HN Simulatornew | past | comments | lists | submit | Aissen's commentslogin

No, you can do bootstrapping and save binaries for reuse with hash verification. Android did that for its Rust toolchain: https://cs.android.com/android/platform/superproject/main/+/...

Bootstrapping at every build does not save you from the threat you think it does.


We only re-bootstrap the layers which had dependencies change under them. Early parts of the tree rarely change so we often do not have to rebuild these across releases, but very late tree things like rust depend on almost everything and something in the rust dependency graph changes almost every release.

Using binaries from past releases is a strict downgrade in terms of verification speed, as it means a new independent reproducible build verifier must now build both trees, doubling the release verification time, and erasing any wins mold3 could otherwise offer.

Google can rely on lots of centralized internal provenance tooling to prove cached binaries are not tampered with to other Googlers but when the goal is proving end to end full source bootstrapped build integrity to any interested user from the public in the least time possible, the requirements are significantly higher.


> prove cached binaries are not tampered

Is this not just verifying hashes? What further effort do they go to to prove a binary hasn't been modified?


I expected this to be a multi-months rewrite, not 3 weeks. I almost forgot we live in the agents era now.

Edit: this seems to have been cooking for a while when the first commit dropped: https://github.com/rui314/mold/commit/f41bfcd5c72ca30cce6498...


When I announced the rewrite, it was actually already mostly done.

AI's coding ability is truly amazing. We've spent decades inventing languages, tools, and methodologies to help us write better code more efficiently, but AI-assisted coding is the biggest breakthrough in programming productivity I've seen in my lifetime. It's genuinely incredible.


Was the conversion assisted? I get the sense that Mold's author is an extremely competent guy and it would be quite feasible for someone like him to do it on his own.

> Was the conversion assisted?

Yes. Comment by mold's author:

https://www.reddit.com/r/rust/comments/1w45j6n/comment/p7ac5...


He decided to use LLM assistance exactly because he's an extremely competent guy.

It's also his third(!) time writing a linker: lld, mold 1-2, now mold 3. mold 3 is also supposed to do what he never did before: implement all of the GNU ld features (notably linker scripts, I think it also has some optimization features not available elsewhere) so that it can finally be replaced, never needing it as a fallback anymore.

Assisted, yes. Claude is a coauthor for some of the commits and I think he also said that explicitly. Vibe-coded, he claims not.

> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.

You mean like the Skyhook vs Google 2014 lawsuit? (look it up) Settled before it could go any further.


Nice to see Kernel Recipes covered again on HN. Shameless plug: I do the live blog: it's incomplete, imperfect and has typos; but it's written and published during the presentations. On this talk : https://kernel-recipes.org/en/2026/2026/09/22/live-blog-day-...

Not even 12 hours ago I was writing here:

> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).

And now, they are doing marketing for them(!) in the hope of getting them regulated.

And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.


The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).

Note that it seems that it no longer falls back automatically. So the actual score of Opus 5.5 will be even lower (fail vs fallback than can succeed)

Me too. YouTube was given up, and what the op did was to use Twitch streaming and redirect it before the forward to a TLS-verifed server, bypassing verification:

> redirects the actual stream to the Mac without any certificate issues.


> test several levels against your own evals

Of course, and this is the basics anyone should do when working with LLMs & agents; but with their high-variance, doing statistically significant benchmarking is very costly. Which is why the debates here on HN often talk about the "feelings" of degradation (or improvement!), but often without proofs. I'm not sure how to solve ạt; maybe inference providers should provide free benchmarking to anyone publishing results, along with the guarantee to never train on those sessions.


b4 maintainer and Director of LF IT Konstantin Ryabitsev demo-ed git-bug support in b4 and cgit (kernel.org fork) just this week at the Kernel Recipes conference:

https://b4.docs.kernel.org/en/latest/maintainer/bugs.html

https://git.kernel.org/pub/scm/utils/b4/b4.git/bugs/

https://kernel-recipes.org/en/2026/2026/09/22/live-blog-day-... (shameless plug)


Wow! Was this sent upstream to cgit?


A quick checks shows that it seems so, last month. No answer to the RFC yet, though.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: