Stepping back from new code tasks...

Discussions about the development and maturation of the platform code (UXP).
Warning: may contain highly-technical topics.

Moderators: trava90, athenian200

User avatar
Moonchild
Project founder
Project founder
Posts: 39725
Joined: 2011-08-28, 17:27
Location: Sweden

Stepping back from new code tasks...

Post by Moonchild » 2026-05-31, 19:47

I don't really like to do this, but I'm wearing too many hats at the moment and with recent contributions I realised that I don't really get nearly as much done as I should with things ending up on the back-burner pretty much indefinitely. Not only does this mean slower progress than what we really need, but also catching myself making too many mistakes.

I'm going to have to re-evaluate where I spend my time so I'll be focusing on fewer things and stepping back from doing major code development.

Going forward, my main focuses will be:
  • Security bugs with every release cycle. This has become much more of an intense job with the massive increase of AI-involved reports leading to massive audits I have to work through.
  • Analysing crash reports and finding fixes for those crashes.
  • Code review (both existing/active code and pull requests).
  • Release engineering (website, build wrangling, packaging, language packs, ...).
  • B2B communication as project lead.
  • Server and services maintainer.
What I will not/no longer be focusing on, which I'm hoping others in the community will be helping out with:
  • New code/feature development. I'm taking a major step back here; I'll still be available for answering questions or giving feedback, of course (see also code review above).
  • Code cleanup tasks. These tend to not be very complex but time consuming. Even if you're not a programmer but are OK with getting familiar with our build system and general wrangling of source code, then you can help out.
  • Keeping an eye on forks/spinoffs/adjacent projects and possible code adoption from them (if you find something we can/should use, make a patch and/or pull request).
  • Web compatibility analysis/fixes/workarounds and potential webmaster/framework evangelism.
  • End-user general support questions of any kind. Y'all here on the forum have got this down pretty well, as a group :)
I may also be reducing general forum participation. If you need my feedback on something and I don't seem to have noticed a thread, feel free to nudge me about it in e.g. a PM.

This will hopefully allow me to be more focused and revisit some things that have gone very much stale (like Pale Moon Commander etc.) as time allows.
"Sales hates anything that can't be turned into a confident sentence." - anonymous warehouse worker
"Why debate someone you fundamentally don't trust?" - Dario Amodei
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
andyprough
Forum staff
Forum staff
Posts: 1672
Joined: 2020-05-31, 04:33

Re: Stepping back from new code tasks...

Post by andyprough » 2026-05-31, 22:25

Moonchild wrote:
2026-05-31, 19:47
End-user general support questions of any kind. Y'all here on the forum have got this down pretty well, as a group
This place could really use a couple of active moderators. There used to be one guy that would show up occasionally, is he still around? You've been filling that role for a long time, but basic moderation shouldn't be taking up your time. Other open source forums I'm on name some of the more reasonable and knowledgeable active forum members as moderators, and get them to tell the new users to post their troubleshooting info, or to tell people to stop yelling at each other, or lock threads that are going nowhere or whatnot. We have some responsible members like @moonbat and @back2themoon that already do some of that work of herding people along without having an official title.

User avatar
athenian200
Contributing developer
Contributing developer
Posts: 1940
Joined: 2018-10-28, 19:56
Location: Georgia

Re: Stepping back from new code tasks...

Post by athenian200 » 2026-06-01, 01:07

To be honest, I kind of suspected you were overwhelmed by security bugs... I noticed you pulling in a lot of stuff seemingly in a rush related to those, and also merging a lot of stuff in a rush from that eUXP fork... and it seemed like both times there were a lot of small regressions related to the stuff being taken on. I wasn't wanting to say anything since security isn't my area, but I was actually a bit nervous about how much code was going in at once... and I kind of worried I made it worse with that big Python 3 PR right before the flurry of security bugs started landing.

Out of the two things you won't be focusing on anymore, the two that are potentially the most worrying are web compatibility and new code, especially if this is permanent rather than something like a very long break. The other stuff... well, I understand, that's probably best left to the community.

Out of the things you are focusing on, the only two I think I could help with at some point potentially are analyzing crash reports and code review... granted, I don't know if I'm on your level exactly, but I think I could try doing some of that if it ever became needed.

Overall, it does seem like you and Basilisk-Dev are both setting boundaries when it comes to this project and circumscribing responsibilities, pulling back, etc, at basically the same time. I'd be lying if I said I wasn't worried about the implications for the future there, but I also can't really blame either of you for the decisions you're making.

It does seem to leave me as the only person at the moment in a position to do much as far as new code/feature development, but it's not like I haven't already shown an interest in that sort of thing.

