Campfyre
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
themachinestops@lemmy.dbzer0.com to Technology@lemmy.worldEnglish · 2 days ago

Linus Torvalds used AI to fix a Linux bug, and now LLM critics on Linux face an uncomfortable choice

www.xda-developers.com

external-link
message-square
398
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
375
external-link

Linus Torvalds used AI to fix a Linux bug, and now LLM critics on Linux face an uncomfortable choice

www.xda-developers.com

themachinestops@lemmy.dbzer0.com to Technology@lemmy.worldEnglish · 2 days ago
message-square
398
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
Avoiding software without AI code is getting very difficult.

https://lists.debian.org/debian-project/2026/08/msg00041.html

  • oce 🐆@jlai.lu
    link
    fedilink
    English
    arrow-up
    149
    arrow-down
    2
    ·
    edit-2
    2 days ago

    In his commit message:

    [And this was a debug session from hell, enormously helped by an AI doing much of the grunt-work.

    I’d like to call it my tireless helper, but the AI several times stated flat out that this was impossible and unsolvable and that we should just write a report about it.

    I suspect those things have been trained by people who may not be quite as stubborn as I am.

    But while the AI was ready to give up several times, it did keep adding debug code and analyzing it faithfully when I pushed. So credit where credit is due and I let the AI write the commit message above.

    This is basically a one-liner fixing a bogus “round_up()” to a “round_down()”, but there were 24 patches adding more and more debug information to this, and 18 kernel boot to finally narrow it down to this. - Linus ]

    Didn’t he state quite early on that LLMs were a good tool to spot bugs? Found this from 3 years ago: https://blog.mathieuacher.com/LinusTorvaldsLLM/

    • FiniteBanjo@feddit.online
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 hours ago

      Add two spaces after a line ends and add the /> symbol at the start of every line.

      Example with:

      I
      wrote
      this

      Example without:

      I wrote

      this

    • Sanctus@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 day ago

      I think Linus yelled at that LLM

    • CosmoNova@lemmy.world
      link
      fedilink
      English
      arrow-up
      94
      arrow-down
      2
      ·
      edit-2
      2 days ago

      Hackers use LLMs to spot odd exploits so it makes sense developers use them too. The usage of LLMs in development likely won‘t make Linux better or safer overall, because bugs and exploits wouldn‘t have been found by either side without it in the first place. It‘s like pandora‘s box where Linus is kind of forced to use it. If that makes sense.

      • FiniteBanjo@feddit.online
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        6 hours ago

        The frequency of bugs and exploits has increased exponentially since AI came about and I don’t think it’s due to hacker sophistication at all. Most of the advanced tools to find exploits aren’t available to the general public if they really exist at all.

      • NuanceDemon@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        30
        ·
        2 days ago

        Like an accelerating arms race.

        • technocrit@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          1
          ·
          1 day ago

          Yes, but this has always been the case before and after this phony “AI” bullshit.

      • ell1e@leminal.space
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        2
        ·
        2 days ago

        He might consider himself forced to use it to find bugs. He wouldn’t be forced to use it to write the fix.

        (Now you might say he wasn’t or isn’t, but even if that were true for the kernel at large this doesn’t seem to be: https://www.theregister.com/os-platforms/2026/08/10/linus-torvalds-says-ai-has-made-huge-linux-kernel-updates-the-new-normal/5285268 And this seems like mostly to be on Linus, for not stepping in here.)

      • oce 🐆@jlai.lu
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        1 day ago

        Following the hacker arm race is a good point. But also the number of bugs is not a bottomless pit. If an LLM allows to find more, and hopefully the test and reviews are good enough to limit the new opportunities to introduce some from LLMs, it should reduce the overall number of bugs and make the software generally safer.

        • technocrit@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          also the number of bugs is not a bottomless pit.

          Are you forgetting about Microsoft?

    • tinsukE@lemmy.world
      link
      fedilink
      English
      arrow-up
      39
      arrow-down
      17
      ·
      1 day ago

      Whatever’s the outcome, the anthropomorphization in that message stinks 🤮

      • psycotica0@lemmy.ca
        link
        fedilink
        English
        arrow-up
        48
        arrow-down
        4
        ·
        1 day ago

        Dude, I’m not an AI zealot, but I anthropomorphize my socks.

        • athatet@lemmy.zip
          link
          fedilink
          English
          arrow-up
          15
          arrow-down
          2
          ·
          1 day ago

          Yeah but people aren’t having conversations with your socks thinking they actually are alive and your socks don’t then talk said people into suicide so I’m pretty sure it’s at least a little bit different.

          • Gaja0@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 day ago

            I saw a post about mom dog jumping into a flood to rescue pups. They said they would end up finding new homes for pups. I amphropromorphized (can’t spell) the mom misising her pups, only to read that it’s common for them to get annoyed by older pups and even eat unwell pups.

      • FishFace@piefed.social
        link
        fedilink
        English
        arrow-up
        30
        arrow-down
        10
        ·
        1 day ago

        Trying to avoid anthropomorphising something with which you interact via natural language is incredibly laborious, and achieves nothing.

        • technocrit@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          7
          arrow-down
          3
          ·
          edit-2
          1 day ago

          Avoiding false statements achieves scientific accuracy and honest progress rather than grifting and bullshit.

          And TBH it’s not at all difficult for me to distinguish between my computer and a human.

      • technocrit@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        11
        arrow-down
        2
        ·
        1 day ago

        That’s a core part of the grift. Even people who supposed hate “AI” still promote this kind of anthropomorphic disinformation. It’s rampant.

      • sepi@piefed.social
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        1 day ago

        Silly humans, antropomorphizing everything. Say, what species are you?

        • KeenFlame@feddit.nu
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          1 day ago

          Correct. A being of power should never anthromorphise. It is a thing of flesh. I laugh at that because I am human and I never anthromorphise even the slightest part of a marble slab. I must be superior to most humans I guess. The forest people, though, those are legit just uninformed I think. I hate those creaks they make. I mean generate. I mean the wind . I mean no i mean the sound that nobody years because nobody is there and only humans and tree people are alive and the other animals are biological machines that we must try to ignore even if they lick us on the face wagging their tiny tail at us. For they are unworthy. I mean its tail. If it generates tail wags it is only an impression of aliveness and we must stand firm beside our tree people brothers and sisters on this.

      • architect@thelemmy.club
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        8
        ·
        1 day ago

        I like it.

    • Feyd@programming.dev
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      3
      ·
      1 day ago

      Regardless of how he got there, this is a pretty obnoxious and useless commit message…

      • Zaktor@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        15
        arrow-down
        2
        ·
        1 day ago

        Seriously. You don’t need to outline your whole journey to finding the bug, commentary on the tools you used, and how it all made you feel, just what the problem was and how it was fixed. Put the rest in a blog post.

    • Kangae_Hishiryo@scribe.disroot.org
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      8
      ·
      24 hours ago

      LLMs are a great tool for create bugs *

      Fuck Linus.

      • AwesomeLowlander@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        20 hours ago

        Let us know how your Linux 2.0 goes.

        • Kangae_Hishiryo@scribe.disroot.org
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          9
          ·
          19 hours ago

          If you don’t have anything better to say than an ad hominem fallacy and a red herring fallacy, then you’re totally discrediting yourself.

          • AwesomeLowlander@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            8
            arrow-down
            1
            ·
            19 hours ago

            Yes, because your original comment was so thought out and well reasoned to begin with 🙄

            • Kangae_Hishiryo@scribe.disroot.org
              link
              fedilink
              English
              arrow-up
              1
              ·
              3 hours ago

              Well, it’s not that I’m telling another thing than the truth.

              You’re attacking something totally unrelated and that I’ve never mentioned (“Linux 2.0”) because you simply can’t deny that LLM are bug-making machinegunss.

              Literature on that in my response.

              • Kangae_Hishiryo@scribe.disroot.org
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                3 hours ago

                Part 1:

                Code Quality (defects, bugs, logic)

                • CodeRabbit: AI code has 1.7× more defects (10.83 vs 6.45 issues/PR); logic errors 1.75×, security 1.57×, XSS 2.74×
                • BusinessWire / CodeRabbit: Performance inefficiencies (excessive I/O) appear ~8× more in AI code; logic problems up 75%
                • The Register: AI code shows 1.4× more critical and 1.7× more major issues; 1.57× more security findings
                • Carnegie Mellon (via Ox Security): Only 61% of AI-generated code functions correctly; only 10.5% passes security review
                • Ranger 2026: 26.6% produce incorrect outputs; 60% of faults are silent logic failures; ~50% has maintenance problems
                • GitClear 2026: Copy-paste code rose 9.4%→15.7%; duplication up ~4×; refactoring down 70%; code churn nearly doubled
                • arXiv 2026: LLMs suffer “Context Rot”; accuracy drops sharply when relevant info is mid-context
                • arXiv 2026: Copilot generates executable code ~90% of the time, but 40% of solutions on critical security tasks contained MITRE Top-25 CWEs
                • arXiv 2026 “Should I Give Up Now?”: LLMs “hallucinate, omit important steps, lose context between turns, or produce deceptive code”
                • Based Info: “The problem is execution, not compilation” — code compiles cleanly but fails at runtime or solves the wrong problem
                • CodeBridge / Ox Security: 10 recurring antipatterns in 80-100% of AI code; 68-73% contain vulnerabilities that pass unit tests but fail in production
                • ResearchGate 2026: Valgrind revealed AI code left 1,068 bytes in 34 reachable blocks at exit (memory leaks) vs 24 bytes in 2 blocks for human code
                • IEEE Spectrum 2026: AI code degrades as newer models create “silent failures” and rely on low-quality training data
                • arXiv 2512.22387: 31.7% of AI-generated projects fail to execute at all (only 68.3% reproducible)
                • arXiv 2510.26130: LLMs achieve 84-89% on synthetic benchmarks but only 25-34% on real-world code (66-75% functionally incorrect)
                • SWE-bench 2026: Top models reach ~80%, most struggle below 20% on repository-level tasks (80%+ failure rate)
                • SmartBear 2026: 70% of engineering leaders say quality has degraded; 60% report code outpacing testing capacity
                • DeviQA 2026: 0% of senior QA (8+ yrs) said AI code has fewer bugs; 37.5% said noticeably more
                • arXiv 2026: 304,362 AI commits → 110,000+ unresolved technical debt issues by Feb 2026
                • How I Dropped Our Production Database and Now Pay 10% More for AWS
                • Claude Tested Everything Except the One Thing That Mattered (AI agent refuses to follow explicit instructions to test createPost() in increasingly erratic ways)
                • Amazon calls engineers for a “deep dive” internal meeting to discuss “GenAI”-related outages
                • GitClear has released reports in 2024 and 2025 indicating a worsening of key code quality metrics correlating with increased LLM adoption.

                Security & Vulnerabilities

                • Veracode 2025/2026: 45% of AI-generated code introduces OWASP Top 10 vulnerabilities (100+ LLMs tested); Java 70%+ failure rate
                • Cloud Security Alliance 2026: Privilege escalation paths +322%, architectural flaws +153%, despite syntax errors −76%; ~20% of samples reference nonexistent packages
                • arXiv “Broken by Default” 2026: Mean vulnerability rate 55.8% (GPT-4o: 62.4%) across 3,500 artifacts verified with Z3
                • Sherlock Forensics 2026: 100% of AI-generated apps contained ≥1 critical vulnerability; 78% store secrets in plaintext; 34% of Node.js projects include hallucinated dependencies
                • Georgetown CSET: 86% failed XSS defense, 88% vulnerable to log injection, 47% SQL injection across 5 LLMs
                • Llama 3.3 SWE-bench study: 11× more new vulnerabilities in LLM patches vs developer patches
                • arXiv 2603.10072: Only 24.8% of LLM security patches achieve full correctness; 51.4% fail BOTH security and functionality
                • Stanford/MIT Mar 2026: 14.3% of AI code has ≥1 security vulnerability vs 9.1% human (2M snippets)
                • Apiiro Fortune 50: AI-assisted devs produce 10× more security issues despite 3–4× more code
                • ACM 2025/2026: ~30% of generated code snippets contain security weaknesses
                • Pagerly 2026: Models produce compilable code almost always but secure code only 56% of the time
                • Dev.to / State of Web Dev 2026: 63% of AI-generated functions had a security finding; review doesn’t scale with volume
                • Stanford (via SC World): In 80% of tasks, devs using AI produced less secure code; 3.5× more likely to believe their code was secure
                • Georgia Tech Vibe Security Radar: 74 CVEs attributed to AI tools (Mar 2026); est. 400–700 real
                • arXiv 2026: Slopsquatting — LLMs hallucinate package names, enabling attackers to register them with malicious code
                • ValueAdd VC 2026: Vulnerability density 2.74× higher in AI code; code churn ~2× higher in AI-heavy repos
                • Meta Security Researcher’s AI Agent Accidentally Deleted Her Emails
                • Moltbook’s “vibe-coded” breach is the future of security failures
                • In a study evaluating over 500k code samples, LLM-generated code was found to contain more high-risk security vulnerabilities than human-generated code
                • LLMs make up package names, making them vulnerable to incorporating malicious code in “slopsquatting” attacks (Arxiv study)
                • Kangae_Hishiryo@scribe.disroot.org
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  3 hours ago

