HNHacker News
TopNewBestAskShowJobs

seodisparate

106 karma · joined May 1, 2017

https://nexus.seodisparate.com

https://github.com/Stephen-Seo

submissionscomments
seodisparate··on C: Simple Defer, Ready to Use
One can use C's `cleanup` attribute like a defer. https://gcc.gnu.org/onlinedocs/gcc/Common-Variable-Attribute...

The function signature is `void(MyType*)` if it is used like:

    __attribute__((cleanup(MyTypeCleanupFunction)))
    MyType myType;
If it's a pointer, it'll call the cleanup as a double ptr, and etc. Note that the specified cleanup function can do anything you want to, though the intended purpose is to cleanup the variable when it goes out of scope.
seodisparate··on Git: The Stupid Password Store
Or using .ssh/config since entries in there act like hostnames:

    # ~/.ssh/config
    Host github_ssh
        HostName github.com
        User git
        IdentityFile ~/.ssh/my_github_key

    > git remote add github github_ssh:Username/RepoName.git
This has worked reliably for me for quite a while now.
seodisparate··on How to read C type declarations (2003)
Reminds me of https://goshdarnfunctionpointers.com/ which has helped in some cases.
seodisparate··on What Are File Descriptors in Linux
Isn't there `proc` on Linux systems?

Get the pid of the process you want to inspect, and while its running, execute `ls -lh /proc/<pid>/fd/`. It will list the open file descriptors for that process.

seodisparate··on Committing Without Git
One could use `printf 'first\0second'` in the Bash shell as an example of making a "string" with null embedded into it, but you can't store that in a Bash variable.

    $ TEST_VAR="$(printf 'first\0second')"
    bash: warning: command substitution: ignored null byte in input
I'm not familiar with working with null characters in Bash in this way, but I think there might be a way to do it.
seodisparate··on Building a Web Game in C
Similarly, I have a somewhat simple demo made for my website that is C++/Emscripten/Raylib. It's open source (MIT License) and you can grok the code here https://git.seodisparate.com/stephenseo/jumpartifact.com_dem... and check out the demo itself from the link within that page.
seodisparate··on ROFL: An open-source license that promotes fun in coding
https://choosealicense.com/ is a good resource that lists a bunch of licenses explained.
seodisparate··on Ditherpunk – The article I wish I had about monochrome image dithering (2021)
I made a C++ project[1] (using OpenCL and blue noise) to generate dithered images/video for a course project (the course taught how to program for the GPU). If anyone wants to just jump straight into generating dithered images, you can try it out yourself. (It only works if OpenCL is configured for your system. It works on my desktop with a GPU and does not work on my laptop without a separate GPU.)

EDIT: Oh right, it also requires FFmpeg to be installed as it uses it. And libpng. And CMake. And PkgConfig.

[1]: https://github.com/Stephen-Seo/EN605.617.81.FA21_StephenSeo_...

seodisparate··on How to Store an SSH Key on a Yubikey
You can use a GPG key stored on a YubiKey with openssh, but with some caveats:

1. gpg-agent must act as your ssh-agent (which means ssh-agent should be disabled and replaced by gpg-agent).

2. If using `pinentry-curses` (YubiKey usually permits access to the contained GPG key via the use of a pin), you must have `export GPG_TTY=$(tty)` (or your shell's equivalent of setting the GPG_TTY environment value to the output of `tty`).

3. You can fetch the public key of your GPG key with `ssh-add -L` (gpg-agent must be acting as your ssh-agent, and the YubiKey with the GPG key has to be plugged in).

4. You must have the line `enable-ssh-support` in your `$GNUPGHOME/gpg-agent.conf`.

I used a guide[1] to set up a GPG key on to a YubiKey, and for those who don't want to use GPG, the guide also has a section[2] about just using an SSH key as well.

[1]: https://github.com/drduh/YubiKey-Guide

[2]: https://github.com/drduh/YubiKey-Guide#ssh

seodisparate··on SELinux is unmanageable; just turn it off if it gets in your way
[1] discusses firejail running as root:

> For a server, the process exposed to the outside world runs as an unprivileged user (unbound or nobody). The process is started by a separate process running as root (as explained by @Ferroin above). The starting process is never exposed to outside.

> The same is true for Firejail. By the time the unprivileged server process starts, Firejail is already sleeping.

And I think Docker has a similar problem as mentioned in the "warning" section in [2]:

> Warning: Anyone added to the docker group is root equivalent because they can use the docker run --privileged command to start containers with root privileges. For more information see [3] and [4].

[1]: https://github.com/netblue30/firejail/issues/1720

[2]: https://wiki.archlinux.org/title/Docker#Installation

seodisparate··on SELinux is unmanageable; just turn it off if it gets in your way
As a lightweight alternative to Docker-based (or any container-based) solutions: Try firejail. You can set up a directory that will be the "home" of the sandboxed application you're running, then you can do something like `firejail --private="${HOME}/my_firefox_jail" firefox`. There are built-in profiles for many applications already, and you can customize them (by adding `.local` files, not editing the existing `.profile` files). See the following link for details.

https://wiki.archlinux.org/title/Firejail

seodisparate··on FBI sounds alarm as QR code usage soars
Someone else on HN earlier posted their QR-code scanning Android app[1], which I've been using because it doesn't automatically follow URLs but displays the raw text of the QR code. It's been helpful for me, especially when I've been setting up QR codes for a new wireless router.

[1]: https://github.com/prof18/Secure-QR-Reader

seodisparate··on Poll: Would HN folks use a discord server to talk about HN?
Is it too old-fashioned of me to prefer IRC? Discord has its place, but I favor IRC.
seodisparate··on Popularity of Programming Languages on Arch Linux
I use the `rustup` package instead of the `rust` package to manage a local installation of rust. This graph seems to show installations of the `rust` package, but I don't think that accounts for `rustup`. `rustup` is recommended on Rust's own website ( https://www.rust-lang.org/learn/get-started ) and some users may have installed `rustup` via the bootstrap script instead of from Arch's own package repository. So I guess there's some additional variables that may not be accounted for regarding `rust`.

EDIT: Try this: https://pkgstats.archlinux.de/compare/packages#packages=dmd,...

seodisparate··on Akamai to Acquire Linode
Been using Linode since 2019. Service worked as expected (worked well), and I hope that won't change after this. If I had to move, I'd have to go through the pain of setting up my website(s) again, but at least I have backups, so it's just a matter of time spent getting set up again..
seodisparate··on JavaScript for Impatient Programmers
As someone with a C/C++ background, this gist was a good reference for those times I needed to use Javascript: https://gist.github.com/yig/8744917
seodisparate··on DNS Privacy Considerations
Oh I see, thanks for the reply. I did a quick search and came upon https://blog.cloudflare.com/encrypted-client-hello/ which does shed light on ECH. Though I am not sure if only Cloudflare-backed servers provide ECH, or if it is even available. Seems relatively new.

EDIT: Ah, the blog post does indicate that ECH is a work in progress.

seodisparate··on DNS Privacy Considerations
Out of curiosity, I once used wireshark to examine packets from my own system which was configured to use DNS over HTTPS (using dnscrypt-proxy). I discovered that the hostname of the server is in plaintext in a header of a packet separate of the DNS query packets. I think this is due to verification of HTTPS certs, but not sure. By what I've discovered, AFAIK that to completely obscure the server's hostname from the currently used ISP, a VPN (or proxy) is probably necessary.
seodisparate··on Linus Torvalds on Rust support in kernel
Redox-OS has a similar situation that kernel code should never panic https://gitlab.redox-os.org/redox-os/redox/blob/master/CONTR... .

    No possible panics should ever exist in kernel space, because then the whole OS would just stop working.
Note that Redox-OS is written completely in Rust.
seodisparate··on Professor suspended for saying 那个 nà ge
In Korean, the vowels ㅣ (ee sound) and ㅐ (eh sound) are different in the written language. There are actually more difficult things such as ㅐ and ㅔ (both "eh" sound) which can get confusing when trying to spell Korean words. In practice, I personally don't get confused differentiating between "nee-gah" and "ne-gah", but that may have been due to me having Korean parents and being used to that terminology since birth.
seodisparate··on Professor suspended for saying 那个 nà ge
So in Korean, the word for "you" is 니가 (pronounced "nee-gah"). Example usage: 니가 언제 먹었어요? (When did you eat? "Nee-gah un-jeh mug-uss-uh-yo") I can't help but wonder if the use of this word would also elicit a similar reaction...

EDIT: I briefly forgot this, but there is a similar Korean word "내가" which is "me" or "I", and pronounced "ne-gah". Example usage: 내가 이 밥을 먹었어요. (I ate this food. "Ne-ga ee bap-uhl mug-uss-uh-yo")

EDIT2: Korean is not my native language so forgive me for this, but "you" is usually just 니 ("nee"), and "me" or "I" is just 내 ("ne"), but the 가 ("gah") part is used like a conjunction to connect to the rest of the phrase.

EDIT3: Ok, so I talked with a better Korean speaker about this and 니가 "nee-ga" is sort of a regional dialect (kind of like a slang term) for 너가 "nuh-ga". 니가 "nee-ga" is more commonly used in southern parts of South Korea, as the proper way of saying/spelling "you" is 너가 "nuh-ga". My Korean is influenced with the southern regional dialect as my parents were from that region. Sorry for the possible confusion. (So just "you" is 너 "nuh".)

EDIT4: PSY (of Gangnam Style fame) has a song titled "Champion" that uses 니가 "nee-ga" a lot:https://youtu.be/uA4fV7Y14eg?t=49

seodisparate··on Make your 404s into 302s
It looks like they want websites to do the following: whenever your website goes under a drastic change, serve the previous version of the website under a subdomain, and redirect all 404s on the newer version to the subdomain. More drastic changes in the future may potentially redirect 404s to previous subdomains/versions like a chain. At least that's my understanding of it.
seodisparate··on Announcing flicker-free boot for Fedora 29
Actually I have my desktop configured with an encrypted root. Turns out GRUB can actually decrypt the partition holding /boot before loading the grub.cfg. Though I have this set up on ArchLinux and had to refer to the Arch wiki a lot to get this set up properly. Definitely not that user friendly, but I can say it is a possible setup after having used it for years on my desktop now.

EDIT: To clarify, my setup requires inputting passwords twice: once for decrypting the root partition, and once to login after everything has booted. During the boot process the system needs to remount everything, so I had the encrypted partition(s) also be decrypted with a key file (typically `dd if=/dev/urandom of=keyfile bs=1M count=4`; LUKS encryption can have multiple keyfiles/passwords to decrypt) and had the key file(s) put in the initramfs so after GRUB has decrypted root and loaded /boot/grub.cfg, the booted system could decrypt and mount everything needed with the key file(s).

seodisparate··on More Good Programming Quotes (2016)
"When stuck debugging, question all of your assumptions about the program."

A shower thought. Helpful if the program does something other than what you thought it did, allowing you to figure that out quicker.

seodisparate··on Findings about schizophrenia rekindle old questions about genes, identity (2016)
Last I checked, uMatrix by default enables everything for 1st party sites. So if you are at twitter.com, all stuff originating from twitter.com will be allowed.

You should be able to remove this rule in uMatrix's settings in the "my rules" tab. Just click on the rules you want to remove on the table on the right and click on commit to save your changes.