Seems like he’s been pushed into using LLMs as a way to cope with the deluge of LLM-generated security reports.

  • Kissaki@programming.dev
    link
    fedilink
    English
    arrow-up
    85
    ·
    2 months ago

    Also, nobody actually knows if human intelligence is just finer grained stochastic prediction as well.

    An interesting but valid argument. It doesn’t make AI better than it is, but any human contribution and change can and often is also faulty. People have gaps of knowledge, sometimes unwarranted confidence, other times lack of care, or just miss things. It’s not like we’re comparing the perfect human vs faulty AI.

    If you don’t mind the security risk then you can of course use an older release.

    I haven’t read the original rage/drama but I can imagine if from other drama instances.

    This post is certainly a good, founded response.

    There’s some valid concerns in AI usage, but unwarranted or inappropriate harsh criticism when it’s an established trusted developer and engineer - if we assumed good practice before then we could assume continued good practice. Maybe LLM is one point of increasing skepticism, but criticism should be open, respectful, and fair.

    They invested a lot of time and effort into a public good project. In that context, they deserve at least respectful and non-worst-assumptuous criticism.

    • silver_wings_of_morning@feddit.dk
      link
      fedilink
      arrow-up
      36
      ·
      2 months ago

      Yeah, the current backlash over LLMs in any capacity is a meme. It has turned into tribal politics. There is no longer thought behind the criticisms.

      Also, it’s not the stochastic prediction part that makes LLMs “not intelligence” to me. It’s that it’s only predicting the next token in a string of text. I don’t believe this can approach what we do. To me it could well be that some other sort of token prediction is what we do even when we introspect and think of a model of the world.

      • supersquirrel@sopuli.xyz
        link
        fedilink
        arrow-up
        41
        ·
        edit-2
        2 months ago

        Yeah, the current backlash over LLMs in any capacity is a meme.

        No, you just don’t want to face the fact that a growing number of people are less gullible than you.

        • Womble@piefed.world
          link
          fedilink
          English
          arrow-up
          9
          ·
          2 months ago

          Thank you for providing a clear example of the “my side good your side bad” style of thinking that completely lacks critical thought.

      • Tiresia@slrpnk.net
        link
        fedilink
        arrow-up
        27
        ·
        2 months ago

        Most LLM implementations to have come out in the past year have had introspection - a section of text where they’re prompted to think1 about the problem at a meta level which isn’t shown to the users. LLM engineers are actively working on expanding this into a more persistent, consistent, and functional world model - a bunch of text statements that other parts of the implementation are trained to treat1 as probably factually true, which it is regularly prompted to curate1 based on its interpretation1 of user input and other data.

        For example, an LLM might have a world model statement that says “As an LLM I may be running at different times. Before stating the current time with confidence, check the current time with an external source such as the UTC API.” so an introspection scratchpad it generates might be “To answer that question accurately I need to know the time. I will refer to the UTC API. Ah, it returned 12:17 on June 3rd 2026. Since Britain is currently at UTC+1 I can confidently say the sun is up in Britain”, and then the text the user sees is “Thank you for asking, the sun is currently up in Britain”.

        As for the lack of thought behind LLM backlash, that’s a factor of human psychology. In order to free up limited mental capacity, the human brain automatically simplifies rules it has learned consciously, imperfectly archiving the conscious method of learning it to long-term memory. People made up their minds about LLMs, and now the reasons are archived and no longer necessary for people’s response to LLMs. So now when people see LLMs, they don’t use the thought, they can just do the behavior they decided on and move on with their life.

        Re-litigating LLMs feels like going to an old archive and digging through dusty tomes. It can absolutely be worth it, but it’s an effort you’re not going to put in just because you see someone using it or praising it.

        Personally, my opposition to non-local LLMs is enshittification. Every habit you let become dependent on LLMs will be used to exploit you. Your habits before LLMs will be archived and too much effort to relearn, so you’ll pay out your ass for a worse service than what you used to be able to do yourself. My opposition to all LLMs is veganism, but that’s a story for a different comment.


        1: LLM instruction text anthropomorphises LLMs. LLMs don’t do these cognitive tasks the same way a human would.

        • prole
          link
          fedilink
          arrow-up
          1
          ·
          2 months ago

          As for the lack of thought behind LLM backlash, that’s a factor of human psychology. In order to free up limited mental capacity, the human brain automatically simplifies rules it has learned consciously, imperfectly archiving the conscious method of learning it to long-term memory. People made up their minds about LLMs, and now the reasons are archived and no longer necessary for people’s response to LLMs. So now when people see LLMs, they don’t use the thought, they can just do the behavior they decided on and move on with their life.

          What an absolute crock of shit. Did your local LLM model tell you this?

          How convenient it must be for you to be able to disregard all criticism as simply “a lack of thought,” and that people have already made up their minds and don’t ever think about it again.

          Honestly, it’s fucking insulting. Just because you’ve given up basic critical thinking doesn’t mean everyone else has.

          • Tiresia@slrpnk.net
            link
            fedilink
            arrow-up
            1
            ·
            2 months ago

            Cached responses are healthy and natural, and they aren’t any more likely to be wrong than well-reasoned arguments.

            Like, suppose you were planning a dinner party with friends. One of them goes “person X? Ugh, can we not invite them?”, to which another friend goes into a long argument about why person X is totally better now. The first friend can’t really articulate what’s wrong, they just have a shitty feeling, and the arguments they use to explain that feeling are weak and full of holes. Which friend’s judgment would you be more inclined to trust?

            I for one would trust the friend with the feeling rather than the friend with the clearly reasoned argument 9 times out of 10.

            And so it is with LLMs/genAI. The reflexive repulsion towards them and towards people supporting them is well-earned. It’s healthy for people to set boundaries conservatively when so many genAI proponents are trying to weasel their way into acceptability with bad-faith comparisons, deliberate violation of “no genAI” boundaries as a form of gotcha, and a systematic lack of integration of critiques of genAI when trying to find new implementations. The Luddites were right, and so are anti-AI movements.

            All of which is to say, I think you got a false positive here, but you’ll get 'em next time.

            (You are correct that people do keep thinking about stuff and adding the impressions of those thoughts to the cached response. The analogy of a archive isn’t quite correct, it’s more like a giant pile of complaints that keeps getting added on to, that you need to shovel through to get back to that good point you heard 524 days ago, if it hasn’t disintegrated into abstract impression. I don’t think this changes the fundamental point, though, that usually the best reasons people have for believing something are not stored in their brain in a legible, rational format, and so the best actions - such as opposition to LLMs - are driven by emotional impression rather than thought).

      • traxex@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        15
        ·
        2 months ago

        Lmao bro, what do you think “stochastic prediction” means? It’s always the people who don’t even understand LLMs defending them the hardest.

        • prole
          link
          fedilink
          arrow-up
          1
          ·
          2 months ago

          They don’t know, it’s just a fancy term their local LLM spit out at them

      • cecilkorik@piefed.ca
        link
        fedilink
        English
        arrow-up
        12
        ·
        2 months ago

        I agree, I’ve been recommending people to try to develop some level of nuance on the topic. I understand the fear, hatred, and loathing of AI; especially the way it’s currently being implemented and used. I really do, and I share 99% of the concerns. But there is room for nuance in the understanding of how it’s being used and what it’s being used for and who is using it, and when nuance leaves the room, we’re blind. And blind hatred is never a good thing and it does not lead to good places.

      • 8oow3291d@feddit.dk
        link
        fedilink
        arrow-up
        2
        ·
        2 months ago

        It’s that it’s only predicting the next token in a string of text.

        An LLM has an internal state while predicting text. The “next token” chosen takes that state - a model of the world - into account. So a LLM is predicting the next token based on a world model and the previous text.

        Saying that it is “only predicting the next token”, without more context, while technically true is very misleading.

    • Zos_Kia@jlai.lu
      link
      fedilink
      arrow-up
      3
      ·
      2 months ago

      People have gaps of knowledge, sometimes unwarranted confidence, other times lack of care, or just miss things. It’s not like we’re comparing the perfect human vs faulty AI.

      I went through the trouble of looking at one of the problematic changes in the latest rsync release, and what happened is that it surfaced a bug introduced in 2007 which was previously silently ignored. That’s definitely a mistake any human contributor could have made.

  • valar@lemmy.ca
    link
    fedilink
    arrow-up
    65
    ·
    2 months ago

    I hate when AI people say “things are so different in just the past few weeks, what you know from last year is meaningless” without specifying what’s so groundbreaking that us regular folks wouldn’t be able to comprehend. It just seems like a way to shut people up and feel superior.

    • Bazoogle@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      2 months ago

      The point is that AI is developing at an insane rate. They don’t specify, because you would always have to be naming new things every other week, by the very nature of the statement. Things AI was not able to do a month ago, it may be able to do incredibly well now.

      If you want an example, AI in security vulnerabilities has made quite a breakthrough recently. Not just Mythos, but multiple AI’s are finding 15+ year old vulnerabilities in open source packages basically the entire world relies on. It couldn’t do that a few months ago.

      • x74sys@programming.dev
        link
        fedilink
        arrow-up
        1
        ·
        2 months ago

        But what they’re also implying is is that most people just can’t keep up. But they can, apparently.

        About the security stuff, I don’t think it is a question of whether AI could do it or couldn’t do it, it just wasn’t extensively used for it. For a long time there have been LLM bots trying to automatically identify security vulnerabilities in hopes of making “free money”, but it wasn’t effective. Now there’s people actually trying to find real issues. And I would argue that AI is not good at it. You can just let it ponder for as long as you can feed it with money, and you will definitely find vulnerabilities. The false-positive rate is very likely high. If I try to roll a dice 12 times, and 3 out of those were 6, then that doesn’t make me a good dice roller.

        I think it’s just more the act of discovering what we can do with AI. It’s like openclaw, that could’ve been around last year, it’s not like AI wasn’t capable enough at that point, it’s just that no-one thought of using it like that (or at least no-one built it to the extent of openclaw and got it that popular).

        • Bazoogle@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          2 months ago

          I think it’s just more the act of discovering what we can do with AI. It’s like openclaw, that could’ve been around last year, it’s not like AI wasn’t capable enough at that point, it’s just that no-one thought of using it like that

          What would you call developement/improvement if not exactly this? Some of histories biggest advancements are finding better ways to utilize things we already have

          • x74sys@programming.dev
            link
            fedilink
            arrow-up
            1
            ·
            2 months ago

            If you ask me personally, I don’t think that any of this has a benefit for anyone. I don’t think this is an advancement. It doesn’t make us work less, it just makes us achieve more in the same amount of time, or at least most people feel that way. It doesn’t make me more productive, it’s rather the opposite.

            And what good is it to us if we achieve more? The only benefit it has is for those god damned capitalists. Great for them. The pay we get stays the same, and it probably even gets less.

            OpenClaw? Why the fuck would I let an AI use my computer? I want to use my computer. I want to read my emails and I want to answer them. I want to research stuff and I want to learn. Why would I let an AI do all of those things? Hire a human because AI can’t touch grass? Seriously?

            It‘s all just so gimmicky, and yes it’s interesting and amazing that those things are possible, but it’s like flying humans to mars, it is really cool? Yeah. Will it have any real benefit? No.

            To me, this is all just fucking sad and will probably mark the advancement from late capitalism stage into hopefully complete economic chaos.

            So yeah, when it comes to AI, I‘m probably not the best one to ask.

    • sobchak@programming.dev
      link
      fedilink
      arrow-up
      4
      ·
      2 months ago

      i think he’s talking about agentic harnesses getting better, and the new models being finetuned to use them. I don’t think the new models are much “smarter,” but it allows them to write shitloads of bad code and tests, then iterate over them until they’re “fixed.”

  • slacktoid@lemmy.ml
    link
    fedilink
    English
    arrow-up
    55
    ·
    2 months ago

    I’ve said this before and I’ll say it again. If an established dev uses AI and you don’t want that? Then get involved.

      • binux@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        29
        ·
        edit-2
        2 months ago

        Well rsync is a pretty integral utility for a whole array of software at this point, and I guarantee you that not all of its userbase has the expertise required for direct contributions. I don’t think it’s fair to write off the complaints of people like that as irrelevant, especially if they have a stake in rsync working well for them without having to worry about AI hallucinations screwing them over.

        • slacktoid@lemmy.ml
          link
          fedilink
          English
          arrow-up
          12
          ·
          2 months ago

          I agree with the worry and wanting an alternative but demanding what the dev does is where it crosses a line I feel

          • binux@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            15
            ·
            2 months ago

            I agree with that too, though I think the self-righteous attitude like that of the person I’m replying to swings in the opposite direction a little too hard for my liking. There’s a happy balance, y’know?

            People shouldn’t complain in a dev’s ear like they owe them something they never promised, and people trying to call that out shouldn’t counter it with a demeaningly confrontational demeanour. Obviously that’s a lot to ask for on the internet, but it’s a good thing to try for at least.

            • slacktoid@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 months ago

              Tell me about it, I am skeptical about AI and I kinda wanna know the True Positive, true negative, false positive, false negatives with these AI classified bugs. Still a useful tool.

              I just think it’s unreasonable to ask someone to do dev work for free, either pay or contribute (code, docs, help in misc ways) or cash (and pull out when they do something you don’t approve that’s your right). But until there’s real fuckery let’s just open bug reports and complain about real issues that can be fixed.

        • onlinepersona@programming.dev
          link
          fedilink
          arrow-up
          7
          ·
          2 months ago

          It’s provided as is, no warranty, no guarantee. If you built your life around it, that’s on you, not the dev. If you want something else, do it yourself or pay somebody to do it for you.

          • binux@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            14
            ·
            2 months ago

            Fair, but a little empathy for rsync users who only mean well would go a long way. The everyone-for-themselves mentality doesn’t tend to be very helpful most of the time, if ever.

