<?xml version="1.0"?>
<rdf:RDF
	xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:foaf="http://xmlns.com/foaf/0.1/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns="http://purl.org/rss/1.0/"
>
<channel rdf:about="https://planet.debian.org/">
	<title>Planet Debian</title>
	<link>https://planet.debian.org/</link>
	<description>Planet Debian - https://planet.debian.org/</description>

	<items>
		<rdf:Seq> 
		  <rdf:li rdf:resource="http://blog.alteholz.eu/?p=2842"/>
		  <rdf:li rdf:resource="https://diffoscope.org/news/diffoscope-327-released/"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-08-06:/2026/08/debconf26-closes.html"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6267"/>
		  <rdf:li rdf:resource="https://gwolf.org/2026/08/subscription-bombing-email-under-attack.html"/>
		  <rdf:li rdf:resource="https://k1024.org/posts/2026/2026-08-05-yes-yes-still-alive/"/>
		  <rdf:li rdf:resource="http://www.enricozini.org/blog/2026/debian/gnome-refusing-to-suspend"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6264"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/08/04#058_fast_easy_reliable_reverse_dependency_checks"/>
		  <rdf:li rdf:resource="http://www.hungry.com/~pere/blog/FreeCAD_MCP_with_llama_cpp__toy_or_tool_.html"/>
		  <rdf:li rdf:resource="http://www.netfort.gr.jp/~dancer/diary/daily/2026-Aug-4.html.en#2026-Aug-4-07:03:26"/>
		  <rdf:li rdf:resource="http://blog.brlink.eu/index.html#i72"/>
		  <rdf:li rdf:resource="https://changelog.complete.org/?p=44456"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/journal/2026-08/001.html"/>
		  <rdf:li rdf:resource="https://www.decadent.org.uk/ben/blog/2026/08/02/foss-activity-in-july-2026"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6260"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/0-7564-1949-2.html"/>
		  <rdf:li rdf:resource="https://xana.scru.org/posts/bamamba/lekkerderworst.html"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6257"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/9798360228431.html"/>
		  <rdf:li rdf:resource="https://www.earth.li/~noodles/blog/2026/07/my-cpu-died.html"/>
		  <rdf:li rdf:resource="https://optimizedbyotto.com/post/estonia-well-governed-country/"/>
		  <rdf:li rdf:resource="https://xana.scru.org/posts/mintings/mergetooling.html"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/0-9863735-1-6.html"/>
		  <rdf:li rdf:resource="https://diffoscope.org/news/diffoscope-326-released/"/>
		  <rdf:li rdf:resource="http://joeyh.name/blog/entry/my_harddrive_is_probably_not_full/"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/9798837010774.html"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/07/28#rcppdate_0.0.7"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/07/27#057_conditionally_quieten_compilers"/>
		  <rdf:li rdf:resource="https://jonathancarter.org/?p=12034"/>
		  <rdf:li rdf:resource="https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/index.html"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/07/25#rcpparmadillo_15.4.2-1"/>
		  <rdf:li rdf:resource="http://00formicapunk00.wordpress.com/?p=344"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6244"/>
		  <rdf:li rdf:resource="https://www.freexian.com/blog/debian-lts-report-2026-06/"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/07/21#qlcal-r_0.1.3"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/interzone/digital/"/>
		  <rdf:li rdf:resource="https://retout.co.uk/2026/07/20/renewal-relationships-between-aws-certifications/"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-07-20:/2026/07/debconf26-starts-today.html"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-07-18:/2026/07/debconf26-welcomes-sponsors.html"/>
		  <rdf:li rdf:resource="tag:www.sergiocipriano.com,2026-07-17:posts/running-gui-in-incus.md"/>
		  <rdf:li rdf:resource="https://diffoscope.org/news/diffoscope-325-released/"/>
		  <rdf:li rdf:resource="http://blog.sesse.net/blog/tech/2026-07-15-08-45_looking_at_dpkg_startup_time.html"/>
		  <rdf:li rdf:resource="https://www.freexian.com/blog/debian-contributions-06-2026/"/>
		  <rdf:li rdf:resource="https://gwolf.org/2026/07/got-your-keys-ready-for-debconf26.html"/>
		  <rdf:li rdf:resource="https://blog.freesources.org//posts/2026/07/zed-xdebug/"/>
		  <rdf:li rdf:resource="hatenablog://entry/14945776032052860672"/>
		  <rdf:li rdf:resource="tag:copyninja.in,2026-07-21:/blog/debvulns-exporter.html"/>
		  <rdf:li rdf:resource="https://reproducible-builds.org/reports/2026-06/"/>
		  <rdf:li rdf:resource="https://current.workingdirectory.net/posts/2026/dns-high-availability/"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/fly30/"/>
		  <rdf:li rdf:resource="https://retout.co.uk/2026/07/10/blocking-distracting-news-links/"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-07-10:/2026/07/new-developers-2026-07.html"/>
		  <rdf:li rdf:resource="https://diffoscope.org/news/diffoscope-324-released/"/>
		  <rdf:li rdf:resource="https://blog.trueelena.org/blog/2026/07/10-cockades/index.html"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/synths/minilogue-xd/module/"/>
		  <rdf:li rdf:resource="http://blog.alteholz.eu/?p=2832"/>
		  <rdf:li rdf:resource="http://aigarius.com/blog/2026/07/05/making-of-group-photo/"/>
		  <rdf:li rdf:resource="https://bisco.org/notes/status-update-june-2026/"/>
		  <rdf:li rdf:resource="http://blog.sesse.net/blog/tech/2026-07-04-15-21_an_update_on_sesse_chromium_org.html"/>
		</rdf:Seq>
	</items>
</channel>


<item rdf:about="http://blog.alteholz.eu/?p=2842">
	<title>Thorsten Alteholz: My Debian Activities in July 2026</title>
	<link>http://blog.alteholz.eu/2026/08/my-debian-activities-in-july-2026/</link>
     <content:encoded>&lt;h3&gt;&lt;strong&gt;Debian LTS/ELTS&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This was my hundred-forty-fifth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
&lt;/p&gt;
&lt;p&gt;
During my allocated time I uploaded or worked on:  
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-security-announce/2026/msg00313.html&quot;&gt;DSA 6402-1&lt;/a&gt;] hplip security update to fix two CVEs in Trixie related to privilege escalation and/or arbitrary code execution. I sent the debdiff to the security team, which resulted in this DSA.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142351&quot;&gt;#1142351&lt;/a&gt;] trixie-pu of libnfs has been uploaded.&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/07/msg00031.html&quot;&gt;DLA 4689-1&lt;/a&gt;]  libnfs security update to fix one CVE in Bookworm and Bullseye related to an integer overflow.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/07/msg00041.html&quot;&gt;DLA 4699-1&lt;/a&gt;] hplip security update to fix two CVEs in Bookworm and Bullseye related to privilege escalation and/or arbitrary code execution.
&lt;/li&gt;&lt;li&gt;[ELA-1775-1] libnfs gimp security update to fix one CVE in Buster and Stretch related to an integer overflow.&lt;/li&gt;&lt;li&gt;[ELA-1784-1] hplip security update to fix two CVEs in Buster and Stretch related to privilege escalation and/or arbitrary code execution.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;
Unfortunately the number of assigned hours was rather low this month. So besides doing some days of FD at the end of the month, where I also had to process a new package list for ELTS, and a review of the rsync package (prepared by Sylvain), not much happened here.
&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Printing&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream versions:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/hplip&quot;&gt;hplip&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/foomatic-db&quot;&gt;foomatic-db&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;Besides the package upload, I also took care of some older bugs of hplip.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://www.freexian.com&quot;&gt;Freexian&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Lomiri&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This month I continued the upload of lomiri packages with new upstream versions. Thanks to the help of my other colleagues, this project could be finished now.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://freiesoftware.gmbh/&quot;&gt;Fre(i)e Software GmbH&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Astro&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/fxload&quot;&gt;fxload&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/indi-orion-ssg3&quot;&gt;indi-orion-ssg3&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/calceph&quot;&gt;calceph&lt;/a&gt; to unstable (sponsored upload).&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;Debian IoT&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;Unfortunately I had no time to work in this category this month.&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Mobcom&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/libgsm&quot;&gt;libgsm&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/libosmocore&quot;&gt;libosmocore&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/libosmo-cc&quot;&gt;libosmo-cc&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;Next month I intend to upload new upstream versions of all Osmocom packages. As far as I can tell, these uploads will happen without soname changes. I like that :-).&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;misc&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/usb-modeswitch&quot;&gt;usb-modeswitch&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/ta-lib&quot;&gt;ta-lib&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/lua-geoip&quot;&gt;lua-geoip&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/lua-systemd&quot;&gt;lua-systemd&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/displaylink-driver&quot;&gt;displaylink-driver&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/nuspell&quot;&gt;nuspell&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-07T17:02:01+00:00</dc:date>
	<dc:creator>alteholz</dc:creator>
</item> 
<item rdf:about="https://diffoscope.org/news/diffoscope-327-released/">
	<title>Reproducible Builds (diffoscope): diffoscope 327 released</title>
	<link>https://diffoscope.org/news/diffoscope-327-released/</link>
     <content:encoded>&lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;327&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[ Colin Watson ]
* Handle missing openssh-client binaries in autopkgtests.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href=&quot;https://diffoscope.org&quot;&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-07T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds (diffoscope)</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-08-06:/2026/08/debconf26-closes.html">
	<title>Bits from Debian: DebConf26 closes in Santa Fe and DebConf27 announced</title>
	<link>https://bits.debian.org/2026/08/debconf26-closes.html</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://wiki.debian.org/DebConf/26/Photos?action=AttachFile&amp;amp;do=view&amp;amp;target=debconf26-group-photo.jpg&quot;&gt;&lt;img alt=&quot;DebConf26 group photo - click to enlarge&quot; src=&quot;https://bits.debian.org/images/debconf26-group-photo_small.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;On Saturday 25 July 2026, the annual &lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;Debian Developers and Contributors
Conference&lt;/a&gt; came to a close.
Over 270 attendees representing 35 countries from around the world came
together for a combined 90 events (including some which took place during
the DebCamp) including more than 27 Talks, 21 Short Talks,
29 Birds of a Feather sessions (&quot;BoF&quot; – informal meeting between developers
and users), 8 workshops, and activities in support of furthering our
distribution and free software, learning from our mentors and peers, building
our community, and having a bit of fun.&lt;/p&gt;
&lt;p&gt;The conference was preceded by the annual
&lt;a href=&quot;https://wiki.debian.org/DebCamp&quot;&gt;DebCamp&lt;/a&gt; hacking session held 13
through 19 July where Debian Developers and Contributors convened to
focus on their individual Debian-related projects or work in team sprints
geared toward in-person collaboration in developing Debian.&lt;/p&gt;
&lt;p&gt;As has been the case for several years, a special effort has been made to
welcome newcomers and help them become familiar with Debian and DebConf
by organizing a sprint &quot;New Contributors Onboarding&quot; every day of Debcamp,
followed more informally by mentorship during DebConf. Half a dozen new
contributors joined the sessions and learned about Debian, free software,
packaging and much more.&lt;/p&gt;
&lt;p&gt;This year, a week-long DebCamp session was dedicated to auditing,
patching, and modernizing the Go ecosystem in Debian and enable the
transition triggered by the recent upload of dh-golang enabling GO111MODULE=on
by default in Experimental.&lt;/p&gt;
&lt;p&gt;In order to make the conference more accessible for local participants,
a local language track was included in the schedule for talks in Spanish,
as was done at DebConf19 in Brazil.&lt;/p&gt;
&lt;p&gt;The actual Debian Developers Conference started on Monday 20 July 2026.&lt;/p&gt;
&lt;p&gt;In addition to the traditional &quot;Bits from the DPL&quot; talk, the continuous
key-signing party, lightning talks, and the announcement of next year&#39;s
DebConf27, there were several update sessions shared by internal projects
and teams.&lt;/p&gt;
&lt;p&gt;Many of the hosted discussion sessions were presented by our technical
core teams with the usual and useful &quot;Meet the Technical Committee&quot;, three
talks about Linux Kernel, early boot and improving Debian’s kernel and
installer support for Chromebooks, and about twenty BoFs and talks about
Debian packaging policy, Debian infrastructure, security and privacy.&lt;/p&gt;
&lt;p&gt;This year, and echoing ongoing discussions within the Free Software community,
Artificial Intelligence and Age Verification have been the subject of
several talks. The Python, Perl, Ruby, Go, and Rust programming
language teams also shared updates on their work and efforts.&lt;/p&gt;
&lt;p&gt;More than 17 BoFs and talks about community, diversity, and local outreach
highlighted the work of various teams involved in not just the technical but
also the social aspect of our community&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://debconf26.debconf.org/schedule/&quot;&gt;schedule&lt;/a&gt;
was updated each day with planned and ad hoc activities introduced by
attendees over the course of the conference. Several traditional activities
took place: a poetry performance, the traditional Cheese and Wine party, the
Group Photos, and the Day Trip.&lt;/p&gt;
&lt;p&gt;For those who were not able to attend, most of the talks and sessions were
broadcasted live and recorded. One can find the seventy hours of recorded
videos available via the conference
&lt;a href=&quot;https://debconf26.debconf.org/schedule/&quot;&gt;schedule&lt;/a&gt;,
or alternatively through this
&lt;a href=&quot;https://meetings-archive.debian.net/pub/debian-meetings/2026/DebConf26/&quot;&gt;link&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Almost all of the sessions facilitated remote participation via IRC and Matrix
messaging apps or online collaborative text documents which allowed remote
attendees to &quot;be in the room&quot; and ask questions or share comments with the
speaker or assembled audience. DebConf26 saw over 341 T-shirts, a day trip,
and up to 130 meals planned per day.&lt;/p&gt;
&lt;p&gt;All of these events, activities, conversations, and streams coupled with our
love, interest, and participation in Debian and F/OSS certainly made this
conference an overall success both here in Santa Fe, Argentina and online
around the world.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf26 website&lt;/a&gt;
will remain active for archival purposes and will continue to offer
links to the presentations and videos of talks and events.&lt;/p&gt;
&lt;p&gt;Next year, &lt;a href=&quot;https://wiki.debian.org/DebConf/27&quot;&gt;DebConf27&lt;/a&gt; will be held
in Asahikawa, Hokkaido, Japan, from Sunday September 5th to Saturday
September 11th, 2027. As tradition follows before the next DebConf the
local organizers in Japan will start the conference activities with DebCamp
with a particular focus on individual and team work towards improving the
distribution.&lt;/p&gt;
&lt;p&gt;DebConf is committed to a safe and welcome environment for all
participants. See the
&lt;a href=&quot;https://debconf26.debconf.org/about/coc/&quot;&gt;web page about the Code of Conduct on the DebConf26 website&lt;/a&gt;
for more details on this.&lt;/p&gt;
&lt;p&gt;Debian thanks the commitment of numerous
&lt;a href=&quot;https://debconf26.debconf.org/sponsors/&quot;&gt;sponsors&lt;/a&gt;
to support DebConf26, particularly our Platinum Sponsors:
&lt;a href=&quot;https://www.infomaniak.com&quot;&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt;, and
&lt;a href=&quot;https://www.proxmox.com/&quot;&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt;,
and our Gold Sponsors : &lt;a href=&quot;https://www.freexian.com/&quot;&gt;&lt;strong&gt;Freexian&lt;/strong&gt;&lt;/a&gt;, and
&lt;a href=&quot;https://www.viridiengroup.com&quot;&gt;&lt;strong&gt;Viridien&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We also wish to thank our Video and Infrastructure teams, the DebConf26
and DebConf committees, our host nation of Argentina, and each and every
person who helped contribute to this event and to Debian overall.
Thank you all for your work in helping Debian continue to be &quot;The Universal
Operating System&quot;.&lt;/p&gt;
&lt;p&gt;See you next year!&lt;/p&gt;
&lt;h3&gt;About Debian&lt;/h3&gt;
&lt;p&gt;The Debian Project was founded in 1993 by Ian Murdock to be a truly free
community project. Since then the project has grown to be one of the
largest and most influential Open Source projects. Thousands of
volunteers from all over the world work together to create and maintain
Debian software. Available in 70 languages, and supporting a huge range
of computer types, Debian calls itself the &lt;em&gt;universal operating system&lt;/em&gt;.&lt;/p&gt;
&lt;h3&gt;About DebConf&lt;/h3&gt;
&lt;p&gt;DebConf is the Debian Project&#39;s developer conference. In addition to a
full schedule of technical, social and policy talks, DebConf provides an
opportunity for developers, contributors and other interested people to
meet in person and work together more closely. It has taken place
annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina,
India, Korea, France. More information about DebConf is available from
&lt;a href=&quot;https://debconf.org&quot;&gt;https://debconf.org/&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;About Infomaniak&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://www.infomaniak.com&quot;&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt; is an independent, employee-owned
Swiss technology company that designs, develops, and operates its own cloud
infrastructure and digital services entirely in Switzerland. With over
300 employees — more than 70% engineers and developers — the company reinvests
all profits into R&amp;amp;D. Its public cloud is built on OpenStack, with managed
Kubernetes, Database as a Service, object storage, and sovereign AI services
accessible via OpenAI-compatible APIs, all running on its own Swiss
infrastructure. Infomaniak also develops a sovereign collaborative suite —
messaging, email, storage, online office tools, videoconferencing, and a
built-in AI assistant — developed in-house and as a privacy-respecting
solution to proprietary platforms. Open source is central to how Infomaniak
operates. Its latest data center (D4) runs on 100% renewable energy and uses
no traditional cooling: all the heat generated by its servers is captured and
fed into Geneva&#39;s district heating network, supplying up to 6,000 homes in
winter and hot water year-round. The entire project has been documented and
open-sourced at &lt;a href=&quot;https://d4project.org/&quot;&gt;d4project.org&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;About Proxmox&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://www.proxmox.com/&quot;&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt; develops powerful, yet easy-to-use
open-source server solutions. The comprehensive open-source ecosystem is
designed to manage divers IT landscapes, from single servers to large-scale
distributed data centers. Our unified platform integrates server
virtualization, easy backup, and rock-solid email security ensuring seamless
interoperability across the entire portfolio. With the Proxmox Datacenter
Manager, the ecosystem also offers a &quot;single pane of glass&quot; for centralized
management across different locations. Since 2005, all Proxmox solutions have
been built on the rock-solid Debian platform. We are proud to return to
DebConf26 as a sponsor because the Debian community provides the foundation
that makes our work possible. We believe in keeping IT simple, open, and under
your control.&lt;/p&gt;
&lt;h3&gt;Contact Information&lt;/h3&gt;
&lt;p&gt;For further information, please visit the DebConf26 web page at
&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;https://debconf26.debconf.org/&lt;/a&gt; or send
mail to &lt;a href=&quot;https://bits.debian.org/feeds/mailto:press@debian.org&quot;&gt;press@debian.org&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-06T21:50:00+00:00</dc:date>
	<dc:creator>Debian Publicity Team and Volunteers</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6267">
	<title>Russell Coker: TV Control etc</title>
	<link>https://etbe.coker.com.au/2026/08/06/tv-control-etc/</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&quot;&gt;In 2008 I wrote a blog post “The Problem is Too Many Remote Controls” [1]&lt;/a&gt; about the issues of controlling a TV and related things. It recently got some comments on Mastodon so I think it’s time for an update.&lt;/p&gt;
&lt;p&gt;The first issue I raised was “Now it’s not uncommon to have separate remote controls for the TV, VCR, DVD player, and the Cable TV box – a total of four remote controls” which seems to have alleviated. VCRs seem to have almost entirely gone away. The &lt;a href=&quot;https://en.wikipedia.org/wiki/VHS&quot;&gt;VHS Wikipedia page [2]&lt;/a&gt; is worth reading for everyone who hasn’t seen a VCR in operation, which I expect to be more than a few readers now and an increasing number over the next 18 years. I personally don’t have Cable TV, I own a DVD player which isn’t connected to my TV because I haven’t used it for years, I don’t own a VCR, and I don’t watch free to air TV. So I have one remote control for the TV which I use for Netflix and sometimes YouTube.&lt;/p&gt;
&lt;p&gt;When viewing YouTube on TV there are significantly more adverts and longer adverts. I presume that is because installing an ad-blocker on my TV isn’t a viable option for me and it’s a total impossibility for most users. Generally my desktop PC is a much better platform for YouTube than my TV, it has a better quality display, is more user friendly (my previous post addressed the difficulty of getting to the data source that’s desired), and doesn’t require entering search terms via a slow on-screen keyboard. Netflix on Linux is limited to 720p at low bitrate which is obviously of low visual quality while on the TV it’s in 4K. I have Netflix so I use that only on the TV.&lt;/p&gt;
&lt;p&gt;In my previous post I wrote a thought experiment on how to use a cheap laptop ($500 at the time – equivalent to $777 in 2025 money according to the Reserve Bank of Australia) to control a $5000 TV ($7770 in 2025 money). Now you can buy a new 65″ 4K TV for under $800 and a new laptop capable of 4K output for under $400 so the options are very different. For a $800 TV the manufacturer isn’t going to develop a remote control interface and Google (who develops the software the TVs run) won’t do it because it could reduce their advertising revenue. But a typical home user could setup a cheap laptop connected to their TV via HDMI providing a familiar and efficient user interface for themselves and visitors. For a Windows laptop 4K Netflix should work and for a Linux laptop the options of a laptop for everything apart from Netflix and the TV for Netflix are bearable, two controls are worse than one but better than the 3+ that used to be common.&lt;/p&gt;
&lt;p&gt;In my previous post I raised the issue that “it’s often the case that you don’t want to stop watching one show while trying to find another”. This is still an unsolved problem and is not addressed in modern software. I am not aware of a Linux music player that supports such functionality and this would be much easier for a music player than for a video player where the screen would have to be shared between the interface for finding the next thing to play and the space for playing the end of the current one. Maybe I should file a bunch of wishlist bugs against music players asking for this.&lt;/p&gt;
&lt;p&gt;I suggested that “cable modem” and “cable TV box” could be integrated into a single device. That has not happened, in fact it’s got worse. A relative who has Foxtel has a cable modem, a cable TV box, and a Wifi AP with VOIP to provide landline phone service and to make it more exciting the latter two both have bugs that require a periodic hardware reset to fix. Hopefully cable TV will go away in the next 18 years.&lt;/p&gt;
&lt;p&gt;Regular PCs have become less noisy in recent years. I am currently using a HP Z640 to write this post and I have HP Z840 and HP Z4G4 systems behind me running as servers and the background noise is still very low. The &lt;a href=&quot;https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/&quot;&gt;allegedly 8K TV [3]&lt;/a&gt; that I have in my lounge room has cooling fans that make more noise than those three high-end HP computers combined. Using a quiet PC like one of those HP systems to drive a TV is a very viable option and I did just that for a couple of years. Kogan has currently got a selection of refurbished Lenovo ThinkStation systems on sale for under $400, they are quiet and would do well for this, it’s also nice that Kogan is selling systems with ECC RAM at home user prices.&lt;/p&gt;
&lt;p&gt;TV does seem to be going away. YouTube and streaming services seem to get more watching time and many people don’t use TV at all.&lt;/p&gt;
&lt;p&gt;Since my previous post the number of streaming services has increased so torrenting offers increasing benefits as no-one wants to subscribe to 6+ services. For anyone who wants to get all the content that interests them while paying the user interface situation is much worse now than it used to be in 2008.&lt;/p&gt;
&lt;p&gt;If you use KDE on a PC then the &lt;b&gt;kconnect&lt;/b&gt; program allows a phone to be used to remotely control some aspects of a PC and has a good interface for pause/resume of a video and seeking 10 seconds forwards/backwards. The interface for controlling volume is hard to get to and doesn’t work on my installation. If you want to use a keyboard to start something playing and then a phone for pause control then kdeconnect is a decent option. A comment on my previous post by Michael Croes raised the issue of remote control which is now a solvable problem. Justin also wrote a comment suggesting a Nokia N800 as a remote.&lt;/p&gt;
&lt;p&gt;Jason suggested a programmable remote, which would be a good option for a power user and a viable option for someone setting things up for their grandparents. But the amount of pain is greater than I’m interested in as lounge room TV isn’t an important thing to me. It may appeal to more people than having a dedicated lounge room PC though.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&quot;&gt; https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://en.wikipedia.org/wiki/VHS&quot;&gt; https://en.wikipedia.org/wiki/VHS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href=&quot;https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/&quot;&gt; https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2021/06/06/netflix-ipv6/&quot; rel=&quot;bookmark&quot; title=&quot;Netflix and IPv6&quot;&gt;Netflix and IPv6&lt;/a&gt; &lt;small&gt;It seems that Netflix has an ongoing issue of not...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2022/01/04/big-smart-tvs/&quot; rel=&quot;bookmark&quot; title=&quot;Big Smart TVs&quot;&gt;Big Smart TVs&lt;/a&gt; &lt;small&gt;Recently a relative who owned a 50″ Plasma TV asked...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&quot; rel=&quot;bookmark&quot; title=&quot;The Problem is Too Many Remote Controls&quot;&gt;The Problem is Too Many Remote Controls&lt;/a&gt; &lt;small&gt;I am often asked for advice about purchasing TVs and...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-08-06T04:01:37+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://gwolf.org/2026/08/subscription-bombing-email-under-attack.html">
	<title>Gunnar Wolf: Subscription Bombing • Email under Attack</title>
	<link>https://gwolf.org/2026/08/subscription-bombing-email-under-attack.html</link>
     <content:encoded>&lt;blockquote&gt;
		 
		   This post is an &lt;em&gt;unpublished&lt;/em&gt; review
		 
		     
		       
		         for &lt;em&gt;&lt;a href=&quot;https://dl.acm.org/doi/full/10.1145/3797487&quot;&gt;Subscription Bombing • Email under Attack&lt;/a&gt;&lt;/em&gt;
		       
		     
		     
		   &lt;/blockquote&gt;
		 
		 &lt;p&gt;One of the most important inputs one can have when designing a response
strategy against a security attack is a good characterization. This article
describes a relatively newly described attack mode (subscription bombing),
hypothetizes on the motivations that can lie behind it, and presents some
countermeasures that can be taken by different actors to reduce its impact.&lt;/p&gt;

&lt;p&gt;At its core, suscription bombing is a classical reflection attack: it uses
a third party service so that the answer to a relatively simple request is
amplified and results in a distributed denial of service (DDoS) for the
victim. And, as with most DDoS attacks, its effectivity lies in that there
is not much a person can do against traffic coming from seemingly random
different providers all around the world.&lt;/p&gt;

&lt;p&gt;The core differentiatof for subscription bombing is that the attack’s
victim is not a network port, but an individual’s e-mail address. The
attacker builds a database of service providers that allow interested users
to sign up for newsletter on their activities, or a mailing list, or even
just to create a new account on a given Web system. This action will
generate a (seemingly legitimate) confirmation mail sent to the victim. But
the attacker scripts together hundreds of thousands of such request,
creating a deluge of confirmation mails sent to the unsuspecting victim.&lt;/p&gt;

&lt;p&gt;The authors explain the goals an attacker might pursue by performing this
kind of attack. They suppose this can be due to harassment (a disgruntled
employee being denied a salary raise, a political adversary, or even a
romantic ex-partner wanting to inconvenience the victim’s use of their
e-mail). More worryingly, the attack can be used as a distraction: by
sending a high volume of mails in a controlled timeframe, the attacker can
reduce the probability of the victim noticing a specific attack warning
them of, i.e., financial fraud, unwanted purchases, or break-in attempts
into their accounts. Attacks targetting mailboxes at private mail servers
can also lead to overloading an account’s limit, causing it to reject
mails after the attack is delivered and before the folder is cleaned. And
it can also pave the way for follow-up, targetted deception attacks, where
the attackers call the victim pretending to be the company’s IT department,
and get them to install a remote desktop monitoring and management tool,
with which they can effectively seize control of the victim’s data.&lt;/p&gt;

&lt;p&gt;To do this, they present a study they made over 24 cases of victims, from
which 47,970 total e-mails were received between October and December 2024,
with individual attacks receiving between 81 and 3,387 e-mails per hour,
from where they presented several descriptive analysis.&lt;/p&gt;

&lt;p&gt;The authors explored cyber criminal’s offers on underground websites,
comparing flooding services and pricing schemes.&lt;/p&gt;

&lt;p&gt;Finally, mitigation strategies are discussed. Mitigation is quite
problematic, as none of the mail servers is acting in either a hostile way
or lacking permissions — they are performing just the task they should. The
authors suggest four mitigation strategies for mail server operators to
reduce the burden on their users, although none of them is easily
automatizab (rate-limit the number of emails a given inbox can receive from
previously unseen senders; educate users about this kind of attacks; group
similar newsletter or account reset mails during active attacks; and
automatically unsubscribe or bounce newsletter messages when a surge is
detected). They also recommend newsletter providers and services accepting
the unrestricted creation of user accounts to provide some hardening to
increase the effort wrongdoers need to spend to abuse their services, such
as requiring CAPTCHAs or requiring users to take several steps before
requesting a subscription, although they recognize this adds friction to
the process providers are most interested in providing; filtering and
triaging known-good and known-bad domains, although this is hard to
implement on a preemptive fashion, and adhering to easy unsubscription
standards, such as easily identifiable headers with which mass
unsubscription could be performed more easily victims, instead of hunting
for the right places to click, potentially even in mails written in an
unknown language.&lt;/p&gt;

&lt;p&gt;The described problem is interesting, and properly tackling it can be a
game changer for many users who will suffer this kind of abuse, and the
article is easy to read and soundly supports its claims.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-06T00:17:35+00:00</dc:date>
	<dc:creator>Gunnar Wolf</dc:creator>
</item> 
<item rdf:about="https://k1024.org/posts/2026/2026-08-05-yes-yes-still-alive/">
	<title>Iustin Pop: Yes-yes, still alive!</title>
	<link>https://k1024.org/posts/2026/2026-08-05-yes-yes-still-alive/</link>
     <content:encoded>&lt;p&gt;I am not sure what happened, but my interests have changed significantly, and… I
haven’t blogged, I haven’t done any open source work, and didn’t even process
any pictures for the entire year. Not because anything went bad, just… new
stuff, new interests, life changes.&lt;/p&gt;
&lt;p&gt;However, still alive, and still struggling with sports, and with sleep :)&lt;/p&gt;
&lt;p&gt;On the positive side, on a recent mid-length flight, I thought — I haven’t done
any work on Corydalis, since last year I closed quite of a few of my “must have”
features, so probably, nothing else to do for now, right? I opened an editor and
started thinking about ideas, and surprised! One hour later, I had written down
enough ideas for a couple of months of work. So now just need to find the time…
but can’t wait for the planned things!&lt;/p&gt;
&lt;p&gt;Stay well!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-05T17:34:00+00:00</dc:date>
	<dc:creator>Iustin Pop</dc:creator>
</item> 
<item rdf:about="http://www.enricozini.org/blog/2026/debian/gnome-refusing-to-suspend">
	<title>Enrico Zini: Gnome refusing to suspend</title>
	<link>http://www.enricozini.org/blog/2026/debian/gnome-refusing-to-suspend</link>
     <content:encoded>&lt;p&gt;I&#39;m tired, I want to do go bed. I click &quot;sleep&quot; on gnome shell, nothing happens.&lt;/p&gt;
&lt;p&gt;Swearwords.&lt;/p&gt;
&lt;p&gt;I want to go to bed. I might have want to put my laptop in a bag and run to
catch a train. &lt;a href=&quot;https://mastodon.bida.im/@spanezz/117017036756831405&quot;&gt;I hate when this happens&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemd-inhibit --list --mode=block&lt;/code&gt; doesn&#39;t help much:&lt;/p&gt;
&lt;div class=&quot;codehilite&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;systemd-inhibit&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;--list&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;--mode&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;block
WHO&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;UID&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;USER&lt;span class=&quot;w&quot;&gt;   &lt;/span&gt;PID&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;COMM&lt;span class=&quot;w&quot;&gt;            &lt;/span&gt;WHAT&lt;span class=&quot;w&quot;&gt;                                                     &lt;/span&gt;WHY&lt;span class=&quot;w&quot;&gt;                        &lt;/span&gt;MODE
enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1000&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;3042&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gsd-power&lt;span class=&quot;w&quot;&gt;       &lt;/span&gt;handle-lid-switch&lt;span class=&quot;w&quot;&gt;                                        &lt;/span&gt;External&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;monitor&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;attached…&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;block
enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1000&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;3037&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gsd-media-keys&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;handle-power-key:handle-suspend-key:handle-hibernate-key&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;GNOME&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;handling&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;keypresses&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;block
enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1000&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;2878&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gnome-session-b&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;sleep&lt;span class=&quot;w&quot;&gt;                                                    &lt;/span&gt;user&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;session&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;inhibited&lt;span class=&quot;w&quot;&gt;     &lt;/span&gt;block
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;After much googling I found out about &lt;code&gt;gnome-session-inhibit&lt;/code&gt;:&lt;/p&gt;
&lt;div class=&quot;codehilite&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gnome-session-inhibit&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;--list
mutter:&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;idle-inhibit&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;idle&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt;
/usr/lib/chromium/chromium:&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;Playing&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;audio&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;suspend&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Found the right tab in chromium, paused playing, sleep works again.&lt;/p&gt;
&lt;p&gt;My sleep was a good half an hour overdue, and all I got for it was to write
this blog post.&lt;/p&gt;
&lt;p&gt;Of course Gnome could have shown me its inhibitor list instead of doing
nothing, since it has that information, but &lt;a href=&quot;https://discourse.gnome.org/t/why-does-gnome-shell-doesnt-notify-user-about-suspend-being-blocked-by-inhibitor/34077&quot;&gt;it didn&#39;t&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;What I really would expect is that if I intentionally click a suspend button,
audio and video playing wouldn&#39;t inhibit the suspend. Maybe in a future version
of Gnome?&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-05T07:57:52+00:00</dc:date>
	<dc:creator>Enrico Zini</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6264">
	<title>Russell Coker: Monitors for Work</title>
	<link>https://etbe.coker.com.au/2026/08/05/monitors-for-work/</link>
     <content:encoded>&lt;h2&gt;The Corporate Monitor Issue&lt;/h2&gt;
&lt;p&gt;Some time ago I worked in the IT department of a company that had a corporate standard of two 27″ FUllHD (either 1920*1080 or 1920*1200) monitors for the desktop. I was pushing to make the standard be one 32″ 4K monitor or the two cheaper monitors. They ended up making one 27″ 4K monitor an option which was still a better option for many users than two FullHD monitors due to having twice the pixels even though it had half the screen area. It was a surprise to me when hardly anyone took up that option.&lt;/p&gt;
&lt;p&gt;One man who worked there brought a wide curved monitor from home and ran with one of the FullHD monitors on each side of that. As an employee in the IT department I had concerns about expensive personal equipment being used in the office regarding who’s going to pay the bill if it gets broken. But I was assured that it was his old monitor that he didn’t need after buying a better one for gaming at home and he wouldn’t be too upset if something happened to it.&lt;/p&gt;
&lt;p&gt;This isn’t the only time I’ve witnessed such problems of companies paying large salaries for skilled people and providing poor equipment for them to do the work. One previous time I raised a OH&amp;amp;S issue because the outdated monitors were so blurry but the company determined that the monitors wouldn’t cause health problems and spending $150 per employee on better replacements was a waste of money.&lt;/p&gt;
&lt;p&gt;Computer hardware tends to become cheaper over time and one thing that has become really cheap recently is portable monitors. &lt;a href=&quot;https://www.kogan.com/au/buy/kogan-xpresso-156-full-hd-ips-usb-c-portable-monitor-kogan/&quot;&gt;Kogan has a 15.6″ FullHD monitor with USB-C and mini-HDMI inputs for $89 [1]&lt;/a&gt;. It wouldn’t be difficult for someone to put one of those on each side of the monitor or monitors that their employer provides and put them in a desk drawer at the end of the day to minimise risk. The same Kogan page has a 16″ monitor with 2560*1600 resolution for $189.&lt;/p&gt;
&lt;h2&gt;Company Ownership&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&quot;&gt;I previously wrote about the potential benefits to companies in not owning all those keyboards, mice, and headsets when they could just give each employee the money and have them buy their own [2]&lt;/a&gt;. I don’t think we are at the stage where that can be applied to monitors as the cheapest price for a decent monitor is about $500 which takes it out of the disposable price range that keyboards and mice are in. Also from an IT support perspective there are real support issues with monitors and cables having compatibility issues. But paying small amounts of money to reimburse employees who buy cheap portable monitors to supplement their main monitor is a more reasonable option. For some people that will allow noteworthy improvements in work performance.&lt;/p&gt;
&lt;h2&gt;Who Will it Help?&lt;/h2&gt;
&lt;p&gt;I don’t think that adding such portable monitors will directly help the majority of workers. I think that to maximise performance and efficiency we need to chase the long tail of improvements. Big monitors, really big monitors (65″ at a larger distance), multiple monitors, standing desks, and whatever else people want.&lt;/p&gt;
&lt;p&gt;There was some research from Microsoft some years ago (back when 27″ was a really big monitor) showing that some tasks had a 50% increase in performance with a larger monitor. Now that 27″ is about the smallest monitor size commonly available the potential for improvement is reduced. Probably most workers now already have monitors that provide the benefits to them that the “big monitors” in Microsoft research provided. But there will always be some portion of the user base who will benefit. If you can get a 50% performance boost for 1% of the users that’s really worth doing. If you can get a 0.5% benefit for 100% of the users that is also worth doing and will theoretically give equal benefits.&lt;/p&gt;
&lt;h2&gt;Costs of Employees&lt;/h2&gt;
&lt;p&gt;It is claimed that the total cost of an employee including all overheads of management and providing office facilities etc amounts to twice their base salary. If that is the case then a minimum wage employee in Australia costs $100k per year, someone at the low end of the IT pay scale costs $200k, and someone at the high end of the IT scale is around $400k. It seems clearly worthwhile to spend $1000 in hardware purchases for a $100k employee who declares that it will really help their work, anything which is noticeable to the user is going to be more than a 1% difference in performance.&lt;/p&gt;
&lt;p&gt;For someone at the high end of the IT pay scale spending $40,000 on hardware to improve their performance could pay for itself. This is not only due to direct return on investment but because the people who do such work are often in key roles in important projects. If there’s too much work for one person on minimum wage to do then you just hire another person. You can’t hire another senior IT person and have them just do the work, it can take months to get up to speed.&lt;/p&gt;
&lt;p&gt;But as management in corporations seems unable to recognise this cheap hardware employees can afford to buy with their own money can bridge the gap.&lt;/p&gt;
&lt;h2&gt;Job Interviews&lt;/h2&gt;
&lt;p&gt;In future when interviewing for jobs I’ll ask about the hardware that’s to be used. I won’t say “I’m not interested in this job offer because you don’t respect your employees enough to buy adequate hardware”, but I may make it a condition of working at a company that the hardware on my desk will not be obsolete.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://www.kogan.com/au/buy/kogan-xpresso-156-full-hd-ips-usb-c-portable-monitor-kogan/&quot;&gt; https://tinyurl.com/26bdng24&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&quot;&gt; https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&quot; rel=&quot;bookmark&quot; title=&quot;Cheap Peripherals for Work&quot;&gt;Cheap Peripherals for Work&lt;/a&gt; &lt;small&gt;A problem with a lot of the purchase of peripherals...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2007/01/04/monitors-for-developers/&quot; rel=&quot;bookmark&quot; title=&quot;monitors for developers&quot;&gt;monitors for developers&lt;/a&gt; &lt;small&gt;Michael Davies recently blogged that all developers should have big...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2019/11/18/4k-monitors/&quot; rel=&quot;bookmark&quot; title=&quot;4K Monitors&quot;&gt;4K Monitors&lt;/a&gt; &lt;small&gt;A couple of years ago a relative who uses a...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-08-04T22:41:18+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/08/04#058_fast_easy_reliable_reverse_dependency_checks">
	<title>Dirk Eddelbuettel: #058: Reverse Dependencies Made Easy, Fast, Reliable</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/08/04#058_fast_easy_reliable_reverse_dependency_checks</link>
     <content:encoded>&lt;p&gt;Welcome to post 58 in the &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/code/r4&quot;&gt;&lt;span class=&quot;math inline&quot;&gt;&lt;em&gt;R&lt;/em&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/span&gt;&lt;/a&gt; series.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.R-Project.org&quot;&gt;R&lt;/a&gt; and the &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; repositories maintain a very
high level of what we might call “quality assurrance” by requiring that
newly-added code does not break any existing dependencies. This is
frequently called a “reverse-dependency check”. For any given &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; package one can quickly
determine it reverse dependencies. Calling
&lt;code&gt;tools::package_dependencies(pkgName, reverse=TRUE)&lt;/code&gt; will for
a scalar or vector-valued argument return a named list with the reverse
dependencies. It is then a matter of looping over this list. There are
helper functions in base R as well as in contributed packages on and off
&lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;. I also wrote my own with
package &lt;a href=&quot;https://github.com/eddelbuettel/prrd&quot;&gt;prrd&lt;/a&gt; which,
while possibly a wee bit specialised and under-documented has served me
well to check on &lt;a href=&quot;https://github.com/rcppcore/rcpp&quot;&gt;Rcpp&lt;/a&gt; and
related packages which can indeed have a &lt;em&gt;large&lt;/em&gt; number of
reverse dependencies.&lt;/p&gt;
&lt;p&gt;I recently looked into one of these contributed runner packages, and
while I will refrain from naming its implementation language let me just
mention that the term “&lt;code&gt;cargo&lt;/code&gt; cult” may be a real thing
here. What go me interested in this was the fact that &lt;em&gt;if&lt;/em&gt; one
has a simple-to-use runner &lt;em&gt;then&lt;/em&gt; the fact that &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; makes it “fast, easy,
reliable: pick all three” (to borrow its slogan) to deal with actual
depencies if Ubuntu has indeed been selected as the host. We will
maintain the position that &lt;em&gt;if&lt;/em&gt; you can in fact integrate with
the system-wide package management then any alternative per-repo package
management approach not doing so will likely be dominated by an approach
that does integrate with the system facilities. Which is what precisely
what &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; does, and
offers. And why it is used enough to by now have shipped eighty eight
million binary packages. So I tested it for the reverse-dependency check
task.&lt;/p&gt;
&lt;p&gt;What I learned by looking into the (much more complicated) runner was
that it at the end of the day it hands the actual task of running the
reverse dependecies off to a helper function &lt;code&gt;rev_check&lt;/code&gt; that
is part of the &lt;a href=&quot;https://github.com/yihui/xfun&quot;&gt;xfun&lt;/a&gt; package
by Yuhui. I quickly found that besides &lt;a href=&quot;https://github.com/yihui/xfun&quot;&gt;xfun&lt;/a&gt; we would also need its
suggested dependency &lt;a href=&quot;https://github.com/rstudio/tinytex&quot;&gt;tinytex&lt;/a&gt; which in turn
would error unless the &lt;code&gt;tlmgr&lt;/code&gt; binary was present. So as the
sole requirement (on an Ubuntu system with &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt;) turns out to be&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb1&quot;&gt;&lt;pre class=&quot;sourceCode sh&quot;&gt;&lt;code class=&quot;sourceCode bash&quot;&gt;&lt;span id=&quot;cb1-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;$&lt;/span&gt; apt install r-cran-xfun r-cran-tinytex texlive-base&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;where we do it all in one &lt;code&gt;apt&lt;/code&gt; call (as &lt;code&gt;root&lt;/code&gt;
in the container). (Given &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; we could also call
&lt;code&gt;install.packages(c(&quot;xfun&quot;,&quot;tinytext&quot;))&lt;/code&gt; followed by
&lt;code&gt;apt install texlive-base&lt;/code&gt; but it is simpler for this setup
step to be just one call).&lt;/p&gt;
&lt;p&gt;With that we are basically done. I did this (twice) using a
&lt;code&gt;rocker/r2u&lt;/code&gt; container with &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; preinstalled, mounting
a local work and scrap directory for the container. In it we expand the
package to be tested (i.e. &lt;code&gt;tar xaf pkgName_*tar.gz&lt;/code&gt; for a
given source package &lt;code&gt;pkgName&lt;/code&gt; from &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;) and then just call with the
package name and expanded direcrtory. I.e. I used this call to test my
package &lt;code&gt;AsioHeaders&lt;/code&gt; (which has just three reverse
dependencies) to both name it and to point to the expanded source
directory created for this purposed:&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb2&quot;&gt;&lt;pre class=&quot;sourceCode r&quot;&gt;&lt;code class=&quot;sourceCode r&quot;&gt;&lt;span id=&quot;cb2-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;system.time&lt;/span&gt;( res &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; xfun&lt;span class=&quot;sc&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;fu&quot;&gt;rev_check&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;AsioHeaders&quot;&lt;/span&gt;, &lt;span class=&quot;at&quot;&gt;src=&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;AsioHeaders&quot;&lt;/span&gt;) )&lt;/span&gt;
&lt;span id=&quot;cb2-2&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-2&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;do&quot;&gt;## ... earlier output omitted for brevity here ...&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-3&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-3&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;   user  system elapsed &lt;/span&gt;
&lt;span id=&quot;cb2-4&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-4&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt; &lt;span class=&quot;fl&quot;&gt;35.732&lt;/span&gt;   &lt;span class=&quot;fl&quot;&gt;3.333&lt;/span&gt; &lt;span class=&quot;fl&quot;&gt;149.683&lt;/span&gt; &lt;/span&gt;
&lt;span id=&quot;cb2-5&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-5&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; res&lt;/span&gt;
&lt;span id=&quot;cb2-6&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-6&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;   httpgd ipaddress websocket &lt;/span&gt;
&lt;span id=&quot;cb2-7&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-7&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;        &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt; &lt;/span&gt;
&lt;span id=&quot;cb2-8&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-8&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; &lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;and about a good two minutes later I would get the timing result and
the summary in variable &lt;code&gt;res&lt;/code&gt;. As I checked the current &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; version, the check was as
expected free of concerns or issues.&lt;/p&gt;
&lt;p&gt;To support this, &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt;
did indeed go off and install about sixty seven binary packages (and the
total includes all binary dependencies fully resolved) delivering on the
‘just works’ promise by the &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; documentation.&lt;/p&gt;
&lt;p&gt;As another check, I did the same for &lt;a href=&quot;https://github.com/eddelbuettel/rcppannoy&quot;&gt;RcppAnnoy&lt;/a&gt; which has
seven reverse dependencies and needed about two hundred &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; packages to be installed. The
full test took just over four minutes with the timing function reporting
some nice gains from parallelisation as total user compute time was on
the order of just under eight minutes. Again, test results were clean
and free of worries as expected:&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb3&quot;&gt;&lt;pre class=&quot;sourceCode r&quot;&gt;&lt;code class=&quot;sourceCode r&quot;&gt;&lt;span id=&quot;cb3-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;system.time&lt;/span&gt;( res &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; xfun&lt;span class=&quot;sc&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;fu&quot;&gt;rev_check&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;RcppAnnoy&quot;&lt;/span&gt;, &lt;span class=&quot;at&quot;&gt;src=&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;RcppAnnoy&quot;&lt;/span&gt;) )&lt;/span&gt;
&lt;span id=&quot;cb3-2&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-2&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;do&quot;&gt;## ... earlier output omitted for brevity here ...&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb3-3&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-3&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;   user  system elapsed &lt;/span&gt;
&lt;span id=&quot;cb3-4&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-4&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;fl&quot;&gt;471.765&lt;/span&gt; &lt;span class=&quot;fl&quot;&gt;378.220&lt;/span&gt; &lt;span class=&quot;fl&quot;&gt;266.855&lt;/span&gt; &lt;/span&gt;
&lt;span id=&quot;cb3-5&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-5&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; res&lt;/span&gt;
&lt;span id=&quot;cb3-6&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-6&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;   bbknnR  bigANNOY  blocking     scDHA    Seurat      uwot VectrixDB &lt;/span&gt;
&lt;span id=&quot;cb3-7&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-7&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;        &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt; &lt;/span&gt;
&lt;span id=&quot;cb3-8&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-8&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; &lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Overall this was a rather useful quick excursion as it demonstrates
that - existing functions can be used to orchestrate a reverse
dependency check - with ‘reasonable’ dependency scale we can do this on
a single machine quite easily taking advantage of parallel computing on
multi-core machines - using &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; gives us &lt;em&gt;fast,
easy, reliable&lt;/em&gt; package installation making testing of packages we
might not otherwise use or know a breeze - doing this in an ephemeral
Docker container facilitates easy build-up of required resources and
leaves no side effects behind which might affect our normal development
environment&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can now &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-04T17:22:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="http://www.hungry.com/~pere/blog/FreeCAD_MCP_with_llama_cpp__toy_or_tool_.html">
	<title>Petter Reinholdtsen: FreeCAD MCP with llama.cpp, toy or tool?</title>
	<link>http://www.hungry.com/~pere/blog/FreeCAD_MCP_with_llama_cpp__toy_or_tool_.html</link>
     <content:encoded>&lt;p&gt;After seeing a video a few months ago demonstrating how a
proprietary CAM solution uses machine learning and large language
models to automatically generate CNC instructions, and successfully
testing it on a real CNC, I began wondering if the same could be
achieved with free software. I still do not know the answer, but I may
be getting closer to finding out. Two weeks ago, I came across the
video &quot;&lt;a href=&quot;https://inv.nadeko.net/watch?v=6trAkQY5_kc&quot;&gt;I Connected
Claude AI to FreeCAD (And It Models Parts Like an Engineer)&lt;/a&gt;&quot; by
Make Form, which introduced me to the
&lt;a href=&quot;https://github.com/neka-nat/freecad-mcp/&quot;&gt;FreeCAD MCP
project&lt;/a&gt;. Even though the video creator apparently believes it is
acceptable to download and run random binaries from the Internet on a
local machine (his setup uses UCX), I do not. I would probably have
left the project alone entirely if I had not noticed that all of its
dependencies are already available in Debian. This significantly
boosted my motivation, so I set out to test it using packages built
from source on Debian rather than relying on untrusted binaries.&lt;/p&gt;

&lt;p&gt;The first hurdle was that
&lt;a href=&quot;https://tracker.debian.org/pkg/python-mcp&quot;&gt;the MCP SDK for
Python&lt;/a&gt; was not present on my Debian Forky test machine. I
initially believed it was missing from Debian altogether, but it has
been available in Debian Unstable for about a month and is only absent
from Forky because some automated tests fail on architectures like
riscv64 and s390. Fortunately, backporting it was straightforward
using `apt-get source -b python3-mcp`. The next hurdle involved an
outdated version of the
&lt;a href=&quot;https://tracker.debian.org/pkg/validators&quot;&gt;Validators Python
library&lt;/a&gt;. Since I am a member of Debian&#39;s Python team, which
maintains this package, updating it to a sufficient version for
FreeCAD MCP was relatively easy. I could not upgrade to the latest
upstream release due to a new dependency on an Ethereum-related
library, so I settled on a 2024 version.&lt;/p&gt;

&lt;p&gt;With those dependencies in place, I proceeded to create a Debian
package for FreeCAD MCP. I had previously submitted a
&lt;a href=&quot;https://bugs.debian.org/1142447&quot;&gt;request for packaging of
FreeCAD MCP&lt;/a&gt; to gauge interest while deciding whether to prioritize
maintaining it myself.  Because salsa.debian.org blocks access from
Tor users like myself, I published my draft packaging scripts in a Git
repository on Codeberg as the
&lt;a href=&quot;https://codeberg.org/pere/debian-freecad-mcp&quot;&gt;Debian FreeCAD
MCP project&lt;/a&gt; and got it working with the FreeCAD 1.1 version in
Forky. I initially struggled with the button controls for the MCP
feature, which led me to submit a pull request titled
&quot;&lt;a href=&quot;https://github.com/neka-nat/freecad-mcp/pull/106&quot;&gt;Fixed
startup sync of checkable toolbar buttons&lt;/a&gt;&quot; proposing a fix. Once
this confusion was resolved and the MCP setup was enabled via the GUI,
I was able to run FreeCAD completely headless using `xvfb-run` on a
machine without an X server to generate models. I am using a private
LLM service running &lt;a href=&quot;https://tracker.debian.org/llama.cpp&quot;&gt;the
Debian package of llama.cpp&lt;/a&gt; with the Qwen 3.6 model downloaded
from Hugging Face, configured with a maximum context window of 105k
tokens. I also tested the Bonsai model on my test laptop; initially,
its context window was too small (8k and 16k could not accommodate the
FreeCAD MCP instructions), but even after increasing it to 32k, it
proved useless for generating FreeCAD models so far. I&#39;ve used Claw
Code, Aider and Open Code with my server so far, and for this test I
ended up with OpenCode because it was easy to set up to use an
MCP. Because none of my LLM services are set up to be multimodal
(capable of processing both text and images in this case), I
configured the MCP to return only textual feedback from FreeCAD. I am
unsure if this is a major limitation, though I suspect it might
be.&lt;/p&gt;

&lt;p&gt;My testing experience remains limited, with no clear successes
yet. Part of the issue likely stems from my ability to provide
effective instructions for modeling 3D objects (I am relatively new to
FreeCAD, English is not my first language, and I lack a precise
vocabulary for describing construction features to an
LLM). Nevertheless, the LLM has demonstrated the capacity to create 3D
models in FreeCAD. In one of my first tests, I asked it to generate a
cube and then produce CAM/G-code instructions for a CNC machine. It
did output G-code (which remains untested), but I was surprised to
find that it bypassed FreeCAD&#39;s built-in CAM module entirely and
instead generated an external Python script to produce the code. This
was not quite what I intended, though my instructions were probably
unclear. The Qwen model with OpenCode seems to strongly prefer
programming directly; it frequently executes Python snippets inside
FreeCAD to achieve its goals rather than using the standard
sketch-and-extrude workflow I am accustomed to. In another test, I
asked the LLM to create a parameterized pipe assembly to see which of
FreeCAD&#39;s parametric tools it would choose, but found no evidence of
traditional parametric features in the output. When prompted, the LLM
explained that the parameters were embedded directly in the Python
script used to generate the model, rather than in native FreeCAD
features. With more explicit instructions, it eventually created a
FreeCAD spreadsheet to manage the parameters. The resulting model
looked much closer to my expectations and could have been useful with
further refinement. My so far last experiment was less successful: I
asked it to design a pipe clamp, but the LLM repeatedly failed to
position the clamping screws in a way that would actually secure the
brackets around the pipe. It is unclear whether this limitation lies
with the model, my prompt, or other factors.&lt;/p&gt;

&lt;p&gt;Based on my testing so far, I am uncertain whether FreeCAD MCP is
merely a fun toy or a genuinely useful tool. I will only commit time
to maintaining it in Debian if it proves to be practically valuable. I
would welcome feedback from anyone who has experience with the
project, preferably via the original request-for-packaging mailing
list thread. Alternatively, I am available in the FreeCAD and Debian
AI IRC channels for further discussion.&lt;/p&gt;

&lt;p&gt;As usual, if you use Bitcoin and wish to support my activities,
please send donations to
&lt;b&gt;&lt;a&gt;15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b&lt;/a&gt;&lt;/b&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-04T09:00:00+00:00</dc:date>
	<dc:creator>Petter Reinholdtsen</dc:creator>
</item> 
<item rdf:about="http://www.netfort.gr.jp/~dancer/diary/daily/2026-Aug-4.html.en#2026-Aug-4-07:03:26">
	<title>Junichi Uekawa: Summer Holiday.</title>
	<link>http://www.netfort.gr.jp/~dancer/diary/daily/2026-Aug-4.html.en#2026-Aug-4-07:03:26</link>
     <content:encoded>Summer Holiday. Busy time as a parent.
        &lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-03T22:03:26+00:00</dc:date>
	<dc:creator>Junichi Uekawa</dc:creator>
</item> 
<item rdf:about="http://blog.brlink.eu/index.html#i72">
	<title>Bernhard R. Link: I learned something new about URLs today</title>
	<link>http://blog.brlink.eu/index.html#i72</link>
     <content:encoded>&lt;p&gt;
Today I stumbled over some behavior that I found quite surprising:
&lt;/p&gt;
&lt;pre&gt;$ ipython3 -c &#39;import httpx;print(httpx.URL(&quot;https://example.com/foo/bar/../../baz&quot;))&#39;
https://example.com/baz
&lt;/pre&gt;
&lt;p&gt;
Even more surprising that behavior is actually standards-compliant,
even mandated by RFC 3986.
&lt;/p&gt;
&lt;p&gt;
The underlying motivation is relative reverences.
If some resource reachable by &quot;&lt;tt&gt;https://example.com/foo/bar&lt;/tt&gt;&quot;
references another resource relatively as &quot;&lt;tt&gt;../../baz&lt;/tt&gt;&quot; then
this is of course the intended result.
&lt;/p&gt;
&lt;p&gt;Getting from this problem to what RFC 3986 suggests
might be surprising in the result, but somewhat understandable if you
look at the consequences of that problem:&lt;/p&gt;
&lt;p&gt;Giving the path components &quot;&lt;tt&gt;..&lt;/tt&gt;&quot; (and &quot;&lt;tt&gt;.&lt;/tt&gt;&quot;)
special meaning at the start of the relative reference means that if you allowed
them in absolute URLs those would be impossible (or at least very convoluted)
to address as relative URLs.
&lt;/p&gt;
&lt;p&gt;
So RFC 3986 describes a way to handle them everywhere:
Just join the path of the base URL and the path of the relative reference
and normalize the result. Or normalize the absolute on either side if only
that is to be taken.
This makes things very convenient:
Multiple reference URLs can just be joined without special handling for
relative references starting with dots, making writing applications handling
them easier.
Programmers don&#39;t have to care how to handle relative references and can
just join everything in whatever way they want.
&lt;/p&gt;
&lt;p&gt;
For maximum elegance there is still some corner case left:
What happens if an absolute URL has a path starting with double-dot components?
Or an relative path starting with more of them then the base URL&#39;s path has components.
You just ignore them:
&lt;/p&gt;
&lt;pre&gt;$ ipython3 -c &#39;import httpx;print(httpx.URL(&quot;https://example.com/../../baz&quot;))&#39;
https://example.com/baz
&lt;/pre&gt;
&lt;p&gt;
With that last point every URL is valid and has well-defined meaning.
Handling relative references and relative paths is very easy and convenient.
&lt;/p&gt;
&lt;p&gt;
So this shows a high regard for simplicity, elegance and convenience.
And a total and uncompromising disregard of security.
&lt;/p&gt;
&lt;p&gt;
After all the most convenient it is for an attacker;
If they are allowed to supply a path component for a request a system
does in their behalf, then they can easily escape anything they were supposed
to be limited to.
The ignoring of dots at the start means they don&#39;t even have to know
exactly how deep their request is:
&lt;/p&gt;
&lt;pre&gt;$ python3 -c &#39;import httpx;print(httpx.URL(&quot;https://example.com/public/api/public/resources/harmless/../../../../../../../../../internal/data&quot;))&#39;
https://example.com/internal/data
&lt;/pre&gt;
&lt;p&gt;
So even if the resource server securely handles request
(unless you consider not having any way to lower your permissions for one request to a specific subset),
your fully RFC conforming client library will already request the permission they should not have permission for.
Even worse dots are usually not characters you can easily forbid so once slashes are to be allowed things get complicated.
&lt;/p&gt;
&lt;p&gt;
There also would have been a simple, elegant and secure way:
Consider every path element &quot;&lt;tt&gt;..&lt;/tt&gt;&quot; or &quot;&lt;tt&gt;.&lt;/tt&gt;&quot;
in an (absolute) URL an error.
Define a reference resolution that allows the relative reference to only start
with &quot;&lt;tt&gt;./&lt;/tt&gt;&quot; or one or multiple &quot;&lt;tt&gt;../&lt;/tt&gt;&quot; and
consider every appearance of a dot or two dots as path components after than an error.
&lt;/p&gt;
&lt;p&gt;
Everything joining two paths has to either use an implementation of that path joining
algorithm, but only if they want to joins paths in the potentially dangerous
way allowing leading &quot;&lt;tt&gt;../&lt;/tt&gt;&quot;. Otherwise they can just use the normal
join and even if an attacker gets those dots that will just cause the generated URL
to be rejected as invalid.
&lt;/p&gt;
&lt;p&gt;Of course using a secure implementation is now even more inconvenient thanks to RFC 3986 being around:
If you have no control over the generator of relative references, it is always possible
that they generate relative references with &quot;&lt;tt&gt;..&lt;/tt&gt;&quot; components after non-dot
components.
&lt;/p&gt;
&lt;p&gt;And if you check all code to properly filter out &quot;&lt;tt&gt;/../&lt;/tt&gt;&quot;,
keep in mind that convienence does not stop there.
After all it is not unheared of for server implementations to helpfully normalize
unicode characters, too, or translate them to their nearest ASCII equivalents.
Or translate percent escaped characters back before doing path splitting.
Or you might think there was some unicode codepoints between those two dots,
but they that those were some meaningless control characters that can be omitted.
So you need some really restrictive allow lists...
&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-03T19:39:43+00:00</dc:date>
	<dc:creator>Bernhard R. Link</dc:creator>
</item> 
<item rdf:about="https://changelog.complete.org/?p=44456">
	<title>John Goerzen: Celebrating 45 Years of Kermit with the First New C-Kermit Release in 15 Years (and working with a decades-old C codebase)</title>
	<link>https://changelog.complete.org/archives/44456-celebrating-45-years-of-kermit-with-the-first-new-c-kermit-release-in-15-years-and-working-with-a-decades-old-c-codebase</link>
     <content:encoded>&lt;p&gt;1981 was a different time for computing.  It was expensive (&lt;a href=&quot;https://changelog.complete.org/archives/10417-the-pc-internet-revolution-in-rural-america&quot;&gt;both hardware and software&lt;/a&gt;), and it was far from a given that machines from one vendor would be able to talk to those from another.  In fact, Columbia University had just such a problem, so in 1981, Frank da Cruz and Bill Catchings designed a serial protocol they called Kermit.  Because of the many &lt;a href=&quot;https://www.columbia.edu/cu/computinghistory/dec20.html#kermit&quot;&gt;quirks&lt;/a&gt; of the &lt;a href=&quot;https://en.wikipedia.org/wiki/DECSYSTEM-20&quot;&gt;DEC-20&lt;/a&gt; and IBM mainframes, the Kermit protocol was highly adaptable from the start: able to handle systems that had trouble processing more than 96 bytes of data at once, able to transfer 8-bit files over 7-bit links, able to translate between character sets (ASCII and EBCDIC then; now also various Unicodes), and of course, handling of error-prone serial links.&lt;/p&gt;
&lt;p&gt;Kermit spread rapidly; by 1982, Kermit had been ported to MS-DOS and Unix.  Eventually, C-Kermit (an implementation of Kermit in C) became the flagship Kermit.  It gained TCP support, an interactive CLI, a powerful scripting language (with features from the shell, Lisp, and &lt;a href=&quot;https://core.tcl-lang.org/expect/index&quot;&gt;expect&lt;/a&gt;), and optimizations for today’s high-speed links, such as jumbo packets, sliding windows, and streaming modes.  Along the way, Kermit &lt;a href=&quot;https://www.kermitproject.org/nasa.html&quot;&gt;flew on the International Space Station&lt;/a&gt;, ran &lt;a href=&quot;https://www.kermitproject.org/em-apex.html&quot;&gt;data collection from sensors during hurricanes&lt;/a&gt;, and &lt;a href=&quot;https://www.kermitproject.org/kermit.html&quot;&gt;many other uses&lt;/a&gt; including postal systems, Boeing 787 manufacturing, and more.&lt;/p&gt;
&lt;p&gt;Today, I use it as a &lt;a href=&quot;https://www.openkermit.org/ckermit/ssh/&quot;&gt;powerful ssh wrapper&lt;/a&gt; (letting me easily transfer files through multiple nested ssh, sudo, su, etc. commands), a &lt;a href=&quot;https://www.openkermit.org/ckermit/bbs/&quot;&gt;BBS client&lt;/a&gt;, to exchange data with me &lt;a href=&quot;https://www.kermitproject.org/hp48filetransfer.html&quot;&gt;HP 48GX calculator&lt;/a&gt;, and so on.  It’s also used today to transmit firmware updates to embedded devices.  And, of course, anyone that works with vintage systems is likely to use Kermit at some point.&lt;/p&gt;
&lt;p&gt;It wouldn’t be until the late 1990s that the TCP/IP stack was finally adopted by most OS vendors, establishing something of a common basis for communication.  Of course, we assume this today.  Though transferring large files between OSs (say, Linux, Windows, MacOS, Android, iPad, etc.) is still a challenge, even though they all speak TCP/IP!  I find that the easiest way to get large files from two computers is to spin up Kermit (see &lt;a href=&quot;https://github.com/davidrg/ckwin&quot;&gt;ckwin&lt;/a&gt; for a Windows fork of C-Kermit) and just set up a TCP connection over the LAN.  In fact, I added a new &lt;tt&gt;show interfaces&lt;/tt&gt; command in C-Kermit 11, making it easy to see your system’s local IPs.&lt;/p&gt;
&lt;p&gt;For most of its history, Columbia’s Kermit project was self-funded.  Columbia charged for commercial use, which limited its inclusion in Linux distributions.  In 2011, 30 years after its founding, Columbia canceled the Kermit Project and released C-Kermit as Open Source under a BSD license.  Frank da Cruz, who had still been working with the Kermit project all those years, volunteered to continue maintaining Kermit outside Columbia, and continued development with alpha and beta releases through his retirement from the project in 2025.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;I dive into this C codebase&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;As Debian maintainer of Kermit, I noticed some areas where it wasn’t matching modern expectations.  One area was, not surprising for a project of its age, security.  Another area was that its character set or line-ending conversions are usually not desired now; we are used to byte-identical binary transfers, and the defaults caused confusion and even some rare instances of data corruption.  So I started making a few patches last year.&lt;/p&gt;
&lt;p&gt;I’ve worked with old C codebases before, such as Varnish.  I’ve generally hated it.  You usually find a mix of bad and terrible practices, unclear memory management, and so forth.&lt;/p&gt;
&lt;p&gt;But I’ve been living in the C-Kermit codebase for a few months now, and I &lt;i&gt;enjoy&lt;/i&gt; it.  Yes, this thing is still designed to build on VMS, OS/2, and with compilers that haven’t heard of ANSI — and those that require modern practices.  (That em-dash was mine; I knew how to use them before LLMs existed and I’m not going to stop just because LLMs have copied people like me!  No AI was used for this post.)&lt;/p&gt;
&lt;p&gt;The there is an elegance in all of that.  As I worked, I fixed a bunch more potential security issues, both with memory safety and with protecting against a malicious remote in roughly the same manner that some patches to scp did a few years back.  I added IPv6 support, of course conditionally compiled because some systems C-Kermit builds on have never heard of IPv6 and never will.  (And, of course, with fallback algorithms at runtime for systems that have IPv6 support but not IPv6 connectivity.)&lt;/p&gt;
&lt;p&gt;I added unit tests and Python-based end-to-end tests, running nearly 2000 test cases in total.  Along the way, I found and fixed a number of bugs going back decades.  I learned about FIONREAD being broken on macOS, about NetBSD’s bugs in the pty driver, and fixed bugs in the Kermit protocol implementation itself.  I added compatibility tests with the gkermit and ekermit (embedded) implementations, as well as the last full release, C-Kermit 9.0.302 from 2011 (which was difficult to get compiled on a modern system).&lt;/p&gt;
&lt;p&gt;There is an &lt;a href=&quot;https://github.com/OpenKermit/ckermit/releases/tag/v11.0.506&quot;&gt;extensive changelog&lt;/a&gt; describing all the improvements in C-Kermit 11.&lt;/p&gt;
&lt;p&gt;C-Kermit development had never really used a VCS at any point, though Kermit veteran Jeffrey Altman imported historical releases into a Git repo, along with some patches that hadn’t made it into a release (which I also pulled in.)  There was a lot of disabled code behind &lt;tt&gt;&lt;a class=&quot;hashtag u-tag u-category&quot; href=&quot;https://changelog.complete.org/archives/tag/ifdef&quot; rel=&quot;tag&quot;&gt;#ifdef&lt;/a&gt; COMMENT&lt;/tt&gt;, along with commentary describing why it was no longer used.  With Git, we would now generally just remove the old code and explain why in a commit message.  I went through and did so with a lot of it, meaning that, at last check, C-Kermit actually has fewer lines of code now than it used to.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Towards a new release&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;It became apparent pretty quickly that I was making more changes than would make sense as a Debian patch series.  Not only that, but they would be more widely applicable to more than just Debian and Ubuntu users.  As Linux and BSD distributions were running everything from the last non-beta release (2011’s 9.0.302) to the last beta release (about 1.5 years ago), depending on their different policies about running betas, even sharing patches in a useful fashion was going to be quite difficult.&lt;/p&gt;
&lt;p&gt;So, I spun up a project at &lt;a href=&quot;https://www.openkermit.org/&quot;&gt;Open Kermit&lt;/a&gt; to coordinate future development in the open and keep Kermit going.&lt;/p&gt;
&lt;p&gt;With modern CI, I run that test suite on Linux (x86_64 and arm64), macOS, FreeBSD, NetBSD, and OpenBSD.  It builds binary releases on all those platforms, plus a statically-linked Linux binary built with musl libc.&lt;/p&gt;
&lt;p&gt;You can &lt;a href=&quot;https://www.openkermit.org/downloads/&quot;&gt;download the latest C-Kermit release&lt;/a&gt;, and of course &lt;a href=&quot;https://www.openkermit.org/contributing/&quot;&gt;contribute to C-Kermit and its website&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Dedication&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Frank da Cruz was directly involved with Kermit for 44 years.  I’m not aware of any other Open Source project founder being involved for so long.  Richard Stallman started working on GNU Emacs in 1984, 3 years after Frank started working on Kermit, but Richard hasn’t &lt;a href=&quot;https://web.archive.org/web/20080524201111/http://www.networkworld.com/community/node/25335&quot;&gt;been in that role since around 2008&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Accordingly, C-Kermit 11 bears this dedication:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;I dedicate this release of C-Kermit to Frank da Cruz.&lt;/p&gt;
&lt;p&gt;Frank was directly involved with Kermit for 44 years, from its initial design in 1981 all the way through 2025.  He maintained Kermit as an Open Source project after Columbia University ended its sponsorship.  I know of no other Open Source project where the founder remains so personally involved for so long.&lt;/p&gt;
&lt;p&gt;When Kermit was begun, transfers between different hardware and operating systems were difficult or impossible.  Frank helped build a bridge.  Kermit glued systems together, from the International Space Station to pocket calculators, and set a new standard for interoperability.  It continues to do so.&lt;/p&gt;
&lt;p&gt;Kermit is still one of the quietly-working pillars of computing today, enabling everything from firmware upgrades to radios.  And, yes, it still reliably transfers files over serial lines.&lt;/p&gt;
&lt;p&gt;As we start to spend a lot of time in the Kermit codebase, we do so standing on the shoulders of a giant.  Thanks, Frank, for your decades of work on Kermit.&lt;/p&gt;
&lt;p&gt;John Goerzen, July 2026&lt;/p&gt;&lt;/blockquote&gt;</content:encoded> 
	<dc:date>2026-08-03T15:45:14+00:00</dc:date>
	<dc:creator>John Goerzen</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/journal/2026-08/001.html">
	<title>Russ Allbery: Term::ANSIColor v6.0.0 TRIAL release</title>
	<link>https://www.eyrie.org/~eagle/journal/2026-08/001.html</link>
     <content:encoded>&lt;p&gt;
Yesterday, I uploaded Term::ANSIColor v6.0.0-TRIAL to CPAN for early
testing. This release will raise the minimum required Perl version to
5.12, dropping support for Perl 5.8 and 5.10. When I did the same with
podlators a couple of years ago, it upset a few people and one of them
asked me to make this sort of test release in the future. Hopefully this
will help.
&lt;/p&gt;

&lt;p&gt;
I have not run the normal release machinery and haven&#39;t archived this
release in the normal places, since I intend it to be transient. It&#39;s only
on CPAN, where people can retrieve it for testing. Once v6.0.0 is
released, few traces of this TRIAL release will be left. This doesn&#39;t
appear to be how other people use the TRIAL mechanism, but it felt more
comfortable to me. If I have to make substantial changes, I&#39;ll consider
changing my approach.
&lt;/p&gt;

&lt;p&gt;
I plan on turning this into the v6.0.0 release in about a month or two,
hopefully with only documentation changes.
&lt;/p&gt;

&lt;p&gt;
Term::ANSIColor is a &quot;very upstream&quot; core module with a lot of
dependencies, and CPAN (unlike some of the archives that followed it, such
as PyPI) doesn&#39;t support conditionally retrieving packages based on the
current Perl version. This release may therefore be disruptive for people
who are still trying to support Perl 5.8 and 5.10, since CPAN installation
tools may attempt to install an incompatible Term::ANSIColor version. I&#39;m
sad that this will be the result, since I know some people still care
about those versions.
&lt;/p&gt;

&lt;p&gt;
I&#39;m pressing forward with updating my Perl modules anyway, though. I
realized that honoring other people&#39;s desire for stability to such a
degree that I was unable to use Perl features added more than 15 years ago
was destroying my motivation to work on these Perl modules at all. So I&#39;ve
decided on a very slow and gradual approach where I&#39;m going to keep
pushing the minimum supported version forward but try to give people a lot
of warning.
&lt;/p&gt;

&lt;p&gt;
Personally, I think it&#39;s time to let ancient versions of Perl go and
follow the
&lt;a href=&quot;https://github.com/Perl-Toolchain-Gang/toolchain-site/blob/master/lyon-amendment.md&quot;&gt;Lyon Amendment&lt;/a&gt; about supported Perl versions. When we&#39;re talking
installing new modules for software released more than 15 years ago, we&#39;re
talking about special limited environments and retrocomputing more than
what I would consider routine software maintenance. Those tasks should
expect to need different tools and a different workflow so that they can
pin historical versions. Since this isn&#39;t something I&#39;m personally
interested in, my willingness to expend time and energy to assist is
limited.
&lt;/p&gt;

&lt;p&gt;
As you can probably tell, I still feel nervous about pressing forward in
this way, but I think this is the approach that lets me continue to enjoy
maintaining these Perl modules. It&#39;s been 29 years for Term::ANSIColor,
but I still enjoy fixing bugs in it and putting out a new release from
time to time, particularly if I can clean up the code a bit each time I
touch it.
&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-02T21:49:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://www.decadent.org.uk/ben/blog/2026/08/02/foss-activity-in-july-2026">
	<title>Ben Hutchings: FOSS activity in July 2026</title>
	<link>https://www.decadent.org.uk/ben/blog/2026/08/02/foss-activity-in-july-2026.html</link>
     <content:encoded>&lt;ul&gt;
  &lt;li&gt;Debian packages:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/apt&quot;&gt;apt&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:apt&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1078608&quot;&gt;#1078608: apt update silently leaves old index data&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-nonfree&quot;&gt;firmware-nonfree&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/151&quot;&gt;!151: Update to 20260622&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-nonfree/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 20260622-1 to unstable&lt;/li&gt;
              &lt;li&gt;uploaded version 20260622-1~bpo13+1 to trixie-backports&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/hexagon-dsp-binaries&quot;&gt;hexagon-dsp-binaries&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:hexagon-dsp-binaries&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://bugs.debian.org/1141904&quot;&gt;#1141904: Missing new DSP binaries for shikra&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/initramfs-tools&quot;&gt;initramfs-tools&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:initramfs-tools&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1142780&quot;&gt;#1142780: initramfs-tools: ip=dhcp lease is not renewed while initramfs remains active&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/kernel-handbook&quot;&gt;kernel-handbook&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/kernel-handbook/-/merge_requests/15&quot;&gt;!15: Update “Building a development version of the Debian kernel package”&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux&quot;&gt;linux&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:linux&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/851695&quot;&gt;#851695: replacing base package with -unsigned removes module files&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1126671&quot;&gt;#1126671: linux-image-6.17.13+deb13-amd64: Disconnect root (path=/) during heavy load on NvME, partial corruption on NTFS.crash soon but not yet&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1130365&quot;&gt;#1130365: linux-image-6.18.15+deb14-amd64: kernel panic during startup&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1140892&quot;&gt;#1140892: thunderbolt: Intel Goshen Ridge CL state regression breaks dock tunneling since 6.12.94&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1141185&quot;&gt;#1141185: linux-image-6.12.94+deb13-amd64: Occasional read problems in RAID/LVM/ext4 stack when under stress.&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141355&quot;&gt;#1141355: linux-image-6.1.0-49-amd64: procfs deadlock triggered by drop_caches on 6.1.0-49-amd64 (regression from 6.1.0-37)&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141448&quot;&gt;#1141448: MT7921 intermittently disappears after reboot on ASUS TUF Gaming F17 FX706HF&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141541&quot;&gt;#1141541: linux: i915 kernel BUG in i915_drm_client_remove_object from Xorg causing hard lock on 6.12.94+deb13-amd64&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141866&quot;&gt;#1141866: linux-image-7.1.3+deb14-amd64: no display on AMD Kaveri/CIK APU VGA output (amdgpu DC regression)&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1936&quot;&gt;!1936: [sparc64] Add nvme module to scsi-modules udeb&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1968&quot;&gt;!1968: [bookworm] net: mana: refresh driver from 6.12.94&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1984&quot;&gt;!1984: udeb: Ensure that aead and macsec modules are in the right packages&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed and closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2003&quot;&gt;!2003: 6.1 backport: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242)&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2004&quot;&gt;!2004: [sparc64] udeb: scsi-modules: Use the default module list&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2010&quot;&gt;!2010: [x86] Backport security fixes for KVM&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2012&quot;&gt;!2012: Update to 6.1.177&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2017&quot;&gt;!2017: Enable NTFS_FS (and replace NTFS3_FS)&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2019&quot;&gt;!2019: Fix rtmutex security issues&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2027&quot;&gt;!2027: Include rsync in Build-Depends-Arch for any build including tools&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2038&quot;&gt;!2038: [loong64] drivers/mmc/host: Enable MMC_LOONGSON2 as module&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2041&quot;&gt;!2041: Update to 5.10.262&lt;/a&gt; (LTS)&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 5.10.259-1 to bullseye-security (LTS)&lt;/li&gt;
              &lt;li&gt;uploaded version 6.1.176-1 to bookworm-security (LTS)&lt;/li&gt;
              &lt;li&gt;uploaded version 6.1.177-1 to bookworm-security (LTS)&lt;/li&gt;
              &lt;li&gt;uploaded version 6.12.95-1~bpo12+1 to bookworm-backports (LTS)&lt;/li&gt;
              &lt;li&gt;uploaded version 7.0.13-1~bpo13+1 to trixie-backports&lt;/li&gt;
              &lt;li&gt;uploaded version 7.1.3-1~bpo13+1 to trixie-backports&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-6.1&quot;&gt;linux-6.1&lt;/a&gt; (LTS):
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-6.1/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 6.1.176-1~deb11u1 to bullseye-security&lt;/li&gt;
              &lt;li&gt;uploaded version 6.1.177-1~deb11u1 to bullseye-security&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;linux-6.12 (LTS):
        &lt;ul&gt;
          &lt;li&gt;Uploads:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 6.12.96-1~deb12u1 to bookworm-security (not
yet accepted)&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-base&quot;&gt;linux-base&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux-base/-/merge_requests/21&quot;&gt;!21: Draft: Add hooks to copy vmlinuz file to /boot&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/localechooser&quot;&gt;localechooser&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:localechooser&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141886&quot;&gt;#1141886: localechooser: Turkey is inconsistently classified under Asia in regionmap&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb&quot;&gt;wireless-regdb&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 2026.05.30-1~deb11u1 to bullseye-security (LTS)&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;Mailing lists:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-kernel/&quot;&gt;debian-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/c6ab03ad04125365bf3ccda6d42285e22bb1e83e.camel@decadent.org.uk&quot;&gt;Agenda items for kernel-team meeting on 2026-07-01&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/d0012f0e7b0c012a3e05675fcc2525e1969666bd.camel@decadent.org.uk&quot;&gt;Agenda items for kernel-team meeting on 2026-07-22&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/&quot;&gt;debian-lts-announce&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/akfam9nRaDaqT2he@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4664-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/akgBqAUAJLAuUiyK@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4665-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/akqhaqWLkM4Jy49D@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4671-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/alKRo0uzT8v9B685@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4676-1] wireless-regdb new upstream version&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/aluK_-ysT8UPk48z@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4688-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/amXknKTE1Xwk58bC@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4700-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-kernel/&quot;&gt;linux-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/linux-kernel/akvddtMQTDKLo2PH@decadent.org.uk/T/&quot;&gt;[PATCH] irqchip/irq-imgpdc: Remove unused driver&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/stable/&quot;&gt;stable&lt;/a&gt; (mostly LTS):
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/1bfb3bb0dda1f5cd66ca8a48de2536c026355ded.camel@decadent.org.uk/T/&quot;&gt;[7.1] drm/amd/display: Add dp_skip_rbr flag for NUTMEG&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/418ca29bbbb1190853136331c572470dca803800.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 01/96] net/sched: act_pedit: use NLA_POLICY for parsing ex keys&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/6359da4c14e0b4c6ffa068407a42c07e56ef9c5c.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 11/96] slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/8601edcd7c9bcc70e75f85a758f8818c57945d07.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 81/96] nfsd: check get_user() return when reading princhashlen&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/c1c9fdd193db5a288c825364ee525d570dadfbe0.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 89/96] misc: fastrpc: Fix NULL pointer dereference in rpmsg callback&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/ed0c9af450494df5f7bfd72670754c8e48e1f36d.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 94/96] mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-02T17:06:31+00:00</dc:date>
	<dc:creator>Ben Hutchings</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6260">
	<title>Russell Coker: Packet Edit Meme and Debian SE Linux</title>
	<link>https://etbe.coker.com.au/2026/08/02/packet-edit-meme-debian-selinux/</link>
     <content:encoded>&lt;p&gt;There’s yet another Linux kernel exploit based on container functions, here’s the result when run as user_t on a SE Linux system:&lt;/p&gt;
&lt;pre&gt;$ ./packet_edit_meme 
[*] target /bin/su as uid 1000; entry at file offset 0x4340; shellcode 48 bytes
unshare: Permission denied
[-] page-cache corruption failed&lt;/pre&gt;
&lt;p&gt;Here is the audit log entry for this failure:&lt;/p&gt;
&lt;pre&gt;type=AVC msg=audit(1785640621.498:1843): avc:  denied  { create } for  pid=1770 comm=&quot;packet_edit_mem&quot; scontext=user_u:user_r:user_t:s0 tcontext=user_u:user_r:user_t:s0 tclass=user_namespace permissive=0&lt;/pre&gt;
&lt;p&gt;Here’s the result of running it from the unconfined_t domain:&lt;/p&gt;
&lt;pre&gt;$ ./packet_edit_meme 
[*] target /bin/su as uid 1001; entry at file offset 0x4340; shellcode 48 bytes
[+] su entry overwritten; exec&#39;ing su -&amp;gt; interactive root shell
# id
uid=0(root) gid=0(root) groups=0(root),1001(test2) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
# &lt;/pre&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.daniel-baumann.ch/posts/20260626-1.html&quot;&gt;Daniel Baumann wrote a blog post describing how this is fixed for Debian systems without SE Linux.&lt;/a&gt;&lt;/p&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/24/debian-selinux-pintheft/&quot; rel=&quot;bookmark&quot; title=&quot;Debian SE Linux and PinTheft&quot;&gt;Debian SE Linux and PinTheft&lt;/a&gt; &lt;small&gt;We have a new Linux exploit called PinTheft [1]. I...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/15/debian-selinux-ssh-keysign-pwn/&quot; rel=&quot;bookmark&quot; title=&quot;Debian SE Linux and ssh-keysign-pwn&quot;&gt;Debian SE Linux and ssh-keysign-pwn&lt;/a&gt; &lt;small&gt;I just tested out the ssh-keysign-pwn exploit [1] on Debian...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/08/dirty-frag-on-debian-and-se-linux/&quot; rel=&quot;bookmark&quot; title=&quot;Dirty Frag on Debian and SE Linux&quot;&gt;Dirty Frag on Debian and SE Linux&lt;/a&gt; &lt;small&gt;Hot on the heels of the Copy Fail vulnerability [1]...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-08-02T03:42:53+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/0-7564-1949-2.html">
	<title>Russ Allbery: Review: How to Steal a Galaxy</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/0-7564-1949-2.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;How to Steal a Galaxy&lt;/cite&gt;, by Beth Revis&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Chaotic Orbits #2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;DAW Books&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;December 2024&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;0-7564-1949-2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;143&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;How to Steal a Galaxy&lt;/cite&gt; is a far-future science fiction caper short
novel (maybe a novella?) and the sequel to &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-7564-1947-6.html&quot;&gt;&lt;cite&gt;Full Speed to a Crash Landing&lt;/cite&gt;&lt;/a&gt;. You don&#39;t have to remember the
details of the previous book to enjoy this one. There&#39;s an excellent
inline summary at the start of this installment.
&lt;/p&gt;

