On Fri, Nov 06, 2020 at 10:14:30AM +0100, Michał Górny wrote:
> On Fri, 2020-11-06 at 08:21 +0100, Agostino Sarubbo wrote:
> > Hello all,
> > 
> > 6 months have been passed after the CI system started to file bug reports.
> > ~ 4700 bugs have been submitted
> > 
> > We _know_ that atm is not possible to set a specific summary, instead a 
> > generic summary is used in case of compile failures and test failures.
> > There are also some documented limitations.
> 
> I do disagree with your presumption that this needs to be automated.
> The whole point behind providing a service is that you should be ready
> to dedicate *your* time into the service.  However, we keep feeling that
> you assume that your time is too precious, and it is better to waste
> a little bit of everybody else's time.  This is why Toralf's effort is
> much more appreciated.
>

ACK. This is the same level of coordination the security team received
when a multitude of bugs were filed once ago discovered fuzzing. It was
lots of bugs, little information, inabilities to reproduce various
crashes, invalid ratings/severity levels, and often a blog that
simply regurgitated the same inaccuracies. Any attempt to ask/coordinate
was met with lack of information or simply "see my blog" responses.

The only time interaction occured was when bugs were closed due to
invalidity, lack of information, or severity/ratings downgraded.

All this to say, I concur his actions seem to show that he believes his
time is more precious than others and that "numbers matter" when it
comes to opening bugs and CVE's.

> To summarize, what your tinderboxing effort lacks is really a human
> touch.  You seem to have set the goal to file as many bugs as possible
> automatically.  I disagree with that, as I would like this effort to
> focus on helping developers, not pursuing them.  This requires a human
> touch, not a machine lord.
>

This right here.

-- 
Cheers,
Aaron

Attachment: signature.asc
Description: PGP signature

Reply via email to