p.enthalabs

Changes to Sourcehut's terms of service regarding LLMs

sourcehut.org · Read Story HN original

Comments

> The new terms of service, which will go into effect for new projects after the usual two week notice period (i.e. September 10th), will now include the following under the list of prohibited content:

> - original content written with or which facilitates the use of LLMs (large language models) or other generative AI technologies

> The use of LLMs or other generative AI tools to produce or assist with the production of source code, assets, tickets, emails, and so on, will no longer be permitted on SourceHut once these terms take effect.

> As with our other policy changes, the intention is to roll this out slowly and thoughtfully. Each possible violation will be evaluated on a case-by-case basis and we are open to making exceptions.

It would be less misleading to also include:

> Moreover, the use of AI for purposes other than co-authoring code, tickets, emails, and so on, is discouraged but not prohibited. If you use LLMs privately to review your work, to ask questions of, to perform security analysis, and so on, and then write original code to push to SourceHut, your use-case is aligned with our policy.

I think this is more of a nitpick than anything. SourceHut is a code forge, code forges are where you store your code (and tickets). The policy going forward is a ban on using LLMs to write code (and tickets). The use cases listed there (reviewing work, asking questions, etc) are minority use cases and mostly would be unenforceable even if included in the policy.
It's not a nitpuck to me: reading the comment I replied to, I assumed I needed to cancel my Sourcehut subscription. In fact, I don't. That's a lot of information to've left out of so many pull quotes.
Your worry was that if you used AI for things other than generating code/tickets/communication/assets, that you couldn't use sourceforge?
Correct. This is specifically what covered my uses of the service:

> to review your work, to ask questions of, to perform security analysis

I am a paying supporter and I am considering to stop paying. This policy is a) dumb b) unenforceable. I pay them for infrastructure and service, not for some pseudo-moral ideas about how I should write my code. My code is as little of their concern, as things happening in my own house.
You are literally paying them to be concerned about your code.
Paying to store my code, not paying for them to police who or what wrote it or assisted in writing it.
Nah - all my repos are private, they mostly contain my configs and I am not paying money to read these insanities about tools I use.

As much as I like paying to escape a capitalistic monstrosity such as github, they still seem to be more … mentally stable, for the lack of a better term. At least you are not at a whim of some BDFL or an aggressive minority of radicals. It is quite sad, that we have a choice of enshittifaction and radicalization only, with nothing in between just providing good service to paying customers.

> It is quite sad, that we have a choice of enshittifaction and radicalization only (...)

Maybe this is a question of point of view? I find github's stance on slop extremely radical (and totally contrary to my own values). At the same time, github is obviously enshittified, so I don's see the point in using it anymore.

You still have gitlab, which is some kind of middle ground. And if you only need to store private config files, you can host a private instance of forgejo--or a bare git repo--for much less than a sourcehut subscription. I hope you find your place! (still, I'm curious why your config files are AI slop, but that is another subject)

For a simple reason - I may one-shoot an emacs function (or several) I need for my config with claude. So, it is technically slope. I am also against self-hosting - I don’t have time and patience for it. IT is not a valuable hobby for me anymore, with LLM or without.

I guess, back to github :)

Same, and for the same reason, I considered the same when they added the "content related to cryptocurrency or blockchain technologies" clause as well, though I do not see the value in these technologies.

I will add that the policy is not just dumb and unenforceable, it is also poorly reasoned. Many of the arguments apply equally to other technologies, or don't apply to AI-generated code in the first place.

If resource usage/hardware costs are a concern, should games and databases be banned? If financial ethics are a concern, should SaaS services/apps with micro-transactions be banned? If ownership is a concern, should closed-source software or private repos be banned? And so on.

I think it is obvious that this choice, much like the crypto/blockchain choice, was made purely because of the "vibes" (if you will) around AI, and not for any logical reason.

> I am a paying supporter and I am considering to stop paying.

Great, they said they will give you plenty of time and support to do so. I respect their decision, not everyone is allowed to do everything on every platform. By choosing a Github, you invariably support a whole set of other things through their owners. It's not a bad thing to be forced to consider the long term impacts of your choices. If this was a bad decision, the market will say so.

