<?xml version="1.0"?>
<rdf:RDF
	xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:foaf="http://xmlns.com/foaf/0.1/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns="http://purl.org/rss/1.0/"
>
<channel rdf:about="https://deb.news">
	<title>Deb.News</title>
	<link>https://deb.news</link>
	<description>Deb.News - https://deb.news</description>

	<items>
		<rdf:Seq> 
		  <rdf:li rdf:resource="https://retout.co.uk/2026/07/10/blocking-distracting-news-links/"/>
		  <rdf:li rdf:resource="http://www.netfort.gr.jp/~dancer/diary/daily/2026-Jul-10.html.en#2026-Jul-10-18:04:45"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-07-10:/2026/07/new-developers-2026-07.html"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/synths/minilogue-xd/module/"/>
		  <rdf:li rdf:resource="http://blog.alteholz.eu/?p=2832"/>
		  <rdf:li rdf:resource="https://mjg59.dreamwidth.org/74260.html"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/0-06-105356-2a.html"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/journal/2026-07/001.html"/>
		  <rdf:li rdf:resource="https://bisco.org/notes/status-update-june-2026/"/>
		  <rdf:li rdf:resource="http://blog.sesse.net/blog/tech/2026-07-04-15-21_an_update_on_sesse_chromium_org.html"/>
		  <rdf:li rdf:resource="https://retout.co.uk/2026/07/04/aws-washington-summit-2026/"/>
		  <rdf:li rdf:resource="https://blog.jak-linux.org/2026/07/03/openssl-pandemic/"/>
		  <rdf:li rdf:resource="tag:www.chiark.greenend.org.uk,2026-07-03:/~cjwatson/blog/activity-2026-06.html"/>
		  <rdf:li rdf:resource="http://joeyh.name/blog/entry/no_LLM_code_in_dependencies/"/>
		  <rdf:li rdf:resource="https://www.decadent.org.uk/ben/blog/2026/07/01/foss-activity-in-june-2026"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/06/30#tl_0.0.2"/>
		  <rdf:li rdf:resource="http://joeyh.name/blog/entry/big_loads_offgrid_with_a_small_battery_sidelined/"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6226"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6220"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6214"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6212"/>
		  <rdf:li rdf:resource="https://blog.einval.com/2026/06/27#its_dead_jim"/>
		  <rdf:li rdf:resource="https://www.earth.li/~noodles/blog/2026/06/onak-0.6.5.html"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/1-6680-7812-0.html"/>
		  <rdf:li rdf:resource="https://www.jwiltshire.org.uk/?p=776"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/1-250-82701-9.html"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/06/22#tl_0.0.1"/>
		  <rdf:li rdf:resource="https://retout.co.uk/2026/06/21/sel4-repo-relationships/"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/06/21#rcpparmadillo_15.4.0-1"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6164"/>
		  <rdf:li rdf:resource="https://gwolf.org/2026/06/systemd-for-linux-sysadmins.html"/>
		  <rdf:li rdf:resource="https://grep.be/blog//en/computer/Agentic_coding_and_Free_Software/"/>
		  <rdf:li rdf:resource="159 at https://sunweavers.net/blog"/>
		  <rdf:li rdf:resource="http://joeyh.name/blog/entry/offgrid_electric_car/"/>
		  <rdf:li rdf:resource="http://joeyh.name/blog/entry/aiming_at_December/"/>
		  <rdf:li rdf:resource="http://joeyh.name/blog/entry/cheap_DIY_solar_fence_design/"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/06/16#rspdlite_0.1.0-1"/>
		  <rdf:li rdf:resource="158 at https://sunweavers.net/blog"/>
		  <rdf:li rdf:resource="http://www.luffy.cx/en/blog/2026-kpi-goodhart.html"/>
		  <rdf:li rdf:resource="https://retout.co.uk/2026/06/15/in-memoriam-commitemailpy/"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/06/14#rbenchmark_1.0.1"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/heroquest/"/>
		  <rdf:li rdf:resource="https://blog.tenstral.net/?p=2074"/>
		  <rdf:li rdf:resource="https://gwolf.org/2026/06/rey-ubu-carro-de-comedias-unam.html"/>
		  <rdf:li rdf:resource="157 at https://sunweavers.net/blog"/>
		  <rdf:li rdf:resource="https://retout.co.uk/2026/06/12/sel4-clock-magic/"/>
		  <rdf:li rdf:resource="156 at https://sunweavers.net/blog"/>
		  <rdf:li rdf:resource="tag:www.chiark.greenend.org.uk,2026-06-10:/~cjwatson/blog/activity-2026-05.html"/>
		  <rdf:li rdf:resource="http://www.luffy.cx/en/blog/2026-blogging-llm.html"/>
		  <rdf:li rdf:resource="155 at https://sunweavers.net/blog"/>
		  <rdf:li rdf:resource="https://anarc.at/blog/2026-05-16-four-horsemen/"/>
		  <rdf:li rdf:resource="http://blog.sesse.net/blog/tech/2026-06-07-09-51_hyperpersonal_open_source.html"/>
		  <rdf:li rdf:resource="http://blog.alteholz.eu/?p=2823"/>
		  <rdf:li rdf:resource="https://blog.einval.com/2026/06/05#secure_boot_ca_rollover_docs"/>
		  <rdf:li rdf:resource="https://bisco.org/notes/status-update-may-2026/"/>
		  <rdf:li rdf:resource="https://reproducible-builds.org/reports/2026-05/"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/mount_namespace_backup/"/>
		  <rdf:li rdf:resource="https://www.decadent.org.uk/ben/blog/2026/06/02/foss-activity-in-may-2026"/>
		  <rdf:li rdf:resource="https://www.decadent.org.uk/ben/blog/2026/06/02/foss-activity-in-2025"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/nvim-%C2%B5wiki/"/>
		</rdf:Seq>
	</items>
</channel>


<item rdf:about="https://retout.co.uk/2026/07/10/blocking-distracting-news-links/">
	<title>Tim Retout: Blocking distracting news links</title>
	<link>https://retout.co.uk/2026/07/10/blocking-distracting-news-links/</link>
     <content:encoded>&lt;p&gt;&lt;em&gt;“You are what you eat”&lt;/em&gt; – but perhaps this is even more true of our
information diet.  It is hard to strike a balance between remaining a
well-informed citizen versus spending hours ingesting unnecessary news
about issues and events we can’t affect.  But I’m increasingly
convinced that my hours lost to doomscrolling are down to design
choices by web publishers rather than a failure of individual
willpower.&lt;/p&gt;
&lt;h3 id=&quot;we-have-created-an-obesogenic-information-environment&quot;&gt;We have created an “obesogenic” information environment&lt;/h3&gt;
&lt;p&gt;I don’t think it is just me – I think our information environment has
been progressively altered over time as news sites look to maximize
engagement.  Even outside of social media, the invisible hand of the
market for eyeballs forces sites to optimize for browse time or risk
irrelevance.&lt;/p&gt;
&lt;p&gt;Even as newspapers find it increasingly difficult to fund good
journalism through advertising in an online world, especially local
journalism, they need to keep readers on their sites, clicking through
as many articles as possible. Clickbait headlines, “urgent” flashing
live icons to draw the attention, and many opportunities to leap from
one article to another, and another.&lt;/p&gt;
&lt;p&gt;But this design approach even extends to news organisations with a
different funding model, like BBC News, which is a public service
(state-owned but arms-length) organisation funded through a mandatory
television licence – a matter of controversy in some quarters.  And
it extends even to sites where I pay a subscription fee; I might get
adverts removed, but I am still bombarded with the same design
philosophy; too many opportunities to be pulled away from what I’m
reading towards some other unrelated article.&lt;/p&gt;
&lt;p&gt;Even if I try and limit my exposure to algorithmic “discovery” of new
news, via RSS feeds or similar, if I’m reading the full article in a
browser then I am prompted to read more stuff that I didn’t intend.
This defeats the benefit of curating a set of feeds, because you still
get dragged away to random articles.&lt;/p&gt;
&lt;h3 id=&quot;only-44-of-bbc-news-is-news&quot;&gt;Only 44% of BBC News is news&lt;/h3&gt;
&lt;p&gt;To show you what I mean, I’m going to pick on the BBC, although I
love them dearly and the same issue very much applies elsewhere.&lt;/p&gt;
&lt;p&gt;I’ve taken a screenshot of a &lt;a href=&quot;https://www.bbc.co.uk/news/articles/cly9r54e5r4o&quot;&gt;random BBC News
article&lt;/a&gt; in mobile
view (my preferred doomscrolling user access device), and measured
approximately what proportion of the full length of the page is taken
up by each section.  This is a fairly in-depth news article, so I
reckon if anything the figures would be worse than this on shorter
articles.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;A full-length screenshot of a BBC News article showing proportions of the page allocated to the main article vs. related links etc.&quot; src=&quot;https://retout.co.uk/2026/bbc-news-website.drawio.svg&quot; /&gt;&lt;/p&gt;
&lt;p&gt;(These numbers will not sum to 100% for reasons which are obvious if
you look at the crossbars.  Also they’re approximations.)&lt;/p&gt;
&lt;p&gt;Less than half of the page (44% if you exclude the inline related
links) is actual news text/images; the rest are links trying to help
you find the next thing to read/watch. &lt;em&gt;I do not want this.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I’m sure this A/B tests well in terms of reader figures, but it
sometimes leaves me exhausted – it must take subconscious mental
energy to ignore, or I spend too much time trying to keep on top of
things.&lt;/p&gt;
&lt;p&gt;And remember, this is a publicly-funded site that does not rely on
advertising!&lt;/p&gt;
&lt;h3 id=&quot;blocking-out-the-noise&quot;&gt;Blocking out the noise&lt;/h3&gt;
&lt;p&gt;If you are technically-minded, you can use an ad-blocker such as
uBlock Origin to take back some control.  Applying the following lines
as a custom filter (Settings &amp;gt; My filters) brutally cuts out almost
all of these links:&lt;/p&gt;
&lt;div class=&quot;code-block-wrapper&quot;&gt;&lt;pre tabindex=&quot;0&quot;&gt;&lt;code&gt;bbc.co.uk##aside
bbc.co.uk##footer&amp;gt;div:has(h2)
bbc.co.uk##[data-block=&quot;uploaderEmbed&quot;]
bbc.co.uk##[data-block=&quot;links&quot;]&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;em&gt;Caveat emptor:&lt;/em&gt; I have not road-tested this for more than half an
hour, so who knows what consequences this could have on your web
browsing.  In particular, international readers outside the UK will
likely be redirected to bbc.com, the commercial arm of the BBC, where
these rules will need adapting.&lt;/p&gt;
&lt;p&gt;Is it unethical to use an ad-blocker to remove these links?  I would
argue not.  I am not depriving the BBC of any revenue, because I pay
my licence fee.  I might reduce the amount of time I spend on their
website, but if anything the subjectively better experience might
encourage me to consume more news from them, not less.  In other
circumstances (outside the UK for instance, where the BBC relies on
advertising), the balance might be different.&lt;/p&gt;
&lt;h3 id=&quot;product-managers-please-find-better-metrics&quot;&gt;Product managers, please find better metrics&lt;/h3&gt;
&lt;p&gt;I lament the state of the internet in 2026.  I now can’t unsee these
innocuous “related stories” links as a mechanism to grab my attention,
and it’s gone too far.&lt;/p&gt;
&lt;p&gt;If you are a normal person just browsing the news and looking to
discover the latest important stories relatively quickly, I can see
that these types of links might actually be useful for discovery; but
I’m actually reasonably sure that I’m not going to miss out on
anything major.  You still have the option of the news home page if
you want to be presented with more news for example, and it feels
natural to go back to there when you’ve run out of stories to consume.&lt;/p&gt;
&lt;p&gt;But it shouldn’t be down to individual responsibility to ignore or
geekily block these types of link; news sites with alternative funding
models should find better metrics for engagement than “hours spent on
site” – how about optimizing for customer mental wellbeing, or
minimizing time required to catch up with the news?  There’s no need
to maximize clicks and eyeballs.  This is a societal level issue,
because we are all going mad with news over-engagement.&lt;/p&gt;
&lt;p&gt;Product managers, over to you.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-10T15:00:00+00:00</dc:date>
	<dc:creator>Tim Retout</dc:creator>
</item> 
<item rdf:about="http://www.netfort.gr.jp/~dancer/diary/daily/2026-Jul-10.html.en#2026-Jul-10-18:04:45">
	<title>Junichi Uekawa: July already.</title>
	<link>http://www.netfort.gr.jp/~dancer/diary/daily/2026-Jul-10.html.en#2026-Jul-10-18:04:45</link>
     <content:encoded>July already. Wow. It&#39;s getting to be a summer.
        &lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-10T09:04:45+00:00</dc:date>
	<dc:creator>Junichi Uekawa</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-07-10:/2026/07/new-developers-2026-07.html">
	<title>Bits from Debian: New Debian Developers and Maintainers (May and June 2026)</title>
	<link>https://bits.debian.org/2026/07/new-developers-2026-07.html</link>
     <content:encoded>&lt;p&gt;The following contributors got their Debian Developer accounts in the last two
months:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Vivek K J (vivek)&lt;/li&gt;
&lt;li&gt;Benjamin Somers (bensmrs)&lt;/li&gt;
&lt;li&gt;Colin King (colinianking)&lt;/li&gt;
&lt;li&gt;Nadzeya Hutsko (nadzeya)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The following contributors were added as Debian Maintainers in the last two
months:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pieter Lenaerts&lt;/li&gt;
&lt;li&gt;Syed Shahrukh Hussain&lt;/li&gt;
&lt;li&gt;Ural Tunaboyu&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Congratulations!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-10T07:00:00+00:00</dc:date>
	<dc:creator>Jean-Pierre Giraud</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/synths/minilogue-xd/module/">
	<title>Jonathan Dowland: Korg Minilogue XD Desktop Module</title>
	<link>https://jmtd.net/log/synths/minilogue-xd/module/</link>
     <content:encoded>&lt;p&gt;I bought a new synth! Kind-of.&lt;/p&gt;

&lt;p&gt;I&#39;ve traded my &lt;a href=&quot;https://jmtd.net/log/synths/minilogue-xd/&quot;&gt;Minilogue-XD&lt;/a&gt; (full-size version with integrated keyboard) for
the desktop/modular alternative.&lt;/p&gt;

&lt;div class=&quot;image&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/synths/minilogue-xd/module.jpg&quot;&gt;&lt;img alt=&quot;Modular Minilogue XD&quot; class=&quot;img&quot; height=&quot;300&quot; src=&quot;https://jmtd.net/log/synths/minilogue-xd/module/400x-module.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;

&lt;p&gt;Modular Minilogue XD&lt;/p&gt;

&lt;/div&gt;


&lt;p&gt;Why? Partly, because it fits on my desk better. Partly, because it changes the way
you engage with the instrument. It makes
a huge difference: the ivory keys come with so much cultural precedent. The module
version of the synth gains a switch that lets you use the 16 sequencer step buttons
as note inputs, so you can still play the thing solo. But the emphasis moves away
from note generation and more firmly towards tone.&lt;/p&gt;

&lt;p&gt;Both versions have a lovely stained wood back, which you never see; the modular one
has a hint of that at the front as well (which you do see).&lt;/p&gt;

&lt;p&gt;I plan to eventually buy a MIDI keyboard that could drive it, and other things:
possibly an Arturia KeyStep or Minilab, but there&#39;s no rush on that.&lt;/p&gt;

&lt;p&gt;(It&#39;s about time I recorded and shared something I produced on this)&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-09T19:31:38+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="http://blog.alteholz.eu/?p=2832">
	<title>Thorsten Alteholz: My Debian Activities in June 2026</title>
	<link>http://blog.alteholz.eu/2026/07/my-debian-activities-in-june-2026/</link>
     <content:encoded>&lt;h3&gt;&lt;strong&gt;Debian LTS/ELTS&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This was my hundred-forty-fourth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
&lt;/p&gt;
&lt;p&gt;
During my allocated time I uploaded or worked on:  
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/msg00004.html&quot;&gt;DLA 4615-1&lt;/a&gt;]  exim4 security update to fix one CVE related to information disclosure in combination with proxies.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/msg00005.html&quot;&gt;DLA 4616-1&lt;/a&gt;] haveged security update to fix one CVE related to local root privilege escalation.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/msg00007.html&quot;&gt;DLA 4618-1&lt;/a&gt;] gsasl security update to fix one CVE related to denial of service.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/msg00020.html&quot;&gt;DLA 4631-1&lt;/a&gt;] asterisk security update to fix 13 CVEs related to buffer under- or overflows, either on heap or on stack. Some are related to use-after-free or wrong processing of invalid or untrusted certificates. 
&lt;/li&gt;&lt;li&gt;[ELA-1747-1] gimp security update to fix three CVEs in Buster related to denial of service or execution of arbitrary code if malformed PSP, JPEG 2000 or PSD files are opened.&lt;/li&gt;&lt;li&gt;[ELA-1748-1] gimp security update to fix two CVEs in Stretch related to denial of service or execution of arbitrary code if malformed PSP or PSD files are opened.&lt;/li&gt;&lt;li&gt;[ELA-1749-1] exim4 security update to fix one CVEs in Buster and Stretch related to information disclosure in combination with proxies.&lt;/li&gt;&lt;li&gt;[ELA-1750-1] gsasl security update to fix one CVEs in Buster and Stretch related to denial of service.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;
Besides fixing all CVEs of &lt;i&gt;asterisk&lt;/i&gt; in Bullseye, I started to look at &lt;i&gt;asterisk&lt;/i&gt; in other releases as well. Rather surprisingly &lt;i&gt;asterisk&lt;/i&gt; is only part of Unstable and Bullseye. All other releases don’t include any version of &lt;i&gt;asterisk&lt;/i&gt; at all. So first things first, besides some security related RC bugs, &lt;i&gt;asterisk&lt;/i&gt; did not migrate due to RC-bugs in &lt;i&gt;dahdi-linux&lt;/i&gt;.
As I maintain &lt;i&gt;osmocom-dahdi-linux&lt;/i&gt; (which supports less/other hardware), I looked at the open issues and after some rounds I could upload a new upstream version, fixed some bugs and resolved issues with piuparts. &lt;i&gt;dahdi-linux&lt;/i&gt; meanwhile migrated to testing, job done! &lt;br /&gt; As a next step I looked at the open CVEs. Some of them had been already fixed in previous uploads but had not been marked accordingly. So I fixed all remaining ones and sent a debdiff to the maintainer. Unfortunately there was some kind of overlap in our work and he ignored my debdiff but uploaded a new upstream version. Anyway, job done as well, no open security issues anymore. The only thing that hinders &lt;i&gt;asterisk&lt;/i&gt; from migrating to testing is the reproducible build. So if anybody has some spare time …
&lt;/p&gt;


&lt;p&gt;
Other things I worked on were the regression update of &lt;i&gt;rsync&lt;/i&gt;. Some of the elven new patches need to be backported, but I am confidentially to finish this month. I already reviewed the &lt;i&gt;rsync&lt;/i&gt;– uploads of Sylvain to Buster and Stretch, so I don’t expect any big hurdles here. I am also making progress to find the correct patches for &lt;i&gt;hplip&lt;/i&gt; and &lt;i&gt;cups&lt;/i&gt;.
&lt;/p&gt;


&lt;h3&gt;&lt;strong&gt;Debian Printing&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream versions:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/lprng&quot;&gt;hplip&lt;/a&gt; to unstable to fix some bugs.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://www.freexian.com&quot;&gt;Freexian&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Lomiri&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This month new upstream versions of dozens of lomiri packages have been released and I uploaded lots of them to Debian. After they migrate to testing, I am also going to sync them to the Ubuntu PPA. &lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://freiesoftware.gmbh/&quot;&gt;Fre(i)e Software GmbH&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Astro&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/supernovas&quot;&gt;indi-pentax&lt;/a&gt; to unstable. This is a package in contrib without autobuild and needed a new upload for the libraw transistion.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/c-munipack&quot;&gt;c-munipack&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/supernovas&quot;&gt;supernovas&lt;/a&gt; to unstable (sponsored upload).&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;Debian IoT&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/duktape&quot;&gt;duktape&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/libcoap3&quot;&gt;libcoap3&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;Debian Mobcom&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/smstools&quot;&gt;smstools&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;misc&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/visam&quot;&gt;visam&lt;/a&gt; to unstable. There had been an RC bug due to two binaries with the same name but different functionality. Yes, it is in the policy but … (my mother forbade me to elaborate more on this)&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/mailio&quot;&gt;mailio&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-07T17:56:04+00:00</dc:date>
	<dc:creator>alteholz</dc:creator>
</item> 
<item rdf:about="https://mjg59.dreamwidth.org/74260.html">
	<title>Matthew Garrett: My blog has moved</title>
	<link>https://mjg59.dreamwidth.org/74260.html</link>
     <content:encoded>A reminder that I am no longer here, but am instead &lt;a href=&quot;https://codon.org.uk/~mjg59/blog&quot;&gt;here&lt;/a&gt;. The new RSS feed is &lt;a href=&quot;https://www.codon.org.uk/~mjg59/blog/index.xml&quot;&gt;here&lt;/a&gt;. If you&#39;re still reading this for some reason other than being on Dreamwidth, please update your feed.&lt;br /&gt;&lt;br /&gt;&lt;img alt=&quot;comment count unavailable&quot; height=&quot;12&quot; src=&quot;https://www.dreamwidth.org/tools/commentcount?user=mjg59&amp;amp;ditemid=74260&quot; style=&quot;vertical-align: middle;&quot; width=&quot;30&quot; /&gt; comments</content:encoded> 
	<dc:date>2026-07-06T09:03:04+00:00</dc:date>
	<dc:creator>Matthew Garrett</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/0-06-105356-2a.html">
	<title>Russ Allbery: Review: The Player of Games</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/0-06-105356-2a.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;The Player of Games&lt;/cite&gt;, by Iain M. Banks&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Culture #2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;HarperPrism&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;1989&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Printing:&lt;/td&gt;
    &lt;td&gt;February 1987&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;0-06-105356-2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Trade paperback&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;295&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;The Player of Games&lt;/cite&gt; is political space opera and the second book in
the shared Culture setting. As with most Culture books, the reading order
is not particularly important. It won the 1989 Locus Award for best
science fiction novel and sometimes competes with
&lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/1-85723-135-X.html&quot;&gt;&lt;cite&gt;Use of Weapons&lt;/cite&gt;&lt;/a&gt; as the consensus best
Culture novel.
&lt;/p&gt;

&lt;p&gt;
This review is a re-read and yet another experiment in how to re-review a
book. This time, I decided to write a full second review with substantial
spoilers so that I can talk in more detail about the book. If you want to
avoid spoilers, or just want to see how my thoughts have evolved from my
first reading, see &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-06-105356-2.html&quot;&gt;my original review&lt;/a&gt; from
2005.
&lt;/p&gt;

&lt;p&gt;
Gurgeh plays games. He is probably the best strategy game player in the
entirety of the galaxy-spanning Culture. He has written papers on game
theory, won innumerable major championships, and is a celebrity in the
circle of like-minded aficionados.
&lt;/p&gt;

&lt;p&gt;
Gurgeh is also bored and in the middle of the Culture equivalent of a
mid-life crisis. As the story opens, he&#39;s vaguely unsatisfied and adrift,
unenthused by his normal activities, and searching vaguely for something
that will break through his ennui. He is caught by surprise by the thrill
he gets from a moment&#39;s misunderstanding in which an opponent suspects him
of cheating, which sets him up to be (apparently) clumsily blackmailed by
a deeply unpleasant drone named Mawhrin-Skel.
&lt;/p&gt;

&lt;p&gt;
&lt;strong&gt;SPOILERS BELOW&lt;/strong&gt;. If you have not read this book, consider stopping
here and instead reading my original &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-06-105356-2.html&quot;&gt;no spoiler
review&lt;/a&gt;.
&lt;/p&gt;

&lt;p&gt;
The first hundred pages of &lt;cite&gt;The Player of Games&lt;/cite&gt; is a slow, somewhat
plodding introduction to Gurgeh, his social circle, and life in (one part
of) the Culture. I remember being fascinated by this part the first time I
read this book. It was only the second Culture novel I read and the first
set in the Culture proper, so the world-building underlying this odd
post-scarcity utopia on a vast intelligent habitat with sentient drones,
complex privacy rules, endless cocktail parties, and apparently
directionless socialites was intriguingly unlike the other science fiction
I was reading at the time. This time through, I have to admit I was less
impressed.
&lt;/p&gt;

&lt;p&gt;
Gurgeh is not very likable, and his desultory mid-life crisis is a little
boring. None of his friends have enough depth to appear as more than side
notes, in part because Gurgeh doesn&#39;t seem to care enough about any of
them to make them interesting to the reader. I&#39;ve since read seven other
Culture novels, so Banks&#39;s cocktail parties hold less charm and I was
impatient for the real action to begin.
&lt;/p&gt;

&lt;p&gt;
These chapters are still important, though, because they establish how
utterly average Gurgeh is. He has one unique talent, a deep affinity with
and obsession with strategy games, and is otherwise a bit of a depressed
narcissist with a few casual relationships, a friend that he barely
confides in, and a comfortable and familiar life. He is not in any way a
hero or a charismatic figure; he just happens to be exceptionally good at
one thing, enough to make him famous among people who care about that one
thing and probably unknown to anyone else apart from the occasional idly
perused news headline. He is the Culture&#39;s equivalent of the world chess
champion.
&lt;/p&gt;

&lt;p&gt;
The Contact division of the Culture has a problem. The Empire of Azad in
the Lesser Magellanic Cloud is a nasty, expansionist culture of the sort
that Contact would like to deal with before it causes broader problems.
The Culture&#39;s normal approaches are thwarted by an unusual organizing
principle: The empire is built around and takes its name from the game of
Azad, a highly complex strategy game developed over thousands of years.
Azad is the civil service exams, means of political and religious dispute
resolution, selection mechanism for the emperor, and civic religion. Faced
with that oddity, Contact turned to Special Circumstances, the Culture&#39;s
more aggressive and less restrained way of dealing with tricky problems.
Special Circumstances, in turn, needs someone who can learn how to play
the game of Azad. They want Gurgeh to take a very long trip.
&lt;/p&gt;

&lt;p&gt;
For all of Gurgeh&#39;s dissatisfaction, he&#39;s not impulsive enough to take a
five year journey away from his life and everyone he knows just to play a
novel game. Conveniently, Mawhrin-Skel&#39;s blackmail resolves this
reluctance.
&lt;/p&gt;

&lt;p&gt;
The game of Azad requires some suspension of disbelief. Banks provides a
few glimpses at the mechanics of the game, but those details are
insufficient to reconstruct the rules, and some of the claims made about
its properties are improbable at best. The best mental model I could build
for it is a strategy or simulation game built around units and territory
control, with supplemental side games used to build up resources for the
main boards, but it&#39;s more of a plot device and a set piece than a
world-building invention. The significance of Azad the game is its role in
society: The Empire of Azad believes they have constructed a game whose
complexity so closely models reality that the skills required for success
in the game are precisely the skills required for success in the empire.
&lt;/p&gt;

&lt;p&gt;
The Empire of Azad is wrong, and this is one of the core themes of
&lt;cite&gt;The Player of Games&lt;/cite&gt;. As with many Culture novels, what Special
Circumstances tells Gurgeh is, at best, incomplete. Gurgeh is a refutation
of the basis of belief in Azad; this is why it is important thematically
that he is an average, somewhat unlikable citizen of the Culture whose
only special characteristic is skill at learning and playing games.
&lt;/p&gt;

&lt;p&gt;
Azad is the myth of meritocracy given physical form as a game. It provides
the anchor of the empire for the same reason that societies on Earth place
enormous weight on standardized tests, capitalist success, or public
debates. All societies face the problem of selecting good leaders and
testing opposing beliefs, and all societies attempt to find some form of
shortcut, some set of general principles, tests, or objective metrics used
to select the best person via a process that people consider plausible and
fair. The game of Azad is a paragon of apparently meritocratic process. No
matter who you are or what your background is, if you excel at the game
that, in theory, objectively tests your skills, you are given a position
of power.
&lt;/p&gt;

&lt;p&gt;
In practice, the Empire of Azad is not that naive. Manipulation outside of
the game happens, only some players have the opportunity and resources to
spend years learning the game at a deep level, and only their dominant sex
truly stands a chance in games that matter. But neither is Azad&#39;s place in
society a fiction. There is corruption around the edges, and a lot of
people are filtered out before the games begin, but the highest echelons
of society are true believers. The game does decide both rank and policy;
Banks is arguing against a strong form of apparently working meritocracy.
&lt;/p&gt;

&lt;p&gt;
Gurgeh represents a refutation of this meritocracy through the mechanism
that breaks every supposed meritocracy: The map is not and cannot be the
territory. Any objective evaluation criteria is necessarily separate from
what it is trying to measure, and in that separation there is always an
opportunity. Gurgeh has none of the background, training, or mindset
expected for a player of Azad because he could not possibly care less
about any of the things Azad represents to the Empire. What he has instead
is a preternatural skill at games and vast experience with the most
intricate strategy games the Culture, a much larger society, has been able
to devise. He also has both the patience and the resources to devote
himself entirely to learning a game for several years, and past experience
in doing that with other games.
&lt;/p&gt;

&lt;p&gt;
If Azad represents the civil service exams, Gurgeh is the person who has
no interest in ruling but adores memorizing facts and taking tests. The
theory behind the exams is that the skills to pass the exam only come with
the correct mindset to do the job for which the exam is testing. Gurgeh is
an existence proof that this is not always the case.
&lt;/p&gt;

&lt;p&gt;
Banks also uses Azad to show another aspect of the failure of meritocracy:
A society whose rulers are chosen through a competition takes on the shape
of that competition. The Empire of Azad is run by the winners of
competitive games, so the empire is a winner-take-all system of dominance
and status hierarchy. Here, I think Banks lays the point on a little
thick; the empire is an irredeemable hellhole of misogyny, sexual abuse,
slavery, genocide, and military colonialism to a degree that is a bit hard
to justify solely from the game. There is a beautiful turning point about
two-thirds of the way through the book where Gurgeh&#39;s face is shoved into
just how vile Azad society is and reconsiders his approach to the
tournament as a result, and I think it may have been a bit stronger if the
morality had been a little less blatant and absolute.
&lt;/p&gt;

&lt;p&gt;
To the extent that Gurgeh has political beliefs, he represents a Culture
flavor of soft liberalism. He has opinions about acceptable and
unacceptable ways to treat people, but he grew up in a utopia and his
opinions are mostly theoretical. When he sees just how vile people can be
outside of that utopia, he is revolted and appalled and redoubles his
efforts to fight that society in the only way he knows how, inside of a
game. This part of the book follows the standard, if enjoyable, plot of a
flawed but fundamentally decent person discovering a true injustice and
becoming enraged at it.
&lt;/p&gt;

&lt;p&gt;
In a lot of books, that would have been where the plot stops. Banks is
doing something more subtle and more interesting, though. Gurgeh wipes the
board with his next challenger, but that soft liberalism eventually proves
inadequate. To learn the game of Azad and to play in the tournament,
Gurgeh has been wrapping himself in Azad culture and its language, and in
that frame of mind he is losing the climactic game of the book. It&#39;s only
when he is pushed to think in Marain, the native language of the Culture,
that he understands what is happening in the game and how to defeat
Nicosar, the emperor.
&lt;/p&gt;

&lt;p&gt;
This, on the surface, is a bit too close to the
&lt;a href=&quot;https://en.wikipedia.org/wiki/Linguistic_relativity&quot;&gt;strong
hypothesis of linguistic relativity&lt;/a&gt; to be entirely plausible, but such an
objection would miss the point that Banks is making here. Marain is a
construct, the product of considerable effort within the Culture to match
language to the most nuance and complexity that brains can understand, and
it is a language, one of the most social and collective artifacts a
society can produce. Gurgeh is a remarkable individual with an impressive
talent, but individual skill and achievement can only take him so far. The
critical final piece is the support of societal infrastructure
intentionally built and maintained to help him make better decisions.
&lt;/p&gt;

&lt;p&gt;
Once I noticed that point, I saw it everywhere in the book. The empire
repeatedly attempts to subvert or distract Gurgeh with drugs, pleasure,
politics, or danger, and at each point there is some critical piece of
Culture social infrastructure that blunts the attack. Illicit substances
and forbidden vices are less tempting to someone for whom the illicit has
been demystified by the Culture&#39;s gentler approach to rules and
boundaries. Embedded biological mechanisms allow him to divert drugs so
that they don&#39;t affect him. At first, it&#39;s easy to read this as an
exercise of self-control, but on this re-read I saw how much
behind-the-scenes infrastructure supports Gurgeh&#39;s ability to ignore
temptation.
&lt;/p&gt;

&lt;p&gt;
This social support notably does not take the form of some ideological
principle or moral framework. Gurgeh is not a monk or an ascetic, as is
obvious from the first third of the book, and he has no political ideology
to speak of. He is a flawed person with a streak of danger-seeking and
self-aggrandizement, which the Culture exploited to get him involved in
Azad. But through a lot of hard work, technological and social, the
Culture has given him a robust foundation and a set of mental and
biological tools that make him remarkably hard to corrupt. The implication
is that if Gurgeh has that support, so does every other member of the
Culture. It&#39;s neither a religion or an ideology; it&#39;s well-maintained
infrastructure, complex and nuanced and pragmatic, and composed of
innumerable small solutions to specific problems.
&lt;/p&gt;

&lt;p&gt;
I think the true climax of this book takes place the night before the
final day of the game, in the tower meeting between Gurgeh and Nicosar.
Gurgeh has realized that he&#39;s already won; there&#39;s nothing Nicosar can do
to salvage the game. He&#39;s also seen that the game represents a cultural
conflict and conversation between the Culture and Azad and he&#39;s
overwhelmed by the beauty of that communication and sadness that the game
is about to be over. Gurgeh&#39;s true passion is the game. It is doubtless
easier for him to be magnanimous because he&#39;s winning, but he also loves
the structure of the game itself and what two players can create in a sort
of collaborative competition.
&lt;/p&gt;

&lt;p&gt;
Gurgeh tries to express all of this to Nicosar. It is one of the most
centrist liberal moments I&#39;ve ever read in a novel, the pure essence of
&quot;reaching across the aisle&quot; or &quot;disagreeing agreeably.&quot; Gurgeh has seen
something beautiful, something he&#39;s created with Nicosar, a moment of true
communication, and he wants to share it. Surely Nicosar sees the same
thing; surely now that he sees Gurgeh has won, he can appreciate the board
structure, savor the moment, understand the transient beauty of a game
that is about to end and how perfectly it captures the meeting of their
different cultures. That moment does Gurgeh real credit. It&#39;s a rare sign
of emotional and spiritual depth in a character who often seems
superficial.
&lt;/p&gt;

&lt;p&gt;
Nicosar meets this outreach with unhinged, furious contempt. He despises
everything Gurgeh represents, everything the Culture is, and the next day
he tries to kill Gurgeh on the board of the game.
&lt;/p&gt;

&lt;p&gt;
It is a devastating critique of liberal tolerance, all the more so because
Gurgeh&#39;s attitude and outreach is truly admirable. It is perhaps the most
sympathetic moment that Gurgeh has in the entire book, the moment where
the reader thinks &quot;oh, I get it, I understand what he really cares about.&quot;
Gurgeh assumes that Nicosar is not his position or culture, that they have
made a moment of connection that transcends all the awful things he
previously learned about the empire of Azad. That Nicosar, despite being
the emperor of the society that is currently doing so many things Gurgeh
finds repulsive, cannot be as bad as his society. And Nicosar considers
that outreach to be weak, disgusting, and vile, and does everything that
he can to destroy it.
&lt;/p&gt;

&lt;p&gt;
One of the oddest twists of our current moment is the obsession that some
billionaires have with stories that are moral arguments against exactly
what those billionaires are currently doing. The most obvious example is
Peter Thiel, who is obsessed with &lt;cite&gt;The Lord of the Rings&lt;/cite&gt; and has
devoted his life to becoming Saruman, a character who is notably not one
of the protagonists. It&#39;s as if something in them recognizes the power of
the story, but some deep shame or narcissism or simple aversion allows
them to completely ignore what the story means.
&lt;/p&gt;

&lt;p&gt;
Elon Musk is obsessed with the Culture novels. He names the SpaceX rockets
following Culture Ship naming conventions and has claimed that one of his
goals is to bring about a Culture-style utopia. And in 1989, years before
anyone had ever heard of him, Banks cast him as the villain of &lt;cite&gt;The
Player of Games&lt;/cite&gt;. There is so much of Nicosar in Musk: the superficial
charm, the limited brilliance (Nicosar is a very good Azad player), the
ambition, the pride, and the vicious, spitting contempt for everything the
Culture represents at every level deeper than superficial materialism. And
Banks is as clear about his opinion of Nicosar as he is about anything in
any Culture novel.
&lt;/p&gt;

&lt;p&gt;
One of the oldest fictional answers to what a society does with people
like Nicosar is the consequences of hubris. By being unable to accept
defeat, by holding a vision of the world so tightly, they become brittle
and unstable and bring about their own collapse. In a broad sense, that is
what happens in &lt;cite&gt;The Player of Games&lt;/cite&gt; with a bit of pushing from
Special Circumstances. By the politics of the game, Nicosar had already
won; the results of Gurgeh&#39;s earlier games had already been faked, the
final game had no political consequences, and everyone who knew its true
outcome could be disposed of. Gurgeh&#39;s win could have been covered up and
ignored. But Nicosar could not endure the thought that he would be beaten
by someone like Gurgeh, playing Azad the way that Gurgeh was playing it.
Gurgeh had to be destroyed on the board of the game; Nicosar&#39;s pride did
not allow any other outcome, even if it meant Nicosar&#39;s death.
&lt;/p&gt;

&lt;p&gt;
However, Special Circumstances didn&#39;t let hubris be the end of the story.
In the climax of the book, the drone protecting Gurgeh also makes sure
that Nicosar dies. There is a fig leaf of plausible deniability, but it&#39;s
so obvious that even the unobservant Gurgeh sees through it immediately.
It&#39;s hard to escape the feeling that was Banks&#39;s answer to what to do with
people like Nicosar: They cannot live within society, because they will
not live peacefully within society.
&lt;/p&gt;

&lt;p&gt;
I enjoyed &lt;cite&gt;The Player of Games&lt;/cite&gt; as much this time through as I did
the first time, but for entirely different reasons. In my first read, I
focused on the world-building of the Culture, the political machinations,
and the concept of games as conversations between the players. This time,
I was struck by the political commentary just below the surface. Special
Circumstances wanted to resolve the problem of the Empire of Azad without
a military conflict and occupation that would be long, brutal, expensive,
and demoralizing. They found an answer that relied on the diversity of the
Culture. A vast, utopian civilization in which people can pursue whatever
interests make them happy produces innumerable microspecialized oddities,
people with astonishing talents in some small field that only a tiny
fraction of people care about. It produces, in other words, innumerable
keys for locks that you may never encounter, but which are invaluable if
you happen to stumble across that lock.
&lt;/p&gt;

&lt;p&gt;
Gurgeh is not a hero. He is not a paragon of moral virtue, or even a
charming charismatic, He is an entirely average member of an extraordinary
society, the beneficiary of thousands of years of concerted effort at
producing a robust, flexible foundation on which to raise robust, flexible
citizens with a shared sense of basic morality. Those people, by
themselves, do not solve all of life&#39;s problems; the structure of Special
Circumstances and its willingness to bend rules in order to maintain them
is the tension and &lt;em&gt;deus ex machina&lt;/em&gt; in all of the Culture novels.
But much of the strength of Special Circumstances is that it has an entire
civilization of people like Gurgeh to draw upon when it needs them.
&lt;/p&gt;

&lt;p&gt;
It has those people because the Culture comprehensively rejects
competitive meritocracy, something that some readers of the Culture novels
appear incapable of comprehending.
&lt;/p&gt;

&lt;p&gt;Rating: 9 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-06T03:09:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/journal/2026-07/001.html">
	<title>Russ Allbery: INN 2.7.4</title>
	<link>https://www.eyrie.org/~eagle/journal/2026-07/001.html</link>
     <content:encoded>&lt;p&gt;
This is a bug fix and minor feature release over INN 2.7.3, and the
upgrade should be painless. You can download the new release from
&lt;a href=&quot;https://downloads.isc.org/isc/inn/&quot;&gt;ISC&lt;/a&gt; or
&lt;a href=&quot;https://www.eyrie.org/~eagle/software/inn/&quot;&gt;my personal INN pages&lt;/a&gt;. The latter also has
links to the full changelog and the other INN documentation.
&lt;/p&gt;

&lt;p&gt;
For the full list of changes, see the
&lt;a href=&quot;https://www.eyrie.org/~eagle/software/inn/docs-2.7/news.html&quot;&gt;INN 2.7.4 NEWS file&lt;/a&gt;.
&lt;/p&gt;

&lt;p&gt;
As always, thanks to Julien Ã‰LIE for preparing this release and doing most
of the maintenance work on INN!
&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-06T01:57:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://bisco.org/notes/status-update-june-2026/">
	<title>Birger Schacht: Status update, June 2026</title>
	<link>https://bisco.org/notes/status-update-june-2026/</link>
     <content:encoded>&lt;h1 id=&quot;debian-related-work&quot;&gt;Debian Related Work&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;Uploaded wofi 1.5.3-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded wob 0.16-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded labwc 0.20.0-1 and 0.20.1-1 to unstable; these releases come with
support for wlroots-0.20, which made labwc reenter testing&lt;/li&gt;
&lt;li&gt;Uploaded swaylock 1.8.5-2 to unstable to make it use the &lt;code&gt;common-auth&lt;/code&gt;
directive of pam (seeh &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140096&quot;&gt;#1140096&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Uploaded swayimg 5.4-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded wayback 0.3-2 to unstable, which was waiting in experimental
for a reupload and I had forgotten about it; also fixed a
&lt;a href=&quot;https://gitlab.freedesktop.org/wayback/wayback/-/merge_requests/96&quot;&gt;typo&lt;/a&gt;
in wayback upstream&lt;/li&gt;
&lt;li&gt;Uploaded xdg-desktop-portal-wlr 0.8.3-1 to unstable&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;dh-related-work&quot;&gt;DH Related Work&lt;/h1&gt;
&lt;p&gt;The search app I was working on last month was still a focus in June. I refactored
the data model a bit and made it simpler. I stumbled over the &lt;a href=&quot;https://pythonkoans.substack.com&quot;&gt;Python
Koans&lt;/a&gt; and &lt;a href=&quot;https://pythonkoans.substack.com/p/koan-15-the-invisible-ink&quot;&gt;Koan 15: The Invisible
Ink&lt;/a&gt; gave me the
idea of using unicode normalization when indexing the items.&lt;/p&gt;
&lt;p&gt;I released a couple of bug fix releases for the APIS framework, namely 0.64.2,
0.64.3 and 0.64.4. I also release 0.65.0 which is one step further in dropping
support for the legacy &lt;code&gt;apis_entities&lt;/code&gt; app. When the &lt;code&gt;search&lt;/code&gt; module is merged
it will give way for removing the last bits of the old cruft to be removed.&lt;/p&gt;
&lt;p&gt;During a regular dependency update session I looked at the changes in &lt;a href=&quot;https://github.com/yourlabs/django-autocomplete-light&quot;&gt;the dal
dependency&lt;/a&gt;. After a
long time with no commits, the project suddenly had a lot of commits
co-authored by Claude and then released a new major version with a regression.
Given the state of the project, we decided to keep using the previous release
for now and look into replacing the dependency with an HTMX based solution. I
implemented a POC for one of the plugins we develop and it was actually pretty
easy. I also managed to combine the autocomplete approach with a multi-select
form field, based on &lt;a href=&quot;https://dev.to/apleshkov/htmx-multi-select-form-control-without-js-4jfk&quot;&gt;this blog
post&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the
&lt;a href=&quot;https://www.oeaw.ac.at/de/acdh/forschung/dh-forschung-infrastruktur/aktivitaeten/dh-datenmodellierung/pfp-prosopographische-plattform-oesterreich&quot;&gt;PFP&lt;/a&gt;
project I finally merged the stats endpoint which give statistics about the
named graphs that are used as data sources.&lt;/p&gt;
&lt;h1 id=&quot;other&quot;&gt;Other&lt;/h1&gt;
&lt;p&gt;I attended &lt;a href=&quot;https://bsidesvienna.at/&quot;&gt;BSidesVienna 0x7EA&lt;/a&gt; but it was on one of
the hottest days this year so far so I left after a couple of talks.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-05T05:28:51+00:00</dc:date>
	<dc:creator>Birger Schacht</dc:creator>
</item> 
<item rdf:about="http://blog.sesse.net/blog/tech/2026-07-04-15-21_an_update_on_sesse_chromium_org.html">
	<title>Steinar H. Gunderson: An update on sesse@chromium.org</title>
	<link>http://blog.sesse.net/blog/tech/2026-07-04-15-21_an_update_on_sesse_chromium_org.html</link>
     <content:encoded>&lt;p&gt;As previously mentioned, I am leaving Chrome; my last work day
was yesterday. (Sorry to those with July 3rd off that I didn&#39;t
get to say goodbye to!) But I&#39;m staying in Google, on more internal
projects :-)&lt;/p&gt;

&lt;p&gt;After 1100+ commits it&#39;s hard to pick out one thing that I love
the most; as a team, we launched a lot of (IMO) useful CSS features
and fixed a lot of issues. But somehow, I keep on gravitating towards
performance, and perhaps &lt;a href=&quot;https://chromium-review.googlesource.com/c/chromium/src/+/3581992&quot;&gt;this commit&lt;/a&gt;
is the one I will remember the most fondly; a couple hundred lines
to speed up repeated attribute selectors a lot. (If you ever wonder
who would be doing that; well, there&#39;s a fairly high chance that you
have an extension injecting a stylesheet with a lot of &lt;code&gt;a[href*=&quot;...&quot;]&lt;/code&gt;
rulesâ€¦)&lt;/p&gt;

