Post B4iZY1NcNgy155ADLM by teftuft@leporid.net
 (DIR) More posts by teftuft@leporid.net
 (DIR) Post #B4iLsMz2N2daW5TVho by ariadne@social.treehouse.systems
       3 likes, 1 repeats
       
       I saw a wild take where someone said distributions are fascist for using systemd because systemd now uses Claude for code review.okay.  fine, I guess.but if we are rejecting dependencies that use AI tooling, where do we go?seriously.  where do we go?if the Linux kernel is using AI tools for codegen, then where do we go?FreeBSD?  I would put money on it that they use AI tools.OpenBSD?  NetBSD?  HURD?do we hard fork every dependency that is now tainted?  do we even have the resources to do it?FreeBSD and Illumos are the only ones reasonably close in the tech tree and I suspect both use AI tools too, as their development, like Linux, is driven by capital.
       
 (DIR) Post #B4iMVqxEsBl2lPSdlo by freya@social.highenergymagic.net
       1 likes, 0 repeats
       
       @ariadne I can almost certainly say that Illumos doesn't, but I take your point
       
 (DIR) Post #B4iNfJlPEM7Cfr0G0G by starchturrets@mastodon.social
       0 likes, 0 repeats
       
       @ariadne Not to mention browsers...
       
 (DIR) Post #B4iNzeP0CqSUTXDfea by bluca@fosstodon.org
       0 likes, 0 repeats
       
       @ariadne there's no "if", the kernel does use LLMs extensively, right now: https://www.theregister.com/2026/03/26/greg_kroahhartman_ai_kernel/ precisely and exactly the same policy as systemd has. LIterally the same. And yet these lunatic takes never demand Linux distros drop Linux. I wonder why ¯\_(ツ)_/¯
       
 (DIR) Post #B4iO2Y4KD6s5hWvhPk by frumble@chaos.social
       0 likes, 0 repeats
       
       @ariadne Relevant discussions:https://exquisite.social/@thomholwerda/116222530071367930https://exquisite.social/@thomholwerda/116268174746934279
       
 (DIR) Post #B4iO4htedpxMlEy4O0 by equinox@chaos.social
       0 likes, 0 repeats
       
       @ariadne I'm (somewhat unwillingly) slowly drifting to "ok, use AI for review, then"… people generally understand and accept you can't have AI both write and review the same code, and between these two choices one is a massive dick move on FOSS maintainers while the other is vaguely stomachable if you don't think about it too much 🫤
       
 (DIR) Post #B4iOA3XTbTU7Kb92uW by lambda@chaosfurs.social
       0 likes, 0 repeats
       
       @ariadne nah, not fine, actually. It's a complete warping of reality that removes all meaning from the word "fascist" and turns it into nothing but a generic insult - probably not intentionally, but definitely as a means to personally get attention.
       
 (DIR) Post #B4iONtCuoSqXLI7jyy by astraleureka@social.treehouse.systems
       0 likes, 0 repeats
       
       @voided @ariadne it's still alpha-grade, "do not trust with important data" level :\
       
 (DIR) Post #B4iOp0XFfwvzt9ZDYu by xyhhx@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne we'll see what happens when the bubble bursts and prices start reconciling with reality
       
 (DIR) Post #B4iP782yUCZoOk2uQ4 by lanodan@queer.hacktivis.me
       1 likes, 0 repeats
       
       @ariadne This one is all wack when like what 3~6 months ago there was a pro-systemd jerk being like "anti-systemd are all facists!"Also yeah in terms of alternatives it's not great, so far I'm stuck with reducing as much as possible and planning to have more stuff like Plan9.(Also pretty sure Hurd got LLM-tainted)
       
 (DIR) Post #B4iPUc2H9f9C4CuuTQ by astraleureka@social.treehouse.systems
       0 likes, 0 repeats
       
       @lanodan @ariadne oh, is that why hurd just suddenly pushed out amd64 support recently, only a cool 25 years late?
       