&lt;p&gt;
After an annoying negotiation with people who keep trying to preach at her
about causes, Ada Lamarr has a new contract. She is going undercover,
after a fashion, at a charity gala and auction on Rigel-Earth. While she&#39;s
there, she&#39;s going to steal something. What, precisely, she keeps a
mystery from both the other characters and from the reader until the end
of the story.
&lt;/p&gt;

&lt;p&gt;
Government agent Rian White is working security at this charity gala. Due
to its link with the plot of &lt;cite&gt;Full Speed to a Crash Landing&lt;/cite&gt;, he was
fairly certain Ada would be there, as indeed she is. What she is planning,
however, is maddeningly unclear. Also maddening is how good Ada looks in a
dress.
&lt;/p&gt;

&lt;p&gt;
As with the previous book, &lt;cite&gt;How to Steal a Galaxy&lt;/cite&gt; is told by Ada in
the first person using the same teasing tone and constant misdirection
that she uses when verbally fencing with Rian and the other characters. I
found this novella even more entertaining and satisfying than the previous
one. The charity gala is supposedly intended to benefit the poor people of
Earth, and is run with exactly the sort of condescension and disguised
capitalist looting typical of such exercises in elite charity. Ada&#39;s
narration is scathing in a deeply relatable way.
&lt;/p&gt;

&lt;p&gt;
Also, there is a trillionaire tech-bro fake philanthropist who is smug and
condescending and accustomed to getting exactly what he wants.
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    &quot;I don&#39;t think anyone should have enough personal wealth to decimate a
    large country&#39;s income just because he&#39;s going through a midlife
    crisis.&quot;
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
Ada&#39;s interactions with Strom Fetor are an absolute delight. He is so sure
of himself that he is incapable of registering her as a threat, and she
effortlessly deceives him by hiding in plain sight.
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    &quot;You really shouldn&#39;t be talking about this,&quot; Rian starts.
&lt;/p&gt;

&lt;p&gt;
    Fetor waves aside his concerns. &quot;We&#39;re all friends here.&quot;
&lt;/p&gt;

&lt;p&gt;
    &quot;Not me,&quot; I say. &quot;I hate you. Remember?&quot;
&lt;/p&gt;

&lt;p&gt;
    Fetor laughs in a tone I&#39;m sure he thinks is charming.
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
Fetor&#39;s complete inability to realize that a beautiful woman might both
sincerely not like him and not be flirting with him is perfect. I was
cackling through half of this book.
&lt;/p&gt;

&lt;p&gt;
Like any good heist story, there are twists and turns, surprises, double
agents, unexpected complications, and a delightful amount of verbal
fencing. I adore the narrative tone Revis uses for these stories. Ada has
just the right mix of idealism, cynicism, professionalism, and irreverence
to carry off the feeling that she&#39;s a step ahead of everyone else.
Underneath the bones of a delightful plot is a character who cares deeply
but is very aware of her limitations, and therefore has taught herself to
laugh at and be ruthless with her own emotions. I am finding it an
incredibly compelling type of competence porn.
&lt;/p&gt;

&lt;p&gt;
I enjoyed the first book of this series, but this one was so much better.
These stories are exactly the right length to keep the reader engrossed
throughout and satisfied but wanting more at the end. &lt;cite&gt;How to Steal a
Galaxy&lt;/cite&gt; ends on a cliffhanger of sorts, to be resolved in the next and
final book. I can hardly wait to start it.
&lt;/p&gt;

&lt;p&gt;
Highly recommended.
&lt;/p&gt;

&lt;p&gt;
Followed by &lt;cite&gt;Last Chance to Save the World&lt;/cite&gt;.
&lt;/p&gt;

&lt;p&gt;Rating: 9 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-01T04:23:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://xana.scru.org/posts/bamamba/lekkerderworst.html">
	<title>Clint Adams: N.K. Jemisin is doing a worldbuilding workshop at the Bronx Library Center tomorrow afternoon</title>
	<link>https://xana.scru.org/posts/bamamba/lekkerderworst.html</link>
     <content:encoded>&lt;div class=&quot;inlinecontent&quot;&gt;
&lt;p&gt;Normally, I do not read book reviews. Either I
haven&#39;t read the book, in which case there&#39;s spoiler
potential, or I have, in which case it&#39;s unlikely to
be useful or enjoyable for me to read a thing about
a thing I&#39;ve already read.&lt;/p&gt;
&lt;p&gt;But &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-316-29068-8.html&quot;&gt;Review: Radiant Star&lt;/a&gt;
caught my eye, and I thought, “Hmm, I&#39;ve read all
those books” and was curious. Of course, because
I am old and senile and have no understanding of
time, the “May 2026” staring at me was not able to
trigger the neural synapses that would remind me
that I haven&#39;t read any Ann Leckie since 2023.&lt;/p&gt;
&lt;p&gt;However, as I read Russ&#39;s review, and began to
wonder what the hell he was talking about, I was
able to piece together that while I have, in fact,
read 6 Ann Leckie books, none of them have been
&lt;em&gt;Radiant Star&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;This presented an opportunity, so I resolved to
add &lt;em&gt;Radiant Star&lt;/em&gt; to my todo list. To my surprise,
it was already there.&lt;/p&gt;
&lt;/div&gt;

&lt;div class=&quot;info&quot;&gt;
    Posted on 2026-07-31
    
&lt;/div&gt;
&lt;div class=&quot;info&quot;&gt;
    
    Tags: &lt;a href=&quot;https://xana.scru.org/tags/bamamba.html&quot; rel=&quot;tag&quot; title=&quot;All pages tagged &#39;bamamba&#39;.&quot;&gt;bamamba&lt;/a&gt;
    
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-31T15:32:32+00:00</dc:date>
	<dc:creator>C</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6257">
	<title>Russell Coker: Links July 2026</title>
	<link>https://etbe.coker.com.au/2026/07/31/links-july-2026/</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/ai-use-by-the-us-government.html&quot;&gt;Bruce Schneier and Nathan E. Sanders wrote a disturbing and informative article about the use of AI by the US government [1]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/ai-and-liability.html&quot;&gt;Bruce Schneier wrote an interesting blog post about corporate liability for AI decisions and the German court ruling about Google’s AI summaries [2]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://cybersecuritynews.com/anthropics-claude-fable-5-jailbroken/&quot;&gt;Cybersecurity News has an interesting article about how Pliny the Liberator succeeded in jailbreaking Anthropic’s latest LLM to give instructions on writing exploits, writing exploitable code (backdoors?), and making meth [3]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://glasswings.com.au/blog/2026-07/05-185304.html&quot;&gt;Andrew Pam wrote about the number of cars with internal combustion engines in NSW decreasing for the first time since 1910, EVs are taking over [4]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://pluralistic.net/2026/06/27/zuckerstreisand-2/#autodisparagement&quot;&gt;Cory Doctorow wrote an informative blog post about Facebook’s attempts to silence whistleblowers and what a pathetic little loser Zuckerberg is [5]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://forwardfuture.com/newsletter/originals/a-tax-system-built-on-labor-is-a-tax-system-built-on-a-melting-glacier&quot;&gt;Scott Santens wrote an insightful article about how to effectively levy taxes in the future when “AI” significantly reduces the number of workers [6]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.rongarret.info/2026/07/birthright-citizenship-hangs-on-by-its.html&quot;&gt;Ron Garrett wrote an insightful post about birthright citizenship in the US and his status as a US citizen who was not born there [7]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.bbc.com/future/article/20260626-how-scotland-changed-the-way-it-tackled-violence&quot;&gt;The BBC has an interesting article about the Scottish Violence Reduction Unit and how treating violence as a disease can significantly address the problem [8]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://archive.md/Gq2jB&quot;&gt;The LA Times has an interesting article about Covid19 causing cancer that had been in remission to return, sparking some new research into the effects of viruses on mammals [9]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=3ddTIa-AhXE&quot;&gt;CMU has an interesting video about ways to physically modify QR codes and how they could be used in real life [10]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://retout.co.uk/2026/07/10/blocking-distracting-news-links/&quot;&gt;Tim Retout wrote an informative post about the pervasive forms of advertising on the Internet, even on the BBC’s site and how some of it can be blocked [11]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.interceptfund.com/p/ending-respiratory-infections&quot;&gt;The Intercept Fund is a project to address respiratory illnesses and the long term mostly unnoticed costs they cause to society, we need governments and corporations to get on board with this [12]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.dw.com/en/german-activists-use-trademark-law-to-fight-far-right-nazi-merchandise/a-77770986&quot;&gt;The German news site DW has an interesting article about activists registering neo-nazi slang as trademarks to prevent the sale of nazi merchanise which funds racism [13]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://theconversation.com/south-sudan-at-15-how-the-political-elite-have-found-a-way-to-profit-from-peace-as-well-as-war-285846&quot;&gt;The Conversation has an insightful article about how in South Sudan and other war ravaged countries the peace process usually just allocates the spoils of war and therefore encourages more war [14]&lt;/a&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/ai-use-by-the-us-government.html&quot;&gt; https://tinyurl.com/26cnn3og&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/ai-and-liability.html&quot;&gt; https://tinyurl.com/22fewyml&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href=&quot;https://cybersecuritynews.com/anthropics-claude-fable-5-jailbroken/&quot;&gt; https://tinyurl.com/2a5t693d&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[4]&lt;a href=&quot;https://glasswings.com.au/blog/2026-07/05-185304.html&quot;&gt; https://glasswings.com.au/blog/2026-07/05-185304.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[5]&lt;a href=&quot;https://pluralistic.net/2026/06/27/zuckerstreisand-2/#autodisparagement&quot;&gt; https://tinyurl.com/26qzcadm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[6]&lt;a href=&quot;https://forwardfuture.com/newsletter/originals/a-tax-system-built-on-labor-is-a-tax-system-built-on-a-melting-glacier&quot;&gt; https://tinyurl.com/2csg4huw&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[7]&lt;a href=&quot;https://blog.rongarret.info/2026/07/birthright-citizenship-hangs-on-by-its.html&quot;&gt; https://tinyurl.com/2blnzzxg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[8]&lt;a href=&quot;https://www.bbc.com/future/article/20260626-how-scotland-changed-the-way-it-tackled-violence&quot;&gt; https://tinyurl.com/25v5j7v9&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[9]&lt;a href=&quot;https://archive.md/Gq2jB&quot;&gt; https://archive.md/Gq2jB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[10]&lt;a href=&quot;https://www.youtube.com/watch?v=3ddTIa-AhXE&quot;&gt; https://www.youtube.com/watch?v=3ddTIa-AhXE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[11]&lt;a href=&quot;https://retout.co.uk/2026/07/10/blocking-distracting-news-links/&quot;&gt; https://tinyurl.com/2xt9dgfp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[12]&lt;a href=&quot;https://blog.interceptfund.com/p/ending-respiratory-infections&quot;&gt; https://tinyurl.com/2y5f26rj&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[13]&lt;a href=&quot;https://www.dw.com/en/german-activists-use-trademark-law-to-fight-far-right-nazi-merchandise/a-77770986&quot;&gt; https://tinyurl.com/29ok2qsu&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[14]&lt;a href=&quot;https://theconversation.com/south-sudan-at-15-how-the-political-elite-have-found-a-way-to-profit-from-peace-as-well-as-war-285846&quot;&gt; https://tinyurl.com/2yxzsp7s&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/04/30/links-april-2026/&quot; rel=&quot;bookmark&quot; title=&quot;Links April 2026&quot;&gt;Links April 2026&lt;/a&gt; &lt;small&gt;Charles Stross wrote an interesting blog post about the apparent...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2024/07/30/links-july-2024/&quot; rel=&quot;bookmark&quot; title=&quot;Links July 2024&quot;&gt;Links July 2024&lt;/a&gt; &lt;small&gt;Interesting Scientific American article about the way that language shapes...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/02/17/links-february-2026/&quot; rel=&quot;bookmark&quot; title=&quot;Links February 2026&quot;&gt;Links February 2026&lt;/a&gt; &lt;small&gt;Charles Stross has a good theory of why “AI” is...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-31T10:33:57+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/9798360228431.html">
	<title>Russ Allbery: Review: Painting the Blues in Gretna Green</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/9798360228431.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;Painting the Blues in Gretna Green&lt;/cite&gt;, by Linzi Day&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Midlife Recorder #2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;Linzi Day&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;November 2022&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;9798360228431&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;577&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;Painting the Blues in Gretna Green&lt;/cite&gt; is a self-published fantasy
novel and the second in the Midlife Recorder series. It picks up
immediately after the end of &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/9798837010774.html&quot;&gt;&lt;cite&gt;Midlife in
Gretna Green&lt;/cite&gt;&lt;/a&gt;. I also read it almost immediately after, so I didn&#39;t pay
attention to how good the recap of previous events was.
&lt;/p&gt;

&lt;p&gt;
As before, this is urban fantasy except not urban. Day calls it paranormal
women&#39;s fantasy, which I suppose is as good of a genre label as any. The
other book I can think of off-hand that would go into that genre would be
Nancy Springer&#39;s &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-380-76742-2.html&quot;&gt;&lt;cite&gt;Larque on the Wing&lt;/cite&gt;&lt;/a&gt;,
although it is considerably more literary.
&lt;/p&gt;

&lt;p&gt;
I suspect I&#39;m going to read this whole series and it&#39;s going to be
impossible to review these books without talking about Niki&#39;s job, so I&#39;m
not going to treat that as a spoiler. It&#39;s fairly well-advertised in the
marketing for the book, so that feels justified. If you&#39;re particularly
averse to any spoilers, though, you may want to stop reading here until
you&#39;ve gotten to the reveal in the first book.
&lt;/p&gt;

&lt;p&gt;
Niki is now officially the Recorder, with the power, advice book, and
sentient house to go with it. She&#39;s about to face her first test in
managing interworld politics: There&#39;s something amiss in the world of the
Picts. Her allies are dropping hints, there&#39;s a petition from a group on
the Pict world that she can&#39;t make sense of, and although she likes the
queen of the Picts, there is a great deal of tension beneath the surface
that she doesn&#39;t understand. Meanwhile, after the incompetent disaster
that she uncovered in the first book, Niki is determined to pick her new
staff by her own criteria.
&lt;/p&gt;

&lt;p&gt;
The second book leans even harder into giving Niki both a tangled mess
created by previous incompetence and enough power to fix it. Watching that
happen is very satisfying, particularly when it involves surprising people
who are rather too used to getting their own way.
&lt;/p&gt;

&lt;p&gt;
I was somewhat less convinced that Niki is getting the right training to
make the decisions that she&#39;s making. Diplomacy and staff management are
real skills that one needs to learn, not just wing on vibes and gut
instinct. My love of competence porn occasionally wishes that Niki had a
bit more structure around her competence. We do at least get a new
fictional self-help book on how to rule that contributes the quotes that
open each chapter. Not the ethics and management training that I would
have chosen, but it&#39;s something!
&lt;/p&gt;

&lt;p&gt;
In defense of Niki&#39;s technique, it becomes clear in this book that the
last few recorders have been far too cautious, conservative, and content
with a status quo that involved a minimum of work. One of the delights of
this book is that Niki thinks power exists to be used to fix things and is
determined to use it, not just sit on it. I had more suspension of
disbelief issues with this book than with the first — some of the problems
Niki is solving seem far too obvious to have been in stasis for this long
while also having this easy of a solution, and the level of political
power given to the Recorder is a bit unbelievable — but it is so
satisfying to see Niki cajole and bully people into being sensible.
&lt;/p&gt;

&lt;p&gt;
I have no idea if this is intentional on Day&#39;s part, but I will not be at
all surprised if adult-diagnosed ADHD comes up at some point in this
series. The way that Niki&#39;s focus jumps, her tendency to veer between
focusing on a problem and forgetting about it, and something about the way
she switches between trains of thought or misses important context because
she&#39;s jumping to conclusions is making me wonder. This, to be clear, is
not a complaint; I think it makes Niki more relatable and more
interesting. It&#39;s a good thing that she has a sentient house to serve as
her assistant. The glee with which she&#39;s delegating any task that involves
keeping track of details or following up with other people feels like a
bit of an indicator by itself.
&lt;/p&gt;

&lt;p&gt;
I did get a bit frustrated with the plot structure of this book. Niki
keeps mentioning that a critical petition submitted to her office makes no
sense, but it takes half of this (rather long) book before she finally
explains to anyone else, even the reader, what&#39;s deficient about it. The
excuse within the book is that she&#39;s having a rather busy day, but by the
third time Niki mentions and then fails to do anything about the petition,
I was wishing Day would stop bringing it up until she was ready for that
part of the plot.
&lt;/p&gt;

&lt;p&gt;
This, as with a few issues in the previous book, feels partly like an
editing problem. There is something joyful in indulgent, sprawling books,
but only up to the point where they become repetitive. &lt;cite&gt;Painting the
Blues&lt;/cite&gt; was right at that line, and once again I wish someone had helped
Day trim about fifty pages out of it.
&lt;/p&gt;

&lt;p&gt;
All that said, and despite having more quibbles with this book than the
previous one, this continues to be great fun. It&#39;s satisfying
wish-fulfillment about fixing long-standing problems and having the power
to not have to put up with abusive nonsense and ridiculous bullshit, and I
am so here for that. I hope Niki realizes she&#39;s eventually going to need
more refined skills than a heart-to-heart over wine, but she&#39;s learning on
the job and I&#39;m happily along for the ride. She&#39;s also capable of
recognizing skill in other people, and that goes a long way.
&lt;/p&gt;

&lt;p&gt;
Recommended if you liked the first one and are in the mood for another
fantasy of &quot;no, we&#39;re not going to leave it that way, we&#39;re going to fix
that right now.&quot;
&lt;/p&gt;

&lt;p&gt;
Followed by &lt;cite&gt;Ties that Bond in Gretna Green&lt;/cite&gt;.
&lt;/p&gt;

&lt;p&gt;Rating: 7 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-31T03:06:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://www.earth.li/~noodles/blog/2026/07/my-cpu-died.html">
	<title>Jonathan McDowell: My CPU died</title>
	<link>https://www.earth.li/~noodles/blog/2026/07/my-cpu-died.html</link>
     <content:encoded>&lt;p&gt;I built my current house server &lt;a href=&quot;https://www.earth.li/~noodles/blog/2019/07/upgrading-the-house-server.html&quot;&gt;back in 2019&lt;/a&gt;. It had an upgrade from the original Ryzen 2700 to a 5700G in late 2021, but otherwise is still running with the original setup. Back in November it developed some erratic behaviour (initially manifesting as problems with the TPM, which is ironic as I’ve spent a bunch of time at my day job trying to improve TPM reliability), culminating in unreliable reboots. I had a limited amount of ability to swap parts out, but ultimately decided it was a motherboard issue (thinking perhaps &lt;a href=&quot;https://www.reddit.com/r/Amd/comments/byi8py/that_board_has_bad_vrms/&quot;&gt;VRM problems&lt;/a&gt;), found a replacement &lt;a href=&quot;https://pcbelfast.co.uk/&quot;&gt;locally&lt;/a&gt;, and everything seemed fine.&lt;/p&gt;

&lt;p&gt;Until May.&lt;/p&gt;

&lt;p&gt;At that point I rebooted the machine for a Debian point release, and it failed to come back. Fans would spin, but there was no sign of actual life. I ended up pressing a temporary machine into service (that could at least run the Home Assistant container, and a few other critical bits) while I tried to work out what was wrong. I’d kept the previous motherboard, and still had the Ryzen 2700, so I did a bunch of swaps (and obtained a motherboard buzzer to try and get some indication about whether there were useful beep codes being emitted), and ultimately came to the conclusion that the CPU had died.&lt;/p&gt;

&lt;p&gt;I’m not quite clear what happened here. I played it safe and replaced the PSU at the same time, in case that was the original cause back in November and ultimately damaged the CPU, but both old + new motherboards worked just fine with the 2700.&lt;/p&gt;

&lt;p&gt;That left a decision about what to do. This &lt;a href=&quot;https://www.earth.li/~noodles/blog/2013/04/building-a-new-house-server.html&quot;&gt;previous server&lt;/a&gt; was from 2013, so this machine has now lasted longer than that and I could justifiably upgrade. However when I went to look at what the equivalent modern machine would be it’s only a couple of generations later (Zen 5 vs Zen 3), and 64GB RAM alone would have set me back ~ £1k. For not a lot of gain. So I ended up buying a replacement Ryzen 5700G, hopefully allowing me to put off thinking about an upgrade until Zen 6 is out, and RAM prices are saner (though I understand that might take a &lt;a href=&quot;https://www.techspot.com/news/112934-ram-prices-expected-rise-another-40-50-q3.html&quot;&gt;couple of years&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;It’s not the first time I’ve had a faulty PSU be the cause of a dead machine, but it was a pretty frustrating experience.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-31T00:28:00+00:00</dc:date>
	<dc:creator>Jonathan McDowell</dc:creator>
</item> 
<item rdf:about="https://optimizedbyotto.com/post/estonia-well-governed-country/">
	<title>Otto Kekäläinen: Estonia, the country of the fit and the wit</title>
	<link>https://optimizedbyotto.com/post/estonia-well-governed-country/</link>
     <content:encoded>&lt;img alt=&quot;Featured image of post Estonia, the country of the fit and the wit&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/featured-image.jpg&quot; /&gt;&lt;p&gt;While many Western democracies seem to be in a state of decay and are no longer the safe, civilized and prosperous countries they once were, there are still some European countries that are governed well. One of those that stand out is Estonia.&lt;/p&gt;
&lt;p&gt;Estonia is probably most well known for &lt;strong&gt;multiple software companies&lt;/strong&gt; that originated from there, such as &lt;a class=&quot;link&quot; href=&quot;https://wise.com/invite/ecac/ottok108&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Wise&lt;/a&gt;, &lt;a class=&quot;link&quot; href=&quot;https://invite.bolt.eu/OTTOKSQ&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Bolt&lt;/a&gt;, Pipedrive and Skype. The government itself is also famous for being early in issuing &lt;strong&gt;government IDs with an embedded smart chip&lt;/strong&gt; for online authentication already in the 1990s. Via the national portal at &lt;a class=&quot;link&quot; href=&quot;https://eesti.ee/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;eesti.ee&lt;/a&gt; all residents can access extensive eServices ranging from viewing their health benefits to filing taxes.&lt;/p&gt;
&lt;p&gt;Estonia has also been running an &lt;a class=&quot;link&quot; href=&quot;https://www.e-resident.gov.ee/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;e-Residency&lt;/a&gt; program since 2014, where they issue digital ID cards to foreigners, making it easy for them to remotely log into the government portals and for example, establish businesses, file annual reports and so forth. Note that the e-Residency is not a path to physical residency. Estonia does, however, have &lt;a class=&quot;link&quot; href=&quot;https://www.e-resident.gov.ee/nomadvisa/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;a separate Digital Nomad visa program&lt;/a&gt; that makes it easy for &lt;strong&gt;non-EU citizens&lt;/strong&gt; to also physically establish themselves in Estonia, assuming, of course, you meet the criteria, which includes, among others, a minimum monthly income of 3960 € from outside Estonia. &lt;strong&gt;EU citizens&lt;/strong&gt; naturally have free mobility inside the EU and can simply get an apartment and register as a resident in Estonia if they so choose. And there are plenty of reasons to do so.&lt;/p&gt;
&lt;h2 id=&quot;estonians-value-health-education-and-entrepreneurship&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#estonians-value-health-education-and-entrepreneurship&quot;&gt;&lt;/a&gt;Estonians value health, education and entrepreneurship
&lt;/h2&gt;&lt;p&gt;I moved to Estonia about one and a half years ago. In &lt;em&gt;my observations&lt;/em&gt; Estonia strikes me as &lt;strong&gt;a country that values health, education&lt;/strong&gt; (in particular programming and natural sciences) and entrepreneurship highly.&lt;/p&gt;
&lt;p&gt;I don’t know how Estonians achieve it, but they look pretty fit and rarely obese. Estonia has rye bread and sauna in their culture just like Finland, and in addition the flat terrain and well-planned bike routes and extensive network of parks (and pull-up bars everywhere) seem to create an environment where it is easy to live in a healthier way. The consumption of processed foods and candy also seems relatively low among Estonians.&lt;/p&gt;
&lt;p&gt;The &lt;a class=&quot;link&quot; href=&quot;https://www.myfitness.ee/en/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;gym chain MyFitness&lt;/a&gt; also seems to be present everywhere. Even the Tallinn airport has a calisthenics workout station right at the departure gates, which anyone is free to use while waiting for their flight to take off. One of the top longevity influencers in Europe, &lt;a class=&quot;link&quot; href=&quot;https://www.siimland.co/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Siim Land&lt;/a&gt;, is Estonian.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Estonia has lots of good bike paths, parks and outdoor gyms&quot; class=&quot;gallery-image&quot; height=&quot;628&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-harbour-pull-up-bar.jpg&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;There is even a calisthenics station with pull-up bar and more at the departure gates at Tallinn airport&quot; class=&quot;gallery-image&quot; height=&quot;628&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-airport-pull-up-bar.jpg&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;Estonians also seem to value the school system highly. The government has been actively &lt;a class=&quot;link&quot; href=&quot;https://www.valitsus.ee/en/news/government-approved-2026-state-budget&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;raising teacher pay and has a stated goal of reaching 120% of the national average by 2027&lt;/a&gt;. The students are also expected to value the education and respect their teachers. According to the &lt;a class=&quot;link&quot; href=&quot;https://www.oecd.org/en/publications/results-from-talis-2024-country-notes_e127f9e2-en/estonia_44178e34-en.html&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;TALIS 2024 survey&lt;/a&gt; (OECD’s international teacher survey), Estonian teachers spend significantly more time on actual teaching and learning and waste less time on interruptions or keeping classroom order compared to the OECD average. This is among the highest rates internationally, meaning they spend relatively little time on maintaining order or dealing with disruptions. While the international education benchmark PISA scores have been dropping globally, Estonia has consistently been climbing the ranks in past decades. In the latest &lt;a class=&quot;link&quot; href=&quot;https://www.oecd.org/en/publications/pisa-2022-results-volume-i_53f23881-en/full-report/how-did-countries-perform-in-pisa_dc514907.html&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;PISA study (from 2022), Estonia ranked number one in Europe&lt;/a&gt; for reading, mathematics and science. In the overall results, Estonia ranked seventh globally, only behind countries such as Japan, Korea and Singapore.&lt;/p&gt;
&lt;p&gt;Valuing entrepreneurship is evident in how the taxation system is set up in Estonia. Famously, in Estonia, companies can defer taxes on annual earnings and reinvest all of their profit in growing the company. Taxes are due only later, when paid out from the company, for example as dividends. For individuals, receiving dividends from any Estonian or foreign company is tax-free as long as the company paying dividends already paid corporate tax on the same income.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The tax system is also very simple.&lt;/strong&gt; For all individuals, all types of income, including salary and capital gains, are always taxed at a flat rate of 22%. This removes the incentive for anyone to try to convert income into different types, setting up holding company structures and other optimizations as there is no gain. All entrepreneurs can simply focus on growing their business and forget extra bureaucracy. There is also no marginal tax rate cliff to stop working at – everyone is encouraged to always try to produce as much value as they can. A simple tax system is also reflected in the fact that anyone can easily &lt;a class=&quot;link&quot; href=&quot;https://emta.ee/en&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;read all tax rules that apply to individuals in plain English on the Estonian tax authority website&lt;/a&gt;, and one does not need to hire any accountants simply to file taxes.&lt;/p&gt;
&lt;p&gt;Estonia also has a very straightforward investment account system: any person can freely open a self-directed investment account at any brokerage at no extra cost and report it as such to the tax authority, and then use it to save for an apartment, retirement, or other purposes, and defer all income taxes until withdrawal. There are no caps or time limits, and all residents are encouraged to save and invest as much as they can and thus take responsibility for their own wealth accumulation.&lt;/p&gt;
&lt;p&gt;It seems that culturally Estonians respect people who are active and progress in their careers and businesses more than in other countries. Unlike in Finland, successful people are admired and living on government welfare is not romanticized. At the same time, the government benefits are less generous so people can’t live comfortably on them and, for example, &lt;a class=&quot;link&quot; href=&quot;https://news.err.ee/600251/nearly-half-of-quota-refugees-currently-not-in-estonia&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;many of the asylum seekers Estonia accepted have since left on their own initiative&lt;/a&gt; to other European countries in search of better benefits.&lt;/p&gt;
&lt;h2 id=&quot;low-crime-high-trust&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#low-crime-high-trust&quot;&gt;&lt;/a&gt;Low crime, high trust
&lt;/h2&gt;&lt;p&gt;Another thing that strikes me when walking the streets of Tallinn is that there are no drug addicts, beggars, thugs or the like. The difference compared to, for example, Vancouver (where I lived previously) is stark. In public buildings, people leave their coats and bags hanging in the lobby while visiting. Private houses and apartment block yards are not fenced. In my building, I noticed people even leave their bikes unlocked in the bike shed. I have also seen the staff of a coffee stall in a shopping mall going for a break and leaving everything unattended, not worrying that anyone would take anything while the staff is away.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Nobody is stealing anything from the unattended coffee shop while staff is having a break at Ülemiste shopping mall&quot; class=&quot;gallery-image&quot; height=&quot;450&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-coffee-stand-unattanded.jpg&quot; width=&quot;600&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;This is not just my personal experience. According to the &lt;a class=&quot;link&quot; href=&quot;https://www.numbeo.com/crime/rankings_by_country.jsp?title=2026&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Numbeo crime index&lt;/a&gt;, Estonia has one of the lowest crime rates in the world. Also, comparing drug and property crime stats, for example, Finland has twice as much crime per capita, and places like Vancouver in Canada almost five times more.&lt;/p&gt;
&lt;p&gt;I don’t have any clear explanation for why crime is so much lower in Estonia, but some suggest that higher social cohesion and lower levels of welfare contribute to people standing to lose more if they behave antisocially. Compared to Finland, Estonia also more readily jails repeat offenders, and those who are put on trial will experience a swifter court process thanks to simplified legal processes and more efficient governance.&lt;/p&gt;
&lt;h2 id=&quot;moving-to-estonia-quick-checklist&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#moving-to-estonia-quick-checklist&quot;&gt;&lt;/a&gt;Moving to Estonia: quick checklist
&lt;/h2&gt;&lt;p&gt;Moving to Estonia is very easy for any EU citizen, in particular if your work is not location-dependent (e.g., remote work or an online business) and you are simply looking for the cleanest and safest environment to live in.&lt;/p&gt;
&lt;p&gt;First, check into a hotel in Tallinn, check out various neighborhoods to figure out what area you like (my favorites are Kalaranna, Kalamaja, Noblessner and Volta) and start browsing available apartments &lt;a class=&quot;link&quot; href=&quot;https://www.kv.ee/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;in English at kv.ee&lt;/a&gt;. Most professionals speak fluent English, so there should not be any difficulty in reaching out to people by email or phone.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Tallinn is famous for the old town&quot; class=&quot;gallery-image&quot; height=&quot;628&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-old-town.jpg&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;The economic boom of recent decades created a lot of new construction, with Kalaranna being among the newest areas&quot; class=&quot;gallery-image&quot; height=&quot;628&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-kalaranta.jpg&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;The next step is to buy a local prepaid SIM card at e.g., an R-Kiosk or a convenience store as signing up for other matters later on will require an Estonian phone number. Once you have an apartment and e.g., signed a rental agreement, you can register in the population registry online.&lt;/p&gt;
&lt;p&gt;After that, you have proof you are a local resident with an address and telephone number in Estonia. With local resident status, you can go to the police station to get a local ID card. Don’t bother scheduling an appointment, just go to the &lt;a class=&quot;link&quot; href=&quot;https://www.politsei.ee/en/services/services/tallinn-tammsaare&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Tammesaare police station in Tallinn&lt;/a&gt;, take a queue number and wait. Once it is your turn, they will guide you on how to use the photo booth, fingerprint registration device, and file your application. A few days later you will receive an email confirming whether your application was accepted, and after a few more days, you will get another email notifying you that your ID card has been printed and is available for pick-up at the same location. &lt;strong&gt;This will also be your first practical experience of how fast and efficient the government in Estonia is.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Once you have the local ID card, you can use the smart card feature to log into all the government eServices and sort out the rest of the relocation process, such as registering tax residency and getting a family doctor.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;The main eServices portal in Estonia: eesti.ee&quot; class=&quot;gallery-image&quot; height=&quot;675&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/estonia-government-eservices-portal.png&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;h2 id=&quot;how-did-estonia-evolve-to-be-like-this&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#how-did-estonia-evolve-to-be-like-this&quot;&gt;&lt;/a&gt;How did Estonia evolve to be like this?
&lt;/h2&gt;&lt;p&gt;After Estonia regained its independence after the fall of the Soviet Union in 1991, the first elected government in 1992 was led by a very progressive 31-year-old Prime Minister &lt;a class=&quot;link&quot; href=&quot;https://en.wikipedia.org/wiki/Mart_Laar&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Mart Laar&lt;/a&gt;, who managed to set up some very good policies and laid the foundation of a society that has evolved well in the decades since. Estonia was very lucky to have people in power in the 1990s who didn’t simply copy what other Western countries were doing, but who tried to think about things from first principles and create Estonia’s own model for efficient and fair governance. As a post-Soviet country, the population had also been vaccinated against overly socialist and unrealistic ideals, and everyone had a healthy distrust of the government’s ability to solve problems and emphasis was placed on people’s liberty to work for themselves as they best see fit. The improvement in living standards over the past 35+ years has also been witnessed by the population, and voting behavior supports keeping the country on the same trajectory.&lt;/p&gt;
&lt;p&gt;General living standards still continue to improve as the &lt;a class=&quot;link&quot; href=&quot;https://stat.ee/en/news/average-wages-increased-by-56-last-year&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;nominal wage growth sits at around 6%&lt;/a&gt;, clearly above the &lt;a class=&quot;link&quot; href=&quot;https://stat.ee/en/news/the-consumer-price-index-was-up-by-31-in-february-year-on-year&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;annual inflation rate of about 3%&lt;/a&gt;. In 2026, the Estonian &lt;a class=&quot;link&quot; href=&quot;https://www.eestipank.ee/en/press/economic-forecast-achieving-lasting-growth-economy-needs-confidence-invest-16062026&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;economy is expected to grow about 2.4%&lt;/a&gt;, which is faster than the EU average. The growth in Estonia is not the result of any accounting tricks - Estonia is part of the euro and can’t print its own currency, nor has it been funding the public sector with excessive debt. With a 24% debt-to-GDP ratio, Estonia consistently ranks as one of the most responsibly managed countries among advanced Western economies.&lt;/p&gt;
&lt;p&gt;As wages in Estonia soon catch up with the EU average, and higher defence spending has forced the government to raise taxes in recent years, the economic growth that Estonia has enjoyed for 35+ years since it exited the Soviet Union might slow down a bit in future years. The policies that fueled this growth in living standards, however, are likely to stay.&lt;/p&gt;
&lt;h2 id=&quot;the-tiger-leap&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#the-tiger-leap&quot;&gt;&lt;/a&gt;The tiger leap
&lt;/h2&gt;&lt;p&gt;There is one specific government policy in Estonia’s history that I think should be highlighted in particular. Estonia was very progressive by announcing the &lt;a class=&quot;link&quot; href=&quot;https://www.educationestonia.org/tiger-leap/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Tiigrihüpe&lt;/a&gt; (&lt;em&gt;Tiger Leap&lt;/em&gt;) program in 1996 with the goal of equipping all schools with computers and teaching all students the basics of programming. This surely had a large influence on why Estonia has so many successful software companies, why the government eServices are so mature that even neighboring countries like Finland are striving to copy the Estonian government’s IT architecture called &lt;a class=&quot;link&quot; href=&quot;https://e-estonia.com/solutions/interoperability-services/x-road/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;em&gt;X-road&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Tiigrihüpe project was originally suggested in the mid-1990s by &lt;a class=&quot;link&quot; href=&quot;https://en.wikipedia.org/wiki/Toomas_Hendrik_Ilves&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Toomas Hendrik Ilves&lt;/a&gt;, then ambassador of Estonia to the United States, Canada and Mexico, and later President of Estonia in 2006–2016. While he was a psychologist by education, he was also a self-taught amateur programmer and used his political influence to promote sensible adoption of information technology in both Estonia and the EU.&lt;/p&gt;
&lt;p&gt;The history of Estonia has several prominent figures who were not lawyers by profession but engineers, scientists and historians who were very practical in their political decisions, which I think is now reflected in how government processes were formed.&lt;/p&gt;
&lt;p&gt;The video below shows how the Estonian government advertises itself and what values they choose to highlight:&lt;/p&gt;
&lt;div class=&quot;video-wrapper&quot;&gt;


&lt;/div&gt;
&lt;h2 id=&quot;should-other-countries-adopt-policies-from-estonia&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#should-other-countries-adopt-policies-from-estonia&quot;&gt;&lt;/a&gt;Should other countries adopt policies from Estonia?
&lt;/h2&gt;&lt;p&gt;Of course, not everything is perfect in Estonia either. The &lt;a class=&quot;link&quot; href=&quot;https://stat.ee/en/en/find-statistics/statistics-theme/population/births&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;fertility rate of 1.16&lt;/a&gt; in Estonia is very low. This trend is present globally, but in Estonia it is way below the EU average. Also, the service culture is something that needs to improve in Estonia. While services are in general fast and efficient, the attitude of people working in cafes and stores does not reflect a willingness to fill in gaps if the standard process falls short, nor are visitors actively made to feel welcome as individual humans, but are treated as mere process inputs.&lt;/p&gt;
&lt;p&gt;However, many of the things listed earlier I think should be studied by policymakers elsewhere. Societies are complex systems and there is of course no guarantee that copying a single policy to another country with different ethnicities, history and ingrained culture would lead to the same policy outcomes. But &lt;strong&gt;considering that Estonia is a small country without favorable geography and no natural resources&lt;/strong&gt;, and that it started out from a place of total chaos, low economic activity and high crime in 1992 to rise to what it is now in 2026, the success it has seen is surely largely a result of good policies, governance and culture that other countries can and should mimic.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-31T00:00:00+00:00</dc:date>
	<dc:creator>Otto Kekäläinen</dc:creator>
</item> 
<item rdf:about="https://xana.scru.org/posts/mintings/mergetooling.html">
	<title>Clint Adams: not ninpo</title>
	<link>https://xana.scru.org/posts/mintings/mergetooling.html</link>
     <content:encoded>&lt;div class=&quot;inlinecontent&quot;&gt;
&lt;p&gt;The UX of &lt;code&gt;jj&lt;/code&gt;&#39;s builtin merge editor finally became
too much for me. So, I looked at the list of merge
tool options, saw &lt;code&gt;vimdiff&lt;/code&gt;, and thought, “Oh, cool,
I know how to use vimdiff.” So, I launched
&lt;code&gt;jj config edit --user&lt;/code&gt;, added a &lt;code&gt;ui&lt;/code&gt; section, and
set &lt;code&gt;merge-editor&lt;/code&gt; to &lt;code&gt;vimdiff&lt;/code&gt;. With the new
config, I ran &lt;code&gt;jj resolve&lt;/code&gt; again. It was at that
point that I realized that I do not, in fact, know
how to use &lt;code&gt;vimdiff&lt;/code&gt;: I only know how to use
&lt;code&gt;vimdiff&lt;/code&gt; with two buffers. What appeared in my
terminal was a 4-pane monstrosity. Why are there
four panes? I&#39;m trying to resolve conflicts
between only two changes on only one file. For a
moment, I nearly go down a rabbit hole, because
&lt;a href=&quot;https://github.com/jj-vcs/jj/wiki/Vim,-Neovim#using-vim-as-a-diff-tool&quot;&gt;this&lt;/a&gt;
says that by default, &lt;code&gt;vimdiff&lt;/code&gt; is “barely useable”
[sic]. Should I be installing some addon or a
Python script? Apparently there are tradeoffs.
I just want to resolve these conflicts without
doing line-by-line approvals for how ever many
hours that would take.&lt;/p&gt;
&lt;p&gt;Accordingly, I ran away in terror, installed &lt;code&gt;meld&lt;/code&gt;,
set &lt;code&gt;merge-editor&lt;/code&gt; to meld, and went clicky-clicky
in the GUI. I&#39;m not happy using a GUI, but at least
it didn&#39;t have a mysterious extra buffer to confuse
and taunt me.&lt;/p&gt;
&lt;/div&gt;

&lt;div class=&quot;info&quot;&gt;
    Posted on 2026-07-30
    
&lt;/div&gt;
&lt;div class=&quot;info&quot;&gt;
    
    Tags: &lt;a href=&quot;https://xana.scru.org/tags/mintings%20jujutsu.html&quot; rel=&quot;tag&quot; title=&quot;All pages tagged &#39;mintings jujutsu&#39;.&quot;&gt;mintings jujutsu&lt;/a&gt;
    
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-30T12:12:12+00:00</dc:date>
	<dc:creator>C</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/0-9863735-1-6.html">
	<title>Russ Allbery: Review: In the House of Aryaman, a Lonely Signal Burns</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/0-9863735-1-6.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;In the House of Aryaman, a Lonely Signal Burns&lt;/cite&gt;, by Elizabeth Bear&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Sub-Inspector Ferron Mysteries #1&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;Sobbing Squonk Press&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;2012&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Printing:&lt;/td&gt;
    &lt;td&gt;2018&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;0-9863735-1-6&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;73&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;In the House of Aryaman, a Lonely Signal Burns&lt;/cite&gt; is a science fiction
police procedural set in relatively near-future India. This novella was
originally published in &lt;cite&gt;Asimov&#39;s SF&lt;/cite&gt; and collected in several
anthologies as well as Bear&#39;s &lt;cite&gt;Shuggoths in Bloom&lt;/cite&gt; collection, which
I have on my shelf but have not yet read. I probably should have checked
that before I got another copy. It is the first story of a series in the
sense that there is an Audible-only sequel available.
&lt;/p&gt;

&lt;p&gt;
Like many police procedurals, this one opens with a crime scene.
Sub-Inspector Ferron and her partner are inspecting a tube of human meat
in the middle of the rug of a luxurious apartment in Bengaluru. The tube
is apparently the remains of one Dexter Coffin, an American with a high
tech workspace who was apparently mangled beyond recognition in his locked
apartment near a table set for two.
&lt;/p&gt;

&lt;p&gt;
Dexter&#39;s cat is a witness. In this future world of cats enhanced with
limited language skills, this would have been very useful, but the cat&#39;s
memory was apparently wiped. Ferron will have to get to the bottom of the
mystery some other way. Also, she apparently now has a new cat.
&lt;/p&gt;

