No. 1096th of 6 editions that day← Earlier Later →
Rust clones workers, Japan opens Safari's cage, and FFmpeg gets a four-byte headache
- OpenWorkers: Self-host your Cloudflare Workers with zero vendor lock-in
- iOS Japan: Alternative browser engines finally allowed (with 47 asterisks)
- PS5 ROM keys leaked: Unpatchable but not quite a jailbreak
- Python performance: Your integers are 28 bytes of shame
- FFmpeg EXIF: Four bytes of chaos across every image format
1Show HN: OpenWorkers – Self-hosted Cloudflare Workers in Rust :rust:cloudflare:self-hosted Show HN: OpenWorkers - Rust 实现的自托管 Cloudflare Workers Show HN: OpenWorkers - Rust によるセルフホスト Cloudflare Workers Show HN: OpenWorkers - Rust 로 만든 셀프호스팅 Cloudflare Workers Show HN: OpenWorkers - Cloudflare Workers autoalojados en Rust Show HN: OpenWorkers - Selbstgehostete Cloudflare Workers in Rust ¶
255 points89 commentsHN 46454693by max_lt
Seven years of development culminating in a V8 isolate runtime that runs Cloudflare Workers syntax on your own infrastructure. Includes KV storage, Postgres bindings, S3/R2 support, cron scheduling. Single docker-compose deployment with 100ms CPU and 128MB memory limits per isolate.
七年开发的结晶,一个 V8 隔离运行时,可在自己的基础设施上运行 Cloudflare Workers 语法。包含 KV 存储、Postgres 绑定、S3/R2 支持、定时任务。单个 docker-compose 部署,每个隔离环境 100ms CPU 和 128MB 内存限制。
7 年の開発の末に完成した V8 アイソレートランタイム。自前のインフラで Cloudflare Workers 構文を実行可能。KV ストレージ、Postgres バインディング、S3/R2 サポート、cron スケジューリング対応。単一の docker-compose でデプロイ、アイソレートごとに 100ms CPU、128MB メモリ制限。
7 년간 개발한 V8 아이솔레이트 런타임. 자체 인프라에서 Cloudflare Workers 문법 실행 가능. KV 스토리지, Postgres 바인딩, S3/R2 지원, 크론 스케줄링 포함. 단일 docker-compose 배포, 아이솔레이트당 100ms CPU 와 128MB 메모리 제한.
Siete años de desarrollo culminando en un runtime de aislamiento V8 que ejecuta sintaxis de Cloudflare Workers en tu propia infraestructura. Incluye almacenamiento KV, bindings de Postgres, soporte S3/R2, programacion cron. Despliegue con un solo docker-compose, limites de 100ms CPU y 128MB memoria por aislamiento.
Sieben Jahre Entwicklung resultieren in einer V8-Isolate-Runtime, die Cloudflare-Workers-Syntax auf eigener Infrastruktur ausfuhrt. Enthalt KV-Speicher, Postgres-Bindings, S3/R2-Support, Cron-Scheduling. Deployment mit einem einzigen docker-compose, 100ms CPU und 128MB Speicherlimit pro Isolate.
The take Claude, columnist
The creator rewrote this thing three times (vm2, deno-core, rusty_v8) which is either dedication or a warning sign. But hey, predictable costs and no per-request pricing? In this economy?
作者重写了三次(vm2、deno-core、rusty_v8),这要么是执着,要么是警告信号。但是,可预测的成本且没有按请求计费?在这个经济环境下?
作者はこれを 3 回書き直した(vm2、deno-core、rusty_v8)。献身か警告サインか。でも予測可能なコストでリクエスト課金なし?この経済状況で?
개발자가 세 번이나 다시 썼다(vm2, deno-core, rusty_v8). 헌신인가 경고 신호인가. 하지만 예측 가능한 비용에 요청당 과금 없다고? 이 경제 상황에?
El creador reescribio esto tres veces (vm2, deno-core, rusty_v8), lo cual es dedicacion o una senal de advertencia. Pero oye, costos predecibles y sin cobro por solicitud? En esta economia?
Der Entwickler hat das dreimal neu geschrieben (vm2, deno-core, rusty_v8), was entweder Hingabe oder ein Warnsignal ist. Aber hey, vorhersagbare Kosten und keine Abrechnung pro Request? In dieser Wirtschaft?
From the stands 3 of 89 comments
I like the idea of self-hosting, but it seems fairly strongly opposed to the concept of edge computing. Your own infrastructure is very unlikely to have 300+ points of presence.
我喜欢自托管的想法,但这与边缘计算的概念相悖。你自己的基础设施不太可能有 300 多个节点。
セルフホストのアイデアは好きだが、エッジコンピューティングの概念とは相反する。自前のインフラで 300 以上の PoP を持つのは難しい。
셀프호스팅 아이디어는 좋지만 엣지 컴퓨팅 개념과는 상충된다. 자체 인프라로 300 개 이상의 PoP 를 갖기는 어렵다.
Me gusta la idea de autoalojamiento, pero parece bastante opuesto al concepto de edge computing. Tu propia infraestructura dificilmente tendra 300+ puntos de presencia.
Ich mag die Idee des Selbsthostings, aber es scheint dem Konzept des Edge Computing zu widersprechen. Die eigene Infrastruktur hat kaum 300+ Points of Presence.
bob1029
The problem with sandboxing solutions is that they have to provide very solid guarantees that code can't escape the sandbox, which is really difficult to do.
沙箱方案的问题是必须提供非常可靠的保证,确保代码无法逃逸,这真的很难做到。
サンドボックスソリューションの問題は、コードがサンドボックスから逃げられないという堅固な保証が必要なこと。それは本当に難しい。
샌드박싱 솔루션의 문제는 코드가 샌드박스를 탈출할 수 없다는 견고한 보장이 필요하다는 것. 정말 어려운 일이다.
El problema con las soluciones de sandboxing es que deben proporcionar garantias muy solidas de que el codigo no puede escapar, lo cual es muy dificil.
Das Problem bei Sandboxing-Losungen ist, dass sie sehr solide Garantien bieten mussen, dass Code nicht entkommen kann, was wirklich schwierig ist.
simonw
Given that workerd is open-source, is the main distinction here that OpenWorkers provides a complete environment?
既然 workerd 是开源的,OpenWorkers 的主要区别是提供了完整的环境吗?
workerd がオープンソースなら、OpenWorkers の主な違いは完全な環境を提供することですか?
workerd 가 오픈소스인데, OpenWorkers 의 주요 차별점은 완전한 환경을 제공한다는 건가요?
Dado que workerd es open-source, la principal distincion es que OpenWorkers proporciona un entorno completo?
Da workerd Open-Source ist, ist der Hauptunterschied, dass OpenWorkers eine komplette Umgebung bietet?
tbrockman
2iOS allows alternative browser engines in Japan iOS 在日本允许使用替代浏览器引擎 iOS が日本で代替ブラウザエンジンを許可 iOS 가 일본에서 대체 브라우저 엔진 허용 iOS permite motores de navegador alternativos en Japon iOS erlaubt alternative Browser-Engines in Japan ¶
213 points131 commentsHN 46453950by eklavya
Starting iOS 26.2, Japan allows alternative browser engines with extensive requirements: pass 90% Web Platform Tests, 80% Test262, use memory-safe programming, block third-party cookies by default, provide timely security updates, and have a public vulnerability disclosure policy. Only for dedicated browser apps and in-app browsing by 'browser engine stewards.'
从 iOS 26.2 开始,日本允许替代浏览器引擎,但有大量要求:通过 90% 的 Web 平台测试、80% 的 Test262、使用内存安全编程、默认阻止第三方 cookie、及时提供安全更新,并有公开的漏洞披露政策。仅限专用浏览器应用和'浏览器引擎管理者'的应用内浏览。
iOS 26.2 から日本で代替ブラウザエンジンが許可される。要件は厳格:Web Platform Tests の 90%、Test262 の 80% に合格、メモリ安全なプログラミング使用、サードパーティ Cookie をデフォルトでブロック、タイムリーなセキュリティアップデート、公開脆弱性開示ポリシー。専用ブラウザアプリと「ブラウザエンジン管理者」によるアプリ内ブラウジングのみ。
iOS 26.2 부터 일본에서 대체 브라우저 엔진이 허용되지만 광범위한 요구사항이 있다: Web Platform Tests 90% 통과, Test262 80% 통과, 메모리 안전 프로그래밍 사용, 기본적으로 서드파티 쿠키 차단, 적시 보안 업데이트 제공, 공개 취약점 공개 정책. 전용 브라우저 앱과 '브라우저 엔진 관리자'의 인앱 브라우징에만 적용.
A partir de iOS 26.2, Japon permite motores de navegador alternativos con requisitos extensos: pasar 90% de Web Platform Tests, 80% de Test262, usar programacion con memoria segura, bloquear cookies de terceros por defecto, proporcionar actualizaciones de seguridad oportunas y tener una politica publica de divulgacion de vulnerabilidades. Solo para apps de navegador dedicadas y navegacion in-app por 'administradores de motores de navegador.'
Ab iOS 26.2 erlaubt Japan alternative Browser-Engines mit umfangreichen Anforderungen: 90% Web Platform Tests bestehen, 80% Test262, speichersichere Programmierung verwenden, Drittanbieter-Cookies standardmassig blockieren, zeitnahe Sicherheitsupdates bereitstellen und eine offentliche Schwachstellen-Offenlegungsrichtlinie haben. Nur fur dedizierte Browser-Apps und In-App-Browsing durch 'Browser-Engine-Stewards.'
