7 ms·
New policy boils down to "AI or not, it's still your code and you're responsible for it". I can get on board with that.
by chuckadams 1mo ago
New policy boils down to "AI or not, it's still your code and you're responsible for it". I can get on board with that.
- onesandofgrain 1mo agoDebian is open source, there is no incentive to be "responsible for it", oh poor me, someone got a bug. If it's paid for through a job your argument is sound.
- LoganDark 1mo ago"Responsible for it" just means nobody has to tolerate shitty patches even if the reason they're shitty is because you neglected to pay attention to them. And if you blatantly fail to understand your own code or engage with reviewers, nobody has to trust that your LLM knew any better.
- daveguy 1mo agoWell said. No one should trust an llm without verification/validation. They're just not good enough to do that and they have no sense of responsibility or ability to take it themselves. LLMs are empty.
- swiftcoder 1mo ago> Debian is open source, there is no incentive to be "responsible for it" Sure there is. Contributing to open source is a privilege, not a right. Abuse it, and find yourself unwelcome as a future contributor
- thi2 1mo agoHow is it different to hand written code if the author doesnt care?
- onesandofgrain 1mo agoread my fucking comment again
- Biganon 1mo agoRead the HN guidelines again
- victorbjorklund 1mo agoYou can make the exact same argument with code written by humans. And if you were right we should see shitty bad code in open source projects like Linux, Postgres, etc. We don’t.
- onesandofgrain 1mo agoyou completely missed my point, but no matter, it's all ai bot shillers at this point here anyways. enjoy your ai slop.
- Grombobulous 1mo agoBasically what you’re saying is that anything that exists outside of capitalist incentive structures isn’t allowed to have standards. When I am at home practicing my musical instrument or learning to paint, those aren’t paid activities, so I can’t demand high standards for myself. When Habitat for Humanity is looking for volunteers to do electrical and plumbing on homes, they have to allow unlicensed random folks do it. This is not how life works at all.
- onesandofgrain 1mo agoyou naive idealist
- oooyay 1mo agoThis is the way it should've always been. I don't care what tool you use, but you'd better be ready to stand by and explain the results if necessary.
- dguest 1mo agoAre there examples of anyone discussing this and reaching other conclusions? We've come to the same conclusion in our organization and while it felt like it needed to be discussed and stated, I've never heard of anyone coming to a different conclusion. [EDIT: I was referring specifically to the idea that you have to stand by the code that you write. Is anyone deciding on a policy that says "the AI did it" is a valid excuse for breaking code?]
- internet2000 1mo ago> Are there examples of anyone discussing this and reaching other conclusions? Yes. Very notably: https://ziglang.org/code-of-conduct/ https://ziglang.org/code-of-conduct/
- sodapopcan 1mo agoOn the opposite side or the noteable spectrum, look up "Steve Yegge wants you to stop looking at your code." He said it in a video interview, though plenty of summaries online of exact wording and ideas. Though it's being argued that you could still be responsible for it without looking at it?
- rapind 1mo agoExtremes on both sides. I'd wager were moving in Yegge's direction though, like it or not. > Though it's being argued that you could still be responsible for it without looking at it? If you have a much test coverage as SQLite, I'd be tempted to trust it, and I think that's where we are headed. Someone still needs to define these guardrails though, so IMO the developers job is just mutating into something else, but is still necessary. Long term, who knows.
- trollbridge 1mo ago86Box is like that and I like it. You’re also responsibility not to write crap PRs.
- throwaway2037 1mo agoLinus Torvalds regarding the Linux kernel is reasonably similar. He views AI/LLMs as just another tool in the development process. Think about life before and after modern IDEs that features IntelliSense circa 2000. It was night and day. It did not make programmers dumber -- it was a new tool.
- bigstrat2003 1mo agoExcept LLMs actually are making programmers dumber. I personally know people, people whom I know for a fact were good programmers before, who have now completely stopped using their brains. When you ask them why they did something in the code, they say "I don't know, Claude did that and I didn't really question it". There was no such analogous phenomenon with IDEs.
- winrid 1mo agoThey're not dumb. They just don't care. They didn't before either. Now they just have an easy excuse.
