HNHacker News
TopNewBestAskShowJobs

gnufx

1,734 karma · joined November 8, 2014

submissionscomments
gnufx··on Devil's Arrows: Ancient builders hauled 55k-lb stones 11 miles for UK stone row
I don't think that's relevant for Register units. Clearly there's a standard brontosaurus somewhere, for instance, otherwise how could we have the conversion table? However, sorry, I was wrong about the football pitch, at least as a unit of area, equal to 194.89nWa per the original article: https://www.theregister.com/offbeat/2007/08/24/so-whats-the-...
gnufx··on Trying to Make a Loop Auto-Vectorize
Actually, one caveat is that GCC's optimization info can be rather inscrutable because it's in terms of compiler internal nomenclature. That's a definite area for improvement (or compiling some sort of key to it).

Indeed, GCC optimizes well. Last time I ran a set of Fortran benchmarks, the geometric mean for them was competitive with other compilers on multiple architectures, and some of the benchmarks could have been sped up considerably with specific compiler options or by re-writing a function sacrificing numerical equivalence, which the Intel compiler seemed to do itself.

gnufx··on Trying to Make a Loop Auto-Vectorize
Vectorization doesn't imply SIMD, of course. The first vectorizing compilers were for CDC(?) systems long before SIMD. Today you have SVE in Arm, for instance, distinct from SIMD Neon.

Anyway, I'm familiar with optimizing numeric loops in C (and Fortran) rather than Rust. I've rarely seen simply using SIMD intrinsics work where GCC auto-vectorization didn't with the same semantics (like numeric equivalence in reductions). In most cases you can get away with -fassociative-math, of course, and not sacrifice peak performance, e.g. BLIS passes its extensive tests with it on, but you should check, of course. (GCC also documents the option as necessary to get Arm (Neon?) to vectorize at all.) Most of the time when people tell you how much better the Itel compiler is, it's because it incorrectly defaults to something like -funsafe-math.

Regardless, GCC (like other compilers) will tell you about vectorization with the -fopt-info- options without examining assembler, and you can have some surprises. For instance, you use unsigned in C for loop indices that you know are positive, and see failed vectorization due to "loop not affine", because of C's overflow semantics; use signed types instead.

There's another reason for using properly-optimized numerical libraries (typically BLAS), is that, at least for level three (matrix-matrix) operations. Even if you get the blocking right for the memory hierarchy, you typically won't get peak performance just with vectorization because tricky preloading is needed for the inner loops.

gnufx··on Devil's Arrows: Ancient builders hauled 55k-lb stones 11 miles for UK stone row
That's not dimensionally correct! Double-decker bus is a unit of length, and footy pitch is too prosaic to be an approved unit: https://www.theregister.com/bootnotes/2026/05/31/the-reg-onl...
gnufx··on Maybe we should revisit microkernels
Not the first time I've said this: the 1970s-era GEC OS4000[1] was really fast, like compared with everyone's VAX 780s, and we users benefited in the '80s. I don't know whether or not it was strictly a microkernel, but at least the moral equivalent; the nucleus was originally in (hard/firm)ware, but it was later emulated on different hardware. (I guess, but don't know, that "4000" and "nucleus" reflected Brinch Hansen's RC 4000 system -- which seemed really steam-driven in the '80s).

1. https://en.wikipedia.org/wiki/OS4000

gnufx··on Pintheft Linux LPE
The latest page cache-related LPE, even though it's not Thursday night (here). EL9 kernels don't have the modules enabled, and the PoC doesn't build on Debian 13 or Ubuntu 24.04, whether or not that means they're safe.
gnufx··on Fragnesia Made Public as Latest Linux Local Privilege Escalation Vulnerability
You might not have root on an organizational "managed" system.
gnufx··on Fragnesia Made Public as Latest Linux Local Privilege Escalation Vulnerability
Any university or national HPC system as I'd understand the term is multi-user.

There are also things like the extensive high energy physics WLCG compute federation, which is somewhat different, but can potentially be compromised quickly at large scale. For the original copy-fail we didn't want to drain our WLCG Alma9 cluster, or just kill all the jobs like the university HPC system. We got eBPF mitigation in place within a couple of hours, relieved the exploit signature wasn't in logs from the night before. That would have been done earlier if Proofpoint hadn't bounced the forwarded oss-security article as "contains malware"; sigh.

gnufx··on Fragnesia Made Public as Latest Linux Local Privilege Escalation Vulnerability
The primary source, which says keep the dirtyfrag mitigations in place, is https://github.com/v12-security/pocs/tree/main/fragnesia
gnufx··on SSH certificates: the better SSH experience
Yes, but its authN components only act locally, and PAM is optional for sshd. It can/does call out to network services like Kerberos/LDAP given a password, of course, but I was thinking of network authN connected directly with OIDC somehow, for which I don't know a mechanism in vanilla OpenSSH. (I don't know what Authentik does for this -- I could imagine it's behind the scenes somehow.) I should probably look it up sometime.
gnufx··on SSH certificates: the better SSH experience
I'm happy for anyone who doesn't have MS Windows/Active Directory -- so Kerberos -- in their organization, but I'd need (Free)IPA or similar for user/access management anyway. Certificates are an extra layer of SSH-specific complexity, which concerns me for security even if it doesn't involve some third party. MFA is needed once a day, say, for SSO to all Kerberized services. [As I understand it, "managing an OIDC IdP" includes shipping the contents of Active Directory to Entra, heaven help us.]

> Setting up Kerberos in 2026 feels somewhat close to malpractice to me.

Microsoft (if that means anything, but they've done good work) and Red Hat obviously disagree, along with decades' experience. It is malpractice not to secure NFS mounts (and other network filesystems with sensitive data), and that means Kerberos.

gnufx··on SSH certificates: the better SSH experience
Yes, FreeIPA is Kerberos+LDAP+X.509 CA, and GSSAPI is in OpenSSH (normally with the key exchange patch). SSSD is a local mechanism, not network authentication. I mentioned authorized keys distribution mechanisms elsewhere, but I was thinking authentication (c.f. OIDC), not authorization.
gnufx··on SSH certificates: the better SSH experience
I don't want to have to get a special purpose credential when I have a TGT which can work generally, and is at least required for secure remote filesystem access.

You have to manage extra infrastructure for certificates and, as a user, have the friction of firing up a JavaScript-enabled web browser via an additional tool, assuming "real IdP" means using OIDC. Unfortunately that flow is actually needed for remote systems and something like Edugain federation, since Moonshot/IETF ABFAB failed, but at least Shibboleth can use the TGT, and it's not the Globus horror.

gnufx··on SSH certificates: the better SSH experience
Public keys (for OpenSSH) can be in DNS (VerifyHostKeyDNS) or in, say, LDAP via KnownHostsCommand and AuthorizedKeysCommand.
gnufx··on SSH certificates: the better SSH experience
If you mean using OIDC, in that space there's at least https://github.com/EOSC-synergy/ssh-oidc, https://dianagudu.github.io/mccli/ and OpenPubkey-ssh discussed in https://news.ycombinator.com/item?id=43470906 (which might mention more).

How does SSSD support help with SSH authN? I know you can now get Kerberos tickets from FreeIPA using OIDC(?), but I forget if SSSD is involved.

gnufx··on SSH certificates: the better SSH experience
Life is easier if you can use Kerberos SSO, i.e. GSSAPIAuthentication in OpenSSH. (If we're talking certificates, presumably it is OpenSSH, or does anything else implement them?)
gnufx··on The future of version control
As far as I remember, that's just because only the find/replace was implemented, and it could have more sophisticated (semantic?) features.
gnufx··on The future of version control
Its author says it implements a CRDT in its theory documentation.
gnufx··on What every computer scientist should know about floating-point arithmetic (1991) [pdf]
Before isnan() the Fortran test for NaN was (x .ne. x), assuming an IEEE 754 implementation.
gnufx··on GrapheneOS – Break Free from Google and Apple
> I had a Fairphone 3, and after 5 years, /e/OS was outdated by 4 years w.r.t. the manufacturer updates

Mine is running /e/ and reporting Android 13, which appears to be the last one Fairphone support. /e/ said it was too difficult to support 14 with the kernel involved. It's had continual security updates apart from the Android version.

Edit: Murena make it clear which phones are officially supported and which have "community" support.

gnufx··on Ga68, a GNU Algol 68 Compiler
Some of those codebases might be (interesting) operating systems.

https://en.wikipedia.org/wiki/ALGOL_68#Operating_systems_wri...

gnufx··on Tiny C Compiler
Used in the impressive Guix bootstrap.

https://guix.gnu.org/manual/1.5.0/en/html_node/Full_002dSour...

gnufx··on Brookhaven Lab's RHIC concludes 25-year run with final collisions
Indeed. The first dedicated light -- for various values of "light" -- source[1] repurposed the tunnel and various bits and techniques from the particle physics accelerator it replaced, and on which parasitic "light" measurements were made previously. See also [2].

1. https://en.wikipedia.org/wiki/Synchrotron_Radiation_Source

2. https://www.ukri.org/publications/new-light-on-science-socio...

gnufx··on Brookhaven Lab's RHIC concludes 25-year run with final collisions
In the context of the article "collider" means intersecting particle beams, like in RHIC and LHC, which obviously involves rather low probability interactions, as opposed to accelerators which slam a beam into a dense target (like the SLAC accelerator). In a synchrotron light source you want the beam to circulate and specifically not collide with anything; they were developed from particle physics accelerators, of course.
gnufx··on Brookhaven Lab's RHIC concludes 25-year run with final collisions
You imply that experiment contaminated drinking, and other, water. How? Are you saying the Cs¹³⁷ leaked, and at concentration above that from fallout, say? Its γ-rays don't activate materials — I've used enough of them.
gnufx··on Brookhaven Lab's RHIC concludes 25-year run with final collisions
Since when were industrial products the purpose? Why do you think my colleagues can't analyse LHC data and discover the Higgs particle? The article says RHIC was a considerable scientific success.
gnufx··on Brookhaven Lab's RHIC concludes 25-year run with final collisions
As I recall, RHIC itself replaced some cancelled project. I remember the tunnel being at least partly there in the mid-80s, with a plan to trundle ions from the tandem lab through a crazy long beamline across the site and stop nuclear structure research there as a result.
gnufx··on UK government launches fuel forecourt price API
Good to see. For what it's worth, data were previously available from the Competition and Markets authority, used by https://localfuelprices.co.uk/
gnufx··on Netbird – Open Source Zero Trust Networking
Oh, I hadn't found that. Yes, it seems strange not to publicize something like that to give users confidence (assuming the audit/pentest isn't damning). It doesn't have to have been perfect initially, as long as appropriate fixes were made.
gnufx··on Netbird – Open Source Zero Trust Networking
With regard to European sovereignty, I note that Netbird uses AWS.
Page 1 of 34Next →