* [qemu-web PATCH] contribute: define clear limits on bug report volume
@ 2026-09-24 13:56 Daniel P. Berrangé
2026-09-24 15:12 ` Alex Bennée
` (3 more replies)
0 siblings, 4 replies; 10+ messages in thread
From: Daniel P. Berrangé @ 2026-09-24 13:56 UTC (permalink / raw)
To: qemu-devel
Cc: Alex Bennée, Paolo Bonzini, Thomas Huth,
Daniel P. Berrangé
Recently QEMU has received a denial of service attack on
its bug tracker in the form of 120 reports in 10 minutes,
and now repeated by another reporter in the form of 50
reports in the same day.
Prior to switching security disclosures to the bug tracker,
single reporters have submited 18, 22, and 114 bug reports.
None of this is sustainable. It is an effective denial of
service attack on the project maintainers' time. Every bug
report is a TODO item added to someone's workload.
It is time to put hard limits on how many bugs, discovered
with assitance of automated tools, we are willing to accept
in a givenm time frame.
This patch proposal suggests
* No more than 5 bugs per week, per reporter
* No more than 10 bugs are permitted to be open at any
time, per reporter.
This is explicitly scoped to bugs discovered with the assistance
of automated tools. Bugs where a human puts in exclusively
personal time / effort to discover a problem are not limited.
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
---
contribute/report-a-bug.md | 37 +++++++++++++++++++++++++++++++++++++
1 file changed, 37 insertions(+)
diff --git a/contribute/report-a-bug.md b/contribute/report-a-bug.md
index b506f9f..8fb7b0b 100644
--- a/contribute/report-a-bug.md
+++ b/contribute/report-a-bug.md
@@ -32,6 +32,43 @@ on GitLab, taking into account the following guidance.
triage of their output to validate all findings and reproducer
scenarios prior to submitting a bug report.
+* QEMU policy forbids the bulk filing of large numbers of
+ bug disclosures that were generated with automated tools
+ (AI/LLM, static analysis, fuzers). Such actions are not
+ a benefit to the project, placing an unsustainable burden
+ on maintainers.
+
+ * **No more than 5 bug/security reports, discovered
+ with assistance of automated tools, are permitted
+ to be filed per week, per reporter.**
+ * **No more than 10 bug/security reports, discovered
+ with assistance of automated tools are permitted
+ to be open at any time, per reporter.**
+ * Reporters must refrain from filing any reports
+ that would cause these thresholds to be exceeded
+ without first obtaining explicit prior permission
+ from project maintainers.
+ * Reporters are **required** to respond to triage
+ comments from maintainers on bugs related to
+ automated tools on a timely basis.
+ * If at any time, the project maintainers request
+ the reporter to stop filing bug reports discovered
+ with assistance of automated tools, this must be
+ honoured.
+
+ Ignoring any of the above rules may lead to the bugs being
+ mass closed without further triage, even if valid reports.
+ In cases where the filing limits are grossly exceeded,
+ the reporter's GitLab account may be reported for abuse
+ (spam), potentially leading to termination.
+
+ If intending to file large numbers of bug disclosures
+ in aggregate, reporters are expected to invest their
+ time in writing patches, providing the patches for
+ review, and then further responding to feedback and
+ iterating on the patches until a maintainer accepts
+ them for it.
+
* Reproduce the problem directly with a QEMU command-line. Avoid
frontends and management stacks, to ensure that the bug is in
QEMU itself and not in a frontend and make it easier for
--
2.55.0
^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-09-24 13:56 [qemu-web PATCH] contribute: define clear limits on bug report volume Daniel P. Berrangé
@ 2026-09-24 15:12 ` Alex Bennée
2026-09-24 15:29 ` Daniel P. Berrangé
2026-09-25 7:51 ` Thomas Huth
` (2 subsequent siblings)
3 siblings, 1 reply; 10+ messages in thread
From: Alex Bennée @ 2026-09-24 15:12 UTC (permalink / raw)
To: Daniel P. Berrangé; +Cc: qemu-devel, Paolo Bonzini, Thomas Huth
Daniel P. Berrangé <berrange@redhat.com> writes:
> Recently QEMU has received a denial of service attack on
> its bug tracker in the form of 120 reports in 10 minutes,
> and now repeated by another reporter in the form of 50
> reports in the same day.
>
> Prior to switching security disclosures to the bug tracker,
> single reporters have submited 18, 22, and 114 bug reports.
>
> None of this is sustainable. It is an effective denial of
> service attack on the project maintainers' time. Every bug
> report is a TODO item added to someone's workload.
>
> It is time to put hard limits on how many bugs, discovered
> with assitance of automated tools, we are willing to accept
> in a givenm time frame.
>
> This patch proposal suggests
>
> * No more than 5 bugs per week, per reporter
> * No more than 10 bugs are permitted to be open at any
> time, per reporter.
>
> This is explicitly scoped to bugs discovered with the assistance
> of automated tools. Bugs where a human puts in exclusively
> personal time / effort to discover a problem are not limited.
>
> Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
> ---
> contribute/report-a-bug.md | 37 +++++++++++++++++++++++++++++++++++++
> 1 file changed, 37 insertions(+)
>
> diff --git a/contribute/report-a-bug.md b/contribute/report-a-bug.md
> index b506f9f..8fb7b0b 100644
> --- a/contribute/report-a-bug.md
> +++ b/contribute/report-a-bug.md
> @@ -32,6 +32,43 @@ on GitLab, taking into account the following guidance.
> triage of their output to validate all findings and reproducer
> scenarios prior to submitting a bug report.
>
> +* QEMU policy forbids the bulk filing of large numbers of
> + bug disclosures that were generated with automated tools
> + (AI/LLM, static analysis, fuzers). Such actions are not
> + a benefit to the project, placing an unsustainable burden
> + on maintainers.
> +
> + * **No more than 5 bug/security reports, discovered
> + with assistance of automated tools, are permitted
> + to be filed per week, per reporter.**
> + * **No more than 10 bug/security reports, discovered
> + with assistance of automated tools are permitted
> + to be open at any time, per reporter.**
> + * Reporters must refrain from filing any reports
> + that would cause these thresholds to be exceeded
> + without first obtaining explicit prior permission
> + from project maintainers.
> + * Reporters are **required** to respond to triage
> + comments from maintainers on bugs related to
> + automated tools on a timely basis.
> + * If at any time, the project maintainers request
> + the reporter to stop filing bug reports discovered
> + with assistance of automated tools, this must be
> + honoured.
> +
> + Ignoring any of the above rules may lead to the bugs being
> + mass closed without further triage, even if valid reports.
> + In cases where the filing limits are grossly exceeded,
> + the reporter's GitLab account may be reported for abuse
> + (spam), potentially leading to termination.
> +
> + If intending to file large numbers of bug disclosures
> + in aggregate, reporters are expected to invest their
> + time in writing patches, providing the patches for
> + review, and then further responding to feedback and
> + iterating on the patches until a maintainer accepts
> + them for it.
> +
> * Reproduce the problem directly with a QEMU command-line. Avoid
> frontends and management stacks, to ensure that the bug is in
> QEMU itself and not in a frontend and make it easier for
It comes across as quite a draconian limit but to be honest after a 6
months of dealing with this flood I'm less inclined to be polite about
it:
Reviewed-by: Alex Bennée <alex.bennee@linaro.org>
--
Alex Bennée
Virtualisation Tech Lead @ Linaro
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-09-24 15:12 ` Alex Bennée
@ 2026-09-24 15:29 ` Daniel P. Berrangé
2026-10-02 11:12 ` Markus Armbruster
0 siblings, 1 reply; 10+ messages in thread
From: Daniel P. Berrangé @ 2026-09-24 15:29 UTC (permalink / raw)
To: Alex Bennée; +Cc: qemu-devel, Paolo Bonzini, Thomas Huth
On Thu, Sep 24, 2026 at 04:12:02PM +0100, Alex Bennée wrote:
> Daniel P. Berrangé <berrange@redhat.com> writes:
>
> > Recently QEMU has received a denial of service attack on
> > its bug tracker in the form of 120 reports in 10 minutes,
> > and now repeated by another reporter in the form of 50
> > reports in the same day.
> >
> > Prior to switching security disclosures to the bug tracker,
> > single reporters have submited 18, 22, and 114 bug reports.
> >
> > None of this is sustainable. It is an effective denial of
> > service attack on the project maintainers' time. Every bug
> > report is a TODO item added to someone's workload.
