx
Software Developement Life Cycle ppt.pptxSoftware Developement Life Cycle ppt.pptx
Software Developement Life Cycle ppt.pptxAbcXyz141938
 
Software process life cycles
Software process life cyclesSoftware process life cycles
Software process life cycles sathish sak
 
OSSJP/ALS19: The Road to Safety Certification: How the Xen Project is Making...
 OSSJP/ALS19: The Road to Safety Certification: How the Xen Project is Making... OSSJP/ALS19: The Road to Safety Certification: How the Xen Project is Making...
OSSJP/ALS19: The Road to Safety Certification: How the Xen Project is Making...The Linux Foundation
 
Applying both of waterfall and iterative development
Applying both of waterfall and iterative developmentApplying both of waterfall and iterative development
Applying both of waterfall and iterative developmentDeny Prasetia
 

Similar to Managing Change in Open Source Projects (20)

Software Process Models
Software Process ModelsSoftware Process Models
Software Process Models
 
system development life cycle
system development life cyclesystem development life cycle
system development life cycle
 
XPDDS19 Keynote: Xen Project Weather Report 2019 - Lars Kurth, Director of Op...
XPDDS19 Keynote: Xen Project Weather Report 2019 - Lars Kurth, Director of Op...XPDDS19 Keynote: Xen Project Weather Report 2019 - Lars Kurth, Director of Op...
XPDDS19 Keynote: Xen Project Weather Report 2019 - Lars Kurth, Director of Op...
 
The Waterfall Model
The Waterfall ModelThe Waterfall Model
The Waterfall Model
 
Software Development Life Cycle Part II
Software Development Life Cycle Part IISoftware Development Life Cycle Part II
Software Development Life Cycle Part II
 
Software Development Taxonomy
Software Development TaxonomySoftware Development Taxonomy
Software Development Taxonomy
 
Introduction to Agile Software Development Process
Introduction to Agile Software Development ProcessIntroduction to Agile Software Development Process
Introduction to Agile Software Development Process
 
Introduction to Software Engineering
Introduction to Software EngineeringIntroduction to Software Engineering
Introduction to Software Engineering
 
Software development process basic
Software development process basicSoftware development process basic
Software development process basic
 
what-is-devops.ppt
what-is-devops.pptwhat-is-devops.ppt
what-is-devops.ppt
 
Seminar on Crystal Clear
Seminar on Crystal ClearSeminar on Crystal Clear
Seminar on Crystal Clear
 
System Development Life Cycle (SDLC) - Part II
System Development Life Cycle (SDLC) - Part IISystem Development Life Cycle (SDLC) - Part II
System Development Life Cycle (SDLC) - Part II
 
April 08
April 08April 08
April 08
 
Software Developement Life Cycle ppt.pptx
Software Developement Life Cycle ppt.pptxSoftware Developement Life Cycle ppt.pptx
Software Developement Life Cycle ppt.pptx
 
software lecture
software lecturesoftware lecture
software lecture
 
Rajesh Paleru
Rajesh PaleruRajesh Paleru
Rajesh Paleru
 
Software process life cycles
Software process life cyclesSoftware process life cycles
Software process life cycles
 
OSSJP/ALS19: The Road to Safety Certification: How the Xen Project is Making...
 OSSJP/ALS19: The Road to Safety Certification: How the Xen Project is Making... OSSJP/ALS19: The Road to Safety Certification: How the Xen Project is Making...
OSSJP/ALS19: The Road to Safety Certification: How the Xen Project is Making...
 
Applying both of waterfall and iterative development
Applying both of waterfall and iterative developmentApplying both of waterfall and iterative development
Applying both of waterfall and iterative development
 
01lifecycles
01lifecycles01lifecycles
01lifecycles
 

More from The Linux Foundation

ELC2019: Static Partitioning Made Simple
ELC2019: Static Partitioning Made SimpleELC2019: Static Partitioning Made Simple
ELC2019: Static Partitioning Made SimpleThe Linux Foundation
 
XPDDS19: How TrenchBoot is Enabling Measured Launch for Open-Source Platform ...
XPDDS19: How TrenchBoot is Enabling Measured Launch for Open-Source Platform ...XPDDS19: How TrenchBoot is Enabling Measured Launch for Open-Source Platform ...
XPDDS19: How TrenchBoot is Enabling Measured Launch for Open-Source Platform ...The Linux Foundation
 
XPDDS19 Keynote: Xen in Automotive - Artem Mygaiev, Director, Technology Solu...
XPDDS19 Keynote: Xen in Automotive - Artem Mygaiev, Director, Technology Solu...XPDDS19 Keynote: Xen in Automotive - Artem Mygaiev, Director, Technology Solu...
XPDDS19 Keynote: Xen in Automotive - Artem Mygaiev, Director, Technology Solu...The Linux Foundation
 
XPDDS19 Keynote: Unikraft Weather Report
XPDDS19 Keynote:  Unikraft Weather ReportXPDDS19 Keynote:  Unikraft Weather Report
XPDDS19 Keynote: Unikraft Weather ReportThe Linux Foundation
 
XPDDS19 Keynote: Secret-free Hypervisor: Now and Future - Wei Liu, Software E...
XPDDS19 Keynote: Secret-free Hypervisor: Now and Future - Wei Liu, Software E...XPDDS19 Keynote: Secret-free Hypervisor: Now and Future - Wei Liu, Software E...
XPDDS19 Keynote: Secret-free Hypervisor: Now and Future - Wei Liu, Software E...The Linux Foundation
 
XPDDS19 Keynote: Xen Dom0-less - Stefano Stabellini, Principal Engineer, Xilinx
XPDDS19 Keynote: Xen Dom0-less - Stefano Stabellini, Principal Engineer, XilinxXPDDS19 Keynote: Xen Dom0-less - Stefano Stabellini, Principal Engineer, Xilinx
XPDDS19 Keynote: Xen Dom0-less - Stefano Stabellini, Principal Engineer, XilinxThe Linux Foundation
 
XPDDS19 Keynote: Patch Review for Non-maintainers - George Dunlap, Citrix Sys...
XPDDS19 Keynote: Patch Review for Non-maintainers - George Dunlap, Citrix Sys...XPDDS19 Keynote: Patch Review for Non-maintainers - George Dunlap, Citrix Sys...
XPDDS19 Keynote: Patch Review for Non-maintainers - George Dunlap, Citrix Sys...The Linux Foundation
 
XPDDS19: Memories of a VM Funk - Mihai Donțu, Bitdefender
XPDDS19: Memories of a VM Funk - Mihai Donțu, BitdefenderXPDDS19: Memories of a VM Funk - Mihai Donțu, Bitdefender
XPDDS19: Memories of a VM Funk - Mihai Donțu, BitdefenderThe Linux Foundation
 
OSSJP/ALS19: The Road to Safety Certification: Overcoming Community Challeng...
OSSJP/ALS19:  The Road to Safety Certification: Overcoming Community Challeng...OSSJP/ALS19:  The Road to Safety Certification: Overcoming Community Challeng...
OSSJP/ALS19: The Road to Safety Certification: Overcoming Community Challeng...The Linux Foundation
 
XPDDS19: Speculative Sidechannels and Mitigations - Andrew Cooper, Citrix
XPDDS19: Speculative Sidechannels and Mitigations - Andrew Cooper, CitrixXPDDS19: Speculative Sidechannels and Mitigations - Andrew Cooper, Citrix
XPDDS19: Speculative Sidechannels and Mitigations - Andrew Cooper, CitrixThe Linux Foundation
 
XPDDS19: Keeping Coherency on Arm: Reborn - Julien Grall, Arm ltd
XPDDS19: Keeping Coherency on Arm: Reborn - Julien Grall, Arm ltdXPDDS19: Keeping Coherency on Arm: Reborn - Julien Grall, Arm ltd
XPDDS19: Keeping Coherency on Arm: Reborn - Julien Grall, Arm ltdThe Linux Foundation
 
XPDDS19: QEMU PV Backend 'qdevification'... What Does it Mean? - Paul Durrant...
XPDDS19: QEMU PV Backend 'qdevification'... What Does it Mean? - Paul Durrant...XPDDS19: QEMU PV Backend 'qdevification'... What Does it Mean? - Paul Durrant...
XPDDS19: QEMU PV Backend 'qdevification'... What Does it Mean? - Paul Durrant...The Linux Foundation
 
