3 ms·
I agree. But I think you've flipped the original question, which presupposes "trust." Your formulation is "does code review eliminate the need for trust?" Which
by Cpoll 3y ago
I agree. But I think you've flipped the original question, which presupposes "trust." Your formulation is "does code review eliminate the need for trust?" Which is clearly a no, for the reasons you've outlined.
A 10000 LOC review isn't usually as bad as it sounds. Once you get some experience reviewing, it becomes easier to separate the critical areas from the boilerplate, and get a lot of value out of a 10min read-over. Most of the time spent on the review should be thinking about the implications of the code, not on passively reading it.
It's also helpful to think adversarially: "How can this code be broken?" This is much easier to do to someone else's code than to your own, because you haven't spent hours developing assumptions about it while writing it.
Sometimes the problem is that a patch does too many things at once. Those can be the most important to review.