From: Willy Tarreau <w@1wt.eu>
To: Jonathan Corbet <corbet@lwn.net>
Cc: greg@kroah.com, security@kernel.org, skhan@linuxfoundation.org,
workflows@vger.kernel.org, linux-doc@vger.kernel.org,
linux-kernel@vger.kernel.org, Willy Tarreau <w@1wt.eu>
Subject: [PATCH 0/5] docs: improve guidance for AI-assisted bug reports
Date: Sun, 2 Aug 2026 22:35:35 +0200 [thread overview]
Message-ID: <20260802203540.3453-1-w@1wt.eu> (raw)
While vulnerability reporters have now started CCing maintainers,
showing they read the docs, the security team still spends a lot of
time repeating the same comments about tested version, incomplete
fixes, poor email client setup causing formatting issues making
patches unusable, unverified reports and missing Assisted-By tags,
each time for AI-assisted reports.
This series adds small updates to security-bugs.rst, threat-model.rst
and coding-assistant.rst to better deal with this and provide minimal
instructions helping the LLM follow our expectations.
The updates were iteratively and carefully tested with 3 models,
Opus-5, Qwen3.6-27B-Architect-Polaris2-Fable-B-F451, and Gemini,
until all of them strictly followed the rules.
It is expected to further improve the situation.
Willy Tarreau (5):
docs: threat-model: clarify "security bug" vs "vulnerability"
docs: threat-model: move fake devices out of "non production use"
docs: security-bugs: clarify what counts as a valid version
docs: coding-assistant: explain important steps when looking for bugs
docs: security-bugs: clarify some mandatory steps for AI reports
Documentation/process/coding-assistants.rst | 37 +++++++++++++++++++
Documentation/process/security-bugs.rst | 26 ++++++++++++++
Documentation/process/threat-model.rst | 39 ++++++++++++---------
3 files changed, 85 insertions(+), 17 deletions(-)
--
2.52.0
next reply other threads:[~2026-08-02 20:36 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-02 20:35 Willy Tarreau [this message]
2026-08-02 20:35 ` [PATCH 1/5] docs: threat-model: clarify "security bug" vs "vulnerability" Willy Tarreau
2026-08-02 20:35 ` [PATCH 2/5] docs: threat-model: move fake devices out of "non production use" Willy Tarreau
2026-08-02 20:35 ` [PATCH 3/5] docs: security-bugs: clarify what counts as a valid version Willy Tarreau
2026-08-02 20:35 ` [PATCH 4/5] docs: coding-assistant: explain important steps when looking for bugs Willy Tarreau
2026-08-02 20:35 ` [PATCH 5/5] docs: security-bugs: clarify some mandatory steps for AI reports Willy Tarreau
2026-08-03 15:37 ` [PATCH 0/5] docs: improve guidance for AI-assisted bug reports Greg KH
2026-08-03 16:20 ` Jonathan Corbet
2026-08-03 16:24 ` Willy Tarreau
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260802203540.3453-1-w@1wt.eu \
--to=w@1wt.eu \
--cc=corbet@lwn.net \
--cc=greg@kroah.com \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=security@kernel.org \
--cc=skhan@linuxfoundation.org \
--cc=workflows@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.