140 karma · joined October 1, 2020
meet.hn/city/es-Oviedo
Interests: Books, Cybersecurity, Hacking, Hardware, Hiking, Mentorship, Music, Open Source, Programming, Startups, Fitness
---
I've been thinking about trying to implement this in freecad but I'm still exploring the idea.
Expecting it to prevent it would be as gullible as expecting it to prevent a toctou or any other type of non trivial vulnerability.
That's why even though I appreciate the role of these slightly safer languages I still have a bit of a knee-jerk reaction to the exagerated claims of their benefits and how much of a piece of crap C is.
Spoiler, crappy programmers write crappy code regardless of the language so maybe we should focus on teaching students to think of the code they're writing from a different perspective and focus safety and maintainability rather than "flashiness"
Claiming it's not a valid bug would be similar to claiming an infoleak isn't as well when it's one of the building blocks of modern exploitation.
I'm not trying to be an ass, I'm just trying to add a bit of context to ensure that the implication is well understood.
Admittedly I stopped after going through a bunch of useless stuff related to CVE-2017-8823 (which was initially reported as remotely exploitable with no proof at all).
I went through the tor repository (not vidalia though) and read a bunch of conversations about some of the memory related bugs but none of those were exploitable either (exploitable as in remote execution, not a DoS) and most of the (not so many) bugs were actually logical bugs.
I really don't care what they decide to do with their project and honestly anything that can potentially improve the security of such a system is fine by me but I really think they're doing themselves and the language a disservice by communicating the way they do.
Also, as a side note, even with a C codebase there is SO MUCH you could (and should) do to minimize the impact of a vulnerability that the fact that some choose to present just rewriting code in a different language is not even funny.
I know animals nap under cars all the time but at least with "regular" cars they seemed to be more aware of the danger.
I'm not talking about waymo, self driving, human in the loop or any of that here, I'm just curious because I wonder if the same thing would've happened with a combustion engine and if there are any "easy wins" in terms of deterrence.
I would've loved to engage in a conversation about coding styles such as MISRA, CERTs or even the small tweaks such as the one that offended you so deeply but you wasted the opportunity to engage in a constructive convesartion and instead chose to nitpick the "reformatting" thing (seriously, I just moved things around slightly, it's the same thing) or the nothing-burger "bug"...
I don't know, maybe I misinterpreted you and if that's the case then I apologize but when I saw that code and felt the urge to play/doodle I thought it could be a fun way to connect with someone over something silly and I just got disappointed.
I understand that you might not like that style but I think you're comming a bit too strong on this, especially considering how carefully I worded my message in terms of not hurting any feeling and being clear about this being MY preference.
I guess I shouldn't probably even answer but it saddens me and makes me a bit angry to get a reminder of why I don't usually participate in social media.
It's painfully verbose but I think it's worth it considering that we're in 2025 and we're not limited to one character variable names.
https://gist.github.com/leonardo-albertovich/984fff0825ff8fe...
Then I opened an existing file and asked it to modify a function to return a fixed value and it did the same.
I'm an absolute newb in this space so if I'm doing something stupid I'd appreciate it if you helped me correct it because I already had the C/C++ extension complain that it can only be used in "proper vscode" (I imported my settings from vscode using the wizard) and when this didn't work either it didn't spark joy as Marie Kondo would say.
Please don't get me wrong, I gave this a try because I like the idea of having a proper local open source IDE where I can run my own models (even if it's slower) and have control over my data. I'm genuinely interested in making this work.
Thanks!
I appreciate the work you are doing by dogfooding textual and how consistent you (or your team, I didn't know there was more than one person behind it) have been.
I just wanted to say thanks so yeah, Thanks!
A few weeks ago I gave it a chance out of curiosity because I wanted to run total comander and was pleasantly surprised of how well it worked which makes me think that it should be able to run openwatcom perfectly.
Side note: in the end, even though TC worked great I just crossed that item from my ToDo and continued using double commander (although the search feature is much better in TC).
Attribution should be given though, regardless of the bug OPs patch introduced the actual line that fixes the issue is clearly the same thing with the appropriate coding style.
As a maintainer, I can understand his reasoning but TBH it would've been easier and more respectful to just reply with the proper code snippet, having the contributor submit it (if he agreed) and then giving them credit.
Honestly, the comment section of this thread sucks, the level of self righteousness, "aggression" and gatekeeping is ridiculously uncalled for.
I think vector could be a very decent middle ground in the performance / safety space.
Last time I went through the code I concluded that it was a bit lacking but that's definitely something that can be (and probable is being) improved.
Side note : their documentation is really nice!
Their processors are quite capable and the entire receiver and exporter contrib collection is pretty good.
I'm not saying it's the best solution out there because that clearly depends on each use case but I don't think such harsh criticism makes sense.
Disclaimer: I'm part of the fluent-bit maintainer team.
It's really valuable (and sometimes even enjoyable) for others to read (or even participate in) a conversation between two (or more) knowledgeable individuals who share their perspective and explain why they made the choices the made in their implementations (hint: here's where he could share some of their work!).
In fact, this is the polar opposite of that and it's just sad.
On a side note, I looked at both codebases and even though I've already said that I wouldn't use either of them I have to say that I find rurbans to be somewhat messier and uglier so I have to disagree with you.
On a more constructive side, I think adding some value by giving the poster some feedback or engaging in a conversation about the topic would be nice, otherwise it just sounds as an attempt to show off.
I'm not a fan of these "header only" projects nor am I a fan of overly clever code because even though it's fun and rewarding to write it's not a great fit for larger or collaborative projects where consistently adhering to a coding style (hopefully one of the secure ones) and favoring readability over "coolness" are the way to go.
People love to blame C for all of its footguns but not a lot of people like to write "boring" code which kinda sucks...
Please don't take this personally, even though I have to admit that I felt somewhat irritated upon reading your comment it is my no means my intention to attack you with this rant.
Some misguided, confused or immature individuals might temporarily idolize him but hopefully they will end up growing up (in any and all senses) and realizing that two wrongs don't make a right and that this was most likely caused by a lack of understanding and support from the rest of the society which is a growing problem nowadays.
Needless to say orbstack earned its place in my setup so thanks a lot!
Edit: sorry, I wasn't clear, what I'm using in orbstack isn't a container instance but a full VM. I don't expect to find a huge difference with containers but I figured I'd make it clear so I don't cause any confusions.
I hope they explore those alternative applications.