-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
1. Overview
- -----------
This email covers two topics that are separate but have some intersection:
There has to be a clearer separation between what Freexian activities
are under oversight of Debian and can be called Debian and might happen
on our infrastructure - and what is an external company competing for
customers in our ecosystem.
While there is no lack of DDs interested in earning money doing LTS and
ELTS work, there is fewer interest in doing the same work unpaid in our
security team instead. In recent weeks I got the impression that the two
members who are doing nearly all the work in our security team seem to
be struggling to keep up with the increased workload due to AI, and I am
worried we might lose our security team to burnout.
2. Debusine, and Freexian in general
- ------------------------------------
While it is laudable that Freexian has the explicit goal of helping
Debian, Debian giving preferential treatment to one company might
outweigh the benefits when this drives away other contributors.
While there is valid criticism at the current use of GitLab in our core
infrastructure,[1] using Debusine in our infrastructure would be worse:
Similar to GitLab, Freexian SARL is a private for-profit company.
Similar to Gitlab, Debusine is Open Source that is also commercially
offered as SaaS.[2]
Worse than GitLab Inc., which is a neutral player providing equal offers
to everyone in the Debian ecosystem, Freexian SARL is competing directly
with the businesses and employers of many other contributors (including
many DDs) in our ecosystem.[3]
There are technical reasons why Debusine is IMHO not suitable for our
core infrastructure, but the point that this is a product of a company
competing in our ecosystem alone should be sufficient that Debian keeps
some distance from it.
A company asking on debian-devel-announce for volunteers to work unpaid
on their product is problematic.[4]
Two of the accepted Google Summer of Code 2026 projects are improvements
for Debusine.[5]
Does Google know that they pay students to work on a company product,
mentored by people working for that company?
Are the Debian mentors paid by Freexian for the mentoring?
Decisions which GSoC applications to select are made by the Outreach delegation.
A majority of the Outreach delegates are receiving income from Freexian.[6,7]
Did these delegates recuse themselves from GSoC due to the conflict of interest?
3. ELTS
- -------
Freexian ELTS is a commercial offer by an external company that has to
be clearly separate from anything called Debian.
It is problematic that information about Freexian ELTS is offered on the
same company website as the information about Debian LTS,[8] and that
Debian gives the impression of official status of ELTS by listing it in
distro-info and distro-info-data.
It should be made clearer to our users what is Debian and what is a
commercial offer by an external company, and Debian LTS information
should be moved to our website.
4. LTS
- ------
After an intervention from Freexian,[9,10] the regular support of
bookworm was shortened from what was originally planned - while longer
full support would have been better for our users, it would have been
worse for Freexian.
Until recently Freexian was transparent about the monthly Debian LTS
payments to individual contributors (multiply with € 85/hour[6]),[11]
but Freexian now removed this transparency.[12]
When non-profits like the Linux Foundation and companies sponsor
something that is called "Debian Long Term Support"[14] and is provided
on our (sponsored) infrastructure, we need more transparency and not
less.
It would be appropriate that Freexian sends detailed monthly financial
reports to a public Debian mailing list, including stating for each work
item invoiced by a Freexian contributor how much Debian LTS money was
spent on it.
Sending such a financial report for June 2026 at the same time as the
report about work done in June 2026 would be a good start.
With approximately € 300k annually[13] Debian LTS is among the larger
budgets in Debian.
Our publicity refers to "Debian and its LTS Team", and Debian does
encourage funding Debian LTS.[14] Debian recommending to fund Debian LTS
instead of recommending donating to Debian might be redirecting some
donations from Debian to Debian LTS.
Since the topic that Freexian no longer wanted my services will
invariably come up:
While there are many people who are doing good work in LTS (and ELTS)
and where the hours invoiced are in a reasonable relation to the work
done, a not so small part of money goes to the half dozen Freexian
contributors where the amount of hours invoiced always felt like an
order of magnitude larger than the quantity and quality of work
delivered. My conflict with Freexian management was around me trying
to get Freexian to do something about it.
Some examples:
Freexian contributors who might suddenly show up on the last day of a
month, do some rather trivial work, and invoice 30 or 50 hours every
month.[15]
A Freexian contributor invoices 19.5 hours[16] (€ 1657.50) from Debian
LTS (plus additional hours from ELTS) with a monthly report[17] that is
largely made up:
The zfs-linux DLA was issued, but this was the 4th month where money was
invoiced for working on this package[17,18,19,20] and no other DLA was
issued by this contributor during that time.
"Worked on phpmyadmin, zabbix, and atril but couldn’t complete them.
Will get back to it next month." There is not much trace of any work
done (or even a DLA issued) on these packages by this contributor.
Most front desk work (mainly triaging) is done with git commits, but
there is not a single commit by this contributor in the git tree[21]
during this week. The list of what was claimed to be triaged and Auto
EOL’d also looks quite similar to what was claimed to be worked on
(and invoiced) a month earlier.[18]
The cheeky "PS: it’s not. :)" for claimed debugging work regarding the
xz backdoor?
This would also have created git commits.
LTS was marked not affected by a member of our security team,[22]
and the ELTS releases were marked not affected by a different Freexian
contributor 2 weeks later.[23]
This monthly report was an example not an exception for this Freexian
contributor, and a point could be made that a DD who is defrauding
Debian LTS is defrauding Debian and should therefore be expelled
from Debian.
After sending analysis of more than one monthly report to the Freexian
managers responsible for LTS and ELTS I gave up, and the person is still
a Freexian contributor today.
A Freexian contributor, who as Debian maintainer of the package in
question should already know it quite well, invoices 130.75 hours[24,25,26,27]
(€ 11 113.75) from Debian LTS (plus additional hours from ELTS) without
ever delivering an LTS update for the package in LTS (buster) and
without doing any other significant work during these months.[28,29,30,31]
The response I got from the Freexian managers responsible for LTS and ELTS:
Santiago and I have communicated with <contributor> and we are satisfied
that the work reported is appropriate to the hours invoiced for July,
and the same going back to April. Based on that, we see no need for
further action.
5. Workload of our Security Team (and LTS)
- ------------------------------------------
For all incoming CVEs, our security team does:
- - map it to the Debian package name (or mark as not-for-us)
- For a CVE in a Debian package our security team does:
- link to the upstream advisory
- often search for the upstream commit(s) fixing it,
and link to them in the security tracker
- triage whether the CVE warrants a DSA for the package
All CVE triaging and tracking, and work assignment for both our security
team and LTS, happens in the same git tree. It is worth noticing that
the two members who are doing most work in our security team together
average nearly 50 commits per day, mostly with CVE triaging and
tracking.[32]
Initial LTS triaging is not hard based in this work already done by our
security team.
The number of DSAs went from ~20 per month a year ago to ~60 per month today.
That's an average of 2 DSAs our security team issues every day.
Different from what some people anticipated in discussions before LTS:
Actual work in LTS is often just taking what the security team has
already published as a DSA one release further back.
Sometimes backporting is some work, but this is not done in the hard
cases - when something is hard usually either the package is listed as
no longer supported or the CVE is marked as "ignored" with a comment
like "too invasive to fix".
This hard work would be the part where providing 5 years of support
would not work unpaid, due to both the skills and the effort required.
To be fair, people with the qualifications to fix hard issues (including
doing hard backports) in security are not available at the hourly rate
paid in LTS, and the security teams of commercial distributions
providing long-term support are also far better resourced.
Debian LTS pays security team work done by the security team member who
is also a Freexian contributor.[33,34,35,36]
Why does Debian LTS pay one security team member, but not the ones who
are doing most of the work?
At the hourly rate paid in LTS the money available equals two full-time
positions, and one option would be to offer the members of our security
team who are doing nearly all of the work this money so that they can
quit (or at least reduce the hours at) their current work and work
full-time on Debian security including LTS.
Other solutions are possible, but Debian continuing to offer the same
work paid and unpaid in different teams is not sustainable.
