Debian grapples with offensive packages, again
A pair of packages containing fortune "cookies" that were deemed offensive have been removed from the upcoming Debian 13 ("trixie") release. This has, of course, led to a lengthy discussion and debate about what does, or does not, belong in the distribution. It may also lead to a general resolution (GR) to decide whether Debian's code of conduct (CoC) applies to the contents of packages.
The fortune program prints out a random quote or other piece of text from one or more topic databases. On Debian, for example, the topic categories shipped with the fortunes package include art, ascii-art, food, love, Linux, pets, Star Trek, and more. Those are installed by default when one installs fortune-mod, the package that contains the fortune program.
The packages that are being removed from trixie—fortunes-it-off and fortunes-scn-off—contain the Italian and Sicilian (respectively) offensive fortunes. "Offensive" here is not an editorial judgment call—the packages are officially designated as offensive in the package names and are maintained separately to ensure that users do not install them accidentally. These packages are not pulled in by default when a user installs fortune-mod; a person would have to install them separately. Even if the -off packages are installed, fortune only chooses from the database of offensive fortunes if one uses the -o option. Debian's man page for fortune includes this guidance for that option:
Please, please, please request a potentially offensive fortune if and only if you believe, deep in your heart, that you are willing to be offended. (And that you'll just quit using -o rather than give us grief about it, okay?)
Debian split the offensive fortunes in English off into a separate
fortunes-off package in 1997. That package was dropped
entirely ahead of the Debian 12 ("bookworm") release, following a
a
lengthy discussion on the debian-project mailing list. That discussion
was started by Debian community team
member Andrew M.A. Cater after the team had received a query about the
fortunes-off package. Someone had asked if the package
contained any Nazi quotes, which "might make it illegal to host the
content on mirrors in at least Germany or Austria
". He said that
he thought any such quotes had been purged from the original BSD
package that served as a basis for Debian's fortune
packages.
However, he raised the question of whether Debian should remove
fortunes-off since it contains quotes that "probably don't
fit in with our Debian values or general societal values 25
years on
". Ultimately, after much debate, it was removed.
But that was only the English version of the package. The fortunes-it-off package was still included in bookworm when it shipped in June, 2023. Salvo Tomaselli took over as maintainer of fortunes-it and fortunes-it-off in November 2023, and introduced the fortunes-scn and fortunes-scn-off packages that month as well. Note that the scn binary packages are built from the same source package (fortunes-it). The scn binary package was added on November 30, 2023.
"No place in Debian"
On July 12, Cater filed bugs against fortunes-scn-off
and fortunes-it-off. Cater's
bug reports simply said that the English fortunes had been removed,
and the subjects for the bugs stated that the packages had "no place in
Debian
". He did not elaborate on any specific text in either package
that he found offensive or explain why he chose to file the bugs when
he did. Debian is currently in freeze and preparing for the trixie
release, so a removal would have the effect of dropping the packages from the
upcoming release entirely, though they would continue to be available in
bookworm.
Tomaselli responded
a day later; he said that the packages in question are not installed
automatically and that no one had actually complained that they were
offended by them. "I think it's fine.
" He added he was happy to
accept pull requests, and had been doing maintenance on the packages after it
had been abandoned for many years: "and actually removed a number
of fascist, racist and sexist quotes that were not in the offensive
section
". With that, he closed the bugs. On July 16, Paul Gevers
of the release team reopened the bugs and said that he was
"reinforcing the decision of the community team
"; he asked
Tomaselli to please drop the offensive packages.
Cater is still a member of Debian's community team, but in a conversation at DebConf25 he said that he had filed the bugs as an individual, not as a member of the community team. While Cater did not identify himself as a member of the community team, it's not difficult to understand why someone might assume he was acting in that capacity given the history. It's possible, if Cater had provided a longer bug report with examples, and if he had stated that the report was not an official community team action, that the ensuing debate could have been avoided—or shortened. He did allow, in retrospect, that he was not good at filing bugs and that the bug report could have been better.
Can they do that?
Tomaselli sent
a message to debian-devel on July 16 about the removal, and
asked whether he could be forced to remove a package by the community
team "even though I did not violate the COC and they did not
receive any complaints?
" The packages have existed since 2003, he
said, "and there have been 0 complaints from offended people in
these 22 years
". He was annoyed that, after working on the package
for two years, he was suddenly being asked to remove it while in
freeze for the trixie release. "I do not appreciate wasting my
time, I do not appreciate having to write this email and I do not
appreciate the collective time wasted on this.
"
Debian does not need to ship offensive fortunes, Charles Plessy argued,
"people who want to install [them] still have plenty of easy ways
to do so
". Maybe, he suggested, there are better battles to
fight. Hanno "Rince" Wagner disagreed;
as long as someone wants to spend their time curating a package, he
did not think that Debian should remove it.
Didier "OdyX" Raboud observed
that if the project had reached consensus that the
fortunes-off package in English should be removed, "it
also follows that they ought to be removed in other languages
".
Debian contributor "NoisyCoil" said that they had wanted to argue in favor of keeping the packages, but after looking at the content they had decided against it:
I went peeking at the package and, unless I'm completely missing something, the second offensive Italian fortune says that women's "no"s should be interpreted as "yes", while the third one explicitly calls for violence on women [1]. Like, it literally says women should be beaten on a regular basis. I'm afraid I can't help you here, sorry.
Tomaselli said
that the reason that offensive file contains calls to beat women is
because he had moved it out of the "normal" fortunes. "Without me
it could have remained in the normal section another 200 years for
what anyone here cares about.
