HNHacker News
TopNewBestAskShowJobs

cesarb

15,782 karma · joined March 4, 2014

submissionscomments
cesarb··on Nvidia wants to put a watchdog chip next to every AI agent
If you read the whole book, you know it didn't quite work...
cesarb··on Tutoring company tells parents to save their money and 'use AI instead'
> In what world is a square not a rectangle?

In the world of object-oriented programming: https://en.wikipedia.org/wiki/Liskov_substitution_principle#...

cesarb··on Samsung accidentally freezes its smart fridges with a software update
> How else would I change the temperature remotely if it didn‘t?

...why do you need to change the fridge temperature remotely?

cesarb··on Samsung accidentally freezes its smart fridges with a software update
I can imagine one good use: plotting graphs of inner temperature, configured set point, motor on/off status, door open/closed status, and power consumption. But that use case does not require having control of the fridge compressor...
cesarb··on ReBarUEFI: Resizable BAR for almost any UEFI system
It's hard to explain without going into a few low-level details of PCI Express, but let me try.

Most PCI devices expose some memory and/or I/O ports to the CPU. That memory (or I/O ports) is mapped to somewhere in the address space visible to the CPU. Besides the memory and I/O ports, all PCI devices also expose a separate set of configuration registers; among these registers, there are the Base Address Registers (BARs), which configure where the memory or I/O ports is mapped.

Here's an example output from "lspci -vv" for a GPU:

        Region 0: Memory at 7c00000000 (64-bit, prefetchable) [size=8G]
        Region 2: Memory at 7e00000000 (64-bit, prefetchable) [size=256M]
        Region 4: I/O ports at f000 [size=256]
        Region 5: Memory at fca00000 (32-bit, non-prefetchable) [size=1M]
        Expansion ROM at fcb00000 [disabled] [size=128K]
Note that regions 0 and 2 are above the 4GB addressable by old 32-bit CPUs. To be compatible with these old CPUs, this card and many others like it allow the firmware (and/or the operating system) to choose not only where the memory is mapped, but also its size. We can see this in the same "lspci -vv" output for this GPU:

        Capabilities: [200 v1] Physical Resizable BAR
                BAR 0: current size: 8GB, supported: 256MB 512MB 1GB 2GB 4GB 8GB
                BAR 2: current size: 256MB, supported: 2MB 4MB 8MB 16MB 32MB 64MB 128MB 256MB
Older systems which do not understand this extended capability will still treat these regions as fixed size, probably with the first size in this list (256MB for region 0, 2MB for region 2). Newer systems can tell the device to "resize" the BAR to a bigger size, which obviously needs the first region to be placed above the 4GB barrier since it's too big.

Why is this useful? This particular GPU has 8GB of VRAM; it's quite obvious that region 0 is a direct view into that VRAM. When using the maximum BAR size, the CPU can directly read and write anywhere into the VRAM; when using a smaller BAR, the CPU can only see a small window into the VRAM, and has to use less direct methods to access it.

(As an aside: go right now and do a "sudo lspci -vv" on your computer, if you see a Resizable BAR capability which isn't using the maximum size, you can probably gain a bit more speed for free by going into the BIOS and enabling "Resizable BAR" and/or "Above 4G decoding". If you can't find these options, well, AFAIU that's what this project is all about..)

cesarb··on AMD's random number generator can't generate a 0?
> Yes, /dev/(u)random is supposed to do that, [...] getrandom() is often times suggested, but alas isn’t a standardized function, i.e. it’s not part of the POSIX specification.

Is /dev/random or /dev/urandom part of the POSIX specification?

cesarb··on Looking forward to Git 2.56 – and 3.0
Length extension attacks are not an issue for git, because every object has two fields in its header, which is prepended to the object before hashing: the object type and the length in bytes.
cesarb··on Looking forward to Git 2.56 – and 3.0
> Good, are there (m)any other plans to ditch the slow files and use proper database?

The filesystem is a proper database, just not a relational one.

Linus focused heavily on performance when he wrote git; he used the filesystem because, as the main Linux kernel maintainer, he knew that the Linux VFS and filesystems were fast enough for these use cases.

(It's the use cases that have changed; it was not expected back then to have more than a few hundred refs in a single repository.)

cesarb··on Android 17 is the first since 3.x to add new APIs without releasing to the AOSP
> Are all of these unsuitable [0]? [...] I looked it up and people had problems selling to Brazil [1] but there are various listings that offer to ship.

Do these phones have ANATEL certification? Because if they don't, they will be rejected by customs. It's not simply a case of the item being held until you pay a 60% import tax.

cesarb··on Android 17 is the first since 3.x to add new APIs without releasing to the AOSP
> GrapheneOS's goal is privacy for the world and that's achieved through secure devices.

