Sign in

Logan Magee

@lberrymage.dev
113 followers 94 following 65 posts

Christian and software developer focused on application and OS security. Creator of Accrescent.

PostsRepliesMedia
Reposted by Logan Magee
Accrescent @accrescent.app · 29/09/2026
How does a complex application like Accrescent manage its API? In this blog post, we discuss some of the API challenges we encountered and our journey to create a single source of truth: accrescent.app/blog/posts/a...
accrescent.app
A Tale of Too Many Protocols - Accrescent
Our journey through protobuf, gRPC, OpenAPI, and more to create a single source of truth for the Accrescent console API.
0142
Logan Magee @lberrymage.dev · 23/09/2026
Nearing 100% Lighthouse coverage for the deterministic (i.e., mostly non-perf) audits feels good
011
Reposted by Logan Magee
Accrescent @accrescent.app · 18/09/2026
Another day, another refresh! We've restyled and unified our website so that you can find everything Accrescent all in one place with one look, blog posts and documentation included. Let us know what you think! accrescent.app
accrescent.app
The private and secure Android app store - Accrescent
Accrescent is an Android app store focused on security, privacy, and usability.
1204
Logan Magee @lberrymage.dev · 17/09/2026
Apparently, it is very difficult to create an accessible, collapsible nav menu on the web without JavaScript. Recent browsers make it possible without hacks though. This was an interesting read: adrianroselli.com/2026/07/link...
adrianroselli.com
Link + Popover Navigation
This is a redress of my 2019 post Link + Disclosure Widget Navigation, except (as the title implies), I’ve modified it to use native HTML popovers instead of ARIA or HTML disclosure widgets. Popover h...
000
Logan Magee @lberrymage.dev · 12/09/2026
It's surprisingly simple to achieve much more complex styling if we want to without adding much more to the final CSS. Good tooling goes a very long way.
001
Logan Magee @lberrymage.dev · 12/09/2026
We rewrote it from scratch. The biggest wins come from not using bloated third-party theming, including fonts, styling, and JS. Also since we fully control the output now, we can add a very strict Content Security Policy once we get around to it.
100
Reposted by Logan Magee
Accrescent @accrescent.app · 12/09/2026
In anticipation of our upcoming blog posts, we've refreshed our blog! It's now simpler, smoother, smaller, and JavaScript-free. We'll be revising it gradually, so let us know what you think of the new design! Accessibility is especially important to us. blog.accrescent.app
blog.accrescent.app
Accrescent Blog
1263
Logan Magee @lberrymage.dev · 05/09/2026
I've really been enjoying @astro.build for static site generation. No JS by default but easy to add incrementally as desired, very customizable, doesn't break as often as Hugo, components, TypeScript/HTML-based templating is so much nicer than DSLs, easy optimized images, etc.
010
Reposted by Logan Magee
GrapheneOS @grapheneos.org · 29/08/2026
We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.
24632137
Logan Magee @lberrymage.dev · 29/08/2026
The refactoring will continue until morale improves
020
Logan Magee @lberrymage.dev · 28/08/2026
Hmm, maybe in the medium-to-long term. proto2 was released publicly in '08 though and used internally for a while before then while Go didn't hit 1.0 until 2012. And I'd just like to think Go isn't inspiring too many design decisions in other projects :)
000
Logan Magee @lberrymage.dev · 28/08/2026
Maybe I'm just conflating explicit presence with "this field is semantically optional" though. The migration back to default explicit presence in editions would make it seem so.
120
Logan Magee @lberrymage.dev · 28/08/2026
I guess I'm trying to distinguish between explicit `[default = x]` and implicit "", 0, false, etc. primitive defaults. To me, it seems natural to return the former from a getter, or even the latter for fields without presence tracking, but the latter for fields with presence is a bit unexpected.
220
Logan Magee @lberrymage.dev · 28/08/2026
Not sure how much of this is a historical artifact though. I can see how the presence changes from proto2 to proto3 to later proto3 to edition 2023 could make changing that API undesirable just for stability reasons for example. Or are primitive default "zero" values used more than I expect?
310
Logan Magee @lberrymage.dev · 28/08/2026
Although I think the getter makes sense, it does bother me how easy it makes it to forget about field presence. That is, stringField.get() will return "" for an unset value regardless of whether the field tracks presence, which feels odd when the schema says presence is meaningful.
330
Logan Magee @lberrymage.dev · 28/08/2026
I remember being excited at that RFC when you first posted it last year. One I should remember to follow along with
020
Logan Magee @lberrymage.dev · 28/08/2026
Hmm, I suppose you're right. I thought of this and forgot why it sounded problematic to me 😅. Seems oddly intentional though since they use enums for oneofs
120
Logan Magee @lberrymage.dev · 28/08/2026
I didn't initially like the ergonomics of the protobuf Rust API either, but my understanding is a lot of the non-idiomatic design choices are necessary to accurately reflect protobuf semantics (e.g., clear() being different depending on proto2/proto3/editions/field presence, gencode back compat)
130
Logan Magee @lberrymage.dev · 28/08/2026
I'm curious how else you would suggest they implement those features. For example, I think they implement enums that way to allow round-tripping unknown enum values, which other implementations support.
350
Logan Magee @lberrymage.dev · 25/08/2026
Software engineering is solved
A screenshot of a terminal opened to a git repository named android_platform_frameworks_base at HEAD (commit 94b4c16). The command "claude" has been run with an error, and the next terminal line says "zsh: segmentation fault (core dumped)  claude".
030
Reposted by Logan Magee
Accrescent @accrescent.app · 24/08/2026
We know it's been a long time since our last progress update, so to keep you more in the loop, we're switching to more frequent, smaller posts from now on. We're getting ever closer to opening up app submissions to everyone. Thank you all for your support and patience!
0254
Reposted by Logan Magee
Accrescent @accrescent.app · 24/08/2026
Progress update! We've been hard at work tackling Accrescent's most pressing development needs, and now we want to share what we've been working on. We'll post blog posts in the next few weeks detailing our security, stability, and feature progress along with what's next!
1233
Logan Magee @lberrymage.dev · 21/08/2026
Apparently getting Claude to write \u-escaped versions of Unicode code points in Kotlin string literals (as opposed to the literal Unicode characters) is very difficult. It'll keep retrying with literal code points, and when it doesn't do that, it'll use extra backslashes
000
Logan Magee @lberrymage.dev · 27/07/2026
It sounds like it's because there's precision loss that the libs team though should be more explicit (and the trait impls would be insta-stable). See github.com/rust-lang/ru... and some earlier comments on that thread.
github.com
Duration div mul extras by newpavlov · Pull Request #52813 · rust-lang/rust
Successor of #52556. This PR adds the following impls: impl Mul<Duration> for u32 (to allow 10*SECOND in addition to SECOND*10) impl Mul<f64> for Duration (to allow 2.5*SECOND vs 2*SEC...
140
Logan Magee @lberrymage.dev · 24/07/2026
Yeah I was aware of that one. I think it's very good at what it does in general and is quite useful for, e.g., single-tenant databases (such as in desktop applications). I've just been confused at the hype around it for use cases where I feel it has significant shortcomings
010
Logan Magee @lberrymage.dev · 24/07/2026
Then again, a significant reason I haven't been convinced by the broad "just use SQLite" arguments is its weak type system
110
Logan Magee @lberrymage.dev · 24/07/2026
> It has become a point of doctrine among many programmers that the best way to prevent application bugs is strict type enforcement. But I find no evidence in support of this. Wow. I wasn't aware of this article, but it surprises me a little that it comes from SQLite.
210
Logan Magee @lberrymage.dev · 10/07/2026
I'm reworking how Accrescent handles Android app versions, and it turns out that there's no consistent global ordering across all Android versions because of how Android composes longVersionCode and accepts negative versions 🫠. I don't think we need versionCodeMajor.
020
Reposted by Logan Magee
GrapheneOS @grapheneos.org · 16/06/2026
Today is the official release day for Android 17. We've already fully ported GrapheneOS to Android 17 and are in the process of pushing the code to our public repositories. We're building a final official release based on Android 16 QPR2 today and we'll do an initial Android 17 release tomorrow.
1020833
Reposted by Logan Magee
GrapheneOS @grapheneos.org · 02/03/2026
We're happy to announce a long-term partnership with Motorola. We're collaborating on future devices meeting our privacy and security standards with official GrapheneOS support. motorolanews.com/motorola-thr...
motorolanews.com
Motorola News | Motorola's new partnership with GrapheneOS
Motorola announces three new B2B solutions at MWC 2026, including GrapheneOS partnership, Moto Analytics and more.
691036240
Reposted by Logan Magee
David Buchanan @retr0.id · 09/02/2026
It's annoying how good discord is. Matrix is a nice idea, but janky in practice.
1936526
Reposted by Logan Magee
GrapheneOS @grapheneos.org · 02/12/2025
GrapheneOS is the only Android-based OS providing the full security preview patches. Samsung ships a small subset of their flagship devices. Pixel stock OS gets a portion of it early but we aren't sure exactly how much since they don't follow their guidelines for listing patches.
1222
Reposted by Logan Magee
Accrescent @accrescent.app · 25/11/2025
If you've wondered how Android developer verification affects Accrescent, today we have a new blog post explaining briefly what it is, how it impacts us, and how we're responding. blog.accrescent.app/posts/androi...
blog.accrescent.app
Accrescent and Android Developer Verification
Google recently announced that starting next year, Android will require all apps to be registered by verified developers for users to install them on their devices, i.e., all apps must be registered b...
