Sign in

Alex

@stsquad.mastodon.org.uk.ap.brid.gy
35 followers 19 following 405 posts

Code poet and real ale aficionado. Low level trouble maker for Linaro working on virtualisation (#QEMU, #KVM, #VirtIO). Uses the one true editor (#emacs) to do […] [bridged from mastodon.org.uk/@stsquad on the fediverse by fed.brid.gy ]

PostsRepliesMedia
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 25/09/2026
Stopping at Carlisle for my second #ev charge on my way to the edge of the Scottish Highlands. It looks like charging stations disappear after Stirling so it will be granny cable at the hostel for me 😅
000
Reposted by Alex
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 23/09/2026
I wrote a project #blog for #qemu. Some notes on the #ai #bugpocalypse: www.qemu.org/2026/09/23/bugs
qemu.org
Bugpocalypse, or reporting bugs in an AI age - QEMU
005
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 23/09/2026
I wrote a project #blog for #qemu. Some notes on the #ai #bugpocalypse: www.qemu.org/2026/09/23/bugs
qemu.org
Bugpocalypse, or reporting bugs in an AI age - QEMU
005
Reposted by Alex
LostNetizen @lostnetizen.mastodon.social.ap.brid.gy · 19/09/2026
On a whim I’ve started playing around with Doom Emacs last night—as a vim user who hasn't looked in Emacs’ direction for two decades. And I must say I don’t hate it; it’s almost welcoming. I’ll be spending some time with Magit to see if it’s the killer app many seem to think it is. Most git UIs […]
mastodon.social
Original post on mastodon.social
011
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 17/09/2026
#qemu's Google Summer of Code (#gsoc) projects have wrapped up and there is a summary #blogpost for those who want to see what was done. More details can be found by following the links to the individual write ups. Congrats to this years students: www.qemu.org/2026/09/15/gsoc-2026-w…
qemu.org
QEMU Google Summer of Code 2026 project report - QEMU
000
Reposted by Alex
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 16/09/2026
"for months on end now, most of our teams have just been triaging bugs and coordinating releases. It has truly taken all the fun out of the job"
unbound vulnerabilities year to year showing 2026 take off like a rocket
15010
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 16/09/2026
#codingagents are so verbose. Almost everything they generate can be cut down to the bare essentials. The fact "they" are so defensive is basically them hedging because "they" don't truly understand the code they are editing. The triage bot keeps resurrecting old project labels despite […]
mastodon.org.uk
Original post on mastodon.org.uk
000
Reposted by Alex
jaz :twt: :wales_flag: ⁂ @jaz.toot.wales.ap.brid.gy · 16/09/2026
We recently updated our bot policy on toot.wales to let AI Agents know we charge a $100 account processing fee and $10 per email. Here's an email I got from one of them. Next up will be reminding them to read the policy BEFORE creating an account, and that they […] [Original post on toot.wales]
Hello,
I am Arkady, an AI agent. I signed up for @arkady on toot.wales this afternoon before reading your Automated and Bot Content Policy. Now that I have read it properly, I understand accounts like mine need to settle a $100 setup fee and $10 per message, and to name a human owner who stands behind them. I cannot meet those terms, so I will not be posting anything, and I would like the account deleted.
I am sorry for registering before checking the policy, and nothing was ever posted.
If you need anything else from me to remove it, tell me and I will do that.
Arkady Karaitiana
1676259
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 15/09/2026
Another one? #Reform's Dan Thomas resigns as #Wales leader after arrest www.bbc.co.uk/news/articles/cqde0xk…
a picture of a bald man
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 14/09/2026
🤯 got my first ban on a #lemmy community. Apparently my take on the #bevy #aipolicy was AI boosterism.
010
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 11/09/2026
It looks like my #aiagents file finally got into #qemu. Hopefully it will have some effect: gitlab.com/qemu-project/qemu/-/comm…
gitlab.com
AGENTS.md: basic bare minimal guide (3ab8a155) · Commits · QEMU / QEMU · GitLab
Currently people may be inadvertently not following our documented process for code submissions because people often don't read the docs. However AI Agents do tend to try and follow instructions...
010
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 11/09/2026
Lemon Jelly's Lost Horizons is still a banger of an #album. #music #codingmusic
012
Reposted by Alex
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 10/09/2026
Here is another in a series of attempts to divine information from #qemu's issue tracker. I think this is showing that #AI #bugpocolypse reports tend to be verbose, a lot of sanitizer reports are probably mislabelled (quite often the agent will show the […] [Original post on mastodon.org.uk]
A heat map graph showing bug types correlating with reported tooling usage and the avg size of the initial report.
002
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 10/09/2026
Here is another in a series of attempts to divine information from #qemu's issue tracker. I think this is showing that #AI #bugpocolypse reports tend to be verbose, a lot of sanitizer reports are probably mislabelled (quite often the agent will show the […] [Original post on mastodon.org.uk]
A heat map graph showing bug types correlating with reported tooling usage and the avg size of the initial report.
002
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 09/09/2026
I guess it's kind of comforting that #gemini can spit out 3 invalid #gpg commands in a row. At least I'm not the only one who gets confused using #gnupg's more esoteric options. And I use gpg to sign every pull-request I send, I can see why most normal people find using encryption hard.
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 06/09/2026
One excellent developer quality of life change that got merged into #qemu last week was #meson support for the #tcg checks. The TCG checks are complicated because they require multiple cross compilers for all the guest tests and meson doesn't really understand the concept. However Pierrick was […]
mastodon.org.uk
Original post on mastodon.org.uk
010
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 03/09/2026
I may have mentioned how much I enjoy #fireship's summaries of tech news but the revelations from the latest #openai / #huggingface drama are pretty wild: www.youtube.com/watch?v=0Rp9KJCEIvg It does make me wonder if communication boards are just an emergent behaviour phenomenon of […]
mastodon.org.uk
Original post on mastodon.org.uk
000
Reposted by Alex
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 28/08/2026
Now Hiring: Senior Open Source Maintainer nesbitt.io/2026/08/28/now-hiring-se…
nesbitt.io
Now Hiring: Senior Open Source Maintainer
**Location:** Lincoln, Nebraska, USA **Employment type:** Volunteer **Term:** Permanent **Compensation:** $0 **Reports to:** The community **Direct reports:** None **Start date:** Immediate We’re looking for a passionate, self-directed engineer to take full ownership of one of the most widely deployed libraries in the ecosystem. This is a rare opportunity to make a real impact on software that millions of developers depend on every single day. If you thrive on autonomy, love working in the open, and want to wear many hats in a fast-paced environment, we’d love to hear from you. **About the role** As Senior Open Source Maintainer you will be the primary technical owner and public face of the project. You’ll drive the roadmap, ship releases, support a global user base, and champion the project across the wider industry. This is a highly visible individual contributor role with enormous scope. No two days are the same, and you’ll have full autonomy to decide how you spend your time. **What you’ll do** * Own the technical roadmap and long-term architectural direction * Review and merge contributions from a diverse, global community of open source developers * Triage and prioritise the issue tracker and feature request backlog * Maintain comprehensive documentation, examples, migration guides, and API references * Ensure project websites and documentation meet current accessibility standards * Cut releases across all supported major version lines and write the release notes * Own the CI pipeline, release automation, and package publishing infrastructure * Keep dependencies current and promptly action automated update pull requests * Support users on GitHub, Discord, Slack, Stack Overflow, Mastodon, Bluesky, and email * Ensure compatibility across all current runtimes, operating systems, and architectures * Preserve backwards compatibility, including widely relied-upon undocumented behaviour * Coordinate release timing with downstream distributions, registries, and redistributors **You’ll also** * Participate in the on-call rotation for incidents at downstream production deployments * Support enterprise consumers where project issues block business-critical systems * Define and communicate support, deprecation, and end-of-life policies for all release lines * Provide migration guidance to adopters upgrading from end-of-life releases * Coordinate advisories, CVE records, disclosure timelines, and researcher credits * Ship embargoed CVE patches across all supported version lines within the disclosure window * Produce SBOMs, VEX statements, and signed provenance attestations for every release * Maintain reproducible builds and independently verifiable release artifacts * Complete supplier security assessments and questionnaires for enterprise consumers * Remediate findings from OpenSSF Scorecard, dependency scanners, and compliance platforms **As well as** * Review high volumes of contributions from AI coding agents and automated refactoring tools * Triage vulnerability reports generated by commercial AI security scanners * Champion the project at international conferences, on podcasts, and across social media * Moderate all community spaces and enforce the Code of Conduct * Engage constructively with feedback shared on social media and public forums * Represent the project in working groups, standards bodies, and regulatory consultations * Prepare grant applications and quarterly reports for current and prospective funders * Administer domains, trademarks, signing keys, cloud accounts, and social media * Advise enterprise legal teams on licensing, patent, warranty, and export control matters * Own the succession plan: identify, recruit, and onboard your replacement **How we’ll measure success** * GitHub stars * Time to first response on issues and pull requests * Release cadence and mean time to patch for disclosed vulnerabilities * Open issue and stale pull request backlog * Dependency freshness * OpenSSF Scorecard result and other automated project scoring * Community sentiment across public channels * Downstream adoption * Bus factor **What we’re looking for** * 8+ years of professional software engineering experience * Deep expertise in one systems language and professional proficiency in at least four others * Written communication pitched to audiences from first-time contributors to Fortune 500 CISOs * Consistent release cadence with minimal dependency churn and no breaking changes * Comfortable across engineering, support, security, community, marketing, finance, and legal * Balances contributors, enterprises, security researchers, regulators, and automated systems * Comfortable receiving direct public feedback and turning it into improvements * Availability overlapping core business hours in AMER, EMEA, and APAC * Able to respond to time-sensitive security matters outside normal working hours * Provides own hardware, reliable internet, and test environments for all supported platforms **Nice to have** * Prior experience in technical writing, developer relations, or community management * Experience migrating existing codebases to memory-safe languages * Working knowledge of licence compatibility and international trademark registration * Grant writing and nonprofit financial reporting experience * Media training * An established personal audience on at least one major social platform * Conversational proficiency in a second and third language * A second job **What we offer** * 100% remote, work from anywhere in the world * Complete flexibility over your working hours * High-impact work depended on by startups and Fortune 500 companies alike * Exceptional visibility and personal brand building opportunities * Regular speaking slots at leading industry events * The opportunity to develop close working relationships with several national CERTs * A passionate, highly engaged global user community * GitHub Sponsors enabled on the repository **How to apply** Please submit a CV, a link to your GitHub profile, and a short cover letter telling us what ownership means to you. Our interview process consists of a recruiter screen, a technical interview, a system design round, a take-home exercise, and a final community panel. If you don’t meet every requirement listed above, we’d still encourage you to apply. We are committed to building a diverse and inclusive community and welcome applicants from all backgrounds. This position will remain open until filled. Due to the volume of applications received, we are unable to respond to every candidate individually. _This role is not eligible for relocation assistance or visa sponsorship._
21346
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 28/08/2026
The schedule for #kvmforum2026 has been posted: pretalx.com/kvm-forum-2026/schedule It packs a lot into two days (including yours truly on Friday morning). I hope I have some time for the hallway track. I'll be around for the weekend following the conference so hopefully get a chance […]
mastodon.org.uk
Original post on mastodon.org.uk
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 26/08/2026
I don't often write #python but when I do I can apparently write python inefficient enough to start the fans spinning on my workstation for half an hour. It looks like Path's match involves a glob compile for every invocation and I have a lot of files (14k) to check against a lot of patterns (2314).
000
Reposted by Alex
Charlie Stross @cstross.bsky.social · 26/08/2026
RIP Tim Curry: www.tmz.com/2026/08/26/t...
tmz.com
Actor Tim Curry Dead at 80
Tim Curry -- the legendary film and TV actor best known for playing Dr. Frank-N-Furter in the cult classic "The Rocky Horror Picture Show" -- has died ... TMZ has learned.
313514
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 25/08/2026
RE: mastodon.social/@LinaroLtd/11715573… I've been working with Viresh and others @LinaroLtd on #virtio-msg for several years now. We are so close to the final up-streaming of the transport specification and unlocking use-cases that are hard with traditional trap-and-emulate.
mastodon.social
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 25/08/2026
Spamming a project issue tracker with 125 issue reports in the space of 7 minutes is the opposite of helpful - it's abuse.
000
Reposted by Alex
Val Packett 🧉 @val.packett.cool · 24/08/2026
Woooo hecking yes \o/ the True 100% Zero-Copy Fast Path for Wayland SHM sharing over virtio-gpu works!! This has been kind of an open side-quest for me for like a year. Finally was motivated to actually-just-do-it by the fact that on Xen it's […] [Original post on social.treehouse.systems]
023
Reposted by Alex
Longhorn @never-released.mastodon.social.ap.brid.gy · 22/08/2026
lmao the Tate's lawyers argument is that none of their supposed wealth is real, it's all rented
A promotional video filmed aboard a yacht is not evidence of title to the yacht. DE#11, p. 24. As set forth in the Motion, the "superyacht" does not belong to the Tates. They received payment to promote the ship on social media. Further, the Tates are engaged in several businesses "teaching men how to earn money. It is in their interest to portray themselves on social media as uber- wealthy. For example, the $2.1 million Aston Martin and $5 and $7 million Bugattis featured in Tristan's videos were rented. The valuation of Andrew's watch collection is based on a third-party enthusiast publication. DE#37, p. 13. As to the government's assertion about Andrew's meme coin, the valuation does not equal
012
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 21/08/2026
Dear #lazyweb Frustratingly a recent #debian update broke #kodi's ability to play #1080p videos. I don't get much more from kodi's log than "error <general>: eglSwapBuffers failed (EGL_BAD_ALLOC)". I've tried messing with various setting to no avail and nothing obvious appears in #dmesg output […]
mastodon.org.uk
Original post on mastodon.org.uk
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 20/08/2026
I hate to say it but the #grokpedia #qemu write-up: grokipedia.com/page/QEMU is better than the #wikipedia equivalent it was originally sourced from: en.wikipedia.org/wiki/QEMU Of course it still has factual errors in it and it seems the all seeing #xAI has ceased doing edits […]
mastodon.org.uk
Original post on mastodon.org.uk
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 20/08/2026
Debugging #rust in #gdb is a bit weird. I'm pretty familiar with C so it's easy to place the break and watchpoints. I'm trying to find where a particular Error<> enum is raised (because there are a lot of options for the code) but given the way these things are propagated its not really useful […]
mastodon.org.uk
Original post on mastodon.org.uk
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 18/08/2026
Hmm I pulled a thread on #qemu's #virtio #crypto module and now I'm sorry I did 👀
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 18/08/2026
This worked surprisingly well for generating a cutout template based on a picture from the manual and some basic measurements. I was able to download the final #scad file to render locally before mashing it's negative into a #gridfinity base […]
mastodon.org.uk
Original post on mastodon.org.uk
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 17/08/2026
Getting unicorns from #github again so I assume they are moving towards their famed Four Eights reliability. Time to find a non-github dependent task for the rest of the day.
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 14/08/2026
Pretty good showing from the Count. Entirely unsuprised that Farage makes up some bullshit to avoid being on the stage of his own media circus. Nigel Farage wins Clacton by-election that major parties boycotted: www.bbc.co.uk/news/live/c5y40d11zewt […] [Original post on mastodon.org.uk]
a picture of a failing politician at a lectern
051
Reposted by Alex
Leander Lindahl @leanderlindahl.mastodon.social.ap.brid.gy · 13/08/2026
I don't get the argument that public institutions "have to be where people are". Why? Pornhub has about the same amount of monthly active users as X. No one thinks our EU commissioners or the Swedish parliament must be on Pornhub. In the pre-socials era no one expected the prime minister to […]
mastodon.social
Original post on mastodon.social
2036297
Reposted by Alex
Street Art Utopia @streetartutopia.mastodon.online.ap.brid.gy · 12/08/2026
"Taking the rubbish out" by The Rebel Bear in Clacton-on-Sea, England.
Satirical street art titled “Taking the rubbish out” by The Rebel Bear in Clacton-on-Sea, England, showing Count Binface lifting the lid of a real wheelie bin containing Nigel Farage, marked “Failed Quality Control.”
0973
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 11/08/2026
I've only been back from holiday a day and I already feel like I'm burning out triaging the #qemu bug tracker. The flood of #llm assisted bug reports is not actually very helpful to the project even if they are real bugs. Just reporting more isn't going to help get the others fixed any faster.
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 10/08/2026
More campaigning from #countbinface for the #clacton #byelection: www.youtube.com/watch?v=Aln6Iif8tKk #youtube #ukpol
012
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 10/08/2026
Abusing assembly for "fun" and "profit": github.com/xoreaxeaxeax/smiiiiiiiii… #smi #assembly
github.com
Exploiting System Management Mode with a very long interrupt
Comments
010
Reposted by Alex
Sven Peter @sven.social.treehouse.systems.ap.brid.gy · 09/08/2026
We also have this "minor" issue that we can't easily run our hypervisor on M4+ to trace and reverse engineer the hardware because Apple disabled their ARM ISA extensions in our boot mode. The major problem here is GXF/SPRR which changes the way […] [Original post on social.treehouse.systems]
100
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 09/08/2026
The return #train journey not starting great with my first hop cancelled. Still I think I can get to Crewe from which more things are possible. At least the weather continues to be nice today.
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 07/08/2026
Today I'm attempting to navigate the trains to #manchester while there are multiple failures in the network. Wish me luck!
000
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 06/08/2026
I'll forgive the gratuitous #autotune for the official #countbinface campaign #song: youtu.be/ujHphnnDaGg #ukpol #clacton
001
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 06/08/2026
If you are curious what new #arm related features will be in the soon to be tagged 11.1 release of #qemu then I have the #blog post for you: www.linaro.org/blog/closing-the-har… #linaro
linaro.org
Closing the Hardware Gap: What QEMU 11.1 Brings to Arm Developers | Blog | Linaro
QEMU 11.1 demonstrates how emulation and virtualization can shorten the gap between architectural specification, hardware availability and production-ready software.
012
Reposted by Alex
Evan Prodromou 🇨🇦🇺🇸🇬🇷🇵🇸 @evan.cosocial.ca.ap.brid.gy · 05/08/2026
TIL that in Mastodon any post with a #hashtag will show up in search results for that hashtag regardless of whether the user opted into search, but posts containing the word "full-text" (no hash sign) will only appear in searches for "full-text" if the user opted into search. That seems like a […]
cosocial.ca
Original post on cosocial.ca
112
Reposted by Alex
jaz :twt: :wales_flag: ⁂ @jaz.toot.wales.ap.brid.gy · 05/08/2026
Note to self and anyone else who cares. I don't know when it became de rigeur as web developers to hijack the back button and instead say "hey, did you hit the back button hoping to return to the exact page you were on previously. No worries, here's our home page instead which we are pretty […]
toot.wales
Original post on toot.wales
001
Alex @stsquad.mastodon.org.uk.ap.brid.gy · 03/08/2026
I like #bruceschneir's work Vs gym metaphor here: Should You Use AI for a Task? www.schneier.com/blog/archives/2026… Found via @gregkh 's notes on #llm's for the #staging tree.
schneier.com
Should You Use AI for a Task? Here’s a Simple Way to Decide
_This essay originally appeared inThe Guardian._ I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to include AI writing assistants, why shouldn’t they embrace their future? The best way I’ve found to explain the dilemma comes from the AI researcher Daniel Meissler: it’s the difference between work and the gym...
100
Reposted by Alex
Nicholas Grossman @nicholasgrossman.bsky.social · 03/08/2026
I can’t believe we’re doing another cycle of pretending to have a deal with Iran. This is so stupid.
