HNHacker News
TopNewBestAskShowJobs

lotharcable

305 karma · joined July 22, 2022

submissionscomments
lotharcable··on Using Podman, Compose and BuildKit
For me LLM is just a rubber duck that talks back.

It is very stupid and is usually wrong in some meaningful way, but it can help break logjams in my thinking. Giving me clues that might be missing. Sort of like how writing gibberish is sometimes effective for writers to break writer's block.

It is also nice for generating boiler plate code for languages that I am not super familiar with.

The biggest problems I have with current state of the art LLMs is that errors compound. Meaning that I only really get somewhat useful answers when starting out with the first few questions or the first couple times I ask it to review some code. The longer the session lasts the more la-la land answers I get.

It is a game of odds. I expect that with systemd and quadlets it is going to particularly useless because there just isn't that many examples out there. It can only regurgitate what it is trained with so if something isn't widely used and checked into code bases it is trained on then it can't really do anything with it.

Which is why it is nice for a lot of common coding tasks, because a lot of code is just same thing tens of thousands people did before for only slightly different contexts and is mostly boilerplate.

lotharcable··on Americans, Be Warned: Lessons from Reddit's Chaotic UK Age Verification Rollout
The biggest problem with Western Governments, and the reason this sort of thing is going on, is the result of the "professionalization" of the political classes.

Earlier in the 20th century politicians tended to be people established in their own right outside of government. Meaning that they tended to be well known and successful outside of government and decided to get involved in politics as a part time or second career. Get involved, represent their community interests, etc.

Which meant that they had experience outside of government they could bring in with them.

Nowadays politicians tend to be "professionals", meaning that they went to school and got law degrees and started their political careers at a young age. They got started in government due to political and family connections, and successful ones learned the bureaucracy of government and the rules (spoken and unspoken) established by their respective political parties and sort of wormed their way up the system from the "inside".

This has created a insular culture. They are "professionals" without any sort of professional regulation or professional organizations or professional standards. The only regulation comes from themselves and their own political parties.

This has created a class of "leaders" that are exceptionally good at understanding the internal beaucracy and party structure which their lives are based on, but are pretty much incapable of connection and communicating with normal people.

The people that make or break them as successful politicians is largely their peers, not the public.

This creates a sort of "ivory tower intellectual" type culture in government and in the top ranks of large corporations. There is the "inner party" of people that set the intellectual and cultural tones that other party members are expected to adhere to, and then a "outer party" that are their functionaries in big business, media, and government, that are expected to put policies and goals established by the "inner party" into motion.

And because of this they are really unable to communicate well with the public or engage in debates over important matters.

They take personal offense and look down on the public when they are questioned. Seeing themselves as experts and professionals while the rest of the public really are just kinda ignorant.

Sort of like how a Dentist must feel when a patient starts arguing loudly with them over whether or not they need a root canal.

Because of all of this, especially with the inability to communicate or relate deeply with the public, they tend to resort to tactics like name calling and censorship.

Which means that there is a strong tendency to label members of the public as "right wing" or "extremist" and try to work with social media companies to "quiet the rabble".

Sort of like how a frustrated and abusive mother resorts to yelling "just shut up already" repeatedly at their toddlers for endlessly crying.

This is one of those "when the only tool you have is a hammer every problem looks like a nail". The "protect the children" is just a excuse to get the regulatory ball rolling and help ensure that they can track and intimidate members of the public they see as obstacles or sources of discontent.

lotharcable··on Linux Performance Analysis (2015)
The proper way is to have a idea of what it normally is before you need to troubleshoot issues.

What is a 'good load' depends on the application and how it works. Some servers something close to 0 is a good thing. Other servers a 10 or lower means something is seriously wrong.

Of course if you don't know what is a 'good' number or you are trying to optimize a application and looking for bottlenecks then it is time to reach for different tools.

lotharcable··on Replit's CEO apologizes after its AI agent wiped a company's code base
I think this is less AI and more PEBKAC
lotharcable··on What will become of the CIA?
Don't worry.

If CIA ends up hurting for money they can go back to using Israel to sell weapons to Iran and selling cocaine to intercity youth.

Like the good old days.

lotharcable··on Please, FOSS world, we need something like ChromeOS
The only desktop to have real meaningful large-ish/professional usability testing is Gnome. And that is only a couple times.

The first time was financed by Sun Microsystems in 2001 for Gnome 1.x and the result was Gnome 2.

The second time was financed by Novell around 2005 or so for their attempt to compete with Microsoft with Novell Linux Desktop. Unfortunately for them the real beneficiary of the improvements that results from their work was Canonical's Ubuntu.

Since then there have been numerous smaller/informal/ad-hoc attempts for both KDE and Gnome.

The results of all of this, of course, is that many "Linux users" believe that Gnome is the result of a conspiracy between IBM, Redhat, and maybe even Microsoft to "destroy the Linux desktop".

So that is fun.

The real success story, from what I can tell, is Blender.

They successfully revamped their user interface without a huge budget. Although it was still financed somewhat by some EU initiative, IIRC. They accomplished this by getting developers sat down next in a big room to actual 3D artists working together to produce a animated feature.

By physically placing users next to devs and having them work together, likely with a great deal of humility and openness, they managed to transform their UI into something that was actually decent.

This is probably a model that can be duplicated by other open source developers, although finding the right type of technical users not experienced in using said software willing to participate is going to always be a major challenge.

lotharcable··on Please, FOSS world, we need something like ChromeOS
It is especially acute when it comes to Linux desktop.
lotharcable··on Please, FOSS world, we need something like ChromeOS
Netbook boom happened and then people actually started trying to use them.

That is why the netbook boom died. Because while they promised to make cheap Linux devices that anybody could use none of them actually delivered on it.

In fact the whole thing was a fiasco.

The classic Linux problem can be described as "9 clicks to shit". Meaning that a Linux desktop looks, on the initial viewing, as something that is actually usable and modern, but once you start clicking around things start going bad. Going bad quickly.

A major problem cause of the problem is "linux is about choice" mentality.

Another problem is that programmers specialize at being good at programming, but things like documentation and UI testing are their own disciplines that are separate and distinct in a lot of meaningful ways. So, in attempt to make up for this, they leave configuration and details up to user choice. It is effectively pawning off the last stages of development onto the end user, who are generally most ill-equipped to make technical decisions on software they are not familiar with.

Instead of presenting something that "just works" users are presented with a myriad of choices and options that they have to make decisions about before ever actually being able to use the software.

Having lots of choices in applications, widget libraries, desktops, ways to install software, init systems, etc etc... results in very significant complexity as it all has to work together.

And complexity breeds bugs.

So each and every user experience ends up being its own unique things. There is no "standard configuration" no "supported configuration" and no "documented configuration".

The end result is that each user is forced to find ways to make the desktop work for their specific use case. Essentially finding a magic combination of things that isn't broken for what they specifically want. The desktop will still be full of buggy behavior, but just not in the way that that particular user cares about.

This creates a extraordinary of frustration and friction when time comes to doing the things that the desktop is actually intended for... which is getting actual work done.

This isn't a problem for a certain class of highly technical users that love technical minutia and configuring things. Knowing how to carve a working system out of a OS riddled with historical artifacts and highly technical choices is a badge of honor for many people.

But this isn't how most people want to do things.

Netbook boom tried to fix this in certain ways, but all that ended up happening is that each little corporation tried to do their own thing and then abandoned it when they realized there was no money to be made and they really lacked the resources and expertise to make it work.

lotharcable··on Please, FOSS world, we need something like ChromeOS
Not even remotely close.

This is why it was such a revolution when Ubuntu came out and quickly dominated the Linux desktop space. When it was new.

It took Debian and made it something approachable. But even then it was a 1/3rd of what is described as needed in the article.

lotharcable··on Solar power has begun to transform the world’s energy system
> If you can get the us federal government to be functional again or have a path to doing that

Impossible.

Federal government in US is failing along with the rest of large scale western style governments. They are too big, cost too much, and have too many fundamental structural deficiencies.

The model of having professional class of administrators and politicians running the country as part of a massive bureaucracy is one that can't work as it is unmanageable and full of conflicts of interests, moral hazards, political market failures and so on and so forth.

They carry on just through inertia at this point. Their one talent is creating a image of control and stability without actually providing any.

If you ever worked in a large publicly traded corporation and realized just how dysfunctional they are as a organization, multiply that a thousandfold and you have modern western governments.

Nuclear is expensive and doesn't work because there are a lot of people in power and next to power that don't want it to work.

lotharcable··on Solar power has begun to transform the world’s energy system
Large scale solar are actually large scale gas plants.

Since there is no way to store electricity large scale and solar energy is unreliable then they depend on gas turbines to work.

lotharcable··on A Higgs-Bugson in the Linux Kernel
> This kernel design is bankrupt. There's much better available, such as seL4+Genode.

I am sure that the tech community would love to read the details of your great success in deploying microkernels for large variety of production workloads.

lotharcable··on Building untrusted container images safely at scale
Build environments are usually "soft targets" in most environments.

Especially ones that utilize a lot of the "CI/CD" pipeline approach.

Lots of secrets getting pulled from various different places, access to testing environments and testing databases needed for unit testing, access to systems that deploy to testing and prod environments. Sensitive code and secrets from multiple applications being used in the same servers and build infrastructure, etc.

So even if you trust containers to containerize securely (which is a bad idea in practice) there are all sorts of holes being poked in them to allow them integrate and access things. Even during building and testing.

Most security effort for most organizations involve hardening parts of production systems that are exposed to users and/or the internet. This not only involves proofing code and setting up firewalls, WAF, and such things, but also monitoring and whatnot.

That is expensive and a lot of work to do, while in build environments it tends to be more slapped together and people ignore them until something breaks.

You have similar situations with backup solutions. People need backups to secure data from corruption or deletion and protect businesses that way, but seeing them as a potential security hole isn't really thought about in the same way as running a production web server. Again it is something that just enough effort is put into to make sure it works and little attention is given to it unless it breaks.

lotharcable··on The $25k car is going extinct?
Emissions, mileage, crash safety standards in the USA punish smaller more fuel efficient cars. The larger the wheel base or "shadow" of the vehicle the easier for it is to meet Federal standards.

This is why nobody sells small pickup trucks here. It is a lot easier for Ford to produce F150s that get 25-30ish mpg then it is to produce small trucks that get 40-50.

The Maverick is the only exception and it isn't really that small and it is also a hybrid.

Essentially the Federal government made selling small cheap cars infeasible in this country.

Also because vehicles last a lot longer thrifty Americans avoid buying new vehicles. They would rather buy a used one and let somebody else absorb the depreciation hit.

And when buying a used car most people are going to want a used mid-ranger or higher end car then buying a used economy car.

lotharcable··on Antitrust defies politics' law of gravity
I wish more people understood what "The Administrative State" is and its history.

Because the "oligarchy" people complain about isn't the cause of massive government corruption.

"Oligarchy" is the natural result of creating a massive politically controlled administrative bureaucracy in charge of most aspects of the business regulation, banking, and so on and so forth.

That is if you want to ensure a powerful oligarchy making decisions for the country the first step in accomplishing this is to make a big and powerful government to regulate the economy.

That is how you get all powerful billionaires.

lotharcable··on bootc-image-builder: Build your entire OS from a Containerfile
What does "native containers" mean in this context?
lotharcable··on Apptainer: Application Containers for Linux
Very good, thank you. I did miss the significance of 'unshare' in your post.
lotharcable··on Apptainer: Application Containers for Linux
Appimage is terrible. It works by trying to make applications in appimages adhere to a lowest common denominator between Linux distros... which amounts to forcing application developers to develop for the oldest version of Linux appimage supports.

Nix is a huge pain to deal with.

Nix makes me think of the old Zawinski joke of:

"Some people, when confronted with a problem, think 'I know, I'll use regular expressions.' Now they have two problems,"

Except there are less upsides for using Nix over something like OCI.

lotharcable··on Apptainer: Application Containers for Linux
It would be more accurate to say that toolbx is based on Podman, but is intended to provide tight configuration with your user's outside environment.

If you want to use toolbx for more isolation you'll have to end up turn off a bunch of features and configuring it in weird ways that ultimately defeats the purpose of having toolbx in the first place....

