5 ms·
LLVM AI tool policy: human in the loop
- whatever1 9mo agoThe code writers increased exponentially overnight. The number of reviewers is constant (slightly reduced due to layoffs).
- rvz 9mo agoAnd so did the slop.
- EdwardDiego 9mo agoGood policy.
- hsuduebc2 9mo agoContributors should never find themselves in the position of saying “I don’t know, an LLM did it” I would never have thought that someone could actually write this.
- clayhacks 9mo agoI’ve seen a bunch of my colleagues say this when I ask about the code they’ve submitted for review. Incredibly frustrating, but likely to become more common
- jfreds 9mo agoI get this at work, frequently. “Oh, cursor wrote that.” If it made it into your pull request, YOU wrote it, and it it’ll be part of your performance review. Cursor doesn’t have a performance review. Simple as
- imron 9mo agoSee this thread from a while back: https://news.ycombinator.com/item?id=46039274 https://news.ycombinator.com/item?id=46039274
- scuff3d 9mo agoIt's depressing this has to be spelled out. You'd think people would be smart enough not to harass maintainers with shit they don't understand.
- ActionHank 9mo agoPeople who are smart enough to think that far ahead are also smart enough not to fall into the “ai can do all jobs perfectly all the time and just need my divine guidance” trap.
- deleted 9mo ago[deleted]
- dvrp 9mo agoNot if they're not programmers!
- georgeburdell 9mo agoIt’s happening a lot with me at work. I am a programmer working largely with a hardware team and now they’re contributing large changes that I’m supposed to just roll with the punches. Management loves it
- 0xpgm 9mo agoI think it's part of the "AI replacing software developers" hype. Many beginners or aspiring developers swallow this whole and simply point an AI to a problem and submit the generated slop to maintainers.
- bakugo 9mo agoPeople who rely on a computer algorithm to literally think for them are not going to be very smart.
- deleted 9mo ago[deleted]
- 29athrowaway 9mo agoThen the vibe coder will ask an LLM to answer questions about the contribution.
- lifthrasiir 9mo agoAt least that's much better than not being able to answer them. If LLMs are truly intelligent enough to justify their contributions (including copyrights!), why should we treat them differently from human contributions?
- wmf 9mo agoThat would also include humans not taking credit for AI's work.
- ronsor 9mo agoI don't know how it is for you, but I find it rather easy to tell when someone doesn't actually understand what they're talking about.
- jfreds 9mo ago> automated review tools that publish comments without human review are not allowed This seems like a curious choice. At my company we have both Gemini and cursor (I’m not sure which model under the hood on that) review agents available. Both frequently raise legitimate points. Im sure they’re abusable, I just haven’t seen it
- bandrami 9mo agoAn LLM is a plausibility engine. That can't be the final step of any workflow.
- justatdotin 9mo agoone reason i can imagine for this choice is that human review distributes new knowledge among human maintainers. Automated review might discourage that valuable interaction. The comment is an artefact of an inherently valuable process, not the sole objective. So I'd prefer code is reviewed by a human who maybe initiates a discussion with an agent. I'd hope this minor workflow detail encourages the human to take a more active lead, rather than risk mere ceremonial approval.
- SunlitCat 9mo agoThe policy isn’t about whether those tools raise good points. It’s about not letting agents act autonomously in project spaces. Human reviewed, opt in use is explicitly allowed.
- zeroonetwothree 9mo agoI only wish my workplace had the same policy. I’m so tired of reviewing slop where the submitter has no idea what it’s even for.
- ivraatiems 9mo agoFor what it's worth, this is essentially the policy my current and most recent previous workplace followed. (My employers before that were pre-LLMs.) If you are the one with your name on the PR, it's your code and you have to understand it. If you don't understand it at least well enough to speak intelligently about it, you aren't ready to submit it for review. If you ask Copilot, Cursor, or whatever to generate a PR for you, it still must be reviewed and approved by you and another engineer who acts as your reviewer. I haven't heard a lot of pushback on this; it feels like common sense to me. It's effectively the same rules we'd use if somebody who wasn't an engineer wanted to submit code; they'd need to go through an engineer to do it. LLM usage has increased our throughput and the quality of our code thus far, but without these rules (and people following the spirit of them, being bought in to their importance), I really don't think it would. I encourage you to raise this policy with your management, if you think you can get them to listen, and demonstrate how it might help. I would be very frustrated if my colleagues were submitting AI-generated code without thinking it through.
