|
|
Log in / Subscribe / Register

Debian splits ftpmaster team

By Joe Brockmeier
October 29, 2025

Debian's ftpmaster team has been responsible for allowing new packages to enter Debian, removing old packages, and otherwise maintaining Debian's package archive for more than two decades. As of October 26, the team is no more and its duties are being split between two new teams. The Archive Operations Team will focus on the infrastructure required to support the Debian archives, and the DFSG, Licensing & New Packages Team, which is responsible for reviewing packages entering the new queue. In time, this move could speed up processing of new packages, as well as making the teams more sustainable, but only after new members are recruited and trained. For now, the same folks are doing the work but spread across two teams.

Ftpmaster frustrations

The ftpmaster team has been in place at least since 2000, according to a snapshot of the Debian Organizational Structure page on the Internet Archive. It held a great deal of control over what did, or did not, enter Debian's archive. And with great power, of course, came a lot of responsibility as well. The team's duties ranged from maintaining the Debian archive infrastructure, developing the Debian Archive Kit (dak) software, and reviewing new packages. When a package is uploaded to Debian for the first time, it is placed in the new queue; before a package is allowed to enter the archive, it must be checked to ensure that it complies with Debian policy, has an appropriate license, its name does not conflict with another package, and so on. The Reject FAQ provides a non-exhaustive list of reasons that packages might be rejected.

It also made the team something of a bottleneck; packages submitted to the new queue could languish for months before being approved or rejected. There is a summary page for the new queue as well as a statistics page with graphs that track the number of packages in new over time. According to the summary page, there are many packages that have been in the queue for several months.

In one of the recent discussions about the ftpmaster team, Otto Kekäläinen cited an example of an aspiring Debian developer waiting months to see their work reviewed by someone from the team. The contributor, he said, "has been mostly idle with his Debian work just waiting for the package to pass in order to proceed". It is fair to note, though, that the delayed packages are outliers: the median time for packages in the new queue is less than two days, according to an email from Matthias Urlichs in March. Even so, developers who have had to wait on reviews likely find little consolation in knowing that other packages are moving through more quickly. It also does not help Debian retain new developers if their early encounters with packaging involve months of waiting.

One of the reasons the ftpmaster team gives for packages waiting a long time for review is that there were too few hands to do the work. That has been a problem for quite some time; when LWN covered the ftpmaster team in 2010, Joerg Jaspert had hoped to add at least one more person to the team, citing too few people to review all of the new packages. Finding qualified volunteers is harder than it may sound, though; the scope of duties meant that it was a rare individual indeed who could fill the shoes of an ftpmaster.

Jaspert said then, in a call for new volunteers, that becoming an ftpmaster required a candidate to possess a basic understanding of "just about every programming language you can imagine", have a good understanding of how packaging works, and have a love of reading and dealing with legal texts. A volunteer should also, he observed, be able to deal with doling out unpopular decisions. "If you can't stand a bit of flames / don't like to take hard decisions, this is no job for you."

Finding people with the full set of skills to do the job was already difficult; adding to that was the fact that the existing members of the team did not have the bandwidth to mentor new users. Debian Project Leader (DPL) Andreas Tille said, in March 2025, that the ftpmaster team was looking for new members, but Sean Whitton quickly replied: "No, we are not." Whitton said that it was not a good time for the ftpmaster team to train new people, because the existing team was too busy doing other things.

Time to split

The split has been in the works since DebConf24 in Busan, South Korea. It was brought up in a "meet the ftpteam" BoF (notes); it was also a topic of discussion during the DPL election campaign period this year. Whitton complained that nothing had been done to address perceived problems with the ftpmaster team. Part of Tille's lengthy reply, was that he wanted to "gather advice from all sides and work toward solutions with consensus".

It has taken a while, but Tille announced, in his "Bits from the DPL" email on October 3, that he was planning to split the ftpmaster team into two teams; one to review packages for compliance with the Debian Free Software Guidelines (DFSG), and one to manage archive operations. This would, he reasoned, make it easier for each team to concentrate on its tasks and for new contributors to be involved, while helping Debian developers to understand the process.

Overall the reaction to the idea was positive, though there was some pushback on his ideas about package removals. Tille had noted that, previously, package removals were not officially part of the ftpmaster set of duties, "though they remain an important responsibility". He proposed that Debian should be able to withdraw a package within 48 hours in the case of copyright claims or major security vulnerabilities.

What "withdraw" meant was not entirely clear, and the timeline given raised a few objections. Adrian Bunk said that it would be challenging to do everything required to remove a package within 48 hours. Even if a code fix was available immediately, he said, updating the source package, rebuilding installers (if required), and creating a new point release would be challenging to do within 48 hours.

Holger Levsen said that he was "perplexed and shocked" that Tille would propose such an aggressive timeline. Tille replied that his choice of wording "shifted the focus into an unfortunate direction". He was really interested in discussing whether the package removals "should explicitly fall under the responsibility of the Archive Operations Team". He also said that he was looking for "a formalized process that shows we take such reports seriously and that helps protect our developers from potential legal exposure".

Delegations

Aside from concerns about removal timelines, there was not much discussion on the list about the proposed split. Tille announced the delegations for the teams on October 26. Both teams are starting with the same four members, carried over from the last ftpmaster delegation that was issued by Tille on August 18: Thorsten Alteholz, Ansgar Burchardt, Luke Faraone, and Jaspert. One email details the DFSG, Licensing & New Packages Team ("DFSG team"), and another describes the Debian Archive Operations Team ("Archive team"). Ultimately, he placed responsibility for package removals with the Archive team. The announcements also revoked the former ftpmaster team delegation, so it officially no longer exists.

One thing that is unclear is the status of those who were involved with the ftpmaster team as an assistant or trainee; whether the new teams will create assistant or trainee roles with lesser privileges remains to be seen.

The list of responsibilities will look familiar; aside from package removals, all of the tasks are the same, just split down the middle (or thereabouts). The Archive team is tasked with operating the Debian archive, maintaining its infrastructure (such as tools for processing uploads) and the dak software, as well as documenting its processes "especially those related to releases". The DFSG team is responsible for handling packages in the new queue, communicating about the status of those packages, ensuring that the packages "respect the DFSG and applicable licensing and legal requirements", and documenting its policies.

Even with the divvying up of duties, volunteers are going to need a rare set of skills to meet the requirements of either team. The problem of finding new volunteers, and mentoring them, still falls to the same people. But, one hopes, this will eventually help Debian expand the number of people doing crucial work and reduce the load on each volunteer. It will be interesting to see how it works out over the coming months.



to post comments

" two days median time" is misleading.

Posted Oct 29, 2025 21:52 UTC (Wed) by ballombe (subscriber, #9523) [Link]

FTP masters approval is required each time a new binary package name is created.
There are roughly three cases where this happens.
1) when a new source package is introduced.
2) when an preexisting source package generates a new binary package.
3) when an preexisting binary package is renamed.

The case 3) happens any time a shared library soname change, since the soname is part of the package name.
The FTP-masters prioritize (for good reasons) cases 2) and 3) since the source package was already part of Debian.
However this completely skews the statistics.
Saying that 'the median time for packages in the new queue is less than two days' is misleading since this is the combined time for 1)+2)+3) where 2)+3) is much faster than 1).

Note that the full quote from Matthias is
""
* I have learned (thanks @roehling) that the *actual* median time packages spend in NEW is less than two days. In other words, *somebody* must have *some* time available.
""


Copyright © 2025, Eklektix, Inc.
This article may be redistributed under the terms of the Creative Commons CC BY-SA 4.0 license
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds