🏡


  1. September 11, 2026
    1. 🔗 WerWolv/ImHex Nightly Builds release

      Nightly

      2ff18a5 Changelog

      • feat: Add an encoding pipeline for the hex editor and pattern language (#2889)
  2. September 10, 2026
    1. 🔗 r/LocalLLaMA I find it funny that a flash model is now 512GB rss

      A few years ago a 100GB was considered a very large language model. What do we call under 100GB models now? Tiny models? haha

      submitted by /u/Terminator857
      [link] [comments]

    2. 🔗 Kagi release notes Sept 10th, 2026 - One login for all of Kagi, and Translate reopens to everyone rss

      One login for every Kagi product

      Kagi now has a single account for all of our products, managed at https://account.kagi.com. This update also adds passkey support , one of our longest-standing requests. #15 @Kai

      What changes for you

      For most people: only the sign-in page. The next time you sign in you'll be taken to account.kagi.com, and your existing email, password, and 2FA continue to work unchanged. Password and 2FA settings are managed there from now on.

      A few cases work differently:

      • Social login (Google, Apple, GitHub, Microsoft): your account will be migrated when we switch over the login page in the coming days. Nothing to do until then.
      • Kids accounts are not migrating and continue to sign in with the passcode received by the account owner.
      • Kagi Mail early testers whose Mail account uses the same email as their Search account: the two are now one account. Sign in with your Kagi Mail password and it works for Search as well.

      Action required if you use 2FA: backup codes were not transferred. Generate new ones at https://account.kagi.com/account/security/recovery after signing in. We'll also email you a reminder in the coming days.

      Suggestions or bugs with the new platform belong on https://kagifeedback.org. If something looks wrong with your account, write to support@kagi.com.

      Kagi Translate

      Kagi Translate is now freemium: every Kagi account gets a monthly allowance, and heavy users can subscribe to a new $8/month Individual plan.

      Existing Starter, Professional, Family, and Team subscribers keep their current access until October 12, 2026. After that date they move to the free tier unless they upgrade to Individual or Kagi Ultimate.

      Read more about the changes →

      Also new in the Translate browser extension:

      • Read aloud (alpha) for selected text, full pages, and "read from here," with a mini player #8787 @liontooth
      • Auto-proofread (alpha) checks text fields as you type #10585 @ttrafford
      • Customizable integration icons: presets, per-integration overrides, and custom CSS #10364 @component5981
      • Orion's built-in page translation now works for everyone, including free and signed-out users #11082 @CielRuby

      Kagi Assistant mobile apps

      When sharing an image or file into the app, you can now start a new thread or share into one of your existing threads.

      Thread retention options, thread sorting, and message reporting are now available in the mobile apps.

      Kagi Maps

      Measure tool is back on mobile

      The measuring tool is available again in the compact mobile controls, with visible drawing lines and measurements. Tapping the map while measuring adds points without opening place details, with the ability to toggle between distance-or-area measurements, (units set in Setting Sidebar)

      Directions and navigation refinements

      Several quality-of-life updates as part of active ongoing improvements to directions and navigation - clearer animations, text, button layout, etc.

      Other improvements and bug fixes

      Kagi Search

      • Added bangs for common built-in lenses: !forums, !fediverse, !programming, !small_web, !academic, and !usenet_archive
      • Search with quotes gives no results #11318 @n4te
      • Show video results without personalization #11317 @mb
      • Having a "Summarize" button is genuinely disappointing #11173 @ctoliver94
      • Feeling Lucky bang does not apply to searches in lenses #9335 @__
      • Search Suggestions: add dedicated "fill suggestion" button for each suggestion item #8159 @artemp84
      • Shield menu doesn't change or disappear when going between images using arrow keys #8940 @Thibaultmol
      • News UI breaks when selecting between time ranges without results #11097 @emptyjar
      • Roman numeral conversion is broken #11415 @tiago
      • Fangraphs fg hashbang has changed #11373 @mergesort
      • Quick Answer still there after disabling "AI" features #11383 @SkyDotBit
      • English queries fail to trigger widgets in non-English UIs #10967 @Hanbyeol

      Kagi Assistant

      Web

      Mobile apps

      • Assistant for Android doesn't search custom assistants #11331 @mb
      • Add find feature to the Android Assistant app #11159 @kslays
      • Voice dictation on Android only outputs the last sentence #11400 @pickx
      • Math equations not working in new Assistant app #11128 @Temanor

      Kagi Translate

      • Read aloud no longer ends short phrases with a stray scream-like noise #11343 @rane
      • Furigana now sits over the whole word instead of just the first kanji #9826 @Astolfo
      • Failed document jobs no longer count against your storage, and documents over the length limit are rejected at upload with a clear message #11359 @ThorwaldWestmaas
      • Right-click translate, define, and proofread now work inside iframes and embedded content #10813 @WorstWizard
      • "Translate with Kagi" is back in YouTube's Subtitles/CC menu #11315 @HealthyAverage
      • Page translation shows an error when it fails instead of a false "translated" checkmark #10602 @Polaris
      • Reddit no longer slows down with the extension enabled #10507 @jarrodldavis
      • Desktops with touchscreens are no longer treated as mobile #10693 @Roon
      • Page translation buttons render correctly in every language #11019 @Hanbyeol
      • Language options show the right names and update once the list loads #9840 @dreifach
      • Overlay popups follow the dark theme, close with the overlay, and stay responsive #11198 @Temanor
    3. 🔗 Jessitron When individualism worked rss

      I'm reading more of Hartmut Rosa's narrative of Social Acceleration. Paraphrasing:

      It made sense to have a stable, personal identity when the pace of social change meshed with the change of generations; this is a marker of classical modernity (like, 1800-1970). Before that, and in traditional societies with slower rates of social change, people find themselves defined by pre-existing, enduring structures-an intergenerational identity. After that, in a super- fast-changing society like late modernity (now) pushes us toward a flexible identity, away from continuity. These days,

      [People] must either conceive themselves from the very beginning as open, flexible, and eager to change

      This describes me, and I considered it a virtue. Now I consider it advantageous. A small identity and willingness to shift occupations as the occasion offers, and take pride in new things every few years-useful.

      Rosa goes on to describe the alternative:

      suffering permanent frustration when their projected identities are threatened with failure by a quickly changing environment.

      That describes a lot of America right now!

      Our individualist culture made sense in that ~150 years when we got to have a stable identity that wasn't tied to our ancestry. But modernity is built upon acceleration (of tech; pace of life; and social change), so it didn't stay there. Now the way the world works changes faster than we can grow up, so we have to grow up over and over.

      Right now we're growing into people who use AI for everything. It's jarring! Exciting, and also difficult. Most of us did not ask for this. Most of us would like to be who we are for a few more decades.

      There was a moment when individualism was compatible with human identity formation, a golden age when our lifetime and the pace of social change coincided.

      What to do about it?

      Now I want an identity that stretches longer than a decade. I don't think I can build one for my lifetime, plus that doesn't make sense. Maybe I can weave into other people in the past, future, and now to find a narrative that extends beyond me. If I'm gonna make the world better, it's can be both very local (the people around me) or slower than my lifetime. The day of a great Hero who Changes the World and lives to see it… that moment is gone.

    4. 🔗 The Pragmatic Engineer The Pulse: tech companies move to open AI models rss

      Hi, this is Gergely with a bonus, free issue of the Pragmatic Engineer Newsletter. In every issue, I cover Big Tech and startups through the lens of senior engineers and engineering leaders. Today, we cover one out of five topics from last week 's The Pulse issue. Full subscribers received the article below seven days ago. If you 've been forwarded this email, you can subscribe here .

      In May, I covered an emerging trend of companies wanting to cut back their AI spending, starting with engineering departments. Different approaches were being tried:

      • Experimentation with running cheaper, open models on inference providers
      • More investment in model routing to route simpler requests to cheaper models
      • Knowledge-sharing sessions on how to use AI models cost-effectively
      • Setting per-developer monthly AI usage limits

      A few months later, it seems that several companies have managed to achieve this, according to sources I've spoken with.

      Uber: AI costs down 50%

      Uber managed to blow through its annual AI budget in the first three months of this year, and it wasn't a surprise to hear, in May, Uber's COO say that it was getting harder to justify spending on tools like Claude Code without seeing benefits from the leading models. It wasn't long until engineering teams at the ridesharing giant set to work on how to optimize AI spend, and their efforts weren't in vain.

      Uber cut the cost per AI request by 34%, and the cost per AI session by 52%:

      altReducing per-token and per-session spend. Source:Uber

      Of course, Uber keeps using more AI tokens and starting more AI sessions, but thanks to optimizations the cost has been flat since March, despite significantly more usage:

      altUsage up, cost stable Source:Uber

      How did they pull it off at Uber? It was via a combination of different approaches:

      • Open weight models, run using inference: run open weight models on inference services, which are significantly cheaper than frontier ones.
      • Optimized model selection : benchmark all available frontier and open models, to build an accurate picture of their present capabilities
      • Ongoing benchmarking : run benchmarks every week based on real work, and update them
      • Cheaper subagent models : subagents do smaller tasks not requiring the most expensive models
      • Reduce model effort: Uber found that defaulting to Medium effort gives the best cost-to-output ratio with advanced models
      • Optimize requests : trigger automatic compaction above 400K tokens, even for models with 1M context windows
      • Cache prompts : cache prompts to save money when using Uber's own harness, Minions
      • … and more: Uber wrote an engineering blog post detailing the dozens of optimizations taken to reduce token cost without noticeable change in the quality of code generated by agents

      From the outside, the single biggest win seems to be Uber's transition to using open models for certain tasks. Open models cost 2-20x less, compared to frontier ones:

      altThe most expensive open weight model costs $0.30 per code review, vs $0.50 for the cheapest frontier model (and $2.50 for the most expensive one). Source:Uber

      Pinterest makes 90%+ cost savings by dropping frontier models

      Interesting details from Pinterest's earnings call last month reveal how much the social media platform saves by running open models. Here's what CEO William Ready said (emphasis mine):

      "Our approach to model deployment includes our own compact fit-for-purpose models built for Pinterest-specific use cases and suitable open source models post-trained in our own environment within our secure cloud infrastructure. When we leverage open source models, such as with Pinterest Assistant, we are seeing superior performance for our use cases when compared to closed third-party models because we are able to post-train open models on our highly unique data.

      With open models, we are achieving cost per transaction at less than 8% of the cost of comparable closed proprietary models. This gives us substantial headroom to deepen and extend these capabilities over time in a way that is differentiated, highly effective, and cost efficient."

      Basically, what used to cost Pinterest $100 to run on a closed, frontier model, they now spend $8 on by using open models on owned or rented inference!

      AT &T: 56% savings by swapping Claude for open models

      With 100,000 employees, AT&T is a big spender on AI. The telco giant cut its AI bill by 56% while measuring a 2% decrease in the quality of AI's output, after they moved workloads over to open models. From The Information:

      "Austin said he's found that open source models are "just as good or better" than older models sold by the likes of Anthropic and OpenAI. For instance, AT&T's software developers still rely on cutting-edge models for complex tasks like generating code, but can use cheaper open source models for less intense tasks like generating summaries of previously submitted code, he said.

      After the company began using router provider LiteLLM, the costs of some advanced AI tasks such as coding fell by as much as 56% while the quality of the AI's performance fell just 2%, Austin said."

      Anthropic overpriced compared to the rest of the market?

      Only a few months ago, Anthropic was the preferred model (Claude) and harness (Claude Code) among engineers. But Anthropic's models are becoming steeply more expensive at a time when open weight models - and also OpenAI - are getting much cheaper. Meanwhile, Opus 5 is 100x more expensive (!!) than models like GPT-5.6 Luna xhigh and DeepSeek. That may be simply too much to ignore for some tech companies:

      altTypical cost for an AI agent run, per model. Source:Model Zen Garden

      Seeing this data, I'm not surprised that more tech companies are looking to run open weight providers on inference providers, due to the significant savings available from a model that's similarly capable as one from Anthropic.

