HNHacker News
TopNewBestAskShowJobs

banthar

153 karma · joined October 27, 2011

submissionscomments
banthar··on Frankenstein's `__init__`
Python context managers somewhat require it. You have to create an object on which you can call `__enter__`.
banthar··on I Like and Use Global Variables
You can make globals thread safe by using thread locals. You can make methods using them reentrant by carefully saving and restoring state. What about exceptions? Any exception from `process()` is going to leave this global state in a total mess.
banthar··on So Google's Gemini Doesn't Like Python Programming and Sanskrit?
100% agree with the AI on @cache decorator. It's a footgun and should never be recommended without a proper disclaimer. Unless it's a simple "single shoot" script, you really do not want the cache global like that.
banthar··on Flatpak is not the future (2021)
Zotero Flatpak comes with 4 year old Firefox binary and full access to your home directory.

The compromise currently being made here is your security.

banthar··on GCC always assumes aligned pointer accesses (2020)
This is how all undefined behavior works. It seems to be working now but breaks with new CPU, GCC version or on wrong moon phase.

"-Wcast-align=strict" will work in this but not all cases - that's why we have UBSAN:

    $ gcc -fsanitize=undefined test.c
    $ ./a.out 
    test.c:6:6: runtime error: store to misaligned address 0x55e4007adeb1 for type 'int', which requires 4 byte alignment
    0x55e4007adeb1: note: pointer points here
     00 00 00  01 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  51 00 00 00 00
banthar··on Intent to approve PEP 703: making the GIL optional
You can pin your JVM process to a single core and will effectively get Python multithreading model.
banthar··on String length functions for single emoji characters evaluate to greater than 1
Defining string as a sequence of unicode codepoints is the mistake.

Nobody ever cares about unicode codepoints. You either want the number of bytes or the width of the string on screen.

UTF-32 codepoints waste space and give you neither.

banthar··on OO in Python is mostly pointless
Object oriented programming is not about defining classes. It's about using objects. You don't have to define new classes to do OOP. Just use existing classes and objects polymorphically!

    url_layout.format()
    resp.raise_for_status()
    resp.json()
    session.add()
All those calls are dynamically dispatched - the essence of object oriented programming. This is what allows you to not worry about: * which string implementation `url_layout` uses * which HTTP protocol, encryption, authentication, chunking `resp` uses * what database is connected to `session`

You cannot avoid using objects - that's how all modern operating systems work.

Using classes without the need to call them polimorphically just as a nice namespace for methods is a separate issue.

banthar··on Deprecating scp
First issue mentioned: CVE-2019-6111 is an example of such attack.
banthar··on Deprecating scp
The problem with scp is that the trust also needs to go the other way. There is a lot of ways ssh server can trick the client into doing bad things on your local machine.
banthar··on Prefer Fakes over Mocks
Mocks have to be updated and fixed every time you do any meaningful changes in production code. Good fake can be reused in many tests and will keep behaving like a real thing with minimum maintenance. Much less complex than maintaining hundreds of mocks each implementing different parts of the interface.
banthar··on Microsoft Put Off Fixing Zero Day for 2 Years
Extra bytes at end of file will be ignored by most formats. You generally don't want to depend on file length.
banthar··on What programmers need to know about encodings and charsets (2011)
There is nothing you can do with text file with unknown encoding but treat it as an array of bytes.

If you start guessing the encoding, at best it won't work in some cases, at worst you are introducing security vulnerabilities. You can try, but there is just no way to do it right.

http://michaelthelin.se/security/2014/06/08/web-security-cro...

banthar··on JSMpeg – Decode It Like It's 1999
MPEG4 the video codec is https://en.wikipedia.org/wiki/MPEG-4_Part_2

mp4 the media container is https://en.wikipedia.org/wiki/MPEG-4_Part_14

MPEG-2 part 4 is some conformance testing specification.

banthar··on Did Finland’s basic income experiment work? [video]
What kind of business is that? How are you funding it? 18000 euros is rather insignificant on business scale.
banthar··on Did Finland’s basic income experiment work? [video]
> For example, under a proper UBI I’d quit my job and start a business. Under this time limited experiment I never would have.

What business would you start that takes more than 2 years to validate but takes basically no funding?

banthar··on 9999999999999999.0 – 9999999999999998.0
Constant expressions are evaluated at compile time. Compilation would suffer any eventual performance penalties. This probably makes the compiler simpler - no need to implement different arithmetic for different types & no need to guess the types.

The dangerous bit is, that just extracting a variable from constant expressions might change the result slightly. That should not be a problem, unless you are depending on exact values.

banthar··on HTTP-over-QUIC will officially become HTTP/3
If you do SCTP in user space with UDP encapsulation, most of its benefits disappear (and you have to do that - also because of Windows).

It's standard only on paper. There is only one significant user space implementation (usrsctp). It's used both by Chrome and Firefox. I don't think it has much use outside of that. And, I don't think other browsers implement data channels (which require SCTP).

Browser implementations will probably never have to interact with kernel implementations (which are not really used outside of telecoms). There is really no reason to make them talk the same protocol. It's likely better to use two different protocols tuned to those specific uses:

https://tools.ietf.org/html/draft-joseph-quic-comparison-qui...

They will probably replace SCTP with QUIC also in WebRTC:

https://w3c.github.io/webrtc-quic/

banthar··on How the JVM compares strings on x86 using pcmpestri
PEP-393 is a stupid compromise. They couldn't choose between UCS-2 and UCS-4, so they are using both. They are wasting tons of CPU cycles converting between them and single character outside of range doubles the size of string.

I don't fully understand the use case for extracting codepoints from strings, but they could have just added Java-like: codePoints and keep returning code units from old methods. This is CPU and memory efficient and 100% backwards compatible.

I think the problem is the same could have been done in Python 2 (with UTF-8) that would mean less reasons for Python 3.

banthar··on How the JVM compares strings on x86 using pcmpestri
Even outside Web, you still have mostly-ASCII:

* filenames

* identifiers

* config files

* text protocols

* host names, email addresses

* embedded scripts (including SQL and OpenGL shaders)

* command line interfaces

* translations for languages using Latin alphabets

I don't think 2/3 size reduction for some languages will offset the cost in all the other places.

banthar··on Using LD_PRELOAD to cheat, inject features and investigate programs (2013)
I've used both LD_PRELOAD and Detours and I like LD_PRELOAD so much better. LD_PRELOAD just needs single standard shared library and one environment variable. With Detours you have to: inject code into executable, stop threads, worry about races, protecting/unprotecting memory. The way it's implemented also feels like a big hack. The hooks are injected into first few instructions of hooked methods. Some system functions even deliberately leave blank space there. I'm yet to encounter a use case where all this complexity is useful.
banthar··on Hello, I’m Mr. Null. My Name Makes Me Invisible to Computers
I'm guessing this mostly happens during serialization to and from strings. One programmer does String.valueOf(x) instead of x.toString() to prevent NullPointerExceptions. This works pretty well until the next guy does x == null || x.equals("null") because "null"s pop up in UI. At this point this is irreversible as nobody can tell what is null and what is "null".
banthar··on 500 Lines or Less
From: https://github.com/aosabook/500lines/blob/master/ci/code/hel...

    s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    s.connect((host, port))
    s.send(request)
    response = s.recv(1024)
    s.close()
Is that correct use of TCP? It seems to rely on response not being fragmented.
banthar··on Examining IPv6 Performance
Are you talking about changing source address in IP header? Most ISPs will drop such packets: https://tools.ietf.org/html/rfc3013#section-4.3
banthar··on Onion names reserved by the IETF
That's onion -> web. If you are connecting to onion address, your packets do not enter plain text internet. Unless you are using some sort of "enter node".
banthar··on Onion names reserved by the IETF
Isn't SSL on .onion domains redundant? It makes sense for onion -> open web, but shouldn't onion -> onion connections be already both authenticated and encrypted?
banthar··on Alternatives to Regular Expressions
Lets try an example. Extract first link address from https://news.ycombinator.com/.

As DOM query:

    document.getElementsByClassName("title")[0].parentElement.getElementsByTagName("a")[1].href
This will break:

* When title element no longer has "title" class.

* When title is no longer a sibling of link.

* When link is no longer 2nd link of its parent.

As regular expression:

    document.documentElement.innerHTML.match('td class="title">.*a href="([^"]*)"')[1]
This will break:

* On any white space change.

* On any new attributes on td or a.

* When ' is used instead of "

* When href includes escaped "

* In most cases when DOM query will break.

Many of those can happen without any server-side changes. It will sometimes works sometimes won't - making it hard to test.

There are cases when regular expression will break less often than DOM but DOM is easier to reason about, more predictable and has less corner cases.

banthar··on Immutable annotations for Java
You can create immutable classes "by hand". Just make all fields final and either primitive or reference to immutable type.

This framework just makes it a little bit shorter to type as it automatically generates some boilerplate code.

banthar··on Immutable annotations for Java
This is just what programmers do. They all have irresistible urge to write their own meta language on top of what they are using.

C programmers do that with pre-processor. C++ programmers do that with templates and pre-processor. Java programmers do that with annotations.

banthar··on Things Rust shipped without
You can't. This is a GCC extension:

https://gcc.gnu.org/onlinedocs/gcc/Labels-as-Values.html

Page 1 of 2Next →