Sign in

Sungbin Jo

@goranmoomin.dev
473 followers 100 following 256 posts

interested in programming languages and low-level system programming. an emacs user. profile image not me.

PostsRepliesMedia
Sungbin Jo @goranmoomin.dev · 05/07/2026
ouch this hurts… i guess i can claim a status on this one :)
A coding agent session, with the model set as (anthropic) claude-fable-5, with the following text:

[user] look at @PLAN.md and try to figure out if there's anything that you feel is off or something that you would do differently. is there any feedback that you would give?
[assistant] I need to check the PLAN.md file to understand what I'm working with.
[assistant] read ~/Developer/Personal/melon/PLAN.md
[assistant] Error: This request triggered restrictions on violative cyber content and was blocked under Anthropic’s Content Usage Policy. To learn more, see https://platform.claude.com/docs/en/build-with-claude/refusals-and-fallback.
010
Sungbin Jo @goranmoomin.dev · 22/06/2026
It's pretty funny to look at thinking traces from kimi k2.7 code: it thinks like Kevin's small talk from The Office: www.youtube.com/watch?v=_K-L.... One of the features of kimi-k2.7-code was optimized thinking (platform.kimi.ai/docs/guide/k...), and it seems the model got trained caveman speak :)
A screen capture of a coding agent session, showing Kimi K2.7 Code's thinking trace and tool calls with the following text:

```
Let's check if the local branch exists. git branch maybe. We can list.

$ git branch -a | grep format

chore/format-ci-check

Took 0.0s


Local branch exists. Good.

We should not push or delete without confirmation. The user said not to push. We can ask whether to delete the local branch. But they want how to test. We can explain.
```
000
Sungbin Jo @goranmoomin.dev · 21/06/2026
I do hate Apple's software lockdown policies on iOS, but then I also see the Apple-enforced Privacy Requirements of browser engines, and then maybe Apple does have a point… Still, Apple could have just opened BrowserEngineKit on all regions, which would have saved a lot of grace… around this
A screen capture of a section of the https://developer.apple.com/support/alternative-browser-engines-jp webpage with the following text:

##### Program privacy requirements

You must:

- Block cross-site cookies (i.e., third-party cookies) by default unless the user expressly opts to allow such cookies with informed consent, or as required for compatibility in the case of popup windows that interact with frames in their opening window;
- Partition any storage or state observable by websites per top-level website, or block such storage or state from cross-site usage and observability;
- Not sync any state (including cookies) between your app and any other app, even another app from the same developer, unless the user has explicitly given permission for the state to be synced, either by signing into both your app and the other app, or through another mechanism of providing explicit permission;
- Not share device identifiers with websites without informed consent and user activation;
- Label network connections using the APIs provided to generate an App Privacy Report on iOS (i.e., wherever your app is distributed); and
Follow commonly adopted web standards on when to require informed user activation and/or user consent, as appropriate for web APIs (e.g., clipboard or full screen access), including those that provide access to PII.
020
Sungbin Jo @goranmoomin.dev · 30/05/2026
with the magic of react native and react-native-macos, some amount of porting and some amount of coding agent usage allows us to run the official bluesky react native client on macos with no code modifications from the react app :) not native looking at all yet, but that's a future step ofc
110
Sungbin Jo @goranmoomin.dev · 29/05/2026
the thinking summarization model is going crazy with a short thinking section from opus 4.7 (medium) :)
A screenshot of a pi.dev coding agent session, with the user requesting: lol no never mind please just replace it to ignore and the model thinking summarized by it's thinking summarization model as:
I don't have any current rewritten thinking to work with, and the next thinking to rewrite just says "Swap back." which is too vague for me to meaningfully rewrite into natural inner monologue.
Could you provide:
1. The original thinking that needs to be rewritten
2. Clarification on what "Swap back" refers to in context
Once I have the actual thinking content, I'll rewrite it as natural first-person inner monologue following all the guidelines.
following an edit to the file ~/.emacs.d/init.el by the main model.
000
Sungbin Jo @goranmoomin.dev · 09/06/2025
i could not resist, i updated my main device to ios 26 on the first day… and it’s burning through battery like crazy lol
030
Sungbin Jo @goranmoomin.dev · 09/06/2025
the fact that the window rounded corners’ radius doesn’t match with the traffic lights annoy me immensely… eww
030
Sungbin Jo @goranmoomin.dev · 09/06/2025
#wwdc25 seems like ipad finally gets an actual honest-to-god windowing system with menu bars, traffic lights, and everything
010
Sungbin Jo @goranmoomin.dev · 09/06/2025
#wwdc25 seems like ipados 25 also has an actual windowing system (finally)? www.apple.com/newsroom/202...
The powerful and intuitive new windowing system lets users fluidly resize app windows, place them exactly where they want, and open even more windows at once.
010
Sungbin Jo @goranmoomin.dev · 26/04/2025
as per xkcd.com/386/: someone is *wrong* on the internet.
A screenshot of a comment on the HackerNews website submission “Apparently Bluesky has one centralized service, the "relay"”, which reads below:

i don’t actively contribute to Bluesky nor Fedi (i do consume content from both), but it’s pretty frustrating to see BlueSky being argued into a centralized service for the recent downtime.
- The downtime was not relay level, but it was a PDS level. So the point is moot already.
- Because it was decentralized at the PDS level, the outage did not affect anyone with personal PDSes, which contains the data that you care about.
- Even if it was the relay level, relays aren’t centralized, anyone can spin up another relay (because everything on the relay is derived from PDS data). It’s just that it’s going to be pretty expensive and consume much resources. Which is a fair point, and might be argued that the network currently has a single big point of failure, but that doesn’t mean it’s centralized.
And then people now start arguing that the fact that BlueSky-hosted PDSes went down at the same time is now another proof that BlueSky is centralized?
That’s like arguing that Gmail can go down and all @gmail.com mail addresses won’t work, so email is centralized. Or AWS can have an outage and all AWS-powered websites will break down, so the web is centralized.
One can say that there’s a single big point of failure (which the BlueSky LLC is, just like AWS, Gmail, or the mastodon.social instance in the case of Fedi), but that doesn’t make the whole service centralized.
010
Sungbin Jo @goranmoomin.dev · 24/04/2025
it’s scarily capable — both openai’s o3 and claude 3.7 sonnet with thinking can go through whole chunks of javascript, figure out which module id corresponds to what logic, and can explain the logic with unminified, prettified names. actually pretty useful, i’ve confirmed that they are correct.
A screenshot of ChatGPT’s o3 model with a table called Bundle overview that matches the Logical name, Original module id, and the Purpose of the module.A screenshot of Claude 3.7 Sonnet with it’s thinking process open, with the following text:

The key insight here is that the entropy is split into two shares (using Shamir's Secret Sharing):
1. One share is stored locally on the device (through l. A which is likely a storage class)
2. Another share is retrieved from the server through an API call (c.u)
3. Both shares are needed to reconstruct the original entropy
This is a robust security approach where neither the client nor the server has the full key, but they must cooperate to reconstruct it.
Let me look at the imported modules to understand more details:
• L.A (from module 33230) seems to be a storage class that handles storing and retrieving wallet shares
• c.u (from module 46871) is likely an API call function to retrieve the server share
• n.k (from module 94928) seems to be the function that combines Shamir shares
• o.st, o.Ay, o.Wi, 0.kG (from module
27510) are wallet creation functions using different entropy typesAnother screenshot of Claude 3.7 Sonnet explaining a minified function in prettified form.

exports. JG = getWalletInstance;
// Retrieve wallet instance (our
main function of interest)
exports._U = upgradeWalletRecovery;
// Upgrade wallet recovery method

The getWalletInstance
Function (Previously Named m)

