Is it unreasonable to ask that if a massive company funds someone to find a CVE in an open source project, they should also submit a patch? Google is a search company. Seems kind of... evil... to pay your devs to find holes in something with nothing to do with searching, then refuse to pay them to fix the problem they noticed.
No it's not "unreasonable" to ask for patches along with bug fixes, but it is unreasonable to be mad if they don't. They could just not file the bug reports at all, and that is an objectively worse outcome.
Note that most open source contributions by Googlers are, as recommended by policy, done under their own personal accounts. There's a required registry internally mapping from their personal account to their @google.com identity.
The nice thing is that the open source contributions done by a Googler aren't necessarily tied to their Google identity.
No, my stance is that it is reasonable for ffmpeg to ask for patches along with bug fixes and that is it simultaneously reasonable for Google to submit bug reports without those patches. Just like it would be reasonable for Google to ask for a feature in ffmpeg and it's equally reasonable for the ffmpeg maintainers to decline to implement the feature. Reasonableness is not a binary thing.
Are you on the autistic spectrum and/or not a native speaker of English? If we are discussing if FFMPEG's stance is reasonable, then it follows we are discussing of Google's actions are unreasonable.
Google is absolutely being unreasonable here -- they should instruct their engineers to submit a patch when submitting CVEs, and FFMPEG is perfectly valid to engage in a little activism to nudge them along.
>it's not "unreasonable" to ask for patches along with bug fixes, but it is unreasonable to be mad if they don't
So the ask (make a patch for your CVEs) is reasonable. It follows that to fail to do so is unreasonable. Whether the poster agrees Google is unreasonable or not is up for debate, but if they choose to espouse that the request is reasonable and that Google is reasonable, they're putting forth an irrational belief not rooted in their own logic.
But hey, lots of folks on HN are biased towards Google for financial reasons, so I totally get it.
But either their stance is how I said, or if their stance differs they are a hypocrite, there really is no middle ground here.