3. Atom 耗尽并非“自伤陷阱”。它占我们已知漏洞(CVEs)的三分之一 Atom Exhaustion Is Not a Footgun. It''s One Third of Our CVEs (erlef.org)
9. Sidekick:在十几个代理重写你的代码时,继续使用 Neovim Sidekick: keep using neovim while a dozen agents rewrite your code (github.com)
13. 不妨将 Emacs 视作你的“孤独堡垒” May I recommend thinking of Emacs as your Fortress of Solitude (martinsos.com)
15. CVE-2026-48710 Starlette 主机头身份验证绕过漏洞 CVE-2026-48710 Starlette Host-Header Auth Bypass (badhost.org)
24. 加拿大的C-22法案与收集更多数据带来的安全成本 Canada’s Bill C-22 and the security cost of collecting more data (tailscale.com)
29. DoomBench 正式发布——您的数据架构能运行《毁灭战士》吗? Introducing DoomBench - Can Your Data Stack Run DOOM? (cedardb.com)
32. 使用 Temporal 构建可扩展的数据摄取管道(上篇) Building a Scalable Ingestion Pipeline with Temporal (Part 1) (blog.rapidflare.ai)
36. 什么是谐波?一部关于加法合成技术的互动漫画 What is a harmonic? An interactive comic about additive synthesis (melatonin.dev)
50. 通过 HTTP 提供文件的三种方式:同步、epoll 和 io_uring Serving files over HTTP three ways: synchronous, epoll, and io_uring (theconsensus.dev)
52. 必须安装 uv 才能构建独立的 Python 发行版 uv must be installed to build a standalone Python distribution (github.com)
53. 教宗利奥十四世《Magnifica Humanitas》通谕 Encyclical Letter of His Holiness Leo XIV Magnifica Humanitas (www.vatican.va)
71. JS Crossword——一款谜题提示等于 eval(答案) 的填字游戏 JS Crossword - a crossword where the clue eval(answer) (lyra.horse)
77. 我的这款轻量级、内存安全的 Go 版 rsync 是如何规避安全漏洞的 How my minimal, memory-safe Go rsync steers clear of vulnerabilities (michael.stapelberg.ch)
80. 一万行代码之后:当一个工具演变为编译器——罗布·达斯特——Gleam Gathering 2026 10,000 Lines Later: When a Tool Became a Compiler - Rob Durst - Gleam Gathering 2026 (www.youtube.com)
82. fht-compositor:一款支持动态平铺的 Wayland 合成器 fht-compositor: A dynamic tiling Wayland compositor (github.com)
85. 批量 memmove 能否加快 std::remove_if 的执行速度?(不能。) Does bulk memmove speed up std::remove_if? (No.) (quuxplusone.github.io)
96. 对1980年“太空实验室”计算机电路进行逆向工程 Reverse engineering circuitry in a Spacelab computer from 1980 (www.righto.com)
100. z386:基于原始微代码构建的开源 80386 处理器 - Small Things Retro z386: An Open-Source 80386 Built Around Original Microcode - Small Things Retro (nand2mario.github.io)
101. 在 C 中仍然无法使用的 C 语言结构——以及少数发生变化的结构 C Constructs That Still Don’t Work in C — and a Few That Changed (lospino.so)
105. 使用 Gomobile 和 Gopherjs 实现动态二维码数据传输 Animated QR data transfer with Gomobile and Gopherjs (divan.dev)
109. 惠普收购了Hyperspace,并曾提供过3种不同的预启动或启动过程中操作系统,其中包括Quickweb HP bought Hyperspace, & once offered 3 different pre-boot or in-boot OSs, including Quickweb (gekk.info)
113. 一套用于编辑和发布RFC的全新现代化工具即将推出 A new suite of modern tools coming for editing and publishing RFCs (www.ietf.org)
117. SPy:一种用于静态类型化 Python 变体的解释器和编译器 SPy: an interpreter and a compiler for a statically typed variant of Python (github.com)
119. 在命令行中调整 Mac 的系统音量 Adjusting a Mac''s System Volume on the Command Line (excessivelyadequate.com)
120. 在四款老旧CPU上对比LZ4解压缩器 Comparing an LZ4 Decompressor on four legacy CPUs (bumbershootsoft.wordpress.com)
122. CVE-2026-46529:Linux PDF 阅读器(XReader/Evince/Atril)中存在一个已存在 10 年的远程代码执行漏洞 CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril) (medeiros.zip)
125. account-center:用于内部服务和知识库文章的自托管、支持 OIDC 身份验证的门户 account-center: Self-hosted, OIDC-authenticated portal for internal services and knowledge base articles (git.sr.ht)
127. 在所有64位整数中,只有17%是由两个32位整数相乘得到的 Only 17% of all 64-bit Integers are products of two 32-bit integers (lemire.me)
128. Apple corecrypto 形式验证蓝图 A blueprint for formal verification of Apple corecrypto (security.apple.com)
129. 开源领域的职业倦怠:一个我们可以共同解决的结构性问题 Burnout in Open Source: A Structural Problem We Can Fix Together (opensourcepledge.com)
131. 《Qud洞穴》(2019)中的端到端程序化生成 End-to-End Procedural Generation in Caves of Qud (2019) (www.youtube.com)
137. 巨齿鲨:利用 CI 工作流对大量 GitHub 仓库植入后门 Megalodon: Mass GitHub Repo Backdooring via CI Workflows (safedep.io)
138. 安全启动与证书颁发机构轮换——致各发行版的提醒 Secure Boot and CA Rollover - a heads-up for distributions (blog.einval.com)
139. 这个博客在 Ubuntu 16.04 上运行了 10 年。我已将其迁移至 FreeBSD This blog ran on Ubuntu 16.04 for 10 years. I migrated it to FreeBSD (crocidb.com)
141. 《离散事件仿真与分布式并发控制中的虚拟时间》(1985) Virtual Time for discrete event simulation and distributed concurrency control (1985) (worrydream.com)
143. 美国联邦贸易委员会(FTC)将要求考克斯传媒集团支付近100万美元,以了结其就“主动倾听”人工智能营销服务误导客户的指控 FTC to Require Cox Media Group to Pay Nearly 1million to Settle Charges They Deceived Customers About “Active Listening” AI-Powered Marketing Service (www.ftc.gov)
144. 即使您已删除 Google API 密钥,它们仍会继续生效,时间之长足以被不法分子利用 Google API keys keep working after you delete them long enough to be exploited (www.aikido.dev)
145. Gnutella:一种比其诞生的世界更长久的协议 Gnutella: A Protocol Outlives the World That Created It (rickcarlino.com)
149. 利用通过 USB/IP 连接 WebUSB 的浏览器内 Linux 虚拟机,让旧扫描仪重获新生 Reviving old scanners with an in-browser Linux VM bridged to WebUSB over USB/IP (yes-we-scan.app)
150. CVE-2026-47243:Kata Containers 通过 virtiofs 实现从 guest-root 到 host-root 的权限提升 CVE-2026-47243: Kata Containers guest-root to host-root escape via virtiofs (www.openwall.com)
155. 依赖冷却时间不公平;我们应该改用分阶段推出 Dependency cooldowns are unfair; we should use phased rollouts instead (illegalcode.net)
159. Gobee:使用 Go 语言编写 eBPF 程序,并通过 clang 进行转译 Gobee: write eBPF programs in Go, transpiled via clang (github.com)
160. Ursula:面向 HTTP 事件流的、采用“每个核心一个线程”架构的多 Raft 运行时(Rust 实现) Ursula: thread-per-core, multi-Raft Rust runtime for HTTP event streams (github.com)
163. Go 语言中的 L1 指令缓存集冲突、关联度与代码对齐 L1 instruction cache set conflicts, associativity, and code alignment in Go (blog.andr2i.com)
166. Python 3.15:那些未被广泛报道的新特性 Python 3.15: features that didn''t make the headlines (blog.changs.co.uk)
171. [RFC] LLVM 基金会关于支持标准文档开放获取的声明 [RFC] LLVM Foundation statement in favor of open access to standards documents (discourse.llvm.org)
174. 那些咄咄逼人的AI爬虫,让运营维基变得有点让人头疼 Aggressive AI scrapers are making it kinda suck to run wikis (weirdgloop.org)
175. Waterfox 6.6.13 版本移除了 Startpage 作为默认搜索提供商 Waterfox Release 6.6.13 removes Startpage as default search provider (www.waterfox.com)
178. OpenAI的一个模型推翻了离散几何学中的一项核心猜想 An OpenAI model has disproved a central conjecture in discrete geometry (openai.com)
183. Chromium在4年后发布了针对该漏洞的修复补丁,结果发现该漏洞实际上并未得到修复 Chromium publishes fixed exploit 4 years later, turns out it''s actually unfixed (infosec.exchange)
184. 围绕用户修改智能电视软件权利的多年之争即将进入庭审阶段 Yearslong fight over users'' right to tweak smart TV software heads to trial (arstechnica.com)
185. XSS 对密钥而言致命:认证机制的隐性风险 XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None (scotthelme.co.uk)
186. Linux 内核中 __ptrace_may_access() 函数的逻辑漏洞 (CVE-2026-46333) Logic bug in the Linux kernel''s __ptrace_may_access() function (CVE-2026-46333) (cdn2.qualys.com)
188. glibc 的 malloc 中如何实现跨线程双重释放检测 How cross-thread double free detection could work in glibc malloc (kallus.org)
192. modulejail:通过将所有当前未使用的模块加入黑名单,主动缩小 Linux 主机的内核模块攻击面 modulejail: Proactively shrink a Linux host''s kernel-module attack surface by blacklisting every module not currently in use (github.com)
193. Grafana Labs 的 GitHub 仓库因 TanStack npm 供应链攻击而遭到入侵 Grafana Labs GitHub repos breached via TanStack npm supply chain attack (grafana.com)
204. GitHub 源代码泄露事件——TeamPCP 声称已获取内部源代码 GitHub Source Code Breach - TeamPCP Claims Access to Internal Source Code (cybersecuritynews.com)
205. 如果你就那样坐在那里无所事事,那至少要把这无所事事做得像样点 If you''re just going to sit there doing nothing, at least do nothing correctly (devblogs.microsoft.com)
207. 我建立了一个虚拟博物馆,里面几乎囊括了你能想到的所有操作系统 I''ve built a virtual museum with nearly every operating system you can think of (www.youtube.com)
215. 关于基于属性的测试在验证形式化规格说明方面的“不可思议的有效性” On the Unreasonable Effectiveness of Property-Based Testing for Validating Formal Specifications (proofsandintuitions.net)
216. pg_deltax:一款基于Apache许可证的PostgreSQL时间序列扩展 pg_deltax: Apache-licensed time-series extension for PostgreSQL (github.com)
220. 我们在强化 Turso 安全性的过程中,如何利用 Quint 发现 SQLite 中超过 10 个漏洞 How we used Quint to find over 10 bugs in SQLite while hardening Turso (turso.tech)
221. 技术揭秘:构建实时和弦识别器 Under the Hood: Building a Real-Time Chord Recognizer (whatchord.earthmanmuons.com)
228. 一个用 C 语言编写的自平衡跳跃表(又称“splay-list”)库 A self-balancing skip-list (aka "splay-list") library in C (codeberg.org)
229. Lime,一款可在运行时合并语法的解析器生成器 Lime, a parser generator that can merge grammars at runtime (codeberg.org)
230. Noxu DB,Berkeley DB Java Edition 的 Rust 移植版 Noxu DB, a Rust port of Berkeley DB Java Edition (codeberg.org)
231. ProseMirror 模型在富文本转换中的超乎寻常的有效性 The Unreasonable Effectiveness of ProseMirror Model in Rich Text Transformation (smoores.dev)
232. Windows DLL 加载器锁:Rust 线程如何导致 JVM 挂起 The Windows DLL loader lock: how a Rust thread can hang your JVM (questdb.com)
237. 利用代数和大型语言模型在Lean中验证飞行计划漏洞修复 Using algebra and LLMs to verify a flight-plan bug fix in Lean (jameshaydon.github.io)
241. Casuarina Linux 简介:一款基于 glibc 的 Chimera Linux 衍生版 Introducing Casuarina Linux: A glibc-Based Chimera Linux Derivative (casuarina.org)
243. CISA管理员在GitHub上泄露了AWS GovCloud密钥 CISA Admin Leaked AWS GovCloud Keys on Github (krebsonsecurity.com)
246. cargo-crap:在 AI 生成的 Rust 代码中发现未经测试的复杂性 cargo-crap: Finding Untested Complexity in AI-Generated Rust Code (minikin.me)
251. Flathub究竟是如何运作的?CDN 和缓存层 How does Flathub even work? The CDN and caching layer (barthalion.blog)
257. 浏览器标签页中的类Linux内核——深入解析BrowserPod架构 A Linux-like kernel in a browser tab - deep dive in the BrowserPod architecture (labs.leaningtech.com)
261. 使用 OpenCode、Llama.cpp 和 Qwen 3.6 查找您代码中的错误 Find bugs in YOUR code using OpenCode, Llama.cpp and Qwen3.6 (wtarreau.blogspot.com)
262. FediMeteo、HAProxy 与不浪费 snac 线程的艺术 FediMeteo, HAProxy, and the art of not wasting snac threads (it-notes.dragas.net)
264. Calvin - 决定论、分布式 ACID 事务(2020) Calvin - Determinism, Distributed ACID transactions (2020) (www.mydistributed.systems)
267. 研究人员称微软在BitLocker中秘密植入了后门 Researcher says Microsoft secretly built a backdoor into BitLocker (www.techspot.com)
268. 使用 Claude Code 对 Android 恶意软件进行逆向工程 Reverse engineering Android malware with Claude Code (zanestjohn.com)
269. 在 Mac 上反转《Grateful Dead: D2S2》(2022) Reversing ‘Grateful Dead: D2S2’ on Mac (2022) (blog.os9.ca)
282. 克劳德·科德成功让 Adobe Lightroom 在 Linux 上运行起来 Claude Code managed to get Adobe Lightroom working on Linux (github.com)
286. Fast16:这款早于“震网”病毒的破坏工具旨在破坏核武器模拟系统 Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations (www.security.com)
289. DeepSeek-V4-Flash 意味着大型语言模型(LLM)的引导技术再次引起关注 DeepSeek-V4-Flash means LLM steering is interesting again (www.seangoedecke.com)
293. 多语言Lisp:Common Lisp、Racket、Clojure、Emacs Lisp Hyperpolyglot Lisp: Common Lisp, Racket, Clojure, Emacs Lisp (hyperpolyglot.org)
297. Tomy Tutor 与 1983 年的家用电脑现状 The Tomy Tutor and the state of 1983 home computers (oldvcr.blogspot.com)