Open source maintainers are drowning in junk bug reports written by AI
theregister.com
theregister.com
I think the natural response will just be lower responsiveness from the maintainers to anonymous reports.
> I used to love using curl; it was a tool I deeply respected and recommended to others. However, after engaging with its creator, I felt disrespected, met with a lack of empathy, and faced unprofessional behavior. This experience has unfortunately made me reconsider my support for curl, and I no longer feel enthusiastic about using or advocating for it. Respect and professionalism are key in any community, and this interaction has been disappointing.
Some of the maintainers tried to keep engaging at that point, but it's so clearly just ChatGPT!
... "delving deeper ..." :)
Charlie Brooker's How to Report the News - Newswipe - BBC
The one project is a rate limiter, and for a while I was getting a fair number of bug reports that boiled down to configuration mistakes, such as accidentally rate limiting the load balancer/reverse proxy rather than a specific end user. I implemented a handful of runtime checks looking for common mistakes like that, each logging a one-line warning with a link to a wiki page that gave more details. Since then, the support burden has come down dramatically.
What would be interesting is who's doing it and why. The incentives wouldn't seem to be malicious, there's no attempt a-la xz-utils to boost credentials for a real human. Honestly if I had to guess it's an AI research group at Microsoft or wherever trying to tune their coding bots.
It seems to me like talentless hacks looking for ChatGPT to get them easy money/cred without any actual work.
Who knows. Might be some sort of "distributed attack" against Open Source by some nefarious actor?
I am still thinking about the "XZ Utils" fiasco. (Not implying they are related, anyhow).-
Such results used to require sophistication and funding, but that is no longer true
So, why? Courtesy, believe it or not. Blame Amazon.
There is a more simple explanation and it is being discussed in the comments.
Kids trying to farm github fame using LLM:s.
The root cause is that LLMs are a damage multiplier for fuckwits. It is literally an attractive hammer for the worst of humanity: laziness and incompetence.
I imagine that could be weaponised quite easily.
Reminds me of Eco's quote about giving the "village idiot" a megaphone. But, transposed to the age of AI.-
Bring back the days of "because it's got electrolytes" because I can easily ignore those ones.
... at least when villages were prevalent. Or, earlier ... :)
I've been dealing with a vexatious conartist that has been using chatgpt to dump thousands of pages of garbage on the courts and my legal team.
The plus side is that the output is exceptionally incompetent.
... getting to an "AI arms race" where the team with the better AI "wins" - if nothing else by virtue of merely being able to survive the slop and get to the actual material - and then, of course, argue.-
It won't be for long. This is reminiscent of the development of the first rifles, which often jammed or misfired, and weren't very accurate to a long range. Now look at weapons like a Barrett .50 cal sniper rifle -- that's what AI will look like in 10 years.
I contend that there are none. Witness the actual transformer kernel technologies over the last 20 years and try to find a single new one.
Neural Networks? that's 90's technology. Scale is the only new factor I can think of.
This is an investor-dollar driven attempt to use brute-force to deliver "magical" results when the fundamental technology is being mis-represented to the general public, to CTOs, and even to Developers.
This is dishonest and will not end well.
I will wait.
(Though, perhaps an unusually pessimistic example of the “real soon now, it’ll be usable, we promise” phenomenon; rifles took about 250 years to go from ‘curiosity’ to ‘somewhat useful’).
There is only scale being employed like never before => vast datasets being plowed through being sufficient to provide the current illusion for the less observant humans out there...
10 years from now this current fad of LLM's pretending to be intelligent will look preposterous and unbelievable: "how COULD they all have fallen for such hype, and what a cost of joules/computation... the least deterministic means possible of coming to any result... just wasteful for no purpose..."
All that time the bow and arrow were long-range, accurate, quiet and worked in the rain. :)
[But yeah, you're right - in our lifetimes technologies have changed immensely.]
He's already announced that he's going to attempt to appeal. I expect that similar to his recently rejected appeal he'll file another few thousand pages of chatgpt hallucinations in this one.
Except I stead of bug reports, he just gets some crap code written and sends it to her assuming it can be dropped in and ran. (It is often wrong)
As far as I can tell, there are people whose entire Github activity is submitting PRs like that. It would be one thing if they were diving into a big codebase, trying to learn it, and wanted to submit a patch for some small issue they found to get acquainted with the maintainers, or just contribute a little as they learned, but they drop one patch like that, then move on to the next project.
I don’t understand the appeal, but to each their own, I guess.
Maybe I have some sort of bias, but it feels like a lot of the projects I see specifically request help with these sorts of low-hanging-fruit contributions (lumping typos in with documentation).
1) They want/intend to contribute more and are starting small, but either get overwhelmed, lose interest, don't have enough time, etc.
2) They are students padding their resumes (making small PRs so they can say they contributed to x-number of open source projects.)
3) Its just the Github badges.
Yeah that's essentially how people are encouraged to start contributing to open source projects, making small changes and cleaning up documentation and such. It's hard to allow for this while also preventing the other two categories.
Wonder how long it'll be until we see wars back and forth between people submitting 'corrections' for things that are just spelled different between dialects like we see on Wikipedia.
You just underestimate evil people. We are long past “bored kid in his parents basement in a hoodie”.
Any piece of OSS code that might end up used by valuable or even not so valuable target is of interest for them.
For example, add some dead code that contains an obvious bug (like a buffer overflow). The scanbots catch it, submit the PR, get banned.
And then post the email address and handle of spam submitters so they are found when potential employers google them.
I will always google applicants as part of the interview process. If I found they had submitted this trash, it would really harm their chances that I hire them.
As a result I started project to use various fine tuned LLMs to do this part for us. I guess this is a case of needing a bigger gun to deal with the guys with gun!
I'm more curious to see what they look like.
Or sometimes bugs are introduced by the endless churn but then attributed to someone who wrote the original bug-free code, which leads to more money and (false) credit for the churn experts.
Can we have AI bug responses? So by default Github assesses each bug reporting using AI and gives us a suggested response or analysis? If it is a simple fix, just propose a PR? If it is junk or not understandable, say so? And if it is a serious issue confirm that and raise awareness.
I want to move towards self-maintaining Github repositories personally. I should only be involved for the high level tasks or gatekeeping new PRs, not the minor issues that are trivial to address.
We need to not simply fight AI, but rather use it to up level everyone.
How to make github issues entirely useless :D
This is an arms race. And unlike traditional arms, because it involves intellectual capabilities of a machine, there may be no limit to the race. It does not sound like a good world in which everyone is fighting everyone else with advancing AIs that use increasingly more energy to train.
It's the mechanization of the broken window fallacy.
I told him to do several commits, and they were just… the same shit but arbitrarily divided into several commits, no logical separation, no way to reject a commit and accept another one.
I said I wasn't going to accept that crap and he got offended.
The goal in some way or another seemed to be spam, either getting access to email addresses, or access to some venue (I guess an issue tracker?) where spam could be posted.
... "prior art" for hallucinated (confabulated) code ...
PS. Sometimes methinks any "moderation"/interaction issue we might encounter nowadays, was faced/dealt with on IRC, before.-
These are not LLM at all, but its the same general issue in that it takes 10 second to generate a report but takes days or weeks to comb through all the noise for the FOSS maintainers.
Most recently, this one https://github.com/hrydgard/ppsspp/issues/19515
I had much worse human reports and even CVE's, which were invalid and absolute trash.
And the recent trend to do sports reports generated by ChatGPT is insulting.
Humanity racing towards maximum idiocy.