10 ms·
RFC: Banning "AI"-backed (LLM/GPT/whatever) contributions to Gentoo
- BlueTemplar 2y agoIn completely unrelated news (/s), supposedly Microsoft is silently (?) installing Copilot on Windows Server 2022 systems ?
- apienx 2y agoNo, thank you. "The goal of Gentoo is to design tools and systems that allow a user to do that work as pleasantly and efficiently as possible, as they see fit." https://www.gentoo.org/get-started/philosophy/ https://www.gentoo.org/get-started/philosophy/ And this is what Torvalds had to say about LLM-enhanced submissions to the kernel. https://www.youtube.com/watch?v=w7-gJicosyA https://www.youtube.com/watch?v=w7-gJicosyA
- gritzko 2y agoTorvalds is cautiously optimistic, hopes that AI will be able to spot bugs in the code. That kind of AI I did not see yet. All the concerning issues from the Gentoo post I can see on a regular basis. For example, plausibly looking BS or AI spam. It is all delivered to my doorstep, so to say. That is the issue.
- ctrw 2y agoI have llm very patiently explain to me why I crashed prod when I used the wrong conversion factor between ms and mus and us. Thanks SI very cool that one of the more often used units needs unicode to be entered into code. Llm are absolutely helping with catching buts and code quality already.
- megous 2y agoI had LLM patiently show me use after free bugs in non-existent Asterisk C code it just made up. :D
- Suzuran 2y agoObviously that's your fault for not having the code it found the bugs in. Why are you attacking progress?
- nonrandomstring 2y ago> Why are you attacking progress? Progress to where? One should not use "progress" as an unqualified noun to denote a scalar. Progress is a vector, with both magnitude and direction. The direction part is really important.
- megous 2y ago:DDD
- deleted 2y ago[deleted]
- Tooster 2y agoSomeone committing poor quality LLM generated code and deeming it appropriate for review could create equally bad, if not worse, handwritten code. By extension, anyone who merges poor quality LLM code could merge equally poorly handwritten code. So ultimately it's up to their judgement and about the trust in the contribution process. If poor quality code ended up in the product, then it's the process that failed. Just because someone can hit you with a stick doesn't mean we should cut down the trees — we should educate people to stop hitting others with sticks instead. "Banning LLM content" is in my opinion an effort spent on the wrong thing. If you want to ensure the quality of the code, you should focus on ensuring the code review and merge process is more thorough in filtering out subpar contributions effectively, instead of wasting time on trying to enforce unenforceable policies. They only give a false sense of trust and security. Would "[x] I solemnly swear I didn't use AI" checkbox give anything more than a false sense of security? Cheaters gonna cheat, and trusting them would be naive, politely said... Spam... yeah, that is a valid concern, but it's also something that should be solved on organizational level.
- larodi 2y agoWell, Torvalds says in the interview ‘we already have tools such as linters and compilers which speed up the work we do as part of software development’ I get the impression he agrees this road to LLM content is inevitable, but also kind of emphasises the role of the reviewer who takes the final decision.
- Nullabillity 2y agoCheaters are gonna cheat, but filtering out the honest/shameless LLM fans is still an improvement. And once you do find out that they lied, you now have a good reason to ban them. Win/win.
- lemagedurage 2y agoChatGPT3.5 already spots bugs, e.g. when I swap the order of conditions in fizzbuzz. An error that a human could make. We've been at the point where AI can help spot bugs for a while already. AI can be used poorly, AI can be used well.
- bayindirh 2y agoAnother problem is how we arrive to a model that can be used poorly or well. There's huge copyright and ethical problems underneath every big model, and I refuse to use models which are trained with copyrighted materials, without consent. Gentoo is right here, and until we pass these hurdles, I don't use any of these systems, even with a 100 feet pole.
- hobs 2y agoOk, now ask it how many Ms are in ammunition. Just because it can do somethings some of the time doesn't mean we'd happily accept contributions from it.
- Philpax 2y ago1) It does not need to solve every issue to be useful; it just needs to surface some issue that a human reviewer can then validate. It's seen a lot of code; it can find common issues. 2) The specific issue you're talking about is because they don't see letters, they see tokens, which are groups of letters / subwords. It can't count those because it can't actually "see" what it's counting. This is being worked on as well.
- keybored 2y agoWhat does their philosophy for the end-user have to do with their development practices?
- speed_spread 2y agoI haven't used Gentoo in a while but if I went back to it and had to manipulate ebuilds, LLMs would absolutely be involved. Even if it was enforceable, a no-LLM policy would deprive infrequent contributors from using one of the most powerful coding tools we've invented. It would be as inane as banning man pages or syntax highlighting. While I understand the goal of high quality input, the net result would just be gatekeep the process to experienced contributors and be detrimental to the project in the long run. LLMs are here to stay and are way too useful to be ruled out.
- t-sauer 2y agoBut DeepL is fine apparently (as it should be in my opinion) so I guess this is going to be a random dice roll what maintainers will allow or not. I can understand the sentiment behind this proposal, but it is way too nuanced and complicated to just solve it with a few basic rules.
- moooo99 2y agoI am confused, how is a translator comparable to an LLM that primarily serves as a generator? Just because it’s powered by some neural network behind the scenes?
- t-sauer 2y agoThat's precisely my point. What does "AI-backed" mean exactly? The RFC doesn't ban LLM, but "AI-backed" contributions. Technically from my understanding and interpretation DeepL would fall under that category and would be banned from being used but in the linked thread people seem to agree that DeepL usage is fine. So where do you draw the line? How do you define which "AI-backed" contributions are still fine and which aren't. Eventually different contributors will have different opinions and it will get messy.
- moooo99 2y agoAt this points it’s just playing word games imho. The RFC specifically mentions tools like Bard, ChatGPT and Co-Pilot as what it considers to be ban-worthy. If I’m going to be extremely pedantic about it: with Co-Pilot, the a actual contents of the contribution are AI generated. With a translator like DeepL, the contents are authored by the contributor, the translation tool just translations what’s already there
- exitb 2y agoIt's similar in that regard that it might be wrong sometimes. It's also similar, as coding LLM may be used to translate code between languages.
- GaggiX 2y ago
- rubymamis 2y agoWhy don't evaluate contributions based on how well the code/documentation is written? What does it matter who wrote it, if it's good? Assuming no spamming by bots.
- somenameforme 2y agoSame reason LLMs aren't so great for regular usage. They do an excellent job of creating highly plausible looking nonsense, which makes it much more likely for things to slip through the cracks. If there was some sort of magical way to ensure code being submitted was flawless, then we'd no longer have bugs in anything, let alone the endless critical flaws that appear in pretty much everything. For a large highly visible open source project, there's also probably intellectual property concerns. LLMs are being trained wholesale on code that's under IP protections (be that copyright or otherwise) and having that end up in your code base could land you in trouble. 'The AI did it' will probably not be seen as a viable defense.
- rubymamis 2y agoCurrent LLMs. While I agree, they sometimes create more problems than solving (I'm currently debugging a bug caused by GPT4 code that I initially approved), they are getting better by the day and already 1.5x my productivity.
- passwordoops 2y agoThat's an oddly specific, very round number. You have metrics for it, or is this the same math being used to declare AGI is a year away?
- rubymamis 2y agoNo scientific at all, but I keep a long to-do list for my current project with dates, and it *feels* like LLMs have allowed me to cut a third of development time.
- constantcrying 2y agoThis seems insane and totally unenforceable. Even when I wrote very single line of code myself, I use AI to ask it about questions regarding the programming language or the library that I use. Banning that is just handicapping yourself. I do like the sentiment. You absolutely do not want people to commit code they don't understand themselves, but the solution isn't to outright ban AI. The solution is to have trusted, knowledgeable developers who are aware of the limits of AI and use it appropriately.
- mattsan 2y agoIt should just be banning the use of AI in code reviews
- constantcrying 2y agoI don't see what you would even do with an LLM in a code review.
