Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
indygreg2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
Mercurial, SHA-1, and Trusting Version Control
(gregoryszorc.com)
2 points
by
indygreg2
10y ago
|
0 comments
32.
▲
by
indygreg2
11y ago
I help run Mozilla's version control infrastructure and the problems described by the GitHub engineer have been known to me for years. Concerns over scaling Git servers are one of the reasons I am extremely reluctant to see Mozilla sup
33.
▲
by
indygreg2
11y ago
Mercurial verifies SHA-1 on every read and write. The code is in revlog.py in revision() and _addrevision() (search for "checkhash"). This is a lower level than changegroup processing, which is where exchange occurs. Since you are
34.
▲
by
indygreg2
11y ago
10+ years is a long time to steward a project. Most projects don't even live that long! Transitioning away after 10+ years is a sign of several positive things: * Creating a successful project that lasts 10+ years * Having the persever
35.
▲
by
indygreg2
11y ago
Twitter is maintaining an internal fork/distribution of Git with patches to attempt to make it scale to their needs. It is described a bit at http://git-merge.com/videos/scaling-git-at-twitter-wilhelm-b... . But ev
36.
▲
by
indygreg2
11y ago
I don't disagree. Although, for the case where you want to copy/move things across repositories, monolithic repositories still have the advantage that history is more easily preserved. Although you can argue that proper submodule
37.
▲
by
indygreg2
11y ago
Instead of cloning just one of your non-monolithic repositories and expecting it to "just work" I need to answer: - How does the build system integrate multiple, discrete repositories into a unified system? - What are the dependen
38.
▲
by
indygreg2
11y ago
Thought experiment: the entire github.com URL space is a single repository. Each organization/user has a top-level directory and projects/forks exist under them. Does that prevent/encourage code sharing? Why or why not?
39.
▲
by
indygreg2
11y ago
If your concerns are driven by resource requirements, then I posit your concerns are driven by limitations of fully distributed version control tools of today. Shallow and/or narrow clone (like the Subversion model) limit the amount
40.
▲
by
indygreg2
12y ago
We know. One of those things that was established 10+ years ago and has a lot of built-up inertia keeping it going. It's part of my job role at Mozilla to bring this process into modernity. We're getting there. Slowly. GitHub pull
41.
▲
by
indygreg2
12y ago
It is much easier to bisect linear history than history with merges.
42.
▲
by
indygreg2
12y ago
Except it isn't internal only. Many of Facebook's tools are open sourced. And not in the "throw it over the wall" sense. Their open sourced projects tend to gain traction and get a significant amount of community contrib
43.
▲
by
indygreg2
12y ago
The site is hosted via GitHub pages. Maybe it's not available to you due to the lingering GitHub DoS. If you care to read HTML and can manage to get through to GitHub: https://github.com/indygreg/indygreg.github.co
44.
▲
by
indygreg2
12y ago
I invented the Python bits of the Firefox build system (moz.build files). I learned after I implemented them that Google's internal approach with Blaze was very similar. It felt reassuring that I independently reinvented a similar so
45.
▲
by
indygreg2
12y ago
More back story: https://twitter.com/indygreg/status/545701974671233024
46.
▲
by
indygreg2
12y ago
If you sign in to Chrome, your bookmarks and full browsing history are uploaded to Google's servers. Only your passwords are encrypted locally before being sent to Google. https://support.google.com/chrome/answer&#
47.
▲
by
indygreg2
12y ago
I blogged about this the other day and would love to hear about your experience! http://gregoryszorc.com/blog/2014/10/13/deterministic-and-mi...
48.
▲
by
indygreg2
12y ago
The path towards deterministic builds is definitely not clear. As many in this thread have pointed out, it's a difficult technical problem. The difficulties are multiplied by a project at Firefox's scale. Further complicating matt
49.
▲
by
indygreg2
12y ago
I filed the linked bug and am the technical owner of Firefox's build system. There were efforts made and discussions outside of the linked bug. To say "nothing" was done is just not true. It would be more accurate to say that
50.
▲
by
indygreg2
12y ago
I think you are missing the point. Versioning and package management problems can largely go away when your entire code base is derived from a single repo. After all, library versioning and packaging are indirections to better solve common
51.
▲
by
indygreg2
12y ago
SOA isn't a magic bullet. What if multiple services are utilizing a shared library? For each service to be independent in the way I think you are advocating for, you would need multiple copies of that shared library (either via separat
52.
▲
by
indygreg2
12y ago
Having all code in a single repository increases developer productivity by lowering the barrier to change. You can make a single atomic commit in one repository as opposed to N commits in M repositories. This is much, much easier than deali
53.
▲
by
indygreg2
12y ago
They aim for a completely linear history. They may even have a policy of not allowing merge commits. It is described in various places on the internet. I like https://secure.phabricator.com/book/phabflavor/article&
54.
▲
by
indygreg2
13y ago
I can relate to these comments because when I was a Git user forced to use Mercurial for Firefox development, I initially thought much of the same. I have since come around [1]. Mercurial has come a long way in the last few years. While I u
55.
▲
by
indygreg2
14y ago
Chrome's sync (i.e. sign in to Chrome) uploads the cleartext of your full browsing history to Google by default: http://gregoryszorc.com/blog/2012/04/08/comparing-the-securi... From a privacy perspective Chrome and Silk sound the same. No
56.
▲
by
indygreg2
14y ago
Assuming all the steps in the article are followed, yes, you are correct. I still think any article talking about verifying credentials is obligated to mention that string comparison could be an attack vector. Like I said, it plants a seed.
57.
▲
by
indygreg2
14y ago
If you are going to go through all the effort to do it properly, you might as well use a proper comparison function. If nothing else, it reinforces the knowledge that string comparisons can be part of security (which goes overlooked by many
58.
▲
by
indygreg2
14y ago
The fact Microsoft is the #1 requester isn't a surprise to me. The 2nd most popular search engine probably automatically identifies "bad" content then siphons off this list to Google. If Google had more paid products (that weren't ad driven
59.
▲
by
indygreg2
14y ago
Works great for me in Firefox Nightly. Couldn't notice any difference from Chrome, despite the message saying it works best in WebKit.
60.
▲
by
indygreg2
15y ago
If they keep releasing new versions so rapidly, I may have to switch to Chrome^H^H^H^H^HWindows.
More ›