Re: Claude AI code audit of GNUstep core stack — 1 50 fixes, 12 perf optimizations, all available for upstream
Gregory Casamento <[email protected]> Wed, 29 Jul 2026 10:53:07 -0400
| Newsgroups | gmane.comp.lib.gnustep.devel |
|---|---|
| Message-ID | <CA+BLX-yybk63xxb=ZD=sFfgagjm8OjGg0Q=nEP_Dz3gWu=8+cw@mail.gmail.com> |
--000000000000a180c60657c11e84 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable GCC released their AI-Policy... it is not terribly different from ours and aligns pretty closely. There are a few areas of divergence: Their policy follows... this is available at https://forge.sourceware.org/redi/gcc-wwwdocs/raw/commit/4d0793a6a14bf9bfe9= e92ac1599840780355199d/htdocs/ai-policy.html GNU Compiler Collection - AI PolicyCommunity First First, all contributors should be treated with respect and kindness <https://gcc.gnu.org/conduct.html>. There are strongly held and widely varying opinions regarding large language models (LLMs) and everyone should be presumed to be contributing in good faith. We welcome all contributors to the community even if they have not yet followed our policies; we should guide such contributors on how to do so. Acceptable Contributions For the time being, the GNU Compiler Collection (GCC) policy is to decline any legally significant <https://www.gnu.org/prep/maintain/maintain.html#Legally-Significant> contributions which include LLM-generated content or are derived from LLM-generated content. The GCC maintainers are free to accept legally insignificant <https://www.gnu.org/prep/maintain/maintain.html#Legally-Significant> contributions generated by an LLM as long as they meet the usual prerequisites <https://gcc.gnu.org/contribute.html> for any contribution and the contribution is clearly marked. As an exception, the GCC maintainers are free to accept *legally significant* <https://www.gnu.org/prep/maintain/maintain.html#Legally-Significant> contributions to *test cases*, generated in whole or in part by an LLM. This policy does not apply to code which does not primarily belong to the GCC project, but is imported from other projects for convenience or to satisfy prerequisites (e.g. libsanitizer). Transparency & Accountability The commit message for any contribution of LLM-generated content must include an =E2=80=9CAssisted-by:=E2=80=9D tag. All contributions must be submitted by a human who understands the changes and is prepared to answer questions about them. The decision to include the contribution in the project must also be made by a human. Only a human may provide the =E2=80=9CSigned-off-by:=E2=80=9D tag certifying the Developer C= ertificate of Origin (DCO) <https://developercertificate.org/>. An LLM may not commit code to the project repository. Personal Use This policy does not apply to a contributor's other uses of AI including the use of these tools to enable them to work with their own computing devices e.g. screen readers, text-to-speech, direct translations, spelling or grammar assistance, where the contributor verifies the output of the tool. This policy does not apply to a contributor's use of AI for the purposes of research, analysis, bug discovery and reporting (output should not be sent verbatim without due consideration), patch review (supporting human review, not replacing it) and debugging, so long as the output is not included in the contributions to the project. If the output is included in the contributions to the project then this policy would apply. Next Steps This policy is expected to evolve with the community or as the overall GNU Project position is updated. At the latest the policy will be reviewed at the start of 2027. This work is marked CC0 1.0 Universal <https://creativecommons.org/publicdomain/zero/1.0/> To Summarize: GNUstep's approach is outcome-based: contributions are judged on licensing, provenance, quality, correctness, maintainability, and human review regardless of the tools used to create them. GCC's approach is process-based for legally significant contributions: AI-generated code is declined because of legal and provenance concerns, even if the resulting code would otherwise satisfy the project's technical standards. This seems fairly closely aligned with our approach with the exception of code that is wholly generated by an LLM. Our approach emphasizes caution in this case and, during our discussion, I recommended not accepting this kind of contribution. We are not bound by GCC's policy, and I recommend we review ours as it becomes necessary as well. Yours, GC On Sat, Jul 18, 2026 at 12:23=E2=80=AFPM Gregory Casamento <greg.casamento@= gmail.com> wrote: > Lars, > > I don't know how the GNU Project is arriving at its policy or whether > individual GNU projects have an opportunity to provide input. I have > written to RMS about our policy and given him a link to it. I hope it ca= n > inform any decision they make. > > I don't think the discussion should become a witch hunt either. AI is a > tool, and like any tool, it can be used well or poorly. Regardless of how > code is produced, I believe our responsibility as maintainers remains the > same: to ensure that contributions meet our standards for licensing, > provenance, quality, correctness, maintainability, and review. > > Ultimately, those standards are what determine whether code belongs in > GNUstep, not the particular tools used during its development. > > I'm hoping the GNU Project reaches a thoughtful and balanced conclusion. > > Yours, Greg > > On Sat, Jul 18, 2026 at 5:00=E2=80=AFAM [email protected]= e < > [email protected]> wrote: > >> Hi Greg, >> >> just one question in this regard: Do we have a voice in GNU=E2=80=99s di= scussion >> on that topic (I hope, there is a discussion an not just a decision by o= ne >> person, namely RMS)? If so, I hope, we make our standpoint clear and don= =E2=80=99t >> go onto a witch-hunt against AI (which would be like a witch hunt agains= t >> compilers and linkers in the times when UNIX was still written in >> assembler). In my opinion AI is just a (very sophisticated) tool which y= ou >> need to know, how to use it and its limitations. Then we can use it sane= ly >> and to our advantage. >> >> Hoping for the best outcome, >> >> Lars >> >> Am 18.07.2026 um 10:23 schrieb Gregory Casamento < >> [email protected]>: >> >> David, >> >> Sorry for the late reply; work has been very demanding lately. Of >> course, any policy they issue will apply to us. I think this is a >> reasonable approach for EMACS if they are waiting for guidance from the = GNU >> Project. >> >> Until that policy is published, however, I don't think it gives us any >> basis for changing GNUstep's existing approach. Once the GNU Project has >> issued its guidance, we can evaluate it on its merits, determine whether >> and how it applies to GNUstep, and discuss whether any changes are >> warranted. >> >> I believe our current policy provides a practical balance as it focuses >> on licensing, provenance, code quality, review, and maintainability rath= er >> than the specific tools contributors use. >> >> As mentioned in previous emails, I have set a clear line on what is >> acceptable, and this was reflected in the discussion a few weeks ago. >> >> Yours, GC >> >> On Wed, Jul 15, 2026 at 4:31=E2=80=AFAM David Chisnall <gnustep@theraven= snest.org> >> wrote: >> >>> On 14 Jul 2026, at 22:48, Gregory Casamento <[email protected]> >>> wrote: >>> > >>> > Based on the discussion, I do not see sufficient consensus or >>> justification to replace our existing AI policy with a "No-AI" policy f= or >>> the GNUstep core libraries. Accordingly, the existing policy will remai= n in >>> effect. >>> >>> Most of the arguments have been covered in other places and it=E2=80=99= s quite >>> surprising that most of the folks in this thread seem unfamiliar with t= hem, >>> but I would add one thing: >>> >>> This week, EMACS paused =E2=80=98AI=E2=80=99 contributions because the = GNU project is >>> expected to provide an explicit policy soon. I presume that policy will >>> apply to GNUstep as well. >>> >>> David >>> >>> >> >> -- >> Gregory Casamento >> GNUstep Lead Developer / Black Lotus, Principal Consultant >> http://www.gnustep.org - http://heronsperch.blogspot.com >> https://www.openhub.net/languages/objective_c >> >> >> > > -- > Gregory Casamento > GNUstep Lead Developer / Black Lotus, Principal Consultant > http://www.gnustep.org - http://heronsperch.blogspot.com > https://www.openhub.net/languages/objective_c > --=20 Gregory Casamento GNUstep Lead Developer / Black Lotus, Principal Consultant http://www.gnustep.org - http://heronsperch.blogspot.com https://www.openhub.net/languages/objective_c --000000000000a180c60657c11e84 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:monospac= e,monospace">GCC released their AI-Policy... it is not terribly different f= rom ours and aligns pretty closely.=C2=A0 There are a few areas of divergen= ce:</div><div class=3D"gmail_default" style=3D"font-family:monospace,monosp= ace"><br></div><div class=3D"gmail_default" style=3D"font-family:monospace,= monospace">Their policy follows...