Post B6ojHQXcJaLleH6jTc by ikke@ipv6.social
 (DIR) More posts by ikke@ipv6.social
 (DIR) Post #B6ninOFi49KahjRtpo by ariadne@social.treehouse.systems
       2 likes, 0 repeats
       
       i plan to package openrsync this weekend in alpine as an alternative to rsync (and probably switch the default rsync implementation in future)
       
 (DIR) Post #B6nir0Jh05c7cx2F8q by ariadne@social.treehouse.systems
       1 likes, 1 repeats
       
       yes, this is because our entire infrastructure is built on rsync, which is now being vibe coded, and that seems like a problem
       
 (DIR) Post #B6njAqv7e4OmHE0VFY by ariadne@social.treehouse.systems
       1 likes, 0 repeats
       
       i honestly do not know how i feel entirely about vibe coding?  i think it is cool that people can theoretically get any program they want at any time.but that's theory.in practice, the code the tools generate has a tendency to be unreliable and frequently also has security issues.and rsync is being vibecoded by just tridge without any supervision.
       
 (DIR) Post #B6njQfLwQ89N2C5l6u by ariadne@social.treehouse.systems
       1 likes, 0 repeats
       
       i think at the very least, you need someone else to review the code which has been generated.  there is too much self-confirmation bias otherwise.
       
 (DIR) Post #B6njb8xdC4vHl1iWSe by dysfun@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne i don't need to know about how it's being done to see that it's been a disaster already.
       
 (DIR) Post #B6njh0xtpnQ6hGdsPo by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       sidebar: given that there is interest in alternatives to GPL software that is now being vibecoded, and these alternatives largely tend to not be copyleft...will vibe coding mean the death of copyleft?
       
 (DIR) Post #B6njkbihdYlbYiFOBk by brahms@chaos.social
       0 likes, 0 repeats
       
       @ariadne even without these, the ethical and the environmental issues one thing that bothers me is that someone has to maintain all that code.there is a reason why software engineering is hard and it certainly isnt because we aint producing enough code.
       
 (DIR) Post #B6nk0C90Ujmus1z2Iq by billchenchina@bcom.moe
       1 likes, 1 repeats
       
       @ariadneBug#1138239: rsync: Consider reverting to pre-LLM versionhttps://bugs.debian.org/1138239
       
 (DIR) Post #B6nkJRi0qleIe4XKzo by AmyZenunim@unstable.systems
       0 likes, 0 repeats
       
       @ariadne majority-AI code cannot be copyrighted. it immediately becomes public domain, basically.
       
 (DIR) Post #B6nkJRv8408nIkfoRM by ariadne@social.treehouse.systems
       1 likes, 1 repeats
       
       @AmyZenunim that wasn't the question.let me break it down:1. alpine is interested in a reliable rsync implementation.2. we presently use rsync, which is GPL, and now vibe-coded.3. openrsync is an alternative rsync implementation, which is maintained by the OpenBSD project, and thus ISC licensed.4. if we repeat this cycle over and over, to avoid other regressions from other unreliable vibecoded software, then the pool of influential GPL software wanes over time.
       
 (DIR) Post #B6nkV3ZOQMZ7Fq2cWO by yoasif@mastodon.social
       0 likes, 0 repeats
       
       @ariadne I kinda think so and I wrote up some thoughts awhile ago: https://www.quippd.com/writing/2026/04/08/ai-code-is-hollowing-out-open-source-and-maintainers-are-looking-the-other-way.html
       
 (DIR) Post #B6nkh6SpUQAZhniQV6 by tk@f.kawa-kun.com
       0 likes, 0 repeats
       
       @ariadne @AmyZenunim If that's the case, doesn't that mean components of rsync that were LLM-generated aren't under the GPL?(This is a response to only the comment I'm replying to, not OP.)
       
 (DIR) Post #B6nkh6eAoFFAGz1UBM by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @tk @AmyZenunim it's not relevant, or at least, the maintainer's choice to publicly document his decision to shoot himself in the foot regarding intellectual property rights is not relevant to distributions, because the overall package remains GPL regardless of the presence of uncopyrightable code.
       
 (DIR) Post #B6nkk2wD3XoPdcrSYy by jamesmarshall@sfba.social
       0 likes, 0 repeats
       
       @ariadne especially for a tool known to be both powerful and dangerous when used uncarefully, and one buried in a zillion automated systems....  :/
       
 (DIR) Post #B6nknpypAuXKbmtMlU by mcdanlj@social.makerforums.info
       0 likes, 0 repeats
       
       @ariadne My work experience has been interesting. I do catch the LLMs introducing some things that if a human did them I would describe as very poor judgement (I'm not ascribing judgement of any sort to the LLMs). On the other hand, I've had them catch subtle downstream impacts that I missed, including avoiding introducing bugs that would have been a pain to track down. On balance they are improving, I think.But I also don't count myself as a second reviewer and the LLM as the author; I am the author using the tool, and I still want real third party human review. Confirmation bias is there — I asked the agent to build something, so I'm clearly predisposed, even when consciously trying to read its plan and its code skeptically, to accept it at a light reading.I'm not sure this is much different in practice from trusting people who have learned how to project confidence in their writing. The machine is statistically likely to produce writing that is at first glance like a person confident in their own analysis. I think it's a difference in degree, since the machines create so much more of it. But I recognize the same temptation to accept specious confidence.
       
 (DIR) Post #B6nksITBC2oQ7rDVOi by dysfun@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne @AmyZenunim other distributions won't have the same standards as alpine. debian already declared they don't give a fuck.
       
 (DIR) Post #B6nl1Xvh5D5UgDxrtY by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @dysfun @AmyZenunim that is also not relevant, but i am not sure that your assertion is true anyway, as at least one debian developer has suggested that the regressions are bad enough to revert back to the last non-LLM version.https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138239
       
 (DIR) Post #B6nlDnSZATMoJyBL0a by billchenchina@bcom.moe
       0 likes, 0 repeats
       
       @ariadne Actually rsync sometimes regresses. Security update sometimes breaks things. rsync's codebase is indeed complex.Previously:https://bugs.debian.org/1093052https://bugs.debian.org/1093089https://lists.debian.org/debian-security-announce/2025/msg00006.htmlNot sure whether to blame vibe coding this time..
       
 (DIR) Post #B6nm05pSAuenBxutM0 by miss_rodent@girlcock.club
       0 likes, 0 repeats
       
       @ariadne Possibly, there seems to be problems from multiple sides; with some vibecoded re-implementations and LLM-generated code effectively licence-washing GPL'd code, while other GPL'd projects voluntarily drown themselves in slop code. Though, there's also GPL projects taking more restrictive stances about how or if LLMs can be used, to avoid the latter problem, and hopefully new copyleft projects starting (though, The Industry™ seems to favour permissive licenses like MIT lately?)
       
 (DIR) Post #B6nmqTNPs08PHZmMaW by dysfun@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne @AmyZenunim LOL, LMAO
       
 (DIR) Post #B6np1i6fe1xa3nQt7I by elle@weathered-steel.social
       0 likes, 0 repeats
       
       @ariadne I think it will be the largest ad for FOSS/copyleft.like how Windows is the biggest ad for Linux
       
 (DIR) Post #B6ntSsIEHNxXHw30ee by justsoup@mstdn.social
       0 likes, 0 repeats
       
       @ariadne Oh, I was actually considering packaging openrsync myself in response to the recent release's bug reports (as a fail-safe for pmOS), but nice to see you beat me to it. I don't know enough about openrsync other than it is an OpenBSD version to really make any solid statements other than thanks :)
       
 (DIR) Post #B6o5NFJ8zsluNbYeIa by me@social.jlamothe.net
       0 likes, 0 repeats
       
       @ariadne I haven't been paying particular attention. What's the problem with rsync?
       
 (DIR) Post #B6o5NFUqIO84xt1zX6 by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @me its now being coded by Claude and there have been regressions
       
 (DIR) Post #B6oGxkg6wHBtatuVGq by nieuemma@mastodon.de
       0 likes, 0 repeats
       
       @ariadne thank you
       
 (DIR) Post #B6oZXfieeU95oXNUB6 by icing@chaos.social
       0 likes, 0 repeats
       
       @ariadne @dysfun @AmyZenunim interesting
       
 (DIR) Post #B6ofKnuvSc1rCSMgbI by waldi@chaos.social
       0 likes, 0 repeats
       
       @ariadne I think about replacing rsync for several years.Now I try to see how far I've got with the prototype of a pre-generated git-like bundle of metadata and http as transport protocol. Okay, only for non-chunked transfers.
       
 (DIR) Post #B6ojHQXcJaLleH6jTc by ikke@ipv6.social
       0 likes, 0 repeats
       
       @dalias @ariadne @AmyZenunim linux is GPL and embracing LLMs.
       
 (DIR) Post #B6ojHQkNY8YgHr4vMu by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @dalias @AmyZenunim @ikke yes, but I think from a software reliability perspective, the kernel is still being appropriately reviewed for the most part.the larger problem will be regressions from the smaller projects where we have solo maintainers using LLMs as a force multiplier without appropriate review, and so far that's where we are seeing regressions from what I've been noticing.and this is nothing to say about the legal status of these projects given that mechanically generated code of any kind does not qualify for copyright protection under the Berne convention...
       
