frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Google Cloud Fraud Defence is just WEI repackaged

https://privatecaptcha.com/blog/google-cloud-fraud-defence-wei/
509•ribtoks•6h ago•247 comments

AI Is Breaking Two Vulnerability Cultures

https://www.jefftk.com/p/ai-is-breaking-two-vulnerability-cultures
72•speckx•2h ago•22 comments

Lets Encrypt Stopping Issuance for Potential Incident

https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3
24•rbaudibert•16m ago•1 comments

What we lost the last time code got cheap

https://www.poppastring.com/blog/what-we-lost-the-last-time-code-got-cheap
38•speckx•1h ago•19 comments

Cartoon Network Flash Games

https://www.webdesignmuseum.org/flash-game-exhibitions/cartoon-network-flash-games
171•willmeyers•3h ago•56 comments

Serving a website on a Raspberry Pi Zero running in RAM

https://btxx.org/posts/memory/
148•xngbuilds•4h ago•58 comments

An Introduction to Meshtastic

https://meshtastic.org/docs/introduction/
305•ColinWright•8h ago•116 comments

Bjarne Stroustrup: How do I deal with memory leaks? (2022)

https://www.stroustrup.com/bs_faq2.html#memory-leaks
50•theanonymousone•2h ago•35 comments

A web page that shows you everything the browser told it without asking

https://sinceyouarrived.world/taken
408•mwheelz•7h ago•203 comments

PC Engine CPU

https://jsgroth.dev/blog/posts/pc-engine-cpu/
96•ibobev•5h ago•38 comments

My first in-prod corrupted hard drive problem

https://blog.pavementlink.ch/2026/05/07/my-first-corrupted-hard-drive-problem/
4•r1chk1t•26m ago•3 comments

David Attenborough's 100th Birthday

https://www.bbc.com/news/articles/cp3pww9g0p5o
184•defrost•7h ago•19 comments

Show HN: GETadb.com – every GET request creates a DB

https://www.getadb.com/
7•nezaj•3h ago•0 comments

Rumors of my death are slightly exaggerated

1239•CliffStoll•2d ago•195 comments

Apple, Intel have reached preliminary chip-making deal

https://www.reuters.com/business/apple-intel-have-reached-preliminary-chip-making-deal-wsj-report...
124•scrlk•2h ago•66 comments

Cloudflare to cut about 20% of its workforce

https://www.reuters.com/business/world-at-work/cloudflare-cut-over-1100-jobs-2026-05-07/
1222•PriorityLeft•23h ago•860 comments

Poland is now among the 20 largest economies

https://apnews.com/article/poland-economy-growth-g20-gdp-26fe06e120398410f8d773ba5661e7aa
780•surprisetalk•7h ago•668 comments

Mojo 1.0 Beta

https://mojolang.org/
194•sbt567•17h ago•136 comments

Google Broke reCAPTCHA for De-Googled Android Users

https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users
49•anonymousiam•1h ago•11 comments

US Government releases first batch of UAP documents and videos

https://www.war.gov/UFO/
162•david-gpu•7h ago•255 comments

Canvas online again as ShinyHunters threatens to leak schools’ data

https://www.theverge.com/tech/926458/canvas-shinyhunters-breach
885•stefanpie•21h ago•588 comments

pg_flight_recorder: Continuously sample PostgreSQL system state via pg_cron

https://github.com/dventimisupabase/pg_flight_recorder
6•tanelpoder•1d ago•0 comments

Maybe you shouldn't install new software for a bit

https://xeiaso.net/blog/2026/abstain-from-install/
787•psxuaw•20h ago•410 comments

Podman rootless containers and the Copy Fail exploit

https://garrido.io/notes/podman-rootless-containers-copy-fail/
94•ggpsv•6h ago•20 comments

Show HN: Git for AI Agents

https://github.com/regent-vcs/re_gent
72•doshay•5h ago•41 comments

Ask HN: We just had an actual UUID v4 collision...

204•mittermayr•12h ago•190 comments

GeoJSON

https://geojson.org/
131•tosh•10h ago•61 comments

Dirtyfrag: Universal Linux LPE

https://www.openwall.com/lists/oss-security/2026/05/07/8
767•flipped•1d ago•308 comments

ClojureScript Gets Async/Await

https://clojurescript.org/news/2026-05-07-release
255•Borkdude•12h ago•61 comments

The surprisingly complex journey to text-selectable client-side generated PDFs

https://sdocs.dev/blogs/journey-to-pdf-generation
64•FailMore•1d ago•52 comments
Open in hackernews

Proposal: Add bare metal support to Go

https://github.com/golang/go/issues/73608
85•rbanffy•1y ago

Comments

Someone•1y ago
FTA:

  // printk emits a single 8-bit character to standard output
  //
  //go:linkname printk runtime.printk
  func printk(c byte)
So, printing “Hello, world!”, necessarily will have to make 13 calls to this function. I think I would have required a printk that prints an array of bytes. I expect that can be significantly faster on lots of hardware.

In contrast, there’s

  // getRandomData generates len(b) random bytes and writes them into b
  //
  //go:linkname getRandomData runtime.getRandomData
  func getRandomData(b []byte)
Here, they seem to acknowledge that it can be faster to make a single call.
jeroenhd•1y ago
The method for printing uses an Intel UART driver to print characters. AFAIK, the standard low level UART generally only does single character transfers unless you write a (relatively) complex driver.

Rendering per string is better per string, but I'm not so sure how bad the difference is when it comes to UART but I doubt the system has enough throughput for the first implementation to matter.

