6/1/2026 at 6:46:54 AM
Hello! I am a Debian Developer, though not likely to work on this as I haven't done a ton of rust binary packaging.I did want to clear up one misconception that you might be having, though. The .deb versions shipped by upstream are great, but they're not really ever going to be useful for Debian. One of the side-effects of Debian's requirements around software freedom is an important principle: you should be able to build any package in Debian with only the things that are in Debian.
The problem with fresh isn't fresh itself -- packaging that isn't particularly difficult, though it does need some amount of care and attention. The problem is that fresh pulls in 732 different crates which all need to be packaged in Debian before fresh can be. Some of them are already in Debian, of course, but... you can imagine that the effort here is very much not insignificant.
Upstream doesn't have to deal with this problem, as they can simply statically build them into the executables. That's a violation of Debian policy, though, and isn't allowed for anything in the archive.
Hope that helps you understand why you may not get many bites at this offer, generous as it is!
by hlieberman
6/1/2026 at 8:28:58 AM
The problem that Debian has with rust packages is that they try to apply handling a C-style dependency chain (usually only a few C libraries with large scope) for the rust crate ecosystem (a lot of dependencies with small scope). Having to maintain 732 just for one release of a new package is not sustainable.I don't understand why the policy is not: pulling all crate sources and prepackaging into a tar with associated licenses. The source tree then is part of the package which can still be built from source and gets linked statically.
by MeltedVoltage
6/1/2026 at 8:00:47 AM
Excellent info thank you. Your explanation makes perfect sense, and leads to the security compliance info that I'm reading.I'm seeking to stop supply chain attacks as described at https://wiki.debian.org/Rust
Could there potentially be a way for a program to include all the source code of all its dependencies, at least for any that aren't on Debian?
by jph