Hi Chinmoy,

why would we fork our dependency here ?

> Reduced risk from repository access, policy, or ownership changes outside the OpenBMC project

What is meant by this? We are consuming the code from stdexec. How they do their governance or policy is maybe irrelevant to us as long as the license is compatible and the code is working ?

What is "risk of repository access" ? If the SRCREV is bumped in the yocto recipe, you can review any changes done to the project, right?

The recipe is here: meta-phosphor/recipes-extended/stdexec/stdexec_git.bb

If you build subprojects out of tree then meson will usually not fetch a new subproject revision unless you explicitly tell it to. So in each case you can review all code changes..

> Broader review and maintainer participation and long-term support

If someone wants to review the changes to stdexec they can do so at https://github.com/NVIDIA/stdexec/pulls ?

What is preventing you from reviewing and long-term supporting stdexec via the normal github workflow?

> Improved community ownership , transparency and reduce dependency risk

IMO ownership means understanding and maintaining the code. Who in the openbmc community is even working on stdexec?
When i look at the contributors, the only one i see from openbmc community is Patrick https://github.com/NVIDIA/stdexec/graphs/contributors?all=1  

(maybe i am wrong and there are more people working on it ?)

Who should own and maintain this stdexec fork you are proposing?
And is the person you are proposing to maintain this qualified to do so?
What would be an example change to stdexec you see as required that cannot be done in the upstream repo and therefore would require forking/patching ?

Thanks,
Alexander

On 7/30/26 07:36, Chinmoy Dey wrote:

Hi Team,

Just following up on my earlier email and resending it to make sure it hasn’t been missed.

I would appreciate it if you could please take a look when you get a chance.

Regards,
Chinmoy


On 23 Jun 2026, at 5:59 PM, Chinmoy Dey <chinmoy@nexthop.ai> wrote:

Hi OpenBMC Community,

I would like to start a discussion around the long-term ownership and maintenance model for the stdexec dependency that is currently part of the OpenBMC dependency chain. As I understand it today:

First, I would like to acknowledge and appreciate the work that has gone into this implementation. The intent of this note is not to question the quality of the code or the contributions made by NVIDIA, but rather to discuss whether there may be an opportunity to align this dependency more closely with OpenBMC’s long-term governance and maintenance model. Since stdexec is now part of a commonly consumed dependency path within OpenBMC, it may be worth considering whether a community-maintained approach could provide additional benefits, such as:

  • Reduced risk from repository access, policy, or ownership changes outside the OpenBMC project
  • Broader review and maintainer participation and long-term support
  • Improved community ownership , transparency and reduce dependency risk

If there have already been discussions on this topic, or if there is a preferred roadmap for the dependency, I would greatly appreciate any references or guidance. My goal is simply to explore whether we can further strengthen the sustainability, transparency, and long-term maintainability of the OpenBMC dependency ecosystem as it continues to grow.

Thank you for your time and consideration. I look forward to hearing the community’s thoughts.

Best regards,

Chinmoy Dey