90s_dev•1y ago
I wonder if this is related to that bare metal bios os post from a week or so ago. I asked the author why he used tty asm calls to print instead of calling int 10 directly and he said it was more efficient, but for different reasons.

https://news.ycombinator.com/item?id=43873822

Someone•1y ago
> The method for printing uses an Intel UART driver to print characters

The spec (rightfully) says “(e.g. serial console)”, not “Intel UART driver”.

You cannot know what bare metal you’re running on. On some hardware it could be sending data out over Bluetooth, USB or WiFi because that’s the only connection to the outside world.

ronsor•1y ago
Arguably `printk(c byte)` should be `printck(c byte)`, and there should be a separate `printk(s []byte)` that handles an array of bytes.

If `printk` isn't implemented, then fall back to repeated calls of `printck`.

lcarsip•1y ago
printk is the low level primitive for stdout printing and it's done this way as low level drivers generally only accept single characters.

There are upper level functions which simply takes a []byte and make fmt.Printf() work seamlessly and effectively when not printing on an UART that only takes a single character as output.

In TamaGo stdout is primarily used for debugging.

timewizard•1y ago
> Here, they seem to acknowledge that it can be faster to make a single call.

It calls the internal Fill function to fill 4 bytes of the slice at a time. That calls the rng assembly stub function which uses 'rdrand' to get 32bits of random data. Which gets called len(b)/4 times.

I don't think they did it for speed but rather to be more idiomatic.

Anyways, OSDev has had a "Go Bare Bones" page for quite a while:

https://wiki.osdev.org/Go_Bare_Bones

jasonthorsness•1y ago
We use 'scratch' containers for many of our Go applications, so they have no user-space stuff other than our application binary. It reduces exposure for security vulnerabilities. This proposal seems to be taking that approach to the extreme - not even a kernel. Super-interesting; I wonder if it could run on cloud VMs? How tiny could the image become?
jasonthorsness•1y ago
Looks like Tamago targets multiple VM runtimes https://github.com/usbarmory/tamago?tab=readme-ov-file
veggieroll•1y ago
How do you handle temp file space, timezone data, and other things that a minimal image provide?
kfreds•1y ago
Temp file space: Use RAM, or talk to host storage over Virtio.

Timezone data etc: You would have to fetch that over the network, or from a metadata API such as the one Firecracker provides to VM guests.

fpoling•1y ago
Services rarely need timezone done. So if one is OK with supporting only UTC, Go runtime works fine without any timezene data.

We use a minimal image to run in on AWS Nitro VM and it contains only kernel, init.d, the Go application file and TLS certificate roots with the root filesystem mounted over tmpfs.

Note that Nitro VM uses a custom kernel provided by AWS so the new proposal is not relevant for us. But if we could run Go directly in that VM, it will surely makes things faster and saves like 10% memory overhead. And it will also avoid OOM killer and few other bad unwanted interactions between Go runtime and Linux kernel memory management.

champtar•1y ago
For timezones data go already has https://pkg.go.dev/time/tzdata
kfreds•1y ago
> This proposal seems to be taking that approach to the extreme - not even a kernel.

To be fair, there is a kernel - the Go runtime. But since there is no privilege separation it classifies as a unikernel. Performance gains should be expected compared to a system where you have to copy data to/from guest VM kernel space to guest VM user space.

> I wonder if it could run on cloud VMs?

Yes. TamaGo currently runs in KVM guests with the following VMMs: Cloud Hypervisor, Firecracker microvm, QEMU microvm.

> How tiny could the image become?

Roughly the same size as your current Go binary. TamaGo doesn't add much.

ignoramous•1y ago
> To be fair, there is a kernel - the Go runtime.

I like Anil Madhavapeddy's definition for such setups. A compiler that just refuses to stop:

  MirageOS is a system written in pure OCaml where not only do common network protocols and file systems and high-level things like web servers and web stacks can all be expressed in OCaml but the compiler just refuses to stop ... compiler, instead of stopping and generating a binary that you then run inside Linux or Windows, will continue to specialize the application that it is compiling and ... emit a full operating system that can just boot by itself.
https://signalsandthreads.com/what-is-an-operating-system / https://archive.vn/yLfkq
eyberg•1y ago
Cloud vms are a main target for unikernels, however, as Russ mentions in one of the linked issues there actually is quite a lot of other code you need to include in your system depending on what you are deploying to.

For instance systems with arm64 might need UEFI or if you enable SEV now you need additional support for that which is why I'd agree with Russ's stance on this.

Every time someone asks us to provide support for a new cloud instance type (like a graviton 4 or azure's arm) we have to go in and sometimes provide a ton of new code to get it working.

kfreds•1y ago
I assume you're referring to this[1]. I don't think it's necessary to bring all of that into the Go runtime itself, or ask the Go team to maintain it. It would be part of your application, and similar to a board support package.

TamaGo already supports UEFI on x86, and that too would be part of the BSP for your application, not something that would need to be upstreamed to Go proper. Same for AMD SEV SNP.

As for you (nanovms) supporting new instance types, wouldn't it be nice to do that work in Go? :)

Edit: I wonder how big the performance impact would be if you used TamaGo's virtio-net support instead of calling from Go into nanos.

advanderveer•1y ago
I would be interested in this if it enabled deterministic simulation testing for the Go programming languages. There have been some efforts in this area but with little success.
rcarmo•1y ago
I use TinyGo, and it does that job well. Not sure if it’s necessary to mainline it.
lcarsip•1y ago
TinyGo targets an entirely different class of systems and is not something that can be upstream being a different compiler, see https://github.com/usbarmory/tamago/wiki/Frequently-Asked-Qu...