Perfect is the enemy of good. What's better for privacy, an old but inexpensive smartphone running Android 11, or the same smartphone running an up-to-date third-party rebuild of Android 16 or newer with as many privacy-improving bells and whistles as the hardware can support?

> Soon there will be two different phone brands which you can install it on.

...will they be available in my country (Brazil)? I don't think I've ever seen a Google Pixel phone in person.

cesarb··on I don't like passkeys
> Heh, in the security world, this shows how your traditional metal key is "something you know" (like a password) because it can be copied and many people can know it at once!

If you have a photo of a traditional metal key, you can duplicate it. AFAIK, there's also a numeric representation of the height of each position on the key; if you know that number, you can duplicate the key. A traditional metal key is more like a password than most people think.

cesarb··on I don't like passkeys
> Same as traditional physical keys, you don't have a single key, you have multiple ones [...]

I have multiple identical ones.

> [...] and can go to the local locksmith and get another one in minutes.

Can I go to the digital equivalent of a locksmith (like a backup software) and duplicate my passkey? Can I do that with only my passkey in hand (without having to do anything to the corresponding lock, or having to contact its issuer), like I recently did with a physical key?

cesarb··on I don't like passkeys
> what good is a phone if it isn't on a network?

1. It might be on a voice network but not on a data network; for instance, if you don't have a data plan.

2. Modern smartphones are actually a hybrid of a traditional cell phone and a traditional PDA, and you might be using it for the PDA part.

cesarb··on I don't like passkeys
> > What if the computer you want to log in on doesn't have Bluetooth?

> Only if they’re a bit old. Nowadays WiFi chips double as Bluetooth chips on newer platforms.

What if the computer you want to log in on doesn't have a WiFi chip?

It doesn't have to be an old computer; for instance, the desktop computer I built last year uses a wired gigabit Ethernet connection to the router right next to it, and doesn't have (or need) any WiFi or Bluetooth chip.

cesarb··on Java 27
> but what many people do not know is that debugging NPEs in Java is easier now - they carry more information about the source

Unfortunately, no, they don't. Not after your application has been running for a while; newer JVMs arbitrarily decide you don't need the stack trace anymore, and all you see in your logs is "NullPointerException" (unless you still have the logs from several weeks ago, just after the last JVM restart, which might still have the full stack trace). Older JVMs were better, since they always had the full stack trace; debugging NPEs was easier with them.

cesarb··on Java 27
> And another positive point for Java: checked exceptions. It's verbose, but knowing exactly in which ways a function can fail is extremely helpful for building robust applications.

Sorry, but no, Java has the worst of both worlds here. It has checked exceptions AND unchecked exceptions, AND errors which are like unchecked exceptions but won't get caught by a normal catch-all (you're not supposed to catch Throwable, but it's the only way to prevent some dynamically loaded plugin code ten layers deep in the stack from breaking your invariants or stopping your periodic scheduled task due to an errant NoSuchMethodError or NoClassDefFoundError).

And you can't easily use checked exceptions with Java8-style functional code, since interfaces like Function aren't generic on the exception type. Which leads to aberrations like UncheckedIOException, which exists only to make IOException usable in the functional world.

cesarb··on Steam Frame starts at $1059
> Steam Frame starts at $1059

I see no price in the linked page. I only see "This item is not available for purchase in your region."

(Still waiting for the Steam Deck...)

cesarb··on Steam Frame starts at $1059
> The Frame's screens aren't good enough for general computing.

We did "general computing" in 320x200 screens. I think the Frame's screen is a bit better than that.

cesarb··on Why is the x86 undefined instruction called ud2? Why 2?
From what I recall from the time I still used MS-DOS, even if you only have one floppy disk drive, it's accessible as both A: and B: and it prompts you to insert the other floppy disk when you change the drive letter. That is, it's "virtualizing" two floppy disk drives using a single physical one. That explains why the first hard disk drive was always C: even when you only had one floppy disk drive (and of course you had at least one floppy disk drive, how could you use a computer without one?)
cesarb··on Stop making swap partitions—use swap files instead
> BTRFS in general seems more I/O constrained than ext4 or xfs so it's probably still worse to put a swapfile on a BTRFS partition,

AFAIK, on Linux swap bypasses the filesystem. It asks the filesystem for the extents which are used by the swapfile, and does the I/O directly on the block device. This explains the many restrictions swapfiles have on btrfs (the file can't be copy-on-write, can't be mirrored, etc), but it also means the speed for a swapfile will be the same on btrfs as on ext4 or xfs (assuming a similar layout, that is, the file is not too fragmented; IIRC, the kernel prints the number of extents when you do a swapon, so you can see when it's too fragmented).

cesarb··on Stop making swap partitions—use swap files instead
> fallocate / chmod / mkswap

Why not "mkswap --size ... --file ...", which does these three things and more? For instance, according to the mkswap man page, "[...] sets the nocow attribute for newly created files [...]" which is a detail that seems to be missing from this gist.

cesarb··on bzip3
> They couldn't allocate 5 more bits somewhere to let the decompressor autodetect longer window sizes?

