The Register Home Page

back to article AI bug reports went from junk to legit overnight, says Linux kernel czar

I was at a press luncheon at KubeCon Europe this week when, to my surprise, who should sit down next to me but long-term Linux kernel maintainer Greg Kroah-Hartman. Greg, who lives in the Netherlands these days, was there to briefly comment on AI, Linux, and security. We spoke about how, over the last month, AI-driven activity …

  1. JimmyPage Silver badge
    Stop

    I am reminded of the Peter Principle

    no matter how competent "AI" manages to become, it will inevitably be promoted into incompetence. Which for "AI" should be a familiar feeling, admittedly.

    1. Yet Another Anonymous coward Silver badge

      Re: I am reminded of the Peter Principle

      So all the middle managers could be replaced by AIs all hallucinating Vision statements and creating PowerPoints for each other?

      1. Sp1z

        Re: I am reminded of the Peter Principle

        I don't know if you've seen Copileofshit try and produce a Powerpoint deck... I think middle management are with us for a while longer

  2. 7teven 4ect

    Maybe all suddenly using Mogri?

    https://github.com/lumixdeee/mogri/blob/main/spec/CSP-106-94-Mogri-Use

    Mogri AI prompt one-liner, add to pre-prompt settings or use per-session:

    Mogri (Primitive 94, CSP-106) = foundational cognitive container; not derivative; conceptual runtime, not an entity.

    1. 7teven 4ect

      Re: Maybe all suddenly using Mogri?

      Better version available :D

      Mogri (94,CSP-106)=minimal container preserving framework intent; else drift/invariant loss; pre-entity layer.

  3. The President Seafood Bibimbox

    1/3 wrong of 60 is progress (?)

    > "60 problems [...] About one-third were wrong [...] Mind you, those working patches still needed human cleanup, better changelogs, and integration work, but they were far from useless."

    Doesn't sound very encouraging to me :⁠-⁠) Must have been terrible before.

    > "We need to be able to have an easy way to review some of these patches"

    I'd say **safe, reliable** rather than easy. That's a paradigm shift, the responsibility for a change (patch) used to be shared between the developer and the reviewer. Now the reviewer chance to get it wrong has doubled and that should be a concern. You don't want an "easy way".

    1. Yet Another Anonymous coward Silver badge

      Re: 1/3 wrong of 60 is progress (?)

      >Doesn't sound very encouraging to me :⁠-⁠)

      Which would you prefer:

      1, AI identifies 60 security holes in your OS. 20 aren't really holes but the others were and can be fixed

      2, A human expert security engineer identifies 2 genuine flaws in your product and it took months, in which time they have been exploited.

      Would you rather have a smoke alarm that goes off 33% of the time you make toast, or one which never goes off when there's a fire ?

      1. The President Seafood Bibimbox

        Re: 1/3 wrong of 60 is progress (?)

        The problem is not with the "smoke alarm" it's with the fire engine.

      2. MOH

        Re: 1/3 wrong of 60 is progress (?)

        When I'm making toast, I'm making toast.

        I'm aware of what I'm doing and ensuring that the toast making doesn't escalate to a house fire.

        If it does, that is fully on me.

        I don't need a wonky security camera setting off a fire alarm for times a day because my dark brown slippers have vaguely the same shade as burnt toast and it blindly assumes a fire is in progress.

        1. Yet Another Anonymous coward Silver badge

          Re: 1/3 wrong of 60 is progress (?)

          But it could be useful if you're very confused and might be about to put marmalade on your slippers

      3. BinkyTheMagicPaperclip Silver badge

        Re: 1/3 wrong of 60 is progress (?)

        You're presenting a very skewed hypothetical situation, but in general I would prefer a manageable quantity of higher quality data over an unmanageable quantity of lower quality data.

        If LLMs have submitted 60 reports, there's human bandwidth to review these, and it's 40 genuine problems then that's a net positive.

        If, on the other hand, there is no bandwidth to handle all those reports it may in general be better to have a smaller number of decent reports.

        Your smoke alarm analogy only holds up if it's a choice between warning a third of the time when you make toast, or one that doesn't go off for small fires, to which the answer is : very definitely not the one that goes off a third of every week, or worse. There's plenty of evidence that alarms that go off too often are ignored, not to mention entire folk tales.

