The user hass has been blocked by the CWG. His profile page is currently inaccessible. As one of the earliest members of drupal.org (ID 85918) he maintained and co-maintained a long list of projects, the most popular being Google Analytics.

Based on his comments history the user was last active about two months ago, although his Gitlab feed shows him active two weeks ago.

Recently several (unrelated) projects were marked as abandoned/unsupported with open security issues, much to the surprise of their user base. To avoid a repeat of that situation we need to ensure that projects with a large install base stay maintained when it has become clear that their maintainer has left.

This is a list of projects where hass has been the owner or sole active maintainer (according to commits). Those with unresolved issue links may become unsupported unless somebody to take charge is found.

The list is based on a 2017 snapshot of the user profile page, but should be complete. Not included are projects that have been marked as obsolete or deprecated.

Here is a lists of tasks that need to be carried out:

  1. try to complete the list of potentially affected projects in the summary
  2. create issues in the respective project queues to raise awareness
  3. use this issue as a central point of communication to plan the transition across projects
  4. create a CWG issue to facilitate maintainership transition as part of a ban (the details and circumstances will have to be discussed there).

Comments

ciss created an issue. See original summary.

ciss’s picture

Issue summary: View changes
avpaderno’s picture

Category: Task » Support request
Status: Active » Fixed

The account has been temporarily blocked from the CWG (Community Working Group). Only users who have the role of user administrator can see blocked accounts and that is why you cannot access https://www.drupal.org/u/hass.

Even if a user would leave drupal.org, we don't reassign each of the projects maintained from that user in a single issue.

ciss’s picture

The account has been temporarily blocked

When will the maintainer be able to reengage in issues?

Even if a user would leave drupal.org, we don't reassign each of the projects maintained from that user in a single issue.

What would be the proper process to track the transition of maintainership for all projects of a user, if the list of affected projects is still unclear?

ciss’s picture

Status: Fixed » Active
Related issues: +#3083289: Has this account been deleted?

I don't consider this issue fixed as long as it is unclear if/when the user will be able to act as maintainer again.

The current situation with admin_views, nodequeue and other projects has made it clear that some preemptive action needs to be taken if a project's sole maintainer cannot perform their duties anymore. Please note that at least half a million sites may be affected by this issue.

avpaderno’s picture

Component: Needs maintainers » Other
Status: Active » Fixed

No, there aren't preemptive actions that need to be taken, whenever the project owner has been temporarily blocked (as in this case) or permanently blocked.
The only actions we take is when there are users who offer to maintain/co-maintain the projects, but even in this case, we don't handle all the projects owned from a user in a single issue. Each project is handled in a single issue.

There isn't any offer to become maintainer/co-maintainer, in this issue, so there isn't any action we need to take.

ciss’s picture

Would you please take the time to read and answer my questions in comment #4?

There isn't any offer to become maintainer/co-maintainer, in this issue

Because that is not the intent of this issue, as was underlined by the component "Needs maintainers" before you changed it to "Other".

, so there isn't any action we need to take.

What is the purpose of the components "Needs maintainers" and "Needs co-maintainers" then?

avpaderno’s picture

Needs maintainers and Needs co-maintainers issues are created from project owners who are looking for new maintainers or co-maintainers for the projects they own.

gisle’s picture

IMHO, this is not "Fixed".

The way I see it, the intent by the OP was to create a public record in the appropriate issue queue to flag that some very important projects in Drupal ecosystem may become abandoned. By creating this issue, the community was alerted about the problem, and this allows for discussion about what can be done about it. Simply closing it as "Fixed" because a technicality about the OPs use of the "Component" metadata was not considering the OP's intent and is not showing respect.

It is very disruptive to the Drupal community when projects that a lot of community members rely on become unsupported, and by twisting an issue where a legitimate concern about this is posted into "support request" (which it never was) and pretending it is "Fixed", metadata is abused and real harm is inflicted on the community. I know that this is harsh words, but I feel strongly about this.

Given the above, I expect kiamlaluno to open this issue again (my suggestion for Category is "Plan" and Component is "Abandoned/unsupported projects (notice the plural) – but I'm not fuzzy over metadata). If this does not happen, my next step is to proceed according to the Conflict Resolution Policy and Process.

mmjvb’s picture

IMO the correct Status for this issue is Fixed according to current policy.

