Comment by thin_carapace
17 hours ago
I get the feeling that the bugs found in this instance can be more directly attributed to the author having zero experience operating a microcontroller
17 hours ago
I get the feeling that the bugs found in this instance can be more directly attributed to the author having zero experience operating a microcontroller
Honestly, I'm going to be a bit harsher: I think they're either:
1. A novice who doesn't know how to debug issues.
2. Totally incompetent and copying code from Stack Overflow.
I don't think it's specific to microcontrollers, either, the error from the C compiler is something that a competent programmer would be able to interpret, or at least see it as a signal to get someone more experienced in the domain to learn about.
> the error from the C compiler is something that a competent programmer would be able to interpret,
contrary to the post, this was almost certainly not an issue of compilers throwing errors.
Reduced familarity with C could have played a role, but given the number of C experts that looked at this knowing there was an error and still misidentified the cause I don't think we need to reach for that powerful an explanation.
Confusion of definedness vs value check would make for a fine underhanded C entry. The flaw was not particularly clear from the source... and most common QA procedures could not distinguish a PRNG from TRNG once the error happened.
Fair point: I was using the information in the article to form my opinion. I still think that, if the developer in question ignored a compiler error as described, that’s a serious competence issue. It’s harder to spot after the fact because any reviewers wouldn’t have had a chance to see the compiler output.
The article makes the fair point of the size of the change and the complete lack of information in the commit message, which should have set off alarm bells…