Remix.run Logo
▲ The era of software quality, or the era of ostriches?(blogs.gnome.org)
28 points by vinhnx 2 days ago | 5 comments
▲kneyed 26 minutes ago | parent | next [-]

The tidal wave of reports will continue, until reporters stand to lose real money from submitting bad reports.

Reporters that submit useful, quality reports, should not only get their money back, but also a dividend on the money taken from low-quality reporters.

▲jongjong an hour ago | parent | prev [-]

Producing correct code is insanely difficult. It's hard to convey this to junior or even mid-level engineers.

In fact, for many complex projects, it's essentially impossible, even with AI.

Eventually, you get to a point when you have every feature you could possibly want but the list of tradeoffs is long and yet not worth trimming.

▲switchbak 24 minutes ago | parent [-]

I am quite a seasoned dev myself, and “insanely difficult” is not what I consider writing code to be. Perhaps if you have a crazy coupled system that is very hard to reason about, or you’re going about things in a very cowboy fashion. Or perhaps you’re writing under very challenging constraints.

Care to explain the circumstances/context that you mean?

▲simonw 16 minutes ago | parent | next [-]

Have you tried having a recent model audit your code for potential security issues recently?

I found that quite humbling. I thought I was a lot better at writing secure code than that.

▲jongjong 12 minutes ago | parent | prev [-]

I work with distributed systems. Try producing correct code with table sharding, replication, cache, realtime updates (targeted/efficient), distributed processing...

When I worked with blockchain before, that was another level because each node had to talk with thousands of other nodes; each running different versions of the code and they had to propagate messages throughout the network in a secure and scalable way without missing any nodes or reaching the same node twice (spam vulnerability) so your code is basically talking to different versions of itself which feels a bit like recursion, but harder and with a network between which adds latency and errors; and you can encounter tricky issues like message storms among others where the nodes keep bouncing and replicating a message between themselves. Or if any kind of propagated processing doesn't deduct tokens, then that's a massive spam vulnerability. Also, if the peer-discovery algorithm is structured, then the network is vulnerable to eclipse attacks. Also, most parts of the code had to be fully deterministic and idempotent or else some nodes could fork off the network. Stamping out all non-deterministic, non-idempotent logic is hard work, especially when you have to do it across multiple distinct nodes running on different machines operated by different people!