Debian permitting use of genAI:
-
@neil @tschenkel that is very tempting unfortunately very tricky given our dependence on complex infrastructure.
I imagine keeping a herd of goats and tending to an olive grove
@mhagdorn @neil @tschenkel Or donkeys
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil thanks Neil for your thoughts.
So Debian in the past has done some possibly questionable decisions like systemd.
I am aware of the environmental harm that AI is doing. On the other hand I can imagine a future where we all run a low resource local AI on better hardware and where there isn't so much money being pumped into these data centers anymore. However nobody knows the future and the sooner these firms go bankrupt, the sooner that there will be some alignment between environmental cost and financial cost.
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil also as a developer, it might be hypocritical to say absolutely no to AI.
There are some use cases that are compelling such as the way it can explain code to me or how can assist me with languages that I know but I am not good at yet for example rust.
For these use cases I would want to use some AI. And I imagine this is true of other developers. Even Debian developers. And that would be responsible use AI, right? This would not be creating slop necessarily.
I can understand that they also some cases where LLMs either by design, or due to insufficient oversight introduce security vulnerabilities into software and these I am concerned about.
So, umm... How to get the balance right? An outright ban for me is too much. But if it is allowed in limited and restricted circumstances only, wouldn't you say yes to that?
-
@neil also as a developer, it might be hypocritical to say absolutely no to AI.
There are some use cases that are compelling such as the way it can explain code to me or how can assist me with languages that I know but I am not good at yet for example rust.
For these use cases I would want to use some AI. And I imagine this is true of other developers. Even Debian developers. And that would be responsible use AI, right? This would not be creating slop necessarily.
I can understand that they also some cases where LLMs either by design, or due to insufficient oversight introduce security vulnerabilities into software and these I am concerned about.
So, umm... How to get the balance right? An outright ban for me is too much. But if it is allowed in limited and restricted circumstances only, wouldn't you say yes to that?
> And that would be responsible use AI, right?
What criteria are you using for this assessment? That would seem to be important here, as to whether your conclusion is really just reinforcing your choice to use genAI because you would find it helpful to do so, or if it is a considered, objective stance.
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil appreciate your thoughtfulness on this, even if I don't necessarily entirely share your values.
My issue with this whole thing comes down to detectability and trust. If I point at a git commit, authored by me, and I pinky swear I didn't use an LLM to write, design, or coach me through any part of it, is that sufficient to meet a project's "no AI" policy?
-
@neil appreciate your thoughtfulness on this, even if I don't necessarily entirely share your values.
My issue with this whole thing comes down to detectability and trust. If I point at a git commit, authored by me, and I pinky swear I didn't use an LLM to write, design, or coach me through any part of it, is that sufficient to meet a project's "no AI" policy?
I think that I see that in the same way as I see other questions of provenance.
For instance, if I promise that I have the permission to contribute a patch, but I do not, that might be hard to detect, but is nevertheless important.
-
@neil also as a developer, it might be hypocritical to say absolutely no to AI.
There are some use cases that are compelling such as the way it can explain code to me or how can assist me with languages that I know but I am not good at yet for example rust.
For these use cases I would want to use some AI. And I imagine this is true of other developers. Even Debian developers. And that would be responsible use AI, right? This would not be creating slop necessarily.
I can understand that they also some cases where LLMs either by design, or due to insufficient oversight introduce security vulnerabilities into software and these I am concerned about.
So, umm... How to get the balance right? An outright ban for me is too much. But if it is allowed in limited and restricted circumstances only, wouldn't you say yes to that?
I would think that just based on license concerns alone would necessitate a policy of "No source-code or binary files may be generated wholly or in part by an LLM."
If _you_ didn't write it, or if you don't have a license to relicense it, you can't in good order publish it under an open-source license. (Or, for that matter, a closed-source license.)
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil i'm personally going to wait a while. these new rules mean that contributers are responsible for ensuring their contributions are copyright-free, and AFAIK debian's semi-militant "foss-only" stance remains in play.
is this going to be a template for malicious compliance? "no, sorry, you can't prove you didn't use copyrighted code". — i don't know.
is this going to be a way to rubber-stamp non-foss code? — i don't know.
wait and see…
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil just use fedora
-
@neil i'm personally going to wait a while. these new rules mean that contributers are responsible for ensuring their contributions are copyright-free, and AFAIK debian's semi-militant "foss-only" stance remains in play.
is this going to be a template for malicious compliance? "no, sorry, you can't prove you didn't use copyrighted code". — i don't know.
is this going to be a way to rubber-stamp non-foss code? — i don't know.
wait and see…
@neil also, sadly, the vast majority of the code in a debian distro is not written by debian developers, and the way things are going _that_ is most likely to have been touched by the magic eight ball - including the kernel. so.
-
I would think that just based on license concerns alone would necessitate a policy of "No source-code or binary files may be generated wholly or in part by an LLM."
If _you_ didn't write it, or if you don't have a license to relicense it, you can't in good order publish it under an open-source license. (Or, for that matter, a closed-source license.)
@skjeggtroll
That's the key difficulty.But in the case of Debian, the main use will be (will, not could) solving dependencies, because that's the key problem facing "developers" (mostly packagers, the unsung heroes of FOSS, really).
-
@neil just use fedora
"just" does a lot of heavy lifting here.
-
@dequbed Thank you!
I have not used Gentoo in 25 years

