Interview with Greg Crow-Hartman about AI-generated error reports

At the KubeCon Europe conference, The Register interviewed Greg Kroah-Hartman, responsible for maintaining the stable and staging branches of the Linux kernel, and a main maintainer in 16 kernel subsystems. The interview discussed Greg's perspective on bug reports identified by AI. AI is already used in the kernel for reviewing changes in the networking subsystem, eBPF, and DRM, and recently integrated Google's Sashiko tool to check submitted changes.

Some of Greg's statements:

  • "A few months ago, we received what we called AI garbage — AI-generated security reports that were clearly incorrect or of low quality. It was even amusing. We didn't worry too much about it... A month ago, something changed, and the situation shifted dramatically. Now we are getting real reports."
  • "A similar situation is observed not only in Linux — all open-source projects are receiving real reports generated by AI, and now they are high-quality and valid. Security teams in the largest open projects have noted the same trend in informal discussions among themselves."
  • When asked what this change was due to, Greg replied: "We don't know. It seems no one knows. Either many tools have gotten significantly better, or people have started saying, 'Hey, let's figure this out.' It seems to be affecting many different groups and companies. As for the kernel, we'll handle it. Our team has grown significantly; it is very dispersed around the world, and our growth is a reality, and it is not slowing down. These are minor issues, nothing serious, but help may be needed for all open projects. Smaller projects have much less capacity to deal with the sudden influx of AI-generated bug and vulnerability reports that mention real bugs, not garbage."
  • Greg mentioned that when he asked AI to find errors in the proposed set of changes, it identified 60 and provided patches for correcting them. Only a third of the identified errors were genuine, and of the patches, only 2/3 proved to be correct solutions that didn't require further adjustments, but all of this was far from useless. According to Greg, maintainers cannot ignore this, especially as the results from AI are improving. A tag 'Co-developed:' was added to mark the patches created using AI. Despite some attempts to use AI for developing new functionality, AI is primarily being utilized in the kernel for reviewing changes.
  • One of the most notable advantages of AI is said to be the reduction in patch processing time. When the AI assistant detects obvious issues, patch authors receive feedback long before an actual maintainer could read the patch: 'If I see that the system is responding to something, it gives feedback to the author faster than a maintainer could do, and that’s great. We already have a number of bots that check patches. If I notice they generate an error, I immediately understand that as a maintainer, I don't even need to look at it. And the developer thinks 'Oh, I can make another version tomorrow,' which helps improve feedback a little.'

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster