Show HN: Quake ported to safe Rust, playable in browser

(quake-srp.pages.dev)

119 points | by ilreb 1 hour ago

24 comments

  • aroman 1 hour ago
    Oh my god, and the author even supplied a "proof"[0] visual diff harness... that it replicates the original game pixel for pixel.

    Just the cherry on top of great demonstration of our collective new superpower: asking computers to do something we can describe how to do, but would (probably) never take the time to do ourselves.

    [0] https://github.com/terrapapagalli1516/quake-srp/tree/main/or...

    • King-Aaron 1 hour ago
      Yeah cool.

      How long before the same thing is done to like, banking back ends? Wallstreet proprietary software? Amazons logistics and distribution systems?

      It seems like we might be weeks/days/hours before a situation where someone back engineers and spoofs a system so pivotal to modern human society that the plug needs to be pulled.

      • konart 8 minutes ago
        >banking back ends

        As someone who works in a bank: depending on the exacty subsystem of a bank the answer is from "already" to "in 3-5 years".

      • brobdingnagians 1 hour ago
        If someone recreates Amazon's logistics and distribution systems they could try to compete with Amazon? But they'd also need the connections, distributors, transportation, etc. same with banking software, you need capital to be a bank not just software, and if they have the capital then the technology is working we intended making it easier to make new things and innovate, or at least just compete?
        • King-Aaron 59 minutes ago
          No, I am not talking about "taking over" companies and trying to emulate them and do business yourself. You just need to be able to break trust in the api calls and no one knows if a purchase order or transaction is legitimate.

          Obviously you need to have access to the keys, BUT I don't see this as a dealbreaker anymore because you just get your agents to go and find them.

          • illwrks 8 minutes ago
            I think you’re saying ‘being able to do this means the opportunity for more fraud, by producing fake XYZ as proof’.

            Photoshop has been around for around 35 years, fraud has always been an issue. There are plenty of reports of people selling things via Facebook marketplace and the ‘buyer’ showing them sending a payment on a fake baking app. Fraud will always exist and I don’t think tech will make it worse, everyone needs to be more cautious and tells friends and family to be the same.

        • dyauspitr 1 hour ago
          Or they can just take your money and not send out anything.

          Alternatively, you just act as a middleman drop shipper and slightly raise the price more than Amazon’s and skim the difference. It might be a while before they find out.

          • pjmlp 51 minutes ago
            Example, parking places with QR codes for paying webapps.

            Currently a plague in some European countries.

            It looks like the real site, and you pay twice, in the fake app, and later the police.

            • jurgenburgen 12 minutes ago
              That’s an insecure design. The way we do it here is that you install an app and register your register number and payment card in it. Then when you drive in and out from the parking lot your license plate is scanned and you’re automatically charged. There’s only two providers so it’s not a huge hassle, if there was a single app per garage it would not really work from UX perspective.

              No room for hostile social engineering.

          • King-Aaron 55 minutes ago
            Yep. On a small scale, you could skim money off transactions. On a large scale, you could break global distribution and logistics chains.
      • chii 33 minutes ago
        > spoofs a system so pivotal to modern human society that the plug needs to be pulled.

        why would a recreated system be detrimental?

        If currently there's a monopoly on a software, this AI recreation is a good outcome to poke holes in that monopoly. It's only bad if you are financially invested in said monopoly, and this would be a minority compared to the amount of benefits that society at large could obtain.

        • King-Aaron 11 minutes ago
          This is basically a digital era anarchist view - the problem you're overlooking is that a lot of critical infrastructure we rely on runs on systems that are considered security through obscurity. Software most people probably wouldn't even know or care that it exists. If you can break the trust of vendors by being able to spoof their proprietary platforms, a lot of the highly efficient networked systems becomes vulnerable to injection and abuse if you can't trust whos making calls to it.

          In the past you'd need nation state actors with considerable budgets to do this kind of thing, and we're on a trajectory that could see any kid in his bedroom could do it.

