Hi,

* Simon Richter <[email protected]> [2026-07-25 02:11]:
On 7/23/26 20:12, Marc Haber wrote:

I still have to manually grep trough the sources of a package I maintain to manually create debian/copyright files instead of uploading the source package to an LLM asking for a debian/copyright file (and of course sampling whether the output makes sense)?

Yes, because otherwise you are offloading this work to the DFSG team.

I could name several uploaders who, at one time or another, "offloaded this work to the DFSG team" (or their mentoring DDs), long before LLMs were a thing.

On the other hand, I was curious and recently uploaded a non-trivial d/copyright file of one of my packages to Claude, gave him the GitHub URL of the upstream sources, and asked him to double-check that the copyright information was accurate, or suggest changes if not. After a few minutes, Claude came back with one nitpick and one genuinely missing copyright attribution.

I could have done this without Claude, sure. But I wouldn't have. It's boring, and the package in question is not going through NEW any time soon. If you ask me, this seems to be a reasonable thing to offload to an AI.

The problem with AI workflows is that they move the effort from the "writing" to the "reviewing" stage. Doing a proper review is more than "sampling" the output, so the "efficiency" gain of such an approach happens on the backs of other volunteers.

Generally, reviewing (and improving) things is easier than creating them from scratch. Sure, some people seem to think *less* effort means *zero* effort, thanks to the corporate marketing bullshit of AI companies who want to sell you access to their LLMs. But people can be educated to calibrate their trust better.

Going back to my example from before, I did not blindly assume that Claude was correct. But it was *much* easier now that I only had to look at 10 files instead of more than 10,000.

This is one of the main issues open source projects have with AI-generated submissions: it takes more work to review these than it took to generate them, in some cases even more work than writing the code by hand would have taken.

The role of the submitter then changes from a person *doing* work to a person *directing* the work of the volunteers -- basically, I can raise the priority of my wishlist bugs by simply feeding it to a prompt, and dumping the result into a PR. The actual work is then done by the maintainers in the time they reserved for onboarding new project members.

That sounds less like an AI problem and more like a priority problem.
Besides, PRs can be and historically often have been rejected on grounds of being too invasive or too hard to review.


Cheers
Timo

--
⢀⣴⠾⠻⢶⣦⠀   ╭────────────────────────────────────────────────────╮
⣾⠁⢠⠒⠀⣿⡁   │ Timo Röhling                                       │
⢿⡄⠘⠷⠚⠋⠀   │ 9B03 EBB9 8300 DF97 C2B1  23BF CC8C 6BDD 1403 F4CA │
⠈⠳⣄⠀⠀⠀⠀   ╰────────────────────────────────────────────────────╯

Attachment: signature.asc
Description: PGP signature

Reply via email to