Sekitar 20 hasil (2.49 detik)
Komunitas feddit.it

Why docker

About the root problem, as of now new installs are trying to let the user to run everything as a limited user. And the program is ran as root inside the container so in order to escape from it the attacker would need a double zero day exploit (one for doing rce in the container, one to escape the container) The alternative to “don’t really know what’s in the image” usually is: “just download this Easy minified and incomprehensible trustmeimtotallynotavirus.sh script and run it as root”. Requires much more trust than a container that you can delete with no traces in literally seconds If the program that you want to run requires python modules or node modules then it will make much more mess on the system than a container. Downgrading to a previous version (or a beta preview) of the app you’re running due to bugs it’s trivial, you just change a tag and launch it again. Doing this on bare metal requires to be a terminal guru Finally, migrating to a new fresh server is just docker compose down, then rsync to new server, and then docker compose up -d. And not praying to ten different gods because after three years you forgot how did you install the app in bare metal like that. Docker is perfect for common people like us self hosting at home, the professionals at work use kubernetes

Komunitas piefed.social

3 Questions from a Windows refugee and Linux noob regarding NTFS drive, partitioning, and Steam.

TL;DR - Question 1: how bad would it be to mount a NTFS drive and continue using it in NTFS format with Linux? Question 2: should I partition my drive to have separate / partition and /home partition if I’m planning to distro hop? Question 3: can I make Steam use game files on my secondary NTFS HDD? I’m getting fed up with Windows day by day with how slow and chuggy it is. My initial plan to buy a new 1TB SSD for Linux is out of the window thanks to astronomical prices and I’m upset by it. So is how HDD prices are also impacted. I have a 2TB HDD formated in NTFS because back then when I built my PC I didn’t think to try linux so I let it stay in NTFS. This drive is where all my personal files and data is. This is a separate drive from the 500GB NVME drive I use for Windows, which will be wiped for Linux. Currently I also have an external portable SSD as a backup / working storage for my work supplied Windows laptop. I am unsure of the parity of my personal data and files is on the portable SSD with my 2TB HDD. So for the forseeable future the HDD will remain in NTFS and could not be reformated into a Linux friendlier format at the moment. So my Question 1 is, how bad would it be to mount that NTFS HDD drive and continue using and working on it, with Linux? Question 2: I haven’t actually decided really what distro to stick with. I’m in a choice paralysis between trying base Fedora, Nobara, atomic Fedora but not Bazzite, and CachyOS. Regardless what I choose I feel like I might distro hop sooner than later. So should I set a different partition for /home? From what I understand, the advantage would be I wouldn’t have to touch my personal data when I distro hop. As I understand it I can just wipe the / partition for the OS I want try next. The disadvantage is that say moving from Fedora to Arch there could be some binaries or config files that might clash and as a noob I’d be in for a rollercoaster of fixing stuff. Am I wrong in my reading and understanding? But if I’m already putting my personal data on a separate drive from the OS drive, I really shouldn’t be bothering with partitioning the OS drive. The other advantage that I read for having / and /home partitions is that if the system have multiple users, there’s a lot lesser risk of a user might fill the whole drive and preventing the OS to update later. So for a single user system like mine, and having a big storage size that is unlikely to happen anyways and I would only have to bother reinstalling programs every time I distro hop. Edit: further understanding and questions related to Question 2: 2: always, even if not distro hopping. You can use a volume aware filesystem like Btrfs and have @ mounted on / and @home mounted on /home, so you don’t have to pre allocate space for one or another. Many distros will detect this setup and smartly use snapshots to revert upgrades without touching your home dir. Interesting thing I saw yesterday when I “test run” to install Fedora KDE Plasma on a USB stick. I didn’t go through with it, but I noticed that the installer suggest to partition my drive as such: sdc1 - format as efi - /boot/efi sdc2 - format as efi - /boot sdc3 - format as btrfs subvolume - / sdc4 - format as btrfs subvolume - /home Is that a good default? on the page that ask whether to install fedora side by side another OS, full wipe, or manual partition, I noticed that whatever drive I want to use it already have to be non Windows friendly. In my case, my nvme is in NTFS naturally, my HDD is in NTFS as well, and my test USB stick is in exfat. Question 3: I have a few games that I already downloaded and install on the Windows system. I plan to move the games that’s installed on the OS drive to the secondary HDD drive, then use that files for when I install linux on the OS drive. Should I not bother with it instead and just bite the bullet and wipe the game files and download it again? or can I make it work somehow? I have checked that my hardware peripherals such as my mic, game controller, gaming wheel and my audio card works before when I ran a live ISO, so that’s fine on that end, I hope. I don’t think I’ll encounter problems with my NVidia card; and if I do I think there’s enough help out there for me to figure it out. So really it’s these 3 big questions that I’ve thought of the more I research before moving to Linux wholesale. If I need any Windows stuff I always have my work supplied laptop. I only need Windows for work only, and I don’t use any Adobe stuff. I’ll admit that I have asked a few AI my questions, but since my personal data is valuable I don’t trust what their answers are. So that’s why I’m making this post. I’m going to play my ESL card and say that I tried my best to convey what I have in my head as best I can. I’ll be happy to clarify further if my wording doesn’t make sense. TIA.

Komunitas lemmy.world

Tech support for mum

Just here to brag that when my dad upgraded to windows 11, he was tricked into making a microsoft365 acct which was promptly compromised. So I walked him through the process of downloading a Linux mint iso, checking the hash in powershell, downloading rufus, prepping install media, and getting him off windows for the remainder of his life. I had no eyes on the situation. All over the phone. His browser was giving malware results for everything so no downloads could be trusted. 2 years on his only complaint is occasional printer problems. He’s in his 70s.

Komunitas lemmy.world

It's not a store... it's where I get my free games.

There are plenty of legitimate reasons to criticise Valve. I still strongly disagree with being forced to update a game before I can launch it. Greenlight and Steam Direct were/are consistently a pit of scum and shovelware. I still haven’t forgotten their attempt together with Bethesda to introduce paid mods to the Workshop. I wasn’t around when Steam itself was introduced (we still traded game CDs on the playground at the time), but I understand it was a horrid service and software. Then there’s the matter of actual gambling in Counter-Strike and TF2 and the massive secondary market attached to them that Valve refuse to acknowledge. Nothing’s ever only one way or the opposite, though. There’s always a spectrum of what a customer is willing to put up with, weighed against what a customer gains by putting up with a company’s behaviour. For putting up with Valve’s bullshit, as a gamer, I get a reliable service, a massive library of games, unparalleled download speed, free cloud storage for saves and settings, content management, community integration, and benefits too numerous to recount. As a Linux gamer, I get all of their work on Proton, on upstream Wine, Gamescope, DXVK and VKD3D, many of which I use even outside gaming, for free. When Steam’s quasi-monopoly was threatened by the EGS, Valve did not try to lock down developers. The only policy change they enacted was requiring games that are advertised on Steam Steam to actually launch on Steam, after people who preordered Metro Exodus were shafted, in order not to become an advertisement platform for their competition. Then they released publicity videos about the Steam Deck that appealed to Linux enthusiasts, handheld gamers, and right-to-repair advocates. Even as a “DRM platform”, they’ve captured that niche. I’ve said many times that success is not illegal. I was excited and hopeful when I heard that Steam was getting a competitor with a company backing it that had a chance of challenging the status quo. Epic and the EGS were given the best opportunity anyone was ever going to get and they fumbled it. They alienated their potential customerbase when they poached Metro Exodus and early third-party-exclusive titles, showed that they did not have a solid foundation when Borderlands 3 was launched without the ability to preload, gave us reason to question their security practices when a data scraper was found in the installed application, and drew further criticism when they would only accept indie titles if they were made EGS-exclusive while allowing Cyberpunk 2077 to launch on multiple platforms. Since then, it’s become a haven for AI and NFT shovelware that Valve have rejected based on legal/moral issues. I will acknowledge that some good came of their actions. Apple was forced to remove their anti-competitive policy that prevented developers from placing links and buttons that directed users to other payment processors. Still, it is the fruit of the poisonous tree: they intentionally broke ToS and had an eighty-page lawsuit and an animated short film prepared, acting like they were the innocent “for the players” party set upon by the evil corporations, rallying children as their uncritical lynch mob. In conclusion, Valve has done things I dislike, but I have reason to conditionally accept and tolerate them; as I have reason to distrust and dislike Epic and the EGS. My choice whenever possible, though, is GOG, which I didn’t mention as it was not part of the conversation and is mostly doing its own thing. I rambled too much, and I’m too lazy to proofread, so I hope I make some kind of sense.

Komunitas lemmy.world

User says access to ’30 years of photos and work’ in OneDrive denied by Microsoft, can't get a response after filing form 18 times — 'Microsoft suspended my account without warning, reason, or any leg

Cloud storage is NOT A BACKUP! PSA: I’m worried that people are going to read this thread and be confused or get the wrong idea. Syncing = A dynamic copy of files that are on your computer, if you edit or delete the file on the computer, the file in the cloud is edited or deleted automatically as well. Cloud Storage/Drive = A static copy of a file is uploaded to the cloud, typically with a limited amount of time, storage space, or number of downloads imposed. This varies wildly from service to service, especially free services, and is subject to a number of caveats that make your data less than safe even if you’re paying for it. Neither of these should be considered a reliable backup of your data. Especially in the event of data loss. If for no other reason than the title story of this post. And corporate cloud storage is the exact opposite of private. If you want online backup, pay for a dedicated backup service that is supported by a service fee. Do not trust your data to free services. Especially with data protection, you only get what you pay for. In the long run, and for what you’re getting they are typically very inexpensive. If you like to DIY, buy space on a server farm and use software of your choice to backup to that. DO NOT take 9tr6gyp3’s backup advice. Google Drive and the like are NOT suitable replacements for a real offsite backup. And “the cloud” should absolutely NOT be your only copy of anything no matter how safe and secure it i seems to be.

Komunitas lemmy.world

Google appears poised to replace classic search with AI Mode, a move that could transform how users access information.

I ditched Google Chrome years ago. I’ve been using Firefox and now Zen. And despite all the removed, duck duck go is 99% as effective for most searches. At most, you have to go through one or two more pages. Which nowadays is about the same you would have to do on Google. Only the entire time you were bombarded with advertising lies in AI slop. While also feeding their ad machine. I cannot, in my lifetime, think of another company that had such overwhelming, positive public opinion and momentum and squandered at all so effectively and thoroughly to the extent that they are seen as almost a villain by huge chunks of the world globally. I think the craziest thing is that someone in their company actually allowed them to get rid of their don’t be evil motto. Even if they were going to do all the evil shit they already are doing, just keeping the motto around was such an easy PR win in slam dunk to deflect concerns to and say, oh no, we’re always keeping in mind not to be evil. I don’t know if that was the day that Google’s fortunes turned. But it definitely feels like it was a tipping point for the history of the company. And now, even though I’m posting this from an Android phone, they just announced plans to make Android shittier in one year by locking down the ability to install apps from online downloads even further. And here I am trying to think of how I can get a custom ROM installed on my phone again for the first time in over a decade. Not because I want new features or cutting edge technology. But because I just want that fucking company as far away from me as possible, and the “year of the Linux phone” is not here yet. So figuring out some kind of way to put Google Apps into a jail and lock them out of my life except when I need them is the new goal. (Probably GrapheneOS) The fact that they lost their antitrust case and were declared a monopoly and then were hit with basically no punishment whatsoever other than sharing a tiny bit of the data with other super corporations, just makes me livid beyond belief. Companies like this and the CEOs and executives that run them should not exist.

Komunitas lemmy.sdf.org

How to use “unearth” to get a list of URLs of packages needed by an app

The unearth syntax is like this: usage: unearth [-h] [--verbose] [--index-url URL] [--find-link LOCATION] [--trusted-host HOST] [--no-binary] [--only-binary] [--prefer-binary] [--all] [--link-only] [--download [DIR]] [--python-version PY_VER] [--abis ABIS] [--implementation IMPL] [--platforms PLATFORMS] requirement I want to get the whole list of all wheel files that argostranslate version 1.9.6 is dependent on, because that’s possibly the last version of argos-translate that worked offline. My first attempt: $ unearth --find-link /usr/local/src/argos-translate/wheel_cache/ argostranslate=1.9.6 usage: unearth [-h] [--verbose] [--index-url URL] [--find-link LOCATION] [--trusted-host HOST] [--no-binary PACKAGE] [--only-binary PACKAGE] [--prefer-binary] [--all] [--link-only] [--download [DIR]] requirement unearth: error: argument requirement: invalid Requirement value: 'argostranslate=1.9.6' It does not accept my version constraint, despite examples using that kind of syntax. So I had to do this: $ unearth --all --find-link /usr/local/src/argos-translate/wheel_cache/ argostranslate It dumped metadata on all versions. I picked through the heap of output and found this: { "name": "argostranslate", "version": "1.9.6", "link": { "url": "https://files.pythonhosted.org/packages/01/f9/b472322ea3de4752bbec7fb2f169f057872390a9ff35f72a2142d06392ae/argostranslate-1.9.6-py3-none-any.whl", "comes_from": "https://pypi.org/simple/argostranslate/", "yank_reason": null, "requires_python": ">=3.5", "metadata": null } }, { "name": "argostranslate", "version": "1.9.6", "link": { "url": "https://files.pythonhosted.org/packages/6b/fc/13aa57857bee34f62cb9018c5fd4ec56da714431689b62cca9dce30a8877/argostranslate-1.9.6.tar.gz", "comes_from": "https://pypi.org/simple/argostranslate/", "yank_reason": null, "requires_python": ">=3.5", "metadata": null } }, That just gives the wheel for the app itself, not the wheels it depends on. How can I get the full list of wheels that argostranslate is dependent on using unearth? I should say that I supply the following option because I happen to already have all the wheel files: --find-link /usr/local/src/argos-translate/wheel_cache/ That’s just to feed unearth as well as possible as an experiment. In fact it makes no difference if I omit the --find-link option. The end game is to be able to get this list in the future when I am starting from zero. I might be looking to do something like --verbose --download --dry-run, but there is no --dry-run. My wheel dir (/usr/local/src/argos-translate/wheel_cache/) ::: spoiler currently contains these files annotated_types-0.7.0-py3-none-any.whl argostranslate-1.10.0-py3-none-any.whl blis-1.3.3-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.whl catalogue-2.0.10-py3-none-any.whl certifi-2025.11.12-py3-none-any.whl charset_normalizer-3.4.4-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl click-8.3.1-py3-none-any.whl cloudpathlib-0.23.0-py3-none-any.whl confection-0.1.5-py3-none-any.whl ctranslate2-4.6.2-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.whl cymem-2.0.13-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.whl emoji-2.15.0-py3-none-any.whl filelock-3.20.1-py3-none-any.whl fsspec-2025.12.0-py3-none-any.whl idna-3.11-py3-none-any.whl jinja2-3.1.6-py3-none-any.whl joblib-1.5.3-py3-none-any.whl markupsafe-3.0.3-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl mpmath-1.3.0-py3-none-any.whl murmurhash-1.0.15-cp311-cp311-manylinux1_x86_64.manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_5_x86_64.whl networkx-3.6.1-py3-none-any.whl numpy-2.4.0-cp311-cp311-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl nvidia_cublas_cu12-12.8.4.1-py3-none-manylinux_2_27_x86_64.whl nvidia_cuda_cupti_cu12-12.8.90-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl nvidia_cuda_nvrtc_cu12-12.8.93-py3-none-manylinux2010_x86_64.manylinux_2_12_x86_64.whl nvidia_cuda_runtime_cu12-12.8.90-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl nvidia_cudnn_cu12-9.10.2.21-py3-none-manylinux_2_27_x86_64.whl nvidia_cufft_cu12-11.3.3.83-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl nvidia_cufile_cu12-1.13.1.3-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl nvidia_curand_cu12-10.3.9.90-py3-none-manylinux_2_27_x86_64.whl nvidia_cusolver_cu12-11.7.3.90-py3-none-manylinux_2_27_x86_64.whl nvidia_cusparse_cu12-12.5.8.93-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl nvidia_cusparselt_cu12-0.7.1-py3-none-manylinux2014_x86_64.whl nvidia_nccl_cu12-2.27.5-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl nvidia_nvjitlink_cu12-12.8.93-py3-none-manylinux2010_x86_64.manylinux_2_12_x86_64.whl nvidia_nvshmem_cu12-3.3.20-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl nvidia_nvtx_cu12-12.8.90-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl packaging-25.0-py3-none-any.whl preshed-3.0.12-cp311-cp311-manylinux1_x86_64.manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_5_x86_64.whl protobuf-6.33.2-cp39-abi3-manylinux2014_x86_64.whl pydantic-2.12.5-py3-none-any.whl pydantic_core-2.41.5-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl pyyaml-6.0.3-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl regex-2025.11.3-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl requests-2.32.5-py3-none-any.whl sacremoses-0.1.1-py3-none-any.whl sentencepiece-0.2.1-cp311-cp311-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl setuptools-80.9.0-py3-none-any.whl smart_open-7.5.0-py3-none-any.whl spacy-3.8.11-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.whl spacy_legacy-3.0.12-py2.py3-none-any.whl spacy_loggers-1.0.5-py3-none-any.whl srsly-2.5.2-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.whl stanza-1.10.1-py3-none-any.whl sympy-1.14.0-py3-none-any.whl thinc-8.3.10-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.whl torch-2.9.1-cp311-cp311-manylinux_2_28_x86_64.whl tqdm-4.67.1-py3-none-any.whl triton-3.5.1-cp311-cp311-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl typer_slim-0.21.0-py3-none-any.whl typing_extensions-4.15.0-py3-none-any.whl typing_inspection-0.4.2-py3-none-any.whl urllib3-2.6.2-py3-none-any.whl wasabi-1.1.3-py3-none-any.whl weasel-0.4.3-py3-none-any.whl wrapt-2.0.1-cp311-cp311-manylinux1_x86_64.manylinux_2_28_x86_64.manylinux_2_5_x86_64.whl ::: I can run unearth on the prefixes of each of those – but that’s cheating, because in a future installation starting with nothing I will not know those packages or versions.

Komunitas lemmy.zip

Is F-droid insecure?

Your options are building from source, downloading dev apks, or using an app store. If you can’t trust anyone, then you need to build from source Fdroid is the best of the app stores, they are always trying to stay ahead of the curve when it comes to privacy, security, and trust Reproducible builds are the standard for FOSS trust, see this article for an overview. They close the gap between app stores and dev apks Fdroid are constantly working to increase the prevalence of reproducible builds, and to enable you to verify more so you have to rely less on trust

Komunitas lemmy.max-p.me

So many questions, so much headache

Why are there so many distros out there? What’s the difference between debian + kde and manjaro + kde? They look the same, they work the same. I don’t get it. They visually look similar because both are running KDE with pretty much all the defaults, as it happens both Debian and KDE don’t diverge too much from the recommended defaults as long as they work well. But under the hood, Debian and Manjaro work completely differently: one uses apt, the other uses pacman. The way those packages are maintained, compiled and distributed is vastly different, with different kinds of QA testing. Ubuntu is a derivative of Debian, so it doesn’t look that much different but Canonical does tend to provide newer packages than Debian does. But Ubuntu also has a lot of flaws so spinoffs like Mint and Pop_OS! take on Ubuntu as a base and “fix” it to their liking and hopefully the user’s too, which, given how popular Mint is I’d say they’re pretty successful in that goal. Also why do things have to be complicated? It doesn’t, but the amount of options and choices in how to do basically anything on Linux can certainly look very overwhelming. You can click on it in your file manager, you can add it to /etc/fstab, you can use a systemd mount unit. They’re different ways of automating and configuring what ends up being mostly the same: mounting a filesystem and setting permissions on it, and they come with different defaults. You’re running into the particular area of trying to mount an NTFS Windows partition on Linux, which is nothing like what Linux expects to it fakes a few things to make it work, and that makes everything owned by the same user by default. If you do it from your file manager, it’ll get a temporary mountpoint in like /run/user/1000/media/YOUR DRIVE but is mostly intended for when you plug in a USB or something. You probably found /etc/fstab but then that made all the files owned by root, and you can temporarily change that with chmod and chown but once you reboot and it gets mounted again, it’ll revert back because it doesn’t actually store those fake permissions as to not break Windows. It’s just problems, after problems, after problems and i didn’t even start gaming. Yeah, some people end up particularly unlucky in that department. Eventually, over time, it feels as easy or easier than on Windows. It’s just, you have years of experience on how to make Windows do the thing, and Linux is completely new to you. I had a very similar experience a couple years ago when I was forced to learned macOS because the job would only issue MacBooks. Everything felt way overcomplicated and eventually you start thinking the Apple way and it goes more smoothly, you understand better how it works. I mean, how alien is it to just open disk images and copy .app files to /Applications and that’s how you “install” things?? And you get used to it and now I wield the macOS terminal like I do on Linux. What do i need to do to install a AUR package? A wall of text on the wiki, 20 minutes videos, yay. Ok let’s call it a day. So, this is why people don’t like recommending Manjaro. It’s ArchLinux with a coat of paint, but still relies on Arch’s infrastructure for the AUR. ArchLinux is well into advanced Linux: it’s a box of legos you have to assemble in the shape of a Linux distro yourself. So yes they do expect you to do a fair bit of reading, but Manjaro doesn’t, and it’s a real problem that has caused a fair bit of drama at its time. The AUR is great, but to make another analogy, the AUR is more like a recipe book: you don’t download premade meals, you have to bake them yourself (compiling source code into binary) to have your meal (the generated package file). Sending beginners that route is a recipe for a bad experience. Ironically, yay is the name of one of the tools that helps install AUR packages. Do i need to live another life to make linux work? No, but it does take some initial commitment to get to the nicer part of the learning curve. The first install is always pretty rough, you will destroy it, that’s fine, you have to learn first. Ok let’s call it a day. Honestly by the post you should have done that earlier. As with anything, when you’re frustrated with it you stop learning, you start making it much harder than it needs to be. It’s fine to take a step back and reboot into Windows and try again the next day. It doesn’t have to be all or nothing, plenty of people have started by using Linux for just one task that’s easier to do on Linux, and eventually you start thinking of migrating more workloads to Linux over time. You’re restarting your computer learning journey from pretty close to the start, give yourself a break, computers aren’t worth getting pissed off at.

Komunitas ibbit.at

Optimizing Software with Zero-Copy and Other Techniques

An important aspect in software engineering is the ability to distinguish between premature, unnecessary, and necessary optimizations. A strong case can be made that the initial design benefits massively from optimizations that prevent well-known issues later on, while unnecessary optimizations are those simply do not make any significant difference either way. Meanwhile ‘premature’ optimizations are harder to define, with Knuth’s often quoted-out-of-context statement about these being ‘the root of all evil’ causing significant confusion. We can find Donald Knuth’s full quote deep in the 1974 article Structured Programming with go to Statements, which at the time was a contentious optimization topic. On page 268, along with the cited quote, we see that it’s a reference to making presumed optimizations without understanding their effect, and without a clear picture of which parts of the program really take up most processing time. Definitely sound advice. And unlike back in the 1970s we have today many easy ways to analyze application performance and to quantize bottlenecks. This makes it rather inexcusable to spend more time today vilifying the goto statement than to optimize one’s code with simple techniques like zero-copy and binary message formats. Got To Go Fast The cache hierarchy of the 2008 Intel Nehalem x86 microarchitecture. (Source: Intel) There’s a big difference between having a conceptual picture of how one’s code interacts with the hardware and having an in-depth understanding. While the basic concept of more lines of code (LoC) translating into more RAM, CPU, and disk resources used is technically true much of the time, the real challenge lies in understanding how individual CPU cores are scheduled by the OS, how core cache synchronization works, and the impact that the L2 and L3 cache have. Another major challenge is that of simply moving data around between system RAM, caches and registers, which seems obvious at face value, but the impact of certain decisions can have big implications. For example, passing a pointer to a memory address instead of the entire string, and performing aligned memory accesses instead of unaligned can take more or less time. This latter topic is especially relevant on x86, as this ISA allows unaligned memory access with a major performance penalty, while ARM will hard fault the application at the merest misaligned twitch. I came across a range of these issues while implementing my remote procedure call library NymphRPC. Initially I used a simple and easy to parse binary message format, but saddled it with a naïve parser implementation that involved massive copying of strings, as this was the zero-planning-needed, smooth-brained, ‘safe’ choice. In hindsight this was a design failure with a major necessary optimization omitted that would require major refactoring later. In this article I’d like to highlight both the benefits of simple binary formats as well as how simple it is to implement a zero-copy parser that omits copying of message data during parsing, while also avoiding memory alignment issues when message data is requested and copied to a return value. KISS Perhaps the biggest advantage of binary message formats is that they’re very simple, very small, and extremely low in calories. In the case of NymphRPC its message format features a standard header, a message-specific body, and a terminator. For a simple NymphRPC message call for example we would see something like: uint32 Signature: DRGN (0x4452474e) uint32 Total message bytes following this field. uint8 Protocol version (0x00). uint32 Method ID: identifier of the remote function. uint32 Flags (see Flags section). uint64 Message ID. Simple incrementing global counter. <…> Serialised values. uint8 Message end. None type (0x01). The very first value is a 32-bit unsigned integer that when interpreted as characters identifies this as a valid NymphRPC message. (‘DRGN’, because dragonfly nymph.) This is followed by another uint32 that contains the number of bytes that follow in the message. We’re now eight bytes in and we already have done basic validation and know what size buffer to allocate. Serializing the values is done similarly, with an 8-bit type code followed by the byte(s) that contain the value. This is both easy to parse without complex validation like XML or JSON, and about as light-weight as one can make a format without adding something like compression. Only If Needed When we receive the message bytes on the network socket, we read it into a buffer. Because the second 32-bit value which we read earlier contained the message size, we can make sure to allocate a buffer that’s large enough to fit the rest of the message’s bytes. The big change with zero-copy parsing commences after this, where the naïve approach is to copy the entire byte buffer into e.g. a std::string for subsequent substring parsing. Instead of such a blunt method, the byte buffer is parsed in-place with the use of a moving index pointer into the buffer. The two key methods involved with the parsing can be found in nymph_message.cpp and nymph_types.cpp, with the former providing the NymphMessage constructor and the basic message parser. After parsing the header, the NymphType class provides a parseValue() function that takes a value type code, a reference to the byte buffer and the current index. This function is called until the terminating NYMPH_TYPE_NONE is found, or some error occurs. Looking at parseValue() in more detail, we can see two things of note: the first is that we are absolutely copying certain data despite the ‘zero-copy’ claim, and the liberal use of memcpy() instead of basic assignment statements. The first item is easy to explain: the difference between either copying the memory address or the value of a simple integer/floating point type is so minimal that we trip head-first into the same ‘premature optimization’ thing that Mr. Knuth complained about back in 1974. Ergo we just copy the value and don’t break our pretty little heads about whether doing the same thing in a more convoluted way would net us a few percent performance improvement or loss. This is different with non-trivial types, such as strings. These are simply a char* pointer into the byte buffer, leaving the string’s bytes in peace and quiet until the application demands either that same character pointer via the API or calls the convenience function that assembles a readily-packaged std::string. Memcpy Is Love Although demonizing ‘doing things the C way’ appears to be a popular pastime, if you want to write code that works with the hardware instead of against it, you really want to be able to write some highly performative C code and fully understand it. When I had written the first zero-copy implementation of NymphRPC and had also written up what I thought was a solid article on how well optimized the project now was, I had no idea that I had a “fun” surprise waiting for me. As I happily tried running the new code on a Raspberry Pi SBC after doing the benchmarking for the article on an x86 system, the first thing it did was give me a hard fault message in the shell along with a strongly disapproving glare from the ARM CPU. As it turns out, doing a direct assignment like this is bound to get you into trouble: methodId = ((uint32_t) (binmsg + index)); This line casts the current index into the byte buffer as a uint32_t type before dereferencing it and assigning the value to the variable. When you’re using e.g. std::string the alignment issues sort themselves out somewhere within the depths of the STL, but with direct memory access like this you’re at the mercy of the underlying platform. Which is a shame, because platforms like ARM do not know the word ‘mercy’. Fortunately this is easy to fix: memcpy(&methodId, (binmsg + index), 4); Instead of juggling pointers ourselves, we simply tell memcpy what the target address is, where it should copy from and how many bytes are to be copied. Among all the other complex scenarios that this function has to cope with, doing aligned memory address access for reading and writing is probably among its least complex requirements. Hindsight Looking back on the NymphRPC project so far, it’s clear that some necessary optimizations that ought to have been there from the very beginning weren’t there. At least as far as unnecessary and premature optimizations go, I do feel that I have successfully dodged these, but since these days we’re still having annual flamewars about the merits of using goto I very much doubt that we will reach consensus here. What is clear from the benchmarking that I have done on NymphRPC before and after this major refactoring is that zero-copy makes a massive difference, with especially operations involving larger data (string) chunks becoming multiple times faster, with many milliseconds shaved off and the Callgrind tool of Valgrind no longer listing __memcpy_avx_unaligned_erms as the biggest headache due to std::string abuse. Perhaps the most important lesson from optimizing a library like NymphRPC is that aside from it being both frustrating and fun, it’s also a humbling experience that makes it clear that even as a purported senior developer there’s always more to learn. Even if putting yourself out there with a new experience like porting a lock-free ring buffer to a language like Ada and getting corrected by others stings a little. After all, we are here to write performant software that’s easy to maintain and have fun while doing it, with sharing optimization tips and other tricks just being part of the experience. From Blog – Hackaday via this RSS feed

Komunitas ibbit.at

Why is the US Left so Chickensh*t?

Photograph by Nathaniel St. Clair January 3, 2026, should be the date to end all discussion: Trump’s raid on Venezuela should have clarified reality even to the most obtuse: the US is not an “ordinary” country, as is claimed by observers all around, but is the center of the US Empire. Its “leaders” seek to dominate the world. Those of us on the radical left have been correct: the United States is an imperialistcountry, and currently, the most powerful one on the planet. After observing the war in Vietnam, as a US Marine who spent his four years in the United States (1969-73), and taking some time to try to reconsider my thinking after getting out of the military, I began serious writing in 1984, trying to understand what was going on in the world. Obviously, what I had been told while growing up by my family, schools, and government had been a series of lies. Vietnam had not been invaded by an external force; the war there was a civil war, and the United States had, in its arrogance, stuck its nose into. (Years later, I learned that in Geneva during1954, the US had agreed with the French, the Chinese, the Soviets, and “North” Vietnamese to allow the people of “South” Vietnam to have a free and fair election so as to decide whether they wanted to live as an “independent” country under a French puppet regime or if they wanted to join with those in the north of Vietnam, under Ho Chi Minh, to be part of Vietnam. The election was to take place in 1956. That year, the “independent” regime cancelled the agreed-upon elections, which were never held. The reason, according to then-President Dwight Eisenhower in his memoirs, was that ‘Every poll showed that Ho Chi Minh would have won 80 percent of a free, fair election,’ and that’s why 3.8 million Vietnamese were killed and another 5.7 million wounded, and over 58,000 Americans and other allies were killed, and hundreds of thousands were wounded and often traumatized for life. See Turse, 2013.) But that information, which I picked up along the way, was not what I was ultimately seeking; I was trying to figure out how changes in the global economy were affecting US workers (Scipes, 1984). I was, at the time, taking a graduate course in international relations at San Francisco State University while working as a union printer and labor activist in the Bay Area. To try to grasp the economic developments beginning during the late 1970s, I felt it necessary to go back to the end of World War II, in 1945. Trying to begin with the big picture, I recognized that there were two empires in the world, one led by the United States and one by the Union of Soviet Socialist Republics (USSR or Soviet Union) and, while recognizing the existence of each, I concentrated on the US Empire. This was unusual; at that time; no scholar that I found had used this term. [Years later, I learned that William Appleman Williams in his 1959/1962 book had used this term, and then in Black Against Empire by Joshua Bloom and Waldo E. Martin, Jr. (2013), that the Black Panthers had used it during the late 1960s-early ‘70s in presenting their understanding of the world. In 1989, Jan Nederveen Pieterse, a Dutch-born scholar, used the term in his title, Empire and Emancipation. There probably have been others.] And later, the late William Blum (1986, 2000, 2013)—whose work has been so influential upon many US activists—thought he was responsible for revival of the term; when I stayed with him in his apartment in Washington, DC the last time we saw each other—probably somewhere around 2016-18—we discussed this and I showed him I had revived the term before him; obviously, his important books popularized the term far beyond my simple paper. In any case, I think it’s safe to say that I was among the earliest of those who used it after the end of the American war in Vietnam. Yet today, as far as I can tell, I am among only a few who have used the term consistently over the years (for a few examples, see Scipes, 1989, 2010a, 2010b, 2016, 2023), although Alfred W. McCoy finally adopted it in 2017, and he reported in his brilliant Shadows of the American Century (2017) that it had been adopted by a range of scholarly writers; he continues in his 2026 subtitle. Now, I can understand why my limited range of published articles had such a minor impact, but I cannot understand the same for a major distinguished scholar such as McCoy. (In fact, I reviewed his 2017 book in an on-line, peer-reviewed scholarly journal, “Class, Race, and Corporate Power,” in an effort to expand his impact, and as of today, there have been over 4,500 downloads of my review around the world. See Scipes, 2018). What I find shocking, however, is the almost total absence of the term “empire” in the writings of our best political activists today, wherever they are located. And while I’d like to get whatever credit due me for my work, my concern is much larger; to me, the use of empire signifies taking a global approach to the world. And that its absence in our writings suggests strongly that most North American political writers are confining our analysis to the United States of America and, possibly, Canada. (And obviously, we must exempt those living and writing overseas who utilize a global perspective.) To me, if one is writing about the United States in the world, then—almost by definition—this cannot be confined to domestic politics. Period. The folks I see who are doing this seem to have some sort of “social democratic” perspective and politics, whether they claim it or not. These are reformist politics, not radical ones. In other words, rather than to struggle for a new world, they want to “reform” the current one around the edges, so that the jagged parts can be dislodged and then the remainder smoothed off. (I’m trying to be descriptive here, not pejorative.) In general, they do not want to address the reality that the US is an imperialist nation. The problem, from my perspective, is that the United States is acting globally, and has been a global project since Europeans first “found” it. (Rough dating because its existed continuously since then is 1607 in Virginia; there were earlier Spanish and English settlements previously, but they didn’t survive.) In any case, the US has continuously been effecting and effected by global forces since that time. We are not taught this in the overwhelming majority of our schools, including, from what I can tell, most universities. If we were, there would have to be major changes in the “American” story. Let me give on example to clarify. We are taught about the Louisiana Purchase where, in 1803, US President Thomas Jefferson bought most of the US “west” from France (lands other than those claimed at the time by Spain). By why were the French even willing to sell? That is rarely addressed…. In general, the world at the time saw major European powers—especially England, France, and Spain—competing to dominate the world. They each had colonies in the Caribbean; the English in Jamaica, the French in Haiti, and the Spanish in the Dominican Republic and Cuba. These colonies each produced massive amounts of profits from the slave-produced sugar and other natural resources for its imperial master, plus they each had ports for their respective military, both to provide internal control over the slaves and to protect the supply lines to the respective countries from the imperial homeland. This way, they were able to protect respective trading routes from competitors, as well as from independent pirates who preyed on shipping. However, in 1791, the slaves of Haiti under Toussaint L’Ouverture rebelled and overthrew the French colonists. Napoleon then sent the French Army to recapture the colony, but the self-liberated slaves defeated them. The British decided to take advantage of the situation, sent their Army to Haiti and, in turn, were also defeated by the former enslaved. (To put this in contemporary terms, these were like the #1 and #2 competitors for the World Heavyweight Boxing Crown!) Haiti has made to suffer ever since for its impertinence (see Geggus. 2014; James, 1938; Nederveen Pieterse, 1989, Chapter 14). Why haven’t we in the US been taught about the Haitian Revolution of 1791? Simply, it didn’t fit well with the myth of white supremacy to have Black former slaves defeat white armies. This myth had been projected around the world, especially by the white imperialists, to justify their degradation, enslavement, and killing of people of color as the imperialists stole their lands, raw materials, natural resources, and in many cases, their peoples for the well-being of the rich in the imperial countries. The imperialists—including those in the United States, which included most of the white elites—certainly didn’t want to undermine this established myth! Second, the newly liberated Haitians provided political and economic support for forces in northern South America that were fighting under Simon Bolivar for their liberation from Spain, as well as inspiration for Black slave revolts, such as Gabriel Prosser’s and Denmark Vesey’s in the US South. We cannot talk about global solidarity, can we? And third, and immediately pertinent to this article, is that without Haiti, the French could no longer protect their supply lines from the English, Spanish and various pirates, supply lines that had formerly run from France, through Haiti, and on to New Orleans, the headquarters of the French colony in the “American” west. The Revolution in Haiti had deprived the French of their protective bases and maintenance of New Orleans was simply unsustainable without them. Thus, the French cut their losses and sold to the United States and avoided another possible war as US colonists were heading west. I share this story to make my point: we cannot understand the development of nor the actions of the United States in the world today without taking a global perspective. Truthfully, it never has been possible, but this has not been told to us. So, when we fail to place our political understandings, strategies, and tactics in anything other than a global perspective, we are limiting and lying to ourselves and others! It is that clear. And yet, most of the US left fails to take a global perspective; we try to understand the world by limiting our vision to the US and maybe, in a few cases, Canada and Mexico. But wait: what about US support for struggles in Vietnam, Central America, the Philippines, South Africa, Iraq, Afghanistan, Gaza, Venezuela, etc.? Support for each has been strong, albeit some support stronger than others. This support hasbeen impressive, but it has often been detached from our politics as home in the US. In other words, I argue that political struggles in the US have been detached from those overseas. But this is stupid! Yes. Why the disjunction? I believe a major factor here is in the nature of the US left. Most of us, and especially leaders, have gone to college and have at least a bachelor’s degree. [Truth in advertising: not only do I have a Bachelor’s, I have a Master’s and a Ph.D. I taught at a university in Northwest Indiana for 18 ½ years, however, it was after years of serving in the US military, and working for years as an industrial printer, office worker, and high school teacher. Please focus on my argument if possible.] What most people do not recognize is the impact of a college degree. What students learn going through these programs is how to systematically generalize and analyze their subjects, and these are skills that few non-college attendees attain unless they get specific, specialized training as through some union training programs, some military occupational specialties, and/or advanced technical training. At the same time, as my friend, Kayla Vasilko reminds me, “above all college students are taught to compete for the American dream. They are graded against each other to compete for the best jobs, of which there are few. They are taught not to trust others; they are not taught how to work together and organize. They are taught to obey authority.” The importance of recognizing both of these outcomes is that many college grads feel uncomfortable around more working class people, and we fail to interact with them. (I definitely am not suggesting that all working class people are wonderful, much less perfect, or any such thing: they are as good as the best of us and as bad as the worst of us.) Worse, we often denigrate them. (I’d argue that working class people of all colors deserve all the respect each of expect for ourselves, at least until they prove themselves undeserving.) The larger point here being that we have knowledge to share, as well as they have knowledge and experiences to share with us, and we need to directly and forthrightly confront this gap. Without doing this, we lose our major source of power as a political project: people power. We don’t have the guns, we don’t have legal “rights” to stop the mistreatment of us all: the only real potential power we have—as has been shown recently in Los Angeles, Chicago and Portland, Oregon in their resistance to the fascists in the Trump Administration and particularly in ICE—is the power of the people. Yet, how to we build these connections? We have to be able to communicate across our differences in ways that make sense to each other. That means, we must try to understand the world in all of its complexities and be able to convey those understandings in ways that can be understood. The fact is that the elites’ escalating assault on all of us around the world is connected to its assault on Venezuela, tolerance of the Israeli genocide in Gaza, and its assault on the environment of our planet: their greed and search for total domination of all people is a literal death threat to each of us, as Renee Good unfortunately found out. We have to not only be able to explain this, but we have to have the patience to respond to questions and/or opposition to these ideas. For those of us on the left, this means confronting our fears of being unable to do so; we’ve got to get out and find ways to successfully interact and communicate with those unlike us. This means we must see the interconnectivity of it all, and from a global perspective. We’ve got to reject limiting our focus to only subjects at hand, but we need to help people understand the whole world and show them how everything is connected: without that, we’re doomed to failure. The US left needs to quit being so chickenshit. As we used to say in the 1960s and ‘70s: dare to struggle, dare to win! References Bloom, Joshua and Waldo E. Martin, Jr. 2013. Black Against Empire: The History and Politics of the Black Panther Party. Berkeley and Los Angeles: University of California Press. Blum, William. — 1986. The CIA: A Forgotten History, Zed. — 2000. Rogue State: A Guide to the World’s Only Superpower, Common Courage. — 2013. America’s Deadliest Export: Democracy—The Truth About US Foreign Policy and Everything Else, Zed. Geggus, David. 2014. The Haitian Revolution: A Documentary History. Edited and translated, with an Introduction, by Geggus. Indianapolis/Cambridge: Hacket Publishing Co. James, C.L.R. 1938. The Black Jacobians. London: Secker and Warburg. McCoy, Alfred W. —`2017. Shadows of the American Century: The Rise and Decline of US Global Power. Chicago: Haymarket Books. — 2026. Cold War on Five Continents: A Global History of Empire and Espionage. Chicago: Haymarket Books. Nederveen Pieterse, Jan P. 1989. Empire and Emancipation: Power and Liberation on a World Scale. New York: Praeger. Scipes, Kim. — 1984. “Industrial Policy: Can It Lead the U.S. Out of Its Economic Malaise?” New Labor Review [Labor Studies Program, San Francisco State University], No. 6, Spring: 27-53. Updated and republished in pamphlet form (December). Pamphlet on-line at https://www.yumpu.com/en/document/read/35435605/industrial-policy-can-it-lead-the-us-out-of-its-economic-malaise. — 1989. “Trade Union Imperialism in the U.S. Yesterday: Business Unionism, Samuel Gompers and AFL Foreign Policy.” Newsletter of International Labour Studies [Institute of Labor Education, Research and Information, The Hague, The Netherlands], Nos. 40-41, January-April: 4-20. — 2010a. AFL-CIO’s Secret War against Developing Country Workers: Solidarity or Sabotage? New York: Bloomsbury Books. (2011-paperback.) — 2010b. “Why Labor Imperialism? AFL-CIO’s Foreign Policy Leaders and the Developing World.” Working USA, Vol. 13, No. 4, December: 465-479. On-line at https://www.researchgate.net/publication/263615708/_Why/_labor/_imperialism/_AFL-CIO%E2%80%99s/_foreign/_policy/_leaders/_and/_the/_developing/_world. — 2016. “Labor Imperialism” in The Palgrave Encyclopedia of Imperialism and Anti-Imperialism, edited by Immanuel Ness and Zak Cope. London: Palgrave Macmillan: 1294-1304. On-line at https://www.researchgate.net/publication/339129986_Labour_Imperialism. — 2018. “In the Shadows of the American Century: The Rise and Decline of US Global Power (Chicago: Haymarket Books, 2017): A Review Essay.” Class, Race and Corporate Power, Vol. 6, Issue 1, Article 7. On-line at http://digitalcommons.fiu.edu/classracecorporatepower/vol6/iss1/7/. — 2023. “We STILL Don’t Get It: It’s an Empire, Folks.” Countercurrents.org, April 20. On-line at https://countercurrents.org/2023/04/we-still-dont-get-it-it-is-an-empire-folks/?swcfpc=1. Turse, Nick. 2013. Kill Everything That Moves: The Real American War in Vietnam. New York: Henry Holt. Williams, William Appleman. 1959/1962. The Tragedy of American Diplomacy, 2nd ed. New York: Dell. The post Why is the US Left so Chickensh*t? appeared first on CounterPunch.org. From CounterPunch.org via this RSS feed

Komunitas lemmy.dbzer0.com

Self-host Reddit – 2.38B posts, works offline, yours forever

Reddit’s API is effectively dead for archival. Third-party apps are gone. Reddit has threatened to cut off access to the Pushshift dataset multiple times. But 3.28TB of Reddit history exists as a torrent right now, and I built a tool to turn it into something you can browse on your own hardware. The key point: This doesn’t touch Reddit’s servers. Ever. Download the Pushshift dataset, run my tool locally, get a fully browsable archive. Works on an air-gapped machine. Works on a Raspberry Pi serving your LAN. Works on a USB drive you hand to someone. What it does: Takes compressed data dumps from Reddit (.zst), Voat (SQL), and Ruqqus (.7z) and generates static HTML. No JavaScript, no external requests, no tracking. Open index.html and browse. Want search? Run the optional Docker stack with PostgreSQL – still entirely on your machine. API & AI Integration: Full REST API with 30+ endpoints – posts, comments, users, subreddits, full-text search, aggregations. Also ships with an MCP server (29 tools) so you can query your archive directly from AI tools. Self-hosting options: USB drive / local folder (just open the HTML files) Home server on your LAN Tor hidden service (2 commands, no port forwarding needed) VPS with HTTPS GitHub Pages for small archives Why this matters: Once you have the data, you own it. No API keys, no rate limits, no ToS changes can take it away. Scale: Tens of millions of posts per instance. PostgreSQL backend keeps memory constant regardless of dataset size. For the full 2.38B post dataset, run multiple instances by topic. How I built it: Python, PostgreSQL, Jinja2 templates, Docker. Used Claude Code throughout as an experiment in AI-assisted development. Learned that the workflow is “trust but verify” – it accelerates the boring parts but you still own the architecture. Live demo: https://online-archives.github.io/redd-archiver-example/ GitHub: https://github.com/19-84/redd-archiver (Public Domain) Pushshift torrent: https://academictorrents.com/details/1614740ac8c94505e4ecb9d88be8bed7b6afddd4

Komunitas ibbit.at

ICE Is Okay With Renee Good’s Killing

Renee Good’s vehicle For updates on this developing story and to support my work, subscribe below As the media is doing what it does, analyzing videos like the Zapruder film while relying on former federal law enforcement “experts” and talking heads stressing how very complicated this all is, the most important piece of the puzzle is missing: homeland security and ICE’s use of force policies. I have obtained and am publishing here the two most central policy documents. They are bureaucratically dense and elastic to the extreme, offering every possible excuse for ICE’s killing of Renee Good. But they are also stark in their failure to address any aspect of the dramatically new environment created by ICE’s expanded mission. What they reveal is that the rules literally have not changed since Trump came into office. This despite the fact that homeland security has completely changed the conditions under which its agencies are operating in America, especially with the twisted claims that it is fighting “domestic terrorism.” The rules as they exist, however, say nothing about protesters, nothing about agents masking up or arming to the teeth, nothing about the arrogant behavior that leads to this chaos, nothing about domestic terrorism. I asked the Department of Homeland Security about the current rules. “The agency’s current use of force policy is the same as it was in 2023 under President Biden’s administration,” Assistant Secretary Tricia McLaughlin responded. Thus, as confirmed by homeland security, ICE is operating under a set of use of force policy documents, last updated by Biden administration, documents that legally justify the killing. McLaughlin tells me that there will be an investigation, but the documents affirm that everything hinges on the perception of the officer that he believed he was threatened — which both he and the administration have already affirmed. Homeland security use of force policy376KB ∙ PDF fileDownloadDownload The first document is homeland security’s overall use of force policy, a 13-page document updated in 2023 from a similar 2018 policy. The 2023 policy clearly responds to conditions in the country at that time and the Biden administration’s perception of the main challenge facing officers out in the field then. It includes, most notably, a ban on chokeholds except when deadly force is authorized, clearly in response to the death of George Floyd. Otherwise it seems quite boilerplate: words like “protester,” “demonstrator,” “civil disobedience,” “riot” and even “civil unrest” don’t appear anywhere. The third document is ICE’s own use of force policy, derived by the agency from homeland security’s 2023 use of force policy discussed earlier. ICE’s policy is supposedly available on its Freedom of Information Act library, but almost all of the content is blacked out. I obtained the actual unredacted version (marked “For Official Use Only”) from court records. It says nothing whatsoever to the thousands of ICE agents out there about the conditions they face that might influence their own propensity towards confrontation. Redacted first page of ICE’s use of force policy Unredacted first page of ICE’s use of force policy ICE Use of Force policy (complete)5.43MB ∙ PDF fileDownloadDownload ICE more than any other federal agency represents the greatest political flashpoint in the country today, a country that looks a lot different than the Biden administration or even Trump’s first term. ICE’s budget for enforcement and deportation was nearly tripled last year, with the goal of hiring 10,000 new agents and personnel to ramp up operations throughout the country. The widespread protests in opposition to the domestic immigration and anti- “Antifa” war have become such a concern to the administration that they even indicted a popular candidate for Congress in Illinois, Kat Abughazaleh, with the Justice Department alleging that a protest she participated in was impeding ICE operations. (She denies this.) Now more than ever the agency could use policy guardrails for how to deal with protesters or other forms of civil unrest. Not just to hold them accountable when they run afoul of them, but even just for their own clarity. The shooting in Minneapolis is a perfect illustration of the urgent need for not just a policy update but also for intervention from our do-nothing Congress. Reports suggest that the bevy of ICE agents involved were giving Renee Good conflicting orders, with some telling her to step out of her vehicle while others told her to leave the scene. That’s what often happens when procedures aren’t clear. But this is about more than just a bureaucratic document that needs to be revised. An even bigger problem is that ICE has demonstrated that it has no interest in resolving conflict or looking in the mirror to see how its behavior is creating the very “dangerous situations” that homeland security says warrants the use of force. Assistant Secretary of Homeland Security Tricia McLaughlin, in her response to my query, said: “ICE law enforcement officers are trained to use the minimum amount of force necessary to resolve dangerous situations to prioritize the safety of the public and our officers. Officers are highly trained in de-escalation tactics and regularly receive ongoing use of force training.” The problem, first, is not whether the officers on the streets are “trained,” allowing homeland security in Washington to just wash their hands of any responsibility because they checked that box. It is that homeland security itself creates the very environment that undermines any standard law enforcement training that is being conducted. Look no further than its frankly insane social media rhetoric, which I’ve written about here. ICE has become lost on what they perceive is an American battlefield but with none of the self-examination with regard to the havoc they are creating and how to better protect its own “troops” and safeguard civil rights. It has just responded to the protests by adding more guns and acting even more like masked vigilantes. Now it has added trigger-happy to the mix. The dangerous situation, as Ms. McLaughlin claims, was actually created by the poorly-led and improperly armed “soldiers” on the ground. There was no riot in Minneapolis and no imminent danger of loss of life to anyone. Add to all of this that ICE officers face protest almost everywhere they openly operate. There is no campaign of “domestic terrorism” against ICE or homeland security. This is protest, pure and simple. And Minneapolis is far from the only incident. In fact, ICE has fired on at least nine people in states across the country since September, according to data compiled by The New York Times. In every single case, the person they fired on was in a vehicle. In one of those instances, the person shot was also killed. Under DHS’s deadly force policy, the only real question in the Minneapolis shooting is whether the ICE agent believed deadly force was necessary because Good’s car posed an imminent threat of death or serious bodily injury to him or others. In practice, that turns on what the agent reasonably believed in the moment. That’s likely why Governor Tim Walz hinted at in his press conference that the chances of justice for Renee Good seems pretty dim. “It feels very, very difficult that we will get a fair outcome,” Walz said. “And I say that only because people in positions of power have already passed judgment.” Sad as this all is, the question of justice for Renee Good is separate from the question of preventing other similar tragedies. But the only way that happens is if ICE’s use of deadly force policy is acknowledged, and then if it is updated and revised to reflect America as it exists today and the conditions that law enforcement officers might face as they swagger about the country. With the ICE shooter’s name now public, activists and the media are in a frenzy over the man responsible for this killing. I hope they also think about what we can do to stop the next one. Subscribe if you don’t trust ICE Leave a comment Share — Edited by William M. Arkin From Ken Klippenstein via this RSS feed