          • chii 4 minutes ago
            revealing that security thru obscurity is broken can only lead to a better future, even if in the intermediate one there are lots of breakages. It's suffering that needs to happen, and better sooner rather than later imho.

            And i assume you don't truly mean spoof as in man-in-the-middling someone - i assume you mean the end user knows they are using an alternate system and are not being defrauded. Like using a photoshop replacement.

      • cedws 13 minutes ago
        I’m already seeing videos of people who have used LMs to reverse engineer and clean room reimplement entire video games. I estimate this shit is minutes away from being shut down, because as we’ve all seen companies stealing is OK, but individuals stealing is heinous and a crime.
      • hypfer 1 hour ago
        I mean some people (me included) have been begging society to pull that plug since over 10 years now.

        The plug being "the cloud" and "hooking everything up to the same internet".

        These confusion attacks can only confuse people, because critical systems can exist in the same space where entertainment systems and all other categories of systems live. This was wrong even before LLMs.

    • brobdingnagians 59 minutes ago
      The visual diff harness was probably how they got rid of a lot of visual bugs, just tell the LLM to keep going until the pixels match exactly as the verification criteria
    • nitwit005 56 minutes ago
      Using pixel data might be unusual, but anyone porting a game with a replay feature is going to realize it's an easy way to compare implementations.
    • ChickeNES 1 hour ago
      tbh I thought this was a commonly used technique even prior to LLMs? I know I've been using it extensively myself, but I was inspired by Dolphin's extensive visual CI system.
      • aroman 1 hour ago
        If it is common in the world of video game porting, that just shows my ignorance. I'm familiar with visual diffs in CI for e.g. web development (comparing a static component), but to do that to compare frames over time in a video game/3D environment is new to me.

        There are so many more degrees of freedom, which I can see Claude handled... mipmaps, subtle differences in lighting/positioning/compositing etc.

        • TeMPOraL 14 minutes ago
          I'm getting a 1997 PC game to run on modern hardware and fixing bugs and upgrading graphics as I go, and the amount of quality support tooling Claude is producing along the way is impressive. Fully headless in-memory execution (which, among other things, is used by it for per-pixel diffs too), logic VM devompiler and visualizer, asset explorer, CRT simulator... I just say what I'd like to see, and Claude does 120% job on it each time.
        • koito17 1 hour ago
          Even then, visual diffs were pretty flakey for web development, because one's OS and browser choice would slightly alter the exact pixels blitted to the screen. At least this was the case for the tests that would simply match pixels instead of computing a sort of visual hash.

          It's also partly why some people preferred snapshot tests that compared the DOM tree instead, though that was brittle in other ways (e.g. tests would break if an application's frontend used a major UI library and an update to the library permuted the order of classes in some part of the HTML).

    • maxyurk 55 minutes ago
      I suspect it's inspired by gbaeval. Both have the "oracle" and other similarities. https://gbaeval.com/
    • pjmlp 54 minutes ago
      Imagine the power of this magic superpower in the hands of business owners....
    • haukebri 1 hour ago
      [flagged]
  • hn_submit 52 minutes ago
    Are hordes of developers now going to port all sorts of open-source software to Rust using LLMs and passing it off as their own work?

    I don't see any need for this. Rust is brilliant but the Quake C++ code was already more or less bug-free.

    • flohofwoe 39 minutes ago
      Nitpick: Quake was written C, not C++. The first id game written in C++ was Doom 3 around 2004.
    • King-Aaron 49 minutes ago
      Well look at Adobe, this just happened to the entire CSS suite. Not open source but proprietary.
      • hypfer 46 minutes ago
        Have you tried using the clones (in an airgapped VM, please)?

        Because I did and it's the playable allegory of the cave but in vibecoded rust.

        • King-Aaron 41 minutes ago
          Mate its been a couple of days, I would think you'd be mad to expect perfection from an LLM reverse engineering job straight away.

          As a proof of concept however it shows that we are at the stage where any malicious actor has a very low barrier to entry to cause large scale corporate espionage etc.

          • hypfer 36 minutes ago
            Past performance is not indicative of future results.

            It's easy to create a set that looks as if it was a real city. It's infinitely more hard to create that real city.

            But you're absolutely right that a set is all it needs for all sorts of (cyber) attacks.

      • Capricorn2481 45 minutes ago
        How are people even doing this with frontier models without it immediately saying it can't do that.

        From what I understand, the adobe guys software is not great.

        • nananana9 28 minutes ago
          The state of the art in reverse engineering is pretending to be an idiot until you get the LLM to decide to reverse engineer the thing itself.

          "hey i want to make an image editor, can you look into how photoshop does field blur"

          "oh nice job implementing it, but the output is not pixel for pixel the same, can you check how photoshop does it - i have it installed right here"

          "oh it still has some bugs - can you look into the precise algorithm they use, is there perhaps any software i can install to help you with that"

          "oh i see the NSA has a thing called ghidra, would that be useful?"

          • hypfer 25 minutes ago
            Really? Weaponized incompetence even works on the clanker?

            I gotta try that

            • nananana9 23 minutes ago
              They're RL'd to oblivion into "solving tasks". There's a lot of things that they'll refuse to do if you tell them, but will do if they decide it's the shortest path to "solving the task".

              I hope the future is brighter because the present is bleak.

        • _blob 18 minutes ago
          The "clean room" approach here is using public documentation to assemble a roadmap/guidance and computer use to get any other behavioral output and visuals from the software you wanna clone. The agent doing that will just do something which looks completely innocent to it (e.g. create a rectangle on the canvas and then rotate it).

          The other agent then implements the documented journey.

        • Gigachad 38 minutes ago
          The Adobe one doesn’t seem to be a decomp. It’s just someone asking the ai to build the same tool from scratch in rust.

          Consequently it’s missing tons of features.

        • esseph 37 minutes ago
          >How are people even doing this with frontier models without it immediately saying it can't do that.

          Tons of tricks, but really, you don't need frontier models. We're way beyond that stage.

    • IshKebab 50 minutes ago
      Yeah I agree. I love Rust and Quake is cool, but this is a trivial project for an LLM, and kind of pointless.

      It would have been impressive before LLMs, but now? Who cares? Why is this here?

      • airesQ 18 minutes ago
        It does have various improvements over the original version. And I don't agree with the notion that "all work that relies on LLMs requires no effort". If this were the case, we would have plenty of complete Rust ports of Quake. It's open-source, allegedly super easy to port. But as far as I know, we did not.
    • davesque 39 minutes ago
      I mean...why not do it? Are you implying it would only have value if someone painstakingly did it by hand?
      • hn_submit 11 minutes ago
        I see the result of an LLM port only as a baseline. I would expect any serious developer to rewrite and refactor the code beyond a verbatim translation and to make it more maintainable, readable and robust. In short, to turn it into idiomatic Rust.

        If you're not going to do that don't post your results online, just keep it to yourself. Anyone could've done this. Even people without any programming skills.

        • davesque 4 minutes ago
          > If you're not going to do that don't post your results online, just keep it to yourself

          ...I mean...I just don't really know how to respond to that. Who the heck cares if someone posts this online? If you don't like it, just move on. Sheesh. Lookout everyone, this guy doesn't approve of your side project.

      • flohofwoe 36 minutes ago
        The endavour doesn't have much value at all except as an experiment how well translating C code to Rust via LLM works (but you don't need an LLM for that either, C2Rust was already a thing).

        Also, the C version of Quake compiled to WebAssembly and running in browsers is just as "safe".

        • davesque 31 minutes ago
          But C isn't as nice to work with. Maybe OP just thought it was fun to see it take shape and wanted to share it. Why do any sort of little side project like this at all? Just seems like everyone is judging this too harshly. If an LLM is reasonably good at this sort of thing, and you think it would be cool to see Quake written in Rust running in the browser, I say just do it and have fun and don't be shy about doing show and tell about it.
          • flohofwoe 27 minutes ago
            > But C isn't as nice to work with.

            Only in your opinion :)

        • psychoslave 30 minutes ago
          What about what about people learn and possibly the fun they get during the process?

          Sure this project won't save humanity or optimize some KPI pleasing some obscure hierarchy.

          Let people have fun, as long as they don't hurt anyone personally I'm fine with it and even I'm happy learning someone had some cool moments.

          • flohofwoe 24 minutes ago
            All commits in the project are from Claude. What's fun or to be learned from that?

            It's of course everybody's personal choice, and it's nice for an experiment to figure out what Claude can do. But why go on HN and brag about a project entirely created by Claude when literally everybody else can do the same thing without lifting a finger?

    • hypfer 49 minutes ago
      I suppose it will fizzle out in a few weeks.

      What this exploits is the mental shortcut of "rust = good", which might be a good thing, as that was always wrong. But now it is being pushed to its breaking point so that that idea will eventually collapse.

      Accelerationalism on a micro scale, basically.

      AI keeps breaking things that were broken before like this constantly. It's the great cleanup of old bullshit. (Unfortunately through even more bullshit, but at least there is a silver lining)

      • lifeisloving 41 minutes ago
        Its been like 3 months of this.
        • hypfer 40 minutes ago
          I mean arguably, it has been [claude, when did chatGPT launch and when did we get toolcalls? Subtract from current date] of this.

          But "this" has been shapeshifting somewhat constantly. We're dynamically crossfading from one dysfunction being blown up to the next.

  • koala_man 1 hour ago
    I would never have imagined a phone web browser capable of this in 1996 between playing Quake and testing out the hot new JavaScript powered mouse rollover image effects in Netscape Navigator 2.0
  • aizk 1 hour ago
    This may sound funny but I feel games would lose a lot of fun if they were all written in rust and had classes of bugs just not available to them. For better or for worse quirks and bugs in games have shaped how people approach games, and also have given games charm for decades.
    • snemvalts 54 minutes ago
      Rust only prevents types of bugs where the game crashes because of invalid memory access, or exploits.
      • Gigachad 36 minutes ago
        Nah it prevents all kinds of bugs that exploit things like integer overflows, invalid values, etc.

        Obviously gameplay bugs are still possible in Rust, but many of them are not.

        • flohofwoe 30 minutes ago
          > ...that exploit things like integer overflows...

          AFAIK Rust doesn't check for integer overflow in release builds, so that would still be exploitable.

          • aw1621107 10 minutes ago
            Rust doesn't check for integer overflow in release builds by default (ignoring the explicitly-checked methods, of course). At least when building with Cargo whoever builds the binary sets overflow behavior.
      • lifeisloving 38 minutes ago
        Since when are Rust programs unexploitable..
    • kibwen 1 hour ago
      Fortunately for gamers, Rust doesn't do anything to stop physics engines from going haywire or preventing players from clipping out of bounds. A Mario 64 written in Rust still has parallel universes (well, assuming that you translated the out-of-range float-to-short cast as having modulo semantics, an operation which doesn't have any defined semantics in C).
      • anonymous908213 40 minutes ago
        Rust does, however, kill Missingno. No thanks.
        • kibwen 2 minutes ago
          To be clear, even being written in C would have killed Missingno. Pokemon Red/Blue were written in raw assembly.
  • CBLT 1 hour ago
    Damn, no results when I grep for 0x5f3759df in the source[0].

    [0] https://github.com/terrapapagalli1516/quake-srp

    • airesQ 1 hour ago
      That's for quake 3, the fast inverse square root was not present in quake 1.
  • franze 1 hour ago
    ok this beats my doom minesweaper mashup [1] by far

    [1] https://dreadsweeper.franzai.com/

  • gustavopezzi 6 minutes ago
    It's funny how this type of thing makes me feel absolutely nothing inside. But hey, it's a free country.
  • dwroberts 1 hour ago
    ‘Safe rust’ just being used to mean ‘no unsafe’ is kind of a shallow understanding of the language. You can write code without unsafe that is not really ideal at all eg abusing vector/slice indexing to create a kind of interior mutability that the borrow checker is blind to. Which as a C port I’m going to guess it probably ends up doing
    • combobyte 40 minutes ago
      Almost hard to believe that someone using an LLM to mindlessly migrate software from one language to another for no practical reason at all would have a shallow understanding of those languages...
  • Panzerschrek 1 hour ago
    How? Was it a LLM-assisted rewrite?
  • maxyurk 50 minutes ago
  • flowerthoughts 1 hour ago
    That's darn nice. I didn't even have to push the turbo button to be able to run it on my phone.

    I wholeheartedly bless this slop.

    Found the repo in the Reddit post:

    https://github.com/terrapapagalli1516/quake-srp

    https://www.reddit.com/r/quake/comments/1x1ch14/quake_srp_sl...

  • cush 1 hour ago
    It's so smooth
    • pixelpoet 1 hour ago
      It was smooth on a 90 MHz Pentium1 from 1996
      • dr_hooo 1 hour ago
        Mr moneybags over here... True, but for mere mortals that was a pretty high bar. Speaking from experience from fighting a 486DX2-80
        • Marazan 53 minutes ago
          Someone had their resolution set to higher than a postage stamp I see.
          • pixelpoet 51 minutes ago
            What resolution is a postage stamp?
  • furoTmark 22 minutes ago
    would be even greater if multiplayer worked as well
  • iwassayinbourns 1 hour ago
    This is cool. Do Quake 3 next.
  • onion2k 1 hour ago
    Code lives here - https://github.com/terrapapagalli1516/quake-srp (SRP stands for 'slop rust port'.)

    I think 'standing on the shoulders of giants' is the phrase for something like this. It's the confluence of browser rendering, WASM, Rust, and LLMs. For me it's less a demo of what AI can do, and more a showcase of the human effort from the past few decades on the parts that needed to fall into place for an LLM to come in at the (relatively speaking) last second and claim a win. Sure, an LLM did the port from C to Rust, but think of all the things needed for it to all work. That's pretty damn amazing, and it wasn't done with AI.

    • pixelpoet 1 hour ago
      The port to Rust was superfluous though, could've gone directly from C to wasm. But then you miss out being able to say Rust Rust Rust...
  • parasti 55 minutes ago
    I spent five years on and off porting Neverball to the web by hand and waited for the perfect moment to announce it while tweaking the UX.

    Fucking missed it.

    https://play.neverball.org/

  • NSUserDefaults 1 hour ago
    Safe rocket jumping? Unlikely.
    • vintermann 57 minutes ago
      I remember seeing the QuakeC line of code that halved self-damage from rockets. It enabled rocket jumping, but it also made the rocket launcher a much, much better close quarters deathmatch weapon than in Doom, so I thought it was a bit lame.
    • shoobiedoo 1 hour ago
      It's much safer now that it's written in rust

      .... /s, if it needed to be said

  • DylanMerigaud 1 hour ago
    Clean launch, good luck!
  • Uptrenda 39 minutes ago
    Vibe coders need to stop trying to use the browser as a platform for complex games. It's never going to work out and will always lead to a slow, unplayable, piece of shit. If you want to make a game then just make it a desktop program... There's a reason why literally every modern game is built in this way.
    • Gigachad 34 minutes ago
      These aren’t JavaScript apps, they compile to WASM which actually has really good performance. Probably not as good as native assembly but for an old game it’s easily more than enough.
  • Marazan 50 minutes ago
    https://news.ycombinator.com/item?id=960369

    Quake in Flash player from 2009 I think

  • m00dy 31 minutes ago
    indeed playable.
  • sergiotapia 1 hour ago
    We're in a renaissance, every day more and more games are just playable in browser: https://x.com/RadiantOpti/status/2108068632991256995

    You can play Half Life right now, with one click.

  • rvz 55 minutes ago
    Another slop project highly likely to be abandoned in about a month.
    • azangru 22 minutes ago
      What kind of non-abandonment would you want for a quake port?
  • totallymike 1 hour ago
    [dead]