Re: Beyond QA: Uploaders field hygiene

Simon Josefsson <[email protected]>
Newsgroups gmane.linux.debian.devel.project
Message-ID <[email protected]>
Jonas Smedegaard <[email protected]> writes:

> Quoting Sebastiaan Couwenberg (2026-08-15 11:07:03)
>> On 8/15/26 10:25 AM, Tobias Frost wrote:
>> > But this is not just an MIA team task. The Uploaders field is part of
>> > the package's maintenance metadata, and keeping it reasonably accurate
>> > should be part of maintaining the package. If you notice that someone
>> > listed there no longer appears to be actively maintaining the package,
>> > please consider cleaning it up.
>> 
>> This will result in no-human-maintainers lintian issues, because
>> many packages are on life support with team uploads where no person
>> wants to commit to the package by adding themselves to Uploaders.
>> 
>> I guess we should just acknowledge that fact in the override comment.
>
> If noone in a team wants to commit to a package by adding themselves as
> in the Uploaders field, it seems that package is team-*un*maintained
> and that fact should be acknowledged by moving the package to QA team.

I disagree -- and think this is at the core of what proper "team"
maintainance of packages could be.

To me, team maintainance would be one where the team as a collective
take responsibility for a package, but no individual person insists on
the ego-boost of assigning personal ownership of the outcome, and
through social means of the Uploader field signal that others should not
feel the same level of ownership.

I think this social signal related to the Maintainer/Uploaders field is
detrimental to a harmonous team spirit in the long run.  It establish
personal ownership and excludes others from feeling empowered to work on
the package, even though they are part of the same team, or if they are
a Debian Developer (which we would prefer to behave like a team).

I believe many Go packages in Debian has this property.  Few people
doing work on each of the dependent Go package cares about that
particular package strongly enough to insist that they have to must a
say in the packaging of it.  This is true for all the packages I help
work on, at least.

Thus, by getting rid of the Maintainer/Uploader fields, I believe we
could get a better collective long-term outcome for packages.  All
packages are collectively maintained by "Debian Developers", for which
we have a process for.  Yes, there will be local "accidents" where this
leads to bad mistakes in packages by people not familiar enough with a
package.  This will be used as an argument against this concept, and
against the people doing those mistakes.  I don't think it is a valid
argument.  It is an argument for improving QA tooling, documentation,
and collaboration processes.  Not for excluding people to contribute,
and further cementing the current situation.

We have some teams in Debian that operate like this, at least to me as
an outsider.  The release team, security team, and the DFSG team
generate artifacts that may sometime have personal names associated with
them (like security announcements), but it always feel like a group
effort rather than a personal effort.  I'm not sure people inside these
teams feel the same, but at least that's the perception I get from an
outside perspective.  I think that is a sign of maturity and health.

/Simon
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmqBdX8UHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJp4fWRBQkOa+rdAAoJENc89jjFPAa+hWIA
/1lQvrJeGlQq50lP6tm99D1zDy7J1tQ3ha4x0Jx7rkFTAP9hpUKuTvm6m1fXyiZV
YZlu2+Id/Dq3CIAZvNF+XEr2BLgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCaeCW1wUJDmqLVgCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+s7AA+gIIHpBApDpcDj1sKhzDngmpvwQf0VkHme6s+EG7qSgpAQDe
/XMrU0c0Pa3ji85cMqZhvzJOFI/soe662lzL0QY3Bbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJp4JbXBQkOaottAAoJENc89jjF
PAa+RNUA/2faQO/nFT06E+MlhlQdo/0chlQXC5TZMPTVvVBFwoLOAP9xLJK0ow5E
jTzYJB4K810AL/Iv6PEOAEgA4cPTHVlbCQAKCRBRcisI/kdFogHNAQDCBq7Ld0L/
z5xuscJGo+Bgskczrnyqz2vO+Cu4/FJZ5QEA0mwkM2540pSu2ZyIqoqaqwYQAPnO
hZZctt3+5aRixgU=
=cAlH
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.