For those outside the loop: rsync starting using AI agents to handle the influx of AI security reports to improve the test suite and fix bugs. It introduced a few CVEs and people who never contributed in any way started firing shots at the maintainer.

rsync maintainer’s response to the people getting pissy about his usage of AI: medium and the related post on programming.dev

  • poVoq@slrpnk.net
    link
    fedilink
    arrow-up
    12
    arrow-down
    2
    ·
    3 days ago

    They could have just refused merging slop. Rsync didn’t need these “contributions”.

    • Zos_Kia@jlai.lu
      link
      fedilink
      arrow-up
      2
      ·
      20 hours ago

      What about the 6 critical security bugs he fixed in that release. Didn’t rsync need those “contributions”?

      • poVoq@slrpnk.net
        link
        fedilink
        arrow-up
        1
        ·
        15 hours ago

        The “critical” bugs that I have recently seen being found by AI were all extremely unlikely to be exploitable under realistic assumptions 🤷

            • Zos_Kia@jlai.lu
              link
              fedilink
              arrow-up
              1
              ·
              1 hour ago

              I mean the ones in the latest release of rsync, tf does nginx have to do with anything ?

              • poVoq@slrpnk.net
                link
                fedilink
                arrow-up
                1
                ·
                39 minutes ago

                I have not looked at the CVEs in Rsync specifically, but given the deludge of “critical” security issue found by AI lately that have been mostly nothing burgers, I am near certain the same applies to those included in that Rsync patchset.