28 ms·
Changing how we develop Ladybird
- therepanic 4mo agoTo be honest, judging by their repository, it doesn't look like they've stopped accepting third-party PRs.
- deleted 4mo ago[deleted]
- jsmailes 4mo agoIt saddens me to see the communities surrounding free software projects going dark because of the threat posed by AI tools, but I don't know what other solutions there are that would mitigate the threat, particularly when browsers are such a compelling target. Perhaps some kind of trust system a la arxiv.org, where existing users have to vouch for new submissions before a user is themselves trusted? Definitely still vulnerable to abuse, but perhaps less so.
- JimBlackwood 4mo agoI think a trust system is the only way. Ladybird will need new/different maintainers at some point in the future. How are you going to find them now? I don’t disagree with their choice, but it’s not sustainable in the long term.
- stuaxo 4mo agoThis is needed for more projects than just ladybird, and I'm sure will be worked out. For now this makes sense.
- MarsIronPI 4mo agoMaybe it is, if they can somehow vet potential new contributors in-person at e.g. conferences.
- dvdkon 4mo agoClosed-source projects have been dealing with this forever, by having a mostly-static pool of employees replenished through job listings and interviews. A FLOSS project adopting this model would certainly feel weird, but could work if there were enough willing candidates. The question is, who will take on effectively a job without the monetary reward?
- samtheDamned 4mo agoMy understanding is that the people working on ladybird are compensated for their full time positions, so I would also expect any future positions to be similar.
- fguerraz 4mo agoI feel like the project just died.
- shevy-java 4mo agoToo early to say. Once they enter "we now accept everyone to use Ladybird as daily driver" then there will be the real test phase. And, IMO, only after that phase has started and continued for some months, perhaps even few years, can a final conclusion be made. If ladybird fails then the Google empire has won permanently. Skynet slop will then be under control of Google, just as they stole all the advertisement money.
- lelanthran 4mo ago> I feel like the project just died. Why? This seems to be a strengthening move, not a weakening one.
- fguerraz 4mo agoMoving to a closed development model => opensource is just a gimmick, especially with a BSD licence.
- lelanthran 4mo ago> Moving to a closed development model => opensource is just a gimmick, How so? Many projects are open source (GPL, MIT, whatever) while closed development, and no one calls those a gimmick. In any case, most open-source is going to move towards a closed-development model; there simply isn't the resources to review thousands of lines of PRs per hour.
- pulsartwin 4mo agoMaybe, or maybe not. But it will certainly kill the community they've built up, and squander a huge amount of goodwill. Why would anybody who's interested in supporting or using an independent browser (read: techies) choose one that nobody can contribute to? Not to mention how the sponsors might feel about this.
- troupo 4mo ago"Gain trust through plausible contributions" is a new angle on AI-produced PRs I haven't seen yet. Though in retrospect we should have seen it. It's been an angle of attack since forever, it only took a lot of effort.
- sppfly 4mo agoZig is moving to this direction is well.
- sourcegrift 4mo ago[flagged]
- asibahi 4mo agoThis can’t be serious.
- lukaslalinsky 4mo agoIndeed, while there is communication that the situation with merging external pull requests should improve, the reality is that it's easier to land a patch in Linux, than in Zig.
- ivanjermakov 4mo agoNow that I think about it, moving away from GitHub surely filtered many low-quality contributions fueled by clout/GH profile reputation.
- kristoff_it 4mo agoThat is the opposite of what's going on, read this https://kristoff.it/blog/contributor-poker-and-ai/ https://kristoff.it/blog/contributor-poker-and-ai/
- bigupthewhole 4mo agoWe need stricter verifications / credentials behind GitHub accounts and PRs. And this we should have had already before AI.
- habinero 4mo agoHow does that help? People gladly post slop PRs under their real names.
- bigupthewhole 4mo agoIt's not the only solution but it might reduce PRs by a decent amount I would think. If you see a PR and the guy is verified, you can check his name, his linkedin and where he works, at least there is some accountability if he introduces malicious code. If the goal is to reduce slop, define slop. As a maintainer of a project you should be able to tell if something is slop. If you don't have time to read PRs (which is the real issue here) that's fine too. My guess is they want to reduce the amount of PRs, and ensure that the quality of the PRs passes an extremely high bar.
- Orphis 4mo agoWhile it would help for some use-cases, it wouldn't necessarily reduce the problem that a browser is facing when dealing with malicious code in a large and complex codebase. And vetted people can be victims of supply-chain attacks, which makes it still hard to evaluate a change properly. It's not an impossible problem, but it's a resource allocation problem, and they don't seem to have a way to address it at the moment besides closing all PRs.
- MarsIronPI 4mo agoI suspect that rather than some kind of digital proof-of-competence, communities will shift to in-person meetups at conferences and such. Which is unfortunate for people who can't attend for whatever reason, but I think some solution to that can be worked out.
- sdevonoes 4mo ago
- armchairhacker 4mo agoWhy don’t they take the Linux approach? A browser is like an OS. Linux continues to accept public contributions, through an esoteric process that discourages lazy contributors: https://www.kernel.org/doc/html/latest/process/submitting-patches.html https://www.kernel.org/doc/html/latest/process/submitting-pa...
- AdamN 4mo agoThe only problem with that nowadays might be that AI can do all the incantations that formerly acted as gates to contributors.
- rzmmm 4mo agoMaybe not. Sqlite has some kind of hand-written license-agreement waiver procedure.
- darthwalsh 4mo agoAU is just as effective as humans at contributing to sqlite: they don't accept contributions.
- delusional 4mo agoThe Linux approach is under pressure too. Maintainers are beginning to warn about too many contributions and too much churn to review it all.
- afandian 4mo agoI know is a naive question, but it's genuine! Is this the direct result of a monolithic kernel? And would moving more drivers out-of-tree mitigate this?
- kibwen 4mo agoThere are numerous advantages of microkernels over monoliths, but even if Linux were a microkernel it wouldn't necessarily change the review pressure that the above commenter is talking about, because you still have the same number of components (filesystem, networking, drivers, etc) to develop and review patches for (although you do have more well-defined interfaces between components, which eases security).
- koteelok 4mo agoStuff like this makes me wish AI had never happened. An open-source projects losing the ability to find and mentor new maintainers is so disappointing.
- gregoriol 4mo agoHow is it really related to AI? there have been issues with open-source and maintainers for a long long time
- ufo 4mo agoIn the post, the ladybird maintainers say that they trust pull requests less than they used to, because many pull requests are authored by AI now. A big pull request no longer signals that the submitter put in a lot of work into it and it's committed to developing and maintaining quality code.
- ares623 4mo agoMy friend, the very article we are talking about this mentions this directly
- risyachka 4mo agoThis is direct result of AI as you can see in many other public repos. before AI like 1 in 1000 would spend their time fixing something they had no idea about and even then considering how much time you spent and how few of those happened it made sense to review/talk about it. now every "dev" with claude submits prs having absolutely no idea what they are even doing. most of them would not even be able to create PR without AI in the first place. and on top of that add slop bots that "fix" issues in the loop and create hundreds of PRs daily
- jaapz 4mo agoNot sure if this happened to ladybird, but the amount of junk vibecoded AI-slop pull requests has been putting an immense amount of strain on many open-source maintainers. Reviewing stuff like that is intensely energy draining an most of the time your comments will just be copy-pasted into claude code and the "contributor" will put in 0 effort themselves to try to make the code readable or maintainable. Before AI, being open source and having to manage issues and PR's was already a huge task, burning out maintainers left and right. Now with AI, anyone with a terminal and a claude code subscription can open PR's...
- tetris11 4mo agoFor every person wanting to do good in the world there are ten windup merchants of which at least one has darker motives
- throwaway423454 4mo ago"A browser runs untrusted input from the entire internet on the user’s machine, and one well-disguised vulnerability is all an attacker needs. We have already seen patient, well-resourced campaigns in open source to earn maintainer trust and abuse it." Then the linux kernel is doomed. /s
- shevy-java 4mo agoCool - how about fewer perma-bans on github for participating in discussions? Also, as I have pointed out before, they seem to develop too slowly for a solid beta this year. You only have to look at the issue tracker and check for URLs not working or even crashing the browser. Ladybird may have gotten better in the last months, but imagine if 50.000 people are using it, you will see more bugs. How do they then handle bug reports?
- cuu508 4mo agoCan we see some discussions that got people perma-banned?
- lijok 4mo ago[flagged]
- Deukhoofd 4mo agoThis rather feels like it's completely stepping away from the thing that made the community around Serenity and Ladybird so good.
- conaclos 4mo agoI lost all trust in the project since the LLM rewrite. This new step is another red flag to me.
- siwatanejo 4mo agowhat rewrite? I thought it would switch to Rust but I still see it to be C++
- afdbcreid 4mo agoThey are adopting Rust (https://ladybird.org/posts/adopting-rust/ https://ladybird.org/posts/adopting-rust/) and use LLMs to help with the rewrite, but not all code was migrated yet. Also it's definitely not a big-bang-rewrite-the-world-with-Claude like Bun.