This is the function we've been looking for! It retrieves or creates a wallet instance based on the provided parameters:
/**
* Retrieves or creates a wallet instance based on specified parameters
* @param {Object} params - Parameters for wallet retrieval
* @returns {Object} Wallet instance with metadata
* /
async function getWalletInstance (params) i
// Extract parameters from
input
const {
151
Sungbin Jo @goranmoomin.dev · 23/04/2025
i had a friend buy me a 4-inch, used iphone se over from a trip to japan (it was 4000 yen), and it feels super weird to hold this tiny, tiny phone (by current standards). almost feels like i’m back in an alternative 2016.
a screenshot of the bluesky app post editor, running on iPhone SE with a 4-inch screen.
010
Sungbin Jo @goranmoomin.dev · 23/02/2025
genuinely curious: why would ‘randomly relink kernel on every boot’ be a mitigation to anything? isn’t it the case where if you can jump a kernel address anyway, that’s pretty much shoot, no? (it’s the openbsd innovation page, if anyone’s interested: www.openbsd.org/innovations....)
trapsleds: Reduction of incidental NOP
instructions/sequences in the instruction stream which could be useful potentially for ROP attack methods to inaccurately target gadgets. These NOP sequences are converted into trap sequences where possible. Todd Mortimer and Theo de Raadt, June 2017.
Kernel relinking at boot: the .o files of the kernel are relinked in random order from a link-kit, before every reboot. This provides substantial interior randomization in the kernel's text and data segments for layout and relative branches/calls.
Basically a unique address space for each kernel boot, similar to the userland forktexec model described above but for the kernel. Theo de Raadt,
June 2017.
110
Sungbin Jo @goranmoomin.dev · 21/02/2025
finally apple intelligence coming in korean (in early april). finally!
Apple Intelligence를 위한 탄생.
Apple Intelligence, 4월 초 한국어 지원 예정
010
Sungbin Jo @goranmoomin.dev · 10/02/2025
i know that i did probably not write a good prompt to begin with, but it does seem that the claude model seems to be biased too much towards react code… i did not expect a react component from asking a way to check health for disks.
A Claude conversation that goes on as below:

q: how can i check the health of specific disks?
a: I'll help you create a script to check disk health. Here's a React component that can display disk health metrics:
<Disk Health Monitor>
This component creates a visual dashboard for monitoring disk health. Here's what it tracks:

Storage usage with a visual progress bar that changes color based on capacity
Disk temperature with warnings for high temperatures
Error count tracking
Read and write speeds
Overall disk health status with warnings for potential issues

The component uses color coding to make it easy to spot potential problems:

Green: Good/normal conditions
Yellow: Warning conditions that need attention
Red: Critical conditions (like very high storage usage)

To get real disk health data, you'd need to connect this component to system monitoring tools that can provide actual disk metrics. Common tools for collecting this data include:

[the remaining conversation is not visible]

On the right, the claude artifact displays a webpage that displays a list of hardcoded storage usage, temperature, error count, i/o speed, and the total status of the two disks.
020
Sungbin Jo @goranmoomin.dev · 04/02/2025
Am I going crazy or is the kerning between Y and e of the Yeah seems to be wrong? This is the official Bluesky client, up-to-date. Seems like something is off with the fonts…
A screenshot of quoting a post with ‘Yeah I really want to see’, with the kerning between Y and e seemingly be too wide.
010
Sungbin Jo @goranmoomin.dev · 08/01/2025
my macos/emacs experience shows
Which Ctrl- keyboard shortcuts do you use in your terminal?

[x] Ctrl-C (quit)
[x] Ctrl-Z (suspend)
[x] Ctrl-R (search history)
[ ] Ctrl-L (clear screen)
[x] Ctrl-D (EOF)
[x] Ctrl-A (beginning of line)
[x] Ctrl-E (end of line)
[x] Ctrl-W (delete word)
020
Sungbin Jo @goranmoomin.dev · 02/01/2025
Just from the screenshots, the settings screen scream obviously Electron. I don’t have a way to really articulate it but from the screen layout, the margins and paddings of the tab titles, the thin titlebar, and the white background color of each tab all feel very… webby and not native at all.
010
Sungbin Jo @goranmoomin.dev · 27/12/2024
That was fast… shout out to Screens! edovia.com/en/screens/
Edovia Support (Edovia Helpdesk)
Dec 27, 2024, 11:53 EST

Hi Sungbin Jo,

Thanks for your inquiry!

Just to let you know that we found the issue and Screens 5.4.9 should be available soon. We'll let you know when the version is available.

Sorry for the inconvenience and thank you for your patience.

Have a wonderful day!
 
—
 
Timothy
Edovia Support
	
Goranmoomin
Dec 27, 2024, 11:03 EST

Hello!

I’d like to report a bug in Screens 5 when using my iPad's hardware keyboard.

The hardware arrow keys are sending wrong key events (or at least different key events from the software arrow keys on screen) via VNC, when connecting to a Wayland compositor. Instead of sending the expected Up keypress (key 111, sym 65362), it is sending a Shift modifier followed by a ‘U’ keypress (key 30, sym 85).

This makes it impossible to use arrow keys for navigation in apps like VSCode, Cursor, and Firefox since they just type 'U' instead of moving the cursor. The same problem happens with other arrow keys and the ESC key too.

The following is output from the Wayland event viewer (wev) between the two:

Software arrow key:

[21: wl_keyboard] key: serial: 331; time: 0; key: 111; state: 1 (pressed)
sym: Up (65362), utf8: ''
[19: wl_keyboard] key: serial: 331; time: 0; key: 111; state: 1 (pressed)
sym: Up (65362), utf8: ''
020
Sungbin Jo @goranmoomin.dev · 04/12/2024
Wait… is #github down?
A GitHub screenshow with the following contents:
 
[unicorn image]

We couldn't respond to your request in time.

Sorry about that. Please try refreshing and contact us if the problem persists.