XPDDS19: Status of PCI Emulation in Xen - Roger Pau Monné, Citrix Systems R&D
XPDDS19: Status of PCI Emulation in Xen - Roger Pau Monné, Citrix Systems R&DXPDDS19: Status of PCI Emulation in Xen - Roger Pau Monné, Citrix Systems R&D
XPDDS19: Status of PCI Emulation in Xen - Roger Pau Monné, Citrix Systems R&DThe Linux Foundation
 
XPDDS19: [ARM] OP-TEE Mediator in Xen - Volodymyr Babchuk, EPAM Systems
XPDDS19: [ARM] OP-TEE Mediator in Xen - Volodymyr Babchuk, EPAM SystemsXPDDS19: [ARM] OP-TEE Mediator in Xen - Volodymyr Babchuk, EPAM Systems
XPDDS19: [ARM] OP-TEE Mediator in Xen - Volodymyr Babchuk, EPAM SystemsThe Linux Foundation
 
XPDDS19: Bringing Xen to the Masses: The Story of Building a Community-driven...
XPDDS19: Bringing Xen to the Masses: The Story of Building a Community-driven...XPDDS19: Bringing Xen to the Masses: The Story of Building a Community-driven...
XPDDS19: Bringing Xen to the Masses: The Story of Building a Community-driven...The Linux Foundation
 
XPDDS19: Will Robots Automate Your Job Away? Streamlining Xen Project Contrib...
XPDDS19: Will Robots Automate Your Job Away? Streamlining Xen Project Contrib...XPDDS19: Will Robots Automate Your Job Away? Streamlining Xen Project Contrib...
XPDDS19: Will Robots Automate Your Job Away? Streamlining Xen Project Contrib...The Linux Foundation
 
XPDDS19: Client Virtualization Toolstack in Go - Nick Rosbrook & Brendan Kerr...
XPDDS19: Client Virtualization Toolstack in Go - Nick Rosbrook & Brendan Kerr...XPDDS19: Client Virtualization Toolstack in Go - Nick Rosbrook & Brendan Kerr...
XPDDS19: Client Virtualization Toolstack in Go - Nick Rosbrook & Brendan Kerr...The Linux Foundation
 
XPDDS19: Core Scheduling in Xen - Jürgen Groß, SUSE
XPDDS19: Core Scheduling in Xen - Jürgen Groß, SUSEXPDDS19: Core Scheduling in Xen - Jürgen Groß, SUSE
XPDDS19: Core Scheduling in Xen - Jürgen Groß, SUSEThe Linux Foundation
 
XPDDS19: Implementing AMD MxGPU - Jonathan Farrell, Assured Information Security
XPDDS19: Implementing AMD MxGPU - Jonathan Farrell, Assured Information SecurityXPDDS19: Implementing AMD MxGPU - Jonathan Farrell, Assured Information Security
XPDDS19: Implementing AMD MxGPU - Jonathan Farrell, Assured Information SecurityThe Linux Foundation
 
XPDDS19: Support of PV Devices in Nested Xen - Jürgen Groß, SUSE
XPDDS19: Support of PV Devices in Nested Xen - Jürgen Groß, SUSEXPDDS19: Support of PV Devices in Nested Xen - Jürgen Groß, SUSE
XPDDS19: Support of PV Devices in Nested Xen - Jürgen Groß, SUSEThe Linux Foundation
 

More from The Linux Foundation (20)

ELC2019: Static Partitioning Made Simple
ELC2019: Static Partitioning Made SimpleELC2019: Static Partitioning Made Simple
ELC2019: Static Partitioning Made Simple
 
XPDDS19: How TrenchBoot is Enabling Measured Launch for Open-Source Platform ...
XPDDS19: How TrenchBoot is Enabling Measured Launch for Open-Source Platform ...XPDDS19: How TrenchBoot is Enabling Measured Launch for Open-Source Platform ...
XPDDS19: How TrenchBoot is Enabling Measured Launch for Open-Source Platform ...
 
XPDDS19 Keynote: Xen in Automotive - Artem Mygaiev, Director, Technology Solu...
XPDDS19 Keynote: Xen in Automotive - Artem Mygaiev, Director, Technology Solu...XPDDS19 Keynote: Xen in Automotive - Artem Mygaiev, Director, Technology Solu...
XPDDS19 Keynote: Xen in Automotive - Artem Mygaiev, Director, Technology Solu...
 