- mannykannot 2y agoThe positive view: generate scenarios in which the code will fail. The negative view: write plausible-seeming explanations justifying the code as correct.
- mattsan 2y agoyep this is what I meant. hallucinating, justifying or missing bad stuff. additionally, similar to how large PRs are more likely to just be skimmed and replied with a "LGTM!", an LLM missing some bad stuff but still producing a seemingly thorough review would increase the chance of the bad stuff making its way in. allowing LLMs to write code would be fine if its truly verified by a human, but let another LLM hallucinate and cloud a persons judgement and you've got a problem
- kragen 2y agoi thought i'd find out, so i picked a quasirandom piece of my own code (http://canonical.org/~kragen/sw/dev3/nonarytbl.py http://canonical.org/~kragen/sw/dev3/nonarytbl.py) and gave it to gpt-4 to review, with the prompt: "Please review the above code. How does it work? Is it well designed? Is it efficient? What are its good points and its bad points? How should it be improved? Is it readable and maintainable?" i feel like gpt-4's code review (included below) was mostly correct and useful. however, the efficiency concerns in particular are unfounded, and the python approach to handling errors like those cited is to just let the exception propagate, suboptimal though that is for usability. also, i'm not sure i agree with its high opinion of the modularity, usability, and readability simply pasting gpt-4's partly incorrect analysis into a textarea when someone asks you for a code review would be malpractice, but it could be a useful source of ideas for possible improvements to suggest and possible problems to investigate. also, i've found it to be especially good at coming up with plausible ways that someone could misunderstand my code, which is to say, ways that my code is unclear and therefore could have its clarity improved overall i'd say that gpt-4 is a lot better at reviewing code than at writing code. i've gotten significant improvements out of its code by asking it to review its own code looking for improvements, then asking it what the code would look like with those improvements. also, having it write test suites, then showing it the results of running the test suites — ⁂ — The provided Python script is designed to generate and print arithmetic tables for balanced nonary (base 9) numbers using a unique set of Unicode glyphs. The script covers operations such as multiplication, maximum, addition, and subtraction. Here's a breakdown of how the code works and an evaluation of its design: ### How It Works: 1. `gen_table` Function: - This function generates a table for a given binary operation (`op`) like multiplication or addition. - It takes an optional `name` parameter for labeling the operation in the table header. - The `values` parameter specifies the range of values to be used in generating the table (default is from -4 to 4). - It constructs each row by applying the operation between all pairs of values. 2. `nonary` Function: - Converts an integer into its balanced nonary representation using specified glyphs. - Handles negative numbers and numbers greater than 8 by recursive calls. 3. `layout` Function: - Formats the table into aligned columns for better readability. 4. `paste` Function: - Combines multiple tables horizontally with spaces between them. 5. Main Execution Block (`if __name__ == '__main__'`): - Generates specific tables for different operations and prints them formatted properly. ### Evaluation: Good Points: - Modularity: Functions like `gen_table`, `nonary`, and `layout` are modular, making specific tasks well encapsulated. - Reusability: The functions can be reused or extended easily; e.g., adding new operations or changing glyph sets. - Readability: Despite some complexity in logic, especially in recursion and formatting, variable names and function names are descriptive which aids understanding. Areas for Improvement: 1. Efficiency Concerns: - Recursion in `nonary`: For large numbers, this could lead to deep recursion levels. - Repeated calculation of widths in `layout`: This could be optimized if performance becomes an issue with larger data sets. 2. Error Handling: - There’s no error handling if invalid inputs are passed to functions like non-existent glyphs or unsupported operations. 3. Documentation & Comments: - While there's a detailed module-level docstring explaining high-level concepts, inline comments explaining complex parts (like recursion in `nonary`) would improve maintainability. - More detailed docstrings on what each function expects as input and what it outputs would help other developers understand their interfaces quickly without diving into code details. 4. Testing & Validation: - Adding unit tests would ensure that changes do not break existing functionality and help validate edge cases like very large/small numbers or unusual sequences of operations. 5. Scalability & Generalization: – Currently tailored specifically to balanced nonary system; generalizing this to handle any base might make it more useful as a tool for exploring other numeral systems. 6. User Interface Improvements: – Providing command-line arguments or interactive prompts could allow users to specify ranges or select specific tables without modifying source code directly. ### Conclusion: The script is well-designed concerning modularity and separation of concerns but lacks robustness due to missing error handling and testing components. Enhancements towards documentation, user interaction, scalability/generalization could significantly increase its utility while maintaining ease-of-use for educational purposes or numerical system explorations.