 (DIR) Post #B6okEenWx6uwwynI5A by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @dalias it very well could be.  but there's a lot of copyleft software adopting this stuff because the maintainers adopting it believe it can act as a force multiplier.
       
 (DIR) Post #B6omQZOP4gzhZMqiNU by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       anyway: mad respect for tridge.the man has done far more for software freedom than most of us have.but he is still a person, and people can easily be convinced by these LLMs that things check out when they actually don't.they use very persuasive language.  if you depend on them, you will inevitably commit mistakes that you should have caught, because nobody does a perfect job.  nobody.
       
 (DIR) Post #B6ompJ3AyLUS7kiQGO by whitequark@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne yeah, i feel the same about this as for phishing, or cultsthere is no amount of "smart" you can be that leaves you immune to ending up in a cult. none. it's a category error. these entities take advantage of vulnerability, which is something you can be, and likely will be at some point, regardless of your skill or achievements
       
 (DIR) Post #B6onYNk0NXtZhgF4vQ by faoluin@chitter.xyz
       0 likes, 0 repeats
       
       @ariadne "You are not immune to propaganda"
       
 (DIR) Post #B6ope5N1nDvoNFLHcW by jaseg@chaos.social
       0 likes, 0 repeats
       
       @ariadne I feel like it’s import to distinguish vibe coding the odd one-time script or tool for personal use, and slopping out parts of essential, load-bearing infrastructure. The latter just has much higher stakes.
       
 (DIR) Post #B6oq4eviCrIIBlEjqK by ariadne@social.treehouse.systems
       1 likes, 3 repeats
       
       what I will say is this.  there are pieces of software that are frankly "mission critical".for example, pkgconf, as a key component of most build toolchains, cannot have regressions because those regressions will reverberate throughout the entire "software supply chain" in the form of build errors.  it is a mission critical piece of software. this is why as lead maintainer of pkgconf I have implemented a number of policies and initiatives to reduce the likelihood of software errors and promote correctness in pkgconf as part of the pkgconf 3.0 work.these initiatives include banning LLM contributions, requiring DCO signoffs on commits, refactoring the codebase to remove entire classes of vulnerability, improving the quality of the windows port so it is equivalent to its unix counterparts and reimplementing and expanding the test suite from scratch.why?  because every single thing I listed reduces the likelihood for regressions.rsync, like pkgconf, is used at all times of the day, all around the world.  I try to visualize the scope to which pkgconf is used and it is just not possible.rsync is the same way: everyone is using it somehow, either to back up their data, or to mirror data from one machine to another.  there are numerous utilities which make use of it somehow to provide functionality.a regression in rsync is even less tolerable than a pkgconf regression: if you have errors in rsync, they can potentially cause data corruption or loss.but rsync goes in basically the opposite direction from pkgconf: it embraces LLM contributions.  it also has had several regressions since doing so.
       
 (DIR) Post #B6oqajJBSjIv2FVYQq by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       another sidebar: I haven't found a great less-capitalist alternative to "software supply chain" to describe components of software and their dependencies.there is the commons, but that is a collection of all libre software.  not the same thing.
       
 (DIR) Post #B6oqirxhAnB4BqL1Y8 by swetland@chaos.social
       0 likes, 0 repeats
       
       @ariadne I'm curious though, how much *active* development is going on in rsync nowadays.  It seems like a good candidate to fork from the last known pre-"ai" version and stay focused on critical bugfixes / security fixes.
       
 (DIR) Post #B6oreQV3Qxu9oXO2uO by Sythelux@social.tchncs.de
       0 likes, 0 repeats
       
       @ariadne I had the discussion with work mates about the services (I think it was called Malus) where you can pay for letting your software vibecoded to avoid GPL.And then we realised that Palantir and other big tech software vendors loose market share because people also use AI to vibecode alternatives to proprietary software as well. So I think we lose some and gain some benefits here. In the end it evens out.GPL as Licence will probably still be important in the future.
       
 (DIR) Post #B6ouUgxbg9yDpen9bE by catselbow@fosstodon.org
       0 likes, 0 repeats
       
       @ariadne Be aware that openrsync isn't a drop-in replacement for rsync. We ran into problems when Apple replaced rsync with openrsync in Sequouia. Scripts that had previously worked broke. We ended up installing the real rsync using homebrew because we couldn't get things to work with openrsync.
       
 (DIR) Post #B6oywTg73Su4Yz77lg by jannem@fosstodon.org
       0 likes, 0 repeats
       
       @ariadne "Dependency network" or something along those lines?
       
