HNHacker News
TopNewBestAskShowJobs

raggi

2,840 karma · joined December 24, 2009

submissionscomments
raggi··on Rune is now open source
Similar reflection, I ran `kitten __benchmark__ --render` in rune, the CPU time spent was 1:55. I ran the same in a libghostty based terminal emulator and spent 0:44 on CPU.

I say this only because yes you can do engineering to meet the benchmark without dropping to deeper systems layers, but closing the gap on efficiency is hard. I'm not saying this to be a downer on your project - an IDE and VTE in Go are a fun project to have around, but the blog post makes implied claims of equivalence with moderate investment - but I think that's limited to single benchmark chasing. I say this as a polyglot who's day job is a Go based program that would be far easier to optimize in a systems language.

raggi··on Rune is now open source
The build time claim in the blog post is dubious, part of the problem is CGO isn't fast, but also if build time was really a motivator the null build path is entirely unoptimized for objects with long build times:

cached null (no changes) build:

        ~github/unstablebuild/rune % make
        pre-commit not installed; skipping git hook setup
        cd cmd/buildstamp && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/buildstamp
        cd cmd/extension_chaos && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/extension_chaos
        cd cmd/extension_color_palette && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/extension_color_palette
        cd cmd/extension_fuzzy_search && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/extension_fuzzy_search
        cd cmd/extension_go && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/extension_go
        cd cmd/extension_python && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/extension_python
        cd cmd/extension_rtc && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/extension_rtc
        cd cmd/extension_rust && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/extension_rust
        cd cmd/extension_zig && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/extension_zig
        cd cmd/runefox && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/runefox
        cd cmd/sshshop && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/sshshop
        cd cmd/walkbench && CGO_ENABLED=1 go build  -ldflags="-X unstable.build/rune/internal/debug.Tag=$(git describe --tags) -X unstable.build/rune/internal/debug.Commit=$(git rev-parse --short HEAD) -X unstable.build/rune/internal/debug.BuildDate=2026-09-11T20:16:22Z  -X unstable.build/rune/internal/debug.Package=six" -o ../../bin/walkbench
        make  35.90s user 5.88s system 191% cpu 21.846 total 1975848 rss
vs. cached non-null (changed) build:

    ~github/zed-industries/zed % touch crates/zed/src/zed.rs
    ~github/zed-industries/zed % cargo build
       Compiling zed v1.18.0 (/home/raggi/src/github.com/zed-industries/zed/crates/zed)
       Finished `dev` profile [unoptimized + debuginfo] target(s) in 8.42s
    cargo build  10.15s user 9.34s system 228% cpu 8.531 total 7930312 rss

Build times are a valid thing to care about and talk about, but the claims implied don't stand up to scrutiny.
raggi··on Matrox: Graphics for Professionals
I have a friend whose wife has strong sight challenges. He once swapped a much newer and more powerful card with me for my last matrox card, iirc it was a millennium ii. The matrox utilities included with the drivers had one of the best desktop zoom systems ever delivered on windows and this was worth more to them than anything else.
raggi··on Tailcat – Like netcat, but over Tailscale’s data plane
always have! our darwin and windows clients are closed source, but they wrap the oss implementation in github.com/tailscale/tailscale and you can see and even use all the same hooks yourself.

the control plane is closed source, but headscale is an open source alternative that we embrace and encourage people to use if it meets their needs/desires

raggi··on Xwayland 26.1.0 rc1
> But, at the same time. A design that requires everyone to implement their own protocols and everyone to refix the same bugs in their own compositor is inherintly bad.

Consider that if every DE wrote their own Xorg implementation the story would be the same.

A key question is why everyone is writing their own compositor, this is not about the protocol design, it's about the state of collaboration.

I spent some time in the last week fixing lowdpi font rendering in cosmic, enabling me to switch to it. I then discovered that cosmic-comp's VRR had a terrible feedback path causing conformant applications to stutter badly, so I have large patch stack rewiring full screen feedback, tranche compatibility, fence timing and so on (it's fucking buttery now though, which is nice). That then showed up some input processing bugs becoming visible via playing videos in firefox, leading further to me discovering that cross-plane locking was causing frame drops too. Now I've got a giant stack of shit I need to cleanup and upstream - but the end result (along with the freetype render patches I got into Firefox a while back) is a better DE than I've had on Linux in decades. Maybe if upstreaming goes well I'll do MPO for an encore.

> In X, if the WM crashes, X is still running, and you can just restart the WM. In Wayland, if you hit a bug it takes everything down with it.

See above, the WM did not need to embed the compositor. That's not a protocol requirement, it's and implementer choice. I actually really wish it didn't. Of all the aforementioned patches only two are in Smithay. As I was actually fixing compositing for the workflow I just had to suffer through I would have had to restart pretty much the whole session anyway - though in fact the later stages of my workflow I was only directly killing cosmic-comp and cosmic-session was automatically restarting it all. No really good way to recover the surfaces though, so apps still need to restart.

