- β
- β
- October 07, 2026
-
π OmniNull/OmniWM Canary 20261007-0428 (2e08501e) release
Automated canary build of
main. It is signed and notarized like a release but skips the owner review, so treat it as unstable.- Commit:
2e08501ec4e0 - Base tag:
canary-20261006-1237-37412968268-1
Changes since canary-20261006-1237-37412968268-1
2e08501Merge PR #816: open the command palette in a specific mode from the CLI3773dc2Merge PR #801: keep CLI installation paths within the home directory7ebce39Fix mistranslated UI text in all 20 languages0182781Show Secure Input on OmniWM's icons and explain what to do380f368Play the launch overlay once per version, faster, over glass5c79342Explain Hidden Bar's Full Disk Access requirement and recheck it44e6daaRemember a requested palette mode even when it is already selected5fbe7e9Open the command palette in a specific mode from the CLI6a83d23Keep CLI installation paths within the home directory
- Commit:
-
π smol-machines/smolvm smolvm v1.24.0 release
What's Changed
- Fall back to a synchronous save for a stored checkpoint the VMM cannot defer by @LoganGrasby in #1584
- Pin a fork's golden layers on pause instead of packing them into every artifact by @LoganGrasby in #1585
- Rebuild the image seeds machines used recently when a server starts, so the first machine of each image after an upgrade does not wait for a seed build by @BinSquare in #1586
- Fix private CA registry pulls and image seeds by @BinSquare in #1587
- Wake TCP relay threads on readiness instead of polling every 10 ms by @BinSquare in #1588
- Let exec/interactive take an argument vector and run on pipes by @adam-r-kowalski in #1538
- Refuse pinned branch ports on a machine that publishes none by @BinSquare in #1589
- Let the embedded runtime keep a branch's source frozen as a reusable branch base by @BinSquare in #1590
- Bump version to 1.24.0 by @BinSquare in #1591
New Contributors
- @adam-r-kowalski made their first contribution in #1538
Full Changelog :
v1.23.7...v1.24.0 -
π New Music Releases Philip Glass - Philip Glass: Music for Film rss
Philip Glass - a new release is available:
- 2026-10-07: Philip Glass: Music for Film (Album)
Amazon: Canada | Deutschland | France | United Kingdom | United States
Visit muspy for more information.
-
- October 06, 2026
-
π Evan Schwartz Scour - September Update rss
Hi friends,
In September, Scour scoured 1.2 million articles (up from ~880,000 in August) from 28,568 feeds. Also, welcome to the 116 new users who signed up since my last product update email!
Here's what's new in the product:
π Library and Article Tabs
You can now find all of your saved, loved, and liked posts, as well as your full reading history, in the Library section.
Also, if you click Read on Scour for any article, that page now has tabs for the article's content, other posts that it cites and that cite it, and the feeds it was found in. Here's an example for a widely cited post.
π Expertise Level
Scour now tries to determine the level of expertise each post assumes and infers the level of expertise you have per topic (based on the wording of your interest is and the types of articles you click on or like). At least for me, this means I'm seeing far fewer beginner Rust questions from Reddit showing up in my feed. (For those in tech, this is powered by Jev.)
π Search for Feeds and People
Scour's Search will now show you results for feeds and authors, in addition to posts that match your query.
Relatedly, you can now follow individual authors as sources and Scour will try to show you their posts from any website they publish on.
ποΈ Detecting More Junk
Scour now detects and hides more junk, ranging from sales pages and SEO garbage to uninformative link roundups and low-value discussion threads. You should see more high-quality content in your feeds. By my current count, about 1 in 10 posts being shown before was some kind of junk that Scour now hides.
β‘ Faster Feed
I continue to obsess over making Scour feel super fast and snappy. In September the slowest feed loads got about 7x faster (p99 went from 2.1 seconds to 282 milliseconds) and the median feed load time got 2x faster (p50 went from 90 ms to 40 ms). This is also while ranking about 1.4x as much content as the month before.
πͺ¦ RIP Reddit Feeds
Unfortunately Reddit announced their plan to turn off RSS feeds on November 13th. This is how Scour checks which discussions are happening on Reddit and finds articles posted on different subreddits. After November 13th you'll no longer see links to the Reddit discussions from Scour π’.
π Some of My Favorite Posts
Here are some of my favorite articles I found on Scour in September:
- The biggest news in the tech / AI world was the release of TypeSafe's Jev model. These were some of the related articles that I found interesting:
- The Latent Space interview with TypeSafe's CEO, Jev: System One models for Prod, not God β with Diogo Almeida, CEO, TypeSafe AI.
- Fingerprints of Jev and Jev's Architecture Unmasked were interesting black box investigations into Jev's base model using the tokenizer and other externally visible properties.
- Sixteen Models Walk Into a Storefront gives a very nice breakdown of techniques that can be used to manipulate LLMs' assessments of which products to buy and how much to pay for products.
- Logo Design Trends in 2027 Favor Marks Someone Can Prove They Made. In the age of AI-generated glossy slop, this is no surprise, but it's a nice write-up.
- The engineering behind the US Strategic Petroleum Reserve. Quite random but an interesting read.
- I Judged My Mum for Overusing AI, Until I Caught Myself Doing Worse. I continue to appreciate Sid's commentary on the age of AI. This is very relatable.
Happy Scouring! - Evan
- The biggest news in the tech / AI world was the release of TypeSafe's Jev model. These were some of the related articles that I found interesting:
-
π roboflow/supervision supervision-0.30.8 release
v0.30.8 β Sharper video, cleaner labels
Video, YOLO labels, masks, VLM parsing and mAP all get more accurate.
VideoSinkkeeps OpenCV's video quality when OpenCV isn't installed.from_yoloreads pose labels as boxes instead of polygons.MeanAveragePrecisionscores class-agnostic runs right when only one side has class IDs.from_vlmreturns one Florence-2 detection per object, not one per polygon.from_inferencemasks no longer drift up to a pixel up and left.
Drop-in upgrade. Without OpenCV, videos get larger; YOLO labels with a negative width or height now raise
ValueError.β¨ Spotlights / highlights
sv.VideoSinkandsv.process_videokeep quality without OpenCVThe PyAV fallback left the encoder bit rate unset, so
mp4vandMJPGfiles came out at under half of whatcv2.VideoWriterwrites. It now uses OpenCV's rate settings for every codec except H.264. Files get larger andvp09may encode more slowly;codec="avc1"keeps files small where an H.264 encoder is available. (#2661)import supervision as sv video_info = sv.VideoInfo.from_video_path("in.mp4") with sv.VideoSink("out.mp4", video_info) as sink: # OpenCV not installed for frame in sv.get_video_frames_generator("in.mp4"): sink.write_frame(frame) # before: mp4v written at under half OpenCV's bit rate, visibly softer # now: same bit rate OpenCV's writer usesYOLO pose labels load as boxes
A pose row is a box followed by keypoints.
from_yoloused to parse the whole row as a polygon, giving wrong boxes and masks nobody asked for. It now reads the box and skips the keypoints thatkpt_shapedeclares. (#2655)ds = sv.DetectionDataset.from_yolo( images_directory_path="pose/images", annotations_directory_path="pose/labels", data_yaml_path="pose/data.yaml", # kpt_shape: [17, 3] ) # before: polygon-parsed boxes and masks # now: one box per rowClass-agnostic mAP with one-sided class IDs
A perfect match scored zero when only one side carried class IDs, such as SAM proposals checked against labeled ground truth. With
class_agnostic=True, both sides now count as one class.One Florence-2 detection per object
(#2648)
Florence-2 returns a segmented object as a list of polygons, one per connected region. An object split in two used to come back as two detections; the polygons now merge into one mask with one box around all of them.
Roboflow masks sit on the right pixels
(#2649)
from_inferencetruncated sub-pixel polygon vertices, shifting each mask up and left by up to a pixel. Vertices are now rounded, the way the COCO, YOLO, LabelMe and Pascal VOC loaders already do.π Migration guide
No migration required for this release.
π Notable changes
π± Changed
sv.DetectionDataset.from_yoloraisesValueErrornaming the annotation file when a label has a negative width or height; it used to load a box withx_minpastx_max, which madeDetections.areanegative and skewed IoU and NMS.as_yolonow orders the corners of a reversed box before measuring, so it no longer writes a file the loader refuses. (#2663)
π§ Fixed
sv.VideoSinkandsv.process_videowritemp4v,MJPGand other non-H.264 video at OpenCV's bit rate when OpenCV isn't installed. A frame rate of zero or less now raisesRuntimeErrorinsv.VideoSink, as it does with OpenCV. (#2661)sv.DetectionDataset.from_yoloreads the box of Ultralytics pose labels and skips their keypoints; akpt_shapeother than[K, 2]or[K, 3]raisesValueError. (#2655)sv.DetectionDataset.from_yolonames a malformed annotation line, one with too few values or, for OBB, not nine, in aValueErrorinstead of failing on an array shape. (#2665)sv.metrics.MeanAveragePrecision(class_agnostic=True)treats detections without class IDs as the same class as labeled ones, and unsigned class ID arrays no longer raiseOverflowErroron NumPy 2. (#2650)sv.Detections.from_vlmwithsv.VLM.FLORENCE_2merges the polygons of one instance into one detection for<REFERRING_EXPRESSION_SEGMENTATION>and<REGION_TO_SEGMENTATION>, and skips instances with no usable polygon. (#2648)sv.Detections.from_vlmwithsv.VLM.QWEN_2_5_VLorsv.VLM.QWEN_3_VLrecovers complete detections from a response cut off inside abbox_2darray or right after a complete object. (#2666)sv.Detections.from_inferencerounds polygon vertices to the nearest pixel before rasterising masks, and raisesValueErrorfor NaN or infinite vertices. (#2649)sv.xyxy_to_maskreturns an empty mask for a box entirely left of or above the image when its maximum coordinate is a negative fraction. (#2646)sv.Detections.get_anchors_coordinatescomputes axis-aligned midpoint anchors without integer overflow. (#2660)sv.LineZone.triggerages crossing history on frames whose detections lacktracker_id, so a reused track ID no longer creates a false crossing after the track expired. (#2644)sv.LineZoneAnnotator(text_orient_to_line=True)no longer raisesTypeErrorwithout OpenCV for lines drawn right to left. (#2659)- The Ultralytics, Inference and YOLO-NAS speed estimation examples measure elapsed time from frame indices; a vehicle missed in one frame of three was reported about 44% too fast. (#2654)
examples/speed_estimation/rfdetr_example.pyno longer raisesAttributeError:supervision._cv2now providesgetPerspectiveTransformandperspectiveTransform. (#2652)
π Contributors
- Mohammad Hijjawi (@MohammadHijjawi97, LinkedIn) β fixed video quality without OpenCV, Florence-2 instance merging and Roboflow mask rounding.
- Kari Pikkarainen (@kari-pikkarainen, LinkedIn) β fixed speed estimation timing, the NumPy
flipfallback and the perspective-transform fallbacks. - Miral Amin (@aminmiral) β made YOLO loading reject negative extents and name malformed lines.
- NIKHIL (@Nikhi00718) β fixed
LineZonehistory expiry and anchor overflow. - kevin (@kevin9327) β made Qwen parsing recover from cut-off responses.
- A Aswanth Raj (@aswanth-07, LinkedIn) β fixed class-agnostic mAP.
- Devulapalli Naga Sri Vaishnavi (@Vaishnavi220506) β fixed masks for off-frame fractional boxes.
- JANG BYUNGKUN (@8rulerstar) β fixed YOLO pose label loading.
Automated contributions:@dependabot
Full changelog :
0.30.7...0.30.8 -
π @HexRaysSA@infosec.exchange The upcoming IDA 9.5 adds 3οΈβ£ new decompilers and will deliver π platform mastodon
The upcoming IDA 9.5 adds 3οΈβ£ new decompilers and will deliver π platform updates.
The new decompilers:
βΎ Android DEX
βΎ Infineon TriCore
βΎ Qualcomm Hexagonπ Read the full blog to see the rest of the updates: https://hex- rays.com/blog/ida-9.5-three-new-decompilers
-
π Hex-Rays Blog IDA 9.5: 3 new decompilers and 10 platform updates rss
Good tooling starts with solid fundamentals. When every instruction decodes correctly and every function reads as clean pseudocode, you can trust what IDA shows and put your time into the binary itself. That holds whether the one reading the output is a person or an agent driving IDA. IDA 9.5 brings that reliability to three new architectures and sharpens it on several familiar ones.

-
π smol-machines/smolvm smolvm v1.23.7 release
What's Changed
- Start machines with a larger storage disk on their image's seed, grown to the requested size by @BinSquare in #1576
- Let as many asset compressors run at once as the host's CPUs fit by @LoganGrasby in #1577
- Let an egress watchlist entry block a match as well as record it by @BinSquare in #1540
- [Agent Experience] Add throwaway-machine skill packet to docs/ by @NickyHeC in #1542
- [Agent Experience] Add nine more skill packets to docs/ by @NickyHeC in #1543
- Refuse exec commands too long for the guest with a clear 400, and retry a layer download that hits a transient network error by @BinSquare in #1579
- [Agent Experience] Fix stale CLI help and examples by @NickyHeC in #1578
- Charge sparse checkpoint entries their stored bytes against the extraction cap, and keep the console of a VM that stopped answering by @BinSquare in #1580
- Make every smolvm process on a server's node follow the restore cache sizing the server chose by @BinSquare in #1581
- Bump version to 1.23.7 by @BinSquare in #1583
Full Changelog :
v1.23.6...v1.23.7 -
π hacker news ida pro references New comment by bri3d in "Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol" rss
I agree! Don't give it away!
Seriously, though, the popular Ghidra MCP is really badly architected; it's way better to rearchitect it or just script Ghidra directly. With that said, Opus 5.5 seems to have been trained on CoT from the popular Ghidra MCP. This makes it work better, but also makes it even more inefficient if you modify the MCP without changing its name and shape significantly (it will try to make tool calls using the "mainline" format, then have to retry them when they fail).
Even with Opus 5.5, IMO it's better to just ditch the MCP and let the LLMs eat with bintools and headless Ghidra; with both GLM and Opus this produces significantly more efficient results than the popular MCP. On the other hand the IDA Pro MCP is much better architected and seems to be pretty good.
-
π hacker news ida pro references New comment by bri3d in "Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol" rss
The IDA Pro MCP is substantially better than the most popular Ghidra MCP, for what it's worth.
-
π r/LocalLLaMA 54gb vram for 35$ rss
| Bought an old mining farm of a guy on avito (Russian eBay), guy had bought a garage a couple of years ago and it was sitting there for a while, found out it was a mining farm and put it up on there for sale for 5000 rub (~60 USD) since he wasn't sure if it works. I negotiated down to 3000 rub (~35 USD), it turned out to have 9x p106 6gb (gtx 1060 6gb) gpus, with 54gb vram total, all working, the only thing missing was an SSD, I booted from USB and it works fine. submitted by /u/markpronkin
[link] [comments]
---|--- -
π r/LocalLLaMA google/embeddinggemma-2 Β· Hugging Face rss
| EmbeddingGemma 2 is an open multimodal embedding model built by Google DeepMind which maps text (incl. code), images, video, and audio inputsβand combinations thereofβinto a single, unified 768-dimensional vector space. The model has 740M total parameters, combining a 270M parameter text model with modular vision (170M) and audio (300M) encoders. Designed to run on consumer hardware such as mobile devices and laptops, EmbeddingGemma 2 delivers low-latency semantic representations for on-device applications, like search, retrieval-augmented generation (RAG), classification, and clustering. EmbeddingGemma 2 builds upon the architectural and capability advancements of Gemma 4, offering several core features: - Native multimodality: Native multimodality: Unifies 4 modalities (text, images, video, and audio) in a single shared 768-dimensional embedding space.
- Multilinguality and code: EmbeddingGemma 2 understands 100+ languages, and achieves a ~14% improvement on code tasks relative to its predecessor.
- Flexible footprint: Combines a 270M parameter text backbone (130M transformer + 140M embedder) with selectively loadable vision (170M) and audio (300M) encoders, allowing developers to load only the modalities required for their use case.
- Matryoshka Representation Learning (MRL): Native support for truncated embeddings across 128d, 256d, 512d, and 768d, enabling up to a 6x reduction in vector storage costs with minimal impact on quality.
- Context length: 8K token context window, capable of processing minutes of audio or video.
- Task-steered representations: Uses lightweight text instruction prefixes to optimize embeddings for different tasks (search, classification, clustering, semantic similarity, etc.).
llama.cpp support https://github.com/ggml-org/llama.cpp/pull/30054 GGUF from GG: https://huggingface.co/ggml-org/embeddinggemma-2-GGUF GGUF from Unsloth: https://huggingface.co/unsloth/embeddinggemma-2-GGUF submitted by /u/jacek2023
[link] [comments]
---|--- -
π hacker news ida pro references New comment by teravor in "Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol" rss
if you include a SKILL.md for the MCP (or just dump it into the prompt) it's not a problem.> there isn't a whole lot of knowledge about how to use them in the training datasetsI don't use Ghidra but IDA Pro MCP works extremely well for me for all manner of tasks. for example, some software likes to call home for license checking (and I wish to run it with networking denied to it). it no longer does.
-
π r/LocalLLaMA Woman used claude as her diary - and got reported to the police for contents of her diary rss
| submitted by /u/Timely_Impression_92
[link] [comments]
---|--- -
π backnotprop/plannotator v0.28.6 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.5 | Several files in one review, theplannotatortool on Pi and OpenCode 2, decisions name the exact file, Ask this session reconnects after sleep
v0.28.4 | Comments come back after the agent edits a file, the agent can list and close its reviews, PR-description feedback no longer dropped, Pi thinking levels
v0.28.3 | Typing into your agent while it answers an Ask no longer streams into Plannotator
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixesWhat's New in v0.28.6
Six PRs, two of them asked for by the community. This is a fix release: Ask AI tells the agent which lines you selected, quick labels can be reordered and given a new emoji, and a few problems found while testing 0.28.5 on Pi and OpenCode are fixed.
Ask AI says which lines you selected
When you select text in a markdown document and ask a question, the question now names the lines, for example
Source: /path/to/doc.md, line 41, orlines 41β44when the selection spans several lines or blocks. Before, it carried only the file path, so when the same phrase appeared twice the agent could not tell which one you meant. The line numbers are the same ones the exported comment for that selection prints, so the question and your feedback point at the same place. This works in plan review and annotate, including linked documents and folder sessions, and through the side chat, Ask this session and the annotate agent terminal. (#1732, closing #1731, requested by @de-tre)Reorder quick labels and change their emoji
Settings β Labels now has Move up and Move down buttons on each quick label, and the emoji is an editable field. The list order decides which Alt/β₯ number applies a label, and the key hint on every row updates as you move things. The emoji field takes exactly one emoji (flags, skin tones and combined emoji included); anything else is shown as invalid and never saved. Two labels with the same text no longer get mixed up when you edit one of them. Your saved labels keep the same format, so nothing needs migrating. (#1738, closing #1736, requested by @RobertoArtiles)
Pi no longer crashes when a fixed port is busy
With
PLANNOTATOR_PORTset in a local Pi session, opening a second/plannotator-annotatewhile one was already open killed Pi withEADDRINUSE. The new review now takes the port over from the old one, as remote mode already did, and Pi stays up. (#1733)OpenCode 2: a review opened by a background subagent no longer adds a
stray turn
With the
plannotatortool turned on, a background subagent that opened a review posted its "session ready" link into the main session while it was idle. The next time the main session woke up, the model answered that link line as its own turn, and the exchange stayed in every later request. The link now goes to the session that called the tool, while that call is still open, so it never becomes a turn of its own. Decisions were always delivered correctly and still go to the main session. (#1734)Additional Changes
- Review names match what opened. On Claude Code,
/plannotator-annotate . a.mdopens onlya.md, but the mod named the review "2 files: ., a.md" in its reply, status line and decision. Reviews are now named from what the CLI actually opened, on Claude Code and for OpenCode 2's tool (#1737). - Contributors' OpenCode setup left alone. Running
bun installin a Plannotator checkout overwrote the developer's own OpenCode commands and skill. The OpenCode plugin's install step now copies them only when the package is installed undernode_modules, and it works on Windows. SetPLANNOTATOR_OPENCODE_POSTINSTALL=1or0to force it either way (#1735).
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- Ask AI: name a text selection's source lines in the question by @backnotprop in #1732
- Settings β Labels: reorder quick labels and edit their emoji by @backnotprop in #1738
- fix(pi): attach the annotate agent terminal after listen so a busy fixed port cannot crash Pi by @backnotprop in #1733
- fix(opencode): a tool launch's session-URL notice never wakes an idle root by @backnotprop in #1734
- fix(mod, opencode): name a review by what the CLI opened, not the typed words by @backnotprop in #1737
- fix(opencode): skip the plugin postinstall inside the monorepo (cross-platform) by @backnotprop in #1735
Community
- @de-tre asked for the selected lines to be included in Ask AI questions, so the agent knows which occurrence of a phrase they meant (#1731).
- @RobertoArtiles asked for a way to reorder quick labels and change their emoji (#1736).
Full Changelog :
v0.28.5...v0.28.6 - Review names match what opened. On Claude Code,
-
π Andrew Ayer - Blog sourcespotter-authorize: Monitor Your Go Modules for Malicious Versions, Without the Noise rss
You can protect the users of your Go modules from supply chain attacks, such as a compromise of your GitHub account, by monitoring Go's checksum database (sumdb). Since the go command won't install a module unless its checksum is published in the sumdb, monitoring the sumdb lets you discover unauthorized versions of your modules. Since the sumdb is a transparency log, you can even detect if Google themselves go rogue and publish a malicious version of your module. Although you can only detect, not prevent, attacks, Go's Minimal Version Selection makes it possible to respond before most of your users have installed the malicious version. Dependency cooldowns, which are coming to Go, will make it even easier to respond in time.
How To Monitor
Source Spotter, which is operated by my company SSLMate as a free service to the Go community, provides Atom feeds listing all versions of your modules found in the sumdb. For example, this Atom feed returns all versions of modules under the src.agwa.name/ prefix:
https://feeds.api.sourcespotter.com/modules/versions.atom?module=src.agwa.name%2FYou can also get Prometheus-compatible metrics:
https://metrics.api.sourcespotter.com/modules?module=src.agwa.name%2FYou can scrape the metrics endpoint using Prometheus and alert in your usual way, subscribe to the Atom feed using your favorite feed reader, or use one of the free services that converts Atom feeds to emails.
Avoiding Noise
Discovery is only half the story. The more important half is deciding whether to alert on a discovered module. Approximately 100% of the records published in the sumdb are legitimate. If you're alerted every time a new version of your module is legitimately published, it will be very hard to notice the one time it's an attack.
I wasn't sure at first how Source Spotter could facilitate no-noise monitoring. Initially, I thought Source Spotter would need access to your module's Git repository so it could cross-check sumdb records against the repo's contents. But that seemed complicated, and it would fail to detect a compromise of your repository host. I also really wanted a solution that wouldn't require users to create accounts.
I finally found a lightweight solution that I really like. I'll show you how you use it, and then explain how it works.
First, you install a small command line tool called sourcespotter- authorize and generate a public/private key pair:
$ go install software.sslmate.com/src/sourcespotter/cmd/sourcespotter- authorize@latest sourcespotter-authorize -keygenRun sourcespotter-authorize again with the
-feed-foror-metrics-forflags to output Atom and Prometheus URLs for the module prefix you want to monitor (src.agwa.name/ in this example):$ sourcespotter-authorize -feed-for src.agwa.name/ https://feeds.api.sourcespotter.com/modules/versions.atom?module=src.agwa.name%2F&mldsa=efbcb2bcb2d4decdf1ad9cab3224b2dd0087b6c6877abe00448a00d31716dff1 $ sourcespotter-authorize -metrics-for src.agwa.name/ https://metrics.api.sourcespotter.com/modules?module=src.agwa.name%2F&mldsa=efbcb2bcb2d4decdf1ad9cab3224b2dd0087b6c6877abe00448a00d31716dff1These are the same URLs shown earlier, but with a new
mldsa=parameter in the query string which is the hash of the public key you generated in the previous step.Initially, these URLs return the same contents as the URLs without the mldsa= parameter. That's because you haven't marked any module versions as authorized yet.
To mark a module version as authorized, change into the Git repository for the module and run sourcespotter-authorize with a Git tag:
$ cd ~/src/snid $ sourcespotter-authorize v0.4.0Now, v0.4.0 of this module is omitted from the feed and metrics URLs.
The command accepts multiple tags as arguments, so you can authorize all the tags in a repo like this:
$ sourcespotter-authorize $(git tag)Moving forward, you should run sourcespotter-authorize any time you tag a new version. I've written a tiny shell script called gotag that runs git tag followed by sourcespotter-authorize:
#!/bin/sh -e git tag "$1" sourcespotter-authorize "$1"As long as you authorize every tag you create, the feed and metrics URLs will report zero unauthorized module versions, eliminating false positive alerts. A supply chain attacker can't hide their malicious versions from your feeds unless they also compromise sourcespotter-authorize's private key.
How It Works
sourcespotter-authorize -keygengenerates an ML-DSA-44 private key (stored under $XDG_CONFIG_HOME/sourcespotter-authorize). The SHA-256 hash of the corresponding public key goes in the mldsa query string parameter.When you authorize a tag, sourcespotter-authorize uses the golang.org/x/mod/zip and golang.org/x/mod/sumdb/dirhash packages to compute the checksums of the go.mod and module zip files for the tag. It formats the module path, version, and hashes for each tag as a go.sum file (no need to invent a new format here), and signs the file with your private ML-DSA key. Finally, it uploads a JSON object to the Source Spotter server containing your public key, the go.sum file, and the signature.
The Source Spotter server verifies the signature using the public key. If valid, it records the module path, version, and hash as being authorized by that public key, and excludes that module version from the feeds and metrics endpoints for the key.
The protocol is simple and documented if you want to implement your own client.
Why Not Just Sign Your Releases?
If you're generating a private key and signing stuff anyway, why not just sign your releases and distribute the signatures? After all, this is the traditional approach to stopping unauthorized software releases.
The problem with the traditional approach is that consumers of your software have to verify the signatures, which means they need to know what your public key is. Key distribution is a hard, hard problem, and most software ecosystems do a bad job at it. I would guess that in practice, few people actually verify signatures of software releases.
In contrast, the go command automatically verifies that every module it installs is listed in the checksum database, without the user needing to do anything. Although sourcespotter-authorize needs a private key, you only need to distribute the public key to Source Spotter (or whatever other monitor you might choose to use), rather than every single consumer of your software. That's a vastly simpler problem, especially when (not if) you need to rotate your keys.
Everyone who signs their software releases will need to rotate their keys soon, as quantum computers are expected to break RSA and elliptic curves within the next few years. An earlier version of sourcespotter-authorize used elliptic curve keys. After it gained ML-DSA support, upgrading my key was super easy - generate a new key, transfer my list of authorized versions to it, and finally update the URL in my feed reader:
$ sourcespotter-authorize -export > tmpfile $ rm ~/.config/sourcespotter-authorize/private_key $ sourcespotter-authorize -keygen $ sourcespotter-authorize -import < tmpfile $ sourcespotter-authorize -feed-for src.agwa.name/This was so much easier than communicating a new key to every consumer of my software would have been, and didn't require a lengthy transition period during which I was signing with two keys.
You can learn more about Source Spotter's module monitoring, get the source code on GitHub, or read my blog post about how Source Spotter also verifies Go's reproducible builds.
-
π sharkdp/hyperfine v2.0.0-alpha.1 release
This is the first alpha release of hyperfine 2.0. Command-line options and export formats may change before the stable release. See the breaking changes below when migrating from hyperfine 1.x.
Features
-
Add support for alternative performance metrics (peak memory usage, CPU cycles, instructions, cache misses, branch misses, ...). By default, hyperfine will now display wall-clock time and peak memory usage (wall-clock time only on Windows),
but users can use the new--metricsoption to select different performance metrics. -
The terminal output now shows an overview of all selected performance metrics, including relative changes.
- Python plotting and analysis scripts support the new JSON format and can select performance metrics with
--metric, see #981 and #984 (@sharkdp).
Breaking changes
-
Benchmarked commands are now executed directly by default, without an intermediate shell (
--shell=none). Use-S(an alias for--shell=default) to restore the previous behavior (shon Unix,cmd.exeon Windows), or select a shell with--shell <SHELL>. -
The JSON format for
--export-jsonhas changed (schema version 2). The new format now includes metadata, per-run measurements, and statistical summaries for all measured quantities, see #790 (@sharkdp). Code that reads those exported JSON files must be updated. For example,results[i].meanis nowresults[i].summary.time_wall_clock.mean, andresults[i].timesis replaced byresults[i].measurements[j].time_wall_clock.value. The new structure looks like this:{ "schema_version": 2, "primary_metric": "time_wall_clock", "metadata": { "hyperfine_version": "2.0.0-alpha.1", "start_time": "2026-10-06T12:00:00Z", "platform": {"os": "Linux", "architecture": "x86_64"} }, "results": [ { "command": "sleep 1", # Actual command after parameter substitution "name": "wait 1s", # Optional custom name, separate from the command "parameters": {"duration": {"value": "1"}}, # Values are now objects "measurements": [ # One entry per run, excluding warmups { "time_wall_clock": {"value": 1.0, "unit": "second"}, "time_user": {"value": 0.0, "unit": "second"}, "time_system": {"value": 0.0, "unit": "second"}, "memory_peak_resident": {"value": 1048576.0, "unit": "byte"}, "exit_code": 0 }, ... # Further runs omitted ], "summary": { "time_wall_clock": { "unit": "second", "count": 2, "mean": 1.0, "stddev": 0.0, "median": 1.0, "min": 1.0, "max": 1.0 } # Other metrics have the same summary structure. } } ]}
Times are always exported in seconds and memory in bytes.
-
--time-unit/-uhas been removed. Units can now be selected using the--metrics METRIC[:UNIT],β¦option, e.g.--metrics time_wall_clock:ms,memory_peak_resident:MiB. -
--sorthas been removed. It complicated hyperfine significantly and doesn't make too much sense with the new output format. -
--referenceand--reference-namehave been removed (for now). The first command is always considered as the reference command. -
The format of Markdown, AsciiDoc, org-mode and CSV exports has also been changed. These formats contain only the primary metric (the first metric selected by
--metrics). CSV now includes columns with the name and the unit of the primary metric.
-
-
π backnotprop/plannotator v0.28.5 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.4 | Comments come back after the agent edits a file, the agent can list and close its reviews, PR-description feedback no longer dropped, Pi thinking levels
v0.28.3 | Typing into your agent while it answers an Ask no longer streams into Plannotator
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocksWhat's New in v0.28.5
Twelve PRs, one from a first-time contributor. Agents on Pi and OpenCode 2 can now open Plannotator reviews themselves without holding the session, a review can cover several files at once, and every decision now names the exact file it is about.
Several files in one review
plannotator annotate spec.md ui/mock.html notes.mdnow opens one review of all the files, in the order you typed them. A header switcher shows "2 of 3", the Files tab keeps that order, and one decision covers the whole set, with the feedback split into a section per file. Ask AI knows which file you are on, and your unsent comments are kept per file. The same works when an agent passes a list of files to theplannotatortool. If one of the paths does not exist, nothing opens and the error names the missing file. Words that are not file paths keep their old meaning, soannotate look at notes.md pleasestill opensnotes.md. (#1718)The
plannotatortool on Pi and OpenCode 2, off until you turn it onOn Claude Code (with the Plannotator mod) agents already had a
plannotatortool. It is now on Pi and OpenCode 2 too. It matters when the agent opens Plannotator itself, for example when you ask it to "show me the HTML plan in Plannotator" or "open a Plannotator code review". Without the tool, the agent runs theplannotatorcommand in its shell, which blocks the session until you finish and leaves Ask AI unable to reach the session. With the tool, the review opens right away while the agent keeps working, your decision comes back as a message, Ask this session works from that review, and the agent can list and close the reviews it opened.The tool adds about 780 tokens to every request, so on Pi and OpenCode 2 it is off by default. The first Plannotator page you open there asks "Do you use Plannotator as a skill?" and turns it on for your next session if you say yes. You can change it any time with the new toggle in Settings β General (plan review, annotate and code review), the
agentToolkey in~/.plannotator/config.json, orPLANNOTATOR_AGENT_TOOL. On Claude Code the tool stays on by default, since Claude loads it only when it is needed; the same switch turns it off there without turning off the rest of the mod. Your/plannotator-*commands work the same either way. (#1714, #1715, #1724, #1725)The tool's description no longer includes the unfinished
replyaction, and Pi's bundled knowledge skill stays out of the model's context by default, keeping the promise from #842.Every decision names the file it is about
A user reviewing two different files that were both named
QUESTIONS.mdapproved one of them. The approval reached the agent as just "QUESTIONS.md β Approved." with no path, and the agent attached it to the other file. Every decision message now carries aTarget:line with the full path (or URL, PR, or folder), taken from the review that recorded the decision, and reviews that share a file name are labelled with their folder, such asreleases-2026-10-04/QUESTIONS.md. A code review decision names the PR that is on screen when you decide, even if you switched PRs inside the review.A related gap is closed too: when a review's port was reused (a fixed
PLANNOTATOR_PORT, remote mode, or rarely by chance), an old browser tab could submit a decision to the new review. Each review now has its own id, and a decision from a tab that belongs to a different review is refused with a "This review was replaced, reload" banner.plannotator sessionsnow lists each review's id and full path, and has a--jsonoption. (#1729)Ask this session reconnects after sleep
With the Claude Code mod, Ask AI in an open review could switch permanently to "This session is no longer available" after your computer slept or the network dropped for a few minutes. It now reconnects on its own, waiting a little longer between attempts while the review is unreachable. Running
claude --continuewhile the old window is still open no longer makes the two windows fight over the review: the window you are using takes it over, each decision is delivered exactly once, and plan approvals reach the right window. If you quit Claude Code after a decision arrived but before Claude saw it, you get a notice next time saying where it was saved. (#1727)Approve with a note in every gated review
Gated annotate reviews (
--gate, or the tool withgate: true) opened from Claude Code never offered "Approve with a noteβ¦", even though the note could be delivered. They do now, for markdown and HTML alike, on every host that delivers the note with the approval. Your note reaches the agent as an "approved with notes" message. A plain approval is unchanged: plain output is still exactlyThe user approved.One thing for scripts: when you approve with a note, plain output now prints the approved-with-notes message instead of that line. Scripts should use--gate --json. (#1728)Additional Changes
- Done says nothing was sent. Clicking Done with nothing to send showed "Feedback Sent". It now shows "Done, nothing was sent", and Close no longer claims a response was sent (#1730).
- Pi keeps the model you picked. Using
/treeto re-answer something during plan execution switched the model back to the plan's original one. It now keeps your choice; moving into or out of plan mode still applies the phase's model (#1723, fixes #1722). - Gruvbox diffs. Added lines in code review were grey on the Gruvbox theme. They are now Gruvbox green in light and dark (#1721).
- Safer settings. A web page in your browser can no longer change Plannotator's settings in the background, and saving settings from the VS Code panel works again, as do viewed-file progress and the Call Flow install there (#1724).
- Type checking now covers the Claude Code side's server code (#1720).
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- feat(annotate): several files in one annotate review by @backnotprop in #1718
- feat(pi): the plannotator tool on Pi by @backnotprop in #1714
- feat(opencode): the plannotator tool on OpenCode 2 by @backnotprop in #1715
- feat(tool): agentTool switch with per-host defaults, Pi tool stability, drop the reserved reply action by @backnotprop in #1724
- feat(ui): agent tool switch in Settings and a one-time offer on Pi and OpenCode 2 by @backnotprop in #1725
- fix: decisions name their full target; refuse stale-tab decisions on a reused port by @backnotprop in #1729
- fix(mod): restart a dead Ask-this-session bridge; one watcher per launch across processes by @backnotprop in #1727
- fix(annotate): offer Approve with a note in every gated session that delivers it by @backnotprop in #1728
- fix(annotate): show a Done screen, not Feedback Sent, when Done sends nothing by @backnotprop in #1730
- fix(pi): keep the user's model on a /tree navigation within the same phase by @backnotprop in #1723
- Fix gruvbox positive diff colors by @TheEdgeOfRage in #1721
- fix(hook): type-check apps/hook/server and fix vibe-plan.ts narrowing by @backnotprop in #1720
New Contributors
- @TheEdgeOfRage made their first contribution in #1721
Contributors
@TheEdgeOfRage fixed the grey added lines in Gruvbox code review, with the color override the colorblind theme already uses.
Community:
- @jasonharrison reported the Pi model reset on
/treewith a clear repro on Oh My Pi (#1722).
Full Changelog :
v0.28.4...v0.28.5 -
π r/LocalLLaMA Qwen 4 apparently coming out at the end of October rss
Hey All,
I spoke to a 0-day partner of Alibaba today and he casually mentioned (didnt know if he was allowed to) that Qwen 4 is apparently planned for the end of October.
To me, this is way faster than expected as there was quite a gap between 3.6 and 3.8.
I tried to get more information out of him regarding which variants will come first and he got a bit cagey.
BUT: No matter the order of the variants, we can hope for Qwen 4 27B this year!
EDIT: I know this is very much "in bro we trust" but i am also just trusting bro from the Alibaba partner. Together we trust in Bro.
submitted by /u/Dependent_Hunter_155
[link] [comments] -
π OmniNull/OmniWM Canary 20261006-1237 (ee9ba550) release
Automated canary build of
main. It is signed and notarized like a release but skips the owner review, so treat it as unstable.- Commit:
ee9ba550e281 - Base tag:
v0.7.5
Changes since v0.7.5
ee9ba55Merge pull request #799 from OmniNull/ci/canary-and-test-fixesfc0ca61Await hidden-bar task completion in lifecycle tests25cf1f8Test both hidden-bar cleanup delivery hops deterministicallyd1237b4Fail canary decisions on Git ancestry errorsa753adfMake canary tags unique across workflow rerunsd5f7f39Restore the serial release gate and make canary tags run-unique80eac3dFix canary prerequisite permissions and API failure handling4ea0cb6Anchor the canary tag to the built commit and rebase notes on the newest tag981470eKeep the canary schedule green until signing is set up4c82417Run the parallel test suite once in release preparef193ba1Publish a daily signed canary from main3ec3062Keep the queued refresh pending until cleanup finishes8af1faaKeep the workspace active when hiding its last windowec56b05Merge pull request #798 from hezhizhen/codex/fix-watch-directory-path415a2caGenerate localization metadata with Xcode Swift78be4e3Match AX frame positions at the top-left cornerf9090f9Skip directories in watch command PATH lookup
- Commit:
-
π r/LocalLLaMA Microsoft confirms OpenAI has been using Looped Transformers in the GPT-6 series rss
| Microsoft confirms on publicly accessible web page that OpenAI has been using Looped Transformers in the GPT-6 series, proving The Information's reporting was correct all along. GPT-6.1 Sol uses 2 inference passes, with a passing mention of "instead of three". For those confused by "same base model weights as GPT-6 Sol", I think Microsoft meant 6 & 6.1 are both post-trained models on top of the same pre-trained "base model", not that the final weights are identical So different post-training (+ one less loop). Update: Microsoft updated the web page to remove it submitted by /u/ResearchCrafty1804
[link] [comments]
---|--- -
π Project Zero How to fix a bug in a fix rss
Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure. Some vendors express concern about potential scenarios in which they are unable to fix vulnerabilities that are causing immediate user harm, due to limitations in their patch delivery systems. Since Project Zero encounters a wide array of systems designed to protect users in the case of exceptional exploitation scenarios, both through vendor discussions and security reviews, we want to share what weβve learned.
This post provides an overview of systems in use by large vendors that allow them to remediate small volumes of vulnerabilities much faster than their typical update process. Our goal is to provide a reference for vendors seeking to implement or enhance the capabilities of such systems, and to encourage vendors to consider how they would fix an urgent vulnerability before they receive one.
