HNHacker News
TopNewBestAskShowJobs

danappelxx

499 karma · joined April 28, 2015

https://danapp.app
submissionscomments
danappelxx··on Grok 4.7
Wow, thanks for sharing, fun benchmark!
danappelxx··on New MCP Roadmap
How does the agent auth with 1pw? How do you give it access to only the credentials it needs, with an approval flow and revocation? Who renews the token? You’ll likely end up reinventing something pretty close to what MCP is building towards.

Authn/authz is one of those things that can be really simple for pointed use cases but gets really complex when you need to support everything.

danappelxx··on The first 40 months of the AI era
There is natural incentive for engineers working on a project to keep Claude skills up to date. I cannot say the same for general documentation.
danappelxx··on Show HN: GitHub "Lines Viewed" extension to keep you sane reviewing long AI PRs
GitHub API is actually quite tricky here because there is a different between “comment” and “review” and “review comment” (paraphrasing, I don’t remember the details). So it’s not as simple as one API call that grabs the markdown. Of course you can write a creative one-liner to extract what you need, though.
danappelxx··on RIP pthread_cancel
If the DNS resolution call blocks the thread, then you need N worker threads to perform N DNS calls. Threads aren’t free, so this is suboptimal. OTOH some thread pools e.g. libdispatch on Apple operating systems will spawn new threads on demand to prevent starvation, so this _can_ be viable. Though of course this can lead to thread explosion which may be even more problematic depending on the use case. In libcurl’s situation, spawning a million threads is probably even worse than a memory leak, which is worse than long timeouts.

In general, what you really want is for the API call to be nonblocking so you’re not forced to burn a thread.

danappelxx··on Using the Internet without IPv4 connectivity
Mirrors my experience. IPv6 issues are frustratingly hard to triage and reproduce, lots of “works on my machine” etc.
danappelxx··on AWS Lambda Web Adapter
This is an interesting point. Hangs usually cost $ from user experience, with serverless they cost $ from compute. All the more reason to set strict deadlines on all API calls!
danappelxx··on Xv6, a simple Unix-like teaching operating system
Took the same class at UCI (with Prof Anton Burtsev). Best class I ever took.
danappelxx··on Distributed SQLite: Paradigm shift or hype?
Yup, exactly. Phones change wifi networks, routers drop packets, load balancers get overloaded. Hard to fully eliminate tail latencies.
danappelxx··on Distributed SQLite: Paradigm shift or hype?
Unless your database is in the browser, you are always going to be at mercy of network latencies talking to the backend.
danappelxx··on Distributed SQLite: Paradigm shift or hype?
I think you always need loading states to account for slow network, or am I missing something?
danappelxx··on Normal Operating Sounds
“Cabin Noise during Acceleration with Ludicrous Enabled” was by far the most interesting
danappelxx··on Gleam: a type safe language on the Erlang VM
Generally stems from the philosophy that code is read more than written, and this helps readability.
danappelxx··on gRPC request context which caries values across microservice boundaries
What do you use instead?
danappelxx··on Nginx Unit – Universal web app server
Not that difficult, but it’s still a separate dependency (with python requirements). If the goal here is a Caddy competitor, then IMO it’s missing the mark in terms of “one stop shop”. What’s the killer feature?
danappelxx··on Are You Sure You Want to Use MMAP in Your Database Management System? (2022)
Ah, good to know!
danappelxx··on Are You Sure You Want to Use MMAP in Your Database Management System? (2022)
It’s becoming standard as a security measure. See: Kata containers, Firecracker VM
danappelxx··on Are You Sure You Want to Use MMAP in Your Database Management System? (2022)
I’ll assume the worst case:

- lots of containers running on a single host

- containers are each isolated in a VM (aka virtualized)

- workloads are not homogenous and change often (your neighbor today may not be your neighbor tomorrow)

I believe these are fair assumptions if you’re running on generic infrastructure with kubernetes.

In this setup, my concerns are pretty much noisy neighbors + throttling. You may get latency spikes out of nowhere and the cause could be any of:

- your neighbor is hogging IO (disk or network)

- your database spawned too many threads and got throttled by CFS

- CFS scheduled your DBs threads on a different CPU and you lost your cache lines

In short, the DB does not have stable, predictable performance, which are exactly the characteristics you want it to have. If you ran the DB on a dedicated host you avoid this whole suite of issues.

You can alleviate most of this if you make sure the DB’s container gets the entire host’s resources and doesn’t have neighbors.

danappelxx··on Are You Sure You Want to Use MMAP in Your Database Management System? (2022)
IMO if you’re concerned about performance and yet are deploying databases this way — mmap should not even be on the radar.
danappelxx··on Are You Sure You Want to Use MMAP in Your Database Management System? (2022)
Who is deploying databases in containers?
danappelxx··on OpenAPI v4 (aka Moonwalk) Proposal
Agreed, but if you’re asking for a solution that will generate a spec from your code, the more proven path is to generate code from a spec. Gives you more and costs less.

In my opinion the problem is that there’s some APIs that are impossible to represent with OpenAPI — that’s the real challenge they should be solving with this version, not reducing spec line count.

danappelxx··on OpenAPI v4 (aka Moonwalk) Proposal
I suspect OpenAPI advocates would argue you should start with the spec and use it to generate both the client and server. This is already a common pattern in other RPC definition languages such as gRPC. You _could_ write a server to match the gRPC spec, but why would you?
danappelxx··on OpenAPI v4 (aka Moonwalk) Proposal
does it add support for streams?
danappelxx··on How to mitigate risk from secrets leaks
Right! Which is why we use (public) short-lived JWTs and (private) long-lived refresh tokens. What’s missing?
danappelxx··on How to mitigate risk from secrets leaks
Interesting. You already don’t have to worry about revoking JWTs if they’re sufficiently short lived. This gives you the exact level of protection as a short-lived mTLS cert, because if that gets stolen the attacker can continue to establish connections until it expires, unless as you say you revoke the certificate. So clearly I am missing something.
danappelxx··on How to mitigate risk from secrets leaks
How does this approach practically differ from using short-lived JWTs+TLS?
danappelxx··on The Garbage Collection Handbook, 2nd Edition
This is incorrect, value types are not referenced counted in Swift. If a value type contains a reference type member (usually an anti pattern!), then that member’s reference count is indeed incremented when the value type is copied. But it is not accurate to claim that value types themselves have reference counts.
danappelxx··on Porting Graphing Calculator from C++ to Swift
There’s partial support which is under active development.

https://github.com/apple/swift/tree/main/docs/CppInteroperab...

https://forums.swift.org/t/swift-and-c-interoperability-work...

danappelxx··on FDA Denies Authorization to Market JUUL Products
Unsurprisingly, this is out of touch. Juul has been dead among teenagers for years, basically immediately after the FDA banned flavors. Its now been replaced by, as far as I can tell, completely unregulated disposable e-cigarettes which have been growing in price, size, and strength. Ask your interns when the last time they saw a Juul at their college was.
danappelxx··on I'm all-in on server-side SQLite
To clarify:

- I was talking about ACID guarantees across databases (ie across users) - I was talking about aggregations across databases (ie across users)

Of course working inside one database works as you would expect it to. My point was that this pattern of database-per-user seems to be a totally different design than people have used with traditional n-tier designs.

Good point about NoSQL! But, wasn’t part of the reason MongoDB fell out of favor because it was lacking consistency?

Page 1 of 6Next →