"Theodore Tso" <[email protected]> writes:

> On Tue, Aug 11, 2026 at 04:10:00PM -0500, Gard Spreemann wrote:
>> The proposal deals with *direct* contributions to Debian, including, but
>> not limited to:
>> 
>> * Debian packaging
>> * Submissions (messages, bug reports, patches, etc.) to the BTS, Salsa,
>>   mailing lists and other Debian platforms 
>> * Debian project software
>> * Debian infrastructure
>> * Debian web resources
>
> What is meant by "Debian infrastructure" or "Debian web resources".

I meant computers run by the project, and web services run by the
project.

> Does Apache or the Linux Kernel considered part of the Debian
> infrastructure or Debian web resource?  These terms aren't explicitly
> defined, so this could lead to confusion.

Just their Debian packaging. Not their upstream parts.

>> With this principle in mind, the
>> proposal does not affect the use of generative AI as an assisitive tool
>> to explore, research, analyze, critique, etc., when contributing.
>
> If the Generative AI discoveres that there is a mising unlock in an
> error return path, does that count as an assistive tool?

Absolutely.

> What if it creates a patch which adds the missing mutex unlock?  Does
> that count as an assistive tool, or "generated code"?

That counts as generated code. Now, if the patch literally just adds an
unlock, then it's highly unlikely that you would write it differently
from the AI. So there is no way for anyone to distinguish between
AI-generated code and human-made code. And then, to me at least, the
whole question becomes moot under this proposal.

> And if we apply that patch on a Debian web server, would that be
> prohibited by this proposal?  Even if it prevents a high severity,
> actively exploited vulnerabity?

Since the patch is indistinguishable from human code, I don't think it's
where our discussion energy should go – if we assume good faith from
people using generative AI in an assistive capacity. I try to think
about it the way we think about generated code in a more traditional
sense. At some small size extreme, also (clasically, by say a build
script) generated code becomes so trivial that we probably wouldn't care
about discussing whether it's generated or not, no?

I agree that it's a weakness in my proposal that "trivial" (in size)
contributions – contributions that really can't end up very differently
whether written by an AI or a human – aren't addressed explicitly.

>
> "Humans create Debian" is a nice tagline, but it doesn't particularly
> well defined.  

That's true. But I also think it's true for most GRs that go beyond
purely technical things.

> After all humans are tool-using animals, including compilers and
> LLM's.

… and yet we frown upon compiled code in packaging contributions.


 Best,
 Gard
 

Attachment: signature.asc
Description: PGP signature

Reply via email to