Why patching takes time
Patching a vulnerability typically involves the following stages:
- Triage β a vulnerability report is received, validated, prioritized and assigned to a specific developer to be fixed
- Patch development β a software development team writes, reviews and commits code that fixes the vulnerability
- Testing β the patch is tested to ensure the vulnerability is remediated and the software still functions correctly when the patch is applied. This can include formal testing by a test team, automated testing and alpha and beta testing where a patch is shipped to a limited group of users for feedback on normal use.
- Partner review β some software updates require review by third parties before they can be shipped, due to relationships between the software vendor and other organizations, for example, carrier acceptance for some mobile updates.
- Delivery β the patch is delivered to and installed by end users
- Activation β sometimes an additional step, such as a system restart, is needed to switch the system to the updated software
Of course, this is a simplified picture. Patching can involve repeating steps, for example rewriting a patch if tests fail, or additional stages when third- party vendors are involved. However, this is a minimal set of steps most software updates require.
The challenges of emergency patches
While triage and patch development time contribute substantially to the speed at which vendors can generally patch vulnerabilities, they contribute less to emergency patch time. Triage is usually very fast in situations where vendors know they have an urgent problem, and patch development can be expedited based on priority. Only in rare circumstances, where a vulnerability is especially complex, or a vendorβs security team does not have a complete picture of their softwareβs components and who within their organization maintains them, have we seen urgent patches delayed in the triage or development phase. Likewise, partner agreements usually have exceptions for updates in emergency situations.
Most vendorsβ patch speed is limited by the testing and delivery stages. Testing is important because all changes to software risk introducing unexpected behavior. The worst-case scenario is that inadequately tested software βbricksβ a device, causing it to malfunction in a way that it can no longer perform key functionality or receive software updates to remediate this. Buggy software updates have also led to situations where user data is corrupted or lost, and any decrease in software functionality after a security update makes users less likely to apply updates in the future.
The potential cost to vendors of shipping poorly tested updates varies depending on the nature of the underlying software. For example, if a mobile application is rendered unusable due to an update that corrupts local data or prevents it from launching, users can easily install the next version via an app store, and their data is usually saved on a remote server, so costs are limited to user support. Meanwhile, if a mobile device gets bricked, it needs to be returned to its manufacturer or place of purchase for repair, leading to substantial costs for the vendor and potentially the user.
The possibility of serious functional bugs is considered in the design of most patch delivery systems. Updates are often rolled out slowly, so that serious problems can be detected before they affect too many users. Often, patching vulnerabilities quickly and avoiding buggy patches are at odds with each other, requiring tradeoffs that prioritize one over the other.
A variety of other technical challenges can limit the speed of patch delivery. One is the design of the patching system. A common design is that devices probe for updates at a regular interval, leading to patch saturation being limited to that interval. βPushβ style update systems can deliver patches to all users faster, but generally require more infrastructure.
User behavior and environment can also be a barrier to patch propagation. Patches that require user interaction to install are often delayed by users, and network speed and data cost are also factors in installation rate. Updating many users at once, as opposed to over a period of time, can strain patch delivery infrastructure. Chrome and Microsoft have written about the challenges of updates requiring restart to install, as users are often reluctant to restart their system and restarts take time.
While testing delays and limitations of the patch delivery system affect all updates, the shorter time frame of emergency updates make them a larger contributor to the overall time it takes to deliver a patch.
Emergency patching methods
Feature flags
Feature flags are conditional statements in source with paths determined by values provided by a remote server. They are often used for A/B testing, but they can also be used for short term remediation of vulnerabilities in emergency situations. A widely publicized case of this was a serious 2019 FaceTime vulnerability, where Apple temporarily disabled Group Facetime with a feature flag. Several vendors have made at least some media codecs available in 0-click contexts controllable via feature flags, and can disable them in the case of active exploitation, falling back to another codec for realtime transmission.
The main benefit of feature flags as a vulnerability remediation method is that testing can be performed with each flag set in advance, so a fast update does not require shipping untested code. They can also be delivered to users much more quickly, as updating feature flags requires transmitting a very small amount of data.
Recently, Meta published a blog post on how they implemented a βdual stackβ library, in which two versions of the WebRTC video conferencing library were compiled into a single binary, with the version in use controllable via a feature flag. This technology enables rapid updates with less testing, as new versions can be shipped with the option to quickly move users back to the previous version if function problems occur. While Meta uses two versions of the same library, it would also be possible to create a βdual stackβ with two different libraries that implement the same features (for example, two H264 libraries), allowing an application to switch to a different library to render a specific vulnerability unreachable without loss of functionality in an emergency. This would require additional testing, but it is testing that can be performed up front. It could also be possible to have a second library that enables performance intensive mitigations that would block many possible bugs, such as ASAN, or enabling DCHECKs.
Filtering
Filtering is running a dynamically updatable ruleset, such as a regular expression, against untrusted input in order to block specific input that is required to reach a vulnerability. An example of this is Androidβs Intent Firewall, which allows specific usages of an Android IPC mechanism called intents to be disabled based on rules in a dynamically updateable XML file, which enables blocking intents that can be used to exercise specific vulnerabilities. It was recently used to block vulnerabilities in third-party Android wallets.
Some platforms have endpoint detection software that can perform filtering on a wide variety of system input, for example Microsoft Defender on Windows systems, and Google Play Protect on Android devices. Rules that block specific exploits or make certain vulnerabilities unreachable can often be deployed to these applications very quickly. Endpoint detection requires parsing a great deal of untrusted input, often in privileged context, so these applications are not without risk, but in systems where they already exist, they are a potential method of emergency remediation.
As an approach, filtering is more flexible than feature flags. For feature flags to be effective, the vendor needs to determine what features they might want to disable in advance, and if this isnβt comprehensive, they might find themselves in a situation where a vulnerability canβt be remediated via feature flags. Meanwhile, filtering can be used to block a wide variety of inputs, even ones that have never been considered. The downside of filtering is that performing filtering frequently can decrease software performance, and at least some testing of new filters is required, and canβt be performed upfront without knowing the vulnerability that needs to be blocked, as it is possible to write filters that interfere with necessary system functions.
Alternate Channels
The network βchannelsβ used to deliver software updates to users can be slow for a variety of reasons discussed above. Vendors sometimes implement alternate channels that can be used to deliver smaller updates more quickly.
Android Pony Express (APEX) is an example of an alternate channel that can be used to ship updates to specific high-risk Android components faster than a full system update. It shortens the patch development time, as OEMs do not need to integrate updates to APEX components. APEX is available to OEMs, and can be used to update OEM- maintained libraries.
Several applications weβve researched have the ability to update individual libraries outside regular updates, usually by having some flag that is regularly checked over the network, and then downloading the library and loading it with
dlopenor equivalent. While this is an effective way to avoid delivery-speed limitations of updates, it can also introduce critical vulnerabilities if libraries delivered in this way are not adequately verified by the client to have originated from the vendor. We encourage vendors to be cautious, and ensure that emergency update mechanisms of this variety have adequate security testing.Hotpatching
Some vendors have implemented update mechanisms that allow units of binary code smaller than libraries to be delivered and applied directly to the memory space of a running process. For example Linux supports Livepatch which enables kernel functions to be directly replaced in memory without a restart. Similarly, Windowsβ hotpatch allows security updates that contain only updated functions to be delivered to users, and applied while the process is still running.
Hotpatching has the potential to deliver very flexible security patches to software very quickly, with no degradation of user experience, though it typically has some limits to the nature of patches it can deliver, for example, updates that require changing the definition of a structure shared between functions are sometimes not supported. Hotpatching has similar security downsides to alternate channels, and also carries the risk of introducing ways to bypass exploit mitigations, as it requires permissions to map pages with write-execute privileges at some point during patching. It also doesnβt address any of the testing challenges of rapid updates, just the delivery challenges.
The importance of emergency patching
LLMs are increasing the vulnerability discovery and exploitation capabilities of both attackers and defenders. A wider array of actors now have the ability to perform novel attacks at greater speed. In light of this, it is important for vendors to consider how to protect their users in the case of active exploitation. Rapid update mechanisms do not need to be heavyweight or be capable of fixing every possible bug and preserving perfect user experience in every scenario. Technologies like feature flags, filtering and alternate update mechanisms can remediate the most likely and severe vulnerabilities in the short term, while keeping devices reasonably functional for users.
It is urgent for vendors to plan how they will protect their users in the worst case scenario of widespread active exploitation. Actions taken now can greatly improve security outcomes for users. By taking stock of update mechanisms already available to them and implementing rapid remediation functionality where gaps exist, vendors can be better prepared for whatever the future holds.
-
π streamyfin/streamyfin v0.55.1 release
fix(ios): keep tab labels on their tabs when built with the iOS 27 SDβ¦
-
π HexRaysSA/plugin-repository commits sync repo: +1 release rss
sync repo: +1 release ## New releases - [ida-settings-editor](https://github.com/williballenthin/ida-settings): 1.3.1 -
π Mitchell Hashimoto A Terminal Protocol for Program Status (OSC 7501) rss
(empty) -
π Armin Ronacher What is Codemode rss
More than a year ago I wrote a few posts here that recommended people not to load custom tools into their context (or MCP servers) but to just use more scripts. Most importantly I wrote that Code Is All You Need and I wrote about that MCP needs code. With Pi 1.0 we now added MCP support via Codemode which in some ways is a long time coming, but then also maybe somewhat surprising to some. So I want to share some updated thoughts on this blog on what this all means.
What Are Tools
When a harness like Pi provides tools for an LLM to call, it does so by supplying some tool definitions which then translate into some token structure on the server side. Whether a model is encouraged to call a tool is the result of the reinforcement learning process. Something I wrote about before if you want to learn more.
One of the reasons we strongly lean towards CLI and bash is because it allows easy composition of calls, and because the model also learns how the file system works when it's trained. So when it invokes a tool like
echo foo > /tmp/test.txtthe model also learns that after that tool call, there is now a file calledtest.txtin/tmp.However bash has one fundamental limitation which is that it can only compose programs that run. And there are some things, which are not programs, but native tools to the LLM and they sort of have to be.
The most obvious example here is
readorview_image. If a multimodal model needs to read an image, it cannot usecatfor that because the harness needs to inject the actual image payload into the protocol of the LLM.Another quite vivid example are sub agents. In order to spawn and orchestrate sub agents, it's tricky to avoid tools that are provided by the harness. While in theory the agent could provide a CLI tool that talks to the outer harness via environment variables and Unix sockets, it's a rather crude process. It however has another issue, and that is where the code runs.
Brains vs Hands
To better understand that, it's important to think a bit more about where all the bits and pieces run. There really usually are two different systems involved. The first is the brain, the harness: it runs on one machine. It's trusted. The second is often the same machine, but it's really where the tools are executing: the hands. In Pi we now call this the execution environment, but you can think of it as the target of all the operations.
Crucially what is important for us, is that there is a dividing line between the harness brain and the target environment that runs bash and executes the tools.
And splitting this in half has some really important consequences. For a start it means that they are running on different file systems and they have different levels of trust. If you for instance use a sandboxing solution like Gondolin your bash stuff will be sandboxed just fine, but the harness itself will not be.
Orchestrating The Harness
Which brings us to what Codemode really does: it's a way for the LLM to express and orchestrate complex operations on the harness side, but not the execution environment side. Codemode runs in the harness, in its own sandbox. In case of Pi it's running in QuickJS within a WASM runtime with intentional limitations: no network, no file system, no timers, limited RAM. The only way is to call more tools. You could also imagine that Codemode could run Scheme or some other language as well.
If you are not familiar with Codemode, it's basically just a way to issue tool calls from within some language, in our case JavaScript. That allows you to compose those calls without necessarily going through the LLM's context. Credit for naming goes to our friends at Cloudflare who coined it.
For instance if you issue a bash call as a regular tool call in the LLM, then we only throw the trailing 2000 lines into the context and if the agent wants more, it needs to look at the overflow file itself. If however the agent issues that invocation via Codemode, then the Codemode side gets larger outputs sent structurally.
Most importantly, because Codemode is JavaScript the agent can express concurrent operations and basic workflows. A common way in which you see agents now use this, is to first probe at 5-10 items from some tool response to see what it looks like, and to then write a Codemode script that processes the next n items.
Codemode also allows you to throw state into the transcript! That means that one Codemode invocation can stash away data, that the next call in the session can load again. And remember: this is on the harness host, not the sandbox.
In case of Pi, Codemode also allows you to issue calls that naturally do not make any sense in Pi's traditional interface. For instance if you want to generate images with an image model or you want to classify some text with a one shot classifier model, those Pi APIs are exposed via Codemode, but not via regular tools where they would just waste context.
What It Looks Like
So now that we talked a bunch about it, it's probably worth being a bit more explicit about it. Let's walk ourselves through some invocations of Codemode of recent Pi sessions of mine. Note that none of this code is human written. It's from real sessions of Pi, just re-indented for your viewing pleasure. The agent starts using Codemode automatically either because it's a task where the model already naturally picks up that tool, or because a user asked it to.
Note that Codemode is by default only enabled in Pi when MCP is enabled, but you can turn it on with
"defaultTools": ["+codemode"]in the settings. Just ask Pi to enable it for you.Generating Images
Let's start simple with image generation. Image generation is a feature that Pi supports in the AI SDK core, but it's not a tool that the agent can use. In the past the only way to use image models has been to write a bespoke extension or to have the agent run node itself and use the internal image APIs. However because we expose quite a few of the internal model APIs within Codemode, it means that the agent can use it:
const [painter] = await models.getAvailableOfType("image"); const result = await models.generateImages(painter, { input: [{ type: "text", text: "A cute little puppy sitting on a grassy " + "lawn, soft natural light, photorealistic" }], }); if (result.stopReason !== "stop") return result.errorMessage; for (const block of result.output) { if (block.type === "image") image(block); else text(block.text); }Note that the call to
image()sends the image back as image content to the LLM. On the harness side it feeds it directly into both the agent, as well as onto disk as a temporary artifact in case the agent wants to be able to pass that image back to bash.Classifying Things
Similar things apply to classifier models such as Jev. They also do not fit well into the workflows of an agent through the typical tools. But rather than making a bespoke tool available, Codemode just allows the agent to reach into the AI SDK and invoke those directly. Here you can see how Jev is used to mass process GitHub issues for a quick sentiment analysis:
const jev = await models.getModelOfType("classifier", "typesafe", "jev-latest"); const r = await tools.bash({ command: "gh issue list --state open --limit 100 " + "--json number,title,body,comments", }); const issues = JSON.parse(r.output); const results = await Promise.all(issues.map(async (issue) => { const res = await models.classify(jev, { state: { title: issue.title, body: (issue.body || "").slice(0, 4000), comments: issue.comments.slice(-5).map(c => c.body.slice(0, 800)), }, questions: { sentiment: { type: "choice", instructions: "What is the overall sentiment of the author towards pi?", criteria: { positive: "Appreciative, happy, constructive praise", neutral: "Matter-of-fact report or request without emotion", negative: "Frustrated, annoyed, upset, or angry", }, }, frustration: { type: "score", instructions: "How frustrated is the reporter?", criteria: ["not at all", "mildly", "clearly frustrated", "very angry"], }, kind: { type: "choice", instructions: "What kind of issue is this?", criteria: { bug: "Bug report or regression", feature: "Feature request or enhancement", question: "Question or support request", other: "Docs, discussion, meta, spam", }, }, }, }); if (res.stopReason !== "stop") { return { n: issue.number, title: issue.title, error: res.errorMessage }; } return { n: issue.number, title: issue.title, ...res.answers }; })); store("sentiment_results", results); return results .filter(r => !r.error) .sort((a, b) => b.frustration.score - a.frustration.score) .slice(0, 12) .map(r => `#${r.n} ${r.frustration.score.toFixed(2)} [${r.kind.choice}] ${r.title}`);Note how in that above example we also call
store()which dumps the result of that execution into the session transcript. A future invocation of Codemode can thus read back that result if it wants to.The
Promise.allhere is fine, because Pi limits the total number of concurrent tool executions itself to four and maintains a queue for the rest.A more adventurous example is to use Jev to drive a game engine for debugging purposes:
Codemode with Jev for Game Debugging
Here it knows about my
tankctlcommand and it built itself quickly a minimal harness around it to drive a game loop to assist a user with debugging a problem. Note how it built a 30 step loop in which each step goes back to both the game engine to get a text dump of what's going on, and then to Jev to determine what to do next:const jev = await models.getModelOfType("classifier", "typesafe", "jev-latest"); const tank = async (cmd) => (await tools.bash({ command: `tools/tankctl "${cmd}"` })).output; await tank("start --map assets/maps/night_arena.map"); const questions = { action: { type: "choice", instructions: "You control the tank '@' in a top-down tank game. " + "Choose the best next action.", criteria: { attack: "an enemy has line of sight to you and you can fire at it", approach: "no enemy has line of sight; drive toward the nearest enemy", dodge: "an enemy shot is heading at you and will hit soon", powerup: "a powerup is close and no enemy threatens you", }, }, }; function commandFor(choice, st) { const p = st.player; const enemy = st.enemies.filter(e => !e.dead) .sort((a, b) => (b.los - a.los) || (a.dist - b.dist))[0]; if (choice === "attack" && enemy) { return `fire_at tank ${enemy.id}; frames 30 until clear,damage,kill`; } if (choice === "dodge") { // move perpendicular to the closest incoming shot const s = st.projectiles.filter(s => !s.yours) .sort((a, b) => a.eta - b.eta)[0]; const dir = s && Math.abs(s.vel[0]) > Math.abs(s.vel[1]) ? (p.pos[1] > s.pos[1] ? "+down" : "+up") : (p.pos[0] > (s ? s.pos[0] : 0) ? "+right" : "+left"); return `input ${dir}; frames 20 until damage; input stop`; } const powerup = st.powerups.filter(u => u.available) .sort((a, b) => a.dist - b.dist)[0]; if (choice === "powerup" && powerup) { return `goto ${powerup.pos[0]} ${powerup.pos[1]} 180`; } return enemy ? `goto ${enemy.pos[0]} ${enemy.pos[1]} 90` : null; } const log = []; for (let step = 0; step < 30; step++) { const st = JSON.parse(await tank("state")); if (st.state !== "playing") break; const threats = st.projectiles .filter(s => !s.yours && s.miss_dist < 1.5 && s.eta < 1.5) .map(s => `incoming shot dist ${s.dist} eta ${s.eta}s`) .join("\n") || "no incoming shots"; const r = await models.classify(jev, { state: { map: await tank("view 8"), threats, hp: st.player.hp }, questions, }); if (r.stopReason !== "stop") { log.push(`#${step} classifier error: ${r.errorMessage}`); break; } const choice = r.answers.action.choice; const cmd = commandFor(choice, st); if (!cmd) break; log.push(`#${step} hp=${st.player.hp} ${choice} -> ${await tank(cmd)}`); } return log.join("\n");Calling MCP Servers
Lastly, Codemode obviously is great for calling MCP servers. And because we do not actually expose any of the MCP tools to the LLM, the agent first uses provided APIs to issue a tool search within Codemode to discover what it might be able to do with the connected servers. This form of progressive discovery makes the whole MCP business work well enough for a lot of use cases today.
