Time Nick Message 04:36 MTDiscord 04:36 MTDiscord \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ 04:36 MTDiscord \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ 04:36 MTDiscord \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ 04:36 MTDiscord The alpha and omega the first and the last 04:40 MTDiscord A least for discord 06:11 MTDiscord maybe nitro will let you see the real final boss... 14:52 crazylad this is insane. github just completely broke again 15:00 technomancy microsoft quality 16:03 MTDiscord 💀 18:13 sfan5 i took 5 minutes to make this page look nicer https://irc.luanti.org/ 18:14 technomancy hell yeah 18:17 Krock Ctrl+F5 needed 18:45 [MatrxMT]_ i demand ai slop quality NOW! 18:54 red-001 right to the slop 21:10 MTDiscord Is anyone reading mails on security ... luanti ... org? Asking because I sent something there and haven't heard back. Should there be an autoresponder or did I write to some complete wrong or outdated address? 21:11 sfan5 ^ rubenwardy 21:12 rubenwardy yes I've received it 21:13 rubenwardy replied 21:18 MTDiscord yay, it worked. thanks! 21:20 technomancy someone mentioned a few days ago that there was some work to get require+package working again in the mod sandbox; anyone know where I could find out more about that? 21:25 sfan5 https://github.com/luanti-org/luanti/pull/16036 21:25 technomancy grand; thank you! 21:37 MTDiscord technomancy: beware, i haven't gotten to updating that yet. i was busy with froscon over the weekend 😄 21:38 MTDiscord fwiw i did also explore the approach where we would reuse lua's built-in require and configure it properly, but that turned out messier and less obviously correct 21:39 technomancy luatic: oh, that's surprising; I've always had great luck re-using the built-in stuff. what kind of problems did you encounter? 21:39 technomancy when you say "configure it properly" you mean "write a sandboxed package.loaders function" or something else? 21:39 technomancy I've probably done this "sandboxed loaders" thing four or five times across various projects 21:46 MTDiscord sandboxed package.loaders. see https://github.com/appgurueu/luanti/tree/fix/require for my WIP branch. 21:49 MTDiscord you have gotchas like _LOADED in the registry which can give you unsanitized built-in libraries 21:50 MTDiscord it can be made to work, but the end result will be somewhat brittle and depend on subtle require implementation details, like require obtaining package.loaders via its fenv 21:51 MTDiscord though i suppose if we leaned more on stripping existing API tables instead of creating new ones with safe functions, it might be a tad bit more straightforward 21:52 MTDiscord in any case a pure lua implementation is very short and in my opinion it is easier to see that it behaves as expected. 21:52 MTDiscord and it also lets us have some nonstandard bonus features :-) 21:54 technomancy I mean... what you're describing sounds pretty straightforward 21:55 technomancy of course if you have some registry tables exposed in the sandbox, things can leak, but that's true regardless of whether you use the built-in require or your own 22:03 technomancy luatic: well, I guess it doesn't matter that much in the end as long as mods have access to the module system. is there anything specific I could help with here? if not I'll just see if I can test it out, read thru it, etc. 22:05 technomancy what's the difference between the fix/require vs feat/require branches? 22:06 MTDiscord fix/require is the one that configures lua's require, feat/require is the one that reimplements it in lua 22:07 technomancy right, gotcha. so the second one replaces the first one? or might replace it? 22:07 MTDiscord yes, the second one is the one i'm currently planning to pursue further. 22:08 technomancy have you thought about adding tests to demonstrate the problems you saw in the first one, to show that the second one addresses them? 22:08 MTDiscord i should definitely do that 22:08 technomancy awesome 22:09 technomancy well, I'll read thru this tonight or tomorrow and see if I have any other ideas 22:10 technomancy another thing I'd add in tests is a proof-of-concept to show that you can nest sandboxes, because that's a ridiculously powerful feature 22:10 technomancy maybe I can try doing that 22:23 MTDiscord better do it tomorrow, let me polish the branch first 22:23 technomancy sounds good =)