Re: Keepassxc hard masked, why ?

Philipp Ludwig <[email protected]> Fri, 17 Apr 2026 17:00:31 +0200
Newsgroups gmane.linux.gentoo.user
Message-ID <[email protected]>
Thank you for this insight. This is far worse than I imagined.

On 4/17/26 16:40, Eli Schwartz wrote:
> On 4/17/26 10:17 AM, Lilia Marina Jiménez Redondo wrote:
>>> The AI policy isn't about software merely packaged by Gentoo (e.g
>>> the Linux kernel), but about the software that's part of Gentoo's
>>> infrastructure.
>>
>> Part of the reason why I thought that AI use upstream was partly the
>> reason for the masking was because there was a mention of AI in the
>> Masks message. Thanks for the clarification :)
> 
> 
> Use of LLM vibe coding is a factor that can influence the gentoo
> maintainer's beliefs regarding whether the package is low quality enough
> that it might not be worth packaging at all.
> 
> If not that, then at least that the maintainer is no longer willing to
> maintain it, and the package flips over to "maintainer-needed" status.
> That is a risky place to be, because packages which are
> maintainer-needed are eligible for last-rites and removal from Gentoo on
> the grounds that "this package requires work in order to be usable and
> that work isn't happening, we are removing the package because it
> doesn't work anymore".
> 
> Some packages, like dev-python/chardet, have been rewritten from scratch
> as vibe coded in newer versions. And we don't package them at all past
> that point, but that is less because of the LLM and more because... the
> package is exceedingly rude and disrespectful towards the original author.
> 
> Or dev-python/autobahn, which has a mask message as follows:
> 
> # Upstream has switched to LLM-first coding which has already caused
> # a number of suspicious bugs.  At this point, new versions
> # of the packages cannot be trusted to be safe to use.  Furthermore,
> # the maintenance cost of dealing with packaging bugs alone
> # is overwhelming to human maintainers of this package.
> 
> That is, here the practical effects of LLM coding have kicked in, and
> the package is such low quality that we tried and failed to package it
> because it was broken, and gave up because the upstream developer used
> an LLM to hallucinate the cause of the bug, write a patch which didn't
> fix the bug, and respond to the Gentoo reporter by saying "we fixed the
> problem" and closing the report when it wasn't in fact fixed or even
> looked at.
> 
> So, yes, packages can be removed from Gentoo because their upstream
> developers use LLMs to develop it. They just aren't removed "because
> violating the LLM ban".
> 
>