I am admittedly hoping that more people in the community get Codex or Claude subscriptions and step up to help out with coding, now that the barrier to entry there has lowered. Then the existing coders who have experience would shift into more of a review role. No idea if this would work out well or not, but it seems like something needs to change.
"Linux makes everything difficult." -- Lyceus Anubite
"Linux is a cancer that attaches itself in an intellectual property sense to everything it touches. That's the way that the license works." -- Steve Ballmer
"We always overestimate the change that will occur in the next two years and underestimate the change that will occur in ten." -- Bill Gates

User avatar
Moonchild
Project founder
Project founder
Posts: 39725
Joined: 2011-08-28, 17:27
Location: Sweden

Re: Stepping back from new code tasks...

Post by Moonchild » 2026-06-01, 07:16

andyprough wrote:
2026-05-31, 22:25
This place could really use a couple of active moderators. There used to be one guy that would show up occasionally, is he still around? You've been filling that role for a long time, but basic moderation shouldn't be taking up your time.
It's not really taking up much of my time, but it's a good point.
The thing with assigning moderators is: I've seen way too often that people who become community moderators actually don't know how to handle the responsibility or aren't actually suited for that role (and actually cause more harm than good in the long run), so I'm very apprehensive about assigning moderators and careful whom I want to give that kind of influence. It takes a shepherd to herd the sheep and not many people are actually shepherds, able to handle both the stray bucking individual sheep and being able to guide larger herd movements in a gentle way. Especially these days when everyone has their opinion on their sleeves ready to shove into your face, it takes a lot of balancing between restraint and action to do it well.

If you're volunteering, though, I'll be happy to make you a global mod here.
athenian200 wrote:
2026-06-01, 01:07
To be honest, I kind of suspected you were overwhelmed by security bugs...
It's just been insanity. Even Dan Veditz of Mozilla called the inrush of sec bugs in the past months a "hellscape" in our communications. Not because sec was bad, but because so much was dumped on them (and by proxy, us), no doubt to cash in on those sweet bounties (often in the couple grand range per incident, if I understood correctly, at Mozilla) by letting an LLM comb through the code and find deviations from what it thinks are the "right" coding patterns to use.
athenian200 wrote:
2026-06-01, 01:07
I noticed you pulling in a lot of stuff seemingly in a rush related to those, and also merging a lot of stuff in a rush from that eUXP fork...
The sec bug code changes weren't rushed. That's just me working full steam for full days on end. I can't do that too often or for too much time without burnout, of course, but it's not overly hurried. The eUXP stuff was indeed rushed and I hated having to do that but I felt severely pressured in that case. Some things weren't exactly ready there and we'll just have to work on ironing out some creases over time.
athenian200 wrote:
2026-06-01, 01:07
Out of the two things you won't be focusing on anymore, the two that are potentially the most worrying are web compatibility and new code
Web Compatibility is more stepping back from the first line of support/analysis/mitigation. I need to just step back and have a more filtered view on what is an actual compat problem in the platform and not just one-offs or corner cases. I'd love to be able to fix everything but that just isn't realistic.
The new code works is indeed the major change; and I don't like to do it but I am just no longer capable of doing high level project administration and low-level code dives in tandem. It takes a lot of effort to switch between those two very different mindsets multiple times a day.
athenian200 wrote:
2026-06-01, 01:07
Overall, it does seem like you and Basilisk-Dev are both setting boundaries when it comes to this project and circumscribing responsibilities, pulling back, etc, at basically the same time.
The timing isn't intentional. I don't know what Basilisk-dev's reasoning is but he did hint at things outside of coding and the project/his browser pulling him away (including personal matters). For me it's very much a re-evaluation within the bounds of the project and what I can or should be doing within my resource and mental energy bounds.
"Sales hates anything that can't be turned into a confident sentence." - anonymous warehouse worker
"Why debate someone you fundamentally don't trust?" - Dario Amodei
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
athenian200
Contributing developer
Contributing developer
Posts: 1940
Joined: 2018-10-28, 19:56
Location: Georgia

Re: Stepping back from new code tasks...

