Submind YouTube summaries
Thumbnail for Package Acceptance in Debian: Challenges and Opportunities

Package Acceptance in Debian: Challenges and Opportunities

Watch on YouTube

Video summary

Andrea Still, serving as Debian Project Leader, opened his session by emphasizing the core values of freedom, equality, and community that drive free software projects like Debian. He acknowledged the critical work performed by the FTP Master team, who manage package acceptance, handle removals, and facilitate releases, often facing criticism despite their essential role. The talk highlighted a recent positive development where the FTP Master team gained the ability to explicitly accept or reject packages based on copyright compliance, a feature requested for years that was finally implemented through community collaboration. This change demonstrates how open communication can lead to tangible improvements in the Debian infrastructure, allowing for better oversight of package quality before they enter the official archives. However, significant challenges remain, particularly regarding unpredictability and bottlenecks in the new package processing workflow. A major technical limitation forces all new binary packages to be uploaded to a single host located in the United States, where manual reviews must occur before files can leave the server. This restriction stems from complex US export laws concerning cryptographic software, which historically prevented non-US developers from accessing or downloading these files directly. Consequently, the process is slow and opaque, leading to long waiting times that frustrate developers who cannot track their package status effectively. The speaker noted that while much work happens quickly behind the scenes, the lack of visibility creates a perception of inefficiency, and the reliance on a single host severely limits scalability and parallel processing capabilities. To address these issues, the session proposed several solutions centered on improving communication, documentation, and team structure. Andrea suggested splitting the FTP Master team into specialized roles for copyright checking and technical tool development to attract more volunteers and reduce burnout. He also floated the idea of time-based membership to encourage participation from those who might otherwise be intimidated by the long-term commitment required. Furthermore, the community discussed enhancing the testing infrastructure by allowing developers to run their own local instances of the review tools, which would bypass the single-host bottleneck once legal restrictions are resolved. The speaker stressed that resolving the legal export issues is crucial, as moving the processing host outside the US or finding alternative compliant methods could unlock significant speedups and allow for automated parallel processing. The conclusion of the talk was a strong call to action for the broader developer community to engage more deeply with the FTP Master team. Andrea urged developers to stop viewing the FTP team as a "black box" and instead actively participate by joining the team, contributing code, or volunteering to observe release processes. He emphasized that the Debian Project Leader's role is to delegate and support the experts rather than dictate their work, trusting the team to find the best procedures for themselves. The session ended with an invitation for volunteers to step forward, either publicly or via a private list, to help solve the remaining legal and technical blockers. Ultimately, the goal is to foster a stronger connection between the maintainers and the contributors, ensuring that Debian's release process remains robust, transparent, and efficient for everyone involved.
Read the full video transcript
Welcome everybody to the next session of Debcon 25 first day. Um I'm excited to introduce uh Andrea Still again. Uh he is a longtime contributor and developer in Debian and since last year uh Debian project lead uh in the second term and he will uh so it's kind of both. It's not like a normal talk and it is about package acceptance in Debian. So please greet the Andreas warm here uh with and [applause] >> yeah hi everyone and happy birthday day. So, liberty, equality, finity, or as we say in Davian, freedom, equality, and endless mailing list threats. But seriously, these values live up pretty well with free software. And so, it's it's all about it. Um, freedom to use and improve software, uh, equal access for software and all, and also global community which mostly works together. So let's celebrate both the revolution in France and in fafair. So at first I want to thank all the people who are doing the FTP master work right. Yeah, [applause] I'm I'm afraid I'm known in this team as a guy who is always criticizing and so and I deeply regret this because they are doing a good job and they do it the job obviously nobody else wanted to do and they are doing it. So this is great. And maybe my German direct way to express things might have messed up something which I also regret. But my intentions are positive. Positive for the team because it's important for DA and so positive for all. So sorry about this if it came up the wrong way. So this is above and you can please interrupt me all the time and I also want you to add your ideas to the to the pet. You find the link to the pet in the schedule. It is down in in this in the um session and please write your ideas at bottom because there was some preparation. Thanks for Anton for summarizing everything which we did because we met on Saturday with York Yaspot and a new trainee and we had