0184
Reposted by Logan Magee
Accrescent @accrescent.app · 11/11/2025
It's time for an update! Check out our blog for a new update on: - What we've accomplished in the last 3 months - What's next for Accrescent Thank you to our supporters for making this possible! blog.accrescent.app/posts/road-b...
blog.accrescent.app
A Road Behind, A Road Ahead
Three months ago, we published an update on our development progress as well as our roadmap for the next three months and beyond. Now that those three months are over, we want to share the development...
0143
Reposted by Logan Magee
Accrescent @accrescent.app · 03/11/2025
Accrescent 0.28.0 is out, including: - Download cancellation support - Better update scheduling (especially on Android 14+) - UI improvements and bug fixes Full release notes below! github.com/accrescent/a...
github.com
Release 0.28.0 · accrescent/accrescent
This release adds a "cancel" button for downloads, provides better update scheduling (especially on Android 14+), and includes a handful of UI improvements and bug fixes. Changed Perform gentle up...
0151
Reposted by Logan Magee
Accrescent @accrescent.app · 24/10/2025
Accrescent 0.27.0 is here! This is the most significant release we've made to date: - New, stable app store API - Complete installer rewrite, resolving all known bugs - Tons of new features - More snappy, correct, & informative UI Check it out! 👇 github.com/accrescent/a...
github.com
Release 0.27.0 · accrescent/accrescent
Happy release day! This release is the most significant Accrescent release to date, marking our migration to a new, stable app store API; completely rewriting our core logic to resolve all known in...
092
Logan Magee @lberrymage.dev · 24/09/2025
...I suspected it had to do with URLs not being valid paths. That worked locally, but failed in our testing environment which has longer APK URLs. The final fix was to hash the APK URL to ensure the APK name is a constant length and thus always a valid file name.
000
Logan Magee @lberrymage.dev · 24/09/2025
For those curious, I actually came across this because Accrescent was using APK URLs as its APK names to uniquely identify them. Those URLs obviously aren't valid file names, so an exception is thrown (for no clear reason). I "fixed" it locally by hex-encoding the URLs since...
100
Logan Magee @lberrymage.dev · 24/09/2025
Another day of Accrescent, another AOSP bug report: issuetracker.google.com/issues/44717... You might say, "Why are you making file names more than 255 characters long? Do you really need to do that?" No, no I don't. But someone had to try.
issuetracker.google.com
Google Issue Tracker
100
Reposted by Logan Magee
Accrescent @accrescent.app · 24/09/2025
Development on our roadmap is progressing smoothly. Our next app and server releases are undergoing final testing before deployment. We hope to make an announcement soon about what Android's recently announced developer verification requirements mean for Accrescent. Stay tuned!
0151
Logan Magee @lberrymage.dev · 03/09/2025
0ver.org
0ver.org
ZeroVer: 0-based Versioning — zer0ver
Software's most popular versioning scheme!
010
Logan Magee @lberrymage.dev · 20/08/2025
Honestly I'm going the cloud-managed route right now and will probably use what's available there when I set up a standby instance. Costs more than DIY-ing it, but saves me enough hours that it feels like it's worth it to me in the end (and the easy IaC integration is a nice plus)
100
Logan Magee @lberrymage.dev · 20/08/2025
As in a high-availability configuration, replication, or something else? Right now I'm just using single-instance PostgreSQL and may add a standby instance in the future. Haven't figured out if I want/need additional read replicas yet to lower latency in other regions.
100
Logan Magee @lberrymage.dev · 20/08/2025
My experience has been similar with K8s. For all the complexity that's talked about (and I don't deny the setup hurdles), it's been quite comfortable for me to manage so far.
110
Reposted by Logan Magee
Accrescent @accrescent.app · 12/08/2025
Since we published our blog post on the future of Accrescent, donations have increased dramatically. According to the rates in that post, we should now be able to fund full-time development through at least May 2026! Thank you to our community for your monumental support!
1162
Reposted by Logan Magee
Accrescent @accrescent.app · 11/08/2025
Today is the day! Read all about our development progress, view our roadmap for the future, and check out the new projects we're releasing as open source in our new blog post! blog.accrescent.app/posts/progre...
blog.accrescent.app
Progress Update and Roadmap
In our recent post about Accrescent’s financial future and sustainability, we announced that to build trust and transparency with our community, we’d be publishing a follow-up blog post about what we’...
1111
Reposted by Logan Magee
Accrescent @accrescent.app · 10/08/2025
Keep an eye out for tomorrow's blog post! We'll be posting a development progress update for the past months and a roadmap for the next few.
0111
Logan Magee @lberrymage.dev · 04/08/2025
Thank you!
010
Logan Magee @lberrymage.dev · 04/08/2025
Thank you for your support!
010
Logan Magee @lberrymage.dev · 04/08/2025
This has been a long time in the making (including the follow-up to be posted next week). I'd appreciate you giving it a read.
050