<?xml version="1.0"?>
<rdf:RDF
	xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:foaf="http://xmlns.com/foaf/0.1/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns="http://purl.org/rss/1.0/"
>
<channel rdf:about="https://planet.debian.org/">
	<title>Planet Debian</title>
	<link>https://planet.debian.org/</link>
	<description>Planet Debian - https://planet.debian.org/</description>

	<items>
		<rdf:Seq> 
		  <rdf:li rdf:resource="https://diffoscope.org/news/diffoscope-328-released/"/>
		  <rdf:li rdf:resource="https://gwolf.org/2026/08/file-recovery-in-process.html"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/punch-out/"/>
		  <rdf:li rdf:resource="http://blog.sesse.net/blog/tech/2026-08-12-16-26_the_psx_gpu_is_wild.html"/>
		  <rdf:li rdf:resource="https://reproducible-builds.org/news/2026/08/12/reproducible-builds-summit-in-gothenburg/"/>
		  <rdf:li rdf:resource="tag:www.chiark.greenend.org.uk,2026-08-11:/~cjwatson/blog/activity-2026-07.html"/>
		  <rdf:li rdf:resource="https://www.freexian.com/blog/debian-contributions-07-2026/"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-08-10:/2026/08/debconf26-words-from-localteam.html"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/guardian_scifi_roundup/"/>
		  <rdf:li rdf:resource="tag:blog.kleine-koenig.org,2026-08-10:/ukl/pgp-keysigning-on-linux-plumbers-and-opensource-summit-europe-2026.html"/>
		  <rdf:li rdf:resource="tag:hashman.ca,2026-08-09:/managing-venvs/"/>
		  <rdf:li rdf:resource="https://reproducible-builds.org/reports/2026-07/"/>
		  <rdf:li rdf:resource="http://blog.alteholz.eu/?p=2842"/>
		  <rdf:li rdf:resource="https://diffoscope.org/news/diffoscope-327-released/"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-08-06:/2026/08/debconf26-closes.html"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6267"/>
		  <rdf:li rdf:resource="https://gwolf.org/2026/08/subscription-bombing-email-under-attack.html"/>
		  <rdf:li rdf:resource="https://k1024.org/posts/2026/2026-08-05-yes-yes-still-alive/"/>
		  <rdf:li rdf:resource="http://www.enricozini.org/blog/2026/debian/gnome-refusing-to-suspend"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6264"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/08/04#058_fast_easy_reliable_reverse_dependency_checks"/>
		  <rdf:li rdf:resource="http://www.hungry.com/~pere/blog/FreeCAD_MCP_with_llama_cpp__toy_or_tool_.html"/>
		  <rdf:li rdf:resource="http://www.netfort.gr.jp/~dancer/diary/daily/2026-Aug-4.html.en#2026-Aug-4-07:03:26"/>
		  <rdf:li rdf:resource="http://blog.brlink.eu/index.html#i72"/>
		  <rdf:li rdf:resource="https://changelog.complete.org/?p=44456"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/journal/2026-08/001.html"/>
		  <rdf:li rdf:resource="https://www.decadent.org.uk/ben/blog/2026/08/02/foss-activity-in-july-2026"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6260"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/0-7564-1949-2.html"/>
		  <rdf:li rdf:resource="https://xana.scru.org/posts/bamamba/lekkerderworst.html"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6257"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/9798360228431.html"/>
		  <rdf:li rdf:resource="https://www.earth.li/~noodles/blog/2026/07/my-cpu-died.html"/>
		  <rdf:li rdf:resource="https://optimizedbyotto.com/post/estonia-well-governed-country/"/>
		  <rdf:li rdf:resource="https://xana.scru.org/posts/mintings/mergetooling.html"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/0-9863735-1-6.html"/>
		  <rdf:li rdf:resource="https://diffoscope.org/news/diffoscope-326-released/"/>
		  <rdf:li rdf:resource="http://joeyh.name/blog/entry/my_harddrive_is_probably_not_full/"/>
		  <rdf:li rdf:resource="https://www.eyrie.org/~eagle/reviews/books/9798837010774.html"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/07/28#rcppdate_0.0.7"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/07/27#057_conditionally_quieten_compilers"/>
		  <rdf:li rdf:resource="https://jonathancarter.org/?p=12034"/>
		  <rdf:li rdf:resource="https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/index.html"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/07/25#rcpparmadillo_15.4.2-1"/>
		  <rdf:li rdf:resource="http://00formicapunk00.wordpress.com/?p=344"/>
		  <rdf:li rdf:resource="https://etbe.coker.com.au/?p=6244"/>
		  <rdf:li rdf:resource="https://www.freexian.com/blog/debian-lts-report-2026-06/"/>
		  <rdf:li rdf:resource="http://dirk.eddelbuettel.com/blog/2026/07/21#qlcal-r_0.1.3"/>
		  <rdf:li rdf:resource="https://jmtd.net/log/interzone/digital/"/>
		  <rdf:li rdf:resource="https://retout.co.uk/2026/07/20/renewal-relationships-between-aws-certifications/"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-07-20:/2026/07/debconf26-starts-today.html"/>
		  <rdf:li rdf:resource="tag:bits.debian.org,2026-07-18:/2026/07/debconf26-welcomes-sponsors.html"/>
		  <rdf:li rdf:resource="tag:www.sergiocipriano.com,2026-07-17:posts/running-gui-in-incus.md"/>
		  <rdf:li rdf:resource="https://diffoscope.org/news/diffoscope-325-released/"/>
		  <rdf:li rdf:resource="http://blog.sesse.net/blog/tech/2026-07-15-08-45_looking_at_dpkg_startup_time.html"/>
		  <rdf:li rdf:resource="https://www.freexian.com/blog/debian-contributions-06-2026/"/>
		  <rdf:li rdf:resource="https://gwolf.org/2026/07/got-your-keys-ready-for-debconf26.html"/>
		  <rdf:li rdf:resource="https://blog.freesources.org//posts/2026/07/zed-xdebug/"/>
		  <rdf:li rdf:resource="hatenablog://entry/14945776032052860672"/>
		  <rdf:li rdf:resource="tag:copyninja.in,2026-07-21:/blog/debvulns-exporter.html"/>
		</rdf:Seq>
	</items>
</channel>


<item rdf:about="https://diffoscope.org/news/diffoscope-328-released/">
	<title>Reproducible Builds (diffoscope): diffoscope 328 released</title>
	<link>https://diffoscope.org/news/diffoscope-328-released/</link>
     <content:encoded>&lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;328&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[ Chris Lamb ]
* Don&#39;t require python3-guestfs in the autopkgtests on 32-bit architectures.
  (Closes: #1144372)

[ Jochen Sprickerhof ]
* Use the XML comparators for SVG vector image files. (Closes: #1144242)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href=&quot;https://diffoscope.org&quot;&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-14T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds (diffoscope)</dc:creator>
</item> 
<item rdf:about="https://gwolf.org/2026/08/file-recovery-in-process.html">
	<title>Gunnar Wolf: File recovery in process...</title>
	<link>https://gwolf.org/2026/08/file-recovery-in-process.html</link>
     <content:encoded>&lt;p&gt;Ohai,&lt;/p&gt;

&lt;p&gt;I have some pending, encrypted mails to answer. And some of my answers for
the next few days (particularly to what pertains to the &lt;a href=&quot;https://www.debian.org/vote/2026/vote_002&quot;&gt;current
in-discussion vote on LLM usage in
Debian&lt;/a&gt;) will be unsigned, even
though I’d like otherwise.&lt;/p&gt;

&lt;p&gt;My desktop system at work is showing some data corruption, and I’m slowly
backing up my data. Fortunately, it seems I haven’t lost any data, but
still, given I’m letting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rsync&lt;/code&gt; run until it starts spewing I/O errors,
then power down and let the machine cool a bit, and start again… it is a
potentially long process.&lt;/p&gt;

&lt;p&gt;And yes, this makes me somewhat angry. Why angry? Because I’m working on a
brand-new computer (well, have used it for slightly over six months),
custom-built to specs requested by my workplace. Specs that I don’t really
need, this machine is an utter luxury (i.e. an AMD Ryzen 9 9950X processor
with 16 real cores / 32 threads; 128GB RAM in this day and age of RAM
shortage, quite recent 32GB GPU, and lots of shiny lights seen in its huge
fishbowl cabinet, liquid-based cooling…). The specs came not from me, but
from people who had no idea what we would use them for. And yes, I expect
the little fortune spent on this machine to be good for my use for probably
a decade, as my previous computer was, but the amount paid
was… exorbitant.&lt;/p&gt;

&lt;p&gt;But still, what I learned recently is that the 4TB nVME SSD it has (a
T-Force TM8FFJX34T) is… a very cheap brand, bought because it was close
to half the price of other offerings similar in capacity. According to
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;smartctl&lt;/code&gt;’s output, th SSD operates with a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Warning Comp. Temp. Threshold:
90 Celsius&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Critical Comp. Temp. Threshold: 110 Celsius&lt;/code&gt;, which sounds
sensible, even too high for my standards (my last two laptops have been
fanless… yes, an ARM system is very different from a high-end gaming
machine). I’m right now typing from my laptop, which shows 78°C and 82°C
for warning/critical thresholds.&lt;/p&gt;

&lt;p&gt;And as expected, under heavy sustained reads (backing up to my NFS server),
the desktop’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;smartctl&lt;/code&gt; shows &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Temperature: 83 Celsius&lt;/code&gt; and, further down,
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Temperature Sensor 1: 107 Celsius&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Temperature Sensor 2: 82 Celsius&lt;/code&gt;
(don’t know which of these would make the threshold jump). The SSD has
sustained &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Media and Data Integrity Errors: 20&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Warning
Comp. Temperature Time: 21&lt;/code&gt; (although &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Critical Comp. Temperature Time: 0&lt;/code&gt;). At least one of my colleagues have shrugged and installed a SATA SSD,
laying the huge nVME basically to waste.&lt;/p&gt;

&lt;p&gt;Anyway… I also learned I am not the first, but the fourth person to
notice this kind of issues in this system (out of ten similar purchased
systems AIUI). It is completely unacceptable, and I’ll be pushing our
Institute’s authorities to demand the provider to provide either good
component quality for this very expensive system that has many luxury
items, or to fix the system’s build in a way the nVME does not heat as much
as it currently does.&lt;/p&gt;

&lt;p&gt;Anyway, &lt;em&gt;sigh&lt;/em&gt;, I only wanted to say, please excuse me for not using my
cryptographic keys for a couple of days 🙃&lt;/p&gt;

&lt;p&gt;PS- I’m also currently not connected to IRC and Jabber (and some similar
technologies), as my bouncer runs from my usual workstation.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-13T17:47:20+00:00</dc:date>
	<dc:creator>Gunnar Wolf</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/punch-out/">
	<title>Jonathan Dowland: DIY skate punch-out</title>
	<link>https://jmtd.net/log/punch-out/</link>
     <content:encoded>&lt;div class=&quot;image&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/punch-out/punch.jpg&quot;&gt;&lt;img alt=&quot;The punch set-up&quot; class=&quot;img&quot; height=&quot;281&quot; src=&quot;https://jmtd.net/log/punch-out/500x-punch.jpg&quot; width=&quot;500&quot; /&gt;&lt;/a&gt;

&lt;/div&gt;




&lt;div class=&quot;image&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/punch-out/marked.jpg&quot;&gt;&lt;img alt=&quot;the punched boot&quot; class=&quot;img&quot; height=&quot;281&quot; src=&quot;https://jmtd.net/log/punch-out/500x-marked.jpg&quot; width=&quot;500&quot; /&gt;&lt;/a&gt;

&lt;/div&gt;


&lt;p&gt;Since I wrote about my &lt;a href=&quot;https://jmtd.net/log/fly30/&quot;&gt;fly30&lt;/a&gt; ice skates, I&#39;d continued to battle pain
around the navicular bone in my feet. The action that seems to have finally
fixed it was to perform a &quot;punch out&quot;: a very localized remoulding of the
area of the boot that presses against the sore area.&lt;/p&gt;

&lt;p&gt;I basically followed the process from &lt;a href=&quot;https://www.youtube.com/watch?v=5RntLK_-lBU&quot;&gt;this helpful YouTube
video&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;I narrowed down the exact spot by borrowing some lipstick and transferring it
from my navicular bone to the boot lining, then making that more permanent with
a sharpie.&lt;/p&gt;

&lt;p&gt;My punch was a spare part from a radiator valve which I packed with US cents
(I couldn&#39;t fit any UK coins in). For the receiving-end, I tried another part
from the radiator valve but I think it wasn&#39;t sufficiently larger than the punch
to work well, so I swapped that out for a spoon.&lt;/p&gt;

&lt;div class=&quot;image&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/punch-out/take2.jpg&quot;&gt;&lt;img alt=&quot;take 2&quot; class=&quot;img&quot; height=&quot;281&quot; src=&quot;https://jmtd.net/log/punch-out/500x-take2.jpg&quot; width=&quot;500&quot; /&gt;&lt;/a&gt;

&lt;p&gt;take 2&lt;/p&gt;

&lt;/div&gt;


&lt;p&gt;I didn&#39;t have a temperature sensor I could use and I used a heat gun rather than
a hairdryer, so I YOLO&#39;d it a little. Some of the wrap on one of my boots is now
distorted from where I didn&#39;t move the heat gun enough. It only took a minute or
two to get the boot hot enough to be flexible. I set a 15 minute timer once the
clamp was in place.&lt;/p&gt;

&lt;p&gt;I&#39;ve only skated one session since I did this but the pain seems to have gone!
It&#39;s remarkably freeing to be skating without constantly trying to manage pain.
Now I can focus on technique.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-13T08:28:08+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="http://blog.sesse.net/blog/tech/2026-08-12-16-26_the_psx_gpu_is_wild.html">
	<title>Steinar H. Gunderson: The PSX GPU is wild</title>
	<link>http://blog.sesse.net/blog/tech/2026-08-12-16-26_the_psx_gpu_is_wild.html</link>
     <content:encoded>&lt;p&gt;Inspired by some recent reverse-engineering, here are some things I
find wild by the original PlayStation GPU:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;VRAM is a flat 1024x512 16-bit image (555 + 1 bit alpha).
You want more than just a framebuffer?  Figure out yourself what goes where.&lt;/li&gt;
&lt;li&gt;Yes, that means you&#39;ll need to allocate two framebuffers
and double-buffer everything yourself.&lt;/li&gt;
&lt;li&gt;Quads are common. No “triangles only” business here.&lt;/li&gt;
&lt;li&gt;Vertex coordinates are screen-space x/y integers. No floats or fixed-point. (I&#39;m ignoring the GTE here,
plus higher-level libraries.)&lt;/li&gt;
&lt;li&gt;Wait, where&#39;s z? There&#39;s no z. So there&#39;s no perspective correction.
(This one is pretty famous)&lt;/li&gt;
&lt;li&gt;OK, so how do you give in subpixel coordinates? You don&#39;t. There&#39;s no AA after all.&lt;/li&gt;
&lt;li&gt;Texture coordinates (u/v) are uint8_t. There&#39;s no texture filtering either;
everything is nearest-neighbor only.&lt;/li&gt;
&lt;li&gt;OK, so that means you can&#39;t have textures larger than 256x256
(pretty common in that era), but how do you give in the handle to the
texture?&lt;/li&gt;
&lt;li&gt;You don&#39;t, it points directly to the 1024x512 VRAM. You manage yourself
what goes where, remember?&lt;/li&gt;
&lt;li&gt;So can you an only have textures in the top-left 256x256? Hah, no,
we give you a bit-packed “texture page” system that offsets
all your u/v coordinates.&lt;/li&gt;
&lt;li&gt;Most textures are paletted to save VRAM (so instead of 555+1, your
pixels now mean something like “two palette indexes”). Where does the palette live?&lt;/li&gt;
&lt;li&gt;Well, duh, that&#39;s a 256x1 (or 16x1, or whatever) area of VRAM too.
The GPU does not care, you can use another texture&#39;s pixels as a palette if
you feel like it.&lt;/li&gt;
&lt;li&gt;OK, so you said there&#39;s no z, how do you do z-buffering? You have a
z-buffer, right… right?&lt;/li&gt;
&lt;li&gt;Yeah, sure, we&#39;re not cavemen. We have an “ordering table” that is
your Z-buffer, drawn back-to-front. If you want 256 levels of Z,
you just allocate an array of 256 linked-list pointers, and then
you put your polygon into the one corresponding to the correct right Z. &lt;/li&gt;
&lt;li&gt;But, eh, what if my polygon is not completely flat in Z-space?&lt;/li&gt;
&lt;li&gt;Hello?&lt;/li&gt;
&lt;li&gt;Hello…?&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-12T14:45:22+00:00</dc:date>
	<dc:creator>Steinar H. Gunderson</dc:creator>
</item> 
<item rdf:about="https://reproducible-builds.org/news/2026/08/12/reproducible-builds-summit-in-gothenburg/">
	<title>Reproducible Builds: Reproducible Builds summit 2026 to take place in Gothenburg</title>
	<link>https://reproducible-builds.org/news/2026/08/12/reproducible-builds-summit-in-gothenburg/</link>
     <content:encoded>&lt;p class=&quot;alert alert-info&quot;&gt;This event is happening soon — see below for registration instructions!&lt;/p&gt;

&lt;p class=&quot;lead&quot;&gt;We are extremely pleased to announce the upcoming Reproducible Builds summit, which will take place from &lt;strong&gt;September 22nd—24th 2026&lt;/strong&gt; in the city of Gothenburg, Sweden.&lt;/p&gt;

&lt;p&gt;This year, we are thrilled to host the tenth edition of this exciting event, following the success of previous summits in various iconic locations around the world, including &lt;a href=&quot;https://reproducible-builds.org/events/vienna2025/&quot;&gt;Vienna&lt;/a&gt; (2025), &lt;a href=&quot;https://reproducible-builds.org/events/hamburg2024/&quot;&gt;Hamburg&lt;/a&gt; (2023—2024), &lt;a href=&quot;https://reproducible-builds.org/events/venice2022/&quot;&gt;Venice&lt;/a&gt; (2022), &lt;a href=&quot;https://reproducible-builds.org/events/Marrakesh2019/&quot;&gt;Marrakesh&lt;/a&gt; (2019), &lt;a href=&quot;https://reproducible-builds.org/events/paris2018/&quot;&gt;Paris&lt;/a&gt; (2018), &lt;a href=&quot;https://reproducible-builds.org/events/berlin2017/&quot;&gt;Berlin&lt;/a&gt; (2017), &lt;a href=&quot;https://reproducible-builds.org/events/berlin2016/&quot;&gt;Berlin&lt;/a&gt; (2016) and &lt;a href=&quot;https://reproducible-builds.org/events/athens2015/&quot;&gt;Athens&lt;/a&gt; (2015).&lt;/p&gt;

&lt;p&gt;If you’re excited about joining us this year, please make sure to read &lt;a href=&quot;https://reproducible-builds.org/events/gothenburg2026/&quot;&gt;the event page which has more details about the event and location&lt;/a&gt;. As in previous years, we will be sending invitations to all those who attended our previous summit events or expressed interest to do so. However, even if you do not receive a personal invitation, please do &lt;a href=&quot;mailto:2026-summit-team@lists.reproducible-builds.org&quot;&gt;email the organizers&lt;/a&gt; and we will find a way to accommodate you.&lt;/p&gt;

&lt;h3 id=&quot;about-the-event&quot;&gt;About the event&lt;/h3&gt;

&lt;p&gt;The Reproducible Builds Summit is a unique gathering that brings together attendees from diverse projects, united by a shared vision of advancing the Reproducible Builds effort. During this enriching event, participants will have the opportunity to engage in discussions, establish connections and exchange ideas to drive progress in this vital field. Our aim is to create an inclusive space that fosters collaboration, innovation and problem-solving.&lt;/p&gt;



&lt;h3 id=&quot;schedule&quot;&gt;Schedule&lt;/h3&gt;

&lt;p&gt;Although the exact content of the meeting will be shaped by the participants, the main goals will include:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Update &amp;amp; exchange about the status of reproducible builds in various projects.&lt;/li&gt;
  &lt;li&gt;Improve collaboration both between and inside projects.&lt;/li&gt;
  &lt;li&gt;Expand the scope and reach of reproducible builds to more projects.&lt;/li&gt;
  &lt;li&gt;Work together and hack on solutions.&lt;/li&gt;
  &lt;li&gt;Establish space for more strategic and long-term thinking than is possible in virtual channels.&lt;/li&gt;
  &lt;li&gt;Brainstorm designs on tools enabling users to get the most benefits from reproducible builds.&lt;/li&gt;
  &lt;li&gt;Discuss how reproducible builds will be usable and meaningful to users and developers alike.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Logs and minutes will be published after the meeting.&lt;/p&gt;

&lt;h3 id=&quot;location--date&quot;&gt;Location &amp;amp; date&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://clarion-hotel-draken-goteborg.hotelcheckins.com/&quot;&gt;Clarion Hotel Draken&lt;/a&gt;, Olof Palmes Plats 2, 413 30 Göteborg, Sweden. (&lt;a href=&quot;https://www.openstreetmap.org/way/1243458002&quot;&gt;OpenStreetMap&lt;/a&gt;, &lt;a href=&quot;https://maps.app.goo.gl/BBDUEojYcR95jAoc8&quot;&gt;Google Maps&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;September 22nd to September 24th 2026&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;registration-instructions&quot;&gt;Registration instructions&lt;/h3&gt;

&lt;p&gt;Please &lt;a href=&quot;https://reproducible-builds.org/events/gothenburg2026/&quot;&gt;reach out&lt;/a&gt; if you’d like to participate in hopefully interesting, inspiring and intense technical sessions about reproducible builds and beyond!&lt;/p&gt;

&lt;p&gt;We look forward to what we anticipate to be yet another extraordinary event!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-12T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds</dc:creator>
</item> 
<item rdf:about="tag:www.chiark.greenend.org.uk,2026-08-11:/~cjwatson/blog/activity-2026-07.html">
	<title>Colin Watson: Free software activity in July 2026</title>
	<link>https://www.chiark.greenend.org.uk/~cjwatson/blog/activity-2026-07.html</link>
     <content:encoded>&lt;p&gt;About 95% of my Debian contributions this month were &lt;a href=&quot;https://www.freexian.com/about/debian-contributions/&quot;&gt;sponsored&lt;/a&gt; by Freexian.&lt;/p&gt;
&lt;p&gt;You can also support my work directly via &lt;a href=&quot;https://liberapay.com/cjwatson&quot;&gt;Liberapay&lt;/a&gt; or &lt;a href=&quot;https://github.com/sponsors/cjwatson&quot;&gt;GitHub Sponsors&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;OpenSSH&lt;/h2&gt;
&lt;p&gt;Now that Ubuntu 26.04 &lt;span class=&quot;caps&quot;&gt;LTS&lt;/span&gt; has been released, I’ve been getting back to the &lt;a href=&quot;https://lists.debian.org/debian-devel/2024/04/msg00044.html&quot;&gt;&lt;span class=&quot;caps&quot;&gt;GSS&lt;/span&gt;-&lt;span class=&quot;caps&quot;&gt;API&lt;/span&gt; key exchange package split&lt;/a&gt; in our OpenSSH packaging.  Once I started testing my draft &lt;code&gt;openssh-gssapi&lt;/code&gt; source package, I realized that I needed to make some changes in the main &lt;code&gt;openssh&lt;/code&gt; source package first in order to support it.  The dependency from &lt;code&gt;openssh-server&lt;/code&gt; to &lt;code&gt;openssh-client&lt;/code&gt; was awkward, as was the (related) fact that &lt;code&gt;openssh-client&lt;/code&gt; contained shared documentation for other OpenSSH binary packages.  After some thought, I created a new &lt;code&gt;openssh-common&lt;/code&gt; binary package, moved shared documentation and the &lt;code&gt;ssh-keygen&lt;/code&gt; program to that, and dropped dependencies on &lt;code&gt;openssh-client&lt;/code&gt; which were no longer necessary (fixing &lt;a href=&quot;https://bugs.debian.org/699473&quot;&gt;#699473&lt;/a&gt; and &lt;a href=&quot;https://bugs.debian.org/1070098&quot;&gt;#1070098&lt;/a&gt; in the process).&lt;/p&gt;
&lt;p&gt;This caused a couple of regressions (&lt;a href=&quot;https://bugs.debian.org/1141420&quot;&gt;#1141420&lt;/a&gt; and &lt;a href=&quot;https://bugs.debian.org/1141550&quot;&gt;#1141550&lt;/a&gt;) that I had to fix, and more subtly it also caused a number of autopkgtest regressions in other packages because &lt;code&gt;openssh-client&lt;/code&gt; is no longer in base images as a result of a dependency from &lt;code&gt;openssh-server&lt;/code&gt;.  I believe I have fixes for all of these either pending review or merged (one of which I did in August rather than July):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/debian/curl/-/merge_requests/65&quot;&gt;curl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/-/merge_requests/170&quot;&gt;diffoscope&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/debian/glome/-/merge_requests/1&quot;&gt;glome&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/go-team/packages/golang-github-appleboy-easyssh-proxy/-/merge_requests/4&quot;&gt;golang-github-appleboy-easyssh-proxy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/debian/parsyncfp2/-/merge_requests/1&quot;&gt;parsyncfp2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://salsa.debian.org/debian/rsync/-/merge_requests/41&quot;&gt;rsync&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I upgraded from 10.3p1 to 10.4p1, and in the process &lt;a href=&quot;https://bugzilla.mindrot.org/show_bug.cgi?id=3974&quot;&gt;contributed a &lt;span class=&quot;caps&quot;&gt;GSS&lt;/span&gt;-&lt;span class=&quot;caps&quot;&gt;API&lt;/span&gt; option handling fix upstream&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I made openssh-ssh1’s package description &lt;a href=&quot;https://bugs.debian.org/1123609&quot;&gt;more accurately describe the package&lt;/a&gt;, thanks to suggestions from Matthias Lang.&lt;/p&gt;
&lt;h2&gt;Installer team&lt;/h2&gt;
&lt;p&gt;With support from a Freexian customer, I reviewed, tested, edited, and merged a patch to add &lt;a href=&quot;https://bugs.debian.org/433568&quot;&gt;&lt;span class=&quot;caps&quot;&gt;VLAN&lt;/span&gt; support&lt;/a&gt;.  I described the details of what I did in a &lt;a href=&quot;https://bugs.debian.org/433568#243&quot;&gt;comment&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This has been vaguely on my to-do list since, er, about 2014, so it was very satisfying to get it sorted out.&lt;/p&gt;
&lt;h2&gt;Python packaging&lt;/h2&gt;
&lt;p&gt;New upstream versions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;cryptodatahub (fixing a &lt;a href=&quot;https://bugs.debian.org/1140974&quot;&gt;build failure&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;dep-logic&lt;/li&gt;
&lt;li&gt;django-q&lt;/li&gt;
&lt;li&gt;flufl.lock&lt;/li&gt;
&lt;li&gt;more-itertools&lt;/li&gt;
&lt;li&gt;multipart&lt;/li&gt;
&lt;li&gt;pyasn1 (fixing &lt;a href=&quot;https://bugs.debian.org/1142388&quot;&gt;&lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-59884, &lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-59885, and &lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2026-59886&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;pytest-rerunfailures&lt;/li&gt;
&lt;li&gt;python-auditwheel&lt;/li&gt;
&lt;li&gt;python-build&lt;/li&gt;
&lt;li&gt;python-certifi&lt;/li&gt;
&lt;li&gt;python-datamodel-code-generator (fixing a &lt;a href=&quot;https://bugs.debian.org/1141004&quot;&gt;build failure&lt;/a&gt;, and an &lt;a href=&quot;https://github.com/koxudaxi/datamodel-code-generator/issues/3578&quot;&gt;incompatibility with pydantic 2.13&lt;/a&gt; that I reported upstream)&lt;/li&gt;
&lt;li&gt;python-django-parler&lt;/li&gt;
&lt;li&gt;python-httplib2&lt;/li&gt;
&lt;li&gt;python-pgbouncer&lt;/li&gt;
&lt;li&gt;python-time-machine&lt;/li&gt;
&lt;li&gt;python-treq&lt;/li&gt;
&lt;li&gt;python-typing-extensions&lt;/li&gt;
&lt;li&gt;python-wheezy.template&lt;/li&gt;
&lt;li&gt;storm&lt;/li&gt;
&lt;li&gt;ubelt&lt;/li&gt;
&lt;li&gt;webpy&lt;/li&gt;
&lt;li&gt;zope.testing&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Other build/test failures:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1131792&quot;&gt;django-q: autopkgtest failure with Python 3.14&lt;/a&gt; (&lt;a href=&quot;https://github.com/django-q2/django-q2/issues/334&quot;&gt;reported upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140980&quot;&gt;httpx: &lt;span class=&quot;caps&quot;&gt;FTBFS&lt;/span&gt;: E assert [(‘uvicorn.ac…1.1 200 &lt;span class=&quot;caps&quot;&gt;OK&lt;/span&gt;”’)] == [(‘httpx’, 20…1.1 200 &lt;span class=&quot;caps&quot;&gt;OK&lt;/span&gt;”’)]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141778&quot;&gt;libntruprime: autopkgtest failures with Python 3.14&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141791&quot;&gt;pygments: Handle None object before &lt;span class=&quot;caps&quot;&gt;HTML&lt;/span&gt; escaping&lt;/a&gt; (fixed build failures in cmd2, gunicorn, python-inline-snapshot, and python-openapi-core)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142205&quot;&gt;python-authlib: some of tests/flask/test_oauth2/rfc9068/ failed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140873&quot;&gt;python-click: autopkgtest regression with pytest 9.1&lt;/a&gt; (&lt;a href=&quot;https://github.com/pallets/click/pull/3656&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141010&quot;&gt;python-httplib2: &lt;span class=&quot;caps&quot;&gt;FTBFS&lt;/span&gt;: &lt;span class=&quot;caps&quot;&gt;ERROR&lt;/span&gt; tests/test_proxy.py - Failed: ‘forked’ not found in &lt;code&gt;markers&lt;/code&gt; configuration option&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1143139&quot;&gt;python-maturin: Please upgrade goblin dependency to 0.10&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1140692&quot;&gt;python-memray: &lt;span class=&quot;caps&quot;&gt;FTBFS&lt;/span&gt; on armhf (segfault)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141210&quot;&gt;python-mne: &lt;span class=&quot;caps&quot;&gt;FTBFS&lt;/span&gt;: E pytest.PytestRemovedIn10Warning: Passing a non-Collection iterable to parametrize is deprecated&lt;/a&gt; (actually fixed in scikit-learn; &lt;a href=&quot;https://github.com/scikit-learn/scikit-learn/pull/34448&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142373&quot;&gt;python-softlayer: autopkgtest fails with python3-click 8.3.3&lt;/a&gt; (&lt;a href=&quot;https://github.com/softlayer/softlayer-python/pull/2262&quot;&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142214&quot;&gt;python-urllib3: &lt;span class=&quot;caps&quot;&gt;FAILED&lt;/span&gt; test/contrib/test_pyopenssl.py&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I fixed some other bugs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1044278&quot;&gt;django-pipeline: Fails to build source after successful build&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1078037&quot;&gt;more-itertools: Please mark python3-more-itertools with M-A: foreign&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I adopted &lt;a href=&quot;https://bugs.debian.org/980407&quot;&gt;transaction&lt;/a&gt; for the Python team.&lt;/p&gt;
&lt;p&gt;I attended the &lt;a href=&quot;https://debconf26.debconf.org/talks/32-debian-python-bof/&quot;&gt;Python BoF&lt;/a&gt; at DebConf remotely, although a badly-timed fibre outage in the village I live in really didn’t help.&lt;/p&gt;
&lt;h2&gt;Code reviews&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142354&quot;&gt;openssh: sshd-session built without crypt(), breaking UsePAM=no password auth&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142938&quot;&gt;openssh: Slovak debconf templates translation&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1045463&quot;&gt;python-treq: Fails to build source after successful build&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1129141&quot;&gt;python-better-exceptions: &lt;span class=&quot;caps&quot;&gt;FTBFS&lt;/span&gt;: failing tests&lt;/a&gt; (sponsored upload for Seyed Mohamad Amin Modaresi)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141577&quot;&gt;yubihsm-connector: patch to make the build reproducible&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Other bits and pieces&lt;/h2&gt;
&lt;p&gt;Dan Poltawski pointed out in a &lt;a href=&quot;https://fedi.talktodan.com/@dan/116982771943815387&quot;&gt;Fediverse post&lt;/a&gt; that the project history didn’t list Sruthi as the current &lt;span class=&quot;caps&quot;&gt;DPL&lt;/span&gt;.  I &lt;a href=&quot;https://salsa.debian.org/publicity-team/debian-history/-/merge_requests/30&quot;&gt;fixed that&lt;/a&gt;, although it doesn’t look as though the fix is in the published version yet.&lt;/p&gt;
&lt;p&gt;I upgraded yubihsm-shell to 2.8.0.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-11T10:42:43+00:00</dc:date>
	<dc:creator>Colin Watson</dc:creator>
</item> 
<item rdf:about="https://www.freexian.com/blog/debian-contributions-07-2026/">
	<title>Freexian Collaborators: Debian Contributions: DebConf 26 organization, d-i VLAN support and more! (by Anupa Ann Joseph)</title>
	<link>https://www.freexian.com/blog/debian-contributions-07-2026/</link>
     <content:encoded>&lt;h1 id=&quot;debian-contributions-2026-07&quot;&gt;Debian Contributions: 2026-07&lt;/h1&gt;
&lt;p&gt;&lt;a href=&quot;https://www.freexian.com/about/debian-contributions/&quot;&gt;Contributing to Debian&lt;/a&gt;
is part of &lt;a href=&quot;https://www.freexian.com/about/&quot;&gt;Freexian’s mission&lt;/a&gt;. This article
covers the latest achievements of Freexian and their collaborators. All of this
is made possible by organizations subscribing to our
&lt;a href=&quot;https://www.freexian.com/lts/&quot;&gt;Long Term Support contracts&lt;/a&gt; and
&lt;a href=&quot;https://www.freexian.com/services/&quot;&gt;consulting services&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;debconf-26-organization-by-lucas-kanashiro-santiago-ruano-rincón-stefano-rivera-and-antonio-terceiro&quot;&gt;DebConf 26 organization, by Lucas Kanashiro, Santiago Ruano Rincón, Stefano Rivera and Antonio Terceiro&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;27th Annual Debian Conference&lt;/a&gt; was held in
Santa Fe, Argentina, and several Freexian fellows were quite busy by being
involved in the organization team.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Santiago continued helping with duties related to the local team, e.g.
preparing or proof-reading some announcements, reviewing the proposed food and
the menus for the different diet required.&lt;/li&gt;
&lt;li&gt;During the conference, Kanashiro and Santiago also carried over tasks related
to the content of the conference, including updating the schedule as it became
necessary during the event.&lt;/li&gt;
&lt;li&gt;Stefano worked within the core video team, setting up equipment in talk rooms
and coordinating the live video streaming. Stefano also supported the front desk
and local organisers as a website developer and conference book-keeper.&lt;/li&gt;
&lt;li&gt;Antonio kept working on website maintenance, specially in support of the
content team. During DebConf he also ran a hands-on workshop to help interested
contributors get started with developing the DebConf websites.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;d-i-vlan-support-by-colin-watson&quot;&gt;d-i VLAN support, by Colin Watson&lt;/h2&gt;
&lt;p&gt;In environments that use &lt;a href=&quot;https://en.wikipedia.org/wiki/IEEE_802.1Q&quot;&gt;IEEE 802.1Q VLANs&lt;/a&gt;,
some hosts (such as routers attached to “trunk” ports) may need to apply VLAN
tags themselves rather than relying on switches to do so. There has been a
&lt;a href=&quot;https://bugs.debian.org/433568&quot;&gt;long-running request&lt;/a&gt; to add support for these
to the Debian installer with a proposed patch set put together by several people
over the years, and a Freexian customer asked us to help get this over the line.
Colin reviewed the latest version of the patch set, applied a number of
corrections, added Netplan support, spent some time testing a variety of
possible paths through the installer, and landed this. There’s also now
&lt;a href=&quot;https://salsa.debian.org/installer-team/installation-guide/-/merge_requests/46&quot;&gt;documentation&lt;/a&gt;
for this in the next version of the installation guide.&lt;/p&gt;
&lt;h2 id=&quot;miscellaneous-contributions&quot;&gt;Miscellaneous contributions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Carles wrote documentation for installing
&lt;a href=&quot;https://wiki.debian.org/Mailman3&quot;&gt;Mailman3 and migrating from Mailman2&lt;/a&gt;. Added
it into Mailman3 &lt;a href=&quot;https://docs.mailman3.org/en/latest/install/distro.html#installing-on-debian&quot;&gt;upstream documentation&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Carles, using &lt;a href=&quot;https://salsa.debian.org/carlespina/po-debconf-manager&quot;&gt;po-debconf-manager&lt;/a&gt;:
reviewed 2 packages, submitted 2 packages&lt;/li&gt;
&lt;li&gt;Carles organized Catalan translation update. Created a Debian Wiki
&lt;a href=&quot;https://wiki.debian.org/ca/L10n/Catalan/TranslationWebWml&quot;&gt;page&lt;/a&gt; to have an
overview of the work / coordination during next months.
&lt;a href=&quot;https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1157&quot;&gt;Reviewed and submitted&lt;/a&gt; some pages.&lt;/li&gt;
&lt;li&gt;Carles improved the documentation for building the debian.org Web in
&lt;a href=&quot;https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1154&quot;&gt;MR 1154&lt;/a&gt;
and &lt;a href=&quot;https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1157&quot;&gt;MR 1557&lt;/a&gt;.
Fixed &lt;a href=&quot;https://salsa.debian.org/debian/debian-reference/-/merge_requests/25&quot;&gt;debian-reference&lt;/a&gt;
documentation. Added sections on Mutt Wiki page
(&lt;a href=&quot;https://wiki.debian.org/Mutt#Making_mailto:_protocol_launch_a_terminal_with_Mutt&quot;&gt;handling of mailto&lt;/a&gt;,
&lt;a href=&quot;https://wiki.debian.org/Mutt#Viewing_HTML_message_parts_in_a_web_browser&quot;&gt;viewing HTML parts web browser&lt;/a&gt;),
update and improve &lt;a href=&quot;https://wiki.debian.org/Add%20Bash%20Completion&quot;&gt;bash-completion Wiki page&lt;/a&gt;.
Added a &lt;a href=&quot;https://wiki.debian.org/SignalDesktop#Not_sending.2Freceiving_messages_after_screen_lock&quot;&gt;troubleshooting&lt;/a&gt;
section in Signal Wiki.&lt;/li&gt;
&lt;li&gt;Thorsten did another upload of hplip to fix RC bugs. He also spent some time
taking care of older bugs. Most of the time such bugs had been fixed in a
previous upload but haven’t been closed in the BTS. He also uploaded a new
upstream version of foomatic-db. Last but not least, he gave some user support
with the package epson-inkjet-printer-escpr. There seems to be a new software
available for Epson printers. Unfortunately the license is not compatible with
DFSG and so this software will never make it into Debian.&lt;/li&gt;
&lt;li&gt;During DebCamp 26, the Golang team had a
&lt;a href=&quot;https://wiki.debian.org/DebConf/26/Sprints/DebianGoTeam/&quot;&gt;dedicated Sprint&lt;/a&gt; to
transition the Golang toolchain (namely on dh-golang) to make builds aware of
the module defined upstream with the aim of solving important issues. To help
in these efforts, Santiago &lt;a href=&quot;https://salsa.debian.org/salsa-ci-team/pipeline/-/merge_requests/753&quot;&gt;made changes&lt;/a&gt;
in the Salsa CI pipeline and
&lt;a href=&quot;https://wiki.debian.org/DebConf/26/Sprints/DebianGoTeam/GoModBuilds#Testing_packages_with_Salsa_CI&quot;&gt;documented on how to use it&lt;/a&gt;
to check if a package requires adjustments after the toolchain update.&lt;/li&gt;
&lt;li&gt;Santiago continued co-mentoring Aryan Karamtoth on the Linux livepatching
project, specifically providing feedback about the implementation of
&lt;a href=&quot;https://salsa.debian.org/spaciouskarter78/dlp-tools&quot;&gt;dlp-tools&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Stefano reviewed and merged a migration of Debian reimbursements from
wkhtmltopdf to weasyprint, unblocking an upgrade to Debian trixie.&lt;/li&gt;
&lt;li&gt;Stefano’s cPython upstream merge request
&lt;a href=&quot;https://github.com/python/cpython/pull/152461&quot;&gt;adding multiarch tags to stable ABI extensions&lt;/a&gt;
was finally merged.&lt;/li&gt;
&lt;li&gt;Stefano iterated on his upstream cPython
&lt;a href=&quot;https://github.com/python/cpython/pull/152831&quot;&gt;merge request to add CI coverage&lt;/a&gt;
for Debian’s multi-arch expectations.&lt;/li&gt;
&lt;li&gt;Stefano uploaded Python 3.15.0 beta 4 to Debian experimental.&lt;/li&gt;
&lt;li&gt;Stefano uploaded Python 3.13 to trixie, fixing
&lt;a href=&quot;https://bugs.debian.org/1141977&quot;&gt;a regression in a previous trixie point update&lt;/a&gt; he made.&lt;/li&gt;
&lt;li&gt;Helmut continued to report undeclared file conflicts.&lt;/li&gt;
&lt;li&gt;Helmut sent patches for three cross build failures.&lt;/li&gt;
&lt;li&gt;Helmut proposed a MR to &lt;a href=&quot;https://salsa.debian.org/debian/piuparts/-/merge_requests/81&quot;&gt;port piuparts to pathlib&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Antonio has done quite some work on Debian CI, including rebuilding the
Debian CI armhf/armel worker VMs, and releasing
&lt;a href=&quot;https://tracker.debian.org/news/1772488/accepted-debci-42-source-into-unstable/&quot;&gt;debci 4.2&lt;/a&gt;,
implementing a backup scheme, and several improvements to the codebase such as
improving the incus-lxc backend in preparation for switching to the upcoming
switch to using it by default as announced in the latest
&lt;a href=&quot;https://lists.debian.org/debian-devel-announce/2026/07/msg00003.html&quot;&gt;bits from the ci.debian.net operators&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Emilio helped with transitions, particularly with Python 3.14 as default and
Perl 5.42. During the Perl transition, an issue was identified with how britney
schedules autopkgtests for binNMUs, and that testing was reverted for the time being.&lt;/li&gt;
&lt;li&gt;Colin restructured openssh-* binary packages to better support the upcoming
GSS-API package split.  This caused several autopkgtest regressions in other
packages because openssh-server no longer depends on openssh-client, all of
which have fixes either pending review or merged now.&lt;/li&gt;
&lt;li&gt;Lucas started a discussion around the creation of a Debian packaging video
course for newcomers in the context of the Outreach team.&lt;/li&gt;
&lt;li&gt;Lucas reviewed some contributions to ruby3.4 and provided feedback.&lt;/li&gt;
&lt;li&gt;Anupa worked with Jean-Pierre Giraud on the point release announcements for
Debian 13.6 and Debian 12.15.&lt;/li&gt;
&lt;li&gt;Anupa joined Jean-Pierre Giraud to prepare the Micronews for DebConf 26 press
coverage.&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-11T00:00:00+00:00</dc:date>
	<dc:creator>Anupa Ann Joseph</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-08-10:/2026/08/debconf26-words-from-localteam.html">
	<title>Bits from Debian: DebConf26 Local Team says goodbye</title>
	<link>https://bits.debian.org/2026/08/debconf26-words-from-localteam.html</link>
     <content:encoded>&lt;p&gt;On Saturday 25 July 2026, the annual &lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;Debian Developers and Contributors
Conference&lt;/a&gt; came to a close.  The Debian Press
team would now like to share this personal and beautiful message from the Santa Fe
Local Team.&lt;/p&gt;
&lt;h3&gt;Words from DC26 Local Team&lt;/h3&gt;
&lt;p&gt;DebConf26 is over, and those of us who were part of the Local Team are trying
to return to “normality”, if such a thing exists after organizing a DebConf.&lt;/p&gt;
&lt;p&gt;This event changed our lives and would not have been possible without the help
of many great people.&lt;/p&gt;
&lt;p&gt;We would especially like to thank everyone who became part of our extended
local team. Our endless thanks go to Gunnar —who also instigated this whole
adventure—, Santiago, Nattie, Stefano, and Olasd. Thank you for supporting and
guiding us, sharing your experience, and helping us find solutions throughout
the entire process.&lt;/p&gt;
&lt;p&gt;It was also made possible thanks to the great work, strong support and patience
of international teams: Fundraising, Bursaries, Content, Video, Treasury, Visa,
Website, Accommodation, Front Desk, Cheese and Wine, Publicity as well as all
the other teams and individuals who contributed. We apologize if we have
forgotten to mention anyone; many people helped make this event possible.&lt;/p&gt;
&lt;p&gt;Our deepest thanks also go to everyone who joined us in working on the event,
especially Fer, José, and Julián, who showed great commitment and took
responsibility for several important tasks.&lt;/p&gt;
&lt;p&gt;We would also like to extend our gratitude to FICH, the Universidad Nacional
del Litoral, the institutions, organizations, sponsors, suppliers, and everyone
who contributed in one way or another to welcoming the Debian community to
Santa Fe.&lt;/p&gt;
&lt;p&gt;And finally, a very special thank you to our families, to whom we dedicated
little time these past few weeks, who supported us on this adventure, enduring
the exhaustion, the calls and messages at all hours, and the occasional
stressful situation. Always giving us that much-needed, encouraging hug with so
much love.&lt;/p&gt;
&lt;p&gt;These were very intense weeks, during which we tried to give our best so that
everyone could enjoy their stay and so that the Debian community had the
necessary conditions to meet, work, share knowledge, and continue creating the
magic that characterizes community life and the development of Debian.&lt;/p&gt;
&lt;p&gt;As happens at every DebConf, there were difficulties, unexpected situations,
and challenges that required us to improvise, learn, and perform a few juggling
acts. There were also moments that will certainly remain as memorable
anecdotes: the “antisocial room”, some gas heaters worthy of a museum, and
newly unlocked powers for negotiating with suppliers.&lt;/p&gt;
&lt;p&gt;We have no evidence, but also no doubt, that for many people the Conference
Dinner was one of the best moments of the event.&lt;/p&gt;
&lt;p&gt;A few ingredients we had hoped would happen naturally were missing, such as
more wine nights and at least one in-person football match.&lt;/p&gt;
&lt;p&gt;During the two weeks of DebConf, we experienced every kind of weather and a
wide range of emotions. Above all, however, we saw people enjoying themselves
and building friendships, which fills us with pride.&lt;/p&gt;
&lt;p&gt;Thank you very much to everyone who came and helped DebConf26 leave such a
beautiful mark on our hearts.&lt;/p&gt;
&lt;p&gt;We hope our paths cross again somewhere in life.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Leonardo, Emmanuel, Mariano, Pablo, and Martín
DebConf26 Local Team&lt;/p&gt;
&lt;h3&gt;About Debian&lt;/h3&gt;
&lt;p&gt;The Debian Project was founded in 1993 by Ian Murdock to be a truly free
community project. Since then the project has grown to be one of the
largest and most influential Open Source projects. Thousands of
volunteers from all over the world work together to create and maintain
Debian software. Available in 70 languages, and supporting a huge range
of computer types, Debian calls itself the &lt;em&gt;universal operating system&lt;/em&gt;.&lt;/p&gt;
&lt;h3&gt;About DebConf&lt;/h3&gt;
&lt;p&gt;DebConf is the Debian Project&#39;s developer conference. In addition to a
full schedule of technical, social and policy talks, DebConf provides an
opportunity for developers, contributors and other interested people to
meet in person and work together more closely. It has taken place
annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina,
India, Korea, France. More information about DebConf is available from
&lt;a href=&quot;https://debconf.org&quot;&gt;https://debconf.org/&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Contact Information&lt;/h3&gt;
&lt;p&gt;For further information, please visit the DebConf26 web page at
&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;https://debconf26.debconf.org/&lt;/a&gt; or send
mail to &lt;a href=&quot;https://bits.debian.org/feeds/mailto:press@debian.org&quot;&gt;press@debian.org&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-10T21:50:00+00:00</dc:date>
	<dc:creator>Publicity team and DebConf26 Local Team</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/guardian_scifi_roundup/">
	<title>Jonathan Dowland: time-delayed scifi roundup feed</title>
	<link>https://jmtd.net/log/guardian_scifi_roundup/</link>
     <content:encoded>&lt;p&gt;I enjoy reading The Guardian&#39;s monthly round-up of new SF novels, which can be
found in their &lt;a href=&quot;https://www.theguardian.com/books/science-fiction&quot;&gt;Science Fiction
Books&lt;/a&gt; section, and can also
be read via &lt;a href=&quot;https://www.theguardian.com/books/science-fiction/rss&quot;&gt;feed&lt;/a&gt;.
Since the round-up is of new books, at the time the round-up is published
they&#39;re usually only available in hardback.&lt;/p&gt;