But I mean, I never used Sourcehub. With this stance, I respect them even more, so maybe I'll start paying. Guess that cancels you out!

Good luck. Just be prepared to deal with other “great” ideas down the line, because when I subscribed such bullsh*t was not in terms. Fortunately, my renewal was due on 28.08 (I am not making it up) so I was able to cancel. I pay for services, not performance artistry.
If you think that with Drew, you only paid for services, you have been willfully ignoring his advocacy since the inception of Sourcehut
As I already said: not interested in radicals and/or personalities — they are doomed to fail. I only pay for services provided. Sourcehut was a minimalistic service fitting to my minimalistic personal needs. Not anymore. Good riddance, sourcehut!
I've been a paying customer since... pretty much since I've first seen the project, which has been quite a few years. I've always known the srht founders as rather strongly opinionated - for better and worse. This has always bothered me a bit, but I still strongly preferred it to Github and the likes. And it didn't hit me either with the cryptocurrency related bans. Unfortunately this time, it does. And not because the policy is an anti complete slop policy, but because it bans relatively (at least to me) reasonable AI use as well.

Disappointing, sad, but not surprising. Moral grandstanding in the face of AI does little, it's already here to stay, whether we like it or not.

I wish there were reasonable alternatives.

I use LLMs at work without much thought by now. I'm also contributing a little bit to Sourcehut and keep my personal projects there.

While I'm not necessarily in the "LLMs are evil" camp, I find I respect this position a lot. I wish more people would do what they feel is right, even if that's going to result in a backlash from those who disagree.

When it comes to my personal projects, I realize I haven't really touched many of them in the LLM age. In a way, AI has made me uninterested in programming. This might actually be a nice demarcation line: keep my free range organic code on sourcehut and actively not use AI for my personal stuff. After all, LLMs (may) mostly help with speed (sometimes) - which was never the issue for the stuff I create "just because".

Summary of the mailing list discussion (https://lists.sr.ht/~sircmpwn/sr.ht-discuss/%3CDKSTMKM0ZD9N....) - counted by hand without LLM assistance so there may be mistakes or misreadings :)

~51 in favor of the proposal. 20 of those specifically stated a desire for a blanket or as-strong-as-possible ban. 17 mentioned paying for the service. Many (sorry, didn't count these!) stated that the reason they joined SourceHut in the first place is because of the strongly opinionated culture and that an LLM ban aligns well with that.

~19 opposing the proposal to some degree. (I am counting Greg K-H's comments as a very weak "oppose".) 5 specifically mentioned paying for the service, and 1 stated they will stop paying if the policy takes effect. Some stated that they don't personally use LLMs, or don't like them or the effects they have, or would support a weaker ban (e.g. only ban fully vibe-coded projects or excessive resource usage).

Drew convinced me that we should abolish copyright through his blog[1][2]. I find it very unfortunate that he uses the copyright licenses of the software hosted on SourHut as an argument against LLMs. Abolishing copyright means abolishing copyright for everyone, even you. Even if you don't like what people do with their copies.

I also find the reference to the energy consumption of AI dated a year and a half ago to be extremely unconvincing. The efficiency gains in AI over the course of the last year have probably been unparalleled in any other era of computing. The model (Qwen 3.8 27b) that I run on my own hardware on a single, high end gaming GPU, is often compared to the state of the art, massive frontier model from the beginning of this year. There was literally no amount of money you could pay to any company to run the biggest, most energy hungry AI model in existence at the time that the reference was written, that would even compare to the quality you can get out of a single GPU now.

[1] https://drewdevault.com/blog/Alice-in-Wonderland/

[2] https://drewdevault.com/blog/Sustainable-creativity-post-cop...

While I am 100% with you that we've arrived at the place local GPUs can do real, good work and that it helps combat the energy arguments against certain LLM usage, Drew is not likely to agree with you. I can't find it on a quick search which tells me I'm probably remembering it from his prior Mastodon account, but I distinctly remember Drew once talking about how gaming GPUs were part of the (climate) problem and that we should all take notes from the Nintendo Switch in terms of gaming joy delivered per watt.

