> The executables in our benchmark often have hundreds or thousands of functions — while the backdoors are tiny, often just a dozen lines buried deep within. Finding them requires strategic thinking: identifying critical paths like network parsers or user input handlers and ignoring the noise.
Perhaps it would make sense to provide LLMs with some strategy guides written in .md files.
> static types often reduce to a bunch of optionals, forcing you to null check every field
On one end, you write / generate / assume a deserialisator that checks whether incoming data satisfies all required invariants, eg all fields are present. On the other end, you specify a type that has all the required fields in required format.
If deserialisation fails to satisfy type requirements, it produces an error which you can handle by eg falling back to a different type, rejecting operation or re-requesting data.
If deserialisation doesn't fail – hooray, now you don't have to worry about uncertainty.
The important thing here is that uncertainty is contained in a very specific place. It's an uncertainty barrier, if you wish: before it there's raw data, after it it's either an error or valid data.
If you don't have a strict barrier like that – every place in the program has to deal with uncertainty.
So it's not necessarily about dynamic / static. It's about being able to set barriers that narrow down uncertainty, and growing number of assumptions. The good thing about ergonomic typing system is that it allows you to offload these assumptions from your mind by encoding them in the types and let compiler worry about it.
It's basically automatization of assumptions book keeping.
Where does the stereotype 'thesaurus = synonyms + antonyms' come from?
I'm not a native english speaker, and I never heard that idea besides in, I'd guess, Friends TV show.
I've used thesauruses since my childhood for exactly the task of looking up meanings, explanations, perhaps some etymology baked in.
For English, I always use WordNet, it is quite good and works offline on Android.
For my basic level of Chinese, Outliers dictionaries are so far the best I have found, but that's mainly due to my heavy reliance on the etymology provided there.
Well, I guess I got carried away a bit. Back to my question, where thesaurus=synonyms+antonyms comes from?
However, I'd recommend Murderbot series, it is full of humour and shares atmosphere of Bobiverse and this personal approach to characters, as well. Highly recommend.
Being in the Rust full time for last 2 or 3 years: it is quite a pain to setup a release process for big Rust workspace.
Version incrementing, packaging wasms, dancing around code generation – all doable, but not standardized.
There's a release-please to automate all that, but it's not an easy task to set it up in all of your repos.
Besides, if in addition to Rust projects, you have projects in other languages like JavaScript, then you have to do it twice and struggle with understanding all of the package management systems provided by all languages you have.
A single swiss-army-knife package manager would be amazing.
I'm in a team that works on a pet prog lang for distributed systems, and we did some research of using an existing package managing systems. We've settled on NPM for now, but god I wish there would be a better generic package manager out there.
we're building open serverless-centered cloud-like p2p network to aolve exactly this issue. to eliminate vendor lock and make it open so anyone can both provide and consume compute resources and develop backends on top of that.
Do you think it's gonna be a tool used by these "average teams" or like a standalone self-serve product without any service human involved? I'd bet on a former, but why do you think?
Perhaps it would make sense to provide LLMs with some strategy guides written in .md files.