GitTorrent: A Decentralized GitHub (2015)
blog.printf.net
blog.printf.net
Bitcoin and BitTorrent v1 were plausible substrates in 2015, but no longer. I think Radicle (https://radicle.xyz) is the project most deserving of attention at the moment.
The hardest thing about such a project is economic: how do you handle issue/comment spammers? Or someone creating as many accounts as they can? How do you incentivize someone to mirror your repo? Or to build you a delta to satisfy your `git pull`, without making the network fall over when someone realizes they can ask you to spend infinite CPU building packfiles for them? And what happens when someone forgets their password or loses their private key? This space was a humbling experience in the necessity of incentive alignment for me.
In effect you can do the same thing better by using a cryptocurrency with cheap transactions, e.g. Bitcoin Cash's Memo.cash. This way git hosts are compensated while at the same time making it too costly to spam.
Longer packfile creation processes will require a greater transaction fee or otherwise be ignored based on heuristics created by the client. This will prevent infinite CPU building packfiles issues in addition to fair compensation for increased computation cost. All while the miner is incentivized to minimize the time to be able to reap that block reward in the context of market competition.
[1] https://lbry.tv/
Add:
> And what happens when someone forgets their password or loses their private key?
Here's an approach I found interesting: https://darkcrystal.pw/
When I think of something that we should be able to do but can't ("I just want a button to do X" type requirements) it is usually apparent why that doesn't exist if I give it some thought.
If it's the case and if anyone from the project is reading this, it would be helpful to mention it on top of landing page.
Also, the landing page is mentioning ssb, is this related to git-ssb?
> how do you handle issue/comment spammers?
I love how ssb is handling that : it's not a problem because you create a "web of trust" and only content from people you trust and people they trust reaches you - and trust can be revoked in case of problem. Obviously, it creates an other problem, though : how a benevolent total stranger can reach you?
By the way, yet an other alternative is hypergit ( https://github.com/noffle/hypergit ). It uses hyperdb/dat. I used it a few times to share code with friends, I loved it because it was the most straightforward for them to install and use.
Keybase's approach is more scalable, but it's still centralized.
I can easily imagine a web of trust system with UX more similar to Facebook’s (and in fact this is basically what SSB’s clients are).
It frustrates me that they use the relation "on top" backwards, but otherwise it's a good read.
Radicle provides a network overlay and gossip protocol, on top of which they run the git smart protocol (they describe it the other way around, which makes no sense).
Then just pick an instance you like.
[0]: https://radicale.org
Even before Friday's censorship, I was pleasantly surprised by the level of support and offers to help I received in mastodon. People there are aware, skilled and ready.
BTW I've got ideas on how to handle the issue/comment spam and other problems rightly highlighted by @cjbprime in his reply to the OP. But first I have to get git-bug (really worth of support too) compiled to WASM and running in the browser.
It's early days, but you can see what I'm up to here: https://safenetforum.org/t/safe-git-ui-discussion/32793?u=ha...
Or follow: https://mastodon.technology/@happybeing https://twitter.com/safepress
The real problem is hosting issues and PRs in such a way. Github has an API and it's possible to script the backup but source code gets backup automatically so when the takedown strikes it's not a big problem.
Sadly not every maintainer signs their commits or tags.
It's a distributed bug-tracker: it stores issues (and one day, PRs) within git. You can work offline and you always have a full copy of everything. It also has bridges for Github, Gitlab and Jira.
git-bug is a pleasure to use so I'm attempting to get it running in the browser using wasm, to create a decentralised github on p2p storage. I'm targeting Safe Network but the same approach could be used on anything with a storage backend, from NextCloud to IPFS, even [cough] AWS.
https://www.fossil-scm.org/home/doc/trunk/www/bugtheory.wiki
Can one simply place a git repo in an IPFS directory (e. g. with some IPFS fuse implementation) and share an IPNS / DNSLink so that future changes can be found under the same address?
In this aporoach github issues and pull requests can be replaced by discussions and patches in a mailing list.
2. How popular is IPFS? How easily usable by lay users?
Why not just stick a txt record on a domain? You can clone gittorrent://awesome.withinboredom.info.
You can easily find a valid gpg key for me in the usual places.
* Write a client in C, JS sucks
* Make a web-frontend for this so average users can jump on quickly.
Going after youtube-dl so publicly has a solid Streisand effect. Feel as though the lawyers aren't going to give up easily on this one and will hound them one way or another.
Regardless, there is some github alternatives available through tor:
Darktea: http://it7otdanqu7ktntxzm427cba6i53w6wlanlh23v5i3siqmos47pzh...
Rootgit: http://rootgit4rghbuenb.onion/explore/repos
And on I2P:
I have created the repo at Darktea, feel free to create your anonymous accounts and join the project, until we find a better/decentralized place.
For now this should be sufficient:
http://it7otdanqu7ktntxzm427cba6i53w6wlanlh23v5i3siqmos47pzh...
I will give the main contributors the neccessary access for reviewing/merging/etc.. or will entirely hand over the project if you can prove you are the maintainer.
[1] https://twitter.com/pijul_org/status/1319159283938983936
Internal hash consistently could be used for verification.