Doubt very much the intentions are as expressed by @Gisle, despite that consider @kiamlaluno to have given the benefit of the doubt. Consider it a sign of respect to point out that the issue initially was reported wrongly and addressing the things done wrong. Consider it absolutely correct to change it to a Support Request, the original post didn't contain a call for action. The wrong assessment of the current situation was corrected and pointed towards the correct procedure to follow.

There is nothing in the issue that is at the right place here in this project. Each project with only one maintainer is a risk to use in your own project. The current policy expects you to report it at that project if you feel strong about that. You do need to provide arguments for your assessment. Without response it can be escalated, adding a specific issue here as proposed above. The difference being it is about a specific project.

When feeling strongly about the current procedure, it should be adjusted in a proper way. Consider just rewriting the procedure incorrect. Obviously, correcting those procedures is allowed. Changing it because you disagree, is not. Expect changes to be approved by governance.

gdemet’s picture

I've already posted this over in the CWG queue, but to provide a little bit of additional context/clarification here, the CWG does not know at this point when or if the user in question will be reinstated. You can read more about our process here.

Given that, we would recommend that interested individuals follow the established procedure for taking over projects with unresponsive maintainers. We understand that some folks are frustrated that there doesn't currently appear to be a way for users of abandoned (or apparently abandoned) projects to draw attention to that fact and/or recruit new maintainers if they are not willing or able to take over the project themselves. While the CWG is happy to help facilitate a conversation about potential changes to existing policy to address this gap, we cannot make those changes ourselves, as our charter expressly forbids the group from making technical policy decisions.

In general, it's our feeling that any project with a large number of users should have multiple maintainers, as there are a variety of reasons that a maintainer might need to step away (burnout, job changes, etc.) that have nothing to do with a CWG action.

ciss’s picture

Status: Fixed » Active

IMO the correct Status for this issue is Fixed according to current policy.

@kiamlaluno changed the issue type to "Support request", but left my questions in #4 unanswered. As such the status cannot be "fixed".

Doubt very much the intentions are as expressed by @Gisle

They are, @gisle's summary was spot-on.

the CWG does not know at this point when or if the user in question will be reinstated

I take it this translates to "indefinitely". @joachim-namyslo has contacted hass in order to get some outlook on the future of hass' projects. If he doesn't receive a response until next week I suggest we:

  1. complete the list of affected projects in the summary
  2. create issues in the respective project queues to raise awareness
  3. use this issue as a central point of communication to organize the transition across projects
  4. create a CWG issue to facilitate maintainership transition as part of a ban (the details and circumstances will have to be discussed there).

I'm setting the status back to "Active" and ask that you leave it at that. I'll happily set it to Fixed myself once I feel that all raised questions have been addressed.

gisle’s picture

Title: Several projects may be abandoned » Plan for deling with projects that may be abandoned
Category: Support request » Plan
Issue summary: View changes

I've added the plan in comment #12 to the issue summary:

As for the second item (create issues in the respective project queues to raise awareness), I've already done this. Links to the issues created below. Two of the projects (so far) appear to have other active maintainers that monitor the issue queue and are prepared to fill the gap left by hass.

mmjvb’s picture

@ciss First, I would like to thank you for the information you provided about figuring out who are the maintainers of a project. I used it to find out you are not listed as maintainer of this project.

Second, FWIW my initial doubt about your intentions has been taken away by looking into this issue further. Glad to hear I was wrong about that.

Third, you have been informed about the situation. The fact you still have unanswered questions doesn't justify keeping this issue open. Those questions are not in scope of this issue/project. You need to raise issues at the right places to possibly get answers. I won't change Status, but expect maintainers to do that, because that is the right thing to do!

gisle’s picture

You need to raise issues at the right places to possibly get answers.

This is the Project Ownership issue queue, and it is he right place to raise issues about project ownership, including issues related to projects that may be unsupported.

Do you know of a more appropriate place to raise such issues?

I won't change Status, but expect maintainers to do that, because that is the right thing to do!

I am a maintainer. Please see comment #9 for my view on that subject.

mmjvb’s picture

@Gisle Yes, you are listed as maintainer for this project. I was addressing @ciss, who isn't. Again, his questions are unrelated to this project.
This project is the right project to raise CERTAIN issues about unsupported projects, NOT ALL issues. You have made those things clear in the policy for abandoned projects.

Obviously, questions about blocked owners have to be addressed by CWG.

I am aware of your point of view, but also both @kiamlaluno and I disagree with you on this particular issue. As he is also maintainer here and unless he changes his mind, expect him or anybody else with proper authorization to close this again.

