<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss version="2.0">

<channel>
	<title>ExcitingAds! Planet Debian</title>
	<link>https://planet.debian.org/</link>
	<language>en</language>
	<description>Planet Debian!</description>


<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
	<title>Dirk Eddelbuettel: linl 0.0.6 on CRAN: Maintenance</title>
	<guid>http://dirk.eddelbuettel.com/blog/2026/08/26#linl_0.0.6</guid>
	<link>http://dirk.eddelbuettel.com/blog/2026/08/26#linl_0.0.6</link>
     <description>  &lt;img src="http://planet.debian.org/heads/dirk.png" width="65" height="90" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;A new release of our &lt;a href="https://github.com/eddelbuettel/linl"&gt;linl package&lt;/a&gt; for writing
LaTeX letters with (R)markdown is now on CRAN. &lt;a href="https://github.com/eddelbuettel/linl"&gt;linl&lt;/a&gt; makes it easy to
write letters in markdown, with some extra bells and whistles thanks to
some cleverness chiefly by &lt;a href="http://aaronwolen.com/"&gt;Aaron&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This version is mostly maintenance: updates to the continuous
integration setup, as well as updates to packaging including use of
Authors@R in DESCRIPTION. No functional changes, no new code, or new
features.&lt;/p&gt;
&lt;p&gt;The NEWS entry follows:&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id="changes-in-linl-version-0.0.6-2026-08-26"&gt;Changes in linl
version 0.0.6 (2026-08-26)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Several updates to continuous integration and testing&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Switch to Authors@R in DESCRIPTION&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of &lt;a href="https://dirk.eddelbuettel.com/cranberries/"&gt;CRANberries&lt;/a&gt;, there
is a comparison to &lt;a href="https://dirk.eddelbuettel.com/cranberries/2026/08/26#linl_0.0.6"&gt;the
previous release&lt;/a&gt;. For questions or comments use the &lt;a href="https://github.com/eddelbuettel/linl/issues"&gt;issue tracker&lt;/a&gt; off
the &lt;a href="https://github.com/eddelbuettel/linl"&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;
&lt;p style="font-size: 80%; font-style: italic;"&gt;
This post by &lt;a href="https://dirk.eddelbuettel.com"&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href="https://dirk.eddelbuettel.com/blog/"&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href="https://github.com/sponsors/eddelbuettel"&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt; </description> 
	<pubDate>Wed, 26 Aug 2026 18:06:00 +0000</pubDate>

</item> 
<item>
	<title>Rapha&amp;#235;l Hertzog: Debian’s General Resolution on AI and LLM</title>
	<guid>https://raphaelhertzog.com/?p=4075</guid>
	<link>https://raphaelhertzog.com/2026/08/26/debians-general-resolution-on-ai-and-llm/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/hertzog.png" width="65" height="93" alt="" align="right" style="float: right;"&gt;  &lt;p class="wp-block-paragraph"&gt;As a Debian developer, I have had to cast a vote for the General Resolution named &lt;a href="https://www.debian.org/vote/2026/vote_002"&gt;LLM usage in Debian&lt;/a&gt; (&lt;a href="https://vote.debian.org/~secretary/gr_llm/"&gt;progress report here&lt;/a&gt;). This was not an easy task for me…&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;It’s a good thing that the vote is secret so that people are not scared of voting according to their own beliefs. I have Debian friends on the whole spectrum of opinions that are represented here, and I hesitated twice on sharing my own thoughts for fear of alienating my relationship with them. But in the end, we all make efforts to respect the opinions of those who are not thinking like us, and it’s precisely that willingness to work together towards a solution that is acceptable by the majority that makes Debian so strong. So here’s the train of thoughts that I followed to cast my vote.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;The difficulty for me was to reconcile the political statement that I want to make and my desire for this vote to not be (too) divisive for the Debian community, and to make sure we are not putting off newcomers with choices that might be hard to stand by in the long term.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;So let’s be clear : if I had a magical wand to make AI and LLM disappear, I would use it for that purpose, since at this point in time I don’t believe that the benefits outweigh the costs that the AI race  is inflicting on us. If I were a political decision-maker, I would forbid the construction of new data centers unless they also build renewable energy infrastructure to cover for their additional energy consumption. I would also legislate so that AI companies have to document what material they used to train their models, and I would forbid scraping for that purpose, and build ways for those companies to buy copies of properly-sourced training data. That is to say, I don’t like the way LLM are built by the players in that market, I’m pretty scared of the ecological impact of what those players are doing, and I’m certainly worried about the long term effect that LLM will have on society as a whole.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;Nevertheless what brought me to Debian is the ability to experiment and contribute to something useful with cool technologies, and as a computer scientist, the potential of LLM done right is hard to ignore. Given what we have seen already, I expect that LLM will empower (a part of) the next generation to learn IT, computing and even Debian packaging. Completely refusing the use of LLM is likely to make it harder for us to attract new contributors. In fact, we have already seen people inside Debian that would likely stop contributing if they are now forbidden to use LLM. I know there are likely others that will quit Debian if we accept it too, but I hope we can find a middle-ground where such persons can decide that LLM are not welcome in the small corner of Debian that they are in charge of…&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;In the end, I decided that answering clearly the question “Shall we accept LLM contributions ?” was more important than making the political statement about the current state of affairs in the AI landscape, both because I believe that Debian statements have a negligible impact on policy-makers, and because historically Debian has grown by staying close to technical excellence and relatively far from politics, except when it comes to the way we handle people. And as much as I care about climate change, I don’t see how bringing this up in the context of a Debian statement is helping its cause.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;More concretely, it gives the following ranking (in decreasing order of importance):&lt;/p&gt;



&lt;ul class="wp-block-list"&gt;
&lt;li&gt;B, D: those two choices are the clearest to express “Yes we should accept LLM contributions” and still acknowledge concerns about the way AI is built today&lt;/li&gt;



&lt;li&gt;F, H: those two choices do not forbid LLM usage but discourage their use and clearly voice the concerns&lt;/li&gt;



&lt;li&gt;E: this choice is basically the statu-quo and fails to acknowledge the concerns, but it does not forbid LLM usage&lt;/li&gt;



&lt;li&gt;None of the above&lt;/li&gt;



&lt;li&gt;G, A, C: those choices forbid LLM usage in various ways&lt;/li&gt;
&lt;/ul&gt;



&lt;p class="wp-block-paragraph"&gt;I don’t know what option will win, but assuming that LLM-assisted contributions are allowed, I believe that it would be helpful to have further statements to clarify a few things:&lt;/p&gt;



&lt;ul class="wp-block-list"&gt;
&lt;li&gt;Even if Debian as a whole doesn’t want to ban LLM-assisted contributions, each maintainer or each team shall be free to forbid LLM assisted contributions in the parts of Debian that they are maintaining&lt;/li&gt;



&lt;li&gt;We should discourage usage of LLM provided by players with unethical behaviors (not sure if there are good players but well…)&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt; </description> 
	<pubDate>Wed, 26 Aug 2026 16:04:10 +0000</pubDate>

</item> 
<item>
	<title>Ian Jackson: Debian LLM GR - Summary of the options</title>
	<guid>tag:dreamwidth.org,2009-05-21:377446:20998</guid>
	<link>https://diziet.dreamwidth.org/20998.html</link>
     <description>  &lt;ul&gt;&lt;li&gt;&lt;a href="https://diziet.dreamwidth.org/data/atom#introduction"&gt;Introduction&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a href="https://diziet.dreamwidth.org/data/atom#a-plea-to-the-undecided-voter"&gt;A plea to the undecided voter&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a href="https://diziet.dreamwidth.org/data/atom#table"&gt;Table&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a href="https://diziet.dreamwidth.org/data/atom#notes"&gt;Notes&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;Debian LLM GR - Summary of the options
&lt;/p&gt;&lt;h1&gt;&lt;a name="introduction"&gt;Introduction&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;LLMs have finally made it to the ultimate stage of Debian’s governance processes, a General Resolution of all the project’s full governing members (DDs).
&lt;/p&gt;&lt;p&gt;There are a lot of options on the ballot, and they all have a different structure and approach the question in a different way. It can be hard to see the wood for the trees. I have made a summary table to try to capture the main differences, both in effect, and sentiment.

&lt;a name="cutid1"&gt;&lt;/a&gt;
&lt;/p&gt;&lt;h1&gt;&lt;a name="a-plea-to-the-undecided-voter"&gt;A plea to the undecided voter&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;Suspending briefly my attempt to be neutral:
&lt;/p&gt;&lt;p&gt;Before voting, I encourage you to read the passionate rationales in options H and A, or at least the summary in my option C.
&lt;/p&gt;&lt;p&gt;Few of the LLM defences in the discussion threads, and none of the LLM-positive proposals, provide answers to any of these profound ethical concerns, many of which ought individually to be a deal-breaker. Instead, these crucial questions are simply dismissed or even ignored.
&lt;/p&gt;&lt;p&gt;Some will tell you we should “keep politics out of software” but as we can see in the world around us, software is political - now more than ever. Debian’s mission is a highly political one: developing a fully-free operating system, and defending its freeness as we do, is far from neutral!
&lt;/p&gt;&lt;p&gt;And of course many of LLMs’ harms affect Debian directly.
&lt;/p&gt;&lt;h1&gt;&lt;a name="table"&gt;Table&lt;/a&gt;&lt;/h1&gt;
&lt;table rules="all"&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;th&gt;&lt;a href="https://www.debian.org/vote/2026/vote_002#texta"&gt;A&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.debian.org/vote/2026/vote_002#textg"&gt;G&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.debian.org/vote/2026/vote_002#textc"&gt;C&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.debian.org/vote/2026/vote_002#texth"&gt;H&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.debian.org/vote/2026/vote_002#textf"&gt;F&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.debian.org/vote/2026/vote_002#textd"&gt;D&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.debian.org/vote/2026/vote_002#textb"&gt;B&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.debian.org/vote/2026/vote_002#texte"&gt;E&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;&lt;th&gt; LLM harms &lt;/th&gt;&lt;td&gt; Robustly discussed &lt;/td&gt;&lt;td&gt; Discussed &lt;/td&gt;&lt;td&gt; Robustly summarised &lt;/td&gt;&lt;td&gt; Robustly discussed; especially re climate &lt;/td&gt;&lt;td&gt; Summarised &lt;/td&gt;&lt;td&gt; Accepted as inevitable &lt;/td&gt;&lt;td&gt; Disregarded [1] &lt;/td&gt;&lt;td&gt; Ignored &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt; Direct contributions of LLM-generated code &lt;/th&gt;&lt;td&gt; Forbidden &lt;/td&gt;&lt;td&gt; Forbidden &lt;/td&gt;&lt;td&gt; Strongly discouraged &lt;/td&gt;&lt;td&gt; Strongly discouraged &lt;/td&gt;&lt;td&gt; Discouraged &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt; Direct use of LLM output in communications (bugs, mailing lists, etc.) &lt;/th&gt;&lt;td&gt; Forbidden &lt;/td&gt;&lt;td&gt; Forbidden &lt;/td&gt;&lt;td&gt; Forbidden (with possible exceptions) &lt;/td&gt;&lt;td&gt; Strongly discouraged &lt;/td&gt;&lt;td&gt; Discouraged &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt; LLM use where LLM output does not end up in the code/message &lt;/th&gt;&lt;td&gt; Forbidden &lt;/td&gt;&lt;td&gt; No position, so permitted &lt;/td&gt;&lt;td&gt; Strongly discouraged &lt;/td&gt;&lt;td&gt; Strongly discouraged &lt;/td&gt;&lt;td&gt; Discouraged &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;td&gt; Permitted &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt; Disclosure of LLM use &lt;/th&gt;&lt;td&gt; LLM use forbidden &lt;/td&gt;&lt;td&gt; LLM use largely forbidden, no further disclosure requirement &lt;/td&gt;&lt;td&gt; Disclosure required &lt;/td&gt;&lt;td&gt; Disclosure encouraged &lt;/td&gt;&lt;td&gt; Disclosure encouraged &lt;/td&gt;&lt;td&gt; Disclosure required &lt;/td&gt;&lt;td&gt; Disclosure required &lt;/td&gt;&lt;td&gt; Undisclosed LLM use is OK &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt; Use of LLMs by upstreams &lt;/th&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt; Condemned &lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt; “Not recommended” &lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt; Positive statements about LLMs &lt;/th&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt; “Here to stay” &lt;/td&gt;&lt;td&gt; Moderate &lt;/td&gt;&lt;td&gt; Strong &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h1&gt;&lt;a name="notes"&gt;Notes&lt;/a&gt;&lt;/h1&gt;
&lt;h2&gt;&lt;a name="ordering"&gt;Ordering&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;I have tried to present the options in semantic order, with most LLM-negative proposals to the left, and the most LLM-positive to the right.
&lt;/p&gt;&lt;p&gt;I have not quoted the one-line titles for the options. These have generally been provided by the proponents of each option, and, unfortunately, some of them are IMO quite misleading.
&lt;/p&gt;&lt;p&gt;Note that, unfortunately, the voting software likes to assign numbers to options but also to preferences. Be mindful of this possible confusion when casting your vote. For clarity I quote only the option letters.
&lt;/p&gt;&lt;h2&gt;&lt;a name="upstream-llm-code-contributions"&gt;Upstream LLM code contributions&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Some of the proposals acknowledge the uncertain legal status of LLM output. But all of them implicitly or explicitly assume that LLM output is or can be DFSG free. So none of the proposals forbid upstream projects with LLM-generated contents.
&lt;/p&gt;&lt;p&gt;None of the proposals would require us to go back to pre-LLM versions of the upstream projects we use, and attempt to fork and maintain them. I very much think there is room in the world for people to try to do that, but I don’t think the Debian project can be that effort.
&lt;/p&gt;&lt;p&gt;Given that the conclusions are the same in each case, whether the matter is discussed does not seem to me to be a significant difference. I have therefore not included a column for it.
&lt;/p&gt;&lt;h2&gt;&lt;a name="ability-of-individual-teams-to-set-their-own-rules"&gt;Ability of individual teams to set their own rules&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;My proposal has a specific paragraph (7) explicitly permitting teams to set a “no LLM” policy. The other proposals do not discuss this point specifically. During the discussion, it seemed that most participants agreed that even options which explicitly permit LLM use generally do not prevent a team from setting its own more restrictive LLM policy.
&lt;/p&gt;&lt;p&gt;I have therefore not tabulated this aspect.
&lt;/p&gt;&lt;h2&gt;&lt;a name="exceptions-and-nuances"&gt;Exceptions and nuances&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Few of the permissive texts are absolute or unconditional. To summarise I have necessarily left out some nuance.
&lt;/p&gt;&lt;p&gt;So for example when an entry says “permitted”, that generally means “permitted with conditions which are believed by LLM users to be readily satisfiable” (for example, DFSG-compatibility - see above).
&lt;/p&gt;&lt;h2&gt;&lt;a name="footnote-re-proposal-b"&gt;[1] Footnote re proposal B&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Proposal B does mention that there are “concerns” about LLM use. But it fails to make an explicit statement about whether these concerns are justified.
&lt;/p&gt;&lt;p&gt;It then proceeds exactly as if they are not justified. IMO “disregarded” is a relatively mild term for such a rhetorical technique.
&lt;/p&gt;&lt;hr /&gt;
&lt;address&gt;
Edited 2026-08-18 09:02 UTC to make the proposal letters in the table be links; 2026-08-26 09:11 UTC to fix typos.&lt;/address&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;img alt="comment count unavailable" height="12" src="https://www.dreamwidth.org/tools/commentcount?user=diziet&amp;amp;ditemid=20998" style="vertical-align: middle;" width="30" /&gt; comments </description> 
	<pubDate>Wed, 26 Aug 2026 09:11:35 +0000</pubDate>

</item> 
<item>
	<title>Matthew Garrett: Hooking an old magicJack adapter to modern Asterisk</title>
	<guid>https://codon.org.uk/~mjg59/blog/p/hooking-an-old-magicjack-adapter-to-modern-asterisk/</guid>
	<link>https://codon.org.uk/~mjg59/blog/p/hooking-an-old-magicjack-adapter-to-modern-asterisk/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/mjg59.png" width="69" height="85" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;I’m on a VPN setup with several friends that, obviously, includes a VoIP
network. I also have an old
&lt;a class="link" href="https://en.wikipedia.org/wiki/MagicJack" rel="noopener" target="_blank"&gt;magicJack&lt;/a&gt; adapter and a deep and
abiding need to use hardware in ways I should not. There was obvious synergy
here.&lt;/p&gt;
&lt;p&gt;Plugging in the magicJack gives a USB vendor id of 0x06e6, which belonged to
a company called TigerJet who made a range of chips for hooking up phones to
computers, either via USB or PCI. Some more digging suggested that it was a
580 part, and someone had conveniently
&lt;a class="link" href="https://www.mediafire.com/file/a3ocbckd7cobr7k/TigerJetCode.tar.gz" rel="noopener" target="_blank"&gt;uploaded&lt;/a&gt;
some reference code and datasheets, so figuring out how to talk to the chip
wasn’t terribly difficult. Once configured it simply sends HID events
whenever a user hits a phone key or changes the hook state, and otherwise
exposes a USB audio device that can be spoken to using the stock kernel
driver. It also has the ability to generate dial tone and assert ring
signal, giving a full traditional phone experience.&lt;/p&gt;
&lt;p&gt;So you’d think this would be a super easy project, but I’d made things
harder for myself by deciding I wanted to tie directly into Asterisk rather
than just smashing an existing SIP stack onto the device. Asterisk uses
&lt;a class="link" href="https://docs.asterisk.org/Fundamentals/Key-Concepts/Channels/" rel="noopener" target="_blank"&gt;channels&lt;/a&gt; to
talk to devices, and channels end up as compiled C code that Asterisk can
load dynamically. I didn’t want to have to deal with the pain of compiling
stuff and matching ABIs and everything so writing a new channel from scratch
was unappealing. Fortunately, the &lt;a class="link" href="https://docs.asterisk.org/Configuration/Channel-Drivers/WebSocket/" rel="noopener" target="_blank"&gt;websocket
channel&lt;/a&gt;
is available in recent versions of Asterisk and provides a convenient way to
get audio in and out, but that still leaves the job of handling incoming and
outgoing calls. That’s handled with the &lt;a class="link" href="https://docs.asterisk.org/Configuration/Interfaces/Asterisk-REST-Interface-ARI/" rel="noopener" target="_blank"&gt;Asterisk Rest
Interface&lt;/a&gt;,
which can initiate a call or respond to an incoming one and bridge various
channels together to produce a bidirectional audio stream. There’s a
convenient &lt;a class="link" href="https://pypi.org/project/asyncari/" rel="noopener" target="_blank"&gt;async Python library&lt;/a&gt; that
handles the low level protocol.&lt;/p&gt;
&lt;p&gt;Code for all this is
&lt;a class="link" href="https://tangled.org/mjg59.eicar-test-file.zip/magicjack-asterisk/" rel="noopener" target="_blank"&gt;here&lt;/a&gt;&lt;sup id="fnref:1"&gt;&lt;a class="footnote-ref" href="https://codon.org.uk/~mjg59/blog/index.xml#fn:1"&gt;1&lt;/a&gt;&lt;/sup&gt;,
and works for my use case, but I should really abstract out the asterisk
side and the magicJack side to make it easier to adapt to other
devices. That’s a job for later, though. For now, you get this:&lt;/p&gt;
&lt;div class="video-wrapper"&gt;
    &lt;video controls="controls" width="600"&gt;
      &lt;source src="https://codon.org.uk/~mjg59/tmp/phonecall.mp4" /&gt;
        &lt;p&gt;
            Your browser doesn't support HTML5 video. Here is a
            &lt;a href="https://codon.org.uk/~mjg59/tmp/phonecall.mp4"&gt;link to the video&lt;/a&gt; instead.
        &lt;/p&gt;
    &lt;/video&gt;
&lt;/div&gt;

&lt;div class="footnotes"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:1"&gt;
&lt;p&gt;This has also been an excuse for me to figure out how to make &lt;a class="link" href="https://tangled.org" rel="noopener" target="_blank"&gt;Tangled&lt;/a&gt; work, which I’ll write about at some later point. But self-hosted git repo with a convenient collaboration plane! &lt;a class="footnote-backref" href="https://codon.org.uk/~mjg59/blog/index.xml#fnref:1"&gt;↩︎&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Wed, 26 Aug 2026 04:04:17 +0000</pubDate>

</item> 
<item>
	<title>Tim Retout: TF RAID</title>
	<guid>https://retout.co.uk/2026/08/25/tf-raid/</guid>
	<link>https://retout.co.uk/2026/08/25/tf-raid/</link>
     <description>  &lt;p&gt;My hobby: following GOV.UK to look for interesting announcements.
Today was an update on the MOD’s &lt;a href="https://www.gov.uk/guidance/rapid-ai-delivery-taskforce-tf-raid"&gt;Rapid AI Delivery
Taskforce&lt;/a&gt;
which was &lt;a href="https://www.gov.uk/government/news/new-taskforce-to-put-ai-on-the-uks-frontline"&gt;previously announced in June during London Tech
Week&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I like this line: “Success is measured in operational advantage delivered, not technology demonstrated.”  To me it recalls “Working software is the primary measure of progress” from &lt;a href="https://agilemanifesto.org/principles.html"&gt;Principles behind the Agile Manifesto&lt;/a&gt; – if you understand “working” to mean “working in production”. Which I do.&lt;/p&gt;
&lt;p&gt;For anyone interested in suggesting ideas to the taskforce, the four
operational challenge areas include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understanding and decision advantage&lt;/li&gt;
&lt;li&gt;Electromagnetic and information advantage&lt;/li&gt;
&lt;li&gt;Planning and automation&lt;/li&gt;
&lt;li&gt;Autonomous systems&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Yesterday’s announcement of &lt;a href="https://www.gov.uk/government/news/new-partnership-set-to-see-the-uk-and-ukraine-develop-battle-winning-technology-as-britain-secures-access-to-ukraines-avengers-ai-labs"&gt;UK access to Ukraine’s Avengers AI Labs
database&lt;/a&gt;
seems incredibly relevant to that last point.&lt;/p&gt;
&lt;p&gt;Machine assistance for handling and interpreting huge volumes of data
would probably benefit decision advantage and interpretation of a
crowded EM spectrum, but this is hopefully(?) more than just LLMs. Of
course, there’s more to AI than large language models… right?&lt;/p&gt;
&lt;p&gt;I worry that “planning and automation” might amount to “generating
&lt;a href="https://www.trngcmd.marines.mil/Portals/207/Docs/TBS/STANAG%202014%20Edition%2009-%20FORMATS%20FOR%20ORDERS%20(OPORD).pdf"&gt;large amounts of
text&lt;/a&gt;
faster”.  Nothing could possibly go wrong with this.&lt;/p&gt; </description> 
	<pubDate>Tue, 25 Aug 2026 20:38:53 +0000</pubDate>

</item> 
<item>
	<title>Antoine Beaupré: A more nuanced view of LLMs</title>
	<guid>https://anarc.at/blog/2026-08-25-llm-nuance/</guid>
	<link>https://anarc.at/blog/2026-08-25-llm-nuance/</link>
     <description>  &lt;blockquote&gt;&lt;p&gt;Also in this series:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://anarc.at/blog/2026-05-16-four-horsemen/"&gt;The Four Horsemen of the LLM Apocalypse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://anarc.at/blog/2026-08-18-people-vs-ai-overlords/"&gt;The people vs the AI overlords&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;p&gt;After ranting and railing about LLMs or "AI" as the optimists (or
&lt;a href="https://en.wikipedia.org/wiki/Accelerationism"&gt;accelerationists&lt;/a&gt;?)  call it, I figured it might be important to
be a little more honest about my use of LLMs and how I think about it
more practically in the world.&lt;/p&gt;

&lt;h1 id="the-debian-vote-context"&gt;The Debian vote context&lt;/h1&gt;

&lt;p&gt;This is not a coming out. I am not using LLMs on a daily basis, and
this blog is, again, written out of my cold dead hands in a dying
world, with over-engineered hardware and (to a certain extent, hi
Emacs!) software, powered by 100% green energy built on &lt;a href="https://en.wikipedia.org/wiki/James_Bay_Cree_hydroelectric_conflict"&gt;stolen land&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;There is a &lt;a href="https://www.debian.org/vote/2026/vote_002"&gt;vote going on in Debian&lt;/a&gt;. If you're unfamiliar with it,
you can &lt;a href="https://lwn.net/SubscriberLink/1087134/77bf350b3d40bc95/"&gt;catch up at LWN&lt;/a&gt;. So far I've essentially said "LLM is
bad" which is not a very balanced or useful opinion. Obviously, people
are using LLMs, sometimes unknowing or unwillingly, and we need to
take that into account. Furthermore, there has been many different
blog posts on Debian planet about this. Some that I found
&lt;a href="https://grep.be/blog//en/computer/debian/Programming_and_GR_2026_002/"&gt;balanced&lt;/a&gt;, &lt;a href="https://diziet.dreamwidth.org/20998.html"&gt;good summaries&lt;/a&gt;, even if I &lt;a href="https://changelog.complete.org/archives/44740-ai-in-debian-the-vote-proposals-and-nuance"&gt;didn't fully agree with
them&lt;/a&gt;, at least some did the basic civil service of being
&lt;a href="http://blog.fai-project.org/posts/llm-usage-gr/"&gt;short&lt;/a&gt;. But others were just not only &lt;a href="https://k1024.org/posts/2026/2026-08-23-another-optimistic-take-on-ai/"&gt;Wrong&lt;/a&gt; but also &lt;a href="http://aigarius.com/blog/2026/08/22/optimistic-take-on-ai/"&gt;so long
that I couldn't finish&lt;/a&gt; that I just &lt;em&gt;had&lt;/em&gt; to write &lt;em&gt;something&lt;/em&gt;.&lt;sup id="fnref:1"&gt;&lt;a href="https://anarc.at/tag/debian-planet/#fn:1" rel="footnote"&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;This is not an explanation of the ballots, nor how I will vote. This
vote is Debian's failure of framing that debate in a reasonable way:
we have 8 options on the ballot with many duplicates. We have failed
to do the hard work of summarizing and aggregating options into a
meaningful set. I doubt the final vote will represent a readable
position we can rally around.&lt;/p&gt;

&lt;p&gt;I have not read the &lt;a href="https://lists.debian.org/debian-vote/2026/07/threads.html"&gt;two&lt;/a&gt; &lt;a href="https://lists.debian.org/debian-vote/2026/08/threads.html"&gt;months&lt;/a&gt; of debates on the topic
either. Normally, before voting, I take a cursory look at the debate
to see points of view I might have missed. But in this case, it will
just make me sad, add noise, and I'm already pretty sure on where I
stand on this.&lt;/p&gt;

&lt;p&gt;So let me describe how I use LLMs and how I think they fit in our
work, as computer engineers and hobbyists.&lt;/p&gt;

&lt;h1 id="my-llm-use"&gt;My LLM use&lt;/h1&gt;

&lt;h2 id="debian-packaging"&gt;Debian Packaging&lt;/h2&gt;

&lt;p&gt;An astute reader has &lt;a href="https://piaille.fr/@TurboTrain/117067460922413248"&gt;pointed out&lt;/a&gt; that I maintain a package in
Debian made to use Anthropic. It's actually multiple packages:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://tracker.debian.org/pkg/llm"&gt;&lt;code&gt;llm&lt;/code&gt;&lt;/a&gt;: a &lt;a href="https://llm.datasette.io/en/stable/"&gt;CLI utility and Python library for interacting with
Large Language Models&lt;/a&gt;, with OpenAI as its default API backend&lt;/li&gt;
&lt;li&gt;&lt;a href="https://tracker.debian.org/pkg/llm-anthropic"&gt;&lt;code&gt;llm-anthropic&lt;/code&gt;&lt;/a&gt;: a plugin for &lt;code&gt;llm&lt;/code&gt; which allows me to talk to
Anthropic's API instead of OpenAI&lt;/li&gt;
&lt;li&gt;&lt;a href="https://tracker.debian.org/pkg/anthropic-sdk-python"&gt;&lt;code&gt;anthropic-sdk-python&lt;/code&gt;&lt;/a&gt;: the SDK &lt;code&gt;llm-anthropic&lt;/code&gt; requires to do
its work&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;As I previously &lt;a href="https://kolektiva.social/@Anarcat/117071797145506717"&gt;explained in response&lt;/a&gt;, I am not entirely
comfortable with this work: it's a compromise. In fact, I first
uploaded &lt;code&gt;llm&lt;/code&gt; to the &lt;code&gt;contrib&lt;/code&gt; section of Debian, where we keep
software that depends on other non-free software, but I was told that,
since &lt;a href="https://tracker.debian.org/pkg/yt-dlp"&gt;&lt;code&gt;yt-dlp&lt;/code&gt;&lt;/a&gt; was in &lt;code&gt;main&lt;/code&gt;, &lt;code&gt;llm&lt;/code&gt; belonged there as well.&lt;/p&gt;

&lt;p&gt;So I &lt;a href="https://tracker.debian.org/news/1718613/accepted-llm-028-2-source-all-into-unstable/"&gt;moved it to main&lt;/a&gt;, alongside similarly controversial tools
like &lt;a href="https://tracker.debian.org/pkg/llama.cpp"&gt;&lt;code&gt;llama.cpp&lt;/code&gt;&lt;/a&gt; or the &lt;a href="https://tracker.debian.org/pkg/python-openai"&gt;&lt;code&gt;python-openai&lt;/code&gt;&lt;/a&gt; library.&lt;/p&gt;

&lt;h2 id="openai-and-anthropic-usage"&gt;OpenAI and Anthropic usage&lt;/h2&gt;

&lt;p&gt;An important part of my work is technology watch. I keep tabs on
thousands of (new and old) software projects, follow news, and
generally try to keep my skills up to date. It's a &lt;a href="https://anarc.at/blog/2018-05-26-kubecon-rant/"&gt;pretty impossible
race&lt;/a&gt;, especially as I grow older, but I still think I'm doing the
right choices in my job.&lt;/p&gt;

&lt;p&gt;Testing large language models is part of that work. At first, I was
using ChatGPT's web interface, but it was annoying to copy-paste
things into a browser, so I looked for different interfaces.&lt;/p&gt;

&lt;p&gt;For a while I tried &lt;a href="https://github.com/karthink/gptel"&gt;&lt;code&gt;gptel&lt;/code&gt;&lt;/a&gt;, a "simple, extensible LLM client for
Emacs" but I found it kind of terrifying. Giving a LLM control over an
Emacs buffer seems like a security nightmare, so I &lt;a href="https://gitlab.com/anarcat/emacs-d/-/commit/57fb1c13e63b58142ece426fc32f4ebdb325a6c3"&gt;stopped doing
that&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;So I use the &lt;code&gt;llm&lt;/code&gt; command-line tool to talk to Anthropic's API. I
started that in the summer of 2025, when I bought 20$USD of API
credits. Before that, I paid for a ChatGPT subscription and then
OpenAI credits, which expired and sent me over to Anthropic, which
&lt;em&gt;seemed&lt;/em&gt; then to have better ethics.&lt;/p&gt;

&lt;p&gt;As it turns out, Anthropic is also happy to work for the US military
(which is a big red line for me). Anthropic also won't let you &lt;a href="https://evanp.me/2026/07/23/claude-wont-let-me-talk-about-the-gaza-genocide/"&gt;talk
about the genocide in Gaza&lt;/a&gt;, it is &lt;a href="https://annas-archive.gl/blog/physical-destruction.html"&gt;destroying physical books&lt;/a&gt;,
and is &lt;a href="https://www.flyingpenguin.com/mythos-grading-mythos-got-patches-yet/"&gt;blackmailing us to use their product for security
coverage&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Needless to say, Anthropic and "Claude" are not my friends, but they
seem like the lesser evil in current "frontier models". So I have
renewed, a couple of weeks ago, another 20$USD of API credits with
Anthropic.&lt;/p&gt;

&lt;h2 id="actual-prompts-and-responses"&gt;Actual prompts and responses&lt;/h2&gt;

&lt;p&gt;So what does 20$ give you at Anthropic anyways? What &lt;em&gt;am&lt;/em&gt; I using LLMs
for and how?&lt;/p&gt;

&lt;p&gt;The neat thing with &lt;code&gt;llm&lt;/code&gt; is that everything is logged in a &lt;code&gt;sqlite&lt;/code&gt;
database, so there are some answers that are easy to get:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;&amp;gt; llm logs status
Logging is ON for all prompts
Found log database at /home/anarcat/.config/io.datasette.llm/logs.db
Number of threads logged:   7
Number of turns logged:     12
Number of legacy conversations: 543
Number of legacy responses: 970
Database file size:         9.61MB
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;That is 10MB of logs, with about a thousand prompts.&lt;/p&gt;

&lt;p&gt;My logs go back to 2024-03-07, a little over two years ago, and
include a mix of Anthropic and OpenAI responses. I used it more in
2024 than 2025, and if the trend continues, I will have used it less
in 2026 again:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;&amp;gt; llm logs list -n 0  --json | jq -r .[].datetime_utc | sed 's/-.*//' | sort | uniq -c 
    527 2024
    357 2025
     98 2026
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;It looks like about 10 prompts per month right now, down from a peak
of about 60 per month in 2024. It's pretty difficult to analyze those
actual logs to get more patterns and I won't run the prompts through a
model &lt;em&gt;again&lt;/em&gt; to process them.&lt;/p&gt;

&lt;h2 id="how-im-using-models-now"&gt;How I'm using models now&lt;/h2&gt;

&lt;p&gt;At first, I was using it partly for benchmarking model's capabilities,
like &lt;a href="https://simonwillison.net/"&gt;Simon Willison&lt;/a&gt; does with his pelicans, clearly not trusting
its output. But I was impressed by the capacities of the Claude Opus
4.5 model when it &lt;a href="https://gitlab.com/anarcat/scripts/-/blob/main/transmodify.py?ref_type=heads"&gt;wrote this script in January&lt;/a&gt;. Impressed, but
also scared: it's the first time I felt I could delegate the entirety
of my programming to a model. Just run the code, if it works, it
works, right?&lt;/p&gt;

&lt;p&gt;So what do I use it now? As an example, here are the 10 last prompts
in my history:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;there is now Claude 5, and a fable model, maybe you know about it?&lt;/li&gt;
&lt;li&gt;impress me&lt;/li&gt;
&lt;li&gt;not impressive, i already know all of this&lt;/li&gt;
&lt;li&gt;chat&lt;/li&gt;
&lt;li&gt;in postfix, i have a 300k mailing that happens regularly here. normally, it delivers within about...&lt;/li&gt;
&lt;li&gt;is there a way i could have drained the maildrop queue faster without removing the milter?&lt;/li&gt;
&lt;li&gt;the problem was that rspamd was timing out on the FUZZY_CALLBACK check. how do i disable that?&lt;/li&gt;
&lt;li&gt;how do i disable all spam checks? i just want rspamd to add dkim signatures&lt;/li&gt;
&lt;li&gt;how do the default_destination_concurrency_limit and initial_destination_concurrency settings int...&lt;/li&gt;
&lt;li&gt;mic check&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;The first one was me trying to confirm which model I am using, which
is not always obvious when going through the whole &lt;code&gt;llm&lt;/code&gt; stack I've
been using. The following two are an attempt at seeing what the model
is capable of and I was "not impressed", to which Claude answered that
I have a "high bar", which, fair enough.&lt;/p&gt;

&lt;p&gt;The &lt;code&gt;chat&lt;/code&gt; is me failing to use a command line, which shows that
perhaps I need to readjust that "high bar", again.&lt;/p&gt;

&lt;p&gt;The next five are a rather embarrassing debacle in a large Postfix
mailing that went sideways, and where I couldn't find an actual
Postfix expert of my level to help. The fabled Claude Fable 5 answered
rather correctly, but dangerously, that I could empty the queue by
disabling the &lt;code&gt;non_smtpd_milters&lt;/code&gt;. What Fable (and myself) did not
realize is that the milter was also adding DKIM signatures, so while the
mailing was expedited, it was done without those precious signatures,
which got us promptly blocked at Gmail. We have recovered since, and,
thanks to the model and reading the &lt;a href="https://www.postfix.org/pickup.8.html"&gt;Postfix manual&lt;/a&gt; for the
hundredth time, that &lt;a href="https://www.postfix.org/pickup.8.html"&gt;pickup(8)&lt;/a&gt; is single-threaded and that we
needed to review the architecture of that mailing (and our spam
filters) a bit. Many tickets ensued.&lt;/p&gt;

&lt;p&gt;The last one is a test I did to make sure my last uploads of
&lt;code&gt;llm-anthropic&lt;/code&gt; and its dependency worked correctly.&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;Note that the above excludes 5 questions I asked Anthropic while
writing this article, where I asked for synonyms and "what nanometer
scale are arduino processors built from? how is an arduino CPU
printed?", a question which Wikipedia furiously evades providing a
good answer.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;Those prompts are pretty typical of my LLM use: I'm testing the models
to see if they work at all, but also, out of desperation, I fire off a
prompt after I fire off questions to colleagues or search engines (in
that order). It's often weird edge cases like the Prometheus query
language, Python's matplotlib, LaTeX, Elisp, optimizations, and so on.&lt;/p&gt;

&lt;p&gt;I use models for translation a lot. Being fully bilingual, it is
common for me to think of a word in French or English and fail to find
exactly the right word for that in the other language. Models help
with that, and are also useful to find synonyms. Those are low-token
uses that seem pretty innocuous to me, but I realize the irony of this
after writing about the &lt;a href="https://anarc.at/blog/2026-05-16-four-horsemen/#the-tower-of-babel"&gt;tower of
Babel&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id="what-i-am-not-using-models-for"&gt;What I am not using models for&lt;/h2&gt;

&lt;p&gt;I am not using models to write prose.&lt;/p&gt;

&lt;p&gt;I am not using models to &lt;em&gt;read&lt;/em&gt; prose. If it's generated with LLMs, I
stop reading.&lt;/p&gt;

&lt;p&gt;I am not using models to write code, with the exception of that single
Python script above.&lt;/p&gt;

&lt;p&gt;I am generally not using models to &lt;em&gt;review&lt;/em&gt; code, with exceptions. If
I get stuck on a hard problem, I might feed a piece of code to the
model. I repeatedly fed &lt;a href="https://gitlab.com/anarcat/asncounter/"&gt;&lt;code&gt;asncounter&lt;/code&gt;&lt;/a&gt; into Claude to try to fix a
performance regression I had introduced. It found micro-optimizations
that taught me a thing or two about Python's internal implementations,
but overall, it was mostly a waste of time. This was in June 2025, so
perhaps now models would fare better. I have not tried again.&lt;/p&gt;

&lt;p&gt;I am not using LLMs to do Debian packaging. When I can, I manually
review the diffs of packages I upload into Debian, still, by hand.&lt;/p&gt;

&lt;p&gt;I do this for the reasons outlined in &lt;a href="https://anarc.at/blog/2026-05-16-four-horsemen/"&gt;The Four Horsemen of the LLM
Apocalypse&lt;/a&gt;, because I refuse to be
complicit in the:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;aggressive and illegal scraping of the servers I steward&lt;/li&gt;
&lt;li&gt;world-wide computer hardware shortage (making it, by the way,
nearly impossible to run presumably clean local models) and the
attack on our job conditions (also discussed in
&lt;a href="https://anarc.at/blog/2026-08-18-people-vs-ai-overlords/"&gt;The people vs the AI overlords&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;death of copyright and free software&lt;/li&gt;
&lt;li&gt;complication and enshifitication of everything, and the
destruction of our communities&lt;/li&gt;
&lt;li&gt;the imperialist &lt;a href="https://www.thenerdreich.com/"&gt;Nerd Reich&lt;/a&gt; that wants to take over the world&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;Like I reluctantly use Intel computers, I &lt;em&gt;do&lt;/em&gt; fire off a prompt. But
I still hold on to the dream that we can build &lt;a href="https://en.wikipedia.org/wiki/Community_of_practice"&gt;communities of
practice&lt;/a&gt; that hold human knowledge collectively and not &lt;a href="https://gizmodo.com/sam-altman-says-intelligence-will-be-a-utility-and-hes-just-the-man-to-collect-the-bills-2000732953"&gt;offload
that as a utility&lt;/a&gt; to some megalomaniac billionaire.&lt;/p&gt;

&lt;h1 id="their-llm-use-i-am-forced-into"&gt;Their LLM use I am forced into&lt;/h1&gt;

&lt;p&gt;So that's me. Clearly, I'm going against the grain here. Everywhere I
look, I see LLM-generated code and projects. Slop and botnets have
flooded the web.&lt;/p&gt;

&lt;p&gt;I use &lt;a href="https://wadamesh.com/"&gt;Wadamesh&lt;/a&gt;, clearly &lt;a href="https://github.com/ALLFATHER-BV/wadamesh/graphs/contributors?from=2026-05-23"&gt;vibe-coded&lt;/a&gt;, because it's the best
graphical interface for MeshCore that runs on portable devices. I wish
it was made by a human, in a community I could participate in, but it
isn't, and I don't.&lt;/p&gt;

&lt;p&gt;I package the above &lt;code&gt;llm&lt;/code&gt; toolset, which is &lt;a href="https://simonwillison.net/2026/Aug/24/llm-anthropic/"&gt;more and more
vibe-coded&lt;/a&gt;, but I still review the diffs. And I have to say: I
trust Simon here. The code is verbose as hell, feels overengineered,
and &lt;code&gt;llm&lt;/code&gt; feels slow, but it generally works, and Simon is still at
the gate.&lt;/p&gt;

&lt;p&gt;The Anthropic SDK is another thing entirely. The &lt;a href="https://salsa.debian.org/python-team/packages/anthropic-sdk-python/-/commit/a3087b3cef63ae239a1f558a6b46565ce0485b7d"&gt;0.91.0 to 0.120
upload&lt;/a&gt;, for example, was nuts:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt; 806 files changed, 72281 insertions(+), 1478 deletions(-)
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;I explicitly did not review that entire diff. It feels like there's a
lot of garbage there to just have a shim between a proprietary API and
Python. But this is the hand I've been dealt.&lt;/p&gt;

&lt;h1 id="larger-projects-llm-use"&gt;Larger projects LLM use&lt;/h1&gt;

&lt;p&gt;LLMs are being used in the Linux kernel, Firefox, &lt;code&gt;rsync&lt;/code&gt;, Rust, and
other places. I don't feel good about this, particularly in Rust, but
they at least made a decent &lt;a href="https://forge.rust-lang.org/policies/llm-usage.html"&gt;policy&lt;/a&gt;. I am glad GCC made a &lt;a href="https://lwn.net/Articles/1086041/"&gt;policy
against LLM contributions&lt;/a&gt; and I support the &lt;a href="https://human-emacs.org/"&gt;human Emacs&lt;/a&gt;
project.&lt;/p&gt;

&lt;p&gt;We need to have a set of foundational tools that are "clean" in the
sense that they are built upon a community of people that understand
how they are built.&lt;/p&gt;

&lt;p&gt;Maybe that's naive or even impossible. The Linux kernel and GCC, in
particular, are massive projects that have long grown past the scale
of a single person's understanding. But the theory was that a
&lt;em&gt;community&lt;/em&gt; of humans can understand &lt;em&gt;collectively&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;Now we seem to be throwing up our hands and giving up on
that community. That LLMs will just fix the problem, whatever it
is. But we're all just one rug pull away from being completely
incapable of managing those projects. The argument there is that we'll
just switch to local models, but no one is actually doing that.
All I see is people use local models &lt;a href="https://micahflee.com/agentic-coding-techniques/"&gt;as a corner case&lt;/a&gt;
(for privacy) or as in &lt;a href="https://changelog.complete.org/archives/44740-ai-in-debian-the-vote-proposals-and-nuance"&gt;theory&lt;/a&gt;, but in reality, everyone uses the
centralized frontier models right now. We just can't fallback.&lt;/p&gt;

&lt;p&gt;We're in the same situation we were, a decade or two ago, when
Microsoft decided it would kill free office alternatives by making
Office free for non-profits. It worked: thousands, if not millions of
schools, community groups and individuals stopped looking for
alternatives (including free software but also "piracy") for Office
and embraced what seemed like a generous offer.&lt;/p&gt;

&lt;p&gt;Now Microsoft pulled the plug and &lt;a href="https://slate.com/technology/2026/08/microsoft-software-nonprofit-data-delete.html"&gt;Over 170,000 Nonprofits Lost All
Their Data&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;I'm afraid the rug pull on LLMs will be much worse: never mind that
Linus won't be able to use his &lt;a href="https://github.com/torvalds/linux/commit/818bebeb63dd6bf5f4e07e145f6cdbace520a34c"&gt;tireless helper&lt;/a&gt; to fix obscure kernel
bugs; we're looking at a collapse of the economy so large that we are
already &lt;a href="https://prospect.org/2026/08/03/ai-bailout-could-be-baked-into-bubble-private-equity-life-insurers-loans/"&gt;talking about bailing out the companies responsible&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;In a sense, the most striking thing about the Debian vote is it has
actually no option to completely refuse upstream LLM contributions. It
seems the community has taken it for granted that it's now impossible
to build Debian entirely without LLMs. We lost the battle even without
a fight, it seems.&lt;/p&gt;

&lt;h1 id="a-plea-for-small"&gt;A plea for small&lt;/h1&gt;

&lt;p&gt;If it has really become impossible for us to manage the complexity we
have built, maybe it's time to stop and think about what we're doing
in the first place. We're struggling to even &lt;a href="https://bootstrappable.org/"&gt;bootstrap&lt;/a&gt; our
current toolchain!&lt;/p&gt;

&lt;p&gt;This is one of the things I like the most about working on the mesh:
it's low tech, small Arduino devices that is built with decades-old
&lt;a href="https://en.wikipedia.org/wiki/Semiconductor_device_fabrication"&gt;semiconductor processes&lt;/a&gt; that is understandable by human
beings.&lt;/p&gt;

&lt;p&gt;Maybe the answer lies more in single-purpose devices like those
communicators and simpler multi-purpose computers than what we have
now, which is what the &lt;a href="https://en.wikipedia.org/wiki/Permacomputing"&gt;permacomputing&lt;/a&gt; movement is about.&lt;/p&gt;

&lt;p&gt;Small is beautiful, let's scale it down.&lt;/p&gt;



&lt;div class="footnotes"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:1"&gt;
and yes, I'm sorry this has gotten this long, I hope you will
forgive those 3000 words.&lt;a href="https://anarc.at/tag/debian-planet/#fnref:1" rev="footnote"&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Tue, 25 Aug 2026 16:07:58 +0000</pubDate>

</item> 
<item>
	<title>Dirk Eddelbuettel: gettz 0.0.6 on CRAN: Maintenance</title>
	<guid>http://dirk.eddelbuettel.com/blog/2026/08/25#gettz_0.0.6</guid>
	<link>http://dirk.eddelbuettel.com/blog/2026/08/25#gettz_0.0.6</link>
     <description>  &lt;img src="http://planet.debian.org/heads/dirk.png" width="65" height="90" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;Another minor routine update 0.0.6 of &lt;a href="https://github.com/eddelbuettel/gettz"&gt;gettz&lt;/a&gt; arrived on &lt;a href="https://cran.r-project.org"&gt;CRAN&lt;/a&gt; just now.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/eddelbuettel/gettz"&gt;gettz&lt;/a&gt; provides a
possible fallback in situations where &lt;code&gt;Sys.timezone()&lt;/code&gt; fails
to determine the system timezone. That happened when &lt;em&gt;e.g.&lt;/em&gt; the
file &lt;code&gt;/etc/localtime&lt;/code&gt; somehow is not a link into the
corresponding file with &lt;a href="https://en.wikipedia.org/wiki/Tz_database"&gt;zoneinfo&lt;/a&gt; data in,
say, &lt;code&gt;/usr/share/zoneinfo&lt;/code&gt;. Since the package was written (in
the fall of 2016), R added a similar extended heuristic approach itself
making the package a little less relevant.&lt;/p&gt;
&lt;p&gt;This release reflects several rounds of updates to the continuous
integration setup, some URL updates, as well as some updates to
packaging including use of Authors@R in DESCRIPTION. As with the
previous releses: No functional changes, no new code, or new
features.&lt;/p&gt;
&lt;p&gt;Thanks to my &lt;a href="https://dirk.eddelbuettel.com/cranberries/"&gt;CRANberries&lt;/a&gt;, there
is a diff to the &lt;a href="https://dirk.eddelbuettel.com/cranberries/2026/08/25#gettz_0.0.6"&gt;previous
release&lt;/a&gt;. Questions, comments etc should go to the &lt;a href="https://github.com/eddelbuettel/gettz/issues"&gt;GitHub issue
tracker&lt;/a&gt; off the &lt;a href="https://github.com/eddelbuettel/gettz"&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;
&lt;p style="font-size: 80%; font-style: italic;"&gt;
This post by &lt;a href="https://dirk.eddelbuettel.com"&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href="https://dirk.eddelbuettel.com/blog/"&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href="https://github.com/sponsors/eddelbuettel"&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt; </description> 
	<pubDate>Tue, 25 Aug 2026 14:01:00 +0000</pubDate>

</item> 
<item>
	<title>Matthias Klumpp: Sovereign Tech Fellowship for Freedesktop Tasks</title>
	<guid>https://blog.tenstral.net/?p=2107</guid>
	<link>https://blog.tenstral.net/2026/08/sovereign-tech-fellowship-for-freedesktop-tasks.html</link>
     <description>  &lt;p class="wp-block-paragraph"&gt;In 2025 I was honored to be selected for the first cohort of &lt;a href="https://www.sovereign.tech/programs/fellowship"&gt;Sovereign Tech Fellows&lt;/a&gt;, a program by Germany’s &lt;a href="https://www.sovereign.tech/"&gt;Sovereign Tech Agency&lt;/a&gt; to improve the resilience of the open source ecosystem by supporting maintainers directly (complementing their existing support for larger FOSS organizations). Back in 2025, I was only working very limited hours – however, this has changed in 2026.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;For the second half of 2026, I am working again as a Sovereign Tech Fellow, but this time with significantly increased hours. After finishing my PhD, I do have time now for new tasks (and new jobs!), and the fellowship presents an amazing opportunity to really advance projects that I maintain or am part of. This also has a very nice effect on contributors and bug reporters, as their feedback gets addressed a lot faster. With some luck, this ultimately will help finding new (co)maintainers for projects as well (although in the age of AI, a lot of how open source used to work is much more uncertain, but that is a matter for a different blog post).&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;The fellowship is time-limited, so I am intending to make the time I currently have count!&lt;/p&gt;



&lt;h2 class="wp-block-heading"&gt;So, what’s planned?&lt;/h2&gt;



&lt;p class="wp-block-paragraph"&gt;I am involved in many projects, but three of them will be getting attention as part of the fellowship. I know I am notoriously slow at blogging, but expect more details on each of them very soon. Here’s an overview:&lt;/p&gt;



&lt;h3 class="wp-block-heading"&gt;Freedesktop.org, Specifications and Organization&lt;/h3&gt;



&lt;p class="wp-block-paragraph"&gt;I maintain the &lt;a href="https://specifications.freedesktop.org/"&gt;Freedesktop Specifications&lt;/a&gt;, which is an area of Freedesktop that has traditionally been a bit chaotic. This “worked” in the past, because Freedesktop was never intended to be a formal standards body, but more a shared space where people could throw a lot of code and ideas over the wall and see what sticks and what people can collaborate on.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;While I very much love the spirit of this and want to keep it in some form, we definitely would benefit not just from more formalization and better procedures, but also from better organization of the specifications in general. A lot of conflicts can be avoided by that. I will work on improving procedures, crunching through the (lots!) of pending bug reports and MRs, and to make the specifications site better searchable and accessible (similar to how Mozilla’s MDN presents information, but I am not sure if we will get quite that far). I also intent to add a compatibility matrix for specifications, so if a desktop opts out of any one of them (or does not implement them yet) that fact is documented and authors of applications know what they can expect. This will allow us to move a lot faster and avoid a lot of conflict, because there is no implicit assumption that “everybody will implement everything” anymore (which has never been quite true anyway).&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;Hopefully, this will ultimately result in a Freedesktop that is both a lot more useful for application authors who want to bring their project to Linux, as well as developers of desktop environments who need to see which specifications are available and which ones are current.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;In addition to that, I have also worked on a Freedesktop.org website refresh, which is pretty much done in its first iteration (pending sysadmin action). The aim there is to have a more official website, separate from user-contributed wiki content, that showcases what Freedesktop is and which projects are using it for hosting. Once the new website is live, I will also review every page again, archive dead projects in their own section and reorganize the software and specifications directory. Those sections are severely outdated and are missing recent efforts from the community, while still containing long-dead old projects (remember &lt;a href="https://en.wikipedia.org/wiki/HAL_(software)"&gt;HAL&lt;/a&gt;? &lt;img alt="&#128521;" class="wp-smiley" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" style="height: 1em;" /&gt;).&lt;/p&gt;



&lt;h3 class="wp-block-heading"&gt;AppStream&lt;/h3&gt;



&lt;p class="wp-block-paragraph"&gt;A lot of extra maintenance work will be (has been!) done on it. This includes things such as JPEG-XL support (blog post soon), sandboxed media processing, support for newer specification additions, better OARS integration (and potentially migrating it to fd.o infrastructure), improvements and API stabilization for &lt;em&gt;libappstream-compose&lt;/em&gt; and a lot of bugfixing and resolution of issues found by AI code review.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;&lt;a href="https://github.com/ximion/appstream"&gt;AppStream&lt;/a&gt; was originally designed to parse only trusted data from vetted Linux distribution sources – this is no longer the case in today’s world and in the way Flatpak uses it, so we need to increase resilience of the project.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;I am also exploring a project that could vastly improve search accuracy for AppStream. Stay tuned for that.&lt;/p&gt;



&lt;h3 class="wp-block-heading"&gt;PackageKit &amp;amp; System Upgrades&lt;/h3&gt;



&lt;p class="wp-block-paragraph"&gt;Many years ago, people thought we would all migrate to atomic Linux distributions and slowly not need &lt;a href="https://github.com/PackageKit/PackageKit"&gt;PackageKit&lt;/a&gt; anymore. This has not turned out to be the case, and there are still plenty of reasons to use a package-based OS, especially in development environments. At the same time, PackageKit has been basically the same for years, and its older architecture is beginning to show. It being a daemon who’s literal job it is to modify the entire system also makes it one of the most security-sensitive components that a Linux system can have, while simultaneously making it near-impossible to sandbox.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;My plan is to create PackageKit 2.0 by building on the great foundation of PackageKit 1.0, but modernizing it. This will include simplifying its code and removing a bunch of features that have no more use in modern desktops, while also adding some features that PackageKit never had but that would be useful to expose to frontends (still no to interactivity an terminal-progress forwarding though!). PK 2.0 will also allow me to solve a few design issues that have been worked around in the past, by replacing them with better solutions. This will be a painful transition, as PackageKit 2.0 will break all interfaces PackageKit has – and those interfaces have been frozen for more than a decade. However, I do fully expect this change to be worth the effort.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;In addition to that, I intend to look into the offline-update procedure again and improve it. The current multi-reboot operation comes with downsides, that newer systemd features such as soft-reboot can alleviate. The end result should be a much smoother, less annoying offline-update experience for users (I especially want to get rid of updates running on system startup, which I consider quite bad from a usability perspective). The new behavior is in the early drafting stages and may need direct support from systemd. I will share more about it once I can.&lt;/p&gt;



&lt;h2 class="wp-block-heading"&gt;That’s a lot of tasks!&lt;/h2&gt;



&lt;p class="wp-block-paragraph"&gt;Yes! I will see how far I get. I am moving project-by-project though, to allow me to focus on one project at a time, rather than scattering my attention continuously. Amazingly, this means that the major tasks for AppStream are already almost done, and we are nearing the 1.2.0 release. AppStream got priority, because the new Freedesktop Flatpak runtime will be released soon, and because I want FlatHub/Flatpak to have access to the new AppStream release sooner. Freedesktop and PackageKit are next on the task list.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;Either way, a lot of progress is coming – if you have any feedback or want to help out, please don’t hesitate to reach out! All work is happening fully in the open, so you can also chime in on the respective GitHub/GitLab tasks &lt;img alt="&#128512;" class="wp-smiley" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f600.png" style="height: 1em;" /&gt;.&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;You can also expect blog posts about key features or interesting changes, so stay tuned! &lt;img alt="&#128578;" class="wp-smiley" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" style="height: 1em;" /&gt;&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;&lt;/p&gt;



&lt;p class="wp-block-paragraph"&gt;&lt;/p&gt; </description> 
	<pubDate>Mon, 24 Aug 2026 21:00:40 +0000</pubDate>