-
@dequbed Thank you!
I have not used Gentoo in 25 years

@neil Well then, it has certainly changed since then; most of it for the better

-
I think that I see that in the same way as I see other questions of provenance.
For instance, if I promise that I have the permission to contribute a patch, but I do not, that might be hard to detect, but is nevertheless important.
@neil I agree with that framing.
The provenance thing provokes the same question for me about where the line is though.
A hidden actor that writes the code directly that I claim? Probably against the policy.
Someone/thing that coaches me through writing the code? Someone who writes a blog/book that inspires me to create the code? Less clear.
What about a machine that takes the voice output of someone unable to type and turns that into code? Is that acceptable?
I don't think "no LLMs / no AI" is anything like precise enough to be useful. It's a good statement of principle, but a wholly inneffective policy imo. I have no good answer or suggestion though

-
@neil Well then, it has certainly changed since then; most of it for the better

The same is true of me

-
@neil I agree with that framing.
The provenance thing provokes the same question for me about where the line is though.
A hidden actor that writes the code directly that I claim? Probably against the policy.
Someone/thing that coaches me through writing the code? Someone who writes a blog/book that inspires me to create the code? Less clear.
What about a machine that takes the voice output of someone unable to type and turns that into code? Is that acceptable?
I don't think "no LLMs / no AI" is anything like precise enough to be useful. It's a good statement of principle, but a wholly inneffective policy imo. I have no good answer or suggestion though

I don't think that most of these are new issues, though - and some seem (to me, anyway) somewhat contrived/forced in the context of the issue in discussion (speech to text in particular).
That said, yes, clarity is welcome.
-
I don't think that most of these are new issues, though - and some seem (to me, anyway) somewhat contrived/forced in the context of the issue in discussion (speech to text in particular).
That said, yes, clarity is welcome.
@neil take your point on contrived. My experience is that the credibility of these things live and die with the edge cases. Today's hypothetical is tomorrow's case study etc. etc.
We will discover and figure this out over time, I'm sure of it!

-
@neil also as a developer, it might be hypocritical to say absolutely no to AI.
There are some use cases that are compelling such as the way it can explain code to me or how can assist me with languages that I know but I am not good at yet for example rust.
For these use cases I would want to use some AI. And I imagine this is true of other developers. Even Debian developers. And that would be responsible use AI, right? This would not be creating slop necessarily.
I can understand that they also some cases where LLMs either by design, or due to insufficient oversight introduce security vulnerabilities into software and these I am concerned about.
So, umm... How to get the balance right? An outright ban for me is too much. But if it is allowed in limited and restricted circumstances only, wouldn't you say yes to that?
@freshstart @neil The "right balance" for #NoAI is no AI. Nothing hypocritical in that if you're not using AI.
You finding it helpful doesn't make the environmental impacts disappear, or make money appear in the pockets of all the people whose IP is being stolen, or even ensure that it's not teaching you to write bad code.
Every AI user finds a way to justify it to themself, but there's nothing responsible about your use case. You're the baddie, here - step away from the edge.