967 karma · joined February 6, 2025
me plus hn-reply at csmantle dot top
[ my public key: https://keybase.io/csharpermantle; my proof: https://keybase.io/csharpermantle/sigs/yY8_8cVL2gNkK1GB4SKuo0EEcsWPP6vUBAejHBNdWxA ]
https://loongfans.cn/en/pages/intro.html#i-m-sold-where-can-...
------
Will this work on lists that sre short? It seems that it relies on overflow to move the element
GNU grep respects user arguments and input files to the dot. It is not probabilistic.
> Browsers are designed to be secure from default settings.
Not quite. They are usually designed to be both fast and safe, but neither goal is considered "done" yet in modern ones. If you want max security, you'll likely have to disable all performance boosts like JS JIT.
Suppose your libpopular forbids ill-faith actors from using it. Also suppose that I wrote a my-utility, a neutral tool, that depends on libpopular. If some bad actor uses my-utility for wrongdoing, will I be responsible for their behavior? Will my-utility be in breach of your license?
Not in where I live though. Competition is fierce, both in industry and academia, for most posts being saturated and most employees face "HR optimization" in their late 30s. Not to mention working over time, and its physical consequences.
> All numbers must be strictly greater than 1 million. The small stuff is inconsequential to us.
[0]: https://securityresearch.google/magika/2025_icse_magika.pdf
BTW, why invent Yet-Another-Toy-Arch(tm)? If a more established architecture is used, existing toolchains can be utilized to produce images for running. Many popular RISC ISAs have "simplified" editions which are void of many complex features, so they hardly need more efforts to implement with respect to this one.
---
Libraries can surely do the same job, but then the exact behavior would vary among a sea of those libs. Having specs defined [0] for such an interface would hopefully iron out much of these variations, as well as enabling some performance gains.
[0]: https://wicg.github.io/sanitizer-api/#dom-element-sethtml
This forced my browser to reload the page, and it beats the entire purpose of anchoring and fragment-based navs.
I agree that banning people without prior communication is rude, but looking at OP's PR[^1], I tend to concur with lodash maintainers this time. The PR gets no description, no explanation, and no prior discussion or RFCs. It adds a totally new GitHub Actions pipeline, while lodash isn't even using GitHub Actions now. It contains various fixup commits that should be squashed. One commit has a super long subject that should be split up. OP here went straight to the top level to propose a brand new release workflow, but the lodash maintainers obviously didn't consider them to be ready for such contributions.
These are common mistakes every contributor would make in the beginning, and I don't think the maintainers meant it personal. As many other comments have pointed out, by choosing an easier task, getting familiar with the workflow, and building trust, OP can get their patch landed.
[^0]: https://www.mozilla.org/en-US/about/governance/policies/comm...
... then waste a few hundred minutes being misled by hallucination. It's quite the opposite of what "cracking open the code" is.
Agreed on the point about hw-level mitigation. The leakage still exists. Containing it in a watertight box is quick and effective, and it does avoid extra overhead. But it doesn't patch the hole.
Another example for buttons. Assuming I don't speak Chinese, how could I know what "下单" and "返回" mean without copy-pasting them into a translator?