[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: leader2013



On Sat, Apr 13, 2013 at 1:00 PM, Adam D. Barratt
<adam@adam-barratt.org.uk> wrote:
> On Sat, 2013-04-13 at 13:52 +0300, vangelis mouhtsis wrote:
>> i tryed to vote but failed. is the vote only for Debian project
>> members?
>
> Yes. Reading the mail should have made this quite clear.
>
> <quote>
> NOTE: The vote must be GPG signed (or PGP signed) with your key that is
> in the Debian keyring.
> </quote>

This is wrong (at least for some definitions of wrong).

Assuming "Debian keyring" refers to the package "debian-keyring" (which should
be a reasonable safe assumption, right?) and ignoring the problem of getting a
fresh version this package includes more than just a "debian-keyring.gpg".
It e.g. contains also the maintainers keyring. But lets ignore this, too.

Looking very closely at the "debian-keyring.gpg" file we can find that it
doesn't include non-uploader-DD keys (which are shipped in a separate file)
and while I haven't checked, the documentation in the package suggests that
the online source for this keyring will not include them either, so while this
requirement excludes the questioner, it also excludes non-packaging DDs which
were allowed to vote (as can be seen in the voters list).


Of course its clear for anyone who knows the process who is entitled to vote
and who is not – and hopefully everyone who is allowed to vote knows the
process –, but not everyone subscribed to d-d-a or the press who picks this
up will know it (yet), so it wouldn't hurt to have a nicer/clearer wording.
Especially as this note isn't really intended to limit the audience but to
remind the intended audience to use the right key …


Beside it is quiet easy to misunderstand it if you are not used to the
"Debian members" == "Debian Developers" mindset, especially if "DM" is
floating around and while everyone can develop Debian (in the §3.2.1 sense)
only certain individuals can be called Developers (as implicitly granted by
 §3.2.2, which is explicitly more concert with prohibitions) while the rest
are at most (= in the Levenshtein distance sense) developers…
(a mindset of which I am not really a fan, but that is another topic)


Best regards

David Kalnischkies, who writes this as a break from "deity" debugging,
so don't try to read too much sense into it if you don't want/have to.

P.S.: How are these DDs called, non-uploader as the keyring suggests or
 non-packaging as the GR suggests? And whats the "correct" abbreviation?
 /me is a bit scared by his first thought "NUDD" for various reasons…


Reply to: