Time Nick Message 00:18 [MatrxMT] Linus Torvalds: 00:18 [MatrxMT] > This is *NOT* some kind of "social warrior" project, never has been, and never will be. 00:19 [MatrxMT] that comment always seemed incredibly tone-deaf given that y'know, the kernel is GPL and Torvalds had skin in the game about GPLv2 vs GPLv3, i.e. placing some importance on software freedom 00:20 [MatrxMT] he's really just trying to throw weight around to stop endless debates 00:23 MTDiscord this sort of thing is why I kind of dislike the anti-ai side 00:24 MTDiscord it should be up to the user if they want to install vibecoded mods 00:24 MTDiscord all the contentdb should do is enforce disclousure and tagging 00:25 MTDiscord I agree about the datacenters and the corporate bullshit but those guys go way too far sometimes 00:25 MTDiscord if the anti-ai side considers the llm users making their own instance that does allow llm stuff a loss to fight then that's a certain bit of entitlement 00:25 MTDiscord yeah 00:25 MTDiscord that's more "anti{cloud llm}" 00:25 MTDiscord yeah I can get behind that more 00:26 MTDiscord imo it's not the tech itself but the corporate asshats that are the "face" of it rn 00:26 MTDiscord mfers acting like running a local llm just to mess around with chatbots is the same as using datacenter llms 00:27 MTDiscord "but chatbot ai psychosis" they sound like people talking about video games in the 90s 00:27 MTDiscord yeah it exists to an extent but it is oftentimes caused by underlying mental health issues and isolation that existed before 00:28 MTDiscord and violent video games can't really be scapegoated for the mental health crisis anymore 00:28 [MatrxMT] yes and the technology made it worse. Much worse in some cases. Not in a way that avideo game would. It's not even fair to compare them 00:29 [MatrxMT] LLMs do have serious, deep-rooted alignment problems and they act in a way that activates people to personify them and begin to trust and attempt to form relationships 00:30 MTDiscord the instances where that person committed suicide "because of the chatbot" clearly had some serious underlying mental health issues before the fact 00:30 [MatrxMT] "Bro was always at risk of getting psychosis before he smoked weed" - so he still shouldn't have been sold weed 00:30 MTDiscord yet people acted like it was 100% the llm and that it was an avengers level threat 00:30 MTDiscord llms are NOT the same as hallucinogenic 00:31 MTDiscord fuck this 00:31 MTDiscord ALL OF YOU are just going to frame me as a socopath 00:31 [MatrxMT] yes let's all have a better day without this 00:31 MTDiscord no 00:32 MTDiscord you hate me and think I am a rabbid techbro 00:32 MTDiscord there will be no peace, YALL want no peace 00:33 MTDiscord you know what screw this server I am making my own game anyway (not vibecoded bc I want to take pride in my own acomplishments and not share the glory with a glorified autocomplete) 00:34 MTDiscord "wow look how deranged the techbro side is, imma post this on reddit and get 50000 updoots" 00:34 MTDiscord for the record though a chatbot is not the same as literal weed 00:35 MTDiscord i'm tired of this, this is why I will never side with the anti-AI side bc yall always take the extreme position 00:35 MTDiscord chatbots are kinda sychophantic but that's not even an llm-exclusive issue 00:36 MTDiscord roleplaying with chatbots is comparable to playing an rpg 00:36 MTDiscord just with less object permanence and more interactive npcs 00:37 MTDiscord ok sorry for blowing up just now 00:37 MTDiscord but I am kind of tired of everyone taking extreme positions on AI 00:37 MTDiscord it is not the messiah, it is not the antichrist 00:38 MTDiscord it is a tool and a toy that can be used to either make garfield argue with squidward about politics or lie about a life experience on r/aita 00:40 MTDiscord and most of the big ticket news stories about serious shit happening bc of chatbots clearly had some underlying mental health issues beforehand 00:40 MTDiscord sane people do not hurt themselves because a glorified video game npc tells them to 00:40 MTDiscord it's like blaming school shootings for "violent first person shooters desensitizing people from violence" 00:42 MTDiscord there are some arguments to be make about parental controls and making an age requirement but a lot of it just feels like the reincarnation of the video games cause school shootings scare from the 90s 00:42 MTDiscord we don't need to ban chatbots we need to improve mental healthcare 00:42 MTDiscord most people suffering from severe AI psychosis turn to the AI because they are socially isolated irl 01:45 technomancy two things can be bad at the same time 01:46 MTDiscord ? 01:48 technomancy current standards of mental healthcare and also LLMs 06:57 Krock Fun. https://duckduckgo.com/?t=ftsa&q=\-Wnull-dereference automatically redirects to the first result of no relevance 07:23 [MatrxMT] oh yeah, from pov the achilles' heel of DDG is that using backslash executes the "I'm feeling lucky" function... and I have no idea how to get around it so I use something else 07:29 sfan5 I think you are supposed to put it in quotes 10:17 [MatrxMT] 1 more patch version and then 6.0 will release 10:17 [MatrxMT] right? 10:43 MTDiscord Sheriff_U3 thank you for the update on your personal beef with a list published through git, you're really fighting an important struggle here 10:43 MTDiscord can't just be having people make lists 13:18 cheapie "-- Configuring done (106.4s)" 13:18 cheapie this might take a while to buil 13:18 cheapie build* 13:27 MTDiscord red-001: I don't have a list/blog published through git. So I'm not sure what you are referring to. 13:30 MTDiscord birdlover32767: It has not yet been determined when Luanti v6.0 will be released. Currently though it looks like it will be a while. 13:30 [MatrxMT] surely it will release after 0.5.17.1 13:34 MTDiscord They have already started development on v5.18 13:34 [MatrxMT] aw man 13:36 MTDiscord They are planning on making v6.0 a bigger update then v5.0 was. 13:39 bgstack15 Oof, I hope they don't drop "core -> minetest" alias 13:39 cheapie Even if they did, it would be trivial to put it back in 13:40 cheapie Ooh, only took 5 minutes to build... the first file 13:41 MTDiscord bgstack15: that is one of the things I want them to drop 13:53 bgstack15 Not that it itself is a problem, but all the old mods never bothered to switch to calling it "core" 13:58 MTDiscord not everyone is taking extreme positions on AI, it's just that those who do tend to be the loudest about it. 13:58 MTDiscord If anything when v6 comes around people would like to avoid the v4 to v5 dumpsterfire. That said its also been said more stuff should have been dropped in v4 to v5 14:01 MTDiscord the many pages of scroll-back about some list of slopware aside, perhaps you should make your own list of lists you are offended by 14:03 [MatrxMT] what happens if i put it inside itself 14:03 MTDiscord (for the IRC users: red-001 is replying to a message by Sheriff U3, "I don't have a list/blog published through git [...]") 14:07 MTDiscord <.zenonseth> why drop the minetest alias though? does it gain anything? frees up the namespace, but it's not like anyone should release a mod named minetest? I guess if you purposefully want to make sure old mods break because 6.0 would potentially have other breaking changes ? 14:08 MTDiscord Personally thought, it would make more sense to break up the api into import/requirable chunks instead of mostly one giant thing under core/minetest 14:08 MTDiscord agreed 14:08 [MatrxMT] so that chatgpt doesn't say "use `minetest.get_connected_players()` at load time to check for singleplayer" probably 14:08 MTDiscord Course you have the function override issue 14:09 MTDiscord yes apologize to IRC users, I presumed the bridge would note it was a reply to another message even if it couldn't show which one 14:10 MTDiscord <.zenonseth> ok, breaking up the api into chunks - that would make sense and would be a good reason to drop any single alias i guess. Would be quite a change, I'm not saying bad, but you instantly lose a lot of mods out of the box, the tradeoffs (e.g. new features) better be worth it 14:10 MTDiscord If anything minetest.env should be burned in a fire. Or whatever it is. The orginal api 14:11 * cheapie chases wsor4035 around with a minetest.env:add_node() call 14:11 [MatrxMT] who even uses *that* anymore 14:11 MTDiscord Could most likely do that now tho tbh. Barely anything uses it 14:11 MTDiscord Ancient ass mods 14:11 MTDiscord Cheapie: I run away screaming 14:11 MTDiscord <.zenonseth> "ancient ass mods" - wonder where the dash goes, between the first two words or between words 2 and 3 :) 14:12 cheapie depends on the mod 14:12 MTDiscord That a reference to the xkcd? 14:12 [MatrxMT] https://xkcd.com/37/ 14:12 MTDiscord I don't think dropping globals really is meaningful 14:12 cheapie IIRC roads still has some minetest.env usage in it, but that was itself a combination of an ancient-ass mod (streets) and ancient ass-mod (infrastructure) in the first place 14:12 MTDiscord <.zenonseth> apparently it is a reference to xkcd, i didn't know, it's a general joke 14:13 MTDiscord Anyways, if your still using minetest.env imo your code deserves not to work 14:13 MTDiscord some of those 5.0 breaking changes could be described in a similar way tbh, that it wasn't really clear why dropping it was actually beneficial to anything 14:13 [MatrxMT] .zenonseth: you beat me to it :P 14:14 MTDiscord <.zenonseth> i mean dropping deprecated things