"Theodore Tso" <[email protected]> writes: > On Tue, Aug 11, 2026 at 04:10:00PM -0500, Gard Spreemann wrote: >> The proposal deals with *direct* contributions to Debian, including, but >> not limited to: >> >> * Debian packaging >> * Submissions (messages, bug reports, patches, etc.) to the BTS, Salsa, >> mailing lists and other Debian platforms >> * Debian project software >> * Debian infrastructure >> * Debian web resources > > What is meant by "Debian infrastructure" or "Debian web resources".
I meant computers run by the project, and web services run by the project. > Does Apache or the Linux Kernel considered part of the Debian > infrastructure or Debian web resource? These terms aren't explicitly > defined, so this could lead to confusion. Just their Debian packaging. Not their upstream parts. >> With this principle in mind, the >> proposal does not affect the use of generative AI as an assisitive tool >> to explore, research, analyze, critique, etc., when contributing. > > If the Generative AI discoveres that there is a mising unlock in an > error return path, does that count as an assistive tool? Absolutely. > What if it creates a patch which adds the missing mutex unlock? Does > that count as an assistive tool, or "generated code"? That counts as generated code. Now, if the patch literally just adds an unlock, then it's highly unlikely that you would write it differently from the AI. So there is no way for anyone to distinguish between AI-generated code and human-made code. And then, to me at least, the whole question becomes moot under this proposal. > And if we apply that patch on a Debian web server, would that be > prohibited by this proposal? Even if it prevents a high severity, > actively exploited vulnerabity? Since the patch is indistinguishable from human code, I don't think it's where our discussion energy should go – if we assume good faith from people using generative AI in an assistive capacity. I try to think about it the way we think about generated code in a more traditional sense. At some small size extreme, also (clasically, by say a build script) generated code becomes so trivial that we probably wouldn't care about discussing whether it's generated or not, no? I agree that it's a weakness in my proposal that "trivial" (in size) contributions – contributions that really can't end up very differently whether written by an AI or a human – aren't addressed explicitly. > > "Humans create Debian" is a nice tagline, but it doesn't particularly > well defined. That's true. But I also think it's true for most GRs that go beyond purely technical things. > After all humans are tool-using animals, including compilers and > LLM's. … and yet we frown upon compiled code in packaging contributions. Best, Gard
signature.asc
Description: PGP signature