&lt;p&gt;
Meanwhile, Ferron is worrying about her partner&#39;s mental health, her
partner is worrying about her use of stimulants to stay on duty for this
murder investigation, and Ferron&#39;s mother is harassing her for money to
pay the bills of her virtual reality addiction. Her job is a good
distraction from other problems she&#39;d rather not deal with.
&lt;/p&gt;

&lt;p&gt;
I am trying to come up with something insightful to say about this story,
and I&#39;m not having much success. It&#39;s a police procedural with a bit of a
science fiction twist. The characters are fine but not, at least for me,
particularly engaging. There is some deft world-building, but nothing that
grabbed my attention or made me desperate to read more stories in this
world.
&lt;/p&gt;

&lt;p&gt;
Perhaps the most interesting part of the background, and the reason why I
picked up this novella, is that this is the universe that eventually
becomes the setting of the &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/1-5344-0300-0.html&quot;&gt;White Space series&lt;/a&gt;.
There is an early version of right-minding handled entirely through
medicine without the later invention of the fox implant, and there are
some signs that humanity is slowly digging itself out of the hole of
climate change and antisocial behavior that it had dug. I found this
mildly interesting, but it doesn&#39;t add much to the later series and is
very skippable.
&lt;/p&gt;

&lt;p&gt;
The source of the title is a bright light originating in the Andromeda
galaxy, which is contained in Uttara Bhādrapadā in Vedic astrology. Ferron
says this is under the influence of the god Aryaman. This is unrelated to
the plot; it&#39;s just a background event that prompts some introspective
musing from Ferron at the end of the story. It&#39;s a nice moment, but I
would have been more interested in the full story of first contact between
Earth and the Synarche.
&lt;/p&gt;

&lt;p&gt;
This was a mildly pleasant way to spend a few hours and I&#39;m already
forgetting all of the details. It&#39;s a competent story, but not one I feel
a need to recommend to others.
&lt;/p&gt;

&lt;p&gt;
Followed by &lt;cite&gt;A Blessing of Unicorns&lt;/cite&gt;, which appears to be an Audible
audiobook exclusive.
&lt;/p&gt;

&lt;p&gt;Rating: 6 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-30T03:25:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://diffoscope.org/news/diffoscope-326-released/">
	<title>Reproducible Builds (diffoscope): diffoscope 326 released</title>
	<link>https://diffoscope.org/news/diffoscope-326-released/</link>
     <content:encoded>&lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;326&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[ Vagrant Cascadian ]
* Add external tool reference for &quot;pedump&quot; to use the &quot;mono&quot; package on
  GNU guix.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href=&quot;https://diffoscope.org&quot;&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-30T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds (diffoscope)</dc:creator>
</item> 
<item rdf:about="http://joeyh.name/blog/entry/my_harddrive_is_probably_not_full/">
	<title>Joey Hess: my harddrive is probably not full</title>
	<link>http://joeyh.name/blog/entry/my_harddrive_is_probably_not_full/</link>
     <content:encoded>&lt;p&gt;I enjoyed reading this post by Marginalia
&lt;a href=&quot;https://www.marginalia.nu/log/a_139_hdd/&quot;&gt;&quot;Your harddrive is probably full&quot;&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;
You can construct an entropic argument that there are simply more ways for
a harddrive to be full than ways in which it can be empty.
&lt;/blockquote&gt;


&lt;p&gt;Of course it made me check how full my laptop drive is, and indeed it was more
than 75% full, as predicted.&lt;/p&gt;

&lt;p&gt;But, I almost never feel that my hard drive is full. I can very easily free
up almost any amount of disk space at any time, without any thought. While
writing this blog post, I ran a single command and now my harddrive is
50% empty.&lt;/p&gt;

&lt;blockquote&gt;
The other part of the equation is that a full disk isn’t a problem until
it’s so full you can’t put more stuff on it, and at the point it’s so
irredeemably cluttered that when you do clean it up, you only have the
patience to clean up enough to bide your time, judging the fate of every
file on the harddrive is simply too much work.
&lt;/blockquote&gt;


&lt;p&gt;Why doesn&#39;t this apply to me? Because I have put in the up-front thought
to organize things, so that I never have to do that anymore.&lt;/p&gt;

&lt;p&gt;I have 3 categories of files that I can remove at any time I need more
space, without any thought:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Any files that are stored in git-annex. This is one of git-annex&#39;s
superpowers; you can &lt;code&gt;git-annex drop&lt;/code&gt; any file and stop it using disk
space, but the file is still there (as a broken symlink) so you don&#39;t
risk losing or forgetting about it.&lt;/li&gt;
&lt;li&gt;Caches.&lt;/li&gt;
&lt;li&gt;Files in &lt;code&gt;~/tmp/&lt;/code&gt;, which is reserved for any files I only want to have a
passing acquaintance with. If I&#39;m not comfortable with something being
deleted at any time, I don&#39;t put it there.&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;Not only do I only have these 3 categories, these are the &lt;em&gt;only&lt;/em&gt; 3
categories for everything except OS files and files I have decided I never
want to remove (eg dotfiles and other files stored in git repos).&lt;/p&gt;

&lt;p&gt;Computer scientists invented caches (and of course cache invalidation is no
problem lol) so I only needed to learn about that one. Unix gave me
&lt;code&gt;/tmp/&lt;/code&gt; as an example that I long ago used as the basis for the rules for my
&lt;code&gt;~/tmp/&lt;/code&gt;. I hope that git-annex might also serve as an example
that moving files between drives is not the best way to manage disk space
use.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-29T17:25:04+00:00</dc:date>
	<dc:creator>Joey Hess</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/9798837010774.html">
	<title>Russ Allbery: Review: Midlife in Gretna Green</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/9798837010774.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt;, by Linzi Day&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Midlife Recorder #1&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;Linzi Day&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;July 2022&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;9798837010774&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;464&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt; is a self-published fantasy novel. It&#39;s
urban fantasy in the sense that it&#39;s set in our world but with magic that
most people don&#39;t know about, but the primary setting is a parish in rural
Scotland and therefore the genre is not urban in that sense. It was Linzi
Day&#39;s published first novel.
&lt;/p&gt;

&lt;p&gt;
As the story opens, Niki McKnight is a widow in Manchester, England with a
job in the Register Office she likes, a boss she hates, and a Bichon Frise
dog she adores. In the year since her husband Nick died, she&#39;s put her
life on hold and made as few decisions as possible, despite some concerned
pushing from her best friend Aysha. The death of her grandmother is not
entirely unexpected, but her inheritance is about to upend her life.
&lt;/p&gt;

&lt;p&gt;
Niki assumes that her grandmother has a modest cottage and a small estate,
and therefore being the named heir will mostly involve cleaning up the
details of a modest life. She is caught by surprise by a requirement in
the will that she live in Gretna Green for a year and a day in order to
inherit. Her initial reaction is to treat this as an absurd impossibility
given her life and job in Manchester, but she slowly realizes something
strange is going on. Her grandmother&#39;s lawyer is lying to her, he refuses
to tell her the value of the estate and seems to think it&#39;s more valuable
than she expected, and her grandmother&#39;s tiny cottage does not seem to be
following the seasons of the rest of the world. There is something magical
at work.
&lt;/p&gt;

&lt;p&gt;
I will not spoil the rest of the reveal. I will say that this is a magical
house book because, if you are anything like me, that is why you will want
to read this series. There are not enough magical house books, and this is
one of the better kind that allow the house to be a full speaking
character.
&lt;/p&gt;

&lt;p&gt;
&lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt; is an unapologetic fantasy of personal
agency. Niki starts the novel with a miserable manager, a messy pile of
unread mail she doesn&#39;t want to deal with, and a lot of personal emotional
baggage. She gets handed a position that requires and rewards standing up
for herself and being decisive. It comes with a pile of unresolved but not
horribly complex problems that were waiting for someone who would listen,
make sensible decisions, and treat other people with respect. Oh, and
there are a few assholes in the way, but they seriously underestimate the
power she has to put a stop to their bullshit.
&lt;/p&gt;

&lt;p&gt;
This is the sort of book that traditional publishers tended not to buy
(although Day apparently did get an offer for this one and turned it
down), and I&#39;m not sure why. Editors thought protagonists should have to
work harder for their payoff? Some lingering Calvinist dourness in English
language publishing mistrusted triumphant books? Obvious wish fulfillment
was considered embarrassing or low-class and thus didn&#39;t warrant
publication? This didn&#39;t apply to the endless &lt;i&gt;bildungsromans&lt;/i&gt;
about magically talented boys, so some level of sexism was probably in
play. Maybe this is finally changing? It reminds me of the bias against
romance novels and their guaranteed happily ever after, and in the case of
romance there was too much money for publishers to leave it on the table.
&lt;/p&gt;

&lt;p&gt;
In any case, the growth of self-publishing has created an alternative
market that let these books reach an audience and I for one am here for
it. A lot of wish-fulfillment books, and a lot of self-published books,
are not very good, but the ones that have a spark of originality and
character can be a delight worth tolerating the somewhat rocky editing and
pacing problems that a full editorial staff might have cleaned up.
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    I loved reading books about kickass women who took no crap and fixed
    their lives up exactly how they wanted them to be. But how did they
    get to be that way? They always started out awesome in the books.
    Seriously, did they kick ass at sixteen? Or did their superpower
    kickassery not kick in until they were thirty? Forty? If so, then I
    was screwed. Would I need to wait till I was fifty or until a genie
    arrived offering wishes? I already felt as if I’d spent my whole life
    waiting for something wild and wonderful to happen.
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
Niki is a Specific Type to a somewhat hilarious degree, and I&#39;m not sure
if Day is playing into that intentionally or if she&#39;s projecting herself
into the book. The amount of self-insertion is not zero: Day also lives in
Gretna Green, owns a Bichon Frise, and worked as an assistant registrar
and civil celebrant. Niki also drinks wine regularly, has a psychic gift,
occasionally reads tarot cards, is an accommodating pushover at work who
struggles to say no to her abusive boss, has impostor syndrome problems,
and swears by a fictional self-help book about grief that provides the
quotes at the starts of chapters. There is a cat, because of course
there&#39;s a cat.
&lt;/p&gt;

&lt;p&gt;
(The fictional self-help book is a spot-on parody played entirely straight
in the story. I think Day is having some fun with the reader? I can&#39;t
tell!)
&lt;/p&gt;

&lt;p&gt;
This is what I mean by unapologetic. It&#39;s easy to read Niki as a
stereotype, but she&#39;s a stereotype a lot of real people can identify with
and there&#39;s something highly satisfying in watching her find her footing.
I &lt;em&gt;like&lt;/em&gt; wish fulfillment books; it&#39;s fun to see someone&#39;s wishes
come true! Particularly in the year of 2026, there&#39;s something immensely
satisfying in seeing an ordinary, insecure person get a massive amount of
power and use it to make the world better. I don&#39;t need everything to be
hard, fraught, and laden with costs in fiction, although I wouldn&#39;t want
every book I read to be like this.
&lt;/p&gt;

&lt;p&gt;
Also, the world building is great. It&#39;s not polished; there&#39;s a bit of a
grab bag feeling to it, I&#39;m dubious the magic system has any underlying
rigorous rule set, and Niki&#39;s powers, once she has access to them, are
more of a semi-sentient genie than a skill she has to learn with hard
practice. But the magic is &lt;em&gt;fun&lt;/em&gt;. The sentient house is one of the
best characters, particularly after Niki realizes how underused it has
been, and I am a sucker for any good sentient house book. The cat is a far
more interesting character than I first thought she would be. And Niki&#39;s
new magical job is more complicated and less typical than the normal
Celtic-inspired fantasy that I thought it was going to be at first.
&lt;/p&gt;

&lt;p&gt;
My primary warning about this book is that Niki starts out beaten down and
grieving her dead husband, and it took me about five pages to decide that
her dead husband was a complete piece of shit who was not worth any of the
grief Niki puts into him. She also doesn&#39;t stand up for herself for the
first hundred pages or so, which made me want to yell at the book a few
times. Both of these problems go away farther into the book, and Niki does
eventually figure out that Nick was abusive trash, but I was relieved when
the &quot;make endless excuses for worthless men&quot; portion of the story was
finally over. You have to stick with it until Niki gets brave enough to
try being the protagonist; once that happens, it becomes great fun.
&lt;/p&gt;

&lt;p&gt;
It is fairly obvious that &lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt; was
self-published, and I wish it had gotten the editing that it deserved. My
copy had a couple of obvious formatting errors, the plot veers about more
than was strictly necessary, and I think a careful editing pass could have
tightened the writing by about fifty pages or so without losing any
important detail. If that sort of thing bothers you, make sure you&#39;re in
self-published fiction mode before starting this one. But it also has that
irrepressible, bubbling-with-ideas feeling of a book where nothing has
suppressed the author&#39;s enthusiasm. It&#39;s a very grabby book; once Niki
starts embracing her new life, I could barely put it down.
&lt;/p&gt;

&lt;p&gt;
If you&#39;re in the mood for a good fantasy wish-fulfillment story that has
no romance and a whole lot of &quot;why are things run this way, no, we&#39;re
changing that,&quot; highly recommended. I had so much fun with this book, and
the series is currently making the rounds of my whole family. Don&#39;t read
this when you&#39;re looking for something challenging and literary and deep;
save it for when you desperately want to watch someone just fix something
for once, damn it.
&lt;/p&gt;

&lt;p&gt;
Followed by &lt;cite&gt;Painting the Blues in Gretna Green&lt;/cite&gt;, which I have
already read, breaking my usual rule of writing reviews before reading the
next book in a series.
&lt;/p&gt;

&lt;p&gt;Rating: 8 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-29T02:19:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/07/28#rcppdate_0.0.7">
	<title>Dirk Eddelbuettel: RcppDate 0.0.7: New Upstream</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/07/28#rcppdate_0.0.7</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://github.com/eddelbuettel/rcppdate&quot;&gt;RcppDate&lt;/a&gt; ships
the featureful &lt;a href=&quot;https://github.com/HowardHinnant/date&quot;&gt;date&lt;/a&gt;
library written by &lt;a href=&quot;https://github.com/HowardHinnant&quot;&gt;Howard
Hinnant&lt;/a&gt; to enable use from R packages. This header-only modern C++
library has been in pretty wide-spread use for a while now, and adds to
C++11, C++14 and C++17 what is (with minor modifications) the ‘date’
library in C++20. The &lt;a href=&quot;https://github.com/eddelbuettel/rcppdate&quot;&gt;RcppDate&lt;/a&gt; package
adds no extra R or C++ code and can therefore be a zero-cost dependency
for any other project; yet a number of other projects decided to
re-vendor it resulting in less-efficient duplication. Oh well. &lt;em&gt;C’est
la vie.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This release syncs with upstream release 3.0.5 made yesterday. We
also made two routine updates to the continuous integration since the
last release a good year ago. The &lt;a href=&quot;https://www.debian.org&quot;&gt;Debian&lt;/a&gt; and &lt;a href=&quot;https://eddelbuettel.github.io/r2u/&quot;&gt;r2u&lt;/a&gt; packages for this new
release have already been uploaded too.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-version-0.0.7-2026-07-27&quot;&gt;Changes in version 0.0.7
(2026-07-27)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Updated to upstream version 3.0.5&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Regular updates to continuous integration setup&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/&quot;&gt;CRANberries&lt;/a&gt;, there
is also a diffstat report for the &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/2026/07/28#RcppDate_0.0.7&quot;&gt;most
recent release&lt;/a&gt;. More information is available at the &lt;a href=&quot;https://github.com/eddelbuettel/rcppdate&quot;&gt;repository&lt;/a&gt; or the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rcpp.date.html&quot;&gt;package
page&lt;/a&gt;.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-28T13:32:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/07/27#057_conditionally_quieten_compilers">
	<title>Dirk Eddelbuettel: #057: Conditionally Quieten Compilers</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/07/27#057_conditionally_quieten_compilers</link>
     <content:encoded>&lt;p&gt;Welcome to post 57 in the &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/code/r4&quot;&gt;&lt;span class=&quot;math inline&quot;&gt;&lt;em&gt;R&lt;/em&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/span&gt;&lt;/a&gt; series.&lt;/p&gt;
&lt;p&gt;R packages with compiled codes can use the file
&lt;code&gt;src/Makevars&lt;/code&gt; to set compilation flags. We often rely on
this to set libraries, include directories or compilation options. When
using external libraries, be it header-only or via headers and linking,
we are often experiencing ‘compilation noise’ when these libraries
tickle warnings under generally-recommended flags such as
&lt;code&gt;-Wall -pedantic&lt;/code&gt;. Two packages I maintain are clearly repeat
offenders here: Eigen, and BH. Both cam generate pages and pages of
compiler output. This is generally not great as it may hide genuine
warnings from our own code.&lt;/p&gt;
&lt;p&gt;What makes matters worse is that some of the available and specific
options for the compilers are treated by &lt;code&gt;R CMD check&lt;/code&gt; as
‘non-portable’ leading to a nag on package checking. Examples are
&lt;code&gt;-Wno-parentheses&lt;/code&gt;, &lt;code&gt;-Wno-maybe-uninitialize&lt;/code&gt; or
&lt;code&gt;-Wno-nunnull&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;I have long resorted to adding these to my per-user
&lt;code&gt;~/.R/Makevars&lt;/code&gt;. When added there, compilation is quieter,
but &lt;code&gt;R CMD check&lt;/code&gt; still nags &lt;em&gt;here&lt;/em&gt; where the option
is set but not at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; or
r-universe. A situation that is not ideal but what somewhat
‘stable’.&lt;/p&gt;
&lt;p&gt;More recently, I realized there was an available check we can use to
&lt;em&gt;conditionally&lt;/em&gt; add extra compilation flags but leave them off by
default. That makes local development quiet allowing us to focus on the
quality of our additions here without noise from third-party libraries
we may use. At the same time we do not need to do anything else to let
&lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; do its work.&lt;/p&gt;
&lt;p&gt;The check we now use is whether there is a &lt;code&gt;.git/&lt;/code&gt;
directory present. If so, we are indeed building from local sources and
can add extra flags. If not, we are likely building from a tar.gz source
archive—which is the case for CRAN—and hence do not set these.&lt;/p&gt;
&lt;p&gt;An example use is this recent additional to package &lt;a href=&quot;https://github.com/qlcal/qlcal-r&quot;&gt;qlcal&lt;/a&gt; where this bit of R
code is invoked from a minimal shell script &lt;code&gt;configure&lt;/code&gt; and
replaces the stub &lt;code&gt;@XTRAFLAGS@&lt;/code&gt; in
&lt;code&gt;src/Makevars.in&lt;/code&gt; (or &lt;code&gt;src/Makevars.win.in&lt;/code&gt;)&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb1&quot;&gt;&lt;pre class=&quot;sourceCode r&quot;&gt;&lt;code class=&quot;sourceCode r&quot;&gt;&lt;span id=&quot;cb1-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;cf&quot;&gt;if&lt;/span&gt; (&lt;span class=&quot;fu&quot;&gt;dir.exists&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;.git&quot;&lt;/span&gt;)) {&lt;/span&gt;
&lt;span id=&quot;cb1-2&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-2&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;do&quot;&gt;## development from a .git directory can use these flags&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-3&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-3&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    xtraflags &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;-Wno-nonnull -Wno-deprecated-declarations&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-4&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-4&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;} &lt;span class=&quot;cf&quot;&gt;else&lt;/span&gt; {&lt;/span&gt;
&lt;span id=&quot;cb1-5&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-5&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;do&quot;&gt;## else build from tarball so stick with existing flags&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-6&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-6&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    xtraflags &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-7&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-7&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;}&lt;/span&gt;
&lt;span id=&quot;cb1-8&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-8&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;win &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;cf&quot;&gt;if&lt;/span&gt; (&lt;span class=&quot;fu&quot;&gt;Sys.info&lt;/span&gt;()[[&lt;span class=&quot;st&quot;&gt;&quot;sysname&quot;&lt;/span&gt;]] &lt;span class=&quot;sc&quot;&gt;==&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;Windows&quot;&lt;/span&gt;) &lt;span class=&quot;st&quot;&gt;&quot;.win&quot;&lt;/span&gt; &lt;span class=&quot;cf&quot;&gt;else&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-9&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-9&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;infile &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;file.path&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;src&quot;&lt;/span&gt;, &lt;span class=&quot;fu&quot;&gt;paste0&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;Makevars&quot;&lt;/span&gt;, win, &lt;span class=&quot;st&quot;&gt;&quot;.in&quot;&lt;/span&gt;))&lt;/span&gt;
&lt;span id=&quot;cb1-10&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-10&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;outfile &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;file.path&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;src&quot;&lt;/span&gt;, &lt;span class=&quot;fu&quot;&gt;paste0&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;Makevars&quot;&lt;/span&gt;, win))&lt;/span&gt;
&lt;span id=&quot;cb1-11&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-11&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;lines &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;readLines&lt;/span&gt;(infile)&lt;/span&gt;
&lt;span id=&quot;cb1-12&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-12&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;lines &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;gsub&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;@XTRAFLAGS@&quot;&lt;/span&gt;, xtraflags, lines)&lt;/span&gt;
&lt;span id=&quot;cb1-13&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-13&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;fu&quot;&gt;writeLines&lt;/span&gt;(lines, outfile)&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;With this change, local compilation is quiet, yet &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; has nothing to nag about (as
seen at the &lt;a href=&quot;https://cran.r-project.org/web/checks/check_results_qlcal.html&quot;&gt;qlcal
results page&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Similarly, one can also check from an actual &lt;code&gt;configure&lt;/code&gt;
file written in autoconf. Here is a similar example from RcppEigen
(showing some relevants parts of the whole file)&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb2&quot;&gt;&lt;pre class=&quot;sourceCode sh&quot;&gt;&lt;code class=&quot;sourceCode bash&quot;&gt;&lt;span id=&quot;cb2-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;co&quot;&gt;# PKG_CXXFLAGS initialized earlier ...&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-2&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-2&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-3&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-3&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;co&quot;&gt;## Check if building locally&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-4&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-4&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;AC_MSG_CHECKING&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[whether&lt;/span&gt; .git/ exists]&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-5&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-5&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;cf&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;bu&quot;&gt;test&lt;/span&gt; &lt;span class=&quot;at&quot;&gt;-d&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;va&quot;&gt;$srcdir&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;/.git&quot;&lt;/span&gt;&lt;span class=&quot;kw&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;cf&quot;&gt;then&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-6&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-6&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;ex&quot;&gt;AC_MSG_RESULT&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[yes,&lt;/span&gt; adding extra flags]&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-7&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-7&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;ex&quot;&gt;AC_SUBST&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[PKG_CXXFLAGS],[&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;va&quot;&gt;${PKG_CXXFLAGS}&lt;/span&gt;&lt;span class=&quot;st&quot;&gt; -Wno-ignored-attributes -Wno-maybe-uninitialized&quot;&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-8&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-8&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;cf&quot;&gt;else&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-9&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-9&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;ex&quot;&gt;AC_MSG_RESULT&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[no,&lt;/span&gt; consider adding &lt;span class=&quot;st&quot;&gt;&#39;-Wno-ignored-attributes -Wno-maybe-uninitialized&#39;&lt;/span&gt; to ~/.R/Makevars]&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-10&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-10&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;cf&quot;&gt;fi&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-11&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-11&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-12&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-12&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;AC_SUBST&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[PKG_CXXFLAGS],&lt;/span&gt; &lt;span class=&quot;pp&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;va&quot;&gt;${PKG_CXXFLAGS}&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;pp&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-13&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-13&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;AC_CONFIG_FILES&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[src/Makevars]&lt;/span&gt;&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-14&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-14&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;AC_OUTPUT&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Once again, with this change compilation is quiet locally, yet
unaffected at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;. Just what
we want. Give it a try in your packages.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can now &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-27T22:40:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="https://jonathancarter.org/?p=12034">
	<title>Jonathan Carter: DebConf26 – Santa Fe, Argentina</title>
	<link>https://jonathancarter.org/2026/07/27/debconf26-santa-fe-argentina/</link>
     <content:encoded>&lt;p class=&quot;wp-block-paragraph&quot;&gt;TL;DR: What a great DebConf! I managed to recharge my Debian batteries, and my talks / BoF sessions all went fine. Already looking forward to DebConf in Japan next year!&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;DebCamp&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The evening before DebCamp started, we had a nice bbq (we taught some locals to call it a “braai” at an organiser’s house and went for a walk around the river as the sun set. It was a very peaceful lead-in to DebCamp.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12057&quot; height=&quot;450&quot; src=&quot;https://jonathancarter.org/files/images/bbq.jpg&quot; width=&quot;800&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12042&quot; height=&quot;452&quot; src=&quot;https://jonathancarter.org/files/images/dc26_blog_river.jpg&quot; width=&quot;800&quot; /&gt;&lt;/figure&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;I set up and sent out the call for Forky desktop artwork:
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/msgid-search/910906f3-7ce4-4884-a49f-4b4a5975471b@debian.org&quot;&gt;https://lists.debian.org/msgid-search/910906f3-7ce4-4884-a49f-4b4a5975471b@debian.org&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;Had many nice discussions about various Debian topics with all the Debian people around. It’s really fun being around people who are natural problem solvers who care deeply about both technical and social issues. At one point Jonas told me “Holy shit, these people are motivated!” and I appreciate that so much too!&lt;/li&gt;
&lt;/ul&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12064&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/ltswine-1024x576.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Debian LTS wine&lt;/em&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Most of my DebCamp was dedicated to preparing for my demo and main talk that followed at DebConf.&lt;/li&gt;



&lt;li&gt;Sadly, we had no loopy this year, I just didn’t have the time, and the people who stepped up to help last year were either overwhelmed with other issues or couldn’t make it. I’ll try to make it happen again for next year by kicking it off long before DC27.&lt;/li&gt;
&lt;/ul&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12059&quot; height=&quot;640&quot; src=&quot;https://jonathancarter.org/files/images/santafe-1024x640.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;View of Santa Fe city from hotel&lt;/em&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;DebConf&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Talk – Is it even possible to build a truly universal system installer?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In &lt;a href=&quot;https://debconf26.debconf.org/talks/6-is-it-even-possible-to-build-a-truly-universal-system-installer/&quot;&gt;this talk&lt;/a&gt; I do a very quick comparison of system installers based on my experience with them. It’s hard to directly compare all of them, since there are so many, and each have their own niche that they attempt to satisfy.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I also introduce &lt;a href=&quot;https://salsa.debian.org/yasi-team/yasi-daemon&quot;&gt;Yasi&lt;/a&gt; – my attempt to answer the question of whether we could build a universal installer, which can also better cover advanced installations, automated installations and niche setups.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s very early days for the project, and I didn’t quite feel ready to share the code with the world, but it was nice that I did a quick demo where I could install a Debian system… and the resulting system actually booted up. *phew*.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is also going to be my main focus for the mid-term future. I aim to have all the basic partitioning options working by the time Debian 14 (Forky) is released, and by the time Debian 15 is released, I have a long list of features that I aim to have working. So, my timeline for having something that’s generally useful is around a year from now, and in around 3 years it should be a fully fledged installer that should cover a very large amount of Debian use cases and architectures. &lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12048&quot; height=&quot;646&quot; src=&quot;https://jonathancarter.org/files/images/image-30-1024x646.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Day Trip&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For the day trip, we did a tour across Santa Fe, visited &lt;a href=&quot;https://www.museodelaconstitucion.org/&quot;&gt;Constitución de la Nación Argentina&lt;/a&gt;, had lunch where we tried various dishes based on local fish from the river, and then went on a boat ride on the river.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12078&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/churchbells.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12090&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/image-32-1024x574.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12092&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/image-33-1024x574.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;BoF Sessions:&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Funding in Free Software Projects:&lt;/strong&gt; I initially registered this BoF because I’m increasingly concerned about how upstreams are asking for donations in their software. I increased the scope to talk about funding in free software in general. It followed Marga’s talk about funding, which focussed more about how developers are funded in general. We didn’t dive very deep into this, but we certainly need some further discussion (and action) on this within Debian.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Debian Social Team:&lt;/strong&gt; My most important issue for this team is a carry-over from last year, I want to set up &lt;a href=&quot;https://pgbarman.org/&quot;&gt;barman&lt;/a&gt; (packaged in Debian) for live postgres syncing for our larger databases. For the smaller DBs, doing a daily dump is quite cheap. But for Matrix, it’s very expensive in terms if i/o and CPU, so it would be ideal to do less regular complete dumps and use live replication for the first line of redundancy instead.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Images Team: &lt;/strong&gt;I wasn’t initially planning to say much during this session, I have some ideas to reduce both size and count of images, without losing any benefits, but I don’t have any work to show for that yet. I ended up talking a lot more than I anticipated, the topics covered were quite good and representative of the current state of Debian images built. I don’t have time to create a full summary, so I suggest checking the etherpad / video recording if you’re interested.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12079&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/cwstablewine.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Some more wine variety during the conference dinner&lt;/em&gt;&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12066&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/busyhacklap-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Debianites in the main hacklab&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Rosario&lt;/h3&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12076&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/rosario-1-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I’m spending two days in Rosario before I head home. Exploring a bit, catching up with sleep, finishing this blog post, signing keys and exploring some ideas I made note of during DebConf.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Thank you to the DebConf26 Team!&lt;/h3&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12073&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/dc-team-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It was a little surreal not being part of any DebConf team for the first time ever, I’ve just been too focussed on getting Yasi ready for my talk (no regrets!). I hope to be more involved again next year, in the meantime, I’m very grateful to everyone who has made this happen, you did a stellar job! I hope to see many of you again next year in Japan!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-27T20:12:18+00:00</dc:date>
	<dc:creator>jonathan</dc:creator>
</item> 
<item rdf:about="https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/index.html">
	<title>Valhalla&#39;s Things: Late Victorian Vampire Shirt</title>
	<link>https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/index.html</link>
     <content:encoded>&lt;article&gt;
    &lt;section class=&quot;header&quot;&gt;
        Posted on July 27, 2026
        &lt;br /&gt;
        
        Tags: &lt;a href=&quot;https://blog.trueelena.org/tags/madeof%3Aatoms.html&quot; title=&quot;All pages tagged &#39;madeof:atoms&#39;.&quot;&gt;madeof:atoms&lt;/a&gt;, &lt;a href=&quot;https://blog.trueelena.org/tags/craft%3Asewing.html&quot; title=&quot;All pages tagged &#39;craft:sewing&#39;.&quot;&gt;craft:sewing&lt;/a&gt;, &lt;a href=&quot;https://blog.trueelena.org/tags/FreeSoftWear.html&quot; title=&quot;All pages tagged &#39;FreeSoftWear&#39;.&quot;&gt;FreeSoftWear&lt;/a&gt;
        
    &lt;/section&gt;
    &lt;section&gt;
        &lt;p&gt;&lt;img alt=&quot;A woman wearing an old-style white shirt with lots of fullness, wide and long sleeves and ruffles at the collar that spread out framing the neck, down the center front to underbust height, covering the slit and at the cuffs, reaching to mid-hand. The shirt is gathered at the waist with a belt, and worn over the bottom garment to show that it reaches to mid tight. Drama levels in the pose are pretty low.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/vampire_shirt.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The recurring joke is that because of some health issues, in summer I
dress like a Victorian Vampire.&lt;/p&gt;
&lt;p&gt;But how would an actual Late Victorian Vampire dress? Picture her, she
would look like some kind of eccentric gentlewoman, as vampires usually
do, probably with a style that is a bit conservative, rather than
following the latest fashions.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Same woman, same shirt, posing as a vampire ready to attack a victim. Drama levels increasing.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/vampire_attack.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Now, she wouldn’t probably wear men’s shirts. But what if she was a
lesbian&lt;a class=&quot;footnote-ref&quot; href=&quot;https://blog.trueelena.org#fn1&quot; id=&quot;fnref1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; vampire? Wouldn’t she need a fancy, frilly shirt to
go with her tailored cycling suit when she’s out seducing the more
active ladies in the neighbourhood?&lt;/p&gt;
&lt;p&gt;Or maybe not. It’s not making a lot of sense, is it? But &lt;em&gt;I&lt;/em&gt; do have a
lot of shirt fabric in my stash&lt;a class=&quot;footnote-ref&quot; href=&quot;https://blog.trueelena.org#fn2&quot; id=&quot;fnref2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt;, and I could use a few more
shirts that were practical and comfortable, but also somewhat over the
top.&lt;/p&gt;
&lt;p&gt;For the practical and comfortable I went to my trusted &lt;a href=&quot;https://sewing-patterns.trueelena.org/historical_menswear/shirts/1880s_shirt/index.html&quot;&gt;1880s shirt&lt;/a&gt;,
while for the over the top part I looked at inspiration from the earlier
18th century frilly shirts, and their later imitations.&lt;/p&gt;
&lt;p&gt;I decided to use some nice cotton batiste I had bought quite a few years
ago to make one of my first historically inspired shirtwaists: I may
have a tendency to buy a bit more fabric than actually needed by the
pattern, but that’s what everybody does, right?&lt;/p&gt;
&lt;p&gt;For the ruffles I decided to use a lighter weight cotton voile, also
from the stash.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;the top edge of a ruffle being whipstitched over some gathered fabric; the rest of the unfinished shirt is visible in the background.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/attaching_fronts.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;At the front, I wanted the ruffle to be inserted in the yoke, but I was
also whipstitching the gathers to it to make them neater, so I started
bu attaching the yoke lining to the gathered front, then I whipstitched
the ruffle to the front, catching each gather, and finally I
whipstitched the other yoke on the ruffle and the rest of the gathered
front.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;The front of a shirt: the body was gathered into a yoke, but it has been unpicked and pulled out to extend a bit past the end of it, into where the collar will be sewn.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/unpicking_unpicking.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;And then after sewing the collar, I realized that this way the slit
would have remained open in the front (or the collar too narrow), so I
had to unpick the front part of the yoke, and sew it again, this time
leaving an excess of fabric as wide as half the placket width from the
pattern, to be sewn directly in the collar band.&lt;/p&gt;
&lt;p&gt;From then, things progressed smoothly, with some interruptions, until I
got to the first sleeve, which I failed to insert twice, as one does.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;The same shirt worn without the ruffle at the collar, with just what looks like a mandarin collar, closed with a clip with an amethyst. Drama levels have gone way down.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/without_collar.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;On the third attempt, with a different method, I succeeded, I tried the
shirt on, and it already felt &lt;em&gt;extra&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Close up of the collar on a table: at the center back of the shirt collar there is a buttonhole, and a double button is used to keep the detached collar in place, while at the front both the shirt collar and the detached collar have buttonholes.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/detachable_collar.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;But it could be even &lt;em&gt;more&lt;/em&gt; extra. With some ruffles also at the collar.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Same close up, but now the collar has been closed with a clip-on earring with an amethyst and some small fake clear stones, and it looks as if the skirt had a ruffle collar and a jewel button (or a pin).&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/collar_closed.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The shirt had been made with a simple collar band, and I could have just
added the ruffle to it, but I also wanted to be able to wear it with
other detachable collars, so I decided to make another collar band with
ruffles, to wear on top.&lt;/p&gt;
&lt;p&gt;And that was mostly it, except for the reinforcement patches at the
side seams and cuffs: I love having them, because they make the seam
end neater and stronger, but they are a bit of a hassle to make, so they
got postponed a few days.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Same woman and shirt, back with the ruffled collar, in a pose like that of an artist that is fainting for futile reasons. Drama levels over the top.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/overdramatic.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;But finally, the shirt was done.&lt;/p&gt;
&lt;p&gt;And I tried it on, and it was good.&lt;/p&gt;
&lt;p&gt;But now I really need a pair of cycling breeches, don’t I?&lt;/p&gt;
&lt;section class=&quot;footnotes footnotes-end-of-document&quot;&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id=&quot;fn1&quot;&gt;&lt;p&gt;ok, maybe straight passing bi? anyway.&lt;a class=&quot;footnote-back&quot; href=&quot;https://blog.trueelena.org#fnref1&quot;&gt;↩︎&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li id=&quot;fn2&quot;&gt;&lt;p&gt;I have &lt;em&gt;no idea&lt;/em&gt; how they got there.&lt;a class=&quot;footnote-back&quot; href=&quot;https://blog.trueelena.org#fnref2&quot;&gt;↩︎&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/section&gt;
    &lt;/section&gt;
&lt;/article&gt;</content:encoded> 
	<dc:date>2026-07-27T00:00:00+00:00</dc:date>
	<dc:creator>Elena “of Valhalla”</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/07/25#rcpparmadillo_15.4.2-1">
	<title>Dirk Eddelbuettel: RcppArmadillo 15.4.2-1 on CRAN: Small Upstream Fixes</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/07/25#rcpparmadillo_15.4.2-1</link>
     <content:encoded>&lt;p&gt;&lt;img alt=&quot;armadillo image&quot; src=&quot;https://dirk.eddelbuettel.com/images/armadillo_logo_two.png&quot; style=&quot;float: left; margin: 10px 10px 10px 0;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://arma.sourceforge.net/&quot;&gt;Armadillo&lt;/a&gt; is a powerful
and expressive C++ template library for linear algebra and scientific
computing. It aims towards a good balance between speed and ease of use,
has a syntax deliberately close to Matlab, and is useful for algorithm
development directly in C++, or quick conversion of research code into
production environments. &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rcpp.armadillo.html&quot;&gt;RcppArmadillo&lt;/a&gt;
integrates this library with the &lt;a href=&quot;https://www.r-project.org&quot;&gt;R&lt;/a&gt; environment and language–and is
widely used by (currently) 1293 other packages on &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;, downloaded 47.8 million
times (per the partial logs from the cloud mirrors of CRAN), and the &lt;a href=&quot;https://doi.org/10.1016/j.csda.2013.02.005&quot;&gt;CSDA paper&lt;/a&gt; (&lt;a href=&quot;https://cran.r-project.org/package=RcppArmadillo/vignettes/RcppArmadillo-intro.pdf&quot;&gt;preprint
/ vignette&lt;/a&gt;) by Conrad and myself has been cited 710 times according
to Google Scholar.&lt;/p&gt;
&lt;p&gt;This versions updates to the 15.4.2 upstream &lt;a href=&quot;https://arma.sourceforge.net/&quot;&gt;Armadillo&lt;/a&gt; release made this
week, as well as to included 15.4.1 version we released only to GitHub
and r-universe so do not exceed the (roughly) monthly cadence. For this
release, we had run the usual complete reverse-dependency check which
came back spotless, and did CRAN so no email exchange needed despite
nearly 1300 reverse dependencies. Automation can be helpful when used
with a well-maintained software stack. The package has also already been
updated for &lt;a href=&quot;https://www.debian.org&quot;&gt;Debian&lt;/a&gt;, built for &lt;a href=&quot;https://eddelbuettel.github.io/r2u/&quot;&gt;r2u&lt;/a&gt;, and will build
shortly at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; for the
different binary releases.&lt;/p&gt;
&lt;p&gt;All changes since the last CRAN release follow.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-rcpparmadillo-version-15.4.2-1-2026-07-25&quot;&gt;Changes in
RcppArmadillo version 15.4.2-1 (2026-07-25)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Upgraded to Armadillo release 15.4.2 (Medium Roast Agave)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fix speed regressions in &lt;code&gt;diagvec()&lt;/code&gt; and
&lt;code&gt;diagmat()&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;changes-in-rcpparmadillo-version-15.4.1-1-github-only-2026-07-09&quot;&gt;Changes
in RcppArmadillo version 15.4.1-1 [github-only] (2026-07-09)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Upgraded to Armadillo release 15.4.1 (Medium Roast Agave)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Fix for rare infinite recursion bug in sparse version of
&lt;code&gt;diagmat()&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;More efficient checks for aliasing&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/&quot;&gt;CRANberries&lt;/a&gt;, there
is a &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/2026/07/25#RcppArmadillo_15.4.2-1&quot;&gt;diffstat
report&lt;/a&gt; relative to previous release. More detailed information is on
the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rcpp.armadillo.html&quot;&gt;RcppArmadillo
page&lt;/a&gt;. Questions, comments etc should go to the &lt;a href=&quot;https://lists.r-forge.r-project.org/cgi-bin/mailman/listinfo/rcpp-devel&quot;&gt;rcpp-devel
mailing list&lt;/a&gt; off the &lt;a href=&quot;https://r-forge.r-project.org/projects/rcpp/&quot;&gt;Rcpp R-Forge&lt;/a&gt;
page.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-25T20:56:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="http://00formicapunk00.wordpress.com/?p=344">
	<title>Emmanuel Kasper: Opensource gaming with nouveau nvidia driver</title>
	<link>https://00formicapunk00.wordpress.com/2026/07/24/opensource-gaming-with-nouveau-nvidia-driver/</link>
     <content:encoded>&lt;p class=&quot;wp-block-paragraph&quot;&gt;So it will not play cyberpunk 2077, but if you prefer opensource drivers for your hardware, nouveau is certainly an option for some opensource gaming.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Using kernel 7.0 from debian backports, I could run opensource classics requiring 3D acceleration  flawlessly with nouveau:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Supertux (&lt;a href=&quot;https://screenshots.debian.net/package/supertux&quot;&gt;Debian package&lt;/a&gt;)&lt;/li&gt;



&lt;li&gt;SuperTux Kart (&lt;a href=&quot;https://screenshots.debian.net/package/supertuxkart&quot;&gt;Debian package&lt;/a&gt;)&lt;/li&gt;



