Finding and Fixing Issues with Legacy Code using AI - Venkat Subramaniam
About this talk
This talk explores the strengths and weaknesses of AI in software development, particularly in code error detection. The speaker humorously admits to writing poor code but excels at identifying faults in others' code, likening this to AI's capabilities. He emphasizes that while AI often struggles with code generation, it is adept at pinpointing issues, as demonstrated through various examples of flawed code. By using large language models, developers can gain insights into common coding errors, enhancing their debugging process. The speaker advocates for using AI as a complementary tool that can help programmers address the cognitive load of understanding and reviewing code, thereby improving overall productivity.
Full transcript
I want to focus on today is a little aspect of AI and and I'm absolutely honest when I say this. Uh AI is an interesting tool. It's powerful in many ways and it's not effective in a lot of other ways. But what I found out was there is one area where AI is absolutely phenomenal when it comes to software development. And and this is the area that
I feel is where it gives me the absolute power on my hands with its ability. And that is in order for it to be able to find problems in code. Now, this is a bit ironical maybe. I don't know. Um This is something that I know about myself and I'll be absolutely honest about it. I write terrible code. Uh there are a few people leaving the room
already, right? This guy is writing terrible code. I don't want to be here. No, just kidding. That that's perfectly, you know, expected, right? Because you expect somebody to be writing really good code, but I'll be honest about it. I write really terrible code. And yes, I do give talks. I talk about quality of code. But when it comes to writing code, that takes a lot of effort.
But then I found out something really special about myself. While I'm really terrible at writing code, I'm extremely good in finding fault with other people's code. And and then I realized that's my superpower. While I cannot do stuff, I can complain about it really well. And look at my surprise when I found out AI is just like me. It's terrible at writing code, but it's super good
in finding fault with code. The irony is this, you tell AI to write code, it writes absolute nonsense. You take exactly the code it wrote, give it right back to it and say, "What do you think of this code?" "Oh, this is all wrong in it." Then why did you write it? And AI is like, "What about you?" I'm like, "Touché." Right? So, essentially, this is one
area where I really think AI is super good in identifying issues. Let me step back for a minute and think What do you want? A machine, hypothetically speaking, right? Would you want a machine that washes your clothes? What do you think? Raise your hand if you do. Yeah, absolutely, right? Absolutely. Would you want a machine to do your dishes, wash the dishes? eat your ice cream? Not
a single person in the room raised their hand, right? Absolutely. You don't want a machine to eat your ice cream. Hey, I want to eat the ice cream. You wash it after I finish it, right? So, the question is, AI is a machine. AI is a tool. What do you want AI to do? Not eat your ice cream. How sad life becomes, right? You sit there, I'm
sitting here watching my AI eat my ice cream. What is it that you and I like? You and I like creativity. You and I like imagination. You and I like about solving problems. You and I don't like the physical act of typing code. Anybody here who says, "I love typing code?" Raise your hand if Not a single person. We're not typist. We love coming up with ideas
and solutions. But, to me, the problem is this, I type really fast. You probably have seen me do it. Of course, my wife always verifies things. He says, "Venkat, you can type really fast backspaces." Sure, I'm not perfect in my typing, right? But, I type really fast. The problem with me is, in spite of me typing really fast, I can never type at the speed of my
thought. I'm like, "Ooh, look at what I can do." Okay, I I type all this now, it's going to take me another 20 minutes. But, what if I can just And don't tell me you can run a wires for me, so you can think and it writes. That's dangerous. You don't want that to be typing what I'm thinking. But, the point is that act of producing code,
manual code, is slow. If AI is able to do that from my ideas, that's great, right? But, at the same time, what is it that one thing just in software development, I'm not talking about washing dishes anymore. In software development, yell out your thought. What are What is hard for us for us as programmers? What do you find hard on a given day in software development? Debugging?
Is that what you said? Debugging. Beautiful. One more. Edge cases? Is it Edge cases? Is that what you said? Oh, the writing test. That's your problem. I'm just kidding. Yeah. When we write test, it gets Again, a manual process, right? You got to How many times have you said, "Oh, I wrote this test, but I got to write another test. It's very similar to it. I got
to copy and paste." That's boring. What else can we think of? Debugging, writing test cases, what else? Documentation. Who likes that? Right? Documentation, I better to somebody else do it. What else can you think of? Come on, come on. We do this every day, Integration, what else? Ah. Reading other people's code. How do you like it? Do you enjoy reading other people's No. You're like, "Who wrote
this?" And then after 20 minutes you realize, "Oops, it was me before the vacation." Now we don't want to admit it, right? Because I'm like, "I cannot believe I wrote this code." And you don't even remember it. Why is Why is it Why is it that we don't like reading other people's code? Why is it Why is it that Why is that? Why don't we like reading
other people's It's hard to understand. So, let's summarize that. Humans cannot handle cognitive load. We suffer from cognitive load. You cannot remember many things. I cannot many things. If you have to read and it contains 20 variables, you're like, "Oh my gosh, this code is from hell." It's cognitive load. So, we cannot handle cognitive load. And guess what? The machine is good at handling You take 7,000
lines of code and give it to a programmer and you have to call medical attention, They're like, "I can't handle this." You throw 7,000 lines at AI, it's like, "Start. Hey, what's next?" Because it's a machine. A machine can do things that humans cannot imagine. And humans can imagine really well. Why bother with a machine to do that, right? So, to me that's the power of AI.
