HNHacker News
TopNewBestAskShowJobs

brewmarche

498 karma · joined August 5, 2018

submissionscomments
brewmarche··on Microsoft agentically ports Copilot runtime to Rust for $120K
Just checked it and I underestimated. Just before the split it was at 54k LOC: <https://github.com/dotnet/runtime/blob/b96f3cc738f7fca9474fb...>

I’ve also read that a first version of the file came from a Common Lisp to C++ code generation step: <https://news.ycombinator.com/item?id=23295041>

brewmarche··on Microsoft agentically ports Copilot runtime to Rust for $120K
Until recently the .NET garbage collector used to be a single 30,000+ line C++ file. And it was maintained by one person if I remember correctly.
brewmarche··on Small programming tricks
Didn’t know about that one, and can’t find any references, but works in my fish

I’ve always used Ctrl+U, it’s an Emacs shortcut, so it works in many shells and other prompts (especially since readline supports it) by default.

(For example Ctrl+Opt+- doesn’t seem to work in the Python REPL whereas Ctrl+U does.)

brewmarche··on We got admin access to Baseten's production GitHub
Yeah I have seen this issue a few times. If you use Docker build arguments that way add `--provenance=false` to get rid of all that build metadata. Build secrets are still better since they allow you to scope the secret inside of the Dockerfile. Also, the metadata can be useful to inspect images.
brewmarche··on Why is the x86 undefined instruction called ud2? Why 2?
I thought MS-DOS had special handling for A: and B: since it allowed you to copy from A: to B: even with just one floppy drive.
brewmarche··on Asahi Linux on M3
Apologies, I focused on LLVM as a whole. You are right about clang (and I didn’t know about the arm64 backend)
brewmarche··on Asahi Linux on M3
They asked about ‘originated’ in particular.
brewmarche··on Asahi Linux on M3
Swift comes to mind, and this website has more https://opensource.apple.com/projects/ (it lists WebKit, but I guess they count WebKit after it split from KHTML, I’d agree with you there)

Also, Bonjour originated at Apple and it is cross-platform, although Avahi probably is more popular

CUPS is associated with Apple as well, but it seems that it also did not originate there

brewmarche··on .gitignore Everything by Default
https://github.com/github/gitignore/blob/main/Global/macOS.g...
brewmarche··on .gitignore Everything by Default
But they do: https://github.com/github/gitignore/blob/main/Global/VisualS...

You need to merge the relevant ignore files to create one specific for you, so if you use VSCode on macOS VisualStudioCode.gitignore (e.g., .vscode) + macOS.gitignore (e.g., .DS_Store). There are files for other OSs and editors as well. Technically their README says that the Global folder is intended for user-specific ignore files. But you can still use them for the repo .gitignore.

There is also this API which you can curl: https://gitignore.io/api/macos,vscode

Some of the templates seem to be identical, but I think they are not in sync.

brewmarche··on Ask HN: Who wants to be hired? (September 2026)

  Location: Germany (UTC +1/+2), EU citizen
  Remote: preferred
  Willing to relocate: no
  Technologies: C# and previously C++ and Java, prefer functional style and privately dabble with F# and Haskell. I know SQL, Azure, Docker, high performance computing (Monte Carlo simulations), see also CV
  CV: https://stash.ldr.name/wwtbh/rcv-202609-vfay7k0zano.pdf
  Email: see CV
I work in mathematical finance so a lot of domain knowledge in that area (derivatives, pricing, probability theory).

I am looking for work in other domains as well.

Happy to provide you with a full CV personally.

brewmarche··on A CVE Dispute
One could argue that this is not an issue with pip, the software, but of the index used. I mean, if you control both index and extra-index there is no problem (and one solution to this is to use your own mirror with a set resolution order). This could very well be addressed in PyPI, for example NuGet allows to reserve package prefixes.

We also do not create a CVE for curl because you can use it to download the wrong bash script. If this was an alert for suspicious usages of pip instead of pip itself, I’d be less critical of it.

brewmarche··on A CVE Dispute
For the attack you mentioned (reusing internal packages in a public repository) prefix reservation is one possible solution. Unfortunately PyPI does not support it.
brewmarche··on A CVE Dispute
Maybe I was too harsh. It’s the CVE in conjunction with its high severity, the maintainers’ decision and the bundling of pip with CPython. In the end what can you do about it as a dev given that the pip maintainers have decided not to fix it? The only option is not to use pip at all (and sure, you can see the CVE as a critique of pip in a way), or discuss with your security team in hope for some exclusion. And since pip or at least ensurepip are part of Python you get a lot of these scan results

E: and if you decide not to use pip I don’t think there’s an official way to remove ensurepip, I typically rm -rf inside of site-packages, it works but doesn’t feel correct

brewmarche··on A CVE Dispute
Yes, I’ve also experienced this kind of attitude. Some scanning tools can detect that certain CVEs do not apply because the specific functionality is not used.

I hope your team was OK with you uninstalling the VMware package manually (this is actually not a bad outcome if you don’t use that package)

There are also ridiculous CVEs like CVE-2018-20225 for pip, which will not get fixed as that behaviour is by design (but here as well it might be a good idea to strip pip if it’s not used)

brewmarche··on Casey Muratori – The Root of the Root of All Evil – BSC 2026 [video]
In other videos Casey argues against the profile–fix–repeat workflow (I’m not saying that you necessarily meant this by measuring), instead arguing for estimating the theoretical maximum, then trying to get close enough to it. His argument is that the former might push you towards a local minimum without realising that you could do much better
brewmarche··on Asahi Linux Progress Report: Linux 7.2
Aren’t the shortcuts with the command key older than the PC ones (which started out as Shift+Insert etc. actually)? I wouldn’t call that desire to be different (also as mentioned below it has a lot of advantages in a terminal)
brewmarche··on A decades-old bug in Knuth's long division (TAOCP Vol II, Algorithm 4.3.1D)
There’s a funny explanation at the bottom:

> It turns out that only 9 of the first 275 checks that I've sent out since the beginning of 2006 have actually been cashed. The others have apparently been cached. So this change in policy will probably not affect too many people. On the other hand, I don't like to renege on promises, so I shall do my best to find a suitable way to send money to anyone who really prefers legal tender.

brewmarche··on Splitting a Git Commit
The Law Stack Exchange tags answers with the jurisdictions they apply to, but I think that’s the only StackExchange site that allows tags on answers.
brewmarche··on Splitting a Git Commit
These answers are ~15 years apart, so the vote difference is not surprising.

