<?xml version="1.0"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
	<title>Developers Planet</title>
	<link>https://devplanet.one.pl/</link>
	<language>en</language>
	<description>Developers Planet - https://devplanet.one.pl/</description>
	<atom:link rel="self" href="https://devplanet.cf/rss20.xml" type="application/rss+xml"/>


<item>
	<title>Peter Czanik: Syslog-ng hardening using Tor</title>
	<guid isPermaLink="false">tag:https://peter.czanik.hu/,2026-07-29:https://peter.czanik.hu/other/syslog-ng-hardening-using-tor/</guid>
	<link>https://peter.czanik.hu/other/syslog-ng-hardening-using-tor/</link>
	<description>For many years, I didn’t think that Tor could be useful for me. However, I’ve recently found a Gist on GitHub that describes how you can use it to harden your central syslog-ng server. And while I have yet to try it, at least now I have a reason to actually test Tor.
The Tor website describes the project as follows: “Protect yourself against tracking, surveillance, and censorship.” I live in a country where thankfully I do not need these, nor do I perform any activities for which Tor would be useful.</description>
	<pubDate>Wed, 29 Jul 2026 11:37:05 +0000</pubDate>
</item>

<item>
	<title>Marcin Juszkiewicz: New keyboard: Alicja v2</title>
	<guid isPermaLink="false">tag:https://marcin.juszkiewicz.com.pl/,2026-07-29:https://marcin.juszkiewicz.com.pl/2026/07/29/new-keyboard-alicja-v2/</guid>
	<link>https://marcin.juszkiewicz.com.pl/2026/07/29/new-keyboard-alicja-v2/</link>
	<description>&lt;p&gt;After over a year of using 
&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2025/03/09/i-built-my-first-mechanical-keyboard/&#34;&gt;Alicja, my prototype keyboard&lt;/a&gt;,
it is time to build a new one: Alicja&amp;nbsp;v2.&lt;/p&gt;
&lt;!--MORE--&gt;

&lt;h3&gt;Experiments&lt;/h3&gt;
&lt;p&gt;Since building Alicja v1, I have been trying out a few design ideas. Some were
intended to make the board sturdier, such as 3D printing a far better plate for
another handwired&amp;nbsp;build.&lt;/p&gt;
&lt;p&gt;I tried different layouts. 3D printed a case for Redox keyboard, built one half
and tried to use it. Not my style as it is too far from typical pc105&amp;nbsp;layout.&lt;/p&gt;
&lt;p&gt;Created the H261 keyboard as some kind of orthogonal Alicja but it was too&amp;nbsp;awful.&lt;/p&gt;
&lt;h3&gt;&lt;span class=&#34;caps&#34;&gt;KLE&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;NG&lt;/span&gt; to the&amp;nbsp;rescue&lt;/h3&gt;
&lt;p&gt;I used &lt;a href=&#34;https://www.keyboard-layout-editor.com/&#34;&gt;Keyboard Layout Editor (&lt;span class=&#34;caps&#34;&gt;KLE&lt;/span&gt;)&lt;/a&gt;
with several of my keyboard experiments. And one day I got info from Adam
Wysocki (adamws) about his &lt;a href=&#34;https://editor.keyboard-tools.xyz/&#34;&gt;&lt;span class=&#34;caps&#34;&gt;KLE&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;NG&lt;/span&gt;&lt;/a&gt; online
tool. Which changed&amp;nbsp;everything&amp;#8230;&lt;/p&gt;
&lt;p&gt;You see, with previous tools, designing a keyboard was a lot of work. Now, with
&lt;span class=&#34;caps&#34;&gt;KLE&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;NG&lt;/span&gt;, it is a matter of creating a design and pressing some buttons. The
result consists of &lt;span class=&#34;caps&#34;&gt;PCB&lt;/span&gt; files for KiCAD and plate files for &lt;span class=&#34;caps&#34;&gt;CAD&lt;/span&gt;&amp;nbsp;software.&lt;/p&gt;
&lt;h3&gt;KiCAD&lt;/h3&gt;
&lt;p&gt;I loaded files created by &lt;span class=&#34;caps&#34;&gt;KLE&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;NG&lt;/span&gt; and it turned out that making a &lt;span class=&#34;caps&#34;&gt;PCB&lt;/span&gt; for a new
keyboard is quite&amp;nbsp;simple:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;add &lt;span class=&#34;caps&#34;&gt;MCU&lt;/span&gt; (I used &lt;a href=&#34;https://www.solder.party/docs/rp2040-stamp/&#34;&gt;&lt;span class=&#34;caps&#34;&gt;RP2040&lt;/span&gt; Stamp&lt;/a&gt; from Solder&amp;nbsp;Party)&lt;/li&gt;
&lt;li&gt;add&amp;nbsp;encoder&lt;/li&gt;
&lt;li&gt;add whatever&amp;nbsp;else&lt;/li&gt;
&lt;li&gt;route&amp;nbsp;everything&lt;/li&gt;
&lt;li&gt;define &lt;span class=&#34;caps&#34;&gt;PCB&lt;/span&gt;&amp;nbsp;edge&lt;/li&gt;
&lt;li&gt;generate gerber&amp;nbsp;files&lt;/li&gt;
&lt;li&gt;order &lt;span class=&#34;caps&#34;&gt;PCB&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;During the whole process I learnt a lot, mostly from my friends in the retro&amp;nbsp;community.&lt;/p&gt;
&lt;figure id=&#34;__yafg-figure-1&#34;&gt;
&lt;img alt=&#34;PCB in KiCAD&#34; src=&#34;https://marcin.juszkiewicz.com.pl/files/2026/07/pcb-700x.jpg&#34; title=&#34;PCB in KiCAD&#34; /&gt;
&lt;figcaption&gt;&lt;span class=&#34;caps&#34;&gt;PCB&lt;/span&gt; in KiCAD&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;I ordered &lt;span class=&#34;caps&#34;&gt;PCB&lt;/span&gt; in China, the process and shiping took about two weeks and I had
five PCBs ready for&amp;nbsp;soldering:&lt;/p&gt;
&lt;figure id=&#34;__yafg-figure-2&#34;&gt;
&lt;img alt=&#34;The physical PCB&#34; src=&#34;https://marcin.juszkiewicz.com.pl/files/2026/07/pcb-real-700x.jpg&#34; title=&#34;The physical PCB&#34; /&gt;
&lt;figcaption&gt;The physical &lt;span class=&#34;caps&#34;&gt;PCB&lt;/span&gt;&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h3&gt;Changes since the first Alicja&amp;nbsp;keyboard&lt;/h3&gt;
&lt;p&gt;As you may see the main change is the &lt;span class=&#34;caps&#34;&gt;PCB&lt;/span&gt;. Handwired keyboard had its own value
but in the long run was a source of problems and&amp;nbsp;frustration.&lt;/p&gt;
&lt;p&gt;I changed the &lt;span class=&#34;caps&#34;&gt;MCU&lt;/span&gt; board, as &lt;span class=&#34;caps&#34;&gt;RP2040&lt;/span&gt; Stamp allowed me to put &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt; signals on a
connector instead of having it on &lt;span class=&#34;caps&#34;&gt;MCU&lt;/span&gt; board. It will help when I add &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt; hub to
the&amp;nbsp;keyboard.&lt;/p&gt;
&lt;p&gt;The whole keyboard uses Kailh &lt;span class=&#34;caps&#34;&gt;MX&lt;/span&gt; hotswap sockets to make it easier to play with
different switches. At the moment I am using some brown ones I got for free at
the &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2025/10/15/mechanicon-2025/&#34;&gt;Mechanicon 2025&lt;/a&gt;&amp;nbsp;event.&lt;/p&gt;
&lt;p&gt;I kept only one encoder &amp;#8212; the one for media control. By default it changes
volume level (and mutes on press). With the Fn key I can change to next/prev
song and play/pause&amp;nbsp;it.&lt;/p&gt;
&lt;p&gt;There are some more keys &amp;#8212; I added right Control key as I missed it several
times. The whole Home/End/Ins/Del/PgUp/PgDn block is present. In a different
setup than usual so adapting to it will take some time. And I have now F13 and
F14 keys (not decided yet what to define on&amp;nbsp;them).&lt;/p&gt;
&lt;p&gt;The space in the middle got one of those funny 5-way switches. I have not
decided how to use it yet. Maybe it will be some kind of silly&amp;nbsp;mouse.&lt;/p&gt;
&lt;p&gt;There is a connector with some free &lt;span class=&#34;caps&#34;&gt;GPIO&lt;/span&gt; lines and power. Who knows, maybe one
day I will decide to make a hole and add a trackpoint from some old Lenovo&amp;nbsp;laptop.&lt;/p&gt;
&lt;p&gt;I also have stabilisers for all 2u+ keycaps. Finally&amp;nbsp;;D&lt;/p&gt;
&lt;p&gt;And the last change: a simple, 3D-printed case. Mounted on a few M2 screws (I
used M2 threaded inserts). Will be replaced with a better design one&amp;nbsp;day.&lt;/p&gt;
&lt;figure id=&#34;__yafg-figure-3&#34;&gt;
&lt;img alt=&#34;Temporary case&#34; src=&#34;https://marcin.juszkiewicz.com.pl/files/2026/07/case1-700x.jpg&#34; title=&#34;Temporary case&#34; /&gt;
&lt;figcaption&gt;Temporary case&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h3&gt;Mistakes&lt;/h3&gt;
&lt;p&gt;Of course, I had to make a few&amp;nbsp;mistakes.&lt;/p&gt;
&lt;p&gt;The main one, visible in the picture above, is the left space key. I used a 2u
size for it instead of a 2.25u one. As a result, I had to choose some non-blank
keycap from
&lt;a href=&#34;https://en.akkogear.com/product/wob-building-blocks-keycap-set282-key/&#34;&gt;the Akko &lt;span class=&#34;caps&#34;&gt;WOB&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;MDA&lt;/span&gt; set&lt;/a&gt;
instead of using a 2.25u blank&amp;nbsp;one.&lt;/p&gt;
&lt;p&gt;The other, not visible one, is the footprint of the 5-way switch. It does not
work as expected. However, I might just need to re-solder the diodes the other
way round, and it will&amp;nbsp;work.&lt;/p&gt;
&lt;p&gt;The connectors on the bottom side (both for the &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt;+buttons and the expansion
port) are a bit bulky &amp;#8212; I used &lt;span class=&#34;caps&#34;&gt;JST&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;XH&lt;/span&gt; 2.54 ones here. They were supposed to be
used as &lt;span class=&#34;caps&#34;&gt;THT&lt;/span&gt; rather than as &lt;span class=&#34;caps&#34;&gt;SMD&lt;/span&gt;, so they take a lot of space. Anyway, those are
inside the case, so no one can see&amp;nbsp;them.&lt;/p&gt;
&lt;h3&gt;Plans for&amp;nbsp;changes&lt;/h3&gt;
&lt;p&gt;I need to design a proper case. With space for &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt; ports (two at the back, one on
the left) and an internal &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt;&amp;nbsp;hub.&lt;/p&gt;
&lt;p&gt;I also need a way to attach feet so the keyboard angle can be adjusted (now I
have 4 rubber feet&amp;nbsp;attached).&lt;/p&gt;
&lt;p&gt;And I plan to use it for quite a while. Which will not stop me from working on
some other&amp;nbsp;designs.&lt;/p&gt;</description>
	<pubDate>Wed, 29 Jul 2026 09:26:00 +0000</pubDate>
</item>