So, are you ready? Let's see if it's true, if I'm just being lying. You can say, at the end of this talk you can say "Venkat was honest or Venkat was hallucinating." Right? So, let's see if that's true. So, we're going to look at the benefits and the drawbacks we talked about. So, let's start with something real quick. This is a question for you, if you will,
for a little bit. I want you to tell me what are some of the most common errors we have uh found, you could say, So, whatever comes to your mind, don't hesitate. What are some of the common errors in the code? What is What is your thought? Logical errors. Absolutely, right? Logical errors. We can actually keep the lights on if you don't mind. I like seeing uh
everyone in the room. Uh that's After all, we are humans, right? So, logical problems, right? Let's see. We can turn on the light for the people. Thank you. There you awesome. Logical What else can Memory leak. I love it. This group is amazing. So, we can do memory leaks, right? We can look at memory leaks. Uh so, memory leaks. >> One inside with >> Infinite loops. >>
Oh, infinite loops. I love it. Infinite loops. Uh I could probably add uh new conditions, right? How many of us have suffered through this? You're always like staring at it. Is it less than or less than or equal to? Never sure. What else can we think? Context, you said? Null pointer Ooh, null pointer. Null pointer exceptions, thank you. NPEs, wonderful. Anything >> Hard-coded configurations. >> Ooh. Hard-coded
Uh uh configurations. Uh race condition, I heard. >> Yeah. Index out of bound exception. >> Uh thank you. Index out of bounds. Multi-threading did I hear? That itself is a problem. Then there's What else? Uh code duplication. This person has been through the trenches, you can Right? Code duplication. What else? Naming convention, did you say? What was that? Yeah, thank you. Thank you for both. Transaction Nice,
right? you are looking at a piece of code that you inherited. And your boss tells you, "We have a problem with this code. Can you please take a look at it and see what we can improve?" And you're like looking for ideas. What are the things I could be looking for in terms of how we can improve it, right? So, this group collectively came up with some
really good ideas. I like it. I'm going to take this right here. What are some of the most common errors we we we have found in code and I'm going to go back here. Let's just pick one. Let's do Claude. Doesn't matter. You can pick any AI tool you want, right? So, I'm going to pick Claude here. So, I'm going to say Claude is so awesome, right?
It even knows it's afternoon. That's great. so let's say, "What are some of the common errors you're found in we're found in code?" And it's thinking about it. Logic errors. Isn't that cool? That's one of the first things you mentioned too. Null undefined issues, type errors, concurrency threading, resource management memory leak, error handling, boundary edge cases, security related. Nobody mentioned this in the group. But that's an
important thing. Performance issues, naming and scoping. did it say a few things we didn't say? Yeah, that's pretty good. Did we say anything it didn't say? Maybe. So, my recommendation is two things. First, human first. That's my philosophy, right? Human first. Just like we did. Take a few minutes to think about the problem. When you see an issue, don't just take it and give it to AI,
it's your problem, right? Take some time, think about it. Why? Because if you understand and at least get a scope of the problem, you can then look at what it says and say that's good, that's useless. You can be better in evaluating and critiquing it. So, don't rush. That's one of the biggest problems in in our world today. We just rush without even looking at what is
around us, right? So, just take your time, spend a few minutes, time box your effort. I'm not saying spend 10 hours. 5 minutes, 10 minutes, whatever it is. Just spend some time on it. Second, I just used Claude here. My recommendation often is whatever you're doing, do it with at least three different LLMs. When you do it with three LLMs, you get a more comprehensive response. For
example, just to illustrate that, let's go here and bring up ChatGPT for a minute. And in ChatGPT, uh I'm going to ask the question, right? So, here, what are some of the most common things we find? And if you strip away the language blah blah blah, off-by-one error. Nobody else said that, right? We didn't say it, Claude didn't say it, but this one said. Now, you know
why I'm saying use at least three different models? Because you're being more comprehensive and you get a much broader set of view of ideas. I don't want to be restricted. When I have the power to use multiple things, I can gain from it. So, this is Now, incorrect assumptions about state. Hey, this is rich. The other one didn't say it, we didn't say it. Concurrency issues, yeah,
that was covered. Error handling, copy-paste error, somebody said that earlier. Bard didn't say it, this one is saying it. Magic numbers, hardcoded, somebody said, Bard didn't say, this one says. Poor naming, misunderstanding language features, aha. None of us said that. Bard didn't, this one did. And resource leaks we identified. And then floating-point errors, uh and then over-engineering, premature abstraction, lack of validation, time zone. Anybody ever seen
that issue? It's the worst problem I think in in uh programming. I can't tell you how annoying this is. I spent countless hours and I'm still getting it wrong. This is really hard problem to solve, as it turns out to be. Beautiful identification, incorrect algorithm logic, the deeper uh pattern uh and um yeah. Good. So far, so good. Now, let's get back and look at something else.
