Debian patch review process (was Complaint regarding conduct on bug 1132795)

Michael Still <[email protected]> Wed, 17 Jun 2026 05:57:52 +1000
Newsgroups gmane.linux.debian.devel.ctte
Message-ID <CAEd1pt5QiD9-UUV5jP=U7=L2pM5f6c1WPcUY3jWoYbcTO8iRcw@mail.gmail.com>
--0000000000006016b10654645c00
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello what is hopefully the Debian TC.

I recently had a weird experience on a Debian bug as an upstream software
author. I am not a Debian Developer.

The relevant artifacts are:

* https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1132795
* https://github.com/mikalstill/pngtools/issues/37
*
https://www.madebymikal.com/is-this-the-standard-of-behavior-we-get-from-de=
bian-now/
*
https://www.madebymikal.com/lets-see-if-the-debian-complaints-process-gets-=
anywhere/

And to a lesser extent the discussion at
https://www.linkedin.com/feed/update/urn:li:activity:7471777300879982592/
although I understand that some aren't super into walled garden business
themed social networks.

I raised the conduct I experienced with [email protected] and while
disappointed that the answer (below) appears to be that this is aligned
with Debian's expectations of upstream interactions, I am more concerned
about another issue. I want to be super clear that I genuinely don't care
about a cosmetic patch to pngtools because of one complaining and quite
rude user.

What I do care about is that I think the experience demonstrated that there
isn't much if any review process for these patches being added. I would
like to understand how Debian ensures that supply chain attacks aren't
being inserted into packages at this packaging layer given they appear to
be able to be landed by a single Debian Developer without any internal
review. Surely this class of attacks should be of concern to Debian just as
much as people's freedom to own and change the software they run?

Thanks,
Michael


---------- Forwarded message ---------
From: Michael Still <[email protected]>
Date: Wed, Jun 17, 2026 at 5:43=E2=80=AFAM
Subject: Re: Complaint regarding conduct on bug 1132795
To: <[email protected]>
Cc: <[email protected]>, <[email protected]>



Honestly, this is a disappointing response while being aligned with my
expectations.

The Debian Developer on that bug, "atzlinux" / "xiao sheng wen" failed to
either attempt to address the unacceptable behaviour of the others in the
bug and in several cases encouraged that behaviour:

The Debian code of coduct calls for community members to be respectful /
collaborative: atzlinux failed to file a meaningful bug upstream. The
entire bug report from him is "=E2=80=9CResolution: (not specified)=E2=80=
=9D is pointless.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1132795. Thanks!".
Largely this entire experience for me has flowed by atzlinux failing to do
a reasonable job of that first minimal step, and then failing to intervene
and course correct when his actions snowballed.

I replied to artzlinux's terse bug report and asked for the bug commenters
to stop describing me as "unwell" and discussing my mental health, and
requesting more details and a justification for why the behaviour was
erroneous given it was specifically added to address a previous bug. I
haven in fact never said I would refuse to take the patch, I have asked for
a meaningful and respectful conversation.

The other users continued in their personal attacks and again instead of
trying to settle things down he simply landed a patch in Debian instead of
replying to me.

I understand that Debian believes in software freedom, including the right
of Debian Maintainers to patch upstream code. I have been using Debian a
very long time and know a lot of Debian Developers. However, I think this
bug has made me realise that Debian lacks a quality control process to
ensure that those patches are reviewed by more than their author, and align
with the overall intent of Debian. I am surprised that the idea that a
supply chain attack could be added at the Debian packaging level appears to
have not been considered at all.

