Re: Policy for Abandoned Extensions

From: Joe Conway <mail(at)joeconway(dot)com>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "David E(dot) Wheeler" <david(at)justatheory(dot)com>
Cc: PostgreSQL Hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Re: Policy for Abandoned Extensions
Date: 2026-10-10 17:57:47
Message-ID: 4a34bc44-8548-4fb4-844b-9e379b00fe4e@joeconway.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On 10/10/26 13:15, Tom Lane wrote:
> "David E. Wheeler" <david(at)justatheory(dot)com> writes:
>> A couple times in the last year, people have hit me up to ask about taking ownership of abandoned extensions on PGXN. In neither case was I able to track down the original owner, not for lack of trying. Then this past week I was alerted to potential superuser escalations in two more abandoned extensions on PGXN.
>
> Clearly not a good situation.
>
>> So I think it may be time for a policy on this. What do you recommend? I have a few thoughts and options, some of which would require additional work on PGXN at some point.
>> * Set up a committee of some kind to investigate abandoned extensions and find vet and find replacement developers when possible.
>> * Cease transferring extensions without permission from long-gone developers and instead suggest that people fork extensions and give them new names.
>> * Add an annotation to apparently abandoned extensions and mark them as such on pgxn.org, along with relevant pointers to replacement extensions and contact information for the original developer to get in touch and reclaim access. Or maybe it goes away if they create a new release.
>
> I think we have to think first of the users' experience. It's not
> good if an extension that is abandoned and has known problems looks
> the same as actively-maintained ones. So I would prioritize your last
> bullet point of somehow annotating seemingly-abandoned extensions.
>
> By the same token, I don't think "fork under a different name" offers
> good user experience: what it offers is confusion. So I prefer a
> mechanism that allows a new developer to take over an abandoned
> extension over one that encourages forking, even if the latter is
> supported by a pointer-to-replacement mechanism. For myself, if I'd
> stopped maintaining something for lack of time/interest, I'd be very
> happy if someone else picked it up; but I do realize that probably
> not everyone feels that way. (Probably-impractical idea: when an
> extension is first listed on pgxn, ask if it'd be okay to reassign
> ownership in the event that development seems dead.)
>
> In any case, I agree that you should have some sort of defined
> process for deciding that an extension is abandoned. Whether
> that's a committee or just a checklist, I don't have a strong
> opinion about. But it should be unsurprising to all concerned
> when such a determination is made.

It may be impractical, but given cases like the XZ Utils backdoor
situation (i.e where a malicious person showed up offering to "help"
maintain an open source project where the original maintainer was
stepping away), it seems like any transfer process needs a vetting step.

--
Joe Conway
PostgreSQL Contributors Team
Amazon Web Services: https://aws.amazon.com

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Tom Lane 2026-10-10 18:02:04 Re: Policy for Abandoned Extensions
Previous Message Zsolt Parragi 2026-10-10 17:27:59 Re: REPACK: warn about skipping foreign partitions