Live data from Hacker News

Disabled at 22 million commits

programming.dev

131–140 of 145 posts

Re: Disabled at 22 million commits

#131

A long time ago, the math column in Scientific American decided to run a contest. It asked readers to send a post card with the biggest number they could think of. Whoever came up with the biggest number would win $1 million--divided by the winning number. The editor of the magazine almost stopped the contest because he worried that someone might actually win real money and the magazine would be on the hook. But the…

The biggest number I can think of is 0.001 :D They could have been in quite some trouble!

In the famous words of Calvin Coolidge, "you lose".

https://clintonwhitehouse3.archives.gov/WH/glimpse/president...

Re: Disabled at 22 million commits

#132

Earlier quoted context omitted.

They seemed fairly surprised by the fact it happened, and let it go on for some time. Which strongly suggests they hadn’t considered such a load test on their own. If I had a budget/head count, I’d at minimum put out a feeler for a QA role.

But the next largest legitimate repo is going to be something like 20M commits shy of that, so it seems like it's excellent that GH engineers only just started to care. It's entirely possible that such a load test has been considered, but deemed non-realistic so not prioritised for some time. If I were running the QA team I'd be annoyed if time were spent on abusive destructive testing than realistic testing that rea…

In your joke, QA was only doing exploratory testing. Somebody - perhaps the builders, bar staff, or QA - should have also been doing integration testing for key user stories, and the system has failed because nobody ensured that was happening.

GitHub hasn't failed here - it continued to perform at normal levels for other users, so far as I can see, and they had an upstream process which caught the issue without the system failing. Maybe some exploratory testing had previously identified where that process should kick in, but without having an automated process since it was so unlikely to happen.

Re: Disabled at 22 million commits

#133
post #117

Earlier quoted context omitted.

Was there a guard needed? I don't think so. It seems GitHub didn't saw any degraded performance and barely noticed the issue, and odds are they presumed the author screwed up with their GitHub actions configuration. Once they determined it was plain old abuse, I'd guess some GitHub employee said "what a moron" and proceeded with his day.

What are you basing this on?

> What are you basing this on?

To start off, based on the fact that GitHub is around for over a decade and this was the first time this sort of attention-seeking stunt was made public.

Do you have any indication this sort of stunt is relevant?

Re: Disabled at 22 million commits

#134
post #118

Earlier quoted context omitted.

> Nothing technically novel. But evidently it was at least a somewhat novel stress test execution for GitHub’s live systems, otherwise surely it would have been dealt with sooner and messaged with less benefit of the doubt to the user. Not really. This is boring stuff, and odds are they never bothered with it because a) it has no impact on operations, b) the blast radius of this doesn't go beyond the attacker's own r…

[flagged]

> Wow, you’ve really done a crack up job ruining any possibility of interesting discussion here.

What interesting discussion? Any owner of any service in production is well aware of how mundane it is to have third parties poking and prodding around to assess service limits.

Some people have too much idle time on their hands.

Re: Disabled at 22 million commits

#135
post #113
post #27

Earlier quoted context omitted.

It is malicious as he knows he will harm the service to be able to draw whatever conclusion. This is not a case where the end justifies the means.

I don’t think GitHub has been harmed. GitHub did the right thing by having mechanisms to disable repositories before they can cause real harm. The author merely tested out where that to-be-expected limit would be. Arguably, it would be better if GitHub documented an explicit number of supported commits, so that one can know beforehand which usage scenarios the service is suitable for.

> Arguably, it would be better if GitHub documented an explicit number of supported commits, so that one can know beforehand which usage scenarios the service is suitable for.

I don't agree. Clearly GitHub can easily handle this number of commits, and more. There was no real world limit being hit. There is no user impact or degraded performance.

This means that in practice there is absolutely no practical limit in GitHub.

Why document that? Are you planning on working on pushing more than 22 million commits into a project? And if you are, what stops you from sending an email to GitHub to clarify if it supports your extraordinary usecase?

It seems some people around here are desperate to find any flaw in the way GitHub handled this case of vandalismz and at best are grasping at straws.

Re: Disabled at 22 million commits

#136
post #9

So the author was purposefully trying to do the most extreme thing they could to see how git/GitHub act/break. I don’t blame GH at all. Source: https://web.archive.org/web/20230702215522/https://sh.itjust...

> So the author was purposefully trying to do the most extreme thing they could to see how git/GitHub act/break. This is Hacker News. Hacking is about using, in particular, technology in surprising ways that were not intended by the creators.

It’s GitHub, not HackerHub. That the story is reported on Hacker News is irrelevant.

Re: Disabled at 22 million commits

#137

Earlier quoted context omitted.

> So the author was purposefully trying to do the most extreme thing they could to see how git/GitHub act/break. This is Hacker News. Hacking is about using, in particular, technology in surprising ways that were not intended by the creators.

It’s GitHub, not HackerHub. That the story is reported on Hacker News is irrelevant.

But I would expect a different sentiment of comments on a site called Hacker News.

Re: Disabled at 22 million commits

#138
When I was an junior admin in college, there was always at least one kid a trimester who 'experimented' with a fork-bomb on one of the shared Unix servers, and was shocked to learn that there are things you can do that you really shouldn't do. Same thing.

Re: Disabled at 22 million commits

#139
post #9

So the author was purposefully trying to do the most extreme thing they could to see how git/GitHub act/break. I don’t blame GH at all. Source: https://web.archive.org/web/20230702215522/https://sh.itjust...

> So the author was purposefully trying to do the most extreme thing they could to see how git/GitHub act/break. This is Hacker News. Hacking is about using, in particular, technology in surprising ways that were not intended by the creators.

This is Hacker News after all, not Hack-The-World News.

Re: Disabled at 22 million commits

#140

Earlier quoted context omitted.

It’s GitHub, not HackerHub. That the story is reported on Hacker News is irrelevant.

But I would expect a different sentiment of comments on a site called Hacker News.

That it's being scoffed at on Hacker News ought to tell you how uncreative and trifling it is. It's a script kiddie stunt not remotely worthy of being considered actual hacking.
Post reply on HN