 (DIR) Post #B4iPcjr1y9cWdHX2v2 by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @astraleureka @ariadne IIRC it's SMP rather than 64-bit but same sort of "Huh? Everyone got that stuff, come on"
       
 (DIR) Post #B4iPmttHVdkuehQjtQ by astraleureka@social.treehouse.systems
       1 likes, 0 repeats
       
       @lanodan @ariadne if it's smp that's actually even sadder than just now getting amd64 support. its a microkernel. supporting multiple cpus is a pretty major win, lol
       
 (DIR) Post #B4iPtC4moCgonJoQyG by brahms@chaos.social
       0 likes, 0 repeats
       
       @ariadne I see it as a "pick your fight"-thing: before LLMs, most users (me definitely included) had the same problem: we have to trust the maintainers. From my perspective, whether they use such tools or not doesnt really matter, since I cant review 95% of my tech stack anyway ,simply due to lack of time.i think software will deteriorate in general by using llms extensively, tho proprietary even more so than free software. Unless I find years to spare, the choice is easy.
       
 (DIR) Post #B4iQ6K9u4MRncuT0xU by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @astraleureka @ariadne Yeah, checked and it's SMPWhich yeah seems quite ridiculous for a microkernel to only get it now but well Hurd is a zombie project that aged decades.
       
 (DIR) Post #B4iRmq6llwF8pgq0iu by aronowski@furry.engineer
       0 likes, 0 repeats
       
       @ariadne One idea would be to stick to using older systems, perhaps with older hardware, from the times when AI usage wasn't as widespread.Of course they will have their vulnerabilities, so I'd use them only for processing my own trusted data, and not e.g. executing JavaScript from random websites.Though let's keep in mind that it applies to personal computers not relying on software delivered with AI. Even if someone was to not use personal computers at all and live an analog life, the exposure to AI-delivered software and machines would still be present, e.g. when having one's sensitive medical data stored on a doctor's computer.
       
 (DIR) Post #B4iTD4LRYy9wTDly1Q by thesamesam@social.treehouse.systems
       1 likes, 0 repeats
       
       @astraleureka @lanodan @ariadne No, it was a lot of work by a handful of people over many years. It has nothing to do with LLMs.
       
 (DIR) Post #B4iUOhmvM1aHwOjs8W by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @lambda hence "I guess".
       
 (DIR) Post #B4iUu0BozIDJzPJ9Hc by thesamesam@social.treehouse.systems
       1 likes, 0 repeats
       
       @lanodan @ariadne re Hurd: I only saw one person doing some LLM review (not of submitted patches but they took it upon themselves to submit its findings), I don't consider that tainted and I don't think it's some sort of official effort or anything, even if I don't like it.systemd embracing it with a CLAUDE.md, using it in all PRs, commits co-authored-by it etc is different.
       
 (DIR) Post #B4iUyEASxWo0V4glXs by ariadne@social.treehouse.systems
       2 likes, 0 repeats
       
       i guess my point here is that reactionary behavior does not really benefit anyone and just leads to bad decisions
       
 (DIR) Post #B4iV0YipVfr6pLsF6G by colinstu@birdbutt.com
       0 likes, 0 repeats
       
       @ariadne what makes (current) hobbyist stuff like REDOX OS just that more exciting. With such a strong/rigid take, yeah I don’t know where they’d expect folks to immediately move to.
       
 (DIR) Post #B4iV2ifxTPBAHFYqEC by bluca@fosstodon.org
       0 likes, 0 repeats
       
       @thesamesam @astraleureka @lanodan @ariadne yeah sure, if you exclude some tiny details like, er, SMP support https://lists.gnu.org/archive/html/bug-hurd/2026-02/msg00133.htmlEnjoy your single-core UNTAINTED systems forever, I guess?
       