- connorgutman 2y agoAs a Gentoo cultist… no thanks!
- matheusmoreira 2y agoDefine "use". What kind of uses? Verbatim code sourced from AI or using the technology in general? I've used AI to learn about massive codebases. It's a bit stupid but still extremely helpful. The free ChatGPT was capable of explaining the concepts in the code and the file system structure of the project, allowing me to get started much faster. It sure as hell beats being a help vampire on some IRC channel or mailing list. This technology is literally too good to be banned. We should be working on taking it as far as humanly possible by getting it running locally and completely uncensored.
- johnisgood 2y agoI am pretty sure that you could use AI to re-phrase your own description. Right?
- nicetryguy 2y agoThose concerns seem legit? Surprised at the negativity here.
- JonChesterfield 2y agoHN thinks LLMs are the early days of the singularity and not a spam generator. I assume this is an echo chamber effect.
- chx 2y agoI stand against the tide for sure. I am grievously concerned about the sea temperature being off the charts for a year now and we do not know why. Wasting tremendous amounts of energy to generate bullshit doesn't seem like a prudent action. Yes it's not yet a large chunk of total energy usage but we do need to stop the hype before going further when it'll be. Because as https://hachyderm.io/@inthehands/112006855076082650 https://hachyderm.io/@inthehands/112006855076082650 explains it's good for naught else. > You might be surprised to learn that I actually think LLMs have the potential to be not only fun but genuinely useful. “Show me some bullshit that would be typical in this context” can be a genuinely helpful question to have answered, in code and in natural language — for brainstorming, for seeing common conventions in an unfamiliar context, for having something crappy to react to. > Alas, that does not remotely resemble how people are pitching this technology. And then of course there are all the ethical concerns.
- wilya7 2y agoHow about Christmas lights? Washing machines? TV and video entertainment? Elevators for the first floor? How about for the second floor? Social media posts, like these? The demand for technology leads to advancements that meet our needs. As we continue to innovate, we must focus on consuming more energy rather than less. You are eager to decide what is useful and what is not. Can you predict the future? Can you predict the full impact of technologies? Can you see second, third and forth order effect? Likely not. For instance, many may not have anticipated the significant role smartphones play today. It concerns me when some individuals attempt to control others' resource usage, potentially leading to authoritarian rule driven by fear. Such actions might result in adverse effects before any noticeable climate changes occur in the near future.
- JonChesterfield 2y agoReading through the linked thread at https://github.com/pkgxdev/pantry/issues/5358 https://github.com/pkgxdev/pantry/issues/5358 I'm in total agreement with Gentoo.
- constantcrying 2y agoYes, something like that absolutely should be avoided at all cost. Genuinely in disbelief what I was reading in that thread. How do people think that an autogenerated nonsense description is better than not describing the software at all?
- suprfsat 2y agoHe can't even invert a binary tree on a whiteboard.
- jddj 2y agoFeels like this is just one of many pets.com moments to come
- red-iron-pine 2y agoAI, but for dogs! [still gets $30M in VC funding because of course it does]
- ComplexSystems 2y agoGetting rid of nonsense descriptions is very sensible. Trying to set some kind of policy to prevent that is also sensible. Banning developers from internally using Copilot, a personal tool that is essentially a glorified autocomplete so you don't have to type as much, all because of "copyright infringement," "ethics" and "energy waste" concerns, is dumb. It is unrelated to the problem at hand, unenforceable, bizarrely overreaching, unnecessarily divisive and also dumb and I hate it.