This is not unlike the _another_ bug stream I tracked down this evening, where cosmic-applets would fail to display tray icons on both displays correctly - that turned out to be a bug where one icon provider was unresponsive to part of the protocol, coupled with a synchronous dispatch from the event handle into that blocking return call. Perhaps more interestingly though that manifest during diagnosis something I've seen a lot in other DE chains where tray icons for auto-started electron apps were highly sketchy - well a common electron wrapper gives up entirely on the first whiff of an error with the dbus interface and doesn't retry.

Years ago I gave up on Linux DE's because reconfiguring xft, gnome, etc was too much of a time sink. How far I've come, now I'm back :'(

raggi··on Xwayland 26.1.0 rc1
Nice. XWayland has been a key transitional piece we'll still need for a while.
raggi··on Google is making private AI practical with homomorphic encryption
https://www.jeremykun.com/2024/05/04/fhe-overview/#the-highe...

> Fourth, there is a bandwidth concern. FHE encryption schemes generally increase the size of the data being encrypted, and the user must send the server a special set of encryption keys to enable the computation, which are relatively large as well. The special keys need only be generated and sent once and can be used for all future computations, but they can easily be gigabytes in size. In one example FHE scheme with lightweight keys, a ciphertext encrypting a single integer is on the order of 25 KB, and the special keys are about 0.5 GB. In others, 16,000 or more integers are packed into a single ciphertext of similar size, but the keys can be 10s of GiBs.

raggi··on Tracking down the 16-year-old WAL-reset SQLite bug
SQLite has an online backup API as well, but it is slower and requires a significant additional page cache cost.

The team chose SQLite early on (there are some blog posts about this) and then we vertically scaled against the SQLite architecture. There are subtle ways you come to depend on the proximity/latency when you scale with local storage that mean switching requires a lot of non-obvious work - it’s probably the largest hazard for embracing SQLite in a growing saas - but at the same time you can push the vertical scale pretty far, which has great margins.

Had we scaled a different architecture of database there’s little reason to believe it would have been plain sailing as seems to be implied here.

raggi··on Tracking down the 16-year-old WAL-reset SQLite bug
We have very good reasons for our checkpointing model, related to our backup + disaster recover strategy, along with resource cost. It might be worth writing about one day, so I'll not give away all the details, but in very short form, we organize a backup strategy that has minimal pause time, avoids doubling the page cache cost of the database, and enables extremely fast byte-copy restores in disaster recovery.
raggi··on "Code was never the hard part" is an insult to all programmers
One of the strongest teams I worked with, working on an extremely large and ambitious project used to answer a lot of product/executive type questions regarding missing areas that we knew how to author and could safely assume general design consensus “it’s just typing”.

It was a very useful contraction in the right senior circles where there was a pretty good understanding of the meaning and decently reliable assumed consensus.

I eventually stoped using the phrase because it had started leaking deeper into the team and the impact on earlier career or less confident programmers was often no longer positive, it could be misinterpreted in lots of different ways but the most harmful was when it would further decimate confidence and discourage requests for help when something wasn’t obvious to the ultimate author.

As with almost every attempt to generalize in software engineering the repetition or extrapolation beyond the context in which it was intended can have negative side effects, it doesn’t matter if it’s a simple notion like “dry”, or a comment like “code was never the hard part”. None of these phrases survive context loss and still retain efficacy at general receivers.

raggi··on Show HN: ssh ssh.place
So really the trend I'm talking about here is people turning SSH into a browser, hosting apps behind SSH that expect a much higher volume of TOFU happening, which is a departure from the "first time i setup my vps" kind of case.

Honestly at this point I'd be kind of happy if we could just use an x.509 cert from a webpki acme provider in the sshd and be done with it, for the host identity part.

raggi··on Show HN: ssh ssh.place
i've seen it, so the answer is non-zero
raggi··on TIME Is Serving AI Bots a Different Website, with Ads Built In
Next step the ads become increasingly sophisticated prompt injection to ensure they make it to the user, but the prices plummet in the meantime because the ads have low efficacy. They get purchased mostly by the scammers and by the time they start showing up in user chats they’ll be full on LLM assisted interactive user manipulation campaigns with far worse outcomes than the worst of YouTube and social media ads.
raggi··on Show HN: ssh ssh.place
When you see people advertising a coffee shop at a conference and people TOFU'ing on conference wifi then plugging in credit card numbers, the picture gets a little more clear.
raggi··on Show HN: ssh ssh.place
Fair!

When I last harassed Crawshaw about this and we discussed bits, he submitted https://github.com/C2SP/C2SP/blob/main/well-known-ssh-hosts....

