Follow @Openwall on Twitter for new release announcements and other news
[<prev] [<thread-prev] [day] [month] [year] [list]
Message-ID: <87bjbma22v.fsf@gmail.com>
Date: Fri, 31 Jul 2026 21:37:12 -0700
From: Collin Funk <collin.funk1@...il.com>
To: oss-security@...ts.openwall.com
Cc: Alan Coopersmith <alan.coopersmith@...cle.com>
Subject: Re: 33 Vulnerabilities in cJSON

Peter Gutmann <pgut001@...auckland.ac.nz> writes:

> Collin Funk <collin.funk1@...il.com> writes:
>
>>Complaining about free software maintainers, who are presumably not funded by
>>the projects (some certainly being corporate) depending on it, while also
>>admitting that you had AI write part of the article for you (as in the author
>>of the post, not the email I am replying to) because you are too lazy is
>>certainly a choice.
>
> I assume you're new to this process so I'll explain: When someone submits bug
> reports to your project that help fix problems, the polite thing to do is to
> say "thanks for the time you've taken to help improve the project", not
> "FOAD", which tends to discourage future contributions.

Note that I am not a maintainer of cJSON, and have never interacted with
them. My understanding is that the maintainers have not been active, as
in they have not been writing commits or reviewing bugs/patches. I am
not sure why you think I would defend anyone saying "FOAD", which I am
not aware of them doing, and would certainly not defend if they did.
Perhaps the weird dreams you refer to are based on personal experience.

My criticism is that the author of this article seems to feel entitled
to fixes. But perhaps that is just my reading. I am referring
specifically to lines like:

    Memory-safety reports sit open and unanswered, and in a few cases
    the patch that would fix them is sitting right there in the same
    thread, unmerged.

Do we need government-mandated pagers for free software maintainers of
packages that are widely depended on, which get triggered every time a
memory-safety bug is reported to their project? That would allow them to
meet their SLAs (which they do not get paid for) to fix them!

Also, the comment "nobody is going to hand you a fixed version". This is
quite literally what the maintainers were doing before they went
inactive, which is perfectly fine and morally permissible for them to
do.

> For the record, if anyone wants to send me a bug report for my code I'll
> accept it whether you found it yourself, used an AI, or it came to you in a
> weird dream you had after a dodgy vindaloo.

Collin

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.