)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"a3b97013a22b986f07b9839fe8d025db1cb75cf9","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"20532eb7_c8972511","updated":"2025-07-30 05:58:27.000000000","message":"Thank you for proposing clarkb, honestly I see this as the only way forward.\n\nI wouldn\u0027t bother with bridging, as discussed here.  AFAIK it\u0027s never _really_ worked.\n\nI would like to suggest that perhaps we think about moderation as part of this.  \n\nAfter some investigation of both Fedora and Ubuntu matrix channels, there really seems to only be one solution, which is a running instance of https://github.com/matrix-org/mjolnir\n\nIn short, the mjolnir service account is added to the rooms to moderate and trusted users can interact with it in a private room.  Unfortunately there\u0027s no finer-grained controls, you\u0027re either in the room or not.\n\nUbuntu wraps this term up as a \"defender\" (https://ubuntu.com/community/communications/matrix/moderation-and-defense) which means you\u0027re in this room and thus able to ban on any channels added.\n\nFedora channels do the same, with a trusted set of admins controlling mjolnir in the background.\n\nI feel like it might not be a bad idea to set this up, so we know it works and can monitor our channels, and have the framework for adding more?  I feel like mjolnir can run on eavesdrop and as a start the infra-roots would be the admins?  Now seems like the time to do it; before we start publicising the room or making additional rooms?  (I am aware I\u0027m asking for work 😊)\n\nUnder the super-admin of mjolnir, channel moderation seems to be granted ad-hoc in both Fedora and Ubuntu cases.  I guess ideally we would like to record this via system-config, have the change reviewed and deploy it via Ansible, rather than peers directly granting privileges.  But I\u0027m not sure if we should block ourselves on that","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"c421cccd0f94c539f9d47678ff129b641aa13992","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"76b5d1dd_6404afda","in_reply_to":"20532eb7_c8972511","updated":"2025-08-05 16:42:48.000000000","message":"We could see if our current EMS hosting provides mjolnir and go ahead and set it up for test rooms and also the zuul room.","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"}],"specs/matrix_for_opendev.rst":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"7aa6a4f79dddf434df87ffb1f8ecf58c87c3f8f2","unresolved":true,"context_lines":[{"line_number":50,"context_line":"corporate firewalls. IRC does not run over HTTP and many corporations consider"},{"line_number":51,"context_line":"it a risk due to historic use as a command and control protocol for botnets."},{"line_number":52,"context_line":"Matrix does run over HTTP and provides an out for users whose corporate"},{"line_number":53,"context_line":"firewall policies allow outbound HTTP connections."},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"Proposed Change"},{"line_number":56,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"4ff4f2af_db03a089","line":53,"updated":"2025-07-23 08:12:29.000000000","message":"there have been rumours that access to matrix is blocked by some companies, too, for similar reasons","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"e1ef935af765224e63b718d4027b0692f11bdc4d","unresolved":true,"context_lines":[{"line_number":50,"context_line":"corporate firewalls. IRC does not run over HTTP and many corporations consider"},{"line_number":51,"context_line":"it a risk due to historic use as a command and control protocol for botnets."},{"line_number":52,"context_line":"Matrix does run over HTTP and provides an out for users whose corporate"},{"line_number":53,"context_line":"firewall policies allow outbound HTTP connections."},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"Proposed Change"},{"line_number":56,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"7757e01f_48038406","line":53,"in_reply_to":"4ff4f2af_db03a089","updated":"2025-07-23 15:35:14.000000000","message":"Yes, organizations can further filter connectivity to specific allowed services. I know people haev claimed that only slack is allowed and that is why some in openstack want to run an openstack slack server. But I think in general http is more likely to be allowed than IRC ports if there is filtering occurring.","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"7aa6a4f79dddf434df87ffb1f8ecf58c87c3f8f2","unresolved":true,"context_lines":[{"line_number":89,"context_line":"the best compromise for us, then we will need to consider what we should do"},{"line_number":90,"context_line":"to migrate our weekly team meetings into Matrix. Likely we would create an"},{"line_number":91,"context_line":"additional meeting room, ``#opendev-meeting:opendev.org``, and update our"},{"line_number":92,"context_line":"existing matrix-eavesdrop bot to support rudimentary meeting commands."},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"Alternatives"},{"line_number":95,"context_line":"------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"291ef73e_3e868746","line":92,"updated":"2025-07-23 08:12:29.000000000","message":"I think there\u0027s a bit more to consider:\n\na) the split from the existing OpenStack community on IRC\nb) more tooling that\u0027s considered useful, like statusbot or accessbot","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"e1ef935af765224e63b718d4027b0692f11bdc4d","unresolved":true,"context_lines":[{"line_number":89,"context_line":"the best compromise for us, then we will need to consider what we should do"},{"line_number":90,"context_line":"to migrate our weekly team meetings into Matrix. Likely we would create an"},{"line_number":91,"context_line":"additional meeting room, ``#opendev-meeting:opendev.org``, and update our"},{"line_number":92,"context_line":"existing matrix-eavesdrop bot to support rudimentary meeting commands."},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"Alternatives"},{"line_number":95,"context_line":"------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"6ab9e279_ab05d961","line":92,"in_reply_to":"291ef73e_3e868746","updated":"2025-07-23 15:35:14.000000000","message":"\u003e I think there\u0027s a bit more to consider:\n\u003e \n\u003e a) the split from the existing OpenStack community on IRC\n\nI think an important part of OpenDev splitting out of OpenStack is giving OpenDev the ability to make decisions that make sense for it that may not always be in alignment with OpenStack (or other hosted projects). The intention here is to determine what the best choice for OpenDev is and that may diverge from OpenStack. While I don\u0027t think its a bad thing to be in alignment I\u0027m also not sure it is a requirement.