It is a lot easier to just to cut out the middle man and use podman directly.

lotharcable··on Apptainer: Application Containers for Linux
Apptainer, like the vast majority of container solutions for Linux, take advantage of Linux namespaces. Which is a lot more robust and flexible then simple chroot.

In Linux (docker, podman, lxc, apptainer, etc) containers are produced by combining underlying Linux features in different way. All of them use Linux namespaces.

https://www.redhat.com/en/blog/7-linux-namespaces

When using docker/podman/apptainer you can pick and choose when and how to use namespaces. Like I can use just use the 'mount' namespace to create a unique view of file systems, but not use the 'process', 'networking', and 'user' namespaces so that the container shares all of those things with the host OS.

For example when using podman the default is to use the networking namespace so it gets its own IP address. When you are using rootless (unprivileged) mode it will use "usermode network" in the form of slirp4netns. This is good enough for most things, but it is limited and slow.

Well I can turn that off. So that applications running in a podman container share the networking with the host OS. I do this for things like 'syncthing' so that the container version of that runs with the same performance as non-containered services without having to require special permissions for setting up rootful network (ie: macvlans or linux bridges with veth devices, etc) )

By default apptainer just uses mount and user namespaces. But it can take advantage of more Linux isolation features if you want it to.

So the process ids, networking, and the rest of it is shared with the host OS.

The mount namespace is like chroot on steroids. It is relatively trivial to break out of chroot jails. In fact it can happen accidentally.

And it makes it easier to take adavantage of container image formats (like apptainer's SIF or more traditional OCI containers)

This is Linux's approach as opposed to the BSD one of BSD Jails were the traditional limited Chroot feature was enhanced to make it robust.

lotharcable··on Apptainer: Application Containers for Linux
Containers in Linux are more a conceptual collection of different isolation techniques. Mostly just based on Linux namespaces. But things like cgroups, Linux capabilities, occasionally MAC (selinux, etc) and a few other items often get thrown in the mix.

https://www.redhat.com/en/blog/7-linux-namespaces

After a quick view of the apptainer documentation it looks like it minimally takes advantage of user and mount namespaces. So each apptainer gets its own idea of what the users/groups are and what the file system looks like.

Flatpak is more about desktop application sandboxing. So while it does use user and mount namespaces like apptainer it takes advantage of more Linux features then that to help enhance the isolation.

Which appears to be the opposite of the point of apptainer. Apptainer wants to use containers that integrate tightly with the rest of the system with very little isolation versus Flatpak wants to be maximally isolated with only the permissions necessary for the application.

That isn't to say that apptainer can't use more Linux features to increase isolation. It supports the use of cgroups for resource quotas and can take advantage of different types of namespaces for network isolation among other things.

Now as far as "OSTree vs containers" statement you are replying to... This is kinda misleading.

OSTree is designed to manage binaries files in a way similar to git with text file. It isn't a type of container technology in itself. It just used for managing how objects on the file system are arranged and managed.

It is used by some flatpak applications, but it is used for things besides flatpak.

The 'containers' he mentioned is really a reference to OCI container image format.

OCI container images is, again, a way to manage the file system contents typically used in containers. It isn't a container technology itself.

It is like a tarball, but for file system images.

OCI containers is a standardized version of Docker images.

Due to the popularity and ubiquity of OCI image related tools and hosting software it makes sense for Flatpak to support it.

OCI images, when combined with bootc, also can be used to deploy Linux container images to "bare hardware". Which is gaining popularity in helping to create and deploy "immutable" or "atomic" Linux distributions. Fedora Atomic-based OSes seem to be moving to use Bootc with OCI over pure OSTree approach... although they still use OSTree in some capacity.

Incidentally Apptainer supports the use of OCI images (in addition to it's native SIF) as well as other commonly used container technologies like CNI. CNI is container network interface and is used with Kubernetes among other things.

lotharcable··on Apptainer: Application Containers for Linux
OCI image repositories are pretty ubiquitous nowadays and are trivial to setup.

I am sure that a lot of people have them deployed and don't even realize it. If you are using Gitea, Gitlab, Github, or any of their major forks/variations of you probably already have a place to put your images.

So I really don't know what the advantage of 'single file distribution model' is here.

This is probably why people don't bother sharing tarballs of docker images with one another even though it is has been a option this entire time.

lotharcable··on Games run faster on SteamOS than Windows 11, Ars testing finds
> So if I understand correctly, you're suggesting that in essence the VM lied to Windows to improve performance?

Pretty much. Just speculating because I don't know how your systems was configured back in the day.

But all of what I said applies to most VM solutions.

If you are dealing with enterprise-grade hardware it isn't a bad things. Keep in mind that typically OSes are going to assume that they are the only things operating on storage. So if you have like 30 windows boxes all trying to write to shared disk at the same time it can lead to some bad behavior if you are not using a write cache.

The system has battery backup and typically they expect you to use shared SAN or NAS with multipath and/or bonded network interfaces for redundancy as well as having backups. So the chances of data loss is a lot less then typical consumer hardware and it gives the hosting OS better chances at optimizing and scheduling writes properly.

Also remember the guest OS still has the option to send a 'flush' command to disk, which would ensure the writes complete regardless.

> It's been many years, but I don't imagine I would have chosen an option like that. I am very surprised VMWare would default to such behavior.

This is pretty normal. You'll see the same sort of options with hardware RAID devices and such things with their own internal battery-backed cache.

lotharcable··on Games run faster on SteamOS than Windows 11, Ars testing finds
For gaming and general desktop on Linux AMD is best if you want a dedicated GPU.

If you want a laptop with good battery life Intel is generally the way to go.

A lot of this is due to the enormous amount of effort Valve put into improving the open source AMD drivers, which is what is used on their Steam platform.

Of course if you want CUDA you need Nvidia, but if you use Nvidia to drive your Linux desktop expect some suffering to go along with it.

lotharcable··on Games run faster on SteamOS than Windows 11, Ars testing finds
Sorta. The devil in the details here.

Depending on the VM technology they use they offer a variety of different caching mode and configurations, but the basic three approaches that most everybody offers are going to be something like;

"writeback" means that when the guest's storage data ends up in the host's cache it is reported back to the guest as 'written'. This means that from the guest's perspective the disk is written to, but in actuality the data is still floating around in memory. If the guest wants data to be 'safe' they need to issue additional flush commands.

"writethrough" means that the host is using its memory for caching file system, but that writes are reported as 'competed' only when they have been committed to actual disk.

and "none" means the cache is used as little as possible.

So if your guest's virtual disk is in 'writeback' mode it isn't actually writing to real disk. It is writing to memory. Which is going to be very fast up to the point were the cache on the host is exhausted.

Certainly Windows could lie to applications and not write information to disk and keep it in memory much longer then it normally would but that would defeat some of the assurances that file systems are supposed to offer to applications.

'writeback' would be closer to what Windows already implements on the OS level, but because Linux is just plain faster it should improve performance somewhat. Microsoft can only work in improving the performance of Windows to get the same results, but Linux is pretty hard to beat.

'none' is what I use when running Linux on Linux because having two layers of cache is just kinda wasteful and doesn't result in real improved performance.

lotharcable··on Ancient X11 scaling technology
It is using OpenGL to draw instead of using X11.

Which pretty much means that it is using the same code paths and drivers that get used in Wayland.

lotharcable··on Ancient X11 scaling technology
Windows is the only platform that tries to do it "correctly" as per the internet peanut gallery.

And, of course, doing it "wrongly" as per what OS X and Gnome does works a lot better in practice.

lotharcable··on Ancient X11 scaling technology
Yes toolkit authors have realized they have to avoid X11 as much as possible if they want to have good results.

This one of the major motivations as to why X11 guys decided Wayland was a good idea.

Because having your display server draw your application's output instead of your application drawing the output is a bad idea.

lotharcable··on Atuin – Magical Shell History
I self host a atuin server.

It is a very easy thing to do.

You can use atuin without syncing it between multiple machines.

I have my shell environments divided up into different distrobox containers. Some of them sync between multiple machines. Some of them don't. Depends what the shell is for.

lotharcable··on Making TRAMP faster
Tramp can work better for containers then it does over SSH.

I use it conjunction with distrobox and podman. It should be able to work with kubernetes as well.

← PreviousPage 2 of 5Next →