What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

1
1
1
0
0

If I had more time I'd write up something about this (maybe will still), but this PR is a good example of why explicit error sets in Zig and explicit checked math is important: github.com/ghostty-org/ghostty

The gist of it is we had implicit error sets in our terminal resize code path along with poor errdefer that allowed for errors we should've handled to cause memory corruption and integer overflows.

These overflows would lead to Ghostty allocating 4GB pages (lots of them) very quickly. You'd see Ghostty go from normal memory to literally hundreds of GB in a second (if your system can handle it via swap). This was a SUPER RARE issue but one we did see happen to users a couple times. It was very hard to trigger with normal workloads.

These were two separate issues that played together to cause this. This bug has existed since our public release and into the private beta.

The fix was to fix up some integral types, do checked math on this path even in unsafe builds, and to use explicit error sets such that our resize path can now only fail on true system OOM.

We also fixed up our errdefer handling to not produce the correct result, but at least produce a coherent result so its not corrupting anything.

This is an important fix.

0
1
1
0
0
0
0

scpコマンドは内部でSFTP3使うようになってなかったっけ?脆弱性云々で使うなというのはなんか違いそうな気がする、勘違いならあれだが

0

"바이브코딩 벌써 옛말…보안위험에 초고수 개발자 선호 흐름"
(샌프란시스코=연합뉴스) 권영전 특파원 = 인공지능(AI)의 등장으로 주목받았던 '바이브 코딩' 열풍이 '초고수 개발자' 선호로 이어지고 있다는...
yna.co.kr/view/AKR202601170182

1
0
2
0
0
0
1

오늘은 내가 잠깐 병원 가야한다고 어제 매니저에게 미리 말해놨는데 이뭔이 고치라는 슬라이드 고칠거 다 고쳐놨고... 오늘 팔로업 미팅을 그 이후로 하기로 했지만 내가 4시전까진 온다고 했고 마침 미팅은 4시에 하기로 했고 근데... 이뭔 분이 자기 빨리 나가야한다고 미팅을 3시 15분에 시작하더라고 ㅋㅋㅋ 어떻게 하겠음 하여간 3시30분에 우여곡절끝에 집에 와서 온라인으로 미팅을 들어갔는데 미팅 그때 딱 끝남 ㅋㅋㅋ...

0
0
0
1

"바이브코딩 벌써 옛말…보안위험에 초고수 개발자 선호 흐름"
(샌프란시스코=연합뉴스) 권영전 특파원 = 인공지능(AI)의 등장으로 주목받았던 '바이브 코딩' 열풍이 '초고수 개발자' 선호로 이어지고 있다는...
yna.co.kr/view/AKR202601170182

1
1
1
0
0
1
0
0
0
0
1
1
0

VRChat turns 12 today!

Happy Anniversary and thank you to our amazing community for being here with us.

Stroll around the updated VRChat Home world to see pictures from our history and take pictures with the cake.

Share your memories with us using the hashtag #VRC12Years ! We'll RT our favorites.

0
0
0
0
1
1
1
0
0
0
1
0

F/OSS 史唯: 우리는 LLM을 거부할 게 아니라 되찾아 와야 한다
------------------------------
#### F/OSS를 LLM 훈련에서 막을 게 아니라, 훈련 결과 모델을 해방시켜야 한다는 주장

* 최근 〈자유·오픈 소스 소프트웨어와 LLM 학습에 관해〉(On FLOSS and training LLMs) 글이 F/OSS 커뮤니티의 좌절감을 잘 표현 — AI 기업의 …
------------------------------
https://news.hada.io/topic?id=25879&utm_source=googlechat&utm_medium=bot&utm_campaign=1834

0
1
0
0
0
1
0