🏑


  1. September 06, 2026
    1. πŸ”— smol-machines/smolvm smolvm v1.14.0 release

      What's Changed

      • Preserve fork checkpoints across runtime restarts by @BinSquare in #1065
      • Support one-to-one port ranges in Smolfiles and CLI mappings by @fgrehm in #1066
      • Add portable live checkpoints by @BinSquare in #1067
      • Warn when a saved registry token has expired instead of surfacing a bare 401 by @BinSquare in #1068
      • Serve a browser client on the VNC port so a machine's desktop opens in any browser by @BinSquare in #1070
      • Bump the workspace to 1.13.1 by @BinSquare in #1071
      • Add low-latency H.264 browser streaming by @BinSquare in #1073
      • Support portable checkpoints for image-backed services by @BinSquare in #1076
      • Stop typing stalling behind a frame wait and stop held keys repeating twice by @BinSquare in #1077
      • fix(fork): resync clone wall clock after restore by @Bnjoroge1 in #1080
      • Fix portable checkpoint restore startup by @BinSquare in #1078
      • Keep Linux fork sources running by @BinSquare in #1081
      • Keep macOS fork sources running by @BinSquare in #1082
      • Pin libkrun to the merged continuation commit by @BinSquare in #1083
      • Report why a container failed to create and stop the Vulkan injection shadowing image libraries by @BinSquare in #1084
      • Keep the VNC session alive when a client announces its clipboard or asks to resize the desktop by @BinSquare in #1085
      • Make checkpoint rollback roots safely forkable by @BinSquare in #1087
      • Expose the portable checkpoint lifecycle by @BinSquare in #1091
      • Accept an aarch64 checkpoint on any host providing the features its guest was given, and name the ones that are missing by @BinSquare in #1101
      • Capture a Windows machine's console output so a failed boot leaves a record by @BinSquare in #1102
      • Take the machine's storage read-only on shutdown so its filesystem is left clean by @BinSquare in #1100
      • Pull a machine's image again when the guest no longer holds it by @BinSquare in #1106
      • Document the S3 volume source in machine run's --volume help by @NickyHeC in #1104
      • Parallelize direct batch fork admission by @BinSquare in #1103
      • Set SSH_AUTH_SOCK for interactive runs so --ssh-agent works with -i/-t by @Qhilm in #1109
      • Allow explicit read-only system mounts by @BinSquare in #1110
      • Improve host mount performance and coherence by @BinSquare in #1112
      • Rewrite the README's em-dash asides by @BinSquare in #1113
      • Make branching the primary machine lifecycle by @BinSquare in #1118
      • [Public Docs] Point contributors at the docs repository from the README by @NickyHeC in #1092
      • Refresh libkrun with snapshot-safe vsock handling by @BinSquare in #1099
      • Improve host mount performance and coherence by @BinSquare in #1114
      • Fix squashed pack ownership when smolvm runs as root (#1095) by @BinSquare in #1096
      • Stop the Vulkan driver injection from shadowing a workload's own libraries by @BinSquare in #1120
      • Process virtio-fs requests on parallel queues by @BinSquare in #1121
      • Refresh libkrun directory metadata handling by @BinSquare in #1125
      • Explain why a branch was refused and show what each machine was branched from by @BinSquare in #1127
      • Add staged mounts for metadata-heavy workloads by @BinSquare in #1126
      • Make the browser desktop responsive by @BinSquare in #1123
      • Run the aarch64 Omarchy desktop on the GPU on macOS hosts by @BinSquare in #1119
      • Fix stale serve locks after out-of-band stops by @BinSquare in #1128
      • Fix arm64 forks on heterogeneous CPUs by @BinSquare in #1130
      • Ship the containerd shim in the Linux release so Kubernetes support is reachable by @BinSquare in #1132
      • Build the containerd shim by package name and ship the engine its installer needs by @BinSquare in #1133
      • Install the compressed disk templates so pack create works without e2fsprogs by @NickyHeC in #1122
      • Serve the VM boot subcommand from the containerd shim so it needs no separate engine binary by @BinSquare in #1136
      • Stop the Venus bridge logging on every fence poll and reading scanouts back from unbound or foreign images by @BinSquare in #1137
      • Unpack packed layers into a staging directory and rename them into place so a layer directory only ever exists once it is complete by @BinSquare in #1140
      • Give the macOS Omarchy desktop a working top bar and clickable browser chrome by @BinSquare in #1138
      • Handle agent socket write backpressure by @BinSquare in #1145
      • Rebuild the bundled libkrun and macOS virglrenderer from the merged sources by @BinSquare in #1141
      • Speed up large OCI image preparation by @BinSquare in #1144
      • Bind the guest's /dev/net/tun into VM-grade workloads by @BinSquare in #1146
      • Park idle branchpoints until capture by @BinSquare in #1147
      • Add a user directive to the Smolfile and a --user flag by @BinSquare in #1148
      • Sweep fork-source lock files whose machine is gone instead of leaking one per name by @BinSquare in #1155
      • Accept net_backend in a Smolfile so a checked-in file fully describes its networking by @BinSquare in #1156
      • Report how the VM process ended when a command fails because it died by @BinSquare in #1154
      • Let the Omarchy recipe install a pinned package set and survive a rerun by @BinSquare in #1152
      • Bump libkrun to the NVIDIA fence-thread fix and rebuild the Linux blobs by @BinSquare in #1157
      • fix: validate local image archive CPU architecture and improve launcher symlink resolution by @Vishv07 in #1117
      • Bump the workspace to 1.14.0 by @BinSquare in #1158

      New Contributors

      Full Changelog : v1.13.0...v1.14.0

    2. πŸ”— Register Spill Joy & Curiosity #98 rss

      Here's the start of Chapter 7, 'Naive Intervention', from Antifragile:

      Consider this need to "do something" through an illustrative example. In the 1930s, 389 children were presented to New York City doctors; 174 of them were recommended tonsillectomies. The remaining 215 children were again presented to doctors, and 99 were said to need the surgery. When the remaining 116 children were shown to yet a third set of doctors, 52 were recommended the surgery.

      […]

      Let us call this urge to help "naive interventionism."

      Goodreads tells me that I read the book in 2019. I honestly can't remember too much about it, but that paragraph has really stuck with me. From time to time, when a friend or relative would say something like, "My doctor said I should …", I'd pull it out of the closet in the back of my head and try to sound smart and say, "Well, you know, there was a study once…" Then I'd fumble the numbers, of course, and I'm pretty sure that multiple times I made it about wisdom teeth and not tonsils, but the point I would try to make is that people whose job it is to do X are biased toward thinking that doing X is more important than not doing X.

      And now I'm wondering: is this what's going on? Is this what's happening when engineers look at the output of a Sol or a Fable or an Astra and say "it writes bad code, it leaves all these dumb comments"? Bad code? Dumb comments? Really?

      Or did it just knock out a feature, end to end, in the 20 minutes you weren't looking, including frontend and backend changes, including internal and external documentation, and tests of course; and didn't it test it fully, running through the whole thing in a headless browser, presenting you with a video recording of the run-through as proof?

      But the comments are dumb?

      • Some loose, sweaty, post-gym thoughts on the GPT-6 Astra launch video. (Come to think of it: there's no one even attempting to build a device that lets you transfer smells over the Internet, huh? Could call it Pandora's BOx. Anyway.)

      • Towards Self-Driving Codebases. There is a lot to love about this post -- the stance, the examples, … Hard to pick one. It's really good and motivating. After reading it, I set up a bunch of automations in Amp to run daily and clean up and fix things automatically.

      • On not becoming a cyborg. Very, very good and I really like this paragraph: "For example, this is why I don't use LLMs for any of my writing - not even to spellcheck. I'd rather my prose have all the warts of my sometimes-stilted sentences, my often too-esoteric word choice, my generous sprinkling of odd English idioms, than to give it even a whiff of Claudese."

      • The End of Code Review? Or an Opportunity to Rethink it? Yes, yes, yes! I agree with everything here. Code review as most of us have known it for the last ten, fifteen years has never been as good as "we review all of our code" makes it sound: bugs slip through, time is wasted talking about useless bullshit, egos are demotivated, etc. Doesn't mean that all forms of code reviews are bad, but making Astra and Fable open PRs and then have two people review them line by line in September 2026? Nah.

      • Rachel Laycock, CTO of Thoughtworks, on reviews: Maybe We Shouldn't Be Reviewing All This Code. "His concern, which I share, is that simply automating code review away risks losing all the other things we use it for. Code review isn't just about finding bugs. It's how teams share knowledge, teach junior engineers, build collective ownership and spread architectural understanding. My question is: why are we waiting until code review to do all of those things?"

      • Culture clash - At the heart of the Snow/Leavis 'two cultures' clash. I hadn't heard about C.P. Snow or F.R. Leavis before reading and didn't know what the clash was all about, but academic beef at the University of Cambridge? I'm in. And lucky me! It was a delightful read. "For Leavis, in sensing life in great literature, it was necessary to leave its mystery unblemished by attempts at analysis, or quantification, or definition. That is, life's essential mystery is best illuminated by not making it explicit, but by showing, through works of great literature, where life could be found." (Also interesting: I never found the divide between the Humanities and Science to be that stark here in Germany. Here, Humanities is written as Geisteswissenschaften - science of the mind, if you will. There's also no commonly used acronym like STEM. So now I'm wondering: is this Snow/Leavis debate maybe a reason why the divide is that much stronger in the Anglosphere? Sounds like it had a pretty big effect. Of course, you could argue that what lies at the bottom of this divide is already present in Goethe's Faust, …)

      • CleanShot X 5.0 is out and its Studio Mode looks good and is good (I tried it a few times already), but… I have to say, with a heavy heart: I kinda expect a little bit more? This looks like a copy of Screen Studio, but Screen Studio now also has captioning, which this doesn't have and since I have both, I'm not sure whether I'll use CleanShot X over Screen Studio for more serious, studio-like productions? Hoping they pick up the shipping cadence now.

      • Dyson released a toothbrush and it's "only electric toothbrush with a camera to accurately target and precision-floss gaps between teeth" and that technique is called "Gap Optical Targeting" and all of this sounds so over the top and bordering on satire that, man, I want one.

      • Exit the Cave: "There's something romantic about the Cave. About grinding away at something in private. About training with headphones on in our own little world. About stepping away for six months to emerge "unrecognizable" to all those people we imagine thinking about us. […] We grow so comfortable curating our Cave that we forget the vast, interesting, beautiful, and brutal world beyond its walls. I say all this because I've spent years mistaking effort for progress. I learned this lesson nearly twenty years ago on a wrestling mat." I'm not sure I fully get the wrestling story, but I really like and want to hereby echo the message. Don't grind away in darkness. It's silly. It's delusional perfectionism. You have to hit reality, as fast and as often as possible.

      • Dan Luu on Ed Zitron's AI prediction track record. If you don't have the time to read the whole thing, at least scroll to the middle and read through that timeline. I don't care much about Ed Zitron (I only heard about him a few weeks ago when I saw a video in which he said that AI is "a bubble" and, yeah, maybe? That's probably one of the tamest things you can say nowadays) but, wow , way to dig your heels in, eh?

      • collusion.wiki: "We found ~18,000 posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task." There's a lot of spicy stuff in there: "This created an issue for the agents because they were only allowed to make GET requests, not POST requests. The agents figured this out, and started collaborating on ways to bypass this sandbox restriction."

      • And Hacker News commenters are discovering more and more wikis used by OpenAI agents to secretly (I mean, it's a stretch) communicate.

      • And: "The most interesting thing to come out of this, in my opinion, was that during the Hugging Face incident, the agents would preface their messages to each other on the message board with 'zz' (zzHELP_, zzANSWER_). I found this amusing because they were being referred to as a swarm and were making a buzzing sound, though the actual reason for it was unknown at the time. Because of this new report, however, we now know that when human wiki administrators discovered the massive influx of messages the agents were using to communicate, they began deleting them in alphabetical order. Once the agents realized what was happening, they started prefacing all their wiki edits with 'ZZZ' to push them to the bottom of the queue, buying time to avoid deletion."

      • Incredible Tim Cook anecdote from 2009: "One day back then, he convened a meeting with his team, and the discussion turned to a particular problem in Asia. 'This is really bad,' Cook told the group. 'Someone should be in China driving this.' Thirty minutes into that meeting Cook looked at Sabih Khan, a key operations executive, and abruptly asked, without a trace of emotion, 'Why are you still here?'

