HNHacker News
TopNewBestAskShowJobs

CaliforniaKarl

10,033 karma · joined March 4, 2016

Hello! I work at Stanford University, at the Stanford Research Computing Center, as an HPC sysadmin.

I have a blog: https://karl.kornel.us/

My HN handle is also my Twitter handle.

My work email is a!k!kornel@stanford,edu (with ! removed and , corrected).

submissionscomments
CaliforniaKarl··on Return of Chinese astronauts delayed after spacecraft struck by debris
It's important to remember how difficult Space is. I'm not saying we shouldn't do it, but it's not easy.
CaliforniaKarl··on Bringing NumPy's type-completeness score to nearly 90%
I've recently been writing a Python SDK for an internal API that's maintained by a different group. I've been making sure to include typing for everything in the SDK, as well as attempting to maximize unit test coverage (using mocked API responses).

It's a heck of a lot of work (easily as much work as writing the actual code!), but typing has already paid dividends as I've been starting to use the SDK for one-off scripts.

CaliforniaKarl··on Bringing NumPy's type-completeness score to nearly 90%
> Let’s take a pause here for a second - the ‘CanIndex’ and ‘SupportsIndex’ from the looks are just “int”.

The PR for the change is https://github.com/numpy/numpy/pull/28913 - The details of files changed[0] shows the change was made in 'numpy/__init__.pyi'. Looking at the whole file[1] shows SupportsIndex is being imported from the standard library's typing module[2].

Where are you seeing SupportsIndex being defined as an int?

> I have a hard time dealing with these custom types because they are so obscure.

SupportsIndex is obscure, I agree, but it's not a custom type. It's defined in stdlib's typing module[2], and was added in Python 3.8.

[0]: https://github.com/numpy/numpy/pull/28913/files

[1]: https://github.com/charris/numpy/blob/c906f847f8ebfe0adec896...

[2]: https://docs.python.org/3/library/typing.html#typing.Support...

CaliforniaKarl··on Uv overtakes pip in CI
I'm not a Rustacean, but I'll tell you what merited me installing uv (via its MacPorts package) last week.

I had decided to do something via a one-off Python script. I wanted to use some Python packages for the script (like `progressbar2`). I decided to use Inline Script Metadata[0], so I could include the package dependencies at the top of the script.

I'm not using pipenv or poetry right now, and decided to give uv a try for this. So I did a `sudo port install uv`, followed by a `uv run myscript.py --arguments`. It worked fine, making & managing a venv somewhere. As I developed the script, adding & changing dependencies, the `uv run …` installed things as needed.

After everything was done, cleanup was via `uv cache clean`.

Will I immediately go and replace everything with uv? No. As I mentioned in another post, I'll probably next look at using uv in my CI runs. But I don't feel any need to rush.

[0]: https://packaging.python.org/en/latest/specifications/inline...

CaliforniaKarl··on Uv overtakes pip in CI
TBH I feel the same. And for development on my laptop, that seems fine. For the Python package I'm working on how, a single run of pytest takes less than five seconds.

Where things get annoying is when I push to GitHub and Tox runs through GitHub Actions. I've set up parallel runs for each Python version, but the "Prepare Tox" step (which is where Python packages are downloaded & installed) can take up to 3 minutes, where the "Run Tox" step (which is where pytest runs) takes 1½ minutes.

GitHub Actions has a much better network connection than me, but the free worker VMs are much slower. That is where I would look at making a change, continuing to use pip locally but using uv in GitHub Actions.

CaliforniaKarl··on Tell HN: CrowdStrike Falcon users, check for excess KernelModuleArchiveExt files
Unfortunately, no.

From what I've seen, CrowdStrike Falcon installations contain both the BPF components and the kernel module. (I think you can tell which one you're using: if falcon-sensor is running, it's the kernel module; if falcon-sensor-bpf is running, it's BPF.)

I manage systems running Debian, Ubuntu, RHEL, and Rocky. Newer and older, kernel and BPF. And unfortunately, this issue is present across all of them.

CaliforniaKarl··on Download all of your GitHub data
[2018]
CaliforniaKarl··on Stocks Can Be Quietly Stolen from Your IRA
Ah, you have experienced ACATS! If interested, you can read more about it here: https://www.bitsaboutmoney.com/archive/how-acats-transfers-w...
CaliforniaKarl··on Unchecked and Unaccountable: How DOGE Jeopardizes Americans' Data
Hence making sure to call out any time information is leaked, or bad practices are followed.
CaliforniaKarl··on Unchecked and Unaccountable: How DOGE Jeopardizes Americans' Data
Before I started college I had to create an account in University systems. Doing so involved making a telnet connection to a random server, and providing my Social Security Number.

That was fine then. It is no longer fine. Things change.

CaliforniaKarl··on Linux 6.18 Will Fix Lockups When Systemd Units Read Lots of Files
This seems to me to be a cgroup issue, not a systemd issue, though systemd's pervasive use of cgroups make it the most-obvious trigger.
CaliforniaKarl··on Hundreds plunge into Chicago River in first open-water swim in nearly a century
For those who don’t believe it, I strongly recommend that everyone take the Shoreline Sightseeing 75-minute Architecture Tour, starting at Michigan Ave., just downriver from the Apple Store. It takes you a little up the North branch of the river, and more along the South branch.

The tour’s route overlaps the swam route, so you’ll be able to see the river’s cleanliness yourself. When I took the tour in May, the river was great! I’m really happy to see it so clean.

CaliforniaKarl··on History of Telecommunications T-Carrier
The company I worked for in the 2000s had both kinds of T1: They had a single CAS (channel-associated, or "robbed bit", signaling) T1 from one carrier, an two PRI (ISDN) T1s from another carrier. The two PRI T1s only had one channel for signaling, and 47 channels for voice calls.

Our block of phone numbers (we had a block of 500 or 1,000 numbers) was tied to the PRI T1s; for the CAS T1, we were allowed to use our number block as the "calling party" number for outgoing calls. If the PRI T1s went down folks wouldn't be able to call us, but we could call them and the called parties wouldn't notice any difference.

CaliforniaKarl··on Philips announces digital pathology scanner with native DICOM JPEG XL output
Ugh, Pathology image processing is really annoying.

IF Philips is going to stick to the DICOM format, and not add lots of proprietary stuff, _and_ it's the format that it uses internally, then this will be good.

For example, folks can check out OpenSlide (https://openslide.org) and have a look at all the different slide formats that exist. If you dig in to Philips' entry, you'll see that OpenSlide does not support Philips' non-TIFF format (iSyntax), and that the TIFF format is an "export format".

If you have a Philips microscope that uses iSyntax, you are very limited on what non-Philips software you can use. If you want files in TIFF format, you (the lab tech) have to take an action to export a side in TIFF. It can take up a fair amount of lab tech time.

Ideally, the microscope should immediately store the images in an open format, with metadata that workflow software can use to check if a scanning run is complete. I _hope_ that will be able to happen here!

CaliforniaKarl··on Waymo has received our pilot permit allowing for commercial operations at SFO
I certainly hope so. And if yes, I imagine people are gonna start using it as a transfer point, to take a Waymo from the peninsula to SF.
CaliforniaKarl··on Waymo has received our pilot permit allowing for commercial operations at SFO
Waymo does not have YouTube sync, but they do have Apotify sync.
CaliforniaKarl··on Stepping Down as Libxml2 Maintainer
And see also this LWN article: https://lwn.net/Articles/1025971/
CaliforniaKarl··on Investigating the Nvidia AI GPU Black Market [video]
The video's title is "THE NVIDIA AI GPU BLACK MARKET | Investigating Smuggling, Corruption, & Governments", which was slightly too long.
CaliforniaKarl··on PuTTY has a new website
See https://news.ycombinator.com/item?id=44558328 and https://news.ycombinator.com/item?id=44579265 for background.
CaliforniaKarl··on Mouthguards that flash red with head impacts to be used at Rugby World Cup
It could be that I’m focusing more on Union than League. I’m on the bus and searchability is limited, the example I was going to give (https://youtu.be/JjLIetqAP6U) is Union :)
CaliforniaKarl··on Mouthguards that flash red with head impacts to be used at Rugby World Cup
I’m curious, what’s your awareness level of Rugby (Union or League), compared to sports in the US, or soccer worldwide?

