Responsible use of llms can't be achieved. Can you verify that all of your training data are square with its creators? If not, how is that responsible?
post
In a nutshell, it looks like AI disclosures are encouraged, but not required, and AI usage is encouraged to be human reviewed, but not required. They have also stated they will not allow the use of online AI services for security reasons (but how this will be enforced I'm not sure, since they are relying on the judgement of contributors)
The only question I have is why. Genuinely.
Debian exists. It has existed for decades. It works. "Oh but AI makes it faster" so fucking what? We didn't need "faster" for years whilst it worked fine, it's not a product on a deadline.
That's true. Nonetheless the maintainers seem to see AI as a valid way to reduce their workload.
No community distro has the capacity to fork thousands of packages and maintain them. That's what a true no Ai policy would require. I also have to add that the Linux kernel itself would need to be forked and then maintained. Just the latter point alone is enough to make all this moot.
At first I was afraid that they would allow for an irresponsible use. But no, they explicitly say "responsible", so that danger is no more. I'm very much relieved.
Also they explicitly mention that humans will remain accountable. Not Nature, or Fate, or the gods; mark that. Good thinking there!
Problems solved.
This is good news; Debian is still the way to go for me:
Debian acknowledges that the legal status of material produced by generative AI systems remains the subject of ongoing discussion in many jurisdictions, including questions relating to copyright, authorship, licensing, and potential reproduction of training material. The Project does not seek to resolve these unsettled legal questions through this General Resolution, nor does it adopt a position on whether AI-generated output is, in whole or in part, copyrightable or derived from copyrighted works.
They basically pass the buck to the individual developer without taking any responsibility themselves.
Debian acknowledges that the legal status of material produced by generative AI systems remains the subject of ongoing discussion in many jurisdictions, including questions relating to copyright, authorship, licensing, and potential reproduction of training material.
The responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian.
"It may be illegal or against FOSS, but that's up to you to decide, good luck I guess"
Yikes, rest in peace Deb users. I just hope it never happens to my distro.
if your distro uses the linux kernel then its already happened.
This vote was not about upstream projects included in the Debian distro, it was about the Debian project itself.
I ain't shook up about it. There's not really a surefire way to detect tool-assisted code gen anyway, so IMO the acceptance criteria should be the same as it's always been, tool-assisted or otherwise. Which is ultimately the path they chose to take.
Obvious slop should be immediate permanently banworthy, sloppers can just keep burning new accounts (as long as they have access to new IP addresses) while real developers deserving of praise and reputation thrive.
sloppers can just keep burning new accounts (as long as they have access to new IP addresses) while real developers deserving of praise and reputation thrive.
Becoming a Debian developer requires you to meet an existing Debian developer in person and have your public key signed by them. It's not possible to keep burning new accounts unless you go and meet a different Debian developer each time and there's a limited number of them in each region and they usually meet together, so more than one person will see your face.
Yep. I'm not familiar with Debian's strategy specifically, but generally, I think any new contributor to a project should be subject to heightened scrutiny. My policy is that new contributors should start small and develop a rapport with the maintainers before submitting more ambitious (and for the maintainers, more costly to review) large and/or critical path PRs. It was a good policy before LLMs and I think it remains a pretty robust method of weeding out irresponsible devs without wasting a ton of maintainer time. There are simply more slop PRs to reject sight unseen these days, which is admittedly very annoying, but the process is much the same as it's always been.
I'll admit I don't maintain any projects anywhere near the popularity or volume of the Debian project, so I'm not really sure what the view is from their vantage point.
I still think that's not good enough, that treating them fairly is a stupid waste of time and resources and unfair to everyone else.
Just make the rule "any slop" and give the idiots a checkbox so they can ban themselves for reasons which will never be revealed to them (sloppers don't read documents, it'll take them a while to figure out). Also start banning people when evidence surfaces of them admitting to slopping.
I don't like this concept that a slopper can potentially produce decent code, the data shows this simply isn't true: sloppers produce vast amounts more and worse bugs and vulnerabilities. It's better for the health of the project to ban it in every scenario.
i'm actually a little surprised, given their history about being so hardcore about dfsg compliance.
This email from 2016 by jwz springs to mind.
I guess you want Debian to be the kind of operation that uses the work of others while blatantly and explicitly ignoring the wishes of the person who did the actual creative work.
I am increasingly of the opinion that all software developers and adjacent people are fucking scum unless proven otherwise.
as a dev I second this opinion.
I was surprised by how many were Trump supporters.
then I was surprised at how many were anti-vax.
now I'm not even surprised.
Oh no, the people creating free shit for you to use that's not monetized in any way, want to reduce their workloads. Scum!
As long as they don't allow AI bots to submit changes, this is probably a realistic decision. Assuming that code generated by AI is never going to be copyrighted by the AI companies. In light of this uncertainty I don't understand why they don't require AI code to be flagged as such. That bit seems like a really bad idea, legally speaking.
There is no such thing as "responsible use of GenAI". That said, I understand the decision in the face of even Linus Torvalds allowing AI-generated code into the kernel. If Debian would have banned AI code entirely they would have had to fork every single thing they include in their distro, wipe the AI code from it, and then work to develop it further themselves. It would be too gargantuan a task.
None of the proposals would have banned AI usage in upstream projects, but banning AI usage in the context of the Debian project was on the table
Dammit. Need to find a new OS.
top 50 comments