HNHacker News
TopNewBestAskShowJobs

mroche

3,603 karma · joined October 4, 2018

Systems Engineer at Skydance Animation

https://omenos.dev/

Online Accounts:

Git{Hub,Lab}, Codeberg, SourceHut: @omenos

Bluesky: @omenos.dev

Matrix: @mroche:fedora.im

Mastodon: @omenos@fosstodon.org

submissionscomments
mroche··on Context should go away for Go 2 (2017)
It sounds like you may have some friction-studded history with Go. Any chance you can share your experience and perspective with using the language in your workloads?
mroche··on Forgejo: A self-hosted lightweight software forge
Gitea 1.22 will be the last release with guaranteed migration support to Forgejo. The next Forgejo LTS release, v11, is due out around April. Migration from Gitea 1.23 will not be supported, and since it was released in December those on the fence are now at the fork in the road.

You still have time to figure out what to do, but you'll need to choose sooner than later.

https://forgejo.org/2024-12-gitea-compatibility/

mroche··on Forgejo: A self-hosted lightweight software forge
Gitea and Forgejo support OAuth integration and AGit Flow*, which is a breath of fresh air compared to the connected "fork" and PR strategies. It's a good middle ground between the "modern" method and email collaboration. With some UX tweaks it could become very accessible for many.

Available platforms like Codeberg provide the option to sign in/register with GitHub and GitLab auth, so needing "yet another account" has become a much weaker argument.

* https://forgejo.org/docs/latest/user/agit-support/

mroche··on Fedora's Captivating 2024 with Many New Features and Leading Innovations
Interesting experience, not one I can corroborate myself.

So a few weeks ago I updated to Fedora 41. (Updating from N-2 -> N is supposed to be fully supported)

Correct, and I do believe F39 -> F41 was tested, but every system will be a little bit different.

I wasn't surprised that it broke my nvidia driver's dkms integration - I don't expect any distro to test their integration of the market leader GPU manufacturer.

Fedora actually does test this. What driver installation method are you using? Unless you are using NVIDIA GRID for vGPU or need to use a very specific version of the generic Linux driver, use RPM Fusion's akmod-nvidia package[0]. Normal DKMS via NVIDIA's modularity CUDA repositories or the binary installer can be fraught with issues that users don't deserve. Rather than just installing the kmods directly, an akmod package will build an RPM for the modules and install that. You'll know well in advance if there's a problem before you reboot, nor have to twiddle your thumbs during the upgrade transactions. Just give the system an extra minute after running a kernel update before rebooting (watching "ps aux" for "dnf", "kmod", and "rpm" helps). Several system configurations regarding module parameters and initramfs boot options are included as well.

I finally did this today (I have a GTX 1070), but configuring my kernel parameters[1] to disable NVIDIA's fbdev allows me to once again have alternate console TTYs. Despite being an experimental option, it is enabled by default in newer drivers and it conflicts with another framebuffer. For the past few Fedora releases since it was flipped on I've had to use a second device to SSH to my system after the version upgrade to gracefully reboot once the driver module package rebuilt. The akmod rebuild trigger doesn't stall the offline upgrade reboot, so the driver isn't prepared in time for first boot. My standard practice is configuring my system to the multi-user target before issuing an offline version upgrade, then switching back after.

the system was suspended. When I wake it up, the screen is also locked. That was weird, as I have disabled all power mgment features, and I have also passwordless autologin on this machine. Then looking at some of the logs, it turned out that xdg-desktop-portal segfaulted in the middle of the night, which in turn killed all user sessions and processes and logged me out. And then it ignored my powermgmt settings, and sent the machine to sleep.

That is definitely a new one to me. In addition to your searching, did you happen to follow through with Fedora's problem reporting checklist[3]? It's not a mandatory step, but it can be incredibly helpful having these issues documented and brought to engineering's attention.

[0]: https://rpmfusion.org/Howto/NVIDIA (alternatively just enable the NVIDIA driver specific repository pre-provided by Fedora: dnf config-manager --enable rpmfusion-nonfree-nvidia-driver)

[1]: grubby --update-kernel=ALL --args="nvidia-drm.fbdev=0" && dracut -f

[2]: https://docs.fedoraproject.org/en-US/quick-docs/bugzilla-fil...

mroche··on ScyllaDB no longer open source
The Redhat model just doesn’t work in 2024 with the sharks constantly looking for fresh meat.

I truly believe that the Red Hat model is still possible to achieve today, but the barrier of entry is much higher than before. What sets Red Hat apart from many of these VC backed projects is what they actually offer. Red Hat doesn't primarily provide "services" or singular components like a database^, but delivers platforms.

RHEL, OpenShift, Ansible Automation Platform, OpenStack, Satellite, etc, are the aggregation of many open source projects tied together to make an offering appealing and attractive to enterprises. They produce the infrastructure and management layers of the stack that all your services and applications are deployed on. Working at this level enables a very different degree of flexibility and "safety" in comparison to single application or SaaS style offerings.

There's distinct boundaries of their products as well from the upstream variants: Fedora vs CentOS vs RHEL, OKD/SCOS vs OCP/RHCOS, RDO vs RHOSO, Ansible ecosystem vs AAP, etc. Red Hat also delivers on support, training/education, partner-driven sales, and OEM integration/certification.

^ Main exception would really be the Java middleware solutions, but the Runtimes and Integration offerings could be argued as a platform of their own. Same with RHEL/OpenShift AI.

mroche··on JavaScript Benchmarking Is a Mess
ThePrimeTime posted a livestream recording a few days ago where he and his guest dove into language comparison benchmarks. Even the first 10 minutes touches on things I hadn't thought of before beyond the obvious "these are not representative of real world workloads." It's an interesting discussion if you have the time.

https://www.youtube.com/watch?v=RrHGX1wwSYM

mroche··on PostgreSQL High Availability Solutions – Part 1: Jepsen Test and Patroni
One thing possibly holding some folks back is the version of Postgres it's held back to. Right now YDB has PostgreSQL 12 comparability. Support for PG15 is under active development, so hopefully it's a 2025 feature. I really wanted to be able to actually use YugabyteDB for once, but our developers reportedly are using PG15+ features.

https://github.com/yugabyte/yugabyte-db/issues/9797

mroche··on Advent of Code 2024
I don't think it attempted to redefine the term, but "web" was left off the beginning of the phrase. Go's primary strength is in creating distributed, concurrent services and other networked systems. This makes sense as a language born within Google, though like any language it can be used for other purposes.
mroche··on Backdoor attempt on Exolabs GitHub repo through an innocent looking PR
If tags are the way people want to work, then there needs to be a new repo class for actions which explicitly removes the ability to delete or force push tags across all branches. And enforced 2FA.

Using a commit hash is the second most secure option. The first (in my eyes) is vendoring the actions you want to use in your user/org's namespace. Maintaining when/if to sync or backport upstream modifications can protect against these kinds of attacks.

However, this does depend on the repo being vetted ahead of time, before being vendored.

mroche··on A React Renderer for Gnome JavaScript
I think it's important to note that GNOME extensions aren't a "real" thing as they have no API. They are runtime modifications injected directly into the GNOME environment. This means if their instantiation, cleanup, or operation are not well defined or are buggy, they can break the entire shell. It's not a plugin or add-on system using a dedicated/sandboxed API set to integrate while isolating them from the core platform.

https://gjs.guide/extensions/overview/architecture.html

mroche··on Create block devices on your computer backed by Redstone Memory
I'm speechless, it is amazing this is even possible. But it's more impressive to me that someone actually thought of this idea and decided to attempt it in the first place.

Sometimes side and off-the-cuff projects are just wacky enough to become amusingly interesting, and inspiring to try something crazy yourself.

mroche··on SELinux bypasses
There are two components to SELinux alerting mechanisms, both of which are documented.

For GUI notifications open the sealert app and disable alerts. For journal/syslog reports disable the setroubleshoot daemon dispatch plugin for auditd:

    sed -i 's/active.=.yes/active = no/' /etc/audit/plugins.d/sedispatch.conf
    service auditd restart
You can also uninstall the setroublshoot-server package completely, and all AVC denials will continue be reported separately outside of the journal.
mroche··on "Extreme" Broadcom-proposed price hike would up VMware costs 1,050%, AT&T says
Thanks for clarifying, that's what I assumed you meant. I've just seen enough people get antsy or vocally against free software using a copyleft license instead of a permissive one* it makes me second guess some phrasings.

> being open source doesn’t automatically mean you can use the software commercially

I acknowledge there is a split in recognizing "open source" as between (a) a broad term of source code read-ability or (b) attributed to the specification defined by the Open Source Initiative. I see both arguments, but I believe using the OSI definition can eliminate some of these uncertainties.

* Despite the fact it's an end-user tool/application they will not be exposing, modifying, or extending in any way.

mroche··on "Extreme" Broadcom-proposed price hike would up VMware costs 1,050%, AT&T says
> Open source software with permissive licensing is the only true guarantee of not getting squeezed.

I may be misinterpreting here, so please do correct me.

Does the permissiveness of the license matter more than the utility of the tool? Whether or not an application/platform is using a permissive or copyleft license shouldn't really be a determining factor here for viability or vendor escape.

> But you can’t always find suitable FOSS etc.

This is the most prevalent problem, it's a lot easier to just spend money for a working tool than use an open source project that doesn't have everything you need, causes papercuts, and is being worked on in the developers' spare time.

However, a lot of FOSS options would be much better off if consumers did contribute to the project. Code is great, but financial support to the core developers goes much, much farther. Particularly if it enables them to prioritize the project over other things in life.

mroche··on Show HN: Ki Editor – Multicursor syntactical editor
> in vim it's wwwww

You may also want to try out <num><action> methods while in normal mode.

    # Move forward 5 words
    5w

    # Move 20 lines up
    20k
The latter paired with relative line numbering can be really handy.
mroche··on The Monospace Web
I'm a fan of the Red Hat font family, i.e. Red Hat Display, Red Hat Text, and Red Hat Mono. They are available via CDNs, font providers, and directly from Red Hat:

https://www.redhat.com/en/about/brand/standards/typography

mroche··on Why we picked AGPL
I'm a fan of AGPL as well, but there's a point of possible confusion for GNU license variants I personally run in to and maybe others as well. It may be worth specifying which variant of the AGPL you are using, e.g. AGPL-3.0-only or AGPL-3.0-or-later.
mroche··on Server Mono: A Typeface Inspired by Typewriters, Apple's SF Mono, and CLIs
I'm really surprised this made it through, it's one of the handful of character sets that require distinct glyphs to prevent confusion/mixups.
mroche··on Verso – Web browser built on top of the Servo web engine
There are two simple solutions to this:

1. Translate the word to another language.

2. Get creative and make up an original name. Mixed translations, word-bashing, not-actual-words, there's a lot of options!

Okay, so the latter isn't super easy but can be a lot of fun to do!

In this case, it seems like a play on the core dependency name than choosing the actual word of "verso": servo -> verso.

mroche··on Animated Film Making Process
There's a bit of an industry adage here: Every improvement and enhancement in compute performance enables an equal and opposite advancement in software capabilities and complexity, resulting in render times staying the same. While a fairly broad and generalized statement, it is reasonably true for a lot of aspects of our industry.

For fun I asked Kagi "why haven't render times gotten better over the years?". The results were pretty spot on:

"""

Increased Complexity: As software evolves, the complexity of scenes and effects increases. Features like advanced lighting, volumetrics, and motion blur require more computational power, often offsetting any improvements in hardware.

Higher Quality Expectations: The demand for higher resolution and quality (e.g., 4K and beyond) leads to longer render times. Users expect more detailed visuals, which inherently take longer to produce.

Hardware Limitations: While hardware has improved, the efficiency gains may not be enough to keep up with the growing demands of modern rendering techniques. For example, ray tracing can dramatically increase render times, and not all hardware can handle it efficiently.

Software Optimization: Not all software updates prioritize optimization. Some updates may introduce new features that, while enhancing capabilities, also increase render times.

Rendering Techniques: Different rendering engines and techniques (e.g., CPU vs. GPU rendering) have varying performance characteristics. Depending on the setup, some may not see substantial improvements.

Overall, while there are advancements in technology, the balance between quality, complexity, and hardware capabilities often results in stagnant or even increased render times.

"""

mroche··on Can we trust Microsoft with Open Source? (2021)
Any particular shenanigans from IBM and Red Hat aside from the EOL and transition of CentOS that was widely viewed internally within Red Hat as an absolute train wreck? For an open source and free software steward, I would side with Red Hat over Microsoft in most (if not all) situations.

That's not to say Red Hat is infallible. The internal organization of things does create misalignments around approach, path, and incentives. But it's not drastically different conceptually from any other business. There's just an inherit foundational hurdle of needing to convince potential customers that their products provide enough value over the upstream projects they derive from to agree to pay money for something they could, in essence, obtain at no-cost.^ Almost everything Red Hat does in the FOSS projects they contribute to can be a double edged sword.

^ No-cost can be a very, very loaded term. What you save on subscription costs may come back to bite you when trying to assemble or use something complex and rapidly developing. Your cost/risk tradeoff becomes staff with expertise, upstream communication, and operational reliability.

mroche··on Using SIMD for Parallel Processing in Rust
Quick search turned up this:

SIMD in Pure Python

https://www.da.vidbuchanan.co.uk/blog/python-swar.html

Don't let the "SIMD in Python" section fool you, it's a short stop on Numpy before putting it aside.

mroche··on Google just updated its algorithm. The Internet will never be the same
You can switch it to a centered layout in your account preferences in the Appearance tab.
mroche··on IBM nearing a buyout deal for HashiCorp, source says
Is there a specific aspect of k8s that's causing friction along the learning curve? I'm assuming your referring to the developer side of the equation, not the ops/admin workflows.