 (DIR) Post #B4iV2it4gdfevvhJfk by thesamesam@social.treehouse.systems
       1 likes, 0 repeats
       
       @bluca @astraleureka @lanodan @ariadne I don't think their work was used at all. But I'm not arguing everyone should switch to Hurd, I'm just saying I don't think it's tainted, and I think some random person (same person each time) sending LLM content a handful of times to an ML isn't the same thing?
       
 (DIR) Post #B4iV6KvHjAXHleSFDU by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @colinstu but that's the thing.  redox is not a project that we can shift our production computing to immediately.
       
 (DIR) Post #B4iVLgJyS4LuTcJtEO by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @thesamesam @ariadne Ah so not yet tainted, but still meh social wise that I guess could be addressed via policy/guidelines.
       
 (DIR) Post #B4iVcagudZP7wF70U4 by omnirabbit@social.treehouse.systems
       0 likes, 1 repeats
       
       @ariadne it's protestantism but swapping the god from the ethereal one to "reason". if you are bad you are tainted permanently and must stone; if they stopped using AI tools it would also not be enough because they are "tainted".this pattern repeats over and over from people who unlearned one piece but didn't deprogram the religious dogmatic patterns, and you end up here. is Linux foundation funding the destruction of jobs, removing human contributions, destroying the world with debt, any of that? of course not! but it's still dogma.I don't have a good answer to this, just to remind people what the actual goals and actions of orgs are and hope they listen.
       
 (DIR) Post #B4iVhcPJgSiKi1HMNE by colinstu@birdbutt.com
       0 likes, 0 repeats
       
       @ariadne indeed it’s not. Yeah the argument right now (to move asap) is just a nonstarter. It’s gong to take time (if ever) to de-AI codebases and projects. There isn’t going to be any simple fix or solution to it :/ For those who hold onto this, what do they use currently? They actually reap what they sow?
       
 (DIR) Post #B4iVlxCAKx1uL8C9iq by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @colinstu at least in my case, every time i've embraced LLM technology, i've come to regret it basically immediately.case in point: grammarly copyediting feature
       
 (DIR) Post #B4iVzWTcTLhNWnpTBg by bluca@fosstodon.org
       0 likes, 0 repeats
       
       @thesamesam @lanodan @ariadne Hurd using LLMs for reviews: perfectly oksystemd using LLMs for reviews: TAINTEDDId I get this right?
       
 (DIR) Post #B4iVzWkdS5JGNZn3i4 by thesamesam@social.treehouse.systems
       0 likes, 0 repeats
       
       @bluca @lanodan @ariadne Someone deciding to send ML output a handful of times an ML is different from it being an established part of the project, sure.(I also didn't say "perfectly ok", it's just that it's clearly different, even if one does or doesn't like it?)
       
 (DIR) Post #B4iVzWxkfJnl2FvX9c by bluca@fosstodon.org
       0 likes, 0 repeats
       
       @thesamesam @lanodan @ariadne gotcha, rules for thee but not for me
       
 (DIR) Post #B4iVzXA9vBj5ejjRUe by thesamesam@social.treehouse.systems
       0 likes, 0 repeats
       
       @bluca @lanodan @ariadne If a contributor had copilot review their PR for systemd but systemd didn't have it as part of CI or as some regular part of contribution, I'd say the same thing.But I'm not even making rules! I'm pointing out a distinction?
       
 (DIR) Post #B4iVzXMZB3eQHDXLpg by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @thesamesam @bluca @lanodan personally, i don't even think i *care* about LLM-based reviews.what i care about is LLM-based code generation because every time i've interacted with people using those tools to produce changesets, it's been fucking miserable
       
 (DIR) Post #B4iW3gkYDeXcY1jdOi by thesamesam@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne @bluca @lanodan I've sort of come to this position as well, especially sympathising w/ what Lennart says about Bad Guys already using LLMs to find vulnerabilities, so may as well try to leverage them to do some good.Don't love it still but I definitely feel warmer to it than the rest.
       
 (DIR) Post #B4iWAS2nIF62xwUcVM by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @thesamesam @bluca @lanodan i guess to me, it feels unnatural and jarring to argue with a chatbot in a code review.but that is far less harmful than dealing with changesets where the author does not even fucking know what he is submitting and cannot defend his work.*that* is true misery as a maintainer.
       
 (DIR) Post #B4iWM9cfbpZnJ9r0a0 by ariadne@social.treehouse.systems
       1 likes, 1 repeats
       
       @thesamesam @bluca @lanodan basically the problem is AI as force multiplier for charlatanism.claude making it miserable for charlatans to get their PRs merged actually seems like a positive use of the technology...
       
 (DIR) Post #B4iWRJEHJsCgYAu2zI by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @thesamesam @ariadne @bluca Kind of still feels bad given how overblown a lot of security vulnerabilities are (I guess ICANN and registries will get more money from website-logo vulns), plus imagine getting a big wave of low-impact security vulnerabilities.But well that's roughly the same issues as with fuzzers, except it's combined with codegen this time.
       
 (DIR) Post #B4iWVUbcxnm2zaoqq8 by thesamesam@social.treehouse.systems
       1 likes, 0 repeats
       
       @lanodan @bluca @ariadne Yes, exactly, it really is fuzzers all over again, just the problem is you now have this script-kiddy enabling tech on top.
       
 (DIR) Post #B4iWYHqUrVSgHo6fXE by ariadne@social.treehouse.systems
       1 likes, 0 repeats
       
       @thesamesam @lanodan @bluca yes, but script kiddies also figured out how to use the fuzzers and submit slop to us with "can you tell me about your bug bounty program?"
       
 (DIR) Post #B4iWecGbqjGjMJL3ey by bluca@fosstodon.org
       0 likes, 0 repeats
       
       @ariadne @thesamesam @lanodan of course and stuff like that gets shot into the sun with a rocket without mercy.But you don't argue with chatbots in reviews - these days claudebot is about 90% signal-to-noise ratio. The 10% noise you just dismiss, there's no arguing involved. But that 90% of signal has got really good in the past ~3 months, and there's no point denying it. This stuff was mostly crap until end of last year, but things change, and there's nothing wrong with changing views
       
 (DIR) Post #B4iWgnkk7EaTYrTWs4 by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @ariadne @thesamesam @bluca I think it's the kind of thing where I could end up replying "Here's my hourly rate for support requests"
       
 (DIR) Post #B4iWgrryoGkkKStMhs by thesamesam@social.treehouse.systems
       1 likes, 0 repeats
       
       @ariadne @lanodan @bluca yeah, and even before fuzzers with any sort of security tooling actually ("hello your CSP policy is missing on ur static website")
       
 (DIR) Post #B4iWtgWWJ0xiu7xx8C by lproven@vivaldi.net
       0 likes, 0 repeats
       
       @ariadne > FreeBSD?  I would put money on it that they use AI tools.As of September they were working on a policy -- to ban it. https://www.theregister.com/2025/09/03/freebsd_project_update_no_ai/
       
 (DIR) Post #B4iWyBIJqGNbUsT3EO by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @bluca @thesamesam @lanodan oh yes, we have been experimenting with it at work for reviews.it has indeed gotten pretty good.but i hesitate becoming dependent on it as a FOSS maintainer because while the first hit is free, when the economic reality catches up... it will probably be quite expensive.
       
 (DIR) Post #B4iXVlcVnxcViPvZlA by bluca@fosstodon.org
       0 likes, 0 repeats
       
       @lanodan @ariadne @thesamesam our security bug bounty in systemd was 99.99% garbage until end of last year. Since then these tools have got way better, and I'd say there's a ~10% valid security bugs, ~70% valid bugs but not security relevant, and ~20% garbage. I'll happily take the 10% of real, valid issue found for the price of having to shoot down ~20% of garbage. The key is to have no mercy - there's no arguing or bargaining involved, a crap report gets binned, end of, no discussions
       
