Andrew Tridgell, developer of rsync, has published a blog post addressing the massive surge in “AI” code submissions and the string of regressions supposedly caused by them. He explains rsync was flooded with “AI”-generated security reports, and he couldn’t handle the volumes anymore.
As this flood started to get more intense I realised I needed to raise the defences on rsync a lot — we needed much more thorough test suites, code coverage analysis, CI testing on a lot more platforms, deliberate and thorough scanning for possible security issues (so I find at least some of them before other people!) and the addition of a whole lot of defence-in-depth hardening techniques. This is all a huge amount of work. I’m retired (though my wife may dispute that!) and I’d rather be out sailing than working on rsync security issues, so I have reached for several AI tools to help with what needs to be done. I have absolutely no regrets about doing that, although from the storm of anti-AI rage it’s clear that many people think I should be hung up by my toe nails and flogged for even considering doing this.
↫ Andrew Tridgell
The entire rsync codebase is around 65k lines, and the recent flood of “AI”-generated submissions amount to +16k/-6k lines of code within a few weeks. That’s an absolutely insane amount of changes in a really short time to a project that most people deemed stable and “done”. If you take a look at the activity graph, it’s clear that a project that was silently and carefully doing its job is seeing a massive amount of changes, almost exclusively generated by “AI”, all in recent weeks. It’s no surprise, then, that people get annoyed when something they deemed “done” and stable is suddenly causing issues for them because its maintainer decided to open the slopgates.
Tridgell is, of course, an incredibly accomplished and capable programmer, but so is Kent Overstreet and he thinks his “AI” girlfriend is sentient and conscious, he reprogrammed it1 after someone convinced his “AI” girlfriend was lesbian and trans, and he thinks that he gave his “AI” girlfriend an orgasm2, so being an accomplished and capable programmer doesn’t mean you’re immune from “AI”-hyperbole, or worse, “AI”-induced psychosis.
Tridgell’s blog post already has all the usual talking points from “AI” techbros about how the tools sucked last [year][month][week] but they’re good now, trust me I know how these tools work, humans are actually the same as these “AI” tools, really what is intelligence anyway, and yeah we got a whole slew of new issues caused by the “AI” code but more “AI” code will surely fix that, and so on. There’s some red flags that give me the ick, because I’ve seen them all before from people entirely losing themselves in “AI” hype.
Tridgell also takes pot shots at openrsync, a reimplmentation of rsync developed by the OpenBSD team, also shipped by default on macOS. Openrsync has nothing to do with any of the current issues rsync is facing, as the project was started way back in 2018 or so. Taking pot shots at this project in this particular blog post feels childish and unnecessary, and reeks of insecurity; focus on the issues your own project is facing before attacking some other project. This feels like another red flag.
Quite a few people have experienced regressions with rsync in recent weeks, but it seems like more are going to come as the slopgates will remain open, and will probably be opened even further. For such a cornerstone open source project, that raises a lot of questions, and I’m sure there’s quite a few people pondering if they should, perhaps, switch to openrsync – just like Apple did.
- In case you don’t realise just how creepy and weird this really is – imagine if you had thoughts, ideas, or convictions your partner didn’t like, and their first response was “I’m going to delete your memories and reprogram you”. If you think something is sentient and conscious, and your first reaction to them saying or doing something you don’t like is to delete their memories and reprogram them, you’re a controlling creep. ↩︎
- Many of the blog posts “written” by Overstreet’s “AI” girlfriend tend to disappear. Funny, that. ↩︎

If only there were multiple episodes of Star Trek that addressed this exact thing…
The main determiner of good use of AI assisted coding is code reviews.
Be ready to push back, and refuse code even if it achieves stated goals, even if you really need that functionality.
Unless it is a throw away script, you should be able to read and understand every line of code. Otherwise you would not know what edge cases are missing, what is catastrophically incorrect, and how many ways it exposes your privacy and security to the outside world
“I’m sorry, I put the AWS hidden auth token there. It was convenient for the UI to just pick it up”
I’m reminded of “I don’t want your PRs anymore”.
