[HN Gopher] Sonar is destroying my job and it's driving me to de...
       ___________________________________________________________________
        
       Sonar is destroying my job and it's driving me to despair
        
       Author : Crazyontap
       Score  : 78 points
       Date   : 2024-07-02 20:00 UTC (3 hours ago)
        
 (HTM) web link (community.sonarsource.com)
 (TXT) w3m dump (community.sonarsource.com)
        
       | dexwiz wrote:
       | No matter the industry, it sucks to have someone managing by
       | dashboard. In classic post modernism, the signifier replaces the
       | signified. If anything, it's a great signal to the employee that
       | it's time to start looking elsewhere.
        
         | shrimp_emoji wrote:
         | Are flies that evolve to look like bees to ward off predators
         | postmodern? It just seems like game theory.
        
           | dexwiz wrote:
           | No, that is convergent evolution. A more apt comparison would
           | be selection of secondary sexual traits that no longer
           | correspond to fitness.
           | 
           | https://en.wikipedia.org/wiki/Signified_and_signifier
        
         | jjmarr wrote:
         | I don't get why people hate on post-structuralism.
         | 
         | The process of reality getting abstracted to the point
         | abstractions stop being representative of reality is extremely
         | common in software engineering.
         | 
         | https://en.wikipedia.org/wiki/Hyperreality
         | 
         | A hyperreal workplace is one where representations of reality
         | take precedence over reality itself, and the reality of a
         | situation ceases to have meaning. i.e. One where people chase
         | metrics for the sake of metrics, instead of understanding that
         | issue count is supposed to reflect the underlying code quality,
         | and code quality should always take priority over the
         | representation.
         | 
         | The broader philosophical context is relevant because it shows
         | the broader cultural problem instead of assuming the issue is
         | limited to a single tool.
        
           | pdonis wrote:
           | _> I don 't get why people hate on post-structuralism._
           | 
           | Because, rather than recognize that overdoing abstractions is
           | a thing and reminding people that there is always reality out
           | there that won't bend to your wishes, post-modernism (which
           | is the term the GP used) tells people that there is no
           | reality out there, it's _all_ just human-created
           | abstractions, and anyone who tries to push back because
           | reality is just insufficiently post-modernist.
        
             | orwin wrote:
             | That's typically _not_ what post-modernism is, that's at
             | best a misunderstanding, but more likely a strawman.
             | 
             | The only point on which all post-modernists agree is a
             | refutation of meta-narratives (and to be explicit: "here is
             | no reality out there, it's all just human-created
             | abstractions" is a meta-narrative).
             | 
             | A very, very charitable interpretation is that you are
             | maybe conflating it with Frankfurt School of critical
             | theory, because it is also somewhat used/based on
             | psychoanalysis (sigh) (latest postmodernists use
             | psychoanalysis way less, also post-modernism isn't built on
             | it, contrary to critical theory). Postmodernism is mostly
             | post-marxism though, while critical theory is mostly neo-
             | marxist imho (also, i don't want to be too critical of
             | Frankfurt's school, i think most of their bad rep is caused
             | by bad vulgarization/pop-science, most critics i read don't
             | seems to understand why it's wrong either).
             | 
             | I do think that the reason most people conflate the two is
             | because of an idiotic canadian psychoanalyst who can't read
             | (or at least, can't understand what he read), who _clearly_
             | has no degree in literature or philosophy, and try to
             | appear smarter than he is. He invent citations of the
             | books, and sometime state that Derrida mean something when
             | Derrida hismself wrote the opposite. 8th grader would do
             | better and their reading comprehension assignment. He is
             | wrong. Read and think by yourself.
        
           | Spooky23 wrote:
           | You need to learn to game it. People care about this stuff
           | are usually stupid. When I led a large support organization I
           | had an SVP who really cared about open incident duration.
           | 
           | His pattern for giving a fuck was predictable. My strategy
           | was to hold certain tickets in an undead state (not impacting
           | the metric), then reopen them and close them, demonstrating a
           | metric improvement.
           | 
           | He got his improvement and big shot street cred, users
           | weren't impacted, and I didn't have to ruin support to try to
           | grind out small gains.
        
           | OJFord wrote:
           | Whenever I want to feel completely stupid, I just open a
           | Wikipedia page on some philosophical term/idea and go down a
           | rabbit hole of links that it's a concept in/argument
           | against/etc.
           | 
           | Just completely impenetrably baffling to me in a way that
           | other fields like chemistry or microbiology or physics or
           | whatever (despite also not being my own) aren't. Not that I
           | understand them, but they're _penetrable_ , I can read more
           | and more and form some kind of understanding.
           | 
           | Is it just me? I don't know what it is, can it really be as
           | simple as philosophy not being taught at school
           | (compulsorily, or young) so I don't have that kind of rough
           | overview of the landscape I do for other broad subjects? (I
           | did take _one_ course in  'contemporary philosophy' at
           | university, which I enjoyed, but we covered only what we
           | covered I suppose - I might be able to hold a (very) basic
           | conversation about Sartre or Wittgenstein, but that page on
           | post-structuralism.. no idea!)
        
             | _dain_ wrote:
             | you aren't stupid. philosophers forgot how to write clearly
             | sometime in the past century.
        
               | orwin wrote:
               | Most modern philosophers papers are 5 to 20 pages long
               | and are mostly understandable, more than a particle
               | physics abstract at least, you should try:
               | 
               | - https://cpb-
               | us-w2.wpmucdn.com/voices.uchicago.edu/dist/9/177... (it's
               | about rationality, it changed the way in manage my
               | emotions and made me question my consciousness, which in
               | the end made me stop alcohol)
               | 
               | - https://philpapers.org/archive/KAMCYB.pdf which made me
               | realize an intuition i had sonce reading the first book
               | (i think the writing is better and clearer, but it might
               | be because the author isn't USian/english and doesn't try
               | to much)
               | 
               | - https://link.springer.com/article/10.1007/s11229-018-02
               | 071-y (i noticed my access wasn't revoked, it's been 4
               | year since i've stopped working for an institution.
               | Hopefully you have an access too, else you might find it
               | on scihub)
        
             | roenxi wrote:
             | More than likely it is "just you", the page on post-
             | structuralism seems clear enough to me (as far as I can
             | tell, the post-structuralists are criticising structuralism
             | because they don't think the structures are sufficiently
             | powerful). What that means in detail is unclear -
             | understanding a position and thinking it is obviously silly
             | is a completely valid stance when dealing with
             | philosophers. Or just having no interest in the questions
             | philosophers often ask (for example, if structuralism seems
             | to be fundamentally invalid then bothering to take a post-
             | structuralist stance to criticise it it requires a certain
             | type of pedantic and argumentative mind). Or the easy
             | explanation which is misunderstanding [0].
             | 
             | I liked the Barthes example on the post-structuralist page
             | - if a text's author doesn't necessarily have the authority
             | to assert the meaning of a text, then the idea that they
             | text is necessarily part of some identifiable structure is
             | open to question. I assume that means that the same text
             | might fit into multiple contexts with different meanings
             | and trying to fit it with one static meaning based on its
             | initial context is doomed, and that suggests structuralist
             | critique is either insufficient or overly reductive.
             | 
             | [0] Although arguably all of philosophy is people
             | misunderstanding each other; otherwise it may as well be a
             | settled field.
        
       | Juliate wrote:
       | The root issue is the superior not having a clue. Sonar in this
       | case, is sadly enabling this type of superior to be even more
       | harmful, not to the developers only, but to the actual business
       | of the company.
       | 
       | And Sonar is far from being alone in this. JIRA is the most
       | glaring example I can think of. Growing companies implement
       | cargo-culted tools without understanding the needs and
       | requirements, and let themselves drift into templates or "best
       | practices" that are not relevant or beneficial to their own
       | operations as-is, resulting in a sum of frustrations, whose
       | impact on the work and the teams they acknowledge only way too
       | late.
       | 
       | The care you need to inject not only in your tools, but how they
       | are apprehended by both your customers and their primary users
       | (which may have very different, if not opposed, perspectives on
       | how/why to use it), from pricing, to documentation, to use-
       | cases...
       | 
       | This is especially very complex when your tool answers to a
       | regulation requirement, because it's very often received as a
       | constraining/oppressing "solution", rather than an enabling one:
       | it may be confortable to you as a seller, and confortable to your
       | customer, but it may also be a counter-sale point to your
       | (customer's) users that will impact future consideration when
       | they become purchasing agents themselves.
        
         | marcosdumay wrote:
         | Yes... but how often have you experienced a non-clueless
         | linter?
         | 
         | Some tools bias people into doing bad things. It's not exactly
         | the tools fault, and they may even have good uses (like Bash
         | linters), but tools guide people and it's good to remind people
         | not to follow.
        
         | icholy wrote:
         | We used to have a rule where you couldn't move issues
         | "backwards" in the workflow. Accidentally closed an issue?
         | Gotta create a new one.
        
       | wetpaws wrote:
       | We use sonar at work and this resonates so much with me.
        
       | zamalek wrote:
       | I'm not sure how much value sonar adds where I work (dotnet). It
       | enormously affects build times, and I've yet to experience a
       | single true positive in 2 years (apart from the code coverage
       | dashboard). The amount of MRR you can generate by vaguely being
       | related to mitigating vulnerabilities is incredible.
        
       | philipwhiuk wrote:
       | Sonarqube issues were the warning for the SOC-report powered
       | issue scanners that have arrived more recently.
        
       | Emigre_ wrote:
       | Sonar doesn't seem to really work in my limited experience. It
       | adds a lot of of time to builds, at least in the cases I've seen,
       | while there are alternate linters or code quality tools capable
       | of doing the same at a fraction of the time. Build times and
       | development speed matter!... They matter a lot. You need a quick
       | feedback loop.
        
         | ars wrote:
         | I use Sonar all the time, but not during build. It runs live
         | while I'm editing a file. I've not noticed any slowdown at all,
         | and it's certainly a quick feedback loop (it runs when I save
         | the file).
         | 
         | I've found the majority of its suggestions helpful, and the
         | ones that are not I simply ignore.
        
           | nsxwolf wrote:
           | It adds about 2 minutes to our gitlab pipelines but the major
           | issue with it is when organizations decide failures should
           | prevent merging code to master or even deploying to a QA
           | environment.
           | 
           | That's the real time sink - figuring out how to get past it.
           | It's a lot more than 2 minutes, sometimes even days if it's
           | something you can't work around and have to go through the
           | red tape if your team isn't empowered to take charge of your
           | own pipelines.
        
       | watwut wrote:
       | Isn't the actual issue here the superior managing the sonar being
       | a controlling jerk? Turning off the rules on sonar is easy,
       | technically. The issue is social.
        
         | kriiuuu wrote:
         | Yes. I would quickly look for a new job. A linter should help
         | the programmer along the way, but be easy to disable when it's
         | invalid.
        
       | elpocko wrote:
       | >SonarQube (formerly Sonar) is an open-source platform developed
       | by SonarSource for continuous inspection of code quality to
       | perform automatic reviews with static analysis of code to detect
       | bugs and code smells on 29 programming languages.
       | 
       | https://en.wikipedia.org/wiki/SonarQube
        
       | eigenvalue wrote:
       | This sounds truly hellish, like being controlled by a stupid
       | robot straight out of Kafka's "The Trial." They should allow
       | special one off exception that are documented with a comment,
       | similar to how you can disable Ruff warnings in python code for a
       | single like                 # noqa: F401
        
         | EricRiese wrote:
         | They do
         | 
         | // Nosonar
        
           | nsxwolf wrote:
           | Google "nosonar doesn't work" for a million war stories about
           | how this is not a solution.
        
           | jahlove wrote:
           | In my organization's sonarqube configuration (where of course
           | every flag is turned on), `// nosonar` actually shows up as a
           | code smell
        
       | jimbokun wrote:
       | > In my case, I have a superior who administers Sonar and is,
       | let's say, completely committed to it. For any 'exception
       | granted' we would have to book time with them days in advance
       | then white-board the reason why Sonar is wrong, or produce a
       | sample program - who has got time for that with tight deadlines?
       | 
       | This superior (sic) is what a negative productivity employee
       | looks like.
        
       | pacifika wrote:
       | Are the defaults emphatic to the engineer or to the ruleset?
        
       | nsxwolf wrote:
       | We frequently have the issue of, upon refactoring code in such a
       | way that involves moving it and its tests to a new file, Sonar
       | will take away our previous "credit" for code coverage
       | percentage, dropping our project below the threshold and failing.
       | 
       | The only workaround I've found is to create a new function, fill
       | it full of many useless no-op lines, and write a test for that
       | function, just to bump the percentages back up. This is often
       | harder than it sounds, because the linter will block many types
       | of useless no-op code. We then remove the code as part of another
       | ticket.
        
         | lesuorac wrote:
         | Heh, at one place I wrote some java code that would use
         | reflections to test the getter/setters in a POJO so that it
         | wouldn't end up with 0% code coverage.
        
       | icholy wrote:
       | At my work you can mark any issue with "won't fix". The issues
       | are right pretty often though.
        
       | dgan wrote:
       | Sonar tries hard to have an authority of a compiler, while having
       | the resources of a linter.
       | 
       | I am not saying it's snake oil, but honestly how i ve seen ut
       | being used, it's not that far
        
       | move-on-by wrote:
       | I sympathize with the OP. Having said that, I've rolled out
       | SonarCloud to two different companies and I would not hesitate to
       | roll it out to a third if given the opportunity.
       | 
       | Initially, people always come out of the woodwork insisting that
       | the gate requirements must be hard blockers and that we can just
       | hand wave away the issues OP listed by tweaking the project
       | rules. I always fight them, insisting that teams should be the
       | owners and to gain quick adoption it should just be considered as
       | another tool for PR reviewers. Eventually, people back off and
       | come to accept that Sonar can be really helpful, but at the end
       | of the day the developers should be trusted to make the right
       | call for the situation. It's not like we aren't still requiring
       | code reviews. I feel for OP, but it's not Sonar's fault the tool
       | is being used for evil instead of good.
       | 
       | This last time I implemented SonarCloud, I took an anonymous
       | survey to get peoples opinion. For the most part people liked the
       | feedback Sonar provided. More junior engineers and more senior
       | engineers liked it the most- midlevel engineers not so much. The
       | junior liked getting quick feedback prior to asking for code
       | reviews. The more senior engineers - who spend a lot of their
       | time doing PR reviews - liked that it handled more of the generic
       | stuff so that they could focus more on the business logic or
       | other aspects of the PR. It's just another tool in the toolbox.
        
       | sigotirandolas wrote:
       | I saw a case where Sonar analysis was being requested by a
       | government agency where software was built by consultants. From
       | the government agency's point of view it made some sense to
       | ensure that the code delivered by the consultants wasn't full-on
       | spaghetti.
       | 
       | However, I saw it causing similar turd polishing behaviour:
       | Sensible code needing to be changed because it exceeded some
       | obstinate metric, any kind of code movement causing existing
       | issues to appear as "new", false positives due to incomplete
       | language feature support, etc.
        
       | karussell wrote:
       | add (2023)?
        
       ___________________________________________________________________
       (page generated 2024-07-02 23:01 UTC)