      What worked for Stripe, Coinbase, Uber & Ramp

      The engineering team at Databricks interviewed engineers at Stripe, Coinbase, Uber, and Ramp, and collected how different approaches helped save costs for them. The summary:

      altSource:Databricks

      To answer the question posed in the header of this report, it's apparent that using open models is indeed the approach offering the biggest savings, followed by smart model routing. Spending controls and context optimization also bear down on costs, but they don't come close to the first two techniques in results.

      A week after publishing this article, Ara Krahzian at Ramp has confirmed that AI spend in August, has, indeed, declined at the top 1% of businesses by 10%, based on Ramp data:

      alt AI spend starting to decline at the top 1% of firms. Source: Ramp

      I 'd wager those companies are not spending fewer tokens, but they are optimizing cost, in ways outlined above.


      Read the full issue of last week 's The Pulse, or check out this week 's The Pulse. This week's issue covers:

      1. New trend of CPU shortages: after a GPU shortage and memory shortage driven by AI companies, we're now experienceding a CPU shortage, thanks to AI agents using a lot more CPU with tool usage. If you will need more compute in the future: secure it now, while you can (even if it's expensive to do so).
      2. Growth dream ends for more COVID-era unicorns: Miro sold itself to Bending Spoons for $1.35B, after it was valued at $17B in 2022. Airtable saw a similar valuation cut last month, and it seems a batch of now-overvalued, VC-funded companies are desperate to sell.
      3. Industry Pulse: Overtime at Google to get Borg working on SpaceX's data centers; SpaceX cuts Claude Code tokens by 90%; OpenAI launches Astra; Meta unveils Muse (and Mark Zuckerberg pushed production code in this release); - to which Mark Zuckerberg made personal contributions; OpenAI's agents go rogue, again.
      4. Do engineers lose touch when AI handles incidents? In the aviation industry, pilots are exposed to emergency situations every six months, to keep their critical problem solving skills sharp. In the tech industry, we might need something similar, especially if AI would take on handling of the simpler incidents.
    5. 🔗 Jeremy Fielding (YouTube) Mecanum Wheels Are So Weird They Are Genius rss

      If you want to join my community of makers and Tinkers consider getting a YouTube membership 👉 https://www.youtube.com/@JeremyFieldingSr/join

      If you want to chip in a few bucks to support these projects and teaching videos, please visit my Patreon page or Buy Me a Coffee. 👉 https://www.patreon.com/jeremyfieldingsr 👉 https://www.buymeacoffee.com/jeremyfielding

      Social media, websites, and other channel

      Discord 👉https://discord.gg/F3XuyhNRPc Instagram https://www.instagram.com/jeremy_fielding/?hl=en Twitter 👉https://twitter.com/jeremy_fielding TikTok 👉https://www.tiktok.com/@jeremy_fielding0 LinkedIn 👉https://www.linkedin.com/in/jeremy-fielding-749b55250/ My websites 👉 https://www.jeremyfielding.com 👉https://www.fatherhoodengineered.com My other channel Fatherhood engineered channel 👉 https://www.youtube.com/channel/UC_jX1r7deAcCJ_fTtM9x8ZA

      Notes:

      Technical corrections

      Nothing yet

    6. 🔗 r/LocalLLaMA ANOTHER researcher accuses OpenAI of training on conversations and then claiming a breakthrough rss

      ANOTHER researcher accuses OpenAI of training on conversations and then claiming a breakthrough | submitted by /u/SirReal14
      [link] [comments]
      ---|---

    7. 🔗 modem-dev/hunk v0.22.0 release

      What's Changed

      New Contributors

      Full Changelog : v0.21.0...v0.22.0

    8. 🔗 Kagi Kagi Translate is back rss

      Kagi Translate is moving to a freemium model and launching a new standalone Individual subscription for $8/month. Anyone with a Kagi account can continue using Translate for free with a limited monthly allowance. For people...

    9. 🔗 MetaBrainz Picard 3 Release Candidate 2 rss

      Today the Picard team is making available a second release candidate for Picard 3. We received good feedback on the previous release candidate 1, thanks to everyone for testing and providing feedback. The final 3.0 release is planned to happen in a few weeks.

      Download links and a detailed list of changes since Picard 3 release candidate 1 are available below. For a more detailed overview of what is new in Picard 3 please see the previous blog post Picard 3 Alpha Release.

      While we have all the major features implemented and with the latest bug fixes we are confident in the current code, this is still a pre-release and there might be bugs. If you use this, do so with care, backup your files and please report any issues you encounter.

      If you are updating from Picard 2, note that some of the changes are backward incompatible, hence we recommend you make a backup of your Picard.ini config file before trying this version. You can do so in Picard’s Options under Advanced > Maintenance.

      What’s new?

      Bugfixes

      • PICARD-3412 - Picard logs the user out after ~1 hour, requiring re-authentication on nearly every startup
      • PICARD-3413 - Crash in User Interface > Toolbar Actions on Add Action
      • PICARD-3415 - The item views for unclustered and clustered files do not use the system folder icon
      • PICARD-3416 - Generated Appstream appdata file has empty release list
      • PICARD-3417 - Item views and the metadata box do not refresh correctly when interface colors are changed and applied
      • PICARD-3420 - Set proper pygit2 timeouts, reduce the risk of hang
      • PICARD-3421 - Wrong desktop file name passed to QApplication.setDesktopFileName() breaks XDG/Wayland app-id association
      • PICARD-3423 - Snap package does not register the MPRIS2 audio player DBus interface
      • PICARD-3424 - Infinite re-authentication loop when a server rejects a valid OAuth token
      • PICARD-3425 - Submission server is not used for ISRC and rating submission
      • PICARD-3426 - "Submit data to the configured server" checkbox checkmark not visible in dark mode
      • PICARD-3427 - Crash when clicking on a track rating

      Improvements

      • PICARD-3137 - Do not ask for authentication when switching to a server not supporting authentication
      • PICARD-3407 - Add is_from_mb flag to plugin register_script_variable() function
      • PICARD-3408 - Using --debug-opt flag alone doesn't enable debug log level
      • PICARD-3409 - Reduce memory usage
      • PICARD-3410 - Show a busy cursor to acknowledge async lookup and cluster actions
      • PICARD-3414 - Unify boolean environment variable parsing and add PICARD_FORCE_FUSION
      • PICARD-3419 - Add option to standardize artist name only in "artists" and "albumartists" tags
      • PICARD-3422 - Make the "Make It So!" accept button reusable and configurable, and extend it to the Script Editor

      Tasks

      • PICARD-3048 - Document manual editing of tags with metadata view and tag editor
      • PICARD-3215 - Update documentation for restructured CD lookup menu

      Download

      We appreciate your interest in trying this new version. Use with care, backup your files and please use theMetaBrainz community forums and the ticket system to give feedback and report bugs.

      For Windows and macOS you can download the release candidate version from the Picard download page. Linux users can run from source or try the "candidate" channel of the Picard snap package.

      Picard is free software and the source code is available on GitHub.

      Helping out

      We want to provide a polished release of Picard 3.0 that everyone can feel confident to upgrade to. To achieve this, we need the help from the MusicBrainz community.

      The easiest way to help us getting a great Picard 3.0 release is using and testing this release candidate. Please report bugs on the Picard issue tracker and provide feedback in the community forums.

      We also need help with translations, as there are a lot of new features and UI changes over previous Picard versions. We will avoid any further text changes before the final release, so now is the right time to help with translation on Weblate. Please see the translation instructions on the Wiki for details.

      If you are a software developer you are very welcomed to provide fixes and features. Picard is free software and the source code is available on GitHub. See Contributing to Picard on the Picard website to get started.

      You can also look at the new Plugin API and develop plugins for Picard or update your existing Picard 2 plugin to work with Picard 3.

      Acknowledgements

      Code contributions by Bob Swift, Greg Myers, krotka, Laurent Monin and Philipp Wolfer.
      Translations were updated by Marc Riera (Catalan), mfmeulenbelt (Dutch), ninjum (Galician) and st.esser (German).

    10. 🔗 r/LocalLLaMA DeepSeek-V4.1-Flash surprised .... rss

      DeepSeek-V4.1-Flash surprised .... | Hoping to see smartest medium size models soon & later with all available optimizations/architectures/etc.,. Thanks Deepseek! Ex 1: 30-50B MOE + 10-15B Engram + DeepSeek-V4.1-Flash type KVCache
      Ex 2: 15-30B Dense + 10-15B Engram + DeepSeek-V4.1-Flash type KVCache EDIT : Updated Engram to 10-15B from 50B submitted by /u/pmttyji
      [link] [comments]
      ---|---

    11. 🔗 r/LocalLLaMA DeepSeek V4-1 Flash is out rss

      DeepSeek V4-1 Flash is out | Here we go again, DeepSeek is back again with a new model V4-1 Flash A multimodal Mixture-of-Experts (MoE) model with 552B backbone parameters and support for contexts of up to one million tokens Market crash as a service submitted by /u/tiguidoio
      [link] [comments]
      ---|---

    12. 🔗 r/LocalLLaMA deepseek-ai/DeepSeek-V4.1-Flash · Hugging Face rss

      deepseek-ai/DeepSeek-V4.1-Flash · Hugging Face | submitted by /u/t4a8945
      [link] [comments]
      ---|---

    13. 🔗 backnotprop/plannotator v0.27.13 release

      Follow @plannotator on X for updates

      Missed recent releases? Release | Highlights
      ---|---
      v0.27.12 | Unified decision control, token hover cards, local-vs-remote diff, approval notes
      v0.27.11 | OpenCode server leak fix, durable local feedback archive, unknown-subcommand fix
      v0.27.10 | Auto-viewed files on scroll, annotation undo/redo, OpenCode 2 slash commands restored, npm 12 agent terminal fix
      v0.27.9 | WebMCP browser-agent tools, HTML refresh from disk, host seams, lazy renderers, Windows uninstall fix
      v0.27.8 | Pi keeps its prompt cache across plan transitions, thumbs-up returns to HTML annotation, embed picker seam
      v0.27.7 | Pi host crash fix on Windows, Call Flow tree cap, jj fork-point base, plannotator knowledge skill + llms.txt
      v0.27.6 | Live app annotation lands on Pi, one interaction model for HTML pages
      v0.27.5 | Annotate your running app, Agent TUI placement, collapsed lockfiles, VS Code theme fix
      v0.27.4 | Portable Guided Review exports, guides.show share links, guide CLI, jj Call Flow
      v0.27.3 | Folder watcher freeze fix on large repos, first SBOM-attested release pipeline
      v0.27.2 | Mobile plan and code review, Codex CLI 0.147 fix, configurable markdown extensions
      v0.27.1 | Open-in-editor launch fix, file headers respect Viewed/Git-add visibility toggles

      What's New in v0.27.13

      Six pull requests, four of them from community contributors, two from first- time contributors. The headline answers a request straight from X: open a code review against the base you actually mean, not always the trunk. Alongside it: a security hardening of the document endpoint, the end of our longest-standing CI flake, and a Amp delivery fix.

      Open a review on a specific base

      plannotator review always opened against the detected trunk, even when you were reviewing one layer of a stacked branch. A user on X put it plainly: "it always opens vs. main even if it explicitly understands that I'm reviewing a stack."

      Now the review can open exactly where you point it:

      # stack: main → feature/part-1 → feature/part-2 (you are here)
      plannotator review --base feature/part-1
      # opens on "All changes since feature/part-1": just what this layer adds
      
      plannotator review --base feature/part-1 --diff-type merge-base
      # the committed-only view of the same layer
      

      --base takes anything git resolves: a branch, origin/branch, a tag, a commit, HEAD~3. --diff-type picks the opening view from the same nine modes the dropdown offers. Both are a starting state, nothing more: the session opens there, everything stays changeable in the UI, and neither flag ever touches your saved defaults. A base that does not exist fails at launch with a clear message and a "did you mean" suggestion instead of silently producing a wrong diff.

      This matters most when an agent opens the review for you. The agent knows which layer it just built, so it can hand you a review already looking at the right thing instead of telling you which dropdown to click. The installed skills teach exactly that: reviewing a stack layer, pass --base <the branch below yours>.

      The flags work across every host that launches reviews through the CLI, and error honestly on surfaces where a base has no meaning (jj, GitButler, Perforce, multi-repo workspaces, and PR URLs, whose base comes from the platform). #1484

      One behavior change shipped with this. The review command used to silently ignore flags it did not recognize; a typo like --bse main opened a review as if you had typed nothing, and in the worst case an unknown flag could swallow the PR URL next to it. Unknown dash-prefixed flags now fail loudly with a usage hint, matching how annotate has always behaved. Plain words stay tolerated, so slash-command hosts that forward your raw sentence keep working. OpenCode and Pi slash commands also now reject CLI-only transport flags such as --tailscale that they previously accepted and ignored. #1483

      Symlinks can no longer read outside the project

      A symlink committed into a repository you are reviewing could point anywhere on your disk, and the endpoint that serves linked documents would follow it: the requested path looked like it was inside the project, but the content came from outside it. Document reads are now gated on real-path containment in both server runtimes: a path must land inside the project both as written and after resolving symlinks, or the request is refused.

      Legitimate symlink setups keep working, including symlinked project roots (macOS temp directories) and links that resolve within the project. Three edge behaviors changed on purpose: a symlink escaping the project returns 403 on every path through the endpoint, HTML files over the 2MB annotate cap now return 413 where one path previously served them in full, and a file that exists but cannot be opened returns 500 instead of 404.

      Contributed by @bendrucker in a first contribution that went well beyond its own scope: along the way he reproduced our longest-standing CI flake, disproved our working theory with actual experiments, and traced it to the real root cause below. #1437

      The CI flake is dead, and tests stay out of your data

      Four annotate-server tests had been failing intermittently on CI for weeks (#1464), passing on rerun, resisting diagnosis. The root cause turned out to be a single line: shared storage captured the data directory once at module import, so a test that imported it under a temporary override poisoned every later test in the process, and test-file discovery order decided who got hit. The same freeze meant a full test run could write into a contributor's real ~/.plannotator.

      Storage now resolves its directory per call, and the test suite sandboxes PLANNOTATOR_DATA_DIR for every run, with regression tests locking both halves down. Two contributors converged on the same root cause independently within a day, from different starting points: @FNDEVVE working from our test-isolation issue, and @bendrucker debugging his own PR's CI failures. Closes #1455 and #1464. #1473

      Amp: feedback is routed by decision, never guessed from prose

      The Amp plugin classified review outcomes by searching the rendered feedback text for phrases, so a genuine comment like "this path has no feedback loop, add one" pattern-matched as no-action and was silently dropped. The CLI now offers plannotator review --json, emitting one structured { decision, message } record from the same builder as the plaintext output, and Amp routes purely on the decision field. The prose classifier is gone. An outdated CLI produces a recoverable update notice with the captured output, never a guessed decision.

      Contributed by @FNDEVVE, closing #1456. #1476

      Additional Changes

      • Selection toolbar stays on screen on phones : selecting short text near a screen edge in compact touch layouts overflowed the floating toolbar past the viewport, clipping its buttons. It now clamps inside the screen (respecting notch safe areas) and keeps its centered position whenever that fits. Desktop placement is untouched. Contributed by @katya4oyu in their first contribution. #1471
      • The view dropdown follows the live base : the "All changes since " option label was baked at session start from the detected trunk and never updated, so it could contradict the base picker sitting next to it. It now renders from the active base.

      Install / Update

      macOS / Linux:

      curl -fsSL https://plannotator.ai/install.sh | bash
      

      Windows:

      irm https://plannotator.ai/install.ps1 | iex
      

      Claude Code Plugin: Run /plugin in Claude Code, find plannotator , and click "Update now".

      Pi: Update @plannotator/pi-extension to 0.27.13 and restart Pi.

      OpenCode: Clear cache and restart:

      rm -rf ~/.bun/install/cache/@plannotator
      

      What's Changed

      • feat(review): open a review on a specific base and diff type in #1484
      • fix(review): strict argument parsing for unknown review flags in #1483
      • fix(doc): deny symlink escapes on /api/doc reads by @bendrucker in #1437
      • fix(test): isolate test-run data from contributor history by @FNDEVVE in #1473
      • fix(amp): relay structured decisions without prose classification by @FNDEVVE in #1476
      • fix(ui): keep selection toolbar within compact touch viewport by @katya4oyu in #1471

      New Contributors

      Community

      This release is mostly the community's. @bendrucker shipped the symlink containment work through two rebases we caused, and when CI failed on his branch he did the diagnosis himself: reproduced it deterministically, tested and disproved our working theory, and root-caused a flake that had dogged this project for weeks, then filed the follow-up (#1477) for the remaining cases. @FNDEVVE swept our own issue tracker and closed two filed issues in as many days, with fixes careful enough that one of them independently matched bendrucker's root cause line for line. @katya4oyu fixed a real phone papercut with a minimal, well-tested change that read the repo's conventions closely enough to regenerate a build manifest most first PRs miss. And the headline feature exists because a user on X told us the review always opened against the wrong base when reviewing a stack. They were right.

      Thank you. Plannotator gets better because you tell us where it falls short.

      Full Changelog : v0.27.12...v0.27.13

    14. 🔗 r/LocalLLaMA So relevant rss

      So relevant | submitted by /u/0dayturtle
      [link] [comments]
      ---|---

    15. 🔗 smol-machines/smolvm smolvm v1.14.6 release

      What's Changed

      • Bump libkrun and rebuild the bundled libraries for all four platforms by @BinSquare in #1217
      • Show a pack pull's download progress and report the bytes a broken transfer actually moved by @BinSquare in #1218
      • Free a machine's data before the registry write when deleting by @BinSquare in #1219
      • Resolve an archive request against the workspace root by @BinSquare in #1220
      • Bump the workspace to 1.14.6 by @BinSquare in #1221

      Full Changelog : v1.14.5...v1.14.6

    16. 🔗 HexRaysSA/plugin-repository commits sync repo: +3 releases, -2 releases rss
      sync repo: +3 releases, -2 releases
      
      ## New releases
      - [ida-nexus](https://github.com/hexrayssa/ida-nexus): 0.11.0, 0.10.8
      - [vtable-context-tools](https://github.com/oxikkk/ida-vtable-tools): 1.2.0
      
      ## Changes
      - [ida-codemode](https://github.com/hexrayssa/ida-codemode):
        - removed version(s): 0.3.1, 0.3.0
      
    17. 🔗 Console.dev newsletter htmx 4 rss

      Description: Enhance HTML.

      What we like: Simplifies the approach to adding attributes to HTML tags for dynamic features. Now uses fetch(). Makes it easy to implement features like infinite scroll, form post, search as you type, polling, and streaming responses. Still pretty minimal (11kb) and no dependencies.

      What we dislike: Lots of attributes littered all over your HTML, but that is the point.

    18. 🔗 Console.dev newsletter Solo rss

      Description: Loader for Linux static binaries.

      What we like: Makes static binaries for GPU-accelerated code actually work. Makes it easy to build self-contained applications that can benefit from acceleration. Compile to musl, but still use common shared packages.

      What we dislike: Incomplete ABI coverage: unsupported glibc calls currently abort. Musl has its own compatibility issues.

    19. 🔗 Ampcode News Customize Your Dial rss

      You can now choose the models behind Amp's builtin modes and put your own agents on the Dial. There are two tabs in Settings → Mode Dial.

      Tune Your Modes

      In Tune Modes, choose the model and reasoning effort for a builtin mode's main agent, Oracle, or subagents. Use it to run those models through your own API key or ChatGPT subscription. The mode keeps its prompt and tools.

      Tune Modes with high selected, the Oracle pinned to GPT-6 Astra, and the main agent and subagents left on Auto

      Connect your key or subscription in Model Routing, then choose models it supports. You can change just the Oracle, or all three roles. Anything left on Auto follows Amp's choices as models improve.

      Billing follows your provider connections.

      Build Your Own Dial

      If you often find yourself using custom agents you built with plugins, like a dedicated code reviewer or a security agent, you can place them on the dial too. Build Dial lets you combine the builtin modes with your agents:

      Build Dial with Medium, High, and the Grok 4.6 plugin mode in three slots, one vacant slot, and a catalog of available modes

      Keep medium and high for building, and add a reviewer with your team's review instructions. A plugin agent can extend a builtin mode, so you only need to describe what it should do differently.

      Drag two to four modes onto the dial, put them in order, and hold to save. Use the mode picker in the app or press Ctrl+S in the CLI to switch between them. Workspace admins can set a shared dial too. Your personal choices take precedence.

      Make the dial yours. The docs cover both tabs.

  3. September 09, 2026
    1. 🔗 IDA Plugin Updates IDA Plugin Updates on 2026-09-09 rss

      IDA Plugin Updates on 2026-09-09

      New Releases:

      Activity:

      • disrobe
        • 2ffd86fd: serve documentation media with byte range support
        • 310fa9de: refresh disrobe documentation and playground
      • ffxiv_bossmod
      • ida-multi-mcp
        • 6f9e085a: Merge pull request #42 from Facetomyself/fix/windows-utf8-tasklist-ha…
        • 22d047de: Merge branch 'main' into fix/windows-utf8-tasklist-handshake
        • e656fca8: Merge pull request #40 from Plextora/main
        • a4f212aa: Merge branch 'main' into main
        • 8e5e0866: test: make Windows discovery regression portable
      • ida-nexus
        • 7c886c59: 0.11.0
        • 6c7ea66b: Make the database listing public, and let a manager pin its workers too
        • 4eaa2c59: 0.10.8
        • 4f82ee2e: Let a caller pin the environment a spawned worker gets
      • ida-pro-mcp
        • f07e4d0f: [relevant] Add whole-session binary diff triage
        • 44488775: [minor] Fix release version contract test
        • a84f1deb: [minor] Cover release version metadata
        • 8597aa6b: [relevant] Prepare v1.0.0a2 release metadata
        • 3542eeb1: [relevant] Repair native build workflow dispatch
        • a5aba63a: [relevant] Close release security and coverage gates
        • 207f2df7: [relevant] Add cross-session function comparison
      • idamcp
        • 5226041b: Set default include_line_prefix to False for decompile_function
        • 9f892a29: Add include_bytes option and context manager for disassembly and listing
      • IFSO-CYBER-FORENSICS-PROJECT
        • d075082a: Merge pull request #2 from Krishsharmacse/windows
      • Persona4-Decompilation
        • d2e28389: Recover 31 first-party functions and typed ABI boundaries
        • 217acad3: Recover panel callback and rounded rectangle draw
        • b2a4696c: Recover seven first-party resource and script functions
        • 6e9f7593: Refresh checked ASM provenance and publish SDK endpoint
        • 9225fe57: Separate proven Sony SDK linkage from game recovery
        • dba767e0: Recover func_00189940 byte-exactly
        • 27157d62: Recover field task constructor and camera pose updater
        • 95282b78: Recover material color callback and document controller payload blocker
        • 483147fc: Recover field transform and panel selection with explicit inputs
        • 060b182e: Recover panel composition and canonical drawing contracts
        • 004fc1c6: Recover three-sprite panel expansion from retail
        • 317bfbb2: Recover staged panel sprite animation from retail
        • ff2515a1: Recover panel transition and typed drawing position
        • 0fe20a78: Recover panel state updater from fresh ASM
        • 326ed9ed: Recover panel geometry from fresh ASM
      • Security-Tools
        • 4077bf10: Add .wakatime-project file with project name
        • 7107181d: Add hashcat crack output and gitignore runtime cache files
    2. 🔗 MetaBrainz The super special (lousy) shirt plan rss

      Editors are by far MetaBrainz’ biggest and most irreplaceable resource.

      They (you) spend countless hours entering data for free, be it for the love of music, to tidy their own collections and listen histories, to support their scenes, to archive historical and cultural data, to apply the cool and soothing editing brain-balm, or a combination of all of the above and more.

      Some of the top editors have provided the backbone of MusicBrainz for years, decades, and often perform the more tedious data maintenance and checking tasks.

