Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Interesting that this makes no distinction from using LLM output and using LLM assistance. An overly strict policy is better than no policy, but I wonder if using llm for conversation and analysis, but not code/config generation, was discussed.by TZubiri
- I’m curious what makes you believe that this distinction is precise or meaningful. What exactly is the difference?by aabhay
- I certainly hope they'll choose C.by mike_hock
- The unhinged Background paragraph is disqualifying.by baggy_trough
- A is good, it's grounded. C is just basedby pixlmint
- i think the line is: expressing that you reputationally certify its correct and its worth the time
- I might su combining Proposal A (but only for contributions (to Debian) that actually involve the output of LLMs/generative-AI or that blindly trust their results) with Proposal C (for everything else).
However, in the case of item 4 of Proposal C, there are multiple kind of "assistance" that is possible; not all of them involve contributing the output of LLMs (e.g. the assistance might be to check for a mistake such as if a paragraph seems to be redundant or is incomplete or something like that; the result from the LLM might be incorrect but you will have to decide by yourself what (if anything) to do about it when writing your message). Even if some kind of assistance should not be banned entirely, it should still be discouraged (like the rest of Proposal C says). (Also, there are other programs that can sometimes be used for the assistance; e.g. sometimes ordinary spelling/grammar checking will do (although that won't find that an incorrect word that is spelled like a correct word in the correct grammar).)
I do not use LLM/generative-AI for any purpose, and would not accept contributions including their output into my projects, and would discourage other uses. (This seems to be similar to Proposal A and Proposal C.)
- This is a very difficult problem. LLM's don't learn from reasoning about trade-offs and from their personal experience, so systems made with AI assistance stop obeying the unwritten rules of why things are the way they are, that comes from the maintainers' decades of experience.
On the other hand, they can produce and test anything anyone asks in minutes, as well as find security issues that lay dormant at the seams for decades.
There is no great answer here.
by logicallee - I think when we're talking about mature software, LLMs aren't the problem. It's the lack of discussion justifying the change. LLMs don't necessarily lower code quality. They put a spotlight on people "just going through the motions".
When the changes are small and properly reviewed, there's no point in caring how it was done. It should be trivial to write, but difficult to approve and merge.
Projects as significant as Debian should own the fact that they are indeed a bureaucracy and take inspiration from what has always worked long before LLMs.
by sublinear - What comprises “assistance?” Getting Claude Code to find bugs, suggest a fix, but a human actually editing the source files and testing the result - is that assistance? Perhaps this policy is as it says: a guiding principle that the community is expected to follow.by russfink
I wonder what fraction of Trixie already violates this requirement of the first proposal...> Documentation and translations added by Debian contributorsby rixed- Gentoo chose to ban LLMs two years ago. They seem to be doing well.by Meneth
- You would not even know about it if they were not doing wellby ekianjo
- I've been running Gentoo for 20 years. What you consider "Gentoo" is simply the package manager and "ebuilds"; instructions to build upstream packages. Right now I'm using LLMs to make my own ebuilds and maintain them. The packages I am compiling are basically vanilla upstream Linux packages. It is laughable to suggest Gentoo doesn't use AI made code because upstream already has it.by hparadiz
- Yes for gentoo and their users it makes sense. Debian is much, much larger and is used pretty extensively in enterprises.
The biggest question, I think, is: does a complete LLM ban interfere with, or slow down, security patches? I think it could, as LLMs are used a lot for vulnerability discovery.
by preg_match - Gentoo is doing as well as it’s always done. It’s clearly a very niche distribution. I say this as someone that used Gentoo for years.
They are free to keep pretending that they aren’t receiving covert AI contributions, because I’d bet the farm that they are.
Debian has a little more ‘general interest’
- Funny because out of all the distros, Gentoo benefits from LLM usage, at least as a power user. I have fixed many-an-issues just having LLMs write patches in a way that portage automatically builds them, or rapidly put together ebuilds. I respect upstream decision though and don't share my changes (and realistically who would want them)by orsorna
- > A LLM (...) merely produces syntactically likely combinations of the training data
While doesn't matter much in the rest of the policy, this is a common misconception among AI skeptics. It is not the case for a long time (since RL is used heavily in the training) and a LLM may go beyond its training data.
by hkalbasi - I would like to offer this comment from three days ago as counterpoint:
- Doesn't the LLM still output the next most probable token (modulus heat/desired variation) according to its model? Training shifts the probability - but doesn't change the fact that the output is a sampling based on input and the model?by e12e
- I assume RL stands for reinforcement learning, which just means that the weights are adjusted by evaluating some loss function. If the loss function uses the training data (i.e. supervised learning) then the original assumption still holds. So I fail to see how this is a misconception.by runarberg
- The natural next argument that I see a lot is "well it's still all probabilistic", which is technically true. However, don't the atoms that make up the cells that make up a human move around and interact based on probabilities?
Saying a LLM is all just based on probabilities is pretty meaningless, even if it is true, since everything else is just based on probabilities too. What matters is the massive amount of machinery that generates those probabilities. Anything from rolling a dice to an accurate model of an entire human, or even a model of the entire universe, is all "just probabilities".
by LiamPowell - I think the questionable term is not “syntactically likely” but “merely”. Syntactical likeness is a vast solution space that encompasses the work of a terrible developer and a genius developer. In fact this solution space is a gap wide enough to encompass all coding knowledge and expertise.by aabhay
- Don't misinterpret this link as representing a final decision. It's actually three separate proposals which will be debated and then voted on.
Proposal A is "expressly forbid any contributions to Debian written with the use or assistance of large language models (LLMs) or other generative AI tools."
Proposal B is "The Debian project allows AI-assisted contributions (partially or fully generated by an LLM), provided the following conditions are met [...]"
Proposal C is "request that all contributors to Debian avoid the use of LLMs in their Debian work" without an outright ban.
by simonw - Note that we are still in the discussion period, and more proposals can and will be added. Some might even be withdrawn.by ckastner
- The title says "proposals"
Why would someone misinterpret this as a final decision?
by lacoolj - while my heart lean heavily toward A, this would serverly limit Debian contribution and would rely on contributor honesty. It might be dismissed as an attempt to gatekeep contribution. But the issue of the human cost on the receiving end of the contribution and how sophisticated attack vector it could potentially be give me some concerns about long term quality.
B being the more pragmatic, despite the (valid) code licensing concerns. but could leave some very openly LLM driven project room to contribute package.
C as a middle ground would not satisfy any party and would only push back the resolution of the status quo.
by dvhh - There actually seem to be 4 separate proposals right now, maybe another was just added?
Proposal D is "Accept AI contributions for Debian specific work"
by infl8ed - Thanks, we've put the three proposals bit in the title above.by dang
- There is also proposal D right at the bottom, which is "Accept AI contributions for Debian specific work".by mmwelt