LLM generated code in free software is a potential landmine. The copyright of such code is an open question, and any current answer to that question risks changing at some point in the future.
This is a particular problem for git-annex since future proofing is an important aspect of its design.
So, git-annex does not contain code generated by LLMs and guarantees it will never do so.
However, libraries and other things that git-annex depends on do not generally have such guarantees. Although it would be very much appreciated if they did.
git-annex currently supports being built with versions of
dependencies that pre-date any introduction of LLM generated code.
To do so, turn on the NoLLMDependencies build flag.
When building with stack, use stack-NoLLMDependencies.yaml.
(It is not currently built that way by default, but such builds are welcome.)
Unfortunately, it's not possible to guarantee that will continue to work in new versions of git-annex. That's the goal, but it may become untenable. See below for details about possible future problems with specific dependencies.
Note that if a security hole is only fixed by a newer version of a
dependency, the NoLLMDependencies build flag will still build with the
older, insecure version.
Additional work needs to be done on an ongoing basis to review git-annex's dependencies to detect the addition of LLM generated code.
Help with finding these is welcome. Please edit this page and/or file bug reports on git-annex if it cannot be built without LLM generated code.
known dependencies that contain LLM generated code
ghc
This commit is probably the first, and will be released in the upcoming ghc 9.15.
git-annex remains buildable with older versions of ghc back to 9.6.6.
This will probably prevent git-annex from taking advantage of most new improvements to the Haskell language going forward. That is deeply unfortunate. This is the main reason why git-annex is not guaranteed to never change to depend on LLM generated code, because cutting it off from all future Haskell language improvements may be worse than the alternative.
ram and its reverse dependencies
ram since 0.21.0.
Note particularly large LLM generated code churn with apparently broken (how?) changes in 0.21.0 being reverted in 0.21.1.
Rather than use ram, git-annex continues to use the unmaintained memory that ram was forked from.
But ram is an dependency of other dependencies, and these in particular depend on 0.21.0 or newer:
- tls since 2.3.1
The NoLLMDependencies build flag depends on an older version of ram
in order to prevent such dependencies using the newer version.
persistent
persistent since 2.15.0.0
git-annex supports being built with older versions.
warp
warp since 3.4.11
yesod
yesod since 1.7.0.0
LLM generated commit with a 1489 line commit message and 10,000+ lines of changes.
(See ditch yesod)
magic
magic since 1.1.1
First disclosed LLM generated code
The person who took over magic from its long-time maintainer has not disclosed their earlier LLM use, but it is apparent, including in their communications to Joey about incorrect LLM-generated statements in the changelog.
crypton
crypton since 1.1.0
Later LLM generated code includes large amounts of C code that seems likely to have attribution or licencing issues. For example, see this issue.
The point of cryptonite was to package up industry standard C
implementations of crypto functions in haskell. This is no longer
that, and as such, does not seem like a trustworthly package to use.
Unfortunately, it is a dependency of several other packages,
including tls.
git-annex supports being built with older versions. The botan build flag enables using botan for most things rather than crypton.
tls
tls since 2.4.4
git-annex supports being built with older versions.
Cabal
Cabal is needed to build git-annex, but is not linked into it. There is a risk that a new version of Cabal could need changes to git-annex.cabal that prevent an old version building it.
git
Status is unclear. Possibly since 2.53 or 2.55.
git's developer documentation states that they will "reject anything that looks AI generated", with similar legal concerns as those discussed at the top of this web page. See this thread.
First Assisted-By LLM code, but the git developers think this and other similar patches mimicked other code in git is a way that makes them not be a potential license problem.
First Co-Authored-By LLM code which was merged into gitk upstream of git and so avoided git's policy.
git-annex supports git back to 2.22.