&lt;p&gt;When it comes to choosing a book to read, these days I am tending towards
paperbacks: I&#39;ve largely ran out of room for hardbacks. So I decided to apply
a time delay to their feed. Six months is roughly enough that a
book mentioned in a round-up should be shortly available in paperback.&lt;/p&gt;

&lt;p&gt;The first obstacle was that The Guardian only publish roughly the
last six months of articles in their feed, and so the posts I want have
disappeared. However, my Feed Reader
(&lt;a href=&quot;https://www.freshrss.org/&quot;&gt;FreshRSS&lt;/a&gt;) had older copies stored in
its database, and I am able to re-publish those
using &lt;a href=&quot;https://freshrss.github.io/FreshRSS/en/users/user_queries.html&quot;&gt;User Queries&lt;/a&gt;.
(This also gives me an opportunity to filter out non-roundup articles
from the Guardian&#39;s feed).&lt;/p&gt;

&lt;p&gt;It&#39;s then a nice short piece of scripting (this time, using Ruby) to filter the
republished feed on the publication date. To make the most recent articles appear new, I
also modify the metadata for filtered entries to appear 6 months newer than they are.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;#!/usr/bin/ruby
require &#39;rss&#39;

# replace with the user query feed URI
uri       = &#39;https://www.theguardian.com/books/science-fiction/rss&#39;
now       = Time.now
sixMonths = 6 * 30 * 24 * 60 * 60
feed      = RSS::Parser.parse(uri)

feed.items.select! do |item|
  item.date + sixMonths &amp;lt; now
end
feed.items.collect! do |item|
  item.date += sixMonths
  item
end

puts &quot;Content-Type: text/xml\r\n\r&quot;
puts feed
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;I stuck that up on my private web server, subscribed to it in my FreshRSS
and voila, a time-delayed list of books to read, most likely available in
paperback.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-10T14:44:31+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="tag:blog.kleine-koenig.org,2026-08-10:/ukl/pgp-keysigning-on-linux-plumbers-and-opensource-summit-europe-2026.html">
	<title>Uwe Kleine-König: PGP Keysigning on Linux Plumbers and OpenSource Summit Europe 2026</title>
	<link>https://blog.kleine-koenig.org/ukl/pgp-keysigning-on-linux-plumbers-and-opensource-summit-europe-2026.html</link>
     <content:encoded>&lt;p&gt;I&#39;m going to this year&#39;s &lt;a href=&quot;https://lpc.events/&quot;&gt;LPC&lt;/a&gt; and &lt;a href=&quot;https://sessionize.com/open-source-summit-europe26&quot;&gt;Open Source Summit
Europe&lt;/a&gt; 🥳.&lt;/p&gt;
&lt;p&gt;I will organize sessions on two days after the conference program to exchange
PGP fingerprints for keysigning to improve the kernel&#39;s web-of-trust (but of
course everyone is welcome).&lt;/p&gt;
&lt;p&gt;For details see my &lt;a href=&quot;https://lore.kernel.org/lkml/lpcosse2026-keysigning@baylibre.com/&quot;&gt;announcement on
LKML&lt;/a&gt;. Note
the registration deadline at 2026-09-27 08:00 UTC.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-10T14:37:00+00:00</dc:date>
	<dc:creator>Uwe Kleine-König</dc:creator>
</item> 
<item rdf:about="tag:hashman.ca,2026-08-09:/managing-venvs/">
	<title>Elana Hashman: Managing virtualenvs with a little bash</title>
	<link>https://hashman.ca/managing-venvs/</link>
     <content:encoded>&lt;p&gt;When you need to install something directly from &lt;a href=&quot;https://pypi.org/&quot;&gt;PyPI&lt;/a&gt;, Python virtualenvs have
been my go-to for over a decade.&lt;/p&gt;
&lt;h2&gt;A quick virtualenv intro&lt;/h2&gt;
&lt;p&gt;Most of my readers are probably already familiar with virtualenvs, but for
completeness, I&#39;ll give you a brief introduction. A &lt;a href=&quot;https://docs.python.org/3/library/venv.html&quot;&gt;virtualenv&lt;/a&gt; (short for
&quot;virtual environment&quot;) is an isolated distribution of Python packages, where
you can independently install packages without disturbing your system packages
or other virtualenvs.&lt;/p&gt;
&lt;p&gt;You can set one up like this, assuming you are using Python 3.3 or higher:&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;python3&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;-m&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;venv&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;~/.venv/my-virtualenv
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The directory specified here is just a convention. I keep all my virtualenvs in
the &lt;code&gt;.venv&lt;/code&gt; folder in my home directory, but you can pick whatever location you
like.&lt;/p&gt;
&lt;p&gt;To use the virtualenv, you must activate it:&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class=&quot;nb&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;~/.venv/my-virtualenv/bin/activate
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This activation script is a special shell script that configures your current
shell, pointing at all the right paths in order to use the virtual environment.
&lt;a href=&quot;https://www.gnu.org/software/bash/manual/bash.html#index-_002e&quot;&gt;&lt;code&gt;source&lt;/code&gt;&lt;/a&gt; runs this script in your current shell session to set it
up. You will notice that this adds &lt;code&gt;(my-virtualenv)&lt;/code&gt; to the beginning of your
shell prompt, reminding you that the &quot;my-virtualenv&quot; virtualenv is active. Now
when you &lt;code&gt;pip install amazing-package&lt;/code&gt;, the software will only be available in
this virtual environment.&lt;/p&gt;
&lt;p&gt;When you&#39;re done, you can deactivate it like so:&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;deactivate
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Wonderful!&lt;/p&gt;
&lt;h2&gt;Managing many virtualenvs gets annoying&lt;/h2&gt;
&lt;p&gt;Over time, I end up accumulating many virtualenvs, which can become harder to
manage. Maybe something like this:&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;ls&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;~/.venv/
my-virtualenv&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;cool-project&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;snakes-ahoy
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;I also don&#39;t want to type &lt;code&gt;source ~/.venv/my-virtualenv/bin/activate&lt;/code&gt; every
time I use the virtualenv, because it gets very repetitive—only the name
of the venv is really needed.&lt;/p&gt;
&lt;p&gt;But luckily, we can write a little bit of bash to make managing this less
annoying. (Or you can use one of many Python developer tools that are designed
to manage this, like &lt;a href=&quot;https://pipx.pypa.io/latest/index.html&quot;&gt;pipx&lt;/a&gt;, but when I merely want to &lt;em&gt;consume&lt;/em&gt; Python
software, I might not have a development environment set up. So that&#39;s beyond
the scope of this post!)&lt;/p&gt;
&lt;p&gt;If you add the following shell function to your &lt;code&gt;~/.bashrc&lt;/code&gt; or
&lt;code&gt;~/.bash_aliases&lt;/code&gt; file, it will nicely wrap our activation command:&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;setup-venv&lt;span class=&quot;o&quot;&gt;()&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;w&quot;&gt;        &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$HOME&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;/.venv/&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$1&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;/bin/activate&quot;&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Now all we need to run is&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;setup-venv&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;my-virtualenv
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;So much quicker!&lt;/p&gt;
&lt;h2&gt;Spicing it up with tab completion&lt;/h2&gt;
&lt;p&gt;The first thing I noticed after writing this wrapper was that I started hitting
tab on the virtual environment name, but... nothing happened. Wouldn&#39;t it be
nice to know what virtualenvs I had available, and to not have to type out the
whole long thing?&lt;/p&gt;
&lt;p&gt;Well, we can write it ourselves 😄&lt;/p&gt;
&lt;p&gt;If for some reason you don&#39;t already have bash completion installed, on a
Debian-based system, you will need to install it with&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;apt&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;install&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;bash-completion
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;In order to configure our &lt;a href=&quot;https://www.gnu.org/software/bash/manual/html_node/Programmable-Completion.html&quot;&gt;bash completion&lt;/a&gt;, we will create a new file,
&lt;code&gt;/etc/bash_completion.d/venv&lt;/code&gt;, with the following contents:&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;_list_venvs&lt;span class=&quot;o&quot;&gt;()&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;local&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;cur&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;prev&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;opts
&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;COMPREPLY&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=()&lt;/span&gt;
&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;cur&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;COMP_WORDS&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[COMP_CWORD]&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;
&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;prev&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;COMP_WORDS&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[COMP_CWORD-1]&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;
&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;opts&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;$(&lt;/span&gt;find&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$HOME&lt;/span&gt;/.venv/&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;-mindepth&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;-maxdepth&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;-type&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;d&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;-printf&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;%f &quot;&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;COMPREPLY&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=(&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;k&quot;&gt;$(&lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;compgen&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;-W&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;opts&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;--&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;si&quot;&gt;${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;cur&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;&lt;span class=&quot;k&quot;&gt;return&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;0&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;nb&quot;&gt;complete&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;-F&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;_list_venvs&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;setup-venv
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This file defines another shell function order to determine how to
autocomplete the options for our &lt;code&gt;setup-venv&lt;/code&gt; function.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;$opts&lt;/code&gt; is where we define the options for our function. We generate it with a
&lt;code&gt;find&lt;/code&gt; command—looking at the &lt;code&gt;.venv&lt;/code&gt; folder in the current user&#39;s home
directory, then only including child folders (excluding the current directory
itself, &lt;code&gt;.venv&lt;/code&gt;, in our results) by using the min/max depth and type arguments,
and printing just the individual directory names, deliminated by spaces using
our print formatter.&lt;/p&gt;
&lt;p&gt;Everything else is the standard scaffolding required to use bash completions.&lt;/p&gt;
&lt;p&gt;Once you save this file and reload your shell, you&#39;ll see that you are able to use completions as expected!&lt;/p&gt;
&lt;div class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;setup-venv&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&amp;lt;tab&amp;gt;
my-virtualenv&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;cool-project&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;snakes-ahoy

setup-venv&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;s&amp;lt;tab&amp;gt;
setup-venv&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;snakes-ahoy
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h2&gt;Complaints, comments, questions?&lt;/h2&gt;
&lt;p&gt;Hope this was helpful! If it wasn&#39;t, that&#39;s too bad. But don&#39;t worry—you
can safely ignore this post.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-09T20:00:00+00:00</dc:date>
	<dc:creator>Elana Hashman</dc:creator>
</item> 
<item rdf:about="https://reproducible-builds.org/reports/2026-07/">
	<title>Reproducible Builds: Reproducible Builds in July 2026</title>
	<link>https://reproducible-builds.org/reports/2026-07/</link>
     <content:encoded>&lt;p class=&quot;lead&quot;&gt;&lt;strong&gt;Welcome to the July 2026 report from the &lt;a href=&quot;https://reproducible-builds.org&quot;&gt;Reproducible Builds&lt;/a&gt; project!&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://reproducible-builds.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/reproducible-builds.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In our reports, we try to outline the most important things that we have been up to over the past month. As a quick recap about what problem our project intends to solve, whilst anyone may inspect the source code of free software for malicious flaws, almost all software is distributed to end users as pre-compiled binaries. The motivation behind the reproducible builds effort is to ensure no flaws have been introduced during this compilation process by promising identical results are always generated from a given source, thus allowing multiple third-parties to come to a consensus on whether a build was compromised or not.&lt;/p&gt;

&lt;p&gt;If you are interested in contributing to the project, please visit the &lt;a href=&quot;https://reproducible-builds.org/contribute/&quot;&gt;&lt;em&gt;Contribute&lt;/em&gt;&lt;/a&gt; page on our website.&lt;/p&gt;

&lt;p&gt;In this month’s report, we cover:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#tool-development&quot;&gt;Tool development&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#distribution-work&quot;&gt;Distribution work&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#three-new-scholarly-papers&quot;&gt;Three new scholarly papers&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#patches&quot;&gt;Patches&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://reproducible-builds.org/blog/index.rss#misc-news&quot;&gt;Misc news&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;hr /&gt;

&lt;h3 id=&quot;tool-development&quot;&gt;Tool development&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://diffoscope.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/diffoscope.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://diffoscope.org&quot;&gt;&lt;strong&gt;diffoscope&lt;/strong&gt;&lt;/a&gt; is our in-depth and content-aware diff utility that can locate and diagnose reproducibility issues. This month, Chris Lamb made the following changes, including preparing and uploading versions &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;324&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;325&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;326&lt;/code&gt; to Debian:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Fix tests to work with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zipdetails&lt;/code&gt; 4.0008. (&lt;a href=&quot;https://bugs.debian.org/1141359&quot;&gt;#1141359&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;Bump debhelper compatibility level to 13. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/474f3702&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Update copyright years. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/4cde19a5&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In addition, Paul Spooren made changes to allow trailing garbage in Gzip files [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/c8dcbf4a&quot;&gt;…&lt;/a&gt;] and Vagrant Cascadian added an external tool reference for the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pedump&lt;/code&gt; binary to use the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mono&lt;/code&gt; package under &lt;a href=&quot;https://guix.gnu.org/&quot;&gt;GNU Guix&lt;/a&gt;. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/diffoscope/commit/b79afa9e&quot;&gt;…&lt;/a&gt;]&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/disorderfs&quot;&gt;&lt;strong&gt;disorderfs&lt;/strong&gt;&lt;/a&gt; is our &lt;a href=&quot;https://en.wikipedia.org/wiki/Filesystem_in_Userspace&quot;&gt;FUSE&lt;/a&gt;-based filesystem that deliberately introduces non-determinism into system calls to reliably flush out reproducibility issues. This month, Christelle Gloor added the option to sort by &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ctime&lt;/code&gt; as returned by the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lstat(2)&lt;/code&gt; &lt;a href=&quot;https://en.wikipedia.org/wiki/System_call&quot;&gt;syscall&lt;/a&gt;. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/disorderfs/commit/68d20f7&quot;&gt;…&lt;/a&gt;], which Chris Lamb uploaded whilst bumping the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Standards-Version&lt;/code&gt; to version 4.7.4 [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/disorderfs/commit/240fae0&quot;&gt;…&lt;/a&gt;]. Bernhard Wiedemann also &lt;a href=&quot;https://build.opensuse.org/request/show/1368149&quot;&gt;updated &lt;em&gt;disorderfs&lt;/em&gt; to version 0.7.0&lt;/a&gt; in &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://reproducible-builds.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/website.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Yet again, there were a number of improvements made to &lt;a href=&quot;https://reproducible-builds.org/&quot;&gt;&lt;strong&gt;our website&lt;/strong&gt;&lt;/a&gt; this month as well. For example, Chris Lamb, by request of &lt;a href=&quot;https://www.digitalocean.com/&quot;&gt;Digital Ocean&lt;/a&gt;, changed the target of a referral link so that they can manage incoming referrers [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/4ac1b2fa&quot;&gt;…&lt;/a&gt;] and pushed a number of changes to the &lt;a href=&quot;https://reproducible-builds.org/tools/&quot;&gt;&lt;em&gt;Tools&lt;/em&gt;&lt;/a&gt; page [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-website/commit/3e3154f2&quot;&gt;…&lt;/a&gt;].&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;distribution-work&quot;&gt;Distribution work&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://debian.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/debian.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In &lt;strong&gt;Debian&lt;/strong&gt; this month, 32 reviews of Debian packages were added, 26 were updated and a total of 21 were removed this month, adding to &lt;a href=&quot;https://tests.reproducible-builds.org/debian/index_issues.html&quot;&gt;our extensive knowledge about identified issues&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;A number of issue types were added by Chris Lamb, including:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;python_towncrier_build_date&lt;/code&gt; [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/83a0efd3&quot;&gt;…&lt;/a&gt;][&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/6f036b2a&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log_files_installed_in_package&lt;/code&gt; [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/c629afdf&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fontforge_varies_by_timezone&lt;/code&gt; [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/d76c0f05&quot;&gt;…&lt;/a&gt;][&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/fc4a9fc5&quot;&gt;…&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Chris also added a further note for the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;build_date_in_manpage_generated_by_spf13_cobra&lt;/code&gt; issue. [&lt;a href=&quot;https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/f7b69082&quot;&gt;…&lt;/a&gt;]&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://openwrt.org/&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/openwrt.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In addition, there is &lt;a href=&quot;https://rebuilderd.n.aparcar.org/?distro=openwrt-image&quot;&gt;a new page showing verification rebuilds&lt;/a&gt; of &lt;a href=&quot;https://openwrt.org/&quot;&gt;OpenWrt&lt;/a&gt; APK packages and firmware images, powered by &lt;a href=&quot;https://github.com/kpcyrd/rebuilderd&quot;&gt;&lt;em&gt;rebuilderd&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://rebuilderd.n.aparcar.org/?distro=openwrt-image&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/openwrt-rebuilderd.png#center&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;three-new-scholarly-papers&quot;&gt;Three new scholarly papers&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;https://ieeexplore.ieee.org/abstract/document/11593337&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/paper-vcaligner.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Yan Li, Nan Jiang, Qihang Zhou, Shaowen Xu, Yamin Xie and Xiaoqi Jia of the &lt;a href=&quot;https://english.cas.cn/&quot;&gt;Chinese Academy of Sciences&lt;/a&gt; published a paper titled &lt;a href=&quot;https://ieeexplore.ieee.org/abstract/document/11593337&quot;&gt;&lt;em&gt;VCAligner: Aligning Source Distribution Versions with Upstream Git Commits to Secure Supply Chain&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;We present VCAligner, a content-based alignment methodology that constructs inverted indexes over VCS histories to precisely map released artifacts to their originating commits, independent of fragile version tags. We evaluated VCAligner on a dataset of 2,984 verifiable PyPI packages derived from the 4,000 most-downloaded projects linked to public GitHub upstreams. &lt;strong&gt;Our results reveal a critical weakness in conventional tag-based heuristics: while they appear effective on 85% of the dataset, the residual 15% failure rate generates a catastrophic downstream audit workload of over 10.3 million commits. In contrast, VCAligner reduces this burden by two orders of magnitude (≈ 158×), bounding the total workload to under 65,000 commits.&lt;/strong&gt; Furthermore, we provide the large-scale characterization of “Packaging Noise,” classifying artifact divergence into structural additions (Path Phantoms) and content mutations (Blob Phantoms), thereby isolating the distinct attack surfaces of malicious injection and code tampering.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://doi.org/10.48550/ARXIV.2607.21888&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/paper-snakeoil.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Jens Dietrich and Spencer Sun from the &lt;a href=&quot;https://www.wgtn.ac.nz/&quot;&gt;Victoria University of Wellington&lt;/a&gt; together with Tim W. White and Behnaz Hassanshahi from &lt;a href=&quot;https://www.oracle.com&quot;&gt;Oracle Inc&lt;/a&gt; pre-published their paper &lt;a href=&quot;https://arxiv.org/pdf/2607.21888&quot;&gt;&lt;em&gt;No Snake Oil: Verifying Python Package Builds&lt;/em&gt;&lt;/a&gt; (PDF):&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Python has become the default language for interacting with AI, with packages being distributed through registries like the Python Package Index (PyPI). This creates a need to analyse supply chains comprising such packages. One such analysis is to rebuild packages in order to identify compromised builds injecting malware. Independent rebuilds in hardened environments have the added advantage that they can generate and record provenance in order to increase the trustworthiness of packages. Two tools that are designed to automate such rebuilds and run them at scale are macaron and oss-rebuild. We study 12,180 popular releases from PyPI and find that the byte-for-byte equivalence rate is generally low. We analyse the reasons why they produce different wheels, and find that equivalence between the original and rebuilt wheels can often still be established, preserving most of the guarantees users expect from rebuildable releases. We present and evaluate daleq4py, a tool to establish the equivalence of Python wheels through the kernel of a normalisation function that is based on provenance-preserving datalog rules. Experimental results show that daleq4py substantially expands the set of rebuilds that can be accepted as equivalent. &lt;strong&gt;Although only 15.4% of macaron rebuilds and 19.1% of oss-rebuild rebuilds are byte-for-byte identical to the published PyPI wheels, daleq4py establishes wheel equivalence for 60.2% and 78.9% of source-equivalent rebuilds, respectively.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://arxiv.org/abs/2607.01890&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;https://reproducible-builds.org/images/reports/2026-07/paper-fdroid.png#right&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Denise Nanni, Julien Malka, Stefano Zacchiroli and Théo Zimmermann from &lt;a href=&quot;https://www.telecom-paris.fr/en/home&quot;&gt;Télécom Paris&lt;/a&gt; together with Gabriele D’Angelo from the &lt;a href=&quot;https://www.unibo.it/en/homepage&quot;&gt;University of Bologna&lt;/a&gt; pre-published their paper &lt;a href=&quot;https://arxiv.org/pdf/2607.01890&quot;&gt;&lt;em&gt;Understanding Build Reproducibility in the F-Droid Ecosystem&lt;/em&gt;&lt;/a&gt; (PDF), which was accepted at the &lt;a href=&quot;https://acm-rep.github.io/2026/accepted/&quot;&gt;2026 ACM Conference on Reproducibility and Replicability&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;The security of open source applications benefits considerably from the possibility of rebuilding their source and verifying the output. F-Droid, a prominent distribution for open source Android applications, systematically rebuilds them from source and tests their bitwise reproducibility at app publishing time. However, F-Droid offers no guarantee that app reproducibility will continue to hold in the future. As software ecosystems evolve, reproducibility may degrade, with potential negative consequences for software preservation and security. We present the first empirical study of build reproducibility in the F-Droid app ecosystem. Analyzing historical reproducibility logs, we find that the overall bitwise reproducibility rate has been steadily increasing over time (as new versions of apps are published). We then evaluate how reproducibility holds in time for fixed app versions, by attempting to rebuild 18 904 app versions that F-Droid had previously confirmed bitwise reproducible, published between September 2018 and February 2026, &lt;strong&gt;achieving an 83% rebuild success rate, and identify missing dependencies as the dominant cause of failure, accounting for 76% of non-rebuildable cases. Among successfully rebuilt apps, 94% are also bitwise reproducible&lt;/strong&gt;-i.e., they still yield bitwise identical artifacts upon rebuild. Together, these results show that while bitwise reproducibility largely holds for apps that can be rebuilt, rebuildability itself is highly sensitive to temporal decay.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;patches&quot;&gt;Patches&lt;/h3&gt;

&lt;p&gt;The Reproducible Builds project detects, dissects and attempts to fix as many currently-unreproducible packages as possible. We endeavour to send all of our patches upstream where applicable or possible. This month, we wrote a large number of such patches, including:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/thread/JLAOJP7W6K3P2SL6XT6UYX444XZ5WQPN/&quot;&gt;openSUSE monthly&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Arnout Engelen:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/apache/ant-ivy/pull/127&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ivy&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/apache/pekko-grpc/pull/746&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pekko-grpc&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/sbt/ivy/pull/51&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sbt-ivy&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/scala/scala3/pull/26510&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;scala&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Bernhard M. Wiedemann:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1364030&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;angelfish&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/python/cpython/pull/154988&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cpython&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://git.enlightenment.org/enlightenment/efl/pulls/133&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;efl&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/erlang/otp/issues/4417#issuecomment-5105267295&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;erlang+ex_doc&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1368578&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;eww/glib-macros&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/intel/intel-graphics-compiler/pull/418&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;intel-graphics-compiler&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1368181&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;java-11-openjdk&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1368181&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;java-17-openjdk&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1368504&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;java-1_8_0-openjdk&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugzilla.opensuse.org/show_bug.cgi?id=1221224&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;java-21-openjdk&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://gitlab.winehq.org/mono/mono/-/work_items/33&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mono-core&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://github.com/medek/nasm-rs/pull/47&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nasm/rav1e&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1364286&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;python-langsmith&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1364231&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zathura*&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://build.opensuse.org/request/show/1368243&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zig0.15&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Chris Lamb:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141505&quot;&gt;#1141505&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/golang-github-tidwall-wal&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;golang-github-tidwall-wal&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141506&quot;&gt;#1141506&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/lightproof&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lightproof&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141582&quot;&gt;#1141582&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/libslow5lib&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libslow5lib&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141687&quot;&gt;#1141687&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/siso&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;siso&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141841&quot;&gt;#1141841&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/grout&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;grout&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142126&quot;&gt;#1142126&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/libpsl&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libpsl&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142492&quot;&gt;#1142492&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/node-grunt-contrib-internal&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;node-grunt-contrib-internal&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142495&quot;&gt;#1142495&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/fontforge&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fontforge&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142496&quot;&gt;#1142496&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/spopt&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;spopt&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142887&quot;&gt;#1142887&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/go-dlib&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;go-dlib&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1143147&quot;&gt;#1143147&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/towncrier&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;towncrier&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Jochen Sprickerhof:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141412&quot;&gt;#1141412&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/python-sphinx-chango&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;python-sphinx-chango&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141553&quot;&gt;#1141553&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/gasnet&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gasnet&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141577&quot;&gt;#1141577&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/yubihsm-connector&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;yubihsm-connector&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1141663&quot;&gt;#1141663&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/dh-fortran&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dh-fortran&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142000&quot;&gt;#1142000&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/watcher&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;watcher&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142001&quot;&gt;#1142001&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/rakudo&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rakudo&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142128&quot;&gt;#1142128&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/kf6-breeze-icons&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;kf6-breeze-icons&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142141&quot;&gt;#1142141&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/oxygen-icons&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;oxygen-icons&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142256&quot;&gt;#1142256&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/gnu-apl&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gnu-apl&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1142513&quot;&gt;#1142513&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/barvinok&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;barvinok&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/1143169&quot;&gt;#1143169&lt;/a&gt; filed against &lt;a href=&quot;https://tracker.debian.org/pkg/ecbuild&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ecbuild&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id=&quot;misc-news&quot;&gt;Misc news&lt;/h3&gt;