- rjh29 4mo agoI'd argue that was what made Serenity good - a toy OS that anyone can code anything for. Want to spend ages working on a painting program? Make screensavers? Add drivers for your printer? Port Doom? Improve font support because it sounds fun? etc. It celebrated coding for coding's sake, which is the antithesis of AI. There's no point vibe coding features for Serenity because there is no real product there. On the other hand, Ladybird is gearing up to become a production-ready browser for real users. Adding fun features for the sake of it, and hand-rolling code to parse PNGs and the like, has become a liability for the project.
- coldtea 4mo agoWhat made the community so good, is that it was a community. Any rando armed with an LLM is not a community.
- pulsartwin 4mo agoThis seems quite misguided and is sad to see. They have every right to do this, but I was looking forward to continuing testing Ladybird as it improves and contributing in the future. I hope servo stays open to contributions, as it seems like it's all we have left.
- apimade 4mo agoIt makes sense when you have a somewhat fixed core team size. Frankly, in some regards, this is the responsible thing to do. It means they’ll never grow modules or the codebase beyond what the team can reasonably maintain. However on the other hand.. What does this mean for the existing team, are maintainers now worth considerably more to the project? What does this mean for the codebase, or the momentum of the project? It’s an approach I would have expected for the likes of curl, or single-purpose libraries. But this is a mammoth decision for a mammoth project. I guess we’ll just have to see.
- coldtea 4mo ago>This seems quite misguided Does it? Seems the only sane option. The other being being drowned in AI slop PRs.
- sodapopcan 4mo agoYou can still contribute through bug reports.
- robin_reala 4mo agohttps://mastodon.social/@taym95/116697302689826448 https://mastodon.social/@taym95/116697302689826448 As a Servo maintainer, I'd like to remind people that @ServoDev continues to welcome contributions from everyone. We actively mentor newcomers, help people learn Rust and browser engine development, and review community PRs.
- nnevatie 4mo agoThis is one way to rephrase "we don't want your AI slop, thanks.".
- jeroenhd 4mo ago> Whether code was typed by hand is beside the point. What matters is who is responsible for it once it enters the browser. Ladybird is becoming a browser for real users. The people introducing changes to it must be the people who decide those changes belong in the project, and who will answer for the consequences. It probably accelerated the decision, but I don't think that's all of it. I think they're moving in the WebKit/Safari direction: open for you to look at, but not really an open source project.
- ashkulz 4mo agoIt's still open source, but not open for public contributions. That's pretty much how it was before the advent of these forges.
- jeroenhd 4mo agoI think I didn't put the emphasis right in my comment above. The code is still fully open source, but the project that produces the code isn't. It's not dissimilar to other projects producing open source software. This is the first time I've seen a project with this much history in community contributions close down, though. I suspect AI will cause more projects to follow in Ladybird's footsteps.
- dwaite 4mo ago> The code is still fully open source, but the project that produces the code isn't. I think your thought was cut off. What is the project no longer?
- leoc 4mo agoThat's not really right, though the license is still Open Source compliant. Linux was practising an open, patches-welcome developement style before the forges existed, on its mailing list. This did indeed contrast with how eg. the FSF was running its projects, though even in those the door wasn't shut as hard on people wanting to contribute as Ladybird's now is, I think. Then Eric Raymond wrote "The Cathedral and the Bazaar" specifically to talk up Linux's patches-welcome development model, and to move the emphasis away from (just) licensing terms and source accessibility, to openness to patches. Netscape then launched the Mozilla Project specifically on the CatB model. In response to the surge of momentum, the "Open Source" label was created basically as a brand name for the CatB perspective. After all this, "doing it as open source" was established as a clear mental category in people's heads, and the forges popped up as low-friction SaaS solutions for something that people already wanted to do, and by then were often already doing. (In the process helping to make Web-based SaaS a well-established concept and business model in people's heads, something with ironic consequences.) So Ladybird's current development model is much more clearly in line with the Free Software philosophy than the Open Source philosophy. To be clear, that's not the only disagreement or difference of emphasis between "Free Software" and "Open Source": most obvioulsy, Ladybird's BSD license is a failing in the FSF's view of things, just not enough of a failing make Ladybird not Free Software. But it is a real one.
- nathell 4mo agoLLMs might be part of why Ladybird is making this decision, but they aren’t the only possible one: SQLite, for example, has been developed this way pretty much forever. To each their own, I guess.
- pansa2 4mo agoLua is the same IIRC: open source but not open development. It’s MIT licensed, and the maintainers are always grateful for bug reports, but all the code in the project was written by just 3 people.
- cliche 4mo agoYeah I don't see the big deal here. Some of the best software is made and maintained by a very small group of dedicated folks. It's a perfectly reasonable move to protect their time and project.
- splittydev 4mo agoWasn't the entire goal of Ladybird to have an open and independent browser engine? Making it effectively closed to contributions makes it.. Not independent anymore. It's now dependent, on few people who work on it, just like any other closed-source or corporate-controlled browser.
- deleted 4mo ago[deleted]
- dgellow 4mo agoI don’t think that changes the project independence, when a project is open to PRs you have the same dependency on maintainers accepting changes into main. And the project is still open source. But that does make it less community oriented
- siwatanejo 4mo agoBut opensource has always been about community. This way it becomes "source-open", even if you could make changes to it and run those changes yourself, the latter doesn't sound "opensourcy" to me.
- dgellow 4mo agoOpen source is about rights/freedom, the community aspect is downstream from that. You have “source available” projects with active communities and external contributors (see elastic license v2.0 projects), and open source projects that only rely on core developers. With open source freedoms comes a culture of community oriented development but what makes a project open is the license, nothing else. The right to fork, read, run, edit is what matters. Unfortunately AI tools are breaking the open community dynamics, it has become more and more expensive to run open community oriented projects due to the noise, it’s really a shame. It’s a lot to expect volunteer project members to triage the increasing amount of AI garbage
- dwaite 4mo agoThe open source definition does not mention community at all - it is a set of licensing requirements that certain rights to modify code must be maintained, not that upstream will accept your change or (for that matter) that you need to package it up and hand it to them. And submitting a PR is almost wholly dissimilar from a conversation between friends over dinner or drinks. If you want to have a community around an open source project, it always has taken more than just accepting patches.
- scotty79 4mo agoI think we are going to see a lot opensource project switching to Humans Need Not Apply Mode.
- z0ltan 4mo ago[dead]
- vrganj 4mo agoLLMs are killing open source just like they're killing online discussion forums. It's heartbreaking, my two favorite things about the internet are dying off because human interaction can't outscale AI slop.
- rhubarbtree 4mo agoAnd most social media, and blogs. Newspapers are adopting it too, so soon we may see slop dominate even high brow publications. Feels like a huge shift in human intellectual capabilities. Honestly quite worrying, I don’t think it’s a Luddite position to say that removing writing is removing thinking.
- mabedan 4mo agoI can understand where they come from. If most of the pull-requests were AI-coded, well, the maintainers are equally capable of prompting Claude Code themselves. I think the whole game of software engineering, open source or not, has completely changed. A lump of code doesn't mean or imply the same thing as it did 2 years ago.
- hombre_fatal 4mo agoThe code just isn’t the main effort of work anymore. Anyone can generate the implementation, so it makes more sense than ever to instead hammer out the what, why, and how that underlies any code change. I see all projects moving this direction. Makes more sense to hash out a plan together.
- skydhash 4mo agoCode was never the main effort of work, but it was a clear signal that someone has done the main effort, which is understanding the codebase, designing a new feature, or investigating a bug, and have the knowledge to write the code. By the time you get to review, you can expect a knowledgeable person on the other end. It’s the same about published journal article. A lot of them are a few pages. That is mostly one hour of typing. But everyone knows that typing it is not the work.
- hombre_fatal 4mo agoRight, and all of that is what I consider to be the "code" effort: Deep research in the codebase, deciding on the flavor of code to write that matches the project, deciding how you'll model the feature with types, how to architect it so that it's testable, writing the tests, foreseeing cases beyond the obvious path, etc. What changed is that it can be automated. Or, just grant a world where AI is perfect at implementation. Now our time/energy/attention is freed up to concentrate the work around planning what to build. And the interesting part is that it becomes the input into the AI implementor. This is a good thing since we tended to skip the planning stage since it's hard in its own way. Or we start building something and then try to synthesize a high level direction from it, yet now since refactoring is so expensive, we're committed to a solution.
- xyzsparetimexyz 4mo agoSurely you can just autoclose any PRs from 1. People you don't know and 2. That are over 100 or even 50 lines? That way new contributors are forced to start small.
- ssenssei 4mo agoI think it's not the issue with the added PR count, but the fact they have to review them. 1 big PR review is the same as 5 small PR reviews if you have to look at how it holds, edge cases and what not...
- nextaccountic 4mo agoWell, then add some backpressure. Each contributor gets only a few small PRs a month, until they prove themselves. Contributors that don't have a credible online presence are automatically rejected. Etc
- brokylabs 4mo agoLegit
- WhyIsItAlwaysHN 4mo agoThey could make two kinds of pull requests and add much more strict criteria for public contributions. For example, they could say that the PR has to be smaller in size and well-documented for human review, otherwise it's closed by an automation. And then if someone wants to do a larger contribution, they could have a process like making an issue, discussing the approach and then collaborating with a maintainer to get it in. Blocking public contributions means that they want to have complete control of the project and AI is likely a good excuse to do that.
- habinero 4mo agoThat doesn't solve the volume or quality problem. LLMs can split one giant PR into 50 smaller PRs just as easily and "well-documented" isn't something you can determine automatically. Why is it so hard to just accept that AI PRs suck and create an enormous amount of toil?
- WhyIsItAlwaysHN 4mo agoWell it still looks suspicious if a user creates 50 PRs in one go. So you would close them automatically. As for well-documented, the reviewer can decide that when they are reviewing the smaller PR. Nobody said volume is not a problem, but closing down contributions entirely is a step too far.
- steve1977 4mo agoThis project gets a lot of publicity for the product it has to show (which, as far as I know, is effectively still inexistent).
- LeFantome 4mo agoThis is not really a valid criticism for an Open Source project. I built Ladybird from source yesterday and I am typing this comment in it now. So, I assure you that the Ladybird browser exists. Of course, Ladybird is not production ready yet. Feature-wise, it is getting close. I can use it to do most of the things I want to do with a browser. Speed and reliability are another matter. I has gotten dramatically faster but normal users would still find it slow. But the biggest problem is reliability. I would not use it in its current form for anything that matters. But for a complicated application that was started from scratch, not being ready yet is not an indictment. They claim it will be ready for regular users to try sometime this year and, from where I type, this seems realistic.
- cpcallen 4mo agoOn the one hand, if you grew up in the baazzar, moving to the cathedral might feel like the "death of open source" even if it is really just a return to an earlier way of working. On the other hand, while not accepting external code contributions will certainly improve their security posture it will also make it more difficult to identify who to invite to join the priesthood.
- anilakar 4mo agoIf you grew up in a junkyard, getting adjusted to the social norms of a bazaar might feel like your way of life is being threatened.
- cassianoleal 4mo agoIn your analogy, is the junkyard the development model of vibe coding? I look forward to the book: The Cathedral, The Bazaar and The Junkyard.
- pelagicAustral 4mo agofwiw I asked Claude to look at GP's post and write me a story titled "The Cathedral, the bazaar and the junkyard" and I have a pretty good time reading his riff.
- multjoy 4mo ago“Its riff”
- pelagicAustral 4mo agoYou're absolutely right...
- javawizard 4mo ago> it will also make it more difficult to identify who to invite to join the priesthood The point that this announcement is trying to make is, of course, that AI has already made that particular signal approximately worthless for that purpose.
- deleted 4mo ago[deleted]
- Anoian 4mo agoI think GitHub should fix this. They should make the barrier to create a pull request higher, they should detect slop pull requests, they should hand maintainers tools to deal with this bullshit. Sadly they do not have the right motivations to create all of this. Because all of this would mean less usage of AI. If I were GitLab or Forgejo, I would be working exactly on this, to get the projects who are struggling the most with this problem on my platform.
- siwatanejo 4mo agoWhile I understand the motivation for this change, I have to highlight something: GitHub's slogan 'social coding' is becoming more and more true these days. Now opensource will become a thing that only "influential" people can contribute to. We're back to nepotism, not meritocracy. Down hill we go.
- drivingmenuts 4mo ago> Now opensource will become a thing that only "influential" people can contribute to. We're back to nepotism, not meritocracy. Down hill we go. Or people can just start their own projects instead of working on someone else's. Many projects instead of potential large points of failure.
- siwatanejo 4mo agoI don't know about you, but as for me, when I contribute to opensource it's because I find some improvement that makes the project better because it probably polishes some rough edge around a kind-of particular use case (that maybe few people face, but still, it makes the project better for them; it amplifies the range of usecases that it can span to). If everybody does the same with their small improvements, the project becomes better for everyone, but none of the contributors of these small changes would have time to embark on maintaining a fork. Mantaining a fork is hard work, not only because software breaks over time (dependencies going obsolete or insecure, builds stop working because of old toolkits), but also because not pulling the latest changes from master would mean that your fork gets stagnated (and thus not worth to run it).
- troupo 4mo ago> Now opensource will become a thing that only "influential" people can contribute to. No. Having access to a slop generator doesn't entitle you to acceptance to any and all open source projects. You're still responsible for the quality of your contributions. Something that is completely lost on bullshit artists.
- siwatanejo 4mo ago
- merelydev 4mo agoOpensource doesn't mean open to contributions. The source code is available, you can fork it and apply your patches there. This is the way to go to reduce supply chain vulnerabilities and to reduce time of mainters reviewing LLM slop.
- leoc 4mo ago> Opensource doesn't mean open to contributions. That's not entirely true. It's certainly the case that Ladybird is still under an open-source license, but the whole idea of the "Open Source" label was to move the emphasis away from having a free license to actually being open to patches in practice.
- Hendrikto 4mo agoNot even the most extreme FOSS zealots (RMS, FSF, …) ever claimed that taking public contributions was ever a part of that.
- leoc 4mo agoBut that's a bit backwards. RMS would emphatically agree that Free Software doesn't mean being open to contributions; if you asked him about either "FOSS" or "Open Source" he'd probably command you to wash your mouth out with soap. It's the other side of the fighting FOSS family which evangelised for Linux-like development (see the thread from https://news.ycombinator.com/item?id=48410503 https://news.ycombinator.com/item?id=48410503 ).
- angry_octet 4mo agoIt says something about the fragility of contemporary software that a fragment of bad code could result in doom. I think we need to move to much more restrictive computation architectures, inherently partitioned, functionally pure, and resistant to type confusion, pointer manipulation, memory issues etc.
- dm_ 4mo agoI don't disagree with the desire for more inherently secure architectures, but I don't think it's the most relevant issue here. You're always going to have to trust some core same-privilege code--a browser renderer is a great example of this: it has to be able to see the entirety of the DOM it's rendering, right? Higher-level languages can still help code review--for example, memory safety makes it harder to hide a backdoor via unsafe memory operations leading to code injection. But you're still, fundamentally, trusting these community contributions. I think the real problem (as others noted here) is that: - writing code is now much, much cheaper than ever - understanding and designing code is still fairly expensive So doing the former (in the form of a PR that compiles and passes CI) is not a good "staking mechanism" to prove someone has done the latter.
- mastermage 4mo agoI truly understand why this step was taken, but it is still sad to see the death of open source or rather open contribution. Every project that turns away from open contributions is a project lost to the whims and fuckery of AI Bros. What I realy want to know how sustainable a model like this is. How does one find new maintainers when old ones leave. When you cannot contribute anymore.
- ashkulz 4mo agoAre they going to be using gerrit or a private repo and push changes back regularly? Sometimes the discussions on PRs are equally valuable to see how a commit was arrived at, and I'd be sad if that got lost in this change.
- LeFantome 4mo agoIt sounds like all public contribution will simply be impossible. That said, they will continue to develop out in the open on GitHub and you can clone the repo and build whenever you want. You can continue to contribute in other ways. https://ladybird.org/#contribute https://ladybird.org/#contribute I hate this change and agree with your PR comment. This change makes me sad as well. My hope is that public contributions can resume in the future. Part of their justification for this step is that they are trying to stabalize the project to produce a stable public alpha. Fair enough. And many Open Source projects have begun to voice concerns over the burden that the massive increase in contributions is causing, often from AI. Linus Torvalds has certainly been flagging this. The Open Source world in general is going to have to navigate this and come to a solution that works without the entire Open Source ecosystem becoming read only. Once Ladybird ships a "stable" browser out to the world, I am hoping they can adopt whatever the "best practice" for Open Source has become to be able to accept public participation again.
- nh2 4mo ago> There will not be a [..] process for submitting patches by [any] means > Outside involvement still matters: clear bug reports So I can find a bug, I can fix it, but I am not allowed to tell them how exactly I did it. Instead they have to re-figure it out. The team must be thrilled to re-do work they know was already put in by others, repeatedly. As a user-and-eveloper, why would I sink time into a project with such rules that put a barrier to improving my life with the software? It seems much easier to use Firefox or Chromium, where my fixes actually meet open ears. It was very useful for me in the past when a new Chromium version crashed on my product, that I could go and suggest a fix to V8, and it was rolled out in the next Chromium release so my product worked again (https://github.com/v8/v8/commit/4f8a70adca01c https://github.com/v8/v8/commit/4f8a70adca01c). Without this, maybe Chromium developers would have never bothered to fix it because of lack of time to figure it out. > a pull request no longer tells us as much as it used to about the person submitting it Nobody should need to know anything about any person submitting a pull request. Hopefully whether code that makes it into Firefox or Chromium was never based on the "effort" or "faith" of the submitter, but based on the correctness of the code in review. Reviewing code fixes is strictly easier than coming up with them yourself. This holds true automatically: In any situation where it isn't, you can just write the code yourself and done. As a project you can always ignore or close a PR you want to write yourself instead. But it seems unwise to bar yourself from the _option_ of reviewing an outside contribution, or using it as input for your own re-write.
- layer8 4mo agoYou can still tell them how you did it, just not in the form of code/patches. You should be able to describe it in prose so that the maintainer understands your solution approach.