a really productive session. As I said it's it's maybe it started by some friction by some miscommunication of mine but I [snorts] personally had a great feeling of the outcome of the discussion. It was extremely productive and I intend now to present what we talked about and some other ideas and emerge of of things I think the developer community should know. So I was blamed about having the agenda to do something. My agenda is easy. I want to tear down hurdles. I want to make people talk to each other and I'm usually asking questions to learn and some people have in mind my question has something no I have no background I want to learn because um finally the DPL is responsible for delegations and if I don't understand things I can't do a proper delegation so I'm asking question I'm questions can be yeah maybe perceived not nice whatever. So my agenda is just to to learn found the best things and once the team is delegated the team is are the experts and I will not touch what they want to do. The initial thing happened last year nearly one year year ago in Busousan and thanks to Luke we had a really great buff. Thank you Luke. He well gave the introduction to us what's what's the FTP master is doing what is what's the details he was firing up a shell and demonstrated the work. This is really cool. You have a link in my in my talk for those who don't know you can do a web search Andreas till the talks you find a table and you find this slides and this slides has the links and you find also a links to the transcript in text so you can browse it easily and happily this buff had a really good outcome because I was a long time requesting a feature that if FTP master has has a option to reject or accept the package and [snorts] some more and I was asking for accept plus back report if if there is free software okay but there is something with the copyright missing but in principle we are permitted to distribute the package but it's not it's not meeting our requirements we've set so this could be in release critical back report I was asking for this and finally someone wrote a merge request and this merge request was implemented. So now FTP masters can do exactly this. And for me this is a good thing to say okay we talked to each other in the buff and someone has observed the buff or read the logs and said oh I could sit down write an enhancement for duck which is a software running the archive and yeah we had a merge request and was I don't know that you you find this link is presented I don't remember the date but it worked so Um, we have another example also requested long time ago. You all know it. If a library gets a sona version bump and the the binary package changed its name or for other reasons I want to split up a large user share. So we have a change in the binary package names and this goes to um is it has to be uploaded to new queue because of a technical limitation of duck so it needs manual processing and well some FTP master has decision well this is a good chance to review the copyright other FTP master said oh I do a technical review to make sure there's no conflict There's a link on the mailing list to this and there's even a bug what he has closes in the room was in the room to request this auto accepting uh for new binary packages which would be extremely h handy but well the bug is open nobody stepped up for fixing it and even the FTP masters have written in mail seven years ago Please could you send us a merge request for this automatic new processing? So now who is responsible that we don't have this feature? Everybody in the room, everybody in community. Well, it's not only FTP masters who work on it. But we can we can do something if we talk about this. And I personally need to admit I found this last request on the mailing list in when preparating these slides. So not before Saturday. So the information is there. We need to look for it and everybody who wants to increase the situation is perfectly welcome to do so. And I perceived from the FTP team the thing that they are very open for patches merge requests and as I I have even the proof that this happened. So what we are doing here is rather some kind of or what we did on Saturday is some kind of brainstorming what could be done what needs to be done. I present you the results of this brainstorming, but we are continuously seeking for new ideas, enhancements, whatever. We are not seeking for DP Muscle is too slow. Some people know, some people disagree. This is not the intention of this buff, right? We want uh to do something friendly to each other. We had on Saturday this um hybrid format onsite uh on-site plus remote part participations and we had finally some FTP masters in the room some from remote and representatives of the developer community like you here. So um we we were informed that FTP master has different tasks. So they are running the suites fix issues as they are coming by. They are doing releases and we are keen on the next release. This is not only done by the FTP masters also press team as there are a lot of teams involved but also FTP master has an extremely important uh share on on a release. So they are coding um and the the well the the main working horse is duck which is coded in Python is accessing postresql database and has some shell script. So people who feel competent in this your contributions are always welcome and the most visible part for the people here in the room is for sure the new processing we are doing also the overriders and removers. So if we talked in the form above about removals if you want to get something removed today is