- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Niels Thykier
- Date:
- 2026-01-10 10:59:53 UTC
- Severity:
- normal
Hi, Historically, we have had a major opt-out for non-free in regards to Policy. One of these opt-outs are that the package does not have to be auto-built on Debian buildds. Since the non-free is entirely opt-in and you had to be very active about opt'ing in as a admin, this seem fine. With the change to non-free-firmware now being enabled by d-i by default, we now have non-free-firmware packages installed by default that can use this opt-out and for me, that changes the game a bit. In my book, ideally, we would require all non-free-firmware to be build on buildds to have it be closer aligned with main since it is now installable by default, where we do not want to trust maintainer build packages (which also makes our contributors less of a target for build-time backdoors). Though, license requirements might prevent that (I have not checked whether all non-free-firmware is auto-buildable), so a second runner up for me would be to have Britney enforce non-free(-firmware) was built on a buildd if the source has `Autobuild` set to `yes`. This would at least close the gap as much as possible. Best regards, Niels
Hi, I totally agree. It would be good if we had the answer to this question, because changing britney2 to do the check for all binaries is trivial [1], and adding a hint explicitly for those that aren't auto-buildable seems maintainable (there are currently only 15 sources in non-free-firmware in sid). Paul [1] https://salsa.debian.org/release-team/britney2/-/blob/master/britney2/policies/policy.py?ref_type=heads#L1543
Paul Gevers: are 10/15 on `Autobuild: yes` with remaining 5 not having the header. No clue whether they could get that or we have to compromise already here. Though, even if they can, there is also the aspect of whether we are ready to commit to all new firmware being `Autobuild: yes`. I figured `d-boot` might have an opinion on that (which is why I have CC'ed them on this bug). The 5 that are not `Autobuild: yes` would be: atmel-firmware bluez-firmware dahdi-firmware live-tasks-non-free-firmware midisport-firmware (as far as my wetware was able to eyeball) Best regards, Niels
... This is a 'meta' package, that only refers to other firmware packages, it does not contain firmware itself. With kind regards, Roland Clobus
Roland Clobus: I was informed on IRC about https://salsa.debian.org/bluetooth-team/bluez-firmware/-/merge_requests/4, so I presume bluez-firmware might disappear Thanks Roland. That sounds like it trivially could be converted to an `Autobuild: yes` package. That leaves us with 3/15 and the question whether we want to commit for future firmware. Best regards, Niels
Hi, I don't think we need to commit, just express a very strong desire to build on buildds when possible, and be practical if we can't. Paul
The question would be whether you want to enforce it in Britney, which basically implies that Autobuild: should default to yes in non-free-firmware. You could ask on debian-devel whether there are any potential use cases in non-free-firmware where this might be problematic. cu Adrian
Hi, I see this as a rephrasing of the discussion, so I can only agree that that's the question. With main we also just decided to do it, with the possibility to have packages hinted through. I'm don't see how it could be problematic, unless you mean that asking for an exception is problematic already. I already made a mental note to announce this when we deploy it, so it doesn't come as a surprise for those following announcements. But maybe you're having a different angle in mind? Paul
2. some packages in non-free have build dependencies that are in non-free or not in Debian at all 3. an "Autobuild: no" package in non-free might download the contents from the internet during the build What I have in mind is whether it can be made a requirement that all packages in non-free-firmware must be legally and technically buildable on the buildds, like in main. And then have the Autobuild default changed first before any change to Britney. "building" would of course usually be "copy blobs from sources to binary package". Britney enforcing source-only uploads in a section with "Autobuild: no" default would require a human at non-free@buildd.debian.org to manually approve every package before it can enter testing for the first time. cu Adrian [1] https://www.debian.org/doc/manuals/developers-reference/pkgs.html#non-free-buildd
Es gibt eine Familienspende in Höhe von 1.850.000,00 USD von Cheng Charlie Saephan. Bitte antworten Sie für weitere Informationen. Denken Sie daran, Ihrer Familie und den Bedürftigen in Ihrer Umgebung Gutes zu tun. Dies ist bereits der zweite Versuch, Sie zu erreichen. Bitte antworten Sie für weitere Details.