eventually is fair, Luanti isn't the linux kernel, where breaking user space is a bug no-go 14:14 MTDiscord <.zenonseth> big no-go* 14:14 MTDiscord And similar to other things dropped like physics override, someone can make a polyfill that should die 14:14 MTDiscord making more tables read-only and a new unsandboxed Lua environment like I suggested before (dropping old trusted mods) I think would be more beneficial, ancient trusted-mods are almost always insecure ones that allow sandbox escapes if enabled 14:15 [MatrxMT] to be fair sometimes you do need to override tables 14:15 MTDiscord yes what's wrong with physics override, I don't really know anything about that, wsor 14:15 [MatrxMT] and you shouldn't need to go knocking on coredevs' doors to change them 14:15 MTDiscord <.zenonseth> agree, as long as its not a security issue, table overrides give more flexibility 14:16 MTDiscord I wrote a polyfill for the ancient physics override api. You should not use it 14:16 MTDiscord birdlover32767: I don't disagree exactly but I think it should be only core and not object metatables or string.* or os.* 14:16 MTDiscord or the globals table itself 14:16 MTDiscord freeze globals, make any writes a mod does go to a compat local metatable, enforce use of require 14:18 MTDiscord On another note, it's very annoying when you want to do a s/old/new on here and discord catches that and makes the edit, I wish the IRC bot would detect an edited message and output that again on the other side if it's not too long 14:18 cheapie I've been in channels that did that, it was somehow even more annoying than just not having the edit 14:19 MTDiscord <.zenonseth> I still do corrections with "new thing*" sometimes, even in platforms where edits are a thing 14:19 MTDiscord also it's criminal that tab does not auto-complete chat commands yet 14:19 cheapie It was real fun when you got a giant wall of text, then a few seconds later the entire wall of text again with one word different and you had to read the thing twice to figure out what changed 14:19 MTDiscord <.zenonseth> yes, call the police, real crime has been committed 14:20 MTDiscord <.zenonseth> cheapie you'd love discord, i swear some people type in multiple lines because of the mese shard point system thing 14:20 MTDiscord <.zenonseth> like one to two words per line 14:20 [MatrxMT] a REAL crime is when you do `local minetest = minetest` 14:20 MTDiscord cheapie: no I'm suggesting the bot runs a diff, and figures out if it's a one word change or something short like that, and posts it as s/tyop/typo as is somewhat of an IRC convention 14:21 cheapie That would be nice 14:21 [MatrxMT] new issue s/hi/im new 14:21 MTDiscord cause I literally can't do that from the discord end, cause the annoying web client will just replace it 14:22 [MatrxMT] wait i totally misunderstood that disregard 14:22 cheapie birdlover32767: Real crime? Take them to https://cheapiesystems.com/media/2025-12-12%2019-32-47.webm :D 14:23 MTDiscord I've been watching the Sopranos lately and I think it has important things to say about AI tbh but I refuse to expand on that, seminal american television that is 14:24 MTDiscord <.zenonseth> Al Lombardo? what'd he ever do to you? 14:24 cheapie That restaurant is still there (minus the siren) 14:24 cheapie Those Luacontrollers have about 3000 lines of code each, because reasons :P 14:24 [MatrxMT] that steve looks a bit... weird 14:25 MTDiscord cheapie how are LuaControllers sandboxed? 14:25 MTDiscord <.zenonseth> also i just love it when people post stuff like "I have weird opinions but don't ask me about them! I swear i won't expand on them" - not attention seeking at all 14:25 cheapie red.023: They get their own environment with limits on instruction count and persistent memory size 14:26 cheapie Or if you mean how it's implemented, mostly setfenv and pcall 14:26 MTDiscord wait so it's like a Lua VM inside Lua? or did someone figure out a way to actually use debug hooks well 14:26 cheapie They're using debug hooks 14:26 MTDiscord it would be kinda nice if the engine did that as a feature, but that's never getting merged even if it was made 14:26 MTDiscord it's a bit of a hackjob. i'm not quite sure how they solved the exponential string concat problem. 14:27 MTDiscord i mean if you have a lua VM in lua that can just be a mod? 14:27 cheapie Maybe I should turn RVController into a mod sometime and /that/ can just be your VM :P 14:27 MTDiscord I meant a sandbox, but you're right for a VM implementation that isn't much reason not to 14:28 MTDiscord first we gotta fix our own sandboxing :juanchi_face: 14:29 * cheapie looks to see how that build is coming 14:29 cheapie 5% 14:30 MTDiscord <.zenonseth> just let cheapie write a sanbox mod and then run all mods through that, why not 14:30 [MatrxMT] new cve discovered: malicious mods are able to kick everyone who joins 14:31 cheapie .zenonseth: At some point you'd end up with me getting Luanti running in emulation inside of some other mod and just putting the mods in there 14:31 MTDiscord birdlover32767: how LLMs move when you ask them to do a security review 14:31 [MatrxMT] fixes: `core.disconnect_player = nil; core.kick_player = nil` 14:32 cheapie birdlover32767: New CVE, server administrator can cause a denial of service by not starting the server 14:33 MTDiscord more like "malicious server can DoS clients by decompression bomb" :juanchi_face: 14:33 MTDiscord luatic: not wrong, I still think we should have had a separate GHSA for some of that, and then re-write everything in rust 14:33 * cheapie rewrites red.023 in RISC-V assembly 14:33 MTDiscord everything? 14:34 [MatrxMT] BREAKING: New CVE discovered that allows malicious players to drug the server operator until they hand over the admin password to gain control of the server 14:34 MTDiscord <.zenonseth> every time someone sees someone else's code: "we should rewrite this to be better" 14:34 MTDiscord tbh i have played with the thought because LLMs seem to make a full Rust rewrite possible, but i feel like development would not necessarily survive such an endeavour 14:35 MTDiscord just have fable do it, it will use unsafe 324 times and introduce 10 new critical CVEs you will have to pay GPT 6 Galaxia to fix 14:35 MTDiscord a small price to pay for Rust :juanchi_face: 14:35 MTDiscord maybe there is a middle ground though? 14:35 MTDiscord development can barely survive being given a short PR to review or merge 14:35 MTDiscord <.zenonseth> why not zig? it can use c code straight up, who cares its still not past 1.0 14:36 MTDiscord e.g. there is a mostly "safe" subset of C++, could make it use more of that 14:36 MTDiscord not to say I was right, but I did say to do the media loading in Rust 14:36 [MatrxMT] real men only code with fully released packages 14:37 MTDiscord <.zenonseth> 14:38 MTDiscord I think switching to Luau would be an interesting move 14:39 [MatrxMT] who even needs nodes when we have parts 14:39 MTDiscord Luau genuinely seems decently engineered and unsurprisingly fits our use case but it just doesn't feel right to me 14:39 rubenwardy is Luau based on LuaJIT or PUC? 14:39 MTDiscord it's the only Lua version that's intended to be sandboxed and is open sourced, unlike LuaJIT which explicitly does not support any kind of sandboxing to the extend that's possible while still maintaining compatibility with Lua PUC 14:39 MTDiscord rubenwardy: PUC, mostly 5.1 like our version but they copied from 5.2 as well 14:40 cheapie That sounds like it would be a disaster for performance 14:40 MTDiscord the diff is a mess, there's a lot of places where they added new features or they changed code seemingly to make it follow defensive coding (like asserting pre-conditions) 14:40 MTDiscord it does hurt performance vs JIT. some of it can be recovered though. 14:40 MTDiscord they have a JIT now 14:40 MTDiscord it's experimental 14:41 cheapie 6% \o/ 14:41 cheapie and it's only been... over an hour 14:41 cheapie I should probably be cross-compiling 14:42 MTDiscord <.zenonseth> cheapie are you compiling luanti or what? 14:43 MTDiscord The biggest issue I see is we would need to probably vendor the Lua "libraries" like os and io since we need those for the insecure environment, or I suppose could just write our own version of io and for os, etc just replicate the functions that mods actually use 14:43 cheapie .zenonseth: Yes (just the server), on what effectively amounts to a DVD player control chip from 2001 14:43 MTDiscord shipped with LuaSocket or websockets would probably do 90% of that right? 14:44 MTDiscord Maybe someone can run a check on content db to get a list of mods that request an insecure environment would help with building out that trusted environment concept I had 14:44 MTDiscord <.zenonseth> > on what effectively amounts to a DVD player control chip from 2001 that explains why its been 1% in like 30mins... 14:44 cheapie wsor4035: ^ zipgrep time? 14:45 [MatrxMT] does it have fans at least 14:45 cheapie birdlover32767: no 14:45 MTDiscord zipgrep for io and os? 14:45 MTDiscord no for insecure environment 14:45 cheapie For request_insecure_environment 14:46 MTDiscord that will be $9.99 😛 14:46 * cheapie /give wsor4035 currency:minegeld_10 14:46 MTDiscord anyways, be done a bit, might be slightly longer as im doing some other stuff 14:46 cheapie keep the change 14:47 MTDiscord (the bridge also doesn't markdown escape messages sent on IRC btw. sometimes that's a feature, sometimes not.) 14:48 MTDiscord I think a bigger issue with Luau is that it changes semantics enough that debug doesn't quite work, something like in-Lua sandboxing by mods might break 14:49 cheapie .zenonseth: This is what I'm compiling it on: https://theretroweb.com/chipset/documentation/55x-6454c074488b2098410908-6a5fc9af9f03b826408093.pdf 14:50 cheapie Mine is the 550, which is just the 552 (the one that's effectively a DVD player chip) minus the video decoding and a few other things 14:50 cheapie The CPU core is pretty much a Rise mP6 PR266 14:52 MTDiscord <.zenonseth> hm a pure x86, ok 14:52 * cheapie nods, 586+MMX 14:53 MTDiscord <.zenonseth> to be honest i haven't thought about luanti running on 32 bit systems but i guess why not 14:53 cheapie CPU-Z not only detects the wrong clock speed (it's only 200MHz) but has no clue what the processor even is: https://valid.x86.fr/95rcdu 14:54 MTDiscord <.zenonseth> i mean the processor pre-dates CPU-Z by quite a bit no? and the 90s was a crazy game with hardware, from what i've read 14:54 MTDiscord <.zenonseth> also, i have to ask, aside from "why not?" - why ? 14:54 cheapie Because user333_ was running Luanti on a potato and I wanted to run it on more of a potato 14:54 MTDiscord <.zenonseth> ah ok the potato competition, sounds good 14:55 cheapie I have slower boxes than this but this seemed like a good place to start 14:55 cheapie ca5$ grep name /proc/cpuinfo 14:55 cheapie model name : Unknown 586-class 14:56 cheapie It's also a bit of a learning experience, I have it running NetBSD 11 and I'm not very familiar with the BSDs 14:57 MTDiscord <.zenonseth> im surprised its an actual somewhat known (at least i've heard the name) distro 14:57 cheapie I would have done Linux, but most Linux distros don't support 586-class CPUs any more 14:57 cheapie I mean, IIRC Gentoo does, but I don't want to spend all year on this 14:58 MTDiscord <.zenonseth> one of my first jobs back in 2014 was for a set top box company and they had some.. idk what .,.. linux kernel stripped down to almost nothing, i think it only worked with telnet at the time 14:58 cheapie ooh, 7% 14:58 MTDiscord <.zenonseth> good luck! please report back the results when you get them in the next week! 14:59 cheapie The choice of NetBSD in particular here is because their system requirements seem to still be along the lines of "CPU recommended" 14:59 cheapie Heck, supposedly it still runs on a suitably-expanded VAX-11/780 from 1977 15:00 MTDiscord <.zenonseth> yeah no idea what that is, afraid to google it, lest google starts showing me ads for dimensia medication :P 15:00 cheapie https://en.wikipedia.org/wiki/VAX-11 15:05 MTDiscord cheapie: https://content.luanti.org/zipgrep/be944618-d512-4794-a7a8-1c4e1e19a894/ 15:05 MTDiscord also, try installing hannah montana linux on it 15:05 cheapie red.023: ^ 15:05 MTDiscord oh that's not too many, I guess I'll go manually code those 15:06 MTDiscord oh them is a fully LLM generated mod inside a system prompt, amazing 15:06 MTDiscord one of* 15:09 [MatrxMT] one of them is a dupe from `modlib` 15:10 cheapie FWIW, the rest of the specs of the box I'm compiling Luanti on, aside from the SiS 550 itself: about 512MiB RAM, Maxtor DiamondMax Plus 9 60GB hard drive, a Pioneer DVR-105 as the first drive I grabbed off the shelf that can read CD-RW, and not much else 15:10 [MatrxMT] 2 of them are dupes from `mapsync` 15:10 [MatrxMT] s/2/3 15:10 MTDiscord umh 15:11 MTDiscord folxs is the file object metatable immutable? 15:12 [MatrxMT] actually wait 4 from modlib, 3 from mapsync and 4 from skins_db (one has both modlib and skins_db) 15:12 [MatrxMT] and fmod has it commented out 15:15 MTDiscord skins_db seems like the easiest to just support in-engine, more of an unintended bad side effect of blocking mods from modifying their own code (perhaps wasn't really something needed to be blocked but certainly was the easiest way to stop some escape paths) 15:15 MTDiscord surely that DB can go into world storage no? same with the textures 15:16 MTDiscord maybe some sort of installation-global mod storage if it really can't 15:33 sfan5 dynamic_add_media works at load time btw 15:33 sfan5 there's no reason skinsdb can't work 15:34 MTDiscord notes so far 15:34 MTDiscord # Usage of insecure enviroment - SkinsDB - Write using insecure, mod modifies itself, unsure why this is required - modslib - lsqlite3, could be implemented using HTTP or websocket API with external DB most likely, or could add DB support - Quiz - not fully updated, not required by the mod - dreambuilder game (mtt) - test system, needs access to require to load luacov, could be supported by engine better - Unified Money Backend - sqlite3, 15:34 MTDiscord unclear why it needs this, seems to be more of tech demo - MQTT - Implements a messaging protocol, needs LuaSockets, could be move to a local service if we had fast sockets probably, most likely more