We talked about these two look at multiple things. Let's ask AI about a few things. let's start with something little bit of a code. Before I show you this code, let me spend a couple of minutes talking about this to set the stage for it. So, this code I'm going to show you is not just a hypothetical code. I just didn't I just didn't make it up.
It's a little bit different from the original, but let me talk to you about the story of that before we go into the Uh there's somebody who works for a financial company and you know the name of the company, I'm not allowed to say it here. And this person deals with financial data. There's a customer and they have a lot of accounts. Imagine this is a very
rich customer with a lot So, the person had written code that given a customer, they go and fetch all the accounts and for all the accounts, for each of the accounts, they perform an operation and then they get a result and they put this back in a list and then they return it. So, that this person sent me an email and the email said this, "Ranked, here
is a snippet of the code. This code has been working fine until yesterday. And I made one change this morning and all hell broke loose. What am I doing wrong?" Now, this person made one change and the code is not working properly. What do you say when you hear somebody say that? If somebody made a change to a code and it doesn't work anymore properly, I call
it lucky. You know why it's lucky? If you wrote the code, it doesn't work and you know it doesn't work on your machine. Because in general, if you're lucky, the code fails on your machine. If you're not lucky, it passes on your machine, fails in production. So, this is why I don't like the phrase it works on my machine. I like the phrase it fails on my
machine. Because then you can find the problem, fix it right away, right? So, this person was very lucky. The code failed on their the question is, what did they do wrong? Now, obviously, I cannot show you the code this person sent because that's NDA, right? I don't have the ability to show that in public. So, what I did was I took their code and instead of accounts,
I just created a bunch of strings. And instead of the transaction they did on the account, I just converted the strings to uppercase. So it's an equivalent operation for all logical purpose, right? A bunch of accounts, bunch of strings. Bunch of transactions, bunch of function calls on the string. So that's basically what I did. And the code is the following. So here you see the code. What
are the issues in this code? Right away. What comes to your mind? And then if you have microphones nearby, you can hand it off to the person who wants to say. Oh, there's a person over here, right in the front. What What was the problem? >> I I had a similar issue. Line number seven using parallel stream with for each. And I was like, "How?" So that
is risky. And I've had issues with that and until and unless you close the stream, what I meant to say is that parallel stream.collect, you do a collect that will not work properly. That parallel stream.for each will cause threading issues that I've seen in production. >> Is the Is the problem for each or is it something more than for each? >> Uh the the problem that I
had there >> I mean, we've had several problems in our lives, but this one. This code. >> Really? Yeah. Yeah, you're correct. >> Is the problem for each or something more? >> Seriously, I really is right. >> It's You're you're you're close, but you're not spot-on yet. Streams are lazy. the result is not uh it's not a concurrent data structure. >> Aha. >> And worse What is
the problem is on line 10. How about that? Line 10. >> Concurrent execution uh so basically you cannot put items while iterating. >> That's right. The problem, thank you. The problem is we are causing a side effect. Right? You're right. So, it is for each, but it's a bit more than for each. It is the add function. Because the add is causing a side So, mutating data
that is external to a pipeline while you're in the functional pipeline is a terrible practice. That is the problem. Now, again, right? With no disrespect to anybody in this room, this is this is the hard part. If I show you this code and ask you what's wrong with it, there are three hurdles to us, right? The first hurdle, I don't know Java. That could be a problem.
So, sometimes you look at a code in a language you're not most familiar with, but you have to because you're a part of the team and somebody says, "This doesn't work. What do I do?" And you're like, "I'm a back-end guy, you're a front-end dude. What do I do?" But sometimes you want to help them, so you're looking at the code, right? Second problem, uh you may
know the language, but you may not know how a stream actually behaves. That's a second problem. Third, you may know how stream behaves, but you may not really catch the problem at the time. And you may not really realize that's what is causing the problem. So, we struggle with this. So, of all the people in the room, very few of us are able to identify it, right?
