Post B4CCz8TrZcSEuzKMGO by cwebber@social.coop
 (DIR) More posts by cwebber@social.coop
 (DIR) Post #B4BqnmKxMgCS41LBey by cwebber@social.coop
       2 likes, 6 repeats
       
       systemd goes AI agent slopware https://github.com/systemd/systemd/blob/c1d4d5fd9ae56dc07377ef63417f461a0f4a4346/AGENTS.mdhas slop documentation now too
       
 (DIR) Post #B4BqnmbGO3FAsayD4q by cwebber@social.coop
       1 likes, 1 repeats
       
       One more reason to use Guix + Shepherd!
       
 (DIR) Post #B4Bqp2NpBsqA7VHZxY by gwenthefops@transfem.social
       2 likes, 1 repeats
       
       @cwebber@social.coop finally, a decent reason to stop using systemd
       
 (DIR) Post #B4C9lMdVqYd2u8aAhE by cwebber@social.coop
       1 likes, 2 repeats
       
       EDIT: See later in thread, it seems like the good news is at least that it's not having auto-merging on, which is where the security risk comes in. I still have other concerns.Looks like they're also using Claude for PR review https://github.com/systemd/systemd/commit/9a70fdcb741fc62af82427696c05560f4d70e4deWhich probably means systemd is now the most attractive target in FOSS for an AI prompt injection attack to insert a backdoorEDIT: It does seem that they don't have auto-merging of PRs from the review bot, which is an improvement over the situation (and mitigates the primary security risk, hopefully it stays that way), and AI contributions are asked to be disclosed. That said, it seems like the issue is closed, and they are firmly in the "we will accept AI contributions, as long as disclosed" camp.
       
 (DIR) Post #B4CCz7hIUBbeUMbZZ2 by skyfaller@jawns.club
       0 likes, 0 repeats
       
       @cwebber Will GNU Guix be able to keep LLMs out of Shepherd and Hurd? I'm also worried about the Linux kernel potentially slopifying.
       
 (DIR) Post #B4CCz7tLlNFP5kFCLo by cwebber@social.coop
       0 likes, 0 repeats
       
       @skyfaller Linux already is slopifying
       
 (DIR) Post #B4CCz86oxI1TlWXxLc by ytvwld@chaos.social
       1 likes, 0 repeats
       
       @cwebber @skyfaller but Hurd is too, right? https://lists.gnu.org/archive/html/bug-hurd/2026-02/msg00133.html
       
 (DIR) Post #B4CCz8JwAWVyQCgQnA by skyfaller@jawns.club
       0 likes, 0 repeats
       
       @ytvwld @cwebber Yes, this is what I was looking for but I couldn't find the reference, looks like slop is infecting Guix-adjacent projects already.EDIT: Guix is not responsible for Hurd, my mistake. Still concerning if GNU Guix soon won't have a kernel option that isn't slopified.
       
 (DIR) Post #B4CCz8TrZcSEuzKMGO by cwebber@social.coop
       1 likes, 1 repeats
       
       @skyfaller @ytvwld Hurd is not Guix, but is one of the kernel options available for Guix.@civodul has loosely floated the idea on here of having a "no AI codegen contributions in Guix" policy (and I think that should extend to the Shepherd). I'm for it.
       
 (DIR) Post #B4CCz92bUSFAeja6Pg by cwebber@social.coop
       0 likes, 0 repeats
       
       @skyfaller @ytvwld @civodul I think an easier option: a one year moritorium on AI based contributions, while what that means shakes out, set to be re-evaluated.
       
 (DIR) Post #B4CCzpyrqDnxpbAE3k by musicman@mastodon.social
       1 likes, 0 repeats
       
       @cwebber you broke github
       
 (DIR) Post #B4CD13sndg6pEmuS9Y by cwebber@social.coop
       1 likes, 0 repeats
       
       @musicman that's right the christine effect isn't limited to fedi nodes
       
 (DIR) Post #B4CDB0XstyzPmarxiK by MrMagne@framapiaf.org
       1 likes, 0 repeats
       
       @cwebber oh, you mean the PID 1 that does everythig… brilliant
       
 (DIR) Post #B4CDC69RXrqLSTxP3g by cwebber@social.coop
       1 likes, 0 repeats
       
       @trentmichael_reznor Prompt injection attacks against PR review agents have resulted in backdoors have resulted in merged PRs with nobody noticing
       
 (DIR) Post #B4CDC6itQ4CREQXiJU by cwebber@social.coop
       0 likes, 0 repeats
       
       @trentmichael_reznor systemd gets a lot more attention, so maybe it's not as likely, but
       
 (DIR) Post #B4CDfZqWDgs3x9A6Lo by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @cwebber @skyfaller @ytvwld @civodul Would be great if it could extend to other GNU projects like gcc, binutils, autotools, … as well otherwise we're in trouble.(as LLVM got LLM slopified, because of course it did)
       
 (DIR) Post #B4CI1zUDyB6Lf9g2Iy by bclindner@mas.to
       0 likes, 0 repeats
       
       @cwebber you'll notice about everything Red Hat touches is compromised in this regard! :harold:
       
 (DIR) Post #B4CI9aPZ5AEaD67Svw by cocaine_owlbear@retro.pizza
       0 likes, 0 repeats
       
       @cwebber well, I was gonna abandon systemd anyway. But gods damn it, I just got my modded-to-hell Skyrim working. The Owlbear is finishing a play through first…
       
 (DIR) Post #B4CI9acKJiRUqg5epE by cocaine_owlbear@retro.pizza
       0 likes, 1 repeats
       
       @cwebber and my saves have vanished. Fuck.
       