> >
> > It is time to put hard limits on how many bugs, discovered
> > with assitance of automated tools, we are willing to accept
> > in a givenm time frame.
> >
> > This patch proposal suggests
> >
> > * No more than 5 bugs per week, per reporter
> > * No more than 10 bugs are permitted to be open at any
> > time, per reporter.
> >
> > This is explicitly scoped to bugs discovered with the assistance
> > of automated tools. Bugs where a human puts in exclusively
> > personal time / effort to discover a problem are not limited.
> >
> > Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
> > ---
> > contribute/report-a-bug.md | 37 +++++++++++++++++++++++++++++++++++++
> > 1 file changed, 37 insertions(+)
> >
> > diff --git a/contribute/report-a-bug.md b/contribute/report-a-bug.md
> > index b506f9f..8fb7b0b 100644
> > --- a/contribute/report-a-bug.md
> > +++ b/contribute/report-a-bug.md
> > @@ -32,6 +32,43 @@ on GitLab, taking into account the following guidance.
> > triage of their output to validate all findings and reproducer
> > scenarios prior to submitting a bug report.
> >
> > +* QEMU policy forbids the bulk filing of large numbers of
> > + bug disclosures that were generated with automated tools
> > + (AI/LLM, static analysis, fuzers). Such actions are not
> > + a benefit to the project, placing an unsustainable burden
> > + on maintainers.
> > +
> > + * **No more than 5 bug/security reports, discovered
> > + with assistance of automated tools, are permitted
> > + to be filed per week, per reporter.**
> > + * **No more than 10 bug/security reports, discovered
> > + with assistance of automated tools are permitted
> > + to be open at any time, per reporter.**
> > + * Reporters must refrain from filing any reports
> > + that would cause these thresholds to be exceeded
> > + without first obtaining explicit prior permission
> > + from project maintainers.
> > + * Reporters are **required** to respond to triage
> > + comments from maintainers on bugs related to
> > + automated tools on a timely basis.
> > + * If at any time, the project maintainers request
> > + the reporter to stop filing bug reports discovered
> > + with assistance of automated tools, this must be
> > + honoured.
> > +
> > + Ignoring any of the above rules may lead to the bugs being
> > + mass closed without further triage, even if valid reports.
> > + In cases where the filing limits are grossly exceeded,
> > + the reporter's GitLab account may be reported for abuse
> > + (spam), potentially leading to termination.
> > +
> > + If intending to file large numbers of bug disclosures
> > + in aggregate, reporters are expected to invest their
> > + time in writing patches, providing the patches for
> > + review, and then further responding to feedback and
> > + iterating on the patches until a maintainer accepts
> > + them for it.
> > +
> > * Reproduce the problem directly with a QEMU command-line. Avoid
> > frontends and management stacks, to ensure that the bug is in
> > QEMU itself and not in a frontend and make it easier for
>
> It comes across as quite a draconian limit but to be honest after a 6
> months of dealing with this flood I'm less inclined to be polite about
> it:
Yes it is draconian. Aside from the periodic "mass filing"
incidents, what prompted me is seeing the graph you produced
at:
https://www.qemu.org/screenshots/2026-09-culm-issues.svg
We see the increasing gap between open & closed bugs from
March, where we failed to keep up with the flow arriving
on qemu-security@nongnu.org
In July we bulk imported the mails to gitlab, and between
many maintainers we resolved alot over a month. After that
first month though, we reverted to the widening gap, at
the same rate we saw when triage was limited to just
qemu-security@nongnu.org
My reading of that is that even opening up triage to all
QEMU maintainers has not fixed our scaling problem. We
already burnt people out from dealing with these reports
from automated tools.
Ideally I would like reporters to put in more personal effort
beyond the initial bug filing. If they do that then bugs might
get through triage and patch review more effectively and get
closed quicker, allowing filing of more reports.
If reporters put in that more sustained patch curation effort
instead of fire-and-forget, then I expect they wouldn't have
time for filing so many bugs to begin with, making the limit
less of a problem.
Also if they're putting in greater effort, I'd be amenable to
granting them an exception to exceed the limits on bug filing.
IMHO any regular maintainers are implicitly exempt from the
limits given their ongoing beneficial work for the project.