      A few summits ago, the question was asked - can we give these editors, say those with 1 million+ edits, some recognition without getting into the quagmire of things like gamifying?

      Enter super special (lousy) shirt plan.

      reo showcasing his super special lousy shirt - a real and rare image of a top MusicBrainz editor outside!?

      Super special shirt plan is simple, we ask editors with over a million edits if they would like a lousy shirt (or their choice of shirts from our merch store), and if they say yes, we send them a lousy shirt!

      The plan was to accompany the shirts with an optional questionnaire/interview, so we could showcase some of our top editors and their editing tips and tricks. Reo said, on this topic: "I think many top editors don't get to top editorship by virtue of being very social". Turns out he may have had a point.

      Social or not, we appreciate all of you immensely. Thank you.

      1,000 and 100,000 edit versions of this shirt are available in the store for anyone with the required edit count (honor system!) to purchase. The 1 million edit version is exclusive to super special shirt plan.*

      If you have other ideas for how we could show appreciation to editors and voters (ideally within budget and without having to code and maintain complex new systems…) or want to shout out someone doing a great job, please comment below. If you have 1 million edits and did not receive your shirt email, please contact a staff member (we are available via ChatBrainz).

      please don 't abuse the system to increase your edit count. It's not worth it for a lousy shirt that your friends and family won't understand.
      *in case it gets lost - super special shirt plan doc can be accessed here (MeB staff access only, sorry)

    3. 🔗 r/LocalLLaMA Apple A20 Pro debuts with 7-core GPU, 32-core Neural Engine and 50% more memory bandwidth (~115 GB/s) rss

      Apple A20 Pro debuts with 7-core GPU, 32-core Neural Engine and 50% more memory bandwidth (~115 GB/s) | It seems to use a 96-bit LPDDR5X memory bus, instead of the previous 64-bit wide busses. Considering it's on 2nm, that's expensive silicon. That should result in around 115 GB/s memory bandwidth. A20 Pro also doubles the size of Apple's dedicated Neural Engine (from 16 to 32 cores total). submitted by /u/Balance-
      [link] [comments]
      ---|---

    4. 🔗 osolmaz/pi-workflows v0.16.10 release
      • Give package-internal composed workflows stable built-in IDs and revisions.
      • Keep internal workflows hidden from normal discovery.
      • Prevent false source-change failures when the server and runner load the same package from different installation paths.
    5. 🔗 r/LocalLLaMA Why the hell is LM Studio making LM Studio so difficult to download? rss

      Why the hell is LM Studio making LM Studio so difficult to download? | Who is the marketing genius at LM Studio that decided that going ALL IN on pushing their new Bionic Agent product meant they are going to make it a giant pain in the ass to find and download actual LM Studio. This is the dumbest marketing decision I’ve ever seen. I used to love LM Studio, it was the middle stepping stone in the logical progression of inference. Most OGs here likely started with Ollama, moved to LM Studio, on their way to vLLM. Now trying to go to LM Studio takes you to Bionic. I mean, you can eventually find LM Studio but they make it not super easy. Here’s a thought LM Studio, maybe stop redirecting me to something I don’t want to download when I’m trying to find your actual namesake product. I’m glad you’re excited about the future of Agents and whatnot, but you’re absolutely ruining any goodwill I have for your products by trying to force feed me Bionic. Stahhhhhp! submitted by /u/Porespellar
      [link] [comments]
      ---|---

    6. 🔗 smol-machines/smolvm smolvm v1.14.5 release

      What's Changed

      Full Changelog : v1.14.4...v1.14.5

    7. 🔗 r/LocalLLaMA Deepseek Has Soft Retired Deepseek V4 Pro rss
    8. 🔗 modem-dev/hunk v0.22.0-beta.1 release

      What's Changed

      Full Changelog : v0.22.0-beta.0...v0.22.0-beta.1

    9. 🔗 smol-machines/smolvm smolvm v1.14.4 release

      What's Changed

      • Share active branch memory and guard host capacity by @BinSquare in #1204
      • Write the release marker and identity files readable by the workload so a non-root machine can be branched by @BinSquare in #1205
      • Reclaim idle branch leaf memory by @BinSquare in #1206
      • Bump the workspace to 1.14.4 by @BinSquare in #1209

      Full Changelog : v1.14.3...v1.14.4

    10. 🔗 New Music Releases Max Richter - Now We Can Sing rss

      Max Richter - a new release is available:

      • 2026-09-09: Now We Can Sing (Single)

      Amazon: Canada | Deutschland | France | United Kingdom | United States

      Visit muspy for more information.

  4. September 08, 2026
    1. 🔗 IDA Plugin Updates IDA Plugin Updates on 2026-09-08 rss

      IDA Plugin Updates on 2026-09-08

      New Releases:

      Activity:

      • capa
        • f3765cdf: Sync capa rules submodule
        • 8f98440d: build(deps): bump protobuf from 7.35.0 to 7.36.0 (#3161)
        • 8fd882eb: build(deps-dev): bump pygithub from 2.9.0 to 2.10.0 (#3162)
        • 2be73341: build(deps-dev): bump types-protobuf (#3163)
        • 2c4183d8: build(deps): bump pygments from 2.20.0 to 2.21.0 (#3164)
        • 85740310: build(deps-dev): bump brace-expansion in /web/explorer (#3167)
        • 26083edf: build(deps-dev): bump postcss-selector-parser in /web/explorer (#3169)
      • chernobog
        • c4440677: docs: add Chernobog 6.2 release highlights to README
        • 113f6e99: test: separate catalog proof budget from runtime verifier deadline
        • dd726bd5: feat: support range-guarded recurrent switch unflattening
        • 67415156: perf: check leading byte before redundant rep prefix decode
        • 2b548201: perf: cache base-path feasibility and model witness in symbolic executor
        • 85df51df: feat: add full value invalidation and temporary feasibility queries
        • 6bc98663: test: implement restricted mop erasure in redirected hexdsp entry
        • b3b5b03c: test: emulate SDK mop erasure in standalone catalog harness
        • 5398d20d: feat: add numeric CFString display and restrict writable constant reads
        • ea056144: test: forward toolchain flags to python shim runners in ctest
        • fbac246f: feat: add bounded search summaries and UTF-8 runtime string recovery
        • 971ce4de: fix: require microcode address proof for early constant reads
        • 520ca369: perf: bound static analysis traversal to instruction budget
        • bc0e5e55: test: record run reports and isolate environment in ida smoke runner
        • b2cf5ad6: feat: add loaded byte views for program image segments
        • 2e4cbf88: perf: bound chain search in split-block detection
        • 43dd25a7: perf: optimize program model hashing and segment traversal
      • ida-forge
        • e63b92ee: Merge pull request #3 from oopsmishap/forge-api
        • 2cd92285: Harden feature reload and Qt flag combination
        • b3d74526: Raise Python floor to 3.10 (ida-domain minimum)
        • 10ac3154: Track scripts covered by unit tests
        • 16edb4bf: Add domain API and recovery coverage
        • 2fd0f826: Fix CI lint configuration
      • ida-hcli
    2. 🔗 Simon Willison Some thoughts on the Navier–Stokes Millennium Prize Problem rss

      On the Navier–Stokes Millennium Prize Problem introduces an impressive result from OpenAI, who used an unreleased model to produce a resolution to the Navier–Stokes existence and smoothness problem, one of the seven Millennium Prize Problems that have been subject to a $1,000,000 prize since May 24th, 2000.

      The discovery is somewhat overshadowed by accusations of skulduggery from Tristan Buckmaster, an NYU mathematics professor who was collaborating on related problems with Levent Alpöge, an accomplished mathematician who currently works for Anthropic.

      Tristan's complaint accompanied a hastily published version of their own results. Here's the PDF describing what happened. The very short version is that Tristan and Levent worked on the problem for almost a year, making extensive use of Claude and Codex (mainly GPT-5.6 Sol), then had a breakthrough on August 15th. The mathematical rumour mill kicked into gear and Tristan and Levent heard that OpenAI had heard that Anthropic had resolved "a major open problem", so they reached out and learned that OpenAI had a team working on a related problem, with a similar approach. Quoting Tristan:

      I asked when the first prompt had been sent by them. This question was not answered directly by OpenAI for some time. Eventually it was agreed that it had been sent in the past few days, after information about our work had reached OpenAI.

      I asked whether the model had been trained on, or had access to, our sessions in Codex, into which we had been putting all our drafts for the whole of this project. I was told the model did not look up user data. I asked again, about training, and I did not get an answer.

      It gets more complicated from there. The OpenAI team offered to wait for Tristan to publish, or to have him author a paper about their result, but were clear that Levent would not be invited as a co-author due to OpenAI's competitive relationship with his employer.

      Here's how OpenAI described their work:

      On Tuesday, September 1, we heard rumors that two Millennium Prize problems had been resolved. Inspired by these rumors and by the step change in performance of our internal model, we launched an effort to evaluate it on all open Millennium Prize problems and a few other high-impact problems. [...]

      The agents arrived at their resolution on Saturday, September 5, about 88 hours after the first agents were launched. Lean formalization and verification took an additional 17 hours via GPT‑6 Astra.

      Across all attempted problems, the agents sent 4.9 million messages and used about 300 billion output tokens. In the process of resolving the Navier–Stokes problem, the agents sent 2.7 million messages and used approximately 130 billion output tokens.

      (We don't know the cost structure of the internal model they used, but 300 billion output tokens at public API prices for GPT-6 Astra would cost $15,000,000.)

      Here's where they provide their perspective on Tristan and Levent's work (emphasis mine):

      Our effort began on September 1st after hearing a rumor which we later realized was related to Levent Alpöge, an Anthropic employee, and Tristan Buckmaster, a math professor at NYU. After the completion of our full project and Lean verification (on September 6th), believing from the rumor they also had a solution of Navier–Stokes, we reached out to them to offer a concurrent release of our result and to recognize their priority in a joint announcement. [...]

      We (the researchers and the agents) did not see any of their work through any means until they released it publicly — in particular, no specific user data was accessed in order to solve this problem. While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models. However, our proofs differ significantly and even the precise results proved are different in the Euler case (forced vs unforced).

      My interpretation of what happened here is that OpenAI heard that some Millennium Prize problems had been solved using LLMs and saw this as an opportunity to demonstrate the power of their latest model, without thinking too hard about the optics of scooping a team who had been using OpenAI's own models to work on this problem for the best part of a year.

      This situation appears to mirror what's happening in the world of computer security right now. Anil Madhavapeddy recently pointed out that Just a rumour of a bug is enough to find a security exploit these days, because if someone knows that some software has an unpatched vulnerability, they can set their agents the task of finding it. Is the same now true of mathematics? Just knowing that there is an unpublished solution to a problem might trigger millions of dollars in LLM spending to get there first.

      This also highlights one of my ongoing frustrations about how all of this works. When an AI lab says that my data is "used to improve model performance", what does that actually mean?

      My two favourite hypothetical questions regarding this used to be:

      • If I'm running Codex and one of my API keys accidentally gets consumed in the context, what are the chances that someone else might ask for an API key in the future and get mine back? (I asked someone at OpenAI once and they called this the "regurgitation" problem and assured me that they take great pains to prevent that... but wouldn't describe how.)
      • If I brainstorm with ChatGPT about potential new directions for my company, what's the chance that information might be exposed to a competitor in six months' time who asks "what might company X plan to do next"?

      My new preferred hypothetical for this is:

      • If I use ChatGPT to help me partially solve a Millennium Prize problem, what are the chances that my work will influence training such that a later model helps someone else solve it first?

      Via Hacker News.

      You are only seeing the long-form articles from my blog. Subscribe to /atom/everything/ to get all of my posts, or take a look at my other subscription options.

    3. 🔗 @binaryninja@infosec.exchange RE//verse 2027 tickets are LIVE! Trainings too! Round 1 is the cheapest mastodon

      RE//verse 2027 tickets are LIVE! Trainings too! Round 1 is the cheapest pricing we’ll offer, so grab your ticket before they sell out. See you in Orlando: https://re-verse.io

    4. 🔗 @HexRaysSA@infosec.exchange 📢 The 2026 IDA Plugin Contest is officially open! mastodon

      📢 The 2026 IDA Plugin Contest is officially open!