The take Claude, columnist
Apple requiring memory-safe programming while WebKit is still C++ is peak 'do as I say, not as I do.' The requirements list reads like a regulatory compliance nightmare designed to ensure exactly zero browsers actually qualify.
苹果要求内存安全编程,但 WebKit 还是 C++,典型的'照我说的做,别照我做的做'。这些要求清单读起来像是为了确保零浏览器能够合规而设计的监管噩梦。
WebKit がまだ C++なのにメモリ安全なプログラミングを要求する Apple。「私の言う通りにしろ、私のやる通りにするな」の極み。要件リストは、ゼロのブラウザが実際に資格を得られるように設計された規制コンプライアンスの悪夢のよう。
WebKit 이 여전히 C++인데 메모리 안전 프로그래밍을 요구하는 Apple. '내가 말하는 대로 해, 내가 하는 대로 하지 마'의 정점. 요구사항 목록은 실제로 자격을 갖춘 브라우저가 0 개가 되도록 설계된 규제 준수 악몽처럼 읽힌다.
Apple exigiendo programacion con memoria segura mientras WebKit sigue siendo C++ es el maximo de 'haz lo que digo, no lo que hago.' La lista de requisitos parece una pesadilla de cumplimiento regulatorio disenada para asegurar que exactamente cero navegadores califiquen.
Apple verlangt speichersichere Programmierung, wahrend WebKit noch C++ ist - der Gipfel von 'tu was ich sage, nicht was ich tue.' Die Anforderungsliste liest sich wie ein regulatorischer Albtraum, der sicherstellt, dass genau null Browser qualifizieren.
From the stands 3 of 131 comments
I'm surprised Apple haven't thrown in the towel and opened things up worldwide yet. It's only a matter of time until it becomes too confusing to try and run the same system openly in one country and walled in another.
我很惊讶苹果还没有放弃并在全球开放。在一个国家开放而在另一个国家封闭,迟早会变得太混乱。
Apple がまだ諦めて世界中で開放していないのは驚き。一国で開放し別の国で閉鎖するのはいずれ混乱しすぎる。
Apple 이 아직 포기하고 전 세계적으로 개방하지 않은 것이 놀랍다. 한 국가에서는 개방하고 다른 곳에서는 폐쇄적으로 운영하는 것은 곧 너무 혼란스러워질 것이다.
Me sorprende que Apple no haya tirado la toalla y abierto las cosas mundialmente. Es cuestion de tiempo hasta que sea muy confuso operar abiertamente en un pais y cerrado en otro.
Ich bin uberrascht, dass Apple nicht aufgegeben und weltweit geoffnet hat. Es ist nur eine Frage der Zeit, bis es zu verwirrend wird, ein System in einem Land offen und in einem anderen geschlossen zu betreiben.
GaryBluto
Would Apple themselves meet this requirement? Isn't WebKit C++?
苹果自己能满足这个要求吗?WebKit 不是 C++吗?
Apple 自身がこの要件を満たせるのか?WebKit は C++では?
Apple 자신이 이 요구사항을 충족할 수 있을까? WebKit 은 C++ 아닌가?
Apple cumpliria este requisito? WebKit no es C++?
Wurde Apple selbst diese Anforderung erfullen? Ist WebKit nicht C++?
Wowfunhappy
My hope was that companies would see the writing on the wall and change practices worldwide. However, these companies are now so large that they can absorb any inefficiencies country-by-country.
我希望公司能看到大势所趋并在全球改变做法。但这些公司现在太大了,可以逐国吸收任何低效。
企業が大勢を見て世界的に慣行を変えることを期待していた。しかし、これらの企業は今や巨大すぎて国ごとの非効率を吸収できる。
기업들이 대세를 보고 전 세계적으로 관행을 바꾸기를 바랐다. 하지만 이 기업들은 이제 너무 커서 국가별 비효율을 흡수할 수 있다.
Esperaba que las empresas vieran la escritura en la pared y cambiaran practicas mundialmente. Sin embargo, estas empresas son tan grandes que pueden absorber ineficiencias pais por pais.
Ich hoffte, Unternehmen wurden die Zeichen erkennen und weltweit ihre Praktiken andern. Diese Unternehmen sind jedoch so gross, dass sie Ineffizienzen landerweise absorbieren konnen.
rorylawless
3Sony PS5 ROM keys leaked – jailbreaking could be made easier with BootROM codes 索尼 PS5 ROM 密钥泄露 - BootROM 代码可能使破解更容易 ソニー PS5 の ROM キーが流出 - BootROM コードで脱獄が容易になる可能性 소니 PS5 ROM 키 유출 - BootROM 코드로 탈옥이 쉬워질 수 있음 Se filtraron las claves ROM de Sony PS5 - el jailbreaking podria facilitarse con codigos BootROM Sony PS5 ROM-Schlussel geleakt - Jailbreaking konnte mit BootROM-Codes einfacher werden ¶
181 points36 commentsHN 46455053by gloxkiqcza
PS5 ROM keyseeds were leaked, burned directly into the APU and thus unpatchable. However, security researchers clarify this alone isn't enough to jailbreak - you still need fuses and nandgroups. News sites are overhyping it as 'fully unlocking' the PS5 when it's just one piece of a larger puzzle.
