5 ms·
They were asked to print their code and typically this is done as part of diligence _before_ closing. This is not sop. It’s Elon making a show of things.
by 8cmj7A 4y ago
They were asked to print their code and typically this is done as part of diligence _before_ closing. This is not sop. It’s Elon making a show of things.
- snotrockets 4y agoVery rarely does due diligence involves actual critique of code on paper. Or code reviews at all, for that matter. Edited: technical review isn’t code review.
- grogenaut 4y agoI've done 2 due diligence in the last 3 years. Both time I read a large part of the code base, and I read the code reviews of the engineers as well. Codebase to find issues with the code but also liabilities that we'd need to deal with. I read the code reviews to help level set for the engineers. I've done on paper reviews as well where it was just easier than getting access to the code repos. Sure it's like 50 lbs of paper but whatever. The nice thing with paper is you're basically sorting, you toss the interesting pages to one side and the uninteresting to the other. Both of these were 20 person companies so I could review the 200-500kloc codebases in around 8 hours. It's not the most fun day :)
- x86x87 4y agoYou need to write a book and/or explain how you can review 500kloc in 8 hours. That sounds ridiculous to me but I may be missing something
- resoluteteeth 4y ago> You need to write a book and/or explain how you can review 500kloc in 8 hours. That sounds ridiculous to me but I may be missing something I feel like what you could do in 8 hours would be less "reviewing" and more "starting to get a basic sense of the codebase in the way a new hire would" but when you're the new CEO of the company maybe saying that doesn't sound cool enough?
- deleted 4y ago[deleted]
- x86x87 4y agoIn 8 hours I would be surprised if you got more than a 10000 feet view. Also, there is deployment, ops, policy. To say you got everything you needed in 8 hours is disrespectful at best (even for way smaller code bases)
- grogenaut 4y agoWhat you're missing is that dilligence is NOT coming in as the new Super Senior Distinguished Principal Architect who's going to rebuild the whole system overnight. If I'm doing dilligence, I'm looking to see if there IS ops, deployment, etc. I'm checking the coverage of the IAC compared to the infra (can spot check in console and ioc). You can ask for an overview of metrics code and how thye monitor their infra (walk through a dashboard). Diligence is NOT being able to re-write the codebase, or even work in it. It's to make sure that what people are saying is happening, is there, is with high confidence, actually there. You're also looking for "oh shit". Such as no IAC, no tests, no monitoring.
- x86x87 4y agoThat's shifting the goalposts quite a bit. You're looking for process, you are also asking for pointers from the people working on the project. Throwing out numbers like 500kloc is completely unnecessary as you're not going to look at them unless in cases where you're spotchecking (and you won't know where to look without someone pointing it out to you)
- grogenaut 4y agoI don't feel I'm moving the goal posts. I'm relating what I did with numbers. Others may have assumed my goals. My goal was to reduce the risks that the acquiring company felt were the biggest. I did that in 8 hours. Then we focused on specific risks previously identified in the review. That usually took the form of asking the selling company to explain, not for me to read more code. Usually the answers clarify the concerns, or admit them.
- grogenaut 4y agoThis is an average rate. There are large parts of the code base that are configurations, mappings, or just glue code. Even if you're not familliar with the language you get a sense for it quickly, you can power through those at 10kloc or higher when you hit a run, you can also rule out directories quickly after you see an example. You can also ask the people you're reviewing "is this directory just all kube config? where's the security settings?". and go at a high rate for reviewing the code. When you get to interesting code you then slow way down, maybe 10loc / minute. Remember, for diligence, you're doing risk reduction, your job specifically is determine that there is in fact secret sauce, the product is there, not to understand it. In fact it's problematic if you 100% understand that secret sauce.
- x86x87 4y agoYeah no. I still don't see it. You claim "I could review the 200-500kloc codebases". I've worked on due diligence from both sides of the table in the past and this is not how it works.
- deleted 4y ago[deleted]
- TomBombadildoze 4y agoYou aren't missing anything. This guy is absolutely, completely, without rival or parallel, beyond compare, unquestionably supreme, the God-King, the Emperor, the One True Big Kahuna, and the Head Motherfucker In Charge of being Full Of Shit. If this guy were the biggest fish in the ocean, he'd be stuffed to the gills with it.
- collegeburner 4y agothis is literally not true. nost diligence has a technical component, esp in M&A (vs. early-stage)
- deleted 4y ago[deleted]
- mousetree 4y agoIn the DD's I have been part of there was always some element of code review.