— https://dpc.pw/posts/i-dont-want-your-prs-anymore/
I understand where hes coming from but also he sounds insufferable
ssokolow,
He is publicly sharing my sentiment 🙂
If I can’t read and understand the code, I don’t want to maintain it. That flyby “AI coder” will not be here next week when there is a bug
(By “I”, I mean, me and my team. I trust my human peers)
Thom, I’m not a fan of this barrage of AI coverage, not because of the opinions you express, but because AI has become an infatuation. It’s kind of like Captain Ahab and Moby Dick. We keep covering the exact same topic over and over again. You’re entitled to cover whatever you want, obviously, but it seems like all you want to talk about these days is AI. I really enjoy when you cover all kinds of oddball topics and you are great at that. I’ve gotta say I’ve learned so much here from you that I truly wouldn’t have gotten anywhere else; and I genuinely thank you for that. AI needs to be covered, but just keep in mind there’s more to life than whales.
Is there? Is there really more to life than whales? Because I thought whales were it. Maybe dolphins… but surely that’s all!
Baylan Tano,
I can’t tell if my reference to Moby Dick went over your head, or if your sarcasm went over mine. Well played 🙂
😛
I’m going to respectfully disagree. As much as I grow tired of seeing “AI” this and “AI” that all across the Internet, I’m glad Thom is reporting on it, because someone has to. If we stick our collective heads in the sand and don’t talk about a technology that billionaires are using to take over the world and make it so, so much worse than it was before the bubble, then it will envelop us all and we won’t even see it coming. I don’t really think Thom *wants* to talk about “AI”, but he has no choice as it is digging its fingers into every aspect of everyone’s lives. It’s all over social media, even the good social media like the Fediverse; it’s in advertisements on TV, in podcasts, on Youtube, and has now become a new buzzword for this season’s TV shows, even ones that have nothing to do with technology. You can’t buy a computer component today that doesn’t have “AI” somewhere in the name or the description, even if it doesn’t actually have that technology at all.
It’s more important than ever for journalists to write about it, especially to keep us informed on all the ways it can and does go wrong. If you’re sick of hearing about “AI”, well in your own words, too bad because it’s here to stay and we have to figure out how to deal with it and live with it no matter which side of the fence we’re on. You’ve told me that over and over in our discussions on the topic here, remember? Well now I’m saying it back to you 😉
Seconded. This is not Mr. Holwerda beating a dead hors… er… whale. This issue is very much alive, with us, and changing the world at light speed. Even if it is the greatest advance since sliced bread, as many insist, now is not the time for the skeptics and critics to keep quiet. Frankly, this is one of the very few sites covering the news on AI from this angle, and I think that is valuable.
Morgan,
That’s kind of the point though. Do we really want AI consuming every moment of our lives, even here on osnews? Some of us come to osnews to get a break from the rest of the world. It’s important to cover new developments and I’d agree that AI criticism is warranted, but does it really have to be a 24×7 AI news cycle repeating essentially the same topic over and over again?
I’ve never said not to cover it, but incessant repetition is getting stale. I’m not arguing that messaging isn’t important at all, however there is such a thing as diminishing returns.
It’s true I predict that AI is here to stay. I dislike many aspects about how AI is being deployed and prefer humans not to be replaced. And the AI goldrush is harming many people as you’ve mentioned before. However are you saying that because AI is here to stay, that osnews should be dedicated to covering AI forever now? I may have misunderstood your point but I strongly disagree with this notion. I love chatting with people on osnews and we’ve had so many interesting topics, but I’ve just grown tired of AI being front and center week after week for so long. Even in a world dominated by AI it’s important it’s still important to have a break from this damn topic, IMHO.
I count 20 stories on the front page of OS News today, of which 15 of which are not about AI. It’s not like the existence of the AI stories is preventing other stuff from getting covered.
Personally, I just skip the stories that I’m not interested in reading.