of a tech demo - Simple protector - lsqlite3, could be replaced if the engine supported storing spacial information in the world map DB 15:35 MTDiscord spatial* 15:35 MTDiscord coverage testing and spatial information seem to be the main uses outside of demos or mods not using features they could 16:21 MTDiscord @luatic why not string.dump in the SSCSM sandbox? Roblox is very unclear about why they removed it, was hoping maybe you have a more clear idea of the issue with it? 16:21 MTDiscord it's a bit of an info leak I suppose but seemed like a fairly minor/trivial one 16:22 MTDiscord they are not clear about it at all, one page claims it's for security, another claims it's because it's not required anymore 16:22 MTDiscord well for one it's not very useful if you can't load bytecode, is it? 16:22 MTDiscord no disagreement but would have made the sandbox policy 30 LOC shorter if you just included all of string innit 16:23 MTDiscord it makes sense for them 16:23 MTDiscord they can just delete the code 16:24 MTDiscord is newproxy dropped by the sandboxes or is github search failing again 16:25 MTDiscord kinda insane that there's a whole undocumented function in Lua 16:26 MTDiscord iirc it was not included, but considering that 5.1 already deprecated it that is also not necessarily a bad idea 16:26 MTDiscord I don't believe the reference manual even mentions it for 5.1 16:27 MTDiscord nor 5.0 actually 16:28 MTDiscord Lua user mailing list has described it as an undocumented feature 16:28 MTDiscord well wasn't it removed in 5.2 or so? 16:30 MTDiscord I don't know, seems plausible 16:30 MTDiscord umh yeah I think I found another thing you cannot do safely in code that uses the insecure environment 16:31 MTDiscord more and more I think that feature needs to be dropped, there's no anti tampering isolation for it 16:33 MTDiscord the ability to disable mod security must be kept and is cheap to keep, the idea of isolated "trusted mods" would require proper env isolation 16:37 [MatrxMT] Lua 5.4.6 Copyright (C) 1994-2023 Lua.org, PUC-Rio 16:37 [MatrxMT] > string.dump 16:37 [MatrxMT] function: 0x64bd27dd5c80 16:37 MTDiscord I kinda feel like people can just recompile tbh if they don't want mod security, like with the proposed changes to require recompiling for built-in edits 16:38 MTDiscord birdlover32767: I know your ASLR base address now, consider lua repl pwned 16:38 [MatrxMT] oh no! anyways 16:39 MTDiscord except not really cause it prints the heap address for the closure 16:40 MTDiscord I don't really feel strongly about it but for debugging or what have you the engine should really implement that 16:40 [MatrxMT] mmh is bytecode that useful 16:41 MTDiscord or disabling mod security should also disable it for the CSM and SSCSM and all other sandboxes if this is meant to be an intentional footgun that everyone has the right to use, like that chrome command line to disable process isolation 16:42 [MatrxMT] turns out disabling mod security enables skynet 16:44 MTDiscord like bin/luanti --dangerous-disable-sandboxing and make it print a big warning message too on the main menu 16:45 rubenwardy Is there any legit reason to disable mod security when insecure envs exist 16:45 MTDiscord I don't think so but clearly some people would disagree considering we are having this conversation 16:46 MTDiscord maybe just the insecure environment being kinda poorly designed 16:46 [MatrxMT] for when you have too many mods requiring insecure env but are too lazy to put them all in manually 16:46 [MatrxMT] or checking for vulnerabilities... although you can just put it in individually so that is moot 16:47 rubenwardy Also skinsdb stores in moddata not the mod 16:47 MTDiscord rubenwardy: it might be an old version perhaps? it seemed to store in the mod in that one, moddata is that a per-mod storage or the per-world per-mod storage? 16:48 MTDiscord the use case is simply you are running a trusted mod set, want to interact with other processes. 16:48 MTDiscord disabling mod security is the easiest way to do that. 16:48 MTDiscord yeah I think that's unusual and people can really just compile from source 16:48 MTDiscord and if they can't they shouldn't be doing this 16:49 rubenwardy Unpublished skinsdb for Hades for leaking the ie 16:49 MTDiscord but command line would at least be a start, it can be a CMAKE flag either 16:49 rubenwardy Mod data is per mod global storage 16:49 [MatrxMT] you know maybe for the same reason `rm` has `--no-preserve-root` 16:50 MTDiscord yeah that's a command line flag tho, not something a user can just set in the menu 16:50 rubenwardy The engine should probably look for global assignments of the ie and throw an error 16:50 MTDiscord wait it did? 16:50 MTDiscord ^ replying to ruben about it leaking ie 16:51 rubenwardy But again the whole thing is so leaky, needs the completely separate envs as said 16:51 rubenwardy Yeah. Skinsdb for Hades did `skins.ie =` where skins is a global 16:51 MTDiscord but then it sets ie back to nil a few lines down 16:51 [MatrxMT] that seems really stupid though 16:52 MTDiscord it IS really stupid, but I thought that won't leak 16:52 Krock that stupid is outdated 16:52 Krock skinsdb no longer uses the insecure env 16:52 rubenwardy You can set a meta table on _G to capture the skins assignment and then add a callback to that 16:52 rubenwardy If you mod loads before this skinsdb 16:53 MTDiscord I don't think that happens anymore since it turned out it was basically impossible to avoid leaking ie if other mods loaded first 16:53 rubenwardy Ah 16:53 MTDiscord well actually maybe direct depends do load first do they? 16:54 MTDiscord I remember there was a PR about this since trying to sandbox anything was so hard 16:54 MTDiscord but it was actually cause it used the file metable, it was still insecure, someone can overwrite that and intercept file writes I think 16:55 MTDiscord which I guess you can avoid by writing crazy defensive code and copying the functions somewhere safe 16:56 rubenwardy Anyway, getting an ie just to write to a mod directory is very much something that should not be a permitted use of insecure env on ContentDB 16:56 rubenwardy ContentDB should detect use of request_insecure_environment and ask devs to provide a justification 16:57 [MatrxMT] and make sure it is in a lua file without being commented! 16:57 rubenwardy Shame we don't have permissions in mod.conf to prevent mods from sneaking their way around detections 16:59 rubenwardy Lol Krock wrote this code 16:59 MTDiscord could I think just do a small breaking change and require the use of http/insecure to be declare in mod.conf? technically breaks backwards compat but it's an easy fix for a player that knows what they are doing, and if they don't, well not to be rude but I don't think they should be enabling a mod using those 17:01 MTDiscord that's too harsh, people can run whatever software they want, but I don't think the current way it works makes it clear enough you are allowing arbitrary code execution on your system 17:01 [MatrxMT] damn, looking through recent contentdb additions and a lot of mods have ai generated stuff 17:01 MTDiscord people love their plagiarism machines as long as they work and don't happen to impact their own job lol 17:02 [MatrxMT] s/a lot/everything i looked at 17:02 MTDiscord not that people haven't had similar attitudes in the past to whatever significantly worse horrors the industrial revolution gave us 17:03 MTDiscord like yeah LLMs have a lot of issues, a Victorian factory was about as close to hell as you can get 17:04 Krock rubenwardy: https://i.imgflip.com/2/8u5o7u.jpg 17:04 Krock those developers! 17:05 MTDiscord well in the common sense of hell, theological conceptions of hell are not really something I know too much about, other than that its a wide range of options 17:10 [MatrxMT] after counting it seems like 26 out of 40 items in the recent place have the ai tag 17:10 [MatrxMT] dividing gives... 13*0.05 = 65% 17:14 Krock I nominate https://content.luanti.org/packages/Strength4549/bucket_flow_fix/ for the Artwork Of The Year 2026 (it made me smile) 17:17 [MatrxMT] looking through random i got 5 out of 40 with the ai tag 17:17 [MatrxMT] which is 12.5% 17:18 MTDiscord why not just run the API to check 17:19 MTDiscord rubenwardy: is the release number for CDB like a version number for the whole database? I'm trying to understand how the client is able to open the CDB so quickly despite it taking like 2 minutes on first load 17:20 MTDiscord like a generation counter or something 17:21 [MatrxMT] i wonder what will happen for the game jam 17:22 MTDiscord llm maxing I presume 17:23 rubenwardy Takes like 2s to load the entire package list though? 17:23 rubenwardy The release int is just a global auto increment 17:24 MTDiscord maybe it was my internet 17:25 MTDiscord but it was like a solid 30 seconds sometimes while I was testing POCs for that GHSA 17:26 MTDiscord related but just got an error response from some LLM provider endpoint and it's the most insane schema I have ever seen HTTP 500: {"type":"error","error":{"type":"error","message":"Internal server error"}} 17:30 [MatrxMT] 3435 packages total 17:32 [MatrxMT] seemingly i can't get flag=genai to work... 17:37 [MatrxMT] anyone knows why /api/packages/?flag=gambling works but not /api/packages/?flag=anyai 17:37 MTDiscord I made a script a while back to analyse the cumulative distribution of package AI disclosure over time. the blue is of course an unknown that could be anything 17:37 MTDiscord