The Linux distribution OpenMandriva has apparently become the target of an internal act of sabotage. According to an announcement in the OpenMandriva forum, one of the project's developers deleted parts of a GitHub repository after an argument and published an empty package. That could have had direct consequences for user systems.
How things escalated
The accused developer is Davide Beatrici, known among other things for his work on the open-source chat app Mumble. He had joined the OpenMandriva team some time ago along with two other developers who weren't named. One of them is said to have repeatedly stirred up trouble and encouraged others to leave the project. After an argument, that developer was eventually removed from the internal Matrix chat.
That's when the situation escalated. Beatrici left the team together with a colleague and then used his still-active administrator rights to harm the project. According to the announcement, he deleted part of the repository on GitHub that the team had worked on for many years. He is also said to have published an empty package in the team's internal Cooker repository, which could have damaged the systems of users running the Gnome and Cosmic desktop environments.
The accused plays it down
The OpenMandriva team says it is working to restore the deleted data and repair the damage. A thorough review reportedly found no further sabotage attempts beyond the actions described. The team says it will not pursue legal action against Beatrici.
Beatrici himself denies the accusation. His actions were "in no way sabotage," he says, and he isn't the kind of person who would do such a thing. He claims he only deleted the Cosmic and Gnome repos, since OpenMandriva focuses mainly on KDE and LXQt anyway and several team members had already wanted them removed. He also says his own work had previously been sabotaged when others deleted build configuration files from several repositories without consulting him. The case shows how quickly missing access controls for departing contributors can become a risk, especially in open-source projects with distributed permissions.