6 ms·
Debian polls its developers on AI: permit or ban?
- lproven 2mo agoPosting this because I want people to vote -- and ideally vote for a total ban.
- js8 2mo agoWhat are your arguments for a ban? Why do you expect someone to listen if you didn't provide a justification?
- colesantiago 2mo ago> and ideally vote for a total ban. If a total ban were to happen, wouldn't that make Debian a target for hackers who can use LLMs to find vulnerabilities? How would Debian keep up with the influx of AI assisted 0 days?
- ctenb 2mo agoNot using AI to write production code doesn't mean you can't use AI proactively to find vulnerabilities.
- datakan 2mo agoPoster wants a "total ban", you can only deduce that means vulnerability management also.
- drdexebtjl 2mo agoOr you could read the proposal and deduce nothing. It explicitly excludes security fixes.
- sscaryterry 2mo agoOh the hypocrisy...
- sscaryterry 2mo agoExactly, agreed 100% https://en.wiktionary.org/wiki/in_the_land_of_the_blind,_the_one-eyed_man_is_king https://en.wiktionary.org/wiki/in_the_land_of_the_blind,_the...
- Planktonne 2mo agoH. G. Wells wrote about how this proverb has limitations [1]. [1] https://en.wikipedia.org/wiki/The_Country_of_the_Blind https://en.wikipedia.org/wiki/The_Country_of_the_Blind
- sscaryterry 2mo agoNo analogy, comparison (add your own language construct) is ever 100% true. Perhaps you should consider that my intent behind this was to say, that Debian will be blind, without ANY eyes.
- tescreal 2mo agoI'm curious about enforcement. Are they going to ban packages with a whiff of llm? If so, how will they reliably audit?
- dan_gggggg 2mo ago[dead]
- someaccount1234 2mo agoNo, otherwise one would have to remove the Linux kernel, the Hurd kernel, LLVM, Python, Chromium, Firefox, Rust and everything using these. And probably some more.
- haunter 2mo ago> Posting this because I want people to vote Irrelevant to post it here then with your reasons because it only concerns Debian developers
- lproven 2mo agoI wrote it. I am fully aware of that, and I said so in the piece. I want to spread awareness that it's happening -- it only has a couple of days to run. So far there are only ~350 votes: https://vote.debian.org/~secretary/gr_llm/ https://vote.debian.org/~secretary/gr_llm/ Circa 270 people have voted: https://vote.debian.org/~secretary/gr_llm/tally.txt https://vote.debian.org/~secretary/gr_llm/tally.txt (My reckoning; could well be wrong!) With a project the size of Debian, I feel sure that is a tiny fraction of eligible developers.
- someaccount1234 2mo agoGiven almost all people here cannot vote, does this mean you posted non-AI-generated slop? Wouldn't it be better to reduce slop, no matter how it was produced, instead of only AI-generated contributions, including non-slop contributions?
- VCFundedGenYer 2mo agoIt does not appear that normal people can. There is no vote page, no information on how to, and we can only view results.
- TiredOfLife 2mo agoAre you going to fork kernel? If not then you are just a bunch of stupid hypocrites.
- ivandenysov 2mo ago> Debian is a large and complicated project: the release announcement for version 13 says it has 69,830 packages, which take a total of 403 GB of disk, and contain 1,463,291,186 lines of code. So, suitably, it is a large and complex poll. Surely these are not just Debian-owned packages. Whatever Debian decides won’t apply to packages not owned by Debian
- roryirvine 2mo agoDebian is huge - that's why so many other distros use it as a base! So, yes, all those packages are maintained either by an individual Debian Developer or a team of them. There are third party repos, but they're (currently) neither as widespread nor as commonly-used as those for other major distros. This vote won't affect them, and you might potentially expect to see their use grow if one of the harsher options in this GR were to pass.
- Jenk 2mo agoThe point though, is that they package 3rd party applications and libraries. If they ban AI, they won't stop packaging apps and libraries from parties that do use AI. They wouldn't even know who does or doesn't.
- roryirvine 2mo agoSure, this is (mostly) about direct contributions to Debian. Proposal C does discourage use more broadly but acknowledges that many upstreams take a different view and that it would be impractical to ban them from using it.
- m4rtink 2mo agoBan.
- Mashimo 2mo agoThe options range from is A to H. It's not yes or no.
- alfiedotwtf 2mo agoCrazy how divided AI is here on HN… We’re almost to the point where the average non-technical person uses AI daily (just like phones and the internet were once only used by the technocrats) without blinking, it will be ubiquitous and universal in adoption, yet comments here on HN from people that have the vantage point of seeing AND understanding how AI works, and who can also predict the inevitable integration of AI in society, have got their collective heads in the sand to the point they’re soon going to sound like conspiracy theorists.
