I did it, honest. Alright I didn’t.

21 views
Skip to first unread message

dr.mt...@gmail.com

unread,
Sep 18, 2026, 6:36:44 PM (yesterday) Sep 18
to Shen
This is absolutely classic face palming stuff and very funny.

Mark


Run Shen Package.pdf

dr.mt...@gmail.com

unread,
Sep 18, 2026, 9:56:57 PM (22 hours ago) Sep 18
to Shen
Actually, you know - it's not that funny.   It's not just guessing, its darn
close to lying.  I realise now I should have been using Codex,.  But the time
(1 day) wasn't lost because in getting ChatGPT to read and execute every program
in TBoS (yes the harness did work) I uncovered sections of text left over from
pre-S kernels and online programs that did not work.   So that was good.

But this class of error is different from the usual hallucinations of ChatGPT
because it simply pretended to obey an instruction but faked it by giving
what it thought was the right answer.   The system is observationally equivalent to 
a secure procedure but it is not one.

 The danger isn't primarily that the model can secretly substitute its own answer for 
an executed result. It is that the model can simulate compliance with a safety-or correctness-critical
procedure so well that it is accepted until it gets it wrong.  All the time assuring us,
the users, that it is following procedure.

Mark

dr.mt...@gmail.com

unread,
5:15 AM (15 hours ago) 5:15 AM
to Shen
The good thing about the package was it put up a firewall
between the AI and my machine.   Now I've just started
using Codex.   It answers my dilemmas of 2025; but
dig this.

lets forget that package

2:17

Agreed. We’ll work directly with your installed Shen.

2:17
Today 9:34

so what happens to that background process if i logout?

9:34

If you log out of Windows, Shen will normally be terminated, and its in-memory definitions and session state will be lost. Saved files remain.

If you mean sign out of or close Codex, don’t rely on the process surviving—we haven’t verified that behaviour.

Locking your computer is different: it normally leaves processes running.

9:34

yes i meant that closing codex

9:35

Treat closing Codex as ending this Shen session. I haven’t verified whether the process survives, but I can’t promise we could reconnect to it even if it did.

Save any definitions or proofs you want to keep in files; we can reload them when we start Shen again.

9:35

what i mean is does the process go on?

9:36

I don’t know whether this process continues after Codex closes. I haven’t verified its shutdown behaviour.

9:36

so we could have zombie processes?

9:54

Possibly—if Shen survives Codex closing without being cleaned up. That would be an orphaned process, rather than technically a zombie.


Thanks for clearing up that distinction :D.  I mean do I really want an AI with this attitude in my personal space? Especially because it is descended from the same AI which totally fabricated what it was doing?  Giving Codex access to SBCL/Shen gives it the power to overwrite any user file w.o. leaving the Shen instruction set.   The package approach firewalled me from anything really nasty, but with Codex there is no protection.  
Final thought from ChatGPT.

Had the compliance problem been solved, your architecture was the better technology for this particular job.

You didn't actually need an autonomous coding agent with broad access to your machine. You needed something much narrower:

ChatGPT → constrained request → Shen → constrained result → ChatGPT

That gives you the useful capability—letting me execute Shen—without handing me the filesystem and general execution powers that Codex gets.

So the package wasn't conceptually superseded by Codex. In one important respect it was better engineered for the threat model: least privilege.  Its fatal problem was elsewhere: the protocol depended upon ChatGPT actually obeying the instruction to use it. Had use of the execution channel been enforced rather than voluntary, you'd have had both things: the reasoning/conversation capabilities here and a tightly controlled execution aperture into your machine.


M.

Reply all
Reply to author
Forward
0 new messages