                  Part 2:

                  Productivity Illusion (perception vs reality)

                  • METR RCT: Experienced OSS devs were 19% slower with AI; 39-point perception gap (believed 20% faster)
                  • McKinsey 2025: 46% time savings on routine tasks but <10% on complex work (4,500 devs)
                  • Sonar State of Code 2026: 96% of devs don’t fully trust AI code; only 48% always verify before commit; 53% say it “appears correct but is unreliable”
                  • Stack Overflow 2025: 66% top frustration = code that’s “almost right but not quite”
                  • Stack Overflow Blog Jan 2026: 45% of developers say debugging AI-generated code takes longer than writing it themselves
                  • Byteiota 2026: Trust in AI tools fell from 40% (2024) to 29% (2025); 96% believe AI code is not fully correct
                  • Smarter Articles 2026: Devs with Copilot introduced a 41% increase in bugs, with no reduction in burnout risk

                  Churn, Replacement & Survival

                  • Faros AI: 65% survival rate for AI code vs 92% human (35% gets silently replaced)
                  • Faros AI: +98% PRs merged but +91% review time, +9% bugs, DORA metrics flat (10,000+ devs)
                  • Kunal Ganglani 2026: 40% of new AI-assisted code is rewritten within two weeks, vs 33% pre-AI
                  • New Relic 2026: 74% of tech leaders report ≥25% of AI code requires significant post-deployment rework; 82% have suffered at least one major production failure caused by AI code
                  • Lightrun 2026: 43% of AI-generated code changes require manual debugging in production after passing QA and staging

                  Production Impact & Outages

                  • CloudBees 2026: 81% of enterprise leaders report increased production issues from AI code
                  • Amazon / CNBC Mar 2026: Amazon convenes “deep dive” meeting over outages caused by GenAI-assisted changes; “high blast radius” incidents since Q3 2025
                  • The New Stack Mar 2026: Amazon mandates senior engineer sign-off on all AI-assisted code changes after multiple outages
                  • Fortune Mar 2026: Amazon retail website crashes from “inaccurate advice” an AI agent pulled from a stale wiki; 4 Sev-1 incidents in one week

                  Deskilling

                  • Brains show less activity when completing tasks with LLMs compared to completing tasks with search or completing tasks without digital help.
                  • Developers who use early-2025 LLMs reported higher subjective performance, but were measured to have lower objective performance. This gap between subjective and objective performance was considered notable.
                  • In an Anthropic study, learners using LLMs demonstrated lower learning rates on average compared to learners not using LLMs.
                  • A recent study uses the term “cognitive surrender” to describe the way humans tend to offload key critical thinking skills onto LLMs, even when the output is wrong.
                  • A paper entitled “AI Assistance Reduces Persistence and Hurts Independent Performance” from April 2026 by academics from MIT, Oxford, UCLA, and Carnegie Mellon showed alarming evidence that performing a variety of tasks with the help of AI for only 10 minutes causes “inpaired unassisted performance and reduced persistence”. The researchers noted that “although AI assistance improves performance in the short-term, people perform significantly worse without AI and are more likely to give up”; they also pointed out that “these findings are particularly concerning because persistence is foundational to skill acquisition and is one of the strongest predictors of long-term learning”.
    • technocrit@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      6
      ·
      1 day ago

      Pretty wild seeing a programmer anthropomorphize their applications and mislabel them as “AI”.

      The Big Lai runs deep.

      • RumRunningDevil@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 day ago

        Okay I’m seeing a lot of your replies here this is a really weird argument to make. You’re literally arguing from symantics.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @[email protected]
  • @[email protected]
  • @[email protected]
  • @[email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 5.55K users / day
  • 10.8K users / week
  • 14.7K users / month
  • 32.1K users / 6 months
  • 1 local subscriber
  • 87.8K subscribers
  • 20.5K Posts
  • 862K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org