            • onlinepersona@programming.dev
              link
              fedilink
              arrow-up
              7
              ·
              2 months ago

              Meaning well and blasting the rsync maintainer with absolutist anti-LLM messages are very different things.

              Th rsync maintainer is ironing out issues. Use an old version and let him cook. Once things are stable, then pull the new version. If you’re on arch or another unstable distro that always pulls the latest version, this is what you signed up for. Staying on the bleeding edge means you’ll bleed.

              It doesn’t excuse attacking he maintainer who seems to be making a genuine effort. That shows a lack of empathy.

              • hendrik@palaver.p3x.de
                link
                fedilink
                English
                arrow-up
                3
                ·
                edit-2
                2 months ago

                We’re mixing up two things here. There’s valid criticism. And there’s the people who want to unleash some social-media style shitstorm. The latter show up in large groups and add some unsubstantiated comments, lots of emojis and drown any kind of conversation. But that doesn’t really take away from the valid criticism. For example a maintainer shouldn’t tag a version and release it, when it’s not ready to be released. That’s the 101 of software development. You can expect as much. Because the “bleeding” thing isn’t really how it works. Once there’s a new minor release tagged by the devs, it’s supposed to be picked up by the distro maintainers and get into any distro’s repositories. Doesn’t matter if it’s Arch unstable or Debian stable. They don’t want bugs and security vulnerabilities in their distro, either. Especially not when it’s 6(!) CVEs! And the Debian dev’s in fact reacted to this. And they even backported stuff to oldstable so the people who run the rock-stable stuff from 3 years ago get the patches! So it really doesn’t matter… Run a bleeding edge distro, or a stable one and don’t update it for 2 years, you’ll be affected by this both ways.

              • binux@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                2
                ·
                2 months ago

                Meaning well and blasting the rsync maintainer with absolutist anti-LLM messages are very different things.

                …Which is why I specified those who only mean well. Obviously that doesn’t include the less pleasant crowd.

      • slacktoid@lemmy.ml
        link
        fedilink
        English
        arrow-up
        10
        ·
        2 months ago

        I’ve had conversations with people when you say that, like they don’t want to get involved, don’t want to code, and they want the dev done their way. Like ok. WTF? Entitled much?

        And this is for established devs and their codebases, not some vibe kiddy

      • prole
        link
        fedilink
        arrow-up
        2
        ·
        2 months ago

        Yeah, everyone with a local LLM running on their PC who suddenly thinks they’re an expert in software development: time to bombard the creator of Rsync with AI bullshit that he will need to wade through.

      • wewbull@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        Contributions are not enough. It needs people to maintain it. That means dedicating time long term. It’s not a small undertaking.

        Contributions can be a step on the road though.

    • Bababasti@feddit.org
      link
      fedilink
      arrow-up
      8
      ·
      2 months ago

      Yea, I find all these knee jerk reactions directly asking for rsync alternatives once AI has been mentioned a bit annoying. Like, we wouldn’t be in this place if a project of this importance wouldn’t have been maintained only by a single dude for years…

      • slacktoid@lemmy.ml
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 months ago

        Completely, some people are just entitled especially in the FOSS and fuck AI crowd. Like I get it but FOSS is literally where it’s gonna be a net good.

          • slacktoid@lemmy.ml
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 months ago

            No net good would be if everyone chirping about AI use in coding picked up a book, Intro to C, Rust, hell even Java. Till then this is all we got. What’s your solution to the problem of developer burnout in FOSS projects?

            • petrol_sniff_king
              link
              fedilink
              arrow-up
              5
              ·
              2 months ago

              They could take a vacation. Generally, that’s how you deal with stress anyway.

              • slacktoid@lemmy.ml
                link
                fedilink
                English
                arrow-up
                2
                ·
                2 months ago

                And who has the time or money for that whenever you want or can? Especially when you’re asked to come out of retirement. Stop being an entitled brat

                • petrol_sniff_king
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  2 months ago

                  This is volunteer work! He can stop doing it at literally any time! No one is forcing him to do this!

                  The more you people go on about how much he has to work, the more I’m thinking that this whole open source thing is a huge human rights violation.

                • petrol_sniff_king
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  2 months ago

                  Money doesn’t reduce stress, it makes people more willing to put up with it.

                  You people are acting like this man has to finish this mukbang 5-foot-long sandwich, and somehow I’m the asshole who wants him to get heartburn because there isn’t a second guy there to help him eat the sandwich.

    • bignose@programming.dev
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 months ago

      No. If an established dev leans on LLMs for coding and shovels it into the main branch, they have abdicated their responsibility and trashed their reputation. We get to point that out

      without any obligation to do their work for them.