- vjay15 9mo agoIt is insane that this is happening in one of the most essential piece of software. This is a much needed step to decrease the increase of slop contribution. It's more work for the maintainer to review all this mess.
- Negitivefrags 9mo agoAt my company I just tell people “You have to stand behind your work” And in practice that means that I won’t take “The AI did it” as an excuse. You have to stand behind the work you did even if you used AI to help. I neither tell people to use AI, nor tell them not to use it, and in practice people have not been using AI much for whatever that is worth.
- bitwize 9mo agoThe smartest and most sensible response. I'm dreading the day the hammer falls and there will be AI-use metrics implemented for all developers at my job.
- locusofself 9mo agoIt's already happened at some very big tech companies
- skeeter2020 9mo agoOne of the reasons I left a senior management position at my previous 500-person shop was that this was being done, but not even accurately. Copilot usage via the IDE wasn't being tracked; just the various other usage paths. It doesn't take long for shitty small companies to copy the shitty policies and procedures of successful big companies. It seems even intelligent executives can't get correlation and causation right.
- darth_avocado 9mo ago> At my company I just tell people “You have to stand behind your work” Since when has that not been the bare minimum. Even before AI existed, and even if you did not work in programming at all, you sort of have to do that as a bare minimum. Even if you use a toaster and your company guidelines suggest you toast every sandwich for 20 seconds, if following every step as per training results in a lump of charcoal for bread, you can’t serve it up to the customer. At the end of the day, you make the sandwich, you’re responsible for making it correctly. Using AI as a scapegoat for sloppy and lazy work needs to be unacceptable.
- looneysquash 9mo agoLooks like a good policy to me. One thing I didn't like was the copy/paste response for violations. It makes sense to have one. Just the text they propose uses what I'd call insider terms, and also terms that sort of put down the contributor. And while that might be appropriate at the next level of escalation, the first level stock text should be easier for the outside contributor to understand, and should better explain the next steps for the contributor to take.
- yxhuvud 9mo agoThe new policy looks very reasonable and fair. Unfortunately I'd be surprised if the bad apples will read the policy before spamming their "help".
- mmsc 9mo agoThis AI usage is like a turbo-charger for the Dunning–Kruger effect, and we will see these policies crop up more and more, as technical people become more and more harassed and burnt out by AI slop. I also recently wrote a similar policy[0] for my fork of a codebase. I had to write this because the original developer took the AI pill, and starting committing totally broken code that was fulled of bugs, and doubled down when asked about it [1]. On an analysis level, I recently commented[2] that "Non-coders using AI to program are effectively non-technical people, equipped with the over-confidence of technical people. Proper training would turn those people into coders that are technical people. Traditional training techniques and material cannot work, as they are targeted and created with technical people in mind." But what's more, we're also seeing programmers use AI creating slop. They're effectively technical people equipped with their initial over-confidence, highly inflated by a sense of effortless capability. Before AI, developers were once (sometimes) forced to pause, investigate, and understand, and now it's just easier and more natural to simply assume they grasp far more than they actually do, because @grok told them this is true. [0]: https://gixy.io/contributing/#ai-llm-tooling-usage-policy https://gixy.io/contributing/#ai-llm-tooling-usage-policy [1]: https://joshua.hu/gixy-ng-new-version-gixy-updated-checks#quality-degradation https://joshua.hu/gixy-ng-new-version-gixy-updated-checks#qu... [2]: https://joshua.hu/ai-slop-story-nginx-leaking-dns-chatgpt#final-thoughts https://joshua.hu/ai-slop-story-nginx-leaking-dns-chatgpt#fi...
- mmsc 9mo agofwiw, the tool is `gixy`, now called `gixy-next`: https://github.com/megamansec/gixy-next https://github.com/megamansec/gixy-next
- jonas21 9mo agoThe title should be changed to "LLVM AI tool policy: human in the loop". At the moment it's "We don't need more contributors who aren't programmers to contribute code," which is from a reply and isn't representative of the original post. The HN guidelines say: please use the original title, unless it is misleading or linkbait; don't editorialize.