 (DIR) Post #B6p0eERd9cNE0rle2C by jacel@m.prettyshiny.org
       0 likes, 0 repeats
       
       @ariadne so many years of talking about swiss cheese security and defence in depth, and reading right over the part where the pr is supposed to be the SECOND review; the first review is 'as I am writing the code'.Short circuiting that to 'the llm generated it, I reviewed it' is purposely discarding protections and nobody who buys into these things seems to care.
       
 (DIR) Post #B6p3CPyL08gTWFUk4G by suetanvil@freeradical.zone
       0 likes, 1 repeats
       
       @ariadne The copyright implications of this are completely unknown. When someone vibe-codes Photoshop or Windows 11 and successfully defends that in court, *then* I'll believe it. For now, it's a legal minefield.
       
 (DIR) Post #B6p7NtFwrcNvLOSSS8 by fazalmajid@vivaldi.net
       0 likes, 0 repeats
       
       @ariadne "dependency graph"?
       
 (DIR) Post #B6p9BISs1njvfcco1g by nobody@mastodon.acm.org
       0 likes, 0 repeats
       
       @ariadneLess applicable to rsync, but "bootstrap chain".
       
 (DIR) Post #B6pASi664zHI2tq99U by nicemicro@fosstodon.org
       0 likes, 0 repeats
       
       @ariadne @AmyZenunim this presupposes that only GPL licensed code will be vibe-coded.
       
 (DIR) Post #B6pj4TmX9KTr5ns2xk by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @otfrom I'm just tired of hearing about LLMs
       
 (DIR) Post #B6qI0xKArjZrxFf3KK by alwayscurious@infosec.exchange
       0 likes, 0 repeats
       
       @ariadne Yup.  Committing LLM-generated code is risky, unless the change is trivial (in which case it could be done without the LLM) or has a machine-checked proof of correctness.Using LLMs to find bugs in human-written code has been very successful, though.
       
 (DIR) Post #B6qPIDFbbXxdx2hSWe by llewelly@sauropods.win
       0 likes, 0 repeats
       
       @ariadne in science, there is a long tradition of using language that is practically the opposite of persuasive.Even though it's terrible for the careers of individual scientists, and their ability to convince the public, it's still a net benefit to the advancement of science.But the world of LLMs chose persuasive language.
       
 (DIR) Post #B6qVhnKXCMVCoYaSUC by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @AmyZenunim @ariadne no, it can still be a derived work of the inputs (including the “training data”
       
 (DIR) Post #B6rYF59AN6Cgh7EJu4 by solaslux@todon.nl
       0 likes, 0 repeats
       
       @ariadne software setup requirements. Vague. Broad. software minimum requirements. If you want to deploy XYour setup requirements are:a, b, c, d etc, and b requires B or you can use P but you then have to use p + k, instead of d use n OR rKind of touches on the existing packaging schemes for distribution (flatpak),
       
 (DIR) Post #B6t7hUzVZH4IVjxSWu by jack@xeno.glyphpress.com
       0 likes, 0 repeats
       
       @ariadne LLMs in general are a threat to copyleft, not just vibecoding. On the artist side of the house, people who used to be "put all your stuff on the internet for free" Creative Commons boosters are now really angry all that stuff they CC licensed ended up as LLM training fodder.
       
 (DIR) Post #B6t8BpezHlJLInp8C0 by jack@xeno.glyphpress.com
       0 likes, 0 repeats
       
       @ariadne I'm very interested in the differing reactions to this between the engineering and art communities.The pattern I see, & I wonder if you've noticed as well, is that engineers arguing against LLM are less focused on the theft of labor/expertise aspect of the debate. Instead, they focus more on the practical outcomes.
       
 (DIR) Post #B6tfY5Jp2paij08tGa by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @jack i think engineering communities are going to focus on outcomes because that is what we are trained to do.while it is *bad* that copyrighted creative works are the sum of the training materials used by the LLM companies, it is more difficult to quantify in an engineering discussion than "this thing generates code with errors"
       
 (DIR) Post #B6thvveIqcFbaqDfkW by jack@xeno.glyphpress.com
       0 likes, 0 repeats
       
       @ariadne For sure, & it's too bad for creative communities that they haven't yet identified something similarly cut & dried to focus on.
       
 (DIR) Post #B7YJQnuwkRZqLyfifA by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @tk @AmyZenunim @ell1e some have tried really hard to make that argument stick, but- intellectual property court cases are dominated by capitaland- capital wants to feed the slop machineso the courts are likely to side with the slop machine, even if their argument is stupid