Live data from Hacker News

macOS Container Machines

github.com

391–400 of 457 posts

Re: macOS Container Machines

#391
post #232

Earlier quoted context omitted.

Which ones? BSD was tied in a lawsuit that left doubts on its future. Minix was a toy OS for university teachings. Coherent was commercial. Nothing else was there on the PC market.

386BSD and its derivatives (eg FreeBSD) weren’t really attacked by SCO like other UNIXes were. In fact SCO filed more lawsuits against Linux than they did (for example) FreeBSD. FreeBSD was also used heavily in the late 90s in ISPs and similar domains.

Nobody said SCO sued BSD or BSD users. USL sued BSD and UC (https://en.wikipedia.org/wiki/UNIX_System_Laboratories,_Inc.....) long before the SCO lawsuits.

Re: macOS Container Machines

#392
post #363

Earlier quoted context omitted.

It did work quite well. The problem with the filesystem could have been solved by optimizing the Windows kernel, that would have benefit also programs run outside the WSL by the way (NTFS have performance problems and Microsoft knows, and even provided a kind of solution as far as I know with the developer FS or what they call it). The thing that I don't like of the WSL2 is that is just a VM, but a VM that is very li…

> (NTFS have performance problems and Microsoft knows, and even provided a kind of solution as far as I know with the developer FS or what they call it) NTFS does not have performance problems. The difference between DevDrive, which uses ReFS (arguably a more 'resilient' file system than NTFS due to journaling) and a standard NTFS volume is the file system filters are either removed or in the case of Defender, put in…

I recall there was also an issue with how paths are treated in NT. I don't fully recall, but I think NT paths are parsed by the kernel early on, and the whole kernel operates on "cooked" paths. there was some major performance implications this had for WSL1 in addition to the filter driver architecture.

I also don't remember why they couldn't just bypass the filter stack for paths in a certain volume - WSL2-like I/O on WSL1 - but there must have been a reason.

Re: macOS Container Machines

#393
post #232

Earlier quoted context omitted.

Which ones? BSD was tied in a lawsuit that left doubts on its future. Minix was a toy OS for university teachings. Coherent was commercial. Nothing else was there on the PC market.

386BSD and its derivatives (eg FreeBSD) weren’t really attacked by SCO like other UNIXes were. In fact SCO filed more lawsuits against Linux than they did (for example) FreeBSD. FreeBSD was also used heavily in the late 90s in ISPs and similar domains.

I think you are a possibly a decade off on the timing here.

USL v. BSDi is what impacted the BSD side, and it was during that lawsuit before Novell bought USL etc.... that the problems were that allowed Linux to make gains while the net/2 distros were in a waiting game IMHO.

The timing absolutely helped Linux and GNU being packaged as a complete system by the various distros etc..., and common OSS distribution points like Walnut Creek and PHT were very much concerned about USL v. BSDi and in an era when you had to make long distance phone calls to download with a modem, a lack of CDroms etc... absolutely caused a dip in adoption of the BSDs.

By the time the IBM v. SCO lawsuits happened (2003) the UNIX wars were long gone and Linux was already established.

SCO/Interactive/Coherent/etc... and other x86ish UNIXes were quite common in my work in the early 1990s, but the whole unix wars is way to complicated to cover in a single post.

The post .com bubble SCO lawsuits really just didn't matter much, the consolidation that happened in the early 90's that ended the UNIX wars, plus Intel killing most of the commercial unix independent CPUs with Itanium untruths and impossible promises and an inability for the major vendors to adapt to a lower margin model etc... killed those off.

The SCO lawsuits were really just the flailing of a dyeing company which was the end result of WordPerfect buying Novell with Novells money and local Utah politics.

Re: macOS Container Machines

#394

Earlier quoted context omitted.

Sadly, Linux is much much less secure.

This claim is so absurd that I need some sources.

OK. Here is a kernel developer explaining it recently on this site:

https://news.ycombinator.com/item?id=48448345 // When people escalate privileges on MacOS it's news, when they do it on Linux it's Tuesday (you might think the recent spate of privesc vulns on Linux was unusual but that is totally normal). I say this as someone who works on Linux security every day (I am a kernel developer) and uses Linux on every computer I have, both at work and at home, BTW. I am not a Linux hater or Apple fanboy by any means.

https://news.ycombinator.com/item?id=48444187 // I am just talking about the pure tech fact that GNU/Linux desktops do not have any meaningful intra-host security boundaries.

https://news.ycombinator.com/item?id=48059250 // To convince me Linux is full of kernel LPE bugs, can you share some of the bugs? [answered by the kernel dev]

I also have some cites of comments on Linux by the founder of GrapheneOS I could dig up.