Michael


On Wed, Jun 17, 2026 at 4:33=E2=80=AFAM Don Armstrong <[email protected]> wrot=
e:

> On Mon, 15 Jun 2026, Michael Still wrote:n
> > I am the author and maintainer of pngtools, a PNG image tooling
> > package that has been packaged by Debian for a long time.
>
> Thank you for your contributions to FOSS.
>
> > I have recently experienced conduct from Debian developers and users
> > on https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1132795
>
> There is exactly one Debian Developer in that discussion, atzlinux.
> Everyone else is a user.
>
> Everyone is also communicating in a language (english) which does not
> appear to be their native language, so please give everyone grace as
> they occasionally use imprecise language.
>
> While ideally every patch that Debian produces gets upstreamed, Debian
> developers can (and frequently do) decide to carry patches that diverge
> from upstream to better serve our users and the distribution. If you
> disagree, the best way to do so is to engage with the Debian Developer
> and explain why you think they should use a different approach.
>
> At the end of the day, we're all volunteers; direct engagement assuming
> good intent yields the best outcomes.
>
>
> Thanks!
>
> --
> Don Armstrong                      https://www.donarmstrong.com
>
> life's not a paragraph
> And death i think is no parenthesis
>  -- e.e. cummings "Four VII" _is 5_
>