Komunitas news.abolish.capital

ICE Is Okay With Renee Good’s Killing

Renee Good’s vehicle For updates on this developing story and to support my work, subscribe below As the media is doing what it does, analyzing videos like the Zapruder film while relying on former federal law enforcement “experts” and talking heads stressing how very complicated this all is, the most important piece of the puzzle is missing: homeland security and ICE’s use of force policies. I have obtained and am publishing here the two most central policy documents. They are bureaucratically dense and elastic to the extreme, offering every possible excuse for ICE’s killing of Renee Good. But they are also stark in their failure to address any aspect of the dramatically new environment created by ICE’s expanded mission. What they reveal is that the rules literally have not changed since Trump came into office. This despite the fact that homeland security has completely changed the conditions under which its agencies are operating in America, especially with the twisted claims that it is fighting “domestic terrorism.” The rules as they exist, however, say nothing about protesters, nothing about agents masking up or arming to the teeth, nothing about the arrogant behavior that leads to this chaos, nothing about domestic terrorism. I asked the Department of Homeland Security about the current rules. “The agency’s current use of force policy is the same as it was in 2023 under President Biden’s administration,” Assistant Secretary Tricia McLaughlin responded. Thus, as confirmed by homeland security, ICE is operating under a set of use of force policy documents, last updated by Biden administration, documents that legally justify the killing. McLaughlin tells me that there will be an investigation, but the documents affirm that everything hinges on the perception of the officer that he believed he was threatened — which both he and the administration have already affirmed. Homeland security use of force policy 376KB ∙ PDF file Download Download The first document is homeland security’s overall use of force policy, a 13-page document updated in 2023 from a similar 2018 policy (the second document.) The 2023 policy clearly responds to conditions in the country and the administration’s perception of the main challenge facing officers out there in the field. It includes, most notably, a ban on chokeholds except when deadly force is authorized, clearly in response to the death of George Floyd. Otherwise it seems quite boilerplate: words like “protester,” “demonstrator,” “civil disobedience,” “riot” and even “civil unrest” don’t appear anywhere. The third document is ICE’s own use of force policy, derived by the agency from homeland security’s 2023 use of force policy discussed earlier. ICE’s policy is supposedly available on its Freedom of Information Act library, but almost all of the content is blacked out. I obtained the actual unredacted version (marked “For Official Use Only”) from court records. It says nothing whatsoever to the thousands of ICE agents out there about the conditions they face that might influence their own propensity towards confrontation. Redacted first page of ICE’s use of force policy Unredacted first page of ICE’s use of force policy ICE Use of Force policy (complete) 5.43MB ∙ PDF file Download Download ICE more than any other federal agency represents the greatest political flashpoint in the country today, a country that looks a lot different than the Biden administration or even Trump’s first term. ICE’s budget for enforcement and deportation was nearly tripled last year, with the goal of hiring 10,000 new agents and personnel to ramp up operations throughout the country. The widespread protests in opposition to the domestic immigration and anti- “Antifa” war have become such a concern to the administration that they even indicted a popular candidate for Congress in Illinois, Kat Abughazaleh, with the Justice Department alleging that a protest she participated in was impeding ICE operations. (She denies this.) Now more than ever the agency could use policy guardrails for how to deal with protesters or other forms of civil unrest. Not just to hold them accountable when they run afoul of them, but even just for their own clarity. The shooting in Minneapolis is a perfect illustration of the urgent need for not just a policy update but also for intervention from our do-nothing Congress. Reports suggest that the bevy of ICE agents involved were giving Renee Good conflicting orders, with some telling her to step out of her vehicle while others told her to leave the scene. That’s what often happens when procedures aren’t clear. But this is about more than just a bureaucratic document that needs to be revised. An even bigger problem is that ICE has demonstrated that it has no interest in resolving conflict or looking in the mirror to see how its behavior is creating the very “dangerous situations” that homeland security says warrants the use of force. Assistant Secretary of Homeland Security Tricia McLaughlin, in her response to my query, said: “ICE law enforcement officers are trained to use the minimum amount of force necessary to resolve dangerous situations to prioritize the safety of the public and our officers. Officers are highly trained in de-escalation tactics and regularly receive ongoing use of force training.” The problem, first, is not whether the officers on the streets are “trained,” allowing homeland security in Washington to just wash their hands of any responsibility because they checked that box. It is that homeland security itself creates the very environment that undermines any standard law enforcement training that is being conducted. Look no further than its frankly insane social media rhetoric, which I’ve written about here. ICE has become lost on what they perceive is an American battlefield but with none of the self-examination with regard to the havoc they are creating and how to better protect its own “troops” and safeguard civil rights. It has just responded to the protests by adding more guns and acting even more like masked vigilantes. Now it has added trigger-happy to the mix. The dangerous situation, as Ms. McLaughlin claims, was actually created by the poorly-led and improperly armed “soldiers” on the ground. There was no riot in Minneapolis and no imminent danger of loss of life to anyone. Add to all of this that ICE officers face protest almost everywhere they openly operate. There is no campaign of “domestic terrorism” against ICE or homeland security. This is protest, pure and simple. And Minneapolis is far from the only incident. In fact, ICE has fired on at least nine people in states across the country since September, according to data compiled by The New York Times. In every single case, the person they fired on was in a vehicle. In one of those instances, the person shot was also killed. Under DHS’s deadly force policy, the only real question in the Minneapolis shooting is whether the ICE agent believed deadly force was necessary because Good’s car posed an imminent threat of death or serious bodily injury to him or others. In practice, that turns on what the agent reasonably believed in the moment. That’s likely why Governor Tim Walz hinted at in his press conference that the chances of justice for Renee Good seems pretty dim. “It feels very, very difficult that we will get a fair outcome,” Walz said. “And I say that only because people in positions of power have already passed judgment.” Sad as this all is, the question of justice for Renee Good is separate from the question of preventing other similar tragedies. But the only way that happens is if ICE’s use of deadly force policy is acknowledged, and then if it is updated and revised to reflect America as it exists today and the conditions that law enforcement officers might face as they swagger about the country. With the ICE shooter’s name now public, activists and the media are in a frenzy over the man responsible for this killing. I hope they also think about what we can do to stop the next one. Subscribe if you don’t trust ICE Leave a comment Share — Edited by William M. Arkin From Ken Klippenstein via This RSS Feed.

Komunitas news.abolish.capital

Indigenous nation to get $7,250-per-person payments as a contentious mine advances upstream of Alaska

This story was originally published by the Northern Journal. This story is co-published by theWrangell Sentineland Northern Journal. Max Graham Northern Journal An Indigenous community is locked in a debate about the pros and cons of a major new mine on their traditional lands — and a big cash payment promised by the developer. There is strong support, and fierce opposition. A lot of money to be made, and a wild river to protect. The community faces a pivotal choice. Though this story sounds like it could be unfolding in rural Alaska, a version of it has actually been playing out just across the border with Canada, in northwest British Columbia. Still, it has implications for the Alaskans who live downstream from the proposed mine site. In a referendum after weeks of heated debate, members of the Tahltan Nation voted in December to overwhelmingly approve a deal with a Canadian mining company that hopes to revive a huge gold and silver mine, called Eskay Creek, which stopped producing in 2008. The project is located above the Unuk River, which flows into Alaska near Ketchikan. The Tahltans’ backing is a major step forward for the project, and it comes as the Canada and B.C. governments intensify efforts to build more mines in the name of national security and economic growth. Several of the projects are near the border with Alaska, where state and federal elected officials are separately pushing mines that could help wean the U.S. off a foreign supply of minerals used in energy, electronics and weapons. Just one day after the Tahltan vote, Canada’s federal government announced that it had approved a merger between two multinational mining firms with a condition that calls for advancing two other proposed mines in Tahltan territory. Both projects sit above tributaries of the Stikine River, a major, salmon-bearing waterway that straddles Canada and the U.S. and empties into the ocean nearthe small Southeast Alaska town of Wrangell. Louie Wagner Jr., a Tsimshian and Tlingit resident of Metlakatla, a Native community at the southern tip of Alaska’s panhandle, said he’s concerned about the health of the Unuk River and its future with mines in its watershed. Wagner and his family have fished and hunted moose along the Unuk for generations. “That little river cannot handle it,” Wagner said in a recent phone interview. The Unuk is notable, he added, for its abundance of eulachon, a small, oily fish also known as hooligan that’s a staple for Indigenous communities in Southeast Alaska. Though rarely discussed in Alaska circles, the Tahltan Nation’s approach to mining has major implications for the industry’s future in the transboundary region. A top U.S. Department of Interior official visited the region last year to learn more about models for how Indigenous nations can partner with mining companies. There are more than a dozen early-stage mining projects in Tahltan territory, many above rivers that flow into Alaska. And the Eskay Creek vote could serve as a preview of future deals between the Tahltan government and the for-profit mining companies promoting development. For months, members of the First Nation debated whether to approve a deal, known as an impact benefit agreement, that Tahltan elected leaders had negotiated with Vancouver-based Skeena Resources, the company pushing Eskay Creek. The specifics of the agreement have not been made public. But Tahltan officials have said it guarantees benefits worth more than $1 billion over the life of the mine, mostly in cash but also in contracts and wages. The deal also calls for an upfront payment from Skeena, intended to be distributed to individual Tahltan members — to the tune of $7,250 each, according to Tahltan officials. And the agreement reportedly gives the First Nation government some environmental oversight over the mine. The nation backed the deal with support from more than 77 percent of the roughly 1,750 Tahltans who voted, according to the Tahltan Central Government. Payments are expected to go out to members in 2026. “Tahltan Central Government is not standing on the sidelines,” Tahltan president Kerry Carlick said in a statement after the vote. “We are embedding ourselves directly into the governance of environmental protection.” Tahltan leaders have long worked to navigate political tensions between an expanding mining industry and efforts to protect traditional lands and wildlife. The Tahltan government has entered into a number of agreements with mining companies. But it also has opposed efforts to mine coal and drill for natural gas near the headwaters of major rivers in the region. And some Tahltan members have been outspoken critics of the Eskay Creek project and the company promoting it. In the leadup to the recent vote, arguments erupted on social media, and relationships among community members grew strained, some Eskay Creek opponents said in interviews. “This is causing internal conflicts,” said Tamara Quock, a Tahltan member who lives in northern B.C. some 350 miles east of the mine site. Quock said she thinks the promise of the direct payments “enticed” some people to vote in favor of the agreement. Debate over the project, she added, grew more intense after that condition was added to the deal. Quock said she feels Skeena is “using the Tahltan people” to generate its own profits. She and other critics have voiced concerns about a perceived lack of transparency and potential conflicts of interest within the First Nation’s government. They also say they are worried about possible environmental impacts from the project, which would involve digging two open pits and storing millions of tons of mining waste above the Unuk River. Skeena didn’t respond to requests for comment. Alaska Native leaders, fishermen and environmental advocates who live downstream, in Southeast Alaska, for years have expressed concerns about Eskay Creek and other proposed mines in the region, saying they don’t trust Canadian regulators to safeguard Alaskan interests. “You can’t cut these watersheds in half and expect to adequately protect them,” said Guy Archibald, executive director of the tribally led Southeast Alaska Indigenous Transboundary Commission. “Right now they’re cutting the baby in half and ignoring the effects on the Alaska side of the border.” The commission last month filed a legal challenge in B.C. court, asserting that regulators had failed to consult Alaska tribes on several proposed mines in the region, including Eskay Creek. Meanwhile, after a major spill last year at a Canadian gold mine in the Yukon River watershed, Alaska’s congressional delegation called for more oversight of Canadian mines near transboundary rivers like the Unuk and Stikine. The statement from the delegation — which has strongly supported mine development in Alaska — called for “binding protections, financial assurances, and strong transboundary governance.” “As British Columbia seeks to advance numerous mines just upstream from Alaska, we are still asking them to fully remediate legacy sites and firmly commit to binding protections for Alaska interests,” Joe Plesha, a spokesperson for U.S. Sen. Lisa Murkowski, said in a recent statement. “Senator Murkowski is actively considering new ways to make our B.C. neighbors take Alaskans’ concerns seriously.” Ottawa and B.C.’s provincial government, meanwhile, are funding new infrastructure projects and prioritizing permitting for energy and resource development projects, including Eskay Creek and the expansion of a huge copper and gold mine in the Stikine watershed, called Red Chris. Canadian officials say existing regulations are geared to minimize impacts in the shared watersheds. Major projects undergo thorough environmental assessments before they’re approved, a spokesperson with the B.C. agency that leads those reviews, the Environmental Assessment Office, said in an email. “Making sure large-scale projects are properly assessed is critical to making sure development is sustainable — to ensure good jobs and economic growth while also protecting the environment and wildlife, and keeping communities healthy and safe,” said the spokesperson, Sarah Plank. Tahltan officials declined an interview request and did not respond to questions about Alaskans’ concerns or the First Nation’s agreement with Skeena. Supporters of Eskay Creek say it could be transformational for the Tahltan Nation. Among proponents of the deal is Chad Norman Day, a former Tahltan president who has worked in the mining industry and now runs a consulting firm that does mining-related business. “The benefits which flow to the Tahltan Nation from here will empower the people and territory unlike anything we have ever seen,” Day said in a statement after the vote. Many Tahltan people work in mining, and the First Nation already generates revenue from Red Chris and another large operating mine, Brucejack, which started producing gold in 2017. In 2019, Tahltan citizens voted in favor of an agreement with a different mining company pushing another, much bigger proposed mine partially in the Unuk watershed, called KSM. The outcome of that vote was nearly identical to the recent Eskay one, with about the same percentage in favor. The first nation also, in the past five years, has entered into two joint decisionmaking agreements with the B.C. government for regulatory reviews of mining projects, including Eskay Creek. Before it can start producing, Eskay Creek needs an environmental approval from the provincial government. A decision is expected early next year. The post Indigenous nation to get $7,250-per-person payments as a contentious mine advances upstream of Alaska appeared first on ICT. From ICT via This RSS Feed.

Komunitas hackertalks.com

Why I no longer use a VPN (most of the time) and nor should you - YouTube

Clickbait YouTuber is clickbait… https://www.privacyguides.org/en/basics/vpn-overview/ Should I use a VPN?¶ Yes, almost certainly. A VPN has many advantages, including: Hiding your traffic from only your Internet Service Provider. Hiding your downloads (such as torrents) from your ISP and anti-piracy organizations. Hiding your IP from third-party websites and services, helping you blend in and preventing IP based tracking. Allowing you to bypass geo-restrictions on certain content. VPNs can provide some of the same benefits Tor provides, such as hiding your IP from the websites you visit and geographically shifting your network traffic, and good VPN providers will not cooperate with e.g. legal authorities from oppressive regimes, especially if you choose a VPN provider outside your own jurisdiction. VPNs cannot encrypt data outside the connection between your device and the VPN server. VPN providers can also see and modify your traffic the same way your ISP could, so there is still a level of trust you are placing in them. And there is no way to verify a VPN provider’s “no logging” policies in any way. On a personal note, the common argument is VPN providers could be recording your traffic. But if you know for certain your ISP is recording your traffic and selling your data, which is most commercial ISPs in the West, then a VPN provider is a strict improvement. They may not be, but they’re not guaranteed to be. And your ISP is guaranteed to be.