=C2=A0 this is available at=C2=A0<a href= =3D"https://forge.sourceware.org/redi/gcc-wwwdocs/raw/commit/4d0793a6a14bf9= bfe9e92ac1599840780355199d/htdocs/ai-policy.html">https://forge.sourceware.= org/redi/gcc-wwwdocs/raw/commit/4d0793a6a14bf9bfe9e92ac1599840780355199d/ht= docs/ai-policy.html</a></div><div class=3D"gmail_default" style=3D"font-fam= ily:monospace,monospace"><h1 style=3D"color:darkslategray;text-align:center= ;font-family:Times">GNU Compiler Collection - AI Policy</h1><h2 style=3D"co= lor:darkslategray;font-family:Times">Community First</h2><p style=3D"color:= rgb(0,0,0);font-family:Times;font-size:medium">First, all contributors shou= ld be treated=C2=A0<a href=3D"https://gcc.gnu.org/conduct.html" style=3D"co= lor:rgb(0,102,187);text-decoration:none">with respect and kindness</a>. The= re are strongly held and widely varying opinions regarding large language m= odels (LLMs) and everyone should be presumed to be contributing in good fai= th. We welcome all contributors to the community even if they have not yet = followed our policies; we should guide such contributors on how to do so.</= p><h2 style=3D"color:darkslategray;font-family:Times">Acceptable Contributi= ons</h2><p style=3D"color:rgb(0,0,0);font-family:Times;font-size:medium">Fo= r the time being, the GNU Compiler Collection (GCC) policy is to decline an= y=C2=A0<a href=3D"https://www.gnu.org/prep/maintain/maintain.html#Legally-S= ignificant" style=3D"color:rgb(0,102,187);text-decoration:none">legally sig= nificant</a>=C2=A0contributions which include LLM-generated content or are = derived from LLM-generated content.</p><p style=3D"color:rgb(0,0,0);font-fa= mily:Times;font-size:medium">The GCC maintainers are free to accept=C2=A0<a= href=3D"https://www.gnu.org/prep/maintain/maintain.html#Legally-Significan= t" style=3D"color:rgb(0,102,187);text-decoration:none">legally insignifican= t</a>=C2=A0contributions generated by an LLM as long as they meet=C2=A0<a h= ref=3D"https://gcc.gnu.org/contribute.html" style=3D"color:rgb(0,102,187);t= ext-decoration:none">the usual prerequisites</a>=C2=A0for any contribution = and the contribution is clearly marked.</p><p style=3D"color:rgb(0,0,0);fon= t-family:Times;font-size:medium">As an exception, the GCC maintainers are f= ree to accept=C2=A0<a href=3D"https://www.gnu.org/prep/maintain/maintain.ht= ml#Legally-Significant" style=3D"color:rgb(0,102,187);text-decoration:none"= ><em>legally significant</em></a>=C2=A0contributions to=C2=A0<strong>test c= ases</strong>, generated in whole or in part by an LLM.</p><p style=3D"colo= r:rgb(0,0,0);font-family:Times;font-size:medium">This policy does not apply= to code which does not primarily belong to the GCC project, but is importe= d from other projects for convenience or to satisfy prerequisites (e.g. lib= sanitizer).</p><h2 style=3D"color:darkslategray;font-family:Times">Transpar= ency & Accountability</h2><p style=3D"color:rgb(0,0,0);font-family:Time= s;font-size:medium">The commit message for any contribution of LLM-generate= d content must include an =E2=80=9CAssisted-by:=E2=80=9D tag.</p><p style= =3D"color:rgb(0,0,0);font-family:Times;font-size:medium">All contributions = must be submitted by a human who understands the changes and is prepared to= answer questions about them. The decision to include the contribution in t= he project must also be made by a human. Only a human may provide the =E2= =80=9CSigned-off-by:=E2=80=9D tag certifying the=C2=A0<a href=3D"https://de= velopercertificate.org/" style=3D"color:rgb(0,102,187);text-decoration:none= ">Developer Certificate of Origin (DCO)</a>. An LLM may not commit code to = the project repository.</p><h2 style=3D"color:darkslategray;font-family:Tim= es">Personal Use</h2><p style=3D"color:rgb(0,0,0);font-family:Times;font-si= ze:medium">This policy does not apply to a contributor's other uses of = AI including the use of these tools to enable them to work with their own c= omputing devices e.g. screen readers, text-to-speech, direct translations, = spelling or grammar assistance, where the contributor verifies the output o= f the tool.</p><p style=3D"color:rgb(0,0,0);font-family:Times;font-size:med= ium">This policy does not apply to a contributor's use of AI for the pu= rposes of research, analysis, bug discovery and reporting (output should no= t be sent verbatim without due consideration), patch review (supporting hum= an review, not replacing it) and debugging, so long as the output is not in= cluded in the contributions to the project. If the output is included in th= e contributions to the project then this policy would apply.