also done by the FTP master team and this is the main dayto-day work. By the way if I personally contacting the FTP master team about removals or so I always end my emails with thank you for doing your FTP master work. I was informed by someone. But if you write it always, it's means nothing. I think typing all these uh keys instead of bye-bye is a sign for at least I mean it that way. Thank you for your work. I mean it that way. I hope others people are also as friendly as possible to these people who are doing good work. So what about new package processing delays? Um I'm just this is just a quote from the um the session. For me it's not only that that some people think we have a long waiting time. For me this is my comment. Um a huge amount of work is actually done really fast. But this is what you don't see. Yeah. You know you if you were working in it your users come only to you if it's not working is there any any users say oh you did it great so every day you do a great job but once a month people are coming oh it doesn't work and I think we are a little bit suffering from this effect right and I'm more concerned about the nonpredictability predictability uh of when a package gets accepted if I would So okay, I upload the package to new and I would certainly know it takes half a year and I put it on a separate mirror that I can keep on working but sometime it takes two days and then well it's not worth the effort to put it on an extra mirror. So if there was would be kind some predictability it I think it would would be well perceived by the community to say oh that's okay I know they are working on it but yeah they need some time okay the causes for these delays are that um files are manual re reviewed and literally every single file is manually reviewed And we also have some legal uncertainty about um export laws. I go into detail into this. And this is somehow causing a technical bottleneck that all the processing you upload to an a host which uh contains a new queue and only this host is permitted to work on this stuff. If you can't download FTP masters are not uh allowed to download it from there for reasons I explain soon but this is one reason for the delays or at least it is a le a reason that was mentioned in on Saturday and we also have some communication gaps somehow for for many developers FTP team somehow seen as a black box. So it is um they have limited visibility into the package status and you can contact them on ILC. There's an ILC channel but we do not really know how many pings are okay. So if I ping them twice a day, it is well perceived or should I wait for one day, one week or so if I have a good reason to contact them, right? You can say, "Oh, we are in the middle of the transition. This package is important." And then you wait [snorts] and this would be helpful if this uh ping frequence and number is would be somehow communicated. So uh regarding onboarding for the team, well there was some disc discussion last year. Um it was um suggested by a member of the FTP master team. Okay, let's maybe split the team because they have different roles. I one role is a not so technical role with some technical components. Sure, but it's it's the copyright checking, license checking. The other thing is that the the programming the tools and doing the releases and so out of the FTP master team cames the suggestion let's split the team in two. Okay. I said well interesting might be attract more newcomers who might be focused. I want to do the the koda and I want to do this one and um yeah I agreed with the team and then I when I wrote it in my bits from DPL in May it was not well perceived or what I have agenda so but there is a lot of miscommunication I don't mind if the team in internal splits and this is clear and transparent for people who are joining go for But if you think it could have some advantage to split those roles and I should write a new delegation for two teams, I'm doing it. I'm I'm following your advice because you are the experts. So we had a last onboarding call a couple of years ago which had no no results for the current team as far as I understood. Maybe I'm wrong. But we have also recently a new trainee on boarded who is as far as I've heard doing a good job. Also uh joined on on Saturday but was not visible if I remember correctly. The team could use more people for any task but the training takes some time. We should talk about this later. And there was an idea I don't know if it's a good idea. We were on brainstorming. There was brought up the idea for a timebased membership of the FTP master team. Some people will we probably very scared about this idea and I was as well for the first moment. But when you think about it, okay, this job to take copyright notice is not really nice. But if I know I have to do it only for one year, I might volunteer. It little bit depends how much training you need or so. This is just throwing in this idea because it came up. No, no. So, uh what about the duck tooling? Uh currently we have one main contributors like the uh copyright checking. Um the test suite could be enhanced. uh specifically specifically if you have a virtual machine then people could run some new processing host themselves and do the all the stuff in testing and then merge request is more easy. There is a script. So you can I I was told there is a script where you can um you can uh create such a duck instance but the test could be enhanced. At least this was said in the in the sprint on on Saturday. So some kind of second duck play instance or something. As I said, merge requests are welcome all