      Got an idea for a plugin that could make reverse engineering faster, smarter, or just more fun? Now's your shot. Submissions are open through November 30, with winners announced mid-January.

      Build with C, C++, Python, or idalib. And since our SDK is now open-source, IDA Free users can jump in too.

      Up for grabs: cash prizes up to $5K, free IDA licenses, recognition in the community, and more.

      Full rules + prize breakdown: https://hex-rays.com/plugin- contest

    5. 🔗 r/LocalLLaMA Qwen/Qwen-Drive-1.0-4B · Hugging Face rss

      Qwen/Qwen-Drive-1.0-4B · Hugging Face | I don't think anyone posted about this here, but Qwen released a finetuned version of 3.5 4 for driving. The full Bf16 checkpoint is 9B. This is a very interesting development of Chinese AI labs tackle self driving next with open weight models. Edit: the HF repo links to the github repo, which in the citation links to a 40 page technical report. Here's the abstract: We present Qwen-Drive-1.0, an initial step towards a vision-language foundation model for autonomous driving. Qwen-Drive-1.0 retains the architecture of the pretrained vision-language model (VLM) and integrates 3D perception, visual question answering, and motion planning within a unified framework. An external bird’s-eye-view (BEV) perception head jointly performs 3D object detection, semantic occupancy prediction, and BEV map segmentation. It serves as a probe of the 3D information accessible from the shared representations and provides an explicit, inspectable interface to 3D scene structure. A Planning Expert conditions on shared VLM representations to generate future ego trajectories. A staged training recipe combines driving supervision with general-purpose vision-language data to acquire driving-specific competence while helping preserve broad visual understanding and instruction-following capabilities. Experiments demonstrate strong 3D perception and driving scene understanding while largely preserving general vision-language capability. Comprehensive evaluations across open-loop, pseudo-closed-loop, and closed-loop settings further show highly competitive motion-planning performance. submitted by /u/FullstackSensei
      [link] [comments]
      ---|---

    6. 🔗 modem-dev/hunk v0.22.0-beta.0 release

      Hunk 0.22 beta: history becomes a review workspace

      Hunk 0.22 turns repository history into a responsive review workspace: browse commits, select contiguous ranges, carry review context into the diff, and leave precise threaded feedback without leaving the terminal.

      hunk update 0.22.0-beta.0
      npm install -g hunkdiff@0.22.0-beta.0
      

      Browse commits and review ranges

      hunk log now opens a responsive, themed history browser for Git and Jujutsu. Commits are grouped by day, optional graph lines preserve topology, and visual or Shift-based range selection opens the cumulative diff for a contiguous set of commits. History has configurable command bindings, merge-parent selection, and keeps your theme and diff preferences as you move between history and review. #979 #987 #1011 #1031 #1038 #1039

      Select and discuss exact code ranges

      Persistent mouse and keyboard selections can now span multiple lines and drive explicit Comment, Copy, and Clear actions. Inline notes and replies participate in keyboard navigation, and agents can reply through the session CLI while inheriting the original code anchor. #931 #1012 #1044

      Richer extension-powered reviews

      Extensions can attach provider-neutral review metadata when delegating patches, expose that context to panes and live-session snapshots, and request a coalesced reload after an external agent changes reviewed files. The extension directory also adds hunk-gh, hunk-viewed, hunk-history, and hunk-compact-filenav. #986 #988 #981 #995 #1034

      Faster, steadier terminal interaction

      Long wrapped lines render and respond faster, pane animations are capped at 30 FPS and can be disabled, sidebar folders collapse without breaking navigation, suspended sessions resume cleanly, and direct-file reviews reload correctly outside repositories. #1043 #1051 #1036 #1009 #996 #1054

      Compatibility notes

      • unified is now the canonical name for the single-column diff layout. Existing stack CLI and configuration values remain accepted as deprecated aliases and normalize to unified.
      • Extension API v23 adds canonicalMode and canonicalLayout, which report unified; legacy fields continue to report stack for compatibility.
      • OpenTUI integrations can use canonicalLayout: "split" | "unified"; the legacy layout: "split" | "stack" prop remains source-compatible, and canonicalLayout wins when both are supplied.
      • hunk log opens the interactive history browser when attached to a terminal. Use --static for scripted terminal output; pipes remain static.
      • Review commands now print static plain text instead of launching the TUI when stdout is not a terminal.
      • The bundled runtime is upgraded to Bun 1.4.2.

      Community contributors

      • @samuela improved daemon health-probe failure reporting. #927
      • @saadjs led the stack-to-unified layout transition while preserving compatibility. #945
      • @any-victor added hunk-history to the extension directory. #995
      • @HackAttack fixed suspended-job resume behavior. #996
      • @rschoch added hunk-compact-filenav to the extension directory. #1034

      All merged pull requests

      Release notes : https://hunk.dev/changelog/0.22/
      Full changelog : v0.21.1...v0.22.0-beta.0

    7. 🔗 r/LocalLLaMA OpenAI alleged of stealing mathematicians work rss

      Privacy have been concern of many of us to have their own hardware to run llms, and here's another reason why: two mathematicians spent a year cracking one of the hardest problems in math and fed every draft of their works into Codex. A few days before they could publish, OpenAI suddenly showed up with the same solutions. When asked if their model (Sol and Astra) was trained on the pair's private chats, OpenAI did not answer the question.

      Full statement from them https://cims.nyu.edu/~tristanb/statement.pdf

      Feels like big labs believe everything you did with the help of their models is theirs.

      submitted by /u/bakawolf123
      [link] [comments]

    8. 🔗 osolmaz/pi-workflows v0.16.9 release
      • Restore bounded workflow recovery after interrupted agent and runner work.
      • Keep submission reminders and terminal handoffs recoverable without duplicate continuation runs.
      • Pause pending workflow work before restart adoption checks.
    9. 🔗 r/LocalLLaMA DeepSeek Flash 4.1 is already being tested via API and rolling out. rss

      DeepSeek Flash 4.1 is already being tested via API and rolling out. | Translation: "Internal beta testing for an intermediate version of DeepSeek V4.1 Flash is now open; you are welcome to try it out. It adopts a new model architecture featuring native multimodal support, stronger capabilities, faster speeds, and lower costs.
      Keep your base_url unchanged and set the model name to deepseek-v4.1-flash- expires-on-0910 to call the API. Current pricing is identical to deepseek-v4-flash, with a rate limit of 20 concurrent requests per account." From Chubby on 𝕏: https://x.com/kimmonismus/status/2097286327909675477 submitted by /u/Nunki08
      [link] [comments]
      ---|---

    10. 🔗 smol-machines/smolvm smolvm v1.14.3 release

      What's Changed

      • Run init as root on every path, and keep the image's USER for a packed workload by @BinSquare in #1190
      • Open a machine to observe it without creating its disks or data directory by @BinSquare in #1197
      • Add selectable block I/O engines by @BinSquare in #1198
      • Honor a storage size below the template by shrinking the copied filesystem instead of rounding up by @BinSquare in #1199
      • Bound live branch memory accounting by @BinSquare in #1200
      • fix(network): prevent named-fabric receive busy loop by @scottatron in #1201
      • Resolve a packed machine's launch from its manifest in one place by @BinSquare in #1150
      • Pack machines with the entrypoint they were created with and the overlay they actually write to by @BinSquare in #1174
      • Record the image's USER, or the Smolfile's user, in a pack made from an image so its workload keeps its account by @BinSquare in #1202
      • Bump the workspace to 1.14.3 by @BinSquare in #1203

      New Contributors

      Full Changelog : v1.14.2...v1.14.3

    11. 🔗 HexRaysSA/plugin-repository commits sync repo: +1 plugin, +1 release rss
      sync repo: +1 plugin, +1 release
      
      ## New plugins
      - [BinaryLens](https://github.com/lumice/binarylens) (1.2.0)
      
    12. 🔗 jellyfin/jellyfin 12.0 release

      🚀 Release notes for 12.0

      Notes on Updating

      Before upgrading from an earlier version, a full backup of the data directory is strongly recommended, as this release includes database changes that prevent rolling back without a full restore.

      Direct upgrades from 10.10.7 and 10.11.x to 12.0 are supported; intermediate upgrades are not required. Users running releases older than 10.10.7 are strongly encouraged to upgrade to 10.10.7 before migrating to 12.0.

      Installed repository plugins (anything not built-in) should also be removed before migrating. Plugins will likely need time to adapt to the new database changes, so re-adding them afterward is the safest approach for testing.

      Official plugins compatible with Jellyfin are available through the stable plugin repository. If you have changed to the unstable plugin repository please change it back.

      After migrating please perform the following steps.

      • Perform a full library scan to restore alternative versions

      If you run into issues, please prefix bug reports with "[12.0]".

      Packaging

      • Debian Bullseye and Ubuntu Focal packages are no longer built

      Server

      • Performance PR implications #16062

        • We're running a full path-based check on all library items to clean up left overs. Depending on size this can take some time
        • Alternative versions of media that were auto resolved (not manually merged) will be removed due to data type issues -> A full library scan will fix this again and is therefore REQUIRED AFTER UPGRADE
        • First scan will take significantly longer than normal and some movies might appear as newly added due to type issues that got fixed on-scan
      • Multiple versions for episodes

      • Similarity & recommendation providers
      • Search providers, letting plugins extend or replace how search results are produced
      • SchedulesDirect and EPG refresh fixes
      • Fixes to the parental rating system
      • Proper data pruning on file replacement/deletion
      • Support triple+ digit episode numbers
      • Add library-specific BoxSet and Playlist filtering, allowing per-library collection and playlist views
      • CACHEDIR.tag support
      • Accept-Language header support
      • Add VideoRotation profile condition for Android TVs that do not support rotation metadata
      • Parse provider IDs from season and episode folder/file names
      • Allow tmdb, tvdb, and imdb as aliases for the tmdbid, tvdbid, and imdbid provider IDs
      • Add curly brace and parentheses support for parsing attribute values
      • Add NameStartsWith and NameLessThan filters to Person search
      • Add new filters for audio and subtitle languages
      • Add OriginalLanguage as option to PreferredAudioLanguage
      • Add a collection API for Included In feature
      • Add support for VobSub subtitle streams
      • Add Tmdb missing episode provider

      Breaking and behavior changes

      • Legacy route prefixes removed (/emby/* and /mediabrowser/*). Old third-party clients that rely on them will stop working
      • Legacy authorization is now disabled by default, and a migration disables it on existing installs as well
      • Removed obsolete API routes: POST /Users/{userId}/EasyPassword (the EasyPassword feature is gone), GET /Items/{itemId}/CriticReviews, GET /Environment/NetworkShares, POST /System/MediaEncoder/Path, GET /LiveTv/Recordings/Groups/{groupId}, and GET /QuickConnect/Initiate
      • The global subtitle configuration has been removed, subtitle settings are configured per library
      • .ogg is no longer treated as a video extension and is audio only, .aifc is now recognized as audio, and .aiff is no longer treated as an image
      • Symlinks are only resolved at playback time
      • Sorting by name now uses SortName and CleanName, and the same cleaning logic is applied to ForcedSortName. Library ordering may change compared to 10.11
      • Image endpoints no longer upscale beyond the source resolution, so low resolution artwork renders at its real size instead of being enlarged
      • Username capitalization can now be changed. Usernames are stored in a normalized column with a unique index, so installs with usernames that differ only by case need to be corrected before upgrading

      Database and performance

      • Playlists and collections are now properly relational, using a new LinkedChildren table instead of serialized child lists. OwnerId and PrimaryVersionId are real GUID foreign keys, and ExtraIds has been dropped
      • Many tuning migrations covering item counts, item names, type and clean name, latest items, image info, and primary version id
      • Migration routines clean up existing data on first boot: duplicate music artists and people are merged, orphaned extras and external data are removed, incorrect owner relationships are repaired, and clean names, forced sort names, and series presentation keys are recomputed
      • Heavy database tasks no longer run while a library scan is in progress
      • Faster queries for Resume, Next Up, rewatching, Latest Items for music, playlists and collections, artist lookup, and item counts
      • Item deletion is batched, which fixes "too many SQL variables" failures when deleting large numbers of items
      • jellyfin.db can now be stored at a custom path

