4 ms·
> You must must understand every line of code yourself. I have never seen this standard reached for any real codebase of any size. Even in projects with a rep
by derf_ 1y ago
> You must must understand every line of code yourself.
I have never seen this standard reached for any real codebase of any size.
Even in projects with a reputation for a strong review culture, people know who the "easy" reviewers are and target them for the dicey stuff (they are often the most overloaded... which only causes them to get more overloaded). I've seen people explicitly state they are just "rubber stamping" PRs. Literally no one reviews every line of third-party dependencies, and especially not when they are updated routinely. I've seen over a million lines of security-sensitive third-party code integrated and pushed out to hundreds of millions of users by a handful of developers in a matter of months. I've seen developers write their new green-field code as a third-party library to circumvent the review process that would have been applied if it had been developed as a series of first-party PRs. None of that had anything to do with AI. It all predated AI coding tools. That is how humans behave.
Does this create ticking time-bombs? It absolutely does. You do the best you can. You triage and deal with the most important things according to your best judgment, and circle back to the rest as time and attention allow. If your judgment is good, it's mostly okay. Some day it might not be. But I do not think that you can argue that the optimal level of risk is zero, outside of a few specialized contexts like space shuttles and nuclear reactors.
I know. It hurts my soul, too. But reality isn't pretty, and worse is better.
- jaredcwhite 1y agoI think the "you" in the quote is referring to the programmer of the PR, not the reviewer. I agree that it's probably unrealistic to expect reviewers to understand every line of code in a PR. That's why it's crucial that the programmers of said PRs themselves understand every line of code. I'll go one step further: If you submit a PR and you yourself can not personally vouch for every line of code as a professional…then you are not a professional. You are a hack. That is why these code generation tools are so dangerous. Sure, it's theoretically possible that a programmer can rely on them for offering suggestions of new code and then "write" that code for a PR such that full human understanding is maintained and true craft is preserved. The reality is, that's not what's happening. At all. And it's a full-blown crisis.