Monthly Shaarli
March, 2021

Web Development History is an excellent resource on different aspects of web development history.

The latest stable release of Grafana comes with a new and improved pie chart panel, alerting support for Loki, a Grafana Tempoo backend data source, and many other improvements.

This short post explains how to use different git usernames and email addresses per directory.
The author discusses which supply chain attacks aren't covered by sigstore.
Nokia has transferred the copyright of Plan 9 to the Plan 9 Foundation.

This in-depth article shows how LinkedIn Engineering improved the capacity projections on their site.

Plausible is a privacy-friendly alternative to Google Analytics, compliant with GDPR.

The git maintenance
command is probably the most notable feature of this newest release of Git.

This article summarizes Seagate's long-term HDD technology roadmap.

Multi-part article series on VM detection tricks focussed on 64-bit Windows guests on multiple virtualization platforms.

In this talk, Jonathan Looney from Netflix describes the Open Connect Appliance and the optimizations that make it possible to serve over 180 GB/s of TLS-encrypted connections with less than 50% CPU on a single 32-core 2.5-GHz CPU in 2 RU.

This post introduces sigstore, a Linux Foundation project that aims to improve open-source software supply chain integrity and verification.

This zstd
release brings significant performance improvements for the --long
mode, a setting designed to improve compression ratio for files with long matches at a large distance.

This article explains the issues with Google's technology called Federated Learning of Cohorts (FLoC).
In this document, Apple explains the different security aspects of its platform.

»The goal of OSV is to provide precise data on where a vulnerability was introduced and where it got fixed, thereby helping consumers of open source software accurately identify if they are impacted and then make security fixes as quickly as possible.«

This article is dedicated to Perseverance rover's Mars Helicopter Ingenuity. It is running NASA's open-sourced framework F Prime on top of a Linux-based OS.
»Cognitively-Oriented Approach to Improving Program Readability«
Links is a text-based open-source web browser.
The Debian project released a fresh point release, including the latest bug fixes and security updates.
A new stable version of the popular desktop environment was released, the first one following the project's new versioning scheme.

The author gives some good reasons why the omnipresent DBMS should not be underestimated.
The performance impact of a new CPU scheduler for AMD EPYC in VMware vSphere 7.0 U2 is described in this document by VMware.

This is an interesting write-up of a PostgreSQL performance issue.
»Starting with Firefox 87, we set the default Referrer Policy to 'strict-origin-when-cross-origin' which will trim user sensitive information accessible in the URL.«
Focalboard is an open-source, self-hosted project management software.
This post takes a deep dive into several bugs inside the iSCSI subsystem of the Linux kernel.

»FreeBSD 13.0 comes out at the end of March. Take a look at what's new in the upcoming release.«

Based on the TOPDB Top Database index, this post gives an overview of the most widely used DBMS since 2006.
redbean
is a single-file distributable web server.

In this post, the author gives an introduction to Kubernetes scheduling and resource management.

In this tutorial, the author shows how to get GlusterFS 8 running on FreeBSD 13.

The author shares his interesting findings in buying and utilizing 14 domains that are 1-bitflip away from windows.com.
SUSE is planning a pre-summer initial public offering.
»Around 3.6 million websites across 464,000 distinct domains were taken offline after the major fire at an OVHcloud datacenter site in Strasbourg overnight.«
»For the third year in a row, "infrastructure modernization" is the top use for enterprise open source software. Furthermore, 64% now cite it as a top use, up from 53% two years ago. This continued popularity isn't really surprising. Linux and other open infrastructure like web servers have long been used to replace proprietary alternatives.«

Reclaim Your Face is a European Citizens' Initiative (ECI) petition for a ban on biometric mass surveillance practices.
The main difference between veb
and the existing bridge
interface is how they use interfaces as ports.

The newest version of Zenital Server is based on Ubuntu Server 20.04 LTS and comes with Samba 4.11.

This post explains Facebook's engineering team's measures to detect a more significant percentage of regressions earlier in the engineering life cycle.

The article reveals a technique serving user-specific favicons to circumvent existing counter-tracking-measures.
Version 2 of Checkmk comes with an overhauled user interface.

Short post-mortem on a Grafana Cloud Prometrheus outage.
This post explains the issue of DoS against regular expressions. The authors also introduce their tool regexploit
, which helps analyze regular expressions against such vulnerabilities.
cosign
is part of the sigstore project to make the open-source software supply chain more secure. In this post, the author describes how to use the cosign
tool to sign container images.
ssss
is a practical implementation of a secret sharing scheme, a method for distributing a secret amongst a group of participants.
Buildroot is a simple, efficient, and easy-to-use tool to generate embedded Linux systems through cross-compilation.
This paper describes the prototype for the onboard scheduler of the Mars 2020 rover.
Paper on the efforts of porting OpenBSD to the RISC-V ISA.

In this article, the authors describe algorithms for durable transactions and infer four rules from them.
In this article, the authors debunk some common myths about developer productivity and introduce a framework that is better suited to understand the matter.

This article explains why on-prem disk-based storage is the most cost-effective and flexible storage solution for Dropbox need for the time being. Currently, Dropbox is rolling out 20TB SMRs at scale.
Murat Demirbas compiled a collection of foundational papers in the distributed systems area.
Apache AGE is a PostgreSQL extension that provides graph database functionality.
Major changes include toolchain updates to glibc-2.33
, and binutils-2.36.1
.
This OpenSSH release enables the UpdateHostKeys option by default to assist the client by automatically migrating to better algorithms if the weak SHA-1 hash algorithm in conjunction with the RSA public key algorithm is still used.

Jonah Edwards gives insight into the Internet Archive Infrastructure.

In this post, the author explains the asymmetry of ICMP ping requests and ways of measuring the difference.

Amongst other improvements, release 21 of Nextcloud hub brings a high-performance back-end for Nextcloud Files.

»bit
is an experimental modernized git CLI built on top of git that provides happy defaults and other niceties.«

Because Ansible is switching to semantic versioning, the version number of this release is 3.0.0 instead of 2.11.0.

The author shares his thoughts about running Postgres in a container.
In this post, the author explains how he discovered a severe RCE in VMware vCenter and how an attacker can exploit it.