<oembed><type>rich</type><version>1.0</version><author_name>npub15758wuggl6u8umupz8ellvdjad7mjcchkn2vcelrmmeg55f48euspfpqkx</author_name><author_url>https://nostr.ae/npub15758wuggl6u8umupz8ellvdjad7mjcchkn2vcelrmmeg55f48euspfpqkx</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2021-11-23&#xA;📝 Original message:&#xA;Each dev does tests on a local machine before push to repo, repo&#xA;maintainers do tests and when satisfied do an acceptance test in the&#xA;proposed system to verify against all other implementations partaking&#xA;before public release. Has not anything to do with You relly, not Your&#xA;private machine but dedicated test machines that do have nano granularity&#xA;in that request against runs can specify unix.ts(start)-range-unix.ts(end)&#xA;of box xyz and independently se if others and own impl behaves as it is&#xA;expected to.&#xA;&#xA;On Tue, Nov 23, 2021 at 5:31 PM x raid &lt;xraid at iprobot.com&gt; wrote:&#xA;&#xA;&gt; so You propose Acinq / Blockstream / Lightning Labs do not have funds to&#xA;&gt; run a box or 2 ?&#xA;&gt;&#xA;&gt; contributions can be made towards each impl by ppl while the project still&#xA;&gt; do need put liquidity on mainnet to be a viable test before a public&#xA;&gt; sanctioned release.&#xA;&gt;&#xA;&gt; I find You choose misread what the text is supposed to convey - those with&#xA;&gt; the write credentials to repo, when do a public release could have been&#xA;&gt; tested, before, against the network, and that in no way hinders PR toward&#xA;&gt; said repo.&#xA;&gt;&#xA;&gt; On Tue, Nov 23, 2021 at 1:44 PM ZmnSCPxj &lt;ZmnSCPxj at protonmail.com&gt; wrote:&#xA;&gt;&#xA;&gt;&gt; Good morning x-raid,&#xA;&gt;&gt;&#xA;&gt;&gt; &gt; what i can imagine is each team should provide boxes and channel&#xA;&gt;&gt; liquidity as stake on mainnet for tests before announce a public realise as&#xA;&gt;&gt; to feel the pain first hand instead of having several K´s of plebs confused&#xA;&gt;&gt; and at worst have funds in channelclosed etc. but mostly for helping in&#xA;&gt;&gt; smooth transitioning into future envisioned mass.&#xA;&gt;&gt;&#xA;&gt;&gt; Not all members of all teams are independently wealthy, and cannot afford&#xA;&gt;&gt; significant liquidity on mainnet, or can afford good Internet connection&#xA;&gt;&gt; and keeping a device operational 24/7.&#xA;&gt;&gt; For example, for some time I was a C-Lightning core developer, yet did&#xA;&gt;&gt; not run a C-Lightning node myself, relying on sheer code review, because I&#xA;&gt;&gt; could not afford to run a node.&#xA;&gt;&gt; What you imagine would raise the barrier towards contribution (i.e. I&#xA;&gt;&gt; might not have been able to start contributing to C-Lightning in the first&#xA;&gt;&gt; place, for example).&#xA;&gt;&gt;&#xA;&gt;&gt; I think you misunderstand the open-source model.&#xA;&gt;&gt; If you have the skill, but not the money, you can contribute directly.&#xA;&gt;&gt; If you do not have the skill, but do have the money, you can contribute&#xA;&gt;&gt; that by hiring developers to work on the project you want.&#xA;&gt;&gt;&#xA;&gt;&gt; So, if you are using a particular open-source implementation and storing&#xA;&gt;&gt; your funds with it, either:&#xA;&gt;&gt;&#xA;&gt;&gt; * You have the 1337 skillz0rs: you contribute review and actual code.&#xA;&gt;&gt; * You do not have the 1337 skillz0rs: you contribute hardware and testing&#xA;&gt;&gt; reports and possibly money.&#xA;&gt;&gt;&#xA;&gt;&gt; If the several Ks of plebs are confused, they can aggregate their&#xA;&gt;&gt; resources and fund one or two developers to review and contribute to the&#xA;&gt;&gt; project they are using, and maybe some hardware and coins for boxes they&#xA;&gt;&gt; keep running.&#xA;&gt;&gt;&#xA;&gt;&gt; At my point of view, the Real Issue (TM) here is how to aggregate the&#xA;&gt;&gt; will of a group of people, without risking that some centralized &#34;manager&#34;&#xA;&gt;&gt; of resources gets incentives that diverge from the group of people and&#xA;&gt;&gt; starts allocating resources in ways that the group of people would, in&#xA;&gt;&gt; aggregate, disagree with.&#xA;&gt;&gt;&#xA;&gt;&gt; &gt;&#xA;&gt;&gt; &gt; If teams rather outsource the running of boxes with channels on mainnet&#xA;&gt;&gt; for impl release and rc versions they would of course be able to, but close&#xA;&gt;&gt; to home for managing analysis of the team impl themselves is what I would&#xA;&gt;&gt; recommend.&#xA;&gt;&gt; &gt;&#xA;&gt;&gt; &gt; Can also see that each box loglines are collected at one central point&#xA;&gt;&gt; whereby requests can be made for comparing interoperability per unix.ts&#xA;&gt;&gt; identified by box.&#xA;&gt;&gt; &gt; (thats alot of data You say --not really in Big Data terms, question is&#xA;&gt;&gt; where to set a proper cap in time for collections ? a week ? a month ?)&#xA;&gt;&gt; &gt; I think i might have a solution for the central point collector that&#xA;&gt;&gt; could be run by an outside of impl teams perimeter. (sponsored?)&#xA;&gt;&gt;&#xA;&gt;&gt; See, if the money on the node is my own, and not contributed by the group&#xA;&gt;&gt; that is going to receive the logs, I am not going to send the logs verbatim&#xA;&gt;&gt; to them, nope not nada.&#xA;&gt;&gt; I do not want to become a target, because logs leak information like who&#xA;&gt;&gt; my channel counterparties are and how often I forward HTLCs and exact dates&#xA;&gt;&gt; and times of each event, and thus can be used to locate my node, and&#xA;&gt;&gt; location is the first step to targeted attack.&#xA;&gt;&gt; I mean I use a frikkin set of 8 random letters, come on.&#xA;&gt;&gt; Possibly if the logs had sensitive information redacted (even dates and&#xA;&gt;&gt; times??), but we need to automate that redaction, and in particular, if the&#xA;&gt;&gt; implementation changes log messages, we need to ensure that changed log&#xA;&gt;&gt; messages do not leak information that gets past the automated redaction.&#xA;&gt;&gt;&#xA;&gt;&gt;&#xA;&gt;&gt; Regards,&#xA;&gt;&gt; ZmnSCPxj&#xA;&gt;&gt;&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/lightning-dev/attachments/20211123/63d5b741/attachment-0001.html&gt;</html></oembed>