IOW, the bug limit should be a problem primarily for people
working on a "file-and-forget" basis.
Still, I welcome suggestions for other ideas, or if we should
have different limits in some level ?
With regards,
Daniel
--
|: https://berrange.com ~~ https://hachyderm.io/@berrange :|
|: https://libvirt.org ~~ https://entangle-photo.org :|
|: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-09-24 13:56 [qemu-web PATCH] contribute: define clear limits on bug report volume Daniel P. Berrangé
2026-09-24 15:12 ` Alex Bennée
@ 2026-09-25 7:51 ` Thomas Huth
2026-09-25 16:08 ` Richard Henderson
2026-10-02 10:46 ` Markus Armbruster
2026-10-02 10:57 ` Mark Cave-Ayland
3 siblings, 1 reply; 10+ messages in thread
From: Thomas Huth @ 2026-09-25 7:51 UTC (permalink / raw)
To: Daniel P. Berrangé, qemu-devel; +Cc: Alex Bennée, Paolo Bonzini
On 24/09/2026 15.56, Daniel P. Berrangé wrote:
> Recently QEMU has received a denial of service attack on
> its bug tracker in the form of 120 reports in 10 minutes,
> and now repeated by another reporter in the form of 50
> reports in the same day.
>
> Prior to switching security disclosures to the bug tracker,
> single reporters have submited 18, 22, and 114 bug reports.
>
> None of this is sustainable. It is an effective denial of
> service attack on the project maintainers' time. Every bug
> report is a TODO item added to someone's workload.
>
> It is time to put hard limits on how many bugs, discovered
> with assitance of automated tools, we are willing to accept
> in a givenm time frame.
>
> This patch proposal suggests
>
> * No more than 5 bugs per week, per reporter
> * No more than 10 bugs are permitted to be open at any
> time, per reporter.
>
> This is explicitly scoped to bugs discovered with the assistance
> of automated tools. Bugs where a human puts in exclusively
> personal time / effort to discover a problem are not limited.
I think this is a good idea, thanks for writing it up!
> diff --git a/contribute/report-a-bug.md b/contribute/report-a-bug.md
> index b506f9f..8fb7b0b 100644
> --- a/contribute/report-a-bug.md
> +++ b/contribute/report-a-bug.md
> @@ -32,6 +32,43 @@ on GitLab, taking into account the following guidance.
> triage of their output to validate all findings and reproducer
> scenarios prior to submitting a bug report.
>
> +* QEMU policy forbids the bulk filing of large numbers of
> + bug disclosures that were generated with automated tools
> + (AI/LLM, static analysis, fuzers). Such actions are not
s/fuzers/fuzzers/ ?
If you agree, I can fix the typo and commit the patch, no need to respin.
Thomas
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-09-25 7:51 ` Thomas Huth
@ 2026-09-25 16:08 ` Richard Henderson
2026-09-30 8:57 ` Thomas Huth
0 siblings, 1 reply; 10+ messages in thread
From: Richard Henderson @ 2026-09-25 16:08 UTC (permalink / raw)
To: Thomas Huth, Daniel P. Berrangé, qemu-devel
Cc: Alex Bennée, Paolo Bonzini
Good idea, Daniel. While you're fixing typos, Thomas:
On 9/25/26 00:51, Thomas Huth wrote:
> On 24/09/2026 15.56, Daniel P. Berrangé wrote:
>> Recently QEMU has received a denial of service attack on
>> its bug tracker in the form of 120 reports in 10 minutes,
>> and now repeated by another reporter in the form of 50
>> reports in the same day.
>>
>> Prior to switching security disclosures to the bug tracker,
>> single reporters have submited 18, 22, and 114 bug reports.
submitted.
>>
>> None of this is sustainable. It is an effective denial of
>> service attack on the project maintainers' time. Every bug
>> report is a TODO item added to someone's workload.
>>
>> It is time to put hard limits on how many bugs, discovered
>> with assitance of automated tools, we are willing to accept
assistance
>> in a givenm time frame.
given
r~
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-09-25 16:08 ` Richard Henderson
@ 2026-09-30 8:57 ` Thomas Huth
0 siblings, 0 replies; 10+ messages in thread
From: Thomas Huth @ 2026-09-30 8:57 UTC (permalink / raw)
To: Richard Henderson, Daniel P. Berrangé, qemu-devel
Cc: Alex Bennée, Paolo Bonzini
On 25/09/2026 18.08, Richard Henderson wrote:
> Good idea, Daniel. While you're fixing typos, Thomas:
>
> On 9/25/26 00:51, Thomas Huth wrote:
>> On 24/09/2026 15.56, Daniel P. Berrangé wrote:
>>> Recently QEMU has received a denial of service attack on
>>> its bug tracker in the form of 120 reports in 10 minutes,
>>> and now repeated by another reporter in the form of 50
>>> reports in the same day.
>>>
>>> Prior to switching security disclosures to the bug tracker,
>>> single reporters have submited 18, 22, and 114 bug reports.
>
> submitted.
>
>>>
>>> None of this is sustainable. It is an effective denial of
>>> service attack on the project maintainers' time. Every bug
>>> report is a TODO item added to someone's workload.
>>>
>>> It is time to put hard limits on how many bugs, discovered
>>> with assitance of automated tools, we are willing to accept
>
> assistance
>
>>> in a givenm time frame.
>
> given
Thanks, I've fixed the typos and pushed it to the repo now.
Thomas
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-09-24 13:56 [qemu-web PATCH] contribute: define clear limits on bug report volume Daniel P. Berrangé
2026-09-24 15:12 ` Alex Bennée
2026-09-25 7:51 ` Thomas Huth
@ 2026-10-02 10:46 ` Markus Armbruster
2026-10-02 10:57 ` Mark Cave-Ayland
3 siblings, 0 replies; 10+ messages in thread
From: Markus Armbruster @ 2026-10-02 10:46 UTC (permalink / raw)
To: Daniel P. Berrangé
Cc: qemu-devel, Alex Bennée, Paolo Bonzini, Thomas Huth
Daniel P. Berrangé <berrange@redhat.com> writes:
> Recently QEMU has received a denial of service attack on
> its bug tracker in the form of 120 reports in 10 minutes,
> and now repeated by another reporter in the form of 50
> reports in the same day.
>
> Prior to switching security disclosures to the bug tracker,
> single reporters have submited 18, 22, and 114 bug reports.
>
> None of this is sustainable. It is an effective denial of
> service attack on the project maintainers' time. Every bug
> report is a TODO item added to someone's workload.
>
> It is time to put hard limits on how many bugs, discovered
> with assitance of automated tools, we are willing to accept
> in a givenm time frame.
>
> This patch proposal suggests
>
> * No more than 5 bugs per week, per reporter
> * No more than 10 bugs are permitted to be open at any
> time, per reporter.
>
> This is explicitly scoped to bugs discovered with the assistance
> of automated tools. Bugs where a human puts in exclusively
> personal time / effort to discover a problem are not limited.
>
> Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
> ---
> contribute/report-a-bug.md | 37 +++++++++++++++++++++++++++++++++++++
> 1 file changed, 37 insertions(+)
>
> diff --git a/contribute/report-a-bug.md b/contribute/report-a-bug.md
> index b506f9f..8fb7b0b 100644
> --- a/contribute/report-a-bug.md
> +++ b/contribute/report-a-bug.md
> @@ -32,6 +32,43 @@ on GitLab, taking into account the following guidance.
> triage of their output to validate all findings and reproducer
> scenarios prior to submitting a bug report.
>
> +* QEMU policy forbids the bulk filing of large numbers of
> + bug disclosures that were generated with automated tools
> + (AI/LLM, static analysis, fuzers). Such actions are not
fuzzers
> + a benefit to the project, placing an unsustainable burden
> + on maintainers.
[...]
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-09-24 13:56 [qemu-web PATCH] contribute: define clear limits on bug report volume Daniel P. Berrangé
` (2 preceding siblings ...)
2026-10-02 10:46 ` Markus Armbruster
@ 2026-10-02 10:57 ` Mark Cave-Ayland
2026-10-02 11:20 ` Markus Armbruster
3 siblings, 1 reply; 10+ messages in thread
From: Mark Cave-Ayland @ 2026-10-02 10:57 UTC (permalink / raw)
To: Daniel P. Berrangé, qemu-devel
Cc: Alex Bennée, Paolo Bonzini, Thomas Huth
On 24/09/2026 14:56, Daniel P. Berrangé wrote:
> Recently QEMU has received a denial of service attack on
> its bug tracker in the form of 120 reports in 10 minutes,
> and now repeated by another reporter in the form of 50
> reports in the same day.