 (DIR) Post #B4CIDJC52RhhyAaSUC by woe2you@beige.party
       0 likes, 0 repeats
       
       @cwebber Great, now I have to replace half my operating system.
       
 (DIR) Post #B4CIDJN4NaUiWFjEcC by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @woe2you @cwebber meh, we all do. I have my Debians systemd-free, never ran it, but Linux is also slopifying.
       
 (DIR) Post #B4CIHE7BrbB9NNAU6K by joshuaelliott@mastodon.social
       0 likes, 1 repeats
       
       @cwebber Goddamnit, I JUST got Fedora set up.fuuuuuuuuuuuuuuuuuuckadoodledoo.
       
 (DIR) Post #B4CLYbSmblUwZhFGpE by unlofl@mstdn.social
       0 likes, 1 repeats
       
       @cwebber "This file provides guidance to AI coding agents when working with code in this repository. Only add instructions to this file if you've seen an AI agent mess up that particular bit of logic in practice."followed by"Never invent your own build commands or try to optimize the build process"lmao, I bet that was a funny screw up
       
 (DIR) Post #B4D31dKL3NsymYNtqa by selea@social.linux.pizza
       0 likes, 0 repeats
       
       @cwebber I just wondered what kind of taste I had in my mouth when I read that PR.Turns out that was puke.
       
 (DIR) Post #B4DIN4N7CBL23OMYOu by Sylvhem@eldritch.cafe
       0 likes, 0 repeats
       
       @cwebber No, no, no, no.
       
 (DIR) Post #B4DZnErUW02RKzdRVw by civodul@toot.aquilenet.fr
       0 likes, 0 repeats
       
       @cwebber @ytvwld @skyfaller I’m planning to submit a Guix Consensus Document (GCD) on this topic (waiting a little bit notably to avoid interfering with the GCDs currently being discussed).
       
 (DIR) Post #B4GiLCBoL5KO0Fiq2a by cwebber@social.coop
       0 likes, 0 repeats
       
       Poettering commented, the issue is now closed. https://github.com/systemd/systemd/issues/41085#issuecomment-4053443496Asking for detection of security vulnerabilities from an LLM is one thing though, that one I could consider useful, but the real question is code and documentation generation. It does seem that for now, the bot usage isn't auto-merging PRs, which does alleviate some previous concerns of mine if reading that right.But, in AGENTS.md it does mention "docs/CODING_STYLE.md — full style guide (must-read before writing code)". https://github.com/systemd/systemd/blob/main/AGENTS.mdThey do require disclosure in the project also of LLM usage. But this does imply that LLM contributed changes are considered welcome, so we will probably see more of them, but I suppose at least they should hopefully be marked appropriately.
       
 (DIR) Post #B4GiLCpVxT5RzOIXvU by cwebber@social.coop
       1 likes, 0 repeats
       
       I will admit, I made this thread when pretty frustrated and upset about it. SystemD is so key to the security of many peoples' machines. I don't necessarily see having security reviews be a problem the same way that codegen and etc are. And I was wrong about the PR review vulnerability risk in that *for now* afaict the review bot is just performing read-only security review, is not taking auto-action on merging, which is the real risk.So maybe I overreacted? But Poettering's comment reads the way that most comments I have read that have been drawn into AIgen code have gone, which is "you gotta admit that things are changing, these things are getting really good" and then opening the door to aigen contributions. Which I am very wary of...
       
 (DIR) Post #B4GiRJ1zoZfixZ2qrQ by janl@narrativ.es
       0 likes, 0 repeats
       
       @cwebber I keep being baffled by these folks just ignoring the code provenance and licensing issues.
       
 (DIR) Post #B4GiRJEl37sdb912ki by cwebber@social.coop
       1 likes, 0 repeats
       
       @janl Indeed, people have gotten the mistaken impression that the licensing issues have been answered. THEY HAVEN'T YET! The US Supreme Court *declined to take on* a case which had ruled in a lower court that AI generated materials were in the public domain. And yet I am seeing *all over the place* people saying that the US Supreme Court said AI output is in the public domain. They didn't!And outside the US, nothing is answered either! It's true that the US tends to set international precedent but we are *also* not in times where we can count on that, either.