</item> 
<item>
	<title>Dirk Eddelbuettel: gaussfacts 0.0.3 on CRAN: Maintenance</title>
	<guid>http://dirk.eddelbuettel.com/blog/2026/08/24#gaussfacts_0.0.1_to_0.0.3</guid>
	<link>http://dirk.eddelbuettel.com/blog/2026/08/24#gaussfacts_0.0.1_to_0.0.3</link>
     <description>  &lt;img src="http://planet.debian.org/heads/dirk.png" width="65" height="90" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;&lt;img alt="Gauss" src="https://upload.wikimedia.org/wikipedia/commons/9/9b/Carl_Friedrich_Gauss.jpg" style="float: left; margin: 10px 30px 10px 0;" width="150" /&gt;&lt;/p&gt;
&lt;p&gt;A new release of &lt;a href="https://github.com/eddelbuettel/gaussfacts"&gt;gaussfacts&lt;/a&gt; package
arrived on &lt;a href="https://cran.r-project.org"&gt;CRAN&lt;/a&gt; – the first in
pretty much exactly a decade! &lt;a href="https://github.com/eddelbuettel/gaussfacts"&gt;gaussfacts&lt;/a&gt;
provides a &lt;a href="https://zeileis.codeberg.page/fortunes/"&gt;fortunes&lt;/a&gt;-inspired
function to display randomly-chosen &lt;em&gt;facts&lt;/em&gt; about &lt;a href="https://en.wikipedia.org/wiki/Carl_Friedrich_Gauss"&gt;Carl Friedrich
Gauss&lt;/a&gt;, based on the collection curated by Mike Cavers via the &lt;a href="http://www.gaussfacts.com"&gt;gaussfacts&lt;/a&gt; web site (with an &lt;a href="https://web.archive.org/web/*/gaussfacts.com"&gt;archive.org&lt;/a&gt; link
it case it vanishes again). Each call of &lt;code&gt;gaussfact()&lt;/code&gt;
displays another (randomly chosen, or indexed) &lt;em&gt;fact&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;An example:&lt;/p&gt;
&lt;div class="sourceCode" id="cb1"&gt;&lt;pre class="sourceCode r"&gt;&lt;code class="sourceCode r"&gt;&lt;span id="cb1-1"&gt;&lt;a href="https://dirk.eddelbuettel.com/blog/index.rss#cb1-1" tabindex="-1"&gt;&lt;/a&gt;&lt;span class="sc"&gt;&amp;gt;&lt;/span&gt; gaussfacts&lt;span class="sc"&gt;::&lt;/span&gt;&lt;span class="fu"&gt;gaussfact&lt;/span&gt;(&lt;span class="dv"&gt;9&lt;/span&gt;)&lt;/span&gt;
&lt;span id="cb1-2"&gt;&lt;a href="https://dirk.eddelbuettel.com/blog/index.rss#cb1-2" tabindex="-1"&gt;&lt;/a&gt;Gauss once played himself &lt;span class="cf"&gt;in&lt;/span&gt; a zero&lt;span class="sc"&gt;-&lt;/span&gt;sum game and won &lt;span class="sc"&gt;$&lt;/span&gt;&lt;span class="fl"&gt;50.&lt;/span&gt; &lt;/span&gt;
&lt;span id="cb1-3"&gt;&lt;a href="https://dirk.eddelbuettel.com/blog/index.rss#cb1-3" tabindex="-1"&gt;&lt;/a&gt;&lt;span class="sc"&gt;&amp;gt;&lt;/span&gt; &lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This releases, as detailed below, accumulates a number of smaller
maintenance changes including switching to Authors@R. Functionality has
not changed. Oddly enough, it appears that I did not blog about the
package when I created it in August 2016. So to (partially) make up for
that, the NEWS for all three releases follow.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id="changes-in-version-0.0.3-2026-08-23"&gt;Changes in version 0.0.3
(2026-08-23)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Several rounds of continuous integration maintenance and
enhancements&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Additional README.md badges&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Updates to DESCRIPTION as CRAN requirements change&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;A duplicate data entry has been removed (Tim Pokart in &lt;a href="https://github.com/eddelbuettel/gaussfacts/pull/4"&gt;#4&lt;/a&gt;)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Documentation prefers https URLs&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Updated continunous integration multiple times&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Correct man page removing an erroneous duplicate word&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changes-in-version-0.0.2-2016-08-03"&gt;Changes in version 0.0.2
(2016-08-03)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Support 'ind' argument to reference by position&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Clean-up encoding and support extended character set (&lt;a href="https://github.com/eddelbuettel/gaussfacts/pull/2"&gt;#2&lt;/a&gt; closes
&lt;a href="https://github.com/eddelbuettel/gaussfacts/issues/1"&gt;#1&lt;/a&gt;)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Updated continunous integration (&lt;a href="https://github.com/eddelbuettel/gaussfacts/pull/3"&gt;#3&lt;/a&gt;)&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changes-in-version-0.0.1-2016-06-19"&gt;Changes in version 0.0.1
(2016-06-19)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Initial version and CRAN upload&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Thanks to my &lt;a href="https://dirk.eddelbuettel.com/cranberries/"&gt;CRANberries&lt;/a&gt;, there
is a diff to the &lt;a href="https://dirk.eddelbuettel.com/cranberries/2026/08/23#gaussfacts_0.0.3"&gt;previous
release&lt;/a&gt;. Questions, comments etc should go to the &lt;a href="https://github.com/eddelbuettel/gaussfacts/issues"&gt;GitHub issue
tracker&lt;/a&gt; off the &lt;a href="https://github.com/eddelbuettel/gaussfacts"&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;
&lt;p style="font-size: 80%; font-style: italic;"&gt;
This post by &lt;a href="https://dirk.eddelbuettel.com"&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href="https://dirk.eddelbuettel.com/blog/"&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href="https://github.com/sponsors/eddelbuettel"&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt; </description> 
	<pubDate>Mon, 24 Aug 2026 19:04:00 +0000</pubDate>

</item> 
<item>
	<title>Vincent Bernat: An interactive introduction to the spanning tree protocol</title>
	<guid>http://www.luffy.cx/en/blog/2026-spanning-tree.html</guid>
	<link>https://vincent.bernat.ch/en/blog/2026-spanning-tree</link>
     <description>  &lt;div class="admonition when-rss"&gt;
&lt;p class="admonition-title"&gt;Warning&lt;/p&gt;
&lt;p&gt;This post contains interactive examples. To visualize and interact
with them, you need to &lt;a href="https://vincent.bernat.ch/en/blog/2026-spanning-tree" title="An interactive introduction to the spanning tree protocol"&gt;leave your RSS reader&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;

&lt;p&gt;Imagine you rent office space for a three-day event. You quickly set up a few
Ethernet switches and tape some cables on the floor to get everyone online.
Unfortunately, Stan, your clumsiest coworker, kicks out a cable every time he
gets up for coffee. You could add extra cables, but then you’d get a broadcast
storm: Ethernet packets that loop and multiply until nothing else gets through.&lt;/p&gt;
&lt;p&gt;That’s where the &lt;em&gt;spanning tree protocol&lt;/em&gt; (&lt;abbr title="Spanning Tree Protocol"&gt;STP&lt;/abbr&gt;) comes in. &lt;abbr title="Spanning Tree Protocol"&gt;STP&lt;/abbr&gt; blocks just enough
of your spare cables to leave a loop-free tree. When Stan strikes again, it
rebuilds the tree in a second, leaving some time for Blobby, your one-person
support crew, to reconnect the cable.&lt;sup id="fnref:sprites"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:sprites"&gt;1&lt;/a&gt;&lt;/sup&gt; See for yourself: the diagram
below runs a real &lt;abbr title="Spanning Tree Protocol"&gt;STP&lt;/abbr&gt; implementation in your browser!&lt;/p&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:demo

A1 @0,0 prio=4096
A2 @0,1
A3 @0,2
A4 @0,3

B1 @1,0 prio=8192
B2 @1,1
B3 @1,2
B4 @1,3

C1 @2,0 prio=8192
C2 @2,1
C3 @2,2
C4 @2,3

A1 -- A2 hazard=0
A2 -- A3 hazard=0
A3 -- A4 hazard=0
B1 -- B2
B2 -- B3
B3 -- B4
C1 -- C2 hazard=0
C2 -- C3 hazard=0
C3 -- C4 hazard=0

A1 -- B1 cost=10
B1 -- C1 cost=10
A4 -- B4 cost=20
B4 -- C4 cost=20

Leo @-0.3,0.7 proto=none icon=&#128102;&#127995;
Mia @-0.3,1.3 proto=none icon=&#128103;&#127997;
Joy @0.3,0.7  proto=none icon=&#128113;&#127995;‍♀️
Roy @0.3,1.3  proto=none icon=&#128104;&#127998;
A2 -- Leo hazard=0 A2:edge
A2 -- Mia hazard=0 A2:edge
A2 -- Joy hazard=0 A2:edge
A2 -- Roy hazard=0 A2:edge

Max @-0.3,1.7 proto=none icon=&#128104;&#127997;
Zoe @-0.3,2.3 proto=none icon=&#128105;&#127998;
Ada @0.3,1.7  proto=none icon=&#128117;&#127998;
Amy @0.3,2.3  proto=none icon=&#128105;&#127996;
A3 -- Max hazard=0 A3:edge
A3 -- Zoe hazard=0 A3:edge
A3 -- Ada hazard=0 A3:edge
A3 -- Amy hazard=0 A3:edge

Eli @0.7,0.7 proto=none icon=&#128102;&#127996;
Jay @0.7,1.3 proto=none icon=&#128104;&#127995;
Kai @1.3,0.7  proto=none icon=&#129489;&#127997;
Ben @1.3,1.3  proto=none icon=&#128113;&#127996;
B2 -- Eli hazard=0.2 B2:edge
B2 -- Jay hazard=0.2 B2:edge
B2 -- Kai hazard=0.2 B2:edge
B2 -- Ben hazard=0.2 B2:edge

Ava @0.7,1.7 proto=none icon=&#128105;&#127995;
Lea @0.7,2.3 proto=none icon=&#129489;&#127998;‍&#129457;
Ivy @1.3,1.7  proto=none icon=&#129493;&#127997;
Rex @1.3,2.3  proto=none icon=&#128116;&#127999;
B3 -- Ava hazard=0.2 B3:edge
B3 -- Lea hazard=0.2 B3:edge
B3 -- Ivy hazard=0.2 B3:edge
B3 -- Rex hazard=0.2 B3:edge

Ana @1.7,0.7 proto=none icon=&#128105;&#127999;
Eve @1.7,1.3 proto=none icon=&#128103;&#127996;
Abe @2.3,0.7  proto=none icon=&#129491;&#127999;
Ian @2.3,1.3  proto=none icon=&#129492;&#127998;
C2 -- Ana hazard=0 C2:edge
C2 -- Eve hazard=0 C2:edge
C2 -- Abe hazard=0 C2:edge
C2 -- Ian hazard=0 C2:edge

Ned @1.7,1.7 proto=none icon=&#128104;&#127996;‍&#129459;
Lou @1.7,2.3 proto=none icon=&#129489;&#127999;
Fay @2.3,1.7  proto=none icon=&#128103;&#127995;
Sue @2.3,2.3  proto=none icon=&#128105;&#127997;‍&#129456;
C3 -- Ned hazard=0 C3:edge
C3 -- Lou hazard=0 C3:edge
C3 -- Fay hazard=0 C3:edge
C3 -- Sue hazard=0 C3:edge
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;div class="admonition"&gt;
&lt;p class="admonition-title"&gt;Note&lt;/p&gt;
&lt;p&gt;This article is also available as a &lt;a href="https://vincent.bernat.ch/en/blog/2026-spanning-tree-video" title="A non-interactive introduction to the spanning tree protocol"&gt;video&lt;/a&gt;, but I advise you to
keep reading here to try the interactive demonstrations.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="toc"&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#the-basics"&gt;The basics&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#historical-interlude"&gt;Historical interlude&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#electing-the-root-bridge"&gt;Electing the root bridge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#assigning-roles-to-ports"&gt;Assigning roles to ports&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#port-state-transition"&gt;Port state transition&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#topology-change-notification"&gt;Topology change notification&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#security"&gt;Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#why-rstp-today"&gt;Why RSTP today?&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#how-large-can-a-network-be"&gt;How large can a network be?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#how-fast-is-rstp"&gt;How fast is RSTP?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#about-mstp"&gt;About MSTP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vincent.bernat.ch#about-the-interactive-examples"&gt;About the interactive examples&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;h1 id="the-basics"&gt;The basics&lt;/h1&gt;
&lt;p&gt;Designed in the ’80s, the &lt;em&gt;spanning tree protocol&lt;/em&gt; has evolved into a “rapid”
flavor (&lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt;) and a “VLAN-aware” variation (&lt;abbr title="Multiple Spanning Tree Protocol"&gt;MSTP&lt;/abbr&gt;).&lt;sup id="fnref:history"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:history"&gt;2&lt;/a&gt;&lt;/sup&gt; Any sound-minded
network engineer knows there are better alternatives, like &lt;a href="https://vincent.bernat.ch/en/blog/2017-vxlan-bgp-evpn" title="VXLAN: BGP EVPN with FRR"&gt;BGP EVPN VXLAN&lt;/a&gt;.
Yet, because any switch speaks it, the venerable spanning tree protocol still
fills a niche.&lt;/p&gt;
&lt;p&gt;We focus on &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt;: it replaced the original protocol in 2004. To eliminate
network loops, &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; implements a complex state machine. Timers, link state
changes, and the link-local control frames a bridge receives from its neighbors
drive its transitions. These Ethernet frames are the &lt;em&gt;Bridge Protocol Data
Units&lt;/em&gt; (&lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt;). You can watch them in action below: hit the “Start” button.&lt;/p&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:protocol rstp
:tx-hold 10

A1 @0,1
C11 @1,0 prio=4096 icon=&#127795;
C12 @1,2 prio=4096 icon=&#127795;
C21 @2,0 prio=4096 icon=&#127795;
C22 @2,2 prio=4096 icon=&#127795;
A2 @3,1

H1 @0,0.2 proto=none icon=&#128187;
H2 @0,1.8 proto=none icon=&#128424;️
H3 @3,0.2 proto=none icon=&#128224;
H4 @3,1.8 proto=none icon=&#128250;

A1 -- C11
A1 -- C12
A2 -- C21
A2 -- C22
C11 -- C12
C11 -- C21
C11 -- C21
C11 -- C22
C12 -- C21
C12 -- C22
C21 -- C22
A1 -- H1 A1:edge
A1 -- H2 A1:edge
A2 -- H3 A2:edge
A2 -- H4 A2:edge
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;After &lt;a href="https://vincent.bernat.ch#mstp:5,..."&gt;some time&lt;/a&gt;, the topology converges to a tree: from the root
C11, there is a path to each bridge&lt;sup id="fnref:bridge"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:bridge"&gt;3&lt;/a&gt;&lt;/sup&gt; and no loop. In the upper right
corner, the interface displays a tree icon &#127795; followed by the time it took to
reach this state. &lt;a href="https://vincent.bernat.ch#mstp:9,C11--C12,..."&gt;Cut a link&lt;/a&gt; and see how the protocol
finds an alternate path to reach C12 in less than a second. You can stop the
simulation, move it forward step by step, reset it to its initial state, or slow
it down with the “snail” mode &#128012;. Don’t worry about all the displayed
information: I explain it later.&lt;/p&gt;
&lt;p&gt;All examples run in your browser, powered by &lt;a href="https://github.com/mstpd/mstpd" title="Multiple Spanning Tree Protocol Daemon"&gt;MSTPD&lt;/a&gt;—an open-source
user-space&lt;sup id="fnref:kernel"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:kernel"&gt;4&lt;/a&gt;&lt;/sup&gt; implementation of &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt;.&lt;sup id="fnref:incomplete"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:incomplete"&gt;5&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;h2 id="historical-interlude"&gt;Historical interlude&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://hiddenheroes.netguru.com/radia-perlman" title="The Magic Box and the Spanning Tree: How Radia Perlman made the Internet work"&gt;Radia Perlman&lt;/a&gt;, an inductee of the &lt;a href="https://www.internethalloffame.org/inductee/radia-perlman/" title="Radia Perlman profile on the Internet Hall of Fame"&gt;Internet Hall of Fame&lt;/a&gt; in 2014,
summarized the ancestor of &lt;abbr title="Spanning Tree Protocol"&gt;STP&lt;/abbr&gt; she invented at &lt;abbr title="Digital Equipment Corporation"&gt;DEC&lt;/abbr&gt; with this poem, later
included in a &lt;a href="https://patents.google.com/patent/US7339900B2/en" title="Method and apparatus for preventing spanning tree loops during traffic overload conditions"&gt;US patent&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I think that I shall never see&lt;br /&gt;
A graph more lovely than a tree.&lt;br /&gt;
A tree whose crucial property&lt;br /&gt;
Is loop-free connectivity.&lt;br /&gt;
A tree which must be sure to span&lt;br /&gt;
So packets can reach every LAN.&lt;br /&gt;
First, the root must be selected.&lt;br /&gt;
By ID, it is elected.&lt;br /&gt;
Least cost paths from root are traced.&lt;br /&gt;
In the tree, these paths are placed.&lt;br /&gt;
A mesh is made by folks like me,&lt;br /&gt;
Then bridges find a spanning tree.&lt;/p&gt;
&lt;p&gt;― &lt;em&gt;Radia Perlman&lt;/em&gt;, &lt;a href="https://hiddenheroes.netguru.com/radia-perlman" title="The Magic Box and the Spanning Tree: How Radia Perlman made the Internet work"&gt;Algorhyme&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="electing-the-root-bridge"&gt;Electing the root bridge&lt;/h2&gt;
&lt;p&gt;To build a tree, &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; first elects the bridge with the &lt;strong&gt;lowest bridge
identifier&lt;/strong&gt; as the &lt;strong&gt;root bridge&lt;/strong&gt;. The bridge identifier combines the priority
and the MAC address: &lt;code&gt;8192.6e:2b:10:a0:5f:29&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;In the example below, S1 and S2 have priorities of 4,096 and 8,192: S1 becomes
root. S4 has a priority of 12,288, while S3 keeps the default priority of
32,768:&lt;sup id="fnref:priority"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:priority"&gt;6&lt;/a&gt;&lt;/sup&gt; S4 becomes root. S5 and S6 don’t have a specific priority, so
the lowest MAC address wins and S5 becomes root.&lt;/p&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:protocol rstp

S1 @0,0 prio=4096
S2 @0,1 prio=8192
S1 -- S2

S3 @1,0
S4 @1,1 prio=12288
S3 -- S4

S5 @2,0
S6 @2,1
S5 -- S6
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;&lt;a href="https://vincent.bernat.ch#mstp:2,S2-&amp;gt;S1,@"&gt;Initially&lt;/a&gt;, each bridge advertises itself as
root:&lt;sup id="fnref:wireshark"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:wireshark"&gt;7&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 8192.02:00:00:01:00:01
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 8192.02:00:00:01:00:01
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Once a bridge receives a &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; advertising a better root bridge, it
&lt;a href="https://vincent.bernat.ch#mstp:3,S2-&amp;gt;S1,@"&gt;propagates&lt;/a&gt; this new information to its neighbors.&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 4096.02:00:00:00:00:00
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 8192.02:00:00:00:00:01
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h2 id="assigning-roles-to-ports"&gt;Assigning roles to ports&lt;/h2&gt;
&lt;p&gt;The second step is to assign a role to each port. &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; defines five roles, each
denoted by a letter:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;root (R),&lt;/li&gt;
&lt;li&gt;designated (D),&lt;/li&gt;
&lt;li&gt;alternate (A),&lt;/li&gt;
&lt;li&gt;disabled (X), or&lt;/li&gt;
&lt;li&gt;backup (B).&lt;sup id="fnref:backup"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:backup"&gt;8&lt;/a&gt;&lt;/sup&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Each non-root bridge chooses its &lt;strong&gt;root port&lt;/strong&gt;, the one with the lowest-cost
path to the root. Unless you override it, each bridge derives the link cost
from the speed: 20,000 for 1 Gbps. In case of equality, the lowest port
identifier wins.&lt;/p&gt;
&lt;p&gt;Each remaining port becomes a &lt;strong&gt;designated port&lt;/strong&gt; if the &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; it sends is
“better” than the &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; it receives. Otherwise, it becomes an &lt;strong&gt;alternate port&lt;/strong&gt;.
Later, if the root port goes down, the “best” alternate port becomes the new
root port. The tiebreakers for the best &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; are:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;the lowest root bridge identifier,&lt;/li&gt;
&lt;li&gt;the lowest accumulated cost to the root,&lt;/li&gt;
&lt;li&gt;the lowest bridge identifier, and&lt;/li&gt;
&lt;li&gt;the lowest port identifier.&lt;/li&gt;
&lt;/ol&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:protocol rstp

S1 @1,0  prio=4096 icon=&#127795;
S2 @0,1
S3 @2,1

S1 -- S2
S1 -- S3
S1 -- S3
S2 -- S3
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;In the example above, &lt;a href="https://vincent.bernat.ch#mstp:13"&gt;after convergence&lt;/a&gt;, S1 is the root bridge
because it has a priority of 4,096, while the other bridges have a priority of
32,768. All its ports are designated ports because the accumulated cost to the
root is 0.&lt;/p&gt;
&lt;p&gt;S2’s port facing S1 becomes a root port because it has the lowest accumulated
cost to the root—20,000 vs 40,000. S3 has two ports facing S1, and the one with
the lowest port identifier becomes the root port—&lt;code&gt;0x8000&lt;/code&gt; vs &lt;code&gt;0x8001&lt;/code&gt;. The other
candidate is an alternate port because the remote port on the link sends a
better &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;, with an accumulated cost of 0. On the segment between S2 and S3,
S2’s port wins: while both bridges have the same accumulated cost to the root
(20,000), S2’s bridge identifier is smaller—&lt;code&gt;32768.02:00:00:00:00:01&lt;/code&gt; vs
&lt;code&gt;32768.02:00:00:00:00:02&lt;/code&gt;.&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 4096.02:00:00:00:00:00
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Root Path Cost&lt;/span&gt;: 20000
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 32768.02:00:00:00:00:01
&lt;/span&gt;&lt;span class="ss"&gt;    Port identifier&lt;/span&gt;: 0x8002
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;If you &lt;a href="https://vincent.bernat.ch#mstp:13,S1--S3:1"&gt;cut the active link between S1 and S3&lt;/a&gt;, S3 promotes
the “best” alternate port to root port. If you also &lt;a href="https://vincent.bernat.ch#mstp:13,S1--S3:1,S1--S3:2"&gt;disable the second
link&lt;/a&gt;, S3 chooses the remaining alternate port as a
root port. But if you &lt;a href="https://vincent.bernat.ch#mstp:13,S1--S2,@,..."&gt;disable the link between S1 and
S2&lt;/a&gt;, S2 needs a bit more work to elect a new root port
because it does not have an alternate port.&lt;/p&gt;
&lt;p&gt;Unless a specific event happens, designated ports send &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; &lt;a href="https://vincent.bernat.ch#mstp:13,S1-&amp;gt;S3:2,S2-&amp;gt;S3,S1-&amp;gt;S2,@"&gt;every 2
seconds&lt;/a&gt;.&lt;sup id="fnref:hello"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:hello"&gt;9&lt;/a&gt;&lt;/sup&gt; If a bridge does not
receive &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; from its neighbor for 3 consecutive hello periods, it considers
the neighbor dead and removes the port information.&lt;/p&gt;
&lt;h2 id="port-state-transition"&gt;Port state transition&lt;/h2&gt;
&lt;p&gt;Each port can have one of three states. The diagram displays a background color
for each state:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;discarding (red),&lt;/li&gt;
&lt;li&gt;learning (yellow), or&lt;/li&gt;
&lt;li&gt;forwarding (green).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A &lt;em&gt;root port&lt;/em&gt; transitions automatically to the forwarding state. An &lt;em&gt;alternate
port&lt;/em&gt; stays in the discarding state. A &lt;em&gt;designated port&lt;/em&gt; has two options to
transition from the discarding state to the forwarding state:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If the port is an &lt;strong&gt;edge port&lt;/strong&gt;, either through configuration or because the
  remote device does not speak any flavor of &lt;abbr title="Spanning Tree Protocol"&gt;STP&lt;/abbr&gt;, the bridge assumes it won’t
  participate in the protocol and cannot create a loop. In this case, the
  designated port immediately transitions to the forwarding state.&lt;/li&gt;
&lt;li&gt;Otherwise, it sends a &lt;strong&gt;proposal&lt;/strong&gt; to its downstream neighbor. If the remote
  bridge agrees that the received &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; is “better” than any other &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; stored
  for other ports, it elects the receiving port as its root port and starts the
  &lt;strong&gt;synchronization&lt;/strong&gt; process: it transitions all non-edge non-synced designated
  ports to the discarding state to avoid a loop. Then, it sends back an
  &lt;strong&gt;agreement&lt;/strong&gt;. Upon receiving the agreement, the peer designated port
  transitions to the forwarding state.&lt;sup id="fnref:learning"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:learning"&gt;10&lt;/a&gt;&lt;/sup&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:protocol rstp

S1 @1,0 prio=4096 icon=&#127795;
S2 @1,1
S3 @0,2
S4 @2,2
S5 @0,3 prio=8192 icon=&#129726;
S6 @2,3
H1 @0,1.2   proto=none icon=&#128424;️
H2 @2,1.2   proto=none icon=&#128224;
H3 @2.5,1.3 proto=none icon=&#128250;
H4 @2.5,2.3 proto=none icon=&#128187;

S1 -- S2
S2 -- S3
S2 -- S4
S3 -- S5
S4 -- S6
S4 -- S3
S5 -- S6

S3 -- H1 S3:edge
S4 -- H2 S4:edge
S4 -- H3 S4:edge
S6 -- H4 S6:edge
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;In the topology above, H1, H2, H3, and H4 are end devices not participating in
the protocol. We configure the ports they connect to as edge ports, so these
ports immediately move to the forwarding state.&lt;/p&gt;
&lt;p&gt;Use the “step” button to move the simulation forward. The clock moves to 1
second. &lt;a href="https://vincent.bernat.ch#mstp:2,S1-&amp;gt;S2,S2-&amp;gt;S1,@"&gt;Step again&lt;/a&gt; and S1 and S2 send a proposal to
each other. Here is the proposal from S2:&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU flags&lt;/span&gt;: 0x4e, Agreement, Port Role: Designated, Proposal
        &lt;span class="no"&gt;0... .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Topology Change Acknowledgment&lt;/span&gt;: No
        &lt;span class="no"&gt;.1.. .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Agreement&lt;/span&gt;: Yes
        &lt;span class="no"&gt;..0. .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Forwarding&lt;/span&gt;: No
        &lt;span class="no"&gt;...0 .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Learning&lt;/span&gt;: No
&lt;span class="hll"&gt;        &lt;span class="no"&gt;.... 11.. &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Port Role&lt;/span&gt;: Designated &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;        &lt;span class="no"&gt;.... ..1. &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Proposal&lt;/span&gt;: Yes
&lt;/span&gt;        &lt;span class="no"&gt;.... ...0 &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Topology Change&lt;/span&gt;: No
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 32768.02:00:00:00:00:01
&lt;/span&gt;&lt;span class="ss"&gt;    Root Path Cost&lt;/span&gt;: 0
&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 32768.02:00:00:00:00:01
&lt;span class="ss"&gt;    Port identifier&lt;/span&gt;: 0x8001
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;S1 ignores it: its own root identifier is lower. When S2 receives a similar
proposal from S1, it accepts S1 as its root bridge. It also elects the port to
S1 as the root port and starts the synchronization process. The two designated
ports are already discarding, so no change here. &lt;a href="https://vincent.bernat.ch#mstp:3,S2-&amp;gt;S1#2,@"&gt;Step
again&lt;/a&gt; and S2 sends two &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; to S1. In one of them, the
agreement bit is 1 and the proposal bit is 0. It also shows that S2 accepted S1
as the root bridge and its root port is now in the forwarding state. When
receiving this &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;, S1 transitions its own designated port to the forwarding
state. From this point, the link between S1 and S2 forwards user traffic.&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU flags&lt;/span&gt;: 0x79, Agreement, Forwarding, Learning, Port Role: Root, Topology Change
        &lt;span class="no"&gt;0... .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Topology Change Acknowledgment&lt;/span&gt;: No
&lt;span class="hll"&gt;        &lt;span class="no"&gt;.1.. .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Agreement&lt;/span&gt;: Yes
&lt;/span&gt;&lt;span class="hll"&gt;        &lt;span class="no"&gt;..1. .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Forwarding&lt;/span&gt;: Yes
&lt;/span&gt;        &lt;span class="no"&gt;...1 .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Learning&lt;/span&gt;: Yes
&lt;span class="hll"&gt;        &lt;span class="no"&gt;.... 10.. &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Port Role&lt;/span&gt;: Root &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;        &lt;span class="no"&gt;.... ..0. &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Proposal&lt;/span&gt;: No
&lt;/span&gt;        &lt;span class="no"&gt;.... ...1 &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Topology Change&lt;/span&gt;: Yes
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 4096.02:00:00:00:00:00
&lt;/span&gt;&lt;span class="ss"&gt;    Root Path Cost&lt;/span&gt;: 20000
&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 32768.02:00:00:00:00:01
&lt;span class="ss"&gt;    Port identifier&lt;/span&gt;: 0x8001
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Let’s look at what happened to S5. &lt;a href="https://vincent.bernat.ch#mstp:2,S5-&amp;gt;S3,S3-&amp;gt;S5,S5-&amp;gt;S6,S6-&amp;gt;S5,@"&gt;Reset the simulation and step
twice&lt;/a&gt;. S5 exchanges &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; with both S3
and S6. Since S5 has a lower root identifier than S3 and S6, it stays the root
bridge, while S3 and S6 accept the proposal and elect their root ports. S3 and
S6 start the synchronization process. S6’s port to H4 stays up because this is
an edge port. &lt;a href="https://vincent.bernat.ch#mstp:3,S3-&amp;gt;S5#1,S6-&amp;gt;S5#1,@"&gt;Move one step&lt;/a&gt;. Both S3 and S6 send
an agreement back to S5, which transitions both designated ports to the
forwarding state. Yet, the link between S5 and S3 keeps discarding user traffic!
If you look carefully, S3’s port toward S5 is now a designated port, not a root
port. During the &lt;a href="https://vincent.bernat.ch#mstp:3,S2-&amp;gt;S3,@"&gt;same step&lt;/a&gt;, S3 also receives a better &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;
from S2 with S1 as the root bridge. It elects its port to S2 as the root port
and downgrades the port to S5 to a designated port, which stays in the
discarding state.&lt;/p&gt;
&lt;p&gt;On the &lt;a href="https://vincent.bernat.ch#mstp:4,S3-&amp;gt;S5,@"&gt;next step&lt;/a&gt;, things get a bit tricky. S3 sends a
proposal to S5:&lt;sup id="fnref:agreement"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:agreement"&gt;11&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU flags&lt;/span&gt;: 0x4f, Agreement, Port Role: Designated, Proposal, Topology Change
        &lt;span class="no"&gt;0... .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Topology Change Acknowledgment&lt;/span&gt;: No
        &lt;span class="no"&gt;.1.. .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Agreement&lt;/span&gt;: Yes
        &lt;span class="no"&gt;..0. .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Forwarding&lt;/span&gt;: No
        &lt;span class="no"&gt;...0 .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Learning&lt;/span&gt;: No
        &lt;span class="no"&gt;.... 11.. &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Port Role&lt;/span&gt;: Designated &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;        &lt;span class="no"&gt;.... ..1. &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Proposal&lt;/span&gt;: Yes
&lt;/span&gt;        &lt;span class="no"&gt;.... ...1 &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Topology Change&lt;/span&gt;: Yes
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 4096.02:00:00:00:00:00
&lt;/span&gt;&lt;span class="ss"&gt;    Root Path Cost&lt;/span&gt;: 40000
&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 32768.02:00:00:00:00:02
&lt;span class="ss"&gt;    Port identifier&lt;/span&gt;: 0x8002
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;S5 elects S1 as its root bridge and the port toward S3 as its root port. It
starts its synchronization process, but the designated port to S6 does &lt;em&gt;not&lt;/em&gt;
move into the discarding state. Why? That port stays a designated port and its
neighbor S6 had already sent an agreement on the link, so the port keeps its
synced status.&lt;/p&gt;
&lt;p&gt;Now, let’s &lt;a href="https://vincent.bernat.ch#mstp:3,@"&gt;step back&lt;/a&gt; to look at what happens to S6. At this point,
S6 believes S5 is the root bridge. &lt;a href="https://vincent.bernat.ch#mstp:4,S4-&amp;gt;S6#1,@"&gt;Step once&lt;/a&gt; and S4 sends
a new proposal to S6. S6 accepts the proposal, elects S1 as the root bridge and
the port to S4 as its root port. The role of the port facing S5 changes: from a
root port, it becomes a designated port. Because its peer keeps advertising an
inferior &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; on the link, this port becomes disputed and moves to the
discarding state. The root port transitions to the forwarding state and the link
starts forwarding immediately because S4’s designated port is already in the
forwarding state. If we &lt;a href="https://vincent.bernat.ch#mstp:5,S5-&amp;gt;S6,S6-&amp;gt;S5,@"&gt;step one more time&lt;/a&gt;, S5 and S6
exchange two &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt;. The one from S5 is better because of its lower bridge
identifier. S5’s port stays a designated port, while S6 downgrades its own port
to an alternate port.&lt;/p&gt;
&lt;p&gt;Let’s rewind one last time from the start: cut the link between S1 and S2, &lt;a href="https://vincent.bernat.ch#mstp:S1--S2,9"&gt;run
the simulation until the topology is stable&lt;/a&gt;, stop the
simulation, and restore the link between S1 and S2. During the &lt;a href="https://vincent.bernat.ch#mstp:S1--S2,9,S1--S2,1,S1-&amp;gt;S2,S2-&amp;gt;S1,@"&gt;first
step&lt;/a&gt;, S1 and S2 exchange proposals. S2
elects S1 as the root bridge instead of S5 and the port to S1 as the root port.
It downgrades the previous root port to a designated port and moves it into the
discarding state. The other designated port stays synced and keeps its
forwarding state. At the &lt;a href="https://vincent.bernat.ch#mstp:S1--S2,9,S1--S2,2,S2-&amp;gt;S1,@"&gt;next step&lt;/a&gt;, S2 sends
an agreement to S1 and the link between them starts forwarding user traffic. It
also &lt;a href="https://vincent.bernat.ch#mstp:S1--S2,9,S1--S2,2,S2-&amp;gt;S3,@"&gt;sends a proposal to S3&lt;/a&gt;, but not to S4.
Instead, &lt;a href="https://vincent.bernat.ch#mstp:S1--S2,9,S1--S2,2,S2-&amp;gt;S4,@"&gt;it sends a regular &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; to S4&lt;/a&gt;. S4
still elects S1 as its root bridge and the port to S2 as its root port. It
demotes its previous root port, the one to S3, to a designated port, which
transitions to the discarding state because of the root port change. The other
alternate port, to S6, also becomes a designated port and stays in the
discarding state. The new root port moves to the forwarding state. On the &lt;a href="https://vincent.bernat.ch#mstp:S1--S2,9,S1--S2,3,S3-&amp;gt;S4#1,@"&gt;next
step&lt;/a&gt;, S4’s port to S3 settles as an
alternate port after receiving a “better” &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; from S3.&lt;/p&gt;
&lt;p&gt;&lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; is a giant state machine split into smaller ones: bridge detection, port
information, port protocol migration, port role selection, port role
transitions, port receive, port state transitions, port timers, port transmit,
and topology change. Some of them are per bridge, some per port. Each bridge
runs an instance. Time, operational port state changes, and the &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; it
receives from other instances drive the transitions. Being event-driven makes
&lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; more efficient but also more difficult to understand.&lt;/p&gt;
&lt;figure class="lf-fullbleed"&gt;&lt;div class="lf-media-outer" style="width: 900px;"&gt;&lt;span class="lf-media-inner"&gt;&lt;img alt="Western Australian Government Railways class Msa Garratt articulated steam locomotive: elevation and plan drawing" class="lf-media lf-opaque" height="390" src="https://d2pzklc15kok91.cloudfront.net/images/msa-garratt@1x.77dc2f6581ab04.jpg" width="900" /&gt;&lt;/span&gt;&lt;/div&gt;Placeholder for the &lt;em&gt;Port Information&lt;/em&gt; state machine extracted from IEEE 802.1Q-2005, page 182. Pending IEEE authorization for reproduction, this is the blueprint for the Western Australian Government Railways class Msa Garratt articulated steam locomotive.&lt;/figure&gt;
&lt;h2 id="topology-change-notification"&gt;Topology change notification&lt;/h2&gt;
&lt;p&gt;A bridge populates a MAC address table: it associates each source MAC address
with the port that last received it. When forwarding an Ethernet frame, it looks
up this table to choose the right port.&lt;sup id="fnref:bum"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:bum"&gt;12&lt;/a&gt;&lt;/sup&gt; When a link fails, a connected
fridge reachable through one port may become reachable through another one. The
affected bridges should flush the MAC addresses they learned, because these
entries may now be wrong.&lt;/p&gt;
&lt;p&gt;For this purpose, &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; implements &lt;em&gt;topology change notifications&lt;/em&gt; using a
flooding mechanism. When a non-edge port transitions to the forwarding state, a
bridge generates &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; with the &lt;em&gt;topology change&lt;/em&gt; (&lt;abbr title="Topology Change"&gt;TC&lt;/abbr&gt;) bit set. It sends them to
all the non-edge designated ports and to the root port. It also flushes the MAC
address table on these ports. When a bridge receives such a &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;, it propagates
the notification to all non-edge designated ports and the root port, except the
one the notification came from. It also flushes the MAC address table on these
ports. In the examples, the &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; with the &lt;abbr title="Topology Change"&gt;TC&lt;/abbr&gt; bit set to 1 have a red circle.&lt;/p&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:protocol rstp

S1 @1,0 prio=4096 icon=&#127795;
S2 @0,1
S3 @1,1
S4 @2,1
S5 @1,2
LPT @0.1,2 proto=none icon=&#128424;️

S1 -- S2
S1 -- S3
S1 -- S4
S2 -- S3
S2 -- S5
S4 -- S5
S5 -- LPT S5:edge
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Start the simulation and wait a &lt;a href="https://vincent.bernat.ch#mstp:10"&gt;few seconds&lt;/a&gt; for the topology to
settle. Stop the simulation and &lt;a href="https://vincent.bernat.ch#mstp:10,S2--S5"&gt;disable the link between S2 and
S5&lt;/a&gt;. S5 elects the port facing S4 as the root port, which
transitions immediately to the forwarding state. &lt;a href="https://vincent.bernat.ch#mstp:10,S2--S5,1,S5-&amp;gt;S4,@"&gt;Step
once&lt;/a&gt; and S5 emits a &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; with the &lt;abbr title="Topology Change"&gt;TC&lt;/abbr&gt; bit set to 1:&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU flags&lt;/span&gt;: 0x79, Agreement, Forwarding, Learning, Port Role: Root, Topology Change
        &lt;span class="no"&gt;0... .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Topology Change Acknowledgment&lt;/span&gt;: No
        &lt;span class="no"&gt;.1.. .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Agreement&lt;/span&gt;: Yes
        &lt;span class="no"&gt;..1. .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Forwarding&lt;/span&gt;: Yes
        &lt;span class="no"&gt;...1 .... &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Learning&lt;/span&gt;: Yes
        &lt;span class="no"&gt;.... 10.. &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Port Role&lt;/span&gt;: Root &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="no"&gt;.... ..0. &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Proposal&lt;/span&gt;: No
&lt;span class="hll"&gt;        &lt;span class="no"&gt;.... ...1 &lt;/span&gt;&lt;span class="o"&gt;= &lt;/span&gt;&lt;span class="ss"&gt;Topology Change&lt;/span&gt;: Yes
&lt;/span&gt;&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 4096.02:00:00:00:00:00
&lt;span class="ss"&gt;    Root Path Cost&lt;/span&gt;: 40000
&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 32768.02:00:00:00:00:04
&lt;span class="ss"&gt;    Port identifier&lt;/span&gt;: 0x8002
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;S4 receives this &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;. It flushes the MAC address table on the port facing S1:
while LPT was previously reachable through this port, it is now reachable
through S5 instead. &lt;a href="https://vincent.bernat.ch#mstp:10,S2--S5,2,S4-&amp;gt;S1,@"&gt;Step once&lt;/a&gt;. S4 sends S1 a &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;
with the &lt;abbr title="Topology Change"&gt;TC&lt;/abbr&gt; bit set to 1. When S1 receives this &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;, it flushes the MAC address
table on the ports facing S2 and S3. &lt;a href="https://vincent.bernat.ch#mstp:10,S2--S5,3,S1-&amp;gt;S2,S1-&amp;gt;S3,@"&gt;Step
once&lt;/a&gt; and S1 sends a notification to S2 and
S3. &lt;a href="https://vincent.bernat.ch#mstp:10,S2--S5,4,S2-&amp;gt;S3,@"&gt;Step once again&lt;/a&gt; and S2 sends a notification to
S3, while S3 does nothing because the port toward S2 is an &lt;em&gt;alternate port&lt;/em&gt;. S3
does not flush any MAC address table: LPT is still reachable through its port to
S1.&lt;/p&gt;
&lt;p&gt;If you &lt;a href="https://vincent.bernat.ch#mstp:10,S2--S5,6,@"&gt;step a bit more&lt;/a&gt;, you will see that some of the
periodic &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; keep the &lt;abbr title="Topology Change"&gt;TC&lt;/abbr&gt; bit set to 1. Each port runs a timer equal to the
hello timer plus one second.&lt;sup id="fnref:timer"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:timer"&gt;13&lt;/a&gt;&lt;/sup&gt; The timer starts when the port emits a
notification. Until it expires, the port sets the &lt;abbr title="Topology Change"&gt;TC&lt;/abbr&gt; bit to 1 in every &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; it
sends. You can also see &lt;a href="https://vincent.bernat.ch#mstp:10,S2--S5,7,S1-&amp;gt;S4,S4-&amp;gt;S5,@"&gt;some periodic &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt;&lt;/a&gt;
without the &lt;abbr title="Topology Change"&gt;TC&lt;/abbr&gt; bit: they originate from a port that only received a notification
and therefore did not arm its timer.&lt;/p&gt;
&lt;h2 id="security"&gt;Security&lt;/h2&gt;
&lt;p&gt;&lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; is weak against configuration errors and malicious actors. A bridge not
talking &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; can create a loop. An attacker can insert themselves into the
topology to disrupt the service, spy on the traffic, or alter it.&lt;/p&gt;
&lt;p&gt;To mitigate such problems, you need to identify the edge ports. An edge port
connects to an end device, like a PC or a printer. Such devices do not generate
&lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; and cannot create a loop. &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; defines two related flags:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;When true, &lt;strong&gt;AdminEdge&lt;/strong&gt; initializes a port as an edge port. It defaults to
  false.&lt;/li&gt;
&lt;li&gt;When true, &lt;strong&gt;AutoEdge&lt;/strong&gt; lets a port become an edge port when it does not
  receive &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; for 3 seconds. It defaults to true.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If an edge port receives a &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;, regardless of the values of these two flags, it
reverts to a non-edge port.&lt;/p&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;R0 @1.5,1.5 prio=8192

# AutoEdge=true, AdminEdge=false, bridge
S1 @3,1.58
R0 -- S1

# AutoEdge=true, AdminEdge=false, end device
H1 @2.84,2.18 icon=&#128424;️ proto=none
R0 -- H1

# AutoEdge=true, AdminEdge=true, bridge
S2 @2.18,2.84
R0 -- S2 R0:edge

# AutoEdge=true, AdminEdge=true, end device
H2 @1.58,3 icon=&#128187; proto=none
R0 -- H2 R0:edge

# AutoEdge=false, AdminEdge=true, bridge
S3 @0.68,2.76
R0 -- S3 R0:edge R0:no-auto-edge

# AutoEdge=false, AdminEdge=true, end device
H3 @0.24,2.32 icon=&#128224; proto=none
R0 -- H3 R0:edge R0:no-auto-edge

# AutoEdge=false, AdminEdge=false, bridge
S4 @0,1.42
R0 -- S4 R0:no-auto-edge

# AutoEdge=false, AdminEdge=false, end device
H4 @0.16,0.82 icon=&#128250; proto=none
R0 -- H4 R0:no-auto-edge

# Network port, bridge
S5 @0.82,0.16
R0 -- S5 R0:network S5:network

# Network port, end device
H5 @1.42,0 icon=☕ proto=none
R0 -- H5 R0:network

# AdminEdge=true, bpdu-guard=true, bridge
S6 @2.32,0.24
R0 -- S6 R0:bpdu-guard R0:edge

# AdminEdge=true, bpdu-guard=true, end device
H6 @2.76,0.68 icon=&#128161; proto=none
R0 -- H6 R0:bpdu-guard R0:edge
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;In the topology above, S1, S2, S3, S4, S5, and S6 act as bridges, while H1, H2,
H3, H4, H5, and H6 act as end devices:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;S1 and H1 are on a port without a specific configuration: &lt;em&gt;AutoEdge&lt;/em&gt; is true,
  &lt;em&gt;AdminEdge&lt;/em&gt; is false,&lt;/li&gt;
&lt;li&gt;S2 and H2 are on a port where &lt;em&gt;AdminEdge&lt;/em&gt; is true,&lt;/li&gt;
&lt;li&gt;S3 and H3 are on a port where &lt;em&gt;AutoEdge&lt;/em&gt; is false and &lt;em&gt;AdminEdge&lt;/em&gt; is true,&lt;/li&gt;
&lt;li&gt;S4 and H4 are on a port where &lt;em&gt;AutoEdge&lt;/em&gt; is false.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you start the topology and &lt;a href="https://vincent.bernat.ch#mstp:24"&gt;wait about 20 seconds&lt;/a&gt;, links to S1,
S2, S3, S4, H1, H2, H3, and H4 eventually forward user traffic: none of the
flags matter.&lt;/p&gt;
&lt;p&gt;But what about the two remaining pairs? S5 and H5 connect to a &lt;em&gt;network&lt;/em&gt; port.
Such a port enables a non-standard feature: &lt;strong&gt;bridge assurance&lt;/strong&gt;. The port
transmits &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; regardless of its role. If it does not receive &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; for 3
consecutive hello periods, it transitions to the discarding state. On the link
between R0 and S5, you can see &lt;a href="https://vincent.bernat.ch#mstp:24,R0-&amp;gt;S5,S5-&amp;gt;R0,@"&gt;&lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; traveling in both
directions&lt;/a&gt;, unlike the other links, where only
designated ports send &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt;.&lt;/p&gt;
&lt;p&gt;S6 and H6 connect to a port where &lt;em&gt;AdminEdge&lt;/em&gt; is true and &lt;strong&gt;&lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; guard&lt;/strong&gt; is
enabled. This is another non-standard feature that shuts down a port if &lt;a href="https://vincent.bernat.ch#mstp:2,S6-&amp;gt;R0,@"&gt;it
receives a &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In summary, if you expect a port to be an edge port, you should set &lt;em&gt;AdminEdge&lt;/em&gt;
to true and enable &lt;em&gt;&lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; guard&lt;/em&gt;. Otherwise, declare it as a &lt;em&gt;network&lt;/em&gt; port.&lt;/p&gt;
&lt;h1 id="why-rstp-today"&gt;Why &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; today?&lt;/h1&gt;
&lt;p&gt;A compelling use case for &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; today is an out-of-band network for a datacenter,
since you can tolerate an outage of a few seconds. The configuration is minimal
and you can use cheap switches, like a Cisco 2960X.&lt;sup id="fnref:price"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:price"&gt;14&lt;/a&gt;&lt;/sup&gt; You need two
switches acting as root bridges, and you build several loops to connect &lt;abbr title="Out-of-band"&gt;OOB&lt;/abbr&gt;
switches in each cabinet. This simple design survives one failure on each
loop.&lt;sup id="fnref:erps"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:erps"&gt;15&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:protocol rstp
:tx-hold 10

# Root bridges
R1 @0,1 prio=0
R2 @0,2 prio=4096
R1 -- R2 cost=200 R1:network R2:network
R1 -- R2 cost=200 R1:network R2:network

# First loop
C1  @1,0 icon=&#128452;️
C4  @2,0 icon=&#128452;️
C7  @3,0 icon=&#128452;️
C10 @4,0 icon=&#128452;️
C12 @5,0 icon=&#128452;️
C13 @5,3 icon=&#128452;️
C15 @4,3 icon=&#128452;️
C18 @3,3 icon=&#128452;️
C21 @2,3 icon=&#128452;️
C24 @1,3 icon=&#128452;️
R1  -- C1  R1:network C1:network
C1  -- C4  C1:network C4:network
C4  -- C7  C4:network C7:network
C7  -- C10 C7:network C10:network
C10 -- C12 C10:network C12:network
C12 -- C13 C12:network C13:network
C13 -- C15 C13:network C15:network
C15 -- C18 C15:network C18:network
C18 -- C21 C18:network C21:network
C21 -- C24 C21:network C24:network
C24 -- R2  C24:network R2:network

# Second loop
C2  @1,0.5 icon=&#128452;️
C5  @2,0.5 icon=&#128452;️
C8  @3,0.5 icon=&#128452;️
C11 @4,0.5 icon=&#128452;️
C14 @4,2.5 icon=&#128452;️
C17 @3,2.5 icon=&#128452;️
C20 @2,2.5 icon=&#128452;️
C23 @1,2.5 icon=&#128452;️
R1  -- C2  R1:network C2:network
C2  -- C5  C2:network C5:network
C5  -- C8  C5:network C8:network
C8  -- C11 C8:network C11:network
C11 -- C14 C11:network C14:network
C14 -- C17 C14:network C17:network
C17 -- C20 C17:network C20:network
C20 -- C23 C20:network C23:network
C23 -- R2  C23:network R2:network

# Third loop
C3  @1,1 icon=&#128452;️
C6  @2,1 icon=&#128452;️
C9  @3,1 icon=&#128452;️
C16 @3,2 icon=&#128452;️
C19 @2,2 icon=&#128452;️
C22 @1,2 icon=&#128452;️
R1  -- C3  R1:network C3:network
C3  -- C6  C3:network C6:network
C6  -- C9  C6:network C9:network
C9  -- C16 C9:network C16:network
C16 -- C19 C16:network C19:network
C19 -- C22 C19:network C22:network
C22 -- R2  C22:network R2:network
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This topology converges in about &lt;a href="https://vincent.bernat.ch#mstp:6"&gt;6 seconds&lt;/a&gt;. Each loop should stay
small (around 16 bridges) to reduce the probability of a double failure and to
avoid sharing too much bandwidth. The design can evolve a bit without adding too
much complexity: one VLAN per loop or one bridge domain per loop.&lt;/p&gt;
&lt;h2 id="how-large-can-a-network-be"&gt;How large can a network be?&lt;/h2&gt;
&lt;p&gt;The maximum age, whose default value is 20, governs the maximum distance of a
node from the root. The topology below is too big for &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; from R1 to reach
beyond S20.&lt;sup id="fnref:root-mac"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:root-mac"&gt;16&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:protocol rstp
:tx-hold 10
:max-age 20

R1 @0,0 prio=4096 icon=&#127795;
R2 @0,5 prio=4096 icon=&#129726;

S1  @1,0
S2  @2,0
S3  @3,0
S4  @4,0
S5  @5,0
S6  @6,0

S7  @6,1
S8  @5,1
S9  @4,1
S10 @3,1
S11 @2,1
S12 @1,1

S13 @1,2
S14 @2,2
S15 @3,2
S16 @4,2
S17 @5,2
S18 @6,2

S19 @6,3
S20 @5,3
S21 @4,3
S22 @3,3
S23 @2,3
S24 @1,3

S25 @1,4
S26 @2,4
S27 @3,4
S28 @4,4
S29 @5,4
S30 @6,4

S31 @6,5
S32 @5,5
S33 @4,5
S34 @3,5
S35 @2,5
S36 @1,5

R1  -- S1
S1  -- S2
S2  -- S3
S3  -- S4
S4  -- S5
S5  -- S6
S6  -- S7
S7  -- S8
S8  -- S9
S9  -- S10
S10 -- S11
S11 -- S12
S12 -- S13
S13 -- S14
S14 -- S15
S15 -- S16
S16 -- S17
S17 -- S18
S18 -- S19
S19 -- S20
S20 -- S21
S21 -- S22
S22 -- S23
S23 -- S24
S24 -- S25
S25 -- S26
S26 -- S27
S27 -- S28
S28 -- S29
S29 -- S30
S30 -- S31
S31 -- S32
S32 -- S33
S33 -- S34
S34 -- S35
S35 -- S36
S36 -- R2
R1  -- R2 cost=200 down
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Once the &lt;a href="https://vincent.bernat.ch#mstp:40"&gt;topology settles&lt;/a&gt;, part of the network considers R1 the
root, while the other votes for R2. At the boundary, S20 tries to start a
synchronization with S21 to move its &lt;em&gt;designated port&lt;/em&gt; to the forwarding state.
The &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; looks like this:&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU flags&lt;/span&gt;: 0x4e, Agreement, Port Role: Designated, Proposal
&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 4096.02:00:00:00:00:00
&lt;span class="ss"&gt;    Root Path Cost&lt;/span&gt;: 400000
&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 32768.02:00:00:00:00:15
&lt;span class="ss"&gt;    Port identifier&lt;/span&gt;: 0x8002
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Message Age&lt;/span&gt;: 20
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Max Age&lt;/span&gt;: 20
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;S21 rejects it because the message age equals the maximum age. On the other
hand, the &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; S21 sends to S20 looks like this:&lt;/p&gt;
&lt;div class="language-wireshark codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nc"&gt;Spanning Tree Protocol&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Identifier&lt;/span&gt;: Spanning Tree Protocol &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x0000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    Protocol Version Identifier&lt;/span&gt;: Rapid Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU Type&lt;/span&gt;: Rapid/Multiple Spanning Tree &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="ss"&gt;    BPDU flags&lt;/span&gt;: 0x7c, Agreement, Forwarding, Learning, Port Role: Designated
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Root Identifier&lt;/span&gt;: 4096.02:00:00:00:00:01
&lt;/span&gt;&lt;span class="ss"&gt;    Root Path Cost&lt;/span&gt;: 320000
&lt;span class="ss"&gt;    Bridge Identifier&lt;/span&gt;: 32768.02:00:00:00:00:16
&lt;span class="ss"&gt;    Port identifier&lt;/span&gt;: 0x8001
&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Message Age&lt;/span&gt;: 16
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="ss"&gt;    Max Age&lt;/span&gt;: 20
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This is not enough to change S20’s &lt;em&gt;root port&lt;/em&gt; because S20 has a lower &lt;em&gt;root
identifier&lt;/em&gt;—&lt;code&gt;4096.02:00:00:00:00:00&lt;/code&gt; vs &lt;code&gt;4096.02:00:00:00:00:01&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vincent.bernat.ch#mstp:40,R1--R2,..."&gt;Fixing the link between R1 and R2&lt;/a&gt; resolves the issue. The
maximum message age any packet carries is now 18, below the configured maximum
age. But it only works until another link breaks. A plausible fix is to increase
the maximum age to 40.&lt;sup id="fnref:forward-delay"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:forward-delay"&gt;17&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;h2 id="how-fast-is-rstp"&gt;How fast is &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt;?&lt;/h2&gt;
&lt;p&gt;&lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; usually converges in a couple of seconds at startup. It often repairs a
tree in less than a second. Even the &lt;a href="https://vincent.bernat.ch/en/blog/2026-spanning-tree#how-large-can-a-network-be"&gt;38-bridge topology&lt;/a&gt; takes less than 10
seconds to converge.&lt;sup id="fnref:time"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:time"&gt;18&lt;/a&gt;&lt;/sup&gt; Some topologies can take a bit more time to recover
when the root bridge becomes unavailable.&lt;sup id="fnref:slow"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:slow"&gt;19&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;div class="language-text-only mstp-topology codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;:protocol rstp

R0 @1,0 prio=0
S1 @1,1 prio=4096
S2 @0,2 prio=8192
S3 @2,2

R0 -- S1
S1 -- S2
S2 -- S3
S3 -- S1
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;In the topology above, start the simulation, &lt;a href="https://vincent.bernat.ch#mstp:10"&gt;wait for convergence&lt;/a&gt;,
hit stop, and &lt;a href="https://vincent.bernat.ch#mstp:10,R0--S1"&gt;cut the link between R0 and S1&lt;/a&gt;. The topology is
already optimal, but &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; has a hard time converging again.&lt;/p&gt;
&lt;p&gt;First, S1 loses its root port. It has no more information about R0 and elects
itself as the root bridge. It keeps its ports to S2 and S3 as designated ports
in the forwarding state. &lt;a href="https://vincent.bernat.ch#mstp:10,R0--S1,1,S1-&amp;gt;S2,S1-&amp;gt;S3,@"&gt;Step once&lt;/a&gt; and it
sends a &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; to both S2 and S3 to let them know about the root change. When
receiving it, S2 accepts S1 as its root because it does not have a better root
on another port. It elects the port to S1 as its root port. The other port stays
a designated port. Both ports keep forwarding.&lt;/p&gt;
&lt;p&gt;When receiving the &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; from S1, S3 behaves differently: it knows R0 as a better
root than S1 through its alternate port to S2. It promotes this port to a root
port and demotes the port facing S1 to a designated port, which requires a new
agreement. &lt;a href="https://vincent.bernat.ch#mstp:10,R0--S1,2,S3-&amp;gt;S1#1,@"&gt;Step once&lt;/a&gt; and S3 sends a proposal to
S1 with R0 as the root bridge. S1 elects R0 as the root bridge and promotes its
port to S3 as a root port.&lt;/p&gt;
&lt;p&gt;During the &lt;a href="https://vincent.bernat.ch#mstp:10,R0--S1,2,S2-&amp;gt;S3,@"&gt;same step&lt;/a&gt;, S3 also receives a &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; from
S2 stating that S1 is the root bridge. Therefore, S3 has no port left with R0 as
the root bridge: it elects S1 as the root bridge and its port to S2 as the root
port. &lt;a href="https://vincent.bernat.ch#mstp:10,R0--S1,3,S3-&amp;gt;S1,@"&gt;Step once&lt;/a&gt; and its next &lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; to S1 includes
this information: S1 elects itself again as the root bridge. But during the
&lt;a href="https://vincent.bernat.ch#mstp:10,R0--S1,3,S1-&amp;gt;S2#1,@"&gt;same wave&lt;/a&gt;, S1 sends a proposal to S2 with R0 as
the root bridge. While S1 and S3 agree that S1 is the root bridge, S2 now
believes this is R0! &lt;a href="https://vincent.bernat.ch#mstp:10,R0--S1,4,@,..."&gt;In turn&lt;/a&gt;, S2 again convinces S3
that R0 is the root bridge, S3 convinces S1, S1 convinces S2, and S2 convinces
S3.&lt;/p&gt;
&lt;p&gt;This could go on forever, but it does not. The &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; saying “R0 is root”
eventually age out when the message age goes past the maximum age. In the
example above, at the &lt;a href="https://vincent.bernat.ch#mstp:10,R0--S1,24,S2-&amp;gt;S3,@"&gt;eleventh second&lt;/a&gt;, S2 sends a
&lt;abbr title="Bridge Protocol Data Unit"&gt;BPDU&lt;/abbr&gt; to S3 with R0 as root, but S3 drops it because its message age reached the
maximum. With some luck, the topology can also converge faster if a port stops
transmitting new &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; after tripping the transmit hold count, whose default
value is 6 per second.&lt;/p&gt;
&lt;h1 id="about-mstp"&gt;About &lt;abbr title="Multiple Spanning Tree Protocol"&gt;MSTP&lt;/abbr&gt;&lt;/h1&gt;
&lt;p&gt;&lt;abbr title="Multiple Spanning Tree Protocol"&gt;MSTP&lt;/abbr&gt; is the “VLAN-aware” version of &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt;: it runs several instances of &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; and
lets the administrator map each VLAN to a specific instance. For example, you
can map VLANs 100 to 200 to a first instance, and 300 to 400 to a second
instance. The remaining VLANs map to a special instance named the Internal
Spanning Tree (&lt;abbr title="Internal Spanning Tree"&gt;IST&lt;/abbr&gt;). &lt;abbr title="Multiple Spanning Tree Protocol"&gt;MSTP&lt;/abbr&gt; adds its own complexity, but the gist is that you have
several logical topologies acting independently. If you want to dig deeper, have
a look at “&lt;a href="https://ine.com/blog/2008-07-27-mstp-tutorial-part-i-inside-a-region" title="MSTP Tutorial Part I: Inside a Region"&gt;&lt;abbr title="Multiple Spanning Tree Protocol"&gt;MSTP&lt;/abbr&gt; Tutorial Part I: Inside a Region&lt;/a&gt;.”&lt;/p&gt;
&lt;h1 id="about-the-interactive-examples"&gt;About the interactive examples&lt;/h1&gt;
&lt;p&gt;The interactive examples run &lt;a href="https://github.com/mstpd/mstpd" title="Multiple Spanning Tree Protocol Daemon"&gt;MSTPD&lt;/a&gt; directly in your browser, compiled to
&lt;a href="https://developer.mozilla.org/en-US/docs/WebAssembly" title="WebAssembly on MDN"&gt;WebAssembly&lt;/a&gt; with &lt;a href="https://emscripten.org/" title="Emscripten documentation"&gt;emscripten&lt;/a&gt;. A C API replaces the code talking to the
Linux kernel: it manages bridges and ports, exports state as JSON, and drives
time deterministically. A JavaScript wrapper makes it more user-friendly:&lt;/p&gt;
&lt;div class="language-javascript codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;loadMSTPD&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kr"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"./dist/mstpd.mjs"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;await&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;loadMSTPD&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