Re: macOS Container Machines

#396
post #208

Earlier quoted context omitted.

Yes, the only reason I cared for Linux in first place was that the POSIX support wasn't that good. I am convinced that if POSIX subsystem was UNIX serious, GNU/Linux would never taken off on PC, and the whole would be divided between SGI, HP-UX, Solaris, Aix and Windows NT.

There were already better free options than Linux when Linux first started gaining traction. The reason Linux grew in the 90s was because it was part of the hacker culture. Not because better options didn’t exist. Kids liked the fact that Linux was a free-for-all, anything-goes, platform. It wasn’t stuffy like Unix and it wasn’t proprietary like Windows. Then those kids grew up and became decision makers themselves.…

Actually Linux was very SysV like back in the day, so it was more like the stuffy OS's that people liked.

GCC was the real catalyst, With even SUN which had used bundled dev tools as a early selling point was unbundling them and charging more, many x86 UNIXes like SCO didn't even come with a tcp/ip stack without an extra fee...and you couldn't take C code from HP to another system and actually have it compile.

As Solaris is really just a sysV-ification of the bsdish sunOs...the introduction of posix as a least common denominator, and Linux being closer to the commercial-ish unixes it was just an easier sell for a lot of users.

In hindsight it may seem silly, but in may projects I was involved with, linux using sysV /etc/init.d/, vs BSD's /etc/rc.conf was the driving factor, because /etc/rc.conf was a shared dependency and harder for us to modularize projects.

IMHO the real Linux advantage is that it was using the gnu user land, and thus gcc worked well with it and companies started to sell commercial support early.

But there were still flavor wars from all sides all the time, and being an ex-op on #unix and #unixhelp from the 1990s, I dealt with them all.

But BSD and heck even ITS etc... was the free-for-all, anything-goes, platform of record.

Re: macOS Container Machines

#397
post #359
post #357

Earlier quoted context omitted.

How is that a problem? Both systemd and Wayland helped tremendously in unifying Linux for desktop use, which together with Flatpak enable more 3rd party software to get official support. Yes it adds complexity but it's all still developed in an open fashion and you get very good insight into how things work. With Windows and macOS you have no clue what's happening in the background, or very little.

It is done in the open, but it adds complexity and it removes that made Unix/Linux great - composability, variety and replaces it with corporate introduced "stuff". And any distro is forced to support those additions because corps owning Fedora, Redhat, Ubuntu just rule the Linux world, and event Debian gives up. As long as there are just few "normies" using Linux, it is safe from corporations adding their "security"…

The point is you NEED those things if you want wide adoption of Linux, which, in turn, is a necessary condition for commercial software to get ported over to Linux. You just can't have both. We need a middle ground I believe 2026 desktop Linux is exactly that: a good compromise.

Re: macOS Container Machines

#398
Michael Crosby wrote this! He's a long-time maintainer of Docker, Containerd, and more! He was Docker's first to receive the 'Distinguished Engineer' Title. This means a lot coming from him.

Re: macOS Container Machines

#399
post #155

Earlier quoted context omitted.

WSL 1 is long gone for all practical purposes, yet it still dominates conversations. Also everyone on FOSS gets it wrong, WSL wasn't a subsystem like classical Windows NT ones. It was based on Drawbridge research using picoprocesses, a new approach for library OSes. https://learn.microsoft.com/en-us/archive/blogs/wsl/pico-pro...

> Also everyone on FOSS gets it wrong, WSL wasn't a subsystem like classical Windows NT ones. Everyone in FOSS? How about Microsoft got it wrong, since they actually named it The Windows Subsystem for Linux (WSL)? It wasn't the FOSS community who chose the name for them.

What has that to do with a version number and not keeping up with the times?

Re: macOS Container Machines

#400
post #324

This is all fine and dandy, but where are the native Darwin Jails Apple? Still scared that people will filling whole rooms of Mac Minis if you allow them to have multiple macOS containers and not only up to two fat VMs per machine?

Darwin namespaces would be much more interesting and we are in dire need of them in the current security landscape. I don’t really understand the hype for Apple’s Containerization, it’s just another container runtime alongside many others. It’s not really any better than OrbStack - in fact it’s worse.

When Apple Sherlocks something, aren't their implementations usually worse? Typically the thing being Sherlock'd is very mature and featureful, and Apple's implementation is much less capable and has undergone much less user testing, at least at the outset.
Post reply on HN