<item>
	<title>Peter Czanik: Syslog-ng journald source: how to avoid log bombs on errors?</title>
	<guid isPermaLink="false">tag:https://peter.czanik.hu/,2026-07-22:https://peter.czanik.hu/other/syslog-ng-journald-source-how-to-avoid-log-bombs-on-error/</guid>
	<link>https://peter.czanik.hu/other/syslog-ng-journald-source-how-to-avoid-log-bombs-on-error/</link>
	<description>Choose your poison: Up until version 4.12, when syslog-ng ran into an error jumping to a saved systemd journal position, it read the journal from the beginning. With the latest syslog-ng version, you can configure what happens in case of such an error.
Read more at https://www.syslog-ng.com/community/b/blog/posts/syslog-ng-journald-source-how-to-avoid-log-bombs-on-errors
syslog-ng logo</description>
	<pubDate>Wed, 22 Jul 2026 11:56:05 +0000</pubDate>
</item>

<item>
	<title>Marcin Juszkiewicz: Half my life ago</title>
	<guid isPermaLink="false">tag:https://marcin.juszkiewicz.com.pl/,2026-07-19:https://marcin.juszkiewicz.com.pl/2026/07/19/half-my-life-ago/</guid>
	<link>https://marcin.juszkiewicz.com.pl/2026/07/19/half-my-life-ago/</link>
	<description>&lt;p&gt;Half my life ago, I graduated with a &amp;#8220;magister inżynier&amp;#8221; degree after 5 years of&amp;nbsp;studies.&lt;/p&gt;
&lt;!--MORE--&gt;

&lt;h3&gt;&lt;span class=&#34;caps&#34;&gt;EN&lt;/span&gt;/&lt;span class=&#34;caps&#34;&gt;US&lt;/span&gt;&amp;nbsp;terminology&lt;/h3&gt;
&lt;p&gt;How to translate this &amp;#8220;magister inżynier&amp;#8221; into English? Well, it depends where
you ask. In some places, it would be &amp;#8220;Master of Science&amp;#8221;, others will say that it
was &amp;#8220;Master of Engineering&amp;#8221;. But does it matter? Not for&amp;nbsp;me.&lt;/p&gt;
&lt;p&gt;I studied &amp;#8220;automation and robotics&amp;#8221; at the Faculty of Mechanical Engineering at
the Białystok University of Technology. And specialised in the &amp;#8220;Information&amp;nbsp;Systems&amp;#8221;:&lt;/p&gt;
&lt;figure id=&#34;__yafg-figure-1&#34;&gt;
&lt;img alt=&#34;&#39;entry in &amp;quot;the index&amp;quot; document&#39;&#34; src=&#34;https://marcin.juszkiewicz.com.pl/files/2026/07/dyplom-700x.jpg&#34; title=&#34;entry in &amp;quot;the index&amp;quot; document&#34; /&gt;
&lt;figcaption&gt;entry in &amp;#8220;the index&amp;#8221; document&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h3&gt;After&amp;nbsp;studies&lt;/h3&gt;
&lt;p&gt;After graduating, I worked&amp;nbsp;as:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&#34;caps&#34;&gt;PHP&lt;/span&gt;&amp;nbsp;programmer&lt;/li&gt;
&lt;li&gt;Linux/Windows C++&amp;nbsp;programmer&lt;/li&gt;
&lt;li&gt;Build&amp;nbsp;Engineer&lt;/li&gt;
&lt;li&gt;Software&amp;nbsp;Engineer&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Different jobs used different&amp;nbsp;titles.&lt;/p&gt;
&lt;h4&gt;&lt;span class=&#34;caps&#34;&gt;PHP&lt;/span&gt;&amp;nbsp;programmer&lt;/h4&gt;
&lt;p&gt;In retrospect, those were weird years. The salary was low, the job was mostly
boring, but the co-workers were nice. I learned that I did not want to deal with
clients, that &lt;span class=&#34;caps&#34;&gt;SCM&lt;/span&gt; (Source Code Management) matters and how to make people angry
(and how to deal with&amp;nbsp;it).&lt;/p&gt;
&lt;p&gt;On 1st February 2007 I officially forgot all my &lt;span class=&#34;caps&#34;&gt;PHP&lt;/span&gt; knowledge. The day after
&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2007/01/31/last-day-at-conecto/&#34;&gt;my last day at work as a &lt;span class=&#34;caps&#34;&gt;PHP&lt;/span&gt; programmer&lt;/a&gt;.&lt;/p&gt;
&lt;h4&gt;Linux/Windows C++&amp;nbsp;programmer&lt;/h4&gt;
&lt;p&gt;This was a short job. The company specialised in set-top boxes and digital
broadcast software. The team I joined was writing software for both the server
side (Linux) and the client side (&lt;span class=&#34;caps&#34;&gt;MS&lt;/span&gt; Windows). I worked there for four months.
And learnt that Windows programming is definitely not my skill. And that
up-to-date documentation matters &amp;#8212; my first few days were spent reading the
official documentation and crossing out or marking every single outdated&amp;nbsp;part.&lt;/p&gt;
&lt;p&gt;I also learnt that &amp;#8220;fuchsia&amp;#8221; is a colour (it was one of the basic colours in &lt;span class=&#34;caps&#34;&gt;MS&lt;/span&gt;
Windows). For the curious ones: &lt;span style=&#34;color: #f0f;&#34;&gt;Fuchsia is their name
for Magenta&lt;/span&gt;.&lt;/p&gt;
&lt;h4&gt;Build/Software&amp;nbsp;Engineer&lt;/h4&gt;
&lt;p&gt;In September 2006
&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2006/09/12/haerwu-created/&#34;&gt;I created my own, one-person company called &amp;#8220;HaeRWu&amp;#8221;&lt;/a&gt;.
It is the Polish pronunciation of my &amp;#8220;Hrw&amp;#8221; nickname. &lt;span class=&#34;caps&#34;&gt;IPA&lt;/span&gt;: /hʌ eə vʊ/ or /xa ɛə&amp;nbsp;vuː/.&lt;/p&gt;
&lt;p&gt;At first, it was a side job. But it also showed that there is far better money to
be made in the Embedded Linux area. So a few months later, I became Build
Engineer &amp;#8212; a contractor. To OpenedHand, Intel, Vernier, BugLabs, &lt;span class=&#34;caps&#34;&gt;ST&lt;/span&gt; Ericsson,
Canonical, and several&amp;nbsp;others.&lt;/p&gt;
&lt;h3&gt;The irony of it&amp;nbsp;all&lt;/h3&gt;
&lt;p&gt;During all those years, I used to say that I do not work at things related to
what I studied. But in reality, I&amp;nbsp;did.&lt;/p&gt;
&lt;p&gt;It was not &amp;#8220;automation&amp;#8221; (unless we count Buildbot, Jenkins, and other &lt;span class=&#34;caps&#34;&gt;CI&lt;/span&gt;/&lt;span class=&#34;caps&#34;&gt;CD&lt;/span&gt;
systems I worked&amp;nbsp;with).&lt;/p&gt;
&lt;p&gt;It was not &amp;#8220;robotics&amp;#8221; but several robots use OpenEmbedded/Yocto derived
operating systems. And for quite a while, I was one of top contributors to those&amp;nbsp;projects.&lt;/p&gt;
&lt;p&gt;But it was definitely &amp;#8220;information systems&amp;#8221;. As this name is so generic that almost
everything I did&amp;nbsp;fits.&lt;/p&gt;</description>
	<pubDate>Sun, 19 Jul 2026 10:04:00 +0000</pubDate>
</item>

<item>
	<title>Peter Czanik: Syslog-ng 4.12.0 available for Ubuntu 26.04 (Resolute)</title>
	<guid isPermaLink="false">tag:https://peter.czanik.hu/,2026-07-14:https://peter.czanik.hu/other/syslog-ng-412-available-for-ubuntu-resolute/</guid>
	<link>https://peter.czanik.hu/other/syslog-ng-412-available-for-ubuntu-resolute/</link>
	<description>Recently I was asked if syslog-ng supports Ubuntu 26.04 (Ubuntu Resolute). Yes, and with the arrival of the syslog-ng 4.12.0 release we also provide ready-to-use packages for it. The release notes mention it, and info is in the Readme on GitHub.
I tend to mention FreeBSD and openSUSE more often in my blogs (personal preference), so today I installed Ubuntu 26.04 and tested syslog-ng myself.
Read more at https://www.syslog-ng.com/community/b/blog/posts/syslog-ng-4-12-0-available-for-ubuntu-26-04-resolute
syslog-ng logo</description>
	<pubDate>Tue, 14 Jul 2026 12:41:41 +0000</pubDate>
</item>

<item>
	<title>Peter Czanik: Syslog-ng Java destination disabled</title>
	<guid isPermaLink="false">tag:https://peter.czanik.hu/,2026-07-09:https://peter.czanik.hu/other/syslog-ng-java-destination-disabled/</guid>
	<link>https://peter.czanik.hu/other/syslog-ng-java-destination-disabled/</link>
	<description>For many years, syslog-ng used Java, where C libraries were unavailable. However, over the years native C libraries became available for Elasticsearch and Kafka, and HDFS practically disappeared. As a “scream test”, I am going to disable Java support in all of my syslog-ng packages.
Once upon a time, Java support was added to syslog-ng to be able to load Elasticsearch Java drivers. Later, Kafka, HDFS, and a generic HTTP destination were also added.</description>
	<pubDate>Thu, 09 Jul 2026 13:19:41 +0000</pubDate>
</item>

<item>
	<title>Steve McIntyre: It's dead, Jim!</title>
	<guid isPermaLink="false">tag:https://blog.einval.com,2026-06-27:https://blog.einval.com/2026/06/27#its_dead_jim</guid>
	<link>https://blog.einval.com/2026/06/27#its_dead_jim</link>
	<description>&lt;p&gt;I previously wrote about the
  upcoming &lt;a href=&#34;https://blog.einval.com/2026/06/05#secure_boot_ca_rollover_docs&#34;&gt;UEFI
  CA rollover&lt;/a&gt;. Well, it&#39;s happened now - the old Microsoft UEFI
  CA from 2011 expired &lt;strong&gt;yesterday&lt;/strong&gt;:
&lt;/p&gt;

&lt;p&gt;
&lt;strong&gt;Third Party Marketplace Root (used for signing option ROMs and other software)&lt;/strong&gt;&lt;br /&gt;
&lt;tt&gt;&lt;pre&gt;
  Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011
  Validity
    Not Before: Jun 27 21:22:45 2011 GMT
    Not After : Jun 27 21:32:45 2026 GMT
&lt;/pre&gt;&lt;/tt&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It&#39;s dead - it&#39;s not coming back...&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The world doesn&#39;t seem to have ended yesterday, so I guess we did
ok? :-) &lt;/p&gt;

&lt;h2&gt;How did we do?&lt;/h2&gt;

&lt;p&gt;After a lot of prodding behind the scenes, Debian and many other
distributions managed to get new shim binaries dual-signed with both
the old and new CAs. The members of the shim-review team did a
sterling job with reviews in the last few weeks. Since I started
pushing people in May, we&#39;ve had 21 reviews accepted successfully -
see &lt;a href=&#34;https://github.com/rhboot/shim-review/issues?q=is%3Aissue%20-label%3Ameta%20-label%3APSA%20created%3A%3E2026-05-01&#34;&gt;here&lt;/a&gt;
for the list. Great stuff! Microsoft have also been working quickly -
many of those shim submissions were accepted and signed by Microsoft
very quickly too, with a turnaround time of less than 1 day in some
cases.&lt;/p&gt;

&lt;p&gt;Not all of those signed shims have been published and used by the
distros involved yet, but expect to see them in the wild in the coming
weeks and months.&lt;/p&gt;

&lt;p&gt;These binaries should be good for people to use for the foreseeable
future, until either we need to do another CA rollover or (sadly, more
likely) we find an issue in shim that necessitates a new release.&lt;/p&gt;

&lt;h2&gt;What&#39;s next?&lt;/h2&gt;