</p><h2 style= =3D"color:darkslategray;font-family:Times">Next Steps</h2><p style=3D"color= :rgb(0,0,0);font-family:Times;font-size:medium">This policy is expected to = evolve with the community or as the overall GNU Project position is updated= . At the latest the policy will be reviewed at the start of 2027.</p><p sty= le=3D"color:rgb(0,0,0);font-family:Times;font-size:medium">This work is mar= ked=C2=A0<a href=3D"https://creativecommons.org/publicdomain/zero/1.0/" sty= le=3D"color:rgb(0,102,187);text-decoration:none">CC0 1.0 Universal</a></p><= /div><div class=3D"gmail_default" style=3D"font-family:monospace,monospace"= >To Summarize:</div><div class=3D"gmail_default" style=3D"font-family:monos= pace,monospace"><br></div><div class=3D"gmail_default" style=3D"font-family= :monospace,monospace">GNUstep's approach is outcome-based: contribution= s are judged on licensing, provenance, quality, correctness, maintainabilit= y, and human review regardless of the tools used to create them. GCC's = approach is process-based for legally significant contributions: AI-generat= ed code is declined because of legal and provenance concerns, even if the r= esulting code would otherwise satisfy the project's technical standards= .</div><div class=3D"gmail_default" style=3D"font-family:monospace,monospac= e"><br></div><div class=3D"gmail_default" style=3D"font-family:monospace,mo= nospace">This seems fairly closely aligned with our approach with the excep= tion of code that is wholly generated by an LLM.=C2=A0 Our approach emphasi= zes caution in this case and, during our discussion, I recommended not acce= pting this kind of contribution.=C2=A0 We are not bound by GCC's policy= , and I recommend we review ours as it becomes necessary as well.</div><div= class=3D"gmail_default" style=3D"font-family:monospace,monospace"><br></di= v><div class=3D"gmail_default" style=3D"font-family:monospace,monospace">Yo= urs, GC</div></div><br><div class=3D"gmail_quote gmail_quote_container"><di= v dir=3D"ltr" class=3D"gmail_attr">On Sat, Jul 18, 2026 at 12:23=E2=80=AFPM= Gregory Casamento <<a href=3D"mailto:[email protected]">greg.cas= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quote" = style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pa= dding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font= -family:monospace,monospace"><p>Lars,</p><p>I don't know how the GNU Pr= oject is arriving at its policy or whether individual GNU projects have an = opportunity to provide input. I have written to RMS about our policy and gi= ven him a link to it.=C2=A0 I hope it can inform any decision they make.</p= ><p>I don't think the discussion should become a witch hunt either. AI = is a tool, and like any tool, it can be used well or poorly. Regardless of = how code is produced, I believe our responsibility as maintainers remains t= he same: to ensure that contributions meet our standards for licensing, pro= venance, quality, correctness, maintainability, and review.</p><p>Ultimatel= y, those standards are what determine whether code belongs in GNUstep, not = the particular tools used during its development.</p><p>I'm hoping the = GNU Project reaches a thoughtful and balanced conclusion.</p><p>Yours, Greg= </p></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gm= ail_attr">On Sat, Jul 18, 2026 at 5:00=E2=80=AFAM <a href=3D"mailto:lars.so= [email protected]" target=3D"_blank">lars.sonchocky-helldorf@hamb= urg.de</a> <<a href=3D"mailto:[email protected]" target= =3D"_blank">[email protected]</a>> wrote:<br></div><blo= ckquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left= :1px solid rgb(204,204,204);padding-left:1ex"><div>Hi Greg,<div><br></div><= div>just one question in this regard: Do we have a voice in GNU=E2=80=99s d= iscussion on that topic (I hope, there is a discussion an not just a decisi= on by one person, namely RMS)? If so, I hope, we make our standpoint clear = and don=E2=80=99t go onto a witch-hunt against AI (which would be like a wi= tch hunt against compilers and linkers in the times when UNIX was still wri= tten in assembler). In my opinion AI is just a (very sophisticated) tool wh= ich you need to know, how to use it and its limitations. Then we can use it= sanely and to our advantage.</div><div><br></div><div>Hoping for the best = outcome,</div><div><br></div><div><span style=3D"white-space:pre-wrap"> </s= pan>Lars<br id=3D"m_-5286653012432761188m_-2588267537875648687lineBreakAtBe= ginningOfMessage"><div><br><blockquote type=3D"cite"><div>Am 18.07.2026 um = 10:23 schrieb Gregory Casamento <<a href=3D"mailto:greg.casamento@gmail.