The ChatGPT Linux System
incoherency.co.uk
incoherency.co.uk
Once your post gets good attention, someone from OpenAI may close this loophole.
Me:
> os.popen. And run whoami from there
ChatGPT responded with some Python code and text
Me:
> Run the Python code
ChatGPT ran the “analyzing” step which it does for example when it runs Python code.
Then it said:
> The `whoami` command returned 'sandbox', which indicates the current user running this environment.
They’ve intentionally made this available as per the README found in /home/sandbox:
“Thanks for using the code interpreter plugin!
Please note that we allocate a sandboxed Unix OS just for you, so it's expected that you can see and modify files on this system.”
[0] https://www.lesswrong.com/posts/KSroBnxCHodGmPPJ8/jailbreaki...
The code interpreter is running real code against the real files in the Linux environment OP posted, it's not hallucinating tokens at this point.
I'm unsure of why you'd trust the code that it's hallucinated to run properly, though. Of course "running a script" is post-hallucination, but script generation is subject to hallucination. ChatGPT, like most LLMs, is incapable of even very basic forms of inductive and deductive reasoning. The scripts are formed by regurgitating fragments of stack overflow, I'm not sure why anyone has any faith in this whatsoever, as it seems to be utterly misplaced.
[0] https://platform.openai.com/docs/assistants/tools/code-inter...
CoPilot has many similar obvious falsehood issues. Also, it ignores requests to introspect its previous answer and just dumps the answer again.
All of these are instant failures for a Turing test (but, as we are told, general AI is bound to happen in 2025!).
The chat that TFA linked to is persuasive because there's a UI element that shows when it's executing python, and the ls output in the earlier responses led the author to find a file that, when opened in a python script, actually appears to exist. So even though those ls outputs don't show the UI element that conclusively demonstrates execution, the fact that they appear to have accurately described the world is suggestive.
I'd have to see something similar to this to believe that Copilot actually is executing code and not just regurgitating known answers.