Unfortunately neither of us has taken time (AFAIK) to go back and implement it anywhere.

raggi··on Show HN: ssh ssh.place
sshfp is not PKI. It's an option and it is off by default in ssh(1). In practice no one actually deploys it, exe.dev, terminal.shop, jobs.{whoever.com}, etc. I've yet to see an in the wild deployment. The aforementioned sites let you perform electronic payment transactions over ssh without it, which is probably a PCI violation tbh, but auditors aren't good enough.

webpki is on by default.

raggi··on Show HN: ssh ssh.place
here, less than most, but look for ssh agents

on terminal.shop, steal credit cards on jobs endpoints, perform identity theft on exe.dev, whatever you put on there

raggi··on Show HN: ssh ssh.place
Time for your regular reminder that ssh has no PKI and is trivial to mitm during tofu.
raggi··on Tailscale didn't stop the Hugging Face intrusion
fwiw, we have been working on increasing modularity options in the client and a substantial volume of features can now be built out of the clients, see https://github.com/tailscale/tailscale/tree/main/feature for details.

If you are motivated to build a much less featureful client, it is easier now than it has ever been, and this work is ongoing.

raggi··on GCC steering committee announces AI policy
The mental model of slow decay into copyable is complicated. The code base is already a wash with contributions that have low copyrightability in US case law anyway, things derived directly from external architecture or documentation in barely novel ways, common system interfaces, and so on. LLM output is another output of this kind of class and sure sometimes large contributions happen that seem more significant, but they likely have little bearing on the work as a whole given it's earlier design provenance (at least for established and massive projects like this).

What is likely to get more muddy over time is the accuracy of any copyright registration, and the enforcement of copyright infringements on portions of the whole. These are already complicated cases and definitely so for compilers with so much "scènes à faire".

It's not clear how much this has a negative impact on cases around the whole, which tend to be the more important cases for the four freedoms that, while they have other intentions, have a primary intention of ensuring that the whole continues to be available for redistribution and extension in perpetuity.

I do not think that there is a clear link between these two areas at all, and the GPL's most important intents may be far safer long term than concerns of dilution suggest.

raggi··on Document-borne AI worms can self-propagate through Copilot for Word
Parse for what? The model has “arbitrary understanding” of “arbitrary input”. The filter is unbounded and the only actually safe result is to filter everything.
raggi··on Document-borne AI worms can self-propagate through Copilot for Word
with LLM architectures I think that’s true, and we don’t have anything looking particularly competitive for large scale use atm

I also don’t think this is about mixing, the LLM part of the problem doesn’t have determinism around the boundaries so they’re feel good at best, maybe making some cases a bit harder

trifecta is a forever problem with this architecture

raggi··on Modern email can be built from borrowed parts
Honestly we should just do this. Maddy and Stalwart have cheap enough concurrency and good enough scalability they could easily delay SMTP accepts server side for a time delay based on a combination of a local and global heuristic. We could easily start to produce an auditable global heuristic as well and start prototyping the solution today. Over time the community will have to decide how to work with the Cabal, or more specifically the Cabal will have to learn to start to re-engage with the community.

Just start.

raggi··on Fil-C: Garbage In, Memory Safety Out [video]
This presentation wasn’t too bad in terms of us vs theming, but in general throughout the lifetime of the project there’s been a strong us vs them rhetoric. I think it’s working as a marketing tactic to some extent but there are better, albeit harder ways to market the thing.
raggi··on I wrote an bash enumerator because I was sick of xargs
In my experience once you get to the point where you run out of space in the glob you’re often suffering with poor performance from spawning children as well and it’s time to move to a more formal program even if it’s a script, writing out work plans and completions to list files to avoid wasted time. It’s often a great guardrail to remind you to do this
raggi··on I wrote an bash enumerator because I was sick of xargs
in zsh you can just write:

   for x (*.sh); echo "before $x after"
or

   for x in *.sh; echo "before $x after"
or

   for x (*.sh) { echo -n "before "; echo -n $x; echo " after" }
raggi··on LG monitors silently install software through Windows Update without consent
there's tons of frustratingly equally bad precedent.

for some reason it also seems like a lot of this companion software from oems is often written by part time contract / interns.

years ago there was a classic example of iirc a logitech mouse driver that was writing the coordinate position of the mouse at ~100hz to the registry.

microsoft should be applying _at least_ app store level / whql level rigor to these, but it seems if the oem is large enough they'll just gladly yolo a 2gb package of crap onto your machine because the oem said "this our driver package"

raggi··on TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
Most variants don't, Alpine in fact does not, nor does the uclibc shell script, nor the commonly copied in implementation in many busybox environments.

Reference: https://gitlab.alpinelinux.org/alpine/aports/-/blob/master/m...

raggi··on TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
Yes
raggi··on TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
The fact that there is no portable way to link the relevant functions that works reliably across all distributions of Linux is a failure of POSIX and GNU, and unfortunately is largely the Linux distribution story in a nutshell.

Your answer is mostly correct, except that when you tug on that thread the shelf comes off the wall, the plaster comes with it, and then it cracks the water pipes on the way to the floor.

Page 1 of 25Next →