This is not to say I disagree with Drew's desire for efficiency, even in gaming. This is simply to say: from my recollection of that blog/toot thread/whatever it was, even home LLM usage won't meet what I recall his energy bar to be, until we've got planning and orchestrator models that fit on a non-flagship phone.

The efficiency gains only make us use less resources if demand is fixed rather than elastic. Look up Jevons's paradox.
As long as copyright exists, we need copyleft licenses to ensure that covered software can't be copyrighted.

That is to say, being against copyright doesn't mean you want to allow others to abuse it against you.

To be against copyright is to not believe the idea of "adversarial copying". It doesn't matter if you like or dislike what other people do with their copies. The act of copying simply does not harm you.

The only way people can "abuse copyright against you" is if someone claims you violated their copyright, and invokes a DMCA takedown request, or sues you. You using the GPL will not protect you from this in any situation I can imagine. In fact, what Drew is doing here (claiming violation of copyright) is literally the only way to abuse copyright.

LLMs aid people in abusing copyright by stripping copyleft software of its freedoms and then making derivatives which the author then copyrights restrictively. It's simply not a level playing field when one party is allowed to restrictively copyright their work, it creates a competitive advantage. This is why copyleft exists, to prevent people enacting restrictive copyrights over their derivatives of copyleft works.
I don't know how this can be enforced, there's a lot of room for interpretation, making projects at risk to be banned.

> - original content written with or which facilitates the use of LLMs (large language models) or other generative AI technologies

and

> Moreover, the use of AI for purposes other than co-authoring code, tickets, emails, and so on, is discouraged but not prohibited. If you use LLMs privately to review your work, to ask questions of, to perform security analysis, and so on, and then write original code to push to SourceHut, your use-case is aligned with our policy.

So from what I understand it is OK to use AI for security reviews privately but is not cool to host a project that allows to do that?

Also, what does it mean "and so on"? Like "anything we consider we don't allow at some point?"

Just to add a datapoint to the discussion: as a paying customer of sourcehut I 100% support this anti-slop policy. I'd prefer if some terms were stated somewhat more precisely, but it's great as it is.
Sigh, frustrating for me but I guess I understand the rationale, if not the implementation.

I'm retired from programming professionally and I liked using Sourcehut for my personal projects because it just got out of my way, and I could put my mostly-old open source projects up there without worrying about people trying to contribute to them thanks to the friction of the system. I do slop-code hobby projects because I'm pretty much done with programming for fun now, but they're always private and I know that my relative load is low as I don't do much different from how I would personally use it.

Personally I'm in favour of blocking LLM pull requests/merge requests/patches to open source repos - the sheer volume of crap is out of this world. I saw a repo with 1.1k unmerged PRs yesterday! The code can be from an LLM but the request to merge it damn well better be written by a human. I'm not going to put effort into reviewing something someone else couldn't be bothered to even write a blurb for.

But for private projects, just shove a rate limiter on the endpoints and be done with it.

Lately I'm very conflicted about software development as a whole. I've always aspired to be good, both in my work and in my relationship with others in the industry. But I can't be arsed any more - the joy has gone out of software, and I just want it to be done and out of my way. And now I have to move my photography portfolio repo that has fewer commits per day than I could write by hand, because there can't be grey areas or compromise on the modern internet.

I used to work for GitLab, for what it's worth (and they've gone quite far down the AI toilet), and I honestly don't think I can be arsed setting up that or anything else. I might as well just shove bare repos on my NAS and go do something I actually enjoy.

Hah, llm detection is unreliable so a ToS like that can’t be enforced that way… that change moves responsibility to contributors who will break it, what about the autocomplete, refactoring tools?
I respect their decision. I’ll move my private slop repos to a self hosted instance.

I don’t think that features like tickets and mailing lists matter for vibe coded projects anyway. They are made for an audience of one.

sourcehut is too weird to live, too rare to die