Contact Support — GitHub Status — @githubstatus
000
Sungbin Jo @goranmoomin.dev · 02/12/2024
yeah so i first created my account with the picopds/create_identity.py script (when first trying to use picopds): github.com/DavidBuchana... and it generated the privkey.pem file for me. i then created the account with all of the info when moving to millipds: as in the screenshot.
sungbin@sungbin-macmini:~/millipds$ uv run millipds account create did:plc:ilbuexsezfgfn6ospjcpkupt test00.dev.goranmoomin.dev --unsafe_password=[redacted] --signing_key=../picopds/privkey.pem
WARNING: passing a password as a CLI arg is not recommended, for security
INFO:millipds.database:creating account for did=did:plc:ilbuexsezfgfn6ospjcpkupt, handle=test00.dev.goranmoomin.dev
110
Sungbin Jo @goranmoomin.dev · 02/12/2024
i'm logging the outbound jwt that i'm sending to the appview, and from logging it does seem that it's being signed by the correct key, and that the corresponding public key is uploaded to plc.directory/did:plc:ilbu... – though tbf i'm failing to validate the jwt in jwt.io.
sungbin@sungbin-macmini:~/millipds$ uv run millipds config
db_version        : 1
pds_pfx           : 'https://pds.dev.goranmoomin.dev'
pds_did           : 'did:web:pds.dev.goranmoomin.dev'
bsky_appview_pfx  : 'https://api.bsky.app'
bsky_appview_did  : 'did:web:api.bsky.app'
jwt_access_secret : '[REDACTED]'
210
Sungbin Jo @goranmoomin.dev · 02/12/2024
so i'm assuming that the jwt error is coming from: github.com/bluesky-soci... which is prob being called from github.com/bluesky-soci... millipds signs a new jwt when proxying to the appview with the right key. so error is prob that bsky is failing to validate them from the keys from plc.directory?
@authenticated
async def static_appview_proxy(request: web.Request):
	lxm = request.path.rpartition("/")[2].partition("?")[0]
	# TODO: verify valid lexicon method?
	logger.info(f"proxying lxm {lxm}")
	db = get_db(request)
	signing_key = db.signing_key_pem_by_did(request["authed_did"])
	authn = {
		"Authorization": "Bearer "
		+ jwt.encode(
			{
				"iss": request["authed_did"],
				"aud": db.config["bsky_appview_did"],
				"lxm": lxm,
				"exp": int(time.time()) + 60 * 60 * 24,  # 24h
			},
			signing_key,
			algorithm="ES256",
		)  # TODO: ES256K compat?
	}  # TODO: cache this!
	appview_pfx = db.config["bsky_appview_pfx"]
	if request.method == "GET":
		async with get_client(request).get(
			appview_pfx + request.path, params=request.query, headers=authn
		) as r:
			body_bytes = await r.read()  # TODO: streaming?
			return web.Response(
				body=body_bytes, content_type=r.content_type, status=r.status
			)  # XXX: allowlist safe content types!
	elif request.method == "POST":
		request_body = await request.read()  # TODO: streaming?
		async with get_client(request).post(
			appview_pfx + request.path, data=request_body, headers=(authn|{"Content-Type": request.content_type})
		) as r:
			body_bytes = await r.read()  # TODO: streaming?
			return web.Response(
				body=body_bytes, content_type=r.content_type, status=r.status
			)  # XXX: allowlist safe content types!
	elif request.method == "PUT":
		raise NotImplementedError("TODO")
100
Sungbin Jo @goranmoomin.dev · 19/10/2024
Was a tad surprising to me at least :)
Marcin Krzyzanowski followed you back
Thomas Ricouard followed you back
110
Sungbin Jo @goranmoomin.dev · 07/10/2024
I’m also just realizing that on the iPad with an external trackpad, a user’s feed doesn’t scroll if you try to scroll it on top of the user description (instead of the top of the posts list). I should know better and report bugs via proper channels, but just to let people know.
110
Sungbin Jo @goranmoomin.dev · 07/10/2024
I’m swiping the same short distance with the same speed & snap for the three apps, and the standard iOS gesture recognization seems to register but the sidebar of the bluesky app seems to bounce off. (Btw I’d love a draft feature in the app, just realized)
110
Sungbin Jo @goranmoomin.dev · 07/10/2024
One of the immediate things that felt ‘off’ to me was navigation. Like I have a video comparing the navigation stack with other apps — the top bar fades out (instead of sliding) and the previous screen should have a light shadow. The sidebar gesture recognizer also feels off…
220
Sungbin Jo @goranmoomin.dev · 21/09/2024
For now, I'm using the enchanted command below: ``` tar -cvzf - -C<srcdir> --no-xattrs --no-mac-metadata . | ssh <dstsrv> tar -xzf - -C<dstdir> ``` Note the flags --no-xattrs and --no-mac-metadata. The manpage is wrong, --no-mac-metadata does applies to c mode as well, not just x mode.
An excerpt of the tar(3) manpage on macOS.

     --no-mac-metadata
             (x mode only) Mac OS X specific.  Do not archive or extract ACLs
             and extended file attributes using copyfile(3) in AppleDouble
             format.  This is the reverse of --mac-metadata.  and the default
             behavior if tar is run as non-root in x mode.
000
Sungbin Jo @goranmoomin.dev · 21/09/2024
Can anyone using Homebrew (brew.sh) and on macOS Sequoia check whether `rsync` works? I'm using rsync v3.3.0 compiled via MacPorts, and it seems that the rsync I have is broken on Sequoia for some reason… Is this specific to MacPorts or is this a global thing?
3 consecutive executions of the command `rsync -avz dist/ sungbin-macmini:/srv/www/cosmo.goranmoomin.dev` failing.

The first failing error message is:

```
ssh: connect to host home.goranmoomin.dev port 8222: Undefined error: 0
rsync: connection unexpectedly closed (0 bytes received so far) [sender]
rsync error: error in rsync protocol data stream (code 12) at io.c(231) [sender=3.3.0]
```

The consecutive error messages are:

```
ssh: connect to host home.goranmoomin.dev port 8222: Undefined error: 0
rsync: connection unexpectedly closed (0 bytes received so far) [sender]
rsync error: unexplained error (code 255) at io.c(231) [sender=3.3.0]
```
000
Sungbin Jo @goranmoomin.dev · 18/09/2024
Building all of my 600 installed packages from source (as there are yet to be binary packages for Sequoia on MacPorts) on my MBP. Hopefully it doesn't take more than a few hours. This time though, MacPorts now finally has an automatic macOS upgrade/migration process (`sudo port migrate`)!
A screenshot of the MacPorts migrate progress, compiling packages.
010
Sungbin Jo @goranmoomin.dev · 18/09/2024
Call me annoyed. Forcing people to precisely place their apps is busywork to most. The majority doesn’t care the exact placing of apps… The iOS home screen is like an app drawer, we really shouldn’t be comparing it with Android. And, their app drawers don’t allow arbitrary icon placements as well.
000
Sungbin Jo @goranmoomin.dev · 18/09/2024
I'm disappointed with the iPhone mirroring feature… it turns out that it doesn't pass through keyboard layout changes. Which basically means for CJK people, it's unusable, period. The app is clearly made of the non-native (scaled to 70%) Catalyst, which is obvious with the blurry screen.
110
Sungbin Jo @goranmoomin.dev · 17/09/2024
Okay, so I'm seeing Ruby 2.6.10 and Python 3.9.6, but tbh the scripting languages might just be coming from the CLT. I have the CLT installed right now.
110
Sungbin Jo @goranmoomin.dev · 17/09/2024
macOS Sequoia ships /usr/bin/jq as a default binary! Horray :)
A screen capture of the terminal, consisting of the following text.

~ $ ls -la /usr/bin/jq 
-rwxr-xr-x  1 root  wheel  1376384 Sep  6 05:54 /usr/bin/jq
~ $ /usr/bin/jq --version
jq-1.6-159-apple-gcff5336-dirty
~ $ curl -sS 'https://api.github.com/repos/jqlang/jq/commits' | 
        /usr/bin/jq -r '.[:15][] | .sha[:7] + "\t" + .commit.message | split("\n")[0]'
860af44	Fix typos (#3173)
37f4cd2	Fix docs for `strptime(fmt)` (#3164)
6322b99	fix: find and source ~/.jq file on windows (fixes #3104) (#3114)
da2a0b9	mktime/0: remove unnecessary  length>=6  input requirement (#3162)
0e0cdd5	feat: uri decode function (#3161)
0b5ae30	Implement add/1 (#3144)
137018d	jv.h: define empty JV_{,V}PRINTF_LIKE macros if __GNUC__ is not defined
c1d885b	website: Make latest release (1.7) be default manual (#3130)
2ee20ca	Avoid ctype.h abuse: cast char to unsigned char first.
e2ffb53	build(deps): bump zipp from 3.16.2 to 3.19.1 in /docs
ba741e5	build(deps): bump docker/build-push-action from 5 to 6 (#3143)
120
Sungbin Jo @goranmoomin.dev · 17/09/2024
So I get that there are false positives, but are there false negatives as well? (Probably yes, I guess so…)
Data-race safety checks were previously available as warnings in Swift 5.10 through the -strict-concurrency=complete compiler flag. Thanks to improved Sendable inference and new compiler analysis for transferring mutable state from one actor to another, Swift 6 warnings about data-race safety have fewer false positives. You can find more information about the Swift 6 language mode and how to migrate at Swift.org/migration.
000