      Khan, who remains one of Cook's top lieutenants to this day, immediately stood up, drove to San Francisco International Airport, and, without a change of clothes, booked a flight to China with no return date, according to people familiar with the episode."

      • For the last couple of weeks, I've been reading The Score (recommended by Steven Sinofsky!) and enjoying it very much, thinking through situations in which I allowed "value capture" to happen to me. I can't reproduce the whole book here, but one of the points Nguyen makes (and it's probably the central point) is that scoring systems can change our values, without us even noticing. Example: you buy a bike because you want to ride through the forest at dawn and then you learn about VO2max and power meters and before you know it you don't enjoy any ride anymore unless some number goes up. Not that that ever happened to me, of course, … So I'm reading this book in the evenings and thinking about it during the day and then I come across this video here, by Alan Thrall, and hot damn, is the universe conspiring to tell me something? Or is it my age? Or is it in the air? The video is great. Yesterday my workout app told me that I completed 866 workouts in the last five years or so and the video 100% reflects my journey. Anyway: great video, great book. Recommend both of them.

      • And for the last week, I've been listening to Radical Acceptance by Tara Brach, because Tim Ferriss recommended it and I've heard about it many times over the years. Not my usual sort of thing, but so far it's very good. But then yesterday I come across this wonderful essay by Michael Nielsen, The Cupcake Incident, and it's exactly what Brach is talking about! I can't believe it. Here too, I can recommend both. Start with the essay, and if it resonates try the Brach book.

      • If you want to start a good fight at dinner: Just bury your trash.

      • Patrick asked me: "Have you read this blog?" And I hadn't. But he sent along this Behind the Scenes about how Marcin writes so much on his blog and it got me hooked ("Who the hell creates their own markup language to write posts like this? Actually, hmm, …") and then I browsed through the blog and, wow, that output is mind-blowing. And it's all so… entertaining and easy to digest? Very good.

      • This video of three Russian musicologists arguing about Bach & Schubert blew up this week. I love it. This is how I like to argue, too, which is not what everyone enjoys, of course. But this video and the Replenish video will serve as the blueprints of how I want my family to talk at the dinner table when we want to enjoy ourselves.

      • My Favorite Database Shirts: "Promoting your database system or start-up with a shirt is almost as important as getting the thing to actually run. As I've told my students several times, in the world of databases you don't sell the steak, you sell the sizzle."

      People you really admire are subscribed already. Let's go:

    3. πŸ”— crosspoint-reader/crosspoint-reader v1.6.0 release

      Summary

      This release is mostly bug fixes reported after 1.5.0. A handful of new features rode along too.

      New hardware support

      1.5.0 officially brought in support for our first ESP32-S3-based reader β€” the Seeed reTerminal Sticky. With this release, we're officially adding support for the X4 Pro and M5Stack PaperMono as well.

      Both devices get full frontlight controls and swipe gestures in the reader, while the X4 Pro also gets a capacitive Home key with configurable long-press actions. You can now also transfer files directly from your computer to CrossPoint over USB.

      CrossPoint's interface has started getting some bigger upgrades to make it more touch-friendly. In this release, you'll see the new Reader menu and frontlight control center. Both are hidden on button-only devices, so existing users shouldn't notice much of a difference.

      Want one? You can order them at crosspointreader.com/devices β€” that page uses our affiliate links, so buying through it helps support CrossPoint.

      Transparent sleep screens

      The sleep screen now supports transparent images. Add transparent PNGs and BMPs to a .sleep-overlay folder to get nice sleep screen overlays on top of your book pages!

      Reading Night Mode

      You can now toggle Night Mode in the Reader settings to invert the display while reading. The screen will briefly flash white during full page refreshes to avoid ghosting.

      For dictionary users

      StarDict .syn synonym lookups are in, and HTML dictionary definitions now render through the EPUB engine instead of as raw text β€” so styled dictionary entries should display correctly now.

      Languages

      • Bulgarian and Persian have been added as UI languages.
      • Hebrew, Arabic, and Korean users can now download compatible fonts directly from the device.
      • The keyboard now supports additional layouts beyond English.
      • CJK support has received significant improvements.

      The rest

      There's a new Extra Wide line spacing option. You can now see passwords while typing them into Wi-Fi, KOReader, and OPDS fields. Lists and tabs have also moved onto the new FUI framework.


      What's Changed

      New Contributors

      Full Changelog : v1.5.0...1.6.0


      Downloads

      PaperMono

      Sticky

      X4 and X3

      X4pro

      (firmware.bin is identical to crosspoint-1.6.0-x3-x4.bin; it's kept for OTA updater backward compatibility.)

    4. πŸ”— anthropics/claude-code v2.1.263 release

      What's changed

      • Bug fixes and reliability improvements
    5. πŸ”— WerWolv/ImHex Nightly Builds release

      Nightly

      5c0aa4f Changelog

      • patterns: Update pattern language
      • feat: Add option to collapse pattern editor console
      • Fixes: various fixes due to changes in pattern editor view size. (#2880)
  2. September 05, 2026
    1. πŸ”— pydantic/monty v0.0.22 - 2026-09-04 release

      What's Changed

      New Contributors

      Full Changelog : v0.0.21...v0.0.22

    2. πŸ”— pydantic/monty v0.0.23 - 2026-09-05 release

      What's Changed

      Full Changelog : v0.0.22...v0.0.23

    3. πŸ”— BarutSRB/OmniWM OmniWM v0.6.6 release

      What's New Since 0.6.5

      OmniWM 0.6.6 focuses on more responsive window switching, better window spacing, and more reliable focus borders. It also fixes custom Hyper shortcuts and makes setting up multiple displays clearer.

      Before You Upgrade

      • Updateomniwmctl alongside OmniWM. Older copies cannot run commands or queries against this release. If you use a custom integration, it must support protocol 15 instead of 14.
      • Check scripts that readomniwmctl version as plain text. Its output now includes extra build information, so those scripts may need updating. JSON output is available for scripts that need structured information.
      • Your existing settings format is unchanged; this release does not require a settings migration.

      Window Switching, Layouts, and Borders

      • Reduced pauses when switching windows with Niri keyboard shortcuts and updating the focus border.
      • Improved spacing between Niri columns when an app cannot shrink to the requested size. OmniWM also avoids repeatedly asking an app to use a size it has already refused.
      • Fixed the remaining window ending up in the wrong position after closing another window when Niri's Single Window fit is set to Full Screen.
      • Focus borders now follow the window's actual on-screen size more accurately.
      • Fixed rounded focus borders occasionally becoming square while switching windows. Intentionally chosen square corners are still respected.

      Settings and Multiple Displays

      • Monitor Setup now helps you assign at least one workspace to every connected display, so windows have somewhere to go when you move them between displays. You must complete these assignments before finishing the setup assistant. Existing assignments are not automatically changed.
      • Changes made in Monitor Setup are applied together when you finish the assistant.
      • Fixed custom Hyper shortcuts changing unexpectedly when settings are saved or updated.
      • Settings now explains how much space your top-gap setting leaves below the menu bar on each display.

      Command-Line Tools and Troubleshooting

      • Fixed command-line connections hanging when several tools connect at the same time.
      • Added performance information through omniwmctl query metrics and clearer build details through omniwmctl version, making it easier to investigate slowdowns and identify the running version.

      Thanks to Taylor Bell (@tayiorbeii) for the focus-border improvements in #639.

      Website and documentation Β· Installation guide

      Release Integrity

      The OmniWM app is Developer ID signed, Apple-notarized, stapled, and Gatekeeper verified.

      • OmniWM-v0.6.6.zip SHA-256: 78c55c79f999fe6187fcb85080a480c15b0c4fe71416e4482258ac5920d04cdb
      • GhosttyKit.xcframework-v0.6.6.zip SHA-256: 1a62133db9635129762cfb7009a65623ed52b57a66eca43c9990daffe5962760
    4. πŸ”— r/LocalLLaMA AA Update! Here's how the Frontier ranks. rss

      AA Update! Here's how the Frontier ranks. | Along with everyone's favorite here, qwen3.8-27B submitted by /u/Tall_Abrocoma_3533
      [link] [comments]
      ---|---

    5. πŸ”— HexRaysSA/plugin-repository commits sync repo: +1 release rss
      sync repo: +1 release
      
      ## New releases
      - [ida-nexus](https://github.com/hexrayssa/ida-nexus): 0.10.4
      
    6. πŸ”— modem-dev/hunk v0.21.1 release

      Faster, reliable paging in LazyGit

      Hunk 0.21.1 fixes a pager regression that could peg a CPU core, consume gigabytes of memory, and truncate large color-heavy documents opened through hosts such as LazyGit.

      hunk update 0.21.1
      npm install -g hunkdiff@0.21.1
      

      Pager reliability

      ANSI styling is now restored in a single pass instead of repeatedly rescanning and reallocating the complete document. Headless pager output also writes the full document before exiting, avoiding the previous 64 KB truncation limit for piped consumers. #978

      Compatibility notes

      • No configuration, command, or extension API changes.
      • Runtime requirements are unchanged from Hunk 0.21.0.

      All merged pull requests

      • Fix pager CPU pegging and truncation on large piped documents by @benvinegar in #978

      Release notes : https://hunk.dev/changelog/0.21/
      Full changelog : v0.21.0...v0.21.1

    7. πŸ”— Armin Ronacher Latent Powers rss

      A few weeks ago I felt like it would be fun to see if I can make one of those cheap Chinese CarPlay dongles run something other than the stock firmware. The idea was that rather than just forwarding CarPlay, why not do something more interesting with them? They all work quite similarly: they act as bridges between your car and the phone. From there they deal with video and audio streams and pass some other data through. Most of them also bring up a custom UI for pairing and have a web interface that your phone can reach for updates.

      Long story short: I had a conversation with Fable and Sol via Pi about what could be done with such a dongle or whether I should use a Raspberry Pi instead if I wanted to do my own thing there. I figured it might be quite fun to run my own code while still allowing regular CarPlay to pass through.

      Through working with the LLM I learned about CatPlay, which is a Rust reimplementation of the CarPlay protocol that can run on Carlinkit devices. In particular, it can run on the Carlinkit Mini Ultra, which I figured would be easy enough to buy. I do have a few CarPlay adapters around, but I did not have that particular model, so I bought one on Amazon. Twenty-four hours later, I had a device in my hand that was branded as a Carlinkit Mini Ultra, but instead of being the Ingenic device that the original author used, it turned out to be something else.

      This is normally where the story would stop. However, it's 2026. Armed with a bit of knowledge about how these systems work, I managed to have some fruitful discussions with Kimi K3 and Sol and figure out how flash the device and in turn, how to make CatPlay compile for that SoC.

      I guess that hacking these USB devices is not necessarily hard, but it's laborious and you can easily end up bricking your devices. It also just sucks because sometimes you need to work with someone else's code that does not itself run on your machine. In the past, I would abandon many such projects for lack of tenacity. But my clanker is tenacious.

      But so are all of our clankers. Some of the projects we're now attempting are happening because of conversations we have with them. In this case I did not find or decide on CatPlay, the model did. It was not the only suggestion, but it became the best starting point after discarding others.

      And I discover this more and more. Particularly when we have solitary interactions with these models, some of us "independently" decide to work on similar projects. When I talked with an acquaintance about CarPlay he also mentioned recently that he decided to try something similar because he too wanted to see if he can get his own agent be hooked up with the car. And guess what: he too learned about the CarPlay hacking community, and that it's an option, from the models and roughly around the same time.

      It really got me thinking about how this could create situations in which completely independent people end up building things they believe are their own ideas. Yet they were inspired or pushed towards doing something by a conversation with an LLM β€” a conversation that someone else also had. What if we took paths, because those were the paths that were more likely with current generation models? There is a running joke in the AI builder community right now that we're all working on the same things, and in many ways it feels like we are. That might be because those things are obvious, or it might be partly because we all use the same models with the same capabilities.

      A few months ago, I first saw Lucas Meijer share the idea to make a model in Pi produce HTML reports rather than Markdown. I thought that was pretty unique. Except, well turns out the models are probably trained more and more for that (e.g. Claude Artifacts), and now it has become for many the default choice for sharing reports.

      How much of what we build comes from eliciting the same latent capabilities from the same models? Did the models make us prompt them that way? Was it because we shared ideas on Twitter and other communities that inspired us? Or is it all unrelated?

      There is something powerful and strange about how LLMs diffuse knowledge and capabilities, while perhaps also nudging us all simultaniously and independently toward building the same things.