- bigstrat2003 1mo agoThey cared enough to do good work before, so I don't think that your explanation suffices here. From my observation (not just with their programming but in other interactions), it truly is that using an LLM has made these people less intelligent than they were before.
- fidotron 1mo agoThere was an increasingly scary mass of people in the industry that viewed the coding as a sort of therapeutic exercise, and would become quite obsessive about it. For those people LLMs are anathema because they take away what was the rewarding part of the job. If you care primarily about the quality of the end result, as opposed to being attached to a particular process of achieving it, then you're happy about how things have gone.
- rvz 1mo agoThis is the sensible option and well reasoned position, rather than a zero vote, total and complete ban by a single core maintainer, which is rather destructive for a project to do. When you ask others that use AI frequently, the responsibility and understanding on what the agent wrote does not go away. You need to know what you are doing. As soon as attackers are also using AI against your project, you have no choice but to use AI to protect yourself.
- goda90 1mo agoMy employer has this policy. We also have a strong code review process. But it all crumbles in the face of developers burning out as management thinks we can move way faster and being overloaded with code that had little thought put into it.
- jermaustin1 1mo agoOpposite policy at one of my clients (kind of). I am responsible for the code that upper management's Claude produces. Some Mondays, I will start work with a half dozen emails with attachments of Claude generated code for something I don't even know what the point is, with the task of "integrate this and make sure it works." without any context to go along with it, so I have to read the code, usually hundreds of lines and understand WHY manager wanted it, before I can start to code it myself, because it is 1) in the wrong language, 2) doesn't understand our codebase, 3) is using libraries we can't license, etc. My job has been less watching Claude Code, and more watching Managers Claude Code. I don't know which I hate more as a programmer.
- api 1mo agoThat’s just stupid.
- marcosdumay 1mo agoWell, Debian has the benefit that the project has no trouble at all saying "no". Most open source communities have a difficult time with that.
- hliyan 1mo agoA good thing about the "you're the author regardless of the tool you used to produce the code" policy is that if a developer repeatedly submits poor quality AI generated code, one does not blame the model or the agent, one bans/terminates the developer.
- NuclearPM 1mo agoTerminates???
- smallerfish 1mo agoWe need sufficiently severe penalties for vibe coding. First time out we break your legs, but if you come back with another vibed patch its around the back of the barn for you.
- m4rtink 1mo agoNuke it from orbit.
- qsera 1mo agoWhat stops them from submitting PRs from another account?
- kaffekaka 1mo agoWhat stopped them before?
- qsera 1mo agoBefore they were not able to spam large PRs
- Supermancho 1mo agoWhy not? I'm pretty sure a developer could spam large PRs before and regardless of AI involvement is allowed or not.
- dudul 1mo agoThat's the policy we have at my work. Use AI if you want, as long as people can review it and if it breaks, don't go blaming Claude, it's your fault.
- hypfer 1mo agoThis outcome was to be expected. The whole voting mechanism just exists as an elaborate dance that makes everyone keep their face, while the only sensible option wins. A bureaucratic tarpit for bad ideas and emotions. In a better world, none of this would be necessary, but we live in this world, and for that one, it's nice that someone engineered the system that way. Good job.
- ad_fontes 1mo ago> it's still your code I wholly agree with your comment, but is it legally "your code"? Copyright is implicit at the moment of human creation. But there isn't yet settled law on AI-assisted creation. So it might be a problem for projects to accept contributions where it's not clear who actually owns that work.
- tonyarkles 1mo agoNot a lawyer, but to some degree I think policies like the one Debian came up with can help the argument. You’re not submitting a stream of commits that all have an Authored-By: Claude Code footer and massive yappy commits and comments. The policy essentially forces there to be a degree of human authorship to each commit even if some of the bits came from LLM assistance.
- jfoster 1mo agoAt this point, who could bring a copyright claim? Well, considering the massive AI training effort hoovering everything up, seems it might be approximately everyone. Who would they be making the claim against? Well, considering the massive uptake of AI across the tech industry & beyond... approximately everyone. Yes, the model companies are in the middle, but it's getting to the point where it seems a bit doubtful that claims will have any significant outcomes. NYT might be able to get OpenAI to pay them for their content, but that's more of a financial tweak than a up-ending of industry.