&lt;span class="c1"&gt;// Create 3 bridges&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;a&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;createBridge&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"A"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;priority&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;4096&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;createBridge&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"B"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;priority&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;8192&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;createBridge&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"C"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="c1"&gt;// Each bridge has two ports&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;a1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;addPort&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"a-b"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;portno&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;a2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;addPort&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"a-c"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;portno&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;addPort&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"b-a"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;portno&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;addPort&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"b-c"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;portno&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;addPort&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"c-a"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;portno&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;addPort&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"c-b"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;portno&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;

&lt;span class="c1"&gt;// Build a triangle topology&lt;/span&gt;
&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;link&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;a1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;link&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;a2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;link&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;b2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c2&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="c1"&gt;// Enable all bridges and ports&lt;/span&gt;
&lt;span class="k"&gt;for&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;br&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;of&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;br&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;enable&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="k"&gt;for&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;p&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;of&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;a1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;a2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;b2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c2&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;p&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;enable&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

&lt;span class="c1"&gt;// Execute 40 seconds' worth of wall clock and display the topology&lt;/span&gt;
&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;step&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mf"&gt;40&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"Topology:"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;mstp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;topology&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Several dozen unit tests explore the features of MSTPD and check that they work
correctly in this environment:&lt;/p&gt;
&lt;div class="language-bash-session codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="gp"&gt;$ &lt;/span&gt;node&lt;span class="w"&gt; &lt;/span&gt;--test&lt;span class="w"&gt; &lt;/span&gt;*.test.mjs
&lt;span class="go"&gt;✔ two bridges: lower priority becomes root (41.657342ms)&lt;/span&gt;
&lt;span class="go"&gt;✔ triangle loop: exactly one port blocks and all agree on the root (5.832ms)&lt;/span&gt;
&lt;span class="go"&gt;✔ breaking the active link reconverges and restoring recovers (18.730753ms)&lt;/span&gt;
&lt;span class="go"&gt;[…]&lt;/span&gt;
&lt;span class="go"&gt;ℹ tests 40&lt;/span&gt;
&lt;span class="go"&gt;ℹ pass 40&lt;/span&gt;
&lt;span class="go"&gt;ℹ fail 0&lt;/span&gt;
&lt;span class="go"&gt;[…]&lt;/span&gt;
&lt;span class="go"&gt;ℹ duration_ms 396.190897&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Additional JavaScript code looks for specific &lt;code&gt;&amp;lt;pre&amp;gt;&lt;/code&gt; blocks containing a
topology definition and turns them into the interactive widget. You can inspect
and modify the definition by hitting the “edit” button.&lt;/p&gt;
&lt;p&gt;There is also a cool trick to tell whether the topology has converged. After
each step, we save a snapshot of the simulation memory, play 50 seconds’ worth
of simulation to check if the topology is stable, and travel back in time by
restoring that snapshot. &#128368;️&lt;/p&gt;
&lt;p&gt;The complete code lives on &lt;a href="https://github.com/vincentbernat/mstpd/tree/feature/wasm/wasm"&gt;GitHub&lt;/a&gt;. I am happy with the result. It can be
difficult to follow everything happening during a single step, but stepping
forward and backward helps. I plan to use the same approach in future blog posts
about networking features.&lt;/p&gt;
&lt;div class="admonition"&gt;
&lt;p class="admonition-title"&gt;Note&lt;/p&gt;
&lt;p&gt;&lt;a href="https://mtlynch.io/"&gt;Michael Lynch&lt;/a&gt; reviewed a first draft of this article. He authored
“&lt;a href="https://refactoringenglish.com/" title="Refactoring English: Effective Writing for Software Developers"&gt;Refactoring English&lt;/a&gt;,” a book to sharpen your writing for blog posts,
documentation, commit messages, and tutorials. Any errors are still mine!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="footnote"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:sprites"&gt;
&lt;p&gt;The sprites for Stan and Blobby come from &lt;a href="https://craftpix.net/" title="Craftpix: 2D game assets"&gt;Craftpix&lt;/a&gt;. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:sprites" title="Jump back to footnote 1 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:history"&gt;
&lt;p&gt;&lt;abbr title="Spanning Tree Protocol"&gt;STP&lt;/abbr&gt; was introduced in &lt;a href="https://sci-hub.fr/10.1109/IEEESTD.1991.101050" title="IEEE Standards for Local and Metropolitan Area Networks: Media Access Control (MAC) Bridges"&gt;IEEE 802.1D-1990&lt;/a&gt;. It is still present in
&lt;a href="https://sci-hub.fr/10.1109/IEEESTD.1998.95619" title="IEEE Standard for Local and Metropolitan Area Networks: Media Access Control (MAC) Bridges"&gt;IEEE 802.1D-1998&lt;/a&gt; but was withdrawn in &lt;a href="https://sci-hub.fr/10.1109/IEEESTD.2004.94569" title="IEEE Standard for Local and Metropolitan Area Networks: Media Access Control (MAC) Bridges"&gt;IEEE 802.1D-2004&lt;/a&gt; in favor of
&lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt;, introduced in &lt;a href="https://sci-hub.fr/10.1109/IEEESTD.2001.93287" title="IEEE Standard for Local and Metropolitan Area Networks: Rapid Reconfiguration of Spanning Tree"&gt;IEEE 802.1w-2001&lt;/a&gt;. &lt;abbr title="Multiple Spanning Tree Protocol"&gt;MSTP&lt;/abbr&gt; was introduced in &lt;a href="https://sci-hub.fr/10.1109/IEEESTD.2002.94223" title="IEEE Standards for Local and Metropolitan Area Networks: Virtual Bridged Local Area Networks — Amendment: Multiple Spanning Trees"&gt;IEEE 802.1s-2002&lt;/a&gt; and merged into &lt;a href="https://sci-hub.fr/10.1109/IEEESTD.2003.94280" title="IEEE Standards for Local and Metropolitan Area Networks: Virtual Bridged Local Area Networks"&gt;IEEE 802.1Q-2003&lt;/a&gt;. Both of them are part
of &lt;a title="IEEE Standard for Local and Metropolitan Area Networks: Bridges and Bridged Networks"&gt;IEEE 802.1Q-2022&lt;/a&gt; along with &lt;a href="https://sci-hub.fr/10.1109/IEEESTD.2012.6231597" title="IEEE Standard for Local and Metropolitan Area Networks: Shortest Path Bridging"&gt;&lt;abbr title="Shortest Path Bridging"&gt;SPB&lt;/abbr&gt;&lt;/a&gt;&lt;del&gt;—a protocol
I had never heard of until writing this article&lt;/del&gt;. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:history" title="Jump back to footnote 2 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:bridge"&gt;
&lt;p&gt;From here, I use “bridge” instead of the more common word “switch.” &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:bridge" title="Jump back to footnote 3 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:kernel"&gt;
&lt;p&gt;The Linux kernel only runs &lt;abbr title="Spanning Tree Protocol"&gt;STP&lt;/abbr&gt;. It delegates the other protocols to
user space. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:kernel" title="Jump back to footnote 4 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:incomplete"&gt;
&lt;p&gt;MSTPD implements the state machine from &lt;a href="https://sci-hub.fr/10.1109/IEEESTD.2006.216285" title="IEEE Standard for Local and Metropolitan Area Networks: Virtual Bridged Local Area Networks"&gt;IEEE 802.1Q-2005&lt;/a&gt;, but
on Linux it runs &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; only. Linux 5.18 added &lt;a href="https://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next.git/commit/?id=ec7328b59176227216c461601c6bd0e922232a9b" title="net: bridge: mst: Multiple Spanning Tree (MST) mode"&gt;support for forwarding
multiple spanning tree&lt;/a&gt;, but MSTPD does not use it yet. See &lt;a href="https://github.com/mstpd/mstpd/pull/150" title="[RFC/RFT] use kernel MST support if available"&gt;PR #150&lt;/a&gt;
for progress on this front. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:incomplete" title="Jump back to footnote 5 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:priority"&gt;
&lt;p&gt;The priority is a multiple of 4,096: with &lt;abbr title="Multiple Spanning Tree Protocol"&gt;MSTP&lt;/abbr&gt;, the lower 12 bits
of the bridge priority encode the &lt;abbr title="Multiple Spanning Tree"&gt;MST&lt;/abbr&gt; instance identifier, leaving only the
upper 4 bits for the configured priority. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:priority" title="Jump back to footnote 6 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:wireshark"&gt;
&lt;p&gt;To inspect the &lt;abbr title="Bridge Protocol Data Units"&gt;BPDUs&lt;/abbr&gt; crossing a link, select it, click the
“Download packets” button, and open the file with &lt;a href="https://www.wireshark.org/" title="Wireshark: network protocol analyzer"&gt;Wireshark&lt;/a&gt;. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:wireshark" title="Jump back to footnote 7 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:backup"&gt;
&lt;p&gt;A backup port only exists if the bridge has several ports on the same
collision domain. This should not happen in a switched network. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:backup" title="Jump back to footnote 8 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:hello"&gt;
&lt;p&gt;This is the value of the “hello” timer. It used to be configurable,
but &lt;a href="https://sci-hub.fr/10.1109/IEEESTD.2006.216285" title="IEEE Standard for Local and Metropolitan Area Networks: Virtual Bridged Local Area Networks"&gt;IEEE 802.1Q-2005&lt;/a&gt; pins it to 2. MSTPD does not allow another value. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:hello" title="Jump back to footnote 9 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:learning"&gt;
&lt;p&gt;If the peer port does not receive an agreement after the hello
timer elapses—or the maximum age if the port has just come up—it falls back
to the timer-based method for compatibility with &lt;abbr title="Spanning Tree Protocol"&gt;STP&lt;/abbr&gt;: it transitions to
the learning state, waits again for the hello timer to expire, and
transitions to the forwarding state. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:learning" title="Jump back to footnote 10 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:agreement"&gt;
&lt;p&gt;As in many proposals, S3 also sets the agreement bit to 1. The
proposal bit says “I am the designated port on this link and I want to
transition to the forwarding state.” The agreement bit says “I am already in
sync with the rest of my bridge on this root information.” Both can be true. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:agreement" title="Jump back to footnote 11 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:bum"&gt;
&lt;p&gt;If it finds no entry, the bridge duplicates the Ethernet frame on all
ports, except the incoming one. The same happens if the destination MAC
address is the broadcast one (&lt;code&gt;ff:ff:ff:ff:ff:ff&lt;/code&gt;). This behavior bootstraps
the learning process. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:bum" title="Jump back to footnote 12 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:timer"&gt;
&lt;p&gt;This timer makes &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt; resistant to packet loss. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:timer" title="Jump back to footnote 13 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:price"&gt;
&lt;p&gt;You can get them for less than US$100 through a broker. All the ports
run &lt;abbr title="Per-VLAN Spanning Tree"&gt;PVST&lt;/abbr&gt;+ by default and automatically fall back to plain &lt;abbr title="Rapid Spanning Tree Protocol"&gt;RSTP&lt;/abbr&gt;. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:price" title="Jump back to footnote 14 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:erps"&gt;
&lt;p&gt;An alternative would be &lt;a href="https://www.itu.int/rec/T-REC-G.8032" title="ITU-T G.8032"&gt;Ethernet Ring Protection Switching&lt;/a&gt; (&lt;abbr title="Ethernet Ring Protection Switching"&gt;ERPS&lt;/abbr&gt;)—another protocol I had never heard of until researching this
article. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:erps" title="Jump back to footnote 15 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:root-mac"&gt;
&lt;p&gt;If you look closely at what happens at t=2s, you can see that R2 is
gaining popularity as root: S17 to S36 believe R2 is the root bridge. S16
does not follow because we hit the maximum age. Later, S17 to S20 reverse
their position. I’ll let you explore the state of the various bridges to
understand the root cause. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:root-mac" title="Jump back to footnote 16 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:forward-delay"&gt;
&lt;p&gt;When increasing the maximum age to 40, you also need to
increase the forward delay to 21 (&lt;code&gt;:forward-delay 21&lt;/code&gt;), as the standard
enforces this condition: 2 × (Forward Delay − 1) ≥ Max Age. For this
specific topology, you could also increase the maximum age to 37 and
forward-delay to 20. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:forward-delay" title="Jump back to footnote 17 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:time"&gt;
&lt;p&gt;The simulation may seem slow, but it does not run in real time. Look at
the current timestamp in the upper right corner to know the wall clock, e.g.
“t=8s.” Once the topology stabilizes, the same corner shows the convergence
time, e.g. “&#127795; 2s.” &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:time" title="Jump back to footnote 18 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:slow"&gt;
&lt;p&gt;Khaled Elmeleegy, Alan Cox, and Eugene Ng formalized this phenomenon in
“&lt;a href="https://www.cs.rice.edu/~eugeneng/papers/INFOCOM06.pdf" title="On Count-to-Infinity Induced Forwarding Loops in Ethernet Networks"&gt;On Count-to-Infinity Induced Forwarding Loops in Ethernet Networks&lt;/a&gt;”
and later in “&lt;a href="https://sci-hub.fr/10.1109/TNET.2008.920874" title="Understanding and Mitigating the Effects of Count to Infinity in Ethernet Networks"&gt;Understanding and Mitigating the Effects of Count to Infinity
in Ethernet Networks&lt;/a&gt;.” They propose a fix that did not find its way into
a standard. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:slow" title="Jump back to footnote 19 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Mon, 24 Aug 2026 15:00:00 +0000</pubDate>

</item> 
<item>
	<title>Vincent Bernat: A non-interactive introduction to the spanning tree protocol</title>
	<guid>http://www.luffy.cx/en/blog/2026-spanning-tree-video.html</guid>
	<link>https://vincent.bernat.ch/en/blog/2026-spanning-tree-video</link>
     <description>  &lt;p&gt;Imagine you rent office space for a three-day event. You quickly set up a few
Ethernet switches and tape some cables on the floor to get everyone online.
Unfortunately, Stan, your clumsiest coworker, kicks out a cable every time he
gets up for coffee. Spare cables would fix that, but a loop turns into a
broadcast storm: Ethernet packets multiply until nothing else gets through.
That’s where the &lt;em&gt;spanning tree protocol&lt;/em&gt; comes in: it blocks just enough of the
spare cables to leave a loop-free tree, and rebuilds it in a second each time
Stan strikes again.&lt;sup id="fnref:credits"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:credits"&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;figure class="lf-fullbleed"&gt;&lt;div class="lf-media-outer" style="width: 1920px;"&gt;&lt;span class="lf-media-inner"&gt;&lt;video class="lf-media lf-opaque" controls="" height="1080" width="1920"&gt;&lt;source src="https://media.bernat.ch/videos/2026-spanning-tree.m3u8" type="application/vnd.apple.mpegurl" /&gt;&lt;source src="https://media.bernat.ch/videos/2026-spanning-tree/progressive.mp4" type="video/mp4; codecs=&amp;quot;mp4a.40.2,avc1.4d401f&amp;quot;" /&gt;&lt;/video&gt;&lt;/span&gt;&lt;/div&gt;&lt;/figure&gt;
&lt;p&gt;This content is also available as a &lt;a href="https://vincent.bernat.ch/en/blog/2026-spanning-tree" title="An interactive introduction to the spanning tree protocol"&gt;text version&lt;/a&gt;, with interactive demos
that run a real implementation directly in your browser!&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;This video is an experiment.&lt;sup id="fnref:time"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:time"&gt;2&lt;/a&gt;&lt;/sup&gt; Honestly, except for Radia Perlman &lt;a href="https://vincent.bernat.ch#video:seek-139"&gt;reading
her poem&lt;/a&gt;,&lt;sup id="fnref:radia"&gt;&lt;a class="footnote-ref" href="https://vincent.bernat.ch#fn:radia"&gt;3&lt;/a&gt;&lt;/sup&gt; you should read the &lt;a href="https://vincent.bernat.ch/en/blog/2026-spanning-tree" title="An interactive introduction to the spanning tree protocol"&gt;original article&lt;/a&gt; instead. It presents the same content, but you can play with the
interactive examples, which are the main contribution. On the other hand, if you
happen to like the video, be sure to tell me in the comments!&lt;/p&gt;
&lt;div class="footnote"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:credits"&gt;
&lt;p&gt;The sprites for Stan and Blobby come from &lt;a href="https://craftpix.net/" title="Craftpix: 2D game assets"&gt;Craftpix&lt;/a&gt;. The
background music is “&lt;a href="https://www.chosic.com/download-audio/25044/" title="Sonatina No. 2 In G Major – III. Allegro by Aaron Dunn"&gt;Sonatina No. 2 in G Major – III. Allegro&lt;/a&gt;” by
Aaron Dunn. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:credits" title="Jump back to footnote 1 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:time"&gt;
&lt;p&gt;I thought automated tools would produce this video in a couple of
hours. In the end, it was another rabbit hole and it took me more than 12. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:time" title="Jump back to footnote 2 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:radia"&gt;
&lt;p&gt;The audio was extracted from a &lt;a href="https://www.youtube.com/watch?v=jOqzLcM2Hbo"&gt;Youtube video&lt;/a&gt; and cleaned up. &lt;a class="footnote-backref" href="https://vincent.bernat.ch#fnref:radia" title="Jump back to footnote 3 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Mon, 24 Aug 2026 14:59:00 +0000</pubDate>

</item> 
<item>
	<title>David Bremner: Reproducing Org mode configuration</title>
	<guid>https://www.cs.unb.ca/~bremner//blog/posts/org-repro/</guid>
	<link>https://www.cs.unb.ca/~bremner//blog/posts/org-repro/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/bremner.png" width="65" height="81" alt="" align="right" style="float: right;"&gt;  &lt;h1 id="Context"&gt;Context&lt;/h1&gt;

&lt;p&gt;Recently I was trying to reproduce a bug with
&lt;a title="https://github.com/andras-simonyi/citeproc-el"&gt;citeproc.el&lt;/a&gt; and
&lt;code&gt;org-mode&lt;/code&gt; in emacs.&lt;/p&gt;

&lt;p&gt;I thought I could use &lt;code&gt;package-vc-install&lt;/code&gt; to install a set of
upstream emacs packages at fixed versions, and thereby let citeproc
upstream test in the same environment as I have.&lt;/p&gt;

&lt;p&gt;It turns out that getting emacs to load the non-builtin version
of org via &lt;code&gt;package-vc-install&lt;/code&gt; did not work because&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;org-mode&lt;/code&gt; needs to run make after cloning&lt;/li&gt;
&lt;li&gt;once package.el was initialized, I always seemed to end up with the
built in &lt;code&gt;org-mode&lt;/code&gt; (yeah, I realize that isn't an explanation).&lt;/li&gt;
&lt;/ul&gt;


&lt;h1 id="Recipe_part_1.3A_get_org"&gt;Recipe part 1: get org&lt;/h1&gt;

&lt;p&gt;Here you can replace &lt;code&gt;9.8.7&lt;/code&gt; with any other tagged release&lt;/p&gt;

&lt;div class="highlight-shellscript"&gt;&lt;pre class="hl"&gt;  EMACSHOME&lt;span class="hl opt"&gt;=&lt;/span&gt;&lt;span class="hl kwd"&gt;$(mktemp -d)&lt;/span&gt;
  git clone https&lt;span class="hl opt"&gt;://&lt;/span&gt;git.sr.ht&lt;span class="hl opt"&gt;/&lt;/span&gt;~bzg&lt;span class="hl opt"&gt;/&lt;/span&gt;org&lt;span class="hl kwb"&gt;-mode&lt;/span&gt; &lt;span class="hl kwd"&gt;${EMACSHOME}&lt;/span&gt;&lt;span class="hl opt"&gt;/&lt;/span&gt;org
  git &lt;span class="hl kwb"&gt;-C&lt;/span&gt; &lt;span class="hl kwd"&gt;${EMACSHOME}&lt;/span&gt;&lt;span class="hl opt"&gt;/&lt;/span&gt;org &lt;span class="hl kwc"&gt;reset&lt;/span&gt; &lt;span class="hl kwb"&gt;--hard&lt;/span&gt; release_9.8&lt;span class="hl num"&gt;.7&lt;/span&gt; 
  &lt;span class="hl kwc"&gt;make&lt;/span&gt; &lt;span class="hl kwb"&gt;-C&lt;/span&gt; &lt;span class="hl kwd"&gt;${EMACSHOME}&lt;/span&gt;&lt;span class="hl opt"&gt;/&lt;/span&gt;org autoloads
  emacs &lt;span class="hl kwb"&gt;-Q --batch -L&lt;/span&gt; &lt;span class="hl kwd"&gt;${EMACSHOME}&lt;/span&gt;&lt;span class="hl opt"&gt;/&lt;/span&gt;org&lt;span class="hl opt"&gt;/&lt;/span&gt;lisp &lt;span class="hl kwb"&gt;--eval&lt;/span&gt; &lt;span class="hl sng"&gt;"(progn (require 'org) (message (org-version)))"&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;This should print &lt;code&gt;9.8.7&lt;/code&gt;, not the version of built in org-mode.&lt;/p&gt;

&lt;h1 id="Recipe_part_2.3A_add-on_packages"&gt;Recipe part 2: add-on packages&lt;/h1&gt;

&lt;p&gt;Now to test some add-on packages, run&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;    emacs -Q --init-directory ${EMACSHOME} -L ${EMACSHOME}/org/lisp
&lt;/code&gt;&lt;/pre&gt;

&lt;div class="highlight-lisp"&gt;&lt;pre class="hl"&gt;  &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;progn&lt;/span&gt;
    &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;require&lt;/span&gt; &lt;span class="hl opt"&gt;'&lt;/span&gt;org&lt;span class="hl opt"&gt;)&lt;/span&gt;
    &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;package-initialize&lt;/span&gt;&lt;span class="hl opt"&gt;)&lt;/span&gt;
    &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;package-vc-install&lt;/span&gt; &lt;span class="hl sng"&gt;"https://github.com/emacs-straight/queue"&lt;/span&gt;&lt;span class="hl opt"&gt;)&lt;/span&gt;
    &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;package-vc-install&lt;/span&gt; &lt;span class="hl sng"&gt;"https://github.com/joostkremers/parsebib"&lt;/span&gt; &lt;span class="hl sng"&gt;"6.7"&lt;/span&gt;&lt;span class="hl opt"&gt;)&lt;/span&gt;
    &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;package-vc-install&lt;/span&gt; &lt;span class="hl sng"&gt;"https://github.com/rejeep/f.el"&lt;/span&gt; &lt;span class="hl sng"&gt;"0.21.0"&lt;/span&gt;&lt;span class="hl opt"&gt;)&lt;/span&gt;
    &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;package-vc-install&lt;/span&gt; &lt;span class="hl sng"&gt;"https://github.com/magnars/s.el"&lt;/span&gt; &lt;span class="hl sng"&gt;"1.13.0"&lt;/span&gt;&lt;span class="hl opt"&gt;)&lt;/span&gt;
    &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;package-vc-install&lt;/span&gt; &lt;span class="hl sng"&gt;"https://github.com/akicho8/string-inflection"&lt;/span&gt; &lt;span class="hl sng"&gt;"1.0.16"&lt;/span&gt;&lt;span class="hl opt"&gt;)&lt;/span&gt;
    &lt;span class="hl opt"&gt;(&lt;/span&gt;&lt;span class="hl kwa"&gt;package-vc-install&lt;/span&gt; &lt;span class="hl sng"&gt;"https://github.com/andras-simonyi/citeproc-el"&lt;/span&gt; &lt;span class="hl sng"&gt;"0.9.5"&lt;/span&gt;&lt;span class="hl opt"&gt;))&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;You can then run your tests in that emacs right away, or restart the environment with&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;  emacs -Q --init-directory ${EMACSHOME} -L ${EMACSHOME}/org/lisp
&lt;/code&gt;&lt;/pre&gt; </description> 
	<pubDate>Mon, 24 Aug 2026 10:30:00 +0000</pubDate>

</item> 
<item>
	<title>Freexian Collaborators: Monthly report about Debian Long Term Support, July 2026 (by Santiago Ruano Rincón)</title>
	<guid>https://www.freexian.com/blog/debian-lts-report-2026-07/</guid>
	<link>https://www.freexian.com/blog/debian-lts-report-2026-07/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/freexian.png" width="215" height="101" alt="" align="right" style="float: right;"&gt;  &lt;img src="https://www.freexian.com/images/debian-lts-logo.png" style="float: right;" /&gt;
&lt;p&gt;The Debian LTS Team, funded by [Freexian’s Debian LTS offering]
(&lt;a href="https://www.freexian.com/lts/debian/%29"&gt;https://www.freexian.com/lts/debian/)&lt;/a&gt;, is pleased to report its activities for
July.&lt;/p&gt;
&lt;h3 id="activity-summary"&gt;Activity summary&lt;/h3&gt;
&lt;p&gt;During the month of July, 23 contributors have been
paid to work on &lt;a href="https://wiki.debian.org/LTS"&gt;Debian LTS&lt;/a&gt; (links to individual
contributor reports are located below).&lt;/p&gt;
&lt;p&gt;The team released &lt;a href="https://lists.debian.org/debian-lts-announce/2026/07/threads.html"&gt;52 DLAs&lt;/a&gt; fixing 2159 CVEs.&lt;/p&gt;
&lt;p&gt;In July, the Debian Stable Release Managers published the
&lt;a href="https://lists.debian.org/debian-stable-announce/2026/07/msg00000.html"&gt;last point release of Debian 12 (“bookworm”)&lt;/a&gt;,
after which the Debian LTS team took full responsibility of Debian 12.  This
completes the handover from the Security Team, that took place in June.  This
also marks the second month in a row where the Debian LTS has been focusing on
two simultaneous Debian releases.&lt;/p&gt;
&lt;p&gt;Other than Debian 12, the team is maintaining Debian 11 (“bullseye”), which
will reach the end of its Long Term Support on 31 August 2026. After that
date, Freexian will continue the security support under the
&lt;a href="https://www.freexian.com/lts/extended/"&gt;Extended LTS&lt;/a&gt; offer.&lt;/p&gt;
&lt;p&gt;The team published several notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;jq (&lt;a href="https://security-tracker.debian.org/tracker/DLA-4662-1"&gt;DLA 4662-1&lt;/a&gt;
and &lt;a href="https://security-tracker.debian.org/tracker/DLA-4661-1"&gt;DLA 4661-1&lt;/a&gt;)
prepared by Andreas Henriksson in collaboration with Jochen Sprickerhof,
addressing multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;Several updates for the different linux supported versions prepared by Ben
Hutchings, in collaboration with Emilio Pozuelo Monfort. Other than the
regular security advisories:
&lt;a href="https://security-tracker.debian.org/tracker/DLA-4664-1"&gt;DLA 4664-1&lt;/a&gt;,
&lt;a href="https://security-tracker.debian.org/tracker/DLA-4665-1"&gt;DLA 4665-1&lt;/a&gt;,
&lt;a href="https://security-tracker.debian.org/tracker/DLA-4671-1"&gt;DLA 4671-1&lt;/a&gt;,
&lt;a href="https://security-tracker.debian.org/tracker/DLA-4688-1"&gt;DLA 4688-1&lt;/a&gt;, and
&lt;a href="https://security-tracker.debian.org/tracker/DLA-4700-1"&gt;DLA 4700-1&lt;/a&gt;, Ben
started preparing packages of 6.12 via bookworm-backports.&lt;/li&gt;
&lt;li&gt;nginx (&lt;a href="https://security-tracker.debian.org/tracker/DLA-4667-1"&gt;DLA 4667-1&lt;/a&gt;),
updated for bookworm by Carlos Henrique Lima Melara, as a follow up of the
bullseye update
(&lt;a href="https://security-tracker.debian.org/tracker/DLA-4660-1"&gt;DLA 4660-1&lt;/a&gt;),
that was prepared in June.&lt;/li&gt;
&lt;li&gt;grub2/bullseye (&lt;a href="https://security-tracker.debian.org/tracker/DLA-4685-1"&gt;DLA 4685-1&lt;/a&gt;),
prepared by Emilio. Other than addressing several security issues, this DLA
was needed for being able to update the shim boot loader.&lt;/li&gt;
&lt;li&gt;samba (&lt;a href="https://security-tracker.debian.org/tracker/DLA-4692-1"&gt;DLA 4692-1&lt;/a&gt;),
uploaded by Markus Koschany, to fix several security flaws in bullseye,
including issues that could yield to remote code execution.&lt;/li&gt;
&lt;li&gt;imagemagick (&lt;a href="https://security-tracker.debian.org/tracker/DLA-4680-1"&gt;DLA 4680-1&lt;/a&gt;
and &lt;a href="https://security-tracker.debian.org/tracker/DLA-4696-1"&gt;DLA 4696-1&lt;/a&gt;),
prepared by Bastien Roucariès, addressing several issues that could lead to
denial of service, information disclosure or potentially arbitrary code
execution in some scenarios.&lt;/li&gt;
&lt;li&gt;poppler (&lt;a href="https://security-tracker.debian.org/tracker/DLA-4709-1"&gt;DLA 4709-1&lt;/a&gt;),
by Guilhem Moulin, fixing several vulnerabilities.&lt;/li&gt;
&lt;li&gt;nss (&lt;a href="https://security-tracker.debian.org/tracker/DLA-4694-1"&gt;DLA-4694-1&lt;/a&gt;),
by Jochen, fixing flaws that may result in or denial of service or
potentially the execution of arbitrary code.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Contributions from outside the LTS Team:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Guillem Jover prepared the
&lt;a href="https://lists.debian.org/debian-lts/2026/07/msg00064.html"&gt;dpkg update&lt;/a&gt;,
released as &lt;a href="https://security-tracker.debian.org/tracker/DLA-4673-1"&gt;DLA-4673-1&lt;/a&gt;
by Arnaud.&lt;/li&gt;
&lt;li&gt;Nicholas Guriev released a rlottie security update
(&lt;a href="https://lists.debian.org/debian-lts-announce/2026/07/msg00017.html"&gt;DLA 4675-1&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Bernhard Schmidt &lt;a href="https://utkarsh2102.org/posts/foss-in-june-26/"&gt;prepared the openvpn&lt;/a&gt;
updates for both bookworm and trixie, released as
&lt;a href="https://security-tracker.debian.org/tracker/DLA-4666-1"&gt;DLA 4666-1&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The LTS Team has also contributed with updates to the latest Debian releases:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Bastien also proposed two updates for imagemagick. The first one released as
&lt;a href="https://security-tracker.debian.org/tracker/DSA-6383-1"&gt;DSA 6383-1&lt;/a&gt;, and the
second as a trixie point update proposal
(&lt;a href="https://bugs.debian.org/1142554"&gt;#1142554&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;python-httplib2 by Emmanuel Arias, and released by the security team as
&lt;a href="https://security-tracker.debian.org/tracker/DSA-6441-1"&gt;DSA 6441-1&lt;/a&gt; in August.&lt;/li&gt;
&lt;li&gt;hplip (&lt;a href="https://security-tracker.debian.org/tracker/DSA-6402-1"&gt;DSA 6402-1&lt;/a&gt;),
prepared by Thorsten Alteholz, to address privilege escalation and arbitrary
code execution related flaws.&lt;/li&gt;
&lt;li&gt;libnfs trixie update (&lt;a href="https://bugs.debian.org/1142351"&gt;#1142351&lt;/a&gt;), by Thorsten&lt;/li&gt;
&lt;li&gt;patool update for trixie &lt;a href="https://bugs.debian.org/1141607"&gt;#1141607&lt;/a&gt;,
by Abhijith PA&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Other contributions:&lt;/p&gt;
&lt;p&gt;Besides the work on security updates, different documentation and tooling
changes were needed, especially in the context of the Debian 12 handover. This
work was mainly done by
&lt;a href="https://lists.debian.org/debian-lts/2026/02/msg00010.html"&gt;Sylvain Beucler&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="individual-debian-lts-contributor-reports"&gt;Individual Debian LTS contributor reports&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://people.debian.org/~abhijith/reports/LTS_ELTS-July-2026.txt"&gt;Abhijith PA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/debian-lts/2026/07/msg00085.html"&gt;Andreas Henriksson&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/msgid-search/397f8bd3-eb5b-451b-8ef5-5743baaf6f48@app.fastmail.com"&gt;Andrej Shadura&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/debian-lts/2026/07/msg00064.html"&gt;Arnaud Rebillout&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/debian-lts/2026/07/msg00091.html"&gt;Bastien Roucariès&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.decadent.org.uk/ben/blog/2026/08/02/foss-activity-in-july-2026.html"&gt;Ben Hutchings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/msgid-search/anAEUcdyc3mp1Nkp@fw13.lan"&gt;Carlos Henrique Lima Melara&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://chris-lamb.co.uk/posts/free-software-activities-in-july-2026"&gt;Chris Lamb&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/debian-lts/2026/08/msg00014.html"&gt;Daniel Leidert&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/debian-lts/2026/08/msg00003.html"&gt;Emmanuel Arias&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://people.debian.org/~pochu/lts/reports/2026-07.txt"&gt;Emilio Pozuelo Monfort&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/msgid-search/?m=Sr1iahmM%2ByWPbsU6@debian.org"&gt;Guilhem Moulin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/msgid-search/amy8kUBV2chs3jcf@mpd"&gt;Jochen Sprickerhof&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/debian-lts/2026/08/msg00009.html"&gt;Lee Garrett&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://people.debian.org/~kanashiro/debian/lts/reports/2026-07.txt"&gt;Lucas Kanashiro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://people.debian.org/~slyon/debian/lts/reports/2026-07.txt"&gt;Lukas Märdian&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dl.gambaru.de/blog/202607_LTS_ELTS_report.txt"&gt;Markus Koschany&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/msgid-search/c1421cdf-de22-42fa-a454-f4530a4e509f@debian.org"&gt;Paride Legovini&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://people.debian.org/~santiago/lts-elts-reports/report-2026-07.txt"&gt;Santiago Ruano Rincón&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/debian-lts/2026/08/msg00000.html"&gt;Sylvain Beucler&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://blog.alteholz.eu/2026/08/my-debian-activities-in-july-2026/"&gt;Thorsten Alteholz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.debian.org/debian-lts/2026/08/msg00015.html"&gt;Tobias Frost&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="thanks-to-our-sponsors"&gt;Thanks to our sponsors&lt;/h3&gt;
&lt;p&gt;Sponsors that joined recently are in bold.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Platinum sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.global.toshiba/ww/top.html"&gt;Toshiba Corporation&lt;/a&gt; (for 130 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cip-project.org"&gt;Civil Infrastructure Platform (CIP)&lt;/a&gt; (for 98 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vyos.io"&gt;VyOS Inc&lt;/a&gt; (for 63 months)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Gold sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.roche.com/about/business/diagnostics.htm"&gt;F. Hoffmann-La Roche AG&lt;/a&gt; (for 141 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.conet.de/"&gt;CONET Deutschland GmbH&lt;/a&gt; (for 124 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.ox.ac.uk"&gt;University of Oxford&lt;/a&gt; (for 81 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.edf.fr"&gt;EDF SA&lt;/a&gt; (for 52 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.dataport.de"&gt;Dataport AöR&lt;/a&gt; (for 27 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://home.cern/"&gt;CERN&lt;/a&gt; (for 25 months)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Silver sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://domainnameshop.com/"&gt;Domeneshop AS&lt;/a&gt; (for 145 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metropole.nantes.fr/"&gt;Nantes Métropole&lt;/a&gt; (for 139 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.akamai.com/"&gt;Akamai - Linode&lt;/a&gt; (for 135 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.univention.de"&gt;Univention GmbH&lt;/a&gt; (for 131 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://portail.univ-st-etienne.fr/"&gt;Université Jean Monnet de St Etienne&lt;/a&gt; (for 131 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ribboncommunications.com/"&gt;Ribbon Communications, Inc.&lt;/a&gt; (for 125 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.exonet.nl"&gt;Exonet B.V.&lt;/a&gt; (for 115 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.lrz.de"&gt;Leibniz Rechenzentrum&lt;/a&gt; (for 109 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.diplomatie.gouv.fr"&gt;Ministère de l’Europe et des Affaires Étrangères&lt;/a&gt; (for 93 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dinahosting.com"&gt;Dinahosting SL&lt;/a&gt; (for 80 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://upsun.com"&gt;Upsun Formerly Platform.sh&lt;/a&gt; (for 75 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.moxa.com"&gt;Moxa Inc.&lt;/a&gt; (for 69 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sipgate.de"&gt;sipgate GmbH&lt;/a&gt; (for 66 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ovhcloud.com"&gt;OVH US LLC&lt;/a&gt; (for 64 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.tilburguniversity.edu/"&gt;Tilburg University&lt;/a&gt; (for 64 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.gsi.de"&gt;GSI Helmholtzzentrum für Schwerionenforschung GmbH&lt;/a&gt; (for 56 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cesky-hosting.cz/"&gt;THINline s.r.o.&lt;/a&gt; (for 28 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cph.dk"&gt;Copenhagen Airports A/S&lt;/a&gt; (for 22 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.isere.fr"&gt;Conseil Départemental de l’Isère&lt;/a&gt; (for 8 months)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.ceos-gmbh.de/en"&gt;CEOS GmbH&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Bronze sponsors:
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.seznam.cz"&gt;Seznam.cz, a.s.&lt;/a&gt; (for 146 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.evolix.fr"&gt;Evolix&lt;/a&gt; (for 145 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://linuxhotel.de"&gt;Linuxhotel GmbH&lt;/a&gt; (for 143 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://intevation.de"&gt;Intevation GmbH&lt;/a&gt; (for 142 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://waays.fr"&gt;WAAYS&lt;/a&gt; (for 141 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.megaspace.de"&gt;Megaspace Internet Services GmbH&lt;/a&gt; (for 140 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.greenbone.net"&gt;Greenbone AG&lt;/a&gt; (for 139 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://numlog.fr"&gt;NUMLOG&lt;/a&gt; (for 139 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wingo.ch/"&gt;WinGo AG&lt;/a&gt; (for 138 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.entrouvert.com/"&gt;Entr’ouvert&lt;/a&gt; (for 130 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://adfinis.com"&gt;Adfinis AG&lt;/a&gt; (for 127 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.plathome.com"&gt;Plat’Home&lt;/a&gt; (for 124 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.legi.grenoble-inp.fr"&gt;Laboratoire LEGI - UMR 5519 / CNRS&lt;/a&gt; (for 122 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.tesorion.nl/"&gt;Tesorion&lt;/a&gt; (for 122 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://bearstech.com"&gt;Bearstech&lt;/a&gt; (for 114 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://lihas.de"&gt;LiHAS&lt;/a&gt; (for 114 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.catalyst.net.nz"&gt;Catalyst IT Ltd&lt;/a&gt; (for 108 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://demarcq.net"&gt;Demarcq SAS&lt;/a&gt; (for 102 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.univ-grenoble-alpes.fr"&gt;Université Grenoble Alpes&lt;/a&gt; (for 88 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.touchweb.fr"&gt;TouchWeb SAS&lt;/a&gt; (for 80 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.spin-ag.de"&gt;SPiN AG&lt;/a&gt; (for 77 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.corefiling.com"&gt;CoreFiling&lt;/a&gt; (for 73 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.osug.fr/"&gt;Observatoire des Sciences de l’Univers de Grenoble&lt;/a&gt; (for 65 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.werfen.com"&gt;Tem Innovations GmbH&lt;/a&gt; (for 59 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://wordfinder.pro"&gt;WordFinder.pro&lt;/a&gt; (for 59 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.resif.fr"&gt;CNRS DT INSU Résif&lt;/a&gt; (for 58 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.soliton.co.jp"&gt;Soliton Systems K.K.&lt;/a&gt; (for 53 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.alterway.fr"&gt;Alter Way&lt;/a&gt; (for 51 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.sobis.com/"&gt;SOBIS Software GmbH&lt;/a&gt; (for 25 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.tuxera.com"&gt;Tuxera Inc.&lt;/a&gt; (for 17 months)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://opm-op.com"&gt;OPM-OP AS&lt;/a&gt; (for 8 months)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.lu-cix.lu"&gt;LU-CIX Management G.I.E.&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt; </description> 
	<pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>

</item> 
<item>
	<title>Russ Allbery: Long delayed haul</title>
	<guid>https://www.eyrie.org/~eagle/journal/2026-08/002.html</guid>
	<link>https://www.eyrie.org/~eagle/journal/2026-08/002.html</link>
     <description>  &lt;p&gt;
I haven't made a new book haul post in I don't know how long, so a lot of
books have piled up and many have already been reviewed. Here's the
overdue catch-up in case anyone is curious what books I am finding
interesting before the reviews get posted.
&lt;/p&gt;

&lt;p&gt;
Ilona Andrews — &lt;cite&gt;Magic Bites&lt;/cite&gt; (sff)&lt;br /&gt;
Elizabeth Bear — &lt;cite&gt;In the House of Aryaman, a Lonely Signal Burns&lt;/cite&gt;
(sff)&lt;br /&gt;
Oliver Burkeman — &lt;cite&gt;Four Thousand Weeks&lt;/cite&gt; (non-fiction)&lt;br /&gt;
Miles Cameron — &lt;cite&gt;Whalesong&lt;/cite&gt; (sff)&lt;br /&gt;
Lee Child — &lt;cite&gt;Killing Floor&lt;/cite&gt; (thriller)&lt;br /&gt;
august clarke — &lt;cite&gt;The Felicity Complex&lt;/cite&gt; (sff)&lt;br /&gt;
Alison Cochrun — &lt;cite&gt;Here We Go Again&lt;/cite&gt; (romance)&lt;br /&gt;
Dan Davies — &lt;cite&gt;The Unaccountability Machine&lt;/cite&gt; (non-fiction)&lt;br /&gt;
Linzi Day — &lt;cite&gt;Midlife in Gretna Green&lt;/cite&gt; (sff)&lt;br /&gt;
Linzi Day — &lt;cite&gt;Painting the Blues in Gretna Green&lt;/cite&gt; (sff)&lt;br /&gt;
Linzi Day — &lt;cite&gt;Ties that Bond in Gretna Green&lt;/cite&gt; (sff)&lt;br /&gt;
Linzi Day — &lt;cite&gt;Spilling the Tea in Gretna Green&lt;/cite&gt; (sff)&lt;br /&gt;
Michelle Diener — &lt;cite&gt;Dark Ambitions&lt;/cite&gt; (sff)&lt;br /&gt;
Michelle Diener — &lt;cite&gt;Dark Class&lt;/cite&gt; (sff)&lt;br /&gt;
Michelle Diener — &lt;cite&gt;Collision Course&lt;/cite&gt; (sff)&lt;br /&gt;
Michelle Diener — &lt;cite&gt;Crash Course&lt;/cite&gt; (sff)&lt;br /&gt;
Henry Farrell — &lt;cite&gt;Underground Empire&lt;/cite&gt; (non-fiction)&lt;br /&gt;
Kathleen A. Flynn — &lt;cite&gt;The Jane Austen Project&lt;/cite&gt; (sff)&lt;br /&gt;
Victoria Goddard — &lt;cite&gt;The Hands of the Emperor&lt;/cite&gt; (sff)&lt;br /&gt;
James Herriot — &lt;cite&gt;All Creatures Great and Small&lt;/cite&gt; (mainstream)&lt;br /&gt;
James Herriot — &lt;cite&gt;All Things Bright and Beautiful&lt;/cite&gt; (mainstream)&lt;br /&gt;
James Herriot — &lt;cite&gt;All Things Wise and Wonderful&lt;/cite&gt; (mainstream)&lt;br /&gt;
James Herriot — &lt;cite&gt;The Lord God Made Them All&lt;/cite&gt; (mainstream)&lt;br /&gt;
James Herriot — &lt;cite&gt;Every Living Thing&lt;/cite&gt; (mainstream)&lt;br /&gt;
Lauren Hough — &lt;cite&gt;Monster of a Land&lt;/cite&gt; (non-fiction collection)&lt;br /&gt;
Bethany Jacobs — &lt;cite&gt;This Brutal Moon&lt;/cite&gt; (sff)&lt;br /&gt;
Guy Gavriel Kay — &lt;cite&gt;Written on the Dark&lt;/cite&gt; (sff)&lt;br /&gt;
Mary Robinette Kowal — &lt;cite&gt;The Martian Contingency&lt;/cite&gt; (sff)&lt;br /&gt;
Ann Leckie — &lt;cite&gt;Radiant Star&lt;/cite&gt; (sff)&lt;br /&gt;
C.B. Lee — &lt;cite&gt;Coffeeshop in an Alternate Universe&lt;/cite&gt; (sff)&lt;br /&gt;
Fonda Lee — &lt;cite&gt;The Last Contract of Isako&lt;/cite&gt; (sff)&lt;br /&gt;
Julie Leong — &lt;cite&gt;The Teller of Small Fortunes&lt;/cite&gt; (sff)&lt;br /&gt;
Julie Leong — &lt;cite&gt;The Keeper of Magical Things&lt;/cite&gt; (sff)&lt;br /&gt;
R.Z. Nicolet — &lt;cite&gt;The Cloak and Its Wizard&lt;/cite&gt; (sff)&lt;br /&gt;
Claire North — &lt;cite&gt;Slow Gods&lt;/cite&gt; (sff)&lt;br /&gt;
Rebecca Ore — &lt;cite&gt;Writing's Writing&lt;/cite&gt; (non-fiction collection)&lt;br /&gt;
Suzanne Palmer — &lt;cite&gt;Ode to the Half-Broken&lt;/cite&gt; (sff)&lt;br /&gt;
Gareth L. Powell — &lt;cite&gt;Fleet of Knives&lt;/cite&gt; (sff)&lt;br /&gt;
Cameron Reed — &lt;cite&gt;What We Are Seeking&lt;/cite&gt; (sff)&lt;br /&gt;
Beth Revis — &lt;cite&gt;Full Speed to a Crash landing&lt;/cite&gt; (sff)&lt;br /&gt;
Beth Revis — &lt;cite&gt;How to Steal a Galaxy&lt;/cite&gt; (sff)&lt;br /&gt;
Beth Revis — &lt;cite&gt;Last Chance to Save the World&lt;/cite&gt; (sff)&lt;br /&gt;
Natalie Zina Walschots — &lt;cite&gt;Villain&lt;/cite&gt; (sff)&lt;br /&gt;
Jo Walton — &lt;cite&gt;Everybody's Perfect&lt;/cite&gt; (sff)&lt;br /&gt;
Martha Wells — &lt;cite&gt;Platform Decay&lt;/cite&gt; (sff)&lt;br /&gt;
James White — &lt;cite&gt;The Galactic Gourmet&lt;/cite&gt; (sff)&lt;br /&gt;
James White — &lt;cite&gt;Final Diagnosis&lt;/cite&gt; (sff)&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;
The James Herriot books were ones my parents were getting rid of. I have
them marked as mainstream fiction as a short-hand since "fictionalized
autobiography" seemed like too much of a mouthful.
&lt;/p&gt; </description> 
	<pubDate>Sun, 23 Aug 2026 21:29:00 +0000</pubDate>

</item> 
<item>
	<title>Sergio Cipriano: Two Debian Days in one week</title>
	<guid>tag:www.sergiocipriano.com,2026-08-23:posts/debian-day-2026.md</guid>
	<link>https://sergiocipriano.com/debian-day-2026.html</link>
     <description>  &lt;h1 id="two-debian-days-in-one-week"&gt;Two Debian Days in one week&lt;/h1&gt;
&lt;p&gt;The Debian Project was officially founded by Ian Murdock on &lt;a href="https://wiki.debian.org/DebianHistory?action=AttachFile&amp;amp;do=get&amp;amp;target=Debian-announcement-1993.txt"&gt;August
16, 1993&lt;/a&gt;. The Debian community celebrates its birthday, Debian Day,
on or around this date every year. This year, I had the chance to attend
two of them: one in João Pessoa, Paraíba, and another in Brasília, the
capital of Brazil.&lt;/p&gt;
&lt;h2 id="joão-pessoa"&gt;João Pessoa&lt;/h2&gt;
&lt;p&gt;&lt;img alt="Debian Day João Pessoa Group Photo" class="markdown-img" src="https://sergiocipriano.com/assets/debianday2026/JP.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;In João Pessoa, we had a two-day event. The first day was dedicated
entirely to workshops, and I ran a packaging workshop for newcomers.&lt;/p&gt;
&lt;p&gt;It was the first time I had been responsible for a workshop, and it
was a great experience. We didn't have a lot of time, so I decided to
start with a 30-minute talk explaining a few things about Debian. For
example, I made this image to explain the packaging workflow:&lt;/p&gt;
&lt;p&gt;&lt;img alt="Debian upload workflow" class="markdown-img" src="https://sergiocipriano.com/assets/debianday2026/debian-upload.png" /&gt;&lt;/p&gt;
&lt;p&gt;This image was based on &lt;a href="https://debian-handbook.info/browse/stable/sect.release-lifecycle.html"&gt;The
Debian Administrator's Handbook&lt;/a&gt;, and I think the participants really
enjoyed learning about this workflow. When I showed the slide with this
image, it was the moment when I received the most questions.&lt;/p&gt;
&lt;p&gt;After the talk, I explained my way of working and what they were
going to do. The hardest part was setting up the environment, since my
approach uses sbuild + gbp. They were running different Debian releases
and, because of my inexperience with workshops, I had some of them
configure sbuild with unshare, even though it is only available in
stable through backports.&lt;/p&gt;
&lt;p&gt;Some of them even managed to learn how to use backports, while others
decided to start again using the "old" way.&lt;/p&gt;
&lt;p&gt;One thing that helped a lot was the &lt;a href="https://debianbrasil.org.br/pt-br/empacotamento"&gt;Debian Brasil
Wiki&lt;/a&gt;. It has all the instructions for configuring sbuild in
Portuguese, along with great examples. The Brazilian wiki is an
opinionated version of the Debian Wiki. We generally prefer to use it
for the convenience of having the exact workflow we follow, as well as
an up-to-date Portuguese version of our process.&lt;/p&gt;
&lt;p&gt;If you want to learn more about the Brazilian community, you can find
more details in the schedules from previous DebConfs. We almost always
had a talk about the community and its activities.&lt;/p&gt;
&lt;p&gt;In the end, everyone successfully set up their development
environment, and all six participants made their first contribution to
Debian. If you take a look at my &lt;a href="https://people.debian.org/~cipriano/uploads/changelogs.html"&gt;upload
tracking page&lt;/a&gt;, you will see that every upload made on August 15,
2026 was a sponsored upload from this event. One of them appear twice in
the list because I sponsored the upload and also made some other
changes.&lt;/p&gt;
&lt;p&gt;I also asked all of them to put this in their changelog:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;* My first contribution!&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The idea was to make it clear to other people that they were only
working on small Lintian issues as a way of learning and understanding
the process. By the way, I made a &lt;a href="https://udd.debian.org/lintian/?email1=team%2Bpython%40tracker.debian.org&amp;amp;email2=team%2Bpkg-go%40tracker.debian.org&amp;amp;email3=&amp;amp;packages=&amp;amp;ignpackages=&amp;amp;format=html&amp;amp;lt_error=on&amp;amp;lt_warning=on&amp;amp;lt_pedantic=on&amp;amp;lintian_tag=redundant-rules-requires-root-no-field#all"&gt;UDD
query&lt;/a&gt; to find packages with the following Lintian tag:
&lt;code&gt;redundant-rules-requires-root-no-field&lt;/code&gt;. To fix this issue,
they only had to remove one line from the &lt;code&gt;debian/control&lt;/code&gt;
file.&lt;/p&gt;
&lt;p&gt;It is obvious that these uploads are not particularly useful. I call
them "motivational uploads" because my goal is to help newcomers
understand the process and immediately give them the reward of having
made a contribution to Debian.&lt;/p&gt;
&lt;p&gt;I'll try to keep in touch with them. My plan is to hold another
session, this time remotetly, to help them continue contributing to
Debian. In fact, I already have another package prepared by one of them
waiting for my review.&lt;/p&gt;
&lt;p&gt;The second day was a full-day event featuring a bunch of talks from
the local community. I gave a talk explaining the new members
process.&lt;/p&gt;
&lt;p&gt;I was the only Debian Developer at the event, and I think having a DD
there made a real difference. Being there to answer questions, and
simply being present, makes Debian feel more tangible and accessible to
people.&lt;/p&gt;
&lt;p&gt;A big shout-out to Rafael Rocha, who put in a lot of work to make
this event happen, with the help of many volunteers who contributed
along the way.&lt;/p&gt;
&lt;h2 id="brasília"&gt;Brasília&lt;/h2&gt;
&lt;p&gt;&lt;img alt="Debian Day talk in Brasília" class="markdown-img" src="https://sergiocipriano.com/assets/debianday2026/DF.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;One thing I really like about Debian Days is that each place has its
own way of doing things. In João Pessoa, we had a MiniDebConf-like
event, while in Brasília, we had something smaller but still very
valuable. We decided to keep things simple: talk to a few students at
the University of Brasília (UnB) and then go somewhere to eat and have a
few drinks.&lt;/p&gt;
&lt;h3 id="a-bit-of-history"&gt;A bit of history&lt;/h3&gt;
&lt;p&gt;For those who don't know, the &lt;a href="https://debconf19.debconf.org/"&gt;DebConf 19&lt;/a&gt; was held in
Curitiba, Brazil. After the event, Arthur Diniz got really excited about
Debian and decided to go back to his University, UnB, to share his
experience and encourage more people to contribute to Debian.&lt;/p&gt;
&lt;p&gt;I attended one of his talks, thanks to Joenio Costa, who invited
Arthur to give the talk. Joenio was also my professor at the time and a
Debian contributor. I really liked what Arthur had to say about free
software, and he did a great job of presenting the Debian community as a
friendly and welcoming place.&lt;/p&gt;
&lt;p&gt;So I decided to attend local meetings of the Debian Brasília
community, which had been inactive for a long time. Lucas Kanashiro was
the Debian Developer who answered our questions and, as I mentioned
earlier, simply being there made Debian feel more tangible.&lt;/p&gt;
&lt;p&gt;Everything stopped when the pandemic began. Then, towards the end of
2020, I saw a message in the Debian Brasília channel saying that the
meetings were back, this time remotely. I was hesitant to join because,
back in 2019, I hadn't managed to make a packaging contribution, even
with their help. I had eventually given up on the process. So this time,
I decided to join the meeting with something already prepared for
review. I watched all of Eriberto's packaging videos, picked a random
package, and joined the meeting.&lt;/p&gt;
&lt;p&gt;I remember Kanashiro being excited that someone had just shown up
with something ready for review. At the time, it was only the second
meeting since Debian Brasília had come back online, and none of the
newcomers had started working on contributions yet.&lt;/p&gt;
&lt;p&gt;During the same meeting, he also convinced us, the newcomers, to give
a talk about Debian just three days later.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://mdcobr2020.debian.net"&gt;MiniDebConf Online Brazil
2020&lt;/a&gt; was happening on Sunday, and the meeting was on the Thursday
before it. Since he has great convincing skills, I went along with the
idea and &lt;a href="https://mdcobr2020.debian.net/talks/10-um-raio-x-do-debian-brasilia-pequenas-acoes-que-transformaram-uma-comunidade-nacional/"&gt;prepared
the talk&lt;/a&gt; with Francisco Ferreira.&lt;/p&gt;
&lt;p&gt;That was the rebirth of the Debian Brasília community.&lt;/p&gt;
&lt;p&gt;Since then, we have maintained a close connection with the University
of Brasília, and today, at least seven Debian Developers are from UnB,
whether as former students or former professors.&lt;/p&gt;
&lt;p&gt;The reason I told this story is that, even though the Debian Day we
held in Brasília was smaller, it is part of something that has been
working for us for several years: staying close to an University. We've
managed to attract and retain many people who share the same values and
interests.&lt;/p&gt;
&lt;p&gt;I've hope you all had a great Debian Day. If you're reading this and
aren't part of the Debian community but would like to join, get in
touch!&lt;/p&gt; </description> 
	<pubDate>Sun, 23 Aug 2026 18:22:15 +0000</pubDate>