&lt;p&gt;We already have &lt;strong&gt;one&lt;/strong&gt; of our new dual-signed shim
binaries in place in Debian, in unstable and testing (Forky) right
now. In a couple of weeks from now, we&#39;ll be rolling out very similar
new dual-signed shim binaries in the next point releases for Debian 12
(bookworm) and Debian 13 (trixie). We&#39;ll also be
upgrading &lt;code&gt;fwupd&lt;/code&gt; in both those point releases, to make DB
and KEK updates work better.&lt;/p&gt;

&lt;p&gt;For more information about these updates,
see &lt;a href=&#34;https://wiki.debian.org/SecureBoot/CAChanges&#34;&gt;https://wiki.debian.org/SecureBoot/CAChanges&lt;/a&gt;. For
your own safety, validate that your systems are updated when
possible. If you don&#39;t, they may fail to boot in future.</description>
	<pubDate>Sat, 27 Jun 2026 21:33:00 +0000</pubDate>
</item>

<item>
	<title>Marcin Juszkiewicz: The end of the AArch64 desktop experiment</title>
	<guid isPermaLink="false">tag:https://marcin.juszkiewicz.com.pl/,2026-06-26:https://marcin.juszkiewicz.com.pl/2026/06/26/the-end-of-the-aarch64-desktop-experiment/</guid>
	<link>https://marcin.juszkiewicz.com.pl/2026/06/26/the-end-of-the-aarch64-desktop-experiment/</link>
	<description>&lt;p&gt;After about eleven months of using an AArch64 desktop, I decided to end that&amp;nbsp;experiment.&lt;/p&gt;
&lt;!--MORE--&gt;

&lt;h3&gt;Hardware&amp;nbsp;used&lt;/h3&gt;
&lt;p&gt;About a year ago, &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2025/06/27/bought-myself-an-ampere-altra-system/&#34;&gt;I bought myself an Ampere Altra system&lt;/a&gt;.
After moving some hardware around and making a few extra orders, the final setup&amp;nbsp;was:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&amp;nbsp;&lt;/th&gt;
&lt;th&gt;&amp;nbsp;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span class=&#34;caps&#34;&gt;CPU&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;Ampere Altra Q80-30 processor (80 cores at 3.0GHz)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span class=&#34;caps&#34;&gt;RAM&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;128 &lt;span class=&#34;caps&#34;&gt;GB&lt;/span&gt; (8x &lt;span class=&#34;caps&#34;&gt;16GB&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;HMA82GR7CJR8N&lt;/span&gt;-&lt;span class=&#34;caps&#34;&gt;XN&lt;/span&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span class=&#34;caps&#34;&gt;GPU&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;&lt;span class=&#34;caps&#34;&gt;AMD&lt;/span&gt; Radeon &lt;span class=&#34;caps&#34;&gt;RX6700XT&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span class=&#34;caps&#34;&gt;NVME&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;Lexar &lt;span class=&#34;caps&#34;&gt;LM970&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;2TB&lt;/span&gt;&lt;br /&gt; &lt;span class=&#34;caps&#34;&gt;ADATA&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;SX8200&lt;/span&gt; Pro &lt;span class=&#34;caps&#34;&gt;1TB&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Motherboard&lt;/td&gt;
&lt;td&gt;ASRock Rack &lt;span class=&#34;caps&#34;&gt;ALTRAD8UD&lt;/span&gt;-&lt;span class=&#34;caps&#34;&gt;1L2T&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span class=&#34;caps&#34;&gt;PSU&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;&lt;span class=&#34;caps&#34;&gt;MSI&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;MPG&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;A850G&lt;/span&gt; (850W)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Case&lt;/td&gt;
&lt;td&gt;Endorfy 700 Air&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span class=&#34;caps&#34;&gt;USB3&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;no-name &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt; 3.2/10Gbps controller (PCIe x4)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;To be fair, I should mention that this is a server motherboard, not a desktop
one, and Altra systems were never meant to be desktops (despite companies
selling them as such). Naturally, the list of tested/approved devices (Qualified
Vendor List (&lt;span class=&#34;caps&#34;&gt;QVL&lt;/span&gt; for &lt;span class=&#34;caps&#34;&gt;TLA&lt;/span&gt; fans)) is quite short and for Ampere Altra systems, it
does not contain &lt;span class=&#34;caps&#34;&gt;AMD&lt;/span&gt; Radeon &lt;span class=&#34;caps&#34;&gt;GPU&lt;/span&gt; cards. They can be made to work, but this often
requires additional&amp;nbsp;effort.&lt;/p&gt;
&lt;p&gt;The extra &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt; 3.2 controller allowed me to have more &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt; devices than the
motherboard alone supported, and gave me some 10Gbps ports for connecting
external NVMe&amp;nbsp;drives.&lt;/p&gt;
&lt;p&gt;The whole system was running just fine&lt;sup&gt;*&lt;/sup&gt; under Fedora&amp;nbsp;42–44.&lt;/p&gt;
&lt;h3&gt;The first&amp;nbsp;issue&lt;/h3&gt;
&lt;p&gt;Have you noticed the small &amp;#8220;*&amp;#8221; at the end of the previous paragraph? The system
I used was not quite Fedora &amp;#8212; I had to use my own, self-built&amp;nbsp;kernel.&lt;/p&gt;
&lt;p&gt;You see, the &lt;span class=&#34;caps&#34;&gt;PCI&lt;/span&gt; Express controller in the Ampere Altra has some issues. Let me
quote the description of
&lt;a href=&#34;https://github.com/AmpereComputing/linux-ampere-altra-erratum-pcie-65&#34;&gt;the Ampere Altra erratum 82288&lt;/a&gt;&amp;nbsp;patches:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Per Altra family erratum, PCIE_65 may cause invalid addresses to be generated
on PCIe mmio writes, impacting certain device types, notably &lt;span class=&#34;caps&#34;&gt;AMD&lt;/span&gt; GPUs, and
thus the Altra family is not generally compatible with those device&amp;nbsp;types.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And longer description from patch&amp;nbsp;itself:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;PCIe device drivers may map &lt;span class=&#34;caps&#34;&gt;MMIO&lt;/span&gt; space as Normal, non-cacheable memory
attribute (e.g. Linux kernel drivers mapping &lt;span class=&#34;caps&#34;&gt;MMIO&lt;/span&gt; using ioremap_wc). This may
be for the purpose of enabling write combining or unaligned accesses. This can
result in data corruption on the PCIe interface’s outbound &lt;span class=&#34;caps&#34;&gt;MMIO&lt;/span&gt; writes due to
issues with the write-combining&amp;nbsp;operation.&lt;/p&gt;
&lt;p&gt;The workaround modifies software that maps PCIe &lt;span class=&#34;caps&#34;&gt;MMIO&lt;/span&gt; space as Normal,
non-cacheable memory (e.g. ioremap_wc) to instead Device, non-gathering memory
(e.g. ioremap). And all memory operations on PCIe &lt;span class=&#34;caps&#34;&gt;MMIO&lt;/span&gt; space must be strictly&amp;nbsp;aligned.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, to have a working Linux system, I had to rebuild the kernel on every package
update. Which usually meant &amp;#8220;weekly&amp;#8221;. Each Monday or Tuesday, I would update
the local copy of the Fedora kernel package repository and build it using my own
versioning scheme, like &amp;#8220;7.0.2-200.fc44.pcie65.6&amp;#8221;. The &amp;#8220;pcie65&amp;#8221; part reminded me
which patches I had applied, and the &amp;#8220;6&amp;#8221; was a counter for the patch&amp;nbsp;rebases.&lt;/p&gt;
&lt;p&gt;I cloned the repository from GitHub and then rebased patches, adapting them
whenever they needed work. The side effect was that I often used a newer kernel
than the official Fedora release &amp;#8212; there is a &amp;#8220;stabilisation&amp;#8221; branch in the
Fedora kernel package repo where the soon-to-be-pushed version is present. So,
when Fedora had 6.19.y kernel, I had 7.0.z&amp;nbsp;one.&lt;/p&gt;
&lt;h3&gt;So many cores, not enough&amp;nbsp;speed&lt;/h3&gt;
&lt;p&gt;As &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2026/06/01/arm-desktop-so-many-cores-not-enough-speed/&#34;&gt;I wrote in my previous post&lt;/a&gt;,
having eighty &lt;span class=&#34;caps&#34;&gt;CPU&lt;/span&gt; cores does not mean that the system is a good, fast desktop&amp;nbsp;machine.&lt;/p&gt;
&lt;h3&gt;&lt;span class=&#34;caps&#34;&gt;AMD&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;GPU&lt;/span&gt; started&amp;nbsp;failing&lt;/h3&gt;
&lt;p&gt;As I mentioned above, to get my &lt;span class=&#34;caps&#34;&gt;AMD&lt;/span&gt; Radeon &lt;span class=&#34;caps&#34;&gt;RX6700XT&lt;/span&gt; running properly I had to
alter kernel with the out-of-tree patches. It worked, I could play some games,
watch videos with hardware-assisted video decode&amp;nbsp;acceleration.&lt;/p&gt;
&lt;p&gt;Until one day, around the Linux 7.0 release, when it started to fail. Running a
game ended&amp;nbsp;with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;kernel: amdgpu 0000:03:00.0: Fence fallback timer expired on ring vcn_dec_0
kernel: amdgpu 0000:03:00.0: Fence fallback timer expired on ring vcn_dec_0
kernel: amdgpu 0000:03:00.0: Fence fallback timer expired on ring vcn_dec_0
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Over and over again. Watching YouTube videos became impossible due to 720 out of
750 frames being dropped,&amp;nbsp;etc.&lt;/p&gt;
&lt;p&gt;Normally I would start to bisect the kernel to find out where the problem is.
But I was running a tainted kernel due to &lt;span class=&#34;caps&#34;&gt;PCIE65&lt;/span&gt; patches so who knew where the
problem actually&amp;nbsp;was&amp;#8230;&lt;/p&gt;
&lt;h3&gt;Let&amp;#8217;s get&amp;nbsp;Nvidia&lt;/h3&gt;
&lt;p&gt;I bought an Nvidia &lt;span class=&#34;caps&#34;&gt;RTX&lt;/span&gt; 2060 graphics card and put it in place of the &lt;span class=&#34;caps&#34;&gt;AMD&lt;/span&gt; Radeon.
It turned out that if I wanted to use it with&amp;nbsp;the &lt;code&gt;nouveau&lt;/code&gt; kernel driver I
still needed &lt;span class=&#34;caps&#34;&gt;PCIE65&lt;/span&gt; patches&amp;nbsp;applied&amp;#8230;&lt;/p&gt;
&lt;p&gt;So I tried default Fedora kernel with Nvidia binary driver. And it worked fine.
Video decoding was accelerated, some games under Wine worked as&amp;nbsp;well.&lt;/p&gt;
&lt;p&gt;But then I started FreeCAD. And OrcaSlicer. And in both cases I got crash and&amp;nbsp;exit&amp;#8230;&lt;/p&gt;
&lt;p&gt;It turned out that there was&amp;nbsp;no &lt;code&gt;org.freedesktop.Platform.GL.nvidia&lt;/code&gt; in Flatpak
repositories for AArch64. And I used both of those tools quite&amp;nbsp;often.&lt;/p&gt;
&lt;h3&gt;Powering up the old&amp;nbsp;x86-64&amp;#8230;&lt;/h3&gt;
&lt;p&gt;At that point, I gave up. And booted my x86-64 system, which had been powered
off all that time. There were a lot of cables to move, some new ones to arrange,
and now I have both &amp;#8220;wooster&amp;#8221; (Ampere Altra) and &amp;#8220;puchatek&amp;#8221; (Ryzen 5 3600)
systems running under my&amp;nbsp;desk.&lt;/p&gt;
&lt;p&gt;Moving from 80 cores to 6 cores (12 threads) was a weird experience. A much
smaller number, yet things work fine. I can load all threads and the music still
plays. All games from my Steam library are playable. A working FreeCAD allows me
to finish designing cases for my home projects and I can 3D print prototypes
straight from&amp;nbsp;OrcaSlicer.&lt;/p&gt;
&lt;p&gt;The &amp;#8220;wooster&amp;#8221; system stays powered on, churning through &lt;span class=&#34;caps&#34;&gt;RISC&lt;/span&gt;-V package builds.
It may be weak in single-thread, but it flies when it comes to multi-core&amp;nbsp;load.&lt;/p&gt;
&lt;h3&gt;Conclusion&lt;/h3&gt;
&lt;p&gt;As for the Ampere Altra, I am not planning to repeat this experiment. Another
AArch64 desktop attempt would require a completely new hardware platform. And I
have no plans to spend over twenty thousand &lt;span class=&#34;caps&#34;&gt;PLN&lt;/span&gt; to buy an Nvidia &lt;span class=&#34;caps&#34;&gt;DGX&lt;/span&gt; Spark&amp;nbsp;system.&lt;/p&gt;</description>
	<pubDate>Fri, 26 Jun 2026 11:18:00 +0000</pubDate>
</item>

<item>
	<title>Peter Czanik: syslog-ng 4.12.0, syslog-ng PE 8.2.0 and SSB 7.8.0 are now available</title>
	<guid isPermaLink="false">tag:https://peter.czanik.hu/,2026-06-16:https://peter.czanik.hu/posts/syslog-ng-4120-released/</guid>
	<link>https://peter.czanik.hu/posts/syslog-ng-4120-released/</link>
	<description>Today, the syslog-ng team released three different syslog-ng versions, which provided a good opportunity to wear my “Release is coming” t-shirt. This coordinated release is due to an SQL injection security bug fix, even if most likely it affects less than a handful of people (I mean, is there anyone who still uses SQL to store logs in 2026…?)
Release is coming What’s new? syslog-ng OSE 4.12.0 arrives with performance optimizations, making syslog-ng more scalable in several situations.</description>
	<pubDate>Tue, 16 Jun 2026 14:50:23 +0000</pubDate>
</item>

<item>
	<title>Steve McIntyre: Secure Boot and Microsoft CA Rollover - user-facing documentation</title>
	<guid isPermaLink="false">tag:https://blog.einval.com,2026-06-05:https://blog.einval.com/2026/06/05#secure_boot_ca_rollover_docs</guid>
	<link>https://blog.einval.com/2026/06/05#secure_boot_ca_rollover_docs</link>
	<description>&lt;p&gt;I previously
wrote &lt;a href=&#34;https://blog.einval.com/2026/05/22#secure_boot_ca_rollover&#34;&gt;some
advice&lt;/a&gt; for developers and distributions about the upcoming
Microsoft CA Rollover, and I hope that was useful for people.&lt;/p&gt;

&lt;p&gt;I&#39;ve now also added some user-facing documentation about the CA
rollover in the Debian wiki
at &lt;a href=&#34;https://wiki.debian.org/SecureBoot/CAChanges&#34;&gt;https://wiki.debian.org/SecureBoot/CAChanges&lt;/a&gt;. I&#39;ve
added guidance on managing certificate updates on Debian systems: how
to check if a system needs those updates and various ways to make them
happen. If you&#39;re running Secure Boot systems, this may be important
for you.&lt;/p&gt;

&lt;p&gt;While the same event is the primary cause for these docs, they&#39;re
designed for different people. Again, I hope this new doc is
helpful!&lt;/p&gt;</description>
	<pubDate>Fri, 05 Jun 2026 17:20:00 +0000</pubDate>
</item>

<item>
	<title>Peter Czanik: The status of OpenSSL 4.0 support in syslog-ng</title>
	<guid isPermaLink="false">tag:https://peter.czanik.hu/,2026-06-04:https://peter.czanik.hu/other/syslog-ng-the-status-of-openssl-4-0-support/</guid>
	<link>https://peter.czanik.hu/other/syslog-ng-the-status-of-openssl-4-0-support/</link>
	<description>OpenSSL 4.0 was released just over a month ago. So, how is its support progressing in syslog-ng? Well, Git master already supports it, and the patch is easy to backport to earlier releases. At the same time, version 4.12 will support OpenSSL 4.0 out of the box.
A month ago, someone from Gentoo Linux reached out to the syslog-ng team about OpenSSL 4.0 support. I asked the community about their expectations, knowing that version 4.</description>
	<pubDate>Thu, 04 Jun 2026 12:01:40 +0000</pubDate>
</item>

<item>
	<title>Marcin Juszkiewicz: Arm desktop: so many cores, not enough speed</title>
	<guid isPermaLink="false">tag:https://marcin.juszkiewicz.com.pl/,2026-06-01:https://marcin.juszkiewicz.com.pl/2026/06/01/arm-desktop-so-many-cores-not-enough-speed/</guid>
	<link>https://marcin.juszkiewicz.com.pl/2026/06/01/arm-desktop-so-many-cores-not-enough-speed/</link>
	<description>&lt;p&gt;Using a system with 80 AArch64 cores can be a pleasure. Or a&amp;nbsp;pain&amp;#8230;&lt;/p&gt;
&lt;!--MORE--&gt;

&lt;h3&gt;Multicore&amp;nbsp;heaven?&lt;/h3&gt;
&lt;p&gt;Having 80 cores sounds nice, doesn&amp;#8217;t it? But not so much during actual&amp;nbsp;use&amp;#8230;&lt;/p&gt;
&lt;p&gt;You see, building Fedora packages was flying by. With all cores in use, ccache
buffers filling up (in case of rebuilds), and 128 &lt;span class=&#34;caps&#34;&gt;GB&lt;/span&gt; of &lt;span class=&#34;caps&#34;&gt;RAM&lt;/span&gt; in constant use,&amp;nbsp;etc.&lt;/p&gt;
&lt;p&gt;But at the same time, 100% load on all cores means you cannot listen to music
on Spotify or watch online videos, etc. All that because the &lt;span class=&#34;caps&#34;&gt;CPU&lt;/span&gt; cores are
occupied by the build&amp;nbsp;processes.&lt;/p&gt;
&lt;p&gt;I tried to use cgroups to&amp;nbsp;limit &lt;code&gt;cpu.max&lt;/code&gt; for&amp;nbsp;each &lt;code&gt;fedpkg mockbuild&lt;/code&gt; call. It
did not help much: the audio was still&amp;nbsp;jerky.&lt;/p&gt;
&lt;p&gt;To compare: I wrote this post on a system powered by a Ryzen 5 3600 &lt;span class=&#34;caps&#34;&gt;CPU&lt;/span&gt; while a
package build was running in the background. All twelve &lt;span class=&#34;caps&#34;&gt;CPU&lt;/span&gt; threads were 100%
busy, yet the music did not&amp;nbsp;skip.&lt;/p&gt;
&lt;p&gt;All of this shows that cores-heavy CPUs are perhaps not a good choice for a
desktop machine. Latencies, the scheduler and context switching &amp;#8212; all of this
introduces enough noise to make a desktop user&amp;nbsp;suffer.&lt;/p&gt;
&lt;h3&gt;The lack of single-thread&amp;nbsp;speed&lt;/h3&gt;
&lt;p&gt;Arm processors are good in many cases, as long as you do not need pure,
single-thread, &lt;span class=&#34;caps&#34;&gt;CPU&lt;/span&gt;&amp;nbsp;power.&lt;/p&gt;
&lt;p&gt;It is very noticeable in a web browser. For example, Bitwarden unlocks with a
noticeable delay, while on a Ryzen 5 3600, it is nearly instant. And it feels even
worse when you watch some YouTube videos like &amp;#8220;who will make faster &lt;span class=&#34;caps&#34;&gt;PC&lt;/span&gt; on a €100
budget&amp;#8221;, and then you run the same browser benchmark and get worse&amp;nbsp;results&amp;#8230;&lt;/p&gt;
&lt;p&gt;Many software builds also highlight this problem. I have a feeling that
developers have grown used to a small number of fast &lt;span class=&#34;caps&#34;&gt;CPU&lt;/span&gt; cores, which is the
norm on the x86-64 architecture, and their code is written to take it for&amp;nbsp;granted.&lt;/p&gt;
&lt;p&gt;And then you look at your machine, where 70 cores do nothing, waiting for some
code to finally compile or link. I have seen one software package where the
bootstrap was composed of &lt;strong&gt;&lt;span class=&#34;caps&#34;&gt;TWO&lt;/span&gt;&lt;/strong&gt; source files. Both were over two megabytes in
size and full of machine-generated C code. Two cores were kept busy for quite a
while, while the other 78 had to&amp;nbsp;wait.&lt;/p&gt;
&lt;p&gt;Not much has changed since my
&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2018/06/06/from-the-diary-of-aarch64-porter-parallel-builds/&#34;&gt;the &amp;#8220;From the diary of AArch64 porter — parallel builds&amp;#8221;&lt;/a&gt;
blog post from eight years&amp;nbsp;ago.&lt;/p&gt;
&lt;p&gt;Of course, there are also packages which will take all cores, whole memory and
as much swap as possible, and do magic in nearly no time. When I started build of
the PrusaSlicer package, I had to add some swap because Firefox was gone due
to &lt;span class=&#34;caps&#34;&gt;OOM&lt;/span&gt;. Having less than 2 &lt;span class=&#34;caps&#34;&gt;GB&lt;/span&gt; of &lt;span class=&#34;caps&#34;&gt;RAM&lt;/span&gt; per &lt;span class=&#34;caps&#34;&gt;CPU&lt;/span&gt; core really sucks&amp;nbsp;;D&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;To use a desktop system you do not need many cores. As long as they are&amp;nbsp;fast.&lt;/p&gt;</description>
	<pubDate>Mon, 01 Jun 2026 13:06:00 +0000</pubDate>
</item>

<item>
	<title>Peter Czanik: Nightly syslog-ng containers based on Alma Linux</title>
	<guid isPermaLink="false">tag:https://peter.czanik.hu/,2026-05-26:https://peter.czanik.hu/other/syslog-ng-nightly-containers-based-on-alma-linux/</guid>
	<link>https://peter.czanik.hu/other/syslog-ng-nightly-containers-based-on-alma-linux/</link>
	<description>For many years, the syslog-ng project provided container images based on Debian. Most of our users run syslog-ng on RHEL &amp;amp; compatibles, and have asked for an RPM-based container. So, nightly containers based on Alma Linux are now also available.
A while ago, I prepared a small test project to run syslog-ng in an Alma Linux container: https://www.syslog-ng.com/community/b/blog/posts/experimental-syslog-ng-container-image-based-on-alma-linux However, that was only an experiment which I never updated. Fast forward to today: nightly syslog-ng containers based on the latest syslog-ng git snapshot package builds are now available on the Docker Hub!</description>
	<pubDate>Tue, 26 May 2026 12:02:31 +0000</pubDate>
</item>

<item>
	<title>Marcin Juszkiewicz: 3D printing at home</title>
	<guid isPermaLink="false">tag:https://marcin.juszkiewicz.com.pl/,2026-05-22:https://marcin.juszkiewicz.com.pl/2026/05/22/3d-printing-at-home/</guid>
	<link>https://marcin.juszkiewicz.com.pl/2026/05/22/3d-printing-at-home/</link>
	<description>&lt;p&gt;After ten years of thinking about buying a 3D printer, I finally bought&amp;nbsp;one.&lt;/p&gt;
&lt;!--MORE--&gt;

&lt;h3&gt;First time: Anet&amp;nbsp;A6&lt;/h3&gt;
&lt;p&gt;Around 2016 I was playing with some 3D printer at my friend&amp;#8217;s company office.
But no one there knew how to run it and I felt weird sitting at their&amp;nbsp;place.&lt;/p&gt;
&lt;p&gt;So started checking the market and found Anet A6 printer. Reviews were mixed.
I got the impression that once you build the printer you need to print half of
it again and repeat until it gets acceptable quality. I decided to skip&amp;nbsp;it.&lt;/p&gt;
&lt;p&gt;Some months later, at some local event, I saw Anet A6/A8 printers. Ouch, they
were&amp;nbsp;terrible!&lt;/p&gt;
&lt;h3&gt;Second moment: Ender&amp;nbsp;3&lt;/h3&gt;
&lt;p&gt;A few years passed, Creality launched Ender 3 line of 3D printers. Reviews were
quite positive, printers looked more like a product than &lt;span class=&#34;caps&#34;&gt;DIY&lt;/span&gt;&amp;nbsp;hobby.&lt;/p&gt;
&lt;p&gt;And then I got a message from brother-in-law that he bought one. So I did not
have&amp;nbsp;to.&lt;/p&gt;
&lt;p&gt;Over the years, I printed countless items with his&amp;nbsp;help.&lt;/p&gt;
&lt;h3&gt;Third&amp;nbsp;case&lt;/h3&gt;
&lt;p&gt;A few months ago I started thinking about buying a 3D printer to have one at
home, eliminating the need to go ~30km each way to collect&amp;nbsp;prints.&lt;/p&gt;
&lt;p&gt;Checked the market options and started watching reviews. Some models started to
appear on a list of considered&amp;nbsp;ones:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Anycubic Kobra&amp;nbsp;S1&lt;/li&gt;
&lt;li&gt;Bambu Lab &lt;span class=&#34;caps&#34;&gt;P1S&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Creality&amp;nbsp;K2&lt;/li&gt;
&lt;li&gt;Elegoo Centauri&amp;nbsp;Carbon&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Crossing out&amp;nbsp;models&lt;/h3&gt;
&lt;p&gt;The more reviews I watched/read, the more I started to cross&amp;nbsp;out.&lt;/p&gt;
&lt;h4&gt;Bambu Lab &lt;span class=&#34;caps&#34;&gt;P1S&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;Bambu Lab &lt;span class=&#34;caps&#34;&gt;P1S&lt;/span&gt; went out due to lack of communication between OrcaSlicer running
on AArch64 desktop system &amp;#8212; their networking plugin is a closed binary
available only for x86-64&amp;nbsp;architecture.&lt;/p&gt;
&lt;p&gt;Also there was a lot of noise about license&amp;nbsp;violations.&lt;/p&gt;
&lt;p&gt;And sorry, but Bambu Lab users give off a vibe similar to the Apple users. You
know, &amp;#8220;there is only one god&amp;#8221;&amp;nbsp;kind.&lt;/p&gt;
&lt;h4&gt;Elegoo Centauri Carbon&amp;nbsp;1/2&lt;/h4&gt;
&lt;p&gt;Carbon 1 has enclosure but, at the time I looked, it lacked any multimaterial
solution. Instead they produced Centauri Carbon 2 (&lt;span class=&#34;caps&#34;&gt;CC2&lt;/span&gt;) printer. Which looks&amp;nbsp;weird.&lt;/p&gt;
&lt;p&gt;The Carbon 2 requires its own slicer as it looks like more and more things done
by other printers are being moved to slicing software. Anyone remember the &lt;span class=&#34;caps&#34;&gt;HP&lt;/span&gt;
710c&amp;nbsp;&amp;#8220;winprinter&amp;#8221;?&lt;/p&gt;
&lt;h4&gt;Creality&amp;nbsp;K2&lt;/h4&gt;
&lt;p&gt;This printer did not vanish from the list &amp;#8212; I decided to buy Anycubic Kobra&amp;nbsp;S1.&lt;/p&gt;
&lt;h3&gt;First&amp;nbsp;day&lt;/h3&gt;
&lt;p&gt;It took almost two weeks from order to delivery but yesterday I got Anycubic
Kobra S1 Combo at home. I unpacked it, set it up, and played a bit with printing
some basic&amp;nbsp;stuff.&lt;/p&gt;
&lt;h3&gt;Rinkhals&lt;/h3&gt;
&lt;p&gt;I would not be myself without modifying the software of a device I just bought.
And a 3D printer is no&amp;nbsp;different.&lt;/p&gt;
&lt;p&gt;So I took &lt;span class=&#34;caps&#34;&gt;USB&lt;/span&gt; thumbdrive and installed &lt;a href=&#34;https://rinkhals-community.github.io/Rinkhals/&#34;&gt;Rinkhals&lt;/a&gt;
to gain more control over my new&amp;nbsp;device.&lt;/p&gt;
&lt;p&gt;I do not care much about what exactly this project installs on my printer. Do
not have to know what Klipper, Mainsail or Moonraker are. What matters to me is
the ability to print directly from the OrcaSlicer running on my AArch64&amp;nbsp;desktop.&lt;/p&gt;
&lt;h3&gt;What to&amp;nbsp;print?&lt;/h3&gt;
&lt;p&gt;My list of things to print has about twenty entries. Ranging from some small
home improvements or replacing missing/broken pieces, to cases for my &lt;span class=&#34;caps&#34;&gt;DIY&lt;/span&gt;
keyboards and&amp;nbsp;devices.&lt;/p&gt;
&lt;p&gt;In the beginning, it gives instant gratification. I printed a piece in 3 minutes
and one thing at home works better. Another piece, and my Lenovo thin terminal
no longer moves because it is secured in three&amp;nbsp;places.&lt;/p&gt;
&lt;h3&gt;Trivia&lt;/h3&gt;
&lt;p&gt;As one of things I got was ability to log in via &lt;span class=&#34;caps&#34;&gt;SSH&lt;/span&gt; I had to check what
hardware is&amp;nbsp;used:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;root@kobra-ks1-02ab:/root# cat /proc/cpuinfo 
processor       : 0
model name      : ARMv7 Processor rev 5 (v7l)
BogoMIPS        : 48.00
Features        : half thumb fastmult vfp edsp neon vfpv3 tls vfpv4 idiva idivt vfpd32 lpae 
CPU implementer : 0x41
CPU architecture: 7
CPU variant     : 0x0
CPU part        : 0xc07
CPU revision    : 5
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Yes, this is single Cortex-A7 core. Rockchip &lt;span class=&#34;caps&#34;&gt;RV1106G&lt;/span&gt;&amp;nbsp;SoC.&lt;/p&gt;
&lt;p&gt;I was hoping to never see 32-bit Arm hardware&amp;nbsp;again&amp;#8230;&lt;/p&gt;</description>
	<pubDate>Fri, 22 May 2026 07:17:00 +0000</pubDate>
</item>

<item>
	<title>Steve McIntyre: Secure Boot and Microsoft CA Rollover - a heads-up for distributions</title>
	<guid isPermaLink="false">tag:https://blog.einval.com,2026-05-21:https://blog.einval.com/2026/05/22#secure_boot_ca_rollover</guid>
	<link>https://blog.einval.com/2026/05/22#secure_boot_ca_rollover</link>
	<description>&lt;h2&gt;Background&lt;/h2&gt;

&lt;p&gt;I&#39;m a member of the EFI team in Debian, and I&#39;ve done much of the
work for Debian to support UEFI Secure Boot (SB) in recent years. We
have included that support for a number of releases now, starting back
with Debian 10 (aka &lt;em&gt;Buster&lt;/em&gt;).&lt;/p&gt;

&lt;p&gt;I&#39;m also a long-time accredited member of
the &lt;a href=&#34;https://github.com/rhboot/shim-review/&#34;&gt;shim-review&lt;/a&gt;
team, the group that checks and approves shim binaries before
Microsoft will sign them.&lt;/p&gt;

&lt;p&gt;See the &lt;a href=&#34;https://wiki.debian.org/SecureBoot&#34;&gt;Debian
wiki&lt;/a&gt; for lots of background details about Secure Boot and how we
do things in Debian.&lt;/p&gt;

&lt;p&gt;Secure Boot depends on signatures, which are verified during boot
using a chain of X.509 certificates. The root certificate(s) in the
chain are embedded in computer firmware, then later software such as
shim can add more certificates to extend the trust. Easy, right?&lt;/p&gt;

&lt;h2&gt;The problem -  certificates expire...&lt;/h2&gt;

&lt;p&gt;Microsoft administer the most widespread Secure Boot root
certificates, and have been doing so since the very beginning of UEFI
Secure Boot as a concept. The Microsoft UEFI CA certificates are
included in just about every x86 and x86-64 computer shipped, and also
in quite a lot of arm64 machines too.&lt;/p&gt;

&lt;p&gt;(The fact that Microsoft is therefore a gatekeeper for Linux
running under Secure Boot on most machines is very unpopular in some
quarters, but this is just a fact of life in the world we live
in. &lt;strong&gt;None of the following will affect you if you&#39;re using
Secure Boot with your own keys only.&lt;/strong&gt;)&lt;/p&gt;

&lt;p&gt;The current certificates have been around since 2011:&lt;/p&gt;

&lt;p&gt;
&lt;strong&gt;1. Windows Production PCA 2011 (used for signing Windows components)&lt;/strong&gt;&lt;br /&gt;
&lt;tt&gt;&lt;pre&gt;
  Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011
  Validity
    Not Before: Oct 19 18:41:42 2011 GMT
    Not After : Oct 19 18:51:42 2026 GMT
&lt;/pre&gt;&lt;/tt&gt;
&lt;/p&gt;

&lt;p&gt;This expires in October this year, ~5 months from now.

&lt;p&gt;
&lt;strong&gt;2. Third Party Marketplace Root (used for signing option ROMs and other software)&lt;/strong&gt;&lt;br /&gt;
&lt;tt&gt;&lt;pre&gt;
  Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011
  Validity
    Not Before: Jun 27 21:22:45 2011 GMT
    Not After : Jun 27 21:32:45 2026 GMT
&lt;/pre&gt;&lt;/tt&gt;
&lt;/p&gt;

&lt;p&gt;For Linux folks, this second certificate is more interesting - it
is the root of the certificate chain that Microsoft use when
signing &lt;a href=&#34;https://github.com/rhboot/shim/&#34;&gt;shim&lt;/a&gt; for Linux
distributions&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;This CA expires 5 weeks from today.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;OMG!!! Will all my existing Secure Boot machines stop booting?&lt;/h2&gt;

&lt;p&gt;Almost definitely not, no.&lt;/p&gt;

&lt;p&gt;The specification for UEFI Secure Boot expects that valid dates on
certificates should not be enforced for signatures here. All that
matters here is the signatures themselves. Modulo buggy firmware,
existing signed binaries should continue just fine.&lt;/p&gt;

&lt;h2&gt;New CAs to be aware of&lt;/h2&gt;

&lt;p&gt;Microsoft have published &lt;strong&gt;three&lt;/strong&gt; new CAs:&lt;/p&gt;

&lt;p&gt;
&lt;strong&gt;1. A new CA used for signing device option ROMs&lt;/strong&gt;&lt;br /&gt;
&lt;tt&gt;&lt;pre&gt;
  Subject: C=US, O=Microsoft Corporation, CN=Microsoft Option ROM UEFI CA 2023
  Validity
    Not Before: Oct 26 19:02:20 2023 GMT
    Not After : Oct 26 19:12:20 2038 GMT
&lt;/pre&gt;&lt;/tt&gt;
&lt;p&gt;

&lt;p&gt;
&lt;strong&gt;2. A new CA used for signing Windows components&lt;/strong&gt;&lt;br /&gt;
&lt;tt&gt;&lt;pre&gt;
  Subject: C=US, O=Microsoft Corporation, CN=Windows UEFI CA 2023
  Validity
    Not Before: Jun 13 18:58:29 2023 GMT
    Not After : Jun 13 19:08:29 2035 GMT
&lt;/pre&gt;&lt;/tt&gt;
&lt;p&gt;

&lt;p&gt;
&lt;strong&gt;3. A new CA used for signing other software (e.g. shim)&lt;/strong&gt;&lt;br /&gt;
&lt;tt&gt;&lt;pre&gt;
  Subject: C=US, O=Microsoft Corporation, CN=Microsoft UEFI CA 2023
  Validity
    Not Before: Jun 13 19:21:47 2023 GMT
    Not After : Jun 13 19:31:47 2038 GMT
&lt;/pre&gt;&lt;/tt&gt;
&lt;p&gt;

&lt;p&gt;New machines and updated older machines will &lt;strong&gt;most
likely&lt;/strong&gt; have all of these new CAs installed. New machines are
already shipping that &lt;strong&gt;only&lt;/strong&gt; include the new CAs; they
will not trust older software and this has already started causing
problems for some users.&lt;/p&gt;

&lt;h2&gt;Isn&#39;t this is all a bit short notice?&lt;/h2&gt;

&lt;p&gt;Yes it is. :-(&lt;/p&gt;

&lt;p&gt;A common rule of thumb when deploying CA certificates is to start
the process of replacement (&#34;rollover&#34;) when a certificate reaches
half of its lifetime. Unfortunately, Microsoft have done this very
late. They generated new keys in 2023, but didn&#39;t start signing shim
and other third-party software with the UEFI CA until October
2025.&lt;/p&gt;

&lt;h2&gt;If I&#39;m a distro developer, what should I do?&lt;/h2&gt;

&lt;p&gt;If you already have an old shim signed by Microsoft for your
distribution from before October 2025, then it will only be signed
using the older CA that expires soon. On newer machines, your users
will already not be able to boot your distro with Secure Boot
enabled.&lt;/p&gt;

&lt;p&gt;If you want your users to be able to use Secure Boot in future, you
will need to get a new shim build submitted, reviewed and signed using
the new CA. However, that signed build will not work on older machines
unless they have had the new CAs installed. This is also likely to
cause problems for some users. You should encourage your users to
update their systems &lt;strong&gt;NOW&lt;/strong&gt; before things break for
them.&lt;/p&gt;

&lt;p&gt;There is an interim solution which will work, but only if you&#39;re
quick! Microsoft are currently returning shim binaries signed
using &lt;strong&gt;both&lt;/strong&gt; the old CA and the new CA. More
specifically, for every binary that is submitted they will return two:
one signed with each CA. If you use these directly, you&#39;ll need to
plan to publish:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;2 signed shim binaries
&lt;li&gt;2 installers
&lt;li&gt;2 sets of live/installer images
&lt;li&gt;etc.
&lt;/ul&gt;

&lt;p&gt;and explain to your users how they&#39;ll need to pick one. Good luck
with that!&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;However&lt;/strong&gt;, it is possible to extract signatures from
those signed shim binaries and attach them all onto one shim, giving
you the Holy Grail here - a single shim that will boot on the vast
majority of machines. Indeed, this is what I&#39;m planning on doing in
Debian. So-called &#34;dual-signed&#34; shims &lt;strong&gt;may&lt;/strong&gt; provoke
issues with buggy firmware, so be aware that you may have to deal with
this too. But take heart: early testing by various distro folks with a
dual-signed Fedora shim did not show any problems.&lt;/p&gt;

&lt;h2&gt;You have 5 weeks and counting...&lt;/h2&gt;

&lt;p&gt;Microsoft have promised to continue signing with the old CA as long
as possible, right up to the last day. They understand how awkward
things are going to be otherwise, and are trying to help here as much
as possible.&lt;/p&gt;

&lt;p&gt;In the shim-review team, we have been expecting to see a surge of
shim submissions before the old CA expires, to make the most of the
&#34;Holy Grail&#34; dual-signed shims described above. But we&#39;ve been really
surprised that this has &lt;strong&gt;not&lt;/strong&gt; been happening.&lt;/p&gt;

&lt;p&gt;So, this blog is a wake-up call for people doing Secure Boot with
shim. Even if you&#39;re not going to be ready to ship a new shim binary
to your users, you should really try to get a new build prepared and
signed &lt;strong&gt;NOW&lt;/strong&gt; so that you have it available to tide you
over through the coming CA transition. Don&#39;t leave it too late.&lt;/p&gt;

&lt;p&gt;If you&#39;re not sure what to do, ask me and the other shim-review
folks. We&#39;re happy to give advice. But don&#39;t delay.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;You have 5 weeks and counting.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;How to make a dual-signed shim binary&lt;/h2&gt;

&lt;p&gt;Microsoft only ship binaries with a single signature included. To
make things work, extract those signatures using &lt;code&gt;sbattach
--detach&lt;/code&gt; (from the sbsigntools source package, available in
most distributions. Then apply those signatures one at a time to your
shim binary, using &lt;code&gt;sbattach --attach&lt;/code&gt;. Simple,
really. There&#39;s one strong recommendation here: order the signatures
on your shim &lt;strong&gt;oldest first&lt;/strong&gt; - that way, old buggy
firmware implementations that potentially don&#39;t look for more than one
signature will find the old signature first.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;pesign&lt;/code&gt; can also handle moving signatures around, but I
chose sbsigntools when doing this work myself.&lt;/p&gt;

&lt;p&gt;If you&#39;re looking to see how others handle multiple signed shim
binaries, feel free to look at the Debian &lt;code&gt;shim-signed&lt;/code&gt;
package for examples. The repo
is &lt;a href=&#34;https://salsa.debian.org/efi-team/shim-signed.git&#34;&gt;https://salsa.debian.org/efi-team/shim-signed.git&lt;/a&gt;.

&lt;h2&gt;References&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Microsoft ship all their CA certificates and binaries you can use
to update computers
at &lt;a href=&#34;https://github.com/microsoft/secureboot_objects&#34;&gt;https://github.com/microsoft/secureboot_objects&lt;/a&gt;
&lt;li&gt;The Debian wiki has a lot more information
about &lt;a href=&#34;https://wiki.debian.org/UEFI&#34;&gt;UEFI&lt;/a&gt;
and &lt;a href=&#34;https://wiki.debian.org/SecureBoot&#34;&gt;Secure Boot&lt;/a&gt;
already, and I&#39;m going to be adding more user-focused documentation
about the CA rollover
at &lt;a href=&#34;https://wiki.debian.org/SecureBoot/CAChanges&#34;&gt;SecureBoot/CAChanges&lt;/a&gt;
shortly.
&lt;/ul&gt;

&lt;p&gt;I&#39;ll add more links here in the coming weeks.&lt;/p&gt;</description>
	<pubDate>Thu, 21 May 2026 23:43:00 +0000</pubDate>
</item>

<item>
	<title>Peter Czanik: Learning syslog-ng</title>
	<guid isPermaLink="false">tag:https://peter.czanik.hu/,2026-05-19:https://peter.czanik.hu/other/syslog-ng-learning/</guid>
	<link>https://peter.czanik.hu/other/syslog-ng-learning/</link>
	<description>How can you learn syslog-ng? There are many possibilities, depending on your time and budget. Possibilities range from tutorial series through reading the documentation to instructor-led training. Find out which one is for you!
Read more at https://www.syslog-ng.com/community/b/blog/posts/learning-syslog-ng
syslog-ng logo</description>
	<pubDate>Tue, 19 May 2026 11:15:16 +0000</pubDate>
</item>

<item>
	<title>Marcin Juszkiewicz: New Fedora package: fedora-active-user</title>
	<guid isPermaLink="false">tag:https://marcin.juszkiewicz.com.pl/,2026-05-04:https://marcin.juszkiewicz.com.pl/2026/05/04/new-fedora-package-fedora-active-user/</guid>
	<link>https://marcin.juszkiewicz.com.pl/2026/05/04/new-fedora-package-fedora-active-user/</link>
	<description>&lt;p&gt;During my work on the &lt;span class=&#34;caps&#34;&gt;RISC&lt;/span&gt;-V 64-bit architecture port of Fedora, I created
several pull requests to Fedora packages. And some were&amp;nbsp;stalled&amp;#8230;&lt;/p&gt;
&lt;!--MORE--&gt;

&lt;h3&gt;Non-responsive maintainer&amp;nbsp;process&lt;/h3&gt;
&lt;p&gt;Fedora project has a process called &lt;a href=&#34;https://docs.fedoraproject.org/en-US/fesco/Policy_for_nonresponsive_package_maintainers/&#34;&gt;&amp;#8216;non-responsive maintainer&amp;#8217;&lt;/a&gt;.
You check is maintainer on vacation, check latest activity and open a bug asking
for&amp;nbsp;action.&lt;/p&gt;
&lt;p&gt;The problem was that it linked to &lt;a href=&#34;https://github.com/pypingou/fedora-active-user/blob/master/fedora_active_user.py&#34;&gt;fedora_active_user.py script&lt;/a&gt;
which does not work since Fedora 41. During cycle of that release&amp;nbsp;the
&lt;code&gt;python-fedora&lt;/code&gt; package got retired and no one updated the&amp;nbsp;script.&lt;/p&gt;
&lt;h3&gt;Let me&amp;nbsp;look&lt;/h3&gt;
&lt;p&gt;As my actions brought some complains (and some discussions) I decided to take a
look at the script and make it work with current Fedora releases. Created pull
request, mailed original author&amp;nbsp;etc.&lt;/p&gt;
&lt;p&gt;There was no answer of any kind so I decided to take over maintaining the
script. Rewrote it to be Python 3 only, moved&amp;nbsp;from &lt;code&gt;urllib&lt;/code&gt; to &lt;code&gt;requests&lt;/code&gt;,
refactored some repeated code into functions&amp;nbsp;etc.&lt;/p&gt;
&lt;p&gt;Then started checking service by service how to get things working better.
Turned out that script had several assumptions which not always&amp;nbsp;apply.&lt;/p&gt;
&lt;h3&gt;&lt;span class=&#34;caps&#34;&gt;FAS&lt;/span&gt; has separate email for&amp;nbsp;Bugzilla&lt;/h3&gt;
&lt;p&gt;Fedora Accounts Service (&lt;span class=&#34;caps&#34;&gt;FAS&lt;/span&gt;) has a separate field for the Bugzilla email. I did
not had to look for testing accounts for this because that&amp;#8217;s my case &amp;#8212; I use
&amp;#8216;short&amp;#8217; Red Hat email in Bugzilla due to Single Sign-On (&lt;span class=&#34;caps&#34;&gt;SSO&lt;/span&gt;) service we use and
my &amp;#8216;long&amp;#8217; one for the rest.&amp;nbsp;So &lt;code&gt;fedora-active-user&lt;/code&gt; script grabs user
information from &lt;span class=&#34;caps&#34;&gt;FAS&lt;/span&gt; and checks for separate Bugzilla email and use it if&amp;nbsp;present.&lt;/p&gt;
&lt;h3&gt;&lt;span class=&#34;caps&#34;&gt;FAS&lt;/span&gt; query requires&amp;nbsp;Kerberos&lt;/h3&gt;
&lt;p&gt;To query &lt;span class=&#34;caps&#34;&gt;FAS&lt;/span&gt; you need Kerberos ticket.&amp;nbsp;Both &lt;code&gt;urllib&lt;/code&gt; and &lt;code&gt;requests&lt;/code&gt; packages
have a way to use it for authentication &amp;#8212; one extra package is needed to make
it&amp;nbsp;work.&lt;/p&gt;
&lt;p&gt;Lack of valid ticket is caught and info is provided to the&amp;nbsp;user.&lt;/p&gt;
&lt;h3&gt;Bugzilla is&amp;nbsp;tricky&lt;/h3&gt;
&lt;p&gt;Querying Bugzilla service is the trickiest part. You can request data but there
is no warranty that you get the latest one. Sure, there is the &amp;#8216;order&amp;#8217; field for
a query but it feels like a mere suggestion. It is nothing strange to get 2008
entries next to 2023&amp;nbsp;ones.&lt;/p&gt;
&lt;h3&gt;Wanna&amp;nbsp;help?&lt;/h3&gt;
&lt;p&gt;For now, I am hosting
&lt;a href=&#34;https://github.com/hrw/fedora-active-user/&#34;&gt;fedora-active-user&lt;/a&gt; on GitHub. Will
move it to Fedora Forge later this year. Feel free to open issues, send pull
requests if you have suggestions or&amp;nbsp;changes.&lt;/p&gt;
&lt;p&gt;Current version is not the best one. It is a bit better than it was two weeks&amp;nbsp;ago.&lt;/p&gt;
&lt;p&gt;At the moment package is present in Fedora rawhide. I am waiting for branches
for stable releases and updates will&amp;nbsp;follow.&lt;/p&gt;
&lt;h3&gt;Example&amp;nbsp;output&lt;/h3&gt;
&lt;pre&gt;&lt;code&gt;$ fedora-active-user --user hrw