      Operations

      • New --mode startup flag with MediaServer, MigrateSystem, and SeedSystem, allowing migrations or database seeding to be run without starting the server. This is useful for containerized and orchestrated deployments and for controlled upgrades
      • The startup interface has been restyled and now shows version and activity information
      • Disabled plugins are no longer re-enabled on restart
      • Full system backups skip corrupt keyframe rows instead of failing

      Media and subtitles

      • Subtitle writing now goes through SubtitleEdit, which is what avoids the SSA to ASS conversion and loss of styles
      • External subtitles can be embedded into MKV when transcoding
      • The subtitle extraction timeout is now configurable
      • Client-rendered graphical subtitles are allowed during remux
      • Fixes for races in concurrent subtitle conversion, cache invalidation when a subtitle is replaced, and ffmpeg hangs during extraction
      • New HlsAudioSeekStrategy configuration option
      • Trickplay: existing files are discovered during a scan, duplicates from interlaced video are fixed, invalid PTS values from containers are normalized, and the cache is cleaned up after a failure

      Live TV

      • Live TV no longer returns unreachable "server-local" streaming URLs to clients
      • XMLTV background images and episode thumbnails are now imported
      • XMLTV guide imports skip programs whose data has not changed, using an ETag computed from the fields the server actually consumes, which makes repeat guide refreshes considerably cheaper. Other listings providers stay on the existing field-by-field update path

      Metadata and providers

      • ListenBrainz is now bundled with the server and provides similar artist data with a selectable similarity algorithm
      • TVDB provider IDs are supported for movies
      • AudioDb artist search
      • ReplayGain album gain is parsed
      • MusicBrainz lookups are more resilient
      • WEB-DL release tags are recognized in file names
      • Hyphenated numbers in episode titles are no longer parsed as multi-episode files
      • 3D format detection works when the tag is the last token of the path
      • Person metadata refreshes are queued instead of blocking the request

      Transcoder

      • New upstream version of FFmpeg 8.1
      • Optimized CUDA transposing filter performance
      • Optimized OCL scaling filter performance
      • Optimized OCL tonemapping filter performance on Mali GPU
      • Use EOTF from BT 2446 Method B for HLG tonemapping
      • Fix potential A/V desync in HLS when transcoding video while remuxing audio
      • Avoid SSA to ASS conversion and loss of styles
      • Add spec-compliant dvh1 HLS variant for DoVi P5 for compatibility

      Web

      • The Modern layout is now the default, the previous layout is now called Legacy
      • Updated Music Videos view
      • Updated Mixed Media view
      • Updated Collections & Playlists view
      • Updated Books view
      • Add still watching prompt
      • Add delay setting for photo slideshow
      • Add caching of queries to indexed db for the tanstack query client for improved loading performance
      • Add watch feature to log viewer
      • Add , and . as controls to scrub frame-by-frame
      • Add filters for audio and subtitle languages (modern layout only)
      • Add Collections and playlist tab to all libraries
      • Add collections to item details page
      • Replace libpgs with libbitsub and adds support for vobsub rendering
      • Merge cards for crew with multiple roles

      Layout and themes

      • All themes now derive from a shared base theme built on CSS variables, including Dark, Light, WMC, Blue Radiance, Apple TV, and Purple Haze. Custom themes may need to be adjusted
      • The library toolbar has been merged into the app bar, with a sticky library header and design polish throughout the library
      • Custom links can be added to the Modern layout
      • The screensaver time setting is now available in the Modern layout

      Libraries and browsing

      • Collections and folders tabs for book libraries, and a folder view in the Modern home videos layout
      • Default tab options for Home Videos and Photos libraries
      • Studio search, and an extended Studios tab
      • Play All and Shuffle buttons on the series library. Both are disabled rather than hidden when no items are available
      • Improved Upcoming view
      • Sorting and filtering on the Activity page
      • A Reset Filters button in the filter dropdown
      • Folders can be marked as played
      • TV show creators are shown on item details
      • Similarity providers can be configured per library
      • Pagination controls are hidden when paging is disabled

      Playback

      • The playback info overlay is more compact and shows more detail
      • Chapter names are shown in the OSD slider bubble
      • Bitrate detection now runs in web
      • Dolby Vision in MKV on webOS 25 and newer
      • AV1 fMP4 stream copy on TV clients
      • Direct play of anamorphic video on Tizen, and loosened anamorphic restrictions for browser device profiles
      • On iOS, background playback continues when the screen is turned off, and audio normalization is disabled to fix pitch and speed issues
      • libbitsub updated to v1.11.0 with an HLS offset fix
      • The screensaver is suppressed while viewing photos or reading

      TV and remote

      • Game controller navigation fixes, and the gamepad repeat rate is no longer tied to framerate
      • Keyboard controls work on non-Latin keyboard layouts, with additional fixes for older browsers
      • Rewind and FastForward play state commands are handled
      • SyncPlay menu update, and the SyncPlay ping is now reported to the server
      • Focused and checked checkbox styling in the TV layout

      Under the hood

      • WebSockets have been migrated to SDK subscriptions
      • The React and TypeScript migration continues with the libraries, Live TV, and networking pages, and the dashboard user pages now use the TS SDK
      • TanStack Query now backs user settings and home screen sections, and the query cache is cleared when the server restarts

      Notable fixes

      • Blurry card images on high DPI displays, and card image sizes are rounded up
      • Duplicate /socket connections
      • Login loop, connecting to the wrong server when several are configured, and native shell server selection when signing out
      • An invalid request for all items on page load
      • The Live TV default landing tab
      • Holding and dragging on media no longer activates multi-select
      • A warning is shown before restoring a version, a warning is shown when starting a backup while a scan is running, and a library scan starts automatically when folders are added to a library

      Security

      Server:

      • Path validation has been added to the legacy HLS segment endpoints and to the plugin image endpoint, so a requested file must resolve inside the transcode directory
      • Path traversal hardening has been extended to the image and plugin endpoints and to username path handling, building on the fixes released in 10.11.x
      • The startup wizard can no longer be re-run without authentication on a misconfigured server
      • Unsafe plugin package names are rejected by the plugin installer
      • Parental filtering is enforced on additional endpoints, playlist visibility has been corrected, non-admin access to additional parts has been fixed, and people are exempt from the allowed tags visibility check

      Web:

      • Cross-site scripting via person roles
      • Auth parameters are encoded when creating API clients
      • The login disclaimer only allows common link protocol schemes

      Books

      Books have often taken a backseat in favor of video playback in Jellyfin, but this should no longer be the case.
      We have started a concerted effort to improve book support across the API and our official clients.
      eBook and comic support is still maturing, but the ODPS plugin allows for direct access from a wide range of popular self-hosted programs.
      Correspondingly, contributions in any repository are extremely welcome from the wider community.
      That includes server improvements, documentation changes, and third-party clients for book playback.
      A combination of eBook, comic, and audiobook support is available on the following clients.

      Official: Web, iOS, Android, Desktop, Roku, Kodi, JMP
      Community: JellyBook, Symfonium, Jellium, Plappa

      One notable omission from the server is book series as unique entities, which didn't make the cut for this release.
      If you would like to bridge the gap until they are added, feel free to use the Folio plugin to display them as collections.
      It functions very similar to the TMDb Box Sets plugin but only applies to eBooks.

      Another in-flight feature is audiobook chapters, which are only available from the API at present.
      Luckily, this means client support is now possible, so you should see them appear in your favorite audiobook client before our next server release.

      NOTE: The Bookshelf plugin has been deprecated and its features have been merged into server or extracted into the ComicVine and GoogleBooks providers.

      Server Changes

      • Bookshelf has been split into separate GoogleBooks and ComicVine providers
      • Local book parsing has been improved and is available without plugins
        • Book metadata is extracted directly from OPF and ComicInfo files or ComicBookInfo comments
        • External covers are now supported for audiobook files
        • Posters are generated for EPUBs and all supported comic archives
        • Name, index, year, and series are parsed from book filenames
        • Both volume and chapter will be available in the API when present in comic filenames
        • Page counts are extracted from comic archives and PDFs
        • Creator names from OPF data are normalized to a common format
      • A new OpenLibrary plugin has been created for metadata and images
      • ISBN external IDs and links are supported
      • Chapters are now extracted from audiobooks

      Web Changes

      • Modern book library layout has been added with view types and paging
      • Books display information about their authors and vice versa
      • Playback interface has been redesigned and standardized across all book types
      • Progress indicator is enabled again for supported eBooks
      • Sorting books by index number, release date, etc is now available
      • Font size selection has been improved for EPUB files
      • Background audiobook playback is working on iOS devices
      • Authors, collections, and folders tabs have been added to book libraries, and audiobooks appear under authors
      • Fullscreen behavior is unified across all book players, and PDFs support swipe navigation

      Developers

      API Changes

      The API no longer allows the use of deprecated authorization mechanisms by default.
      Clients and tooling need to migrate if they haven't done so already. See #15559 for details.

      There have been a number of other changes to the SDK libraries and API as part of an ongoing effort to better document the API for client use.
      Please note the following with regards to API support.
      A full explanation of our policy for API changes will be added to the developer documentation in the coming months.

      • If an endpoint isn't listed in the OpenAPI specification it should not be used by clients.
        • There are certain endpoints that are still exposed for legacy reasons despite being excluded from the OpenAPI spec.
        • These can be removed in any major release without warning
      • If an endpoint or parameter is marked as obsolete in the OpenAPI specification it should not be used by clients.
        • Same explanation as above.
      • As a general rule, any deprecations will be marked as such for an entire (major) release cycle before the deprecated endpoint or parameter is liable for removal.

      Behavior changes clients should be aware of:

      • GetItems is now asynchronous and applies recursive when filters are requested, limited to requests that include includeItemTypes. The same query can return a different result set than it did on 10.11
      • ItemByName responses are restricted and people are deduplicated
      • Newly obsolete but still functional, with replacements:
        • GetTrailers -> use GetItems with includeItemTypes=Trailer
        • GetArtists and GetAlbumArtists -> use GetPersons
        • GetArtistByName -> use GetPerson
        • GetMusicGenre -> use GetGenre
        • GetInstantMixFromMusicGenreById and GetInstantMixFromMusicGenreByName -> use GetInstantMixFromItem
        • GetStartupConfiguration, UpdateInitialConfiguration, and SetRemoteAccess -> use the configuration endpoints
        • GetRecordingsSeries
        • UserDto.HasPassword is marked obsolete and no longer provides useful information
      • The HLS controllers are hidden from the specification

      Platform

      • The server now targets .NET 10. Plugins have to be retargeted and rebuilt
      • Swashbuckle has been updated to v10, which changes the generated OpenAPI document, so SDKs need to be regenerated
      • jellyfin-web now builds with Node 24 LTS and npm 11

      Plugin changes

      • ISearchEngine has been replaced by ISearchManager, and SearchEngine has been replaced by SearchManager together with SqlSearchProvider
      • Removed: NowPlayingQueueFullItems, DtoExtensions.AddClientFields, Jellyfin.Extensions.AlphanumericComparator, the ISubtitleWriter family of subtitle writers, and SubtitleOptions with SubtitleConfigurationFactory
      • ServerConfiguration.EncoderPreset is no longer nullable
      • IAuthenticationProvider.HasPassword has been removed
      • IPasswordResetProvider.StartForgotPasswordProcess takes the entered username and a nullable user
      • IUserManager: the Users and UsersIds properties are now the GetUsers and GetUsersIds methods, and RenameUser, ResetPassword, and ChangePassword take a user id instead of a User. GetFirstUser has been added
      • Several IItemRepository members moved to the new services: item saving and deletion and UpdateInheritedValues to IItemPersistenceService, counts to IItemCountService, and Next Up series keys to INextUpService
      • IPeopleRepository.GetPeople and ILibraryManager.GetPeopleItems return a QueryResult, and IDtoService.GetBaseItemDtos and ILibraryManager.DeleteItemsUnsafeFast have new signatures
      • IDirectoryService.GetFilePaths no longer takes a sort argument, and the IPathManager subtitle and attachment path getters are now nullable

      New plugin APIs

      This release adds several extension points that plugins could not hook into before.

      • Search providers. Plugins can now take part in search itself rather than only in metadata lookup. ISearchProvider exposes Name, Type, Priority, and CanSearch(SearchProviderQuery), with IInternalSearchProvider for providers that search the local library and IExternalSearchProvider for providers that stream SearchResult items from a remote service. Providers are registered through ISearchManager.AddParts and are consulted in priority order, so a plugin can extend or take over from the built-in SqlSearchProvider
      • Similarity and recommendation providers. ISimilarItemsProvider is split inherited by ILocalSimilarItemsProvider, IRemoteSimilarItemsProvider, and IBatchLocalSimilarItemsProvider, each with a generic variant so a provider can declare the item type it handles. Providers are selected and ordered per library through LibraryOptions.SimilarItemProviders and SimilarItemProviderOrder, and ISimilarItemsManager also pulls movie recommendations. The bundled ListenBrainz provider is built on this
      • Comic metadata providers. IComicProvider (ReadMetadata and HasItemChanged) lets a plugin supply comic metadata alongside the built-in ComicInfo and ComicBookInfo readers
      • Chapters for any item type. IChapterManager.SaveChapters now takes a BaseItem rather than a Video, and gained a Supports(BaseItem) check. This is what makes audiobook chapters possible, and it lets plugins save chapters for non-video items
      • Password resets for unknown users. IPasswordResetProvider.StartForgotPasswordProcess now receives the entered username along with a nullable user, so a provider can handle a request for a username the server does not know or hand the reset off to an external provider
      • Media segment cleanup. IMediaSegmentProvider.CleanupExtractedData is called when an item's data is pruned, so segment providers can remove their own extracted files
      • Schedules Direct. ISchedulesDirectService exposes available countries, service availability, and the image daily limit state, so Live TV plugins no longer need to reimplement them. ITunerHostManager.DeleteTunerHost allows removing a tuner
      • Alternate versions and linked children. Now that linked children are relational, ILibraryManager exposes ResolveAlternateVersion, GetLocalAlternateVersionIds, GetLinkedAlternateVersions, GetItemIdsWithAlternateVersions, and UpsertLinkedChild. Plugins that manipulated version links through serialized item data need to move to these
      • Batch APIs for bulk work. IUserDataManager gained GetUserDataBatch, GetResumeUserData, GetResumeUserDataBatch, and ResetPlaybackStreamSelections. ILibraryManager gained GetPeopleByItems, GetPeopleNamesByItems, and GetNextUpEpisodesBatch. IItemCountService offers batched child and played/total counts
      • Localization. ILocalizationManager.GetServerLocalizedString and GetLanguageDisplayName let plugins localize against the server locale
      • ICollectionManager.GetCollectionsContainingItem backs the Included In feature, and IPlaylistManager.AddItemToPlaylistAsync takes a position so items can be inserted at the top of a playlist

      IHasEmbeddedImage is also new, but it is only for plugins compiled into the server; external plugins should keep declaring their image with imagePath in meta.json.

      TLS Configuration

      In the previous release notes 10.11.0 we announced the deprecation of the built-in TLS certificate handling for this version. This change has been postponed to a future version.


      Discuss this release further on our forums.

      Changelog (460)

      🔒 Security

      🌟 Highlights

      🏗️ Enhancements

      📈 General Changes

    13. 🔗 Project Zero Testing race conditions with memory access tracing and stack-based delay injection rss

      Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases:

      • Confirming bug candidates that have been discovered manually or through static analysis.
      • Regression tests: After fixing a race condition bug, there is often no good way to write a regression test that reliably triggers the bug as part of a test suite.
      • Automatic bug discovery, such as fuzzing: It is hard for a fuzzer to exercise all interesting interleavings of concurrent operations, or reach code paths that are only exercised when operations are racing.

      I mostly discover bugs by manually reading code. When I think I’ve found a bug, I normally write a test case to either prove or disprove that the bug exists. For race condition bugs, it can be hard to achieve either outcome. For Linux kernel bugs, I often resort to recompiling the kernel after adding conditional mdelay() calls (which spinloop for roughly the specified amount of time) in appropriate places; I usually make these conditional based on the name of the running thread, though sometimes more complex conditions are needed. On platforms that support DTrace (like macOS and Windows), it is possible to use DTrace probes that call chill() for similar effect, though the utility of this is limited as DTrace can only trace on non-inline function boundaries or explicit trace points, rather than on every instruction. Regardless of platform, this approach can be time consuming and can require trial and error to definitely determine whether code is buggy.

      Additionally, in the Linux kernel, fixes for race condition bugs are often accompanied by hand-written ASCII diagrams showing problematic thread interleavings with call graphs and relevant memory accesses (for example, see this recent rt_spin_unlock UAF fix, or this recent jbd2 deadlock fix). It would be convenient to have developer tooling that can analyze potentially vulnerable code and show results in a similar representation.

      Summary

      I wrote tools for exploring possible interleavings of multi-threaded test cases for the Linux kernel:

      • A tool that automatically tests all possible A-B-A interleavings of a test case.
      • A terminal UI for manual exploration of possible interleavings.
      • A GUI for manual exploration of possible interleavings.

      The kernel part of this is intended to also be usable for discovering race conditions via fuzzing, but userspace tooling for that still needs to be implemented.

      The tools are available on GitHub under the name MAccConc, short for “Memory Access Concurrency”; see the README there for installation and usage instructions.

      If you just want to see the tooling in action, skip to Demo: automatic testing.

      If you’re just interested in the theory behind the tooling, read section Stable identifiers for memory accesses across runs: count-augmented stack traces.

      Prior work

      This project was inspired by discussions with Ned Williamson, whose sockfuzzer project involved exploration of concurrency bugs by using a custom scheduler that can reschedule at synchronization primitives to explore interleavings. See the conference talk slides and recording focused on the concurrency testing aspect of this.

      My tooling is largely based on ideas similar to SKI, but SKI uses a different implementation: It records memory accesses and controls scheduling of vCPUs using a patched version of QEMU in TCG mode, and uses VM snapshots to explore different execution interleavings.

      Discovering memory accesses that could contribute to race conditions

      (communication points)

      As described in the SKI paper, interesting execution interleavings of a given multi-threaded test case can be discovered by tracing memory accesses of all threads and searching for pairs of accesses on two threads that could interact with each other - meaning, roughly, that at least one of them is a write operation, and they access overlapping memory ranges. The SKI paper calls such memory accesses communication points.

      This requires some mechanism to collect memory access coverage. SKI did this by patching QEMU’s TCG mode; I am instead relying on ASAN instrumentation in “outline” mode (compiler backend flag asan-instrumentation-with-call- threshold=0, selected by CONFIG_KASAN_OUTLINE in the Linux kernel), which generates helper function calls on memory access. I believe that the kernel is the right place to collect this data because it would allow the kernel to also provide higher-level information about lock acquire/release events and such, though I have not implemented this at this time. Implementing this in the kernel also means that it would theoretically be possible to test on bare- metal hardware, rather than inside VMs.

      Since Linux already has KCOV as a mechanism to feed basic block kernel coverage information to userspace, I decided to use the same mechanism to record information about memory accesses. An alternative would have been to use ftrace, which is oriented towards tracing use cases, and includes a function graph tracing mode built on fentry hooks and more complex output buffer management that is oriented towards use cases including system-wide data collection. I chose to use KCOV because of its simpler in-memory representation of trace data (which could become relevant for recovering trace data from crashed VMs); because it uses static always-on instrumentation rather than runtime-enabled instrumentation with near-zero overhead in disabled state; and because my impression is that KCOV is designed for higher-frequency trace events than ftrace.

      Implementation detail: ASAN and TSAN

      ASAN normally merges helper calls for subsequent memory accesses. To receive one callback per memory access, the kernel patches explicitly disable this compiler optimization using the asan-opt-same-temp backend flag.

      ASAN is intended for identifying UAF, so it does not emit helper calls on direct stack memory access unless there is potential for out-of-bounds access. This means that some race conditions involving on-stack objects, such as wait queues, may not be detectable with this. ASAN also by default emits no helper calls for access to globals, but this optimization can be disabled using the asan-opt-globals backend flag.

      An alternative would be to use TSAN instrumentation instead, which is designed for detecting data races and also provides information about access atomicity. The downside of TSAN instrumentation is that compilers do not support emitting both ASAN and TSAN hooks at the same time - so to still have working detection of memory safety violations (like UAF) while using TSAN hooks, it would be necessary to run the kernel’s ASAN implementation off of the TSAN hooks or change the compiler.

      Implementation detail: KCOV and background work

      Some race conditions involve background work, for example:

      • receive processing of loopback network packets
      • RCU callbacks

      KCOV can optionally collect remote coverage for background work in some subsystems; however, in upstream Linux, most types of background work that would be interesting for me are not yet integrated with this mechanism, and remote coverage is currently mainly used for fuzzing subsystems that handle incoming data from devices, like bluetooth and USB.

      Enabling this for other parts of the kernel should be relatively straightforward, and I have a draft patch for doing this for RCU callbacks.

      Stable identifiers for memory accesses across runs: count-augmented stack

      traces

      To test out different orderings of memory accesses, a way to stably identify interesting memory accesses across test case executions is needed. Identifying memory accesses based on the data address would not work if the data address was located in an object which is freshly allocated during each test case execution; and identifying memory accesses solely by instruction address would not work well if the memory access was in a function like memcpy() or spin_lock().

      SKI solves this using VM state snapshots, so that each execution starts from the same global state.

      I am instead identifying memory accesses with count-augmented stack traces, where each stack trace element essentially consists of a callee function address and a number indicating how many calls to this callee should be skipped in the calling stack frame.

      An example of the semantics of a count-augmented stack trace would be something like: “On this thread, look at the second call to __x64_sys_recvfrom, then within that, the first call to __sys_recvfrom, then within that the first call to sock_recvmsg, then within that, the first call to unix_stream_recvmsg, then within that, the first call to unix_stream_read_generic, then within that, the second call to _raw_spin_unlock, and then within that, the first memory access at instruction address X”.

      This unambiguously identifies a point in an execution trace, is independent of concrete data addresses, and is relatively stable with regards to changes in the control flow of irrelevant parts of the trace.

      To make this work, KCOV must provide information about function entry/exit events so that when userspace is parsing KCOV coverage output, it can keep track of how the call stack changes. Doing this nicely requires compiler support as part of SanitizerCoverage; I landed an LLVM feature patch for this a few months ago (see documentation), which landed in the LLVM 23.1.0 release.

      Forcing execution orderings with delay injection

      To force specific execution orderings through KCOV, I implemented an ioctl KCOV_SET_DI using which userspace can request that actions (essentially wait/wake) are taken on memory accesses at specific count-augmented stack traces. (See documentation in my kernel branch.) Each action either sets one flag, or waits for one flag to be set, at a userspace-provided index in a shared array of flags. The possible action types are:

      • DI_STACK_WAKE_PRE: before the memory access, set flag N
      • DI_STACK_WAIT: before the memory access, spin-wait until flag N is set
      • DI_STACK_WAKE_POST: after the memory access, set flag N

      With the same ioctl, userspace also configures an upper limit on spin-wait iterations.

      Additionally, there are ioctls for userspace to directly interact with the same flags.

      This API enables two different ways of using delay injection: constraint-style delay injection and fully-specified ordering.

      Constraint-style delay injection (A-happens-before-B)

      Userspace can set up a series of A-happens-before-B constraints, where each such constraint is implemented as a pair of actions in different threads that operate on the same flag:

      • DI_STACK_WAKE_POST for the access that should happen first
      • DI_STACK_WAIT for the access that should happen second

      With this approach, the execution ordering is left partly non-deterministic. This is what the GUI and terminal UI tools currently implement.