 (DIR) Post #B4iXVloD6SygIhOuzg by bluca@fosstodon.org
       0 likes, 0 repeats
       
       @lanodan @ariadne @thesamesam the 70% of valid-bugs-but-not-vulnerabilities is kinda 50-50 our fault and the bots fault. The bots fault because it's a dumb LLM in the end, it doesn't understand the big picture (well doesn't "understand", full stop). Our fault because a lot of the security models are pretty much implicit, and scarcely documented if at all, so the bot has nothing to keep it grounded to reality
       
 (DIR) Post #B4iXVm2OFkJv0g2F60 by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @bluca @lanodan @thesamesam yes, in our own experiments at work, we are having to write a lot into the system prompt in order to inform claude about the threat model.otherwise it does silly things like "zones have device nodes in them that allow accessing hypervisor services"well, yes.i would hope so.considering that it's running in a hypervisor, and you need those services to access secure enclaves, for example.
       
 (DIR) Post #B4iXd7Qv6RILOW0l04 by bluca@fosstodon.org
       0 likes, 0 repeats
       
       @ariadne @thesamesam @lanodan yeah that's obviously the end goal of all this wild and absurd speculation, but capitalism gotta capitalism. At some point the bubble will pop and then we'll see what's left standing
       
 (DIR) Post #B4iYP9NhACBtKtPEQK by omnirabbit@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne I don't want to see the world eaten by AI but people use the tool and it drives results for them. There's nowhere much else to go.It's like Stallman arguing for owning every piece of your machine - eventually, you have some closed source firmware blob. Purity vs reality.
       
 (DIR) Post #B4iYP9a6Q47DxND8lM by omnirabbit@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne also, you should be more concerned about whether you are actually doing fascism (i.e. snitching on your neighbors, working for the actual fascist goon army) versus vague ideological debates that the people doing Real Fascism will never even give a second thought to.if systemd is actually fascist. You Will Know.
       
 (DIR) Post #B4iYP9rTNU0gpFL0q0 by oblomov@sociale.network
       0 likes, 0 repeats
       
       @omnirabbit @ariadne (let's say that the age thing doesn't shine a positive light on systemd either)
       
 (DIR) Post #B4iYPA2ohJ5HOQe4WG by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @oblomov @omnirabbit what "age thing"it's a fucking optional field in a user database for birthdatethey aren't enforcing anything or anything like that.it is a field in a schema.vcard also has a field for birthdate.  is it also fascist?
       
 (DIR) Post #B4iYaJit3MJgb0dvWq by oblomov@sociale.network
       0 likes, 0 repeats
       
       @ariadne why was the field added?(VCARD has a lot of field for PII. Heck's, it's basically just PII> That doesn't mean that systemd should have that same information. They are different tools for different purposes.)@omnirabbit
       
 (DIR) Post #B4iZBU3naA2ZN49A00 by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @brib fwiw, pkgconf does not allow agents to work autonomously in our tree as a matter of policy:https://github.com/pkgconf/pkgconf/blob/master/CONTRIBUTING.md#instructions-for-agentic-systems
       
 (DIR) Post #B4iZY1NcNgy155ADLM by teftuft@leporid.net
       0 likes, 0 repeats
       
       @ariadne yeah, its looks like more and more code it going to be tainted or produced by LLMs in some way. It seems unavoidable, so I guess we need more ergonomic tools for safely running untrusted code to protect as much as is possible from its flaws. But, I think even before there were LLMs this was the case. I haven't audited all of the code my computer runs and some is very flawed I'm sure.
       
 (DIR) Post #B4iaPsaVHoFXRxs9Uu by aronowski@furry.engineer
       0 likes, 0 repeats
       
       @ariadne @thesamesam @bluca @lanodan The end-user should always be responsible for what they deliver, no matter the tools. Then any excuses like "AI wrote it" would not have any rights to defend the user.
       