- growfeather 2y ago
- nonrandomstring 2y agoIt's interesting because you can see it as both a very conservative approach and a high risk stance which don't seem like common bedfellows. If you acknowledge up front that AI is unfit for purpose and is very likely to introduce some serious security problems then it seems wise. When it turns out the LLM models have all been compromised to insert backdoors into the compiler toolchain, you win by being the last distro left standing. You could look at it as a very high risk strategy for the same reason, if you think you'll be "left behind". Either way who dares wins (or dies). Dare to go against the mob, or dare to bet the farm on a principle. AFAIK Gentoo is one of the more conservative communities. But I'd also expect to see this policy being considered in BSD circles too.
- vasco 2y ago> In other words, explicitly forbid people from using ChatGPT, Bard, GitHub Copilot, and so on, to create ebuilds, code, documentation, messages, bug reports and so on for use in Gentoo. Maybe a naive question but, how will they know?
- ceejayoz 2y agoI mean, I came across a StackOverflow post the other day with "I apologize for the misunderstanding." in the middle of it. There's a bit of a "intro paragraph, five numbered list items, concluding paragraph" style format that you start to notice pretty quickly.
- speedgoose 2y agoCertainly, but you can prompt the LLM to write following a specific style.
- xniclb 2y agoIt's not about "how". When it is discovered that your submission is AI generated, it is enough reason to discard the submission without having to review it any further. Many open communities do the same.
- Tooster 2y ago"Many communities depend on AI tools to detect and ban AI content" interesting... If not depending on AI tools then depending on a... hunch? So like a modern-era witch hunting?
- mannykannot 2y agoIf the submitter acts as a competent gatekeeper to keep out the crap, no-one will know and neither will they care.
- mminer237 2y agoIf they can already tell easily whether or not a submission is bad, what is the relevance of an AI ban? It will push out good contributors who use AI responsibly, and presumably make zero effect on people just wanting to abuse AI to get a patch into Gentoo. You still have to do the exact same work to tell whether a contribution is good or not.
- jbandela1 2y agoI am not sure what “AI” means but: Yes, yes. It is past time we do it. People are producing plausible sounding bullshit because of ease of just cranking out and iterating code quickly. And we have made it way too easy to incorporate potentially copyrighted other people’s code. As Donald Knuth would know, back when you had to generate punch cards and stand in line to load them on the mainframe, you spent a lot more time carefully designing and logically working through your code, instead of producing massive amounts of plausible bullshit. So yes, I agree. You are talking about banning interactive editors with copy/paste and interactive compilers and debuggers right?
- Draiken 2y agoSeems impossible to enforce, but I applaud the spirit of it. Pretty soon anyone looking to add "open source contributor" to their GH profile can take a Gentoo issue and ask an AI to cook up a solution, put that on a PR, and send it in. This will be a nightmare for maintainers. I'm not sure if there is a solution, since AI usage will spread regardless of how good/accurate it is and there's no way for us to differentiate between plausible bullshit and actual contributions, without reading it carefully. Reputation of contributors is probably the best proxy for genuine contributions, but that's a catch 22, so it can't be the only way.
- madeofpalk 2y agoAs a maintainer of a Very Large open source project, I have not found this to be the case. I have not found that AI/LLM tools have generated noticably more noise. The occasional low-effort PR existed before ChatGPT and Copilot, and it continues to exist after it. 'Banning AI' does not absolve your responsibility to review PRs, nor do I believe does it make your job actually easier. I believe I've noticed only one 'LLM spam' comment on an issue needlessly comparing different Javascript package mangers.
- Draiken 2y agoTo be clear, I don't think this is true right now. But if the technology does improve just a bit further, it will be easy enough to be spammable and it will be abused.