the time and you can talk to the people how you possibly can to create the merge request best. Well, what about the release process? Um, as far as I was informed on Saturday, the point releases are very well documented and quick. It's um, well, you do it point releases, we have it every month, but in a time frame where you don't forget. so much to know how it gets the next time. Um full releases are knowledge heavy and they are also depending from lot of teams. So press team DSA every everybody needs together and the the release is done by first asking the people do you have time this weekend we need your full attention for a full weekend to work on the release. So thanks also to other other people who joined this. So we we will see it hopefully soon maybe in the next couple of weeks or so that this heavy work will be done. So there exists some documentation but I'm wondering of whether we should find some experienced documentation writer who sitting down with all these people and writing down what it's done because this is crucial knowledge for Debian to know how a release is done and we need the good documentation to be on the safe side. So maybe there's even some kind of training how to do a release on a virtual machine. So let's let's do some release training. All costs time. Everybody here in the room has probably not so much time but time is um not absolute time is um prioritization. And if you think my priority priorities are very high that Dian releases will be run smoothly, you should probably consider to work on this. Yeah. So maybe we find some volunteers to observe the next release. As I said in my previous talk, if you volunteer for any task, please add your name to the pet also with a part you want to involve too. It's yeah very open for the moment to get involved. So as I said the nucle work workflow is seen as a bottleneck [snorts] and done by one person and this demonstration from Luke helped a lot had a lot the ideas where we could um take packages somehow to get some information. This is needed for transition or something like this to to to make FTP master aware. So this is maybe more important than this other package which is not so so we some kind of communication on a technical level. Then we have this gateway to new this is somehow some effort the link is there um on salsa some evaluation of the package so we can get an uh review of other Dian de developers before it goes to the new queue. So packages this went through this gateway are hopefully better have a better copyright file. I'm just was ling the other talk which was before here in some other room. Maybe there were some other answers for this. I don't know. And um it would help to have some better visibility on the status and some locks. Yes, there's a question. Can you please uh take the microphone? >> Uh more of a comment really, but something you might adopt for that >> for Apache software projects. There's a vote by the TLP every the by the um >> uh members of the TLP PLC um every time there's a release a software release. So if you could get enough volunteers in this gateway idea that all give plus ones, then that would be visible to Luke or whoever's doing it >> to amplify or speed up what they're doing. >> Yeah, this is a very good comment. This I'm I'm aware that the open sus project doing the same. They have a set of volunteers and if you get five look good to me, then the package is accepted. I would love if we change the procedure how to process new at all. But we need first we need people who do the work and if we have people who do the work and I hope you all raise your hand later on these people will decide to what what procedure is is used. Well, I I don't see my job as DPL to say you have to do this, but the competent team should decide how to work and how they have fun on to do this work. I mean if if the FTP team is way more fun and they are famous like oh this join the FTP team it's so great because we are doing this workflow which just requires to five look good to me and I love to seek to learn about packages because I'm just reading and learning if you read about packages you don't know before you always learn something I experienced this before in the in in the back of the day thinking I learned so much. So this can be fun and if these people who are working on it decide to do it, great. If it works better than before, yes, this would be really great. Thank you for the comment. Well, this is the law issue. I do not want to read out it. You find it here. This is gives the reason why we have to use a host in the United States because we had the export restrictions for crypto software in the United States which means you are not permitted to export uh crypto software from the United States outside. So OS Debian developers were not permitted to upload non uh viewed code outside the US. So we moved it the the host inside the US. Other people were able to import into the US. So everything is sitting on this host and this is a restriction which is um somehow blocking FTP masters to use other tools or work in parallel or this this is a law issue. I will not uh talk about this more except that is not this the law has changed in 2021 and um we have a couple of questions what to do but maybe legal consition uh consultations are ongoing and all the things has consequences for the discussion how it needs to be invent invented. But there was also the idea if we now move the host out of the United States then the US developers are permitted currently and according to current law to upload to this host outside the USA and then we do not need to respect this