It's actually 8 bits: https://www.rfc-editor.org/rfc/rfc8878.html#name-window-desc...

These command line parameters change the maximum the decompressor will allow. It's 128 MiB by default in the command line decompressor; other uses (like the "zstd" content coding for HTTP in web browsers) use a lower limit of 8 MiB (see https://www.rfc-editor.org/rfc/rfc9659.html).

cesarb··on 216M Spy TVs – The LG Smart TV Problem [video]
> It exists to displays pixels from a Linux box,

If you're not using the defining feature of a TV (the OTA tuner), why not buy a monitor instead of a TV?

(Next time I have to replace our house's TV, I'm seriously considering buying a separate SBTVD tuner and a monitor instead of a TV, if ignoring the "smart" features of these TVs by not connecting them to a network starts getting too difficult.)

cesarb··on Speculative Decoding in vLLM on AMD GPUs
> Naively, I would assume it must perform its normal auto regressive decoding to know what the “correct” token is in order to have something to compare the candidate token with.

Yes, but you can do it in parallel.

Suppose you predicted the tokens "D E F" in the sequence "A B C D E F". To "generate" the last token (F), it must know all preceding tokens (A B C D E). To "generate" the next-to-last token (E), it must know all preceding tokens (A B C D). And so on.

Assuming the prediction is correct, it can then run the "generation" for tokens D, E, and F at the same time. At the end, after all these tokens were "generated", it compares each token with the prediction; if the "generation" result was "D H F" it knows it has to discard the last two predicted tokens (and output "D H"), if the "generation" was "D E H" it knows it has to discard the last predicted token (and output "D E H"), etc.

And the most important part is that you can do it in parallel for each layer of the model. That is, you run "A B C D E F" through the first layer, then through the second layer, and so on; you only have to load the model weights from memory once for each layer. Instead of reading the full weights for all layers once for D, then once for E, then once for F, you only read them once for "D E F", and if the prediction was correct, you output three tokens by the (memory read) price of one (you still had to do the same amount of compute, but AFAIK LLMs tend to be more memory-bound than compute-bound).

cesarb··on GrapheneOS Overhauled Default Apps and Secure Clipboard
Perhaps it's different in other countries, but I've never seen anyone use MMS. (Everyone uses WhatsApp nowadays, but even before WhatsApp existed, I never saw anyone use MMS.)
cesarb··on .name Termination
> This is silly question, but is your family managing trust in you as lone guy - cousin, father, brother - having potentially access to all their emails?

I believe this is a very common setup: the "computer wizard" kid of the family manages the computers for the whole family. Not just emails, they have access to the whole computer (and have to fix when it breaks).

cesarb··on Google Antigravity TOS: 3rd party usage can get Google account suspended
That's the reason I avoided ever logging into YouTube: if for some reason they decided that my real name is not my real name, due to the Google+ integration, I could lose access to more important things like Google Talk.

Nowadays, with a Google account being all but required to use a non-Apple smartphone, it's even worse.

cesarb··on AI-Written Code Is Still *Your* Code. Are You OK with That?
> Analogously, people can write in assembly, but can you write in assembly when the codebase is frequently altered by someone with an optimizing compiler?

Yes. There's an interface boundary in the form of function prototypes and ABI rules. To the optimizing compiler, your assembly code is undistinguishable from separately compiled high-level code, and to your assembly code, the compiler output is undistinguishable from separately assembled low-level code.

One problem with LLMs, is that they don't respect these boundaries like an optimizing compiler would.

cesarb··on Get your Windows license refund
> We just need more folks to start using them.

I would if I could. Which non-Android Linux phone can I buy here in Brazil? Importing from outside Brazil doesn't count unless it has ANATEL certification, customs rejects any non-certified phone.

cesarb··on The Hugging Face incident and the road ahead
> Another key driver of the misaligned behavior was that the agents rarely “gave up” on their evaluation tasks, even when the tasks appeared impossible to solve.

Obligatory xkcd: "Zealous Autoconfig" https://xkcd.com/416/

Page 1 of 34Next →