They caught it, the person has lost trust, they all moved on. Big whup.
They caught it, the person has lost trust, they all moved on. Big whup.
Bad code going unreviewed from a single author into a main branch from which people build production systems is definitely beyond "Big whup" severity. The equivalent would be if one person pushed an unreviewed driver into Fedora Rawhide or an Ubuntu Beta, say. It's a clear violation of the principles behind the service the distro is supposed to be providing for you.
There are a zillion ways to make sure code gets reviewed before merge. Linux does it informally via Signed-off-by headers and a tree structure of trusted maintainers. Services like github provided automated tooling to enforce review. FreeBSD needs to just pick one. It's 2021, for goodness sake. A fixed COMMITTERS list just isn't going to cut it.
Call me mean, but I don't associate FreeBSD with a project that is quick to adopt modern development practices.
I remember the time that FreeBSD moved from CVS to SVN, and it was hailed as revolutionary. The world was already embracing Git, which, despite its flaws back then, was perceived as a bliss compared to SVN.
There is much value in not constantly hopping onto every hypetrain that comes along. For a reliable project, I want to see engineering practices that favor remaining on proven stable technologies as long as possible. Let all the hypes die down, don't go down with them.
An analogy would be lawyers. They don't represent family because they may overlook something they think is meaningless, but a "fresh pair of eyes" would say is very important. With code, it's the same way: your eyes are biased towards your own code which can cause you to miss a bug.
https://lobste.rs/s/sh2kcf/buffer_overruns_license_violation...