Hi,

On Wed, 2026-07-29 at 01:50 +0100, Steve McIntyre wrote:
> On Mon, Jul 27, 2026 at 11:48:55PM +0200, Marc Haber wrote:
> > On Mon, Jul 27, 2026 at 02:44:56PM +0100, Ian Jackson wrote:
> 
> ...
> 
> > > If someone were to file an LLM-generated bug report, or MR, or
> > > something, we would probably close it, stating this (package-specific)
> > > policy.
> > 
> > By ignoring a valid bug report, you're violating the social contract which
> > says that our focus is on our users.
> 
> That's another can of worms. Nowhere in the social contract do we
> promise any focus on interacting with AI bots. Would you want to force
> people to spend time on dealing with the kind of slop "bug reports"
> that the curl project has been infamously dealing with?

And since you mention the curl project, let me also add this quote from
LWN about that:

+---
| Two months later, Stenberg is now spending hours per day looking
| at ""really good"" LLM-generated security reports. He finds it hard
| to complain about the workload when the reports point out real
| security problems, but the high volume of reports causes its own
| problems.
+---[ https://lwn.net/Articles/1066581/ ]

You can also look at reports about LLMs reporting security issues in
the kernel, Mozilla ("Suddenly, the bugs are very good" [1]), and so
on. This paints a very different picture than what is implied by issues
"that the curl project has been infamously dealing with".

It feels disingenuous to mention the problems the curl project had in
the past without mentioning that the situation changed significantly
since then. For policy decisions about present and future we should
consider current, not past, LLM capabilities and their likely future
development. At the very least, these capabilities are unlikely to
decrease.

Note that the GR is not limited to forbidding use of obsolete models.

And no, I don't have a problem with expecting maintainers to deal with
high-quality bug reports.

Ansgar

  [1]: https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/

Reply via email to