XPDDS19 Keynote: Unikraft Weather Report
XPDDS19 Keynote:  Unikraft Weather ReportXPDDS19 Keynote:  Unikraft Weather Report
XPDDS19 Keynote: Unikraft Weather Report
 
XPDDS19 Keynote: Secret-free Hypervisor: Now and Future - Wei Liu, Software E...
XPDDS19 Keynote: Secret-free Hypervisor: Now and Future - Wei Liu, Software E...XPDDS19 Keynote: Secret-free Hypervisor: Now and Future - Wei Liu, Software E...
XPDDS19 Keynote: Secret-free Hypervisor: Now and Future - Wei Liu, Software E...
 
XPDDS19 Keynote: Xen Dom0-less - Stefano Stabellini, Principal Engineer, Xilinx
XPDDS19 Keynote: Xen Dom0-less - Stefano Stabellini, Principal Engineer, XilinxXPDDS19 Keynote: Xen Dom0-less - Stefano Stabellini, Principal Engineer, Xilinx
XPDDS19 Keynote: Xen Dom0-less - Stefano Stabellini, Principal Engineer, Xilinx
 
XPDDS19 Keynote: Patch Review for Non-maintainers - George Dunlap, Citrix Sys...
XPDDS19 Keynote: Patch Review for Non-maintainers - George Dunlap, Citrix Sys...XPDDS19 Keynote: Patch Review for Non-maintainers - George Dunlap, Citrix Sys...
XPDDS19 Keynote: Patch Review for Non-maintainers - George Dunlap, Citrix Sys...
 
XPDDS19: Memories of a VM Funk - Mihai Donțu, Bitdefender
XPDDS19: Memories of a VM Funk - Mihai Donțu, BitdefenderXPDDS19: Memories of a VM Funk - Mihai Donțu, Bitdefender
XPDDS19: Memories of a VM Funk - Mihai Donțu, Bitdefender
 
OSSJP/ALS19: The Road to Safety Certification: Overcoming Community Challeng...
OSSJP/ALS19:  The Road to Safety Certification: Overcoming Community Challeng...OSSJP/ALS19:  The Road to Safety Certification: Overcoming Community Challeng...
OSSJP/ALS19: The Road to Safety Certification: Overcoming Community Challeng...
 
XPDDS19: Speculative Sidechannels and Mitigations - Andrew Cooper, Citrix
XPDDS19: Speculative Sidechannels and Mitigations - Andrew Cooper, CitrixXPDDS19: Speculative Sidechannels and Mitigations - Andrew Cooper, Citrix
XPDDS19: Speculative Sidechannels and Mitigations - Andrew Cooper, Citrix
 
XPDDS19: Keeping Coherency on Arm: Reborn - Julien Grall, Arm ltd
XPDDS19: Keeping Coherency on Arm: Reborn - Julien Grall, Arm ltdXPDDS19: Keeping Coherency on Arm: Reborn - Julien Grall, Arm ltd
XPDDS19: Keeping Coherency on Arm: Reborn - Julien Grall, Arm ltd
 
XPDDS19: QEMU PV Backend 'qdevification'... What Does it Mean? - Paul Durrant...
XPDDS19: QEMU PV Backend 'qdevification'... What Does it Mean? - Paul Durrant...XPDDS19: QEMU PV Backend 'qdevification'... What Does it Mean? - Paul Durrant...
XPDDS19: QEMU PV Backend 'qdevification'... What Does it Mean? - Paul Durrant...
 
XPDDS19: Status of PCI Emulation in Xen - Roger Pau Monné, Citrix Systems R&D
XPDDS19: Status of PCI Emulation in Xen - Roger Pau Monné, Citrix Systems R&DXPDDS19: Status of PCI Emulation in Xen - Roger Pau Monné, Citrix Systems R&D
XPDDS19: Status of PCI Emulation in Xen - Roger Pau Monné, Citrix Systems R&D
 
XPDDS19: [ARM] OP-TEE Mediator in Xen - Volodymyr Babchuk, EPAM Systems
XPDDS19: [ARM] OP-TEE Mediator in Xen - Volodymyr Babchuk, EPAM SystemsXPDDS19: [ARM] OP-TEE Mediator in Xen - Volodymyr Babchuk, EPAM Systems
XPDDS19: [ARM] OP-TEE Mediator in Xen - Volodymyr Babchuk, EPAM Systems
 
XPDDS19: Bringing Xen to the Masses: The Story of Building a Community-driven...
XPDDS19: Bringing Xen to the Masses: The Story of Building a Community-driven...XPDDS19: Bringing Xen to the Masses: The Story of Building a Community-driven...
XPDDS19: Bringing Xen to the Masses: The Story of Building a Community-driven...
 
XPDDS19: Will Robots Automate Your Job Away? Streamlining Xen Project Contrib...
XPDDS19: Will Robots Automate Your Job Away? Streamlining Xen Project Contrib...XPDDS19: Will Robots Automate Your Job Away? Streamlining Xen Project Contrib...
XPDDS19: Will Robots Automate Your Job Away? Streamlining Xen Project Contrib...
 
XPDDS19: Client Virtualization Toolstack in Go - Nick Rosbrook & Brendan Kerr...
XPDDS19: Client Virtualization Toolstack in Go - Nick Rosbrook & Brendan Kerr...XPDDS19: Client Virtualization Toolstack in Go - Nick Rosbrook & Brendan Kerr...
XPDDS19: Client Virtualization Toolstack in Go - Nick Rosbrook & Brendan Kerr...
 
XPDDS19: Core Scheduling in Xen - Jürgen Groß, SUSE
XPDDS19: Core Scheduling in Xen - Jürgen Groß, SUSEXPDDS19: Core Scheduling in Xen - Jürgen Groß, SUSE
XPDDS19: Core Scheduling in Xen - Jürgen Groß, SUSE
 
XPDDS19: Implementing AMD MxGPU - Jonathan Farrell, Assured Information Security
XPDDS19: Implementing AMD MxGPU - Jonathan Farrell, Assured Information SecurityXPDDS19: Implementing AMD MxGPU - Jonathan Farrell, Assured Information Security
XPDDS19: Implementing AMD MxGPU - Jonathan Farrell, Assured Information Security
 
XPDDS19: Support of PV Devices in Nested Xen - Jürgen Groß, SUSE
XPDDS19: Support of PV Devices in Nested Xen - Jürgen Groß, SUSEXPDDS19: Support of PV Devices in Nested Xen - Jürgen Groß, SUSE
XPDDS19: Support of PV Devices in Nested Xen - Jürgen Groß, SUSE
 

Recently uploaded

Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
costume and set research powerpoint presentation
costume and set research powerpoint presentationcostume and set research powerpoint presentation
costume and set research powerpoint presentationphoebematthew05
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 

Recently uploaded (20)

Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
costume and set research powerpoint presentation
costume and set research powerpoint presentationcostume and set research powerpoint presentation
costume and set research powerpoint presentation
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 

