Amazon Lumberyard: A Scream of Anguish
viva64.com
viva64.com
Similar to linting, where often I need variation in rules, sometimes there's red herrings even in static code analysis.
Game software in general can be fly-by-the-wind because it's real-world software
... of course this is all me reacting and trying to argue with the clickbait :/
Yup. Something like :
> You have bugs in your codebase of 1M+ line, you want to fix them ? Buy my proprietary software for 30$/Month per user , which was built 100% on open source tech obviously.
Getting traffic using linting issues from a large codebase to promote a proprietary software , Outrageous.
NaN === NaN // -> false
This check is sometimes used to check if a number is NaN.I completely agree that having these warnings in the compiler is much better than a standalone analysis tool, because they're less likely to be ignored. But I think it may have been a bit of a shift of mindset for the compiler developers to put more effort into warnings and diagnosing dubious code rather than simply being a code generator for correct code.
Everything that is outsourced for an external tool, just happens not to be used by the majority.
Clearly the introduction of clang and its sanitizers has changed a bit the mindset, however they are still used by a minority.
As per CppCon 2016, 1% of the audience confirmed they were using some kind of validation tool.
a.x = x;
a.y = y;
a.y = z; <==
But those heuristics will usually also emit false-positives. This is why pretty much all static analyzers have an easy way to suppress warnings for a certain line (usually through a "magic comment"), but suppressing compiler warnings for a single line is much more cumbersome, since it has to be done through the preprocessor.It effectively shows value of their software while being interesting enough and relevant to something popular that already has (some) following. Perfect.
Makes me wish they had something similar for JS or Python. I know I've made these mistakes all too often.
That being said, I think this article really overstates the dire state of Lumberyard. Yep, it has bugs. I don't think this convinces me that the sky is falling if the devs don't change their ways.
I work at one of the companies who's product they "reviewed" and many of us got unsolicited emails basically saying, we found all these bugs using our code analyzer. Buy a license from us to fix them or we will post a negative review of your code.
It's a horrible business practice and they do that with many open source products. This behavior shouldn't be praised.
That's ANY shady son of a bitch for you, really.
Yes, it could not happen elsewhere, e.g:
https://www.xdesk.com/wirecutter-standing-desk-review-pay-to...
(And from a NYT backed website, nonetheless)
>That's ANY shady son of a bitch for you, really.
Better.
The optics of asking for that and after being denied changing the recommendation (presumably to something where they do get affiliate payouts) are quite bad.
That's a problem for the Wirecutter with products not available on Amazon: their (IMHO reasonable) argument has been that since they get the payout from a Amazon and not the individual vendors, they have no incentive to recommend a product that's not the best, since they get paid for whatever they recommend. This only works as long as everything tested is on Amazon. As soon as they start creating individual agreements with manufacturers, it becomes a lot less obvious that they can be trusted to not optimize for the most profitable affiliate terms. (Maybe there'd be something about having a policy that all agreements have to be the same, but that's tricky)
If it really is blackmail, have you contacted a law-enforcement agency?
But don't email me asking for money and threatening to write a bad review if I don't do as you say.
Blackmail or not, this is stupid.
Yes, these posts are advertisements for PVS-Studio, and since they frequently land on HN, they obviously work for them. Besides, you don't even have to buy PVS-Studio, since the Demo already will show you the complete analyzer output, you just won't be able to directly jump to the source.
Vulnerability != Weakness!
Cryengine is notoriously difficult to use. Crytek have also had severe financial difficulties. Amazon have their own team working on the source, I'm not sure how this has worked out but clearly amazon have plenty of resources to throw at it if they choose to.
The details are few and far between, but the possibility or being sued by the vendor would be a bit off putting for me.
> I remember reading about this and being left with the impression that [CIG] was in the green there.
If so, ISTR CIG is fine, but then they have a lot of money and fancy lawyers, a lot of smaller companies might have fared less well, and it doesn't really look good when a vendor is seen to be suing their customers because it is rumoured they are running out of money.
Would someone like Unreal have swallowed that from a client in order to avoid bad PR? Possibly. But if the allegations are true then I wouldn't go so far as to expect (in the moral sense) CryTek to let it slide.
CIG have moved to Lumberyard, a tech based on CryEngine, so lines of similar looking code are seemingly expected.
And the license was negotiated for a single game, not two as StarCitizen now is, but this would seem to be negated by the fact that these games are no-longer using CryEngine.
On the subject of CIG passing back engine improvements or not to CryEngine, I don't know.
Ran static analysis tool author is trying to sell on a 1 million+ line code base for Amazon's open source game engine Lumberyard.
Found warnings. Used it to infer quality of the product and wrote a very click-bait title.
They just bought it. Maybe the new team will clean up the code of Crytek?