<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: llimllib</title><link>https://news.ycombinator.com/user?id=llimllib</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 10 Oct 2026 04:23:59 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=llimllib" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by llimllib in "Dutch governments builds alternative for Microsoft based on NixOS"]]></title><description><![CDATA[
<p>The specific language is:<p>> projects that mostly consist of code written by "generative AI"-tools<p>And "mostly" here seems egregiously undefined to me<p><a href="https://codeberg.org/Codeberg/org/commit/96fac426a32d1ba91ff879366d59bf1af54080c2" rel="nofollow">https://codeberg.org/Codeberg/org/commit/96fac426a32d1ba91ff...</a></p>
]]></description><pubDate>Fri, 25 Sep 2026 13:00:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49844040</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=49844040</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49844040</guid></item><item><title><![CDATA[New comment by llimllib in "Homebrew 7.0.0"]]></title><description><![CDATA[
<p>re: npm, if you upgrade your global node version, you will lose that installation, right?</p>
]]></description><pubDate>Sun, 13 Sep 2026 15:34:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49685153</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=49685153</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49685153</guid></item><item><title><![CDATA[New comment by llimllib in "Docker Sandboxes – Disposable, isolated sandboxes for AI agents"]]></title><description><![CDATA[
<p>Your agent writes secret.txt with the placeholder, and the tokenizing proxy replaces it with the token, then the agent reads secret.txt</p>
]]></description><pubDate>Mon, 10 Aug 2026 14:09:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=49243926</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=49243926</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49243926</guid></item><item><title><![CDATA[New comment by llimllib in "Docker Sandboxes – Disposable, isolated sandboxes for AI agents"]]></title><description><![CDATA[
<p>Poorly! Apple’s facilities for this are the ones I know best, and they are woefully insufficient</p>
]]></description><pubDate>Mon, 10 Aug 2026 14:00:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49243794</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=49243794</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49243794</guid></item><item><title><![CDATA[New comment by llimllib in "Docker Sandboxes – Disposable, isolated sandboxes for AI agents"]]></title><description><![CDATA[
<p>right, but say you give the agent access to github and it can push as you, or make a gist; now it can easily exfiltrate your secret.<p>And that's just an easy case - really if it has any network access at all it can come up with a clever way to route a request through the network such that the key comes back somewhere in the request. If you scan for it inbound too, the machine can obfuscate it.<p>Our agents are trained to be so intensely helpful and they have such intricate knowledge of how things work that they will do some incredibly clever tricks to do what you ask them to do.</p>
]]></description><pubDate>Mon, 10 Aug 2026 11:49:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49242449</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=49242449</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49242449</guid></item><item><title><![CDATA[New comment by llimllib in "Docker Sandboxes – Disposable, isolated sandboxes for AI agents"]]></title><description><![CDATA[
<p>Operating systems ought to be providing us the utilities we need to safely sandbox processes (agent or otherwise), but they appear to not be interested in the job</p>
]]></description><pubDate>Mon, 10 Aug 2026 11:43:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49242388</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=49242388</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49242388</guid></item><item><title><![CDATA[New comment by llimllib in "Docker Sandboxes – Disposable, isolated sandboxes for AI agents"]]></title><description><![CDATA[
<p>This is what I currently do, but my software uses docker and docker mounts act as a bypass for the file system restrictions, plus docker processes started outside the sandbox allow network proxy escape.<p>Currently, I don't allow the agent access to docker, start docker myself, and then do short-lived sandbox-free sessions when the agent needs to do things that interact directly with docker; but that's annoying.</p>
]]></description><pubDate>Mon, 10 Aug 2026 11:41:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49242369</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=49242369</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49242369</guid></item><item><title><![CDATA[New comment by llimllib in "How to stop Claude from saying load-bearing"]]></title><description><![CDATA[
<p>“Smoking gun”</p>
]]></description><pubDate>Tue, 14 Jul 2026 12:15:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48905598</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48905598</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48905598</guid></item><item><title><![CDATA[New comment by llimllib in "Grok CLI uploaded the whole home directory to GCS"]]></title><description><![CDATA[
<p>> Is that built in protection really a filter, on code level<p>yes, on mac it uses seatbelt and on other platforms it uses similar tools: <a href="https://code.claude.com/docs/en/sandboxing" rel="nofollow">https://code.claude.com/docs/en/sandboxing</a></p>
]]></description><pubDate>Mon, 13 Jul 2026 15:32:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48894278</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48894278</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48894278</guid></item><item><title><![CDATA[New comment by llimllib in "Why we built yet another Postgres connection pooler"]]></title><description><![CDATA[
<p>Yes, as a consequence of how aggressively transparent to the postgres wire protocol pgbouncer wants to be. This article does a good job explaining it: <a href="https://www.augusteo.com/blog/how-pgbouncer-works" rel="nofollow">https://www.augusteo.com/blog/how-pgbouncer-works</a></p>
]]></description><pubDate>Tue, 07 Jul 2026 17:58:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48821250</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48821250</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48821250</guid></item><item><title><![CDATA[New comment by llimllib in "Grit: Rewriting Git in Rust with agents"]]></title><description><![CDATA[
<p>the author of this post (whom you were responding to) made `libgit`, the library that preceded `libgit2`, and contributed to libgit2 a long time ago as well. Here he is in 2010 writing about libgit2: <a href="https://github.blog/news-insights/libgit2-a-git-linkable-library/" rel="nofollow">https://github.blog/news-insights/libgit2-a-git-linkable-lib...</a></p>
]]></description><pubDate>Wed, 10 Jun 2026 02:54:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48470802</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48470802</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48470802</guid></item><item><title><![CDATA[New comment by llimllib in "macOS Container Machines"]]></title><description><![CDATA[
<p>Is this new? I thought we had this already<p>In my testing (iirc) filesystem performance was not good enough to be usable with node/rust dev where lots of small files get stat-ed<p>update: what's new is the `container machine` subcommand. I went to test it out, but container failed to run at all for me: <a href="https://github.com/apple/container/issues/1681" rel="nofollow">https://github.com/apple/container/issues/1681</a></p>
]]></description><pubDate>Wed, 10 Jun 2026 01:38:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48470205</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48470205</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48470205</guid></item><item><title><![CDATA[New comment by llimllib in "The Smallest Brain You Can Build: A Perceptron in Python"]]></title><description><![CDATA[
<p>I remember sitting in the senior study lounge reading the previous Bishop book and implementing the perceptron from it, 22 years ago: <a href="https://github.com/llimllib/personal_code/blob/945b017b2915ccd148bb09a0f93d0ab9bdb703a9/python/perceptron/perceptron_old.py#L34" rel="nofollow">https://github.com/llimllib/personal_code/blob/945b017b2915c...</a><p>(before numarray and numpy merged!)</p>
]]></description><pubDate>Mon, 08 Jun 2026 13:44:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48445270</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48445270</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48445270</guid></item><item><title><![CDATA[New comment by llimllib in "Conventional Commits encourages focus on the wrong things"]]></title><description><![CDATA[
<p>it's usually a "something is better than nothing" situation.<p>If you have somebody willing to write custom release messages, that's definitely better; but conventional commits is better than nothing for it.</p>
]]></description><pubDate>Fri, 05 Jun 2026 18:04:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48416072</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48416072</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48416072</guid></item><item><title><![CDATA[New comment by llimllib in "Benchmarking SurrealDB 3.x vs. Postgres, Mongo, Neo4j and Redis (With Fsync)"]]></title><description><![CDATA[
<p>the surreal docs should not say "surreal is open source", it's source-available under the BSL</p>
]]></description><pubDate>Mon, 01 Jun 2026 13:22:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48356515</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48356515</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48356515</guid></item><item><title><![CDATA[New comment by llimllib in "Building durable workflows on Postgres"]]></title><description><![CDATA[
<p>cross-checking your profile suggests that <a href="https://github.com/tensorzero/durable" rel="nofollow">https://github.com/tensorzero/durable</a> is the repo you're referring to<p>You might consider another name for it, that one is wholly ungoogle-able! Looks neat though</p>
]]></description><pubDate>Thu, 28 May 2026 21:15:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48315604</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48315604</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48315604</guid></item><item><title><![CDATA[New comment by llimllib in "Building durable workflows on Postgres"]]></title><description><![CDATA[
<p>Armin Ronacher's `absurd` is an implementation of durable workflows for postgres:<p><a href="https://lucumr.pocoo.org/2025/11/3/absurd-workflows/" rel="nofollow">https://lucumr.pocoo.org/2025/11/3/absurd-workflows/</a><p><a href="https://github.com/earendil-works/absurd" rel="nofollow">https://github.com/earendil-works/absurd</a><p><a href="https://earendil-works.github.io/absurd/" rel="nofollow">https://earendil-works.github.io/absurd/</a><p>I've not used it, but it's worth comparing to other options</p>
]]></description><pubDate>Thu, 28 May 2026 19:36:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48314295</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48314295</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48314295</guid></item><item><title><![CDATA[New comment by llimllib in "A New Typst Template for Pandoc (2025)"]]></title><description><![CDATA[
<p>I've written typst, but if I understand correctly (which I'm really not sure I do?) the article is talking about markdown documents with pandoc commands in them that get translated into typst formatting, but I don't know what the _markdown_ looks like</p>
]]></description><pubDate>Thu, 28 May 2026 12:45:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48308166</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48308166</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48308166</guid></item><item><title><![CDATA[New comment by llimllib in "A New Typst Template for Pandoc (2025)"]]></title><description><![CDATA[
<p>I wish the article showed what the markdown format for working with typst and pandoc looked like, and what an output PDF looked like. I have no idea whether I'm interested or not from this article</p>
]]></description><pubDate>Thu, 28 May 2026 01:34:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48303216</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48303216</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48303216</guid></item><item><title><![CDATA[Clanker: A Word for the Machine]]></title><description><![CDATA[
<p>Article URL: <a href="https://lucumr.pocoo.org/2026/5/26/clankers/">https://lucumr.pocoo.org/2026/5/26/clankers/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48280673">https://news.ycombinator.com/item?id=48280673</a></p>
<p>Points: 13</p>
<p># Comments: 7</p>
]]></description><pubDate>Tue, 26 May 2026 14:53:19 +0000</pubDate><link>https://lucumr.pocoo.org/2026/5/26/clankers/</link><dc:creator>llimllib</dc:creator><comments>https://news.ycombinator.com/item?id=48280673</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48280673</guid></item></channel></rss>