Debian splits its archive into main, contrib and non-free (and, on recent releases, non-free-firmware). What distinguishes these areas, and why does the split matter to a company deciding whether it can redistribute a Debian-based system?
answer
- it is a licence boundary, not a quality one
- one area is Debian; the rest are carried
- free program, unfree dependency
- hardware blobs got their own area
- outside the core, licences differ per package
basics
~20 sOnly main is Debian proper: everything in it meets the Debian Free Software Guidelines and depends on nothing outside main. contrib holds free software that needs non-free components; non-free holds software failing the guidelines; non-free-firmware carves hardware firmware out of non-free. Redistribution terms differ per area.
solid answer
~50 sThe split is a licensing boundary, not a quality one. **main** contains only packages that satisfy the Debian Free Software Guidelines and that depend on nothing outside main — this is what Debian actually claims as the Debian system, and it is the part you can redistribute under uniform, well-understood terms. **contrib** is itself DFSG-free but depends on something that is not: a package that downloads a proprietary blob, or a free front end for a proprietary engine. **non-free** contains packages whose own licences fail the guidelines — redistribution rights there vary per package and must be checked individually. Debian 12 introduced **non-free-firmware** so that hardware-enabling firmware could be shipped on installation media without dragging in the rest of non-free. The procurement consequence is direct: if you build an appliance image or ship a derived product, packages outside main require a per-package licence review, and Debian's own support commitments are strongest for main.
code
bash · 7 lines# Enable every archive area for Debian 12 (bookworm)
echo 'deb http://deb.debian.org/debian bookworm main contrib non-free non-free-firmware' \
| sudo tee /etc/apt/sources.list.d/all-areas.list
sudo apt-get update
# Inventory anything installed from outside main
dpkg-query -W -f='${Package} ${Section}\n' | grep -E ' (contrib|non-free)'go deeper
Be able to say that main is free software Debian fully supports, that non-free is not free software, and that these are separate archive areas you must enable explicitly in your sources.
Draw the line precisely: contrib is DFSG-free software that depends on something non-free, while non-free is software whose own licence fails the guidelines. Mention that firmware got its own area in Debian 12.
Show you can inventory what a machine actually has outside main and explain why the boundary matters for images you redistribute, including that security handling outside main is best-effort.
Own it as a policy question: define which areas your organisation's images may enable, why firmware is normally the accepted exception, and how the per-package licence review outside main is tracked and kept current as the fleet changes.
## Where the split comes from Debian's Social Contract states which software the project considers part of Debian, and the **Debian Free Software Guidelines (DFSG)** are the licence test it applies. The DFSG require, among other things, free redistribution, availability of source, permission to modify and to distribute modified works, and no discrimination against persons, groups or fields of endeavour — including no clause forbidding commercial use. Licences are assessed against that list, and the result places a package into an archive *area*. ## The areas - **main** — the package's own licence satisfies the DFSG **and** it does not require anything outside main to build or run. This is Debian. When the project says a release contains a given number of packages, it means main. - **contrib** — the package itself is DFSG-free, but it depends on something that is not. Typical shapes: a free installer that fetches a proprietary binary at runtime, a free client for a proprietary service, or a free game engine that needs non-redistributable data files. - **non-free** — the package's own licence fails the DFSG. Common reasons are restrictions on modification, on commercial use, or on redistribution of modified versions. Debian carries these on its mirrors as a service to users, but they are explicitly not part of Debian. - **non-free-firmware** — introduced with Debian 12 (bookworm). Device firmware blobs, which are not DFSG-free but are required to make ordinary hardware such as wireless adapters work at all, were separated out of non-free into their own area so that the official installer could include them by default without enabling the whole of non-free. A useful way to remember contrib versus non-free: the question is about *this package's licence*, and contrib is the case where this package is fine but its world is not. ## How to tell what you have Each area is enabled explicitly in a sources entry — the words after the suite name are the areas: ``` deb http://deb.debian.org/debian bookworm main contrib non-free non-free-firmware ``` A machine that lists only `main` cannot install anything from the other areas at all. On an installed system, a package's `Section` field is prefixed with the area for anything outside main (for example `non-free/net`), so an inventory of what you actually have is a query away rather than a guess. ## Why this is a procurement question, not a philosophy question The distinction turns concrete the moment you stop being an end user and start being a distributor — building an appliance image, an installable product, a customer-shipped virtual machine, or a base image handed to another organisation: - **Redistribution rights are uniform in main and per-package outside it.** Everything in main may be redistributed on the same broad terms. In non-free, one package may permit unlimited redistribution, another may forbid charging for it, another may forbid modification. "We ship Debian" is a statement you can defend for main and a statement you must audit per package outside it. - **Support commitments are strongest for main.** Debian's guarantees are written about the Debian system, and packages carried outside main do not attract the same commitment — security handling for non-free is best-effort and depends heavily on what upstream provides, since the project often cannot patch the source itself. - **Firmware is the one nearly everybody actually needs.** Refusing non-free entirely is a defensible policy right up to the point where a laptop's wireless or a server's network adapter does not come up. The bookworm-era separation exists precisely so that an organisation can take firmware without adopting the rest of non-free — a much easier policy to write and to enforce. - **Auditability is the real deliverable.** The value of the split to a legal or procurement team is that the boundary is machine-readable. You can state which areas your build enables, enumerate every installed package outside main, and attach the licence review to that short list, rather than reviewing thousands of packages. ## The answer that lands in an interview Say that main is the DFSG-clean, self-contained core and the only part Debian calls Debian; that contrib is free-but-dependent; that non-free is not free and needs per-package licence review; that firmware was split out in Debian 12 so installation media could be practical; and then say what it *costs you*: everything outside main is a package your organisation, not the project, has to justify redistributing.
- Give a concrete example of why a package lands in contrib rather than non-free.A package whose own source is entirely under a free licence but which cannot function without a proprietary component — a free installer or wrapper that downloads a vendor's binary at run time, or a free front end whose backend engine is not redistributable. The packaging and code pass the DFSG, so it is not non-free; it cannot satisfy the "depends on nothing outside main" rule, so it is not main either.
- Why did Debian create a separate non-free-firmware area instead of leaving firmware in non-free?Because firmware is the one non-free category ordinary hardware genuinely requires, and forcing users to enable all of non-free to get a working network adapter was both impractical and a much broader policy concession than intended. Separating it, from Debian 12 onward, let the official installer include firmware by default while leaving the rest of non-free opt-in, so an organisation can accept firmware without accepting everything else.
saying these in an interview costs you the question
- Thinks contrib means packages contributed by outside users
- Says the areas rank packages by quality or maturity
- Assumes non-free is hosted by third parties, not Debian
- Believes non-free is enabled by default on every install
- Treats redistribution terms as uniform across all areas