That's just the nature of But, of course, you may say, "What's really the issue in this case, Mankid, because it seems really okay, right?" So, I'm going to go over here to this code. I'm going to just drop the code in here, right? That's all I did. I copied and pasted it. And I'm going to then say, uh Java sample.java, run it. Notice it says there are
seven elements in that collection, right? So, is that correct? Is there seven elements in the collection? So, we had all these names, but we're converting those of five letters into uppercase. So, that is apple, then we have grape, guav- guava, and then we have mango, and then we have uh peach, and we have lemon, and one more I'm missing here. That's how efficient I'm in counting it.
Is it nine? Okay. So, that's seven. So, that's correct, right? So, you you look at this and say, "Hey, it it gave us seven. What's your problem?" You cannot sometimes just run the code and prove its correctness. So, you cannot say the code works. You only can say the code behaves. Whether it's right or wrong is more, right? And I cannot guarantee this for you because it's
non-deterministic. This error is. I'm going to run it a few times, but I cannot guarantee it's going to fail in front of you, right? But, I will try. So, let's go ahead and run this just a few times just to see maybe You know what? Let's do it this way. Let's do uh a Java sample.java, right? That's what we want to run. So, let's do a run.sh,
and I'm going to just run this a few times in here. So, let's just run it a few times. I don't know how many times. You can just run a few times and see if it's going to maybe show its face and tell us what's wrong with this. Like I said, I can't guarantee any of these, right? So, let's go ahead and run this code and see.
So, it's running a few times right there. And um notice the result is consistently seven, right? It's consistently seven. Oh, I just realized. I'm really sorry. I did not sacrifice that goat this morning to the demo gods. I should have done that. Don't it. So, let's try this one more time. Maybe maybe maybe we'll we'll you know, say send all our prayers to the demo god, right?
And see if it does. And maybe we could run this several times and maybe we'll never ever see the problem. There's no guarantees, right? And that is the beauty of a solution like this. It is extremely unpredictable, right? Extremely non-deterministic. So, I'm going to try it just one more time and see if it were to maybe occasionally fail, right? And and and maybe it won't. I I
can't guarantee like I said. There are times when I would do this demo and it shows multiple failures and and and then there are times it doesn't. How's that? You see it? Of all the times we ran what did we what what fruit did we lose? Apple is there. So, there is Yeah, mango is there, lemon is there, peach is there. Grape grape is gone. Where are
grape? It rolled off. Who wants to debug this code? Raise your hand. The phone just rang at 2:00 a.m. at your house and your family is angry at you for waking everybody. And your boss says, "The code doesn't work. Come fix it." And you say, "I've been in this job for 1 week. I just got the pager." And now you have You're the victim. You have to
go fix this code you don't know. How does that feel, right? This is the problem. This is an extremely complex piece of code sitting inside so much code and it doesn't work. You rerun the code. Folks, I love writing unit test. Do you think you would have written a unit test for this so easily? Not. With respect, as much as we all love unit test, very difficult
to write a unit test for So, so these kinds of problems can be really, really hard, right? So, you're sitting there and scratching your head. You know, they reported data missing. I ran it 200 times. It seems to work fine. I don't know what to do. And you call your colleague and say, "Excuse me, colleague, this code is not working. Can you help me?" What does your
colleague do? They look at the code and say, "It looks fine to me." And then they say, "Can you run it?" And you run it. And guess what it does? It does what it's supposed to do. And they're like, "It seems to work." And now you're like, "Okay, so I thank you for your help. I'll continue to debug this." Because the problem is in production and we're
not able to repeat it. And then what happens? Then we file back not repeatable. Well, I can't repeat it. What can I do, Is it really true? Let's go over here and just paste it right there. What are the issues in this code, right? That's all I'm asking. And And when I say that question, it says, "Identifying race condition in parallel stream with array string." The issue
in this code, critical race condition. Remember somebody here said that when I said, "What are the common errors, right? Somebody in this area said race condition. That's exactly the problem in this code. What's the issue? Critical race condition. We have a stream while writing to plain array list, which is not thread safe. So, the problem is multi-threading writing concurrently. While most of us couldn't find this, a
