HNHacker News
TopNewBestAskShowJobs

codys

1,283 karma · joined October 6, 2011

podcast-again-1k@icloud.com
submissionscomments
codys··on RIP ROP: CET Internals in Windows 20H1
Can you provide some details on your binary rewriter to add shadow stack support? Was this a pure software approach, or was it designed to take advantage of the support in new intel microprocessors? Do you have a write up of or can you give a quick overview of your methodology? Is the source code published somewhere?
codys··on Pine64 announce the Pinecil, TS100 compatible RISC-V soldering iron
> The metcal PS900 is actually cheaper now than the equivalent bottom end Weller TCP units and much much cheaper than the Hakko FX951 irons.

- Hakko FX951 is listed for $269.77, less tips

https://www.hakkousa.com/products/soldering/hakko-fx-951-sol...

- Metcal PS-900 is listed for $275.93

https://www.mouser.com/ProductDetail/Metcal/PS-900

The statement that the PS-900 is much much cheaper does not appear to be accurate now.

codys··on Your DS18B20 temperature sensor is likely a fake, counterfeit, clone
As exmadscientist noted, these use the 1wire bus.

The general mechanism (to use 1 io pin as both an input and an output) though is to have the io-pin operate in "open collector" mode. Essentially: it assumes that there is something external "pulling up" the io _line_ (normally a resistor attached to the positive logic level), and all devices attached to the io-line only "pull down" (ie: output the 0 logic level, normally 0v) on their io-pin. The io-pins, thus, have 2 states: low (ie: 0v), and hi-z (high impedance, ie: not driving the output in any direction)

This ensures that no device on the io-line will directly push/pull against the level being driven by the other device (because all devices only drive 0v, and none drive the the logic 1 level, they rely on the pull up).

Then to allow communication to occur reasonably (without both ends pulling the io-line low all the time), buses like 1wire specify how the devices decide which one "wins" (ie: gets to transmit it's data), or which one goes first, or which one directs the other devices to "talk".

codys··on Scaling Linux Services: Before accepting connections
This particular name originates from BSD 4.2 [1], which was released in 1983. (For some context, GCC 1.0 is from 1987, pcc was used to build BSD 4.2. The first Linux release was 1991).

1: https://github.com/dspinellis/unix-history-repo/blob/0f4556f...

codys··on Almost 1 in 3 pilots in Pakistan have fake licenses, aviation minister says
I also noticed the "Q" in the video opening, but youtube appears to indicate the video was uploaded 10 years ago (Sept 4, 2009). Wikipedia's page on QAnon [1] indicates it began in October 2017. It appears the video is a promotional from the Dillon Aero company, and the "Q" graphic appears to be something they included (again, based on upload data, 10 years ago). It seems plausible the "Q" in the video is meant to refer to something different.

1: https://en.wikipedia.org/wiki/QAnon

Edit: also see the same video from 2007 from another uploader:

https://www.youtube.com/watch?v=AowpYoYhzEI

It appears "Q" might refer to the product here. Or perhaps it is a James Bond reference.

codys··on 3K, 60fps, 130ms: achieving it with Rust
This assumes that video encoding latency is lower than the audio latency.
codys··on New inline assembly syntax available in Rust nightly
"safely abstracting `unsafe`" is the important concept with respect to rust and it's use of `unsafe`.

`unsafe` occurs in rust source code where the author of some code needs to do things in a way that can't be directly proven to the compiler to be safe. These include things like calling C functions and ASM code (both cases where we can't infer all the information necessary to ensure safety). The author of the unsafe code then provides an "safe" abstraction around the unsafety that ensures that when one uses the "safe" interface, no undefined behavior occurs.

At the lowest level there is always some unsafety: system calls, libc function invocations, asm, modifying various memory mapped registers. What rust provides vs C or C++ is effective isolation of the unsafety.

codys··on Running Linux on My MacBook
I run sway too, but I've kept firefox using X11 instead of native wayland due to the trackpad scrolling in firefox under wayland not being exact (ie: it jumps as if I had a mouse with a clicky scroll wheel instead of exactly following finger motion). In x11, I set `MOZ_USE_XINPUT2=1` to get exact trackpad scroll.
codys··on Those Win9x Crashes on Fast Machines
It looks like there's a copy in the library of congress [1]. Unclear how one would go about making a copy.

1: https://www.worldcat.org/title/spontaneous-assembly-for-cc-a...

codys··on As Qualified Immunity Takes Center Stage, More Delay from SCOTUS
The immunity enjoyed by Legislators is similar to but distinct from the Qualified Immunity enjoyed by government employees.

In the case of Federal Legislators, their immunity is written into the constitution explicitly.

No such explicit provision exists for government employees.

codys··on W64devkit: A Portable C and C++ Development Kit for Windows
qmake is has very poor handling of dependencies between generate header files, like those used with protobuf.

https://github.com/jmesmon/qmake-protobuf-example

codys··on Amazon sellers marking products as collectible to get around price gouging rules
Yes, it could make a lot of sense to enact price control boards like those of the WW2 era to allow some level of price changes without allowing price changes to the extent that it is harmful to the national interest.
codys··on US customs and border protection is flying a surveillance drone over Minneapolis
> should we not allow trucks on the road?

Perhaps not ones designed for carrying ballistic missiles.

Though this still isn't a perfect comparison because it ignores the fact that drone usage can be targeted to individuals, which is a factor that makes it more dangerous in our context of homeland operations.

codys··on New fuzzing tool finds USB bugs in Linux, Windows, macOS, and FreeBSD
Since v3.0, Linux has treated the first _2_ numbers of it's version as something that is incremented sequentially (in the v2.6 era, the _3_rd number was used, prior to v2.6 there was a even/odd stable/unstable split)

For example, we have normal releases v4.19 then v4.20 then v5.0 then v5.1. There will never be a v4.21.

Stable releases use the third number. v4.14.81 is a stable release of v4.14.0.

So the v4.20-rc2 statement just dates the work:

    $ git show v4.20-rc2
    tag v4.20-rc2
    Tagger: Linus Torvalds <torvalds@linux-foundation.org>
    Date:   Sun Nov 11 17:12:54 2018 -0600
codys··on The Ten Commandments for C Programmers (1987)
Not the parent, but `auto` in c++ improves the situation wrt implicit conversions as variables now automatically get the type of the thing assigned to them. IOW: less unintentional implicit conversions.
codys··on TI removes access to assembly programs on the TI-83 Premium CE
The TI-84 Premium/Plus CE uses a larger RSA key that has not been factored.
codys··on DirectX is coming to the Windows Subsystem for Linux
Only for copyright claims. Patent claims are not diminished by publishing items and asking for review. We can see this in the various video codec and other standards that publish a bunch of info that is covered extensively by patents.
codys··on DirectX is coming to the Windows Subsystem for Linux
The standard for Linux gpu access is the dri/drm kernel interface, not the new wsl specific api they've added.

Their porting Mesa to use a proprietary library that interacts with the wsl only kernel interface isn't that same as behaving like a standard Linux gpu

codys··on Rust/WinRT Public Preview
For linux I believe you mean D-Bus instead of DCOP. (that said, it's largely similar in concept)
codys··on Pointermove event latency in web browsers
It is trying to make the linux kernel more real time capable. Having periods of time where preemption isn't enabled (due to having interrupts disabled, etc) results in more variation in when tasks are scheduled, including real time tasks.

The reality is that "real time" as a definition covers many "features" and design choices because many ducks need to be in a row for real time tasks to run properly. Decreasing variation in the scheduling of (real time) tasks is one of those items.

As a result, it's entirely reasonable to call "linux-rt" "linux-rt".

codys··on Pointermove event latency in web browsers
linux-rt is a patchset that changes the behavior of linux to increase the number of places where preemption can occur (among other things).

Doing this decreases certain types of latency in certain situations. As an example, it tries to have interrupts disabled less frequently and for shorter intervals, and uses mutexes instead of spinlocks.

As a result, using linux-rt can provide a lower latency experience compared plain linux.

codys··on Pointermove event latency in web browsers
The article does mention that the predictive tracking feels worse:

> predictive tracking will feel much worse than direct (technically lagging) tracking when there is no system cursors to match.

Additionally, we can see the lag between the red box and your cursor in the video of your screen that you've uploaded.

https://i.imgur.com/ZEBcGch.png

codys··on Embedding Binary Objects in C
One place it's used is to avoid central "registration" for multiple "things". For example, consider a program with many fairly separate "subcommands". Using this mechanism allows adding a new subcommand simply by linking in a new source file (without changing a shared source file to list the new command).
codys··on Show HN: Tom Nook's Laptop
yep. opening in FF 75.0 on Linux shows a white blank page. Opening in chromium renders properly.

Looks like it's three.js failing to initialize webgl in firefox. Probably some firefox webgl issue.

codys··on California, Oregon and Washington announce western states pact
The current administration's position isn't relatively pro-state here though: Trump is on record insisting he can "reopen" the economy over the heads of state governments.

The position on "closing down" (that it was up to states) doesn't tell us anything about the administration's principle in regard to COVID because the administration is willing to change those "principles" very quickly, as evidenced by their current statements (among other actions taken by Republicans)

It's arguable that the position on closing down was based on the desire of the admin that the country remain "open", but was faced with legal/political difficulties in directly applying their desire to the country as a whole. What ever tactic is taken with respect to this Pact, we should be unsurprised if it ignores any "principles" and instead looks to effect the policy that Trump desires to put into place, or the effect on Trump's perception of his authority.

codys··on California, Oregon and Washington announce western states pact
Yes, I'm curious about the way they're intending to handling this legally as well. A bit of searching shows a Supreme Court case Virginia v. Tennessee, 148 U.S. 503 (1893) [1]. This restricts the application of that clause somewhat, but it isn't 100% clear to me that this Pact is a perfect match for the facts in that case.

It also sounds like [2] things are rather flexible in what approval is and when it is obtained. It's plausible that they expect to ask for approval, or rely on it being unlikely that congress explicitly disapproves, or perhaps they expect to obtain approval in the future.

[note: I've linked to a point in the opinion discussing Congressional approval]

1: https://scholar.google.com/scholar_case?case=103881997639573...

2: https://www.gsgp.org/media/1313/understanding_interstate_com...

codys··on FreeRDP 2.0 – A Remote Desktop Protocol implementation
Yes, this is because firefox doesn't allow multiple ff instances to use the same profile at the same time. You can ask firefox to create a new profile (`firefox -ProfileManager`) and then use a seperate profile for the remote instance
codys··on Io_uring By Example: cat, cp and a web server with io_uring
`forgetting` is not an edge case. In the context of rust, having an API that invokes unsafe behavior without it being marked unsafe is not acceptable. Keeping ourselves to this rule is what makes the concept of `unsafe` useful because we can rely on the behavior/api-spec of other code.

Failing to ensure correct behavior in the presence of `forget` means that once the program gets complex enough it can blow up in undetermined ways because one piece of code somewhere wasn't aware of a restriction in another piece of code that is potentially very far away.

Failing to isolate this type of unsafety is a pitfall waiting for some future developer to be trapped in.

codys··on Static Analysis in GCC 10
gcc also has ubsan since gcc version 4.9. Many of the sanitizers are shared by the clang & gcc projects. Some functionality, like emitting errors on unsigned overflow, is confined to clang.
codys··on WD Passport 4TB drives don't support WRITE SAME command
That sounds like a performance issue, not a security issue?
← PreviousPage 8 of 14Next →