Debian splits ftpmaster team
Debian's ftpmaster team has been responsible for allowing new packages to enter Debian, removing old packages, and otherwise maintaining Debian's package archive for more than two decades. As of October 26, the team is no more and its duties are being split between two new teams. The Archive Operations Team will focus on the infrastructure required to support the Debian archives, and the DFSG, Licensing & New Packages Team, which is responsible for reviewing packages entering the new queue. In time, this move could speed up processing of new packages, as well as making the teams more sustainable, but only after new members are recruited and trained. For now, the same folks are doing the work but spread across two teams.
Ftpmaster frustrations
The ftpmaster team has been in place at least since 2000, according to a snapshot of the Debian Organizational Structure page on the Internet Archive. It held a great deal of control over what did, or did not, enter Debian's archive. And with great power, of course, came a lot of responsibility as well. The team's duties ranged from maintaining the Debian archive infrastructure, developing the Debian Archive Kit (dak) software, and reviewing new packages. When a package is uploaded to Debian for the first time, it is placed in the new queue; before a package is allowed to enter the archive, it must be checked to ensure that it complies with Debian policy, has an appropriate license, its name does not conflict with another package, and so on. The Reject FAQ provides a non-exhaustive list of reasons that packages might be rejected.
It also made the team something of a bottleneck; packages submitted to the new queue could languish for months before being approved or rejected. There is a summary page for the new queue as well as a statistics page with graphs that track the number of packages in new over time. According to the summary page, there are many packages that have been in the queue for several months.
In one of the recent discussions about the ftpmaster team, Otto
Kekäläinen cited
an example of an aspiring Debian developer waiting months to see their
work reviewed by someone from the team. The contributor, he said,
"has been mostly idle with his Debian work just waiting for the
package to pass in order to proceed
". It is fair to note, though,
that the delayed packages are outliers: the median time for packages in the
new queue is less than two days, according to an email
from Matthias Urlichs in March. Even so, developers who have had to
wait on reviews likely find little consolation in knowing that other
packages are moving through more quickly. It also does not help Debian
retain new developers if their early encounters with packaging
involve months of waiting.
One of the reasons the ftpmaster team gives for packages waiting a long time for review is that there were too few hands to do the work. That has been a problem for quite some time; when LWN covered the ftpmaster team in 2010, Joerg Jaspert had hoped to add at least one more person to the team, citing too few people to review all of the new packages. Finding qualified volunteers is harder than it may sound, though; the scope of duties meant that it was a rare individual indeed who could fill the shoes of an ftpmaster.
Jaspert said then, in a call for new
volunteers, that becoming an ftpmaster required a candidate to possess
a basic understanding of "just about every programming language you
can imagine
", have a good understanding of how packaging works,
and have a love of reading and dealing with legal
texts. A volunteer should also, he observed, be able to deal with
doling out unpopular decisions. "If you can't stand a bit of flames
/ don't like to take hard decisions, this is no job for you.
"
Finding people with the full set of skills to do the job was
already difficult; adding to that was the fact that the existing
members of the team did not have the bandwidth to mentor new
users. Debian Project Leader (DPL) Andreas Tille said, in
March 2025, that
the ftpmaster team was looking for new members, but Sean Whitton quickly
replied:
"No, we are not.
" Whitton said
that it was not a good time for the ftpmaster team to train new
people, because the existing team was too busy doing other things.
Time to split
The split has been in the works since DebConf24 in Busan, South
Korea. It was brought up in a "meet the ftpteam" BoF (notes);
it was also a topic of discussion during the DPL election campaign
period this year. Whitton complained
that nothing had been done to address perceived problems with the
ftpmaster team. Part of Tille's lengthy reply,
was that he wanted to "gather advice from all sides and work
toward solutions with consensus
".
It has taken a while, but Tille announced, in his "Bits from the DPL" email on October 3, that he was planning to split the ftpmaster team into two teams; one to review packages for compliance with the Debian Free Software Guidelines (DFSG), and one to manage archive operations. This would, he reasoned, make it easier for each team to concentrate on its tasks and for new contributors to be involved, while helping Debian developers to understand the process.
Overall the reaction to the idea was positive, though there was
some pushback on his ideas about package removals. Tille had noted
that, previously, package removals were not officially part of the
ftpmaster set of duties, "though they remain an important
responsibility
". He proposed that Debian should be able to
withdraw a package within 48 hours in the case of copyright claims or
major security vulnerabilities.
What "withdraw" meant was not entirely clear, and the timeline given raised a few objections. Adrian Bunk said that it would be challenging to do everything required to remove a package within 48 hours. Even if a code fix was available immediately, he said, updating the source package, rebuilding installers (if required), and creating a new point release would be challenging to do within 48 hours.
Holger Levsen said
that he was "perplexed and shocked
" that Tille would propose
such an aggressive timeline. Tille replied
that his choice of wording "shifted the focus into an unfortunate
direction
". He was really interested in discussing whether the package
removals "should explicitly fall under the responsibility of the
Archive Operations Team
". He also said
that he was looking for "a formalized process that shows we take
such reports seriously and that helps protect our developers from
potential legal exposure
".
Delegations
Aside from concerns about removal timelines, there was not much discussion on the list about the proposed split. Tille announced the delegations for the teams on October 26. Both teams are starting with the same four members, carried over from the last ftpmaster delegation that was issued by Tille on August 18: Thorsten Alteholz, Ansgar Burchardt, Luke Faraone, and Jaspert. One email details the DFSG, Licensing & New Packages Team ("DFSG team"), and another describes the Debian Archive Operations Team ("Archive team"). Ultimately, he placed responsibility for package removals with the Archive team. The announcements also revoked the former ftpmaster team delegation, so it officially no longer exists.
One thing that is unclear is the status of those who were involved with the ftpmaster team as an assistant or trainee; whether the new teams will create assistant or trainee roles with lesser privileges remains to be seen.
The list of responsibilities will look familiar; aside from package
removals, all of the tasks are the same, just split down the middle
(or thereabouts). The Archive team is tasked with operating the Debian
archive, maintaining its infrastructure (such as tools for processing
uploads) and the dak software, as well as documenting its processes
"especially those related to releases
". The DFSG team is
responsible for handling packages in the new queue, communicating
about the status of those packages, ensuring that the packages
"respect the DFSG and applicable licensing and legal
requirements
", and documenting its policies.
Even with the divvying up of duties, volunteers are going to need a rare set of skills to meet the requirements of either team. The problem of finding new volunteers, and mentoring them, still falls to the same people. But, one hopes, this will eventually help Debian expand the number of people doing crucial work and reduce the load on each volunteer. It will be interesting to see how it works out over the coming months.