few of us did. And some of us said race condition. But did you notice how it nailed it as the very first issue? Now, you may say, "I don't get it. Why is it so bad in writing code? And why is it so good in finding fault with code?" That's a question, right? Why is an important question. That's what critical thinking is all We don't just shrug
and say, "Okay, that's life in the big city, right?" Ask the question, "Why? Why can't it not write good code? Why is it so good in finding fault?" The reason is extremely simple. AI is an inference engine. That's all it does. It infers. When you say it write code, it looks at the vast amount of code humans have ever written. And what can you tell me about
collectively the code humans have written? It's a bad code. Would you agree? It's a bad code. Raise your hand if you think humans have written the best code in the world. Yeah, nobody, right? I'm not asking have you written the best code. You always say yes. But have the humans done it? Oh, no, no, no. I write great code. Everybody else sucks. I will tell you I
suck at writing code. I can't write good code, right? But what did we let AI do? We showed those to AI and said, "Here, learn from it." We never told AI, "This is good. This is bad." So, that's why it's not great in generating code. But when you show a code and say what's guess what it's been trained on? It's been trained on books. It's been trained
on blog post. It's been trained on incident reports. So, now it is looking at some other piece of information. What do books tell you? Books show you bad code and say, "Dear reader, this is the type of code you shouldn't be writing. And here's why this is bad code and here's how you fix it." And AI is like, "Aha, I've seen that one in this book. I've
read it." This is AI saying, "I've read Brian Goetz's book on concurrency and he tells me what to do and what not to do. I know this stuff," says AI, right? So, AI has been trained on literature, books, material, tutorials, blog post that all teach us good versus bad. And when you give an example code, it knows where to get it from. So, it's not that it's
doing anything different. It is just we are giving it a different problem to solve and it's so good at one, not so good at another one. So, when you start realizing these things, you get better control over using AI. So, that's the first problem it gave us, right? Secondary, non-deterministic ordering in terms of for each, a little bit of a problem. And and then of course, summary.
And what is the a fix? It says collect collectors.tolist. I want to pause right here. is great in identifying problems. AI is not great in writing code. I cannot emphasize this enough. If you come to me and say, "This code has a problem, Venkat. This problem with the code is race condition. It's doing wrong things." And I'm going to ask you, "How do you know?" Hey, I
know it. I've seen the problem before in my life among all the problems I had in my life. Or I I consulted AI and it agreed with my problem or it discovered it. I'm like, cool, that's awesome. And then you say do collect collectors start to list. why do you say that? And you say, because AI said it. How many of you think that's the right solution?
Raise your hand if you think Raghunathan is raising the hand just to kind of tease me on this. Yeah, he knows this is not the right thing. What would you do instead of Anybody? Rather than calling collect uh collector's start to list, what should you do starting Java 16? You should call the toList method directly on the stream. But toList method on the stream creates a immutable
list. The toList on the collectors creates a That is old way of writing code. If you're in Java 16 or later your colleagues will come to you and say, why are you calling that function? There's a newer function, why are you not using it? And you're like, oh, because AI told me that. So, that's why be a little uh what do Cautious careful about listening to what
AI says. Ideas are There's no cost in examining an idea. Solutions are much more important. If you take the solution and use it somebody is going to challenge you. It's like, why are you doing that? You could have used a toList directly. So, be a little bit careful. So, the solution to this problem that you see here should be to really say don't create a list here,
obviously. And go directly here. excuse me, rather than doing this to list directly on the stream, right? And a smaller issue, not a big one, is to flip this. Filter and map. Not map and filter. But that would be the right solution for And then you can return the result, or you can simply do the return right here, right? So, return right from there. And that would
be the fix. So, the pro- point really here is AI is really good at finding issues, not great in writing code or giving you solutions. Just be mindful of Well, okay, we saw an example. Lovely. Let's go a little further, then. Here's your next challenge. What's wrong with this code? Anyone? It needs returning a null. That's a smell, right? How do you feel about line number six?