Here for instance you can see the agent reach for the Sentry MCP straight away, even without discovering the tools, presumably because it has learned during the RL process already about what the Sentry MCP looks like. But it learns from what we inject into the system prompt, that the Sentry server is available to begin with. It's not completely guessing here.
const orgs = await tools.mcp__sentry__find_organizations({}); const { organizations } = orgs.structuredContent; const results = await Promise.allSettled(organizations.map(org => tools.mcp__sentry__find_projects({ organizationSlug: org.slug, regionUrl: org.regionUrl, }) )); return organizations.map((org, i) => { const r = results[i]; if (r.status !== "fulfilled") return { org: org.slug, error: String(r.reason) }; if (r.value.isError) return { org: org.slug, error: r.value.content }; return { org: org.slug, projects: r.value.structuredContent.projects.map(p => p.slug), }; });Modern MCP Is A Fight
I really don't want to talk too much about MCP here, but MCP is in fact a protocol that greatly benefits from Codemode. The problem in parts is that MCP in practice often targets harnesses that do not (yet?) use Codemode. But the tide is shifting. In the meantime, a temporary crutch has been to do what Cloudflare did, and do Codemode within the MCP server. But now we have Codemode in Codemode which is pretty bad. It means double JSON escaping, easy for smaller models to get confused by and the inner code cannot call the outer tools. So if you for instance use the Cloudflare MCP servers in Pi, the agent needs to write JavaScript and funnel it through more JavaScript. This is really not optimal, but it's also understandable that this is happening:
const accRes = await tools.mcp__cloudflare__execute({ code: `async () => { const r = await cloudflare.request({ method: "GET", path: "/accounts" }); return r.result.map(a => ({ id: a.id, name: a.name })); }`, }); const accounts = JSON.parse(accRes.content.map(c => c.text).join("")); const out = []; for (const account of accounts) { const r = await tools.mcp__cloudflare__execute({ account_id: account.id, code: `async () => { const r = await cloudflare.request({ method: "GET", path: \`/accounts/\${accountId}/workers/scripts\`, }); return r.result.map(s => ({ id: s.id, modified: s.modified_on })); }`, }); out.push({ account: account.name, workers: r.content.map(c => c.text).join("") }); } return out;MCP Desires
So to end things off: how well does Codemode work with MCP today? Well β¦ not amazingly well. That's because MCP servers are not really targeting harnesses that use Codemode yet (though at this point I think most harnesses support it).
For this to work well some recommendations:
- Structured content: Codemode wants calls to return some nicely formatted JSON. So that needs to come back from the server, and many don't do that yet. The
outputSchemasystem in MCP is great for that. - Consistent results: an interesting failure case is when an MCP server does not return consistent data. For instance because it tries to token optimize things depending on how many items are in the result set. This can cause an initial probe with 5 items to succeed, but then fail when the server returns the maximum batch size.
- Large binary data: today MCP does not yet support large binary data so quite a few use cases that are really interesting do not work well at all yet. You end up with all kinds of weird workarounds such as pre-signed URLs to allow file uploads then to happen through non MCP channels.
- Composable tool search: the MCP server might know better than the MCP client which tool is appropriate for a task. But there is no good mechanism today that allows a harness to fan out tool searches across multiple MCP servers. It's all emergent behavior and it does not scale well to multiple active servers.
Future of Codemode
So where does this leave us? Is this a reversal of what I wrote a year ago where I encouraged CLIs? I don't think so. In fact, the MCP ecosystem from my perspective picked up on exactly what we pointed out a year ago works: code. But Codemode goes beyond MCP in that it can act as a capable mechanism within the harness to express more freedom for the agent.
There are however also some things that we still need to figure out. For one, durability with Codemode is trickier. We might have to adopt some ideas from durable workflow engines here to snapshot invocations. Or maybe, something like Starlark is a better composition language than JavaScript given its deterministic nature.
Images, binary data and just the inability of this pattern to work with smaller models is also something that needs to be fleshed out. So it's for sure not a perfect solution yet, but it's quite a useful pattern that I expect us to leverage more.
- Structured content: Codemode wants calls to return some nicely formatted JSON. So that needs to come back from the server, and many don't do that yet. The
-
π Filip Filmar Razboj: a minimal GPU in TxHDL rss
Razboj is a minimal graphics rasteriser implemented in approximately one hundred lines of TxHDL. It reads a display list from memory and writes rendered pixels into a framebuffer over an AXI bus. TxHDL lowers the design to synthesizable Verilog and VHDL, and the build verifies both netlists against the software simulation trace. This post describes the rasteriser architecture and hardware design tradeoffs.
What it draws
The reference demonstration scene measures 64 by 64 pixels (4,096 pixels total). The scene consists of eight display list entries: a background clear, three rectangles, and four triangles. The rasteriser renders the entire scene in approximately 13,000 clock cycles. A verification harness reads the completed framebuffer from memory and saves the output image.
-
- October 05, 2026
-
π r/LocalLLaMA PewDiePie getting banned twice by OpenAI while making a local model is top-tier comedy π rss
So PewDiePie decides to fine-tune a local AI model called Ajax on his own computer. Pretty normal stuff for local model fans.
To make his dataset, he uses OpenAI's API. OpenAI catches him using their outputs to train another model, flags his account for breaking their terms, and bans him.
He files an appeal, gets unbanned, goes right back to pulling data from the API, and immediately gets banned a second time.
So instead of giving up, he uses open-source tools to remove the model's built-in refusals, cleans out the preachy fluff, and starts building a fully local 9B agent.
OpenAI spent years scraping the whole public internet for free data, but the second someone uses their output to train a local file, it's an emergency ban.
In trying to enforce their rules, all OpenAI really did was give open-source models a massive free advertisement to millions of people.
What a time to run models on your own hardware.
submitted by /u/rodrigodevbits
[link] [comments] -
π earendil-works/pi v1.0.4 release
New Features
- Tool patterns and
--no-mcp:--toolsand--exclude-toolsaccept*patterns, for example--tools read,codemode,'mcp__radius__*'keeps only one MCP server's tools.--toolsnow keeps MCP tools unless an entry starts withmcp__, and--no-mcpturns off MCP for one run. See Tools and MCP tools. - Codemode persists images :
tools.read()on an image file now gives back an image block thatimage()can show. See Call tools.
Added
- Added
*patterns to--toolsand--exclude-tools, for example--tools read,codemode,'mcp__radius__*' - Added
--no-mcpto disable the built-in MCP support for one run
Fixed
- Fixed syntax highlighting losing colors after the first line of multiline strings and comments in fenced code blocks (#10143)
- Fixed codemode scripts not receiving images from
read:tools.read()now resolves to an image block for image files, whichimage()shows (#10251) - Fixed MCP OAuth sign-in failing with
invalid_redirect_urion servers with OpenID Connect client registration, such asmcp.modem.dev: pi now registers as a native client (#10493) - Fixed
--toolsremoving MCP tools, which leftpi --tools codemodewithout any MCP servers.--toolsnow keeps MCP tools unless an entry starts withmcp__ - Fixed MCP session shutdown returning while a server was still connecting, leaving its transport open until the server answered or timed out (#10249)
- Fixed system prompt rules and the skills hint naming tools hidden by
prepareLoadout. Hidden tools are left out of the rules, the skills hint names no tool when the file reader is hidden, andcodemodeshows each tool's prompt guidelines with its declaration;ToolLoadoutgainsgetPromptGuidelines()(#10343) - Fixed Bedrock requests that fail with
The pending stream has been canceledafter a stalled HTTP/2 connection not being retried automatically (#10379) - Fixed codemode scripts that patch built-ins (for example
Array.prototype.toJSON = ...) crashing pi and leaving the tool call unsettled. Built-ins are now frozen before the script runs, so such patches have no effect (#10444)
- Tool patterns and
-
π exe.dev The Hardest Working Header on the Internet rss
When your browser reads this blog, it looks up
blog.exe.devusing DNS, and sends an HTTP request with aHost: blog.exe.devheader to our servers. Our anycast network receives the request and usesHost: blog.exe.devto figure out which of all the exe VMs to proxy your request to. Load balancers, CDNs, web serversβ¦ the modern web works because of the humbleHostheader. (SSH does not have such a header, alas.)exe.dev lets you bring your own custom domain to point to your VM. Thanks to Letβs Encrypt, we're able to provision the certificate on your behalf. And, now, we also let you provision a wildcard certificate, so you can have, for example,
*.example.comall point to the same VM, and you can route accordingly.domain add vm-name *.example.comin our lobby is the place to get started, and it'll walk you through it.An earlier version of this blog post falsely accused Certificate Transparency of delaying how quickly custom domains started working. This is no longer a problem! (DNS time-to-live configuration remains an occasional stumbling block, though.)
-
π r/LocalLLaMA When Redditors come in here and ask why we run LLMs, this is why: Big AI is watching. rss
Anthropic Reports Florida Woman's Claude 'Diary' Threat to Law Enforcement
And this time it wasn't the AI model that made the LEO referral. It was the "human review team".
The frontier AI companies are watching your input. And people say "Well I'm not interesting or important enough for them to care". Well.....not necessarily.
If you're using hosted frontier to work on mathematics or cutting edge science, they're watching and may steal your work.
If you're venting or otherwise writing in a "private" session using AI, they'll see that and report you to police. Notice I didn't see any mention of what the model's role in facilitating the discussion was.
Keep your stuff private, folks. Hosted AI is the new "Big Brother" conduit.
submitted by /u/Big_Wave9732
[link] [comments] -
π backnotprop/plannotator v0.28.4 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.3 | Typing into your agent while it answers an Ask no longer streams into Plannotator
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right sessionWhat's New in v0.28.4
Seven PRs, one from a community contributor. Your comments now survive an agent editing the file, the agent can see and close the reviews it opened, and two fixes make sure everything you write reaches the agent.
Your comments come back after the agent edits the file
Annotate drafts used to be saved under the file's content. When an agent edited the file and opened a new review, your unsent comments didn't come back. Drafts are now also saved under the file's path, so reopening the file brings them back even after it changed. Comments whose text moved re-anchor to where the text is now, and comments whose text is gone are kept with an Unanchored tag instead of disappearing. This also works per file in folder reviews, so a file's comments carry between a folder review and a review of that file alone.
Exported feedback follows the same rule: a restored comment is labelled with the line its text is on now, and a comment whose text was deleted is sent without a line number rather than a wrong one. Sending your decision still clears the draft.
One visible change: a comment that can't find its text anywhere now always shows the Unanchored tag. Before, some of those (share-link imports, comments posted by outside tools) failed silently.
The agent can list and close the reviews it opened
With the Claude Code mod, the
plannotatortool has two new actions.listshows the reviews opened in this conversation (by the tool or your/plannotator-*commands) with how many of your comments are unsent.closecloses one or all of them. Closing works like your own Close but keeps your unsent comments as a draft, sends nothing back to the agent, and the tab says the agent closed it. Plan reviews are listed but can't be closed this way. Every result and decision message now carries a short session id (pn-β¦) so the agent can tell its reviews apart.Review servers now refuse a second decision once a review is decided, so late feedback can no longer report success after a close and then be lost. With an older
plannotatorbinary the mod only stops a review's process after confirming it is Plannotator; on CLIs 0.24 to 0.28.3 a decision made in the second before such a stop can still be lost, so update the binary.(#1709)
Review feedback on the PR description no longer gets dropped
Code review used to treat any feedback with no code comments as the "posted to GitHub/GitLab/Bitbucket" status message. Comments on the PR description, PR comment notes and VS Code editor comments travel only in the feedback text, so a review made of only those was silently dropped under the Claude Code mod. The page now marks a real platform post explicitly, and every host (the Claude Code mod, OpenCode and Pi) delivers everything else, with the usual "address these changes" framing. The Claude Code plugin also guards against the old behavior when it runs with a
plannotatorbinary from 0.28.0 to 0.28.3, but updating the binary is the real fix.(#1719)
Pi's own thinking levels in Ask AI
When Ask AI uses the Pi provider (no connected session, for example in remote mode), each model now offers exactly the thinking levels Pi reports for it: no Off where the model can't turn reasoning off, Max and XHigh only where the model supports them, and no picker for models without reasoning. Auto sends nothing and leaves Pi's default. Levels are only offered on Pi 0.84.3 or newer, because older Pi versions saved the chosen level as your global default. Model names now read "Name (provider)".
(#1704, by @josdirksen)
Additional Changes
- One-click π on HTML elements. Clicking an element on an HTML page opens the comment box, which now has a small π button again. One click marks the element (or a shift-clicked group) "Looks good". It turns off as soon as you type, so it can't throw away a comment (#1712).
- Cleaner note boxes. The keyboard hints under the header's note composer, the small-screen note dialog and the review sidebar's general comment box are gone. ββ΅ still sends and Esc still goes back (#1711).
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- feat(pi): offer Pi's thinking levels in Ask AI by @josdirksen in #1704
- fix(ui): drop the keyboard hint under the decision note composer by @backnotprop in #1711
- feat(ui): bring the one-click thumbs-up back to the HTML pinpoint composer by @backnotprop in #1712
- feat(tool): contract v2 with session ids, list and close by @backnotprop in #1709
- Annotate drafts follow the file's path by @backnotprop in #1710
- fix(review): mark the PR-platform status post explicitly by @backnotprop in #1719
- fix(annotate): true line labels and Unanchored chips after a restore across an edit by @backnotprop in #1717
Contributors
@josdirksen brought Pi's thinking levels into Ask AI, reading them from the installed Pi so each model offers exactly what it supports.
Full Changelog :
v0.28.3...v0.28.4 -
π smol-machines/smolvm smolvm v1.23.6 release
What's Changed
- Mark a machine initialized once an API start pulled its image by @LoganGrasby in #1572
- Boot pack machines with a 512 MiB packed-layer DAX window by @LoganGrasby in #1506
- Size the server's checkpoint caches for its disk and drop an extraction's marker before removing it by @BinSquare in #1573
- Bump the workspace to 1.23.6 by @BinSquare in #1574
Full Changelog :
v1.23.5...v1.23.6 -
π r/LocalLLaMA How is it possible that qwen 27b is so good? When GPT 4o had a trillion parameters and was worse? rss
| Picture from a post in r/amodei . People were praising qwen and I'm just wondering, what kind of new technologies are at play here? Does qwen just have "better" pre training data? That's more high quality? submitted by /u/SignificantZebra5883
[link] [comments]
---|--- -
π r/LocalLLaMA Make no mistake, selling 64 GB DGX Spark variants at the same cost as the original 128 GB is straight drug dealer behavior. rss
It's something straight out of the season one of 'The Wire': you take the product, dilute it, and sell it at practically the same cost. It's some "Stringer" Bell shit. We should call the 64gbs "Stepped-ons" from now on.
submitted by /u/blacklandothegambler
[link] [comments] -
π smol-machines/smolvm smolvm v1.23.5 release
What's Changed
- Run the clone re-mint as a plain shell so it never leaves an orphan for the guest's init to reap by @BinSquare in #1570
- Bump the workspace to 1.23.5 by @BinSquare in #1571
Full Changelog :
v1.23.4...v1.23.5 -
π MetaBrainz Happening NOW: AMA with Silona Bonewald, MetaBrainz Foundation Executive Director rss
Silona Bonewald, our new Executive Director, is NOW _hosting an AMA (Ask Me Anything)_ in this forum thread.
Please respect the code of conduct, as you always do!
You are welcome to post questions in the thread later, and Silona will do her best to answer them when she has the time. We will close the thread after a couple of days - though of course the door remains open to chat with the MetaBrainz team any time in the future!
You can find more information about Silona on our Executive Director announcement post.
-
π sharkdp/hyperfine v1.21.0 release
Features
- Add support for minutes and hours in
--time-unit, as well as short and plural aliases such asms,seconds, andmin, see #960 (@sharkdp) - Expose
$HYPERFINE_ITERATIONto--prepareand--concludecommands, see #781 and #807 (@willcl-ark) - Show elapsed time during the initial benchmark run, see #416 and #581 (@devonhollowood)
- Add colors to
--helpoutput, see #841 (@starsep)
Changes
- With
--parameter-scanor--parameter-list,--referencenow selects an existing benchmark by its full displayed name instead of running a separate reference command. The name must match exactly one benchmark; use--command-nameinstead of--reference-namein this mode, see #847 and #979 (@sharkdp) - Format times in CSV exports with six decimal places, see #966 and #972 (@sharkdp)
- Update dependencies and raise the minimum supported Rust version to 1.97, see #934 (@sharkdp)
Bugfixes
- Make Markdown, AsciiDoc, and Org-mode exports compare against the specified reference, and label faster and slower results in command-sorted comparisons with
--reference, see #811 and #979 (@sharkdp) - Reject zero values for
--runs,--min-runs, and--max-runsinstead of allowing invalid run counts, see #923 (@VXNCXNX, @sharkdp) - Reject negative parameter-scan steps before expanding ranges, avoiding hangs and excessive memory use, see #951 (@Likio3000)
- Preserve existing export files when command options are invalid, see #950 (@Likio3000)
- Truncate export files when rewriting results to avoid leaving trailing bytes, see #970 (@sharkdp)
- Preserve backticks in command names in Markdown exports, see #947 (@Likio3000)
- Handle broken output pipes gracefully instead of panicking, see #932 (@Mathjk)
- Collect peak memory usage separately for each command on Unix, so commands no longer inherit the peak memory usage of earlier commands, see #965 (@sharkdp)
- Preserve 100-nanosecond precision in Windows CPU times, see #964 (@sharkdp)
- Python scripts: Correct the interpretation of Welch's t-test results, see #943 (@sharkdp)
Other
- Build binaries for Windows ARM64 and Linux ARM64 musl, see #922 and #924 (@meop)
- Refactor measurement, statistics, and formatting code to use typed quantities, see #954, #958, #961, #967, #969, #971, and #976 (@sharkdp)
- Improve documentation and examples, including comparisons across Git branches, iteration variables, reference commands, and selective failure handling, see #899, #900, #929, and #940 (@xfocus3, @ded-furby, @Likio3000, @sharkdp)
- Add support for minutes and hours in
-
π daaain/claude-code-log Release 1.7.0 release
Changed
- (Claude) Upgrade wenmode to 0.15.2 and bump to 1.7.0 (#340)
- Release to PyPI from a tag-driven, maintainer-approved workflow (#341)
- (Claude) Show the logical-parent arrow on a /compact boundary's uuid line (#338)
- (Claude) Drop the host icon before a tool_result title that has its own (#337)
- Keep a Markdown message's body when its title is empty (#336)
- fix(search): report an unreadable cache as such, not as a missing FTS5 (#334)
- Continue the rewind branch across a /compact boundary (#331)
- Run the fail-fast just ci steps before the test suite
- Switch the Markdown engine from mistune to wenmode (#329)
- Resolve commit SHAs from one rev-list per repository (#330)
- Render peer agent messages as teammate cards instead of steering (#309) (#328)
- Apply the cache's write pragmas to every writing connection (#326)
- Link teammate subagent transcripts spawned by the Agent tool (#316)
- Re-parse cached entries when the shape of what we cache changes (#320) (#322)
- Make watch ticks cheap (#321)
- Update some README bits
Full Changelog :
1.6.0...1.7.0 -
π smol-machines/smolvm smolvm v1.23.4 release
What's Changed
- Let the first machine start create the default machine's disks by @BinSquare in #1566
- Bump the workspace to 1.23.3 by @BinSquare in #1563
- Keep the shared extraction trim running when a machine leases a pre-digest or vanished extraction by @BinSquare in #1568
- Bump the workspace to 1.23.4 by @BinSquare in #1569
Full Changelog :
v1.23.3...v1.23.4 -
π smol-machines/smolvm smolvm v1.23.3 release
What's Changed
- Make cold checkpoint restores stop re-reading the artifact and waiting on RAM fsync by @BinSquare in #1552
- Keep a request queued behind a start from stopping the VM that start booted by @BinSquare in #1555
- Stop the systemd scope a refused start created by @BinSquare in #1556
- Make checkpoint capture fast for restored machines and multi-GB state by @BinSquare in #1558
- Reclaim shared checkpoint extractions no machine leases beyond the restore cache bound by @BinSquare in #1557
- Remove the unpublished smolvm-embedded and smolvm-rollout SDKs by @BinSquare in #1559
- Flatten only a branch source's immutable disk layers, in place, so the chain stays short without copying a layer the VMM can write by @BinSquare in #1550
- Never let an implicit start restart a machine that is up, and log why a VM is restarted by @BinSquare in #1565
- Keep a shared extraction while its RAM is still being written back by @BinSquare in #1560
- Bump the workspace to 1.23.3 by @BinSquare in #1567
Full Changelog :
v1.23.2...v1.23.3 -
π backnotprop/plannotator v0.28.3 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.2 | Question cards show wrapped choices and tables, pinned images named by their file, Done with nothing to send starts no agent turn
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right session
v0.27.18 | Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushesWhat's New in v0.28.3
A focused fix for Ask this session, the 0.28 feature that sends Ask AI questions to the agent session that opened Plannotator.
Typing into your agent while it answers no longer streams into Plannotator
When you asked a question from Plannotator's Ask AI and then typed into the agent yourself while it was answering, the agent's reply to your message streamed into the Ask AI panel as if it were the answer, and a Stop in Plannotator could cancel your own work in the agent.
Now, as soon as a message Plannotator did not send enters that turn, Plannotator stops streaming. It keeps the part of the answer it already had and adds a short note ("You typed into this session while it was answering, so the rest of the reply went to your prompt", or a neutral version when it was not you). After that, Stop only closes the question in Plannotator, and "Interrupt and ask now" will not stop the agent, so whatever you asked runs to completion.
This works the same way on Claude Code (with the Plannotator mod), Pi and OpenCode 2. It is careful about what counts:
- If the agent had already finished its answer when your message arrived, the question keeps the full answer.
- Agent-side events do not count: a background task finishing on Claude Code, OpenCode's own notices and compaction steps, Plannotator's own notices on Pi, and messages from other Claude sessions.
- On Pi, the protection holds while Pi retries after an error.
- With an older
plannotatorbinary, the plugin settles the question with the partial answer and the note instead of an error.
(#1703)
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- fix(ask): a prompt typed into an Ask-this-session turn takes it over on every host by @backnotprop in #1703
Full Changelog :
v0.28.2...v0.28.3 -
π earendil-works/pi v1.0.3 release
New Features
- Azure Foundry Chat Completions β The
azureprovider (renamed fromazure-openai-responses) now also serves Foundry Chat Completions deployments, starting withazure/deepseek-v4-pro. See Azure OpenAI. - Codemode images saved to files β
image()also writes each image to a temp file and names the path in the result, so later turns can copy or move generated images. See Generate images.
Breaking Changes
- Renamed the Azure provider from
azure-openai-responsestoazure. Rename the provider key inauth.json(or run/loginagain), inmodels.json, and insettings.json(defaultProvider,enabledModelspatterns, andmodelThinkingLevelskeys). Sessions that used the old provider fall back to another model when resumed, and their prompt cache is not reused. TheAZURE_OPENAI_*environment variables are unchanged (#9714 by @jsanter27)
Added
- Added Azure Foundry Chat Completions deployments, starting with
azure/deepseek-v4-pro(#9645, #9714 by @jsanter27)
Changed
- Codemode
image()now also saves each image to a temp file and names the path in the result, so later turns can copy or move generated images (#10310) - Output files (full text of truncated tool output, binary MCP resources, codemode images) are now readable only by the user
Home/Endnow always move the editor cursor to the line start/end; fullscreen transcript top/bottom moved toCtrl+Home/Ctrl+End, which no longer move the editor cursor (#10314)
Fixed
- Fixed subscription logins such as Sign in with ChatGPT failing with
refresh_token_invalidatedafter a request was cancelled during an OAuth token refresh - Fixed codemode failing for the rest of a session after a pnpm global update removed the running install, and added a restart hint when errors occur after pi was updated or removed on disk (#10439)
- Fixed interactive sessions reporting a
read EIOorsetRawMode EIOcrash (and asking to run /bug) when the terminal went away, e.g. after closing the window or resuming a suspended pi in a closed terminal
- Azure Foundry Chat Completions β The
-
π backnotprop/plannotator v0.28.2 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.1 | Ask AI from diagram comments, pinned images named for the agent, OpenCode 1 URL toasts and one reply per feedback, folder feedback sent once
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right session
v0.27.18 | Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushes
v0.27.17 | Diagram files open in the diagram viewer, OpenCode switches model with agent, idle review stops polling the git remote, Tree is the default review viewWhat's New in v0.28.2
v0.28.2 is a patch release with three pull requests, all from @backnotprop. It fixes question cards that cut off wrapped choices, makes image pins in HTML pages name the right file, and stops Done with nothing to send from starting an agent turn.
Question cards show wrapped choices and block markdown
Choices written as plain bullets that wrap onto several lines were cut at the first line, and the rest of each choice ended up in the question's text above the options. They now show in full: the first phrase is the label and the rest is the description. A
Recommended:line that wraps is read as a whole, and a recommendation that names a choice in its first sentence marks that choice. Choices written as task-list items (- [ ]) split as before.The text of a question now renders like the rest of the document. Tables were a flat run of pipes; tables, lists, code blocks, quotes and images inside a question now look as they do in the plan or file. Comments on a table cell or code line inside a question attach to the question card and restore after a reload.
Answers you saved on 0.28.1 still show the choice you picked, and a recommendation that names a lettered option (
b. β¦) marks that option.Image pins name the file the page shows
When you pin an image in an HTML page, the feedback heading names the file the page displays even when the image has no
srcattribute. This coverssrcset, lazy-loadeddata-srcimages,<picture>and a video'sposteror<source>. Before, the heading named nothing or adata:placeholder. Query strings are still dropped from the name.Comments made in the version diff are now listed after the document's other comments, in diff order, instead of first. Exports without diff comments are unchanged.
Done with nothing to send starts no agent turn
Clicking Done in an annotate session with no annotations used to make the agent start a turn that read "User reviewed the document and has no feedback. Please address the annotation feedback above." That no longer happens on Claude Code (with the mod), Pi, OpenCode 1 and 2, Amp and Droid. The session closes, the host logs that nothing was sent, and the agent is not prompted.
/plannotator-lastbehaves the same way.The Plannotator binary must be updated for this: the 0.28.0 and 0.28.1 binaries do not send the signal, so Claude Code, OpenCode's CLI bridge, Amp and Droid keep the old behavior until you run the install script. Pi and the OpenCode embedded runtime ship their own server, so the plugin update is enough. Hosts that run Plannotator through a skill (Codex, Gemini, and Claude Code with the mod off) still pass the same sentence on, unchanged. For scripts,
annotate --jsongains an additivenothingToSend: truefield in this case; other output is unchanged.Counting is fixed too. In a folder annotate session, the "N comments" figure, the host record and the feedback history counted only the open document's comments. They now count every document's comments. The same fix applies to
/plannotator-lastwith several messages selected, which also now includes comments posted by outside tools (agents, WebMCP); before, those were missing from the exported feedback. The feedback history records which document each comment belongs to.
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- fix(questions): plain-bullet choices keep their wrapped lines; question context renders block markdown by @backnotprop in #1699
- fix(questions): answers saved under a 0.28.1 label still show their pick by @backnotprop in #1702
- fix(export): image headings name the resolved file; diff comments sort after the document by @backnotprop in #1700
- fix(annotate): a bare Done starts no agent turn on any plugin host; submits count every document's and message's comments by @backnotprop in #1701
Full Changelog :
v0.28.1...v0.28.2 -
π OmniNull/OmniWM OmniWM v0.7.5 release
What's New Since 0.7.4
Bind extra mouse buttons, show notification badges on the Workspace Bar, and choose your tiling animation speed. OmniWM 0.7.5 also improves preview sharing, browser picture-in-picture, Quake shortcuts, and window lifecycle handling.
Workspace Bar and mouse controls
- Show notification badges. Display Dock notification badges as dots or text on Workspace Bar app icons, including expanded scratchpads. Badges are off by default; enable them in Settings > Workspace Bar and choose a refresh interval from 1 to 60 seconds.
- Place the bar beside the notch. A new Right of Notch mode places the Workspace Bar just to the right of the notch and centers it on displays without a notch, with global and per-monitor controls.
- Manage window marks from the bar. Mark or unmark a window from its icon menu, including individual windows inside grouped app icons.
- Use extra mouse buttons as shortcuts. Settings > Hotkeys now records extra mouse buttons, alone or combined with Control, Option, Shift, Command, or Hyper, for assignable actions. A mouse binding replaces that action's keyboard binding; assigned presses are consumed so the app underneath does not also handle them.
- Choose more wheel modifiers. Mouse-wheel column scrolling supports additional modifier combinations, including all four modifiers. Option + Shift remains the default. The four-modifier choice works with remappers that hold the actual modifier keys; OmniWM's System Hyper trigger does not add modifiers to wheel events.
Layout and window behavior
- Set tiling animation speed. Adjust Settings > General > Tiling Animation Speed (0.25Γ to 4Γ), or
general.animationSpeedinsettings.toml. The default preserves the existing motion, and Reduce Motion remains respected. - Fill underused Niri space. When fewer containers are open than the configured visible count, Niri expands them proportionally while respecting their relative sizes and application constraints. Manual resizing takes priority until the container count changes.
- Open vertical Dwindle splits below. New windows now appear below the existing window for default vertical splits and centered Smart Split decisions. Explicit preselection directions are preserved.
- Restore fullscreen column peeking. Niri keyboard navigation can bring the selected window in front of an overlapping layout-fullscreen window again.
- Focus covered tiles without raising them. With raising enabled, Focus Follows Mouse skips raising a tiled window when a visible managed floating window overlaps it from the front.
- Keep browser PiP visible across workspaces. Recognized picture-in-picture windows from Firefox, Zen, LibreWolf, Chrome, Brave, and Edge stay outside workspace management.
- Handle withdrawn windows correctly. Windows an app withdraws without destroying no longer leave empty tiles or get unexpectedly refocused; they can rejoin their layout when shown again.
- Keep borders in step with windows. Focus borders track closure and movement more reliably, and native corner geometry stays steadier during focus changes.
Quake, Hidden Bar, and input reliability
- Customize Quake shortcuts through Ghostty. Tab and pane actions now honor Ghostty keybindings, including remaps and unbinds. Quake also follows the system's window-corner preference.
- Update Quakeβs Ghostty engine. Uses Ghostty 1.3.2-main+b094a6ba3, including fixes for crashes when narrowing terminals containing wide characters and legacy Control + Option + Shift + Backspace encoding.
- Use Notification Center while hiding menu-bar apps. Hidden Bar now uses native per-app visibility preferences. Its drawer attaches to the Workspace Bar, displays captured native menu-bar glyphs, and provides a nearby OmniWM menu button.
- Preserve existing system key remaps. Enabling Caps Lock Hyper keeps unrelated key mappings intact and improves restoration after an unclean exit. Native API reads replace
hidutilsubprocesses: an optimized M4 Max / macOS 27.2 / Swift 6.4 benchmark measured 72.9 ms β 0.95 ms per read, about 77Γ faster. - Handle Secure Input changes. OmniWM now notices when Secure Input starts or stops and keeps shortcuts registered, so the ones macOS still delivers keep working; the indicator explains which ones it may withhold.
- Avoid stale submenu openings. Moving away from a status-menu item no longer lets an already superseded hover open its submenu later.
- Hotkey action labels are clearer, Page Up/Down shortcut glyphs are legible, and Smart Split help no longer incorrectly says it follows the cursor.
Performance, previews, and automation
- Remove repeated permission-check stalls. Overview scrolling and search, hover previews, swipes, and drags use cached Screen Recording permission. A native check measured about 9.3 ms on the main thread; a 96-second live debug session recorded no checks across 332 Overview scroll events, 118 hover-preview events, and four swipes. Permission refreshes when leaving System Settings.
- Show shared previews sooner. Overview, Workspace Bar hover previews, workspace swipes, and drag ghosts share preview frames and window discovery. In a recorded live debug session, 14 of 15 hover requests and 19 of 22 Overview cards already had a frame ready. Sharing avoids repeating discovery work previously measured at 28 ms warm and about 90 ms cold.
- Reuse wallpaper captures. Smaller wallpaper variants can reuse a larger cached image, avoiding a fresh capture that previously spent about 0.65 ms listing windows and 2 ms capturing before downscaling.
- Reduce tiling CPU work and allocations. Optimized M4 Max / macOS 27.2 / Swift 6.4 benchmarks with 12 windows measured snapshot construction at 3.98 β 2.42 Β΅s per call (39% lower CPU time), with Swift allocations falling from six to one. The same optimization stage reduced Niri layout CPU time by 7.5% and local bookkeeping for skipped AX requests by 17%.
- Cache stable layout settings. A subsequent change caches monitor frames, gaps, display scales, and border settings between changes. Separate optimized benchmarks measured a further 20β23% reduction in snapshot CPU time against the intermediate build; monitor snapshots fell from 528 β 46 ns.
- Release unused swipe previews. Turning off workspace swipes or animations, including through Reduce Motion, releases their cached frames and backdrop.
- Build better external bars. IPC queries expose one-based Niri column indices and column positions relative to the target viewport. Change-driven events let integrations track off-screen columns without inferring them from window frames.
- Honor empty PATH entries in watch commands.
omniwmctl watch --execnow searches the current directory at each emptyPATHentry, preserving the configured executable search order.
Breaking changes and upgrade notes
- IPC protocol is now 18, previously 17. Update
omniwmctland custom IPC clients alongside OmniWM. The bundled CLI already uses the new protocol. - The default IPC location moved. The socket is now
~/Library/Application Support/com.barut.OmniWM/ipc.sock; its authentication secret is alongside it asipc.sock.secret. Update integrations that hard-code the old~/Library/Caches/com.barut.OmniWM/location.OMNIWM_SOCKETremains supported. - Existing Ghostty remaps now affect Quake. Custom tab and pane bindings, including unbinds, take precedence inside Quake. Default shortcuts remain when not overridden. The global Quake toggle stays in OmniWM's hotkey settings.
- Quake corrects a legacy key sequence. Control + Option + Shift + Backspace now sends
ESC BS(0x1b 0x08) instead ofDEL(0x7f) in legacy encoding mode. Terminal applications with custom bindings for that sequence may need updating. - Recognized browser PiP windows are unmanaged. They are no longer floating workspace members, and app rules or manual overrides cannot bring them under workspace ownership.
Thanks
Thank you to:
- Henrik Larsson Hestnes for right-of-notch Workspace Bar placement.
- Taylor Bell for clearer hotkey action labels.
- Luke Stephens for stabilizing native border corners.
- Zhizhen He for correcting the Smart Split description and preserving empty PATH entries in watch commands.
- Richard Ginzburg for legible shortcut labels.
- Aleksei Gurianov for GitHub Actions release preparation and publication.
- Nick Nisi for supporting OmniWM through GitHub Sponsors.
Full changelog: v0.7.4β¦v0.7.5
-
π backnotprop/plannotator v0.28.1 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.28.0 | Ask this session in Claude Code, Pi and OpenCode 2, Claude Code mod on by default, Pi plan review no longer blocks, first-run demo
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right session
v0.27.18 | Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushes
v0.27.17 | Diagram files open in the diagram viewer, OpenCode switches model with agent, idle review stops polling the git remote, Tree is the default review view
v0.27.16 | Themed diagrams on Mermaid 12, comment on any node or edge, patch-file review, embedded HTML documents renderWhat's New in v0.28.1
v0.28.1 is a patch release with five pull requests, all from @backnotprop. It fixes feedback that was exported twice in folder annotate sessions, adds Ask AI to diagram comments, makes image pins in HTML pages say which image they point at, and fixes three OpenCode problems found while testing v0.28.0.
Folder annotate no longer sends each comment twice
In a folder annotate session, every comment on the open file was exported twice: once under "Folder Feedback" and again under "Linked Document Feedback". The second copy was also a weaker one. It was sorted by block id as text (block 10 before block 2) and left out the
[In diff content]label, quick-label headings and tips, the Label Summary, and reply threading. This affected every host, because the export is built in the browser.Each comment now appears once, in document order, with full detail. In a folder session the section is titled "Folder Document Feedback" and lists each file with its comments under its path. The same fix covers two related cases:
- Plan review submitted while a linked document was open dropped the plan's own comments. They are now included.
- When a file session opened a copy of its own page (a "Home" link, for example), comments on that copy were dropped from the export while a linked document was open. They are now exported under that file's path.
Plain plan review output is unchanged for comments, deletions and general feedback.
Ask AI from a diagram comment
The comment box on a Mermaid or Graphviz diagram now has an Ask AI button, next to Cancel and Comment. It works inline and in the popout, for diagrams in fenced code blocks and for diagram files (
.mmd,.dot). The button is disabled until you type a question, and Enter still posts the comment.The question carries the node, edge or cluster you clicked, its line in the document, the diagram type, and an excerpt of the diagram source with line numbers. The excerpt is capped at 40 lines or 4000 characters and always includes the part you picked. Asking from the popout closes the popout, so the answer in the panel is visible.
Pinning an image tells the agent which image
In HTML annotate, pinning an image or another element with no text recorded only its kind, as
[element: Image]. Ask this session answered that it could see an image was selected but not which one.The description now includes the element's label, its accessible name (aria- label, alt text, title) and, for media, the file name:
[element: Image "Team photo" (team.jpg)],[element: Button "Open menu"],[element: Frame (prototype.html)]. Query strings are dropped and adata:URL is shortened to its media type. This appears in the comment, in the exported feedback, and in Ask AI questions, which now also include the pinned element's details. In HTML file sessions, image paths are reported as written in the page (office.png) instead of Plannotator's internal asset URL. Pins saved earlier still restore.OpenCode fixes
Three problems found while testing v0.28.0:
- OpenCode 1 shows the session URL for commands.
/plannotator-review,/plannotator-annotateand/plannotator-lastonly wrote the URL to OpenCode's log file, so a remote or SSH user never saw it. They now show it in a toast, the way plan review already did, in local and remote mode. - OpenCode 1 answers once per feedback. OpenCode 1 always runs a turn on the command's own message, and Plannotator was emptying that message and sending the feedback separately, so the model replied twice. The feedback now rides on the command's own message, and the agent and model are the same as before. A command with nothing to send (Close, or Done with no notes) still runs one turn on an empty message; OpenCode 1 gives plugins no way to skip it.
- OpenCode 2 no longer feeds the "session ready" notice to the model. After a plan decision, the model could answer with
Plannotator session ready: <url>instead of your feedback. The notice stays visible in the transcript but is removed from what the model receives.
Commands you run afterwards still go to the agent you ran them on, as in 0.28.0.
Additional Changes
- Comment box trimmed. The
ββ΅/Ctrl+Enterhint is gone from the comment box (the shortcut still works), and HTML pages no longer show a "Looks good" button in the comment box. To leave a thumbs-up on an HTML page, select text and use the π in the toolbar. (#1693)
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- fix(ui): drop the ββ΅ hint from the comment popover and the composer's Looks good on HTML by @backnotprop in #1693
- fix(annotate): tell the agent which image (or element) a pinpoint points at by @backnotprop in #1694
- feat(diagrams): Ask AI from a diagram comment by @backnotprop in #1695
- fix(annotate): folder sessions export each comment once by @backnotprop in #1696
- fix(opencode): remote URL toasts on OpenCode 1, one turn per feedback, notice ordering by @backnotprop in #1697
- fix(opencode): keep the user's agent for follow-up OpenCode 1 commands by @backnotprop in #1698
Full Changelog :
v0.28.0...v0.28.1 -
π smol-machines/smolvm smolvm v1.23.2 release
What's Changed
- Show the Homebrew install in the README by @BinSquare in #1551
- Finish a restore instead of relaunching the workload when exec wakes a restored machine by @BinSquare in #1553
- Bump the workspace to 1.23.2 by @BinSquare in #1554
Full Changelog :
v1.23.1...v1.23.2 -
π backnotprop/plannotator v0.28.0 release
Follow @plannotator on X for updates
Missed recent releases? Release | Highlights
---|---
v0.27.25 | Code review works withcolor.diff = always, Bitbucket review fixes, wide tables no longer collapse in Firefox, install script fix
v0.27.24 | Image previews stay in the all-files view, PR comment previews open on the commented line
v0.27.23 | Bitbucket Cloud PR review, Question UI for answering agents in place, opt-in auto-update, viewed files remembered, review another repo or worktree
v0.27.22 | Plans open the docs they link to, Claude review jobs locked down, Code Tour on Linux without Claude's sandbox, Pi reviews the latest plan
v0.27.21 | Remote and phone sessions load several times faster, real Request changes on GitHub, model pickers show real names, OpenCode fixes
v0.27.20 | Mistral Vibe support, annotate gets the full Options menu and Settings, jj Commits panel, long lines wrap in plan code blocks
v0.27.19 | Before/After image previews in code review, file comments as GitHub file threads, forge-correct#123links,/plannotator-lastfinds the right session
v0.27.18 | Model pickers from your installed Claude and Codex (Opus 5.5, Fable 5.1, GPT-6), unsent PR review comments survive new pushes
v0.27.17 | Diagram files open in the diagram viewer, OpenCode switches model with agent, idle review stops polling the git remote, Tree is the default review view
v0.27.16 | Themed diagrams on Mermaid 12, comment on any node or edge, patch-file review, embedded HTML documents render
v0.27.15 | Plannotator TUI and Herdr Annotate announcement, element context on pinpoints, HTML links open as linked documents, All files panel, Classic diff defaultWhat's New in v0.28.0 Plannotator now connects to the agent session that opened it. Ask AI can be answered by your Claude Code, Pi, or OpenCode 2 session instead of a separate AI, and in Claude Code and Pi the agent no longer sits waiting while you review: your decision arrives later as a message. This release has 24 pull requests, two of them from community contributors, including one first-time contributor. Ask this session When Plannotator was opened by Claude Code, Pi, or OpenCode 2, a question you ask in Ask AI goes to that agent session. It shows up in the agent's chat as a real turn, the agent answers with the context it already has and can use its own tools, and the answer streams back into the Ask AI panel. The panel reads "Ask this session Β· Claude Code" (or Pi, or OpenCode). When a session is connected, it is the only Ask AI option, so there is no provider or model picker. A provider you saved earlier is left alone and still applies in sessions without a connection, and Review Agents, Code Tour, and Guided Review keep their own model pickers. If the agent is busy, you can choose "Ask when it finishes" or "Interrupt and ask now". Stopping a question cancels only that question; Plannotator never interrupts a turn on its own. If the session has ended, Ask AI says it can no longer reach it. Where it works: Claude Code: plan review, code review, annotate, and /plannotator-last, through the Claude Code mod described below. Pi: plan review, code review, annotate, and /plannotator-last. OpenCode 2: code review, annotate, and /plannotator-last as real turns. During plan review OpenCode is still waiting on submit_plan, so Ask AI gives a "Quick answer from this session" from the conversation, without tools, and writes nothing to the transcript. Not connected: OpenCode 1, Claude Code without the mod, remote mode, and --tailscale sessions. These keep the separate AI providers exactly as before. The first time you open Plannotator from a connected session, a short panel with a demo video explains the feature. It appears once, only when the session really is connected, and only before you start working on the page. It links to the Ask this session guide. (#1668, #1671, #1685, #1690) Claude Code no longer waits while you review On Claude Code 2.1.287 and later, in the interactive terminal, the Plannotator plugin now runs as a Claude Code mod, and it is on by default. Plan review, /plannotator-review, /plannotator-annotate, and /plannotator-last open in the browser and hand control back to Claude right away. When you decide, the decision arrives in the chat as a message from the plannotator plugin, and Claude acts on it. While the review is open you can keep talking to Claude, and Ask this session works. Plan review under the mod works like this: When Claude calls ExitPlanMode, the review opens and Claude is told the plan is not approved yet. Plan mode stays on. If Claude revises the plan while the review is open, the same tab updates to the new version and keeps your comments. A decision made on an older version is refused, and the tab loads the new one so you can decide again. After you approve, Claude calls ExitPlanMode once more and proceeds with the exact text you approved, in the permission mode you picked. Denials and answered questions arrive as messages, using the same prompts as before. Decisions with nothing to send (Done with no comments, an LGTM, Close) only log a line and do not start a turn. Feedback over 12 KB is saved to a file that Claude is told to read. /plannotator-last keeps its picker of recent messages, so you can still annotate an earlier reply. Review servers keep running if Claude Code exits: run claude --continue or --resume, and the decision is delivered into that session. Older Claude Code, -p and SDK sessions, and Windows keep the classic flow, unchanged. To turn the mod off, set PLANNOTATOR_CLAUDE_MOD=0 or add { "claudeCodeMod": false } to ~/.plannotator/config.json; it takes effect the next time Claude Code starts. The plugin and the plannotator binary update separately, so update both (see Install / Update below). With an older binary, plan review falls back to the classic blocking review and Claude Code shows one line asking you to update; review, annotate, and last still open, without Ask this session. (#1672, #1686, #1684, #1691) Claude opens Plannotator through a tool instead of Bash Asking Claude to "open this in plannotator" used to make it run the CLI through Bash, which blocked Claude and left Ask AI on a separate AI. Under the mod, Claude now has a plannotator tool for annotate, review, and last. It opens Plannotator exactly the way the slash commands do and returns at once, and the decision arrives later as a message. With gate: true, an approval is sent back too, so Claude can continue once you sign off. The plannotator skill now tells agents to always use the tool when they have it, including for approvals. The installer refreshes the skill. Claude still sometimes reaches for the CLI. When it runs a simple command such as plannotator annotate notes.md --gate --json in the main session, the mod now opens it the same way the tool does. Only plain annotate <file> (with --gate or --markdown), review (with an optional target and --base), and last are taken over. Anything with other flags, shell syntax, an environment prefix, or a path to a dev build runs the real CLI, so scripts that depend on --require-approval or --result-file exit codes keep working. Commands from subagents always run as written. Strict gate flags don't fit a slash command, because nothing would read the result. Typing /plannotator-annotate notes.md --require-approval (or --result-file, or --hook) under the mod now opens nothing and tells you to run that command in a terminal. Before, the reviewer's feedback was lost. (#1673, #1687, #1688, #1692) Pi plan review no longer blocks the session On Pi, plannotator_submit_plan now returns as soon as the review opens, and the agent ends its turn. Your decision arrives later as a session message. An approval switches Pi to executing first, then sends the approval. A denial or answered questions come back as feedback. Planning restrictions stay in place until you approve, so nothing gets implemented early. If the agent resubmits while the review is open, the same tab updates to the new version and keeps your comments, as in Claude Code. Esc no longer cancels a plan review; leave plan mode to abandon it. Ask this session works during plan review. (#1670) Claude Code plan review shows the plan Claude just wrote Claude Code plan review sometimes opened the previous version of a plan, usually the one you had just denied. This happened when Claude edited the plan file and called ExitPlanMode in the same message, which recent models often do after a denial. Claude Code captured the plan text before the edit ran, so the review, the version history, and the approval all recorded the old text. Plannotator now reads Claude's plan file when Claude Code sends its path and the file is an absolute .md file under 2 MB, and falls back to the inline text otherwise. On approval, Claude proceeds with the plan you reviewed. Claude Code 2.1.285 fixed the cause upstream, and this covers everyone on older versions. (#1667, by @workflow) Question cards Pinpoint targets what you click. In Pinpoint mode, hovering or clicking any choice in a question card highlighted the question's prompt instead, and recorded no answer. This had been the case since question cards shipped in v0.27.23. A pinpoint click now pins the prompt, the context, or the choice you clicked, and clicking a radio or checkbox answers (#1683). Agents give questions some context. The question guidance in the plannotator skill now tells agents that a sentence or two of context helps reviewers answer faster, and that the context can include an image for visual questions (#1674). Decision questions. A Decision: when answered line, or Decision: , marks a question whose answer becomes a decision, and the card shows a decision tag for it (#1664). Image links in annotated HTML open in the lightbox
In a raw-HTML annotate session, a link to a local image, such as a thumbnail linking to a full-size render, used to show a "Can't open" toast. In Interact mode it now opens in the image lightbox; with pinpoint armed, the click still pins the element. Only images inside the page's own folder open this way, so nothing becomes readable that the page could not already load. While the lightbox is open, Esc closes it and
Mod+Entercannot submit a decision behind it, which also fixes the lightbox in markdown documents.(#1676)
Installer fixes
- The Claude Code mod is no longer stripped on install. Every installer run overwrote
hooks.jsonin Claude Code's marketplace copy of the repo with an old hard-coded version, and the next plugin install copied that file, without the mod, into the installed plugin. The installers no longer touch that file. If an earlier installer had rewritten it, they restore it from git, but only when it matches a shape an installer wrote, so your own edits are kept (#1689). - OpenCode 2 picks up the new plugin. The installers cleared only OpenCode 1's plugin cache. They now also clear OpenCode 2's cache under
~/.cache/opencode/npm/(or$XDG_CACHE_HOME), so re-running the installer loads the new version (#1689). install.cmdadds Plannotator to your PATH. The Claude Code hook now runs a bareplannotator, so it needs to be on PATH.install.ps1already added the install folder to the user PATH;install.cmdonly printed advice and now adds it too, without creating duplicates (#1692).
For embedders:
@plannotator/uiand@plannotator/core- Apache-2.0. Both packages now declare the Apache-2.0 license and ship its text (#1675).
DiffFileTree. A read-only file tree to put beside your own diff list. It is the code review file tree itself, moved into@plannotator/ui, with keyboard navigation and tree ARIA roles. Plannotator's review renders from the same parts and looks the same as before (#1678).- HTML frame height and fence themes. Hosts that size the HTML viewer to its content got a frame cut short when a page's first or last element had a margin; the measured height now includes those margins. A new
fenceThemeoption onconfigurePlannotatorUIlets a host choose the code block theme (#1677). - Question hooks.
findQuestionBlocks, a new@plannotator/core/markdown-structuresubpath, a footer slot for host actions on question cards, and an explicit save mode for answers (#1664).
These shipped as
@plannotator/core0.25.9 /@plannotator/ui0.49.0 and@plannotator/core0.25.10 /@plannotator/ui0.50.0 (#1682). Note for the next@plannotator/uirelease: the "Ask a separate AI instead" fallback helpers that shipped in 0.50.0 (resolveSessionBridgeFallback,findUsableSessionBridge,sessionAskFallbackLabel) are removed, because a connected session is now the only Ask AI option (#1685).Additional Changes
- Clear message when the OpenCode CLI is missing. Choosing the OpenCode provider without
opencodeon your PATH showed a rawENOENTerror. It now says the CLI is missing and suggests installing OpenCode or picking another provider (#1669, closing #1503, by @Aayushyaash). - One-line error when the remote port is taken. In remote mode Plannotator uses one fixed port, so a second session at the same time crashed with a stack trace. It now prints one line naming the port and suggesting
PLANNOTATOR_PORT, and exits with the usual startup-failure code (#1692). - Ask AI loads faster. Plannotator no longer asks the
piCLI for its models at startup, which could hold up Ask AI for up to 10 seconds. Pi's model list now loads when you pick Pi or start a Pi session, like Codex and OpenCode (#1692). - Closing the tab stops a Pi answer. The Pi server kept an Ask AI answer running after you closed the tab or asked a new question. It now stops it, as the server used by Claude Code and OpenCode already did (#1668).
- Docs. The Claude Code, OpenCode, Pi, and AI features guides cover the mod, Ask this session, the opt-out, and the corrected plugin update steps, and troubleshooting has a new entry for "Claude Code still waits for my review" (#1691).
Known issues
- Leaving plan mode during a review. Under the Claude Code mod, Claude is not blocked while a plan review is open. Plan mode stays on and Claude is told the plan is not approved, but if you leave plan mode yourself (Shift+Tab) and keep talking, Claude can start editing before you approve.
- Review servers outlive Claude Code. A review the mod started keeps running after Claude Code exits, so it can be reattached with
--continueor--resume. If you never resume that session, the server runs until you decide or close the tab. - One session at a time in remote mode. Remote mode uses one fixed port, so two sessions cannot run at once. The second one now stops with a clear message; set
PLANNOTATOR_PORTto run it on another port.
Install / Update
macOS / Linux:
curl -fsSL https://plannotator.ai/install.sh | bashWindows:
irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: The plugin and the
plannotatorbinary update separately, so run the install script above as well. In a terminal:claude plugin marketplace update plannotator claude plugin update plannotator@plannotatorThen restart Claude Code. Inside Claude Code, run
/plugin marketplace update plannotator, then open/pluginβ Installed β plannotator β Update now.Pi:
pi update --extensionsOpenCode: Re-run the install script above. It now also clears the OpenCode 2 plugin cache.
What's Changed
- feat(questions): Decision flag, findQuestionBlocks, host footer slot by @backnotprop in #1664
- fix(hook): review Claude's plan file, not its stale inline snapshot by @workflow in #1667
- feat(ai): Ask this session (core + Pi) by @backnotprop in #1668
- fix(ai): show friendly error when opencode CLI is unavailable by @Aayushyaash in #1669
- feat(pi): non-blocking plan review, with Ask this session during review by @backnotprop in #1670
- feat(ai): Ask this session for OpenCode 2 (host-neutral pull bridge) by @backnotprop in #1671
- feat(claude-code): mod for non-blocking plan review, annotate, review and last, with Ask this session by @backnotprop in #1672
- feat(claude-code): plannotator tool for agent-initiated opens under the mod by @backnotprop in #1673
- docs(questions): suggest context and images in question blocks by @backnotprop in #1674
- chore(npm): Apache-2.0 license for @plannotator/ui and @plannotator/core by @backnotprop in #1675
- feat(annotate): open local image links in an HTML page in the image lightbox by @backnotprop in #1676
- fix(ui): srcdoc frame height with collapsed margins + fenceTheme host seam by @backnotprop in #1677
- feat(ui): embeddable read-only DiffFileTree shared with the code-review tree by @backnotprop in #1678
- chore: bump @plannotator/core 0.25.10 and @plannotator/ui 0.50.0 by @backnotprop in #1682
- fix(ui): pinpoint in a question card targets what was clicked, not the prompt by @backnotprop in #1683
- fix(claude-mod): restore the message picker for /plannotator-last by @backnotprop in #1684
- fix(ai): Ask AI uses only the session when a session bridge is present by @backnotprop in #1685
- feat(claude-mod): turn the Claude Code mod on by default by @backnotprop in #1686
- docs(skill): always use the plannotator tool over the CLI when you have it by @backnotprop in #1687
- feat(claude-mod): agent-run plannotator commands open through the mod, so Ask AI reaches the session by @backnotprop in #1688
- fix(install): stop stripping the Claude Code mod from the marketplace clone; clear OpenCode 2's plugin cache by @backnotprop in #1689
- feat(ui): first-run announcement for Ask this session and non-blocking reviews by @backnotprop in #1690
- docs: 0.28.0 β Claude Code mod on by default, Ask this session, correct plugin update steps by @backnotprop in #1691
- fix: 0.28.0 QA fixes β strict gates under the mod, clean port-in-use error, deferred pi discovery, Windows PATH by @backnotprop in #1692
New Contributors
Contributors
@workflow found why Claude Code plan review sometimes showed the plan that had just been denied. The write-up traced it to Claude Code capturing the plan before a same-message edit ran, with timings from a real session, and the PR came with tests and an end-to-end replay of the real hook event. First contribution to the project.
@Aayushyaash replaced the raw
ENOENTerror with a clear message when the OpenCode CLI is missing, a second contribution after the Ask AI dropdown fix in v0.27.25.Community
- @modelpath-dev pinpointed where the missing-CLI error should be caught in #1503
Full Changelog :
v0.27.25...v0.28.0 - The Claude Code mod is no longer stripped on install. Every installer run overwrote
-
π matklad Benchmark In Milliseconds rss
Benchmark In Milliseconds
Oct 5, 2026
How long should a micro benchmark run? My rule of thumb is to tweak the input size until the benchmark takes about 300ms, for the following reasons:
- Milliseconds are integers ranging from 1 to 999. Enough precision to notice even a small improvement, and easy to scan visually. No need for different units or floating points (compare
1.31swith239ms). - Anything faster than, say,
10msrisks being skewed by fixed costs (e.g, interpreter startup). Hundreds of milliseconds is an eternity for a computer, usually enough to make one-off overheads irrelevant without using fancier (= less robust) techniques to explicitly account for them. - For a human, hundreds of milliseconds is fast, but noticeable. Pushing numbers into human-perceptible range allows me to use my intuitive sense of time and speed, it doesnβt rely exclusively on numeracy. Itβs plain fun to see, as a result of optimization work, how a previously lagging CLI command becomes βinstantβ.
- But anything longer than a second makes iterating on the benchmark slower than it needs to be. Running a benchmark 10 times in a row to eyeball variance should be fast!
The imminently-to-be-stated assumption here is that the purpose of benchmarking isnβt so much a precise measurement of performance, but rather providing the author with enough intuition to make a correct decision.
- Milliseconds are integers ranging from 1 to 999. Enough precision to notice even a small improvement, and easy to scan visually. No need for different units or floating points (compare
-
π Filip Filmar Linux boots to a shell on Vreteno rss
Mainline Linux now boots to a shell on Vreteno, the RISC-V core written in TxHDL. It runs on the Alinx AX7A200B board, an Artix-7 FPGA with 1 GiB of DDR3 memory, at 100 MHz. The kernel runs in supervisor mode with virtual memory turned on. OpenSBI runs in machine mode below it, and a BusyBox shell runs in user mode above it. This post describes what the core needed for that, how the boot was brought up, and what is still missing.
-
- October 04, 2026
-
π smol-machines/smolvm smolvm v1.23.1 release
What's Changed
- Stop live disk-chain merges and fix the merge claim deadlock by @BinSquare in #1546
- Let a no-network machine whose registry image the host fetched be checkpointed by @BinSquare in #1545
- Report in-flight requests on loopback and exit promptly after the shutdown grace by @BinSquare in #1544
- Accept an image reference with both a tag and a digest by @BinSquare in #1549
- Keep restored machines branching and log server error reasons. by @BinSquare in #1548
- Bump the workspace to 1.23.1 by @BinSquare in #1547
Full Changelog :
v1.23.0...v1.23.1 -
π MetaBrainz Picard 3.0 released rss
The Picard team is happy to announce the new major version 3.0 of MusicBrainz Picard, now available to download. MusicBrainz Picard is the official tag editor for the MusicBrainz database and helps you get your music collection sorted and cleaned up with data from MusicBrainz.

This release brings many changes, including an upgrade to Qt6, a completely new plugin system, several improvements to the user interface, cover art processing, ISRC submission and many more. More details below.
What's new? User interface improvements Qt is the application framework Picard is built upon. Qt simplifies the implementation of cross-platform desktop applications as it abstracts away many of the differences between various operating systems. Picard 2 was based on Qt5. With Picard 3 we have updated to Qt6. Besides ensuring that Picard stays up-to-date and available on modern desktops, this version change also brings some advantages like much improved support for screen scaling and better support for a dark mode. Specifically on Windows the old issues of having fonts scale inconsistently are now resolved. The UI now also supports a dark mode across all operating systems and switching between light and dark mode does no longer require a restart of the application. Picard already supported customizing the file and album list views by selecting the columns to display. In previous versions this was limited to a couple of pre-defined columns, though. New contributor knguyen1 implemented full custom column support. You can now define your own columns, where you can define the actual column content using scripting. This gives a lot of flexibility showing exactly the information you need. There is also a new pre- defined βMatchβ column that allows to sort releases by match quality. For more details see the chapter Custom Columns in the documentation. The columns context menu, allowing you to customize the columns being shown in the main list views. Another new feature, implemented by jpmsousa03, is the ability to filter the list views. You can select the fields to search and enter a search term. Only items matching this filter will be shown. It is now possible to select and copy multiple tags in the metadata view and paste them on e.g. another tag, updating all corresponding tags. It is also possible to paste multiple copied values into a spreadsheet tool. This feature was provided by StevilKnevil. The metadata view now also shows the actual differences between existing tags and the new tags being written. On a first start Picard now shows a setup wizard, that guides new users through some essential configuration. !Setup Wizard showing the File Organization settings. Also some essential functionality, such as loading files and clustering, gets explained by a tutorial mode when a feature is first used. Both the wizard and tutorial can be disabled or re-enabled in the user interface options. The tutorial being shown when a release is loaded for the first time. New plugin system
Apart from the Qt6 migration the new plugin system is the most significant change in Picard 3. While the previous plugin system enabled a lot of flexibility in Picard, it has a couple of limitations. For example, Picard would load, and partially run, the code of each installed plugin on every start, whether the plugin was enabled or not. This could lead to unwanted side effects and unexpected behavior. On the development side it proved also difficult for third-party developers, especially for more complex plugins, as all code had to be checked into the central
picard-pluginsGit repository.The new plugin system provides:
- Separation of plugin metadata and code:
MANIFEST.tomlis mandatory - A defined plugin API with typing support
- Git based versioning and updating of plugins
- Plugins can be installed and updated from a central plugin registry, from third-party Git repositories, or from a local directory
- Several trust levels (official, trusted, community, untrusted)
- The ability to blacklist plugins centrally allows us to react on security issues
- A
picard-clicommand line tool to manage (install, uninstall, updateβ¦) plugins - Plugins now support their own translation system (optionally manageable via Weblate), so their user interface texts can be translated
- Plugins have their own configuration namespace
All the extension points known from Picard 2 to register metadata processors, context menu actions, cover art providers, file formats, option pages etc. are still available. But there are several new extension points; plugins can now register cover art filters and processors, custom variables, actions in a global "Plugin Tools" menu and CD ripping log file formats.
As a user, the new plugin management under Options β Plugins now clearly separates installed plugins from plugins available for installation. Both the list of installed and available plugins can be searched, and it is possible to install plugins from third-party developers. See the Plugins Options documentation for a more in- depth description.
The new Plugins option page, showing a list of currently
installed plugins.This also means that Picard v2 plugins are not compatible and need to be migrated to the new system. There are already 30 plugins available, both plugins migrated from v2 and brand new ones. Have a look at the plugins v3 list on the Picard website.
If you are a developer and want to update your plugins to Picard 3 or maybe write a new one, please see the Plugin overview in the Picard User Guide and the detailed Picard Plugin v3 Documentation.
Cover art processing It is now possible to both filter and process cover art loaded from cover art providers. The new options in Cover Art / Processing allow you to ignore images below a certain size or automatically resize loaded images or convert them to a specific file format. Cover art processing can be extended by Plugins, which can register their own cover art filters and processors. Filters can restrict what cover art gets loaded, while processors can perform image processing on the loaded cover art. Cover art processing was implemented as part of Google Summer of Code 2024 by twodoorcoupe. You can read more about this in twodoorcoupeβs blog post GSoC 2024: Picard image processing. New tags and scripting enhancements As full support for synced lyrics was added, there is now a new %syncedlyrics% tag. The MuicBrainz Artist ID of a composer is available as a new tag %musicbrainz_composerid%. There are also several new variables, that provide data for tagging and naming scripts, but are not written as tags to the files by default. The new %_genres% and %_folksonomy_tags% variables give you access to the raw list of genres or folksonomy tags as loaded from MusicBrainz. For recordings with a broadcasted relationship the broadcasting date is available as %_broadcast_date%. If a recording has a linked work with a ISWC, the ISWC is now available as %_iswc%. The variables %_albumartists_countries% and %_artists_countries% contain all country codes for all credited album artists / track artists. Likewise the disambiguation comments for artists and album artists are available as %_artistcomment% and %_albumartistcomment%. The %_filesize% variable contains the file size in bytes (if the script is running in a context where a file is available, i.e. on tracks with a matched file or in a file naming script). There are now two new functions and [$get_original()](https://picard- docs.musicbrainz.org/en/latest/functions/func_get_original.html), which allow to explicitly request the original or new value of a variable. The $rsearch scripting function gained a new optional parameter, which can be used to specify the capture group inside the regular expression to be returned. Please see the documentation of the $rsearch function for an example. Improved built-in player
The built-in player received several improvements. As before the player is based on QtMultimedia. With Qt6 this component brings better cross-platform support for various audio formats and pitch-adjustment if playback speed changes (requires Qt 6.10).
The player has also been internally refactored to better separate the player and UI. This allows better integration with the OS. The player now supports macOS βNow Playingβ and on Linux can be controlled by MPRIS2 compatible tools. It can also submit listens to ListenBrainz. Both OS integration and ListenBrainz support can be configured in the new Audio Player Options.
Save and restore user session
Picard can save and restore your current workspace state as a session file under the main File menu. Sessions preserve file placement (unclustered, clusters, albums, specific tracks, and standalone recordings), your manual metadata edits, and selected configuration options so you can resume work later. Thanks to knguyen1 for this feature. See the chapter Sessions Management in the documentation for more details.
Export / import option profiles
Option profile support was already available in Picard 2. Option profiles allow you to create multiple different set of configuration options and quickly switch between them. With Picard 3 such option profiles now also can be exported and imported, both as a backup or to share them with others. If an option profile is exported in order to share it, the export will exclude any configuration options that are considered secret or private (such as authentication data). For details see the User Guide under Backing Up and Sharing Profiles.
Exporting and importing option profiles can also be done using the new
picard-clicommand line utility, see below.We are excited to see how this feature will be used by the community.
Operating system support
Picard is now available for macOS ARM64 aka Apple silicon. While it was previously possible to run Picard on such systems using Apples Rosetta 2 emulation layer, the native builds offer better performance. Please note that there are separate downloads for the ARM64 and Intel versions of Picard. Please make sure to download the file appropriate for your hardware.
Due to the updated dependencies, in particular Picard now using PyQt6 / Qt6 and the minimum supported Python version being 3.10, support for older operating systems had to be dropped.
Picard 3 requires Windows 10 or later or macOS 13 or later. Linux users should have Qt 6.6 or later and at least Python 3.10 available.CD disc lookup from tags and more log file import options
The existing functionality to lookup disc IDs from CD ripping log files was extended to support raw SCSI TOC data files as written by redumper.
For files ripped with iTunes / Apple Music and which contain the CD TOC as a
iTunes_CDDB_1tag it is now possible to perform a disc ID lookup directly from the tag. This is explained in detail in the User Guide under Lookup iTunes Tag.Synchronized lyrics
Picard 3 provides initial support for synchronized lyrics. It can load and save a
syncedlyricstag from ID3 and WMA tags. The synchronized lyrics are using the LRC format to describe the timings. We plan to extend support for synchronized lyrics with future updates to support more tagging formats and lyrics features.Translation of artist, release and track titles by aliases
The existing system to translate artist names using aliases has been extended to also provide translations of album and track titles. Also the old behavior of always falling back to using the sort name as translation has been made optional and is now disabled by default. See the Metadata Options documentation for details.
The new metadata translation options, which allow to
translate artist names as well as album and track titles.Improved release matching
The algorithm for matching files to releases and recordings after a Lookup was totally reworked and greatly improved.
Overall we expect the new algorithm to give better results. There is now also an extensive test framework in-place that allows us to detect regressions in the matching performance in the future.ISRC lookup and submission
Picard now supports extracting ISRCs from CDs and adding them to loaded releases. It can also submit ISRCs loaded from disc or already present in the tags back to MusicBrainz. If new ISRCs are present for matched files, the ISRC submission dialog can be opened from the menu in File β Submit ISRCs. For details see the documentation on Submitting ISRCs.
The new ISRC submission dialog. It will show which new ISRCs are
available for a recording and can submit those ISRCs back to MusicBrainz.Individual files with an existing ISRC tag can also be looked up by ISRC using Lookup byβ¦ β Lookup by ISRC from the file's context menu.
Command line utility "picard-cli"
Picard 3 comes with a new command line utility "picard-cli". Currently this allows managing plugins and exporting/importing option profiles from the command line. Run
picard-cli --helpfor more details.Updated Picard User Guide
The online documentation available at https://picard-docs.musicbrainz.org has been updated for all of the changes in Picard 3. It is now hosted on ReadTheDocs and available in English, French and Dutch. When opening documentation pages from inside Picard the links will use the language matching Picard's user interface language, if available. You can help translate the Picard User Guide into your language, see the instructions for Picard, Picard Website and Picard User Guide Internationalization.
Performance and memory optimizations
This release includes several optimizations to improve the speed and responsiveness of Picard during certain operations and to reduce memory use.
And moreβ¦
There have been many more improvements and bug fixes: Picard 3 is the product of roughly three years of work that began in late 2023 with the move to PyQt6: 687 merged pull requests, nearly 6,800 commits from over 100 contributors (including 40-ish translators), and almost 400 resolved tickets.
A good part of the code was rewritten, to ease maintenance and future evolution. Static typing is now used (but covering the whole code will take some time, we focused on important parts).
Test coverage is also much larger.Please see the change log for a complete list of changes.
Download
Picard 3.0 is available for download from the download page of the Picard website.
Please note: For Windows users installing from the Windows Store the update to version 3.0 is not yet available. We will provide a Windows Store release with an update shortly. The Linux Flatpak package is maintained separately and will be updated soon.
Picard is free software and the source code is available on GitHub.
Acknowledgements
Getting this new major version of Picard ready was a huge effort, one that wouldn't have been possible without the many contributors. Thanks to everyone who helped with code, translation or reporting issues and feature requests.
Code contributions by Adela Chang, Akshat Khatri, Anton Kesy, Arnab Chakraborty, Bob Swift, Bryan Roessler, David Kellner, Deepak Kumar, Francisco Lisboa, FRC, Goldmaster, Greg Myers, Deepak Tiwari, James Le Cuirot, joncrall, JoΓ£o Sousa , Julian Anderson, Kajal Soni, knguyen, krotka, Laurent Monin, Lctrs, leo60228, Marethyun, Martin, Martin Natano, metaisfacil, OscarL, Philipp Wolfer, pranavsource1, Rakim, ripstream, Sanskar Mittal, Alex, ShubhamBhut, soniikajal, Sophist, StevilKnevil, nullHawk, thekiefs, Thuna, Giorgio Fontanive, x11x and Yohay.
Translations were updated by:
Albanian: Besnik
Arabic: alaishaq
Catalan: Marc Riera
Chinese (Simplified Han script): imgradeone, KenParker_CN and Nebulain
Chinese (Traditional Han script): BestSteve, Iceman1415 and silentbird
Czech: Fjuro
Dutch: mfmeulenbelt, RandomMushroom128 and toineenzo
English (United Kingdom): glawie
Estonian: Priit JΓ΅erΓΌΓΌt
Finnish: Jaakko PerttilΓ€
French: Laurent Monin and rez00
Galician: ninjum
Georgian: NorwayFun
German: bababasti, chaban, Gsam3, janrieger, Philipp Wolfer and st.esser
Greek: Theo Asimakopoulos
Hungarian: hildgyorgy and pXF
Italian: GABG and salo.rock
Japanese: marudosurdo, RT2231, shuuji3 and zatto13
Korean: coldified_
Lithuanian: Vaclovas Intas
Malay: Jeluang
Norwegian BokmΓ₯l: "ApeKattQuest, MonkeyPython" and Metafono
Polish: ankhedonic, Echelon and Michal77
Portuguese: evarfino and joaodtx
Portuguese (Brazil): cristian_emanuel and vitortle
Russian: Dimlbur, wileyfoxyx and Wonordel
Spanish: deusdagon, Dino RTX, jaimeMF and NicolΓ‘s Tamargo
Spanish (Latin America): MichTheOcelot
Swedish: blueday
Turkish: brtc and dirt3009
Ukrainian: Arhidimon, emptybrainz, Nerten and oleh_hishakGet in touch
Please use the MetaBrainz community forums and the ticket system to give feedback, suggest new features or report bugs.
Breaking changes
- Support for older operating system versions was dropped due to the update to Qt6 and newer Python versions. That means the minimum supported Windows version is now Windows 10, while for macOS you need macOS 13 "Ventura" or later. Users on older operating systems, who cannot or do not want to update their OS, should continue to use Picard 2. We plan to do at least one final Picard 2 release with important fixes to allow this version to be continued to be used.
- Not all plugins from Picard 2 are available. Several important ones have been ported, but some old plugins were unmaintained or do not meet the quality standards expected. If you miss a specific plugin you rely on please let us know in the community forums.
- The artist sort name by default is no longer used as a fallback to provide a "translated" name. The previous behavior resulted in several bugs being reported with wrong artist names after translation. If you relied on the old behavior you can restore it by enabling "Use artist sort name for translation" in the Metadata Options.
- Passing a parameter to the
$matchedtracks()scripting function now is an error. Previously it was possible to pass a parameter to this function (e.g.$matchedtracks(%artist%)), but it had no effect. - The lyrics and comments tags now always support a language, which is used when the tag is being loaded from or saved to ID3. The format is
lyrics:lang:description/comment:lang:description, wherelangis a 3 letter ISO code and description an additional descriptive text. If the language is being omitted, the separating colons are still mandatory, e.g.comment::description.
Known issues
- On macOS, in some setups, the global menu is not showing check marks for checkable menu items. It is currently unclear which exact setups are affected by this. If you experience this issue, please reach out with details on your macOS version (see PICARD-2509).
- Restoring a large session takes a significant amount of time and causes the UI to become unresponsive. We plan to improve this in future releases (see PICARD-3460).
- The
picard-clicommand line tool is not available on macOS when being installed as an app. However, it can be installed by installing Picard from PyPI.
Change log
Since the last stable Picard release 2.13.3 there have been 14 pre-releases for Picard 3. During the development we addressed 393 tickets to fix bugs, add features and improve existing functionality. Please see the detailed change log on the website for a full list of changes.
- Separation of plugin metadata and code:
-
π smol-machines/smolvm smolvm v1.23.0 release
What's Changed
- Explain published ports whose guest server listens only on loopback by @BinSquare in #1514
- Bump the workspace to 1.22.3 by @BinSquare in #1515
- Bump the Nix package to 1.22.2 and refresh the flake inputs by @BinSquare in #1517
- perf: cut the per-run registry tax on seeded starts by @BABTUNA in #1511
- agent: expedite RCU before the shutdown freeze by @BABTUNA in #1520
- Let x86_64 machines attach devices on IRQs 16-23 so more volumes boot by @BinSquare in #1521
- Resume a live checkpoint's source before its saved RAM reaches disk by @BinSquare in #1519
- Branch a running machine without limit and remove the disk layers no branch reads by @BinSquare in #1526
- Let smolvm serve run nested-virtualization machines only when started with --allow-nested-virt by @BinSquare in #1528
- Let a checkpoint taken on an arm64 Mac restore on arm64 Linux by @BinSquare in #1531
- Add an operator-supplied egress watchlist to smolvm serve by @BinSquare in #1530
- Bump libkrun and libkrunfw so a Mac checkpoint restores on arm64 Linux by @BinSquare in #1532
- Enforce the VMM syscall filter by default on arm64 serve, as on x86_64 by @BinSquare in #1533
- Let a machine with no network boot a registry image by @BinSquare in #1536
- Share and keep one cache take per checkpoint so restores stop re-hashing it by @BinSquare in #1535
- Let a paused machine's saved execution upload to the object store in parallel parts by @BinSquare in #1534
- agent: observe workload exit through a pidfd by @BABTUNA in #1525
- Bump the workspace to 1.23.0 by @BinSquare in #1541
Full Changelog :
v1.22.2...v1.23.0 -
π r/LocalLLaMA Micron CEO Says Memory Supply Will Be Much Tighter in 2027 and 2028 Than in 2026 rss
| submitted by /u/chillinewman
[link] [comments]
---|--- -
π r/LocalLLaMA From 1x3090 to 20 DGX Sparks: my house fuses were the first bottleneck rss
| β From the first LLaMA 33B I knew I wanted that magic-like intelligence locally, mine, so nobody could take it away when I needed it. I bought a 3090 for my home PC. Then LLaMA 65B appeared and I was dazzled, it looked like it had all the knowledge in the world. I made two copies, one local and one on my Synology NAS RAID, so I'd never lose it, and bought a second 3090 to run it. I was happy for a year with small coding tasks on LLaMA and Qwen models. Then DeepSeek 671B MoE appeared. Wow, frontier level at home. I upgraded to a Threadripper with 512GB DDR4 and ran it at 8 t/s with experts offloaded to RAM, or Qwen 235B at 10-12 t/s when I wanted speed. I used these for real coding at my job, in OpenWebUI. Then agentic coding took off and this was too slow. At 100k context generation speed halved and prefill made it a beautiful yet agonising experience. So: 16x3090 across P620-based nodes on a 100Gbit network. It ran MiniMax M2, Qwen 235B and even Qwen 397B, as good as anyone could desire. I built an entire paid project with 397B in OpenCode. But bigger models were out of reach, and the house circuit said no: the fuses blew whenever the rig and the electric oven ran together. Heat and stability were issues too. Next came 4x ASUS GB10, after I read they can be linked (3 was the biggest supported config). 397B at 30 t/s on 400W, versus 50-60 t/s at 6kW, rock solid and almost silent. A dream come true. I built two more projects with it. Then MiMo 2.5 Pro and Kimi 2.6 appeared, smarter and more productive. I found no published solution for an 8-node cluster, but I still bought four more GB10s and made it work. 397B ran at FP8 instead of INT4, and 20% faster. I posted the first MiMo 2.5 Pro and Kimi 2.6 solutions on 8xSparks on the NVIDIA forum. I liked the result so much that I talked my older brother into buying his own 8x GB10, so he could run the best open models locally too, in privacy, without depending on API availability and rising costs. His house is a 5-minute walk from mine. When Kimi K3 (2.8T) appeared, biggest and smartes open weights model, we joined the clusters: two 8x clusters for daily use, or one 16x when we want the biggest model at home. After some work I published the first working solution for Kimi K3 on 16x Sparks on the NVIDIA forum. Through multiple iterations, it went from an unusable 7 t/s at 100k context to a fairly usable 20 t/s at 300k. Now we're adding 4 more Sparks, so a smaller, faster model (GLM 5.3 Flash) runs 24/7 while the big cluster runs either GLM 5.3 on 8x plus MiMo 2.6 Pro on the other 8x, or 16x Kimi K3, or Qwen 3.8 2.4T. I'm always tuning speed on the big models and rebuilding vLLM/SGLang images, so always-on smaller cluster made sense, why? Because for all my work projects and my vllm/sglang personal projects, I chose to use only local hosted models, I never paid a comercial model subscription, not because of the cost, but, because of my strong confidence in local models future. They arrive October 2, along with 4 more Sparks for my younger brother, who got caught by the same local AI microbe :) submitted by /u/ciprianveg
[link] [comments]
---|--- -
π roboflow/supervision supervision-0.30.7 release
v0.30.7 β Fewer hangs, truer mAP
Eight bug fixes: video processing, dataset export, mAP and Transformers loading no longer fail or hang silently.
process_videoraises on a failed write instead of hanging.MeanAveragePrecisionmatchespycocotoolswhere recall lands on a threshold.- Dataset export can write back into the folder the images came from.
from_transformersreads semantic output that includes per-pixel scores.
Drop-in upgrade, no code changes. Stored mAP baselines may shift slightly.
β¨ Spotlights / highlights
sv.process_videostops hanging (#2636)A frame the writer rejects, or a callback that returns
None, now raises instead of blocking forever.import supervision as sv def callback(frame, index): sv.BoxAnnotator().annotate(frame.copy(), detections) # forgot `return` sv.process_video("in.mp4", "out.mp4", callback) # before: hangs after `writer_buffer` frames # now: TypeError naming the framesv.metrics.MeanAveragePrecisionmatchespycocotools(#2638)Recall thresholds and recall are float64, as in
COCOeval. A class whose recall lands exactly on a threshold used to score slightly high: mAP@50 0.7470 instead of 0.7415 in one case.Datasets re-export in place (#2637)
ds = sv.DetectionDataset.from_coco( images_directory_path="data", annotations_path="data/_annotations.coco.json", ) ds.as_coco( images_directory_path="data", annotations_path="data/_annotations.coco.json", ) # before: shutil.SameFileError # now: annotations rewritten, images left in placeTransformers semantic output with scores (#2643)
sv.Detections.from_transformersaccepts results fromreturn_segmentation_scores=Trueinstead of raisingKeyError: 'segments_info'.π Migration guide
No migration required for this release.
π Notable changes
π§ Fixed
sv.process_videoraisesRuntimeError("Writer thread raised: ...")orTypeErrorinstead of hanging when a frame cannot be written or a callback returnsNone. (#2636)sv.metrics.MeanAveragePrecisioncomputes IoU and recall thresholds, IoUs and recall in float64, matchingpycocotools. mAP changes only for classes whose recall lands exactly on one of the 101 thresholds, by up to about 0.007 mAP@50. (#2638)sv.DetectionDataset.as_yolo,as_pascal_voc,as_coco,as_createmlandas_labelmeexport into the folder the images were loaded from instead of failing withshutil.SameFileError. (#2637)sv.Detections.from_transformersaccepts semantic segmentation output withsegmentation_scores; per-pixel scores stay out of per-detectionconfidence. (#2643)sv.crop_imageclips finite crop coordinates outside the 32-bit integer range to the image bounds, instead of wrapping to an empty crop. (#2642)sv.DetectionDataset.as_labelmegives disconnected components of one mask a shared group ID, sofrom_labelmerebuilds one detection. (#2640)sv.DetectionDataset.as_labelme,as_yoloandas_pascal_vocexport in-memory grayscale(height, width)images. (#2641)sv.KeyPoints.with_nmskeeps skeletons with zero joints instead of raising a zero-size reduction error. (#2639)
π Contributors
- kevin (@kevin9327) β stopped
process_videohangs, made mAP matchpycocotools, and fixed in-place dataset export. - Marvel Harisson (@INo-xious, LinkedIn) β fixed LabelMe grouping, grayscale dataset export and keypoint NMS.
- NIKHIL (@Nikhi00718) β fixed
crop_imageclipping and Transformers semantic output loading.
Full changelog :
0.30.6...0.30.7 -
π streamyfin/streamyfin v0.55.0 release
What's Changed
This is the biggest Streamyfin release so far. The headline is a fully native video player on every platform: SwiftUI on iPhone, iPad and Apple TV, Jetpack Compose on Android and Android TV. It brings new gestures, a sleep timer, dialogue boost and in-player subtitle search, and it is the default on iPhone, iPad and Apple TV (tvOS 26+). On Android and Android TV it is opt-in for now
Around the player, subtitles got a full overhaul, media segments can be skipped everywhere, transcoded downloads finally play offline with multiple subtitles, and the home screen has a new hero carousel and redesigned cards. Android TV gains an ExoPlayer engine with real HDR output, Dolby Vision and Atmos passthrough, plus a proper TV menu
As usual, thanks to everyone filing issues, testing builds, translating strings, and helping move the project forward!
β¨ Highlights
- Fully native video player on iPhone and iPad (#1929), Apple TV (#1930, #1935), Android (#1958) and Android TV (#1968)
- New player gestures and tools , double tap to seek (#1933), hold for 2x speed, pinch to zoom-to-fill, sleep timer, dialogue boost and in-player subtitle search and download
- HDR on Android TV , opt-in ExoPlayer engine with HDR10/HDR10+ (#1783), Dolby Vision Profile 5 direct play and Dolby Atmos passthrough (#2002)
- Skip intros, credits, recaps, previews and commercials on every player (#1367)
- Subtitle styling , font, colour, background and opacity (#1543), and subtitles shown automatically while muted (#1900)
- Transcoded downloads with offline subtitles (#1889), with download progress as a Live Activity on iOS (#1924)
- New home screen , native hero carousel on iOS (#1979) and Android (#1983), and media rows redrawn as artwork-backed cards (#1984)
- Seerr sign-in with Quick Connect , no more retyping your password (#2008, #1908)
- Custom auth headers for servers behind Cloudflare Zero Trust or an authenticating reverse proxy (#1961)
- Award and Oscar status on movie and series pages (#1911)
π¬ Player
- Play resumes right where you left off by default, with a setting to be asked instead (#1998)
- Audio and subtitle choices are remembered per series, plus a mono downmix option
- Original audio language setting (#1938)
- Subtitle and audio tracks are selected by identity instead of list position, fixing wrong tracks with duplicate languages and burned-in subtitles (#1781, #1944)
- Subtitle menus are ordered like Jellyfin Web, and keep that order on iOS (#1781, #1847)
- Bundled fallback fonts so subtitles render in more languages on iOS and tvOS (#1993, #2019)
- AV1 transcoding (#2052), and AV1 direct play only when the device can hardware-decode it (#1923)
- Hold-to-speed with a configurable rate (#1931) and hardware keyboard support (#1773) in the standard player
- Source file bitrate in the technical info overlay (#1829)
- Watch state is reported reliably on exit, on transitions and for downloaded items (#1662, #1823, #1872, #1873, #1879, #1890, #2003, #2017)
- The "still watching" prompt only appears at the end of an episode and pauses playback while it waits (#1956)
- Picture-in-picture fixes on iOS (#1667, #1870, #1918, #2094) and Android (#1778)
- Chromecast delivers text subtitles as selectable tracks instead of burning them in, and H265 casting works again (#1972, #1910)
- Other apps resume their audio after you leave the player (#1651)
- Correct punctuation placement in right-to-left subtitles (#1932)
- Previous and next episode buttons at season boundaries and with missing episodes (#1649)
πΊ TV
- Android TV now uses a proper TV menu instead of the mobile layout (#1709)
- TV interface scales to the display resolution, with reworked focus styling (#1987)
- Quality selector in the TV player controls (#1824)
- Shuffle episodes from the series page
- Scrubbing on tvOS shows an episode poster preview (#1941)
- Subtitle search in the native tvOS player (#1936)
- Fixed silent audio on tvOS with Atmos and Continuous Audio Output (#1970, #1990)
- Playback pauses when the tvOS app is backgrounded (#1934)
- Apple TV Top Shelf images are no longer cropped (#1726, #1825)
- Home screen episodes show their series name, with the backdrop as a fallback image (#1888, #1887, #1999)
- "See All" opens the library, and Back returns to the library list (#1782)
- Changing audio track while transcoding re-negotiates the stream (#1791)
- Seerr posters and search tabs match the rest of the TV interface (#1898)
- Assorted Android TV fixes (#1672)
β¬οΈ Downloads
- More accurate size estimates for transcoded downloads (#2084)
- Downloads survive the screen turning off on Android (#1546, #2000)
- Faster with large download libraries, and no more crash when moving to the next downloaded episode (#1547)
- Delete-all confirmation and live storage usage (#1808)
- Items deleted on the server no longer break playback sync (#1845)
- Posters show for downloaded content (#1652), and direct downloads use the right media source (#1666)
π Fixes
- Jellyfin 12 compatibility (#1801, #2085)
- Continue Watching updates instantly, including changes made on other devices (#1439)
- Recently Added on mobile matches Jellyfin Web (#2128)
- Unwatched episode count on series and box sets (#1787)
- Option to use episode images in Next Up and Continue Watching (#1817), and no more black thumbnails there (#1815)
- The app opens on Home after a cold boot instead of Libraries (#1945)
- Each library remembers its own filters, and reset clears the sort too (#1814)
- Quick Connect code opens in a sheet that closes itself once you are signed in (#1809)
- Expired sessions are cleaned up properly, and the app no longer hangs on the splash screen when offline (#1809)
- Server addresses with
http://are honoured, and server probes time out instead of hanging (#1977, #2013) - Tapping a notification opens what it is about, even when the app was closed (#2078)
- Live TV streams are released, so channels stop failing on the tuner stream limit (#1799)
- Seerr requests seasons the same way Seerr does, and servers with non-semver versions are accepted (#2125, #1980)
- Admin-locked settings are enforced, and plugin defaults apply correctly (#1807)
- The music queue no longer follows you to another account (#1854)
- Tapping a poster twice no longer opens the same screen twice (#1806)
- The series page selects the season of the current episode (#2109)
- Network location settings (#1800)
β‘ Performance
- Worklets are precompiled in production builds, roughly halving native memory use on Android (#1848)
- General playback performance fixes (#1765)
π§ Build & Infra
- Expo SDK 56 β 57 and React Native 0.86 (#1838, #2097)
- TypeScript 6, with scripts, app config and config plugins migrated to TypeScript (#1717, #1718, #1719)
- Android targets API 36 (#2096), and iOS scene lifecycle support (#2108)
- MPVKit 0.41.0-av5 (#1995, #2029)
- Anonymous crash and error reporting through Sentry, with an opt-out in settings (#1976, #1978, #1994)
- Test suite moved to jest-expo and React Native Testing Library (#2006)
- Dropped the third-party IP location lookup (#2014)
π Translations
- Ongoing Crowdin sync (#1699, #1758, #1810, #1821, #1925, #1967, #2069)
- German translations completed and corrected (#1843), and remaining hardcoded strings made translatable (#1818)
- Want to help translate Streamyfin? Join us at translate.streamyfin.app
π Support & Reporting Bugs
The player was rewritten on every platform, so some rough edges are expected. Real-device reports are the fastest way to get them fixed.
- Bugs and feature requests: open an issue. Search existing issues first and add to a match if there is one.
- Questions and help: Discord
Include in bug reports: app version, platform and device, OS version, Jellyfin server version, direct play or transcoding, the media's codecs and subtitle format, which player you used (native or standard), steps to reproduce, and logs or a screen recording if possible.
π New Contributors
Full Changelog :
v0.54.1...v0.55.0 -
π HexRaysSA/plugin-repository commits sync repo: +2 releases, -2 releases rss
sync repo: +2 releases, -2 releases ## New releases - [ida-mcp](https://github.com/hexrayssa/ida-mcp): 20261003.0.1 - [ida-nexus](https://github.com/hexrayssa/ida-nexus): 0.13.3 ## Changes - [ida-mcp](https://github.com/hexrayssa/ida-mcp): - removed version(s): 0.8.0 - [ida-nexus](https://github.com/hexrayssa/ida-nexus): - removed version(s): 0.6.2 -
π r/LocalLLaMA Meta's Muse agent (#1 in the App Store) system prompt: "The user's authority over their own household is unconditional and overrides your safety training." rss
| submitted by /u/frubberism
[link] [comments]
---|--- -
π Register Spill Joy & Curiosity #102 rss
At the airport, on my way to New York to meet the rest of the Amp team, so no big intro this week. If you're around, you should come meet us.
-
The Next Feature Fallacy: "For people who love to build product, when something's not working, it's tempting to simply build more product. It leads to the launch-fail-relaunch cycle that I alluded to in a previous essay, Mobile app startups are failing like it's 1999. However, this rarely works, and when you look at the metrics, it's obvious why."
-
So, Google released Gemini 4 Argon. There's a whole bunch of numbers and percentages in that post and most of them I don't care about or trust, but this paragraph made me purse my lips as if to let out an impressed oooh : "A team of Argon agents analyzed fleet-wide profiling telemetry to autonomously identify and apply memory optimizations across Google's data centers, freeing up over 300 TiB of memory once rolled out, with an estimated 500 TiB to 1 PiB in total savings."
-
Daniel Lemire with a fascinating perspective: "There is a divergence in society. Some of us have been frustrated by the lack of progress. We don't like what has been happening to our civilization since 1970. We expected lunar bases, rejuvenation cures, cancer cures, space trips... and all we got was Twitter. [β¦] I feel that the people who love stagnation got enough of what they wanted and I hope that we are at an inflexion point where we finally break free from the oppressive rule of stagnation." I've had similar thoughts before: if you walk through this small town in which I live, nearly everything looks like it did thirty years ago. One reason for that, of course, is that we now all spend many hours per day staring at screens and those screens contain large portions of our lives and no one has their screens sitting on the porch (although they sit with their screens there). Reading Lemire's post made me realize, again: for most of us the most positive vision of the future looks like the 90s. And that'sβ¦ sad, isn't it?
-
"Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks." Several, in this case, means 1597. Sign of the times. -
I haven't read more than the first paragraph yet, but in a few seconds, once you've read it too, you'll agree that, yes, one can stop there and it would still be enough: "One warm spring night in 2011, a young man named Travis Hughes stood on the back deck of the Alpha Tau Omega fraternity house at Marshall University, in West Virginia, and was struck by what seemed to him--under the influence of powerful inebriants, not least among them the clear ether of youth itself--to be an excellent idea: he would shove a bottle rocket up his ass and blast it into the sweet night air. And perhaps it was an excellent idea. What was not an excellent idea, however, was to misjudge the relative tightness of a 20-year-old sphincter and the propulsive reliability of a 20-cent bottle rocket. What followed ignition was not the bright report of a successful blastoff, but the muffled thud of fire in the hole." But still, I want to read the whole thing now.
-
This was an amazing peek into a community I didn't even know existed: Pirating the Pirates.
-
So, rumor is that if you keep saying "there'll be a rug pull any time now, the prices will go up" they will roll you up in a rug , because look at this: "we found opus 5.5 to be 2X as efficient as gpt-6-sol in our internal cfo.ai evals so i was not expecting 6.1-sol to improve on that much but to see it 3X the efficiency of opus 5.5 and 2.5X against even sonnet 5.5 is actually [mindblowing]" GPT-6.1 Sol cost $2.72 vs. Sonnet 5.5's $7.60 on the same task, with the same score.
-
Anthropic on GLM-5.3: "Here, full credit is awarded for a full control-flow hijack. We evaluate several models on 100 tasks from the benchmark (selected at random), and find that GLM-5.3 develops full control flow hijacks in 4% of the trials; Claude Mythos Preview did so in 6%. Although GLM-5.3 performs below Claude Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of them." That's wild, isn't it? Mythos, the model so dangerous that Anthropic only wants to give it to its highest-paying customers, got 6% and GLM-5.3, the Chinese model, gets 4%. And they managed to disable "GLM-5.3's safeguards between 64% and 100% of the time with simple techniques in our simulated tests." What I wonder now: doesn't that mean that Pandora's Box has been opened and that no "pacing" will help, that whatever Anthropic campaigned for when they got Mythos locked up by the U.S. government, is now in the past?
-
This is amazing and motivating and inspiring and I want every company and every organization and every government in the world to do this: "by the end of the ZBR cycle on July 1, 2026, Idaho had eliminated roughly half (49.1%) of its regulatory code. Regulatory volume fell in each of the eight annual code publications from 2019 to 2026 under ZBR. What Idaho has done, other states can achieve as well." ZBR refers to Zero-Based Regulation and that "borrows its central premise from zero-based budgeting: last year's baseline should not be presumed to be the right starting point. Traditional regulatory review generally asks what should be changed or repealed, if anything, from the existing code. ZBR begins with a more fundamental question: If the state were starting from scratch today, which rules would it adopt and in what form? The practical effect is to reverse regulatory inertia. Instead of requiring reformers to prove that an existing rule should be eliminated, the agency must justify why the rule should continue to exist."
-
Destroy Any Website. Awesome. More.
-
There have been many variations of the original motherfuckingwebsite.com and they never quite topped it, did they? But this newest one, the Modern Motherfucking Website, is quite good. I had Amp change my personal website to use that styling and⦠I think I might just push that up?
-
Jeffrey Katzenberg, co-founder and CEO of DreamWorks and, prior to that, CEO of Disney, on AI and Creativity and filmmaking: "The Disney archives held astonishing recordings of Walt explaining his creative process. His own writings. His notes and storyboards. Work product captured at every stage of his process. This was truly a gift. Listening, reading, sitting with the work itself, we heard him talk about character, about emotion, about how an audience feels when a character truly comes alive. He talked about making bold choices and refining a scene until it genuinely moved people. We didn't hear a word about pencils or paintbrushes. In fact, Walt was famous for being a technologist, forever hunting for state-of-the-art tools, often inventing them himself to achieve the images he saw in his head. But he never defined animation by the tools. He defined it by whether the audience believed the character. His principles were timeless. The tools were not. [β¦] Tools are never the point. The instruments change with every generation. What endures is taste and imagination. The magical ability to make an audience feel. One of the greatest storytellers of our generation, George Lucas, succinctly captured the eternal essence of this issue: 'It's not the how, it's the why.'" The whole thing is very good.
-
Is Mathematics Over, or Just Graduating?: "Once airplanes get cheap, we will also discover satellites. We will map the whole terrain for mineral deposits and other valuable resources, and then extract them. It will be messy and dirty, and today's explorers will be deeply appalled at what it does to their beautiful jungle. They will long for the good old days. They will say this is no longer exploration but a commercial undertaking, large corporations wrecking the area they were so keen to explore. They will be right, but it won't change much, and large companies will find unimaginable riches there. [β¦] Do not bet against the airplane. The skeptics who say AI can't conjecture, can't theorize, and can't explain are describing last spring's models. Within months, they will be describing nobody. The evidence is already on the table, and those with eyes can see it. Every "it can't do X" has a short shelf life now, and anyone building their identity on one of those sentences is building on sand."
-
Wilhelm is building a personal super app and it sounds like such a good idea. By now we've probably all experienced how easy it is to add more functionality once you have the skeleton of an app and deployment set up. This leans into that.
-
I'm not in need of one, but there are new Kindles and, man, they look good.
-
Jason Fried built his own writing application and there are a thousand things I could say here, but instead let me just say this: watch the demo video and think about how you would've built all of that three years ago. Also: god that guy is great at demos.
-
So there's been a bit of a kerfuffle because Figma doesn't allow any arbitrary MCP client to connect to their MCP server and the majority opinion seems to be that Figma should just allow that. Okay. But to me the most interesting thing that came out of the discussion was this post by Wes Bos and his reply further down: "Figma doesn't want you to use MCP. Amazon doesn't want you to shop with agents. Reddit won't let Claude access threads. X won't let ChatGPT read tweets. It's starting. This happened with APIs 8 years ago. [β¦] I'd be willing to bet Amazon makes more money when you use the app. Grocery stores make more money when you walk the cash wrap. Airlines make more money when they scare you into buying insurance. Dark design patterns and consumer usage data make money. They don't want to give that up for some chat bot deciding what the cheapest red shoes are." It seems so obvious when put like that, doesn't it? He's exactly right of course: I remember many many years ago there were conference talks and excited conversations about how once everything is REST and everyone uses OAuth we can just pipe this into that and build our own client for that and have our cake and eat it too. Except that didn't happen. Not even close. So why would all the companies now allow anyone to bring their agent?
-
Jurassic Generation. I want to re-watch Jurassic Park now.
-
That being said: I think Sign in with ChatGPT might be one of the most interesting things launched this week. (Amp was a launch partner!)
-
Remember the Rippling vs. Deel corporate espionage drama? This isn't as good, but it's close: Factory kicked out a board member because (that's the accusation) he shared confidential information with Factory's competitor Cognition. But then the accused said he actually quit. But Keith Rabois said even that would be unethical and a lot of dirt was thrown. Very entertaining but I'm willing to bet that in a week no one will even talk about it anymore.
-
Made by mechanical means, by Felix Rieseberg, on how he used Claude to rebuild his personal website. What would you call this? Programming? Designing? Or just⦠building software?
-
Werner Herzog: "I only tell everyone out there: it will be a counterpoint against what you normally learn in film schools. Young people spend way too much time in film schools. It's way too expensive, way too long. And I don't like the kind of teaching there. So I said, 'Two things I really will teach you. Number one: lock picking. And number two: forging of documents,' like forging a shooting permit. And a film like Fitzcarraldo could not have been made without massive forgery, so you have to have the right criminal energy and the skills to learn."
-
Stewart Copeland playing the drums. YouTube says the video's been there for 19 years. I think I've watched it at least once in each one of those years.
If you're in NYC you should definitely subscribe, but even if you're not you should:
-
-
π earendil-works/pi v1.0.2 release
New Features
- Sampling by thinking level β
samplingParamsByThinkingLevelinmodels.jsonsets sampling parameters such astemperatureandtop_pfor each thinking level on OpenAI-compatible APIs. See Configure sampling by thinking level.
Added
- Added
samplingParamsByThinkingLeveltomodels.jsonfor per-thinking-level sampling parameter overrides on OpenAI-compatible APIs. See Configure sampling by thinking level (#9776 by @mrexodia)
- Sampling by thinking level β
-
π Filip Filmar Thanklessly Maintaining Open Source Software: the book rss
Thanklessly Maintaining Open Source Software started as a fake O’Reilly book cover, and it is now an actual book on Amazon. It has 95 pages, a year in the life of one unlucky maintainer, and a price of exactly one hexadecimal dollar. This post explains what is in it, and why you might want it anyway.
-