Last action on koji:
   2026-05-04 built fedora-active-user-26.05.04-1.fc45
   2024-09-12 built python-system-calls-6.11.0-1.fc42
   2024-01-08 built python-system-calls-6.7.0-1.fc40
   2023-09-18 built python-system-calls-6.6.0-1.fc40
   2023-05-08 built python-system-calls-6.4.0-2.fc39
   2022-08-06 built python-system-calls-5.19.0-2.fc37
   2022-07-25 built python-system-calls-5.19.0-1.fc36
   2022-07-25 built python-system-calls-5.19.0-1.fc37
   2022-01-10 built python-system-calls-5.16.2-1.fc36
   2021-11-15 built python-system-calls-5.16.0-1.fc35

Last package updates on bodhi:
   2026-05-04 fedora-active-user-26.05.04-1.fc45
   2024-09-12 python-system-calls-6.11.0-1.fc42
   2024-01-08 python-system-calls-6.7.0-1.fc40
   2023-09-18 python-system-calls-6.6.0-1.fc40
   2023-05-08 python-system-calls-6.4.0-2.fc39
   2022-08-06 python-system-calls-5.19.0-2.fc37
   2022-07-25 python-system-calls-5.19.0-1.fc36
   2022-07-25 python-system-calls-5.19.0-1.fc37
   2022-01-10 python-system-calls-5.16.2-1.fc36
   2021-11-15 python-system-calls-5.16.0-1.fc35
   2021-11-15 python-system-calls-5.16.0-1.fc36
   2021-09-21 python-system-calls-5.15.5-1.fc36

Last actions performed according to fedmsg:
   2026-05-04 hrw commented on the pull-request rpms/prusa-slicer#67
   2026-05-04 hrw&#39;s Badges rank changed from 272 to 260
   2026-05-04 hrw was awarded the badge `Missed the Train`
   2026-05-04 hrw commented on update fedora-active-user-26.05.04-1.fc45 (karma: 0)
   2026-05-04 fedora-active-user-26.05.04-1.fc45 was tagged into f45 by bodhi
   2026-05-04 fedora-active-user-26.05.04-1.fc45 was untagged from f45-updates-candid
   2026-05-04 hrw&#39;s fedora-active-user-26.05.04-1.fc45 bodhi update has met stable te
   2026-05-04 fedora-active-user-26.05.04-1.fc45 was untagged from f45-updates-testin
   2026-05-04 fedora-active-user-26.05.04-1.fc45 was tagged into f45-updates-testing-
   2026-05-04 fedora-active-user-26.05.04-1.fc45 was untagged from f45-signing-pendin

Last emails on Fedora mailing lists:
   2026-04-29 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora
   2026-04-17 mjuszkiewicz@redhat.com as Marcin Juszkiewicz mailed devel@lists.fedora

Bugzilla activity (may not be the latest):
   No activity found on Bugzilla
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Looks like I still need to work on querying Bugzilla&amp;nbsp;;D&lt;/p&gt;</description>
	<pubDate>Mon, 04 May 2026 06:37:00 +0000</pubDate>
</item>

<item>
	<title>Marcin Juszkiewicz: Twenty-one years of blogging</title>
	<guid isPermaLink="false">tag:https://marcin.juszkiewicz.com.pl/,2026-04-01:https://marcin.juszkiewicz.com.pl/2026/04/01/twenty-one-years-of-blogging/</guid>
	<link>https://marcin.juszkiewicz.com.pl/2026/04/01/twenty-one-years-of-blogging/</link>
	<description>&lt;p&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2005/04/01/new-website/&#34;&gt;Twenty-one years ago&lt;/a&gt; I&amp;nbsp;wrote:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This is 3th (or 4th) version of my website and I hope that this time it will
stay for much longer and that I will use it more often to publish some
OpenEmbedded related articles and&amp;nbsp;informations.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And here we are, 21 years later. With the same&amp;nbsp;website.&lt;/p&gt;
&lt;!--MORE--&gt;