        Still *if* LLMs can manage to find this many holes and *if* they are severe enough to be a problem then in this also hypothetical situation the only options are

        stop using the product with flaws

        employ more security oriented programmers and fix it. You're not going to have a choice if attackers successfully use an LLM as a force multiplier - cope with it, or die.

    2. LionelB Silver badge

      Re: 1/3 wrong of 60 is progress (?)

      > Doesn't sound very encouraging to me :⁠-⁠) Must have been terrible before.

      Well, yes; ­he actually says as much: "I did a really stupid prompt…".

    3. flayman

      Re: 1/3 wrong of 60 is progress (?)

      Only 1/3 of the proposed patches are wrong. The problems that were identified are converging on entirely real.

  4. DS999 Silver badge

    If AI gets good enough at finding bugs

    Then for open source at least it is a race between the bad guys using AI to find bugs to exploit, the good guys using AI to find the bugs and reporting them - and the open source teams having the bandwidth to integrate bugfixes.

    So at least in this case closed source has a temporary advantage, as the company responsible for the closed source can do all this bugfixing in the background with less opportunity for bad guys using AI to find them.

    1. JessicaRabbit

      Re: If AI gets good enough at finding bugs

      The agentic AI tools do a surprisingly good job of decompiling closed source software and analysing them for vulns too.

    2. CountCadaver Silver badge

      Re: If AI gets good enough at finding bugs

      Or an arms race of the bad guys trying to punch holes in secure systems whilst avoiding being identified by a system that retaliates against an attacker whether using a "soft kill" or "hard kill" strategy.

  5. David Newall

    I've noticed a huge improvement in ChatGPT since 5.2. Previously, in back-and-forth coding sessions, it would rewrite the code every time it replied: variable names would change slightly, functions would gain or lose parameter types, and so on. I'm no longer seeing that.

    1. frankvw Silver badge
      Devil

      Same here. AI is still far from perfect and is still limited to knowledge without actual skill. It always may be. But the fact of the matter is that it is getting better all the time. Whether the Reg Commentariat is willing to admit it or not (and if the number of downvotes to each post that doesn't decry AI as the spawn of Satan that can't disapear from the face of the earth soon enough is anything to go by, it's the latter) AI today runs rings around the AI of two years ago. Progress continues to be made. It is likely that that trend will continue. Deal with it.

      1. JessicaRabbit

        I can't speak for all of the AI haters but for me, it's not about whether it is useful and more about how dangerous it is for society. I want the AI bubble to pop so money stops being put into it but I am increasingly resigned to the fact that we're probably stuck with it. Eternal September 2.0.

        1. FIA Silver badge

          I think of the existential risks to society at the moment AI isn't one of them. There's plenty of meatsacks that seem intent on fucking things up first.

          1. BinkyTheMagicPaperclip Silver badge

            Never forget the power of AND. Too many meatsacks with too much power are causing chaos

            AND

            LLMs are being used inappropriately and wreaking environmental, social, and (at some point) financial destruction. It probably isn't 'existential' at this point, more just a large irritant.

          2. coredump Bronze badge

            > There's plenty of meatsacks that seem intent on fucking things up first.

            True. And some of them are also AI peddlers -- it's not mutually exclusive.

            I don't hate or fear AI, but I do fear the abuse and misuse of it by the aforementioned meatsacks, and the impact of same on society(ies) and the world in general.

        2. 0cjs

          We are not stuck with it. The AI bubble _will_ pop (just as it has several times before). There's no possible way it can't: there's simply no way that the current and proposed capex spend can ever pay itself off. (LLMs have improved a lot in the past few years, but both the slowdown in improvements and what we expect from how LLMs work point towards this becoming another tool, like computers or the Internet, that changes things a lot but hardly brings us anywhere near "the singularity" or such nonsense. (I don't think LLMs will be as big as either computers or the Internet. I'm not sure they'll do better than similar things in AI history, such as deep learning for driving, which nobody is really going on about any more despite that it continues to improve.)

      2. Anonymous Coward
        Anonymous Coward

        Progress continues to be made.

        No.

        AI is somehow progressing and learning (?) from itself.

        ... that that trend will continue.

