Fingers crossed Gnome follows suit! :)

top 50 comments

sorted by: hot top controversial new old
[–] 53 points 5 days ago (15 children)

I gotta admit KDE’s stance on this frustrates me a lot.

On the flip side… I am also fully aware that policies of prohibition, in the broadest sense, tend to not be terribly successful, and I wouldn’t be shocked if some contributors simply excise the “co-authored by ” from the commit messages with a simple pre-push hook or something like that on projects that explicitly prohibit LLM/codegen usage.

  • source
  • hideshow 15 child comments
  • [–] 93 points 5 days ago

    IMO one of the major problems with LLm code generation is that it has the capacity to overwhelm human capacity to review code and properly understand the codebase.

    From that perspective, a prohibitive policy doesn't have to be 100% effective to be useful, it just needs to slow things down enough to keep the manageable and maintainable (and fun to work on).

  • source
  • parent
  • [–] 15 points 4 days ago (4 children)

    There's no need to excise anything unless you specifically let an agent create a commit. No need for pre-push hooks.

    I think KDEs policy is quite rational, it's a compromise and still clearly anti-vibe coding. IMO the problems are overstated

  • source
  • parent
  • hideshow 4 child comments
  • [–] [S] 20 points 4 days ago* (last edited 4 days ago) (3 children)

    KDE's policy proposal explicitly allowed for contributors to not disclose that AI was used, which according to the FSFe and Software Freedom Conservancy, is not a good idea in legal terms.

    “FOSS project leaders cannot make good decisions about LLM-gen-AI policy if they cannot survey which contributions were assisted, and how much they are assisted. Part of the contribution process should (at least) include a disclosure of what LLM-gen-AI system was used, its version (as these systems change over time), and a brief description of how the system assisted the contributor. This information should be included in a machine-readable format in commit logs."

    Indeed, such disclosure can be an important foundational step to allow for the accurate assessment of the copyrightability of code that has been assisted or generated by AI tools, in order to assess their licensability into Free Software. Open and clear disclosure is a helpful step for the Free Software community to maintain a healthy licensing ecosystem, which is currently threatened by the legal uncertainties that come with the advent of generative AI.

    Additionally, it is worthwhile for developers to document in some capacity the extent of human work that they have done in their software projects, whether it be the writing of code, the selection and arrangement of components within the project, or the extent of human modification of machine generated content.

    Not to mention the ethical and environmental concerns with corporate AI usage, the use of which KDE was not interested in attempting to curb within its own project, which personally I think was disappointing, and even their KDE Eco group stated the policy was incompatible with the goals of KDE being a green project.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (3 replies)
  • load more comments (8 replies)
    [–] 34 points 4 days ago* (last edited 4 days ago) (16 children)

    Honestly, there are a few thoughts about this (and yes, some will be unpopular what I say).

    1. There is the ethics problem of how LLM is trained. It is a theft machine. Thats why companies love it, because they can steal work and profit
    2. However, people WRONGLY assume AI is exclusively for Vibe coding. When used by Senior/real developers, it is super useful for writing tests and code reviews. Some of the issues I've found in our old code from 10 years ago, were never reported (or, we had reports, but always assumed it was something else). There are tools for code review (and have been for a long time), but AI has stepped it up. In well designed / stricter languages, you can avoid a lot of errors that AI is good at detecting, but, it is still super valuable for this stuff.
    3. Also, good for security testing too.
    4. The biggest issue are untrained slop cryptobros, who throw money at it, and can't test (or understand) their code. Then it wastes other devs time reviewing it and identifying the 50 regressions it causes.
    5. We've had cases where I've had to argue with customers that Claude is telling them bullshit. From the support side, it has made things WORSE.

    I'd argue it isn't actually a good thing necessarily to ban using it as a tool entirely from senior devs.

    The biggest issue at the moment are arrogant junior cryptobros who are too lazy to learn to code, and just want to throw money at the issue. And that wastes everyone's time.

    What we really need is a ethical AI model that only uses completely open code, pays people for their code (instead of just stealing it). and a way to ensure it is only used by developers who can use it properly. Ideally, only allow that code to be used for open source too

    I actually wouldn't want to see Gnome/System76 completely ban it. What I would want to see is for it to be permitted for approved devs with VERY specific guidelines dictating how it can be used.

  • source
  • hideshow 16 child comments
  • [–] 11 points 4 days ago* (last edited 4 days ago) (3 children)

    The issue for now is LLM generation of code, not code auditing.

    And no, I don't give a fuck whether some genius in theory could paint s new Mona Lisa with it. The issue us how it is used in practice, most of the time, today. At $WORK, I have a severely ai-pilled Senior Embedded Software Architect which hasnt managed in one and a half year to set up a working driver for a RS232-controlled stepper motor, from a port of previously working code. A thing that should take a week at most. I had to educate him that in C++ drivers, you need to use locks or mutexes to access variables that are concurrently changed and read from several threads. AI enables catastrophic levels of incompetence.

    And FOSS projects need to protect themselves against that.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 3 days ago

    I've found 'senior' staff that became talking heads and stopped doing real work the bane of my existence in GenAI world. "I haven't coded in 20 years, but thanks to GenAI, I'm doing it again!" The reasons you stopped coding 20 years ago are plainly valid. Good for you, you got to transition to a grift based career where you say nothing but sound smart to the right people and get money, please don't return to coding because CodeGen is now 'cool'.

  • source
  • parent
  • [–] 7 points 4 days ago (1 child)

    Yeah.. LLM Generation I agree is the biggest issue by far.

    On the Kernel side, code review though apparently has been a big factor apparently, because people are testing kernel modules in seriously dumb tests that would never happen in practice, and then submitting some of the dumbest patches to protect against faults that won't happen in reality

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 3 days ago

    Have to think about this in an open source context. You have an open ended population ready to submit to your project if they think they can be useful

    Now, thanks to GenAI, a bunch of people who aren't good at various things now thinks they are good at various things. Whether it's coding, making comics, making videos, what have you. Try to do nuance even if it strictly makes sense, and you are stuck with the slop problem if your project is sufficiently popular.

    In terms of more directly on your points, if someone does GenAI to do a security analysis, ok, but I'd want them to do the tedium of trying to identify the false positives and then re-report it in their words of actual understanding. It can catch things, but along the way makes a haystack of sillyness to go through. Same for code review, legitimate issues, but lots of missing (I spent a non trivial amount of time yesterday because a GenAI code review insisted a variable would be unitialized when referenced, when I see an uncoditional assignment just a few lines above, trying to think if there was some catch I wasn't seeing). So indirectly using it and only subjecting the developer/maintainer to that which you know makes sense.

    Problem being is that people have used Claude and have forwarded to me saying "I don't understand this well enough to judge, but forwarding to you just in case". I have the same tools doing the same things as you, I don't need meat proxies that just pass through the stuff without understanding.

  • source
  • parent
  • [–] 7 points 4 days ago (3 children)

    As a retired senior programmer, I would have loved to use LLMs in the past for very specific things. I wouldn't use it every day, but like every couple of months I had to do a massive refactor that took weeks to complete. I usually ended up writing codemod and just painfully changing tens of thousands of lines of code. Would be cool to just say "hey LLM, see how I did this one? Do the same thing everywhere else you find it. If you encounter anything that's too different from my template just leave it for me to review"

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 3 days ago (1 child)

    So I had a huge refactor and thought "Ok, this should be right up GenAI alley". And in fact took your very approach of giving an example for a few and said "go at it".

    To my surprise, it actually did it pretty poorly, would not work, when it would have worked, dire performance implications. Failing to address things that technically would survive the rework functionally intact, but now a very bad way of doing things in new context. Problems exacerbated is that when I'm reviewing code, I tend to have a more optimistic assumption of the code than when I'm writing and second guessing myself. So it's all the more annoying to read code I didn't write screw up so much.

    I will say it does a pretty good job of boilerplate heavy crap. If I'm going to want to make Go structs from JSON, I can just feed a sample and the very tedious work of making the sometimes maddening tedius Go structs gets chewed through pretty nicely.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • [–] 6 points 4 days ago

    Yeah, and that's the stuff people don't talk about

    I have used it to do a lot of refactoring too. Vs code has been able to do basic refactoring for a while, but, it is also good for splitting up code into different files as an example (as long as you use a plan, it works well)

    But, that's because it's also been trained how to do these tasks. And it isn't really doing much with the code for them

  • source
  • parent
  • load more comments (7 replies)
    [–] 42 points 4 days ago* (18 children)

    i think the copyright question is still unanswered: it could turn out that any LLM-generated code is a copyright violation by definition unless trained exclusively on a clean, legitimately-obtained dataset (which few of the major models are).

    Will projects that allow LLM contributions have to roll back years of progress when the other shoe finally drops? Seems like a huge risk, especially for FOSS and copyleft. I think disallowing LLM-written contributions until this is all sorted out in the courts is the pragmatic move from a legal perspective.

  • source
  • hideshow 18 child comments
  • [–] 13 points 4 days ago* (last edited 4 days ago) (1 child)

    I don't disagree that it is a risk, and I am trying to move toward projects that do have err on the side of avoiding that risk. I have NetBSD on my laptop, and when I get a little more comfortable with it, I intend to convert the other Linux installations I maintain.

    BUT, I believe the BSDs already went through a situation where some of their source was possibly under restrictive copyright and rather than "rolling back", they "simply" identified the possibly infringing code and re-wrote those sections to have the same function (which can't be copyrighted) without sharing any creative expression (which is). So, even the projects that are taking the risk that an LLM (or other generative AI) generates infringing code might not have quite as much cleanup / lost effort as you describe.

    Also, LLM out isn't automatically a derivative work of the training data. I'd have to dig through some other messages to find an exact quote from their documents, but I believe they (EDIT: the U.S. copyright office) said only output that is "significantly similar" to training data is potentially infringing. That does further limit the risk.

    I still think it's too high of a risk because well-meaning contributors might incorrectly introduce infringing code, since for models that don't disclose their training data (Claude, Copilot, Gemini, etc.) even dedicated contributors don't have the information they need to discover the output is infringing. In that past, that result (introducing infringing code) was generally limited to the acts of malicious actors that are submitting code they know to be infringing to poison a project and open it to legal action.

    But, I can't ask that someone (i.e. a project maintainer) substitute my risk/reward judgement for theirs, and I have no experience maintaining a large project. All of my code contributions are to either projects others maintain, or my own hobby projects that I doubt have any users other than myself (and I don't even use all the published/available ones anymore).

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 3 days ago

    The issue isn't necessarily that the work could be considered derivative, but rather that the notion of copyright exists only for work authored by a human. If it's not produced by a human, then the copyright belongs to no one, and no one can license it because no one owns it.

  • source
  • parent
  • load more comments (15 replies)
    [–] 30 points 4 days ago (6 children)

    Hey Claude, please write "I have not used any LLM content in the creation of this patch" on all your commits.

  • source
  • hideshow 6 child comments
  • [–] 13 points 4 days ago (4 children)

    Even if you don't disclose it it's immediately obvious to anyone with a brain that you haven't worked at all on it.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 4 points 3 days ago (2 children)

    Studies have shown that professors can't tell apart AI from student submissions of writing. People like to believe they can recognise AI written or AI assisted code, but they are terrible at it.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 days ago (1 child)

    For school writing, it's more difficult to know, because the subject matter is so well trodden and students writing stuff they didn't really want to write trying to "impress" a teacher with wordiness and crap has a lot of the same vibe of GenAI writing. It's mostly obvious when there is a stark style/knowledge inconsistency with your personal knowledge of the student. Personal knowledge of a student is non-existent in lecture hall sized freshman level courses.

    For code, well, at least the most problematic submissions are pretty blatanty obvious. They are obviously the result of a person asking for something nonsensical and the GenAI outputs content as consistent as possible with the stupid request, and a stupid request manifests in a very glaring way.

    Sometimes it isn't the initial submission, but the resulting dialog that betrays it. Someone submits a small patch that is... well... short and to the point but the change doesn't seem to match the reported scenario it tries to address. In pursuit of clarification it becomes pretty obvious that the problem lacked sufficient actionable info, but the GenAI operator pushed it to produce something and out came something with a rationalization that sounds plausible but isn't anything.