"
The debate featured many other responses both for and against
removing the package, though the bulk of responses seem to favor
removal. Contributors shared opinions on what is or isn't offensive
and questions about other content—such as the Bible—that
might offend others. If this seems familiar, it may be because similar
points had been raised during the prior discussion about removing the
English-language package. Long-time Debian users may recall the
project grappling with the
same issues more than 20 years ago when Thibaut Varene proposed packaging
"hot-babe", a graphical utility that promised to display "system
activity in a very special way
"; specifically, it would display a
graphic of a woman undressing as system temperature increased.
Getting consensus
After a few days of debate, Wouter Verhelst sent
an email to debian-vote and said that "it's clear by now that
we need a project-wide consensus on what policies apply to the
contents of packages
". When he wrote Debian's code of conduct,
which was ratified by the project in 2014, he had not made it explicit
that it was not meant to apply to the content of packages, though that was
his intent. (Updated to add not in the previous sentence.)
Since the discussion keeps coming up, he said, the project should
probably vote on a GR about the subject. There were four options he
thought would be appropriate: the first two were that the CoC
applies unmodified to all source code in a package or that it does not
apply to the contents of packages, and that no alternative CoC is needed for
packages. A third option, he said, would be that the CoC
applies to "all program messages or documentation
" that could
be seen by a user, with exceptions for "historic texts that are
widely disseminated outside of Debian
". If that
option had been Debian policy, the guidance would have clearly applied
to this situation and made it an easy call to remove the packages.
The fourth option he thought likely was that the current code of
conduct does not apply to packages, but a "code of contents" should be
written that would apply to packages. Creating such a thing, however,
would be a lot of work that he was unwilling to do. Anyone who wanted
to propose such an option should have the text ready, "otherwise
we're discussing hypotheticals rather than solutions
". He said
that he would make a formal GR proposal with the third option "a
few weeks from now
", unless the thread was still ongoing and
productive.
Tomaselli said
that he had also been thinking of starting a thread about a GR,
but Verhelst had been quicker. Tomaselli thought there should be an
"entirely new and different policy
" about what to accept and
not accept, because "there will inevitably be a lot of mismatches
if we just apply the code of conduct to all the code we
have
". Verhelst replied
that sounded like his option four and reminded Tomaselli that he had
plenty of time to draft an option like that.
Is it really a problem?
Iustin Pop thought
that package content had generally not been a significant problem in
Debian, with the exception of the fortune packages. He
wondered whether Debian really wanted to have a CoC for enforcing
morality standards "which can change over time
", or if the
project wanted to be neutral and ship software as-is. Verhelst replied
that he wanted an answer to the question of whether the CoC applies to Debian packages. He pointed to other discussions, such as
hot-babe and the sudo insults
feature, "which used to be enabled by default, but was disabled
after a bug report with complaints
". He said it was not absolutely
necessary to have a CoC for packages, but he thought it was a good
idea.
Former Debian Project Leader Bdale Garbee thought a
code for acceptable content was "an exceptionally bad idea
". He
said that the only policy that should govern package content should be
compliance with the Debian Free Software Guidelines (DFSG):
If external forces, like laws, force us to elide some content or come up with additional complications in our distribution mechanisms as US law on crypto export once did, then fine, we'll deal with those when we must. But trying to apply some sort of moral code to package content, or offering to avoid offending individuals or groups with the software we distribute, feels likely to be directly in conflict with DFSG 5, "No Discrimination Against Persons or Groups", and/or DFSG 6, "No Discrimination Against Fields of Endeavor".
At best, Garbee said, it would be a slippery slope given the
differences of opinion that exist within the Debian project. Tiago
Bortoletto Vaz felt
that a GR was unnecessary. He said it was not a recurrent problem for
the project, "so perhaps it doesn't really need new rules
":
Honest question: in ~30 years, how many packages have been removed from our archive due to offensive content? 4? 5? How many of the removal requests turned into big drama?
"AFAIK, all of them
", replied
Tomaselli. This was the first time he had encountered package removal
as a Debian developer, but not his first time "having packages
disappear because someone else decided they were immoral
". Having
a firm rule would be less controversial, he said.
Russ Allbery noted
that, since there is no content policy for packages, every time there's
a question about content it gets argued "to death
" on the
mailing lists:
A careful debian-devel observer could have listed most of the people who would respond to the thread and written a pretty good paraphrase of what they would say the moment they saw the first few messages in the thread.
Verhelst said,
that it would also make life easier for Debian's release team to have
a concrete policy. The team had decided that the package should be
removed, based on Debian's code of conduct, but Verhelst said it was
unclear whether the CoC even applies to packages. He also questioned
whether the release team is even the right team to make the decision,
though he was quick to add that was not meant as a criticism: "They
do a hard job under difficult circumstances, and that is
appreciated
".
Clearly, he said, some people in the project believe that Debian should have a content policy that should be imposed. That being the case, the project should make a decision:
And honestly, if we think about this and decide as a project that "anything is allowed except things that are obviously illegal", then that's fine with me too. I just want us to think about this and make the call, rather than leaving this to a team that really have a different responsibility and will take the flak for doing something that shouldn't even be their job but nobody else is doing it.
Later he added that a policy is already being imposed with the removal of the offensive fortune packages:
This means that we already do have an effective code of acceptable conduct, decided by the release team and not the project at large, and I think that is wrong.
For now, the conversation has largely died down; many of the participants are no doubt busy getting trixie ready for its release on August 9 without the offensive fortune files. Sometime after the release, Debian may finally come to a firm decision on whether it wants to moderate the content of packages, and where it draws the line if it chooses to impose one.