- f321x_ 2y agoBased
- ekidd 2y agoI do write some niche open source projects, ones which: - Have been written with CoPilot enabled in my editor, and - which optionally use GPT 3.5 as a translation API, and - Which use OpenAI's text-to-speech model to generate spoken dialog files for testing. I suppose I can try to mark my projects in a such a way as to inform Gentoo that it's against their policy to package them. Overall, I would guess that my CoPilot-assisted code is slightly worse than code I hand-craft. The biggest difference seems to be that with CoPilot I write fewer tiny functions, and I tend to keep more related code in one place. On the other hand, CoPilot makes writing test code extremely quick. And I'm not talking about generic boilerplate here: CoPilot can write non-trivial parser or type inference code that relies heavily on internal project APIs that do not exist outside my project. Overall, I'd guess that CoPilot allows me to produce twice as much code at 90-95% of the quality. Which since we're talking about open source projects that I maintain in my spare time (and that were painfully over-engineered to begin with), is probably a decent tradeoff.
- layer8 2y agoTFA is not about upstream content, as explicitly mentioned.
- ekidd 2y agoMy takeaway was that they weren't happy about upstreams, but didn't feel like there was anything that could actually be done: > We can't do much about upstream projects using it. As a potential upstream, I could potentially help them by adding some kind of metadata to my package, indicating, "Some portions of this code were written with CoPilot active." And this could allow them to automatically filter out and reject packaging requests from users. (As an open source author, I'm deeply ambivalent about distro packaging anyways. I release my software as pre-built, standalone binaries specifically to avoid the tarpit of distro packaging politics. If my software is packaged for a distro, it will almost always need to go through someone else, who may or may not do a good job, or keep the software up to date, or break the software in a way that creates more support requests for me.)
- 2y ago
- tgsovlerkhgsel 2y agoThe quality concerns are absolutely justified. The complaints about energy use sound like unfounded, extremely far-fetched arguments just used by people who don't like LLMs for other reasons. The inference energy cost is likely on the same order of magnitude as the computer + screen used to read the answer (higher wattage, but much shorter time to generate the response than to formulate the request and read it). The training energy cost is significant only if we ignore that it is used by many people. For GPT-3, I've seen plausible estimates of ~1 GWh, which would equal to about 400 tons of CO2, about as much as a single long-distance plane (total, not per passenger, fuel consumption only) round trip. Estimates for newer models usually ignore the existence and likely use of more efficient accelerators.
- agentultra 2y agoIt’s not completely unfounded. Water consumption skyrocketed while training up the current generation of models [0]. The energy (and water) usage to service requests is not staggering but it is concerning that is uses as much as it does for the output it generates [1] [0] https://futurism.com/critics-microsoft-water-train-ai-drought https://futurism.com/critics-microsoft-water-train-ai-drough... [1] https://www.forbes.com/sites/cindygordon/2024/03/12/chatgpt-and-generative-ai-innovations-are-creating-sustainability-havoc/?sh=d0472193f6d6#:~:text=ChatGPT%20consumes%20over%20half%20a,using%20about%20twenty%2Dnine%20kilowatts https://www.forbes.com/sites/cindygordon/2024/03/12/chatgpt-....
- pantalaimon 2y agoThe energy use of Gentoo is already way above any other distribution as it requires the user to compile all software themselves.
- TheFreim 2y agoHearing complaints about energy consumption from someone using a source-based distribution is quite rich considering they're often wasting much more energy than they need by compiling themselves instead of using a binary distribution.
- GuB-42 2y agoIt looks like a knee-jerk reaction by some "AI" hater rather than a well thought out request. - 7 instances of the word "shit". I don't mind swearing, but it is indicative of the author being maybe a bit too emotional for a technical proposal. - It is unnecessarily broad. Not using AI to create bug reports? What if you use AI tech to find a bug? Are you not allowed to report it? The stated issue here seems to be mostly about code completion, but it is stretched to everything AI-related, everywhere. The point raised are copyright, quality and ethics, which are valid points, but not specific to AI. Copyright: You have the same problem when copy-pasting code, and people do that, you can't really single out AI. Instead of banning AI, a more sensible guideline would be to just be aware of copyright when importing code from elsewhere, including AI generated code, but also copy/pasting from online sources (ex: StackOverflow) and using external libraries. There are tools to check for copyright compliance. Quality: AI-generated code is often lower quality, but so is code written by bad coders, judge by quality of contribution, not by how it is done. As for the "we can't really rely on all our contributors being aware of the risks", maybe start by picking contributors you can rely on. And if you think they may not be aware of the risks, tell them about the risks rather than saying "you can't do that". Ethics: I don't know what Gentoo stands for, but I'm guessing it is mostly about making a good source-based Linux distribution. Don't hijack the project for your own goals. Now, I have no problem with a Linux distribution that has "no AI" as one of its core values, but it doesn't have to be Gentoo.
