Live data from Hacker News

ZCode – Harness for GLM-5.2

zcode.z.ai

351–360 of 382 posts

Re: ZCode – Harness for GLM-5.2

#351
post #336

Earlier quoted context omitted.

When I was in university in 2009, the student union I was in had set up their Linux computers with a small program that one of the members wrote, that had the suid bit set and would exec apt-get install passing the arguments along. This way, all members of the student union were able to install any software they wanted to on the student union computers without having to give out blanket root access to the members. On…

Giving users ability to use apt with root privileges is pretty much game over security wise. Full root is a malicious package away

The student union mainly kept the full root privileges restricted to a select few students to avoid accidental destruction rather than as a measure against maliciousness.

After you had been a member for a while and demonstrated that you mostly knew what you were doing, they’d give you full root access if you had some reason to want it that they agreed with.

And thanks to the dedicated suid program that exec’d into apt, wanting to install additional software was not a reason to be granted full root privileges since everyone could already install packages from the apt repositories this way without full root privileges.

Along with full root access came basically just a couple of simple rules, one of which was:

Do not abuse your root access to walk into other members home directories.

That rule was put in place after a previous member with root access had used the root privileges to copy the homework of another member into his own home directory without asking the other member for permission to see his work.

Aside from that one thing happening that one time, there hadn’t really been anyone doing anything malicious AFAIK. We were a rather small group of members in this student union, and it was a pretty chill and nice place. People came there to hang out, drink beer and tinker with electronics and computers.

There wasn’t much that root privileges could be abused for anyway. Regular members could already use all of the machines via graphical login at the desks, and remotely over ssh. Really the main two things anyone could have done maliciously would be to steal other people’s homework (like that one guy was kicked out for doing), or to steal credentials from others (no known cases of that happening there).

And if someone had started acting really maliciously, using the student union computers to attack the wider network, the university would have been on top of that real fast. The computer network of the student union was a subnet of the university network, and this university had a very competent crew of people watching over the university computer network as a whole.

A friend of mine once wondered how many computers were on the university computer network in total and did a port scan from one of the university computers (not from the student union computers). It did not take long from he started the port scan until university employees contacted him and gave him a stern talking to, and also told him the proper way find the answer to how many computers were on the university network.

Re: ZCode – Harness for GLM-5.2

#352
post #124

Earlier quoted context omitted.

You're surprised? I think harnesses are almost as important as the underlying model. Folks have been able to improve benchmark results by nearly 2x based on harness alone. Harnesses are quickly becoming critical components of the "model" itself imo. Not shocking to me at all that a company that spots a revenue opportunity is keeping its harness closed source.

Source? The most trusted benchmark right now (deepSWE) scores better or just as well on their minimal harness than when using CC or codex

deepSWE clearly doesn't need complex tool calling?

Re: ZCode – Harness for GLM-5.2

#353
post #272

Earlier quoted context omitted.

Agent that can apt-get is more useful.

When I was in university in 2009, the student union I was in had set up their Linux computers with a small program that one of the members wrote, that had the suid bit set and would exec apt-get install passing the arguments along. This way, all members of the student union were able to install any software they wanted to on the student union computers without having to give out blanket root access to the members. On…

I hope you see how this is less secure than a docker container?

Re: ZCode – Harness for GLM-5.2

#356
post #145

Earlier quoted context omitted.

I am not surprised it is not open source. These harnesses are hard to build - they are not just wrappers - and often they contain business logic that is not suitable for public distribution for all kinds of reasons.

hard? wut lol.... no. they. are. not. Some people are just terrible at it.

Maybe they’re not “hard” to build, but some are sufficiently complex because they’re tailored to a model. If Z thinks their harness can improve on GLM’s shortcomings, that can give them a tiny edge, I guess?

Dunno. I’ve moved to Pi for most of my work and it’s finally better than Claude Code for me; BUT the Anthropic models are definitely better in CC itself.

Re: ZCode – Harness for GLM-5.2

#357

Earlier quoted context omitted.

Yeah, I use GLM 5.2 in OpenCode, running in a Docker container with CodeNomad as the web-based GUI. It works perfectly; I can access it from anywhere, and it runs all models (except for Anthropic's subscriptions).

From your experience, is it comparable to Claude Code with Opus 4.8? How does it feel? How do the two differ?

From my experience (~10M tokens on each): Opus remains better at more or less everything, and seems to hold its own better in large context work. It’s also more thorough. And usually can fix the weirdest of bugs, GLM is a bit hit and miss.

That said, GLM is worlds cheaper and a great little planner if you do a couple of rounds covering edge cases or things it might have forgotten. I can’t cache it via OpenCode Go, so I plan with GLM after gathering context cheaply, and then pass the plan to Gwen. That pairs well and shows the beauty of a multi-provider harness.

I should also add that I run GLM in Pi with a lot of cool little things such as hashline edits, some plugins for general smartness, etc. Opus runs in CC with the native tooling (except for Semble and Serena).

Re: ZCode – Harness for GLM-5.2

#358
post #349

Earlier quoted context omitted.

If distillation is stealing, then so is generating code using an ai model. It’s the same thing: prompt a model, use the output to make software. Not to mention, claude and gpt only exist because of massive ip theft in the first place.

yeah, sure, laws are just pointless things. Lets move to caves and if I kill you first , i'm right, if not i lost. THat's your logic. there is ToS, and every single person who is doing distillation knows it's illegal. Also on IP theft. There were several courts, in different countries they limit certain knowledge bases and thats it. so that entire claim is baseless. Again this is the difference. A major book publishe…

You make some good points, but 3 issues:

1) If training a model on IP theft is stealing, distillation has the same ethical base and we can’t really complain there.

2) While Chinese companies have some protection, they still have to uphold the different laws to enter other markets. We can complain all we want about their immunity, but good luck buying a Chinese car that doesn’t respect EU-wide safety standards.

3) Most (all?) big US-based companies now put arbitrage into their ToS. So no, I can’t sue them either. At best, I can run an expensive uphill campaign against them, which will be mostly pointless in the end.

Re: ZCode – Harness for GLM-5.2

#359
post #82

It's impressive all these companies are getting away with "base usage allowance included" [1] or "standard limits" [2], layering the higher plans as a multiplier of that "base" but never disclosing what it is. I guess the base is whatever the profit margin needs to be this month. [1]: https://zcode.z.ai/en#:~:text=Base%20usage%20allowance%20inc... [2]: https://support.google.com/gemini/answer/16275805?hl=en#:~:t...

When running the app, it actually tells you what the base usages are, but the name of the plans are different from the page. It reads: Start plan: 5 Million tokens a day (GLM-5.2 3M, GLM-5 Turbo 2M) For individuals: (+150% quota) $18.00USD+ For individual developers with a dedicated Coding Plan quota.

5M tokens regardless of “type”? Because then it takes a very good harness to not destroy that quota just with over-eager inputs.

Re: ZCode – Harness for GLM-5.2

#360
post #82

It's impressive all these companies are getting away with "base usage allowance included" [1] or "standard limits" [2], layering the higher plans as a multiplier of that "base" but never disclosing what it is. I guess the base is whatever the profit margin needs to be this month. [1]: https://zcode.z.ai/en#:~:text=Base%20usage%20allowance%20inc... [2]: https://support.google.com/gemini/answer/16275805?hl=en#:~:t...

Agreed this sucks. We publish ours here and try to be as transparent as possible: https://synthetic.new/rate-limits

Why price per request? What’s a request made of to cause GLM Flash to be 10x cheaper?
Post reply on HN