[FFmpeg-devel] [IMPORTANT] AI written TLS Code in WHIP patch

James Almer jamrial at gmail.com
Tue Jul 29 23:11:15 EEST 2025


On 7/29/2025 5:02 PM, Kieran Kunhya via ffmpeg-devel wrote:
> Hello,
> 
> It seem there is strong evidence that AI wrote TLS code as part of the
> WHIP patch. It goes without saying why this is bad. Further discussion
> here:
> https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20053
> 
> This patch was pushed without ML review.
> 
> I think this code should be removed before the FFmpeg release. I
> include TC in this email for that reason.

The UTF8 dashes are not so much an indication of LLM output but one that 
it was written with an unusual locale, I'd say.

As for the allegations that the code was seemingly written with one 
objective in mind, sure, that can be what an LLM does based on prompts, 
but also what a person does. It would not be the first time someone 
writes code without thinking of it having to work generically (The 
amount of API that was made for a single, very specific usecase that had 
to then be replaced by a more general one is not small).

That said, I agree the changes did look weird in places, so I'm not 
against reverting them in the release/8.0 branch so we have more time to 
properly audit it.

> 
> Regards,
> Kieran Kunhya
> _______________________________________________
> ffmpeg-devel mailing list
> ffmpeg-devel at ffmpeg.org
> https://ffmpeg.org/mailman/listinfo/ffmpeg-devel
> 
> To unsubscribe, visit link above, or email
> ffmpeg-devel-request at ffmpeg.org with subject "unsubscribe".

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 495 bytes
Desc: OpenPGP digital signature
URL: <https://ffmpeg.org/pipermail/ffmpeg-devel/attachments/20250729/3987786e/attachment.sig>


More information about the ffmpeg-devel mailing list