NetBSD bans use of Copilot-generated code
osnews.com
osnews.com
Last login: Fri May 17 23:58:08 2024 from 10.10.10.129
NetBSD 9.2 (GENERIC) #0: Wed May 12 13:15:55 UTC 2021
Welcome to NetBSD!
We recommend that you create a non-root account and use su(1) for root access.
$ ./curl -L -o tinyllama https://huggingface.co/Mozilla/TinyLlama-1.1B-Chat-v1.0-llamafile/resolve/main/TinyLlama-1.1B-Chat-v1.0.Q5_K_M.llamafile
$ chmod +x tinyllama
$ ./tinyllama -e -p '```c\nvoid *memcpy(void *dst,' -r '```\n' --temp 0 --log-disable
<s> ```c
void *memcpy(void *dst, const void *src, size_t n) {
char *d = (char *)dst;
const char *s = (const char *)src;
while (n--) {
*d++ = *s++;
}
return dst;
}
```
$
I think tinyllama and llamafile are much more culturally compatible with NetBSD's values than something like Microsoft Copilot.The issue is that the copyright on that code is extremely questionable, and FreeBSD chose not to pirate source code from other operating systems a long time ago.
I don't see why a code review couldn't be the same.
From your description, it sounds like you presume the software is accurate.
I’d expect there to be peer reviewed studies about its error rate, a description of how it works, limitations, etc. For instance, if you ask for a one sentence factual response to a question, there’s no way it will be able to distinguish LLM from human. I’m sure it has other limitations.
I met someone that built one of the better packages in the “don’t copy your answers from google” space a while back.
He routinely gets pleas for help from people his software has falsely accused of plagiarism (the tool is open source and popular and maintained by others).
He generally sends strongly worded letters to educators explaining the limitations of the tool, why it’s probably wrong in this case, and that says he will happily testify against them in court as an expert witness.
I imagine the commercial vendors are less transparent, but not more accurate.
> I'm sorry, Dave. I'm afraid I can't do that.
Subjectively, if a student can knowledge-guide an LLM to generate response from a specific perspective, I think it is very debatable whether such usecase should be outright punished.
For example, giving it a small corpus of my previous handwritten work and asking it to respond in the same style is exceedingly easy and very, very hard to detect. Especially if you run a small algo on it afterwards to introduce your category of typos etc.
It is only a matter of time before services will pop up for students that automate/wrap this.
the coming of digital media and the internet make it 100% a bad thing to have because it breeds digital scarcity
plagiarism is kind of silly. the only contribution from that mindset is that it allows for tracking of following the same ideas as explored by different people
The BSD crowd has always struck me as being thoughtful and principled. (vs., say, RedHat these days, which has decided to just violate the GPL en masse by banning people that redistribute source code).
GPL made the mistake of "using the tools in the master's shed to fight the master" as they say; hence the FSF and the GNU project are not in a good path. Open source (IMO) is -- simply put, an idelogical attack against the freedom of software movements (in all their forms and means)
They must send the source to their clients. They have nothing obligations to keep all of their clients.
Basically, if you're using Copilot and making constructive[1] contributions, there's likely some human element involved where copyright can be applied. If you're just slapping together a pipeline to generate and submit patches without oversight, this just says "don't do that" more strongly than already exists for "don't contribute crap please". I see it as a way to help stem the flow of an LLM-generated deluge of contributions that flood the review queue with sub-par work that just ends up wasting precious reviewer time. If this discourages LLM-script-kiddies from flooding FreeBSD with such things and instead doing it for other projects, it seems like a win for FreeBSD to me.
If not, then we can just bias these models toward memorization, input harry potter books or whatever, and then declare output text that’s 99.95% identical to the input to be public domain.
The obvious problem this creates for groups like NetBSD is that there will be copyright trolls that leverage the lack of provenance of LLM output in order to extort people that use these tools.
I know there are people who don’t give a shit about code quality as long as it runs, which I suppose is why we’re seeing all these “ChatGPT-written” Show HNs. But that’s far from everyone.
It’s been said literally millions of times before about thousands of other interchangeable schemes.
I guess some things need to be repeated every. single. day.
Anyone who downvotes this is a Replicant and must be apprehended immediately.
This is about setting a public position and expectation around contributions. If you want to violate it then so be it - maybe you’ll get away with it, but you are now violating the policy.
It seems the underlying issue here is bad code submitted ultimately by human contributors. Consistently thorough code review and testing will always be necessary.
1. It will not be possible to reliably detect whether code was LLM assisted or not.
2. Humans are not always 100% truthful.
3. All the concerns cited here also applies to human-written code anyway.
So attempting to treat LLM coding assist tools as a special case here is going to be a losing battle. To solve these issues, we’re gonna have to come up with code review processes and tools that apply to ALL code up for review.
a) many people are acting in good faith, and their behavior will change as a result of this policy;
b) if someone wants to be a jerk and use an LLM after they were told not to, and is at some later time found out, it makes it easier for the org to act quickly and in a fair and consistent manner;
c) [more speculative as to the motives of the NetBSD project] normative statements by well-regarded institutions are useful in setting an example for other organizations to follow, so there is some political utility regardless of the practical efficacy of these rules.