Live data from Hacker News

Debian decides not to decide on AI-generated contributions

lwn.net

281–290 of 308 posts

Re: Debian decides not to decide on AI-generated contributions

#281

Earlier quoted context omitted.

> without a battle of ego. This resonates. Recently, I've started to consider Claude as a partner. I like how he's willing to accept he's wrong when you provide evidence. It can be more pleasant than working with humans.

Please don't anthropomorphize LLMs even further by assigning them gendered pronouns. LLMs are always "it"s. They're not alive, they're just really complicated linear algebra expressions. Prematurely anthropomorphizing them, even subtly like this, will come back to bite us if we keep doing it.

Can you defend that though? Does living mean needing cells? Does it mean possessing the ability to think and reason? Is Claude thinking and reasoning?

Re: Debian decides not to decide on AI-generated contributions

#282

Earlier quoted context omitted.

Every order of magnitude of difference constitutes a categorical difference. The ability to create spam instantly, fitted perfectly to any situation, and doing that 24/7, everywhere, is very different from before. Before, spam was annoying but generally different enough to tell apart. It was also (in general) never too much as to make an entire platform useless. With AI, the entire internet IS spam. No matter what yo…

And even if you figure out a reliable way to detect AI, guess what, USERS USE IT TOO for legitimate content, so you can't even use system like this. It's horrid

I tried to build something: https://github.com/YM2132/PR_guard which aims to help in these cases. It's not perfect but with stronger AI detection tools (Pangram) it could be improved although the issue of cost then arises and who pays for it.

Re: Debian decides not to decide on AI-generated contributions

#283
post #26

Very reasonable stance. I see reviewing and accepting a PR is a question of trust - you trust the submitter to have done the most he can for the PR to be correct and useful. Something might be required now as some people might think that just asking an LLM is "the most he can done", but it's not about using AI it's about being aware and responsible about using it.

Important though we generally assume few bad actors. But like the XZ attack, we kind of have to assume that advanced perissitant threats are a reality for FOSS too. I can envisage a Sybil attack where several seemingly disaparate contributors are actually one actor building a backdoor. Right now we have a disparity in that many contributors can use LLMs but the recieving projects aren't able to review them as effecti…

> LLM generated content often (perhaps by definition) seems acceptable to LLMs.

In my experience (albeit with non-coding questions), ChatGPT 5.2 is often quite eager to critique snippets of its own replies from previous conversations. And reasoning models can definitely find flaws in LLM-written code.

Re: Debian decides not to decide on AI-generated contributions

#284
post #91

My two cents: I've been coding practically my entire life, but a few years back I sustained a pretty significant and lasting injury to my wrists. As such, I have very little tolerance for typing. It's been quite a problem and made full time work impossible. With the advent of LLMs, AI-autocomplete, and agent-based development workflows, my ability to deliver reliable, high-quality code is restored and (arguably) bett…

>Personally, I love the "hallucinations" as they help me fine-tune my prompts, base instructions, and reinforce intentionality This reads almost like satire of an AI power user. Why would you like it when an LLM makes things up? Because you get to write more prompts? Wouldn't it be better if it just didn't do that? It's like saying "I love getting stuck in traffic because I get to drive longer!" Sorry but that one se…

I can’t say what the OP finds specifically useful but as an example if you’re aiming to make sure you’ve accurately and clearly documented / explained your intent, the misunderstandings and tangents AIs can go down are useful in the same way that putting your theoretically perfect UI into the hands of real users is also useful. It helps you want places where you assumed knowledge or understanding that someone else might not have.

Building up style guidelines for AI tools has been an eye opening experience in realizing how many stylistic choices we make that aren’t embedded in the linter, and aren’t documented anywhere else either. The resulting files have actually been a really good resource not just for the AI but for new developers on the project too.

It all depends on what your specific goal is.

Re: Debian decides not to decide on AI-generated contributions

#285

Concerns about the wasting of maintainer’s time, onboarding, or copyright, are of great interest to me from a policy perspective. But I find some of the debate around the quality of AI contributions to be odd. Quality should always be the responsibility of the person submitting changes. Whether a person used LLMs should not be a large concern if someone is acting in good-faith. If they submitted bad code, having used…

[deleted]

Re: Debian decides not to decide on AI-generated contributions

#286

Earlier quoted context omitted.

>So because some projects can absorb some PRs of a certain size, all projects of should be able to absorb PRs of that same size? Your argument has nothing to do with AI and more to do with PR size and 'fire and forget' feature merges. That's what the commenter your responding to is pointing out.