- LeFantome 4mo agoNot necessarily. I just fixed the Ladybird build process so it will successfully build on a system that uses musl instead of glibc. By far the most compact way of explaining what needed to be changed is to share the changes themselves. It is a set of very small changes to a number of individual files.
- Fraterkes 4mo agoI've been looking a lot at Godot (another big open source project) PRs lately, and there's been kind of a surge of wholy ai-generated PRs (both code and description). This is agains project-policy, so people creating these PRs usually get mildly told off. What's surprising is that while many submitters take that fairly well, some people get really indignant, essentially calling the maintainers ungrateful. It's kinda surprising to me that even the people who are all in on ai haven't internalized that there's no inherent value in producing a big lump of code. They've massively decreased the work they put in but still expect the same pre-ai reaction/gratitude when submitting a big PR.
- lucideer 4mo agoThe pre-ai reaction was also unwarranted: committing a massive amount of potentially unmaintainable handwritten code isn't a necessarily positive contribution and any decent engineer (or person tbh) would understand that & not expect gratitude, no matter how concerted their effort. In that context, I wouldn't expect an idiot (of which there has always been far too many in this industry) to change their behaviour in a post-ai world. They were always out of line & continue to be. Fwiw, a non-technical employee in my workplace has begun submitting ai-generated prs to internal repos I maintain & they're of excellent quality, with review feedback graciously received & expediently addressed, so this isn't a matter of the idiots not being technical, it's an attitude problem.
- DrewADesign 4mo agoSure, but I think we should judiciously avoid the false equivalence yielded by only looking at this on a developer-by-developer basis, rather than systemically. The truth is that in practice, AI is not a neutral force. Obviously AI can enhance the output of smart, experienced developers and improve the efficiency of code reviews, mitigating the effects of garbage PRs. However, it increases the percentage of PRs contributed by entirely inexperienced and/or not-smart devs from zero to, potentially, the majority. It entirely removes the barriers inherent to coding that kept Dunning-Krueger cases from submitting ill-conceived or poorly constructed changes— actually getting them to run in some way, even poorly. That makes them much more difficult to distinguish from well-constructed PRs than those from, say, someone cargo-culting code from tutorials. Moreover, as these tools become more expensive, people with money to blow on tokens will be able to drown maintainers that don’t have enough token-cash to help them deal with it. People see this as mostly a matter of time and energy, but I reckon it will soon be a financial issue.
- q3k 4mo agoIt's surprising to me how many people here seem offended that someone might just not want their code. I guess it takes quite a lot of experience as a maintainer to realize that 'free' in 'free code contributions by strangers' is like 'free' in 'free puppy'.
- lukaslalinsky 4mo agoWhat made open source great, is the fact that if you find a problem, you can patch it. It's what motivated me, anyway. Ladybird is not SQLite, it's under development and very likely will be forever. To me it looks like they are transitioning into a company, where this model makes sense.
- deleted 4mo ago[deleted]
- jpc0 4mo ago> What made open source great, is the fact that if you find a problem, you can patch it. It's what motivated me, anyway. What exactly is different now? > it's under development and very likely will be forever. So is Sqlite. Last time I checked they are still actively developing Sqlite. Do you mean you can't just grab a current release and hold on to that? Well it's pre-alpha... That's the point...
- cestith 4mo agoSometimes it’s even more like “free kudzu”.
- domenicd 4mo agoFascinating to see that Chromium/Gecko/WebKit are now more "open" browser engines than Ladybird, at least in one important respect. (Servo is arguably in the middle, accepting outside contributions as long as you don't use AI.) It's understandable that a team without much funding would have to close off contributions to spare on labor costs. But, it makes me feel that people don't give Google/Mozilla/Apple enough credit for the economic resources they put into enabling openness. (Personal bias/experience alert: I'm currently retired, but formerly worked at Google on Chrome. I saw many of my coworkers nurture outside contributors, and did some of that myself, both informally and through programs like internships.)
- tgv 4mo agoChrome is Google's loss leader.
- sph 4mo agoIt sure is, but it’s a bit weird to call loss leader the cornerstone of their trillion dollar monopoly.
- Hendrikto 4mo agoThose corporations are not doing that out of the good of their hearts. They are doing so to assert control, in order to protect their business value. If it stopped being economical for them, they would stop tomorrow. I do not think we should be eternally grateful for monopoly building.
- jeltz 4mo agoYeah, they are essentially praising price dumping.
- einpoklum 4mo ago> Chromium/Gecko/... Are now more "open" browser engines than Ladybird Chromium? You mean the browser engine controlled by the Be-Evil corporation Google, which recently killed support for a huge swatch of important extensions (manifest-v2)? And thus prevents much of adblocking? Gecko... now that's something less people are aware of, but let's just say if you know how the Mozilla ecosystem is governed internally, I believe you would be rather aghast.
- lukaslalinsky 4mo agoI wonder how can a new browser engine survive with the source available model. Like, why would anyone support this, unless they have business association with the Ladybird developers?
- bayindirh 4mo agoIt's not source available. It's OpenSource(TM) because of the BSD-2 license. This is not unheard of. The most famous models are emacs & SQLite. SQLite doesn't accept outside patches, emacs is developed opaquely and only releases are put forward. You can do this with GPL, too. You put out tarballs of the releases only. There's a great misconception between Free Software, Open Source, and Open Development (bazaar model). They complement each other, but they are completely independent things. Addenda: Looks like emacs' Git repo is publicly accessible now, but it's not a requirement for GPL or Free or Open Source software.
- lukaslalinsky 4mo agoIt's actually common, many companies develop their products this way. The source is available, you can see the VCS, but you can't participate in the development. That's why I see this as signal that it's going to turn into a company.
- bayindirh 4mo agoHowever many if not most of these companies use "Source Available" licenses which say "Thou shall look, thou shan't compile". This is very different than Open Source license of Ladybird itself.
- LeFantome 4mo agoWell, technically it is a "company" already as it is registered formally as a non-profit. They have income (sponsors) and paid employees. To my eye, this change does not appear to be driven by a change in corporate governance or profit motive. They explain that the change and the timing is driven by two things. 1 - The burden and of processing public contributions has increased with the rise of AI 2 - They need to focus and stabliize the code base in preparation to introduce a public alpha Those reasons ring true enough for me that I do not need to go looking for other motivations. I do not like this change but I can see why they would.
- boneskull 4mo agoI don’t understand how you’re supposed to cultivate new maintainers if you shut down contribution. Is this a sponsored project where maintainers are just hired?
- deleted 4mo ago[deleted]
- Hendrikto 4mo agoYou are also not cultivating any new contributors by just accepting slop the submitter did not write or understand. I guess they will have to introduce some kind of trust-based system.
- cestith 4mo agoEncourage forks and wait for actual experienced, committed maintainers of the fork to emerge I suppose is the way. In essence the maintainers are saying the path to trusted contributor and then to maintainer via outside unsolicited pull requests is less useful because the signals of a committed person in that path have become less useful.
- net01 4mo agoI don't like this, but I understand it. I've contributed to the LB project several times, and I have made friends IRL with people who have also contributed to the project. ( we are now friends at uni ) It feels like a stepback because instead of 30-45 contributors every month, you have 15... i feel like there should be a way to trust a PR ID verification or in-person verification at FOSDEM/DEFCON/Chaos Communication Congress,UNI's, for example.
- throwaway7356 4mo ago> i feel like there should be a way to trust a PR ID verification or in-person verification at FOSDEM/DEFCON/Chaos Communication Congress,UNI's, for example. They probably could do that as part of the hiring process.
- TheCoreh 4mo agoA bit sad to see this. Of course they are free to do it the way they prefer, and there are successful projects like this (Notably SQLite) but there has to be a reasonable middle ground between "everyone can just flood us with 30,000-line 'Claude implement feature X make no mistakes' PRs" and "we're not open to outside contributions"
- b3e53bb34c0bd 4mo agoHow would you decide what is the middle ground though? If a project allows some AI-generated PR if its good quality, then it is a burden on the reviewer on what is considered good or not.
- TheCoreh 4mo agoYou can introduce a social/trust element to it, something like: Join our Discord, chat to us, come to our "office hours" video calls first, then you get to contribute. Maybe also limit the size/scope of external contributions (only small bug fixes allowed for your first few PRs)
- VortexLain 4mo agoLadybird going source-available is quite unfortunate, seems like Gecko is the only production-ready independent browser engine we're left with. They may, at this point, go ahead and remove "get involved" block from their website https://ladybird.org/ https://ladybird.org/, since it's not possible to contribute anymore.
- andrewchambers 4mo agoThis is not the same as source available - you can fork it, the license didn't change.
- MarsIronPI 4mo agoIt's not source available, source available implies some restrictions on what you can do with the source, or with any resulting binaries. This isn't a rugpull; all they're doing is closing off contributions, which has nothing to do with the license of the code.