- rsynnott 2y ago> Not using AI to create bug reports? What if you use AI tech to find a bug? Are you not allowed to report it? I mean, the hot new trend seems to be people reporting completely imaginary bugs that some AI tool thought it saw to projects, so, eh, I can see where they're coming from there.
- pantalaimon 2y ago> The AI bubble is causing huge energy waste. Pretty ironic coming from a distribution that requires every user to compile everything from source.
- emporas 2y agoWhen every program is compiled for a specific architecture, doesn't that enable optimizations otherwise impossible? Of course, two users compiling each program twice for the same architecture is wasteful, but optimizations will save cycles down the line. No?
- epcoa 2y ago> but optimizations will save cycles down the line. No? No. There are not practically enough cycles saved to overcome the often minutes of CPU time to build every update of a large software package. > When every program is compiled for a specific architecture Every binary distribution already "compiles" for a specific architecture. The inane variant "tuning" generally renders miniscule speedups. Even if there is performance to be gained it can be done on a limited case by case basis.
- oefrha 2y ago> In other words, explicitly forbid people from using ChatGPT, Bard, GitHub Copilot, and so on, to create ebuilds, code, documentation, messages, bug reports and so on for use in Gentoo. On the one hand, I’m on the fence about this heavy-handed approach. Tons of people, myself included, use AI assistants to create high quality work in less time. Of course I’m also aware of tons of low quality garbage. On the other hand, I’m all for banning automated submissions which have been on the rise for the past couple of years, which are often thinly veiled (if at all) ads for AI startups. GitHub in particular should allow owners to ban all unsanctioned bots, and report unlabeled bots.
- AtNightWeCode 2y agoI think it is a more general problem. One can't see in GIT what tools have been used to create and validate the code. It is impossible to use most modern devtools completely without AI. I think it is better to regulate the usage and enforce transparency.
- agentultra 2y agoSeems like a reasonable move to me. I’ve seen folks use ChatGPT to generate code and review it for security flaws. It does often solve the tasks. And it leaves behind many kinds of vulnerabilities: injections, overruns, etc. Based on the little empirical evidence we have about informal code review [0], it seems that we ought to limit or outright ban generated code. A Human can only read so much code before their impact on catching errors significantly drops. OSS project maintainers have enough on their plate and we don’t need to exhaust them with trying to maintain AI generated code. [0] https://sail.cs.queensu.ca/data/pdfs/EMSE_AnEmpiricalStudyOfTheImpactOfModernCodeReviewPracticesOnSoftwareQuality.pdf https://sail.cs.queensu.ca/data/pdfs/EMSE_AnEmpiricalStudyOf... Update spelling
- cik 2y agoAbsolutely - though for me it's a personal anecdote. I remember within the first week of ChatGPT becoming generally available, I spent 2 hours crafting a response to a pull request, detailing a "security vulnerability". It didn't matter that this wasn't a vulnerability; it didn't matter that the reporter didn't know of what they were speaking. What mattered was eliminating the time I had that morning, to do meaningful work. Responding to that (and since, several) PRs was not the desired outcome. It also kicked off internal, processes - which in turn added more time. If you think about it, it's an interesting hack at least!
- nl 2y agoI can't say how strongly I disagree with the ethical/copyright concerns raised here. The idea that intelligences - whether they be human, artificial or alien - should be forbidden from learning from code freely shared on the internet goes against everything I like about open source. I think it's fair that no one should be able to use reproduced copyright code verbatim, whether that by by a human memorizing something or a computer copying it. But I take the complete opposite view on the ethics of letting machine learn from work. I think this should be encouraged.
