# POSIX

POSIX is a standard operating system interface and environment, including a shell and common utility programs, designed to support source-code portability for applications.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Libreboot Build System Audit 6

DevFeed: [Libreboot Build System Audit 6](<https://devfeed.tech/articles/libreboot-build-system-audit-6-32666.md>)

Original publisher: [Read original article](<https://libreboot.org/news/audit6.html>)

Author: Leah Rowe

Published: 2026-09-17T04:32:50.666044Z

Content type: article

Language: en

Sources: [News about Libreboot releases and development](<https://devfeed.tech/sources/news-about-libreboot-releases-and-development.md>)

Topics: [audit](<https://devfeed.tech/topics/audit.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [Code](<https://devfeed.tech/topics/code.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [bios](<https://devfeed.tech/tags/bios.md>), [build-system](<https://devfeed.tech/tags/build-system.md>), [canoeboot](<https://devfeed.tech/tags/canoeboot.md>), [code](<https://devfeed.tech/tags/code.md>), [coreboot](<https://devfeed.tech/tags/coreboot.md>), [free-software](<https://devfeed.tech/tags/free-software.md>), [libre](<https://devfeed.tech/tags/libre.md>), [libreboot](<https://devfeed.tech/tags/libreboot.md>), [opensource](<https://devfeed.tech/tags/opensource.md>), [release](<https://devfeed.tech/tags/release.md>), [return](<https://devfeed.tech/tags/return.md>), [shell](<https://devfeed.tech/tags/shell.md>), [uefi](<https://devfeed.tech/tags/uefi.md>)

### AI overview

This article reports on the sixth audit of Libreboot's lbmk build system. It describes code cleanup, bug fixes, feature changes, and a reduction from 1,482 to 1,109 lines of shell script, a 25% decrease, between the Libreboot 20240612 release and the 19 July 2024 revision.

### Source excerpt

Article: Libreboot Build System Audit 6 Web link: https://libreboot.org/news/audit6.html

## Libreboot Build System Audit 5

DevFeed: [Libreboot Build System Audit 5](<https://devfeed.tech/articles/libreboot-build-system-audit-5-32665.md>)

Original publisher: [Read original article](<https://libreboot.org/news/audit5.html>)

Author: Leah Rowe

Published: 2026-09-17T04:32:50.666044Z

Content type: article

Language: en

Sources: [News about Libreboot releases and development](<https://devfeed.tech/sources/news-about-libreboot-releases-and-development.md>)

Topics: [audit](<https://devfeed.tech/topics/audit.md>), [opensource](<https://devfeed.tech/topics/opensource.md>), [boot](<https://devfeed.tech/topics/boot.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [ide](<https://devfeed.tech/topics/ide.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [bios](<https://devfeed.tech/tags/bios.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [canoeboot](<https://devfeed.tech/tags/canoeboot.md>), [clean-code](<https://devfeed.tech/tags/clean-code.md>), [coreboot](<https://devfeed.tech/tags/coreboot.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [free-software](<https://devfeed.tech/tags/free-software.md>), [libre](<https://devfeed.tech/tags/libre.md>), [libreboot](<https://devfeed.tech/tags/libreboot.md>), [linux](<https://devfeed.tech/tags/linux.md>), [opensource](<https://devfeed.tech/tags/opensource.md>), [operating-systems](<https://devfeed.tech/tags/operating-systems.md>), [posix](<https://devfeed.tech/tags/posix.md>), [uefi](<https://devfeed.tech/tags/uefi.md>)

### AI overview

This article describes the fifth audit of Libreboot's lbmk build system, covering changes made since the Libreboot 20240504 release. It reports a reduction in shell-script size, bug fixes, feature changes, and improvements aimed at cleaner and more efficient code.

### Source excerpt

Article: Libreboot Build System Audit 5 Web link: https://libreboot.org/news/audit5.html

## Sound Open Firmware 2.15 Released With AMD ACP 7.x Support, Intel UAOL

DevFeed: [Sound Open Firmware 2.15 Released With AMD ACP 7.x Support, Intel UAOL](<https://devfeed.tech/articles/sound-open-firmware-2-15-released-with-amd-acp-7-x-support-intel-uaol-26768.md>)

Original publisher: [Read original article](<https://www.phoronix.com/news/Sound-Open-Firmware-2.15>)

Author: Michael Larabel

Published: 2026-09-15T13:04:40Z

Content type: release

Language: en

Sources: [Phoronix](<https://devfeed.tech/sources/phoronix.md>)

Topics: [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [intel](<https://devfeed.tech/topics/intel.md>), [Security](<https://devfeed.tech/topics/security.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [Xtensa](<https://devfeed.tech/topics/xtensa.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [desktop-linux](<https://devfeed.tech/tags/desktop-linux.md>), [driver](<https://devfeed.tech/tags/driver.md>), [dsp](<https://devfeed.tech/tags/dsp.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [intel](<https://devfeed.tech/tags/intel.md>), [linux-benchmarking](<https://devfeed.tech/tags/linux-benchmarking.md>), [linux-hardware-benchmarks](<https://devfeed.tech/tags/linux-hardware-benchmarks.md>), [linux-hardware-reviews](<https://devfeed.tech/tags/linux-hardware-reviews.md>), [linux-how-to](<https://devfeed.tech/tags/linux-how-to.md>), [linux-performance](<https://devfeed.tech/tags/linux-performance.md>), [linux-server-benchmarks](<https://devfeed.tech/tags/linux-server-benchmarks.md>), [open](<https://devfeed.tech/tags/open.md>), [open-source-graphics](<https://devfeed.tech/tags/open-source-graphics.md>), [phoronix](<https://devfeed.tech/tags/phoronix.md>), [phoronix-test-suite](<https://devfeed.tech/tags/phoronix-test-suite.md>), [posix](<https://devfeed.tech/tags/posix.md>), [processor](<https://devfeed.tech/tags/processor.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [ubuntu-benchmarks](<https://devfeed.tech/tags/ubuntu-benchmarks.md>), [ubuntu-hardware](<https://devfeed.tech/tags/ubuntu-hardware.md>), [usb](<https://devfeed.tech/tags/usb.md>), [xtensa](<https://devfeed.tech/tags/xtensa.md>)

### AI overview

Sound Open Firmware 2.15 adds user-space, memory-protected module execution, AMD ACP 7.x and NXP i.MX8MP support, Intel UAOL USB audio offload, testing targets, security hardening, and new audio processing modules.

### Source excerpt

Sound Open Firmware as the open-source, vendor-independent audio DSP firmware stack and driver framework is out today with a new feature update...

## AAOS SDV - Secure by Design

DevFeed: [AAOS SDV - Secure by Design](<https://devfeed.tech/articles/aaos-sdv-secure-by-design-22687.md>)

Original publisher: [Read original article](<http://android-developers.googleblog.com/2026/08/aaos-sdv-secure-by-design.html>)

Author: Android Developers (noreply@blogger.com)

Published: 2026-08-24T16:00:31Z

Content type: article

Language: en

Sources: [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog-3.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Security](<https://devfeed.tech/topics/security.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [SELinux](<https://devfeed.tech/topics/selinux.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [article](<https://devfeed.tech/tags/article.md>), [google](<https://devfeed.tech/tags/google.md>), [posix](<https://devfeed.tech/tags/posix.md>), [process](<https://devfeed.tech/tags/process.md>), [security](<https://devfeed.tech/tags/security.md>), [selinux](<https://devfeed.tech/tags/selinux.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>)

### AI overview

This article explains the security design of Android Automotive Operating System for Software Defined Vehicle (AAOS SDV). It describes virtualization for domain isolation, UID-based application and service sandboxing, POSIX capabilities, SELinux deny-by-default enforcement, and Android's vulnerability management and disclosure processes.

### Source excerpt

Posted by Markus Vill, Software Engineer, Sean Keys, Security Engineer, and Istvan Nador, Software Engineer, Android Auto At Google, we believe our products should be secure by design, which is why we built the Android Automotive Operating System for Software Defined Vehicle (AAOS SDV) on existing, market-proven platforms, leveraging virtualization technologies like Cuttlefish. While our release announcements focused on the features, this blog post outlines some of the security concepts. Foundation: Domain IsolationVirtualization to isolate co-hosted instances The current trend of consolidating Electronic Control Units (ECUs) into a single chip reduces isolation by running multiple domains side-by-side. While AAOS SDV instances provide internal isolation mechanisms, it is often preferable to run logical domains independently. For instance, a cluster and an infotainment system have distinct requirements. We use virtual machines to run multiple instances in parallel, ensuring that sharing remains explicit and isolation is the default behavior. Inherited Android Security AAOS SDV evolved from Microdroid, a minimalistic Android version optimized for privacy virtual machines (pVM). This lineage provides Android platform engineers with established security features they already know. Process Isolation & Deny by Default AAOS SDV follows Android's User ID (UID)-based isolation model to set up a sandbox for each application. Each service runs in a dedicated process with a unique UID to manage access rights, data directories, and other restrictions. We employ Portable Operating System Interface (POSIX) capabilities to strictly limit operations and pair this with Security-Enhanced Linux (SELinux) to enforce a "deny-by-default" posture. This approach restricts each service to the absolute minimum required, meaning missing configurations block access rather than creating an over-permissive system. We apply this same strategy to our communication permission system, as explained l

## Vim: por qué merece la pena frente a nano

DevFeed: [Vim: por qué merece la pena frente a nano](<https://devfeed.tech/articles/vim-por-que-merece-la-pena-frente-a-nano-34091.md>)

Original publisher: [Read original article](<https://tengoping.com/blog/vim-por-que-aprenderlo-en-vez-de-nano/>)

Author: Antonio Pérez

Published: 2026-08-01T13:00:00Z

Content type: tutorial

Language: es

Sources: [tengoping.com](<https://devfeed.tech/sources/tengoping-com.md>)

Topics: [Vim](<https://devfeed.tech/topics/vim.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Unix](<https://devfeed.tech/topics/unix.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [distro](<https://devfeed.tech/tags/distro.md>), [editor](<https://devfeed.tech/tags/editor.md>), [posix](<https://devfeed.tech/tags/posix.md>), [unix](<https://devfeed.tech/tags/unix.md>), [vim](<https://devfeed.tech/tags/vim.md>)

### AI overview

A practical Spanish tutorial explaining why Vim is worth learning instead of nano. It covers how to exit, save, undo, and redo, then argues that Vim is widely available on Unix systems because vi is required by POSIX. It also discusses BusyBox, Alpine, and Vim's modes.

### Source excerpt

Vim parece complicado pero no lo es: aprende a salir, moverte y editar con lo mínimo imprescindible, sin miedo y sin memorizar todo de golpe.

## GNU Hurd Q2 2026 development updates

DevFeed: [GNU Hurd Q2 2026 development updates](<https://devfeed.tech/articles/2026-q2-32750.md>)

Original publisher: [Read original article](<http://www.gnu.org/software/hurd/news/2026-q2.html>)

Published: 2026-07-03T20:32:51Z

Content type: news

Language: en

Sources: [GNU Hurd](<https://devfeed.tech/sources/gnu-hurd.md>)

Topics: [Code](<https://devfeed.tech/topics/code.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [SVG](<https://devfeed.tech/topics/svg.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [virtio](<https://devfeed.tech/topics/virtio.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Wiki](<https://devfeed.tech/topics/wiki.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [code](<https://devfeed.tech/tags/code.md>), [crash](<https://devfeed.tech/tags/crash.md>), [cross-compilation](<https://devfeed.tech/tags/cross-compilation.md>), [posix](<https://devfeed.tech/tags/posix.md>), [servers](<https://devfeed.tech/tags/servers.md>), [svg](<https://devfeed.tech/tags/svg.md>), [virtio](<https://devfeed.tech/tags/virtio.md>), [wiki](<https://devfeed.tech/tags/wiki.md>)

### AI overview

A quarterly GNU Hurd development update covering a public 9pfs repository with basic file browsing and reading support, additional write support, POSIX-related validation, bug fixes, cross-compilation work, Rust translator development, and planned dynamic device population.

### Source excerpt

Hello and welcome to another Qoth! Here's what's been happening in Q2 of 2026! Joshua Branson added a pretty cool svg logo for our ethernet multiplexor. He built that image with Inkscape whilst using a Hurd laptop (Thinkpad 420) running on real iron! The Hurd wiki could certainly use more artwork. Perhaps you have a favorite Hurd translator that you believes needs some artwork! Sergey Bugaev announced his WIP 9pfs (source code), and it has a wiki page! He writes: Some years ago, I experimented with implementing a 9P translator for the Hurd. Hopefully there is no need to tell this list what 9P is :) Besides just browsing files on the few existing servers out there, a potential use case is virtio-9p, to enable shared directory trees between VMs and the host. But that would need someone to implement virtio support in the Hurd. I wanted to complete 9pfs before publishing, but that ultimately didn't happen, so now it's time to turn it over to the community. I now went and made the repository public on GitHub: https://github.com/bugaevc/9pfs What's implemented is basic browsing (readdir, stat), path resolution (dir_lookup), and reading files (io_read). And below that, the whole tracking for nodes, peropens, protids, fids, tags, and 9p RPCs. Improvements are welcome, send patches to this list with [PATCH 9pfs] in the subject. A good starting point would be to continue porting things that I had implemented in the old netfs-based version (see netfs.c) but didn't yet port to the new one. He then got a little more motivated, and he added some write support! Etienne Brateau added validation to msync, so that the Hurd better follows POSIX. Diego Nieto Cid worked on allowing privileged users to set their task priority (nice value). His patches landed in glibc and GNU Mach. He also fixed a tiny bug in our test suite. He fixed an adjtime bug, which is helpful to the OpenNTPD port, and he fixed two more bugs. Paulo Duarte sent a RFC patch series trying to commit Sergey's previous AA

## Coding Challenge #124 - Du

DevFeed: [Coding Challenge #124 - Du](<https://devfeed.tech/articles/coding-challenge-124-du-29200.md>)

Original publisher: [Read original article](<https://codingchallenges.substack.com/p/coding-challenge-124-du>)

Author: John Crickett

Published: 2026-06-13T08:01:14Z

Content type: tutorial

Language: en

Sources: [Coding Challenges](<https://devfeed.tech/sources/coding-challenges.md>)

Topics: [Code Challenge](<https://devfeed.tech/topics/code-challenge.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [Utility Software](<https://devfeed.tech/topics/utility.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [coding](<https://devfeed.tech/tags/coding.md>), [exercise](<https://devfeed.tech/tags/exercise.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [posix](<https://devfeed.tech/tags/posix.md>), [programming](<https://devfeed.tech/tags/programming.md>), [programming-language](<https://devfeed.tech/tags/programming-language.md>), [run](<https://devfeed.tech/tags/run.md>), [unix](<https://devfeed.tech/tags/unix.md>), [utilities](<https://devfeed.tech/tags/utilities.md>)

### AI overview

A coding challenge asks readers to build their own POSIX-compatible du utility. It covers recursively traversing directories, calculating disk usage, handling hard links and symbolic links, and presenting results in multiple formats.

### Source excerpt

This challenge is to build your own du.

## ESP-IDF v6.0: Default libc Switches from Newlib to PicolibC

DevFeed: [ESP-IDF v6.0: Default libc Switches from Newlib to PicolibC](<https://devfeed.tech/articles/esp-idf-v6-0-default-libc-switches-from-newlib-to-picolibc-13762.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/04/esp-idf-6-default-libc-picolibc/>)

Author: John Lee

Published: 2026-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [C](<https://devfeed.tech/topics/c.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Streams](<https://devfeed.tech/topics/streams.md>), [Library](<https://devfeed.tech/topics/library.md>), [POSIX](<https://devfeed.tech/topics/posix.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [architectures](<https://devfeed.tech/tags/architectures.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c](<https://devfeed.tech/tags/c.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [libc](<https://devfeed.tech/tags/libc.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [memory](<https://devfeed.tech/tags/memory.md>), [migration](<https://devfeed.tech/tags/migration.md>), [newlib](<https://devfeed.tech/tags/newlib.md>), [performance](<https://devfeed.tech/tags/performance.md>), [picolibc](<https://devfeed.tech/tags/picolibc.md>), [posix](<https://devfeed.tech/tags/posix.md>), [streams](<https://devfeed.tech/tags/streams.md>), [systems](<https://devfeed.tech/tags/systems.md>), [toolchains](<https://devfeed.tech/tags/toolchains.md>)

### AI overview

ESP-IDF v6.0 changes its default C library from Newlib to PicolibC. The article compares the libraries' memory usage, standard I/O behavior, compatibility, and migration considerations, including measurements on ESP32-C3.

### Source excerpt

ESP-IDF v6.0 switches the default C library from Newlib to PicolibC. This article compares both libraries in terms of memory usage, stdio behavior, compatibility, and migration tradeoffs, and explains when keeping Newlib still makes sense.

## Introducing the SPIFFS component

DevFeed: [Introducing the SPIFFS component](<https://devfeed.tech/articles/introducing-the-spiffs-component-13757.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/03/introducing-spiffs-component/>)

Author: John Lee

Published: 2026-03-23T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [Streams](<https://devfeed.tech/topics/streams.md>), [C](<https://devfeed.tech/topics/c.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [ESP32](<https://devfeed.tech/topics/esp32.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [beginner](<https://devfeed.tech/tags/beginner.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c](<https://devfeed.tech/tags/c.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [guide](<https://devfeed.tech/tags/guide.md>), [posix](<https://devfeed.tech/tags/posix.md>), [spiffs](<https://devfeed.tech/tags/spiffs.md>), [storage](<https://devfeed.tech/tags/storage.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

This practical guide introduces the SPIFFS component bundled with ESP-IDF for storing files on SPI NOR flash. It explains how SPIFFS works with the VFS layer and standard C and POSIX file APIs, describes features such as wear levelling, consistency checks, and format-on-mount, and outlines a basic flow for mounting, writing, renaming, and reading files. It also points to SPIFFSgen and an official working example.

### Source excerpt

Learn what the ESP-IDF SPIFFS component is, how it works with the VFS layer and standard C file APIs, and how to use the SPIFFSgen tool to embed files. This article is a practical guide with references to the official example.

## Advanced techniques for porting libraries to ESP-IDF components

DevFeed: [Advanced techniques for porting libraries to ESP-IDF components](<https://devfeed.tech/articles/advanced-techniques-for-porting-libraries-to-esp-idf-components-13733.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2025/11/advanced-porting-libraries-as-components/>)

Author: John Lee

Published: 2025-11-24T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Library](<https://devfeed.tech/topics/library.md>), [AWS IoT Core](<https://devfeed.tech/topics/aws-iot-core.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [WebSocket](<https://devfeed.tech/topics/websocket.md>), [aio](<https://devfeed.tech/topics/aio.md>), [CMake](<https://devfeed.tech/topics/cmake.md>), [make](<https://devfeed.tech/topics/make.md>), [POSIX](<https://devfeed.tech/topics/posix.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [cmake](<https://devfeed.tech/tags/cmake.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [component](<https://devfeed.tech/tags/component.md>), [components](<https://devfeed.tech/tags/components.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [feature-flags](<https://devfeed.tech/tags/feature-flags.md>), [library](<https://devfeed.tech/tags/library.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mqtt](<https://devfeed.tech/tags/mqtt.md>), [porting](<https://devfeed.tech/tags/porting.md>), [posix](<https://devfeed.tech/tags/posix.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [systems](<https://devfeed.tech/tags/systems.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

This follow-up article presents advanced techniques for porting larger libraries, particularly those designed for Linux or POSIX systems, into reusable ESP-IDF components. It covers assessing reusable code, adapting build systems and port layers, configuration, header injection, linker wrapping, and compiler-warning management, with examples including asio, mosquitto, libssh, and libwebsockets.

### Source excerpt

This article follows up on the article 'Porting a library to an ESP-IDF component' and shows some advanced tips and tricks when porting larger libraries into ESP-IDF components.

## A Higgs-bugson in the Linux Kernel

DevFeed: [A Higgs-bugson in the Linux Kernel](<https://devfeed.tech/articles/a-higgs-bugson-in-the-linux-kernel-20143.md>)

Original publisher: [Read original article](<https://blog.janestreet.com/a-higgs-bugson-in-the-linux-kernel/>)

Author: Nikhil Jha

Published: 2025-07-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Jane Street](<https://devfeed.tech/sources/jane-street.md>)

Topics: [bug](<https://devfeed.tech/topics/bug.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [debug](<https://devfeed.tech/topics/debug.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [data](<https://devfeed.tech/tags/data.md>), [debug](<https://devfeed.tech/tags/debug.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [posix](<https://devfeed.tech/tags/posix.md>), [security](<https://devfeed.tech/tags/security.md>), [trading](<https://devfeed.tech/tags/trading.md>)

### AI overview

A Jane Street engineering post investigates a difficult-to-reproduce bug affecting large file copies in Gord, a system that stores and distributes trading activity data. It explains the role of NFS, Kerberos authentication, and Linux kernel credential handling during the debugging process.

### Source excerpt

We recently ran across a strange higgs-bugson that manifested itself in a critical system that stores and distributes the firm's trading activity data, called Gord. (A higgs-bugson is a bug that is reported in practice but difficult to reproduce, named for the Higgs boson, a particle which was theorized in the 1960s but only found in 2013.) In this post I'll walk you through the process I took to debug it. I tried to write down relevant details as they came up, so see if you can guess what the bug is while reading along.

## Converting a UTC Date-Time String to a UNIX Epoch Timestamp in C and C++

DevFeed: [Converting a UTC Date-Time String to a UNIX Epoch Timestamp in C and C++](<https://devfeed.tech/articles/the-surprising-struggle-to-get-a-unix-epoch-time-from-a-utc-string-in-c-or-c-36444.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/how-to-get-a-unix-epoch-from-a-utc-date-time-string/>)

Published: 2025-01-19T15:02:00Z

Content type: tutorial

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [C](<https://devfeed.tech/topics/c.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [posix](<https://devfeed.tech/tags/posix.md>), [programming](<https://devfeed.tech/tags/programming.md>), [unix](<https://devfeed.tech/tags/unix.md>), [utc](<https://devfeed.tech/tags/utc.md>)

### AI overview

The article examines how to convert a UTC date-time string into a UNIX epoch timestamp in C and C++. It discusses unexpected behavior in POSIX time-handling functions and the complications caused by local times and daylight-saving transitions.

### Source excerpt

So how hard could it be. As input we have something like Fri, 17 Jan 2025 06:07:07 in UTC, and we'd like to turn this into 1737094027, the notional (but not actual) number of seconds that have passed since 1970-01-01 00:00:00 UTC. Trying to figure this out led me to discover many 'surprise features' and otherwise unexpected behaviour of POSIX time handling functions as implemented in various C libraries & the languages that build on them.

## Signals, shells, and docker: an onion of footguns

DevFeed: [Signals, shells, and docker: an onion of footguns](<https://devfeed.tech/articles/signals-shells-and-docker-an-onion-of-footguns-20130.md>)

Original publisher: [Read original article](<https://benchling.engineering/signals-shells-and-docker-an-onion-of-footguns-ee592e2b587b?source=rss----3d4aa8fb07ea---4>)

Author: raylu

Published: 2024-05-22T16:01:32Z

Content type: article

Language: en

Sources: [Benchling](<https://devfeed.tech/sources/benchling.md>)

Topics: [POSIX](<https://devfeed.tech/topics/posix.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [bash](<https://devfeed.tech/tags/bash.md>), [docker](<https://devfeed.tech/tags/docker.md>), [linux](<https://devfeed.tech/tags/linux.md>), [logs](<https://devfeed.tech/tags/logs.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [pytest](<https://devfeed.tech/tags/pytest.md>), [shell-script](<https://devfeed.tech/tags/shell-script.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

This article investigates surprising POSIX signal behavior across shells and containers in Benchling's CI test pipeline. It explains how canceled test runs stopped forwarding logs while pytest continued running, then examines signal propagation through zsh, bash, and child processes.

### Source excerpt

On a few occasions, we've needed to debug POSIX signals (SIGINT, SIGTERM, etc.). Inevitably, there's a shell involved too. One day, we were debugging some weird interaction between signals, shells, and containers and found ourselves bamboozled by some behaviors. People who consider themselves knowledgeable about Linux have found some of the details of our investigation surprising, so read on if this sort of thing doesn't make you want to defenestrate your laptop and become an alpaca-farming hermit. The scene of the crime At Benchling, we have a pretty standard testing/continuous integration (CI) setup: when you push code to a pull request branch, we run tests for you. A few years back, we added a little optimization: if you push again and tests are still running on the previous commit, we cancel the previous test run. You probably don't care about that run anyway and we save some money... or do we? The code that runs our tests is basically def test_pipeline() -> int: test_result = subprocess.run(["pytest", ...]) report_test_metrics() upload_artifacts() return test_result.returncode So our process tree is test_pipeline └──pytest subprocess.run blocks until the child process exits, so it should take almost all the time. We see in our CI logs that the tests get interrupted halfway through and then we see no more logs, so it sure looks like it's working. But we're able to get metrics and artifacts for our canceled runs, which makes no sense. We'll later discover that while we reported that the run was canceled and stopped forwarding logs, pytest just kept running. Back to basics Thinking that perhaps the problem was not forwarding a signal from test_pipeline to pytest, we thought about basic signal handling first. In a terminal running zsh, we can get the pid of zsh with $ echo $$ 20147 Then, we can run bash inside zsh and sleep infinity (like our tests, a very slow command) inside bash. $ bash $ sleep infinity From another shell, we can see the process tree. $ pstree -p 20