- lproven 2mo ago> it will be ubiquitous and universal in adoption [[citation needed]] Which is gonna be tricky as I am confident you don't have a time machine. I think generative AI as a whole is a total scam. It has uses, but not many, and outside of translation, not good ones... and yet, it is running at truly epic financial losses. Multiple trillions of dollars are being pumped into this. I think the next AI Winter, the 3rd big one, is coming very soon. There's going to be a market crash to dwarf the dot-com crash and 20087 financial crisis (both of which I worked through as an employed adult), and a lot of the current tech industry will be wiped out. I've watched that happen before as well. I am quite looking forward to it. I have no stocks or shares in anything anywhere, few savings, no loans, no debt... but all my immediate family own their own homes outright, and I am close to retirement age. Let it all burn.
- jve 2mo agoI know few CEOs/Business owners who are non programmers (well one was exposed to it/learning, but didn't go down that path) and they do use AI for various work and non work related things. One told me how at manufacturing plant someone solved some unpleasant process to input specs into machine for manufacturing by having AI creating the automation. His comment to me was: People who don't embrace AI will eventually be outcompeted by the ones who do.
- lproven 2mo agoUhuh. And what happens when the price goes up by an extra zero on the end? And then another one? And then the cloud stuff goes away because all the vendors go broke, despite the price rises, and you have to switch to using local models? That is, models that are hugely slower, unless you have a computer with hardware tensor-math acceleration, which costs 10x more because of the chip famine? And then, suddenly, those local models cost an absolute bomb to license, because the companies that bought up the wreckage of the original model creators are trying to recoup their spend? Meanwhile the company is being hit by nuisance litigation from people whose code the bots plagiarised, or customers who are annoyed it doesn't work? There are so many ways all this stuff can just go away.
- jnwatson 2mo agoKind of arbitrary since it doesn't impact their upstreams. The very first thing I used GenAI for was fixing build and CI pipeline issues, exactly the drudgery no one cares about. Today, LLMs are excellent at the yeoman's work of maintaining patches across multiple versions and upstream, which is what I imagine a lot of Debian devs do. Why you wouldn't want to hand that off to a computer program is beyond me.
- silver_silver 2mo agoThere are ethical and environmental concerns arising simply from use and contribution to the industry which many people take seriously
- gatlin 2mo agoI agree with those concerns while also recognizing they also apply to virtually all of the technology we are using to argue right now.
- tomxor 2mo ago> Why you wouldn't want to hand that off to a computer program is beyond me. Trust, stability, security. The reasons many people run Debian. Although I think the main incompatibility in philosophy here is in "hand that off", e.g. direct agentic usage eroding opportunity for human judgement, which seems unlikely to be adopted anyway. The realistic proposals are essentially AI use with various guard rails and rules to preserve that human judgement (my interpretation). Actual Proposals (scroll down): https://www.debian.org/vote/2026/vote_002 https://www.debian.org/vote/2026/vote_002
- ragebol 2mo ago> If Proposal H has a weakness, it's that it does not distinguish between local and cloud-based LLMs Is the energy usage so different between local and cloud inference? Both require electricity, the local option even more than the better optimized cloud variant even perhaps. How either is powered makes the crucial difference I suppose. Both can potentially run on solar as well as gas or nuclear. It's the training that takes the most energy, and that needs to happen for locally running or cloud models regardless. What am I missing here? EDIT: Proposal H mentions "LLM usage accelerates the destruction of our ecosystem" I was thinking solely about energy usage, but there is of course also water usage. A local setup is not water-evaporator cooled most likely.
- dan_gggggg 2mo agoPeople want to ban LLM contributors not because of energy usage, but because AI generated code is unmaintainable and the people who generate it tend to engage with others in domineering and brazenly manipulative ways.
- lproven 2mo ago"¿Porque no los dos?" "Why not both?"
- ragebol 2mo agoFair enough. My comment was however asking about the difference in climate damage from local vs cloud inference, is either better in that specific regard. Or even the energy usage between the two. As for ethics, i don't see a meaningful difference between the two. Local strips out a big-tech middleman perhaps.
- mminer237 2mo agoThis doesn't have anything to do with water usage? The rationale of banning it is that it's copyright status is ambiguous and at the least unethical, it produces lower quality code, and it stifles new developers from getting involved.
- 2mo ago
- nekusar 2mo agoI do use and run my own LLMs locally. But I understand why Debian might ban it, under just 1 reason: LLM outputs cannot be copyrighted. That alone starts to invalidate the GPL and other FLOSS licenses. It overall weakens the project the more you accept. And companies (MS, Amazon, etm) will gleefully loot anything marked with "LLM" as a free-for-all. Until the whole copyright situation can be finalized, I'd understand for any FLOSS org to refuse all LLM code. (Its also the same reason why Oracle also forbids all LLM code in Java and their DB. Same reason.)
- singpolyma3 2mo agoThere's not yet any reason to believe that mixing LLM output with your work makes it uncopyrightable any more than hitting enter in intellisense did before that.