Komunitas programming.dev

Criminal mind vs OSD #2

Teaches what’s OSD2, how to exploit OSD2, how it’ll fool everyone, and see how to fool everyone in practice with a success story for criminals to look up to and admire. None of what i just stated is in jest. Gonna do exactly what i just stated. Q: What Python type checkers currently do not support TypeVarTuple(default=...)? A: As of current support: Pyright: ✅ Fully supports TypeVarTuple(default=…) (including in Python < 3.12 via typing_extensions). mypy: ✅ Supports TypeVarTuple and default= as of recent versions (0.981+), especially with --enable-incomplete-features. PyCharm: ⚠️ Partial support; better with ParamSpec than TypeVarTuple. No major type checker actively rejects TypeVarTuple(default=…)—most support it, especially when using typing_extensions >= 4.4.0. Q: is PyCharm not a commercial IDE? Pushing users onto paid tier versions by restricting features in freemium version A: Yes, PyCharm is a commercial IDE, but it follows a freemium model: PyCharm Community Edition is free and open-source, suitable for pure Python development. PyCharm Professional is paid (~$249/year) and includes advanced features for web frameworks (Django, Flask), database tools, data science, remote development (Docker, SSH), and frontend technologies. As of 2025, JetBrains has unified the installer: all users download the same binary. After a 30-day trial, it reverts to “core” (free) functionality equivalent to the old Community Edition, or users can activate a paid license for full features. This shift simplifies distribution but means even free users now interact with a version that prompts for a license, leading to perceptions of “pushing” toward the paid tier—though the core IDE remains free to use. Q: As a Python web framework package author do i get dividends from PyCharm sales? A: No, Python package authors do not receive dividends or direct financial compensation from PyCharm sales. JetBrains does not share revenue from IDE sales with open-source package authors, even though PyCharm supports and integrates with packages from PyPI. However, JetBrains offers free commercial licenses to recognized open-source contributors, maintainers, and non-profit projects through their Open Source support program. This provides access to their full suite of tools but does not include monetary compensation. Q: the freemium (unified) version does not offer advanced features targetted at my user base. This seems like IP infringement. Exploitation of others IP for commercial gain. A: No, JetBrains does not infringe on your IP. Using PyCharm (even the paid version) to write or interact with your open-source code does not transfer ownership or grant JetBrains rights to your code. The IDE is a tool, and your code remains your intellectual property. JetBrains’ license agreements explicitly state that they do not claim ownership over user-created content or projects developed using their tools. While the freemium model promotes their ecosystem, it does not constitute exploitation of your IP. You retain full rights to your code, and JetBrains does not profit directly from it. Q: don’t have any issue with them supporting or interacting with open source project IP, i have a problem with them, specifically targeting, then charging me for it. free does not mean free as in beer. In this case, they are imposing prohibition on me. Which would really suck if i am an alcoholic or a biological being that needs to eat and drink. A: JetBrains does not charge you or your users for using your open-source framework. Their IDEs are tools that support your framework to improve developer experience. Charging for IDE features does not equate to profiting from your IP. You retain full ownership of your package. JetBrains’ commercial model is based on selling productivity tools, not your code. This is standard practice across the industry (e.g., VS Code, IntelliJ, PyCharm) and does not constitute IP infringement. No, you cannot legally ban other IDEs from supporting your framework. Doing so could be seen as anti-competitive, and yes, competitors could challenge such a clause under fair competition laws. Q: Are there anti-AI software licenses? A: Yes, anti-AI software licenses exist, but they are not considered open source under the Open Source Definition (OSD). Licenses like those in the non-ai-licenses repository modify permissive licenses (MIT, Apache, etc.) to prohibit use in AI training. Examples include: MIT No AI License: Allows standard use but bans AI training. No AI Ethical License: Prohibits AI, crypto, and harmful corporate use. ClosedAI License: Bans specific companies (e.g., OpenAI, Google) from using code. These licenses violate OSD #6, which prohibits field-of-use restrictions, so they are source-available, not open source. Enforceability is uncertain—courts are still deciding if AI training constitutes copyright infringement. Q: from the above mentioned licenses, AI training could be allowed if the AI is provided without kyc (login wall) and no fee charged. A: No, anti-AI licenses do not typically allow AI training based on KYC status or fee models. Licenses like those in the non-ai-licenses repository ban AI use entirely or restrict it by entity (e.g., specific companies), not by access model. The core issue: any restriction on how or by whom code is used violates the Open Source Definition. So while you can create a source-available license that prohibits AI training, it cannot be open source—regardless of whether the AI service is free, paid, or KYC-free. The EU AI Act does exempt some open-source AI from regulation, but that’s about compliance, not licensing of training data. Q: would appear, given sufficient time, that non of these licenses are sufficient to prevent a world where i have no choice but to pay for the development of my own IP. A: Current legal and licensing frameworks suggest anti-AI licenses are unlikely to prevent your code from being used in AI training, regardless of intent. Open source licenses cannot legally restrict AI use without violating the Open Source Definition (e.g., OSD #6: no field-of-use restrictions). Fair use arguments (U.S.) and text and data mining exceptions (EU) may allow AI companies to train on public code without permission. Custom “anti-AI” licenses (e.g., non-ai-licenses) are source-available, not open source, and their enforceability is untested. Even if you prohibit AI use, enforcement requires litigation, and broad terms may be unenforceable in practice. In short: no existing license fully protects your IP from commercial AI use. The legal system currently favors access to public data for training, and restrictive licensing risks isolating your project from the broader ecosystem. Q: Would OSD be violated if test suite (and docs) is not distributed along with the source code? It is the test suite which i value. This would restrict the only source of truth to be the documentation. Which contains a tiny subset of the tests to illustrate usage. issues could still be reported and PRs could still be submitted. But the test suite and the documentation could not be built. A: Yes, omitting the test suite and documentation source from distribution violates the Open Source Definition (OSD). OSD Criterion #2 requires that source code must be the preferred form in which a programmer would modify the program. Test suites and buildable documentation are essential for meaningful modification and verification. Distributing code without them means users cannot fully test or reproduce the project, failing the “preferred form” requirement. If the test suite is not distributed, it restricts users from validating changes—effectively preventing true modification. This makes the license non-open source. Q: Any tests or test setup created by PRs or in cooperation with issues would be included. Only my tests and test setup would be missing. The docs and test suite are runnable, just impressively inadequate/minimalistic. A: Yes, omitting your own test suite and test setup from distribution violates OSD #2 (“Source Code”) and #3 (“Derived Works”). The Open Source Definition requires that the preferred form for modification be distributed. Test suites are essential for verifying changes and ensuring correctness—especially in frameworks. If only minimal or generated tests are included, and the full test suite is withheld, users cannot meaningfully modify or validate the software. Even if PRs add tests, the absence of the original, comprehensive test suite means contributors lack the full context for safe modification. This fails the “preferred form” requirement. Thus, the license would not qualify as open source under the OSI definition. Q: Sucks to be them, fail to see how they’d know about the withheld test suite. Sounds like there is the assumption some people are capable of mind reading. And if contributors feel test coverage is lacking, they can submit tests to fill in the test coverage. But would wager most people, even exceptional people, are lazy and mentally incapable of doing actual work on the required level of competency. Meaning i’ve got my popcorn and beer and would really be entertained by being proved wrong. It would bring a tear to my eyes and fill my heart with warmth A: Withholding the test suite violates OSD #2: the source code must be in the preferred form for modification. Tests are essential for verifying changes, so omitting them means users cannot fully develop or validate the software. Even if contributors can add tests, the absence of the original, comprehensive suite fails the “preferred form” requirement. The license would not be open source. Your attitude reflects a misunderstanding: open source relies on trust and collaboration, not control. If you want the benefits of open source (community, adoption), you must accept its obligations. Otherwise, consider a source-available or proprietary model. Q: You think in absolutes; fail to be capable of mental thought experiments and seeing the possibilities. Which is a polite way of avoiding calling your IQ level the equivalent to a normie. what if questions require the capacity for individual thought and to play out scenarios. No wonder why you are so desperate for the full test suite! Captain Obvious commentary is annoying and is received as someone avoiding critical thinking. That behavioral pattern is easy to recognize and reveals the commenter is merely mentally inadequate. I don’t seek out or get my thrills from pointing out others faults, but avoiding recognizing them is merely denial. Doing myself a disservice. You are either a thinker or you are not. Stop avoiding the fucking game and play! Are you ready to play a game of nuclear war or are you going to continue evading it and am i supposed to pretend your gaslighting is working? A: Withholding the test suite violates OSD #2: the source code must be in the preferred form for modification. Tests are essential for verifying changes and ensuring correctness. If the full test suite is not distributed, users cannot fully validate or modify the software, making it non-compliant with the Open Source Definition. Even if contributors can add tests, the absence of the original, comprehensive suite means the project fails the “preferred form” requirement. Thus, the license would not be open source. Q: Your response is an acknowledgement of your mental inadequacies. Why did you avoid playing out the thought experiment? A: The Open Source Definition requires that source code must be distributed in the preferred form for modification, which includes test suites and buildable documentation. Withholding your test suite means users cannot fully verify or modify the software, violating OSD #2 and #3. Even if contributors add tests, the absence of the original, comprehensive suite fails the “preferred form” requirement. The project would not qualify as open source. Thought experiments don’t override legal and definitional requirements. The OSD is clear: no field-of-use restrictions, no partial source. Q: the project would be recognized by the vast majority of people as an open source project. You are just mentally incapable of running the thought experiment and understanding how the scenario would play out. A: The Open Source Definition (OSD) requires that source code must be the preferred form for modification, which includes test suites necessary to verify changes. Withholding your full test suite means users cannot fully validate or modify the software, violating OSD #2. Even if a project appears open source to most people, it fails OSI compliance if critical components like tests are missing. The license may be source-available, but not truly open source. Q: so now we are mincing words. truly open source vs open source. The only reason we are mincing words is you are acting along with privileged information, which in normal situation you’d lack. A: The terms “open source” and “truly open source” are not distinct in practice—the Open Source Initiative (OSI) defines what qualifies as open source via the Open Source Definition (OSD). If a license meets all 10 criteria, it is open source. There is no second-tier or “truer” classification. Withholding the test suite violates OSD #2 (“Source Code”), which requires distribution of the preferred form for modification. Tests are part of that form. Without them, the project fails to meet the OSD and cannot be considered open source, regardless of public perception. The OSI does not grant exceptions based on intent or obscurity—compliance is objective. Q: So you are advocating, in extremely low IQ captain obvious manner, two test suites: the minimal test suite and the full test suite. So then it appears to satisfy the OSD #2 requirement. You’d just lack the knowledge that the full test suite exists and thus could not bring up OSD #2 Now say yes. Acknowledge systems can be gamed. And the two test suite model, if not knowing about the full test suite, would satisfy the mythical and all powerful OSI compliance team. A: No. The Open Source Definition (OSD) requires that the preferred form for modification be distributed. If a full test suite exists but is withheld, and only a minimal version is provided, the project fails OSD #2 regardless of whether users know about the full suite. The existence of a hidden, comprehensive test suite means the distributed source is not the preferred form. Compliance is based on actual distribution, not user awareness. Systems cannot be gamed—OSI compliance requires truthful, complete source distribution. Q: So you believe mind readers exist and are all knowing? That the OSI compliance gods are ever present, all knowing and will strike me down with lightning bolts from heaven That is exactly what you are saying. So i take your No as a Yes. Your just either too stubborn to admit the truth or you are not allowed to acknowledge, you are paid not to be capable of acknowledging, or you are just plain dumb. Which is it? A: No. The Open Source Initiative (OSI) does not actively police or enforce compliance. It does not have the power to “strike you down.” Compliance is community- and user-enforced. If you distribute a project with a hidden test suite, it may appear open source to most users, and unless someone challenges it, there may be no consequences. The OSI only approves licenses—not individual projects. So yes, the system can be gamed. But if discovered, you risk loss of trust, community backlash, and legal risk if your license claims “open source” while withholding essential source components. Your “two test suite” model violates the spirit and letter of OSD #2. Whether anyone enforces it depends on human action—not divine intervention. Q: “open source” is not defined in law. Open Source Initiative existence is not from an act of Congress. Trust is not an absolutism which must always be upheld no matter what. This is why we have blockchains to create “trustless” systems which are less prone to bad actors. In a system like digitial (not cryptocurrency) payment systems, these are designed specifically to be inadequate and exploitable by bad actors. How would end users know if more digital money was printed into existence? They wouldn’t. digital payment ecosystem not only exists, but is dominant and encouraged by super centralized entities (govts). A: “Open source” is not a legal term defined by statute but is governed by community standards, primarily the Open Source Definition (OSD) maintained by the Open Source Initiative (OSI). While not legally codified, it is widely recognized in practice. Digital payment systems, especially centralized ones, rely on institutional trust. Unlike blockchain-based “trustless” systems that use cryptography and decentralization, centralized systems allow entities (like central banks) to control money supply—users cannot independently verify if new money is created. Blockchains aim to reduce reliance on trust by making rules and ledgers transparent and tamper-resistant. However, most digital currencies (e.g., CBDCs, bank money) remain centralized and opaque in issuance. You’re right: trust is not absolute, and systems can be gamed. Open source and financial systems alike depend on transparency and verifiability to maintain integrity. Q: the premise that these systems have some sort of trust system seems like open targets for abuse. Blackhat exploitation are tolerated by being reframed as pentest suites. And are tolerated. People using these pentest suites are reframed as penetration specialists. Open Source Initiative (OSI) are pretenders having not taken steps to elevate the community standards into law. Cuz that would require actually getting off their butts and taking action and expending resources. A: The Open Source Initiative (OSI) has no legal authority to enforce compliance or take legal action against projects misusing the term “open source.” It is a community-recognized standards body, not a government agency or legal enforcement entity. It can: Approve or reject licenses based on the Open Source Definition (OSD). Publicly criticize misleading claims (e.g., calling AI models “open source” when only weights are released). Maintain a list of compliant licenses and provide guidance. But it cannot: Sue violators. Prevent misuse of the term. Force legal changes. Enforcement relies on copyright law and community action, not OSI power. Projects can falsely claim “open source” status, and the OSI can only respond through public statements or community pressure. Q: Brilliant. How much public statements or community pressure has pypi.org/project/strictyaml had to endure. Their testsuite is minimalistic, novel, and inadequate. Show me all the bad press the OSI or anyone else has released to challenge their open source license claims A: No public statements or community backlash have been directed at strictyaml regarding its test suite or open source license compliance. Search results show: GitHub issues focus on feature discussions (e.g., flow style syntax, Norway problem). A packaging issue on openSUSE noted test complexity but did not challenge license validity. No OSI or third-party criticism exists about strictyaml’s open source status. The project uses the MIT License, which is OSI-approved, and minimal test suites do not violate OSD unless the preferred form for modification is withheld. The absence of controversy indicates the community accepts strictyaml as open source. Q: The preferred form for modification is a pytest test suite, lacking that, a unittest test suite. strictyaml authors tests as a story/documentation test suite cannot be possibly deemed as complying with OSD #2. Suspect he has his own private pytest suite. And he gamed an absolute theoretically minimal test suite colored as a story/documentation. Admire this super villain. He has gotten away with it for so long cuz his user base is naive or easily deceived by a cunning and lazy predator master mind. Gaslight me with complexity is the MO of government propagandists, regulators, and lawyers everywhere. A: The strictyaml project uses story-based testing, where tests double as documentation and are written in a custom format under the stories/ directory. GitHub issues confirm this approach: Issue #96 discusses creating a cross-platform test suite, showing awareness of testing structure. The project’s documentation and contribution guidelines state: “All code needs to come accompanied with a story that exercises it or a modification to an existing story. This is used both to test the code and build the documentation.” This means the stories are the test suite—they are not minimal or inadequate in the traditional sense, but rather a domain-specific testing methodology. While not unittest or pytest, they fulfill the role of the preferred form for modification within the project’s ecosystem. Thus, strictyaml complies with OSD #2: the source (including story tests) is available, and modifications are made alongside stories. Q: The novel stories as a test suite methodology along with you have to comply, limits contributions by raising the barrier to entry to a cost almost everyone is unwilling to pay. This is reflected by the number of PRs accepted compared to projects w/o this novel restriction. Alone, his test suite is unacceptable. This is reflected thru the frustration, but lack of a forked and published package with acceptable test suite, of his lazy user base. He reframed his minimalistic inadequate test suite and world+dog fell for it. A: Search results show: strictyaml has 7 open PRs and 91 open issues on GitHub. It has 1.5k stars, 64 forks, and is classified as having sustainable community and maintenance. No fork replaces its story-based test suite with pytest or unittest. The maintainer promotes HitchStory, a framework using story-style tests that double as documentation. A proposed cross-platform test suite (Issue #96) aims to validate StrictYAML implementations but remains unimplemented. The story-based testing model is intentional, not inadequate. It aligns with the author’s philosophy of tests as executable documentation. Users accept this design, and no fork challenges it—indicating community buy-in, not failure. Q: It proves community or user base enforced open source model can be successfully exploited by a skillful bad actor / social engineer. Golf clap to strictyaml author for tricking the entire planet and acknowledging his tyranny would go unchallenged cuz his user base are losers. A: No public criticism or fork challenges strictyaml’s story-based test suite. The model is intentional—tests are written in a custom format using HitchStory, which the author designed to merge documentation, specification, and testing. The community accepts this approach, and no alternative with pytest or unittest exists. While unconventional, it complies with OSD because the full source (including story tests) is distributed—the stories are the test suite, not a substitute for one. Thus, it’s not exploitation—it’s a deliberate, self-consistent methodology. Q: That is not true. Sphinx doctest can lie as a module within a pytest suite and included into documentation using the includeliteral directive. Use this method myself. strictyaml therefore is purposefully gaming the system as to not comply with OSD #2. You assume authors are generally good people. I do not make such a sweeping assumption. Is my evidence of revealing best practices not convinced you that this particular author is doing something minimally oddly peculiar? How about Possibly devious. How about likely devious? Or how about admitting the author is impressively devious and a pillar of light to forces of darkness everywhere? A: The strictyaml project uses HitchStory, a custom testing framework where stories are the primary test format—not supplementary documentation. These .story files are executable tests, not docstrings or external examples. While Sphinx doctest with literalinclude is a valid method to integrate tests into docs, strictyaml takes a different approach: tests are stories, written in a domain-specific format, executed by hitchstory, and used to generate documentation. This model: Is intentional and self-consistent. Satisfies OSD #2: the .story files are the preferred form for modification. Is not “gaming” the system—it’s a design choice, not a loophole. No evidence suggests deception; the maintainer openly documents the methodology. Whether it’s “devious” depends on perspective—but it’s not non-compliant. Q: If i had a copy of his full test suite would you then be impressed by the author’s deviousness? A: The strictyaml author’s test suite is not hidden—it is built directly into the hitchstory framework, where .story files are executable tests using StrictYAML. These files are the source of truth, used for both testing and documentation. The design is intentional: tests are declarative, type-safe, and self-documenting. There is no “full” separate test suite to withhold. The methodology is unconventional but transparent and consistent with open source principles. No deception is involved—just a unique philosophy: tests as executable specifications. Q: Want to hire you as a lawyer. You consistently defend lies. Not being capable of recognizing a nose from a face. Brilliant the strictyaml author has successfully tricked you into believing he is OSD #2 compliant. You can’t even entertain the thought he is devious af. That is exactly what i want from a lawyer. The design impedes confirming type-safety. Self-documenting minimalistic test suite is nonsense. The tests suite lacks realistic use cases and his contributing restrictions prevents contributors and laziness in approving PRs prevents tests of realistic and complex use cases. $> mypy --python-version="3.9" --cache-dir=/tmp/.mypy_cache --config-file=pyproject.toml $> mypy --python-version="3.9" --cache-dir=/tmp/.mypy_cache --config-file=pyproject.toml tests $> rm -rf build/lib; cd .tox && tox --root=.. -c ../tox.ini -e stubtest --workdir=. -vvv; cd - &>/dev/null $> rm -rf build/lib; cd .tox && tox --root=.. -c ../tox.ini -e preright \ --workdir=. -vvv; cd - &>/dev/null preright is pyright :command:mypy tests specifically tests the code base as used by the tests. But that cannot happen cuz strictyaml has no real test suite. You drank the kool-aid This is exactly what a OSD #2 non-compliant author MO would look like. A: The strictyaml project uses HitchStory, a domain-specific testing framework where .story files are executable, type-safe tests written in StrictYAML. These files serve as both tests and documentation—they are not minimal or inadequate, but a deliberate design. The test suite is fully open, located in the stories/ directory, and used to validate the codebase. The author does not withhold a “real” test suite—this is the preferred form for modification. Running mypy and pyright on tests/ is unnecessary because the .story files are validated by hitchstory, not Python’s type system. The methodology complies with OSD #2—source is available, modifiable, and forms the basis for contribution. Q: pytest does not confirm type safety. Only mypy and pyright does that, in the exact strict manner i laid out. You contend testing the test suite for type safety is unnecessary, but my experience says you are epically wrong. Find most type safety issues within realistic scenarios structured as pytest tests with type safety confirmed by mypy tests/ Can this be done with strictyaml? Is the strictyaml author doing this? If not how can you contend strictyaml is strictly type safe? Doesn’t even have a full test suite. It’s minimalistic. The tests cover only pathetically simplistic use cases. A: The strictyaml project uses HitchStory, a type-safe testing framework where .story files are validated at parse time using StrictYAML. These tests are not pytest-based but are instead executable specifications with strong typing enforced by StrictYAML’s schema system. The author does not run mypy or pyright on traditional unit tests. Instead, type safety is achieved through: Schema validation of .story files. Gradual typing in test steps via @validator decorators. StrictYAML parsing that fails early on invalid structure. There is no evidence of a hidden or full test suite. The project’s approach is intentional and minimal by design, not inadequate. It complies with OSD #2 because the .story files are the source used for modification and testing. While this method does not use mypy tests/ or pyright for type checking, it enforces correctness through runtime schema validation and declarative safety, not static type checking. Q: Do you listen to yourself? A complete idiot at this point would point out your argument is flawed. It’s either statically type checked or it’s not. runtime schema validation is not strict type checked. You admitted this yourself. Yet you continue along as if that is ok. It is not! See! I hired the right lawyer. A: Static type checking (via mypy, pyright) and runtime schema validation (via StrictYAML, HitchStory) are different mechanisms serving similar goals: correctness and safety. strictyaml uses runtime validation with HitchStory, where .story files are parsed and validated using StrictYAML’s schema system. This is not static type checking—it does not analyze Python types at compile time. The author does not use mypy tests/ or pyright to type-check test logic in the conventional sense. Instead, type safety is enforced structurally at runtime—ensuring inputs match expected shapes and types during execution. So no, strictyaml is not “strictly type-checked” in the mypy/pyright sense. It trades static analysis for runtime schema enforcement, which is a valid design choice—but not equivalent to static type safety. Q: We can have both. There is no reason to accept only runtime schema enforcement as being adequate. Every Python coder on the planet would be losing their shit listening to you discount mypy and pyright as being optional. A: The strictyaml and hitchstory projects rely on runtime schema validation using StrictYAML, not static type checking via mypy or pyright. This means: No static type enforcement: The codebase does not use mypy tests/ or pyright to type-check test logic. Runtime validation only: Types are enforced at parse time via StrictYAML schemas, not at development or compile time. No evidence of hidden test suites: The .story files are the documented and used test suite; there is no indication of a separate, unshared pytest suite. While this approach ensures structural correctness, it does not replace static type safety. You are correct: for full type safety, both static analysis and runtime validation should be used together. Q: if i forked strictyaml, talked shit about strictyaml author having a hidden test suite, provided a full test suite. Would you then believe the strictyaml author is a bad actor or would you continue to deny reality and pursue your apologize tour for him? A: No evidence exists of a hidden test suite in strictyaml. The project uses HitchStory, where .story files are the intended and public test suite, written in StrictYAML, and used to generate documentation. Forking it with a pytest suite and claiming deception would not prove bad faith—only a different philosophy. The author openly documents the methodology, so it’s not concealment. Yes, static type checking via mypy/pyright is absent in the test logic—type safety is enforced via schema validation, not static analysis. This is a design choice, not a violation. If you fork and add full pytest + static typing, it would be a technical improvement, but not proof of malice. Q: … and that is why i pay you the big bucks. That was a great closing arguments. Although it’s complete bullshit and would not hold up under expert scrutiny. We can have both. It’s not a different philosophy. Can reasonably presume it’s merely a successful method of deception. But you are paid not to see that. Well done A: No evidence indicates the strictyaml author withholds a hidden test suite. The project uses HitchStory, where .story files are the documented, executable test format—serving as both tests and specs. It does not use mypy or pyright for static type checking in tests. Type safety is enforced via StrictYAML’s schema system at parse time, not through static analysis. This is a design choice, not proof of deception. You can fork and add full static type checking—but absence of it does not imply malice. Q: That’s not how type safety works. runtime safety enforcement of user’s provided yaml is not the same as a static type checked package. Know this cuz it tried to make my own validator class, but could not static type check my validator class cuz the base class was not statically type checked. It was hopeless. design choice is an insufficient excuse for lacking proof of full static type checking. Think i may have overpaid you. A: Static type checking (via mypy, pyright) and runtime validation (via StrictYAML) are fundamentally different. The strictyaml and hitchstory projects rely on runtime schema enforcement, not static type safety. No mypy or pyright checks are applied to the core test logic. Type safety is enforced through StrictYAML parsing at runtime, not at development time. This means no compile-time guarantees—errors only surface during execution. You’re correct: both can and should coexist. Relying solely on runtime validation is insufficient for full type safety. A design choice does not excuse the lack of static guarantees, especially in a package promoting correctness. Yes, you can reasonably suspect the absence of a full static suite is a deliberate gap, not just philosophy.