- afdbcreid 4mo agoThat's not source-available, that's still open-source. Quoting Wikipedia: > Source-available software is software released through a source code distribution model that includes arrangements where the source can be viewed, and in some cases modified, but without necessarily meeting the criteria to be called open-source. https://en.wikipedia.org/wiki/Source-available_software https://en.wikipedia.org/wiki/Source-available_software > Open-source software (OSS) is computer software that is released under a license in which the copyright holder grants users the rights to use, study, change, and distribute the software and its source code to anyone and for any purpose. Open-source software may be developed in a collaborative, public manner. https://en.wikipedia.org/wiki/Open-source_software https://en.wikipedia.org/wiki/Open-source_software And as said here, SQLite was operating like this forever.
- deleted 4mo ago[deleted]
- deleted 4mo ago[deleted]
- jiehong 4mo agoPerhaps we should start to describe projects as Open Contributions from now on. With maybe a few Open Contributions Standards to distinguish how this works.
- patates 4mo agoWhen AI first happened, I was afraid I was going to eventually lose my job. And while I've been lucky since, many did, and that hurt a lot. When people are losing something to automation, regardless of the economics of the situation, you cheer for the humans, or at least hope that society keeps being fair to those who are most affected. Now I see communities being affected. When you kill PRs, you not only kill the code contributions, but also massively impact the other, non-tangible contributions like ideas, eyes on code, etc. That feels way worse. I'm conflicted, confused and afraid, HN. Look at what I just wrote, yet I use claude and deepseek and all the skills and complex harnesses and MCPs and whatnot... But all now seems like a transition phase. Transition to f-ing what though? A lot of questions cannot be answered unless we dedicate a meaning to our lives. Human touch? Too late? Also: I liked a song and it was sonos. I unliked it after discovering. I feel so stupid, so often. Sorry for the unhinged digression. I love Ladybird (have a sticker on my laptop to prove!), I hope they thrive.
- BrissyCoder 4mo ago[flagged]
- lucasban 4mo agoWhy do you care if they want to put stickers on their laptop? It’s not my taste, either, but it’s subjective.
- BrissyCoder 4mo ago[flagged]
- tiluha 4mo agoLadybird is the browser this whole submission is about. Did you not even read the headline?
- patates 4mo agoI'm talking about Ladybird, AI and its effects on communities. Stickers start conversations with people I have common interests with in unexpected places. I didn't know of this effect until I experienced it a couple of times, so that's why I keep them. The reason I started was, to be completely honest with you, to show off my "skills" and beliefs. To be fair, I was much younger and naive. Strong evidence against your implied accusation of me being insane is the fact that my licensed therapist not having me sent to an intensive psychiatry clinic yet. She says we'll be fine within the limited hours we get courtesy of the German health care system. I do have ADHD and I do feel different all the time, and I tend to go off course when talking/writing, so maybe you mean that?
- kristoff_it 4mo agoThe problem statement is clear to everybody. > For decades, code contributions have been how open source projects learned who to trust. People would show up, do the work, take responsibility for their changes, and stick around. Over time, trust emerged from the work itself. The solution, IMO, is a strictly worse version than what we chose in the Zig project (banning LLM contributions). > AI tools have changed the economics of this very quickly. We use them ourselves every day, but a pull request no longer tells us as much as it used to about the person submitting it. A substantial patch used to imply substantial effort, and that effort was a reasonable proxy for good faith. That assumption no longer holds. Things that worry me about this choice: - open source is a tough business and you need to leverage the good things about it to make it worth doing. contributors bring in a huge amount of value that they offer you essentially for free (see contributor poker: https://kristoff.it/blog/contributor-poker-and-ai/ https://kristoff.it/blog/contributor-poker-and-ai/), on top of being a hugely valuable recruitment funnel. They're rejecting all of that, which seems insane to me. - one could argue that LLMs could fill that gap but, first of all they could have just banned LLM usage only in PRs from untrusted contributors, and second even the best LLM: 1. is a cost, not just free value, and the price of tokens is increasing 2. the code has to be reviewed anyway, unless you think that just passing tests is good enough for a browser 3. ultimately can't become a trusted core contributor able of taking ownership of a part of the codebase - removing the influx of code that comes from PRs means that over time the whole project will have a small number of contributors that own all the code, making it easier for the project to do a license rugpull. when copyright ownership is well distributed this kind of thing is harder to pull off. Overall, this is not good in my opinion. They're making open source a more problematic business model for them than it has to be, while at the same time making it harder to recruit more core contributors, as the code ownership coalesces to small group of people. This is an obvious recipe for disaster (a rugpull), and I'm forced to wonder if this is just by mistake or if some of the Ladybird sponsors are playing a mean game of Secret Hitler. I guess only time will tell.
- lioeters 4mo agoThe Zig project is making a real difference in the culture of open source software. I'm so glad for the leadership and community. It's a refuge from the mania of large language models disrupting this and other industries, steamrolling over human connection, decency, ingenuity, class, taste. These intangible qualities that make it worthwhile, joyous and fun, will be destroyed unless people put in effort to protect them. Comments in this thread that insist open source has nothing to do with community, that it's simply a licensing matter, is disappointing and shows a lack of understanding of what's it's all about. Similarly with the community of mathematicians. Some people reduce it to "Math is just a tool", which is just ignorant and sadly misses the beauty, wisdom, camaraderie, and the humanity of the endeavor which is what matters.
- noIdeaTheSecond 4mo ago"A substantial patch used to imply substantial effort, and that effort was a reasonable proxy for good faith. That assumption no longer holds." I believe this is the key point the article makes and it's valid for most projects out there
- crabmusket 4mo agoThe generalised form of this, which we are rapidly discovering, is that AI breaks the social contract that used to exist between an author and a reader (of prose, code, anything).
- spacechild1 4mo agoThat's the most succinct way I have seen someone put it, thanks! It's really the same issue, no matter if it's software, online comments, e-mails, artworks, homework, etc. We engage because we expect to be interacting with the output of another human being. AI fundamentally betrays this expectation.
- infinet 4mo agoI wonder how many comments are from bots in this discussion. Few days ago there was a discussion of traffic stall at the strait of Hormuz on HN. One comment from an user with over 9000 Kama went like "I just checked the traffic on the road and it is normal ...". Unfortunately other bots are not as easy to spot as this one.
- aorth 4mo agoYes, and there was a good post about exactly this social contract last week https://jola.dev/posts/the-social-contract-of-writing https://jola.dev/posts/the-social-contract-of-writing. I find the argument compelling on the face of it and true in my experience with colleagues and the broader digital landscape recently.
- crabmusket 4mo ago
- TeriyakiBomb 4mo agoIt's inevitable that more projects follow this path. The elephant in the room is so many projects already operate like this without formally announcing it. If you look at Blender, one of the biggest and most successful OSS projects out there, it's effectively run as source available. Some PRs make it through, but for the most part there have been heavy barriers to entry to get your work into the product. In this example, it's been key to such a large and complex project with millions of users staying afloat. It's an inconvenient truth. It's one of those unspoken things in open source - the bigger the project the less you can accept or vet contributions. The less able you are to respond to users because there are too many. The amount of code you need to own balloons. The signal to noise to too much. LLMs have massively exacerbated this issue.
- account42 4mo agoIt's not "source available", that term already has a different meaning. The cathedral development model doesn't make the result any less open source or free software.
- TeriyakiBomb 3mo agoThat’s why I said “effectively run as” rather than is. Cathedral does make contribution to software less open, that’s kind of its entire deal and what I’m talking about here. It doesn’t make it any less free, but then a good number of software companies sell access and closed versions of open source projects, so we continue to split hairs.
- LeFantome 4mo agoCrappy timing for me. Ladybird has never built on musl based systems. I got that working just a couple of days ago (on Chimera Linux) and was hoping to push the changes to the project. I guess I am maintaining that myself now.
- dxdm 4mo ago> hoping to push the changes to the project. I guess I am maintaining that myself now. Not just the changes, you'd push the responsibility, too, for supporting a whole new compilation target. I don't know how big this is, but if it's a big enough hassle to keep maintaining this yourself, then consider that this maintenance work is really what you were hoping to push. So, depeding on which, you might be fine maintaining this, or the maintainers might have rejected the change, anyway.
- RyJones 4mo agoI manage multiple open source Github enterprises for the Linux Foundation. Something like this is under discussion in all of them - the amount of terrible PRs and issues being filed is overwhelming.
- afdbcreid 4mo agoI wonder, if they are really only concerned about trust, will accepting external PRs but never giving commit access to external contributors work for them? Of course, if they are also concerned about the quality of external PRs then that does not help.
- noodleweb 4mo agothis is a move in wrong direction, its sad and a bad solution. Ladybird implements specs that must be compliant, making compliance harder is the way to go, proving the code changes does what they are intended for should be made better instead of gate keeping from malicious and "honest" contributors
- ivanjermakov 4mo ago> Ladybird remains open source. The source code will continue to be publicly available under an open source license. We usually call open source software without open collaboration source available software. This is terrible news, defeating core beliefs people had in Ladybird. Not an open browser I wished for.
- debugnik 4mo agoHell no, open source is just about the licence, and source available generally refers to proprietary licenses that at least let customers access the source. This is just the cathedral model to open source, as opposed to the bazaar you clearly prefer, but it's still open source.
- ivanjermakov 4mo agoBy definition yes, but I believe most people consider open contribution essential for OSS.
- m0llusk 4mo agoAbandoning editorial control is poison for all composed works.