      • slacktoid@lemmy.ml
        link
        fedilink
        English
        arrow-up
        8
        ·
        2 months ago

        Point it out, doesn’t change the fact that you’re not addressing the core problem, which is developer burnout in these FOSS projects.

        Also no its not their work, its literally a voluntary job so stop dictating how people spend their free time.

        But that’s just me, you do you.

      • onlinepersona@programming.dev
        link
        fedilink
        arrow-up
        3
        ·
        2 months ago

        It’s his project. He can do whatever he wants to with it. He doesn’t have a “responsibility” to you or anybody else. Stop being so entitled.

      • Kissaki@programming.dev
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        This reasoning assumes any LLM-assisted change is faulty, right?

        The linked article doesn’t make me concerned. They seem to have the expertise, seem to apply due diligence and good practice around (selectively) using LLM.

        Can people not directly involved in and working on the project assess the risks well? Do we not have to depend on author and project leadership expertise just like we had to before with any parts of development, management, and tool and infrastructure use?

        I haven’t looked up the original communication or drama, but I assume communication could have been much better. Maybe the commits didn’t say much about the reasoning and due diligence that they describe in this article? Other than that, how can you make a better judgment about the changes than them without taking a thorough look and assessment?

  • Mikina@programming.dev
    link
    fedilink
    arrow-up
    47
    ·
    edit-2
    2 months ago

    I can’t wait for companies to finally price out most of developers out of AI use, especially the FOSS ones.

    I just hope most of them won’t get too addicted to the tech crack they are getting free/cheap samples of currently, and will be able able to find back their motivation and skill to work without a feel-good dopamine machines.

    Also, lol at all the coments being like “if you’re 100% against the tech crack, you’re delusional. The cat is already out of the bag, it makes you way better at coding, if you use it responsibly!”

    The problem isn’t that it’s not somewhat good, the issue is that soon you won’t be able to afford it, while also being addicted and dependant on it. But I’m sure y’all are able to use crack responsibly and will be fiiine.

    • locuester@lemmy.zip
      link
      fedilink
      English
      arrow-up
      22
      ·
      2 months ago

      I run Qwen 3.6 27B at home. For “free”. It is extremely useful.

      My point being that I’m not going to be priced out of using it

      • Mikina@programming.dev
        link
        fedilink
        arrow-up
        2
        ·
        2 months ago

        What hardware that needs? My issue with running local models was that it’s too much of a resource hog to be able to do gamedev on the same machine, and any sensible model needs pretty expensive hardware to just get a server for it. Especially with current prices.

        • locuester@lemmy.zip
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 months ago

          64GB unified memory. I run it (and a lot more) on a dgx spark, but a Mac mini would suffice also.

          You could prob run 4-bit version on a RTX card with 32g. Maybe even 24g. Like a 5090 or 4090 or such.

          So much info out there.

          • wewbull@feddit.uk
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 months ago

            Mac Minis top out at 48GB and are 1.8k when configured like that. It’s going to be at least $2k to buy anything that has a hope of running it at a reasonable speed.

            Running local isn’t free, but at least it’s just a single upfront payment.

            • Darkaga@lemmy.world
              link
              fedilink
              arrow-up
              2
              ·
              2 months ago

              The M4 Pro Mac Mini caps out at 64GB RAM. Whether or not Apple can sell you that SKU right now is a different question with the ongoing DRAM shortage.

        • AlteredEgo@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          2 months ago

          Geforce 3090 with 24TB should be able to run a “Q5 version” of it. Maybe get a second older computer, or maybe you can run two cards in one PC.

      • EldritchFemininity
        link
        fedilink
        arrow-up
        1
        ·
        2 months ago

        Don’t worry, they want to replace your hardware with a “cloud based computing solution” as well.

        When did that absurdity come back? I thought we killed the cloud computer nonsense a decade ago.

    • Bogus007@lemmy.zip
      link
      fedilink
      arrow-up
      7
      ·
      2 months ago

      If the project is understaffed and mistakes were made, wouldn’t it be more constructive to help maintain it or encourage broader participation, rather than dogpiling on a volunteer maintainer?

    • COASTER1921@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      2 months ago

      Even if too expensive for FOSS devs the mega corps relying on their software will still be able to afford them to run their own security testing, feeding the bug reports back to the project. And with time the hardware and models are only getting more efficient (for a comparable performance level).

  • ooterness@lemmy.world
    link
    fedilink
    English
    arrow-up
    45
    ·
    2 months ago

    The whole rsync repo is 65k lines total. Recent AI-centric changes account for +16k/-6k, including massive changes to the unit tests. Somehow that’s not even considered a “minor” update (v3.4.1 to v3.4.3).

    That’s not responsible use of AI, that’s malpractice.

    • Buddahriffic@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      2 months ago

      Any specific issues though? Yeah, it’s a large change and I’d be more surprised if it didn’t have issues, but are there any specific issues with the updates that have been found so far?

        • fruitcantfly@programming.dev
          link
          fedilink
          arrow-up
          5
          ·
          2 months ago

          Yes, there’s been several regressions that would’ve been caught by the original tests, but missed by the new vibe-coded tests.

          That is directly contradicted by what the developer of rsync wrote in the linked article:

          yes, there were regressions in some use cases of rsync in the 3.4.3 release. … None of those cases were covered by the existing rsync test suite or by all the manual testing I did (yes, I use rsync, I don’t just develop it).

          It’s possible that somebody in the issue you linked to pointed to a test that would have caught one of the regressions, but I was not able to find it in the 327 comment mess. A direct link would be appreciated, if that is the case.

          But I doubt that you will find such a comment. Because I tried running the 3.4.1 test-suite with the 3.4.3 binary, and all tests passed

          • ooterness@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 months ago

            Seems I was mistaken. My previous statement was based on what others have said, but I haven’t actually run the tests myself. In any case, I have learned not to rely on statements made by the accused in this type of dispute.

    • Kissaki@programming.dev
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 months ago

      Have you read the linked article? They explain how they used AI. It’s not like AI produced the code and that’s it.

      They also explain about this version and the next minor version.

    • ikidd@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      3
      ·
      2 months ago

      Then get on your IDE and lend them a hand. Then the retired guy that’s asked for help several times in the last decade unsuccessfully wouldn’t have to buy tokens to get help.

      Seems like most people want to spend their effort getting on their high horse instead of being the change they want to see.

  • exu@feditown.com
    link
    fedilink
    English
    arrow-up
    43
    ·
    2 months ago

    He makes some fair points. However I do think the large amount of regressions in 3.4.3 should have resulted in a new release rolling back those changes.

    I still like the response of the libxml2 maintainer, where any vulnerability will be disclosed openly and fixed when it’s ready. Maybe more open source projects currently drowning in CVE should take that stance instead of their maintainers burning themselves out over it.

  • iglou@programming.dev
    link
    fedilink
    arrow-up
    28
    ·
    2 months ago

    I used AI tools to do the grunt work because they are good at that.

    This is something people complaining should remember. AI is good at some parts of the work of a software engineer: the grunt work.

    • wewbull@feddit.uk
      link
      fedilink
      English
      arrow-up
      26
      ·
      2 months ago

      People pointing at new breakages are trying to say “No it isn’t and here’s the proof”.

      • Bazoogle@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        2 months ago

        How do you know those were the result of the AI?

        I quite deliberately tried to err on the side of fixing security issues for that release, and there were some valid (but unusual) use cases that got caught up in the changes.

        Seems to me like it was just his own fault. AI may very well have had nothing to do with the regressions, other than maybe not identifying them?

    • Kairos@lemmy.today
      link
      fedilink
      arrow-up
      4
      ·
      2 months ago

      As a software engineer, the grunt work is reasoning about my code, something a statistical model can’t do.

    • wpb@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      2 months ago

      Apparently not good enough, if we look at the case of rsync. Remember, this while conversation started because of some show stopping bugs caused by generated code.

  • Bazoogle@lemmy.world
    link
    fedilink
    arrow-up
    26
    ·
    2 months ago

    Seems like he’s been pushed into using LLMs as a way to cope with the deluge of LLM-generated security reports

    It’s not just LLM generated security reports, but vulnerabilities discovered by AI. Your wording implies they were just reports, and of less validity. Lazy LLM reports are not what he is trying to cope with, since there is nothing to do but close those reports. He is talking about real, verified, vulnerabilities that weren’t discovered until AI tools. Not because humans couldn’t find them, but none ever did. When it comes to finding, it really doesn’t matter if it’s found by human or AI, since that doesn’t change its existence or severity.

    • Nalivai@lemmy.world
      link
      fedilink
      arrow-up
      11
      ·
      2 months ago

      I am reporting that every line of your code has 17 errors. I just generated 1562364 bug reports for you. Now you just need to close those that are false, no big deal.

    • Theoriginalthon@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      2 months ago

      And the side that noone else talks about, threat actors are highly likely to be using ai to find these potential vulnerability. So you you are not doing the same you are immediately at a disadvantage

  • misk@piefed.social
    link
    fedilink
    English
    arrow-up
    26
    ·
    2 months ago

    Also, nobody actually knows if human intelligence is just finer grained stochastic prediction as well.

    I think some people are stochastic parrots and some are not. I think most of our true understanding of things comes from escaping our limitations. Why so many people want to become a stochastic parrot is beyond me though.