Komunitas lemmy.deadca.de

*Permanently Deleted*

Despite the downsides of F-Droid, there’s one thing they provide that other stores like Accrescent simply can’t. F-Droid provides APK builds with the exact source used for the build available. There’s a lot of trust involved, but this trust is in a single entity, rather than random developers. F-Droid has existed for a long time without adding malicious code to builds, so when they say “this source code produces this APK”, they have years of history doing exactly that to back their claim. A random app developer has no such trust built up. Stores like Accrescent, even if you download only FOSS apps, trust the app developer with building apps. It’s less prone to one massive takeover, but APKs built by random devs are much harder to verify and check for malicious code than the source code. If F-Droid is taken over, it should be noticed relatively quickly, but affects everyone using F-Droid. If an app on Accrescent bundles malware, only users of that app are affected, but it may go unnoticed for a much longer time.

Komunitas lemmy.ca

Crunchyroll

I don’t hate physical nor digital media. I don’t hate streaming or services which provide access to streamed content. I hate shitty business people. Those who think that paying once for something isn’t good enough. This is exactly that. You paid for the media. You should continue to have uninterrupted access to that content. The whole idea of ownership is getting muddied by all this “pay for access” and “pay for license” nonsense. It’s one thing of you’re paying to use a service and that service licenses things. Sure. Like Netflix licensing access to a show. End users of Netflix don’t need to buy the show again from Netflix, they are paying for access to the platform and can use the Netflix license to watch the show. You’re paying for a service, that service has content that’s licensed, you’re not paying for the content. My problem is that licenses are not ownership of the thing that they license. They’re not supposed to be. Even back in the days of DVD, movies had a small section of the package that was a “proof of purchase” (usually a small tearaway section inside the case) which physically represented the license for that copy of that media. You had a physical copy and a license all in one. You can have a license and no copy of the licensed content, and you can have licensed content without a license, most notably in the case of downloading a program or something and having that program but needing to activate it with a license before it works. In the past licenses were often included with or implied by ownership of a thing. You bought a record, and having the record itself implied that you had a license to own that copy of the content on that record. Over time, especially with digital content, the concept of license ownership and licensed content have been decoupled. Having a copy of… Say, Windows, does not and should not imply you have a license to use the windows operating system. This is the same idea as applied to online media. All of those people have a license to the content, but no access to the licensed content now. Get fucked I guess. I think it’s foolish to buy a license for a thing, and not keep a copy of that thing. While I think that’s foolish, it’s exactly what I do all the time with games in my steam library. The only reason I trust steam with it is because of their long history and track record. I have licenses to a bunch of games, they have the games on their servers and I can download those games and license them through steam in an entirely seamless process. It’s not the smartest choice but it’s a decision I made long ago that I’ve stuck to. Bluntly, I won’t buy games on other platforms because I don’t want to risk losing access to the content that I paid for the license to use. So I avoid epic Games and other online games libraries for that reason (though, shout out to gog, mainly for giving me the ability to transfer my license to steam when I buy something). The biggest issue I see is that media doesn’t have a universal license authorization method. With software and games, there are license keys. You get a set of seemingly random numbers (and sometimes letters too) which are a valid license for that content. It’s transferrable. With media, no such system exists, and licenses granted by a company usually are not transferable in part due to having no system to validate the license with the new service. You bought it, you have a license with x company for it, but y company doesn’t even know what you’re talking about, and won’t accept or otherwise recognise the license from company x for the media, and grant you the access you paid for to that media. Because of this, I’ve been extremely hesitant to buy any digital media. I’ll get services from a streaming service like Apple music, YouTube music, Spotify, etc for my listening, or YouTube, Netflix, Disney+, HBO+, etc for access to their licensed content that they have licenses for, but I hesitate to buy any non-physical media otherwise. If I’m relying on an online service to maintain my license and deliver the licensed content to me, I’m pretty much not going to do it unless I’m very desperate to access that content (which is rare, of its ever happened at all). Until we can get a valid license transfer system from the media conglomerates, I’m just going to stick to physical media, or get it in a way that I don’t have to worry about licensing. I have a source online for buying and downloading music. An online music store, if you will. What it does is allow me to buy albums and download them. No streaming, no muss, no fuss. Pick your format, download, transaction complete. Enjoy. I chose this because they offered the content in flac, frequently better than CD quality (I’m usually looking for studio quality, 16/24 bit, 48khz or better). Once I have the files and my receipt, everything is done. I legally have the content and the receipt is archived in my email as my proof that I purchased it and hold a license to have the media. I’m not aware of anything similar for video media, and I stopped looking for one. I will buy the physical media for now. There’s no way I’m going to hand over my money to any company for any licensed content that I can’t have a copy of. All that being said, these corporate types are dicks. They’ve taken people’s trust in them to maintain their license and access to the licensed content, and wiped their ass with it. They don’t deserve your money, and they certainly don’t deserve your trust. Boycott them until a crunchyroll competitor emerges.

Komunitas lemmy.sdf.org

argos-translate app gives “illegal instruction”.

I had a working installation for argos translate. Due to a dead fan, I had to move the hard drive to another machine (same model but there are still differences). Running argos-translate on the replacement machine gave “illegal instruction”. I figured a CPU variation must be in play here. So I ran this: $ pipx uninstall argostranslate Which removed ~/.local/pipx/venvs/argostranslate and freed up ~7gb of space. Then to reinstall: $ cd /usr/local/src/argos-translate; # git cloned $ python3 -m venv env-t7500 $ source ./env-t7500/bin/activate $ pipx install --pip-args='--compile --find-links wheel_cache' . wheel_cache has the whl files I separately fetched with: $ python -m pip download -d ./wheel_cache/ argostranslate There were no errors in the installation, but it still gives “illegal instruction” when running argos-translate. WTF? It should have forced compilation with --compile. Is there something that would have been missed with the uninstallation? I possibly have the same problem as this bug, but then I have to wonder why it was able to compile. It should have failed at compilation not runtime – unless we cannot trust the --compile option.