public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Adrian Bunk <bunk@stusta.de>
To: Ben Chelf <ben@coverity.com>
Cc: linux-kernel@vger.kernel.org
Subject: Re: Coverity Open Source Defect Scan of Linux
Date: Mon, 6 Mar 2006 11:27:29 +0100	[thread overview]
Message-ID: <20060306102729.GD3974@stusta.de> (raw)
In-Reply-To: <440BCA0F.50501@coverity.com>

On Sun, Mar 05, 2006 at 09:35:11PM -0800, Ben Chelf wrote:

> Hello Linux Developers,


Hi Ben,


>   I'm the CTO of Coverity, Inc., a company that does static source code 
> analysis to look for defects in code. You may have heard of us or of our 
> technology from its days at Stanford (the "Stanford Checker"). The 
> reason I'm writing is because we have set up a framework internally to 
> continually scan open source projects and provide the results of our 
> analysis back to the developers of those projects. Linux is one of the 
> 32 projects currently scanned at:
> 
> http://scan.coverity.com
>...
>   Right now, we're guarding access to the actual defects that we report 
> for a couple of reasons: (1) We think that you, as developers of Linux, 
> should have the chance to look at the defects we find to patch them 
> before random other folks get to see what we found and (2) From a 
> support perspective, we want to make sure that we have the appropriate 
> time to engage with those who want to use the results to fix the code. 
> Because of this second point, I'd ask that if you are interested in 
> really digging into the results a bit further for your project, please 
> have a couple of core maintainers (or group nominated individuals) reach 
> out to me to request access. As this is a new process for us and still 
> involves a small number of packages, I want to make sure that I 
> personally can be involved with the activity that is generated from this 
> effort.
>...


It seems there is some internal communication problem inside your 
company:

This is far from being a "new process", you already offered this for 
some time at http://linuxbugsdb.coverity.com/ (with the exception that 
you stopped updating the results half a year ago).

If you as the CTO didn't know about this it is giving a very bad 
impression of your company.

Some questions regarding this move:
- can you migrate the accounts from linuxbugsdb.coverity.com?
- are the comments Linux kernel developers like me did at 
  linuxbugsdb.coverity.com migrated to scan.coverity.com or was this 
  wasted work?


Another thing you could give a small clarification about:
Your email sounds as if your offer was like a charity offer from 
Coverity, Inc.

OTOH, I remember press rumors of Coverity, Inc getting 297 000 Dollar 
for this from the Department of Homeland Security.

I'm sure you are not silently omitting that you are getting public 
fundings for what you are offering, but an official statement would be 
nice.

 
> -ben


cu
Adrian

-- 

       "Is there not promise of rain?" Ling Tan asked suddenly out
        of the darkness. There had been need of rain for many days.
       "Only a promise," Lao Er said.
                                       Pearl S. Buck - Dragon Seed


  parent reply	other threads:[~2006-03-06 10:27 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-03-06  5:35 Coverity Open Source Defect Scan of Linux Ben Chelf
2006-03-06  5:49 ` Dave Jones
2006-03-06 10:27 ` Adrian Bunk [this message]
2006-03-06 10:43   ` Bernd Petrovitsch
2006-03-06 11:03     ` Michal Schmidt
2006-03-06 11:08       ` Bernd Petrovitsch
2006-03-06 13:39         ` Ben Chelf
2006-03-06 11:57       ` Gene Heskett
2006-03-06 12:38         ` [OT] Linux washing powder (was: Re: Coverity Open Source Defect Scan of Linux) Michal Schmidt
2006-03-06 20:13           ` Gene Heskett
2006-03-06 13:07         ` Coverity Open Source Defect Scan of Linux Dick Streefland
2006-03-06 13:46   ` Ben Chelf
2006-03-06 15:46 ` Greg KH
2006-03-06 18:33 ` Pavel Machek
2006-03-06 18:53   ` Jesper Juhl
2006-03-14 12:37 ` Mauro Carvalho Chehab
2006-03-15  3:41 ` Lee Revell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20060306102729.GD3974@stusta.de \
    --to=bunk@stusta.de \
    --cc=ben@coverity.com \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox