35 ms·
GCC: The customer has nuclear weapons. They do not do “bounty”
- slackfan 5y agoMost organizations with nuclear weapons most certainly do pay bounties. Generally for foreign intelligence, but I believe it applies. https://www.forbes.com/sites/adamandrzejewski/2021/11/18/fbi-and-other-agencies-paid-informants-548-million-in-recent-years-with-many-committing-authorized-crimes/ https://www.forbes.com/sites/adamandrzejewski/2021/11/18/fbi...
- petertodd 5y agoI think in this case that comment was just a funny way of saying both "this is actually for the well known USA nuclear weapons program, which everyone knows uses Crays" as well as "I couldn't get anyone to approve a bounty"
- boulos 5y agoAs was the joking response about not discussing IEEE implementations due to their ops sec :).
- gowld 5y agoOh, I didn't understand what that was getting at, beyond the generael idea of trolling the misbehaving requester, but which I thought cored devs don't do in their own bug tracker. > Hi Bill, per our operational security procedure we can't talk about ieee_arithmetic, especially when we dont get paid.
- pydry 5y agoStill about 100x more alarming than funny.
- hughrr 5y agoI worked for a large defence contractor and getting approval for anyone to pay for that would have been more difficult than actually learning how to fix it myself and fixing it myself. At which point I would never be allowed to contribute the fix back to the original project due to the no code export policy and airgapped network. I could of course have done a clean room patch at home based on my retained knowledge but quite frankly I probably couldn’t be assed with it by the time I’d got home and eaten dinner due to the depression of working in such a horrible place. That’s the reality of working for such folk.
- dhosek 5y agoI'm so glad that I never did that work when it was a possibility.
- dathinab 5y agoI wonder if they couldn't "just" put up a misc. software support money pool with a reasonable but in the huge picture small amount of money they can "low complexity" spend on such things?
- hughrr 5y agoConsidering it took three tiers of management and three facilities department members to replace a coffee machine that had an actual service contract in place already, I think something of that administrative complexity would have been beyond them. Either that or like most SMEs I’ve worked for they’re actually only using the stuff because it’s “free” by their corrupted definition of “free” which is basically it didn’t have to go through a PO process.
- deleted 5y ago[deleted]
- bluGill 5y agoI got around that one place by just writing up a bug report and a it seems like line x of file... this wasn't government and so they wouldn't have cared anyway so i just avoided figuring out the paperwork to contribute.
- miles 5y ago> The customer has nuclear weapons. They do not do "bounty". :) Not only is this not funny, it would likely have the unfortunate effect of turning off any of the "very, very, very, few individuals"[0] who might be able to help. The fact that the issue apparently remains open after a year and a half seems to attest to that. [0] https://gcc.gnu.org/bugzilla/show_bug.cgi?id=95644#c8 https://gcc.gnu.org/bugzilla/show_bug.cgi?id=95644#c8
- akersten 5y agoYeah, that sort of entitlement would throw this issue at the bottom of the priority queue for me. They're lucky they even got a nice workaround kludge posted in the thread. Knowing that probably 3 layers of government contractors are being paid fat stacks to accomplish the task of posting breathless "bump, wen fix?" on the maintainer mailing list is salt in the wound. I would have closed the issue right then and there as a wontfix, personally. We shouldn't enable those sort of attitudes towards volunteers.
- neltnerb 5y agoDefinitely nauseating that "Bill Long" probably gets paid $450 an hour for their time but can't manage to just write the patch themselves or find one of the thousands of programmers in their org to deal with it and submit a fix.
- vanusa 5y agoI don't see how one can not find it funny. Then again, I've never particularly desired to work for that line of "customer".
- kortex 5y agoIt's funny in the abstract. It's not so funny when the implication/connotation is to light a fire under the ass of FOSS maintainers. That's how I read it at least.
- 5y ago
- qzw 5y agoIf the customer has nuclear weapons, then the customer has magnitudes more money in their couch cushions than would be required to pay to have this functionality implemented. For that matter, they’re probably paying Bill Long’s employer some significant chunk of change, and it would be easy for them to offer to pay for this functionality. But it’s free/oss software, so let’s just keep bugging the maintainers instead.
- drjasonharrison 5y agoI think Bill Long needs to be added to https://en.wikipedia.org/wiki/Bill_Long https://en.wikipedia.org/wiki/Bill_Long Done.
- layer8 5y agoAnd already undone due to https://en.wikipedia.org/wiki/Wikipedia:Manual_of_Style/Disambiguation_pages#Red_links https://en.wikipedia.org/wiki/Wikipedia:Manual_of_Style/Disa... .
