#1077845 release.debian.org: Should non-free-firmware require being built on buildd?

#1077845#5
Date:
2024-08-03 09:55:19 UTC
From:
To:
Hi,

Historically, we have had a major opt-out for non-free in regards to
Policy. One of these opt-outs are that the package does not have to be
auto-built on Debian buildds.

Since the non-free is entirely opt-in and you had to be very active
about opt'ing in as a admin, this seem fine. With the change to
non-free-firmware now being enabled by d-i by default, we now have
non-free-firmware packages installed by default that can use this
opt-out and for me, that changes the game a bit.

In my book, ideally, we would require all non-free-firmware to be build
on buildds to have it be closer aligned with main since it is now
installable by default, where we do not want to trust maintainer build
packages (which also makes our contributors less of a target for
build-time backdoors).
   Though, license requirements might prevent that (I have not checked
whether all non-free-firmware is auto-buildable), so a second runner up
for me would be to have Britney enforce non-free(-firmware) was built on
a buildd if the source has `Autobuild` set to `yes`. This would at least
close the gap as much as possible.

Best regards,
Niels

#1077845#10
Date:
2024-08-03 10:36:42 UTC
From:
To:
Hi,

I totally agree.

It would be good if we had the answer to this question, because changing
britney2 to do the check for all binaries is trivial [1], and adding a
hint explicitly for those that aren't auto-buildable seems maintainable
(there are currently only 15 sources in non-free-firmware in sid).

Paul

[1]
https://salsa.debian.org/release-team/britney2/-/blob/master/britney2/policies/policy.py?ref_type=heads#L1543

#1077845#15
Date:
2024-08-03 16:30:26 UTC
From:
To:
Paul Gevers:
are 10/15 on `Autobuild: yes` with remaining 5 not having the header.

No clue whether they could get that or we have to compromise already
here. Though, even if they can, there is also the aspect of whether we
are ready to commit to all new firmware being `Autobuild: yes`. I
figured `d-boot` might have an opinion on that (which is why I have
CC'ed them on this bug).

The 5 that are not `Autobuild: yes` would be:

atmel-firmware
bluez-firmware
dahdi-firmware
live-tasks-non-free-firmware
midisport-firmware

(as far as my wetware was able to eyeball)

Best regards,
Niels

#1077845#20
Date:
2024-08-04 06:33:11 UTC
From:
To:
...

This is a 'meta' package, that only refers to other firmware packages,
it does not contain firmware itself.

With kind regards,
Roland Clobus

#1077845#25
Date:
2024-08-04 07:31:43 UTC
From:
To:
Roland Clobus:

I was informed on IRC about
https://salsa.debian.org/bluetooth-team/bluez-firmware/-/merge_requests/4,
so I presume bluez-firmware might disappear

Thanks Roland. That sounds like it trivially could be converted to an
`Autobuild: yes` package.

That leaves us with 3/15 and the question whether we want to commit for
future firmware.

Best regards,
Niels

#1077845#30
Date:
2024-08-04 08:31:30 UTC
From:
To:
Hi,

I don't think we need to commit, just express a very strong desire to
build on buildds when possible, and be practical if we can't.

Paul

#1077845#35
Date:
2024-08-04 11:22:11 UTC
From:
To:
The question would be whether you want to enforce it in Britney,
which basically implies that Autobuild: should default to yes in
non-free-firmware.

You could ask on debian-devel whether there are any potential use cases
in non-free-firmware where this might be problematic.

cu
Adrian

#1077845#40
Date:
2024-08-04 11:32:24 UTC
From:
To:
Hi,

I see this as a rephrasing of the discussion, so I can only agree that
that's the question.

With main we also just decided to do it, with the possibility to have
packages hinted through. I'm don't see how it could be problematic,
unless you mean that asking for an exception is problematic already. I
already made a mental note to announce this when we deploy it, so it
doesn't come as a surprise for those following announcements. But maybe
you're having a different angle in mind?

Paul

#1077845#45
Date:
2024-08-04 12:12:26 UTC
From:
To:
2. some packages in non-free have build dependencies that are in non-free
   or not in Debian at all
3. an "Autobuild: no" package in non-free might download the contents
   from the internet during the build

What I have in mind is whether it can be made a requirement that all
packages in non-free-firmware must be legally and technically buildable
on the buildds, like in main. And then have the Autobuild default
changed first before any change to Britney.

"building" would of course usually be "copy blobs from sources to binary package".

Britney enforcing source-only uploads in a section with "Autobuild: no"
default would require a human at non-free@buildd.debian.org to manually
approve every package before it can enter testing for the first time.

cu
Adrian

[1] https://www.debian.org/doc/manuals/developers-reference/pkgs.html#non-free-buildd

#1077845#50
Date:
2026-01-10 10:10:41 UTC
From:
To:
Es gibt eine Familienspende in Höhe von 1.850.000,00 USD von Cheng Charlie
Saephan. Bitte antworten Sie für weitere Informationen. Denken Sie daran,
Ihrer Familie und den Bedürftigen in Ihrer Umgebung Gutes zu tun.

Dies ist bereits der zweite Versuch, Sie zu erreichen. Bitte antworten Sie
für weitere Details.