[PATCH 0/5] docs: improve guidance for AI-assisted bug reports

Willy Tarreau posted 5 patches 2 months ago
Documentation/process/coding-assistants.rst | 37 +++++++++++++++++++
Documentation/process/security-bugs.rst     | 26 ++++++++++++++
Documentation/process/threat-model.rst      | 39 ++++++++++++---------
3 files changed, 85 insertions(+), 17 deletions(-)
[PATCH 0/5] docs: improve guidance for AI-assisted bug reports
Posted by Willy Tarreau 2 months ago
While vulnerability reporters have now started CCing maintainers,
showing they read the docs, the security team still spends a lot of
time repeating the same comments about tested version, incomplete
fixes, poor email client setup causing formatting issues making
patches unusable, unverified reports and missing Assisted-By tags,
each time for AI-assisted reports.

This series adds small updates to security-bugs.rst, threat-model.rst
and coding-assistant.rst to better deal with this and provide minimal
instructions helping the LLM follow our expectations.

The updates were iteratively and carefully tested with 3 models,
Opus-5, Qwen3.6-27B-Architect-Polaris2-Fable-B-F451, and Gemini,
until all of them strictly followed the rules.

It is expected to further improve the situation.

Willy Tarreau (5):
  docs: threat-model: clarify "security bug" vs "vulnerability"
  docs: threat-model: move fake devices out of "non production use"
  docs: security-bugs: clarify what counts as a valid version
  docs: coding-assistant: explain important steps when looking for bugs
  docs: security-bugs: clarify some mandatory steps for AI reports

 Documentation/process/coding-assistants.rst | 37 +++++++++++++++++++
 Documentation/process/security-bugs.rst     | 26 ++++++++++++++
 Documentation/process/threat-model.rst      | 39 ++++++++++++---------
 3 files changed, 85 insertions(+), 17 deletions(-)

-- 
2.52.0
Re: [PATCH 0/5] docs: improve guidance for AI-assisted bug reports
Posted by Jonathan Corbet 1 month, 4 weeks ago
Willy Tarreau <w@1wt.eu> writes:

> While vulnerability reporters have now started CCing maintainers,
> showing they read the docs, the security team still spends a lot of
> time repeating the same comments about tested version, incomplete
> fixes, poor email client setup causing formatting issues making
> patches unusable, unverified reports and missing Assisted-By tags,
> each time for AI-assisted reports.
>
> This series adds small updates to security-bugs.rst, threat-model.rst
> and coding-assistant.rst to better deal with this and provide minimal
> instructions helping the LLM follow our expectations.
>
> The updates were iteratively and carefully tested with 3 models,
> Opus-5, Qwen3.6-27B-Architect-Polaris2-Fable-B-F451, and Gemini,
> until all of them strictly followed the rules.
>
> It is expected to further improve the situation.

Just FWIW I've read through these and can't really find anything to
complain about.  It looks like Greg is planning to pick them up, so I'll
not do anything with them unless instructed otherwise.

Thanks,

jon
Re: [PATCH 0/5] docs: improve guidance for AI-assisted bug reports
Posted by Willy Tarreau 1 month, 4 weeks ago
On Mon, Aug 03, 2026 at 10:20:43AM -0600, Jonathan Corbet wrote:
> Willy Tarreau <w@1wt.eu> writes:
> 
> > While vulnerability reporters have now started CCing maintainers,
> > showing they read the docs, the security team still spends a lot of
> > time repeating the same comments about tested version, incomplete
> > fixes, poor email client setup causing formatting issues making
> > patches unusable, unverified reports and missing Assisted-By tags,
> > each time for AI-assisted reports.
> >
> > This series adds small updates to security-bugs.rst, threat-model.rst
> > and coding-assistant.rst to better deal with this and provide minimal
> > instructions helping the LLM follow our expectations.
> >
> > The updates were iteratively and carefully tested with 3 models,
> > Opus-5, Qwen3.6-27B-Architect-Polaris2-Fable-B-F451, and Gemini,
> > until all of them strictly followed the rules.
> >
> > It is expected to further improve the situation.
> 
> Just FWIW I've read through these and can't really find anything to
> complain about.  It looks like Greg is planning to pick them up, so I'll
> not do anything with them unless instructed otherwise.

OK, many thanks to you both for the quick response!
Willy
Re: [PATCH 0/5] docs: improve guidance for AI-assisted bug reports
Posted by Greg KH 1 month, 4 weeks ago
On Sun, Aug 02, 2026 at 10:35:35PM +0200, Willy Tarreau wrote:
> While vulnerability reporters have now started CCing maintainers,
> showing they read the docs, the security team still spends a lot of
> time repeating the same comments about tested version, incomplete
> fixes, poor email client setup causing formatting issues making
> patches unusable, unverified reports and missing Assisted-By tags,
> each time for AI-assisted reports.
> 
> This series adds small updates to security-bugs.rst, threat-model.rst
> and coding-assistant.rst to better deal with this and provide minimal
> instructions helping the LLM follow our expectations.
> 
> The updates were iteratively and carefully tested with 3 models,
> Opus-5, Qwen3.6-27B-Architect-Polaris2-Fable-B-F451, and Gemini,
> until all of them strictly followed the rules.
> 
> It is expected to further improve the situation.
> 
> Willy Tarreau (5):
>   docs: threat-model: clarify "security bug" vs "vulnerability"
>   docs: threat-model: move fake devices out of "non production use"
>   docs: security-bugs: clarify what counts as a valid version
>   docs: coding-assistant: explain important steps when looking for bugs
>   docs: security-bugs: clarify some mandatory steps for AI reports
> 
>  Documentation/process/coding-assistants.rst | 37 +++++++++++++++++++
>  Documentation/process/security-bugs.rst     | 26 ++++++++++++++
>  Documentation/process/threat-model.rst      | 39 ++++++++++++---------
>  3 files changed, 85 insertions(+), 17 deletions(-)
> 
> -- 
> 2.52.0
> 

All of these look great, thanks for them!  I'll wait a day or two before
committing them to my tree and getting them to Linus for 7.2-final to
hopefully quell the onslaught of "bad" bugs being reported...

greg k-h