Before jumping straight into production k8s, something you can mess around with is using Podman to generate[0] and run[1] Kubernetes resources that you can parse through and familiarize yourself with. Paired with Podman Desktop[2] can produce a nice graphical environment. After that you could take a look at more production-simulating environments with minikube[3], OpenShift Local[4] (very much recommend if you have the resources to run it), and the no-cost OpenShift Sandbox[5].

In general, the Red Hat Developer[6] site has a lot of good resources to learn from, both passive and interactive. I highly recommend going through the courses and tutorials available if it can help your team skill up (assuming k8s is the direction you want to go in).

[0] https://docs.podman.io/en/latest/markdown/podman-generate.1....

[1] https://docs.podman.io/en/latest/markdown/podman-kube.1.html

[2] https://podman.io/features | https://podman-desktop.io/

[3] https://minikube.sigs.k8s.io/docs/

[4] https://developers.redhat.com/products/openshift-local/overv...

[5] https://developers.redhat.com/developer-sandbox

[6] https://developers.redhat.com/

mroche··on Seismologists suspect earthquake on San Andreas Fault is imminent
This is the way the world ends

This is the way the world ends

This is the way the world ends

Not with a bang but a whimper.

---

Excerpt from The Hollow Men by T.S. Eliot[0].

I'll have to add it to the page, but it was also used as the introduction for The Compound by S.A. Bodeen[1]. It's an interesting young adult novel about a family living underground in a state of the art bomb shelter after a nuclear attack occurs.

[0] https://en.m.wikipedia.org/wiki/The_Hollow_Men

[1] https://bookshop.org/p/books/the-compound-s-a-bodeen/1554853...

mroche··on Retrospective on 10 Years of colour-science
Thomas, thank you and everyone contributing to Colour Science for the work you have done. You have truly pushed color management and understanding of the pipeline to the next level. It's great to see your efforts merged into the upstream project (the CS ACES configs were a lifesaver at the time), and I'm definitely going to have to take a look at Colour in the near future!

If you rely on or have benefitted from this work, considering sharing some coin with them over on OpenCollective!

https://opencollective.com/colour-science

mroche··on Microsoft unbundles Office and Teams globally following years-long criticism
I have a preference for Slack over GChat, but I last used the latter in 2021. I had the opportunity to use it briefly during the latest major Teams outage so my team could keep communicating. Some things were definitely different than I remember, but I'm pretty sure in a good way. Didn't get enough time to do a full review, though.
mroche··on Microsoft unbundles Office and Teams globally following years-long criticism
I no longer buy this argument these days. You don't need a "heavy" argument to avoid Teams, you need decision makers who can listen to teams other than the bean-counters.

Sure, it has integrations with the broader Microsoft suite and productivity ecosystems making it easier to approve if the org is a M/O365 org. However, this is not a universal state (Google Workspace, Zoho Workplace, etc), and if the decision maker actually cares about communication efficiency then Teams would never be part of the discussion. There's such a wide field for messaging and calling applications, just going with "easiest bundle that ticks boxes" is rather poor thinking (not that I'm expecting much from C-Suites these days).

I currently have to use Teams today across macOS, Linux, and Windows... personally, I would welcome switching to Google Chat (used at last gig) over this mess.

mroche··on I no longer maintain my Emacs projects on Sourcehut
I run a self hosted Forgejo instance in my homelab, and have it set up to push mirror to hosted forges for redundancy/publication. It's stupid easy to set up and maintain (I've given it 2vCPUs, 2GiB of RAM, and a 20GiB disk).
mroche··on I no longer maintain my Emacs projects on Sourcehut
> GitLab’s UI really feels like it steers you towards work inside of a company more than open collaboration like GitHub does.

That's kind of what it was designed for, though. GitLab.com wasn't a popular choice for open projects compared to GitHub until the "big migration" several years ago. Before that, GitLab was very popular for self-hosted internal instances (their customer reel demonstrated that). Even before modifying their OSS org policy for self-hosting, many groups ran their own GitLab CE instance. You couldn't (and still can't) do this with GitHub*. It also had a longstanding unlimited private repos compared to GitHub's free tier (formerly) that enticed developers.

GitLab's UI/UX was made for business workflows and processes (hence it being an "all-in-one DevOps platform." GitHub leans more into the community graph and semi-social media style for orgs/communities (the Discussions section a case example). It has come a long way for the business side, though.

* Yes, GitHub Enterprise Server exists: good luck getting it without paying for it (unless things have changed).

← PreviousPage 3 of 17Next →