HNHacker News
TopNewBestAskShowJobs

vrtx0

174 karma · joined December 24, 2015

Vertex Zero: The center of everywhere. The middle of nowhere.
submissionscomments
vrtx0··on Ask HN: Anyone else find LLM related posts causing them to lose interest in HN
Absolutely. Truly innovative research and projects are always fascinating to me. But even generalized to AI/ML, I can’t think of anything more recent than GANs (2015), Transformers (2017), and maybe AlphaFold 2 (2021)…

Just my personal taste though; I don’t mean to knock LLMs.

vrtx0··on C stdlib isn't threadsafe and even safe Rust didn't save us
So, I’m real, and just trying to offer constructive feedback for a few errors I believe I noticed.

I could be wrong though —- could you be specific? I don’t want to misinform anyone…

vrtx0··on C stdlib isn't threadsafe and even safe Rust didn't save us
I provided a copy/paste from the site about the envp array size you asked about.

I clarified why I mentioned fork().

I tried to explain the difference between registers and variables.

I’m not trying to show off or bring anyone down… I just like to help people. I’m old (my first Linux kernel commit was in 2004). And I could be wrong — please LMK if I made a factual error (I’d appreciate it, honestly).

All good?

vrtx0··on C stdlib isn't threadsafe and even safe Rust didn't save us
x20 is a general purpose register; optimizing compilers can use it for any number of variables, immediate values or intermediate computations at different points within that same function — or none at all (the variable ep could be optimized away).

Re: fork(), I just meant to be thorough in explaining the environment is copied, not shared by processes. Setenv() only affects the process from which it’s called.

The array size bit in the article: The value 0x220 looks suspiciously close to the size of the old environment in 64-bit words (0x220 / 8 = 68), and this value was written over the terminating NULL of the environment block…

HTH!

vrtx0··on C stdlib isn't threadsafe and even safe Rust didn't save us
Let me try to help:

1. If a process crashes and dumps, be sure to look at the system log of the cause (e.g. SIGSEGV, OOM, invalid instruction, etc.)

2. Be certain you’re looking at the right core dumps — I believe UID 1000 just means posix UserID (which is unrelated to a PID), though I don’t use containers.

3. Stay focused on the right level of abstraction — memory model details are great to know, but irrelevant here.

4. Variables do not correlate 1:1 with registers, except in C calling conventions. The assumption about x20 and a local variable is incorrect, unfortunately.

5. getenv() and setenv() do not work as implied in the post. When a process starts via execve(), the OS/libc constructs a new snapshot of the environment, and cannot be modified by an ancestral process. It’s a snapshot in time, unless updated by the process itself. When a process fork()s, the child gets a new copy of the parent’s environment — updates do not propagate.

getenv() is thread safe and reentrant. You don’t use an environment to pass shared data — setenv() is generally used when constructing the environment for a child process before a fork(). See man environment.

6. FWIW, ‘char** env’ is a null-terminated array of pointers, so dumping memory from *env (or env[0]) is only valid until you hit the first NULL. The size of the array is not stored in the array.

I hope this helps! And apologies if this is redundant — I read so many comments; mostly variations of “the problem with getenv is x”, but gave up before reading all of the (currently) 168 comments.

vrtx0··on Homomorphic encryption in iOS 18
I don’t see any merit, honestly. That would assume one is able to audit every bit of code they run, including updates, and control the build system.

I mean, the Wally paper contains enough information to effectively implement homomorphic encryption for similar purposes. The field was almost entirely academic ~12 years ago…

I miss talking shop on HN. Comments like that are why we can’t have nice things.

vrtx0··on Homomorphic encryption in iOS 18
Sorry, what do you mean by “proprietary details”?
vrtx0··on Homomorphic encryption in iOS 18
Do you mean the ability to search in Apple Photos is “privacy-bruising”, or are you referring to landmark identification?

If the latter, please note that this feature doesn’t actually send a query to a server for a specific landmark — your device does the actual identification work. It’s a rather clever feature in that sense…

vrtx0··on Homomorphic encryption in iOS 18
Thank you! This is exactly the information the OP seems to have missed. It seems to confirm my suspicion that the author’s concerns about server-side privacy are unfounded — I think:

> The client decrypts the reply to its PNNS query, which may contain multiple candidate landmarks. A specialized, lightweight on-device reranking model then predicts the best candidate…

[please correct me if I missed anything — this used to be my field, but I’ve been disabled for 10 years now, so grain of salt]

vrtx0··on Homomorphic Encryption in iOS 18
Is the Apple Photos feature mentioned actually implemented using Wally, or is that just speculation?

From a cursory glance, the computation of centroids done on the client device seems to obviate the need for sending embedded vectors of potentially sensitive photo details — is that incorrect?

I’d be curious to read a report of how on-device-only search (using latest hardware and software) is impacted by disabling the feature and/or network access…

vrtx0··on The race to replace Redis
Whoa, very biased article (especially for LWN). Only cites media coverage; no links supporting that Amazon, MSFT, Google, etc. were in fact EEE’ing (or at best, behaving unethically) with each of these projects.

It even suggests cloud providers did contribute, and uses bad data (git commits “by employer” w/o dataset) that basically contradicts their argument.

I may be biased, as I saw Amazon doing exactly what this article claims “maybe they weren’t”. But statements like this seem intentionally misleading, and easily disproven:

“Distributing a source-available version of MongoDB could be seen as a loss-leader strategy to reach developers that the company wagered did not care about open-source.”

MongoDB is still “source-available”, and on the same GitHub repo I’ve used since 2010. The SSPL only impacts cloud-providers, and has exceptions for cloud providers who release their source code.

The OSI doesn’t get to define open-source. Neither do I, but at least I was part of the community for ~20 years…

vrtx0··on FerretDB: open-source MongoDB alternative
I think “including, without limitation, […]” applies to the breadth of components, not depth, right? I mean, I’m not a lawyer, but that seems to be what syntactic context and logic indicate… no?

If you disagree, could you indicate the relevant text?

vrtx0··on FerretDB: open-source MongoDB alternative
Er, I could be wrong, but I think you’re missing the scope set in the first sentence:

If you make the functionality of the Program or a modified version available to third parties as a service, you must make the… SNIP …programs that you use to make the Program or modified version available as a service…

I’m eliding for clarity, but the NAS doesn’t make the program available as a service. The code that accesses the file system on the NAS to offer your service? Probably need to release code that calls fread/fwrite/NtFileX in your infrastructure code.

I get that it sounds vague and everything, but the FAQ also clarifies none of this applies unless you’re competing and targeting third parties. If you’re one of the few companies who want to do that, your legal team can formalize the line of demarcation.

Apologies, I hate defending the SSPL, but I can’t think of any better way to stop the monopolistic and EEE practices against open source projects. If anyone has a better solution to protect the freedoms of open-source developers, please, please publish it!

vrtx0··on FerretDB: open-source MongoDB alternative
The cloud provider wouldn’t have to, if you are the one running your infra. The SSPL restrictions only apply to businesses that offer MongoDB as a service.

In fact, you can build a similar service and offer it within your organization (and subsidiaries), and you still don’t have to release anything. The license only applies to companies like Amazon if they offer MongoDB as their own service (DocumentDB).

I know that’s a bit tangential, but hope that helps a bit?

vrtx0··on FerretDB: open-source MongoDB alternative
No, full list is in the license, but it’s only those components that they provide MongoDB as a service to end users. Doesn’t penetrate OS abstractions AFAICT, but I’d check the license and/or consult an expert if starting a relevant business!

FWIW, just realized it doesn’t even apply if deployed internally (within an organization and/or subsidiaries)…

vrtx0··on FerretDB: open-source MongoDB alternative
I could name more, but let me clarify something. I’m not a fan of the SSPL, but I get why it was necessary.

It was rough seeing huge cloud providers profit off open source projects without giving anything back. When they offered competing hosting services with no value added (well, past “integrated billing”), no contributions or innovation, and drove their new customers to the documentation and libraries of the companies backing these projects, they crossed a huge line.

And it’s not just MongoDB. Or Elastic. Just look at all the “services” AWS offers, and note how many AWS actually invented or even contributed to…

Monopolistic practices forced a lot of companies to either shut down, or find a way to survive. I’m glad MongoDB decided to use the SSPL instead of shut down like so many others. I’m glad they’ve continued to thrive.

Changing to the SSPL isn’t ideal, but it only impacts people who want to sell hosted versions of the software (not users, self-hosted or otherwise). For those infinitesimal few selling hosted versions of the software, it doesn’t even stop them from doing what they want — it just stopped the monopolies from destroying something a lot of people dedicated a lot of effort to... That seems like a pretty amazing feat to me, given the reality...

I wish the OSI wasn’t so successful painting users of the SSPL as somehow betraying the open source community. And I wish the SSPL wasn’t necessary. But until there a better option, I’m ok with the SSPL…

Again, I say this with all due respect, and this is just my opinion. Corrections and new perspectives welcome!

vrtx0··on FerretDB: open-source MongoDB alternative
Er, if you develop the infrastructure to host MongoDB, you should absolutely be able to open-source that infrastructure. I mean, before MongoDB, I wrote a cluster management system for virtualized software security and hypervisor research, and all of it was either open source or something I wrote…

Also, if you bought something closed-source to sell MongoDB as a service, why isn’t it realistic to buy a license?

Your suggestion of a monopoly in the DBaaS space seems to preclude the existence of other databases… Or am I misunderstanding?

I’m not sure what you mean by “IT is a business decision” — could you elaborate?

-edit- P.S. I’m trying to be supportive here; not trying to take anything away from what you’ve built with FerretDB! Honestly, there’s room for so room for innovation in this domain, and it’s nice to see new projects…

vrtx0··on FerretDB: open-source MongoDB alternative
Er, why can’t you run a MongoDB replica set on your M1?

I mean, I wouldn’t recommend running a ReplicaSet on the same host on any production host (it defeats the purpose), but for testing, I’ve run a sharded cluster w/ 3 replicas per shard…

Happy to try and help!

vrtx0··on FerretDB: open-source MongoDB alternative
No, the term “open source” was in use before long before the OSI, and it was in popular/hacker culture in the 1980s. UNIVAC used it in for a major system in the 1950s. [1] I used it in 1993 (I wrote a small BBS).

The OSI looks and sounds like an authority on open source software, but their entire strategy is legal, political and quasi-philosophical. I get how easy it is to be mislead by them though — they’re good at spinning things and rewriting history.

https://en.m.wikipedia.org/wiki/History_of_free_and_open-sou...

vrtx0··on FerretDB: open-source MongoDB alternative
MongoDB’s source code is still freely available. It’s still actively developed in the open on GitHub. Unless you’re offering MongoDB as a service, it’s just as “open source” as ever.

If you want to offer MongoDB as a service, you can still do so free of charge, as long as the service infrastructure is also made openly available, right? And if you don’t want to make the source available, you can purchase a license and do so, right?

Furthermore, if you’re using MongoDB, be it self-hosted, with a vendor, or even some proprietary database that implements the wire protocol for compatibility, you’re likely using MongoDB-developed clients/drivers, which are Apache 2.0 (“OSI-approved open source”).

So it seems like the only way to be locked into a vendor is if you’re using MongoDB drivers to connect with a 3rd party database that doesn’t fully implement all functionality of MongoDB in a compatible way… Right?

I could be wrong, but as someone who contributed to MongoDB as an open source project, and was later hired by MongoDB based on said contributions, it kinda hurts to see the OSI’s “MongoDB isn’t open source anymore” campaign work so well.

That said, I sincerely wish the team behind this project all the best!

My complaints aren’t against anyone in the open source communities I’ve known and loved. Just this self-important legal organization that acts like it controls (and even gets to define) open source software.

P.S. I left MongoDB in 2015 due to a neurological disability, but it was one of the highlights of my career, with so many kind and brilliant people. But it’s also been a while, and my brain doesn’t work so well these days, so please correct me if I got anything wrong!

vrtx0··on The Free Software Foundation is dying
Ah, interesting… I think the discrepancy is where we’re looking. FWIW, I started my career at AOL-Time Warner in Florida in the late ‘90s. Management was all “good ol’ boys”. Definitely no role models anywhere. (I was closeted at the time).

I’ve been fortunate in some ways, but nothing came easy to me. I didn’t come from money, didn’t graduate college, didn’t know anyone… I moved to LA just to escape that toxic environment, and found a good job developing embedded systems in 2 weeks. I’m an autodidact, so my only qualifications were a portfolio of projects, including an old TI DSP project and a pre-Wi-Fi embedded wireless device. Over the next ~15 years, I kept moving up in rank and salary, changed jobs a few times, received patents, contributed to papers, and was lucky enough to be mentored by some truly amazing people…

I’ve always felt success is a combination of hard work and luck, even for those “born into it”. If true, that likely means for everyone like me, there are a dozen or so who didn’t make it, or never took a chance.

And yeah, being gay still isn’t fun. Maybe it made it easier to take a chance moving 2600 miles from home though — I figured I’d be dead within a year if I stayed where I was…

Hope that doesn’t sound like some kind of humble brag; I’ve obviously had my share of failures and loss.. That said, given how lucky I feel at this point (I’m in my 40s), I couldn’t understand how you’ve never met a positive role model… But I do now, and it was naive of me to extrapolate my experience into the general population… And I’m not suggesting I worked harder or did anything to deserve my good fortune… FWIW, I’m really sorry you (and likely most people) haven’t known the same men and women I’ve been lucky enough to know…

Really hope that doesn’t sound like some arrogant humblebrag, or diminish your hard work!

vrtx0··on The Free Software Foundation is dying
My perspective as an openly gay male with 20+ years of experience in software security, systems programming and distributed databases: Tech companies tend to be extremely supportive and welcoming of talent from diverse backgrounds. My proudest technical accomplishments have always been with a diverse group of peers, including straight white males who champion diversity. These people are heroes to me, but it’s not like they’re the type to gloat…

I’m not the best person to ask about movies, but most example of protagonist “hackers” that comes to mind include white males. Counter examples that come to mind are “The Web” (female), and Sens8 (transgender lead, helped by straight white male)…

That said, I may have misunderstood your point, but happy to correct it elaborate if I’m off base!

vrtx0··on The Free Software Foundation is dying
IMHO, this just seems to be another polarizing piece of clickbait, rehashing the pointless “RMS vs. ESR” diatribes.

The author frequently posts in support of the OSI (applied for a seat, endorses their “we get to define open source” nonsense, etc.). A March 2022 post rants against Elastic and others because of a non-OSI “open source” license change, while glossing over Amazon’s and the OSI’s roles leading to that change. It also makes a strange argument about bias, which almost comically contradicts itself at the end.

IMHO, the OSI, FSF, RMS and ESR have all done more harm than good to the open source community. I’m not saying they’re all equal, or even always bad, but I’m not a fan of bringing one-sided political or philosophical arguments into the hobby and career I’ve truly enjoyed for over 20 years. And no, my contributions don’t somehow mean I get to define what “open source” means for everyone.

vrtx0··on Cracks are showing in Enterprise Open Source's foundations
Projects that change from Apache or GPL-like licenses to SSPL are still open source. This doesn’t mean you have to release your source code if you use these projects — only if you start selling a hosted platform that offers the software as a service. Every company I’ve seen do this was been backed into a corner by Amazon, who almost never contributes to these projects. This is nothing more than Amazon trying to kill these projects by causing fragmentation.

*Yes, I’ve read the OSI link AWS-fans always refer to.

vrtx0··on East Coast Internet Outage
Same here. Seeing heavy packet loss to most (but not all) sites that route through verizondigitalmedia.com.customer.alter.net in NYC.
vrtx0··on AWS announces forks of Elasticsearch and Kibana
With all due respect, dictionaries can certainly define the term. They create definitions based on examples of the word's use, and Oxford English defines it as: "Denoting software for which the original source code is made freely available and may be redistributed and modified."

We can agree to disagree about the details; no use arguing on the internet, and I respect your view. But please keep in mind the OSI's mission is fitting open source into a legal framework. It's not the ASF, FSF, Mozilla Foundation or other organizations who actually support and organize open source projects. Full disclosure; I also worked on Apache Drill, thanks to the ASF.

My primary point is that Amazon is not part of the open source community (AFAIK, they've never claimed to be). So it's hard for me to trust a company overtly focused on monetizing OSS without contributing. IMHO, all of the engineers at Elastic who gave so much time and effort for this project are still part of the open source community. I hate to see Amazon effectively judging which projects/people are "truly" part of the community when their motivation is so clearly corrupt.