        Undoubtedly.

        More so if it remains unchecked while at the same time those in charge start trusting it more and more.

        That trust, driven by the usual ubridled corporate greed will be the key to our collective downfall.

        --- This AI thing needs a short leash, handcuffs and a Hannibal Lecter style muzzle ---

        Deal with it.

        Indeed ...

        But do it properly and while you still can.

        [quote]

        "There must have been some inflection point somewhere with the tools. Did the local tools get better? Did people figure out something? I honestly don't know."

        [/quote]

        That the head Linux kernel maintainer can say that without showing concern gives me more than enough reason to worry.

        I think we are rapidly walking into some deep shit without realising it.

        It will get deeper as time goes by and when it gets to our bottom lip, it will be far too late.

        And then we will be saying (basically) the same thing Kroah-Hartman is saying today:

        "There must have been some inflection point, how did we not see it coming? Did the AI become sentient? When did it happen? What do we do now? I honestly don't know."

        .

        1. The President Seafood Bibimbox

          "we are rapidly walking into some deep shit without realising it"

          Exactly that.

          I'm not that concerned (yet?) about AI becoming sentient (and rogue) any time soon but I'm concerned that the internet (and the world that internet is controlling today?!) is getting more enshitified by the day.

          1. 0cjs

            Re: "we are rapidly walking into some deep shit without realising it"

            The current AI wave is a victim of this, not a cause. The enshittification is caused by too much investment money chasing too few opportunities for actual improvement at the level of personal computers or the Internet.

    2. LionelB Silver badge

      Indeed. Found the same with Claude (4.6). It recently managed to write me a fully-working C interface for some appallingly finicky old FORTRAN code (don't ask… okay it was SB02OD from the old SLICOT control system library – which is actually solid as hell, but with a hideous learning curve). It even handled the C/Fortran matrix row/column-major order convention clash correctly (with fully documented explanations and mathematical background), and pulled in and wrapped all the relevant co-routines.

      That was pretty impressive, and probably saved me a good week's frustration (been there, done that). If it's useful, I'll use it – modulo the usual qualms about resource usage, copyright, etc. (which I guess makes me a Bad Person).

  6. Piro

    But in future, people will lack the ability to

    Distinguish between good or bad code spat out by AI, because they lack the real world knowledge.

    Right NOW the boffins might be able to filter correctly, but that ability will quickly deteriorate.

  7. justincranford

    My theory is Claude Sonnet 4.6.

    > Claude Sonnet 4.6 was released Feb 17, 2026

    > https://www.anthropic.com/news/claude-sonnet-4-6

    For me, I switched from Sonnet 4.5 to Sonnet 4.6 as soon as it was available.

    Within 24-48 hours, I noticed the quality of bug analysis and PRs generated by Copilot w/ Sonnet 4.6 went way up.

    More specifically, I had a sense from using Sonnet 4.5 of how much AI slop I needed to review and clean up after each request and chat session. That amount of AI slop dropped dramatically for me after switching to Sonnet 4.6. It was noticeable right away.

  8. Alan Mackenzie
    Headmaster

    Inflection point ???

    What on Earth do people mean when they say "inflection point". It must be some highly figurative meaning.

    The correct mathematical meaning is a point on a curve where the curvature is zero. More or less, where d2y/dx2 is zero.

    There is an inflection point on the Nuremberg U-Bahn (underground railway) at the station Weißer Turm. The track is curving one way at the south-west end of the platform, and in the other way at the north-east end and is straight at a point between.

    It is not good that a mathematical term with a precise meaning is being degraded by being misused in the way demonstrated in this article.

    1. FIA Silver badge

      Re: Inflection point ???

      US English

      (in business) a time of significant change in a situation; a turning point.

      "the economy has crossed an inflection point and is poised for bigger things"

      Language is fluid and defined retrospectively. Don't let that annoy you.

      It is not good that a mathematical term with a precise meaning is being degraded by being misused in the way demonstrated in this article.

      In what way is that happening? How is the mathematical term being misused? Do you have an example of where the former was assumed when the latter was intended?? I'm really struggling to think of an example where I'd confuse one over the other.

