Re: CVS Account Request

From: Date: Thu, 16 Nov 2000 00:22:52 +0000
Subject: Re: CVS Account Request
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-38279@lists.php.net to get a copy of this message
Zeev Suraski wrote: > > At 01:27 16/11/2000, Jim Jagielski wrote: > >Generally, we are talking mostly about a QA process. Can we maintain > >QA control over PHP with the current setup? I'm not qualified > >to answer that, but in a netshell that's the deal. > > I think that the kind of QA we're trying to develop for PHP is > functional-level, and not source level. It's not going to address the > security concerns involved in giving people CVS write access very quickly. > Source-level code is the core of QA. If you can't control or monitor the quality of the code coming in, then you can't monitor or control the quality of the final product. Security concerns in the code, or in patches applied to the code, is most definately a QA process. One way of ensuring this is a review-then-commit process, where a patch is submitted, reviewed and if approved commited. Well, maybe not "ensuring" it because it depends on how well it's "reviewed" and even when reviewed, interactions happen that cause problems. But it *does* increase the overall QA process. Also saying "just you 5 guys have commit access" does it as well. Not everyone who submits a patch needs CVS commit. :) CVS implies trust of the committer and responsibility of others to look over the patch. -- =========================================================================== Jim Jagielski [|] jim@jaguNET.com [|] http://www.jaguNET.com/ "Are you suggesting coconuts migrate??"

« previous php.dev (#38279) next »