21,070 karma · joined December 16, 2009
Contact me: hn@username.is . The "hn" helps me organize; it's unnecessary, but appreciated.
I'm also currently @groxx@hachyderm.io
It doesn't have to be a disc. It almost certainly does need to be physical.
# transaction has been commented out
# with transaction():
db_models = DBAccess.fetch_records(ids)
db_models[0].yo_mama_fat = True
# request ends, data poofs into the ether
tbh if this doesn't fail either immediately (no open transaction == error on modification attempt) or at GC time (if there's some kind of deferred logic), then I'd say this is an extremely bad framework and it does hold a major part of the blame. "You can mutate database-connected objects and sometimes they save back to the DB, sometimes they do not" is not reasonable behavior.(obviously these frameworks exist. quite a few of them. quantity does not in any way imply sanity.)
> 2. DO NOT pass DB models in and out of the DB layer.
Yea, the more I've used "thin" ORMs that give you plain objects, the more I've grown convinced they're the best choice basically all the time. Trying to be magical is cute, but it's guaranteed to be made of spicy unobtanium, and at some point it'll blow up in your face in an extremely convoluted way due to a simple cause that you'll notice is absolutely everywhere and you're just stuck being paranoid forever. There's no need to live like that.
Which works entirely fine in most cases. You're at greater risk of phantom reads and general "stuff that can occur while you hold open a transaction", but if you're not handling that correctly then you're not handling that correctly. It's only a matter of volume, not existence.
... with a clear exception for cases where you do need to truly end a transaction, like if you're relying on some other thread to do something on a different transaction that needs to see your changes, or when you risk a deadlock somewhere due to not releasing your lock. Those are both a risky patterns for a lot of reasons though, and worth avoiding at design-time if at all possible.
Revocation was hard, but it's not like existing systems are solving that in practice either, and you can get a long way by just keeping short leases (which is fine because nothing needs to communicate with any third party).
If passkeys weren't so blatantly DRM-friendly I might like those, but they seem intentionally human-hostile for no good reason at all.
And every time I think about it for more than a second, I get mad that OpenID got eaten by OAuth.
But in practice it does produce fairly reasonable output fairly often, and if you've been there watching and correcting it you can probably validate the result quite easily. "Re-read everything before" and similar are definitely anthropomorphizing, but that doesn't mean they're ineffective.
They sound fairly human, until you notice the patterns. They sound like they're thinking, until you pay attention.
GitHub constantly feels like features get requested with a one-sentence description, and then people who have never used any other major code review systems go build it without any further assistance or feedback, and eventually it just escapes containment and nobody tells the authors that there's a gigantic pile of bug feedback threads until almost a year later. Ten things get fixed, then another feature breaks out and focus shifts.
False advertising, no human has regretted pizza, even the lactose intolerant.
Practically every other attempt at describing them leans too technical and unfamiliar (stochastic parrot) or too anthropomorphic (even describing them as "not like a human" gets people thinking in terms of humans, like how if I mention that your tongue is in your mouth all the time, using up almost all of the room, feeling your teeth and tasting itself, you're now uncomfortably aware of it and the numerous bumps on the surface).
You need to work from a reference that has both a shared understanding, and does not lead to problematic "if X has Y, and Z is like X, then Z has Y" seemingly-logical derived beliefs. "Spicy autocomplete" is a fairly safe starting point in both ways.
Also I really don't see how this meets "unreadable". It's very plain and normal, at least on mobile. (Which is a compliment to the site)
You can do this now. It works alright sometimes. Other times you're reminded that this is largely just reading tea leaves, and you're trying very hard to separate anecdotes from data and not anthropomorphize it.
if someone is accused of something (possibly retroactively), any of those may be illegal (under specific details etc). if not, then... am I going to be required to never delete anything just in case?
wiping the device before carrying it across the border seems essentially identical to me. like, saying "you can't wipe it when searched" would also imply "you can't have an empty device when crossing because it may have been wiped before the search to avoid having your data searched" since people can (and often do) do that for exactly that reason.
that may very well be what they want / what they are trying to legally allow during searches, but it also seems like it'd raise a hell of a lot more outrage. it's essentially claiming all citizens are under full legal hold all the time, if they ever intend to leave the country for any length of time.
As evidence, I point to the massive number of mostly-LLM-generated LLM-sandboxing projects. Practically every day, I see a new 100k+ LoC project to make agentic coding safe, with shiny emoji-and-badge-encrusted readmes...
... and no issues, no forks, and usually no new commits after the first two weeks. Try to use one and you'll quickly see they're all extremely bug-ridden (one of the few constants with LLM code). And some have stood the test of time and have ten thousand issues that are mostly regressions that were once fixed but come back every other week. But they keep popping up rapidly!
There seems to be somewhat of an upswing lately though. Federation is cool again, and many of the implementations active now seem much more stable, instead of weird half-research projects that killed themselves by ignoring the real world too much (which was sometimes true to their goals, which is fine but unfortunate).
But it is extremely simple to make a custom vet-like tool, because it's a trivial binary wrapper around the analysis framework, which is first-party (though it's structurally pretty limited by design, and won't handle all linting needs): https://cs.opensource.google/go/go/+/refs/tags/go1.26.5:src/...
I don't agree. At all. Existence and utility are not the defining characteristics of "open source" in roughly any reasonable definition. "Open weights" is descriptive and more than good enough, just use that.
Open weights can sometimes get additional training, but you can't remove existing training, so there kinda isn't a fair claim to "just train it to be [nationality]". That would need "real" open source so you can train a realistically-equivalent model from the ground up.
I'm somewhat boggled that json5 hasn't grown to be more of a thing.