https://cdn.discordapp.com/attachments/749727888659447960/1540776928326455348/image.png?ex=6a8b2fd5&is=6a89de55&hm=81353cc7ca6f6af5e14351cad1880c0364bd14eeed99d3d9a9bc0242a2dac5f3& 17:37 [MatrxMT] ah you beat me to it 17:39 [MatrxMT] that url is going to expire in 2 days or so... 17:39 MTDiscord birdlover perhaps check the source code for CDB 17:39 MTDiscord and here is non-cumulative based on per month. so yeah, even though there is a big amount of packages that are marked as NONE, a lot of packages now are either marked as assisted or generated 17:39 MTDiscord https://cdn.discordapp.com/attachments/749727888659447960/1540777550425628682/image.png?ex=6a8b306a&is=6a89deea&hm=e9554394f4d6ddb6b938dc1e2688a72491064842b8ba396badeee23b804d37ff& 17:41 [MatrxMT] also i assume that a noticeable chunk of "NONE" is also ai in disguise 17:42 MTDiscord yeah I would probably assume there is some amount of packages with AI generated code that are marked as NONE 17:42 MTDiscord lot more obvious to see it for generated assets than with code 17:43 [MatrxMT] i say descriptions are **also obvious** when **half** the words are in **boldface** or *italics* 17:45 [MatrxMT] s/* s/*–s 17:45 sfan5 you could let an AI detect the AI 17:46 MTDiscord "that url is going to expire..." I could upload these images somewhere more permanent but I can also just put up the scripts I use in a github gist: https://gist.github.com/rollerozxa/fad7bcd286dd7d053077ef77a7fc7c0a 17:47 MTDiscord it runs on an extracted CDB data export which you can find here: https://content.luanti.org/help/backups/ 17:48 sfan5 I find worrying about expiry weird considering people on IRC use temporary file hosting all the time 17:54 MTDiscord <.zenonseth> whats the license of gists? 17:54 MTDiscord <.zenonseth> I can put the ai script to run on my mirror every time it updates probably, if i pull the ai disclosure column too 17:55 MTDiscord I put 0BSD in the gist title, do whatever you want with the scripts. currently it generates a matplotlib graph out of the data 17:57 MTDiscord <.zenonseth> ok, i may have to figure out a different way to visualize it, but i can at least use your script as a starting point and keep the historic data 19:22 cheapie Compilation progress update, about 6 hours in: 35% 19:26 MTDiscord are you compiling Luanti 19:28 cheapie yes 19:45 Krock cheapie: I hope you disabled LTO and perhaps -O2 instead of -O3 19:46 cheapie Krock: LTO is off (CMake's test of it failed anyway and I wasn't going to debug that, but then I explicitly turned it off too), optimization is at whatever the default was 19:48 cheapie Looks like said default is -O3 19:49 Krock it took about 35 minutes on a Celeron D, for reference. 19:49 cheapie Also -march=i486 for some reason, I probably should've made that -march=pentium-mmx but *shrug* 19:50 cheapie There doesn't seem to be an -march=mp6 otherwise I would say it would be that one 21:07 sfan5 disabling warnings will actually save time on weak systems 21:19 cheapie A bit late for that now 21:19 red-001 Is there any legit reason to disable mod security when insecure envs exist 21:19 red-001 Opened an issue about this #17492 by take is it should be a command line flag if it's kept, and the engine should warn when messing with other security-related settings mods aren't allowed to modify and explain to the user what they are doing. But I'm not a UX researcher so I'm not too sure I know the solutions that would work best 21:19 ShadowBot https://github.com/luanti-org/luanti/issues/17492 -- The engine should do more to protect the user from themselves 21:20 [MatrxMT] maybe you should have tried 0.4.x first 21:24 cheapie If I wanted a release version, I'd just do "pkgin install luanti" (and probably have to install some other sets, but whatever) and... they're actually shipping 5.17 already 21:24 cheapie But part of this whole thing is I wanted to see how long compiling would take 21:24 [MatrxMT] "ERROR[ServerStart]: worldedit_gui requires a supported gui management mod to be installed." - world edit 21:25 [MatrxMT] wrong line oh god (also worldedit*) 21:25 [MatrxMT] "To use the it you need to either:" i will get back after i use the it 21:25 cheapie Looks like the binary packages they have are still 5.16.1, but same story, I could just install those but I wanted to compile 22:01 pgimeno birdlover32767: why is `local minetest = minetest` a crime? localizing globals is pretty standard practice in both PUC and LJ 22:05 pgimeno from the previously posted list https://content.luanti.org/zipgrep/be944618-d512-4794-a7a8-1c4e1e19a894/ - out of the listed 61 mods, I counted 11 using core.request_blah and 50 using minetest.request_blah, it seems that few mods update that 23:22 cheapie When you do half a click with the screwdriver: https://cheapiesystems.com/media/2026-08-22%2018-19-47.webm