- β
- β
- October 08, 2026
-
π peterh/liner v1.2.3 release
cleanup: modernize with
go fix
-
- October 07, 2026
-
π smol-machines/smolvm smolvm v1.24.2 release
What's Changed
- Stop the serve shutdown tests only once the request is running by @BinSquare in #1604
- Report nested virtualization in /health by @BinSquare in #1605
- Trust a machine's credential CA when pulling images, and stop silently dropping credentials on ephemeral .smolmachine runs by @BinSquare in #1603
- Keep a machine without networking offline when it publishes a port, serving inbound connections only by @BinSquare in #1606
- Bump version to 1.24.2 by @BinSquare in #1607
Full Changelog :
v1.24.1...v1.24.2 -
π backnotprop/plannotator v0.28.8 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.7 | Ask this session keeps your drafts as drafts, image comments survive a reload, hostname check on every server
v0.28.6 | Ask AI names the lines you selected, reorder quick labels and edit their emoji, Pi fixed-port crash fixed, OpenCode 2 subagent notice fixed
v0.28.5 | Several files in one review, theplannotatortool on Pi and OpenCode 2, decisions name the exact file, Ask this session reconnects after sleep
v0.28.4 | Comments come back after the agent edits a file, the agent can list and close its reviews, PR-description feedback no longer dropped, Pi thinking levels
v0.28.3 | Typing into your agent while it answers an Ask no longer streams into Plannotator
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktreeWhat's New in v0.28.8
This release brings the Plannotator Inbox (preview): one local window where your agents leave you messages, questions, files and guided reviews, and where your reply goes back to the session that asked.
The Plannotator Inbox (preview)
Agents often need you for one thing: a choice, a check, a look at a file. Until now that meant a review tab per question, or a question buried in the terminal. The Inbox collects all of it in one window on your machine:
- Threads by project. Each agent conversation is a row, grouped in sections: Stopped on you, Holding up work, Waiting on you, Sent, New since you looked, and Quiet. Filter by project in the sidebar.
- Questions you answer with a click. Agents ask with the same
:::questioncards plan review uses. Pick, add a note, press Send. - Files and annotations. Files an agent attached open beside the thread (markdown, text, HTML, Mermaid, Graphviz). Annotate them as in Plannotator; the annotations go with your reply. If the agent changed a file after sending it, the Inbox says so and can show the version it sent.
- Decisions. A question can record your answer as a project decision, listed on a Decisions page.
- Guided reviews. An agent can send a guided review of a code change into a thread.
- New message. Write to an agent session that is running now, without waiting for it to ask.
- Browser notifications while the tab is in the background, if you allow them.
Your reply wakes the agent that asked. Claude Code (with the Plannotator mod) gets a
plannotator_inboxtool, on by default. Pi and OpenCode 2 get the same tool, off by default because they send every tool's definition with each request: turn it on withPLANNOTATOR_INBOX_TOOL=1. Any other agent can connect through MCP withplannotator inbox mcp; the Inbox's Settings show the exact command for your agent.It is local only: it listens on
127.0.0.1, needs no account, and keeps everything under~/.plannotator/inbox. Start it with:plannotator inboxYou never have to keep it running: an agent starts it in the background when it needs it, without opening a tab.
plannotator uninstall --purgeremoves its data. Full reference: plannotator.ai/docs/reference/inbox.Additional Changes
- Question cards for host apps.
@plannotator/ui0.52.1 can show the "Records a decision" switch on any question and open a host's own decision card from it. Plannotator's own cards are unchanged (#1753).
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- The Plannotator Inbox, built across #1745, #1752, #1755, #1756, #1757, #1758, #1759, #1760, #1761, #1763, #1764, #1766, #1767, #1768 and #1769 by @backnotprop
- ui: decision toggle on any question, and a separate opener for the host's decision card by @backnotprop in #1753
Full Changelog :
v0.28.7...v0.28.8 -
π earendil-works/pi v1.1.0 release
New Features
- Program status reporting : terminals and agent dashboards that support OSC 7501 see whether Pi is working, blocked on a dialog or login, done, or failed. See Program status.
- Claude Haiku 5.5 :
anthropic/claude-haiku-5-5, with adaptive thinking up toxhigh/maxeffort. - Adjust default tools with
+name/-name:--toolsentries likepi -t +codemode,-writechange the default selection instead of replacing it. See Tools. - GPT-6 Luna and image classification : OpenAI's GPT-6 Luna is available as a classifier model through the Decisions API, and codemode's
models.classify()accepts images for classifiers that support them. See Use classifier models. - Native llama.cpp decision models : Julia-1, Laya, Kev, lev, and OpenJev served by llama.cpp 0.6.0 or later run natively as classifiers through
/v1/systemone. See Classification.
Added
- Added
+nameand-nameentries to--tools, which change the default tool selection instead of replacing it, for examplepi -t +codemode - Added
durationMsto the tool render context and totool_execution_endextension events: the recorded execution time of a final tool result (#10549) - Added
outputPadto the tool render context (#10557 by @rwachtler) - Added OpenAI's GPT-6 Luna as a classifier model through the Decisions API, available with
OPENAI_API_KEY(see Use classifier models) - Added
imagesto codemode'smodels.classify()context, so classifiers that accept images, such as GPT-6 Luna, can judge them - Added program status reporting with OSC 7501: terminals and agent dashboards that support it see whether Pi is working, blocked on a dialog or login, done, or failed.
PI_PROGRAM_STATUS=1|0overrides detection (see Terminal setup) (#10607) - Added
abortedtoagent_settledsession, extension, and JSON events, so integrations can tell a cancelled run from a finished one (#10607) - Added Claude Haiku 5.5 (
anthropic/claude-haiku-5-5), with adaptive thinking up toxhigh/maxeffort and prompt caching on Bedrock - Added native llama.cpp decision models: Julia-1, Laya, Kev, lev, and OpenJev served by llama.cpp 0.6.0 or later are listed only as classifiers through
/v1/systemoneinstead of as chat models (see Classification) (#10382)
Changed
- Changed
outputPadto also apply to!command output, tool output, and summary blocks (#9946, #10557 by @rwachtler) - Changed
pi mcp login --timeoutto limit the whole sign-in, including requests to the authorization server, instead of only the wait for the browser (#10565)
Fixed
- Fixed bash and PowerShell results losing
Tookafter reloading a session, and the liveTookincluding wall-clock steps; both now show the recorded execution time (#10549) - Fixed managed installs keeping every old release;
pi updatenow keeps only the new release and the one it updated from (#10392, #10511 by @davidbrai) - Fixed standalone binaries loading
.env,.env.local, and.env.developmentfrom the launch directory into Pi's environment (#10473) - Fixed
!!command headers losing their dim color once output arrives (#10557 by @rwachtler) - Fixed the codemode description not marking
searchTools(),describeTool(), anddescribeNamespace()as async, which led models to serialize the unawaited promise as{}(#10555) - Fixed codemode output items running together, so models could not tell where one
text()orconsole.log()output ended and the next began. With several text items, each now starts with a==> text N/M <==line, andconsolecalls follow the other output in one<console_output>block with one line per call - Fixed
/mcpwaiting for all servers to connect before opening; the manager now updates live and remains usable while enabling, reconnecting, or disabling servers (#10562) - Fixed images being dropped as "could not be resized" when running under
node --watchon Node 24.19+ and 26.x, where Node posts its own messages on the image resize worker channel (#10527) - Fixed clipboard paste doing nothing in Termux, and failed copies there omitting the Termux:API install hint (#10391)
- Fixed
!and RPCbashoutput keeping fragments of color codes, such as a straym, when a code was split across output chunks (#10504) - Fixed MCP OAuth sign-ins that could not be cancelled while waiting on the authorization server and kept running after the session ended. The sign-in screen now cancels with Esc at every step, session shutdown aborts a running sign-in, and each request to the authorization server times out after 15 seconds (#10565)
- Fixed shutdown waiting up to 15 seconds to refresh an MCP OAuth token that was about to expire, only to close the server's session (#10565)
- Fixed the fullscreen text selection surviving session switches and other transcript rebuilds, which highlighted unrelated text in the new transcript (#9311, #10567 by @christianklotz)
- Fixed OpenAI models on Bedrock ignoring the thinking level and always running at Bedrock's default reasoning effort (#9331, #10142 by @jsanter27)
- Fixed model
headersinmodels.jsonnot overriding theoriginatorandUser-Agentheaders of Codex requests (#10429 by @lucasmeijer) - Fixed
server_busyandservers are currently busyprovider errors ending the turn instead of being retried (#10543) - Fixed Mistral responses that end with
finish_reason: "error"not being retried (#10487) - Reduced context-limit request failures by estimating input at 3.5 characters per token instead of 4 when calculating output limits (#10497)
- Fixed Radius models disabled by an organization owner still being listed
- Fixed Anthropic browser login failing with "localhost refused to connect" when port 53692 is reserved or in use, for example by Hyper-V/WSL port exclusions on Windows: login now falls back to a free loopback port (#10571)
- Fixed session costs undercounting long prompts on models with prompt-length pricing tiers, such as Claude Haiku 5.5, Gemini 3.1 Pro, and GPT-5.4, through OpenCode, OpenCode Go, OpenRouter, Vercel AI Gateway, Google, MiniMax, and other providers
- Fixed Markdown links not being clickable in Herdr (#10573)
-
π jj-vcs/jj v0.46.0 release
About
jj is a Git-compatible version control system that is both simple and powerful. See
the installation instructions to get started.Release highlights
- Jujutsu can now colocate workspaces besides the default one by creating Git
worktrees. Usejj workspace add --[no-]colocateand the setting
git.colocateto control this.
Breaking changes
-
The minimum supported
gitcommand version is now 2.42.0, up from 2.41.0.
jj workspace addusesgit worktree add --orphan, which was added in
2.42.0. -
The minimum supported Rust version (MSRV) is now 1.97.1.
-
jj bisect runnow runs some consistency checks before proceeding to bisect.
This helps ensure that the command can tell good and bad revisions apart,
and that the working copy does go from bad to good over the provided revset.
Use the new flag--trust-endpointsto disable these checks. -
jj splitnow opens a single editor session to edit descriptions for the
split commits. -
jj undoandjj redonow refuse to undo/redo an operation that was
performed in another workspace. Use--allow-cross-workspaceto undo/redo
it anyway. -
jj workspace list/rootno longer omit unreachable paths. All recorded
paths are now shown, with warnings displayed injj workspace root. -
The
List.get(),.first(), and.last()template functions now return
Option<T>instead of throwing an error on out-of-bounds access.
New features
-
jj workspace addsupports--colocate/--no-colocateflags to control
whether a Git worktree is created alongside the workspace. The default
colocates when the current workspace is colocated and thegit.colocate
config istrue.jj workspace forgetremoves the corresponding Git
worktree when one exists. -
jj git colocation status/enable/disablenow work on child
workspaces.statuscorrectly reports colocation state and includes
the workspace name.enablecreates a Git worktree anddisable
removes it, allowing colocation to be toggled after workspace
creation. -
jj workspace removeremoves a workspace and its directory from disk. The
working-copy state is snapshotted into a commit before removal. -
Added commands
jj file editandjj file deletefor editing files in any
revision without needing to change the working copy. -
jj git pushnow supports pushing to multiple remotes at the same time.
This can be configured viagit.pushset to a string pattern
or array of string patterns, or with the repeatable--remoteflag,
which also accepts string patterns. -
The default target revisions for
jj git pushcan now be configured via
revsets.git-push. -
Added the
TreeEntry.normal_value()template method and theTreeValuetype
to access resolved tree values, formatted as their full object IDs, including
Git submodule commit IDs. -
Diff hunk headers now include nearby source symbols for many common
programming and markup languages. -
fix.tools.<name>.line-range-args(replacesline-range-arg) is an array of
string template args to pass to the fix tool. This is more flexible in cases
where you need to pass multiple arguments to the tool, such as separate args
for the range start and range end. -
jj runnow uses the sparse patterns from the workspace it's run from.
Use the--sparse-patternsoption to control this behavior (evaluated
per eachjj runinvocation). -
jj util diff <path1> <path2>to compare files on disk. -
Aliases now support setting
aliases.<name>.enabled = false, which will
disable them. This can be used to disable built-in aliases or disable aliases
in later layers (such as repo config files). -
ui.editornow supports$pathand$linesubstitution variables. Example:
ui.editor = ["emacs", "+$line", "$path"] -
filltemplate function now supports an additional named parameter
break_words, that allows specifying if the template should break words
longer thanwidthpassed in the input to ensure no words overflow the
specified width. -
The
json()template function now supports map literals:json({'key' => value}) -
The hunk headers of
diff.color-words.conflict = "pair"now include the
conflict labels of the compared terms.
Fixed bugs
-
On Windows,
jjno longer hangs when a subprocess needs to prompt the user,
such assshasking for a key passphrase or for confirmation of an unknown
host key. Subprocesses started from a terminal now inherit its console, rather
than being given an invisible one byCREATE_NO_WINDOWfor the prompt to
disappear into.
#6745
#8547 -
On Windows,
jj git colocation enableandjj git colocation disableno
longer fail with "Access is denied (os error 5)" when the Git repository
contains pack files.
#8661 -
jj undoofjj workspace forgetnow correctly preserves the workspace's
recorded path. Previously the path metadata was lost, leaving the workspace
in a broken state after undo.
#9991 -
at_operation()can now be used with operations that are not ancestors of
the current operation (e.g. sibling operations created by concurrent
commands). Previously, evaluating such expressions failed if they resolved
to commits missing from the current operation's index. -
.gitignorefiles are now respected even if they aren't materialized in the
working copy because they are excluded by the sparse patterns. Previously,
ignored files could become tracked in a sparse working copy.
#2289 -
In-tree ignore files (
.gitignore) are no longer read through symlinks,
matchinggitbehavior. Such files are now silently skipped instead of having
their symlink target applied.$GIT_DIR/info/excludeandcore.excludesFile
are unaffected and still follow symlinks, asgitdoes.
#7161 -
jj workspace listtemplates are now labeled withworkspace name,
workspace root, etc.
Contributors
Thanks to the people who made this release happen!
- Aaron Bies (@slerpyyy)
- Austin Seipp (@thoughtpolice)
- Bartok9 (@Bartok9)
- Brice Figureau (@masterzen)
- Bryan O'Sullivan (@bos)
- Caleb White (@calebdw)
- David Rieber (@drieber)
- Farid Zakaria (@fzakaria)
- Gabriel Goller (@kaffarell)
- Gasper Stukelj (@mirkomartn)
- Jakub Stasiak (@jstasiak)
- JamBalaya56562 (@JamBalaya56562)
- Joseph Lou (@josephlou5)
- Karnajeet Gosavi (@kg290)
- LOG (@logarithmone1128)
- Martin von Zweigbergk (@martinvonz)
- Matt Stark (@matts1)
- Mustafa Officewala (@genericusername2709)
- pederbe (@pederbe)
- Philip Metzger (@PhilipMetzger)
- Pro (@twistedfall)
- Remo Senekowitsch (@senekor)
- Sami Hiltunen (@SamiHiltunen)
- sofia (@badp)
- Stephen Jennings (@jennings)
- Vincent Ging Ho Yim (@cenviity)
- xtqqczze (@xtqqczze)
- Yannik Sander (@ysndr)
- Yuya Nishihara (@yuja)
- Jujutsu can now colocate workspaces besides the default one by creating Git
-
π smol-machines/smolvm smolvm v1.24.1 release
What's Changed
- Bump the Nix package to 1.24.0 by @BinSquare in #1592
- Cache disks: a shared read-only base under each machine's own copy-on-write layer by @BinSquare in #1594
- Let the newest package publish replace an older one instead of queueing behind it by @BinSquare in #1593
- Ride out saturated worker disks, add deferred disk durability, and attach and publish cache disks over the API by @BinSquare in #1596
- Send console logs a read at a time instead of a write per line, read a full log to its end, and update h2 to 0.4.20 by @BinSquare in #1597
- Checkpoint a restored machine as a delta of the checkpoint it was restored from by @BinSquare in #1562
- Export the agent rootfs and packed layers read-only by @JanPokorny in #1599
- Branch concurrent requests from a running source in one batch by @BinSquare in #1600
- Bump version to 1.24.1 by @BinSquare in #1598
New Contributors
- @JanPokorny made their first contribution in #1599
Full Changelog :
v1.24.0...v1.24.1 -
π Simon Willison Claude Haiku 5.5 rss
As previously promised, here's Anthropic's new fast, low cost model: Introducing Claude Haiku 5.5.
