Re: Ballot option: Debian is created by humans

Gard Spreemann <[email protected]>
Newsgroups gmane.linux.debian.devel.vote
Message-ID <87ldacnuq6.fsf@moose>
"Theodore Tso" <[email protected]> writes:

> On Tue, Aug 11, 2026 at 04:10:00PM -0500, Gard Spreemann wrote:
>> The proposal deals with *direct* contributions to Debian, including, but
>> not limited to:
>> 
>> * Debian packaging
>> * Submissions (messages, bug reports, patches, etc.) to the BTS, Salsa,
>>   mailing lists and other Debian platforms 
>> * Debian project software
>> * Debian infrastructure
>> * Debian web resources
>
> What is meant by "Debian infrastructure" or "Debian web resources".

I meant computers run by the project, and web services run by the
project.

> Does Apache or the Linux Kernel considered part of the Debian
> infrastructure or Debian web resource?  These terms aren't explicitly
> defined, so this could lead to confusion.

Just their Debian packaging. Not their upstream parts.

>> With this principle in mind, the
>> proposal does not affect the use of generative AI as an assisitive tool
>> to explore, research, analyze, critique, etc., when contributing.
>
> If the Generative AI discoveres that there is a mising unlock in an
> error return path, does that count as an assistive tool?

Absolutely.

> What if it creates a patch which adds the missing mutex unlock?  Does
> that count as an assistive tool, or "generated code"?

That counts as generated code. Now, if the patch literally just adds an
unlock, then it's highly unlikely that you would write it differently
from the AI. So there is no way for anyone to distinguish between
AI-generated code and human-made code. And then, to me at least, the
whole question becomes moot under this proposal.

> And if we apply that patch on a Debian web server, would that be
> prohibited by this proposal?  Even if it prevents a high severity,
> actively exploited vulnerabity?

Since the patch is indistinguishable from human code, I don't think it's
where our discussion energy should go – if we assume good faith from
people using generative AI in an assistive capacity. I try to think
about it the way we think about generated code in a more traditional
sense. At some small size extreme, also (clasically, by say a build
script) generated code becomes so trivial that we probably wouldn't care
about discussing whether it's generated or not, no?

I agree that it's a weakness in my proposal that "trivial" (in size)
contributions – contributions that really can't end up very differently
whether written by an AI or a human – aren't addressed explicitly.

>
> "Humans create Debian" is a nice tagline, but it doesn't particularly
> well defined.  

That's true. But I also think it's true for most GRs that go beyond
purely technical things.

> After all humans are tool-using animals, including compilers and
> LLM's.

… and yet we frown upon compiled code in packaging contributions.


 Best,
 Gard
signature.asc (application/pgp-signature, 857 B)
-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEEz8XvhRCFHnNVtV6AnRFYKv1UjPoFAmp7pbISHGdzcHJAbm9u
ZW1wdHkub3JnAAoJEJ0RWCr9VIz6mMEP/R1lWjoc8M11/7vLKhcNpkSvUdZ6B40q
/F1t3QhKdKMUblgecARUWMgUhcOfefxotJpFQJjkUsybeUBQD549FHITpWgFIVRM
zFxa4p6XckTfzQTs63XrMmBF8RPASK9mhaSyB00JcijBcyMiEONisHpIghXk10J0
lL95uuADDFs7G6RllRH83a3PCwXA4rNWSNX/QguSe7PW0QSOjDSFRoJChuaEkLUD
5zx/7kXVs2yj/0MeO6KRrvTm9cn7N71YwvKmCy9fJPtc4wunYwWvNfzuIbHMoGlS
S3/LrcysyO0/8WiX8usV7IWGLsZw/26zFVf6bhRgm+dI5JBmuooSKEBA2G7KqksC
ZpY7tK6ovbzr46fWcXcfMrqBhWYrJ9CbDrItoV+Zt0ZB8EVMjbf0l3WFsSBUOvKL
aPzn0kA6YiywxJ1JWMmmPs9wm+UgSvA/T3WLYsNolAtA/SWiXTXtMxQw/sl2ppQy
L6xMiqo7OdTrQ7neK4e9nQqZoH3DkB1z8a+2em5MlzDzYGoKgQ/t1fuaba0E1GK/
Q2/QDWC1q+L2o9JEuwSivyBvM7IovKqiRG5H1WZ3ooCQpa456EthPbNQRB/TsR7i
9TzP8PyygaH4CZ0ihswgbUTWjPG3IukzHPjjTsbhPasXCalwgjifTqkwAhn9WUab
CcaqKjhM97BZ
=kwS0
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.