I hope this comes across with respect, and please know that I'd much rather not see licenses like the SSPL. But after seeing Amazon's monopolistic and anticompetitive behavior play out repeatedly with various companies, I can't just watch them do this without saying something. Even on a stale HN thread. :)

One last thing to note -- Bruce Perens left the OSI in January of 2020 (shortly after the SSPL stuff went down), and said: "We created a tower of babel of licenses. We did not design-in license compliance and we have a tremendous noncompliance problem that isn't getting better. We did not design a good framework for where proprietary software can go, and where it never should. Our license loopholes are exploited." ESR (who I detest as a human being), was banned from the OSI two months later. I don't mean to suggest this was a direct reaction the SSPL though -- please see the OSI's wikipedia page and cited sources.

vrtx0··on AWS announces forks of Elasticsearch and Kibana
If you don’t believe the SSPL is open source, then you definitely don’t believe the GPL (and related licenses) are open source.

The definition of open source Amazon points everybody to is not the same as what’s defined by the FSF and other organizations. Nobody gets to own the term “open source” — that simply means the source code is available for you to modify, build learn from, etc. The details Amazon mentions only come into play when trying to make money off of an open source project.

vrtx0··on AWS announces forks of Elasticsearch and Kibana
If time permits, please read through thread in the “SSPLv2 being withdrawal by its stewards” section. Specifically, the SaaS grab Eliot mentions.

Unfortunately I wasn’t involved in the discussions with Amazon, so I don’t want to speculate on details or mislead anybody. I can say that MongoDB absolutely had a relationship with Amazon prior the SaaS grab. I believe Amazon was the largest deployment target for MDB’s cloud service (which runs on most major cloud platforms).

That said, the reason I say Amazon is blatantly misleading people is that the authors of the blog post chose a definition of “open source” that fits their argument against Elastic. They state companies that use SSPL software may have to give up their entire source code, which simply isn’t the case. It’s not even as restrictive as the GPL (the FSF has a different definition of open source). Please note that the OSI doesn’t consider any GPL license open source.

Honestly, the only accurate definition of open source is that the source code is available to the public. That means we can modify the software, learn from it, etc. With the SSPL, you can even run a customized Elastic or MongoDB server to support any business needs unless your business is providing said software as a service and making money from it. Even then, all you have to do is release the code that runs said software as a service...

Amazon is claiming that you’d have to release your code even if you’re using the product for your game, social network, analytics app, etc. That’s just not true.

For the record, I wish everything could be under a permissive MIT or BSD-style license. But companies like Oracle, Microsoft (in the 90s) and Amazon felt entitled to destroy open projects that competed with their own. Hence the wide variety of open source licenses that now exist.

My first kernel commit was 2004, and while I don’t think anybody can own the term “open source”, I feel like I’ve been part of the open source community for ~20 years now. IMHO, Amazon is by far the least open source friendly company out there. They never contributed a single commit to MongoDB (at least while I was there), yet made money off their own SaaS, and even directed their users to MongoDB’s documentation.

Hope that clarifies my stance (and frustration) a bit...

vrtx0··on AWS announces forks of Elasticsearch and Kibana
Nobody wants the SSPL (not even MongoDB), but Amazon is forcing companies to do this while contributing nothing. These projects are still open source, and actually contribute to the libraries they depend upon. As a former developer of MongoDB who watched this happen, I’ve contributed to a variety of open source projects. MongoDB also couldn’t just lay everybody off and let Amazon grow their monopolies (much like Oracle’s behavior). But please don’t suggest I’m any less a part of the open source community than I was 20 years ago.
vrtx0··on AWS announces forks of Elasticsearch and Kibana
Wow. Amazon is blatantly misleading people here. They know the SSPL was created specifically because MongoDB had the same issues with Amazon’s service. I worked for MongoDB. Nobody wanted the SSPL, but Amazon was relentless.

MongoDB’s cloud service offering was thriving quite well (and still is, thankfully). Then Amazon announced the exact feature set as their own service, while contributing nothing to the project. They even linked entirely to MongoDB’s comprehensive documentation. “Anticompetitive” is the kindest description I can offer of Amazon’s behavior.

Just remember —- the SSPL and similar licenses are still completely open source. Amazon knows they’re forcing companies to change licenses, but shaming them as being “unacceptable to many in the open source community”.

This is political rhetoric, and I’m shocked anybody outside of Amazon would support this. The people who started these projects and surrounding businesses are generally very good people — I’ve been disabled with a neurological condition for 6 years now, but live can afford to live relatively comfortably thanks to the people at MongoDB. And I contributed code to the project before I started working for them (10gen at the time). So I’m admittedly biased, but it really seems like Amazon has become the Trump of Silicon Valley. I’m done with political rhetoric like this.

All opinions are my own.

Page 1 of 2Next →