>
> Prior to switching security disclosures to the bug tracker,
> single reporters have submited 18, 22, and 114 bug reports.
submitted
> None of this is sustainable. It is an effective denial of
> service attack on the project maintainers' time. Every bug
> report is a TODO item added to someone's workload.
>
> It is time to put hard limits on how many bugs, discovered
> with assitance of automated tools, we are willing to accept
assistance
> in a givenm time frame.
given
> This patch proposal suggests
>
> * No more than 5 bugs per week, per reporter
> * No more than 10 bugs are permitted to be open at any
> time, per reporter.
>
> This is explicitly scoped to bugs discovered with the assistance
> of automated tools. Bugs where a human puts in exclusively
> personal time / effort to discover a problem are not limited.
>
> Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
> ---
> contribute/report-a-bug.md | 37 +++++++++++++++++++++++++++++++++++++
> 1 file changed, 37 insertions(+)
>
> diff --git a/contribute/report-a-bug.md b/contribute/report-a-bug.md
> index b506f9f..8fb7b0b 100644
> --- a/contribute/report-a-bug.md
> +++ b/contribute/report-a-bug.md
> @@ -32,6 +32,43 @@ on GitLab, taking into account the following guidance.
> triage of their output to validate all findings and reproducer
> scenarios prior to submitting a bug report.
>
> +* QEMU policy forbids the bulk filing of large numbers of
> + bug disclosures that were generated with automated tools
> + (AI/LLM, static analysis, fuzers). Such actions are not
> + a benefit to the project, placing an unsustainable burden
> + on maintainers.
> +
> + * **No more than 5 bug/security reports, discovered
> + with assistance of automated tools, are permitted
> + to be filed per week, per reporter.**
> + * **No more than 10 bug/security reports, discovered
> + with assistance of automated tools are permitted
> + to be open at any time, per reporter.**
> + * Reporters must refrain from filing any reports
> + that would cause these thresholds to be exceeded
> + without first obtaining explicit prior permission
> + from project maintainers.
> + * Reporters are **required** to respond to triage
> + comments from maintainers on bugs related to
> + automated tools on a timely basis.
> + * If at any time, the project maintainers request
> + the reporter to stop filing bug reports discovered
> + with assistance of automated tools, this must be
> + honoured.
> +
> + Ignoring any of the above rules may lead to the bugs being
> + mass closed without further triage, even if valid reports.
> + In cases where the filing limits are grossly exceeded,
> + the reporter's GitLab account may be reported for abuse
> + (spam), potentially leading to termination.
Do we know if people are doing this purely for the recognition? Perhaps
we could suggest that if these rules are broken, all bug reports
submitted by the reporter will remain private (to reporters) on GitLab:
if a maintainer decides to fix a reported bug at their discretion, the
original reporter will not be credited in the commit message.
> + If intending to file large numbers of bug disclosures
> + in aggregate, reporters are expected to invest their
> + time in writing patches, providing the patches for
> + review, and then further responding to feedback and
> + iterating on the patches until a maintainer accepts
> + them for it.
> +
> * Reproduce the problem directly with a QEMU command-line. Avoid
> frontends and management stacks, to ensure that the bug is in
> QEMU itself and not in a frontend and make it easier for
ATB,
Mark.
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-09-24 15:29 ` Daniel P. Berrangé
@ 2026-10-02 11:12 ` Markus Armbruster
0 siblings, 0 replies; 10+ messages in thread
From: Markus Armbruster @ 2026-10-02 11:12 UTC (permalink / raw)
To: Daniel P. Berrangé
Cc: Alex Bennée, qemu-devel, Paolo Bonzini, Thomas Huth
Daniel P. Berrangé <berrange@redhat.com> writes:
> On Thu, Sep 24, 2026 at 04:12:02PM +0100, Alex Bennée wrote:
>> It comes across as quite a draconian limit but to be honest after a 6
>> months of dealing with this flood I'm less inclined to be polite about
>> it:
>
> Yes it is draconian. Aside from the periodic "mass filing"
> incidents, what prompted me is seeing the graph you produced
> at:
>
> https://www.qemu.org/screenshots/2026-09-culm-issues.svg
We're pulling the emergency brake. Minor injuries must be accepted in
order to avoid major ones.