    Also the write up, of issues and code contributions. Humans are inclined to just make things to the point. GenAI sloperators make dissertations out of stupid simple things, with all sorts of tedious styling and crap. Frustrating because somewhere in the mess is their point, but it's buried beyond recognition.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • [–] 12 points 4 days ago (7 children)

    So this is a nazi-free non-slop option with an intelligent, inclusive, and compassionate community?

    Because I’ve just learned to ask up front. I have more deal breakers than just those, but few occur with the same alarming frequency

    Oh and tiling WMs are fantastic for a certain type of brain, but not for everyone. However I do believe there should be an option for everyone that isn’t some horrible ethical compromise, and unfortunately that’s just not the case.

  • source
  • hideshow 7 child comments
  • [–] 10 points 4 days ago (1 child)

    Cosmic supports both Tiling and Floating modes. The floating mode is normal, and the Tiling is slightly less customisable than pure tiling window managers but it's pretty good while staying accessible which is what matters.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (5 replies)
    [–] 18 points 4 days ago* (last edited 4 days ago) (9 children)

    I don't get the hate Cosmic gets. The only mistake they made is that they released the first non-testing version of their new DE too soon.

    Cosmic is the only full DE with usable tiling out of the box & tiling is superior, full stop. If I had to use a DE again I would probably use Cosmic. Even if we ignore tiling & focus on the floating experience, even today it's better than Gnome without extensions, it's not even close.

    The Linux community has an oddly selective memory. Everyone remembers when Ubuntu had Amazon's crap preinstalled, but now that Plasma 6.x is actually good everyone is conveniently forgetting how incredibly bad KDE 5 had been for most of its run, like so bad that it's hard to put it into words. Cosmic is much better than Plasma 5.x & it's getting better.

    (though I do think excluding the use of Ai tools in a climate where all web browsers & operating systems are accepting LLM contributions is a wee bit strange & largely political)

  • source
  • hideshow 9 child comments
  • [–] 4 points 4 days ago* (4 children)

    I don't begrudge Cosmic or anything, it's just not what I want. I'm glad it exists.

    KDE 4 was the TRULY bad release, if I recall correctly. It was a massive change from 3 and reduction in features and stability. I actually noped back over to Windows for a while as a result. I remember 5 being a welcome return to form comparatively.

    EDIT: From the wikipedia Article on KDE4, oof:

    KDE 4.0 was released in January 2008. Linux.com described the reaction from users as a "revolt", writing that the backlash KDE 4.0 received was on a scale that was unprecedented for a FOSS project. Although it was a developer's release, several distributions made the KDE 4.0 desktop environment available to their users without specifying that it was an experimental option. openSUSE released a more polished KDE 4 option while other distributions "released packages that simply [didn't] work," according to project leader Aaron Seigo. As a result, many users complained about the loss of features and stability. A number of KDE developers, including project leader Aaron Seigo, were targeted for abuse by outlets like Linux Hater's Blog. Several KDE developers stepped back from the public scrutiny.[36]

  • source
  • parent
  • hideshow 4 child comments
  • load more comments (4 replies)
  • [–] 2 points 3 days ago

    they released the first non-testing version of their new DE too soon.

    This was the only issue I had with Cosmic. I don't know what the current state of the DE is these days, but surely they've fleshed out some bugs by now.

    Also, cosmic-text is an amazing gift to the world, for what that's worth. Doesn't really justify using the DE, but that library is amazing.

  • source
  • parent
  • load more comments (3 replies)
    [–] 10 points 4 days ago (1 child)

    This might make me move from KDE after their shit stance on AI.

    I just don't trust humans to prompt the gambling machines with any sort of integrity. People take shortcuts, AI now makes shortcuts super easy, addictive, and it massages your ego when you're right or wrong.

    I really don't trust LLMs as they're made now. Natural language prompting is just gambling, think about it.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 24 points 5 days ago (4 children)

    Loving my move to Fedora Atomic Cosmic. Happy Silverblue user of long time, Cosmic just fits my personal zen better.

    With their fast pace of fixes/new features, this AI stance is just the nice cherry on top.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 4 points 3 days ago

    I've come for my daily dose of corporate wolf in sheep's clothing marketing. Was not upset.

  • source
  • [–] 15 points 5 days ago

    Now if only it wasn't a buggy mess all on its own.

  • source
  • load more comments
    view more: next ›