&lt;li&gt;LibreQuake (&lt;a href=&quot;https://flathub.org/en/apps/io.github.lavenderdotpet.LibreQuake&quot;&gt;Flatpak&lt;/a&gt; with ironquake engine, Full HD and 60 fps)&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I would like to highlight here how good is LibreQuake.&lt;br /&gt;It is an horror cosmic 3D shooter, using the Quake engine, but with newly made game assets under the GPL, thus creating a 100% opensource Quake-based first person shooter.  Although their documentation mentions it is a work in progress, as of 2026 I find it very much of a finished product.&lt;br /&gt;&lt;br /&gt;&lt;img alt=&quot;LibreQuake Screenshot&quot; class=&quot;wp-image-347&quot; height=&quot;1067&quot; src=&quot;https://00formicapunk00.wordpress.com/wp-content/uploads/2026/07/librequake-dismalshores.png&quot; style=&quot;width: 1024px;&quot; width=&quot;1911&quot; /&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;em&gt;Dismal shores, my preferred game level.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;I missed Quake in the 90s, happy to discover such a classic today.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-24T15:31:24+00:00</dc:date>
	<dc:creator>Manu</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6244">
	<title>Russell Coker: Systemd Linger</title>
	<link>https://etbe.coker.com.au/2026/07/24/systemd-linger/</link>
     <content:encoded>&lt;h2&gt;Killing Processes&lt;/h2&gt;
&lt;p&gt;One of the features of systemd that is most controversial is the option to kill user processes when the user logs out. That initially killed screen/tmux/nohup processes too. In recent Debian releases the default configuration of systemd-logind (the login manager for systemd) is to allow processes to keep running, the configuration file &lt;b&gt;/etc/systemd/logind.conf&lt;/b&gt; has an option &lt;b&gt;KillUserProcesses&lt;/b&gt; that can be enabled to have user processes killed. If you do that then there are options to only kill processes for certain users and to exclude some users (default to excluding root). If using that option you can apparently use a systemd unit to start screen which prevents it being killed on logout.&lt;/p&gt;
&lt;p&gt;This is a very handy feature for some particular user cases. One situation was that I was supporting some people who weren’t very good at computers on a system running KDE and some KDE processes would linger. So the option of logout and login again to deal with an issue of akonadi or some other KDE service misbehaving didn’t work. On that system I enabled the option to kill user processes which reduced the number of problems they had while not requiring rebooting.&lt;/p&gt;
&lt;p&gt;It is widely believed that the “linger” feature is required to allow screen/tmux/nohup to work, in Debian (and probably most distributions) that is not the case. It might be that some combinations of configuration requires “linger” to allow screen/tmux to work but I am not interested in trying to discover them. Of all the people I have directly supported for Linux desktop use (which numbers in the hundreds) none of them have had the ability to use screen/tmux and also the cluelessnes that makes me want to automatically kill their processes when the logout.&lt;/p&gt;
&lt;h2&gt;Controlling Linger&lt;/h2&gt;
&lt;p&gt;You can enable and disable “linger” for your own account with the following commands if polkit is installed and in a typical configuration:&lt;/p&gt;
&lt;pre&gt;loginctl enable-linger
loginctl disable-linger&lt;/pre&gt;
&lt;p&gt;If running as root you can enable and disable it for another user with the following commands:&lt;/p&gt;
&lt;pre&gt;loginctl enable-linger $ACCOUNT
loginctl disable-linger $ACCOUNT&lt;/pre&gt;
&lt;p&gt;There doesn’t seem to be any documented way of discovering if an account has linger enabled or for listing accounts that have it, it seems that “&lt;b&gt;ls /var/lib/systemd/linger&lt;/b&gt;” is the only option.&lt;/p&gt;
&lt;h2&gt;Linger on Debian&lt;/h2&gt;
&lt;p&gt;On a Debian system with close to default settings the processes won’t be killed on logout and the only difference “linger” makes is to start programs in the user’s context BEFORE they login. A friend was recently testing out a bunch of LLM programs on one of my servers and the account he used for that ended up with “linger” enabled, presumably one of the install scripts he ran was written on the assumption that enabling linger was necessary for nohup to work and it did so automatically without being asked.&lt;/p&gt;
&lt;p&gt;One benefit I’ve found from this behaviour is on my laptop. I’m currently testing out new SE Linux policy on my laptop and rebooting it a lot. When I enabled linger on my account it caused the laptop to connect to wifi on boot without needing to login which is convenient. I can then ssh to it even when the X11/Wayland login configuration is broken.&lt;/p&gt;
&lt;p&gt;I will leave it enabled after finishing these tests. Having background processes like Pipewire and Bluetooth start before I login will presumably make things slightly faster when I do login.&lt;/p&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2015/01/13/systemd-notes/&quot; rel=&quot;bookmark&quot; title=&quot;Systemd Notes&quot;&gt;Systemd Notes&lt;/a&gt; &lt;small&gt;A few months ago I gave a lecture about systemd...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2016/02/25/ethernet-naming-systemd/&quot; rel=&quot;bookmark&quot; title=&quot;Ethernet Interface Naming With Systemd&quot;&gt;Ethernet Interface Naming With Systemd&lt;/a&gt; &lt;small&gt;Systemd has a new way of specifying names for Ethernet...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/09/systemd-mobile-linux-containers/&quot; rel=&quot;bookmark&quot; title=&quot;Systemd, Mobile Linux, and Containers&quot;&gt;Systemd, Mobile Linux, and Containers&lt;/a&gt; &lt;small&gt;I’ve had some problems running apps I want on my...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-24T07:48:23+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://www.freexian.com/blog/debian-lts-report-2026-06/">
	<title>Freexian Collaborators: Monthly report about Debian Long Term Support, June 2026 (by Thorsten Alteholz)</title>
	<link>https://www.freexian.com/blog/debian-lts-report-2026-06/</link>
     <content:encoded>&lt;img src=&quot;https://www.freexian.com/images/debian-lts-logo.png&quot; style=&quot;float: right;&quot; /&gt;
&lt;p&gt;The Debian LTS Team, funded by [Freexian’s Debian LTS offering]
(&lt;a href=&quot;https://www.freexian.com/lts/debian/%29&quot;&gt;https://www.freexian.com/lts/debian/)&lt;/a&gt;, is pleased to report its activities for
June.&lt;/p&gt;
&lt;h3 id=&quot;activity-summary&quot;&gt;Activity summary&lt;/h3&gt;
&lt;p&gt;During the month of June, 20 contributors have been
paid to work on &lt;a href=&quot;https://wiki.debian.org/LTS&quot;&gt;Debian LTS&lt;/a&gt; (links to individual
contributor reports are located below).&lt;/p&gt;
&lt;p&gt;The team released &lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/threads.html&quot;&gt;48 DLAs&lt;/a&gt; fixing 231 CVEs.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.debian.org/releases/bookworm/&quot;&gt;Debian 12 (“bookworm”)&lt;/a&gt; has been handed over to
the LTS Team on June 11th. During this handover Sylvain helped to update relevant tools and
documentation.  If you benefit from Debian, especially during the
full 5-year lifecycle, please consider subscribing as a sponsor of Debian LTS:
&lt;a href=&quot;https://www.freexian.com/lts/debian/&quot;&gt;https://www.freexian.com/lts/debian/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Moreover, Debian 11 (“bullseye”) will reach the end of the Debian LTS period on
August 31st. After that, Freexian will continue the security support under the
&lt;a href=&quot;https://www.freexian.com/lts/extended/&quot;&gt;Extended LTS&lt;/a&gt; offer.&lt;/p&gt;
&lt;p&gt;The team published several notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;haveged update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4616-1&quot;&gt;DLA-4616-1&lt;/a&gt;),
prepared by Thorsten, to address local privilege escalation.&lt;/li&gt;
&lt;li&gt;tomcat9 update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4619-1&quot;&gt;DLA-4619-1&lt;/a&gt;),
prepared by Markus, to address, among others, an authentication bypass.&lt;/li&gt;
&lt;li&gt;apache2 update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4620-1&quot;&gt;DLA-4620-1&lt;/a&gt;),
prepared by Bastien, to address a HTTP/2 bomb.&lt;/li&gt;
&lt;li&gt;apache2 update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4629-1&quot;&gt;DLA-4629-1&lt;/a&gt;),
prepared by Bastien, to address, among others, remote code execution and privilege escalation.&lt;/li&gt;
&lt;li&gt;libinput update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4626-1&quot;&gt;DLA-4626-1&lt;/a&gt;),
prepared by Santiago, to address local privilege escalation and arbitrary code execution.&lt;/li&gt;
&lt;li&gt;asterisk update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4631-1&quot;&gt;DLA-4631-1&lt;/a&gt;),
prepared by Thorsten, to address, among others, wrong processing of invalid or untrusted certificates.&lt;/li&gt;
&lt;li&gt;nginx update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4634-1&quot;&gt;DLA-4634-1&lt;/a&gt;),
prepared by Charles, to address a remote code execution and denial of service.&lt;/li&gt;
&lt;li&gt;firefox-esr update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4635-1&quot;&gt;DLA-4635-1&lt;/a&gt;),
prepared by Emilio, to address dozens of CVEs, among other things, related to arbitrary code execution and privilege escalation.&lt;/li&gt;
&lt;li&gt;thunderbird update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4636-1&quot;&gt;DLA-4636-1&lt;/a&gt;),
prepared by Emilio, to address dozens of CVEs, among other things, related to arbitrary code execution.&lt;/li&gt;
&lt;li&gt;chromium update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4654-1&quot;&gt;DLA-4654-1&lt;/a&gt;),
prepared by Emilio, to address dozens of CVEs, among other things, related to arbitrary code execution.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Contributions from outside the LTS Team:&lt;/p&gt;
&lt;p&gt;We are greatly thankful for the contributions from people outside the LTS Team:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Salvatore Bonaccorso prepared a libhttp-daemon-perl update, that was released by Santiago as
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4639-1&quot;&gt;DLA-4639-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Salvatore also directly uploaded libgd-perl
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4638-1&quot;&gt;DLA-4638-1&lt;/a&gt;
and libconfig-inifiles-perl
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4637-1&quot;&gt;DLA-4637-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Peter Palfrader prepared a tor update, that was released by Santiago as
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4656-1&quot;&gt;DLA-4656-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Pieter Lenaerts prepared a beets update, that was released by Emmanuel as
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4641-1&quot;&gt;DLA-4641-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Noah Meyerhans prepared a cloud-init update
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4645-1&quot;&gt;DLA-4645-1&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The LTS Team has also contributed with updates to the latest Debian releases:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Besides publishing
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4642-1&quot;&gt;DLA-4642-1&lt;/a&gt; for package u-boot
Andreas also prepared an NMU for an upload to sid and prepared a stable-proposed-update (SPU) bug
for &lt;a href=&quot;https://bugs.debian.org/1140663&quot;&gt;trixie&lt;/a&gt;, which was already acknowledged by a stable release manager (SRM).&lt;/li&gt;
&lt;li&gt;Andreas also prepared an upload of package atril for trixie, which was handled by the security team as
&lt;a href=&quot;https://lists.debian.org/debian-security-announce/2026/msg00260.html&quot;&gt;DSA-6349-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Besides publishing
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4620-1&quot;&gt;DLA-4620-1&lt;/a&gt; for package apache
Bastien also prepared an upload for trixie, which was handled by the security team as
&lt;a href=&quot;https://lists.debian.org/debian-security-announce/2026/msg00234.html&quot;&gt;DSA-6323-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Tobi uploaded package mesa to &lt;a href=&quot;https://bugs.debian.org/1140473&quot;&gt;trixie&lt;/a&gt;
and &lt;a href=&quot;https://bugs.debian.org/1140495&quot;&gt;bookworm&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Thorsten fixed some (not security related but RC) issues in package dahdi-linux. This was in preparation to fix lots of security issues in asterisk.
Unfortunately the maintainer ignored the corresponding debdiff and prefered to upload a new upstream version.
Anyway, the concerns of the security team about security support of asterisk could be overcome and asterisk can migrate to tesing and again be
part of a Debian release.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;individual-debian-lts-contributor-reports&quot;&gt;Individual Debian LTS contributor reports&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://people.debian.org/~abhijith/reports/LTS_ELTS-June-2026.txt&quot;&gt;Abhijith PA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/06/msg00065.html&quot;&gt;Andreas Henriksson&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/06/msg00058.html&quot;&gt;Arnaud Rebillout&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00006.html&quot;&gt;Bastien Roucariès&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.decadent.org.uk/ben/blog/2026/07/01/foss-activity-in-june-2026.html&quot;&gt;Ben Hutchings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00021.html&quot;&gt;Carlos Henrique Lima Melara&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://chris-lamb.co.uk/posts/free-software-activities-in-june-2026&quot;&gt;Chris Lamb&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00007.html&quot;&gt;Daniel Leidert&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00000.html&quot;&gt;Emmanuel Arias&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://people.debian.org/~pochu/lts/reports/2026-06.txt&quot;&gt;Emilio Pozuelo Monfort&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/msgid-search/?m=ft1Z8V9o2E3C8iOv@debian.org&quot;&gt;Guilhem Moulin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/msgid-search/akULnNGyjIvjKHX2@mpd&quot;&gt;Jochen Sprickerhof&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00014.html&quot;&gt;Lee Garrett&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://people.debian.org/~kanashiro/debian/lts/reports/2026-06.txt&quot;&gt;Lucas Kanashiro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://dl.gambaru.de/blog/202606_LTS_ELTS_report.txt&quot;&gt;Markus Koschany&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://people.debian.org/~santiago/lts-elts-reports/report-2026-06.txt&quot;&gt;Santiago Ruano Rincón&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00004.html&quot;&gt;Sylvain Beucler&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.alteholz.eu/2026/07/my-debian-activities-in-june-2026/&quot;&gt;Thorsten Alteholz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/06/msg00047.html&quot;&gt;Tobias Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://utkarsh2102.org/posts/foss-in-june-26/&quot;&gt;Utkarsh Gupta&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;thanks-to-our-sponsors&quot;&gt;Thanks to our sponsors&lt;/h3&gt;
&lt;p&gt;Sponsors that joined recently are in bold.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Platinum sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.global.toshiba/ww/top.html&quot;&gt;Toshiba Corporation&lt;/a&gt; (for 129 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cip-project.org&quot;&gt;Civil Infrastructure Platform (CIP)&lt;/a&gt; (for 97 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://vyos.io&quot;&gt;VyOS Inc&lt;/a&gt; (for 61 months)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Gold sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.roche.com/about/business/diagnostics.htm&quot;&gt;F. Hoffmann-La Roche AG&lt;/a&gt; (for 139 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.conet.de/&quot;&gt;CONET Deutschland GmbH&lt;/a&gt; (for 123 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.ox.ac.uk&quot;&gt;University of Oxford&lt;/a&gt; (for 79 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.edf.fr&quot;&gt;EDF SA&lt;/a&gt; (for 51 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.dataport.de&quot;&gt;Dataport AöR&lt;/a&gt; (for 26 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://home.cern/&quot;&gt;CERN&lt;/a&gt; (for 24 months)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Silver sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://domainnameshop.com/&quot;&gt;Domeneshop AS&lt;/a&gt; (for 144 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://metropole.nantes.fr/&quot;&gt;Nantes Métropole&lt;/a&gt; (for 138 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.akamai.com/&quot;&gt;Akamai - Linode&lt;/a&gt; (for 133 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.univention.de&quot;&gt;Univention GmbH&lt;/a&gt; (for 130 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://portail.univ-st-etienne.fr/&quot;&gt;Université Jean Monnet de St Etienne&lt;/a&gt; (for 130 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://ribboncommunications.com/&quot;&gt;Ribbon Communications, Inc.&lt;/a&gt; (for 124 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.exonet.nl&quot;&gt;Exonet B.V.&lt;/a&gt; (for 114 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.lrz.de&quot;&gt;Leibniz Rechenzentrum&lt;/a&gt; (for 108 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.diplomatie.gouv.fr&quot;&gt;Ministère de l’Europe et des Affaires Étrangères&lt;/a&gt; (for 92 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://dinahosting.com&quot;&gt;Dinahosting SL&lt;/a&gt; (for 79 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://upsun.com&quot;&gt;Upsun Formerly Platform.sh&lt;/a&gt; (for 73 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.moxa.com&quot;&gt;Moxa Inc.&lt;/a&gt; (for 67 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://sipgate.de&quot;&gt;sipgate GmbH&lt;/a&gt; (for 65 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://ovhcloud.com&quot;&gt;OVH US LLC&lt;/a&gt; (for 63 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.tilburguniversity.edu/&quot;&gt;Tilburg University&lt;/a&gt; (for 63 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.gsi.de&quot;&gt;GSI Helmholtzzentrum für Schwerionenforschung GmbH&lt;/a&gt; (for 54 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cesky-hosting.cz/&quot;&gt;THINline s.r.o.&lt;/a&gt; (for 27 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cph.dk&quot;&gt;Copenhagen Airports A/S&lt;/a&gt; (for 21 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.isere.fr&quot;&gt;Conseil Départemental de l’Isère&lt;/a&gt; (for 7 months)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Bronze sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://www.evolix.fr&quot;&gt;Evolix&lt;/a&gt; (for 144 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.seznam.cz&quot;&gt;Seznam.cz, a.s.&lt;/a&gt; (for 144 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://intevation.de&quot;&gt;Intevation GmbH&lt;/a&gt; (for 141 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://linuxhotel.de&quot;&gt;Linuxhotel GmbH&lt;/a&gt; (for 141 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://waays.fr&quot;&gt;Daevel SARL&lt;/a&gt; (for 140 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.megaspace.de&quot;&gt;Megaspace Internet Services GmbH&lt;/a&gt; (for 139 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.greenbone.net&quot;&gt;Greenbone AG&lt;/a&gt; (for 138 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://numlog.fr&quot;&gt;NUMLOG&lt;/a&gt; (for 138 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.wingo.ch/&quot;&gt;WinGo AG&lt;/a&gt; (for 137 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.entrouvert.com/&quot;&gt;Entr’ouvert&lt;/a&gt; (for 129 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://adfinis.com&quot;&gt;Adfinis AG&lt;/a&gt; (for 126 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.plathome.com&quot;&gt;Plat’Home&lt;/a&gt; (for 122 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.legi.grenoble-inp.fr&quot;&gt;Laboratoire LEGI - UMR 5519 / CNRS&lt;/a&gt; (for 121 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.tesorion.nl/&quot;&gt;Tesorion&lt;/a&gt; (for 121 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://bearstech.com&quot;&gt;Bearstech&lt;/a&gt; (for 112 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://lihas.de&quot;&gt;LiHAS&lt;/a&gt; (for 112 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.catalyst.net.nz&quot;&gt;Catalyst IT Ltd&lt;/a&gt; (for 107 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://demarcq.net&quot;&gt;Demarcq SAS&lt;/a&gt; (for 101 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.univ-grenoble-alpes.fr&quot;&gt;Université Grenoble Alpes&lt;/a&gt; (for 87 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.touchweb.fr&quot;&gt;TouchWeb SAS&lt;/a&gt; (for 79 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.spin-ag.de&quot;&gt;SPiN AG&lt;/a&gt; (for 76 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.corefiling.com&quot;&gt;CoreFiling&lt;/a&gt; (for 72 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.osug.fr/&quot;&gt;Observatoire des Sciences de l’Univers de Grenoble&lt;/a&gt; (for 63 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.werfen.com&quot;&gt;Tem Innovations GmbH&lt;/a&gt; (for 58 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://wordfinder.pro&quot;&gt;WordFinder.pro&lt;/a&gt; (for 57 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.resif.fr&quot;&gt;CNRS DT INSU Résif&lt;/a&gt; (for 56 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.soliton.co.jp&quot;&gt;Soliton Systems K.K.&lt;/a&gt; (for 51 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.alterway.fr&quot;&gt;Alter Way&lt;/a&gt; (for 49 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.sobis.com/&quot;&gt;SOBIS Software GmbH&lt;/a&gt; (for 24 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.tuxera.com&quot;&gt;Tuxera Inc.&lt;/a&gt; (for 15 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://opm-op.com&quot;&gt;OPM-OP AS&lt;/a&gt; (for 7 months)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.lu-cix.lu&quot;&gt;LU-CIX Management G.I.E.&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-22T00:00:00+00:00</dc:date>
	<dc:creator>Thorsten Alteholz</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/07/21#qlcal-r_0.1.3">
	<title>Dirk Eddelbuettel: qlcal 0.1.3 on CRAN: Micro Bugfix, Build Tweak</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/07/21#qlcal-r_0.1.3</link>
     <content:encoded>&lt;p&gt;The twenty-first release of the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;qlcal&lt;/a&gt; package
arrivied at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; just now, and
has been built for &lt;a href=&quot;https://eddelbuettel.github.io/r2u/&quot;&gt;r2u&lt;/a&gt;. It comes a week
after the &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/2026/07/14#qlcal-r_0.1.2&quot;&gt;0.1.2
release&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;qlcal&lt;/a&gt;
delivers the calendaring parts of &lt;a href=&quot;https://www.quantlib.org&quot;&gt;QuantLib&lt;/a&gt;. It is provided (for the R
package) as a set of included files, so the package is self-contained
and does not depend on an external &lt;a href=&quot;https://www.quantlib.org&quot;&gt;QuantLib&lt;/a&gt; library (which can be
demanding to build). &lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;qlcal&lt;/a&gt; covers
over seventy country / market calendars and can compute holiday lists,
its complement (&lt;em&gt;i.e.&lt;/em&gt; business day lists) and much more.
Examples are in the README at the &lt;a href=&quot;https://github.com/qlcal/qlcal-r&quot;&gt;repository&lt;/a&gt;, the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;package page&lt;/a&gt;,
and course at the &lt;a href=&quot;https://cran.r-project.org/package=qlcal&quot;&gt;CRAN package
page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This releases includes a one-line fix we also sent &lt;a href=&quot;https://github.com/lballabio/QuantLib/pull/2662&quot;&gt;upstream as a
now-merged PR&lt;/a&gt;: one of the calendar files added in QuantLib 1.43 also
needed to include the &lt;code&gt;vector&lt;/code&gt; header file. And every
compiler appears to be lenient (QuantLib itself has fourty different
continuous integration jobs, we test with all builds at r-universe)
apart from the CRAN macOS x86-64 machine. Sigh. This is now fixed. We
also included a neat little local trick I should blog about: if the
build is detected as a non-CRAN local build (simply by checking for a
&lt;code&gt;.git&lt;/code&gt; directory) then compiler flags can be updated to
quieten the build. We cannot do that in the package because we would get
our fingers slapped over so-called ‘non-portable compiler flags’. Sigh
again. Anyway, the trick helps.&lt;/p&gt;
&lt;p&gt;The full details from &lt;code&gt;NEWS.Rd&lt;/code&gt; follow.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-version-0.1.3-2026-07-21&quot;&gt;Changes in version 0.1.3
(2026-07-21)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Add missing &#39;vector&#39; header to new IslamicHolidays calendar file,
also PRed upstream and merged there&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;In local compilation out of git repo add additional compiler
flags&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/&quot;&gt;CRANberries&lt;/a&gt;, there
is a diffstat report for &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/2026/07/21/#qlcal_0.1.3&quot;&gt;this
release&lt;/a&gt;. See the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;project page&lt;/a&gt;
and package documentation for more details, and more examples.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-21T13:18:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/interzone/digital/">
	<title>Jonathan Dowland: Interzone digital</title>
	<link>https://jmtd.net/log/interzone/digital/</link>
     <content:encoded>&lt;p&gt;&lt;em&gt;(no, this isn&#39;t a blog post about Joy Division songs)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://jmtd.net/log/interzone/294/&quot;&gt;Last time I wrote about Interzone&lt;/a&gt;, I was discussing issue #294, the
first published under new management in a paperback-sized format
(&quot;JB6&quot;). The format and presentation of the magazine was fantastic: it fit in a
lot of my pockets, and was packed with 15 stories as well as the regular
columns, in full colour with fantastic layouts and illustrations. Sadly there
was only one more physical issue before Interzone was forced to become a
digital-only publication.&lt;/p&gt;

&lt;div class=&quot;centre&quot;&gt;
&lt;div class=&quot;image+centre&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/interzone/physical_iz.jpg&quot;&gt;&lt;img alt=&quot;IZ issues 294 and 295&quot; class=&quot;img&quot; height=&quot;333&quot; src=&quot;https://jmtd.net/log/interzone/digital/250x-physical_iz.jpg&quot; width=&quot;250&quot; /&gt;&lt;/a&gt;

&lt;p&gt;IZ issues 294 and 295&lt;/p&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;I don&#39;t want to dwell on the sad necessity to move to digital. Interzone
continues on, celebrating the milestone issue #300 in 2024. Subscriptions
are managed via &lt;a href=&quot;https://www.patreon.com/c/interzonemag/membership&quot;&gt;Patreon&lt;/a&gt;.
Issue #305 just came out.&lt;/p&gt;

&lt;p&gt;Instead I wanted to write a small bit about how &lt;em&gt;I&lt;/em&gt; engaged with the paper
magazine, and the difficulties I&#39;ve had trying to engage with not just
Interzone but &lt;em&gt;any&lt;/em&gt; magazine-style publication in a digital context.&lt;/p&gt;

&lt;p&gt;With most fiction, I read linearly: start the beginning and read to the end, in
order. That works well for me with &lt;a href=&quot;https://jmtd.net/log/ereader/&quot;&gt;e-readers&lt;/a&gt;. But for magazines (and
most non-fiction) I don&#39;t, I jump around: usually starting with the
table of contents, I might pick a short column to start, or jump into the
middle of the &quot;book reviews&quot; section to read about a specific book. I might
skip sections entirely. I find it very difficult to read like this with an
e-reader. I think this is partly because I reference the &lt;em&gt;depth&lt;/em&gt; of the
paper book or magazine, its thickness, to orient myself. But it&#39;s also partly
the limitations of e-ink.&lt;/p&gt;

&lt;div class=&quot;centre&quot;&gt;
&lt;div class=&quot;image+centre&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/interzone/iz_ticklist.jpg&quot;&gt;&lt;img alt=&quot;My tick-list for an issue of IZ&quot; class=&quot;img&quot; height=&quot;444&quot; src=&quot;https://jmtd.net/log/interzone/digital/400x-iz_ticklist.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;

&lt;p&gt;My tick-list for an issue of IZ&lt;/p&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;For print-Interzone, I used to start by inserting a small piece of paper
inside the cover (the delivery slip was ideal). On this I listed the stories
within and ticked them off when I read them (sometimes I double-ticked if I
really liked a story). That helped me to remember, perhaps months or years
later, whether I&#39;d read all the stories or not, and which I liked.
I &lt;em&gt;could&lt;/em&gt; do something similar on some e-readers: the &lt;a href=&quot;https://jmtd.net/log/remarkable/&quot;&gt;Remarkable&lt;/a&gt; for
instance. But it&#39;s far from convenient to do on most e-ink devices.&lt;/p&gt;

&lt;p&gt;Interzone digital is available as both &lt;a href=&quot;https://en.wikipedia.org/wiki/EPUB&quot;&gt;ePUB&lt;/a&gt;, the most common format for e-books, and PDF. For reading on my
regular Kobo e-reader, PDFs don&#39;t work very well at all. I think this is
generally true of most e-readers.&lt;/p&gt;

&lt;p&gt;Interzone was (and is) a well-designed magazine. The value of it was not
just the &lt;em&gt;content&lt;/em&gt; of the text, but the &lt;em&gt;context&lt;/em&gt;: how the stories were
presented; the accompanying art (most often colour in recent decades),
but also the typesetting. ePUB
doesn&#39;t specify much of that stuff
exactly: it leaves that up to the client and the client&#39;s preferences.
And there&#39;s a lot of advantages to that:
Prefer a different font face or size? No problem. And
most importantly for accessibility:
If reading in ePUB makes Interzone available to more readers then that&#39;s
a great thing. But sadly a lot is lost, IMHO.&lt;/p&gt;

&lt;div class=&quot;centre&quot;&gt;
&lt;div class=&quot;image+centre&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/interzone/iz_ipad.jpg&quot;&gt;&lt;img alt=&quot;IZ #305 on iPad Mini&quot; class=&quot;img&quot; height=&quot;533&quot; src=&quot;https://jmtd.net/log/interzone/digital/400x-iz_ipad.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;

&lt;p&gt;IZ #305 on iPad Mini&lt;/p&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;The solution I&#39;m trying is to read the PDF version on the &lt;a href=&quot;https://jmtd.net/log/ipad_mini/&quot;&gt;iPad Mini&lt;/a&gt; I
resurrected earlier in the year.
Despite being an Internet tablet, since it&#39;s not really usable for browsing the
web anymore it&#39;s strangely still a distraction-free device. In fact it&#39;s pretty
much single-purpose for reading Interzone and the odd other book which benefits
from being read as PDF. I can appreciate the stylistic choices made in the
page-setting as they were intended; I can quickly jump around the issue without
waiting for an e-ink refresh; I get full colour; and whilst it would be tiring
to read for a long time on the iPad screen, for the length of articles or
stories in a magazine, this isn&#39;t a problem.&lt;/p&gt;

&lt;p&gt;It&#39;s not a solution for tracking what I&#39;ve read (that version of ipadOS is too
old to support clumsily scrawling on PDF pages with your fingers, at least in
the Books app) but it otherwise seems to work well, so I&#39;ll see how it goes.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-20T21:26:22+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="https://retout.co.uk/2026/07/20/renewal-relationships-between-aws-certifications/">
	<title>Tim Retout: Renewal relationships between AWS certifications</title>
	<link>https://retout.co.uk/2026/07/20/renewal-relationships-between-aws-certifications/</link>
     <content:encoded>&lt;p&gt;When you pass an AWS certification exam, sometimes it can extend the
life of related lesser AWS certifications.  But I could not find an
illustration of exactly which ones, so here’s an up-to-date diagram:&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;AWS Certification renewal dependencies&quot; src=&quot;https://retout.co.uk/2026/aws-certs.svg&quot; /&gt;
&lt;em&gt;Figure: Renewal relationships between AWS certifications.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Each arrow is a ‘renews’ relation – there’s no obligation to pass
lesser exams before the harder ones, but you could also follow the
arrows backwards if you want to learn easier material before sitting
the more difficult exams.&lt;/p&gt;
&lt;p&gt;I have made two important simplifications to the graph:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The ‘Advanced Networking – Specialty’ certification is being
retired soon, so I’ve omitted it entirely.  The last date to take that
exam is 25th August 2026.  But Specialty certs don’t renew anything
else anyway.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;I have left out transitive relationships in order to simplify the
graph – so e.g. if you pass a ‘Solutions Architect – Professional’
exam, it also renews any Cloud Practitioner certificate you might
hold, even if you do not currently hold the relevant Associate
certificate.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You also have the option of sitting each exam again to renew of
course, and there’s a new scheme to ‘maintain’ various certs via AWS
Skill Builder which can extend them by one year rather than three.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-20T20:52:17+00:00</dc:date>
	<dc:creator>Tim Retout</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-07-20:/2026/07/debconf26-starts-today.html">
	<title>Bits from Debian: DebConf26 starts today in Santa Fe on Monday, July 20, 2026</title>
	<link>https://bits.debian.org/2026/07/debconf26-starts-today.html</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf26&lt;/a&gt;, the 27th annual
&lt;a href=&quot;https://www.debconf.org/&quot;&gt;Debian Developer Conference&lt;/a&gt;, is taking place at
Santa Fe, Argentina from 20 to 25 July 2026.
Debian contributors from all over the world have come together at the Facultad
de Ingeniería en Ciencias Hídricas (Faculty of Engineering in Water Sciences),
one of the faculties that belong to the Universidad Nacional del Litoral
(National University of the Littoral), to participate and work in a
conference exclusively ran by volunteers.&lt;/p&gt;
&lt;p&gt;Today the main conference starts with around 300 expected attendants and over
80 scheduled activities, including 45-minute and 20-minute talks, Bird of a
Feather (&quot;&lt;abbr&gt;BoF&lt;/abbr&gt;&quot;) team meetings, workshops, a job fair, as well as
a variety of other events.
The full &lt;a href=&quot;https://debconf26.debconf.org/schedule/&quot;&gt;schedule&lt;/a&gt; is updated each
day, including activities planned ad-hoc by attendees over the course of the
conference.&lt;/p&gt;
&lt;p&gt;If you would like to engage remotely, you can follow the &lt;strong&gt;video streams&lt;/strong&gt;
available from the &lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf26 website&lt;/a&gt; for the
events happening in the three main talk rooms: Aula Magna - FADU,
Aula Magna - FBCB and Aula 0.3 - FICH accessible from the DebConf26 homepage.
You can also join the conversations happening inside the talk rooms via the
&lt;a href=&quot;https://www.oftc.net/&quot;&gt;OFTC IRC network&lt;/a&gt; in the
&lt;a href=&quot;irc://irc.oftc.net/debconf-fadu&quot;&gt;#debconf-fadu&lt;/a&gt;,
&lt;a href=&quot;irc://irc.oftc.net/debconf-fbcb&quot;&gt;#debconf-fbcb&lt;/a&gt;,
and &lt;a href=&quot;irc://irc.oftc.net/debconf-fich3&quot;&gt;#debconf-fich3&lt;/a&gt; channels.
Please also join us in the &lt;a href=&quot;irc://irc.oftc.net/debconf&quot;&gt;#debconf&lt;/a&gt; channel for
common discussions related to DebConf.&lt;/p&gt;
&lt;p&gt;You can also follow the live coverage of news about DebConf26 provided by our
&lt;a href=&quot;https://micronews.debian.org/&quot;&gt;micronews service&lt;/a&gt; or the @debian profile on
your favorite social network.&lt;/p&gt;
&lt;p&gt;DebConf is committed to a safe and welcoming environment for all participants.
Please see our &lt;a href=&quot;https://debconf26.debconf.org/about/coc/&quot;&gt;Code of Conduct page&lt;/a&gt;
for more information on this.&lt;/p&gt;
&lt;p&gt;Debian thanks the commitment of numerous sponsors to support DebConf26,
particularly our Platinum Sponsors:
&lt;a href=&quot;https://www.infomaniak.com/&quot;&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt; and
&lt;a href=&quot;https://www.proxmox.com/&quot;&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;DebConf26 sponsors logo&quot; src=&quot;https://bits.debian.org/images/debconf26-sponsors-banner.svg&quot; /&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-20T09:50:00+00:00</dc:date>
	<dc:creator>The Debian Publicity Team</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-07-18:/2026/07/debconf26-welcomes-sponsors.html">
	<title>Bits from Debian: DebConf26 welcomes its sponsors</title>
	<link>https://bits.debian.org/2026/07/debconf26-welcomes-sponsors.html</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://bits.debian.org/images/Romina_Molina_dc26_2.svg&quot;&gt;&lt;img alt=&quot;Alt DebConf26 by Romina Molina&quot; src=&quot;https://bits.debian.org/images/Romina_Molina_dc26_2.svg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf26&lt;/a&gt;, the 27th edition of the Debian
conference is taking place at the
&lt;a href=&quot;https://www.fich.unl.edu.ar/&quot;&gt;Facultad de Ingeniería en Ciencias Hídricas&lt;/a&gt; of
the Universidad Nacional del Litoral, in Santa Fe, Argentina. We appreciate
the organizers for their hard work, and hope this event will be highly
beneficial for those who attend in person as well as online.&lt;/p&gt;
&lt;p&gt;This event would not be possible without the help from our generous sponsors.
We would like to warmly welcome the sponsors of DebConf26, and introduce them
to you.&lt;/p&gt;
&lt;p&gt;We have two Platinum sponsors.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Our first Platinum sponsor is &lt;a href=&quot;https://www.proxmox.com/&quot;&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt;.
  Proxmox develops powerful, yet easy-to-use open-source server solutions.
  The comprehensive open-source ecosystem is designed to manage divers IT
  landscapes, from single servers to large-scale distributed data centers.
  Our unified platform integrates server virtualization, easy backup, and
  rock-solid email security ensuring seamless interoperability across the
  entire portfolio. With the Proxmox Datacenter Manager, the ecosystem also
  offers a &quot;single pane of glass&quot; for centralized management across different
  locations.
  Since 2005, all Proxmox solutions have been built on the rock-solid Debian
  platform. We are proud to return to DebConf26 as a sponsor because the
  Debian community provides the foundation that makes our work possible. We
  believe in keeping IT simple, open, and under your control.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://www.infomaniak.com/&quot;&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt; is the second Platinum sponsor.
  Infomaniak is an independent, employee-owned Swiss technology company that
  designs, develops, and operates its own cloud infrastructure and digital
  services entirely in Switzerland. With over 300 employees — more than 70%
  engineers and developers — the company reinvests all profits into R&amp;amp;D. Its
  public cloud is built on OpenStack, with managed Kubernetes, Database as a
  Service, object storage, and sovereign AI services accessible via OpenAI-
  compatible APIs, all running on its own Swiss infrastructure. Infomaniak also
  develops a sovereign collaborative suite — messaging, email, storage, online
  office tools, videoconferencing, and a built-in AI assistant — developed in-
  house and as a privacy-respecting solution to proprietary platforms. Open
  source is central to how Infomaniak operates. Its latest data center (D4)
  runs on 100% renewable energy and uses no traditional cooling: all the heat
  generated by its servers is captured and fed into Geneva&#39;s district heating
  network, supplying up to 6,000 homes in winter and hot water year-round. The
  entire project has been documented and open-sourced at
  &lt;a href=&quot;https://d4project.org/&quot;&gt;d4project.org&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Our Gold sponsors are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://www.freexian.com/&quot;&gt;&lt;strong&gt;Freexian&lt;/strong&gt;&lt;/a&gt;, Freexian specializes in Free
  Software with a particular focus on Debian GNU/Linux. Freexian can assist
  with consulting, training, technical support, packaging, or software
  development on projects involving use or development of Free software.
  All of Freexian&#39;s employees and partners are well-known contributors in the
  Free Software community, a choice that is integral to Freexian&#39;s business
  model.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://www.viridiengroup.com&quot;&gt;&lt;strong&gt;Viridien&lt;/strong&gt;&lt;/a&gt; an advanced technology,
  digital and Earth data company that pushes the boundaries of science for
  a more prosperous and sustainable future. Viridien has been using
  Debian-based systems to power most of its HPC infrastructure and its
  cloud platform since 2009 and currently employs two active Debian
  Project Members.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Our Silver sponsors are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.arm.com/&quot;&gt;&lt;strong&gt;Arm&lt;/strong&gt;&lt;/a&gt;: leading technology provider of processor
  IP, Arm powered solutions have been supporting innovation for
  more than 30 years and are deployed in over 280 billion chips to date.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.pexip.com/&quot;&gt;&lt;strong&gt;Pexip&lt;/strong&gt;&lt;/a&gt; brings the ease of commercial video
  platforms to secure and sovereign environments without compromising control
  or performance.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://www.bfh.ch/&quot;&gt;&lt;strong&gt;Bern University of Applied Sciences&lt;/strong&gt;&lt;/a&gt; with around
  7,959 students enrolled, located in the Swiss capital.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.canonical.com/&quot;&gt;&lt;strong&gt;Ubuntu&lt;/strong&gt;&lt;/a&gt;,
  the Operating System delivered by Canonical.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://os-sci.com/&quot;&gt;&lt;strong&gt;OS-Sci&lt;/strong&gt;&lt;/a&gt;, Open Source Science is a world-leading
  institution dedicated to teaching computer science through Free and Open
  Source Software (FOSS).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.gcoop.coop/&quot;&gt;&lt;strong&gt;gcoop&lt;/strong&gt;&lt;/a&gt;, a free software development company
  with over 19 years of market experience, organized as a worker cooperative,
  promoting best practices in software development.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.qualcomm.com/developer/opensource&quot;&gt;&lt;strong&gt;Qualcomm&lt;/strong&gt;&lt;/a&gt; Technologies,
  one of the world&#39;s leading companies in field of mobile technology, sponsors
  and contributes to Open Source developer communities that drive collaboration.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cip-project.org/&quot;&gt;&lt;strong&gt;Civil Infrastructure Platform&lt;/strong&gt;&lt;/a&gt;,
  a collaborative project hosted by the Linux Foundation, establishing an open
  source “base layer” of industrial grade software.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://opensource.siemens.com/&quot;&gt;&lt;strong&gt;Siemens&lt;/strong&gt;&lt;/a&gt; is a technology company
  focused on industry, infrastructure and transport.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.collabora.com/&quot;&gt;&lt;strong&gt;Collabora&lt;/strong&gt;&lt;/a&gt;, a global consultancy delivering
  Open Source software solutions to the commercial world.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://nerdearla.com/en/&quot;&gt;&lt;strong&gt;NERDEARLA&lt;/strong&gt;&lt;/a&gt;, the largest free tech event in
  the Spanish-speaking world.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Bronze sponsors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.loongson.cn/&quot;&gt;&lt;strong&gt;Loongson&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.credativ.de/&quot;&gt;&lt;strong&gt;credativ&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://google.com/&quot;&gt;&lt;strong&gt;Google&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.spacemit.com/&quot;&gt;&lt;strong&gt;SpacemiT&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And finally, our Supporter level sponsors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://altusmetrum.org/&quot;&gt;&lt;strong&gt;Altus Metrum&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://loongfans.cn/en/&quot;&gt;&lt;strong&gt;Loongson Hobbyists Community&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.santafe.gob.ar/&quot;&gt;&lt;strong&gt;Secretaría de Tecnologías para la Gestión de la Provincia de Santa Fe&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A special thanks to the
&lt;a href=&quot;https://www.fich.unl.edu.ar/&quot;&gt;&lt;strong&gt;Facultad de Ingeniería y Ciencias Hídricas - FICH UNL&lt;/strong&gt;&lt;/a&gt;,
our Venue Partner!&lt;/p&gt;
&lt;p&gt;Thanks to all our sponsors for their support!
Their contributions enable a diverse global community of Debian developers and
maintainers to collaborate, support one another, and share knowledge at
DebConf26.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-18T12:00:00+00:00</dc:date>
	<dc:creator>The Debian Publicity Team</dc:creator>
</item> 
<item rdf:about="tag:www.sergiocipriano.com,2026-07-17:posts/running-gui-in-incus.md">
	<title>Sergio Cipriano: Running Graphical Applications in Incus Containers</title>
	<link>https://sergiocipriano.com/running-gui-in-incus.html</link>
     <content:encoded>&lt;h1 id=&quot;running-graphical-applications-in-incus-containers&quot;&gt;Running
Graphical Applications in Incus Containers&lt;/h1&gt;
&lt;p&gt;I didn&#39;t know how easy it is to display the graphical console of a
virtual machine until I tried recently.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ sudo apt install virt-viewer
$ incus launch images:debian/trixie test --vm
$ incus console test --type=vga&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;That&#39;s it.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-17T20:17:17+00:00</dc:date>
	<dc:creator>Sérgio de Almeida Cipriano Júnior</dc:creator>
</item> 
<item rdf:about="https://diffoscope.org/news/diffoscope-325-released/">
	<title>Reproducible Builds (diffoscope): diffoscope 325 released</title>
	<link>https://diffoscope.org/news/diffoscope-325-released/</link>
     <content:encoded>&lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;325&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[ Chris Lamb ]
* Fix tests to work with zipdetails 4.0008. (Closes: #1141359)
* Downgrade debhelper compatibility level to 13 for now.
* Update copyright years.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href=&quot;https://diffoscope.org&quot;&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-17T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds (diffoscope)</dc:creator>
</item> 
<item rdf:about="http://blog.sesse.net/blog/tech/2026-07-15-08-45_looking_at_dpkg_startup_time.html">
	<title>Steinar H. Gunderson: Looking at dpkg startup time</title>
	<link>http://blog.sesse.net/blog/tech/2026-07-15-08-45_looking_at_dpkg_startup_time.html</link>
     <content:encoded>&lt;p&gt;Five years or so ago, I had a look at trying to speed up dpkg&#39;s package
installation; I concluded that it was probably possible to speed up,
but that there was no appetite for this kind of large-scale changes.
(You&#39;d probably need to rewrite the transaction system to get rid of
a lot of fsyncs, you&#39;d ideally want to reduce the number of syscalls
for unpack by io_uring and so on.)&lt;/p&gt;

