HNHacker News
TopNewBestAskShowJobs

nikeee

1,587 karma · joined May 5, 2015

submissionscomments
nikeee··on JEP 540: Simple JSON API (Now in Incubator)
I don't like this:

    String body = ... REST response body, which is a JSON document ... ;
    JsonValue json = Json.parse(body);
    json.get("properties").get("periods").asList().stream()
        .mapToInt(j -> j.get("temperature").asInt())
        .average()
        .ifPresent(IO::println);
Why am I able to call `.get(string)` or `.get(int)` on a JsonValue? Shouldn't these be on the JsonObject and JsonArray instead?

> If the JsonValue instance is of the wrong type, or if the requested member or element does not exist, the access methods throw a JsonValueException.

So if I get an exception, I can't tell whether the value was of the wrong type or the object didn't have the requested key? This looks like a footgun to me.

They just brought pattern matching to Java. Why not move those .get to JsonArray and JsonObject? That would solve this confusions. So we could just use something like `if (json instanceof JsonObject o) o.get("properties")`

nikeee··on Throwing AI-generated walls of text into conversations
I suspect that, too. But to me, it signals the exact opposite.
nikeee··on Throwing AI-generated walls of text into conversations
In that case I still want to see exactly this prompt. Then I know that the person didn't even think about my question thoug I asked _them_ for their opinion and I could have asked ChatGPT myself (and already probably have).
nikeee··on Throwing AI-generated walls of text into conversations
When I'm encountering some WoT like that, I'd like to have a button like "view source", but for "view prompt".

Most ai generated messages or docs are unnecessarily verbose and just reading the prompt would suffice. I don't really get why some people seem to think that it's somehow better to have their bullet point prompt as a huge text.

It just wastes my time. And probably only makes it look like it took more effort than it actually did (it may be the exact opposite).

nikeee··on Zig → Rust porting guide
Zig is a moving target that has breaking changes in every release (which is fine as they are sub-1.0). But that means that AI tools have been trained on outdated syntax/etc. Zig isn't that common, so there is even less training data to begin with.

Rust on the other hand is pretty established by now and has less breaking changes. It also has more compile-time safety-guarantees that makes vibe-coding a bit more confident.

In top of that, Zig has rejected their upstream contributions. So they'd have to maintain their own compiler in the long run, which is probably just technical debt to maintain.

nikeee··on I just want simple S3
I am building an S3 client [1] where I have a test matrix that tests against common S3 implementations, including RustFS.

That test matrix uncovered that post policies were only checked for exsitence and a valid signature, not if the request actually conforms to the signed policy. That was an arbitrary object write resulting in CVE-2026-27607 [2].

In the very first issue for this bug [3], it seemed that the authors of the S3 implementation didn't know the difference between the content-length of GetObject and content-length-range of a PostObject. That was kind of a bummer and leads me to advise all my friends not to use rustfs, though I like what they are doing in principal (building a Minio alternative).

[1]: https://github.com/nikeee/lean-s3 [2]: https://github.com/rustfs/rustfs/security/advisories/GHSA-w5... [3]: https://github.com/rustfs/rustfs/issues/984

nikeee··on Does coding with LLMs mean more microservices?
What matters for LLMs is what matters for humans, which usually means DX. Most Microservice setups are extremely hard to debug across service boundaries, so I think in the future, we'll see more architectural decisions that make sense for LLMs to work with. Which will probably mean modular monoliths or something like that.
nikeee··on Temporal: The 9-year journey to fix time in JavaScript
It is called Duration.
nikeee··on Making WebAssembly a first-class language on the Web
> the only viable use cases were compute-heavy workloads like codecs and crypto,

I tried using it for crypto, but WASM does not have instructions for crypto. So it basically falls back to be non-hw-accelerated. Tried to find out why and the explanation seems to be that it's not needed because JS has a `crypto` API which uses hw intrinsics.

nikeee··on Package managers need to cool down
That could probably be solved by opting in to the permission model of Node. But that won't work for everybody, especially in legacy applications.

Having trusted dependencies at least drastically reduces the risk that 'git clone && npm install' takes over the entire system.

Cooling down dependencies would certainly help, also.

nikeee··on Package managers need to cool down
Some tools also install pre-commit hooks. I don't like this practice, but I get why people are using it.
nikeee··on Package managers need to cool down
Bun added `trustedDependencies` [1] to package.json and only executes postInstall scripts coming from these dependencies. I think this is something that should be supported across all JS package managers, even more than version cooldowns.

[1]: https://bun.com/docs/guides/install/trusted

nikeee··on What does " 2>&1 " mean?
So if i happen to know the numbers of other file descriptors of the process (listed in /proc), i can redirect to other files opened in the current process? 2>&1234? Or is it restricted to 0/1/2 by the shell?

Would probably be hard to guess since the process may not have opened any file once it started.

nikeee··on I found a useful Git one liner buried in leaked CIA developer docs
I use git-trim for that:

https://github.com/foriequal0/git-trim

Readme also explains why it's better than a bash-oneliner in some cases.

nikeee··on Farewell, Rust for web
Or you don't use the defualt case and rely on definite assignment analysis or checks for returns in every code path.

I find the never type in TS actually being a proper bottom type + having control-flow based types vastly superior to what rust offers.

nikeee··on Nuudel: Non-Tracking Appointment Tool
There was dudle [1] developed and hosted by a German university. Seems unmaintained, but there is an independent project called BitPoll [2].

[1]: https://github.com/kellerben/dudle [2]: https://github.com/fsinfuhh/BitPoll

nikeee··on Dead Internet Theory
I hope that when all online content is entirely AI generated, humanity will put their phone aside and re-discover reality because we realize that the social networks have become entirely worthless.
nikeee··on AWS European Sovereign Cloud
What if the software is developed and potentially backdoored in the US and deployed by the EU team in the sovereign region? Or did they rewrite the entire AWS stack?
nikeee··on Kidnapped by Deutsche Bahn
Keep in mind that a train in Germany counts as one-time if it is less than 6 minutes late. In Switzerland, it's 3 minutes.

Also in Germany, a train that did not even arrive does not count as too late.

There is also a concept of the "Pofalla-Wende", which is when a train is so late that it just does a 180 and drives back, to mitigate that the delay doesn't carry over to the train's next route. Of course, that means that it skips the stations at the end of the route.

nikeee··on Pricing Changes for GitHub Actions
Given that I can dump hundreds of TBs into the private container registry without paying anything I'm pretty surprised that they now charge for what is basically providing log streaming and retention.
nikeee··on Icons in Menus Everywhere – Send Help
MS Office only has icons for the things that matter most. I think MS even had a UI guideline similar to the one that is cited from apple in TFA, but I cannot find it.

The author doesn't ask for _no_ icons at all. So I really don't get this critique.

Intentionally omitting some icons is a really powerful tool to draw attention to the actions that the user wants to do most of the time. I think that pattern went away in some places because it looks more consistent (that doesn't mean that usability is better) and some designers have some kind of OCD. At least that's what I have experienced in that exact case.

nikeee··on Checked-size array parameters in C
GCC also has an extension to support references to other parameters of the function:

    #include <stddef.h>
    void foo(size_t n, int b[static n]);
https://godbolt.org/z/c4o7hGaG1

It is not limited to compile-time constants. Doesn't work in clang, sadly.

nikeee··on MinIO is now in maintenance-mode
I maintain an S3 client that has a test matrix for the commonly used S3 implementations. RustFS regularly breaks it. Last time it did I removed it from the matrix because deleteObject suddenly didn't delete the object any more. It is extremely unstable in its current form. The website states that it is not in a production-ready state, which I can confirm.

I'd take a look at garage (didn't try seaweed yet).

nikeee··on MinIO is now in maintenance-mode
Didn't contribute to MinIO, but if they accepted external contributions without making them sign a CLA, they cannot change the license without asking every external contributor for consent to the license change. As it is AGPL, they still have to provide the source code somewhere.

IANAL, of course

nikeee··on Progress on TypeScript 7 – December 2025
The "types as comments" proposal has a stated goal to not codify any semantics to the annotations.

This is not only due to implementation complexity, but also to keep TS to be able to change. Or even to build an entire different JS superset. With that proposal, even flow could be natively executed.

nikeee··on Google Antigravity just deleted the contents of whole drive
The folders actually have the English name in all languages. It's just explorer.exe that uses the desktop.ini inside those folders to display a localized name. When using the CLI, you can see that.

At least it's like that since Windows 7. In windows XP, it actually used the localized names on disk.

nikeee··on `satisfies` is my favorite TypeScript keyword (2024)
I still keep my assertNever function because it will handle non-exhaustiveness at runtime.
nikeee··on My Git history was a mess of 'update' and 'fix' – so I made AI clean it up
Yeah, "fixed it" doesn't provide any information that might be hallucinated.

Please don't use AI-generated commit messages blindly. Instead, use AI later when reading commit messages. It will have more context (following commits) to see what was actually happening. Having to guess whether a message was hallucinated by an AI won't help. If the message conflicts in its intention with what it isactually doing, you can spot the bug. You won't get that with AI messages.

Also, using AI commit messages will freeze it's capabilities in time, when creating the commit. When using AI at reading commit messages, you'll always get the latest options for analyzing the commits.

Just because it has more text doesn't make it a better message.

nikeee··on Using the Web Monetization API for fun and profit
Not to be confused with the already existing Payment Request API: https://developer.mozilla.org/en-US/docs/Web/API/Payment_Req...
nikeee··on NaN, the not-a-number number that isn't NaN
I think a better reasoning is that NaN does not have a single binary representation but in software, one may not be able to distinguish them.

An f32-NaN has 22 bits that can have any value, originally intended to encode error information or other user data. Also, there are two kinds of NaNs: queit NaN (qNaN) and signalling NaNs (sNaN) which behave differently when used in calculations (sNaNs may throw exceptions).

Without looking at the bits, all you can see is NaN, so it makes sense to not equal them in general. Otherwise, some NaN === NaN and some NaN !== NaN, which would be even more confusing.

Page 1 of 11Next →