 (DIR) Post #B4iaSXBjJ1TNwuYCI4 by distractions@mastodon.social
       0 likes, 0 repeats
       
       @ariadne well, as a developer who has been writing linux kernel code since back in about 2001 or so (actually I think it was something alsa/bluetooth related so probably user space at that point, but … I remember digging deep) - I don’t think it’s feasible to continue OSS without making use of gen AI in development. Its like saying we can’t use C, everything has to be ASM. That doesn’t mean developers don’t need to read or understand the code anymore before committing. But a hard ban? Idk.
       
 (DIR) Post #B4iaV5hPxuhXYwajcO by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @aronowski @thesamesam @bluca @lanodan yes, that is basically the pkgconf contribution policy in a nutshell.we have taken some steps to tell agentic tools to fuck off though, because i do not want to deal with it
       
 (DIR) Post #B4iiF0ZQ4BCgeggzgG by ariadne@social.treehouse.systems
       0 likes, 1 repeats
       
       @distractions why is it infeasible to continue OSS without using GenAI?that seems like an absolutely *wild* claim.
       
 (DIR) Post #B4iibrkP2Gwhx5jH1s by dysfun@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne @distractions i feel like the decades we've managed already are worth something.
       
 (DIR) Post #B4ijEsg7VZqc8JKVhA by kirakira@furry.engineer
       0 likes, 0 repeats
       
       @ariadne i do wonder what a path away from this (that isn't "everyone agrees that doing that is bad") looks like
       
 (DIR) Post #B4ijQEWCeEDf3Q6Wye by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @lproven they may not allow agentic development, but i guarantee you there are people using AI tools to develop changesets.
       
 (DIR) Post #B4ijSalUuFCid8No5Q by distractions@mastodon.social
       0 likes, 0 repeats
       
       @ariadne well, because the world already has been changed. That’s a historic hard fact. Pretending it hasn’t won’t stop the wheel from turning. Anyone can set up a new project on GitHub (or CodeBerg for that matter) and put anything up there, and if it somehow does the trick, people won’t care how it does. It’s sad, but that’s how things progress. I believe it more worthwhile to harden our processes **around** and with gAI, not against it. Because the train will roll.
       
 (DIR) Post #B4imtr7IWEvJ1cGujw by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @oblomov @omnirabbit if you think systemd should not have the information, then don't give systemd the information?
       
 (DIR) Post #B4izMEbA0VQbPVXRAW by wronglang@bayes.club
       0 likes, 0 repeats
       
       @ariadne yeah and our taxes are funding the genocide in Palestine so, yes we're all fascist, we are the baddies, but the solution is to find each other and make the place less shit, not to spend time arguing about which basic tools are too fascist to use. I'd love to not have to contribute to fascism by driving but I'm not getting that either.
       
 (DIR) Post #B4j0DnZugQi7FLUpnM by dvshkn@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne Since the start I've been trying to take a qualitative approach because at the limit are you even going to know what's AI and what's not? If the quality is good I'm "fine" with it. If it's bad drop it. At least we can still look at the code.
       
 (DIR) Post #B4j53427fBjmrlOLho by icing@chaos.social
       0 likes, 0 repeats
       
       @ariadne @bluca @thesamesam @lanodan Yes, the review tools have become good. No, I don‘t think either that free maintainers can afford them once the bubble is over. But attackers may find the money, which is not good for security.Security researchers (good and charlatans) use them extensively now, we see that in the reports increase at curl and the ASF.We also see duplicate findings from different reporters. Obviously using the same tools.
       
 (DIR) Post #B4mzDqNAyEZiakpt3Y by moody@hj.9fs.net
       0 likes, 0 repeats
       
       There is 9front which is about as far as you can get for "driven by capital", with all the shortcomings and benefits that comes with that. For the most part we reimplement programs and libraries or build shim layers, we are certainly missing some of the harder problems, but for a lot of code its works out surprisingly well. Not exactly comparable to Linux, but it may serve as a reference point for "hard fork and continue on your own without corporate interests".