Re: ungarbled and properly wrapped

Matthias Urlichs <[email protected]> Sat, 25 Jul 2026 09:20:02 +0200
Newsgroups gmane.linux.debian.devel.vote
Message-ID <[email protected]>
On 23.07.26 17:01, Ansgar 🙀 wrote:
> You could add "a Debian contributor uses a LLM to find a highly
> critical bug in Debian's software and/or infrastructure" to the list.

The typical frontier LLM doesn't just find the bug, it also writes a 
patch and verifies that it actually fixes the problem.

… in theory. In practice it often doesn't, not yet anyway, but that's 
not my point.

 > "a Debian contributor uses a LLM"

This GR strongly discourages that … but what do I do (as a DD) when 
Somebody Else generates an LLM-generated patch that looks and feels 
sensible, might even have been vetted by others, and needs to be applied 
by me because it's my own software, or maybe 'cause Upstream is 
broken/lazy/compromised? Read it and update the source manually to look 
exactly the same? Read it and re-word everything so there's no[t much] 
AI content left? Not read it and fix the problem on my own? (History has 
shown that the latter practice is very likely to introduce a new problem 
instead.)

> I guess the GR would forbid submitting or acting on such reports? Would
> we just leave the hole open?

Various people are going to let Mythos or Galaxy (the officially-unnamed 
better-than-Sol model from OpenAI that recently hacked HuggingFace; name 
coined by Zvi Mowshowitz <https://substack.com/@thezvi>) or 
whichever-frontier-model loose on **/d/patches/** and ask "does any of 
these introduce a security problem?" sooner or later, if they haven't 
done it already. Yes we can ask them not to do that, and we can 
more-or-less-strongly declare our unwillingness to look at those reports 
… but if there's any positive effect of doing so, I don't see it.

-- 
-- regards
-- 
-- Matthias Urlichs
OpenPGP_signature.asc (application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEr9eXgvO67AILKKGfcs+OXiW0wpMFAmpkY6IFAwAAAAAACgkQcs+OXiW0wpN/
bg//eJabHRevHkXSGQjTzpwj1b/QTEp7hiM8DeuhQXvaKmxYOTKC0eydzTYP5yfes0Vl8yfBQR45
IYxdq4vSlePKBvlUpMtvj1cEG7e6MVrXntUudoke2lC6hd+AaQ+RfjJFf/ijhiNGQZSOw6Lcockk
c4KWIF9dDFW31f/LnN+giyvjHB8e34qIsjBpfdxk8492KdZnETyBTTihA9YNt2f0PDJAzhoSE3G5
zq5bGBcw5WDper1yepbmvHSWoFaPTP9mM67a5ajxqOZSI2eiCeGsT8mu2Vr7zd0O5PzPSzJDjxpz
B2zFfd+vjkW5YuogwIrzRzKvgs7id3U3Vfkrm7sGypGt7Mckc9mtNdSTX10uWZ60nqjeGpjIqoVn
QsrwHcbVvDdwWEfg26686NE96nEtRvXVksWfc4D17EXfMg6gWDrmgKar1X/Cz1dnKVJUVJnXMSqO
DnNcQJ0wQoxz1k+R1AVl8aIRJeda7pKL2kKkoUD/uv0R+o5tDWhgK8Dn6qC/B3Hv0YcZj+vc0scM
i3vypG77YRiHph15P/2WL2HutLd2+iGOB2GOxcr1AGcXj8Xq8gx3797vUyxk8tCAaR0SySNQMa8w
y+gk+7c6PT2buJRQZsTGFfkYfOS11q2YxEwudgzrS9L8BHn6HSs0T9AnK7Uc7qPWrYjO4/2Lnx8Q
Rnw=
=FJp3
-----END PGP SIGNATURE-----