Finding bugs in SQLite, the easy way
lcamtuf.blogspot.com
lcamtuf.blogspot.com
I can't stress how quickly this will turn me from "it's a good library" to "it's an amazing library". (Or prevent me from tacking on, "but it's kinda abandoned".) I've never sent patches SQLite's way, but I've sent patches to other open source projects, and whole quarters go by with nary a peep. This is not only frustrating, but often it feels like it pushes more work onto me than just accepting an even potentially buggy patch would cause. If I'm sending a patch, there's a good chance I'm using it myself, and thus your library has become a special-cased wart in my deployment process that I'd very much like to kill. (E.g., since I work in Python: I can't `pip install package==version` anymore; it needs to be on Github or something; thankfully pip makes this fairly easy; patches to things that some other package has decided to bundle rather than just use the package-manager approved version of are especially painful.)
While I'm not sure I'd go this far, the lament reminds me of http://felixge.de/2013/03/11/the-pull-request-hack.html
It is far, far better to send us a test case. The smaller the test case, the better, but any test case will do. We are much freer to accept test cases without copyright complications, and test cases have to be written anyhow before any changes are checked in. So just send in a test case and let us find and fix the bug for you. If it is a crash bug, it is usually fixed quickly - within hours.
lcamtuf always sent us succinct test cases. Never patches.