[PATCH 4/5] docs: coding-assistant: explain important steps when looking for bugs

Willy Tarreau <[email protected]> Sun, 2 Aug 2026 22:35:39 +0200
Newsgroups org.kernel.vger.workflows,org.kernel.vger.linux-doc,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Due to the increasing capabilities of available AI models, it's becoming
common to see them used to find bugs anywhere. Unfortunately the quality
of reports (especially when they're believed to be security relevant) is
still lacking a lot.

Let's add a section dedicated to bug finding, explaining the few
mandatory steps (noting commit ID, writing the fix from the session that
found the bug, building and testing, etc). This was tested both against
Qwen3.6-27B-Architect-Polaris2-Fable-B-F451 running under Hermes, and
Opus-5, and both followed the instructions to the letter, verifying
their results and checking threat-model.rst to decline the vulnerability
aspect. At least in the current form it's expected to improve the
situation a little bit.

Cc: Greg KH <[email protected]>
Signed-off-by: Willy Tarreau <[email protected]>
---
 Documentation/process/coding-assistants.rst | 37 +++++++++++++++++++++
 1 file changed, 37 insertions(+)

diff --git a/Documentation/process/coding-assistants.rst b/Documentation/process/coding-assistants.rst
index 899f4459c52d2..e71df7d28467e 100644
--- a/Documentation/process/coding-assistants.rst
+++ b/Documentation/process/coding-assistants.rst
@@ -57,3 +57,40 @@ Basic development tools (git, gcc, make, editors) should not be listed.
 Example::
 
   Assisted-by: Claude:claude-3-opus coccinelle sparse
+
+Procedure for finding and fixing bugs
+=====================================
+
+When an AI assistant is used to find and fix bugs, it **MUST** follow at least
+these steps:
+
+1. Before starting, read the whole process documentation listed above, as well
+   as any other document mentioned in the request. Do not rely on isolated
+   parts found by keyword search.
+2. Note the commit ID and Locate a bug as instructed.
+3. For any bug found that is not trivial, verify that it looks real by
+   attempting to create a reproducer to demonstrate it. Lacking it may cause
+   the report to be ignored, as many unverified bug reports sent to maintainers
+   happen to be invalid. Stop here if it finally looks wrong.
+4. Write a fix for the bug. This part is not optional: except in a few very
+   rare cases, an AI assistant able to find a bug is able to fix it. Note that
+   fixes written in the same session as used to find the bug will generally
+   lead to better and more accurate fixes as the LLM's reasoning context
+   remains present.
+5. Build and verify that the fix works either using the reproducer or by
+   re-running a complete analysis; drop any fix that doesn't work and try
+   another one. The fix must not add build warnings and must pass the
+   checkpatch.pl checks (see submitting-patches.rst).
+6. Commit the working fix with a detailed message describing the problem, the
+   solution and a Fixes tag. Do not add a Signed-off-by tag, and add an
+   Assisted-by tag, as described above.
+7. Identify the maintainers and lists using scripts/get_maintainer.pl.
+   Documentation/process/security-bugs.rst shows how to do that.
+8. Indicate what could not be done. If the fix could not be built or tested, or
+   if no reproducer could be produced, say so explicitly: maintainers currently
+   waste too much time analyzing unverified reports and untested fixes.
+9. Read Documentation/process/threat-model.rst to determine whether the bug is
+   a vulnerability or a regular bug, and leave the result to the reporter for
+   review (the assistant must never send anything itself). Regular bugs are
+   submitted as described in Documentation/process/submitting-patches.rst,
+   vulnerabilities as described in Documentation/process/security-bugs.rst.
-- 
2.52.0