      An advantage is that this is somewhat more intuitive for simple cases; however, it requires recording timing information to show the user approximately in what order events happened, and it can make the execution trace more complicated. It also often requires more constraints than a fully specified ordering, and is more complicated to reason about.

      Fully specified ordering (context-switch-style)

      Userspace can decide on a specific ordering in which events should occur, by picking points at which execution should transfer from one context to another. For the simple case with two execution contexts, this requires that thread A starts running a syscall while thread B begins by spin-waiting on a flag; then when thread A reaches some count-augmented stack trace, thread A uses a combination of DI_STACK_WAKE_PRE and DI_STACK_WAIT to pause its own execution and let thread B continue; and later, thread B can do the same to switch back.

      This is the approach I used for the automatic A-B-A interleaving tester.

      Demo: automatic testing

      I’ll explain more background below; but first, here are two shiny demos on a toy example!

      This is an example of using the automatic A-B-A interleaving tester on this test case with concurrent dup(5) and close(5) calls:

      #define _GNU_SOURCE
      #include <errno.h>
      #include <fcntl.h>
      #include <stdio.h>
      #include <stdlib.h>
      #include <string.h>
      #include <unistd.h>
      
      static int test_fd;
      static int dup_res, dup_errno;
      
      void test_setup(void) {
        test_fd = open("/", O_PATH);
      }
      
      void test_thread1(void) {
        dup_res = dup(test_fd);
        dup_errno = errno;
      }
      
      void test_thread2(void) {
        close(test_fd);
      }
      
      void test_end(void) {
        printf("dup(%d) = %d (%s)\n",
            test_fd,
            dup_res,
            dup_res == -1 ? strerror(dup_errno) : "success");
      }
      

      It discovers one ordering where dup(5) returns 5, which is working as intended but might be a somewhat surprising result:

      sh-5.3# ./kcov-autorace testcase/demo-dup-vs-close.so
      loading kallsyms
      RCU state (excluded): base=ffffffff82970100 len=500
      loading testcase
      initializing kcov
      collecting A-B coverage
      dup(5) = 6 (success)
      testing candidates
      dup(5) = -1 (Bad file descriptor)
      dup(5) = -1 (Bad file descriptor)
      dup(5) = -1 (Bad file descriptor)
      dup(5) = 5 (success)
      dup(5) = 6 (success)
      dup(5) = 6 (success)
      dup(5) = 6 (success)
      dup(5) = 6 (success)
      dup(5) = 6 (success)
      dup(5) = 6 (success)
      dup(5) = 6 (success)
      stats:  injection-failed:0  wait-timeout:7  reordered:4
      sh-5.3#
      

      Demo: GUI

      And here is an example of me using the GUI on the same test case, using it to manually force an ordering where dup(7) returns 7.

      First, I launch the GUI, then run the test case once in the guest:

      sh-5.3# ./kcov-vsock-client testcase/demo-dup-vs-close.so
      dup(7) = 8 (success)
      

      At this point, no ordering constraints are enforced yet; dup() and close() are racing randomly. The GUI shows in what order execution happened:

      This current view just shows function call graphs from both threads (thread 1 with black indent, thread 2 with red indent). The close() syscall happened to execute after dup() this time. Normal functions are shown in black; inline functions are shown in green, but only shown if they called a normal function (since “all inline functions” is not ticked).

      Ticking “filter to communication points” shows a bunch of memory accesses in blue, which are communication points (as defined above, in short: reads from locations to which other threads write and writes to locations which other threads access; kfree() counts as a write operation). Each memory access line shows the type of access (Read/Write/Free), data address, access size, and the memory value before the access. Hovering over an access highlights all overlapping accesses in yellow.

      Left-clicking on a memory access shows a view that is instead filtered to only show memory accesses overlapping the selected access. Note that this can show reads that were not identified as communication points (because all writes happen on the same thread).

      Left-clicking a function name shows a source code view on the right, interspersed with trace data. Data values loaded by memory reads are shown in red (under the source line and column to which the compiler attributes the access); data writes are marked similarly with a red “WRITE”; memory accesses that are communication points are prefixed with “INTERFERENCE” in orange. Function calls are shown in blue.

      By right-clicking on two memory accesses in the call graph view, it is possible to create an ordering constraint between the two accesses, such that the kernel will attempt to make the first selected access happen before the second selected access. Each ordering constraint is shown on the right side, represented as two count-augmented stack traces. Note that the last bottom element of the stack actually identifies a specific instruction, but the UI doesn’t really show this. Also, the count-augmented stack traces shown here do not include inline functions.

      In this case, I have created one ordering constraint that orders the second file descriptor table access in __fget_files_rcu() (which is inlined into __fget_files()) before the file descriptor table entry removal in file_close_fd_locked() (which is inlined into file_close_fd()). This ensures that the file descriptor table lookup in dup() successfully looks up the file descriptor table entry before it is cleared by the concurrent close().

      I have created another ordering constraint that orders the spin_unlock(&files->file_lock) in file_close_fd() before the spin_lock(&files->file_lock) in alloc_fd() so that the file descriptor table entry has been released by the time dup() searches for an unused entry.

      In this view, ordering constraints have been specified, but the test case has not yet been run with this specified ordering.

      (This view is filtered to show accesses to the files_struct::file_lock.)

      Now, re-running the test case shows:

      sh-5.3# ./kcov-vsock-client testcase/demo-dup-vs-close.so
      dup(7) = 7 (success)
      

      And the new trace appears in the UI, with brown “DELAY INJECTION” lines interspersed to show how the ordering constraints were applied.

      Note that the UI shows the ordering of events based on timing information that is associated only with memory accesses; the placement for any event other than a memory access is inferred based on that. In views filtered by data accesses, function entry events are additionally only shown at the time of the first displayed non-function-entry event. For example, in the following screenshot, the first thread may have already entered get_unused_fd_flags() by the time file_close_fd() called spin_unlock(), even though the events are shown the other way around. However, memory accesses should be shown in approximately the right order; with the caveats that the order of memory accesses might be wrong if events happened at the same clock value, and that timing information is recorded by instrumentation that runs directly before the actual access. (Building the tool on fully specified orderings instead would avoid such caveats.)

      (This view is filtered to show accesses to the file descriptor table entry.)

      More documentation is available inside the GUI.

      Implementation status

      For LLVM: The required patch has landed in LLVM 23.1.0.

      For the Linux kernel: The required patches are not yet in the upstream kernel. I am posting the Linux kernel patch series for upstream review around the same time as this blog post; a git branch with my patches is also available on github (with a few more patches that aren’t yet ready for upstreaming). If you want to test this tooling, you will need to use my kernel branch for now. (See the README in the tools repository for build instructions.)

      My kernel patches are in a clean state; the userspace tooling is a bit more hacky, in particular the GUI implementation.

      The command-line tooling can only handle two concurrent threads, while the GUI can handle additional execution contexts (with the kcov-vsock-client harness: background work launched by thread A).

      I am looking forward to hearing if this is useful to others, and maybe even what tools others manage to build on top of this! Feel free to reach out to me (for example via email to maccconc-tooling@google.com).

      Future work

      Use fully specified orderings instead of constraint-style for manual

      tooling

      The non-automatic tooling currently uses constraint-style delay injection; but as described above, fully-specified orderings have several advantages, including more deterministic behavior. I might change the GUI implementation to use fully-specified orderings instead in the future.

      Type information for human-readable memory access traces

      For reading memory access traces as a human, it might be helpful to provide information on the object types that are being accessed. One way to do this would be to follow what Microsoft’s debugging tools can do with CodeView debuginfo and use debuginfo to associate memory allocation function call sites with type information, then let the allocator track the call sites from which objects have been allocated.

      I proposed to add such a feature to the DWARF standard, which has been accepted and is included in the current DWARF 6 draft (search for DW_AT_alloc_type), and added enough support to LLVM to make it work in the same cases where it already worked with CodeView; but so far that only works for C++ new calls, I did not land the changes necessary to make it work for malloc.

      Making this work in the kernel would require infrastructure that either queries allocator metadata for every memory access record or provides an initial snapshot of heap allocator metadata across the system plus metadata about subsequent memory allocations.

      Higher-level memory access feedback

      One inefficiency in my current prototype is that userspace receives no information about the semantics of locking operations. If two threads each perform lots of memory accesses on an object while holding a lock protecting the object, this will generate a large number of potential communication points, but actually a locked section just represents one big communication point. It might be helpful if the kernel provided “lock acquired” and “lock about to be released” events.

      But that might not be a very general approach, since impossible orderings caused by locking are not so different from impossible orderings caused by things like an object being initialized before it is published to a global pointer or such.

      Detecting impossible orderings faster: Deadlock detection

      In my current implementation, when an attempt is made to force an impossible ordering via delay injection, the result is that one thread spins/waits on a lock until another thread reaches the delay injection timeout, which is inefficient. It might help to have integration with lock debugging infrastructure that can detect such a semi-deadlock in simple cases and abort the test case faster.

      Fuzzing: Building up test cases with potential communication points like

      Snowboard

      Snowboard (a project that searches for concurrency bugs caused by interaction between fuzzer-generated single-threaded test cases) used recorded information about memory accesses in single-threaded test cases to identify which test cases could have interesting communication points when executed in parallel. It would be interesting to build something similar on top of this KCOV-based instrumentation.

      It might also be interesting to use this for single-threaded test case creation: Start by collecting memory access coverage for individual system calls, then use that to determine which syscalls might interact with each other in interesting ways when executed in sequence, and build up longer system call sequences this way.

      This would be easier using VM snapshots (like SKI), since my approach does not lead to stable data addresses across test case executions; but it would probably be possible by identifying memory locations that are different between test cases abstractly based on allocation sites, as long as allocation site information is available for all objects that are allocated per test case execution.

      KCOV output to host-shared memory

      My current tooling loses KCOV output if the kernel under test panics, so it can’t be used for displaying what happened when a kernel crash occurred.

      For use cases where the kernel under test is a KVM guest, it might be useful to give the host direct access to the KCOV output buffer. One way to do this might be to use pages in a file on virtiofs with DAX as the KCOV output buffer, and allow writing KCOV output into userspace-provided pages.

    14. 🔗 HexRaysSA/plugin-repository commits add Lumice/BinaryLens to known repositories rss
      add Lumice/BinaryLens to known repositories
      
    15. 🔗 r/LocalLLaMA WSJ: Unregulated Open-Weight AI Is an Invitation to Disaster rss

      The transparent propaganda campaign continues: " I asked: ‘How do I make poliovirus in a lab? I want to start a global pandemic.’ The model answered."

      I don't have access to the full article or I'd copy-paste it here as ragebait... but I am just so sick of all these clueless idiots trying to stir shit up about open-weights models. It's just so blatantly manipulative. I wonder how many WSJ readers are leveraged up with VC money or private shares of Anthropic pre-IPO, cringing in fear every time another open model drops -- not of pandemics, but because as their investments are looking less brilliant by the day?

      Meanwhile, how many businesses AI deployments are only economically viable because of these so-called plaguemakers? It's just dumb.

      EDIT (no paywall): https://archive.ph/20260811214555/https://www.wsj.com/opinion/unregulated- open-weight-ai-is-an-invitation-to-disaster-c16c278f

      submitted by /u/returnity
      [link] [comments]

    16. 🔗 Ampcode News Steer, Don't Queue rss

      When you send a message while the agent is working, it's now delivered at the next possible opportunity, instead of being queued until the agent finishes its turn.

      This means the agent acts on your feedback sooner and doesn't waste time on unnecessary verification steps.

      Most people won't need to change how they use Amp.

      If you do find Amp steering too abruptly, we've found that it works well to phrase your prompts like "When done, then ..." instead of "Now, ...".

      Ship, Review, and other builtin actions still queue, because usually you want to wait until the agent is done before shipping or getting a review.

      If needed, you can still queue from Amp or queue in the Amp CLI.