log☇︎
38100+ entries in 0.315s
douchebag: I've been having a lot of fun with XML parsers lately, last night I reported a vulnerability to a mail provider. They didn't allow use of SYSTEM or DTD's however since Entities were being processed I could have knocked the whole service offline using a billion laughs attack
trinque: great. I'd like you to review the dependencies of trb (which were frozen at particular versions) for known public exploits, and to publish a report of this on your own mpwp blog. ☟︎
douchebag: Well, I'm a man of my word
douchebag: so that when the 30 minute timer is up it downs a non existent nick
ben_vulpes: asciilifeform: perhaps give the good readers a place at which to start?
trinque: my thinking on the thing is that it's as simple as each patch introducing a new line in HISTORY that matches the patch's name.
trinque: sure, antecedents are per-file, so if you want to have one line of history, gotta have a file that is the line.
spyked: thanks mod6. I wonder if it's one of those cases that spawned the discussion which led to the idea of a manifest file. in any case, it looks like the patch above (vdiff_lib_xalloc_static_xnmalloc) can have multiple children.
spyked: (also, I had to redo the patch anyway, since I initially used the keccak vdiff; but I'm pretty sure this should be a child of vdiff_fixes_newline_gcc, since the hashes for vtools/lib/xalloc.h match)
spyked: v.pl flow. not sure how to debug this yet, but I can take a look at it tomorrow
a111: Logged on 2018-03-28 20:37 phf: mod6: pressing to different tails should produce alternative builds without any conflicts. but the issue has been discovered, and it requires a patch. spyked originally found both the problem and the solution
xanthyos: not a full coin
danielpbarron: he has a key
mod6: well, read some docs, make a key, register it. then up yourself. 1 BTC is a hefty prize!
mod6: if there's a way to check, let me know, be happy to paste you the results.
phf: mod6: pressing to different tails should produce alternative builds without any conflicts. but the issue has been discovered, and it requires a patch. spyked originally found both the problem and the solution ☟︎
mod6: So there are a few things that I probably should ask about, as it wasn't wholly clear to me about the pressing side of things. Since there are multiple roots, and multiple leaves, there are two different press paths. Now, maybe I'm not supposed to have all of these in there?? But it looked to me from the thread at phf's site, that I needed to have them all.
phf: i think brk/sbrk is a reasonable alternative to malloc, since it makes a claim on a certain amount of processes's address space, without allocator's bookkeeping, that you then can use for heterogenous purposes. it's a dynamic alternative to having something like a static int heap[HEAP_SIZE] in your code.
phf: there's a bunch of others, around i think gets/getc, brk/sbrk, etc.
asciilifeform: even a musl gnat would be considerable improvement.
mircea_popescu: this is pretty terrible altogether. ave1 you got a moment ? how close is alf's "quite close" ? ☟︎☟︎
phf: spyked: if you sign your patch, i can include it in the vtools graph, a "collaborative" experience :)
phf: "Making a function an inline function suggests that calls to the function be as fast as possible. The extent to which such suggestions are effective is implementation-defined."
asciilifeform: mircea_popescu: it is a correct pill but not the culprit in hanbot's case : phf however just nao found the actual culprit
mircea_popescu: asciilifeform i dunno that it's entirely wrong ; "don't link libc if you're making a library" is right!
a111: Logged on 2018-03-01 13:52 spyked: anyway, comment was that I managed to compile and run vdiff with small mods; error: http://p.bvulpes.com/pastes/BiBTI/?raw=true and fix patch: http://p.bvulpes.com/pastes/9mOiz/?raw=true (tested this with the generated vdiff); I can try to link this reply later in a comment to test.
asciilifeform: and does. not. belong. in. a. library
asciilifeform: it's a libc function
asciilifeform: but in principle the answer seen in my gpr, is the pill. no libc in libs, it makes for duped linkage. (incidentally just as barfy in a c/cpp proggy as in gnat)
phf: the issue was already reported by someone else, but at the time the suggested fix was to put a bunch of C level annotations (some combination of static inlines), which i didn't think was an adequate solution, given that i don't understand why it does or doesn't work. but ascii's explanation makes sense, though i can't reproduce the issue on any of the machines i have with adacore's gnat (freebsd, osx, debian)
phf: these kind of flags are set by ~xml~ files inside gnat's gprbuild support files, so there can be a general patch on gnat to do the right thing
asciilifeform: ( even superceder, should really be a vpatch on diana_coman's artifact imho )
mircea_popescu: at least until/unless ave1 publishes a superseder.
asciilifeform: we still dun have a gnat-for-pc that shits out a binary ~wholly~ without libc ( although ave1 iirc is working on one and is quite close ) . but hanbot's issue is that libc got linked ~into the lib~ which results in attempting to link with 2 copies of libc (1 goes into the main) .
mircea_popescu: i am thinking this is actually something that needs changing in vdiff and being made a general rule.
mircea_popescu: anyway, whole issue seems to be that mktemp could "guess" a file that's about to be created by root and wipe it.
mod6: smh. im gonna take a few minutes here and try to build phf's thing. will report back in a bit.
mod6: I might be in over my head, phf, enlighten us when you have a moment plz.
mod6: "oh shit, it thinks my schlong is a snake! take cover!"
mod6: it's pretty fortunate to see such a thing!
mircea_popescu: bird was there for a good half hour, trying to figure out how to best extract the quarry, it was something else.
mircea_popescu: in other unrelated not-news, "gun crazy" is a terrible "film". just thought nobody'd like to know.
mircea_popescu: nah, not over a day like that.
mod6 feels much better after a nasty round of food poisoning
mircea_popescu: with a pencildick or ?
mircea_popescu: mmm pretty sure diana_coman has a holy gnat incarnation somewhere, part of the eucrypt writeup.
phf: asciilifeform: building weechat on a work laptop using homebrew. i mean, that's deep behind enemy lines, so it's not surprising, but i'm fascinated by the increasing levels of fail
shinohai: http://logs.bvulpes.com/trilema?d=2018-3-27#320406 <<< and I thank you for the hours of instruction not only on trb, but V as well. Has been a pleasure and an honour, Sir! o7
mod6: jurov^ The above is a Pizarro invoice for services rendered to The Bitcoin Foundation during the Month of March. Please remit the amount indicated to the address indicated in the deed. Thanks in advance! Please let me know if you have any questions.
mod6: <+hanbot> p.bvulpes.com/pastes/Sqn1u/?raw=true << anyone else ever seen this wonder? << you're missing a output directory
phf: http://btcbase.org/log/2018-03-27#1789989 << no, it's diffed with sha512 differ (a keccak vpatch wouldn't link into existing graph either, since hashes won't match) ☝︎
mircea_popescu: wait a damned second.
trinque: certainly the thing is needed in the abstract. service exists and user wants a stream of happenings.
mircea_popescu: trinque there's two layers here. layer 1 : there's a lot of flexibility in letting it be rss ; i can have a rss reader read it for me rather than put all failure points in freenode-dns.
asciilifeform: ( iirc mod6 introduced a check in a recent edition of his vtron, but possible that hanbot has the old one ? )
asciilifeform: this looks like a classic missing-commandline-util barf
mimisbrunnr: Logged on 2018-03-26 01:41 mircea_popescu: incidentally, "every shop must have a website (with ssl everywhere!!!)" and "every customer must have a loyalty card" trends of useless nonsense somehow haven't converged to the most basic sanity of, "give us your rsa pubkey, then download your data from our website whenever you want to, just go to shop.com/yourname"
mircea_popescu: trinque could the deedbot be strengthened with a) a rss page on the site, along the lines of http://logs.bvulpes.com/trilema?d=2018-3-26#319646 ; whereby i can visit http://deedbot.org/6160E1CAC8A3C52966FD76998A736F0E2FB7B452/feed where all items of interest (incoming payments and invoices as well as deeds signed by me) are announced (as rsa encrypted to my key items) ?
BingoBoingo: Right, nothing's a sure thing. Pantsuit is eating their Facebook of all things. US politics is getting deliciously weird on the way to the flush.
mircea_popescu: depends how the campaign goes. but if people turn out to actually give a shit about "stood up in arms to federal govt and won", heck, he's got it.
BingoBoingo: The best part is this isn't even the photogenic brother. This is the one whose face got run over by a car and droops. But yes he can win.
mircea_popescu: that country's a whole other level of comedy gold.
spyked: http://btcbase.org/log/2018-03-26#1789669 <-- of course, I'd be glad to! though I agree with diana_coman's observation that I'm a candidate but maybe not fit for lordship yet (perhaps a superfluous comment on my part, but since you asked) ☝︎
mircea_popescu: ben_vulpes not such a good idea to introduce more moving parts. but simply "n = x for a + y for b + z for c"
ben_vulpes: mircea_popescu: i suppose the thing to do is invoice once with a link to the deeded linen items
mircea_popescu: you know you should probably consolidate invoices, it'\s a pain in the ass to pay the same person 3 or n times in the same day/week
douchebag: Yeah I realize that, I just read up on a new technique and I'm geniunely interested to see if it's successful
mircea_popescu: but this is a fundamental part of the security model.
mircea_popescu: i taught her a lesson in handicapping of magnificent splendour rarely seen : halfway through last quarter, the score being 80 (to 40 something) i asked her whether they clear 94. no way. she bet me, and well...
mircea_popescu: in other proceedings, i met hanbot for drinks at the blue marlin (local brothel), where we watched teen hussies duke it out. literally : uconn beat the shit out of south carolina (all black girls, for maximum lulz. a tall lanky one even cried!).
BingoBoingo: asciilifeform: And we are solidly in autumn temperatures. Short sleeves are fine during the day, jacket may be desirable at night. The wind is starting to get a little bit of bite.
phf: i took a long walk over sf hills, and wanted to take an ocean dip at the end, but the last 15km on the way to the ocean were on flats, with a piercing cold wind. i was cold wearing a shirt and a sweater, so no swimming, but still it was a pleasant walk. there's really nothing bad to say about the weather here.
phf: http://btcbase.org/log/2018-03-26#1789697 << not as hot as palm springs (which is full blown summer at this point), but basically spring. it was raining last week, but right now it's a shirt weather. if you're close to the ocean, then it's blowing cold wind. what i'm trying to say is that the weather is excellent, and i'm loathing going back to the swamps. ☝︎
mircea_popescu: all right an' proper like a real corp over here.
BingoBoingo: And when the US was having its civil war Brasil, Argentina, and Uruguay went into Paraguay and fucked their shit up as a bonding experience.
BingoBoingo: They have a fairly important river, but more like the Mississippi and less of a wide "is this a river or sea" thing like the Rio de la Plata
mircea_popescu: lobbes ima put it in the mar report ; but the short story is, server i supposedly bought in feb still not here by late march, minigame dun have a server now.
mircea_popescu: a yea
mircea_popescu: http://trilema.com/2016/there-has-not-yet-been-seen-a-simple-thing-even-if-were-drowning-in-simple-people/
BingoBoingo: Upon arrival "Look at that chop job, a motorcycle with a truck bed"
BingoBoingo: Hey, I was shocked when I found out the Yumbo Cargo is a factory model and not a local hack http://archive.is/nJ1ML
asciilifeform: eng. linguists used to call 'lcd language' , a 'pidgin' ( not to be confused with the homophonic bird ) , but iirc this term is now pantsuit-verboten
BingoBoingo: Not a process post, but a who is coming in post.
BingoBoingo: Ah, a sort of Dominican-Spanish
mircea_popescu: whole lotta "france got me! i'm a phrancophone! i only eat at French's diner in wisconsin."
BingoBoingo: <mircea_popescu> swahili isn't one of them. << Swahili's the one Soviet allies in US academia were directed to, likely because not a language
mircea_popescu: so now he's a scumbag who's trying to eat out of getting people to be colors ?
BingoBoingo: "I credit that group with creating my identity consciousness. Before that, I was a brown kid that wanted to be white. Eusa Nia (Swahili for Black Purpose) got me."
BingoBoingo: ^ Ah, bonus I didn't notice until pasting the text. Author's name is PATEL!!! A wild PREEET
mircea_popescu: all that carefully crafted tower of narcisism and self-absorbtion (they prefer to call it "intellectual property")! how cruel and unfair that the world doesn't give a damn!
mircea_popescu: a
mircea_popescu: is that a rapper ?
BingoBoingo: And so that it is entered into the record, Killer Mike is a rapper beloved by black people and nearly unknown by the category of people who consider themselves "cucked white allies"
BingoBoingo: A couple other typos spotted an killed
mircea_popescu: in other lulz from the nursery, "stereotypes are bad" "isn't that a stereotype ?"
mimisbrunnr: Logged on 2018-02-14 14:18 mircea_popescu: MEANWHILE, however, they have 100% unaccounted for the time externality. so basically it's a contest consisting of a guy without legs going about finding fault with people's fingers. because he's decided "legs don't count", and so as he has much better hands than the rest of those losers he should be captain of the football team.
asciilifeform: re 'bostonism of star trek', i recall reading that it is ~officially~ a plot point, that the starship had no toilet. erryone shits in pants, and it is teleported out. this is automatically what i think of when hear 'star trek'
mircea_popescu: which is how come a) "oh, we have the dumb flickering plastic from star trek!!!" is somehow supposed to be a pillar of faith supporting the pantsuit money printing press ; while b) nobody fucking notices that the ~only item of any value whatsoever in the whole franchise was marina sirtis' ass, and they still don't get to see that, much like there's no jane russell porn.
mircea_popescu: then there's that heyman faggot with the harry potter crapolade... there's seriously not a fucking human being among them.
asciilifeform: ... or is it moar of a general-purpose 'workout', a la stalin's generals, i.e. 'yes guess what, generals are removable'