I personally sort by ‘date modified (newest first)’ on StackExchange sites.

brewmarche··on AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
I get scared when I see these string interpolations in GitHub Actions.

Use `env:` instead and just work with environment variables in your shell script.

Yes, you still need to vet your script. Quoting is a common source of problems. Use shellcheck. Do not call eval/source/python/perl/whatever with untrusted input.

But you removed one layer of problems already by not pasting a value into your shell script code directly.

brewmarche··on Moving integer division to floating-point is trivial
DIVSD latency 13–14 cycles, reciprocal throughput 4 cycles

Use this instead of x87’s FDIV

brewmarche··on As a Windows user, it's a surreal way to install a program
> but the decision to not ship with a regular installation UI in OG macOS X came with the tradeoff of not cleanly _uninstalling_ software either. config files etc were always left over.

But they have regular installers, they are called .pkg and look like a wizard. Programs distributed as a single .app don’t really need them though.

brewmarche··on Lost my phone at the office. Claude suggested tracking Bluetooth signal strength
I remember years ago before LLMs my colleague told me he was impressed by my Google-fu. I was just as speechless whenever I saw him type his search queries which led nowhere. Apparently it’s a skill
brewmarche··on Fixing a bug with byte order marks
PS: Did some research and while it is true that a ZWNBSP will break up ligatures in many systems, that’s not its intended use. It’s there to prevent line breaks (up to Unicode 3.2), nowadays only kept for compatibility outside of BOM. Modern Unicode uses U+2060 WORD JOINER to express the same intention.

The old Unicode rules for ZWNBSP are also quite tricky: you are not supposed to ignore the first ZWNBSP if you already know the encoding. Which means to express an initial actual ZWNBSP you need to write two of them if the encoding is unknown to the receiver and only one of them if known.

> Where the character set information is explicitly marked, such as in UTF-16BE or UTF-16LE, then all U+FEFF characters, even at the very beginning of the text, are to be interpreted as zero width no-break spaces. Similarly, where Unicode text has known byte order, initial U+FEFF characters are also not required and are to be interpreted as zero width no-break spaces. For example, for strings in an API, the memory architecture of the processor provides the explicit byte order. For databases and similar structures, it is much more efficient and robust to use a uniform byte order for the same field (if not the entire database), thereby avoiding use of the byte order mark. Systems that use the byte order mark must recognize that an initial U+FEFF signals the byte order; it is not part of the textual content. It should be removed before processing, because otherwise it may be mistaken for a legitimate zero width no-break space. To represent an initial U+FEFF ZERO WIDTH NO-BREAK SPACE in a UTF-16 file, use U+FEFF twice in a row. The first one is a byte order mark; the second one is the initial zero width no-break space.

— Unicode 3.0 Standard, p. 325 <https://www.unicode.org/versions/Unicode3.0.0/ch13.pdf>

(With modern Unicode you can write WJ or ZWNBSP,WJ and there is no problem)

brewmarche··on Fixing a bug with byte order marks
No, a ZWNBSP that’s not at the start is just a regular ZWNBSP. Can be used to break up ligatures for example
brewmarche··on Log is non-monotonic in PHP and Lua
> The usual "0.1 + 0.2 != 0.3" is _not_ imprecision.

Correct. That’s using the wrong base. Decimal floating point doesn’t have that problem.

brewmarche··on Self-contained highly-portable Python distributions
I install these Python builds into distroless containers with uv python install and it just works. (If you try this with Google’s images, use gcr.io/distroless/cc, libgcc/libstdc++ is needed for some extensions, like numpy)
brewmarche··on Ruff v0.16.0 – Significant new updates – 413 default rules up from 59
FWIW, ruff sees your line comment and keeps each item on its line. It only adds a trailing comma and additional space.

It also does not collapse lines when there’s a trailing comma.

Your output seems to be from black. IMO it’s insane to collapse lines when there are line comments.

  $ uvx ruff format --diff formatting.py
  --- formatting.py
  +++ formatting.py
  @@ -1,8 +1,4 @@
  -no_comma  = {
  -    "x": 3,
  -    "y": 42,
  -    "z": 2
  -}
  +no_comma = {"x": 3, "y": 42, "z": 2}
  
  with_comma = {
       "x": 3,
  @@ -12,6 +8,6 @@
  
  comment = {
       "x": 3,
  -    "y": 42, # Answer to the Ultimate Question!
  -    "z": 2
  +    "y": 42,  # Answer to the Ultimate Question!
  +    "z": 2,
   }
  
  1 file would be reformatted
(I intentionally switched to double quotes since that really is a stylistic choice in Python, you can escape in both, and if you use double quotes inside of single quotes ruff leaves it as-is)
brewmarche··on Em dashes are amazing
That’s how we distinguish the Cox–Zucker Machine [1] from other Cox-Zucker Machines (scnr)

[1]: https://en.wikipedia.org/wiki/Cox–Zucker_machine

Page 1 of 9Next →