You're like, "Ew." It is setting a null. That's one problem. What else can we think of? Good. Several problems in this There you go. >> Pass by reference and pass by value. >> Um uh almost, almost. Java always passes by reference for most part. The references are by value, so it's by reference. But but you're getting close to it. The The problem here is I would say
this is really a very, very bad practice, right? Look at line number four and line number six. We are modifying the parameter given to a function. And the string came in as an input and we are changing the string that was given as an input in those two lines. But then we are returning that back. So, that's insane because that's confusing. This is actually I'll give you
an example of this. This happened years ago, but somebody came to me and said, "I've got this function. It's not working. I've spent a lot of time debugging. I don't understand the code I wrote. Can you please help me?" And I quickly read the code and I said, "If this is the input, that should be the output." He said, "I know, right? But it's not working." So,
we both are staring at this code. And then I suddenly said, "Wait. On line number seven, are you really changing the parameter given to the function?" And he's like, "You know what? I'm stupid. Thanks for finding that." And he walks away. So, it can be really hard to debug code when we do this. What does good practice in Java say? Make the parameter final, right? If you
make the parameter final, you will not be able to mutate it. But in all fairness, other languages like Kotlin and Scala automatically treat parameters as final. So, this code similar code like this will not even compile if you try to mutate it. The second problem. So, the first problem is we are mutating parameters. Second problem is setting it to null, as you said. The third problem. If
you return a null, you're not conveying the intent properly. What does this mean to me as a user of this function, as a caller of this function, right? That information is not clear from this. So, so essentially in this case, we are writing code that is not very expressive. So, there are several problems in this code, as you can see. and ask the question, what is wrong
with this code? That's what we're doing. And And typically, when you're in an IDE, you can just in the IDE ask this question to your AI tool. If I'm using IntelliJ or if I'm using VS Code, I would just bring up Copilot, select the model I want to select, and I would say, "What's wrong with this code?" And it'll tell me right in the IDE. You don't
have to use a browser. So, it says issues in this code, null pointer exception, critical. It doesn't have a null check. What's the next problem? Design issue, returning null as a signal. That's a really bad way of writing code. A third problem, re- reassigning method parameter. By the way, minor is judgmental. I think it's major, not minor. That's not a good way to write code. So, but
it is saying minor doesn't mean that's minor. But, I would rather not ask it to, you know, evaluate the measures a criticality, but tell me what's wrong. Reusing the method parameter, that's a really bad practice. Reusing the parameter as a working variable is a is a terrible thing to do. And And so, that gives you a a few things. And again, as you can see, it was
able to nail the problem really well, right? And that's pretty darn good, isn't it? So, let's look at the next one. Uh this is a code that is that that I wrote to as a intentionally provide me if the Wordle guess is correct. Who plays Wordle here? Okay, a few of us. So, you know how Wordle works. For the rest of us who don't play Wordle, the
idea is you have a five-letter word the the program chooses. Your Your objective is to guess that word. If you identify letters in the exact position, it gives you a green color for that letter. If you identify a letter at a not correct position, it gives you a yellow color to say that you found the letter, but it's not in the right not in the right place.
If you find a letter that's not even in the word, it gives you a gray color or a white color in this example. So, I thought I'll just write a little code to play with it. So, here is called check, which takes a given word and a guess word and returns the evaluation for the given word. The words are always five letters long. There you go. What's
wrong with this First, we have to read the code, then we have to think, then we have to analyze. And some of us may be familiar with the logic. Some of us are not familiar with uh is is is is running towards This is This is is opportunity to get enough steps for the day, He's going to go home this evening, and they're going to look at
him and say, "You've been working out, aren't you, right?" So, this is great. Can I Can I do that for the next session? Run around with the mic. This is great. I've not had a chance to go to the gym this morning. Please. Uh in use of equals equals instead of we can use dot equals method to compare the value of character. Mhm. So, rather than a
double equals, we could use a not equals, That's a little bit of a Is it a Is it That's a little bit of an improvement, right? Fair enough. Anything else? What was that again? You don't need two of those, maybe. this is what we struggle with every day, You're looking at a code that you did not write. And you are like, I'm looking at this code. Is
the code correct? Is the code good? Can it be improved? So many thoughts in our mind, right? This is where we humans are not good at. Let's be honest about it, right? You and I are really good at a lot of things, but this is what we are not good at. When you hire a person in company, what do you normally tell them? Before you get into
coding, spend some time debugging and being in a QA. Does anyone enjoy that? They put you through the worst of the things. If you survived it and didn't quit, now they tell you you can start writing code, right? Because it takes a lot of effort to understand systems. That That's the problem. So, most of us could not find what's wrong with this Some of us came with
a few ideas, but let's go here and ask again, we can consult with multiple uh So, I'm asking, what's wrong with this code, right? Is there any problems with And what does it say? It is saying and and usually I would say the first thing is actually really good most of the time. That's been my observation so far. So, tracing through the test case of valid bug
hypothesis, but it thinks there's a bug And let's see if that's actually true. It's taking a little longer. That's how bad the code is, I guess. So, tracing through the test cases. Oh, you can do it. it's taking a little longer than usual. I'm a little surprised that it's taking this long. It could also be because of slowness and correct connection. Oh, green position get overwritten by
as yellow. Oh, by the way, it's bug one. That means there's more bugs in it. How comforting. So, green position gets overwritten as And it tells you what is it's This is the beautiful thing, right? It even gives you an example scenario. You know what's cool about it? You can take that example, write it as a unit test. This is one of the tenets I follow. When
I find a bug, I don't fix it. When I find a bug, guess what I do? You confirm the bug, but it's it's No, it's No, it's there's a bug. You When you find a bug, don't fix it. What's the first thing you do? >> Write tests. >> I love it. I was going to say blame the person who wrote the code, but you're better than me.
