Re: GR: Ban LLM contributions from Debian
Simon Richter <[email protected]>
| Newsgroups | gmane.linux.debian.devel.vote |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On 7/23/26 00:35, Matthias Geiger wrote:
> BEGIN PROPOSAL
>
>
> Preamble
> ===========
>
> This proposal aims to expressly forbid any contributions to Debian
> written with
> the use or assistance of large language models (LLMs) or other
> generative AI tools.
>
> The scope of this GR is (non-exhaustive): - Debian source packages
> - Official Debian project software, such as lintian
> - Debian web resources - Documentation and translations added by Debian
> contributors
> - Official communication from Debian
>
> It does not include: - Upstream projects using LLMs for development
> - AI-related software
>
>
> Rationale
> ===========
>
> Debian has a well-earned reputation for stability. This stability is
> crucial to Debian's position in the free software ecosystem. It is our
> belief that widespread LLM usage comes from the "move fast, and break
> things" attitude that, while common in many parts of this industry, is
> contrary to what makes Debian Debian, and is inappropriate for Debian
> contributors.
> In practical terms, LLM usage raises the following concerns:
> 1. Copyright LLM output has very unclear legal status: it may be
> possible to copyright on its own merits, or not; it may be affected by
> all of the licenses and copyrights in the training data, or not.
> Debian Policy and the DFSG require absolute clarity for licensing and
> copyright[1][2]. Software and other contributions written conventionally
> by humans with unclear copyright or license status are not allowed
> in Debian;
> LLM output should not have a special exception to this.
> 2. Quality LLM output has many well-known problems with accuracy.
> [3][4][5] A LLM can never "know" if its output is correct since it
> merely produces syntactically likely combinations of the training data.
> In some environments this is good enough. In Debian, it is not. For
> instance, in packaging, each Debian source package is unique. Since
> packaging syntax and best practices have changed over time, a LLM-
> produced package will have a mixture of contents spanning the age of the
> archive, with watch files that do not work, overrides out of context,
> imaginary copyright, and will generally be unfit for upload. A
> seasoned Debian contributor with packaging expertise may find some
> limited usefulness here, but a new contributor cannot, and would not
> know how to fix it. These same quality and accuracy concerns apply
> clearly to all of the areas listed in the scope of this proposal above.
> If Debian were a closed organization comprising only domain experts
> who never leave, this might not be an issue; however,
> 3. Community Debian is a project that is more than just code: it is a
> community built on shared interests in free software and solving
> technical problems. Debian intentionally grows this community through
> many means, and new contributors are always encouraged to join. Allowing
> LLM contributions breaks this. New contributors submitting LLM output
> for review places an unnecessary strain on the reviewer, which can lead
> to burnout. Furthermore, LLM-dependent new contributors do not
> actually learn and understand the details of Debian packaging or
> processes, so they cannot come to replace a former burned out DD.
> 4. Ethics LLM companies directly hurt the free software community as
> whole by scraping the whole web for training data without any regard for
> license, copyright, or even established
> conventions such as robots.txt.[6]
> This has had a major negative impact on Debian's public web
> resources, effectively a large scale and perpetual Denial of Service
> attack on sites that many users rely on.
> As a consequence parts of our infrastructure were not reachable at
> all, and JS-based checks had to be enabled. Many other projects were
> similarly affected. Furthermore, LLM training consumes a staggering
> amount of resources[7], and the user verification systems that we have
> been forced to implement as protection waste resources as well.
> This is blatant disregard for the internet as a public resource,
> wastes system administrator time, and although individual LLM sessions
> do not directly use massive resources or DoS the public web, the fact
> that they can be used at all is a direct result of these unethical
> behaviours by the LLM companies.
> Debian has a Social Contract. [8] Our priorities are our users and free
> software.
> Debian is Stable. [9] Users and organizations choose Debian because it
> is reliable and secure.
>
> Debian is not here to generate as much code as possible requiring manual
> review by a shrinking number of human volunteers, or to package every
> piece of software, or to rush new features, but these are what LLMs are
> used for.
> In conclusion, allowing LLM contributions is contrary to the social
> contract and the common cause of creating a free operating system with a
> focus on quality and stability.
>
>
> Proposal
> ===========
>
> In the interest of not eroding Debian's reputation or further damaging
> the community, LLM-assisted contributions should be prohibited from
> inclusion in Debian.
> Though our position is that LLM contributions are contrary to documents
> already ratified by Debian, in order to remove all doubt, we propose the
> following addition to the Social Contract:
> 6. Works Created through the use of Large Language Models (LLMs)
> We will not allow direct contributions to Debian written with the
> use or assistance
> of large language models (LLMs) or other generative AI tools. Direct
> contributions are
> defined as packaging, native Debian software like lintian,
> documentation and translations
> written by Debian contributors, and official Debian web resources,
> etc. Other categories
> such as upstream projects written with LLM assistance may be
> included at a later date. This ensures that Debian remains a stable,
> trusted, and reliable operating
> system, and protects the interests of the Debian volunteers who make
> it possible.
>
> Possible Issues
> ===========
>
> Other projects exploring similar decisions have elicited a common reply:
> "How will you enforce a ban on LLM contributions?"
> While enforcement could be a challenge, this is a statement of intent by
> the Debian community, and we trust this community to adhere to it in
> good faith.
>
> END PROPOSAL
Seconded.
Regarding enforcement: this is a social problem only, therefore it needs
a social solution.
We take people at their word. If that trust turns out to be unfounded,
that has social consequences.
Simon
OpenPGP_signature.asc
(application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEtjuqOJSXmNjSiX3Tfr04e7CZCBEFAmpg9EYACgkQfr04e7CZ CBG5zAf/SJr+H37tL/K42YPPkwG1NfRgATPVfQWE2wv808H9107N/RbenNjSeWFJ x2OCGVlDLRJgg2JY2cpd8+gG/0WWdwfaT5nC42jUp+tGkKYUQ6GggS4CsllvtWgD rjpOX8jBjnY2EiUSDZn6w1HluCkhE2rcszV0PiRimOsBMig0EC5NDv5G5tVKEuZr U5sEhlzN+YzgC7j7Gvrz6srdpbZgAFHG5y9DhrbzNV+zvN7KzqTfAxFM3XNtotpG jP/QqgLb5pgsfjU7s+xmCrCdOqulyAtFcatpDUDPM3XfPNL2Z3QOKnSmlLPR228n iRouVQU1i9fCkSUv4UQMne0Ich8baQ== =J2G1 -----END PGP SIGNATURE-----