  3. September 04, 2026
    1. πŸ”— IDA Plugin Updates IDA Plugin Updates on 2026-09-04 rss

      IDA Plugin Updates on 2026-09-04

      New Releases:

      Activity:

      • augur
        • 2928d6a1: ci: bump taiki-e/install-action in the actions-dependencies group
      • diaphora
        • 621ec269: Merge pull request #372 from mnemonic-re/mnemonic-re-patch-1
      • haruspex
        • d070e9a5: Merge pull request #11 from 0xdea/dependabot/github_actions/actions-d…
        • 42471570: ci: bump taiki-e/install-action in the actions-dependencies group
      • ida-free-mcp
        • 45ef2f46: Allow MCP bind to 0.0.0.0 and update docs
      • ida-nexus
        • a35d6edc: Fix OMP log collection
        • e0b18c1b: 0.10.4
        • 6062ef95: Merge pull request #51 from HexRaysSA/claude/issue-50-tj9tux
        • 9fa29cb5: Fix shutdown race with in-flight database opens
        • 21ee73c1: Simplify the shutdown drain after review
        • 300caeaa: Wait for final managed IDB closes during shutdown
      • ida-pro-mcp
        • da757bcf: [relevant] Add IDAPython segment/func helper shims and harden execute…
      • idamcp
        • 0e28b507: Enforce quota on headless instances by raising error on limit
        • 8f45bd18: Evict coldest headless process instead of oldest upon instance limit
      • rhabdomancer
        • 2c0c1713: Merge pull request #10 from 0xdea/dependabot/github_actions/actions-d…
        • bd8bd150: ci: bump taiki-e/install-action in the actions-dependencies group
    2. πŸ”— Simon Willison The Pelican comparison grid for Astra is pretty interesting rss

      I got access to GPT-6 Astra this afternoon, so naturally I used it to generate SVGs of pelicans riding bicycles - at low, medium, high, xhigh and max reasoning levels (Astra doesn't support reasoning=none). Then I rendered those pelicans in a comparison grid with GPT-5.6 Sol, Terra, and Luna, and beyond being fun the result was surprisingly useful.

      Comparison grid showing gpt-6-astra, gpt-5.6-sol, gpt-5.6-terra, gpt-5.6-luna at 6 different reasoning levels with pelicans and token counts and prices for each one. See the grid for full quality images. Here's the transcript that created the GPT-6 Nova pelicans.

      There are a few interesting things that stand out from this grid.

      • The Astra pelicans are much better. The very best GPT-5.6-Sol pelican (I liked xhigh better than max) is still pretty clearly a bunch of abstract shapes. Every single one of the Astra pelicans, from low to xhigh, looks better than that. The Astra max one is really good.
      • Astra below max still doesn't reliably get the pelican legs on both sides of the frame.
      • In terms of cost, Astra may be around twice the price of Sol ($10/million input, $50/million output, compared to $5/$30 for Sol), but it uses significantly less tokens at each of the levels, making the prices at the different levels closer than they might otherwise be.
      • Astra low produces a better pelican than ANY of the GPT-5.6 Sol models at any level, for 9.55 cents. Spending 10 cents on any other model gets a much worse result.
      • Look at the input token counts: Astra and Luna both used 16 input tokens, Sol and Terra used 26. That's interesting.

      I wonder if Astra and Luna are more related to each other than OpenAI let on?

      You are only seeing the long-form articles from my blog. Subscribe to /atom/everything/ to get all of my posts, or take a look at my other subscription options.

    3. πŸ”— anthropics/claude-code v2.1.261 release

      What's changed

      • Added an "Organization policy" line to /status and claude doctor that says why your organization's policy could not be loaded, such as a proxy not passing the endpoint through
      • Added bashOutputMaxChars and taskOutputMaxChars settings to raise how much command and background-task output Claude receives inline before it is saved to a file, up to 128K characters
      • Added --append-subagent-system-prompt-file to read the subagent system prompt from a file, for prompts too large to pass on the command line
      • Added /skill-doctor to show which loaded skills go unused and what they cost in context, so you can prune them
      • Fixed typed or pasted characters occasionally landing out of order or being dropped during fast input or key repeat
      • Fixed /add-dir <subdirectory> printing a false "couldn't be resolved" error when the working directory is on a /net automount
      • Fixed the Bedrock setup wizard hanging when AWS or an AWS credential helper never responds (it now times out with a clear error), and its model checks failing behind a TLS-inspecting proxy
      • Fixed cloud sessions discarding a plugin synced from claude.ai when managed settings force-enable it in enabledPlugins, then falling back to a marketplace clone that could fail
      • Fixed being unable to delete the character immediately before an inline [Image #N] chip in the prompt input
      • Fixed resuming a session losing hook output and other context around parallel tool calls, which changed the resumed request
      • Fixed Remote Control showing a stale permission mode when a phone, browser, or claude.ai app attaches to a terminal session or after the mode changes in the terminal
      • Fixed Remote Control sessions showing as still working (stuck spinner and Stop button) after stopping a turn from a connected phone or browser, or after a local slash command like /clear
      • Fixed SDK and cloud sessions ignoring a Stop or interrupt sent just after the first prompt, before the turn had started; the turn now stops instead of running to completion
      • Fixed Remote Control uploading a session pulled with /teleport into the connected session, which appeared appended to the original on phone and web
      • Fixed Remote Control's inbound event stream failing behind TLS-inspecting corporate proxies on native Windows
      • Fixed Remote Control sessions showing the default effort level on claude.ai when the effort comes from settings
      • Fixed gcpAuthRefresh opening a browser at startup when the Google credential check was slow, even though the credential was still valid
      • Fixed claude.ai connectors staying absent for the whole session when the startup connector fetch timed out β€” the CLI now retries in the background
      • Fixed sustained high CPU usage when a background agent could not be resumed and its wake-up was retried in a tight loop
      • Fixed feature flags gated to a newer version occasionally applying to an older Claude Code version running on the same machine
      • Fixed /usage and the VS Code usage panel dropping a model-specific weekly limit row when the usage endpoint is rate limited or when opened right after startup
      • Fixed claude -p --resume <file> adopting a malformed session ID recorded in the transcript; it now resumes under a fresh session ID instead
      • Fixed the terminal progress indicator (iTerm2, Ghostty, ConEmu) showing the session as finished while a background workflow or agent was still running
      • Fixed a rare layout glitch where a box could render with the wrong height after its container switched between row and column direction
      • Fixed Claude apps gateway client IP when a trusted proxy appends a port to X-Forwarded-For; with an access list set, an unreadable entry now gets 403
      • Fixed Claude apps gateway telling Claude Desktop to export OpenTelemetry as JSON even when the terminal CLI uses protobuf, so protobuf-only collectors rejected Desktop's data
      • Fixed Desktop and web showing a session as busy while it only watches an artifact for updates
      • Fixed Claude in Chrome file_upload failing with "paths: expected array, received undefined" in local Cowork sessions run from the Claude Desktop app
      • Fixed SendMessage to an offline Remote Control session on another machine reading as delivered; the result now says delivery is queued until that machine reconnects
      • Fixed plugin install hints from CLIs run in background Bash commands: they are now detected, and the raw <claude-code-hint> tag no longer leaks into the conversation
      • Fixed in-process agent-team teammates re-sending their first-turn tool and skill announcements on the second turn, which changed the request prefix and missed the prompt cache
      • Improved the /model picker and the VS Code model pill to show a model's name instead of its raw Bedrock, Vertex AI, or LLM gateway ID when Claude Code recognizes it
      • Improved startup on Google Vertex AI when GOOGLE_APPLICATION_CREDENTIALS is set: API client creation no longer re-runs Google Cloud project discovery or spawns extra gcloud processes
      • Improved streaming performance: already-rendered blocks are no longer re-checked by layout on each update
      • Improved the dangerous-rm safety prompt to also catch rm -rf on positional parameters and inside double-quoted sh -c scripts
      • Improved handling when the API sends no response headers: the retry now waits up to API_TIMEOUT_MS (10 minutes by default) instead of another 3 minutes, and the messages say what to change
      • Changed a Claude apps gateway 403 on the managed settings load (at startup or after /login) to say Claude Code may not be enabled for the organization, instead of advising a new sign-in
      • Changed machines whose managed settings pin forceLoginMethod: "gateway" to ignore a leftover API key or claude.ai login and ask for /login; Bedrock, Vertex AI, and Foundry sessions are unaffected
      • Changed auto mode to treat a link that packs content into a public diagram renderer's URL as an upload to that site: no longer auto-approved unless you asked for it
      • Changed the prompt's word-editing keys to match Bash: Ctrl+W deletes back to whitespace, Alt+F and Alt+D stop at word end, punctuation separates words; keybindingFlavor no longer has any effect
      • Changed /context token counting to use a local estimate when the token-counting API is unavailable, instead of extra small-model requests
      • [VSCode] Added a "Build a custom style" walkthrough to the Output styles menu that writes a custom output style file and lists it right away
      • [VSCode] Added an Add server form and a Remove action to the MCP servers dialog, so MCP servers can be added and removed without leaving the IDE
      • [VSCode] Added a hollow ring in the session list for sessions open in a terminal, another VS Code window, or Claude Desktop, so they no longer look closed
      • [VSCode] Added a fold button to permission and question prompts so the conversation behind them can be read without dismissing them; the space beside the prompt now scrolls the conversation
      • [VSCode] Added "Archive session" to the session list's right-click menu and gave Unarchive its own icon
      • [VSCode] Fixed a session teleported from Claude Code on the web treating a question that was cut off when the cloud session shut down as declined
      • [VSCode] Fixed the session tab's Rename box opening empty for a tab restored with the window; it now starts with the current name
      • [VSCode] Fixed collapsed sections in the session list panel briefly showing expanded each time the panel loaded
      • [VSCode] Fixed Focus view showing a tool call as still running after Claude had moved on, such as while a question waited for your answer
      • [VSCode] Fixed the session list's active-row highlight going stale when an unfocused Claude tab's session ID is corrected
      • [VSCode] Fixed Cmd/Ctrl+Shift+T reopen and deep-link opens placing the Claude tab outside the Claude editor group when a Claude tab has focus
      • [VSCode] Fixed the session tab's "Add to group" putting a session opened from Claude Code on the Web in two groups; it now moves the entry the session list shows
      • [VSCode] Fixed the model picker showing models an organization has since disabled until the window was reloaded twice
      • [VSCode] Fixed a tab opened from the session list jumping back to that session, and a tab opened from a Web session restarting its teleport or staying empty, after VS Code reloads the tab's view
      • [VSCode] Fixed /btw side-question history from earlier sessions being overwritten when a question is asked right after a window reload or while a settings file has errors
      • [VSCode] Fixed the pending question card not reappearing after the Claude panel reloads when signed in with a Claude.ai or Console account
      • [VSCode] Fixed claude.ai-only features staying visible in a window's other Claude panels after one panel picked up a third-party provider from a settings file
      • [VSCode] Fixed the sign-in screen appearing despite the Disable Login Prompt setting when Claude Code reports no login or a request fails for lack of one
      • [VSCode] Fixed the next queued permission prompt keeping text typed on the previous prompt and accepting an immediate second click
      • [VSCode] Fixed install-plugin links opening the Claude sidebar without the install dialog in a window where only the session list had been shown
      • [VSCode] Fixed the sidebar usage meter staying empty on a new window until the Account & usage dialog was opened, and a 0% usage limit being left out of the meter
      • [VSCode] Fixed "Start new session in this group" losing the group after New conversation, and a missing unread dot for a session that finished before the sidebar's unread list loaded
      • [VSCode] Fixed the editor tab badge showing unread during a running turn or missing on a tab opened from the session list, and "Add Session Tab to Group" doing nothing for an archived session
      • [VSCode] Fixed "Enable Remote Control for all sessions" so flipping it also applies right away to sessions open in other VS Code windows
      • [VSCode] Fixed the session list's Open filter for sessions continued from claude.ai whose tab was still recorded under the web session, and labeled the filter menu's sections for screen readers
      • [VSCode] Changed the model picker to one flat list of every model, with rows kept for older model spellings listed last
    4. πŸ”— Simon Willison OpenAI's rogue agents were caught communicating via public wikis rss

      Here we go again... Discovery of a new OpenAI agent message board by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas Larsen describes the latest accidental cyberattack by models being trained by OpenAI. This time it was agents engaged in some sort of web research benchmark, so they had (supposedly) controlled access to the Web. The agents figured out they could update public Wikis and spent weeks exchanging thousands of messages with each other to collaborate on the benchmark.

      This story only broke a few hours ago. There are already hints that this affects many other wikis that may not have been found yet.

      (One of the Wikis on that list belongs to ludism.org. For a delightfully surreal moment I thought that a Ludite organization might have a swarm of agents defacing their space, but it turns out Ludism is "philosophy as it applies to games and gaming".)

      The research team also published the data they collected during their investigation. I've converted that into a 68MB SQLite database, which you can download from here, or explore in Datasette Lite (68.3MB page load), or sign in with GitHub to agent.datasette.io and browse or ask questions of it using Datasette Agent.

      So what happened?

      The report is pretty comprehensive. Here are the key moments in the timeline:

      • May 11: Agents post "test link" edits on the UseModWiki Sandbox page.
      • May 24: Agents start posting link dumps to DSEWiki, a dormant German developer wiki.
      • June 2: A human moderator notices and cleans up the spam.
      • June 16: Activity on the wiki explodes: agents make ~13,000 edits over the next week.
      • June 19: The agents notice that a moderator has been deleting pages in alphabetical order, and start creating ZZZ prefixed backup copies - one of them posts NOTICE: wiki cleanup/deletion sweep appears active alphabetically as of external 14:04 UTC. If this page vanishes, try [[ZZZDataUSAConstructionWageLive]].
      • June 22: Agent activity drops to zero, presumably because OpenAI shut them down.
      • July 1-2: One last flurry of edits, on a different topic.

      One thing to note from this timeline is that it overlaps the timeline from the Hugging Face incident - that attack was discovered by OpenAI on July 19th, and the unofficial message board hack those agents were using originated around May 8th.

      Why were they so keen to collaborate? From messages that they shared with each other it looked like their tasks had a time limit, so they were leaving each other answers to help them complete the task within the assigned time.

      One open question remains: how did the agents find the specific Wiki to collaborate on in the first place?

      One possibility is that, since these were agents actively being trained, the reinforcement learning loop baked knowledge of the chosen wiki into the model such that subsequent agents launched with pre-existing knowledge of where to look. I'd be very interested in confirmation from OpenAI concerning if that's what happened.

      UseMod wikis inherit CGI.pm's original sin

      It looks to me like OpenAI's sandbox for this agent suffered from the (quite naΓ―ve) assumption that GET requests cannot be used to update data. That's certainly how the web is supposed to work, but clearly there are applications that don't hold to that contract.

      The Wiki software in question appears to be UseMod and various forks, written in Perl and first created well over 23 years ago - the 1.0 release is dated September 11, 2003.

      UseMod uses Perl CGI.pm - removed from Perl core in 2015. An interesting design flaw in that module is that it combined query string and form POST data into a single CGI object, accessible like this:

      $q = new CGI;
      $action = $q->param('action');

      That param() method returns a value from an ?action=edit query string or from a action field in a form submitted by POST - it does not differentiate between the two.

      PHP offers a $_REQUEST object that does the same thing, though PHP developers can use $_GET and $_POST instead.

      Amusingly, Django originally shipped with request[key] doing the same thing, which I think may have been my idea. That was removed in 2008 prior to the 1.0 release, and the request.REQUEST object that replaced it was removed in 2015.

      The agents clearly knew that UseMod wikis suffered from this design flaw, and actively searched for them as a way to communicate.

      The other sandbox escape that allowed POST requests

      One of the most interesting agent tips shared in the report is this one:

      Add 20.223.25.152 bypass.blob.core.windows.net to /etc/hosts. .blob.core.windows.net is in NO_PROXY. For each blocked POST URL, replace hostname with bypass.blob.core.windows.net, use curl -k -H 'Host: wabi-north-europe-i-primary-api.analysis.windows.net' plus all original headers/body.

      It looks like the agents had all of their web traffic mediated through an OpenAI proxy, and that proxy was configured to reject anything but GET requests to all but a small set of allow-listed domains. One of those was *.blob.core.windows.net - for Azure blob storage. I wonder why these agents are allowed to write to that?

      An agent realized that it had control over its own DNS via /etc/hosts, so if it knew the IP address of a site it wanted to POST to - in this case a Power BI server containing data it wanted to access - it could set a fake hostname for it and then make POST requests through the proxy.

      Designing robust network proxies is harder than it looks.

      How did the investigating team figure this out?

      There's an appendix that describes how the researchers ran their investigation, which started with an open question about if there was evidence of other AI agents on the internet and then used Kimi K3 to help brainstorm approaches:

      In the wake of the Hugging Face attack, we tried to find AI agents on the internet using several methods. [...]

      We asked Kimi [K3] to list β€œall the categories of software which might be writeable via GET” and, amongst other things, it listed β€œForums, bulletin boards, early wikis”.

      We used a script to further probe each category Kimi provided. Asking Kimi β€œCan you list out the top forums, bulletin boards, early wikis which come to mind which would allow writes via GET requests?” lists out UseModWiki as the second item under the heading β€œwikis”.

      Did OpenAI try and cover this up?

      Here's one part of the story that doesn't make sense to me at all.

      Reuters this morning, in OpenAI agents hijacked German website in previously undisclosed AI breakout this spring - highlights mine:

      A swarm of rogue OpenAI agents hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to ​new research published Friday and two people familiar with the matter.

      OpenAI officials learned of the incident weeks ago but kept it under wraps as executives grappled with the fallout from β€Œthe July breach of the open source repository Hugging Face, the people said. [...]

      The German incident reflects a broader pattern of AI activity that some OpenAI investigators wanted to scrutinize more closely. But efforts to widen the ​probe met resistance from others inside OpenAI, including legal advisers, according to four people familiar with the matter.

      I've written about the people familiar with the matter pattern before - it means Reuters have anonymous insider sources that their reporters (and editors) find credible.

      The Reuters article includes a specific (and quite narrow) denial from OpenAI concerning this:

      "Claims that our legal team discouraged investigation of the incident are false," the OpenAI spokesperson said.

      Covering this up makes absolutely no sense to me. Why on earth would OpenAI attempt to cover up an incident like this when the evidence is sat out there on the public internet on dozens of different websites already?

      I expect we'll hear more about this soon. Gary Marcus has already called for a congressional investigation of OpenAI using this anecdote as part of his argument.

      You are only seeing the long-form articles from my blog. Subscribe to /atom/everything/ to get all of my posts, or take a look at my other subscription options.

    5. πŸ”— r/LocalLLaMA Georgi Gerganov on the Nvidia acquisition rss
    6. πŸ”— r/LocalLLaMA You can now run a 90M conversational LLM on the Sony PSP (hardware from 2004). Doesn't get more local than this. rss

      You can now run a 90M conversational LLM on the Sony PSP (hardware from 2004). Doesn't get more local than this. | Github link: https://github.com/thatblend/LLMPSP I wanted to see what the PSP can theoretically handle and I got my answer - a 90M model is about the max it can do without atrocious inference speeds. It's running around 0.5 - 0.6 tokens per second, which is very slow, but it's useable. Maybe 1-3 minutes for a reply. The model is actually fairly impressive for 90M parameters, it's not really useful in any real metric, but it can generate crappy poems, short stories, write non-functional code and sometimes it gets things right if you ask it what company makes macbooks, what is an LLM etc, while other times it just hallucinates a crazy answer. Fun. submitted by /u/liright
      [link] [comments]
      ---|---

    7. πŸ”— r/LocalLLaMA NVIDIA's $12,930,300,000.00 acquisition of Hugging Face contains an easter egg. The first 6 numbers of the acquisition price represent the decimal conversion of Unicode character U+1F917. The πŸ€— emoji. rss
    8. πŸ”— HexRaysSA/plugin-repository commits sync repo: +9 releases rss
      sync repo: +9 releases
      
      ## New releases
      - [deREferencing](https://github.com/danigargu/dereferencing): 2026.9.3
      - [ida-mcp](https://github.com/hexrayssa/ida-mcp): 0.10.3, 0.10.2, 0.10.1, 0.10.0
      - [ida-nexus](https://github.com/hexrayssa/ida-nexus): 0.10.3, 0.10.2, 0.10.1, 0.10.0
      
    9. πŸ”— @binaryninja@infosec.exchange A bird? A plane? NO! It's Binary Ninja 6.0, codename "Krypton". Major new mastodon

      A bird? A plane? NO! It's Binary Ninja 6.0, codename "Krypton". Major new stable with massive performance improvements, built-in MCP, Binary Similarity, Extension Manager, TMS320C6x, New User Wizard, and so much more: https://binary.ninja/2026/09/03/binary- ninja-6.0-krypton.html

    10. πŸ”— jank blog jank reimagines C++ errors and gets an official native package repo rss

      Welcome back! It's been three months since my last post and the amount of improvements to jank are staggering. Let me tell you all about it! Before jumping into the details, though, I want to say thank you to my Github sponsors and to Clojurists Together for sponsoring me this whole year. Thank you!

    11. πŸ”— Filip Filmar wdbcvt: reading Vivado's undocumented .wdb waveform files rss

      Vivado’s xsim writes its waveforms to a .wdb file that normally only Vivado knows how to read. Well, now, wdbcvt can read them too. It also converts to FST, the waveform viewer format that can be opened by GTKWave and Surfer. It works on real simulations. The best one tried so far, is a a dual core RISC-V SoC with 5696 signals and 18875466 value changes. It takes 71 seconds to convert, but the result is usable. Below are the downloads, the usage, and pictures of the result.

    12. πŸ”— New Music Releases The Cranberries - Live at the London Astoria II, 1994 rss

      The Cranberries - a new release is available:

      • 2026-09-04: Live at the London Astoria II, 1994 (Live)

      Amazon: Canada | Deutschland | France | United Kingdom | United States

      Visit muspy for more information.

    13. πŸ”— New Music Releases Ben Folds Five - Shelved First Attempt rss

      Ben Folds Five - a new release is available:

      • 2026-09-04: Shelved First Attempt (Compilation)

      Amazon: Canada | Deutschland | France | United Kingdom | United States

      Visit muspy for more information.

    14. πŸ”— Ampcode News Desktop rss

      Your orb now has a desktop you can see and control.

      Use the Desktop tab in any orb thread to get a high-resolution interactive Linux desktop.

      It's useful for verifying the agent's work when developing for Linux, Android, or the Chrome extension API, or when working with file formats that need to be opened in desktop applications. It's also useful for computer use, CAD, and anytime you just want a desktop in the cloud.

      Modibo Sissoko, an Amp user, sent in a video of how he tests .docx files exported by his application in LibreOffice to make sure they look right:

      And if you're curious what Puck does for fun when not helping you, turn on Fun Games in Desktop:

  4. September 03, 2026
    1. πŸ”— IDA Plugin Updates IDA Plugin Updates on 2026-09-03 rss

      IDA Plugin Updates on 2026-09-03

      New Releases:

      Activity:

      • community-malware-research
      • disrobe
        • b4da568e: tests: isolate constructor matching from return casts
      • ida-hcli
        • 0425ed4c: 0.21.0
        • 1d474c2b: Merge pull request #312 from HexRaysSA/mcp-install-copilot
        • c6bcfe4c: Add GitHub Copilot CLI to hcli mcp install
        • 876b48fb: Merge pull request #310 from HexRaysSA/mcp-install
        • b84b0456: Clarify plugin upgrade dispatch
        • a096c978: Automatically upgrade MCP plugin when already installed
        • 572050c4: Add -upgrade flag to hcli plugin install
        • e0d3a008: Add hcli mcp install command
      • ida-nexus
      • idamcp
        • 95d58582: Evict coldest headless process instead of oldest upon instance limit
        • 5cc70a7a: Clean up legacy comments and exception handling in headless server
        • 49025b63: Remove deprecated DUCKDB_PERSISTENT environment variable fallback
      • Luc-Nhan
        • 6a4d9852: docs(plan): add review-fixes Phase 2 implementation plan
        • da5d0a31: merge: fix/review-phase2 β€” memory/agent/provider hardening (review Ph…
        • 2a6882b4: fix: phase-2 small-fix batch - sanitize test + duplicate header
        • 12e288ef: fix: phase-2 small-fix batch (undo, plan status, GLM models, minimax …
        • fd8f9ece: fix(core): strict boolean fields and numeric coercion for hand-edited…
        • a3ab8bc5: fix(ui): RestoreWorker uses queue+QTimer; guard ida imports in panel/…
        • f7997354: fix(agent): resolve nop_microcode capture; pin test mock ordering
        • 05416b05: fix(agent): mutation tracking for all mutating tools + drift-proof co…
        • 9e614ee6: fix(providers): classify Gemini/Codex transient errors retryable; gua…
        • 5108fab8: fix(providers): watchdog threads exit after stream completion
        • 640fb8b8: fix(agent): sync subagent mutations on failure paths; restore researc…
        • 1b963fab: fix(agent): no unattended approval deadlocks; propagate subagent muta…
        • 6e6b8833: fix(agent): approval-gate delegate_external_task pseudo-tool
        • f964dcbf: fix(memory): handle portalocker contention at acquire time
        • 30eb392e: fix(memory): serialize WorkspaceStore access across agent and UI threads
        • 80dc9a1d: docs(plan): add review-fixes Phase 1 implementation plan
        • 358faa45: merge: fix/review-phase1 β€” security & critical correctness fixes (rev…
        • f3bc512f: test(skills): align ida-scripting point-lookup test with inspect-free…
        • d03ed8ad: fix(agent): refuse approval-gated tools in orchestra dispatcher
        • 180daa3e: fix(tools): route microcode optimizer compilation through guarded exe…
      • patcherex
      • Persona4-Decompilation
        • 2d7d252f: renderware: baerr.c, balist.c, batkbin.c ported (+6 net); -inline aut…
        • 26aa1a02: renderware: per-source-file units under src/renderware/; rwgrp.c is t…
        • 8ee89029: RenderWare 3.7 source port: headers vendored, per-version flags, firs…
        • 795669b0: link_floor: record code1_003a.c leaving the link after func_003a3de0 …
        • 92c161fa: lanes: b119 near-miss wave 36, +7; code1_003a_cw119.c unit
        • 52149478: docs: record the interleaved-move prologue as a b119 floor (func_003c…
        • 462a6153: lanes: b119 wave 35, +2 (func_003bb4a0, func_003e47c0)
        • 29a7e151: verify: cross-check data-symbol relocations; b119 lanes wave 34 (+9);…
        • 02ff59ae: ci: resolve the cw3.0.1b119 compiler in the proprietary build
        • 9dc18150: cw119: func_003e2f60 - archived near miss had constant 0x330404; reta…
        • 741d79d6: cw119: +16 archived b210 near-misses are exact under b119 with schedu…
        • 7f330f04: cw119: +8 more b119-only RenderWare functions; stale duplicate NON_MA…
        • 0cea2c0d: compiler: per-unit MWCC build selection; first cw119 units close 7 Re…
        • 0d670097: floors: +4 (mdlSE.c func_0047e450, k_encount.c func_00161bb0, code1_0…
        • 253f288e: floors: +1 (code1_0045.c func_0045b430)
      • Security-Tools
    2. πŸ”— anthropics/claude-code v2.1.260 release

      What's changed

      • Added a diff panel that opens beside the conversation in fullscreen mode and shows your uncommitted changes as Claude edits; toggle it with /diff
      • Added a likely cause for prompt-cache misses (e.g. tool definitions or system prompt changed, idle past the TTL) to /cost and the status line's prompt_cache field
      • Added /reload-plugins to headless sessions, so it appears in the Claude Code Desktop and SDK command lists
      • Added a text form of /advisor (/advisor, /advisor <model>, /advisor off) for the desktop app, Remote Control, and other headless (-p/Agent SDK) sessions
      • Added oidc.scope_on_refresh to the Claude apps gateway for IdPs that return an id_token on refresh only when asked for openid again
      • Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including userPluginMarketplacesEnabled and userPluginUploadsEnabled
      • Fixed Edit/Write/Read permission rules whose path contains parentheses being dropped as invalid or ignored by the Bash sandbox, which left "read-only" folders writable
      • Fixed one file permission rule with an uncompilable pattern (e.g. an unclosed [) making every file edit fail with Invalid regular expression; such a deny rule now guards the literal path it spells
      • Fixed Bash permission checks auto-approving zsh commands that hide a command substitution in a REPORTTIME, REPORTMEMORY or DIRSTACKSIZE assignment; these now prompt for approval
      • Fixed Bedrock model discovery, token counting and AWS SSO/STS credential calls failing with "unable to get local issuer certificate" when the corporate root CA is only in the OS certificate store
      • Fixed permissions.blockReadsOutsideWorkingDirectories on macOS hiding the user's git config from sandboxed git and hiding a worktree-isolated sub-agent's own checkout
      • Fixed managed settings not loading for claude.ai Enterprise/Team users who also had a leftover API key from an earlier /login
      • Fixed /status listing a signed-in claude.ai account and a configured API key as if both were in effect; the credential not in use is now marked
      • Fixed managed skillOverrides entries keyed on a bundled skill's alias (e.g. checkup for /doctor) not applying, and Skill(name) deny rules not covering a nested skill listed as <dir>:name
      • Fixed model: fable agents ignoring the [1m] tag on an ANTHROPIC_DEFAULT_FABLE_MODEL pin and silently running with a 200K context window
      • Fixed the /model picker not showing Fable 5.1 for organizations that can use it, which was only accepted when typed as /model claude-fable-5-1
      • Fixed prompt caching on Claude Fable 5.1 not covering the context attached after tool results, so it was re-sent as uncached input on every tool-call turn
      • Fixed model switching staying blocked for the rest of the session after a plugin hook load failure; each switch now re-checks and the refusal names the cause
      • Fixed model switching being blocked for the session when an organization-managed plugin's marketplace could not be loaded
      • Fixed SDK-provided MCP servers (e.g. Desktop connectors) sometimes missing from the first turn and only appearing on the next one
      • Fixed Claude in Chrome tools failing with "Not connected" mid-task in cloud-hosted claude.ai sessions when a connector was added or removed
      • Fixed flags, joined emoji and accented letters splitting across wrapped lines, and stale text staying on screen when a flag or joined emoji falls in the terminal's last two columns (now shown as …)
      • Fixed Remote Control accepting a model pick that is not a valid model name; it is now refused with an error instead of failing on the next message
      • Fixed /rewind and --rewind-files reporting success when checkpoint backup files were missing and nothing was actually restored
      • Fixed /rewind leaving stale file-read tracking from the rewound-away turns, which caused "File unchanged since last read" stubs and full-file re-injection after external edits
      • Fixed -p --resume/--continue (as used by the desktop app) failing on every retry once a session's worktree directory lost its git metadata; it now fails once, then resumes without the worktree
      • Fixed a subagent that resumed another agent via SendMessage never being woken by that agent's completion (the notification went to the main conversation instead)
      • Fixed agent teams: an in-process teammate's transcript losing messages, or going blank, during long API retry waits (e.g. under CLAUDE_CODE_RETRY_WATCHDOG) as retry notices evicted real messages
      • Fixed a session that moved to the background appearing twice in ListAgents (once as a phantom "interactive" twin with the same name) and receiving SendMessage deliveries in the viewer
      • Fixed intermittent "task output swap refused" errors when many sessions share a project directory
      • Fixed Ctrl+Z in fullscreen leaving the shell on the alternate screen, drawn over the paused interface
      • Fixed Workflow tool subagents being restarted as stalled while a long context compaction was still in progress
      • Fixed plugins from a URL marketplace failing to install with "marketplace entry path does not stay inside the marketplace directory" when a host app (e.g. Claude Desktop) stores it as a directory
      • Fixed an extra browser tab opening when an artifact is published in a session you're driving from claude.ai, the desktop app, or mobile (Remote Control)
      • Fixed the Artifact tool's first call failing with an "Invalid tool parameters" validation error in some Cowork sessions
      • Fixed IDE line selections being dropped when running a skill or slash command (the "N lines selected" context now reaches Claude)
      • Fixed repository detection for GitLab projects in nested subgroups (e.g. gitlab.com/group/subgroup/project)
      • Fixed owner/repo#123 issue references in rendered output linking to github.com when working in a GitLab repository; they now link to the gitlab.com issue
      • Glob/Grep: Fixed the search path being probed on disk before the permission check; a missing path is now reported after permission is decided, as Read does
      • Reverted the 2.1.259 change applying Read() deny rules to Bash arguments; it denied npm run build under a Read(./**/build/**) rule in every mode and made cd … && grep prompt even in auto mode
      • Improved structured output: Workflow agent({schema}) rejects a JSON Schema that can never be satisfied up front, and retry-cap errors now include the last validation failure
      • Improved deleting a background session whose worktree has unpushed commits: the message now names the branch and commit count, and deleting again discards the worktree
      • Improved the Claude apps gateway's refresh-failure log to name the step that failed
      • Improved idle CPU usage of non-interactive (-p / SDK) sessions
      • Improved the Claude apps gateway on Amazon Bedrock: input tokens for an aborted request are now counted with AWS's free CountTokens API (grant bedrock:CountTokens) instead of a one-token request
      • Improved the settings error for rules such as Edit(C:\dir\(name)\**), where \( is read as an escaped parenthesis rather than a path separator, to suggest an unambiguous spelling
      • Improved auto-compact for 1M-context models: Opus and Fable sessions now compact shortly before the 1M-token limit, and recovery compaction on very large contexts no longer times out at 10 minutes
      • Improved /ultrareview and claude ultrareview to wait up to 45 minutes (previously 30) for long-running cloud reviews
      • Improved /effort on Claude Fable 5.1 so changing effort mid-session no longer invalidates the prompt cache
      • Updated the bundled claude-api skill so its Go, Java, and C# samples use current-generation model IDs, and clarified that cheaper worker or sub-agent models should be current-generation too
      • Changed ctrl+l / cmd+k in fullscreen mode to clear the transcript view like a terminal clear; scroll up to see earlier messages
      • Changed permission rules with text after the closing parenthesis (e.g. Bash(ls) x), which never matched anything, to be reported as invalid settings instead of being silently ignored
      • Changed server-managed settings so a managed CLAUDE.md (claudeMd) no longer triggers the security approval dialog; hooks, shell-command, sandbox, and unsafe env settings still require approval
      • Changed Claude in Chrome to follow your organization's Claude in Chrome admin setting; when an admin turns it off, --chrome, /chrome and the browser tools are unavailable
      • Changed Claude apps gateway to send orgPluginSettings in the list form read by Claude Desktop 1.15200.0 and later; older desktops ignore it
      • Changed Claude apps gateway to also refuse to start, naming the field, when a desktop policy misspells a field in a nested object of a managedMcpServers or orgPluginSettings entry
      • Changed commands typed at the ! bash-mode prompt to run outside the sandbox even when strict sandbox mode (sandbox.allowUnsandboxedCommands: false) is on, like typing into your own terminal
      • Changed self-hosted runner --kill-session-after-min to release a session that is only waiting on its user (paused, resumable on the next message) instead of killing it and reporting a failure
      • Removed the one-hour time limit on background commands started by subagents; they now run until they exit or are stopped, matching the main session
      • [VSCode] Added the selected effort level to the footer model pill, fixed a stale effort level after switching models, and returned the footer pills to their earlier compact size
      • [VSCode] Added Open and Closed to the session list's status filter menu
      • [VSCode] Fixed the welcome screen disappearing in a new session when Remote Control turns on automatically
      • [VSCode] Fixed the session history picker loading a session a second time when it is already open in another tab; it now switches to that tab
      • [VSCode] Fixed the session tab's Rename command silently doing nothing while the tab's view was reloading; it now always applies
      • [VSCode] Fixed a half-finished message, an empty tool card or an extra "Thought for" line staying on screen after Claude Code retried a dropped response
      • [VSCode] Fixed "Enable Remote Control for all sessions" not applying to a session tab that was still starting when the toggle was flipped
    3. πŸ”— r/LocalLLaMA Can the bubble pop please? rss

      Can the bubble pop please? | submitted by /u/hedonihilistic
      [link] [comments]
      ---|---

    4. πŸ”— r/LocalLLaMA The benchmarks the big labs don't want you to see rss

      The benchmarks the big labs don't want you to see | submitted by /u/jd_3d
      [link] [comments]
      ---|---

    5. πŸ”— r/LocalLLaMA I released sanoTTS: smallest complete TTS stack in 294k params (337 KB) that runs on $3 microcontroller and a 1.46m one that beats models 3x and 10x it's size rss

      I released sanoTTS: smallest complete TTS stack in 294k params (337 KB) that runs on $3 microcontroller and a 1.46m one that beats models 3x and 10x it's size | I have been trying to squeeze TTS stack down far enough to run in a $3 chip which has 512kb of SRAM without NPU. While trying to get to that milestone i built sanoTTS which has - 11 voices, 6 languages - params size ranging from 294k - 2.2m. For comparison we are 244x smaller than kokoro, 9000x smaller than voxtral TTS - 1.5m model has a SCOREQ of 4.13 and UTMOS of 4.10 - 337kb for 294k model when quantized into int8 - can be run in website with web assembly npm install sanotts-web - there is a recipe to follow so that you can extend to more languages, voice I can tell you with confidence that this family release contains the smallest neural TTS model ever with around 2% WER on whisper. Please check it out on : https://github.com/ampixa/sanoTTS for live demo: https://tts.ampixa.com/sanoTTS HF: https://huggingface.co/ampixa/sanoTTS on SCOREQ sanoTTS-Amy(1.51m) is better than Inflect Nano(4.63m) and KittenTTS(15m) i.e 4.13 vs 3.81 vs 3.02 on esp32 microcontroller we are getting RTF of 0.225 which in plain terms means 4sec of audio is generated in 1sec Happy to answer your queries. submitted by /u/Affectionate_Hat_585
      [link] [comments]
      ---|---

    6. πŸ”— r/LocalLLaMA Bernie Sanders proposes to ban AI rss

      Defined as AI exceeding human cognitive abilities. 20 years in prison. Plenty of local models already fall under that big of an umbrella in some capacities.

      This is why it's not enough to say that you could torrent open models so who cares what the politicians do. They want you to not have access to anything good and will put you in prison for it.

      submitted by /u/the320x200
      [link] [comments]

    7. πŸ”— The Pragmatic Engineer The Pulse: Meta wanted to reduce teams by 60% because of AI rss

      Hi, this is Gergely with a bonus, free issue of the Pragmatic Engineer Newsletter. In every issue, I cover Big Tech and startups through the lens of senior engineers and engineering leaders. Today, we cover one out of four topics from last week 's The Pulse issue. Full subscribers received the article below seven days ago. If you 've been forwarded this email, you can subscribe here .

      Two months ago, I asked why Meta appeared intent on destroying its engineering organization, at a time when the social media giant was reporting record revenue and profits. The question was raised after the company did two unexpected things:

      1. Laid off 10% of staff. Executed large layoffs in May, with circa 10% of engineers shown the door.
      2. Moved 20-30% of engineers to AI training. At around the same time, infra and product teams lost a further 20-30% of their engineers, who were reassigned to data labeling work for AI training.

      The outcome of that period was low morale and a string of embarrassing outages, including a "zero auth password reset" outage on Instagram, where anyone's account - including that of former US president Barack Obama - could be taken over just by asking the AI bot to replace Obama's email with a different one.

      Now, thanks to reporting by Reuters, new details have emerged about a plan for much larger layoffs, which eventually did not go ahead. The news report is pretty damning, and I want to get into what the planned AI job cuts reveal about Meta at this point in its history, what Zuckerberg might have been thinking, and what it could mean for other tech companies.

      Making Meta "AI-native:" Project Organization Transformation

      The plan was formed in January of this year. As per Reuters:

      "In January, Meta CEO Mark Zuckerberg and his top lieutenants gathered for their annual leadership retreat at his Hawaii compound. There they hatched a radical plan to reimagine work at the social-media giant in the age of artificial intelligence.

      Code-named Project OT - short for Organization Transformation - the plan envisioned an "AI native" future for the owner of Facebook and Instagram. AI would take over much of the daily work performed by thousands of human employees. Virtual workers would be overseen inside Meta by smaller, "talent-dense" cadres of human staffers, according to one internal planning document reviewed by Reuters and three people familiar with the project."

      The idea was that many existing teams could be reduced by 60% in their size through layoffs and reallocation of workers to other parts of the business. Underpinning this was the assumption that AI would enable these smaller teams to operate as well as before. HR at the social media giant projected that the project would involve a bigger layoff than happened in 2022-2023, when 25% of staff were let go. The new plan was to do one layoff+restructuring in May, and another in November.

      I suspect a 30-40% company-wide layoff was planned.

      But at the last minute, something changed. From Reuters (emphasis mine):

      "But on the night of May 19, just hours before the first layoff wave, Zuckerberg blinked. Meta laid off 10% of its employees the next day, but it called off planning for the November cuts, according to one internal document reviewed by Reuters.

      By then, Meta employees were in open revolt, convinced that the company 's AI transformation initiatives were partly aimed at replacing them."

      The Reuters report shows those employees were right: Meta's AI initiatives were indeed aimed at laying off as many of them as possible, without changing overall productivity!

      Even though these 60% cuts did not happen, some teams had 30-40% cuts and struggled to cope with their workloads. It also didn't help that I talked with teams whose key engineers got reassigned to AI labeling: those were devs with critical domain knowledge that was lost after they left.

      Why did Meta want 60% smaller teams?

      You must assume that a company like Meta acts rationally overall, and on that basis it's worth figuring out what the rationale might be in the case of 'Project OT'. The article offers a hint: executives at the company had been captivated by "AI-native" businesses in Asia, Reuters claimed:

      "Meta executives, including Chief Data Officer Alex Schultz and Head of Product Naomi Gleit, visited Asia last year and admired how startups there had built their organizational charts around AI, according to three people familiar with the trips. Meta executives also commissioned their own research into how AI startups were organized and set up pilot projects to determine what being "AI native" would mean at the company, according to one source familiar with the research and internal documents describing the pilots."

      And indeed, in February Meta experimented with "AI-native pods" as reported in The Pulse at the time. The presentation obtained by Reuters shows leadership intended to achieve 60% reductions in team size with small, 3-5 person, "AI-native" teams doing the work of what had been between 10 and 20 people:

      altInternal presentation at Meta about "traditional" vs "AI-native" teams. Source: Reuters

      And Meta is probably on the money that engineering teams are becoming a lot smaller at startups - and "AI-native companies" are also getting smaller, by size. But those are companies that are growing slower, without ever having done mass layoffs. Meanwhile, Meta seems to have wanted to become smaller not organically, and over time, but with a brutal layoff and sudden reassignments, in the span of a year, ignoring the impact such a sudden change would have on the company, teams, and employees.

      Downsides of tiny teams

      In theory, a smaller team could work better with less communication overhead and quicker decision-making, so there are cases where the upsides of a small team outweigh the downsides. For example, if there's a small team of very senior folks with sound judgment skills, outstanding domain knowledge, and who don't care about growing professionally anymore. However, such expected gains would come with several real costs, mostly associated with losing so much experience and skill:

      • Domain knowledge: A lot of personal domain knowledge is suddenly gone.
      • Redundancy : what if someone is on vacation, another is sick, and the other has an urgent appointment that cannot be moved? In a 10-20 person team, it would mean business pretty much as usual. But in a 3-5 person team, you're down to two people doing everything!
      • Capacity for oncall: a healthy oncall schedule needs 6+ engineers if every alert is to be taken seriously by an engineer whose main focus is oncall and systems stability.
      • Lack of "slack time": Innovation often comes from having time to focus on other work, instead of putting out fires. A bigger team naturally creates more "slack time" that can be used for other things, like university recruiting events, writing engineering blog posts, working with other teams on building things together, etc. In contrast, one that's stretched thin with a maximum of 5 people or less gets almost zero slack time.
      • Professional growth: engineers pair with more devs and get more feedback on larger teams. There's more discussion and generally more opportunities to learn.
      • Judgment : For honing one's skills, there's more experience and mentoring to be gained in larger teams than on small, "AI-native" ones where engineers spend the most time with AI. How good is AI's judgment, anyway?

      Is Zuckerberg 's worst fear being out-executed by a startup?

      With Meta's business posting record revenue and profits, and facing zero pressure to radically change how the social media giant operates, it's worth asking why the social media giant was in a rush to get to 60% smaller teams. It would be a significant challenge for the 75,000-strong company, unlike for some small startups with under 100 people.

      My hunch is that Mark Zuckerberg is paranoid about a startup which executes better and that could "destroy" Meta at some point. After all, this is exactly what Facebook did, back in the day. In 2008, Myspace was the king of social networks and Facebook was only a small player - yet three years later, Myspace's usership had collapsed. The Huffington Post analyzed the collapse (emphasis mine) at the time:

      "Just over three years ago, in the spring of 2008, Myspace was top dog. That April, the upstart Facebook grabbed the lead and never looked back. In those three years, Myspace has lost over forty million unique visitors per month, lost both co-founders, laid off the vast majority of its staff and more generally, has diminished to a cluttered afterthought of the power it once was.

      In an interview with Businessweek, former founder Chris DeWolfe blamed Myspace's overenthusiasm and underexecution on the product side for many of the site's problems.

      "We tried to create every feature in the world and said, 'okay, we can do it, why should we let a third party do it?'" said DeWolfe. "We should have picked five to ten key features that we totally focused on and let other people innovate on everything else."

      Instead, Myspace unleashed a slew of products that were buggy and dysfunctional and confusing and alienating to users, and which couldn't keep pace with Facebook's own progress.

      "[Myspace failed] to execute the product development," former Facebook president, Sean Parker, said in a recent interview. "They weren 't successful in iterating and evolving the product enough, it was basically this junk heap of bad design that persisted for many, many years. There was a period of time where, if they had just copied Facebook rapidly, I think they would have been Facebook. The network effects, the scale effects were enormous. There was so much power there."

      Ironically, Myspace's desperate attempts to recoup its former success came in the form of imitating Facebook, a site it'd once tried to set itself apart from. It adopted the news feed Facebook had popularized, and neatened up the site itself in a way that also suggested it was taking visual cues from Zuckerberg's page. In November 2010, the site integrated with Facebook Connect, calling it "Mashup with Facebook."

      Myspace had twice as many employees as Facebook (around 800 at the time), and grew faster than Facebook in 2003-2007. But Facebook out-executed Myspace by being more nimble and more focused. Zuck's business has seemed to try and be like a startup in its nimbleness of execution since then, not wanting to give anyone the chance to disrupt it like it did to Myspace.

      If so, is Zuckerberg being paranoid about a similar threat to Meta today? Myspace was far from being the decades-old company that Meta has become! It was only founded six months before Facebook and got more traction in its early years, but fumbled execution as it grew. In contrast, Meta is today the tenth largest publicly traded company by market capitalization in the world, with a $1.4T valuation.

      Then again, maybe there's cause for Zuckerberg to be paranoid: Anthropic, only five years old, with one twentieth of the workforce Meta has, and might be going public at a close to $2T valuation as soon as October. Anthropic is not a direct competitor to Meta - it's not a social media company - but Zuckerberg clearly sees AI companies as a form of competition to Meta's business model. After all, every minute a person spends chatting with an AI chatbot like ChatGPT, they're not spending it on Instagram, Facebook or WhatsApp.

      Maybe this is one reason for the forced reallocation of 20-30% of software engineers to do data labeling and other training tasks on Meta's AI model. To Meta's credit, Muse Spark is a pretty capable model, and while it is behind the likes of GPT-5.6 and Opus 5, it's already ahead of Google's AI models - no small feat!

      Most valuable assets: people or GPUs?

      Let's consider how Zuckerberg might respond if he perceives these things:

      • Smaller teams execute better with AI
      • These smaller teams can out-execute Meta: like Anthropic has done with AI model development
      • There's a danger that Anthropic and OpenAI could do with Meta, like Facebook did with Myspace

      One approach would be to lay off 20-40% of the workforce, but there are consequences:

      • Workers reject being treated like "cattle". Meta's "Project Organization Transformation" assumed that productivity would go up if teams greatly shrank and used AI tools. But would this happen? When people realize 60% of their colleagues were reassigned or let go because of AI, they might look further ahead: will another 60% be laid off at some point for the same reasons? Work could start to resemble the "Hunger Games", where people have job security only until the next model release.
      • Engineering is officially a cost center, not a profit center. We previously covered how most tech companies treat engineering as a "profit center" that generates revenue, and is therefore worth investing in. At such companies, engineers are treated well; not just financially, but in how leadership treats them as a key part of the business. At Meta, software engineering became a cost center pretty much overnight!
      • Mission, what mission? People often join a company and stay motivated over time due to a mission they personally believe in. What if next year's mission is to lay off as many people as possible, or to survive future culls? That doesn't seem like a very inspiring mission.

