Posts
521
Following
487
Followers
397
Linux Kernel security developer, working for Microsoft. Also W7TXT. Views are my own.
Topics: #Linux #kernel #security, #amateurradio, #RF, #hamradio, #electronics, #science, #radioastronomy, #physics, #space, #arduino.

📡 https://w7txt.net/
🐧 https://blog.namei.org/
☠️ https://www.facebook.com/w7txt


Linux Security Summit 🐧

LSS-EU kicks off today in Amsterdam, with conference chair Elena Reshetova presenting opening remarks.

https://lsseu2025.sched.com/list/simple
1
3
2
Where am I? Wrong answers welcome.
1
0
0
Got addicted to Severance on a recent flight, but I need to subscribe to 🍏 tv to see the full season now. This dystopia is getting very ~meta~ blobcatchefskiss
0
0
3
Edited 2 months ago

AI agents can potentially gain extensive access to user data, and even write or execute arbitrary code.

OpenAI Codex CLI uses sandboxing to reduce the risk of buggy or malicious commands: https://github.com/openai/codex/pull/763

For now, it only blocks arbitrary file changes, but there’s room to strengthen protections further, and the ongoing rewrite in will help: https://github.com/openai/codex/pull/629

Landlock is designed for exactly this kind of use case, providing unprivileged and flexible access control.

0
3
1
Anyone using Claude for kernel / system level development? How do you make the most of it?
I like the idea of having something which can do deep code review - eg. does this code actually do what I specified? Are there any bugs? Obviously - but also not so obviously in a complex system. Have I broken layering abstractions? Is the code maintainable? What does the maintainer of this subsystem expect? Etc.
2
0
1

David Chisnall (*Now with 50% more sarcasm!*)

Excellent news yesterday, the RTOS paper was accepted at SOSP!

Huge thanks to @hle, who led on rewriting the rejected submission and made numerous improvements to the implementation.

We now have CHERIoT papers in top architecture and OS venues, I guess security and networking are the next places to aim for!

0
2
1

David Chisnall (*Now with 50% more sarcasm!*)

Dear journalists writing about AI being the end of programming as a profession:

Programming has a long history of embracing tools that make things more productive. The manual for the STANTEC ZEBRA explains that a limitation of 150 instructions is not a practical problem because no one could possibly write a working program that complex. Today, we routinely write programs several three orders of magnitude more complex than that in an afternoon. Higher-level languages have increased programmer productivity by literal orders of magnitude. Things like integrated debugging environments, reliable autocompletion, higher-level type systems, and so on have all been embraced because they let you solve the problems faster.

Note that they don’t all let you write more code quickly. Most of the improvements in productivity have had the opposite impact. They don’t let you write code faster, they let you write less code to do the same things. This started with libraries of reusable code and simple abstractions like functions and has grown over time. I can write a simple dynamic web page in a couple of lines of PHP, where doing the same thing in the assembly languages that the ZEBRA folks were talking about would require me to write thousands of lines. The PHP version would be more portable and also vastly easier to adapt to changing requirements.

At the same time, there are far more problems that need programs to solve them than there are people who can write programs. If programmer productivity doubled tomorrow, there would not be enough programmers. If people who can’t program were all suddenly able to program at the level of a first-year undergraduate tomorrow, there would still not be enough programmers. And that’s why our industry puts so much effort into end-user programming languages. That’s why the most successful programming language, with over a billion users, is Microsoft Excel.

With all that in mind, don’t you think that the fact that most programmers need mandates from management to use bullshit generators to ‘help’ programming might be an indication that the hype isn’t all it claims to be?

3
5
1

More details about the Gaussfest in London on the 7th September

https://www.extremeelectronics.co.uk/the-gaussfest/

High voltage, tesla coils, electrostatic machines and another Victorian/Edwardian pumping station to look around.

and a chance of seeing a working mercury rectifier.

I can't think of a better day out :)

3
5
1

📣 The schedule for All Systems Go! 2025 is now live. https://cfp.all-systems-go.io/all-systems-go-2025/schedule/
🗣️ We look forward to hear from all the great speakers on Sept 30th-Oct. 1st.
🎟️ Grab your tickets to join in: https://ti.to/all-systems-go/all-systems-go-2025
ℹ️ Get more info here: https://all-systems-go.io/

0
9
2
Tapping stainless steel with a small diameter bit is a little stressful 😬
2
0
3
Published 3D print & model files for a mounting bracket for the Leo Bodnar mini GPSDO device. These are commonly used in VHF+ amateur communications as 10 MHz references for use with timing-critical weak signal modes and for frequency-locking microwave & mmwave equipment.

I'm using the CERN-OHL-W license, which seems best for design files.

https://github.com/xjamesmorris/bodnar-gpsdo-mount

#electronics #hamradio #amateurradio #osh
2
3
8

I do have a bunch of HV capacitors of uncertain vintage if anyone in the UK has a fun use for them.

1
2
1

🔔 The proposal notifications just went out for All Systems Go! 2025.
🙏 Thanks to everyone who submitted!
📆 Once we have the confirmations in, we'll publish the schedule.

0
5
0
The simple elegance of the Mac Mini is unmatched.
0
0
2
Edited 4 months ago

This graph is the one I'm most excited about: the lifetime of security flaws in Linux is finally starting to get shorter (and the number of fixed flaws continues to rise).

https://hachyderm.io/@LinuxSecSummit@social.kernel.org/114750428620118674

1
12
3

Linux Security Summit 🐧

Edited 4 months ago
Linux Security Summit North America 2025 kicking off now in Denver, Colorado. No livestream (alas) but videos will be available after the conference.
#linux #linuxsecuritysummit

@lwn @linuxfoundation
2
2
1

Jonathan Corbet

It took a long time and over 60 articles but, at @lwn, we have finally managed to complete our reporting from the 2025 Linux Storage, Filesystem, Memory Management, and BPF Summit. If you want to know what is going on in those core parts of the kernel, this is the place to look.

We've put together an EPUB version of the whole set as well — good bedtime reading!

https://lwn.net/Articles/1026338/
1
28
59
Weekend plans:
33% Finish just one of many unfinished projects
0% Start a new project
16% Start two new projects
16% Start an entirely new hobby
0% Resin printing?
33% Jousting?
0% Binge watch Andora
0
0
0
Followed ChatGPT recommended slicer settings for PETG 👍🏼
0
1
1
Show older