- SunlitCat 9mo agoAdditionally, it comes across as pretty hostile toward new contributors, which isn’t the intent of the article at all.
- atoav 9mo agoI'll say it as it is: if you can't read code, but have a friend write it for you, you are in fact the wrong person to submit it, since you are the most exhausting person to deal with. A human in the loop that doesn't understand what is going on but still pushes isn't only useless, but actively harmful.
- octoberfranklin 9mo agoI'd like to know why the title hasn't been fixed.
- pertymcpert 9mo agoMy original link was to a comment in this thread which I quoted that from. The link's now been changed to the main thread.
- fmajid 9mo agoSeconded, the original title ("We don't need more contributors who aren't programmers to contribute code") caricatured what seems like an eminently measured and sensible policy change.
- jdlyga 9mo agoAs a a developer, you're not only responsible for contributing code. But verifying that it works. I've seen this practice be put in place on other teams, not just with LLM's, but with devs who contribute bugfixes without understanding the problem
- willtemperley 9mo agoYou also have a second responsibility with LLM generated code you publish: it must not be copyrighted.
- dcow 9mo agoHow is this different from any other code you publish?
- grayhatter 9mo agoit's not, but stupid people assume they own the copyright to ai induced code. So it still has to be said so the people who don't understand have a chance.
- colesantiago 9mo ago"Vibe coding" (i.e. the kind of code that is statistically 'plausible' that sometimes works and the user doesn't look at the code but tries it to see if it works to their liking (with no tests) ) Was the worst thing to happen to programming, computer science I have seen, good for prototypes but not production software, and especially for important projects like LLVM. It is good to gatekeep this slop from LLVM before it gets out of control.
- cookiengineer 9mo agoI think it's great that this AI slop fatigue happened so quickly. Now we can still identify them easily, and I am maintaining bookmarks of non slop codebases, so that I know which software to avoid. I encourage everyone to do the same because the slopcode fallout will be inevitable, and likely be the most harmful thing that ever happened to open source as a philosophy. We need to change our methodology of how to develop verifiable and specdriven software, because TDD isn't good enough to catch this. Something that is able to verify logical conclusions and implications (aka branches) and not only methods and their types/signatures.
- RodgerTheGreat 9mo agoNot just codebases, but developers too. Keep your eyes open: if someone visibly embraces slop, you know they're a clown. Don't let clowns touch your repos, and do your best to cut out dependencies on anything maintained by clowns.
- ares623 9mo agoI don't have enough snark in me (yet) to make a "proud to be AI" list to make such lookups easier.
- InvertedRhodium 9mo agoPersonally, I’ve got fatigue at the phrase “AI slop”. It’s used as a catch all to dismiss the content due to the source, regardless of the quality or suitability when taken in context. Just like everything else these days the responses skew towards both extremes on the spectrum and people hand waving away the advancements is just as annoying as those who are zealots on the other end.
- fleroviumna 9mo ago[dead]
- mberning 9mo agoI am so exhausted by reviewing the AI slop from other “developers”. For a while I was trying to be a good sport and point out where it was just wrong or doing things that were unnecessary or inefficient. I’m at the point of telling people to not bother using an AI. I don’t have the time or energy to deal with it. It’s like a missile defense system that costs a million dollars to intercept but the incoming projectile cost $10 for your adversary. It’s not sustainable.
- rvz 9mo agoOpen source projects like LLVM need to do this as it is one of those projects that is widely used in the software supply chain, on the level that needs protection from contributors who do not understand the code they are writing or cannot defend their changes. There needs to be a label which designates such open source projects that is so important and adopted throughout the industry that not anyone can throw patches to it without understanding what it does, and why they need it.
- octoberfranklin 9mo agoThis is why gcc and linux use mailing lists instead of github pull requests. In the gcc/linux flow, convincing the rest of the mailing list to not ignore their message is the submitter's job. In the github flow, keeping the "unresolved PR count" (displayed right beneath your project's title) low is the developers' job.