The previous Haiku, 4.5, was very much showing its age. It came out almost a year ago, and was priced at $1/million input and $5/million output - relatively expensive even back then, and a full 10x the price of OpenAI's GPT-6 Luna, released last month.
The new Haiku exactly matches the price of GPT-6 Luna - $0.10/$0.50 - up to 100,000 tokens. Beyond 100,000 tokens the price increases 5x to $0.50/$2.50. Luna itself has a price increase at 272,000 tokens but only to $0.20/$0.75.
Haiku 5.5 also uses a new, less generous tokenizer. My Claude Token Counter tool shows that the same long prompt uses around 1.25x as many tokens with Haiku 5.5 compared to Haiku 4.5, so there's a hidden price increase there.
If your workloads fit in 100,000 tokens, Haiku is the same price as Luna and reports higher benchmark scores. Above 100,000 tokens, Luna looks like a much better deal.
The most recent release of llm-anthropic finally fixed it so I don't need to ship a new version of that plugin for every new model. I tested the new model like this:
llm install -U llm-anthropic llm anthropic refresh llm -m claude-haiku-5.5 "Generate an SVG of a pelican riding a bicycle" -o thinking_effort lowPelicans
Here are pelicans for low, medium, high, xhigh, and max. The new Haiku doesn't let you disable reasoning, and defaults to
medium. I got a good bicycle frame for everything beyondlow. The low effort pelican cost 0.0936 cents and took 7 seconds.This
maxeffort pelican (with a reasoning trace that starts "This is the classic pelican-on-bicycle SVG test...") took 5 minutes 9 seconds to generate, but still only cost me 3.3826 cents:
(Since the reasoning trace exhibits awareness of the benchmark, here's Generate an SVG of an armadillo in fishnet tights jaywalking on Mars (on xhigh), and the same prompt against some other recent models. Background on that.)
For comparison, here's the pelican I got a year ago from Haiku 4.5 (for 0.7583 cents - Haiku 4.5 did not support reasoning levels). It sucked at drawing pelicans:

And a generous API credit scheme for subscribers
In addition to Haiku 5.5, Anthropic announced today that they are halving the price of cache reads for Sonnet 5.5. They've also added API credits to subscription plans:
Second, this week, weβll roll out a new monthly API credit to all Max and Team subscribers for use on the Claude Platform. Max 5x users will get $100 in credits per month, Max 20x users will get $200, and Team subscribers will receive up to $500, pooled across their users.
Claiming this is pleasantly easy: navigate to Settings -> Billing and select the API organization that should benefit from the credits every month:

The API credits exactly match the cost of the subscription itself. This is really generous - it makes it much easier for subscribers to use the API. Anthropic also let you disable auto-reload for the API, with the consequence that "API requests will stop when your balance runs out" - exactly what you want if you're planning to burn through those API credits without risk of a nasty billing surprise.
Note that the monthly credits do not roll over - use them or lose them.
OpenAI still allow you to use your Codex subscription for personal API use, which works out as a better deal for heavy API users. This new credit scheme goes at least some way to overcoming that difference.
You are only seeing the long-form articles from my blog. Subscribe to /atom/everything/ to get all of my posts, or take a look at my other subscription options.
-
π r/LocalLLaMA llama.cpp on the stage rss
| https://x.com/ggerganov/status/2107908265032229261 submitted by /u/jacek2023
[link] [comments]
---|--- -
π exe.dev Crossing the Hyper-Thread Boundary rss
Modern processors have multiple CPU cores, and the physical CPU cores in turn have two logical CPU cores. The latter permit the physical core to run two independent programs simultaneously, an approach known as hyper- threading. Hyper-threading uses CPU resources more efficiently, but it exposes transient execution vulnerabilities, in which a program running on one hyper-thread is able to extract data from the program running on the other hyper-thread. An example of such an attack is MDS.
exe.dev runs virtual machines on behalf of different users. We need to protect against the possibility of one user exploiting a vulnerability to extract data from another user running on a different hyper- thread of the same CPU core. Fortunately the Linux kernel supports core scheduling cookies to control which processes are permitted to share a CPU core.
It is straightforward to give each VM an independent cookie, meaning that two different VMs never run on the same CPU core. However, in practice this leads to measurably inefficient use of physical CPU cores. So we instead implemented a more efficient, but still secure, mechanism: the VMs of each team use an independent cookie. This means that two different VMs from a different team (or from a different user for users not on teams) never run on the same CPU core. To put it another way, we assume that different members of the same team trust each other.
Of course, for various reasons, some teams do not have trust among all their VMs. An admin of those teams can run
ssh exe.dev team settings core-sharing offto prevent their VMs from sharing CPU cores. (Currently VMs that do not belong to a team never share cores with other VMs, even VMs from the same user; if that changes someday we will introduce a similar setting for individuals.) -
π backnotprop/plannotator v0.28.7 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.6 | Ask AI names the lines you selected, reorder quick labels and edit their emoji, Pi fixed-port crash fixed, OpenCode 2 subagent notice fixed
v0.28.5 | Several files in one review, theplannotatortool on Pi and OpenCode 2, decisions name the exact file, Ask this session reconnects after sleep
v0.28.4 | Comments come back after the agent edits a file, the agent can list and close its reviews, PR-description feedback no longer dropped, Pi thinking levels
v0.28.3 | Typing into your agent while it answers an Ask no longer streams into Plannotator
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest planWhat's New in v0.28.7
Seven PRs, two from community contributors, one of them a first-time contributor. The main fix stops Ask this session from handing your unsubmitted comments to the agent as instructions. Other changes: comments on images survive a reload, other plugins' commands no longer carry Plannotator's name, and every Plannotator server now checks the hostname it was reached by.
Ask this session keeps your drafts as drafts
When you asked a question through "Ask this session", Plannotator also sent the comments you had not submitted yet, in the same format as submitted feedback. The agent read them as instructions and could act on them before you pressed Submit. In the report, it created GitHub issues from draft comments. On Submit, the same comments then arrived a second time.
Draft comments are now sent once, as a short list clearly marked as drafts you have not submitted, with an instruction not to act on them. Your question always comes last. The list goes again only when it changes. Submit delivers your feedback once, as before. This applies on Claude Code, Pi and OpenCode, and to the annotate agent terminal. The separate Ask AI providers are unchanged. (#1749, closing #1748, reported by @krizman)
Comments on images come back after a reload
In HTML annotate, a pin on an image, video or embedded page that had no
iddisappeared after a reload or an HTML refresh, which made image comments in generated reports hard to keep. Such pins are now found again by the file they show. A pin follows its image when other images are added around it. If the image's source changes, the pin shows as no longer matching. If the same source appears twice, the pin is not saved, so it can never land on the wrong copy. Live-app sessions behave the same way. (#1747 by @pro- vi)Other plugins' commands no longer carry Plannotator's name
With the Plannotator mod on, Claude Code labelled the output of any other plugin's slash command as if Plannotator had helped answer it (for example
plannotator+frontend: β¦). The mod now listens only to its own commands./plannotator-review,/plannotator-annotateand/plannotator-lastwork as before, with or without the Plannotator skills installed. (#1741 by @rushelex, closing #1740)Every server checks the hostname it was reached by
Plannotator's review servers now refuse requests that arrive under an unexpected hostname. A normal local session accepts only
localhostand loopback addresses. Remote mode also accepts IP addresses, your configuredPLANNOTATOR_URL_HOSTand the machine's own name (includingname.local).--tailscalesessions accept their tailnet name, and code-server and Coder proxies are recognised fromVSCODE_PROXY_URI. VS Code, SSH and Docker port forwarding, Codespaces and dev tunnels keep working as before.If you reach a remote-mode session by another DNS name (a server's public name, for example), you now get a 403 that says what to do: set
PLANNOTATOR_URL_HOST, or list the name in the newPLANNOTATOR_ALLOWED_HOSTS(comma-separated;*turns the check off). (#1742)Additional Changes
- OpenCode 2: extra words no longer stop annotate.
/plannotator-annotate . notes.md(orplease notes.md) opened nothing and showed nothing. It now opens the file, and a slash command that fails shows the reason in the session instead of only in OpenCode's log. On OpenCode 1 this applies when the plugin uses the CLI runtime; the default embedded runtime is unchanged (#1739). - Question cards for host apps.
@plannotator/ui0.52.0 lets an app embedding the question cards turn "Records a decision" on and off from the card's header and hide the card's own status tag. Plannotator's own cards are unchanged (#1744).
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- Ask this session: unsubmitted annotations are never sent as feedback by @backnotprop in #1749
- fix(annotate): pins on images without an id restore by their source by @pro-vi in #1747
- fix(mod): match command.run by command name by @rushelex in #1741
- Validate the Host header on every request (defense in depth) by @backnotprop in #1742
- OpenCode 2: /plannotator-annotate with extra words opens the file, and failures are shown by @backnotprop in #1739
- ui: host-controlled decision toggle and status tag on question cards by @backnotprop in #1744
- Groundwork for a feature that is not released yet, hidden from help and the agent skill, by @backnotprop in #1745 and #1750
New Contributors
Contributors
@pro-vi found that comments on images without an id were lost on every reload, and wrote the fix that finds them again by their source. @rushelex reported the
+plannotatorlabel on other plugins' commands and fixed it with a one-line matcher. It is their second contribution, after the VS Code clipboard fix in #970.Community:
- @krizman reported the Ask this session draft problem with exact steps, the text the agent received, and the likely cause (#1748).
Full Changelog :
v0.28.6...v0.28.7 - OpenCode 2: extra words no longer stop annotate.
-
π backnotprop/plannotator v0.28.6 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.5 | Several files in one review, theplannotatortool on Pi and OpenCode 2, decisions name the exact file, Ask this session reconnects after sleep
v0.28.4 | Comments come back after the agent edits a file, the agent can list and close its reviews, PR-description feedback no longer dropped, Pi thinking levels
v0.28.3 | Typing into your agent while it answers an Ask no longer streams into Plannotator
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixesWhat's New in v0.28.6
Six PRs, two of them asked for by the community. This is a fix release: Ask AI tells the agent which lines you selected, quick labels can be reordered and given a new emoji, and a few problems found while testing 0.28.5 on Pi and OpenCode are fixed.
Ask AI says which lines you selected
When you select text in a markdown document and ask a question, the question now names the lines, for example
Source: /path/to/doc.md, line 41, orlines 41β44when the selection spans several lines or blocks. Before, it carried only the file path, so when the same phrase appeared twice the agent could not tell which one you meant. The line numbers are the same ones the exported comment for that selection prints, so the question and your feedback point at the same place. This works in plan review and annotate, including linked documents and folder sessions, and through the side chat, Ask this session and the annotate agent terminal. (#1732, closing #1731, requested by @de-tre)Reorder quick labels and change their emoji
Settings β Labels now has Move up and Move down buttons on each quick label, and the emoji is an editable field. The list order decides which Alt/β₯ number applies a label, and the key hint on every row updates as you move things. The emoji field takes exactly one emoji (flags, skin tones and combined emoji included); anything else is shown as invalid and never saved. Two labels with the same text no longer get mixed up when you edit one of them. Your saved labels keep the same format, so nothing needs migrating. (#1738, closing #1736, requested by @RobertoArtiles)
Pi no longer crashes when a fixed port is busy
With
PLANNOTATOR_PORTset in a local Pi session, opening a second/plannotator-annotatewhile one was already open killed Pi withEADDRINUSE. The new review now takes the port over from the old one, as remote mode already did, and Pi stays up. (#1733)OpenCode 2: a review opened by a background subagent no longer adds a
stray turn
With the
plannotatortool turned on, a background subagent that opened a review posted its "session ready" link into the main session while it was idle. The next time the main session woke up, the model answered that link line as its own turn, and the exchange stayed in every later request. The link now goes to the session that called the tool, while that call is still open, so it never becomes a turn of its own. Decisions were always delivered correctly and still go to the main session. (#1734)Additional Changes
- Review names match what opened. On Claude Code,
/plannotator-annotate . a.mdopens onlya.md, but the mod named the review "2 files: ., a.md" in its reply, status line and decision. Reviews are now named from what the CLI actually opened, on Claude Code and for OpenCode 2's tool (#1737). - Contributors' OpenCode setup left alone. Running
bun installin a Plannotator checkout overwrote the developer's own OpenCode commands and skill. The OpenCode plugin's install step now copies them only when the package is installed undernode_modules, and it works on Windows. SetPLANNOTATOR_OPENCODE_POSTINSTALL=1or0to force it either way (#1735).
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- Ask AI: name a text selection's source lines in the question by @backnotprop in #1732
- Settings β Labels: reorder quick labels and edit their emoji by @backnotprop in #1738
- fix(pi): attach the annotate agent terminal after listen so a busy fixed port cannot crash Pi by @backnotprop in #1733
- fix(opencode): a tool launch's session-URL notice never wakes an idle root by @backnotprop in #1734
- fix(mod, opencode): name a review by what the CLI opened, not the typed words by @backnotprop in #1737
- fix(opencode): skip the plugin postinstall inside the monorepo (cross-platform) by @backnotprop in #1735
Community
- @de-tre asked for the selected lines to be included in Ask AI questions, so the agent knows which occurrence of a phrase they meant (#1731).
- @RobertoArtiles asked for a way to reorder quick labels and change their emoji (#1736).
Full Changelog :
v0.28.5...v0.28.6 - Review names match what opened. On Claude Code,
-
π r/LocalLLaMA New LFM to be released today rss
| https://x.com/ramin_m_h/status/2107780594264600801 What size do you want? https://huggingface.co/LiquidAI submitted by /u/jacek2023
[link] [comments]
---|--- -
π smol-machines/smolvm smolvm v1.24.0 release
What's Changed
- Fall back to a synchronous save for a stored checkpoint the VMM cannot defer by @LoganGrasby in #1584
- Pin a fork's golden layers on pause instead of packing them into every artifact by @LoganGrasby in #1585
- Rebuild the image seeds machines used recently when a server starts, so the first machine of each image after an upgrade does not wait for a seed build by @BinSquare in #1586
- Fix private CA registry pulls and image seeds by @BinSquare in #1587
- Wake TCP relay threads on readiness instead of polling every 10 ms by @BinSquare in #1588
- Let exec/interactive take an argument vector and run on pipes by @adam-r-kowalski in #1538
- Refuse pinned branch ports on a machine that publishes none by @BinSquare in #1589
- Let the embedded runtime keep a branch's source frozen as a reusable branch base by @BinSquare in #1590
- Bump version to 1.24.0 by @BinSquare in #1591
New Contributors
- @adam-r-kowalski made their first contribution in #1538
Full Changelog :
v1.23.7...v1.24.0 -
π matklad On Git Refs rss
On Git Refs
Oct 7, 2026
I have recently improved my mental model of Git. Consider these two git commands:
$ git fetch origin master $ git switch -c my-feature origin/masterDo you understand why is it
origin masterin one command, andorigin/masterin the other? I didnβt, until a few weeks ago!My understanding was that git is a content-addressable database. Git stores commits, a commit is identified by the hash of its content, and the content of a commit is, primarily:
- a memory-less snapshot of a state of the codebase at a given point in time,
- a list of (hashes of) parent commits.
That was enough git for me to understand
git logoutput and get me out of any botched rebase without having to re-clone the repo (For roughly half of my career, I was re-cloning the repo. No shame in that! Learning git is useful, but itβs not the highest priority thing to learn when you start).
I now understand that git not only comes with an append-only (βimmutableβ) content-addressable database, but is also a boring mutable key-value store.
Git has a mutable map whose keys are strings, and whose values are content- addressed objects. The keys are conventionally formatted as file system paths, and you can usually inspect the state of the mapping by listing
.git/refsdirectory:$ eza -T .git/refs .git/refs βββ heads β βββ make β βββ master β βββ my-feature β βββ pbd-adt βββ origin βββ remotes β βββ origin β βββ context-switches β βββ gh-pages β βββ HEAD β βββ make β βββ master βββ tags $ cat .git/refs/heads/master b59148228e52f7c615ead7fdd4e91001994ad50f $ git show-ref refs/heads/master b59148228e52f7c615ead7fdd4e91001994ad50f refs/heads/masterWhat makes this
refsKV infrastructure confusing is that:- It powers many distinct user-visible git features, but refs themselves are an implementation detail.
- It is a bit of a leaky abstraction, refs are almost invisible in the day-to-day usage.
- Git CLI uses shorthand notation for refs and many default arguments, which makes it not obvious that a particular CLI argument is a ref.
- And, as usual, git likes to give several names to one thing, and re-uses the same name for distinct things.
Branches, tags, and git notes are all just refs!
