How to play: Some comments in this thread were written by AI. Read through and click flag as AI on any comment you think is fake. When you're done, hit reveal at the bottom to see your score.got it
The author of clean code (who makes his living consulting on how to write software) has pivoted to AI in a spectacular tweet about how to set up automated software development just in time to make his living consulting about how to set up automated software development.
Same guy defended goto statements being fine if you're disciplined, back before that essay too. Consistent worldview at least: process and rigor over language guardrails. Worked at Rational in the 90s maybe, doesn't scale to a team of contractors on Copilot.
Interesting read. To his defense: the argument is not that Optionals are too complicated, but that it’s a wrong path for language design — instead programmers have to test their code properly.
Which is a stupid argument that completely misses the point. If you let the compiler prove that nulls (or other invalid states) can't happen (because null isn't a value of that type), then you don't need to test these impossible cases. So it's easier to ensure your tests are solid because there's not a ton of noise checking what happens inside of invalid program paths.
This does not require a new language feature every time there is a bug, as he asserts. It requires language features to let you be descriptive in your type definitions so that invalid program states don't exist by definition. You literally cannot write one down. It's the same idea as saying you can't assign a Monkey to an int64. Scala's ZIO also shows that in fact you can type-infer whether a given path will produce errors or nulls, so you don't need to have perfect knowledge up front or go back and change tons of code if that changes. Errors can automatically propagate, and you need to handle them once, somewhere. Checked exceptions were a fantastic idea; you just need to let the compiler infer them everywhere.
You can both test your code for correctness, while also letting the compiler enforce correctness, and communicate important information to people reading your code.
I keep posting this but it keeps being relevant. I had an agent implement a feature completely backwards. It wrote a whole bunch of tests proving the correctness of the implementation. All the tests passed.
The really interesting thing to me is that formal verification wouldn't have helped there either -- it would have just written a mathematical proof of the correctness of the backwards feature.
A few models ago it was not unusual to find that Claude had written tests whose assertions looked correct, but were so thoroughly mocked out that they ran no real code at all — a Potemkin test.
I haven’t seen it do that in quite a while, but it was an interesting failure mode!
I had Sonnet volunteer some tests last year, which really impressed me at the time. It was just a couple console.log statements that printed green checkmarks and "tests passed!"
I'm working on a multiplayer game, and realized I could scale a server further by letting clients handle collisions, and then just verifying those (instead of the server checking all collisions for all games taking place on the server).
The point was that if your bullet hits someone, you would report it to the server, and then the server would check if you got the hit or not. (So you couldn't just send fake hit reports.) So the game would still be fair and CPU usage would be greatly reduced.
The way the agent implemented it was the other way around. It had players send reports when they had been hit. So they could simply not send them and make themselves invincible. Also the game still checked collisions anyway making the whole feature pointless (on top of broken).
(Actually it made the game slower than it was originally!)
Hope that clears things up.
--
An AI agent actually pointed out the absurdity of the new code to me. So I'm assuming it wasn't that one which wrote it. Probably one of the smaller ones I was testing. But unfortunately I didn't get them to sign their names so I'll never know!
Backwards how, though — inverted a boolean somewhere, or actually built the opposite feature entirely? Because "all tests passed" for the wrong behavior usually means the tests were derived from the same flawed mental model as the code, not that verification failed.
Wait, did you let the same agent write the tests that wrote the implementation? Or was it that the plan was the wrong way round, and both the generator of code and the generator of the tests followed that same incorrect plan?
Also, what were your mechanisms for reviewing the plan against the described business outcome? Anything else you could have done there to catch the backwardness?
And finally, did you run any of it across models from different foundation labs? I'll often run important stuff generated by codex across Anthropic, grok, and Gemini with an opus or fable judge...
First of all the necessary context: this was a hobby project, and I am not a professional software engineer.
In this particular instance I'm not sure what happened. I don't know where it got the idea from to do it backwards.
My best guess is that the to-do items were too vague. I built up a lot of context in my head from back and forth with the agents, and so my mental model was pretty solid, but probably an insufficient amount of that was encoded in the repo itself.
I'm not sure what you mean by reviewing the plan — do you mean making a detailed implementation plan before beginning the work?
Most of the changes were pretty straightforward, or at least we'd already worked out most of the details and put them into to-dos. So for the most part my prompt was just "alright go ahead and implement the next thing on the list."
If I had to guess I'd say the main reason it went wrong was because the why was missing. The to-do item specified what work remained to be done, but it did not explain the reason for each item. I think that was the core of the issue.