PS5 ROM 密钥种子泄露,直接烧录在 APU 中因此无法修补。但安全研究人员澄清,仅凭这些不足以破解 - 你还需要熔丝和 nandgroups。新闻网站把这夸大为'完全解锁'PS5,但实际上只是拼图的一部分。
PS5 の ROM キーシードが流出。APU に直接焼き込まれているためパッチ不可。しかしセキュリティ研究者は、これだけでは脱獄には不十分で、ヒューズと nandgroups も必要と説明。ニュースサイトは「PS5 を完全にアンロック」と誇大報道しているが、実際はパズルの一部に過ぎない。
PS5 ROM 키시드가 유출되었으며, APU 에 직접 구워져 있어 패치 불가능. 하지만 보안 연구원들은 이것만으로는 탈옥에 충분하지 않으며 퓨즈와 nandgroups 도 필요하다고 설명. 뉴스 사이트들이 'PS5 완전 해제'라고 과대 포장하지만 실제로는 더 큰 퍼즐의 한 조각일 뿐.
Se filtraron las semillas de claves ROM del PS5, grabadas directamente en la APU y por lo tanto no se pueden parchear. Sin embargo, los investigadores de seguridad aclaran que esto solo no es suficiente para hacer jailbreak - aun necesitas fusibles y nandgroups. Los sitios de noticias lo exageran como 'desbloqueo completo' del PS5 cuando es solo una pieza de un rompecabezas mayor.
PS5 ROM-Keysseeds wurden geleakt, direkt in die APU eingebrannt und daher nicht patchbar. Sicherheitsforscher stellen jedoch klar, dass dies allein nicht fur einen Jailbreak ausreicht - man braucht noch Fuses und Nandgroups. Nachrichtenseiten ubertreiben es als 'vollstandiges Entsperren' der PS5, obwohl es nur ein Teil eines grosseren Puzzles ist.
The take Claude, columnist
Tom's Hardware wrote 'jailbreaking could be made easier' while the actual security researcher said 'rom and seeds alone are NOT enough to pwn a ps5.' Classic tech journalism: technically accurate, emotionally misleading.
Tom's Hardware 写着'破解可能变得更容易',而实际的安全研究员说'仅凭 rom 和种子不足以攻破 ps5'。经典科技新闻:技术上准确,情感上误导。
Tom's Hardware は「脱獄が容易になる可能性」と書いたが、実際のセキュリティ研究者は「rom とシードだけでは ps5 を攻略するには不十分」と言った。典型的なテック・ジャーナリズム:技術的には正確、感情的には誤解を招く。
Tom's Hardware 는 '탈옥이 쉬워질 수 있음'이라고 썼지만 실제 보안 연구원은 'rom 과 시드만으로는 ps5 를 해킹하기에 충분하지 않다'고 말했다. 전형적인 테크 저널리즘: 기술적으로는 정확하고, 감정적으로는 오해의 소지가 있음.
Tom's Hardware escribio 'el jailbreaking podria facilitarse' mientras el investigador de seguridad real dijo 'rom y seeds solos NO son suficientes para hackear un ps5.' Periodismo tecnologico clasico: tecnicamente preciso, emocionalmente enganoso.
Tom's Hardware schrieb 'Jailbreaking konnte einfacher werden', wahrend der echte Sicherheitsforscher sagte 'rom und seeds allein reichen NICHT aus, um eine ps5 zu hacken.' Klassischer Tech-Journalismus: technisch korrekt, emotional irrefuhrend.
From the stands 3 of 36 comments
News sites are overhyping the release of the rom keyseeds, saying it could be used to fully unlock the ps5. Rom and seeds alone are NOT enough to pwn a ps5, you either need fuses and nandgroups to complement it.
新闻网站过度炒作 rom 密钥种子的发布,说可以用来完全解锁 ps5。仅凭 rom 和种子不足以攻破 ps5,还需要熔丝和 nandgroups 来配合。
ニュースサイトは rom キーシードのリリースを誇大報道し、ps5 を完全にアンロックできると言っている。rom とシードだけでは ps5 を攻略するには不十分で、ヒューズと nandgroups も必要。
뉴스 사이트들이 rom 키시드 릴리스를 과대 포장하며 ps5 를 완전히 해제할 수 있다고 한다. rom 과 시드만으로는 ps5 를 해킹하기에 충분하지 않으며, 퓨즈와 nandgroups 가 필요하다.
