2. Absurd 是一個 Postgres 原生的持久化工作流系統 Absurd is a Postgres-native durable workflow system (earendil-works.github.io)
8. Reed 規範或更優的前綴認證 (2023) Reed Specification or Better Prefix Authentication (2023) (worm-blossom.github.io)
9. Scriba:支持多後端和自動配置的 Lisp 結構化日誌記錄庫(Scheme 庫) Scriba: Structured logging in Lisp with multiple backends and auto-config (Scheme library) (codeberg.org)
11. 有哪些重要的數據系統問題被研究界所忽視?(2024) What are important data systems problems, ignored by research? (2024) (databasearchitects.blogspot.com)
12. Unicode 字符串的等價性很奇怪(2016) Equivalence of Unicode strings is strange (2016) (databasearchitects.blogspot.com)
19. Lunacy——支持懶惰基本代碼塊版本控制和即時編譯(JIT)的 Lua 5.1 解釋器 Lunacy - Lua 5.1 interpreter with Lazy Basic Block Versioning and JIT (redvice.org)
20. Neptune 簡介:適用於 QEMU 的 Direct3D 虛擬化 Introducing Neptune: Direct3D virtualization for QEMU (blog.getutm.app)
25. Roto——Rust 的編譯型腳本語言,誕生一週年 One year of Roto, the compiled scripting language for Rust (blog.nlnetlabs.nl)
26. CIFSwitch:一個非通用型 Linux 本地 root 權限漏洞 CIFSwitch: a non-universal Linux local root vulnerability (heyitsas.im)
33. RIPE NCC 會話固定:利用 Atlas 探針竊取登錄憑據 RIPE NCC session fixation: poaching logins with an Atlas probe (mxsasha.eu)
37. airtop:專為無線網絡設計的 htop —— 終端中的實時 802.11(Wi-Fi)射頻儀表盤 airtop: htop for the airwaves — a live 802.11 (Wi-Fi) RF dashboard in your terminal (github.com)
39. 對《創:戰紀》中Shell歷史場景的吹毛求疵 Nitpicking the shell history scene in ‘Tron: Legacy’ (www.chiark.greenend.org.uk)
47. 在不使用跳板函數的情況下,使用 GCC 的嵌套函數與寬指針 Using GCC''s Nested Functions with Wide Pointers and no Trampolines (uecker.codeberg.page)
54. Gleam,快兩歲生日快樂——路易斯·皮爾福德——Gleam聚會2026 Happy almost 2nd Birthday Gleam - Louis Pilfold - Gleam Gathering 2026 (youtu.be)
57. Atom 耗盡並非“自傷陷阱”。它佔我們已知漏洞(CVEs)的三分之一 Atom Exhaustion Is Not a Footgun. It''s One Third of Our CVEs (erlef.org)
63. Sidekick:在十幾個代理重寫你的代碼時,繼續使用 Neovim Sidekick: keep using neovim while a dozen agents rewrite your code (github.com)
67. 不妨將 Emacs 視作你的“孤獨堡壘” May I recommend thinking of Emacs as your Fortress of Solitude (martinsos.com)
69. CVE-2026-48710 Starlette 主機頭身份驗證繞過漏洞 CVE-2026-48710 Starlette Host-Header Auth Bypass (badhost.org)
78. 加拿大的C-22法案與收集更多數據帶來的安全成本 Canada’s Bill C-22 and the security cost of collecting more data (tailscale.com)
83. DoomBench 正式發佈——您的數據架構能運行《毀滅戰士》嗎? Introducing DoomBench - Can Your Data Stack Run DOOM? (cedardb.com)
86. 使用 Temporal 構建可擴展的數據攝取管道(上篇) Building a Scalable Ingestion Pipeline with Temporal (Part 1) (blog.rapidflare.ai)
90. 什麼是諧波?一部關於加法合成技術的互動漫畫 What is a harmonic? An interactive comic about additive synthesis (melatonin.dev)
104. 通過 HTTP 提供文件的三種方式:同步、epoll 和 io_uring Serving files over HTTP three ways: synchronous, epoll, and io_uring (theconsensus.dev)
106. 必須安裝 uv 才能構建獨立的 Python 發行版 uv must be installed to build a standalone Python distribution (github.com)
107. 教宗利奧十四世《Magnifica Humanitas》通諭 Encyclical Letter of His Holiness Leo XIV Magnifica Humanitas (www.vatican.va)
118. Lambda on Lambda:AWS 上的無服務器 Haskell Lambda on Lambda: Serverless Haskell on AWS (jackkelly.name)
125. JS Crossword——一款謎題提示等於 eval(答案) 的填字遊戲 JS Crossword - a crossword where the clue eval(answer) (lyra.horse)
131. 我的這款輕量級、內存安全的 Go 版 rsync 是如何規避安全漏洞的 How my minimal, memory-safe Go rsync steers clear of vulnerabilities (michael.stapelberg.ch)
134. 一萬行代碼之後:當一個工具演變為編譯器——羅布·達斯特——Gleam Gathering 2026 10,000 Lines Later: When a Tool Became a Compiler - Rob Durst - Gleam Gathering 2026 (www.youtube.com)
136. fht-compositor:一款支持動態平鋪的 Wayland 合成器 fht-compositor: A dynamic tiling Wayland compositor (github.com)
139. 批量 memmove 能否加快 std::remove_if 的執行速度?(不能。) Does bulk memmove speed up std::remove_if? (No.) (quuxplusone.github.io)
150. 對1980年“太空實驗室”計算機電路進行逆向工程 Reverse engineering circuitry in a Spacelab computer from 1980 (www.righto.com)
154. z386:基於原始微代碼構建的開源 80386 處理器 - Small Things Retro z386: An Open-Source 80386 Built Around Original Microcode - Small Things Retro (nand2mario.github.io)
155. 在 C 中仍然無法使用的 C 語言結構——以及少數發生變化的結構 C Constructs That Still Don’t Work in C — and a Few That Changed (lospino.so)
159. 使用 Gomobile 和 Gopherjs 實現動態二維碼數據傳輸 Animated QR data transfer with Gomobile and Gopherjs (divan.dev)
163. 惠普收購了Hyperspace,並曾提供過3種不同的預啟動或啟動過程中操作系統,其中包括Quickweb HP bought Hyperspace, & once offered 3 different pre-boot or in-boot OSs, including Quickweb (gekk.info)
167. 一套用於編輯和發佈RFC的全新現代化工具即將推出 A new suite of modern tools coming for editing and publishing RFCs (www.ietf.org)
171. SPy:一種用於靜態類型化 Python 變體的解釋器和編譯器 SPy: an interpreter and a compiler for a statically typed variant of Python (github.com)
173. 在命令行中調整 Mac 的系統音量 Adjusting a Mac''s System Volume on the Command Line (excessivelyadequate.com)
174. 在四款老舊CPU上對比LZ4解壓縮器 Comparing an LZ4 Decompressor on four legacy CPUs (bumbershootsoft.wordpress.com)
176. CVE-2026-46529:Linux PDF 閱讀器(XReader/Evince/Atril)中存在一個已存在 10 年的遠程代碼執行漏洞 CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril) (medeiros.zip)
179. account-center:用於內部服務和知識庫文章的自託管、支持 OIDC 身份驗證的門戶 account-center: Self-hosted, OIDC-authenticated portal for internal services and knowledge base articles (git.sr.ht)
181. 在所有64位整數中,只有17%是由兩個32位整數相乘得到的 Only 17% of all 64-bit Integers are products of two 32-bit integers (lemire.me)
182. Apple corecrypto 形式驗證藍圖 A blueprint for formal verification of Apple corecrypto (security.apple.com)
183. 開源領域的職業倦怠:一個我們可以共同解決的結構性問題 Burnout in Open Source: A Structural Problem We Can Fix Together (opensourcepledge.com)
185. 《Qud洞穴》(2019)中的端到端程序化生成 End-to-End Procedural Generation in Caves of Qud (2019) (www.youtube.com)
191. 巨齒鯊:利用 CI 工作流對大量 GitHub 倉庫植入後門 Megalodon: Mass GitHub Repo Backdooring via CI Workflows (safedep.io)
192. 安全啟動與證書頒發機構輪換——致各發行版的提醒 Secure Boot and CA Rollover - a heads-up for distributions (blog.einval.com)
193. 這個博客在 Ubuntu 16.04 上運行了 10 年。我已將其遷移至 FreeBSD This blog ran on Ubuntu 16.04 for 10 years. I migrated it to FreeBSD (crocidb.com)
195. 《離散事件仿真與分佈式併發控制中的虛擬時間》(1985) Virtual Time for discrete event simulation and distributed concurrency control (1985) (worrydream.com)
197. 美國聯邦貿易委員會(FTC)將要求考克斯傳媒集團支付近100萬美元,以了結其就“主動傾聽”人工智能營銷服務誤導客戶的指控 FTC to Require Cox Media Group to Pay Nearly 1million to Settle Charges They Deceived Customers About “Active Listening” AI-Powered Marketing Service (www.ftc.gov)
198. 即使您已刪除 Google API 密鑰,它們仍會繼續生效,時間之長足以被不法分子利用 Google API keys keep working after you delete them long enough to be exploited (www.aikido.dev)
199. Gnutella:一種比其誕生的世界更長久的協議 Gnutella: A Protocol Outlives the World That Created It (rickcarlino.com)
203. 利用通過 USB/IP 連接 WebUSB 的瀏覽器內 Linux 虛擬機,讓舊掃描儀重獲新生 Reviving old scanners with an in-browser Linux VM bridged to WebUSB over USB/IP (yes-we-scan.app)
204. CVE-2026-47243:Kata Containers 通過 virtiofs 實現從 guest-root 到 host-root 的權限提升 CVE-2026-47243: Kata Containers guest-root to host-root escape via virtiofs (www.openwall.com)
209. 依賴冷卻時間不公平;我們應該改用分階段推出 Dependency cooldowns are unfair; we should use phased rollouts instead (illegalcode.net)
213. Gobee:使用 Go 語言編寫 eBPF 程序,並通過 clang 進行轉譯 Gobee: write eBPF programs in Go, transpiled via clang (github.com)
214. Ursula:面向 HTTP 事件流的、採用“每個核心一個線程”架構的多 Raft 運行時(Rust 實現) Ursula: thread-per-core, multi-Raft Rust runtime for HTTP event streams (github.com)
217. Go 語言中的 L1 指令緩存集衝突、關聯度與代碼對齊 L1 instruction cache set conflicts, associativity, and code alignment in Go (blog.andr2i.com)
220. Python 3.15:那些未被廣泛報道的新特性 Python 3.15: features that didn''t make the headlines (blog.changs.co.uk)
225. [RFC] LLVM 基金會關於支持標準文檔開放獲取的聲明 [RFC] LLVM Foundation statement in favor of open access to standards documents (discourse.llvm.org)
228. 那些咄咄逼人的AI爬蟲,讓運營維基變得有點讓人頭疼 Aggressive AI scrapers are making it kinda suck to run wikis (weirdgloop.org)
229. Waterfox 6.6.13 版本移除了 Startpage 作為默認搜索提供商 Waterfox Release 6.6.13 removes Startpage as default search provider (www.waterfox.com)
232. OpenAI的一個模型推翻了離散幾何學中的一項核心猜想 An OpenAI model has disproved a central conjecture in discrete geometry (openai.com)
237. Chromium在4年後發佈了針對該漏洞的修復補丁,結果發現該漏洞實際上並未得到修復 Chromium publishes fixed exploit 4 years later, turns out it''s actually unfixed (infosec.exchange)
238. 圍繞用戶修改智能電視軟件權利的多年之爭即將進入庭審階段 Yearslong fight over users'' right to tweak smart TV software heads to trial (arstechnica.com)
