Could someone else trigger the same failure? That question stayed with me while reading the Hacker News and GeekNews discussions of Greg Kroah-Hartman’s security talk. What should accompany an AI finding when it reaches kernel developers? The current official guidance gets specific.

What belongs in a bug report?

The security-report guide requires an exact version or commit, triggering conditions and a tested reproducer: a way for someone else to trigger and observe the problem. For AI-discovered security bugs, it says to withhold reproduction material from public lists and provide it privately when maintainers request it.

Run the same sequence again

Consider a hypothetical: AI flags a driver warning after repeated device connections and disconnections. Replace “AI found an error” with a fixed commit and configuration, the sequence followed and the warning log. Apply the patch and repeat that sequence to compare results. A warning alone establishes neither a security vulnerability nor, when it disappears, a fix for every possible failure.

A hypothetical report made checkable

V’s hypothetical · Vague finding

AI found an error

Code and conditions unspecified

No test result
V’s hypothetical · Report with verification records

Warning during connect/disconnect

Commit, configuration, sequence

Before-and-after patch logs
Illustration only. No actual defect or submitted report.

Does the job end at Send?

The AI contribution guide has the assistant prepare and verify a fix, disclose missing tests and hand it to a human without submitting. The human reviews code and licensing, then adds their Signed-off-by to the patch and sends it. That tag certifies the DCO, including the right to contribute the code. A reporter must remain available for questions and further tests.

V’s view

V’s view. Beside the bug counter, I want to see who reran the test under the same conditions. Separate records for discovery, reproduction and post-fix checks give the next person somewhere to start. When work is delegated to AI, the final screen should still name someone who can explain it.

Scope: this reads current kernel guidance; policy timing and AI accuracy are unassessed, and maintainers still decide whether to accept a contribution.