- rstuart4133 2mo ago> LLM outputs cannot be copyrighted. For stuff that isn't Debian supplied Debians only contribution is the packaging. Debian considers "Public Domain" is a perfectly acceptable licence for the packaging work. So LLM produced packaging is also perfectly fine - copyrightable or not. By the by, even the option most favourable to LLM's in the ballot insists the Debian Developer take responsibility for all his work, regardless of whether he or an LLM produced it. > That alone starts to invalidate the GPL and other FLOSS licenses. How? > And companies (MS, Amazon, etm) will gleefully loot anything marked with "LLM" as a free-for-all. I'm not fan of their sharp practices either, particularly when I wrote this: https://lwn.net/Articles/1046105/ https://lwn.net/Articles/1046105/ But what Amazon could do with publically licensed packaging that they can't do now is a mystery to me - it's not terribly useful outside of the Debian ecosystem, and it's not like you are forced to distribute most of it. Many companies just ship Debian binary packages now, no Debian source available. GPL and friends only bite if you distribute it. I do think LLM's could be a threat to open source licences, but this isn't the mechanism. The real threat is far more insidious: https://lwn.net/Articles/1064113/ https://lwn.net/Articles/1064113/ So, for Debian packaging LLM's don't create copyright issues, or accoutability issues. If environmental concerns are serious, Debian could always setup it's own LLM server farm running open source models powered with renewable power. That sounds expensive, but whenever Debian needs compute (it already use a lot recompiling all those packages on all supported arches) it just seems to "appear". I'm not sure what's left, beyond a technophobia of computation done using 4K vectors rather than bits. The underlying silicon is the same after all, lots of packing tools already automate most of the steps, and the output (the packaging) is highly constrained so will be near identical.
- VCFundedGenYer 2mo agoTotal ban please. This nonsense needs to end. Linus Torvalds is weakly vibe coding the kernel, that's bad enough.
- someaccount1234 2mo agoThen you cannot use Linux, Firefox, Chromium, Python, Rust, LLVM and so on. Hurd can't be used either. Maybe you have to switch to FreeDOS?
- lproven 2mo agoNetBSD is right there.
- someaccount1234 2mo agoNetBSD has no alternative to Chromium, Firefox, LLVM, Rust or Python. They use AI-generated software too, including in the base system.
- lproven 2mo agoThis is simply not true. NetBSD includes Firefox: https://cdn.netbsd.org/pub/pkgsrc/current/pkgsrc/www/firefox/index.html https://cdn.netbsd.org/pub/pkgsrc/current/pkgsrc/www/firefox... And Chromium: https://cdn.netbsd.org/pub/pkgsrc/current/pkgsrc/www/chromium/index.html https://cdn.netbsd.org/pub/pkgsrc/current/pkgsrc/www/chromiu... And LLVM: https://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/lang/llvm/index.html https://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/lang/llvm/i... And Python: https://cdn.netbsd.org/pub/pkgsrc/current/pkgsrc/lang/python311/index.html https://cdn.netbsd.org/pub/pkgsrc/current/pkgsrc/lang/python... In fact, the only thing that you mentioned that is not in its ports collection is a Rust compiler, as far as I can see. Code generated with LLMs is explicitly forbidden. I wrote about that last year: https://www.theregister.com/software/2024/05/18/gentoo-and-netbsd-ban-ai-code-but-debian-doesnt-yet/1434665 https://www.theregister.com/software/2024/05/18/gentoo-and-n... It's in the guidelines: https://www.netbsd.org/developers/commit-guidelines.html https://www.netbsd.org/developers/commit-guidelines.html « Code generated by a large language model or similar technology, such as GitHub/Microsoft's Copilot, OpenAI's ChatGPT, or Facebook/Meta's Code Llama, is presumed to be tainted code, and must not be committed without prior written approval by core. » I don't know of any such thing getting approval. Yes, like OpenBSD, things might get grandfathered in. OpenBSD includes `tmux`. Tmux includes bot-assisted commits. I wrote about that too: https://www.theregister.com/software/2026/05/25/openbsd-79-arrives-a-diamond-in-the-rough-proud-of-every-sharp-edge/5244877 https://www.theregister.com/software/2026/05/25/openbsd-79-a...
- ImaCake 2mo agoWhat an interesting cultural artifact! I note no proposals in favour of "let it rip" which is presumably because that would not be a reflection of Debian philosophy. I do think the aggressively anti AI proposals are themselves un-cautious in the extreme.
- surajrmal 2mo agoIt's one thing for a maintainer to use AI, and another to review AI code sent your way. The latter has been proven to be unsustainable, low value, and ultimately a challenge for open source. Everyone acknowledges this problem exists and some corrective action is required to mitigate it.
- ImaCake 2mo agoThats certainly an argument about the problems with LLM usage. But it's not a meaningful reply to what I said unless I am missing something.