Post by athenian200 » 2026-06-01, 08:49

Moonchild wrote:
2026-06-01, 07:16
It's just been insanity. Even Dan Veditz of Mozilla called the inrush of sec bugs in the past months a "hellscape" in our communications. Not because sec was bad, but because so much was dumped on them (and by proxy, us), no doubt to cash in on those sweet bounties (often in the couple grand range per incident, if I understood correctly, at Mozilla) by letting an LLM comb through the code and find deviations from what it thinks are the "right" coding patterns to use.
This is admittedly something I have been worried about, because I do follow LLM stuff in the news... that basically, security bugs will be found at such a rapid rate that it will almost overwhelm Mozilla, and possibly drive you to your breaking point. If this is the "new normal," this project may become essentially unmaintainable without new contributors who are capable of helping you with this side of things. I'm hoping it's just the LLMs finding a lot of low-hanging fruit, maybe thinking in ways humans don't or finding patterns we wouldn't, but eventually it will stabilize after a lot of the stuff it finds obvious has been picked over.
The sec bug code changes weren't rushed. That's just me working full steam for full days on end. I can't do that too often or for too much time without burnout, of course, but it's not overly hurried. The eUXP stuff was indeed rushed and I hated having to do that but I felt severely pressured in that case. Some things weren't exactly ready there and we'll just have to work on ironing out some creases over time.
That makes sense. I think I was just reading too much into the crashes I saw users had with the point releases and then all the issues with the merged code and started worrying the codebase might be getting a little too full of stuff users haven't fully tested in a real release. It made sense to me when you started that testing program recently, I think we learned from the whole GRE experiment how quickly a ton of new untested code can turn into a nightmare.
Web Compatibility is more stepping back from the first line of support/analysis/mitigation. I need to just step back and have a more filtered view on what is an actual compat problem in the platform and not just one-offs or corner cases. I'd love to be able to fix everything but that just isn't realistic.
The new code works is indeed the major change; and I don't like to do it but I am just no longer capable of doing high level project administration and low-level code dives in tandem. It takes a lot of effort to switch between those two very different mindsets multiple times a day.
The mental image I'm getting from all this... is actually that you're using all the time you'd normally use for low-level code dives on this deluge of security bugs, and thus you're trying to reserve the rest of the time for high-level project administration? Because obviously you are still working on code... it's just that now all that low-level coding falls disproportionately in one category, the security stuff that only you really have the skills to deal with.

It also does sound like you would fix major web compatibility issues if they come up... but will try to leave the smaller stuff to others, and maybe focus more on the high-level task of creating open research issues if anything (high-level administration), rather than dive in and fix it yourself. That seems reasonable enough.

Well, assessing things over all... I'm back from college, so that might help a bit. I'm glad this didn't happen a year ago when I was busy studying. But overall, this just seems to reinforce my feeling that we can't afford to do something like adopt a "no AI-generated code" stance... for one thing, Mozilla will almost certainly be using AI, so anything we get upstream from them has a non-zero chance of being AI generated. For another, we're a smaller project with a community of power users who are probably just short of the skill level needed to write code themselves, and we'd likely be leaving a lot of good code on the table. Should probably talk about that more on another thread, but what I learned here leaves me more convinced we need to learn how to work with these tools as a community.
"Linux makes everything difficult." -- Lyceus Anubite
"Linux is a cancer that attaches itself in an intellectual property sense to everything it touches. That's the way that the license works." -- Steve Ballmer
"We always overestimate the change that will occur in the next two years and underestimate the change that will occur in ten." -- Bill Gates

User avatar
Moonchild
Project founder
Project founder
Posts: 39725
Joined: 2011-08-28, 17:27
Location: Sweden

Re: Stepping back from new code tasks...

Post by Moonchild » 2026-06-01, 09:03

athenian200 wrote:
2026-06-01, 08:49
my feeling that we can't afford to do something like adopt a "no AI-generated code" stance...
That has never been something I agreed with. As I stated elsewhere, I welcome using AI as a development tool, but it needs to have its output thoroughly checked for obvious reasons (i.e. please don't "vibe code" as in ask an LLM then casually glance over it to see you like the vibe and shove it out there without actual checking of work). I will never adopt a "no AI-generated code at all" stance. It's being extremist and purist and it would make a lot of things so much more difficult. If people hate AI so much they think a reactionary roadblock is necessary then they should just go off and do their own Luddite thing elsewhere. Use the best tool for the job, and keep using your brain in tandem.
"Sales hates anything that can't be turned into a confident sentence." - anonymous warehouse worker
"Why debate someone you fundamentally don't trust?" - Dario Amodei
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
andyprough
Forum staff
Forum staff
Posts: 1672
Joined: 2020-05-31, 04:33

Re: Stepping back from new code tasks...

Post by andyprough » 2026-06-02, 02:24

Moonchild wrote:
2026-06-01, 07:16
If you're volunteering, though, I'll be happy to make you a global mod here.
Ok, let's do it. I'd really like to see a couple of technically oriented people also be made moderators, people like @moonbat and @back2themoon who I mentioned already help fill that role unofficially.

User avatar
Moonchild
Project founder
Project founder
Posts: 39725
Joined: 2011-08-28, 17:27
Location: Sweden

Re: Stepping back from new code tasks...

Post by Moonchild » 2026-06-02, 06:49

Done
"Sales hates anything that can't be turned into a confident sentence." - anonymous warehouse worker
"Why debate someone you fundamentally don't trust?" - Dario Amodei
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Basilisk-Dev
Astronaut
Astronaut
Posts: 708
Joined: 2022-03-23, 16:41
Location: Chamber of Secrets

Re: Stepping back from new code tasks...

Post by Basilisk-Dev » 2026-06-02, 12:53

Moonchild wrote:
2026-06-01, 07:16
The timing isn't intentional. I don't know what Basilisk-dev's reasoning is but he did hint at things outside of coding and the project/his browser pulling him away (including personal matters).
Off-topic:
Correct, I am slowing things down for now due to things in my life unrelated to UXP or the community here.
Basilisk Project Owner

viewtopic.php?f=61&p=230756