http://www.mail-archive.com/dev@openoffice.apache.org/msg277...
http://www.mail-archive.com/dev@openoffice.apache.org/msg277...
An outright "merger" of the two projects seems unlikely due to the licensing differences and the associated thinking. Some people prefer permissive licenses like the ALv2, others prefer the GPL/LGPL world. So getting everybody to agree on that is probably a non-starter.
And? I mean, yeah, it would be nice to have more cool new stuff coming out, but it's not like AOO owes the world anything. It's open source, it's volunteer driven. If people want more new features, more development, etc, then more people need to volunteer. If they don't, well... the world gets what it gets from the folks who are contributing.
It arguably owes its users not distributing security holes to them. Sitting on the vulnerability since October 2015, only revealing it in July because the reporter said they were going public with it ... there is no way that is responsible stewardship of end user software.
In fact, I just checked - I went to www.openoffice.org, went all the way through to download, and it still gives me the vulnerable version and doesn't give me information that there's a vulnerability or a fix.
You're an AOO dev. What do you see as your responsibility in this regard?
"In the case of Apache OpenOffice, needing to disclose security
vulnerabilities for which there is no mitigation in an update has
become a serious issue. In responses to concerns raised in June, the
PMC is currently tasked by the ASF Board to account for this
inability and to provide a remedy. An indicator of the seriousness
of the Board's concern is the PMC been requested to report to the
Board every month, starting in August, rather than quarterly, the
normal case. One option for remedy that must be considered is
retirement of the project. The request is for the PMC's
consideration among other possible options."In terms of the various security issues that have cropped up, I'd say that if we reach a point where we simply cannot ship a fix AND it's a serious vulnerability, then we have an obligation to inform users of the situation so they can make up their own minds what level of risk they are comfortable with.
This is part of the ongoing discussion on the dev lists. The OP quotes Dennis, the OpenOffice Chair to this effect.
OTOH, maybe things have changed since I formed that impression. At any rate, your willingness to do so is appreciated. As far-fetched as it sounds, I still hold out hope that one day the two projects can have an amicable co-existence and collaborate to a greater extent (than today).
I will share a story.
Awhile ago I was employed by Red Hat and, as we know, Red Hat has a number of developers working on LO. I was talking w/ our CTO at the time and suggested that it would be a Good Thing if Red Hat allowed all our code donated to LO be triple-licensed (MPL/GPL/ALv2) so that AOO could benefit from these contributions. He thought it was a great idea since it showed that Red Hat was all about open source and true universal sharing.
But when we asked the developers they refused to do so. The explanations were either (1) We refuse to contribute to permissive projects or (2) We have been told by TDF that they will not accept any of our contributions so licensed.
So the "resistance" in code flowing to AOO is, in fact, reality. My hope is that we can change that for the benefit of the entire OO eco-system.
The "enemy", lest we forget, is MSO, not any of the OO implementations.
If the purpose of the "war" is to increase userbase by stealing users from MSO, then having a single implementation that is broadly supported and has brand recognition is vastly preferable to the current situation with two forks, one of which has the branding, while the other one has the features.
Btw, the claim that Red Hat's CTO (or anyone else at RH) "thought it was a great idea" seems to be a bit exaggerated as well. The words you yourself used at that time were "... saw the logic of it".
This claim is false, and it's a false claim I've seen you make before. If you maintain it is not, please link and quote the email that you consider substantiates it.
If, however, there are, or have been, patches that could be consumed by AOO, I'd like to see URLs for those discussions and pull/merge requests. Thx!