Good. So, write test. Absolutely, right? So, when you find a bug, write test. Lovely. So, when it gives you this example, you can take this example and say, "Whoa, that's great." You can convert that example into a test. Even better, as as she said earlier, right? Writing test is hard. Sure. Just tell the AI, "Why don't you take this example, write a unit test for me. Thank
you." And just take that into your system. That could be a nice way, right? So, it found one bug. Bug number two. Yellow matches don't consume the match to character. And it gives you another example for it. again, be wary of the solution, though. What do you think? Is that pretty awesome? That it is able to really look at your analyze it, and say, "Here you go.
These are your bugs." Now, somebody said or to me, "Oh, wait a minute. Word and is a known problem. This is unfair. You gave a known problem to AI." Let's be honest. The problem may be known, but the code is not known to it. I wrote that code. And it's able to read my code, even for a known problem, and say what's wrong with it. And those
of us who know Word in the room couldn't tell what the problem is, right? Again, no insult to anybody in this room. That's the whole point. We as humans are never going to be good at that. But when a machine can do it really well, that's where the strength of the machine is. And and we can leverage that for better. And that's where I want to use
it more and more. All right. Couple of more things to take as a challenge. The next one is a little bit more tricky here, but let's take a look at what this is. Are you able to see the problem in this code? Again, I've seen problems like this one in other situations. And I've just created these examples based on what I've seen in other places. So, the
question is, what's wrong with What is that? Lossy conversion. Good try. Return type is It should be different. >> If it's a float value and we are type casting it to int, suppose it's returning the calculation is returning a point zero zero one zero. So, after type casting it will return zero. >> So, you're going to lose some precisions on the values. Good try, but that's not
the problem. >> The conversion rate value is duplicated in both functions. >> Yeah, it's a code duplication. >> There is There's not enough sugar in the coffee. But the building is on fire. yeah, code duplication, not enough sugar What was it again? Nope, multiplying int with a float. There could be more milk in the coffee. Hard, right? Hard for us to see what's going on. >> Uh
my guess is that low cost currency converter can act as a currency converter if you don't pass a double. If you pass an integer. >> You're almost there. You're almost there. I love it. You are You're so close. So, he said the low cost converter can as a currency converter. Let me translate what he said to a little bit more stronger words. He's hinting on polymorphism. Cuz
that's what you talk about, right? This can act as that. that polymorphism. For polymorphism to work, there is a important rule. What is that? Signature has to be the same. If the signature is not the signature is not the same, you will not have a method override the other method. So, what do you normally do in Java to avoid these kinds of problems? You annotate the method
with @Override. And I did not put @Override in this code. So, take a look at this. If I grab this code right there for a minute, let's go ahead and replace this so I can see it here. So, notice I run the code, it's doing some work. But I go back here and I said @ Override because my intention is to override the point he made. You're
able to substitute this polymorphism, right? You get a compilation error. Method does not override or implement a method in the supertype. this is not proper over overriding. This is not proper So, we we struggled and one of us in the room said, "Hey, that's kind of where the problem is." And we took a lot of effort, right? We got some amazing people in this room and yet
we all found it hard. And one of us came close to it. Can AI really be good in this? Critical bug. Look at that. Overloading That's shocking, isn't it? It nails it on the first It says the main problem, lowercase currency converter changed the parameter type from into double, so it does not override the parent method. It creates a second separate overloaded method, which means to the
point he was making, polymorphism will not work. So, when it when it ran the code, that result was wrong. That's the problem, it says, "Missing override annotation." Pretty darn good, isn't it? It's able to tell you what you are doing wrong. You should have put the annotation, it says, right? And then, code duplication. Somebody mentioned that over there. That comes in as a third one. As you
can see, magic numbers, minor ones, and those are design issues, but the other things are bugs. So, that was able to identify that as well. Pretty nice. So, let's pause for a minute and talk about something else really quickly. You could say, "Hmm, AI knows this, Wordle problem. AI knows this, knows that, knows this." But, I would argue those statements are reflection of two things. To say
that, "Oh, AI only did this because it knows this, right?" To me, those reflect two things, two problems in our conversation. The first problem we're in denial that AI can be successful. I'm not saying AI will always succeed, but let's give credit where it's due. It is good at certain things, not good at other things. And and when it's good at something, let's appreciate that. It's good
doing it. First The second problem with that statement, right? Knew this, so it was able to do yes, it knows it, but it's a language model. That's a job of it to analyze, understand these structures. So, it's just doing its job. But I really wanted to prove it's a lot more than that. You and I, when we sit down to read code, you are you and I
are struggling to understand code. you and I can struggle, we normally go get stronger cups of coffee, take it in, and we plow through the and then 2 days later, you come out saying, "You know what? It was really hard, but I finally figured it out." And we celebrate, right? sometimes you work with programmers who absolutely hate everyone in this So, they write code in a way
no one can understand. You know who I'm talking They will use single-letter variables everywhere. They will not indent code properly. They will give weird names to functions. They will make sure that no human can ever understand this code. And you look at this code, and you are thinking, "Oh my gosh." And you tell, "Dear God, why did you let people write code like Dear God, why did
you create people who write code like this, right? And if the code is so hard to understand, variable names and their meanings, they give you abstraction. Function names give you abstraction. Class names give you abstraction. What if all that is completely removed? Would you be able to handle such a code? And then I'm going to ask you, would AI be able to handle such a code? So,
I apologize to you already. This is going to hurt you really bad. So, put on your seat belts. Wear it tight. If oxygen masks come from the ceiling, I know it's a very tall ceiling, but if oxygen masks come from the ceiling, put it on yourself first before you help the person next to you. You've been warned, right? So, here you go. I want you to look
at this code and tell me what does this code actually do? That's your question. And don't feed this into AI. That's unfair. Don't do that. I'm watching you. Bless you. See, I told you. You can already see he starts sneezing. That's how it starts. That's how toxic this code is. It causes allergies. That's the first step. And then you can start seeing fumes come What is this
code doing? I'll give you something else for you to think about. I have literally, not figuratively, I've literally shown this code to about 1,200 people so far. Of the 1,200 people, four people have come somewhat close. Not a single person has ever identified what the code is doing yet. But four have said they kind of come into the vicinity. Out of the 100 1,200 people, four people
have come closer. That's how horrible this code is. What is the code doing? I'll give you another half a minute. Wrong answers are acceptable also. I love that the mic runners are just slowly pacing. Hard stuff, right? Occasionally we work in companies where we come across code like that, right? And you're like, "Oh my gosh, I cannot understand anything this code is doing." All right, should we
ask AI? All right, let's do this. Let's go to AI and we'll ask the question. So, here we go. Grab that one. Let's go to Claude and say, "Hey, what is this code doing? Tell me." Thinking about it, code analysis, here are the steps by step breakdown, outer loop, inner loop, prime. It says, "Find the first three primes." Well, okay. Once K primes have been found, the
loop breaks and R is returned. So, what does it do? Find the first K prime numbers greater or equal to N and return the sum of their square roots. Isn't that shocking? That's what this code is doing, actually. It returns the sum of the square roots of the first K prime numbers that starts with the given number. Like I said, I've shown this to more than a
thousand people. No one has found the answer yet. But AI is able to nail it. That's very shocking, isn't it? In terms of its ability to analyze the code. Why? You and I suffer with AI is a machine. It doesn't have any emotions. It doesn't have any cognitive It doesn't have these constraints that we humans have. It can just flow through it. It can remember. And then
it can tell you what's happening. So, that is the power of this tool. So, what does that mean? For all the legacy code you have to deal this can be a great tool. Because as you're suffering through to understand what the code is doing, you're like, "Hey, help me out here. What is code doing? I can't understand this." Not that you have to trust it, but you
can go back and verify it, And now that you know it's computing the double of the square root of the Uh sorry, the sum of the square root of the functions uh for the for the first K prime numbers starting with N. Now you can read the code knowing that. Now you're going to see it very differently, right? Because once you you're going to be looking at
it and say, "Oh, I see what's going on now." Because you it's it's revealed the real core of the problem it's solving. And that is the beauty of it. And it can even give you the documentation and tell you this is how it works. And it gives you examples for it. The beauty is now you can write the test cases for it. And then you can come
back and refactor it. You can write test case with AI. And then once you have the test case in place, you can ask AI to refactor the code as well. And then you can go back and review it. So, the moral of the story is let's ask AI to do what it's really good And it turns out what it's really good at is also what we are
not good at. And I think that's a really good combination, right? Because when a tool can do better what I am not good at or I'm not really excited about, that's where the perfect match is. And I think that's where we can benefit from it really well also. I hope that was useful. Thank you. >> [music]
More from this event
See all 126 talks →
AI Is Not the Risk. Architectural Drift Is - Sunil Kalkunte
17:39
Breaking the Monolith: Tesco’s Journey to Federated GraphQL with xAPI - Vishwas Chandrashekar
29:13
A Practical Introduction to LangChain4j - Venkat Subramaniam
1:01:28
Beyond the AI Models: How Lowe’s is Building the Store That Knows - Swaroop Shivaram
13:59