HN user

theK

977 karma

Home at https://kind.software

meet.hn/city/50.3533278,7.5943951/Koblenz

Socials: - github.com/kiriakos

Interests: Programming, Type Systems, AI/ML, Blockchain, Data Science, DevOps, Entrepreneurship, Freelancing, Startups, Technology, Web Development

---

Posts5
Comments487
View on HN

CVE-2026-64012: net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked.

You are right, its over.

On a more serious note. Yes and no. The kernel is secure. It is probably the most scrutinized piece of software in existence. LLMs will find things but most probably they just will help contributors fix bugs.

Kimi Work 2 days ago

I think it can safely be argued that (only) good UX but also great marketing are the reason of that.

Json as a common language for human in visualization has been around for a while

Plant, Mermaid, Graphviz are all declarative textual representations designed for human authoring, JSON is made for tools. Its not a criticism just a statement that if interop across agent and human was intended this is not the simplest option.

Yeah, there are definitely valid contexts for hosting chat like this. E2EE has the benefit of not needing to trust the host, which I personally like but I can see this being fine or even wanted for lots of cases.

Podman v6.0.0 20 days ago

for years

Don't know about that. I did a ddg search "using docker compose (v2) plugin with podman" I do get some tutorials but they all are from 2026. This also aligns with my experience from late 2024 where you where typical advised to use `podman compose` or the compose script.

Podman v6.0.0 20 days ago

The CLI plugin or the script? Last time I checked the podman CLI did not support docker CLI plugins and the script is EOL since years.

Podman v6.0.0 20 days ago

I spent about a week last year trying to move from docker+compose plugin to a podman hosted variant. It has issues on multiple stages of the lifecycle as I mentioned in my original comment. Mac users lose fs events, a lot of compose.yml features are flaky (post start events), buggy (reset and import), or just not implemented (don't remember the exact features).

If you use podman and have no issues that is awesome but your use case is probably quite narrow, you are most probably on a non fedora based Linux and keep compose usage to a minimum.

Podman v6.0.0 20 days ago

Last time I checked podman compose was only a superficial docker compose equivalent. Also stuff like inotify seems to randomly break a lot on the podman side.

I'd love to be able to recommend people use podman but not having a good docker compose compatibility and missing inotify on volumes makes the DX just too problematic.

I don't know how this works nowadays but when I got taught to write (the pencil and paper kind) and specifically when I got taught syntax, it was "if you want to introduce a clause that explains or expands upon something that precedes it, you draw a small horizontal line" no mention of special chars, Unicode or whatsoever. So why is it so special other than being authors fancy?

What is the typical motivation to start using em-dashes?

Why go the extra way to have a slightly elongated dash when a normal one would just as well do the job?

I might be conpletely off here but I've never seen a situation where using a normal dash where a long one should be causes any sort of syntactic trouble.

That's definitely a thing in the corporate world. It doesn't even have to be the project lead, sometimes it comes via stakeholders, some times its even well meaning devs. It is a difficult balance to strike if you want to "only be reasonably safe" whereas cargo culting all security features might take a bit of time but you now can say "hey we did everything"

[]: everything may very well not be a thing but people like to pretend it is

Didn't he just say that fork turns out to be comparatively faster to the non-fork samples we get? Ie Linux spawns processes faster than Microsoft's kernels?

I've stumbled upon that too! Funnily I see it having two forms:

1. Some bad idea gets embedded into the context that you just can't argue away

2. Some important idea gets lost in compression and the ai wheres off into funland without recourse.

In both cases if is often better to start over or just do it yourself. I sometimes find myself asking for a summary, editing it and then using the edited one to seed a new session.

Edit: s/Finland/funland/

Mostly with you, though in recent years I have wondered whether those people are part of what caused the latest boom of political populism. If there is no one there to debate the problematic ideas, problematic ideas will become the rhetoric after all.

I don't know whether Github is in trouble as an organization or whether there is a crowd just waiting for it to go down in flames and I don't care about that.

What I can attest to is that Github has been uncharacteristically flaky this past year. At least for large clients in the EU. Its not that there is outright downtime but if you have an Actions or PR invested team you probably have felt the uptick in troubleshooting these two features in the past 12 months.

And again, its not that these features go completely down, mostly its just "why is this status not being reported" or, "where is the run for this event?" And similar things. Its not that the roof fell off, its just that it is leaky and it rains and this distracts you from actually doing important things.

I'm totally onboard with k3s/k8s being better in a lot of cases.

But docker compose can actually be very sufficient for what many projects actually need.

Granted I am a guy pushing for compose based localdevs and such but going further you often just cannot beat the simplicity of doing update QA or other CI/CD workloads in compose based projects. I have had dozens of projects where we replaced flaky slow and maintenance heavy pipelines with just docker compose up --build --wait in the past years. How come you say health checks are still broken?

That link you shared in your other comment actually counters your "runs google blobs" argument.

Speech to text is afaik completely anonymized and if you care that much, it actually is possible to just not use it, rip it out or even replace it with something that runs locally in your home.

hopelessly behind on Linux kernel versions

Can you substantiate that? Given that many OEMs still run linux 4 and 5 in their Flagship ROMs today, I'd like to see how open source does so much worse.

I can see the alure of having a very secure mobile device and can understand why you personally wouldn't see a reason to use anything else.

But Graphene requires too much fidling to get spouse approval.

/e/ might not be as secure as GrapheneOS but it is at least as secure as everything else. Plus it actively helps you preserve your privacy and use self hosted services.