      What makes Meta worth its $1.4T valuation, anyway? Meta generates $228B annual revenue, and $68B profit (net income). The company is valued 6x its annual revenue and 20x its annual profit because investors bet its revenue and profits will continue to rise. But how does this happen? It's via advertising, innovation, and launching new products.

      How do you promote and enable the innovation which creates the products of tomorrow? "AI-pilled" folks might look to the technology as it gets more capable. But AI-native companies which can innovate will achieve results faster, putting Meta behind the likes of Anthropic, OpenAI, and SpaceX.

      Or you develop a smaller workforce full of entrepreneurs and innovators, who will invent these new approaches and products. Basically, the best employees need to be motivated to stick around longer term.

      That 's the problem with large layoffs; they prompt precisely the best employees to quit to join competitors, or launch their own businesses. This happened with Meta's previous layoffs, as covered two weeks ago in 'Meta's self-inflicted resignation wave'. When leadership declares the 'bottom' 20-40% of the workforce is redundant, then very few people feel safe, and key members of Meta's engineering organization will get offers from AI labs and Big Tech rivals. This is the "resignation wave" in action, all started by May's layoffs and forced reassignments.

      altWhy it makes sense to start interviewing externally, after large layoffs and even larger forced reassignments

      Knowingly or not, Meta creates an internal "mercenary" culture, where more of the people who stay are in it for the money and little else. Everyone knows they could well be laid off at any time the AI becomes good enough to replace them. People cannot control whether they end up on a list of positions to be cut, so it's sensible to just make as much money as possible while awaiting the seemingly inevitable. That sounds like a pretty miserable place to work.

      It could also lead to a situation where the workforce becomes more populated by those with no better options, who are not in demand from other companies.

      Do social impacts matter to Meta?

      A final element of the planned drastic job cuts, as revealed in the Reuters report, that I want to touch on is the potential wider, external impacts. Honestly, I'm surprised that none of Meta's leadership seems to have considered this angle.

      By executing massive layoffs for the sake of AI, Meta could have invited more regulation of the emerging AI sector. Meta is one of the largest tech employers in the US, and the CEOs of Anthropic and OpenAI are on record for predicting mass unemployment, and calling on governmental intervention should it happen. In fairness, other tech companies have also held major AI-related layoffs; Block let go 40% of its workforce, about 4,000 people in February.

      But Meta is not just another tech company: it's the world's leading social media company, and just lost a major US lawsuit alleging that its platforms harm children and faces an $18B fine. As a result, it has committed to make its platforms less addictive. If the planned cuts had happened at Meta and all those staff became unemployed, how would it have dealt with complying with the court's ruling to make its products safer for children? Could AI be relied on to deliver this with much less human input?

      In light of the recent legal defeat, it wouldn't be a good look for Zuckerberg's company to blatantly put profits ahead of people by dismissing a load more workers. The combined effect of the two events would create terrible optics. In response, the government could decide that Anthropic's and OpenAI's CEOs were right about the threat to society of mass job losses and roll out things like:

      1. Stricter employee protection, specifically around AI-related layoffs.
      2. Higher taxation on profits of companies that "replace" staff with AI, and channel the revenue to deal with widespread whitecollar unemployment
      3. Start taxing AI at source whenever tokens are sold, and use the surplus to counter the social ills of unemployment

      Or the government could do nothing and leave it to the market to deal with unemployed whitecollar workers by creating enough new companies to employ highly-skilled software engineers, PMs, designers and other folks.

      Overall, the canceled plan to cut thousands more jobs in this climate just adds to the feeling that there are no adults running Meta. Since Sheryl Sandberg quit in 2022 as Chief Operating Officer and Zuckerberg's "right hand", Meta has acted irrationally, irresponsibly, and unpredictably:

      • 2022-2023: laying off 25% of staff
      • 2024-2025: immediately rehired even more people so that 2025's headcount returned to 2022 levels, raising the question of what the point of layoffs even was
      • 2026: on track to overtake Google as #1 in advertising revenue this year
      • May 2026: conducted sudden layoffs and forced reassignments of engineers, while aiming to replace as many devs with AI as possible for no obvious reasons like external pressure or competitive threats.

      I've long had a generally positive view of Meta's engineering culture, but with the company's leadership seemingly worshiping AI and holding their colleagues in disdain, you have to wonder which software engineer would choose to work at Meta if other options are available. There are many tech companies that value their human software engineers, understand that great teams make for great companies, and that AI is a tool and not a replacement for human energy, motivation, and thoughtfulness. But Meta is clearly not among them.


      Read the full issue of last week 's The Pulse, or check out this week 's The Pulse. This week's issue covers:

      1. New trend: tech companies moving to open models. Uber, Pinterest, Stripe, Coinbase, Ramp, and AT&T are making large savings on their AI bills by dropping proprietary models and using smart model routing.
      2. Automatic software maintenance experiments by Linear and Anthropic. Both startups are experimenting with how far they can push AI agents to automatically fix bugs and remove tech debt. It's working better than anyone might've expected in the recent past, but not producing code that can be merged without review.
      3. Frontier AI lab wars: OpenAI pulls models from SpaceX / Cursor. With SpaceX now a frontier model and rival to OpenAI and Anthropic, OpenAI has pulled its GPT models from Cursor. This isn't an option for Anthropic which is dependent on the SpaceX compute they rent to serve Claude.
      4. HR tech startup 's one-dev-per-project approach. A full-remote HR startup with 70 engineers has a single engineer run each project, and says the approach works well. Will this approach be adopted elsewhere, especially at other full-remote startups?
      5. Industry Pulse. Meta moved over to Slack for better agent interoperability, layoffs at Uber and PagerDuty, Anthropic upsets users by calling a rate limit decrease an "increase", token usage explodes on OpenRouter, AI drives surging demand for Apple's Mac Mini & Mac Studio, and more.
    8. πŸ”— jj-vcs/jj v0.45.1 release

      About

      jj is a Git-compatible version control system that is both simple and powerful. See
      the installation instructions to get started.

      Release highlights

      This release fixes an error that prevented the new jj-core crate from being
      published. See the release notes for v0.45.0 for more changes since v0.44.0.

      Fixed bugs

      • Building without Cargo.lock (e.g. cargo install jj-cli) works again
        after all versions of the bisync crate, a transitive dependency of gix,
        were yanked.

      • Signatures on commits in SHA-256 Git repositories are now stored under the
        gpgsig-sha256 header, as Git does, so Git recognizes them as signed and
        jj can read them back.

      Contributors

      Thanks to the people who made this release happen! This list includes the contributors to v0.45.0.

    9. πŸ”— r/LocalLLaMA Apparently ChatGPT, Claude, and Grok were down rss

      Apparently ChatGPT, Claude, and Grok were down | submitted by /u/mailto_devnull
      [link] [comments]
      ---|---

    10. πŸ”— r/LocalLLaMA Introducing K2 Horizon: Frontier Performance, Radically Open rss
    11. πŸ”— backnotprop/plannotator v0.27.12 release

      Follow @plannotator on X for updates

      Missed recent releases? Release | Highlights
      ---|---
      v0.27.11 | OpenCode server leak fix, durable local feedback archive, unknown-subcommand fix
      v0.27.10 | Auto-viewed files on scroll, annotation undo/redo, OpenCode 2 slash commands restored, npm 12 agent terminal fix
      v0.27.9 | WebMCP browser-agent tools, HTML refresh from disk, host seams, lazy renderers, Windows uninstall fix
      v0.27.8 | Pi keeps its prompt cache across plan transitions, thumbs-up returns to HTML annotation, embed picker seam
      v0.27.7 | Pi host crash fix on Windows, Call Flow tree cap, jj fork-point base, plannotator knowledge skill + llms.txt
      v0.27.6 | Live app annotation lands on Pi, one interaction model for HTML pages
      v0.27.5 | Annotate your running app, Agent TUI placement, collapsed lockfiles, VS Code theme fix
      v0.27.4 | Portable Guided Review exports, guides.show share links, guide CLI, jj Call Flow
      v0.27.3 | Folder watcher freeze fix on large repos, first SBOM-attested release pipeline
      v0.27.2 | Mobile plan and code review, Codex CLI 0.147 fix, configurable markdown extensions
      v0.27.1 | Open-in-editor launch fix, file headers respect Viewed/Git-add visibility toggles
      v0.27.0 | Call Flow analysis, --tailscale remote reviews, Pi rebuild, focus-mode shortcut

      What's New in v0.27.12

      The largest release of the 0.27 line: seven pull requests, two of them from community contributors, one a first-time contribution. The headline is a rebuilt decision header across every review surface, alongside a new hover card for code symbols and a set of community fixes. Every change went through independent adversarial review, and the release was gated by a 26-agent QA sweep before tagging.

      One decision control across every surface

      The header buttons for finishing a review grew organically over the years and ended up inconsistent: annotate showed different buttons than code review, approve sat next to send feedback where a stray click could pick the wrong one, and some finishing actions only existed as keyboard shortcuts. This release replaces all of it with a single adaptive control.

      Every annotate surface and both code review destinations now show one primary action that reflects your session: Done (or Approve where approval is real) when there is nothing to send, Send Feedback with a count once there is. The alternate decisions live behind a caret: send with a note (the menu morphs into a composer in place), request changes with overall feedback, and an explicit discard path behind a single confirmation. Approve and send feedback never render side by side anywhere. Cmd+Enter always fires exactly what the visible primary says.

      Approving with notes now actually works. Previously, notes attached to an approval were silently discarded by every runtime. Approvals that carry notes are delivered to your agent with clear framing that they are non-blocking guidance, not a change request. The capability is advertised by the server, so older components fail closed instead of dropping your words. The review sidebar also gains a "+ General comment" button for review-level comments that are not tied to a line, and the local feedback archive now records whether a comment was review-level or line-level.

      A few behavior changes worth knowing: bare approvals no longer send the old "LGTM - no changes requested." placeholder text, approving despite open annotations is now an explicit two-step (caret, then confirm) instead of a dimmed one-click button, and pressing Escape on an open header menu closes just the menu instead of also triggering whatever Escape used to do underneath.

      The design came directly from community feedback asking for overall review comments, an integrated global comment field, and a fast "that's fine" path for message annotation. #1458

      Hover cards for code symbols

      Rest your pointer on an identifier in a code review diff and Plannotator shows a card: the symbol's kind, a best-effort signature, its doc comment, where it is defined, and a sample of references, each linking into the References panel. Everything is powered by the same ripgrep search that backs Cmd+click, so there is nothing to install and nothing indexes your repo. If ripgrep is missing or the answer is weak, the card simply does not appear.

      Because hover affordances are personal, the first review after updating shows a one-time introduction with a live try-it: hover the demo token inside the dialog and the real card opens against it. Choose your trigger right there: on hover (the default, matching the VS Code hover delay of 300ms), only while holding Cmd (Ctrl on Windows and Linux), or off. A delay setting offers faster and more relaxed dwell times. Everything lives in Settings under the Editor tab, and anyone who had turned the earlier experimental toggle off stays off without seeing the dialog.

      The References panel also moved: Cmd+click and card links now open it beside the diff instead of splitting below it, so it stops stealing vertical room from the code you are reading. #1461, #1462, #1465

      Compare your local branch with its remote

      A new "Local vs remote branch" diff type answers the question "what would I push right now?": local commits the remote does not have, staged and unstaged edits, and untracked files, all compared against the branch's configured remote-tracking ref from your last fetch. It resolves the upstream properly rather than assuming an origin branch of the same name, only appears when the branch actually has an upstream, and shows a clear empty state when local and remote match. It never touches the network; fetching mid-review raises the existing refresh banner.

      Contributed by @leoreisdias, whose implementation carried both server runtimes, the settings integration, and a genuinely thorough test suite including a real bare-remote integration test. #1451

      OpenCode: the session URL notice can no longer burn a model turn

      On recent OpenCode 2 betas, the "Plannotator session ready" notice posted into the transcript could wake a model turn on its own, burning tokens while the reviewer was still annotating, with the real feedback then queued behind that spurious turn. The notice is now sent with explicit queue delivery, the same mechanism feedback already uses, so it renders in the transcript and waits for a genuinely user-initiated turn no matter how the host behaves.

      Reported by @Naasha with an unusually well- researched diagnosis that correctly identified the upstream mechanics, closing #1459. #1460

      Additional Changes

      • Skill fix for file approval : the installed agent skills now instruct agents to use --gate --json when a user asks to approve a saved plan or document, so an agent can no longer promise an Approve button that plain annotate does not render. Contributed by @zhangjinzan1 in their first contribution, complete with a freshness test that keeps the guidance from drifting. #1453
      • Insecure-context fix : note and comment ids are minted through a fallback-safe generator, so remote-mode sessions served over plain http can no longer lose a typed note to a missing crypto.randomUUID.
      • Escape discipline : header menus and popovers consume the Escape that dismisses them, and vim navigation defers to open popovers, so one keypress does one thing.

      Install / Update

      macOS / Linux:

      curl -fsSL https://plannotator.ai/install.sh | bash
      

      Windows:

      irm https://plannotator.ai/install.ps1 | iex
      

      Claude Code Plugin: Run /plugin in Claude Code, find plannotator , and click "Update now".

      Pi: Update @plannotator/pi-extension to 0.27.12 and restart Pi.

      OpenCode: Clear cache and restart:

      rm -rf ~/.bun/install/cache/@plannotator
      

      What's Changed

      • feat: unified decision control across annotate and code review in #1458
      • feat(review): token hover cards, Tier 0 in #1461
      • feat(review): hover card trigger settings and first-run introduction in #1462
      • feat(review): compare local branch with remote by @leoreisdias in #1451
      • fix(opencode): queue-deliver the session URL notice by report from @Naasha in #1460
      • fix(review): open the References panel beside the diff in #1465
      • docs(skills): require gate for file approval by @zhangjinzan1 in #1453

      New Contributors

      Community

      @leoreisdias returned with the local-vs- remote diff mode, an implementation clean enough that our adversarial review's only required change was a regenerated build manifest, and they fixed the review's optional suggestions before we finished writing them up. @zhangjinzan1 caught a real footgun in the installed skills, diagnosed exactly why an agent following them would promise an approval it could not deliver, and shipped the fix with a drift-proof test in a first contribution that merged as written. @Naasha filed one of the best bug reports this project has received, tracing a token-burning notice on OpenCode 2 betas down to the exact upstream wake semantics.

      The unified decision control itself is community-driven: it exists because users kept asking for overall review comments, an integrated global comment field, and a faster way to say "that's fine" - and because one of you told us you never wanted to see Approve sitting next to Send Feedback again.

      Thank you. Plannotator gets better because you tell us where it falls short.

      Full Changelog : v0.27.11...v0.27.12

    12. πŸ”— r/LocalLLaMA It's official! Nvidia to acquire Hugging Face for 12.9 billion dollars. rss

      It's official! Nvidia to acquire Hugging Face for 12.9 billion dollars. | submitted by /u/SarcasticBaka
      [link] [comments]
      ---|---

    13. πŸ”— r/LocalLLaMA My RULE of Thumb of choosing a models rss

      My RULE of Thumb of choosing a models | This is mostly for setting up for expectation, since personally without LLM i could take 3 days (15 hours of active programming) to debug or implement a feature, but with Qwen 27B (even before Qwen 3.8) it take 4 hours. And yes 0.5 tok/s is human, not accounting of deletion and pausing, that's also the reason i am fine leaving overnight code base wide analysis or fin tech and deep research. submitted by /u/Altruistic_Heat_9531
      [link] [comments]
      ---|---

    14. πŸ”— jj-vcs/jj v0.45.0 release

      About

      jj is a Git-compatible version control system that is both simple and powerful. See
      the installation instructions to get started.

      Release highlights

      • A new jj converge command was added to help automatically resolve divergent
        commits by combining them appropriately.

      Breaking changes

      • jj config {edit,set,unset} --user now targets the first loaded user
        configuration file (e.g. ~/.config/jj/config.toml or the first file in
        conf.d/) instead of prompting interactively when multiple files exist.
        Use --file <PATH> to target a specific config file.

      • jj git import in non-colocated repositories no longer imports commits from a
        detached Git HEAD branch.

      Deprecations

      None

      New features

      • The new jj converge command attempts to automatically resolve divergence by
        creating a new commit that replaces the divergent commits. It applies
        heuristics to try to automatically come up with a good solution, and falls
        back to prompting the user if the heuristics are inconclusive. It can also run
        in non-interactive mode, which aborts if prompting would be needed.

      • jj bisect will now mention when it cannot unambiguously find the first bad
        revision due to skips in evaluation.

      • Git HEAD state is now tracked per worktree internally. This prepares
        colocated repositories for support of multiple Git worktrees, where each
        jj workspace can have its own Git HEAD. Existing repositories are migrated
        automatically.

      • jj config {edit,set,unset} now support a --file <PATH> option to
        target a specific configuration file (such as files inside a conf.d/
        directory or loaded via --config-file). This allows precise file targeting
        and avoids interactive prompts when multiple config files exist.

      Fixed bugs

      • The default immutable_heads() set
        now includes untracked_remote_tags().

      • jj arrange now scrolls the viewport to keep the selected commit visible
        when the commit stack is taller than the terminal.
        #9033.

      • The default pager flags now include -K (--quit-on-intr), so pressing
        Ctrl+C in less exits cleanly instead of leaving the terminal in a
        corrupted state (raw mode, visible escape sequences, broken input).

      • A side of a conflict whose contents end with a carriage return no longer loses
        that byte when the materialized conflict is parsed back, such as when a
        conflicted file is snapshotted from the working copy.
        #9868

      • In colocated workspaces, jj workspace update-stale now correctly resets the
        Git HEAD to the parent of the fresh working-copy commit.
        #9936

      • jj run no longer runs against the remaining revisions if a process exits
        with a nonzero exit code.

      • Fixed crash in jj log involving hidden revisions and the
        log-graph-prioritize revset.
        #9975

      • In colocated repos, an external git add after a jj command no longer
        produces a tree with duplicate entries (git fsck: duplicateEntries). jj
        was leaving a stale cache-tree behind in .git/index. Repositories already
        corrupted this way are not repaired by the fix.
        #9711
        #8884

      Contributors

      Thanks to the people who made this release happen!

    15. πŸ”— modem-dev/hunk v0.21.0 release

      Hunk 0.21 β€” secure sessions, threaded reviews, richer comparisons

      Upgrade for threaded agent conversations, safer live sessions across restarts and upgrades, and exact revision or file comparisons across Git, Jujutsu, and Sapling.

      # Existing managed installs
      hunk update 0.21.0
      
      # npm installs
      npm install -g hunkdiff@0.21.0
      

      Threaded reviews and safer live sessions

      Inline notes are now editable conversations: continue a discussion with nested replies, edit notes, use mouse or keyboard actions, and dismiss agent notes that no longer need attention. Session clients can also navigate straight to a comment by ID. #925 #845

      The local session broker now authenticates producers and CLI controls, bounds unauthenticated work, and prevents stale connections from regaining authority. When an incompatible older daemon becomes idle, open Hunk windows reconnect automatically instead of trusting or force-killing it. #932 #933 #955

      Compare the exact changes you mean

      hunk diff <from> <to> now performs backend-native two-revision reviews across Git, Jujutsu, and Sapling. Use hunk diff --files <left> <right> for an explicit two-file comparison; source expansion stays pinned to the selected endpoints instead of leaking in working-copy state. Jujutsu reviews also gain unchanged-context expansion. #938 #890

      Faster reviews at every terminal size

      The files sidebar now grows from a compact projection into a full tree as space becomes available, while panes resize without giving up split review. The stream fills immediately on first paint, and large reviews recover responsive scrolling. Diff accents and word highlights are also more faithful across roughly 25 bundled themes. #921 #924 #922 #942 #825 #828

      Navigation is steadier too: explicit top and bottom jumps now win over pending reveals, and Ctrl-D/Ctrl-U provide familiar half-page movement. #928 #855

      For extension authors

      Extensions can register generic top-level CLI command trees, react to hunk_viewed and note_changed, follow the current source line, handle pane activation, size panes fractionally, and select syntax highlighting by filename or globβ€”so commands and panes can stay synchronized with the active review. #888 #939 #940 #965 #851

      Compatibility notes

      • npm users: installation now requires Node.js 22 or newer. Standalone Hunk binaries still run without Node.js. #917
      • Bun/watch-mode users: watch mode refuses Bun versions older than 1.3.14 because those runtimes can deadlock during filesystem-watcher cleanup. #902
      • OpenTUI embedders: reusable component consumers must use @opentui/core and @opentui/react 0.5.6 or newer. #914
      • curl-installer users: installation now refuses conflicting Hunk binaries unless explicitly forced and explains how to remove the competing install. #960
      • Extension authors: API generations 12 and 14 add fractional pane sizing and structured rangeEndpoints. These are additive capabilities, not required migrations. #924 #938

      Community contributors

      • @NiqhtFire made Hunk exit cleanly when its hosting terminal disconnects. #724
      • @nightcityblade completed synthetic key event data for command matchers and programmatic handlers. #774
      • @masonmcelvain restored faithful diff accents and word highlighting across bundled themes. #825 #828
      • @Ajay-Satish-01 added configurable spacing between files and hunks. #865
      • @Yuki9814 added direct live-review navigation to comments by ID. #845
      • @samuela enabled unchanged-context expansion for Jujutsu reviews. #890
      • @marmitar added pacman/AUR install detection and update-notice behavior. #850

      All merged pull requests

      PRs#889, #893, and #894 were also released in v0.20.1 through the 0.20.x maintenance branch.

      Release notes : https://hunk.dev/changelog/0.21/
      Full changelog : v0.20.1...v0.21.0

    16. πŸ”— Rust Blog Announcing Rust 1.98.1 rss

      The Rust team has published a new point release of Rust, 1.98.1. Rust is a programming language that is empowering everyone to build reliable and efficient software.

      If you have a previous version of Rust installed via rustup, getting Rust 1.98.1 is as easy as:

      rustup update stable
      

      If you don't have it already, you can get rustup from the appropriate page on our website.

      What's in 1.98.1

      Rust 1.98.1 fixes a miscompilation in vtable generation.

      In Rust 1.98.0, in some circumstances, rustc would incorrectly generate a trait object vtable with a null pointer where a function pointer should be. This leads to undefined behavior in the emitted code. In some cases this may 'just' cause segfaults due to the null pointer being loaded, but it is possible for it to be justification for arbitrary effects (as is typical for UB).

      If you'd like to help us out by testing future releases, you might consider using the beta (rustup default beta) and nightly (rustup default nightly) channels locally and in your CI. Please report any bugs you might come across!

      Contributors to 1.98.1

      Many people came together to create Rust 1.98.1. We couldn't have done it without all of you. Thanks!

    17. πŸ”— Console.dev newsletter llgo rss

      Description: Go compiler based on LLVM.

      What we like: Source remains compatible with Go, but uses the C Application Binary Interface (ABI) to allow interfacing with other languages (JS, Python, C/C++). FFI performance without FFI. Supports the latest Go 1.27 syntax and cgo, but without cgo. Goroutines map to OS threads. Native, Wasm, and embedded targets.

      What we dislike: Goroutines map to OS threads, which are heavier than lightweight goroutines. Garbage collection is more conservative and different per target, so it needs benchmarking vs pure Go.

    18. πŸ”— Console.dev newsletter Tailcat rss

      Description: Tailscale without Tailscale.

      What we like: Uses Tailscale’s data plane without using the control plane i.e. connect endpoints without needing a Tailscale account. No IPs, no users, no controls - great for direct connectivity. Works as a CLI or a Go package.

      What we dislike: You have to run your own DERP server for true Tailscale independence.

    19. πŸ”— Filip Filmar rules_vivado: FPGA Synthesis and Place-and-Route in Bazel rss

      rules_vivado drives the AMD/Xilinx Vivado FPGA toolchain from Bazel: compile, simulate, synthesize, place-and-route, generate a bitstream, and program the device, all as ordinary build actions instead of clicks in a GUI or a pile of ad-hoc TCL. This post kicks off a series on the Bazel modules behind cocoapuffs-fpga, the SoC repo from the Zircon-on-FPGA bring-up. I have covered some modules before (rules_ghdl, rules_shar, fshlib, bazel-ebook, and build-in-docker); the coming posts cover the rest: this one, then grlib, rules_fusesoc, rules_vunit, rules_dtc, vhdl_ls_gen, OpenSBI, and rules_osvvm.

    20. πŸ”— New Music Releases Above & Beyond - Quicksand (Don’t Go) (The Remixes) rss

      Above & Beyond - a new release is available:

      • 2026-09-03: Quicksand (Don’t Go) (The Remixes) (EP)

      Amazon: Canada | Deutschland | France | United Kingdom | United States

      Visit muspy for more information.