And my entire point is that LLM-generated feature requests are strongly correlated with high risk merge requests / pull requests, to which the commenter made no meaningful argument against. Instead the commenter chose to focus on the size of the PR and say “well I’ve seen it in the wild”. The way to get around this without getting all the LLM influencer bros in an uproar is to come up with a system that allows open s…

Maybe you'll agree with another post I made about how UX/processes already fail us here (without LLMs) and they should be improved: https://news.ycombinator.com/item?id=47324816

I think that's the only shot at progress since it can address the general problem instead of trying to special-case unenforceable rules that you hope the lowest quality people follow.

For example, a 3000+ line PR with no communication beforehand is already a low quality PR before AI. And it's one of the most annoying contributions to deal with since you have to basically tell them "sorry but all that work you did isn't acceptable". Yet they probably did all of it in earnest.

Presumably you already have a policy where you accept random PRs for small tweaks like doc fixes, but you don't want unsolicited PRs that make substantial changes. So a rule against AI doesn't change anything there.

And if you saw an uptick in large unsolicited PRs, then surely the solution is to update the process like disallow PRs that don't link to an issue.

Re: Debian decides not to decide on AI-generated contributions

#287
post #112

Earlier quoted context omitted.

You say "on a long enough timeline", but you already can't tell today in the hands of someone who knows what they're doing. I think a lot of anti-LLM opinions just come from interacting with the lowest effort LLM slop and someone not realizing that it's really a problem with a low value person behind it. It's why "no AI allowed" is pointless; high value contributors won't follow it because they know how to use it pro…

> high value contributors won't follow it High-value contributors follow the rules and social mores of the community they are contributing to. If they intentionally deceive others, they are not high-value.

This is a good example of my point.

Instead of progressing to a system resilient to the fact that you can't know how code was written, you've created a rule that, because it's unenforceable and deniable, must retreat to moralization about what someone does in private.

That might make you feel good, but it won't work.

Re: Debian decides not to decide on AI-generated contributions

#288

Earlier quoted context omitted.

>You're literally saying that the upsides of hallucinanigenic gifts are worth the downside of collapsing society. No, literally, he didn't.

Yes, I literally quoted it.

You quoted him and then put words into his mouth based on your own strongly held beliefs. Words he neither said nor implied.

Re: Debian decides not to decide on AI-generated contributions

#289
post #135

Earlier quoted context omitted.

>other people are reasonable like you No AI needed. Spam on the internet is a great example of the amount of unreasonable people on the internet. And for this I'll define unreasonable as "committing an action they would not want committed back at them". AI here is the final nail in the coffin that many sysadmins have been dealing with for decades. And that is that unreasonable actors are a type of asymmetric warfare…

Every order of magnitude of difference constitutes a categorical difference. The ability to create spam instantly, fitted perfectly to any situation, and doing that 24/7, everywhere, is very different from before. Before, spam was annoying but generally different enough to tell apart. It was also (in general) never too much as to make an entire platform useless. With AI, the entire internet IS spam. No matter what yo…

"The internet is super duper extra dead."

I get unreasonably angry when I read this statement, or similar ones.

If you mean "portions of the web I go to or my email inbox", you may be right.

But for the rest of us that hang out in one or multiple private spaces, sometimes with connections between them, the internet is better connected and easier to find people, groups, information, and interests than ever before.

Re: Debian decides not to decide on AI-generated contributions

#290

Good decision. The two extremes of this decision are both bad. On one hand the status quo of a lot of slop demanding attention from busy people is just not sustainable and something has to change. But throwing out the baby with the bath water by just blanket banning all forms of AI contributions is not a long term sustainable solution. It's a stop gap solution at best. And one that would be challenged more and more a…

> The right way might be to fight AI slop with AI enforced guard rails. Whenever I you tried to develop using guardrails with LLMs, I found out that they are much better at ,,cheating'' than a human: getting around the guardrails by creating the ugliest hacks around them.

Mostly works for me. Most of my projects I have some guardrails for what to do around testing, deploying, etc. Seems to work. You are right that LLMs are good at avoiding work and finding loopholes to do so. But generally if you ask codex to "hey look at my gh prs and label the ones that don't meet the contributor guidelines with 'slop'" it might do a decent enough job. Maybe add a skill that spells out criteria. Maybe set up openclaw or similar to do this every morning and then give you the list of prs it will auto close after you say the word.
Post reply on HN