Haelwenn /элвэн/ :triskell: (nprofile…8m52) pistolero (nprofile…9683) nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqyrwhw6tgqnnrq2y7q7xh7dl6pdqxmpaenvqa49g8xy430ykfus9spfzr8z (nprofile…zr8z)
>>And 9front's even more elegant:
>3. Submitted code is not computer-generated
Technically that bans also completely mundane stuff like auto-generated headers from things like device trees/spec sheet documentation or m4 macro expansions. Of course it will never be enforced that way.
>and at very least 90% of code is pure crap nobody wants to read (and so nobody reads).
Things got way better in the last year or so with new-ish models. If you take the time to set up a workflow for the new models, the results are still somewhat easy to distinguish from non-clanker contributions, but they aren't bad either and usually require some smaller fixups and removal of some overly defensive checks. If done by someone that knows stuff at least. And even with the "chat in a browser window" way, you can get decent-ish results if you keep things small.
>Plus outside of purely code, since then there's also the absolute spam of completely bogus security reports
On the other hand you also have security reports with really high severity that were found within a day or two of letting a model loose on a codebase. The recent nginx CVEs were all found by LLMs, most of the recent Linux LPEs as well. The way I see it is the same as static analyzers and fuzzers, a useful tool in the hands of someone knowing how to handle it.
