Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
wyoung2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
wyoung2
6y ago
Fossil is a single executable with low system requirements operating on a single SQLite database file, so it's really easy to chroot. It'll even chroot itself if started as root: https://www.fossil-scm.org/home
32.
▲
by
wyoung2
6y ago
The biggest difference was that write(1) was 1:1, whereas this lets any number of people participate. It's got a bit of formatting control as well, though not full Markdown, alas.
33.
▲
by
wyoung2
6y ago
Yes, chat messages are stored in a table in the SQLite DB backing the repository you're chatting about, which allows you to close the browser window when you need some peace to concentrate on work, then revisit the chat room later and
34.
▲
by
wyoung2
6y ago
Yes. Developers working independently is best for productivity, but sometimes you need to coordinate something, which then brings up the question: what to use? The last time I tried to list it, I came up with over a dozen options, all of wh
35.
▲
by
wyoung2
6y ago
> one must assume those same people using fossil will also want to hide their "imperfect" code too One must not, because if one did, one would be wrong. :) Go read Weinberger. It's $10 on Kindle right now. > Please read
36.
▲
by
wyoung2
6y ago
I don't see why you would bisect in this situation in the first place. The problem's fixed now, as of commit 5. But okay, let's take your example as-is: you determine the "good" point is commit 1, and the ...um, ot
37.
▲
by
wyoung2
6y ago
The whole point of those articles is to compare and contrast.
38.
▲
by
wyoung2
6y ago
It isn't shipped on macOS, and the Homebrew version of Git has it packaged separately. I fired it up on a Git export of a Fossil repo here, and it's missing features of Fossil's web UI timeline view: 1. Cherrypick markers 2.
39.
▲
by
wyoung2
6y ago
You don't even need the temporary files: $ vim ...write, write, write... :w !fossil wiki create "The Foo Article" - :q! Later: $ vim :r !fossil wiki export "The Foo Article" - ...w
40.
▲
by
wyoung2
6y ago
> Windows Vista...components were being developed in private branches. The claim isn't that Microsoft developers on the Vista project used Git and private branches. The claim is that private branches are another form of siloing whic
41.
▲
by
wyoung2
6y ago
Crypto is something best delegated to others. There are a bunch of ways to host Fossil, several of which offer HTTPS proxying: https://www.fossil-scm.org/home/doc/trunk/www/server/index.h...
42.
▲
by
wyoung2
6y ago
A lot of us Fossil users host it on $5 VPSes. It's written in C atop SQLite, so the network is almost always the bottleneck, not the server-side processing speed. sqlite.org and all of the other repos D. Richard Hipp maintains (Fossil,
43.
▲
by
wyoung2
6y ago
> not built by Apple If you hadn't included that restriction, I'd tell you about Numbers. Not all spreadsheet type problems fit into its limitations, but for those that do, it makes you ask "Why don't all spreadsheets
44.
▲
by
wyoung2
7y ago
In large measure, you actually can't, since there's a good chance those repos are behind HTTPS-only these days, and those versions of Git will be linked to ancient versions of OpenSSL that won't even talk to modern TLS implem
45.
▲
by
wyoung2
7y ago
> Fossil...would force me to commit the proverbial 500-line blob all at once Nope. If it were me doing such a thing as you describe, I'd start the work on a feature branch. If I'm working on that repo with other active develope
46.
▲
by
wyoung2
7y ago
> ideology conflates architectural decisions and workflow processes with individual worth No. You start with the ideology based on your local culture and project needs, then you pick the tool that supports your project's needs. This
47.
▲
by
wyoung2
7y ago
> If the people checking all see the valid files ...which will likely contain thousands of bytes of pseudorandom data in order to force the hash collision... > they cannot raise any alarms You think a human won't be able to notic
48.
▲
by
wyoung2
7y ago
If you try to use Fossil 1.37 — the last 1.x release — to clone a repo that has SHA-3 hashed artifacts in it, it says, "server returned an error - clone aborted". Since 1.37 pre-dates this feature, it can't give a more detail
49.
▲
by
wyoung2
7y ago
SQLite can be considerably faster than the filesystem: https://www.sqlite.org/fasterthanfs.html If you think your filesystem-based Git repo is easy to manipulate, go poking around in there, and what you'll find is a be
50.
▲
by
wyoung2
7y ago
> history does not matter if the change was parented in some temporary context It does if it means a big ball o' hackage lands on the public working branch, since it complicates merges, backouts, cherrypicks, and bisects. Git users
51.
▲
by
wyoung2
7y ago
> sometimes I don't care about history and I'm just trying to coordinate developers across timelines The fact that Fossil preserves history does not prevent you from coordinating with people across timelines. It is rather the w
52.
▲
by
wyoung2
7y ago
When is the right time to worry? Maybe wait until someone publishes a practical attack, then wait years for the new code to get sufficiently far out into the world that you can switch to it? I mean, I see you're expressing concern, b
53.
▲
by
wyoung2
7y ago
It only takes one person to raise the flag. Sure, many thousands of people doing blind "git clone && configure && sudo make install" could be burned by a problem like this, but someone would eventually do a diff
54.
▲
by
wyoung2
7y ago
Wow! I wouldn't have guessed that Git had that vulnerability. Fossil solves it easily: creating a new repo involves generating a random project code (a nonce) which goes into the hash of the first commit, so that even two identical com
55.
▲
by
wyoung2
7y ago
It's worth noting that this attack is a property of the Merkle–Damgård hash construction, not of SHA-1 specifically, which means SHA-2 (Git's path forward) is also vulnerable: https://en.wikipedia.org/wiki/Mer
56.
▲
by
wyoung2
7y ago
In addition to D. Richard Hipp's thoughts as HN user SQLite — author also of Fossil, so he oughtta know — I offer these: 1. Keep in mind that Fossil and Git are both applications of blockchain technology, which in this particular pract
57.
▲
by
wyoung2
7y ago
> Furthermore, the evil.c file with the same SHA1 hash would need to be valid C code that does something evil while still yielding the same hash ...and also produce an innocent-looking diff! I mean, you could stuff a bunch of random byte
58.
▲
by
wyoung2
7y ago
> That cute rhetoric will not fool anyone. Well, let's see, the Fossil equivalents are: 1. Do nothing at all for a conversion from the SHA-1 to SHA-3 — yes, 3, not 2 as in Git! — because it's automatic for months now and dead e
59.
▲
by
wyoung2
7y ago
Agreed. Bisecting a deep and complex version history can be a lifesaver, especially under a time crunch. Fossil has bisecting with much the same CLI as Git, for what that's worth.
60.
▲
by
wyoung2
7y ago
> Ammending changes the hash of the commit Not necessarily. Fossil's `amend` command works by adding additional information to the repo that the web UI and commands like `fossil info` look at when building up information intended fo
More ›