239. XSS 對密鑰而言致命:認證機制的隱性風險 XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None (scotthelme.co.uk)
240. Linux 內核中 __ptrace_may_access() 函數的邏輯漏洞 (CVE-2026-46333) Logic bug in the Linux kernel''s __ptrace_may_access() function (CVE-2026-46333) (cdn2.qualys.com)
242. glibc 的 malloc 中如何實現跨線程雙重釋放檢測 How cross-thread double free detection could work in glibc malloc (kallus.org)
246. modulejail:通過將所有當前未使用的模塊加入黑名單,主動縮小 Linux 主機的內核模塊攻擊面 modulejail: Proactively shrink a Linux host''s kernel-module attack surface by blacklisting every module not currently in use (github.com)
247. Grafana Labs 的 GitHub 倉庫因 TanStack npm 供應鏈攻擊而遭到入侵 Grafana Labs GitHub repos breached via TanStack npm supply chain attack (grafana.com)
258. GitHub 源代碼洩露事件——TeamPCP 聲稱已獲取內部源代碼 GitHub Source Code Breach - TeamPCP Claims Access to Internal Source Code (cybersecuritynews.com)
259. 如果你就那樣坐在那裡無所事事,那至少要把這無所事事做得像樣點 If you''re just going to sit there doing nothing, at least do nothing correctly (devblogs.microsoft.com)
261. 我建立了一個虛擬博物館,裡面幾乎囊括了你能想到的所有操作系統 I''ve built a virtual museum with nearly every operating system you can think of (www.youtube.com)
269. 關於基於屬性的測試在驗證形式化規格說明方面的“不可思議的有效性” On the Unreasonable Effectiveness of Property-Based Testing for Validating Formal Specifications (proofsandintuitions.net)
270. pg_deltax:一款基於Apache許可證的PostgreSQL時間序列擴展 pg_deltax: Apache-licensed time-series extension for PostgreSQL (github.com)
274. 我們在強化 Turso 安全性的過程中,如何利用 Quint 發現 SQLite 中超過 10 個漏洞 How we used Quint to find over 10 bugs in SQLite while hardening Turso (turso.tech)
275. 技術揭秘:構建實時和絃識別器 Under the Hood: Building a Real-Time Chord Recognizer (whatchord.earthmanmuons.com)
282. 一個用 C 語言編寫的自平衡跳躍表(又稱“splay-list”)庫 A self-balancing skip-list (aka "splay-list") library in C (codeberg.org)
283. Lime,一款可在運行時合併語法的解析器生成器 Lime, a parser generator that can merge grammars at runtime (codeberg.org)
284. Noxu DB,Berkeley DB Java Edition 的 Rust 移植版 Noxu DB, a Rust port of Berkeley DB Java Edition (codeberg.org)
285. ProseMirror 模型在富文本轉換中的超乎尋常的有效性 The Unreasonable Effectiveness of ProseMirror Model in Rich Text Transformation (smoores.dev)
286. Windows DLL 加載器鎖:Rust 線程如何導致 JVM 掛起 The Windows DLL loader lock: how a Rust thread can hang your JVM (questdb.com)
291. 利用代數和大型語言模型在Lean中驗證飛行計劃漏洞修復 Using algebra and LLMs to verify a flight-plan bug fix in Lean (jameshaydon.github.io)
295. Casuarina Linux 簡介:一款基於 glibc 的 Chimera Linux 衍生版 Introducing Casuarina Linux: A glibc-Based Chimera Linux Derivative (casuarina.org)
297. CISA管理員在GitHub上洩露了AWS GovCloud密鑰 CISA Admin Leaked AWS GovCloud Keys on Github (krebsonsecurity.com)
300. cargo-crap:在 AI 生成的 Rust 代碼中發現未經測試的複雜性 cargo-crap: Finding Untested Complexity in AI-Generated Rust Code (minikin.me)