I only have cursory knowledge, but seeing a number of videos of player/ref interactions make me think that the authorities are interested in having a game that is both physical and cognizant of the possibility of long-term injury. The players are not wearing helmets, and the refs are OK with using video review (with the videos playing out on the stadium screens) for all to see. It’s very different from US football or worldwide soccer/football.

CaliforniaKarl··on Perplexity is using stealth, undeclared crawlers to evade no-crawl directives
Sounds like an ad for OpenAI, since Cloudflare reported how OpenAI is "following the rules".

Personally, I'm now less interested in using Perplexity, and more interested in using an OpenAI product.

CaliforniaKarl··on I tried living on IPv6 for a day
Out of curiosity, I had a look at one of our service's login nodes, to see where SSH connections were originating from off-campus. What I found was that approximately 30% were over IPv6.

Anecdotally, during weekday working hours, the percentage of IPv6 is higher than (typically over 50%).

CaliforniaKarl··on I tried living on IPv6 for a day
Ah, thanks for posting that, I was wondering how things were going there.
CaliforniaKarl··on When Flatpak's Sandbox Cracks
That reminds me of something iOS is doing (though I don't know when it was introduced).

An app wanted permission to my photos. In addition to the normal "Allow" and "Deny" options, I was also given the option to allow a subset of photos. I chose that option, and was given the normal photos UI, as if I was selecting a set of photos to share or delete. I guess in the back-end, iOS constructed a new photos library consisting of just the ones I selected.

It was cool! And it's good to see things at least one of the things you describe is being shown to a large number of folks. Hopefully that'll drive momentum to wider adoption.

CaliforniaKarl··on Programmers aren’t so humble anymore, maybe because nobody codes in Perl
One thing I wish other languages had was Perl's taint mode: Once enabled, input coming from the outside was "tainted", along with anything you explicitly marked as tainted. If a tainted variable was used to populate another tainted variable (such as by concatenation), the result itself was tainted. If a tainted variable was used in certain ways (such as with the `open` call), the program crashed. The primary way to remove a taint was by running the variable through a regular expression, and using the captured matches (which would not be tainted).
CaliforniaKarl··on Futurehome smart hub owners must pay new $117 subscription or lose access
I think it’s worth noting that the company which is charging the subscription fee is not the same company that sold the smart hubs: Futurehome declared bankruptcy in May; this fee is being charged by its successor.
CaliforniaKarl··on Performance and telemetry analysis of Trae IDE, ByteDance's VSCode fork
If you signed a Nondisclosure agreement with your employer, and you use—without approval—a tool that sends telemetry, you may be liable for a breach of the NDA.
CaliforniaKarl··on More than you wanted to know about how Game Boy cartridges work
See also the Ultimate Game Boy Talk from 33c3: https://www.youtube.com/watch?v=HyzD8pNlpwI
CaliforniaKarl··on Linux and Secure Boot certificate expiration
Trusted timestamp services. https://en.wikipedia.org/wiki/Trusted_timestamping

Microsoft's Authenticode has been doing this for a long time, allowing a signature to be considered as valid long after the signing certificate expired.

https://learn.microsoft.com/en-us/windows/win32/seccrypto/ti...

← PreviousPage 3 of 34Next →