    Now to the future, because we’re not done yet by a long shot. The security reports keep rolling in. I’m working on a bunch of CVEs right now. Luckily I’ve been joined by some other very good developers with great systems development skills and security knowledge. Some of these people came to my attention partly because of all the rage happening at the moment, so I get some rage storm clouds have silver linings. Watch out for some credits for some great new rsync developers in the next release.

    The project is being taken over by vibe coders, yay.

    • Lucy :3@feddit.org
      link
      fedilink
      arrow-up
      14
      ·
      edit-2
      2 months ago

      In my perception¹, ML differs from a brain by operating on words in form of tokens, while the human brain works by associating a concrete piece of information or thing with another, with the path in between being formed at some points, but crucially, being editable more or less easily and flexibly by retraining. And that’s the points, humans learn on a fundamental level. Dropping the prod DB means that my brain will form a hard association between the action of writing ‘drop database’ and fear, which in turn triggers deeper thoughts about wth I’m doing. LLMs see “conflict at line 1, 12”, and for some reason one possible path of tokens to generate can be a drop command. And as the underlying model data does not change, they don’t learn.

      On how living being’s speech centres work, idk.

      ¹The perception of an acidhead. So don’t trust me.

      • TehPers@beehaw.org
        link
        fedilink
        English
        arrow-up
        28
        ·
        2 months ago

        The differences between a human brain and any kind of model we can currently train are too great to be listed. They are incomparable. It turns out that no matter how many perceptrons you put together, you don’t get a brain.

        Heck, we don’t even know how brains work, and you got people talking about how they’re making AI clones of themselves with LLMs lol.

      • misk@piefed.social
        link
        fedilink
        English
        arrow-up
        9
        ·
        edit-2
        2 months ago

        You can look at the tone of the whole post to understand where the author is mentally. You can also make an educated guess about who will want to work on a project that’s being coded with LLMs. If I’m wrong remind me and I’ll own it. But I don’t think I am.

          • misk@piefed.social
            link
            fedilink
            English
            arrow-up
            9
            ·
            2 months ago

            Lol, I’m not a court of law, I’m a person. I can make my own judgments based on what someone said and how they said it.

            • MagnificentSteiner@lemmy.zip
              link
              fedilink
              English
              arrow-up
              6
              ·
              2 months ago

              Cool story bro.

              Conjecture (and largely unfounded at that) isn’t evidence. I’d bet money that you don’t even have the ability to evaluate the project to determine if it’s being vibe-coded (as it seems is the case for everyone raging about this).

              Lol, I’m not a court of law, I’m a person.

              Get lost with this deflection crap. You’re the one who was making a definitive statement (“The project is being taken over by vibe coders, yay.”) about a widely respected figure responsible for creating one of the most used pieces of software ever (not to mention Samba too) who IMO deserves the benefit of the doubt until proven otherwise.

              I merely asked you to provide evidence to back up your statement and clearly you’re unable to do that. Don’t try to push it back onto me trying to make me seem unreasonable for asking.

              • misk@piefed.social
                link
                fedilink
                English
                arrow-up
                4
                ·
                2 months ago

                I’ve seen it enough times to see a pattern. This post is riddled with tech bro language, there’s no denying it. More of it is coming with everything that entails.

                Thankfully there’s still openrsync. I didn’t even realise I was already using it so I’m not invested into arguing further. To all vanilla rsync users, Godspeed.

      • TheOctonaut@piefed.zip
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 months ago

        There is a significant majority of people on Lemmy who think installing Linux made them a software engineer and think that code completion is “vibe-coding” and not a basic feature of fucking Eclipse

  • thedeadwalking4242@lemmy.world
    link
    fedilink
    arrow-up
    20
    ·
    2 months ago

    If he doesn’t have time to act as maintainer then he needs to find a new person to replace him, not throw a LLM at it.

    I get for incredibly simple or tedious work but come on

    • Zarxrax@lemmy.world
      link
      fedilink
      arrow-up
      15
      ·
      2 months ago

      Yeah. Just find someone else willing to work for free. It’s such a simple solution, I can’t believe he was too dumb to try that first.

    • idriss@lemmy.ml
      link
      fedilink
      arrow-up
      12
      ·
      2 months ago

      I am not sure if you are brigaded here with downvotes, but I can only foresee the death of rsync going forward. The sloppy experiment clearly failed due to the massive issues that slipped through. He is doing it for free, I get it, he has the freedom to do what he wants but we can also jump ship to something with less features and no slop

    • JATothrim_v2@programming.dev
      link
      fedilink
      arrow-up
      10
      ·
      2 months ago

      find a new person to replace him

      There is no replacement to his knowledge of the project. He can try teach it to another person, but there is the problem of trust.