- 8bitsrule 5y agoUseful info can be added to disambiguation pages without any links "if doing so will be more helpful to readers..." (See "ignore all rules".) In this case, that info probably wasn't useful ;-|
- rat9988 5y agoWhy would you do such a lowly thing?
- ridethebike 5y agoIn practice it's also very likely that customer mind boggling amount of bureaucracy, allocating extra penny might require approval from several committees.
- hn_throwaway_99 5y ago
- deleted 5y ago[deleted]
- cozzyd 5y agoI suppose threatening to strike GCC developers with nukes might be more effective than bounties, but it also seems like a lot more expensive to carry out.
- rurban 5y agoNot GCC, just gfortran. No support for f2018 yet. GCC itself also doesn't have full support for c11 yet. Which was 7 years earlier. So they seem to have other priorities than fulfilling standards
- cozzyd 5y agoSure, but gfortran is part of the GNU Compiler Collection :) And I think there is C11 support other than optional parts? https://gcc.gnu.org/wiki/C11Status https://gcc.gnu.org/wiki/C11Status
- turminal 5y ago> GCC itself also doesn't have full support for c11 yet. Neither do other, much better funded compilers, to be fair.
- rurban 5y agomsvc and embarcadero do, imho. clang and icc not.
- Someone 5y agoAre there much better funded compilers? I don’t think we know much about how much funding the various compilers get. Apple/Intel/Microsoft may have lots of money, but that doesn’t mean their C compiler teams get much funding. I hear people say Apple’s work on clang is limited to their needs, and those may not involve getting full C11 support. Microsoft also may not need full C11 support for their internal use. That can make getting that a low or zero priority task. Intel recently moved their backend to LLVM. That doesn’t give me confidence they’re investing heavily there. Now, gcc technically is volunteer work, but lots of development is done by people paid to do that by their employers.
- zozbot234 5y agoClearly, GCC needs a new GPL licensing exception: "You acknowledge that the Program is not designed or intended for use in the design, construction, operation or maintenance of any nuclear facility." If Java does it...
- Jach 5y agoSeems useless given the existing clauses with the disclaimer of warranty and limitation of liability.
- iso1631 5y agoWhy? GPL is a license to permit you to modify and distribute the source code which is normally illegal under copyright law. Nothing more, nothing less.
- st_goliath 5y ago> Nothing more, nothing less. Well actually, 2 more things: distribute the modifications as well, and to use it without restrictions (Well that, plus making sure anybody who gets a copy gets the same rights). The latter of the two points happens to be the retroactively added freedom #0 in the FSF's definition of free software[0], which is also repeated in the GPL license text, IIRC somewhere at the top. The Open Source Definition used by the OSI has clauses to a similar effect (See points 5 and 6)[1]. GP's suggestion, adding restrictions on how the software could be used, would run counter to that, conflicting with the very philosophy from which the GPL originates. Bruce Perens, who originally wrote the Debian Free Software Guidelines[4] (the OSI OSD is based on that), also commented on that in 2019, when the idea to put forward to add ethics based usage restrictions to software licenses[2][3]. [0] https://www.gnu.org/philosophy/free-sw.en.html https://www.gnu.org/philosophy/free-sw.en.html [1] https://opensource.org/osd https://opensource.org/osd [2] https://perens.com/2019/09/23/sorry-ms-ehmke-the-hippocratic-license-cant-work/ https://perens.com/2019/09/23/sorry-ms-ehmke-the-hippocratic... [3] https://perens.com/2019/10/12/invasion-of-the-ethical-licenses/ https://perens.com/2019/10/12/invasion-of-the-ethical-licens... [4] https://en.wikipedia.org/wiki/Debian_Free_Software_Guidelines https://en.wikipedia.org/wiki/Debian_Free_Software_Guideline...
- dragonwriter 5y agoCray/HPE, presumably, has a contract to provide support to the customer with nuclear weapons. If this fix is necessary to that contract, Cray/HPE should set the bounty needed to get it done as part of the necessary cost of fulfilling their contract (if they didn't figure it in, and it's not a cost-plus contract, and it cuts into the profit margin, well, that's the risk you take with fixed-cost contracting.) Free Software may often tend to be free-as-in-beer as well as free-as-in-speech but, where it is, that is as is. If you have special, and especially time-sensitive, needs that aren't as is, you pay someone to do it. It's not a gratis support contract with response time guarantees. As Cray/HPE ought to be well aware, that kind of support is expensive, and doesn't happen if no one is paying.
- pjmlp 5y agoFully agree with you.
