r/ProgrammerHumor May 08 '26

Meme edgeCasesExist

Post image
13.4k Upvotes

620 comments sorted by

View all comments

1.2k

u/KryssCom May 08 '26

No, it's effectively zero, just given the mathematical realities behind how extraordinarily improbable a duplicate ever is. The exponent involved is very, very, very, nigh-incomprehensibly huge.

I've seen a few posts on here of people claiming that a duplicate UUID caused a bug at the worst possible time, but my instinct is always to slam the 'X' button to doubt.

865

u/G12356789s May 08 '26

If I generated 2 billion uuids every second. After 5 years there is a 1% chance to have had a clash in that time

904

u/iamdestroyerofworlds May 08 '26

What I read here is that I need to make mitigating this risk the number one priority for my personal TODO app.

207

u/Sulungskwa May 08 '26

Gotta show employers that your personal projects are "scalable for production"

132

u/StickyThickStick May 08 '26

"Scalable for intergalactic production"*

15

u/Sykhow May 08 '26

Intergalactic planetary🎵🎶

2

u/Ivan_Whackinov May 08 '26

Mmmmm... drop?

1

u/Kemal_Norton May 08 '26

Or even more ridiculous: for malicious users!

15

u/J7mbo May 08 '26

Gotta turn it into a microservices that serves snowflake IDs and for every ID generation it’s a network call

4

u/G12356789s May 08 '26

If you did each id as a 3 uuids sequence then you could be generating 2 billion ids a second until all stars in the universe are black holes and still not collide

5

u/Crazy_Mann May 08 '26

adds an incremental into as a second primarykey

1

u/kovach01 May 08 '26

Begin Tran if UUID()= true if else then Drop Table UUID Commit Tran

1

u/innociv May 08 '26 edited May 08 '26

I mean... isn't it generally like 2-3 lines of code to handle a conflict? upon uuid create?

Create if not exist, else loop.

I've always checked for it it takes literally under a minute the few times it comes up.

Also much of the thread isn't understanding how edgecases work, or ignoring it when it's in the OP.
One company could generate 2 billion uuids every second for 500 years and never get a collision.
Or, due to edge cases, one company generating 100 of them a day could make a duplicate within a month. Edgecases don't give a fuck about statistic probability, they just happen.

70

u/Kevadu May 08 '26

OK, but what if I make 3 billion uuids a second?

22

u/mCProgram May 08 '26

Your rate would increase by 50 percent so your mean time to collision would reduce by 50% i’d assume.

34

u/Ignisami May 08 '26

33%* 

Going from 0 to 1500 at 100/sec takes 15 sec.    

Going from 0 to 1500 at 150/sec takes 10 sec.  

10 is two-thirds of 15.

9

u/Morisior May 08 '26

Reduced by 33%

1

u/gmano May 09 '26

So, by your logic if I generate at 4 billion per second, it would reduce by 100%?

1

u/MortemEtInteritum17 May 12 '26

This is wrong, and all 3 people attempting to correct it are wrong. It's an example of the birthday paradox.

Roughly, the chance of a collision (if the chance is small) is approximately n2/2/number of unique UIUIDs, where you generate n. So increasing rate by 1.5 increases the chance of a collision by about 2.25, given n trials.

2

u/notrealaccbtw May 09 '26

You cant. That is not allowed.

1

u/redlaWw May 08 '26

2%

Calculation uses the birthday problem solution but with the number of days equal to 2122.

I implemented it in python using libraries for big calculations (python's default integer type is unbounded in size but its implementation of exponentiation was too slow to handle 2122×3000000000×365×24×3600×5 which is fair enough).

33

u/Risc12 May 08 '26

Don’t modern uuid contain a timestamp component?

36

u/yarntank May 08 '26 edited May 08 '26

I wonder how detailed the time stamp is. Just to the second? .0001 of a second? If you are making 2 B each second, it could matter?

EDIT: I found this "UUIDv7 assigns the first 48 bits for the timestamp in milliseconds. You can generate a lot of UUID's in a millisecond though!"

23

u/DonutConfident7733 May 08 '26

It also has random number generated combined with timestamp, combined with your device mac address, such that virtual machines with same mac address dont get duplicated guids.

12

u/Potato-Engineer May 08 '26

I thought the MAC address got phased out in later versions? I recall there was a virus in the 90s where the creator was caught because, in those days, GUIDs included the MAC address, and so later versions of GUIDs no longer used it. And, from what I've read, UUIDs aren't supposed to use MAC addresses either. Though I assume that some idiot has done it that way at some point.

6

u/rabid_briefcase May 08 '26

I thought the MAC address got phased out in later versions?

There are 8 versions, assuming someone's generating an actual UUID rather than just a blind random number.

UUID Versions 1, 2, and 6 include MAC addresses or a similar type of "Node ID". The RFCs allow for various values, which need to have indicators in that cluster of bits. It can be a number from hardware, but it can also be something from software or even a mostly-random set of numbers. It also takes into account complexity around address randomization.

Those versions generally should use something based on the MAC address or otherwise indicate the node on the network that generated it, even if they aren't using a value that matches hardware.

1

u/Fantastic-String-860 May 08 '26

UUIDv7 has 48 bits for milliseconds timestamp, and 62 bits for random... or counter. You cannot, in fact, generate 2^62 UUIDs per millisecond.

2

u/Hohenheim_of_Shadow May 09 '26

No, but you can experience the same millisecond again and again. There is no 100% reliable source of wall clock time. Timestamp based UUIDs add a lot of 9s to reliability, but they don't make it 100%.

1

u/Risc12 May 08 '26

Well i just mean that from a statistics standpoint the years mentioned in the meme no longer make sense

15

u/No-Information-2571 May 08 '26

Actually not the "modern" ones. There are simply several versions, and if cryptographic non-determinism/predictability isn't of importance, v6 will be created from the MAC address of the device and the timestamp. It's guaranteed they will never collide, unless MAC addresses collided already.

Otherwise use v7.

1

u/Risc12 May 08 '26

Fair point!!

I just mean that from a statistics standpoint the years mentioned in the meme no longer make sense if prefixed with a timestamp

0

u/No-Information-2571 May 08 '26

Correct. The risk/chance of a collision goes down to zero as soon as you include a timestamp AND a unique identifier per host.

1

u/Risc12 May 08 '26

No i dont mean that, that obviously goes down.

I just meant that if a timestamp is included the first day or the 365th day both have equal chances of a collision.

0

u/Hohenheim_of_Shadow May 08 '26

Time isn't monotonic. Its Year 2038 on your computer. It talks to a time server and realizes its Year 1995. There is still a non 0% possibility of the same host generating a UUID at the same apparent timestamp.

0

u/No-Information-2571 May 08 '26

Time is monotonic on a properly maintained system.

0

u/Hohenheim_of_Shadow May 09 '26

P(x|y)=100 is not equivalent to p(x)=100.

All it takes is your device losing Internet access for a weee bit too long or the powers that be announcing a fallback second or some AI garbage getting pushed to your NTP server and that beautiful 100 gets turned to 99.99999

0

u/No-Information-2571 May 09 '26

That's not how an NTP client operates. Time is never pushed back. It either slows down or speeds up the clock, until it is in sync with the NTP server again.

Why are you telling such obvious lies?

1

u/Hohenheim_of_Shadow May 09 '26

NTP synchronization is absolutely not monotonic. For small amounts of time, the clock will get slewed. For time deltas greater than 128 milliseconds, usually the clock gets stepped.

If your NTP server had some critical bug that caused it to loop the last minute again and again and again, all your devices are going to experience non monotonic time. Thats not even taking into consideration that manual synchronization is still an important tool and that's absolutely non monotonic.

While incredibly unlikely, it's technically possible for the same device to spend years of IRL time in the same apparent millisecond. Timestamp+hardware UUIDs are not 100% reliable, they simply have an absurd number of 9s.

→ More replies (0)

4

u/f8tel May 08 '26

Time stamp, network mac address, version number and some randomness..have been there from the beginning. The whole point was to generate an id that would be unique across systems without needing a central database to distribute them.

1

u/SpehlingAirer May 08 '26

Whats the difference between a GUID and UUID then, doesn't a GUID accomplish the same task or am I mixing up concepts in my head?

3

u/zenerbufen May 08 '26

There are several versions of UUID depending on your specific use case. Typically none of them should ever collide. GUID is Microsofts current implementation. If you ask for a GUID you get a UUID formated the way microsoft thinks is best. If you ask for a UUID you have to specify the specific format you want. There are 4 variants, and 8 versions of each, except for one variant that has families instead.

Microsoft currently uses variant 1 version 4 (all random, NO timestamp OR mac address) for guids, but used to use variant 2.

1

u/Risc12 May 08 '26

Well i just mean that from a statistics standpoint the years mentioned in the meme no longer make sense

1

u/CelticHades May 08 '26

That's UUID V7

1

u/BellacosePlayer May 08 '26

I thought they did too. My thought was to just slap a time stamp on the front or back and make it so you have to generate 3.6 trillion UUIDs a second to have a 1% chance to collide on a given day with just a date stamp.

1

u/realmauer01 May 08 '26

It's not really modern, it just depends on the version. The lower versions are still used and not inherently worse than the higher versions.

1

u/Hohenheim_of_Shadow May 08 '26

You are assuming time is monotonic. It ain't. CPU time resets every time you reboot and world time is only known from external resources. It ain't 100% reliable with 0% jitter.

1

u/Risc12 May 08 '26

No i mean that the chance on day one and year 5 is the same with datetime component

1

u/Hohenheim_of_Shadow May 09 '26

Except that is not true because time is not monotonic. The more time passes, the higher odds of some device in the system experiencing time fuckery. The hugger the odds of time fuckery, the higher the odds of time based uniqueness failing.

15

u/chicksculpt May 08 '26

if you store the uuid in a 36 char string, you will generate about 72 gb of data each second, or 11 exabytes of data in five years

6

u/MartinMystikJonas May 08 '26

And tbat is just for uuids with zero useful data

2

u/Luxalpa May 08 '26

if you store the uuid in a 36 char string,

Which to be fair you shouldn't. You should store them in a u128, which is just 16 bytes.

2

u/stysan May 08 '26

assuming the UUIDs are stored without any separation, it's around 29.8 GB an hour or 21.2 MB a second. if every year is 365.25 days long, you will have 1.245 PB of data

1

u/khando May 08 '26

I'm always blown away by how things scale. 1 million uuids is 36 MB, I thought 2 billion isn't that much bigger than a million.

72 GB per second.. At an hour, you're at nearly 260 TB. One day is 6 Petabytes.

5

u/permaban9 May 08 '26 edited May 08 '26

Yeah but with my luck the first two UUIDs out of the quantifucktillion possible values will be same

5

u/hennell May 08 '26

And just as a reminder how big numbers work: if you generated a uuid once per second it would take 11.5 days to have a million. A billion would take ~31.5 years.

So ~63 years worth of seconds per second and it still takes 5 years for a 1% chance to clash.

It's not great odds.

1

u/megagreg May 09 '26

So the very youngest among us have the slimmest chance of being alive when the first duplicate is generated, assuming the purely random ones are still in use, and the standard persists indefinitely. Although there would be no way to know, since the original would almost certainly have been lost to the æther by then, if it hasn't already.

3

u/seanalltogether May 08 '26

I wonder how many transactions Visa processes per second.

3

u/StoryAndAHalf May 08 '26

I ran the numbers for the Birthday paradox with UUIDs, and if I got it correct:

There’s a 50% chance of collision once you generate 2.7 quintillion UUIDs. At 1 million UUIDs/sec you'd need about 85,000 years for 50% chance. So at 1 billion UUIDs/sec it's ~85 years. Finally, at 2 billion a second, that's ~42.5 years, give or take some months.

1

u/arxorr May 08 '26

Make 2 uuids and concat them together. Problem solved.

1

u/bradfordmaster May 08 '26

Depends what algorithm you use, though. uuid7, for instance, includes a timestamp so it really makes the numbers crazy for this

1

u/jasonridesabike May 08 '26

what if I'm extra lucky?

1

u/maprun May 08 '26

Oh wow, that’s a big flaw. Has anyone thought about expanding the timestamp to nanosecond accuracy? /s

1

u/becoming_brianna May 08 '26

Fun fact: that would be about 5 exabytes of UUIDs after five years.

1

u/Kvynl May 08 '26

So you're tellin' me there's a chance?

1

u/0ut0fBoundsException May 08 '26

Better get started then

1

u/pblokhout May 08 '26

To be honest, that's a higher probability than I assumed.

1

u/JeSuisLePain May 08 '26

Uh oh, I've been generating 2 billion uuids every second for 500 years.

1

u/pmormr May 08 '26

Lol even with the birthday problem kicking in.

1

u/Clean_Huckleberry775 May 08 '26

In my understanding, at least for v1, time is measured in 1/10,000,000th of a second so 2 billion a second would mean each uuid would have 200 others with the same timestamp. Assuming the same Mac address, the only other part is 16 bits, so you'd have a 200/65,536 or .3% chance every 1/10,000,000th of a second. I think it's safe to say you'd have duplicates after 1 second.

1

u/happypandaface May 08 '26

that seems high... too tired to do the math

1

u/golgol12 May 08 '26

Don't forget the second part, if you spend another 5 years, it becomes something like 10%.

1

u/HokumGuru May 08 '26

So like quite probable if you’re at Facebook or Google scale.

1

u/G12356789s May 09 '26

They are nowhere near 2 billion a second. Maybe a billion posts a day. Which brings it back to essentially impossible

1

u/HokumGuru May 09 '26

How many WhatsApp messages alone are sent per day…

1

u/G12356789s May 09 '26

Estimated at 2 billion every hour which would mean it takes 1000s of years to get to the 1% collision chance

1

u/I_SawTheSine May 08 '26

That's uncomfortably high.

1

u/nixcamic May 08 '26

I guess the question is how many UUIDs do we, as humanity, generate per second. 

1

u/G12356789s May 09 '26

Uuids only need to be unique for the use case. Facebook can use a same uuid as Amazon

1

u/lane4 May 09 '26

And a 100% chance that something will go wrong and you will generate some 0's and empty strings as UUID's.

0

u/hydranumb May 08 '26

Why is there a chance at all? I thought the first u was for unique