[1] but there was no better option available at the time
[2] https://www.freexian.com/services/debusine/
[3] https://www.freexian.com/services/
[4] https://lists.debian.org/debian-devel-announce/2025/08/msg00005.html
[5] https://summerofcode.withgoogle.com/programs/2026/organizations/debian
[6] https://www.freexian.com/lts/debian/details/#faq
[7] https://www.freexian.com/about/team/
[8] https://www.freexian.com/lts/
[9] https://lists.debian.org/debian-release/2025/09/msg00507.html
[10] https://lists.debian.org/debian-release/2025/09/msg00509.html
[11] https://www.freexian.com/blog/debian-lts-report-2025-09/
[12] https://www.freexian.com/blog/debian-lts-report-2026-05/
[13] https://www.freexian.com/lts/debian/
[14] https://lists.debian.org/debian-announce/2026/msg00007.html
[15] LTS and ELTS combined
[16] https://www.freexian.com/blog/debian-lts-report-2024-03/
[17]
https://web.archive.org/web/20240620143011/https://utkarsh2102.org/posts/foss-in-march-24/
[18]
https://web.archive.org/web/20240620141659/https://utkarsh2102.org/posts/foss-in-feb-24/
[19]
https://web.archive.org/web/20260414090616/https://utkarsh2102.org/posts/foss-in-jan-24/
[20]
https://web.archive.org/web/20260213185556/https://utkarsh2102.org/posts/foss-in-dec-23/
[21] https://salsa.debian.org/freexian-team/extended-lts/security-tracker
[22]
https://salsa.debian.org/freexian-team/extended-lts/security-tracker/-/commit/49a400ede5d
[23]
https://salsa.debian.org/freexian-team/extended-lts/security-tracker/-/commit/c3f49879ae1
[24] https://www.freexian.com/blog/debian-lts-report-2024-04/
[25] https://www.freexian.com/blog/debian-lts-report-2024-05/
[26] https://www.freexian.com/blog/debian-lts-report-2024-06/
[27] https://www.freexian.com/blog/debian-lts-report-2024-07/
[28] https://lists.debian.org/debian-lts/2024/05/msg00004.html
[29] https://lists.debian.org/debian-lts/2024/06/msg00002.html
[30] https://lists.debian.org/debian-lts/2024/07/msg00014.html
[31] https://lists.debian.org/debian-lts/2024/08/msg00002.html
[32]
https://salsa.debian.org/security-tracker-team/security-tracker/-/commits/master
[33] https://www.freexian.com/blog/debian-lts-report-2026-01/
[34] https://dl.gambaru.de/blog/202601_LTS_ELTS_report.txt
[35] https://www.freexian.com/blog/debian-lts-report-2026-03/
[36] https://dl.gambaru.de/blog/202603_LTS_ELTS_report.txt
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmpdAe0ACgkQiNJCh6LY
mLGt4g/9GCf4QNGYtBwlv2AHuuiCCDv78+9st4w5XwYr7qH6Llta3eH3Ppw4xHrz
yZP5sprKPjFgLl7kC06pePK5nyyhBof/7EopIlhaEg0DdqIje6tEc35FvfBIyaQ6
5P8qq/N25lW7WDea6u/53O2d5o1YPTZZnmyrTwSXJJcHBcydHBOZ+T/sXU+zBPSU
4iV3LUDSMNwEuivbPc33pxh7rev4eKn195EGtuY9Do/2sD1wTrI0e3nN8T84xMd9
ZCsGvy7uGmLugxuwyzYXrZVdcD5dNRrk4j43XMrkAMxcwczSXxxw/RDhjp+q+d6Y
YdL7tXw/yuOTzBu/sIvk2GSof/ctq7QYWxd+l5/zVQcGkfGpLUNDVKNmpAak4uze
U4woofBQxFJSSrZrnGfaS1+mgPnFUD3HNRIDzMfLrWuFUEua+tMiUoSRrx0bXXxn
h37Xh3fvRWcb0mo5kKSfJTdRJ3ejKaOzs1zGYKZ2eSa1aojFgK/0vfEvMMsqgu0b
F+zYeA/lRPzNEv3m53XcKQbyICb8agcuMVhGgiDnrIYCUaEjAE5DTXq03Z+hHIJz
nt90LHlvZ63YJbFWIaq33hZHIFKc2YGlAZdfD7r/RUTO+bqok3ioRYOOeQqvdrql
lFRbnGtdlS0nVgAbZHM19ftB9x7tCU11AxkGKCSRt3jFdLaZy08=
=ehCS
-----END PGP SIGNATURE-----