</item> 
<item>
	<title>Colin Watson: GSS-API support split out from main Debian OpenSSH packages</title>
	<guid>tag:www.chiark.greenend.org.uk,2026-08-23:/~cjwatson/blog/openssh-gssapi-split.html</guid>
	<link>https://www.chiark.greenend.org.uk/~cjwatson/blog/openssh-gssapi-split.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/cjwatson.png" width="70" height="82" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;In an &lt;a href="https://lists.debian.org/debian-devel/2024/04/msg00044.html"&gt;option review&lt;/a&gt; I did in 2024, shortly after the &lt;a href="https://en.wikipedia.org/wiki/XZ_Utils_backdoor"&gt;xz-utils backdoor&lt;/a&gt;, I explained that having &lt;span class="caps"&gt;GSS&lt;/span&gt;-&lt;span class="caps"&gt;API&lt;/span&gt; authentication and key exchange support in the main OpenSSH packages is problematic.  The key exchange patch is large and intrusive.  Furthermore, even linking to the necessary libraries is not without risk: as the &lt;a href="https://attack.mitre.org/software/S0377/"&gt;Ebury malware attack&lt;/a&gt; demonstrated way back in 2009, each extra library linked into security-critical daemons such as &lt;code&gt;sshd&lt;/code&gt; (or nowadays into its privilege-separated helper programs) can modify the behaviour of the daemon even if you aren’t doing anything that would involve calling into that library.  Of course some of that risk remains, but as &lt;a href="https://lists.debian.org/debian-devel/2024/04/msg00045.html"&gt;Damien Miller wrote&lt;/a&gt;, minimizing the number of libraries that end up in the address space of &lt;code&gt;sshd&lt;/code&gt; and friends is still valuable.&lt;/p&gt;
&lt;p&gt;I just uploaded openssh 1:10.4p1-5 to unstable, completing this split.  As of this version, the OpenSSH client and server are built without &lt;span class="caps"&gt;GSS&lt;/span&gt;-&lt;span class="caps"&gt;API&lt;/span&gt; authentication and key exchange support.  If you need those features, install &lt;code&gt;openssh-client-gssapi&lt;/code&gt; or &lt;code&gt;openssh-server-gssapi&lt;/code&gt; instead, as appropriate.  Debian 13 (trixie) already has packages with those names that just depend on the regular &lt;code&gt;openssh-client&lt;/code&gt; and &lt;code&gt;openssh-server&lt;/code&gt; so that you can pre-emptively install them, as &lt;a href="https://www.debian.org/releases/trixie/release-notes/issues.en.html#deprecated-components-for-releasename"&gt;documented in the release notes&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The new &lt;code&gt;openssh-*-gssapi&lt;/code&gt; packages have relatively tight dependencies on &lt;code&gt;openssh-common&lt;/code&gt;, in order for the testing migration system to ensure that we can’t forget to keep them up to date.  This will mean a bit more ongoing work for me on each new upstream version, but I think it will be manageable.&lt;/p&gt; </description> 
	<pubDate>Sun, 23 Aug 2026 17:16:11 +0000</pubDate>

</item> 
<item>
	<title>Iustin Pop: Another optimistic take on AI</title>
	<guid>https://k1024.org/posts/2026/2026-08-23-another-optimistic-take-on-ai/</guid>
	<link>https://k1024.org/posts/2026/2026-08-23-another-optimistic-take-on-ai/</link>
     <description>  &lt;h2 id="disclaimers"&gt;Disclaimers&lt;/h2&gt;
&lt;p&gt;The current discussion in Debian aroun the AI GR is very heated, and I won’t add
to that, however, I am very confused about some of the viewpoints there. But, I
had no idea how to even try to write this, so did shut up, until I saw Aigars’
excellent &lt;a href="https://aigarius.com/blog/2026/08/22/optimistic-take-on-ai/"&gt;Optimistic take on
AI&lt;/a&gt;, which
motivated me to try, at least. For the record, I fully subscribe to the post,
and to the voting suggestions (and I just voted).&lt;/p&gt;
&lt;p&gt;Also, for full disclosure, I don’t think I did any contribution to Debian until
now using AI, neither packaging, nor emails, nor bug reports. And this blog post
specifically is 100% hand written.&lt;/p&gt;
&lt;p&gt;With that out of the way… there are two points I want to make in this post.&lt;/p&gt;
&lt;h2 id="ai-is-useful-even-if-it-has-risks"&gt;AI &lt;em&gt;is&lt;/em&gt; useful, even if it has risks&lt;/h2&gt;
&lt;p&gt;First is, that even if we could put the genie back in the metaphorical bottle,
we should not. We do need to continue working towards safe AI, and efficient AI
(less environmental impact), but we should not work towards removing the usage
of AI. There are already significant advancements in sciences and technology
thanks to the use of AI, so desiring AI to not exist (assuming we had a magical
wand) is the wrong approach.&lt;/p&gt;
&lt;p&gt;Sure, AI has significant risks — and I can see ways in which AI can do
significant damage to society — but I don’t think we can go from Kardashev I to
II without the use of AI, and definitely not to III. And I think, that should be
the goal.&lt;/p&gt;
&lt;p&gt;A few simple examples: Do we want to rollback all the 20 years old security
issues that AI found? Do we want to rollback the recent Moderna cancer findings?
Do we want to rollback the concept of “extremely large scalle pattern
matchings”, just because it runs on chips and no longer in one person’s head?&lt;/p&gt;
&lt;h2 id="reading-debian-lists"&gt;Reading Debian lists&lt;/h2&gt;
&lt;p&gt;The second point is, lately I found less and less enjoyment in reading Debian
lists. Even with that already being the case, I feel soo disconnected from many
of the opinions being voiced in this discussion.&lt;/p&gt;
&lt;p&gt;On one hand, it’s normal and healthy that people have different opinions,
disagree, and move foward.&lt;/p&gt;
&lt;p&gt;On the other hand, looking at one of the proposed options:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;“Moderators and disciplinary teams may make narrow and tailored exceptions to
rule 4, and decide on interpretation”.&lt;/li&gt;
&lt;li&gt;“Violations of these requirements should be treated as violations of the
relevant Code of Conduct and should result in swift and proportionate
disciplinary action”.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I already knew Debian, and some large parts of the OSS world, is left leaning.
But those phrasings, to me, are too close to socialism/communmism. As someone
who grew up under communism, this is a much more slippery slope (disciplinary
teams? really?) than AI usage. Ask me in person for more details.&lt;/p&gt;
&lt;p&gt;So, it is possible that Debian continues to evolve in such a way that I don’t
find myself in any way close to its ongoing culture. I will be sad at that
point, but it will be what it is.&lt;/p&gt;
&lt;h2 id="where-to"&gt;Where to?&lt;/h2&gt;
&lt;p&gt;I think that, until such a time that an AI bubble bursts, what any organisation
should do is try to logically see where and if AI can help. And in an
organisation that is about computer software, I see hundreds of places that are
subject to very large scale pattern matching… so the half of the discussion is,
to me, mind-boggling.&lt;/p&gt;
&lt;p&gt;To be clear, it’s not about “if you can’t beat them, join them”. As I wrote
above, I think AI is useful, so the point is how to use it effectively.&lt;/p&gt;
&lt;p&gt;Well, will see what Debian votes. I am half curious, half sad alreay.&lt;/p&gt; </description> 
	<pubDate>Sun, 23 Aug 2026 16:19:40 +0000</pubDate>

</item> 
<item>
	<title>Wouter Verhelst: Programming and GR 2026 002</title>
	<guid>https://grep.be/blog//en/computer/debian/Programming_and_GR_2026_002/</guid>
	<link>https://grep.be/blog//en/computer/debian/Programming_and_GR_2026_002/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/wouter3.png" width="85" height="80" alt="" align="right" style="float: right;"&gt;  &lt;h2 id="programminglanguagegenerations"&gt;Programming language generations&lt;/h2&gt;

&lt;p&gt;When I was young, I learned about a model of classifying programming
language: the system of programming language generations.&lt;/p&gt;

&lt;p&gt;In this model, first generation programming languages are, basically,
where you program the computer in the language that is defined by its
architecture. On a &lt;a href="https://en.wikipedia.org/wiki/Von_Neumann_architecture"&gt;Von Neumann
machine&lt;/a&gt;, with
its load-and-store architecture, you do that by inputting a string of
numbers. The first programmer in human history -- her name was &lt;a href="https://en.wikipedia.org/wiki/Ada_Lovelace"&gt;Ada
Lovelace&lt;/a&gt; -- wrote in a
first-generation language. 1GLs aren't so much invented as they are a
byproduct of the computers for which they're created.&lt;/p&gt;

&lt;p&gt;Second-generation languages are the assembler languages. Because humans
are not computers, and because decoding long lines of numbers to
understand what the computer is doing, when programming became a
full-time job, the programmers that did it decided that doing all this
assembling manually is too complicated, so they quickly wrote assemblers
to automate the process for them. They still could understand the 1GL
output of the 2GL assembler, but most of them quickly forgot how to
write software in a first-generation language. Not that anyone cared, as
the translation from a 2GL to a 1GL is lossless and you can just revert
it.&lt;/p&gt;

&lt;p&gt;Third-generation languages are higher-level languages. When the first
3GLs were invented (such as &lt;a href="https://en.wikipedia.org/wiki/COBOL"&gt;COBOL&lt;/a&gt;
and, more famously, &lt;a href="https://en.wikipedia.org/wiki/FORTRAN"&gt;FORTRAN&lt;/a&gt;) in
the late 1950s and early 1960s, it was believed by some that the work of
programming a computer so accessible to non-programmers that the job of
programmer would eventually cease to exist, and people would just ask
the computer what they needed by entering COBOL instructions. This of
course was ridiculous and incorrect, because converting algorithms to
computer instructions, whether at the 2GL or 3GL level, is a specialized
skill that some automation can perhaps make simpler but never completely
take away the need for. At the time, some people also felt to some
extent that &lt;a href="https://en.wikipedia.org/wiki/The_Story_of_Mel"&gt;using 3GL wasn't the same thing as actually programming
3GLs&lt;/a&gt;, but eventually
the world moved on and embraced things. The invention of 3GL
environments reduced, but did not completely take away, the need for
people to understand 2GLs, as compiler and operating system authors
still need to understand them, and some highly optimized code still
continues to be written in 2GLs to this day.&lt;/p&gt;

&lt;p&gt;Fourth-generation languages abstract away some or all of the process of
programming. For instance, a database-related 4GL will hide away the
complexities of storing data in particular locations, how to fetch that
data, how to index it such that you can fetch it efficiently, how to
loop over the data to get you a summary of that data, and instead allows
you to express the required information in an abstract way, expecing the
computer to fill in the blanks. When SQL, an early 4GL, was invented,
some people believed that the language made accessing databases so
simple that the requirement to implement database applications would
eventually cease to exist and we would just hand SQL prompts to users
who need to access data. This of course was ridiculous and incorrect,
because understanding data schemas and using that understanding to query
data from a database is a specialized skill that perhaps a higher
abstraction can help you make simpler, but that in the longer run it can
never completely take away the need for. The invention of 4GLs also
reduced, but did not completely take away, the need for people to
understand how to do the things that the 4GLs automate for you manually,
as the people who do write those things still need to understand them,
and there are also environments where these particular 4GLs are rather
not appropriate or just very slow.&lt;/p&gt;

&lt;p&gt;The first definition of programming language generations that I read
about in the 1980s simply stated that fifth-generation languages did not
yet exist, but that they would in the future, and that in those, you
would "tell the computer what to do, and it would then do that". Now
that &lt;a href="https://en.wikipedia.org/wiki/Large_language_model"&gt;we have a way of doing
so&lt;/a&gt;, it could be
said that by some definition, we now actually do have a number of 5GLs.
The existence of these LLM systems has caused some, especially the
people who build and exploit these systems, to exclaim that programming
as we know it today is going to cease to exist, and everyone will just
ask an LLM to generate a program, which will then do so. That is of
course ridiculous and incorrect, as no automaton can generate software
from nothing; input is still required for the model to be able to
produce something that approaches usability, and being able to word that
input in a correct and productive fashion will be a skill that future
programmers can benefit from. I ran &lt;a href="https://grep.be/blog/en/computer/Agentic_coding_and_Free_Software/"&gt;some
experiments&lt;/a&gt;
a while back, and from that concluded that, if we look only at the
technical side, LLM use can, in some niches, increase productivity for a
programmer. There are certainly things that you shouldn't use an LLM
for, but equally there can be cases where use of an LLM to perform some
task that traditionally would have been done by a programmer would be a
net positive.&lt;/p&gt;

&lt;p&gt;But LLMs, as they exist today, are highly problematic.&lt;/p&gt;

&lt;p&gt;They require vast amounts of data to build the model. The companies that
build these models are disrespectful of people who run web services, and
as a result, everyone now has to implement various types of application
firewalls just to not make systems fall over from the overwhelming
requests for data. They are also disregarding the licenses that are
attached to these vast amounts of data, which makes me, as a person who
believes in the tenets of free software, sad.&lt;/p&gt;

&lt;p&gt;They require vast amounts of energy, causing an already-critical global
warming crisis to, well, not improve.&lt;/p&gt;

&lt;p&gt;They require vast amounts of coolant to dissipate the energy
concentrated in their data centers, causing further environmental
effects.&lt;/p&gt;

&lt;p&gt;In this, they are problematic and to be avoided. But these are side
states of the current state of affairs; I do not believe that they are
inherently implied to be able to build and operate an LLM -- &lt;em&gt;any&lt;/em&gt; LLM.&lt;/p&gt;

&lt;p&gt;I guess it's fair to say that my feelings towards LLM usage are complex
and many-faceted. I haven't been involved in many debates about the
subject, debates that to me seem to be mostly focused on "LLM good" vs
"LLM bad" arguments that aren't as nuanced as the position that I would
believe is more accurate. This is not because I don't care, but
partially because I've been busy in my personal life recently and
partially because the whole thing seems somewhat disheartening.&lt;/p&gt;

&lt;p&gt;But then Debian popped up &lt;a href="https://www.debian.org/vote/2026/vote_002"&gt;GR
2026-002&lt;/a&gt;, meaning, I now
have to come up with an opinion about various candidate statements in
the context of the above, which is... not easy. But I did it anyway.&lt;/p&gt;

&lt;p&gt;There are 8 choices on the ballot, and they all have some truth and some
falsehood to them. My position about LLMs can be summarized as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The current state of affairs wrt LLMs is disastrous and we should not
encourage them&lt;/li&gt;
&lt;li&gt;However, there's no &lt;em&gt;technical&lt;/em&gt; reason why this must remain true for
all time&lt;/li&gt;
&lt;li&gt;And so any statement should keep in mind what might happen in the
future and that the current disastrousness of the whole thing isn't
guaranteed to continue to exist for all eternity.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;With that, let's go over them.&lt;/p&gt;

&lt;h2 id="grvoteoptions"&gt;GR vote options&lt;/h2&gt;

&lt;h3 id="proposala"&gt;Proposal A&lt;/h3&gt;

&lt;p&gt;Its summary, from the GR text:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;This proposal aims to expressly forbid any contributions to Debian
  written with the use or assistance of large language models (LLMs) or
  other generative AI tools.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This falls squarely in the "LLM bad" camp, outlawing all generative-AI
contributions, disregarding potential future ones where the problematic
situations that exist today are not present.&lt;/p&gt;

&lt;p&gt;It makes a change to the social contract, which is especially difficult
to reverse (on purpose), and which therefore also will require a 3:1
supermajority, but if we want to ban LLM-assisted contributions, this is
probably the best way to do it.&lt;/p&gt;

&lt;h3 id="proposalb"&gt;Proposal B&lt;/h3&gt;

&lt;p&gt;This one tries to allow AI-assisted contributions under certain
conditions. It's mostly an "LLM good" proposal, with some caveats that
can be discribed as "make sure you know what you're doing".&lt;/p&gt;

&lt;h3 id="proposalc"&gt;Proposal C&lt;/h3&gt;

&lt;p&gt;This proposal is both a weaker (in some places) and stronger (in other
places) version of Proposal A. It makes changes to the code of conduct
instead of to the social contract, and it also wants to, at least,
&lt;em&gt;suggest&lt;/em&gt; policy to parties beyond the Debian project. By not changing
the social contract, however, it is more likely to reach its simple
majority requirement than proposal A.&lt;/p&gt;

&lt;p&gt;I don't think the language that it wants to add to the code of conduct
is particularly well phrased, however.&lt;/p&gt;

&lt;h3 id="proposald"&gt;Proposal D&lt;/h3&gt;

&lt;p&gt;This is a weaker form of proposal B. The language is more compact and
there are a few requirements that are spelled out in proposal B that are
not spelled out in proposal D, but if you read between the lines you'll
see that the requirement is still there really and I don't understand
why proposals B and D were not merged into one.&lt;/p&gt;

&lt;h3 id="proposale"&gt;Proposal E&lt;/h3&gt;

&lt;p&gt;This proposal tries to hold a middle ground between "LLM good" and "LLM
bad". It appreciates that things are quite muddled at the present time,
and that perhaps the situation might might change in the future. It
acknowledges that certain questions remain unanswered and that perhaps
future considerations might therefore be different. But it essentially
refuses to take a stance on whether LLMs should be accepted by the
project or not.&lt;/p&gt;

&lt;h3 id="proposalf"&gt;Proposal F&lt;/h3&gt;

&lt;p&gt;Similar to proposal E, this proposal tries to discourage Debian
contributors from using LLMs, while still allowing people to use it
should they want to, but with some requests and requirements to mark
LLM-assisted contributions to account for those people who don't want to
interact with LLM-generated software. As such, it is a proposal similar
to proposal E that leans closer to the "LLM bad" camp.&lt;/p&gt;

&lt;h3 id="proposalg"&gt;Proposal G&lt;/h3&gt;

&lt;blockquote&gt;
  &lt;p&gt;This proposal aims to ensure that contributions directly to Debian are
  created by humans, while at the same time avoiding restrictions on the
  tools those humans may choose to use when contributing&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Another "LLM bad" proposal, it however restricts the "bad" bits to only
the &lt;em&gt;direct&lt;/em&gt; output of the LLM. If you use an LLM to do something and
then clean-room re-implement the same thing yourself, that's apparently
fine.&lt;/p&gt;

&lt;h3 id="proposalh"&gt;Proposal H&lt;/h3&gt;

&lt;p&gt;This proposal condemns the use of LLM for its environmental and moral
problems, but explicitly not for its technical considerations. I feel
that it is closest to my position as explained above.&lt;/p&gt;

&lt;h2 id="voting"&gt;Voting&lt;/h2&gt;

&lt;p&gt;Expressing a vote on a ballot so convoluted and complicated like this
one takes time. I have to read and understand every ballot option, and
formulate an order of them.&lt;/p&gt;

&lt;p&gt;And I shouldn't &lt;em&gt;just&lt;/em&gt; state which option has my preference; Debian's
voting process allows a rich expression of opinion on ballot options.&lt;/p&gt;

&lt;p&gt;Anyway, I eventually ended up voting in a way that I think is consistent
with my opinion. But it wasn't easy.&lt;/p&gt; </description> 
	<pubDate>Sun, 23 Aug 2026 14:02:13 +0000</pubDate>

</item> 
<item>
	<title>Aigars Mahinovs: Optimistic take on AI</title>
	<guid>http://aigarius.com/blog/2026/08/22/optimistic-take-on-ai/</guid>
	<link>http://aigarius.com/blog/2026/08/22/optimistic-take-on-ai/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/aigarius_hg.png" width="85" height="116" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;As I am writing this, there is a &lt;a href="https://www.debian.org/vote/2026/vote_002"&gt;vote&lt;/a&gt; ongoing in the Debian
project on how to deal with AI in general and AI-assisted contributions to Debian specifically. Massive discussions
have happened in &lt;a href="https://lists.debian.org/debian-vote/"&gt;debian-vote&lt;/a&gt; and other locations. I have also asked
questions there and offered my perspective. IMHO now is the time to summarize that, after all the discussions
that I've had with people on multiple sides of this debate both online and offline, and explain how I will be
voting and why. Hopefully that will be helpful to someone else as well. None of this has been compiled with AI
assistance, but only because I think that forming opinions is not something where AI can really be helpful.
Spellcheck was used though.&lt;/p&gt;
&lt;p&gt;So, first I will describe how I see each of the 8 proposals, then what my vote will be, and then a bit more
detail on the reasoning and thinking behind this. WARNING - this went &lt;em&gt;long&lt;/em&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Proposal A(1) - Action: ban all AI-assisted contributions via Social Contract amendment, except from upstreams
 (so not rolling back the Linux kernel and other software to "pure", pre-AI state). Claims that copyright/licensing
 status is unclear, quality is bad, community is being destroyed, web resources see extra load and that training
 consumes "staggering" resources. Needs 2/3rd majority to pass. - IMHO worst and most inconsistent. If copyright
 and licensing of AI products &lt;em&gt;is&lt;/em&gt; unclear, then be consistent - ban ALL software with AI contributions, fork Linux
 kernel and other software from pre-AI versions, reject all security fixes of issues found with AI. Quality section
 lists problems that have not existed in the real world since at least a year of rapid AI coding development. Community
 section assumes that now all Debian contributions will be drive-by AI slop and no one will learn anything anymore.
 Ethics section mixes up effects of badly configured systems (AI web load is no different from load from a badly
 configured Perl script) with claimed "resource" usage without any context, taking on trust project ambitions of
 startups and assuming exponential growth. And then concludes that delivering less is in the interest of our
 users somehow.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Proposal B(2) - Action: allow AI-assisted contributions, with conditions of: legality, accountability, disclosure,
  no uncoordinated bulk actions, privacy. Concerns on quality and legal status as well as environmental impact
  and scraper load are noted, but not really addressed beyond labelling them as concerns. - IMHO it is an ok starting
  position as it establishes that each contributing &lt;em&gt;person&lt;/em&gt; must still be fully responsible for &lt;em&gt;their&lt;/em&gt;
  contribution (both legally and technically) and for that has to also understand (and review) what they submit.
  Disclosure lets others know to watch out for other classes of problems when code was changed with AI assistance.
  Prior discussion for bulk changes just says that the (already established) practice should not be neglected
  just because now large changes are easier to do. And the privacy part warns against accidentally sending private or
  confidential data (like a not yet published security bug) to a public service where it could become public.
  Personally I would have liked a stronger statement to encourage use of environmentally responsible AI services
  and local AI tools. Possibly a preference for open-weight models with a clear path forward to preferring truly
  free AI models, when such a category of products could be clearly delineated and established.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Proposal C(3) - Action: reject AI-assisted contributions at Code of Conduct level. Claims all the world's evils come
  from LLMs and that "Ethical and safe use of this technology is almost impossible". Goes as far as banning any
  use of LLMs even in Debian mailing list emails and Debian Planet blog posts - if you do, it's a CoC violation
  and may result in exclusion from the project. Additionally &lt;em&gt;mandates&lt;/em&gt; the disclosure of the usage ... presumably
  to ban you more efficiently for it. - IMHO truly a dictatorial nightmare option. Zero actual reasoning or
  basis for such a decision. Zero sources. Nothing claimed in this option's rationale is even close to reality and
  nothing claimed there is in any way related to the actual technology being discussed. Like, an "LLM" does not
  automagically commit "fraud" when you use it, like this proposal claims, as if that was a well-known fact.
  LLMs are not all "owned by horrible people and companies". Even if some include a (prominent Debian user,
  long-time supporter and sponsor) Google into "horrible companies" (which is what this proposal implies!),
  there are plenty of LLMs owned by all kinds of companies all over the world and there are plenty of open-weight
  LLMs that are not really owned by anyone. Most invasive and dishonest option on the ballot.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Proposal D(4) - Action: allow AI-assisted contributions, with conditions of: legality, accountability,
  disclosure, privacy. IMHO same as B, just shorter. Adds a "we don't recommend" towards others developing software
  with AI assistance. Seems pretty weird to add that and then immediately accept Debian contributors doing so.
  Assumes that the bulk change bit of B is implied as AI is just tooling, so bulk changes should be pre-discussed
  just like today - so no change and thus no point in mentioning that. Fair. D is a bit more explicit on expected
  technical details - like that the "person" submitting the change is supposed to sign it, not AI. Notable is
  the complete absence of resource usage or the environment from concerns. IMHO it would be better to have that
  and also recommendations on how to avoid causing environmental damage when using AI.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Proposal E(5) - Action: no action as such - AI-assisted contributions must follow the same rules as all other
  contributions and those rules are sufficient. IMHO despite its length this is a very well-worded position
  statement that describes how and why AI-assisted contributions already work perfectly fine in the Debian context
  when &lt;em&gt;all&lt;/em&gt; the same rules that apply to all contributions are also consistently applied to AI-assisted
  contributions. It describes how the same legality, accountability, no bulk change and privacy requirements
  are already in place and still apply and how AI-assisted contributions can and must still satisfy them. I could
  add again that some guidance would be nice here for both legal and environmental decisions when using AI,
  but in this case it does not really belong in this proposal itself. We as Debian do not have a document that
  requires that our non-AI-assisted contributions be made with only sustainably sourced electricity, for example.
  So why should AI be special one way or another? IMHO Debian &lt;em&gt;should&lt;/em&gt; have a datacenter sustainability policy,
  regardless of the AI discussion.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Proposal F(6) - Action: discourage AI, but allow it based on existing processes (similar idea to E). Dances a bit
  around the question of disclosure of AI use (as a courtesy) and accepting that some people may still ban
  all contributions where any AI was involved in any way. Which in turn discourages disclosure to avoid pointless
  rejection of valuable contributions (like security patches). IMHO this option is ok, but so watered down that
  it is bound to bring up further discussions and conflicts on details.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Proposal G(7) - Action: ban non-humans from &lt;em&gt;directly&lt;/em&gt; contributing to Debian. IMHO - another bizarre and
  self-contradictory option. It bans &lt;em&gt;all&lt;/em&gt; Debian interactions with AI assistance, including email messages to
  Debian mailing lists and (supposedly) blog posts on Planet Debian. It "reminds" people who "use such tools
  assistively" of the DFSG and Social Contract - isn't that a threat of a ban and expulsion similar to C? The
  proposal does take pains to delineate where a contribution comes from AI as output (bad) vs when you are
  assisted by AI in the process of exploring, researching or maybe even reviewing the code, but you
  actually type all the code yourself and use the AI just as a taskmaster with a whip (good). And just like A
  or C it completely ignores how this inherently evil and unstable AI-generated code becomes perfectly fine and
  good as soon as someone develops that &lt;em&gt;outside&lt;/em&gt; of the Debian project. Even if the same person then packages
  it for Debian the next day. It is hypocritical, unsustainable and ignores the needs of our users. Just like
  C it also bans someone writing an email or bug report in their native language and using a modern translation
  tool or service (that uses LLMs nowadays for better grammatical clarity) to translate that to English before
  sending it to a Debian mailing list or BTS. Heavy-handed and invasive. And the only reasoning provided
  for this is some unnamed "concerns" of "extra work" being borne by "other people"? Kind of does not feel
  right to bear such draconian restrictions for some unspecified concerns.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Proposal H(8) - Action: &lt;em&gt;condemn&lt;/em&gt; usage, but not &lt;em&gt;actually&lt;/em&gt; ban anything. And then it goes on to claim
  (without any evidence or elaboration) that LLM usage accelerates the destruction of "planet earth" (sic).
  IMHO this proposal is at the same time the loudest ("The planet is burning") and also the one that demands the
  &lt;em&gt;least&lt;/em&gt; action. It dances a really twisty line between raising "significant" concerns in all areas and even
  claiming that use of LLMs destroys the planet, flies by explicit condemnation of LLM usage and then suddenly
  collapses with not condemning LLM users and swinging to lamentations that it is actually impossible to impose
  policies on LLM usage or even detect when an LLM was used (which kind of directly contradicts bad quality
  claims from A, C and G) and lands on "encouraging" contributors not to use LLMs (where practical) and otherwise
  do nothing else. It's like this is a 5th draft that started off with the rationale and total ban like in C,
  but then got defanged so far that its action side no longer matches the rationale stated.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With all the above considered I will vote like this (earlier options are preferred over later options):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Proposal E(5) - solid &lt;em&gt;hack&lt;/em&gt; of integrating AI into already existing Debian rules and conventions&lt;/li&gt;
&lt;li&gt;Proposal B(2) - explicit and detailed&lt;/li&gt;
&lt;li&gt;Proposal D(4) - lower because of discouragement to others on what we agreed to do ourselves&lt;/li&gt;
&lt;li&gt;Proposal F(6) - I am not a fan of dancing around with disclosures&lt;/li&gt;
&lt;li&gt;Further discussion(9) - I do not want any option below this to succeed as they would do more harm than good&lt;/li&gt;
&lt;li&gt;Proposal H(8) - loud, but not doing anything actually&lt;/li&gt;
&lt;li&gt;Proposal A(1) - at least this one does not set rules for emails&lt;/li&gt;
&lt;li&gt;Proposal G(7) - at least this one allows an AI overseer to tell you what to write with your own fingers&lt;/li&gt;
&lt;li&gt;Proposal C(3) - the most draconic and invasive one that explicitly wants to kick people out of the project&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Details on rationale&lt;/p&gt;
&lt;p&gt;Hypocrisy - I find &lt;em&gt;any&lt;/em&gt; proposal that would ban AI-assisted contributions to Debian, but at the same time &lt;em&gt;not&lt;/em&gt;
ban including AI-assisted contributions from upstream projects to be inherently hypocritical. If LLMs
and AI are the very incarnation of evil (a puppy-killing machine, as the analogy went in some emails), then
any rational proposal would involve excluding any and &lt;em&gt;ALL&lt;/em&gt; code contaminated by this evil from the project. What
does it matter if puppies were killed in writing the debian subfolder of the source code or the src subfolder?
No proposals went there because everyone knows that such a ban would be the death of the relevance of the project
for the future. Debian would be frozen on some old version of the Linux kernel forever and other software would be
falling to the same problem too, for example as projects on GitHub start enabling AI-supported reviews with patch
suggestions. Soon the "development" of Debian could just be stopped as there is nothing to develop without any
upstreams.&lt;/p&gt;
&lt;p&gt;Assumptions - a lot of proposals mention various "concerns" with at most one word, like "practical" or "community"
without an explanation of what &lt;em&gt;exactly&lt;/em&gt; they mean by that. The proposers assumed that everyone lives in the same info
bubble as they do and already know everything that they mean and already agree to that. That is false.
Proposal A was a positive stand-out in this area. Debian has contributors all over the world with very different
exposure to different information sources and very different world views. If you want to convince the project as a
whole that LLMs are bad because of "ethics", then you &lt;em&gt;do&lt;/em&gt; really need to explain what you mean by that and give
links to sources, at least as well as Proposal A did. All other proposals were really weak in this area.&lt;/p&gt;
&lt;p&gt;Copyright - the question on how copyright law interacts with training LLMs and their outputs is still not settled
law. The closest legal statements we have so far are that - just because an LLM is trained on copyrighted material
does &lt;em&gt;not&lt;/em&gt; make that LLM itself be a derivative work of the training data (you, however, cannot just create and
distribute a "library" of copyrighted materials just because you plan to train LLMs on it). The output of the LLM
&lt;em&gt;might&lt;/em&gt; not be subject to copyright law at all, like a photo taken by a monkey. It would then be public domain and
thus can be modified and then licensed by the user of the LLM. It &lt;em&gt;might&lt;/em&gt; also be a derived work of the &lt;em&gt;context&lt;/em&gt;
of the inference (so for software - if you refactor a GPL project, the refactoring itself is likely GPL too).
Any stricter interpretations would break a lot of existing copyright doctrine, such as raising questions like:
"does the output of any programmer now become a derived work of the programming manual books they read in college?".
In any case it is really not up to Debian to legislate the nuances of copyright law. And I strongly disagree with
the concept that an author can tell me how I am allowed to use the learnings that I gained by reading their work.
That is not how either copyright or society works. I can look at 10 pictures of a sunset and draw my own,
inspired by the ones I saw. No one can forbid me that expression. The same must be true for a machine learning and
replicating patterns.&lt;/p&gt;
&lt;p&gt;Ethics - I've re-read all proposals and emails and the only real specifically ethical concern I could find was
the complaint that some LLMs (or their training farms) are running their web scrapers too aggressively and that
causes extra load on services. Like that is not an LLM problem. Scraping the web is not an inherent part of
the LLM training or inference process. It's just a few misconfigured scripts. We saw the exact same thing in the
early days of web search engine proliferation. Then we banned/blocked the misconfigured engines and the
survivors learned that obeying robots.txt is one of the rules for surviving. Literally the exact same problem
and it will be solved the same way. Did we ban all search engines back then just because some of them were
misconfigured? No.&lt;/p&gt;
&lt;p&gt;Some claims (like in Proposal C) are just bombastic hyperbole ("hazards to users' mental health", "fraud", ...)
and on top of that have zero relevance to the topic at hand - AI-assisted contributions to Debian. What
"hazard to users' mental health" is created when a Coderabbit spots that a lock is not taken before accessing
a resource in a particular function and suggests an AI-generated patch to fix it? What "fraud" is committed by
this? There is no sane answer. I get that some people are very busy fighting some culture wars and sometimes,
some AI-bros happen to be on the other side of one such war, so it is useful to label everything coming
from the AI sphere as "bad" in all possible and impossible ways. You do you. In private. Why pull Debian into
that? Why force your position on everyone else in the project? Why deny everyone in the project access to
useful tooling, just because you have strong feelings about some of the people promoting some of those tools?&lt;/p&gt;
&lt;p&gt;This seems to me a repeating pattern here - blaming the technology as a whole or blaming &lt;em&gt;all&lt;/em&gt; providers
of this type of technology for failings (ethical or technical) of &lt;em&gt;some&lt;/em&gt; of those providers. Like refusing
to wear &lt;em&gt;all&lt;/em&gt; shoes and condemning all shoemakers and sellers, just because &lt;em&gt;some&lt;/em&gt; American billionaires figured
out a way to make and sell cheap shoes by killing puppies. Not refusing and condemning &lt;em&gt;those&lt;/em&gt; providers,
but condemning &lt;em&gt;all&lt;/em&gt; for the actions of a &lt;em&gt;few&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Resource usage - this is a big topic for many and it has reasonable points to it. The LLM and AI technology
has no &lt;em&gt;inherent&lt;/em&gt; need to be damaging to the environment in any way for it to function. It does not need to
burn oil or dig up cobalt. It does not need to sacrifice a ton of water to the Gods. It is perfectly
possible to run AI (both inference and training) purely from green, electrical energy and cool data centers
in equally sustainable ways, like with simple air-source heat pumps (also known as air conditioning) or even
use it beneficially (many data centers are used for heating surrounding buildings via district heating).
However, &lt;em&gt;some&lt;/em&gt; AI companies &lt;em&gt;do&lt;/em&gt; use non-green power for their data centers, some do use locally-limited
fresh water for evaporative cooling (evaporated water still rains down as rain, it is not really lost, but
that may happen in another location so lack of water can still happen locally). Some even run unlicensed
natural gas turbines in their data centers to provide them with power. And those specific providers can
and should be shunned and condemned. Not the other ones, who are doing the right things. Not the technology
or its users or its outputs.&lt;/p&gt;
&lt;p&gt;There is a &lt;em&gt;very&lt;/em&gt; wide spectrum of options on how an AI system could be powered: starting from local execution
on already existing private hardware powered by one's own local solar power (good), to a data center stuffed with
borrowed AI-only cards powered by a gas turbine or coal power station that operates &lt;em&gt;solely&lt;/em&gt; to supply this
data center (bad). Proposals that talk about ecological impact, but do not even consider where on that (very
wide) spectrum to draw the line between "good", "acceptable", "discouraged" and "bad" — well, I cannot see
those proposals being &lt;em&gt;actually&lt;/em&gt; serious about the environment to begin with. It feels like they just refer
to it for points.&lt;/p&gt;
&lt;p&gt;And if we go into the power question deeper, well the grid dynamics and economics become very, very complex and
often also non-intuitive. Like, all large software companies with data centers (that also happen to provide
AI services), like Google, Meta, Apple, Microsoft and others do actually care about sustainability (in part
because their customers care and vote with their wallets) and so all of them use 100% green energy for their
data centers (including AI data centers) .... "on an annual scale". Wait, what does &lt;em&gt;that&lt;/em&gt; mean?
Well, the electrical grid is special - the amount of electricity produced and consumed on the whole electrical
grid together has to match almost exactly every &lt;em&gt;second&lt;/em&gt;. If there is just a single second where there is
significantly more energy consumed from the grid than is produced, the frequency will plummet and you get
a brownout and risk a grid collapse. The same is true in reverse - that causes a voltage swell. So grid operators
manage energy flows every second and command power stations to increase and decrease generation all the time.
Some power stations are easier to regulate dynamically than others. In the end, all that means is that
even if your data center has a contract for 100% green energy with your power company, at &lt;em&gt;some&lt;/em&gt; seconds
across the year there might not be enough green energy in the grid to fully supply ALL people and companies
that have 100% green energy contracts. This gets compensated in other seconds, so that across the year
("on an annual scale") for each kWh that your data center pulled from the grid, the same amount of kWh of
100% green energy flows into the grid. But it &lt;em&gt;might&lt;/em&gt; not happen at the exact same second. Pedantic
companies, like Google, take that discrepancy and count that as CO2 emissions for themselves. And then
they and the power companies (they have contracts with) invest billions into new green energy projects,
better grids and better batteries so that &lt;em&gt;eventually&lt;/em&gt; this discrepancy goes down to zero. In this way
green AI data centers with their increasing consumption of green energy are &lt;em&gt;actually&lt;/em&gt; doing a lot
of good work in making our electrical grid &lt;em&gt;more&lt;/em&gt; green. They are making more resources than they are
consuming. And that is just the tip of the iceberg. This is a &lt;em&gt;deep&lt;/em&gt; topic that really abhors generalizations
like "more consumption = bad".&lt;/p&gt;
&lt;p&gt;I've heard similar discussions in the context of electric cars - "so you got an electric car? you'd have fewer
emissions if you drove no car at all!". That might be so. And I would also reduce my emissions to zero
if I stopped breathing, but I &lt;em&gt;really&lt;/em&gt; do not want that kind of thinking to be propagated further, especially
when impressionable young people are around who may take it to its logical (but wrong!) conclusion. Instead
I talk about how early adopters use electric cars to gather experience and achieve volume to start the
network effects working. Once network effects of many electric cars on the roads are sufficient, it becomes
an economically logical choice to get an electric car. People who &lt;em&gt;cannot&lt;/em&gt; avoid having a car start
to switch over. And at the point of mass switchover the reduction of emissions is so massive that those
early adopters failing to go all the way to riding a bicycle becomes a rounding error.&lt;/p&gt;
&lt;p&gt;But surely that does not apply to LLMs? They are only increasing consumption and bring no benefit?&lt;/p&gt;
&lt;p&gt;Benefit - and here we have to actually talk about benefits. Because you cannot make any cost-benefit
analysis if you do not &lt;em&gt;actually&lt;/em&gt; fully investigate the benefits. Are there environmental benefits from
running those AI models? Yes, in a lot of very diverse ways. Hard to measure, however. There are projects
that are easy to quantify - like that Google AI project on contrail avoidance. An advanced, special model
trained and executed in Google AI data centers was able to predict where in the air contrails would be
produced and could generate proposed course adjustments to commercial flights to avoid specific heights
in specific locations at specific times. This stopped these aircraft from creating contrails and those
contrails did not make a further contribution to global warming. That benefit in a year was many times higher than
the environmental cost of training and running that AI model. And it can keep running for many years
accumulating further benefits.&lt;/p&gt;
&lt;p&gt;On a personal scale, I've had problems that I bashed my head (and computer
and CI resources) against without much success years ago solved with a few minutes of compute. Having
a good enough candidate solution quickly is &lt;em&gt;much&lt;/em&gt; cheaper from a resource perspective than spending days
trying different things, running my PC for it, trying different patches on CI executions, doing different
rebuilds. I've seen very significant benefits in AI-assisted development in enterprise environments
where code way more complex than what is in Debian (especially in Debian tools and packaging) gets
analysed, reviewed, modified or even refactored or rewritten in another language with AI assistance.
And it generally works. The commonly mentioned "hallucinations" are a thing of last year in the coding
context. Nowadays the AIs work in special coding harnesses and use real tools as foundational facts.
You cannot "hallucinate" an API call or parameter if you have to run and pass the unit tests and
integration tests by your harness before you can return "success" to the caller. I've personally
seen high-level AI models read very complex software projects across multiple repositories and point
out a very specific design consideration that was encoded in the code logic, but never mentioned in
comments or documentation. It was so obscure that even I did not immediately know what it was
talking about (and I wrote that code). Only on close inspection of code interaction across three repos
did I remember that there was indeed that bug 2 years ago that I fixed by doing the change that
this AI picked up (it wasn't in the history of this git repo due to repo migration). It mentioned
this because it was very relevant to the task I initially gave it to review.&lt;/p&gt;
&lt;p&gt;These LLMs in a proper harness with proper system instructions and usage approach are not just fancy
spell checkers or auto-complete. They function more like very advanced pattern matchers. They have learned
millions of patterns from training data. When they look at the code, they see hundreds or thousands of
overlapping patterns. When you ask them to make or change something, they pull out a pattern (or ten)
from their training and apply those patterns to the context of your program. You get something that
looks just like the surrounding code, same style choices, same language, same comment voice, but it
implements something new there, based on other patterns learned. If you've studied design patterns
in your CS class, this will be familiar. But people can learn and remember maybe 20-30 patterns, while
an LLM can have a million patterns and can combine them when needed. So it takes a pattern of
Python code, pattern of standalone script, pattern of parsing command line parameters, pattern of
classes, pattern for background threads, pattern for file tree traversing, pattern for pipes, ... and
squishes them together to make a solution for your query. And then tries to debug it with compilation,
tests and execution until it works as expected. Even if there is zero LLM development going forward, it
will take many years to fully appreciate the benefits we can extract from the already trained models.
They don't even have to be retrained - for existing languages they just keep working. For new
language variations, like a new Python version, you can feed the changelog into context and they will
be able to work with a Python version that they never saw in training. And patterns are mostly abstract,
so not really specific to any language - human or programming.&lt;/p&gt;
&lt;p&gt;This is another big enabler that LLMs have created that we have not really explored yet. LLMs have
created &lt;em&gt;really&lt;/em&gt; free software. People can &lt;em&gt;actually&lt;/em&gt; create software that is perfectly suited just
for them and no one else. They don't even have to know how to program and don't even need to speak
English. I've seen people writing prompts in their native language and LLMs creating and then adjusting
web apps or Android/iPhone apps and deploying them to the user's own phone. It was too buggy to work last
year, but this year it is actually very functional for simpler use-cases. And the code looks just
fine too - I've seen external contractors in a business setting deliver far worse. If you start with
a good initial system prompt, the project will have architecture documentation, use-case documentation,
unit tests, integration tests, deployment harness, testing and production deployments, audit logs,
monitoring, clear git commits, CI validation on commit, ... Modern AI systems have the capabilty
to deliver software freedom to people who are not coders. I really can not overstate the consequences
this may have on the world.&lt;/p&gt;
&lt;p&gt;Community - I find the concerns that new people will be using LLMs so much that they will no longer
be understanding the actual code they are contributing a bit regressive. I don't see any significant
difference between this and people relying on compilers, on high-level languages or on debhelper.
Writing modern debhelper packaging feels more like writing configuration and not writing code. It
takes really significant effort to dig down through layers of abstraction to find what &lt;em&gt;actually&lt;/em&gt;
is being executed in debian/rules. AI does not really make this worse. In fact, I find that AI
can make it much easier to understand arcane syntax because you can ask an LLM to &lt;em&gt;explain&lt;/em&gt; what is
happening in any part of the code and it will do a pretty good job of it, digging down through
the layers of abstraction for you. All the pro-AI proposals include the requirement that each
&lt;em&gt;human&lt;/em&gt; contributor needs to understand and stand behind their AI-assisted contribution and I
believe that is a good requirement and also a sufficient requirement. Modern LLMs not only produce
clear and concise code, but they are also capable of producing good comments explaining why the
code is how it is, good commit messages explaining the change and reason behind it and also
making corresponding changes to test suites and documentation. You know - the housekeeping stuff
that is often skipped because it slows down the actual feature development, but then its lack
becomes a problem for future contributors. Responsible use of AI assistance is a great chance
to actually &lt;em&gt;strengthen&lt;/em&gt; our community and make our software easier to maintain.&lt;/p&gt;
&lt;p&gt;That said, I have no qualms about flat-out rejecting contributions that do not make sense. And
it does not matter if they are made with or without AI assistance. If the contributor will not
explain their patch, it might be they do not understand what their AI produced &lt;em&gt;or&lt;/em&gt; it could be
that the contribution is deliberately hiding a backdoor being planted. It is also quite common
for a contribution of a new feature to be rejected because the author/maintainer does not believe
that it is a good fit for the project. Featuritis is a real disease. AI or not. There have always
been drive-by contributions to various projects. They will continue to exist. Each of them should
be evaluated on its merits - is this feature valuable to our users and is the added complexity
(if any) worth the functionality? A lot of security bug reports are "drive-by" contributions as
well. And many of them nowadays are discovered, exploited and patched with AI assistance. We
could reject them, but that just leaves us holding the bag on the now-known exploits.&lt;/p&gt;
&lt;p&gt;And the New Maintainer process should be able to figure out if an upcoming Developer has actually
understood the nuances of Debian packaging or not. A contributor with upload rights to the
archive &lt;em&gt;has to&lt;/em&gt; be able to create a basic package with no support tooling (maybe even without
using debhelper?) and be able to understand and modify more complex packages (possibly with
tooling support). IMHO that is a separate discussion that is worth having, involving experts from
the educational sector.&lt;/p&gt;
&lt;p&gt;Conclusion&lt;/p&gt;
&lt;p&gt;IMHO the Debian project should not restrict what tooling individual contributors use to contribute.
Expecting high-quality contributions and that contributors understand what they are contributing
(as a first level of review) is enough.&lt;/p&gt;
&lt;p&gt;However, Debian should provide its contributors (internal or external) with guidance on &lt;em&gt;how&lt;/em&gt;
to contribute in the best way possible. That could include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;information on which AI services have Terms and Conditions that make them problematic for free
  software development, legally speaking&lt;/li&gt;
&lt;li&gt;information on which AI services do (or do not) achieve a sufficient level of sustainability to be
  worth recommending (and then do the same for other data centers we already use)&lt;/li&gt;
&lt;li&gt;information on which local AI models were trained in sustainable ways&lt;/li&gt;
&lt;li&gt;base-level prompts to set technical expectations on various types of contributions, like bug
  reports or patches to packaging or translations&lt;/li&gt;
&lt;li&gt;default configuration for AI-assisted code reviews on Salsa that projects could enable and
  supplement with their own instructions on top&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In addition to that it would be helpful for Debian, as a project, to reach out to AI service
providers to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;encourage them to improve sustainability (where needed)&lt;/li&gt;
&lt;li&gt;investigate and fix problems causing excessive scraping load on systems&lt;/li&gt;
&lt;li&gt;provide AI resources for Debian usage, for example in CI infrastructure or to provide equal
  development support opportunities for Debian developers who cannot afford paid AI services&lt;/li&gt;
&lt;li&gt;improve coding outputs of their models in the Debian context if/when systematic deficiencies
  in the output are found by us&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Questions? Feedback? Just ask
&lt;a href="https://bsky.app/profile/aigarius.com/post/3mtql3ologs2p"&gt;here&lt;/a&gt; or
&lt;a href="https://www.threads.com/share/DXreYglXv/"&gt;here&lt;/a&gt;.&lt;/p&gt; </description> 
	<pubDate>Sat, 22 Aug 2026 19:30:00 +0000</pubDate>

</item> 
<item>
	<title>Russell Coker: Links August 2026</title>
	<guid>https://etbe.coker.com.au/?p=6285</guid>
	<link>https://etbe.coker.com.au/2026/08/23/links-august-2026/</link>
     <description>  &lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=TCn7bA1eg_0"&gt;This YouTube video about the Cashier Girl Meme is interesting in the context of AI systems that generate images of people and can communicate with people, hotter than any real human is an achievable goal [1]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=ZJ8KThKAfbs"&gt;Stand Up Maths has an interesting Youtube video about LLMs solving maths problems which I highly recommend watching (it does not require any real knowledge of maths), I think this opens the door to attacks on well established cryptologic systems [2]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=gpSghW4J3ws"&gt;Adam Conover made an insightful YouTube video about how and why Hollywood is now unable to make good sitcoms and why this is bad for society [3]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://skycroeser.net/blog/conference-digital-and-sexual-citizenship-in-an-age-of-social-media-bans/"&gt;Sky Croeser wrote an interesting and insightful blog post about topics covered at the “Digital and sexual citizenship in an age of social media bans: Interrogating the rights of children and young people conference” [4]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://zanestjohn.com/blog/reing-with-claude-code"&gt;Zane wrote a very informative blog post about reverse engineering a trojaned Android projector with Claude Code [5]&lt;/a&gt;. We need much better security on home networks to break the business model for this sort of thing.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://reneedoesstuff.substack.com/p/puritans-wouldnt-eat-pussy-so-they"&gt;Renee Stonebraker’s article “Puritans Wouldn’t Eat Pussy, So They Invented the Western” has a lot of interesting information about early days of colonising the US, and not much about eating pussy [6]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.iflscience.com/the-icy-fingers-of-death-that-creep-beneath-the-frozen-antarctic-68416"&gt;IFLScience has an interesting article about brinicles, icicles of brine that form under sea ice [7]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://nautil.us/could-an-industrial-civilization-have-predated-humans-on-earth-352964"&gt;Nautilus has an interesting article about the Silurian Hypothesis [8]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://theconversation.com/what-is-no-till-farming-and-is-it-actually-better-for-the-environment-287292"&gt;The Conversation has an intersting article about the pros and cons of no-till farming [9]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://365tomorrows.com/2024/03/27/cold-war-2/"&gt;Cold War is a 365tomorrows story about bio-warfare which raises several disturbing possibilities we need to guard against [10]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://scottsantens.substack.com/p/land-value-tax-dividend-ubi"&gt;Scott Santens wrote an insightful article describing how a land value tax would reduce rent and solve the housing shortages [11]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.positive.news/environment/can-provocative-climate-messaging-on-only-fans-cut-through-social-medias-noise/"&gt;Positive News has an interesting article about using OnlyFans to teach people about climate change [12]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://theconversation.com/cultural-safety-in-healthcare-is-not-ideological-it-is-saving-lives-286335"&gt;The Conversation has an interesting article about cultural safety in healthcare, sounds good, and while we are at it lets deal with sexism [13]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://doctoreww.github.io/EvilFontTool/"&gt;Doctoreww has an interesting web page about ways of displaying different strings to humans and machines, this could result in you running a different command to what you thought you copied from a web site or defeating tools designed to block hostile content [14]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://locusmag.com/feature/commentary-cory-doctorow-hell-is-other-people/"&gt;Cory Doctorow wrote an insightful article “Commentary Hell is Other People” about the way rich people want to use AI to replace all people [15]&lt;/a&gt;. Also psychologists who help rich people accept being greedy are worthy of a Luigi&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.sciencedirect.com/science/article/pii/S0749597826000300"&gt;The research article “Worship me at the office altar: Why narcissistic leaders resist remote work” is interesting, yet another reason to get rid of narcissistic executives [16]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://reneweconomy.com.au/renewables-sector-learning-from-messy-failures-after-oil-company-collapses-with-200m-clean-up-bill/"&gt;Renew Economy has an interesting article about clean up costs for mining (which is usually left for the government to pay) and how this could impact renewable energy production facilities [17]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://freedium-mirror.cfd/https://medium.com/@elvirabary/the-financial-collapse-putin-cannot-bomb-his-way-out-of-b6798b10fdf2"&gt;Elvira Bary wrote an insightful article on the Russian financial collapse that is happening now [18]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.theguardian.com/culture/2026/jul/18/black-american-women-south-korea-healthcare"&gt;The Guardian has an interesting article about Afro-American women who travel to South Korea for healthcare because of problems with racism and sexism in American hospitals [19]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://theconversation.com/what-if-disabled-astronauts-are-just-better-suited-to-space-287222"&gt;The Conversation has an interesting article about the potential for disabled people to be more productive in space than non-disabled people [20]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/"&gt;Krebs has an interesting article about LG banning residential proxy code from apps after the LG store was found to have such code in 42% of it’s apps [21]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.theguardian.com/commentisfree/2026/jul/22/stephen-miller-marco-rubio-trump-speeches"&gt;Robert B Shpiner wrote an insightful article for The Guardian about the death of democracy in the US [22]&lt;/a&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href="https://www.youtube.com/watch?v=TCn7bA1eg_0"&gt; https://www.youtube.com/watch?v=TCn7bA1eg_0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href="https://www.youtube.com/watch?v=ZJ8KThKAfbs"&gt; https://www.youtube.com/watch?v=ZJ8KThKAfbs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href="https://www.youtube.com/watch?v=gpSghW4J3ws"&gt; https://www.youtube.com/watch?v=gpSghW4J3ws&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[4]&lt;a href="https://skycroeser.net/blog/conference-digital-and-sexual-citizenship-in-an-age-of-social-media-bans/"&gt; https://tinyurl.com/28b6jclu&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[5]&lt;a href="https://zanestjohn.com/blog/reing-with-claude-code"&gt; https://zanestjohn.com/blog/reing-with-claude-code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[6]&lt;a href="https://reneedoesstuff.substack.com/p/puritans-wouldnt-eat-pussy-so-they"&gt; https://tinyurl.com/2y2b6a58&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[7]&lt;a href="https://www.iflscience.com/the-icy-fingers-of-death-that-creep-beneath-the-frozen-antarctic-68416"&gt; https://tinyurl.com/2awjppn5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[8]&lt;a href="https://nautil.us/could-an-industrial-civilization-have-predated-humans-on-earth-352964"&gt; https://tinyurl.com/2y89gftt&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[9]&lt;a href="https://theconversation.com/what-is-no-till-farming-and-is-it-actually-better-for-the-environment-287292"&gt; https://tinyurl.com/2b27vo8o&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[10]&lt;a href="https://365tomorrows.com/2024/03/27/cold-war-2/"&gt; https://365tomorrows.com/2024/03/27/cold-war-2/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[11]&lt;a href="https://scottsantens.substack.com/p/land-value-tax-dividend-ubi"&gt; https://tinyurl.com/2aqkn4z6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[12]&lt;a href="https://www.positive.news/environment/can-provocative-climate-messaging-on-only-fans-cut-through-social-medias-noise/"&gt; https://tinyurl.com/2dy5vy8g&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[13]&lt;a href="https://theconversation.com/cultural-safety-in-healthcare-is-not-ideological-it-is-saving-lives-286335"&gt; https://tinyurl.com/25rld7v3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[14]&lt;a href="https://doctoreww.github.io/EvilFontTool/"&gt; https://doctoreww.github.io/EvilFontTool/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[15]&lt;a href="https://locusmag.com/feature/commentary-cory-doctorow-hell-is-other-people/"&gt; https://tinyurl.com/2c2guu89&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[16]&lt;a href="https://www.sciencedirect.com/science/article/pii/S0749597826000300"&gt; https://tinyurl.com/27kq4qqu&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[17]&lt;a href="https://reneweconomy.com.au/renewables-sector-learning-from-messy-failures-after-oil-company-collapses-with-200m-clean-up-bill/"&gt; https://tinyurl.com/2blp477w&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[18]&lt;a href="https://freedium-mirror.cfd/https://medium.com/@elvirabary/the-financial-collapse-putin-cannot-bomb-his-way-out-of-b6798b10fdf2"&gt; https://tinyurl.com/27aybgge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[19]&lt;a href="https://www.theguardian.com/culture/2026/jul/18/black-american-women-south-korea-healthcare"&gt; https://tinyurl.com/29covbrp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[20]&lt;a href="https://theconversation.com/what-if-disabled-astronauts-are-just-better-suited-to-space-287222"&gt; https://tinyurl.com/27qdj6co&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[21]&lt;a href="https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/"&gt; https://tinyurl.com/22pxub8v&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[22]&lt;a href="https://www.theguardian.com/commentisfree/2026/jul/22/stephen-miller-marco-rubio-trump-speeches"&gt; https://tinyurl.com/25zf4hnp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="yarpp yarpp-related yarpp-related-rss yarpp-template-list"&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2024/08/31/links-august-2024/" rel="bookmark" title="Links August 2024"&gt;Links August 2024&lt;/a&gt; &lt;small&gt;Bruce Schneier and Kim Córdova wrote an insightful article about...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2026/02/17/links-february-2026/" rel="bookmark" title="Links February 2026"&gt;Links February 2026&lt;/a&gt; &lt;small&gt;Charles Stross has a good theory of why “AI” is...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2025/08/31/links-august-2025/" rel="bookmark" title="Links August 2025"&gt;Links August 2025&lt;/a&gt; &lt;small&gt;Dimitri John Ledkov wrote an informative blog post about self...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Sat, 22 Aug 2026 16:05:00 +0000</pubDate>

</item> 
<item>
	<title>Dirk Eddelbuettel: RProtoBuf 0.4.28 on CRAN: Small Updates</title>
	<guid>http://dirk.eddelbuettel.com/blog/2026/08/22#rprotobuf_0.4.28</guid>
	<link>http://dirk.eddelbuettel.com/blog/2026/08/22#rprotobuf_0.4.28</link>
     <description>  &lt;img src="http://planet.debian.org/heads/dirk.png" width="65" height="90" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;A new minor release 0.4.28 of &lt;a href="https://dirk.eddelbuettel.com/code/rprotobuf.html"&gt;RProtoBuf&lt;/a&gt;
arrived on &lt;a href="https://cran.r-project.org"&gt;CRAN&lt;/a&gt; today. &lt;a href="https://dirk.eddelbuettel.com/code/rprotobuf.html"&gt;RProtoBuf&lt;/a&gt;
provides &lt;a href="https://www.r-project.org"&gt;R&lt;/a&gt; with bindings to the
&lt;a href="https://github.com/google/protobuf"&gt;Google Protocol Buffers
(“ProtoBuf”)&lt;/a&gt; data encoding and serialization library used and
released by Google, and deployed very widely in numerous projects as a
language and operating-system agnostic protocol. The new release is also
already as a binary via &lt;a href="https://eddelbuettel.github.io/r2u"&gt;r2u&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release corrects a really old bug. &lt;a href="https://github.com/troyhernandez"&gt;Troy&lt;/a&gt; found, when working on
&lt;a href="https://grpc.io/"&gt;gRPC&lt;/a&gt; based extensions, which is in and by
itself exciting, that a small part of our interface surface (for service
descriptors) was just wrong confusing single and double underscores.
adjusts to a change upstream. This has been corrected. I updated a few
of the usual continuous integration parts, updated a help page for a
newly-added nag by &lt;a href="https://cran.r-project.org"&gt;CRAN&lt;/a&gt;, and
also got a last-minute round of noodling in as the JSS paper vignette
was still referencing OmegaHat which the &lt;a href="https://cran.r-project.org"&gt;CRAN&lt;/a&gt; URL checker objected to. I
created a quick one-off repo to serve pdf files should the need arise
again, and rebuilt the vignette linking to it. No other changes.&lt;/p&gt;
&lt;p&gt;The following section from the NEWS.Rd file has all details and
links.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id="changes-in-rprotobuf-version-0.4.28-2026-08-21"&gt;Changes in
RProtoBuf version 0.4.28 (2026-08-21)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Standard maintenance of continuous integration&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The type help page has received a usage section&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Cleanup of several methods for ServiceDescriptor, correct several
other declaration (Troy Hernandez in &lt;a href="https://github.com/eddelbuettel/rprotobuf/pull/117"&gt;#117&lt;/a&gt;
fixing &lt;a href="https://github.com/eddelbuettel/rprotobuf/pull/116"&gt;#116&lt;/a&gt;)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Adjusted vignette reference to Omegahat paper to alternate
location&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Thanks to my &lt;a href="https://dirk.eddelbuettel.com/cranberries/"&gt;CRANberries&lt;/a&gt;, there
is a diff to the &lt;a href="https://dirk.eddelbuettel.com/cranberries/2026/08/21#RProtoBuf_0.4.28"&gt;previous
release&lt;/a&gt;. The &lt;a href="https://dirk.eddelbuettel.com/code/rprotobuf.html"&gt;RProtoBuf&lt;/a&gt;
page has copies of the &lt;a href="https://dirk.eddelbuettel.com/code/rprotobuf/RProtoBuf-intro.pdf"&gt;(older)
package vignette&lt;/a&gt;, the &lt;a href="https://dirk.eddelbuettel.com/code/rprotobuf/RProtoBuf-quickref.pdf"&gt;‘quick’
overview vignette&lt;/a&gt;, and the &lt;a href="https://cloud.r-project.org/web/packages/RProtoBuf/vignettes/RProtoBuf-paper.pdf"&gt;pre-print
of our JSS paper&lt;/a&gt;. Questions, comments etc should go to the &lt;a href="https://github.com/eddelbuettel/rprotobuf/issues"&gt;GitHub issue
tracker&lt;/a&gt; off the &lt;a href="https://github.com/eddelbuettel/rprotobuf"&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;
&lt;p style="font-size: 80%; font-style: italic;"&gt;
This post by &lt;a href="https://dirk.eddelbuettel.com"&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href="https://dirk.eddelbuettel.com/blog/"&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can &lt;a href="https://github.com/sponsors/eddelbuettel"&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt; </description> 
	<pubDate>Sat, 22 Aug 2026 12:24:00 +0000</pubDate>

</item> 
<item>
	<title>Emmanuel Kasper: Create a development VM using Debian cloud images</title>
	<guid>http://00formicapunk00.wordpress.com/?p=361</guid>
	<link>https://00formicapunk00.wordpress.com/2026/08/22/create-a-development-vm-using-debian-cloud-images/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/manu.png" width="65" height="85" alt="" align="right" style="float: right;"&gt;  &lt;div class="wp-block-jetpack-markdown"&gt;&lt;p&gt;Following on &lt;a href="https://00formicapunk00.wordpress.com/2026/08/21/moving-software-development-to-separate-vm-to-reduce-credential-scavenging/"&gt;the rationale of the previous post&lt;/a&gt;, here is how I create
a development VM based on ready to use disk images made by the debian cloud team.
I could as well install the VM myself using an ISO, but why download a collection of packages in a ISO only to copy them right onto a disk image ?&lt;/p&gt;
&lt;p&gt;From the list of images available at &lt;a href="https://cloud.debian.org/images/cloud/" rel="nofollow"&gt;https://cloud.debian.org/images/cloud/&lt;/a&gt;
we will start with the &lt;strong&gt;generic qcow2&lt;/strong&gt; disk image, it has cloud-init, which allows initial automatic configuration, and snapshots of the VM via the qcow2 disk format.&lt;/p&gt;
&lt;p&gt;As for the virtualization, I am using &lt;code&gt;virsh&lt;/code&gt; &lt;code&gt;virt-install&lt;/code&gt; and &lt;code&gt;virt-manager&lt;/code&gt;, which are part of the  libvirt framework. Libvirt offers an excellent API accessible over qemu/KVM via shell (virsh), GUI (virt-manager) and Web (cockpit) .&lt;/p&gt;
&lt;p&gt;To use libvirt, properly you need to make sure your standard user is member of the libvirt group, and the libvirt default network is started via &lt;code&gt;virsh net-autostart default&lt;/code&gt;.
Also make sure you set &lt;code&gt;export LIBVIRT_DEFAULT_URI=qemu:///system&lt;/code&gt; to use the system wide instance of libvirt, which is needed for the default bridged networking.&lt;/p&gt;
&lt;p&gt;Download the debian cloud image:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ wget https://cloud.debian.org/images/cloud/trixie/daily/latest/debian-13-generic-amd64-daily.qcow2
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Add the disk image as a libvirt volume:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ export SIZE=$(stat -Lc%s debian-13-generic-amd64-daily.qcow2)
$ virsh vol-create-as default dev-vm $SIZE --format qcow2
$ virsh vol-upload --pool default dev-vm debian-13-generic-amd64-daily.qcow2
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Create a VM with the root password set to “root”:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ echo root &amp;gt; password.txt
$ virt-install --name dev-vm --memory 4096 --noreboot \
	--os-variant detect=on,name=linux2024 \
	--disk vol=default/dev-vm \
	--import \
	--boot uefi \
	--cloud-init root-password-file=password.txt,clouduser-ssh-key=$HOME/.ssh/.ssh/id_ed25519,disable=on
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;At the point libvirt will create a VM (a domain in libvirt parlance) and start it.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Starting install...
Allocating 'virtinst-ns9oa7_i-cloudinit.iso'                | 368 kB  00:00     
Transferring 'virtinst-ns9oa7_i-cloudinit.iso'              | 368 kB  00:00     
Creating domain...                                          |         00:00     
Connected to domain 'dev-vm'

BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x3)/Pci(0x0,0x0)

Booting `Debian GNU/Linux'

Loading Linux 6.12.101+deb13-amd64 ...