anymore. This is subject for discussion. It was also result of our uh brainstorming. I have no outcome for you but it might be that this blocker is [snorts] possibly solve before the Trixie release which would be would be the optimal situation because before the Trixie release we will change nothing on the FTP team, right? So nothing will happen there because we we need to be safe to have a good release. So this this major blocking is is holding up pending questions and to for any process and once this will be solved it will be enabled most probably downloading and using your own tooling. So the FTP master does not need to go to this host and and read their line by line but can download and use own tools different tools write own tools to evaluate whatever or we can implement a second host and enable parallel work which involves a lot of coding and making sure that the parallelization will not break something. But anyway, and it could also be more friendly for newcomers because the um uh evaluation of the copyrights um requires yeah a lot of learning and um the trainee can tell you about this but maybe it can be technically more easy and you can attract more people. Um >> yeah, there is uh one more question uh about this law. uh I will just read it from IRC and if we move it outside the US how are affected by the laws of the target country. I do not know whether you are able to >> the the question is is is good. This question was also asked. We have no real answer. We we need to decide first if we can move out of the US and later we see where to move and if there are other restrictions. Yeah, the per the question is perfectly valid. Okay, thank you. So, yep. Another question. >> Is there a reason why this is a single queue? Can't it be distributed? >> Yeah. Yeah. The reason is that we have this this because you the software want this there is not permitted to leave this host before it's evaluated and and accepted. Right? you upload to this host and then it is not permitted to leave this host before it's >> okay but me as a European could upload to a >> yeah you can server and and and and somebody as from the US could upload there and then you have two of these >> this is this is a detail I can just say this the people dealing with this had a long long discussion with with lawyers I'm not a lawyer Maybe I give you the wrong answer. I trust them that at the time when it was implemented, it was necessary, right? >> Is so I'm not sure if DJIT allow allows us to do uploads of new packages, but wouldn't then that have the same problem and there I don't think we have any restrictions on on reading. >> Is is is a comment or a question? >> It's a question. then please ask again because I don't understand it. So you know about this service called DG which is pretty popular for uploading packages right >> I'm not sure if that allows uploading of new packages >> okay >> where we don't know the copyright status but if it does wouldn't then that have the same problem as we have then for new packages on FTP master >> well I I think digit is from from my point of view just another user who is uploading and for the in the current situation it needs to go to the United States but the question is very good because um the git is also it's exporting >> I'm talking about the distribution side there not >> not tag to upload but rather the distribution side where anyone think about t no I'm not talking about tag to upload I'm talking about the distribution side here where >> like it the protocol is very different and like this the semantics in terms of how we think about the packages in Debian and so on is very different but fundamentally it's it's about distributing the source or the source and binaries uh that we do. >> Yeah. Well, the the thing is um for these kind of hosts like GitLab, every other forge has all the same problem but they are not distribution distributing the sense of we are handing out binaries to someone. So we Dian is in is a bit little bit different situation than just a hosting platform of source code at least to my weak understanding of the problem. Right. >> Okay. Because historically uh there's been multiple reasons for why we did not uh let people read from you. One is this around export restrictions from the US but it was also that we did not know the distribution status of whatever people uploaded to new. >> Yeah. And these are these are separate problems but they're I think they might have been co-mingled in you know the 20 plus years that have happened since uh >> since we moved stopped having non US as a separate archive. >> Yeah. What the what I the message I want to provide is 20 years ago there was some necessary to do something and nobody until now questions this means if they are needed and we should now question this this need for this what we did and most probably do something else [snorts] that's good uh thank you we have one more comment I think no no more okay Thank you. >> About communication channels. Um there is um a public IRC channel between the FTP master and developers. There's they are also using a private RC for their internal communication which is preferred. So if you are scared about RC, yeah, you should not. And um they are working with merge requests on CISA which can also get commence. And um yeah, this is a public call to the FTP masters. Just let us know what help is needed. We would like to see some kind of to-do list you want us to do for you. There's most probably this automatic upload of new binary names on the which I introduced in the beginning. This would be a really cool thing and maybe other things