- raxxorraxor 2y agoAgreed. Although it is sometimes difficult to imagine any sensible application of copyright of code in the first place apart from code that for some reason or another contains data. There exist copyrighted algorithms for certain applications, especially for AI application these days, but a reengineering should be possible and similarities should be handled as liberal as possible.
- zdimension 2y ago> learning Therein lies the rub. Most of the discourse and debate around LLMs and copyright revolve around the central question of what it means to learn. Virtually everyone agrees that a human learning from reading code doesn't violate copyright (by somehow copying the knowledge into one's brain), because the human brain is some kind of copyright laundering machine, maybe? I don't really know whether there is any argument for that apart that can't be reduced to an appeal to common sense. On the other hand, a DL algorithm learning from processing tokens of code scraped from public sources such as GitHub doesn't present the same kind of obviousness. My personal belief is that it's also learning and shouldn't be forbidden, but I can't deny the negative consequences of that. We're already seeing a lot of bad things come out of the democratization of GPTs.
- nonrandomstring 2y ago> the human brain is some kind of copyright laundering machine, maybe? I don't really know whether there is any argument for that apart that can't be reduced to an appeal to common sense. Because it's an end not a means. The concept is central in philosophy, law, ethics, education.
- deleted 2y ago[deleted]
- malet 2y agoAll very well, the question is, how will you know? And if you can’t reliably differentiate between ai or human contributions how could this be enforced?
- skissane 2y agoHuman-generated and AI-generated aren’t mutually exclusive categories anyway. For example, a person writing a document (or software package) can start out with some rough human-generated notes, pass them to an AI to flesh out, and then edit the AI’s output to improve it, fix anything the AI got wrong (or even that they just don’t agree with, e.g. “this code is correct but it’s not how I’d write it”) What’s the fundamental difference between that and a human doing it without an AI’s help at all? It could be essentially the same outcome, just more time and human effort
- gritzko 2y agoThe author clarifies that there is no way to detect it. He only wants it explicitly stated in the policy: "don't bring that".
- denton-scratch 2y agoYes, this would be like the Wikipedia policy that uncited material can be deleted at any time.
- kevindamm 2y agoI thought the same at first, but if you look at the discussion page linked at the end, there's an example of some package descriptions that were auto-generated but the result was very inaccurate -- claiming features that aren't even close to what the package offers. Not knowing the contents of the package, you might not notice. And it would definitely trip up any attempt at indexing these descriptions for search. Then a bot responded to the discussion poster's concerns and it was humorous but also it offered no way to resolve the issue. So there are one or two cases where a maintainer might notice something off and this policy would offer a clear-cut way to reject whatever submitted the inaccurate decisions or to take the AI out of the discussion forum. But for the cases of copilot-authored code I don't think there's any reliable way to detect or reject it. This probably falls under their "but not upstream changes" caveat.
- drrlvn 2y agoThis is from February, is there any update or progress?
- cqqxo4zV46cp 2y agoNot to be too snarky, but this is exactly the proposal and associated conversation that I’d expect to see around Gentoo. It is as impractical as it is unnecessarily standoffish. There are multiple repliers that very clearly don’t understand how LLMs work. “It’s computers, so I can intuit it!” is typical techie hubris.
- blueflow 2y agoAI generated contents are just low quality stuff, reviewing them is a huge sink of time. You are better off in terms of manpower/time by banning AI contributors and doing the work yourself.
- andybak 2y agoThere's a vast spectrum of contributions. I use Copilot and most of the time it's just autocomplete with a bit more awareness of context. Like - it suggests the next 10 characters or so it's either correct or correct enough that it saves me some typing. So in the same way that people complain about CGI in movies (if the CGI is good CGI then they probably haven't even noticed it) - the only AI you notice will be the bad stuff.
- BaculumMeumEst 2y agoRFC: Banning contributions written on systems with proprietary software
- gjs278 2y ago[dead]