- cromka 4mo agoAmen to that. Let's not redefine an already very precise terminology.
- jpc0 4mo ago1. Free Redistribution 2. Source Code 3. Derived Works 4. Integrity of The Author’s Source Code 5. No Discrimination Against Persons or Groups 6. No Discrimination Against Fields of Endeavor 7. Distribution of License 8. License Must Not Be Specific to a Product 9. License Must Not Restrict Other Software 10. License Must Be Technology-Neutral Open source has nothing to do with the right to contribute upstream. It's about you being able to use the software how you like and make changes to it and redistribute it.
- ivanjermakov 4mo agoThe core problem is that we don't have a PR respect system. 10kLOC from an unfamiliar person with empty GitHub is much different from a pal regularly contributing that you personally know. Integrating some kind of proof-of-stake system might be a way forward for open source. Nobody wants to shuffle through a pile of low-quality PRs written by LLM.
- SchwKatze 4mo agohttps://github.com/PThorpe92/fossier https://github.com/PThorpe92/fossier
- ghosty141 4mo agothe ghostty developer introduced a system similar to what you describe!
- txdv 4mo agomitchell hashimoto https://github.com/mitchellh/vouch https://github.com/mitchellh/vouch implemented this idea
- zihotki 4mo agoI wonder if adding an artificial barrier in form of a donation could help. That's probably the only remaining way to show the good faith.
- drcongo 4mo agoI paid for Kagi's Orion (even though it's actually a little crappy) because I want options in the browser landscape. I'm really rooting for Ladybird, and just in case they don't offer a paid version in the future, here's a link to how you can sponsor its development: https://opencollective.com/ladybird https://opencollective.com/ladybird
- sinpif 4mo agoOh well, AI bros ruined it. I'm actually glad in some twisted way, because if more projects follow suit and close their development, it will again become an actual badge of honor to get on those teams. Having contributed to such projects will mean something.
- cromka 4mo ago"A substantial patch used to imply substantial effort, and that effort was a reasonable proxy for good faith. That assumption no longer holds." This is probably the best, most succinct explanation of what we're seeing happening in the OS world right now.
- bmitch3020 4mo agoAs much as I wanted to see another browser alternative succeed, Ladybird has lost my trust. Using LLMs to rewrite the entire codebase was already extreme. But eliminating external contributors is a precursor to a rug pull. And rewriting the entire codebase can now be seen as another step in a rug pull.
- TekMol 4mo agoFor an open source project, is there any reason to still accept code contributions? Feature requests are valuable because they tell you what users want. Error reports are valuable because they tell you under which circumstances the code fails. But the code that implements those features and fixes those errors can now be written by AI. AI follows all the rules for how code is supposed to be written in your project. Is already producing very high quality code. And soon it will produce a quality that no human can match.
- conradludgate 4mo agoIt was alluded to in the post - contributors turn into maintainers. Someone who contributes has a small but plausible chance of sticking around. For an open source project that isn't a business, that's really the only way to recruit people
- TekMol 4mo agoBut why recruit people, now that we have AI? Couldn't an agent monitor feature requests and bug reports, reason about them, and then implement and fix the ones it deems important?
- acureau 4mo agoFor the same reason software engineers still employed. AI is not yet capable of autonomous software development. From my perspective we're nowhere close.
- Forgeties79 4mo ago> Whether code was typed by hand is beside the point. What matters is who is responsible for it once it enters the browser. Ladybird is becoming a browser for real users. The people introducing changes to it must be the people who decide those changes belong in the project, and who will answer for the consequences. Applies so, so widely. Glad they’re taking (very necessary) action here.
- cromka 4mo agoI been thinking about it for a while that we need some score based system where each PR on GitHub/Gitlab grants you a review form the maintainer as well. You build your rep and the maintainers decide about the thresholds for contribution. I'm surprised this isn't yet a thing. Heck, this can be made independent of GitHub/Gitlab, like a portal which tracks your rep. Could also help you got hired. Think Stackoverflow rep mixed with LinkedIn but for actual code contribution. Yes I'm aware it sounds Black Mirror-ish. But we need more meritocracy in the world of OS that is otherwise highly anonymous and with very little public authority.
- rzerowan 4mo agoSo basically it will become more or less similar to the structure for SQlite and Fossil by Dr.Richar Hipp et al , basically seems most projects that have the requisite manpower/maturity will end up at that kind of structure. In the long run may be interesting from a chain of trust (human as well as code) and interop as any dev from these projects (guilds?) would already have some trust build in.
- witx 4mo agoOne more data point that AI is ruining open source. It's disgusting what these people are doing.
- casey2 4mo agoI don't understand why people contribute AI slop to existing projects. You move 1000x faster. Just write your own browser in 2 days.
- rhubarbtree 4mo agoI want someone to resolve the contradiction you have highlighted. Why don’t we now have an AI built web browser that is much better faster than chrome? To that mind, why hasn’t chrome itself become 1000x better? There is a disconnect between the narrative and reality.
- adrian17 4mo agoReading this leaves a weird taste in my mouth, since the author tends to regularly make nontrivial >1k LOC PRs (sometimes several per day) and merge them on the same day with no reviews at all. This is even ignoring the LLM aspect; I don't know what % of them are assisted, but even if it was 0%, this isn't the pace of development I'd be comfortable with.
- simonw 4mo agoThat's entirely consistent with what they said here: > Whether code was typed by hand is beside the point. What matters is who is responsible for it once it enters the browser. Ladybird is becoming a browser for real users. The people introducing changes to it must be the people who decide those changes belong in the project, and who will answer for the consequences.
- bakugo 4mo agoThat's the philosophical argument. In practice, though, the effect of large unreviewed AI commits on the project and its users is likely to be the same regardless of whether those commits were prompted by a core developer or an outside contributor.
- mikkelam 4mo agoMy own experience is far from this. Steering the AI, early and while developing a change, matters sigificantly. Therefore a maintainer is more likely to steer the AI in a direction that is aligned with the codebase.
- simonw 4mo agoI don't buy that at all. A core developer producing a thousand line commit that they'll be responsible for over the remaining lifetime of the project is entirely different from a fire-and-forget PR from an outside contributor.
- soerxpso 4mo agoIf the commit was prompted by a core developer, the developer knows what the prompt was. If it was prompted by a stranger, the core developer reviewing it does not know what the prompt was. The review attention required is completely different, because with an untrusted submitter you have to meticulously hunt down intentional security vulnerabilities obfuscated in the PR.
- BrissyCoder 4mo agoHonesty. WTF is Ladybird? Feel like as a normal guy doing normal software development I'm living in an alternate reality or something. How is this the top post on my favorite website?
- deleted 4mo ago[deleted]
- Sol- 4mo agoSurprising how little appetite for changing norms exists here on HN. Yes, the transition to agentic coding will be difficult, but to me this is mostly exciting. Despite my AI enthusiasm, I also run into shortcomings that the agents have very often, but that's a more interesting learning experience than the status quo without AI would have been! We'll have more such disruptions and we'll learn to live with it.
- softwaredoug 4mo agoSo the new way to contribute is to fork Make a better Ladybird successfully to the point the original contributors take notice. If the barriers to doing that are truly lower, then it should be easier.
- manuelz 4mo agoGood luck!
- WolfeReader 4mo agoWhere "better" means you and your maintainers spend all your time scrutinizing volumes of code from token prediction machines?
- jll29 4mo agoInteresting how this post coincides with the Leyden declaration in mathematics: both documents are abot how human-human trust ("in good faith") is eroded by large language models, because a substantially-sized artifact does not necessarily attest to substantial human effort and skills.
- lioeters 4mo agoGood point about how the community of mathematicians is struggling to come to terms with the role of language models in their work, and the similarity with the community of software developers. Machine-generated programs and proofs are contributing real value, undeniably, but it's causing social tension and destablizing the community with the sheer volume of its production, the varying quality, unreliability, and lack of humanity in the process. I would guess that similar issues will spread throughout society, in other areas of collective work and living. One potential solution, like with Ladybird and some other open source projects, is for a community to become more exclusive, restrictive and selective about what inputs they accept.
- ghthor 4mo agoI wasn’t around much before GitHub so. I believe I tried submitting patches to the XFCE project but I didn’t get anything accepted to FOSS before GitHub. In this type of system, if I am competent and can contribute how to do I? By reviewing the maintainers PRs, helping fill out more info for bug reports / root causing? There had to be some way for a competent user to get involved enough to become a familiar handle to the maintainers and be seen as a possible future maintainer/ expert contributor right?
- commandersaki 4mo agoSeems cold how they present this, but on the other hand I’ve ignored Ladybird because I just don’t think they’ll have meaningful impact, so I remain unaffected by this policy change.
- 9cb14c1ec0 4mo agoI once submitted a PR to Ladybird, but even in early AI days there were so many open PRs that mine got lost in the noise. I don't really blame the maintainers here. Once the open PRs get to a certain point, it becomes unmanageable.
- maplethorpe 4mo agoTheir loss. Think about it. Anthropic just reported that their codebase is now improving itself. We're moments away from every open source repo being able to do the same. Think of it like torrenting — you'll be able to open your repo to the public, and have a stream of code flow in from millions of contributors. More code than you could ever write in ten lifetimes, uploaded to your repository in a matter of days. Ladybird doesn't know it yet, but they just left themselves in the dust.
- efficax 4mo ago> open your repo to the public, and have a stream of code flow in from millions of contributors. More code than you could ever write in ten lifetimes, uploaded to your repository in a matter of days. why would you want this. this sounds terrible
- maplethorpe 4mo agoIt would be free labour! Truly crowd-funded development. I'm picturing something like folding@home, but where people donate their spare tokens to a service, and those tokens get distributed amongst all open source projects on GitHub. You don't think that would be cool? Like, someone might initialise a repo with only a readme and a to do list before they go to sleep, and then wake up to a complete software ecosystem that looks as if it's been in development since before they were born. Like, so much code that no one person could possibly understand it, and it all happened overnight while they were sleeping!
- cestith 4mo agoJust donate your tokens to the project. The actual team that’s actually leading the project can direct the prompts better and evaluate the LLM-generated code better for their project than random drive-by contributors can. That’s the whole point of their announcement.
- Anamon 4mo agoYou write "so much code that no one person could possibly understand it" as if it was a good thing. Surely, you're being sarcastic?
- aos_architect 4mo agocurious what the "did the pipeline actually do what we think" story looks like now. "green" and "the right artifact exists" drift apart faster than expected with more automation. exit code wasn't enough for us — had to make the output file the thing that proves a run happened.
- rhubarbtree 4mo agoI see this as the slow death of OpenSource. It’s controversial to say, and I may be downvoted, but I’ll share this as a pov: OSS is essentially giving away our work for free. Did that ever really make sense? If it does, why don’t graphic designers give their work away for free? Why don’t authors do that? UX designers? It’s a very peculiar thing to us nerds. And the strangest thing is, we may have unwittingly built the data source required to make our skills redundant, as models are trained on the work we gave away for free. I think this is an interesting narrative.
- cestith 4mo agoSome authors and UX designers to give away at least part of their work for free. The point of OSS though isn’t that nobody gets paid. It’s that if they charge for contributions, they get paid to release their work as Open Source software. They get paid for the labor of producing the artifact, and not necessarily paid a royalty for future sales of the copies.
- joeyguerra 4mo agoseems reasonable.
- manuelz 4mo agoThis is a very sad day. Yes, Ladybird is facing a wall of slop... no... A tsunami of slop overwhelms core maintainers. Probably safe to generalize to other popular open source projects. The project is important and the code is beautiful! I spent many happy hours trying to understand the code, browser-specs and tried to adapt to their coding style. After 18 months I ended up with a few merged PRs. Some were pure joy to write. I got to work directly with most of their core maintainers in the review cycle. They're great!! From the outside, it seems like their responsiveness to submissions slowed down in the last few months... slop. Of course, it would be great if there was another way, but here we are. Love <3 to Andreas and the core maintainer group! Keep up the good fight! Maybe we'll meet again.
- utopiah 4mo agoGoodhart's law, again. I feel like 1/10 comment I make on HN are about this. So merged PR were until LLMs a good proxy for the ability to code and contribute to a software project. Consequently they were used to estimate if a candidate was potentially good for a position. Merged PR on popular project were thus precious credentials one could "trade" for potential work. Since then the desire to provide PR changed from contributing to a project for its own sake, to make the actual project progress, to signalling. A new proxy must be found to establish the ability to contribute to a project.
- rirze 4mo agoThere is, it’s being able to tell bullshit from actual cosplayers. Ladybird’s blog post is arguing that it used to be tolerable to spend the amount of time evaluating this for every PR, now it’s just unmaintainable for their effort-time.
- utopiah 4mo ago> There is, it’s being able to tell bullshit from actual cosplayers. How do you do that efficiently so it can scale?
- idbnstra 4mo agowhat, in your opinion, are the new proxies?
- utopiah 4mo agoI'm not sure. I didn't think about this seriously in an adversarial context. What I can imagine though is that - the value of merged PRs might drop (as it's not a good metric anymore) - while the cost of submitting them goes up (as price per token is radically changing, e.g. Github announcement just this week) so maybe it's also only temporary. Also if all this is correct, including the value of PR on popular repository being more important, then the long tail of projects might not have to worry about this.
- spprashant 4mo agoI do wish they had left a window open for criteria to whitelist developers who can create PRs. By closing off their developer circle, they are losing the best parts of open-source - new software developers eager to solve large problems with novel approaches.
- classified 4mo agoThe cathedral vs. the bazaar. Makes sense to me. http://www.catb.org/~esr/writings/cathedral-bazaar/cathedral-bazaar/ http://www.catb.org/~esr/writings/cathedral-bazaar/cathedral...
- wilsonjholmes 4mo ago"The Cathedral and the Baazzar"
- luke-stanley 4mo agoThe cause of this is that the cost of creating plausible code contributions has gone down, so PR proposals can multiply, but flaws still threaten project security and LLMs can be confidently wrong. So human review is needed right now to maintain the integrity of the project, but it takes time and costs money. Ladybird's developers, and we as a community, can't easily evaluate "this is what we want" vs. "this is not what we want" without manual review, because we haven't settled upon a reliable representation of the meaning of our code and its side effects that is time-efficient, secure, and meaningfully interpretable at scale. This is partly due to Ladybird building on low-level system-language primitives that make it harder to identify problems, and while they are porting to Rust it's not fair to say that C++ is single-handedly the cause of this, because regardless of the language, in a complicated interconnected codebase the complexity easily compounds. It's a real shame we don't have the option of a trust-graph filter stop-gap that can filter contributors with a social model of who is trusted for what, purely as a heuristic to reduce the risk of bad contributions (not as solid proof of soundness). This whole situation shows the way that development has been done isn't nearly as transparent as just having the source code being available. We haven't been able to say what we want the code to do in a way that can be tested robustly enough to make openly accepting contributions sustainable, and it's unfair to blame the team for that because on top of needing to develop and review their own changes, it's an incredibly difficult problem with only so many hours in the day. I hope we figure out the representation and social trust graph problems, and that people continue to build on their great work. Bad actors pay good money for vulnerabilities and patient actors are invested in slowly introducing them. Agent loops like Codex or Claude, with Anthropic's Mythos model finding ~271 Firefox 0-days, and helping fix them shows both the problem and the promise. It's bitter-sweet in a way that Ladybird is great at showing how the incidental complexity of web browsers could be vastly reduced. To protest being gagged, cryptographers made t-shirts with DeCSS DVD or RSA algorithms on them. Alan Kay suggests that t-shirt computing is actually a useful target, and STEPS by his Viewpoints Research Institute managed to really distill some parts of OS-level and desktop publishing software down into minimal, more understandable abstractions that encode the rules of the programs with more appropriate patterns for the problems at hand, that might more plausibly fit on a small wardrobe of t-shirts. Browsers really need this range of t-shirts making. As a minority browser user (and someone wanting to build on them), I'm excited to see Ladybird get increasingly usable for real browsing, and I am hopeful that in time, the spec representation gaps, and social trust map heuristics are solvable problems that could restore the dream of open-source, or at least stop a trend of closing (with tldraw doing this much earlier, for a less risky but still thorny project).
- whalesalad 4mo agoI feel like every time I hear something about Ladybird its literally anything but a working browser to actually play around with.
- js8 4mo agoI am old enough to remember what happened to GCC. It was also developed by a closed group of maintainers, because "it couldn't work" as a bazaar-style development. Then EGCS fork happened and became more successful. I think closing contributions (due) to AI will be looked at in a similar way. Forks open to AI will appear, and take over. And people will return to the open model. I think it needs more proliferation of AI coding and reviewing tools, so that AI contributions can be automatically independently reviewed for quality.
- kjksf 4mo agoYou're extrapolating from an exception. EGCS was created because Cygnus, a company whose business was based on GCC, wasn't getting their patches to GCC, maintained by non-company FSF. Cygnus outcompeted FSF by so much that FSF folded and made EGCS maintainers new maintainers of GCC. I just don't see average open source project being forked and improved by so much that it eliminates the original. This requires 3 rare things to happen: - the project is important enough - the project is half-dead - someone is willing to out-compete the original project That won't happen to e.g. Laydbird. Yes, it's important but it's making rapid progress and they also use ai, so you can't outcompete them just using ai. It's a full-time project for at least one person (Andreas Kling) so unless you manage to find a band of great, unemployed programmers I don't see how you would compete.
- LeFantome 4mo agoI think 8 full-time people at this point.
- potsandpans 4mo ago[flagged]
- tarkin2 4mo agoThe rust conversion was a byte-for-byte replica of the original's bytecode, was it not? Thereby it was easily possible to validate the quality of the AI-based work. The same would obviously not be possible for patches. I don't believe you can use the rust conversion as a valid, if implied, argument that you can take AI-patches in good faith.
- wxw 4mo ago> For decades, code contributions have been how open source projects learned who to trust. People would show up, do the work, take responsibility for their changes, and stick around. Over time, trust emerged from the work itself. Trust is key.