--0000000000006016b10654645c00
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br>Hello what is hopefully the Debian TC.<div><br></div><=
div>I recently had a weird experience on a Debian bug as an upstream softwa=
re author. I am not a Debian Developer.<br><br>The relevant artifacts are:<=
/div><div><br></div><div>*=C2=A0<a href=3D"https://bugs.debian.org/cgi-bin/=
bugreport.cgi?bug=3D1132795">https://bugs.debian.org/cgi-bin/bugreport.cgi?=
bug=3D1132795</a><br>*=C2=A0<a href=3D"https://github.com/mikalstill/pngtoo=
ls/issues/37">https://github.com/mikalstill/pngtools/issues/37</a></div><di=
v>*=C2=A0<a href=3D"https://www.madebymikal.com/is-this-the-standard-of-beh=
avior-we-get-from-debian-now/">https://www.madebymikal.com/is-this-the-stan=
dard-of-behavior-we-get-from-debian-now/</a><br>*=C2=A0<a href=3D"https://w=
ww.madebymikal.com/lets-see-if-the-debian-complaints-process-gets-anywhere/=
">https://www.madebymikal.com/lets-see-if-the-debian-complaints-process-get=
s-anywhere/</a></div><div><br></div><div>And to a lesser extent the discuss=
ion at=C2=A0<a href=3D"https://www.linkedin.com/feed/update/urn:li:activity=
:7471777300879982592/">https://www.linkedin.com/feed/update/urn:li:activity=
:7471777300879982592/</a> although I understand that some aren&#39;t super =
into walled garden business themed social networks.</div><div><br></div><di=
v>I raised the conduct I experienced with <a href=3D"mailto:[email protected]=
ian.org">[email protected]</a> and while disappointed that the answer =
(below) appears to be that this is aligned with Debian&#39;s expectations o=
f upstream interactions, I am more concerned about another issue. I want to=
 be super clear that I genuinely don&#39;t care about a cosmetic patch to p=
ngtools because of one complaining and quite rude user.</div><div><br></div=
><div>What I do care about is that I think the experience demonstrated that=
 there isn&#39;t much if any review process for these patches being added. =
I would like to understand how Debian ensures that supply chain attacks are=
n&#39;t being inserted into packages at this packaging layer given they app=
ear to be able to be landed by a single Debian Developer without any intern=
al review. Surely this class of attacks should be of concern to Debian just=
 as much as people&#39;s freedom to own and change the software they run?</=
div><div><br></div><div>Thanks,</div><div>Michael</div><div><br><br><div cl=
ass=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_a=
ttr">---------- Forwarded message ---------<br>From: <strong class=3D"gmail=
_sendername" dir=3D"auto">Michael Still</strong> <span dir=3D"auto">&lt;<a =
href=3D"mailto:[email protected]">[email protected]</a>&gt;</span><br>Date:=
 Wed, Jun 17, 2026 at 5:43=E2=80=AFAM<br>Subject: Re: Complaint regarding c=
onduct on bug 1132795<br>To:  &lt;<a href=3D"mailto:[email protected]">=
[email protected]</a>&gt;<br>Cc:  &lt;<a href=3D"mailto:[email protected]=
an.org">[email protected]</a>&gt;,  &lt;<a href=3D"mailto:community@deb=
ian.org">[email protected]</a>&gt;<br></div><br><br><div dir=3D"ltr"><br=
><div>Honestly, this is a disappointing response=C2=A0while being aligned w=
ith my expectations.</div><div><br></div><div>The Debian Developer on that =
bug, &quot;atzlinux&quot; / &quot;xiao sheng wen&quot; failed to either att=
empt to address the unacceptable behaviour of the others in the bug and in =
several cases encouraged that behaviour:</div><div><br></div><div>The Debia=
n code of coduct calls for community members to be respectful / collaborati=
ve: atzlinux failed to file a meaningful bug upstream. The entire=C2=A0bug =
report from him is &quot;=E2=80=9CResolution: (not specified)=E2=80=9D is p=
ointless. <a href=3D"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D11=
32795" target=3D"_blank">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=
=3D1132795</a>. Thanks!&quot;. Largely this entire experience for me has fl=
owed by atzlinux failing to do a reasonable job of that first minimal step,=
 and then failing to intervene and course correct when his actions snowball=
ed.</div><div><br></div><div>I replied to artzlinux&#39;s terse bug report =
and asked for the bug commenters to stop describing me as &quot;unwell&quot=
; and discussing my mental health, and requesting more details and a justif=
ication for why the behaviour was erroneous given it was specifically added=
 to address a previous bug. I haven in fact never said I would refuse to ta=
ke the patch, I have asked for a meaningful and respectful conversation.</d=
iv><div><br></div><div>The other users continued in their personal attacks =
and again instead of trying to settle things down he simply landed a patch =
in Debian instead of replying to me.</div><div><br></div><div>I understand =
that Debian believes in software freedom, including the right of Debian Mai=
ntainers to patch upstream code. I have been using Debian a very long time =
and know a lot of Debian Developers. However, I think this bug has made me =
realise that Debian lacks a quality control process to ensure that those pa=
tches are reviewed by more than their author, and align with the overall in=
tent of Debian. I am surprised that the idea that a supply chain attack cou=
ld be added at the Debian packaging level appears to have not been consider=
ed at all.</div><div><br></div><div>Michael</div><div><br></div></div><br><=
div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Jun=
 17, 2026 at 4:33=E2=80=AFAM Don Armstrong &lt;<a href=3D"mailto:don@debian=
.org" target=3D"_blank">[email protected]</a>&gt; wrote:<br></div><blockquote =
class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px sol=
id rgb(204,204,204);padding-left:1ex">On Mon, 15 Jun 2026, Michael Still wr=
ote:n<br>
&gt; I am the author and maintainer of pngtools, a PNG image tooling<br>
&gt; package that has been packaged by Debian for a long time.<br>
<br>
Thank you for your contributions to FOSS.<br>
<br>
&gt; I have recently experienced conduct from Debian developers and users<b=
r>
&gt; on <a href=3D"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1132=
795" rel=3D"noreferrer" target=3D"_blank">https://bugs.debian.org/cgi-bin/b=
ugreport.cgi?bug=3D1132795</a><br>
<br>
There is exactly one Debian Developer in that discussion, atzlinux.<br>
Everyone else is a user.<br>
<br>
Everyone is also communicating in a language (english) which does not<br>
appear to be their native language, so please give everyone grace as<br>
they occasionally use imprecise language.<br>
<br>
While ideally every patch that Debian produces gets upstreamed, Debian<br>
developers can (and frequently do) decide to carry patches that diverge<br>
from upstream to better serve our users and the distribution. If you<br>
disagree, the best way to do so is to engage with the Debian Developer<br>
and explain why you think they should use a different approach.<br>
<br>
At the end of the day, we&#39;re all volunteers; direct engagement assuming=
<br>
good intent yields the best outcomes.<br>
<br>
<br>
Thanks!<br>
<br>
-- <br>
Don Armstrong=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=
 =C2=A0 =C2=A0 <a href=3D"https://www.donarmstrong.com" rel=3D"noreferrer" =
target=3D"_blank">https://www.donarmstrong.com</a><br>
<br>
life&#39;s not a paragraph<br>
And death i think is no parenthesis<br>
=C2=A0-- e.e. cummings &quot;Four VII&quot; _is 5_<br>
</blockquote></div>
</div></div></div>

--0000000000006016b10654645c00--