On Thu, 23 Jul 2026 13:18, Ansgar 🙀 <[email protected]> wrote:
Hi,

On Wed, 2026-07-22 at 17:35 +0200, Matthias Geiger wrote:
he scope of this GR is (non-exhaustive): - Debian source packages
- Official Debian project software, such as lintian

So if, say, lintian was no longer "official Debian project software",
this would not be a problem?

It is hard to define what official project software is and what not. Is dose3 official? By my definition I mean: Anything that is developed primary for use with Debian, very often by DDs themselves. We can't enforce rules for upstream projects, but we can do so for primarily debian-native software developed by us.
It does not include: - Upstream projects using LLMs for development

But you explicitly say below that "Debian Policy and the DFSG require
absolute clarity for licensing and copyright". Do you say this is the
case for LLM output?

You say there should be no special exception, so please make explicit
whether upstream projects no longer require "absolute clarity for
licensing and copyright" or that requirement is fulfilled for LLM
output.

Well, in my book any NEW package that used LLM contribtions does not meet the DFSG; this is different for packages already in the archive such as the kernel where we just can't go and rip out the source code in question.
Though our position is that LLM contributions are contrary to documents already ratified by Debian, in order to remove all doubt, we propose the following addition to the Social Contract:
6. Works Created through the use of Large Language Models (LLMs)
    We will not allow direct contributions to Debian written with the use or 
assistance
    of large language models (LLMs) or other generative AI tools. Direct 
contributions are
    defined as packaging, native Debian software like lintian, documentation 
and translations
    written by Debian contributors, and official Debian web resources, etc. 
Other categories
    such as upstream projects written with LLM assistance may be included at a later date.     This ensures that Debian remains a stable, trusted, and reliable operating
    system, and protects the interests of the Debian volunteers who make it 
possible.

So there are now special exceptions for contributions to Debian vs.
contributions to Debian via upstream projects?

As patches are part of the packaging, I guess backporting security
fixes from upstream will be forbidden? Or will there be an exception
for this? If yes, please include it.

Done so in the updated version.
Are backports of feature patches also allowed? Or will there be no
exception for those?

How will you handle existing LLM contributions? Remove everything? Or
are only new contributions problematic?

As stated above, existing code replacement is always problematic, thus this would only affect new contributions from when it'd be in effect.

best,

--

Matthias Geiger <werdahias>

Debian Developer -- KiCad Contributor
GPG: ECBEDBB607B9B2BE

Reply via email to