- skydhash 9mo agoAnd I think in mailing lists. it’s quite rude to send a patch without a rationale why the change is necessary.
- willtemperley 9mo agoTheir copyright clause reflects my own quandry about LLM usage: I am responsible for ensuring copyright has not been violated with LLM generated code I publish. However, proving the negative, i.e. the code is not copyrighted is almost impossible. I have experienced this - Claude came up with an almost perfect solution to a tricky problem, ten lines to do what I've seen done in multiple KLOC, and I later found the almost identical solution in copyrighted material.
- foxglacier 9mo agoCopyright is for creative work so if it really is the best way to do it, you should be safe even if the AI copied the idea from somebody else. You can't use copyright to restrict access to useful technology like a patent.
- deleted 9mo ago[deleted]
- deleted 9mo ago[deleted]
- willtemperley 9mo agoThat's very useful feedback. I suspect if the solution is irreducible it's OK, which in this case is close to true (this is for bit-unpacking integers): // bytes are added to the buffer until a value of bitwidth is available for _ in 0..<bitWidth { let byte = try UInt8(parsing: &input) buffer |= UInt64(byte) << bitsInBuffer bitsInBuffer += 8 // Values of bitwidth are right-shifted off the buffer. while bitsInBuffer >= bitWidth && outPos < numValues { let value = Int(buffer & mask) out[outPos + outOffset] = value outPos += 1 buffer >>= bitWidth bitsInBuffer -= bitWidth } }
- grayhatter 9mo ago> That's very useful feedback it's also nonsense, so be careful how you try to apply said feedback
- SunlitCat 9mo agoOh wow. That something like this is necessary is kind of sad. At first (while reading the title), I thought they just didn’t want AI-generated contributions at all (which would be understandable as well). But all they are actually asking for is that one understands (and label) the contributions they submit, regardless of whether those are AI-generated, their own work, or maybe even written by a cat (okay, that last one was added by me ;). Reading through the (first few) comments and seeing people defending the use of pure AI tools is really disheartening. I mean, they’re not asking for much just that one reviews and understands what the AI produced for them.
- bryanhogan 9mo agoI feel like the title should definitely be changed. Requiring people who contribute to "able to answer questions about their work during review." is definitely reasonable. The current title of "We don't need more contributors who aren't programmers to contribute code" is an entirely different discussion.
- atoav 9mo agoIs it tho? If you don't speak Hungarian and you have a Hungarian friend write a text for you that you submit to a collection of worthy Hungarian poetry, do you really think you are the correct person to answer questions about the text that was written? You know what is supposed to be in it, but that's it. You can't judge the quality of the text and how it is fitting the rest at all. You can only trust your friend. And it is okay if you do, just don't pull others into it. IMO it is extremely rude to even try to pull this off and if you do, shame on you for wasting peoples time.
- porksoda 9mo agoIts everywhere. I worked with a micro-manager CTO who farmed code review out to claude, which of course, when instructed to find issues with my code, did so. With little icons of rocket ships and such.
- itissid 9mo agoOne (narrow) circumstance to make the process of reviewing a large contribution — with significant aid from LLM — easier to review is to jump on a call with the reviewer, explain what the change is, and answer their questions on why is it necessary and what it brings to the table. This first pass is useful for a few reasons: 1. It shifts the cognitive load from the reviewer to the author because now the author has to do an elevator pitch and this can work sort of like a "rubber duck" where one would likely have to think about these questions up front. 2. In my experience this is a much faster to do this than a lonesome review with no live input from the author on the many choices they made. First pass and have a reviewer give a go/no-go with optional comments on design/code quality etc.
- utopiah 9mo ago> jump on a call with the reviewer Have you ever done that with new contributors to open source projects? Typically things tend to be asynchronous but maybe it's a practice I've just not encountered in such context.
- itissid 9mo agoI've done that in contributions to unknown people's repo but not necessarily open source ones. I believe that this is quite under valued for the reasons I listed. In addition, 1:1 contact can speed up things immensely in such situations because most activity on a change happens very soon after the first change is made and that initial voluminous back and forth can be faster than typing to have a back and forth on github for a PR.