Now that you changed the scope of the issue things may work out differently. IMO the plan issue should have been created by a maintainer the moment they were informed by CWG. With tasks for each of the responsibilities. Consider allowing these issues to be created by anyone a bad idea.
Same thing for changing scope of issues.

gisle’s picture

Rather than debating where questions that already has been addressed here by the CWG (see comment #11 above) belong, I would like you to read the issue summary, which summarizes what the issue is about. Given the summary, do you still insist this issue is off-topic in the Project Ownership issue queue and should be closed?

As I've written elsewhere: I believe the maintainers here should assume good intent and work with the concerned community members that report a problem in this issue queue to work together to resolve the problem, rather than slapping a bogus "Fixed" status on the issue and pretend that the reported problem does not exist.

mmjvb’s picture

@gisle You beat me while I responded to @ciss. He opened the issue due to unanswered questions unrelated to this issue.

Agree with a plan or task issue opened by a maintainer of ownership project. Agree with a support request by anyone to deal with unresponsive owners as long as they are for a specific project. Disagree on anyone creating plans or tasks, that would be the prerogative of maintainers. Consider that in line with current policy, for all projects.

Agree about assuming good intent, pointing out mistakes and correct procedure are part of that. Sorry to hear how you feel about it. Wonder why you consider that acceptable in other situations, but not in this case.

Suggest to have a look at the active issues of D8CPT (https://www.drupal.org/project/issues/contrib_tracker?categories=All). Unresponsive projects!

ciss’s picture

He opened the issue due to unanswered questions unrelated to this issue.

@mmjvb Please stop and read the complete issue (including the comments) before making these false claims. I asked for the correct procedure in #4 after the issue was changed to "Support request" and closed. The reason given ignored the intent as described in the original summary. That question in turn received no answer.

Frankly, this discussion is exhausting and (imo) misplaced. We're a community, not a bureaucracy.

ciss’s picture

Issue summary: View changes

I've added a clarification to the summary to offer some context that may have not been obvious to everyone involved in this issue:

Recently several (unrelated) projects were marked as abandoned with open security issues, much to the surprise of their user base. To avoid a repeat of that situation we need to ensure that projects with a large install base stay maintained when it has become clear that their maintainer has left.

ciss’s picture

Issue summary: View changes
ciss’s picture

@gisle As webmaster, do you have the means to fetch a complete list of projects to which hass was assigned as maintainer?

mmjvb’s picture

@ciss Sorry to hear you don't want to play according to the rules. The rules you accepted when entering this community. For the record I did read everything and still stand by my statement your questions are inappropriate here, including your actions in this issue.

With the changed scope of the issue, I'll refrain from further participation here.

gisle’s picture

@gisle As webmaster, do you have the means to fetch a complete list of projects to which hass was assigned as maintainer?

AFAIK, I only have the same access as everybody else - the archived version of hass' profile page: https://web.archive.org/web/20170426235942/https://www.drupal.org/user/8...

By going through the list of projects listed there, it should be possible to identify those where hass is the main or the only maintainer and add those to the issue summary.

ciss’s picture

Issue summary: View changes
ciss’s picture

Issue summary: View changes
avpaderno’s picture

The project owner and only maintainer for Google Analytics is budda; for Real Name, the project owner is NancyDru; for PHP, the project owner is RobLoach.

megachriz’s picture

@kiamlaluno
I guess hass has been removed from Google Analytics as a maintainer. He used to be a maintainer on that project. I think on the other two projects you mention, hass has been the most active one in the past few years. But thanks for looking it up. It sounds like these three projects are in no direct danger then.

ciss’s picture

Issue summary: View changes

Included issue links from #13 in summary.

gisle’s picture

Issue summary: View changes

The Google Analytics team has responded that the project is still maintained.

ciss’s picture

There is now a tool to inspect a project's complete list of maintainers in a more user-friendly way: https://observablehq.com/@mootari/drupal-project-maintainers

gisle’s picture

Issue summary: View changes

Link Checker and Matomo Analytics has got a new owner and are now maintained again.

gisle’s picture

Issue summary: View changes

RobLoach (owner of reCAPTCHA and PHP) has not responded to the issues requesting support status for these projects, but he just pushed a new release of reCAPTCHA. I..e he is still on Drupal.org and maintaining his projects. This means that we don't need to find replacement for hass for these two

gisle’s picture

Assigned: Unassigned » gisle
Issue summary: View changes
Status: Active » Fixed

The last one was User registration notification. It has now been marked as "Unsupported". Closing this.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

avpaderno’s picture