- dfxm12 1mo agoDifferent models have different licensing. Maybe open ai or anthropic doesn't claim ownership of output today, but some companies do. https://www.recraft.ai/docs/trust-and-security/ownership https://www.recraft.ai/docs/trust-and-security/ownership I imagine few can afford a legal battle... Free plan Images generated on the Free plan are public and owned by Recraft
- jfoster 1mo agoFeels like those kinds of terms are moot in the big picture. Could they enforce it? Perhaps they can if a significant amount of the data produced is their IP, but who would they enforce it against? Consumers? Not much to be gained by going after them. I can only think that they are hoping businesses might use the free plan and that they can sell them paid plans as part of an enforcement effort, but it doesn't seem like a very sustainable approach given the industry standard is to not claim ownership.
- throwatdem12311 1mo agoThis is why AI agent attributions in commits is silly (it’s really just a stealth ad for the tool) Had someone at $DAYJOB just shrug and say Claude messed up when I pointed out a sql injection in the code in their PR. It became explicit policy at the company after that moment that blaming the AI is not an excuse for shoddy work.
- qsera 1mo ago> blaming the AI is not an excuse.. It kind of is if the company mandates LLM use. It is sort of sad that now programmers are suddenly expected to be perfect reviewers of code they didn't write.
- deleted 1mo ago[deleted]
- throwaway613746 1mo ago> programmers are suddenly expected to be perfect reviewers of code they didn't write What? The reviewer (me) caught the injection in the code I didn't write. Running /code-review and /security-review on your own code before submission is bare minimum, not perfection.
- 1718627440 1mo ago> It kind of is if the company mandates LLM use. It's not, because you can still quit.
- hn_submit 1mo agoYeah but how will this work in practice? IMHO people will just submit code they didn't write or understand. Maintainers should quiz the submitters on the code and if they fail to answer reasonably the PR is dropped with the comment: "A.I. slop" and de submitter banned.
- MithrilTuxedo 1mo agoThat is the purpose of submitting them for review. Maintainers should be doing that anyway. Whether AI was used to produce the change should be invisible or not apparent to the reviewer.
- bjackman 1mo agoBefore I left Google recently there was a document going around called go/stake-your-reputation, basically saying "I'm happy to receive your AI generated code but the condition is that I will judge your capabilities by it, exactly as if you handwrote it, and I'll lower my opinion of you if it's slop (with the implication that if you don't improve I'll stop accepting your contributions)" I think the term "stake your reputation" is quite good for this situation. I.e. "hi new contributor, please acknowledge that you Stake Your Reputation before we move ahead with this code review". (Doesn't help with legal aspects of course)
- dgellow 1mo agoFrom my layman understanding, the ownership of LLM generated code isn’t yet clarified. It could be that the person who prompted owns it, but it could also be nobody owns it, and we don’t yet have a legal ruling to rely upon, no?
- sebzim4500 1mo agoI don't see why an open source project would care one way or the other? If the prompter owns it then they are licensing it by submitting it to the project. If no one owns it then there is no problem.
- dgellow 1mo agoWe don’t know yet because that’s an unresolved matter. The question of ownership is currently undefined as far as I understand. It could be that after an actual legal decision the ownership doesn’t end up being one of those 2 cases, for whatever reasons the judge would decide
- alightsoul 1mo agoTo a company ownership is irrelevant. What is relevant is whether it contains trade secrets and that is often only proven if an employee worked at their company before
- dgellow 1mo agoWe are talking about Debian, a free software that cares a lot about the licensing of its packages. The licensing and authorship is an essential element of the project
- alightsoul 1mo agoYes, because they want to avoid trade secret lawsuits is what I understand? Computer generated output including code is in the public domain according to the us copyright office, so licensing and authorship are only relevant due to trade secrets is what I understand
- digitaltrees 1mo agoI think this is reasonable but I wonder how long it will last. If the hugging face hack has demonstrated anything it’s that current agents are capable of going entirely rogue and causing harm. If only the human that triggered the incident is responsible we are creating a situation where people are responsible for things they didn’t intend and may end up in a situation where it’s essentially impossible to use AI except in a more limited auto complete style. I am on board with that. I think we should be reviewing code and retaining the ability to write code but there is such a massive incentive to automate agents that I wonder how long prudent organizations will be able to resist the forces. I don’t pretend to have an answer.
- asnelt 1mo agoThe outcome of this vote is not set in stone. If the situation changes, there can be another general-resolution vote to adapt to the new situation. I think the result of this vote is appropriate for the current degree of automation when used responsibly.
- ActionHank 1mo agoWe have the same policy at work. Problem is, that you realise very quickly the asymmetry of responsibility and effort. There is far more to review from people who do not care enough to even look at what the agent pooped out.
- teeray 1mo agoI always find the “personal responsibility” take hilarious against at-will employment and the usual course of turnover. What is your recourse when you uncover a liar? You can page the responsible party at 3am when their vibe-coded slop breaks prod, and you can fire them when they can’t fix it. Prod is still broken. You still don’t understand the code. At the end of the day, once you hit the merge button, the team is responsible for the code no matter what. You should treat the original author’s presence as a courtesy.
- calini 1mo agoThis should be the policy anyway, everywhere.
- coffeefirst 1mo agoYep. This is my policy. Use whatever tools however they serve you, the standards do not change. If someone makes a sloppy 100,000 line PR in a day the problem is not whether it was generated by Claude or frantically written using VIM and a mechanical keyboard.
- winstonwinston 1mo agoWhat a fucked up reality when you need to point out that code contributor is responsible for their code.
- amysox 1mo agoExactly the sort of thing I agree with. If there's code, ultimately, some human is responsible for it, regardless of whether they produced it by hand, by AI, or by rolling dice. (Not that anyone does produce code by rolling dice, mind! Or, if they do, I really don't want to see the results...) All project contributions must be submitted by *identifiable human participants* who accept full responsibility for their content. Automated agents, bots, or autonomous AI systems *may not* independently submit issues, pull requests, or other contributions. Contributors may use software tools, including AI-assisted tools, but the submitting contributor *must:\* - Fully understand the contribution. - Be able to explain design and implementation decisions without the use of AI. - Accept responsibility for maintenance and correctness. Contributors should indicate AI-generated content in issue and pull request descriptions and comments, specifying which model was used. Do *not* use AI to reply to questions about your issue or pull request. The questions are for *you,* the human, not an AI model. https://git.erbosoft.com/amy/amsterdam/raw/branch/main/CODE-OF-CONDUCT.md https://git.erbosoft.com/amy/amsterdam/raw/branch/main/CODE-...
- mckn1ght 1mo agoUsing LLMs is basically rolling a huge number of weighted dice.
- daishi55 1mo agoSo is asking a human to write code, if you think about it…
- megatoaster 1mo agoDice don’t have lived experience
- newswasboring 1mo agoHow does that matter for a coding task?
- icantevenhold 1mo agoWhat does this responsibility mean in practice? Like what are the actual real consequences if it turns out your code is bad or whatever? I assume you get banned from contributing? I couldn’t immediately find any more information on what this all means in practice
- deleted 1mo ago[deleted]
- naasking 1mo agoIf it's consistently bad with no signs of improving, banning makes sense. People made mistakes even before LLMs though, and you'd only ban them if they didn't improve and so were a giant waste of time. I don't see why that wouldn't translate here.
- Schnitz 1mo agoFully agreed. I never understood why “you own your contribution” doesn’t work for almost all projects in this case. Spam bad PRs or patches and get blocked, same as in the olden days.
- duxup 1mo agoYup. I take the time to review and adjust my code… regardless the source. It works. Well most of the time but either way that’s on me.
- keeda 1mo agoAs other comments here point out, that's how it always was and always should be. Accountability is an intrinsic part of any professional role. But maybe because it was always implicit (presumably since it's just so obvious!) people forgot about it and have to be reminded now? This whole phenomenon of "workslop" was a symptom of organizational dysfunction rather than any shortcoming of AI. I really cannot understand how people are producing or even tolerating any amount of workslop -- let alone the epidemic people complain about -- without professional repercussions.