1,771 karma · joined February 13, 2010
The gem we use is here: https://github.com/discourse/ruby-landlock highly recommend all Rubyists out there consider this. We are also in the process of moving away from Magick to Vips (which also runs in a sandbox, not in process)
HEIF is patched, but I doubt this is the last buffer overflow in HEIF, I will not be surprised if in the upcoming weeks or months someone will discover something in libpng or some other native image library. Given where stuff is at, defense in depth is critical.
Another thing worth mentioning to all self hosters, always be updating! The rate of CVEs this year across all open source software is through the roof, self hosting now is double scary, you need to have some routines setup to update monthly if not weekly.
https://github.com/samsaffron/term-llm
It is about my 10th attempt at the problem so I am aware of a lot of the edge cases, a very interesting bit of research here is:
https://gist.github.com/SamSaffron/5ff5f900645a11ef4ed6c87f2...
Fascinating read.
https://discuss.samsaffron.com/t/your-vibe-coded-slop-pr-is-...
Impressive answer for a model that can run on your own computer
https://discuss.samsaffron.com/discourse-ai/ai-bot/shared-ai...
It simply did not want to use XML tools for some reason something that even qwen coder does not struggle with: https://discuss.samsaffron.com/discourse-ai/ai-bot/shared-ai...
I have not seen any model including sonnet that is able to 1 shot a working 9x9 go board
For ref gpt-4o which is still quite bad https://discuss.samsaffron.com/discourse-ai/ai-bot/shared-ai...
https://meta.discourse.org/t/discourse-chat-plugin/230881
You can try it out meta.discourse.org if log in to meta and then join the https://meta.discourse.org/g/chat-testers group (self serve)
Regarding bundle sizes, we hear you and have some long term plans to investigate code splitting, it is a very long journey but we will get there. At the moment you get the majority of the app on first payload, making subsequent clicks very fast.
And maybe do an addendum 5 minute announcement episode on the “on the metal” podcast?
Love your excellent work, thank you all
Discourse is a profitable, open source company, we host for thousands of public forums and internal team sites.
Our infrastructure team is responsible for taking care of all our hosting concerns including monitoring/deployments/alerting and so on. Much of our work involves amending and improving automation.
We are hosted on bare metal Linux servers and AWS.
To apply and for a full job desc see: https://www.discourse.org/jobs
The difference between the RAM your program uses to PSS to actual memory your process can reach vs the memory your program has allocated can all make your head spin. Agree it makes sense to add a section to illustrate this.
Just had a quick play ... on arch linux `yay nushell-git` already works!!!
One area where I got a bit stuck was around help. `man where` gave me nothing, `help where` also. I tries stuff like `ls | where type = File` and got a type error. I think it would be amazing if this thing onboarded people a bit nicer, "where needs a condition, to learn about where type "help where" ... stuff like that
Overall really enjoying the ideas here and I am absolutely going to be following this!
1. is the VM 2. is handling filesystem mounts across operating systems
(2) can be debilitating in dev environments on Mac for example where you want to edit files outside the container but have the container have access to them. Docker have done a lot to improve this over the years but it is still very painful.
This is not the case on Windows and MacOS where there is a significant cost.
That 8 minute spec run, also takes 8 minutes in docker.
https://meta.discourse.org/t/beginners-guide-to-install-disc...
We use a tool called `rake autospec` at Discourse which is a smart test runner. I personally like the vim integration we built.
The way it works...
1. Run `bin/rake autospec` in a terminal 2. I head to the code I want to change, I change the code 3. The spec runner figures out what the right test is run and runs that. 4. While it is busy running specs at any time it can be interrupted by saving a "*.spec" file in which case the spec runner will run the spec at the cursor
This has worked wonderfully well for us.
When I started running the spec suite in WSL, defender went way up (so I gave it a break), pretty sure stuff would have been way worse with defender on.
The prevailing recommendation though from the WSL team is to leave defender on for now. So I kind of cheated by disabling it.