      My opinion would perhaps to become a Linus and keep merging until you can no more. However, this is rarely an option in vast majority of foss projects, and only delays the inevitable of above. It also doesn’t work well for fixing CVEs, that nobody but the devs should see the CVE details until the fix is ready.

      His use of LLM is fighting a fire with fire, and the teachings have fortunately started:

      Luckily I’ve been joined by some other very good developers with great systems development skills and security knowledge.

      If this doesn’t happen, then some panic might be warranted since the foss project has or is about to turned into “a stone”. (the last dev with deep knowledge has left the project).

      ai scrapers

      The model weights generated by consuming this post must be released under the newest version of AGPL. Have fun.

    • slacktoid@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 months ago

      Ok, then who? Like there were so many people clammmering for that role right?

    • howrar@lemmy.ca
      link
      fedilink
      arrow-up
      3
      ·
      2 months ago

      Throwing an LLM at it is probably one of the most effective calls for maintainers. If nothing comes of this, then it’s unlikely anything else would have any success.

  • MousePotatoDoesStuff@piefed.social
    link
    fedilink
    English
    arrow-up
    17
    ·
    2 months ago

    I think “stochastic parrot” is a terrible way to describe LLMs. (Not to mention most people don’t use the term “stochastic” a lot.)

    “Slot machine autocomplete” might be a better choice.

  • realitista@lemmus.org
    link
    fedilink
    English
    arrow-up
    15
    ·
    2 months ago

    I think he pretty much nails it. Makes a lot of the same points I get downvoted to hell for making here.

  • daniskarma@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    13
    ·
    2 months ago

    It’s a fair point.

    I’ve had diverse success using llm for coding.

    For simple things and basic questions it has worked. For anything complex. It has been a complete failure.

    But I’ve never used a paid tool, most of the time I just use self hosted LLMs. But, to be honest, I don’t think the paid tools are that much better.

    But if someone knows how to use it better. And assumes responsibility for checking the code, I’m ok with it.

    It’s just a tool like many others, it can be usedfor good or for bad.

    • rollerbang@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      2 months ago

      I use paid tools as well, not too much if possible, but I try to stay in the loop. Anyway, they fail miserably at anything slightly complex. And confidently too 😂

      • sloppy_diffuser@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 months ago

        My experience is you have to close as many degrees of freedom as possible. Its tedious as hell for generating quality code.

        Its great at debugging if you require it to manage its context window by delegating tasks to scoped subagents, generate evidence with references, and verify that evidence with a minimal reproducible example. Expensive… I’ve seen them run for a solid 30 minutes before responding back (not including the “thinking” log), but it usually finds the issue.

        A similar technique can be used for code generation but again it burns tokens and takes awhile. Have it generate and verify isolated reference implementations for anything nontrivial. Much easier to review with the rest of your domain and layered on complexity stripped out. The “thinking” log is interesting to watch as it bangs it head against bad assumptions or documentation and needs to start digging into dependency source code to work it out.

        Only then apply the implementation to your project from the reference implementation. Takes breaking down the tasks though to small enough units and closing those degrees of freedom.

        Anecdote on degrees of freedom: This one didn’t require a reference implementation in particular. I was reviewing a PR (LLM assisted, I wasn’t the authoring dev) to add signature validation to OAuth tokens. It duplicated the entire header/token parsing logic. It needed that path closed with a pointer to where the existing logic was and explicit requirements to enhance it. Refactor was great upon reviewing and the PR size was reduced by more than half.

  • MehBlah@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 months ago

    If you read this Andrew, most of us support your reasoned use of AI. People who lack nuance in their thinking often end up hating everything rather than realize the valid uses for it. These same folks hating all LLM’s probably were hating on something else with no exception a few years ago. I use rsync and have for years. Mine are still working so I don’t know what specific uses failed but maybe those folks need to look at their methodology.

    • prole
      link
      fedilink
      arrow-up
      1
      ·
      2 months ago

      People who lack nuance in their thinking

      Talk about a straw man

  • Shin@piefed.social
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 months ago

    That was a fair response. But I get the feeling that a lot of “intelligence” is given in this tool. Feels like they are seeing something that I’m not.

    • Kissaki@programming.dev
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      I didn’t get that feeling at all. They didn’t make any such claims or used such wordings which I often see elsewhere.

      • Shin@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        Well I can always point to English isn’t my native tongue, so I can always infer stuff that isn’t there :D

        Still, the way it explain give the idea of something that I can’t see it. And this is what is concerning me for the last week at least.

        • ReptilianCleric@lemmy.zip
          link
          fedilink
          arrow-up
          3
          ·
          2 months ago

          Trust. For me that fits your description, the thing I don’t “see” but some out there do. I try to keep an open mind, but the way this stuff is being sold hard bothers me.