We all hate this
@gregkh dropping necessary bombs about LLMs in Linux security and development.
https://www.youtube.com/watch?v=NnV_cWeoo5Q
The purported 79 vulnerabilities were mostly bogus (not a bug, fabricated data) or had already been patched; the few real (all very minor) bugs took him an hour to fix. He says "do not panic", and emphasizes that time to apply patches is the main vulnerability these days (not an LLM problem).
"These are pattern-matching tools", "they do not have intent". (Vindicating to @emilymbender and @timnitGebru re "stochastic parrots"; it was accurate at the time and accurate today, protestations from boorish AI boosters notwithstanding.)
New code is 50% wrong, generated code is littered with new vulnerabilities; need to reject a lot but believes review processes are adequate to prevent a shipping a flood of LLM-generated vulnerabilities.
High false-positive rates make the models incredibly irritating. Cf. Coverity's post-mortem with a deterministic tool that had low false-positive rates.
Push back hard [on corporate marketing to developers]
With regard to higher CVE rates:
We'll grind it down like we did with the fuzzers.
If you want to look for bugs with an LLM (which amounts to fuzzy pattern-matching), use a local model and never upload to platforms.
I have banned LLMs from driver staging, unless you have the hardware and can prove you have tested the patch. That's not what staging is for. Staging is to learn how to do development and get involved with our community. [...] Kernel development is all about trust. If I take patches from you and I don't know who you are, now I am responsible for that patch. [...] You need to build up trust.
It's put a lot of additional burden on us, as maintainers.
#Linux 7.3, since a few hours ago, will definitely be the #kernel with the most commits, as right now it already has 18.672 (17.410 if you ignore merges).
The previous record holder was 6.7, which had 18.404 (17.284) -- and was bigger than other releases at that time because it contained nearly 3,000 commits of bcachefs history.
For more stats on #LinuxKernel releases, see https://docs.google.com/spreadsheets/d/1_yH7lFmZxAoSWrtsd8tGu3befG4zIcMnytB1ml4pQQM/edit?usp=sharing
@gregkh @KernelRecipes @muvlon we've partially addressed this confusion at ADI by generating CVE lists specific to our defconfigs:
https://analogdevicesinc.github.io/linux-security-vulns/#known-vulnerabilities
It's like everyone who came on board to AI because "they can write code now!" thinks the primary argument the rest of us have is "no it can't"
So I'll be the one to say it: yes AI can write code. I believe you. They can write code. It compiles. It even passes the tests that the AI also wrote.
Unfortunately the code they write is shit. It's automated technical debt with built in landmines. You think people coding in C causes issues? Wait'll you see what LLM code produced on massive scale does
Kairui Song is starting the last day of the conference : Swap and Memory Reclaim: Squeezing Out More RAM
What was SWAP subsystem before and now: Too many indirections kill indirections
@KernelRecipes @gregkh nah, the line is green and green means good! 😁
What kernel maintainers think of bots, in four slides:
they talk: endless changelogs nobody asked for
they flood: dozens of "fix leak" patches before your first coffee
they lie: the "best" models are still wrong half the time
they leak: whatever you tell them, they'll tell someone else
So basically... the perfect coworker!
#kr2026
Survival guide for the age of bots, #kr2026 edition:
If it feels wrong, it probably is
Ignore the doom marketing
Keep your models at home
NEVER feed them anything non-public
Found a bug? Fix it. Today. Yourself.
Meanwhile, the kernel security team now asks for a patch with your report. Revolutionary concept.