- hitekker 5y agoYeah, I thought Bill Long from Cray was joking at first. But his follow-up messages are plain passive aggressive > Inquiry from the original site: "Does GCC provide a timeline for when they will conform to F2018?"
- okl 5y agoChoosing beggar mentality. I hate it.
- myrandomcomment 5y agoThis is a bit tongue and cheek as sharing just that random bit of information on a true SCI program about the customer would cause “issues”. The customer is obviously DoD/DoE, however bug did not come from the SCI side. If Cray/HPE is the contractor to the customer in supporting this system and the software being used then it is their issue write the fix or pay for a bounty to fix it WITHOUT reveling the customer. Even as a joke as the customer I would be upset. Any large tech vendor likely has some dealing with certain government agencies. It has been my experience that those customers are NEVER referred to by name in any communications by the vendor and always given generic names like “customer blue”. You may see a bug tagged as customer blue in your bug db, but you did not know what agency that mapped to.
- iso1631 5y agoSounds like Cray are dealing with North Korea to me
- gjvc 5y agopsst... "tongue in cheek"
- myrandomcomment 5y agoAck.
- slt2021 5y agoBill Long has disclosed a specific supply chain vector to attack nuclear operations site.
- baybal2 5y agoThe first thing I thought of in this context was that GCC meant "Gulf Cooperation Council"
- sanguy 5y agoYou would be shocked at how much "military critical" software is built on OSS tools, libraries, and code bases. More shocking are the primary contractors charge top rates, contribute little to OSS, and try to hide the OSS usage from the end client.
- derefr 5y agoYou'd in turn perhaps be shocked at how much OSS software originates in militaries. Especially in the software security / cryptography space — if a crypto algorithm isn't literally designed by some military, it's often designed by some mathematicians who were contracted by a military to come up with an algorithm with some particular nice set of properties, who then (probably much later) reused their paid learning to create another algorithm with similar nice properties for public use, but different enough that it doesn't "give anything away" cryptanalytically about its confidential progenitor algorithm. "Opened" projects like Tor or Ghidra aren't at-all uncommon, either. The unusual part with those projects is that we know where they came from; usually such things are thoroughly scrubbed of their origins and handed over to a maintainer with a public identity, who is to claim that they created it themselves.
- rackjack 5y agoCan you name some projects that have been scrubbed and handed over?
- derefr 5y agoThat would rather put to waste the effort of scrubbing them, no? A lot of the reason for the scrubbing isn't confidentiality of authorship per se (though obviously that's important), but rather optics. If people see a FOSS project described as being e.g. "created by the NSA", they'll get skeeved out of using it or contributing to it, even if the NSA is no longer involved (or is only involved in the sense that people who happen to work at the NSA contribute to the project as civilians, in their time off, without the goals of the NSA driving the contributions.) Most of these opened projects are just a result of people in the organizations seeing a genuinely-good project that was created as a byproduct of some project — probably by some contractors that were actually decent for a change — that nobody internally can get the resourcing to maintain any more, and so is going to be canned and replaced — and thinking they can advocate to give it a new life as a civilian asset. People thinking of the public good, basically. If revealing the origins of the work would void that benefit to the public good, they'll fastidiously avoid doing so.
- throwaway984393 5y agoThey should change bug priority to "low", add a label cheap-bastards, and go on with their day.
- deleted 5y ago[deleted]
- IshKebab 5y agoWhat a dick. "It's not fixed. When will it be fixed? I'm not paying." Ok screw you Bill.
- deleted 5y ago[deleted]
- PreddyMW 5y agoAirstrike confirmed.
- sgt101 5y ago£50k and I'll do it today!
- somehnguy 5y agoIn my opinion that should have been an instant close of the issue. If the customer has the type of money to have a nuclear weapons program then surely they have the money to pay for the software they're relying on. Or maybe since they're apparently paying Bill to handle the software - Bill should take issues he has into his own hands and fix it himself. Sheesh.
- marcodiego 5y agoThis makes me partially sad and even a bit furious. The costumer has nuclear weapons, why don't they pay developers then?
- scotty79 5y agoThey could pay with warheads if that's the only thing they have.
- mokus 5y agoThey have way more patience than I do. I’d have pointed out pretty quickly that this “customer” is not a customer of the gfortran team and is therefore irrelevant to the discussion.
- marcodiego 5y agoIn this case, developers are in the powerful position to say: "I don't care about your nuclear weapons, pay me or forget it."
- temikus 5y agoAs an OSS maintainer myself writing something like that on the bug tracker would make it less likely to be worked on as this indicates complete disregard for maintainer’s time and efforts. I know for a fact that I have at least one trillion and multiple billion-dollar companies using a piece of my (somewhat obscure) software. Somehow they’re always the ones asking for urgent fixes and never the ones contributing patches.