- deleted 9mo ago[deleted]
- 578_Observer 9mo agoAs a loan officer, I like this policy. We use plenty of models to calculate credit risk, but we never let the model sign the contract. An algorithm can't go to court, and it can't apologize to a bankrupt family. "Human in the Loop" isn't just about code quality. It's about liability. If production breaks, we need to know exactly which human put their reputation on the line to merge it. Accountability is still the one thing you can't automate.
- schwede 9mo agoThis account seems like LLM slop looking at the post history. Who starts every post ‘from Japan’? I don’t want to interact with hidden chat bots on HN. The irony of this comment about accountability is also frustrating.
- sadeshmukh 9mo agoThey have a post describing themselves as not a programmer, and one as "as engineers". It's got all the hallmarks (lists, "not just but", bolding when you can't). But what really got me was this conversation literally about why they're not AI! It's insanity, and now I'm convinced it's at least a few accounts in tandem, if not more. Someone else, please, scroll through the account, then read this thread and tell me I'm not crazy: https://news.ycombinator.com/item?id=46439821 https://news.ycombinator.com/item?id=46439821
- dcow 9mo agoThis sub thread really doesn’t add value to the discussion IMO and isn’t a fit for HN. The only likely outcome is a real human is attacked based on pure speculation. Let the mods decide if a user is breaking any policy regarding AI comment submissions. Litigating it here is cringe.
- ifwinterco 9mo agoI would go even further and say AI witch hunts aren't productive, period. In this case where the person writing is ostensibly writing in a second language it's even more silly
- librasteve 9mo agoGood idea. I have just proposed that Raku adopts this policy for core and module submissions https://github.com/Raku/problem-solving/issues/510 https://github.com/Raku/problem-solving/issues/510
- panstromek 9mo agoI like this, especially because it focuses on the actual problem these contributioms cause, not the AI tools themselves. I especially like the term "extractive contribution." That captures the issue very well and covers even non-AI instances of the problem which were already present before LLMs. Making reviewer friendly contributions is a skill on its own and makes a big difference.
- bgwalter 9mo agoIt is insane how pro-industry people argue with corpspeak and LLMspeak and are still getting serious responses. This is where open source discussions have arrived now, and no one dares to tell them to STFU because of their corporate sponsors: "To critique the fortress is not enough. We must offer a blueprint for a better structure: a harbor. A harbor, unlike a fortress, does not have a simple binary function of letting things in or keeping them out. It is an active, intelligent system with channels, docks, workshops, and expert pilots, all designed to guide valuable cargo safely to shore, no matter the state of the vessel that carries it. This is the model we must adopt for open source in a post-AI world. The anxiety over “extractive” contributions is real, but the solution is not a higher wall; it is a smarter intake process."
- wccrawford 9mo agoI 100% think that every programmer is responsible for the code they submit for PR, whether they used AI or not. Whether they used Google/StackExchange/etc or not. They are responsible for it. However, here's a different situation: If the company you're working for requires you to use LLMs to code, I think it's 100% defensible to say "Oh, the AI did that" when there's a problem because the company required its usage. You would have done it better if the company hadn't forced you to cut corners.
- grayhatter 9mo ago> You would have done it better if the company hadn't forced you to cut corners. I assume (hope to god) you're being hyperbolic, but I feel it important to point out to everyone who doesn't get it. This is just the CS version of "just following orders". And deserves the exact same amount of respect and fairness.
- wccrawford 9mo agoThe company can't be mad that they both require me to use AI to save time and that I do it. Cleaning up after AI can easily take longer than it takes to just it right the first time myself. I'm not saying that this is going to be a daily occurrence, and I do find that AI is great at speeding up some tasks. But it absolutely will cause errors. If they expect it to save time, they're going to have to accept an increased error rate. Especially of hard-to-find/predict/test bugs. If they don't require it, and I use it to lower my workload, then it's on me, not them.
- jasonm23 9mo agoI remember a 2019 "initiative" at a fairly large international insurance corporation: "Everyone should code" This led to a flood of projects trying to get pitched to software, and it also crashed headlong into COVID / furloughs. That entire C-suite team have been churned, that's how good that idea was.