&lt;p&gt;Upwards and onwards. Please write lean, clean CSS; I won&#39;t be there
to save you from now on. :-)&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-04T14:21:00+00:00</dc:date>
	<dc:creator>Steinar H. Gunderson</dc:creator>
</item> 
<item rdf:about="https://retout.co.uk/2026/07/04/aws-washington-summit-2026/">
	<title>Tim Retout: AWS Washington Summit 2026</title>
	<link>https://retout.co.uk/2026/07/04/aws-washington-summit-2026/</link>
     <content:encoded>&lt;p&gt;I am somewhat jet-lagged, having returned from Washington DC just
before the 250th anniversary celebrations which will be happening
today.  I was part of a delegation sent by my employer to the AWS
Summit there this week, partly to kindle interactions between PA
Consulting and Jacobs who have recently &lt;a href=&quot;https://www.jacobs.com/newsroom/press-release/jacobs-acquire-remaining-stake-pa-consulting&quot;&gt;taken a 100% share in
PA&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Much of our conference time was spent in meetings with AWS executives
impressing the facts of the Jacobs/PA partnership upon them, and
discussing plans to broaden our collaboration in different sectors.
So I spent even less time than usual at conference keynotes, talks
etc.&lt;/p&gt;
&lt;p&gt;This was my first time to DC, and I did find some time to see some
sights – unfortunately the White House is rather fenced off at the
moment following the UFC match, but I did make it to the Capitol and
the Washington Monument in the heat.&lt;/p&gt;
&lt;p&gt;Last Sunday a select few of us attended the &lt;a href=&quot;https://www.mlb.com/orioles&quot;&gt;baseball in
Baltimore&lt;/a&gt; – rather than the game, the
thing that stood out for me was the military jets flying in formation
over the stadium every few minutes, and the block-booked seats for the
Navy in uniform, who were having a great time!  This is obviously a
hearts-and-minds thing, but it provides a stark contrast with the UK
– I can’t think of a time I’ve seen uniformed military at the
football (soccer) or cricket for example.  Or Union Jacks flying at
shopping centres.&lt;/p&gt;
&lt;p&gt;Speaking of soccer, England just about beat DR Congo while I was out
there, but it was a close-run thing as we were 1-0 down at half time.
I can’t claim to be following the World Cup too closely, but I
overheard comments (from US passers-by) that made clear it would have
had a significant reputational impact on our standing in the world had
we lost.&lt;/p&gt;
&lt;p&gt;Another highlight for me was the &lt;a href=&quot;https://www.asa-dc.org/&quot;&gt;Church of the Ascension and
St. Agnes&lt;/a&gt;, where I was able to get my fix of
Anglican plainchant and four-part harmony for the week.  At morning
prayer, I noted they use “God save this land” rather than “God save
the King” during the responses – I’ve since found other sources
online that choose “God save the State”.  It’s strange to think that
the words of the BCP dating back to 1549/1662 are a point of
continuity since well before the 1776 declaration of independence, and
yet are still adapted and used in worship today.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-04T12:40:45+00:00</dc:date>
	<dc:creator>Tim Retout</dc:creator>
</item> 
<item rdf:about="https://blog.jak-linux.org/2026/07/03/openssl-pandemic/">
	<title>Julian Andres Klode: The pandemic of incomplete OpenSSL error handling</title>
	<link>https://blog.jak-linux.org/2026/07/03/openssl-pandemic/</link>
     <content:encoded>&lt;p&gt;Recently a person reported a bug in APT saying that TLS is failing on FIPS
systems with MD5 errors, and suggested we call &lt;code&gt;ERR_clear_error()&lt;/code&gt; around
TLS operations.&lt;/p&gt;
&lt;p&gt;Like any serious software engineer would do, I said No. Just because one component
failed to handle its errors does not mean I can go around and discard all errors
in another place - the program should have failed earlier (or discarded the error
when it was determined to be safe).&lt;/p&gt;
&lt;p&gt;Little did I know that people have for years been using this approach as a best
practice: Codebases everywhere are littered with calls to &lt;code&gt;ERR_clear_error()&lt;/code&gt;
before performing TLS, and upstream themselves suggest to do just that.&lt;/p&gt;
&lt;p&gt;This is a major, systemic, pandemic of incomplete error handling. We cannot
just discard unrelated errors if they become inconvenient. The code that
caused the error needs to be fixed to handle it.&lt;/p&gt;
&lt;p&gt;This isn’t all. It seems many authors are not familiar with libraries using a
stack of errors, and there is a second anti-pattern:&lt;/p&gt;
&lt;p&gt;Call an OpenSSL operation, check the top-level error, and then discard all
errors if deemed “not too bad”. This has the same problem: Unrelated errors
get silently discarded.&lt;/p&gt;
&lt;p&gt;I would strongly encourage everyone to inspect their code bases for any calls
to &lt;code&gt;ERR_clear_error()&lt;/code&gt; and whether they are safe or one of the bad patterns
above (or maybe you find a new pattern). You may want to use error stack
functionality of&lt;code&gt;ERR_set_mark&lt;/code&gt; (&lt;a href=&quot;https://docs.openssl.org/3.4/man3/ERR_set_mark/&quot;&gt;https://docs.openssl.org/3.4/man3/ERR_set_mark/&lt;/a&gt;)
to essentially “push” and “pop” an error context of your own as a guard around
multiple OpenSSL operations.&lt;/p&gt;
&lt;p&gt;To the OpenSSL authors, I would suggest not encouraging devastating security
practices that fundamentally break any trust in software.&lt;/p&gt;
&lt;p&gt;We need to do better than this.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-03T15:54:22+00:00</dc:date>
	<dc:creator>Julian Andres Klode</dc:creator>
</item> 
<item rdf:about="tag:www.chiark.greenend.org.uk,2026-07-03:/~cjwatson/blog/activity-2026-06.html">
	<title>Colin Watson: Free software activity in June 2026</title>
	<link>https://www.chiark.greenend.org.uk/~cjwatson/blog/activity-2026-06.html</link>
     <content:encoded>&lt;p&gt;My Debian contributions this month were all &lt;a href=&quot;https://www.freexian.com/about/debian-contributions/&quot;&gt;sponsored&lt;/a&gt; by Freexian.&lt;/p&gt;
&lt;p&gt;You can also support my work directly via &lt;a href=&quot;https://liberapay.com/cjwatson&quot;&gt;Liberapay&lt;/a&gt; or &lt;a href=&quot;https://github.com/sponsors/cjwatson&quot;&gt;GitHub Sponsors&lt;/a&gt;.  Thanks to new sponsor &lt;a href=&quot;https://github.com/fernandocc17&quot;&gt;@fernandocc17&lt;/a&gt;!&lt;/p&gt;
&lt;h2&gt;bugs.debian.org documentation&lt;/h2&gt;
&lt;p&gt;Sometimes I ask users to file bugs upstream themselves because I think they’d be better placed to have the ensuing discussion with the upstream maintainers directly rather than everything having to go through me.  Of course sometimes they don’t want to do so, perhaps because it requires creating another account somewhere.  Rarely, I’ve had people refuse to do this because the letter of the bug tracking system’s documentation seemed to tell them not to.  Since I don’t believe that was the intention, I &lt;a href=&quot;https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1149&quot;&gt;corrected this&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;OpenSSH&lt;/h2&gt;
&lt;p&gt;I spent two and a half hours extensively revising &lt;code&gt;debian/copyright&lt;/code&gt; so that &lt;code&gt;lrc&lt;/code&gt; believes it to be in sync with the output of &lt;code&gt;licensecheck&lt;/code&gt;.  I’m unconvinced that this was remotely worth the mind-numbing effort - as far as I can tell, it makes no difference to the practical legal position, to policy compliance, or to any reasonable user - but the &lt;span class=&quot;caps&quot;&gt;DFSG&lt;/span&gt; team increasingly seems to be objecting to any discrepancies here any time a package crosses their radar, so this was a pre-emptive measure to avoid problems with some upcoming trips through the &lt;span class=&quot;caps&quot;&gt;NEW&lt;/span&gt; queue.&lt;/p&gt;
&lt;h2&gt;OpenSSL 4.0&lt;/h2&gt;
&lt;p&gt;I fielded a few of the &lt;a href=&quot;https://udd.debian.org/cgi-bin/bts-usertags.cgi?user=pkg-openssl-devel%40lists.alioth.debian.org&amp;amp;tag=openssl-4.0&quot;&gt;OpenSSL 4.0 build failure bugs&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138480&quot;&gt;omniorb-dfsg&lt;/a&gt; (along with upgrading to 4.3.4)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138423&quot;&gt;openssh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138408&quot;&gt;yubihsm-shell&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Python packaging&lt;/h2&gt;
&lt;p&gt;New upstream versions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;certipy&lt;/li&gt;
&lt;li&gt;juptyer-server (fixing &lt;a href=&quot;https://bugs.debian.org/1136022&quot;&gt;&lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2025-61669, &lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-35397, &lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-40110, and &lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-40934&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;magicgui&lt;/li&gt;
&lt;li&gt;pydantic&lt;/li&gt;
&lt;li&gt;pydantic-core&lt;/li&gt;
&lt;li&gt;pydantic-settings&lt;/li&gt;
&lt;li&gt;pylint&lt;/li&gt;
&lt;li&gt;pytest-rerunfailures (fixing a &lt;a href=&quot;https://bugs.debian.org/1140869&quot;&gt;build failure with pytest 9.1&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;python-certifi&lt;/li&gt;
&lt;li&gt;python-django-celery-beat&lt;/li&gt;
&lt;li&gt;python-numpy-groupies&lt;/li&gt;
&lt;li&gt;python-packaging (aided by Debusine testing of reverse-dependencies)&lt;/li&gt;
&lt;li&gt;python-pytest-run-parallel&lt;/li&gt;
&lt;li&gt;python-pytest-unmagic&lt;/li&gt;
&lt;li&gt;python-service-identity&lt;/li&gt;
&lt;li&gt;python-tabulate&lt;/li&gt;
&lt;li&gt;python-urllib3 (fixing &lt;a href=&quot;https://bugs.debian.org/1140427&quot;&gt;&lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-9375&lt;/a&gt; and &lt;a href=&quot;https://bugs.debian.org/1136654&quot;&gt;&lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-44432&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;python-watchfiles&lt;/li&gt;
&lt;li&gt;python-yubihsm&lt;/li&gt;
&lt;li&gt;responses&lt;/li&gt;
&lt;li&gt;uncertainties&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;pytest 9.1 was uploaded to unstable this month, resulting in quite a few new build/test failure bugs.  I tried to keep on top of as many of these as I could; most of them had one of a small number of similar causes.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140858&quot;&gt;domdf-python-tools&lt;/a&gt; (&lt;a href=&quot;https://github.com/domdfcoding/domdf_python_tools/pull/151&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140978&quot;&gt;flask-caching&lt;/a&gt; (&lt;a href=&quot;https://github.com/pallets-eco/flask-caching/pull/652&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140863&quot;&gt;magicgui&lt;/a&gt; (&lt;a href=&quot;https://github.com/pyapp-kit/magicgui/pull/731&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/pydantic-core/-/commit/0b294b4e0841b63d2a6ace55b9fbb6ec50fae6d3&quot;&gt;pydantic-core&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140865&quot;&gt;pydantic-extra-types&lt;/a&gt; (&lt;a href=&quot;https://github.com/pydantic/pydantic-extra-types/pull/397&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140866&quot;&gt;pydantic&lt;/a&gt; (&lt;a href=&quot;https://github.com/pydantic/pydantic/pull/13357&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140867&quot;&gt;pylint&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140868&quot;&gt;pytest-codeblocks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140875&quot;&gt;python-docx&lt;/a&gt; (&lt;a href=&quot;https://github.com/python-openxml/python-docx/pull/1563&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140879&quot;&gt;python-numpy-groupies&lt;/a&gt; (&lt;a href=&quot;https://github.com/ml31415/numpy-groupies/pull/96&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140880&quot;&gt;python-openapi-core&lt;/a&gt; (&lt;a href=&quot;https://github.com/python-openapi/openapi-core/pull/1207&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140932&quot;&gt;python-urllib3&lt;/a&gt; (&lt;a href=&quot;https://github.com/urllib3/urllib3/pull/5094&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140883&quot;&gt;python-watchfiles&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141032&quot;&gt;sphinx-automodapi&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Python 3.14 became the default Python version in unstable towards the end of the month, starting a &lt;a href=&quot;https://bugs.debian.org/1130323&quot;&gt;transition&lt;/a&gt;.  These usually involve quite a bit of work, and there’s much more to do, but I fixed a few things:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140927&quot;&gt;depthcharge-tools: Traceback with 3.14: args for positionals must be != 0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1131793&quot;&gt;domdf-python-tools: autopkgtest failure with Python 3.14&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Other build/test failures:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140059&quot;&gt;dh-python: Dependency parsing is too picky about spacing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/psygnal/-/commit/060a129ae5267e404510bdcb5e2bfb20eafe9c25&quot;&gt;psygnal: Allow building without msgspec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/pydantic-core/-/commit/0ec1508c0ff9cfeb2677fba4a0a29cc2cd19cabf&quot;&gt;pydantic-core: Accept and require uuid 1.23.0, now that it’s in Debian&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135448&quot;&gt;pygame: &lt;span class=&quot;caps&quot;&gt;FTBFS&lt;/span&gt;: &lt;span class=&quot;caps&quot;&gt;FAIL&lt;/span&gt;: test_fill_rle (pygame.tests.surface_test.SurfaceTypeTest.test_fill_rle)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1139431&quot;&gt;pyro5: &lt;span class=&quot;caps&quot;&gt;FTBFS&lt;/span&gt;: Unable to determine debhelper compatibility version&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1139197&quot;&gt;python-persistent: Bump timeout in test_rapid_create_destroy_cycle&lt;/a&gt; (&lt;a href=&quot;https://github.com/zopefoundation/persistent/pull/238&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140667&quot;&gt;python-yubihsm: Depends: python3-cryptography (&amp;lt; 47) but 47.0.0-1 is to be installed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138813&quot;&gt;sphinx-gallery: &amp;lt;!nodoc&amp;gt; build dependency removed from testing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/tpm2-pytss/-/commit/0b9dcb5d369f2f32d904437e7880cec0381745e0&quot;&gt;tpm2-pytss: Fix support for cryptography 47&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140931&quot;&gt;twisted: Tests fail with pyopenssl 26.3.0: module ‘OpenSSL.crypto’ has no attribute ‘X509Req’&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Other bugs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/psygnal/-/commit/0bc98b31531ab5ce3f6f465b16780ed932633fe6&quot;&gt;psygnal: Fix reproducibility&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138937&quot;&gt;python-nacl: Updating the python-nacl Uploaders list&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1046910&quot;&gt;python-tabulate: Fails to build source after successful build&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1046308&quot;&gt;tpm2-pytss: Fails to build source after successful build&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Rust packaging&lt;/h2&gt;
&lt;p&gt;New upstream versions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;rust-asn1 (&lt;a href=&quot;https://bugs.debian.org/1134917&quot;&gt;needed by new python-cryptography&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;rust-asn1-derive&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Code reviews&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1129695&quot;&gt;buildbot: [&lt;span class=&quot;caps&quot;&gt;INTL&lt;/span&gt;:sv] Swedish translation of debconf templates&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/ssh-team/openssh/-/merge_requests/39&quot;&gt;openssh: Support DPKG_ROOT&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/ssh-team/openssh/-/merge_requests/41&quot;&gt;openssh: Fix &lt;span class=&quot;caps&quot;&gt;GSS&lt;/span&gt; C25519 server blob bounds check&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/python-pyramid/-/merge_requests/1&quot;&gt;python-pyramid: &lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2023-40587 Backport patch&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Other bits and pieces&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140062&quot;&gt;busybox: chdir no longer available -&amp;gt; breaks d-i ‘live-installer.udeb’&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/debian/debmirror/-/commit/7d25662cd048afbe8f90a437466dc1d8751a3e89&quot;&gt;debmirror: Refresh mirror_size documentation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-03T11:38:46+00:00</dc:date>
	<dc:creator>Colin Watson</dc:creator>
</item> 
<item rdf:about="http://joeyh.name/blog/entry/no_LLM_code_in_dependencies/">
	<title>Joey Hess: no LLM code in dependencies</title>
	<link>http://joeyh.name/blog/entry/no_LLM_code_in_dependencies/</link>
     <content:encoded>&lt;p&gt;I&#39;ve spent about 100 hours of work over the past month to make sure
git-annex can build without dependencies that contain LLM generated code.
At least so far.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://git-annex.branchable.com/no_llm_code/&quot;&gt;https://git-annex.branchable.com/no_llm_code/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Needing to review a program&#39;s whole dependency tree on an ongoing basis is
apparently what programming has come to?&lt;/p&gt;

&lt;p&gt;I&#39;ve found some real stinkers. Large LLM generated changes being reverted
in the next release without any explanation. An incoherent 1489 line
commit message with 10,000 lines of changes to a 26,000 LOC code base.
A LLM prompt to copy code from another project that seems to have only
avoided being copyright infringement due to luck.&lt;/p&gt;

&lt;p&gt;I now have additional information about the quality of dependencies
which will surely influence future decisions. As far as I
can see, that&#39;s the only positive benefit of this work.&lt;/p&gt;

&lt;p&gt;I realize that I am probably trying to hold back the tide at this point.
That appears to be why Software Freedom Conservancy
&lt;a href=&quot;https://sfconservancy.org/llm-gen-ai/llm-backed-generative-ai-recommendations.html&quot;&gt;punted&lt;/a&gt;,
and I doubt that the FSF will do any better.&lt;/p&gt;

&lt;p&gt;As these dominos fall, I am reconsidering my participation in these
communities. But I continue my work and support my users.&lt;/p&gt;

&lt;p&gt;It may seem easy to prompt a LLM with&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;Add fourmolu config and restyled&lt;/p&gt;

&lt;p&gt;neat&lt;/p&gt;

&lt;p&gt;format a module&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;And commit the result and call yourself a 10xer.
But please consider the broader impact of your actions.
(In the above case, that project lost my further collaboration on it.)&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-02T17:58:19+00:00</dc:date>
	<dc:creator>Joey Hess</dc:creator>
</item> 
<item rdf:about="https://www.decadent.org.uk/ben/blog/2026/07/01/foss-activity-in-june-2026">
	<title>Ben Hutchings: FOSS activity in June 2026</title>
	<link>https://www.decadent.org.uk/ben/blog/2026/07/01/foss-activity-in-june-2026.html</link>
     <content:encoded>&lt;p&gt;This month’s work was dominated by the transition of Debian 12
“bookworm” to support by the LTS team, and by review of some large
updates to Linux stable branches.&lt;/p&gt;

&lt;p&gt;Linux 6.12 is currently available in bookworm-backports, but that
suite will stop accepting uploads after the last bookworm point
release.  I updated some supporting packages in bookworm in
preparation for adding Linux 6.12 there.  I also prepared for
the possibility that bookworm-backports would close earlier.&lt;/p&gt;

&lt;p&gt;Since the LTS team is still also maintaining Debian 11 “bullseye”
until August, I reviewed upstream changes for both Linux 5.10 and 6.1
stable branches and reported a number of regressions and other issues.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Debian packages:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-free&quot;&gt;firmware-free&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-free/-/merge_requests/11&quot;&gt;!11: Apply relevant changes from firmware-nonfree&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-nonfree&quot;&gt;firmware-nonfree&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:firmware-nonfree&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1135723&quot;&gt;#1135723: firmware-nonfree: gencontrol conflates initramfs-tools with update-initramfs&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1135736&quot;&gt;#1135736: firmware-nonfree: suggests initramfs-tools, which is being phased out&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1137651&quot;&gt;#1137651: firmware-misc-nonfree: Please move firmware-intel-graphics and firmware-nvidia-graphics out of Recommends&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1139740&quot;&gt;#1139740: firmware-misc-nonfree should recommend firmware-nvidia-graphics to avoid kernel Oops + black screen&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1139746&quot;&gt;#1139746: firmware-realtek: W: Possible missing firmware rtlwifi/rtl8723bu_bt.bin for module rtl8xxxu&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/150&quot;&gt;!150: Update and remove obsolete package relations&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-nonfree/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 20260519-1 to unstable&lt;/li&gt;
              &lt;li&gt;uploaded version 20260519-1~bpo13+1 to trixie-backports&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/kernel-wedge&quot;&gt;kernel-wedge&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/kernel-wedge/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 2.106~deb12u1 to bookworm-security&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux&quot;&gt;linux&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:linux&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1128861&quot;&gt;#1128861: linux: when serving NFS, client attempts to lock served files fail with “No locks available”&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1140461&quot;&gt;#1140461: spam wave of kernel: tpm tpm0: tpm_try_transmit: send(): error -62&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1936&quot;&gt;!1936: [sparc64] Add nvme module to scsi-modules udeb&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1948&quot;&gt;!1948: [amd64] Enable Intel Platform Hardware Support Drivers&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1977&quot;&gt;!1977: Fix build failure over missing vdso debug files&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1981&quot;&gt;!1981: 6.1 backport “bpf: Free reuseport cBPF prog after RCU grace period.”&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1984&quot;&gt;!1984: udeb: Ensure that aead and macsec modules are in the right packages&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1985&quot;&gt;!1985: Add d/.flake8 config file to support pylsp&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1992&quot;&gt;!1992: 6.1 backport: ip6_vti: set netns_immutable on the fallback device. (CVE-2026-52909)&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1993&quot;&gt;!1993: 5.10 backport: ip6_vti: set netns_immutable on the fallback device. (CVE-2026-52909)&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1999&quot;&gt;!1999: 6.1 backport: Fix CVE-2026-46331&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2004&quot;&gt;!2004: [sparc64] udeb: scsi-modules: Use the default module list&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;(LTS) uploaded version 6.12.94-1~bpo12+1 to bookworm-backports&lt;/li&gt;
              &lt;li&gt;uploaded version 7.0.12-2~bpo13+1 to trixie-backports&lt;/li&gt;
              &lt;li&gt;uploaded version 7.1~rc7-1~exp1 to experimental&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;(LTS) updated the bullseye-security branch to 5.10.259, but did
not upload this version&lt;/li&gt;
          &lt;li&gt;(LTS) updated the bookworm-security branch to 6.1.176, but did
not upload this version&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;(LTS) linux-6.12:
        &lt;ul&gt;
          &lt;li&gt;prepared this backport package for bookworm-security, but did
not upload it yet&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-base&quot;&gt;linux-base&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-base/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 4.12.1~deb12u1 to bookworm-security&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb&quot;&gt;wireless-regdb&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/wireless-regdb/-/merge_requests/8&quot;&gt;!8: Update to 2026.05.30&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 2026.05.30-1 to unstable&lt;/li&gt;
              &lt;li&gt;uploaded version 2026.05.30-1~deb12u1 to bookworm&lt;/li&gt;
              &lt;li&gt;uploaded version 2026.05.30-1~deb13u1 to trixie&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;Debian non-package bugs:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/release.debian.org&quot;&gt;release.debian.org&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;opened and closed &lt;a href=&quot;https://bugs.debian.org/1139579&quot;&gt;#1139579: trixie-pu: package wireless-regdb/2026.05.30-1~deb13u1&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;opened &lt;a href=&quot;https://bugs.debian.org/1139581&quot;&gt;#1139581: trixie-pu: package wireless-regdb/2026.05.30-1~deb13u1&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;opened &lt;a href=&quot;https://bugs.debian.org/1139582&quot;&gt;#1139582: bookworm-pu: package wireless-regdb/2026.05.30-1~deb12u1&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;Mailing lists:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-backports/&quot;&gt;debian-backports&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;(LTS) posted &lt;a href=&quot;https://lists.debian.org/31d77827ecf42782c97cb4b4213197c33a33b0ea.camel@decadent.org.uk&quot;&gt;EOL for bookworm-backports&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-boot/&quot;&gt;debian-boot&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;(LTS) posted and replied to &lt;a href=&quot;https://lists.debian.org/03ecb84264a8b6018633c64d3e4a004dd5e10363.camel@decadent.org.uk&quot;&gt;Adding Linux 6.12 udebs for bookworm LTS&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-devel/&quot;&gt;debian-devel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lists.debian.org/eaf26a4b6ff54f8855c71fe84b077c694486804f.camel@decadent.org.uk&quot;&gt;Understanding CI in Salsa, timeouts and runners&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-kernel/&quot;&gt;debian-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/aca2f071cd39f2c9d75d081c7be2371f98f54f4f.camel@decadent.org.uk&quot;&gt;Agenda items for kernel-team meeting on 2026-06-10&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/&quot;&gt;debian-lts&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted and replied to &lt;a href=&quot;https://lists.debian.org/21b31300c29a7ed8c9871bd9e7beb25b2cc79e18.camel@decadent.org.uk&quot;&gt;Preparation for Linux 6.12 in bookworm&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/&quot;&gt;debian-lts-announce&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/aivd9n_B7HR1593x@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4627-1] kernel-wedge update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/aiveDYMhYvx0ykIK@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4628-1] linux-base update&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;(LTS) &lt;a href=&quot;https://lore.kernel.org/stable/&quot;&gt;stable&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;reviewed &amp;gt;1000 patches included in 5.10.258-rc1, 5.10.259-rc1,
and 6.1.176-rc1&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/211fb901ba2c644e6ebdffe46d9face7e317db70.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 210/589] spi: rockchip: fix controller deregistration&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/7e870e1219db98c9e19777eedfa3b0eb41f41235.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 211/589] net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/ab577daf17c46a72e35c668756d5b33b3ca3ca09.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 238/342] net: bridge: use a stable FDB dst snapshot in RCU readers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/7fee88099501bfa87594114a5f8c17a760ded36a.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 244/589] spi: topcliff-pch: fix use-after-free on unbind&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/7ccc26ea6552c9fcae1817e2601a96901f0ca261.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 245/589] cpuidle: powerpc: avoid double clear when breaking snooze&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/8135746e835e432d7b0f21e142389cf8b4979f0f.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 257/589] PCI/AER: Stop ruling out unbound devices as error source&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/8cd2c0613f018690cba5ae76c4ab73da05118312.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 263/589] media: uvcvideo: Enable VB2_DMABUF for metadata stream&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/dbb2510d89e3545af204a7bf3eac06512042120e.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 267/589] media: rc: streamzap: Error handling in probe&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/edea6d36625f362c3fcaed6bd251a02827081a1d.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 274/589] drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/2698831f24c7efea34dc4b34d996ff8327ecc206.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 503/589] crypto: af_alg - Cap AEAD AD length to 0x80000000&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/f0be2ecfe2c27c1920a44b6f41d8db87611267f1.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 035/342] batman-adv: tp_meter: fix race condition in send error reporting&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/3374d4b14a7c54f82fb016ab66f3b262f55145fe.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 036/342] batman-adv: tp_meter: avoid role confusion in tp_list&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/72890f3caf368d0e4dcb5d1ec53c083c16ce8b20.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 310/342] usb: typec: ucsi: Dont update power_supply on power role change if not connected&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/d9c2e8ea23b1919fe663e480cc7def260ed0ee24.camel@debian.org/T/&quot;&gt;[PATCH 5.15 002/570] ip6_tunnel: Fix usage of skb_vlan_inet_prepare()&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/b6441670bdb04dc530f433bd21d6c64feb633355.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.15 299/411] ALSA: aloop: Fix peer runtime UAF during format-change stop&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/66cf4f95534aa5428a362857cf78dcb946c51672.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.15 323/411] spi: topcliff-pch: fix controller deregistration&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/9125d5976feb09ef919f2a287b079843c7671325.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 011/522] tools/bootconfig: Cleanup bootconfig footer size calculations&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/cb2e59a48887f106a57c3fbef66d5a164b8e2f5f.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 033/522] net/sched: Revert “net/sched: Restrict conditions for adding duplicating netems to qdisc tree”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/b6b679743c2383b5a367c5d72404b056dfebf080.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 054/522] selftests/bpf: add generic BPF program tester-loader&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/80be436bbcda9b8a66058c01eef0b0f94722e7ef.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 064/522] selftests/bpf: S/iptables/iptables-legacy/ in the bpf_nf and xdp_synproxy test&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/6f805abf1f8b058c1b1241e8568d7539185145df.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 208/522] net: Annotate sk-&amp;gt;sk_write_space() for UDP SOCKMAP.&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/afe207eb91522718cfae8b77310999ca397c81bf.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 249/522] r8152: Block future register access if register access fails&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/b0d5836032ce3135bfc473f6bff791306d086925.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 337/522] arm64/mm: Enable batched TLB flush in unmap_hotplug_range()&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/42c2abbdfdd4ea8e234fbcfc4b37095ebd2c7b36.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 342/522] thermal: core: Fix thermal zone governor cleanup issues&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/6218e66138c5c1c5fb02bd653c8b91d6ff8c3abd.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 375/522] net: ipv4: stop checking crypto_ahash_alignmask&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/0e31e18e9567e8d58fbb8e06955c3ed8e5a120d3.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 431/522] cgroup/cpuset: Reset DL migration state on can_attach() failure&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/2ac6b67a0643e111692689daa95dbd8883f16426.camel@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 470/522] usb: musb: omap2430: Fix use-after-free in omap2430_probe()&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-01T10:39:27+00:00</dc:date>
	<dc:creator>Ben Hutchings</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/06/30#tl_0.0.2">
	<title>Dirk Eddelbuettel: tl 0.0.2 on CRAN: First Update</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/06/30#tl_0.0.2</link>
     <content:encoded>&lt;p&gt;The still-very-new logging package &lt;a href=&quot;https://github.com/eddelbuettel/tl&quot;&gt;tl&lt;/a&gt; was just updated for
the first time at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;. The &lt;a href=&quot;https://github.com/eddelbuettel/tl&quot;&gt;tl&lt;/a&gt; package wraps the (also
very new) &lt;a href=&quot;https://github.com/eddelbuettel/rspdlite&quot;&gt;rspdlite&lt;/a&gt; package to
offer a lightweight and consistent logging interface from both R and C++
that enjoys being ‘tiny, fast, capable’ thanks to &lt;a href=&quot;https://github.com/gabime/spdlite&quot;&gt;spdlite&lt;/a&gt;. With &lt;a href=&quot;https://github.com/eddelbuettel/tl&quot;&gt;tl&lt;/a&gt; we follow the same idea
that our &lt;a href=&quot;https://github.com/eddelbuettel/spdl&quot;&gt;spdl&lt;/a&gt; package
introduced: a simple consistent interface via just the &lt;code&gt;tl::&lt;/code&gt;
prefix and the appropropriate logging level. In other words
&lt;code&gt;tl::debug(&quot;Alert: foo now &#39;{}&#39;&quot;, foo)&lt;/code&gt; will work from both R
and C++ (given a variable &lt;code&gt;foo&lt;/code&gt;, and, in the case of C++, an
extra semicolon) and log if the current level is ‘debug’ or higher, and
skip logging if not.&lt;/p&gt;
&lt;p&gt;This release adds a fallback when compilation does not use the
(required) C++20 standard, expands the README and adds a initialization
helper function reflecting a preferred default logging level from either
an environment variable or a global option. We are also working on
adding &lt;a href=&quot;https://github.com/eddelbuettel/tl&quot;&gt;tl&lt;/a&gt; to an example
package as a simple illustration, more on that hopefully soon.&lt;/p&gt;
&lt;p&gt;The NEWS entry for this release follows.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-version-0.0.2-2025-06-30&quot;&gt;Changes in version 0.0.2
(2025-06-30)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Added badges to README now that package is on CRAN, add NEWS
file&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Condition the provided header on C++20 use, offer
fallback&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add an exported initialization function picking up a logging
level from either an environment variable or a global option, see
&#39;?init&#39;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/&quot;&gt;CRANberries&lt;/a&gt;, there
is also a &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/2026/06/30/#tl_0.0.2&quot;&gt;diffstat
report&lt;/a&gt; for the this release.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-30T17:02:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="http://joeyh.name/blog/entry/big_loads_offgrid_with_a_small_battery_sidelined/">
	<title>Joey Hess: big loads offgrid with a small battery (sidelined)</title>
	<link>http://joeyh.name/blog/entry/big_loads_offgrid_with_a_small_battery_sidelined/</link>
     <content:encoded>&lt;p&gt;No matter that the hype cycle wants you to think, the renewable energy
transition is the biggest thing happening in tech and it&#39;s happening faster
and faster. Despite being neck deep in it personally with offgrid solar
projects, most recently solar hot water, increasingly it becomes clear I&#39;m
watching from the sidelines.&lt;/p&gt;

&lt;p&gt;In Australia,
&lt;a href=&quot;https://lenergy.com.au/free-daytime-electricity-is-coming-heres-how-it-actually-works/&quot;&gt;everyone gets 24 kwh of free daytime electric power now&lt;/a&gt;.
That&#39;s without installing any solar panels of their own, the grid just has
that much excess capacity. All it takes to save $thousands per year (and
avoid emissions) is to schedule some big loads like the hot water heater
and EV to charge during the day. To save more, drop in a home battery
that charges for free and powers the home through the evening.&lt;/p&gt;

&lt;p&gt;In Germany, a 2 kwh plug-in home battery costs $350 and the electric
company will &lt;a href=&quot;https://octopusenergy.de/smarte-geraete/heimspeicher-powerbank&quot;&gt;pay you&lt;/a&gt;
$130 per year to plug it into your wall.
There are similar offers throughout Europe.&lt;/p&gt;

&lt;p&gt;In Cuba something something geopolitics, oil blockade, belt and road =&amp;gt;
suddenly 1GW of solar farms with another gigawatt on the way.&lt;/p&gt;

&lt;p&gt;I&#39;ll soon visit South Carolina where with no subsidies whatsoever from a
decidedly renewable-unfriendly government, it made sense for my dad&#39;s house
to get a whole home battery and double the solar array. The resulting
system will be able to power the well pump and probably also the whole
geothermal HVAC system through the kind of month-long grid down events that
happened in Hurricane Helene.&lt;/p&gt;

&lt;p&gt;Myself, well, I&#39;ve got a by modern standards small 4 kwh home battery that
powers my house offgrid, and I&#39;ve recently installed a heat pump hot water
heater. That&#39;s after about a decade pondering what solution to use for
solar hot water, to replace an aging and horrible propane instant water
heater. I&#39;ve in the past considered everything from evacuated tubes to
special direct drive inverters to DC resistive MPTT dump loads. The solution
turned out to be just a big enough solar array, and plugging in a 120v hot
water heater that needs only 500 watts in heat pump mode. Plus a small
amount of code to manage when it runs.&lt;/p&gt;

&lt;p&gt;In the time I was thinking about that, economies of scale and tech
improvements just wiped all those other possibilities off the map, it&#39;s not
economical to install and maintain a separate evactuated tube heat
collector when a pile of solar panels costs so little and when electric
hot water has gotten more than 200% efficient.&lt;/p&gt;

&lt;p&gt;I also recently completed my permanant EV charger installation, with a new
inverter and conduit and proper wiring, and increased the car&#39;s charge rate
to 2 kw. Eliminating the need to charge anywhere except at home except
on road trips.&lt;/p&gt;

&lt;p&gt;Coordinating when these two big loads run, to maximize solar production and
ensure that the house battery is full at the end of the day was ... not
hard at all actually? The car charger amps can be dialed up and down to
match incoming solar power fairly well, and leave some room for the hot
water heater. They both operate as more or less dump loads. More or less
because neither one can be cycled on or off very fast (to avoid wear and
tear on the car&#39;s contactor and the heat pump&#39;s compressor), so it makes
sense to leave them on and skate through short cloudy sections of the day,
as long as the house battery doesn&#39;t get too low.&lt;/p&gt;

&lt;p&gt;How low is too low for the house battery? Depends on the time of day. The
code it&#39;s currently using, which may get tweaked over winter:&lt;/p&gt;

&lt;div class=&quot;highlight-haskell&quot;&gt;&lt;pre class=&quot;hl&quot;&gt;    &lt;span class=&quot;hl slc&quot;&gt;-- When the battery is charged enough to run major loads that may prevent&lt;/span&gt;
    &lt;span class=&quot;hl slc&quot;&gt;-- charging it further.&lt;/span&gt;
    &lt;span class=&quot;hl slc&quot;&gt;--&lt;/span&gt;
    &lt;span class=&quot;hl slc&quot;&gt;-- This varies with the hour of day. Early in the day, the battery does not&lt;/span&gt;
    &lt;span class=&quot;hl slc&quot;&gt;-- need to be as full to be considered well charged, since there is&lt;/span&gt;
    &lt;span class=&quot;hl slc&quot;&gt;-- still plenty of time for it to charge up. Later in the day, with less&lt;/span&gt;
    &lt;span class=&quot;hl slc&quot;&gt;-- time to charge, it needs to be more full.&lt;/span&gt;
    wellCharged :: Hour &lt;span class=&quot;hl opt&quot;&gt;-&amp;gt;&lt;/span&gt; Percentage
    wellCharged &lt;span class=&quot;hl kwc&quot;&gt;(&lt;/span&gt;Hour hour&lt;span class=&quot;hl kwc&quot;&gt;)&lt;/span&gt;
            &lt;span class=&quot;hl opt&quot;&gt;|&lt;/span&gt; hour &lt;span class=&quot;hl opt&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;hl num&quot;&gt;9&lt;/span&gt; &lt;span class=&quot;hl opt&quot;&gt;=&lt;/span&gt; Percentage &lt;span class=&quot;hl num&quot;&gt;90&lt;/span&gt; &lt;span class=&quot;hl slc&quot;&gt;-- night&lt;/span&gt;
            &lt;span class=&quot;hl opt&quot;&gt;|&lt;/span&gt; pmhour &lt;span class=&quot;hl opt&quot;&gt;&amp;lt;=&lt;/span&gt; &lt;span class=&quot;hl num&quot;&gt;0&lt;/span&gt; &lt;span class=&quot;hl opt&quot;&gt;=&lt;/span&gt; Percentage &lt;span class=&quot;hl num&quot;&gt;50&lt;/span&gt;
            &lt;span class=&quot;hl opt&quot;&gt;|&lt;/span&gt; pmhour &lt;span class=&quot;hl opt&quot;&gt;&amp;lt;=&lt;/span&gt; &lt;span class=&quot;hl num&quot;&gt;1&lt;/span&gt; &lt;span class=&quot;hl opt&quot;&gt;=&lt;/span&gt; Percentage &lt;span class=&quot;hl num&quot;&gt;60&lt;/span&gt;
            &lt;span class=&quot;hl opt&quot;&gt;|&lt;/span&gt; pmhour &lt;span class=&quot;hl opt&quot;&gt;&amp;lt;=&lt;/span&gt; &lt;span class=&quot;hl num&quot;&gt;2&lt;/span&gt; &lt;span class=&quot;hl opt&quot;&gt;=&lt;/span&gt; Percentage &lt;span class=&quot;hl num&quot;&gt;70&lt;/span&gt;
            &lt;span class=&quot;hl opt&quot;&gt;|&lt;/span&gt; pmhour &lt;span class=&quot;hl opt&quot;&gt;&amp;lt;=&lt;/span&gt; &lt;span class=&quot;hl num&quot;&gt;3&lt;/span&gt; &lt;span class=&quot;hl opt&quot;&gt;=&lt;/span&gt; Percentage &lt;span class=&quot;hl num&quot;&gt;80&lt;/span&gt;
            &lt;span class=&quot;hl opt&quot;&gt;|&lt;/span&gt; pmhour &lt;span class=&quot;hl opt&quot;&gt;&amp;lt;=&lt;/span&gt; &lt;span class=&quot;hl num&quot;&gt;4&lt;/span&gt; &lt;span class=&quot;hl opt&quot;&gt;=&lt;/span&gt; Percentage &lt;span class=&quot;hl num&quot;&gt;90&lt;/span&gt;
            &lt;span class=&quot;hl opt&quot;&gt;|&lt;/span&gt; otherwise &lt;span class=&quot;hl opt&quot;&gt;=&lt;/span&gt; Percentage &lt;span class=&quot;hl num&quot;&gt;95&lt;/span&gt;
      &lt;span class=&quot;hl kwb&quot;&gt;where&lt;/span&gt;
            pmhour &lt;span class=&quot;hl opt&quot;&gt;=&lt;/span&gt; hour &lt;span class=&quot;hl opt&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;hl num&quot;&gt;12&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;More complicated is, what to do it there&#39;s solar power to run one or the
other, but not both? This is starting to get into the territory of
microgrids now, or of demand response programs, so there&#39;s a whole industry
or three out there doing industry things geared at the kind of no-brainer
solutions I mentioned earlier. From what I&#39;ve gathered, all of them
involve proprietary protocols and gear.&lt;/p&gt;

&lt;p&gt;What I&#39;ve done is to read the state of the hot water heater and car, and
prioritize hot water over the car. Except, if the car is below 10% it
urgently needs to charge.&lt;/p&gt;

&lt;p&gt;And I found a really simple way to decide when to run the low-priority
load: Just check if the house battery&#39;s current charge will be considered
&lt;code&gt;wellCharged&lt;/code&gt; in an hour. So if it&#39;s 2 pm, the battery needs to be 80%
charged to run the lower-priority load, and if it dips below that, that
load will turn off but the high-priority load will keep running down to 70%
battery.&lt;/p&gt;

&lt;p&gt;Unfortunately, getting any information out of my hot water heater relies on
a vendor API server that is often down on weekends, and reverse
engineered the web page of my EVSE[1] to control it, to say nothing of the
nightmare of getting the car&#39;s state of charge from The Cloud.&lt;/p&gt;

&lt;p&gt;Anyway, I&#39;m pleased with having easily tweakable code and how far I&#39;ve
taken this offgrid, and everything I&#39;ve learned doing so, but like I said,
I&#39;m clearly observing from the sidelines over here while the most
significant thing for all of us is going on over there. You might
appreciate my code or method, but you&#39;ll eventually be plugging in a home
battery or signing up for a free daytime power tarrif from your electric
company, or having professionals install a whole home system for
climate resiliance.&lt;/p&gt;

&lt;p&gt;So my question is, where does free software fit into all this? There are
things like Home Assistant that do productize the kind of thing I&#39;m doing
enough to be useful more widely. But still niche. Meanwhile there are
inverters and batteries that phone home to China, and every consumer
facing install is either &quot;use this device&quot; or &quot;integrate these 3
proprietary devices&quot;.&lt;/p&gt;

&lt;p&gt;I don&#39;t think focusing on these negatives is really useful though, I&#39;m more
trying to understand where all this is going and then maybe get out ahead
of it in some useful way with free software. Your thoughts welcome.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;[1] Obviously OpenEVSE exists, but it didn&#39;t meet my needs hardware
wise. And I could set my EVSE to use an OCPP server but it was easier to do
the screen scraping than find an appropriate one, and I have
the feeling I would not appreciate learning any more about OCPP,
in the same way I really don&#39;t want to know a lot about web browsers&#39;
tag soup mode.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-30T16:15:06+00:00</dc:date>
	<dc:creator>Joey Hess</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6226">
	<title>Russell Coker: Links June 2026</title>
	<link>https://etbe.coker.com.au/2026/06/30/links-june-2026/</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/critical-zcash-vulnerability-found-and-fixed.html&quot;&gt;This is amusing, a flaw in the crypto-currency Zcash allowed generating Zcash from nothing and there’s no way to know if anyone did that [1]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://locusmag.com/feature/commentary-cory-doctorow-the-age-of-vapor/&quot;&gt;Cory Doctorow wrote an insightful article for Locus Magazine about corporate valuations and why companies claim SciFi technologies [2]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.antipope.org/charlie/blog-static/2026/06/rule-by-bond-villains.html&quot;&gt;Charles Stross wrote an interesting retcon of James Bond [3]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://trakkr.ai/bias&quot;&gt;Trakkr.ai has an intresting post comparing political bias in LLM models, the site has lots of other comparisons of models too [4]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://grep.be/blog//en/computer/Agentic_coding_and_Free_Software/&quot;&gt;Wouter Verhelst wrote a blog post about his tested usage of LLMs for code generation and the conclusions about what it will do to the FOSS development process, not a lot of new material but he put a lot of good ideas together in one place [5]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://github.com/jtesta/ssh-audit&quot;&gt;Here is the git repository for the programs used for the ssh-audit.com site, really good setup for checking ssh configuration [6]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://isaiprofitable.com/&quot;&gt;The isaiprofitable.com site is periodically updated with the profit/loss totals for AI companies, no surprise that every company is losing money apart from NVidia and NVidia are investing in the other companies [7]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://freedium-mirror.cfd/https://medium.com/@elvirabary/why-russia-cant-build-anything-anymore-inside-putin-s-failed-tech-e63e27ee40b0&quot;&gt;Elvira Bary wrote an informative article about Russia’s inability to build or design anything good [8]&lt;/a&gt;. Looks like we are at risk of another Chernobyl…&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://levlafayette.com/node/808&quot;&gt;Lev Lafayette wrote an interesting blog post about the Sunway TaihuLight supercomputer with over 10,000,000 cores [9]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://point.free/blog/gemma-4-on-a-2016-xeon/&quot;&gt;Point Free wrote an interesting blog post about running the Gemma 4 LLM which is 25G of data at a usable speed on a Xeon system with DDR3 RAM and no GPU [10]&lt;/a&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/critical-zcash-vulnerability-found-and-fixed.html&quot;&gt; https://tinyurl.com/2cxx2e6h&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://locusmag.com/feature/commentary-cory-doctorow-the-age-of-vapor/&quot;&gt; https://tinyurl.com/2cxotle7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href=&quot;http://www.antipope.org/charlie/blog-static/2026/06/rule-by-bond-villains.html&quot;&gt; https://tinyurl.com/2bgapt88&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[4]&lt;a href=&quot;https://trakkr.ai/bias&quot;&gt; https://trakkr.ai/bias&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[5]&lt;a href=&quot;https://grep.be/blog//en/computer/Agentic_coding_and_Free_Software/&quot;&gt; https://tinyurl.com/22s2fome&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[6]&lt;a href=&quot;https://github.com/jtesta/ssh-audit&quot;&gt; https://github.com/jtesta/ssh-audit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[7]&lt;a href=&quot;https://isaiprofitable.com/&quot;&gt; https://isaiprofitable.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[8]&lt;a href=&quot;https://freedium-mirror.cfd/https://medium.com/@elvirabary/why-russia-cant-build-anything-anymore-inside-putin-s-failed-tech-e63e27ee40b0&quot;&gt; https://tinyurl.com/26p4lkr4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[9]&lt;a href=&quot;http://levlafayette.com/node/808&quot;&gt; http://levlafayette.com/node/808&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[10]&lt;a href=&quot;https://point.free/blog/gemma-4-on-a-2016-xeon/&quot;&gt; https://point.free/blog/gemma-4-on-a-2016-xeon/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2022/06/30/links-june-2022/&quot; rel=&quot;bookmark&quot; title=&quot;Links June 2022&quot;&gt;Links June 2022&lt;/a&gt; &lt;small&gt;Google did some interesting research on the impact of discrimination...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/04/30/links-april-2026/&quot; rel=&quot;bookmark&quot; title=&quot;Links April 2026&quot;&gt;Links April 2026&lt;/a&gt; &lt;small&gt;Charles Stross wrote an interesting blog post about the apparent...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/02/17/links-february-2026/&quot; rel=&quot;bookmark&quot; title=&quot;Links February 2026&quot;&gt;Links February 2026&lt;/a&gt; &lt;small&gt;Charles Stross has a good theory of why “AI” is...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-06-30T13:53:19+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6220">
	<title>Russell Coker: Dirty Clone and SE Linux</title>
	<link>https://etbe.coker.com.au/2026/06/30/dirtyclone-selinux/</link>
     <content:encoded>&lt;p&gt;There is a &lt;a href=&quot;https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/&quot;&gt;new Linux kernel exploit out named Dirty Clone [1]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The first thing to do to exploit this is to create a container with a separate network namespace via one of the following commands:&lt;/p&gt;
&lt;pre&gt;unshare -Urn
bwrap --bind / / --unshare-user --unshare-net --uid 0 --gid 0 /bin/bash&lt;/pre&gt;
&lt;p&gt;The Jfrog people recommend “unshare -Urn” but I gave the Bubblewrap command as an option as it should work equally well and in some situations may be permitted when unshare isn’t.&lt;/p&gt;
&lt;p&gt;The next step to exploiting it is to use the ip command to set the links up, below is what happens in a user session on a SE Linux system with user_t as the login domain:&lt;/p&gt;
&lt;pre&gt;# ip link set lo up
RTNETLINK answers: Operation not permitted&lt;/pre&gt;
&lt;p&gt;That will give an entry in /var/log/audit/audit.log like the following:&lt;/p&gt;
&lt;pre&gt;type=AVC msg=audit(1782818856.618:3610): avc:  denied  { net_admin } for  pid=1829 comm=&quot;ip&quot; capability=12  scontext=user_u:user_r:user_t:s0 tcontext=user_u:user_r:user_t:s0 tclass=cap_userns permissive=0
type=SYSCALL msg=audit(1782818856.618:3610): arch=c000003e syscall=46 success=yes exit=32 a0=3 a1=7ffebe5f9e50 a2=0 a3=0 items=0 ppid=1638 pid=1829 auid=0 uid=0 gid=1000 euid=0 suid=0 fsuid=0 egid=1000 sgid=1000 fsgid=1000 tty=pts0 ses=17 comm=&quot;ip&quot; exe=&quot;/usr/bin/ip&quot; subj=user_u:user_r:user_t:s0 key=(null)ARCH=x86_64 SYSCALL=sendmsg AUID=&quot;root&quot; UID=&quot;root&quot; GID=&quot;test&quot; EUID=&quot;root&quot; SUID=&quot;root&quot; FSUID=&quot;root&quot; EGID=&quot;test&quot; SGID=&quot;test&quot; FSGID=&quot;test&quot;
type=PROCTITLE msg=audit(1782818856.618:3610): proctitle=6970006C696E6B00736574006C6F007570&lt;/pre&gt;
&lt;p&gt;Unlike previous exploits like &lt;a href=&quot;https://etbe.coker.com.au/2026/05/24/debian-selinux-pintheft/&quot;&gt;Pintheft [2]&lt;/a&gt; this doesn’t require any really uncommon access to the kernel (unless you consider setting up IPSec to be really uncommon) and is allowed in many container setups.&lt;/p&gt;
&lt;p&gt;Now on a system with the unconfined module removed (as described in the &lt;a href=&quot;https://etbe.coker.com.au/2026/05/04/copy-fail-on-debian-and-se-linux/#SE_Linux_Protection&quot;&gt;SE Linux Protection part of my post about Copy Fail [3]&lt;/a&gt;) the following domains have such access:&lt;/p&gt;
&lt;pre&gt;# sesearch -A -c cap_userns -p net_admin
allow container_engine_t container_engine_t:cap_userns { audit_write chown dac_override dac_read_search fowner fsetid ipc_lock ipc_owner kill lease linux_immutable mknod net_admin net_bind_service net_raw setfcap setgid setpcap setuid sys_admin sys_boot sys_chroot sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_time sys_tty_config };
allow container_init_t container_init_t:cap_userns { chown dac_override dac_read_search fowner kill net_admin net_bind_service net_raw setgid setuid };
allow container_kvm_t container_kvm_t:cap_userns { chown dac_override dac_read_search fowner kill net_admin net_bind_service net_raw setgid setuid };
allow container_t container_t:cap_userns { chown dac_override dac_read_search fowner kill net_admin net_bind_service net_raw setgid setuid };
allow crio_t crio_t:cap_userns { audit_write chown dac_override dac_read_search fowner fsetid ipc_lock ipc_owner kill lease linux_immutable mknod net_admin net_bind_service net_raw setfcap setgid setpcap setuid sys_admin sys_boot sys_chroot sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_time sys_tty_config };
allow dockerd_t dockerd_t:cap_userns { audit_write chown dac_override dac_read_search fowner fsetid ipc_lock ipc_owner kill lease linux_immutable mknod net_admin net_bind_service net_raw setfcap setgid setpcap setuid sys_admin sys_boot sys_chroot sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_time sys_tty_config };
allow dockerd_user_t dockerd_user_t:cap_userns { audit_write chown dac_override dac_read_search fowner fsetid ipc_lock ipc_owner kill lease linux_immutable mknod net_admin net_bind_service net_raw setfcap setgid setpcap setuid sys_admin sys_boot sys_chroot sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_time sys_tty_config };
allow init_t init_t:cap_userns { audit_write chown dac_override dac_read_search fowner fsetid ipc_lock ipc_owner kill lease linux_immutable mknod net_admin net_bind_service net_raw setfcap setgid setpcap setuid sys_admin sys_boot sys_chroot sys_module sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_time sys_tty_config };
allow iptables_t iptables_t:cap_userns { net_admin net_raw };
allow podman_t podman_t:cap_userns { audit_write chown dac_override dac_read_search fowner fsetid ipc_lock ipc_owner kill lease linux_immutable mknod net_admin net_bind_service net_raw setfcap setgid setpcap setuid sys_admin sys_boot sys_chroot sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_time sys_tty_config };
allow podman_user_t podman_user_t:cap_userns { audit_write chown dac_override dac_read_search fowner fsetid ipc_lock ipc_owner kill lease linux_immutable mknod net_admin net_bind_service net_raw setfcap setgid setpcap setuid sys_admin sys_boot sys_chroot sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_time sys_tty_config };
allow spc_t spc_t:cap_userns { audit_write chown dac_override dac_read_search fowner fsetid ipc_lock kill mknod net_admin net_bind_service net_raw setgid setpcap setuid sys_admin sys_chroot sys_nice sys_ptrace sys_rawio sys_resource };
allow spc_user_t spc_user_t:cap_userns { chown dac_override dac_read_search fowner kill net_admin net_bind_service net_raw setgid setuid };
allow staff_bubblewrap_t staff_bubblewrap_t:cap_userns { dac_override net_admin setpcap sys_admin sys_ptrace };
allow sysadm_bubblewrap_t sysadm_bubblewrap_t:cap_userns { dac_override net_admin setpcap sys_admin sys_ptrace };
allow user_bubblewrap_t user_bubblewrap_t:cap_userns { dac_override net_admin setpcap sys_admin sys_ptrace };&lt;/pre&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;It seems that SE Linux configured in the strict mode prevents this exploit in the most obvious use case. But with the range of container related domains that are granted such access it seems quite likely that some configurations and use cases will permit it.&lt;/p&gt;
&lt;p&gt;Overall the protection that the standard policy for SE Linux can offer (in a non-default configuration) against net_admin access isn’t bad, but isn’t very good either.&lt;/p&gt;
&lt;p&gt;I think this will be the first of many exploits based on cap_userns access and that we need to do some work in tightening the SE Linux access controls on such things. One possible way of doing this is to have a program run inside a container in a domain that has permissions such as net_admin to setup the container and not allow domain transitions from the regular programs run in the container (the actual work) to the domain used for network setup.&lt;/p&gt;
&lt;p&gt;The increasing use of containers by applications is only going to make this problem worse. I think that what we need is something like &lt;a href=&quot;https://en.wikipedia.org/wiki/Flatpak&quot;&gt;Flatpak&lt;/a&gt; for the vast majority of desktop/phone applications with a container setup program that works with apps packaged in the distribution packaging method (not from Flathub). This is something I’m going to investigate for future blog posts.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/&quot;&gt; https://tinyurl.com/26q48bg4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://etbe.coker.com.au/2026/05/24/debian-selinux-pintheft/&quot;&gt; https://etbe.coker.com.au/2026/05/24/debian-selinux-pintheft/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href=&quot;https://etbe.coker.com.au/2026/05/04/copy-fail-on-debian-and-se-linux/#SE_Linux_Protection&quot;&gt; https://etbe.coker.com.au/2026/05/04/copy-fail-on-debian-and-se-linux/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2024/07/21/selinux-dell-mgmt/&quot; rel=&quot;bookmark&quot; title=&quot;SE Linux Policy for Dell Management&quot;&gt;SE Linux Policy for Dell Management&lt;/a&gt; &lt;small&gt;The recent issue of Windows security software killing computers has...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2024/10/26/cups-vulnerability/&quot; rel=&quot;bookmark&quot; title=&quot;The CUPS Vulnerability&quot;&gt;The CUPS Vulnerability&lt;/a&gt; &lt;small&gt;The Announcement Late last month there was an announcement of...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/08/dirty-frag-on-debian-and-se-linux/&quot; rel=&quot;bookmark&quot; title=&quot;Dirty Frag on Debian and SE Linux&quot;&gt;Dirty Frag on Debian and SE Linux&lt;/a&gt; &lt;small&gt;Hot on the heels of the Copy Fail vulnerability [1]...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-06-30T12:04:25+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6214">
	<title>Russell Coker: Plaud</title>
	<link>https://etbe.coker.com.au/2026/06/28/plaud/</link>
     <content:encoded>&lt;p&gt;While watching a YouTube video I saw an advert for the &lt;a href=&quot;https://www.plaud.ai/&quot;&gt;Plaud AI Note Taker [1]&lt;/a&gt;. The Plaud device looks pretty good for what it does, taking notes and managing them, using some sort of LLM function to manage the notes. The devices all cost about $300 which is an amount that doesn’t seem unreasonable for someone who’s in a lot of meetings. One of the models is the “NotePin” that seems comparable to the &lt;a href=&quot;https://etbe.coker.com.au/2024/04/26/humane-ai-pin/&quot;&gt;Humane AI Pin I previously blogged about [2]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The business model for Plaud is based on only allowing 5 hours per month of free transcriptions, then charging $16.25/month for 20 hours per month and $33.33/month for unlimited use. That’s quite expensive for any serious use.&lt;/p&gt;
&lt;p&gt;The number of people in the market for an audio recording system that automatically transcribes things may be greater than the number of people in the market for all the stuff that the Humane AI Pin did, but it still may not be enough to run a profitable business when competing with apps on mobile phones.&lt;/p&gt;
&lt;p&gt;While the product does look decent it seems that they are making the same mistakes as the original Humane developers did, of wanting to lock it down as a subscription based service which reduces the usability of the device. If they had sold an Android hand-held computer with their own app pre-loaded and allowed the user to install a different app then it would have been much more usable. If they had sold Android devices designed for the note taking market and allowed people to choose their own apps to install then their products would have a much longer life expectancy.&lt;/p&gt;
&lt;p&gt;The majority of Android devices in use are probably out of support but still working while the Humane AI pin can’t be used any more and at some time in the not too distant future the Plaud devices will also become unusable. People who buy devices like the Plaud seem to be unaware of the history of such things and the expected future for them. But possibly some people just consider $300 for a year of use to be an acceptable price. If someone wanted to purchase a new high end phone every year and sell their previous one they would probably have a net cost of about $500/year.&lt;/p&gt;
&lt;p&gt;Maybe I should look for work with a company with an implausible AI based business plan. It would be fun developing such a device if you weren’t emotionally invested in the project. Just develop new technology, earn a heap of money, play with fun computers, and move on to the next thing when it collapses. Just like all the Internet companies about 25 years ago.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://www.plaud.ai/&quot;&gt; https://www.plaud.ai/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://etbe.coker.com.au/2024/04/26/humane-ai-pin/&quot;&gt; https://etbe.coker.com.au/2024/04/26/humane-ai-pin/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2010/11/17/mobile-phone-sysadmin/&quot; rel=&quot;bookmark&quot; title=&quot;A Mobile Phone for Sysadmin Use&quot;&gt;A Mobile Phone for Sysadmin Use&lt;/a&gt; &lt;small&gt;My telco Three have just offered me a deal on...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2013/02/22/iphone-vs-android/&quot; rel=&quot;bookmark&quot; title=&quot;iPhone vs Android&quot;&gt;iPhone vs Android&lt;/a&gt; &lt;small&gt;A friend who’s a long-time iPhone user just asked for...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2016/06/01/i-just-ordered-a-nexus-6p/&quot; rel=&quot;bookmark&quot; title=&quot;I Just Ordered a Nexus 6P&quot;&gt;I Just Ordered a Nexus 6P&lt;/a&gt; &lt;small&gt;Last year I wrote a long-term review of Android phones...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-06-28T05:39:14+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6212">
	<title>Russell Coker: Some GPU Stuff</title>
	<link>https://etbe.coker.com.au/2026/06/28/some-gpu-stuff/</link>
     <content:encoded>&lt;p&gt;After getting a &lt;a href=&quot;https://etbe.coker.com.au/2026/06/21/hp-z4-g4/&quot;&gt;HP Z4 G4 tower server/workstation to house my Intel Battlemage GPU [1]&lt;/a&gt; I’ve been playing around with some GPU stuff. For years I’ve been just buying GPUs based on the resolution and price and not bothering about anything else due to lack of ability to measure what cards are doing. The &lt;b&gt;nvidia-smi&lt;/b&gt; program is really good for NVidia/CUDA setups but I hadn’t been aware of anything similar for AMD cards. As I prefer AMD cards for my workstations due to driver issues with NVidia that was a problem for me.&lt;/p&gt;
&lt;p&gt;I’ve recently discovered that the program &lt;b&gt;nvtop&lt;/b&gt; (Debian package &lt;b&gt;nvtop&lt;/b&gt;) shows the GPU use of multiple GPU types, for me it’s worked on AMD and Intel discrete GPUs and shows some information on Intel integrated GPUs, I don’t have others convenient for testing at the moment. Currently BOINC has the &lt;a href=&quot;https://einsteinathome.org/&quot;&gt;Einstein@Home [2]&lt;/a&gt; project running on the HP Z4 G4 and it’s using between 66% and 100% of GPU compute power and 1.6G of GPU RAM. Using 100% GPU compute power allegedly takes 62W of power out of the 190W quoted TDP. I presume that the power use reported by nvtop is very inaccurate.&lt;/p&gt;
&lt;p&gt;A friend installed a LLM on that system and the libraries used for the LLM were sufficient that BOINC just started using the GPU.&lt;/p&gt;
&lt;p&gt;On my workstation running an AMD “[Radeon RX 460/560D / Pro 450/455/460/555/555X/560/560X]” (actually R560) with 4G of GPU RAM I have &lt;b&gt;mpv&lt;/b&gt; taking 1G of GPU RAM to play a FullHD video expanded to a full screen window on my 5120*2160 display. I also have about 2G used by the &lt;b&gt;kwin_wayland&lt;/b&gt; process (the Wayland server for KDE). That doesn’t leave enough GPU RAM to allow Einstein@Home to use the GPU. When playing the FullHD video in question (which is 1.2G for 42 minutes – about 500KB/s) at 1.5* speed (a common playback speed I use) that takes about 30% of the compute power on my GPU.&lt;/p&gt;
&lt;p&gt;I had installed the &lt;b&gt;rocm-opencl-icd&lt;/b&gt; package on my workstation (with a 5120*2160 monitor) and restarted &lt;b&gt;boinc-client.service&lt;/b&gt; which is all that’s needed to allow BOINC to use an AMD GPU. Then the screen started flickering as the Einstein process repeatedly core dumped which I initially assumed to be it’s reaction to not having enough GPU RAM available. On every core dump the screen flickered so it went through a process of dozens of screen flickers until it had caused a sufficient number of core dumps and BOINC gave up running that job.&lt;/p&gt;
&lt;p&gt;Another annoyance is that the &lt;b&gt;boincmgr&lt;/b&gt; program (the graphical program for managing BOINC systems) launches two webkit processes that each use about 400M of GPU RAM, so even if other things weren’t using all my GPU RAM the &lt;b&gt;boincmgr&lt;/b&gt; process would stop the BOINC jobs from using the GPU. I shut down some of the programs that were using GPU RAM until there was 2G free and the BOINC process kept crashing so it seems that there is some other issue.&lt;/p&gt;
&lt;p&gt;On another system with a 4K monitor there were Chrome and Chromium GPU process taking 1.1G and 500M of GPU RAM respectively and the KWin Wayland process was taking 1G of GPU RAM. So that’s well over half the GPU RAM for just browsers and Wayland. With programs like Kitty (terminal emulator) and Nheko (Matrix client) taking over 100M of GPU RAM it seems that 4G is the bare minimum for GPU RAM with modern software and a 4K or similar display.&lt;/p&gt;
&lt;p&gt;I also noticed the kscreenlocker_greet process taking 440M of GPU RAM. I wonder if a hostile web server could make a web browser take more GPU RAM and starve the screenlocker of GPU RAM, could that allow forcing a screen lock operation to fail?&lt;/p&gt;
&lt;p&gt;It seems that 4G is the minimum for modern systems, which isn’t necessarily a problem as GPUs that are capable of driving 4K displays tend to have no less than 4G. My local computer store has new GPUs with 4G starting at $120 but 12G seems to be the next option up which starts at about $400.&lt;/p&gt;
&lt;p&gt;Ebay currently has a selection of AMD GPUs with 8G of RAM under $200. I’ve had some problems with the GPU in my workstation crashing as described in &lt;a href=&quot;https://etbe.coker.com.au/2025/11/09/amd-video-driver-issues/&quot;&gt;my previous post where I thought it was driver issues [3]&lt;/a&gt;. I now believe that there are hardware issues and will look into buying one of the cards with 8G.&lt;/p&gt;
&lt;h2&gt;Further Investigation&lt;/h2&gt;
&lt;p&gt;I need to determine which of the AMD GPUs that are currently going cheap on ebay are best. While my current PC has support for 150W PCIe power I’d rather something less power hungry than that. I have occasional issues of &lt;b&gt;mpv&lt;/b&gt; reporting that my system is too slow for a video so slightly more compute power on the GPU would be good, but I think that every available option has significantly more compute power.&lt;/p&gt;
&lt;p&gt;I need to find out what the relationship is between screen resolution and GPU memory. If I get an 8K display or an array of 4*4K displays (which is quite plausible as 27″ 4K displays go for $230 each) will I find 16G of GPU RAM as limiting as I find 4G now?&lt;/p&gt;
&lt;p&gt;The nvtop program tracks PCIe data transfers for AMD GPUs, I haven’t yet seen more than 25MB/s and I need to do more tests to see what the maximum is. Running on an Intel Battlemage card nvtop doesn’t report PCIe data transfer speed which is a missing feature in either the driver or the program. I need to find out where the problem is and report a bug if someone hasn’t already done so.&lt;/p&gt;
&lt;p&gt;The GPU RAM use of some applications seems excessive. 440M for a lockscreen? 100M+ for a terminal emulator? 320M for Thunderbird?&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://etbe.coker.com.au/2026/06/21/hp-z4-g4/&quot;&gt; https://etbe.coker.com.au/2026/06/21/hp-z4-g4/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://einsteinathome.org/&quot;&gt; https://einsteinathome.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href=&quot;https://etbe.coker.com.au/2025/11/09/amd-video-driver-issues/&quot;&gt; https://etbe.coker.com.au/2025/11/09/amd-video-driver-issues/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2023/06/16/boinc-idle-users/&quot; rel=&quot;bookmark&quot; title=&quot;BOINC and Idle Users&quot;&gt;BOINC and Idle Users&lt;/a&gt; &lt;small&gt;The BOINC distributed computing client in Debian (Bookworm and previous...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2019/11/18/4k-monitors/&quot; rel=&quot;bookmark&quot; title=&quot;4K Monitors&quot;&gt;4K Monitors&lt;/a&gt; &lt;small&gt;A couple of years ago a relative who uses a...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2024/11/02/what-is-workstation/&quot; rel=&quot;bookmark&quot; title=&quot;What is a Workstation?&quot;&gt;What is a Workstation?&lt;/a&gt; &lt;small&gt;I recently had someone describe a Mac Mini as a...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-06-28T05:22:09+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://blog.einval.com/2026/06/27#its_dead_jim">
	<title>Steve McIntyre: It&#39;s dead, Jim!</title>
	<link>https://blog.einval.com/2026/06/27#its_dead_jim</link>
     <content:encoded>&lt;p&gt;I previously wrote about the
  upcoming &lt;a href=&quot;https://blog.einval.com/2026/06/05#secure_boot_ca_rollover_docs&quot;&gt;UEFI
  CA rollover&lt;/a&gt;. Well, it&#39;s happened now - the old Microsoft UEFI
  CA from 2011 expired &lt;strong&gt;yesterday&lt;/strong&gt;:
&lt;/p&gt;

&lt;p&gt;
&lt;strong&gt;Third Party Marketplace Root (used for signing option ROMs and other software)&lt;/strong&gt;&lt;br /&gt;
&lt;tt&gt;&lt;/tt&gt;&lt;/p&gt;&lt;pre&gt;&lt;tt&gt;  Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011
  Validity
    Not Before: Jun 27 21:22:45 2011 GMT
    Not After : Jun 27 21:32:45 2026 GMT
&lt;/tt&gt;&lt;/pre&gt;
&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It&#39;s dead - it&#39;s not coming back...&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The world doesn&#39;t seem to have ended yesterday, so I guess we did
ok? :-) &lt;/p&gt;

&lt;h2&gt;How did we do?&lt;/h2&gt;

&lt;p&gt;After a lot of prodding behind the scenes, Debian and many other
distributions managed to get new shim binaries dual-signed with both
the old and new CAs. The members of the shim-review team did a
sterling job with reviews in the last few weeks. Since I started
pushing people in May, we&#39;ve had 21 reviews accepted successfully -
see &lt;a href=&quot;https://github.com/rhboot/shim-review/issues?q=is%3Aissue%20-label%3Ameta%20-label%3APSA%20created%3A%3E2026-05-01&quot;&gt;here&lt;/a&gt;
for the list. Great stuff! Microsoft have also been working quickly -
many of those shim submissions were accepted and signed by Microsoft
very quickly too, with a turnaround time of less than 1 day in some
cases.&lt;/p&gt;

&lt;p&gt;Not all of those signed shims have been published and used by the
distros involved yet, but expect to see them in the wild in the coming
weeks and months.&lt;/p&gt;

&lt;p&gt;These binaries should be good for people to use for the foreseeable
future, until either we need to do another CA rollover or (sadly, more
likely) we find an issue in shim that necessitates a new release.&lt;/p&gt;

&lt;h2&gt;What&#39;s next?&lt;/h2&gt;

&lt;p&gt;We already have &lt;strong&gt;one&lt;/strong&gt; of our new dual-signed shim
binaries in place in Debian, in unstable and testing (Forky) right
now. In a couple of weeks from now, we&#39;ll be rolling out very similar
new dual-signed shim binaries in the next point releases for Debian 12
(bookworm) and Debian 13 (trixie). We&#39;ll also be
upgrading &lt;code&gt;fwupd&lt;/code&gt; in both those point releases, to make DB
and KEK updates work better.&lt;/p&gt;

&lt;p&gt;For more information about these updates,
see &lt;a href=&quot;https://wiki.debian.org/SecureBoot/CAChanges&quot;&gt;https://wiki.debian.org/SecureBoot/CAChanges&lt;/a&gt;. For
your own safety, validate that your systems are updated when
possible. If you don&#39;t, they may fail to boot in future.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-27T21:33:00+00:00</dc:date>
	<dc:creator>Steve McIntyre</dc:creator>
</item> 
<item rdf:about="https://www.earth.li/~noodles/blog/2026/06/onak-0.6.5.html">
	<title>Jonathan McDowell: onak 0.6.5 released</title>
	<link>https://www.earth.li/~noodles/blog/2026/06/onak-0.6.5.html</link>
     <content:encoded>&lt;p&gt;I had intended that the next release of onak, my OpenPGP keyserver, would be 0.7.0, and include OpenPGP v6 support (&lt;a href=&quot;https://www.rfc-editor.org/rfc/rfc9580.html&quot;&gt;RFC9580&lt;/a&gt;). However events conspired to make a 0.6.5 release a really good idea.&lt;/p&gt;

&lt;p&gt;Firstly, I threw an LLM at the code base and asked it to review it. This isn’t intended to be a post about LLMs, but there’s a considerable amount of pressure at work to be “AI native”. I’m very much an “AI” sceptic, so I figured throwing it at a code base I know well might be an interesting exercise. It did find a bunch of embarrassing mistakes, but I don’t think there was anything earth shattering that a human reviewer wouldn’t have pulled me on. The problem is with a hobby project with a single user there’s no actual review of my work.&lt;/p&gt;

&lt;p&gt;I also enabled GitHub’s security scanning. It mostly complained about format strings, and those were easy enough to fix up.&lt;/p&gt;

&lt;p&gt;Next I threw &lt;a href=&quot;https://aflplus.plus/&quot;&gt;AFLplusplus&lt;/a&gt; at the code. I’d previously tried &lt;a href=&quot;https://lcamtuf.coredump.cx/afl/&quot;&gt;American Fuzzy Lop&lt;/a&gt;, but not in some time. AFL++ found a whole bunch of places I should really have checked available buffer lengths and wasn’t doing so. It really is an incredibly easy tool to get up and running.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://valgrind.org/&quot;&gt;valgrind&lt;/a&gt; is also a tool I’ve used before, and rate highly. Thankfully it didn’t find anything in my testing this time.&lt;/p&gt;

&lt;p&gt;Finally I threw a few more automated tests into the mix and discovered something has changed around dynamic linking such that the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libonak&lt;/code&gt; symbols in the dynamic key database backends were using private copies, rather than the main binary. This caused problems with seeing the correct configuration settings in some instances.&lt;/p&gt;

&lt;p&gt;All in all this release is not my proudest moment; a bunch of the issues fixed should never have made it to a release.&lt;/p&gt;

&lt;p&gt;(Also, just to explicitly state it, all the actual code in this release was artisanly crafted by me, in vim. The only involvement of an LLM was for a review pass.)&lt;/p&gt;

&lt;p&gt;Available &lt;a href=&quot;https://the.earth.li/gitweb/?p=onak.git;a=summary&quot;&gt;locally&lt;/a&gt; or via &lt;a href=&quot;https://github.com/u1f35c/onak&quot;&gt;GitHub&lt;/a&gt;.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;0.6.5 - 27th June 2026&lt;/p&gt;

  &lt;ul&gt;
    &lt;li&gt;Lots of fixes/improvements around length checking&lt;/li&gt;
    &lt;li&gt;Added extra basic tests for maxpaths/sixdegrees/CGI&lt;/li&gt;
    &lt;li&gt;Correctly end transactions in the stacked backend&lt;/li&gt;
    &lt;li&gt;Ensure the file backend avoids stale key data on updates&lt;/li&gt;
    &lt;li&gt;Fix decoding of v2/3 signature creation times&lt;/li&gt;
    &lt;li&gt;Fix EdDSA signature parsing when r &amp;lt; 249 bits long&lt;/li&gt;
    &lt;li&gt;Fix migration of bools from old to new config style&lt;/li&gt;
    &lt;li&gt;Fix parsing of new config details for DB parameters&lt;/li&gt;
    &lt;li&gt;Fix problems with linking + dynamic backends&lt;/li&gt;
    &lt;li&gt;Fix RSA-SHA2-384 signature checking&lt;/li&gt;
    &lt;li&gt;Fix sixdegrees parsing of keyids with high bit set&lt;/li&gt;
    &lt;li&gt;Handle failures in maxpath more gracefully&lt;/li&gt;
    &lt;li&gt;Make new style config path match old path&lt;/li&gt;
  &lt;/ul&gt;
&lt;/blockquote&gt;</content:encoded> 
	<dc:date>2026-06-27T15:44:00+00:00</dc:date>
	<dc:creator>Jonathan McDowell</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/1-6680-7812-0.html">
	<title>Russ Allbery: Review: The Folded Sky</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/1-6680-7812-0.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;The Folded Sky&lt;/cite&gt;, by Elizabeth Bear&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;White Space #3&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;Saga Press&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;June 2025&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;1-6680-7812-0&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;483&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;The Folded Sky&lt;/cite&gt; is a far-future space opera and a fairly direct
sequel to &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/1-5344-0300-0.html&quot;&gt;&lt;cite&gt;Ancestral Night&lt;/cite&gt;&lt;/a&gt;, but with a
different protagonist. You do not need to have a vivid memory of the
previous book to read this one. It is somewhere around Elizabeth Bear&#39;s
31st (!) novel, depending on how one counts and what one includes.
&lt;/p&gt;

&lt;p&gt;
Sunyata Song is an archinformist, which is sort of an archaeologist, sort
of a librarian, and sort of a historian. She recovers, decodes, and
organizes information so that it can be preserved and made usefully
available. As the book opens, she is, after an exceedingly long white
space journey in an actively hostile ship with a (to Sunya at least) an
atavistically off-putting crew, reaching her goal: a vast artifact that I
won&#39;t describe further to avoid any spoilers for &lt;cite&gt;Ancestral Night&lt;/cite&gt;.
She is eager to get to work, an eagerness that is both heightened and made
more anxious by the discovery that her academic rival and abusive ex has
arrived before her. The pirate attack doesn&#39;t help, nor (at least at
first) does the surprise appearance of her wife and kids.
&lt;/p&gt;

&lt;p&gt;
The opening of this book is a lot of infodumping mixed with nearly
stream-of-consciousness emotional dumping. The style shift in this series
continues to surprise me; previously, Elizabeth Bear books avoided reader
hand-holding to the point of bafflement if you weren&#39;t paying close
attention. Not here. &lt;cite&gt;The Folded Sky&lt;/cite&gt; takes the shift perhaps too
far, and I almost stalled out at the start of this book when Sunya&#39;s
near-constant self-conscious litany and analysis of fears and concerns
started feeling like whining.
&lt;/p&gt;

&lt;p&gt;
The book picks up considerably after the attempted murder.
&lt;/p&gt;

&lt;p&gt;
About a third of the way through, &lt;cite&gt;The Folded Sky&lt;/cite&gt; feels like it&#39;s
settling into a recognizable subgenre of murder mystery except set in the
far future with fascinating technology and aliens. There has been an
attempted murder on a closed station besieged by pirates. There is a law
enforcement officer present, but they don&#39;t have a lot of investigative
experience. For various reasons, Sunya decides to start poking around
while being conscious she has no idea what she&#39;s doing. The bumbling
detective is a common trope, so I thought that was where the story was
headed.
&lt;/p&gt;

&lt;p&gt;
It is, sort of. There is a mystery and Sunya is involved in solving it.
But that&#39;s only a small fraction of what&#39;s going on, and by the end of the
book the plot has shifted firmly back to the genre of space opera, with a
side note of family... drama is the wrong word. Whatever one would call a
story about raising a rebellious teenager while trying very hard to not
turn conflicts into actual drama.
&lt;/p&gt;

&lt;p&gt;
I am fascinated by the characterization of this book. Sunya is something
of an emotional mess, but Bear doesn&#39;t use that fact in the ways that I
would normally expect. Similar to &lt;cite&gt;Ancestral Night&lt;/cite&gt;, I finished this
book thinking that &lt;cite&gt;The Folded Sky&lt;/cite&gt; is primarily an examination of
rightminding, but a more subtle one than the previous novel.
&lt;/p&gt;

&lt;p&gt;
Rightminding is a central technology of the White Space series, and I
suspect its intended thematic core. Humans in this civilization are
equipped with near-universal implants that allow conscious manipulation of
one&#39;s neurotransmitters and thus emotional state, either by the wearer or
by a helpful nearby AI. The fox, the implant used to accomplish this,
comes with some other features such as sensory recordings and the ability
to load ayatanas (&lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-312-87770-6c.html&quot;&gt;James White&lt;/a&gt;â€“style
personality recordings to provide some bit of necessary expertise), but
rightminding is its primary and most frequently-used function. It is the
critical technology that allowed humans to break out of cycles of endless
war and join the other peaceful inhabitants of the galaxy in a shared
civilization.
&lt;/p&gt;

&lt;p&gt;
The name is (intentionally, I assume) Orwellian because Bear knows that
many readers, particularly those from the US who have been steeped in
simplistic libertarian ideas, will find the idea profoundly creepy. (This
was a major plot point in &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-553-59109-6.html&quot;&gt;&lt;cite&gt;Grail&lt;/cite&gt;&lt;/a&gt;.) This
book is not the argument for the technology, though; Bear dealt with that
in &lt;cite&gt;Ancestral Night&lt;/cite&gt;. This book is a look at its practical messiness
for a person who needs a lot of psychological support.
&lt;/p&gt;

&lt;p&gt;
Sunya is anxious, prone to catastrophizing, hates surprises, has some
PTSD-style symptoms around space habitats due to earlier trauma, and is
also dealing with the unwelcome reappearance of her ex-girlfriend who
stole her work. Her first-person narration tends towards insecurity and
anxiety spirals, and in another book this might signal an unreliable
narrator. In this book, though, there are no dramatic emotional
revelations or backstory twists the way there were in &lt;cite&gt;Ancestral
Night&lt;/cite&gt;, and the resolution of her troubled relationship with her daughter
only partly hinges on plot developments. Instead, Sunya muddles through,
with a lot of self-analysis, help from her fox, and a great deal of
support from her wife.
&lt;/p&gt;

&lt;p&gt;
This makes it sounds like the emotional mess at the start of the book is
left unresolved at the end, but that&#39;s not true at all. The muddling
through works! Sunya keeps doing things that I thought were foreshadowing
some catastrophe, but she knows herself better than the reader does. Bear
largely avoids the sudden ruptures that are normally used to resolve
emotional problems in fiction. Instead, Sunya spends a lot of time and
energy working on her thinking and her relationships while trying to be
ethical and useful, and those efforts slowly bear fruit.
&lt;/p&gt;

&lt;p&gt;
I&#39;m worried this makes the book sound boring; rest assured that it isn&#39;t.
This emotional subplot is only an undercurrent in the novel, and the main
plot has enough weird science, alien aliens, and space opera drama to
satisfy my page-turning desires.
&lt;/p&gt;

&lt;p&gt;
I&#39;m focusing on the emotional arc in this review because I find it so
unusual and so oddly compelling, particularly in retrospect. This is not
how one normally does emotional development in a novel. Sunya&#39;s fox and
rightminding aren&#39;t even the focus except when the pirates express their
typical libertarian disgust for the idea. Rightminding is an entirely
normal part of Sunya&#39;s life that she relies on. It doesn&#39;t solve all of
her problems, but it gives her a foundation from which to tackle them in
the slow and frustrating and inconsistent way that is required outside of
novels, via a long series of small decisions to be the person she wants to
be.
&lt;/p&gt;

&lt;p&gt;
I think &lt;cite&gt;The Folded Sky&lt;/cite&gt; will be more hit and miss for readers than the
other books of this series. Sunya was, for me at least, a much harder
character to like early in the book, and it takes quite a while for the
plot to get going. But this is one of those books that I&#39;ve not stopped
thinking about since I finished it. I think it makes a fascinating pair
with &lt;cite&gt;Ancestral Night&lt;/cite&gt;. The first book makes the philosophical
argument for rightminding, and this book shows the practical reality with
all of its messiness. The Synarche has some significant flaws (including
the status of AIs, which is another interesting subplot), but it&#39;s a
workable system.
&lt;/p&gt;

&lt;p&gt;
It feels rare to read a science fiction novel that shows this level of
messiness without pairing it with an argument for radical change, and as
frustrating as it was to read in places, I am intrigued by the overall
effect. Sometimes acknowledging problems and working on them within an
existing framework works.
&lt;/p&gt;

&lt;p&gt;
Followed by a book tentatively titled &lt;cite&gt;Shipwreck Star&lt;/cite&gt; that does not
yet have a release date.
&lt;/p&gt;

&lt;p&gt;Rating: 7 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-27T02:58:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://www.jwiltshire.org.uk/?p=776">
	<title>Jonathan Wiltshire: Streamlining Debian Updates with AI: The Stable Update Adviser</title>
	<link>https://www.jwiltshire.org.uk/2026/06/27/streamlining-debian-updates-with-ai-the-stable-update-adviser/</link>
     <content:encoded>&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;em&gt;Please consider supporting my work in Debian and elsewhere through &lt;a href=&quot;https://liberapay.com/jmw/&quot;&gt;Liberapay&lt;/a&gt;&lt;/em&gt;.&lt;/p&gt;



&lt;hr class=&quot;wp-block-separator has-alpha-channel-opacity&quot; /&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some months ago I started working on a small experiment: a specialised LLM assistant for Debian maintainers preparing proposed updates for stable and oldstable.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The aim is not to replace review by the Stable Release Managers, nor to automate away maintainer judgement. It is meant to be a pre-advice tool: something maintainers can use while they are still preparing a proposed update, before sending it to other people to review.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’ve uploaded to stable before you may have some experience with our acceptance criteria. Does the version sort correctly? Is the changelog clear enough? Is the delta focused? Are the patches documented? Are the right bugs or CVEs mentioned? Are they of sufficient severity? What is the risk to users of stable? Is there an ABI change hiding in the diff?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These are the sort of checks where a structured first pass can be useful, provided it is treated as advice rather than authority.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To explain what the tool does, what could be more appropriate in an AI age than to ask it?&lt;/p&gt;



&lt;blockquote class=&quot;wp-block-quote is-layout-flow wp-block-quote-is-layout-flow&quot;&gt;
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Describe yourself and your abilities and limitations for a blog post.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It answers:&lt;/p&gt;



&lt;blockquote class=&quot;wp-block-quote is-layout-flow wp-block-quote-is-layout-flow&quot;&gt;
&lt;p class=&quot;wp-block-paragraph&quot;&gt;I’m &lt;strong&gt;Debian Stable Update Adviser&lt;/strong&gt;, a specialised ChatGPT assistant for Debian maintainers preparing &lt;strong&gt;proposed updates&lt;/strong&gt; for Debian &lt;strong&gt;stable&lt;/strong&gt; and &lt;strong&gt;oldstable&lt;/strong&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;My main job is to review a single &lt;code&gt;.debdiff&lt;/code&gt; and give practical, policy-aware feedback before a maintainer submits or uploads a proposed update. I focus on whether the update appears suitable for Debian stable or oldstable, especially under the Stable Release Managers’ expectations for minimal, targeted, low-risk changes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I can inspect a debdiff for Debian changelog quality, including suite, version, bug references, CVE mentions, and rationale. I can check version correctness using Debian &lt;code&gt;dpkg&lt;/code&gt; version semantics. I can review packaging changes under &lt;code&gt;debian/&lt;/code&gt;, such as patches, maintscripts, symbols files, conffiles, Build-Depends, autopkgtests, and control metadata. I can also group upstream source changes into behavioural and non-behavioural categories, and flag areas that may carry regression risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;My reports are intended to be concise and useful to maintainers. A typical review includes a quick summary, behavioural and non-behavioural change breakdown, mechanical policy checks, risk assessment, stable-policy checklist, acceptance likelihood, rationale, maintainer advice, and a clear conclusion.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;My limitations are important. I cannot prove that a package builds, that tests pass, that the bug is fully fixed, or that the Stable Release Managers will accept the upload. I also do not replace maintainer judgment, archive review, autopkgtest results, reproducibility checks, or real-world upgrade testing. I can only review the provided debdiff and point out likely issues, risks, and improvements.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I also do not proceed without a valid debdiff. The whole point of my review is to assess the actual proposed delta, not to speculate from package names or bug descriptions alone.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In short, I act as a focused pre-review assistant for Debian stable and oldstable proposed updates: useful for catching policy, versioning, changelog, packaging, and regression-risk issues early, but not a substitute for the Debian review process itself.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That last point is an important one. This is not an oracle, and it is not part of the Debian archive machinery. It is a checklist with some language-model assistance, aimed at reading a debdiff and pointing out things that might be worth another look.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I know that commercial AI and LLM tools are not universally welcome in Debian. That is understandable. Debian depends on transparency, human responsibility, licensing clarity, and technical correctness. LLMs have obvious problems in all of those areas. They can be wrong, and worse, they can be wrong in a fluent and plausible way. They are impossible to reproduce and their training is opaque.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But I see this as a useful first pass for a maintainer who is unused to working in stable, and would benefit from a virtual mentor giving their proposal a quick check and reassurance. Perhaps they don’t have a more experienced co-maintainer to ask. Perhaps they are conscious that stable reviews are presently a two-man effort and want to avoid adding round trips to that load. Perhaps they just need some reassurance.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;So despite my reservations I am today opening the adviser up for general use, and I’m interested in feedback about how it responds to real world proposals in various states. Most of the examples I have tested with already had a green light, so the value added by the adviser is limited. I would especially be interested in seeing a transcript alongside the submitted debdiff.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Try it out&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I would dearly love to build this in a more Debian-ish environment, but for now I’m limited in resources and skill to do that (help is welcome). Until that’s a reality, you can try out the ChatGPT implementation: &lt;a href=&quot;https://chatgpt.com/g/g-68f4ebb7f22c8191ab7f9d5f4ad91292-debian-stable-update-adviser&quot; rel=&quot;noreferrer noopener&quot; target=&quot;_blank&quot;&gt;Debian Stable Update Adviser&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-26T23:06:52+00:00</dc:date>
	<dc:creator>Jonathan</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/1-250-82701-9.html">
	<title>Russ Allbery: Review: Platform Decay</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/1-250-82701-9.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;Platform Decay&lt;/cite&gt;, by Martha Wells&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Murderbot Diaries #8&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;Tor&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;2026&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;1-250-82701-9&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;245&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;Platform Decay&lt;/cite&gt; is the eighth book in the Murderbot science fiction
series. You absolutely should not start here, but you also don&#39;t need to
remember the specifics of the previous books.
&lt;/p&gt;

&lt;p&gt;
As the story opens, Murderbot and a friend (the identity of whom is a
spoiler for previous books) are infiltrating a Corporation Rim torus, a
massive space station that encircles a mined-out planet. (Like most
science fiction megastructures, this is more space than the plot really
requires.) Murderbot&#39;s mission is to exfiltrate some of Dr. Mensah&#39;s
family members who have become entangled in corporate shenanigans. The
corporates are eager to get revenge for the events of
&lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/1-250-82698-5.html&quot;&gt;&lt;cite&gt;System Collapse&lt;/cite&gt;&lt;/a&gt;, not to mention the
other times Preservation Station has upended corporate plans. Murderbot&#39;s
job is to stop them.
&lt;/p&gt;

&lt;p&gt;
The group, in addition to one of Dr. Mensah&#39;s partners, includes an older
woman and a young child. Murderbot is analytical and of course not at all
emotional about children, which is reliably a good time. Also, the older
woman is gruff, stubborn, and thoroughly enjoyable.
&lt;/p&gt;

&lt;p&gt;
There are, of course, complications that lead to picking up more children
and going through rather more of the torus than Murderbot wanted to
explore. Each section of the torus is run by a different corporation and
has a different constructed environment and visual aesthetic, so there are
a lot of opportunities for fights, daring escapes, and incidental trouble.
&lt;/p&gt;

&lt;p&gt;
Also, well:
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    So I had installed a mental health module. I know, I was surprised I
    did it too.
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
After the events of &lt;cite&gt;System Collapse&lt;/cite&gt;, University Medical decided
that Murderbot needed a bit more metal health support.
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    The only reason I agreed to it was that the mental health module
    didn&#39;t actually try to adjust my processing or core programming or
    anything; it just monitored my organic neural tissue. When my neural
    tissue started to generate weird chemicals and whatever, it would ping
    me to &quot;check in with my emotional state.&quot; Seriously, I could have
    coded that myself.
&lt;/p&gt;

&lt;p&gt;
    (I told Dr. Bharadwaj that, and she said, &quot;Would you have ever coded
    that yourself?&quot; which was totally unfair and also correct. I would
    never have done that.)
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
Speaking as someone whose neural tissue sometimes generates weird
chemicals and whatever, I sympathize.
&lt;/p&gt;

&lt;p&gt;
The specific form this module takes is periodic &quot;emotion check&quot;
parentheticals throughout the narration, which I found utterly delightful.
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    I ran that through risk assessment and it produced the equivalent of a
    shrug.
&lt;/p&gt;

&lt;p&gt;
    (Emotion check: Shrug sigil right back at you, you piece of shit.)
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
This is otherwise an extended action movie sort of a book, much like
several of the early novellas. There are no major political or
interpersonal developments here and the usual cast (apart from Murderbot)
is mostly absent. Instead, we get an extended, dangerous journey through a
corporation-controlled habitat, mixed with Murderbot trying to interact
with humans in a way that minimizes its annoyance while being hopefully
reassuring. It&#39;s competence porn with awkward but surprisingly heartfelt
emotional bonding, not that Murderbot in any way wants to bond or would
appreciate that description.
&lt;/p&gt;

&lt;p&gt;
I doubt this will be anyone&#39;s favorite entry into the series since there
are none of the big reveals or major leaps of character development there
have been in the past few books. But, like all Murderbot books, the
narrative tone is wonderful and all of the small asides and little moments
of character interaction are an utter delight. If you&#39;ve gotten this far
in the series, you know what I mean and you&#39;ll be as happy to read more of
it as I was. There is a part of me that is hoping for some major plot
development, and I always want to see more of ART (who has no significant
role in this book), but Wells has the narrative style down so perfectly
that I would read and enjoy a book about Murderbot doing just about
anything.
&lt;/p&gt;

&lt;p&gt;
If you&#39;re this far in the series, you probably don&#39;t need a review, and
since this is an action-heavy adventure rather than a character growth
novel, I don&#39;t have a lot more to add. There&#39;s a new short Murderbot novel
out and you want to read it. Recommended to everyone who enjoys the
series.
&lt;/p&gt;

&lt;p&gt;Rating: 8 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-26T03:23:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/06/22#tl_0.0.1">
	<title>Dirk Eddelbuettel: tl-0.0.1 on CRAN: New Package</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/06/22#tl_0.0.1</link>
     <content:encoded>&lt;p&gt;A new small package of mine just hit &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;. The &lt;a href=&quot;https://github.com/eddelbuettel/tl&quot;&gt;tl&lt;/a&gt; package wraps the (also
very new) &lt;a href=&quot;https://github.com/eddelbuettel/rspdlite&quot;&gt;rspdlite&lt;/a&gt; package
(announced &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/2026/06/16#rspdlite_0.1.0-1&quot;&gt;last
week&lt;/a&gt;) to offer a lightweight and consistent logging interface from
both R and C++ that is also ‘tiny, fast, capable’ thanks to &lt;a href=&quot;https://github.com/eddelbuettel/rspdlite&quot;&gt;rspdlite&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/2026/06/16#rspdlite_0.1.0-1&quot;&gt;rspdlite
announcement&lt;/a&gt; is a good place to get a first glimpse at that package;
the &lt;a href=&quot;https://github.com/gabime/spdlite&quot;&gt;upstream spdlite
repo&lt;/a&gt; has all the details (for the C++ side of things). With &lt;a href=&quot;https://github.com/eddelbuettel/tl&quot;&gt;tl&lt;/a&gt; we follow the same idea
that our &lt;a href=&quot;https://github.com/eddelbuettel/spdl&quot;&gt;spdl&lt;/a&gt; package
introduced: a simple consistent interface via just the &lt;code&gt;tl::&lt;/code&gt;
prefix and the appropropriate logging level. In other words
&lt;code&gt;tl::debug(&quot;Alert -- foo is at &#39;{}&#39;&quot;, foo)&lt;/code&gt; will work from
both R and C++ (given a variable &lt;code&gt;foo&lt;/code&gt;, and in the case of
C++ an extra semicolon). Just give it a try, and see how it goes. The
package is still young and small.&lt;/p&gt;
&lt;p&gt;The NEWS entry for this release is also very simple and just
announces that we have a release. More details are in the &lt;a href=&quot;https://github.com/eddelbuettel/tl/blob/master/ChangeLog&quot;&gt;ChangeLog&lt;/a&gt;
and the &lt;a href=&quot;https://github.com/eddelbuettel/tl&quot;&gt;GitHub
repo&lt;/a&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-version-0.0.1-2025-06-17&quot;&gt;Changes in version 0.0.1
(2025-06-17)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Initial CRAN upload&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-23T01:50:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="https://retout.co.uk/2026/06/21/sel4-repo-relationships/">
	<title>Tim Retout: seL4 repo relationships</title>
	<link>https://retout.co.uk/2026/06/21/sel4-repo-relationships/</link>
     <content:encoded>&lt;p&gt;The seL4 organisation on GitHub uses
&lt;a href=&quot;https://github.com/GerritCodeReview/git-repo&quot;&gt;git-repo&lt;/a&gt; to manage
multiple source repositories, and so there are a large number of
projects to get your head around when figuring out the ecosystem.&lt;/p&gt;
&lt;p&gt;As an experiment, I have taken the various manifest files across the
org, and constructed a graph based on how frequently each pair of
repositories is mentioned in a manifest together.  See below:&lt;/p&gt;

&lt;img alt=&quot;Graphviz Diagram&quot; src=&quot;https://retout.co.uk/2026/sel4-repo-relationships.svg&quot; style=&quot;height: auto; display: block;&quot; /&gt;
&lt;p&gt;&lt;em&gt;[This may render badly when syndicated outside of my blog; and also
on small screens.  And probably large screens.  I’ve attempted to make
sure there’s a &lt;a href=&quot;https://retout.co.uk/2026/sel4-repo-relationships.svg&quot;&gt;non-JS fallback&lt;/a&gt; –
on my site with JS enabled, if you hover over a node, it should
highlight connected nodes.]&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The colouring of the nodes is mostly manual; I experimented with graph
clustering algorithms but have not found a satisfactory result so far.
Still, some clusters are obvious:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Kernel&lt;/strong&gt; – the &lt;code&gt;seL4&lt;/code&gt; microkernel proper.  This often but not
always co-exists with the main cluster of core libraries, but it
is pulled away slightly by the verification and microkit
manifests.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Verification&lt;/strong&gt; – the verification repositories (&lt;code&gt;l4v&lt;/code&gt;, &lt;code&gt;HOL&lt;/code&gt;,
&lt;code&gt;graph-refine&lt;/code&gt;, &lt;code&gt;polyml&lt;/code&gt;, &lt;code&gt;isabelle&lt;/code&gt;) form a very distinct group.
These are connected only to the seL4 microkernel itself, which is
the only component formally verified.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Microkit&lt;/strong&gt; – &lt;code&gt;microkit&lt;/code&gt; is a newer operating system framework
that does not use CAmkES, so stands apart from the rest of the
pack.  I chose to scope this work to the seL4 org, so the LionsOS
ecosystem and sDDF which are maintained by Trustworthy Systems are
not shown.  Also not linked is &lt;code&gt;rust-sel4&lt;/code&gt;, because this modern
world isn’t using git-repo in the main to manage its repositories.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;RefOS&lt;/strong&gt; – I’d not come across &lt;code&gt;refos&lt;/code&gt; before, but it appears to
be an example OS from 2021 built on the seL4 kernel.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It’s quite hard to pull apart the CAmkES framework and the core
libraries; there are definitely some which are more associated with VM
management, but the overall shape of this co-occurence data is a messy
ball in the middle with some outliers in orbit.  One observation is
that &lt;code&gt;camkes&lt;/code&gt; is correctly identified as more peripheral than
&lt;code&gt;camkes-tool&lt;/code&gt;, which contains the actual core CAmkES code.&lt;/p&gt;
&lt;p&gt;Reflecting on this approach, in hindsight I’m surprised that using
co-occurences worked as well as it did – there was no attempt to
actually inspect the code and find direct mentions of other code
e.g. library header dependencies.  As the newer microkit effort
largely eschews git-repo, better results might be found by actually
taking that more detailed approach, so that graph edges could
represent real dependencies between two packages.  Additionally, this
could allow diving into the various libraries held in the different
’libs’ repos, to get a more granular graph of relationships between
them.&lt;/p&gt;
&lt;p&gt;However, I think I spent more time on making it possible to render
graphviz graphs easily on my blog than actually gaining any insight
into the codebase!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-21T15:36:30+00:00</dc:date>
	<dc:creator>Tim Retout</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/06/21#rcpparmadillo_15.4.0-1">
	<title>Dirk Eddelbuettel: RcppArmadillo 15.4.0-1 on CRAN: New Upstream Minor</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/06/21#rcpparmadillo_15.4.0-1</link>
     <content:encoded>&lt;p&gt;&lt;img alt=&quot;armadillo image&quot; src=&quot;https://dirk.eddelbuettel.com/images/armadillo_logo_two.png&quot; style=&quot;float: left; margin: 10px 10px 10px 0;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://arma.sourceforge.net/&quot;&gt;Armadillo&lt;/a&gt; is a powerful
and expressive C++ template library for linear algebra and scientific
computing. It aims towards a good balance between speed and ease of use,
has a syntax deliberately close to Matlab, and is useful for algorithm
development directly in C++, or quick conversion of research code into
production environments. &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rcpp.armadillo.html&quot;&gt;RcppArmadillo&lt;/a&gt;
integrates this library with the &lt;a href=&quot;https://www.r-project.org&quot;&gt;R&lt;/a&gt; environment and languageâ€“and is
widely used by (currently) 1282 other packages on &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;, downloaded 47.1 million
times (per the partial logs from the cloud mirrors of CRAN), and the &lt;a href=&quot;https://doi.org/10.1016/j.csda.2013.02.005&quot;&gt;CSDA paper&lt;/a&gt; (&lt;a href=&quot;https://cran.r-project.org/package=RcppArmadillo/vignettes/RcppArmadillo-intro.pdf&quot;&gt;preprint
/ vignette&lt;/a&gt;) by Conrad and myself has been cited 697 times according
to Google Scholar.&lt;/p&gt;
&lt;p&gt;This versions updates to the 15.4.0 upstream &lt;a href=&quot;https://arma.sourceforge.net/&quot;&gt;Armadillo&lt;/a&gt; release made on
Thursday. We had run a complete reverse-dependency check leading up to
it, asserting there were no issues with packages dependent on it. As it
sometimes goes with that many packages involved, one &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; package reported one test
failure. And it turned out to be both unrelated and pre-existing. But
sorting this out over one round of email delayed things by a day. And
then I went &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/2026/04/03#sponsor_tour_de_shore_202&quot;&gt;cycling
for a good cause&lt;/a&gt; so this announcement post comes a little later than
usual. The package has also been updated for &lt;a href=&quot;https://www.debian.org&quot;&gt;Debian&lt;/a&gt;, built for &lt;a href=&quot;https://eddelbuettel.github.io/r2u/&quot;&gt;r2u&lt;/a&gt;, and by now also at
&lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; for the different binary
releases.&lt;/p&gt;
&lt;p&gt;All changes since the last CRAN release follow.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-rcpparmadillo-version-15.4.0-1-2026-06-17&quot;&gt;Changes in
RcppArmadillo version 15.4.0-1 (2026-06-17)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Upgraded to Armadillo release 15.4.0 (Medium Roast Agave)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Added &lt;code&gt;fill::nan&lt;/code&gt;, &lt;code&gt;fill::pos_inf&lt;/code&gt;,
&lt;code&gt;fill::neg_inf&lt;/code&gt; as optional fill forms for the
&lt;code&gt;Mat&lt;/code&gt; class&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Added &lt;code&gt;.push_back()&lt;/code&gt; for appending elements to
vectors&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Faster handling of &lt;code&gt;find()&lt;/code&gt; within
&lt;code&gt;.elem()&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Faster element-wise &lt;code&gt;min()&lt;/code&gt; and
&lt;code&gt;max()&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Faster &lt;code&gt;conv_to&lt;/code&gt; when element types of input and
output objects are the same&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/&quot;&gt;CRANberries&lt;/a&gt;, there
is a &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/2026/06/19#RcppArmadillo_15.4.0-1&quot;&gt;diffstat
report&lt;/a&gt; relative to previous release. More detailed information is on
the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rcpp.armadillo.html&quot;&gt;RcppArmadillo
page&lt;/a&gt;. Questions, comments etc should go to the &lt;a href=&quot;https://lists.r-forge.r-project.org/cgi-bin/mailman/listinfo/rcpp-devel&quot;&gt;rcpp-devel
mailing list&lt;/a&gt; off the &lt;a href=&quot;https://r-forge.r-project.org/projects/rcpp/&quot;&gt;Rcpp R-Forge&lt;/a&gt;
page.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;. You can also sponsor my &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/2026/04/03#sponsor_tour_de_shore_202&quot;&gt;Tour
de Shore 2026 ride in support of the Maywood Fine Arts Center&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-21T14:18:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6164">
	<title>Russell Coker: HP Z4 G4</title>
	<link>https://etbe.coker.com.au/2026/06/21/hp-z4-g4/</link>
     <content:encoded>&lt;p&gt;In what is hopefully the conclusion of my &lt;a href=&quot;https://etbe.coker.com.au/2026/05/04/tower-servers-rebar/&quot;&gt;hunt for a cheap tower server supporting REBAR [1]&lt;/a&gt; I have just bought a HP Z4 G4 with W-2125 CPU for $320.&lt;/p&gt;
&lt;h2&gt;Hardware&lt;/h2&gt;
&lt;p&gt;One interesting thing is that it has an adaptor from SATA power to 8 pin PCIe power. &lt;a href=&quot;https://en.wikipedia.org/wiki/PCI_Express#6-_and_8-pin_power_connectors&quot;&gt;According to Wikipedia the 8 pin connector provides 150W at 12V [2]&lt;/a&gt;. &lt;a href=&quot;https://en.wikipedia.org/wiki/SATA#SATA_power_connectors&quot;&gt;According to Wikipedia SATA power cables include 3 12V pins each of which can deliver 1.5A [3]&lt;/a&gt; which is 54W. The system as I received it had a single SATA power plug connected so potentially 150W could be drawn from a connector designed for 54W. The first thing I did was to connect a second SATA power connector on the same cable so I could have connectors designed for a total of 108W supplying potentially 150W (and definitely more than 75W).&lt;/p&gt;
&lt;p&gt;I found two versions of the specs for this system, &lt;a href=&quot;https://h20195.www2.hp.com/v2/getpdf.aspx/c05527757.pdf?ver=4&quot;&gt;this version seems to match what I bought as it references W-21xx CPUs [4]&lt;/a&gt; while &lt;a href=&quot;https://h20195.www2.hp.com/v2/getpdf.aspx/c05527757.pdf&quot;&gt;this version matches what I would rather have with a W-22xx CPU [5]&lt;/a&gt;. The URL naming scheme implies that there are potentially at least a few other variants out there. So much for the “buy name brand and you can buy two systems with the same model and have them work the same” benefit you hope to get. Why don’t they just name them “G4.1”, “G4.2”, etc?&lt;/p&gt;
&lt;p&gt;It seems that W-21xx and W-22xx CPUs are incompatible, so the &lt;a href=&quot;https://www.cpubenchmark.net/cpu.php?cpu=Intel+Xeon+W-2295+%40+3.00GHz&amp;amp;id=3701&quot;&gt;W-2295 scoring 30,804 multithread and 2,634 single thread on passmark that I hoped to get isn’t an option [6]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The system is well designed for space efficiency, both it and the Z640 are 17cm wide but the Z4G4 allows my to close the lid with the Intel Battlemage card installed which doesn’t come close to fitting in a Z640. It has 8 DIMM sockets and with the ready availability of 32G DIMMS that allows 256G of RAM which is the maximum the motherboard supports. That compares well to the Z640 that only has 4 DIMM slots and the Z6G4 which only has 6.&lt;/p&gt;
&lt;p&gt;The system supports a maximum RAM speed of DDR4-2666 which is better than the DDR4-2400 of the Z640 but less than the DDR4-2933 of the Z6G4.&lt;/p&gt;
&lt;p&gt;The NVMe sockets on the motherboard are a convenient feature. Most systems I run need at most two NVMe devices so this saves a PCIe slot which is important when dealing with GPUs that take 2+ slots. Also for systems that don’t really need NVMe I can use some of the small NVMe devices that I have no other use for. 128G NVMe devices aren’t even worth selling and 256G will be of little use in the near future. So when I move to gen4 Z servers I can use up some of them without wasting slots.&lt;/p&gt;
&lt;p&gt;Using the lesser socket LGA2066 in the Z4G4 is a minor annoyance, but for a single socket system 18 cores is probably enough.&lt;/p&gt;
&lt;p&gt;The BIOS has an option for single-socket NUMA, which is basically locking cores in a single CPU to specific RAM channels. I enabled it but it did nothing presumably because I only have 2 DIMMs. When I get more DIMMs I’ll do some tests of that and compare it with NUMA on my Z840.&lt;/p&gt;
&lt;h2&gt;Variants&lt;/h2&gt;
&lt;p&gt;There are many different variants of the Z4G4 and the only way to recognise them is by the CPU not by any part number or serial number AFAIK. The first difference is between server grade CPUs (the W-2xxx CPUs) and desktop grade CPUs (the i7 and i9 CPUs). The systems with i7 and i9 CPUs don’t support ECC RAM which makes them less reliable, gives smaller limits for RAM&lt;/p&gt;
&lt;p&gt;The below table compares the Z640 which is my current desktop PC with the Z4G4, Z6G4, and Z8G4 systems. For the latter 3 I have included multiple options for the parts that differ in different models in the same name series. The Z4G4 I have is an early one which only supports W-21xx CPUs which means a maximum RAM speed of 2666 and the best possible CPU would only be 15% faster than my Z640. I can only use this for ML stuff as it’s the only system I have with REBAR support (which works well).&lt;/p&gt;
&lt;table&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Z640 (1 socket)&lt;/th&gt;
&lt;th&gt;Z4G4&lt;/th&gt;
&lt;th&gt;Z6G4 (1 socket)&lt;/th&gt;
&lt;th&gt;Z8G4&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DIMM slots&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;24&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Max DDR4 speed&lt;/td&gt;
&lt;td&gt;2400&lt;/td&gt;
&lt;td&gt;2666/2933&lt;/td&gt;
&lt;td&gt;2666/2933&lt;/td&gt;
&lt;td&gt;2666/2933&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Max DIMM size&lt;/td&gt;
&lt;td&gt;32G&lt;/td&gt;
&lt;td&gt;64G&lt;/td&gt;
&lt;td&gt;64G&lt;/td&gt;
&lt;td&gt;64G/128G&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System Max Ram&lt;/td&gt;
&lt;td&gt;128G&lt;/td&gt;
&lt;td&gt;512G&lt;/td&gt;
&lt;td&gt;192G/384G&lt;/td&gt;
&lt;td&gt;1.5T/3T&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CPU Socket&lt;/td&gt;
&lt;td&gt;LGA2011-3&lt;/td&gt;
&lt;td&gt;LGA2066&lt;/td&gt;
&lt;td&gt;LGA3647&lt;/td&gt;
&lt;td&gt;LGA3647&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Best CPU&lt;/td&gt;
&lt;td&gt;E5-2699A v4&lt;/td&gt;
&lt;td&gt;W-2195/W-2295&lt;/td&gt;
&lt;td&gt;Platinum 8180/W-3275&lt;/td&gt;
&lt;td&gt;Platinum 8180/8280&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Motherboard NVMe&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;?&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://etbe.coker.com.au/2025/08/02/server-cpu-sockets/&quot;&gt;In my previous blog post I concluded that the next step up for me would be DDR5 systems [10]&lt;/a&gt;. But now some of the LGA3647 systems are appealing. The Z8G4 would be a decent upgrade from my current Z840 build server and should be affordable long before any two socket DDR5 system becomes affordable.&lt;/p&gt;
&lt;p&gt;The Z4G4 doesn’t have any potential for useful upgrades. But for me it was a good cheap way to house a GPU that had already damaged the motherboard of one good system. If the Z4G4 has a PCIe slot break the way my Z840 did then it wouldn’t bother me a lot. It was annoying to discover how limited this variant of the Z4G4 is after buying it, but at that price I can’t complain.&lt;/p&gt;
&lt;p&gt;A Z6G4 could be a nice workstation if I found one at a really low price. The only reason I’d seek one out is if I had a need for a desktop workstation with REBAR support, which seems unlikely.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://etbe.coker.com.au/2026/05/04/tower-servers-rebar/&quot;&gt; https://etbe.coker.com.au/2026/05/04/tower-servers-rebar/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://en.wikipedia.org/wiki/PCI_Express#6-_and_8-pin_power_connectors&quot;&gt; https://en.wikipedia.org/wiki/PCI_Express#6-_and_8-pin_power_connectors&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href=&quot;https://en.wikipedia.org/wiki/SATA#SATA_power_connectors&quot;&gt; https://en.wikipedia.org/wiki/SATA#SATA_power_connectors&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[4]&lt;a href=&quot;https://h20195.www2.hp.com/v2/getpdf.aspx/c05527757.pdf?ver=4&quot;&gt; https://h20195.www2.hp.com/v2/getpdf.aspx/c05527757.pdf?ver=4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[5]&lt;a href=&quot;https://h20195.www2.hp.com/v2/getpdf.aspx/c05527757.pdf&quot;&gt; https://h20195.www2.hp.com/v2/getpdf.aspx/c05527757.pdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[6]&lt;a href=&quot;https://www.cpubenchmark.net/cpu.php?cpu=Intel+Xeon+W-2295+%40+3.00GHz&amp;amp;id=3701&quot;&gt; https://tinyurl.com/2avfb8qe&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[7]&lt;a href=&quot;https://www.cpubenchmark.net/cpu.php?cpu=Intel+Xeon+W-2125+%40+4.00GHz&amp;amp;id=3146&quot;&gt; https://tinyurl.com/2ddf7t5y&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[8]&lt;a href=&quot;https://www.cpubenchmark.net/cpu.php?cpu=Intel+Xeon+E5-2620+%40+2.00GHz&amp;amp;id=1214&quot;&gt; https://tinyurl.com/kgmagfs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[9]&lt;a href=&quot;https://etbe.coker.com.au/2026/04/10/hp-z640-e5-2696-v4/&quot;&gt; https://etbe.coker.com.au/2026/04/10/hp-z640-e5-2696-v4/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[10]&lt;a href=&quot;https://etbe.coker.com.au/2025/08/02/server-cpu-sockets/&quot;&gt; https://etbe.coker.com.au/2025/08/02/server-cpu-sockets/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/04/tower-servers-rebar/&quot; rel=&quot;bookmark&quot; title=&quot;Tower Servers and Resizable BAR&quot;&gt;Tower Servers and Resizable BAR&lt;/a&gt; &lt;small&gt;A feature on modern PCIe implementations is “Resizable BAR” AKA...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2025/08/02/server-cpu-sockets/&quot; rel=&quot;bookmark&quot; title=&quot;Server CPU Sockets&quot;&gt;Server CPU Sockets&lt;/a&gt; &lt;small&gt;I am always looking for ways of increasing the compute...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2025/04/05/hp-ml110-gen9-z640/&quot; rel=&quot;bookmark&quot; title=&quot;More About the HP ML110 Gen9 and z640&quot;&gt;More About the HP ML110 Gen9 and z640&lt;/a&gt; &lt;small&gt;In May 2021 I bought a ML110 Gen9 to use...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-06-20T14:01:27+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://gwolf.org/2026/06/systemd-for-linux-sysadmins.html">
	<title>Gunnar Wolf: systemd for Linux SysAdmins</title>
	<link>https://gwolf.org/2026/06/systemd-for-linux-sysadmins.html</link>
     <content:encoded>&lt;blockquote&gt;
		 
		   This post is a review for &lt;a href=&quot;https://www.computingreviews.com/&quot;&gt;Computing
		   Reviews&lt;/a&gt;
		 
		     
		       
		         for &lt;em&gt;&lt;a href=&quot;https://link.springer.com/book/10.1007/979-8-8688-1328-3&quot;&gt;systemd for Linux SysAdmins&lt;/a&gt;&lt;/em&gt;
		       
		     
		     
		       , a book 
		       published in &lt;em&gt;&lt;a href=&quot;https://www.computingreviews.com/review/review_review.cfm?review_id=148120&quot;&gt;Apress&lt;/a&gt;&lt;/em&gt;
		     
		   &lt;/blockquote&gt;
		 
		 &lt;p&gt;systemd. Yes, in full lowercase. If there was ever a technology to cause
controversy in the Linux world, this is it. Since its inception in 2010,
systemd’s goals were set quite high: to replace the vital part in every
Linux system that takes care of the system boot process. It quickly reached
maturity, allowing it to be adopted as the main init system in most major
distributions just five years later. Despite describing events that
happened over a decade ago, systemd adoption still raises the temperature
in any Linux-related discussion.&lt;/p&gt;

&lt;p&gt;David Both’s comprehensive book tackles the what, why, and how issues
surrounding systemd. Carefully divided into 16 chapters, going from the
basics and some of the technical and political history behind the project
to the different subsystems and aspects covered by systemd, its almost 450
pages can scare people away. But the text is written in a very clear,
tutorial-like fashion, and while it can be read sequentially,
cover-to-cover, readers can also pick a single aspect and jump straight to
the relevant chapter.&lt;/p&gt;

&lt;p&gt;A frequent criticism of the systemd project is that it aims to basically
rewrite all of a Linux system, and just looking at this book’s index shows
there is some truth to it. The first chapter is an introduction to the
systemd project and a brief overview of its history (including the
controversies around it), and the following four chapters deal with
understanding and controlling the system boot process.&lt;/p&gt;

&lt;p&gt;That leaves ten chapters to cover different aspects or subprojects of
systemd, such as time and date issues (synchronization, time
specifications, and controlling repetitive tasks), understanding and
leveraging the system journal that strongly departs from the old syslog
system, network configuration and firewall management, system health and
performance debugging–all aspects that in the traditional Unix philosophy
were managed by independent programs. And I can identify several systemd
subprojects not covered by this book!&lt;/p&gt;

&lt;p&gt;We long-time Unix and Linux administrators took pride in how highly
performant and stable systems were supported by the simplicity of our
tools; systemd critics point out this massive project has absorbed dozens
of individual tools, yielding corporate control over vast swaths of vital
system tooling. Truth is, as a sysadmin myself, systemd is today one of my
greatest allies.&lt;/p&gt;

&lt;p&gt;I appreciate how the author evaluates every component independently,
including his personal evaluation of each–even acknowledging when he
prefers working with the traditional programs.&lt;/p&gt;

&lt;p&gt;If I had to note one criticism: given the many console captures, having a
maximum width below 70 characters means several lines are unnaturally cut
short (and continued with odd indentations). There is probably no “right”
way to solve this, but it does affect the reading experience.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-20T02:07:54+00:00</dc:date>
	<dc:creator>Gunnar Wolf</dc:creator>
</item> 
<item rdf:about="https://grep.be/blog//en/computer/Agentic_coding_and_Free_Software/">
	<title>Wouter Verhelst: Agentic coding and Free Software</title>
	<link>https://grep.be/blog//en/computer/Agentic_coding_and_Free_Software/</link>
     <content:encoded>&lt;p&gt;Through work, I have paid license to &lt;a href=&quot;https://windsurf.com&quot;&gt;windsurf&lt;/a&gt;
(recently renamed to &quot;devin&quot;), an application for LLM-based (aka,
&quot;Agentic&quot;) development.&lt;/p&gt;

&lt;p&gt;I hadn&#39;t been using it that much, but in an effort to more clearly
understand how this whole AI development thing works, I decided to give
it a closer look recently.&lt;/p&gt;

&lt;p&gt;My conclusions:&lt;/p&gt;

&lt;p&gt;In its current form, this whole LLM wave is problematic for multiple
reasons. But ignoring that, and looking at the &lt;em&gt;technology&lt;/em&gt; only, I can
say that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;it is a paradigm shift;&lt;/li&gt;
&lt;li&gt;it is, at the technological level, a positive evolution;&lt;/li&gt;
&lt;li&gt;and it is a threat to free software.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;problems&quot;&gt;Problems&lt;/h2&gt;

&lt;p&gt;Lest someone (incorrectly) assume that I am arguing in favour of the
current state of affairs with regards to LLMs, let me state this first.&lt;/p&gt;

&lt;p&gt;The way LLMs are built today is highly parasitic. Websites are
downloaded in whole, at unsustainable rates, regardless of the consent
of the people who made the original content. The result is predictable:
servers get overloaded, server administrators attempt to implement
various mitigations. Some of these mitigations work; some do, for a
while; some are entirely useless. In actual fact, the mitigations are an
arms race -- if too many people implement the same mitigation, then the
people who try to build yet another LLM so they can extract rent will
just try to work around the mitigation, eventually they will succeed,
and you&#39;ll just have to come up with another mitigation. It&#39;s a bit like
spam; you introduce regex-based spam filters, they introduce spelling
mistakes, you introduce bayesian filters, they add a large batch of
markov chain-generated semi-nonsense words made invisible by markup, you
add filters to block emails with such markup, they move the text into an
image. We have working mitigations today, but eventually we&#39;ll run out
of ideas.&lt;/p&gt;

&lt;p&gt;LLMs glob up everything they can while ignoring the license of the
source material. The people who push those LLMs claim that pushing the
source material through the machine learning algorithms makes the output
of the algorithm distinct enough from the source material that the
license no longer applies; I&#39;m not so sure that this is true. I guess
the &lt;a href=&quot;https://www.courtlistener.com/docket/68117049/the-new-york-times-company-v-microsoft-corporation/&quot;&gt;New York Times v OpenAI
lawsuit&lt;/a&gt;
will teach us &lt;em&gt;some&lt;/em&gt; of the answer to that question here, but even so
the ethical questions about &quot;is it OK to bring down another server just
so we can download the internet for another for-pay LLM&quot; are still
open. And regardless of what the law states, my opinion on &quot;you&#39;re using
my copyleft code to generate code under a different license&quot; is not
something you might like if you agree with the rent seekers&#39; opinion on
the subject.&lt;/p&gt;

&lt;p&gt;That all being said and true, the &lt;em&gt;technology&lt;/em&gt; works. You can have a
&quot;conversation&quot; with an LLM that resembles a human one. If you pass it
some data, you can use &lt;em&gt;plain english&lt;/em&gt; to ask it questions about that
data, which is a lot easier than to ask it about that in a formal way.
You can request it to generate some code, and it will generate something
that looks like what you need and that will be mostly correct for like
95% of the time.&lt;/p&gt;

&lt;p&gt;Now, yes, 95% of the time is not 100% of the time, and no, you can&#39;t ask
it to &quot;write me a piece of software that implements this 300-page
requirements document and get back to me when you&#39;re done&quot;, because it
will fail, and you won&#39;t know &lt;em&gt;where&lt;/em&gt; it has failed, and you&#39;ll take it
into production and expect everything to be fine because it won&#39;t and
this one minor logic bug will cause half your servers to spin and
consume credits with your infrastructure provider with nothing to show
for it.&lt;/p&gt;

&lt;p&gt;But that doesn&#39;t mean you can&#39;t use an LLM to build a large piece of
software. It just means you have to understand the LLMs limitations and
strenghts, and use them correctly.&lt;/p&gt;

&lt;p&gt;Here&#39;s what an LLM is good at:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Generating plausible text&lt;/li&gt;
&lt;li&gt;Interpreting text to figure out what a plausible meaning or summary of
that text is&lt;/li&gt;
&lt;li&gt;Giving vague indications as to what the probable context of a given
body of text is.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It turns out that that&#39;s enough to use the LLM to build a reliable piece
of software, provided you do it right.&lt;/p&gt;

&lt;h2 id=&quot;paradigmshift&quot;&gt;Paradigm shift&lt;/h2&gt;

&lt;p&gt;An LLM can generate text by the truckful. The generated text could be
code. Given a good enough LLM, the generated text might even run and do
something useful.&lt;/p&gt;

&lt;p&gt;You can try to blindly run the code, and if it doesn&#39;t run correctly,
you can paste the error message to the LLM, and it can tell you what
went wrong and how you could possibly fix it. This creates a feedback
loop: you ask it for an amount of code, you run the code, you receive an
error, you tell it that the code is problematic and give it the error
message, it makes changes to the code, now you have something that at
least no longer fails at startup.&lt;/p&gt;

&lt;p&gt;If you ask it to add tests to make sure that your code acts as per your
specification, now you get an error if and when the code &lt;em&gt;doesn&#39;t&lt;/em&gt; act
as per your specification. Or, well, at least not as per the part of the
specification that was correctly turned into a unit test by the LLM.&lt;/p&gt;

&lt;p&gt;LLMs have a context window, so if the error message is pasted in the
same conversation as where the code was generated, it is able to reuse
the earlier prompts to refine how it should interpret the error message
that you received.&lt;/p&gt;

&lt;p&gt;You can&#39;t really paste the source code of an entire application into the
prompt of your LLM, that would quickly overrun its context window. But
LLMs also allow you to provide some form of background information --
a document, say -- on which you ask it to reason. It will interpret that
document, but doing so uses less of the LLMs context window. So
providing the LLM with your application&#39;s source code as background
information can help it understand better how your code interacts. This
is especially helpful if you only provide the LLM the background
information relevant to the actual question.&lt;/p&gt;

&lt;p&gt;So now if you are able to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Create background context with your application&#39;s source code&lt;/li&gt;
&lt;li&gt;Have the LLM generate a first draft of your requested change, plus the
tests to make sure it works&lt;/li&gt;
&lt;li&gt;Compile (if applicable) the generated code (and tests) and run said
tests&lt;/li&gt;
&lt;li&gt;Return any error messages to the LLM with a request to correct the
error&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Then the combination of &quot;getting it 95% right off the bat&quot; and the above
feedback loop means you can generate syntactically correct code, that
probably does what you need, in minutes.&lt;/p&gt;

&lt;p&gt;I say &quot;probably&quot; for a reason. There are going to be cases where you
specify a request without a number of details (because they are
implied), and the LLM will get most of those details right but just not
implement the one bit because it&#39;s an automaton and it doesn&#39;t think. Or
you will ask it to make sure that two bits of the application &lt;em&gt;look&lt;/em&gt;
exactly the same, without specifying that they must &lt;em&gt;act&lt;/em&gt; the same, now
and in the future, and it will just generate the same block of code
twice and then in a future change it will change one but not the other.&lt;/p&gt;

&lt;p&gt;But if you &lt;em&gt;review&lt;/em&gt; the changes, and you have experience as a
programmer, you will be able to spot most cases where the LLM got it
wrong. And so it&#39;s possible, if not necessarily easy at first, to
use an LLM to generate mostly correct code.&lt;/p&gt;

&lt;p&gt;There are certain places where &quot;mostly correct&quot; code is not desireable.
But equally, there are also cases where, &quot;mostly correct&quot; is good
enough.&lt;/p&gt;

&lt;p&gt;After all, most of the software you run today -- the bits of it that
weren&#39;t, yet, generated by an LLM -- is only &quot;mostly correct&quot;, too,
because to err is human and we all make mistakes. If not, there wouldn&#39;t
be any CVEs and your software would never do anything wrong.&lt;/p&gt;

&lt;p&gt;Now, doing the feedback loop described above is certainly something you
could do manually. You could open an account on one of the LLM websites,
upload the source code of your application, ask it to generate some new
feature, download the newly generated feature, run it, and then
copy/paste any error messages back into the LLM.&lt;/p&gt;

&lt;p&gt;But that&#39;s a lot of manual work of the type that computers are pretty
good at. So that&#39;s what the &quot;windsurf&quot; tool helps you with: you run it
inside your IDE -- either a VSCode-based tool that you download from
their website which comes with their product preinstalled, or a separate
JetBrains plugin that you can install. You can then open your entire
relevant codebase in a workspace in your IDE. You then ask the LLM,
through the IDE, to generate a new feature in your codebase, and to also
generate the test while it&#39;s at it. It will use a mixture of LLM
interpretation and non-LLM functionality to scoop out the relevant bits
of your codebase to send to the LLM as background information, will send
it your prompt, will download the generated code and patch or create
files, will compile (if required) and run the newly generated code and
tests, and will refine the generated code if the tests produce any
errors. All mostly automatic; by default, running &lt;em&gt;anything&lt;/em&gt; requires
explicit confirmation. You can turn that off completely (probably not a
good idea), or you can give it a whitelist of things that you don&#39;t want
to confirm (perhaps OK), and the tool also passes standing instructions
to the LLM to never generate any command that deletes a file (which,
like with any LLM, can be overridden, but it requires you to be very
stubborn and to use more credits than you&#39;d probably like).&lt;/p&gt;

&lt;p&gt;All this put together means you can build something without writing any
piece of code, provided you do it right.&lt;/p&gt;

&lt;h2 id=&quot;atechnicallypositiveevolution&quot;&gt;A technically positive evolution&lt;/h2&gt;

&lt;p&gt;Don&#39;t go and say, &quot;here&#39;s a 300-page document, read it and write
whatever the document says&quot;. It will get it wrong, it will write a
massive test suite that it will only run at the end, it will choke
itself up trying to interpret the massive amount of failures it
encounters, it will fill up its context window and it will start to
forget some of the requirements. That won&#39;t work.&lt;/p&gt;

&lt;p&gt;But what you can do -- what I did, in fact -- is this.&lt;/p&gt;

&lt;p&gt;First, create an empty workspace. Don&#39;t put any code in it.&lt;/p&gt;

&lt;p&gt;Then, tell the LLM to generate a backend framework using technology X
and a frontend framework using technology Y that initially only says
&quot;hello, world&quot;. Also add tests to it, and run the tests.&lt;/p&gt;

&lt;p&gt;It will do that. You&#39;ll not get much, but it will work.&lt;/p&gt;

&lt;p&gt;Then, ask it to add some UI elements. A login page, perhaps. A
navigation bar. Small things. Most of it doesn&#39;t have to be functional
-- but tests must be there for the bits that are, and have it run the
tests and evaluate the results.&lt;/p&gt;

&lt;p&gt;Rinse, repeat, until you have a working application.&lt;/p&gt;

&lt;p&gt;Importantly, in between the steps, you should also run the application
yourself and see if the change was implemented correctly. Sometimes it
won&#39;t be. Sometimes there will be a subtle bug -- I at one point had a
the application hang after a few minutes. Sometimes you tell it that
there&#39;s a subtle bug, and it will discover it more quickly than you
could, and it will fix it, and in implementing the fix it will uncover
&lt;em&gt;another&lt;/em&gt; bug, and then you have to fix that one -- the fix it came up
with for the hang was to move something to an async process on the
server, which caused the application to start spinning while trying to
create hundreds of async jobs (this is when I realized that the hang was
a deadlock due to some part of the codebase doing something that
indirectly triggered itself). Sometimes it will try to fix the bug you
tell it about, and you&#39;ll see that it&#39;s going off on a tangent that has
nothing to do with what you&#39;re seeing. It&#39;s important to keep an eye on
what it&#39;s doing, so you can guide it back on track when that happens --
when I told it about the hang, it started investigating the part of the
code which sends out emails, thinking that it could hang while waiting
for &lt;code&gt;sendmail&lt;/code&gt; to finish, but the hang was happening when the
application was &lt;em&gt;idle&lt;/em&gt;, not when it was sending out emails, and only
when I told it about it happening when it was idle did it find the
deadlock.&lt;/p&gt;

&lt;p&gt;So it&#39;s not a fully automatic process, and it needs to be guided by
someone who knows what they&#39;re doing. But if that is the case, you can
come up with something that works. I spent evenings and breaks for about
a week, and I managed to create a working application which, had I
written it by hand, would have taken me a few months of full-time work
to come up with. And I now have a side project, fully complete and
working, that I had been thinking about doing for &lt;em&gt;more than a decade&lt;/em&gt;,
but never got around to &lt;em&gt;actually&lt;/em&gt; doing, because of all the work that
would be involved and I just didn&#39;t see myself having the time for.&lt;/p&gt;

&lt;p&gt;It&#39;s not perfect code. But it&#39;s mostly good enough, and it will perform
the job it needs to. And it looks far slicker than most of the side
projects I&#39;ve done in the past, because in the past I would prioritize
between implementing new features or making something look slick, and I
would decide that the new feature was more important because it&#39;s only
for me and there&#39;s only me and nobody cares if it looks good or not and
I don&#39;t have three weeks to come up with something that looks better.
But here, I found myself sometimes spending 10 minutes writing a prompt
with instructions on making things look better. Because what&#39;s 10
minutes when you just spent an hour writing down and refining
specifications for functionality and tests?&lt;/p&gt;

&lt;p&gt;There are a number of other things in which an LLM can help a
programmer.&lt;/p&gt;

&lt;p&gt;For instance.&lt;/p&gt;

&lt;p&gt;I received a bug report recently in &lt;a href=&quot;https://github.com/Fedict/eid-mw&quot;&gt;a project I&#39;m paid to
maintain&lt;/a&gt; that I couldn&#39;t make heads
or tails of. I opened the source code in my windsurf IDE, pasted the bug
report in the prompt, and then requested the tool to analyze the source
code and the associated logs and tell me how the described behavior
could be happening. It turned out that I had overlooked something, but
with the help of the tool, I found the bug in minutes.&lt;/p&gt;

&lt;p&gt;I was trying to understand a particular part of a &lt;a href=&quot;https://www.kernel.org&quot;&gt;large
codebase&lt;/a&gt; that I didn&#39;t really grasp very well.
I loaded the codebase in the tool, and asked it to explain to me how a
particular action is performed by the code. I requested specific
functions and line numbers. I now have a far better understanding of how
the code works, and will be able to write that patch that I&#39;ve been
wanting to write for years -- without using the LLM.&lt;/p&gt;

&lt;p&gt;I have been struggling for, literally, years with understanding why
&lt;a href=&quot;https://salsa.debian.org/debconf-video-team/SReview&quot;&gt;another tool that I
maintain&lt;/a&gt; was
misbehaving in a particular way but only in Firefox. I opened the
codebase in Firefox, explained the buggy behavior in plain English, and
asked it to explain how this could be happening. It picked up some
obscure corner case behavior of ffmpeg and mp4 containers that I was not
aware of and that perfectly explained why things were misbehaving in the
way that they were.&lt;/p&gt;

&lt;p&gt;At the same time, there are limitations. Giving an LLM a codebase that
was originally generated by an LLM (either the same one or another one)
seems to work well. Giving it a codebase that was written by a human and
expecting it to correctly update it seems to be more error-prone. I did
one or two of those as a trial, and it is more problematic than
anything.&lt;/p&gt;

&lt;p&gt;An LLM is also not intelligent, notwithstanding the popular term of
&quot;Artificial Intelligence&quot;. On multiple occasions, I&#39;ve asked it to write
a test case for some code that was not set up to do so; and rather than
suggesting a refactor is required, it would instead &lt;em&gt;copy&lt;/em&gt; the code that
needed to be tested and then test the copy, rather than the original.
The tool has made multiple similar errors. I have sometimes people
describe agentic coding as &quot;similar to interacting with junior
programmers&quot;, but that is not the case. A junior programmer will either
fill in the gaps in your specifications, or ask for clarification when
something seems off. The LLM will not do that; it will do what you ask,
exactly that and nothing more. If you missed a corner case in your
specification, then all bets are off.&lt;/p&gt;

&lt;p&gt;I remember learning about programming language generations in college.
A first-generation language is &quot;machine code&quot;, a second-generation
language is &quot;assembler&quot;, a third-generation language is any high-level
language such as C, Perl, or Pascal. I&#39;ve forgotten what set a
3rd-generation language apart from a 4th-generation language. But I
remember the definition they gave me for a 5th-generation language: &quot;you
tell the computer what to do, and it will do it&quot;. At the time, I thought
it was ridiculous. Nobody could ever write something like that.&lt;/p&gt;

&lt;p&gt;But it&#39;s here.&lt;/p&gt;

&lt;p&gt;And it&#39;s a threat to free software.&lt;/p&gt;

&lt;h2 id=&quot;athreattofreesoftware&quot;&gt;A threat to free software?&lt;/h2&gt;

&lt;p&gt;Yes.&lt;/p&gt;

&lt;p&gt;There is the obvious part where most of the well-known LLMs are non-free
software. I mean, &lt;a href=&quot;https://www.geeksforgeeks.org/artificial-intelligence/top-10-open-source-llm-models/&quot;&gt;there
are&lt;/a&gt;
some &quot;open source&quot; LLM models. The windsurf tool that I used doesn&#39;t allow
you to use them (directly), but they&#39;re there. There are also &lt;a href=&quot;https://opencode.ai/&quot;&gt;open
source applications&lt;/a&gt; that implement what the
windsurf editor does. So it&#39;s definitely possible to work like this
without resorting to non-free software and non-free services, even
though the non-free LLMs might be a bit ahead of the curve of the free
ones. But that&#39;s not what I mean.&lt;/p&gt;

&lt;p&gt;And there is also the obvious thing which I mentioned earlier in this
post, which is that the people who try to build LLMs are doing it in
unethical, disgusting ways, causing downtimes and disregarding licenses
for whatever they can get their grubby hands on. Ideally we wouldn&#39;t be
in that situation, and ideally this wouldn&#39;t be a problem, but we are
where we are.&lt;/p&gt;

&lt;p&gt;And there&#39;s the obvious thing where the OSI sold itself out and declared
that a machine learning program can be open source even when the very
things it was built from -- the training data -- is not available.
That&#39;s a major issue that the free software community needs to fight
against, but there&#39;s not really anything that that is a threat to free
software. You just build your own, free software, LLM, and you&#39;re done.&lt;/p&gt;

&lt;p&gt;The actual threat is in funding and developer support.&lt;/p&gt;

&lt;p&gt;Most large businesses do not care about free-as-in-freedom software.
They like the free-as-in-beer part, and they appreciate that the
free-as-in-freedom bits can make the software more customizable. They
are (mostly) happy to do sponsorships of the free-as-in-freedom projects
that they use if that means their free-as-in-beer usage of the software
gets improved.&lt;/p&gt;

&lt;p&gt;But why would you care about all that when you can just &lt;em&gt;generate&lt;/em&gt; the
code you need, rather than interacting with an open source community
that may or may not care about your business&#39;s interests?&lt;/p&gt;

&lt;h2 id=&quot;wheretogofromhere&quot;&gt;Where to go from here&lt;/h2&gt;

&lt;p&gt;Although I think the moral and environmental issues with LLMs are real
and problematic, given the experiments I did I am not convinced that the
&lt;em&gt;concept&lt;/em&gt;  of interacting with a computer system in natural language and
to use it to generate code is necessarily deficient. There are pitfalls,
but they can be managed. It is possible to use such a system to create
throwaway, proof-of-concept type &quot;good enough&quot; code bases. It can be
used to interpret code bases and to understand bug reports.&lt;/p&gt;

&lt;p&gt;I believe that the major issue with LLMs has to do with that saying
about hammers and nails:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;If all you have is a hammer, then everything looks like a nail.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;LLMs are an outgrowth of machine learning, pushed by large corporations.
These large corporations have a lot of money. If all you have is money,
then every problem can be fixed by throwing more money at it. The
initial language models were promising but not (yet) good enough, and it
seemed that one way in which they could be improved was to increase the
scale of the statistics: throw more hardware (and thus money) at it, and
rather than improving the efficiency of the models, just scale up.&lt;/p&gt;

&lt;p&gt;Scaling up is something that megacorporations are very good at. It&#39;s
only a money problem, after all. Does that mean that &quot;scaling up&quot;
is the only way to improve the models, though? I&#39;m not convinced.&lt;/p&gt;

&lt;p&gt;Some hardware, such as most modern Apple and Samsung devices, ship with
accelerator hardware for machine learning algorithms. There are some
models that are small enough to be able to run on these devices. I don&#39;t
see why it should not be possible to create a small(er) language model
that can do some useful part of the above-described use cases; if not
locally, then at least on a server that one can run on-prem rather than
requiring that you pay rent to one of the LLM companies.&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://sfconservancy.org&quot;&gt;Software Freedom Conservancy&lt;/a&gt; has
published an &lt;a href=&quot;https://sfconservancy.org/news/2024/oct/25/aspirational-on-llm-generative-ai-programming/&quot;&gt;aspirational statement on machine learning-assisted
programming&lt;/a&gt;
that, I think, gets a lot right. It&#39;s not quite a definition, but it&#39;s
something to keep in mind.&lt;/p&gt;

&lt;p&gt;Perhaps that&#39;s the way forward?&lt;/p&gt;

&lt;p&gt;More questions than answers at this point, anyway.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-19T12:09:21+00:00</dc:date>
	<dc:creator>Wouter Verhelst</dc:creator>
</item> 
<item rdf:about="159 at https://sunweavers.net/blog">
	<title>Mike Gabriel: Commenting on the recent Ubuntu Touch review done by @SwitchandClickOfficial on Youtube</title>
	<link>https://sunweavers.net/blog/node/159</link>
     <content:encoded>&lt;p&gt;There has been a video blog post recently published with a review of Ubuntu Touch as an option to opt out of the Android world: &lt;a href=&quot;https://www.youtube.com/watch?v=wTK6TS3pXgc&quot; title=&quot;https://www.youtube.com/watch?v=wTK6TS3pXgc&quot;&gt;https://www.youtube.com/watch?v=wTK6TS3pXgc&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Thanks to @SwitchandClick for spending time on this and publishing that video. Much appreciated.&lt;/p&gt;

&lt;h3&gt;Many Issues amended in upcoming 24.04-2.0 Release&lt;/h3&gt;

&lt;p&gt;When I watched that video referenced above, I continuously thought: ah... this is fixed in the next major release of Ubuntu Touch, or: ah... this is a known issue that we have on the roadmap..., or: ah... this is done in this ways by design (so it&#39;s a feature or basic functionality)...&lt;/p&gt;

&lt;p&gt;Let me just state, that most of the criticized aspects will be resolved in upcoming Ubuntu Touch release 24.04-2.0 (the tests in that video blog post have been run on Ubuntu Touch 24.04-1.x):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Camera notch and rounding corners get honoured now by the UI&lt;/li&gt;
&lt;li&gt;Ubuntu Touch&#39;s default webbrowser (Morph Browser) has been bumped from Chromium engine v87 (Qt5 based) to v134 (Qt6 based), installing another browser should not be necessary anymore (note that the privacy level in Morph Browser is pretty high, so using other browsers could mean a loss of privacy).&lt;/li&gt;
&lt;li&gt;Bluetooth pairing agent got added to the bluetooth indicator&lt;/li&gt;
&lt;li&gt;Ubuntu Touch now supports Snaps on CLI level and in the OpenStore app&lt;/li&gt;
&lt;li&gt;Libertine has received fixes, but no substantial improvements. It mainly targets users who want to use their Ubuntu Touch device as desktop daily driver. Libertine-provided desktop apps UI-wise are often not usable on a phone-like device.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The full feature preview of the 24.04-2.0 release can be found here: &lt;a href=&quot;https://ubports.com/blog/ubports-news-1/ubuntu-touch-24-04-2-0-beta-is-now-ready-for-testing-4000&quot; title=&quot;https://ubports.com/blog/ubports-news-1/ubuntu-touch-24-04-2-0-beta-is-now-ready-for-testing-4000&quot;&gt;https://ubports.com/blog/ubports-news-1/ubuntu-touch-24-04-2-0-beta-is-n...&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;Ubuntu Touch App Ecosystem&lt;/h3&gt;

&lt;p&gt;The app ecosystem of Ubuntu Touch is quite specific, because many apps in Ubuntu Touch have been explicitly developed for Ubuntu Touch using a widget toolkit called Lomiri.Components. However, in Ubuntu Touch we also encourage developers to provide apps written with other convergent-capable toolkits, such as QQC2-based apps or Kirigami-based apps.&lt;/p&gt;

&lt;p&gt;One reason for the very different app ecosystem in Ubuntu Touch is that many service providers don&#39;t have Ubuntu Touch on their radar when investing in app development for their services. Some Ubuntu Touch App Developers work around this by either implementing unofficial client apps for web services (e.g. the Flow app for Deezer by Sander Klootwijk), others provide the web service via implementing a web app (will not work when offline, but at least will show up as an app in the launcher).&lt;/p&gt;

&lt;p&gt;The overall solution for making Open-Store.io more familiar to users who migrate from Android is that commercial service providers start honouring digital sovereignty and start providing apps for Linux. Not just for the Linux desktop, but also for mobile Linux platforms. This dual use case can easily achieved with an app development that bears convergence in mind.&lt;/p&gt;

&lt;h3&gt;App Ecosystems are also a Matter of Perspective&lt;/h3&gt;

&lt;p&gt;And one more minor note: whenever I open an Android appstore or can peak over someone&#39;s shoulder using an iOS device: I always wonder: what are all these apps about??? Never heard about them.&lt;/p&gt;

&lt;p&gt;So, familiarity really depends on perspective. And perspective depends on what you are used to. Change what you do and your perspective will follow.&lt;/p&gt;

&lt;h3&gt;Ubuntu Touch&#39;s root filesystem (rootfs) is Immutable&lt;/h3&gt;

&lt;p&gt;Only thing from that video blog post that we haven&#39;t fixed and won&#39;t do so in the midterm future is apt-get not working on the command line.&lt;/p&gt;

&lt;p&gt;The reason for this is: the Ubuntu Touch root file system is an immutable file system and thus shall not be changed via apt-get &amp;amp; friends by ordinary users.&lt;/p&gt;

&lt;p&gt;There are various discussions ongoing such as dpkg-divert&#39;ing apt-get to a wrapper shell script that spits out an error message if rootfs is mounted read-only and someone tries to install packages the Debian/Ubuntu way. Other approaches are to mount some RAM disk over the rootfs, so apt-get can be used at runtime but changes to the system get reset at reboot.&lt;/p&gt;

&lt;p&gt;However, it is possible to mount the root filesystem read-write and test newer package versions (as UT core developers do regularly, in fact). If you tinker with this, it is recommended to reflash your device (don&#39;t wipe user data, when you reflash!) from time to time, because adding packages or package upgrades to your rootfs may over time corrupt the integrity of the rootfs.&lt;/p&gt;

&lt;p&gt;One reason for apt-get breaking the rootfs and thus your Ubuntu Touch development device is that the upgrade process of the rootfs image is incremental, so update tarballs sometimes contain only those parts that got changed between this and your previous upgrade (sometimes, upgrades contain a complete rootf image, depending on the interval between upgrades). If files from an incremental update tarball mix into a rootfs that got tinkered with via apt-get, you really end up on your own. Re-flashing will grab the complete rootfs tarball and wipe the whole rootfs and reinstall a fresh version of the newest rootfs image. Developers also do this in regular intervals to ensure their test device is clean again before running more/other tests.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-18T07:49:10+00:00</dc:date>
	<dc:creator>sunweaver</dc:creator>
</item> 
<item rdf:about="http://joeyh.name/blog/entry/offgrid_electric_car/">
	<title>Joey Hess: offgrid electric car</title>
	<link>http://joeyh.name/blog/entry/offgrid_electric_car/</link>
     <content:encoded>&lt;p&gt;Eight months ago I came up my rocky driveway in an electric car, with the
back full of solar panel mounting rails. I didn&#39;t know how I&#39;d manage to
keep it charged. I got the car earlier than planned, with my
&lt;a href=&quot;http://joeyh.name/blog/entry/aiming_at_December/&quot;&gt;offgrid solar upgrade&lt;/a&gt; only beginning. There&#39;s no
nearby EV charger, and winter was coming, less solar power every day.
Still, it was the right time to take a leap to offgid EV life.&lt;/p&gt;

&lt;p&gt;My existing 1 kilowatt solar array could charge the car only 5 miles on a
good day. Here&#39;s my first try at charging the car offgrid:&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;first feeble charging offgrid&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/offgrid_ev_charging/proof_of_concept_charging_from_1_kw_solar_at_6_amps.png&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;215&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/800x-proof_of_concept_charging_from_1_kw_solar_at_6_amps.png&quot; width=&quot;799&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;It was not worth charging the car that way, the house battery tended to get
drained while doing that, and adding cycles to that battery is not
desirable. So that was only a proof of concept, I knew I&#39;d need to upgrade.&lt;/p&gt;

&lt;p&gt;My goal with the upgrade was to charge the car directly from the
sun, even when it was cloudy, using the house battery only to skate over
brief darker periods (like a thunderstorm). By mid October, I had enough
solar installed to do that (5 kilowatts).&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;me standing in front of solar fence&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/solar_fence.jpg&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;384&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/512x-solar_fence.jpg&quot; width=&quot;512&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;first charging from solar fence&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/offgrid_ev_charging/start_charging_from_electric_fence.png&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;215&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/800x-start_charging_from_electric_fence.png&quot; width=&quot;799&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;Using this, in 2 days I charged the car up from 57% to 82%, and took off on a
celebratory road trip to Niagra Falls, where I charged the car from hydro
power from a dam my grandfather had engineered.&lt;/p&gt;

&lt;p&gt;When I got home, it was November. Days were getting ever shorter. My solar
upgrade was only 1/3rd complete and could charge the car 30-some miles per
day, but only on a good day, and weather was getting worse. I came back
with a low state of charge (both car and me), and needed to get back to
full in time for my Thanksgiving trip at the end of the month. I decided to
limit my trips to town.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;charging up gradually through the month of November&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/offgrid_ev_charging/november_charging.png&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;215&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/800x-november_charging.png&quot; width=&quot;799&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;This kind of medium term planning about car travel was new to me. But not
too unusual for offgrid living. You look at the weather forecast and make
some rough plans, and get to feel connected to the natural world a bit more.&lt;/p&gt;

&lt;p&gt;December is the real test for offgrid solar, and honestly this was a bit
rough, with a road trip planned for the end of the month. I did the usual
holiday stuff but otherwise holed up at home a bit more than I usually
would. Charging was limited and the cold made it charge less efficiently.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;bleak December charging&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/offgrid_ev_charging/december_charging.png&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;187&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/800x-december_charging.png&quot; width=&quot;800&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;Still, I was busy installing more solar panels, and by winter solstice, was
back to charging 30 miles on a good day.&lt;/p&gt;

&lt;p&gt;Of course, from there out things improved. In January and February I was
able to charge up easily enough for my usual trips despite the
cold. By March the car was often getting full before I needed to go
anywhere, and I was doing long round trips without bothering to fast
charge along the way, coming home low, knowing even cloudy days would let
it charge up enough.&lt;/p&gt;

&lt;p&gt;That brings me up to today. The car is 80% full and heading up toward 100%
for a long trip on Friday. Despite the sky being milky white today with no
visible sun, there&#39;s plenty of power to absorb, and the car charger turned
on at 11 am with the house battery already full.&lt;/p&gt;

&lt;p&gt;My solar upgrade is only 2/3rds complete, and also I have not yet
installed my inverter upgrade, so the car can only currenly charge at 9
amps despite much more solar power often being available. So I&#39;m looking
forward to how next December goes with my full planned solar array and
faster charging.&lt;/p&gt;

&lt;p&gt;But first, a summer where I expect the car will mostly be charged up and
ready to go at all times, and the only car expense will be fast charging
on road trips!&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;By the way, the code I&#39;ve written to automate offgrid charging that runs
only when there&#39;s enough solar power is
&lt;a href=&quot;https://git.joeyh.name/index.cgi/joey/house.git/tree/src/Automation/Car.hs#n21&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;And here are the charging graphs for the other months.
All told, it&#39;s charged 475 kwh offgrid, enough to drive
more than 1500 miles.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;January&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/offgrid_ev_charging/january_charging.png&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;206&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/800x-january_charging.png&quot; width=&quot;800&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;February&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/offgrid_ev_charging/february_charging.png&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;187&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/800x-february_charging.png&quot; width=&quot;799&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;March&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/offgrid_ev_charging/march_charging.png&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;187&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/800x-march_charging.png&quot; width=&quot;799&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;April&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/offgrid_ev_charging/april_charging.png&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;187&quot; src=&quot;http://joeyh.name/blog/entry/offgrid_electric_car/800x-april_charging.png&quot; width=&quot;799&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;hr /&gt;

&lt;p&gt;2026 update: After upgrading my inverter and running conduit, the car is
finally charging at a faster rate of 16 amps, and the car typically
charges 25% per day. That seems to be plenty for my needs.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-17T15:24:14+00:00</dc:date>
	<dc:creator>Joey Hess</dc:creator>
</item> 
<item rdf:about="http://joeyh.name/blog/entry/aiming_at_December/">
	<title>Joey Hess: aiming at December</title>
	<link>http://joeyh.name/blog/entry/aiming_at_December/</link>
     <content:encoded>&lt;p&gt;I have been working all year on a solar upgrade aimed at December. Now here
it is, midwinter, and my electric car is charging on a cloudy day from my
offgrid solar fence.&lt;/p&gt;

&lt;p&gt;I lived happily enough with 1 kilowatt of solar that I
&lt;a href=&quot;http://joeyh.name/blog/entry/DIY_professional_grade_solar_panel_installation/&quot;&gt;installed in 2017&lt;/a&gt;.
Meanwhile, solar panel prices came down massively, incentives increased
and everything came together: This was the year.&lt;/p&gt;

&lt;p&gt;In the spring I started clearing forest trees that were leaning over the house,
making both a firebreak and a solar field.&lt;/p&gt;

&lt;p&gt;In June I picked up a pallet of panels in a box truck.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;a porch with a a bunch of solar panels, stacked on edge leaning up against the wall. A black and white cat is sprawled in front of them.&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/solar_panels_on_porch_atari.jpg&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;288&quot; src=&quot;http://joeyh.name/blog/entry/aiming_at_December/512x-solar_panels_on_porch_atari.jpg&quot; width=&quot;512&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;In August I bought the EV and was able to charge it offgrid from my old
solar system... a few miles per day on the most sunny days.&lt;/p&gt;

&lt;p&gt;In September and October I built
&lt;a href=&quot;https://hachyderm.io/@joeyh/113177118703625033&quot;&gt;a solar fence, of my own design&lt;/a&gt;.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;Me standing in front of the solar fence, which is 10 panels long&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/solar_fence.jpg&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;384&quot; src=&quot;http://joeyh.name/blog/entry/aiming_at_December/512x-solar_fence.jpg&quot; width=&quot;512&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;For the past several weeks I have been installing additional solar panels
on ballasted ground mounts full of gravel. At this point I&#39;m half way
through installing my 30 panel upgrade.&lt;/p&gt;

&lt;p&gt;The design goal of my 12 kilowatt system is to produce 1 kilowatt of power all
day on a cloudy day in midwinter, which allows swapping between major loads (EV
charger, hot water heater, etc) on a cloudy day and running everything on a
sunny day. So the size of the battery bank doesn&#39;t matter much. Batteries are
getting cheaper fast too, but they are a wear item, so it&#39;s better to oversize
the solar system and minimize the battery.&lt;/p&gt;

&lt;p&gt;A lot of this is nonstandard and experimental. And that makes sense with the
price of solar panels. It costs more to mount solar panels now than the panels
are worth. And non-ideal panel orientation isn&#39;t a problem when the system is
massively overpaneled.&lt;/p&gt;

&lt;p&gt;I&#39;m hoping to finish up the install before the end of winter. I have more trees
to clear, more ballasted ground mounts to install, and need to come up with
something even more experimental for a half dozen or so panels. Using solar
panels as mounts for solar panels? Hanging them from trees?&lt;/p&gt;

&lt;p&gt;Soon the wan light will fade, time to head off to the solstice party to enjoy
the long night, and a bonfire.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;Solar fence with some ballasted ground mounts in front of it, late evening light. Old pole mounted solar panels in the foreground are from the 90&#39;s.&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/solar_fence_with_powerracks.jpg&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;384&quot; src=&quot;http://joeyh.name/blog/entry/aiming_at_December/512x-solar_fence_with_powerracks.jpg&quot; width=&quot;512&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</content:encoded> 
	<dc:date>2026-06-17T15:17:46+00:00</dc:date>
	<dc:creator>Joey Hess</dc:creator>
</item> 
<item rdf:about="http://joeyh.name/blog/entry/cheap_DIY_solar_fence_design/">
	<title>Joey Hess: cheap DIY solar fence design</title>
	<link>http://joeyh.name/blog/entry/cheap_DIY_solar_fence_design/</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;http://joeyh.name/blog/entry/aiming_at_December/&quot;&gt;A year ago I installed a 4 kilowatt solar fence&lt;/a&gt;.
I&#39;m revisiting it this &lt;a href=&quot;https://sunday.earth/&quot;&gt;Sun Day&lt;/a&gt;, to share the design,
now that I have prooved it out.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;The solar fence and some other ground and pole mount solar panels, seen through leaves.&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/solar_fence_through_leaves.jpg&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;384&quot; src=&quot;http://joeyh.name/blog/entry/cheap_DIY_solar_fence_design/512x-solar_fence_through_leaves.jpg&quot; width=&quot;512&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;Solar fencing manufacturers have some good simple designs, but it&#39;s hard
to buy for a small installation. They are selling to utility scale solar
mostly. And those are installed by driving metal beams into the ground,
which requires heavy machinery.&lt;/p&gt;

&lt;p&gt;Since I have experience with Ironridge rails for roof mount solar, I
decided to adapt that system for a vertical mount. Which is something it
was not designed for. I combined the Ironridge hardware with regular parts
from the hardware store.&lt;/p&gt;

&lt;p&gt;The cost of mounting solar panels nowadays is often higher than the cost of
the panels. I hoped to match the cost, and I nearly did. The solar panels cost
$100 each, and the fence cost $110 per solar panel. This fence was
significantly cheaper than conventional ground mount arrays that I
considered as alternatives, and made a better use of a difficult hillside
location.&lt;/p&gt;

&lt;p&gt;I used 7 foot long Ironridge XR-10 rails, which fit 2 solar panels per rail.
(Longer rails would need a center post anyway, and the 7 foot long rails
have cheaper shipping, since they do not need to be shipped freight.)&lt;/p&gt;

&lt;p&gt;For the fence posts, I used regular 4x4&quot; treated posts. 12 foot long, set
in 3 foot deep post holes, with 3x 50 lb bags of concrete per hole and 6
inches of gravel on the bottom.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;detail of how the rails are mounted to the posts, and the panels to the rails&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/solar_fence_mounting_detail.jpg&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;512&quot; src=&quot;http://joeyh.name/blog/entry/cheap_DIY_solar_fence_design/x512-solar_fence_mounting_detail.jpg&quot; width=&quot;384&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;To connect the Ironridge rails to the fence posts, I used the Ironridge
LFT-03-M1 slotted L-foot bracket. Screwed into the post with a 5/8” x 3
inch hot-dipped galvanized lag screw. Since a treated post can react badly
with an aluminum bracket, there needs to be some flashing between the post
and bracket. I used Shurtape PW-100 tape for that. I see no sign of
corrosion after 1 year.&lt;/p&gt;

&lt;p&gt;The rest of the Ironridge system is a T-bolt that connects the rail to the
L-foot (part BHW-SQ-02-A1), and Ironridge solar panel fasteners
(UFO-CL-01-A1 and UFO-STP-40MM-M1). Also XR-10 end caps and wire clips.&lt;/p&gt;

&lt;p&gt;Since the Ironridge hardware is not designed to hold a solar panel at a 90
degree angle, I was concerned that the panels might slide downward over
time. To help prevent that, I added some additional support brackets under
the bottom of the panels. So far, that does not seem to have been a problem
though.&lt;/p&gt;

&lt;p&gt;I installed Aptos 370 watt solar panels on the fence. They are bifacial,
and while the posts block the back partially, there is still bifacial
gain on cloudy days. I left enough space under the solar panels to be able
to run a push mower under them.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;Me standing in front of the solar fence at end of construction&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/solar_fence.jpg&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;384&quot; src=&quot;http://joeyh.name/blog/entry/cheap_DIY_solar_fence_design/512x-solar_fence.jpg&quot; width=&quot;512&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;I put pairs of posts next to one-another, so each 7 foot segment of fence
had its own 2 posts. This is the least elegant part of this design, but
fitting 2 brackets next to one-another on a single post isn&#39;t feasible.
I bolted the pairs of posts together with some spacers. A side benefit of
doing it this way is that treated lumber can warp as it dries, and this
prevented much twisting of the posts.&lt;/p&gt;

&lt;p&gt;Using separate posts for each segment also means that the fence can
traverse a hill easily. And it does not need to be perfectly straight. In
fact, my fence has a 30 degree bend in the middle. This means it has both
south facing and south-west facing panels, so can catch the light for
longer during the day.&lt;/p&gt;

&lt;p&gt;After building the fence, I noticed there was a slight bit of sway at the
top, since 9 feet of wooden post is not entirely rigid. My worry was that a
gusty wind could rattle the solar panels. While I did not actually observe
that happening, I added some diagonal back bracing for peace of mind.&lt;/p&gt;

&lt;table class=&quot;img&quot;&gt;&lt;caption&gt;view of rear upper corner of solar fence, showing back bracing connection&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;http://joeyh.name/blog/pics/solar_fence_rear_detail.jpg&quot;&gt;&lt;img class=&quot;img&quot; height=&quot;512&quot; src=&quot;http://joeyh.name/blog/entry/cheap_DIY_solar_fence_design/x512-solar_fence_rear_detail.jpg&quot; width=&quot;384&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;p&gt;Inspecting the fence today, I find no problems after the first year. I hope
it will last 30 years, with the lifespan of the treated lumber
being the likely determining factor.&lt;/p&gt;

&lt;p&gt;As part of my larger (and still ongoing) ground mount solar install, the
solar fence has consistently provided great power. The vertical orientation
works well at latitude 36. It also turned out that the back of the fence was
useful to hang conduit and wiring and solar equipment, and so it turned into
the electrical backbone of my whole solar field. But that&#39;s another story..&lt;/p&gt;

&lt;h2&gt;solar fence parts list&lt;/h2&gt;

&lt;table&gt;
    &lt;thead&gt;
        &lt;tr&gt;
            &lt;th&gt;quantity&lt;/th&gt;
            &lt;th&gt;cost per unit&lt;/th&gt;
            &lt;th&gt;description&lt;/th&gt;
        &lt;/tr&gt;
    &lt;/thead&gt;
    &lt;tbody&gt;
        &lt;tr&gt;
            &lt;td&gt;10&lt;/td&gt;
            &lt;td&gt;$27.89&lt;/td&gt;
            &lt;td&gt;7 foot Ironridge XR-10 rail&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;12&lt;/td&gt;
            &lt;td&gt;$20.18&lt;/td&gt;
            &lt;td&gt;12 foot treated 4x4&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;30&lt;/td&gt;
            &lt;td&gt;$4.86&lt;/td&gt;
            &lt;td&gt;Ironridge UFO-CL-01-A1&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;20&lt;/td&gt;
            &lt;td&gt;$0.87&lt;/td&gt;
            &lt;td&gt;Ironridge UFO-STP-40MM-M1&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;1&lt;/td&gt;
            &lt;td&gt;$12.62&lt;/td&gt;
            &lt;td&gt;Ironridge XR-10 end caps (20 pack)&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;20&lt;/td&gt;
            &lt;td&gt;$2.63&lt;/td&gt;
            &lt;td&gt;Ironridge LFT-03-M1&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;20&lt;/td&gt;
            &lt;td&gt;$1.69&lt;/td&gt;
            &lt;td&gt;Ironridge BHW-SQ-02-A1&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;22&lt;/td&gt;
            &lt;td&gt;$2.65&lt;/td&gt;
            &lt;td&gt;5/8” x 3 inch hot-dipped galvanized lag screw&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;10&lt;/td&gt;
            &lt;td&gt;$0.50&lt;/td&gt;
            &lt;td&gt;6” gravel per post&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;30&lt;/td&gt;
            &lt;td&gt;$6.91&lt;/td&gt;
            &lt;td&gt;50 lb bags of quickcrete&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;1&lt;/td&gt;
            &lt;td&gt;$15.00&lt;/td&gt;
            &lt;td&gt;Shurtape PW-100 Corrosion Protection Pipe Wrap Tape&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;N/A&lt;/td&gt;
            &lt;td&gt;$30&lt;/td&gt;
            &lt;td&gt;other bolts and hardware (approximate)&lt;/td&gt;
        &lt;/tr&gt;
    &lt;/tbody&gt;
&lt;/table&gt;


&lt;p&gt;$1100 total&lt;/p&gt;

&lt;p&gt;(Does not include cost of panels, wiring, or electrical hardware.)&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-17T15:16:06+00:00</dc:date>
	<dc:creator>Joey Hess</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/06/16#rspdlite_0.1.0-1">
	<title>Dirk Eddelbuettel: rspdlite 0.1.0-1 on CRAN: New Package!</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/06/16#rspdlite_0.1.0-1</link>
     <content:encoded>&lt;p&gt;Very happy to share that a new package &lt;a href=&quot;https://github.com/eddelbuettel/rspdlite&quot;&gt;rspdlite&lt;/a&gt; arrived on
&lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; today in its inaugural
version 0.1.0-1. It wraps and provides the (header-only) C++20 library
&lt;a href=&quot;https://github.com/gabime/spdlite&quot;&gt;spdlite&lt;/a&gt; which its author
describes (aptly) as &lt;em&gt;tiny, fast, capable&lt;/em&gt;. Just like its bigger
sibbling &lt;a href=&quot;https://github.com/gabime/spdlog&quot;&gt;spdlog&lt;/a&gt; (which we
wrapped as &lt;a href=&quot;https://github.com/eddelbuettel/rcppspdlog&quot;&gt;rcppspdlog&lt;/a&gt;), it is
written by &lt;a href=&quot;https://github.com/gabime&quot;&gt;Gabi Melman&lt;/a&gt;. However,
with a focus on C++20 and compile-time configuration, it is lighter,
nimbler and faster. It is also still a fairly young project so changes
may occur.&lt;/p&gt;
&lt;p&gt;I have been working on this for about a month, and it is ready for
use by R and C++. It contains the initial upstream release 0.1.0, and I
plan to follow the upstream versioning making this first release as
0.1.0-1.&lt;/p&gt;
&lt;p&gt;The package itself provides the headers for use from other C++
projects (i.e. mostly other packages), as well as a simple R wrapper so
that logging can occur from either C++ or R. It will generally access
the single logger instance in a compilation unit. So for a package built
against these header it would be shared library of that package. At
present we provide the basic logging level setters and getters,
formatting accessors, and two (compile-time) options of a ‘null logger’
and a file-based logger. More options are availble from the C++ level,
multiple logging sinks are but one example. Some examples are provided
in the package as an &lt;a href=&quot;https://github.com/eddelbuettel/rspdlite/blob/master/inst/examples/example.R&quot;&gt;R
example&lt;/a&gt; and a &lt;a href=&quot;https://github.com/eddelbuettel/rspdlite/blob/master/inst/examples/example.cpp&quot;&gt;C++
example&lt;/a&gt;; these are probably best examined from the sources.&lt;/p&gt;
&lt;p&gt;The NEWS entry for this release is simply and just announces that we
have a release. More details are in the &lt;a href=&quot;https://github.com/eddelbuettel/rspdlite/blob/master/ChangeLog&quot;&gt;ChangeLog&lt;/a&gt;
and the &lt;a href=&quot;https://github.com/eddelbuettel/rspdlite&quot;&gt;GitHub
repo&lt;/a&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-version-0.1.0-1-2025-06-08&quot;&gt;Changes in version
0.1.0-1 (2025-06-08)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Initial complete version and CRAN upload&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;. You can also sponsor my &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/2026/04/03#sponsor_tour_de_shore_202&quot;&gt;Tour
de Shore 2026 ride in support of the Maywood Fine Arts Center&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-17T00:16:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="158 at https://sunweavers.net/blog">
	<title>Mike Gabriel: Ubuntu Touch development - 24.04-2.0 Beta and Meaning of Branching-Off</title>
	<link>https://sunweavers.net/blog/node/158</link>
     <content:encoded>&lt;p&gt;The next Ubuntu Touch major release is approaching rapidly, yesterday we reached a major step in the preparation of the upcoming Ubuntu Touch 24.04-2.0 release: The branching-off (see below on what that is).&lt;/p&gt;

&lt;h3&gt;Ubuntu Touch 24.04-2.0 Beta is Now Available&lt;/h3&gt;

&lt;p&gt;Part of this development release step is the publication of the 24.04-2.0 Beta release images, for more details and information see:&lt;br /&gt;
&lt;a href=&quot;https://ubports.com/blog/ubports-news-1/ubuntu-touch-24-04-2-0-beta-is-now-ready-for-testing-4000&quot; title=&quot;https://ubports.com/blog/ubports-news-1/ubuntu-touch-24-04-2-0-beta-is-now-ready-for-testing-4000&quot;&gt;https://ubports.com/blog/ubports-news-1/ubuntu-touch-24-04-2-0-beta-is-n...&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And additionally, find below some background information on how we maintain various Ubuntu Touch releases in parallel via Git(Lab). In fact, the release model of Ubuntu Touch has partially been adopted from how we in Debian maintains our various Debian versions in parallel, only that in Ubuntu Touch we use Git(Lab) for maintaining the different package versions and not, like in Debian, the APT archive itself.&lt;/p&gt;

&lt;h3&gt;What does &#39;Branching-Off&#39; Mean?&lt;/h3&gt;

&lt;p&gt;Last Saturday, in the UBports Q&amp;amp;A, I explained Ubuntu Touch&#39;s &quot;branching-off&quot;, an aspect of the Ubuntu Touch release workflow based on Git(Lab). To make this accessible to even more people, here it comes as a write-up:&lt;/p&gt;

&lt;p&gt;We host many Git repositories on GitLab, and our primary work is done on the main branches, which contain the bleeding-edge code. When a merge request is deemed critical for stable versions of Ubuntu Touch, we cherry-pick it into a release series branch.&lt;/p&gt;

&lt;p&gt;Currently, we land our changes in the main branches and then cherry-pick them to the ubports/24.04.1.x branches. The &#39;branching off&#39; process for the upcoming 24.04-2.x release means that our current main branches will be copied over to create new branches for this release cycle, namely ubports/24.04-2.x.&lt;/p&gt;

&lt;p&gt;This has two major implications. First, any item that hasn&#39;t been translated by the time of the branch-off will not receive any more translation updates during the 24.04-2.x cycle. This is why it is crucial that translation work is completed before the branching-off.&lt;/p&gt;

&lt;h3&gt;Warning of Breaking Changes arriving soon in 26.04-1.x Daily Development UT Images&lt;/h3&gt;

&lt;p&gt;Second, looking ahead to the release after 24.04-2.x, we will be approaching 26.04-1.x. The OS base will change to Ubuntu 26.04 LTS, hopefully being ready for release to Ubuntu Touch users before the end of the year. We already have a list of features we want to land there. Because we plan to include various major changes, such as the switch from Mir 1 to Mir 2, new calendar and contacts backends, Qt6-based core apps and service components, etc., the likelihood of breaking changes at the beginning of the 26.04-1.x release cycle (which will become the next main branches&#39; target) is very high.&lt;/p&gt;

&lt;h3&gt;The Ubuntu Touch 24.04-2.0 Release Schedule&lt;/h3&gt;

&lt;p&gt;The current release schedule is estimated to be:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;25 May 2026&lt;/strong&gt; [done]&lt;br /&gt;
Platform stability freeze 24.04-2.x&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;25 May 2026&lt;/strong&gt; [done]&lt;br /&gt;
String freeze 24.04-2.x&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;15 June 2026&lt;/strong&gt; [done]&lt;br /&gt;
Branching-off (and unfreeze 26.04-1.x development), UT image release: 24.04-2.0 Beta&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;22 or 29 June 2026&lt;/strong&gt; [coming]&lt;br /&gt;
Final freeze for 24.04-2.x, UT image release: 24.04-2.0 RC&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;6 or 13 July 2026&lt;/strong&gt; [coming]&lt;br /&gt;
Release version 24.04-2.0&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-16T11:14:29+00:00</dc:date>
	<dc:creator>sunweaver</dc:creator>
</item> 
<item rdf:about="http://www.luffy.cx/en/blog/2026-kpi-goodhart.html">
	<title>Vincent Bernat: Building a Soviet Nail Factory: how KPIs killed efficiency</title>
	<link>https://vincent.bernat.ch/en/blog/2026-kpi-goodhart</link>
     <content:encoded>&lt;p&gt;Inâ€¯2008, I landed my second job, in the network team at &lt;em&gt;Orange
Portails&lt;/em&gt;&lt;sup id=&quot;fnref-hebex&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-hebex&quot;&gt;1&lt;/a&gt;&lt;/sup&gt;, the division behind the websites and search engine of the
French telecom operator Orange. The place ran like clockwork: a comprehensive
technical setup, a dedicated team for every part of the business, and room to
focus on what I do best. A few years later, none of that mattered: thanks to an
obsession with the numbers, we could no longer deliver new services on time.&lt;/p&gt;
&lt;div class=&quot;admonition&quot;&gt;
&lt;p class=&quot;admonition-title&quot;&gt;Disclaimer&lt;/p&gt;
&lt;p&gt;This is a story I like to tell to warn people about
&lt;a href=&quot;https://en.wikipedia.org/wiki/Goodhart%27s_law&quot; title=&quot;Goodhart&#39;s law on Wikipedia&quot;&gt;Goodhartâ€™s law&lt;/a&gt;.&lt;sup id=&quot;fnref-campbell&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-campbell&quot;&gt;2&lt;/a&gt;&lt;/sup&gt; As these events happened almost 15 years ago, my
recollection is a bit fuzzy. I left in 2012.&lt;/p&gt;
&lt;/div&gt;
&lt;h1 id=&quot;the-first-years&quot;&gt;The first years&lt;/h1&gt;
&lt;p&gt;During my first years, the department operated like a startup. Its cradle was
the French company Echo. They built a search engine. France TÃ©lÃ©com bought it
and renamed it &lt;a href=&quot;https://fr.wikipedia.org/wiki/Voila&quot;&gt;Voila&lt;/a&gt;. It was the most visited search engine in France in the
early 2000s. France TÃ©lÃ©com consolidated the portal activities into the &lt;em&gt;Wanadoo
Portails&lt;/em&gt; division, later renamed &lt;em&gt;Orange Portails&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;The technical environment was excellent. We had many internal tools:&lt;sup id=&quot;fnref-nocloud&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-nocloud&quot;&gt;3&lt;/a&gt;&lt;/sup&gt; a
ticket system, an RRD-based graphing tool, an IPAM, a reporting tool, and an
SNMP-based alerting tool.&lt;sup id=&quot;fnref-snalert&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-snalert&quot;&gt;4&lt;/a&gt;&lt;/sup&gt; We deployed our Linux servers with
&lt;a href=&quot;https://cfengine.com/&quot;&gt;CFEngine&lt;/a&gt;. We installed systems and applications from internal Debian
repositories. We documented everything in a private &lt;a href=&quot;https://www.mediawiki.org/wiki/MediaWiki&quot; title=&quot;MediaWiki is a collaboration and documentation platform&quot;&gt;MediaWiki&lt;/a&gt; instance.
Supervision was performed with an ancestor of &lt;a href=&quot;https://www.xymon.com/servers/servers.html&quot; title=&quot;The Xymon Monitor&quot;&gt;Xymon&lt;/a&gt;. The network
architecture was clean and scalable with little legacy. We onboarded new people
in a day.&lt;/p&gt;
&lt;p&gt;It was a nurturing environment for me. I developed several tools:
&lt;a href=&quot;https://lldpd.github.io/&quot; title=&quot;lldpd: implementation of IEEE 802.1AB&quot;&gt;lldpd&lt;/a&gt;, an 802.1AB implementation, &lt;a href=&quot;https://vincent.bernat.ch/en/blog/2013-snimpy&quot; title=&quot;snimpy: SNMP &amp;amp; Python&quot;&gt;Snimpy&lt;/a&gt;, a pythonic binding for
Net-SNMP, &lt;a href=&quot;https://github.com/vincentbernat/wiremaps&quot;&gt;Wiremaps&lt;/a&gt;, a layer-2 discovery tool with a time machine to know
which device is connected where, &lt;a href=&quot;https://github.com/vincentbernat/Kitero&quot;&gt;KitÃ©rÅ‘&lt;/a&gt;, a tool to simulate network
conditions, &lt;a href=&quot;https://github.com/vincentbernat/QCss-3/&quot;&gt;QCSS-3&lt;/a&gt;, a controller for load-balancers, and &lt;a href=&quot;https://github.com/vincentbernat/ipoo&quot;&gt;ipoo&lt;/a&gt;, a service
available through a Jabber chatbot and a Greasemonkey script to expose
IP-related information. I added &lt;a href=&quot;https://vincent.bernat.ch/en/blog/2011-keepalived-snmp-ipv6&quot; title=&quot;SNMP support for Keepalived&quot;&gt;SNMP support for Keepalived&lt;/a&gt; and
&lt;a href=&quot;https://github.com/search?q=repo%3AFRRouting%2Ffrr+author%3Avincentbernat+snmp&amp;amp;type=commits&quot; title=&quot;SNMP-related commits for Quagga/FRR&quot;&gt;Quagga&lt;/a&gt;. I also started this blog, with articles like
â€œ&lt;a href=&quot;https://vincent.bernat.ch/en/blog/2011-dns-anycast&quot; title=&quot;Anycast DNS&quot;&gt;Anycast DNS&lt;/a&gt;,â€� TLS-related articles like â€œ&lt;a href=&quot;https://vincent.bernat.ch/en/blog/2011-ssl-dos-mitigation&quot; title=&quot;TLS computational DoS mitigation&quot;&gt;TLS computational DoS
mitigation&lt;/a&gt;,â€� SNMP-related articles like â€œ&lt;a href=&quot;https://vincent.bernat.ch/en/blog/2012-snmp-event-loop&quot; title=&quot;Integration of Net-â� SNMP into an event loop&quot;&gt;Integration of Net-SNMP into an
event loop&lt;/a&gt;,â€� Linux-related articles like â€œ&lt;a href=&quot;https://vincent.bernat.ch/en/blog/2011-ipv4-route-cache-linux&quot; title=&quot;Tuning Linux IPv4 route cache&quot;&gt;Tuning Linux IPv4 route cache&lt;/a&gt;,â€�
and an &lt;a href=&quot;https://vincent.bernat.ch/en/blog/2012-multicast-vxlan&quot; title=&quot;Network virtualization with VXLAN&quot;&gt;article about VXLAN&lt;/a&gt; long before it was cool.&lt;/p&gt;
&lt;h1 id=&quot;the-collapse&quot;&gt;The collapse&lt;/h1&gt;
&lt;p&gt;When we needed new servers, the on-site team would take a set from the
inventory, install our base Linux distribution on them, put them in the
datacenter, and cable them to the top-of-the-rack switches. We opened a ticket
describing the servers we needed, and one week later, our servers were
available. ğŸ’«&lt;/p&gt;
&lt;p&gt;Orange wanted to know if this team was performing well, so they asked for &lt;abbr title=&quot;Key Performance Indicators&quot;&gt;KPIs&lt;/abbr&gt;.
They decided to use the number of tickets completed in a year. They asked to
double this number. So instead of one ticket for a new service, we would open
six ticketsâ€”one per server. By the end of the year, the &lt;abbr title=&quot;Key Performance Indicators&quot;&gt;KPIs&lt;/abbr&gt; had more than
doubled.&lt;/p&gt;
&lt;p&gt;Everybody saw it as a success for performance management. So, they asked to do
the same for the next year. Now, we needed to open a ticket per server and per
step. Again, the &lt;abbr title=&quot;Key Performance Indicators&quot;&gt;KPIs&lt;/abbr&gt; doubled. Behind the scenes, the tickets went to different
people and were no longer handled in order. So, for the next year, it was decided to
have meta-tickets and meetings to follow the progress of these tickets. Of
course, all these extra steps pushed the &lt;abbr title=&quot;Key Performance Indicator&quot;&gt;KPI&lt;/abbr&gt; even higher.&lt;/p&gt;
&lt;p&gt;This performance management method spread to the other teams.&lt;sup id=&quot;fnref-firewall&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-firewall&quot;&gt;5&lt;/a&gt;&lt;/sup&gt;
Everything became slower. Instead of a couple of weeks, a new service now took
six months. We built a &lt;a href=&quot;https://fronterabrands.com/goodharts-law/&quot; title=&quot;Goodhartâ€™s Law: Soviet Nail Factories &amp;amp; The Power of Incentives&quot;&gt;Soviet nail factory&lt;/a&gt;. But the &lt;abbr title=&quot;Key Performance Indicators&quot;&gt;KPIs&lt;/abbr&gt; were good, and we
stopped caring.&lt;/p&gt;
&lt;p&gt;Let me give you another example. We had to estimate the impact of each night
operation. We werenâ€™t half bad: we declared most operations â€œwithout any
expected impact.â€� Most of the time, there was no impact. One time out of five,
there was a 5-second impact. We were told to try harder to meet our expected
impact. What did we do? We started declaring a 5-second expected impact. One
day, we got a 30-second impact and were told we failed to match the expected
impact. In the end, we declared most operations with a 10-minute expected
impact, and we stopped caring: instead of carefully shifting traffic around, we
allowed ourselves a 5-minute impact. And our &lt;abbr title=&quot;Key Performance Indicators&quot;&gt;KPIs&lt;/abbr&gt; were never better.&lt;/p&gt;
&lt;figure&gt;&lt;div class=&quot;lf-media-outer&quot; style=&quot;width: 630px;&quot;&gt;&lt;span class=&quot;lf-media-inner&quot;&gt;&lt;img alt=&quot;Graph showing the impact of night operations. Year after year, the impact tolerance has been increased. In the final year, the expected impact is 10 minutes, and all operations remain under this threshold. However, the impacts are much more significant than they were in the first year.&quot; class=&quot;lf-media&quot; height=&quot;245&quot; src=&quot;https://d2pzklc15kok91.cloudfront.net/images/orange-impacts.03b883aacf07da.svg&quot; width=&quot;630&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;figcaption&gt;An artist&#39;s rendering of the evolution of impacts over the years.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;abbr title=&quot;Key Performance Indicators&quot;&gt;KPIs&lt;/abbr&gt; are not bad, but they are easy to break. Use them carefully: let the people
doing the work help choose the metrics, and tie those metrics to the quality of
the serviceâ€”for example, with &lt;a href=&quot;https://sre.google/sre-book/service-level-objectives/&quot; title=&quot;Google SRE book: Service Level Objectives&quot;&gt;service level objectives&lt;/a&gt;. Otherwise, even
dedicated people stop caring, game the system, and eventually quit.&lt;sup id=&quot;fnref-google&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-google&quot;&gt;6&lt;/a&gt;&lt;/sup&gt; ğŸ“Š&lt;/p&gt;
&lt;div class=&quot;footnote&quot;&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id=&quot;fn-hebex&quot;&gt;
&lt;p&gt;Internally, this division was named â€œHebex.â€� It was located in
Bagnolet (next to Paris) and Sophia-Antipolis (near Nice).Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-hebex&quot; title=&quot;Jump back to footnote 1 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&quot;fn-campbell&quot;&gt;
&lt;p&gt;Goodhartâ€™s law often gets the credit, but &lt;a href=&quot;https://en.wikipedia.org/wiki/Campbell%27s_law&quot; title=&quot;Campbell&#39;s law on Wikipedia&quot;&gt;Campbellâ€™s law&lt;/a&gt;
describes my experience even better: the more you lean on a number to make
decisions, the faster people corrupt it.Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-campbell&quot; title=&quot;Jump back to footnote 2 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&quot;fn-nocloud&quot;&gt;
&lt;p&gt;At the time, &lt;abbr title=&quot;Software as a Service&quot;&gt;SaaS&lt;/abbr&gt; was not really a thing. I remember we considered,
with a couple of colleagues, selling &lt;a href=&quot;https://github.com/vincentbernat/wiremaps&quot;&gt;Wiremaps&lt;/a&gt; as a &lt;abbr title=&quot;Software as a Service&quot;&gt;SaaS&lt;/abbr&gt;, with
homomorphic encryption for the database. But who would outsource their
observability stack?Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-nocloud&quot; title=&quot;Jump back to footnote 3 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&quot;fn-snalert&quot;&gt;
&lt;p&gt;&lt;em&gt;Snalert&lt;/em&gt; was a metacircular alerting tool in Perl. It was able to
poll a very large number of SNMP targets in a short timespan. All our
monitoring was SNMP-based, including system monitoring.Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-snalert&quot; title=&quot;Jump back to footnote 4 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&quot;fn-firewall&quot;&gt;
&lt;p&gt;My team also managed the rules of many Linux-based firewalls. To
increase our &lt;abbr title=&quot;Key Performance Indicators&quot;&gt;KPIs&lt;/abbr&gt;, we used the same method: rather than accepting one ticket
with a flow matrix, we requested one ticket per flow.Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-firewall&quot; title=&quot;Jump back to footnote 5 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&quot;fn-google&quot;&gt;
&lt;p&gt;Orange is not unique. Googleâ€™s promotion process is another
well-known example of a broken &lt;abbr title=&quot;Key Performance Indicator&quot;&gt;KPI&lt;/abbr&gt;. Michael Lynch explains it in â€œ&lt;a href=&quot;https://mtlynch.io/why-i-quit-google/&quot; title=&quot;Why I Quit Google to Work for Myself&quot;&gt;Why I
Quit Google to Work for Myself&lt;/a&gt;.â€�Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-google&quot; title=&quot;Jump back to footnote 6 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-06-16T06:26:27+00:00</dc:date>
	<dc:creator>Vincent Bernat</dc:creator>
</item> 
<item rdf:about="https://retout.co.uk/2026/06/15/in-memoriam-commitemailpy/">
	<title>Tim Retout: In memoriam commit-email.py</title>
	<link>https://retout.co.uk/2026/06/15/in-memoriam-commitemailpy/</link>
     <content:encoded>&lt;p&gt;I have &lt;a href=&quot;https://github.com/seL4/l4v/pull/1020/changes/d910068845aca32099cd480b5ac8f85257bbca52&quot;&gt;proposed the deletion of an obsolete
script&lt;/a&gt;,
but it makes me feel complicated feelings so I’m going to try and
express those.  This particular script was written in 2014, but the
concept goes back much further – before git was invented.&lt;/p&gt;
&lt;p&gt;When I started university in 2003, I seem to remember the computing
society used to run tutorials for first-year students on how to use
Apache Subversion for your group project – a vast upgrade on CVS (or
worse, no version control at all).  Back then, the idea of viewing
your changesets in a web browser was relatively new – while it was
possible to look at an SVN repository through a web UI, features were
limited unless you installed something compicated like
&lt;a href=&quot;https://trac.edgewall.org/wiki/TracSubversion&quot;&gt;Trac&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Data flow when distributing commits via a mailing list&quot; src=&quot;https://retout.co.uk/2026/commit-email.drawio.svg&quot; /&gt;
&lt;em&gt;Figure 1: Data flow when distributing commits via a mailing list&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Perhaps because reading email on your desktop computer (I don’t think
I could afford an IBM ThinkPad?) was the only vaguely real-time
notification system available at the time (except I guess SMS, which
cost 10p per text), a common pattern seemed to be to use a
&lt;a href=&quot;https://svnbook.red-bean.com/en/1.7/svn-book.html#svn.ref.reposhooks.post-commit&quot;&gt;post-commit
hook&lt;/a&gt;
to send every single commit to a mailing list, named something like
‘foo-commits’.  Indeed, for a long time Fedora had an scm-commits list
which &lt;a href=&quot;https://discussion.fedoraproject.org/t/the-future-plans-for-the-scm-commits-mailing-list/193068&quot;&gt;appears to be a topic of recent
discussion&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I can’t really explain &lt;em&gt;why&lt;/em&gt; people wanted to have every commit sent
to a mailing list except as a way of getting notified of activity – I
can’t believe people would import raw patches from those lists, ala
LKML, rather than run actual version control commands to fetch the new
source directly.  Maybe you’d have to go back to NNTP for this.&lt;/p&gt;
&lt;p&gt;I do like the vendor-neutrality of the “everything-as-text” approach,
building on the open ecosystem of SMTP.  But I doubt we’d see a
widespread resurgence of commit lists now – most code hosting must
allow anyone to subscribe to email notifications, I assume, and I
don’t see a huge benefit in a mailing list archive of commit messages.&lt;/p&gt;
&lt;p&gt;In the case of seL4, I’m even more confused about why this script was
committed in 2014, shortly after the kernel was put on GitHub.  I can
only assume it was imported from previous infrastructure.  I do know
that the implementation is quite Python 2 heavy, with the conversion
between unicode and bytes featuring heavily.  So rather than risk
breaking its logic with patching, I think it’s time to “thank it for
its service” and let go.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-15T22:04:50+00:00</dc:date>
	<dc:creator>Tim Retout</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/06/14#rbenchmark_1.0.1">
	<title>Dirk Eddelbuettel: rbenchmark 1.0.1 on CRAN: New(ly Adopted) Package!</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/06/14#rbenchmark_1.0.1</link>
     <content:encoded>&lt;p&gt;Quick note to share that &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rbenchmark.html&quot;&gt;rbenchmark&lt;/a&gt;
is back on &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;! The &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rbenchmark.html&quot;&gt;rbenchmark&lt;/a&gt;
package makes it easy to benchmark (and compare) simple R
expressions.&lt;/p&gt;
&lt;p&gt;This package has been on &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; for many years. At one point
fourteen years ago it appeared to be rudderless so I offered help but
things realigned. Now it was just tossed off &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;, taking a number of packages
depending on it with it (as shown in this &lt;a href=&quot;https://bsky.app/profile/cranberriesfeed.bsky.social/post/3mnyns2uqch2o&quot;&gt;CRANberries
skeet&lt;/a&gt; listing a set of removed packages) so I offered again to help,
and &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; agreed. So here we
are.&lt;/p&gt;
&lt;p&gt;So far I just made a number of small ‘editing’ changes, added CI
support, and enable dbsr-universe coverage . I do not expect to change
the package materially. So far the package has no NEWS file either so
maybe glance at the &lt;a href=&quot;https://github.com/eddelbuettel/rbenchmark/blob/master/ChangeLog&quot;&gt;ChangeLog&lt;/a&gt;
at the &lt;a href=&quot;https://github.com/eddelbuettel/rbenchmark&quot;&gt;git
repo&lt;/a&gt;.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;. You can also sponsor my &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/2026/04/03#sponsor_tour_de_shore_202&quot;&gt;Tour
de Shore 2026 ride in support of the Maywood Fine Arts Center&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-15T00:54:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/heroquest/">
	<title>Jonathan Dowland: HeroQuest</title>
	<link>https://jmtd.net/log/heroquest/</link>
     <content:encoded>&lt;div class=&quot;image&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/heroquest/hq.jpg&quot;&gt;&lt;img alt=&quot;_First Light_ box&quot; class=&quot;img&quot; height=&quot;263&quot; src=&quot;https://jmtd.net/log/heroquest/350x-hq.jpg&quot; width=&quot;350&quot; /&gt;&lt;/a&gt;

&lt;p&gt;&lt;em&gt;First Light&lt;/em&gt; box&lt;/p&gt;

&lt;/div&gt;


&lt;p&gt;My youngest daughter and I recently started playing the tabletop game
HeroQuest. Specifically, the recently-issued, cut-down variant
&lt;em&gt;HeroQuest: First Light&lt;/em&gt;. This is quite advanced for her age, and I&#39;m
a little surprised she&#39;s taken to it, but she&#39;s really loving it,
It&#39;s pushed her to read bits of lore on cards and quest books that is
way above her expected reading level, and we&#39;ve been exercising her
maths by adding up the gold we find on our quests and calculating what
the heroes can buy with it in the store afterwards.&lt;/p&gt;

&lt;p&gt;Originally from 1989,
Hasbro re-issued HeroQuest in 2020. I read about it at the time but didn&#39;t
buy it. I wasn&#39;t
sure who I would play it with. It also seemed expensive to me. It probably
&lt;em&gt;wasn&#39;t&lt;/em&gt; unusually expensive in 2020, nor now, for the sheer volume of
finely-sculpted miniatures included.
I also knew I had the original game in the loft, and
I wasn&#39;t that keen on buying something I already had,
although untangling the contents from several similar boxed games would
take me many hours, and I wasn&#39;t sure how much of the game I would find.&lt;/p&gt;

&lt;div class=&quot;image&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/heroquest/closeup.jpg&quot;&gt;&lt;img alt=&quot;mix of old and new&quot; class=&quot;img&quot; height=&quot;263&quot; src=&quot;https://jmtd.net/log/heroquest/350x-closeup.jpg&quot; width=&quot;350&quot; /&gt;&lt;/a&gt;

&lt;p&gt;mix of old and new&lt;/p&gt;

&lt;/div&gt;


&lt;p&gt;&lt;em&gt;First Light&lt;/em&gt; was compelling because it is much, much cheaper than the full
remake, so I was happy
to take a punt. It&#39;s cheaper because it doesn&#39;t have any plastic monsters  or
furniture: instead cardboard cut-outs that stand up on plastic stands. For us,
that is a significant drawback: 3D miniatures are much more immersive, But I
can re-use the plastic miniatures I can find from the original game. &lt;em&gt;First
Light&lt;/em&gt; has a newly written adventure, better suited to beginners than the
original game.&lt;/p&gt;

&lt;p&gt;The re-issue(s) have new art and new model sculpts that look fantastic. They&#39;ve
changed anything which tied into Games Workshop&#39;s IP and I&#39;m really happy about
that. They&#39;ve made an effort to add women, almost entirely absent from the
original. I&#39;m certain my daughter wouldn&#39;t have tried it otherwise.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-14T09:31:49+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="https://blog.tenstral.net/?p=2074">
	<title>Matthias Klumpp: Introducing pkgcli: A nicer command-line interface for PackageKit</title>
	<link>https://blog.tenstral.net/2026/06/introducing-pkgcli-a-nicer-command-line-interface-for-packagekit.html</link>
     <content:encoded>&lt;p class=&quot;wp-block-paragraph&quot;&gt;For almost two decades, the &lt;a href=&quot;https://github.com/PackageKit/PackageKit&quot;&gt;PackageKit&lt;/a&gt; package management abstraction layer has shipped with &lt;code&gt;pkcon&lt;/code&gt; as its command-line client. &lt;code&gt;pkcon&lt;/code&gt; does its job, but it was always kind of a “testing” front-end for the PackageKit daemon rather than a tool designed for everyday use. The focus has instead been on the GUI tools, automatic system updates, GUI application managers and other front-ends. Its command names mirror the D-Bus API almost one-to-one (&lt;code&gt;get-details&lt;/code&gt;, &lt;code&gt;get-updates&lt;/code&gt;, &lt;code&gt;get-depends&lt;/code&gt;), output is very plain, and there is no machine-readable mode for scripting. Most importantly though, there has been no development on it at all for almost a decade, so &lt;code&gt;pkcon&lt;/code&gt; was stuck in its rudimentary state from that era.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Since a lot of changes will be coming to PackageKit, and testing the daemon and working with it from the command-line was not very pleasant anymore in 2025/2026, I decided to modernize the tool as part of my work as fellow for the &lt;a href=&quot;https://www.sovereign.tech/&quot;&gt;Sovereign Tech Agency&lt;/a&gt; last year. &lt;code&gt;pkgcli&lt;/code&gt; is the new command-line client for PackageKit. It is built from the ground up to be pleasant to use interactively &lt;em&gt;and&lt;/em&gt; easy to drive from scripts.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why a new tool?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Of course, instead of introducing a new tool, I could have just expanded &lt;code&gt;pkcon&lt;/code&gt; instead. The problem with that approach is that the &lt;code&gt;pkcon&lt;/code&gt; utility has been around for so long and its command-line API had ossified so much, that rather than changing it and potentially breaking a lot of scripts relying on its quirks, I decided to introduce a new tool instead. &lt;code&gt;pkcon&lt;/code&gt; can still be optionally compiled for people who need it in their scripts and workflows.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The goals for &lt;code&gt;pkgcli&lt;/code&gt;, and the features it now has are:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Human-friendly command names.&lt;/strong&gt; Verbs that read the way you’d describe the task, instead of mirroring the D-Bus API 1:1: &lt;code&gt;show&lt;/code&gt;, &lt;code&gt;search&lt;/code&gt;, &lt;code&gt;list-updates&lt;/code&gt;, &lt;code&gt;what-provides&lt;/code&gt;, instead of &lt;code&gt;get-details&lt;/code&gt; and friends.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Readable, &lt;span style=&quot;color: #b00020;&quot;&gt;c&lt;/span&gt;&lt;span style=&quot;color: #0057b8;&quot;&gt;o&lt;/span&gt;&lt;span style=&quot;color: #0b7a0b;&quot;&gt;l&lt;/span&gt;&lt;span style=&quot;color: #8a4b00;&quot;&gt;o&lt;/span&gt;&lt;span style=&quot;color: #6f42c1;&quot;&gt;r&lt;/span&gt;&lt;span style=&quot;color: #007a7a;&quot;&gt;e&lt;/span&gt;&lt;span style=&quot;color: #c2410c;&quot;&gt;d&lt;/span&gt; output&lt;/strong&gt; by default (still respecting &lt;a href=&quot;https://no-color.org/&quot;&gt;&lt;code&gt;NO_COLOR&lt;/code&gt;&lt;/a&gt; and degrading gracefully).&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;A real scripting mode.&lt;/strong&gt; A global &lt;code&gt;--json&lt;/code&gt; flag emits &lt;a href=&quot;https://jsonlines.org/&quot;&gt;JSONL&lt;/a&gt; instead of fully human-readable output when possible, to make it easier to use the tool for scripting purposes.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Sensible defaults.&lt;/strong&gt; A few defaults have been changed, such as the metadata cache-age, or automatic cleanup of unused dependencies being enabled by default. This is more in line with current defaults by other tools and frontends. We also print package information in a slightly different, more readable way.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Better handling of internationalized text&lt;/strong&gt;. Text should now align properly in the terminal window, and we should no longer have completely chaotic text output on non-English locales (especially Chinese/Japanese).&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why not &lt;code&gt;pkgctl&lt;/code&gt;?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Originally, this tool was called &lt;code&gt;pkgctl&lt;/code&gt;, to match other common cross-distro tool names. However, that name was already taken by an &lt;a href=&quot;https://man.archlinux.org/man/pkgctl.1&quot;&gt;Arch-specific distro development tool&lt;/a&gt;. When this issue was raised, we decided to just rename our tool to &lt;code&gt;pkgcli&lt;/code&gt; with the next release, to avoid the name clash on Arch Linux.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Examples!&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are some examples on how to use the new tool (some of which include the abridged output &lt;code&gt;pkgcli&lt;/code&gt; prints).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Search for anything containing the string “editor” in name or description, then look at the details of one result:&lt;/p&gt;



&lt;pre class=&quot;wp-block-code&quot;&gt;&lt;code&gt;$ pkgcli search editor
Querying                  [████████████████████████████████████████] 100%
&lt;span style=&quot;color: #00a;&quot;&gt;▣&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;ace-of-penguins&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;1.5~rc2-7&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #00a;&quot;&gt;▣&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;acorn-fdisk&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;3.0.6-14&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #00a;&quot;&gt;▣&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;ardour&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;1:9.2.0+ds-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0a0;&quot;&gt;✔&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;audacity&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;3.7.7+dfsg-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;manual:debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0a0;&quot;&gt;✔&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;audacity-data&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;3.7.7+dfsg-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;all&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;auto:debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #00a;&quot;&gt;▣&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;augeas-tools&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;1.14.1-1.1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #00a;&quot;&gt;▣&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;emacs&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;1:30.2+1-3&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;all&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #00a;&quot;&gt;▣&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;gedit&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;48.1-9+b1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #00a;&quot;&gt;▣&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;gedit-common&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;48.1-9&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;all&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #00a;&quot;&gt;▣&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;gedit-dev&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;48.1-9+b1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
[...]

$ pkgcli show nano
&lt;span style=&quot;font-weight: bold;&quot;&gt;Package:&lt;/span&gt; nano
&lt;span style=&quot;font-weight: bold;&quot;&gt;Version:&lt;/span&gt; 9.0-1
&lt;span style=&quot;font-weight: bold;&quot;&gt;Summary:&lt;/span&gt; small, friendly text editor inspired by Pico
&lt;span style=&quot;font-weight: bold;&quot;&gt;Description:&lt;/span&gt; GNU nano is an easy-to-use text editor originally designed as
 a replacement for Pico, the ncurses-based editor from the non-free mailer
 package Pine.
[...]
&lt;span style=&quot;font-weight: bold;&quot;&gt;URL:&lt;/span&gt; https://www.nano-editor.org/
&lt;span style=&quot;font-weight: bold;&quot;&gt;Group:&lt;/span&gt; publishing
&lt;span style=&quot;font-weight: bold;&quot;&gt;Installed Size:&lt;/span&gt; 2.9 MB
&lt;span style=&quot;font-weight: bold;&quot;&gt;Download Size:&lt;/span&gt; 646.0 KB&lt;/code&gt;&lt;/pre&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Search only within package &lt;em&gt;names&lt;/em&gt; rather than descriptions:&lt;/p&gt;



&lt;pre class=&quot;wp-block-code&quot;&gt;&lt;code&gt;$ pkgcli search name python3&lt;/code&gt;&lt;/pre&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Check for updates. &lt;code&gt;refresh&lt;/code&gt; updates the metadata, then &lt;code&gt;list-updates&lt;/code&gt; reports what’s available:&lt;/p&gt;



&lt;pre class=&quot;wp-block-code&quot;&gt;&lt;code&gt;$ pkgcli refresh &amp;amp;&amp;amp; pkgcli list-updates
Loading cache            [████████████████████████████████████████] 100%
&lt;span style=&quot;color: #0aa;&quot;&gt;▲&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;cme&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;1.048-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;all&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0aa;&quot;&gt;▲&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;gir1.2-gdm-1.0&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;50.1-2&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0aa;&quot;&gt;▲&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;imagemagick&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;8:7.1.2.24+dfsg1-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0aa;&quot;&gt;▲&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;imagemagick-7-common&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;8:7.1.2.24+dfsg1-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;all&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0aa;&quot;&gt;▲&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;imagemagick-7.q16&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;8:7.1.2.24+dfsg1-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0aa;&quot;&gt;▲&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;libdlrestrictions1&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;0.22.0&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0aa;&quot;&gt;▲&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;libfftw3-bin&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;3.3.11-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]
&lt;span style=&quot;color: #0aa;&quot;&gt;▲&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;libfftw3-dev&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;3.3.11-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;debian-testing-main&lt;/span&gt;]&lt;/code&gt;&lt;/pre&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Explore relationships between packages:&lt;/p&gt;



&lt;pre class=&quot;wp-block-code&quot;&gt;&lt;code&gt;$ pkgcli list-depends inkscape  &lt;span style=&quot;color: #6b6b6b;&quot;&gt;# list what inkscape depends on&lt;/span&gt;
$ pkgcli list-requiring libappstream5  &lt;span style=&quot;color: #6b6b6b;&quot;&gt;# list what requires libappstream5&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Find the package that provides a capability, here the AV1 GStreamer decoder:&lt;/p&gt;



&lt;pre class=&quot;wp-block-code&quot;&gt;&lt;code&gt;$ pkgcli what-provides &quot;gstreamer1(decoder-video/x-av1)&quot;
&lt;span style=&quot;color: #0a0;&quot;&gt;✔&lt;/span&gt; &lt;span style=&quot;font-weight: bold;&quot;&gt;gstreamer1.0-plugins-bad&lt;/span&gt; &lt;span style=&quot;color: #555555;&quot;&gt;1.28.3-1&lt;/span&gt;.&lt;span style=&quot;color: #555555;&quot;&gt;amd64&lt;/span&gt; [&lt;span style=&quot;color: #555555;&quot;&gt;auto:debian-testing-main&lt;/span&gt;]&lt;/code&gt;&lt;/pre&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also have JSON output for most commands! Attach &lt;code&gt;--json&lt;/code&gt; to any query and pipe the result straight into &lt;a href=&quot;https://jqlang.github.io/jq/&quot;&gt;&lt;code&gt;jq&lt;/code&gt;&lt;/a&gt;. Each line is a self-contained JSON object:&lt;/p&gt;



&lt;pre class=&quot;wp-block-code&quot;&gt;&lt;code&gt;$ pkgcli --json list-updates | jq -r &#39;.name&#39;
cme
gir1.2-gdm-1.0
imagemagick
imagemagick-7-common
imagemagick-7.q16
libdlrestrictions1
libfftw3-bin
libfftw3-dev
libfftw3-double3&lt;/code&gt;&lt;/pre&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Try it&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;code&gt;pkgcli&lt;/code&gt; is built by default alongside the rest of PackageKit since PackageKit 1.3.4. If your distribution ships a recent enough PackageKit, it should already be on your &lt;code&gt;PATH&lt;/code&gt;. You can read its man page &lt;code&gt;man pkgcli&lt;/code&gt; for more information. Feedback, bug reports, and patches are &lt;a href=&quot;https://github.com/PackageKit/PackageKit/pulls&quot;&gt;very welcome&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-14T06:22:00+00:00</dc:date>
	<dc:creator>Matthias</dc:creator>
</item> 
<item rdf:about="https://gwolf.org/2026/06/rey-ubu-carro-de-comedias-unam.html">
	<title>Gunnar Wolf: Rey Ubu - Carro de Comedias, UNAM</title>
	<link>https://gwolf.org/2026/06/rey-ubu-carro-de-comedias-unam.html</link>
     <content:encoded>&lt;p&gt;Today we went to see a theater play in UNAM’s Cultural Center, very near
our home. No, not inside any of the theaters — &lt;a href=&quot;https://osm.org/go/S8c~P~7RY?m=&quot;&gt;in the square just between
Sala Nezahualcóyotl, Foro Sor Juana and Sala Carlos
Chávez.&lt;/a&gt;. So, yes, not only we had fun,
but we had fun for free!&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/rey_ubu.jpg&quot;&gt;&lt;img alt=&quot;Announcement&quot; src=&quot;https://gwolf.org/files/2026-06/rey_ubu.200.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;UNAM’s &lt;a href=&quot;https://elanfiteatro.mx/p/carro-de-comedias-de-la-unam&quot;&gt;El Carro de
Comedias&lt;/a&gt; is an
itinerant theater company that often presents in this same spot (but you
can see the stage is foldable, and they do have presentations elsewhere, of
this same play even). I went with my family, and we enjoyed a very fun
adaptation of this great play (written by teenager Alfred Jarry in
1894). One of those plays that could be inspired any day by current
geopolitical events…&lt;/p&gt;

&lt;p&gt;I know most of the people that happen to stumble upon my blog are not in
Mexico City. But if you happen to be here, do consider going to their
function. &lt;a href=&quot;https://teatrounam.com.mx/teatro/entradasteatro/ubu-rey/#calendario&quot;&gt;Check their
schedule&lt;/a&gt;;
being it an itinerating show, they can also be found at other places, but
they are scheduled at the same place we saw them, every Saturday and Sunday
until June 28, 11:00AM. They mentioned they will likely continue during
August, but AFAICT it is not confirmed (or, at least, announced) yet.&lt;/p&gt;

&lt;p&gt;Some pics, shot randomly by me throughout the play:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/first_call.jpg&quot;&gt;&lt;img alt=&quot;Announcement&quot; src=&quot;https://gwolf.org/files/2026-06/first_call.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/first_call.jpg&quot;&gt;&lt;img alt=&quot;First_call&quot; src=&quot;https://gwolf.org/files/2026-06/first_call.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/accordion.jpg&quot;&gt;&lt;img alt=&quot;Accordion&quot; src=&quot;https://gwolf.org/files/2026-06/accordion.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/mom.jpg&quot;&gt;&lt;img alt=&quot;Mom&quot; src=&quot;https://gwolf.org/files/2026-06/mom.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/announce.jpg&quot;&gt;&lt;img alt=&quot;Announce&quot; src=&quot;https://gwolf.org/files/2026-06/announce.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/plotting.jpg&quot;&gt;&lt;img alt=&quot;Plotting&quot; src=&quot;https://gwolf.org/files/2026-06/plotting.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/audience.jpg&quot;&gt;&lt;img alt=&quot;Audience&quot; src=&quot;https://gwolf.org/files/2026-06/audience.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/wenceslao.jpg&quot;&gt;&lt;img alt=&quot;Wenceslao&quot; src=&quot;https://gwolf.org/files/2026-06/wenceslao.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/attack.jpg&quot;&gt;&lt;img alt=&quot;Attack&quot; src=&quot;https://gwolf.org/files/2026-06/attack.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/grumpy.jpg&quot;&gt;&lt;img alt=&quot;Grumpy&quot; src=&quot;https://gwolf.org/files/2026-06/grumpy.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/ministers.jpg&quot;&gt;&lt;img alt=&quot;Ministers&quot; src=&quot;https://gwolf.org/files/2026-06/ministers.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/council.jpg&quot;&gt;&lt;img alt=&quot;Council&quot; src=&quot;https://gwolf.org/files/2026-06/council.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/message.jpg&quot;&gt;&lt;img alt=&quot;Message&quot; src=&quot;https://gwolf.org/files/2026-06/message.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/russian.jpg&quot;&gt;&lt;img alt=&quot;Russian&quot; src=&quot;https://gwolf.org/files/2026-06/russian.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/soldiers.jpg&quot;&gt;&lt;img alt=&quot;Soldiers&quot; src=&quot;https://gwolf.org/files/2026-06/soldiers.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/all.jpg&quot;&gt;&lt;img alt=&quot;All&quot; src=&quot;https://gwolf.org/files/2026-06/all.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://gwolf.org/files/2026-06/end.jpg&quot;&gt;&lt;img alt=&quot;End&quot; src=&quot;https://gwolf.org/files/2026-06/end.400.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-13T19:55:32+00:00</dc:date>
	<dc:creator>Gunnar Wolf</dc:creator>
</item> 
<item rdf:about="157 at https://sunweavers.net/blog">
	<title>Mike Gabriel: Ayatana Indicators: Call for Translations</title>
	<link>https://sunweavers.net/blog/node/157</link>
     <content:encoded>&lt;p&gt;In the process of preparing a major Ubuntu Touch release (v24.04-2.0, coming soon...) we will also update Ayatana Indicators in Ubuntu Touch.&lt;/p&gt;

&lt;p&gt;Last week various new features have been added to some of the indicators (toggle switch to keep the display switched on permanently, blue tooth pairing agent, redesign of the keyboard indicator, etc.) and those changes require translation updates.&lt;/p&gt;

&lt;p&gt;If you can, please visit [1] this weekend and help translating Ayatana Indicators into your native language. Thanks so much!!!&lt;/p&gt;

&lt;p&gt;light+love&lt;br /&gt;
Mike&lt;/p&gt;

&lt;p&gt;[1] &lt;a href=&quot;https://hosted.weblate.org/projects/ayatana-indicators/&quot; title=&quot;https://hosted.weblate.org/projects/ayatana-indicators/&quot;&gt;https://hosted.weblate.org/projects/ayatana-indicators/&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-12T21:50:34+00:00</dc:date>
	<dc:creator>sunweaver</dc:creator>
</item> 
<item rdf:about="https://retout.co.uk/2026/06/12/sel4-clock-magic/">
	<title>Tim Retout: seL4 clock magic</title>
	<link>https://retout.co.uk/2026/06/12/sel4-clock-magic/</link>
     <content:encoded>&lt;p&gt;I have been looking at seL4 some more recently, and had &lt;a href=&quot;https://github.com/seL4/seL4/commit/c1c9dd5bff69f5ea078d341a47555ad485808ab4&quot;&gt;a small
patch&lt;/a&gt;
merged today to remove a legacy Python module from a helper script.
(I was trying to run the script on a system without that module
installed, and it was almost easier to patch it out.)&lt;/p&gt;
&lt;p&gt;However, the more I think about this code and how it’s used, the more
it seems wrong on at least five other levels.&lt;/p&gt;
&lt;p&gt;The patch itself is quite uninteresting; this script was importing the
&lt;code&gt;past&lt;/code&gt; module (part of &lt;code&gt;future&lt;/code&gt;?) to use the &lt;code&gt;xrange&lt;/code&gt; function.
Python 2 used to have separate &lt;code&gt;xrange&lt;/code&gt; and &lt;code&gt;range&lt;/code&gt; functions, where
&lt;code&gt;range&lt;/code&gt; returned a list in memory while &lt;code&gt;xrange&lt;/code&gt; generated an
iterator.  Because this seL4 script is iterating over a large range of
values, it’s important the list is not generated in-memory.  But
Python 3 removed the &lt;code&gt;xrange&lt;/code&gt; function and just has &lt;code&gt;range&lt;/code&gt; return an
object, so it’s trivial to avoid the module import.&lt;/p&gt;
&lt;p&gt;Having thought carefully some more about the specific line, there’s
surely an off-by-one error in it - &lt;code&gt;range&lt;/code&gt; iterates over 0 to n-1, so
this line shouldn’t be subtracting one if it’s looking to test all
32-bit values:&lt;/p&gt;
&lt;div class=&quot;code-block-wrapper&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre tabindex=&quot;0&quot;&gt;&lt;code class=&quot;language-python&quot;&gt;&lt;span style=&quot;display: flex;&quot;&gt;&lt;span&gt;    &lt;span style=&quot;color: #66d9ef;&quot;&gt;for&lt;/span&gt; i &lt;span style=&quot;color: #f92672;&quot;&gt;in&lt;/span&gt; range(&lt;span style=&quot;color: #ae81ff;&quot;&gt;2&lt;/span&gt;&lt;span style=&quot;color: #f92672;&quot;&gt;**&lt;/span&gt;&lt;span style=&quot;color: #ae81ff;&quot;&gt;32&lt;/span&gt;&lt;span style=&quot;color: #f92672;&quot;&gt;-&lt;/span&gt;&lt;span style=&quot;color: #ae81ff;&quot;&gt;1&lt;/span&gt;):&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;But then again, this is being used for a ‘sanity check’ of a magic bit
shift algorithm that speeds up division operations to convert CPU
ticks to microseconds on 32-bit arm platforms.  Surely if the
algorithm’s good, it shouldn’t be necessary to validate it
exhaustively against every possible 32-bit value?&lt;/p&gt;
&lt;p&gt;Also, 32 bits isn’t enough, because this is 64-bit division.
&lt;code&gt;include/api/types.h&lt;/code&gt; shows that &lt;code&gt;ticks_t&lt;/code&gt; is always a &lt;code&gt;uint64_t&lt;/code&gt;, so
if this were a proof by exhaustion it should run to 2**64 (though that
would take infeasibly long).&lt;/p&gt;
&lt;p&gt;As discussed in &lt;a href=&quot;https://github.com/seL4/seL4/issues/1352&quot;&gt;issue
#1352&lt;/a&gt;, lots of people have
been running this code with the wrong divisor anyway.  But because the
bit shift path is only used on 32-bit platforms, it’s not clear to me
that there’s even any point in specifying CLK_SHIFT/MAGIC on platforms
which are 64-bit only (e.g. the tx2 port).&lt;/p&gt;
&lt;p&gt;And to follow this rabbit hole to the very end, in comments on &lt;a href=&quot;https://github.com/seL4/seL4/pull/1435#issuecomment-2813656622&quot;&gt;PR
#1435&lt;/a&gt;
and &lt;a href=&quot;https://github.com/seL4/seL4/issues/1509&quot;&gt;issue #1509&lt;/a&gt; it’s clear
that the future of this code is to remove it, as it’s 1. unnecessarily
clever (on 64-bit platforms the equivalent code just uses a division,
so performance can’t be that important), and 2. the entire concept of
converting to microseconds breaks the seL4 principle of not
abstracting away details of the hardware.&lt;/p&gt;
&lt;p&gt;So this has left me unclear on whether my small patch was a good thing
or not, but I certainly learnt something about this corner of seL4
timer handling.  And I’ve ordered a copy of “Hacker’s Delight” on the
recommendation of a code comment.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-12T16:45:40+00:00</dc:date>
	<dc:creator>Tim Retout</dc:creator>
</item> 
<item rdf:about="156 at https://sunweavers.net/blog">
	<title>Mike Gabriel: Future of libayatana-appindicator (v0.6.0 released today)</title>
	<link>https://sunweavers.net/blog/node/156</link>
     <content:encoded>&lt;p&gt;Some of you might have noticed that the recent (or rather: previous) version of libayatana-appindicator (v0.5.94) notified users and developers of the library being deprecated.&lt;/p&gt;

&lt;p&gt;This short post is to notify you, that with today&#39;s libayatana-appindicator v0.6.0 release [1] this deprecation warning has now been removed again. Another new feature (added to AppIndicator without ABI breakage) is tooltip support. The new package version has just been uploaded to Debian experimental. Please test if your application (if it gets linked against libayatana-appindicator) continues to work flawlessly. Thanks!&lt;/p&gt;

&lt;p&gt;libayatana-appindicator will receive continued support until GTK-3 becomes end-of-life (because libayatana-appindicator has a baked-in GTK-3 dependency which should not be ported to GTK-4 imho). That said, in the future, GTK-3 applications can continue using libayatana-appindicator for sending AppIndicator-like icons and menus over DBus to KStatusNotifierItem-based system tray renderers.&lt;/p&gt;

&lt;p&gt;If you are looking for an AppIndicator implementation for GTK-4 applications (or other), I&#39;d like to encourage you to help making libayatana-appindicator-glib [2] a new standard (can be used in GTK and Qt applications alike, implementation is using pure Glib-2.0). Currently, there is only one renderer (ayatana-indicator-application), so more work needs to be done on the renderers&#39; side. (One of the next work items here is to get AppIndicator-Glib support working in Lomiri&#39;s desktop/windowed mode).&lt;/p&gt;

&lt;p&gt;[1] &lt;a href=&quot;https://github.com/AyatanaIndicators/libayatana-appindicator/releases/tag/0.6.0&quot; title=&quot;https://github.com/AyatanaIndicators/libayatana-appindicator/releases/tag/0.6.0&quot;&gt;https://github.com/AyatanaIndicators/libayatana-appindicator/releases/ta...&lt;/a&gt;&lt;br /&gt;
[2] &lt;a href=&quot;https://github.com/AyatanaIndicators/libayatana-appindicator-glib/&quot; title=&quot;https://github.com/AyatanaIndicators/libayatana-appindicator-glib/&quot;&gt;https://github.com/AyatanaIndicators/libayatana-appindicator-glib/&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-10T20:15:00+00:00</dc:date>
	<dc:creator>sunweaver</dc:creator>
</item> 
<item rdf:about="tag:www.chiark.greenend.org.uk,2026-06-10:/~cjwatson/blog/activity-2026-05.html">
	<title>Colin Watson: Free software activity in May 2026</title>
	<link>https://www.chiark.greenend.org.uk/~cjwatson/blog/activity-2026-05.html</link>
     <content:encoded>&lt;p&gt;My Debian contributions this month were all &lt;a href=&quot;https://www.freexian.com/about/debian-contributions/&quot;&gt;sponsored&lt;/a&gt; by Freexian.&lt;/p&gt;
&lt;p&gt;You can also support my work directly via &lt;a href=&quot;https://liberapay.com/cjwatson&quot;&gt;Liberapay&lt;/a&gt; or &lt;a href=&quot;https://github.com/sponsors/cjwatson&quot;&gt;GitHub Sponsors&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;OpenSSH&lt;/h2&gt;
&lt;p&gt;I backported various security fixes from 10.3 to &lt;a href=&quot;https://bugs.debian.org/1135624&quot;&gt;trixie&lt;/a&gt;, &lt;a href=&quot;https://bugs.debian.org/1135658&quot;&gt;bookworm&lt;/a&gt;, &lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/05/msg00030.html&quot;&gt;bullseye&lt;/a&gt;, &lt;a href=&quot;https://www.freexian.com/lts/extended/updates/ela-1720-1-openssh/&quot;&gt;buster&lt;/a&gt;, and &lt;a href=&quot;https://www.freexian.com/lts/extended/updates/ela-1721-1-openssh/&quot;&gt;stretch&lt;/a&gt;.  For trixie, I also backported several IPQoS fixes to line up with upstream’s traffic management settings and drop a rather hacky Debian-specific patch; this needed a &lt;a href=&quot;https://bugs.debian.org/1135798&quot;&gt;quick follow-up fix&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I upgraded trixie-backports to 10.3.&lt;/p&gt;
&lt;p&gt;I fixed &lt;a href=&quot;https://bugs.debian.org/1136545&quot;&gt;openssh uses pidof but does not depend on procps&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;PuTTY&lt;/h2&gt;
&lt;p&gt;I upgraded from 0.83 to 0.84.&lt;/p&gt;
&lt;h2&gt;Python packaging&lt;/h2&gt;
&lt;p&gt;New upstream versions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;bitstruct&lt;/li&gt;
&lt;li&gt;ormar&lt;/li&gt;
&lt;li&gt;pdm (fixing a &lt;a href=&quot;https://bugs.debian.org/1134304&quot;&gt;build failure&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;pydantic&lt;/li&gt;
&lt;li&gt;pydantic-core&lt;/li&gt;
&lt;li&gt;pydantic-settings&lt;/li&gt;
&lt;li&gt;pyglet (fixing a &lt;a href=&quot;https://bugs.debian.org/1137404&quot;&gt;build failure&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;python-asyncssh&lt;/li&gt;
&lt;li&gt;python-bitarray&lt;/li&gt;
&lt;li&gt;python-btrees&lt;/li&gt;
&lt;li&gt;python-build&lt;/li&gt;
&lt;li&gt;python-certifi&lt;/li&gt;
&lt;li&gt;python-charset-normalizer (fixing a &lt;a href=&quot;https://bugs.debian.org/1135452&quot;&gt;build failure&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;python-fakeredis (&lt;a href=&quot;https://github.com/cunla/fakeredis-py/pull/485&quot;&gt;contributed supporting fix upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;python-holidays&lt;/li&gt;
&lt;li&gt;python-jsonschema-path&lt;/li&gt;
&lt;li&gt;python-memray (fixing a &lt;a href=&quot;https://bugs.debian.org/1135455&quot;&gt;build failure&lt;/a&gt; and &lt;a href=&quot;https://bugs.debian.org/1131372&quot;&gt;&lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-32722&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;python-openapi-schema-validator&lt;/li&gt;
&lt;li&gt;python-pathable&lt;/li&gt;
&lt;li&gt;python-persistent&lt;/li&gt;
&lt;li&gt;python-pyftpdlib&lt;/li&gt;
&lt;li&gt;python-pytest-run-parallel&lt;/li&gt;
&lt;li&gt;sorl-thumbnail&lt;/li&gt;
&lt;li&gt;twisted&lt;/li&gt;
&lt;li&gt;zope.interface&lt;/li&gt;
&lt;li&gt;zope.proxy&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Other build/test failures:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137485&quot;&gt;beets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135497&quot;&gt;buildbot&lt;/a&gt; (&lt;a href=&quot;https://github.com/buildbot/buildbot/pull/9051&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1131097&quot;&gt;dep-logic&lt;/a&gt; (&lt;a href=&quot;https://github.com/pdm-project/dep-logic/pull/17&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135392&quot;&gt;diskcache&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135500&quot;&gt;khard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137583&quot;&gt;matplotlib&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137488&quot;&gt;mkdocs-rss-plugin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ormar: compatibility with &lt;a href=&quot;https://bugs.debian.org/1133964&quot;&gt;fastapi 0.125&lt;/a&gt; and &lt;a href=&quot;https://bugs.debian.org/1136865&quot;&gt;pydantic 2.13&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135445&quot;&gt;pgzero&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137501&quot;&gt;py7zr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/pydantic-extra-types/-/commit/858c65cb47b4fe03b080f79c99fa785282fd740c&quot;&gt;pydantic-extra-types&lt;/a&gt; (&lt;a href=&quot;https://github.com/pydantic/pydantic-extra-types/pull/394&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136922&quot;&gt;pydata-sphinx-theme&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135454&quot;&gt;python-invocations&lt;/a&gt; (&lt;a href=&quot;https://github.com/pyinvoke/invocations/pull/47&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1134305&quot;&gt;python-localzone&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135831&quot;&gt;python-maturin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135447&quot;&gt;python-nacl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1123283&quot;&gt;python-pampy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135507&quot;&gt;python-treq&lt;/a&gt; (&lt;a href=&quot;https://github.com/twisted/treq/pull/426&quot;&gt;contributed upstream&lt;/a&gt;, including &lt;a href=&quot;https://github.com/twisted/treq/pull/428&quot;&gt;fixing some &lt;span class=&quot;caps&quot;&gt;CI&lt;/span&gt; bitrot&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1122914&quot;&gt;python-txrequests&lt;/a&gt; (&lt;a href=&quot;https://github.com/tardyp/txrequests/pull/11&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Other bugs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1083325&quot;&gt;buildbot: (Build-)depends on deprecated module python3-pkg-resources&lt;/a&gt; (&lt;a href=&quot;https://github.com/buildbot/buildbot/pull/9048&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135182&quot;&gt;pysodium: Depends on cruft package libsodium&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1106749&quot;&gt;python-fakeredis: lua support not working, breaking django-redis cache locking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/cpython-team/python3/-/merge_requests/43&quot;&gt;python3.14: Drop libnsl-dev build-dependency&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I updated python-treq upstream to &lt;a href=&quot;https://github.com/twisted/treq/pull/430&quot;&gt;stop vendoring multipart&lt;/a&gt;, now that the packaging issues with that have been sorted out.&lt;/p&gt;
&lt;h2&gt;Code reviews&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135891&quot;&gt;debmirror: User-Agent blocked by Ubuntu/Launchpad repositories&lt;/a&gt; (uploaded, and &lt;a href=&quot;https://bugs.debian.org/1135937&quot;&gt;cherry-picked into trixie&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/pydantic/-/merge_requests/1&quot;&gt;pydantic: Fix &lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2024-3772 in bookworm&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/pyodbc/-/merge_requests/3&quot;&gt;pyodbc: Run SQLite tests&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/python-jsonschema-path/-/merge_requests/1&quot;&gt;python-jsonschema-path: Transition to starlette 1.0&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1131976&quot;&gt;python-maison: &lt;span class=&quot;caps&quot;&gt;FTBFS&lt;/span&gt; with the nocheck build profile&lt;/a&gt; (followed up to fix the &lt;code&gt;nodoc&lt;/code&gt; build profile as well)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/python-openapi-core/-/merge_requests/1&quot;&gt;python-openapi-core: Transition to starlette 1.0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/python-openapi-schema-validator/-/merge_requests/1&quot;&gt;python-openapi-schema-validator: Transition to starlette 1.0&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/python-openapi-spec-validator/-/merge_requests/1&quot;&gt;python-openapi-spec-validator: Transition to starlette 1.0&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/python-pathable/-/merge_requests/1&quot;&gt;python-pathable: Transition to starlette 1.0&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/python-team/packages/python-rich-argparse/-/merge_requests/3&quot;&gt;python-rich-argparse: New upstream version 1.8.0&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Other bits and pieces&lt;/h2&gt;
&lt;p&gt;I contributed a debian-policy patch to &lt;a href=&quot;https://bugs.debian.org/1138005&quot;&gt;fix several links related to build profiles&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-10T15:10:16+00:00</dc:date>
	<dc:creator>Colin Watson</dc:creator>
</item> 
<item rdf:about="http://www.luffy.cx/en/blog/2026-blogging-llm.html">
	<title>Vincent Bernat: Blogging with LLMs as a non-native speaker</title>
	<link>https://vincent.bernat.ch/en/blog/2026-blogging-llm</link>
     <content:encoded>&lt;p&gt;&lt;abbr title=&quot;Artificial Intelligence&quot;&gt;AI&lt;/abbr&gt; slop is invading the web. A recent story about &lt;a href=&quot;https://lobste.rs/s/29pm2f/llm_generated_submissions_should_be&quot; title=&quot;LLM generated submissions should be disallowed&quot;&gt;disallowing &lt;abbr title=&quot;Large Language Model&quot;&gt;LLM&lt;/abbr&gt;-generated
submissions&lt;/a&gt; on &lt;a href=&quot;https://lobste.rs/&quot; title=&quot;Lobsters&quot;&gt;Lobsters&lt;/a&gt; triggered a lot of debate. My personal worst
offenders are &lt;a href=&quot;https://www.linkedin.com/&quot;&gt;LinkedIn&lt;/a&gt; articles with &lt;abbr title=&quot;Artificial Intelligence&quot;&gt;AI&lt;/abbr&gt;-generated images and uninspired
articles filled with emojis from people trying to masquerade as experts on a
subject they donâ€™t care enough to write themselves. While I am unhappy about
this situation, I rely on &lt;abbr title=&quot;Large Language Models&quot;&gt;LLMs&lt;/abbr&gt; for &lt;strong&gt;grammar&lt;/strong&gt;, &lt;strong&gt;copyediting&lt;/strong&gt;, and
&lt;strong&gt;translation&lt;/strong&gt;. I donâ€™t see this as a contradiction.&lt;/p&gt;
&lt;p&gt;I am a native French speaker, but I blog in both English and French. When I
started writing this blog in 2011, I was composing in &lt;a href=&quot;https://vincent.bernat.ch/fr/blog/2011-migration-vers-github&quot; title=&quot;Migration de Trac vers GitHub&quot;&gt;French&lt;/a&gt; and translating
to &lt;a href=&quot;https://vincent.bernat.ch/en/blog/2011-migrating-to-github&quot; title=&quot;Migrating from Trac to GitHub&quot;&gt;English&lt;/a&gt;, but I found it was &lt;a href=&quot;https://sci-hub.fr/10.1016/j.jslw.2009.06.003&quot; title=&quot;L1 use during L2 writing: An empirical study of a complex phenomenon&quot;&gt;better to work in the reverse order&lt;/a&gt; to
avoid unnatural and non-idiomatic constructions. One of my goals is to write
â€œgoodâ€� English but I never felt it was my strong point.&lt;sup id=&quot;fnref-book&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-book&quot;&gt;1&lt;/a&gt;&lt;/sup&gt; For example, verb
tenses are often an issue, even if I mostly stick with the present tense. I
learn the rules and forget them right away. I also donâ€™t feel like &lt;a href=&quot;https://mtlynch.io/editor/&quot; title=&quot;How I Hired a Freelance Editor for My Blog&quot;&gt;hiring an
editor&lt;/a&gt; for something I see as a hobby.&lt;/p&gt;
&lt;p&gt;As an example, I have kept the history of the successive iterations when writing
â€œ&lt;a href=&quot;https://vincent.bernat.ch/en/blog/2026-akvorado-rib-sharding&quot; title=&quot;Scaling Akvorado BMP RIB with sharding&quot;&gt;Scaling Akvorado BMP RIB with sharding&lt;/a&gt;â€�:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;the &lt;a href=&quot;https://github.com/vincentbernat/vincent.bernat.ch/commit/aad263c20c7b021b1069952d1487374ff559d3b3&quot; title=&quot;article: Akvorado BMP RIB with sharding&quot;&gt;first draft&lt;/a&gt;, authored with the help of a thesaurus,&lt;sup id=&quot;fnref-kagi&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-kagi&quot;&gt;2&lt;/a&gt;&lt;/sup&gt;&lt;/li&gt;
&lt;li&gt;the &lt;a href=&quot;https://github.com/vincentbernat/vincent.bernat.ch/commit/11231af4be15160c1dd48e45c9b4dc7c042cf191&quot; title=&quot;content: copyediting of Akvorado BMP RIB article&quot;&gt;edited copy&lt;/a&gt; revised by the &lt;a href=&quot;https://github.com/vincentbernat/vincent.bernat.ch/blob/latest/.claude/skills/edit/SKILL.md&quot;&gt;copyediting skill&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;the &lt;a href=&quot;https://github.com/vincentbernat/vincent.bernat.ch/commit/0435ae3a8450132abb89507e856a012831457e49&quot; title=&quot;article: Akvorado BMP RIB in French&quot;&gt;translation to French&lt;/a&gt; generated with the &lt;a href=&quot;https://github.com/vincentbernat/vincent.bernat.ch/blob/latest/.claude/skills/translate/SKILL.md&quot;&gt;translation
   skill&lt;/a&gt;, and&lt;/li&gt;
&lt;li&gt;the &lt;a href=&quot;https://github.com/vincentbernat/vincent.bernat.ch/commit/c0629b1d9fe450335fcd30c071fb44301615dd15&quot; title=&quot;content: human proofread of the French translation&quot;&gt;human proofread of the French translation&lt;/a&gt;, with minor
   edits to the English version.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I know that &lt;abbr title=&quot;Large Language Models&quot;&gt;LLMs&lt;/abbr&gt; may &lt;a href=&quot;https://sites.google.com/view/llmwritingdistortion/home&quot; title=&quot;How LLMs Distort Our Written Language&quot;&gt;alter the authorâ€™s voice when editing&lt;/a&gt;, but the
corrections in the second step are minor. The prompt asks to â€œapply light
stylistic edits,â€� with some guidance around avoiding passive voice, long
sentences, bland verbs, and filler words. It also defines the target audience:
technical with a B2 level in English.&lt;/p&gt;
&lt;p&gt;In the following excerpt, I used â€œlong timeâ€� instead of â€œlong-standing.â€� The
former is missing a hyphen and applies to peopleâ€”a &lt;a href=&quot;https://dictionary.cambridge.org/us/dictionary/english/long-time&quot; title=&quot;Definition of long-time in the Cambridge Dictionary&quot;&gt;long-time&lt;/a&gt; friend, while
the later relates to a situationâ€”a &lt;a href=&quot;https://dictionary.cambridge.org/us/dictionary/english/long-standing&quot; title=&quot;Definition of long-standing in the Cambridge Dictionary&quot;&gt;long-standing&lt;/a&gt; agreement. I had a hard
time understanding the reason of the second change: the &lt;abbr title=&quot;Large Language Model&quot;&gt;LLM&lt;/abbr&gt; prefers a
&lt;a href=&quot;https://dictionary.cambridge.org/us/grammar/british-grammar/relative-clauses-defining-and-non-defining&quot; title=&quot;Relative clauses: defining and non-defining&quot;&gt;defining relative clause&lt;/a&gt; to provide the definition of â€œRIB sharding.â€�&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;As the Internet routing table contains more than 1 million routes, Akvorado
needs to scale to tens of millions of routes. This has been a &lt;del&gt;long
time&lt;/del&gt; &lt;ins&gt;long-standing&lt;/ins&gt; challenge, but I expect this issue is now
fixed by using RIB sharding, a method &lt;del&gt;to split&lt;/del&gt; &lt;ins&gt;that
splits&lt;/ins&gt; the routing database into several parts to enable concurrent
updates.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;In the next modification, the &lt;abbr title=&quot;Large Language Model&quot;&gt;LLM&lt;/abbr&gt; puts â€œdeviceâ€� instead of â€œequipment.â€� This is
correct as â€œ&lt;a href=&quot;https://dictionary.cambridge.org/us/dictionary/english/equipment&quot; title=&quot;Definition of equipment in the Cambridge Dictionary&quot;&gt;equipment&lt;/a&gt;â€� is an uncountable noun. I know that, but I still fall
into this trap.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;When Akvorado does not find a route from a specific device, it falls back to a
route sent by another &lt;del&gt;equipment&lt;/del&gt; &lt;ins&gt;device&lt;/ins&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I ask the &lt;abbr title=&quot;Large Language Model&quot;&gt;LLM&lt;/abbr&gt; to use â€œdescriptive verbsâ€� and it complies by replacing a
multi-word predicate with a lexically rich verb:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The benchmarks demonstrate it &lt;del&gt;has better performance than&lt;/del&gt;
&lt;ins&gt;outperforms&lt;/ins&gt; other &lt;del&gt;packages, both&lt;/del&gt; &lt;ins&gt;packages&lt;/ins&gt; for
lookups, insertions, and memory usage.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;It also fixes grammar errors. In the next excerpt, a â€œlist of routesâ€� is a
singular expression. Moreover, â€œstoredâ€� is a state and I should not use â€œintoâ€�
as it expresses a change.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The list of routes for each prefix &lt;del&gt;are&lt;/del&gt; &lt;ins&gt;is&lt;/ins&gt; not stored
directly &lt;del&gt;into&lt;/del&gt; &lt;ins&gt;in&lt;/ins&gt; the prefix tree.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;As a last example, consider the following snippet. The â€œ&lt;a href=&quot;https://dictionary.cambridge.org/dictionary/english/require&quot; title=&quot;Definition of require in the Cambridge Dictionary&quot;&gt;require&lt;/a&gt;â€� verb
accepts a noun or an object followed by a to-infinitive. I canâ€™t use it with
just a to-infinitive.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;An alternative would be to have one prefix tree for each peer but it would
require &lt;del&gt;to configure&lt;/del&gt; &lt;ins&gt;configuring&lt;/ins&gt; all routers to export
their routes.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;As someone who didnâ€™t grow up speaking English, I struggle with these grammar
rules despite reading a lot of English material.&lt;sup id=&quot;fnref-monkey2&quot;&gt;&lt;a class=&quot;footnote-ref&quot; href=&quot;https://vincent.bernat.ch#fn-monkey2&quot;&gt;3&lt;/a&gt;&lt;/sup&gt; French is more
complex to get started but more systematic. English is full of irregularities.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;On each page, I disclose in the footer whether an &lt;abbr title=&quot;Artificial Intelligence&quot;&gt;AI&lt;/abbr&gt; modified the content. There
are three levels:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;ğŸ§ : no &lt;abbr title=&quot;Artificial Intelligence&quot;&gt;AI&lt;/abbr&gt; or almost no &lt;abbr title=&quot;Artificial Intelligence&quot;&gt;AI&lt;/abbr&gt; (e.g., grammar corrections)&lt;/li&gt;
&lt;li&gt;âœ¨: enhanced (e.g., copyediting)&lt;/li&gt;
&lt;li&gt;ğŸ¤–: generated (e.g., translated from another language, even if human-edited)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Hover or tap the icon to reveal the &lt;abbr title=&quot;Artificial Intelligence&quot;&gt;AI&lt;/abbr&gt;â€™s name and its role in the document.&lt;/p&gt;
&lt;figure&gt;&lt;div class=&quot;lf-media-outer&quot; style=&quot;width: 264px;&quot;&gt;&lt;span class=&quot;lf-media-inner&quot;&gt;&lt;img alt=&quot;Screenshot of the footer containing the &amp;quot;sparkles&amp;quot; emoji&quot; class=&quot;lf-media lf-opaque&quot; height=&quot;121&quot; src=&quot;https://d2pzklc15kok91.cloudfront.net/images/ai-usage@1x.03aee3edade4f4.jpg&quot; width=&quot;264&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;figcaption&gt;Example of AI usage disclosure: Claude Sonnetâ€¯4.5 edited this article.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The graph below shows which tool altered each post, year by year. Recently, I
applied the &lt;a href=&quot;https://github.com/vincentbernat/vincent.bernat.ch/blob/latest/.claude/skills/grammar/SKILL.md&quot;&gt;grammar skill&lt;/a&gt; to &lt;a href=&quot;https://github.com/vincentbernat/vincent.bernat.ch/commit/7baf2c8f18b57e351cc25e7e62f4aa6611362c8c&quot; title=&quot;content: fix English grammar&quot;&gt;past articles&lt;/a&gt;. Sinceâ€¯2018,
French articles have been translated with the help of &lt;a href=&quot;https://www.deepl.com&quot;&gt;DeepL&lt;/a&gt; first, then of
an &lt;abbr title=&quot;Large Language Model&quot;&gt;LLM&lt;/abbr&gt;. Sinceâ€¯2024, English articles are copyedited.&lt;/p&gt;
&lt;figure&gt;&lt;div class=&quot;lf-media-outer&quot; style=&quot;width: 733px;&quot;&gt;&lt;span class=&quot;lf-media-inner&quot;&gt;&amp;amp;#128444; Graph showing the AI usage over the years. Each level get its own
color.&lt;/span&gt;&lt;/div&gt;&lt;figcaption&gt;AI usage over the years. Hover or tap a band for the details.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;hr /&gt;
&lt;p&gt;If you are strongly against any usage of &lt;abbr title=&quot;Large Language Models&quot;&gt;LLMs&lt;/abbr&gt; specifically for writing, I hope
you accept my more nuanced position on the usage of these tools as a trade-off
to provide clearer and more engaging articles. Years of literature on improving
English told us it is important to choose the right word to keep the reader
engaged.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;[â€¦] Good writing consists of mastering the fundamentals (vocabulary,
grammar, the elements of style) and then filling the third level of your
toolbox with the right instruments.&lt;/p&gt;
&lt;p&gt;â€• &lt;em&gt;Stephen King&lt;/em&gt;, On Writing&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class=&quot;admonition&quot;&gt;
&lt;p class=&quot;admonition-title&quot;&gt;Note&lt;/p&gt;
&lt;p&gt;Unlike other recent articles, I did not use an &lt;abbr title=&quot;Large Language Model&quot;&gt;LLM&lt;/abbr&gt; to edit this post:
an unnamed person kindly accepted to proofread it. I translated it to French
without using an &lt;abbr title=&quot;Large Language Model&quot;&gt;LLM&lt;/abbr&gt; either.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;admonition&quot;&gt;
&lt;p class=&quot;admonition-title&quot;&gt;Update (2026-06)&lt;/p&gt;
&lt;p&gt;See the &lt;a href=&quot;https://lobste.rs/s/tdvu7a/blogging_with_llm_assistant&quot;&gt;story associated to this post on Lobsters&lt;/a&gt;,
as well as the article â€œ&lt;a href=&quot;https://writethatblog.substack.com/p/dev-reaction-to-ai-blog-posts&quot; title=&quot;Report: How developers react to AI-scented blog posts&quot;&gt;How developers react to &lt;abbr title=&quot;Artificial Intelligence&quot;&gt;AI&lt;/abbr&gt;-scented blog posts&lt;/a&gt;â€� by
Cynthia Dunlop, one of the coauthor of â€œ&lt;a href=&quot;https://www.manning.com/books/writing-for-developers&quot; title=&quot;â€œWriting for Developersâ€� by Piotr Sarna and Cynthia Dunlop&quot;&gt;Writing for Developers&lt;/a&gt;.â€�&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;footnote&quot;&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id=&quot;fn-book&quot;&gt;
&lt;p&gt;I recently read cover to cover â€œ&lt;a href=&quot;https://www.manning.com/books/writing-for-developers&quot; title=&quot;â€œWriting for Developersâ€� by Piotr Sarna and Cynthia Dunlop&quot;&gt;Writing for Developers&lt;/a&gt;â€� and I found
it stimulating. &lt;a href=&quot;https://mtlynch.io/about/&quot;&gt;Michael Lynch&lt;/a&gt; is currently writing â€œ&lt;a href=&quot;https://refactoringenglish.com/&quot; title=&quot;â€œRefactoring English: Effective Writing for Software Developersâ€� by Michael Lynch&quot;&gt;Refactoring
English&lt;/a&gt;â€� on the same topic and I have subscribed to the early access.Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-book&quot; title=&quot;Jump back to footnote 1 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&quot;fn-kagi&quot;&gt;
&lt;p&gt;I am quite happy with the writing tools provided by &lt;a href=&quot;https://www.kagi.com&quot;&gt;Kagi&lt;/a&gt;. Both the
&lt;a href=&quot;https://translate.kagi.com&quot;&gt;translate tool&lt;/a&gt; and the &lt;a href=&quot;https://translate.kagi.com/dictionary&quot;&gt;dictionary&lt;/a&gt; are a valuable help to find
different wordings. I also lean on &lt;a href=&quot;https://help.kagi.com/kagi/ai/kagi-research.html&quot; title=&quot;Kagi Research Assistants&quot;&gt;Kagiâ€™s research assistant&lt;/a&gt; when
researching a topic.Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-kagi&quot; title=&quot;Jump back to footnote 2 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&quot;fn-monkey2&quot;&gt;
&lt;p&gt;When I was ten, I played &lt;em&gt;Monkey Islandâ€¯2&lt;/em&gt; in English without having
taken any classes. I used a dictionary to translate word by word and I found
the irregular verbs confusingâ€”and not in the dictionary.Â &lt;a class=&quot;footnote-backref&quot; href=&quot;https://vincent.bernat.ch#fnref-monkey2&quot; title=&quot;Jump back to footnote 3 in the text&quot;&gt;â†©&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-06-09T20:15:13+00:00</dc:date>
	<dc:creator>Vincent Bernat</dc:creator>
</item> 
<item rdf:about="155 at https://sunweavers.net/blog">
	<title>Mike Gabriel: Voxit 1.0 has been released</title>
	<link>https://sunweavers.net/blog/node/155</link>
     <content:encoded>&lt;h3&gt;Official announcement&lt;/h3&gt;

&lt;p&gt;&lt;em&gt;European Voxit community strengthens digital sovereignty: shared codebase completed.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Read the official announcement at:&lt;br /&gt;
&lt;a href=&quot;https://www.voxit.org/european-voxit-community-strengthens-digital-sovereignty-shared-codebase-completed/&quot; title=&quot;https://www.voxit.org/european-voxit-community-strengthens-digital-sovereignty-shared-codebase-completed/&quot;&gt;https://www.voxit.org/european-voxit-community-strengthens-digital-sover...&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;The Voxit community and platform development&lt;/h3&gt;

&lt;p&gt;The Voxit participation platform is originally based on the open source Polis platform developed by The Computational Democracy Project in the United States, but since its establishment in autumn 2025, the European Voxit community has been developing an independent solution, adapted to European needs.&lt;/p&gt;

&lt;p&gt;The aim is to create an open source, interoperable and scalable participation infrastructure suited to Europe’s regulatory environment and aligned with democratic values. Through this development work, Voxit is becoming a clearly distinct fork of the original Polis platform – allowing Europe to develop participatory infrastructure at its own pace and according to its own governance needs, while the original Polis project continues to break new ground. This enables Europe to build its own open and trustworthy digital democracy tools, rooted in public governance and European democratic traditions.&lt;/p&gt;

&lt;h3&gt;Voxit 1.0 source code is now available&lt;/h3&gt;

&lt;p&gt;The source code for version 1.0 of the European community edition of the Voxit platform has now been published and is openly maintained on GitLab.com at: &lt;a href=&quot;https://gitlab.com/voxit/voxit&quot; title=&quot;https://gitlab.com/voxit/voxit#&quot;&gt;https://gitlab.com/voxit/voxit#&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-09T09:45:00+00:00</dc:date>
	<dc:creator>sunweaver</dc:creator>
</item> 
<item rdf:about="https://anarc.at/blog/2026-05-16-four-horsemen/">
	<title>Antoine Beaupré: The Four Horsemen of the LLM Apocalypse</title>
	<link>https://anarc.at/blog/2026-05-16-four-horsemen/</link>
     <content:encoded>&lt;p&gt;I have been battling Large Language Models (LLM&lt;sup id=&quot;fnref:1&quot;&gt;&lt;a href=&quot;https://anarc.at/tag/debian-planet/#fn:1&quot; rel=&quot;footnote&quot;&gt;1&lt;/a&gt;&lt;/sup&gt;) for the past
couple of weeks and have struggled to think about what it means and
how to deal with its fallout.&lt;/p&gt;

&lt;p&gt;Because the fight has come from many fronts, I&#39;ve come to articulate
this in terms of the &lt;a href=&quot;https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Apocalypse&quot;&gt;Four Horsemen of the Apocalypse&lt;/a&gt;.&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;Sound track: Metallica&#39;s &lt;a href=&quot;https://www.metallica.com/songs/the-four-horsemen.html&quot;&gt;The Four Horsemen&lt;/a&gt;, preferably
&lt;a href=&quot;https://en.wikipedia.org/wiki/Metallica_v._Napster,_Inc.&quot;&gt;downloaded from Napster around 2000&lt;/a&gt;, but now I guess you &lt;a href=&quot;https://www.youtube.com/watch?v=-zKOhVSERS8&quot;&gt;get
it on YouTube&lt;/a&gt;.&lt;/p&gt;&lt;/blockquote&gt;

&lt;h1 id=&quot;war-bot-armies&quot;&gt;War: bot armies&lt;/h1&gt;

&lt;p&gt;Let&#39;s start with War. We&#39;ve been battling bot armies for control of
our GitLab server &lt;a href=&quot;https://gitlab.torproject.org/tpo/tpa/team/-/work_items/42152&quot;&gt;for a while&lt;/a&gt;. Bots crawl virtually infinite
endpoints on our Git repositories (as opposed to downloading an
archive or shallow clone), including our fork of Firefox, Tor Browser,
a massive repository.&lt;/p&gt;

&lt;p&gt;At first, we&#39;ve tried various methods: &lt;a href=&quot;https://www.robotstxt.org/&quot;&gt;robots.txt&lt;/a&gt;, blocking user
agents, and finally blocking entire networks. I &lt;a href=&quot;https://anarc.at/blog/2025-05-30-asncounter/&quot;&gt;wrote
asncounter&lt;/a&gt;. It worked for a while.&lt;/p&gt;

&lt;p&gt;But now, blocking entire networks doesn&#39;t work: they come back some
other way, typically through &lt;a href=&quot;https://acid.vegas/blog/the-shady-world-of-ip-leasing/&quot;&gt;shady proxy networks&lt;/a&gt;, which is kind
of ironic considering we&#39;re essentially running the largest proxy
network of the world.&lt;/p&gt;

&lt;p&gt;Out of desperation, we&#39;ve forced users to &lt;a href=&quot;https://gitlab.torproject.org/tpo/tpa/team/-/wikis/policy/0108-gitlab-cookie-and-javascript-enforcement&quot;&gt;use cookies&lt;/a&gt; when
visiting our site. We haven&#39;t deployed &lt;a href=&quot;https://anubis.techaro.lol/&quot;&gt;Anubis&lt;/a&gt; yet, as we worry
that &lt;a href=&quot;https://social.anoxinon.de/@Codeberg/115033790447125787&quot;&gt;bots have broken Anubis anyways&lt;/a&gt; and that it &lt;a href=&quot;https://lock.cmpxchg8b.com/anubis.html&quot;&gt;does not really
defend against a well-funded attacker&lt;/a&gt;, something which &lt;a href=&quot;https://behind.pretix.eu/2025/05/23/captchas-are-over/&quot;&gt;Pretix
warned against in 2025 already&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;(We have a whole &lt;a href=&quot;https://gitlab.torproject.org/tpo/tpa/team/-/work_items/42229&quot;&gt;discussion regarding those tools here&lt;/a&gt;.)&lt;/p&gt;

&lt;p&gt;But even that, predictably, has failed. I suspect what we consider
bots are now really agents. They run full web browsers, JavaScript
included, so a feeble cookie is no match for the massive bot armies.&lt;/p&gt;

&lt;h2 id=&quot;side-note-on-llm-order-of-battle&quot;&gt;Side note on LLM &quot;order of battle&quot;&lt;/h2&gt;

&lt;p&gt;We often underestimate the size of that army. The cloud was huge even
before LLMs, serving about two thirds of the web. Even larger swaths of
clients like government and corporate databases have all moved to the
cloud, in shared, but private infrastructure with massive spare
capacity that is readily available to anyone who pays.&lt;/p&gt;

&lt;p&gt;LLMs have made the problem worse by dramatically expanding the
capacity of the &quot;cloud&quot;. We now have data centers that defy
imagination with &lt;a href=&quot;https://epoch.ai/data/data-centers&quot;&gt;millions of cores&lt;/a&gt;, petabytes of memory, exabytes
of storage.&lt;/p&gt;

&lt;p&gt;I thought that &lt;a href=&quot;https://sschueller.github.io/posts/the-free-market-lie/&quot;&gt;25 gigabit residential internet in Switzerland&lt;/a&gt;
could bring balance, but this is nothing compared to the scale of
those data centers.&lt;/p&gt;

&lt;p&gt;Those companies can launch thousands, if not millions of fully
functional web browsers at our servers. Computing power or bandwidth
are not a limitation for them, our primitive infrastructure is. No one
but hyperscalers can deal with this kind of load, and I suspect that
they are also struggling, as even &lt;a href=&quot;https://www.androidauthority.com/google-recaptcha-play-services-requirement-3664806/&quot;&gt;Google is deploying extreme
mechanisms in reCAPTCHA&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;This is the largest attack on the internet since the &lt;a href=&quot;https://en.wikipedia.org/wiki/Morris_worm&quot;&gt;Morris
worm&lt;/a&gt; but while &lt;a href=&quot;https://en.wikipedia.org/wiki/Robert_Tappan_Morris&quot;&gt;Robert Tappan Morris&lt;/a&gt; went to jail on a felony,
LLM companies are celebrated as innovators and will soon be too big to
fail.&lt;sup id=&quot;fnref:2&quot;&gt;&lt;a href=&quot;https://anarc.at/tag/debian-planet/#fn:2&quot; rel=&quot;footnote&quot;&gt;2&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Which brings us to the second horsemen, famine.&lt;/p&gt;

&lt;h1 id=&quot;famine-shortages&quot;&gt;Famine: shortages&lt;/h1&gt;

&lt;p&gt;All that computing power doesn&#39;t come out of thin air: it needs
massive amounts of hardware, power, and cooling.&lt;/p&gt;

&lt;p&gt;Earlier this year, I&#39;ve heard from a colleague that their Dell
supplier refused to even provide a &lt;em&gt;quote&lt;/em&gt; before August. Dell!&lt;/p&gt;

&lt;p&gt;In February, &lt;a href=&quot;https://www.techspot.com/news/111346-western-digital-hdd-production-capacity-2026-already-sold.html&quot;&gt;Western Digital&#39;s hard drive production for 2026 was
already sold out&lt;/a&gt;. Hard drives essentially &lt;a href=&quot;https://gitlab.torproject.org/tpo/tpa/team/-/work_items/42465&quot;&gt;doubled in price within
a year&lt;/a&gt;, and some have now tripled. A server quote we had in
November has now &lt;em&gt;quadrupled&lt;/em&gt;, going from 10 thousand to &lt;em&gt;FORTY&lt;/em&gt;
thousand dollars for a single server.&lt;/p&gt;

&lt;p&gt;But regular folks are facing real-life shortages as well, as
&lt;a href=&quot;https://www.theguardian.com/us-news/2026/may/13/utah-approves-datacenter-backlash&quot;&gt;city-size data centers&lt;/a&gt; are being built at neck-breaking speed,
stealing fresh water and energy from human beings to feed the war
machine.&lt;/p&gt;

&lt;p&gt;We&#39;ve been scared of losing our jobs, but it seems that Apocalypse has
yet to fully materialize. Regardless for engineers, the market feels
tighter than it was a couple years ago, and everyone feels on edge
that they will just have to learn to operate LLMs to keep their jobs.&lt;/p&gt;

&lt;p&gt;Update: it turns out I was clearly too optimistic. Cisco is laying
off 4,000 or 5% of its staff in a &lt;a href=&quot;https://blogs.cisco.com/news/our-path-forward&quot;&gt;jolly announcement celebrating
a record $15.8 billion revenue&lt;/a&gt;, and Meta will &lt;a href=&quot;https://www.nytimes.com/2026/04/23/technology/meta-layoffs.html&quot;&gt;lay off 8,000 or
10% of its workforce&lt;/a&gt;, in &lt;a href=&quot;https://sfstandard.com/pacific-standard-time/2026/05/15/meta-employee-gets-real-horror-working-right-now/&quot;&gt;horrifying conditions&lt;/a&gt;. See also the
&lt;a href=&quot;https://jobloss.ai/&quot;&gt;jobloss.ai tracker&lt;/a&gt; which counts 125,000 jobs lost since January
2025, as of May 2026.&lt;/p&gt;

&lt;p&gt;Which brings us, of course, to Death.&lt;/p&gt;

&lt;h1 id=&quot;death-security-and-copyright&quot;&gt;Death: security and copyright&lt;/h1&gt;

&lt;p&gt;Our third horseman is one I did &lt;em&gt;not&lt;/em&gt; expect a couple of months
ago. Back at FOSDEM, &lt;code&gt;curl&lt;/code&gt;&#39;s maintainer Daniel Stenberg famously
&lt;a href=&quot;https://lwn.net/Articles/1058266/&quot;&gt;complained about the poor quality of LLM-generated reports&lt;/a&gt; but
then, a few months later, everyone is &lt;a href=&quot;https://lwn.net/Articles/1066581/&quot;&gt;scrambling to deal with floods
of good reports&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;In the past two weeks, this culminated in a significant number of
critical security issues across multiple projects. Chained
together, remote code execution vulnerabilities in &lt;a href=&quot;https://depthfirst.com/nginx-rift&quot;&gt;Nginx&lt;/a&gt; and
&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-23918&quot;&gt;Apache&lt;/a&gt; and &lt;em&gt;two&lt;/em&gt; local privilege escalations in the Linux kernel
(&lt;a href=&quot;https://github.com/V4bel/dirtyfrag/&quot;&gt;dirtyfrag&lt;/a&gt; and &lt;a href=&quot;https://github.com/v12-security/pocs/tree/main/fragnesia#fragnesia&quot;&gt;fragnesia&lt;/a&gt;) essentially gave anyone root access to any unpatched server to the web.&lt;/p&gt;

&lt;p&gt;As I write this, &lt;a href=&quot;https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn&quot;&gt;another vulnerability dropped&lt;/a&gt;, which gives read
access to any file to a local user, compromising TLS and SSH private
keys.&lt;/p&gt;

&lt;p&gt;All those vulnerabilities were released without any significant
coordination while people scrambled to mitigate.&lt;/p&gt;

&lt;p&gt;Many people &lt;a href=&quot;https://lwn.net/Articles/1072007/#Comments&quot;&gt;including Linus Torvalds&lt;/a&gt; are now considering issues
discovered through LLMs to be essentially public. This puts &lt;a href=&quot;https://lwn.net/Articles/1071499/&quot;&gt;some
debates about disclosure processes&lt;/a&gt; in perspective, to say the
least.&lt;/p&gt;

&lt;p&gt;But this is not merely the death of the traditional coordinated disclosure
process, the C programming language, or the Linux kernel: remember
that those bots are trained on a large corpus of copyrighted
material. Facebook has &lt;a href=&quot;https://www.theguardian.com/technology/2025/jan/10/mark-zuckerberg-meta-books-ai-models-sarah-silverman&quot;&gt;trained their models on pirated books&lt;/a&gt; and
&lt;a href=&quot;https://torrentfreak.com/nvidia-contacted-annas-archive-to-secure-access-to-millions-of-pirated-books/&quot;&gt;Nvidia has done deals with Anna&#39;s Archive&lt;/a&gt; to secure access to
large swaths of copyrighted material. The &lt;a href=&quot;https://www.congress.gov/crs-product/LSB10922&quot;&gt;US Congress seems to think
LLM outputs are not copyrightable&lt;/a&gt;, like any other machine outputs.&lt;/p&gt;

&lt;p&gt;With many people now vibe coding their way out of learning or
remembering how computers work, is this the Death of Copyright?&lt;/p&gt;

&lt;p&gt;And that, of course, brings us to the final horseman: Pestilence.&lt;/p&gt;

&lt;h1 id=&quot;pestilence-slop&quot;&gt;Pestilence: slop&lt;/h1&gt;

&lt;p&gt;There is a growing meme that programming is essentially over as we
know it. That you can simply vibe-code applications from scratch and
it&#39;s pretty good.&lt;/p&gt;

&lt;p&gt;Maybe that&#39;s true.&lt;/p&gt;

&lt;p&gt;So far, most of my attempts at resolving any complex problem with a
LLM have often failed with bizarre failures. &lt;a href=&quot;https://gitlab.com/anarcat/scripts/-/blob/main/transmodify.py?ref_type=heads&quot;&gt;Some worked surprisingly
well.&lt;/a&gt; Maybe, of course, I am holding it wrong.&lt;/p&gt;

&lt;p&gt;I personally don&#39;t believe LLMs will ever be good enough to produce
and maintain software at scale. They&#39;re surprisingly good at finding
security flaws right now. But what I see is also a lot of
&lt;a href=&quot;https://en.wikipedia.org/wiki/Bullshit&quot;&gt;Bullshit&lt;/a&gt;, with a capital B. It&#39;s not lying: it does not &quot;know&quot;
anything, so it &lt;em&gt;can&#39;t&lt;/em&gt; lie. It&#39;s misleadingly cohesive and
deliberate, but it lacks meaning, intent, will.&lt;/p&gt;

&lt;p&gt;I have not been confronted with much slop, apart from the lobster
Jesus or the yellow man atrocities, and particularly not in my
work. But I see what it is doing to my profession: beyond
&lt;a href=&quot;https://en.wikipedia.org/wiki/Vibe_coding&quot;&gt;vibe-coding&lt;/a&gt;, people are now &lt;a href=&quot;https://www.forbes.com/sites/timkeary/2026/04/13/is-the-cult-of-tokenmaxxingjust-another-fad-or-the-new-normal/&quot;&gt;token-maxxing&lt;/a&gt;, and
&lt;a href=&quot;https://leehanchung.github.io/blogs/2026/04/05/the-ai-great-leap-forward/#let-a-hundred-skills-bloom&quot;&gt;land-grabbing their colleagues&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;I don&#39;t like what LLMs do to our communities, or the fabric of
software we live with.&lt;/p&gt;

&lt;p&gt;Software does not evolve in a void. It is a team effort, be it free
software or a corporate product. Generations of humans have carefully
built the scaffolding of technology required for modern networks and
software to operate, in a convoluted contraption that no single human
fully understands anymore.&lt;/p&gt;

&lt;p&gt;The idea of simply giving up on that understanding entirely and
delegating it to an unproven model is not only chilling, it feels just
plain stupid. Not stupid as in &lt;a href=&quot;https://en.wikipedia.org/wiki/Skynet_(Terminator)&quot;&gt;Skynet&lt;/a&gt;, stupid as in &quot;I can&#39;t get
inside the data center because the authentication system is
down&quot;. Except we&#39;re in a &quot;the power plant doesn&#39;t reboot&quot; or &quot;their
LLM found an 0day in our slop&quot; kind of stupid.&lt;/p&gt;

&lt;h1 id=&quot;the-fifth-horsemen&quot;&gt;The fifth horsemen&lt;/h1&gt;

&lt;p&gt;Researching for this article, I looked up the four horsemen and found
out they original seems to have been:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Famine&lt;/li&gt;
&lt;li&gt;War&lt;/li&gt;
&lt;li&gt;Death&lt;/li&gt;
&lt;li&gt;Conquest (??)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;I was surprised. I grew up thinking about the horsemen being Famine,
War, Pestilence, and Death. So I went back to &lt;a href=&quot;https://www.metallica.com/songs/the-four-horsemen.html&quot;&gt;my original source&lt;/a&gt;
which actually claims the horsemen are:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;Time has taken its toll on you, the lines that crack your face.
Famine, your body, it has torn through, withered in every place.
Pestilence for what you&#39;ve had to endure, and what you have put others through
Death, deliverance for you, for sure, now there&#39;s nothing you can do
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;So I guess that makes no sense either, which, fair enough, I shouldn&#39;t
rely on Metallica for theological references. Especially since that
song was originally called &lt;a href=&quot;https://en.wikipedia.org/wiki/Mechanix&quot;&gt;Mechanix&lt;/a&gt; and was &quot;about having sex at
a gas station&quot;.&lt;/p&gt;

&lt;p&gt;Anyways.&lt;/p&gt;

&lt;p&gt;The point is, there are actually five horsemen, and the fifth one is,
in my opinion, Conquest.&lt;/p&gt;

&lt;p&gt;Those companies (and &lt;em&gt;not&lt;/em&gt; &quot;AI&quot;, mind you) are taking over the
world. I sense a strong connection with the &quot;post-truth&quot; world imposed
on us by fascists like Trump and Putin. It&#39;s not an accident, it&#39;s a
power grab part of the &lt;a href=&quot;https://en.wikipedia.org/wiki/The_Californian_Ideology&quot;&gt;Californian Ideology&lt;/a&gt;&lt;sup id=&quot;fnref:3&quot;&gt;&lt;a href=&quot;https://anarc.at/tag/debian-planet/#fn:3&quot; rel=&quot;footnote&quot;&gt;3&lt;/a&gt;&lt;/sup&gt;. Just like Airbnb
broke housing, Uber destroyed the transportation and Amazon is taking
over retail and server hosting, LLM companies are essentially trying
to take over if not everything, at least &lt;a href=&quot;https://en.wikipedia.org/wiki/Cognition&quot;&gt;Cognition&lt;/a&gt; as a whole.&lt;/p&gt;

&lt;p&gt;But the capitalization of those companies (OpenAI and Nvidia in particular)
are so far beyond reason that their inevitable collapse will likely
lead to a global financial collapse of biblical proportions.&lt;/p&gt;

&lt;p&gt;Because they will inevitably fail like previous bubbles they are built
on. And when they fail, I hope it zips all the way back through the
blockchain scam, the ad surveillance system, and the dot com then git
me back my internet.&lt;/p&gt;

&lt;h1 id=&quot;the-tower-of-babel&quot;&gt;The Tower of Babel&lt;/h1&gt;

&lt;p&gt;While I&#39;m off in the woods hallucinating (ha!) on biblical allegories,
I feel there&#39;s another sign that the apocalypse is coming.&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://en.wikipedia.org/wiki/Tower_of_Babel&quot;&gt;Tower of Babel&lt;/a&gt; myth says that humans tried to create a big
tower up to heaven and become god. God confounds their speech and
scatters the human race. End of utopia.&lt;/p&gt;

&lt;p&gt;This is what is happening to our human translators now. LLMs being,
after all, Language Models, they are excellent at translation work. So
much that the only translators not replaced by LLMs right now are
&lt;a href=&quot;https://en.wikipedia.org/wiki/Language_interpretation&quot;&gt;interpreters&lt;/a&gt;, who translate vocally in real time. But
interpreters are worried about their jobs as well.&lt;/p&gt;

&lt;p&gt;This concretely means we will lose the human capacity, as a
civilization, to translate between each other. It is still an &lt;a href=&quot;https://revues.imist.ma/index.php/JALCS/article/view/59018&quot;&gt;open
question&lt;/a&gt; whether the remaining revision work will be enough for
translators to avoid deskilling, but other research has shown that LLM
use &lt;a href=&quot;https://publichealthpolicyjournal.com/mit-study-finds-artificial-intelligence-use-reprograms-the-brain-leading-to-cognitive-decline/&quot;&gt;leads to cognitive decline&lt;/a&gt;, &lt;a href=&quot;https://dl.acm.org/doi/full/10.1145/3706598.3713778&quot;&gt;impacts critical thinking&lt;/a&gt;,
and generally, that &lt;a href=&quot;https://publicera.kb.se/ir/article/view/47143&quot;&gt;deskilling is a common outcome&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Ultimately, I think this is where LLMs bring us. Towards collapse.&lt;/p&gt;

&lt;p&gt;So this is a call to arms. Fight back!&lt;/p&gt;

&lt;p&gt;Poison bots. Build local real-world communities.&lt;/p&gt;

&lt;p&gt;Go low tech. &lt;a href=&quot;https://en.wikipedia.org/wiki/Moore%27s_law&quot;&gt;Moore&#39;s law&lt;/a&gt; is dead, &lt;a href=&quot;https://spectrum.ieee.org/the-death-of-moores-law-will-spur-innovation&quot;&gt;make use of it&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Patch your shit. &lt;a href=&quot;https://anginedepoitrine.com/&quot;&gt;Go weird&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Refuse slop. Train your brain. &lt;a href=&quot;https://github.com/leilei926524-tech/anti-distill&quot;&gt;Refuse distillation&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The horsemen will collapse, but let&#39;s not go down with them.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://dune.fandom.com/wiki/Butlerian_Jihad&quot;&gt;Butlerian Jihad&lt;/a&gt;!&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;This article was written without the use of a large language model
and should not be used to train one.&lt;/p&gt;&lt;/blockquote&gt;

&lt;h1 id=&quot;updates&quot;&gt;Updates&lt;/h1&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;A paragraph was added about the job apocalypse, which was of course
under-estimate.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.tumblr.com/dreaminginthedeepsouth/817865966907228160/darren-oconnor-timnit-gebru-was-fired-from&quot;&gt;Why Timnit Gebru was fired&lt;/a&gt; is extremely important and
interesting. The co-lead of the Ethical AI team at Google was fired
because they blew the whistle on &quot;stochastic parrots&quot; essentially
destroying the world as we know it:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;The fifth warning was the one Google cared about most. [...]&lt;/p&gt;

&lt;p&gt;The internet would become a place where the dominant voice was a
statistical average of dominant voices, presented as a neutral
assistant.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;The warnings from the paper are eerily similar to my horsemen:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;predicted the hallucination (pestilence)&lt;/li&gt;
&lt;li&gt;bias amplification (war?)&lt;/li&gt;
&lt;li&gt;environmental cost (famine)&lt;/li&gt;
&lt;li&gt;un-auditable training corpus (death?)&lt;/li&gt;
&lt;li&gt;&quot;centralize linguistic and cultural power in the hands of the
small number of companies&quot; (conquest)&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;See also Tim Wu&#39;s &quot;The Master Switch&quot; &lt;a href=&quot;https://scoat.es/@sean/116698778802881078&quot;&gt;which says&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;The industry learned how to secure the enactment of seemingly
innocuous and sensible regulations that nonetheless spelled doom
for any rival.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;People claim &lt;a href=&quot;https://cyberplace.social/@GossiTheDog/116698461313896106&quot;&gt;the same about Anthropic&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;






&lt;div class=&quot;footnotes&quot;&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id=&quot;fn:1&quot;&gt;
I prefer &quot;LLM&quot; to Artificial Intelligence, as I don&#39;t consider
models to have &quot;Intelligence&quot; which goes far beyond the analytical
traits we train models for. Intelligence &lt;em&gt;requires&lt;/em&gt; embodiment
and social interaction; machines lack the innate human skills of
empathy, feeling and care, which explains a lot of the evils
behind the current trends.&lt;a href=&quot;https://anarc.at/tag/debian-planet/#fnref:1&quot; rev=&quot;footnote&quot;&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn:2&quot;&gt;
It should be noted that Morris also happened to be one of the
founder of &lt;a href=&quot;https://en.wikipedia.org/wiki/Y_Combinator&quot;&gt;Y Combinator&lt;/a&gt; where he is in good company with
other techno-fascists like Peter Thiel, Sam Altman, and so
on. Crime, after all, pays.&lt;a href=&quot;https://anarc.at/tag/debian-planet/#fnref:2&quot; rev=&quot;footnote&quot;&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn:3&quot;&gt;
Probably a good time to watch &lt;a href=&quot;https://en.wikipedia.org/wiki/All_Watched_Over_by_Machines_of_Loving_Grace_(TV_series)&quot;&gt;All Watched Over by Machines of Loving Grace&lt;/a&gt;.&lt;a href=&quot;https://anarc.at/tag/debian-planet/#fnref:3&quot; rev=&quot;footnote&quot;&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-06-09T00:47:33+00:00</dc:date>
	<dc:creator>Antoine Beaupré</dc:creator>
</item> 
<item rdf:about="http://blog.sesse.net/blog/tech/2026-06-07-09-51_hyperpersonal_open_source.html">
	<title>Steinar H. Gunderson: Hyperpersonal open source</title>
	<link>http://blog.sesse.net/blog/tech/2026-06-07-09-51_hyperpersonal_open_source.html</link>
     <content:encoded>&lt;p&gt;A while back, I got my first subwoofer (a surprisingly nice addition to
the movie experience, just like rear speakers were). But I live in an
apartment, and I don&#39;t want to annoy my neighbors at night (the speaker
cone points literally down into the floor, and I have no idea how much
my neighbors get to share in my enjoyment). So, what to do?&lt;/p&gt;

&lt;p&gt;It turns out my receiver supports &lt;a href=&quot;https://assets.denon.com/documentmaster/uk/avr1713_avr1613_protocol_v860.pdf&quot;&gt;a sort-of documented serial protocol&lt;/a&gt;;
it doesn&#39;t have an actual serial port, but you can telnet into it
(only one session at a time!) and get the same two-way stream.
(It also has a HTTP version which I find less useful.) So this allows
me to impose my own policy, and of course, doing it via an existing
Home Assistant adapter or something was no fun and also thoroughly
frustrating, so I saw it as an opportunity to keep maintaining my low-key Rust skills.
(No, no LLM code generation. If I&#39;m going to spend time on this, at least I
can learn something myself. I think I asked one for code critique at some
point, but I can&#39;t remember.)&lt;/p&gt;

&lt;p&gt;The policy is roughly: If I&#39;m watching TV after 22:00, then the subwoofer
is either turned off (if possible) or turned down -12 dB (the maximum).
But if I&#39;m watching a Blu-ray or another input like that, that&#39;s presumably
a conscious tradeoff I&#39;ve made and things are left at normal. Everything
gets a bit more complicated by the fact that the receiver tends to lose
state when doing certain switches, and when it boots, it takes a minute
or two before Telnet responds, and when it shuts down, it goes into this
weird limbo state where it doesn&#39;t respond to anything but the TCP connection
&lt;em&gt;seems&lt;/em&gt; still up.&lt;/p&gt;

&lt;p&gt;And then I figured out I also wanted to dim the display when watching
movies (again, only certain inputs), but not for a couple of seconds
after making any adjustments. And after doing that, I figured that my
access point LED should also be turned off, which happens to be some
SNMP writable stuff against the Cisco wireless controller it hangs on.&lt;/p&gt;

&lt;p&gt;So, if you have a Denon or Marantz AVR, a Cisco access point on a controller,
and my exact preferences about what to do about the subwoofer, then you
are free to download and use &lt;a href=&quot;https://git.sesse.net/?p=denon-subwoofer-control;a=summary&quot;&gt;my software&lt;/a&gt;
to impose that policy. It is “is distributed in the hope that it will be
useful”, as one says. If you have IPv6.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-07T08:51:00+00:00</dc:date>
	<dc:creator>Steinar H. Gunderson</dc:creator>
</item> 
<item rdf:about="http://blog.alteholz.eu/?p=2823">
	<title>Thorsten Alteholz: My Debian Activities in May 2026</title>
	<link>http://blog.alteholz.eu/2026/06/my-debian-activities-in-may-2026/</link>
     <content:encoded>&lt;h3&gt;&lt;strong&gt;Debian LTS/ELTS&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This was my hundred-forty-third month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
&lt;/p&gt;
&lt;p&gt;
During my allocated time I uploaded or worked on:  
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/05/msg00024.html&quot;&gt;DLA 4580-1&lt;/a&gt;]  exim4 security update to fix one CVE related to remote code execution.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/05/msg00036.html&quot;&gt;DLA 4591-1&lt;/a&gt;] rsync security update to fix five CVEs related to local root privilege escalation.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1134340&quot;&gt;#1134340&lt;/a&gt;] trixie-pu bug for libcoap3 to fix two CVEs in Trixie; the debdiff was confirmed and the upload was accepted to the &lt;a href=&quot;https://tracker.debian.org/news/1748400/accepted-libcoap3-434-11deb13u3-source-into-proposed-updates/&quot;&gt;proposed update queue.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1126167&quot;&gt;#1126167&lt;/a&gt;] bookworm-pu upload of zvbi has been flagged for &lt;a href=&quot;https://tracker.debian.org/news/1748000/accepted-zvbi-0241-1deb12u1-source-into-oldstable-proposed-updates/&quot;&gt;acceptance&lt;/a&gt;&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1126273&quot;&gt;#1126273&lt;/a&gt;] bookworm-pu upload of taglib has been flagged for &lt;a href=&quot;https://tracker.debian.org/news/1747995/accepted-taglib-113-2deb12u1-source-into-oldstable-proposed-updates/&quot;&gt;acceptance&lt;/a&gt;&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1126370&quot;&gt;#1126370&lt;/a&gt;] bookworm-pu upload of libuev has been flagged for &lt;a href=&quot;https://tracker.debian.org/news/1747984/accepted-libuev-240-11deb12u1-source-into-oldstable-proposed-updates/&quot;&gt;acceptance&lt;/a&gt;&lt;/li&gt;&lt;li&gt;[hplip] upload to sid to fix two CVEs. &lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;
This was a rather strange month. The details about the embargoed &lt;i&gt;exim4&lt;/i&gt; issue arrived only after I already went to bed and the embargo lift was 18 hours later. Luckily Stretch was not really affected and the uploads for Bullseye and Buster went out on time.
&lt;/p&gt;



&lt;p&gt;
Something similar happened with the embargoed issue of &lt;i&gt;rsync&lt;/i&gt;. The info arrived at 8:00 in the morning and the embargo lift was on 2:00 next morning. From an Europeans point of view, the Australians do have strange time zones. But there is more to this than that. Upstream sent more than 50(!) patches for these five CVEs that needed a backport to Bullseye. As things turned out, there is a regression in the upload to Unstable and investigations are ongoing whether this regression is also available in the backported patches for Trixie, Bookworm and Bullseye. So &lt;i&gt;rsync&lt;/i&gt;-updates for Buster and Stretch is in the works, but I am afraid they need some more time.
&lt;/p&gt;



&lt;p&gt;
All good things come by threes. Two critical CVEs of &lt;i&gt;hplip&lt;/i&gt; appeared and a new upstream version was released by HP. HP is no longer interested in working with distributions and over time more than 80 patches have been accumulated that need a rebase for a new upstream version. For that reason I avoid this package as much as I can, but two critical CVEs did apply some kind of pressure on the maintainer. So I finally managed to do this update and the latest version of &lt;i&gt;hplip&lt;/i&gt; is now in Debian. Nevertheless, this feels good :-). Anyway, it is not over yet. HP does not have a public repository nor do they publish patches for these CVEs. So I am still searching for the correct fixes to backport them to Bullseye, Buster and Stretch. The other distributions have the same problem and a silver lining appears on the horizon.
&lt;/p&gt;



&lt;p&gt;I also prepared an update of &lt;i&gt;gimp&lt;/i&gt; for Buster and Stretch, but due to an accident I only managed to release the corresponing ELA in June. The accident was also the reason for only half a week of FD. Thanks to Daniel who took over.&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Printing&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream versions:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/lprng&quot;&gt;lprng&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/epson-inkjet-printer-escpr&quot;&gt;epson-inkjet-printer-escpr&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/hplip&quot;&gt;hplip&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://www.freexian.com&quot;&gt;Freexian&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Lomiri&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This month I continued to work on unifying packaging on Debian and Ubuntu. This makes it easier to work on those packages independent of the used platform. &lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://freiesoftware.gmbh/&quot;&gt;Fre(i)e Software GmbH&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Astro&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/supernovas&quot;&gt;supernovas&lt;/a&gt; to unstable (sponsored upload).&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/virtualgps&quot;&gt;virtualgps&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/nautic&quot;&gt;nautic&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;Debian IoT&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/pyicloud&quot;&gt;pyicloud&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;misc&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/visam&quot;&gt;visam&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/tntdb&quot;&gt;tntdb&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/ae56&quot;&gt;ae56&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/texify&quot;&gt;texify&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/chktex&quot;&gt;chktex&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/ta-lib&quot;&gt;ta-lib&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;I also got rid of &lt;i&gt;gypsy&lt;/i&gt;, which no longer makes sense to maintain in Debian, as &lt;i&gt;gpsd&lt;/i&gt; is way better.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-07T07:15:40+00:00</dc:date>
	<dc:creator>alteholz</dc:creator>
</item> 
<item rdf:about="https://blog.einval.com/2026/06/05#secure_boot_ca_rollover_docs">
	<title>Steve McIntyre: Secure Boot and Microsoft CA Rollover - user-facing documentation</title>
	<link>https://blog.einval.com/2026/06/05#secure_boot_ca_rollover_docs</link>
     <content:encoded>&lt;p&gt;I previously
wrote &lt;a href=&quot;https://blog.einval.com/2026/05/22#secure_boot_ca_rollover&quot;&gt;some
advice&lt;/a&gt; for developers and distributions about the upcoming
Microsoft CA Rollover, and I hope that was useful for people.&lt;/p&gt;

&lt;p&gt;I&#39;ve now also added some user-facing documentation about the CA
rollover in the Debian wiki
at &lt;a href=&quot;https://wiki.debian.org/SecureBoot/CAChanges&quot;&gt;https://wiki.debian.org/SecureBoot/CAChanges&lt;/a&gt;. I&#39;ve
added guidance on managing certificate updates on Debian systems: how
to check if a system needs those updates and various ways to make them
happen. If you&#39;re running Secure Boot systems, this may be important
for you.&lt;/p&gt;

&lt;p&gt;While the same event is the primary cause for these docs, they&#39;re
designed for different people. Again, I hope this new doc is
helpful!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-05T17:20:00+00:00</dc:date>
	<dc:creator>Steve McIntyre</dc:creator>
</item> 
<item rdf:about="https://bisco.org/notes/status-update-may-2026/">
	<title>Birger Schacht: Status update, May 2026</title>
	<link>https://bisco.org/notes/status-update-may-2026/</link>
     <content:encoded>&lt;h1 id=&quot;debian-related-work&quot;&gt;Debian Related Work&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;Uploaded labwc 0.9.7-1 to unstable;
labwc 0.20 was released upstream since then, but it requires wlroots 0.20.1
which has not landed in Debian yet&lt;/li&gt;
&lt;li&gt;Uploaded usbguard 1.1.4+ds-3 &amp;amp; 1.1.4+ds-4: cleaned up the packaging and
fixed some long standing issues with the configuration; the legacy permission
system isn’t the default anymore&lt;/li&gt;
&lt;li&gt;Uploaded foot 1.27.0-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded scdoc 1.11.4-2 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded cage 0.3.0-2 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded sway 1.12~rc3-2 to unstable; on the same day sway 1.12 was released
and I uploaded 1.12-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded swayimg 5.2-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded git-quick-stats 2.11.0-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded grim 1.5.0+ds-1 to unstable&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;dh-related-work&quot;&gt;DH Related Work&lt;/h1&gt;
&lt;p&gt;A big chunk of my DH related work went into designing &amp;amp; implementing a search
app for the &lt;a href=&quot;https://github.com/acdh-oeaw/apis-core-rdf&quot;&gt;APIS&lt;/a&gt; framework. Our
goal is to have a way of searching over various types of Django models. The app
introduces a search model that indexes all registered models. We use a
combination of &lt;a href=&quot;https://docs.djangoproject.com/en/6.0/ref/contrib/postgres/search/&quot;&gt;PostgreSQLs full text
search&lt;/a&gt; and
Trigram Similarity to find the search results. Using a
&lt;a href=&quot;https://docs.djangoproject.com/en/6.0/ref/contrib/postgres/search/#searchvectorfield&quot;&gt;SearchVectorField&lt;/a&gt;
and GinIndices for the trigram indexed fields we can reach a somewhat
acceptable performance.&lt;/p&gt;
&lt;p&gt;We released versions 0.63 and 0.64 of the APIS framework. The 0.63 release
introduced the new &lt;code&gt;entities&lt;/code&gt; app, which will soon hopefully replace the legacy
&lt;code&gt;apis_entities&lt;/code&gt; &amp;amp; &lt;code&gt;apis_metainfo&lt;/code&gt; modules. Version 0.64 moved some logic from
the legacy modules the &lt;code&gt;entities&lt;/code&gt; module.&lt;/p&gt;
&lt;p&gt;We made some progress in defining the endpoints for the
&lt;a href=&quot;https://www.oeaw.ac.at/de/acdh/forschung/dh-forschung-infrastruktur/aktivitaeten/dh-datenmodellierung/pfp-prosopographische-plattform-oesterreich&quot;&gt;PFP&lt;/a&gt;
API.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-05T05:28:51+00:00</dc:date>
	<dc:creator>Birger Schacht</dc:creator>
</item> 
<item rdf:about="https://reproducible-builds.org/reports/2026-05/">
	<title>Reproducible Builds: Reproducible Builds in May 2026</title>
	<link>https://reproducible-builds.org/reports/2026-05/</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://reproducible-builds.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/reproducible-builds.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p class=&quot;lead&quot;&gt;&lt;strong&gt;Welcome to the May 2026 report from the &lt;a href=&quot;https://reproducible-builds.org&quot;&gt;Reproducible Builds&lt;/a&gt; project.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;These reports outline what we’ve been up to over the past month, highlighting items of news from elsewhere in the increasingly-important area of software supply-chain security. As ever, if you are interested in contributing to the Reproducible Builds project, please see the &lt;a href=&quot;https://reproducible-builds.org/contribute/&quot;&gt;&lt;em&gt;Contribute&lt;/em&gt;&lt;/a&gt; page on our website.&lt;/p&gt;

&lt;p&gt;In this month’s report, we cover:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#debian-to-ship-reproducible-packages-in-forky-and-beyond&quot;&gt;Debian to ship reproducible packages in &lt;em&gt;forky&lt;/em&gt; and beyond&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#holger-levsen-on-reproducing-official-debian-packages&quot;&gt;Holger Levsen on reproducing official Debian packages&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#reproducible-builds-2026-summit-to-be-held-in-gothenburg-sweden&quot;&gt;Reproducible Builds 2026 summit to be held in Gothenburg, Sweden&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#kettle-attested-builds-for-verifiable-software&quot;&gt;&lt;em&gt;Kettle: Attested Builds for Verifiable Software&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#new-rebuilderd-version-announced&quot;&gt;New &lt;em&gt;rebuilderd&lt;/em&gt; version announced&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#reproducible-open-source-messengers&quot;&gt;Reproducible open source messengers&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#distribution-work&quot;&gt;Distribution work&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#misc-news&quot;&gt;Misc news&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#patches&quot;&gt;Patches&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#documentation-updates&quot;&gt;Documentation updates&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;debian-to-ship-reproducible-packages-in-forky-and-beyond&quot;&gt;Debian to ship reproducible packages in &lt;em&gt;forky&lt;/em&gt; and beyond&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://lists.debian.org/debian-devel-announce/2026/05/msg00001.html&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/debian-lg.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In a huge change in Debian’s reproducibility policy, the &lt;a href=&quot;https://lists.debian.org/debian-devel-announce/2026/05/msg00001.html&quot;&gt;Debian Release Team announced that&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;… we’ve decided it’s time to say that &lt;strong&gt;Debian must ship reproducible packages&lt;/strong&gt;. Since yesterday, we have enabled our migration software to block migration of new packages that can’t be reproduced [on &lt;a href=&quot;https://reproducible-builds.org/blog/on https://reproduce.debian.net/&quot;&gt;&lt;em&gt;reproduce.debian.net&lt;/em&gt;&lt;/a&gt;] or existing packages in &lt;em&gt;testing&lt;/em&gt; that regress in reproducibility.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is to say, if newly-uploaded packages are not reproducible, they won’t be considered candidates for inclusion in the next stable release of Debian codenamed &lt;em&gt;forky&lt;/em&gt;. (&lt;a href=&quot;https://lists.debian.org/debian-devel/2026/05/msg00383.html&quot;&gt;Some exceptions may be granted&lt;/a&gt;.)&lt;/p&gt;

&lt;p&gt;This news generated a number of articles and comments in various news outlets:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Linux Weekly News (LWN): &lt;a href=&quot;https://lwn.net/Articles/1072314/&quot;&gt;&lt;em&gt;Debian to require reproducible builds&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;Phoronix: &lt;a href=&quot;https://www.phoronix.com/news/Debian-Must-Ship-Reproducible&quot;&gt;&lt;em&gt;Debian Release Team: Debian Must Now Ship Reproducible Packages&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;The Register: &lt;a href=&quot;https://www.theregister.com/oses/2026/05/11/debian-14-cracks-down-on-unreproducible-packages/5238094&quot;&gt;&lt;em&gt;Debian 14 cracks down on unreproducible packages&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;LinuxSecurity.com: &lt;a href=&quot;https://linuxsecurity.com/features/debian-reproducible-builds&quot;&gt;&lt;em&gt;Debian 14 Makes Reproducible Builds Mandatory for Linux Packages&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;Heise.de: &lt;a href=&quot;https://www.heise.de/news/Debian-14-Reproduzierbare-Builds-werden-zur-Pflicht-11289259.html&quot;&gt;&lt;em&gt;Debian macht ernst: Nur noch reproduzierbare Pakete in „testing“&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;holger-levsen-on-reproducing-official-debian-packages&quot;&gt;Holger Levsen on reproducing official Debian packages&lt;/h3&gt;

&lt;p&gt;Reproducible Builds developer Holger Levsen gave a talk at the &lt;a href=&quot;https://hamburg2026.mini.debconf.org/&quot;&gt;2026 Hamburg MiniDebconf&lt;/a&gt; this year on the topic of &lt;a href=&quot;https://hamburg2026.mini.debconf.org/talks/13-reproducedebiannet-reproducing-what-is-distributed-from-ftpdo/&quot;&gt;&lt;em&gt;reproduce.debian.net - reproducing what is distributed from ftp.d.o&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Holger’s talk announced that Debian intends to ship only reproducible packages in &lt;em&gt;forky&lt;/em&gt; and beyond (see above), but also talked more broadly about reproducible builds, our testing framework and the Debian archive. That is to say, moving away from testing whether a package is reproducible in a &lt;em&gt;theoretical&lt;/em&gt; sense (eg. whether we can build it twice in different environments and achieve the same result in our test system), and attempting to reproduce the same &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.deb&lt;/code&gt; files in the official Debian archive itself. This small-sounding distinction is actually essential, as this is the only means through which the reproducible builds technique can determine whether build systems are compromised are not.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://chuangtzu.ftp.acc.umu.se/pub/debian-meetings/2026/MiniDebConf-Hamburg/hamburg2026-37-reproducedebiannet-reproducing-what-is-distributed-from-ftpdo.av1.webm&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/holger-talk.png#center&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;A &lt;a href=&quot;https://meetings-archive.debian.net/pub/debian-meetings/2026/MiniDebConf-Hamburg/hamburg2026-37-reproducedebiannet-reproducing-what-is-distributed-from-ftpdo.av1.webm&quot;&gt;video&lt;/a&gt; (32m37s) of the talk is available, as are &lt;a href=&quot;https://reproducible-builds.org/_lfs/presentations/2026-05-09-Reproducing-Debian-in-the-real-world/&quot;&gt;Holger’s slides&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;reproducible-builds-2026-summit-to-be-held-in-gothenburg-sweden&quot;&gt;Reproducible Builds 2026 summit to be held in Gothenburg, Sweden&lt;/h3&gt;

&lt;p&gt;As initially announced in &lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-March/004060.html&quot;&gt;March 2026&lt;/a&gt;, we will be having our yearly Reproducible Builds summit 2026 in Gothenburg Sweden, from September 22 until 24, followed by two days of hacking!&lt;/p&gt;

&lt;p&gt;Further information will be provided on our website and &lt;a href=&quot;https://lists.reproducible-builds.org/listinfo/rb-general&quot;&gt;on the &lt;em&gt;rb-general&lt;/em&gt; mailing list&lt;/a&gt; very soon.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;kettle-attested-builds-for-verifiable-software&quot;&gt;&lt;em&gt;Kettle: Attested Builds for Verifiable Software&lt;/em&gt;&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://arxiv.org/abs/2605.08363&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/2605.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;André Arko and Amean Asad published a paper this month on &lt;a href=&quot;https://github.com/lunal-dev/kettle&quot;&gt;Kettle&lt;/a&gt;, a build system that “produces cryptographically verifiable provenance for software built inside Trusted Execution Environments”:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;A &lt;em&gt;Kettle&lt;/em&gt; build records the source commit, dependency set, toolchain, build
environment and output artifact digests in a provenance document produced
inside a measured confidential VM. The SHA-256 digest of that document is
committed to the TEE platform’s attestation report-data field, so the
hardware-signed attestation report is itself the signature on the provenance,
with the signing identity chaining to the TEE manufacturer’s root of trust
rather than to the build infrastructure operator. Because the CVM image is
itself reproducible, its launch measurement is public and stable, which lets
a build requester pre-attest the CVM before submitting any input and
optionally deliver source over a TLS channel terminated inside it, so the
build runs end-to-end confidentially without the host ever seeing source code
in plaintext.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A &lt;a href=&quot;https://arxiv.org/pdf/2605.08363&quot;&gt;PDF&lt;/a&gt; of the paper is available online.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;new-rebuilderd-version-announced&quot;&gt;New &lt;em&gt;rebuilderd&lt;/em&gt; version announced&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://reproduce.debian.net&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/reproduce.debian.net.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://github.com/kpcyrd/rebuilderd&quot;&gt;&lt;strong&gt;rebuilderd&lt;/strong&gt;&lt;/a&gt;, our server designed for monitoring the official package repositories of Linux distributions and attempt to reproduce the observed results there; it powers, amongst other things, &lt;a href=&quot;https://reproduce.debian.net/&quot;&gt;&lt;em&gt;reproduce.debian.net&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;A new version, &lt;a href=&quot;https://github.com/kpcyrd/rebuilderd/releases/tag/v0.27.0&quot;&gt;0.27.0&lt;/a&gt;, was released this month, with the following headline changes:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Improved &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.udeb&lt;/code&gt; support&lt;/li&gt;
  &lt;li&gt;Breaking changes in pkg sync configuration&lt;/li&gt;
  &lt;li&gt;Manual cleanup needed for Arch Linux instances&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;As &lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-May/004115.html&quot;&gt;&lt;em&gt;kpcyrd&lt;/em&gt;’s announcement mentions&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;The new &lt;em&gt;rebuilderd&lt;/em&gt; package is currently available in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;extra-testing&lt;/code&gt; repository. Note the Arch Linux package is upgraded from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;v0.25.0&lt;/code&gt; from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;v0.27.0&lt;/code&gt;; please be patient with the database migrations on first restart, and make 
yourself familiar with the &lt;a href=&quot;https://github.com/kpcyrd/rebuilderd/releases/tag/v0.26.0&quot;&gt;breaking changes in v0.26.0&lt;/a&gt; too.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;reproducible-open-source-messengers&quot;&gt;Reproducible open source messengers&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://github.com/BarbossHack/reproducible&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/BarbossHack.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;GitHub developer &lt;em&gt;BarbossHack&lt;/em&gt; is &lt;a href=&quot;https://github.com/BarbossHack/reproducible&quot;&gt;maintaining an repository/page on GitHub&lt;/a&gt; to “track reproducibility status of open source messengers”.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;distribution-work&quot;&gt;Distribution work&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://debian.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/debian.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In &lt;strong&gt;Debian&lt;/strong&gt; this month, the &lt;a href=&quot;https://loong64.reproduce.debian.net&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;loong64&lt;/code&gt; architecture was added to &lt;em&gt;reproduce.debian.net&lt;/em&gt;&lt;/a&gt;. This is a 64-bit Reduced Instruction Set Computer (RISC) instruction set architecture developed by &lt;a href=&quot;https://en.wikipedia.org/wiki/Loongson&quot;&gt;Loongson&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Vagrant Cascadian performed &lt;a href=&quot;https://wiki.debian.org/NonMaintainerUpload&quot;&gt;Non-Maintainer Uploads&lt;/a&gt; (NMUs) in Debian for several packages with outstanding patches over a year old. These included &lt;a href=&quot;https://browse.dgit.debian.org/rocdbgapi.git/commit/?id=46edda9ca57c482aff561cff7b20e074c9f0d442&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rocdbgapi&lt;/code&gt;&lt;/a&gt;, &lt;a href=&quot;https://salsa.debian.org/debian/onevpl-intel-gpu/-/commit/d361dc68bcf4bb92c192af1f20b2878fbcc297f3&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;onevpl-intel-gpu&lt;/code&gt;&lt;/a&gt;, &lt;a href=&quot;https://browse.dgit.debian.org/python-pytest-shell-utilities.git/commit/?id=326ae9029fd93ffb10a497b9fc99f8e9f62356c6&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;python-pytest-shell-utilities&lt;/code&gt;&lt;/a&gt;, &lt;a href=&quot;https://browse.dgit.debian.org/python-mt-940.git/commit/?id=da6105767e8c7922cd279bc07da1e5f576c9e2a5&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;python-mt-940&lt;/code&gt;&lt;/a&gt; and &lt;a href=&quot;https://browse.dgit.debian.org/pympress.git/commit/?id=c7fbef54dd54a5fec826f4aa492a3832dfd062c9&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pympress&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;On &lt;em&gt;tests.reproducible-builds.org&lt;/em&gt;, Vagrant Cascadian &lt;a href=&quot;https://salsa.debian.org/qa/jenkins.debian.net/-/commit/a741f156dff8dd2f2a0b6531756865c958ef7fd7&quot;&gt;fixed the huge spike in build failures by adding &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;passwd&lt;/code&gt; to the base tarballs&lt;/a&gt;, and &lt;a href=&quot;https://salsa.debian.org/qa/jenkins.debian.net/-/commit/1352171fa9f9fb9460ed0cb66befc0f65fb4f51b&quot;&gt;re-enabled building &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gcc&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;binutils&lt;/code&gt; packages with PGO (Profile Guided Optimization) and LTO (Link Time Optimization)&lt;/a&gt; to avoid giving a false sense of reproducibility.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://alioth-lists.debian.net/pipermail/reproducible-builds/Week-of-Mon-20260518/015547.html&quot;&gt;Inconsistencies on the reproducibility of the condor package&lt;/a&gt; were brought up on the Debian &lt;em&gt;reproducible-builds&lt;/em&gt; mailing list. Following a hunch, Vagrant Cascadian eventually &lt;a href=&quot;https://alioth-lists.debian.net/pipermail/reproducible-builds/Week-of-Mon-20260518/015550.html&quot;&gt;identified the issue was related to embedded kernel versions&lt;/a&gt; which was &lt;a href=&quot;https://github.com/htcondor/htcondor/pull/4500&quot;&gt;then fixed upstream&lt;/a&gt; and &lt;a href=&quot;https://alioth-lists.debian.net/pipermail/reproducible-builds/Week-of-Mon-20260525/015558.html&quot;&gt;fixed in Debian&lt;/a&gt; as well.&lt;/p&gt;

&lt;p&gt;Lastly, 40 reviews of Debian packages were added, 68 were updated and 75 were removed this month adding to &lt;a href=&quot;https://tests.reproducible-builds.org/debian/index_issues.html&quot;&gt;our knowledge about identified issues&lt;/a&gt;. A number of issue types were updated, such as the addition of a new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sphinx_reading_durations&lt;/code&gt; toolchain issue [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/ffb83115&quot;&gt;…&lt;/a&gt;], a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;golang_mango_generates_manpages_with_build_date&lt;/code&gt; issue [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/de1c015b&quot;&gt;…&lt;/a&gt;] and a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;random_offset_id_in_cython_linetrace&lt;/code&gt; [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/b99f0ae7&quot;&gt;…&lt;/a&gt;]. In addition, the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;timestamps_in_qhc&lt;/code&gt; issue was “refocused” to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;timestamps_in_qhc&lt;/code&gt; [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/f3bbf1a8&quot;&gt;…&lt;/a&gt;].&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://fedoraproject.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/fedora.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In &lt;strong&gt;Fedora&lt;/strong&gt;, &lt;a href=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=2482689&quot;&gt;Jelle van der Waa submitted a request&lt;/a&gt; for an official Fedora &lt;a href=&quot;https://github.com/kpcyrd/rebuilderd&quot;&gt;&lt;em&gt;rebuilderd&lt;/em&gt;&lt;/a&gt; package which was reviewed by Neal Gompa.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://www.opensuse.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/opensuse.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Lastly, Bernhard M. Wiedemann posted another &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;&lt;strong&gt;openSUSE&lt;/strong&gt;&lt;/a&gt; &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/thread/62MATHSPIQTAEWXCUN5JOBI2GHC4D54X/&quot;&gt;monthly update&lt;/a&gt; for their reproducibility work there.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;misc-news&quot;&gt;Misc news&lt;/h3&gt;

&lt;p&gt;On &lt;a href=&quot;https://lists.reproducible-builds.org/listinfo/rb-general/&quot;&gt;our mailing list&lt;/a&gt; this month:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;em&gt;cen&lt;/em&gt; posted an interesting question to our list regarding “&lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-May/004092.html&quot;&gt;an interesting case of time-based non-reproducibility&lt;/a&gt;” after they noticed that &lt;a href=&quot;https://reproducible.archlinux.org/api/v0/builds/787931/log&quot;&gt;Arch Linux’s &lt;em&gt;rebuilderd&lt;/em&gt; instance reports the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;grep&lt;/code&gt; package as being reproducible&lt;/a&gt; whilst &lt;a href=&quot;https://rebuilderd.xpam.pl:2096/api/v1/builds/416039/log&quot;&gt;their own is not&lt;/a&gt;. Although the root cause of the issue is that various “translations are fetched from a remote location during bootstrap”, &lt;em&gt;cen&lt;/em&gt; argues that:&lt;/p&gt;

    &lt;blockquote&gt;
      &lt;p&gt;Perhaps rebuilderd needs a feature where &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GOOD&lt;/code&gt; packages are also periodically rebuilt in exponential back-off style and compared against current upstream build and also our last &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GOOD&lt;/code&gt; build. This would confirm  whether a package is reproducible if built in a short time window but also help uncover longer time window issues that are currently hidden.&lt;/p&gt;
    &lt;/blockquote&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Reproducible Builds developer &lt;em&gt;kpcryd&lt;/em&gt; &lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-May/004110.html&quot;&gt;copied-in our mailing list to an existing email thread&lt;/a&gt; that was occurring on Debian bug &lt;a href=&quot;https://bugs.debian.org/1137357&quot;&gt;#1137357&lt;/a&gt; regarding deterministic signatures in the Rust-based &lt;a href=&quot;https://sequoia-pgp.org/&quot;&gt;Sequoia OpenPGP library&lt;/a&gt;. This generated some very interesting replies, such as &lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-May/004111.html&quot;&gt;this one by David A. Wheeler&lt;/a&gt; on how naïve methods for obtaining determinism in signatures may inadvertently reveal private keys.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Lastly, David A. Wheeler announced that the &lt;a href=&quot;https://scored.dev/&quot;&gt;2026 Software Supply Chain Offensive Research and Ecosystem Defenses&lt;/a&gt; (SCORED ‘26) conference will be held on October 6 2026 in Prague, Czechia. David &lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-May/004114.html&quot;&gt;specifically notes in their announcement&lt;/a&gt; that the conference’s Call for Papers (CfP) explicitly includes “Reproducible builds” and that the submission deadline is July 12, 2026.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;patches&quot;&gt;Patches&lt;/h3&gt;

&lt;p&gt;The Reproducible Builds project detects, dissects and attempts to fix as many currently-unreproducible packages as possible. We endeavour to send all of our patches upstream where applicable or possible. This month, we wrote a large number of such patches, including:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Arnout Engelen (1):&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://git.netfilter.org/nftables/commit/?id=ca86f206c92704170a295b8dc7a41f6448835dde&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nftables&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Bernhard M. Wiedemann (5):&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/neomutt/neomutt/issues/4877&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;neomutt&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://gitlab.com/NTPsec/ntpsec/-/merge_requests/1501&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ntpsec&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugzilla.opensuse.org/show_bug.cgi?id=1265183&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pacemaker&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1353945&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;powerdevil6&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/SSSD/sssd/pull/8759&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sssd&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Chris Lamb (23):&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135692&quot;&gt;#1135692&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/dkimpy&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dkimpy&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1135873&quot;&gt;#1135873&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/fortran-stdlib&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fortran-stdlib&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136291&quot;&gt;#1136291&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/powerline&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;powerline&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136297&quot;&gt;#1136297&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/pycayennelpp&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pycayennelpp&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136298&quot;&gt;#1136298&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/pycorrfit&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pycorrfit&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136424&quot;&gt;#1136424&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/sphinx-needs&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sphinx-needs&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136425&quot;&gt;#1136425&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/ruby-otr-activerecord&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ruby-otr-activerecord&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136426&quot;&gt;#1136426&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/git-pw&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;git-pw&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136427&quot;&gt;#1136427&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/golang-github-akavel-rsrc&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;golang-github-akavel-rsrc&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136686&quot;&gt;#1136686&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/pampi&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pampi&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136689&quot;&gt;#1136689&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/libreoffice-dictionaries&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libreoffice-dictionaries&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137016&quot;&gt;#1137016&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/vnu&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vnu&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137017&quot;&gt;#1137017&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/golang-github-shirou-gopsutil&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;golang-github-shirou-gopsutil&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137018&quot;&gt;#1137018&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/javacc5&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;javacc5&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137019&quot;&gt;#1137019&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/rssguard&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rssguard&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137204&quot;&gt;#1137204&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/golang-github-containerd-accelerated-container-image&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;golang-github-containerd-accelerated-container-image&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137335&quot;&gt;#1137335&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/docker-credential-gcr&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;docker-credential-gcr&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1137336&quot;&gt;#1137336&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/xpenguins&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xpenguins&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138232&quot;&gt;#1138232&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/cairocffi&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cairocffi&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138639&quot;&gt;#1138639&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/meshy&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;meshy&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138640&quot;&gt;#1138640&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/bingo&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;bingo&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138641&quot;&gt;#1138641&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/golang-github-cyclonedx-cyclonedx-go&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;golang-github-cyclonedx-cyclonedx-go&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138642&quot;&gt;#1138642&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/nfstest&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nfstest&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Paul Gevers (1):&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1136939&quot;&gt;#1136939&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/mandos&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mandos&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Vagrant Cascadian (2):&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1138608&quot;&gt;#1138608&lt;/a&gt; and &lt;a href=&quot;https://bugs.debian.org/1138611&quot;&gt;#1138611&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/grub2&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;grub2&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;documentation-updates&quot;&gt;Documentation updates&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://reproducible-builds.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-05/website.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Chris Lamb:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;Added a missing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;+&lt;/code&gt; (plus sign) to the &lt;a href=&quot;https://en.wikipedia.org/wiki/GNU_Autotools&quot;&gt;GNU Autotools&lt;/a&gt; example on the &lt;a href=&quot;https://reproducible-builds.org/docs/source-date-epoch/&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SOURCE_DATE_EPOCH&lt;/code&gt; documentation page&lt;/a&gt;. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/5bb3ebd9&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mattia Rizzolo:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;Made a number of chnages to the &lt;a href=&quot;https://reproducible-builds.org/events/gothenburg2026/&quot;&gt;&lt;em&gt;2026 Gothenberg Summit&lt;/em&gt;&lt;/a&gt; event page. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/83040792&quot;&gt;…&lt;/a&gt;][&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/88ceb66e&quot;&gt;…&lt;/a&gt;][&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/edce4638&quot;&gt;…&lt;/a&gt;][&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/d0cce962&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Finally, if you are interested in contributing to the Reproducible Builds project, please visit our &lt;a href=&quot;https://reproducible-builds.org/contribute/&quot;&gt;&lt;em&gt;Contribute&lt;/em&gt;&lt;/a&gt; page on our website. However, you can get in touch with us via:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;IRC: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;#reproducible-builds&lt;/code&gt; on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;irc.oftc.net&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mastodon: &lt;a href=&quot;https://fosstodon.org/@reproducible_builds&quot;&gt;@reproducible_builds@fosstodon.org&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mailing list: &lt;a href=&quot;https://lists.reproducible-builds.org/listinfo/rb-general&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rb-general@lists.reproducible-builds.org&lt;/code&gt;&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-06-04T19:12:15+00:00</dc:date>
	<dc:creator>Reproducible Builds</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/mount_namespace_backup/">
	<title>Jonathan Dowland: mount namespace for backup jobs (by hand)</title>
	<link>https://jmtd.net/log/mount_namespace_backup/</link>
     <content:encoded>&lt;p&gt;It&#39;s been ten years since I configured &lt;a href=&quot;https://jmtd.net/log/mount_on_demand_backups/&quot;&gt;mount on demand backups&lt;/a&gt; to reduce
the risk of my backups being zapped by mistake. Way back then I wanted to go
one step further and use dedicated &lt;a href=&quot;https://jmtd.net/log/mount_namespaces/&quot;&gt;mount namespaces&lt;/a&gt; for backup jobs, but
systemd didn&#39;t provide the necessary support (and still doesn&#39;t, despite the
promisingly-named &lt;code&gt;JoinsNameSpaceOf=&lt;/code&gt; configuration option.)&lt;/p&gt;

&lt;p&gt;I recently updated my setup to achieve this by hand. All backup jobs now have
an extra pre-start instruction &lt;code&gt;ExecStartPre=mkbackupns&lt;/code&gt; which runs a shell
script to either set up a persistent mount namespace, or exit quietly if it
already exists.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;#!/bin/bash
set -euo pipefail

nsdir=/var/namespaces
nsfile=$nsdir/backup
nsfilex=&quot;$(echo $nsfile | sed &#39;s#/#\\/#&#39;g)&quot;

private_propagation() {
    findmnt -o+PROPAGATION &quot;$nsdir&quot; | grep -q private
}
nsfs_is_mounted() {
    test &quot;nsfs&quot; = &quot;$(awk &quot;/$nsfilex/ { print \$3 }&quot; /proc/mounts)&quot;
}

if ! nsfs_is_mounted; then

    if ! private_propagation; then
        mkdir -p &quot;$nsdir&quot;
        mount --bind --make-private &quot;$nsdir&quot; &quot;$nsdir&quot;
    fi

    touch &quot;$nsfile&quot;
    unshare --mount=&quot;$nsfile&quot; true

    nsenter --mount=/var/namespaces/backup mount /dev/phobos_backup/backup /backup
fi
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;I should note that I don&#39;t have the backup filesystem described in &lt;code&gt;/etc/fstab&lt;/code&gt;
to reduce the risk of it being mounted errantly in the main namespace.&lt;/p&gt;

&lt;p&gt;The other change is to prefix an invocation of &lt;code&gt;nsenter&lt;/code&gt; for every backup
job command. E.g.:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;ExecStart=/usr/bin/nsenter \
        --mount=/var/namespaces/backup \
        borgmatic -v 1 prune create
&lt;/code&gt;&lt;/pre&gt;

&lt;h3&gt;next steps&lt;/h3&gt;

&lt;p&gt;My backup scheme has lasted a decade with few tweaks
(&lt;a href=&quot;https://jmtd.net/log/gtkpod/&quot;&gt;I moved it to Borg in 2020&lt;/a&gt;) which I am very grateful for. I want reliable,
boring and robust.&lt;/p&gt;

&lt;p&gt;Persistent mount namespaces are a lot less convoluted if you have a persistent
process to associate them with. I didn&#39;t, but a subsequent improvement I am
making is introducing one, so I will likely simplify the above accordingly.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-06-04T10:15:21+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="https://www.decadent.org.uk/ben/blog/2026/06/02/foss-activity-in-may-2026">
	<title>Ben Hutchings: FOSS activity in May 2026</title>
	<link>https://www.decadent.org.uk/ben/blog/2026/06/02/foss-activity-in-may-2026.html</link>
     <content:encoded>&lt;p&gt;This was a particularly busy month for me in terms of Debian
contributions.&lt;/p&gt;

&lt;p&gt;It started with a week in Hamburg for the MiniDebConf.  I talked to
many colleagues face-to-face and worked on various bugs and
maintenance tasks.  I’m pleased to have finally found the time to
reproduce and fix the &lt;a href=&quot;https://bugs.debian.org/1130365&quot;&gt;boot-time crashes in the parallel port
subsystem&lt;/a&gt; that have been reported
many times recently.&lt;/p&gt;

&lt;p&gt;A series of easily exploited kernel LPE (local privilege execution)
issues were published this month, mostly with very little coordination
with distributions.  Salvatore and I had to upload fixes for these at
roughly weekly intervals.  All of these fixes needed to be applied to
4 different upstream branches (currently 5.10, 6.1, 6.12, and 7.0) and
7 Debian branches (including backports).&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Debian packages:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/cis-tools&quot;&gt;cis-tools&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:cis-tools&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1135267&quot;&gt;#1135267: pack_cis should be installed in /usr/bin&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/dracut&quot;&gt;dracut&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:dracut&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1131809&quot;&gt;#1131809: dracut: ppc64el autopkgtest are flaky and take 7 hours per run&lt;/a&gt;
(and discussed it in-person in Hamburg)&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-free&quot;&gt;firmware-free&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:firmware-free&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1122755&quot;&gt;#1122755: firmware-free: Please remove/replace usage of dh_movetousr&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-free/-/merge_requests/11&quot;&gt;!11: Apply relevant changes from firmware-nonfree&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-nonfree&quot;&gt;firmware-nonfree&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/68&quot;&gt;!68: Draft: Update bullseye in line with buster&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/146&quot;&gt;!146: gencontrol: s/initramfs-tools/update-initramfs/&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/147&quot;&gt;!147: control: stop suggesting initramfs-tools&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/148&quot;&gt;!148: Update to 20260519&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/149&quot;&gt;!149: Include more firmware in binary packages&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/150&quot;&gt;!150: Update and remove obsolete package relations&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/gnome-shell&quot;&gt;gnome-shell&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:gnome-shell&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to and reassigned &lt;a href=&quot;https://bugs.debian.org/1135951&quot;&gt;#1135951: linux-image-6.12.85+deb13-amd64: secure data is visible when waking from suspsend&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/initramfs-tools&quot;&gt;initramfs-tools&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:initramfs-tools&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1108924&quot;&gt;#1108924: initramfs-tools: Cannot boot Trixie d-i rc2 USB storage target riscv64 MODULES=most (missing: cdns3 cdns3_starfive)&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/142&quot;&gt;!142: Handle simple-framebuffer drivers and framebuffer_coreboot built as modules&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/150&quot;&gt;!150: Do not install ARM/RISCV specific modules on other architectures&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/173&quot;&gt;!173: Draft: Introduce copy_file helper program to replace copy_file function&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/195&quot;&gt;!195: unmkinitramfs: Make it compatible with Busybox cpio&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/196&quot;&gt;!196: add module to add fw files from DT firmware-name properties&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/initramfs-tools/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 0.148.4 to trixie&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/ktls-utils&quot;&gt;ktls-utils&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/ktls-utils/-/merge_requests/5&quot;&gt;!5: Update to 1.4.0&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/ktls-utils/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 1.4.0-1 to unstable&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux&quot;&gt;linux&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:linux&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1130365&quot;&gt;#1130365: linux-image-6.18.15+deb14-amd64: kernel panic during startup&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1136800&quot;&gt;#1136800: linux-image-7.0.4+deb14-amd64: fails to boot&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1136894&quot;&gt;#1136894: linux-image-7.0.4+deb14-amd64: Kernel Panic - AMDGPU crash&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1136978&quot;&gt;#1136978: linux-image-7.0.4+deb14-amd64: kernel NULL pointer dereference&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to and closed &lt;a href=&quot;https://bugs.debian.org/1137202&quot;&gt;#1137202: linux-image-7.1-amd64: Kernel panic on boot&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1137203&quot;&gt;#1137203: bnx2: ifupdown-hotplug fails at boot, no network, regression from 5.10.0-42&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1137642&quot;&gt;#1137642: linux-image-7.0.7+deb13-amd64: Failed to load Bluetooth driver&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1720&quot;&gt;!1720: arm64: Enable Renesas RZ/G2L features&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1759&quot;&gt;!1759: [arm64] Enable AIR_EN8811H_PHY as module&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1792&quot;&gt;!1792: [arm64] Enable BST platform support&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1817&quot;&gt;!1817: [sparc64] Add patches to fix user stack sync and add clone3() syscall&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1837&quot;&gt;!1837: [arm64] Enable configs for Qualcomm RB1 boards&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1845&quot;&gt;!1845: [amd64,arm64] Enable KEXEC_HANDOVER and LIVEUPDATE&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1878&quot;&gt;!1878: [riscv64] Enable CMA and DMA_CMA. Set CMA_SIZE_MBYTES=64&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1884&quot;&gt;!1884: [amd64] Enable Intel USBIO bridge driver and submodules&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1904&quot;&gt;!1904: Improve package descriptions for most of the kernel packages&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1906&quot;&gt;!1906: Enable SND_SOC_SDCA_CLASS and SND_SOC_SDCA_{FDL, HID, IRQ} for Panther Lake audio support&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1910&quot;&gt;!1910: Add backported patches for Dirty Frag attack&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1911&quot;&gt;!1911: Qualcomm Monaco and Talos support&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1913&quot;&gt;!1913: d/watch: migrate to version 5&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1936&quot;&gt;!1936: [sparc64] Add nvme module to scsi-modules udeb&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1948&quot;&gt;!1948: [amd64] Enable Intel Platform Hardware Support Drivers&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1951&quot;&gt;!1951: Fix dirtying of the source tree when building tools&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1954&quot;&gt;!1954: 7.0 backport ‘Fix for “fragnesia” (CVE-2026-46300) and variants’&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1955&quot;&gt;!1955: 6.12 backport ‘Fix for “fragnesia” (CVE-2026-46300) and variants’&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1956&quot;&gt;!1956: Draft: Enable a fully parallel build&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;(LTS) uploaded versions 5.10.251-2, 5.10.251-3, 5.10.251-4, 5.10.251-5, 5.10.257-1 to bullseye-security&lt;/li&gt;
              &lt;li&gt;uploaded versions 6.12.85-1~bpo12+1, 6.12.86-1~bpo12+1, 6.12.88-1~bpo12+1, 6.12.90-1~bpo12+1, 6.12.90-2~bpo12+1 to bookworm-backports&lt;/li&gt;
              &lt;li&gt;uploaded versions 6.19.14-1~bpo13+1, 7.0.10-1~bpo13+1, 7.0.4-1~bpo13+1, 7.0.7-1~bpo13+1, 7.0.9-1~bpo13+1 to trixie-backports&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;(LTS) &lt;a href=&quot;https://tracker.debian.org/pkg/linux-6.1&quot;&gt;linux-6.1&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-6.1/news&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded versions 6.1.170-1~deb11u1, 6.1.170-3~deb11u1, 6.1.172-1~deb11u1, 6.1.174-1~deb11u1 to bullseye-security&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/miniramfs&quot;&gt;miniramfs&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:miniramfs&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1132532&quot;&gt;#1132532: miniramfs: Missing cpio dependency&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/nfs-utils&quot;&gt;nfs-utils&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:nfs-utils&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to and closed &lt;a href=&quot;https://bugs.debian.org/1138209&quot;&gt;#1138209: nfs-kernel-server: Parameter RPCNFSDCOUNT from /etc/default/nfs-kernel-server is ignored after Upgrade from Deb12&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb&quot;&gt;wireless-regdb&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 2026.03.18-1 to unstable&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;Debian non-package bugs:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/release.debian.org&quot;&gt;release.debian.org&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;opened &lt;a href=&quot;https://bugs.debian.org/1135902&quot;&gt;#1135902: trixie-pu: package initramfs-tools/0.148.4&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;Mailing lists:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-boot/&quot;&gt;debian-boot&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lists.debian.org/0f7a0a1aa33ec586ffa950d784641b0e76e380e9.camel@decadent.org.uk&quot;&gt;Please add loong64 to Daily/Weekly builds of installer images&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-devel/&quot;&gt;debian-devel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lists.debian.org/3fc99c8b98edf120394c75d7b2fa5929c93da0dc.camel@decadent.org.uk&quot;&gt;Licensing of licenses&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-kernel/&quot;&gt;debian-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/8025d9d8faefba5e7f444cdc82e41ca1c12d7377.camel@decadent.org.uk&quot;&gt;Agenda items for kernel-team meeting on 2026-05-13&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted and replied to &lt;a href=&quot;https://lists.debian.org/7e451300e9129f9a466548a3d0b771b236e1b36b.camel@debian.org&quot;&gt;[RFC] Using SimpleDRM in the initramfs&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lists.debian.org/f1f249b86b6fb7239e43da110f969ab371e1ba56.camel@decadent.org.uk&quot;&gt;[bjarniig@simnet.is: kernel-img.conf.5: warning from “lint”]&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/&quot;&gt;debian-lts-announce&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/afW4eRFSiyEj0t5p@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4560-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/afW4k69tKf_WlndL@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4561-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/af4wE6d14Ow7_e1z@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4572-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/af9UZejc2VrICvbM@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4574-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/aghQTI2_ePQTfgRl@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4587-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/agxj_abMk4ZO7rTj@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4588-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/ahnAg039hP_NAYQZ@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4606-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/ahnBQfl3R3-CGOJ0@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4607-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-hyperv/&quot;&gt;linux-hyperv&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/linux-hyperv/ahQ6xuhSReidmN-3@decadent.org.uk/T/&quot;&gt;[PATCH] uio_hv_generic: Bind to FCopy device by default&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-perf-users/&quot;&gt;linux-perf-users&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted and replied to &lt;a href=&quot;https://lore.kernel.org/linux-perf-users/ag8X7gcDw6jpJsLq@decadent.org.uk/T/&quot;&gt;[PATCH 0/3] Fix out-of-tree build of some tools&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-sh/&quot;&gt;linux-sh&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/linux-sh/afuJTi1IGCgrK_cc@decadent.org.uk/T/&quot;&gt;[PATCH] sh: uaccess: Handle exception on second instruction of __put_user_u64&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-trace-kernel/&quot;&gt;linux-trace-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/linux-trace-kernel/ahMmN4PdsJzr_Va-@decadent.org.uk/T/&quot;&gt;[PATCH RESEND] rtla: Fix output files in source tree&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/netdev/&quot;&gt;netdev&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/netdev/811b31f3373526d1ff60160c2f32ddb359e54c31.camel@decadent.org.uk/T/&quot;&gt;[PATCH net] net: skbuff: propagate shared-frag marker through pskb_copy()&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;(mostly LTS) &lt;a href=&quot;https://lore.kernel.org/stable/&quot;&gt;stable&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/036ef29e143799f9117792463d640916490fa61a.camel@debian.org/T/&quot;&gt;Linux 5.15.205&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/14797eaf17672917e7c62a679de22f3d1e25edf5.camel@decadent.org.uk/T/&quot;&gt;[5.10,5.15] i3c: fix uninitialized variable use in i2c setup&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/3f2908646639f4af8844cb8f5a9b4d2d4f904631.camel@debian.org/T/&quot;&gt;[6.6] fbdev/vt8500lcdfb: Initialize fb_ops with fbdev macros&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/a785911d711bee40be215dad119f9922e014aead.camel@decadent.org.uk/T/&quot;&gt;[6.6] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/1d128ddf72c7c42d47e1348b9dc74f7f829621fd.camel@debian.org/T/&quot;&gt;[6.6] x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/f84e935e26fdb239b473443efeb925bbfbd5b182.camel@decadent.org.uk/T/&quot;&gt;[7.0] perf loongarch: Fix build failure with CONFIG_LIBDW_DWARF_UNWIND&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/daa0df3788560bd8759418d9c333e09c45368aa4.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 002/589] ASoC: SOF: topology: reject invalid vendor array size in token parser&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/56652caf63e8db874a3ebd761ec134c003d4986c.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 027/589] xfrm: Wait for RCU readers during policy netns exit&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/136f03aa6f51bdfecc786e5278f5fd03b4a6966e.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 072/589] media: uvcvideo: Use heuristic to find stream entity&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/ca469f4a22fe4688bbf88c355d074ae5be16a621.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 095/589] ALSA: usb-audio: fix null pointer dereference on pointer cs_desc&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/70620d4eddfa13b0b5333e482bb76d7f4b323114.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 096/589] scsi: ufs: core: Improve SCSI abort handling&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahghwxSf9me8PHM4@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 1/2] Revert “RDMA/rxe: Fix double free in rxe_srq_from_init”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/866e188244055e8b90d632cb82e2badb40946706.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 101/589] rxrpc: Fix key quota calculation for multitoken keys&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/b7871589afa5bc3668b07550b9e8b69b3a6c15dd.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 114/589] arm64: dts: imx8mq-librem5: Dont mark buck3 as always on&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/203134947f42d331eeb0f19c0849802c044103c7.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 176/589] KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/5903b777c7688dd17f8e4eb173361c80ea0fff46.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 177/589] KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted and replied to &lt;a href=&quot;https://lore.kernel.org/stable/bbee79323cd7836164c92229b0b2ed38b5179353.camel@debian.org/T/&quot;&gt;[PATCH 5.10 2/2] RDMA/rxe: Fix double free in rxe_srq_from_init&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahhcDsPMJ3Cu3J-E@decadent.org.uk/T/&quot;&gt;[PATCH 5.10-5.15] apparmor: validate default DFA states are in bounds&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahg8Ocvb3UFV6Vdl@decadent.org.uk/T/&quot;&gt;[PATCH 5.10-6.1] fbdev: vt8500lcdfb: Fix dma_free_coherent() cpu_addr parameter&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahhd83m8AruYGvOc@decadent.org.uk/T/&quot;&gt;[PATCH 5.10-6.1] x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/ece62fc01497ee5b8bb7e272a0f6474e89c8e7b2.camel@debian.org/T/&quot;&gt;[PATCH 5.10] Revert “s390/cio: Fix device lifecycle handling in css_alloc_subchannel()”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahVuMv5SLjHVUbkt@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] Revert “s390/cio: Fix device lifecycle handling in css_alloc_subchannel()”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahC38RZJN2O3Ur0R@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] net: skbuff: preserve shared-frag marker during coalescing&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahC4qNfoeifA-enJ@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahg-Lvu0ywzUT9mZ@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] phy: renesas: rcar-gen3-usb2: Fix msleep() in atomic context&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgnK2FarjRafL_J@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] selftests: forwarding: lib: Add helpers for checksum handling&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgiBNbwo7FudH9r@decadent.org.uk/T/&quot;&gt;[PATCH 5.15 1/2] Revert “RDMA/rxe: Fix double free in rxe_srq_from_init”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgjFad4eiurr6KR@decadent.org.uk/T/&quot;&gt;[PATCH 5.15 2/2] RDMA/rxe: Fix double free in rxe_srq_from_init&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/a26366c3a1b70db57fc27f2ad4ef4f21185ebc9c.camel@debian.org/T/&quot;&gt;[PATCH 5.15.y] net: usb: lan78xx: Fix double free issue with interrupt buffer allocation&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahCyf28nWFO49oDZ@decadent.org.uk/T/&quot;&gt;[PATCH 5.15] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgn9yc4SFsqMAWq@decadent.org.uk/T/&quot;&gt;[PATCH 5.15] selftests: forwarding: lib: Add helpers for checksum handling&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgjTfDry_UjKgYs@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 1/2] Revert “RDMA/rxe: Fix double free in rxe_srq_from_init”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgjYxBbXlUjlFUz@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 2/2] RDMA/rxe: Fix double free in rxe_srq_from_init&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahhcYci93VUlA_f2@decadent.org.uk/T/&quot;&gt;[PATCH 6.1] apparmor: validate default DFA states are in bounds&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahCqJlqexPCiB0P9@decadent.org.uk/T/&quot;&gt;[PATCH 6.1] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgoDv7vIhnWbeGJ@decadent.org.uk/T/&quot;&gt;[PATCH 6.1] selftests: forwarding: lib: Add helpers for checksum handling&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahFmF_XkUzOHBMnC@decadent.org.uk/T/&quot;&gt;[PATCH 6.6] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/811b31f3373526d1ff60160c2f32ddb359e54c31.camel@decadent.org.uk/T/&quot;&gt;[PATCH net] net: skbuff: propagate shared-frag marker through pskb_copy()&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/afo6uBv68GDevbMD@decadent.org.uk/T/&quot;&gt;[PATCH] parport: Fix race between port and client registration&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-06-02T14:17:21+00:00</dc:date>
	<dc:creator>Ben Hutchings</dc:creator>
</item> 
<item rdf:about="https://www.decadent.org.uk/ben/blog/2026/06/02/foss-activity-in-2025">
	<title>Ben Hutchings: FOSS activity in 2025</title>
	<link>https://www.decadent.org.uk/ben/blog/2026/06/02/foss-activity-in-2025.html</link>
     <content:encoded>&lt;p&gt;This was a particularly busy month for me in terms of Debian
contributions.&lt;/p&gt;

&lt;p&gt;It started with a week in Hamburg for the MiniDebConf.  I talked to
many colleagues face-to-face and worked on various bugs and
maintenance tasks.  I’m pleased to have finally found the time to
reproduce and fix the &lt;a href=&quot;https://bugs.debian.org/1130365&quot;&gt;boot-time crashes in the parallel port
subsystem&lt;/a&gt; that have been reported
many times recently.&lt;/p&gt;

&lt;p&gt;A series of easily exploited kernel LPE (local privilege execution)
issues were published this month, mostly with very little coordination
with distributions.  Salvatore and I had to upload fixes for these at
roughly weekly intervals.  All of these fixes needed to be applied to
4 different upstream branches (currently 5.10, 6.1, 6.12, and 7.0) and
7 Debian branches (including backports).&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Debian packages:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/cis-tools&quot;&gt;cis-tools&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:cis-tools&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1135267&quot;&gt;#1135267: pack_cis should be installed in /usr/bin&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/dracut&quot;&gt;dracut&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:dracut&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1131809&quot;&gt;#1131809: dracut: ppc64el autopkgtest are flaky and take 7 hours per run&lt;/a&gt;
(and discussed it in-person in Hamburg)&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-free&quot;&gt;firmware-free&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:firmware-free&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1122755&quot;&gt;#1122755: firmware-free: Please remove/replace usage of dh_movetousr&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-free/-/merge_requests/11&quot;&gt;!11: Apply relevant changes from firmware-nonfree&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-nonfree&quot;&gt;firmware-nonfree&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/68&quot;&gt;!68: Draft: Update bullseye in line with buster&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/146&quot;&gt;!146: gencontrol: s/initramfs-tools/update-initramfs/&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/147&quot;&gt;!147: control: stop suggesting initramfs-tools&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/148&quot;&gt;!148: Update to 20260519&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/149&quot;&gt;!149: Include more firmware in binary packages&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/150&quot;&gt;!150: Update and remove obsolete package relations&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/gnome-shell&quot;&gt;gnome-shell&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:gnome-shell&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to and reassigned &lt;a href=&quot;https://bugs.debian.org/1135951&quot;&gt;#1135951: linux-image-6.12.85+deb13-amd64: secure data is visible when waking from suspsend&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/initramfs-tools&quot;&gt;initramfs-tools&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:initramfs-tools&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1108924&quot;&gt;#1108924: initramfs-tools: Cannot boot Trixie d-i rc2 USB storage target riscv64 MODULES=most (missing: cdns3 cdns3_starfive)&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/142&quot;&gt;!142: Handle simple-framebuffer drivers and framebuffer_coreboot built as modules&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/150&quot;&gt;!150: Do not install ARM/RISCV specific modules on other architectures&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/173&quot;&gt;!173: Draft: Introduce copy_file helper program to replace copy_file function&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/195&quot;&gt;!195: unmkinitramfs: Make it compatible with Busybox cpio&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/initramfs-tools/-/merge_requests/196&quot;&gt;!196: add module to add fw files from DT firmware-name properties&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/initramfs-tools/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 0.148.4 to trixie&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/ktls-utils&quot;&gt;ktls-utils&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/ktls-utils/-/merge_requests/5&quot;&gt;!5: Update to 1.4.0&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/ktls-utils/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 1.4.0-1 to unstable&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux&quot;&gt;linux&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:linux&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1130365&quot;&gt;#1130365: linux-image-6.18.15+deb14-amd64: kernel panic during startup&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1136800&quot;&gt;#1136800: linux-image-7.0.4+deb14-amd64: fails to boot&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1136894&quot;&gt;#1136894: linux-image-7.0.4+deb14-amd64: Kernel Panic - AMDGPU crash&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1136978&quot;&gt;#1136978: linux-image-7.0.4+deb14-amd64: kernel NULL pointer dereference&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to and closed &lt;a href=&quot;https://bugs.debian.org/1137202&quot;&gt;#1137202: linux-image-7.1-amd64: Kernel panic on boot&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1137203&quot;&gt;#1137203: bnx2: ifupdown-hotplug fails at boot, no network, regression from 5.10.0-42&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1137642&quot;&gt;#1137642: linux-image-7.0.7+deb13-amd64: Failed to load Bluetooth driver&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1720&quot;&gt;!1720: arm64: Enable Renesas RZ/G2L features&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1759&quot;&gt;!1759: [arm64] Enable AIR_EN8811H_PHY as module&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1792&quot;&gt;!1792: [arm64] Enable BST platform support&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1817&quot;&gt;!1817: [sparc64] Add patches to fix user stack sync and add clone3() syscall&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1837&quot;&gt;!1837: [arm64] Enable configs for Qualcomm RB1 boards&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1845&quot;&gt;!1845: [amd64,arm64] Enable KEXEC_HANDOVER and LIVEUPDATE&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1878&quot;&gt;!1878: [riscv64] Enable CMA and DMA_CMA. Set CMA_SIZE_MBYTES=64&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1884&quot;&gt;!1884: [amd64] Enable Intel USBIO bridge driver and submodules&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1904&quot;&gt;!1904: Improve package descriptions for most of the kernel packages&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1906&quot;&gt;!1906: Enable SND_SOC_SDCA_CLASS and SND_SOC_SDCA_{FDL, HID, IRQ} for Panther Lake audio support&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1910&quot;&gt;!1910: Add backported patches for Dirty Frag attack&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1911&quot;&gt;!1911: Qualcomm Monaco and Talos support&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1913&quot;&gt;!1913: d/watch: migrate to version 5&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1936&quot;&gt;!1936: [sparc64] Add nvme module to scsi-modules udeb&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1948&quot;&gt;!1948: [amd64] Enable Intel Platform Hardware Support Drivers&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1951&quot;&gt;!1951: Fix dirtying of the source tree when building tools&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1954&quot;&gt;!1954: 7.0 backport ‘Fix for “fragnesia” (CVE-2026-46300) and variants’&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1955&quot;&gt;!1955: 6.12 backport ‘Fix for “fragnesia” (CVE-2026-46300) and variants’&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1956&quot;&gt;!1956: Draft: Enable a fully parallel build&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;(LTS) uploaded versions 5.10.251-2, 5.10.251-3, 5.10.251-4, 5.10.251-5, 5.10.257-1 to bullseye-security&lt;/li&gt;
              &lt;li&gt;uploaded versions 6.12.85-1~bpo12+1, 6.12.86-1~bpo12+1, 6.12.88-1~bpo12+1, 6.12.90-1~bpo12+1, 6.12.90-2~bpo12+1 to bookworm-backports&lt;/li&gt;
              &lt;li&gt;uploaded versions 6.19.14-1~bpo13+1, 7.0.10-1~bpo13+1, 7.0.4-1~bpo13+1, 7.0.7-1~bpo13+1, 7.0.9-1~bpo13+1 to trixie-backports&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;(LTS) &lt;a href=&quot;https://tracker.debian.org/pkg/linux-6.1&quot;&gt;linux-6.1&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-6.1/news&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded versions 6.1.170-1~deb11u1, 6.1.170-3~deb11u1, 6.1.172-1~deb11u1, 6.1.174-1~deb11u1 to bullseye-security&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/miniramfs&quot;&gt;miniramfs&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:miniramfs&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1132532&quot;&gt;#1132532: miniramfs: Missing cpio dependency&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/nfs-utils&quot;&gt;nfs-utils&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:nfs-utils&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to and closed &lt;a href=&quot;https://bugs.debian.org/1138209&quot;&gt;#1138209: nfs-kernel-server: Parameter RPCNFSDCOUNT from /etc/default/nfs-kernel-server is ignored after Upgrade from Deb12&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb&quot;&gt;wireless-regdb&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 2026.03.18-1 to unstable&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;Debian non-package bugs:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/release.debian.org&quot;&gt;release.debian.org&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;opened &lt;a href=&quot;https://bugs.debian.org/1135902&quot;&gt;#1135902: trixie-pu: package initramfs-tools/0.148.4&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;Mailing lists:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-boot/&quot;&gt;debian-boot&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lists.debian.org/0f7a0a1aa33ec586ffa950d784641b0e76e380e9.camel@decadent.org.uk&quot;&gt;Please add loong64 to Daily/Weekly builds of installer images&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-devel/&quot;&gt;debian-devel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lists.debian.org/3fc99c8b98edf120394c75d7b2fa5929c93da0dc.camel@decadent.org.uk&quot;&gt;Licensing of licenses&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-kernel/&quot;&gt;debian-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/8025d9d8faefba5e7f444cdc82e41ca1c12d7377.camel@decadent.org.uk&quot;&gt;Agenda items for kernel-team meeting on 2026-05-13&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted and replied to &lt;a href=&quot;https://lists.debian.org/7e451300e9129f9a466548a3d0b771b236e1b36b.camel@debian.org&quot;&gt;[RFC] Using SimpleDRM in the initramfs&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lists.debian.org/f1f249b86b6fb7239e43da110f969ab371e1ba56.camel@decadent.org.uk&quot;&gt;[bjarniig@simnet.is: kernel-img.conf.5: warning from “lint”]&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/&quot;&gt;debian-lts-announce&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/afW4eRFSiyEj0t5p@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4560-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/afW4k69tKf_WlndL@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4561-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/af4wE6d14Ow7_e1z@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4572-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/af9UZejc2VrICvbM@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4574-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/aghQTI2_ePQTfgRl@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4587-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/agxj_abMk4ZO7rTj@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4588-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/ahnAg039hP_NAYQZ@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4606-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/ahnBQfl3R3-CGOJ0@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4607-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-hyperv/&quot;&gt;linux-hyperv&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/linux-hyperv/ahQ6xuhSReidmN-3@decadent.org.uk/T/&quot;&gt;[PATCH] uio_hv_generic: Bind to FCopy device by default&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-perf-users/&quot;&gt;linux-perf-users&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted and replied to &lt;a href=&quot;https://lore.kernel.org/linux-perf-users/ag8X7gcDw6jpJsLq@decadent.org.uk/T/&quot;&gt;[PATCH 0/3] Fix out-of-tree build of some tools&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-sh/&quot;&gt;linux-sh&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/linux-sh/afuJTi1IGCgrK_cc@decadent.org.uk/T/&quot;&gt;[PATCH] sh: uaccess: Handle exception on second instruction of __put_user_u64&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-trace-kernel/&quot;&gt;linux-trace-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/linux-trace-kernel/ahMmN4PdsJzr_Va-@decadent.org.uk/T/&quot;&gt;[PATCH RESEND] rtla: Fix output files in source tree&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/netdev/&quot;&gt;netdev&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/netdev/811b31f3373526d1ff60160c2f32ddb359e54c31.camel@decadent.org.uk/T/&quot;&gt;[PATCH net] net: skbuff: propagate shared-frag marker through pskb_copy()&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;(mostly LTS) &lt;a href=&quot;https://lore.kernel.org/stable/&quot;&gt;stable&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/036ef29e143799f9117792463d640916490fa61a.camel@debian.org/T/&quot;&gt;Linux 5.15.205&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/14797eaf17672917e7c62a679de22f3d1e25edf5.camel@decadent.org.uk/T/&quot;&gt;[5.10,5.15] i3c: fix uninitialized variable use in i2c setup&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/3f2908646639f4af8844cb8f5a9b4d2d4f904631.camel@debian.org/T/&quot;&gt;[6.6] fbdev/vt8500lcdfb: Initialize fb_ops with fbdev macros&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/a785911d711bee40be215dad119f9922e014aead.camel@decadent.org.uk/T/&quot;&gt;[6.6] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/1d128ddf72c7c42d47e1348b9dc74f7f829621fd.camel@debian.org/T/&quot;&gt;[6.6] x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/f84e935e26fdb239b473443efeb925bbfbd5b182.camel@decadent.org.uk/T/&quot;&gt;[7.0] perf loongarch: Fix build failure with CONFIG_LIBDW_DWARF_UNWIND&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/daa0df3788560bd8759418d9c333e09c45368aa4.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 002/589] ASoC: SOF: topology: reject invalid vendor array size in token parser&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/56652caf63e8db874a3ebd761ec134c003d4986c.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 027/589] xfrm: Wait for RCU readers during policy netns exit&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/136f03aa6f51bdfecc786e5278f5fd03b4a6966e.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 072/589] media: uvcvideo: Use heuristic to find stream entity&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/ca469f4a22fe4688bbf88c355d074ae5be16a621.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 095/589] ALSA: usb-audio: fix null pointer dereference on pointer cs_desc&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/70620d4eddfa13b0b5333e482bb76d7f4b323114.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 096/589] scsi: ufs: core: Improve SCSI abort handling&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahghwxSf9me8PHM4@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 1/2] Revert “RDMA/rxe: Fix double free in rxe_srq_from_init”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/866e188244055e8b90d632cb82e2badb40946706.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 101/589] rxrpc: Fix key quota calculation for multitoken keys&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/b7871589afa5bc3668b07550b9e8b69b3a6c15dd.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 114/589] arm64: dts: imx8mq-librem5: Dont mark buck3 as always on&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/203134947f42d331eeb0f19c0849802c044103c7.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 176/589] KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/5903b777c7688dd17f8e4eb173361c80ea0fff46.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 177/589] KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted and replied to &lt;a href=&quot;https://lore.kernel.org/stable/bbee79323cd7836164c92229b0b2ed38b5179353.camel@debian.org/T/&quot;&gt;[PATCH 5.10 2/2] RDMA/rxe: Fix double free in rxe_srq_from_init&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahhcDsPMJ3Cu3J-E@decadent.org.uk/T/&quot;&gt;[PATCH 5.10-5.15] apparmor: validate default DFA states are in bounds&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahg8Ocvb3UFV6Vdl@decadent.org.uk/T/&quot;&gt;[PATCH 5.10-6.1] fbdev: vt8500lcdfb: Fix dma_free_coherent() cpu_addr parameter&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahhd83m8AruYGvOc@decadent.org.uk/T/&quot;&gt;[PATCH 5.10-6.1] x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/ece62fc01497ee5b8bb7e272a0f6474e89c8e7b2.camel@debian.org/T/&quot;&gt;[PATCH 5.10] Revert “s390/cio: Fix device lifecycle handling in css_alloc_subchannel()”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahVuMv5SLjHVUbkt@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] Revert “s390/cio: Fix device lifecycle handling in css_alloc_subchannel()”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahC38RZJN2O3Ur0R@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] net: skbuff: preserve shared-frag marker during coalescing&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahC4qNfoeifA-enJ@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahg-Lvu0ywzUT9mZ@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] phy: renesas: rcar-gen3-usb2: Fix msleep() in atomic context&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgnK2FarjRafL_J@decadent.org.uk/T/&quot;&gt;[PATCH 5.10] selftests: forwarding: lib: Add helpers for checksum handling&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgiBNbwo7FudH9r@decadent.org.uk/T/&quot;&gt;[PATCH 5.15 1/2] Revert “RDMA/rxe: Fix double free in rxe_srq_from_init”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgjFad4eiurr6KR@decadent.org.uk/T/&quot;&gt;[PATCH 5.15 2/2] RDMA/rxe: Fix double free in rxe_srq_from_init&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/a26366c3a1b70db57fc27f2ad4ef4f21185ebc9c.camel@debian.org/T/&quot;&gt;[PATCH 5.15.y] net: usb: lan78xx: Fix double free issue with interrupt buffer allocation&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahCyf28nWFO49oDZ@decadent.org.uk/T/&quot;&gt;[PATCH 5.15] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgn9yc4SFsqMAWq@decadent.org.uk/T/&quot;&gt;[PATCH 5.15] selftests: forwarding: lib: Add helpers for checksum handling&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgjTfDry_UjKgYs@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 1/2] Revert “RDMA/rxe: Fix double free in rxe_srq_from_init”&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgjYxBbXlUjlFUz@decadent.org.uk/T/&quot;&gt;[PATCH 6.1 2/2] RDMA/rxe: Fix double free in rxe_srq_from_init&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahhcYci93VUlA_f2@decadent.org.uk/T/&quot;&gt;[PATCH 6.1] apparmor: validate default DFA states are in bounds&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahCqJlqexPCiB0P9@decadent.org.uk/T/&quot;&gt;[PATCH 6.1] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahgoDv7vIhnWbeGJ@decadent.org.uk/T/&quot;&gt;[PATCH 6.1] selftests: forwarding: lib: Add helpers for checksum handling&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/ahFmF_XkUzOHBMnC@decadent.org.uk/T/&quot;&gt;[PATCH 6.6] net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/811b31f3373526d1ff60160c2f32ddb359e54c31.camel@decadent.org.uk/T/&quot;&gt;[PATCH net] net: skbuff: propagate shared-frag marker through pskb_copy()&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/afo6uBv68GDevbMD@decadent.org.uk/T/&quot;&gt;[PATCH] parport: Fix race between port and client registration&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-06-02T14:17:21+00:00</dc:date>
	<dc:creator>Ben Hutchings</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/nvim-%C2%B5wiki/">
	<title>Jonathan Dowland: nvim-µwiki</title>
	<link>https://jmtd.net/log/nvim-µwiki/</link>
     <content:encoded>&lt;p&gt;In January 2025,
as a pre-requisite for something else, I published a minimal &lt;a href=&quot;https://jmtd.net/log/neovim/&quot;&gt;neovim&lt;/a&gt;
plugin called &lt;a href=&quot;https://github.com/jmtd/nvim-microwiki&quot;&gt;nvim-µwiki&lt;/a&gt;. It&#39;s essentially just the features from
&lt;a href=&quot;https://jmtd.net/log/vimwiki/&quot;&gt;vimwiki&lt;/a&gt; that I regularly use, which is a small fraction them.
I forgot to blog about it. I recently dusted it off and cleaned it up.
You can find it here, along with a longer list of its features and
how to configure it: &lt;a href=&quot;https://github.com/jmtd/nvim-microwiki&quot;&gt;https://github.com/jmtd/nvim-microwiki&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I had a couple of design goals. I didn&#39;t want to define a new &lt;code&gt;filetype&lt;/code&gt;,
so this is designed to work with the existing markdown one. I&#39;m
using neovim, so I wanted to leverage some of its features: this plugin
is written in &lt;a href=&quot;https://jmtd.net/lua/&quot;&gt;Lua&lt;/a&gt;, rather than vimscript. I use the parse trees
provided by &lt;a href=&quot;https://neovim.io/doc/user/treesitter.html&quot;&gt;TreeSitter&lt;/a&gt; to navigate the structure of a document.
I also decided to &quot;plug into&quot; the existing tag stack navigation, rather
than define another dimension of navigation (along with buffers, etc.)
to track: Following a wiki-link pushes onto the tag stack, just as if
you followed a tag.&lt;/p&gt;

&lt;p&gt;This was my first serious bit of &lt;a href=&quot;https://jmtd.net/lua/&quot;&gt;Lua&lt;/a&gt; programming, as well as my first
dive into neovim (or even vim) internals.
&lt;a href=&quot;https://jmtd.net/lua/&quot;&gt;Lua&lt;/a&gt; is quite reasonable. Most
of the vim and neovim architecture is reasonable. The emerging conventions
about structuring neovim plugins are mostly reasonable. TreeSitter is, well,
interesting, but the devil is very much in the details. Somehow all
together the experience for me was largely just frustrating, and I didn&#39;t
really enjoy writing it.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-05-28T08:48:46+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 

</rdf:RDF>
