User-triggerable NULL pointer dereference
jira.mongodb.org
jira.mongodb.org
Now, about the tone - be a human first, programmer second. Even though it seems 10gen screwed up big time, everyone makes mistakes. You could inform them of what seems to be a major issue privately and politely, not ridicule them in public. I wouldn't want it done to me and I'm sure neither would you.
As said by Chazal (old timey Jewish scholars): "Proper behavior precedes the Torah ... and whoever humiliates another, it is as though he killed him"
EDIT: I'd just like to add that among the companies affected by this disclosure and which are now totally open to attack are Craiglist, Firebase, MTV, SourceForge, Codecademy and others. Here's the full list - http://www.mongodb.org/about/production-deployments/
However, I've written similarly irate messages at 4 or 5am, particularly after spending months working on a product. And this level of coding quality is unacceptable in any product which wants to be large-scale deployed on the internet.
Proper disclosure takes effort. The product owner can offer bounties to motivate others to make that effort for them. But if you can't/won't spend that effort, then it's still better to publish the bug than not publish it.
I'm sure we can come up with a best way to go about things. I'm not really cool with the "oh Mike" part of it. But I think it's mostly okayish. Certainly a lot more okay than the bug.
It's not hard to find out how to report security issues to 10gen: http://docs.mongodb.org/manual/administration/vulnerability-... and the terms they ask for look reasonable to me.
Dehumanization creates more harm than ten thousand crashing web apps. Packaging the evil as the wisdom of religious scholarship changes nothing.
Refined words and moralizing demeanor but gilly suit vileness and violence.
Even so, I still stand by the message even if the wording was wrong - one should be a human first in the sense that one should be empathetic and strive to be good. And yes, I still stand by the quote from Chazal which, even as an atheist, I appreciate as a part of my cultural heritage. All it's saying is that being a good person is more important than anything (even studying the Torah) and that one should not humiliate others. I think those are important and valid messages.
Databases are such a system. They're expected to attain and maintain an extremely high level of quality and reliability. Those who build them should expect to do everything in their power to avoid flaws, and these people should be more than willing to accept harsh reprisals when issues are found.
When the security and safety of data is at risk, some developer's hurt feelings should be the last thing anyone is concerned about. There are far more pressing problems at hand in such a situation.
The forum in which we are dialoguing is not the MongoDB IRC. It is HN.
The effects of dehumanizing those who do not share our background are well documented by history. They extend well beyond hurt feelings.
In my opinion, MongoDB is a questionable component.
A few years ago, when it was really hyped beyond belief, I think that anyone with at least some database experience, and who could look at it objectively, was inherently suspicious of MongoDB.
There were, and clearly still are, just too many things that are disconcerting about it. These range from how it rejects much of the proven knowledge and experience gained over the past four decades, right down to the community who embraced it and the people who hyped it the most.
Thankfully, many of us saw this, and we stood against the use of MongoDB and other unsuitable NoSQL "databases" for the projects we work on, or within the organizations we may work for.
While it is unfortunate if others suffer as a result of this bug, I can't help but feel that they should have known better than to use MongoDB in the first place. The unease and skepticism should've been there. Given the numerous other proven and reliable DBs, including free and open source ones, there's really no reason to have used MongoDB, in my mind.
I strongly agree with the author on the rampant disconnect between Mongo's actual quality and its marketed quality.
:)
I'm in good company then.
But I'd rather think that being a dumbass is orthogonal to caring for tone.
Who's Paul Graham to stereotype hackers as socially awkward and blunt? http://www.paulgraham.com/nerds.html
Who's Miguel De Icaza to do it?http://tirania.org/blog/archive/2011/Feb-17.html
As for me, I'm someone who's a geek and has been around geeks and/or hackers for ages. And you has read and seen most of the hacker folklore, from the dictionary, to Pirates of the Silicon Valley, to blogs to HN.
I also don't like the "all" qualifier you used. That can make any (otherwise totally valid) generalisation appear wrong.
A "stereotype" is not something that necessarily applies to ALL members of a group. It's just something that the statistical majority of some group holds.
(Or course it can also not hold at all. But the hackers I know at least, would agree it holds for hackers, especially the more absorbed and technical ones -- e.g think Torvalds and Wozniak not DHH or some random startup coder who does some front end work and is otherwise a total hipster).
Actually, just fixing the bugs after public outrage will no do.
They should focus A LOT on the noisy part of the message.
And feel shame. And then do something about it.
I'm glad for the noisy part myself.
No the MongoDB team should not feel ashamed, the author of this bug report should. This kind of aggressive writing is unprofessional, rude and childish.
People make mistakes, even good engineers do. They should not be yelled at like this even if they screw up badly. Writing software is a team effort, and the users of open source software should be a part of that team and take the collective responsibility of finding, reporting and fixing bugs in an effective and civilized manner.
The tone of this bug report does not help fixing this bug faster or better, but it does make the reporter look like an ass.
They don't even need Coverity, there are numerous cheaper and free static analysers that could have caught this before it left 10gen's offices.
Marketing a database server that crashes with such C-101 style bugs due to the shape of the data being stored is simply beyond.
I disagree that publicizing stupidity like this can do harm – the crash is clean enough that any trivial crash restart loop (e.g. just about any production web server) will catch it. In the meantime the company are much more motivated to provide a fix that I need, that I should never have needed in the first place.
For all the "responsible disclosure" idiocy on this thread, in most cases the crash is not remotely exploitable unless some API directly stores JSON objects provided by a user, and even then, amounts to little more than a slow request – a crash triggering a potentially expensive restart of the failed process. Useful for a DDoS perhaps, but not an immediate national security threat.
We happen to want this functionality since its one of the main "it's just JSON" selling points of Mongo to begin with, we want index visibility for the user data, and we think it's ridiculous that we should have to double-serialize the user data (and write our own indexing) in order to avoid obvious bugs.
But would you go yell like that at a real person in real life when working at the office? If not, why would it be ok to do it in a bug tracker anonymously?
I can't think of any offense I could do that would make it acceptable to yell at me in an irate manner as in the bug report. I'm really glad I don't work with people who consider this kind of behavior acceptable.
Definitely YES.
It's Paul Graham's hierarchy of disagreement.
People make mistakes, even good engineers do. They should not be derided like this even if they lose their temper. Writing software is a team effort, and the users of open source software should be a welcomed part of that team and their feedback taken in an effective and civilized manner.
The prudery of your comment does not help fixing this bug faster or better, but it does make it look like your priorities are severely misplaced.
Requoting that is ridiculous. Allow me to list why:
1. There is nothing for the parent poster to feel ashamed about. Nothing he said is shame worthy.
2. He wasn't aggressive. It wasn't a knee-jerk reaction. It wasn't unprofessional, rude or childish.
3. The author of the bug didn't make a mistake. They submitted a bug report designed to be as brutal and belittling as possible. They didn't just lose their temper in the heat of the moment, they decided to setup a new account under a pseudoname, then blasted the author of the software product.
4. Writing software is indeed a team effort, but as with any team if one party abuses the other the team rapidly becomes less effective.
5. Feedback doesn't have to be abusive. It's a bit rich to say on the one hand feedback can be abusive, but on the other hand that abusive feedback must be then taken in a "civilized manner". Do you not see the contradiction?
6. There's nothing "prudish" about remarking that abusive bug reports don't make the bug get fixed faster or better. To be a prude, you must be excessively concerned about propriety, and there's nothing in the parent's comment that is excessive.
7. The parent's comment was a general comment, and wasn't an attempt to fix the bug. There's nothing misplaced about the poster's priorities. He's here to comment on HN, and that is indeed what he's done.
You should read about the pseudorandom number generators used ubiquitously in the 1970s and 1980s, for example. Or the Patriot missile bug. The second one cost lives and really, it was kind of obvious.
So: no, impoliteness is useless, unhelpful and a waate of time. Humor is difficult (just pouring a list of swear words and admiration marks is not funny).
We all have bad days and Mike is not an exception.
Hence: thanks for the bug report, keep your (meaning the OP's) shit to yourself.
I may use a product that, like all products in the history of mankind, has flaws, because it has apparently done its job so well that those threatened by its success have been reduced to gibbering idiots.
Admittedly, the latter does seem more logical, since he explicitly chose to register under a false name as he clearly knew his report was unacceptable, but I usually choose to assume people are not simply evil, malicious animals.
But if you'd like me to assume he is a Reddit troll, fine. The bug should be closed as presumed invalid and someone who isn't evil should re-file in a manner appropriate to civilized society.
At the same time, MongoDB is a free, OSS solution. While it's true it's marketed way above reality, you both don't have to pay for it (beyond support) and can contribute to it if something doesn't work as you wish it did.
This tone is not acceptable in a formal bug report. It's fine to pour out your frustration in this tone to your coworkers over a pint of beer, but it is not fine to go and yell it at someones face in a formal environment.
Everyone has wasted hours and hours in a frustrating debugging spree, we all know that feeling. Get over it and be a professional, report the bug, fix it and shut up.
Anyone who thinks that publicly attacking an individual at this level is in any way acceptable should work hard at being more empathic. No long hours of working justify this.
YAWN. Or people could just get thicker skin so we can actually have fun? This is just banter.
Yes, ridiculing others has been fun for adults for several millennia.
And ridiculing others that deserve it has also been a kind of justice.
Fixed that for you :)
And slightly hypocritical -- seeing as your snarky comment was meant to ridicule mine.
As to the hypocrisy, I consider myself an adult, and did not appreciate you speaking for all of us, so it was meant as a correction, not ridicule.
Well, as an adult you probably have heard of "figures of speech" and "generalisations".
I know some people have a difficulty with the mechanics of casual conversation, but a phrase like "ridiculing others has been fun for adults for several millennia" does not mean it necessarily applies to ALL adults.
Just most of them.
The author has a strong point that quality of the development process for mongodb must not be good if a bug like this one gets into production, when it could be avoided using automated tools. This won't be such a fault for a random open source project, but if you are making a business out of it, and you are encouraging others to base use it as a key part of their business it do is a great problem.
I always describe programming as incredibly easy, except for the part when things don't work as they're supposed to work. Very often you eventually find this is outside of your control. You have to be more calm and patient than the bug.
He's not going to win any friends or help acting like a pompous ass who's never made a mistake in his life. Maybe he hasn't because this is his first real project.
Or am I missing something important?
Beyond that, it's an undefined pointer dereference - who knows what this could be use for in certain combinations and systems. Use a "not so critical" bug in that subsystem, a "not so critical" mistake over there, another "somewhat severe" error over there and you got a root shell going. It's simply disconcerning and annoying if you consider that static checkers could have caught it.
EDIT: That's not to say it's professional. It is amusing to read though.
Let's just shame IF his list of non-pristine commits are marketed to high heavens, deployed worldwide, still exist in a 3+ year old codebase AND are as basic as those.
(This picture is funny but very accurate: If you can review code without swear words, your soul just isn't into it)
The fact that MongoDB has in itself a vulnerability to unchecked input is not great. But consider that if you are dealing with client side browser or server side software, the entire stack is rife with security vulnerabilities because the components themselves right down to TCP/IP are inherently insecure.
Be careful out there, and write nicer bug reports. Use the process. If you were on the other end of that bug report, you would feel differently.
Doing that will almost certainly get you thrown behind bars.
"Nobody expects the Inquisition"