we could talk about but we as a developers have no good information what is needed to enhance their work and they are probably overworked to do the work all on their own which they can perfectly understand considering the the limited number of people in the team. Yeah. about the vision. I I think we we the FTP master team is doing a lot of very good work but it's done for 20 years and so where where won't it be won't we be in in 10 years or so maybe we change everything or not and I really hope that we find new members and they bring in new ideas and that these idea will be accepted. So it's definitely needed to enhance the documentation and the communication and I really really want to have a stronger connection between FTP master and developer community in well actually this la last point was my strongest motivation to run for DPL because there's a team doing actually a service for Debian. It's it's a very important service. It's extremely uh important to know what the for the community what this service means for them and for the people doing the service what wants the community what expects the community from me and so I really love this connection between both sides don't even know it's both sides the correct word here but yeah and I hope that you know what I So um there were some solutions for all the problems which I uh mentioned proposed. So if we manage to solve this law problem we can move the new package process to a separate host. Um by the way there is some documentation for the refu process on sala. This is just not very public. It was linked last year and the the above. It was written by Jean Whitten and uh so if you wonder what FTP masters are checking it's in their git and we try to we should allow more participation for the processing. Well there are more existing problems. So um well the review process or not more but this is a summary of the existing problems. The refu proise process has room for improvement. The communication about the Q status could be enhanced. The reliance on on the single host restrictions uh restricts [snorts] no the reliance on the single host as I explained restricts the scalability. We have legal issues which are stalling technical redesign and for sure more developer help is needed for archive and tools and every every task. So volunteers please raise your hand. Is there any volunteer who is motivated to join the team? Please raise your hand. Or if you are scared to do this in public, [snorts] please add your name to the pet. And um we are well tomorrow has this bits talk and on Wednesday's day trip and so but we have three days left for discussion. I would really love to meet people here in one room probably in the after the talks are ended because the schedule is very dense. So if we meet in in the evening hours to find a common room and talk about this maybe even with the help of FTP muscles they might join they many of them live in the same time zone. I think Luke is here. I think all of them are in the same time zone now. Then we can uh set up a meeting. So this would be the most direct connection. Right. So I would love to all you contact me if you mind putting your name somewhere. This would be really great. I would even bring some sweets to this puff >> to bribe you. Yes. >> Let me be very clear. This is not me volunteering for anything as of yet. Um I I do have a question because I'm uh apparently not very smart. Um I understand that the single host is a limitation. Yeah. >> What I don't really understand is exactly why. Like why does that bog everything down because there is a single host? >> Well, this it's it's the Luke. Yeah. >> Well, it it it it's in part that um all of the work of review has to be done on that host and putting in quotation marks. So like um one needs to page through and do do the review via session rather than say downloading locally and doing an analysis in any any other way. Uh does that make sense? Make sense why there's a limited limitation. >> M okay. Okay. >> Thank you. >> This was actually this blocker was identified last in last year's buff. So we so it's takes some time to work on it. >> Any more questions? >> Okay. Forwarding uh something from Yaspad from IRC. He also welcomes volunteers or people doing work to the FTP master directly IRC or male. uh doing coding tasks is uh welcome and also just tell them what you want. >> Yeah, I'd just like to repeat that you provided extremely valuable knowledge on Saturday and was extremely cooperative and and so it is I I was sensing a very open environment. [snorts] All right. Um please use other part to add yourself if you decide lately. Yeah. >> [snorts] >> Yeah, once these blockers are solved, we and we find a new team, this team finds their consents about the new policy. I just repeat I I can delegate as as a DPL team and then this team has to work without my intervention. Right? This is perfectly intended and I really hope that you bring in yourself. Well, this is this is as I said in the beginning I can't solve the problem. We all need to solve and I'm very positive we will solve the problem but it needs your your cooperation and then we this new team can develop tools to implement this new policy they might agree upon. So we have identified some action items, finalize the legal question with lawyers, improve the documentation, start technical work to maybe have more parallelization and recute contributors for active tool development which I'm here which I'm this is the reason why I'm standing here right I've assembled some links You could click on and applause once more for the FTP master team. [applause]