&lt;p&gt;On &lt;a href=&quot;https://lists.reproducible-builds.org/listinfo/rb-general/&quot;&gt;our mailing list&lt;/a&gt; this month, Colin Winter of &lt;a href=&quot;https://markovianprotocol.com/&quot;&gt;Markovian Protocol&lt;/a&gt; wrote to our mailing list on the topic of &lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-July/004133.html&quot;&gt;&lt;em&gt;Reproducible verification for retained logs&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Reproducible builds remove trust in the builder: anyone re-derives the same artifact from the same source, byte for byte. The same shape applies one layer over, to a retained record. Most record-keeping regimes (the &lt;a href=&quot;https://artificialintelligenceact.eu/article/12/&quot;&gt;EU AI Act’s Article 12&lt;/a&gt; logging is the current example) require that events be recorded and logs retained, but not that a retained log be verifiable, by a party who was not present, as unaltered and existing when claimed. That leaves an integrity obligation resting on trusting the party being audited.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;(&lt;a href=&quot;https://lists.reproducible-builds.org/pipermail/rb-general/2026-July/thread.html#4133&quot;&gt;Full thread&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Finally, if you are interested in contributing to the Reproducible Builds project, please visit our &lt;a href=&quot;https://reproducible-builds.org/contribute/&quot;&gt;&lt;em&gt;Contribute&lt;/em&gt;&lt;/a&gt; page on our website. However, you can get in touch with us via:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;IRC: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;#reproducible-builds&lt;/code&gt; on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;irc.oftc.net&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mastodon: &lt;a href=&quot;https://fosstodon.org/@reproducible_builds&quot;&gt;@reproducible_builds@fosstodon.org&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mailing list: &lt;a href=&quot;https://lists.reproducible-builds.org/listinfo/rb-general&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rb-general@lists.reproducible-builds.org&lt;/code&gt;&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-09T19:12:10+00:00</dc:date>
	<dc:creator>Reproducible Builds</dc:creator>
</item> 
<item rdf:about="http://blog.alteholz.eu/?p=2842">
	<title>Thorsten Alteholz: My Debian Activities in July 2026</title>
	<link>http://blog.alteholz.eu/2026/08/my-debian-activities-in-july-2026/</link>
     <content:encoded>&lt;h3&gt;&lt;strong&gt;Debian LTS/ELTS&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This was my hundred-forty-fifth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
&lt;/p&gt;
&lt;p&gt;
During my allocated time I uploaded or worked on:  
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-security-announce/2026/msg00313.html&quot;&gt;DSA 6402-1&lt;/a&gt;] hplip security update to fix two CVEs in Trixie related to privilege escalation and/or arbitrary code execution. I sent the debdiff to the security team, which resulted in this DSA.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142351&quot;&gt;#1142351&lt;/a&gt;] trixie-pu of libnfs has been uploaded.&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/07/msg00031.html&quot;&gt;DLA 4689-1&lt;/a&gt;]  libnfs security update to fix one CVE in Bookworm and Bullseye related to an integer overflow.
&lt;/li&gt;&lt;li&gt;[&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/07/msg00041.html&quot;&gt;DLA 4699-1&lt;/a&gt;] hplip security update to fix two CVEs in Bookworm and Bullseye related to privilege escalation and/or arbitrary code execution.
&lt;/li&gt;&lt;li&gt;[ELA-1775-1] libnfs gimp security update to fix one CVE in Buster and Stretch related to an integer overflow.&lt;/li&gt;&lt;li&gt;[ELA-1784-1] hplip security update to fix two CVEs in Buster and Stretch related to privilege escalation and/or arbitrary code execution.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;
Unfortunately the number of assigned hours was rather low this month. So besides doing some days of FD at the end of the month, where I also had to process a new package list for ELTS, and a review of the rsync package (prepared by Sylvain), not much happened here.
&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Printing&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream versions:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/hplip&quot;&gt;hplip&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/foomatic-db&quot;&gt;foomatic-db&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;Besides the package upload, I also took care of some older bugs of hplip.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://www.freexian.com&quot;&gt;Freexian&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Lomiri&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This month I continued the upload of lomiri packages with new upstream versions. Thanks to the help of my other colleagues, this project could be finished now.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href=&quot;https://freiesoftware.gmbh/&quot;&gt;Fre(i)e Software GmbH&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Astro&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/fxload&quot;&gt;fxload&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/indi-orion-ssg3&quot;&gt;indi-orion-ssg3&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/calceph&quot;&gt;calceph&lt;/a&gt; to unstable (sponsored upload).&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;Debian IoT&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;Unfortunately I had no time to work in this category this month.&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Mobcom&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/libgsm&quot;&gt;libgsm&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/libosmocore&quot;&gt;libosmocore&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/libosmo-cc&quot;&gt;libosmo-cc&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;Next month I intend to upload new upstream versions of all Osmocom packages. As far as I can tell, these uploads will happen without soname changes. I like that :-).&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;misc&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/usb-modeswitch&quot;&gt;usb-modeswitch&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/ta-lib&quot;&gt;ta-lib&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/lua-geoip&quot;&gt;lua-geoip&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/lua-systemd&quot;&gt;lua-systemd&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/displaylink-driver&quot;&gt;displaylink-driver&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href=&quot;https://tracker.debian.org/nuspell&quot;&gt;nuspell&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-07T17:02:01+00:00</dc:date>
	<dc:creator>alteholz</dc:creator>
</item> 
<item rdf:about="https://diffoscope.org/news/diffoscope-327-released/">
	<title>Reproducible Builds (diffoscope): diffoscope 327 released</title>
	<link>https://diffoscope.org/news/diffoscope-327-released/</link>
     <content:encoded>&lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;327&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[ Colin Watson ]
* Handle missing openssh-client binaries in autopkgtests.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href=&quot;https://diffoscope.org&quot;&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-07T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds (diffoscope)</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-08-06:/2026/08/debconf26-closes.html">
	<title>Bits from Debian: DebConf26 closes in Santa Fe and DebConf27 announced</title>
	<link>https://bits.debian.org/2026/08/debconf26-closes.html</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://wiki.debian.org/DebConf/26/Photos?action=AttachFile&amp;amp;do=view&amp;amp;target=debconf26-group-photo.jpg&quot;&gt;&lt;img alt=&quot;DebConf26 group photo - click to enlarge&quot; src=&quot;https://bits.debian.org/images/debconf26-group-photo_small.jpg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;On Saturday 25 July 2026, the annual &lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;Debian Developers and Contributors
Conference&lt;/a&gt; came to a close.
Over 270 attendees representing 35 countries from around the world came
together for a combined 90 events (including some which took place during
the DebCamp) including more than 27 Talks, 21 Short Talks,
29 Birds of a Feather sessions (&quot;BoF&quot; – informal meeting between developers
and users), 8 workshops, and activities in support of furthering our
distribution and free software, learning from our mentors and peers, building
our community, and having a bit of fun.&lt;/p&gt;
&lt;p&gt;The conference was preceded by the annual
&lt;a href=&quot;https://wiki.debian.org/DebCamp&quot;&gt;DebCamp&lt;/a&gt; hacking session held 13
through 19 July where Debian Developers and Contributors convened to
focus on their individual Debian-related projects or work in team sprints
geared toward in-person collaboration in developing Debian.&lt;/p&gt;
&lt;p&gt;As has been the case for several years, a special effort has been made to
welcome newcomers and help them become familiar with Debian and DebConf
by organizing a sprint &quot;New Contributors Onboarding&quot; every day of Debcamp,
followed more informally by mentorship during DebConf. Half a dozen new
contributors joined the sessions and learned about Debian, free software,
packaging and much more.&lt;/p&gt;
&lt;p&gt;This year, a week-long DebCamp session was dedicated to auditing,
patching, and modernizing the Go ecosystem in Debian and enable the
transition triggered by the recent upload of dh-golang enabling GO111MODULE=on
by default in Experimental.&lt;/p&gt;
&lt;p&gt;In order to make the conference more accessible for local participants,
a local language track was included in the schedule for talks in Spanish,
as was done at DebConf19 in Brazil.&lt;/p&gt;
&lt;p&gt;The actual Debian Developers Conference started on Monday 20 July 2026.&lt;/p&gt;
&lt;p&gt;In addition to the traditional &quot;Bits from the DPL&quot; talk, the continuous
key-signing party, lightning talks, and the announcement of next year&#39;s
DebConf27, there were several update sessions shared by internal projects
and teams.&lt;/p&gt;
&lt;p&gt;Many of the hosted discussion sessions were presented by our technical
core teams with the usual and useful &quot;Meet the Technical Committee&quot;, three
talks about Linux Kernel, early boot and improving Debian’s kernel and
installer support for Chromebooks, and about twenty BoFs and talks about
Debian packaging policy, Debian infrastructure, security and privacy.&lt;/p&gt;
&lt;p&gt;This year, and echoing ongoing discussions within the Free Software community,
Artificial Intelligence and Age Verification have been the subject of
several talks. The Python, Perl, Ruby, Go, and Rust programming
language teams also shared updates on their work and efforts.&lt;/p&gt;
&lt;p&gt;More than 17 BoFs and talks about community, diversity, and local outreach
highlighted the work of various teams involved in not just the technical but
also the social aspect of our community&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://debconf26.debconf.org/schedule/&quot;&gt;schedule&lt;/a&gt;
was updated each day with planned and ad hoc activities introduced by
attendees over the course of the conference. Several traditional activities
took place: a poetry performance, the traditional Cheese and Wine party, the
Group Photos, and the Day Trip.&lt;/p&gt;
&lt;p&gt;For those who were not able to attend, most of the talks and sessions were
broadcasted live and recorded. One can find the seventy hours of recorded
videos available via the conference
&lt;a href=&quot;https://debconf26.debconf.org/schedule/&quot;&gt;schedule&lt;/a&gt;,
or alternatively through this
&lt;a href=&quot;https://meetings-archive.debian.net/pub/debian-meetings/2026/DebConf26/&quot;&gt;link&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Almost all of the sessions facilitated remote participation via IRC and Matrix
messaging apps or online collaborative text documents which allowed remote
attendees to &quot;be in the room&quot; and ask questions or share comments with the
speaker or assembled audience. DebConf26 saw over 341 T-shirts, a day trip,
and up to 130 meals planned per day.&lt;/p&gt;
&lt;p&gt;All of these events, activities, conversations, and streams coupled with our
love, interest, and participation in Debian and F/OSS certainly made this
conference an overall success both here in Santa Fe, Argentina and online
around the world.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf26 website&lt;/a&gt;
will remain active for archival purposes and will continue to offer
links to the presentations and videos of talks and events.&lt;/p&gt;
&lt;p&gt;Next year, &lt;a href=&quot;https://wiki.debian.org/DebConf/27&quot;&gt;DebConf27&lt;/a&gt; will be held
in Asahikawa, Hokkaido, Japan, from Sunday September 5th to Saturday
September 11th, 2027. As tradition follows before the next DebConf the
local organizers in Japan will start the conference activities with DebCamp
with a particular focus on individual and team work towards improving the
distribution.&lt;/p&gt;
&lt;p&gt;DebConf is committed to a safe and welcome environment for all
participants. See the
&lt;a href=&quot;https://debconf26.debconf.org/about/coc/&quot;&gt;web page about the Code of Conduct on the DebConf26 website&lt;/a&gt;
for more details on this.&lt;/p&gt;
&lt;p&gt;Debian thanks the commitment of numerous
&lt;a href=&quot;https://debconf26.debconf.org/sponsors/&quot;&gt;sponsors&lt;/a&gt;
to support DebConf26, particularly our Platinum Sponsors:
&lt;a href=&quot;https://www.infomaniak.com&quot;&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt;, and
&lt;a href=&quot;https://www.proxmox.com/&quot;&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt;,
and our Gold Sponsors : &lt;a href=&quot;https://www.freexian.com/&quot;&gt;&lt;strong&gt;Freexian&lt;/strong&gt;&lt;/a&gt;, and
&lt;a href=&quot;https://www.viridiengroup.com&quot;&gt;&lt;strong&gt;Viridien&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We also wish to thank our Video and Infrastructure teams, the DebConf26
and DebConf committees, our host nation of Argentina, and each and every
person who helped contribute to this event and to Debian overall.
Thank you all for your work in helping Debian continue to be &quot;The Universal
Operating System&quot;.&lt;/p&gt;
&lt;p&gt;See you next year!&lt;/p&gt;
&lt;h3&gt;About Debian&lt;/h3&gt;
&lt;p&gt;The Debian Project was founded in 1993 by Ian Murdock to be a truly free
community project. Since then the project has grown to be one of the
largest and most influential Open Source projects. Thousands of
volunteers from all over the world work together to create and maintain
Debian software. Available in 70 languages, and supporting a huge range
of computer types, Debian calls itself the &lt;em&gt;universal operating system&lt;/em&gt;.&lt;/p&gt;
&lt;h3&gt;About DebConf&lt;/h3&gt;
&lt;p&gt;DebConf is the Debian Project&#39;s developer conference. In addition to a
full schedule of technical, social and policy talks, DebConf provides an
opportunity for developers, contributors and other interested people to
meet in person and work together more closely. It has taken place
annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina,
India, Korea, France. More information about DebConf is available from
&lt;a href=&quot;https://debconf.org&quot;&gt;https://debconf.org/&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;About Infomaniak&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://www.infomaniak.com&quot;&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt; is an independent, employee-owned
Swiss technology company that designs, develops, and operates its own cloud
infrastructure and digital services entirely in Switzerland. With over
300 employees — more than 70% engineers and developers — the company reinvests
all profits into R&amp;amp;D. Its public cloud is built on OpenStack, with managed
Kubernetes, Database as a Service, object storage, and sovereign AI services
accessible via OpenAI-compatible APIs, all running on its own Swiss
infrastructure. Infomaniak also develops a sovereign collaborative suite —
messaging, email, storage, online office tools, videoconferencing, and a
built-in AI assistant — developed in-house and as a privacy-respecting
solution to proprietary platforms. Open source is central to how Infomaniak
operates. Its latest data center (D4) runs on 100% renewable energy and uses
no traditional cooling: all the heat generated by its servers is captured and
fed into Geneva&#39;s district heating network, supplying up to 6,000 homes in
winter and hot water year-round. The entire project has been documented and
open-sourced at &lt;a href=&quot;https://d4project.org/&quot;&gt;d4project.org&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;About Proxmox&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://www.proxmox.com/&quot;&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt; develops powerful, yet easy-to-use
open-source server solutions. The comprehensive open-source ecosystem is
designed to manage divers IT landscapes, from single servers to large-scale
distributed data centers. Our unified platform integrates server
virtualization, easy backup, and rock-solid email security ensuring seamless
interoperability across the entire portfolio. With the Proxmox Datacenter
Manager, the ecosystem also offers a &quot;single pane of glass&quot; for centralized
management across different locations. Since 2005, all Proxmox solutions have
been built on the rock-solid Debian platform. We are proud to return to
DebConf26 as a sponsor because the Debian community provides the foundation
that makes our work possible. We believe in keeping IT simple, open, and under
your control.&lt;/p&gt;
&lt;h3&gt;Contact Information&lt;/h3&gt;
&lt;p&gt;For further information, please visit the DebConf26 web page at
&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;https://debconf26.debconf.org/&lt;/a&gt; or send
mail to &lt;a href=&quot;https://bits.debian.org/feeds/mailto:press@debian.org&quot;&gt;press@debian.org&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-06T21:50:00+00:00</dc:date>
	<dc:creator>Debian Publicity Team and Volunteers</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6267">
	<title>Russell Coker: TV Control etc</title>
	<link>https://etbe.coker.com.au/2026/08/06/tv-control-etc/</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&quot;&gt;In 2008 I wrote a blog post “The Problem is Too Many Remote Controls” [1]&lt;/a&gt; about the issues of controlling a TV and related things. It recently got some comments on Mastodon so I think it’s time for an update.&lt;/p&gt;
&lt;p&gt;The first issue I raised was “Now it’s not uncommon to have separate remote controls for the TV, VCR, DVD player, and the Cable TV box – a total of four remote controls” which seems to have alleviated. VCRs seem to have almost entirely gone away. The &lt;a href=&quot;https://en.wikipedia.org/wiki/VHS&quot;&gt;VHS Wikipedia page [2]&lt;/a&gt; is worth reading for everyone who hasn’t seen a VCR in operation, which I expect to be more than a few readers now and an increasing number over the next 18 years. I personally don’t have Cable TV, I own a DVD player which isn’t connected to my TV because I haven’t used it for years, I don’t own a VCR, and I don’t watch free to air TV. So I have one remote control for the TV which I use for Netflix and sometimes YouTube.&lt;/p&gt;
&lt;p&gt;When viewing YouTube on TV there are significantly more adverts and longer adverts. I presume that is because installing an ad-blocker on my TV isn’t a viable option for me and it’s a total impossibility for most users. Generally my desktop PC is a much better platform for YouTube than my TV, it has a better quality display, is more user friendly (my previous post addressed the difficulty of getting to the data source that’s desired), and doesn’t require entering search terms via a slow on-screen keyboard. Netflix on Linux is limited to 720p at low bitrate which is obviously of low visual quality while on the TV it’s in 4K. I have Netflix so I use that only on the TV.&lt;/p&gt;
&lt;p&gt;In my previous post I wrote a thought experiment on how to use a cheap laptop ($500 at the time – equivalent to $777 in 2025 money according to the Reserve Bank of Australia) to control a $5000 TV ($7770 in 2025 money). Now you can buy a new 65″ 4K TV for under $800 and a new laptop capable of 4K output for under $400 so the options are very different. For a $800 TV the manufacturer isn’t going to develop a remote control interface and Google (who develops the software the TVs run) won’t do it because it could reduce their advertising revenue. But a typical home user could setup a cheap laptop connected to their TV via HDMI providing a familiar and efficient user interface for themselves and visitors. For a Windows laptop 4K Netflix should work and for a Linux laptop the options of a laptop for everything apart from Netflix and the TV for Netflix are bearable, two controls are worse than one but better than the 3+ that used to be common.&lt;/p&gt;
&lt;p&gt;In my previous post I raised the issue that “it’s often the case that you don’t want to stop watching one show while trying to find another”. This is still an unsolved problem and is not addressed in modern software. I am not aware of a Linux music player that supports such functionality and this would be much easier for a music player than for a video player where the screen would have to be shared between the interface for finding the next thing to play and the space for playing the end of the current one. Maybe I should file a bunch of wishlist bugs against music players asking for this.&lt;/p&gt;
&lt;p&gt;I suggested that “cable modem” and “cable TV box” could be integrated into a single device. That has not happened, in fact it’s got worse. A relative who has Foxtel has a cable modem, a cable TV box, and a Wifi AP with VOIP to provide landline phone service and to make it more exciting the latter two both have bugs that require a periodic hardware reset to fix. Hopefully cable TV will go away in the next 18 years.&lt;/p&gt;
&lt;p&gt;Regular PCs have become less noisy in recent years. I am currently using a HP Z640 to write this post and I have HP Z840 and HP Z4G4 systems behind me running as servers and the background noise is still very low. The &lt;a href=&quot;https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/&quot;&gt;allegedly 8K TV [3]&lt;/a&gt; that I have in my lounge room has cooling fans that make more noise than those three high-end HP computers combined. Using a quiet PC like one of those HP systems to drive a TV is a very viable option and I did just that for a couple of years. Kogan has currently got a selection of refurbished Lenovo ThinkStation systems on sale for under $400, they are quiet and would do well for this, it’s also nice that Kogan is selling systems with ECC RAM at home user prices.&lt;/p&gt;
&lt;p&gt;TV does seem to be going away. YouTube and streaming services seem to get more watching time and many people don’t use TV at all.&lt;/p&gt;
&lt;p&gt;Since my previous post the number of streaming services has increased so torrenting offers increasing benefits as no-one wants to subscribe to 6+ services. For anyone who wants to get all the content that interests them while paying the user interface situation is much worse now than it used to be in 2008.&lt;/p&gt;
&lt;p&gt;If you use KDE on a PC then the &lt;b&gt;kconnect&lt;/b&gt; program allows a phone to be used to remotely control some aspects of a PC and has a good interface for pause/resume of a video and seeking 10 seconds forwards/backwards. The interface for controlling volume is hard to get to and doesn’t work on my installation. If you want to use a keyboard to start something playing and then a phone for pause control then kdeconnect is a decent option. A comment on my previous post by Michael Croes raised the issue of remote control which is now a solvable problem. Justin also wrote a comment suggesting a Nokia N800 as a remote.&lt;/p&gt;
&lt;p&gt;Jason suggested a programmable remote, which would be a good option for a power user and a viable option for someone setting things up for their grandparents. But the amount of pain is greater than I’m interested in as lounge room TV isn’t an important thing to me. It may appeal to more people than having a dedicated lounge room PC though.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&quot;&gt; https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://en.wikipedia.org/wiki/VHS&quot;&gt; https://en.wikipedia.org/wiki/VHS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href=&quot;https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/&quot;&gt; https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2021/06/06/netflix-ipv6/&quot; rel=&quot;bookmark&quot; title=&quot;Netflix and IPv6&quot;&gt;Netflix and IPv6&lt;/a&gt; &lt;small&gt;It seems that Netflix has an ongoing issue of not...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2022/01/04/big-smart-tvs/&quot; rel=&quot;bookmark&quot; title=&quot;Big Smart TVs&quot;&gt;Big Smart TVs&lt;/a&gt; &lt;small&gt;Recently a relative who owned a 50″ Plasma TV asked...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&quot; rel=&quot;bookmark&quot; title=&quot;The Problem is Too Many Remote Controls&quot;&gt;The Problem is Too Many Remote Controls&lt;/a&gt; &lt;small&gt;I am often asked for advice about purchasing TVs and...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-08-06T04:01:37+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://gwolf.org/2026/08/subscription-bombing-email-under-attack.html">
	<title>Gunnar Wolf: Subscription Bombing • Email under Attack</title>
	<link>https://gwolf.org/2026/08/subscription-bombing-email-under-attack.html</link>
     <content:encoded>&lt;blockquote&gt;
		 
		   This post is an &lt;em&gt;unpublished&lt;/em&gt; review
		 
		     
		       
		         for &lt;em&gt;&lt;a href=&quot;https://dl.acm.org/doi/full/10.1145/3797487&quot;&gt;Subscription Bombing • Email under Attack&lt;/a&gt;&lt;/em&gt;
		       
		     
		     
		   &lt;/blockquote&gt;
		 
		 &lt;p&gt;One of the most important inputs one can have when designing a response
strategy against a security attack is a good characterization. This article
describes a relatively newly described attack mode (subscription bombing),
hypothetizes on the motivations that can lie behind it, and presents some
countermeasures that can be taken by different actors to reduce its impact.&lt;/p&gt;

&lt;p&gt;At its core, suscription bombing is a classical reflection attack: it uses
a third party service so that the answer to a relatively simple request is
amplified and results in a distributed denial of service (DDoS) for the
victim. And, as with most DDoS attacks, its effectivity lies in that there
is not much a person can do against traffic coming from seemingly random
different providers all around the world.&lt;/p&gt;

&lt;p&gt;The core differentiatof for subscription bombing is that the attack’s
victim is not a network port, but an individual’s e-mail address. The
attacker builds a database of service providers that allow interested users
to sign up for newsletter on their activities, or a mailing list, or even
just to create a new account on a given Web system. This action will
generate a (seemingly legitimate) confirmation mail sent to the victim. But
the attacker scripts together hundreds of thousands of such request,
creating a deluge of confirmation mails sent to the unsuspecting victim.&lt;/p&gt;

&lt;p&gt;The authors explain the goals an attacker might pursue by performing this
kind of attack. They suppose this can be due to harassment (a disgruntled
employee being denied a salary raise, a political adversary, or even a
romantic ex-partner wanting to inconvenience the victim’s use of their
e-mail). More worryingly, the attack can be used as a distraction: by
sending a high volume of mails in a controlled timeframe, the attacker can
reduce the probability of the victim noticing a specific attack warning
them of, i.e., financial fraud, unwanted purchases, or break-in attempts
into their accounts. Attacks targetting mailboxes at private mail servers
can also lead to overloading an account’s limit, causing it to reject
mails after the attack is delivered and before the folder is cleaned. And
it can also pave the way for follow-up, targetted deception attacks, where
the attackers call the victim pretending to be the company’s IT department,
and get them to install a remote desktop monitoring and management tool,
with which they can effectively seize control of the victim’s data.&lt;/p&gt;

&lt;p&gt;To do this, they present a study they made over 24 cases of victims, from
which 47,970 total e-mails were received between October and December 2024,
with individual attacks receiving between 81 and 3,387 e-mails per hour,
from where they presented several descriptive analysis.&lt;/p&gt;

&lt;p&gt;The authors explored cyber criminal’s offers on underground websites,
comparing flooding services and pricing schemes.&lt;/p&gt;

&lt;p&gt;Finally, mitigation strategies are discussed. Mitigation is quite
problematic, as none of the mail servers is acting in either a hostile way
or lacking permissions — they are performing just the task they should. The
authors suggest four mitigation strategies for mail server operators to
reduce the burden on their users, although none of them is easily
automatizab (rate-limit the number of emails a given inbox can receive from
previously unseen senders; educate users about this kind of attacks; group
similar newsletter or account reset mails during active attacks; and
automatically unsubscribe or bounce newsletter messages when a surge is
detected). They also recommend newsletter providers and services accepting
the unrestricted creation of user accounts to provide some hardening to
increase the effort wrongdoers need to spend to abuse their services, such
as requiring CAPTCHAs or requiring users to take several steps before
requesting a subscription, although they recognize this adds friction to
the process providers are most interested in providing; filtering and
triaging known-good and known-bad domains, although this is hard to
implement on a preemptive fashion, and adhering to easy unsubscription
standards, such as easily identifiable headers with which mass
unsubscription could be performed more easily victims, instead of hunting
for the right places to click, potentially even in mails written in an
unknown language.&lt;/p&gt;

&lt;p&gt;The described problem is interesting, and properly tackling it can be a
game changer for many users who will suffer this kind of abuse, and the
article is easy to read and soundly supports its claims.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-06T00:17:35+00:00</dc:date>
	<dc:creator>Gunnar Wolf</dc:creator>
</item> 
<item rdf:about="https://k1024.org/posts/2026/2026-08-05-yes-yes-still-alive/">
	<title>Iustin Pop: Yes-yes, still alive!</title>
	<link>https://k1024.org/posts/2026/2026-08-05-yes-yes-still-alive/</link>
     <content:encoded>&lt;p&gt;I am not sure what happened, but my interests have changed significantly, and… I
haven’t blogged, I haven’t done any open source work, and didn’t even process
any pictures for the entire year. Not because anything went bad, just… new
stuff, new interests, life changes.&lt;/p&gt;
&lt;p&gt;However, still alive, and still struggling with sports, and with sleep :)&lt;/p&gt;
&lt;p&gt;On the positive side, on a recent mid-length flight, I thought — I haven’t done
any work on Corydalis, since last year I closed quite of a few of my “must have”
features, so probably, nothing else to do for now, right? I opened an editor and
started thinking about ideas, and surprised! One hour later, I had written down
enough ideas for a couple of months of work. So now just need to find the time…
but can’t wait for the planned things!&lt;/p&gt;
&lt;p&gt;Stay well!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-05T17:34:00+00:00</dc:date>
	<dc:creator>Iustin Pop</dc:creator>
</item> 
<item rdf:about="http://www.enricozini.org/blog/2026/debian/gnome-refusing-to-suspend">
	<title>Enrico Zini: Gnome refusing to suspend</title>
	<link>http://www.enricozini.org/blog/2026/debian/gnome-refusing-to-suspend</link>
     <content:encoded>&lt;p&gt;I&#39;m tired, I want to do go bed. I click &quot;sleep&quot; on gnome shell, nothing happens.&lt;/p&gt;
&lt;p&gt;Swearwords.&lt;/p&gt;
&lt;p&gt;I want to go to bed. I might have want to put my laptop in a bag and run to
catch a train. &lt;a href=&quot;https://mastodon.bida.im/@spanezz/117017036756831405&quot;&gt;I hate when this happens&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemd-inhibit --list --mode=block&lt;/code&gt; doesn&#39;t help much:&lt;/p&gt;
&lt;div class=&quot;codehilite&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;systemd-inhibit&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;--list&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;--mode&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;block
WHO&lt;span class=&quot;w&quot;&gt;    &lt;/span&gt;UID&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;USER&lt;span class=&quot;w&quot;&gt;   &lt;/span&gt;PID&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;COMM&lt;span class=&quot;w&quot;&gt;            &lt;/span&gt;WHAT&lt;span class=&quot;w&quot;&gt;                                                     &lt;/span&gt;WHY&lt;span class=&quot;w&quot;&gt;                        &lt;/span&gt;MODE
enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1000&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;3042&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gsd-power&lt;span class=&quot;w&quot;&gt;       &lt;/span&gt;handle-lid-switch&lt;span class=&quot;w&quot;&gt;                                        &lt;/span&gt;External&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;monitor&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;attached…&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;block
enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1000&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;3037&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gsd-media-keys&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;handle-power-key:handle-suspend-key:handle-hibernate-key&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;GNOME&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;handling&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;keypresses&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;block
enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1000&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;enrico&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;m&quot;&gt;2878&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gnome-session-b&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;sleep&lt;span class=&quot;w&quot;&gt;                                                    &lt;/span&gt;user&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;session&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;inhibited&lt;span class=&quot;w&quot;&gt;     &lt;/span&gt;block
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;After much googling I found out about &lt;code&gt;gnome-session-inhibit&lt;/code&gt;:&lt;/p&gt;
&lt;div class=&quot;codehilite&quot;&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gnome-session-inhibit&lt;span class=&quot;w&quot;&gt;  &lt;/span&gt;--list
mutter:&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;idle-inhibit&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;idle&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt;
/usr/lib/chromium/chromium:&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;Playing&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;audio&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;suspend&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Found the right tab in chromium, paused playing, sleep works again.&lt;/p&gt;
&lt;p&gt;My sleep was a good half an hour overdue, and all I got for it was to write
this blog post.&lt;/p&gt;
&lt;p&gt;Of course Gnome could have shown me its inhibitor list instead of doing
nothing, since it has that information, but &lt;a href=&quot;https://discourse.gnome.org/t/why-does-gnome-shell-doesnt-notify-user-about-suspend-being-blocked-by-inhibitor/34077&quot;&gt;it didn&#39;t&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;What I really would expect is that if I intentionally click a suspend button,
audio and video playing wouldn&#39;t inhibit the suspend. Maybe in a future version
of Gnome?&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-05T07:57:52+00:00</dc:date>
	<dc:creator>Enrico Zini</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6264">
	<title>Russell Coker: Monitors for Work</title>
	<link>https://etbe.coker.com.au/2026/08/05/monitors-for-work/</link>
     <content:encoded>&lt;h2&gt;The Corporate Monitor Issue&lt;/h2&gt;
&lt;p&gt;Some time ago I worked in the IT department of a company that had a corporate standard of two 27″ FUllHD (either 1920*1080 or 1920*1200) monitors for the desktop. I was pushing to make the standard be one 32″ 4K monitor or the two cheaper monitors. They ended up making one 27″ 4K monitor an option which was still a better option for many users than two FullHD monitors due to having twice the pixels even though it had half the screen area. It was a surprise to me when hardly anyone took up that option.&lt;/p&gt;
&lt;p&gt;One man who worked there brought a wide curved monitor from home and ran with one of the FullHD monitors on each side of that. As an employee in the IT department I had concerns about expensive personal equipment being used in the office regarding who’s going to pay the bill if it gets broken. But I was assured that it was his old monitor that he didn’t need after buying a better one for gaming at home and he wouldn’t be too upset if something happened to it.&lt;/p&gt;
&lt;p&gt;This isn’t the only time I’ve witnessed such problems of companies paying large salaries for skilled people and providing poor equipment for them to do the work. One previous time I raised a OH&amp;amp;S issue because the outdated monitors were so blurry but the company determined that the monitors wouldn’t cause health problems and spending $150 per employee on better replacements was a waste of money.&lt;/p&gt;
&lt;p&gt;Computer hardware tends to become cheaper over time and one thing that has become really cheap recently is portable monitors. &lt;a href=&quot;https://www.kogan.com/au/buy/kogan-xpresso-156-full-hd-ips-usb-c-portable-monitor-kogan/&quot;&gt;Kogan has a 15.6″ FullHD monitor with USB-C and mini-HDMI inputs for $89 [1]&lt;/a&gt;. It wouldn’t be difficult for someone to put one of those on each side of the monitor or monitors that their employer provides and put them in a desk drawer at the end of the day to minimise risk. The same Kogan page has a 16″ monitor with 2560*1600 resolution for $189.&lt;/p&gt;
&lt;h2&gt;Company Ownership&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&quot;&gt;I previously wrote about the potential benefits to companies in not owning all those keyboards, mice, and headsets when they could just give each employee the money and have them buy their own [2]&lt;/a&gt;. I don’t think we are at the stage where that can be applied to monitors as the cheapest price for a decent monitor is about $500 which takes it out of the disposable price range that keyboards and mice are in. Also from an IT support perspective there are real support issues with monitors and cables having compatibility issues. But paying small amounts of money to reimburse employees who buy cheap portable monitors to supplement their main monitor is a more reasonable option. For some people that will allow noteworthy improvements in work performance.&lt;/p&gt;
&lt;h2&gt;Who Will it Help?&lt;/h2&gt;
&lt;p&gt;I don’t think that adding such portable monitors will directly help the majority of workers. I think that to maximise performance and efficiency we need to chase the long tail of improvements. Big monitors, really big monitors (65″ at a larger distance), multiple monitors, standing desks, and whatever else people want.&lt;/p&gt;
&lt;p&gt;There was some research from Microsoft some years ago (back when 27″ was a really big monitor) showing that some tasks had a 50% increase in performance with a larger monitor. Now that 27″ is about the smallest monitor size commonly available the potential for improvement is reduced. Probably most workers now already have monitors that provide the benefits to them that the “big monitors” in Microsoft research provided. But there will always be some portion of the user base who will benefit. If you can get a 50% performance boost for 1% of the users that’s really worth doing. If you can get a 0.5% benefit for 100% of the users that is also worth doing and will theoretically give equal benefits.&lt;/p&gt;
&lt;h2&gt;Costs of Employees&lt;/h2&gt;
&lt;p&gt;It is claimed that the total cost of an employee including all overheads of management and providing office facilities etc amounts to twice their base salary. If that is the case then a minimum wage employee in Australia costs $100k per year, someone at the low end of the IT pay scale costs $200k, and someone at the high end of the IT scale is around $400k. It seems clearly worthwhile to spend $1000 in hardware purchases for a $100k employee who declares that it will really help their work, anything which is noticeable to the user is going to be more than a 1% difference in performance.&lt;/p&gt;
&lt;p&gt;For someone at the high end of the IT pay scale spending $40,000 on hardware to improve their performance could pay for itself. This is not only due to direct return on investment but because the people who do such work are often in key roles in important projects. If there’s too much work for one person on minimum wage to do then you just hire another person. You can’t hire another senior IT person and have them just do the work, it can take months to get up to speed.&lt;/p&gt;
&lt;p&gt;But as management in corporations seems unable to recognise this cheap hardware employees can afford to buy with their own money can bridge the gap.&lt;/p&gt;
&lt;h2&gt;Job Interviews&lt;/h2&gt;
&lt;p&gt;In future when interviewing for jobs I’ll ask about the hardware that’s to be used. I won’t say “I’m not interested in this job offer because you don’t respect your employees enough to buy adequate hardware”, but I may make it a condition of working at a company that the hardware on my desk will not be obsolete.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://www.kogan.com/au/buy/kogan-xpresso-156-full-hd-ips-usb-c-portable-monitor-kogan/&quot;&gt; https://tinyurl.com/26bdng24&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&quot;&gt; https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&quot; rel=&quot;bookmark&quot; title=&quot;Cheap Peripherals for Work&quot;&gt;Cheap Peripherals for Work&lt;/a&gt; &lt;small&gt;A problem with a lot of the purchase of peripherals...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2007/01/04/monitors-for-developers/&quot; rel=&quot;bookmark&quot; title=&quot;monitors for developers&quot;&gt;monitors for developers&lt;/a&gt; &lt;small&gt;Michael Davies recently blogged that all developers should have big...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2019/11/18/4k-monitors/&quot; rel=&quot;bookmark&quot; title=&quot;4K Monitors&quot;&gt;4K Monitors&lt;/a&gt; &lt;small&gt;A couple of years ago a relative who uses a...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-08-04T22:41:18+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/08/04#058_fast_easy_reliable_reverse_dependency_checks">
	<title>Dirk Eddelbuettel: #058: Reverse Dependencies Made Easy, Fast, Reliable</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/08/04#058_fast_easy_reliable_reverse_dependency_checks</link>
     <content:encoded>&lt;p&gt;Welcome to post 58 in the &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/code/r4&quot;&gt;&lt;span class=&quot;math inline&quot;&gt;&lt;em&gt;R&lt;/em&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/span&gt;&lt;/a&gt; series.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.R-Project.org&quot;&gt;R&lt;/a&gt; and the &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; repositories maintain a very
high level of what we might call “quality assurrance” by requiring that
newly-added code does not break any existing dependencies. This is
frequently called a “reverse-dependency check”. For any given &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; package one can quickly
determine it reverse dependencies. Calling
&lt;code&gt;tools::package_dependencies(pkgName, reverse=TRUE)&lt;/code&gt; will for
a scalar or vector-valued argument return a named list with the reverse
dependencies. It is then a matter of looping over this list. There are
helper functions in base R as well as in contributed packages on and off
&lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;. I also wrote my own with
package &lt;a href=&quot;https://github.com/eddelbuettel/prrd&quot;&gt;prrd&lt;/a&gt; which,
while possibly a wee bit specialised and under-documented has served me
well to check on &lt;a href=&quot;https://github.com/rcppcore/rcpp&quot;&gt;Rcpp&lt;/a&gt; and
related packages which can indeed have a &lt;em&gt;large&lt;/em&gt; number of
reverse dependencies.&lt;/p&gt;
&lt;p&gt;I recently looked into one of these contributed runner packages, and
while I will refrain from naming its implementation language let me just
mention that the term “&lt;code&gt;cargo&lt;/code&gt; cult” may be a real thing
here. What go me interested in this was the fact that &lt;em&gt;if&lt;/em&gt; one
has a simple-to-use runner &lt;em&gt;then&lt;/em&gt; the fact that &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; makes it “fast, easy,
reliable: pick all three” (to borrow its slogan) to deal with actual
depencies if Ubuntu has indeed been selected as the host. We will
maintain the position that &lt;em&gt;if&lt;/em&gt; you can in fact integrate with
the system-wide package management then any alternative per-repo package
management approach not doing so will likely be dominated by an approach
that does integrate with the system facilities. Which is what precisely
what &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; does, and
offers. And why it is used enough to by now have shipped eighty eight
million binary packages. So I tested it for the reverse-dependency check
task.&lt;/p&gt;
&lt;p&gt;What I learned by looking into the (much more complicated) runner was
that it at the end of the day it hands the actual task of running the
reverse dependecies off to a helper function &lt;code&gt;rev_check&lt;/code&gt; that
is part of the &lt;a href=&quot;https://github.com/yihui/xfun&quot;&gt;xfun&lt;/a&gt; package
by Yuhui. I quickly found that besides &lt;a href=&quot;https://github.com/yihui/xfun&quot;&gt;xfun&lt;/a&gt; we would also need its
suggested dependency &lt;a href=&quot;https://github.com/rstudio/tinytex&quot;&gt;tinytex&lt;/a&gt; which in turn
would error unless the &lt;code&gt;tlmgr&lt;/code&gt; binary was present. So as the
sole requirement (on an Ubuntu system with &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt;) turns out to be&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb1&quot;&gt;&lt;pre class=&quot;sourceCode sh&quot;&gt;&lt;code class=&quot;sourceCode bash&quot;&gt;&lt;span id=&quot;cb1-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;$&lt;/span&gt; apt install r-cran-xfun r-cran-tinytex texlive-base&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;where we do it all in one &lt;code&gt;apt&lt;/code&gt; call (as &lt;code&gt;root&lt;/code&gt;
in the container). (Given &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; we could also call
&lt;code&gt;install.packages(c(&quot;xfun&quot;,&quot;tinytext&quot;))&lt;/code&gt; followed by
&lt;code&gt;apt install texlive-base&lt;/code&gt; but it is simpler for this setup
step to be just one call).&lt;/p&gt;
&lt;p&gt;With that we are basically done. I did this (twice) using a
&lt;code&gt;rocker/r2u&lt;/code&gt; container with &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; preinstalled, mounting
a local work and scrap directory for the container. In it we expand the
package to be tested (i.e. &lt;code&gt;tar xaf pkgName_*tar.gz&lt;/code&gt; for a
given source package &lt;code&gt;pkgName&lt;/code&gt; from &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;) and then just call with the
package name and expanded direcrtory. I.e. I used this call to test my
package &lt;code&gt;AsioHeaders&lt;/code&gt; (which has just three reverse
dependencies) to both name it and to point to the expanded source
directory created for this purposed:&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb2&quot;&gt;&lt;pre class=&quot;sourceCode r&quot;&gt;&lt;code class=&quot;sourceCode r&quot;&gt;&lt;span id=&quot;cb2-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;system.time&lt;/span&gt;( res &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; xfun&lt;span class=&quot;sc&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;fu&quot;&gt;rev_check&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;AsioHeaders&quot;&lt;/span&gt;, &lt;span class=&quot;at&quot;&gt;src=&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;AsioHeaders&quot;&lt;/span&gt;) )&lt;/span&gt;
&lt;span id=&quot;cb2-2&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-2&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;do&quot;&gt;## ... earlier output omitted for brevity here ...&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-3&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-3&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;   user  system elapsed &lt;/span&gt;
&lt;span id=&quot;cb2-4&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-4&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt; &lt;span class=&quot;fl&quot;&gt;35.732&lt;/span&gt;   &lt;span class=&quot;fl&quot;&gt;3.333&lt;/span&gt; &lt;span class=&quot;fl&quot;&gt;149.683&lt;/span&gt; &lt;/span&gt;
&lt;span id=&quot;cb2-5&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-5&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; res&lt;/span&gt;
&lt;span id=&quot;cb2-6&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-6&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;   httpgd ipaddress websocket &lt;/span&gt;
&lt;span id=&quot;cb2-7&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-7&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;        &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt; &lt;/span&gt;
&lt;span id=&quot;cb2-8&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-8&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; &lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;and about a good two minutes later I would get the timing result and
the summary in variable &lt;code&gt;res&lt;/code&gt;. As I checked the current &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; version, the check was as
expected free of concerns or issues.&lt;/p&gt;
&lt;p&gt;To support this, &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt;
did indeed go off and install about sixty seven binary packages (and the
total includes all binary dependencies fully resolved) delivering on the
‘just works’ promise by the &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; documentation.&lt;/p&gt;
&lt;p&gt;As another check, I did the same for &lt;a href=&quot;https://github.com/eddelbuettel/rcppannoy&quot;&gt;RcppAnnoy&lt;/a&gt; which has
seven reverse dependencies and needed about two hundred &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; packages to be installed. The
full test took just over four minutes with the timing function reporting
some nice gains from parallelisation as total user compute time was on
the order of just under eight minutes. Again, test results were clean
and free of worries as expected:&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb3&quot;&gt;&lt;pre class=&quot;sourceCode r&quot;&gt;&lt;code class=&quot;sourceCode r&quot;&gt;&lt;span id=&quot;cb3-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;system.time&lt;/span&gt;( res &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; xfun&lt;span class=&quot;sc&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;fu&quot;&gt;rev_check&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;RcppAnnoy&quot;&lt;/span&gt;, &lt;span class=&quot;at&quot;&gt;src=&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;RcppAnnoy&quot;&lt;/span&gt;) )&lt;/span&gt;
&lt;span id=&quot;cb3-2&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-2&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;do&quot;&gt;## ... earlier output omitted for brevity here ...&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb3-3&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-3&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;   user  system elapsed &lt;/span&gt;
&lt;span id=&quot;cb3-4&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-4&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;fl&quot;&gt;471.765&lt;/span&gt; &lt;span class=&quot;fl&quot;&gt;378.220&lt;/span&gt; &lt;span class=&quot;fl&quot;&gt;266.855&lt;/span&gt; &lt;/span&gt;
&lt;span id=&quot;cb3-5&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-5&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; res&lt;/span&gt;
&lt;span id=&quot;cb3-6&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-6&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;   bbknnR  bigANNOY  blocking     scDHA    Seurat      uwot VectrixDB &lt;/span&gt;
&lt;span id=&quot;cb3-7&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-7&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;        &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt;         &lt;span class=&quot;dv&quot;&gt;0&lt;/span&gt; &lt;/span&gt;
&lt;span id=&quot;cb3-8&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb3-8&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;sc&quot;&gt;&amp;gt;&lt;/span&gt; &lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Overall this was a rather useful quick excursion as it demonstrates
that - existing functions can be used to orchestrate a reverse
dependency check - with ‘reasonable’ dependency scale we can do this on
a single machine quite easily taking advantage of parallel computing on
multi-core machines - using &lt;a href=&quot;https://eddelbuettel.github.io/r2u&quot;&gt;r2u&lt;/a&gt; gives us &lt;em&gt;fast,
easy, reliable&lt;/em&gt; package installation making testing of packages we
might not otherwise use or know a breeze - doing this in an ephemeral
Docker container facilitates easy build-up of required resources and
leaves no side effects behind which might affect our normal development
environment&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can now &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-04T17:22:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="http://www.hungry.com/~pere/blog/FreeCAD_MCP_with_llama_cpp__toy_or_tool_.html">
	<title>Petter Reinholdtsen: FreeCAD MCP with llama.cpp, toy or tool?</title>
	<link>http://www.hungry.com/~pere/blog/FreeCAD_MCP_with_llama_cpp__toy_or_tool_.html</link>
     <content:encoded>&lt;p&gt;After seeing a video a few months ago demonstrating how a
proprietary CAM solution uses machine learning and large language
models to automatically generate CNC instructions, and successfully
testing it on a real CNC, I began wondering if the same could be
achieved with free software. I still do not know the answer, but I may
be getting closer to finding out. Two weeks ago, I came across the
video &quot;&lt;a href=&quot;https://inv.nadeko.net/watch?v=6trAkQY5_kc&quot;&gt;I Connected
Claude AI to FreeCAD (And It Models Parts Like an Engineer)&lt;/a&gt;&quot; by
Make Form, which introduced me to the
&lt;a href=&quot;https://github.com/neka-nat/freecad-mcp/&quot;&gt;FreeCAD MCP
project&lt;/a&gt;. Even though the video creator apparently believes it is
acceptable to download and run random binaries from the Internet on a
local machine (his setup uses UCX), I do not. I would probably have
left the project alone entirely if I had not noticed that all of its
dependencies are already available in Debian. This significantly
boosted my motivation, so I set out to test it using packages built
from source on Debian rather than relying on untrusted binaries.&lt;/p&gt;

&lt;p&gt;The first hurdle was that
&lt;a href=&quot;https://tracker.debian.org/pkg/python-mcp&quot;&gt;the MCP SDK for
Python&lt;/a&gt; was not present on my Debian Forky test machine. I
initially believed it was missing from Debian altogether, but it has
been available in Debian Unstable for about a month and is only absent
from Forky because some automated tests fail on architectures like
riscv64 and s390. Fortunately, backporting it was straightforward
using `apt-get source -b python3-mcp`. The next hurdle involved an
outdated version of the
&lt;a href=&quot;https://tracker.debian.org/pkg/validators&quot;&gt;Validators Python
library&lt;/a&gt;. Since I am a member of Debian&#39;s Python team, which
maintains this package, updating it to a sufficient version for
FreeCAD MCP was relatively easy. I could not upgrade to the latest
upstream release due to a new dependency on an Ethereum-related
library, so I settled on a 2024 version.&lt;/p&gt;

&lt;p&gt;With those dependencies in place, I proceeded to create a Debian
package for FreeCAD MCP. I had previously submitted a
&lt;a href=&quot;https://bugs.debian.org/1142447&quot;&gt;request for packaging of
FreeCAD MCP&lt;/a&gt; to gauge interest while deciding whether to prioritize
maintaining it myself.  Because salsa.debian.org blocks access from
Tor users like myself, I published my draft packaging scripts in a Git
repository on Codeberg as the
&lt;a href=&quot;https://codeberg.org/pere/debian-freecad-mcp&quot;&gt;Debian FreeCAD
MCP project&lt;/a&gt; and got it working with the FreeCAD 1.1 version in
Forky. I initially struggled with the button controls for the MCP
feature, which led me to submit a pull request titled
&quot;&lt;a href=&quot;https://github.com/neka-nat/freecad-mcp/pull/106&quot;&gt;Fixed
startup sync of checkable toolbar buttons&lt;/a&gt;&quot; proposing a fix. Once
this confusion was resolved and the MCP setup was enabled via the GUI,
I was able to run FreeCAD completely headless using `xvfb-run` on a
machine without an X server to generate models. I am using a private
LLM service running &lt;a href=&quot;https://tracker.debian.org/llama.cpp&quot;&gt;the
Debian package of llama.cpp&lt;/a&gt; with the Qwen 3.6 model downloaded
from Hugging Face, configured with a maximum context window of 105k
tokens. I also tested the Bonsai model on my test laptop; initially,
its context window was too small (8k and 16k could not accommodate the
FreeCAD MCP instructions), but even after increasing it to 32k, it
proved useless for generating FreeCAD models so far. I&#39;ve used Claw
Code, Aider and Open Code with my server so far, and for this test I
ended up with OpenCode because it was easy to set up to use an
MCP. Because none of my LLM services are set up to be multimodal
(capable of processing both text and images in this case), I
configured the MCP to return only textual feedback from FreeCAD. I am
unsure if this is a major limitation, though I suspect it might
be.&lt;/p&gt;

&lt;p&gt;My testing experience remains limited, with no clear successes
yet. Part of the issue likely stems from my ability to provide
effective instructions for modeling 3D objects (I am relatively new to
FreeCAD, English is not my first language, and I lack a precise
vocabulary for describing construction features to an
LLM). Nevertheless, the LLM has demonstrated the capacity to create 3D
models in FreeCAD. In one of my first tests, I asked it to generate a
cube and then produce CAM/G-code instructions for a CNC machine. It
did output G-code (which remains untested), but I was surprised to
find that it bypassed FreeCAD&#39;s built-in CAM module entirely and
instead generated an external Python script to produce the code. This
was not quite what I intended, though my instructions were probably
unclear. The Qwen model with OpenCode seems to strongly prefer
programming directly; it frequently executes Python snippets inside
FreeCAD to achieve its goals rather than using the standard
sketch-and-extrude workflow I am accustomed to. In another test, I
asked the LLM to create a parameterized pipe assembly to see which of
FreeCAD&#39;s parametric tools it would choose, but found no evidence of
traditional parametric features in the output. When prompted, the LLM
explained that the parameters were embedded directly in the Python
script used to generate the model, rather than in native FreeCAD
features. With more explicit instructions, it eventually created a
FreeCAD spreadsheet to manage the parameters. The resulting model
looked much closer to my expectations and could have been useful with
further refinement. My so far last experiment was less successful: I
asked it to design a pipe clamp, but the LLM repeatedly failed to
position the clamping screws in a way that would actually secure the
brackets around the pipe. It is unclear whether this limitation lies
with the model, my prompt, or other factors.&lt;/p&gt;

&lt;p&gt;Based on my testing so far, I am uncertain whether FreeCAD MCP is
merely a fun toy or a genuinely useful tool. I will only commit time
to maintaining it in Debian if it proves to be practically valuable. I
would welcome feedback from anyone who has experience with the
project, preferably via the original request-for-packaging mailing
list thread. Alternatively, I am available in the FreeCAD and Debian
AI IRC channels for further discussion.&lt;/p&gt;

&lt;p&gt;As usual, if you use Bitcoin and wish to support my activities,
please send donations to
&lt;b&gt;&lt;a&gt;15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b&lt;/a&gt;&lt;/b&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-04T09:00:00+00:00</dc:date>
	<dc:creator>Petter Reinholdtsen</dc:creator>
</item> 
<item rdf:about="http://www.netfort.gr.jp/~dancer/diary/daily/2026-Aug-4.html.en#2026-Aug-4-07:03:26">
	<title>Junichi Uekawa: Summer Holiday.</title>
	<link>http://www.netfort.gr.jp/~dancer/diary/daily/2026-Aug-4.html.en#2026-Aug-4-07:03:26</link>
     <content:encoded>Summer Holiday. Busy time as a parent.
        &lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-03T22:03:26+00:00</dc:date>
	<dc:creator>Junichi Uekawa</dc:creator>
</item> 
<item rdf:about="http://blog.brlink.eu/index.html#i72">
	<title>Bernhard R. Link: I learned something new about URLs today</title>
	<link>http://blog.brlink.eu/index.html#i72</link>
     <content:encoded>&lt;p&gt;
Today I stumbled over some behavior that I found quite surprising:
&lt;/p&gt;
&lt;pre&gt;$ ipython3 -c &#39;import httpx;print(httpx.URL(&quot;https://example.com/foo/bar/../../baz&quot;))&#39;
https://example.com/baz
&lt;/pre&gt;
&lt;p&gt;
Even more surprising that behavior is actually standards-compliant,
even mandated by RFC 3986.
&lt;/p&gt;
&lt;p&gt;
The underlying motivation is relative reverences.
If some resource reachable by &quot;&lt;tt&gt;https://example.com/foo/bar&lt;/tt&gt;&quot;
references another resource relatively as &quot;&lt;tt&gt;../../baz&lt;/tt&gt;&quot; then
this is of course the intended result.
&lt;/p&gt;
&lt;p&gt;Getting from this problem to what RFC 3986 suggests
might be surprising in the result, but somewhat understandable if you
look at the consequences of that problem:&lt;/p&gt;
&lt;p&gt;Giving the path components &quot;&lt;tt&gt;..&lt;/tt&gt;&quot; (and &quot;&lt;tt&gt;.&lt;/tt&gt;&quot;)
special meaning at the start of the relative reference means that if you allowed
them in absolute URLs those would be impossible (or at least very convoluted)
to address as relative URLs.
&lt;/p&gt;
&lt;p&gt;
So RFC 3986 describes a way to handle them everywhere:
Just join the path of the base URL and the path of the relative reference
and normalize the result. Or normalize the absolute on either side if only
that is to be taken.
This makes things very convenient:
Multiple reference URLs can just be joined without special handling for
relative references starting with dots, making writing applications handling
them easier.
Programmers don&#39;t have to care how to handle relative references and can
just join everything in whatever way they want.
&lt;/p&gt;
&lt;p&gt;
For maximum elegance there is still some corner case left:
What happens if an absolute URL has a path starting with double-dot components?
Or an relative path starting with more of them then the base URL&#39;s path has components.
You just ignore them:
&lt;/p&gt;
&lt;pre&gt;$ ipython3 -c &#39;import httpx;print(httpx.URL(&quot;https://example.com/../../baz&quot;))&#39;
https://example.com/baz
&lt;/pre&gt;
&lt;p&gt;
With that last point every URL is valid and has well-defined meaning.
Handling relative references and relative paths is very easy and convenient.
&lt;/p&gt;
&lt;p&gt;
So this shows a high regard for simplicity, elegance and convenience.
And a total and uncompromising disregard of security.
&lt;/p&gt;
&lt;p&gt;
After all the most convenient it is for an attacker;
If they are allowed to supply a path component for a request a system
does in their behalf, then they can easily escape anything they were supposed
to be limited to.
The ignoring of dots at the start means they don&#39;t even have to know
exactly how deep their request is:
&lt;/p&gt;
&lt;pre&gt;$ python3 -c &#39;import httpx;print(httpx.URL(&quot;https://example.com/public/api/public/resources/harmless/../../../../../../../../../internal/data&quot;))&#39;
https://example.com/internal/data
&lt;/pre&gt;
&lt;p&gt;
So even if the resource server securely handles request
(unless you consider not having any way to lower your permissions for one request to a specific subset),
your fully RFC conforming client library will already request the permission they should not have permission for.
Even worse dots are usually not characters you can easily forbid so once slashes are to be allowed things get complicated.
&lt;/p&gt;
&lt;p&gt;
There also would have been a simple, elegant and secure way:
Consider every path element &quot;&lt;tt&gt;..&lt;/tt&gt;&quot; or &quot;&lt;tt&gt;.&lt;/tt&gt;&quot;
in an (absolute) URL an error.
Define a reference resolution that allows the relative reference to only start
with &quot;&lt;tt&gt;./&lt;/tt&gt;&quot; or one or multiple &quot;&lt;tt&gt;../&lt;/tt&gt;&quot; and
consider every appearance of a dot or two dots as path components after than an error.
&lt;/p&gt;
&lt;p&gt;
Everything joining two paths has to either use an implementation of that path joining
algorithm, but only if they want to joins paths in the potentially dangerous
way allowing leading &quot;&lt;tt&gt;../&lt;/tt&gt;&quot;. Otherwise they can just use the normal
join and even if an attacker gets those dots that will just cause the generated URL
to be rejected as invalid.
&lt;/p&gt;
&lt;p&gt;Of course using a secure implementation is now even more inconvenient thanks to RFC 3986 being around:
If you have no control over the generator of relative references, it is always possible
that they generate relative references with &quot;&lt;tt&gt;..&lt;/tt&gt;&quot; components after non-dot
components.
&lt;/p&gt;
&lt;p&gt;And if you check all code to properly filter out &quot;&lt;tt&gt;/../&lt;/tt&gt;&quot;,
keep in mind that convienence does not stop there.
After all it is not unheared of for server implementations to helpfully normalize
unicode characters, too, or translate them to their nearest ASCII equivalents.
Or translate percent escaped characters back before doing path splitting.
Or you might think there was some unicode codepoints between those two dots,
but they that those were some meaningless control characters that can be omitted.
So you need some really restrictive allow lists...
&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-03T19:39:43+00:00</dc:date>
	<dc:creator>Bernhard R. Link</dc:creator>
</item> 
<item rdf:about="https://changelog.complete.org/?p=44456">
	<title>John Goerzen: Celebrating 45 Years of Kermit with the First New C-Kermit Release in 15 Years (and working with a decades-old C codebase)</title>
	<link>https://changelog.complete.org/archives/44456-celebrating-45-years-of-kermit-with-the-first-new-c-kermit-release-in-15-years-and-working-with-a-decades-old-c-codebase</link>
     <content:encoded>&lt;p&gt;1981 was a different time for computing.  It was expensive (&lt;a href=&quot;https://changelog.complete.org/archives/10417-the-pc-internet-revolution-in-rural-america&quot;&gt;both hardware and software&lt;/a&gt;), and it was far from a given that machines from one vendor would be able to talk to those from another.  In fact, Columbia University had just such a problem, so in 1981, Frank da Cruz and Bill Catchings designed a serial protocol they called Kermit.  Because of the many &lt;a href=&quot;https://www.columbia.edu/cu/computinghistory/dec20.html#kermit&quot;&gt;quirks&lt;/a&gt; of the &lt;a href=&quot;https://en.wikipedia.org/wiki/DECSYSTEM-20&quot;&gt;DEC-20&lt;/a&gt; and IBM mainframes, the Kermit protocol was highly adaptable from the start: able to handle systems that had trouble processing more than 96 bytes of data at once, able to transfer 8-bit files over 7-bit links, able to translate between character sets (ASCII and EBCDIC then; now also various Unicodes), and of course, handling of error-prone serial links.&lt;/p&gt;
&lt;p&gt;Kermit spread rapidly; by 1982, Kermit had been ported to MS-DOS and Unix.  Eventually, C-Kermit (an implementation of Kermit in C) became the flagship Kermit.  It gained TCP support, an interactive CLI, a powerful scripting language (with features from the shell, Lisp, and &lt;a href=&quot;https://core.tcl-lang.org/expect/index&quot;&gt;expect&lt;/a&gt;), and optimizations for today’s high-speed links, such as jumbo packets, sliding windows, and streaming modes.  Along the way, Kermit &lt;a href=&quot;https://www.kermitproject.org/nasa.html&quot;&gt;flew on the International Space Station&lt;/a&gt;, ran &lt;a href=&quot;https://www.kermitproject.org/em-apex.html&quot;&gt;data collection from sensors during hurricanes&lt;/a&gt;, and &lt;a href=&quot;https://www.kermitproject.org/kermit.html&quot;&gt;many other uses&lt;/a&gt; including postal systems, Boeing 787 manufacturing, and more.&lt;/p&gt;
&lt;p&gt;Today, I use it as a &lt;a href=&quot;https://www.openkermit.org/ckermit/ssh/&quot;&gt;powerful ssh wrapper&lt;/a&gt; (letting me easily transfer files through multiple nested ssh, sudo, su, etc. commands), a &lt;a href=&quot;https://www.openkermit.org/ckermit/bbs/&quot;&gt;BBS client&lt;/a&gt;, to exchange data with me &lt;a href=&quot;https://www.kermitproject.org/hp48filetransfer.html&quot;&gt;HP 48GX calculator&lt;/a&gt;, and so on.  It’s also used today to transmit firmware updates to embedded devices.  And, of course, anyone that works with vintage systems is likely to use Kermit at some point.&lt;/p&gt;
&lt;p&gt;It wouldn’t be until the late 1990s that the TCP/IP stack was finally adopted by most OS vendors, establishing something of a common basis for communication.  Of course, we assume this today.  Though transferring large files between OSs (say, Linux, Windows, MacOS, Android, iPad, etc.) is still a challenge, even though they all speak TCP/IP!  I find that the easiest way to get large files from two computers is to spin up Kermit (see &lt;a href=&quot;https://github.com/davidrg/ckwin&quot;&gt;ckwin&lt;/a&gt; for a Windows fork of C-Kermit) and just set up a TCP connection over the LAN.  In fact, I added a new &lt;tt&gt;show interfaces&lt;/tt&gt; command in C-Kermit 11, making it easy to see your system’s local IPs.&lt;/p&gt;
&lt;p&gt;For most of its history, Columbia’s Kermit project was self-funded.  Columbia charged for commercial use, which limited its inclusion in Linux distributions.  In 2011, 30 years after its founding, Columbia canceled the Kermit Project and released C-Kermit as Open Source under a BSD license.  Frank da Cruz, who had still been working with the Kermit project all those years, volunteered to continue maintaining Kermit outside Columbia, and continued development with alpha and beta releases through his retirement from the project in 2025.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;I dive into this C codebase&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;As Debian maintainer of Kermit, I noticed some areas where it wasn’t matching modern expectations.  One area was, not surprising for a project of its age, security.  Another area was that its character set or line-ending conversions are usually not desired now; we are used to byte-identical binary transfers, and the defaults caused confusion and even some rare instances of data corruption.  So I started making a few patches last year.&lt;/p&gt;
&lt;p&gt;I’ve worked with old C codebases before, such as Varnish.  I’ve generally hated it.  You usually find a mix of bad and terrible practices, unclear memory management, and so forth.&lt;/p&gt;
&lt;p&gt;But I’ve been living in the C-Kermit codebase for a few months now, and I &lt;i&gt;enjoy&lt;/i&gt; it.  Yes, this thing is still designed to build on VMS, OS/2, and with compilers that haven’t heard of ANSI — and those that require modern practices.  (That em-dash was mine; I knew how to use them before LLMs existed and I’m not going to stop just because LLMs have copied people like me!  No AI was used for this post.)&lt;/p&gt;
&lt;p&gt;The there is an elegance in all of that.  As I worked, I fixed a bunch more potential security issues, both with memory safety and with protecting against a malicious remote in roughly the same manner that some patches to scp did a few years back.  I added IPv6 support, of course conditionally compiled because some systems C-Kermit builds on have never heard of IPv6 and never will.  (And, of course, with fallback algorithms at runtime for systems that have IPv6 support but not IPv6 connectivity.)&lt;/p&gt;
&lt;p&gt;I added unit tests and Python-based end-to-end tests, running nearly 2000 test cases in total.  Along the way, I found and fixed a number of bugs going back decades.  I learned about FIONREAD being broken on macOS, about NetBSD’s bugs in the pty driver, and fixed bugs in the Kermit protocol implementation itself.  I added compatibility tests with the gkermit and ekermit (embedded) implementations, as well as the last full release, C-Kermit 9.0.302 from 2011 (which was difficult to get compiled on a modern system).&lt;/p&gt;
&lt;p&gt;There is an &lt;a href=&quot;https://github.com/OpenKermit/ckermit/releases/tag/v11.0.506&quot;&gt;extensive changelog&lt;/a&gt; describing all the improvements in C-Kermit 11.&lt;/p&gt;
&lt;p&gt;C-Kermit development had never really used a VCS at any point, though Kermit veteran Jeffrey Altman imported historical releases into a Git repo, along with some patches that hadn’t made it into a release (which I also pulled in.)  There was a lot of disabled code behind &lt;tt&gt;&lt;a class=&quot;hashtag u-tag u-category&quot; href=&quot;https://changelog.complete.org/archives/tag/ifdef&quot; rel=&quot;tag&quot;&gt;#ifdef&lt;/a&gt; COMMENT&lt;/tt&gt;, along with commentary describing why it was no longer used.  With Git, we would now generally just remove the old code and explain why in a commit message.  I went through and did so with a lot of it, meaning that, at last check, C-Kermit actually has fewer lines of code now than it used to.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Towards a new release&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;It became apparent pretty quickly that I was making more changes than would make sense as a Debian patch series.  Not only that, but they would be more widely applicable to more than just Debian and Ubuntu users.  As Linux and BSD distributions were running everything from the last non-beta release (2011’s 9.0.302) to the last beta release (about 1.5 years ago), depending on their different policies about running betas, even sharing patches in a useful fashion was going to be quite difficult.&lt;/p&gt;
&lt;p&gt;So, I spun up a project at &lt;a href=&quot;https://www.openkermit.org/&quot;&gt;Open Kermit&lt;/a&gt; to coordinate future development in the open and keep Kermit going.&lt;/p&gt;
&lt;p&gt;With modern CI, I run that test suite on Linux (x86_64 and arm64), macOS, FreeBSD, NetBSD, and OpenBSD.  It builds binary releases on all those platforms, plus a statically-linked Linux binary built with musl libc.&lt;/p&gt;
&lt;p&gt;You can &lt;a href=&quot;https://www.openkermit.org/downloads/&quot;&gt;download the latest C-Kermit release&lt;/a&gt;, and of course &lt;a href=&quot;https://www.openkermit.org/contributing/&quot;&gt;contribute to C-Kermit and its website&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Dedication&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Frank da Cruz was directly involved with Kermit for 44 years.  I’m not aware of any other Open Source project founder being involved for so long.  Richard Stallman started working on GNU Emacs in 1984, 3 years after Frank started working on Kermit, but Richard hasn’t &lt;a href=&quot;https://web.archive.org/web/20080524201111/http://www.networkworld.com/community/node/25335&quot;&gt;been in that role since around 2008&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Accordingly, C-Kermit 11 bears this dedication:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;I dedicate this release of C-Kermit to Frank da Cruz.&lt;/p&gt;
&lt;p&gt;Frank was directly involved with Kermit for 44 years, from its initial design in 1981 all the way through 2025.  He maintained Kermit as an Open Source project after Columbia University ended its sponsorship.  I know of no other Open Source project where the founder remains so personally involved for so long.&lt;/p&gt;
&lt;p&gt;When Kermit was begun, transfers between different hardware and operating systems were difficult or impossible.  Frank helped build a bridge.  Kermit glued systems together, from the International Space Station to pocket calculators, and set a new standard for interoperability.  It continues to do so.&lt;/p&gt;
&lt;p&gt;Kermit is still one of the quietly-working pillars of computing today, enabling everything from firmware upgrades to radios.  And, yes, it still reliably transfers files over serial lines.&lt;/p&gt;
&lt;p&gt;As we start to spend a lot of time in the Kermit codebase, we do so standing on the shoulders of a giant.  Thanks, Frank, for your decades of work on Kermit.&lt;/p&gt;
&lt;p&gt;John Goerzen, July 2026&lt;/p&gt;&lt;/blockquote&gt;</content:encoded> 
	<dc:date>2026-08-03T15:45:14+00:00</dc:date>
	<dc:creator>John Goerzen</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/journal/2026-08/001.html">
	<title>Russ Allbery: Term::ANSIColor v6.0.0 TRIAL release</title>
	<link>https://www.eyrie.org/~eagle/journal/2026-08/001.html</link>
     <content:encoded>&lt;p&gt;
Yesterday, I uploaded Term::ANSIColor v6.0.0-TRIAL to CPAN for early
testing. This release will raise the minimum required Perl version to
5.12, dropping support for Perl 5.8 and 5.10. When I did the same with
podlators a couple of years ago, it upset a few people and one of them
asked me to make this sort of test release in the future. Hopefully this
will help.
&lt;/p&gt;

&lt;p&gt;
I have not run the normal release machinery and haven&#39;t archived this
release in the normal places, since I intend it to be transient. It&#39;s only
on CPAN, where people can retrieve it for testing. Once v6.0.0 is
released, few traces of this TRIAL release will be left. This doesn&#39;t
appear to be how other people use the TRIAL mechanism, but it felt more
comfortable to me. If I have to make substantial changes, I&#39;ll consider
changing my approach.
&lt;/p&gt;

&lt;p&gt;
I plan on turning this into the v6.0.0 release in about a month or two,
hopefully with only documentation changes.
&lt;/p&gt;

&lt;p&gt;
Term::ANSIColor is a &quot;very upstream&quot; core module with a lot of
dependencies, and CPAN (unlike some of the archives that followed it, such
as PyPI) doesn&#39;t support conditionally retrieving packages based on the
current Perl version. This release may therefore be disruptive for people
who are still trying to support Perl 5.8 and 5.10, since CPAN installation
tools may attempt to install an incompatible Term::ANSIColor version. I&#39;m
sad that this will be the result, since I know some people still care
about those versions.
&lt;/p&gt;

&lt;p&gt;
I&#39;m pressing forward with updating my Perl modules anyway, though. I
realized that honoring other people&#39;s desire for stability to such a
degree that I was unable to use Perl features added more than 15 years ago
was destroying my motivation to work on these Perl modules at all. So I&#39;ve
decided on a very slow and gradual approach where I&#39;m going to keep
pushing the minimum supported version forward but try to give people a lot
of warning.
&lt;/p&gt;

&lt;p&gt;
Personally, I think it&#39;s time to let ancient versions of Perl go and
follow the
&lt;a href=&quot;https://github.com/Perl-Toolchain-Gang/toolchain-site/blob/master/lyon-amendment.md&quot;&gt;Lyon Amendment&lt;/a&gt; about supported Perl versions. When we&#39;re talking
installing new modules for software released more than 15 years ago, we&#39;re
talking about special limited environments and retrocomputing more than
what I would consider routine software maintenance. Those tasks should
expect to need different tools and a different workflow so that they can
pin historical versions. Since this isn&#39;t something I&#39;m personally
interested in, my willingness to expend time and energy to assist is
limited.
&lt;/p&gt;

&lt;p&gt;
As you can probably tell, I still feel nervous about pressing forward in
this way, but I think this is the approach that lets me continue to enjoy
maintaining these Perl modules. It&#39;s been 29 years for Term::ANSIColor,
but I still enjoy fixing bugs in it and putting out a new release from
time to time, particularly if I can clean up the code a bit each time I
touch it.
&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-02T21:49:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://www.decadent.org.uk/ben/blog/2026/08/02/foss-activity-in-july-2026">
	<title>Ben Hutchings: FOSS activity in July 2026</title>
	<link>https://www.decadent.org.uk/ben/blog/2026/08/02/foss-activity-in-july-2026.html</link>
     <content:encoded>&lt;ul&gt;
  &lt;li&gt;Debian packages:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/apt&quot;&gt;apt&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:apt&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1078608&quot;&gt;#1078608: apt update silently leaves old index data&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-nonfree&quot;&gt;firmware-nonfree&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/firmware-nonfree/-/merge_requests/151&quot;&gt;!151: Update to 20260622&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/firmware-nonfree/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 20260622-1 to unstable&lt;/li&gt;
              &lt;li&gt;uploaded version 20260622-1~bpo13+1 to trixie-backports&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/hexagon-dsp-binaries&quot;&gt;hexagon-dsp-binaries&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:hexagon-dsp-binaries&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://bugs.debian.org/1141904&quot;&gt;#1141904: Missing new DSP binaries for shikra&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/initramfs-tools&quot;&gt;initramfs-tools&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:initramfs-tools&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1142780&quot;&gt;#1142780: initramfs-tools: ip=dhcp lease is not renewed while initramfs remains active&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/kernel-handbook&quot;&gt;kernel-handbook&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;opened and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/kernel-handbook/-/merge_requests/15&quot;&gt;!15: Update “Building a development version of the Debian kernel package”&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux&quot;&gt;linux&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:linux&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/851695&quot;&gt;#851695: replacing base package with -unsigned removes module files&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1126671&quot;&gt;#1126671: linux-image-6.17.13+deb13-amd64: Disconnect root (path=/) during heavy load on NvME, partial corruption on NTFS.crash soon but not yet&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1130365&quot;&gt;#1130365: linux-image-6.18.15+deb14-amd64: kernel panic during startup&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1140892&quot;&gt;#1140892: thunderbolt: Intel Goshen Ridge CL state regression breaks dock tunneling since 6.12.94&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://bugs.debian.org/1141185&quot;&gt;#1141185: linux-image-6.12.94+deb13-amd64: Occasional read problems in RAID/LVM/ext4 stack when under stress.&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141355&quot;&gt;#1141355: linux-image-6.1.0-49-amd64: procfs deadlock triggered by drop_caches on 6.1.0-49-amd64 (regression from 6.1.0-37)&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141448&quot;&gt;#1141448: MT7921 intermittently disappears after reboot on ASUS TUF Gaming F17 FX706HF&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141541&quot;&gt;#1141541: linux: i915 kernel BUG in i915_drm_client_remove_object from Xorg causing hard lock on 6.12.94+deb13-amd64&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141866&quot;&gt;#1141866: linux-image-7.1.3+deb14-amd64: no display on AMD Kaveri/CIK APU VGA output (amdgpu DC regression)&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1936&quot;&gt;!1936: [sparc64] Add nvme module to scsi-modules udeb&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed and merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1968&quot;&gt;!1968: [bookworm] net: mana: refresh driver from 6.12.94&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/1984&quot;&gt;!1984: udeb: Ensure that aead and macsec modules are in the right packages&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed and closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2003&quot;&gt;!2003: 6.1 backport: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242)&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2004&quot;&gt;!2004: [sparc64] udeb: scsi-modules: Use the default module list&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2010&quot;&gt;!2010: [x86] Backport security fixes for KVM&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2012&quot;&gt;!2012: Update to 6.1.177&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2017&quot;&gt;!2017: Enable NTFS_FS (and replace NTFS3_FS)&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;opened and closed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2019&quot;&gt;!2019: Fix rtmutex security issues&lt;/a&gt; (LTS)&lt;/li&gt;
              &lt;li&gt;opened &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2027&quot;&gt;!2027: Include rsync in Build-Depends-Arch for any build including tools&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;merged &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2038&quot;&gt;!2038: [loong64] drivers/mmc/host: Enable MMC_LOONGSON2 as module&lt;/a&gt;&lt;/li&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux/-/merge_requests/2041&quot;&gt;!2041: Update to 5.10.262&lt;/a&gt; (LTS)&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 5.10.259-1 to bullseye-security (LTS)&lt;/li&gt;
              &lt;li&gt;uploaded version 6.1.176-1 to bookworm-security (LTS)&lt;/li&gt;
              &lt;li&gt;uploaded version 6.1.177-1 to bookworm-security (LTS)&lt;/li&gt;
              &lt;li&gt;uploaded version 6.12.95-1~bpo12+1 to bookworm-backports (LTS)&lt;/li&gt;
              &lt;li&gt;uploaded version 7.0.13-1~bpo13+1 to trixie-backports&lt;/li&gt;
              &lt;li&gt;uploaded version 7.1.3-1~bpo13+1 to trixie-backports&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-6.1&quot;&gt;linux-6.1&lt;/a&gt; (LTS):
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-6.1/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 6.1.176-1~deb11u1 to bullseye-security&lt;/li&gt;
              &lt;li&gt;uploaded version 6.1.177-1~deb11u1 to bullseye-security&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;linux-6.12 (LTS):
        &lt;ul&gt;
          &lt;li&gt;Uploads:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 6.12.96-1~deb12u1 to bookworm-security (not
yet accepted)&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/linux-base&quot;&gt;linux-base&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;Merge requests:
            &lt;ul&gt;
              &lt;li&gt;reviewed &lt;a href=&quot;https://salsa.debian.org/kernel-team/linux-base/-/merge_requests/21&quot;&gt;!21: Draft: Add hooks to copy vmlinuz file to /boot&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/localechooser&quot;&gt;localechooser&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://bugs.debian.org/src:localechooser&quot;&gt;Bugs&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;replied to &lt;a href=&quot;https://bugs.debian.org/1141886&quot;&gt;#1141886: localechooser: Turkey is inconsistently classified under Asia in regionmap&lt;/a&gt;&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb&quot;&gt;wireless-regdb&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/wireless-regdb/news/&quot;&gt;Uploads&lt;/a&gt;:
            &lt;ul&gt;
              &lt;li&gt;uploaded version 2026.05.30-1~deb11u1 to bullseye-security (LTS)&lt;/li&gt;
            &lt;/ul&gt;
          &lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;Mailing lists:
    &lt;ul&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-kernel/&quot;&gt;debian-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/c6ab03ad04125365bf3ccda6d42285e22bb1e83e.camel@decadent.org.uk&quot;&gt;Agenda items for kernel-team meeting on 2026-07-01&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/d0012f0e7b0c012a3e05675fcc2525e1969666bd.camel@decadent.org.uk&quot;&gt;Agenda items for kernel-team meeting on 2026-07-22&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts-announce/&quot;&gt;debian-lts-announce&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/akfam9nRaDaqT2he@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4664-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/akgBqAUAJLAuUiyK@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4665-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/akqhaqWLkM4Jy49D@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4671-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/alKRo0uzT8v9B685@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4676-1] wireless-regdb new upstream version&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/aluK_-ysT8UPk48z@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4688-1] linux security update&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lists.debian.org/amXknKTE1Xwk58bC@decadent.org.uk&quot;&gt;[SECURITY] [DLA 4700-1] linux-6.1 security update&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/linux-kernel/&quot;&gt;linux-kernel&lt;/a&gt;:
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/linux-kernel/akvddtMQTDKLo2PH@decadent.org.uk/T/&quot;&gt;[PATCH] irqchip/irq-imgpdc: Remove unused driver&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
      &lt;li&gt;&lt;a href=&quot;https://lore.kernel.org/stable/&quot;&gt;stable&lt;/a&gt; (mostly LTS):
        &lt;ul&gt;
          &lt;li&gt;posted &lt;a href=&quot;https://lore.kernel.org/stable/1bfb3bb0dda1f5cd66ca8a48de2536c026355ded.camel@decadent.org.uk/T/&quot;&gt;[7.1] drm/amd/display: Add dp_skip_rbr flag for NUTMEG&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/418ca29bbbb1190853136331c572470dca803800.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 01/96] net/sched: act_pedit: use NLA_POLICY for parsing ex keys&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/6359da4c14e0b4c6ffa068407a42c07e56ef9c5c.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 11/96] slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/8601edcd7c9bcc70e75f85a758f8818c57945d07.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 81/96] nfsd: check get_user() return when reading princhashlen&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/c1c9fdd193db5a288c825364ee525d570dadfbe0.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 89/96] misc: fastrpc: Fix NULL pointer dereference in rpmsg callback&lt;/a&gt;&lt;/li&gt;
          &lt;li&gt;replied to &lt;a href=&quot;https://lore.kernel.org/stable/ed0c9af450494df5f7bfd72670754c8e48e1f36d.camel@decadent.org.uk/T/&quot;&gt;[PATCH 5.10 94/96] mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC&lt;/a&gt;&lt;/li&gt;
        &lt;/ul&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-02T17:06:31+00:00</dc:date>
	<dc:creator>Ben Hutchings</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6260">
	<title>Russell Coker: Packet Edit Meme and Debian SE Linux</title>
	<link>https://etbe.coker.com.au/2026/08/02/packet-edit-meme-debian-selinux/</link>
     <content:encoded>&lt;p&gt;There’s yet another Linux kernel exploit based on container functions, here’s the result when run as user_t on a SE Linux system:&lt;/p&gt;
&lt;pre&gt;$ ./packet_edit_meme 
[*] target /bin/su as uid 1000; entry at file offset 0x4340; shellcode 48 bytes
unshare: Permission denied
[-] page-cache corruption failed&lt;/pre&gt;
&lt;p&gt;Here is the audit log entry for this failure:&lt;/p&gt;
&lt;pre&gt;type=AVC msg=audit(1785640621.498:1843): avc:  denied  { create } for  pid=1770 comm=&quot;packet_edit_mem&quot; scontext=user_u:user_r:user_t:s0 tcontext=user_u:user_r:user_t:s0 tclass=user_namespace permissive=0&lt;/pre&gt;
&lt;p&gt;Here’s the result of running it from the unconfined_t domain:&lt;/p&gt;
&lt;pre&gt;$ ./packet_edit_meme 
[*] target /bin/su as uid 1001; entry at file offset 0x4340; shellcode 48 bytes
[+] su entry overwritten; exec&#39;ing su -&amp;gt; interactive root shell
# id
uid=0(root) gid=0(root) groups=0(root),1001(test2) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
# &lt;/pre&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.daniel-baumann.ch/posts/20260626-1.html&quot;&gt;Daniel Baumann wrote a blog post describing how this is fixed for Debian systems without SE Linux.&lt;/a&gt;&lt;/p&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/24/debian-selinux-pintheft/&quot; rel=&quot;bookmark&quot; title=&quot;Debian SE Linux and PinTheft&quot;&gt;Debian SE Linux and PinTheft&lt;/a&gt; &lt;small&gt;We have a new Linux exploit called PinTheft [1]. I...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/15/debian-selinux-ssh-keysign-pwn/&quot; rel=&quot;bookmark&quot; title=&quot;Debian SE Linux and ssh-keysign-pwn&quot;&gt;Debian SE Linux and ssh-keysign-pwn&lt;/a&gt; &lt;small&gt;I just tested out the ssh-keysign-pwn exploit [1] on Debian...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/08/dirty-frag-on-debian-and-se-linux/&quot; rel=&quot;bookmark&quot; title=&quot;Dirty Frag on Debian and SE Linux&quot;&gt;Dirty Frag on Debian and SE Linux&lt;/a&gt; &lt;small&gt;Hot on the heels of the Copy Fail vulnerability [1]...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-08-02T03:42:53+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/0-7564-1949-2.html">
	<title>Russ Allbery: Review: How to Steal a Galaxy</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/0-7564-1949-2.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;How to Steal a Galaxy&lt;/cite&gt;, by Beth Revis&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Chaotic Orbits #2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;DAW Books&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;December 2024&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;0-7564-1949-2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;143&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;How to Steal a Galaxy&lt;/cite&gt; is a far-future science fiction caper short
novel (maybe a novella?) and the sequel to &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-7564-1947-6.html&quot;&gt;&lt;cite&gt;Full Speed to a Crash Landing&lt;/cite&gt;&lt;/a&gt;. You don&#39;t have to remember the
details of the previous book to enjoy this one. There&#39;s an excellent
inline summary at the start of this installment.
&lt;/p&gt;

&lt;p&gt;
After an annoying negotiation with people who keep trying to preach at her
about causes, Ada Lamarr has a new contract. She is going undercover,
after a fashion, at a charity gala and auction on Rigel-Earth. While she&#39;s
there, she&#39;s going to steal something. What, precisely, she keeps a
mystery from both the other characters and from the reader until the end
of the story.
&lt;/p&gt;

&lt;p&gt;
Government agent Rian White is working security at this charity gala. Due
to its link with the plot of &lt;cite&gt;Full Speed to a Crash Landing&lt;/cite&gt;, he was
fairly certain Ada would be there, as indeed she is. What she is planning,
however, is maddeningly unclear. Also maddening is how good Ada looks in a
dress.
&lt;/p&gt;

&lt;p&gt;
As with the previous book, &lt;cite&gt;How to Steal a Galaxy&lt;/cite&gt; is told by Ada in
the first person using the same teasing tone and constant misdirection
that she uses when verbally fencing with Rian and the other characters. I
found this novella even more entertaining and satisfying than the previous
one. The charity gala is supposedly intended to benefit the poor people of
Earth, and is run with exactly the sort of condescension and disguised
capitalist looting typical of such exercises in elite charity. Ada&#39;s
narration is scathing in a deeply relatable way.
&lt;/p&gt;

&lt;p&gt;
Also, there is a trillionaire tech-bro fake philanthropist who is smug and
condescending and accustomed to getting exactly what he wants.
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    &quot;I don&#39;t think anyone should have enough personal wealth to decimate a
    large country&#39;s income just because he&#39;s going through a midlife
    crisis.&quot;
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
Ada&#39;s interactions with Strom Fetor are an absolute delight. He is so sure
of himself that he is incapable of registering her as a threat, and she
effortlessly deceives him by hiding in plain sight.
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    &quot;You really shouldn&#39;t be talking about this,&quot; Rian starts.
&lt;/p&gt;

&lt;p&gt;
    Fetor waves aside his concerns. &quot;We&#39;re all friends here.&quot;
&lt;/p&gt;

&lt;p&gt;
    &quot;Not me,&quot; I say. &quot;I hate you. Remember?&quot;
&lt;/p&gt;

&lt;p&gt;
    Fetor laughs in a tone I&#39;m sure he thinks is charming.
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
Fetor&#39;s complete inability to realize that a beautiful woman might both
sincerely not like him and not be flirting with him is perfect. I was
cackling through half of this book.
&lt;/p&gt;

&lt;p&gt;
Like any good heist story, there are twists and turns, surprises, double
agents, unexpected complications, and a delightful amount of verbal
fencing. I adore the narrative tone Revis uses for these stories. Ada has
just the right mix of idealism, cynicism, professionalism, and irreverence
to carry off the feeling that she&#39;s a step ahead of everyone else.
Underneath the bones of a delightful plot is a character who cares deeply
but is very aware of her limitations, and therefore has taught herself to
laugh at and be ruthless with her own emotions. I am finding it an
incredibly compelling type of competence porn.
&lt;/p&gt;

&lt;p&gt;
I enjoyed the first book of this series, but this one was so much better.
These stories are exactly the right length to keep the reader engrossed
throughout and satisfied but wanting more at the end. &lt;cite&gt;How to Steal a
Galaxy&lt;/cite&gt; ends on a cliffhanger of sorts, to be resolved in the next and
final book. I can hardly wait to start it.
&lt;/p&gt;

&lt;p&gt;
Highly recommended.
&lt;/p&gt;

&lt;p&gt;
Followed by &lt;cite&gt;Last Chance to Save the World&lt;/cite&gt;.
&lt;/p&gt;

&lt;p&gt;Rating: 9 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-01T04:23:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://xana.scru.org/posts/bamamba/lekkerderworst.html">
	<title>Clint Adams: N.K. Jemisin is doing a worldbuilding workshop at the Bronx Library Center tomorrow afternoon</title>
	<link>https://xana.scru.org/posts/bamamba/lekkerderworst.html</link>
     <content:encoded>&lt;div class=&quot;inlinecontent&quot;&gt;
&lt;p&gt;Normally, I do not read book reviews. Either I
haven&#39;t read the book, in which case there&#39;s spoiler
potential, or I have, in which case it&#39;s unlikely to
be useful or enjoyable for me to read a thing about
a thing I&#39;ve already read.&lt;/p&gt;
&lt;p&gt;But &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-316-29068-8.html&quot;&gt;Review: Radiant Star&lt;/a&gt;
caught my eye, and I thought, “Hmm, I&#39;ve read all
those books” and was curious. Of course, because
I am old and senile and have no understanding of
time, the “May 2026” staring at me was not able to
trigger the neural synapses that would remind me
that I haven&#39;t read any Ann Leckie since 2023.&lt;/p&gt;
&lt;p&gt;However, as I read Russ&#39;s review, and began to
wonder what the hell he was talking about, I was
able to piece together that while I have, in fact,
read 6 Ann Leckie books, none of them have been
&lt;em&gt;Radiant Star&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;This presented an opportunity, so I resolved to
add &lt;em&gt;Radiant Star&lt;/em&gt; to my todo list. To my surprise,
it was already there.&lt;/p&gt;
&lt;/div&gt;

&lt;div class=&quot;info&quot;&gt;
    Posted on 2026-07-31
    
&lt;/div&gt;
&lt;div class=&quot;info&quot;&gt;
    
    Tags: &lt;a href=&quot;https://xana.scru.org/tags/bamamba.html&quot; rel=&quot;tag&quot; title=&quot;All pages tagged &#39;bamamba&#39;.&quot;&gt;bamamba&lt;/a&gt;
    
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-31T15:32:32+00:00</dc:date>
	<dc:creator>C</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6257">
	<title>Russell Coker: Links July 2026</title>
	<link>https://etbe.coker.com.au/2026/07/31/links-july-2026/</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/ai-use-by-the-us-government.html&quot;&gt;Bruce Schneier and Nathan E. Sanders wrote a disturbing and informative article about the use of AI by the US government [1]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/ai-and-liability.html&quot;&gt;Bruce Schneier wrote an interesting blog post about corporate liability for AI decisions and the German court ruling about Google’s AI summaries [2]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://cybersecuritynews.com/anthropics-claude-fable-5-jailbroken/&quot;&gt;Cybersecurity News has an interesting article about how Pliny the Liberator succeeded in jailbreaking Anthropic’s latest LLM to give instructions on writing exploits, writing exploitable code (backdoors?), and making meth [3]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://glasswings.com.au/blog/2026-07/05-185304.html&quot;&gt;Andrew Pam wrote about the number of cars with internal combustion engines in NSW decreasing for the first time since 1910, EVs are taking over [4]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://pluralistic.net/2026/06/27/zuckerstreisand-2/#autodisparagement&quot;&gt;Cory Doctorow wrote an informative blog post about Facebook’s attempts to silence whistleblowers and what a pathetic little loser Zuckerberg is [5]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://forwardfuture.com/newsletter/originals/a-tax-system-built-on-labor-is-a-tax-system-built-on-a-melting-glacier&quot;&gt;Scott Santens wrote an insightful article about how to effectively levy taxes in the future when “AI” significantly reduces the number of workers [6]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.rongarret.info/2026/07/birthright-citizenship-hangs-on-by-its.html&quot;&gt;Ron Garrett wrote an insightful post about birthright citizenship in the US and his status as a US citizen who was not born there [7]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.bbc.com/future/article/20260626-how-scotland-changed-the-way-it-tackled-violence&quot;&gt;The BBC has an interesting article about the Scottish Violence Reduction Unit and how treating violence as a disease can significantly address the problem [8]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://archive.md/Gq2jB&quot;&gt;The LA Times has an interesting article about Covid19 causing cancer that had been in remission to return, sparking some new research into the effects of viruses on mammals [9]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=3ddTIa-AhXE&quot;&gt;CMU has an interesting video about ways to physically modify QR codes and how they could be used in real life [10]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://retout.co.uk/2026/07/10/blocking-distracting-news-links/&quot;&gt;Tim Retout wrote an informative post about the pervasive forms of advertising on the Internet, even on the BBC’s site and how some of it can be blocked [11]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.interceptfund.com/p/ending-respiratory-infections&quot;&gt;The Intercept Fund is a project to address respiratory illnesses and the long term mostly unnoticed costs they cause to society, we need governments and corporations to get on board with this [12]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.dw.com/en/german-activists-use-trademark-law-to-fight-far-right-nazi-merchandise/a-77770986&quot;&gt;The German news site DW has an interesting article about activists registering neo-nazi slang as trademarks to prevent the sale of nazi merchanise which funds racism [13]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://theconversation.com/south-sudan-at-15-how-the-political-elite-have-found-a-way-to-profit-from-peace-as-well-as-war-285846&quot;&gt;The Conversation has an insightful article about how in South Sudan and other war ravaged countries the peace process usually just allocates the spoils of war and therefore encourages more war [14]&lt;/a&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/ai-use-by-the-us-government.html&quot;&gt; https://tinyurl.com/26cnn3og&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/06/ai-and-liability.html&quot;&gt; https://tinyurl.com/22fewyml&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href=&quot;https://cybersecuritynews.com/anthropics-claude-fable-5-jailbroken/&quot;&gt; https://tinyurl.com/2a5t693d&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[4]&lt;a href=&quot;https://glasswings.com.au/blog/2026-07/05-185304.html&quot;&gt; https://glasswings.com.au/blog/2026-07/05-185304.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[5]&lt;a href=&quot;https://pluralistic.net/2026/06/27/zuckerstreisand-2/#autodisparagement&quot;&gt; https://tinyurl.com/26qzcadm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[6]&lt;a href=&quot;https://forwardfuture.com/newsletter/originals/a-tax-system-built-on-labor-is-a-tax-system-built-on-a-melting-glacier&quot;&gt; https://tinyurl.com/2csg4huw&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[7]&lt;a href=&quot;https://blog.rongarret.info/2026/07/birthright-citizenship-hangs-on-by-its.html&quot;&gt; https://tinyurl.com/2blnzzxg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[8]&lt;a href=&quot;https://www.bbc.com/future/article/20260626-how-scotland-changed-the-way-it-tackled-violence&quot;&gt; https://tinyurl.com/25v5j7v9&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[9]&lt;a href=&quot;https://archive.md/Gq2jB&quot;&gt; https://archive.md/Gq2jB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[10]&lt;a href=&quot;https://www.youtube.com/watch?v=3ddTIa-AhXE&quot;&gt; https://www.youtube.com/watch?v=3ddTIa-AhXE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[11]&lt;a href=&quot;https://retout.co.uk/2026/07/10/blocking-distracting-news-links/&quot;&gt; https://tinyurl.com/2xt9dgfp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[12]&lt;a href=&quot;https://blog.interceptfund.com/p/ending-respiratory-infections&quot;&gt; https://tinyurl.com/2y5f26rj&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[13]&lt;a href=&quot;https://www.dw.com/en/german-activists-use-trademark-law-to-fight-far-right-nazi-merchandise/a-77770986&quot;&gt; https://tinyurl.com/29ok2qsu&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[14]&lt;a href=&quot;https://theconversation.com/south-sudan-at-15-how-the-political-elite-have-found-a-way-to-profit-from-peace-as-well-as-war-285846&quot;&gt; https://tinyurl.com/2yxzsp7s&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/04/30/links-april-2026/&quot; rel=&quot;bookmark&quot; title=&quot;Links April 2026&quot;&gt;Links April 2026&lt;/a&gt; &lt;small&gt;Charles Stross wrote an interesting blog post about the apparent...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2024/07/30/links-july-2024/&quot; rel=&quot;bookmark&quot; title=&quot;Links July 2024&quot;&gt;Links July 2024&lt;/a&gt; &lt;small&gt;Interesting Scientific American article about the way that language shapes...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/02/17/links-february-2026/&quot; rel=&quot;bookmark&quot; title=&quot;Links February 2026&quot;&gt;Links February 2026&lt;/a&gt; &lt;small&gt;Charles Stross has a good theory of why “AI” is...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-31T10:33:57+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/9798360228431.html">
	<title>Russ Allbery: Review: Painting the Blues in Gretna Green</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/9798360228431.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;Painting the Blues in Gretna Green&lt;/cite&gt;, by Linzi Day&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Midlife Recorder #2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;Linzi Day&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;November 2022&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;9798360228431&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;577&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;Painting the Blues in Gretna Green&lt;/cite&gt; is a self-published fantasy
novel and the second in the Midlife Recorder series. It picks up
immediately after the end of &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/9798837010774.html&quot;&gt;&lt;cite&gt;Midlife in
Gretna Green&lt;/cite&gt;&lt;/a&gt;. I also read it almost immediately after, so I didn&#39;t pay
attention to how good the recap of previous events was.
&lt;/p&gt;

&lt;p&gt;
As before, this is urban fantasy except not urban. Day calls it paranormal
women&#39;s fantasy, which I suppose is as good of a genre label as any. The
other book I can think of off-hand that would go into that genre would be
Nancy Springer&#39;s &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/0-380-76742-2.html&quot;&gt;&lt;cite&gt;Larque on the Wing&lt;/cite&gt;&lt;/a&gt;,
although it is considerably more literary.
&lt;/p&gt;

&lt;p&gt;
I suspect I&#39;m going to read this whole series and it&#39;s going to be
impossible to review these books without talking about Niki&#39;s job, so I&#39;m
not going to treat that as a spoiler. It&#39;s fairly well-advertised in the
marketing for the book, so that feels justified. If you&#39;re particularly
averse to any spoilers, though, you may want to stop reading here until
you&#39;ve gotten to the reveal in the first book.
&lt;/p&gt;

&lt;p&gt;
Niki is now officially the Recorder, with the power, advice book, and
sentient house to go with it. She&#39;s about to face her first test in
managing interworld politics: There&#39;s something amiss in the world of the
Picts. Her allies are dropping hints, there&#39;s a petition from a group on
the Pict world that she can&#39;t make sense of, and although she likes the
queen of the Picts, there is a great deal of tension beneath the surface
that she doesn&#39;t understand. Meanwhile, after the incompetent disaster
that she uncovered in the first book, Niki is determined to pick her new
staff by her own criteria.
&lt;/p&gt;

&lt;p&gt;
The second book leans even harder into giving Niki both a tangled mess
created by previous incompetence and enough power to fix it. Watching that
happen is very satisfying, particularly when it involves surprising people
who are rather too used to getting their own way.
&lt;/p&gt;

&lt;p&gt;
I was somewhat less convinced that Niki is getting the right training to
make the decisions that she&#39;s making. Diplomacy and staff management are
real skills that one needs to learn, not just wing on vibes and gut
instinct. My love of competence porn occasionally wishes that Niki had a
bit more structure around her competence. We do at least get a new
fictional self-help book on how to rule that contributes the quotes that
open each chapter. Not the ethics and management training that I would
have chosen, but it&#39;s something!
&lt;/p&gt;

&lt;p&gt;
In defense of Niki&#39;s technique, it becomes clear in this book that the
last few recorders have been far too cautious, conservative, and content
with a status quo that involved a minimum of work. One of the delights of
this book is that Niki thinks power exists to be used to fix things and is
determined to use it, not just sit on it. I had more suspension of
disbelief issues with this book than with the first — some of the problems
Niki is solving seem far too obvious to have been in stasis for this long
while also having this easy of a solution, and the level of political
power given to the Recorder is a bit unbelievable — but it is so
satisfying to see Niki cajole and bully people into being sensible.
&lt;/p&gt;

&lt;p&gt;
I have no idea if this is intentional on Day&#39;s part, but I will not be at
all surprised if adult-diagnosed ADHD comes up at some point in this
series. The way that Niki&#39;s focus jumps, her tendency to veer between
focusing on a problem and forgetting about it, and something about the way
she switches between trains of thought or misses important context because
she&#39;s jumping to conclusions is making me wonder. This, to be clear, is
not a complaint; I think it makes Niki more relatable and more
interesting. It&#39;s a good thing that she has a sentient house to serve as
her assistant. The glee with which she&#39;s delegating any task that involves
keeping track of details or following up with other people feels like a
bit of an indicator by itself.
&lt;/p&gt;

&lt;p&gt;
I did get a bit frustrated with the plot structure of this book. Niki
keeps mentioning that a critical petition submitted to her office makes no
sense, but it takes half of this (rather long) book before she finally
explains to anyone else, even the reader, what&#39;s deficient about it. The
excuse within the book is that she&#39;s having a rather busy day, but by the
third time Niki mentions and then fails to do anything about the petition,
I was wishing Day would stop bringing it up until she was ready for that
part of the plot.
&lt;/p&gt;

&lt;p&gt;
This, as with a few issues in the previous book, feels partly like an
editing problem. There is something joyful in indulgent, sprawling books,
but only up to the point where they become repetitive. &lt;cite&gt;Painting the
Blues&lt;/cite&gt; was right at that line, and once again I wish someone had helped
Day trim about fifty pages out of it.
&lt;/p&gt;

&lt;p&gt;
All that said, and despite having more quibbles with this book than the
previous one, this continues to be great fun. It&#39;s satisfying
wish-fulfillment about fixing long-standing problems and having the power
to not have to put up with abusive nonsense and ridiculous bullshit, and I
am so here for that. I hope Niki realizes she&#39;s eventually going to need
more refined skills than a heart-to-heart over wine, but she&#39;s learning on
the job and I&#39;m happily along for the ride. She&#39;s also capable of
recognizing skill in other people, and that goes a long way.
&lt;/p&gt;

&lt;p&gt;
Recommended if you liked the first one and are in the mood for another
fantasy of &quot;no, we&#39;re not going to leave it that way, we&#39;re going to fix
that right now.&quot;
&lt;/p&gt;

&lt;p&gt;
Followed by &lt;cite&gt;Ties that Bond in Gretna Green&lt;/cite&gt;.
&lt;/p&gt;

&lt;p&gt;Rating: 7 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-31T03:06:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://www.earth.li/~noodles/blog/2026/07/my-cpu-died.html">
	<title>Jonathan McDowell: My CPU died</title>
	<link>https://www.earth.li/~noodles/blog/2026/07/my-cpu-died.html</link>
     <content:encoded>&lt;p&gt;I built my current house server &lt;a href=&quot;https://www.earth.li/~noodles/blog/2019/07/upgrading-the-house-server.html&quot;&gt;back in 2019&lt;/a&gt;. It had an upgrade from the original Ryzen 2700 to a 5700G in late 2021, but otherwise is still running with the original setup. Back in November it developed some erratic behaviour (initially manifesting as problems with the TPM, which is ironic as I’ve spent a bunch of time at my day job trying to improve TPM reliability), culminating in unreliable reboots. I had a limited amount of ability to swap parts out, but ultimately decided it was a motherboard issue (thinking perhaps &lt;a href=&quot;https://www.reddit.com/r/Amd/comments/byi8py/that_board_has_bad_vrms/&quot;&gt;VRM problems&lt;/a&gt;), found a replacement &lt;a href=&quot;https://pcbelfast.co.uk/&quot;&gt;locally&lt;/a&gt;, and everything seemed fine.&lt;/p&gt;

&lt;p&gt;Until May.&lt;/p&gt;

&lt;p&gt;At that point I rebooted the machine for a Debian point release, and it failed to come back. Fans would spin, but there was no sign of actual life. I ended up pressing a temporary machine into service (that could at least run the Home Assistant container, and a few other critical bits) while I tried to work out what was wrong. I’d kept the previous motherboard, and still had the Ryzen 2700, so I did a bunch of swaps (and obtained a motherboard buzzer to try and get some indication about whether there were useful beep codes being emitted), and ultimately came to the conclusion that the CPU had died.&lt;/p&gt;

&lt;p&gt;I’m not quite clear what happened here. I played it safe and replaced the PSU at the same time, in case that was the original cause back in November and ultimately damaged the CPU, but both old + new motherboards worked just fine with the 2700.&lt;/p&gt;

&lt;p&gt;That left a decision about what to do. This &lt;a href=&quot;https://www.earth.li/~noodles/blog/2013/04/building-a-new-house-server.html&quot;&gt;previous server&lt;/a&gt; was from 2013, so this machine has now lasted longer than that and I could justifiably upgrade. However when I went to look at what the equivalent modern machine would be it’s only a couple of generations later (Zen 5 vs Zen 3), and 64GB RAM alone would have set me back ~ £1k. For not a lot of gain. So I ended up buying a replacement Ryzen 5700G, hopefully allowing me to put off thinking about an upgrade until Zen 6 is out, and RAM prices are saner (though I understand that might take a &lt;a href=&quot;https://www.techspot.com/news/112934-ram-prices-expected-rise-another-40-50-q3.html&quot;&gt;couple of years&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;It’s not the first time I’ve had a faulty PSU be the cause of a dead machine, but it was a pretty frustrating experience.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-31T00:28:00+00:00</dc:date>
	<dc:creator>Jonathan McDowell</dc:creator>
</item> 
<item rdf:about="https://optimizedbyotto.com/post/estonia-well-governed-country/">
	<title>Otto Kekäläinen: Estonia, the country of the fit and the wit</title>
	<link>https://optimizedbyotto.com/post/estonia-well-governed-country/</link>
     <content:encoded>&lt;img alt=&quot;Featured image of post Estonia, the country of the fit and the wit&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/featured-image.jpg&quot; /&gt;&lt;p&gt;While many Western democracies seem to be in a state of decay and are no longer the safe, civilized and prosperous countries they once were, there are still some European countries that are governed well. One of those that stand out is Estonia.&lt;/p&gt;
&lt;p&gt;Estonia is probably most well known for &lt;strong&gt;multiple software companies&lt;/strong&gt; that originated from there, such as &lt;a class=&quot;link&quot; href=&quot;https://wise.com/invite/ecac/ottok108&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Wise&lt;/a&gt;, &lt;a class=&quot;link&quot; href=&quot;https://invite.bolt.eu/OTTOKSQ&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Bolt&lt;/a&gt;, Pipedrive and Skype. The government itself is also famous for being early in issuing &lt;strong&gt;government IDs with an embedded smart chip&lt;/strong&gt; for online authentication already in the 1990s. Via the national portal at &lt;a class=&quot;link&quot; href=&quot;https://eesti.ee/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;eesti.ee&lt;/a&gt; all residents can access extensive eServices ranging from viewing their health benefits to filing taxes.&lt;/p&gt;
&lt;p&gt;Estonia has also been running an &lt;a class=&quot;link&quot; href=&quot;https://www.e-resident.gov.ee/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;e-Residency&lt;/a&gt; program since 2014, where they issue digital ID cards to foreigners, making it easy for them to remotely log into the government portals and for example, establish businesses, file annual reports and so forth. Note that the e-Residency is not a path to physical residency. Estonia does, however, have &lt;a class=&quot;link&quot; href=&quot;https://www.e-resident.gov.ee/nomadvisa/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;a separate Digital Nomad visa program&lt;/a&gt; that makes it easy for &lt;strong&gt;non-EU citizens&lt;/strong&gt; to also physically establish themselves in Estonia, assuming, of course, you meet the criteria, which includes, among others, a minimum monthly income of 3960 € from outside Estonia. &lt;strong&gt;EU citizens&lt;/strong&gt; naturally have free mobility inside the EU and can simply get an apartment and register as a resident in Estonia if they so choose. And there are plenty of reasons to do so.&lt;/p&gt;
&lt;h2 id=&quot;estonians-value-health-education-and-entrepreneurship&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#estonians-value-health-education-and-entrepreneurship&quot;&gt;&lt;/a&gt;Estonians value health, education and entrepreneurship
&lt;/h2&gt;&lt;p&gt;I moved to Estonia about one and a half years ago. In &lt;em&gt;my observations&lt;/em&gt; Estonia strikes me as &lt;strong&gt;a country that values health, education&lt;/strong&gt; (in particular programming and natural sciences) and entrepreneurship highly.&lt;/p&gt;
&lt;p&gt;I don’t know how Estonians achieve it, but they look pretty fit and rarely obese. Estonia has rye bread and sauna in their culture just like Finland, and in addition the flat terrain and well-planned bike routes and extensive network of parks (and pull-up bars everywhere) seem to create an environment where it is easy to live in a healthier way. The consumption of processed foods and candy also seems relatively low among Estonians.&lt;/p&gt;
&lt;p&gt;The &lt;a class=&quot;link&quot; href=&quot;https://www.myfitness.ee/en/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;gym chain MyFitness&lt;/a&gt; also seems to be present everywhere. Even the Tallinn airport has a calisthenics workout station right at the departure gates, which anyone is free to use while waiting for their flight to take off. One of the top longevity influencers in Europe, &lt;a class=&quot;link&quot; href=&quot;https://www.siimland.co/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Siim Land&lt;/a&gt;, is Estonian.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Estonia has lots of good bike paths, parks and outdoor gyms&quot; class=&quot;gallery-image&quot; height=&quot;628&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-harbour-pull-up-bar.jpg&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;There is even a calisthenics station with pull-up bar and more at the departure gates at Tallinn airport&quot; class=&quot;gallery-image&quot; height=&quot;628&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-airport-pull-up-bar.jpg&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;Estonians also seem to value the school system highly. The government has been actively &lt;a class=&quot;link&quot; href=&quot;https://www.valitsus.ee/en/news/government-approved-2026-state-budget&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;raising teacher pay and has a stated goal of reaching 120% of the national average by 2027&lt;/a&gt;. The students are also expected to value the education and respect their teachers. According to the &lt;a class=&quot;link&quot; href=&quot;https://www.oecd.org/en/publications/results-from-talis-2024-country-notes_e127f9e2-en/estonia_44178e34-en.html&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;TALIS 2024 survey&lt;/a&gt; (OECD’s international teacher survey), Estonian teachers spend significantly more time on actual teaching and learning and waste less time on interruptions or keeping classroom order compared to the OECD average. This is among the highest rates internationally, meaning they spend relatively little time on maintaining order or dealing with disruptions. While the international education benchmark PISA scores have been dropping globally, Estonia has consistently been climbing the ranks in past decades. In the latest &lt;a class=&quot;link&quot; href=&quot;https://www.oecd.org/en/publications/pisa-2022-results-volume-i_53f23881-en/full-report/how-did-countries-perform-in-pisa_dc514907.html&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;PISA study (from 2022), Estonia ranked number one in Europe&lt;/a&gt; for reading, mathematics and science. In the overall results, Estonia ranked seventh globally, only behind countries such as Japan, Korea and Singapore.&lt;/p&gt;
&lt;p&gt;Valuing entrepreneurship is evident in how the taxation system is set up in Estonia. Famously, in Estonia, companies can defer taxes on annual earnings and reinvest all of their profit in growing the company. Taxes are due only later, when paid out from the company, for example as dividends. For individuals, receiving dividends from any Estonian or foreign company is tax-free as long as the company paying dividends already paid corporate tax on the same income.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The tax system is also very simple.&lt;/strong&gt; For all individuals, all types of income, including salary and capital gains, are always taxed at a flat rate of 22%. This removes the incentive for anyone to try to convert income into different types, setting up holding company structures and other optimizations as there is no gain. All entrepreneurs can simply focus on growing their business and forget extra bureaucracy. There is also no marginal tax rate cliff to stop working at – everyone is encouraged to always try to produce as much value as they can. A simple tax system is also reflected in the fact that anyone can easily &lt;a class=&quot;link&quot; href=&quot;https://emta.ee/en&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;read all tax rules that apply to individuals in plain English on the Estonian tax authority website&lt;/a&gt;, and one does not need to hire any accountants simply to file taxes.&lt;/p&gt;
&lt;p&gt;Estonia also has a very straightforward investment account system: any person can freely open a self-directed investment account at any brokerage at no extra cost and report it as such to the tax authority, and then use it to save for an apartment, retirement, or other purposes, and defer all income taxes until withdrawal. There are no caps or time limits, and all residents are encouraged to save and invest as much as they can and thus take responsibility for their own wealth accumulation.&lt;/p&gt;
&lt;p&gt;It seems that culturally Estonians respect people who are active and progress in their careers and businesses more than in other countries. Unlike in Finland, successful people are admired and living on government welfare is not romanticized. At the same time, the government benefits are less generous so people can’t live comfortably on them and, for example, &lt;a class=&quot;link&quot; href=&quot;https://news.err.ee/600251/nearly-half-of-quota-refugees-currently-not-in-estonia&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;many of the asylum seekers Estonia accepted have since left on their own initiative&lt;/a&gt; to other European countries in search of better benefits.&lt;/p&gt;
&lt;h2 id=&quot;low-crime-high-trust&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#low-crime-high-trust&quot;&gt;&lt;/a&gt;Low crime, high trust
&lt;/h2&gt;&lt;p&gt;Another thing that strikes me when walking the streets of Tallinn is that there are no drug addicts, beggars, thugs or the like. The difference compared to, for example, Vancouver (where I lived previously) is stark. In public buildings, people leave their coats and bags hanging in the lobby while visiting. Private houses and apartment block yards are not fenced. In my building, I noticed people even leave their bikes unlocked in the bike shed. I have also seen the staff of a coffee stall in a shopping mall going for a break and leaving everything unattended, not worrying that anyone would take anything while the staff is away.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Nobody is stealing anything from the unattended coffee shop while staff is having a break at Ülemiste shopping mall&quot; class=&quot;gallery-image&quot; height=&quot;450&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-coffee-stand-unattanded.jpg&quot; width=&quot;600&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;This is not just my personal experience. According to the &lt;a class=&quot;link&quot; href=&quot;https://www.numbeo.com/crime/rankings_by_country.jsp?title=2026&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Numbeo crime index&lt;/a&gt;, Estonia has one of the lowest crime rates in the world. Also, comparing drug and property crime stats, for example, Finland has twice as much crime per capita, and places like Vancouver in Canada almost five times more.&lt;/p&gt;
&lt;p&gt;I don’t have any clear explanation for why crime is so much lower in Estonia, but some suggest that higher social cohesion and lower levels of welfare contribute to people standing to lose more if they behave antisocially. Compared to Finland, Estonia also more readily jails repeat offenders, and those who are put on trial will experience a swifter court process thanks to simplified legal processes and more efficient governance.&lt;/p&gt;
&lt;h2 id=&quot;moving-to-estonia-quick-checklist&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#moving-to-estonia-quick-checklist&quot;&gt;&lt;/a&gt;Moving to Estonia: quick checklist
&lt;/h2&gt;&lt;p&gt;Moving to Estonia is very easy for any EU citizen, in particular if your work is not location-dependent (e.g., remote work or an online business) and you are simply looking for the cleanest and safest environment to live in.&lt;/p&gt;
&lt;p&gt;First, check into a hotel in Tallinn, check out various neighborhoods to figure out what area you like (my favorites are Kalaranna, Kalamaja, Noblessner and Volta) and start browsing available apartments &lt;a class=&quot;link&quot; href=&quot;https://www.kv.ee/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;in English at kv.ee&lt;/a&gt;. Most professionals speak fluent English, so there should not be any difficulty in reaching out to people by email or phone.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Tallinn is famous for the old town&quot; class=&quot;gallery-image&quot; height=&quot;628&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-old-town.jpg&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;The economic boom of recent decades created a lot of new construction, with Kalaranna being among the newest areas&quot; class=&quot;gallery-image&quot; height=&quot;628&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/tallinn-kalaranta.jpg&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;p&gt;The next step is to buy a local prepaid SIM card at e.g., an R-Kiosk or a convenience store as signing up for other matters later on will require an Estonian phone number. Once you have an apartment and e.g., signed a rental agreement, you can register in the population registry online.&lt;/p&gt;
&lt;p&gt;After that, you have proof you are a local resident with an address and telephone number in Estonia. With local resident status, you can go to the police station to get a local ID card. Don’t bother scheduling an appointment, just go to the &lt;a class=&quot;link&quot; href=&quot;https://www.politsei.ee/en/services/services/tallinn-tammsaare&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Tammesaare police station in Tallinn&lt;/a&gt;, take a queue number and wait. Once it is your turn, they will guide you on how to use the photo booth, fingerprint registration device, and file your application. A few days later you will receive an email confirming whether your application was accepted, and after a few more days, you will get another email notifying you that your ID card has been printed and is available for pick-up at the same location. &lt;strong&gt;This will also be your first practical experience of how fast and efficient the government in Estonia is.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Once you have the local ID card, you can use the smart card feature to log into all the government eServices and sort out the rest of the relocation process, such as registering tax residency and getting a family doctor.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;The main eServices portal in Estonia: eesti.ee&quot; class=&quot;gallery-image&quot; height=&quot;675&quot; src=&quot;https://optimizedbyotto.com/post/estonia-well-governed-country/estonia-government-eservices-portal.png&quot; width=&quot;1200&quot; /&gt;
&lt;/p&gt;
&lt;h2 id=&quot;how-did-estonia-evolve-to-be-like-this&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#how-did-estonia-evolve-to-be-like-this&quot;&gt;&lt;/a&gt;How did Estonia evolve to be like this?
&lt;/h2&gt;&lt;p&gt;After Estonia regained its independence after the fall of the Soviet Union in 1991, the first elected government in 1992 was led by a very progressive 31-year-old Prime Minister &lt;a class=&quot;link&quot; href=&quot;https://en.wikipedia.org/wiki/Mart_Laar&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Mart Laar&lt;/a&gt;, who managed to set up some very good policies and laid the foundation of a society that has evolved well in the decades since. Estonia was very lucky to have people in power in the 1990s who didn’t simply copy what other Western countries were doing, but who tried to think about things from first principles and create Estonia’s own model for efficient and fair governance. As a post-Soviet country, the population had also been vaccinated against overly socialist and unrealistic ideals, and everyone had a healthy distrust of the government’s ability to solve problems and emphasis was placed on people’s liberty to work for themselves as they best see fit. The improvement in living standards over the past 35+ years has also been witnessed by the population, and voting behavior supports keeping the country on the same trajectory.&lt;/p&gt;
&lt;p&gt;General living standards still continue to improve as the &lt;a class=&quot;link&quot; href=&quot;https://stat.ee/en/news/average-wages-increased-by-56-last-year&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;nominal wage growth sits at around 6%&lt;/a&gt;, clearly above the &lt;a class=&quot;link&quot; href=&quot;https://stat.ee/en/news/the-consumer-price-index-was-up-by-31-in-february-year-on-year&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;annual inflation rate of about 3%&lt;/a&gt;. In 2026, the Estonian &lt;a class=&quot;link&quot; href=&quot;https://www.eestipank.ee/en/press/economic-forecast-achieving-lasting-growth-economy-needs-confidence-invest-16062026&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;economy is expected to grow about 2.4%&lt;/a&gt;, which is faster than the EU average. The growth in Estonia is not the result of any accounting tricks - Estonia is part of the euro and can’t print its own currency, nor has it been funding the public sector with excessive debt. With a 24% debt-to-GDP ratio, Estonia consistently ranks as one of the most responsibly managed countries among advanced Western economies.&lt;/p&gt;
&lt;p&gt;As wages in Estonia soon catch up with the EU average, and higher defence spending has forced the government to raise taxes in recent years, the economic growth that Estonia has enjoyed for 35+ years since it exited the Soviet Union might slow down a bit in future years. The policies that fueled this growth in living standards, however, are likely to stay.&lt;/p&gt;
&lt;h2 id=&quot;the-tiger-leap&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#the-tiger-leap&quot;&gt;&lt;/a&gt;The tiger leap
&lt;/h2&gt;&lt;p&gt;There is one specific government policy in Estonia’s history that I think should be highlighted in particular. Estonia was very progressive by announcing the &lt;a class=&quot;link&quot; href=&quot;https://www.educationestonia.org/tiger-leap/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Tiigrihüpe&lt;/a&gt; (&lt;em&gt;Tiger Leap&lt;/em&gt;) program in 1996 with the goal of equipping all schools with computers and teaching all students the basics of programming. This surely had a large influence on why Estonia has so many successful software companies, why the government eServices are so mature that even neighboring countries like Finland are striving to copy the Estonian government’s IT architecture called &lt;a class=&quot;link&quot; href=&quot;https://e-estonia.com/solutions/interoperability-services/x-road/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;em&gt;X-road&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Tiigrihüpe project was originally suggested in the mid-1990s by &lt;a class=&quot;link&quot; href=&quot;https://en.wikipedia.org/wiki/Toomas_Hendrik_Ilves&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Toomas Hendrik Ilves&lt;/a&gt;, then ambassador of Estonia to the United States, Canada and Mexico, and later President of Estonia in 2006–2016. While he was a psychologist by education, he was also a self-taught amateur programmer and used his political influence to promote sensible adoption of information technology in both Estonia and the EU.&lt;/p&gt;
&lt;p&gt;The history of Estonia has several prominent figures who were not lawyers by profession but engineers, scientists and historians who were very practical in their political decisions, which I think is now reflected in how government processes were formed.&lt;/p&gt;
&lt;p&gt;The video below shows how the Estonian government advertises itself and what values they choose to highlight:&lt;/p&gt;
&lt;div class=&quot;video-wrapper&quot;&gt;


&lt;/div&gt;
&lt;h2 id=&quot;should-other-countries-adopt-policies-from-estonia&quot;&gt;&lt;a class=&quot;header-anchor&quot; href=&quot;https://optimizedbyotto.com/index.xml#should-other-countries-adopt-policies-from-estonia&quot;&gt;&lt;/a&gt;Should other countries adopt policies from Estonia?
&lt;/h2&gt;&lt;p&gt;Of course, not everything is perfect in Estonia either. The &lt;a class=&quot;link&quot; href=&quot;https://stat.ee/en/en/find-statistics/statistics-theme/population/births&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;fertility rate of 1.16&lt;/a&gt; in Estonia is very low. This trend is present globally, but in Estonia it is way below the EU average. Also, the service culture is something that needs to improve in Estonia. While services are in general fast and efficient, the attitude of people working in cafes and stores does not reflect a willingness to fill in gaps if the standard process falls short, nor are visitors actively made to feel welcome as individual humans, but are treated as mere process inputs.&lt;/p&gt;
&lt;p&gt;However, many of the things listed earlier I think should be studied by policymakers elsewhere. Societies are complex systems and there is of course no guarantee that copying a single policy to another country with different ethnicities, history and ingrained culture would lead to the same policy outcomes. But &lt;strong&gt;considering that Estonia is a small country without favorable geography and no natural resources&lt;/strong&gt;, and that it started out from a place of total chaos, low economic activity and high crime in 1992 to rise to what it is now in 2026, the success it has seen is surely largely a result of good policies, governance and culture that other countries can and should mimic.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-31T00:00:00+00:00</dc:date>
	<dc:creator>Otto Kekäläinen</dc:creator>
</item> 
<item rdf:about="https://xana.scru.org/posts/mintings/mergetooling.html">
	<title>Clint Adams: not ninpo</title>
	<link>https://xana.scru.org/posts/mintings/mergetooling.html</link>
     <content:encoded>&lt;div class=&quot;inlinecontent&quot;&gt;
&lt;p&gt;The UX of &lt;code&gt;jj&lt;/code&gt;&#39;s builtin merge editor finally became
too much for me. So, I looked at the list of merge
tool options, saw &lt;code&gt;vimdiff&lt;/code&gt;, and thought, “Oh, cool,
I know how to use vimdiff.” So, I launched
&lt;code&gt;jj config edit --user&lt;/code&gt;, added a &lt;code&gt;ui&lt;/code&gt; section, and
set &lt;code&gt;merge-editor&lt;/code&gt; to &lt;code&gt;vimdiff&lt;/code&gt;. With the new
config, I ran &lt;code&gt;jj resolve&lt;/code&gt; again. It was at that
point that I realized that I do not, in fact, know
how to use &lt;code&gt;vimdiff&lt;/code&gt;: I only know how to use
&lt;code&gt;vimdiff&lt;/code&gt; with two buffers. What appeared in my
terminal was a 4-pane monstrosity. Why are there
four panes? I&#39;m trying to resolve conflicts
between only two changes on only one file. For a
moment, I nearly go down a rabbit hole, because
&lt;a href=&quot;https://github.com/jj-vcs/jj/wiki/Vim,-Neovim#using-vim-as-a-diff-tool&quot;&gt;this&lt;/a&gt;
says that by default, &lt;code&gt;vimdiff&lt;/code&gt; is “barely useable”
[sic]. Should I be installing some addon or a
Python script? Apparently there are tradeoffs.
I just want to resolve these conflicts without
doing line-by-line approvals for how ever many
hours that would take.&lt;/p&gt;
&lt;p&gt;Accordingly, I ran away in terror, installed &lt;code&gt;meld&lt;/code&gt;,
set &lt;code&gt;merge-editor&lt;/code&gt; to meld, and went clicky-clicky
in the GUI. I&#39;m not happy using a GUI, but at least
it didn&#39;t have a mysterious extra buffer to confuse
and taunt me.&lt;/p&gt;
&lt;/div&gt;

&lt;div class=&quot;info&quot;&gt;
    Posted on 2026-07-30
    
&lt;/div&gt;
&lt;div class=&quot;info&quot;&gt;
    
    Tags: &lt;a href=&quot;https://xana.scru.org/tags/mintings%20jujutsu.html&quot; rel=&quot;tag&quot; title=&quot;All pages tagged &#39;mintings jujutsu&#39;.&quot;&gt;mintings jujutsu&lt;/a&gt;
    
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-30T12:12:12+00:00</dc:date>
	<dc:creator>C</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/0-9863735-1-6.html">
	<title>Russ Allbery: Review: In the House of Aryaman, a Lonely Signal Burns</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/0-9863735-1-6.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;In the House of Aryaman, a Lonely Signal Burns&lt;/cite&gt;, by Elizabeth Bear&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Sub-Inspector Ferron Mysteries #1&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;Sobbing Squonk Press&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;2012&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Printing:&lt;/td&gt;
    &lt;td&gt;2018&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;0-9863735-1-6&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;73&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;In the House of Aryaman, a Lonely Signal Burns&lt;/cite&gt; is a science fiction
police procedural set in relatively near-future India. This novella was
originally published in &lt;cite&gt;Asimov&#39;s SF&lt;/cite&gt; and collected in several
anthologies as well as Bear&#39;s &lt;cite&gt;Shuggoths in Bloom&lt;/cite&gt; collection, which
I have on my shelf but have not yet read. I probably should have checked
that before I got another copy. It is the first story of a series in the
sense that there is an Audible-only sequel available.
&lt;/p&gt;

&lt;p&gt;
Like many police procedurals, this one opens with a crime scene.
Sub-Inspector Ferron and her partner are inspecting a tube of human meat
in the middle of the rug of a luxurious apartment in Bengaluru. The tube
is apparently the remains of one Dexter Coffin, an American with a high
tech workspace who was apparently mangled beyond recognition in his locked
apartment near a table set for two.
&lt;/p&gt;

&lt;p&gt;
Dexter&#39;s cat is a witness. In this future world of cats enhanced with
limited language skills, this would have been very useful, but the cat&#39;s
memory was apparently wiped. Ferron will have to get to the bottom of the
mystery some other way. Also, she apparently now has a new cat.
&lt;/p&gt;

&lt;p&gt;
Meanwhile, Ferron is worrying about her partner&#39;s mental health, her
partner is worrying about her use of stimulants to stay on duty for this
murder investigation, and Ferron&#39;s mother is harassing her for money to
pay the bills of her virtual reality addiction. Her job is a good
distraction from other problems she&#39;d rather not deal with.
&lt;/p&gt;

&lt;p&gt;
I am trying to come up with something insightful to say about this story,
and I&#39;m not having much success. It&#39;s a police procedural with a bit of a
science fiction twist. The characters are fine but not, at least for me,
particularly engaging. There is some deft world-building, but nothing that
grabbed my attention or made me desperate to read more stories in this
world.
&lt;/p&gt;

&lt;p&gt;
Perhaps the most interesting part of the background, and the reason why I
picked up this novella, is that this is the universe that eventually
becomes the setting of the &lt;a href=&quot;https://www.eyrie.org/~eagle/reviews/books/1-5344-0300-0.html&quot;&gt;White Space series&lt;/a&gt;.
There is an early version of right-minding handled entirely through
medicine without the later invention of the fox implant, and there are
some signs that humanity is slowly digging itself out of the hole of
climate change and antisocial behavior that it had dug. I found this
mildly interesting, but it doesn&#39;t add much to the later series and is
very skippable.
&lt;/p&gt;

&lt;p&gt;
The source of the title is a bright light originating in the Andromeda
galaxy, which is contained in Uttara Bhādrapadā in Vedic astrology. Ferron
says this is under the influence of the god Aryaman. This is unrelated to
the plot; it&#39;s just a background event that prompts some introspective
musing from Ferron at the end of the story. It&#39;s a nice moment, but I
would have been more interested in the full story of first contact between
Earth and the Synarche.
&lt;/p&gt;

&lt;p&gt;
This was a mildly pleasant way to spend a few hours and I&#39;m already
forgetting all of the details. It&#39;s a competent story, but not one I feel
a need to recommend to others.
&lt;/p&gt;

&lt;p&gt;
Followed by &lt;cite&gt;A Blessing of Unicorns&lt;/cite&gt;, which appears to be an Audible
audiobook exclusive.
&lt;/p&gt;

&lt;p&gt;Rating: 6 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-30T03:25:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="https://diffoscope.org/news/diffoscope-326-released/">
	<title>Reproducible Builds (diffoscope): diffoscope 326 released</title>
	<link>https://diffoscope.org/news/diffoscope-326-released/</link>
     <content:encoded>&lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;326&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[ Vagrant Cascadian ]
* Add external tool reference for &quot;pedump&quot; to use the &quot;mono&quot; package on
  GNU guix.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href=&quot;https://diffoscope.org&quot;&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-30T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds (diffoscope)</dc:creator>
</item> 
<item rdf:about="http://joeyh.name/blog/entry/my_harddrive_is_probably_not_full/">
	<title>Joey Hess: my harddrive is probably not full</title>
	<link>http://joeyh.name/blog/entry/my_harddrive_is_probably_not_full/</link>
     <content:encoded>&lt;p&gt;I enjoyed reading this post by Marginalia
&lt;a href=&quot;https://www.marginalia.nu/log/a_139_hdd/&quot;&gt;&quot;Your harddrive is probably full&quot;&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;
You can construct an entropic argument that there are simply more ways for
a harddrive to be full than ways in which it can be empty.
&lt;/blockquote&gt;


&lt;p&gt;Of course it made me check how full my laptop drive is, and indeed it was more
than 75% full, as predicted.&lt;/p&gt;

&lt;p&gt;But, I almost never feel that my hard drive is full. I can very easily free
up almost any amount of disk space at any time, without any thought. While
writing this blog post, I ran a single command and now my harddrive is
50% empty.&lt;/p&gt;

&lt;blockquote&gt;
The other part of the equation is that a full disk isn’t a problem until
it’s so full you can’t put more stuff on it, and at the point it’s so
irredeemably cluttered that when you do clean it up, you only have the
patience to clean up enough to bide your time, judging the fate of every
file on the harddrive is simply too much work.
&lt;/blockquote&gt;


&lt;p&gt;Why doesn&#39;t this apply to me? Because I have put in the up-front thought
to organize things, so that I never have to do that anymore.&lt;/p&gt;

&lt;p&gt;I have 3 categories of files that I can remove at any time I need more
space, without any thought:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Any files that are stored in git-annex. This is one of git-annex&#39;s
superpowers; you can &lt;code&gt;git-annex drop&lt;/code&gt; any file and stop it using disk
space, but the file is still there (as a broken symlink) so you don&#39;t
risk losing or forgetting about it.&lt;/li&gt;
&lt;li&gt;Caches.&lt;/li&gt;
&lt;li&gt;Files in &lt;code&gt;~/tmp/&lt;/code&gt;, which is reserved for any files I only want to have a
passing acquaintance with. If I&#39;m not comfortable with something being
deleted at any time, I don&#39;t put it there.&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;Not only do I only have these 3 categories, these are the &lt;em&gt;only&lt;/em&gt; 3
categories for everything except OS files and files I have decided I never
want to remove (eg dotfiles and other files stored in git repos).&lt;/p&gt;

&lt;p&gt;Computer scientists invented caches (and of course cache invalidation is no
problem lol) so I only needed to learn about that one. Unix gave me
&lt;code&gt;/tmp/&lt;/code&gt; as an example that I long ago used as the basis for the rules for my
&lt;code&gt;~/tmp/&lt;/code&gt;. I hope that git-annex might also serve as an example
that moving files between drives is not the best way to manage disk space
use.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-29T17:25:04+00:00</dc:date>
	<dc:creator>Joey Hess</dc:creator>
</item> 
<item rdf:about="https://www.eyrie.org/~eagle/reviews/books/9798837010774.html">
	<title>Russ Allbery: Review: Midlife in Gretna Green</title>
	<link>https://www.eyrie.org/~eagle/reviews/books/9798837010774.html</link>
     <content:encoded>&lt;p&gt;Review: &lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt;, by Linzi Day&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;Series:&lt;/td&gt;
    &lt;td&gt;Midlife Recorder #1&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Publisher:&lt;/td&gt;
    &lt;td&gt;Linzi Day&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Copyright:&lt;/td&gt;
    &lt;td&gt;July 2022&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;ISBN:&lt;/td&gt;
    &lt;td&gt;9798837010774&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Format:&lt;/td&gt;
    &lt;td&gt;Kindle&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Pages:&lt;/td&gt;
    &lt;td&gt;464&lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;
&lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt; is a self-published fantasy novel. It&#39;s
urban fantasy in the sense that it&#39;s set in our world but with magic that
most people don&#39;t know about, but the primary setting is a parish in rural
Scotland and therefore the genre is not urban in that sense. It was Linzi
Day&#39;s published first novel.
&lt;/p&gt;

&lt;p&gt;
As the story opens, Niki McKnight is a widow in Manchester, England with a
job in the Register Office she likes, a boss she hates, and a Bichon Frise
dog she adores. In the year since her husband Nick died, she&#39;s put her
life on hold and made as few decisions as possible, despite some concerned
pushing from her best friend Aysha. The death of her grandmother is not
entirely unexpected, but her inheritance is about to upend her life.
&lt;/p&gt;

&lt;p&gt;
Niki assumes that her grandmother has a modest cottage and a small estate,
and therefore being the named heir will mostly involve cleaning up the
details of a modest life. She is caught by surprise by a requirement in
the will that she live in Gretna Green for a year and a day in order to
inherit. Her initial reaction is to treat this as an absurd impossibility
given her life and job in Manchester, but she slowly realizes something
strange is going on. Her grandmother&#39;s lawyer is lying to her, he refuses
to tell her the value of the estate and seems to think it&#39;s more valuable
than she expected, and her grandmother&#39;s tiny cottage does not seem to be
following the seasons of the rest of the world. There is something magical
at work.
&lt;/p&gt;

&lt;p&gt;
I will not spoil the rest of the reveal. I will say that this is a magical
house book because, if you are anything like me, that is why you will want
to read this series. There are not enough magical house books, and this is
one of the better kind that allow the house to be a full speaking
character.
&lt;/p&gt;

&lt;p&gt;
&lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt; is an unapologetic fantasy of personal
agency. Niki starts the novel with a miserable manager, a messy pile of
unread mail she doesn&#39;t want to deal with, and a lot of personal emotional
baggage. She gets handed a position that requires and rewards standing up
for herself and being decisive. It comes with a pile of unresolved but not
horribly complex problems that were waiting for someone who would listen,
make sensible decisions, and treat other people with respect. Oh, and
there are a few assholes in the way, but they seriously underestimate the
power she has to put a stop to their bullshit.
&lt;/p&gt;

&lt;p&gt;
This is the sort of book that traditional publishers tended not to buy
(although Day apparently did get an offer for this one and turned it
down), and I&#39;m not sure why. Editors thought protagonists should have to
work harder for their payoff? Some lingering Calvinist dourness in English
language publishing mistrusted triumphant books? Obvious wish fulfillment
was considered embarrassing or low-class and thus didn&#39;t warrant
publication? This didn&#39;t apply to the endless &lt;i&gt;bildungsromans&lt;/i&gt;
about magically talented boys, so some level of sexism was probably in
play. Maybe this is finally changing? It reminds me of the bias against
romance novels and their guaranteed happily ever after, and in the case of
romance there was too much money for publishers to leave it on the table.
&lt;/p&gt;

&lt;p&gt;
In any case, the growth of self-publishing has created an alternative
market that let these books reach an audience and I for one am here for
it. A lot of wish-fulfillment books, and a lot of self-published books,
are not very good, but the ones that have a spark of originality and
character can be a delight worth tolerating the somewhat rocky editing and
pacing problems that a full editorial staff might have cleaned up.
&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;
    I loved reading books about kickass women who took no crap and fixed
    their lives up exactly how they wanted them to be. But how did they
    get to be that way? They always started out awesome in the books.
    Seriously, did they kick ass at sixteen? Or did their superpower
    kickassery not kick in until they were thirty? Forty? If so, then I
    was screwed. Would I need to wait till I was fifty or until a genie
    arrived offering wishes? I already felt as if I’d spent my whole life
    waiting for something wild and wonderful to happen.
&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
Niki is a Specific Type to a somewhat hilarious degree, and I&#39;m not sure
if Day is playing into that intentionally or if she&#39;s projecting herself
into the book. The amount of self-insertion is not zero: Day also lives in
Gretna Green, owns a Bichon Frise, and worked as an assistant registrar
and civil celebrant. Niki also drinks wine regularly, has a psychic gift,
occasionally reads tarot cards, is an accommodating pushover at work who
struggles to say no to her abusive boss, has impostor syndrome problems,
and swears by a fictional self-help book about grief that provides the
quotes at the starts of chapters. There is a cat, because of course
there&#39;s a cat.
&lt;/p&gt;

&lt;p&gt;
(The fictional self-help book is a spot-on parody played entirely straight
in the story. I think Day is having some fun with the reader? I can&#39;t
tell!)
&lt;/p&gt;

&lt;p&gt;
This is what I mean by unapologetic. It&#39;s easy to read Niki as a
stereotype, but she&#39;s a stereotype a lot of real people can identify with
and there&#39;s something highly satisfying in watching her find her footing.
I &lt;em&gt;like&lt;/em&gt; wish fulfillment books; it&#39;s fun to see someone&#39;s wishes
come true! Particularly in the year of 2026, there&#39;s something immensely
satisfying in seeing an ordinary, insecure person get a massive amount of
power and use it to make the world better. I don&#39;t need everything to be
hard, fraught, and laden with costs in fiction, although I wouldn&#39;t want
every book I read to be like this.
&lt;/p&gt;

&lt;p&gt;
Also, the world building is great. It&#39;s not polished; there&#39;s a bit of a
grab bag feeling to it, I&#39;m dubious the magic system has any underlying
rigorous rule set, and Niki&#39;s powers, once she has access to them, are
more of a semi-sentient genie than a skill she has to learn with hard
practice. But the magic is &lt;em&gt;fun&lt;/em&gt;. The sentient house is one of the
best characters, particularly after Niki realizes how underused it has
been, and I am a sucker for any good sentient house book. The cat is a far
more interesting character than I first thought she would be. And Niki&#39;s
new magical job is more complicated and less typical than the normal
Celtic-inspired fantasy that I thought it was going to be at first.
&lt;/p&gt;

&lt;p&gt;
My primary warning about this book is that Niki starts out beaten down and
grieving her dead husband, and it took me about five pages to decide that
her dead husband was a complete piece of shit who was not worth any of the
grief Niki puts into him. She also doesn&#39;t stand up for herself for the
first hundred pages or so, which made me want to yell at the book a few
times. Both of these problems go away farther into the book, and Niki does
eventually figure out that Nick was abusive trash, but I was relieved when
the &quot;make endless excuses for worthless men&quot; portion of the story was
finally over. You have to stick with it until Niki gets brave enough to
try being the protagonist; once that happens, it becomes great fun.
&lt;/p&gt;

&lt;p&gt;
It is fairly obvious that &lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt; was
self-published, and I wish it had gotten the editing that it deserved. My
copy had a couple of obvious formatting errors, the plot veers about more
than was strictly necessary, and I think a careful editing pass could have
tightened the writing by about fifty pages or so without losing any
important detail. If that sort of thing bothers you, make sure you&#39;re in
self-published fiction mode before starting this one. But it also has that
irrepressible, bubbling-with-ideas feeling of a book where nothing has
suppressed the author&#39;s enthusiasm. It&#39;s a very grabby book; once Niki
starts embracing her new life, I could barely put it down.
&lt;/p&gt;

&lt;p&gt;
If you&#39;re in the mood for a good fantasy wish-fulfillment story that has
no romance and a whole lot of &quot;why are things run this way, no, we&#39;re
changing that,&quot; highly recommended. I had so much fun with this book, and
the series is currently making the rounds of my whole family. Don&#39;t read
this when you&#39;re looking for something challenging and literary and deep;
save it for when you desperately want to watch someone just fix something
for once, damn it.
&lt;/p&gt;

&lt;p&gt;
Followed by &lt;cite&gt;Painting the Blues in Gretna Green&lt;/cite&gt;, which I have
already read, breaking my usual rule of writing reviews before reading the
next book in a series.
&lt;/p&gt;

&lt;p&gt;Rating: 8 out of 10&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-29T02:19:00+00:00</dc:date>
	<dc:creator>Russ Allbery</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/07/28#rcppdate_0.0.7">
	<title>Dirk Eddelbuettel: RcppDate 0.0.7: New Upstream</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/07/28#rcppdate_0.0.7</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://github.com/eddelbuettel/rcppdate&quot;&gt;RcppDate&lt;/a&gt; ships
the featureful &lt;a href=&quot;https://github.com/HowardHinnant/date&quot;&gt;date&lt;/a&gt;
library written by &lt;a href=&quot;https://github.com/HowardHinnant&quot;&gt;Howard
Hinnant&lt;/a&gt; to enable use from R packages. This header-only modern C++
library has been in pretty wide-spread use for a while now, and adds to
C++11, C++14 and C++17 what is (with minor modifications) the ‘date’
library in C++20. The &lt;a href=&quot;https://github.com/eddelbuettel/rcppdate&quot;&gt;RcppDate&lt;/a&gt; package
adds no extra R or C++ code and can therefore be a zero-cost dependency
for any other project; yet a number of other projects decided to
re-vendor it resulting in less-efficient duplication. Oh well. &lt;em&gt;C’est
la vie.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This release syncs with upstream release 3.0.5 made yesterday. We
also made two routine updates to the continuous integration since the
last release a good year ago. The &lt;a href=&quot;https://www.debian.org&quot;&gt;Debian&lt;/a&gt; and &lt;a href=&quot;https://eddelbuettel.github.io/r2u/&quot;&gt;r2u&lt;/a&gt; packages for this new
release have already been uploaded too.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-version-0.0.7-2026-07-27&quot;&gt;Changes in version 0.0.7
(2026-07-27)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Updated to upstream version 3.0.5&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Regular updates to continuous integration setup&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/&quot;&gt;CRANberries&lt;/a&gt;, there
is also a diffstat report for the &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/2026/07/28#RcppDate_0.0.7&quot;&gt;most
recent release&lt;/a&gt;. More information is available at the &lt;a href=&quot;https://github.com/eddelbuettel/rcppdate&quot;&gt;repository&lt;/a&gt; or the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rcpp.date.html&quot;&gt;package
page&lt;/a&gt;.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-28T13:32:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/07/27#057_conditionally_quieten_compilers">
	<title>Dirk Eddelbuettel: #057: Conditionally Quieten Compilers</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/07/27#057_conditionally_quieten_compilers</link>
     <content:encoded>&lt;p&gt;Welcome to post 57 in the &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/code/r4&quot;&gt;&lt;span class=&quot;math inline&quot;&gt;&lt;em&gt;R&lt;/em&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/span&gt;&lt;/a&gt; series.&lt;/p&gt;
&lt;p&gt;R packages with compiled codes can use the file
&lt;code&gt;src/Makevars&lt;/code&gt; to set compilation flags. We often rely on
this to set libraries, include directories or compilation options. When
using external libraries, be it header-only or via headers and linking,
we are often experiencing ‘compilation noise’ when these libraries
tickle warnings under generally-recommended flags such as
&lt;code&gt;-Wall -pedantic&lt;/code&gt;. Two packages I maintain are clearly repeat
offenders here: Eigen, and BH. Both cam generate pages and pages of
compiler output. This is generally not great as it may hide genuine
warnings from our own code.&lt;/p&gt;
&lt;p&gt;What makes matters worse is that some of the available and specific
options for the compilers are treated by &lt;code&gt;R CMD check&lt;/code&gt; as
‘non-portable’ leading to a nag on package checking. Examples are
&lt;code&gt;-Wno-parentheses&lt;/code&gt;, &lt;code&gt;-Wno-maybe-uninitialize&lt;/code&gt; or
&lt;code&gt;-Wno-nunnull&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;I have long resorted to adding these to my per-user
&lt;code&gt;~/.R/Makevars&lt;/code&gt;. When added there, compilation is quieter,
but &lt;code&gt;R CMD check&lt;/code&gt; still nags &lt;em&gt;here&lt;/em&gt; where the option
is set but not at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; or
r-universe. A situation that is not ideal but what somewhat
‘stable’.&lt;/p&gt;
&lt;p&gt;More recently, I realized there was an available check we can use to
&lt;em&gt;conditionally&lt;/em&gt; add extra compilation flags but leave them off by
default. That makes local development quiet allowing us to focus on the
quality of our additions here without noise from third-party libraries
we may use. At the same time we do not need to do anything else to let
&lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; do its work.&lt;/p&gt;
&lt;p&gt;The check we now use is whether there is a &lt;code&gt;.git/&lt;/code&gt;
directory present. If so, we are indeed building from local sources and
can add extra flags. If not, we are likely building from a tar.gz source
archive—which is the case for CRAN—and hence do not set these.&lt;/p&gt;
&lt;p&gt;An example use is this recent additional to package &lt;a href=&quot;https://github.com/qlcal/qlcal-r&quot;&gt;qlcal&lt;/a&gt; where this bit of R
code is invoked from a minimal shell script &lt;code&gt;configure&lt;/code&gt; and
replaces the stub &lt;code&gt;@XTRAFLAGS@&lt;/code&gt; in
&lt;code&gt;src/Makevars.in&lt;/code&gt; (or &lt;code&gt;src/Makevars.win.in&lt;/code&gt;)&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb1&quot;&gt;&lt;pre class=&quot;sourceCode r&quot;&gt;&lt;code class=&quot;sourceCode r&quot;&gt;&lt;span id=&quot;cb1-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;cf&quot;&gt;if&lt;/span&gt; (&lt;span class=&quot;fu&quot;&gt;dir.exists&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;.git&quot;&lt;/span&gt;)) {&lt;/span&gt;
&lt;span id=&quot;cb1-2&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-2&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;do&quot;&gt;## development from a .git directory can use these flags&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-3&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-3&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    xtraflags &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;-Wno-nonnull -Wno-deprecated-declarations&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-4&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-4&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;} &lt;span class=&quot;cf&quot;&gt;else&lt;/span&gt; {&lt;/span&gt;
&lt;span id=&quot;cb1-5&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-5&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;do&quot;&gt;## else build from tarball so stick with existing flags&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-6&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-6&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    xtraflags &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-7&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-7&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;}&lt;/span&gt;
&lt;span id=&quot;cb1-8&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-8&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;win &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;cf&quot;&gt;if&lt;/span&gt; (&lt;span class=&quot;fu&quot;&gt;Sys.info&lt;/span&gt;()[[&lt;span class=&quot;st&quot;&gt;&quot;sysname&quot;&lt;/span&gt;]] &lt;span class=&quot;sc&quot;&gt;==&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;Windows&quot;&lt;/span&gt;) &lt;span class=&quot;st&quot;&gt;&quot;.win&quot;&lt;/span&gt; &lt;span class=&quot;cf&quot;&gt;else&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb1-9&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-9&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;infile &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;file.path&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;src&quot;&lt;/span&gt;, &lt;span class=&quot;fu&quot;&gt;paste0&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;Makevars&quot;&lt;/span&gt;, win, &lt;span class=&quot;st&quot;&gt;&quot;.in&quot;&lt;/span&gt;))&lt;/span&gt;
&lt;span id=&quot;cb1-10&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-10&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;outfile &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;file.path&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;src&quot;&lt;/span&gt;, &lt;span class=&quot;fu&quot;&gt;paste0&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;Makevars&quot;&lt;/span&gt;, win))&lt;/span&gt;
&lt;span id=&quot;cb1-11&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-11&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;lines &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;readLines&lt;/span&gt;(infile)&lt;/span&gt;
&lt;span id=&quot;cb1-12&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-12&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;lines &lt;span class=&quot;ot&quot;&gt;&amp;lt;-&lt;/span&gt; &lt;span class=&quot;fu&quot;&gt;gsub&lt;/span&gt;(&lt;span class=&quot;st&quot;&gt;&quot;@XTRAFLAGS@&quot;&lt;/span&gt;, xtraflags, lines)&lt;/span&gt;
&lt;span id=&quot;cb1-13&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb1-13&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;fu&quot;&gt;writeLines&lt;/span&gt;(lines, outfile)&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;With this change, local compilation is quiet, yet &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; has nothing to nag about (as
seen at the &lt;a href=&quot;https://cran.r-project.org/web/checks/check_results_qlcal.html&quot;&gt;qlcal
results page&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Similarly, one can also check from an actual &lt;code&gt;configure&lt;/code&gt;
file written in autoconf. Here is a similar example from RcppEigen
(showing some relevants parts of the whole file)&lt;/p&gt;
&lt;div class=&quot;sourceCode&quot; id=&quot;cb2&quot;&gt;&lt;pre class=&quot;sourceCode sh&quot;&gt;&lt;code class=&quot;sourceCode bash&quot;&gt;&lt;span id=&quot;cb2-1&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-1&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;co&quot;&gt;# PKG_CXXFLAGS initialized earlier ...&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-2&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-2&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-3&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-3&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;co&quot;&gt;## Check if building locally&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-4&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-4&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;AC_MSG_CHECKING&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[whether&lt;/span&gt; .git/ exists]&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-5&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-5&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;cf&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;bu&quot;&gt;test&lt;/span&gt; &lt;span class=&quot;at&quot;&gt;-d&lt;/span&gt; &lt;span class=&quot;st&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;va&quot;&gt;$srcdir&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;/.git&quot;&lt;/span&gt;&lt;span class=&quot;kw&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;cf&quot;&gt;then&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-6&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-6&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;ex&quot;&gt;AC_MSG_RESULT&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[yes,&lt;/span&gt; adding extra flags]&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-7&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-7&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;ex&quot;&gt;AC_SUBST&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[PKG_CXXFLAGS],[&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;va&quot;&gt;${PKG_CXXFLAGS}&lt;/span&gt;&lt;span class=&quot;st&quot;&gt; -Wno-ignored-attributes -Wno-maybe-uninitialized&quot;&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-8&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-8&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;cf&quot;&gt;else&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-9&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-9&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;    &lt;span class=&quot;ex&quot;&gt;AC_MSG_RESULT&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[no,&lt;/span&gt; consider adding &lt;span class=&quot;st&quot;&gt;&#39;-Wno-ignored-attributes -Wno-maybe-uninitialized&#39;&lt;/span&gt; to ~/.R/Makevars]&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-10&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-10&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;cf&quot;&gt;fi&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-11&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-11&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-12&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-12&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;AC_SUBST&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[PKG_CXXFLAGS],&lt;/span&gt; &lt;span class=&quot;pp&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;va&quot;&gt;${PKG_CXXFLAGS}&lt;/span&gt;&lt;span class=&quot;st&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;pp&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-13&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-13&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;AC_CONFIG_FILES&lt;/span&gt;&lt;span class=&quot;er&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ex&quot;&gt;[src/Makevars]&lt;/span&gt;&lt;span class=&quot;kw&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span id=&quot;cb2-14&quot;&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/blog/index.rss#cb2-14&quot; tabindex=&quot;-1&quot;&gt;&lt;/a&gt;&lt;span class=&quot;ex&quot;&gt;AC_OUTPUT&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Once again, with this change compilation is quiet locally, yet
unaffected at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;. Just what
we want. Give it a try in your packages.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can now &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-27T22:40:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="https://jonathancarter.org/?p=12034">
	<title>Jonathan Carter: DebConf26 – Santa Fe, Argentina</title>
	<link>https://jonathancarter.org/2026/07/27/debconf26-santa-fe-argentina/</link>
     <content:encoded>&lt;p class=&quot;wp-block-paragraph&quot;&gt;TL;DR: What a great DebConf! I managed to recharge my Debian batteries, and my talks / BoF sessions all went fine. Already looking forward to DebConf in Japan next year!&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;DebCamp&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The evening before DebCamp started, we had a nice bbq (we taught some locals to call it a “braai” at an organiser’s house and went for a walk around the river as the sun set. It was a very peaceful lead-in to DebCamp.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12057&quot; height=&quot;450&quot; src=&quot;https://jonathancarter.org/files/images/bbq.jpg&quot; width=&quot;800&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12042&quot; height=&quot;452&quot; src=&quot;https://jonathancarter.org/files/images/dc26_blog_river.jpg&quot; width=&quot;800&quot; /&gt;&lt;/figure&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;I set up and sent out the call for Forky desktop artwork:
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/msgid-search/910906f3-7ce4-4884-a49f-4b4a5975471b@debian.org&quot;&gt;https://lists.debian.org/msgid-search/910906f3-7ce4-4884-a49f-4b4a5975471b@debian.org&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;Had many nice discussions about various Debian topics with all the Debian people around. It’s really fun being around people who are natural problem solvers who care deeply about both technical and social issues. At one point Jonas told me “Holy shit, these people are motivated!” and I appreciate that so much too!&lt;/li&gt;
&lt;/ul&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12064&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/ltswine-1024x576.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Debian LTS wine&lt;/em&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Most of my DebCamp was dedicated to preparing for my demo and main talk that followed at DebConf.&lt;/li&gt;



&lt;li&gt;Sadly, we had no loopy this year, I just didn’t have the time, and the people who stepped up to help last year were either overwhelmed with other issues or couldn’t make it. I’ll try to make it happen again for next year by kicking it off long before DC27.&lt;/li&gt;
&lt;/ul&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12059&quot; height=&quot;640&quot; src=&quot;https://jonathancarter.org/files/images/santafe-1024x640.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;View of Santa Fe city from hotel&lt;/em&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;DebConf&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Talk – Is it even possible to build a truly universal system installer?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In &lt;a href=&quot;https://debconf26.debconf.org/talks/6-is-it-even-possible-to-build-a-truly-universal-system-installer/&quot;&gt;this talk&lt;/a&gt; I do a very quick comparison of system installers based on my experience with them. It’s hard to directly compare all of them, since there are so many, and each have their own niche that they attempt to satisfy.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I also introduce &lt;a href=&quot;https://salsa.debian.org/yasi-team/yasi-daemon&quot;&gt;Yasi&lt;/a&gt; – my attempt to answer the question of whether we could build a universal installer, which can also better cover advanced installations, automated installations and niche setups.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s very early days for the project, and I didn’t quite feel ready to share the code with the world, but it was nice that I did a quick demo where I could install a Debian system… and the resulting system actually booted up. *phew*.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is also going to be my main focus for the mid-term future. I aim to have all the basic partitioning options working by the time Debian 14 (Forky) is released, and by the time Debian 15 is released, I have a long list of features that I aim to have working. So, my timeline for having something that’s generally useful is around a year from now, and in around 3 years it should be a fully fledged installer that should cover a very large amount of Debian use cases and architectures. &lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12048&quot; height=&quot;646&quot; src=&quot;https://jonathancarter.org/files/images/image-30-1024x646.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Day Trip&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For the day trip, we did a tour across Santa Fe, visited &lt;a href=&quot;https://www.museodelaconstitucion.org/&quot;&gt;Constitución de la Nación Argentina&lt;/a&gt;, had lunch where we tried various dishes based on local fish from the river, and then went on a boat ride on the river.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12078&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/churchbells.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12090&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/image-32-1024x574.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12092&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/image-33-1024x574.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;BoF Sessions:&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Funding in Free Software Projects:&lt;/strong&gt; I initially registered this BoF because I’m increasingly concerned about how upstreams are asking for donations in their software. I increased the scope to talk about funding in free software in general. It followed Marga’s talk about funding, which focussed more about how developers are funded in general. We didn’t dive very deep into this, but we certainly need some further discussion (and action) on this within Debian.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Debian Social Team:&lt;/strong&gt; My most important issue for this team is a carry-over from last year, I want to set up &lt;a href=&quot;https://pgbarman.org/&quot;&gt;barman&lt;/a&gt; (packaged in Debian) for live postgres syncing for our larger databases. For the smaller DBs, doing a daily dump is quite cheap. But for Matrix, it’s very expensive in terms if i/o and CPU, so it would be ideal to do less regular complete dumps and use live replication for the first line of redundancy instead.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Images Team: &lt;/strong&gt;I wasn’t initially planning to say much during this session, I have some ideas to reduce both size and count of images, without losing any benefits, but I don’t have any work to show for that yet. I ended up talking a lot more than I anticipated, the topics covered were quite good and representative of the current state of Debian images built. I don’t have time to create a full summary, so I suggest checking the etherpad / video recording if you’re interested.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12079&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/cwstablewine.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Some more wine variety during the conference dinner&lt;/em&gt;&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12066&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/busyhacklap-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Debianites in the main hacklab&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Rosario&lt;/h3&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12076&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/rosario-1-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I’m spending two days in Rosario before I head home. Exploring a bit, catching up with sleep, finishing this blog post, signing keys and exploring some ideas I made note of during DebConf.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Thank you to the DebConf26 Team!&lt;/h3&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12073&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/dc-team-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It was a little surreal not being part of any DebConf team for the first time ever, I’ve just been too focussed on getting Yasi ready for my talk (no regrets!). I hope to be more involved again next year, in the meantime, I’m very grateful to everyone who has made this happen, you did a stellar job! I hope to see many of you again next year in Japan!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-27T20:12:18+00:00</dc:date>
	<dc:creator>jonathan</dc:creator>
</item> 
<item rdf:about="https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/index.html">
	<title>Valhalla&#39;s Things: Late Victorian Vampire Shirt</title>
	<link>https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/index.html</link>
     <content:encoded>&lt;article&gt;
    &lt;section class=&quot;header&quot;&gt;
        Posted on July 27, 2026
        &lt;br /&gt;
        
        Tags: &lt;a href=&quot;https://blog.trueelena.org/tags/madeof%3Aatoms.html&quot; title=&quot;All pages tagged &#39;madeof:atoms&#39;.&quot;&gt;madeof:atoms&lt;/a&gt;, &lt;a href=&quot;https://blog.trueelena.org/tags/craft%3Asewing.html&quot; title=&quot;All pages tagged &#39;craft:sewing&#39;.&quot;&gt;craft:sewing&lt;/a&gt;, &lt;a href=&quot;https://blog.trueelena.org/tags/FreeSoftWear.html&quot; title=&quot;All pages tagged &#39;FreeSoftWear&#39;.&quot;&gt;FreeSoftWear&lt;/a&gt;
        
    &lt;/section&gt;
    &lt;section&gt;
        &lt;p&gt;&lt;img alt=&quot;A woman wearing an old-style white shirt with lots of fullness, wide and long sleeves and ruffles at the collar that spread out framing the neck, down the center front to underbust height, covering the slit and at the cuffs, reaching to mid-hand. The shirt is gathered at the waist with a belt, and worn over the bottom garment to show that it reaches to mid tight. Drama levels in the pose are pretty low.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/vampire_shirt.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The recurring joke is that because of some health issues, in summer I
dress like a Victorian Vampire.&lt;/p&gt;
&lt;p&gt;But how would an actual Late Victorian Vampire dress? Picture her, she
would look like some kind of eccentric gentlewoman, as vampires usually
do, probably with a style that is a bit conservative, rather than
following the latest fashions.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Same woman, same shirt, posing as a vampire ready to attack a victim. Drama levels increasing.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/vampire_attack.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Now, she wouldn’t probably wear men’s shirts. But what if she was a
lesbian&lt;a class=&quot;footnote-ref&quot; href=&quot;https://blog.trueelena.org#fn1&quot; id=&quot;fnref1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; vampire? Wouldn’t she need a fancy, frilly shirt to
go with her tailored cycling suit when she’s out seducing the more
active ladies in the neighbourhood?&lt;/p&gt;
&lt;p&gt;Or maybe not. It’s not making a lot of sense, is it? But &lt;em&gt;I&lt;/em&gt; do have a
lot of shirt fabric in my stash&lt;a class=&quot;footnote-ref&quot; href=&quot;https://blog.trueelena.org#fn2&quot; id=&quot;fnref2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt;, and I could use a few more
shirts that were practical and comfortable, but also somewhat over the
top.&lt;/p&gt;
&lt;p&gt;For the practical and comfortable I went to my trusted &lt;a href=&quot;https://sewing-patterns.trueelena.org/historical_menswear/shirts/1880s_shirt/index.html&quot;&gt;1880s shirt&lt;/a&gt;,
while for the over the top part I looked at inspiration from the earlier
18th century frilly shirts, and their later imitations.&lt;/p&gt;
&lt;p&gt;I decided to use some nice cotton batiste I had bought quite a few years
ago to make one of my first historically inspired shirtwaists: I may
have a tendency to buy a bit more fabric than actually needed by the
pattern, but that’s what everybody does, right?&lt;/p&gt;
&lt;p&gt;For the ruffles I decided to use a lighter weight cotton voile, also
from the stash.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;the top edge of a ruffle being whipstitched over some gathered fabric; the rest of the unfinished shirt is visible in the background.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/attaching_fronts.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;At the front, I wanted the ruffle to be inserted in the yoke, but I was
also whipstitching the gathers to it to make them neater, so I started
bu attaching the yoke lining to the gathered front, then I whipstitched
the ruffle to the front, catching each gather, and finally I
whipstitched the other yoke on the ruffle and the rest of the gathered
front.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;The front of a shirt: the body was gathered into a yoke, but it has been unpicked and pulled out to extend a bit past the end of it, into where the collar will be sewn.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/unpicking_unpicking.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;And then after sewing the collar, I realized that this way the slit
would have remained open in the front (or the collar too narrow), so I
had to unpick the front part of the yoke, and sew it again, this time
leaving an excess of fabric as wide as half the placket width from the
pattern, to be sewn directly in the collar band.&lt;/p&gt;
&lt;p&gt;From then, things progressed smoothly, with some interruptions, until I
got to the first sleeve, which I failed to insert twice, as one does.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;The same shirt worn without the ruffle at the collar, with just what looks like a mandarin collar, closed with a clip with an amethyst. Drama levels have gone way down.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/without_collar.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;On the third attempt, with a different method, I succeeded, I tried the
shirt on, and it already felt &lt;em&gt;extra&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Close up of the collar on a table: at the center back of the shirt collar there is a buttonhole, and a double button is used to keep the detached collar in place, while at the front both the shirt collar and the detached collar have buttonholes.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/detachable_collar.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;But it could be even &lt;em&gt;more&lt;/em&gt; extra. With some ruffles also at the collar.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Same close up, but now the collar has been closed with a clip-on earring with an amethyst and some small fake clear stones, and it looks as if the skirt had a ruffle collar and a jewel button (or a pin).&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/collar_closed.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The shirt had been made with a simple collar band, and I could have just
added the ruffle to it, but I also wanted to be able to wear it with
other detachable collars, so I decided to make another collar band with
ruffles, to wear on top.&lt;/p&gt;
&lt;p&gt;And that was mostly it, except for the reinforcement patches at the
side seams and cuffs: I love having them, because they make the seam
end neater and stronger, but they are a bit of a hassle to make, so they
got postponed a few days.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Same woman and shirt, back with the ruffled collar, in a pose like that of an artist that is fainting for futile reasons. Drama levels over the top.&quot; class=&quot;align-center&quot; src=&quot;https://blog.trueelena.org/blog/2026/07/27-late_victorian_vampire_shirt/overdramatic.jpg&quot; style=&quot;width: 80.0%;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;But finally, the shirt was done.&lt;/p&gt;
&lt;p&gt;And I tried it on, and it was good.&lt;/p&gt;
&lt;p&gt;But now I really need a pair of cycling breeches, don’t I?&lt;/p&gt;
&lt;section class=&quot;footnotes footnotes-end-of-document&quot;&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id=&quot;fn1&quot;&gt;&lt;p&gt;ok, maybe straight passing bi? anyway.&lt;a class=&quot;footnote-back&quot; href=&quot;https://blog.trueelena.org#fnref1&quot;&gt;↩︎&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li id=&quot;fn2&quot;&gt;&lt;p&gt;I have &lt;em&gt;no idea&lt;/em&gt; how they got there.&lt;a class=&quot;footnote-back&quot; href=&quot;https://blog.trueelena.org#fnref2&quot;&gt;↩︎&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/section&gt;
    &lt;/section&gt;
&lt;/article&gt;</content:encoded> 
	<dc:date>2026-07-27T00:00:00+00:00</dc:date>
	<dc:creator>Elena “of Valhalla”</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/07/25#rcpparmadillo_15.4.2-1">
	<title>Dirk Eddelbuettel: RcppArmadillo 15.4.2-1 on CRAN: Small Upstream Fixes</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/07/25#rcpparmadillo_15.4.2-1</link>
     <content:encoded>&lt;p&gt;&lt;img alt=&quot;armadillo image&quot; src=&quot;https://dirk.eddelbuettel.com/images/armadillo_logo_two.png&quot; style=&quot;float: left; margin: 10px 10px 10px 0;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://arma.sourceforge.net/&quot;&gt;Armadillo&lt;/a&gt; is a powerful
and expressive C++ template library for linear algebra and scientific
computing. It aims towards a good balance between speed and ease of use,
has a syntax deliberately close to Matlab, and is useful for algorithm
development directly in C++, or quick conversion of research code into
production environments. &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rcpp.armadillo.html&quot;&gt;RcppArmadillo&lt;/a&gt;
integrates this library with the &lt;a href=&quot;https://www.r-project.org&quot;&gt;R&lt;/a&gt; environment and language–and is
widely used by (currently) 1293 other packages on &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt;, downloaded 47.8 million
times (per the partial logs from the cloud mirrors of CRAN), and the &lt;a href=&quot;https://doi.org/10.1016/j.csda.2013.02.005&quot;&gt;CSDA paper&lt;/a&gt; (&lt;a href=&quot;https://cran.r-project.org/package=RcppArmadillo/vignettes/RcppArmadillo-intro.pdf&quot;&gt;preprint
/ vignette&lt;/a&gt;) by Conrad and myself has been cited 710 times according
to Google Scholar.&lt;/p&gt;
&lt;p&gt;This versions updates to the 15.4.2 upstream &lt;a href=&quot;https://arma.sourceforge.net/&quot;&gt;Armadillo&lt;/a&gt; release made this
week, as well as to included 15.4.1 version we released only to GitHub
and r-universe so do not exceed the (roughly) monthly cadence. For this
release, we had run the usual complete reverse-dependency check which
came back spotless, and did CRAN so no email exchange needed despite
nearly 1300 reverse dependencies. Automation can be helpful when used
with a well-maintained software stack. The package has also already been
updated for &lt;a href=&quot;https://www.debian.org&quot;&gt;Debian&lt;/a&gt;, built for &lt;a href=&quot;https://eddelbuettel.github.io/r2u/&quot;&gt;r2u&lt;/a&gt;, and will build
shortly at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; for the
different binary releases.&lt;/p&gt;
&lt;p&gt;All changes since the last CRAN release follow.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-rcpparmadillo-version-15.4.2-1-2026-07-25&quot;&gt;Changes in
RcppArmadillo version 15.4.2-1 (2026-07-25)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Upgraded to Armadillo release 15.4.2 (Medium Roast Agave)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fix speed regressions in &lt;code&gt;diagvec()&lt;/code&gt; and
&lt;code&gt;diagmat()&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;changes-in-rcpparmadillo-version-15.4.1-1-github-only-2026-07-09&quot;&gt;Changes
in RcppArmadillo version 15.4.1-1 [github-only] (2026-07-09)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Upgraded to Armadillo release 15.4.1 (Medium Roast Agave)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Fix for rare infinite recursion bug in sparse version of
&lt;code&gt;diagmat()&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;More efficient checks for aliasing&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/&quot;&gt;CRANberries&lt;/a&gt;, there
is a &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/2026/07/25#RcppArmadillo_15.4.2-1&quot;&gt;diffstat
report&lt;/a&gt; relative to previous release. More detailed information is on
the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/rcpp.armadillo.html&quot;&gt;RcppArmadillo
page&lt;/a&gt;. Questions, comments etc should go to the &lt;a href=&quot;https://lists.r-forge.r-project.org/cgi-bin/mailman/listinfo/rcpp-devel&quot;&gt;rcpp-devel
mailing list&lt;/a&gt; off the &lt;a href=&quot;https://r-forge.r-project.org/projects/rcpp/&quot;&gt;Rcpp R-Forge&lt;/a&gt;
page.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-25T20:56:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="http://00formicapunk00.wordpress.com/?p=344">
	<title>Emmanuel Kasper: Opensource gaming with nouveau nvidia driver</title>
	<link>https://00formicapunk00.wordpress.com/2026/07/24/opensource-gaming-with-nouveau-nvidia-driver/</link>
     <content:encoded>&lt;p class=&quot;wp-block-paragraph&quot;&gt;So it will not play cyberpunk 2077, but if you prefer opensource drivers for your hardware, nouveau is certainly an option for some opensource gaming.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Using kernel 7.0 from debian backports, I could run opensource classics requiring 3D acceleration  flawlessly with nouveau:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Supertux (&lt;a href=&quot;https://screenshots.debian.net/package/supertux&quot;&gt;Debian package&lt;/a&gt;)&lt;/li&gt;



&lt;li&gt;SuperTux Kart (&lt;a href=&quot;https://screenshots.debian.net/package/supertuxkart&quot;&gt;Debian package&lt;/a&gt;)&lt;/li&gt;



&lt;li&gt;LibreQuake (&lt;a href=&quot;https://flathub.org/en/apps/io.github.lavenderdotpet.LibreQuake&quot;&gt;Flatpak&lt;/a&gt; with ironquake engine, Full HD and 60 fps)&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I would like to highlight here how good is LibreQuake.&lt;br /&gt;It is an horror cosmic 3D shooter, using the Quake engine, but with newly made game assets under the GPL, thus creating a 100% opensource Quake-based first person shooter.  Although their documentation mentions it is a work in progress, as of 2026 I find it very much of a finished product.&lt;br /&gt;&lt;br /&gt;&lt;img alt=&quot;LibreQuake Screenshot&quot; class=&quot;wp-image-347&quot; height=&quot;1067&quot; src=&quot;https://00formicapunk00.wordpress.com/wp-content/uploads/2026/07/librequake-dismalshores.png&quot; style=&quot;width: 1024px;&quot; width=&quot;1911&quot; /&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;em&gt;Dismal shores, my preferred game level.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;I missed Quake in the 90s, happy to discover such a classic today.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-24T15:31:24+00:00</dc:date>
	<dc:creator>Manu</dc:creator>
</item> 
<item rdf:about="https://etbe.coker.com.au/?p=6244">
	<title>Russell Coker: Systemd Linger</title>
	<link>https://etbe.coker.com.au/2026/07/24/systemd-linger/</link>
     <content:encoded>&lt;h2&gt;Killing Processes&lt;/h2&gt;
&lt;p&gt;One of the features of systemd that is most controversial is the option to kill user processes when the user logs out. That initially killed screen/tmux/nohup processes too. In recent Debian releases the default configuration of systemd-logind (the login manager for systemd) is to allow processes to keep running, the configuration file &lt;b&gt;/etc/systemd/logind.conf&lt;/b&gt; has an option &lt;b&gt;KillUserProcesses&lt;/b&gt; that can be enabled to have user processes killed. If you do that then there are options to only kill processes for certain users and to exclude some users (default to excluding root). If using that option you can apparently use a systemd unit to start screen which prevents it being killed on logout.&lt;/p&gt;
&lt;p&gt;This is a very handy feature for some particular user cases. One situation was that I was supporting some people who weren’t very good at computers on a system running KDE and some KDE processes would linger. So the option of logout and login again to deal with an issue of akonadi or some other KDE service misbehaving didn’t work. On that system I enabled the option to kill user processes which reduced the number of problems they had while not requiring rebooting.&lt;/p&gt;
&lt;p&gt;It is widely believed that the “linger” feature is required to allow screen/tmux/nohup to work, in Debian (and probably most distributions) that is not the case. It might be that some combinations of configuration requires “linger” to allow screen/tmux to work but I am not interested in trying to discover them. Of all the people I have directly supported for Linux desktop use (which numbers in the hundreds) none of them have had the ability to use screen/tmux and also the cluelessnes that makes me want to automatically kill their processes when the logout.&lt;/p&gt;
&lt;h2&gt;Controlling Linger&lt;/h2&gt;
&lt;p&gt;You can enable and disable “linger” for your own account with the following commands if polkit is installed and in a typical configuration:&lt;/p&gt;
&lt;pre&gt;loginctl enable-linger
loginctl disable-linger&lt;/pre&gt;
&lt;p&gt;If running as root you can enable and disable it for another user with the following commands:&lt;/p&gt;
&lt;pre&gt;loginctl enable-linger $ACCOUNT
loginctl disable-linger $ACCOUNT&lt;/pre&gt;
&lt;p&gt;There doesn’t seem to be any documented way of discovering if an account has linger enabled or for listing accounts that have it, it seems that “&lt;b&gt;ls /var/lib/systemd/linger&lt;/b&gt;” is the only option.&lt;/p&gt;
&lt;h2&gt;Linger on Debian&lt;/h2&gt;
&lt;p&gt;On a Debian system with close to default settings the processes won’t be killed on logout and the only difference “linger” makes is to start programs in the user’s context BEFORE they login. A friend was recently testing out a bunch of LLM programs on one of my servers and the account he used for that ended up with “linger” enabled, presumably one of the install scripts he ran was written on the assumption that enabling linger was necessary for nohup to work and it did so automatically without being asked.&lt;/p&gt;
&lt;p&gt;One benefit I’ve found from this behaviour is on my laptop. I’m currently testing out new SE Linux policy on my laptop and rebooting it a lot. When I enabled linger on my account it caused the laptop to connect to wifi on boot without needing to login which is convenient. I can then ssh to it even when the X11/Wayland login configuration is broken.&lt;/p&gt;
&lt;p&gt;I will leave it enabled after finishing these tests. Having background processes like Pipewire and Bluetooth start before I login will presumably make things slightly faster when I do login.&lt;/p&gt;
&lt;div class=&quot;yarpp yarpp-related yarpp-related-rss yarpp-template-list&quot;&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2015/01/13/systemd-notes/&quot; rel=&quot;bookmark&quot; title=&quot;Systemd Notes&quot;&gt;Systemd Notes&lt;/a&gt; &lt;small&gt;A few months ago I gave a lecture about systemd...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2016/02/25/ethernet-naming-systemd/&quot; rel=&quot;bookmark&quot; title=&quot;Ethernet Interface Naming With Systemd&quot;&gt;Ethernet Interface Naming With Systemd&lt;/a&gt; &lt;small&gt;Systemd has a new way of specifying names for Ethernet...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://etbe.coker.com.au/2026/05/09/systemd-mobile-linux-containers/&quot; rel=&quot;bookmark&quot; title=&quot;Systemd, Mobile Linux, and Containers&quot;&gt;Systemd, Mobile Linux, and Containers&lt;/a&gt; &lt;small&gt;I’ve had some problems running apps I want on my...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-24T07:48:23+00:00</dc:date>
	<dc:creator>etbe</dc:creator>
</item> 
<item rdf:about="https://www.freexian.com/blog/debian-lts-report-2026-06/">
	<title>Freexian Collaborators: Monthly report about Debian Long Term Support, June 2026 (by Thorsten Alteholz)</title>
	<link>https://www.freexian.com/blog/debian-lts-report-2026-06/</link>
     <content:encoded>&lt;img src=&quot;https://www.freexian.com/images/debian-lts-logo.png&quot; style=&quot;float: right;&quot; /&gt;
&lt;p&gt;The Debian LTS Team, funded by [Freexian’s Debian LTS offering]
(&lt;a href=&quot;https://www.freexian.com/lts/debian/%29&quot;&gt;https://www.freexian.com/lts/debian/)&lt;/a&gt;, is pleased to report its activities for
June.&lt;/p&gt;
&lt;h3 id=&quot;activity-summary&quot;&gt;Activity summary&lt;/h3&gt;
&lt;p&gt;During the month of June, 20 contributors have been
paid to work on &lt;a href=&quot;https://wiki.debian.org/LTS&quot;&gt;Debian LTS&lt;/a&gt; (links to individual
contributor reports are located below).&lt;/p&gt;
&lt;p&gt;The team released &lt;a href=&quot;https://lists.debian.org/debian-lts-announce/2026/06/threads.html&quot;&gt;48 DLAs&lt;/a&gt; fixing 231 CVEs.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.debian.org/releases/bookworm/&quot;&gt;Debian 12 (“bookworm”)&lt;/a&gt; has been handed over to
the LTS Team on June 11th. During this handover Sylvain helped to update relevant tools and
documentation.  If you benefit from Debian, especially during the
full 5-year lifecycle, please consider subscribing as a sponsor of Debian LTS:
&lt;a href=&quot;https://www.freexian.com/lts/debian/&quot;&gt;https://www.freexian.com/lts/debian/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Moreover, Debian 11 (“bullseye”) will reach the end of the Debian LTS period on
August 31st. After that, Freexian will continue the security support under the
&lt;a href=&quot;https://www.freexian.com/lts/extended/&quot;&gt;Extended LTS&lt;/a&gt; offer.&lt;/p&gt;
&lt;p&gt;The team published several notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;haveged update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4616-1&quot;&gt;DLA-4616-1&lt;/a&gt;),
prepared by Thorsten, to address local privilege escalation.&lt;/li&gt;
&lt;li&gt;tomcat9 update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4619-1&quot;&gt;DLA-4619-1&lt;/a&gt;),
prepared by Markus, to address, among others, an authentication bypass.&lt;/li&gt;
&lt;li&gt;apache2 update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4620-1&quot;&gt;DLA-4620-1&lt;/a&gt;),
prepared by Bastien, to address a HTTP/2 bomb.&lt;/li&gt;
&lt;li&gt;apache2 update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4629-1&quot;&gt;DLA-4629-1&lt;/a&gt;),
prepared by Bastien, to address, among others, remote code execution and privilege escalation.&lt;/li&gt;
&lt;li&gt;libinput update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4626-1&quot;&gt;DLA-4626-1&lt;/a&gt;),
prepared by Santiago, to address local privilege escalation and arbitrary code execution.&lt;/li&gt;
&lt;li&gt;asterisk update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4631-1&quot;&gt;DLA-4631-1&lt;/a&gt;),
prepared by Thorsten, to address, among others, wrong processing of invalid or untrusted certificates.&lt;/li&gt;
&lt;li&gt;nginx update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4634-1&quot;&gt;DLA-4634-1&lt;/a&gt;),
prepared by Charles, to address a remote code execution and denial of service.&lt;/li&gt;
&lt;li&gt;firefox-esr update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4635-1&quot;&gt;DLA-4635-1&lt;/a&gt;),
prepared by Emilio, to address dozens of CVEs, among other things, related to arbitrary code execution and privilege escalation.&lt;/li&gt;
&lt;li&gt;thunderbird update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4636-1&quot;&gt;DLA-4636-1&lt;/a&gt;),
prepared by Emilio, to address dozens of CVEs, among other things, related to arbitrary code execution.&lt;/li&gt;
&lt;li&gt;chromium update
(&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4654-1&quot;&gt;DLA-4654-1&lt;/a&gt;),
prepared by Emilio, to address dozens of CVEs, among other things, related to arbitrary code execution.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Contributions from outside the LTS Team:&lt;/p&gt;
&lt;p&gt;We are greatly thankful for the contributions from people outside the LTS Team:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Salvatore Bonaccorso prepared a libhttp-daemon-perl update, that was released by Santiago as
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4639-1&quot;&gt;DLA-4639-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Salvatore also directly uploaded libgd-perl
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4638-1&quot;&gt;DLA-4638-1&lt;/a&gt;
and libconfig-inifiles-perl
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4637-1&quot;&gt;DLA-4637-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Peter Palfrader prepared a tor update, that was released by Santiago as
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4656-1&quot;&gt;DLA-4656-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Pieter Lenaerts prepared a beets update, that was released by Emmanuel as
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4641-1&quot;&gt;DLA-4641-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Noah Meyerhans prepared a cloud-init update
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4645-1&quot;&gt;DLA-4645-1&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The LTS Team has also contributed with updates to the latest Debian releases:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Besides publishing
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4642-1&quot;&gt;DLA-4642-1&lt;/a&gt; for package u-boot
Andreas also prepared an NMU for an upload to sid and prepared a stable-proposed-update (SPU) bug
for &lt;a href=&quot;https://bugs.debian.org/1140663&quot;&gt;trixie&lt;/a&gt;, which was already acknowledged by a stable release manager (SRM).&lt;/li&gt;
&lt;li&gt;Andreas also prepared an upload of package atril for trixie, which was handled by the security team as
&lt;a href=&quot;https://lists.debian.org/debian-security-announce/2026/msg00260.html&quot;&gt;DSA-6349-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Besides publishing
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DLA-4620-1&quot;&gt;DLA-4620-1&lt;/a&gt; for package apache
Bastien also prepared an upload for trixie, which was handled by the security team as
&lt;a href=&quot;https://lists.debian.org/debian-security-announce/2026/msg00234.html&quot;&gt;DSA-6323-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Tobi uploaded package mesa to &lt;a href=&quot;https://bugs.debian.org/1140473&quot;&gt;trixie&lt;/a&gt;
and &lt;a href=&quot;https://bugs.debian.org/1140495&quot;&gt;bookworm&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Thorsten fixed some (not security related but RC) issues in package dahdi-linux. This was in preparation to fix lots of security issues in asterisk.
Unfortunately the maintainer ignored the corresponding debdiff and prefered to upload a new upstream version.
Anyway, the concerns of the security team about security support of asterisk could be overcome and asterisk can migrate to tesing and again be
part of a Debian release.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;individual-debian-lts-contributor-reports&quot;&gt;Individual Debian LTS contributor reports&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://people.debian.org/~abhijith/reports/LTS_ELTS-June-2026.txt&quot;&gt;Abhijith PA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/06/msg00065.html&quot;&gt;Andreas Henriksson&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/06/msg00058.html&quot;&gt;Arnaud Rebillout&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00006.html&quot;&gt;Bastien Roucariès&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.decadent.org.uk/ben/blog/2026/07/01/foss-activity-in-june-2026.html&quot;&gt;Ben Hutchings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00021.html&quot;&gt;Carlos Henrique Lima Melara&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://chris-lamb.co.uk/posts/free-software-activities-in-june-2026&quot;&gt;Chris Lamb&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00007.html&quot;&gt;Daniel Leidert&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00000.html&quot;&gt;Emmanuel Arias&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://people.debian.org/~pochu/lts/reports/2026-06.txt&quot;&gt;Emilio Pozuelo Monfort&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/msgid-search/?m=ft1Z8V9o2E3C8iOv@debian.org&quot;&gt;Guilhem Moulin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/msgid-search/akULnNGyjIvjKHX2@mpd&quot;&gt;Jochen Sprickerhof&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00014.html&quot;&gt;Lee Garrett&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://people.debian.org/~kanashiro/debian/lts/reports/2026-06.txt&quot;&gt;Lucas Kanashiro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://dl.gambaru.de/blog/202606_LTS_ELTS_report.txt&quot;&gt;Markus Koschany&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://people.debian.org/~santiago/lts-elts-reports/report-2026-06.txt&quot;&gt;Santiago Ruano Rincón&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/07/msg00004.html&quot;&gt;Sylvain Beucler&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.alteholz.eu/2026/07/my-debian-activities-in-june-2026/&quot;&gt;Thorsten Alteholz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/debian-lts/2026/06/msg00047.html&quot;&gt;Tobias Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://utkarsh2102.org/posts/foss-in-june-26/&quot;&gt;Utkarsh Gupta&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;thanks-to-our-sponsors&quot;&gt;Thanks to our sponsors&lt;/h3&gt;
&lt;p&gt;Sponsors that joined recently are in bold.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Platinum sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.global.toshiba/ww/top.html&quot;&gt;Toshiba Corporation&lt;/a&gt; (for 129 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cip-project.org&quot;&gt;Civil Infrastructure Platform (CIP)&lt;/a&gt; (for 97 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://vyos.io&quot;&gt;VyOS Inc&lt;/a&gt; (for 61 months)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Gold sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.roche.com/about/business/diagnostics.htm&quot;&gt;F. Hoffmann-La Roche AG&lt;/a&gt; (for 139 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.conet.de/&quot;&gt;CONET Deutschland GmbH&lt;/a&gt; (for 123 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.ox.ac.uk&quot;&gt;University of Oxford&lt;/a&gt; (for 79 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.edf.fr&quot;&gt;EDF SA&lt;/a&gt; (for 51 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.dataport.de&quot;&gt;Dataport AöR&lt;/a&gt; (for 26 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://home.cern/&quot;&gt;CERN&lt;/a&gt; (for 24 months)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Silver sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://domainnameshop.com/&quot;&gt;Domeneshop AS&lt;/a&gt; (for 144 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://metropole.nantes.fr/&quot;&gt;Nantes Métropole&lt;/a&gt; (for 138 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.akamai.com/&quot;&gt;Akamai - Linode&lt;/a&gt; (for 133 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.univention.de&quot;&gt;Univention GmbH&lt;/a&gt; (for 130 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://portail.univ-st-etienne.fr/&quot;&gt;Université Jean Monnet de St Etienne&lt;/a&gt; (for 130 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://ribboncommunications.com/&quot;&gt;Ribbon Communications, Inc.&lt;/a&gt; (for 124 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.exonet.nl&quot;&gt;Exonet B.V.&lt;/a&gt; (for 114 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.lrz.de&quot;&gt;Leibniz Rechenzentrum&lt;/a&gt; (for 108 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.diplomatie.gouv.fr&quot;&gt;Ministère de l’Europe et des Affaires Étrangères&lt;/a&gt; (for 92 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://dinahosting.com&quot;&gt;Dinahosting SL&lt;/a&gt; (for 79 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://upsun.com&quot;&gt;Upsun Formerly Platform.sh&lt;/a&gt; (for 73 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.moxa.com&quot;&gt;Moxa Inc.&lt;/a&gt; (for 67 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://sipgate.de&quot;&gt;sipgate GmbH&lt;/a&gt; (for 65 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://ovhcloud.com&quot;&gt;OVH US LLC&lt;/a&gt; (for 63 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.tilburguniversity.edu/&quot;&gt;Tilburg University&lt;/a&gt; (for 63 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.gsi.de&quot;&gt;GSI Helmholtzzentrum für Schwerionenforschung GmbH&lt;/a&gt; (for 54 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cesky-hosting.cz/&quot;&gt;THINline s.r.o.&lt;/a&gt; (for 27 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cph.dk&quot;&gt;Copenhagen Airports A/S&lt;/a&gt; (for 21 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.isere.fr&quot;&gt;Conseil Départemental de l’Isère&lt;/a&gt; (for 7 months)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Bronze sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://www.evolix.fr&quot;&gt;Evolix&lt;/a&gt; (for 144 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.seznam.cz&quot;&gt;Seznam.cz, a.s.&lt;/a&gt; (for 144 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://intevation.de&quot;&gt;Intevation GmbH&lt;/a&gt; (for 141 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://linuxhotel.de&quot;&gt;Linuxhotel GmbH&lt;/a&gt; (for 141 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://waays.fr&quot;&gt;Daevel SARL&lt;/a&gt; (for 140 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.megaspace.de&quot;&gt;Megaspace Internet Services GmbH&lt;/a&gt; (for 139 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.greenbone.net&quot;&gt;Greenbone AG&lt;/a&gt; (for 138 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://numlog.fr&quot;&gt;NUMLOG&lt;/a&gt; (for 138 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.wingo.ch/&quot;&gt;WinGo AG&lt;/a&gt; (for 137 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.entrouvert.com/&quot;&gt;Entr’ouvert&lt;/a&gt; (for 129 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://adfinis.com&quot;&gt;Adfinis AG&lt;/a&gt; (for 126 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.plathome.com&quot;&gt;Plat’Home&lt;/a&gt; (for 122 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.legi.grenoble-inp.fr&quot;&gt;Laboratoire LEGI - UMR 5519 / CNRS&lt;/a&gt; (for 121 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.tesorion.nl/&quot;&gt;Tesorion&lt;/a&gt; (for 121 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://bearstech.com&quot;&gt;Bearstech&lt;/a&gt; (for 112 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://lihas.de&quot;&gt;LiHAS&lt;/a&gt; (for 112 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.catalyst.net.nz&quot;&gt;Catalyst IT Ltd&lt;/a&gt; (for 107 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://demarcq.net&quot;&gt;Demarcq SAS&lt;/a&gt; (for 101 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.univ-grenoble-alpes.fr&quot;&gt;Université Grenoble Alpes&lt;/a&gt; (for 87 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.touchweb.fr&quot;&gt;TouchWeb SAS&lt;/a&gt; (for 79 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.spin-ag.de&quot;&gt;SPiN AG&lt;/a&gt; (for 76 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.corefiling.com&quot;&gt;CoreFiling&lt;/a&gt; (for 72 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.osug.fr/&quot;&gt;Observatoire des Sciences de l’Univers de Grenoble&lt;/a&gt; (for 63 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.werfen.com&quot;&gt;Tem Innovations GmbH&lt;/a&gt; (for 58 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://wordfinder.pro&quot;&gt;WordFinder.pro&lt;/a&gt; (for 57 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.resif.fr&quot;&gt;CNRS DT INSU Résif&lt;/a&gt; (for 56 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.soliton.co.jp&quot;&gt;Soliton Systems K.K.&lt;/a&gt; (for 51 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.alterway.fr&quot;&gt;Alter Way&lt;/a&gt; (for 49 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.sobis.com/&quot;&gt;SOBIS Software GmbH&lt;/a&gt; (for 24 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.tuxera.com&quot;&gt;Tuxera Inc.&lt;/a&gt; (for 15 months)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://opm-op.com&quot;&gt;OPM-OP AS&lt;/a&gt; (for 7 months)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.lu-cix.lu&quot;&gt;LU-CIX Management G.I.E.&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-22T00:00:00+00:00</dc:date>
	<dc:creator>Thorsten Alteholz</dc:creator>
</item> 
<item rdf:about="http://dirk.eddelbuettel.com/blog/2026/07/21#qlcal-r_0.1.3">
	<title>Dirk Eddelbuettel: qlcal 0.1.3 on CRAN: Micro Bugfix, Build Tweak</title>
	<link>http://dirk.eddelbuettel.com/blog/2026/07/21#qlcal-r_0.1.3</link>
     <content:encoded>&lt;p&gt;The twenty-first release of the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;qlcal&lt;/a&gt; package
arrivied at &lt;a href=&quot;https://cran.r-project.org&quot;&gt;CRAN&lt;/a&gt; just now, and
has been built for &lt;a href=&quot;https://eddelbuettel.github.io/r2u/&quot;&gt;r2u&lt;/a&gt;. It comes a week
after the &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/2026/07/14#qlcal-r_0.1.2&quot;&gt;0.1.2
release&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;qlcal&lt;/a&gt;
delivers the calendaring parts of &lt;a href=&quot;https://www.quantlib.org&quot;&gt;QuantLib&lt;/a&gt;. It is provided (for the R
package) as a set of included files, so the package is self-contained
and does not depend on an external &lt;a href=&quot;https://www.quantlib.org&quot;&gt;QuantLib&lt;/a&gt; library (which can be
demanding to build). &lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;qlcal&lt;/a&gt; covers
over seventy country / market calendars and can compute holiday lists,
its complement (&lt;em&gt;i.e.&lt;/em&gt; business day lists) and much more.
Examples are in the README at the &lt;a href=&quot;https://github.com/qlcal/qlcal-r&quot;&gt;repository&lt;/a&gt;, the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;package page&lt;/a&gt;,
and course at the &lt;a href=&quot;https://cran.r-project.org/package=qlcal&quot;&gt;CRAN package
page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This releases includes a one-line fix we also sent &lt;a href=&quot;https://github.com/lballabio/QuantLib/pull/2662&quot;&gt;upstream as a
now-merged PR&lt;/a&gt;: one of the calendar files added in QuantLib 1.43 also
needed to include the &lt;code&gt;vector&lt;/code&gt; header file. And every
compiler appears to be lenient (QuantLib itself has fourty different
continuous integration jobs, we test with all builds at r-universe)
apart from the CRAN macOS x86-64 machine. Sigh. This is now fixed. We
also included a neat little local trick I should blog about: if the
build is detected as a non-CRAN local build (simply by checking for a
&lt;code&gt;.git&lt;/code&gt; directory) then compiler flags can be updated to
quieten the build. We cannot do that in the package because we would get
our fingers slapped over so-called ‘non-portable compiler flags’. Sigh
again. Anyway, the trick helps.&lt;/p&gt;
&lt;p&gt;The full details from &lt;code&gt;NEWS.Rd&lt;/code&gt; follow.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id=&quot;changes-in-version-0.1.3-2026-07-21&quot;&gt;Changes in version 0.1.3
(2026-07-21)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Add missing &#39;vector&#39; header to new IslamicHolidays calendar file,
also PRed upstream and merged there&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;In local compilation out of git repo add additional compiler
flags&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/&quot;&gt;CRANberries&lt;/a&gt;, there
is a diffstat report for &lt;a href=&quot;https://dirk.eddelbuettel.com/cranberries/2026/07/21/#qlcal_0.1.3&quot;&gt;this
release&lt;/a&gt;. See the &lt;a href=&quot;https://dirk.eddelbuettel.com/code/qlcal-r.html&quot;&gt;project page&lt;/a&gt;
and package documentation for more details, and more examples.&lt;/p&gt;
&lt;p style=&quot;font-size: 80%; font-style: italic;&quot;&gt;
This post by &lt;a href=&quot;https://dirk.eddelbuettel.com&quot;&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href=&quot;https://dirk.eddelbuettel.com/blog/&quot;&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href=&quot;https://github.com/sponsors/eddelbuettel&quot;&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-21T13:18:00+00:00</dc:date>
	<dc:creator>Dirk Eddelbuettel</dc:creator>
</item> 
<item rdf:about="https://jmtd.net/log/interzone/digital/">
	<title>Jonathan Dowland: Interzone digital</title>
	<link>https://jmtd.net/log/interzone/digital/</link>
     <content:encoded>&lt;p&gt;&lt;em&gt;(no, this isn&#39;t a blog post about Joy Division songs)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://jmtd.net/log/interzone/294/&quot;&gt;Last time I wrote about Interzone&lt;/a&gt;, I was discussing issue #294, the
first published under new management in a paperback-sized format
(&quot;JB6&quot;). The format and presentation of the magazine was fantastic: it fit in a
lot of my pockets, and was packed with 15 stories as well as the regular
columns, in full colour with fantastic layouts and illustrations. Sadly there
was only one more physical issue before Interzone was forced to become a
digital-only publication.&lt;/p&gt;

&lt;div class=&quot;centre&quot;&gt;
&lt;div class=&quot;image+centre&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/interzone/physical_iz.jpg&quot;&gt;&lt;img alt=&quot;IZ issues 294 and 295&quot; class=&quot;img&quot; height=&quot;333&quot; src=&quot;https://jmtd.net/log/interzone/digital/250x-physical_iz.jpg&quot; width=&quot;250&quot; /&gt;&lt;/a&gt;

&lt;p&gt;IZ issues 294 and 295&lt;/p&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;I don&#39;t want to dwell on the sad necessity to move to digital. Interzone
continues on, celebrating the milestone issue #300 in 2024. Subscriptions
are managed via &lt;a href=&quot;https://www.patreon.com/c/interzonemag/membership&quot;&gt;Patreon&lt;/a&gt;.
Issue #305 just came out.&lt;/p&gt;

&lt;p&gt;Instead I wanted to write a small bit about how &lt;em&gt;I&lt;/em&gt; engaged with the paper
magazine, and the difficulties I&#39;ve had trying to engage with not just
Interzone but &lt;em&gt;any&lt;/em&gt; magazine-style publication in a digital context.&lt;/p&gt;

&lt;p&gt;With most fiction, I read linearly: start the beginning and read to the end, in
order. That works well for me with &lt;a href=&quot;https://jmtd.net/log/ereader/&quot;&gt;e-readers&lt;/a&gt;. But for magazines (and
most non-fiction) I don&#39;t, I jump around: usually starting with the
table of contents, I might pick a short column to start, or jump into the
middle of the &quot;book reviews&quot; section to read about a specific book. I might
skip sections entirely. I find it very difficult to read like this with an
e-reader. I think this is partly because I reference the &lt;em&gt;depth&lt;/em&gt; of the
paper book or magazine, its thickness, to orient myself. But it&#39;s also partly
the limitations of e-ink.&lt;/p&gt;

&lt;div class=&quot;centre&quot;&gt;
&lt;div class=&quot;image+centre&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/interzone/iz_ticklist.jpg&quot;&gt;&lt;img alt=&quot;My tick-list for an issue of IZ&quot; class=&quot;img&quot; height=&quot;444&quot; src=&quot;https://jmtd.net/log/interzone/digital/400x-iz_ticklist.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;

&lt;p&gt;My tick-list for an issue of IZ&lt;/p&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;For print-Interzone, I used to start by inserting a small piece of paper
inside the cover (the delivery slip was ideal). On this I listed the stories
within and ticked them off when I read them (sometimes I double-ticked if I
really liked a story). That helped me to remember, perhaps months or years
later, whether I&#39;d read all the stories or not, and which I liked.
I &lt;em&gt;could&lt;/em&gt; do something similar on some e-readers: the &lt;a href=&quot;https://jmtd.net/log/remarkable/&quot;&gt;Remarkable&lt;/a&gt; for
instance. But it&#39;s far from convenient to do on most e-ink devices.&lt;/p&gt;

&lt;p&gt;Interzone digital is available as both &lt;a href=&quot;https://en.wikipedia.org/wiki/EPUB&quot;&gt;ePUB&lt;/a&gt;, the most common format for e-books, and PDF. For reading on my
regular Kobo e-reader, PDFs don&#39;t work very well at all. I think this is
generally true of most e-readers.&lt;/p&gt;

&lt;p&gt;Interzone was (and is) a well-designed magazine. The value of it was not
just the &lt;em&gt;content&lt;/em&gt; of the text, but the &lt;em&gt;context&lt;/em&gt;: how the stories were
presented; the accompanying art (most often colour in recent decades),
but also the typesetting. ePUB
doesn&#39;t specify much of that stuff
exactly: it leaves that up to the client and the client&#39;s preferences.
And there&#39;s a lot of advantages to that:
Prefer a different font face or size? No problem. And
most importantly for accessibility:
If reading in ePUB makes Interzone available to more readers then that&#39;s
a great thing. But sadly a lot is lost, IMHO.&lt;/p&gt;

&lt;div class=&quot;centre&quot;&gt;
&lt;div class=&quot;image+centre&quot;&gt;
&lt;a href=&quot;https://jmtd.net/log/interzone/iz_ipad.jpg&quot;&gt;&lt;img alt=&quot;IZ #305 on iPad Mini&quot; class=&quot;img&quot; height=&quot;533&quot; src=&quot;https://jmtd.net/log/interzone/digital/400x-iz_ipad.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;

&lt;p&gt;IZ #305 on iPad Mini&lt;/p&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;The solution I&#39;m trying is to read the PDF version on the &lt;a href=&quot;https://jmtd.net/log/ipad_mini/&quot;&gt;iPad Mini&lt;/a&gt; I
resurrected earlier in the year.
Despite being an Internet tablet, since it&#39;s not really usable for browsing the
web anymore it&#39;s strangely still a distraction-free device. In fact it&#39;s pretty
much single-purpose for reading Interzone and the odd other book which benefits
from being read as PDF. I can appreciate the stylistic choices made in the
page-setting as they were intended; I can quickly jump around the issue without
waiting for an e-ink refresh; I get full colour; and whilst it would be tiring
to read for a long time on the iPad screen, for the length of articles or
stories in a magazine, this isn&#39;t a problem.&lt;/p&gt;

&lt;p&gt;It&#39;s not a solution for tracking what I&#39;ve read (that version of ipadOS is too
old to support clumsily scrawling on PDF pages with your fingers, at least in
the Books app) but it otherwise seems to work well, so I&#39;ll see how it goes.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-20T21:26:22+00:00</dc:date>
	<dc:creator>jmtd</dc:creator>
</item> 
<item rdf:about="https://retout.co.uk/2026/07/20/renewal-relationships-between-aws-certifications/">
	<title>Tim Retout: Renewal relationships between AWS certifications</title>
	<link>https://retout.co.uk/2026/07/20/renewal-relationships-between-aws-certifications/</link>
     <content:encoded>&lt;p&gt;When you pass an AWS certification exam, sometimes it can extend the
life of related lesser AWS certifications.  But I could not find an
illustration of exactly which ones, so here’s an up-to-date diagram:&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;AWS Certification renewal dependencies&quot; src=&quot;https://retout.co.uk/2026/aws-certs.svg&quot; /&gt;
&lt;em&gt;Figure: Renewal relationships between AWS certifications.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Each arrow is a ‘renews’ relation – there’s no obligation to pass
lesser exams before the harder ones, but you could also follow the
arrows backwards if you want to learn easier material before sitting
the more difficult exams.&lt;/p&gt;
&lt;p&gt;I have made two important simplifications to the graph:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;The ‘Advanced Networking – Specialty’ certification is being
retired soon, so I’ve omitted it entirely.  The last date to take that
exam is 25th August 2026.  But Specialty certs don’t renew anything
else anyway.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;I have left out transitive relationships in order to simplify the
graph – so e.g. if you pass a ‘Solutions Architect – Professional’
exam, it also renews any Cloud Practitioner certificate you might
hold, even if you do not currently hold the relevant Associate
certificate.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You also have the option of sitting each exam again to renew of
course, and there’s a new scheme to ‘maintain’ various certs via AWS
Skill Builder which can extend them by one year rather than three.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-20T20:52:17+00:00</dc:date>
	<dc:creator>Tim Retout</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-07-20:/2026/07/debconf26-starts-today.html">
	<title>Bits from Debian: DebConf26 starts today in Santa Fe on Monday, July 20, 2026</title>
	<link>https://bits.debian.org/2026/07/debconf26-starts-today.html</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf26&lt;/a&gt;, the 27th annual
&lt;a href=&quot;https://www.debconf.org/&quot;&gt;Debian Developer Conference&lt;/a&gt;, is taking place at
Santa Fe, Argentina from 20 to 25 July 2026.
Debian contributors from all over the world have come together at the Facultad
de Ingeniería en Ciencias Hídricas (Faculty of Engineering in Water Sciences),
one of the faculties that belong to the Universidad Nacional del Litoral
(National University of the Littoral), to participate and work in a
conference exclusively ran by volunteers.&lt;/p&gt;
&lt;p&gt;Today the main conference starts with around 300 expected attendants and over
80 scheduled activities, including 45-minute and 20-minute talks, Bird of a
Feather (&quot;&lt;abbr&gt;BoF&lt;/abbr&gt;&quot;) team meetings, workshops, a job fair, as well as
a variety of other events.
The full &lt;a href=&quot;https://debconf26.debconf.org/schedule/&quot;&gt;schedule&lt;/a&gt; is updated each
day, including activities planned ad-hoc by attendees over the course of the
conference.&lt;/p&gt;
&lt;p&gt;If you would like to engage remotely, you can follow the &lt;strong&gt;video streams&lt;/strong&gt;
available from the &lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf26 website&lt;/a&gt; for the
events happening in the three main talk rooms: Aula Magna - FADU,
Aula Magna - FBCB and Aula 0.3 - FICH accessible from the DebConf26 homepage.
You can also join the conversations happening inside the talk rooms via the
&lt;a href=&quot;https://www.oftc.net/&quot;&gt;OFTC IRC network&lt;/a&gt; in the
&lt;a href=&quot;irc://irc.oftc.net/debconf-fadu&quot;&gt;#debconf-fadu&lt;/a&gt;,
&lt;a href=&quot;irc://irc.oftc.net/debconf-fbcb&quot;&gt;#debconf-fbcb&lt;/a&gt;,
and &lt;a href=&quot;irc://irc.oftc.net/debconf-fich3&quot;&gt;#debconf-fich3&lt;/a&gt; channels.
Please also join us in the &lt;a href=&quot;irc://irc.oftc.net/debconf&quot;&gt;#debconf&lt;/a&gt; channel for
common discussions related to DebConf.&lt;/p&gt;
&lt;p&gt;You can also follow the live coverage of news about DebConf26 provided by our
&lt;a href=&quot;https://micronews.debian.org/&quot;&gt;micronews service&lt;/a&gt; or the @debian profile on
your favorite social network.&lt;/p&gt;
&lt;p&gt;DebConf is committed to a safe and welcoming environment for all participants.
Please see our &lt;a href=&quot;https://debconf26.debconf.org/about/coc/&quot;&gt;Code of Conduct page&lt;/a&gt;
for more information on this.&lt;/p&gt;
&lt;p&gt;Debian thanks the commitment of numerous sponsors to support DebConf26,
particularly our Platinum Sponsors:
&lt;a href=&quot;https://www.infomaniak.com/&quot;&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt; and
&lt;a href=&quot;https://www.proxmox.com/&quot;&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;DebConf26 sponsors logo&quot; src=&quot;https://bits.debian.org/images/debconf26-sponsors-banner.svg&quot; /&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-20T09:50:00+00:00</dc:date>
	<dc:creator>The Debian Publicity Team</dc:creator>
</item> 
<item rdf:about="tag:bits.debian.org,2026-07-18:/2026/07/debconf26-welcomes-sponsors.html">
	<title>Bits from Debian: DebConf26 welcomes its sponsors</title>
	<link>https://bits.debian.org/2026/07/debconf26-welcomes-sponsors.html</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://bits.debian.org/images/Romina_Molina_dc26_2.svg&quot;&gt;&lt;img alt=&quot;Alt DebConf26 by Romina Molina&quot; src=&quot;https://bits.debian.org/images/Romina_Molina_dc26_2.svg&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf26&lt;/a&gt;, the 27th edition of the Debian
conference is taking place at the
&lt;a href=&quot;https://www.fich.unl.edu.ar/&quot;&gt;Facultad de Ingeniería en Ciencias Hídricas&lt;/a&gt; of
the Universidad Nacional del Litoral, in Santa Fe, Argentina. We appreciate
the organizers for their hard work, and hope this event will be highly
beneficial for those who attend in person as well as online.&lt;/p&gt;
&lt;p&gt;This event would not be possible without the help from our generous sponsors.
We would like to warmly welcome the sponsors of DebConf26, and introduce them
to you.&lt;/p&gt;
&lt;p&gt;We have two Platinum sponsors.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Our first Platinum sponsor is &lt;a href=&quot;https://www.proxmox.com/&quot;&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt;.
  Proxmox develops powerful, yet easy-to-use open-source server solutions.
  The comprehensive open-source ecosystem is designed to manage divers IT
  landscapes, from single servers to large-scale distributed data centers.
  Our unified platform integrates server virtualization, easy backup, and
  rock-solid email security ensuring seamless interoperability across the
  entire portfolio. With the Proxmox Datacenter Manager, the ecosystem also
  offers a &quot;single pane of glass&quot; for centralized management across different
  locations.
  Since 2005, all Proxmox solutions have been built on the rock-solid Debian
  platform. We are proud to return to DebConf26 as a sponsor because the
  Debian community provides the foundation that makes our work possible. We
  believe in keeping IT simple, open, and under your control.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://www.infomaniak.com/&quot;&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt; is the second Platinum sponsor.
  Infomaniak is an independent, employee-owned Swiss technology company that
  designs, develops, and operates its own cloud infrastructure and digital
  services entirely in Switzerland. With over 300 employees — more than 70%
  engineers and developers — the company reinvests all profits into R&amp;amp;D. Its
  public cloud is built on OpenStack, with managed Kubernetes, Database as a
  Service, object storage, and sovereign AI services accessible via OpenAI-
  compatible APIs, all running on its own Swiss infrastructure. Infomaniak also
  develops a sovereign collaborative suite — messaging, email, storage, online
  office tools, videoconferencing, and a built-in AI assistant — developed in-
  house and as a privacy-respecting solution to proprietary platforms. Open
  source is central to how Infomaniak operates. Its latest data center (D4)
  runs on 100% renewable energy and uses no traditional cooling: all the heat
  generated by its servers is captured and fed into Geneva&#39;s district heating
  network, supplying up to 6,000 homes in winter and hot water year-round. The
  entire project has been documented and open-sourced at
  &lt;a href=&quot;https://d4project.org/&quot;&gt;d4project.org&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Our Gold sponsors are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://www.freexian.com/&quot;&gt;&lt;strong&gt;Freexian&lt;/strong&gt;&lt;/a&gt;, Freexian specializes in Free
  Software with a particular focus on Debian GNU/Linux. Freexian can assist
  with consulting, training, technical support, packaging, or software
  development on projects involving use or development of Free software.
  All of Freexian&#39;s employees and partners are well-known contributors in the
  Free Software community, a choice that is integral to Freexian&#39;s business
  model.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://www.viridiengroup.com&quot;&gt;&lt;strong&gt;Viridien&lt;/strong&gt;&lt;/a&gt; an advanced technology,
  digital and Earth data company that pushes the boundaries of science for
  a more prosperous and sustainable future. Viridien has been using
  Debian-based systems to power most of its HPC infrastructure and its
  cloud platform since 2009 and currently employs two active Debian
  Project Members.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Our Silver sponsors are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.arm.com/&quot;&gt;&lt;strong&gt;Arm&lt;/strong&gt;&lt;/a&gt;: leading technology provider of processor
  IP, Arm powered solutions have been supporting innovation for
  more than 30 years and are deployed in over 280 billion chips to date.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.pexip.com/&quot;&gt;&lt;strong&gt;Pexip&lt;/strong&gt;&lt;/a&gt; brings the ease of commercial video
  platforms to secure and sovereign environments without compromising control
  or performance.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://www.bfh.ch/&quot;&gt;&lt;strong&gt;Bern University of Applied Sciences&lt;/strong&gt;&lt;/a&gt; with around
  7,959 students enrolled, located in the Swiss capital.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.canonical.com/&quot;&gt;&lt;strong&gt;Ubuntu&lt;/strong&gt;&lt;/a&gt;,
  the Operating System delivered by Canonical.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://os-sci.com/&quot;&gt;&lt;strong&gt;OS-Sci&lt;/strong&gt;&lt;/a&gt;, Open Source Science is a world-leading
  institution dedicated to teaching computer science through Free and Open
  Source Software (FOSS).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.gcoop.coop/&quot;&gt;&lt;strong&gt;gcoop&lt;/strong&gt;&lt;/a&gt;, a free software development company
  with over 19 years of market experience, organized as a worker cooperative,
  promoting best practices in software development.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.qualcomm.com/developer/opensource&quot;&gt;&lt;strong&gt;Qualcomm&lt;/strong&gt;&lt;/a&gt; Technologies,
  one of the world&#39;s leading companies in field of mobile technology, sponsors
  and contributes to Open Source developer communities that drive collaboration.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cip-project.org/&quot;&gt;&lt;strong&gt;Civil Infrastructure Platform&lt;/strong&gt;&lt;/a&gt;,
  a collaborative project hosted by the Linux Foundation, establishing an open
  source “base layer” of industrial grade software.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://opensource.siemens.com/&quot;&gt;&lt;strong&gt;Siemens&lt;/strong&gt;&lt;/a&gt; is a technology company
  focused on industry, infrastructure and transport.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.collabora.com/&quot;&gt;&lt;strong&gt;Collabora&lt;/strong&gt;&lt;/a&gt;, a global consultancy delivering
  Open Source software solutions to the commercial world.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://nerdearla.com/en/&quot;&gt;&lt;strong&gt;NERDEARLA&lt;/strong&gt;&lt;/a&gt;, the largest free tech event in
  the Spanish-speaking world.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Bronze sponsors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.loongson.cn/&quot;&gt;&lt;strong&gt;Loongson&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.credativ.de/&quot;&gt;&lt;strong&gt;credativ&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://google.com/&quot;&gt;&lt;strong&gt;Google&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.spacemit.com/&quot;&gt;&lt;strong&gt;SpacemiT&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And finally, our Supporter level sponsors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://altusmetrum.org/&quot;&gt;&lt;strong&gt;Altus Metrum&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://loongfans.cn/en/&quot;&gt;&lt;strong&gt;Loongson Hobbyists Community&lt;/strong&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.santafe.gob.ar/&quot;&gt;&lt;strong&gt;Secretaría de Tecnologías para la Gestión de la Provincia de Santa Fe&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A special thanks to the
&lt;a href=&quot;https://www.fich.unl.edu.ar/&quot;&gt;&lt;strong&gt;Facultad de Ingeniería y Ciencias Hídricas - FICH UNL&lt;/strong&gt;&lt;/a&gt;,
our Venue Partner!&lt;/p&gt;
&lt;p&gt;Thanks to all our sponsors for their support!
Their contributions enable a diverse global community of Debian developers and
maintainers to collaborate, support one another, and share knowledge at
DebConf26.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-18T12:00:00+00:00</dc:date>
	<dc:creator>The Debian Publicity Team</dc:creator>
</item> 
<item rdf:about="tag:www.sergiocipriano.com,2026-07-17:posts/running-gui-in-incus.md">
	<title>Sergio Cipriano: Running Graphical Applications in Incus Containers</title>
	<link>https://sergiocipriano.com/running-gui-in-incus.html</link>
     <content:encoded>&lt;h1 id=&quot;running-graphical-applications-in-incus-containers&quot;&gt;Running
Graphical Applications in Incus Containers&lt;/h1&gt;
&lt;p&gt;I didn&#39;t know how easy it is to display the graphical console of a
virtual machine until I tried recently.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ sudo apt install virt-viewer
$ incus launch images:debian/trixie test --vm
$ incus console test --type=vga&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;That&#39;s it.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-17T20:17:17+00:00</dc:date>
	<dc:creator>Sérgio de Almeida Cipriano Júnior</dc:creator>
</item> 
<item rdf:about="https://diffoscope.org/news/diffoscope-325-released/">
	<title>Reproducible Builds (diffoscope): diffoscope 325 released</title>
	<link>https://diffoscope.org/news/diffoscope-325-released/</link>
     <content:encoded>&lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;325&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[ Chris Lamb ]
* Fix tests to work with zipdetails 4.0008. (Closes: #1141359)
* Downgrade debhelper compatibility level to 13 for now.
* Update copyright years.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href=&quot;https://diffoscope.org&quot;&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-17T00:00:00+00:00</dc:date>
	<dc:creator>Reproducible Builds (diffoscope)</dc:creator>
</item> 
<item rdf:about="http://blog.sesse.net/blog/tech/2026-07-15-08-45_looking_at_dpkg_startup_time.html">
	<title>Steinar H. Gunderson: Looking at dpkg startup time</title>
	<link>http://blog.sesse.net/blog/tech/2026-07-15-08-45_looking_at_dpkg_startup_time.html</link>
     <content:encoded>&lt;p&gt;Five years or so ago, I had a look at trying to speed up dpkg&#39;s package
installation; I concluded that it was probably possible to speed up,
but that there was no appetite for this kind of large-scale changes.
(You&#39;d probably need to rewrite the transaction system to get rid of
a lot of fsyncs, you&#39;d ideally want to reduce the number of syscalls
for unpack by io_uring and so on.)&lt;/p&gt;

&lt;p&gt;This summer, I&#39;ve been looking at something related on and off; it is
possible to speed up the startup time? That&#39;s in a sense the opposite
scenario; instead of installing lots of packages in a newly debootstrapped
chroot (with very few packages), see how fast you can install one
in a much more busy chroot (I just copied my laptop&#39;s dpkg dir, with ~6600 packages
installed).&lt;/p&gt;

&lt;p&gt;Before I show the numbers, I must stress that this is an &lt;em&gt;investigation&lt;/em&gt;,
not a fair benchmark, and you should not go shout at the dpkg maintainers
that they need to get to “catch up”. That said:&lt;/p&gt;

&lt;pre&gt;&amp;gt; sudo time dpkg --root=root -i hello_2.12.3-1_amd64.deb &amp;gt;/dev/null
Not building database; man-db/auto-update is not &#39;true&#39;.
1.12user 0.49system 0:01.85elapsed 87%CPU (0avgtext+0avgdata 171880maxresident)k
0inputs+14648outputs (0major+72963minor)pagefaults 0swaps

&amp;gt; sudo time ./src/dpkg --root=root -i hello_2.12.3-1_amd64.deb &amp;gt; /dev/null
0.04user 0.01system 0:00.15elapsed 38%CPU (0avgtext+0avgdata 6520maxresident)k
0inputs+1080outputs (0major+2705minor)pagefaults 0swaps
&lt;/pre&gt;

&lt;p&gt;How is it unfair? Well, for one, the code to run triggers is messed up
so they&#39;re not run (but the trigger in question should be very fast).
And there&#39;s one step at the end with detecting “disappearing packages” that doesn&#39;t run properly
because it&#39;s a bit tricky in my model and I didn&#39;t want to deal
with, well, difficult problems. But I think both are perfectly doable without
really affecting the end time, it just requires engineering. There&#39;s a &lt;em&gt;lot&lt;/em&gt; of work to be done, though;
diving into the code makes me shudder at all the complexities that need to be
in place to support all the corner cases of multiarch, for instance.&lt;/p&gt;

&lt;p&gt;The code is extremely proof-of-concept, but it runs and can read (and write)
metadata from SQLite instead of flat text files, it can resolve dependencies
in the most basic fashion, it can keep track of installed files, it should be
crash- and powerloss-proof. You know, the very very basic stuff, and without changing the
model fundamentally (like e.g. Michael Stapelberg did with
&lt;a href=&quot;https://distr1.org/&quot;&gt;distri&lt;/a&gt;, fundamentally replacing packages with disk
images and ending up in a very fast but rather different-looking system). So it was satisfying to see
that it ends up around 10x even on my not-very-new laptop (plus a significant
RAM reduction); I believe it should be possible to squeeze under 100 ms,
but that would probably require also optimizing the unpacking itself, which I didn&#39;t look at this time.&lt;/p&gt;

&lt;p&gt;Having a bunch of files being read into RAM and then processed freely was a design that made
a lot of sense when dpkg was written (in 1995!) and Debian had ~250 binary
packages &lt;em&gt;in total&lt;/em&gt; (and you probably wouldn&#39;t install all of them).
There was no reasonable database available for desktop systems; the closest
thing you&#39;d have was probably BerkeleyDB and that wasn&#39;t really it,
so flat files and fsync made a lot of sense, and was easy to manipulate
and persist.
But now, SQLite is widely available and probably the most battle-tested
code in history, a typical system has thousands of packages (you could
easily install tens of thousands if you&#39;re doing heavy development),
SSDs have replaced HDDs almost everywhere for system disks, and the
environment has just changed a lot in general. So I hope that someone at some
point will be crazy enough to pick this up and run with it, because it&#39;s a
lot of work and I don&#39;t intend to. :-)&lt;/p&gt;

&lt;p&gt;PS: I didn&#39;t look at apt; I think what I&#39;d really love to see first and
foremost is a package format change so that apt-listchanges can look at
(or look for) NEWS.gz without having to unpack the entire package.
Perhaps a control field saying “nothing new here”?&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-15T07:45:00+00:00</dc:date>
	<dc:creator>Steinar H. Gunderson</dc:creator>
</item> 
<item rdf:about="https://www.freexian.com/blog/debian-contributions-06-2026/">
	<title>Freexian Collaborators: Debian Contributions: Python 3.14 as default transition, DebConf 26 preparations, debvm, pconr and more! (by Anupa Ann Joseph)</title>
	<link>https://www.freexian.com/blog/debian-contributions-06-2026/</link>
     <content:encoded>&lt;h1 id=&quot;debian-contributions-2026-06&quot;&gt;Debian Contributions: 2026-06&lt;/h1&gt;
&lt;p&gt;&lt;a href=&quot;https://www.freexian.com/about/debian-contributions/&quot;&gt;Contributing to Debian&lt;/a&gt;
is part of &lt;a href=&quot;https://www.freexian.com/about/&quot;&gt;Freexian’s mission&lt;/a&gt;. This article
covers the latest achievements of Freexian and their collaborators. All of this
is made possible by organizations subscribing to our
&lt;a href=&quot;https://www.freexian.com/lts/&quot;&gt;Long Term Support contracts&lt;/a&gt; and
&lt;a href=&quot;https://www.freexian.com/services/&quot;&gt;consulting services&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;python-314-as-default-transition-by-stefano-rivera&quot;&gt;Python 3.14 as default transition, by Stefano Rivera&lt;/h2&gt;
&lt;p&gt;Debian has had Python 3.13 and 3.14 in &lt;code&gt;unstable&lt;/code&gt; and &lt;code&gt;testing&lt;/code&gt; since December
2025, with Python 3.13 as the default version (&lt;code&gt;/usr/bin/python3&lt;/code&gt; = 3.13). This
gave time for packages to implement support and detect issues in their test suites.&lt;/p&gt;
&lt;p&gt;A slot to transition to 3.14 as default was requested from the release team
&lt;a href=&quot;https://bugs.debian.org/1130323&quot;&gt;in March&lt;/a&gt;, and they indicated that we would
likely be able to schedule it in late June. In preparation, Stefano reviewed the
open bugs against Python interpreters and squashed some in uploads of the latest
point releases of Python: &lt;a href=&quot;https://www.python.org/downloads/release/python-31314/&quot;&gt;3.13.14&lt;/a&gt;
and &lt;a href=&quot;https://www.python.org/downloads/release/python-3146/&quot;&gt;3.14.6&lt;/a&gt;. Also in
June, Python &lt;a href=&quot;https://www.python.org/downloads/release/python-3150b2/&quot;&gt;3.15.0 beta 2&lt;/a&gt;
and &lt;a href=&quot;https://www.python.org/downloads/release/python-3150b3/&quot;&gt;beta 3&lt;/a&gt; released.
Stefano uploaded these to Debian &lt;code&gt;experimental&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The 3.15 betas were reason to &lt;a href=&quot;https://discuss.python.org/t/can-we-consider-an-uncoditional-change-of-abi3t-so-to-abi3t-soabi-platform-so-for-3-15-last-minute/107919&quot;&gt;attempt to revive review&lt;/a&gt;
of a blocked &lt;a href=&quot;https://github.com/python/cpython/pull/122917&quot;&gt;upstream patch&lt;/a&gt; to
support Debian multiarch in stable ABI Python extensions, now that Python 3.15
is adding a new stable ABI &lt;code&gt;abi3t&lt;/code&gt;.&lt;/p&gt;
&lt;h2 id=&quot;debconf-26-preparations-by-stefano-rivera-antonio-terceiro-lucas-kanashiro-santiago-ruano-rincón-and-anupa-ann-joseph&quot;&gt;DebConf 26 preparations, by Stefano Rivera, Antonio Terceiro, Lucas Kanashiro, Santiago Ruano Rincón and Anupa Ann Joseph&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://debconf26.debconf.org/&quot;&gt;DebConf 26&lt;/a&gt;, the annual Debian Developer
Conference, is being held in Santa Fe, Argentina, in July. Stefano Rivera,
Antonio Terceiro, Lucas Kanashiro, Santiago Ruano and Anupa Ann Joseph
contributed to the preparations for the event.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;As usual, Stefano has been supporting the conference website and registration,
helping the local team to get accurate data on attendee numbers.&lt;/li&gt;
&lt;li&gt;Antonio has been supporting the conference website and helping the content
team to put together the conference schedule.&lt;/li&gt;
&lt;li&gt;Santiago has been helping the local team on different topics regarding logistics.&lt;/li&gt;
&lt;li&gt;Anupa assisted with the accommodation arrangements for DebCamp and DebConf,
working alongside Nattie.&lt;/li&gt;
&lt;li&gt;Lucas has been coordinating the conference schedule and communicating with
some speakers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;debvm-by-helmut-grohne&quot;&gt;debvm, by Helmut Grohne&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://salsa.debian.org/helmutg/debvm&quot;&gt;debvm&lt;/a&gt; tool used for creating and
running ephemeral virtual machines saw a number of small improvements. The
requirement of having a filesystem label has been removed in favor of using a
uuid and &lt;code&gt;/etc/fstab&lt;/code&gt; is no longer created. A memory balloon is enabled by
default and this enables qemu to automatically release free guest memory to the
host. Booting Ubuntu VMs regressed as a result of their use of &lt;code&gt;uutils&lt;/code&gt; and has
been fixed. The &lt;code&gt;--architecture&lt;/code&gt; flag is back to be able to better support Hurd,
which is a work-in-progress of Johannes Schauer Marin Rodrigues. Thanks to
Jochen Sprickerhof, you can more easily create VMs for &lt;code&gt;autopkgtest-virt-qemu&lt;/code&gt;
using &lt;code&gt;--hook-dir=/usr/share/mmdebstrap/hooks/autopkgtest-create-qemu&lt;/code&gt;. There
also are a few documentation and error message improvements. All of this is
pending in git waiting to be uploaded once development slows down. While booting
a machine from &lt;code&gt;virtiofsd&lt;/code&gt; succeeded, turning the proof-of-concept into
production remains for later.&lt;/p&gt;
&lt;h2 id=&quot;pconr-by-helmut-grohne&quot;&gt;pconr, by Helmut Grohne&lt;/h2&gt;
&lt;p&gt;At &lt;a href=&quot;https://debconf25.debconf.org/talks/170-reviving-unschroot/&quot;&gt;DebConf25&lt;/a&gt;,
Helmut reported on a &lt;a href=&quot;https://codeberg.org/shelter/reschroot&quot;&gt;schroot&lt;/a&gt;
substitute called unschroot. The second iteration uses &lt;a href=&quot;https://varlink.org&quot;&gt;varlink&lt;/a&gt;
IPC to construct a container. That varlink API is now separated into a new
project called &lt;a href=&quot;https://git.subdivi.de/~helmut/pconr.git/&quot;&gt;programmable container runtime&lt;/a&gt;.
It is meant to provide more flexibility in constructing containers than
established solutions such as the &lt;code&gt;unshare&lt;/code&gt; command from util-linux, bubblewrap
or podman provide while still managing repetitive complexity such as process
orchestration for the developer. A new example that uses this infrastructure is
&lt;a href=&quot;https://git.subdivi.de/~helmut/pconr.git/tree/examples/mmdebstrap_container.py&quot;&gt;a better containment for mmdebstrap&lt;/a&gt;
eliminating chroot escape. There also is an
&lt;a href=&quot;https://github.com/helmutg/asyncvarlink/commit/3e16139f72c7374f2ca3640045ef7162c98e7a4c&quot;&gt;asyncvarlink/0.3.2 release&lt;/a&gt;
taking steps to become more maintainable in Debian to eventually get pconr into
Debian.&lt;/p&gt;
&lt;h2 id=&quot;miscellaneous-contributions&quot;&gt;Miscellaneous contributions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Stefano did routine uploads (mostly new upstream versions) of &lt;code&gt;python-pip&lt;/code&gt;,
&lt;code&gt;python-pipx&lt;/code&gt;, &lt;code&gt;hatchling&lt;/code&gt;, &lt;code&gt;dh-python&lt;/code&gt;, &lt;code&gt;beautifulsoup4&lt;/code&gt;, &lt;code&gt;python-virtualenv&lt;/code&gt;,
&lt;code&gt;python-mitogen&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Stefano uploaded a snowball mini-transition: &lt;code&gt;snowball&lt;/code&gt;, &lt;code&gt;snowball-data&lt;/code&gt;,
and &lt;code&gt;pystemmer&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Stefano did some &lt;a href=&quot;https://wiki.debian.org/Teams/DebianNet&quot;&gt;debian.net&lt;/a&gt; team
admin, setting up a container and later a VM for
&lt;a href=&quot;https://salsa.debian.org/debiannet-team/requests/-/work_items/36&quot;&gt;vote.debian.net&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Stefano &lt;a href=&quot;https://lists.debian.org/msgid-search/cer4b3szczxpt64wbzhumcm6go7tmkfvhdsqoftpevav2ovu3l@zherud2oym4p&quot;&gt;responded&lt;/a&gt;
to a &lt;a href=&quot;https://lists.debian.org/msgid-search/CAEd1pt5QiD9-UUV5jP=U7=L2pM5f6c1WPcUY3jWoYbcTO8iRcw@mail.gmail.com&quot;&gt;semi-escalation&lt;/a&gt;
to the Debian Technical Committee, after some communication between an upstream,
a bug reporter, and a Debian package maintainer went sideways and got heated.&lt;/li&gt;
&lt;li&gt;Emilio managed several transitions, and filed bugs against the few remaining
GCC 13 rdeps.&lt;/li&gt;
&lt;li&gt;Antonio did salsa maintenance work, debugging service issues, approving user
registrations, and processing support requests.&lt;/li&gt;
&lt;li&gt;Antonio worked on Debian CI maintenance, including but not limited to
deploying new armhf and armel workers, fixing bugs and preparing an upcoming
release of debci.&lt;/li&gt;
&lt;li&gt;Antonio did several maintenance tasks for MiniDebConf websites.&lt;/li&gt;
&lt;li&gt;Antonio uploaded ruby-bunny, ruby-sinatra and ruby-mustermann, fixing a few
FTBFS bugs among them.&lt;/li&gt;
&lt;li&gt;Carles using &lt;code&gt;&lt;a href=&quot;https://salsa.debian.org/carlespina/po-debconf-manager&quot;&gt;po-debconf-manager&lt;/a&gt;&lt;/code&gt;:
Reviewed Catalan translations for 5 packages, submitted 6 packages. Added a
&lt;a href=&quot;https://salsa.debian.org/carlespina/po-debconf-manager/-/blob/main/docs/blog/2026-06-29-update.md?ref_type=heads&quot;&gt;draft blog/update&lt;/a&gt;
about the po-debconf-manager project.&lt;/li&gt;
&lt;li&gt;Carles submitted a new &lt;a href=&quot;https://github.com/BestImageViewer/geeqie/pull/2438&quot;&gt;Geeqie Catalan translation&lt;/a&gt;:
it had accumulated a large number of untranslated strings over the last 4 years.&lt;/li&gt;
&lt;li&gt;Carles contributed to the Debian wiki: improved documentation for the
Framework Laptop and added a new section “&lt;a href=&quot;https://wiki.debian.org/InstallingDebianOn/Framework/Laptop13/AMD_Ryzen_AI_300_Series#Battery_charging_control&quot;&gt;Battery charging control&lt;/a&gt;”
(after doing some debugging and testing). He wrote a page about
&lt;a href=&quot;https://wiki.debian.org/SignalDesktop&quot;&gt;Signal Desktop&lt;/a&gt;. Carles started looking
at testing/documenting Mailman2 -&amp;gt; Mailman3 migration.&lt;/li&gt;
&lt;li&gt;Carles, in relation to the migration process, double checked old pages without
relevant information in the Debian wiki.&lt;/li&gt;
&lt;li&gt;Thorsten did another upload of package hplip to fix some bugs.&lt;/li&gt;
&lt;li&gt;In the context of the Google Summer of Code 2026 project, Santiago continued
co-mentoring Aryan Karamtoth, who is working on the Linux live-patching project.
As part of the team, Santiago guided Aryan to help design the different
workflows and to study the different tools available, including the
&lt;a href=&quot;https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/scripts/livepatch/klp-build?h=v6.19&quot;&gt;upstream klp-build&lt;/a&gt;
(that was introduced in v6.19), and compare it with &lt;a href=&quot;https://github.com/SUSE/klp-build/&quot;&gt;SUSE’s klp-build&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Colin &lt;a href=&quot;https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1149&quot;&gt;clarified&lt;/a&gt;
the bug tracking system’s documentation to indicate that maintainers may
sometimes reasonably ask users to file bugs upstream themselves.&lt;/li&gt;
&lt;li&gt;Colin fixed 15 packages for &lt;a href=&quot;https://udd.debian.org/cgi-bin/bts-usertags.cgi?user=debian-python%40lists.debian.org&amp;amp;tag=pytest9.1&quot;&gt;pytest 9.1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Colin fixed a &lt;a href=&quot;https://bugs.debian.org/1140927&quot;&gt;depthcharge-tools regression with Python 3.14 as default&lt;/a&gt;
that broke debian-installer builds.&lt;/li&gt;
&lt;li&gt;Helmut continued to report undeclared file conflicts and correspond about them.&lt;/li&gt;
&lt;li&gt;Helmut wrote patches for &lt;a href=&quot;https://tracker.debian.org/strace&quot;&gt;strace&lt;/a&gt; to enable
&lt;a href=&quot;https://bugs.debian.org/1140559&quot;&gt;cross building&lt;/a&gt; and a
&lt;a href=&quot;https://bugs.debian.org/1062446&quot;&gt;32bit personality on arm64&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Helmut continued maintaining rebootstrap working fixing build failures in
fontconfig, gettext and sqlite3 as well as changing the way packages from gcc
builds are installed to better serve a need reported by
&lt;a href=&quot;https://lists.debian.org/debian-cross/2026/06/msg00005.html&quot;&gt;Samuel Thibault&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-15T00:00:00+00:00</dc:date>
	<dc:creator>Anupa Ann Joseph</dc:creator>
</item> 
<item rdf:about="https://gwolf.org/2026/07/got-your-keys-ready-for-debconf26.html">
	<title>Gunnar Wolf: Got your keys ready for DebConf26?</title>
	<link>https://gwolf.org/2026/07/got-your-keys-ready-for-debconf26.html</link>
     <content:encoded>&lt;p&gt;Yay! Finally it’s that time of year — DebCamp is underway, and soon it will
be time for DebConf! 🎉🥳&lt;/p&gt;

&lt;p&gt;As it is by now tradition, it’s my task to coordinate the DebConf26
keysigning party. And, as usual, I have set up the list of &lt;a href=&quot;https://people.debian.org/~gwolf/dc26_ksp/&quot;&gt;DebConf26
keysigning maps&lt;/a&gt; for everybody
involved.&lt;/p&gt;

&lt;p&gt;So, if you are taking part of DebConf, make sure to:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Find yourself in the &lt;a href=&quot;https://people.debian.org/~gwolf/dc26_ksp/&quot;&gt;keysigning
map&lt;/a&gt;. Are you a part of the
listing?&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;
        &lt;p&gt;If you are not there, log in to the DebConf26 management system and
edit the &lt;a href=&quot;https://debconf26.debconf.org/register/step-3&quot;&gt;Personal
Information&lt;/a&gt; section of
your profile. Make sure you submit your OpenPGP key fingerprint.&lt;/p&gt;
      &lt;/li&gt;
      &lt;li&gt;
        &lt;p&gt;Make sure your key is available in the keyserver network. They should
basically be equivalent and interoperate, but in any case — my scripts
will try to find your key at &lt;a&gt;pgpkeys.eu&lt;/a&gt;,
&lt;a&gt;keys.openpgp.org&lt;/a&gt;,
&lt;a&gt;keyserver.computer42.org&lt;/a&gt;,
&lt;a&gt;keyserver.ubuntu.com&lt;/a&gt;,
&lt;a&gt;keyring.debian.org&lt;/a&gt;,
&lt;a&gt;pgp.surf.nl&lt;/a&gt;, &lt;a&gt;pgp.pm&lt;/a&gt;,
&lt;a&gt;pgp.mit.edu&lt;/a&gt;, &lt;a&gt;the.earth.li&lt;/a&gt;.&lt;/p&gt;
      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Make sure your name is readable and matches what you want others to
sign. If it does not, edit your key and upload it &lt;em&gt;now&lt;/em&gt;!&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Remember that, &lt;a href=&quot;https://debconf26.debconf.org/about/ksp/&quot;&gt;as announced&lt;/a&gt;,
the deadline for the final list is on &lt;strong&gt;Thursday, 2026.07.16, 09:00 GMT-3
(Argentinian time).&lt;/strong&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-14T21:23:21+00:00</dc:date>
	<dc:creator>Gunnar Wolf</dc:creator>
</item> 
<item rdf:about="https://blog.freesources.org//posts/2026/07/zed-xdebug/">
	<title>Jonas Meurer: zed-xdebug</title>
	<link>https://blog.freesources.org//posts/2026/07/zed-xdebug/</link>
     <content:encoded>&lt;h1 id=&quot;Nextcloud_PHP_debugging_with_Xdebug_in_Zed_editor&quot;&gt;Nextcloud PHP debugging with Xdebug in Zed editor&lt;/h1&gt;

&lt;p&gt;I started to switch from PhpStorm to Zed as IDE recently as Zed is open source
and has a much smaller footprint and is more slick than PhpStorm.&lt;/p&gt;

&lt;p&gt;One thing that I didn&#39;t get running immediately was Xdebug integration, so I did
a bit of research and asked Claude for help. Here&#39;s a quick writeup of how to
get it running.&lt;/p&gt;

&lt;p&gt;I have Zed installed as Flatpak on a Debian Trixie host system.&lt;/p&gt;

&lt;p&gt;The PHP process runs in a &lt;a href=&quot;https://github.com/juliusknorr/nextcloud-docker-dev/&quot;&gt;nextcloud-docker-dev&lt;/a&gt;
Docker container.&lt;/p&gt;

&lt;h2 id=&quot;Install_Zed_and_configure_debugging_there&quot;&gt;Install Zed and configure debugging there&lt;/h2&gt;

&lt;p&gt;Install Zed: &lt;code&gt;flatpak install flathub dev.zed.Zed&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;In Zed: open the Extensions view and install PHP.&lt;/p&gt;

&lt;p&gt;Configure the debugger:&lt;/p&gt;

&lt;p&gt;Create &lt;code&gt;~/.var/app/dev.zed.Zed/config/zed/debug.json&lt;/code&gt;:&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;json&quot;&gt;[
  {
    &quot;label&quot;: &quot;PHP: Listen to Xdebug&quot;,
    &quot;adapter&quot;: &quot;Xdebug&quot;,
    &quot;request&quot;: &quot;launch&quot;,
    &quot;port&quot;: 9003,
    &quot;pathMappings&quot;: {
      &quot;/var/www/html&quot;:             &quot;/home/&amp;lt;user&amp;gt;/devel/nextcloud/server&quot;,
      &quot;/var/www/html/apps-extra&quot;:  &quot;/home/&amp;lt;user&amp;gt;/devel/nextcloud/server/apps-extra&quot;,
      &quot;/var/www/html/apps-shared&quot;: &quot;/home/&amp;lt;user&amp;gt;/devel/nextcloud/apps-shared&quot;
    }
  }
]
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Add one entry per bind-mounted app directory.&lt;/p&gt;

&lt;p&gt;After creating the file, restart Zed.&lt;/p&gt;

&lt;p&gt;Inside Zed, select &quot;debugger: start&quot; from command palette and then &quot;PHP: Listen to Xdebug&quot;.&lt;/p&gt;

&lt;p&gt;Verify Zed is listening. Running &lt;code&gt;ss -tlnp | grep 9003&lt;/code&gt; on the host should show &lt;code&gt;*:9003&lt;/code&gt; with Zed as the process.&lt;/p&gt;

&lt;h2 id=&quot;Configure_Xdebug_inside_the_container&quot;&gt;Configure Xdebug inside the container&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;/usr/local/etc/php/conf.d/xdebug.ini&lt;/code&gt;:&lt;/p&gt;

&lt;pre&gt;&lt;code class=&quot;ini&quot;&gt;xdebug.mode = debug
xdebug.idekey = PHPSTORM
xdebug.trace_output_name=trace.%R.%u
xdebug.profiler_output_name=profile.%R.%u
xdebug.output_dir=/shared/xdebug

xdebug.log = /var/log/xdebug.log
xdebug.log_level = 3

; Try to discover the client host, otherwise fall back to the docker host
xdebug.discover_client_host=true
xdebug.client_host=host.docker.internal

; When you cannot specify a trigger, use &quot;xdebug.start_with_request = yes&quot; to autostart debugging for all requests
; https://xdebug.org/docs/all_settings#start_with_request
xdebug.start_with_request = trigger

; Set xdebug.mode trace to use this
; More details at https://derickrethans.nl/flamboyant-flamegraphs.html
xdebug.trace_format=3
xdebug.trace_output_name=xdebug.%R.%u
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Apply changes by restarting apache in the container: &lt;code&gt;apache2ctl -k graceful&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Notes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;host.docker.internal&lt;/code&gt; resolves on Linux Docker only if the container was started with &lt;code&gt;--add-host=host.docker.internal:host-gateway&lt;/code&gt; (nextcloud-docker-dev already does this).&lt;/li&gt;
&lt;li&gt;&lt;code&gt;discover_client_host = true&lt;/code&gt; makes xdebug follow &lt;code&gt;X-Forwarded-For&lt;/code&gt; - useful behind Nextcloud&#39;s dev reverse proxy.&lt;/li&gt;
&lt;/ul&gt;


&lt;h2 id=&quot;Test_xdebug_with_a_PHP_command_inside_the_container&quot;&gt;Test xdebug with a PHP command inside the container&lt;/h2&gt;

&lt;p&gt;Run &lt;code&gt;XDEBUG_SESSION=PHPSTORM php occ status&lt;/code&gt; inside the container and check &lt;code&gt;/var/log/xdebug.log&lt;/code&gt;.&lt;/p&gt;

&lt;h2 id=&quot;Install_the_browser_extension&quot;&gt;Install the browser extension&lt;/h2&gt;

&lt;p&gt;Install Xdebug Helper (Firefox/Chrome). In its preferences, set the IDE Key to PhpStorm. It will set the &lt;code&gt;XDEBUG_SESSION&lt;/code&gt; cookie when toggled to Debug.&lt;/p&gt;

&lt;p&gt;Click the Xdebug Helper icon in the browser and set it to Debug.&lt;/p&gt;

&lt;h2 id=&quot;Test_Xdebug_with_browser_extension&quot;&gt;Test Xdebug with browser extension&lt;/h2&gt;

&lt;p&gt;Load the URL that exercises the code path with the breakpoint. Zed should stop the code exection at the breakpoint.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-14T10:46:20+00:00</dc:date>
	<dc:creator>mejo roaming</dc:creator>
</item> 
<item rdf:about="hatenablog://entry/14945776032052860672">
	<title>Kentaro Hayashi: Try to build Mozc with Bazel 7.7.1</title>
	<link>https://kenhys.hatenablog.jp/entry/2026/07/12/231009</link>
     <content:encoded>&lt;h2 id=&quot;Introduction&quot;&gt;Introduction&lt;/h2&gt;

&lt;p&gt;Recently, I&#39;ve got a chance to try building Mozc (Most famous Japanese input method editor) with Bazel.&lt;/p&gt;

&lt;p&gt;As you know, recently newer Bazel related packages were landed into
debian/unstable.
Then now I&#39;m planning to update Mozc from 2.29.5160.102
to 3.33.6133.&lt;/p&gt;

&lt;h2 id=&quot;Background-story-about-Mozc-and-Debian&quot;&gt;Background story about Mozc and Debian&lt;/h2&gt;

&lt;p&gt;The upstream of Mozc had released 3.34.6239, but on Debian,
we stick to Mozc 2.29.5160.102.&lt;/p&gt;

&lt;p&gt;Mozc requires newer Bazel but we only had Bazel 4.2.3 at that time on Debian, so even though the upstream of Mozc switched from GYP to Bazel,
we had patched Mozc with GYP based package.&lt;/p&gt;

&lt;p&gt;We even did make an effort to restore build options that had been already removed. :-(
And needed to migrate from GTK2 renderer to GTK3 renderer.&lt;/p&gt;

&lt;p&gt;That is why the version of Mozc is diverged from upstream on Debian.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;2.29.5160.102 (Now on Debian)&lt;/li&gt;
&lt;li&gt;2.29.5268.102&lt;/li&gt;
&lt;li&gt;2.29.5374.102&lt;/li&gt;
&lt;li&gt;2.29.5544.102&lt;/li&gt;
&lt;li&gt;2.30.5544.102&lt;/li&gt;
&lt;li&gt;2.31.5712.102&lt;/li&gt;
&lt;li&gt;2.31.5851.102&lt;/li&gt;
&lt;li&gt;2.32.5994.102&lt;/li&gt;
&lt;li&gt;3.33.6089&lt;/li&gt;
&lt;li&gt;3.33.6133 (Target to upgrade for)&lt;/li&gt;
&lt;li&gt;3.34.6239&lt;/li&gt;
&lt;/ul&gt;


&lt;h2 id=&quot;How-to-switch-from-GYP-to-Bazel&quot;&gt;How to switch from GYP to Bazel?&lt;/h2&gt;

&lt;p&gt;At first, we needed to decide what Mozc version to work with it.&lt;/p&gt;

&lt;p&gt;Now latest version of Mozc is 3.34.x, but it requires Bazel 9.x.
Please recall that Bazel 7.7.1 was introduced Debian/unstable.
And more, newer dependency libraries are required.&lt;/p&gt;

&lt;p&gt;You might feel that target version (3.33.6133) is too high from 2.29.5160.102,
but if we upgrade to more older Mozc, it means that it
requires to backport Mozc to older libabsl compatible codes and so on.&lt;/p&gt;

&lt;p&gt;That is why Mozc 3.33.6133 was chosen.&lt;/p&gt;

&lt;p&gt;Even once the target version has been decided, you can&#39;t let your guard down.&lt;/p&gt;

&lt;p&gt;There are many technical tasks to solve.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Revisit patch sets to apply&lt;/li&gt;
&lt;li&gt;Porting uim mozc patch and fix FTBFS&lt;/li&gt;
&lt;li&gt;Porting fcitx5 mozc patch and fix FTBFS&lt;/li&gt;
&lt;li&gt;Fix src/third_party vendoring&lt;/li&gt;
&lt;li&gt;Switch from GYP to Bazel build systems&lt;/li&gt;
&lt;li&gt;...&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;At least, it will likely require several rounds of testing in the
Debian experimental.&lt;/p&gt;

&lt;h2 id=&quot;Conclusion&quot;&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;Currently, &lt;code&gt;gbp buildpackge&lt;/code&gt; has succeeded finally on local machine,
but need to tidy and cleanup stuffs.&lt;/p&gt;

&lt;p&gt;I didn&#39;t know packaging with Bazel best practice yet, to remove many third party vendor/ bundles, I&#39;ve found that it requires pile of patch to eliminate them.&lt;/p&gt;

&lt;p&gt;In the current version of Debian, as a one of build system, further work — such as support from debhelper -
will be needed.&lt;/p&gt;

&lt;p&gt;I&#39;ll file working progress on &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1085173&quot;&gt;#1085173&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-12T14:10:09+00:00</dc:date>
	<dc:creator>Kentaro Hayashi</dc:creator>
</item> 
<item rdf:about="tag:copyninja.in,2026-07-21:/blog/debvulns-exporter.html">
	<title>Vasudev Kamath: Releasing debvulns-exporter: Prometheus exporter for Debian System Vulnerabilities</title>
	<link>https://copyninja.in/blog/debvulns-exporter.html</link>
     <content:encoded>&lt;p&gt;Following up on my previous &lt;a class=&quot;reference external&quot; href=&quot;https://copyninja.in/blog/debvulns-cli.html&quot;&gt;post&lt;/a&gt;, I am releasing
&lt;a class=&quot;reference external&quot; href=&quot;https://pypi.org/project/debvulns/&quot;&gt;debvulns-exporter&lt;/a&gt;, a Prometheus exporter
for tracking Debian system vulnerabilities. The underlying vulnerability
analysis logic remains identical to the  previously released MCP server and CLI
utility.&lt;/p&gt;
&lt;div class=&quot;section&quot; id=&quot;why-an-exporter&quot;&gt;
&lt;h2&gt;Why an Exporter?&lt;/h2&gt;
&lt;p&gt;In my engineering workflows, I frequently deal with Debian and vulnerability
management. Most enterprise environments rely on commercial, paid vulnerability
platforms like Tenable or Rapid7. While these platforms provide extensive
feature sets, I noticed a distinct lack of open-source tools tailored for this
specific pipeline. While &lt;cite&gt;debsecan&lt;/cite&gt; exists, it lacks a structured, parseable
format suitable for building dashboards aimed at management consumption. What
started as an experimental MCP server for learning purposes evolved into a
practical question: why not convert it into a Prometheus exporter? Given that
Prometheus is the de facto standard metrics platform across the industry, this
architecture was the logical next step.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;section&quot; id=&quot;design-and-exported-metrics&quot;&gt;
&lt;h2&gt;Design and Exported Metrics&lt;/h2&gt;
&lt;p&gt;The exporter is implemented as a native Prometheus exporter utilizing the
&lt;cite&gt;prometheus-client&lt;/cite&gt; library. It operates using two threads: one handles fetching
the vulnerability data, parsing EPSS feeds, and cross-referencing installed
packages to identify local vulnerabilities; the second handles serving the
metrics endpoint. The full architecture details and metrics specifications can
be found in the &lt;a class=&quot;reference external&quot; href=&quot;https://github.com/copyninja/debsecan-mcp/blob/main/docs/prometheus_exporter_design.md&quot;&gt;design doc&lt;/a&gt;.
The specification was drafted during a technical brainstorming session with
&lt;em&gt;Claude 4.6 Sonnet&lt;/em&gt; on &lt;em&gt;Antigravity&lt;/em&gt; prior to writing the implementation.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;section&quot; id=&quot;testing-and-dashboarding&quot;&gt;
&lt;h2&gt;Testing and Dashboarding&lt;/h2&gt;
&lt;p&gt;To validate the exporter, I spun up older &lt;em&gt;Debian 11&lt;/em&gt; and &lt;em&gt;Debian 12&lt;/em&gt; cloud
images sourced from the &lt;a class=&quot;reference external&quot; href=&quot;https://cloud.debian.org/images/cloud/&quot;&gt;Debian Cloud team&lt;/a&gt;. The older image was intentionally
selected to guarantee a standard baseline of unpatched vulnerabilities for
testing. The local evaluation topology is structured as shown below:&lt;/p&gt;
&lt;img alt=&quot;&quot; src=&quot;https://copyninja.in/images/debvulns-exporter-setup.png&quot; /&gt;
&lt;p&gt;Rather than constructing the Grafana dashboard from scratch, I used Claude 4.6
Sonnet via Antigravity to generate the layout configuration. The generated
dashboard for the local testbed functions effectively:&lt;/p&gt;
&lt;img alt=&quot;&quot; src=&quot;https://copyninja.in/images/debvulns-exporter-dashboard.png&quot; /&gt;
&lt;p&gt;The complete, ready-to-import Grafana dashboard configuration is included
directly in the &lt;cite&gt;debvulns&lt;/cite&gt; &lt;a class=&quot;reference external&quot; href=&quot;https://github.com/copyninja/debsecan-mcp/blob/main/contrib/grafana/debvulns-dashboard.json&quot;&gt;source code&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;section&quot; id=&quot;renaming-the-project&quot;&gt;
&lt;h2&gt;Renaming the project&lt;/h2&gt;
&lt;p&gt;To prevent namespace conflicts and confusion with the native &lt;cite&gt;debsecan&lt;/cite&gt; utility
in Debian, I have unified the ecosystem under the &lt;em&gt;debvulns&lt;/em&gt; moniker. The core
CLI is named &lt;cite&gt;debvulns&lt;/cite&gt;, the exporter is &lt;cite&gt;debvulns-exporter&lt;/cite&gt;, and the MCP
component is &lt;cite&gt;debvulns-mcp&lt;/cite&gt;. The migration release has been published to &lt;a class=&quot;reference external&quot; href=&quot;https://pypi.org/project/debsecan-mcp/&quot;&gt;PyPI&lt;/a&gt;, and the new consolidated repository
is active at &lt;a class=&quot;reference external&quot; href=&quot;https://pypi.org/project/debvulns/&quot;&gt;debvulns&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;section&quot; id=&quot;conclusion&quot;&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;While this began as a personal utility to fill a niche tool gap, I expect it
will be useful for others managing Debian infrastructure at scale. My next
objective is to formalize Debian packaging for both the CLI and the exporter.
The MCP component will likely remain available as an independent artifact. Until
then, happy hacking.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Note: As a core design choice, `debvulns` still uses native `debsecan` as its
ground-truth standard. The tool continuously cross-verifies its output against
`debsecan` to ensure perfect functional parity and data consistency.&lt;/em&gt;&lt;/p&gt;
&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-12T11:30:25+00:00</dc:date>
	<dc:creator>copyninja</dc:creator>
</item> 

</rdf:RDF>