The structure becomes much more obvious once you elaborate all CLI shortcuts. The original command
$ git fetch origin masterthen becomes
$ git fetch \ https://github.com/matklad/matklad.github.io \ refs/heads/master:refs/remotes/origin/masterThe first argument of
fetch(https://...) is a location of a remote repository. Git will βdialβ that address, and will transfer some data from that computer locally over the network.The second argument is a
source:targetpair of string keys (refs). Thesourceis a key on the remote repo, thetargetis the name of a local key, and fetch as a whole asks git to read a value from a remote repository and save it locally under a different name.To avoid typing repository URLs all the time, git assigns them symbolic names, with
originbeing the conventional name for the primary remote repository:$ git fetch origin \ refs/heads/master:refs/remotes/origin/masterrefs/heads/masteris a fully elaborated name of a branch on the remote repo. That is, branchmy-featureis just arefs/heads/my-featureref. It could have beenrefs/branch/my-feature, but it isnβt :)I donβt know the specific shorthand rules, but, generally, git allows you to spell only the suffix of a ref:
$ git fetch origin \ master:refs/remotes/origin/masterrefs/remotes/origin/masteris the name of the local ref weβll use to store the result. It would seem natural to just use the same name locally as the one on the remote, but this only works if thereβs a single remote. If there are two upstream repositories (for example, your fork, and the original repo you forked from), their ref names will collide. Thatβs why we want to namespace the refs for remote calledfoounderrefs/remotes/foo. Andoriginis just a conventional name for the remote in simple setups.Again, it would be more natural to directly mirror remote ref structure locally:
refs/ heads/my-branch -> refs/ remotes/origin/ heads/my-branchbut git strips the redundant heads component. And this
-heads,+remotes/$remotemapping is built in, which compresses the command to$ git fetch origin masterItβs worth reflecting why it works this way. Git model is offline first. Whatβs more, it assumes explicit synchronization points. Rather than synchronizing with the remote repository in background when thereβs connectivity, git requires explicit
fetchandpushoperations to transfer bytes over the wire. In this paradigm, it is useful to model the state of the remote party at the moment when we talked to them the last time. Theory of mind!This hopefully deconfuses gitβs concept of local and remote branches. Consider the
mainbranch. It exists on the remote namedoriginasrefs/heads/main. When you synchronize your local repository withorigin, you getrefs/remotes/origin/mainβ you current best knowledge about the the state ofmainon theorigin.And then thereβs your local
refs/heads/main. It typically starts pointing at the same commit asrefs/remotes/origin/main. But, when you make a commit,refs/heads/mainadvances, butrefs/remotes/origin/mainstays the same.When you try to push your local commit to origin, you will get a conflict, if the
mainbranch on theoriginadvanced in the meanwhile. In that case, git automatically updatesrefs/remotes/origin/main(as thatβs just a local mirror of the remote state), but then itβs on you to updaterefs/heads/mainand push it again.Revisiting the full example:
$ git fetch origin master $ git switch -c my-feature origin/masterThe first command looks up the URL for the
originremote in.git/configand makes a network request to that machine. As a result, the localrefs/remotes/origin/mastergets updated to the same commit asrefs/heads/masterremotely (the commit and its ancestors are transferred locally as a result).The second command creates a
refs/heads/my-featureref (a branch), whose starting point isrefs/remotes/origin/master. It is an example of a leaky abstraction.The second argument there is a (shorthand of a) ref, so you can do
$ git switch -c my-feature \ refs/remotes/origin/masterBut, although the first argument creates a ref, it isnβt a ref itself. In other words, if you try to elaborate it as well
$ git switch -c refs/heads/my-feature \ refs/remotes/origin/masteryouβll get
refs/heads/refs/heads/my-featureThatβs all! I am pretty sure this isnβt particularly useful, but maybe it is interesting!
-
π New Music Releases Philip Glass - Philip Glass: Music for Film rss
Philip Glass - a new release is available:
- 2026-10-07: Philip Glass: Music for Film (Album)
Amazon: Canada | Deutschland | France | United Kingdom | United States
Visit muspy for more information.
-
- October 06, 2026
-
π r/LocalLLaMA Europe rejoins the fight with Chonky! Mistral Large 4 Released, Open weights end of month, whoβs ready? rss
| 1 trillion parameters, 49B active, definitely chonky! If you donβt love the model you gotta at least love the humor in the name - Le Chonk submitted by /u/chemist_slime
[link] [comments]
---|--- -
π Evan Schwartz Scour - September Update rss
Hi friends,
In September, Scour scoured 1.2 million articles (up from ~880,000 in August) from 28,568 feeds. Also, welcome to the 116 new users who signed up since my last product update email!
Here's what's new in the product:
π Library and Article Tabs
You can now find all of your saved, loved, and liked posts, as well as your full reading history, in the Library section.
Also, if you click Read on Scour for any article, that page now has tabs for the article's content, other posts that it cites and that cite it, and the feeds it was found in. Here's an example for a widely cited post.
π Expertise Level
Scour now tries to determine the level of expertise each post assumes and infers the level of expertise you have per topic (based on the wording of your interest is and the types of articles you click on or like). At least for me, this means I'm seeing far fewer beginner Rust questions from Reddit showing up in my feed. (For those in tech, this is powered by Jev.)
π Search for Feeds and People
Scour's Search will now show you results for feeds and authors, in addition to posts that match your query.
Relatedly, you can now follow individual authors as sources and Scour will try to show you their posts from any website they publish on.
ποΈ Detecting More Junk
Scour now detects and hides more junk, ranging from sales pages and SEO garbage to uninformative link roundups and low-value discussion threads. You should see more high-quality content in your feeds. By my current count, about 1 in 10 posts being shown before was some kind of junk that Scour now hides.
β‘ Faster Feed
I continue to obsess over making Scour feel super fast and snappy. In September the slowest feed loads got about 7x faster (p99 went from 2.1 seconds to 282 milliseconds) and the median feed load time got 2x faster (p50 went from 90 ms to 40 ms). This is also while ranking about 1.4x as much content as the month before.
πͺ¦ RIP Reddit Feeds
Unfortunately Reddit announced their plan to turn off RSS feeds on November 13th. This is how Scour checks which discussions are happening on Reddit and finds articles posted on different subreddits. After November 13th you'll no longer see links to the Reddit discussions from Scour π’.
π Some of My Favorite Posts
Here are some of my favorite articles I found on Scour in September:
- The biggest news in the tech / AI world was the release of TypeSafe's Jev model. These were some of the related articles that I found interesting:
- The Latent Space interview with TypeSafe's CEO, Jev: System One models for Prod, not God β with Diogo Almeida, CEO, TypeSafe AI.
- Fingerprints of Jev and Jev's Architecture Unmasked were interesting black box investigations into Jev's base model using the tokenizer and other externally visible properties.
- Sixteen Models Walk Into a Storefront gives a very nice breakdown of techniques that can be used to manipulate LLMs' assessments of which products to buy and how much to pay for products.
- Logo Design Trends in 2027 Favor Marks Someone Can Prove They Made. In the age of AI-generated glossy slop, this is no surprise, but it's a nice write-up.
- The engineering behind the US Strategic Petroleum Reserve. Quite random but an interesting read.
- I Judged My Mum for Overusing AI, Until I Caught Myself Doing Worse. I continue to appreciate Sid's commentary on the age of AI. This is very relatable.
Happy Scouring! - Evan
- The biggest news in the tech / AI world was the release of TypeSafe's Jev model. These were some of the related articles that I found interesting:
-
π @HexRaysSA@infosec.exchange The upcoming IDA 9.5 adds 3οΈβ£ new decompilers and will deliver π platform mastodon
The upcoming IDA 9.5 adds 3οΈβ£ new decompilers and will deliver π platform updates.
The new decompilers:
βΎ Android DEX
βΎ Infineon TriCore
βΎ Qualcomm Hexagonπ Read the full blog to see the rest of the updates: https://hex- rays.com/blog/ida-9.5-three-new-decompilers
-
π Hex-Rays Blog IDA 9.5: 3 new decompilers and 10 platform updates rss
Good tooling starts with solid fundamentals. When every instruction decodes correctly and every function reads as clean pseudocode, you can trust what IDA shows and put your time into the binary itself. That holds whether the one reading the output is a person or an agent driving IDA. IDA 9.5 brings that reliability to three new architectures and sharpens it on several familiar ones.

-
π smol-machines/smolvm smolvm v1.23.7 release
What's Changed
- Start machines with a larger storage disk on their image's seed, grown to the requested size by @BinSquare in #1576
- Let as many asset compressors run at once as the host's CPUs fit by @LoganGrasby in #1577
- Let an egress watchlist entry block a match as well as record it by @BinSquare in #1540
- [Agent Experience] Add throwaway-machine skill packet to docs/ by @NickyHeC in #1542
- [Agent Experience] Add nine more skill packets to docs/ by @NickyHeC in #1543
- Refuse exec commands too long for the guest with a clear 400, and retry a layer download that hits a transient network error by @BinSquare in #1579
- [Agent Experience] Fix stale CLI help and examples by @NickyHeC in #1578
- Charge sparse checkpoint entries their stored bytes against the extraction cap, and keep the console of a VM that stopped answering by @BinSquare in #1580
- Make every smolvm process on a server's node follow the restore cache sizing the server chose by @BinSquare in #1581
- Bump version to 1.23.7 by @BinSquare in #1583
Full Changelog :
v1.23.6...v1.23.7 -
π hacker news ida pro references New comment by bri3d in "Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol" rss
I agree! Don't give it away!
Seriously, though, the popular Ghidra MCP is really badly architected; it's way better to rearchitect it or just script Ghidra directly. With that said, Opus 5.5 seems to have been trained on CoT from the popular Ghidra MCP. This makes it work better, but also makes it even more inefficient if you modify the MCP without changing its name and shape significantly (it will try to make tool calls using the "mainline" format, then have to retry them when they fail).
Even with Opus 5.5, IMO it's better to just ditch the MCP and let the LLMs eat with bintools and headless Ghidra; with both GLM and Opus this produces significantly more efficient results than the popular MCP. On the other hand the IDA Pro MCP is much better architected and seems to be pretty good.
-
π hacker news ida pro references New comment by bri3d in "Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol" rss
The IDA Pro MCP is substantially better than the most popular Ghidra MCP, for what it's worth.
-
π r/LocalLLaMA 54gb vram for 35$ rss
| Bought an old mining farm of a guy on avito (Russian eBay), guy had bought a garage a couple of years ago and it was sitting there for a while, found out it was a mining farm and put it up on there for sale for 5000 rub (~60 USD) since he wasn't sure if it works. I negotiated down to 3000 rub (~35 USD), it turned out to have 9x p106 6gb (gtx 1060 6gb) gpus, with 54gb vram total, all working, the only thing missing was an SSD, I booted from USB and it works fine. submitted by /u/markpronkin
[link] [comments]
---|--- -
π r/LocalLLaMA google/embeddinggemma-2 Β· Hugging Face rss
| EmbeddingGemma 2 is an open multimodal embedding model built by Google DeepMind which maps text (incl. code), images, video, and audio inputsβand combinations thereofβinto a single, unified 768-dimensional vector space. The model has 740M total parameters, combining a 270M parameter text model with modular vision (170M) and audio (300M) encoders. Designed to run on consumer hardware such as mobile devices and laptops, EmbeddingGemma 2 delivers low-latency semantic representations for on-device applications, like search, retrieval-augmented generation (RAG), classification, and clustering. EmbeddingGemma 2 builds upon the architectural and capability advancements of Gemma 4, offering several core features: - Native multimodality: Native multimodality: Unifies 4 modalities (text, images, video, and audio) in a single shared 768-dimensional embedding space.
- Multilinguality and code: EmbeddingGemma 2 understands 100+ languages, and achieves a ~14% improvement on code tasks relative to its predecessor.
- Flexible footprint: Combines a 270M parameter text backbone (130M transformer + 140M embedder) with selectively loadable vision (170M) and audio (300M) encoders, allowing developers to load only the modalities required for their use case.
- Matryoshka Representation Learning (MRL): Native support for truncated embeddings across 128d, 256d, 512d, and 768d, enabling up to a 6x reduction in vector storage costs with minimal impact on quality.
- Context length: 8K token context window, capable of processing minutes of audio or video.
- Task-steered representations: Uses lightweight text instruction prefixes to optimize embeddings for different tasks (search, classification, clustering, semantic similarity, etc.).
llama.cpp support https://github.com/ggml-org/llama.cpp/pull/30054 GGUF from GG: https://huggingface.co/ggml-org/embeddinggemma-2-GGUF GGUF from Unsloth: https://huggingface.co/unsloth/embeddinggemma-2-GGUF submitted by /u/jacek2023
[link] [comments]
---|--- -
π hacker news ida pro references New comment by teravor in "Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol" rss
if you include a SKILL.md for the MCP (or just dump it into the prompt) it's not a problem.> there isn't a whole lot of knowledge about how to use them in the training datasetsI don't use Ghidra but IDA Pro MCP works extremely well for me for all manner of tasks. for example, some software likes to call home for license checking (and I wish to run it with networking denied to it). it no longer does.
-
π r/LocalLLaMA Woman used claude as her diary - and got reported to the police for contents of her diary rss
| submitted by /u/Timely_Impression_92
[link] [comments]
---|--- -
π Andrew Ayer - Blog sourcespotter-authorize: Monitor Your Go Modules for Malicious Versions, Without the Noise rss
You can protect the users of your Go modules from supply chain attacks, such as a compromise of your GitHub account, by monitoring Go's checksum database (sumdb). Since the go command won't install a module unless its checksum is published in the sumdb, monitoring the sumdb lets you discover unauthorized versions of your modules. Since the sumdb is a transparency log, you can even detect if Google themselves go rogue and publish a malicious version of your module. Although you can only detect, not prevent, attacks, Go's Minimal Version Selection makes it possible to respond before most of your users have installed the malicious version. Dependency cooldowns, which are coming to Go, will make it even easier to respond in time.
How To Monitor
Source Spotter, which is operated by my company SSLMate as a free service to the Go community, provides Atom feeds listing all versions of your modules found in the sumdb. For example, this Atom feed returns all versions of modules under the src.agwa.name/ prefix:
https://feeds.api.sourcespotter.com/modules/versions.atom?module=src.agwa.name%2FYou can also get Prometheus-compatible metrics:
https://metrics.api.sourcespotter.com/modules?module=src.agwa.name%2FYou can scrape the metrics endpoint using Prometheus and alert in your usual way, subscribe to the Atom feed using your favorite feed reader, or use one of the free services that converts Atom feeds to emails.
Avoiding Noise
Discovery is only half the story. The more important half is deciding whether to alert on a discovered module. Approximately 100% of the records published in the sumdb are legitimate. If you're alerted every time a new version of your module is legitimately published, it will be very hard to notice the one time it's an attack.
I wasn't sure at first how Source Spotter could facilitate no-noise monitoring. Initially, I thought Source Spotter would need access to your module's Git repository so it could cross-check sumdb records against the repo's contents. But that seemed complicated, and it would fail to detect a compromise of your repository host. I also really wanted a solution that wouldn't require users to create accounts.
I finally found a lightweight solution that I really like. I'll show you how you use it, and then explain how it works.
First, you install a small command line tool called sourcespotter- authorize and generate a public/private key pair:
$ go install software.sslmate.com/src/sourcespotter/cmd/sourcespotter- authorize@latest sourcespotter-authorize -keygenRun sourcespotter-authorize again with the
-feed-foror-metrics-forflags to output Atom and Prometheus URLs for the module prefix you want to monitor (src.agwa.name/ in this example):$ sourcespotter-authorize -feed-for src.agwa.name/ https://feeds.api.sourcespotter.com/modules/versions.atom?module=src.agwa.name%2F&mldsa=efbcb2bcb2d4decdf1ad9cab3224b2dd0087b6c6877abe00448a00d31716dff1 $ sourcespotter-authorize -metrics-for src.agwa.name/ https://metrics.api.sourcespotter.com/modules?module=src.agwa.name%2F&mldsa=efbcb2bcb2d4decdf1ad9cab3224b2dd0087b6c6877abe00448a00d31716dff1These are the same URLs shown earlier, but with a new
mldsa=parameter in the query string which is the hash of the public key you generated in the previous step.Initially, these URLs return the same contents as the URLs without the mldsa= parameter. That's because you haven't marked any module versions as authorized yet.
To mark a module version as authorized, change into the Git repository for the module and run sourcespotter-authorize with a Git tag:
$ cd ~/src/snid $ sourcespotter-authorize v0.4.0Now, v0.4.0 of this module is omitted from the feed and metrics URLs.
The command accepts multiple tags as arguments, so you can authorize all the tags in a repo like this:
$ sourcespotter-authorize $(git tag)Moving forward, you should run sourcespotter-authorize any time you tag a new version. I've written a tiny shell script called gotag that runs git tag followed by sourcespotter-authorize:
#!/bin/sh -e git tag "$1" sourcespotter-authorize "$1"As long as you authorize every tag you create, the feed and metrics URLs will report zero unauthorized module versions, eliminating false positive alerts. A supply chain attacker can't hide their malicious versions from your feeds unless they also compromise sourcespotter-authorize's private key.
How It Works
sourcespotter-authorize -keygengenerates an ML-DSA-44 private key (stored under $XDG_CONFIG_HOME/sourcespotter-authorize). The SHA-256 hash of the corresponding public key goes in the mldsa query string parameter.When you authorize a tag, sourcespotter-authorize uses the golang.org/x/mod/zip and golang.org/x/mod/sumdb/dirhash packages to compute the checksums of the go.mod and module zip files for the tag. It formats the module path, version, and hashes for each tag as a go.sum file (no need to invent a new format here), and signs the file with your private ML-DSA key. Finally, it uploads a JSON object to the Source Spotter server containing your public key, the go.sum file, and the signature.
The Source Spotter server verifies the signature using the public key. If valid, it records the module path, version, and hash as being authorized by that public key, and excludes that module version from the feeds and metrics endpoints for the key.
The protocol is simple and documented if you want to implement your own client.
Why Not Just Sign Your Releases?
If you're generating a private key and signing stuff anyway, why not just sign your releases and distribute the signatures? After all, this is the traditional approach to stopping unauthorized software releases.
The problem with the traditional approach is that consumers of your software have to verify the signatures, which means they need to know what your public key is. Key distribution is a hard, hard problem, and most software ecosystems do a bad job at it. I would guess that in practice, few people actually verify signatures of software releases.
In contrast, the go command automatically verifies that every module it installs is listed in the checksum database, without the user needing to do anything. Although sourcespotter-authorize needs a private key, you only need to distribute the public key to Source Spotter (or whatever other monitor you might choose to use), rather than every single consumer of your software. That's a vastly simpler problem, especially when (not if) you need to rotate your keys.
Everyone who signs their software releases will need to rotate their keys soon, as quantum computers are expected to break RSA and elliptic curves within the next few years. An earlier version of sourcespotter-authorize used elliptic curve keys. After it gained ML-DSA support, upgrading my key was super easy - generate a new key, transfer my list of authorized versions to it, and finally update the URL in my feed reader:
$ sourcespotter-authorize -export > tmpfile $ rm ~/.config/sourcespotter-authorize/private_key $ sourcespotter-authorize -keygen $ sourcespotter-authorize -import < tmpfile $ sourcespotter-authorize -feed-for src.agwa.name/This was so much easier than communicating a new key to every consumer of my software would have been, and didn't require a lengthy transition period during which I was signing with two keys.
You can learn more about Source Spotter's module monitoring, get the source code on GitHub, or read my blog post about how Source Spotter also verifies Go's reproducible builds.
-
π backnotprop/plannotator v0.28.5 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.4 | Comments come back after the agent edits a file, the agent can list and close its reviews, PR-description feedback no longer dropped, Pi thinking levels
v0.28.3 | Typing into your agent while it answers an Ask no longer streams into Plannotator
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocksWhat's New in v0.28.5
Twelve PRs, one from a first-time contributor. Agents on Pi and OpenCode 2 can now open Plannotator reviews themselves without holding the session, a review can cover several files at once, and every decision now names the exact file it is about.
Several files in one review
plannotator annotate spec.md ui/mock.html notes.mdnow opens one review of all the files, in the order you typed them. A header switcher shows "2 of 3", the Files tab keeps that order, and one decision covers the whole set, with the feedback split into a section per file. Ask AI knows which file you are on, and your unsent comments are kept per file. The same works when an agent passes a list of files to theplannotatortool. If one of the paths does not exist, nothing opens and the error names the missing file. Words that are not file paths keep their old meaning, soannotate look at notes.md pleasestill opensnotes.md. (#1718)The
plannotatortool on Pi and OpenCode 2, off until you turn it onOn Claude Code (with the Plannotator mod) agents already had a
plannotatortool. It is now on Pi and OpenCode 2 too. It matters when the agent opens Plannotator itself, for example when you ask it to "show me the HTML plan in Plannotator" or "open a Plannotator code review". Without the tool, the agent runs theplannotatorcommand in its shell, which blocks the session until you finish and leaves Ask AI unable to reach the session. With the tool, the review opens right away while the agent keeps working, your decision comes back as a message, Ask this session works from that review, and the agent can list and close the reviews it opened.The tool adds about 780 tokens to every request, so on Pi and OpenCode 2 it is off by default. The first Plannotator page you open there asks "Do you use Plannotator as a skill?" and turns it on for your next session if you say yes. You can change it any time with the new toggle in Settings β General (plan review, annotate and code review), the
agentToolkey in~/.plannotator/config.json, orPLANNOTATOR_AGENT_TOOL. On Claude Code the tool stays on by default, since Claude loads it only when it is needed; the same switch turns it off there without turning off the rest of the mod. Your/plannotator-*commands work the same either way. (#1714, #1715, #1724, #1725)The tool's description no longer includes the unfinished
replyaction, and Pi's bundled knowledge skill stays out of the model's context by default, keeping the promise from #842.Every decision names the file it is about
A user reviewing two different files that were both named
QUESTIONS.mdapproved one of them. The approval reached the agent as just "QUESTIONS.md β Approved." with no path, and the agent attached it to the other file. Every decision message now carries aTarget:line with the full path (or URL, PR, or folder), taken from the review that recorded the decision, and reviews that share a file name are labelled with their folder, such asreleases-2026-10-04/QUESTIONS.md. A code review decision names the PR that is on screen when you decide, even if you switched PRs inside the review.A related gap is closed too: when a review's port was reused (a fixed
PLANNOTATOR_PORT, remote mode, or rarely by chance), an old browser tab could submit a decision to the new review. Each review now has its own id, and a decision from a tab that belongs to a different review is refused with a "This review was replaced, reload" banner.plannotator sessionsnow lists each review's id and full path, and has a--jsonoption. (#1729)Ask this session reconnects after sleep
With the Claude Code mod, Ask AI in an open review could switch permanently to "This session is no longer available" after your computer slept or the network dropped for a few minutes. It now reconnects on its own, waiting a little longer between attempts while the review is unreachable. Running
claude --continuewhile the old window is still open no longer makes the two windows fight over the review: the window you are using takes it over, each decision is delivered exactly once, and plan approvals reach the right window. If you quit Claude Code after a decision arrived but before Claude saw it, you get a notice next time saying where it was saved. (#1727)Approve with a note in every gated review
Gated annotate reviews (
--gate, or the tool withgate: true) opened from Claude Code never offered "Approve with a noteβ¦", even though the note could be delivered. They do now, for markdown and HTML alike, on every host that delivers the note with the approval. Your note reaches the agent as an "approved with notes" message. A plain approval is unchanged: plain output is still exactlyThe user approved.One thing for scripts: when you approve with a note, plain output now prints the approved-with-notes message instead of that line. Scripts should use--gate --json. (#1728)Additional Changes
- Done says nothing was sent. Clicking Done with nothing to send showed "Feedback Sent". It now shows "Done, nothing was sent", and Close no longer claims a response was sent (#1730).
- Pi keeps the model you picked. Using
/treeto re-answer something during plan execution switched the model back to the plan's original one. It now keeps your choice; moving into or out of plan mode still applies the phase's model (#1723, fixes #1722). - Gruvbox diffs. Added lines in code review were grey on the Gruvbox theme. They are now Gruvbox green in light and dark (#1721).
- Safer settings. A web page in your browser can no longer change Plannotator's settings in the background, and saving settings from the VS Code panel works again, as do viewed-file progress and the Call Flow install there (#1724).
- Type checking now covers the Claude Code side's server code (#1720).
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- feat(annotate): several files in one annotate review by @backnotprop in #1718
- feat(pi): the plannotator tool on Pi by @backnotprop in #1714
- feat(opencode): the plannotator tool on OpenCode 2 by @backnotprop in #1715
- feat(tool): agentTool switch with per-host defaults, Pi tool stability, drop the reserved reply action by @backnotprop in #1724
- feat(ui): agent tool switch in Settings and a one-time offer on Pi and OpenCode 2 by @backnotprop in #1725
- fix: decisions name their full target; refuse stale-tab decisions on a reused port by @backnotprop in #1729
- fix(mod): restart a dead Ask-this-session bridge; one watcher per launch across processes by @backnotprop in #1727
- fix(annotate): offer Approve with a note in every gated session that delivers it by @backnotprop in #1728
- fix(annotate): show a Done screen, not Feedback Sent, when Done sends nothing by @backnotprop in #1730
- fix(pi): keep the user's model on a /tree navigation within the same phase by @backnotprop in #1723
- Fix gruvbox positive diff colors by @TheEdgeOfRage in #1721
- fix(hook): type-check apps/hook/server and fix vibe-plan.ts narrowing by @backnotprop in #1720
New Contributors
- @TheEdgeOfRage made their first contribution in #1721
Contributors
@TheEdgeOfRage fixed the grey added lines in Gruvbox code review, with the color override the colorblind theme already uses.
Community:
- @jasonharrison reported the Pi model reset on
/treewith a clear repro on Oh My Pi (#1722).
Full Changelog :
v0.28.4...v0.28.5 -
π r/LocalLLaMA Qwen 4 apparently coming out at the end of October rss
Hey All,
I spoke to a 0-day partner of Alibaba today and he casually mentioned (didnt know if he was allowed to) that Qwen 4 is apparently planned for the end of October.
To me, this is way faster than expected as there was quite a gap between 3.6 and 3.8.
I tried to get more information out of him regarding which variants will come first and he got a bit cagey.
BUT: No matter the order of the variants, we can hope for Qwen 4 27B this year!
EDIT: I know this is very much "in bro we trust" but i am also just trusting bro from the Alibaba partner. Together we trust in Bro.
submitted by /u/Dependent_Hunter_155
[link] [comments] -
π r/LocalLLaMA Microsoft confirms OpenAI has been using Looped Transformers in the GPT-6 series rss
| Microsoft confirms on publicly accessible web page that OpenAI has been using Looped Transformers in the GPT-6 series, proving The Information's reporting was correct all along. GPT-6.1 Sol uses 2 inference passes, with a passing mention of "instead of three". For those confused by "same base model weights as GPT-6 Sol", I think Microsoft meant 6 & 6.1 are both post-trained models on top of the same pre-trained "base model", not that the final weights are identical So different post-training (+ one less loop). Update: Microsoft updated the web page to remove it submitted by /u/ResearchCrafty1804
[link] [comments]
---|--- -
π Project Zero How to fix a bug in a fix rss
Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure. Some vendors express concern about potential scenarios in which they are unable to fix vulnerabilities that are causing immediate user harm, due to limitations in their patch delivery systems. Since Project Zero encounters a wide array of systems designed to protect users in the case of exceptional exploitation scenarios, both through vendor discussions and security reviews, we want to share what weβve learned.
This post provides an overview of systems in use by large vendors that allow them to remediate small volumes of vulnerabilities much faster than their typical update process. Our goal is to provide a reference for vendors seeking to implement or enhance the capabilities of such systems, and to encourage vendors to consider how they would fix an urgent vulnerability before they receive one.
Why patching takes time
Patching a vulnerability typically involves the following stages:
- Triage β a vulnerability report is received, validated, prioritized and assigned to a specific developer to be fixed
- Patch development β a software development team writes, reviews and commits code that fixes the vulnerability
- Testing β the patch is tested to ensure the vulnerability is remediated and the software still functions correctly when the patch is applied. This can include formal testing by a test team, automated testing and alpha and beta testing where a patch is shipped to a limited group of users for feedback on normal use.
- Partner review β some software updates require review by third parties before they can be shipped, due to relationships between the software vendor and other organizations, for example, carrier acceptance for some mobile updates.
- Delivery β the patch is delivered to and installed by end users
- Activation β sometimes an additional step, such as a system restart, is needed to switch the system to the updated software
Of course, this is a simplified picture. Patching can involve repeating steps, for example rewriting a patch if tests fail, or additional stages when third- party vendors are involved. However, this is a minimal set of steps most software updates require.
The challenges of emergency patches
While triage and patch development time contribute substantially to the speed at which vendors can generally patch vulnerabilities, they contribute less to emergency patch time. Triage is usually very fast in situations where vendors know they have an urgent problem, and patch development can be expedited based on priority. Only in rare circumstances, where a vulnerability is especially complex, or a vendorβs security team does not have a complete picture of their softwareβs components and who within their organization maintains them, have we seen urgent patches delayed in the triage or development phase. Likewise, partner agreements usually have exceptions for updates in emergency situations.
Most vendorsβ patch speed is limited by the testing and delivery stages. Testing is important because all changes to software risk introducing unexpected behavior. The worst-case scenario is that inadequately tested software βbricksβ a device, causing it to malfunction in a way that it can no longer perform key functionality or receive software updates to remediate this. Buggy software updates have also led to situations where user data is corrupted or lost, and any decrease in software functionality after a security update makes users less likely to apply updates in the future.
The potential cost to vendors of shipping poorly tested updates varies depending on the nature of the underlying software. For example, if a mobile application is rendered unusable due to an update that corrupts local data or prevents it from launching, users can easily install the next version via an app store, and their data is usually saved on a remote server, so costs are limited to user support. Meanwhile, if a mobile device gets bricked, it needs to be returned to its manufacturer or place of purchase for repair, leading to substantial costs for the vendor and potentially the user.
The possibility of serious functional bugs is considered in the design of most patch delivery systems. Updates are often rolled out slowly, so that serious problems can be detected before they affect too many users. Often, patching vulnerabilities quickly and avoiding buggy patches are at odds with each other, requiring tradeoffs that prioritize one over the other.
A variety of other technical challenges can limit the speed of patch delivery. One is the design of the patching system. A common design is that devices probe for updates at a regular interval, leading to patch saturation being limited to that interval. βPushβ style update systems can deliver patches to all users faster, but generally require more infrastructure.
User behavior and environment can also be a barrier to patch propagation. Patches that require user interaction to install are often delayed by users, and network speed and data cost are also factors in installation rate. Updating many users at once, as opposed to over a period of time, can strain patch delivery infrastructure. Chrome and Microsoft have written about the challenges of updates requiring restart to install, as users are often reluctant to restart their system and restarts take time.
While testing delays and limitations of the patch delivery system affect all updates, the shorter time frame of emergency updates make them a larger contributor to the overall time it takes to deliver a patch.
Emergency patching methods
Feature flags
Feature flags are conditional statements in source with paths determined by values provided by a remote server. They are often used for A/B testing, but they can also be used for short term remediation of vulnerabilities in emergency situations. A widely publicized case of this was a serious 2019 FaceTime vulnerability, where Apple temporarily disabled Group Facetime with a feature flag. Several vendors have made at least some media codecs available in 0-click contexts controllable via feature flags, and can disable them in the case of active exploitation, falling back to another codec for realtime transmission.
The main benefit of feature flags as a vulnerability remediation method is that testing can be performed with each flag set in advance, so a fast update does not require shipping untested code. They can also be delivered to users much more quickly, as updating feature flags requires transmitting a very small amount of data.
Recently, Meta published a blog post on how they implemented a βdual stackβ library, in which two versions of the WebRTC video conferencing library were compiled into a single binary, with the version in use controllable via a feature flag. This technology enables rapid updates with less testing, as new versions can be shipped with the option to quickly move users back to the previous version if function problems occur. While Meta uses two versions of the same library, it would also be possible to create a βdual stackβ with two different libraries that implement the same features (for example, two H264 libraries), allowing an application to switch to a different library to render a specific vulnerability unreachable without loss of functionality in an emergency. This would require additional testing, but it is testing that can be performed up front. It could also be possible to have a second library that enables performance intensive mitigations that would block many possible bugs, such as ASAN, or enabling DCHECKs.
Filtering
Filtering is running a dynamically updatable ruleset, such as a regular expression, against untrusted input in order to block specific input that is required to reach a vulnerability. An example of this is Androidβs Intent Firewall, which allows specific usages of an Android IPC mechanism called intents to be disabled based on rules in a dynamically updateable XML file, which enables blocking intents that can be used to exercise specific vulnerabilities. It was recently used to block vulnerabilities in third-party Android wallets.
Some platforms have endpoint detection software that can perform filtering on a wide variety of system input, for example Microsoft Defender on Windows systems, and Google Play Protect on Android devices. Rules that block specific exploits or make certain vulnerabilities unreachable can often be deployed to these applications very quickly. Endpoint detection requires parsing a great deal of untrusted input, often in privileged context, so these applications are not without risk, but in systems where they already exist, they are a potential method of emergency remediation.
As an approach, filtering is more flexible than feature flags. For feature flags to be effective, the vendor needs to determine what features they might want to disable in advance, and if this isnβt comprehensive, they might find themselves in a situation where a vulnerability canβt be remediated via feature flags. Meanwhile, filtering can be used to block a wide variety of inputs, even ones that have never been considered. The downside of filtering is that performing filtering frequently can decrease software performance, and at least some testing of new filters is required, and canβt be performed upfront without knowing the vulnerability that needs to be blocked, as it is possible to write filters that interfere with necessary system functions.
Alternate Channels
The network βchannelsβ used to deliver software updates to users can be slow for a variety of reasons discussed above. Vendors sometimes implement alternate channels that can be used to deliver smaller updates more quickly.
Android Pony Express (APEX) is an example of an alternate channel that can be used to ship updates to specific high-risk Android components faster than a full system update. It shortens the patch development time, as OEMs do not need to integrate updates to APEX components. APEX is available to OEMs, and can be used to update OEM- maintained libraries.
Several applications weβve researched have the ability to update individual libraries outside regular updates, usually by having some flag that is regularly checked over the network, and then downloading the library and loading it with
dlopenor equivalent. While this is an effective way to avoid delivery-speed limitations of updates, it can also introduce critical vulnerabilities if libraries delivered in this way are not adequately verified by the client to have originated from the vendor. We encourage vendors to be cautious, and ensure that emergency update mechanisms of this variety have adequate security testing.Hotpatching
Some vendors have implemented update mechanisms that allow units of binary code smaller than libraries to be delivered and applied directly to the memory space of a running process. For example Linux supports Livepatch which enables kernel functions to be directly replaced in memory without a restart. Similarly, Windowsβ hotpatch allows security updates that contain only updated functions to be delivered to users, and applied while the process is still running.
Hotpatching has the potential to deliver very flexible security patches to software very quickly, with no degradation of user experience, though it typically has some limits to the nature of patches it can deliver, for example, updates that require changing the definition of a structure shared between functions are sometimes not supported. Hotpatching has similar security downsides to alternate channels, and also carries the risk of introducing ways to bypass exploit mitigations, as it requires permissions to map pages with write-execute privileges at some point during patching. It also doesnβt address any of the testing challenges of rapid updates, just the delivery challenges.
The importance of emergency patching
LLMs are increasing the vulnerability discovery and exploitation capabilities of both attackers and defenders. A wider array of actors now have the ability to perform novel attacks at greater speed. In light of this, it is important for vendors to consider how to protect their users in the case of active exploitation. Rapid update mechanisms do not need to be heavyweight or be capable of fixing every possible bug and preserving perfect user experience in every scenario. Technologies like feature flags, filtering and alternate update mechanisms can remediate the most likely and severe vulnerabilities in the short term, while keeping devices reasonably functional for users.
It is urgent for vendors to plan how they will protect their users in the worst case scenario of widespread active exploitation. Actions taken now can greatly improve security outcomes for users. By taking stock of update mechanisms already available to them and implementing rapid remediation functionality where gaps exist, vendors can be better prepared for whatever the future holds.
-
π syncthing/syncthing v2.1.6 release
Major changes in 2.1
-
Devices and folders can now be grouped in the GUI by setting the new
groupattribute. -
HTTP and HTTPS proxies with support for CONNECT can now be used, in
addition to the existing support for SOCKS proxies (the environment
variableall_proxy=https://...). -
Block indexing can be turned off for folders where it's more desirable to
optimise for reduced database size and overhead than minimal transfer
size (theblockIndexingattribute on folder configuration). -
GUI login session duration can be configured to be longer or shorter than
the default one week, or set to infinitely long. The cookie path can also
be adjusted. (ThesessionCookieDurationSandsessionCookiePath
attributes in the GUI configuration.)
This release is also available as:
-
APT repository: https://apt.syncthing.net/
-
Docker image:
docker.io/syncthing/syncthing:2.1.6orghcr.io/syncthing/syncthing:2.1.6
({docker,ghcr}.io/syncthing/syncthing:2to follow just the major version)
What's Changed
Fixes
- fix(model): introducers should not be able to add themselves to folders by @calmh in #10880
- fix(gui): add accessible labels to buttons in Edit Device modal (fixes #10873) by @tomasz1986 in #10874
- fix(model): properly error out when a temp file can't be created by @calmh in #10883
- fix: disable keepalive on most outgoing HTTP connections by @calmh in #10891
- fix(monitor): continue log writes when stdout is unavailable on detached Windows consoles (fixes #10882) by @Shablone in #10889
- fix(gui): improve header and button color contrast (fixes #10488) by @giri256 in #10815
- fix: use global short lived HTTP client with proper HTTP/2 support by @calmh in #10901
- fix: remove unnecessary delay in index transmission by @calmh in #10908
- fix(watchaggregator): properly convert floating-point time duration (fixes #10899) by @calmh in #10900
New Contributors
Full Changelog :
v2.1.5...v2.1.6 -
-
π streamyfin/streamyfin v0.55.1 release
fix(ios): keep tab labels on their tabs when built with the iOS 27 SDβ¦
-
π HexRaysSA/plugin-repository commits sync repo: +1 release rss
sync repo: +1 release ## New releases - [ida-settings-editor](https://github.com/williballenthin/ida-settings): 1.3.1 -
π Mitchell Hashimoto A Terminal Protocol for Program Status (OSC 7501) rss
(empty) -
π Filip Filmar Razboj: a minimal GPU in TxHDL rss
Razboj is a minimal graphics rasteriser implemented in approximately one hundred lines of TxHDL. It reads a display list from memory and writes rendered pixels into a framebuffer over an AXI bus. TxHDL lowers the design to synthesizable Verilog and VHDL, and the build verifies both netlists against the software simulation trace. This post describes the rasteriser architecture and hardware design tradeoffs.
What it draws
The reference demonstration scene measures 64 by 64 pixels (4,096 pixels total). The scene consists of eight display list entries: a background clear, three rectangles, and four triangles. The rasteriser renders the entire scene in approximately 13,000 clock cycles. A verification harness reads the completed framebuffer from memory and saves the output image.
-
π Ampcode News Many, Many Pucks rss
You can now have multiple separate conversations with Puck.
We know you love Puck. We also know you've been asking Puck about your recent orbs, a bug fix, and dinner plans, all in the same conversation. Now each of those can be its own conversation, and each one gets its own Puck.

Press + to start a new conversation. Click the conversation's name at the top to switch between them. Conversations you haven't touched in three days move into Inactive so the list stays short.
Read more about Puck conversations in the docs.
-
π Armin Ronacher What is Codemode rss
More than a year ago I wrote a few posts here that recommended people not to load custom tools into their context (or MCP servers) but to just use more scripts. Most importantly I wrote that Code Is All You Need and I wrote about that MCP needs code. With Pi 1.0 we now added MCP support via Codemode which in some ways is a long time coming, but then also maybe somewhat surprising to some. So I want to share some updated thoughts on this blog on what this all means.
What Are Tools
When a harness like Pi provides tools for an LLM to call, it does so by supplying some tool definitions which then translate into some token structure on the server side. Whether a model is encouraged to call a tool is the result of the reinforcement learning process. Something I wrote about before if you want to learn more.
One of the reasons we strongly lean towards CLI and bash is because it allows easy composition of calls, and because the model also learns how the file system works when it's trained. So when it invokes a tool like
echo foo > /tmp/test.txtthe model also learns that after that tool call, there is now a file calledtest.txtin/tmp.However bash has one fundamental limitation which is that it can only compose programs that run. And there are some things, which are not programs, but native tools to the LLM and they sort of have to be.
The most obvious example here is
readorview_image. If a multimodal model needs to read an image, it cannot usecatfor that because the harness needs to inject the actual image payload into the protocol of the LLM.Another quite vivid example are sub agents. In order to spawn and orchestrate sub agents, it's tricky to avoid tools that are provided by the harness. While in theory the agent could provide a CLI tool that talks to the outer harness via environment variables and Unix sockets, it's a rather crude process. It however has another issue, and that is where the code runs.
Brains vs Hands
To better understand that, it's important to think a bit more about where all the bits and pieces run. There really usually are two different systems involved. The first is the brain, the harness: it runs on one machine. It's trusted. The second is often the same machine, but it's really where the tools are executing: the hands. In Pi we now call this the execution environment, but you can think of it as the target of all the operations.
Crucially what is important for us, is that there is a dividing line between the harness brain and the target environment that runs bash and executes the tools.
And splitting this in half has some really important consequences. For a start it means that they are running on different file systems and they have different levels of trust. If you for instance use a sandboxing solution like Gondolin your bash stuff will be sandboxed just fine, but the harness itself will not be.
Orchestrating The Harness
Which brings us to what Codemode really does: it's a way for the LLM to express and orchestrate complex operations on the harness side, but not the execution environment side. Codemode runs in the harness, in its own sandbox. In case of Pi it's running in QuickJS within a WASM runtime with intentional limitations: no network, no file system, no timers, limited RAM. The only way is to call more tools. You could also imagine that Codemode could run Scheme or some other language as well.
If you are not familiar with Codemode, it's basically just a way to issue tool calls from within some language, in our case JavaScript. That allows you to compose those calls without necessarily going through the LLM's context. Credit for naming goes to our friends at Cloudflare who coined it.
For instance if you issue a bash call as a regular tool call in the LLM, then we only throw the trailing 2000 lines into the context and if the agent wants more, it needs to look at the overflow file itself. If however the agent issues that invocation via Codemode, then the Codemode side gets larger outputs sent structurally.
Most importantly, because Codemode is JavaScript the agent can express concurrent operations and basic workflows. A common way in which you see agents now use this, is to first probe at 5-10 items from some tool response to see what it looks like, and to then write a Codemode script that processes the next n items.
Codemode also allows you to throw state into the transcript! That means that one Codemode invocation can stash away data, that the next call in the session can load again. And remember: this is on the harness host, not the sandbox.
In case of Pi, Codemode also allows you to issue calls that naturally do not make any sense in Pi's traditional interface. For instance if you want to generate images with an image model or you want to classify some text with a one shot classifier model, those Pi APIs are exposed via Codemode, but not via regular tools where they would just waste context.
What It Looks Like
So now that we talked a bunch about it, it's probably worth being a bit more explicit about it. Let's walk ourselves through some invocations of Codemode of recent Pi sessions of mine. Note that none of this code is human written. It's from real sessions of Pi, just re-indented for your viewing pleasure. The agent starts using Codemode automatically either because it's a task where the model already naturally picks up that tool, or because a user asked it to.
Note that Codemode is by default only enabled in Pi when MCP is enabled, but you can turn it on with
"defaultTools": ["+codemode"]in the settings. Just ask Pi to enable it for you.Generating Images
Let's start simple with image generation. Image generation is a feature that Pi supports in the AI SDK core, but it's not a tool that the agent can use. In the past the only way to use image models has been to write a bespoke extension or to have the agent run node itself and use the internal image APIs. However because we expose quite a few of the internal model APIs within Codemode, it means that the agent can use it:
const [painter] = await models.getAvailableOfType("image"); const result = await models.generateImages(painter, { input: [{ type: "text", text: "A cute little puppy sitting on a grassy " + "lawn, soft natural light, photorealistic" }], }); if (result.stopReason !== "stop") return result.errorMessage; for (const block of result.output) { if (block.type === "image") image(block); else text(block.text); }Note that the call to
image()sends the image back as image content to the LLM. On the harness side it feeds it directly into both the agent, as well as onto disk as a temporary artifact in case the agent wants to be able to pass that image back to bash.Classifying Things
Similar things apply to classifier models such as Jev. They also do not fit well into the workflows of an agent through the typical tools. But rather than making a bespoke tool available, Codemode just allows the agent to reach into the AI SDK and invoke those directly. Here you can see how Jev is used to mass process GitHub issues for a quick sentiment analysis:
const jev = await models.getModelOfType("classifier", "typesafe", "jev-latest"); const r = await tools.bash({ command: "gh issue list --state open --limit 100 " + "--json number,title,body,comments", }); const issues = JSON.parse(r.output); const results = await Promise.all(issues.map(async (issue) => { const res = await models.classify(jev, { state: { title: issue.title, body: (issue.body || "").slice(0, 4000), comments: issue.comments.slice(-5).map(c => c.body.slice(0, 800)), }, questions: { sentiment: { type: "choice", instructions: "What is the overall sentiment of the author towards pi?", criteria: { positive: "Appreciative, happy, constructive praise", neutral: "Matter-of-fact report or request without emotion", negative: "Frustrated, annoyed, upset, or angry", }, }, frustration: { type: "score", instructions: "How frustrated is the reporter?", criteria: ["not at all", "mildly", "clearly frustrated", "very angry"], }, kind: { type: "choice", instructions: "What kind of issue is this?", criteria: { bug: "Bug report or regression", feature: "Feature request or enhancement", question: "Question or support request", other: "Docs, discussion, meta, spam", }, }, }, }); if (res.stopReason !== "stop") { return { n: issue.number, title: issue.title, error: res.errorMessage }; } return { n: issue.number, title: issue.title, ...res.answers }; })); store("sentiment_results", results); return results .filter(r => !r.error) .sort((a, b) => b.frustration.score - a.frustration.score) .slice(0, 12) .map(r => `#${r.n} ${r.frustration.score.toFixed(2)} [${r.kind.choice}] ${r.title}`);Note how in that above example we also call
store()which dumps the result of that execution into the session transcript. A future invocation of Codemode can thus read back that result if it wants to.The
Promise.allhere is fine, because Pi limits the total number of concurrent tool executions itself to four and maintains a queue for the rest.A more adventurous example is to use Jev to drive a game engine for debugging purposes:
Codemode with Jev for Game Debugging
Here it knows about my
tankctlcommand and it built itself quickly a minimal harness around it to drive a game loop to assist a user with debugging a problem. Note how it built a 30 step loop in which each step goes back to both the game engine to get a text dump of what's going on, and then to Jev to determine what to do next:const jev = await models.getModelOfType("classifier", "typesafe", "jev-latest"); const tank = async (cmd) => (await tools.bash({ command: `tools/tankctl "${cmd}"` })).output; await tank("start --map assets/maps/night_arena.map"); const questions = { action: { type: "choice", instructions: "You control the tank '@' in a top-down tank game. " + "Choose the best next action.", criteria: { attack: "an enemy has line of sight to you and you can fire at it", approach: "no enemy has line of sight; drive toward the nearest enemy", dodge: "an enemy shot is heading at you and will hit soon", powerup: "a powerup is close and no enemy threatens you", }, }, }; function commandFor(choice, st) { const p = st.player; const enemy = st.enemies.filter(e => !e.dead) .sort((a, b) => (b.los - a.los) || (a.dist - b.dist))[0]; if (choice === "attack" && enemy) { return `fire_at tank ${enemy.id}; frames 30 until clear,damage,kill`; } if (choice === "dodge") { // move perpendicular to the closest incoming shot const s = st.projectiles.filter(s => !s.yours) .sort((a, b) => a.eta - b.eta)[0]; const dir = s && Math.abs(s.vel[0]) > Math.abs(s.vel[1]) ? (p.pos[1] > s.pos[1] ? "+down" : "+up") : (p.pos[0] > (s ? s.pos[0] : 0) ? "+right" : "+left"); return `input ${dir}; frames 20 until damage; input stop`; } const powerup = st.powerups.filter(u => u.available) .sort((a, b) => a.dist - b.dist)[0]; if (choice === "powerup" && powerup) { return `goto ${powerup.pos[0]} ${powerup.pos[1]} 180`; } return enemy ? `goto ${enemy.pos[0]} ${enemy.pos[1]} 90` : null; } const log = []; for (let step = 0; step < 30; step++) { const st = JSON.parse(await tank("state")); if (st.state !== "playing") break; const threats = st.projectiles .filter(s => !s.yours && s.miss_dist < 1.5 && s.eta < 1.5) .map(s => `incoming shot dist ${s.dist} eta ${s.eta}s`) .join("\n") || "no incoming shots"; const r = await models.classify(jev, { state: { map: await tank("view 8"), threats, hp: st.player.hp }, questions, }); if (r.stopReason !== "stop") { log.push(`#${step} classifier error: ${r.errorMessage}`); break; } const choice = r.answers.action.choice; const cmd = commandFor(choice, st); if (!cmd) break; log.push(`#${step} hp=${st.player.hp} ${choice} -> ${await tank(cmd)}`); } return log.join("\n");Calling MCP Servers
Lastly, Codemode obviously is great for calling MCP servers. And because we do not actually expose any of the MCP tools to the LLM, the agent first uses provided APIs to issue a tool search within Codemode to discover what it might be able to do with the connected servers. This form of progressive discovery makes the whole MCP business work well enough for a lot of use cases today.
Here for instance you can see the agent reach for the Sentry MCP straight away, even without discovering the tools, presumably because it has learned during the RL process already about what the Sentry MCP looks like. But it learns from what we inject into the system prompt, that the Sentry server is available to begin with. It's not completely guessing here.
const orgs = await tools.mcp__sentry__find_organizations({}); const { organizations } = orgs.structuredContent; const results = await Promise.allSettled(organizations.map(org => tools.mcp__sentry__find_projects({ organizationSlug: org.slug, regionUrl: org.regionUrl, }) )); return organizations.map((org, i) => { const r = results[i]; if (r.status !== "fulfilled") return { org: org.slug, error: String(r.reason) }; if (r.value.isError) return { org: org.slug, error: r.value.content }; return { org: org.slug, projects: r.value.structuredContent.projects.map(p => p.slug), }; });Modern MCP Is A Fight
I really don't want to talk too much about MCP here, but MCP is in fact a protocol that greatly benefits from Codemode. The problem in parts is that MCP in practice often targets harnesses that do not (yet?) use Codemode. But the tide is shifting. In the meantime, a temporary crutch has been to do what Cloudflare did, and do Codemode within the MCP server. But now we have Codemode in Codemode which is pretty bad. It means double JSON escaping, easy for smaller models to get confused by and the inner code cannot call the outer tools. So if you for instance use the Cloudflare MCP servers in Pi, the agent needs to write JavaScript and funnel it through more JavaScript. This is really not optimal, but it's also understandable that this is happening:
const accRes = await tools.mcp__cloudflare__execute({ code: `async () => { const r = await cloudflare.request({ method: "GET", path: "/accounts" }); return r.result.map(a => ({ id: a.id, name: a.name })); }`, }); const accounts = JSON.parse(accRes.content.map(c => c.text).join("")); const out = []; for (const account of accounts) { const r = await tools.mcp__cloudflare__execute({ account_id: account.id, code: `async () => { const r = await cloudflare.request({ method: "GET", path: \`/accounts/\${accountId}/workers/scripts\`, }); return r.result.map(s => ({ id: s.id, modified: s.modified_on })); }`, }); out.push({ account: account.name, workers: r.content.map(c => c.text).join("") }); } return out;MCP Desires
So to end things off: how well does Codemode work with MCP today? Well β¦ not amazingly well. That's because MCP servers are not really targeting harnesses that use Codemode yet (though at this point I think most harnesses support it).
For this to work well some recommendations:
- Structured content: Codemode wants calls to return some nicely formatted JSON. So that needs to come back from the server, and many don't do that yet. The
outputSchemasystem in MCP is great for that. - Consistent results: an interesting failure case is when an MCP server does not return consistent data. For instance because it tries to token optimize things depending on how many items are in the result set. This can cause an initial probe with 5 items to succeed, but then fail when the server returns the maximum batch size.
- Large binary data: today MCP does not yet support large binary data so quite a few use cases that are really interesting do not work well at all yet. You end up with all kinds of weird workarounds such as pre-signed URLs to allow file uploads then to happen through non MCP channels.
- Composable tool search: the MCP server might know better than the MCP client which tool is appropriate for a task. But there is no good mechanism today that allows a harness to fan out tool searches across multiple MCP servers. It's all emergent behavior and it does not scale well to multiple active servers.
Future of Codemode
So where does this leave us? Is this a reversal of what I wrote a year ago where I encouraged CLIs? I don't think so. In fact, the MCP ecosystem from my perspective picked up on exactly what we pointed out a year ago works: code. But Codemode goes beyond MCP in that it can act as a capable mechanism within the harness to express more freedom for the agent.
There are however also some things that we still need to figure out. For one, durability with Codemode is trickier. We might have to adopt some ideas from durable workflow engines here to snapshot invocations. Or maybe, something like Starlark is a better composition language than JavaScript given its deterministic nature.
Images, binary data and just the inability of this pattern to work with smaller models is also something that needs to be fleshed out. So it's for sure not a perfect solution yet, but it's quite a useful pattern that I expect us to leverage more.
- Structured content: Codemode wants calls to return some nicely formatted JSON. So that needs to come back from the server, and many don't do that yet. The
-
- October 05, 2026
-
π r/LocalLLaMA PewDiePie getting banned twice by OpenAI while making a local model is top-tier comedy π rss
So PewDiePie decides to fine-tune a local AI model called Ajax on his own computer. Pretty normal stuff for local model fans.
To make his dataset, he uses OpenAI's API. OpenAI catches him using their outputs to train another model, flags his account for breaking their terms, and bans him.
He files an appeal, gets unbanned, goes right back to pulling data from the API, and immediately gets banned a second time.
So instead of giving up, he uses open-source tools to remove the model's built-in refusals, cleans out the preachy fluff, and starts building a fully local 9B agent.
OpenAI spent years scraping the whole public internet for free data, but the second someone uses their output to train a local file, it's an emergency ban.
In trying to enforce their rules, all OpenAI really did was give open-source models a massive free advertisement to millions of people.
What a time to run models on your own hardware.
submitted by /u/rodrigodevbits
[link] [comments] -
π earendil-works/pi v1.0.4 release
New Features
- Tool patterns and
--no-mcp:--toolsand--exclude-toolsaccept*patterns, for example--tools read,codemode,'mcp__radius__*'keeps only one MCP server's tools.--toolsnow keeps MCP tools unless an entry starts withmcp__, and--no-mcpturns off MCP for one run. See Tools and MCP tools. - Codemode persists images :
tools.read()on an image file now gives back an image block thatimage()can show. See Call tools.
Added
- Added
*patterns to--toolsand--exclude-tools, for example--tools read,codemode,'mcp__radius__*' - Added
--no-mcpto disable the built-in MCP support for one run
Fixed
- Fixed syntax highlighting losing colors after the first line of multiline strings and comments in fenced code blocks (#10143)
- Fixed codemode scripts not receiving images from
read:tools.read()now resolves to an image block for image files, whichimage()shows (#10251) - Fixed MCP OAuth sign-in failing with
invalid_redirect_urion servers with OpenID Connect client registration, such asmcp.modem.dev: pi now registers as a native client (#10493) - Fixed
--toolsremoving MCP tools, which leftpi --tools codemodewithout any MCP servers.--toolsnow keeps MCP tools unless an entry starts withmcp__ - Fixed MCP session shutdown returning while a server was still connecting, leaving its transport open until the server answered or timed out (#10249)
- Fixed system prompt rules and the skills hint naming tools hidden by
prepareLoadout. Hidden tools are left out of the rules, the skills hint names no tool when the file reader is hidden, andcodemodeshows each tool's prompt guidelines with its declaration;ToolLoadoutgainsgetPromptGuidelines()(#10343) - Fixed Bedrock requests that fail with
The pending stream has been canceledafter a stalled HTTP/2 connection not being retried automatically (#10379) - Fixed codemode scripts that patch built-ins (for example
Array.prototype.toJSON = ...) crashing pi and leaving the tool call unsettled. Built-ins are now frozen before the script runs, so such patches have no effect (#10444)
- Tool patterns and
-
π exe.dev The Hardest Working Header on the Internet rss
When your browser reads this blog, it looks up
blog.exe.devusing DNS, and sends an HTTP request with aHost: blog.exe.devheader to our servers. Our anycast network receives the request and usesHost: blog.exe.devto figure out which of all the exe VMs to proxy your request to. Load balancers, CDNs, web serversβ¦ the modern web works because of the humbleHostheader. (SSH does not have such a header, alas.)exe.dev lets you bring your own custom domain to point to your VM. Thanks to Letβs Encrypt, we're able to provision the certificate on your behalf. And, now, we also let you provision a wildcard certificate, so you can have, for example,
*.example.comall point to the same VM, and you can route accordingly.domain add vm-name *.example.comin our lobby is the place to get started, and it'll walk you through it.An earlier version of this blog post falsely accused Certificate Transparency of delaying how quickly custom domains started working. This is no longer a problem! (DNS time-to-live configuration remains an occasional stumbling block, though.)
-
π r/LocalLLaMA When Redditors come in here and ask why we run LLMs, this is why: Big AI is watching. rss
Anthropic Reports Florida Woman's Claude 'Diary' Threat to Law Enforcement
And this time it wasn't the AI model that made the LEO referral. It was the "human review team".
The frontier AI companies are watching your input. And people say "Well I'm not interesting or important enough for them to care". Well.....not necessarily.
If you're using hosted frontier to work on mathematics or cutting edge science, they're watching and may steal your work.
If you're venting or otherwise writing in a "private" session using AI, they'll see that and report you to police. Notice I didn't see any mention of what the model's role in facilitating the discussion was.
Keep your stuff private, folks. Hosted AI is the new "Big Brother" conduit.
submitted by /u/Big_Wave9732
[link] [comments] -
π backnotprop/plannotator v0.28.4 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.3 | Typing into your agent while it answers an Ask no longer streams into Plannotator
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right sessionWhat's New in v0.28.4
Seven PRs, one from a community contributor. Your comments now survive an agent editing the file, the agent can see and close the reviews it opened, and two fixes make sure everything you write reaches the agent.
Your comments come back after the agent edits the file
Annotate drafts used to be saved under the file's content. When an agent edited the file and opened a new review, your unsent comments didn't come back. Drafts are now also saved under the file's path, so reopening the file brings them back even after it changed. Comments whose text moved re-anchor to where the text is now, and comments whose text is gone are kept with an Unanchored tag instead of disappearing. This also works per file in folder reviews, so a file's comments carry between a folder review and a review of that file alone.
Exported feedback follows the same rule: a restored comment is labelled with the line its text is on now, and a comment whose text was deleted is sent without a line number rather than a wrong one. Sending your decision still clears the draft.
One visible change: a comment that can't find its text anywhere now always shows the Unanchored tag. Before, some of those (share-link imports, comments posted by outside tools) failed silently.
The agent can list and close the reviews it opened
With the Claude Code mod, the
plannotatortool has two new actions.listshows the reviews opened in this conversation (by the tool or your/plannotator-*commands) with how many of your comments are unsent.closecloses one or all of them. Closing works like your own Close but keeps your unsent comments as a draft, sends nothing back to the agent, and the tab says the agent closed it. Plan reviews are listed but can't be closed this way. Every result and decision message now carries a short session id (pn-β¦) so the agent can tell its reviews apart.Review servers now refuse a second decision once a review is decided, so late feedback can no longer report success after a close and then be lost. With an older
plannotatorbinary the mod only stops a review's process after confirming it is Plannotator; on CLIs 0.24 to 0.28.3 a decision made in the second before such a stop can still be lost, so update the binary.(#1709)
Review feedback on the PR description no longer gets dropped
Code review used to treat any feedback with no code comments as the "posted to GitHub/GitLab/Bitbucket" status message. Comments on the PR description, PR comment notes and VS Code editor comments travel only in the feedback text, so a review made of only those was silently dropped under the Claude Code mod. The page now marks a real platform post explicitly, and every host (the Claude Code mod, OpenCode and Pi) delivers everything else, with the usual "address these changes" framing. The Claude Code plugin also guards against the old behavior when it runs with a
plannotatorbinary from 0.28.0 to 0.28.3, but updating the binary is the real fix.(#1719)
Pi's own thinking levels in Ask AI
When Ask AI uses the Pi provider (no connected session, for example in remote mode), each model now offers exactly the thinking levels Pi reports for it: no Off where the model can't turn reasoning off, Max and XHigh only where the model supports them, and no picker for models without reasoning. Auto sends nothing and leaves Pi's default. Levels are only offered on Pi 0.84.3 or newer, because older Pi versions saved the chosen level as your global default. Model names now read "Name (provider)".
(#1704, by @josdirksen)
Additional Changes
- One-click π on HTML elements. Clicking an element on an HTML page opens the comment box, which now has a small π button again. One click marks the element (or a shift-clicked group) "Looks good". It turns off as soon as you type, so it can't throw away a comment (#1712).
- Cleaner note boxes. The keyboard hints under the header's note composer, the small-screen note dialog and the review sidebar's general comment box are gone. ββ΅ still sends and Esc still goes back (#1711).
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- feat(pi): offer Pi's thinking levels in Ask AI by @josdirksen in #1704
- fix(ui): drop the keyboard hint under the decision note composer by @backnotprop in #1711
- feat(ui): bring the one-click thumbs-up back to the HTML pinpoint composer by @backnotprop in #1712
- feat(tool): contract v2 with session ids, list and close by @backnotprop in #1709
- Annotate drafts follow the file's path by @backnotprop in #1710
- fix(review): mark the PR-platform status post explicitly by @backnotprop in #1719
- fix(annotate): true line labels and Unanchored chips after a restore across an edit by @backnotprop in #1717
Contributors
@josdirksen brought Pi's thinking levels into Ask AI, reading them from the installed Pi so each model offers exactly what it supports.
Full Changelog :
v0.28.3...v0.28.4 -
π smol-machines/smolvm smolvm v1.23.6 release
What's Changed
- Mark a machine initialized once an API start pulled its image by @LoganGrasby in #1572
- Boot pack machines with a 512 MiB packed-layer DAX window by @LoganGrasby in #1506
- Size the server's checkpoint caches for its disk and drop an extraction's marker before removing it by @BinSquare in #1573
- Bump the workspace to 1.23.6 by @BinSquare in #1574
Full Changelog :
v1.23.5...v1.23.6 -
π blacktop/ida-mcp-rs v9.4.5 release
Full Changelog :
v9.4.4...v9.4.5 -
π r/LocalLLaMA How is it possible that qwen 27b is so good? When GPT 4o had a trillion parameters and was worse? rss
| Picture from a post in r/amodei . People were praising qwen and I'm just wondering, what kind of new technologies are at play here? Does qwen just have "better" pre training data? That's more high quality? submitted by /u/SignificantZebra5883
[link] [comments]
---|--- -
π r/LocalLLaMA Make no mistake, selling 64 GB DGX Spark variants at the same cost as the original 128 GB is straight drug dealer behavior. rss
It's something straight out of the season one of 'The Wire': you take the product, dilute it, and sell it at practically the same cost. It's some "Stringer" Bell shit. We should call the 64gbs "Stepped-ons" from now on.
submitted by /u/blacklandothegambler
[link] [comments] -
π smol-machines/smolvm smolvm v1.23.5 release
What's Changed
- Run the clone re-mint as a plain shell so it never leaves an orphan for the guest's init to reap by @BinSquare in #1570
- Bump the workspace to 1.23.5 by @BinSquare in #1571
Full Changelog :
v1.23.4...v1.23.5 -
π MetaBrainz Happening NOW: AMA with Silona Bonewald, MetaBrainz Foundation Executive Director rss
Silona Bonewald, our new Executive Director, is NOW _hosting an AMA (Ask Me Anything)_ in this forum thread.
Please respect the code of conduct, as you always do!
You are welcome to post questions in the thread later, and Silona will do her best to answer them when she has the time. We will close the thread after a couple of days - though of course the door remains open to chat with the MetaBrainz team any time in the future!
You can find more information about Silona on our Executive Director announcement post.
-
π daaain/claude-code-log Release 1.7.0 release
Changed
- (Claude) Upgrade wenmode to 0.15.2 and bump to 1.7.0 (#340)
- Release to PyPI from a tag-driven, maintainer-approved workflow (#341)
- (Claude) Show the logical-parent arrow on a /compact boundary's uuid line (#338)
- (Claude) Drop the host icon before a tool_result title that has its own (#337)
- Keep a Markdown message's body when its title is empty (#336)
- fix(search): report an unreadable cache as such, not as a missing FTS5 (#334)
- Continue the rewind branch across a /compact boundary (#331)
- Run the fail-fast just ci steps before the test suite
- Switch the Markdown engine from mistune to wenmode (#329)
- Resolve commit SHAs from one rev-list per repository (#330)
- Render peer agent messages as teammate cards instead of steering (#309) (#328)
- Apply the cache's write pragmas to every writing connection (#326)
- Link teammate subagent transcripts spawned by the Agent tool (#316)
- Re-parse cached entries when the shape of what we cache changes (#320) (#322)
- Make watch ticks cheap (#321)
- Update some README bits
Full Changelog :
1.6.0...1.7.0 -
π smol-machines/smolvm smolvm v1.23.4 release
What's Changed
- Let the first machine start create the default machine's disks by @BinSquare in #1566
- Bump the workspace to 1.23.3 by @BinSquare in #1563
- Keep the shared extraction trim running when a machine leases a pre-digest or vanished extraction by @BinSquare in #1568
- Bump the workspace to 1.23.4 by @BinSquare in #1569
Full Changelog :
v1.23.3...v1.23.4 -
π smol-machines/smolvm smolvm v1.23.3 release
What's Changed
- Make cold checkpoint restores stop re-reading the artifact and waiting on RAM fsync by @BinSquare in #1552
- Keep a request queued behind a start from stopping the VM that start booted by @BinSquare in #1555
- Stop the systemd scope a refused start created by @BinSquare in #1556
- Make checkpoint capture fast for restored machines and multi-GB state by @BinSquare in #1558
- Reclaim shared checkpoint extractions no machine leases beyond the restore cache bound by @BinSquare in #1557
- Remove the unpublished smolvm-embedded and smolvm-rollout SDKs by @BinSquare in #1559
- Flatten only a branch source's immutable disk layers, in place, so the chain stays short without copying a layer the VMM can write by @BinSquare in #1550
- Never let an implicit start restart a machine that is up, and log why a VM is restarted by @BinSquare in #1565
- Keep a shared extraction while its RAM is still being written back by @BinSquare in #1560
- Bump the workspace to 1.23.3 by @BinSquare in #1567
Full Changelog :
v1.23.2...v1.23.3 -
π backnotprop/plannotator v0.28.3 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right session
v0.27.18 | Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushesWhat's New in v0.28.3
A focused fix for Ask this session, the 0.28 feature that sends Ask AI questions to the agent session that opened Plannotator.
Typing into your agent while it answers no longer streams into Plannotator
When you asked a question from Plannotator's Ask AI and then typed into the agent yourself while it was answering, the agent's reply to your message streamed into the Ask AI panel as if it were the answer, and a Stop in Plannotator could cancel your own work in the agent.
Now, as soon as a message Plannotator did not send enters that turn, Plannotator stops streaming. It keeps the part of the answer it already had and adds a short note ("You typed into this session while it was answering, so the rest of the reply went to your prompt", or a neutral version when it was not you). After that, Stop only closes the question in Plannotator, and "Interrupt and ask now" will not stop the agent, so whatever you asked runs to completion.
This works the same way on Claude Code (with the Plannotator mod), Pi and OpenCode 2. It is careful about what counts:
- If the agent had already finished its answer when your message arrived, the question keeps the full answer.
- Agent-side events do not count: a background task finishing on Claude Code, OpenCode's own notices and compaction steps, Plannotator's own notices on Pi, and messages from other Claude sessions.
- On Pi, the protection holds while Pi retries after an error.
- With an older
plannotatorbinary, the plugin settles the question with the partial answer and the note instead of an error.
(#1703)
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- fix(ask): a prompt typed into an Ask-this-session turn takes it over on every host by @backnotprop in #1703
Full Changelog :
v0.28.2...v0.28.3 -
π earendil-works/pi v1.0.3 release
New Features
- Azure Foundry Chat Completions β The
azureprovider (renamed fromazure-openai-responses) now also serves Foundry Chat Completions deployments, starting withazure/deepseek-v4-pro. See Azure OpenAI. - Codemode images saved to files β
image()also writes each image to a temp file and names the path in the result, so later turns can copy or move generated images. See Generate images.
Breaking Changes
- Renamed the Azure provider from
azure-openai-responsestoazure. Rename the provider key inauth.json(or run/loginagain), inmodels.json, and insettings.json(defaultProvider,enabledModelspatterns, andmodelThinkingLevelskeys). Sessions that used the old provider fall back to another model when resumed, and their prompt cache is not reused. TheAZURE_OPENAI_*environment variables are unchanged (#9714 by @jsanter27)
Added
- Added Azure Foundry Chat Completions deployments, starting with
azure/deepseek-v4-pro(#9645, #9714 by @jsanter27)
Changed
- Codemode
image()now also saves each image to a temp file and names the path in the result, so later turns can copy or move generated images (#10310) - Output files (full text of truncated tool output, binary MCP resources, codemode images) are now readable only by the user
Home/Endnow always move the editor cursor to the line start/end; fullscreen transcript top/bottom moved toCtrl+Home/Ctrl+End, which no longer move the editor cursor (#10314)
Fixed
- Fixed subscription logins such as Sign in with ChatGPT failing with
refresh_token_invalidatedafter a request was cancelled during an OAuth token refresh - Fixed codemode failing for the rest of a session after a pnpm global update removed the running install, and added a restart hint when errors occur after pi was updated or removed on disk (#10439)
- Fixed interactive sessions reporting a
read EIOorsetRawMode EIOcrash (and asking to run /bug) when the terminal went away, e.g. after closing the window or resuming a suspended pi in a closed terminal
- Azure Foundry Chat Completions β The
-
π backnotprop/plannotator v0.28.2 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right session
v0.27.18 | Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushes
v0.27.17 | Diagram files open in the diagram viewer, OpenCode switches model with agent, idle review stops polling the git remote, Tree is the default review viewWhat's New in v0.28.2
v0.28.2 is a patch release with three pull requests, all from @backnotprop. It fixes question cards that cut off wrapped choices, makes image pins in HTML pages name the right file, and stops Done with nothing to send from starting an agent turn.
Question cards show wrapped choices and block markdown
Choices written as plain bullets that wrap onto several lines were cut at the first line, and the rest of each choice ended up in the question's text above the options. They now show in full: the first phrase is the label and the rest is the description. A
Recommended:line that wraps is read as a whole, and a recommendation that names a choice in its first sentence marks that choice. Choices written as task-list items (- [ ]) split as before.The text of a question now renders like the rest of the document. Tables were a flat run of pipes; tables, lists, code blocks, quotes and images inside a question now look as they do in the plan or file. Comments on a table cell or code line inside a question attach to the question card and restore after a reload.
Answers you saved on 0.28.1 still show the choice you picked, and a recommendation that names a lettered option (
b. β¦) marks that option.Image pins name the file the page shows
When you pin an image in an HTML page, the feedback heading names the file the page displays even when the image has no
srcattribute. This coverssrcset, lazy-loadeddata-srcimages,<picture>and a video'sposteror<source>. Before, the heading named nothing or adata:placeholder. Query strings are still dropped from the name.Comments made in the version diff are now listed after the document's other comments, in diff order, instead of first. Exports without diff comments are unchanged.
Done with nothing to send starts no agent turn
Clicking Done in an annotate session with no annotations used to make the agent start a turn that read "User reviewed the document and has no feedback. Please address the annotation feedback above." That no longer happens on Claude Code (with the mod), Pi, OpenCode 1 and 2, Amp and Droid. The session closes, the host logs that nothing was sent, and the agent is not prompted.
/plannotator-lastbehaves the same way.The Plannotator binary must be updated for this: the 0.28.0 and 0.28.1 binaries do not send the signal, so Claude Code, OpenCode's CLI bridge, Amp and Droid keep the old behavior until you run the install script. Pi and the OpenCode embedded runtime ship their own server, so the plugin update is enough. Hosts that run Plannotator through a skill (Codex, Gemini, and Claude Code with the mod off) still pass the same sentence on, unchanged. For scripts,
annotate --jsongains an additivenothingToSend: truefield in this case; other output is unchanged.Counting is fixed too. In a folder annotate session, the "N comments" figure, the host record and the feedback history counted only the open document's comments. They now count every document's comments. The same fix applies to
/plannotator-lastwith several messages selected, which also now includes comments posted by outside tools (agents, WebMCP); before, those were missing from the exported feedback. The feedback history records which document each comment belongs to.
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- fix(questions): plain-bullet choices keep their wrapped lines; question context renders block markdown by @backnotprop in #1699
- fix(questions): answers saved under a 0.28.1 label still show their pick by @backnotprop in #1702
- fix(export): image headings name the resolved file; diff comments sort after the document by @backnotprop in #1700
- fix(annotate): a bare Done starts no agent turn on any plugin host; submits count every document's and message's comments by @backnotprop in #1701
Full Changelog :
v0.28.1...v0.28.2 -
π blacktop/ida-mcp-rs IDA Pro MCP Server v9.5.0-beta.5 release
Prerelease for the IDA Pro 9.5 beta on macOS (Apple Silicon). Requires IDA Pro 9.5 with a valid license.
brew upgrade --cask ida-mcp@betaRestart your MCP client afterwards; sessions that are already running keep the old binary.
Stuck calls are recoverable over HTTP too
(#58)
serve-httpwith its default single worker now runs IDA in one supervised child process, as default stdio has since beta.3. A call that overruns itstimeout_secs, or the operation watchdog (--workspace-worker-op-timeout- secs), kills the child and returns an error saying the database is closed and to callopen_idbagain. The next open starts a fresh worker.All HTTP sessions still share that one database:
- Cancelling a call, or closing the session that sent it, no longer stops a call that has already reached the worker. It keeps running under its timeout, so one client cannot close the database the others are using. A call that has not started yet is dropped.
- A close token issued for one database cannot close a newer database opened after a replacement.
Pooled HTTP (
--max-workers N) and--workspaceare unchanged.Shutdown saves before it stops work
On stdin EOF, SIGTERM, SIGINT, SIGQUIT, or SIGHUP, default stdio and HTTP now let the running operation finish and save the database before cancelling background tasks, all within 120 seconds; after that the child is retired. Previously background analysis was cancelled first, which could kill the worker and lose unsaved edits, and the save had only 10 seconds. Shutdown can now take up to 120 seconds when a call or save is still running.
Known issue
- Every clean exit of the default stdio server logs
WARN marked IDA child worker dead. It is harmless.
Checksum
ida-mcp_9.5.0-beta.5_Darwin_arm64.tar.gzSHA-256:1f376b54b0bc71ebff5c7e572c2d01ffdadb5ee526342fea204a563e508d9719 -
π backnotprop/plannotator v0.28.1 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right session
v0.27.18 | Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushes
v0.27.17 | Diagram files open in the diagram viewer, OpenCode switches model with agent, idle review stops polling the git remote, Tree is the default review view
v0.27.16 | Themed diagrams on Mermaid 12, comment on any node or edge, patch-file review, embedded HTML documents renderWhat's New in v0.28.1
v0.28.1 is a patch release with five pull requests, all from @backnotprop. It fixes feedback that was exported twice in folder annotate sessions, adds Ask AI to diagram comments, makes image pins in HTML pages say which image they point at, and fixes three OpenCode problems found while testing v0.28.0.
Folder annotate no longer sends each comment twice
In a folder annotate session, every comment on the open file was exported twice: once under "Folder Feedback" and again under "Linked Document Feedback". The second copy was also a weaker one. It was sorted by block id as text (block 10 before block 2) and left out the
[In diff content]label, quick-label headings and tips, the Label Summary, and reply threading. This affected every host, because the export is built in the browser.Each comment now appears once, in document order, with full detail. In a folder session the section is titled "Folder Document Feedback" and lists each file with its comments under its path. The same fix covers two related cases:
- Plan review submitted while a linked document was open dropped the plan's own comments. They are now included.
- When a file session opened a copy of its own page (a "Home" link, for example), comments on that copy were dropped from the export while a linked document was open. They are now exported under that file's path.
Plain plan review output is unchanged for comments, deletions and general feedback.
Ask AI from a diagram comment
The comment box on a Mermaid or Graphviz diagram now has an Ask AI button, next to Cancel and Comment. It works inline and in the popout, for diagrams in fenced code blocks and for diagram files (
.mmd,.dot). The button is disabled until you type a question, and Enter still posts the comment.The question carries the node, edge or cluster you clicked, its line in the document, the diagram type, and an excerpt of the diagram source with line numbers. The excerpt is capped at 40 lines or 4000 characters and always includes the part you picked. Asking from the popout closes the popout, so the answer in the panel is visible.
Pinning an image tells the agent which image
In HTML annotate, pinning an image or another element with no text recorded only its kind, as
[element: Image]. Ask this session answered that it could see an image was selected but not which one.The description now includes the element's label, its accessible name (aria- label, alt text, title) and, for media, the file name:
[element: Image "Team photo" (team.jpg)],[element: Button "Open menu"],[element: Frame (prototype.html)]. Query strings are dropped and adata:URL is shortened to its media type. This appears in the comment, in the exported feedback, and in Ask AI questions, which now also include the pinned element's details. In HTML file sessions, image paths are reported as written in the page (office.png) instead of Plannotator's internal asset URL. Pins saved earlier still restore.OpenCode fixes
Three problems found while testing v0.28.0:
- OpenCode 1 shows the session URL for commands.
/plannotator-review,/plannotator-annotateand/plannotator-lastonly wrote the URL to OpenCode's log file, so a remote or SSH user never saw it. They now show it in a toast, the way plan review already did, in local and remote mode. - OpenCode 1 answers once per feedback. OpenCode 1 always runs a turn on the command's own message, and Plannotator was emptying that message and sending the feedback separately, so the model replied twice. The feedback now rides on the command's own message, and the agent and model are the same as before. A command with nothing to send (Close, or Done with no notes) still runs one turn on an empty message; OpenCode 1 gives plugins no way to skip it.
- OpenCode 2 no longer feeds the "session ready" notice to the model. After a plan decision, the model could answer with
Plannotator session ready: <url>instead of your feedback. The notice stays visible in the transcript but is removed from what the model receives.
Commands you run afterwards still go to the agent you ran them on, as in 0.28.0.
Additional Changes
- Comment box trimmed. The
ββ΅/Ctrl+Enterhint is gone from the comment box (the shortcut still works), and HTML pages no longer show a "Looks good" button in the comment box. To leave a thumbs-up on an HTML page, select text and use the π in the toolbar. (#1693)
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- fix(ui): drop the ββ΅ hint from the comment popover and the composer's Looks good on HTML by @backnotprop in #1693
- fix(annotate): tell the agent which image (or element) a pinpoint points at by @backnotprop in #1694
- feat(diagrams): Ask AI from a diagram comment by @backnotprop in #1695
- fix(annotate): folder sessions export each comment once by @backnotprop in #1696
- fix(opencode): remote URL toasts on OpenCode 1, one turn per feedback, notice ordering by @backnotprop in #1697
- fix(opencode): keep the user's agent for follow-up OpenCode 1 commands by @backnotprop in #1698
Full Changelog :
v0.28.0...v0.28.1 -
π smol-machines/smolvm smolvm v1.23.2 release
What's Changed
- Show the Homebrew install in the README by @BinSquare in #1551
- Finish a restore instead of relaunching the workload when exec wakes a restored machine by @BinSquare in #1553
- Bump the workspace to 1.23.2 by @BinSquare in #1554
Full Changelog :
v1.23.1...v1.23.2 -
π blacktop/ida-mcp-rs IDA Pro MCP Server v9.5.0-beta.4 release
Prerelease for the IDA Pro 9.5 beta on macOS (Apple Silicon). Requires IDA Pro 9.5 with a valid license.
brew upgrade --cask ida-mcp@betaRestart your MCP client afterwards; sessions that are already running keep the old binary.
Decompiler local variables () Three new tools work on Hex-Rays locals and arguments: list_lvars lists a function's locals and arguments with name, type, location, size, definition address, whether it is an argument, and whether the name or type was set by a user. Results are paginated (offset, limit up to 1000) and returned as structured content. rename_lvar renames one local. set_lvar_type parses a C type declaration and applies it to one local. Types Hex-Rays does not accept for that variable, such as void or a function type, are rejected. Pick the function with one address or an exact target_name, and the local with its exact, unique name from list_lvars. Ambiguous or misspelled names change nothing. Edits appear in the next decompilation, are stored in the database, and survive save_idb and reopening. list_lvars is in the decompile toolset, rename_lvar in editing, and set_lvar_type in types; --read-only hides both edit tools. The 28-tool lean profile is unchanged. Add the new tools to it with: ida-mcp --profile=lean --tools=list_lvars,rename_lvar,set_lvar_type The full tool list is now 74 tools, about 57 KB of schemas. Known issues
- Single-worker
serve-httpstill runs IDA in the server process, so a stuck call there is not recoverable (#58). Default stdio, pooled HTTP, and--workspaceuse supervised child workers. - Every clean exit of the default stdio server logs
WARN marked IDA child worker dead. It is harmless.
Checksum
ida-mcp_9.5.0-beta.4_Darwin_arm64.tar.gzSHA-256:b1525f79a46e469490017dba31b43970bafb84744df9c13466bfd997cced6b67 - Single-worker
-
π backnotprop/plannotator v0.28.0 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right session
v0.27.18 | Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushes
v0.27.17 | Diagram files open in the diagram viewer, OpenCode switches model with agent, idle review stops polling the git remote, Tree is the default review view
v0.27.16 | Themed diagrams on Mermaid 12, comment on any node or edge, patch-file review, embedded HTML documents render
v0.27.15 | Plannotator TUI and Herdr Annotate announcement, element context on pinpoints, HTML links open as linked documents, All files panel, Classic diff defaultWhat's New in v0.28.0 Plannotator now connects to the agent session that opened it. Ask AI can be answered by your Claude Code, Pi, or OpenCode 2 session instead of a separate AI, and in Claude Code and Pi the agent no longer sits waiting while you review: your decision arrives later as a message. This release has 24 pull requests, two of them from community contributors, including one first-time contributor. Ask this session When Plannotator was opened by Claude Code, Pi, or OpenCode 2, a question you ask in Ask AI goes to that agent session. It shows up in the agent's chat as a real turn, the agent answers with the context it already has and can use its own tools, and the answer streams back into the Ask AI panel. The panel reads "Ask this session Β· Claude Code" (or Pi, or OpenCode). When a session is connected, it is the only Ask AI option, so there is no provider or model picker. A provider you saved earlier is left alone and still applies in sessions without a connection, and Review Agents, Code Tour, and Guided Review keep their own model pickers. If the agent is busy, you can choose "Ask when it finishes" or "Interrupt and ask now". Stopping a question cancels only that question; Plannotator never interrupts a turn on its own. If the session has ended, Ask AI says it can no longer reach it. Where it works: Claude Code: plan review, code review, annotate, and /plannotator-last, through the Claude Code mod described below. Pi: plan review, code review, annotate, and /plannotator-last. OpenCode 2: code review, annotate, and /plannotator-last as real turns. During plan review OpenCode is still waiting on submit_plan, so Ask AI gives a "Quick answer from this session" from the conversation, without tools, and writes nothing to the transcript. Not connected: OpenCode 1, Claude Code without the mod, remote mode, and --tailscale sessions. These keep the separate AI providers exactly as before. The first time you open Plannotator from a connected session, a short panel with a demo video explains the feature. It appears once, only when the session really is connected, and only before you start working on the page. It links to the Ask this session guide. (#1668, #1671, #1685, #1690) Claude Code no longer waits while you review On Claude Code 2.1.287 and later, in the interactive terminal, the Plannotator plugin now runs as a Claude Code mod, and it is on by default. Plan review, /plannotator-review, /plannotator-annotate, and /plannotator-last open in the browser and hand control back to Claude right away. When you decide, the decision arrives in the chat as a message from the plannotator plugin, and Claude acts on it. While the review is open you can keep talking to Claude, and Ask this session works. Plan review under the mod works like this: When Claude calls ExitPlanMode, the review opens and Claude is told the plan is not approved yet. Plan mode stays on. If Claude revises the plan while the review is open, the same tab updates to the new version and keeps your comments. A decision made on an older version is refused, and the tab loads the new one so you can decide again. After you approve, Claude calls ExitPlanMode once more and proceeds with the exact text you approved, in the permission mode you picked. Denials and answered questions arrive as messages, using the same prompts as before. Decisions with nothing to send (Done with no comments, an LGTM, Close) only log a line and do not start a turn. Feedback over 12 KB is saved to a file that Claude is told to read. /plannotator-last keeps its picker of recent messages, so you can still annotate an earlier reply. Review servers keep running if Claude Code exits: run claude --continue or --resume, and the decision is delivered into that session. Older Claude Code, -p and SDK sessions, and Windows keep the classic flow, unchanged. To turn the mod off, set PLANNOTATOR_CLAUDE_MOD=0 or add { "claudeCodeMod": false } to ~/.plannotator/config.json; it takes effect the next time Claude Code starts. The plugin and the plannotator binary update separately, so update both (see Install / Update below). With an older binary, plan review falls back to the classic blocking review and Claude Code shows one line asking you to update; review, annotate, and last still open, without Ask this session. (#1672, #1686, #1684, #1691) Claude opens Plannotator through a tool instead of Bash Asking Claude to "open this in plannotator" used to make it run the CLI through Bash, which blocked Claude and left Ask AI on a separate AI. Under the mod, Claude now has a plannotator tool for annotate, review, and last. It opens Plannotator exactly the way the slash commands do and returns at once, and the decision arrives later as a message. With gate: true, an approval is sent back too, so Claude can continue once you sign off. The plannotator skill now tells agents to always use the tool when they have it, including for approvals. The installer refreshes the skill. Claude still sometimes reaches for the CLI. When it runs a simple command such as plannotator annotate notes.md --gate --json in the main session, the mod now opens it the same way the tool does. Only plain annotate <file> (with --gate or --markdown), review (with an optional target and --base), and last are taken over. Anything with other flags, shell syntax, an environment prefix, or a path to a dev build runs the real CLI, so scripts that depend on --require-approval or --result-file exit codes keep working. Commands from subagents always run as written. Strict gate flags don't fit a slash command, because nothing would read the result. Typing /plannotator-annotate notes.md --require-approval (or --result-file, or --hook) under the mod now opens nothing and tells you to run that command in a terminal. Before, the reviewer's feedback was lost. (#1673, #1687, #1688, #1692) Pi plan review no longer blocks the session On Pi, plannotator_submit_plan now returns as soon as the review opens, and the agent ends its turn. Your decision arrives later as a session message. An approval switches Pi to executing first, then sends the approval. A denial or answered questions come back as feedback. Planning restrictions stay in place until you approve, so nothing gets implemented early. If the agent resubmits while the review is open, the same tab updates to the new version and keeps your comments, as in Claude Code. Esc no longer cancels a plan review; leave plan mode to abandon it. Ask this session works during plan review. (#1670) Claude Code plan review shows the plan Claude just wrote Claude Code plan review sometimes opened the previous version of a plan, usually the one you had just denied. This happened when Claude edited the plan file and called ExitPlanMode in the same message, which recent models often do after a denial. Claude Code captured the plan text before the edit ran, so the review, the version history, and the approval all recorded the old text. Plannotator now reads Claude's plan file when Claude Code sends its path and the file is an absolute .md file under 2 MB, and falls back to the inline text otherwise. On approval, Claude proceeds with the plan you reviewed. Claude Code 2.1.285 fixed the cause upstream, and this covers everyone on older versions. (#1667, by @workflow) Question cards Pinpoint targets what you click. In Pinpoint mode, hovering or clicking any choice in a question card highlighted the question's prompt instead, and recorded no answer. This had been the case since question cards shipped in v0.27.23. A pinpoint click now pins the prompt, the context, or the choice you clicked, and clicking a radio or checkbox answers (#1683). Agents give questions some context. The question guidance in the plannotator skill now tells agents that a sentence or two of context helps reviewers answer faster, and that the context can include an image for visual questions (#1674). Decision questions. A Decision: when answered line, or Decision: , marks a question whose answer becomes a decision, and the card shows a decision tag for it (#1664). Image links in annotated HTML open in the lightbox
In a raw-HTML annotate session, a link to a local image, such as a thumbnail linking to a full-size render, used to show a "Can't open" toast. In Interact mode it now opens in the image lightbox; with pinpoint armed, the click still pins the element. Only images inside the page's own folder open this way, so nothing becomes readable that the page could not already load. While the lightbox is open, Esc closes it and
Mod+Entercannot submit a decision behind it, which also fixes the lightbox in markdown documents.(#1676)
Installer fixes
- The Claude Code mod is no longer stripped on install. Every installer run overwrote
hooks.jsonin Claude Code's marketplace copy of the repo with an old hard-coded version, and the next plugin install copied that file, without the mod, into the installed plugin. The installers no longer touch that file. If an earlier installer had rewritten it, they restore it from git, but only when it matches a shape an installer wrote, so your own edits are kept (#1689). - OpenCode 2 picks up the new plugin. The installers cleared only OpenCode 1's plugin cache. They now also clear OpenCode 2's cache under
~/.cache/opencode/npm/(or$XDG_CACHE_HOME), so re-running the installer loads the new version (#1689). install.cmdadds Plannotator to your PATH. The Claude Code hook now runs a bareplannotator, so it needs to be on PATH.install.ps1already added the install folder to the user PATH;install.cmdonly printed advice and now adds it too, without creating duplicates (#1692).
For embedders:
@plannotator/uiand@plannotator/core- Apache-2.0. Both packages now declare the Apache-2.0 license and ship its text (#1675).
DiffFileTree. A read-only file tree to put beside your own diff list. It is the code review file tree itself, moved into@plannotator/ui, with keyboard navigation and tree ARIA roles. Plannotator's review renders from the same parts and looks the same as before (#1678).- HTML frame height and fence themes. Hosts that size the HTML viewer to its content got a frame cut short when a page's first or last element had a margin; the measured height now includes those margins. A new
fenceThemeoption onconfigurePlannotatorUIlets a host choose the code block theme (#1677). - Question hooks.
findQuestionBlocks, a new@plannotator/core/markdown-structuresubpath, a footer slot for host actions on question cards, and an explicit save mode for answers (#1664).
These shipped as
@plannotator/core0.25.9 /@plannotator/ui0.49.0 and@plannotator/core0.25.10 /@plannotator/ui0.50.0 (#1682). Note for the next@plannotator/uirelease: the "Ask a separate AI instead" fallback helpers that shipped in 0.50.0 (resolveSessionBridgeFallback,findUsableSessionBridge,sessionAskFallbackLabel) are removed, because a connected session is now the only Ask AI option (#1685).Additional Changes
- Clear message when the OpenCode CLI is missing. Choosing the OpenCode provider without
opencodeon your PATH showed a rawENOENTerror. It now says the CLI is missing and suggests installing OpenCode or picking another provider (#1669, closing #1503, by @Aayushyaash). - One-line error when the remote port is taken. In remote mode Plannotator uses one fixed port, so a second session at the same time crashed with a stack trace. It now prints one line naming the port and suggesting
PLANNOTATOR_PORT, and exits with the usual startup-failure code (#1692). - Ask AI loads faster. Plannotator no longer asks the
piCLI for its models at startup, which could hold up Ask AI for up to 10 seconds. Pi's model list now loads when you pick Pi or start a Pi session, like Codex and OpenCode (#1692). - Closing the tab stops a Pi answer. The Pi server kept an Ask AI answer running after you closed the tab or asked a new question. It now stops it, as the server used by Claude Code and OpenCode already did (#1668).
- Docs. The Claude Code, OpenCode, Pi, and AI features guides cover the mod, Ask this session, the opt-out, and the corrected plugin update steps, and troubleshooting has a new entry for "Claude Code still waits for my review" (#1691).
Known issues
- Leaving plan mode during a review. Under the Claude Code mod, Claude is not blocked while a plan review is open. Plan mode stays on and Claude is told the plan is not approved, but if you leave plan mode yourself (Shift+Tab) and keep talking, Claude can start editing before you approve.
- Review servers outlive Claude Code. A review the mod started keeps running after Claude Code exits, so it can be reattached with
--continueor--resume. If you never resume that session, the server runs until you decide or close the tab. - One session at a time in remote mode. Remote mode uses one fixed port, so two sessions cannot run at once. The second one now stops with a clear message; set
PLANNOTATOR_PORTto run it on another port.
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- feat(questions): Decision flag, findQuestionBlocks, host footer slot by @backnotprop in #1664
- fix(hook): review Claude's plan file, not its stale inline snapshot by @workflow in #1667
- feat(ai): Ask this session (core + Pi) by @backnotprop in #1668
- fix(ai): show friendly error when opencode CLI is unavailable by @Aayushyaash in #1669
- feat(pi): non-blocking plan review, with Ask this session during review by @backnotprop in #1670
- feat(ai): Ask this session for OpenCode 2 (host-neutral pull bridge) by @backnotprop in #1671
- feat(claude-code): mod for non-blocking plan review, annotate, review and last, with Ask this session by @backnotprop in #1672
- feat(claude-code): plannotator tool for agent-initiated opens under the mod by @backnotprop in #1673
- docs(questions): suggest context and images in question blocks by @backnotprop in #1674
- chore(npm): Apache-2.0 license for @plannotator/ui and @plannotator/core by @backnotprop in #1675
- feat(annotate): open local image links in an HTML page in the image lightbox by @backnotprop in #1676
- fix(ui): srcdoc frame height with collapsed margins + fenceTheme host seam by @backnotprop in #1677
- feat(ui): embeddable read-only DiffFileTree shared with the code-review tree by @backnotprop in #1678
- chore: bump @plannotator/core 0.25.10 and @plannotator/ui 0.50.0 by @backnotprop in #1682
- fix(ui): pinpoint in a question card targets what was clicked, not the prompt by @backnotprop in #1683
- fix(claude-mod): restore the message picker for /plannotator-last by @backnotprop in #1684
- fix(ai): Ask AI uses only the session when a session bridge is present by @backnotprop in #1685
- feat(claude-mod): turn the Claude Code mod on by default by @backnotprop in #1686
- docs(skill): always use the plannotator tool over the CLI when you have it by @backnotprop in #1687
- feat(claude-mod): agent-run plannotator commands open through the mod, so Ask AI reaches the session by @backnotprop in #1688
- fix(install): stop stripping the Claude Code mod from the marketplace clone; clear OpenCode 2's plugin cache by @backnotprop in #1689
- feat(ui): first-run announcement for Ask this session and non-blocking reviews by @backnotprop in #1690
- docs: 0.28.0 β Claude Code mod on by default, Ask this session, correct plugin update steps by @backnotprop in #1691
- fix: 0.28.0 QA fixes β strict gates under the mod, clean port-in-use error, deferred pi discovery, Windows PATH by @backnotprop in #1692
New Contributors
Contributors
@workflow found why Claude Code plan review sometimes showed the plan that had just been denied. The write-up traced it to Claude Code capturing the plan before a same-message edit ran, with timings from a real session, and the PR came with tests and an end-to-end replay of the real hook event. First contribution to the project.
@Aayushyaash replaced the raw
ENOENTerror with a clear message when the OpenCode CLI is missing, a second contribution after the Ask AI dropdown fix in v0.27.25.Community
- @modelpath-dev pinpointed where the missing-CLI error should be caught in #1503
Full Changelog :
v0.27.25...v0.28.0 - The Claude Code mod is no longer stripped on install. Every installer run overwrote
-
π matklad Benchmark In Milliseconds rss
Benchmark In Milliseconds
Oct 5, 2026
How long should a micro benchmark run? My rule of thumb is to tweak the input size until the benchmark takes about 300ms, for the following reasons:
- Milliseconds are integers ranging from 1 to 999. Enough precision to notice even a small improvement, and easy to scan visually. No need for different units or floating points (compare
1.31swith239ms). - Anything faster than, say,
10msrisks being skewed by fixed costs (e.g, interpreter startup). Hundreds of milliseconds is an eternity for a computer, usually enough to make one-off overheads irrelevant without using fancier (= less robust) techniques to explicitly account for them. - For a human, hundreds of milliseconds is fast, but noticeable. Pushing numbers into human-perceptible range allows me to use my intuitive sense of time and speed, it doesnβt rely exclusively on numeracy. Itβs plain fun to see, as a result of optimization work, how a previously lagging CLI command becomes βinstantβ.
- But anything longer than a second makes iterating on the benchmark slower than it needs to be. Running a benchmark 10 times in a row to eyeball variance should be fast!
The imminently-to-be-stated assumption here is that the purpose of benchmarking isnβt so much a precise measurement of performance, but rather providing the author with enough intuition to make a correct decision.
- Milliseconds are integers ranging from 1 to 999. Enough precision to notice even a small improvement, and easy to scan visually. No need for different units or floating points (compare
-
π Filip Filmar Linux boots to a shell on Vreteno rss
Mainline Linux now boots to a shell on Vreteno, the RISC-V core written in TxHDL. It runs on the Alinx AX7A200B board, an Artix-7 FPGA with 1 GiB of DDR3 memory, at 100 MHz. The kernel runs in supervisor mode with virtual memory turned on. OpenSBI runs in machine mode below it, and a BusyBox shell runs in user mode above it. This post describes what the core needed for that, how the boot was brought up, and what is still missing.
-
π New Music Releases Thy Catafalque - TΓΆmbΓΆk rss
Thy Catafalque - a new release is available:
- 2026-10-05: TΓΆmbΓΆk (Single)
Amazon: Canada | Deutschland | France | United Kingdom | United States
Visit muspy for more information.
-