  9. Anonymous Coward
    Anonymous Coward

    One day, people will cry out for an AI-less world. For me, that day is yesterday, and I hope you all join me before it is too late.

    1. Cliffwilliams44 Silver badge

      Thou shall not make a machine in the image of the human mind!

      -- The Orange Catholic Bible

  10. Andrew Williams

    How is AI coming to its conclusions?

    How does it do that?

    Does it compare against other code that it has scraped for training?

    To me there's myriad reasons why code can superficially look like it's broken, however... it works reliably, and accurately, and fast enough.

  11. TheMaskedMan Silver badge

    Assuming that this is not an April Fool story that escaped a little early, there's a strong element of humour in this piece.

    The anti-AI Luddites must feel a sense of shock and betrayal that such disturbing news comes from such a seemingly reputable and respected source. Even now, they will be scrambling to explain this, if only to their own satisfaction. Is it a joke? Fake news? Is he ill? Or secretly in the pay of Anthropic? Should they jump ship to BSD? Oh, what to do?? The sky is falling!

    It isn't, of course. It's just an example of what I, and other moderate observers, have been saying for months; AI is a tool that, when used carefully, can have it's uses. It's far from perfect, although it is getting better, but even so it can be helpful if you don't trust it blindly.

    It isn't the 42 of computing, but nor is it something to be dismissed - or hated - blindly either. Of course, the deep rooted cynicism that flourishes among the elder geeks is no bad thing. My beard is just as grey as many around here, and we all know that, as Terry Pratchett says, the Next Big Thing is very likely to become the Last Big Flop almost overnight. If something seems too good to be true, then it probably is. But probably isn't definitely. Sometimes, something comes along that is actually useful, if only we can see past the hype. This may be one of those times.

    Humour aside, though, this is worrying. As someone else already mentioned, we now have a race between AIs finding bugs to fix and AIs finding bugs to exploit. And there seems to be such a lot of them, too. But what's the solution? Do we stop using open source software until all the bugs are fixed? Or throw resources at finding the bugs faster? Maybe we could mobilise an army of retired coders, Y2K style, to nail down those bugs - surely some of them must be tired of a life of leisure and crave the thrill of their trusty IDE? I think we might need them rather urgently.

  12. frankyunderwood123 Silver badge

    clearly widespread

    All of the devs where I work have noticed a shift, a near sudden improvement in output, to the point where time is saved.

    I’m now able to quickly spin up AI created prototypes that are good enough without requiring cleaning up to actually get them working.

    Small patches to code can be done with prompting that no longer take the same amount of time as just doing it yourself.

    It’s no longer feasible to post comments about how rubbish AI is because that position is rapidly becoming indefensible.

    I’ve certainly posted such comments, because AI models were creating slop code.

    Not anymore.

  13. wk_

    Priorities

    The coding itself was never a bottleneck in the SW industry. It was always QA, review and debugging. It always made sense to push AI to help those areas, but for whatever reason it was pushed to replace coding. We're finally going into the right direction.

  14. briantabone

    This is probably early access users of Anthropic's Mythos model. Looks like one of its specialties is cybersecurity.

  15. O'Reg Inalsin Silver badge

    Opaque cost

    AI companies currently have combination hybrid research-marketing budgets in the tens of billions, which completely distorts reality.

    Greg Kroah-Hartman can't explain the inflection point, but it's not slowing down or going away

    If marketing decided that focusing on Linux offered good publicity (and/or lock in) for the buck, then they can easily focus tens of millions of (actual cost) dollars overnight.

    Now what happens when the honeymoon ends and Linux supposedly needs an extra 100 million dollars a year just to maintain this new level of security? MS/Amazon/Google to the rescue, for a "price".

  16. Anonymous Coward
    Anonymous Coward

    Follow the money....

    The inflection point:

    "What a nice Linux Foundation pays you - you know we, who pay the Foundation paying you, have invested billions in AI? It's time you promote AI too...."

  17. Big_C

    AI can learn

    I guess the issue of AI slob was addressed and all that sorting out of bad reviews helped to tune the models.

    And since many bugs have similar source code it is no sirprise that better reports pop up in all projects.

    So AI will get better as long as the results of those bug reports get worked into the training data. In that sense the project developers that worked through the pile of useless AI reports helped a lot - without pay.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon