Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cyphar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
121.
▲
by
cyphar
10mo ago
Not only that, almost every software license (FOSS or proprietary) has a similar clause (often in all-caps).
122.
▲
by
cyphar
10mo ago
There are quite a few open source or royalty free Japanese fonts (Google Fonts has 50[1]). But, as everyone else has mentioned, font usage in games (and most creative visual works) is more particular than just the bare minimum of "does
123.
▲
by
cyphar
10mo ago
Other LSMs are slowly switching to syscalls too, and while I in principle like (and have abused) the whole "everything is a file" principle, most security mechanisms really should be done via special-purpose syscalls. Way too many
124.
▲
by
cyphar
10mo ago
glibc has been reticent about adding new syscall wrappers for a few years. The situation did improve for a bit recently (and they added something like 5 years of syscalls from their backlog in the past few years) but I'm not surprised
125.
▲
by
cyphar
11mo ago
You absolutely can, both systems are practically identical in this respect. > In Go you know exactly what code you’re building thanks to gosum Cargo.lock > just create vendor dirs before and after updating packages and diff them [.
126.
▲
by
cyphar
11mo ago
Of course it doesn't provide backports by itself, it's a versioning system. But version number changes with SemVer are meant to indicate whether an update includes new fearhews or not (minor bump means new features, patch bump mea
127.
▲
by
cyphar
11mo ago
On Debian you can use the local registry for Rust which is backed by packages. Though I will say, even as someone who works at a company that sells Linux distributions (SUSE), while the fact we have an additional review step is nice, I thin
128.
▲
by
cyphar
11mo ago
"Lots" is a relative term, but the overwhelming majority of kernel developers are employed and usually do kernel work as part of their job (usually at least ~80% but it could be argued as high as 97% depending on how you interpret
129.
▲
by
cyphar
11mo ago
> For those that don't know, Fizz Buzz is less an aptitude test and more of an attitude test. The articles which popularised FizzBuzz as an interview question stated as a categorical fact that most computer science graduates or pr
130.
▲
by
cyphar
11mo ago
I forked Incus from LXD, and I would not describe LXD as Incus's upstream at all. In fact LXD, tends to take patches from Incus these days -- on the other hand, we can't take patches or even look at patches from LXD because they&#
131.
▲
by
cyphar
11mo ago
I've been thinking about this a bit over the past few days, and I think this is a fairly reasonable middle ground (and also allows maintainers to decide how they wish to engage with LLM-generated work).
132.
▲
by
cyphar
11mo ago
> I would need to spend hours of time to articulate exactly how uncomfortable this would make me if I was working along side you. I think this came out a little wrong -- my point was that if we are going to go with a middle-ground approa
133.
▲
by
cyphar
11mo ago
> I considered posting this in the GH thread, but you asked nicely not to... [...] you posted the Issue as an RFC. but then explicitly excluded, HN from commenting on the issue. I think that was a fantastic decision, and expertly writte
134.
▲
by
cyphar
11mo ago
> LLMs are really good at writing these. IF they think this will prove the author is human, they're mistaken. That is not my general experience. LLM explanations of code tend to add extra specifics that are incorrect, and the whole
135.
▲
by
cyphar
11mo ago
> I have an issue with low quality slop whether it comes from a machine or from a human. It's very hard for a human to mask a low-quality PR as thought it were reasonable quality. It is incredibly easy for an LLM to do it (in fact t
136.
▲
by
cyphar
11mo ago
I completely agree, but it seems that our industry has decided to turn a blind eye to it. They might even get away with it -- the recent rulings around fair use with regard to Facebook and Anthropic's unrepentant copyright violations[1
137.
▲
by
cyphar
11mo ago
(OP here.) Well, we don't receive that many low-quality PRs in general (I opened this issue to discuss solutions before it becomes a real problem). Speaking personally, when it does happen I try to help mentor the person to improve t
138.
▲
by
cyphar
11mo ago
Not really, OpenVZ was/is really quite good, it was just hampered by the fact it requires out of tree modules. LXC has also always been very usable (Docker even used it for several years) but it was IMHO too focused on the VM-like mana
139.
▲
by
cyphar
11mo ago
FYI, we just merged FreeBSD jail support into the OCI runtime spec v1.3[1]. There is already at least one implementation of it[2] as well. [1]: https://github.com/opencontainers/runtime-spec/pull/1286 [2]: h
140.
▲
by
cyphar
11mo ago
On the other hand, it can be a grave mistake to confuse how things should be with how things are. Activists and whistleblowers should not act with the blind assumption that laws will protect them and that "minor" hurdles to law en
141.
▲
by
cyphar
11mo ago
Not if you use git submodules, which is how most people would end up using such a scheme in practice (and the handful of people that do this have ended up using submodules). Go-style vendoring does dump everything into a directory but that
142.
▲
by
cyphar
11mo ago
I agree, that is what I talk about in the second paragraph! ;)
143.
▲
by
cyphar
11mo ago
rpm and dpkg both provide mechanisms to run scripts on user machines (usually used to configure users and groups on the user machine), so this aspect is not an NPM-specific. Rust has the same thing with build.rs (which is necessary to find
144.
▲
by
cyphar
11mo ago
Rightly or wrongly, large companies are very averse to using AGPL software even if it would cause them very little additional burden to comply with the AGPL. Lots of projects use this cynically to help sell proprietary licenses (the proof o
145.
▲
by
cyphar
11mo ago
I think AGPL/Proprietary license split and eventual move to proprietary is just a slightly less overt way of the same "freeloader" argument. The intention of the original license was to make the software unpalatable to enterp
146.
▲
by
cyphar
11mo ago
You are obviously free to choose to use a proprietary license, that's fine -- but the primary purpose of free licenses has very little to do with contributing code back upstream. As a maintainer of several free software projects, there
147.
▲
by
cyphar
1y ago
The libc syscall wrappers are part of the libc API, but on Linux, syscalls are part of the stable ABI and so you can freely do __asm__(...) to write your own version of syscall(2) and it is fully supported. Yeah, __asm__ is probably not in
148.
▲
by
cyphar
1y ago
This has changed a lot in the past decade -- any modern Fedora box has SELinux enabled by default now and so I would wager the majority of Fedora/CentOS/AlmaLinux/RHEL boxes have SELinux enabled and in enforcing mode. openSUS
149.
▲
by
cyphar
1y ago
Not to mention that most drives start having issues with dead sectors rather than bitflips, and that's (usually) 4K.
150.
▲
by
cyphar
1y ago
Most FDE systems are not authenticated so you would only lose one block (16 bytes for AES). Can this be bad? Yeah, but it's not that bad for data recovery.
More ›