I'm not sure the policy gets that across. "Not a benefit to the
project" and "place an unsustainable burden on maintainers" feel to me
like British understatement for "harm the project" and "threaten to
destroy the maintainer community".
> We see the increasing gap between open & closed bugs from
> March, where we failed to keep up with the flow arriving
> on qemu-security@nongnu.org
>
> In July we bulk imported the mails to gitlab, and between
> many maintainers we resolved alot over a month. After that
> first month though, we reverted to the widening gap, at
> the same rate we saw when triage was limited to just
> qemu-security@nongnu.org
>
> My reading of that is that even opening up triage to all
> QEMU maintainers has not fixed our scaling problem. We
> already burnt people out from dealing with these reports
> from automated tools.
>
> Ideally I would like reporters to put in more personal effort
> beyond the initial bug filing. If they do that then bugs might
> get through triage and patch review more effectively and get
> closed quicker, allowing filing of more reports.
>
> If reporters put in that more sustained patch curation effort
> instead of fire-and-forget, then I expect they wouldn't have
> time for filing so many bugs to begin with, making the limit
> less of a problem.
Wouldn't it be nice.
> Also if they're putting in greater effort, I'd be amenable to
> granting them an exception to exceed the limits on bug filing.
> IMHO any regular maintainers are implicitly exempt from the
> limits given their ongoing beneficial work for the project.
>
> IOW, the bug limit should be a problem primarily for people
> working on a "file-and-forget" basis.
>
>
> Still, I welcome suggestions for other ideas, or if we should
> have different limits in some level ?
Submitters submit when they expect the effort to be worth their while.
I call this friction. It helps deter low-value contributions. It's
more effective when it can be felt upfront.
AI has lowered upfront friction for bug submitters.
AI has not yet materially lowered the cost of triage, review, etc.
The policy change doesn't restore upfront friction, it merely gives us
license to ignore certain submitters who flood us.
Sadly, I don't have any bright ideas on how to restore friction.
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [qemu-web PATCH] contribute: define clear limits on bug report volume
2026-10-02 10:57 ` Mark Cave-Ayland
@ 2026-10-02 11:20 ` Markus Armbruster
0 siblings, 0 replies; 10+ messages in thread
From: Markus Armbruster @ 2026-10-02 11:20 UTC (permalink / raw)
To: Mark Cave-Ayland
Cc: Daniel P. Berrangé, qemu-devel, Alex Bennée,
Paolo Bonzini, Thomas Huth
Mark Cave-Ayland <mark.caveayland@nutanix.com> writes:
> On 24/09/2026 14:56, Daniel P. Berrangé wrote:
[...]
>> + Ignoring any of the above rules may lead to the bugs being
>> + mass closed without further triage, even if valid reports.
>> + In cases where the filing limits are grossly exceeded,
>> + the reporter's GitLab account may be reported for abuse
>> + (spam), potentially leading to termination.
>
> Do we know if people are doing this purely for the recognition? Perhaps we could suggest that if these rules are broken, all bug reports submitted by the reporter will remain private (to reporters) on GitLab: if a maintainer decides to fix a reported bug at their discretion, the original reporter will not be credited in the commit message.
Reducing the reward might be a possible partial replacement for
friction.
However, to not give credit for a bug we first need to fix the bug.
This has turned out to be pretty much infeasible in the cases covered by
the proposed policy.
[...]
^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2026-10-02 11:21 UTC | newest]
Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-24 13:56 [qemu-web PATCH] contribute: define clear limits on bug report volume Daniel P. Berrangé
2026-09-24 15:12 ` Alex Bennée
2026-09-24 15:29 ` Daniel P. Berrangé
2026-10-02 11:12 ` Markus Armbruster
2026-09-25 7:51 ` Thomas Huth
2026-09-25 16:08 ` Richard Henderson
2026-09-30 8:57 ` Thomas Huth
2026-10-02 10:46 ` Markus Armbruster
2026-10-02 10:57 ` Mark Cave-Ayland
2026-10-02 11:20 ` Markus Armbruster
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.