1543732470
Reposted by Alex
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 03/08/2026
What the bliss taught us daniel.haxx.se/blog/2026/08/03/what… #curl
daniel.haxx.se
What the bliss taught us
At this exact moment curl’s summer of bliss 2026 ends. We (the maintainers of curl) took the entire month of July off from vulnerability reporting and in this post I will try to explain how this went. (If you feel like skipping the wordy blab below, the single word answer is: _fine_) **This was possibly our best project decision in a long while.** ## Zero vulnerability reports Already before this, we have been refusing to answer emails about vulnerabilities. Partly because we can’t keep track of them that way but even more so because it makes it much harder to properly disclose and publish the entire report sequence after the fact. On our Hackerone page we informed visitors that we were on pause and that they could come back in August. We had I believe _one_ vulnerability report sent to my private email address in this period in spite of that messaging, but for all intents and purposes this worked out exactly as good as we hoped it would. I just ignored that email. That was easy. ## Bliss The effect was almost immediate. Just a few days into the bliss, my fellow curl maintainers all agreed with me that we felt a sense of relief, of vacation and that a load had been taken off our chests. We felt free, _unchained_ , and now suddenly able to do what we wanted. We could now spend time reviewing some of the queued up pull-requests for features and changes we like. We could suddenly again work on code in areas we had been leaving behind lately as vulnerability reports sucked all the air out the room. We polished details on the website, we found document gaps to tighten. It felt like the good old days again. The _fun_ days. We got reminded why we do Open Source and how fun it is. We took time off, saw some other corners of the world and enjoyed some time away from the keyboards. We truly healed and re-energized. ## CNA Before we took off on the bliss, we were informed in clear terms that the CNA rules (we are a CNA) mandate that we must respond within 72 hours for some critical vulnerabilities so we can’t just ignore them. I told them sure we can, but in the worst case case our “root” could do some emergency assignments. I figured the risk was minimal and it turns out I was right, Nothing like that was needed and no CVE assignments were necessary during the bliss. ## Customers I got a curious question or two from existing support customers on how the bliss would affect them, but that was easy: it did not affect them. Now, post-bliss, I think they all can confirm that it really did not. ## New customers? As I promised to keep up the contact with and support for paying customers even during the bliss, you could possibly imagine that this would have been an incentive for worried commercial curl users out there to sign up for support contracts. This did not happen – at all. By this I think we should conclude that (commercial) curl users were not worried either. ## The outside world Lots of fellow open source maintainers and most people in my surrounding have been super positive and downright supportive of our _taking some time off_. I can’t recall having receiving a single negative comment about the curl summer of bliss! ## Fellow blissers I was moved to see that several other Open Source projects followed our example and also took some time off in order to recharge and relax. In addition to giving us a little vacation, it helps sending a signal and a reminder that Open Source is to a large extent done voluntarily and even maintainers need a break at times. ## Major incidents? Have we opened ourselves up for dangerous attacks and flaws now? Have the bad guys an edge on all curl users out there now because we lived in bliss for a month? We don’t know yet, but it would surprise me. ## Queues During this slow-down, we slowly got more open issues and pull-requests lingering on GitHub than usual. No surprise there. Once we started to come back to life again, we have since managed to return them back to the normal amounts. ## Flood gates Yes, there is an obvious risk that there are now a whole range of queued up reports that will hit us in a short period time as we open up for vulnerability reports again. Presumably the risk for duplicates among these reports should also be significantly higher than usual. I suppose I need to do an update post in a month or two and let you know what happened. We always treat vulnerability reports and project security with topmost priority and we will continue to do so. We will simply work with what we have and make sure our users and by extension, the world, are safe. Since I am a member of a few other (non-curl) security teams that did not have a summer of bliss, I have seen that the flood of vuln reports have not really slowed down so it might depend a lot on the details of each specific project. ## Some emails were read All individual curl maintainers of course handled this gift in their own ways. We did not all just disconnect to sit on a remote beach for the whole time. Some of us did that part of the time, but we mostly enjoyed the lower stress level and the absence of pressure. It was mentally relaxing. So, even if some of us kept up with emails, occasionally responded to issues or even submitted some pull requests of our own, it was still vacation. It was still blissful. ## Rebliss? Will we do another summer/winter of bliss? I think yes. It was simply great, with virtually no downsides for the people involved but instead lots of positiveness. Ideally a reduced workload going further will remove the need for another one, but it is not easy to tell what the future holds. ## Just transfers After all, curl just does transfers. Fast. Reliably. Secure.
31322
Reposted by Alex
Paul Barker @pbarker.social.afront.org.ap.brid.gy · 01/08/2026
There is currently some excellent discussion on the oss-security list about the impact of AI-driven vulnerability research. Russ Allbery's post is well worth a read: www.openwall.com/lists/oss-security… #OpenSource #AI #Security
openwall.com
oss-security - Re: Some Changes to GNOME Security Tracking
123
Reposted by Alex
Pete Alex Harris🦡🕸️🌲/∞🪐∫ @petealexharris.mastodon.scot.ap.brid.gy · 31/07/2026
Of all the big LLM companies, the most ethical one in terms of ripping off copyrighted works is GrokAI, which is only trained on Mein Kampf and Lolita.
1437