Loading initial ramdisk ...

EFI stub: Loaded initrd from LINUX_EFI_INITRD_MEDIA_GUID device path
EFI stub: UEFI Secure Boot is enabled.
[    0.000000] Linux version 6.12.101+deb13-amd64 (debian-kernel@lists.debian.org) (x86_64-linux-gnu-gcc-14 (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44) #1 SMP PREEMPT_DYNAMIC Debian 6.12.101-1 (2026-08-05)
[    0.000000] Command line: BOOT_IMAGE=/boot/vmlinuz-6.12.101+deb13-amd64 root=PARTUUID=2b4578e2-9d2e-4b32-b6a4-b5b2ca607ef6 ro console=tty0 console=ttyS0,115200 earlyprintk=ttyS0,115200 consoleblank=0
...
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Once the VM is created you have now three ways to access it:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# open a serial console to the VM
$ virsh console dev-vm
# access the graphical console
$ virt-manager
# Access the VM via SSH with the precreated cloud user "debian"
$ virsh domifaddr dev-vm
 Name       MAC address          Protocol     Address
-------------------------------------------------------------------------------
 vnet7      52:54:00:23:e6:61    ipv4         192.168.122.225/24
$ ssh debian@192.168.122.225
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;In the next blog post we will see how to configure the IDE (vscodium) to run confortably in the VM.&lt;/p&gt;
&lt;/div&gt; </description> 
	<pubDate>Sat, 22 Aug 2026 08:39:33 +0000</pubDate>

</item> 
<item>
	<title>Emmanuel Kasper: Moving software development to separate VM to reduce credential scavenging</title>
	<guid>http://00formicapunk00.wordpress.com/?p=354</guid>
	<link>https://00formicapunk00.wordpress.com/2026/08/21/moving-software-development-to-separate-vm-to-reduce-credential-scavenging/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/manu.png" width="65" height="85" alt="" align="right" style="float: right;"&gt;  &lt;div class="wp-block-jetpack-markdown"&gt;&lt;h2&gt;Rationale:&lt;/h2&gt;
&lt;p&gt;I was remembered via &lt;a href="https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/" rel="nofollow"&gt;https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/&lt;/a&gt; (linked from &lt;a href="https://anarc.at/blog/2026-08-18-people-vs-ai-overlords/" rel="nofollow"&gt;https://anarc.at/blog/2026-08-18-people-vs-ai-overlords/&lt;/a&gt;) of the risk of downloading untrusted packages in a dev environment.
If you read the blog post above you will see that it is way to easy do have a random npm, or even &lt;a href="https://blog.dreamfactory.com/the-litellm-supply-chain-attack-a-complete-technical-breakdown-of-what-happened-who-is-affected-and-what-comes-next"&gt;python package&lt;/a&gt; in a dev environment scavenge your long running credentials from your workstation, either on disk, or reading from memory !&lt;/p&gt;
&lt;p&gt;I will thus move to the following set up:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;things running directly in my workstation will require either to come from a trusted source (Debian package that is) or run in a sandboxed infrastructure (Podman rootless is the best thing here, followed by Flatpaks)&lt;/li&gt;
&lt;li&gt;everything else, will run in a Libvirt VM based on Debian cloud images. For me it will be mostly in the beginning the &lt;a href="https://github.com/VSCodium/vscodium"&gt;VSCodium editor&lt;/a&gt;, with its myriad of extensions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I am aware of whole blown solutions like &lt;a href="https://www.qubes-os.org/"&gt;QubeOS&lt;/a&gt; however I don’t indent to reinstall the whole OS, and QubeOS does not run on ARM64 which is one of the environment I am using.&lt;/p&gt;
&lt;p&gt;I will try to document this setup in two blog posts, one about the VM creation using Debian Cloud Images, the second one about running a graphical env in the VM with some filesystem passthrough. Stay tuned !&lt;/p&gt;
&lt;/div&gt;



&lt;p class="wp-block-paragraph"&gt;&lt;/p&gt; </description> 
	<pubDate>Fri, 21 Aug 2026 11:09:18 +0000</pubDate>

</item> 
<item>
	<title>Reproducible Builds (diffoscope): diffoscope 329 released</title>
	<guid>https://diffoscope.org/news/diffoscope-329-released/</guid>
	<link>https://diffoscope.org/news/diffoscope-329-released/</link>
     <description>  &lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class="language-plaintext highlighter-rouge"&gt;329&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class="language-plaintext highlighter-rouge"&gt;&lt;div class="highlight"&gt;&lt;pre class="highlight"&gt;&lt;code&gt;[ Jochen Sprickerhof ]
* Handle missing cpio and qemu-img in autopkgtests. (Closes: #1144617)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href="https://diffoscope.org"&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt; </description> 
	<pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate>

</item> 
<item>
	<title>Ian Jackson: Open Letter to the Wikimedia Foundation Board</title>
	<guid>tag:dreamwidth.org,2009-05-21:377446:21442</guid>
	<link>https://diziet.dreamwidth.org/21442.html</link>
     <description>  &lt;p&gt;
I have just sent an open letter to the Board of the Wikimedia Foundation, the umbrella organisation for Wikipedia (and a number of other projects), expressing my support for Wiki Workers United and the unionisation effort by WMF staff.

&lt;/p&gt;&lt;p&gt;
Here is the letter:

&lt;a name="cutid1"&gt;&lt;/a&gt;

&lt;/p&gt;&lt;p&gt;
To: Board of Trustees, Wikimedia Foundation

&lt;/p&gt;&lt;p&gt;
via Wikimedia_Foundation_Board_noticeboard and WWU &lt;br /&gt;
published at https://diziet.dreamwidth.org/21442.html

&lt;/p&gt;&lt;p&gt;
Re: My support for Wiki Workers United

&lt;/p&gt;&lt;p&gt;
Dear Trustees

&lt;/p&gt;&lt;p&gt;
Wikipedia has become one of the pillars of the free and open Internet.
Across the world, reliable sources of information are under attack.

&lt;/p&gt;&lt;p&gt;
I'm proud to have played my very small part in the community of
editors of English Wikipedia for the last 20 years.  I am also proud
of my contributions to the Free Software movement, including
especially Debian.  Debian, whose constitution and package installer I
originally wrote, has become one of the technological foundations of
the open Internet.

&lt;/p&gt;&lt;p&gt;
Unfortunately, there are signs that the Wikimedia Foundation is not
performing its proper role as bulwark against attacks on democracy,
including from moneyed interests.  Recent events at WMF have been very
alarming to me, and seem to form part of a disturbing trend.

&lt;/p&gt;&lt;p&gt;
As a Trustee Director of a UK charity myself, I understand that WMF
Trustees must defend the interests of the Foundation.  But that cannot
mean taking actions that undermine the Foundation's mission.  Nor can
it mean the deplorable, and even dishonest, practices, that WMF
appears to have been engaging in.

&lt;/p&gt;&lt;p&gt;
As a Wikipedian, as a Free Software activist, and as a citizen of the
planet, I stand in solidarity with Wiki Workers United.  Union-
busting must stop immediately.  The Foundation should immediately
formally recognise the unions in the UK and the US.

&lt;/p&gt;&lt;p&gt;
Further, WMF is an international organisation.  Collective
decisionmaking needs to be transnational too.  WMF should recognise
WWU as a negotiating partner worldwide, even if thresholds for formal
legal recognition are not met in individual national jurisdictions.

&lt;/p&gt;&lt;p&gt;
Wiki Workers are not the WMF's enemy.  WMF needs capable and
ideologically committed staff to maintain and operate its highly
complex systems, in the face of constant attacks.  Staff with
principles and a mission are WMF's biggest asset.

&lt;/p&gt;&lt;p&gt;
Dr Ian Jackson&lt;br /&gt;
Cambridge, UK&lt;br /&gt;
20th August 2026&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;img alt="comment count unavailable" height="12" src="https://www.dreamwidth.org/tools/commentcount?user=diziet&amp;amp;ditemid=21442" style="vertical-align: middle;" width="30" /&gt; comments </description> 
	<pubDate>Thu, 20 Aug 2026 20:58:51 +0000</pubDate>

</item> 
<item>
	<title>Jonathan Dowland: Bauer X4 inline skates</title>
	<guid>https://jmtd.net/log/inlines/</guid>
	<link>https://jmtd.net/log/inlines/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/jmtd.png" width="65" height="85" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;I’m really enjoying getting back into ice skating, but I can only get to the
rink once a week (at least over the summer -- I'm aiming for twice weekly once
Schools re-open) and I have the itch to do more skating than that.&lt;/p&gt;

&lt;div class="centre"&gt;
&lt;div class="image+centre"&gt;
&lt;a href="https://jmtd.net/log/inlines/inline.jpg"&gt;&lt;img alt="photo of me wearing inline skates, from above" class="img" height="303" src="https://jmtd.net/log/inlines/400x-inline.jpg" width="400" /&gt;&lt;/a&gt;

&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;Where I live we’re blessed with a seaside park with lots of smooth paths, a
recently resurfaced beachside promenade, and a newly-built
pedestrian/cycle path stretching up and down the coast: all great surfaces for
roller skates. I convinced myself to buy some inline skates whilst the weather
is good.&lt;/p&gt;

&lt;div class="image"&gt;
&lt;a href="https://jmtd.net/log/inlines/group.jpg"&gt;&lt;img alt="group shot of my skates" class="img" height="300" src="https://jmtd.net/log/inlines/400x-group.jpg" width="400" /&gt;&lt;/a&gt;

&lt;/div&gt;


&lt;p&gt;I wanted something as close to my ice skating experience as possible. Bauer
actually make an inline version of my ice boot, but the chassis is an unusual
composite plastic thing which put me off. (&lt;a href="https://youtu.be/Pu5UNck16SQ?si=2i2trx26f_0lUv5J"&gt;here's a great video of a fantastic
inline skater trying out the chassis&lt;/a&gt;).
CCM have a new inline range for 2026, but sadly (much like their Jetspeed ice range)
the fit wasn't good for me.&lt;/p&gt;

&lt;p&gt;I found a clearance pair of Bauer vapors from the previous generation: the Bauer Vapor x4. Very
similar to my Fly30, but the difference in quality between the tiers is very
apparent: boot stiffness, the comfort and quality of the liner.
They fit well (possibly better), the rolling motion is
really smooth (I think that's the bearings) and they looked pretty good to me:
yellow highlights instead of the red used across the ice range.&lt;/p&gt;

&lt;p&gt;I've done a couple of miles in them so far. Time will tell if they prove useful
for off-ice training! Many inline hockey players buy ice skates and convert
them to inline. If I end up not using them enough I could consider doing the
opposite.&lt;/p&gt; </description> 
	<pubDate>Thu, 20 Aug 2026 09:54:51 +0000</pubDate>

</item> 
<item>
	<title>Sergio Cipriano: My experience at DebConf 2026 in Santa Fé</title>
	<guid>tag:www.sergiocipriano.com,2026-08-19:posts/debconf-santafe-2026.md</guid>
	<link>https://sergiocipriano.com/debconf-santafe-2026.html</link>
     <description>  &lt;h1 id="my-experience-at-debconf-2026-in-santa-fé"&gt;My experience at
DebConf 2026 in Santa Fé&lt;/h1&gt;
&lt;p&gt;&lt;img alt="The Official DebConf26 Group Photo" class="markdown-img" src="https://sergiocipriano.com/assets/debconf2026/debconf26.png" /&gt;&lt;/p&gt;
&lt;p&gt;Last month, I attended &lt;a href="https://debconf26.debconf.org/"&gt;DebConf 2026 in Santa Fé&lt;/a&gt;,
which was my 5th DebConf. As always, it was an amazing experience, and I
met a lot of great people there.&lt;/p&gt;
&lt;p&gt;For those unfamiliar with the event, it takes place over the course
of two weeks. The first week is called DebCamp and is geared more
towards hacking and organizing the event itself, while also offering a
great opportunity to discuss ideas with others. The second week is the
DebConf. We still have the hacklabs, but the talks and workshops are the
main focus.&lt;/p&gt;
&lt;h2 id="my-activities-during-debcamp"&gt;My Activities during DebCamp&lt;/h2&gt;
&lt;p&gt;My main activity was working on the &lt;a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136152"&gt;python-click
transition&lt;/a&gt; that I started in May. There were only a few packages
left, and with the help of Guilherme Puida, we managed to work through
all the remaining bugs.&lt;/p&gt;
&lt;p&gt;I plan to talk in details about this transition in another blog post,
where I will focus on the tools I used and my experience with mass
rebuilds and mass bug filing.&lt;/p&gt;
&lt;p&gt;I also helped with de &lt;a href="https://wiki.debian.org/DebConf/26/Sprints/DebianGoTeam"&gt;Golang
Sprint&lt;/a&gt;. I worked on a few packages and experimented with the dak API
to &lt;a href="https://lists.debian.org/debian-go/2026/07/msg00072.html"&gt;generate
a list of packages that needed manual action.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;There was a lot of manual, repetitive work and false positives, so I
eventually moved on to some other, more fun stuff.&lt;/p&gt;
&lt;p&gt;I also learned a few thinks about kernel live patching while talking
to David Tadokoro. I had to work on the Ubuntu Kernel package recently
as part of my job, so we exchanged some ideas, and the conversation was
really helpful.&lt;/p&gt;
&lt;p&gt;He also taught me two commands that I wasn't familiar with, since I'm
a newbie in kernel development. Here are the commands:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ b4 am https://lore.kernel.org/lkml/20240730071904.1047-1-sergiosacj@riseup.net/
$ b4 diff *mbox&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;By the way, this is the first and only patch I have submitted to the
Linux Kernel. I worked on it during DebConf 2024, when I attended the
workshop Helen Koike runs to help newcomers submit their first patch to
the Linux Kernel.&lt;/p&gt;
&lt;p&gt;Another great interaction was with Marcos Talau. He showed me his
remote access setup, which he is using to help students make
contributions to Debian without the struggle of setting up the
development environment.&lt;/p&gt;
&lt;p&gt;Another cool thing is that Puida showed me the command:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ gbp clone vcs-git:typer&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;After that, I decided to read the gbp manpage because these little
details really improve the overall experience.&lt;/p&gt;
&lt;p&gt;I also had many other amazing interactions. I just decided to write
down the ones that I felt made the most sense for this kind of "blog
report" post.&lt;/p&gt;
&lt;h2 id="my-activities-during-debconf"&gt;My Activities during DebConf&lt;/h2&gt;
&lt;p&gt;I gave a &lt;a href="https://chuangtzu.ftp.acc.umu.se/pub/debian-meetings/2026/DebConf26/debconf26-413-introducing-dh-make-vim.lq.webm"&gt;talk&lt;/a&gt;
about &lt;a href="https://salsa.debian.org/vim-team/dh-make-vim/"&gt;dh-make-vim&lt;/a&gt;, a
tool I have been working on sporadically. An interesting detail is that
one of the video team volunteers for the talk, Piotr, spoke to me about
his tool, pypi2deb, which is similar but aimed at the Python ecosystem.
There are many tools of this kind in Debian, and they are all
interesting pieces of software. I plan to write more about them in the
future.&lt;/p&gt;
&lt;p&gt;I attended several talks and participated in a few BoF sessions, and
they were all great. But something that really stood out to me was the
workshop on the Debian Installer, led by Alper Nebi Yasak. I didn't know
anything about the Debian Installer, and I liked the way he approached
the subject and showed the specific details.&lt;/p&gt;
&lt;p&gt;I'll take some time to read the &lt;a href="https://d-i.debian.org/doc/internals/index.html"&gt;Debian Installer
internals documentation&lt;/a&gt;. I was not familiar with udebs or with the
fact that the Debian Installer uses &lt;a href="https://www.debian.org/doc/packaging-manuals/debconf_specification.html"&gt;debconf&lt;/a&gt;
under the hood.&lt;/p&gt;
&lt;h2 id="wrap-up"&gt;Wrap up&lt;/h2&gt;
&lt;p&gt;It was an amazing event. Unfortunatly, a lot of people I know were
not able to attend for different reasons, and they were missed.&lt;/p&gt;
&lt;p&gt;There were many other things that I enjoyed during this trip. Here
are a few more highlights:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;World Cup matches&lt;/li&gt;
&lt;li&gt;A day trip around Santa Fé&lt;/li&gt;
&lt;li&gt;The Cheese &amp;amp; Wine party&lt;/li&gt;
&lt;li&gt;Empanadas!!&lt;/li&gt;
&lt;/ul&gt; </description> 
	<pubDate>Wed, 19 Aug 2026 23:02:02 +0000</pubDate>

</item> 
<item>
	<title>Dirk Eddelbuettel: RcppMsgPack 0.2.5 on CRAN: Minor Maintenance</title>
	<guid>http://dirk.eddelbuettel.com/blog/2026/08/19#rcppmsgpack_0.2.5</guid>
	<link>http://dirk.eddelbuettel.com/blog/2026/08/19#rcppmsgpack_0.2.5</link>
     <description>  &lt;img src="http://planet.debian.org/heads/dirk.png" width="65" height="90" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;Another maintenance release of &lt;a href="https://dirk.eddelbuettel.com/code/rcpp.msgpack.html"&gt;RcppMsgPack&lt;/a&gt;
got onto &lt;a href="https://cran.r-project.org"&gt;CRAN&lt;/a&gt; today. &lt;a href="https://msgpack.org/"&gt;MessagePack&lt;/a&gt; itself is an efficient
binary serialization format. It lets you exchange data among multiple
languages like JSON. But it is faster and smaller. Small integers are
encoded into a single byte, and typical short strings require only one
extra byte in addition to the strings themselves. &lt;a href="https://dirk.eddelbuettel.com/code/rcpp.msgpack.html"&gt;RcppMsgPack&lt;/a&gt;
brings both the C++ headers of MessagePack as well as clever code (in
both R and C++) Travers wrote to access MsgPack-encoded objects directly
from R.&lt;/p&gt;
&lt;p&gt;This release is once again chiefly maintenance. Besides standard
upkeep to the README.md and continuous integration setup we had to add
one &lt;code&gt;#include&lt;/code&gt;. The &lt;code&gt;clang++-23&lt;/code&gt; compiler, when
also running with its own library, now now needs the
&lt;code&gt;type_traits.h&lt;/code&gt; header file (in the upstream &lt;a href="https://msgpack.org/"&gt;MessagePack&lt;/a&gt; code) so we added that. No
other changes, so no user-facing changes. Details follow from the NEWS
file.&lt;/p&gt;
&lt;blockquote&gt;
&lt;h4 id="changes-in-version-0.2.5-2026-08-19"&gt;Changes in version 0.2.5
(2026-08-19)&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Explicitly include header "type_traits.h" to appease
clang++-23&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard maintenance updating continuous integration, adding
minor helper script, and updating README.md&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Courtesy of my &lt;a href="https://dirk.eddelbuettel.com/cranberries"&gt;CRANberries&lt;/a&gt;, there
is also a diffstat report for &lt;a href="https://dirk.eddelbuettel.com/cranberries/2026/08/19#RcppMsgPack_0.2.5"&gt;this
release&lt;/a&gt;. For questions, suggestions, or issues please use the &lt;a href="https://github.com/eddelbuettel/rcppmsgpack/issues"&gt;issue
tracker&lt;/a&gt; at the &lt;a href="https://github.com/eddelbuettel/rcppmsgpack"&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;
&lt;p style="font-size: 80%; font-style: italic;"&gt;
This post by &lt;a href="https://dirk.eddelbuettel.com"&gt;Dirk
Eddelbuettel&lt;/a&gt; originated on his &lt;a href="https://dirk.eddelbuettel.com/blog"&gt;Thinking inside the box&lt;/a&gt;
blog. If you like this or other open-source work I do, you can now &lt;a href="https://github.com/sponsors/eddelbuettel"&gt;sponsor me at
GitHub&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt; </description> 
	<pubDate>Wed, 19 Aug 2026 20:07:00 +0000</pubDate>

</item> 
<item>
	<title>Antoine Beaupré: The people vs the AI overlords</title>
	<guid>https://anarc.at/blog/2026-08-18-people-vs-ai-overlords/</guid>
	<link>https://anarc.at/blog/2026-08-18-people-vs-ai-overlords/</link>
     <description>  &lt;blockquote&gt;&lt;p&gt;Also in this series:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://anarc.at/blog/2026-05-16-four-horsemen/"&gt;The Four Horsemen of the LLM Apocalypse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://anarc.at/blog/2026-08-25-llm-nuance/"&gt;A more nuanced view of LLMs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;p&gt;In a &lt;a href="https://lwn.net/ml/all/87o6fmdgs6.fsf@hope.eyrie.org/"&gt;post to oss-security&lt;/a&gt;, my (Debian) co-developer Russ Allbery
stated that "open source software [OSS] is coming face to face with a
motivation crisis that has been building for a long time". His point
is essentially that large language models (LLMs&lt;sup id="fnref:1"&gt;&lt;a href="https://anarc.at/tag/debian-planet/#fn:1" rel="footnote"&gt;1&lt;/a&gt;&lt;/sup&gt;) are making the
existing OSS community crisis worse. For him, it's the flood of code
reviews, but he argues that varies according to people's desires, for
others it's security issues and so on.&lt;/p&gt;

&lt;p&gt;I think Russ is right, but I would argue there's something much bigger
than our open &lt;em&gt;communities&lt;/em&gt; going on here, and it's about the entire
&lt;em&gt;field&lt;/em&gt; of computing. This pressure is on &lt;em&gt;all&lt;/em&gt; of us, regardless of
whether we work on open source software or not.&lt;/p&gt;

&lt;h1 id="how-people-use-models"&gt;How people use models&lt;/h1&gt;

&lt;p&gt;People using LLMs in their workflow have &lt;em&gt;radically&lt;/em&gt; changed how
programming works, even for &lt;a href="https://www.spurint.org/journal/2026/07/llms-and-xfwl4"&gt;people who claim to avoid
vibe-coding&lt;/a&gt;. And I'm sorry to single out one poor maintainer here:
it's not you, Brian, you're just one example among many. But this is
typical use of those models nowadays:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;Once it’s done, I’ll use &lt;code&gt;/code-review&lt;/code&gt; and let Claude spawn
sub-agents to do a full review of the new code. This usually finds
some problems, even problems that the “main” Claude instance didn’t
find during its validation. I usually keep running &lt;code&gt;/code-review&lt;/code&gt;
again and again after finding and fixing issues, until there aren’t
any left.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;Think about what that means for a minute. This is automation built to
fire up dozens of agents crunching at a problem for minutes if not
hours of GPU compute time, in parallel. This is essentially a couple
of shelves in a datacenter rack, totally maxed out on power and
cooling, abstracted behind a cute little &lt;code&gt;/code-review&lt;/code&gt; command.&lt;/p&gt;

&lt;p&gt;The author, here, is rightly concerned that "Anthropic could pull the
rug out and require API pricing", which is perhaps a code word for
"charging something closer to actual costs". Brian also pays lip
service to environmental and societal costs but those are largely
abstracted away, so let's keep that conversation aside here as well,
as we have &lt;a href="https://anarc.at/blog/2026-05-16-four-horsemen/"&gt;discussed it before anyways&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;But clearly, this way of working has an (&lt;a href="https://drewdevault.com/blog/Stop-externalizing-your-costs-on-me/"&gt;externalized&lt;/a&gt;) cost, to
say the least.&lt;/p&gt;

&lt;h1 id="paying-for-non-free-tools"&gt;Paying for non-free tools&lt;/h1&gt;

&lt;p&gt;For decades my work has been focused on free and open source
software. I've long stopped using proprietary operating systems like
Windows or Mac, and even before that switch, I was mostly using free
software on those platforms, partly out of principle, but also because
I was too poor. So the tools of my trade are free, and I build free
tools with them.&lt;/p&gt;

&lt;p&gt;It feels like we're going backwards: when I was in school, a millennia
ago, my classmates didn't have access to a compiler and were wondering
how they would scrape the money to buy a compiler like &lt;a href="https://en.wikipedia.org/wiki/Borland_C%2B%2B"&gt;Borland's&lt;/a&gt;
or &lt;a href="https://en.wikipedia.org/wiki/Microsoft_Visual_C%2B%2B"&gt;Microsoft's&lt;/a&gt;. I had a compiler built into my operating system
(&lt;a href="https://www.freebsd.org/"&gt;FreeBSD&lt;/a&gt; at the time), so that wasn't a problem for me. For them,
it was a significant expense, but at least those expenses (or more
&lt;a href="https://en.wikipedia.org/wiki/Warez"&gt;shady sourcing of programs&lt;/a&gt;) were a one-shot deal.&lt;/p&gt;

&lt;p&gt;Fast forward 30 years, and software is rented: you pay monthly for
Adobe's Photoshop and Microsoft's office suite just like you pay for
Netflix, Disney+ or Spotify&lt;sup id="fnref:2"&gt;&lt;a href="https://anarc.at/tag/debian-planet/#fn:2" rel="footnote"&gt;2&lt;/a&gt;&lt;/sup&gt;. And now you need to add dozens (if not
hundreds of dollars) of monthly credits to access LLMs on top of that.&lt;/p&gt;

&lt;p&gt;So, now we have to &lt;em&gt;pay&lt;/em&gt; to get anything done? This is peak
&lt;a href="https://craphound.com/category/enshittification/"&gt;enshitification&lt;/a&gt; of our job: first they steal our work to train their
models, and then they sell it back to us at a profit.&lt;/p&gt;

&lt;h1 id="attacking-the-engineers"&gt;Attacking the engineers&lt;/h1&gt;

&lt;p&gt;AI is coming for our jobs, as engineers, if not &lt;em&gt;everyone&lt;/em&gt;, according
to the narrative. For a while now, our job market has deteriorated:
less jobs, for less pay. Lots of skilled engineers looking for work
and finding crap jobs then still looking while working.&lt;/p&gt;

&lt;p&gt;This is not by accident.&lt;sup id="fnref:3"&gt;&lt;a href="https://anarc.at/tag/debian-planet/#fn:3" rel="footnote"&gt;3&lt;/a&gt;&lt;/sup&gt; We engineers have a &lt;em&gt;lot&lt;/em&gt; of power, it is not
organized, but that's just a couple of unions away (&lt;a href="https://www.ibtimes.sg/wikimedia-foundation-declines-voluntary-union-recognition-labor-dispute-grows-91377"&gt;easy&lt;/a&gt;!). Tech
overlords know this, so they are attacking our profession, directly,
by forcing us to train and use models that &lt;em&gt;they&lt;/em&gt; can control.&lt;/p&gt;

&lt;p&gt;Even in environments where programmers are not &lt;em&gt;forced&lt;/em&gt; to use LLMs,
the mere pressure of other people's LLM-generated work is huge. One can
be forced to review LLM outputs, or just peer pressured you into
producing more.&lt;/p&gt;

&lt;p&gt;We're now supposed to accelerate delivery, because models can
&lt;em&gt;presumably&lt;/em&gt; do things so much better and faster. With supply chain
security becoming such a large vector that we now have &lt;a href="https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"&gt;worms crawling
around developers accounts on NPM&lt;/a&gt;, increasing the delivery cadence
seems like a really bad idea.&lt;sup id="fnref:4"&gt;&lt;a href="https://anarc.at/tag/debian-planet/#fn:4" rel="footnote"&gt;4&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The LLM hype is part of the larger wave of cyberwar against workers,
against water, against the Earth, against all the people. This is not
a matter of individually "adapting to the reality" or personal choice,
but a political, social, hard problem we need to address collectively.&lt;/p&gt;





&lt;div class="footnotes"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:1"&gt;
I again prefer the term LLM to "AI" because models do &lt;em&gt;not&lt;/em&gt;
possess &lt;a href="https://en.wikipedia.org/wiki/Intelligence"&gt;intelligence&lt;/a&gt;. I did use it in the title because
click baiting is apparently important, but I stopped short of
calling this one "Rage Against the Machines" because that would be
the title of every blog post I have ever made.&lt;a href="https://anarc.at/tag/debian-planet/#fnref:1" rev="footnote"&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;li id="fn:2"&gt;
Yes, I know that &lt;a href="https://en.wikipedia.org/wiki/Visual_Studio"&gt;Visual Studio&lt;/a&gt; is kind of free now, but I
wouldn't be surprised if they turn that into a rental as well,
because why not.&lt;a href="https://anarc.at/tag/debian-planet/#fnref:2" rev="footnote"&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;li id="fn:3"&gt;
Beyond sabotaging the job market, Sam Altman event wants to
sell "&lt;a href="https://gizmodo.com/sam-altman-says-intelligence-will-be-a-utility-and-hes-just-the-man-to-collect-the-bills-2000732953"&gt;intelligence as a utility&lt;/a&gt;" something that is just a
&lt;a href="https://www.psychologytoday.com/us/blog/the-digital-self/202603/intelligence-as-a-commodity"&gt;really bad idea&lt;/a&gt; but especially shows how megalomaniac those
people are.&lt;a href="https://anarc.at/tag/debian-planet/#fnref:3" rev="footnote"&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;li id="fn:4"&gt;
This brings back memories of &lt;a href="https://en.wikipedia.org/wiki/Morris_worm"&gt;another era&lt;/a&gt;, walking us
back decades in terms of computer security.&lt;a href="https://anarc.at/tag/debian-planet/#fnref:4" rev="footnote"&gt;↩&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Wed, 19 Aug 2026 14:14:42 +0000</pubDate>

</item> 
<item>
	<title>Thomas Lange: LLM usage in Debian</title>
	<guid>http://blog.fai-project.org/posts/llm-usage-gr/</guid>
	<link>http://blog.fai-project.org/posts/llm-usage-gr/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/mrfai.png" width="76" height="100" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;After spending many hours on reading all the proposals and discussions
the best choice for me is NOTA (None of the above).&lt;/p&gt;

&lt;p&gt;We do not need to create new rules for LLM usage, we already have our
DFSG and our social contract.&lt;/p&gt;

&lt;p&gt;Keep it simple, stupid. Avoid more rules!&lt;/p&gt; </description> 
	<pubDate>Tue, 18 Aug 2026 13:41:45 +0000</pubDate>

</item> 
<item>
	<title>Andy Simpkins: My first go at tracking down a kernel bug…</title>
	<guid>https://blog.koipond.org.uk/?p=371</guid>
	<link>https://blog.koipond.org.uk/archives/371</link>
     <description>  &lt;img src="http://planet.debian.org/heads/andy.png" width="80" height="109" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;A couple of weekends back, I upgraded my home sever. It failed to restart after running &lt;code&gt;apt dist-upgrade &lt;/code&gt;&lt;/p&gt;



&lt;p&gt;The only update that was performed was to the kernel, it went from &lt;code&gt;6.12.88+deb13-amd64&lt;/code&gt; to &lt;code&gt;6.12.100+deb13-amd64&lt;/code&gt;.  I had previously performed an &lt;code&gt;apt-get upgrade&lt;/code&gt;, and rebooted the machine, so I was pretty sure that this was to blame.  This blog entry (is a late) attempt to document how I went about finding a fix for this issue so that next time I don’t need as much hand holding as I did this time around :-)&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;(1)&lt;/strong&gt;&lt;br /&gt;Having my machine not boot following an upgrade is pretty rare, but has happened before. Usually it is because I have done something wrong so as always confirming I haven’t broken something by accident is always my first step…&lt;/p&gt;



&lt;p&gt;I plugged in a keyboard an monitor to the machine and watched it boot. Being a server this takes a long time (I guess because at this stage of system initialisation we want to test things sequentially)&lt;/p&gt;



&lt;p&gt;Watching the system boot I see the usual BIOS/UEFI stages for this machine, followed by the grub menu and the the local screen showed:&lt;/p&gt;



&lt;pre class="wp-block-preformatted has-cyan-bluish-gray-background-color has-background"&gt;&lt;code&gt;            Loading Linux 6.12.100+deb13-amd64 ...
            Loading initial ramdisk ...&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;Nothing else. That was it.  OK that looks like I have a broken system all right, and at very early stage of the boot process process.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;(2) &lt;/strong&gt;&lt;br /&gt;Breaking into the grub menu and removing the quiet option yields a little more information (but not much):&lt;/p&gt;



&lt;pre class="wp-block-preformatted has-cyan-bluish-gray-background-color has-background"&gt;&lt;code&gt;            Loading Linux 6.12.100+deb13-amd64 …
            Loading initial ramdisk ...
            

            	EFI stub: Loaded initrd from LINUX_EFI_INITRD_MEDIA_GUID d
            	evice path
            		EFI stub: Measured initrd data into PCR 9&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;and nothing else.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;(3)&lt;/strong&gt; &lt;strong&gt;Initial debugging&lt;/strong&gt;&lt;/p&gt;



&lt;ul&gt;
&lt;li&gt;Confirmed that I could still boot the machine with the old kernel &lt;code&gt;6.12.88+deb13-amd64&lt;/code&gt; (During boot select Advanced options from the grub menu followed by the kernel image wanted) 
&lt;ul&gt;
&lt;li&gt;Yes – the system starts happily with the previous kernel&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;Checked that /boot had enough space
&lt;ul&gt;
&lt;li&gt;Yes – plenty of space&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;Is anyone else reporting this problem?  
&lt;ul&gt;
&lt;li&gt;Nothing jumps out on Debian’s bug tracker&lt;/li&gt;



&lt;li&gt;Actually not mush referenced for my search “&lt;code&gt;EFI stub: Measured initrd data into PCR 9 apart&lt;/code&gt;” other than the usual rantings to “turn off secure boot” (on this server that currently isn’t turned on – bad me)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;(4)&lt;/strong&gt; &lt;strong&gt;Triage&lt;/strong&gt;&lt;/p&gt;



&lt;p&gt;Start looking for where the fault first occurred.  At this point I needed help, and given that Sledge was visiting I asked if he would sanity check what I was doing.  His initial thoughts were that that /boot had run out of space, but replaying my step (3) with him acting as a ‘rubber duck’ showed that this was something other than PBKAC&lt;/p&gt;



&lt;p&gt;Sledge had a quick look, then informed me that between kernel images &lt;code&gt;6.12.88+deb13&lt;/code&gt; and &lt;code&gt;6.12.100+deb13&lt;/code&gt; Debian stable has only had shipped &lt;code&gt;.90 .94 .95&lt;/code&gt; and &lt;code&gt;.96&lt;/code&gt; kernels.  We could easily try them all:&lt;/p&gt;



&lt;ul&gt;
&lt;li&gt;&lt;code&gt;wget&lt;/code&gt; each kernel package then install (&lt;code&gt;dpkg -i&lt;/code&gt;)  followed by an &lt;code&gt;update-grub&lt;/code&gt;, checking that there was sufficient space on disks especially my small&lt;code&gt; /boot partition&lt;/code&gt;)&lt;/li&gt;



&lt;li&gt;I started with image &lt;code&gt;6.12.95+deb13&lt;/code&gt; and this worked&lt;/li&gt;



&lt;li&gt;&lt;code&gt;6.12.96+deb13&lt;/code&gt; yielded the same lock up on boot as &lt;code&gt;6.12.100+deb13&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;OK I now have the first kernel image that doesn’t boot on my system, time to raise a bug…&lt;/p&gt;



&lt;p class="has-vivid-cyan-blue-color has-text-color"&gt;&lt;em&gt;Up until now I have been walking to my garage where the server is located and standing in front of a rack&lt;br /&gt;with a monitor and keyboard plugged into the machine. However this machine supports IPMI so I spent a little time getting that up and running so that I can continue from the relative comfort of my desk (with lights, a chair and not needing to hold the keyboard with one hand)&lt;/em&gt;&lt;/p&gt;



&lt;p&gt;Great I can now grab screen shots from the confort of my desk (unfortunatly they are only screen shots not text files, but at least we can seen the early stage of boot, Post, grub menu and then initramfs before system log happens)&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;(5) Collating information for the initial bug report&lt;/strong&gt;&lt;/p&gt;



&lt;p&gt;Sledge had mentioned my problem in irc/#debain-kernal where iam_tj suggested that we try appending&lt;br /&gt;‘debug earlycon=efifb’ to the kernal command line. This yielded 15 seconds worth of messages before the system locked up the last few messages being (vmlinuz-6.12.96+deb13-amd64):&lt;/p&gt;



&lt;p class="has-cyan-bluish-gray-background-color has-background has-small-font-size"&gt;[ 14.663477] RCU Tasks: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.&lt;br /&gt;[ 14.750474] RCU Tasks Rude: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.&lt;br /&gt;[ 14.838024] RCU Tasks Trace: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.&lt;br /&gt;[ 14.929752] NR_IRQS: 524544, nr_irqs: 584, preallocated irqs: 16&lt;br /&gt;[ 15.016814] rcu: srcu_init: Setting srcu_struct sizes based on contention.&lt;br /&gt;[ 15.104011] Console: colour dummy device 80×25&lt;br /&gt;[ 15.191236] printk: legacy console [tty0] enabled&lt;br /&gt;[ 15.278249] printk: legacy bootconsole [efifb0] disabled&lt;/p&gt;



&lt;p&gt;Booting the working kernel with the same kernel options yields the SAME messages with slightly differing times, but then continues to login prompt:&lt;/p&gt;



&lt;pre class="wp-block-preformatted has-cyan-bluish-gray-background-color has-background has-small-font-size"&gt; [   14.697466] RCU Tasks: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
 [   14.784936] RCU Tasks Rude: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
 [   14.872067] RCU Tasks Trace: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
 [   14.964000] NR_IRQS: 524544, nr_irqs: 584, preallocated irqs: 16
 [   15.051482] rcu: srcu_init: Setting srcu_struct sizes based on contention.
 [   15.226079] printk: legacy console [tty0] enabled
 [   15.313751] printk: legacy bootconsole [efifb0] disabled
 [   15.400831] ACPI: Core revision 20240827
 [   15.401415] clocksource: hpet: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 79635855245 ns
 [   15.401464] APIC: Switch to symmetric I/O mode setup
 
&lt;code&gt;... and so on&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;iam_tj also suggested adding keep_bootcon – with ‘debug earlycon=efifb keep_bootcon’ on vmlinuz-6.12.96+deb13-amd64:&lt;br /&gt;We get a LOT further – and we see a crash / trace-back:&lt;/p&gt;



&lt;pre class="wp-block-preformatted has-cyan-bluish-gray-background-color has-background has-small-font-size"&gt;&lt;code&gt;[ 34.285342] BUG: kernel NULL pointer dereference, address: 0000000000000000&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;I raised bug &lt;a href="mailto:1143721@bugs.debian.org"&gt;#1143721&lt;/a&gt; and followed it up with screen captures of the boot sequence (captured from the IPMI client) and files containing the output of dmidecode, lscpu and lspci to kive the kernel team as much information as possible:&lt;/p&gt;



&lt;div class="is-vertical is-content-justification-left is-layout-flex wp-container-1 wp-block-group"&gt;
&lt;pre class="wp-block-preformatted has-small-font-size"&gt;[&lt;a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=1143721;filename=6.12.96%2Bdeb13-amd64+debug+earlycon%3Defifb+keep_bootcon.tar.gz;msg=10"&gt;6.12.96+deb13-amd64 debug earlycon=efifb keep_bootcon.tar.gz&lt;/a&gt; (application/gzip, attachment)]&lt;/pre&gt;



&lt;pre class="wp-block-preformatted has-small-font-size"&gt;[&lt;a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?att=2;bug=1143721;filename=dmidecode.txt;msg=10"&gt;dmidecode.txt&lt;/a&gt; (text/plain, attachment)]&lt;/pre&gt;



&lt;pre class="wp-block-preformatted has-small-font-size"&gt;[&lt;a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?att=3;bug=1143721;filename=lscpu.txt;msg=10"&gt;lscpu.txt&lt;/a&gt; (text/plain, attachment)]&lt;/pre&gt;



&lt;pre class="wp-block-preformatted has-small-font-size"&gt;[&lt;a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?att=4;bug=1143721;filename=lspci.txt;msg=10"&gt;lspci.txt&lt;/a&gt; (text/plain, attachment)]
&lt;/pre&gt;
&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;(6) Tracking down the bug Git Bisect&lt;/strong&gt;&lt;/p&gt;



&lt;p&gt;The problem with this type of bug is that it is hardware (class) specific, whilst the kernel doesn’t boot on my system, it clearly has worked on machines used by the kernel team, the Debian test and build infrastructure, &lt;em&gt;(otherwise this kernel would never have been released)&lt;/em&gt; and everyone else who has upgraded to the newer &lt;em&gt;kernel&lt;/em&gt; before I did &lt;em&gt;(otherwise we would be drowning in fails to boot bug reports)&lt;/em&gt;.  Carnil’s excellent response to my bug: &lt;a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143721#15"&gt;Message #15&lt;/a&gt; (and help in IRC) provided me with a detailed step by step guide in how to track down the individual git commit that fails on my system.  I had already (with Sledge’s suggestion) made a clone of the stable branch, but was struggling to follow the steps in the &lt;a href="https://kernel-team.pages.debian.net/kernel-handbook/ch-common-tasks.html#s-common-building"&gt;Debian Linux Kernel Handbook&lt;/a&gt; to re-build a duplicate kernel because I didn’t understand how to obtain the same configuration that Debian used to build the kernel; Carnil’s email provided me the missing steps (Highlighted).&lt;/p&gt;



&lt;pre class="wp-block-preformatted has-cyan-bluish-gray-background-color has-background has-small-font-size"&gt;git clone --single-branch -b linux-6.12.y https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git
cd linux-stable
git checkout v6.12.95
&lt;strong&gt;cp /boot/config-$(uname -r) .config
yes '' | make localmodconfig
make savedefconfig
mv defconfig arch/x86/configs/my_def&lt;/strong&gt;
test 6.12.96 to ensure this is "bad"
git checkout v6.12.96
&lt;strong&gt;make my_defconfig&lt;/strong&gt;
make -j $(nproc) bindeb-pkg
… install the resulting .deb package and confirm it fails to boot and triggers the NULL pointer dereference.&lt;strong&gt;
&lt;/strong&gt;&lt;/pre&gt;



&lt;p&gt;Right I can now start to Bisect the problem:&lt;/p&gt;



&lt;pre class="wp-block-preformatted has-cyan-bluish-gray-background-color has-background has-small-font-size"&gt;&lt;code&gt;git bisect start
git bisect good v6.12.95
git bisect bad v6.12.96&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;Rather than use the half step point’s git bisect suggested I was advised in irc to jump straight to the a given commit that from the git log was suspected as the culprit: &lt;/p&gt;



&lt;p class="has-cyan-bluish-gray-background-color has-background has-small-font-size"&gt;git checkout 977855894bca4b87afa50d21e3f3e85a5a0e901f&lt;br /&gt;build and install….&lt;br /&gt;fails…&lt;br /&gt;git bisect bad&lt;/p&gt;



&lt;p class="has-cyan-bluish-gray-background-color has-background has-small-font-size"&gt;git checkout 977855894bca4b87afa50d21e3f3e85a5a0e901f~1 ## ~1 is the commit beforehand&lt;br /&gt;build and install….&lt;br /&gt;fails…&lt;br /&gt;git bisect good&lt;/p&gt;



&lt;p&gt;The entire test tree can shown with &lt;code&gt;git bisect log&lt;/code&gt; and this was submitted as an email to the bug report, we have found our smoking gun :-)&lt;/p&gt;



&lt;p&gt;&lt;em&gt;Finally I would like to thank Carnil, Iam_tj for their time patience and fantastic support in guiding me through finding this regression.  Right now kernel bugs are coming in thick and fast with a lot of AI assisted bug hunting, the increased numbers of bugs mean that the kernel team are especially busy.  Hopefully our paths will cross and I’ll be able to buy you some beers (or whatever) soon.  thank you.  Sledge also deserves thanks for putting up with me and pointing me in the right direction (as ever).  Lucky for me that he lives nearby so I can provide beers on a regular basis :-)&lt;/em&gt;&lt;/p&gt; </description> 
	<pubDate>Tue, 18 Aug 2026 10:50:43 +0000</pubDate>

</item> 
<item>
	<title>John Goerzen: AI in Debian: The Vote, Proposals, and Nuance</title>
	<guid>https://changelog.complete.org/?p=44740</guid>
	<link>https://changelog.complete.org/archives/44740-ai-in-debian-the-vote-proposals-and-nuance</link>
     <description>  &lt;p&gt;Let me start with a hypothesis:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;For human developers, using coding LLMs magnifies their difference in skill levels.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;I am one that rarely thinks things are always black and white.  Back in March, I wrote &lt;a href="https://changelog.complete.org/archives/42503-artificial-intelligence-shades-of-gray"&gt;Artifial Intelligence: Shades of Gray&lt;/a&gt;.  Since then, I’ve had more of a chance to experiment with LLMs myself.  I also happen to work for an employer that is taking a very pragmatic approach to LLMs: teams and individuals use it as they see fit, but if they are causing considerable expense, they have to justify it.&lt;/p&gt;
&lt;p&gt;In various settings, I have seen the egregious examples of AI slop we all know about.  As I wrote in March, “I have seen it both waste more time than it saves, and save a ton of time.”&lt;/p&gt;
&lt;p&gt;I have come to see that, as a tool, it is most valuable when it is running under the supervision of an experienced engineer.  It is at its worst when it has no such supervision; the “vibe coding” and other low-quality slop we see.&lt;/p&gt;
&lt;p&gt;A coding agent is like a junior developer or research assistant.  When properly supervised, they help projects move along more quickly by letting a senior developer focus on the more difficult, less mundane aspects of the project.  But one couldn’t expect a junior developer to consistently deliver high-quality code and architecture on their own.&lt;/p&gt;
&lt;p&gt;Let’s put a pin in this idea and look at the story in Debian.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;LLM use in Debian&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;There is a &lt;a href="https://www.debian.org/vote/2026/vote_002"&gt;vote happening&lt;/a&gt; in Debian around the use of LLMs.  In typical Debian fashion, there are 8 options to choose from, many of them similar.  Most of these proposals acknowledge there are different types of tasks done in Debian, but the proposals don’t differentiate between them well.  Let me do so here.  These are some of the LLM-relevant tasks people in Debian perform:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Packaging upstream software for Debian (by far the largest task)&lt;/li&gt;
&lt;li&gt;Writing Debian-specific code (eg, apt or the Debian installer)&lt;/li&gt;
&lt;li&gt;Maintaining Debian infrastructure (build systems, for instance)&lt;/li&gt;
&lt;li&gt;Writing documentation and translations&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I’m going to focus my remarks here on packaging upstream software for Debian, since this is by far the most time-consuming developer task project-wide.&lt;/p&gt;
&lt;p&gt;It matters to our users that we get this right, and packaging quality is one of the things that sets Debian apart from other distros.  Packaging things for Debian requires knowledge of some specific tools, such as debhelper, that aren’t widely used anywhere else.  In most cases, it is fairly rote time-consuming work.  In other words, by its design, it requires people with senior-level skills to do grunt work.&lt;/p&gt;
&lt;p&gt;I can’t overstate how massive a burden this grunt work is.  I maintain some packages for Go and Rust.  By Debian policy, all of those packages’ dependencies must also exist as Debian packages, and be used to build against.  When upstream adopts a newer version of some library, it can unleash cascading dependencies that can take hours to sort out.  Worse, the Rust team and the Go team use entirely different ways of managing packages (Go uses one Git repo per package, while Rust has a monorepo with specialized scripts to import Cargo packages and generate Debian ones).  On top of that, we can’t just modify things like usual; we have to use quilt.  And on top of that, I’m also a backports maintainer, so all the work (and usually even more) has to be done there also.&lt;/p&gt;
&lt;p&gt;Now let’s pull on that pin from the earlier conversation.  This is exactly the kind of scenario that a well-supervised coding LLM is most effective in.  I could see a seasoned developer saving hours, maybe even days, by turning over the mundane tasks of managing trees of cascading dependencies over to a coding tool — and verifying and directing the process.  (Yes, I have been using em-dashes for years; LLMs have copied people like me, not the other way around!  This post was not written with any AI assistance.)&lt;/p&gt;
&lt;p&gt;Actually, this is almost a dream scenario for a coding assistant.  The result is time-consuming to formulate but easy to review, which is the opposite of the way these things often go.&lt;/p&gt;
&lt;p&gt;I can assure you with 100% certainty that humans aren’t adding a lot of value in this process.  It would be wrong to believe that a human is carefully reading every line of code in dozens of updated or new library packages.  The problem set is too big, the time too short, and the code too varied and complex.&lt;/p&gt;
&lt;p&gt;Coding agents seem to be most effective when there are strong test suites that they can test changes against.  Debian builds, especially of modern packages, tend to have this property.  Many packages have test suites that are run during build.  And, if the package builds in an isolated environment (and especially if its downstream dependencies do also), then there is a decent chance that it’s fairly correct.  Maybe needing some manual tweaking here and there, but generally a successful build is a reasonable indicator.&lt;/p&gt;
&lt;p&gt;You can argue that it would make more sense for Debian to just include dependencies in source packages, along with some version information to support security rebuilds, and I’d tend to agree with you.  But we are where we are.  This would be one of the more significant leaps forward in developer productivity, but it complicates things like copyright reviews.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Where are LLMs run?  What is the environmental impact?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Most of the proposals seem to make the assumption that LLMs must always run in some large, hosted datacenter.  As I noted in &lt;a href="https://changelog.complete.org/archives/42503-artificial-intelligence-shades-of-gray"&gt;my March article&lt;/a&gt;, I have had credible results on even an older GPU running on solar power.&lt;/p&gt;
&lt;p&gt;That said, it is undeniable that LLMs are fueling a datacenter boom, and this in turn is producing a significant new demand for resources.  Most notably for the global scale: electricity, which is sometimes generated using carbon-emitting technologies.&lt;/p&gt;
&lt;p&gt;Bill McKibben, who has been a leading voice in the fight against climate change since the 1980s, has made some interesting points recently: he’s noted that &lt;a href="https://www.youtube.com/watch?v=_iOxU4-OLss"&gt;solar power is the fastest kind of generation we can build&lt;/a&gt;, and a number of large AI companies are investing heavily in solar, even to the point of fully offsetting new datacenter’s needs.  On the other hand, he’s also noted that some companies are buying inefficient and dirty gas turbines.  It is decidedly a mixed bag.  The heavy investment in solar can have knock-on positive effects for infrastructure.  Obviously, not every picture here is rosy.  This analysis doesn’t touch on the real land and water use situation, either.&lt;/p&gt;
&lt;p&gt;On the other hand, if an LLM allows me to do in an hour what I would have done in a day, that’s a day of not heating or cooling the work area — generally not sustaining a human for the purpose of writing code for Debian.  HVAC energy consumption dwarfs my GPU, and I’d imagine probably also the slice of LLM energy used.&lt;/p&gt;
&lt;p&gt;Holistically, I would have to conclude the picture is mixed.  It is possible to use LLMs in a pretty green way, and also in a pretty dirty way.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Assuming Conditions Never Change&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;A flaw in most of these proposals is they assume that the conditions at this present moment will always hold.  In fact, that the conditions at the present moment will &lt;b&gt;not&lt;/b&gt; continue is something both AI cheerleaders and AI skeptics agree on.&lt;/p&gt;
&lt;p&gt;For instance:&lt;/p&gt;
&lt;p&gt;Ed Zitron has done a &lt;a href="https://www.wheresyoured.at/"&gt;ton of research&lt;/a&gt; into the financing side of AI, and has concluded that the current model is unsustainable and headed for a significant bubble burst.  I’m not positioned to personally evaluate those claims, but if that happens, what is the result?  Perhaps it is a steeply increasing cost of inference for the frontier models, slower pace of training/evolution for them, etc.&lt;/p&gt;
&lt;p&gt;In a &lt;a href="https://www.youtube.com/watch?v=f_6TzmifxnI"&gt;recent episode of Oxide and Friends&lt;/a&gt;, Simon Willison discussed the open weight models that are now available.  They have been making remarkable strides in efficiency and capabilities, to the point where $50,000 of hardware can now run high-end open weight models with capabilities that are at least in the same ballpark as the American frontier models.  This puts running high-end models locally squarely within reach of universities and small- to medium-sized businesses, with power requirements that can be met with standard commercial solar and wind installations.&lt;/p&gt;
&lt;p&gt;The lack of nuance in the more restrictive proposals is particularly concerning.  Proposal A doesn’t allow “the use or assitance of… LLMs”.  So it bans my solar-powered GPU.  It bans using LLMs to find security issues.  It bans all sorts of things that don’t seem to be ban-worthy, alongside the things that do.  And it codifies it in the very hard-to-change social contract.&lt;/p&gt;
&lt;p&gt;That proposal, and some like it, seem to imply that all LLM output is bad.  I grant you that AI slop is a real and legitimate concern, and many Open Source projects have to deal with it.  On the other hand, we have all seen first-hand how the security of the Linux kernel has benefited dramatically from AI analysis.  It is certain that black hats are using these tools.  If we refuse to use modern security tools, our security will be compromised (and what is the environmental and social impact of THAT?)&lt;/p&gt;
&lt;p&gt;I find the statement “Generative AI is characterized by producing output of a nature that would ordinarily be produced and consumed by humans” to be particularly interesting.  The same was once said of compilers.  &lt;/p&gt;
&lt;p&gt;&lt;b&gt;The Real Concerns&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;You might think from reading this that I am some AI cheerleader.  I’m not.  I share the ethics of the FLOSS movement, and have for decades.  I abhor the power and lack of ethics that many big names in the field are running with at the moment.  I’ve had to put up Anubis on this blog, for instance.&lt;/p&gt;
&lt;p&gt;I have personally experienced the effects of AI slop, especially at review time.  This is a real problem, though I don’t think the more draconian policies are likely to help (the looser “you must disclose” stand a fighting chance, but I’m not sure they would help, either.)  Done poorly, AI threatens developer burnout by overwhelming them with poor code and verbose but useless explanations.  Done well, AI can help prevent developer burnout by automating tedious and low-value tasks.&lt;/p&gt;
&lt;p&gt;Shouldn’t our goal be that humans submit work to Debian, using tools they prefer, and take responsibility for it?  Does it matter if someone uses ed, vim, emacs, or vscode?  If they use LSP or just run gcc manually?  I’d say we benefit from the diversity.  Wouldn’t we be better off to benefit from the diversity here, and judge work as we always have: on its merits, not what tools were used to create it?&lt;/p&gt;
&lt;p&gt;Fundamentally, a GR is a long and arduous process.  It’s not easy to reverse later.  Amending the Social Contract is even longer and more arduous (I should know; I may have been the &lt;a href="https://www.debian.org/vote/2000/vote_0008"&gt;first one to try&lt;/a&gt;).  The LLM landscape is fast-moving.  None of us can really predict where it will be in a year.  Will the current market leading companies even still exist?  Will it be at all credible to refuse to use AI-assisted security tools?   What is the most effective way to deal with AI slop?  What level of utility will we be able to achieve with models run locally?&lt;/p&gt;
&lt;p&gt;Some of these proposals would make sense if drafted in some way short of a GR, which would allow more maneuverability as the landscape changes.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Brief analysis of the options&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Considering the proposals:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Proposal A: seeks to amend the social contract, which I am opposed to for reasons already laid out above.  It names some real concerns about AI that I agree with, but implies that all LLM uses and models are guilty of the problems, which is not the case with all of the claims.  It also sets us behind the curve on security and stability by forbidding the use or assistance of those tools, even if run by others.  It &lt;b&gt;requires us to ignore reports of actual security bugs, or correct fixes, if those reports were generated with the assistance of an LLM&lt;/b&gt;, which I find to be absolutely untenable.&lt;/li&gt;
&lt;li&gt;Proposal B: This is the “AI with accountability” approach.  It notes the real concerns with LLMs without painting with an overbroad brush.  It strikes me as level-headed and sensible.&lt;/li&gt;
&lt;li&gt;Proposal C: It paints with an over-broad brush and makes some non-binding requests.  Then it winds up largely like proposal B, though while it is worded more strongly, has fewer binding requirements (for instance, it lacks proposal B’s prohibition on transmitting sensitive information to untrusted providers)&lt;/li&gt;
&lt;li&gt;Proposal D: Seems broadly similar to proposal B, an “AI with accountability” approach.  I’m not really clear why we need both.&lt;/li&gt;
&lt;li&gt;Proposal E: Largely the status quo.  It is like proposals B and D in that it says humans are accountable for their contributions.  It encourages disclosure of LLM use, but does not mandate it.  Like proposal B, it prohibits disclosing sensitive information to third-party AI services.  Note that both proposals B and D have an appropriate nuance: a local model is fine, a third-party one is not.&lt;/li&gt;
&lt;li&gt;Proposal F: This seems really similar to proposal E.  I’m not sure why we have these two.&lt;/li&gt;
&lt;li&gt;Proposal G: Disallows “the output of generative AI as direct contributions to Debian.”  This is something of a weakened proposal A; it doesn’t seek to amend the social contract, nor does it ban all use; it simply bans the use as a direct contribution.&lt;/li&gt;
&lt;li&gt;Proposal H: Ban due to climate impacts.  “How is this even an argument” is disrespectful to reasoned conversation.  I have already noted that LLMs can be and are used in ways that are not climate-harming.  It explicitly contains no binding requirements at all, and is effectively a rant.  While I agree with the sentiment that climate change is an urgent problem, and that some LLMs are exacerbating it, I disagree with that all LLM usage does so and therefore disagree with the conclusion.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;In favor of nuance&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;I find that black-and-white thinking is almost always something to be avoided.  I see it too often.  I see it in politics, I see it in our software, I see it in discussions around AI.  Are there deeply unethical things happening in AI?  &lt;a href="https://www.404media.co/we-tracked-a-shipment-of-rare-books-it-ended-at-an-amazon-ai-training-facility/"&gt;Absolutely&lt;/a&gt;.  Are they doing some impressive things?  &lt;a href="https://cybersecuritynews.com/linux-patches-400-kernel-vulnerabilities/"&gt;Also yes&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We have accepted this nuance in other areas.  For instance, almost all the hardware Debian runs on has closed-source hardware, and has components manufactured or assembled in countries with some of the worst human rights records on the planet.  I’m not saying this is a great state of affairs.  It is something we should speak up about and act upon.  But the &lt;i&gt;worse&lt;/i&gt; state of affairs would be “no Debian because the hardware is impure”.&lt;/p&gt; </description> 
	<pubDate>Tue, 18 Aug 2026 01:39:54 +0000</pubDate>

</item> 
<item>
	<title>Bits from Debian: Debian turns 33!</title>
	<guid>tag:bits.debian.org,2026-08-16:/2026/08/debian-turns-33.html</guid>
	<link>https://bits.debian.org/2026/08/debian-turns-33.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/dwn.png" width="77" height="85" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;It has now been thirty-three years since the Debian project was &lt;a href="https://wiki.debian.org/DebianHistory?action=AttachFile&amp;amp;do=get&amp;amp;target=Debian-announcement-1993.txt"&gt;announced&lt;/a&gt; to
the world by Ian Murdock, on August 16, 1993. This anniversary is an
opportunity to reaffirm the goals, characteristics, and qualities of the
Debian project: it’s an association of individuals who have made common cause
to create a free operating system. Our distribution is characterized by a
commitment to software freedom, as enshrined in the &lt;a href="https://www.debian.org/social_contract"&gt;Debian Social Contract&lt;/a&gt;
and the Debian Free Software Guidelines. It focuses on security and
stability. This stability is crucial to Debian position in the free software
ecosystem.&lt;/p&gt;
&lt;p&gt;With our users as our priority, Debian makes special efforts regarding
accessibility with &lt;a href="https://www.debian.org/devel/debian-accessibility/"&gt;Debian-Accessibility&lt;/a&gt; and diversity with our &lt;a href="https://wiki.debian.org/Teams/Outreach"&gt;Outreach
Programs&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Debian Day is a great opportunity to get together, whether for a local meetup,
or simply to grab a coffee with other members of the Debian community. Check
out the &lt;a href="https://wiki.debian.org/DebianDay/2026"&gt;Debian Day wiki&lt;/a&gt; to see if there is a celebration near you. And if
there isn't, maybe &lt;a href="https://wiki.debian.org/DebianDay#Organize_a_local_Debian_Day_celebration"&gt;you can organize it&lt;/a&gt; next year!&lt;/p&gt;
&lt;p&gt;Today is also an opportunity for you to start or resume your contributions
to Debian. For example, you can install the &lt;a href="https://packages.debian.org/trixie/how-can-i-help"&gt;how-can-i-help package&lt;/a&gt; and
see if there is a bug in any of the software that you use that you can help
to fix, contribute small tips on how to install Debian on your machines to our
&lt;a href="https://wiki.debian.org/InstallingDebianOn/"&gt;wiki pages&lt;/a&gt;, or put a &lt;a href="https://www.debian.org/CD/live/"&gt;Debian live&lt;/a&gt; image in an USB memory
and give it to some person near you, who still didn't discover Debian.&lt;/p&gt;
&lt;p&gt;Thanks to everybody who has contributed to develop our beloved operating
system in these 33 years, and
&lt;strong&gt;Happy birthday Debian!&lt;/strong&gt;&lt;/p&gt; </description> 
	<pubDate>Sun, 16 Aug 2026 13:00:00 +0000</pubDate>

</item> 
<item>
	<title>Vasudev Kamath: Releasing debvulns-exporter and debvulns CLI 0.2.2</title>
	<guid>tag:copyninja.in,2026-08-16:/blog/debvulns-exporter-newversion.html</guid>
	<link>https://copyninja.in/blog/debvulns-exporter-newversion.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/vasudev.png" width="65" height="85" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;I made another minor release with several enhancements: handling non-Debian
origin vulnerabilities, improving data caching, and sharing the cache
between the &lt;tt class="docutils literal"&gt;debvulns&lt;/tt&gt; CLI and the exporter. Additionally, there are a few
improvements on the dashboard front. Here is a breakdown of what changed.&lt;/p&gt;
&lt;div class="section" id="handling-vulnerabilities-in-non-debian-origin-packages"&gt;
&lt;h2&gt;Handling Vulnerabilities in Non-Debian Origin Packages&lt;/h2&gt;
&lt;p&gt;During the previous release, I noticed that the &lt;tt class="docutils literal"&gt;grafana&lt;/tt&gt; package—which is
not in Debian and was installed via an upstream repository—was reported as
vulnerable with multiple issues. Looking into why this happened, I found that
all the CVEs reported in the dashboard were indeed listed on
&lt;tt class="docutils literal"&gt;&lt;span class="pre"&gt;security-tracker.debian.org&lt;/span&gt;&lt;/tt&gt;, but without a fixed version or status
description. The logic assumed no fix was available and marked the package
as vulnerable on the dashboard.&lt;/p&gt;
&lt;div class="section" id="how-did-i-solve-this"&gt;
&lt;h3&gt;How Did I Solve This?&lt;/h3&gt;
&lt;p&gt;Google maintains a distributed vulnerability database for open-source
projects called &lt;a class="reference external" href="https://osv.dev"&gt;osv.dev&lt;/a&gt;. I checked the generic vulnerability
data for those CVEs on OSV (unbound to any specific distribution) and found that
the issues were already fixed in the upstream version I was running. What I
needed was a way to differentiate native Debian packages from non-Debian
packages, which corresponds to the &lt;tt class="docutils literal"&gt;Origin&lt;/tt&gt; field in APT metadata.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="pitfall"&gt;
&lt;h3&gt;Pitfall&lt;/h3&gt;
&lt;p&gt;The AI-generated code initially attempted to differentiate package origin using
&lt;tt class="docutils literal"&gt;apt_pkg.PackageRecords&lt;/tt&gt; and its &lt;tt class="docutils literal"&gt;origin&lt;/tt&gt; field. However, many native Debian
packages were incorrectly flagged as non-Debian. On closer inspection, when an
upgrade is available for a package, the installed version's origin field can be
unset. I had to resolve this by detecting available upgrades and inspecting the
candidate version's origin instead, which was implemented in &lt;a class="reference external" href="https://github.com/copyninja/debsecan-mcp/commit/cc72d477d0d0a6ff2ba5d2b70007bfc13fd50172"&gt;this patch&lt;/a&gt;.
This solution was proudly crafted by me ;-) (partly because I ran out of API
limits and had to wait 6 hours for the next reset).&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="caching-osv-data"&gt;
&lt;h3&gt;Caching OSV Data&lt;/h3&gt;
&lt;p&gt;Initially, the AI implemented the exporter to re-download the entire OSV dataset
on every run, which was unnecessary. Since vulnerability data does not change
rapidly once published, caching it on disk for longer than the standard 24-hour
Debian/EPSS cache makes sense. OSV vulnerability data is now cached for 7 days
before a refresh is triggered.&lt;/p&gt;
&lt;p&gt;All cache expiration thresholds remain configurable via CLI flags.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="catch"&gt;
&lt;h3&gt;Catch&lt;/h3&gt;
&lt;p&gt;One caveat with this approach: I have not yet verified whether every upstream CVE
is tracked on &lt;tt class="docutils literal"&gt;&lt;span class="pre"&gt;security-tracker.debian.org&lt;/span&gt;&lt;/tt&gt;. In the case of &lt;tt class="docutils literal"&gt;grafana&lt;/tt&gt;, the
entries existed. This feature operates on the assumption that
&lt;tt class="docutils literal"&gt;&lt;span class="pre"&gt;security-tracker.debian.org&lt;/span&gt;&lt;/tt&gt; indexes CVE metadata regardless of whether the
package is native to Debian. I plan to re-evaluate this and add fallback handling
if that assumption fails.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="unified-cache-directory-for-cli-and-exporter"&gt;
&lt;h2&gt;Unified Cache Directory for CLI and Exporter&lt;/h2&gt;
&lt;p&gt;Another issue was cache segregation: the &lt;tt class="docutils literal"&gt;debvulns&lt;/tt&gt; CLI utility defaulted to
&lt;tt class="docutils literal"&gt;/var/cache/debvulns&lt;/tt&gt;, while the Prometheus exporter used
&lt;tt class="docutils literal"&gt;&lt;span class="pre"&gt;/var/cache/debvulns-exporter&lt;/span&gt;&lt;/tt&gt;. While harmless when running only one tool,
installing both led to duplicated cache storage and redundant network requests.
Since the core evaluation logic is identical across both tools, they now share a
unified cache directory to eliminate duplicate downloads.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="dashboard-changes"&gt;
&lt;h2&gt;Dashboard Changes&lt;/h2&gt;
&lt;p&gt;During the initial dashboard rollout, my test environment (my laptop alongside
Debian 11 and Debian 12 VMs) reported a high aggregated vulnerability count.
It was not immediately obvious whether these were distinct vulnerabilities or the
same CVEs replicated across all three machines. This mirrors common questions
raised during vulnerability reviews:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;How many unique vulnerabilities are present across the fleet?&lt;/li&gt;
&lt;li&gt;Which unique packages are affected?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The dashboard has been redesigned to surface unique vulnerability counts
alongside affected package lists. The updated dashboard is shown below:&lt;/p&gt;
&lt;img alt="" src="https://copyninja.in/images/new_debvulns_dashboard.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="what-s-next"&gt;
&lt;h2&gt;What's Next?&lt;/h2&gt;
&lt;p&gt;A few planned items remain to make &lt;tt class="docutils literal"&gt;debvulns&lt;/tt&gt; a comprehensive vulnerability
reporting toolkit for Debian systems:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;&lt;strong&gt;Kernel Vulnerability Handling:&lt;/strong&gt; Currently, installing a patched kernel
marks the vulnerability as resolved, even if the system has not rebooted into
it. The system remains exposed while the vulnerable kernel is executing in
memory. Factoring in running kernel versions is crucial.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reboot and Service Restart Tracking:&lt;/strong&gt; Similar to kernel upgrades requiring
a reboot, userland library and binary fixes require running services to be
restarted. This is typically detected via &lt;tt class="docutils literal"&gt;needrestart&lt;/tt&gt;. Integrating this
behavior directly into &lt;tt class="docutils literal"&gt;debvulns&lt;/tt&gt; will provide complete visibility in a
single dashboard metric.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Debian Packaging:&lt;/strong&gt; Once the above features are stable, the final step is
packaging &lt;tt class="docutils literal"&gt;debvulns&lt;/tt&gt; for Debian so it can be installed directly from the
archive.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Until then, happy hacking.&lt;/p&gt;
&lt;/div&gt; </description> 
	<pubDate>Sun, 16 Aug 2026 11:30:00 +0000</pubDate>

</item> 
<item>
	<title>Benjamin Mako Hill: Sad Story</title>
	<guid>https://mako.cc/copyrighteous/?p=3361</guid>
	<link>https://mako.cc/copyrighteous/sad-story</link>
     <description>  &lt;img src="http://planet.debian.org/heads/mako.gif" width="65" height="93" alt="" align="right" style="float: right;"&gt;  &lt;figure class="wp-block-image size-large"&gt;&lt;a href="https://mako.cc/copyrighteous/wp-content/uploads/2026/08/PXL_20260719_1815328531-scaled.jpg"&gt;&lt;img alt="Picture of a box in a fireplace saying: " class="wp-image-3363" height="1024" src="https://mako.cc/copyrighteous/wp-content/uploads/2026/08/PXL_20260719_1815328531-576x1024.jpg" width="576" /&gt;&lt;/a&gt;&lt;/figure&gt;



&lt;p class="wp-block-paragraph"&gt;Not a &lt;a href="https://screenshotsofdespair.tumblr.com/"&gt;screenshot of despair&lt;/a&gt;. But only because it’s not a screenshot.&lt;/p&gt; </description> 
	<pubDate>Sun, 16 Aug 2026 07:01:10 +0000</pubDate>

</item> 
<item>
	<title>Sven Hoexter: FrOSCon 2026: TLS Talk</title>
	<guid>http://sven.stormbind.net/blog/posts/talk_froscon2026_tls_ech_caa_https/</guid>
	<link>http://sven.stormbind.net/blog/posts/talk_froscon2026_tls_ech_caa_https/</link>
     <description>  &lt;p&gt;Info: German content only, sorry.&lt;/p&gt;

&lt;p&gt;I was pondering for the past three years if I should give some sort
of TLS basics talk at FrOSCon. I finally stepped up this year
and gave that talk today, with the title
"TLS, mTLS, SNI, ECH, CAA, HTTPS, PKI, Zertifikate und ein bisschen PQC".
I was too optimistic with my 50 slides, and had to drop the
Post Quantum Cryptography part at the end. Still got positive feedback from
Zugschlus and others - thanks a lot for that &amp;lt;3 - and was asked for the slides.
It's not a piece of art, but maybe it helps to release the LibreOffice odp file
as well, so others can use it as a base for other events or corp internal talks.
So here is the
&lt;a href="https://sven.stormbind.net/talks/froscon2026/froscon-tls-2026.pdf"&gt;froscon-tls-2026.pdf&lt;/a&gt;
and
&lt;a href="https://sven.stormbind.net/talks/froscon2026/froscon-tls-2026.odp"&gt;froscon-tls-2026.odp&lt;/a&gt;,
both released under the CC BY-NC license.&lt;/p&gt;

&lt;p&gt;The video is also available at
&lt;a href="https://media.ccc.de/v/froscon2026-3584-tls_mtls_sni_ech_caa_https_pki_zertifikate_und_ein_bisschen_pqc"&gt;media.ccc.de&lt;/a&gt; if you want to watch it.&lt;/p&gt;

&lt;p&gt;Thanks to everyone who made FrOSCon happen for the 21th time!&lt;/p&gt; </description> 
	<pubDate>Sat, 15 Aug 2026 18:02:03 +0000</pubDate>

</item> 
<item>
	<title>Russell Coker: Hacked by Chinafans</title>
	<guid>https://etbe.coker.com.au/?p=6276</guid>
	<link>https://etbe.coker.com.au/2026/08/15/hacked-chinafans/</link>
     <description>  &lt;h2&gt;What Happened&lt;/h2&gt;
&lt;p&gt;On 2026/08/10 at 2:11 am Australian eastern standard time (2026/08/09 16:11 UTC) someone created a post titled “Hacked by Chinafans” on &lt;a href="https://doc.coker.com.au/"&gt;my documents blog [1]&lt;/a&gt;. The person in question created an account named “67965e42a3c3” on that site with the email address 67965e42a3c3@google.com associated with it (I tried emailing that address and it bounced).&lt;/p&gt;
&lt;p&gt;At 04:28:41am Australian eastern standard time (18:28 UTC) I was sent an email titled “Have you been hacked” by a reader of my blogs who subscribed to the RSS feed of my documents blog (a blog that I never expected anyone to read by RSS). Along the lines of “the wisdom of crowds” should we have “the unexpected observation and problem reporting of crowds”? I appreciate the notification, I might not have noticed until the next time I watched an unusually good movie otherwise.&lt;/p&gt;
&lt;p&gt;The account in question was apparently created on 2026-07-21 at 16:43:47 (presumably UTC) even though at the time I believe creating accounts was not permitted. As an aside the timestamp of account creation is stored in the user_registered column of the wp_users table in the database, there doesn’t appear to be a way to access this in a standard WordPress installation other than doing a SQL query.&lt;/p&gt;
&lt;pre&gt;2026-07-24 15:43:17 status triggers-pending wordpress:all 7.0+dfsg1-1
2026-07-24 15:43:19 upgrade wordpress:all 7.0+dfsg1-1 7.0.2+dfsg1-1&lt;/pre&gt;
&lt;p&gt;Above are the relevant sections of my dpkg log showing the WordPress versions in use. I was running version 7.0+dfsg1-1 at the time the account was apparently created. I am confident in the accuracy of the dpkg logs and believe that they did not compromise the OS, I am not sure whether they ran hostile SQL code to change fields in the MySQL database so had to consider the possibility that the account creation time could have been set to a deliberately misleading value. I checked backups of the MySQL database stored off-site and found that the account in question was not in the 2026-07-21 backup (which was done before 16:43) but in the 2026-07-22 backup.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://en-au.wordpress.org/download/releases/"&gt;WordPress release history [2]&lt;/a&gt; has version 7.0.1 released on 2026-07-09 and version 7.0.2 released on 2026-07-17. So presumably the attacker diffed the code on those releases, found an exploitable bug, and used it to create an account on my blog with admin privs. Then they waited a few weeks to see if I would notice and published a blog post when I didn’t notice.&lt;/p&gt;
&lt;h2&gt;WordPress Deficiencies&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;WordPress doesn’t seem to store the version it’s running at the time of operations. So anyone who doesn’t have a suitable external log of versions deployed (such as the dpkg.log file for a Debian managed installation) won’t know for sure which version was running. It supports automatic updates but you can’t be sure that they happened soon after the release.&lt;/li&gt;
&lt;li&gt;There is no log of IP addresses used for operations. There are apparently some 3rd party modules to log such things and web pages documenting how to modify the PHP to add it but nothing in the standard distribution.&lt;/li&gt;
&lt;li&gt;Software should have a standard distribution with some support for logging of security relevant data. The typical situation is that people don’t plan for logging such things until after they have been attacked so the data should be recorded without users going out of their way to log it.&lt;/li&gt;
&lt;li&gt;A log of security relevant data should be stored in a database table with only insert access (no update, delete, or drop).&lt;/li&gt;
&lt;li&gt;Ideally a CMS would support different database accounts for different purposes. Someone from an internal network or VPN could talk to an instance of the web server which has a database username and password giving full access. Everyone from outside the trusted range gets an instance of the web server with database access only allowing to read the posts and appearance configuration and to enter comments. If the database didn’t allow the account used for public access to create new admin users or create posts then it would be a lot harder for attackers.&lt;/li&gt;
&lt;li&gt;Ideally for everything that stores user account data there would be an easy way of getting a list of users in a plain text format to allow running diff. The design of WordPress has two tables, one for users and one for encoded metadata about users of which one will be the access level. The following SQL command will give a list of all users that aren’t subscribers (everyone above the minimum level of access which is typical for new users) along with their encoded password and access level. This could be used in a monitoring system to alert about new privileged users. The TABLE_PREFIX variable is for the prefix for WordPress tables, which is “wp_” by default but can be any legal value.
&lt;pre&gt;select $TABLE_PREFIXusers.user_login, $TABLE_PREFIXusers.user_pass, $TABLE_PREFIXusermeta.meta_value from  $TABLE_PREFIXusers join $TABLE_PREFIXusermeta on $TABLE_PREFIXusers.id = $TABLE_PREFIXusermeta.user_id and meta_key='$TABLE_PREFIXcapabilities' and meta_value != 'a:1:{s:10:"subscriber";b:1;}';&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;What Next?&lt;/h2&gt;
&lt;p&gt;The blog post they created had a couple of links to Telegram which could presumably be used to contact them. If anyone involved in computer security wants a copy of the original post to do so then they can contact me by any of the usual methods.&lt;/p&gt;
&lt;p&gt;I am interested in communication with the attacker if they wish, Telegram is not a service I use but I presume that anyone capable of doing this sort of attack is also capable of finding other ways of contacting me.&lt;/p&gt;
&lt;p&gt;I have idly considered changing to a static site generator, &lt;a href="https://jamstack.org/generators/"&gt;here is a good list of static site generators [3]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I have also idly considered other platforms for blogging such as Lemmy. I don’t know if Lemmy is better than WordPress for security and updates, but there are plenty of free instances running where it wouldn’t be an issue I have to work on.&lt;/p&gt;
&lt;h2&gt;15 Years&lt;/h2&gt;
&lt;p&gt;It’s been &lt;a href="https://etbe.coker.com.au/2011/12/31/server-cracked/"&gt;15 years since my blog server was cracked by a trojaned ssh client [4]&lt;/a&gt;. At least this time it was only one service that was compromised.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href="https://doc.coker.com.au/"&gt; https://doc.coker.com.au/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href="https://en-au.wordpress.org/download/releases/"&gt; https://en-au.wordpress.org/download/releases/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href="https://jamstack.org/generators/"&gt; https://jamstack.org/generators/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[4]&lt;a href="https://etbe.coker.com.au/2011/12/31/server-cracked/"&gt; https://etbe.coker.com.au/2011/12/31/server-cracked/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="yarpp yarpp-related yarpp-related-rss yarpp-template-list"&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2006/09/12/blogging-software/" rel="bookmark" title="blogging software"&gt;blogging software&lt;/a&gt; &lt;small&gt;Previously I asked for advice about running an Intranet blog,...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2007/10/22/wordpress-and-thumbnails/" rel="bookmark" title="WordPress and Thumbnails"&gt;WordPress and Thumbnails&lt;/a&gt; &lt;small&gt;I have just had a lot of trouble with Thumbnails...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2010/08/04/wordpress-maintainability/" rel="bookmark" title="WordPress Maintainability"&gt;WordPress Maintainability&lt;/a&gt; &lt;small&gt;For a while I’ve been maintaining my own WordPress packages....&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Sat, 15 Aug 2026 09:31:47 +0000</pubDate>

</item> 
<item>
	<title>Russell Coker: AMD Video Drivers, LLMs, and Debian Kernels</title>
	<guid>https://etbe.coker.com.au/?p=6278</guid>
	<link>https://etbe.coker.com.au/2026/08/15/amd-video-llms-debian-kernels/</link>
     <description>  &lt;h2&gt;The AMD GPU Problem&lt;/h2&gt;
&lt;p&gt;For a while I’ve been having issues with AMD GPUs, video locking up periodically. &lt;a href="https://etbe.coker.com.au/2025/11/09/amd-video-driver-issues/"&gt;I blogged about this late last year but I first had noticeable problems early last year [1]&lt;/a&gt;. The problems hadn’t only concerned my workstation but also my home server which is also used as a workstation. I’ve recently upgraded my machines to Debian/Testing, my home server has been generally OK but my workstation has been crashing a lot. Every second day when on kernel 7.1.6 and then when on 7.1.7 it crashed at least once a day.&lt;/p&gt;
&lt;p&gt;The AMD GPUs I have are “&lt;b&gt;[AMD/ATI] Baffin [Radeon RX 460/560D / Pro 450/455/460/555/555X/560/560X] (rev e5)&lt;/b&gt;” in my main desktop workstation, “&lt;b&gt;[AMD/ATI] Lexa [Radeon 540X/550X/630 / RX 640 / E9171 MCM] (rev c1)&lt;/b&gt;” in my build server, and “&lt;b&gt;[AMD/ATI] Baffin [Radeon RX 460/560D / Pro 450/455/460/555/555X/560/560X] (rev cf)&lt;/b&gt;” in my home server. They aren’t new GPUs, but also aren’t really old and they all support 4K and better resolution.&lt;/p&gt;
&lt;h2&gt;Chat GPT Was Useful&lt;/h2&gt;
&lt;p&gt;When I googled the errors I was seeing I found nothing useful. On the suggestion of a friend I tried asking ChatGPT. Generally I don’t recommend asking LLMs about such things, but it can be a last resort as long as you know what you are doing. ChatGPT asked me to run a number of commands to get information for it to make more informed decisions. I know that the output of lspci and similar commands isn’t a risk, but a novice could be tricked into running commands that expose sensitive data.&lt;/p&gt;
&lt;p&gt;ChatGPT did give me some useful information, not a solution but an indication that the problem was due to driver bugs.&lt;/p&gt;
&lt;h2&gt;Upgrading to Experimental&lt;/h2&gt;
&lt;p&gt;Debian/Experimental is for packages that are expected to have problems and generally aren’t recommended even for the people who usually use Debian/Unstable. It’s commonly used for packages that are needed to develop other packages, EG new libraries that aren’t fully usable but which are needed to package newer versions of applications.&lt;/p&gt;
&lt;p&gt;I upgraded my workstation to the Debian/Experimental kernel 7.2~rc7-1~exp1 after having tried every other convenient option. Generally I wouldn’t recommend that anyone run an Experimental kernel without a really good reason, but crashing more than once a day is a fairly good reason. That kernel has now given me over 4 days of uptime on a system that previously wouldn’t last a day. I installed it on my dual-socket build server that has an old AMD GPU in it for test purposes and that also hasn’t crashed since. I installed it on my ML test machine which has an Intel B580 Battlemage GPU with 16G of VRAM and was repeatedly getting a kernel panic related to the GPU a few seconds after boot and now it also works correctly.&lt;/p&gt;
&lt;p&gt;It seems that the 7.1.x kernels have bugs in the AMD video drivers and in some part of the code that affects Intel video drivers and that the bugs in question are fixed in the tree that will become 7.2. I would not recommend anyone who has a 7.1.x kernel working fine for them try 7.2 RC kernels at this time, but anyone who has GPU related problems (particularly Intel and AMD GPUs) should definitely test it out.&lt;/p&gt;
&lt;p&gt;I also don’t recommend upgrading any system with an AMD GPU to Debian/Testing or Debian/Unstable at this time unless you are also prepared to install an Experimental kernel if it becomes necessary.&lt;/p&gt;
&lt;p&gt;There are a several kernel log dumps related to this after the break (which won’t be in RSS feeds). This is mainly for Google so that other people who have such issues can get more useful results out of Google searches than I got.&lt;/p&gt;
&lt;h2&gt;Future Support Options&lt;/h2&gt;
&lt;p&gt;Separate from the issue of whether commercial LLMs like ChatGPT can be useful for solving technical problems there is the issue of whether they are desirable. I think that we really don’t want people solving problems in FOSS systems with closed-source LLMs. This leads to loss of privacy, loss of the control users deserve to have over their own systems, and an implied promotion of non-fee software.&lt;/p&gt;
&lt;p&gt;I think that the ideal would be to have a cross distribution effort to generate training data for a support LLM system which can then be further trained by each distribution for a greater emphasis on distribution specific issues.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href="https://etbe.coker.com.au/2025/11/09/amd-video-driver-issues/"&gt; https://etbe.coker.com.au/2025/11/09/amd-video-driver-issues/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span id="more-6278"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Errors on AMD GPUs&lt;/h2&gt;
&lt;pre&gt;2026-08-09T23:03:06.004792+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 147 0x00024802
2026-08-09T23:03:06.004792+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 42037 thread kscreenloc:cs0 pid 42044
2026-08-09T23:03:06.004793+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_ADDR 0x00000800
2026-08-09T23:03:06.004794+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_STATUS 0x0F048002
2026-08-09T23:03:06.004795+10:00 xev kernel: amdgpu 0000:02:00.0: VM fault (0x02, vmid 7, pasid 130) at page 2048, write from 'TC0' (0x54433000) (72)
2026-08-09T23:03:06.008762+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 147 0x00004802
2026-08-09T23:03:06.008768+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 42037 thread kscreenloc:cs0 pid 42044&lt;/pre&gt;
&lt;pre&gt;2026-08-04T01:13:37.505839+10:00 xev kernel: ------------[ cut here ]------------ 
2026-08-04T01:13:37.505859+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] drm_WARN_ON_ONCE(cur_vblank != vblank-&amp;gt;last) 
2026-08-04T01:13:37.505862+10:00 xev kernel: WARNING: CPU: 6 PID: 210534 at drivers/gpu/drm/drm_vblank.c:362 drm_update_vblank_count+0x2f1/0x3c0 [drm] 
2026-08-04T01:13:37.505866+10:00 xev kernel: snd_intel_dspcfg wmi_bmof rc_core snd_intel_sdw_acpi drm_ttm_helper uas realtek snd_usbmidi_lib snd_hda_codec ttm mdio_devres snd_hda_core snd_seq_midi drm_kms_helper usb_storage mc snd_hwdep libphy snd_seq_midi_event intel_uncore snd_pcm_oss i2c_algo_bit serio_raw snd_rawmidi pcspkr snd_mixer_oss i2c_i801 video snd_seq snd_pcm i2c_smbus lpc_ich snd_seq_device mei_me e1000e snd_timer mei snd tpm_infineon soundcore joydev bnx2 wmi button nfsd auth_rpcgss nfs_acl lockd grace sunrpc coretemp br_netfilter bridge stp llc sg ghash_clmulni_intel loop msr i2c_dev drm efi_pstore configfs nfnetlink ip_tables x_tables autofs4 btrfs blake2b_generic dm_crypt dm_mod raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx libcrc32c xor raid6_pq raid1 raid0 md_mod ext4 crc16 mbcache jbd2 crc32c_generic virtio_blk evdev hid_generic usbhid hid sd_mod xhci_pci xhci_hcd ahci ehci_pci ehci_hcd libahci crc32c_intel libata usbcore aesni_intel nvme psmouse scsi_mod gf128mul crypto_simd nvme_core cryptd 
2026-08-04T01:13:37.505879+10:00 xev kernel: nvme_auth scsi_common usb_common efivarfs 
2026-08-04T01:13:37.505880+10:00 xev kernel: CPU: 6 UID: 1008 PID: 210534 Comm: sshd-session Tainted: G D 6.12.88+deb13-amd64 #1 Debian 6.12.88-1 
2026-08-04T01:13:37.505881+10:00 xev kernel: Tainted: [D]=DIE 
2026-08-04T01:13:37.505883+10:00 xev kernel: Hardware name: Hewlett-Packard HP Z640 Workstation/212A, BIOS M60 v02.61 03/23/2023 
2026-08-04T01:13:37.505884+10:00 xev kernel: RIP: 0010:drm_update_vblank_count+0x2f1/0x3c0 [drm] 
2026-08-04T01:13:37.505885+10:00 xev kernel: Code: 48 8b 5f 50 48 85 db 75 03 48 8b 1f e8 68 eb 2b cf 48 c7 c1 70 3e cb c0 48 89 da 48 c7 c7 f9 6f cb c0 48 89 c6 e8 af d7 a6 ce &amp;lt;0f&amp;gt; 0b e9 4b fe ff ff 48 8b 4c 24 18 e9 31 fe ff ff 31 f6 48 85 db 
2026-08-04T01:13:37.505887+10:00 xev kernel: RSP: 0000:ffffd3cc8681fca0 EFLAGS: 00010082 
2026-08-04T01:13:37.505888+10:00 xev kernel: RAX: 0000000000000000 RBX: ffff8c6b42b13710 RCX: 0000000000000027 
2026-08-04T01:13:37.505889+10:00 xev kernel: RDX: ffff8c89ef521788 RSI: 0000000000000001 RDI: ffff8c89ef521780 
2026-08-04T01:13:37.505890+10:00 xev kernel: RBP: 0000000000000000 R08: 0000000000000000 R09: ffffd3cc8681fb20 
2026-08-04T01:13:37.505891+10:00 xev kernel: R10: ffff8c8a6fef3628 R11: 0000000000000003 R12: 0000000000000000 
2026-08-04T01:13:37.505892+10:00 xev kernel: R13: ffff8c6c07853828 R14: 0000000000000003 R15: 0000000000000000 
2026-08-04T01:13:37.505893+10:00 xev kernel: FS: 00007ffaf2fd5880(0000) GS:ffff8c89ef500000(0000) knlGS:0000000000000000 
2026-08-04T01:13:37.505895+10:00 xev kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 
2026-08-04T01:13:37.505896+10:00 xev kernel: CR2: 00007fb1718c8000 CR3: 000000074521a004 CR4: 00000000003706f0 
2026-08-04T01:13:37.505897+10:00 xev kernel: Call Trace: 
2026-08-04T01:13:37.505898+10:00 xev kernel:  
2026-08-04T01:13:37.505899+10:00 xev kernel: drm_crtc_accurate_vblank_count+0x41/0xc0 [drm] 
2026-08-04T01:13:37.505900+10:00 xev kernel: dm_pflip_high_irq+0x155/0x330 [amdgpu] 
2026-08-04T01:13:37.505901+10:00 xev kernel: amdgpu_dm_irq_handler+0x85/0x1f0 [amdgpu] 
2026-08-04T01:13:37.505902+10:00 xev kernel: amdgpu_irq_dispatch+0xd2/0x230 [amdgpu] 
2026-08-04T01:13:37.505903+10:00 xev kernel: amdgpu_ih_process+0x84/0x100 [amdgpu] 
2026-08-04T01:13:37.505904+10:00 xev kernel: amdgpu_irq_handler+0x23/0x60 [amdgpu] 
2026-08-04T01:13:37.505905+10:00 xev kernel: __handle_irq_event_percpu+0x4a/0x190
2026-08-04T01:13:37.505907+10:00 xev kernel: handle_irq_event+0x38/0x80 
2026-08-04T01:13:37.505908+10:00 xev kernel: handle_edge_irq+0x8b/0x230 
2026-08-04T01:13:37.505909+10:00 xev kernel: __common_interrupt+0x45/0xe0 
2026-08-04T01:13:37.505910+10:00 xev kernel: common_interrupt+0x42/0xa0 
2026-08-04T01:13:37.505911+10:00 xev kernel: asm_common_interrupt+0x26/0x40 
2026-08-04T01:13:37.505912+10:00 xev kernel: RIP: 0033:0x7ffaf3c5fd7b 
2026-08-04T01:13:37.505913+10:00 xev kernel: Code: 70 c7 00 66 0f 6e f8 c1 ef 02 66 0f 70 f7 e0 83 c7 01 66 0f ef ff 66 0f fa f2 0f 1f 44 00 00 f3 0f 7e 01 66 0f 6f ce 83 c6 01 &amp;lt;48&amp;gt; 83 e9 08 f2 0f 70 c0 1b 66 0f 6f e0 66 0f 6f e8 66 41 0f f9 c0 
2026-08-04T01:13:37.505915+10:00 xev kernel: RSP: 002b:00007fff86a5e0e0 EFLAGS: 00000202 
2026-08-04T01:13:37.505916+10:00 xev kernel: RAX: 0000000000008000 RBX: 0000562614a04050 RCX: 0000562614982ed8 
2026-08-04T01:13:37.505946+10:00 xev kernel: RDX: 0000000000007fe2 RSI: 0000000000000fad RDI: 0000000000002000 
2026-08-04T01:13:37.505948+10:00 xev kernel: RBP: 0000000000000000 R08: 000056261498ac40 R09: 0000000000008000 
2026-08-04T01:13:37.505949+10:00 xev kernel: R10: 0000000000000066 R11: 0000000000007fe1 R12: 0000000000007efa
2026-08-04T01:13:37.505950+10:00 xev kernel: R13: 0000000000008000 R14: 0000000000008000 R15: 000000000000ffe0 
2026-08-04T01:13:37.505951+10:00 xev kernel:  
2026-08-04T01:13:37.505953+10:00 xev kernel: ---[ end trace 0000000000000000 ]--- 
2026-08-04T01:55:40.844110+10:00 xev kernel: pcieport 0000:00:03.3: AER: Multiple Correctable error message received from 0000:00:03.3 
2026-08-04T01:55:40.844130+10:00 xev kernel: pcieport 0000:00:03.3: PCIe Bus Error: severity=Correctable, type=Data Link Layer, (Receiver ID) 
2026-08-04T01:55:40.844132+10:00 xev kernel: pcieport 0000:00:03.3: device [8086:6f0b] error status/mask=00000040/00002000 
2026-08-04T01:55:40.844134+10:00 xev kernel: pcieport 0000:00:03.3: [ 6] BadTLP&lt;/pre&gt;
&lt;pre&gt;2026-08-11T09:33:33.473855+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 147 0x00024802
2026-08-11T09:33:33.473871+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 150905 thread kscreenloc:cs0 pid 150912
2026-08-11T09:33:33.473871+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_ADDR 0x00000800
2026-08-11T09:33:33.473873+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_STATUS 0x0F048002
2026-08-11T09:33:33.473873+10:00 xev kernel: amdgpu 0000:02:00.0: VM fault (0x02, vmid 7, pasid 63) at page 2048, write from 'TC0' (0x54433000) (72)
2026-08-11T09:33:33.473874+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 147 0x00004802
2026-08-11T09:33:33.473874+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 150905 thread kscreenloc:cs0 pid 150912
2026-08-11T09:33:33.473875+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_ADDR 0x00000800
2026-08-11T09:33:33.473876+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_STATUS 0x0E048002
2026-08-11T09:33:33.473876+10:00 xev kernel: amdgpu 0000:02:00.0: VM fault (0x02, vmid 7, pasid 63) at page 2048, read from 'TC0' (0x54433000) (72)
2026-08-11T09:33:35.481863+10:00 xev kernel: amdgpu 0000:02:00.0: Dumping IP State
2026-08-11T09:33:35.481875+10:00 xev kernel: amdgpu 0000:02:00.0: Dumping IP State Completed
2026-08-11T09:33:35.481875+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] AMDGPU device coredump file has been created
2026-08-11T09:33:35.481876+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] Check your /sys/class/drm/card0/device/devcoredump/data
2026-08-11T09:33:35.481877+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 146 0x0110040c
2026-08-11T09:33:35.481877+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 150905 thread kscreenloc:cs0 pid 150912
2026-08-11T09:33:35.481878+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_ADDR 0x00000022
2026-08-11T09:33:35.481879+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_STATUS 0x0E00400C
2026-08-11T09:33:35.481879+10:00 xev kernel: amdgpu 0000:02:00.0: VM fault (0x0c, vmid 7, pasid 63) at page 34, read from 'TC3' (0x54433300) (4)
2026-08-11T09:33:35.489845+10:00 xev kernel: amdgpu 0000:02:00.0: ring gfx timeout, signaled seq=5123619, emitted seq=5123621
2026-08-11T09:33:35.489853+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 150905 thread kscreenloc:cs0 pid 150912
2026-08-11T09:33:35.489854+10:00 xev kernel: amdgpu 0000:02:00.0: GPU reset begin!. Source: 1
2026-08-11T09:33:35.493839+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] ERROR Failed to initialize parser -125!
2026-08-11T09:33:35.737848+10:00 xev kernel: amdgpu: cp is busy, skip halt cp
2026-08-11T09:33:35.897842+10:00 xev kernel: amdgpu: rlc is busy, skip halt rlc
2026-08-11T09:33:35.897852+10:00 xev kernel: amdgpu 0000:02:00.0: BACO reset
2026-08-11T09:33:36.485849+10:00 xev kernel: amdgpu 0000:02:00.0: GPU reset succeeded, trying to resume
2026-08-11T09:33:36.485859+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] PCIE GART of 256M enabled (table at 0x000000F402000000).
2026-08-11T09:33:36.485860+10:00 xev kernel: amdgpu 0000:02:00.0: VRAM is lost due to GPU reset!&lt;/pre&gt;
&lt;h2&gt;Errors on Battlemage&lt;/h2&gt;
&lt;pre&gt;Aug 11 17:01:47 ami kernel: ------------[ cut here ]------------
Aug 11 17:01:47 ami kernel: xe 0000:23:00.0: [drm] DMC 1 mmio[0]/0x5f074 incorrect (expected 0x96fc0, current 0x0)
Aug 11 17:01:47 ami kernel: WARNING: drivers/gpu/drm/i915/display/intel_dmc.c:696 at assert_dmc_loaded+0x275/0x430 [xe], CPU#0: kworker/0:3/215
Aug 11 17:01:47 ami kernel: Modules linked in: intel_rapl_msr intel_rapl_common intel_uncore_frequency intel_uncore_frequency_common xe(+) skx_edac snd_h&amp;gt;
Aug 11 17:01:47 ami kernel:  msr i2c_dev configfs efi_pstore efivarfs autofs4 btrfs libblake2b raid6_pq xor mpt3sas raid_class scsi_transport_sas megarai&amp;gt;
Aug 11 17:01:47 ami kernel: CPU: 0 UID: 0 PID: 215 Comm: kworker/0:3 Not tainted 7.1.7+deb14-amd64 #1 PREEMPT(lazy)  Debian 7.1.7-1 
Aug 11 17:01:47 ami kernel: Hardware name: HP HP Z4 G4 Workstation/81C5, BIOS P61 v03.00 04/15/2026
Aug 11 17:01:47 ami kernel: Workqueue: sync_wq local_pci_probe_callback
Aug 11 17:01:47 ami kernel: RIP: 0010:assert_dmc_loaded+0x291/0x430 [xe]
Aug 11 17:01:47 ami kernel: Code: 24 10 e8 f2 e5 a3 ce 48 8d 3d bb 85 0d 00 8b 54 24 0c 45 89 e9 45 89 e0 48 89 c6 52 8b 4c 24 2c 51 8b 4c 24 30 48 8b 54&amp;gt;
Aug 11 17:01:47 ami kernel: RSP: 0018:ffffd27ac0b87b80 EFLAGS: 00010282
Aug 11 17:01:47 ami kernel: RAX: ffffffffc1743dfd RBX: ffff8c5b80e54000 RCX: 0000000000000001
Aug 11 17:01:47 ami kernel: RDX: ffff8c5b81df5a10 RSI: ffffffffc1743dfd RDI: ffffffffc1605860
Aug 11 17:01:47 ami kernel: RBP: ffff8c5b86955000 R08: 0000000000000000 R09: 000000000005f074
Aug 11 17:01:47 ami kernel: R10: 0000000000000000 R11: 0000000000091050 R12: 0000000000000000
Aug 11 17:01:47 ami kernel: R13: 000000000005f074 R14: 0000000000000001 R15: 0000000000000000
Aug 11 17:01:47 ami kernel: FS:  0000000000000000(0000) GS:ffff8c673e172000(0000) knlGS:0000000000000000
Aug 11 17:01:47 ami kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Aug 11 17:01:47 ami kernel: CR2: 00007ffed1fdcd00 CR3: 0000000ae942a003 CR4: 00000000003706f0
Aug 11 17:01:47 ami kernel: Call Trace:
Aug 11 17:01:47 ami kernel:  
Aug 11 17:01:47 ami kernel:  intel_dmc_enable_pipe+0xe4/0x290 [xe]
Aug 11 17:01:47 ami kernel:  ? drm_crtc_vblank_reset+0x4d/0x120 [drm]
Aug 11 17:01:47 ami kernel:  intel_modeset_setup_hw_state+0xb50/0x1e10 [xe]
Aug 11 17:01:47 ami kernel:  ? intel_display_driver_probe_nogem+0x138/0x1a0 [xe]
Aug 11 17:01:47 ami kernel:  intel_display_driver_probe_nogem+0x138/0x1a0 [xe]
Aug 11 17:01:47 ami kernel:  xe_display_init_early+0xb2/0x140 [xe]
Aug 11 17:01:47 ami kernel:  xe_device_probe+0x3c8/0xb50 [xe]
Aug 11 17:01:47 ami kernel:  ? xe_pm_init_early+0x152/0x160 [xe]
Aug 11 17:01:47 ami kernel:  xe_pci_probe+0xc26/0x1150 [xe]
Aug 11 17:01:47 ami kernel:  local_pci_probe+0x3e/0x90
Aug 11 17:01:47 ami kernel:  local_pci_probe_callback+0x16/0x20
Aug 11 17:01:47 ami kernel:  process_one_work+0x19d/0x3a0
Aug 11 17:01:47 ami kernel:  worker_thread+0x1af/0x320
Aug 11 17:01:47 ami kernel:  ? __pfx_worker_thread+0x10/0x10
Aug 11 17:01:47 ami kernel:  kthread+0xe3/0x120
Aug 11 17:01:47 ami kernel:  ? __pfx_kthread+0x10/0x10
Aug 11 17:01:47 ami kernel:  ret_from_fork+0x2b2/0x340
Aug 11 17:01:47 ami kernel:  ? __pfx_kthread+0x10/0x10
Aug 11 17:01:47 ami kernel:  ret_from_fork_asm+0x1a/0x30
Aug 11 17:01:47 ami kernel:  
Aug 11 17:01:47 ami kernel: ---[ end trace 0000000000000000 ]---&lt;/pre&gt;
&lt;div class="yarpp yarpp-related yarpp-related-rss yarpp-template-list"&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2025/11/09/amd-video-driver-issues/" rel="bookmark" title="AMD Video Driver Issues"&gt;AMD Video Driver Issues&lt;/a&gt; &lt;small&gt;I have had some graphics hangs on my HP z640...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2008/10/22/kernel-issues-with-debian-xen-and-centos-kernels/" rel="bookmark" title="Kernel issues with Debian Xen and CentOS Kernels"&gt;Kernel issues with Debian Xen and CentOS Kernels&lt;/a&gt; &lt;small&gt;Last time I tried using a Debian 64bit Xen kernel...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2025/11/02/pcie-problems/" rel="bookmark" title="PCIe Problems"&gt;PCIe Problems&lt;/a&gt; &lt;small&gt;HP z840 Dead Slot I just had an issue with...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Sat, 15 Aug 2026 08:09:51 +0000</pubDate>

</item> 
<item>
	<title>Reproducible Builds (diffoscope): diffoscope 328 released</title>
	<guid>https://diffoscope.org/news/diffoscope-328-released/</guid>
	<link>https://diffoscope.org/news/diffoscope-328-released/</link>
     <description>  &lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class="language-plaintext highlighter-rouge"&gt;328&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class="language-plaintext highlighter-rouge"&gt;&lt;div class="highlight"&gt;&lt;pre class="highlight"&gt;&lt;code&gt;[ Chris Lamb ]
* Don't require python3-guestfs in the autopkgtests on 32-bit architectures.
  (Closes: #1144372)

[ Jochen Sprickerhof ]
* Use the XML comparators for SVG vector image files. (Closes: #1144242)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href="https://diffoscope.org"&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt; </description> 
	<pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>

</item> 
<item>
	<title>Gunnar Wolf: File recovery in process...</title>
	<guid>https://gwolf.org/2026/08/file-recovery-in-process.html</guid>
	<link>https://gwolf.org/2026/08/file-recovery-in-process.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/gwolf.png" width="69" height="83" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;Ohai,&lt;/p&gt;

&lt;p&gt;I have some pending, encrypted mails to answer. And some of my answers for
the next few days (particularly to what pertains to the &lt;a href="https://www.debian.org/vote/2026/vote_002"&gt;current
in-discussion vote on LLM usage in
Debian&lt;/a&gt;) will be unsigned, even
though I’d like otherwise.&lt;/p&gt;

&lt;p&gt;My desktop system at work is showing some data corruption, and I’m slowly
backing up my data. Fortunately, it seems I haven’t lost any data, but
still, given I’m letting &lt;code class="language-plaintext highlighter-rouge"&gt;rsync&lt;/code&gt; run until it starts spewing I/O errors,
then power down and let the machine cool a bit, and start again… it is a
potentially long process.&lt;/p&gt;

&lt;p&gt;And yes, this makes me somewhat angry. Why angry? Because I’m working on a
brand-new computer (well, have used it for slightly over six months),
custom-built to specs requested by my workplace. Specs that I don’t really
need, this machine is an utter luxury (i.e. an AMD Ryzen 9 9950X processor
with 16 real cores / 32 threads; 128GB RAM in this day and age of RAM
shortage, quite recent 32GB GPU, and lots of shiny lights seen in its huge
fishbowl cabinet, liquid-based cooling…). The specs came not from me, but
from people who had no idea what we would use them for. And yes, I expect
the little fortune spent on this machine to be good for my use for probably
a decade, as my previous computer was, but the amount paid
was… exorbitant.&lt;/p&gt;

&lt;p&gt;But still, what I learned recently is that the 4TB nVME SSD it has (a
T-Force TM8FFJX34T) is… a very cheap brand, bought because it was close
to half the price of other offerings similar in capacity. According to
&lt;code class="language-plaintext highlighter-rouge"&gt;smartctl&lt;/code&gt;’s output, th SSD operates with a &lt;code class="language-plaintext highlighter-rouge"&gt;Warning Comp. Temp. Threshold:
90 Celsius&lt;/code&gt; and &lt;code class="language-plaintext highlighter-rouge"&gt;Critical Comp. Temp. Threshold: 110 Celsius&lt;/code&gt;, which sounds
sensible, even too high for my standards (my last two laptops have been
fanless… yes, an ARM system is very different from a high-end gaming
machine). I’m right now typing from my laptop, which shows 78°C and 82°C
for warning/critical thresholds.&lt;/p&gt;

&lt;p&gt;And as expected, under heavy sustained reads (backing up to my NFS server),
the desktop’s &lt;code class="language-plaintext highlighter-rouge"&gt;smartctl&lt;/code&gt; shows &lt;code class="language-plaintext highlighter-rouge"&gt;Temperature: 83 Celsius&lt;/code&gt; and, further down,
&lt;code class="language-plaintext highlighter-rouge"&gt;Temperature Sensor 1: 107 Celsius&lt;/code&gt; and &lt;code class="language-plaintext highlighter-rouge"&gt;Temperature Sensor 2: 82 Celsius&lt;/code&gt;
(don’t know which of these would make the threshold jump). The SSD has
sustained &lt;code class="language-plaintext highlighter-rouge"&gt;Media and Data Integrity Errors: 20&lt;/code&gt; and &lt;code class="language-plaintext highlighter-rouge"&gt;Warning
Comp. Temperature Time: 21&lt;/code&gt; (although &lt;code class="language-plaintext highlighter-rouge"&gt;Critical Comp. Temperature Time: 0&lt;/code&gt;). At least one of my colleagues have shrugged and installed a SATA SSD,
laying the huge nVME basically to waste.&lt;/p&gt;

&lt;p&gt;Anyway… I also learned I am not the first, but the fourth person to
notice this kind of issues in this system (out of ten similar purchased
systems AIUI). It is completely unacceptable, and I’ll be pushing our
Institute’s authorities to demand the provider to provide either good
component quality for this very expensive system that has many luxury
items, or to fix the system’s build in a way the nVME does not heat as much
as it currently does.&lt;/p&gt;

&lt;p&gt;Anyway, &lt;em&gt;sigh&lt;/em&gt;, I only wanted to say, please excuse me for not using my
cryptographic keys for a couple of days &#128579;&lt;/p&gt;

&lt;p&gt;PS- I’m also currently not connected to IRC and Jabber (and some similar
technologies), as my bouncer runs from my usual workstation.&lt;/p&gt; </description> 
	<pubDate>Thu, 13 Aug 2026 17:47:20 +0000</pubDate>

</item> 
<item>
	<title>Jonathan Dowland: DIY skate punch-out</title>
	<guid>https://jmtd.net/log/punch-out/</guid>
	<link>https://jmtd.net/log/punch-out/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/jmtd.png" width="65" height="85" alt="" align="right" style="float: right;"&gt;  &lt;div class="image"&gt;
&lt;a href="https://jmtd.net/log/punch-out/punch.jpg"&gt;&lt;img alt="The punch set-up" class="img" height="281" src="https://jmtd.net/log/punch-out/500x-punch.jpg" width="500" /&gt;&lt;/a&gt;

&lt;/div&gt;




&lt;div class="image"&gt;
&lt;a href="https://jmtd.net/log/punch-out/marked.jpg"&gt;&lt;img alt="the punched boot" class="img" height="281" src="https://jmtd.net/log/punch-out/500x-marked.jpg" width="500" /&gt;&lt;/a&gt;

&lt;/div&gt;


&lt;p&gt;Since I wrote about my &lt;a href="https://jmtd.net/log/fly30/"&gt;fly30&lt;/a&gt; ice skates, I'd continued to battle pain
around the navicular bone in my feet. The action that seems to have finally
fixed it was to perform a "punch out": a very localized remoulding of the
area of the boot that presses against the sore area.&lt;/p&gt;

&lt;p&gt;I basically followed the process from &lt;a href="https://www.youtube.com/watch?v=5RntLK_-lBU"&gt;this helpful YouTube
video&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;I narrowed down the exact spot by borrowing some lipstick and transferring it
from my navicular bone to the boot lining, then making that more permanent with
a sharpie.&lt;/p&gt;

&lt;p&gt;My punch was a spare part from a radiator valve which I packed with US cents
(I couldn't fit any UK coins in). For the receiving-end, I tried another part
from the radiator valve but I think it wasn't sufficiently larger than the punch
to work well, so I swapped that out for a spoon.&lt;/p&gt;

&lt;div class="image"&gt;
&lt;a href="https://jmtd.net/log/punch-out/take2.jpg"&gt;&lt;img alt="take 2" class="img" height="281" src="https://jmtd.net/log/punch-out/500x-take2.jpg" width="500" /&gt;&lt;/a&gt;

&lt;p&gt;take 2&lt;/p&gt;

&lt;/div&gt;


&lt;p&gt;I didn't have a temperature sensor I could use and I used a heat gun rather than
a hairdryer, so I YOLO'd it a little. Some of the wrap on one of my boots is now
distorted from where I didn't move the heat gun enough. It only took a minute or
two to get the boot hot enough to be flexible. I set a 15 minute timer once the
clamp was in place.&lt;/p&gt;

&lt;p&gt;I've only skated one session since I did this but the pain seems to have gone!
It's remarkably freeing to be skating without constantly trying to manage pain.
Now I can focus on technique.&lt;/p&gt; </description> 
	<pubDate>Thu, 13 Aug 2026 08:28:08 +0000</pubDate>

</item> 
<item>
	<title>Steinar H. Gunderson: The PSX GPU is wild</title>
	<guid>http://blog.sesse.net/blog/tech/2026-08-12-16-26_the_psx_gpu_is_wild.html</guid>
	<link>http://blog.sesse.net/blog/tech/2026-08-12-16-26_the_psx_gpu_is_wild.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/sesse.png" width="74" height="85" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;Inspired by some recent reverse-engineering, here are some things I
find wild by the original PlayStation GPU:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;VRAM is a flat 1024x512 16-bit image (555 + 1 bit alpha).
You want more than just a framebuffer?  Figure out yourself what goes where.&lt;/li&gt;
&lt;li&gt;Yes, that means you'll need to allocate two framebuffers
and double-buffer everything yourself.&lt;/li&gt;
&lt;li&gt;Quads are common. No “triangles only” business here.&lt;/li&gt;
&lt;li&gt;Vertex coordinates are screen-space x/y integers. No floats or fixed-point. (I'm ignoring the GTE here,
plus higher-level libraries.)&lt;/li&gt;
&lt;li&gt;Wait, where's z? There's no z. So there's no perspective correction.
(This one is pretty famous)&lt;/li&gt;
&lt;li&gt;OK, so how do you give in subpixel coordinates? You don't. There's no AA after all.&lt;/li&gt;
&lt;li&gt;Texture coordinates (u/v) are uint8_t. There's no texture filtering either;
everything is nearest-neighbor only.&lt;/li&gt;
&lt;li&gt;OK, so that means you can't have textures larger than 256x256
(pretty common in that era), but how do you give in the handle to the
texture?&lt;/li&gt;
&lt;li&gt;You don't, it points directly to the 1024x512 VRAM. You manage yourself
what goes where, remember?&lt;/li&gt;
&lt;li&gt;So can you an only have textures in the top-left 256x256? Hah, no,
we give you a bit-packed “texture page” system that offsets
all your u/v coordinates.&lt;/li&gt;
&lt;li&gt;Most textures are paletted to save VRAM (so instead of 555+1, your
pixels now mean something like “two palette indexes”). Where does the palette live?&lt;/li&gt;
&lt;li&gt;Well, duh, that's a 256x1 (or 16x1, or whatever) area of VRAM too.
The GPU does not care, you can use another texture's pixels as a palette if
you feel like it.&lt;/li&gt;
&lt;li&gt;OK, so you said there's no z, how do you do z-buffering? You have a
z-buffer, right… right?&lt;/li&gt;
&lt;li&gt;Yeah, sure, we're not cavemen. We have an “ordering table” that is
your Z-buffer, drawn back-to-front. If you want 256 levels of Z,
you just allocate an array of 256 linked-list pointers, and then
you put your polygon into the one corresponding to the correct right Z. &lt;/li&gt;
&lt;li&gt;But, eh, what if my polygon is not completely flat in Z-space?&lt;/li&gt;
&lt;li&gt;Hello?&lt;/li&gt;
&lt;li&gt;Hello…?&lt;/li&gt;
&lt;/ul&gt; </description> 
	<pubDate>Wed, 12 Aug 2026 15:26:00 +0000</pubDate>

</item> 
<item>
	<title>Reproducible Builds: Reproducible Builds summit 2026 to take place in Gothenburg</title>
	<guid>https://reproducible-builds.org/news/2026/08/12/reproducible-builds-summit-in-gothenburg/</guid>
	<link>https://reproducible-builds.org/news/2026/08/12/reproducible-builds-summit-in-gothenburg/</link>
     <description>  &lt;p class="alert alert-info"&gt;This event is happening soon — see below for registration instructions!&lt;/p&gt;

&lt;p class="lead"&gt;We are extremely pleased to announce the upcoming Reproducible Builds summit, which will take place from &lt;strong&gt;September 22nd—24th 2026&lt;/strong&gt; in the city of Gothenburg, Sweden.&lt;/p&gt;

&lt;p&gt;This year, we are thrilled to host the tenth edition of this exciting event, following the success of previous summits in various iconic locations around the world, including &lt;a href="https://reproducible-builds.org/events/vienna2025/"&gt;Vienna&lt;/a&gt; (2025), &lt;a href="https://reproducible-builds.org/events/hamburg2024/"&gt;Hamburg&lt;/a&gt; (2023—2024), &lt;a href="https://reproducible-builds.org/events/venice2022/"&gt;Venice&lt;/a&gt; (2022), &lt;a href="https://reproducible-builds.org/events/Marrakesh2019/"&gt;Marrakesh&lt;/a&gt; (2019), &lt;a href="https://reproducible-builds.org/events/paris2018/"&gt;Paris&lt;/a&gt; (2018), &lt;a href="https://reproducible-builds.org/events/berlin2017/"&gt;Berlin&lt;/a&gt; (2017), &lt;a href="https://reproducible-builds.org/events/berlin2016/"&gt;Berlin&lt;/a&gt; (2016) and &lt;a href="https://reproducible-builds.org/events/athens2015/"&gt;Athens&lt;/a&gt; (2015).&lt;/p&gt;

&lt;p&gt;If you’re excited about joining us this year, please make sure to read &lt;a href="https://reproducible-builds.org/events/gothenburg2026/"&gt;the event page which has more details about the event and location&lt;/a&gt;. As in previous years, we will be sending invitations to all those who attended our previous summit events or expressed interest to do so. However, even if you do not receive a personal invitation, please do &lt;a href="mailto:2026-summit-team@lists.reproducible-builds.org"&gt;email the organizers&lt;/a&gt; and we will find a way to accommodate you.&lt;/p&gt;

&lt;h3 id="about-the-event"&gt;About the event&lt;/h3&gt;

&lt;p&gt;The Reproducible Builds Summit is a unique gathering that brings together attendees from diverse projects, united by a shared vision of advancing the Reproducible Builds effort. During this enriching event, participants will have the opportunity to engage in discussions, establish connections and exchange ideas to drive progress in this vital field. Our aim is to create an inclusive space that fosters collaboration, innovation and problem-solving.&lt;/p&gt;



&lt;h3 id="schedule"&gt;Schedule&lt;/h3&gt;

&lt;p&gt;Although the exact content of the meeting will be shaped by the participants, the main goals will include:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Update &amp;amp; exchange about the status of reproducible builds in various projects.&lt;/li&gt;
  &lt;li&gt;Improve collaboration both between and inside projects.&lt;/li&gt;
  &lt;li&gt;Expand the scope and reach of reproducible builds to more projects.&lt;/li&gt;
  &lt;li&gt;Work together and hack on solutions.&lt;/li&gt;
  &lt;li&gt;Establish space for more strategic and long-term thinking than is possible in virtual channels.&lt;/li&gt;
  &lt;li&gt;Brainstorm designs on tools enabling users to get the most benefits from reproducible builds.&lt;/li&gt;
  &lt;li&gt;Discuss how reproducible builds will be usable and meaningful to users and developers alike.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Logs and minutes will be published after the meeting.&lt;/p&gt;

&lt;h3 id="location--date"&gt;Location &amp;amp; date&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href="https://clarion-hotel-draken-goteborg.hotelcheckins.com/"&gt;Clarion Hotel Draken&lt;/a&gt;, Olof Palmes Plats 2, 413 30 Göteborg, Sweden. (&lt;a href="https://www.openstreetmap.org/way/1243458002"&gt;OpenStreetMap&lt;/a&gt;, &lt;a href="https://maps.app.goo.gl/BBDUEojYcR95jAoc8"&gt;Google Maps&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;September 22nd to September 24th 2026&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id="registration-instructions"&gt;Registration instructions&lt;/h3&gt;

&lt;p&gt;Please &lt;a href="https://reproducible-builds.org/events/gothenburg2026/"&gt;reach out&lt;/a&gt; if you’d like to participate in hopefully interesting, inspiring and intense technical sessions about reproducible builds and beyond!&lt;/p&gt;

&lt;p&gt;We look forward to what we anticipate to be yet another extraordinary event!&lt;/p&gt; </description> 
	<pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>

</item> 
<item>
	<title>Colin Watson: Free software activity in July 2026</title>
	<guid>tag:www.chiark.greenend.org.uk,2026-08-11:/~cjwatson/blog/activity-2026-07.html</guid>
	<link>https://www.chiark.greenend.org.uk/~cjwatson/blog/activity-2026-07.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/cjwatson.png" width="70" height="82" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;About 95% of my Debian contributions this month were &lt;a href="https://www.freexian.com/about/debian-contributions/"&gt;sponsored&lt;/a&gt; by Freexian.&lt;/p&gt;
&lt;p&gt;You can also support my work directly via &lt;a href="https://liberapay.com/cjwatson"&gt;Liberapay&lt;/a&gt; or &lt;a href="https://github.com/sponsors/cjwatson"&gt;GitHub Sponsors&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;OpenSSH&lt;/h2&gt;
&lt;p&gt;Now that Ubuntu 26.04 &lt;span class="caps"&gt;LTS&lt;/span&gt; has been released, I’ve been getting back to the &lt;a href="https://lists.debian.org/debian-devel/2024/04/msg00044.html"&gt;&lt;span class="caps"&gt;GSS&lt;/span&gt;-&lt;span class="caps"&gt;API&lt;/span&gt; key exchange package split&lt;/a&gt; in our OpenSSH packaging.  Once I started testing my draft &lt;code&gt;openssh-gssapi&lt;/code&gt; source package, I realized that I needed to make some changes in the main &lt;code&gt;openssh&lt;/code&gt; source package first in order to support it.  The dependency from &lt;code&gt;openssh-server&lt;/code&gt; to &lt;code&gt;openssh-client&lt;/code&gt; was awkward, as was the (related) fact that &lt;code&gt;openssh-client&lt;/code&gt; contained shared documentation for other OpenSSH binary packages.  After some thought, I created a new &lt;code&gt;openssh-common&lt;/code&gt; binary package, moved shared documentation and the &lt;code&gt;ssh-keygen&lt;/code&gt; program to that, and dropped dependencies on &lt;code&gt;openssh-client&lt;/code&gt; which were no longer necessary (fixing &lt;a href="https://bugs.debian.org/699473"&gt;#699473&lt;/a&gt; and &lt;a href="https://bugs.debian.org/1070098"&gt;#1070098&lt;/a&gt; in the process).&lt;/p&gt;
&lt;p&gt;This caused a couple of regressions (&lt;a href="https://bugs.debian.org/1141420"&gt;#1141420&lt;/a&gt; and &lt;a href="https://bugs.debian.org/1141550"&gt;#1141550&lt;/a&gt;) that I had to fix, and more subtly it also caused a number of autopkgtest regressions in other packages because &lt;code&gt;openssh-client&lt;/code&gt; is no longer in base images as a result of a dependency from &lt;code&gt;openssh-server&lt;/code&gt;.  I believe I have fixes for all of these either pending review or merged (one of which I did in August rather than July):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://salsa.debian.org/debian/curl/-/merge_requests/65"&gt;curl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://salsa.debian.org/reproducible-builds/diffoscope/-/merge_requests/170"&gt;diffoscope&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://salsa.debian.org/debian/glome/-/merge_requests/1"&gt;glome&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://salsa.debian.org/go-team/packages/golang-github-appleboy-easyssh-proxy/-/merge_requests/4"&gt;golang-github-appleboy-easyssh-proxy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://salsa.debian.org/debian/parsyncfp2/-/merge_requests/1"&gt;parsyncfp2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://salsa.debian.org/debian/rsync/-/merge_requests/41"&gt;rsync&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I upgraded from 10.3p1 to 10.4p1, and in the process &lt;a href="https://bugzilla.mindrot.org/show_bug.cgi?id=3974"&gt;contributed a &lt;span class="caps"&gt;GSS&lt;/span&gt;-&lt;span class="caps"&gt;API&lt;/span&gt; option handling fix upstream&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I made openssh-ssh1’s package description &lt;a href="https://bugs.debian.org/1123609"&gt;more accurately describe the package&lt;/a&gt;, thanks to suggestions from Matthias Lang.&lt;/p&gt;
&lt;h2&gt;Installer team&lt;/h2&gt;
&lt;p&gt;With support from a Freexian customer, I reviewed, tested, edited, and merged a patch to add &lt;a href="https://bugs.debian.org/433568"&gt;&lt;span class="caps"&gt;VLAN&lt;/span&gt; support&lt;/a&gt;.  I described the details of what I did in a &lt;a href="https://bugs.debian.org/433568#243"&gt;comment&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This has been vaguely on my to-do list since, er, about 2014, so it was very satisfying to get it sorted out.&lt;/p&gt;
&lt;h2&gt;Python packaging&lt;/h2&gt;
&lt;p&gt;New upstream versions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;cryptodatahub (fixing a &lt;a href="https://bugs.debian.org/1140974"&gt;build failure&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;dep-logic&lt;/li&gt;
&lt;li&gt;django-q&lt;/li&gt;
&lt;li&gt;flufl.lock&lt;/li&gt;
&lt;li&gt;more-itertools&lt;/li&gt;
&lt;li&gt;multipart&lt;/li&gt;
&lt;li&gt;pyasn1 (fixing &lt;a href="https://bugs.debian.org/1142388"&gt;&lt;span class="caps"&gt;CVE&lt;/span&gt;-2026-59884, &lt;span class="caps"&gt;CVE&lt;/span&gt;-2026-59885, and &lt;span class="caps"&gt;CVE&lt;/span&gt;-2026-59886&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;pytest-rerunfailures&lt;/li&gt;
&lt;li&gt;python-auditwheel&lt;/li&gt;
&lt;li&gt;python-build&lt;/li&gt;
&lt;li&gt;python-certifi&lt;/li&gt;
&lt;li&gt;python-datamodel-code-generator (fixing a &lt;a href="https://bugs.debian.org/1141004"&gt;build failure&lt;/a&gt;, and an &lt;a href="https://github.com/koxudaxi/datamodel-code-generator/issues/3578"&gt;incompatibility with pydantic 2.13&lt;/a&gt; that I reported upstream)&lt;/li&gt;
&lt;li&gt;python-django-parler&lt;/li&gt;
&lt;li&gt;python-httplib2&lt;/li&gt;
&lt;li&gt;python-pgbouncer&lt;/li&gt;
&lt;li&gt;python-time-machine&lt;/li&gt;
&lt;li&gt;python-treq&lt;/li&gt;
&lt;li&gt;python-typing-extensions&lt;/li&gt;
&lt;li&gt;python-wheezy.template&lt;/li&gt;
&lt;li&gt;storm&lt;/li&gt;
&lt;li&gt;ubelt&lt;/li&gt;
&lt;li&gt;webpy&lt;/li&gt;
&lt;li&gt;zope.testing&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Other build/test failures:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1131792"&gt;django-q: autopkgtest failure with Python 3.14&lt;/a&gt; (&lt;a href="https://github.com/django-q2/django-q2/issues/334"&gt;reported upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1140980"&gt;httpx: &lt;span class="caps"&gt;FTBFS&lt;/span&gt;: E assert [(‘uvicorn.ac…1.1 200 &lt;span class="caps"&gt;OK&lt;/span&gt;”’)] == [(‘httpx’, 20…1.1 200 &lt;span class="caps"&gt;OK&lt;/span&gt;”’)]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1141778"&gt;libntruprime: autopkgtest failures with Python 3.14&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1141791"&gt;pygments: Handle None object before &lt;span class="caps"&gt;HTML&lt;/span&gt; escaping&lt;/a&gt; (fixed build failures in cmd2, gunicorn, python-inline-snapshot, and python-openapi-core)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1142205"&gt;python-authlib: some of tests/flask/test_oauth2/rfc9068/ failed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1140873"&gt;python-click: autopkgtest regression with pytest 9.1&lt;/a&gt; (&lt;a href="https://github.com/pallets/click/pull/3656"&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1141010"&gt;python-httplib2: &lt;span class="caps"&gt;FTBFS&lt;/span&gt;: &lt;span class="caps"&gt;ERROR&lt;/span&gt; tests/test_proxy.py - Failed: ‘forked’ not found in &lt;code&gt;markers&lt;/code&gt; configuration option&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1143139"&gt;python-maturin: Please upgrade goblin dependency to 0.10&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1140692"&gt;python-memray: &lt;span class="caps"&gt;FTBFS&lt;/span&gt; on armhf (segfault)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1141210"&gt;python-mne: &lt;span class="caps"&gt;FTBFS&lt;/span&gt;: E pytest.PytestRemovedIn10Warning: Passing a non-Collection iterable to parametrize is deprecated&lt;/a&gt; (actually fixed in scikit-learn; &lt;a href="https://github.com/scikit-learn/scikit-learn/pull/34448"&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1142373"&gt;python-softlayer: autopkgtest fails with python3-click 8.3.3&lt;/a&gt; (&lt;a href="https://github.com/softlayer/softlayer-python/pull/2262"&gt;contributed upstream&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1142214"&gt;python-urllib3: &lt;span class="caps"&gt;FAILED&lt;/span&gt; test/contrib/test_pyopenssl.py&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I fixed some other bugs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1044278"&gt;django-pipeline: Fails to build source after successful build&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1078037"&gt;more-itertools: Please mark python3-more-itertools with M-A: foreign&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I adopted &lt;a href="https://bugs.debian.org/980407"&gt;transaction&lt;/a&gt; for the Python team.&lt;/p&gt;
&lt;p&gt;I attended the &lt;a href="https://debconf26.debconf.org/talks/32-debian-python-bof/"&gt;Python BoF&lt;/a&gt; at DebConf remotely, although a badly-timed fibre outage in the village I live in really didn’t help.&lt;/p&gt;
&lt;h2&gt;Code reviews&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1142354"&gt;openssh: sshd-session built without crypt(), breaking UsePAM=no password auth&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1142938"&gt;openssh: Slovak debconf templates translation&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1045463"&gt;python-treq: Fails to build source after successful build&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1129141"&gt;python-better-exceptions: &lt;span class="caps"&gt;FTBFS&lt;/span&gt;: failing tests&lt;/a&gt; (sponsored upload for Seyed Mohamad Amin Modaresi)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bugs.debian.org/1141577"&gt;yubihsm-connector: patch to make the build reproducible&lt;/a&gt; (merged and uploaded)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Other bits and pieces&lt;/h2&gt;
&lt;p&gt;Dan Poltawski pointed out in a &lt;a href="https://fedi.talktodan.com/@dan/116982771943815387"&gt;Fediverse post&lt;/a&gt; that the project history didn’t list Sruthi as the current &lt;span class="caps"&gt;DPL&lt;/span&gt;.  I &lt;a href="https://salsa.debian.org/publicity-team/debian-history/-/merge_requests/30"&gt;fixed that&lt;/a&gt;, although it doesn’t look as though the fix is in the published version yet.&lt;/p&gt;
&lt;p&gt;I upgraded yubihsm-shell to 2.8.0.&lt;/p&gt; </description> 
	<pubDate>Tue, 11 Aug 2026 10:42:43 +0000</pubDate>

</item> 
<item>
	<title>Freexian Collaborators: Debian Contributions: DebConf 26 organization, d-i VLAN support and more! (by Anupa Ann Joseph)</title>
	<guid>https://www.freexian.com/blog/debian-contributions-07-2026/</guid>
	<link>https://www.freexian.com/blog/debian-contributions-07-2026/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/freexian.png" width="215" height="101" alt="" align="right" style="float: right;"&gt;  &lt;h1 id="debian-contributions-2026-07"&gt;Debian Contributions: 2026-07&lt;/h1&gt;
&lt;p&gt;&lt;a href="https://www.freexian.com/about/debian-contributions/"&gt;Contributing to Debian&lt;/a&gt;
is part of &lt;a href="https://www.freexian.com/about/"&gt;Freexian’s mission&lt;/a&gt;. This article
covers the latest achievements of Freexian and their collaborators. All of this
is made possible by organizations subscribing to our
&lt;a href="https://www.freexian.com/lts/"&gt;Long Term Support contracts&lt;/a&gt; and
&lt;a href="https://www.freexian.com/services/"&gt;consulting services&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="debconf-26-organization-by-lucas-kanashiro-santiago-ruano-rincón-stefano-rivera-and-antonio-terceiro"&gt;DebConf 26 organization, by Lucas Kanashiro, Santiago Ruano Rincón, Stefano Rivera and Antonio Terceiro&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://debconf26.debconf.org/"&gt;27th Annual Debian Conference&lt;/a&gt; was held in
Santa Fe, Argentina, and several Freexian fellows were quite busy by being
involved in the organization team.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Santiago continued helping with duties related to the local team, e.g.
preparing or proof-reading some announcements, reviewing the proposed food and
the menus for the different diet required.&lt;/li&gt;
&lt;li&gt;During the conference, Kanashiro and Santiago also carried over tasks related
to the content of the conference, including updating the schedule as it became
necessary during the event.&lt;/li&gt;
&lt;li&gt;Stefano worked within the core video team, setting up equipment in talk rooms
and coordinating the live video streaming. Stefano also supported the front desk
and local organisers as a website developer and conference book-keeper.&lt;/li&gt;
&lt;li&gt;Antonio kept working on website maintenance, specially in support of the
content team. During DebConf he also ran a hands-on workshop to help interested
contributors get started with developing the DebConf websites.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="d-i-vlan-support-by-colin-watson"&gt;d-i VLAN support, by Colin Watson&lt;/h2&gt;
&lt;p&gt;In environments that use &lt;a href="https://en.wikipedia.org/wiki/IEEE_802.1Q"&gt;IEEE 802.1Q VLANs&lt;/a&gt;,
some hosts (such as routers attached to “trunk” ports) may need to apply VLAN
tags themselves rather than relying on switches to do so. There has been a
&lt;a href="https://bugs.debian.org/433568"&gt;long-running request&lt;/a&gt; to add support for these
to the Debian installer with a proposed patch set put together by several people
over the years, and a Freexian customer asked us to help get this over the line.
Colin reviewed the latest version of the patch set, applied a number of
corrections, added Netplan support, spent some time testing a variety of
possible paths through the installer, and landed this. There’s also now
&lt;a href="https://salsa.debian.org/installer-team/installation-guide/-/merge_requests/46"&gt;documentation&lt;/a&gt;
for this in the next version of the installation guide.&lt;/p&gt;
&lt;h2 id="miscellaneous-contributions"&gt;Miscellaneous contributions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Carles wrote documentation for installing
&lt;a href="https://wiki.debian.org/Mailman3"&gt;Mailman3 and migrating from Mailman2&lt;/a&gt;. Added
it into Mailman3 &lt;a href="https://docs.mailman3.org/en/latest/install/distro.html#installing-on-debian"&gt;upstream documentation&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Carles, using &lt;a href="https://salsa.debian.org/carlespina/po-debconf-manager"&gt;po-debconf-manager&lt;/a&gt;:
reviewed 2 packages, submitted 2 packages&lt;/li&gt;
&lt;li&gt;Carles organized Catalan translation update. Created a Debian Wiki
&lt;a href="https://wiki.debian.org/ca/L10n/Catalan/TranslationWebWml"&gt;page&lt;/a&gt; to have an
overview of the work / coordination during next months.
&lt;a href="https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1157"&gt;Reviewed and submitted&lt;/a&gt; some pages.&lt;/li&gt;
&lt;li&gt;Carles improved the documentation for building the debian.org Web in
&lt;a href="https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1154"&gt;MR 1154&lt;/a&gt;
and &lt;a href="https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/1157"&gt;MR 1557&lt;/a&gt;.
Fixed &lt;a href="https://salsa.debian.org/debian/debian-reference/-/merge_requests/25"&gt;debian-reference&lt;/a&gt;
documentation. Added sections on Mutt Wiki page
(&lt;a href="https://wiki.debian.org/Mutt#Making_mailto:_protocol_launch_a_terminal_with_Mutt"&gt;handling of mailto&lt;/a&gt;,
&lt;a href="https://wiki.debian.org/Mutt#Viewing_HTML_message_parts_in_a_web_browser"&gt;viewing HTML parts web browser&lt;/a&gt;),
update and improve &lt;a href="https://wiki.debian.org/Add%20Bash%20Completion"&gt;bash-completion Wiki page&lt;/a&gt;.
Added a &lt;a href="https://wiki.debian.org/SignalDesktop#Not_sending.2Freceiving_messages_after_screen_lock"&gt;troubleshooting&lt;/a&gt;
section in Signal Wiki.&lt;/li&gt;
&lt;li&gt;Thorsten did another upload of hplip to fix RC bugs. He also spent some time
taking care of older bugs. Most of the time such bugs had been fixed in a
previous upload but haven’t been closed in the BTS. He also uploaded a new
upstream version of foomatic-db. Last but not least, he gave some user support
with the package epson-inkjet-printer-escpr. There seems to be a new software
available for Epson printers. Unfortunately the license is not compatible with
DFSG and so this software will never make it into Debian.&lt;/li&gt;
&lt;li&gt;During DebCamp 26, the Golang team had a
&lt;a href="https://wiki.debian.org/DebConf/26/Sprints/DebianGoTeam/"&gt;dedicated Sprint&lt;/a&gt; to
transition the Golang toolchain (namely on dh-golang) to make builds aware of
the module defined upstream with the aim of solving important issues. To help
in these efforts, Santiago &lt;a href="https://salsa.debian.org/salsa-ci-team/pipeline/-/merge_requests/753"&gt;made changes&lt;/a&gt;
in the Salsa CI pipeline and
&lt;a href="https://wiki.debian.org/DebConf/26/Sprints/DebianGoTeam/GoModBuilds#Testing_packages_with_Salsa_CI"&gt;documented on how to use it&lt;/a&gt;
to check if a package requires adjustments after the toolchain update.&lt;/li&gt;
&lt;li&gt;Santiago continued co-mentoring Aryan Karamtoth on the Linux livepatching
project, specifically providing feedback about the implementation of
&lt;a href="https://salsa.debian.org/spaciouskarter78/dlp-tools"&gt;dlp-tools&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Stefano reviewed and merged a migration of Debian reimbursements from
wkhtmltopdf to weasyprint, unblocking an upgrade to Debian trixie.&lt;/li&gt;
&lt;li&gt;Stefano’s cPython upstream merge request
&lt;a href="https://github.com/python/cpython/pull/152461"&gt;adding multiarch tags to stable ABI extensions&lt;/a&gt;
was finally merged.&lt;/li&gt;
&lt;li&gt;Stefano iterated on his upstream cPython
&lt;a href="https://github.com/python/cpython/pull/152831"&gt;merge request to add CI coverage&lt;/a&gt;
for Debian’s multi-arch expectations.&lt;/li&gt;
&lt;li&gt;Stefano uploaded Python 3.15.0 beta 4 to Debian experimental.&lt;/li&gt;
&lt;li&gt;Stefano uploaded Python 3.13 to trixie, fixing
&lt;a href="https://bugs.debian.org/1141977"&gt;a regression in a previous trixie point update&lt;/a&gt; he made.&lt;/li&gt;
&lt;li&gt;Helmut continued to report undeclared file conflicts.&lt;/li&gt;
&lt;li&gt;Helmut sent patches for three cross build failures.&lt;/li&gt;
&lt;li&gt;Helmut proposed a MR to &lt;a href="https://salsa.debian.org/debian/piuparts/-/merge_requests/81"&gt;port piuparts to pathlib&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Antonio has done quite some work on Debian CI, including rebuilding the
Debian CI armhf/armel worker VMs, and releasing
&lt;a href="https://tracker.debian.org/news/1772488/accepted-debci-42-source-into-unstable/"&gt;debci 4.2&lt;/a&gt;,
implementing a backup scheme, and several improvements to the codebase such as
improving the incus-lxc backend in preparation for switching to the upcoming
switch to using it by default as announced in the latest
&lt;a href="https://lists.debian.org/debian-devel-announce/2026/07/msg00003.html"&gt;bits from the ci.debian.net operators&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Emilio helped with transitions, particularly with Python 3.14 as default and
Perl 5.42. During the Perl transition, an issue was identified with how britney
schedules autopkgtests for binNMUs, and that testing was reverted for the time being.&lt;/li&gt;
&lt;li&gt;Colin restructured openssh-* binary packages to better support the upcoming
GSS-API package split.  This caused several autopkgtest regressions in other
packages because openssh-server no longer depends on openssh-client, all of
which have fixes either pending review or merged now.&lt;/li&gt;
&lt;li&gt;Lucas started a discussion around the creation of a Debian packaging video
course for newcomers in the context of the Outreach team.&lt;/li&gt;
&lt;li&gt;Lucas reviewed some contributions to ruby3.4 and provided feedback.&lt;/li&gt;
&lt;li&gt;Anupa worked with Jean-Pierre Giraud on the point release announcements for
Debian 13.6 and Debian 12.15.&lt;/li&gt;
&lt;li&gt;Anupa joined Jean-Pierre Giraud to prepare the Micronews for DebConf 26 press
coverage.&lt;/li&gt;
&lt;/ul&gt; </description> 
	<pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>

</item> 
<item>
	<title>Bits from Debian: DebConf26 Local Team says goodbye</title>
	<guid>tag:bits.debian.org,2026-08-10:/2026/08/debconf26-words-from-localteam.html</guid>
	<link>https://bits.debian.org/2026/08/debconf26-words-from-localteam.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/dwn.png" width="77" height="85" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;On Saturday 25 July 2026, the annual &lt;a href="https://debconf26.debconf.org/"&gt;Debian Developers and Contributors
Conference&lt;/a&gt; came to a close.  The Debian Press
team would now like to share this personal and beautiful message from the Santa Fe
Local Team.&lt;/p&gt;
&lt;h3&gt;Words from DC26 Local Team&lt;/h3&gt;
&lt;p&gt;DebConf26 is over, and those of us who were part of the Local Team are trying
to return to “normality”, if such a thing exists after organizing a DebConf.&lt;/p&gt;
&lt;p&gt;This event changed our lives and would not have been possible without the help
of many great people.&lt;/p&gt;
&lt;p&gt;We would especially like to thank everyone who became part of our extended
local team. Our endless thanks go to Gunnar —who also instigated this whole
adventure—, Santiago, Nattie, Stefano, and Olasd. Thank you for supporting and
guiding us, sharing your experience, and helping us find solutions throughout
the entire process.&lt;/p&gt;
&lt;p&gt;It was also made possible thanks to the great work, strong support and patience
of international teams: Fundraising, Bursaries, Content, Video, Treasury, Visa,
Website, Accommodation, Front Desk, Cheese and Wine, Publicity as well as all
the other teams and individuals who contributed. We apologize if we have
forgotten to mention anyone; many people helped make this event possible.&lt;/p&gt;
&lt;p&gt;Our deepest thanks also go to everyone who joined us in working on the event,
especially Fer, José, and Julián, who showed great commitment and took
responsibility for several important tasks.&lt;/p&gt;
&lt;p&gt;We would also like to extend our gratitude to FICH, the Universidad Nacional
del Litoral, the institutions, organizations, sponsors, suppliers, and everyone
who contributed in one way or another to welcoming the Debian community to
Santa Fe.&lt;/p&gt;
&lt;p&gt;And finally, a very special thank you to our families, to whom we dedicated
little time these past few weeks, who supported us on this adventure, enduring
the exhaustion, the calls and messages at all hours, and the occasional
stressful situation. Always giving us that much-needed, encouraging hug with so
much love.&lt;/p&gt;
&lt;p&gt;These were very intense weeks, during which we tried to give our best so that
everyone could enjoy their stay and so that the Debian community had the
necessary conditions to meet, work, share knowledge, and continue creating the
magic that characterizes community life and the development of Debian.&lt;/p&gt;
&lt;p&gt;As happens at every DebConf, there were difficulties, unexpected situations,
and challenges that required us to improvise, learn, and perform a few juggling
acts. There were also moments that will certainly remain as memorable
anecdotes: the “antisocial room”, some gas heaters worthy of a museum, and
newly unlocked powers for negotiating with suppliers.&lt;/p&gt;
&lt;p&gt;We have no evidence, but also no doubt, that for many people the Conference
Dinner was one of the best moments of the event.&lt;/p&gt;
&lt;p&gt;A few ingredients we had hoped would happen naturally were missing, such as
more wine nights and at least one in-person football match.&lt;/p&gt;
&lt;p&gt;During the two weeks of DebConf, we experienced every kind of weather and a
wide range of emotions. Above all, however, we saw people enjoying themselves
and building friendships, which fills us with pride.&lt;/p&gt;
&lt;p&gt;Thank you very much to everyone who came and helped DebConf26 leave such a
beautiful mark on our hearts.&lt;/p&gt;
&lt;p&gt;We hope our paths cross again somewhere in life.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Leonardo, Emmanuel, Mariano, Pablo, and Martín
DebConf26 Local Team&lt;/p&gt;
&lt;h3&gt;About Debian&lt;/h3&gt;
&lt;p&gt;The Debian Project was founded in 1993 by Ian Murdock to be a truly free
community project. Since then the project has grown to be one of the
largest and most influential Open Source projects. Thousands of
volunteers from all over the world work together to create and maintain
Debian software. Available in 70 languages, and supporting a huge range
of computer types, Debian calls itself the &lt;em&gt;universal operating system&lt;/em&gt;.&lt;/p&gt;
&lt;h3&gt;About DebConf&lt;/h3&gt;
&lt;p&gt;DebConf is the Debian Project's developer conference. In addition to a
full schedule of technical, social and policy talks, DebConf provides an
opportunity for developers, contributors and other interested people to
meet in person and work together more closely. It has taken place
annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina,
India, Korea, France. More information about DebConf is available from
&lt;a href="https://debconf.org"&gt;https://debconf.org/&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Contact Information&lt;/h3&gt;
&lt;p&gt;For further information, please visit the DebConf26 web page at
&lt;a href="https://debconf26.debconf.org/"&gt;https://debconf26.debconf.org/&lt;/a&gt; or send
mail to &lt;a href="https://bits.debian.org/feeds/mailto:press@debian.org"&gt;press@debian.org&lt;/a&gt;.&lt;/p&gt; </description> 
	<pubDate>Mon, 10 Aug 2026 21:50:00 +0000</pubDate>

</item> 
<item>
	<title>Jonathan Dowland: time-delayed scifi roundup feed</title>
	<guid>https://jmtd.net/log/guardian_scifi_roundup/</guid>
	<link>https://jmtd.net/log/guardian_scifi_roundup/</link>
     <description>  &lt;img src="http://planet.debian.org/heads/jmtd.png" width="65" height="85" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;I enjoy reading The Guardian's monthly round-up of new SF novels, which can be
found in their &lt;a href="https://www.theguardian.com/books/science-fiction"&gt;Science Fiction
Books&lt;/a&gt; section, and can also
be read via &lt;a href="https://www.theguardian.com/books/science-fiction/rss"&gt;feed&lt;/a&gt;.
Since the round-up is of new books, at the time the round-up is published
they're usually only available in hardback.&lt;/p&gt;

&lt;p&gt;When it comes to choosing a book to read, these days I am tending towards
paperbacks: I've largely ran out of room for hardbacks. So I decided to apply
a time delay to their feed. Six months is roughly enough that a
book mentioned in a round-up should be shortly available in paperback.&lt;/p&gt;

&lt;p&gt;The first obstacle was that The Guardian only publish roughly the
last six months of articles in their feed, and so the posts I want have
disappeared. However, my Feed Reader
(&lt;a href="https://www.freshrss.org/"&gt;FreshRSS&lt;/a&gt;) had older copies stored in
its database, and I am able to re-publish those
using &lt;a href="https://freshrss.github.io/FreshRSS/en/users/user_queries.html"&gt;User Queries&lt;/a&gt;.
(This also gives me an opportunity to filter out non-roundup articles
from the Guardian's feed).&lt;/p&gt;

&lt;p&gt;It's then a nice short piece of scripting (this time, using Ruby) to filter the
republished feed on the publication date. To make the most recent articles appear new, I
also modify the metadata for filtered entries to appear 6 months newer than they are.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;#!/usr/bin/ruby
require 'rss'

# replace with the user query feed URI
uri       = 'https://www.theguardian.com/books/science-fiction/rss'
now       = Time.now
sixMonths = 6 * 30 * 24 * 60 * 60
feed      = RSS::Parser.parse(uri)

feed.items.select! do |item|
  item.date + sixMonths &amp;lt; now
end
feed.items.collect! do |item|
  item.date += sixMonths
  item
end

puts "Content-Type: text/xml\r\n\r"
puts feed
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;I stuck that up on my private web server, subscribed to it in my FreshRSS
and voila, a time-delayed list of books to read, most likely available in
paperback.&lt;/p&gt; </description> 
	<pubDate>Mon, 10 Aug 2026 14:44:31 +0000</pubDate>

</item> 
<item>
	<title>Uwe Kleine-König: PGP Keysigning on Linux Plumbers and OpenSource Summit Europe 2026</title>
	<guid>tag:blog.kleine-koenig.org,2026-08-10:/ukl/pgp-keysigning-on-linux-plumbers-and-opensource-summit-europe-2026.html</guid>
	<link>https://blog.kleine-koenig.org/ukl/pgp-keysigning-on-linux-plumbers-and-opensource-summit-europe-2026.html</link>
     <description>  &lt;p&gt;I'm going to this year's &lt;a href="https://lpc.events/"&gt;LPC&lt;/a&gt; and &lt;a href="https://sessionize.com/open-source-summit-europe26"&gt;Open Source Summit
Europe&lt;/a&gt; &#129395;.&lt;/p&gt;
&lt;p&gt;I will organize sessions on two days after the conference program to exchange
PGP fingerprints for keysigning to improve the kernel's web-of-trust (but of
course everyone is welcome).&lt;/p&gt;
&lt;p&gt;For details see my &lt;a href="https://lore.kernel.org/lkml/lpcosse2026-keysigning@baylibre.com/"&gt;announcement on
LKML&lt;/a&gt;. Note
the registration deadline at 2026-09-27 08:00 UTC.&lt;/p&gt; </description> 
	<pubDate>Mon, 10 Aug 2026 14:37:00 +0000</pubDate>

</item> 
<item>
	<title>Elana Hashman: Managing virtualenvs with a little bash</title>
	<guid>tag:hashman.ca,2026-08-09:/managing-venvs/</guid>
	<link>https://hashman.ca/managing-venvs/</link>
     <description>  &lt;p&gt;When you need to install something directly from &lt;a href="https://pypi.org/"&gt;PyPI&lt;/a&gt;, Python virtualenvs have
been my go-to for over a decade.&lt;/p&gt;
&lt;h2&gt;A quick virtualenv intro&lt;/h2&gt;
&lt;p&gt;Most of my readers are probably already familiar with virtualenvs, but for
completeness, I'll give you a brief introduction. A &lt;a href="https://docs.python.org/3/library/venv.html"&gt;virtualenv&lt;/a&gt; (short for
"virtual environment") is an isolated distribution of Python packages, where
you can independently install packages without disturbing your system packages
or other virtualenvs.&lt;/p&gt;
&lt;p&gt;You can set one up like this, assuming you are using Python 3.3 or higher:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;python3&lt;span class="w"&gt; &lt;/span&gt;-m&lt;span class="w"&gt; &lt;/span&gt;venv&lt;span class="w"&gt; &lt;/span&gt;~/.venv/my-virtualenv
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The directory specified here is just a convention. I keep all my virtualenvs in
the &lt;code&gt;.venv&lt;/code&gt; folder in my home directory, but you can pick whatever location you
like.&lt;/p&gt;
&lt;p&gt;To use the virtualenv, you must activate it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="nb"&gt;source&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;~/.venv/my-virtualenv/bin/activate
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This activation script is a special shell script that configures your current
shell, pointing at all the right paths in order to use the virtual environment.
&lt;a href="https://www.gnu.org/software/bash/manual/bash.html#index-_002e"&gt;&lt;code&gt;source&lt;/code&gt;&lt;/a&gt; runs this script in your current shell session to set it
up. You will notice that this adds &lt;code&gt;(my-virtualenv)&lt;/code&gt; to the beginning of your
shell prompt, reminding you that the "my-virtualenv" virtualenv is active. Now
when you &lt;code&gt;pip install amazing-package&lt;/code&gt;, the software will only be available in
this virtual environment.&lt;/p&gt;
&lt;p&gt;When you're done, you can deactivate it like so:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;deactivate
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Wonderful!&lt;/p&gt;
&lt;h2&gt;Managing many virtualenvs gets annoying&lt;/h2&gt;
&lt;p&gt;Over time, I end up accumulating many virtualenvs, which can become harder to
manage. Maybe something like this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class="w"&gt; &lt;/span&gt;ls&lt;span class="w"&gt; &lt;/span&gt;~/.venv/
my-virtualenv&lt;span class="w"&gt; &lt;/span&gt;cool-project&lt;span class="w"&gt; &lt;/span&gt;snakes-ahoy
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;I also don't want to type &lt;code&gt;source ~/.venv/my-virtualenv/bin/activate&lt;/code&gt; every
time I use the virtualenv, because it gets very repetitive—only the name
of the venv is really needed.&lt;/p&gt;
&lt;p&gt;But luckily, we can write a little bit of bash to make managing this less
annoying. (Or you can use one of many Python developer tools that are designed
to manage this, like &lt;a href="https://pipx.pypa.io/latest/index.html"&gt;pipx&lt;/a&gt;, but when I merely want to &lt;em&gt;consume&lt;/em&gt; Python
software, I might not have a development environment set up. So that's beyond
the scope of this post!)&lt;/p&gt;
&lt;p&gt;If you add the following shell function to your &lt;code&gt;~/.bashrc&lt;/code&gt; or
&lt;code&gt;~/.bash_aliases&lt;/code&gt; file, it will nicely wrap our activation command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;setup-venv&lt;span class="o"&gt;()&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="nb"&gt;source&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$HOME&lt;/span&gt;&lt;span class="s2"&gt;/.venv/&lt;/span&gt;&lt;span class="nv"&gt;$1&lt;/span&gt;&lt;span class="s2"&gt;/bin/activate"&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Now all we need to run is&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;setup-venv&lt;span class="w"&gt; &lt;/span&gt;my-virtualenv
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;So much quicker!&lt;/p&gt;
&lt;h2&gt;Spicing it up with tab completion&lt;/h2&gt;
&lt;p&gt;The first thing I noticed after writing this wrapper was that I started hitting
tab on the virtual environment name, but... nothing happened. Wouldn't it be
nice to know what virtualenvs I had available, and to not have to type out the
whole long thing?&lt;/p&gt;
&lt;p&gt;Well, we can write it ourselves &#128516;&lt;/p&gt;
&lt;p&gt;If for some reason you don't already have bash completion installed, on a
Debian-based system, you will need to install it with&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;apt&lt;span class="w"&gt; &lt;/span&gt;install&lt;span class="w"&gt; &lt;/span&gt;bash-completion
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;In order to configure our &lt;a href="https://www.gnu.org/software/bash/manual/html_node/Programmable-Completion.html"&gt;bash completion&lt;/a&gt;, we will create a new file,
&lt;code&gt;/etc/bash_completion.d/venv&lt;/code&gt;, with the following contents:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;_list_venvs&lt;span class="o"&gt;()&lt;/span&gt;
&lt;span class="o"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="nb"&gt;local&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;cur&lt;span class="w"&gt; &lt;/span&gt;prev&lt;span class="w"&gt; &lt;/span&gt;opts
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="nv"&gt;COMPREPLY&lt;/span&gt;&lt;span class="o"&gt;=()&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="nv"&gt;cur&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt;&lt;span class="nv"&gt;COMP_WORDS&lt;/span&gt;&lt;span class="p"&gt;[COMP_CWORD]&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="nv"&gt;prev&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt;&lt;span class="nv"&gt;COMP_WORDS&lt;/span&gt;&lt;span class="p"&gt;[COMP_CWORD-1]&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="nv"&gt;opts&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="k"&gt;$(&lt;/span&gt;find&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$HOME&lt;/span&gt;/.venv/&lt;span class="w"&gt; &lt;/span&gt;-mindepth&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;-maxdepth&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;-type&lt;span class="w"&gt; &lt;/span&gt;d&lt;span class="w"&gt; &lt;/span&gt;-printf&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"%f "&lt;/span&gt;&lt;span class="k"&gt;)&lt;/span&gt;

&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="nv"&gt;COMPREPLY&lt;/span&gt;&lt;span class="o"&gt;=(&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;compgen&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;-W&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt;&lt;span class="nv"&gt;opts&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;--&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt;&lt;span class="nv"&gt;cur&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="k"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="nb"&gt;complete&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;-F&lt;span class="w"&gt; &lt;/span&gt;_list_venvs&lt;span class="w"&gt; &lt;/span&gt;setup-venv
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This file defines another shell function order to determine how to
autocomplete the options for our &lt;code&gt;setup-venv&lt;/code&gt; function.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;$opts&lt;/code&gt; is where we define the options for our function. We generate it with a
&lt;code&gt;find&lt;/code&gt; command—looking at the &lt;code&gt;.venv&lt;/code&gt; folder in the current user's home
directory, then only including child folders (excluding the current directory
itself, &lt;code&gt;.venv&lt;/code&gt;, in our results) by using the min/max depth and type arguments,
and printing just the individual directory names, deliminated by spaces using
our print formatter.&lt;/p&gt;
&lt;p&gt;Everything else is the standard scaffolding required to use bash completions.&lt;/p&gt;
&lt;p&gt;Once you save this file and reload your shell, you'll see that you are able to use completions as expected!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;setup-venv&lt;span class="w"&gt; &lt;/span&gt;&amp;lt;tab&amp;gt;
my-virtualenv&lt;span class="w"&gt; &lt;/span&gt;cool-project&lt;span class="w"&gt; &lt;/span&gt;snakes-ahoy

setup-venv&lt;span class="w"&gt; &lt;/span&gt;s&amp;lt;tab&amp;gt;
setup-venv&lt;span class="w"&gt; &lt;/span&gt;snakes-ahoy
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h2&gt;Complaints, comments, questions?&lt;/h2&gt;
&lt;p&gt;Hope this was helpful! If it wasn't, that's too bad. But don't worry—you
can safely ignore this post.&lt;/p&gt; </description> 
	<pubDate>Sun, 09 Aug 2026 20:00:00 +0000</pubDate>

</item> 
<item>
	<title>Reproducible Builds: Reproducible Builds in July 2026</title>
	<guid>https://reproducible-builds.org/reports/2026-07/</guid>
	<link>https://reproducible-builds.org/reports/2026-07/</link>
     <description>  &lt;p class="lead"&gt;&lt;strong&gt;Welcome to the July 2026 report from the &lt;a href="https://reproducible-builds.org"&gt;Reproducible Builds&lt;/a&gt; project!&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://reproducible-builds.org/"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/reproducible-builds.png#right" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In our reports, we try to outline the most important things that we have been up to over the past month. As a quick recap about what problem our project intends to solve, whilst anyone may inspect the source code of free software for malicious flaws, almost all software is distributed to end users as pre-compiled binaries. The motivation behind the reproducible builds effort is to ensure no flaws have been introduced during this compilation process by promising identical results are always generated from a given source, thus allowing multiple third-parties to come to a consensus on whether a build was compromised or not.&lt;/p&gt;

&lt;p&gt;If you are interested in contributing to the project, please visit the &lt;a href="https://reproducible-builds.org/contribute/"&gt;&lt;em&gt;Contribute&lt;/em&gt;&lt;/a&gt; page on our website.&lt;/p&gt;

&lt;p&gt;In this month’s report, we cover:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;&lt;a href="https://reproducible-builds.org/blog/index.rss#tool-development"&gt;Tool development&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href="https://reproducible-builds.org/blog/index.rss#distribution-work"&gt;Distribution work&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href="https://reproducible-builds.org/blog/index.rss#three-new-scholarly-papers"&gt;Three new scholarly papers&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href="https://reproducible-builds.org/blog/index.rss#patches"&gt;Patches&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href="https://reproducible-builds.org/blog/index.rss#misc-news"&gt;Misc news&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;hr /&gt;

&lt;h3 id="tool-development"&gt;Tool development&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://diffoscope.org/"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/diffoscope.png#right" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://diffoscope.org"&gt;&lt;strong&gt;diffoscope&lt;/strong&gt;&lt;/a&gt; is our in-depth and content-aware diff utility that can locate and diagnose reproducibility issues. This month, Chris Lamb made the following changes, including preparing and uploading versions &lt;code class="language-plaintext highlighter-rouge"&gt;324&lt;/code&gt;, &lt;code class="language-plaintext highlighter-rouge"&gt;325&lt;/code&gt; and &lt;code class="language-plaintext highlighter-rouge"&gt;326&lt;/code&gt; to Debian:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Fix tests to work with &lt;code class="language-plaintext highlighter-rouge"&gt;zipdetails&lt;/code&gt; 4.0008. (&lt;a href="https://bugs.debian.org/1141359"&gt;#1141359&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;Bump debhelper compatibility level to 13. [&lt;a href="https://salsa.debian.org/reproducible-builds/diffoscope/commit/474f3702"&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;Update copyright years. [&lt;a href="https://salsa.debian.org/reproducible-builds/diffoscope/commit/4cde19a5"&gt;…&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In addition, Paul Spooren made changes to allow trailing garbage in Gzip files [&lt;a href="https://salsa.debian.org/reproducible-builds/diffoscope/commit/c8dcbf4a"&gt;…&lt;/a&gt;] and Vagrant Cascadian added an external tool reference for the &lt;code class="language-plaintext highlighter-rouge"&gt;pedump&lt;/code&gt; binary to use the &lt;code class="language-plaintext highlighter-rouge"&gt;mono&lt;/code&gt; package under &lt;a href="https://guix.gnu.org/"&gt;GNU Guix&lt;/a&gt;. [&lt;a href="https://salsa.debian.org/reproducible-builds/diffoscope/commit/b79afa9e"&gt;…&lt;/a&gt;]&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://tracker.debian.org/pkg/disorderfs"&gt;&lt;strong&gt;disorderfs&lt;/strong&gt;&lt;/a&gt; is our &lt;a href="https://en.wikipedia.org/wiki/Filesystem_in_Userspace"&gt;FUSE&lt;/a&gt;-based filesystem that deliberately introduces non-determinism into system calls to reliably flush out reproducibility issues. This month, Christelle Gloor added the option to sort by &lt;code class="language-plaintext highlighter-rouge"&gt;ctime&lt;/code&gt; as returned by the &lt;code class="language-plaintext highlighter-rouge"&gt;lstat(2)&lt;/code&gt; &lt;a href="https://en.wikipedia.org/wiki/System_call"&gt;syscall&lt;/a&gt;. [&lt;a href="https://salsa.debian.org/reproducible-builds/disorderfs/commit/68d20f7"&gt;…&lt;/a&gt;], which Chris Lamb uploaded whilst bumping the &lt;code class="language-plaintext highlighter-rouge"&gt;Standards-Version&lt;/code&gt; to version 4.7.4 [&lt;a href="https://salsa.debian.org/reproducible-builds/disorderfs/commit/240fae0"&gt;…&lt;/a&gt;]. Bernhard Wiedemann also &lt;a href="https://build.opensuse.org/request/show/1368149"&gt;updated &lt;em&gt;disorderfs&lt;/em&gt; to version 0.7.0&lt;/a&gt; in &lt;a href="https://www.opensuse.org/"&gt;openSUSE&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://reproducible-builds.org/"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/website.png#right" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Yet again, there were a number of improvements made to &lt;a href="https://reproducible-builds.org/"&gt;&lt;strong&gt;our website&lt;/strong&gt;&lt;/a&gt; this month as well. For example, Chris Lamb, by request of &lt;a href="https://www.digitalocean.com/"&gt;Digital Ocean&lt;/a&gt;, changed the target of a referral link so that they can manage incoming referrers [&lt;a href="https://salsa.debian.org/reproducible-builds/reproducible-website/commit/4ac1b2fa"&gt;…&lt;/a&gt;] and pushed a number of changes to the &lt;a href="https://reproducible-builds.org/tools/"&gt;&lt;em&gt;Tools&lt;/em&gt;&lt;/a&gt; page [&lt;a href="https://salsa.debian.org/reproducible-builds/reproducible-website/commit/3e3154f2"&gt;…&lt;/a&gt;].&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id="distribution-work"&gt;Distribution work&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://debian.org/"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/debian.png#right" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In &lt;strong&gt;Debian&lt;/strong&gt; this month, 32 reviews of Debian packages were added, 26 were updated and a total of 21 were removed this month, adding to &lt;a href="https://tests.reproducible-builds.org/debian/index_issues.html"&gt;our extensive knowledge about identified issues&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;A number of issue types were added by Chris Lamb, including:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;python_towncrier_build_date&lt;/code&gt; [&lt;a href="https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/83a0efd3"&gt;…&lt;/a&gt;][&lt;a href="https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/6f036b2a"&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;log_files_installed_in_package&lt;/code&gt; [&lt;a href="https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/c629afdf"&gt;…&lt;/a&gt;]&lt;/li&gt;
  &lt;li&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;fontforge_varies_by_timezone&lt;/code&gt; [&lt;a href="https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/d76c0f05"&gt;…&lt;/a&gt;][&lt;a href="https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/fc4a9fc5"&gt;…&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Chris also added a further note for the &lt;code class="language-plaintext highlighter-rouge"&gt;build_date_in_manpage_generated_by_spf13_cobra&lt;/code&gt; issue. [&lt;a href="https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/f7b69082"&gt;…&lt;/a&gt;]&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://openwrt.org/"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/openwrt.png#right" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In addition, there is &lt;a href="https://rebuilderd.n.aparcar.org/?distro=openwrt-image"&gt;a new page showing verification rebuilds&lt;/a&gt; of &lt;a href="https://openwrt.org/"&gt;OpenWrt&lt;/a&gt; APK packages and firmware images, powered by &lt;a href="https://github.com/kpcyrd/rebuilderd"&gt;&lt;em&gt;rebuilderd&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://rebuilderd.n.aparcar.org/?distro=openwrt-image"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/openwrt-rebuilderd.png#center" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id="three-new-scholarly-papers"&gt;Three new scholarly papers&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://ieeexplore.ieee.org/abstract/document/11593337"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/paper-vcaligner.png#right" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Yan Li, Nan Jiang, Qihang Zhou, Shaowen Xu, Yamin Xie and Xiaoqi Jia of the &lt;a href="https://english.cas.cn/"&gt;Chinese Academy of Sciences&lt;/a&gt; published a paper titled &lt;a href="https://ieeexplore.ieee.org/abstract/document/11593337"&gt;&lt;em&gt;VCAligner: Aligning Source Distribution Versions with Upstream Git Commits to Secure Supply Chain&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;We present VCAligner, a content-based alignment methodology that constructs inverted indexes over VCS histories to precisely map released artifacts to their originating commits, independent of fragile version tags. We evaluated VCAligner on a dataset of 2,984 verifiable PyPI packages derived from the 4,000 most-downloaded projects linked to public GitHub upstreams. &lt;strong&gt;Our results reveal a critical weakness in conventional tag-based heuristics: while they appear effective on 85% of the dataset, the residual 15% failure rate generates a catastrophic downstream audit workload of over 10.3 million commits. In contrast, VCAligner reduces this burden by two orders of magnitude (≈ 158×), bounding the total workload to under 65,000 commits.&lt;/strong&gt; Furthermore, we provide the large-scale characterization of “Packaging Noise,” classifying artifact divergence into structural additions (Path Phantoms) and content mutations (Blob Phantoms), thereby isolating the distinct attack surfaces of malicious injection and code tampering.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://doi.org/10.48550/ARXIV.2607.21888"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/paper-snakeoil.png#right" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Jens Dietrich and Spencer Sun from the &lt;a href="https://www.wgtn.ac.nz/"&gt;Victoria University of Wellington&lt;/a&gt; together with Tim W. White and Behnaz Hassanshahi from &lt;a href="https://www.oracle.com"&gt;Oracle Inc&lt;/a&gt; pre-published their paper &lt;a href="https://arxiv.org/pdf/2607.21888"&gt;&lt;em&gt;No Snake Oil: Verifying Python Package Builds&lt;/em&gt;&lt;/a&gt; (PDF):&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Python has become the default language for interacting with AI, with packages being distributed through registries like the Python Package Index (PyPI). This creates a need to analyse supply chains comprising such packages. One such analysis is to rebuild packages in order to identify compromised builds injecting malware. Independent rebuilds in hardened environments have the added advantage that they can generate and record provenance in order to increase the trustworthiness of packages. Two tools that are designed to automate such rebuilds and run them at scale are macaron and oss-rebuild. We study 12,180 popular releases from PyPI and find that the byte-for-byte equivalence rate is generally low. We analyse the reasons why they produce different wheels, and find that equivalence between the original and rebuilt wheels can often still be established, preserving most of the guarantees users expect from rebuildable releases. We present and evaluate daleq4py, a tool to establish the equivalence of Python wheels through the kernel of a normalisation function that is based on provenance-preserving datalog rules. Experimental results show that daleq4py substantially expands the set of rebuilds that can be accepted as equivalent. &lt;strong&gt;Although only 15.4% of macaron rebuilds and 19.1% of oss-rebuild rebuilds are byte-for-byte identical to the published PyPI wheels, daleq4py establishes wheel equivalence for 60.2% and 78.9% of source-equivalent rebuilds, respectively.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://arxiv.org/abs/2607.01890"&gt;&lt;img alt="" src="https://reproducible-builds.org/images/reports/2026-07/paper-fdroid.png#right" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Denise Nanni, Julien Malka, Stefano Zacchiroli and Théo Zimmermann from &lt;a href="https://www.telecom-paris.fr/en/home"&gt;Télécom Paris&lt;/a&gt; together with Gabriele D’Angelo from the &lt;a href="https://www.unibo.it/en/homepage"&gt;University of Bologna&lt;/a&gt; pre-published their paper &lt;a href="https://arxiv.org/pdf/2607.01890"&gt;&lt;em&gt;Understanding Build Reproducibility in the F-Droid Ecosystem&lt;/em&gt;&lt;/a&gt; (PDF), which was accepted at the &lt;a href="https://acm-rep.github.io/2026/accepted/"&gt;2026 ACM Conference on Reproducibility and Replicability&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;The security of open source applications benefits considerably from the possibility of rebuilding their source and verifying the output. F-Droid, a prominent distribution for open source Android applications, systematically rebuilds them from source and tests their bitwise reproducibility at app publishing time. However, F-Droid offers no guarantee that app reproducibility will continue to hold in the future. As software ecosystems evolve, reproducibility may degrade, with potential negative consequences for software preservation and security. We present the first empirical study of build reproducibility in the F-Droid app ecosystem. Analyzing historical reproducibility logs, we find that the overall bitwise reproducibility rate has been steadily increasing over time (as new versions of apps are published). We then evaluate how reproducibility holds in time for fixed app versions, by attempting to rebuild 18 904 app versions that F-Droid had previously confirmed bitwise reproducible, published between September 2018 and February 2026, &lt;strong&gt;achieving an 83% rebuild success rate, and identify missing dependencies as the dominant cause of failure, accounting for 76% of non-rebuildable cases. Among successfully rebuilt apps, 94% are also bitwise reproducible&lt;/strong&gt;-i.e., they still yield bitwise identical artifacts upon rebuild. Together, these results show that while bitwise reproducibility largely holds for apps that can be rebuilt, rebuildability itself is highly sensitive to temporal decay.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id="patches"&gt;Patches&lt;/h3&gt;

&lt;p&gt;The Reproducible Builds project detects, dissects and attempts to fix as many currently-unreproducible packages as possible. We endeavour to send all of our patches upstream where applicable or possible. This month, we wrote a large number of such patches, including:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;a href="https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/thread/JLAOJP7W6K3P2SL6XT6UYX444XZ5WQPN/"&gt;openSUSE monthly&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Arnout Engelen:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href="https://github.com/apache/ant-ivy/pull/127"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;ivy&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://github.com/apache/pekko-grpc/pull/746"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;pekko-grpc&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://github.com/sbt/ivy/pull/51"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;sbt-ivy&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://github.com/scala/scala3/pull/26510"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;scala&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Bernhard M. Wiedemann:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href="https://build.opensuse.org/request/show/1364030"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;angelfish&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://github.com/python/cpython/pull/154988"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;cpython&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://git.enlightenment.org/enlightenment/efl/pulls/133"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;efl&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://github.com/erlang/otp/issues/4417#issuecomment-5105267295"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;erlang+ex_doc&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://build.opensuse.org/request/show/1368578"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;eww/glib-macros&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://github.com/intel/intel-graphics-compiler/pull/418"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;intel-graphics-compiler&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://build.opensuse.org/request/show/1368181"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;java-11-openjdk&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://build.opensuse.org/request/show/1368181"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;java-17-openjdk&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://build.opensuse.org/request/show/1368504"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;java-1_8_0-openjdk&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugzilla.opensuse.org/show_bug.cgi?id=1221224"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;java-21-openjdk&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://gitlab.winehq.org/mono/mono/-/work_items/33"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;mono-core&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://github.com/medek/nasm-rs/pull/47"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;nasm/rav1e&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://build.opensuse.org/request/show/1364286"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;python-langsmith&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://build.opensuse.org/request/show/1364231"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;zathura*&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://build.opensuse.org/request/show/1368243"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;zig0.15&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Chris Lamb:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141505"&gt;#1141505&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/golang-github-tidwall-wal"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;golang-github-tidwall-wal&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141506"&gt;#1141506&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/lightproof"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;lightproof&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141582"&gt;#1141582&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/libslow5lib"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;libslow5lib&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141687"&gt;#1141687&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/siso"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;siso&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141841"&gt;#1141841&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/grout"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;grout&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142126"&gt;#1142126&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/libpsl"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;libpsl&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142492"&gt;#1142492&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/node-grunt-contrib-internal"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;node-grunt-contrib-internal&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142495"&gt;#1142495&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/fontforge"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;fontforge&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142496"&gt;#1142496&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/spopt"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;spopt&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142887"&gt;#1142887&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/go-dlib"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;go-dlib&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1143147"&gt;#1143147&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/towncrier"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;towncrier&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Jochen Sprickerhof:&lt;/p&gt;

    &lt;ul&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141412"&gt;#1141412&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/python-sphinx-chango"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;python-sphinx-chango&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141553"&gt;#1141553&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/gasnet"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;gasnet&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141577"&gt;#1141577&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/yubihsm-connector"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;yubihsm-connector&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1141663"&gt;#1141663&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/dh-fortran"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;dh-fortran&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142000"&gt;#1142000&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/watcher"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;watcher&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142001"&gt;#1142001&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/rakudo"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;rakudo&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142128"&gt;#1142128&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/kf6-breeze-icons"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;kf6-breeze-icons&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142141"&gt;#1142141&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/oxygen-icons"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;oxygen-icons&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142256"&gt;#1142256&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/gnu-apl"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;gnu-apl&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1142513"&gt;#1142513&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/barvinok"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;barvinok&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://bugs.debian.org/1143169"&gt;#1143169&lt;/a&gt; filed against &lt;a href="https://tracker.debian.org/pkg/ecbuild"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;ecbuild&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h3 id="misc-news"&gt;Misc news&lt;/h3&gt;

&lt;p&gt;On &lt;a href="https://lists.reproducible-builds.org/listinfo/rb-general/"&gt;our mailing list&lt;/a&gt; this month, Colin Winter of &lt;a href="https://markovianprotocol.com/"&gt;Markovian Protocol&lt;/a&gt; wrote to our mailing list on the topic of &lt;a href="https://lists.reproducible-builds.org/pipermail/rb-general/2026-July/004133.html"&gt;&lt;em&gt;Reproducible verification for retained logs&lt;/em&gt;&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Reproducible builds remove trust in the builder: anyone re-derives the same artifact from the same source, byte for byte. The same shape applies one layer over, to a retained record. Most record-keeping regimes (the &lt;a href="https://artificialintelligenceact.eu/article/12/"&gt;EU AI Act’s Article 12&lt;/a&gt; logging is the current example) require that events be recorded and logs retained, but not that a retained log be verifiable, by a party who was not present, as unaltered and existing when claimed. That leaves an integrity obligation resting on trusting the party being audited.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;(&lt;a href="https://lists.reproducible-builds.org/pipermail/rb-general/2026-July/thread.html#4133"&gt;Full thread&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Finally, if you are interested in contributing to the Reproducible Builds project, please visit our &lt;a href="https://reproducible-builds.org/contribute/"&gt;&lt;em&gt;Contribute&lt;/em&gt;&lt;/a&gt; page on our website. However, you can get in touch with us via:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;IRC: &lt;code class="language-plaintext highlighter-rouge"&gt;#reproducible-builds&lt;/code&gt; on &lt;code class="language-plaintext highlighter-rouge"&gt;irc.oftc.net&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mastodon: &lt;a href="https://fosstodon.org/@reproducible_builds"&gt;@reproducible_builds@fosstodon.org&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Mailing list: &lt;a href="https://lists.reproducible-builds.org/listinfo/rb-general"&gt;&lt;code class="language-plaintext highlighter-rouge"&gt;rb-general@lists.reproducible-builds.org&lt;/code&gt;&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt; </description> 
	<pubDate>Sun, 09 Aug 2026 19:12:10 +0000</pubDate>

</item> 
<item>
	<title>Thorsten Alteholz: My Debian Activities in July 2026</title>
	<guid>http://blog.alteholz.eu/?p=2842</guid>
	<link>http://blog.alteholz.eu/2026/08/my-debian-activities-in-july-2026/</link>
     <description>  &lt;h3&gt;&lt;strong&gt;Debian LTS/ELTS&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This was my hundred-forty-fifth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
&lt;/p&gt;
&lt;p&gt;
During my allocated time I uploaded or worked on:  
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;[&lt;a href="https://lists.debian.org/debian-security-announce/2026/msg00313.html"&gt;DSA 6402-1&lt;/a&gt;] hplip security update to fix two CVEs in Trixie related to privilege escalation and/or arbitrary code execution. I sent the debdiff to the security team, which resulted in this DSA.
&lt;/li&gt;&lt;li&gt;[&lt;a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142351"&gt;#1142351&lt;/a&gt;] trixie-pu of libnfs has been uploaded.&lt;/li&gt;&lt;li&gt;[&lt;a href="https://lists.debian.org/debian-lts-announce/2026/07/msg00031.html"&gt;DLA 4689-1&lt;/a&gt;]  libnfs security update to fix one CVE in Bookworm and Bullseye related to an integer overflow.
&lt;/li&gt;&lt;li&gt;[&lt;a href="https://lists.debian.org/debian-lts-announce/2026/07/msg00041.html"&gt;DLA 4699-1&lt;/a&gt;] hplip security update to fix two CVEs in Bookworm and Bullseye related to privilege escalation and/or arbitrary code execution.
&lt;/li&gt;&lt;li&gt;[ELA-1775-1] libnfs gimp security update to fix one CVE in Buster and Stretch related to an integer overflow.&lt;/li&gt;&lt;li&gt;[ELA-1784-1] hplip security update to fix two CVEs in Buster and Stretch related to privilege escalation and/or arbitrary code execution.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;
Unfortunately the number of assigned hours was rather low this month. So besides doing some days of FD at the end of the month, where I also had to process a new package list for ELTS, and a review of the rsync package (prepared by Sylvain), not much happened here.
&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Printing&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream versions:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/hplip"&gt;hplip&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/foomatic-db"&gt;foomatic-db&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;Besides the package upload, I also took care of some older bugs of hplip.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href="https://www.freexian.com"&gt;Freexian&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Lomiri&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;&lt;/p&gt;&lt;p&gt;This month I continued the upload of lomiri packages with new upstream versions. Thanks to the help of my other colleagues, this project could be finished now.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;This work is generously funded by &lt;a href="https://freiesoftware.gmbh/"&gt;Fre(i)e Software GmbH&lt;/a&gt;!&lt;/strong&gt;&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Astro&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/fxload"&gt;fxload&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/indi-orion-ssg3"&gt;indi-orion-ssg3&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/calceph"&gt;calceph&lt;/a&gt; to unstable (sponsored upload).&lt;/li&gt;&lt;/ul&gt;



&lt;h3&gt;&lt;strong&gt;Debian IoT&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;Unfortunately I had no time to work in this category this month.&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;Debian Mobcom&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/libgsm"&gt;libgsm&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/libosmocore"&gt;libosmocore&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/libosmo-cc"&gt;libosmo-cc&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt;



&lt;p&gt;Next month I intend to upload new upstream versions of all Osmocom packages. As far as I can tell, these uploads will happen without soname changes. I like that :-).&lt;/p&gt;



&lt;h3&gt;&lt;strong&gt;misc&lt;/strong&gt;&lt;/h3&gt;



&lt;p&gt;This month I uploaded a new upstream version  or a bugfix version of:&lt;/p&gt;



&lt;ul&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/usb-modeswitch"&gt;usb-modeswitch&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/ta-lib"&gt;ta-lib&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/lua-geoip"&gt;lua-geoip&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/lua-systemd"&gt;lua-systemd&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/displaylink-driver"&gt;displaylink-driver&lt;/a&gt; to unstable.&lt;/li&gt;&lt;li&gt;… &lt;a href="https://tracker.debian.org/nuspell"&gt;nuspell&lt;/a&gt; to unstable.&lt;/li&gt;&lt;/ul&gt; </description> 
	<pubDate>Fri, 07 Aug 2026 17:02:01 +0000</pubDate>

</item> 
<item>
	<title>Reproducible Builds (diffoscope): diffoscope 327 released</title>
	<guid>https://diffoscope.org/news/diffoscope-327-released/</guid>
	<link>https://diffoscope.org/news/diffoscope-327-released/</link>
     <description>  &lt;p&gt;The diffoscope maintainers are pleased to announce the release of diffoscope
version &lt;code class="language-plaintext highlighter-rouge"&gt;327&lt;/code&gt;. This version includes the following changes:&lt;/p&gt;

&lt;div class="language-plaintext highlighter-rouge"&gt;&lt;div class="highlight"&gt;&lt;pre class="highlight"&gt;&lt;code&gt;[ Colin Watson ]
* Handle missing openssh-client binaries in autopkgtests.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You find out more by &lt;a href="https://diffoscope.org"&gt;visiting the project homepage&lt;/a&gt;.&lt;/p&gt; </description> 
	<pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>

</item> 
<item>
	<title>Bits from Debian: DebConf26 closes in Santa Fe and DebConf27 announced</title>
	<guid>tag:bits.debian.org,2026-08-06:/2026/08/debconf26-closes.html</guid>
	<link>https://bits.debian.org/2026/08/debconf26-closes.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/dwn.png" width="77" height="85" alt="" align="right" style="float: right;"&gt;  &lt;p&gt;&lt;a href="https://wiki.debian.org/DebConf/26/Photos?action=AttachFile&amp;amp;do=view&amp;amp;target=debconf26-group-photo.jpg"&gt;&lt;img alt="DebConf26 group photo - click to enlarge" src="https://bits.debian.org/images/debconf26-group-photo_small.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;On Saturday 25 July 2026, the annual &lt;a href="https://debconf26.debconf.org/"&gt;Debian Developers and Contributors
Conference&lt;/a&gt; came to a close.
Over 270 attendees representing 35 countries from around the world came
together for a combined 90 events (including some which took place during
the DebCamp) including more than 27 Talks, 21 Short Talks,
29 Birds of a Feather sessions ("BoF" – informal meeting between developers
and users), 8 workshops, and activities in support of furthering our
distribution and free software, learning from our mentors and peers, building
our community, and having a bit of fun.&lt;/p&gt;
&lt;p&gt;The conference was preceded by the annual
&lt;a href="https://wiki.debian.org/DebCamp"&gt;DebCamp&lt;/a&gt; hacking session held 13
through 19 July where Debian Developers and Contributors convened to
focus on their individual Debian-related projects or work in team sprints
geared toward in-person collaboration in developing Debian.&lt;/p&gt;
&lt;p&gt;As has been the case for several years, a special effort has been made to
welcome newcomers and help them become familiar with Debian and DebConf
by organizing a sprint "New Contributors Onboarding" every day of Debcamp,
followed more informally by mentorship during DebConf. Half a dozen new
contributors joined the sessions and learned about Debian, free software,
packaging and much more.&lt;/p&gt;
&lt;p&gt;This year, a week-long DebCamp session was dedicated to auditing,
patching, and modernizing the Go ecosystem in Debian and enable the
transition triggered by the recent upload of dh-golang enabling GO111MODULE=on
by default in Experimental.&lt;/p&gt;
&lt;p&gt;In order to make the conference more accessible for local participants,
a local language track was included in the schedule for talks in Spanish,
as was done at DebConf19 in Brazil.&lt;/p&gt;
&lt;p&gt;The actual Debian Developers Conference started on Monday 20 July 2026.&lt;/p&gt;
&lt;p&gt;In addition to the traditional "Bits from the DPL" talk, the continuous
key-signing party, lightning talks, and the announcement of next year's
DebConf27, there were several update sessions shared by internal projects
and teams.&lt;/p&gt;
&lt;p&gt;Many of the hosted discussion sessions were presented by our technical
core teams with the usual and useful "Meet the Technical Committee", three
talks about Linux Kernel, early boot and improving Debian’s kernel and
installer support for Chromebooks, and about twenty BoFs and talks about
Debian packaging policy, Debian infrastructure, security and privacy.&lt;/p&gt;
&lt;p&gt;This year, and echoing ongoing discussions within the Free Software community,
Artificial Intelligence and Age Verification have been the subject of
several talks. The Python, Perl, Ruby, Go, and Rust programming
language teams also shared updates on their work and efforts.&lt;/p&gt;
&lt;p&gt;More than 17 BoFs and talks about community, diversity, and local outreach
highlighted the work of various teams involved in not just the technical but
also the social aspect of our community&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://debconf26.debconf.org/schedule/"&gt;schedule&lt;/a&gt;
was updated each day with planned and ad hoc activities introduced by
attendees over the course of the conference. Several traditional activities
took place: a poetry performance, the traditional Cheese and Wine party, the
Group Photos, and the Day Trip.&lt;/p&gt;
&lt;p&gt;For those who were not able to attend, most of the talks and sessions were
broadcasted live and recorded. One can find the seventy hours of recorded
videos available via the conference
&lt;a href="https://debconf26.debconf.org/schedule/"&gt;schedule&lt;/a&gt;,
or alternatively through this
&lt;a href="https://meetings-archive.debian.net/pub/debian-meetings/2026/DebConf26/"&gt;link&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Almost all of the sessions facilitated remote participation via IRC and Matrix
messaging apps or online collaborative text documents which allowed remote
attendees to "be in the room" and ask questions or share comments with the
speaker or assembled audience. DebConf26 saw over 341 T-shirts, a day trip,
and up to 130 meals planned per day.&lt;/p&gt;
&lt;p&gt;All of these events, activities, conversations, and streams coupled with our
love, interest, and participation in Debian and F/OSS certainly made this
conference an overall success both here in Santa Fe, Argentina and online
around the world.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://debconf26.debconf.org/"&gt;DebConf26 website&lt;/a&gt;
will remain active for archival purposes and will continue to offer
links to the presentations and videos of talks and events.&lt;/p&gt;
&lt;p&gt;Next year, &lt;a href="https://wiki.debian.org/DebConf/27"&gt;DebConf27&lt;/a&gt; will be held
in Asahikawa, Hokkaido, Japan, from Sunday September 5th to Saturday
September 11th, 2027. As tradition follows before the next DebConf the
local organizers in Japan will start the conference activities with DebCamp
with a particular focus on individual and team work towards improving the
distribution.&lt;/p&gt;
&lt;p&gt;DebConf is committed to a safe and welcome environment for all
participants. See the
&lt;a href="https://debconf26.debconf.org/about/coc/"&gt;web page about the Code of Conduct on the DebConf26 website&lt;/a&gt;
for more details on this.&lt;/p&gt;
&lt;p&gt;Debian thanks the commitment of numerous
&lt;a href="https://debconf26.debconf.org/sponsors/"&gt;sponsors&lt;/a&gt;
to support DebConf26, particularly our Platinum Sponsors:
&lt;a href="https://www.infomaniak.com"&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt;, and
&lt;a href="https://www.proxmox.com/"&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt;,
and our Gold Sponsors : &lt;a href="https://www.freexian.com/"&gt;&lt;strong&gt;Freexian&lt;/strong&gt;&lt;/a&gt;, and
&lt;a href="https://www.viridiengroup.com"&gt;&lt;strong&gt;Viridien&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We also wish to thank our Video and Infrastructure teams, the DebConf26
and DebConf committees, our host nation of Argentina, and each and every
person who helped contribute to this event and to Debian overall.
Thank you all for your work in helping Debian continue to be "The Universal
Operating System".&lt;/p&gt;
&lt;p&gt;See you next year!&lt;/p&gt;
&lt;h3&gt;About Debian&lt;/h3&gt;
&lt;p&gt;The Debian Project was founded in 1993 by Ian Murdock to be a truly free
community project. Since then the project has grown to be one of the
largest and most influential Open Source projects. Thousands of
volunteers from all over the world work together to create and maintain
Debian software. Available in 70 languages, and supporting a huge range
of computer types, Debian calls itself the &lt;em&gt;universal operating system&lt;/em&gt;.&lt;/p&gt;
&lt;h3&gt;About DebConf&lt;/h3&gt;
&lt;p&gt;DebConf is the Debian Project's developer conference. In addition to a
full schedule of technical, social and policy talks, DebConf provides an
opportunity for developers, contributors and other interested people to
meet in person and work together more closely. It has taken place
annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina,
India, Korea, France. More information about DebConf is available from
&lt;a href="https://debconf.org"&gt;https://debconf.org/&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;About Infomaniak&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://www.infomaniak.com"&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;&lt;/a&gt; is an independent, employee-owned
Swiss technology company that designs, develops, and operates its own cloud
infrastructure and digital services entirely in Switzerland. With over
300 employees — more than 70% engineers and developers — the company reinvests
all profits into R&amp;amp;D. Its public cloud is built on OpenStack, with managed
Kubernetes, Database as a Service, object storage, and sovereign AI services
accessible via OpenAI-compatible APIs, all running on its own Swiss
infrastructure. Infomaniak also develops a sovereign collaborative suite —
messaging, email, storage, online office tools, videoconferencing, and a
built-in AI assistant — developed in-house and as a privacy-respecting
solution to proprietary platforms. Open source is central to how Infomaniak
operates. Its latest data center (D4) runs on 100% renewable energy and uses
no traditional cooling: all the heat generated by its servers is captured and
fed into Geneva's district heating network, supplying up to 6,000 homes in
winter and hot water year-round. The entire project has been documented and
open-sourced at &lt;a href="https://d4project.org/"&gt;d4project.org&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;About Proxmox&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://www.proxmox.com/"&gt;&lt;strong&gt;Proxmox&lt;/strong&gt;&lt;/a&gt; develops powerful, yet easy-to-use
open-source server solutions. The comprehensive open-source ecosystem is
designed to manage divers IT landscapes, from single servers to large-scale
distributed data centers. Our unified platform integrates server
virtualization, easy backup, and rock-solid email security ensuring seamless
interoperability across the entire portfolio. With the Proxmox Datacenter
Manager, the ecosystem also offers a "single pane of glass" for centralized
management across different locations. Since 2005, all Proxmox solutions have
been built on the rock-solid Debian platform. We are proud to return to
DebConf26 as a sponsor because the Debian community provides the foundation
that makes our work possible. We believe in keeping IT simple, open, and under
your control.&lt;/p&gt;
&lt;h3&gt;Contact Information&lt;/h3&gt;
&lt;p&gt;For further information, please visit the DebConf26 web page at
&lt;a href="https://debconf26.debconf.org/"&gt;https://debconf26.debconf.org/&lt;/a&gt; or send
mail to &lt;a href="https://bits.debian.org/feeds/mailto:press@debian.org"&gt;press@debian.org&lt;/a&gt;.&lt;/p&gt; </description> 
	<pubDate>Thu, 06 Aug 2026 21:50:00 +0000</pubDate>

</item> 
<item>
	<title>Russell Coker: TV Control etc</title>
	<guid>https://etbe.coker.com.au/?p=6267</guid>
	<link>https://etbe.coker.com.au/2026/08/06/tv-control-etc/</link>
     <description>  &lt;p&gt;&lt;a href="https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/"&gt;In 2008 I wrote a blog post “The Problem is Too Many Remote Controls” [1]&lt;/a&gt; about the issues of controlling a TV and related things. It recently got some comments on Mastodon so I think it’s time for an update.&lt;/p&gt;
&lt;p&gt;The first issue I raised was “Now it’s not uncommon to have separate remote controls for the TV, VCR, DVD player, and the Cable TV box – a total of four remote controls” which seems to have alleviated. VCRs seem to have almost entirely gone away. The &lt;a href="https://en.wikipedia.org/wiki/VHS"&gt;VHS Wikipedia page [2]&lt;/a&gt; is worth reading for everyone who hasn’t seen a VCR in operation, which I expect to be more than a few readers now and an increasing number over the next 18 years. I personally don’t have Cable TV, I own a DVD player which isn’t connected to my TV because I haven’t used it for years, I don’t own a VCR, and I don’t watch free to air TV. So I have one remote control for the TV which I use for Netflix and sometimes YouTube.&lt;/p&gt;
&lt;p&gt;When viewing YouTube on TV there are significantly more adverts and longer adverts. I presume that is because installing an ad-blocker on my TV isn’t a viable option for me and it’s a total impossibility for most users. Generally my desktop PC is a much better platform for YouTube than my TV, it has a better quality display, is more user friendly (my previous post addressed the difficulty of getting to the data source that’s desired), and doesn’t require entering search terms via a slow on-screen keyboard. Netflix on Linux is limited to 720p at low bitrate which is obviously of low visual quality while on the TV it’s in 4K. I have Netflix so I use that only on the TV.&lt;/p&gt;
&lt;p&gt;In my previous post I wrote a thought experiment on how to use a cheap laptop ($500 at the time – equivalent to $777 in 2025 money according to the Reserve Bank of Australia) to control a $5000 TV ($7770 in 2025 money). Now you can buy a new 65″ 4K TV for under $800 and a new laptop capable of 4K output for under $400 so the options are very different. For a $800 TV the manufacturer isn’t going to develop a remote control interface and Google (who develops the software the TVs run) won’t do it because it could reduce their advertising revenue. But a typical home user could setup a cheap laptop connected to their TV via HDMI providing a familiar and efficient user interface for themselves and visitors. For a Windows laptop 4K Netflix should work and for a Linux laptop the options of a laptop for everything apart from Netflix and the TV for Netflix are bearable, two controls are worse than one but better than the 3+ that used to be common.&lt;/p&gt;
&lt;p&gt;In my previous post I raised the issue that “it’s often the case that you don’t want to stop watching one show while trying to find another”. This is still an unsolved problem and is not addressed in modern software. I am not aware of a Linux music player that supports such functionality and this would be much easier for a music player than for a video player where the screen would have to be shared between the interface for finding the next thing to play and the space for playing the end of the current one. Maybe I should file a bunch of wishlist bugs against music players asking for this.&lt;/p&gt;
&lt;p&gt;I suggested that “cable modem” and “cable TV box” could be integrated into a single device. That has not happened, in fact it’s got worse. A relative who has Foxtel has a cable modem, a cable TV box, and a Wifi AP with VOIP to provide landline phone service and to make it more exciting the latter two both have bugs that require a periodic hardware reset to fix. Hopefully cable TV will go away in the next 18 years.&lt;/p&gt;
&lt;p&gt;Regular PCs have become less noisy in recent years. I am currently using a HP Z640 to write this post and I have HP Z840 and HP Z4G4 systems behind me running as servers and the background noise is still very low. The &lt;a href="https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/"&gt;allegedly 8K TV [3]&lt;/a&gt; that I have in my lounge room has cooling fans that make more noise than those three high-end HP computers combined. Using a quiet PC like one of those HP systems to drive a TV is a very viable option and I did just that for a couple of years. Kogan has currently got a selection of refurbished Lenovo ThinkStation systems on sale for under $400, they are quiet and would do well for this, it’s also nice that Kogan is selling systems with ECC RAM at home user prices.&lt;/p&gt;
&lt;p&gt;TV does seem to be going away. YouTube and streaming services seem to get more watching time and many people don’t use TV at all.&lt;/p&gt;
&lt;p&gt;Since my previous post the number of streaming services has increased so torrenting offers increasing benefits as no-one wants to subscribe to 6+ services. For anyone who wants to get all the content that interests them while paying the user interface situation is much worse now than it used to be in 2008.&lt;/p&gt;
&lt;p&gt;If you use KDE on a PC then the &lt;b&gt;kconnect&lt;/b&gt; program allows a phone to be used to remotely control some aspects of a PC and has a good interface for pause/resume of a video and seeking 10 seconds forwards/backwards. The interface for controlling volume is hard to get to and doesn’t work on my installation. If you want to use a keyboard to start something playing and then a phone for pause control then kdeconnect is a decent option. A comment on my previous post by Michael Croes raised the issue of remote control which is now a solvable problem. Justin also wrote a comment suggesting a Nokia N800 as a remote.&lt;/p&gt;
&lt;p&gt;Jason suggested a programmable remote, which would be a good option for a power user and a viable option for someone setting things up for their grandparents. But the amount of pain is greater than I’m interested in as lounge room TV isn’t an important thing to me. It may appeal to more people than having a dedicated lounge room PC though.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href="https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/"&gt; https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href="https://en.wikipedia.org/wiki/VHS"&gt; https://en.wikipedia.org/wiki/VHS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[3]&lt;a href="https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/"&gt; https://etbe.coker.com.au/2025/11/25/edid-and-my-8k-tv/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="yarpp yarpp-related yarpp-related-rss yarpp-template-list"&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2021/06/06/netflix-ipv6/" rel="bookmark" title="Netflix and IPv6"&gt;Netflix and IPv6&lt;/a&gt; &lt;small&gt;It seems that Netflix has an ongoing issue of not...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2022/01/04/big-smart-tvs/" rel="bookmark" title="Big Smart TVs"&gt;Big Smart TVs&lt;/a&gt; &lt;small&gt;Recently a relative who owned a 50″ Plasma TV asked...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2008/09/15/the-problem-is-too-many-remote-controls/" rel="bookmark" title="The Problem is Too Many Remote Controls"&gt;The Problem is Too Many Remote Controls&lt;/a&gt; &lt;small&gt;I am often asked for advice about purchasing TVs and...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Thu, 06 Aug 2026 04:01:37 +0000</pubDate>

</item> 
<item>
	<title>Gunnar Wolf: Subscription Bombing • Email under Attack</title>
	<guid>https://gwolf.org/2026/08/subscription-bombing-email-under-attack.html</guid>
	<link>https://gwolf.org/2026/08/subscription-bombing-email-under-attack.html</link>
     <description>  &lt;img src="http://planet.debian.org/heads/gwolf.png" width="69" height="83" alt="" align="right" style="float: right;"&gt;  &lt;blockquote&gt;
		 
		   This post is an &lt;em&gt;unpublished&lt;/em&gt; review
		 
		     
		       
		         for &lt;em&gt;&lt;a href="https://dl.acm.org/doi/full/10.1145/3797487"&gt;Subscription Bombing • Email under Attack&lt;/a&gt;&lt;/em&gt;
		       
		     
		     
		   &lt;/blockquote&gt;
		 
		 &lt;p&gt;One of the most important inputs one can have when designing a response
strategy against a security attack is a good characterization. This article
describes a relatively newly described attack mode (subscription bombing),
hypothetizes on the motivations that can lie behind it, and presents some
countermeasures that can be taken by different actors to reduce its impact.&lt;/p&gt;

&lt;p&gt;At its core, suscription bombing is a classical reflection attack: it uses
a third party service so that the answer to a relatively simple request is
amplified and results in a distributed denial of service (DDoS) for the
victim. And, as with most DDoS attacks, its effectivity lies in that there
is not much a person can do against traffic coming from seemingly random
different providers all around the world.&lt;/p&gt;

&lt;p&gt;The core differentiatof for subscription bombing is that the attack’s
victim is not a network port, but an individual’s e-mail address. The
attacker builds a database of service providers that allow interested users
to sign up for newsletter on their activities, or a mailing list, or even
just to create a new account on a given Web system. This action will
generate a (seemingly legitimate) confirmation mail sent to the victim. But
the attacker scripts together hundreds of thousands of such request,
creating a deluge of confirmation mails sent to the unsuspecting victim.&lt;/p&gt;

&lt;p&gt;The authors explain the goals an attacker might pursue by performing this
kind of attack. They suppose this can be due to harassment (a disgruntled
employee being denied a salary raise, a political adversary, or even a
romantic ex-partner wanting to inconvenience the victim’s use of their
e-mail). More worryingly, the attack can be used as a distraction: by
sending a high volume of mails in a controlled timeframe, the attacker can
reduce the probability of the victim noticing a specific attack warning
them of, i.e., financial fraud, unwanted purchases, or break-in attempts
into their accounts. Attacks targetting mailboxes at private mail servers
can also lead to overloading an account’s limit, causing it to reject
mails after the attack is delivered and before the folder is cleaned. And
it can also pave the way for follow-up, targetted deception attacks, where
the attackers call the victim pretending to be the company’s IT department,
and get them to install a remote desktop monitoring and management tool,
with which they can effectively seize control of the victim’s data.&lt;/p&gt;

&lt;p&gt;To do this, they present a study they made over 24 cases of victims, from
which 47,970 total e-mails were received between October and December 2024,
with individual attacks receiving between 81 and 3,387 e-mails per hour,
from where they presented several descriptive analysis.&lt;/p&gt;

&lt;p&gt;The authors explored cyber criminal’s offers on underground websites,
comparing flooding services and pricing schemes.&lt;/p&gt;

&lt;p&gt;Finally, mitigation strategies are discussed. Mitigation is quite
problematic, as none of the mail servers is acting in either a hostile way
or lacking permissions — they are performing just the task they should. The
authors suggest four mitigation strategies for mail server operators to
reduce the burden on their users, although none of them is easily
automatizab (rate-limit the number of emails a given inbox can receive from
previously unseen senders; educate users about this kind of attacks; group
similar newsletter or account reset mails during active attacks; and
automatically unsubscribe or bounce newsletter messages when a surge is
detected). They also recommend newsletter providers and services accepting
the unrestricted creation of user accounts to provide some hardening to
increase the effort wrongdoers need to spend to abuse their services, such
as requiring CAPTCHAs or requiring users to take several steps before
requesting a subscription, although they recognize this adds friction to
the process providers are most interested in providing; filtering and
triaging known-good and known-bad domains, although this is hard to
implement on a preemptive fashion, and adhering to easy unsubscription
standards, such as easily identifiable headers with which mass
unsubscription could be performed more easily victims, instead of hunting
for the right places to click, potentially even in mails written in an
unknown language.&lt;/p&gt;

&lt;p&gt;The described problem is interesting, and properly tackling it can be a
game changer for many users who will suffer this kind of abuse, and the
article is easy to read and soundly supports its claims.&lt;/p&gt; </description> 
	<pubDate>Thu, 06 Aug 2026 00:17:35 +0000</pubDate>

</item> 
<item>
	<title>Iustin Pop: Yes-yes, still alive!</title>
	<guid>https://k1024.org/posts/2026/2026-08-05-yes-yes-still-alive/</guid>
	<link>https://k1024.org/posts/2026/2026-08-05-yes-yes-still-alive/</link>
     <description>  &lt;p&gt;I am not sure what happened, but my interests have changed significantly, and… I
haven’t blogged, I haven’t done any open source work, and didn’t even process
any pictures for the entire year. Not because anything went bad, just… new
stuff, new interests, life changes.&lt;/p&gt;
&lt;p&gt;However, still alive, and still struggling with sports, and with sleep :)&lt;/p&gt;
&lt;p&gt;On the positive side, on a recent mid-length flight, I thought — I haven’t done
any work on Corydalis, since last year I closed quite of a few of my “must have”
features, so probably, nothing else to do for now, right? I opened an editor and
started thinking about ideas, and surprised! One hour later, I had written down
enough ideas for a couple of months of work. So now just need to find the time…
but can’t wait for the planned things!&lt;/p&gt;
&lt;p&gt;Stay well!&lt;/p&gt; </description> 
	<pubDate>Wed, 05 Aug 2026 17:34:00 +0000</pubDate>

</item> 
<item>
	<title>Enrico Zini: Gnome refusing to suspend</title>
	<guid>http://www.enricozini.org/blog/2026/debian/gnome-refusing-to-suspend</guid>
	<link>http://www.enricozini.org/blog/2026/debian/gnome-refusing-to-suspend</link>
     <description>  &lt;p&gt;I'm tired, I want to do go bed. I click "sleep" on gnome shell, nothing happens.&lt;/p&gt;
&lt;p&gt;Swearwords.&lt;/p&gt;
&lt;p&gt;I want to go to bed. I might have want to put my laptop in a bag and run to
catch a train. &lt;a href="https://mastodon.bida.im/@spanezz/117017036756831405"&gt;I hate when this happens&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;systemd-inhibit --list --mode=block&lt;/code&gt; doesn't help much:&lt;/p&gt;
&lt;div class="codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class="w"&gt; &lt;/span&gt;systemd-inhibit&lt;span class="w"&gt; &lt;/span&gt;--list&lt;span class="w"&gt; &lt;/span&gt;--mode&lt;span class="o"&gt;=&lt;/span&gt;block
WHO&lt;span class="w"&gt;    &lt;/span&gt;UID&lt;span class="w"&gt;  &lt;/span&gt;USER&lt;span class="w"&gt;   &lt;/span&gt;PID&lt;span class="w"&gt;  &lt;/span&gt;COMM&lt;span class="w"&gt;            &lt;/span&gt;WHAT&lt;span class="w"&gt;                                                     &lt;/span&gt;WHY&lt;span class="w"&gt;                        &lt;/span&gt;MODE
enrico&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;1000&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;enrico&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;3042&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;gsd-power&lt;span class="w"&gt;       &lt;/span&gt;handle-lid-switch&lt;span class="w"&gt;                                        &lt;/span&gt;External&lt;span class="w"&gt; &lt;/span&gt;monitor&lt;span class="w"&gt; &lt;/span&gt;attached…&lt;span class="w"&gt; &lt;/span&gt;block
enrico&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;1000&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;enrico&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;3037&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;gsd-media-keys&lt;span class="w"&gt;  &lt;/span&gt;handle-power-key:handle-suspend-key:handle-hibernate-key&lt;span class="w"&gt; &lt;/span&gt;GNOME&lt;span class="w"&gt; &lt;/span&gt;handling&lt;span class="w"&gt; &lt;/span&gt;keypresses&lt;span class="w"&gt;  &lt;/span&gt;block
enrico&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;1000&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;enrico&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="m"&gt;2878&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;gnome-session-b&lt;span class="w"&gt; &lt;/span&gt;sleep&lt;span class="w"&gt;                                                    &lt;/span&gt;user&lt;span class="w"&gt; &lt;/span&gt;session&lt;span class="w"&gt; &lt;/span&gt;inhibited&lt;span class="w"&gt;     &lt;/span&gt;block
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;After much googling I found out about &lt;code&gt;gnome-session-inhibit&lt;/code&gt;:&lt;/p&gt;
&lt;div class="codehilite"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class="w"&gt; &lt;/span&gt;gnome-session-inhibit&lt;span class="w"&gt;  &lt;/span&gt;--list
mutter:&lt;span class="w"&gt; &lt;/span&gt;idle-inhibit&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;idle&lt;span class="o"&gt;)&lt;/span&gt;
/usr/lib/chromium/chromium:&lt;span class="w"&gt; &lt;/span&gt;Playing&lt;span class="w"&gt; &lt;/span&gt;audio&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;suspend&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Found the right tab in chromium, paused playing, sleep works again.&lt;/p&gt;
&lt;p&gt;My sleep was a good half an hour overdue, and all I got for it was to write
this blog post.&lt;/p&gt;
&lt;p&gt;Of course Gnome could have shown me its inhibitor list instead of doing
nothing, since it has that information, but &lt;a href="https://discourse.gnome.org/t/why-does-gnome-shell-doesnt-notify-user-about-suspend-being-blocked-by-inhibitor/34077"&gt;it didn't&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;What I really would expect is that if I intentionally click a suspend button,
audio and video playing wouldn't inhibit the suspend. Maybe in a future version
of Gnome?&lt;/p&gt; </description> 
	<pubDate>Wed, 05 Aug 2026 07:57:52 +0000</pubDate>

</item> 
<item>
	<title>Russell Coker: Monitors for Work</title>
	<guid>https://etbe.coker.com.au/?p=6264</guid>
	<link>https://etbe.coker.com.au/2026/08/05/monitors-for-work/</link>
     <description>  &lt;h2&gt;The Corporate Monitor Issue&lt;/h2&gt;
&lt;p&gt;Some time ago I worked in the IT department of a company that had a corporate standard of two 27″ FUllHD (either 1920*1080 or 1920*1200) monitors for the desktop. I was pushing to make the standard be one 32″ 4K monitor or the two cheaper monitors. They ended up making one 27″ 4K monitor an option which was still a better option for many users than two FullHD monitors due to having twice the pixels even though it had half the screen area. It was a surprise to me when hardly anyone took up that option.&lt;/p&gt;
&lt;p&gt;One man who worked there brought a wide curved monitor from home and ran with one of the FullHD monitors on each side of that. As an employee in the IT department I had concerns about expensive personal equipment being used in the office regarding who’s going to pay the bill if it gets broken. But I was assured that it was his old monitor that he didn’t need after buying a better one for gaming at home and he wouldn’t be too upset if something happened to it.&lt;/p&gt;
&lt;p&gt;This isn’t the only time I’ve witnessed such problems of companies paying large salaries for skilled people and providing poor equipment for them to do the work. One previous time I raised a OH&amp;amp;S issue because the outdated monitors were so blurry but the company determined that the monitors wouldn’t cause health problems and spending $150 per employee on better replacements was a waste of money.&lt;/p&gt;
&lt;p&gt;Computer hardware tends to become cheaper over time and one thing that has become really cheap recently is portable monitors. &lt;a href="https://www.kogan.com/au/buy/kogan-xpresso-156-full-hd-ips-usb-c-portable-monitor-kogan/"&gt;Kogan has a 15.6″ FullHD monitor with USB-C and mini-HDMI inputs for $89 [1]&lt;/a&gt;. It wouldn’t be difficult for someone to put one of those on each side of the monitor or monitors that their employer provides and put them in a desk drawer at the end of the day to minimise risk. The same Kogan page has a 16″ monitor with 2560*1600 resolution for $189.&lt;/p&gt;
&lt;h2&gt;Company Ownership&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/"&gt;I previously wrote about the potential benefits to companies in not owning all those keyboards, mice, and headsets when they could just give each employee the money and have them buy their own [2]&lt;/a&gt;. I don’t think we are at the stage where that can be applied to monitors as the cheapest price for a decent monitor is about $500 which takes it out of the disposable price range that keyboards and mice are in. Also from an IT support perspective there are real support issues with monitors and cables having compatibility issues. But paying small amounts of money to reimburse employees who buy cheap portable monitors to supplement their main monitor is a more reasonable option. For some people that will allow noteworthy improvements in work performance.&lt;/p&gt;
&lt;h2&gt;Who Will it Help?&lt;/h2&gt;
&lt;p&gt;I don’t think that adding such portable monitors will directly help the majority of workers. I think that to maximise performance and efficiency we need to chase the long tail of improvements. Big monitors, really big monitors (65″ at a larger distance), multiple monitors, standing desks, and whatever else people want.&lt;/p&gt;
&lt;p&gt;There was some research from Microsoft some years ago (back when 27″ was a really big monitor) showing that some tasks had a 50% increase in performance with a larger monitor. Now that 27″ is about the smallest monitor size commonly available the potential for improvement is reduced. Probably most workers now already have monitors that provide the benefits to them that the “big monitors” in Microsoft research provided. But there will always be some portion of the user base who will benefit. If you can get a 50% performance boost for 1% of the users that’s really worth doing. If you can get a 0.5% benefit for 100% of the users that is also worth doing and will theoretically give equal benefits.&lt;/p&gt;
&lt;h2&gt;Costs of Employees&lt;/h2&gt;
&lt;p&gt;It is claimed that the total cost of an employee including all overheads of management and providing office facilities etc amounts to twice their base salary. If that is the case then a minimum wage employee in Australia costs $100k per year, someone at the low end of the IT pay scale costs $200k, and someone at the high end of the IT scale is around $400k. It seems clearly worthwhile to spend $1000 in hardware purchases for a $100k employee who declares that it will really help their work, anything which is noticeable to the user is going to be more than a 1% difference in performance.&lt;/p&gt;
&lt;p&gt;For someone at the high end of the IT pay scale spending $40,000 on hardware to improve their performance could pay for itself. This is not only due to direct return on investment but because the people who do such work are often in key roles in important projects. If there’s too much work for one person on minimum wage to do then you just hire another person. You can’t hire another senior IT person and have them just do the work, it can take months to get up to speed.&lt;/p&gt;
&lt;p&gt;But as management in corporations seems unable to recognise this cheap hardware employees can afford to buy with their own money can bridge the gap.&lt;/p&gt;
&lt;h2&gt;Job Interviews&lt;/h2&gt;
&lt;p&gt;In future when interviewing for jobs I’ll ask about the hardware that’s to be used. I won’t say “I’m not interested in this job offer because you don’t respect your employees enough to buy adequate hardware”, but I may make it a condition of working at a company that the hardware on my desk will not be obsolete.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[1]&lt;a href="https://www.kogan.com/au/buy/kogan-xpresso-156-full-hd-ips-usb-c-portable-monitor-kogan/"&gt; https://tinyurl.com/26bdng24&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[2]&lt;a href="https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/"&gt; https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="yarpp yarpp-related yarpp-related-rss yarpp-template-list"&gt;

&lt;p&gt;Related posts:&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2023/06/22/cheap-peripherals-work/" rel="bookmark" title="Cheap Peripherals for Work"&gt;Cheap Peripherals for Work&lt;/a&gt; &lt;small&gt;A problem with a lot of the purchase of peripherals...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2007/01/04/monitors-for-developers/" rel="bookmark" title="monitors for developers"&gt;monitors for developers&lt;/a&gt; &lt;small&gt;Michael Davies recently blogged that all developers should have big...&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://etbe.coker.com.au/2019/11/18/4k-monitors/" rel="bookmark" title="4K Monitors"&gt;4K Monitors&lt;/a&gt; &lt;small&gt;A couple of years ago a relative who uses a...&lt;/small&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt; </description> 
	<pubDate>Tue, 04 Aug 2026 22:41:18 +0000</pubDate>

</item> 
<item>
	<title>Petter Reinholdtsen: FreeCAD MCP with llama.cpp, toy or tool?</title>
	<guid>http://www.hungry.com/~pere/blog/FreeCAD_MCP_with_llama_cpp__toy_or_tool_.html</guid>
	<link>http://www.hungry.com/~pere/blog/FreeCAD_MCP_with_llama_cpp__toy_or_tool_.html</link>
     <description>  &lt;p&gt;After seeing a video a few months ago demonstrating how a
proprietary CAM solution uses machine learning and large language
models to automatically generate CNC instructions, and successfully
testing it on a real CNC, I began wondering if the same could be
achieved with free software. I still do not know the answer, but I may
be getting closer to finding out. Two weeks ago, I came across the
video "&lt;a href="https://inv.nadeko.net/watch?v=6trAkQY5_kc"&gt;I Connected
Claude AI to FreeCAD (And It Models Parts Like an Engineer)&lt;/a&gt;" by
Make Form, which introduced me to the
&lt;a href="https://github.com/neka-nat/freecad-mcp/"&gt;FreeCAD MCP
project&lt;/a&gt;. Even though the video creator apparently believes it is
acceptable to download and run random binaries from the Internet on a
local machine (his setup uses UCX), I do not. I would probably have
left the project alone entirely if I had not noticed that all of its
dependencies are already available in Debian. This significantly
boosted my motivation, so I set out to test it using packages built
from source on Debian rather than relying on untrusted binaries.&lt;/p&gt;

&lt;p&gt;The first hurdle was that
&lt;a href="https://tracker.debian.org/pkg/python-mcp"&gt;the MCP SDK for
Python&lt;/a&gt; was not present on my Debian Forky test machine. I
initially believed it was missing from Debian altogether, but it has
been available in Debian Unstable for about a month and is only absent
from Forky because some automated tests fail on architectures like
riscv64 and s390. Fortunately, backporting it was straightforward
using `apt-get source -b python3-mcp`. The next hurdle involved an
outdated version of the
&lt;a href="https://tracker.debian.org/pkg/validators"&gt;Validators Python
library&lt;/a&gt;. Since I am a member of Debian's Python team, which
maintains this package, updating it to a sufficient version for
FreeCAD MCP was relatively easy. I could not upgrade to the latest
upstream release due to a new dependency on an Ethereum-related
library, so I settled on a 2024 version.&lt;/p&gt;

&lt;p&gt;With those dependencies in place, I proceeded to create a Debian
package for FreeCAD MCP. I had previously submitted a
&lt;a href="https://bugs.debian.org/1142447"&gt;request for packaging of
FreeCAD MCP&lt;/a&gt; to gauge interest while deciding whether to prioritize
maintaining it myself.  Because salsa.debian.org blocks access from
Tor users like myself, I published my draft packaging scripts in a Git
repository on Codeberg as the
&lt;a href="https://codeberg.org/pere/debian-freecad-mcp"&gt;Debian FreeCAD
MCP project&lt;/a&gt; and got it working with the FreeCAD 1.1 version in
Forky. I initially struggled with the button controls for the MCP
feature, which led me to submit a pull request titled
"&lt;a href="https://github.com/neka-nat/freecad-mcp/pull/106"&gt;Fixed
startup sync of checkable toolbar buttons&lt;/a&gt;" proposing a fix. Once
this confusion was resolved and the MCP setup was enabled via the GUI,
I was able to run FreeCAD completely headless using `xvfb-run` on a
machine without an X server to generate models. I am using a private
LLM service running &lt;a href="https://tracker.debian.org/llama.cpp"&gt;the
Debian package of llama.cpp&lt;/a&gt; with the Qwen 3.6 model downloaded
from Hugging Face, configured with a maximum context window of 105k
tokens. I also tested the Bonsai model on my test laptop; initially,
its context window was too small (8k and 16k could not accommodate the
FreeCAD MCP instructions), but even after increasing it to 32k, it
proved useless for generating FreeCAD models so far. I've used Claw
Code, Aider and Open Code with my server so far, and for this test I
ended up with OpenCode because it was easy to set up to use an
MCP. Because none of my LLM services are set up to be multimodal
(capable of processing both text and images in this case), I
configured the MCP to return only textual feedback from FreeCAD. I am
unsure if this is a major limitation, though I suspect it might
be.&lt;/p&gt;

&lt;p&gt;My testing experience remains limited, with no clear successes
yet. Part of the issue likely stems from my ability to provide
effective instructions for modeling 3D objects (I am relatively new to
FreeCAD, English is not my first language, and I lack a precise
vocabulary for describing construction features to an
LLM). Nevertheless, the LLM has demonstrated the capacity to create 3D
models in FreeCAD. In one of my first tests, I asked it to generate a
cube and then produce CAM/G-code instructions for a CNC machine. It
did output G-code (which remains untested), but I was surprised to
find that it bypassed FreeCAD's built-in CAM module entirely and
instead generated an external Python script to produce the code. This
was not quite what I intended, though my instructions were probably
unclear. The Qwen model with OpenCode seems to strongly prefer
programming directly; it frequently executes Python snippets inside
FreeCAD to achieve its goals rather than using the standard
sketch-and-extrude workflow I am accustomed to. In another test, I
asked the LLM to create a parameterized pipe assembly to see which of
FreeCAD's parametric tools it would choose, but found no evidence of
traditional parametric features in the output. When prompted, the LLM
explained that the parameters were embedded directly in the Python
script used to generate the model, rather than in native FreeCAD
features. With more explicit instructions, it eventually created a
FreeCAD spreadsheet to manage the parameters. The resulting model
looked much closer to my expectations and could have been useful with
further refinement. My so far last experiment was less successful: I
asked it to design a pipe clamp, but the LLM repeatedly failed to
position the clamping screws in a way that would actually secure the
brackets around the pipe. It is unclear whether this limitation lies
with the model, my prompt, or other factors.&lt;/p&gt;

&lt;p&gt;Based on my testing so far, I am uncertain whether FreeCAD MCP is
merely a fun toy or a genuinely useful tool. I will only commit time
to maintaining it in Debian if it proves to be practically valuable. I
would welcome feedback from anyone who has experience with the
project, preferably via the original request-for-packaging mailing
list thread. Alternatively, I am available in the FreeCAD and Debian
AI IRC channels for further discussion.&lt;/p&gt;

&lt;p&gt;As usual, if you use Bitcoin and wish to support my activities,
please send donations to
&lt;b&gt;&lt;a&gt;15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b&lt;/a&gt;&lt;/b&gt;.&lt;/p&gt; </description> 
	<pubDate>Tue, 04 Aug 2026 09:00:00 +0000</pubDate>

</item> 
<item>
	<title>Anuradha Weeraman: Plan 9 from Bell Labs, the little OS that could</title>
	<guid>https://weeraman.com/plan-9-from-bell-labs-the-little-os-that-could</guid>
	<link>https://weeraman.com/plan-9-from-bell-labs-the-little-os-that-could</link>
     <description>  &lt;figure&gt;&lt;img alt="Plan 9 Fourth Edition showing the rio windowing system" src="https://weeraman.com/images/plan-9-from-bell-labs-the-little-os-that-could/plan-9-rio.png" /&gt;&lt;a href="https://commons.wikimedia.org/wiki/File:Plan_9_Fourth_Edition_rio_interaction_screenshot.png" rel="noopener noreferrer" target="_blank"&gt;Screenshot by VulcanSphere via Wikimedia Commons&lt;/a&gt; · &lt;a href="https://opensource.org/license/mit" rel="noopener noreferrer" target="_blank"&gt;MIT License&lt;/a&gt;&lt;/figure&gt;&lt;div&gt;&lt;p&gt;I first heard of &lt;a href="https://p9f.org/sys/doc/9.html" rel="noopener noreferrer" target="_blank"&gt;Plan 9&lt;/a&gt; from my friend &lt;a href="https://vajra.me" rel="noopener noreferrer" target="_blank"&gt;Vajra&lt;/a&gt; in 1999 or so, as we were distro-hopping on early Linux distributions and trying to find our way. Vajra is now a Nebula Award-winning science fiction author - have a look at his work. We had just been through &lt;a href="https://en.wikipedia.org/wiki/Tomsrtbt" rel="noopener noreferrer" target="_blank"&gt;Tom's Root Boot&lt;/a&gt;, a UNIX-like operating system crammed into a single floppy, and through it discovered a whole new world outside of DOS 6.22. Combing through old UNIX manuals, we went in search of the perfect OS, through Slackware, Caldera, TurboLinux, SUSE and Red Hat. I finally settled on Debian, which lived up to everything I stood for.&lt;/p&gt;
&lt;p&gt;Plan 9 was distinct. It came out of the Computing Sciences Research Center at Bell Labs, built by Rob Pike, Ken Thompson, Dave Presotto and Phil Winterbottom, with Dennis Ritchie heading the department. The name is a joke at their own expense, borrowed from Ed Wood's 1959 &lt;em&gt;Plan 9 from Outer Space&lt;/em&gt;, routinely nominated as the worst film ever made. Thompson and Ritchie had, of course, built the original UNIX; it almost seemed as if they were building a new OS from the lessons learnt from building it - which was in turn built on the lessons from Multics. I remember the awe I felt playing around with Plan 9, and I've not been able to replicate it since.&lt;/p&gt;
&lt;p&gt;Plan 9 was different in a couple of fundamental ways: per-process namespaces, and a protocol that abstracted locality of resources to processes. As a consequence of these core primitives, the OS surface area was distinctly small. The entire system from the core kernel, to the system call interface, to the compiler, linker and shell was reduced to a form small enough that a single developer could hold it in their head. Lessons from the implementation of UNIX helped the designers make the system leaner, and in Ken Thompson's words, it's the "best operating system out except that it doesn't have the apps that everybody demands" &lt;a href="https://www.youtube.com/watch?v=EoYUZtZl02g" rel="noopener noreferrer" target="_blank"&gt;[1]&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;It also took the concept of "everything is a file" in UNIX to a whole new level. The network stack is a filesystem (&lt;code&gt;/net&lt;/code&gt;), processes are files, the display is a file (&lt;code&gt;/dev/draw&lt;/code&gt;). Because every resource speaks 9P and every process has its own namespace, you can mount another machine's &lt;code&gt;/net&lt;/code&gt; into your namespace and your program makes network calls through that machine's stack without knowing or caring. No sockets API, no RPC layer, just ordinary file system operations through a simple system call interface.&lt;/p&gt;
&lt;p&gt;Some would say that OS research is dead, and that backwards-compatibility and POSIX killed it. Rob Pike himself argued as much in his 2000 talk, "Systems Software Research is Irrelevant" - but we didn't care at the time. There was so much happening that we didn't have time to take it all in. And then Linux happened, and Software Freedom became a focal point (more on that in a later post).&lt;/p&gt;
&lt;p&gt;In the summer of 2020, with the world deep in Covid lockdowns, I decided to build a toy operating system, just to try my hand at the the thing that I had always wanted to do. I spent three feverish months working on &lt;a href="https://github.com/aweeraman/odyssey" rel="noopener noreferrer" target="_blank"&gt;Odyssey&lt;/a&gt; and, looking back, it is perhaps the most fun I have ever had. I would not dare compare it to the magnum opus that is Plan 9, but it gave me perspective: how hard it is to build an OS from scratch, and above all, how &lt;em&gt;fun&lt;/em&gt; it is to build an OS from scratch, and why the original creators kept coming back to the same problem. The highlight of those three months was booting the OS and watching it render "The Great Wave off Kanagawa". Nothing in my professional achievements to date captures what that meant to me.&lt;/p&gt;
&lt;figure&gt;
  &lt;source type="image/avif" /&gt;&lt;source type="image/webp" /&gt;&lt;source /&gt;&lt;img alt="Odyssey rendering The Great Wave off Kanagawa during boot" class="max-w-full h-auto" src="https://weeraman.com/images/plan-9-from-bell-labs-the-little-os-that-could/odyssey-splash.png" /&gt;
  Odyssey displaying "The Great Wave Off Kanagawa"
&lt;/figure&gt;
&lt;p&gt;Decades on from the first time I booted Plan 9, I look back with nothing but awe and respect for the creators of this little operating system and marvel at the foresight that went into it. While many readers will not have heard of Plan 9, they have almost certainly worked with the ideas that came from it: 9P (if you ever used the Windows Subsystem for Linux), UTF-8 (if you ever used any modern operating system), per-process namespaces (if you've ever run a container), Go (whose assembler still uses Plan 9 syntax).&lt;/p&gt;
&lt;p&gt;Plan 9 still lives on in &lt;a href="https://9front.org/" rel="noopener noreferrer" target="_blank"&gt;9front&lt;/a&gt;, a community-maintained fork. Separately, Yoann Padioleau &lt;a href="https://www.youtube.com/watch?v=blVTDhr4QN8" rel="noopener noreferrer" target="_blank"&gt;[2]&lt;/a&gt; has produced a set of annotated books at &lt;a href="https://principia-softwarica.org/" rel="noopener noreferrer" target="_blank"&gt;principia-softwarica.org&lt;/a&gt;, presenting the Plan 9 source in the spirit of Donald Knuth's literate programming - an admirable effort to introduce new readers to the art of operating systems engineering.&lt;/p&gt;
&lt;p&gt;Pike thought systems research had become irrelevant, and Thompson thought Plan 9 would never "make it" &lt;a href="https://www.youtube.com/watch?v=EoYUZtZl02g" rel="noopener noreferrer" target="_blank"&gt;[1]&lt;/a&gt;. Both were right about the industry, but may have been pessimistic about the impact. The system lost as a product but won as a set of ideas, assimilated one at a time by modern operating systems. Success is not always measured by popularity. The mark that Plan 9 left behind is greater than what's reflected in its current user base.&lt;/p&gt;
&lt;p&gt;To me, Plan 9 will always be the OS that punched above its weight class, the little OS that could.&lt;/p&gt;
&lt;h2&gt;References&lt;/h2&gt;
&lt;p&gt;[1] &lt;a href="https://www.youtube.com/watch?v=EoYUZtZl02g" rel="noopener noreferrer" target="_blank"&gt;Ken Thompson Interview, March 6, 2024&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[2] &lt;a href="https://www.youtube.com/watch?v=blVTDhr4QN8" rel="noopener noreferrer" target="_blank"&gt;Yoann Padioleau — Principia Softwarica, May 9, 2026&lt;/a&gt;&lt;/p&gt;&lt;/div&gt; </description> 
	<pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>

</item> 
</channel>
</rss>