&lt;h3&gt;Time&amp;nbsp;flows&lt;/h3&gt;
&lt;p&gt;For sure I managed to keep it running &amp;#8220;for much longer&amp;#8221; than any earlier version
of my website. The previous one existed for about two years. Older ones were
more Lynx bookmarks split into several files rather than a&amp;nbsp;website.&lt;/p&gt;
&lt;h3&gt;Engines&lt;/h3&gt;
&lt;p&gt;When I started this website in 2005, WordPress was something new. Easy to use,
no &lt;span class=&#34;caps&#34;&gt;HTML&lt;/span&gt; knowledge needed&amp;nbsp;etc.&lt;/p&gt;
&lt;p&gt;In 2006, &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2006/09/12/haerwu-created/&#34;&gt;I created my own consulting company&lt;/a&gt; and
moved to WordPress &lt;span class=&#34;caps&#34;&gt;MU&lt;/span&gt; (MultiUser). I had two separate websites then &amp;#8212; one for
my company and my personal blog. Merged them into one a few years&amp;nbsp;later.&lt;/p&gt;
&lt;p&gt;In the meantime &lt;span class=&#34;caps&#34;&gt;WPMU&lt;/span&gt; got integrated into WordPress. And one day I recreated the
whole website on a fresh install of &lt;span class=&#34;caps&#34;&gt;WP&lt;/span&gt; to cut more than half of the database
size &amp;#8212; there was a lot of unused data left from several plugins I used through
all those&amp;nbsp;years.&lt;/p&gt;
&lt;p&gt;And then, in 2019, &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2019/04/24/good-bye-wordpress/&#34;&gt;I said &amp;#8220;good bye&amp;#8221; to WordPress&lt;/a&gt;
and moved to Pelican, static page generator. It was a good move. It cost me a
day or two of handling &lt;span class=&#34;caps&#34;&gt;WP&lt;/span&gt; export, cleaning posts, sorting out tags, images etc.
It was worth it &amp;#8212; I still use Pelican to generate this&amp;nbsp;website.&lt;/p&gt;
&lt;h3&gt;Grammar and&amp;nbsp;language&lt;/h3&gt;
&lt;p&gt;Reading old posts (especially pre-2010 ones) shows how awful my English grammar
and vocabulary were. In 2010,
&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2010/04/06/another-job-change/&#34;&gt;when I signed contract with Canonical to work at Linaro&lt;/a&gt;,
I went to language school to work on improving both grammar and
vocabulary. And it paid&amp;nbsp;off.&lt;/p&gt;
&lt;p&gt;I am not going to edit language of my old posts. I may alter tags, formatting or
fix/remove links in them. But not how they were written. I keep them as a
reminder how my English looked in the past. Not that it is fluent and nice
nowadays&amp;nbsp;:D&lt;/p&gt;
&lt;h3&gt;Markdown all the&amp;nbsp;time&lt;/h3&gt;
&lt;p&gt;I have never been a fan of using &lt;span class=&#34;caps&#34;&gt;HTML&lt;/span&gt; to edit blog posts. So when I discovered
Markdown I started using it.
With &lt;a href=&#34;https://michelf.ca/projects/php-markdown/extra/&#34;&gt;&lt;span class=&#34;caps&#34;&gt;PHP&lt;/span&gt; Markdown Extra&lt;/a&gt;&amp;nbsp;extensions.&lt;/p&gt;
&lt;p&gt;My current Pelican configuration for Markdown is&amp;nbsp;simple:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;MARKDOWN = {
    &#39;extension_configs&#39;: {
        &#39;markdown.extensions.extra&#39;: {},
        &#39;markdown.extensions.meta&#39;: {},
        &#39;markdown_del_ins&#39;: {},
        &#39;yafg&#39;: {},
    },
    &#39;output_format&#39;: &#39;html5&#39;,
}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It gives me abbreviations, attribute lists, definition lists, fenced code
blocks, footnotes, markdown in html, tables, meta-data, delete and insert tags
and the &amp;#8216;yafg&amp;#8217; extension wraps images into the &amp;lt;figure&amp;gt; tag with a caption.
In other words: all stuff I ever used in any&amp;nbsp;post.&lt;/p&gt;
&lt;h3&gt;Social&amp;nbsp;Media&lt;/h3&gt;
&lt;p&gt;Around 2009 - 2011 I started using social media and blog slowly started getting
fewer short entries as those went to twitter, facebook and google+&amp;nbsp;services.&lt;/p&gt;
&lt;p&gt;Still kept the rule of posting long texts on my website with links shared rather
than posting only on social&amp;nbsp;media.&lt;/p&gt;
&lt;h3&gt;Popular&amp;nbsp;posts&lt;/h3&gt;
&lt;p&gt;When it comes to posts it is hard to tell as I never kept statistics. But some
kind of a way to measure popularity of my posts is how often they landed on
external&amp;nbsp;websites.&lt;/p&gt;
&lt;p&gt;Many people read websites like &lt;a href=&#34;https://news.ycombinator.com/&#34;&gt;Hacker News&lt;/a&gt; or
&lt;a href=&#34;https://lobster.rs/&#34;&gt;Lobster&lt;/a&gt;, so I checked which of my posts landed there and
got more than 10&amp;nbsp;points:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Article&lt;/th&gt;
&lt;th&gt;Hacker News&lt;/th&gt;
&lt;th&gt;Lobster&lt;/th&gt;
&lt;th&gt;points&lt;/th&gt;
&lt;th&gt;comments&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2026/03/10/risc-v-is-sloooow/&#34;&gt;&lt;span class=&#34;caps&#34;&gt;RISC&lt;/span&gt;-V Is Sloooow&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=47328214&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://lobste.rs/s/ta3jjk/risc_v_is_sloooow&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;317&lt;/td&gt;
&lt;td&gt;379 + 111&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2016/07/25/aarch64-desktop-hardware/&#34;&gt;64-bit &lt;span class=&#34;caps&#34;&gt;ARM&lt;/span&gt; desktop hardware?&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=12158068&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;243&lt;/td&gt;
&lt;td&gt;169&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2025/06/27/bought-myself-an-ampere-altra-system/&#34;&gt;Bought myself an Ampere Altra system&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=44419446&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://lobste.rs/s/oiabdv/bought_myself_ampere_altra_system&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;206&lt;/td&gt;
&lt;td&gt;97 + 9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2025/07/22/arm-desktop-emulation/&#34;&gt;Arm desktop: emulation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=44823580&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://lobste.rs/s/mf5mup/arm_desktop_x86_emulation&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;98&lt;/td&gt;
&lt;td&gt;50 + 7&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2024/02/12/twenty-years-of-my-work-with-arm-architecture/&#34;&gt;Twenty years of my work with Arm architecture&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=39353784&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;94&lt;/td&gt;
&lt;td&gt;54&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2019/10/23/what-is-wrong-with-all-those-aarch64-desktops/&#34;&gt;What is wrong with all those AArch64 desktops?&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=22014393&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;90&lt;/td&gt;
&lt;td&gt;141&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2021/02/22/aarch64-boards-and-perception/&#34;&gt;AArch64 Boards and Perception&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=26222300&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://lobste.rs/s/eijsrh/aarch64_boards_perception&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;67&lt;/td&gt;
&lt;td&gt;31&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2019/10/15/how-to-survive-fosdem/&#34;&gt;How to Survive &lt;span class=&#34;caps&#34;&gt;FOSDEM&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=34337793&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&#34;https://lobste.rs/s/i28ei1/how_survive_fosdem&#34;&gt;thread&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;42&lt;/td&gt;
&lt;td&gt;15 + 5&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Some posts landed on places like &lt;a href=&#34;https://phoronix.com/&#34;&gt;Phoronix&lt;/a&gt; or
&lt;a href=&#34;https://osnews.com&#34;&gt;OSNews&lt;/a&gt; and got several&amp;nbsp;comments.&lt;/p&gt;
&lt;p&gt;I do not track where my posts got quoted &amp;#8212; most of the time friends send me
links. I read comments and sometimes I edit original blog post to make it easier
to understand. And I try to stay away from commenting (if someone is wrong on
the Internet, I do not need to stay awake to correct&amp;nbsp;them).&lt;/p&gt;
&lt;p&gt;And there was &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2013/04/22/death-to-raspberrypi-beaglebone-black-is-on-a-market/&#34;&gt;Death to Raspberry/Pi — Beaglebone Black is on a market&lt;/a&gt;
one&amp;#8230; It landed on Slashdot and generated such load that I was unable to log in
to my server. A day after I changed whole web server configuration and went from
Apache to Lighttpd (and some time later to&amp;nbsp;Nginx).&lt;/p&gt;
&lt;h3&gt;Popular&amp;nbsp;tags&lt;/h3&gt;
&lt;p&gt;It is easier to check which tags were the most popular during all those 21&amp;nbsp;years:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;tag name&lt;/th&gt;
&lt;th&gt;number of articles&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/linaro&#34;&gt;Linaro&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;177&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/ubuntu&#34;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;170&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/aarch64&#34;&gt;AArch64&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;154&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/openembedded&#34;&gt;OpenEmbedded&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;129&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/fedora&#34;&gt;Fedora&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;114&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/nokia&#34;&gt;Nokia&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;90&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/development&#34;&gt;development&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;84&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/debian&#34;&gt;Debian&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;82&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/openmoko&#34;&gt;Openmoko&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;70&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/conferences&#34;&gt;conferences&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/life&#34;&gt;life&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/phone&#34;&gt;phone&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;58&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/travels&#34;&gt;travels&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;52&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/linux&#34;&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;51&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/maemo&#34;&gt;Maemo&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;47&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/openzaurus&#34;&gt;OpenZaurus&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;45&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/arm&#34;&gt;Arm&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;44&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/website&#34;&gt;website&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;41&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/poky&#34;&gt;Poky&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;40&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/zaurus&#34;&gt;Zaurus&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;40&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/tag/red hat&#34;&gt;Red Hat&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;31&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The high position of the Ubuntu tag suggests a need for review as for some posts
it was used to get them placed on the 
&lt;a href=&#34;https://planet.ubuntu.com/&#34;&gt;Planet Ubuntu&lt;/a&gt;&amp;nbsp;aggregator.&lt;/p&gt;
&lt;p&gt;With the Nokia-related posts comes a story. Each post bumped &amp;#8216;karma&amp;#8217; on
Maemo.org website. And I mostly complained in them. But &amp;#8216;karma is a beach&amp;#8217;,
right? I got it high enough to get invitation to the Nokia N900 developer
program. It was a nice phone with software written to gather&amp;nbsp;complaints.&lt;/p&gt;
&lt;h3&gt;Requested&amp;nbsp;edits&lt;/h3&gt;
&lt;p&gt;During all those years there were some requests to edit some of my posts. I
rejected some and fulfilled&amp;nbsp;others.&lt;/p&gt;
&lt;h4&gt;No camera,&amp;nbsp;please&lt;/h4&gt;
&lt;p&gt;In 2009 &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2009/08/04/nhk15-arrived/&#34;&gt;I received &lt;span class=&#34;caps&#34;&gt;NHK15&lt;/span&gt; developer board&lt;/a&gt; from
&lt;span class=&#34;caps&#34;&gt;ST&lt;/span&gt;-Ericsson. As I had not signed any &lt;span class=&#34;caps&#34;&gt;NDA&lt;/span&gt;, I decided to show them the post before
publishing to make sure I do not mention too&amp;nbsp;much.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Can you remove the camera module from it? It will not be in a boxes we give
out during the&amp;nbsp;event.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I took one photo again, removed mentions of a camera module and&amp;nbsp;published.&lt;/p&gt;
&lt;p&gt;Move forward two months to the &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2009/10/19/st-ericsson-community-workshop-2009/&#34;&gt;&lt;span class=&#34;caps&#34;&gt;ST&lt;/span&gt;-Ericsson Community Workshop 2009&lt;/a&gt;
event. A day before it, decision was made to include that camera module.
One guy was going through each box to add&amp;nbsp;it&amp;#8230;&lt;/p&gt;
&lt;h4&gt;Pre-announced &lt;span class=&#34;caps&#34;&gt;SBC&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;Most of Linaro Connect events had a &amp;#8216;Demo day&amp;#8217; event where companies, projects
and developers presented some interesting things related to our work. I was
there walking, looking and asking&amp;nbsp;questions.&lt;/p&gt;
&lt;p&gt;And one year I asked a company (sorry, no names this time) will they have an
&lt;span class=&#34;caps&#34;&gt;SBC&lt;/span&gt; similar to the Beagleboard. And the answer was &amp;#8220;yes, it will be called
A_NAME&amp;#8221;. I asked was this information public and can I write about it on my
blog. Got confirmation, so an hour later I mentioned it in a blog&amp;nbsp;post.&lt;/p&gt;
&lt;p&gt;A few minutes later, when I was going to the hotel bar for an evening event, I
was asked by my manager where I got that info from. And then got a request to
remove it &amp;#8220;because they plan to announce it next week on some &lt;span class=&#34;caps&#34;&gt;BIG&lt;/span&gt; trade&amp;nbsp;show&amp;#8221;.&lt;/p&gt;
&lt;p&gt;I took my phone from my pocket, edited and we went for a&amp;nbsp;beer.&lt;/p&gt;
&lt;h4&gt;Lessons&amp;nbsp;learnt&lt;/h4&gt;
&lt;p&gt;Whenever non-public information is shared, wait until it is properly announced
publicly. Then, check how much information was released. My work is related to
many non-disclosure agreements (NDAs). So, if I know something, it needs to be
checked against public information before I can disclose any of it. You may also
want to confirm with an official source that the public disclosure was not due
to a leak or other incorrect source of&amp;nbsp;information.&lt;/p&gt;
&lt;h3&gt;Fewer technical&amp;nbsp;posts&lt;/h3&gt;
&lt;p&gt;If you look into &lt;a href=&#34;https://marcin.juszkiewicz.com.pl/archives/&#34;&gt;archives page&lt;/a&gt; you may notice that there are fewer
technical posts than there were in previous years. There is a simple explanation
for&amp;nbsp;it:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Well, you are some kind of influencer, get over it.
People do pay attention to what you&amp;nbsp;write.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Writing a technical post nowadays&amp;nbsp;means:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;asking a few people who know stuff to check whether I was right or&amp;nbsp;wrong&lt;/li&gt;
&lt;li&gt;asking a few people who do not know stuff to check what I&amp;nbsp;missed&lt;/li&gt;
&lt;li&gt;doing some technical review and&amp;nbsp;correction&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This changes writing a post for a personal blog into writing a technical&amp;nbsp;article.&lt;/p&gt;
&lt;p&gt;And then publishing still means a lot of online comments where maybe 25% of them
make any&amp;nbsp;sense.&lt;/p&gt;
&lt;h3&gt;Plans for the&amp;nbsp;future&lt;/h3&gt;
&lt;p&gt;I do not have any special plans for the future of this website. Will keep it
operational and add posts from time to time. I still have some ideas for the
content and have some drafts which wait for my&amp;nbsp;retirement.&lt;/p&gt;</description>
	<pubDate>Wed, 01 Apr 2026 08:13:00 +0000</pubDate>
</item>

<item>
	<title>Marcin Juszkiewicz: Upgraded to OpenWRT 25.12</title>
	<guid isPermaLink="false">tag:https://marcin.juszkiewicz.com.pl/,2026-03-24:https://marcin.juszkiewicz.com.pl/2026/03/24/upgraded-to-openwrt-2512/</guid>
	<link>https://marcin.juszkiewicz.com.pl/2026/03/24/upgraded-to-openwrt-2512/</link>
	<description>&lt;p&gt;I upgraded my router to OpenWRT 25.12. Nothing strange&amp;nbsp;right?&lt;/p&gt;
&lt;p&gt;And then I realized that I use OpenWRT for over twenty&amp;nbsp;years&amp;#8230;&lt;/p&gt;
&lt;!--MORE--&gt;

&lt;h3&gt;All started with Linksys &lt;span class=&#34;caps&#34;&gt;WRT54GS&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;Long, long time, when I worked from an office,
&lt;a href=&#34;https://marcin.juszkiewicz.com.pl/2005/06/07/i-got-wrt54gs/&#34;&gt;I got Linksys &lt;span class=&#34;caps&#34;&gt;WRT54GS&lt;/span&gt;&lt;/a&gt; as a donation.
&lt;span class=&#34;caps&#34;&gt;IIRC&lt;/span&gt; I got money to buy it as this was simpler than sending device from&amp;nbsp;abroad.&lt;/p&gt;
&lt;p&gt;Having Wi-Fi at home allowed me to test more stuff on Sharp Zaurus devices. Or
install/upgrade packages in an easy&amp;nbsp;way.&lt;/p&gt;
&lt;p&gt;It was running OpenWRT WhiteRussian for quite a while as device upgrades were
quite problematic at that&amp;nbsp;time.&lt;/p&gt;
&lt;h3&gt;Other&amp;nbsp;devices&lt;/h3&gt;
&lt;p&gt;During next years I used a mix of devices running OpenWRT. Routers, access
points or devices which served both those functions at the same&amp;nbsp;time.&lt;/p&gt;
&lt;p&gt;Netgear &lt;span class=&#34;caps&#34;&gt;WNDR4300&lt;/span&gt; N750 brought 5GHz Wi-Fi network to my flat. Running MiniPC +
Belkin &lt;span class=&#34;caps&#34;&gt;BT3200&lt;/span&gt; (aka Linksys E8450) combo brought network separation as I started
using VLANs. Etc.&amp;nbsp;etc.&lt;/p&gt;
&lt;h3&gt;Why&amp;nbsp;OpenWRT?&lt;/h3&gt;
&lt;p&gt;Having a unified way of doing network setup was a key for me when I was choosing
next router/&lt;span class=&#34;caps&#34;&gt;AP&lt;/span&gt; device. Or ability to install additional packages which brings
more functions. Especially since 512 &lt;span class=&#34;caps&#34;&gt;MB&lt;/span&gt; &lt;span class=&#34;caps&#34;&gt;RAM&lt;/span&gt; became popular in a&amp;nbsp;router.&lt;/p&gt;
&lt;p&gt;Why it matters to me? I am not a network admin. Never planned to be. So being
able to switch to a new device and restore configuration from a previous one
saves my&amp;nbsp;time. &lt;/p&gt;
&lt;p&gt;There are no limitations on how I name my Wi-Fi networks (national characters,
emojis, spaces), how many of them will be, what kind of firewall zones I want
and which devices/networks are in which zone.&amp;nbsp;Etc&amp;#8230;&lt;/p&gt;</description>
	<pubDate>Tue, 24 Mar 2026 07:18:00 +0000</pubDate>
</item>

<item>
	<title>Gema Gomez: Overview of 2025</title>
	<guid isPermaLink="false">tag:https://knitpick.me/,2026-01-02:https://knitpick.me/2026/01/02/2025-overview/</guid>
	<link>https://knitpick.me/2026/01/02/2025-overview/</link>
	<description></description>
	<pubDate>Fri, 02 Jan 2026 00:00:00 +0000</pubDate>
</item>

</channel>
</rss>