On 23.07.26 17:01, Ansgar 🙀 wrote:
You could add "a Debian contributor uses a LLM to find a highly critical bug in Debian's software and/or infrastructure" to the list.
The typical frontier LLM doesn't just find the bug, it also writes a patch and verifies that it actually fixes the problem.
… in theory. In practice it often doesn't, not yet anyway, but that's not my point.
> "a Debian contributor uses a LLM"This GR strongly discourages that … but what do I do (as a DD) when Somebody Else generates an LLM-generated patch that looks and feels sensible, might even have been vetted by others, and needs to be applied by me because it's my own software, or maybe 'cause Upstream is broken/lazy/compromised? Read it and update the source manually to look exactly the same? Read it and re-word everything so there's no[t much] AI content left? Not read it and fix the problem on my own? (History has shown that the latter practice is very likely to introduce a new problem instead.)
I guess the GR would forbid submitting or acting on such reports? Would we just leave the hole open?
Various people are going to let Mythos or Galaxy (the officially-unnamed better-than-Sol model from OpenAI that recently hacked HuggingFace; name coined by Zvi Mowshowitz <https://substack.com/@thezvi>) or whichever-frontier-model loose on **/d/patches/** and ask "does any of these introduce a security problem?" sooner or later, if they haven't done it already. Yes we can ask them not to do that, and we can more-or-less-strongly declare our unwillingness to look at those reports … but if there's any positive effect of doing so, I don't see it.
-- -- regards -- -- Matthias Urlichs
OpenPGP_signature.asc
Description: OpenPGP digital signature