Managing Change in Open Source Projects

  • 1. Lars Kurth Community Manager, Xen Project Chairman, Xen Project Advisory Board Director, Open Source Business Office, Citrix lars_kurth
  • 2. Theory: Open Source Flywheel The demands on what vendors and users want from Xen Project is changing using the Flywheel to illustrate The project has a recent history of change Example: The history of the Security Vulnerability Management Process Other examples of recent and ongoing changes New demands on the project: New Features/Community Growth vs. Review Process and Review Capacity New demands on the project: New Features/Community Growth vs. Quality and Security Feature Lifecycle Management and Documentation
  • 5.
  • 6.
  • 7.
  • 8.
  • 9. Tragedy of the Commons (sort of) Moyan Brenn @ Flickr
  • 11.
  • 12. Source: Ohloh.net Prior to Heartbleed Growing Codebase Static and small contributor base 1 person maintaining 100 KLoC = Underinvestment Extremely large user base Critical infrastructure component Thus impact of Heartbleed is huge Heartbleed
  • 13.
  • 14. Stay vigilant to sustain a balanced Flywheel Vinovyn @ Flickr
  • 15. The Demands on what vendors and users want from Xen Project is changing Vinovyn @ Flickr
  • 16.
  • 17.
  • 18.
  • 19. External factors are accelerating the amount of change
  • 20. Evolution of Xen Project Security Vulnerability Process xenproject.org/security-policy.html
  • 21. 2011 2012 2013 2014 2015 2016 Goals: Allow fixing, packaging and testing; Allow service providers to prepare (but not deploy) during embargo Pre-disclosure: Membership biased towards distros & large service providers No predefined disclosure time 1.0
  • 22. 2011 2012 2013 2014 2015 2016 July 2012: CVE-2012-0217, Intel SYSRET Affected FreeBSD, NetBSD, Solaris, Xen and Microsoft Windows A large pre-disclosure list member put pressure on key members of the Xen Project Community to get an embargo extension They eventually convinced the discoverer to request an extension 1.0
  • 23. 2011 2012 2013 2014 2015 2016 Centered on: Predetermined disclosure schedule: 1 week to fix, 2 weeks embargo Who should be allowed on the pre-disclosure list Fairness issues between small and large service providers Direct vs. indirect Xen consumers The risk of larger pre-disclosure list membership 1.0
  • 24. 2011 2012 2013 2014 2015 2016 Strongly recommended disclosure schedule Inclusive pre-disclosure list membership Changes to application procedure (based on checkable criteria) 1.0 2.0
  • 25. 2011 2012 2013 2014 2015 2016 Sept 2014: CVE-2014-7118 Leading to the first Cloud Reboot AWS pre-announced cloud reboot to their customers Other vendors didn’t. Policy was interpreted differently by vendors. This highlighted ambiguities in the project’s security policy (what can/can’t be said/done during an embargo) 1.0 2.0
  • 26. 2011 2012 2013 2014 2015 2016 Goals: Allow fixing, packaging and testing Allow service providers to prepare (and normally to deploy) during embargo Pre-disclosure: Clearer application criteria Public application process (transparency) Clear information on what is/is not allowed during an embargo (per XSA) Means for pre-disclosure list members to collaborate 1.0 2.0 3.0
  • 27. 2011 2012 2013 2014 2015 2016 Conducted XSA-133 Retrospective upon request Process change: Earlier embargoed pre-disclosure without patches May 2015: CVE-2015-3456 First time we were affected by a branded bug QEMU bug, which was handled by several security teams: QEMU, OSS Distro Security, Oracle Security & Xen Project From a process perspective: were not able to provide a fix 2 weeks before the embargo date ended 1.0 2.0 3.0
  • 28. Of other recent changes And changes under discussion
  • 29. More focus on design reviews, designs as specs, in-code API docs • Avoid disagreement later in the review cycle • Create a “knowledge base” for new developers Design Reviews Design Docs API Docs Increased Focus on Quality Share the cost of testing (Past: everyone tested independently) Test Lab OSSTEST Slightly shorter release cycle Harder freeze dates Branch master earlier  longer active development period Release Management 4.6 Release Management 4.7 Short and fixed release cycle (June and December) Even harder freeze dates: no feature freeze exceptions • Make it easier for consumers of Xen to plan their products • Decrease the impact of features not making it into Xen x.y Change Description
  • 30. • Better understanding of feature maturity for users • Encourage more testing: only tested features can be “supported” • Find a way to classify non-core features Feature Maturity Lifecycle • Not optimized for “process and convention changes” • Make the process clearer and streamline it Decision Making • Contributing to Xen has become harder • This just happened, without being discussed, and came as a surprise • Caused issues because of mismatching expectations Review Process Review Criteria Contribution Reporting • Find better ways to high-light non-code contributions • Encourage more code reviews and tests Change Goals Conducted a survey in Q3’15: still early days • Highlighted different expectations by different people • Have a range of options to improve things Roles / Project Leadership
  • 31. The project is adapting to a changing environment Don’t get caught out by changes Participate in discussions Vinovyn @ Flickr
  • 32.
  • 33. Review Capacity Review Criteria New Features Community Growth
  • 34.
  • 35.
  • 36.
  • 37. We managed to part-fix this through training of new contributors, process changes, better co-ordination
  • 38. Tougher requirements on Quality gradually happened There was no discussion about the quality- contribution trade-off, which led to surprises and some contributors having wrong expectations In fact: we didn’t know this was happening until recently Vinovyn @ Flickr
  • 39. For new contributors contributing up to smaller 10-15 patches per year: – None For new contributors planning to contributing complex and 15+ patches per year: – Reviewers are less willing to review patches without getting something in return At a minimum: – Engage with the Roadmap Process : Communicate your priorities – Submit early in the review process and submit designs early for complex code – Have realistic expectations Ideally: – Observe patch reviews on xen-devel@ and help with patch reviews of other people’s code – Help with testing (test days, test reports, test code) – Long term: work towards maintainership of components/features you care about
  • 40.
  • 41. 100 - 500 patches under active review Patch series A … Patch series B … Patch series N … Reviewer 1 Reviewer 2 Reviewer 3 Reviewers review according to their own schedule and own priorities. There is no centralized priority list. You may need to ping reviewers: overdoing this is counter-productive (may be considered as hassling).
  • 42. Quality, Security Different use-cases New Features Community Growth
  • 43.
  • 44. Media coverage is just a side-effect. We care about … – There are people out there trying to break Xen – And use exploits against Xen users This means … – Code is reviewed with security in mind – Think about security when designing a feature – Think about security before submitting a patch – You may be asked to modify related code that is related to your patch (often reviewers code “surrounding” your patch)
  • 45. Fix some Coverity Scan Issues – You can get access : see xenproject.org/help/contribution-guidelines.html – Small, bite-size issues to practice contributing to Xen
  • 47. Preview Part Experimental Core Complete (New) Full Yes Yes Yes Yes Supported (New) Full Yes Yes Yes Yes Supported-Legacy-Stable Full Yes Yes
  • 48. Preview Dev* No No Experimental Dev* No No Complete (New) Dev* No** No Supported (New) Yes Yes Yes Supported-Legacy-Stable Yes Yes Yes This is a state which has not existed in the past. It is aimed at larger new features, which may only be in use or of interest to a small number of contributors, or where not enough expertise exists in the community to treat the feature as Supported. *) At developer(s) discretion **) At Release Managers discretion
  • 49. Complete is aimed at non-core use-cases – Defuse tensions for non-core features – Cover for the case where we loose the capability to support Supported requires automated testing or manual testing during RC phase (otherwise it may be downgraded to Complete) Supported-Legacy-Stable accounts for the fact that many features that existed for a long time, may not be documented or automatically tested – Phase out over time
  • 50. Too many similar states – Need to simplify Some Open Questions – Templates and Exact Format of Feature Status – Location of files – How to handle legacy
  • 51. Traditionally we treated designs review different to code reviews – Using PDFs and Text Designs on xen-devel@ – Issues: Agreements and changes are not tracked Emerging Alternative – Post designs as patches in xen.git @ docs/… folders – Example: xen.git @ docs/misc/xsplice.markup with discussion at lists.xen.org/archives/html/xen-devel/2015-11/msg00244.html – Using pandoc markdown language and templates (see pandoc.org/README.html#pandocs-markdown) – Advantages: 1. ACKs are tracked  It is clear who agreed with the design 2. Design evolves with the code  Change the design doc with patches (include into series) 3. Easy to read and write  Can generate html, pdf’s, etc.