= com" target=3D"_blank">[email protected]</a>>:</div><br><div><div= dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:monospace,mo= nospace"><p>David,</p><p>Sorry for the late reply; work has been very deman= ding lately.=C2=A0 Of course, any policy they issue will apply to us.=C2=A0= I think this is a reasonable approach for EMACS if they are waiting for gu= idance from the GNU Project.</p><p>Until that policy is published, however,= I don't think it gives us any basis for changing GNUstep's existin= g approach. Once the GNU Project has issued its guidance, we can evaluate i= t on its merits, determine whether and how it applies to GNUstep, and discu= ss whether any changes are warranted.</p><p>I believe our current policy pr= ovides a practical balance as it focuses on licensing, provenance, code qua= lity, review, and maintainability rather than the specific tools contributo= rs use.</p><p>As mentioned in previous emails, I have set a clear line on w= hat is acceptable, and this=C2=A0was reflected in the discussion a few=C2= =A0weeks ago.</p><p>Yours, GC</p></div></div><br><div class=3D"gmail_quote"= ><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Jul 15, 2026 at 4:31=E2=80= =AFAM David Chisnall <<a href=3D"mailto:[email protected]" targe= t=3D"_blank">[email protected]</a>> wrote:<br></div><blockquote = class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px sol= id rgb(204,204,204);padding-left:1ex">On 14 Jul 2026, at 22:48, Gregory Cas= amento <<a href=3D"mailto:[email protected]" target=3D"_blank">gr= [email protected]</a>> wrote:<br> > <br> > Based on the discussion, I do not see sufficient consensus or justific= ation to replace our existing AI policy with a "No-AI" policy for= the GNUstep core libraries. Accordingly, the existing policy will remain i= n effect.<br> <br> Most of the arguments have been covered in other places and it=E2=80=99s qu= ite surprising that most of the folks in this thread seem unfamiliar with t= hem, but I would add one thing:<br> <br> This week, EMACS paused =E2=80=98AI=E2=80=99 contributions because the GNU = project is expected to provide an explicit policy soon. I presume that poli= cy will apply to GNUstep as well.<br> <br> David<br> <br> </blockquote></div><div><br clear=3D"all"></div><div><br></div><span class= =3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_s= ignature"><div dir=3D"ltr"><div dir=3D"ltr"><div><div dir=3D"ltr"><font fac= e=3D"monospace">Gregory Casamento<br>GNUstep Lead Developer / Black Lotus, = Principal Consultant<br><a href=3D"http://www.gnustep.org/" target=3D"_blan= k">http://www.gnustep.org</a> - <a href=3D"http://heronsperch.blogspot.com/= " target=3D"_blank">http://heronsperch.blogspot.com</a><br></font></div></d= iv><div dir=3D"ltr"><font color=3D"#888888" face=3D"monospace"><a href=3D"h= ttps://www.openhub.net/languages/objective_c" style=3D"color:rgb(17,85,204)= " target=3D"_blank">https://www.openhub.net/languages/objective_c</a></font= ></div></div></div></div> </div></blockquote></div><br></div></div></blockquote></div><div><br clear= =3D"all"></div><div><br></div><span class=3D"gmail_signature_prefix">-- </s= pan><br><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D"ltr"><div di= r=3D"ltr"><div><div dir=3D"ltr"><font face=3D"monospace">Gregory Casamento<= br>GNUstep Lead Developer / Black Lotus, Principal Consultant<br><a href=3D= "http://www.gnustep.org" target=3D"_blank">http://www.gnustep.org</a> - <a = href=3D"http://heronsperch.blogspot.com" target=3D"_blank">http://heronsper= ch.blogspot.com</a><br></font></div></div><div dir=3D"ltr"><font color=3D"#= 888888" face=3D"monospace"><a href=3D"https://www.openhub.net/languages/obj= ective_c" style=3D"color:rgb(17,85,204)" target=3D"_blank">https://www.open= hub.net/languages/objective_c</a></font></div></div></div></div> </blockquote></div><div><br clear=3D"all"></div><div><br></div><span class= =3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_s= ignature"><div dir=3D"ltr"><div dir=3D"ltr"><div><div dir=3D"ltr"><font fac= e=3D"monospace">Gregory Casamento<br>GNUstep Lead Developer / Black Lotus, = Principal Consultant<br><a href=3D"http://www.gnustep.org" target=3D"_blank= ">http://www.gnustep.org</a> - <a href=3D"http://heronsperch.blogspot.com" = target=3D"_blank">http://heronsperch.blogspot.com</a><br></font></div></div= ><div dir=3D"ltr"><font color=3D"#888888" face=3D"monospace"><a href=3D"htt= ps://www.openhub.net/languages/objective_c" style=3D"color:rgb(17,85,204)" = target=3D"_blank">https://www.openhub.net/languages/objective_c</a></font><= /div></div></div></div> --000000000000a180c60657c11e84--