\n\n\u003e b) more tooling that\u0027s considered useful, like statusbot or accessbot\n\nThis is a good point. There are a few other bot tools we use that don\u0027t currently have Matrix equivalents. Statusbot we can probably map over in a fairly direct manner replacing the irc connectivity with matrix connectivity (or adding it as an option). Due to how Matrix does permissions accessbot may need a bit more of a redesign. (Access is provided on a linear integer scale iirc and not with specific roles like op/voice/etc like irc).","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"e209dd633605874775ae999d41ba9cd85f36860b","unresolved":true,"context_lines":[{"line_number":89,"context_line":"the best compromise for us, then we will need to consider what we should do"},{"line_number":90,"context_line":"to migrate our weekly team meetings into Matrix. Likely we would create an"},{"line_number":91,"context_line":"additional meeting room, ``#opendev-meeting:opendev.org``, and update our"},{"line_number":92,"context_line":"existing matrix-eavesdrop bot to support rudimentary meeting commands."},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"Alternatives"},{"line_number":95,"context_line":"------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"fdd404ec_bb64b6a5","line":92,"in_reply_to":"3cb517ec_3b263af0","updated":"2025-08-06 08:17:12.000000000","message":"That\u0027s a good point to note, too: Administration like handling spam/abuse will have to be done on our own, there\u0027s (afaict) no equivalent of the global IRC (OFTC) admins taking care of most issues. Or is there something done by the hosting we have, like blocking known rogue homeservers?","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"c421cccd0f94c539f9d47678ff129b641aa13992","unresolved":true,"context_lines":[{"line_number":89,"context_line":"the best compromise for us, then we will need to consider what we should do"},{"line_number":90,"context_line":"to migrate our weekly team meetings into Matrix. Likely we would create an"},{"line_number":91,"context_line":"additional meeting room, ``#opendev-meeting:opendev.org``, and update our"},{"line_number":92,"context_line":"existing matrix-eavesdrop bot to support rudimentary meeting commands."},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"Alternatives"},{"line_number":95,"context_line":"------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"3cb517ec_3b263af0","line":92,"in_reply_to":"6ab9e279_ab05d961","updated":"2025-08-05 16:42:48.000000000","message":"I would probably defer accessbot work until we have a whole lot of rooms to manage, like if openstack says they want to move to matrix.","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"7aa6a4f79dddf434df87ffb1f8ecf58c87c3f8f2","unresolved":true,"context_lines":[{"line_number":103,"context_line":"  doable it is non zero effort and requires coordination with OFTC. We\u0027ve also"},{"line_number":104,"context_line":"  gotten feedback from some that using Matrix for IRC is not as simple as they"},{"line_number":105,"context_line":"  would like it to be. Running a Matrix client for Matrix rooms should be"},{"line_number":106,"context_line":"  simpler for users."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Implementation"},{"line_number":109,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9fbc4e5b_778e3120","line":106,"updated":"2025-07-23 08:12:29.000000000","message":"could this be combined with the proposed solution? i.e. run our own bridge, but just to allow access via IRC to the new matrix channel, not the other way around?","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"e1ef935af765224e63b718d4027b0692f11bdc4d","unresolved":true,"context_lines":[{"line_number":103,"context_line":"  doable it is non zero effort and requires coordination with OFTC. We\u0027ve also"},{"line_number":104,"context_line":"  gotten feedback from some that using Matrix for IRC is not as simple as they"},{"line_number":105,"context_line":"  would like it to be. Running a Matrix client for Matrix rooms should be"},{"line_number":106,"context_line":"  simpler for users."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Implementation"},{"line_number":109,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"4a13ec56_2a7e7272","line":106,"in_reply_to":"9fbc4e5b_778e3120","updated":"2025-07-23 15:35:14.000000000","message":"Yes, I suppose another alternative would be to only bridge into IRC channels/rooms which are canonically hosted on Matrix. Rather than bridging into Matrix channels/rooms which are canonically hosted on IRC. I think the tooling is largely the same. Its just a matter of selecting the mappings between things in configuration.","commit_id":"7a3a54f0426d05c415d43f0bd805c3953423b5ef"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"e7c385df35316466c86297e15e7ebf6e78830a4b","unresolved":true,"context_lines":[{"line_number":96,"context_line":"This bot would then be joined to each of the rooms we manage on Matrix as an"},{"line_number":97,"context_line":"administrator. Trusted users would be invited to mjolnir\u0027s management room."},{"line_number":98,"context_line":"Users in this management room are trusted by mjolnir and it will carry out"},{"line_number":99,"context_line":"any requests made by those users to moderate the other rooms mjolnir is in."},{"line_number":100,"context_line":""},{"line_number":101,"context_line":"Next, we currently rely on Limnoria\u0027s meetbot plugin to help manage our"},{"line_number":102,"context_line":"weekly team meetings. This simplifies note taking and historical record"}],"source_content_type":"text/x-rst","patch_set":2,"id":"c160e2c4_c2c7072b","line":99,"updated":"2025-08-11 23:40:53.000000000","message":"It might be worth noting the difference that accessbot is idempotently run from committed config, but (afaict) mjolnir and matrix admin setting for channels is less compliant to this, and would take quite some work if it is possible.  we could have some conventions, like admins are listed in a file that is +2\u0027d and committed before access or something, but that\u0027s not quite as strong as what we had.  I think we\u0027re OK with this, and as I mentioned in prior review AFAICT it\u0027s how other projects like ubuntu and fedora manage their matrix presences.  But it would explicitly note we thought about it.","commit_id":"57774eb84f725d39414720d45d7fbd2e2824d883"}]}