Editor's Notes

  1. TIMING: 7 MiNUTES Inspired by the Bezos Flywheel which “explains how to attract ever more sales in an online store”
  2. #1 We all understand the basic elements of the OSS dev model I did want to cover some important but less covered aspects Option Value = ability to implement new feature in the easiest way for the developer Modularity #ALL : the whole cycle can become virtuous ## There are also feedback loops (e.g. Users to Dev Activity) – but I want to keep things simple for now
  3. So: how this this actually work?
  4. #1: when you have a working cycle, the outcome is “community growth” So let’s look at this on more detail
  5. # More biz opportunities => More development activity BECAUSE Existing vendors have more opportunities
  6. To accommodate for the whole cycle, the community has to evolve and improve the development process E.g. do new things, such as marketing Then CLICK: which means betterdev model … Then CLICK
  7. TIMING: 11 MINS Definition: Individuals, acting independently and rationally according to each one's self-interest, behave contrary to the whole group's long-term best interests by depleting some common resource
  8. Mention: Core Infrastructure Initiative
  9. The reason for these issues is often an imbalanced or broken cycle In the case of the Xen Project, we also had an imbalanced cycle, and I spent the last 4 years at the project fixing this.
  10. So: how this this actually work?
  11. 30M
  12. What was interesting, was a large vendor – call it V CEOs of members of the security team, maintainers and committers to get a 6 week extension Handed of handling off this CVE off to Mitre
  13. Was: distros + VERY LARGE users Small service providers felt they could go out of business because of a sec issue, while large vendors reputation merely would be damaged What about service providers who are customers of a commercial distro? They shouldn’t be disadvantaged
  14. An example of transparency
  15. 30M
  16. After the cloud reboot, we were suddenly a high profile target for the tech press Every time we made a point release (which contained some XSA’s) the story was a security atory Every XSA is now a security story (regardless of whether it is Xen or QEMU)
  17. TIMING: 35 MINUTES