- heavyset_go 5y ago> I know for a fact that I have at least one trillion and multiple billion-dollar companies using a piece of my (somewhat obscure) software. Somehow they’re always the ones asking for urgent fixes and never the ones contributing patches. Release the fixes under the AGPL and offer them paid proprietary licenses to use them.
- frays 5y agoFascinating thread. Thanks HN.
- gaze 5y ago“Fuck you, pay me” is the only appropriate response.
- xyst 5y agoThis is open source software with access to the source code. Why not just submit a patch on your own? Just bill the customer with "nuclear weapons" for time spent contributing to OSS. Contractor gets paid. Client gets working software. OSS community gets a patch. Is it incompetence? Is it laziness? Is it bad management? Is it all of the above? Personally, I would love to get paid to work on OSS on behalf of X company. Much better than re-inventing the wheel, plus with the added benefit of learning something new.
- phkahler 5y agoMy guess is that Cray/HPE does not want to set a precedent where they actually PAY the developers. They want to cheaply "work with" the community to get things done.
- slt2021 5y agoThank you Bill Long, now everybody knows the place where to submit code patches to get them executed at the nuclear operations site
- modshatereality 5y agoLOL so fucking fix it, noobs with nukes...
- infogulch 5y ago> The customer has nuclear weapons. They do not do "bounty". :) > We do not do "fix your problems for free". In addition, the bounty for customers with nuclear weapons is automatically 10x the normal bounty. :) Is what they should have said.
- ralph84 5y agoI don't get it. In the OP he shows that the Cray compiler handles this feature. So why not just have the customer use that compiler? Yes there's a license fee but presumably someone from Cray can get a good price on the Cray compiler if they have a customer satisfaction issue.
- jfim 5y agoIt might be that to avoid compiler implementation specific issues, they test code against multiple compilers.
- jeroenhd 5y agoSo, gfortran is used to control nukes. Now I do wonder, how hard would it be for a foreign influence to sneak bugs into an almost-functional module providing the requested feature so that whatever control system gfortran operates faults or fails? It's not like Cray/HPE are looking deeply into the code, they're too cheap to pitch in any effort themselves, after all, and arithmetic bugs that only appear when calculating orbits or trajectories might just be hidden from most unit tests. Open source is great for a lot of things, but don't trust a bunch of randos from the internet to maintain your critical defence infrastructure.
- samus 5y agoCould also just be used for some regression tests. Like compiling and executing the testsuite with different compilers and verifying that there are no unexpected differences in performance and behavior:
- hbrav 5y agoIt's more likely that it's being used for fluid dynamics simulations. Lots of use for simulations when you can't test the weapon directly. And there's lot of legacy code written by a lot of legacy professors.
- JonChesterfield 5y agoThat's a stretch. Fortran used by group with nukes does not imply Fortran used to contol the nukes.
- deleted 5y ago[deleted]
- pyuser583 5y agoSorry I’m not seeing anything like what’s mentioned. Has the linked page changed?
- CRConrad 5y agoI saw it less than an hour ago, on Firefox Android. Perhaps you need to wait a second after your browser first opens the page, for it to fully load so it can scroll down to the comment anchor. Or just search manually for "nuclear".
- sfifs 5y agoDo major projects like GCC maintain a list of developers who are willing to take on paid consulting work with standard contracts to do things like this? The GCC devs could simply point to details page of such an arrangement of it exists as a way to speed up. "Bounty" may not work in corporate or government environments but consulting is fairly standard and if there's an easy path to enable this, corporate money will more easily flow.
- dlsa 5y agoI'd love to but Charles said we can't do it. Something about if they're a customer then they need to pay actual money.
- deterministic 5y agoThe answer from the GCC team should have been: “You obviously can afford to pay to get this fixed. So pay us.”
- Havoc 5y agoThe most charitable explanation here is that this is Bills first encounter with open source and uh humans
- hindsightbias 5y agoIf I were Bill, how big a number would I have to write on my personal checkbook to make this happen?
- deleted 5y ago[deleted]
- aahortwwy 5y agoGotta love the passive-aggressive sniping at someone politely asking for a timeline for when a fix will be made. Like, the answer is obviously just "without a bounty there is no timeline for a fix" but they can't just leave it at that...
- pylua 5y agoBills response is not professional at all. Maybe it was meant to be taken with humor; but this style of communication does not work in every case. Humility and humbleness would have been a better style here. Unfortunately this is how software developers are often treated.