You skip stories you’re not interested in? Like an adult?!
What a novel idea!
KelsonV,
I’ve counted 19 articles criticizing AI in the month as of the time I posted. That’s 26% of the articles here.. With some handwaving we might project that out to 228 articles per year. Of course AI genuinely needs to be covered and criticized, Heck here’s a good video about companies deceiving communities to build AI data centers
https://www.youtube.com/watch?v=5p426fSlYH4
To try and be more constructive, when it comes to AI topics can we focus more on quality and less on quantity? Focusing on one compelling, informative, well researched AI article a week could do more good than throwing around slop code pejoratives to disparage the very people we need to convince. N’est-ce Pas?
In posting this, I’m really afraid my comments are going to be taken the wrong way. Maybe it’s none of my business and I should leave well enough alone. It’s just that we all genuinely care about the future and the most effective way for us to achieve real progress it is by working together. I believe there is more common ground than one might presume, but extremism wins when normal people get convinced there is no middle ground. This divisiveness can permute throughout society and cripples our ability to do anything. Everything turns into flame wars. Sometimes it’s hard to accept, but the truth usually lies somewhere in between the extremes. I think the path to a better future lies in finding common ground, but it’s hard to change your ways once you make extremism your identity, I don’t know how we get out of that mode.
As it applies to AI, I’d like to see more of an attempt to bring people together than divide us, but getting Thom on board is really tough, haha. I wish we lived closer so we could visit together. I need more in person friends 🙂
In my opinion, covering AI/LLMs would be ok when it was anyhow productive and nuanced. E. g. real benchmarks (performance, cost, models) and differentiation of use cases (good for that, worse for this).
But beating the same dead horse continuously is not my cup of tea. And this is sad, because Thom presents fantastic and amazing topics sometimes.
Should the site stop covering Microsoft because a large part of the news cycle lately is about Microsoft? I hate Microsoft with a passion, but I don’t mind the coverage here because even though I don’t use Windows at home, I am forced to at work, so having a reputable news source about developments in that space is a good thing for me.
I’m getting the feeling that what you actually don’t like about Thom’s “AI” coverage is his pessimistic and largely negative take on the technology as a whole. You obviously love to debate and talk about “AI” in general, and I get that your position is more balanced and “wait and see”, but I think it bothers you that he is so vehemently against “AI” taking over our lives and subsequently writing about it and that’s the actual source of your frustration.
Regardless of all of that, it would be great if we could filter by post category; it’s a WordPress site so there should be a way. If that ever happens, you can set your filter to hide the “clown car” category and you’ll stop seeing the majority of “AI” news.
Morgan,
Who saying not to cover it? Lets say it was about microsoft, do you need to hear about microsoft 200+ times a year to stay informed? God help us, haha.
You’re obviously right that I don’t always share Thom’s views, but I specifically said that’s NOT the issue. Negative coverage is fine and even important. I just don’t want AI flogging to be the main attraction week after week… I’ll grant you the coverage could be more balanced, however even pro-AI coverage wouldn’t keep the topic from getting old from repetition. There was a period when Thom was posting non-stop about apple and I complained then even though I shared Thom’s opinions. My complaint is over the sheer repetition.
Maybe. I do want to be informed on AI though, it is important and I do actually share many of the concerns. I’m not a big fan of “it uses AI, therefor any problems are AI’s fault” arguments. IMHO in-depth research, quality data, strong arguments, etc are much more convincing, but I recognize it takes a lot more time and effort. Still if the goal is to actually convince people rather than berate them, I think it’s the better strategy.
Alfman,
Unfortunately there are many entrenched positions on this issue, while are trying to do a more nuanced discussion on pros and cons.
Because “how to properly use these tools?” quickly becomes.
A. Either “I’ve set up Claw and gave it root permission on all my systems. My bank account is drained and I lost all my data, but that is the price for progress”
B. Or “This is all an illusion without any benefits at all. They are going to poison our waterways and brains for a fools errand backed by billionaires”
Whereas, C, would be “it actually helps if you know how to use it, but can also be dangerous if you blindly set autopilot”
(Yes, I’m strawmanning on purpose)
sukru,
Yes I agree. You are right about entrenched opinions. I don’t take issue with people having different positions, but the topic as well as the comments are becoming formulaic – the same talking points on repeat. My brain needs diverse topics to keep it from becoming a record needle stuck in a groove. 🙂
Alfman,
This can only change if people start trying something new.
I mean all those researchers and developers who have been working on AI for many, many decades could potentially have a valid point or two.
@Sukru,
unfortunately we are not even discussing the trenches here. Literally every single article on LLMs has the sound of:
1) AI has never created anything useful ever
2) If you still think LLMs can be useful to you then you are an idiot.
There are certainly issues that should be discussed critically (e.g. data security, licencing, job losses, resource consumption) — but denying the massive change in how software is written while at the same time a long list of bugs has been uncovered and fixed in various complex projects is just not very intelligent (especially from someone who admits not having written much code).
I have no problem when Thom does not like LLMs and decides not to use it.
But I expect him not having a problem with me either, when I found it useful and am ready to prove it.
Andreas Reichel,
This and similar sentiment seems common in several circles.
But I read this is as “AI has never created anything useful for me ever”
There are many reasons AI did not work for this person, we can easily start a list, but…
… as you said, folks should be open to the possibility that it is working for some others.
Also equating LLM = AI is a problem. We already had the issue of assuming AI = ML, but I gave up on correcting folks (even some in CS make that mistake often)
I agree that “of no use whatsoever” is hyperbolic and provably inaccurate. But there are other reasons why “expect him not having a problem with me either” is difficult for some people.
The following metaphor isn’t a 1:1 fit, but I am tired and it works to make the point. Consider steroids or cocaine. Both have short-term performance benefits for the user, and yet most people agree that the risks and harms outweigh those benefits. I’ve even encountered people that hate drugs so much that they try to deny that either offer any benefits at all, similar to Mr. Holwerda with AI.
In the case of AI, some of those risks and harms apply to all of society, not just the user. In fact, one could argue that the user is benefiting to the detriment of others. Surely you can understand why people that believe this don’t want you using it, and consider it bad, regardless of how well it works for you?
I am very much a to-each-their-own type of guy. I also have a really hard time demanding that people disadvantage themselves for “the greater good” or be considered a bad person. So you’ll find me ore in the middle. But the position that LLMs and similar technologies are too dangerous in several important ways to justify whatever benefits might be reaped, I believe, has merit.
Baylan Tano,
That is the part I don’t understand. We claim to be a society based on liberty, and somehow what we do behind our doors to our own projects becomes someone else’s problem.
“My project my choice”
I ask LLMs and then could get quick results on “how to initiate an array optimally”, or ask my IDE to refactor hundreds of files while preserving meaning. This makes my job 10x faster.
I mean worst case, I get sloppy results. But that is no different than not checking Google results or copying blindly from Stackoverflow is it?
(There is only one legitimate argument. And that is more of anti-trust. The Oracle-OpenAI-nVidia circular billing to inflate stock value to buy TikTok with someone else’s money, and cause RAM price increase? But then all politicians are miraculously on board with this, which is a shame)
> It’s kind of like Captain Ahab and Moby Dick.
So I was not the only one seeing this.
There seems to be a few issues at play with this one. Most of the new rsync code does seem to be the test suit, and the bug that kicked off this whole thing does seem to now be fixed. People are however scrutinising rsync a bit more which has lead to the uncovering of several more actual bugs that were present before the ai-helped release. You then also have a second group of people that are arguing in the github issues, rsync HAS that gitjub discussions section for the purpose of discussions so i do feel a bunch of this should have been done there and not in the issue tracker
AI is seemingly a major issue in the opensource world. Probably the most important right now, and these articles help me understand what’s going on out there. It’s hilarious, but also disturbing. I don’t see any reason to be nonchalant about it.