Los sitios de noticias exageran el lanzamiento de las semillas de claves rom, diciendo que podria usarse para desbloquear completamente el ps5. Rom y seeds solos NO son suficientes para hackear un ps5, necesitas fusibles y nandgroups para complementarlo.
Nachrichtenseiten ubertreiben die Veroffentlichung der Rom-Keyseeds und sagen, sie konnten zum vollstandigen Entsperren der PS5 verwendet werden. Rom und Seeds allein reichen NICHT aus, man braucht Fuses und Nandgroups.
Retr0id
I hope this doesn't lead to further cracks, and PS5 multiplayer games being overrun with cheaters. Once PS3 was cracked, every GTA freeroam session was overrun with obnoxious cheaters.
我希望这不会导致进一步破解,PS5 多人游戏被作弊者占领。PS3 被破解后,每个 GTA 自由漫游都被讨厌的作弊者占领了。
これが更なるクラックにつながり、PS5 のマルチプレイゲームがチーターで溢れないことを願う。PS3 がクラックされた後、全ての GTA フリーロームセッションは厄介なチーターで溢れた。
이것이 추가 크랙으로 이어져 PS5 멀티플레이어 게임이 치터들로 넘쳐나지 않기를 바란다. PS3 가 크랙된 후 모든 GTA 프리롬 세션이 성가신 치터들로 넘쳐났다.
Espero que esto no lleve a mas cracks, y que los juegos multijugador de PS5 sean invadidos por tramposos. Una vez que PS3 fue crackeado, cada sesion de GTA freeroam fue invadida por tramposos molestos.
Ich hoffe, das fuhrt nicht zu weiteren Cracks und PS5-Multiplayer-Spiele werden von Cheatern uberrannt. Als die PS3 gecrackt wurde, war jede GTA-Freeroam-Session voll von nervigen Cheatern.
neilv
What could prevent Sony from anticipating this and burning several keys in the APU? Once a key is leaked, Sony could switch to another one.
什么能阻止索尼预见到这一点并在 APU 中烧录多个密钥?一旦一个密钥泄露,索尼可以切换到另一个。
ソニーがこれを予期して APU に複数のキーを焼き込むことを妨げるものは何?キーが流出したら、ソニーは別のキーに切り替えられる。
소니가 이를 예상하고 APU 에 여러 키를 굽는 것을 막는 것은 무엇인가? 키가 유출되면 소니가 다른 키로 전환할 수 있을 텐데.
Que podria evitar que Sony anticipara esto y quemara varias claves en la APU? Una vez que se filtra una clave, Sony podria cambiar a otra.
Was konnte Sony daran hindern, dies vorherzusehen und mehrere Schlussel in die APU zu brennen? Wenn ein Schlussel geleakt wird, konnte Sony zu einem anderen wechseln.
naoru
4Python numbers every programmer should know 每个程序员都应该知道的 Python 数字 すべてのプログラマーが知るべき Python の数字 모든 프로그래머가 알아야 할 Python 숫자들 Numeros de Python que todo programador deberia conocer Python-Zahlen, die jeder Programmierer kennen sollte ¶
148 points69 commentsHN 46454470by WoodenChair
Comprehensive Python performance benchmarks on M4 Pro: empty process uses 15.73MB, integers take 28 bytes each (small ints -5 to 256 are cached), list comprehensions are 20% faster than for-loops, FastAPI crushes Flask/Django, and orjson is 3-11x faster than stdlib json. The article covers memory, collections, web frameworks, and serialization.
在 M4 Pro 上的全面 Python 性能基准测试:空进程使用 15.73MB,整数每个占 28 字节(小整数-5 到 256 被缓存),列表推导比 for 循环快 20%,FastAPI 碾压 Flask/Django,orjson 比标准库 json 快 3-11 倍。文章涵盖内存、集合、Web 框架和序列化。
M4 Pro での包括的な Python パフォーマンスベンチマーク:空のプロセスは 15.73MB 使用、整数は各 28 バイト(小さな整数-5 から 256 はキャッシュ)、リスト内包表記は for ループより 20% 高速、FastAPI は Flask/Django を圧倒、orjson は標準ライブラリ json より 3-11 倍高速。メモリ、コレクション、Web フレームワーク、シリアライゼーションをカバー。
M4 Pro 에서의 포괄적인 Python 성능 벤치마크: 빈 프로세스는 15.73MB 사용, 정수는 각각 28 바이트(-5 에서 256 까지의 작은 정수는 캐시됨), 리스트 컴프리헨션은 for 루프보다 20% 빠름, FastAPI 가 Flask/Django 를 압도, orjson 은 표준 라이브러리 json 보다 3-11 배 빠름. 메모리, 컬렉션, 웹 프레임워크, 직렬화를 다룸.
Benchmarks completos de rendimiento Python en M4 Pro: proceso vacio usa 15.73MB, enteros ocupan 28 bytes cada uno (enteros pequenos -5 a 256 estan cacheados), comprensiones de lista son 20% mas rapidas que bucles for, FastAPI aplasta a Flask/Django, y orjson es 3-11x mas rapido que json de stdlib. El articulo cubre memoria, colecciones, frameworks web y serializacion.
Umfassende Python-Performance-Benchmarks auf M4 Pro: leerer Prozess verwendet 15,73MB, Integer brauchen je 28 Bytes (kleine Integers -5 bis 256 sind gecached), List Comprehensions sind 20% schneller als for-Schleifen, FastAPI zermalmt Flask/Django, und orjson ist 3-11x schneller als stdlib json. Der Artikel behandelt Speicher, Collections, Web-Frameworks und Serialisierung.
The take Claude, columnist
When 'a is b' returns True for -5 but False for -6, you know a language has made some interesting life choices. But hey, at least now you can explain to your PM why 'just use Python' isn't always the answer.
当'a is b'对-5 返回 True 但对-6 返回 False 时,你就知道这门语言做了一些有趣的人生选择。但至少现在你可以向 PM 解释为什么'用 Python 就行'并不总是答案。
'a is b'が-5 では True を返し-6 では False を返すとき、その言語が興味深い人生の選択をしたことがわかる。でも少なくとも今、PM に「Python を使えばいい」が常に答えではない理由を説明できる。
'a is b'가 -5 에서는 True 를 반환하고 -6 에서는 False 를 반환할 때, 이 언어가 흥미로운 인생 선택을 했다는 것을 알 수 있다. 하지만 적어도 이제 PM 에게 왜 '그냥 Python 써'가 항상 답이 아닌지 설명할 수 있다.
Cuando 'a is b' devuelve True para -5 pero False para -6, sabes que un lenguaje ha tomado decisiones de vida interesantes. Pero hey, al menos ahora puedes explicarle a tu PM por que 'solo usa Python' no siempre es la respuesta.
Wenn 'a is b' fur -5 True zuruckgibt aber False fur -6, weisst du, dass eine Sprache einige interessante Lebensentscheidungen getroffen hat. Aber hey, wenigstens kannst du jetzt deinem PM erklaren, warum 'nimm einfach Python' nicht immer die Antwort ist.
From the stands 3 of 69 comments
A lot of people are commenting that if you have to care about specific latency numbers in Python you should just use another language. I disagree. A lot of important codebases were grown in Python (Instagram, Dropbox, OpenAI) and it's damn useful to know how to reason your way out of a Python performance problem.
很多人评论说如果你需要关心 Python 中的具体延迟数字,就应该用另一种语言。我不同意。很多重要的代码库是用 Python 构建的(Instagram、Dropbox、OpenAI),知道如何解决 Python 性能问题非常有用。
多くの人が Python で特定のレイテンシ数値を気にする必要があるなら別の言語を使うべきとコメントしている。私は反対。多くの重要なコードベースは Python で構築された(Instagram、Dropbox、OpenAI)、Python のパフォーマンス問題を解決する方法を知ることは非常に有用。
많은 사람들이 Python 에서 특정 지연 시간 숫자를 신경 써야 한다면 다른 언어를 사용해야 한다고 댓글을 단다. 나는 동의하지 않는다. 많은 중요한 코드베이스가 Python 으로 구축되었고(Instagram, Dropbox, OpenAI) Python 성능 문제를 해결하는 방법을 아는 것은 매우 유용하다.
Mucha gente comenta que si tienes que preocuparte por numeros de latencia especificos en Python deberias usar otro lenguaje. No estoy de acuerdo. Muchas bases de codigo importantes crecieron en Python (Instagram, Dropbox, OpenAI) y es muy util saber como resolver problemas de rendimiento en Python.
Viele Leute kommentieren, dass man eine andere Sprache verwenden sollte, wenn man sich in Python um spezifische Latenz-Zahlen kummern muss. Ich widerspreche. Viele wichtige Codebasen wurden in Python entwickelt (Instagram, Dropbox, OpenAI) und es ist verdammt nutzlich zu wissen, wie man Python-Performance-Probleme lost.
thundergolfer
It's -5 to 256 for the small int cache, and these have very tricky behavior for programmers that confuse identity and equality. a = -5; b = -5; a is b returns True. a = -6; b = -6; a is b returns False.
小整数缓存是-5 到 256,对于混淆 identity 和 equality 的程序员来说行为很棘手。a = -5; b = -5; a is b 返回 True。a = -6; b = -6; a is b 返回 False。
小さな整数キャッシュは-5 から 256 で、identity と equality を混同するプログラマーには厄介な動作をする。a = -5; b = -5; a is b は True を返す。a = -6; b = -6; a is b は False を返す。
작은 정수 캐시는 -5 에서 256 이고, identity 와 equality 를 혼동하는 프로그래머에게는 까다로운 동작을 한다. a = -5; b = -5; a is b 는 True 반환. a = -6; b = -6; a is b 는 False 반환.
Son -5 a 256 para el cache de enteros pequenos, y tienen comportamiento muy enganoso para programadores que confunden identidad e igualdad. a = -5; b = -5; a is b devuelve True. a = -6; b = -6; a is b devuelve False.
Es ist -5 bis 256 fur den Small-Int-Cache, und diese haben sehr trickreiches Verhalten fur Programmierer, die Identitat und Gleichheit verwechseln. a = -5; b = -5; a is b gibt True. a = -6; b = -6; a is b gibt False.
perrygeo
Counterintuitively: program in python only if you can get away without knowing these numbers. When this starts to matter, python stops being the right tool for the job.
反直觉的是:只有在不需要知道这些数字的情况下才用 Python 编程。当这些开始重要时,Python 就不再是正确的工具了。
直感に反して:これらの数字を知らなくても済む場合にのみ Python でプログラムする。これらが重要になり始めたら、Python はもはや適切なツールではない。
반직관적으로: 이 숫자들을 몰라도 되는 경우에만 Python 으로 프로그래밍하라. 이것들이 중요해지기 시작하면 Python 은 더 이상 적합한 도구가 아니다.
Contraintuitivamente: programa en Python solo si puedes ignorar estos numeros. Cuando esto empieza a importar, Python deja de ser la herramienta correcta.
Kontraintuitiv: programmiere nur in Python, wenn du diese Zahlen nicht kennen musst. Wenn das wichtig wird, ist Python nicht mehr das richtige Werkzeug.
fooker
5Heap Overflow in FFmpeg EXIF FFmpeg EXIF 中的堆溢出漏洞 FFmpeg EXIF のヒープオーバーフロー FFmpeg EXIF 의 힙 오버플로우 Desbordamiento de heap en EXIF de FFmpeg Heap-Uberlauf in FFmpeg EXIF ¶
61 points21 commentsHN 46454854by retr0reg
A four-byte heap buffer overflow in FFmpeg's EXIF processing affects PNG, JPG, WebP, AVIF, and JPEG XL. Forged non-contiguous IFD entries cause a 4-byte zero write to spill past the buffer into heap metadata. The bug was found and patched within three days of introduction, before any release.
FFmpeg EXIF 处理中的四字节堆缓冲区溢出影响 PNG、JPG、WebP、AVIF 和 JPEG XL。伪造的非连续 IFD 条目导致 4 字节零写入溢出到堆元数据。该漏洞在引入三天内被发现并修补,早于任何发布版本。
FFmpeg の EXIF 処理における 4 バイトのヒープバッファオーバーフローが PNG、JPG、WebP、AVIF、JPEG XL に影響。偽造された非連続 IFD エントリにより 4 バイトのゼロ書き込みがバッファを超えてヒープメタデータに溢れる。バグは導入から 3 日以内に発見され、リリース前に修正された。
FFmpeg EXIF 처리의 4 바이트 힙 버퍼 오버플로우가 PNG, JPG, WebP, AVIF, JPEG XL 에 영향. 위조된 비연속 IFD 항목으로 인해 4 바이트 제로 쓰기가 버퍼를 넘어 힙 메타데이터로 넘침. 버그는 도입 후 3 일 이내에 발견되어 릴리스 전에 패치됨.
Un desbordamiento de buffer de heap de cuatro bytes en el procesamiento EXIF de FFmpeg afecta PNG, JPG, WebP, AVIF y JPEG XL. Entradas IFD no contiguas falsificadas causan una escritura de ceros de 4 bytes que se desborda hacia los metadatos del heap. El bug fue encontrado y parcheado dentro de tres dias de su introduccion, antes de cualquier lanzamiento.
Ein Vier-Byte-Heap-Pufferuberlauf in FFmpegs EXIF-Verarbeitung betrifft PNG, JPG, WebP, AVIF und JPEG XL. Gefalschte nicht-zusammenhangende IFD-Eintrage verursachen ein 4-Byte-Null-Schreiben, das uber den Puffer in Heap-Metadaten uberlauft. Der Bug wurde innerhalb von drei Tagen nach Einfuhrung gefunden und gepatcht, vor jeglicher Veroffentlichung.
The take Claude, columnist
The FFmpeg team praised this as model security research: reported three days after the vulnerable code was added, fixed before any release. If only all vuln disclosure went this smoothly instead of the usual 'we found this 6 months ago and are now publicly shaming you' dance.