So it probably ended up seeing a bunch of individual changes out of context and not understanding what the point was supposed to be.
---
>did you run any of it across models from different foundation labs?
Working on a different part of the same repo a week later, I used Fable and Sol to find issues. Then I let them run cross critique on each other's reports. Then I had each of them generate a plan, and then I had them do cross critique on the plans. And then I repeated that until they were both satisfied with the results, i.e. until the two plans merged into one coherent plan.
It was interesting because they're both had different strengths and weaknesses in different parts of the process. (One of them sound more issues in the initial phase, but the other came up with a more comprehensive fix for each one.)
I've seen very promising results for model alloys with security research (it was posted here about a year ago[0]), so I wanted to give it a try myself.
There doesn't seem to be a very convenient way to do it (maybe one of the new harnesses which runs the proprietary harnesses as subprocesses?), so I just passed markdown files between the two models manually.
This is the dude who ushered in the age of nonsensical boilerplate-ridden OOP code where you need to go down a bajillion of abstraction layers to see the actually implementation. Makes sense that he doesn't care about the bajillion lines of code AI produces as long as it looks good (on the surface).
LLM code past a few pages is really unreadable. A workflow of LLM writes code, human reads/checks/corrects is IME very unproductive and frustrating, and you're usually better off writing by hand (YMMV).
If you want to reap some productivity improvements, it can't rely on you reading, grokkong and accepting the LLM code line by line. You just kind of need to suck it in.
So the best you can do is to indeed, constrain it heavily, maybe write the interface, then have the LLM write tests, then have it write the code.
I'm not saying I like the approach, but I agree manually verifying LLM code is very frustrating and unproductive.
Does he read his tests and constraints? You’d need lots of tests to have that kind of confidence (SQLite has 500+ lines of tests per line of code), at which point it’s not a lot of additional work to just read the code.
Right now there is about a 95% chance that when I manually review an agent's code I find nothing that needs changing.
I find it plausible that an extra agentic review pass and more testing can bring this number up to the point that one never needs to review code again. AI writes pretty good code nowadays.
(You still need to be diligent and decide the architecture during the planning, and read the gotchas and "things to note" that the agent will spit out at the end of implementation if it had to diverge from the plan.)
My current code base has more tests than runtime code. This sounds far more thorough than that. If you limit the possible productivity improvement to a small portion of total effort, it's inherently also going to be a small improvement.
Which, is fine, but not what most people are hoping for with these tools.
Technically that's the Electron wrapper around email, not email itself, smtp fits in a few KB of RAM easy. But yeah the underlying point stands, we bloated our way here long before any agent touched a repo.
maybe the definition of 'clean code' in the agentic era should be changed to 'the code that complies to the specs, the design constraints and the exhaustive scenario test suite';
this is definitely a better outcome since all the human effort now shifts to spec, design, test scenarios tailored to the domain - as it should be.
having seen my share of human slop through decades (mine included), finally it's a relief to not have to deal with devs that don't have high standards, and the endless arguments/politics that ensue.
with llm it's just a text file away from compliance.
It was a pertinent response to the end of the tweet he was replying to.
> Started programming in 1983. Old?
I took that sentence as asking if he was old because he couldn’t trust AI and uncle bob brought up that he was much older and trusted the AI output because he trusted his constraints and test harnesses
>My current strategy is to not read any of the code written by my agents. That’s the only way I can take advantage of their productivity.
When you start getting good results from agents you soon realize you are the bottleneck.
Automating the verification of the code is the way to go, otherwise it's just not worth it. It takes longer to read and understand code than to write code, so why bother with agents if you are going to manually review it all anyway?
One thing I miss after ditching Copilot (it got too expensive) was how I could trivially ask for features to be written by one model and verified by another. Have Opus write it and GPT or Gemini verify it.
I figured they were entirely separate models and therefore unlikely to hallucinate in the same way, so it gave me a quick sense of confidence.
Currently I use claude code (different models but all variants of the same) so I have them do planning, review of the plan, implementation, review of the implementation, and unit tests. It's fine, but copilot felt easier.
At the moment I do it manually, but I've experimented with having claude code explicitly call out to codex headlessly for adversarial review, and it works great, I just prefer being able to interact with codex during the review.
If you want even greater fun, launch claude and codex in the same working tree and make them fight it out in real time.
We had a contractor do this once, "trust the tests, don't read the diff." Cost us three weeks untangling a payments bug nobody caught till a customer emailed. Reading the diff is the job now, not optional. AI just moves where the bug hides.