&lt;p&gt;This summer, I&#39;ve been looking at something related on and off; it is
possible to speed up the startup time? That&#39;s in a sense the opposite
scenario; instead of installing lots of packages in a newly debootstrapped
chroot (with very few packages), see how fast you can install one
in a much more busy chroot (I just copied my laptop&#39;s dpkg dir, with ~6600 packages
installed).&lt;/p&gt;

&lt;p&gt;Before I show the numbers, I must stress that this is an &lt;em&gt;investigation&lt;/em&gt;,
not a fair benchmark, and you should not go shout at the dpkg maintainers
that they need to get to “catch up”. That said:&lt;/p&gt;

&lt;pre&gt;&amp;gt; sudo time dpkg --root=root -i hello_2.12.3-1_amd64.deb &amp;gt;/dev/null
Not building database; man-db/auto-update is not &#39;true&#39;.
1.12user 0.49system 0:01.85elapsed 87%CPU (0avgtext+0avgdata 171880maxresident)k
0inputs+14648outputs (0major+72963minor)pagefaults 0swaps

&amp;gt; sudo time ./src/dpkg --root=root -i hello_2.12.3-1_amd64.deb &amp;gt; /dev/null
0.04user 0.01system 0:00.15elapsed 38%CPU (0avgtext+0avgdata 6520maxresident)k
0inputs+1080outputs (0major+2705minor)pagefaults 0swaps
&lt;/pre&gt;

&lt;p&gt;How is it unfair? Well, for one, the code to run triggers is messed up
so they&#39;re not run (but the trigger in question should be very fast).
And there&#39;s one step at the end with detecting “disappearing packages” that doesn&#39;t run properly
because it&#39;s a bit tricky in my model and I didn&#39;t want to deal
with, well, difficult problems. But I think both are perfectly doable without
really affecting the end time, it just requires engineering. There&#39;s a &lt;em&gt;lot&lt;/em&gt; of work to be done, though;
diving into the code makes me shudder at all the complexities that need to be
in place to support all the corner cases of multiarch, for instance.&lt;/p&gt;

&lt;p&gt;The code is extremely proof-of-concept, but it runs and can read (and write)
metadata from SQLite instead of flat text files, it can resolve dependencies
in the most basic fashion, it can keep track of installed files, it should be
crash- and powerloss-proof. You know, the very very basic stuff, and without changing the
model fundamentally (like e.g. Michael Stapelberg did with
&lt;a href=&quot;https://distr1.org/&quot;&gt;distri&lt;/a&gt;, fundamentally replacing packages with disk
images and ending up in a very fast but rather different-looking system). So it was satisfying to see
that it ends up around 10x even on my not-very-new laptop (plus a significant
RAM reduction); I believe it should be possible to squeeze under 100 ms,
but that would probably require also optimizing the unpacking itself, which I didn&#39;t look at this time.&lt;/p&gt;

&lt;p&gt;Having a bunch of files being read into RAM and then processed freely was a design that made
a lot of sense when dpkg was written (in 1995!) and Debian had ~250 binary
packages &lt;em&gt;in total&lt;/em&gt; (and you probably wouldn&#39;t install all of them).
There was no reasonable database available for desktop systems; the closest
thing you&#39;d have was probably BerkeleyDB and that wasn&#39;t really it,
so flat files and fsync made a lot of sense, and was easy to manipulate
and persist.
But now, SQLite is widely available and probably the most battle-tested
code in history, a typical system has thousands of packages (you could
easily install tens of thousands if you&#39;re doing heavy development),
SSDs have replaced HDDs almost everywhere for system disks, and the
environment has just changed a lot in general. So I hope that someone at some
point will be crazy enough to pick this up and run with it, because it&#39;s a
lot of work and I don&#39;t intend to. :-)&lt;/p&gt;

&lt;p&gt;PS: I didn&#39;t look at apt; I think what I&#39;d really love to see first and
foremost is a package format change so that apt-listchanges can look at
(or look for) NEWS.gz without having to unpack the entire package.
Perhaps a control field saying “nothing new here”?&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-15T07:45:00+00:00</dc:date>
	<dc:creator>Steinar H. Gunderson</dc:creator>
</item> 
<item rdf:about="https://www.freexian.com/blog/debian-contributions-06-2026/">
	<title>Freexian Collaborators: Debian Contributions: Python 3.14 as default transition, DebConf 26 preparations, debvm, pconr and more! (by Anupa Ann Joseph)</title>
	<link>https://www.freexian.com/blog/debian-contributions-06-2026/</link>
     <content:encoded>&lt;h1 id=&quot;debian-contributions-2026-06&quot;&gt;Debian Contributions: 2026-06&lt;/h1&gt;
&lt;p&gt;&lt;a href=&quot;https://www.freexian.com/about/debian-contributions/&quot;&gt;Contributing to Debian&lt;/a&gt;
is part of &lt;a href=&quot;https://www.freexian.com/about/&quot;&gt;Freexian’s mission&lt;/a&gt;. This article
covers the latest achievements of Freexian and their collaborators. All of this
is made possible by organizations subscribing to our
&lt;a href=&quot;https://www.freexian.com/lts/&quot;&gt;Long Term Support contracts&lt;/a&gt; and
&lt;a href=&quot;https://www.freexian.com/services/&quot;&gt;consulting services&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;python-314-as-default-transition-by-stefano-rivera&quot;&gt;Python 3.14 as default transition, by Stefano Rivera&lt;/h2&gt;
&lt;p&gt;Debian has had Python 3.13 and 3.14 in &lt;code&gt;unstable&lt;/code&gt; and &lt;code&gt;testing&lt;/code&gt; since December
2025, with Python 3.13 as the default version (&lt;code&gt;/usr/bin/python3&lt;/code&gt; = 3.13). This
gave time for packages to implement support and detect issues in their test suites.&lt;/p&gt;
&lt;p&gt;A slot to transition to 3.14 as default was requested from the release team
&lt;a href=&quot;https://bugs.debian.org/1130323&quot;&gt;in March&lt;/a&gt;, and they indicated that we would
likely be able to schedule it in late June. In preparation, Stefano reviewed the
open bugs against Python interpreters and squashed some in uploads of the latest
point releases of Python: &lt;a href=&quot;https://www.python.org/downloads/release/python-31314/&quot;&gt;3.13.14&lt;/a&gt;
and &lt;a href=&quot;https://www.python.org/downloads/release/python-3146/&quot;&gt;3.14.6&lt;/a&gt;. Also in
June, Python &lt;a href=&quot;https://www.python.org/downloads/release/python-3150b2/&quot;&gt;3.15.0 beta 2&lt;/a&gt;
and &lt;a href=&quot;https://www.python.org/downloads/release/python-3150b3/&quot;&gt;beta 3&lt;/a&gt; released.
Stefano uploaded these to Debian &lt;code&gt;experimental&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The 3.15 betas were reason to &lt;a href=&quot;https://discuss.python.org/t/can-we-consider-an-uncoditional-change-of-abi3t-so-to-abi3t-soabi-platform-so-for-3-15-last-minute/107919&quot;&gt;attempt to revive review&lt;/a&gt;
of a blocked &lt;a href=&quot;https://github.com/python/cpython/pull/122917&quot;&gt;upstream patch&lt;/a&gt; to
support Debian multiarch in stable ABI Python extensions, now that Python 3.15
is adding a new stable ABI &lt;code&gt;abi3t&lt;/code&gt;.&lt;/p&gt;
&lt;h2 id=&quot;debconf-26-preparations-by-stefano-rivera-antonio-terceiro-lucas-kanashiro-santiago-ruano-rincón-and-anupa-ann-joseph&quot;&gt;DebConf 26 preparations, by Stefano Rivera, Antonio Terceiro, Lucas Kanashiro, Santiago Ruano Rincón and Anupa Ann Joseph&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf 26&lt;/a&gt;, the annual Debian Developer
Conference, is being held in Santa Fe, Argentina, in July. Stefano Rivera,
Antonio Terceiro, Lucas Kanashiro, Santiago Ruano and Anupa Ann Joseph
contributed to the preparations for the event.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;As usual, Stefano has been supporting the conference website and registration,
helping the local team to get accurate data on attendee numbers.&lt;/li&gt;
&lt;li&gt;Antonio has been supporting the conference website and helping the content
team to put together the conference schedule.&lt;/li&gt;
&lt;li&gt;Santiago has been helping the local team on different topics regarding logistics.&lt;/li&gt;
&lt;li&gt;Anupa assisted with the accommodation arrangements for DebCamp and DebConf,
working alongside Nattie.&lt;/li&gt;
&lt;li&gt;Lucas has been coordinating the conference schedule and communicating with
some speakers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;debvm-by-helmut-grohne&quot;&gt;debvm, by Helmut Grohne&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://salsa.debian.org/helmutg/debvm&quot;&gt;debvm&lt;/a&gt; tool used for creating and
running ephemeral virtual machines saw a number of small improvements. The
requirement of having a filesystem label has been removed in favor of using a
uuid and &lt;code&gt;/etc/fstab&lt;/code&gt; is no longer created. A memory balloon is enabled by
default and this enables qemu to automatically release free guest memory to the
host. Booting Ubuntu VMs regressed as a result of their use of &lt;code&gt;uutils&lt;/code&gt; and has
been fixed. The &lt;code&gt;--architecture&lt;/code&gt; flag is back to be able to better support Hurd,
which is a work-in-progress of Johannes Schauer Marin Rodrigues. Thanks to
Jochen Sprickerhof, you can more easily create VMs for &lt;code&gt;autopkgtest-virt-qemu&lt;/code&gt;
using &lt;code&gt;--hook-dir=/usr/share/mmdebstrap/hooks/autopkgtest-create-qemu&lt;/code&gt;. There
also are a few documentation and error message improvements. All of this is
pending in git waiting to be uploaded once development slows down. While booting
a machine from &lt;code&gt;virtiofsd&lt;/code&gt; succeeded, turning the proof-of-concept into
production remains for later.&lt;/p&gt;
&lt;h2 id=&quot;pconr-by-helmut-grohne&quot;&gt;pconr, by Helmut Grohne&lt;/h2&gt;
&lt;p&gt;At &lt;a href=&quot;https://debconf25.debconf.org/talks/170-reviving-unschroot/&quot;&gt;DebConf25&lt;/a&gt;,
Helmut reported on a &lt;a href=&quot;https://codeberg.org/shelter/reschroot&quot;&gt;schroot&lt;/a&gt;
substitute called unschroot. The second iteration uses &lt;a href=&quot;https://varlink.org&quot;&gt;varlink&lt;/a&gt;
IPC to construct a container. That varlink API is now separated into a new
project called &lt;a href=&quot;https://git.subdivi.de/~helmut/pconr.git/&quot;&gt;programmable container runtime&lt;/a&gt;.
It is meant to provide more flexibility in constructing containers than
established solutions such as the &lt;code&gt;unshare&lt;/code&gt; command from util-linux, bubblewrap
or podman provide while still managing repetitive complexity such as process
orchestration for the developer. A new example that uses this infrastructure is
&lt;a href=&quot;https://git.subdivi.de/~helmut/pconr.git/tree/examples/mmdebstrap_container.py&quot;&gt;a better containment for mmdebstrap&lt;/a&gt;
eliminating chroot escape. There also is an
&lt;a href=&quot;https://github.com/helmutg/asyncvarlink/commit/3e16139f72c7374f2ca3640045ef7162c98e7a4c&quot;&gt;asyncvarlink/0.3.2 release&lt;/a&gt;
taking steps to become more maintainable in Debian to eventually get pconr into
Debian.&lt;/p&gt;
&lt;h2 id=&quot;miscellaneous-contributions&quot;&gt;Miscellaneous contributions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Stefano did routine uploads (mostly new upstream versions) of &lt;code&gt;python-pip&lt;/code&gt;,
&lt;code&gt;python-pipx&lt;/code&gt;, &lt;code&gt;hatchling&lt;/code&gt;, &lt;code&gt;dh-python&lt;/code&gt;, &lt;code&gt;beautifulsoup4&lt;/code&gt;, &lt;code&gt;python-virtualenv&lt;/code&gt;,
&lt;code&gt;python-mitogen&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Stefano uploaded a snowball mini-transition: &lt;code&gt;snowball&lt;/code&gt;, &lt;code&gt;snowball-data&lt;/code&gt;,
and &lt;code&gt;pystemmer&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Stefano did some &lt;a href=&quot;https://wiki.debian.org/Teams/DebianNet&quot;&gt;debian.net&lt;/a&gt; team
admin, setting up a container and later a VM for
&lt;a href=&quot;https://salsa.debian.org/debiannet-team/requests/-/work_items/36&quot;&gt;vote.debian.net&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Stefano &lt;a href=&quot;https://lists.debian.org/msgid-search/cer4b3szczxpt64wbzhumcm6go7tmkfvhdsqoftpevav2ovu3l@zherud2oym4p&quot;&gt;responded&lt;/a&gt;
to a &lt;a href=&quot;https://lists.debian.org/msgid-search/CAEd1pt5QiD9-UUV5jP=U7=L2pM5f6c1WPcUY3jWoYbcTO8iRcw@mail.gmail.com&quot;&gt;semi-escalation&lt;/a&gt;
to the Debian Technical Committee, after some communication between an upstream,
a bug reporter, and a Debian package maintainer went sideways and got heated.&lt;/li&gt;
&lt;li&gt;Emilio managed several transitions, and filed bugs against the few remaining
GCC 13 rdeps.&lt;/li&gt;
&lt;li&gt;Antonio did salsa maintenance work, debugging service issues, approving user
registrations, and processing support requests.&lt;/li&gt;
&lt;li&gt;Antonio worked on Debian CI maintenance, including but not limited to
deploying new armhf and armel workers, fixing bugs and preparing an upcoming
release of debci.&lt;/li&gt;
&lt;li&gt;Antonio did several maintenance tasks for MiniDebConf websites.&lt;/li&gt;
&lt;li&gt;Antonio uploaded ruby-bunny, ruby-sinatra and ruby-mustermann, fixing a few
FTBFS bugs among them.&lt;/li&gt;
&lt;li&gt;Carles using &lt;code&gt;&lt;a href=&quot;https://salsa.debian.org/carlespina/po-debconf-manager&quot;&gt;po-debconf-manager&lt;/a&gt;&lt;/code&gt;:
Reviewed Catalan translations for 5 packages, submitted 6 packages. Added a
&lt;a href=&quot;https://salsa.debian.org/carlespina/po-debconf-manager/-/blob/main/docs/blog/2026-06-29-update.md?ref_type=heads&quot;&gt;draft blog/update&lt;/a&gt;
about the po-debconf-manager project.&lt;/li&gt;
&lt;li&gt;Carles submitted a new &lt;a href=&quot;https://github.com/BestImageViewer/geeqie/pull/2438&quot;&gt;Geeqie Catalan translation&lt;/a&gt;:
it had accumulated a large number of untranslated strings over the last 4 years.&lt;/li&gt;
&lt;li&gt;Carles contributed to the Debian wiki: improved documentation for the
Framework Laptop and added a new section “&lt;a href=&quot;https://wiki.debian.org/InstallingDebianOn/Framework/Laptop13/AMD_Ryzen_AI_300_Series#Battery_charging_control&quot;&gt;Battery charging control&lt;/a&gt;”
(after doing some debugging and testing). He wrote a page about
&lt;a href=&quot;https://wiki.debian.org/SignalDesktop&quot;&gt;Signal Desktop&lt;/a&gt;. Carles started looking
at testing/documenting Mailman2 -&amp;gt; Mailman3 migration.&lt;/li&gt;
&lt;li&gt;Carles, in relation to the migration process, double checked old pages without
relevant information in the Debian wiki.&lt;/li&gt;
&lt;li&gt;Thorsten did another upload of package hplip to fix some bugs.&lt;/li&gt;
&lt;li&gt;In the context of the Google Summer of Code 2026 project, Santiago continued
co-mentoring Aryan Karamtoth, who is working on the Linux live-patching project.
As part of the team, Santiago guided Aryan to help design the different
workflows and to study the different tools available, including the
&lt;a href=&quot;https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/scripts/livepatch/klp-build?h=v6.19&quot;&gt;upstream klp-build&lt;/a&gt;
(that was introduced in v6.19), and compare it with &lt;a href=&quot;https://github.com/SUSE/klp-build/&quot;&gt;SUSE’s klp-build&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Colin &lt;a href=&quot;https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1149&quot;&gt;clarified&lt;/a&gt;
the bug tracking system’s documentation to indicate that maintainers may
sometimes reasonably ask users to file bugs upstream themselves.&lt;/li&gt;
&lt;li&gt;Colin fixed 15 packages for &lt;a href=&quot;https://udd.debian.org/cgi-bin/bts-usertags.cgi?user=debian-python%40lists.debian.org&amp;amp;tag=pytest9.1&quot;&gt;pytest 9.1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Colin fixed a &lt;a href=&quot;https://bugs.debian.org/1140927&quot;&gt;depthcharge-tools regression with Python 3.14 as default&lt;/a&gt;
that broke debian-installer builds.&lt;/li&gt;
&lt;li&gt;Helmut continued to report undeclared file conflicts and correspond about them.&lt;/li&gt;
&lt;li&gt;Helmut wrote patches for &lt;a href=&quot;https://tracker.debian.org/strace&quot;&gt;strace&lt;/a&gt; to enable
&lt;a href=&quot;https://bugs.debian.org/1140559&quot;&gt;cross building&lt;/a&gt; and a
&lt;a href=&quot;https://bugs.debian.org/1062446&quot;&gt;32bit personality on arm64&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Helmut continued maintaining rebootstrap working fixing build failures in
fontconfig, gettext and sqlite3 as well as changing the way packages from gcc
builds are installed to better serve a need reported by
&lt;a href=&quot;https://lists.debian.org/debian-cross/2026/06/msg00005.html&quot;&gt;Samuel Thibault&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-15T00:00:00+00:00</dc:date>
	<dc:creator>Anupa Ann Joseph</dc:creator>
</item> 
<item rdf:about="https://gwolf.org/2026/07/got-your-keys-ready-for-debconf26.html">
	<title>Gunnar Wolf: Got your keys ready for DebConf26?</title>
	<link>https://gwolf.org/2026/07/got-your-keys-ready-for-debconf26.html</link>
     <content:encoded>&lt;p&gt;Yay! Finally it’s that time of year — DebCamp is underway, and soon it will
be time for DebConf! 🎉🥳&lt;/p&gt;

&lt;p&gt;As it is by now tradition, it’s my task to coordinate the DebConf26
keysigning party. And, as usual, I have set up the list of &lt;a href=&quot;https://people.debian.org/~gwolf/dc26_ksp/&quot;&gt;DebConf26
keysigning maps&lt;/a&gt; for everybody
involved.&lt;/p&gt;

&lt;p&gt;So, if you are taking part of DebConf, make sure to:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Find yourself in the &lt;a href=&quot;https://people.debian.org/~gwolf/dc26_ksp/&quot;&gt;keysigning
map&lt;/a&gt;. Are you a part of the
listing?&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;
        &lt;p&gt;If you are not there, log in to the DebConf26 management system and
edit the &lt;a href=&quot;https://debconf26.debconf.org/register/step-3&quot;&gt;Personal
Information&lt;/a&gt; section of
your profile. Make sure you submit your OpenPGP key fingerprint.&lt;/p&gt;
      &lt;/li&gt;
      &lt;li&gt;
        &lt;p&gt;Make sure your key is available in the keyserver network. They should
basically be equivalent and interoperate, but in any case — my scripts
will try to find your key at &lt;a&gt;pgpkeys.eu&lt;/a&gt;,
&lt;a&gt;keys.openpgp.org&lt;/a&gt;,
&lt;a&gt;keyserver.computer42.org&lt;/a&gt;,
&lt;a&gt;keyserver.ubuntu.com&lt;/a&gt;,
&lt;a&gt;keyring.debian.org&lt;/a&gt;,
&lt;a&gt;pgp.surf.nl&lt;/a&gt;, &lt;a&gt;pgp.pm&lt;/a&gt;,
&lt;a&gt;pgp.mit.edu&lt;/a&gt;, &lt;a&gt;the.earth.li&lt;/a&gt;.&lt;/p&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Make sure your name is readable and matches what you want others to
sign. If it does not, edit your key and upload it &lt;em&gt;now&lt;/em&gt;!&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Remember that, &lt;a href=&quot;https://debconf26.debconf.org/about/ksp/&quot;&gt;as announced&lt;/a&gt;,
the deadline for the final list is on &lt;strong&gt;Thursday, 2026.07.16, 09:00 GMT-3
(Argentinian time).&lt;/strong&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-14T21:23:21+00:00</dc:date>
	<dc:creator>Gunnar Wolf</dc:creator>
</item> 
<item rdf:about="https://blog.freesources.org//posts/2026/07/zed-xdebug/">
	<title>Jonas Meurer: zed-xdebug</title>
	<link>https://blog.freesources.org//posts/2026/07/zed-xdebug/</link>
     <content:encoded>&lt;h1 id=&quot;Nextcloud_PHP_debugging_with_Xdebug_in_Zed_editor&quot;&gt;Nextcloud PHP debugging with Xdebug in Zed editor&lt;/h1&gt;

&lt;p&gt;I started to switch from PhpStorm to Zed as IDE recently as Zed is open source
and has a much smaller footprint and is more slick than PhpStorm.&lt;/p&gt;

&lt;p&gt;One thing that I didn&#39;t get running immediately was Xdebug integration, so I did
a bit of research and asked Claude for help. Here&#39;s a quick writeup of how to
get it running.&lt;/p&gt;

&lt;p&gt;I have Zed installed as Flatpak on a Debian Trixie host system.&lt;/p&gt;

&lt;p&gt;The PHP process runs in a &lt;a href=&quot;https://github.com/juliusknorr/nextcloud-docker-dev/&quot;&gt;nextcloud-docker-dev&lt;/a&gt;
Docker container.&lt;/p&gt;

&lt;h2 id=&quot;Install_Zed_and_configure_debugging_there&quot;&gt;Install Zed and configure debugging there&lt;/h2&gt;

&lt;p&gt;Install Zed: &lt;code&gt;flatpak install flathub dev.zed.Zed&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;In Zed: open the Extensions view and install PHP.&lt;/p&gt;

&lt;p&gt;Configure the debugger:&lt;/p&gt;

&lt;p&gt;Create &lt;code&gt;~/.var/app/dev.zed.Zed/config/zed/debug.json&lt;/code&gt;:&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;json&quot;&gt;[
  {
    &quot;label&quot;: &quot;PHP: Listen to Xdebug&quot;,
    &quot;adapter&quot;: &quot;Xdebug&quot;,
    &quot;request&quot;: &quot;launch&quot;,
    &quot;port&quot;: 9003,
    &quot;pathMappings&quot;: {
      &quot;/var/www/html&quot;:             &quot;/home/&amp;lt;user&amp;gt;/devel/nextcloud/server&quot;,
      &quot;/var/www/html/apps-extra&quot;:  &quot;/home/&amp;lt;user&amp;gt;/devel/nextcloud/server/apps-extra&quot;,
      &quot;/var/www/html/apps-shared&quot;: &quot;/home/&amp;lt;user&amp;gt;/devel/nextcloud/apps-shared&quot;
    }
  }
]
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Add one entry per bind-mounted app directory.&lt;/p&gt;

&lt;p&gt;After creating the file, restart Zed.&lt;/p&gt;

&lt;p&gt;Inside Zed, select &quot;debugger: start&quot; from command palette and then &quot;PHP: Listen to Xdebug&quot;.&lt;/p&gt;

&lt;p&gt;Verify Zed is listening. Running &lt;code&gt;ss -tlnp | grep 9003&lt;/code&gt; on the host should show &lt;code&gt;*:9003&lt;/code&gt; with Zed as the process.&lt;/p&gt;

&lt;h2 id=&quot;Configure_Xdebug_inside_the_container&quot;&gt;Configure Xdebug inside the container&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;/usr/local/etc/php/conf.d/xdebug.ini&lt;/code&gt;:&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;ini&quot;&gt;xdebug.mode = debug
xdebug.idekey = PHPSTORM
xdebug.trace_output_name=trace.%R.%u
xdebug.profiler_output_name=profile.%R.%u
xdebug.output_dir=/shared/xdebug

xdebug.log = /var/log/xdebug.log
xdebug.log_level = 3

; Try to discover the client host, otherwise fall back to the docker host
xdebug.discover_client_host=true
xdebug.client_host=host.docker.internal

; When you cannot specify a trigger, use &quot;xdebug.start_with_request = yes&quot; to autostart debugging for all requests
; https://xdebug.org/docs/all_settings#start_with_request
xdebug.start_with_request = trigger

; Set xdebug.mode trace to use this
; More details at https://derickrethans.nl/flamboyant-flamegraphs.html
xdebug.trace_format=3
xdebug.trace_output_name=xdebug.%R.%u
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Apply changes by restarting apache in the container: &lt;code&gt;apache2ctl -k graceful&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Notes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;host.docker.internal&lt;/code&gt; resolves on Linux Docker only if the container was started with &lt;code&gt;--add-host=host.docker.internal:host-gateway&lt;/code&gt; (nextcloud-docker-dev already does this).&lt;/li&gt;
&lt;li&gt;&lt;code&gt;discover_client_host = true&lt;/code&gt; makes xdebug follow &lt;code&gt;X-Forwarded-For&lt;/code&gt; - useful behind Nextcloud&#39;s dev reverse proxy.&lt;/li&gt;
&lt;/ul&gt;


&lt;h2 id=&quot;Test_xdebug_with_a_PHP_command_inside_the_container&quot;&gt;Test xdebug with a PHP command inside the container&lt;/h2&gt;

&lt;p&gt;Run &lt;code&gt;XDEBUG_SESSION=PHPSTORM php occ status&lt;/code&gt; inside the container and check &lt;code&gt;/var/log/xdebug.log&lt;/code&gt;.&lt;/p&gt;

&lt;h2 id=&quot;Install_the_browser_extension&quot;&gt;Install the browser extension&lt;/h2&gt;

&lt;p&gt;Install Xdebug Helper (Firefox/Chrome). In its preferences, set the IDE Key to PhpStorm. It will set the &lt;code&gt;XDEBUG_SESSION&lt;/code&gt; cookie when toggled to Debug.&lt;/p&gt;

&lt;p&gt;Click the Xdebug Helper icon in the browser and set it to Debug.&lt;/p&gt;

&lt;h2 id=&quot;Test_Xdebug_with_browser_extension&quot;&gt;Test Xdebug with browser extension&lt;/h2&gt;

&lt;p&gt;Load the URL that exercises the code path with the breakpoint. Zed should stop the code exection at the breakpoint.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-14T10:46:20+00:00</dc:date>
	<dc:creator>mejo roaming</dc:creator>
</item> 
<item rdf:about="hatenablog://entry/14945776032052860672">
	<title>Kentaro Hayashi: Try to build Mozc with Bazel 7.7.1</title>
	<link>https://kenhys.hatenablog.jp/entry/2026/07/12/231009</link>
     <content:encoded>&lt;h2 id=&quot;Introduction&quot;&gt;Introduction&lt;/h2&gt;

&lt;p&gt;Recently, I&#39;ve got a chance to try building Mozc (Most famous Japanese input method editor) with Bazel.&lt;/p&gt;

&lt;p&gt;As you know, recently newer Bazel related packages were landed into
debian/unstable.
Then now I&#39;m planning to update Mozc from 2.29.5160.102
to 3.33.6133.&lt;/p&gt;

&lt;h2 id=&quot;Background-story-about-Mozc-and-Debian&quot;&gt;Background story about Mozc and Debian&lt;/h2&gt;

&lt;p&gt;The upstream of Mozc had released 3.34.6239, but on Debian,
we stick to Mozc 2.29.5160.102.&lt;/p&gt;

&lt;p&gt;Mozc requires newer Bazel but we only had Bazel 4.2.3 at that time on Debian, so even though the upstream of Mozc switched from GYP to Bazel,
we had patched Mozc with GYP based package.&lt;/p&gt;

&lt;p&gt;We even did make an effort to restore build options that had been already removed. :-(
And needed to migrate from GTK2 renderer to GTK3 renderer.&lt;/p&gt;

&lt;p&gt;That is why the version of Mozc is diverged from upstream on Debian.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;2.29.5160.102 (Now on Debian)&lt;/li&gt;
&lt;li&gt;2.29.5268.102&lt;/li&gt;
&lt;li&gt;2.29.5374.102&lt;/li&gt;
&lt;li&gt;2.29.5544.102&lt;/li&gt;
&lt;li&gt;2.30.5544.102&lt;/li&gt;
&lt;li&gt;2.31.5712.102&lt;/li&gt;
&lt;li&gt;2.31.5851.102&lt;/li&gt;
&lt;li&gt;2.32.5994.102&lt;/li&gt;
&lt;li&gt;3.33.6089&lt;/li&gt;
&lt;li&gt;3.33.6133 (Target to upgrade for)&lt;/li&gt;
&lt;li&gt;3.34.6239&lt;/li&gt;
&lt;/ul&gt;


&lt;h2 id=&quot;How-to-switch-from-GYP-to-Bazel&quot;&gt;How to switch from GYP to Bazel?&lt;/h2&gt;

&lt;p&gt;At first, we needed to decide what Mozc version to work with it.&lt;/p&gt;

&lt;p&gt;Now latest version of Mozc is 3.34.x, but it requires Bazel 9.x.
Please recall that Bazel 7.7.1 was introduced Debian/unstable.
And more, newer dependency libraries are required.&lt;/p&gt;

&lt;p&gt;You might feel that target version (3.33.6133) is too high from 2.29.5160.102,
but if we upgrade to more older Mozc, it means that it
requires to backport Mozc to older libabsl compatible codes and so on.&lt;/p&gt;

&lt;p&gt;That is why Mozc 3.33.6133 was chosen.&lt;/p&gt;

&lt;p&gt;Even once the target version has been decided, you can&#39;t let your guard down.&lt;/p&gt;

&lt;p&gt;There are many technical tasks to solve.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Revisit patch sets to apply&lt;/li&gt;
&lt;li&gt;Porting uim mozc patch and fix FTBFS&lt;/li&gt;
&lt;li&gt;Porting fcitx5 mozc patch and fix FTBFS&lt;/li&gt;
&lt;li&gt;Fix src/third_party vendoring&lt;/li&gt;
&lt;li&gt;Switch from GYP to Bazel build systems&lt;/li&gt;
&lt;li&gt;...&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;At least, it will likely require several rounds of testing in the
Debian experimental.&lt;/p&gt;

&lt;h2 id=&quot;Conclusion&quot;&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;Currently, &lt;code&gt;gbp buildpackge&lt;/code&gt; has succeeded finally on local machine,
but need to tidy and cleanup stuffs.&lt;/p&gt;

&lt;p&gt;I didn&#39;t know packaging with Bazel best practice yet, to remove many third party vendor/ bundles, I&#39;ve found that it requires pile of patch to eliminate them.&lt;/p&gt;

&lt;p&gt;In the current version of Debian, as a one of build system, further work — such as support from debhelper -
will be needed.&lt;/p&gt;

&lt;p&gt;I&#39;ll file working progress on &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1085173&quot;&gt;#1085173&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-12T14:10:09+00:00</dc:date>
	<dc:creator>Kentaro Hayashi</dc:creator>
</item> 
<item rdf:about="tag:copyninja.in,2026-07-21:/blog/debvulns-exporter.html">
	<title>Vasudev Kamath: Releasing debvulns-exporter: Prometheus exporter for Debian System Vulnerabilities</title>
	<link>https://copyninja.in/blog/debvulns-exporter.html</link>
     <content:encoded>&lt;p&gt;Following up on my previous &lt;a class=&quot;reference external&quot; href=&quot;https://copyninja.in/blog/debvulns-cli.html&quot;&gt;post&lt;/a&gt;, I am releasing
&lt;a class=&quot;reference external&quot; href=&quot;https://pypi.org/project/debvulns/&quot;&gt;debvulns-exporter&lt;/a&gt;, a Prometheus exporter
for tracking Debian system vulnerabilities. The underlying vulnerability
analysis logic remains identical to the  previously released MCP server and CLI
utility.&lt;/p&gt;
&lt;div class=&quot;section&quot; id=&quot;why-an-exporter&quot;&gt;
&lt;h2&gt;Why an Exporter?&lt;/h2&gt;
&lt;p&gt;In my engineering workflows, I frequently deal with Debian and vulnerability
management. Most enterprise environments rely on commercial, paid vulnerability
platforms like Tenable or Rapid7. While these platforms provide extensive
feature sets, I noticed a distinct lack of open-source tools tailored for this
specific pipeline. While &lt;cite&gt;debsecan&lt;/cite&gt; exists, it lacks a structured, parseable
format suitable for building dashboards aimed at management consumption. What
started as an experimental MCP server for learning purposes evolved into a
practical question: why not convert it into a Prometheus exporter? Given that
Prometheus is the de facto standard metrics platform across the industry, this
architecture was the logical next step.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;section&quot; id=&quot;design-and-exported-metrics&quot;&gt;
&lt;h2&gt;Design and Exported Metrics&lt;/h2&gt;
&lt;p&gt;The exporter is implemented as a native Prometheus exporter utilizing the
&lt;cite&gt;prometheus-client&lt;/cite&gt; library. It operates using two threads: one handles fetching
the vulnerability data, parsing EPSS feeds, and cross-referencing installed
packages to identify local vulnerabilities; the second handles serving the
metrics endpoint. The full architecture details and metrics specifications can
be found in the &lt;a class=&quot;reference external&quot; href=&quot;https://github.com/copyninja/debsecan-mcp/blob/main/docs/prometheus_exporter_design.md&quot;&gt;design doc&lt;/a&gt;.
The specification was drafted during a technical brainstorming session with
&lt;em&gt;Claude 4.6 Sonnet&lt;/em&gt; on &lt;em&gt;Antigravity&lt;/em&gt; prior to writing the implementation.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;section&quot; id=&quot;testing-and-dashboarding&quot;&gt;
&lt;h2&gt;Testing and Dashboarding&lt;/h2&gt;
&lt;p&gt;To validate the exporter, I spun up older &lt;em&gt;Debian 11&lt;/em&gt; and &lt;em&gt;Debian 12&lt;/em&gt; cloud
images sourced from the &lt;a class=&quot;reference external&quot; href=&quot;https://cloud.debian.org/images/cloud/&quot;&gt;Debian Cloud team&lt;/a&gt;. The older image was intentionally
selected to guarantee a standard baseline of unpatched vulnerabilities for
testing. The local evaluation topology is structured as shown below:&lt;/p&gt;
&lt;img alt=&quot;&quot; src=&quot;https://copyninja.in/images/debvulns-exporter-setup.png&quot; /&gt;
&lt;p&gt;Rather than constructing the Grafana dashboard from scratch, I used Claude 4.6
Sonnet via Antigravity to generate the layout configuration. The generated
dashboard for the local testbed functions effectively:&lt;/p&gt;
&lt;img alt=&quot;&quot; src=&quot;https://copyninja.in/images/debvulns-exporter-dashboard.png&quot; /&gt;
&lt;p&gt;The complete, ready-to-import Grafana dashboard configuration is included
directly in the &lt;cite&gt;debvulns&lt;/cite&gt; &lt;a class=&quot;reference external&quot; href=&quot;https://github.com/copyninja/debsecan-mcp/blob/main/contrib/grafana/debvulns-dashboard.json&quot;&gt;source code&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;section&quot; id=&quot;renaming-the-project&quot;&gt;
&lt;h2&gt;Renaming the project&lt;/h2&gt;
&lt;p&gt;To prevent namespace conflicts and confusion with the native &lt;cite&gt;debsecan&lt;/cite&gt; utility
in Debian, I have unified the ecosystem under the &lt;em&gt;debvulns&lt;/em&gt; moniker. The core
CLI is named &lt;cite&gt;debvulns&lt;/cite&gt;, the exporter is &lt;cite&gt;debvulns-exporter&lt;/cite&gt;, and the MCP
component is &lt;cite&gt;debvulns-mcp&lt;/cite&gt;. The migration release has been published to &lt;a class=&quot;reference external&quot; href=&quot;https://pypi.org/project/debsecan-mcp/&quot;&gt;PyPI&lt;/a&gt;, and the new consolidated repository
is active at &lt;a class=&quot;reference external&quot; href=&quot;https://pypi.org/project/debvulns/&quot;&gt;debvulns&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;section&quot; id=&quot;conclusion&quot;&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;While this began as a personal utility to fill a niche tool gap, I expect it
will be useful for others managing Debian infrastructure at scale. My next
objective is to formalize Debian packaging for both the CLI and the exporter.
The MCP component will likely remain available as an independent artifact. Until
then, happy hacking.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Note: As a core design choice, `debvulns` still uses native `debsecan` as its
ground-truth standard. The tool continuously cross-verifies its output against
`debsecan` to ensure perfect functional parity and data consistency.&lt;/em&gt;&lt;/p&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-12T11:30:25+00:00</dc:date>
	<dc:creator>copyninja</dc:creator>
</item> 
<item rdf:about="https://reproducible-builds.org/reports/2026-06/">
	<title>Reproducible Builds: Reproducible Builds in June 2026</title>
	<link>https://reproducible-builds.org/reports/2026-06/</link>
     <content:encoded>&lt;p class=&quot;lead&quot;&gt;&lt;strong&gt;Welcome to the June 2026 report from the &lt;a href=&quot;https://reproducible-builds.org&quot;&gt;Reproducible Builds&lt;/a&gt; project!&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://reproducible-builds.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/reproducible-builds.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In these reports, we outline the most important things that we have been up to over the past month. As a quick recap about what problem our project intends to solve, whilst anyone may inspect the source code of free software for malicious flaws, almost all software is distributed to end users as pre-compiled binaries. The motivation behind the reproducible builds effort is to ensure no flaws have been introduced during this compilation process by promising identical results are always generated from a given source, thus allowing multiple third-parties to come to a consensus on whether a build was compromised or not.&lt;/p&gt;

&lt;p&gt;If you are interested in contributing to the project, please visit our &lt;a href=&quot;https://reproducible-builds.org/contribute/&quot;&gt;&lt;em&gt;Contribute&lt;/em&gt;&lt;/a&gt; page on our website.&lt;/p&gt;

&lt;p&gt;In this month’s report, we cover:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#only-installing-reproducible-packages-with-repro-threshold&quot;&gt;Only installing reproducible packages with &lt;em&gt;repro-threshold&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#distribution-work&quot;&gt;Distribution work&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#diffoscope-development&quot;&gt;diffoscope development&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#from-our-mailing-list&quot;&gt;From our mailing list…&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#documentation-updates&quot;&gt;Documentation updates&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#patches&quot;&gt;Patches&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#four-new-scholarly-papers&quot;&gt;Four new scholarly papers&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;only-installing-reproducible-packages-with-repro-threshold&quot;&gt;Only installing reproducible packages with &lt;em&gt;repro-threshold&lt;/em&gt;&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://rebuilderd.xpam.pl:2096/demo.html&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/repro-threshold.png#center&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;A &lt;a href=&quot;https://rebuilderd.xpam.pl:2096/demo.html&quot;&gt;very interesting demonstration&lt;/a&gt; is now available showing how you might configure your Debian system to only install packages that have been reproduced by &lt;em&gt;m/n&lt;/em&gt; rebuilders.&lt;/p&gt;

&lt;p&gt;This is implemented via a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;reproduced+https://&lt;/code&gt; &lt;a href=&quot;https://en.wikipedia.org/wiki/APT_(software)&quot;&gt;APT&lt;/a&gt; transport ( a mechanism for communicating between the APT client and its repository source — commonly HTTP):&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Every package download is intercepted by &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;repro-threshold&lt;/code&gt;, which queries two independent rebuilders for a signed attestation before allowing installation to proceed. [It] is important to note that [an] install will only succeed if all package dependencies are also reproducible.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The &lt;a href=&quot;https://rebuilderd.xpam.pl:2096/demo.html&quot;&gt;demo&lt;/a&gt; gives examples of how to quickly experiment with this using a &lt;a href=&quot;https://www.docker.com/&quot;&gt;Docker&lt;/a&gt; container.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;distribution-work&quot;&gt;Distribution work&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://debian.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/debian.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In &lt;strong&gt;Debian&lt;/strong&gt; this month:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;The &lt;a href=&quot;https://tracker.debian.org/pkg/debian-installer&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;debian-installer&lt;/code&gt;&lt;/a&gt; package in Debian was uploaded with a &lt;a href=&quot;https://tracker.debian.org/news/1768824/accepted-debian-installer-20260628-source-into-unstable/&quot;&gt;substantial reproducibility-related changelog&lt;/a&gt;. This means, for the first time, the &lt;a href=&quot;https://reproduce.debian.net/excuses.html?source_name=debian-installer&quot;&gt;uploaded version could finally be reproduced&lt;/a&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Various &lt;a href=&quot;https://openjdk.org/&quot;&gt;OpenJDK&lt;/a&gt; packages were also uploaded to Debian, including the fix for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;JDK-8385738&lt;/code&gt; (“Javadoc does not produce reproducible output…”) (&lt;a href=&quot;https://reproduce.debian.net/all/api/v1/builds/206100/artifacts/426780/diffoscope&quot;&gt;for example&lt;/a&gt;). [&lt;a href=&quot;https://tracker.debian.org/news/1760093/accepted-openjdk-27-2724ea-2-source-into-unstable/&quot;&gt;…&lt;/a&gt;][&lt;a href=&quot;https://tracker.debian.org/news/1760960/accepted-openjdk-26-26018-3-source-into-unstable/&quot;&gt;…&lt;/a&gt;][&lt;a href=&quot;https://tracker.debian.org/news/1760962/accepted-openjdk-25-25044ea-1-source-into-unstable/&quot;&gt;…&lt;/a&gt;]&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;The “reason” pages on &lt;a href=&quot;https://reproduce.debian.net&quot;&gt;&lt;em&gt;reproduce.debian.net&lt;/em&gt;&lt;/a&gt;, &lt;a href=&quot;https://reproduce.debian.net/ppc64el/stats/unstable/&quot;&gt;such as the one for &lt;em&gt;ppc64el&lt;/em&gt;&lt;/a&gt;, now feature links labeled with the &lt;a href=&quot;https://www.compart.com/en/unicode/U+1F41B&quot;&gt;bug emoji&lt;/a&gt; (i.e. 🐛) which links to the categorized issues packages have been tagged with in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;reproducible-notes.git&lt;/code&gt; repo.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Indeed, 25 reviews of Debian packages were added, 31 were updated and 33 were removed this month adding to &lt;a href=&quot;https://tests.reproducible-builds.org/debian/index_issues.html&quot;&gt;our extensive knowledge about identified issues&lt;/a&gt;. Two issue types were updated as well. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/a2302451&quot;&gt;…&lt;/a&gt;][&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/9e09f1ee&quot;&gt;…&lt;/a&gt;]&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href=&quot;https://apt.izzysoft.de/fdroid/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/izzyondroid.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://apt.izzysoft.de/fdroid/&quot;&gt;&lt;strong&gt;IzzyOnDroid&lt;/strong&gt;&lt;/a&gt; Android APK repository reached its next milestone this month, now covering 2 out of every 3 apps (66.7%) with reproducible builds. Their &lt;a href=&quot;https://izzyondroid.org/docs/reproducibleBuilds/DebugFailedRBs/&quot;&gt;documentation for debugging and fixing failed builds&lt;/a&gt; has steadily grown as well. More clients have picked up showing reproducibility results (e.g. Droid-ify), and &lt;a href=&quot;https://apt.izzysoft.de/packages/com.machiav3lli.fdroid&quot;&gt;Neo Store&lt;/a&gt; now can be configured to stick to only reproducible applications. Further, an &lt;a href=&quot;https://shields.rbtlog.dev/&quot;&gt;independent builder&lt;/a&gt; has been added to the build farm, increasing the trust level even more as APK builds can have multiple confirmations now.&lt;/p&gt;

&lt;p&gt;At the same time, IzzyOnDroid’s &lt;a href=&quot;https://codeberg.org/IzzyOnDroid/rbtlog&quot;&gt;&lt;em&gt;rbtlog&lt;/em&gt;&lt;/a&gt; got several new features. The most outstanding is caching for frequently used resources such as &lt;a href=&quot;https://github.com/obfusk/reproducible-apk-tools&quot;&gt;&lt;em&gt;reproducible-apk-tools&lt;/em&gt;&lt;/a&gt;, command-line tools and NodeJS in order to counter ongoing issues with GitHub availability, while at the same time saving bandwidth and build time. This change also enables some other some smaller enhancements such as being able to configure build timeouts per recipe for those builds running longer than the average, release pattern filtering for update checks or having a field for maintainer notes to shortly summing up e.g. why a reproducible build failed.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://www.opensuse.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/opensuse.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Lastly, Bernhard M. Wiedemann posted another &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;&lt;strong&gt;openSUSE&lt;/strong&gt;&lt;/a&gt; &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/thread/LQPMRQ5W3XJ7RWAQ6ITI4EY2EDVTVHKA/&quot;&gt;monthly update&lt;/a&gt; for their reproducibility work there.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;diffoscope-development&quot;&gt;&lt;em&gt;diffoscope&lt;/em&gt; development&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://diffoscope.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/diffoscope.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://diffoscope.org&quot;&gt;&lt;strong&gt;diffoscope&lt;/strong&gt;&lt;/a&gt; is our in-depth and content-aware diff utility that can locate and diagnose reproducibility issues. This month, Chris Lamb made the following changes, including preparing and uploading versions &lt;a href=&quot;https://tracker.debian.org/news/1762589/accepted-diffoscope-319-source-into-unstable/&quot;&gt;319&lt;/a&gt;, &lt;a href=&quot;https://tracker.debian.org/news/1764827/accepted-diffoscope-320-source-into-unstable/&quot;&gt;320&lt;/a&gt;, &lt;a href=&quot;https://tracker.debian.org/news/1764860/accepted-diffoscope-321-source-into-unstable/&quot;&gt;321&lt;/a&gt;, &lt;a href=&quot;https://tracker.debian.org/news/1767978/accepted-diffoscope-322-source-into-unstable/&quot;&gt;322&lt;/a&gt; and &lt;a href=&quot;https://tracker.debian.org/news/1769647/accepted-diffoscope-323-source-into-unstable/&quot;&gt;323&lt;/a&gt; to Debian:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Debian adds an extra &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Flags:&lt;/code&gt; line in the output of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ocamlobjinfo&lt;/code&gt;, so adjust the test for cross-distribution compatibility. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/3a2303e5&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Bump debhelper compatibility level to 14. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/ae1d587a&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Fix compatibility with Ocaml 5.4.1. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/50476c66&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--long-form&lt;/code&gt;-style arguments when calling &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;apktool&lt;/code&gt; in order to support &lt;em&gt;apktool&lt;/em&gt; version 3. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/02c65572&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Support Androguard version 4 and previous versions at the same time. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/2b17885b&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Update copyright years. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/bf7aa877&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In addition, Jochen Sprickerhof added better header detection for the &lt;a href=&quot;https://www.sphinx-doc.org/en/master/&quot;&gt;Sphinx documentation system&lt;/a&gt; [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/b800d697&quot;&gt;…&lt;/a&gt;], Michael Daniels fixed the tests when run with &lt;em&gt;zipdetails&lt;/em&gt; version 4.006 [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/fade8d04&quot;&gt;…&lt;/a&gt;] and Zbigniew Jędrzejewski-Szmek added a version of the deprecated &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;os.path.commonprefix&lt;/code&gt; method [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/2af9e134&quot;&gt;…&lt;/a&gt;].&lt;/p&gt;

&lt;p&gt;In addition, Vagrant Cascadian &lt;a href=&quot;https://codeberg.org/guix/guix/commit/43f80a83c99f7e3bf82cc27c5a95b9aead659ee6&quot;&gt;updated &lt;em&gt;diffoscope&lt;/em&gt; in GNU Guix to version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;321&lt;/code&gt;&lt;/a&gt; and &lt;a href=&quot;https://codeberg.org/guix/guix/commit/636a104836fe00fca5844e15e3c40c9cf5cd1427&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;323&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Chris Lamb also made the following changes to &lt;em&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/strip-nondeterminism&quot;&gt;strip-nondeterminism&lt;/a&gt;&lt;/em&gt;, our tool to remove specific non-deterministic results from a completed build:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Skip symlinks when manually called via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/usr/bin/strip-nondeterminism&lt;/code&gt;. (&lt;a href=&quot;https://bugs.debian.org/1139000&quot;&gt;#1139000&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;Update &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;debian/watch&lt;/code&gt; format. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/strip-nondeterminism/commit/9042813&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Drop &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Rules-Requires-Root: no&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Priority: optional&lt;/code&gt; fields. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/strip-nondeterminism/commit/7399bc4&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Bump &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Standards-Version&lt;/code&gt; to version 4.7.4. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/strip-nondeterminism/commit/aa3e692&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;from-our-mailing-list&quot;&gt;From our mailing list…&lt;/h3&gt;

&lt;p&gt;On &lt;a href=&quot;https://lists.reproducible-builds.org/listinfo/rb-general/&quot;&gt;our mailing list&lt;/a&gt; this month:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;em&gt;kpcyrd&lt;/em&gt; posted to our mailing list regarding the “waves of malware uploads to &lt;a href=&quot;https://aur.archlinux.org/&quot;&gt;aur.archlinux.org&lt;/a&gt;”. Curiously, “every incident I looked at used npmjs.com for malware delivery”, specifically where the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;npm&lt;/code&gt; package includes an (automatically executed) &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;preinstall&lt;/code&gt; script that is an ELF binary.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;em&gt;kpcyrd&lt;/em&gt; also announced the release of &lt;a href=&quot;https://github.com/kpcyrd/debian-repro-status&quot;&gt;&lt;em&gt;debian-repro-status&lt;/em&gt;&lt;/a&gt; version &lt;a href=&quot;https://github.com/kpcyrd/debian-repro-status/releases/tag/v0.4.0&quot;&gt;0.4.0&lt;/a&gt;, a tool written “to give you an approximate idea of how viable it would be to enforce a ‘reproducible packages only’ update policy for the computer system you’ve built”:&lt;/p&gt;

    &lt;blockquote&gt;
      &lt;p&gt;The change updates dependencies to the latest versions, and adds support for multiple &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-H&lt;/code&gt; options, to query results from multiple rebuilderd instances. The results are also now fetched concurrently.&lt;/p&gt;
    &lt;/blockquote&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;em&gt;kpcyrd&lt;/em&gt; also reported that, whilst taking a screenshot for the above release, they noticed that the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;debian:sid&lt;/code&gt; &lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-June/004121.html&quot;&gt;container now is 100% reproducible&lt;/a&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Finally, &lt;em&gt;kpcyrd&lt;/em&gt; &lt;strong&gt;also&lt;/strong&gt; &lt;a href=&quot;https://github.com/keszybz/add-determinism/pull/78&quot;&gt;created a pull request&lt;/a&gt; against the &lt;a href=&quot;https://github.com/keszybz/add-determinism&quot;&gt;&lt;em&gt;add-determinism&lt;/em&gt;&lt;/a&gt; package to update the &lt;a href=&quot;https://docs.python.org/3/library/itertools.html&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;itertools&lt;/code&gt;&lt;/a&gt; and &lt;a href=&quot;https://docs.python.org/3/library/zipfile.html&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zip&lt;/code&gt;&lt;/a&gt; Python dependencies.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;documentation-updates&quot;&gt;Documentation updates&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://reproducible-builds.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/website.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Yet again, there were a number of improvements made to our website this month including:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Chris Lamb added a reminder re. using the UTC variants of the Javascript &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Date&lt;/code&gt; methods. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/27245b53&quot;&gt;…&lt;/a&gt;]&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mattia Rizzolo moved &lt;a href=&quot;https://www.opentech.fund/&quot;&gt;OTF&lt;/a&gt; to the ‘old’ sponsors list. Thank you for your support!. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/d029630d&quot;&gt;…&lt;/a&gt;]&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;em&gt;kpcyrd&lt;/em&gt; updated the &lt;a href=&quot;https://rust-lang.org/&quot;&gt;Rust&lt;/a&gt; documentation to recommend using the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--release&lt;/code&gt; argument for consistency. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/f5d645e5&quot;&gt;…&lt;/a&gt;]&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;patches&quot;&gt;Patches&lt;/h3&gt;

&lt;p&gt;The Reproducible Builds project detects, dissects and attempts to fix as many currently-unreproducible packages as possible. We endeavour to send all of our patches upstream where applicable or possible. This month, we wrote a large number of such patches, including:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Bernhard M. Wiedemann:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugzilla.opensuse.org/show_bug.cgi?id=1268265&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cvise&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1362390&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;efl&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugzilla.opensuse.org/show_bug.cgi?id=1268542&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gettext-runtime/bash&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugzilla.opensuse.org/show_bug.cgi?id=1268340&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hadrian&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1362888&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;plasma6-keyboard&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://invent.kde.org/frameworks/syntax-highlighting/-/merge_requests/806&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;syntax-highlighting&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Chris Lamb:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1139654&quot;&gt;#1139654&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/node-fuse.js&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;node-fuse.js&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1139655&quot;&gt;#1139655&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/node-egjs-hammerjs&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;node-egjs-hammerjs&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1139656&quot;&gt;#1139656&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/node-chartjs-adapter-date-fns&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;node-chartjs-adapter-date-fns&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1139662&quot;&gt;#1139662&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/mkdocs-include-markdown-plugin&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mkdocs-include-markdown-plugin&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1139704&quot;&gt;#1139704&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/lmarbles&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lmarbles&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140240&quot;&gt;#1140240&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/rocm-docs-core&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rocm-docs-core&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140567&quot;&gt;#1140567&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/libecoli&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libecoli&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140688&quot;&gt;#1140688&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/golang-github-tobischo-gokeepasslib&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;golang-github-tobischo-gokeepasslib&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Jochen Sprickerhof:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1139457&quot;&gt;#1139457&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/c-munipack&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;c-munipack&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140365&quot;&gt;#1140365&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/latex-coffee-stains&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;latex-coffee-stains&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140366&quot;&gt;#1140366&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/cxxtest&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cxxtest&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140367&quot;&gt;#1140367&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/slime&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;slime&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140368&quot;&gt;#1140368&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/spooles&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;spooles&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140369&quot;&gt;#1140369&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/sdpb&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sdpb&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140645&quot;&gt;#1140645&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/procmail&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;procmail&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140676&quot;&gt;#1140676&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/proftpd-dfsg&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;proftpd-dfsg&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141059&quot;&gt;#1141059&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/mah-jong&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mah-jong&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141133&quot;&gt;#1141133&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/dxf2gcode&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dxf2gcode&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141194&quot;&gt;#1141194&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/afterstep&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;afterstep&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141195&quot;&gt;#1141195&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/ledger2beancount&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ledger2beancount&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141196&quot;&gt;#1141196&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/ocamlviz&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ocamlviz&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Kris Van Hee and Vagrant Cascadian:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140167&quot;&gt;#1140167&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/dtrace&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dtrace&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;four-new-scholarly-papers&quot;&gt;Four new scholarly papers&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://lab.iisec.ac.jp/~suzaki_lab/PDF/DSN-HAP26_muto.pdf&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/DSN-HAP26_muto.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Kenichiro Muto and Kuniyasu Suzaki of the &lt;a href=&quot;https://www.iisec.ac.jp/english/&quot;&gt;Institute of Information Security&lt;/a&gt; in Yokohama, Japan published an interesting paper this month titled &lt;a href=&quot;https://lab.iisec.ac.jp/~suzaki_lab/PDF/DSN-HAP26_muto.pdf&quot;&gt;&lt;em&gt;Attestable Build Chain: Enabling Trust in Reproducible Builds&lt;/em&gt;&lt;/a&gt; (PDF). Their abstract is as follows:&lt;/p&gt;

&lt;p&gt;Ensuring trust in software supply chains requires verifying not only artifacts but also the processes that produce them. Although Reproducible Builds (R-B) require rebuilding to validate artifacts, they cannot verify whether the build was executed with the intended toolchain and inputs and may reproduce unintended or compromised builds without detection. We present Attestable Build Chain, a framework for externally verifying build-time execution without rebuilding. Rather than preventing compromise, it provides verifiable, tamper-evident evidence of actual build-time execution, enabling verification of build process integrity from observed file accesses during the build. [&lt;a href=&quot;https://lab.iisec.ac.jp/~suzaki_lab/PDF/DSN-HAP26_muto.pdf&quot;&gt;…&lt;/a&gt;]&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://hal.science/hal-05630285v1&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/2025-nixpkgs-reproducibility-extended.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Julien Malka, Stefano Zacchiroli and Théo Zimmermann published a 50-page report detailing &lt;a href=&quot;https://hal.science/hal-05630285v1&quot;&gt;&lt;em&gt;A Decade of Software Reproducibility in the Nix Package Ecosystem&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;We find that functional package management enables extremely high rebuildability over time (&lt;strong&gt;near-universal ability to reconstitute historical build environments and rebuild software packages&lt;/strong&gt;), while bitwise reproducibility has steadily improved and reaches a high point in recent years (up to 93% in 2024). Early years show substantially lower bitwise reproducibility, indicating that functional package management alone does not guarantee bitwise-identical outputs, and that the observed high level of bitwise reproducibility is not solely due to the package management approach. Common causes of unreproducibility, both in the rebuildability and bitwise reproducibility dimensions, include management of dates in build and test processes; we quantify their prevalence and other common causes using manual analysis of logs of rebuild failures and automated analysis of &lt;a href=&quot;https://diffoscope.org/&quot;&gt;&lt;em&gt;diffoscope&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A &lt;a href=&quot;https://hal.science/hal-05630285v1/file/2025-nixpkgs-reproducibility-extended.pdf&quot;&gt;PDF of their report&lt;/a&gt; is available online&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://devguard.org/research-development/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.pdf&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Tim Bastin of &lt;a href=&quot;https://l3montree.com/&quot;&gt;L3montree GmbH&lt;/a&gt; and Jacek Galowicz of &lt;a href=&quot;https://applicative.systems/&quot;&gt;Applicative Systems GmbH&lt;/a&gt; from &lt;a href=&quot;https://devguard.org/&quot;&gt;DevGuard&lt;/a&gt; published a paper detailing &lt;a href=&quot;https://devguard.org/research-development/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.pdf&quot;&gt;&lt;em&gt;How We Built a Sovereign, Reproducible Container Supply Chain for DevGuard&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;This paper presents how the &lt;a href=&quot;https://devguard.org/&quot;&gt;DevGuard&lt;/a&gt; project rebuilt its &lt;a href=&quot;https://opencontainers.org/&quot;&gt;OCI container&lt;/a&gt; pipeline around reproducible &lt;a href=&quot;https://nixos.org/&quot;&gt;Nix&lt;/a&gt; builds and independent dual-platform digest verification. DevGuard images are built hermetically from pinned source revisions, signed with &lt;a href=&quot;https://github.com/sigstore/cosign&quot;&gt;Sigstore/Cosign&lt;/a&gt;, and verified through digest comparison across GitHub Actions and sovereign GitLab infrastructure hosted on container.gov.de. We describe the practical integration of reproducible OCI image builds into existing CI/CD workflows and argue that independently reproducible container digests provide a stronger integrity guarantee against build tampering than provenance alone. The paper further discusses remaining trust assumptions and the relevance of sovereign build infrastructure for government and regulated environments.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://www.sciencedirect.com/science/article/pii/S2405959526001086&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-06/1-s2.0-S2405959526001086-main.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Finally, Yiseul Choi, Junga Kim, Jun-Ho Hong and Seongmin Kim of the &lt;a href=&quot;https://www.sungshin.ac.kr/main_eng/15348/subview.do&quot;&gt;Department of Convergence Security Engineering&lt;/a&gt; at the &lt;a href=&quot;https://www.sungshin.ac.kr/&quot;&gt;Sungshin Women’s University&lt;/a&gt; in Seoul, Korea titled &lt;a href=&quot;https://www.sciencedirect.com/science/article/pii/S2405959526001086&quot;&gt;&lt;em&gt;Attestation-based verification of SBOM integrity via consumer-side reproducibility&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Software bills of materials (SBOMs) support supply chain transparency, but they do not prove that a delivered SBOM reproducibly corresponds to its software artifact. Existing signing and provenance mechanisms protect integrity and traceability, yet lack consumer-side reproducible verification. We propose an SBOM integrity verification framework combining procedure disclosure, consumer-side reproduction, authority-generated reference evidence, and digest comparison. A trusted authority records a reference digest, and consumers compare it with locally reproduced and delivered SBOM digests. Experiments on 100 real-world container images show detection of artifact tampering, SBOM substitution, distribution modification, and adaptive tampering beyond signature-based approaches&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Finally, if you are interested in contributing to the Reproducible Builds project, please visit our &lt;a href=&quot;https://reproducible-builds.org/contribute/&quot;&gt;&lt;em&gt;Contribute&lt;/em&gt;&lt;/a&gt; page on our website. However, you can get in touch with us via:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;IRC: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;#reproducible-builds&lt;/code&gt; on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;irc.oftc.net&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mastodon: &lt;a href=&quot;https://fosstodon.org/@reproducible_builds&quot;&gt;@reproducible_builds@fosstodon.org&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mailing list: &lt;a href=&quot;https://lists.reproducible-builds.org/listinfo/rb-general&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rb-general@lists.reproducible-builds.org&lt;/code&gt;&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-11T19:27:22+00:00</dc:date>
	<dc:creator>Reproducible Builds</dc:creator>
</item> 
<item rdf:about="https://current.workingdirectory.net/posts/2026/dns-high-availability/">
	<title>Jamie McClelland: DNS, OG of high availability</title>
	<link>https://current.workingdirectory.net/posts/2026/dns-high-availability/</link>
     <content:encoded>&lt;p&gt;At &lt;a href=&quot;https://mayfirst.coop&quot;&gt;May First&lt;/a&gt;, we recently received (all within a
single week) three different complaints about domain names that previously
worked fine suddenly not resolving to our servers.&lt;/p&gt;
&lt;p&gt;While that isn’t terribly uncommon, we discovered that in each case, the domain
name’s authoritative name servers were pointing to our mail servers
(&lt;code&gt;a.mx.mayfirst.org&lt;/code&gt;, &lt;code&gt;b.mx.mayfirst.org&lt;/code&gt; and &lt;code&gt;c.mx.mayfirst.org&lt;/code&gt;) instead of
our name servers (&lt;code&gt;a.ns.mayfirst.org&lt;/code&gt;, &lt;code&gt;b.ns.mayfirst.org&lt;/code&gt; and
&lt;code&gt;c.ns.mayfirst.org&lt;/code&gt;). The weird part: this mistaken configuration was happening
at the registrar level, protected by each member’s own credentials that we
don’t have access to.&lt;/p&gt;
&lt;p&gt;Each affected member fixed their records to resolve the problem but also made
very clear that they had not logged into their registrar in years, sugggesting
that the DNS authoritative records in their registrar accounts spontaneously
changed on their own. The first time was weird, the second time could possibly
be a coincidence? But by the third time this happened, we started to panic.
&lt;em&gt;How could registrar records spontaneously change?&lt;/em&gt; All three domain names were
registered with different companies - so it couldn’t be a single registrar
problem? Are we going to get a flood of these complaints? What is going on!?!?&lt;/p&gt;
&lt;p&gt;We did an inventory to see if this was happening with other domain names in use
by our membership and that’s when we discovered just how hard it is for our
mostly non-technical users to set a domain’s authoritative name servers. The
error rate was less than 1% but still that was a lot of domain names with
typos:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;raise your fist in the air with &lt;code&gt;a.ns.mayfist.org&lt;/code&gt;!&lt;/li&gt;
&lt;li&gt;or just plain give up and hit the floor with &lt;code&gt;a.ns.matfirst.org&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Or more commonly people added our name servers, but also left the default
name servers in place.&lt;/li&gt;
&lt;li&gt;Also, one person added as their authoritative name servers:
&lt;code&gt;a.ns.mayfirst.org&lt;/code&gt;, &lt;code&gt;b.ns.mayfirst.org&lt;/code&gt;, &lt;code&gt;c.ns.mayfirst.org&lt;/code&gt;,
&lt;code&gt;a.mx.mayfirst.org&lt;/code&gt;, &lt;code&gt;b.mx.mayfirst.org&lt;/code&gt;, &lt;code&gt;c.mx.mayfirst.org&lt;/code&gt;, and even
&lt;code&gt;a.webproxy.mayfirst.org&lt;/code&gt; - in other words, all the domain names we tell you
do to anything with.&lt;/li&gt;
&lt;li&gt;And lastly, I did find two more domains just pointing to
&lt;code&gt;a.mx.mayfirst.org&lt;/code&gt;, &lt;code&gt;b.mx.mayfirst.org&lt;/code&gt; and &lt;code&gt;c.mx.mayfirst.org&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That’s when it occurred to me: for years we have maintained an offsite server
that provides &lt;em&gt;both&lt;/em&gt; &lt;code&gt;c.ns.mayfirst.org&lt;/code&gt; and &lt;code&gt;c.mx.mayfirst.org&lt;/code&gt;. It hangs out
in case something terrible happens to our main colo. The week before we started
receiving these complaints, I separated these services, moving
&lt;code&gt;c.mx.mayfirst.org&lt;/code&gt; to a dedicated MX server. As a result, these two domain
names stopped pointing to the same IP address. And that’s when the complaints
started rolling in. In other words: the affected members set the incorrect name
servers years ago, but because just one of the name servers resolved to an IP
that happened to provide the correct authoritative lookup services, it went
undeteced all this time.&lt;/p&gt;
&lt;p&gt;So… mystery solved. Nobody’s authoritative registrar records “suddenly”
changed. They were mis-configured for years but &lt;em&gt;thanks to the amazing
resilience of the DNS system, nobody noticed because just one working DNS
server is all you need.&lt;/em&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-11T12:27:10+00:00</dc:date>
	<dc:creator>Jamie McClelland</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/fly30/">
	<title>Jonathan Dowland: Bauer Fly30 ice skates</title>
	<link>https://jmtd.net/log/fly30/</link>
     <content:encoded>&lt;p&gt;I used to ice skate as a teenager but I stopped at University. I tried to
pick it back up in 2024 but had to stop when I got &lt;a href=&quot;https://jmtd.net/log/ouch/&quot;&gt;ill&lt;/a&gt;. I restarted
in 2025, initially with a weekly skate session but last month I started group
hockey skate lessons.&lt;/p&gt;

&lt;div class=&quot;centre&quot;&gt;
&lt;div class=&quot;image+centre&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/fly30/heat.jpg&quot;&gt;&lt;img alt=&quot;IR photo of me skating&quot; class=&quot;img&quot; height=&quot;378&quot; src=&quot;https://jmtd.net/log/fly30/400x-heat.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;

&lt;p&gt;&lt;/p&gt;&lt;p&gt;There&#39;s not a lot of pics of me skating…
this one from an IR camera&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;I&#39;ve been skating in a pair of Bauer&lt;sup id=&quot;fnref:1&quot;&gt;&lt;a href=&quot;https://jmtd.net/log/#fn:1&quot; rel=&quot;footnote&quot;&gt;1&lt;/a&gt;&lt;/sup&gt; Nexus N77s that I bought &lt;a href=&quot;https://jmtd.net/log/Toronto/&quot;&gt;7 years
ago on a work trip to Toronto&lt;/a&gt;.
These did a great job of getting me back into the hobby for 6 years but
recently I felt it was time to step up to a better quality pair.
Despite being a size down from my shoe size, the Nexuses are too
large: I had been compensating with thick socks but still struggling to
get the boots tight enough. I&#39;d have to wear gloves to lace up because I&#39;d
cut my hands pulling the laces otherwise.&lt;/p&gt;

&lt;p&gt;After too long researching/deliberating/kvetching (very much on trend for me)
I upgraded to Bauer Vapor Fly30s another half-size down (and nearly ten times
as much).
The fit is &lt;em&gt;much&lt;/em&gt; better, in almost every respect. They actually go on easier
and I don&#39;t have to tear my hands tightening the laces. They feel like a natural
extension of my feet. I seem to be using a different set of muscles to skate,
so the first few sessions were very fatiguing, but that settled.
The Vapor line is speed-oriented, which I thought would fit my skate style best.&lt;/p&gt;

&lt;div class=&quot;centre&quot;&gt;
&lt;div class=&quot;image+centre&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/fly30/skates.jpg&quot;&gt;&lt;img alt=&quot;new and old skates&quot; class=&quot;img&quot; height=&quot;225&quot; src=&quot;https://jmtd.net/log/fly30/400x-skates.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;

&lt;p&gt;new and old skates&lt;/p&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;I have unfortunately gained a common problem: arch pain. More precisely, my
navicular bone seems to be quite prominent&lt;sup id=&quot;fnref:2&quot;&gt;&lt;a href=&quot;https://jmtd.net/log/#fn:2&quot; rel=&quot;footnote&quot;&gt;2&lt;/a&gt;&lt;/sup&gt;, and that part is
pressing uncomfortably into the boot. Boots typically take a few sessions to
break in, but after 7-8 sessions the pain was getting to the stage that I
couldn&#39;t skate for a full session without being in agony.&lt;/p&gt;

&lt;p&gt;The last time I skated I tried to throw everything at the problem: I&#39;d had
the skates baked&lt;sup id=&quot;fnref:3&quot;&gt;&lt;a href=&quot;https://jmtd.net/log/#fn:3&quot; rel=&quot;footnote&quot;&gt;3&lt;/a&gt;&lt;/sup&gt;; bought some orthotic insoles; then some &quot;Bunga&quot; pads over the sore bit and an
attempt to more loosely tie the laces over the affected area. I tried a ten
minute skate, and it &lt;em&gt;seemed&lt;/em&gt; a bit better.&lt;/p&gt;

&lt;p&gt;I then tried experimentally to swap back to my old skates, and I felt like
Bambi: I just couldn&#39;t do it!
They didn&#39;t press on the navicular, and they&#39;re
softer so you &lt;em&gt;can&lt;/em&gt; compensate for the size with tight lacing, but I had no
confidence in them, I couldn&#39;t lean into the turns. They just felt &lt;em&gt;weird&lt;/em&gt;.
I realised there&#39;s no way back.&lt;/p&gt;

&lt;p&gt;I switched back to the fly30s, adjusted the bunga pad positioning, tweaked
the lacing and went back on for about 40 minutes. It went well: the rink was
quiet, it was cool whilst we had a heat wave outside, so I worked up a sweat.
By the end there was &lt;em&gt;some&lt;/em&gt; discomfort, but not too much, and I think partly
the area is currently sensitive so just about anything will cause discomfort.
Fingers (or toes) crossed that I&#39;ve mitigated the problem! If not, it might
be time to try a &lt;em&gt;punch out&lt;/em&gt;.&lt;/p&gt;
&lt;div class=&quot;footnotes&quot;&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id=&quot;fn:1&quot;&gt;
I&#39;ve owned four pairs of skates: all hockey, my first were Bauers,
my second CCM Tacks of some kind. I&#39;ve no idea what happened to them.&lt;a href=&quot;https://jmtd.net/log/#fnref:1&quot; rev=&quot;footnote&quot;&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn:2&quot;&gt;
Or possibly I have &lt;em&gt;accessory navicular&lt;/em&gt; bones&lt;a href=&quot;https://jmtd.net/log/#fnref:2&quot; rev=&quot;footnote&quot;&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn:3&quot;&gt;
modern mid-tier skates are thermoformable, and many skate shops carry
a specially designed oven to briefly bake skates such that you wear them as
they cool and the padding should mould to your foot.&lt;a href=&quot;https://jmtd.net/log/#fnref:3&quot; rev=&quot;footnote&quot;&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-10T20:57:20+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="https://retout.co.uk/2026/07/10/blocking-distracting-news-links/">
	<title>Tim Retout: Blocking distracting news links</title>
	<link>https://retout.co.uk/2026/07/10/blocking-distracting-news-links/</link>
     <content:encoded>&lt;p&gt;&lt;em&gt;“You are what you eat”&lt;/em&gt; – but perhaps this is even more true of our
information diet.  It is hard to strike a balance between remaining a
well-informed citizen versus spending hours ingesting unnecessary news
about issues and events we can’t affect.  But I’m increasingly
convinced that my hours lost to doomscrolling are down to design
choices by web publishers rather than a failure of individual
willpower.&lt;/p&gt;
&lt;h3 id=&quot;we-have-created-an-obesogenic-information-environment&quot;&gt;We have created an “obesogenic” information environment&lt;/h3&gt;
&lt;p&gt;I don’t think it is just me – I think our information environment has
been progressively altered over time as news sites look to maximize
engagement.  Even outside of social media, the invisible hand of the
market for eyeballs forces sites to optimize for browse time or risk
irrelevance.&lt;/p&gt;
&lt;p&gt;Even as newspapers find it increasingly difficult to fund good
journalism through advertising in an online world, especially local
journalism, they need to keep readers on their sites, clicking through
as many articles as possible. Clickbait headlines, “urgent” flashing
live icons to draw the attention, and many opportunities to leap from
one article to another, and another.&lt;/p&gt;
&lt;p&gt;But this design approach even extends to news organisations with a
different funding model, like BBC News, which is a public service
(state-owned but arms-length) organisation funded through a mandatory
television licence – a matter of controversy in some quarters.  And
it extends even to sites where I pay a subscription fee; I might get
adverts removed, but I am still bombarded with the same design
philosophy; too many opportunities to be pulled away from what I’m
reading towards some other unrelated article.&lt;/p&gt;
&lt;p&gt;Even if I try and limit my exposure to algorithmic “discovery” of new
news, via RSS feeds or similar, if I’m reading the full article in a
browser then I am prompted to read more stuff that I didn’t intend.
This defeats the benefit of curating a set of feeds, because you still
get dragged away to random articles.&lt;/p&gt;
&lt;h3 id=&quot;only-44-of-bbc-news-is-news&quot;&gt;Only 44% of BBC News is news&lt;/h3&gt;
&lt;p&gt;To show you what I mean, I’m going to pick on the BBC, although I
love them dearly and the same issue very much applies elsewhere.&lt;/p&gt;
&lt;p&gt;I’ve taken a screenshot of a &lt;a href=&quot;https://www.bbc.co.uk/news/articles/cly9r54e5r4o&quot;&gt;random BBC News
article&lt;/a&gt; in mobile
view (my preferred doomscrolling user access device), and measured
approximately what proportion of the full length of the page is taken
up by each section.  This is a fairly in-depth news article, so I
reckon if anything the figures would be worse than this on shorter
articles.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;A full-length screenshot of a BBC News article showing proportions of the page allocated to the main article vs. related links etc.&quot; src=&quot;https://retout.co.uk/2026/bbc-news-website.drawio.svg&quot; /&gt;&lt;/p&gt;
&lt;p&gt;(These numbers will not sum to 100% for reasons which are obvious if
you look at the crossbars.  Also they’re approximations.)&lt;/p&gt;
&lt;p&gt;Less than half of the page (44% if you exclude the inline related
links) is actual news text/images; the rest are links trying to help
you find the next thing to read/watch. &lt;em&gt;I do not want this.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I’m sure this A/B tests well in terms of reader figures, but it
sometimes leaves me exhausted – it must take subconscious mental
energy to ignore, or I spend too much time trying to keep on top of
things.&lt;/p&gt;
&lt;p&gt;And remember, this is a publicly-funded site that does not rely on
advertising!&lt;/p&gt;
&lt;h3 id=&quot;blocking-out-the-noise&quot;&gt;Blocking out the noise&lt;/h3&gt;
&lt;p&gt;If you are technically-minded, you can use an ad-blocker such as
uBlock Origin to take back some control.  Applying the following lines
as a custom filter (Settings &amp;gt; My filters) brutally cuts out almost
all of these links:&lt;/p&gt;
&lt;div class=&quot;code-block-wrapper&quot;&gt;&lt;pre tabindex=&quot;0&quot;&gt;&lt;code&gt;bbc.co.uk##aside
bbc.co.uk##footer&amp;gt;div:has(h2)
bbc.co.uk##[data-block=&quot;uploaderEmbed&quot;]
bbc.co.uk##[data-block=&quot;links&quot;]&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;em&gt;Caveat emptor:&lt;/em&gt; I have not road-tested this for more than half an
hour, so who knows what consequences this could have on your web
browsing.  In particular, international readers outside the UK will
likely be redirected to bbc.com, the commercial arm of the BBC, where
these rules will need adapting.&lt;/p&gt;
&lt;p&gt;Is it unethical to use an ad-blocker to remove these links?  I would
argue not.  I am not depriving the BBC of any revenue, because I pay
my licence fee.  I might reduce the amount of time I spend on their
website, but if anything the subjectively better experience might
encourage me to consume more news from them, not less.  In other
circumstances (outside the UK for instance, where the BBC relies on
advertising), the balance might be different.&lt;/p&gt;
&lt;h3 id=&quot;product-managers-please-find-better-metrics&quot;&gt;Product managers, please find better metrics&lt;/h3&gt;
&lt;p&gt;I lament the state of the internet in 2026.  I now can’t unsee these
innocuous “related stories” links as a mechanism to grab my attention,
and it’s gone too far.&lt;/p&gt;
&lt;p&gt;If you are a normal person just browsing the news and looking to
discover the latest important stories relatively quickly, I can see
that these types of links might actually be useful for discovery; but
I’m actually reasonably sure that I’m not going to miss out on
anything major.  You still have the option of the news home page if
you want to be presented with more news for example, and it feels
natural to go back to there when you’ve run out of stories to consume.&lt;/p&gt;
&lt;p&gt;But it shouldn’t be down to individual responsibility to ignore or
geekily block these types of link; news sites with alternative funding
models should find better metrics for engagement than “hours spent on
site” – how about optimizing for customer mental wellbeing, or
minimizing time required to catch up with the news?  There’s no need
to maximize clicks and eyeballs.  This is a societal level issue,
because we are all going mad with news over-engagement.&lt;/p&gt;
&lt;p&gt;Product managers, over to you.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-10T15:00:00+00:00</dc:date>
	<dc:creator>Tim Retout</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-07-10:/2026/07/new-developers-2026-07.html">
	<title>Bits from Debian: New Debian Developers and Maintainers (May and June 2026)</title>
	<link>https://bits.debian.org/2026/07/new-developers-2026-07.html</link>
     <content:encoded>&lt;p&gt;The following contributors got their Debian Developer accounts in the last two
months:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Vivek K J (vivek)&lt;/li&gt;
&lt;li&gt;Benjamin Somers (bensmrs)&lt;/li&gt;
&lt;li&gt;Colin King (colinianking)&lt;/li&gt;
&lt;li&gt;Nadzeya Hutsko (nadzeya)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The following contributors were added as Debian Maintainers in the last two
months:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pieter Lenaerts&lt;/li&gt;
&lt;li&gt;Syed Shahrukh Hussain&lt;/li&gt;
&lt;li&gt;Ural Tunaboyu&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Congratulations!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-10T07:00:00+00:00</dc:date>
	<dc:creator>Jean-Pierre Giraud</dc:creator>
</item> 
<item rdf:about="https://diffoscope.org/news/diffoscope-324-released/">
	<title>Reproducible Builds (diffoscope): diffoscope 324 released</title>
	<link>https://diffoscope.org/news/diffoscope-324-released/</link>
     <content:encoded>&lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;324&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[ Paul Spooren ]
* Allow trailing garbage in Gzip files.

[ Chris Lamb ]
* Bump debhelper compatibility level to 14.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href=&quot;https://diffoscope.org&quot;&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-10T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds (diffoscope)</dc:creator>
</item> 
<item rdf:about="https://blog.trueelena.org/blog/2026/07/10-cockades/index.html">
	<title>Valhalla&#39;s Things: Cockades!</title>
	<link>https://blog.trueelena.org/blog/2026/07/10-cockades/index.html</link>
     <content:encoded>&lt;article&gt;
    &lt;section class=&quot;header&quot;&gt;
        Posted on July 10, 2026
        &lt;br /&gt;
        
        Tags: &lt;a href=&quot;https://blog.trueelena.org/tags/madeof%3Aatoms.html&quot; title=&quot;All pages tagged &#39;madeof:atoms&#39;.&quot;&gt;madeof:atoms&lt;/a&gt;, &lt;a href=&quot;https://blog.trueelena.org/tags/FreeSoftWear.html&quot; title=&quot;All pages tagged &#39;FreeSoftWear&#39;.&quot;&gt;FreeSoftWear&lt;/a&gt;, &lt;a href=&quot;https://blog.trueelena.org/tags/craft%3Asewing.html&quot; title=&quot;All pages tagged &#39;craft:sewing&#39;.&quot;&gt;craft:sewing&lt;/a&gt;
        
    &lt;/section&gt;
    &lt;section&gt;
        &lt;p&gt;&lt;img alt=&quot;six cockades in black, grey, white, purple, in different sizes and with different centrepieces. One is only black and white and has a penguin pin in the middle.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/10-cockades/pile_of_cockades.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Earlier this year, I made myself a new hat (it will be blogged), and I
wanted to put a nice cockade on it.
So, I looked for suitable ribbons, and couldn’t find any.
I found some ribbon that looked passable, but the colours I wanted
weren’t available, so I set up the website to notify me, and kept
working on the hat.&lt;/p&gt;
&lt;p&gt;Eventually the hat was done, the ribbon was still not available, so I
decorated the hat with fake flowers from my stash, and started wearing
it.&lt;/p&gt;
&lt;p&gt;And that’s when I got notified that the ribbon was back in stock.&lt;/p&gt;
&lt;p&gt;By the time the ribbon arrived, I had decided that the hat looked better
with the flowers, and project cockade was put on hold, possibly for a
future hat.&lt;/p&gt;
&lt;p&gt;And then June came, and what could be a better time than that for a
project based on flag colours?&lt;/p&gt;
&lt;p&gt;As I feared, the ribbon I got wasn’t the best: it was a bit too stiff
and plasticy, and not really usable for many other things. It did
however work well enough for a cockade, and I decided it was a good
chance to try different methods and designs, and then make another one
to take pictures and publish step-by-step instructions.&lt;/p&gt;
&lt;p&gt;And that’s the perfect recipe to find oneself surrounded by a somewhat
unreasonable number of very similar cockades, I guess.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;A big cockade with four ribbons, starting with purple on the outside, and a black bead in the middle covering the centre of the black ribbon. The pleating isn&#39;t the most regular, and the black ribbon at the centre is almost more gathered than pleated.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/10-cockades/number_one.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I looked around for instructions, and the ones that gave a result that
was closer to my mental idea of a cockade were the ones by &lt;a href=&quot;https://blog.americanduchess.com/2010/04/how-to-make-18th-c-cockades.html&quot;&gt;American
Duchess&lt;/a&gt;,
so on my first attempt I tried to follow those.&lt;/p&gt;
&lt;p&gt;I didn’t have a cork board with a hole, so it was a bit fiddly, and the
result was passable, but could have been better. Meanwhile I saw &lt;a href=&quot;https://www.authentic-campaigner.com/forum/military-forums/camp-of-instruction/18697-easy-to-make-cockades#post163741&quot;&gt;a
forum post commenting on the above tutorial&lt;/a&gt;
and that gave me ideas for a procedure more suitable to the tools I had.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;A cockade with tree ribbons, starting with purple on the outside, then white, grey, and a black bead in the middle that is a bit bigger than the one on the previous one. The pleating isn&#39;t perfect, but neater than the previous one.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/10-cockades/number_two.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The second cockade I made was indeed more satisfactory, and I also
started to experiment with making a center piece with ribbons, to cut
down on the types of materials needed.&lt;/p&gt;
&lt;p&gt;On this one I also tried to add a pin backing, so that I could write
instructions on how to do it in what I believe is a more stable way than
simply adding it to the felt backing at the end.&lt;/p&gt;
&lt;p&gt;I’m not sure whether the other ones will be tacked to a hat, and thus
won’t require pins at all, or if I’ll just put them on some dress with
pins hidden under the ribbon layers.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;A cockade with three ribbons, starting with black on the outside, then grey and white, and a flat pentagonal knot of purple ribbon at the centre.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/10-cockades/number_tree.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;And then I was ready to make a third cockade, taking step by step
pictures for my website, and I planned to start on it the next morning.&lt;/p&gt;
&lt;p&gt;Trenord had different ideas.&lt;/p&gt;
&lt;p&gt;Thanks to the combination of independent but complete disruptions on
&lt;em&gt;two&lt;/em&gt; nearby train lines, I spent the morning driving a couple of people
to the nearest station that was still being served by trains, and then
back home less than 10 minutes before I had to start working, which if
you ask&lt;a class=&quot;footnote-ref&quot; href=&quot;https://blog.trueelena.org#fn1&quot; id=&quot;fnref1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; me was pretty homophobic of the train company.&lt;/p&gt;
&lt;p&gt;There was way less traffic than I expected, and I did enjoy the drive
&lt;a class=&quot;footnote-ref&quot; href=&quot;https://blog.trueelena.org#fn2&quot; id=&quot;fnref2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt;, but for various reasons it meant a significant delay for this
post.&lt;/p&gt;
&lt;p&gt;Anyway, less than a week later than I had planned, halfway in June I
managed to publish &lt;a href=&quot;https://sewing-patterns.trueelena.org/accessories/decorations/multi_colour_cockade/index.html&quot;&gt;step by step instructions on my website&lt;/a&gt;, but I wasn’t done with the project yet.&lt;/p&gt;
&lt;p&gt;Beside the fact that I still needed to finish sewing the backing felt to
the cockades I had done, I also had a few ideas for more centrepieces
made of ribbon I wanted to try.&lt;/p&gt;
&lt;p&gt;And this means that I moved on to another project that was already in
progress (this one will also be blogged).&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;A cockade with three ribbons, starting with black on the outside, then grey and white, and two squares of purple ribbon at the centre, forming a sort of eight point star. The ribbons are box pleated and this gives the cockade a bit more of a tree-dimensional shape.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/10-cockades/number_four.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;After I’ve finished that one, at the very end of June I quickly made the
last two centrepieces, taking pictures for the instructions, and in the
next few days I also finished the cockades.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;A cockade with three ribbons, starting with purple on the outside, then white and grey, and an hexagonal shape made of black ribbon at the centre. The ribbons are again box pleated.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/10-cockades/number_five.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This time, instead of plain pleats I tried to use box pleats, and I
quite like the look they give, so if in the future I’ll have a need for
more cockades I may use again this pleating pattern.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;A cockade with just two gathered ribbons, starting with black on the outside, then white, and a linux.it pin in the middle with a black background and two eyes and an orange beak reminding of a penguin.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/10-cockades/number_six.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;For the last cockade I wanted to try two things: putting a pin in the
middle as a centrepiece, and gathering the ribbons.&lt;/p&gt;
&lt;p&gt;For the pin, I found that the only one I had that had a colour scheme
compatible with the ribbons I had was one with the penguin from
linux.it, which had a black background, so I put black ribbon on the
outside and white next to it for contrast.&lt;/p&gt;
&lt;p&gt;And gathering was done with a whipped gather with ribbons that were one
and a half times the outer circumference of their slot, and looks decent
enough, but I think I prefer the look of pleated cockades a lot. Maybe
it would look better with a softer ribbon.&lt;/p&gt;
&lt;p&gt;Anyway, I think this is plenty of cockades for the time being, unless I
get tempted by buying more colours of ribbon to make different ones. But
I’m not making an online purchase just for those. &lt;em&gt;I&lt;/em&gt; &lt;em&gt;am&lt;/em&gt; &lt;em&gt;not&lt;/em&gt;.&lt;/p&gt;
&lt;section class=&quot;footnotes footnotes-end-of-document&quot;&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id=&quot;fn1&quot;&gt;&lt;p&gt;you probably shouldn’t.&lt;a class=&quot;footnote-back&quot; href=&quot;https://blog.trueelena.org#fnref1&quot;&gt;↩︎&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li id=&quot;fn2&quot;&gt;&lt;p&gt;also thanks to my partner who, on entering the destination
town, told me to stop on the big, straight, two-way road with plenty
of roundabouts to turn around, and went through the maze of one-way
streets to the station by foot.&lt;a class=&quot;footnote-back&quot; href=&quot;https://blog.trueelena.org#fnref2&quot;&gt;↩︎&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/section&gt;
    &lt;/section&gt;
&lt;/article&gt;</content:encoded> 
	<dc:date>2026-07-10T00:00:00+00:00</dc:date>
	<dc:creator>Elena “of Valhalla”</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/synths/minilogue-xd/module/">
	<title>Jonathan Dowland: Korg Minilogue XD Desktop Module</title>
	<link>https://jmtd.net/log/synths/minilogue-xd/module/</link>
     <content:encoded>&lt;p&gt;I bought a new synth! Kind-of.&lt;/p&gt;

&lt;p&gt;I&#39;ve traded my &lt;a href=&quot;https://jmtd.net/log/synths/minilogue-xd/&quot;&gt;Minilogue-XD&lt;/a&gt; (full-size version with integrated keyboard) for
the desktop/modular alternative.&lt;/p&gt;

&lt;div class=&quot;image&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/synths/minilogue-xd/module.jpg&quot;&gt;&lt;img alt=&quot;Modular Minilogue XD&quot; class=&quot;img&quot; height=&quot;300&quot; src=&quot;https://jmtd.net/log/synths/minilogue-xd/module/400x-module.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;

&lt;p&gt;Modular Minilogue XD&lt;/p&gt;

&lt;/div&gt;


&lt;p&gt;Why? Partly, because it fits on my desk better. Partly, because it changes the way
you engage with the instrument. It makes
a huge difference: the ivory keys come with so much cultural precedent. The module
version of the synth gains a switch that lets you use the 16 sequencer step buttons
as note inputs, so you can still play the thing solo. But the emphasis moves away
from note generation and more firmly towards tone.&lt;/p&gt;

&lt;p&gt;Both versions have a lovely stained wood back, which you never see; the modular one
has a hint of that at the front as well (which you do see).&lt;/p&gt;

&lt;p&gt;I plan to eventually buy a MIDI keyboard that could drive it, and other things:
possibly an Arturia KeyStep or Minilab, but there&#39;s no rush on that.&lt;/p&gt;

&lt;p&gt;(It&#39;s about time I recorded and shared something I produced on this)&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-09T19:31:38+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="http://blog.alteholz.eu/?p=2832">
	<title>Thorsten Alteholz: My Debian Activities in June 2026</title>
	<link>http://blog.alteholz.eu/2026/07/my-debian-activities-in-june-2026/</link>
     <content:encoded>&lt;h3&gt;&lt;strong&gt;Debian LTS/ELTS&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This was my hundred-forty-fourth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
&lt;/p&gt;
&lt;p&gt;
During my allocated time I uploaded or worked on:  
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/msg00004.html&quot;&gt;DLA 4615-1&lt;/a&gt;]  exim4 security update to fix one CVE related to information disclosure in combination with proxies.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/msg00005.html&quot;&gt;DLA 4616-1&lt;/a&gt;] haveged security update to fix one CVE related to local root privilege escalation.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/msg00007.html&quot;&gt;DLA 4618-1&lt;/a&gt;] gsasl security update to fix one CVE related to denial of service.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/msg00020.html&quot;&gt;DLA 4631-1&lt;/a&gt;] asterisk security update to fix 13 CVEs related to buffer under- or overflows, either on heap or on stack. Some are related to use-after-free or wrong processing of invalid or untrusted certificates. 
&lt;/li&gt;&lt;li&gt;[ELA-1747-1] gimp security update to fix three CVEs in Buster related to denial of service or execution of arbitrary code if malformed PSP, JPEG 2000 or PSD files are opened.&lt;/li&gt;&lt;li&gt;[ELA-1748-1] gimp security update to fix two CVEs in Stretch related to denial of service or execution of arbitrary code if malformed PSP or PSD files are opened.&lt;/li&gt;&lt;li&gt;[ELA-1749-1] exim4 security update to fix one CVEs in Buster and Stretch related to information disclosure in combination with proxies.&lt;/li&gt;&lt;li&gt;[ELA-1750-1] gsasl security update to fix one CVEs in Buster and Stretch related to denial of service.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;
Besides fixing all CVEs of &lt;i&gt;asterisk&lt;/i&gt; in Bullseye, I started to look at &lt;i&gt;asterisk&lt;/i&gt; in other releases as well. Rather surprisingly &lt;i&gt;asterisk&lt;/i&gt; is only part of Unstable and Bullseye. All other releases don’t include any version of &lt;i&gt;asterisk&lt;/i&gt; at all. So first things first, besides some security related RC bugs, &lt;i&gt;asterisk&lt;/i&gt; did not migrate due to RC-bugs in &lt;i&gt;dahdi-linux&lt;/i&gt;.
As I maintain &lt;i&gt;osmocom-dahdi-linux&lt;/i&gt; (which supports less/other hardware), I looked at the open issues and after some rounds I could upload a new upstream version, fixed some bugs and resolved issues with piuparts. &lt;i&gt;dahdi-linux&lt;/i&gt; meanwhile migrated to testing, job done! &lt;br /&gt; As a next step I looked at the open CVEs. Some of them had been already fixed in previous uploads but had not been marked accordingly. So I fixed all remaining ones and sent a debdiff to the maintainer. Unfortunately there was some kind of overlap in our work and he ignored my debdiff but uploaded a new upstream version. Anyway, job done as well, no open security issues anymore. The only thing that hinders &lt;i&gt;asterisk&lt;/i&gt; from migrating to testing is the reproducible build. So if anybody has some spare time …
&lt;/p&gt;


&lt;p&gt;
Other things I worked on were the regression update of &lt;i&gt;rsync&lt;/i&gt;. Some of the elven new patches need to be backported, but I am confidentially to finish this month. I already reviewed the &lt;i&gt;rsync&lt;/i&gt;– uploads of Sylvain to Buster and Stretch, so I don’t expect any big hurdles here. I am also making progress to find the correct patches for &lt;i&gt;hplip&lt;/i&gt; and &lt;i&gt;cups&lt;/i&gt;.
&lt;/p&gt;


&lt;h3&gt;&lt;strong&gt;Debian Printing&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream versions:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/lprng&quot;&gt;hplip&lt;/a&gt; to unstable to fix some bugs.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://www.freexian.com&quot;&gt;Freexian&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Lomiri&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This month new upstream versions of dozens of lomiri packages have been released and I uploaded lots of them to Debian. After they migrate to testing, I am also going to sync them to the Ubuntu PPA. &lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://freiesoftware.gmbh/&quot;&gt;Fre(i)e Software GmbH&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Astro&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/supernovas&quot;&gt;indi-pentax&lt;/a&gt; to unstable. This is a package in contrib without autobuild and needed a new upload for the libraw transistion.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/c-munipack&quot;&gt;c-munipack&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/supernovas&quot;&gt;supernovas&lt;/a&gt; to unstable (sponsored upload).&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;Debian IoT&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/duktape&quot;&gt;duktape&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/libcoap3&quot;&gt;libcoap3&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;Debian Mobcom&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/smstools&quot;&gt;smstools&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;misc&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/visam&quot;&gt;visam&lt;/a&gt; to unstable. There had been an RC bug due to two binaries with the same name but different functionality. Yes, it is in the policy but … (my mother forbade me to elaborate more on this)&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/mailio&quot;&gt;mailio&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-07T17:56:04+00:00</dc:date>
	<dc:creator>alteholz</dc:creator>
</item> 
<item rdf:about="http://aigarius.com/blog/2026/07/05/making-of-group-photo/">
	<title>Aigars Mahinovs: How to make a good group photo</title>
	<link>http://aigarius.com/blog/2026/07/05/making-of-group-photo/</link>
     <content:encoded>&lt;p&gt;Taking a good group photo consists of multiple aspects:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;hardware&lt;/li&gt;
&lt;li&gt;scouting&lt;/li&gt;
&lt;li&gt;organization&lt;/li&gt;
&lt;li&gt;preparation&lt;/li&gt;
&lt;li&gt;execution&lt;/li&gt;
&lt;li&gt;processing&lt;/li&gt;
&lt;li&gt;publishing&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I can say with confidence that nearly everything here comes from having failed to do these things right
at least once, even on the latest attempts, so this is an ideal to reach towards, not something we expect to
hit every time.&lt;/p&gt;
&lt;h3&gt;The Goal&lt;/h3&gt;
&lt;p&gt;The main goal of a big event group photo is capture both the moment itself and each individual person inside
that moment.&lt;/p&gt;
&lt;p&gt;We want people, who were &lt;em&gt;not&lt;/em&gt; there to see all the people involved and get an impression of what
it was like being there. It needs to show the breadth and depth of people that make up this group, this project.&lt;/p&gt;
&lt;p&gt;And we want people who &lt;em&gt;were&lt;/em&gt; there to be able to look back the next week, the next year
or in ten years and remember - ah, yes, I was there, I was standing right there with this grin on my face next
to this wonderful person and I was feeling great.&lt;/p&gt;
&lt;h3&gt;Hardware&lt;/h3&gt;
&lt;p&gt;Based on the goal we want to have high level photographic gear that is able to capture both a broad enough picture
to encompass all the people and some of their surroundings to communicate the context (without undue distortions)
and to deliver enough detail and resolution so that faces and facial expressions and underlying feelings of every
single person in that group could be clearly seen and preserved.&lt;/p&gt;
&lt;p&gt;To both capture the context and minimise distortion the final picture should be just a bit wider than normal human
field of view. That is about 50mm for a full-frame camera or 35mm for a typical 1.6 crop camera. You can go a bit
wider if there are no better alternatives (as detailed in the scouting section), but be prepared that corners
of the image will be distorted and not really usable (but we can fix that in processing step). Or you can go
to unusual aspect ratios, like we did in &lt;a href=&quot;https://wiki.debconf.org/wiki/DebConf10/GroupPhoto&quot;&gt;Debconf 10&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the absence of a 100MP+ camera, you will need to be stitching together multiple frames to achieve resolution
high enough to have enough pixels-per-face to see emotions clearly. This means that the photos you will actually
be taking will be tighter than the overall field of view mentioned above. Still, a higher resolution camera body
is preferable - nowadays 24MP-32MP cameras APS-C provide a good compromise between resolution and price, but
45-67MP full-frame cameras also exist on the market. Assume that we will be shooting in a bright environment,
so most likely with quite low ISO settings, that means that high-ISO noise characteristics of more expensive
cameras will not really play a role here. You will also not need very fast burst modes, even manual speed of
one frame per second is sufficient.&lt;/p&gt;
&lt;p&gt;You will also want to get as much detail as possible out of your lens, and this is the &lt;em&gt;most important&lt;/em&gt; part.
You can do amazing work in all other steps of the process and have a great camera too, but if you pair it with
a lens that is not sharp, then the end result will be disappointing.&lt;/p&gt;
&lt;p&gt;You want the lens that is sharpest corner-to-corner when stepped down to about f/8-f/11, that you can get for
your system. You also want that lens to be about 85mm full-size sensor or 50mm for 1.6 crop size. Luckily that kind of
range is also a great range for optical design and sharpest lenses are typically available in exactly these kinds
of sizes. You absolutely want to have a fixed focal length lens, not a zoom lens. Even profession grade zoom lenses
often deliver worse image quality compared to fixed lenses that cost less 1/10th of their price (when shooting in
the same focal length). Newer design lenses are better than older lenses - optical design, coatings and precision
manufacturing have advanced a lot over the decades. Retro look is great for mood, but not as good for actual
resolution and clarity. You don&#39;t need to overpay for most expensive lenses because those often only improve
image quality on lower F-stops. To encompass the whole group we will need to shoot at f/8 and in bright light,
so the extra benefits of those f/1.2-capable super expensive lenses will not come into play here.&lt;/p&gt;
&lt;p&gt;We will have no use for a flash here. A tripod will be too restrictive when rapidly repositioning the camera between
different parts of the panorama shoot. But a monopod might help with stability - I have not tried that myself,
however.&lt;/p&gt;
&lt;p&gt;For my last photos I used a Canon EOS R7 (32.5MP) with Canon RF 50mm f/1.8 STM lens and considering an upgrade
to Sigma 56mm f/1.4 DC DN for the next time.&lt;/p&gt;
&lt;h3&gt;Scouting&lt;/h3&gt;
&lt;p&gt;Scouting a good location for the group photo is another big chunk of a successful picture. The critical piece of
the puzzle is lens-to-face distance. In order to keep everyone&#39;s face in-focus and have enough resolution on the
farthest faces (without making nearest faces truly massive) we want to do everything possible to reduce the
variance in lens-to-face distance - to reduce the difference in distance between closest and farthest face.&lt;/p&gt;
&lt;p&gt;The most effective way to do that is to have the photographer climb higher. To see this in action on the
&lt;a href=&quot;https://wiki.debian.org/DebConf/GroupPhotoAll&quot;&gt;Debconf photos&lt;/a&gt;, compare Debconf6 (very high camera position,
group on level ground - good) to Debconf10 (camera not too high, group on stairs, still good) and to Debconf17
(camera could not get high enough and the group is on flat ground - not great). Even the Debconf25 photo was
suboptimal from this perspective. The Debconf23 photo was a very good example from the recent years - good height
and also the group was positioned in a semi-circle so there were no people directly in front and very near to
the camera.&lt;/p&gt;
&lt;p&gt;So you are looking for the highest point you could get to (even if that requires a special permission of key or a
ladder) with a field large enough to fit the whole group comfortably. How to check that? Normally I simply take a
photo from the top of the whole area and note down from there where the extreme corners of the group could be
and still be fully seen in the shot - not blocked by trees, buildings and shadows. Then I go down and measure
that space. Rule of thumb being - people in one horizontal line can stand 1 normal length step from each other and
two horizontal lines can be half a step from each other vertically. So I can just measure a rough rectangle in
steps, multiply the sides, multiply that by two and I have the rough number of people that can fit there for the
photo.&lt;/p&gt;
&lt;p&gt;Once you have a candidate location or two, it is important to check them at the same time-of-day as you plan to
do the photo (see organization section for that). You want to make sure that the whole area of the group is in the
same illumination - if half of the group is in the sun and half in a shadow, then you will be having a very bad
time later. The absolute ideal positioning for the group photo is to have everyone be in shadow, but still have
enough bright skies and bright buildings in front of the people to give good illumination of the faces. Worst
you can do is have the sun be behind the people (so all the faces are really dark) and second worst is have the sun
be directly in front of the group, so that the faces are very well illuminated, but everyone&#39;s eyes are closed
because they are being blinded by the sun. And sometimes all you can do is pray for some light clouds to provide
for even and dispersed light. Debconf23 was very lucky that way.&lt;/p&gt;
&lt;p&gt;Another consideration is to how people are going to get to that place. You need to consider accessibility needs
of people (it is ok, if it takes more effort or time, but it needs to be organized and communicated well in
advance). And you need to consider how the big masses of people will be getting there - how to tell people where
&lt;em&gt;exactly&lt;/em&gt; it is and how to get there from various locations where people might be hanging out during the event?&lt;/p&gt;
&lt;p&gt;Having an alternate location indoors might be necessary if the weather report for the next days is not sufficiently
predictable. We had to use that contingency in Debconf9, for example.&lt;/p&gt;
&lt;h3&gt;Organization&lt;/h3&gt;
&lt;p&gt;It&#39;s hard to take a good group photo if half of the group does not show up or is too late, so this needs some
organization to happen smoothly.&lt;/p&gt;
&lt;p&gt;First of all you need to choose date and time for the photo. The photo does not take too much time from the
schedule of the event and can be squeezed in after all the other events are already scheduled. In fact I prefer
that as it allows you the flexibility of choosing the date based on weather conditions and time based on light
and shadow conditions in potential photo spots. You don&#39;t want to choose the daytrip day as most people will be
away and return times are not really predictable. You do not want to choose the morning after Cheese and Wine
party for obvious reasons. First day and last two days are also sub-optimal as some people arrive late and some
leave early for various personal reasons. Also &lt;em&gt;you&lt;/em&gt; don&#39;t want it to happen just before Cheese and Wine either
because then you&#39;d have very little time and clarity to do the processing of the image on the same day.&lt;/p&gt;
&lt;p&gt;For timing, the best way, in my experience, is to schedule the photo directly after the end of talk sessions before
a meal break - lunch or dinner. Typically in the Debconf schedule there are 2-3 daily breaks planned, say for
Debconf25 there was lunch, afternoon break and dinner. Talks are planned to end ~10 minutes before those breaks
(and meals) begin, so for example, afternoon break starts at 16:00 and all talks in the previous block end at
15:50. In such a case just schedule the &quot;Group photo&quot; event from 15:50 to 16:05. This gives people the info to go
there &lt;em&gt;directly&lt;/em&gt; from the end of all talks and that they will have sufficient time for break/meal afterwards.
Do not forget to specify the location (as exactly as possible) in that event entry and make sure to post it at
least two days in advance. People often want to wear something specific for the photo and thus need to know about it
in advance. This also makes sure that people do not make alternate food plans for that specific break and don&#39;t
leave the venue.&lt;/p&gt;
&lt;p&gt;Announce the date, time and the exact location as wide as possible, don&#39;t be shy. Announce and discuss mailing
lists, IRC, Signal, Telegram, make sure the front desk knows in case anyone asks in-person, ... Check that it
is again included in the announcements email on the day preceding the photo date.&lt;/p&gt;
&lt;p&gt;When the date has arrived, it is a good idea to check in early with people with special mobility needs to make
sure they know where to go, how to get there and how much time they will need to be able to get there on time.&lt;/p&gt;
&lt;p&gt;As the final round of talks before the group photo is starting up, it is time to recruit &quot;runners&quot;. I&#39;ve had great
success with this technique. The idea is pretty simple - for each room where people congregate (talk rooms,
hacklabs, cafeteria, outside hackspace, front-desk, ...) go there and choose one person. You want to choose a person
that you will recognise and remember among everyone else in the group, either because of who they are or what they
are wearing, whatever works best for you. If they agree to help, instruct them to: &quot;at end of talk, announce that
the group photo happening now and the location, herd people towards the photo location, be the last person out,
make sure there are no stragglers from this area behind you, when you arrive to the photo place I will assume
that everyone else from this room is also now there, when you are there catch my attention and show this sign so
I know for sure that it is all good and make sure that I did see it from you&quot;. With that sorted out all you will
need to remember is how many runners you recruited and how many have reported in to figure out if everyone has now
arrived or if we still have to wait for someone or some group.&lt;/p&gt;
&lt;p&gt;Then you will only have one last point of organization left - shaping the crowd into a group. People will not
know what your vision for the group photo is, so you will have to give clear and &lt;strong&gt;LOUD&lt;/strong&gt; instructions on where
people should &lt;em&gt;not&lt;/em&gt; be standing. Use clear, large gestures to support your words. You want to compact the group,
have the people that just joined in the last moment and are standing to the side come deeper in and join the
crowd. Have any holes in the middle of the crowd filled in. Forming a semi-circle instead of a blob helps with
averaging face-to-lens distances. Make sure people are not in unexpected shadows. Make sure carried objects, like
umbrellas of flags do not cover the faces of other people. Take the time to look at everyone face to make sure there
are no people hiding behind someone&#39;s shoulder - typically they are not aware that their face is in fact not really
visible. If there are such people, call them out and point directly at them and encourage them to step forward, if
they wish to do so. You are the &lt;em&gt;only&lt;/em&gt; one seeing the final picture now and only you can correct it before
capturing the moment. So a few extra seconds here are worth taking, even if 300+ people are standing in scorching
heat and waiting on you.&lt;/p&gt;
&lt;p&gt;When you are happy with what you are seeing, make sure to tell people clearly that you are now about to take
the pictures and &lt;em&gt;again&lt;/em&gt; remind them not to move and &lt;em&gt;explicitly&lt;/em&gt; not to turn their heads to the side until you
are done (this is the source of most of the extra work in processing). Be very loud and clear and make sure
you have everyone&#39;s undivided attention &lt;em&gt;before&lt;/em&gt; you start saying the important stuff.&lt;/p&gt;
&lt;p&gt;When done - say so. There will be other groups that will want to also have a photo taken after the main group
is a bit more dispersed, so don&#39;t run away. Typically at least the T-shirt group will want a picture and also
all the organizers.&lt;/p&gt;
&lt;p&gt;Final bit of organization during the group photo shooting itself is the sneaky self-insert. You may choose not
to bother with it, or do it in the simplest way, like I did in Debconf6, but if you really want to blend in with
the crowd, you need to have someone else take a photo of you in the exact same location at the same date and time
from the same location. So you should already during shaping the crowd decide where you would fit in, it is easiest
to blend in at the back of the crowd and to one or other side, so that it appears like you are just standing behind
the shoulders of a couple peoples. Remember that spot - it is easiest if you stand in the exact same ground spot
when your photo is taken. Just go down, recruit a volunteer to take your photo, make sure the settings are fixed
to the same ones as for the group photo shots and have them take a handful of shots of you - one of you centered in
the camera frame and a couple more with you more towards the corners of the frame. This distortion from being
off-center in the frame may be important later.&lt;/p&gt;
&lt;h3&gt;Preparation&lt;/h3&gt;
&lt;p&gt;In addition to preparing the crowd for the photo, you also need to prepare yourself and the equipment. Make sure
you have dusted your camera sensor and cleaned both inside and outside glass of your lens. It is usually a good
idea to remove any filters from the lens. Install the hood, if that could help with blocking the sun flares.
Make sure you have the right lens and that you have installed the right lens.&lt;/p&gt;
&lt;p&gt;For fixed settings I typically shoot in JPEG with RAW being there more like an emergency backup. The extra dynamic
range of RAW could be used, but it is really complex to do that in combination with image blending and it is
hard to get right, so I prefer an all-JPEG workflow and fix the dynamic range in the scene itself, before shooting.
For Canon I am using the Standard profile that boosts the color saturation and sharpness a bit as I just enjoy
that look and find it hard to get anything significantly better from RAW data even with a lot of effort.
In any case make sure you have enough space on the cards to take at least 100 images and that you have a full
battery. Do not use high speed burst setting because it is then too easy to take too many pictures at the start
of the sequence and be stuck with your camera still in &quot;Busy&quot; state writing big RAW files to slowish SD cards
and not allowing you to finish the full picture rapidly.&lt;/p&gt;
&lt;p&gt;You want to have the shutter speed at at least 1/100th of a second to prevent blur from both your hand movements
and also from people in the shot moving around a bit (image stabilisation will not help you there). And you want
to have the aperture to be around f/8 - lower apertures risk people in front or behind falling out of focus, make
the lenses look less sharp. Higher apertures also start to become less sharp due to diffraction effects above f/8.
ISO should stay as low as possible, ideally at ISO 100, but if there is not enough light then upping the ISO to 400
would be the first step that I would try to do and second would be decreasing the aperture to f/5.6. If there is
too much light, then increasing the shutter speed should be the safe thing to do.&lt;/p&gt;
&lt;p&gt;As people start to arrive into the shooting location - check the exposure and nail down the settings, ideally in
manual mode. Consider that left side could be a bit lighter or darker than right side. Err on the side of making
the picture a bit too dark as there is more depth to darkness before cut-off compared to clipping on the high
end. However, do not trust the exposure detection, instead take a picture and look specifically at skin tones in
faces of people that already are standing in the photo area. Faces are the key bit and the exposure needs to be
adjusted just to the faces and ignore darker of lighter clothing. Do some test shots and find settings where faces
look not too bright, but also not very dark and fix those settings in manual mode.&lt;/p&gt;
&lt;p&gt;Now you are ready for the action. Shape the crowd, check the faces and the action can start!&lt;/p&gt;
&lt;h3&gt;Execution&lt;/h3&gt;
&lt;p&gt;During taking of the group photo you want to finish it fast, but at the same time you have to take the time to
make it right. If you hurry too much under pressure, you risk being left with unusably blurry images and the
whole effort wasted. Having already prepared and verified the manual settings makes it easier.&lt;/p&gt;
&lt;p&gt;When you are taking pictures, you have to remain as still as possible - even at very high
shutter speeds even slow hand movements are still bad for image quality. So think of the movement as of
biathlon athlete shooting the very middle of five, very separate targets - take a burst, reframe, then steady
up for a second and only then take the next burst. 3 frames per burst are sufficient. 90% of the time the very
first photo of a burst will be best. As you move from frame to frame, aim for just a bit more than half-frame
overlap. This will give the opportunity to skip frames if all is good, but also have backup coverage of every
face in case of problems. Proceed systematically, I typically start off on the top left of the crowd, then
go right until the end of the line, then shift down half a frame and go left until the end and repeat until
I am done with the crowd. &lt;/p&gt;
&lt;p&gt;After that it is &lt;em&gt;very&lt;/em&gt; helpful to also immediately take photos of a &quot;frame&quot; around
the whole crowd. Stitching process often distorts the frames in weird ways that leave holes in the resulting image
that you can fill if you have a wide frame around the crowd. It is possible to compensate with creative
cutouts in the final image (like Debconf9), but the more framing room you make, the more flexible you will be
able to be with cropping of the final photo. The frame also gives you the opportunity to capture more of the
context of the place and space.&lt;/p&gt;
&lt;p&gt;As an example, Debconf25 group photo in the end consisted from 9 images + 1 for sick people + 1 for me. I ended
up missing the framing shots for bottom left, top left and top right corners. To get there I took 68 images. And
in some years it was more than a hundred.&lt;/p&gt;
&lt;h3&gt;Processing&lt;/h3&gt;
&lt;p&gt;This part might be less stressful than taking the pictures from intensity perspective, but it lasts longer. Depending
on you luck, skill and perfectionism it can take anywhere from 3 to 9 hours of work to complete.&lt;/p&gt;
&lt;p&gt;Before you start, however, you should first request things that you will need for other people. This &lt;em&gt;can&lt;/em&gt; even be
done before taking the actual group photo, but usually I forget. To finish the photo you will need three things:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;good quality vector graphics of the current Debconf logo&lt;/li&gt;
&lt;li&gt;good quality vector graphics of the &lt;em&gt;next&lt;/em&gt; years Debconf logo (even if preliminary)&lt;/li&gt;
&lt;li&gt;motto of the conference&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The first two you should be able to get from the respective organizers. The motto is harder. I typically try to
ask the current DPL to come up with something describing the current mood of the project or of the event, but
it is rare that it is that easy. Most of the time I came up with something as I was editing the photo and
reflecting on what was the mood, the feeling, the mojo of this conference and of this year was like. Bend that
around a recognisable phrase or expression, make it a bit more insider-relevant and you are on the right path.
Some years this was the hardest part.&lt;/p&gt;
&lt;p&gt;For the panorama stitching I will describe the workflow that has served me good for years, but maybe there are
better ways possible nowadays. Feel free to let me know!&lt;/p&gt;
&lt;p&gt;First I would save all photos taken and select one sharpest photo from every burst. Next I would select the minimal
number of photos that appear to be covering the entire crowd. The fewer images you use, the better in the end
because the most quality problems crop up in the areas where photos are getting stitched together. Fewer seams
leads to fewer issues.&lt;/p&gt;
&lt;p&gt;Open &lt;a href=&quot;https://packages.debian.org/search?keywords=hugin&quot;&gt;Hugin&lt;/a&gt; (you will also need enblend and enfuse installed)
and import your minimal set of images into it. Click the &quot;Align&quot; button and wait a while - the processor will be
trying to figure out keypoints in each image and then try to match these points between the images to try to
fit them all together into a single projection. To do that it will distort the images. This is the trial and error
process part. You may need to add, remove or replace images to get the stitching to work or to work better. You
may want to add more of the frame images to fill the ragged holes around the image.&lt;/p&gt;
&lt;p&gt;After initial alignment, go to &quot;Move/Drag&quot; tab and move the image a bit up in the projected field of view and
make it a bit more central visually. That will help a bit with the distortions in the near-by people and people
in the corners of the image. In the &quot;Crop&quot; tab set the initial crop - leave it generous, you can always crop more
in later steps. Do not be afraid of leaving in sizable chunks of black homes, empty skies or grass. All of that
can be filled in later as well.&lt;/p&gt;
&lt;p&gt;Go back to the &quot;Assistant&quot; tab and click &quot;Create panorama&quot;. It is good enough to have JPEG output at 100% quality
using exposure corrected low dynamic range output option. Make sure to check the &quot;Keep intermediate images&quot; option.
This will not only generate the final, merged panorama, but also keep around the individual images &lt;em&gt;after&lt;/em&gt;
perspective correction and exposure blending steps. These are critical for fixing blending error in the next step.&lt;/p&gt;
&lt;p&gt;You might need to go back a forth a few times with a different sets of source images, maybe adding some image
between other two, maybe removing another to reach a better starting point. The key part to pay attention - how
many ugly stitches are there in the image. Check every face, the blending algorithms do not recognise faces and
sometimes try to stitch one face from two or more images creating very weird effects. They &lt;em&gt;can&lt;/em&gt; be fixed in the
next step, but it is rather hard manual work, so the fewer such faces are in the blended image, the less work
you will have. In some years I&#39;ve managed to find a combination where all faces were good and in other years
I had to manually fix 13-15 faces.&lt;/p&gt;
&lt;p&gt;Do not try to blend the extra pictures (like with you or with sick people) into the main panorama with Hugin - it
will get very confused with the parts of the grass that it is able to see where other people were standing.&lt;/p&gt;
&lt;p&gt;The next is the final processing in &lt;a href=&quot;https://packages.debian.org/search?keywords=gimp&quot;&gt;GIMP&lt;/a&gt;. Think of it like
a large and complex project - do as much as possible in separate layers, save often.&lt;/p&gt;
&lt;p&gt;Fixing wrongly stitched faces and also putting yourself into the photo are very similar activities in the end.
Just the scale and the source differ. For yourself you just cut out yourself (upper torso is enough) from the
separate photo. For corrupted face, choose one of two intermediate images that the Hugin created where the
face is transformed, but not yet merged (with a different version of itself). In either case crop the photo to
roughly the interesting size and put roughly in the right spot as a separate layer on top of the group photo
background. Reduce the opacity of the small layer to 30-40% and zoom in to 400%. With that it is much simpler to
position the layer with pixel precision. Then all you need to do is add a layer mask to this layer and paint it
just right. Basically in layer mask black means transparent and white means non-transparent. So you need to &lt;em&gt;just&lt;/em&gt;
make everything that is you have white mask and everything that is not you have black mask. And smudge the border
a bit with finger tool or blur to make the transition smoother. Easy to say. Hard to do. This is what takes most
of the actual work hours in post-processing.&lt;/p&gt;
&lt;p&gt;You &lt;em&gt;might&lt;/em&gt; miss someone. I am sure Phill is just thrilled to see me in the very middle of the Debconf25 final
picture .... But do try to fix them all.&lt;/p&gt;
&lt;p&gt;Use large, sweeping geometric figures to cover up black holes, empty grass fields and other sub-optimal corner
features. And then use that newly created free space to put in a large version of the logo of this years
conference, decently sized motto and slightly smaller invitation to the next years conference.&lt;/p&gt;
&lt;p&gt;Do not forget to add a copyright and license statement somewhere in the corner in smaller, but still well
readable font. I am using a text like: &quot;Photo by: Full Name, Email: fullemail@debian.org, License: GPLv2+ or
CCv3-BY&quot; This ensures that this image may be used in any press coverage (with basic attribution) and also
can be included in any GPL-licensed software, if that ever comes up. The same statement is also in the
metadata of the image file (see Image-Metadata-Edit metadata in GIMP) along with information that states
that this is &quot;Debian Developer Conference Group photo, City, Country, Year&quot;. 
Image-&amp;gt;Image properties-&amp;gt;Comment is another place where GIMP hides this EXIF information.&lt;/p&gt;
&lt;p&gt;For ease of use, in addition to a full-resolution image it is also useful to make a lower resolution version
that would still fit on a 4K screen at full resolution, so about 3840px wide. Some photo hosting services set
other limits for image size as well, so it might be needed to scale the image down below 100Mpix to upload it
to Google Photos, for example.&lt;/p&gt;
&lt;h3&gt;Publishing&lt;/h3&gt;
&lt;p&gt;So, it is finally 1AM and the group photo is ready! How do you push it out to people? Well, in all possible ways
and places. Again - don&#39;t be shy, people do really want to see it.&lt;/p&gt;
&lt;p&gt;Push it to whatever you use for your shared photos. Push it to 
&lt;a href=&quot;https://salsa.debian.org/debconf-team/public/share&quot;&gt;Debconf shared git&lt;/a&gt; (note that this is GIT-LFS repo, make sure
you know how to add content to the LFS specifically). All permanent links to that in 
&lt;a href=&quot;https://wiki.debian.org/DebConf/GroupPhotoAll&quot;&gt;GroupPhotosAll wiki&lt;/a&gt;. And then send those links to IRC, Signal,
Telegram groups, debconf-announce mailing list. Publish it in your blog and push that to 
&lt;a href=&quot;https://planet.debian.org/&quot;&gt;Debian Planet&lt;/a&gt;. Push it in Threads, Bluesky and Mastodon.
 Send an email separately to Debconf orga team. And one to 
&lt;a href=&quot;https://wiki.debian.org/Teams/Publicity&quot;&gt;Debian Publicity Team&lt;/a&gt; so they can put it into the
&lt;a href=&quot;https://www.debian.org/&quot;&gt;Debian Home Page&lt;/a&gt; and push via Debian micronews accounts.&lt;/p&gt;
&lt;p&gt;And that is about it. Now you can go back to enjoying the rest of the conference. Or running around doing other
things that you think need to be done. It&#39;s up to you. You did it. This moment will remain with people for a
very long time. And you helped.&lt;/p&gt;
&lt;p&gt;Questions? Feedback? Just ask
&lt;a href=&quot;https://bsky.app/profile/aigarius.com/post/3mpytbrm5dc2w&quot;&gt;here&lt;/a&gt; or
&lt;a href=&quot;https://www.threads.com/@aigarius/post/DadpZDbjqAx?xmt=AQG0WPOLDjK2ZkbDiiuXEOqQQWF5bum51R8V_uNtv9nliA&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-06T19:30:00+00:00</dc:date>
	<dc:creator>Aigars Mahinovs</dc:creator>
</item> 
<item rdf:about="https://bisco.org/notes/status-update-june-2026/">
	<title>Birger Schacht: Status update, June 2026</title>
	<link>https://bisco.org/notes/status-update-june-2026/</link>
     <content:encoded>&lt;h1 id=&quot;debian-related-work&quot;&gt;Debian Related Work&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;Uploaded wofi 1.5.3-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded wob 0.16-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded labwc 0.20.0-1 and 0.20.1-1 to unstable; these releases come with
support for wlroots-0.20, which made labwc reenter testing&lt;/li&gt;
&lt;li&gt;Uploaded swaylock 1.8.5-2 to unstable to make it use the &lt;code&gt;common-auth&lt;/code&gt;
directive of pam (seeh &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140096&quot;&gt;#1140096&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Uploaded swayimg 5.4-1 to unstable&lt;/li&gt;
&lt;li&gt;Uploaded wayback 0.3-2 to unstable, which was waiting in experimental
for a reupload and I had forgotten about it; also fixed a
&lt;a href=&quot;https://gitlab.freedesktop.org/wayback/wayback/-/merge_requests/96&quot;&gt;typo&lt;/a&gt;
in wayback upstream&lt;/li&gt;
&lt;li&gt;Uploaded xdg-desktop-portal-wlr 0.8.3-1 to unstable&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;dh-related-work&quot;&gt;DH Related Work&lt;/h1&gt;
&lt;p&gt;The search app I was working on last month was still a focus in June. I refactored
the data model a bit and made it simpler. I stumbled over the &lt;a href=&quot;https://pythonkoans.substack.com&quot;&gt;Python
Koans&lt;/a&gt; and &lt;a href=&quot;https://pythonkoans.substack.com/p/koan-15-the-invisible-ink&quot;&gt;Koan 15: The Invisible
Ink&lt;/a&gt; gave me the
idea of using unicode normalization when indexing the items.&lt;/p&gt;
&lt;p&gt;I released a couple of bug fix releases for the APIS framework, namely 0.64.2,
0.64.3 and 0.64.4. I also release 0.65.0 which is one step further in dropping
support for the legacy &lt;code&gt;apis_entities&lt;/code&gt; app. When the &lt;code&gt;search&lt;/code&gt; module is merged
it will give way for removing the last bits of the old cruft to be removed.&lt;/p&gt;
&lt;p&gt;During a regular dependency update session I looked at the changes in &lt;a href=&quot;https://github.com/yourlabs/django-autocomplete-light&quot;&gt;the dal
dependency&lt;/a&gt;. After a
long time with no commits, the project suddenly had a lot of commits
co-authored by Claude and then released a new major version with a regression.
Given the state of the project, we decided to keep using the previous release
for now and look into replacing the dependency with an HTMX based solution. I
implemented a POC for one of the plugins we develop and it was actually pretty
easy. I also managed to combine the autocomplete approach with a multi-select
form field, based on &lt;a href=&quot;https://dev.to/apleshkov/htmx-multi-select-form-control-without-js-4jfk&quot;&gt;this blog
post&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the
&lt;a href=&quot;https://www.oeaw.ac.at/de/acdh/forschung/dh-forschung-infrastruktur/aktivitaeten/dh-datenmodellierung/pfp-prosopographische-plattform-oesterreich&quot;&gt;PFP&lt;/a&gt;
project I finally merged the stats endpoint which give statistics about the
named graphs that are used as data sources.&lt;/p&gt;
&lt;h1 id=&quot;other&quot;&gt;Other&lt;/h1&gt;
&lt;p&gt;I attended &lt;a href=&quot;https://bsidesvienna.at/&quot;&gt;BSidesVienna 0x7EA&lt;/a&gt; but it was on one of
the hottest days this year so far so I left after a couple of talks.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-05T05:28:51+00:00</dc:date>
	<dc:creator>Birger Schacht</dc:creator>
</item> 
<item rdf:about="http://blog.sesse.net/blog/tech/2026-07-04-15-21_an_update_on_sesse_chromium_org.html">
	<title>Steinar H. Gunderson: An update on sesse@chromium.org</title>
	<link>http://blog.sesse.net/blog/tech/2026-07-04-15-21_an_update_on_sesse_chromium_org.html</link>
     <content:encoded>&lt;p&gt;As previously mentioned, I am leaving Chrome; my last work day
was yesterday. (Sorry to those with July 3rd off that I didn&#39;t
get to say goodbye to!) But I&#39;m staying in Google, on more internal
projects :-)&lt;/p&gt;

&lt;p&gt;After 1100+ commits it&#39;s hard to pick out one thing that I love
the most; as a team, we launched a lot of (IMO) useful CSS features
and fixed a lot of issues. But somehow, I keep on gravitating towards
performance, and perhaps &lt;a href=&quot;https://chromium-review.googlesource.com/c/chromium/src/+/3581992&quot;&gt;this commit&lt;/a&gt;
is the one I will remember the most fondly; a couple hundred lines
to speed up repeated attribute selectors a lot. (If you ever wonder
who would be doing that; well, there&#39;s a fairly high chance that you
have an extension injecting a stylesheet with a lot of &lt;code&gt;a[href*=&quot;...&quot;]&lt;/code&gt;
rules…)&lt;/p&gt;

&lt;p&gt;Upwards and onwards. Please write lean, clean CSS; I won&#39;t be there
to save you from now on. :-)&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-04T14:21:00+00:00</dc:date>
	<dc:creator>Steinar H. Gunderson</dc:creator>
</item> 

</rdf:RDF>