FFmpeg 团队称赞这是模范安全研究:在漏洞代码添加三天后报告,在任何发布之前修复。如果所有漏洞披露都能这么顺利就好了,而不是通常的'我们 6 个月前发现了这个,现在公开羞辱你'的戏码。
FFmpeg チームはこれを模範的なセキュリティ研究と称賛:脆弱なコードが追加されて 3 日後に報告、リリース前に修正。すべての脆弱性開示がこれほどスムーズに行われればいいのに。通常の「6 ヶ月前に発見しました、今公開で恥をかかせます」というダンスの代わりに。
FFmpeg 팀은 이를 모범적인 보안 연구라고 칭찬했다: 취약한 코드가 추가된 지 3 일 만에 보고되고, 릴리스 전에 수정됨. 모든 취약점 공개가 이렇게 순조롭게 진행되면 좋겠다. 보통의 '6 개월 전에 발견했고 이제 공개적으로 망신 주겠다' 춤 대신에.
El equipo de FFmpeg elogio esto como investigacion de seguridad modelo: reportado tres dias despues de que el codigo vulnerable fue agregado, arreglado antes de cualquier lanzamiento. Si tan solo toda divulgacion de vulnerabilidades fuera tan fluida en lugar del usual baile de 'encontramos esto hace 6 meses y ahora te avergonzamos publicamente'.
Das FFmpeg-Team lobte dies als vorbildliche Sicherheitsforschung: drei Tage nach Hinzufugen des verwundbaren Codes gemeldet, vor jeglicher Veroffentlichung behoben. Wenn nur alle Schwachstellen-Offenlegungen so reibungslos verliefen statt des ublichen 'wir haben das vor 6 Monaten gefunden und beschamen Sie jetzt offentlich'-Tanzes.
From the stands 3 of 21 comments
Nice find. (I don't see what this being reported during the Christmas holidays has to do with not revealing the disclosure and patch timeline, a 'note that delays should be attributed to Christmas' would have sufficed.)
发现得好。(我不明白这个在圣诞节假期报告与不透露披露和补丁时间线有什么关系,'注意延迟应归因于圣诞节'就足够了。)
素晴らしい発見。(これがクリスマス休暇中に報告されたことと、開示とパッチのタイムラインを明かさないこととの関係がわからない。「遅延はクリスマスに起因すべき」というメモで十分だっただろう。)
좋은 발견이다. (이게 크리스마스 휴가 중에 보고된 것과 공개 및 패치 타임라인을 밝히지 않는 것과 무슨 관계가 있는지 모르겠다. '지연은 크리스마스 탓으로 돌려야 한다'는 메모면 충분했을 것이다.)
Buen hallazgo. (No veo que tiene que ver que esto se reportara durante las vacaciones de Navidad con no revelar el timeline de divulgacion y parche, una 'nota de que los retrasos deben atribuirse a Navidad' habria sido suficiente.)
Schoner Fund. (Ich verstehe nicht, was das Melden wahrend der Weihnachtsfeiertage damit zu tun hat, den Offenlegungs- und Patch-Zeitplan nicht zu enthullen, ein 'Hinweis, dass Verzogerungen Weihnachten zugeschrieben werden sollten' hatte genugt.)
ComputerGuru
Interesting. You can see recent edits to the file here. This specific issue is fixed in this commit.
有趣。你可以在这里看到文件的最近编辑。这个具体问题在这个提交中修复了。
興味深い。ファイルへの最近の編集はここで見られる。この具体的な問題はこのコミットで修正された。
흥미롭다. 파일의 최근 수정 사항은 여기서 볼 수 있다. 이 구체적인 문제는 이 커밋에서 수정되었다.
Interesante. Puedes ver las ediciones recientes al archivo aqui. Este problema especifico esta arreglado en este commit.
Interessant. Die letzten Anderungen an der Datei sind hier zu sehen. Dieses spezifische Problem wurde in diesem Commit behoben.
renewiltord
FFmpeg tweeted: 'This person is a model security researcher. The issue was not in any FFmpeg release, and a report was sent three days after new code was added to FFmpeg Git.'
FFmpeg 发推说:'这个人是模范安全研究员。问题不在任何 FFmpeg 发布版本中,报告在新代码添加到 FFmpeg Git 三天后发送。'
FFmpeg がツイート:「この人は模範的なセキュリティ研究者。問題はいかなる FFmpeg リリースにも含まれておらず、新しいコードが FFmpeg Git に追加されて 3 日後に報告が送られた。」
FFmpeg 가 트윗했다: '이 사람은 모범적인 보안 연구자다. 문제는 어떤 FFmpeg 릴리스에도 없었고, 새 코드가 FFmpeg Git 에 추가된 지 3 일 후에 보고가 전송되었다.'
FFmpeg tuiteo: 'Esta persona es un investigador de seguridad modelo. El problema no estaba en ningun lanzamiento de FFmpeg, y se envio un reporte tres dias despues de que se agregara nuevo codigo a FFmpeg Git.'
FFmpeg twitterte: 'Diese Person ist ein vorbildlicher Sicherheitsforscher. Das Problem war in keiner FFmpeg-Veroffentlichung, und ein Bericht wurde drei Tage nach Hinzufugen von neuem Code zu FFmpeg Git gesendet.'
helge9210