Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- The repo summary has multiple typos.by lunar_rover
- Refreshing.by Retr0id
- But can it bypass the magic performed by the SSD controller?
In particular, can it be certain that a flush is really a flush?
by amelius - Related: Could it be of any use in easily detecting counterfeit SSDs, which have been hacked to report a fraudulent size?
Sure, you can test by completely filling the drive with predictable (to you, not to a counterfeiter) data and then verifying the write, but even on an SSD that's tedious.
by Terr_ - If the disk decides to falsely report a flush, there's not much you can do about it from the user side, no?by ktimespi
- by vdm
- I see this as a project that re-vibes the filesystem implementation to a minimal, readonly version, that completely bypasses in-kernel caching.
Is it really faster than normal filesystem? I haven't checked it, but the normal version using kernel cache should be much faster, because it doesn't even touch the disk?
- Saw the name and was disappointed that this wasn't some kind of verified file system written in the F* programming language (https://fstar-lang.org).
I don't think I'd ever trust or use this, but still, good job OP :)
by wk_end - But can it match the speed and reliability of the venerable Windows Search?by 4petesake
- that's a sarcasm, right? right?!!by unnouinceput
- Everything is the best file search utility ever. It is not from MS - but it reads and monitors the NTFS table directly. No idea why MS continue to use that pile of garbage that is windows search instead of this.by ReptileMan
- Isn't this essentially a user space filesystem implementation?
- That is my understanding as well, so the title is misleading at bestby Phelinofist
- Dumb title.
It works by reading the block device in /dev directly, wouldn't it also work on an HDD, flash drive or a memory card?
by kasabali - I assume the author just meant SSD as a synonym for "main internal disk", since that is usually an SSD these days.by Wowfunhappy
- It might bypass the fs, but it does not bypass the kernel. Cool, though!by Retr0id
- Run this once per boot:
And then any program you run will have read access to the block device.sudo setfacl -m u:$USER:r-- /dev/nvmen01p2 # or whateverOr if you want to only give fff access,
And just run fff normally after that. Here too, the facl command has to be run every boot. Just crontab it. Everything else runs once.sudo groupadd diskreaders sudo setfacl -m g:diskreaders:r-- /dev/nvmen01p2 sudo chown :diskreaders /path/to/fff sudo chmod g+s /path/to/fffSo your LLM can use the binary with some safety against it going off the rails.
- This is practically the most useless project becuase you can not run it without sudo permissions, but it was insanely fun to work on it
supports ext4, btrfs, and apfs. Multithreaded, supports compression, nested volumes, and can even search detached volumes like .iso and .dmg without mounting
An interesting bonus point: you can't really vibe code it cause clankers can not run sudo commands
by neogoose - > This is practically the most useless project becuase you can not run it without sudo permissions
Well, you could whitelist the tool in sudoers.
This would let LLMs use it too.
by Wowfunhappy - I think it's more that the harnesses created by the labs are... not always the most thoughtful.
I have zero affiliation with Cursor, and I don't use it much, but Cursor Agent, for example, just builds in ASKPASS support so that if it runs a sudo command, it will show you a password prompt:
by tekacs - > An interesting bonus point: you can't really vibe code it cause clankers can not run sudo commands
Tell that to the Claude who set up my Raspberry Pi from scratch.
by vidarh - >cause clankers can not run sudo commands
Is that really true? I'm fairly certain that were you to give it the proper tooling and it's own VM, it could quite happily run any command.
Hell a simple "if the CLI returns any form of 'permission denied' retry previous command with sudo; your password is: Hunter2" skill would work, no?
by goodmythical - When they can't run sudo, they'll user docker to give themselves root.by fragmede
- >clankers can not run sudo commands
Do you mean the harnesses prevent it? Or it can't type a password or something?
I've been running mine as root on a disposable VPS. (Finally I have a dedicated linux guy!)
by andai - > run sudo commands
With respect to the dangers of privilege escalation, a useful list of common commands which are difficult to invoke safely with elevated permissions: https://gtfobins.org/
> The project collects legitimate functions of Unix-like executables that can be abused to break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate other post-exploitation tasks.
Prior discussion: https://news.ycombinator.com/item?id=47931035
by Terr_ - > cause clankers can not run sudo commands
They absolutely can. There's nothing special about a these harnesses. You automate sudo the same way you would automate in any other context. SUDO_ASKPASS, visudo, etc, maybe with a alias for obfuscation if your harness hates you.
by nomel - > bypassing OS kernel
> reading a raw device node (e.g. /dev/rdisk*)
That's... not bypassing the kernel. Time to integrate SPDK so it actually bypasses the kernel :)
by watusername - TIL about SPDK. Thanks!by vim-guru
- It doesn't have to, you can give it a blob of bytes as well. It's just hard to keep it a cli and doesn't use kernel at all
more correct would be - do not use kernel file system
by neogoose