HNHacker News
TopNewBestAskShowJobs

prussian

261 karma · joined March 24, 2020

submissionscomments
prussian··on Sherver: Bash lightweight web server
Someone beat me to it. When I think of pure bash, I don't really think of invoking anything that isn't a builtin or a grammatical feature of bash. If socat is fair-play, almost anything you can spawn on a shell should count then.

edit: on top of that, I already found a perl script utility in the repo: https://github.com/remileduc/sherver/blob/master/scripts/uti...

prussian··on Prevent Zoom from consuming all your CPU on Linux
https://chrome.google.com/webstore/detail/zoom-redirector/fm...

I just use this. I'm assuming that is what you're asking about.

prussian··on File picker meme
Not really how? https://github.com/ranchester2/nautilus-as-file-chooser-poc This is a standardized GTK workflow that works in and out of flatpak.
prussian··on File picker meme
I believe that is the purpose of the xdg portals specification.

https://flatpak.github.io/xdg-desktop-portal/portal-docs.htm...

prussian··on SF's crime debate turns nasty
This seems strange to me though. How does one collect on insurance without it being reported to the police? Are businesses and individuals just eating the cost or are adjusters just writing out checks without a police report?
prussian··on Mimicking a device is becoming almost impossible
Starting to wonder if the techniques like those outlined in this article are why I'm constantly presented with a captcha asking if I'm a bot. I suppose the future is now.
prussian··on QUIC at Snapchat
So in such cases, why not just use a camera activity or at least expose a configurable choice for which experience the android user prefers? It is unfortunate that the camera API clearly needs more work though.
prussian··on Lethal Autonomous Weapons Exist; They Must Be Banned
Hell you don't even need to go that high tech. Just make model jet aircraft cheaper, easier to handle, maybe even autonomous and I'd like to see those current anti-drone countermeasures stop it from zooming in and dropping whatever dumb payload someone could possibly want.
prussian··on SSH quoting
This is a common problem I see a lot at my current job and the only advice I can give you is just say no. If you must use something akin to system() there are tools bash provides like:

    printf -v quoted %q "$my_shell_crud"
Or

    printf %s "${my_shell_crud@Q}"
This problem exists in other unfortunate and unlikely places like:

    echo "some script" | at ...some time spec
If you don't want to use bash, the gnu awk info docs has a snippet that you can use in any awk I know of: https://www.gnu.org/software/gawk/manual/html_node/Shell-Quo...
prussian··on GNU Coding Standards: Writing Robust Programs
> I've spent 10 years writing security critical C code. There's no problem writing secure code in C. You just have to stop being clever and prioritize security above "speed". Your code will probably be fast enough anyway.

Are there good examples of what you mean by this? From my own C++ experience, when dealing with c libraries and std::string types, I'll sometimes use the copying api's[0] when passing around std::string::c_str() because I find it easier than worrying about invalidating the returned reference if the string is destructed or modified.

[0]: e.g. https://curl.se/libcurl/c/CURLOPT_COPYPOSTFIELDS.html

prussian··on Helix: a post-modern modal text editor
not sure about worse. enabling evil-ex-visual-char-range allows you to do things ex commands in (neo)vim cannot do. That is, run things like !rev on a visual select. in (neo)vim this reverses the whole line where with (evil-ex-visual-char-range t) enabled in evil does what I'd argue is expected, only reversing the string selected in visual mode.
prussian··on HTML Sanitizer API
Given I've seen some CMS's double escape html character entities and other such bad uses of sanitation filters, I think it is a reasonable concern to think about. Forcing people to source a library would make it clear what their intent is in terms of cleaning things up.
prussian··on HTML Sanitizer API
The only positive I can think of, is you run, say a comment section on a news aggregator. You could let people freely type up their own markup in a <textarea>, accept it as is and just throw it at clients to clean on their own. Another great use I could think of, say you have an image upload service, assuming this would work with SVG as well, you could just serve all sorts of potentially malicious SVG and have the client remove all the script tags.

While I'd prefer the inputs stored server-side to be pre-sanitized, I can see the benefit for just not touching it and shrugging.

prussian··on HTML Sanitizer API
This feels an awful lot like we're going full PHP[1]. Can't this just remain as a library someone else could implement?

[1]: https://www.php.net/manual/en/filter.filters.sanitize.php

prussian··on The handshake emoji is more complicated than you might think
This honestly reminds me how on skype (for business) or Lync, where people would type strange messages to me that I didn't understand, but in skype/lync apparently it was transformed into a thumbs up emote; I was using pidgin/sipe which didn't do this. I'd say for the most part, at least Emojis generally work everywhere I need them and I even get the hatching representations in most VT100-like emulators. the worst case I've seen is some of my environments cannot handle the modifiers, which honestly doesn't matter. I can see the symbols and reconstruct what they mean myself.
prussian··on My Favorite One Liners
Even funner quirk with stuff like that:

    $ bash -c 'shopt -s extglob; rm -- !(x)'
    bash: -c: line 1: syntax error near unexpected token `('
    bash: -c: line 1: `shopt -s extglob; rm -- !(x)'
Because of the strangeness of the bash parser, the glob has to come on the preceding line:

    $  bash -c $'shopt -s extglob\nrm -- !(x)'
prussian··on Volta
I remember contributing a fix for an expansion issue in either bash or zsh (can't really recall) for nvm. Just running it was very, slow. This slowness is primarily why I usually use guix / nix on my distro of choice instead. I'm glad this exists as I can imagine this way of handling which node to use is much faster than how nvm was doing it.
prussian··on Ignoring Docker updates is a paid feature now?
For docker desktop you should be able to manage your own Linux VM install and forward the dockerd socket to your host machine and use the docker tooling with the appropriate DOCKER_HOST environment variable. As far as I remember, that's basically how docker desktop works.
prussian··on Experian’s credit freeze security is still a joke
ID Kiosk skimming or shimming perhaps. Some kind of MitM
prussian··on Btrfs on Zoned Block Devices
it is kind of humorous having to balance regularly. I had hit a problem where statfs() call returned a { .f_bavail = 0 } which made some tool complain; funnier, the other statfs information was their expected values and one could calculate bavail correctly from them. I didn't even notice it until then. The solution unfortunately was a full fs rebalance and for some reason the rebalance tool will usually fail with some unhelpful and scary warning.

either way, my story is the same as yours. I have no troubles, I have at least ~10 daily snapshots of many subvolumes I can pull from if I accidentally: `rm -rf /usr` or something silly like that. It's a great FS and unlike ZFS, is actually upstream in the Linux kernel.

prussian··on How to navigate directories faster with Bash (2015)
I'm surprised autocd was not mentioned. I saw

  alias ..='cd ..'
  # etc ...
But not.

  shopt -s autocd
zsh also has this. This seems like the fastest way to navigate since you no longer need to type, or retype, cd.
prussian··on Linus Torvalds on Rust support in kernel
I'm more than familiar with overcommit and it has nothing to do with being out of memory. In fact, im explicitly talking about the kernel failing to allocate (-ENOMEM) in a alleged future driver.

It may interest you to know the WebKit takes this behavior to 11 and actually uses overcommit to isolate heaps even. That "runway" of memory between heaps is not used and thus the +99GiB virtual memory size is bunk. Really nothing to do with being out of memory.

prussian··on Linus Torvalds on Rust support in kernel
What does this have to do with my comment? If you're out of memory, how can zig know you can just continue on? What if your memory is held in tasks that are effectively dead-locked because a dependent task is incapable of allocating? There are many things that can be happening once memory is effectively maxed out. The more common towards the edge is higher I/O and the system crawls.

I'm sure Zig is great, but I don't see from what you linked how that changes what I said.

prussian··on Linus Torvalds on Rust support in kernel
I mean, it sounds like you're describing overcommit to me. Ask whatever large amount you want. Maybe even be like webkit and use overcommit for heap isolation. It works out great for the userspace case, until the limits are actually reached and you still have a failure problem, one probably harder to deal with than without overcommit.
prussian··on Linus Torvalds on Rust support in kernel
It honestly isn't.

Out of memory means, your system is simply not designed for the task at hand. The kernel returning -ENOMEM only masks the fact that eventually Linux will have to OOM Panic if it can't OOM Kill. Hell imagine the swapping and the I/O spike because your VFS cache has been or is currently being purged. I honestly think the best case is to just fail when a fundamental resource is simply not there.

prussian··on Bitcoin miners are buying power plants
I don't think it helps that carbon isn't the be-all, end-all in the polluting effects of general consumption (including crypto mining). Even if all these miners were 100% green energy, the green tech would still be a net pollution on the world. I wish we stopped thinking of things so simply.
prussian··on Unusual Stock Trading by Whales in US Congress
Honestly, this should be held for any positions where insider information is clearly a conflict. Maybe not in specific instruments, but investments should be made through a third-party money manager.
prussian··on Bash-LSP: A language server for Bash
Kind of cute. Jumped around with xref and found callers for functions, but can't really imagine this to be useful unless you're as crazy as I am or also responsible to insane number of these _things_.

Not sure what qualifies as doc strings, I discovered you have to use two hashes for multiple lines. More documentation on that might be helpful then I can adjust my comments to match its expectations. Also I'm pretty sure I must have broken it or something is going on in emacs lsp as it stops doing anything.

prussian··on The Deno Company
late reply. I've sort of experimented with async iterators and using pipeline() to pipe them together and it seems to work out for the most part; not sure what is awkward about them, I mean consume with an async iter on the source passed as an arg and you can throw at any time to kill it with an error. In fact I find the new async generator transforms easier and more ergonomic. in terms of event emitters. I can just use `await once(emiter, 'event');` now. Not sure how .on would be expected to work outside of it being some kind of async iterator.

I mean, I don't mind using util.promisify or just importing the "to be" xyz/promises paths. The code exists clearly, either behind a symbol or otherwise.

prussian··on Don’t use environment variables for configuration
A files' contents are not effectively smuggled just because halfway through a file a NUL is in it, unlike environment or arguments.
← PreviousPage 2 of 4Next →