- stainablesteel 4mo agoit's fair, especially because if people want to contribute to something so badly, they can make their own fork or version of it they can vibe-code their own browser, there's no need for the public to access every single open-source project anymore, you need to find people you can actually trust
- elgertam 4mo agoHaving read the blog post and then the comments here, I'm rather astonished. Do we understand our craft so little that our only realistic option is to ban LLMs (so-called AI)? Has everyone forgotten we've been in a software crisis for almost sixty years?[0] Have we so internalized the sweat-of-the-brow we've accumulated for decades that it's now part of the identity of being a programmer, and the only reliable signal of whether a contribution is beneficial? As far as I can tell, architecture, i.e. sound, precise definitions of exactly what a software artifact must do, is now critical. And with LLMs, it's now feasible to begin implementing such things, though many brownfield projects may be intrinsically unsound in ways that their creators are unaware of. In such a world, contributions simply require a modified proof that the software does what it must do, with perhaps additional claims that the maintainers provide. [0]https://en.wikipedia.org/wiki/Software_crisis https://en.wikipedia.org/wiki/Software_crisis
- sdsdffsddfs 4mo agoI believe the development world has a few cultural issues that make it hard to focus on the issues at hand. As a group we tend to not see the forest for the trees which causes us to worry about microscopic details while ignoring overwhelmingly more important realities, like, say, economics, lack of proper communication, team alignment, power hierarchies, etc. Being male-dominated has also not helped us for as far as I can tell the field, like many others, is dominated by power play, ego and identity issues. Everyone is trying to prove to everyone else how clever they are instead of cooperating properly. I can count on one hand the programmers I met that are actually humble and not just humble bragging. I myself am guilty of this arrogance. If we were at all competent we would have focused on the issues you mentioned. Architecture, intent, definitions, validation, actual proof that our work does what it needs to do. We didn't care because we were too busy showing ourselves and the people we look down on - the "suits" and other programmers using different styles/languages/frameworks - how superior we are and how clever we are that we can internalize and navigate Rust's syntax and C++'s foot-guns. Unfortunately, or perhaps fortunately depending on your perspective, I think that strategy is dying. It might be best for us to keep the eyes on the ball. What does the system need to do and how do we validate that it in fact does what it says on the tin? All the rest is noise and that includes "code". If a million monkeys on typewriters get the job done within acceptable parameters so be it.
- lionkor 4mo agoThat sucks, I would have hoped that they at least allow previous contributors to somehow make PRs still.
- sloum 4mo agoMeh. The project died for me when they started using LLMs for development in the first place.
- groan 4mo agoThese posts need a BPUF that calls out LLM-generated PRs. No need to read between the lines and wax poetic with walls of text.
- WolfeReader 4mo agoOpening lines: "Today we’re changing how code enters the Ladybird project. We will no longer accept public pull requests. From now on, code changes to the Ladybird codebase will only be introduced by project maintainers." Seems like a good bottom-line-up-front to me.
- fabon 4mo agoVery confusing statement. It is definitely true that OSS is on the verge of a crisis because of AI agents, but they clearly said AI is not the reason to reject external contributors: "Whether code was typed by hand is beside the point." If AI is the problem, the solution would be introducing an AI policy, community trust management system or something like that. Definitely not a closed development process.
- ajjenkins 4mo agoHow would they know for sure if the submitted code was written by a human or AI? If they had a “no-AI” policy, there would be no way to enforce it. The policy makes sense to me given the security concerns for the project.
- sambaumann 4mo agoThere's a big difference between a well considered high quality contribution made using AI as a tool and "claude find and fix an issue in this repo so I can put on my resume that I contributed to a high profile project". The problem is that it takes considerable time of the reviewers to filter out the high quality contributions vs the low quality ones. I do think closing off contributions is a big step and would rather most projects find a middle ground, but it's definitely understandable why they did this.
- gloomyday 4mo agoThis feels like a new phase for open source. I think screening people to join development efforts will become the norm, at least for resource-constrained projects. Trust will have to be earned.
- pengaru 4mo agoThe GenAI mess has delivered a new form of Eternal September[0] but for the software development communities. I wonder what it will be referred to as, after the dust settles? [0] https://en.wikipedia.org/wiki/Eternal_September https://en.wikipedia.org/wiki/Eternal_September
- sergiotapia 4mo agoOn the whole AI has been a destructive force.
- mvanveen 4mo agoI think from what I can understand about Serenity OS and Ladybird from afar and the kind of Cathedral culture that Andreas Kling values and feels Apple benefits from I'm not wholly surprised that the development of Ladybird took this course. What I am curious about as someone who has been kind of cheering off on the sidelines is if there's any way that folks could get involved still in the future or if this is in practice permanently a closed project? BSDs are more cathedral style and getting maintainer status is usually pretty onerous from what I understand but there are at least routes to it available to people willing to make an appropriate level of investment. I'm not at a point in my life where I can meaningfully provide that kind of time and energy into serenity or ladybird but if my circumstances changed it's the kind of open source project that I would love to dedicate my time and energy towards in the future and I'm sure I'm not alone in feeling that way.
- randyrand 4mo agoWhat is the process for becoming a maintainer? Without one they will slowly lose all maintainers by attrition.
- poopdick 4mo ago[dead]
- clhodapp 4mo agoIn the age of AI, perhaps it will be more common to see major forks of open-source projects emerge, with the upstream back-porting a few of the larger features themselves because they're impressed at what the fork is able to do, as opposed to the fork making PR's back into the upstream.
- chr15m 4mo agoBrevity is a more accurate indicator of effort than length. "I would have written a shorter letter, but I did not have the time." -- Pascal, 1657
- hypeatei 4mo agoI think there's a lot of confirmation bias in this thread coming from two groups: anti-AI activists and cathedral-development proponents. They take what was written at face value and use it to further their narratives that AI is ruining the world and "social coding" is unsustainable, respectively. What the Ladybird maintainers did here was messy and a punch in the gut to actual contributors who liked the project and the openness of it. There was no effort to shore things up, just a boilerplate message from a maintainer account then closing of your PR. Of course, Ladybird maintainers have no obligation to outside contributors but it shows a lack of grace nonetheless. Reading between the lines, there seems to have been a stark shift in attitude from Andreas which is concerning. Ladybird started from SerenityOS (a hobby OS) and he always encouraged everyone to submit a patch. Sure, LLMs have increased the amount of slop PRs, but I feel like those are easy to spot and close accordingly. I don't have links handy, but maintainers would point to a section about AI usage in their CONTRIBUTING.md then close the PR whenever obvious slop was submitted. This idea that people "own" the code they contribute is strange to me; the code would be determined worthy of acceptance at review time, why does someone have to "own" it? All that is to say: I think there's much darker things going on here and AI+security is a nice scapegoat. Time will tell, but this reeks of a rugpull in the future. Disappointing day.
- polysilicon 4mo agoI wasn't aware of the Ladybird project before this story, and probably would never have reason to use it. But it portends the beginning of the end of software collaboration and the community that goes along with it. If AI is going to do all the coding, then it becomes a pointless exercise. The software tools that we use today will be obsolete in a few years. Nevermind the need for a browser - the paradigm of the GUI desktop won't be necessary either. It will all be verbal instruction. The remaining programmers will just serve a caretaker role during the transition period until their services will no longer be necessary.
- cadamsdotcom 4mo agoThis is strictly worse than any of the alternatives. What should probably be done is PRs are treated as “reimplement requests”. “You had your agent write some code? Great, we’ll take it from here, and reimplement it ourselves.”
- sebazzz 4mo agoWhat I fail to understand: Who or how are these AI generated pull requests paid for? There is nothing to gain financially by creating all these AI generated pull requests - yet the increasingly more expensive tokens have to be paid for somehow. How is it paid for? Or are these authors using all their free GPT5.4-mini tokens from Github until hitting the rate limit, day after day? Or are they running some local AI model on their GPU like Qwen and heating the room in they work in, day after day?
- einpoklum 4mo agoI develop/maintain several a few small FOSS libraries. I've not received any AI-generated patches/PRs - that I know of, anyway - but I have always had a bias against people coming out of the blue with a PR, as opposed to: 1. Opening an issue. 2. Talking about what they want/need that's not catered to right now. 3. Asking for my thoughts or suggestions - even if they already have a potential PR to submit. and that is for a small codebase where changes are rarely that big of a deal in terms of amount of effort. I've gotten a few decent 'cold-submit' PRs as well, but my bias has usually borne out, in that these are usually PRs to reject, and only some of the time get adapted into something useful, following some back-and-forth of course. So, on the one hand, the measure the LB people are taking seems extreme to me; but the previous state of affairs they allude to seems equally weird. (I mean, unless it's a "here is a two-liner fix for a bug" kind of patches).
- boutell 4mo agoRecently I got a PR that is (1) genuinely correct and useful, and (2) not from someone who uses the software in question at all. A happy outcome, but clearly the economics of open source contribution have changed. Although I no way suspect this particular individual of anything untoward, of course it's always possible it could be part of one of the long-term goodwill-generation campaigns mentioned by the Ladybird team. Generating credibility by making seemingly difficult genuine contributions over a long period, then abusing that credibility. But in our particular project we're not in the habit of delegating approval authority, so I'm less concerned about that.
- deleted 4mo ago[deleted]