## Why C's setenv() and unsetenv() Are Not Thread-Safe

DevFeed: [Why C's setenv() and unsetenv() Are Not Thread-Safe](<https://devfeed.tech/articles/setenv-is-not-thread-safe-and-c-doesn-t-want-to-fix-it-20760.md>)

Original publisher: [Read original article](<https://www.evanjones.ca/setenv-is-not-thread-safe.html>)

Published: 2023-11-19T14:13:23Z

Content type: opinion

Language: en

Sources: [Evan Jones](<https://devfeed.tech/sources/evan-jones.md>)

Topics: [C](<https://devfeed.tech/topics/c.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Concurrency](<https://devfeed.tech/topics/concurrency.md>), [Concurrent Programming](<https://devfeed.tech/topics/concurrent-programming.md>), [Go](<https://devfeed.tech/topics/go.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Rust](<https://devfeed.tech/topics/rust.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [c](<https://devfeed.tech/tags/c.md>), [crash](<https://devfeed.tech/tags/crash.md>), [dns](<https://devfeed.tech/tags/dns.md>), [go](<https://devfeed.tech/tags/go.md>), [posix](<https://devfeed.tech/tags/posix.md>), [rust](<https://devfeed.tech/tags/rust.md>), [thread](<https://devfeed.tech/tags/thread.md>)

### AI overview

The article explains that C's setenv() and unsetenv() modify global environment state and can race with getenv(), causing crashes in multithreaded programs. It argues that the POSIX interface is difficult to use safely and has affected software such as Go and Rust.

### Source excerpt

You can't safely use the C setenv() or unsetenv() functions in a program that uses threads. Those functions modify global state, and can cause other threads calling getenv() to crash. This also causes crashes in other languages that use those C standard library functions, such as Go's os.Setenv (Go issue) and Rust's std::env::set_var() (Rust issue). I ran into this in a Go program, because Go's built-in DNS resolver can call C's getaddrinfo(), which uses environment variables. This cost me 2 days to track down and file the Go bug. Sadly, this problem has been known for decades. For example, an article from January 2017 said: "None of this is new, but we do re-discover it roughly every five years. See you in 2022." This was only one year off! (She wrote an update in October 2023 after I emailed her about my Go bug.) This is a flaw in the POSIX standard, which extends the C Standard to allow modifying environment varibles. The most infuriating part is that many people who could influence the standard or maintain the C libraries don't see this as a problem. The argument is that the specification clearly documents that setenv() cannot be used with threads. Therefore, if someone does this, the crashes are their fault. We should apparently read every function's specification carefully, not use software written by others, and not use threads. These are unrealistic assumptions in modern software. I think we should instead strive to create APIs that are hard to screw up, and evolve as the ecosystem changes. The C language and standard library continue to play an important role at the base of most software. We either need to figure out how to improve it, or we need to figure out how to abandon it. Why is setenv() not thread-safe? The biggest problem is that getenv() returns a char*, with no need for applications to free it later. One thread could be using this pointer when another thread changes the same environment variable using setenv() or unsetenv(). The getenv() function

## How SerenityOS declares ssize\_t

DevFeed: [How SerenityOS declares ssize\_t](<https://devfeed.tech/articles/how-serenityos-declares-ssize-t-38356.md>)

Original publisher: [Read original article](<https://awesomekling.github.io/How-SerenityOS-declares-ssize_t/>)

Author: Andreas Kling

Published: 2023-04-04T00:00:00Z

Content type: opinion

Language: en

Sources: [Andreas Kling](<https://devfeed.tech/sources/andreas-kling.md>)

Topics: [C](<https://devfeed.tech/topics/c.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [compilers](<https://devfeed.tech/topics/compilers.md>), [standard](<https://devfeed.tech/topics/standard.md>), [Library](<https://devfeed.tech/topics/library.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [compilers](<https://devfeed.tech/tags/compilers.md>), [cpp](<https://devfeed.tech/tags/cpp.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [library](<https://devfeed.tech/tags/library.md>), [posix](<https://devfeed.tech/tags/posix.md>), [serenityos](<https://devfeed.tech/tags/serenityos.md>), [standard](<https://devfeed.tech/tags/standard.md>), [technical](<https://devfeed.tech/tags/technical.md>), [unix](<https://devfeed.tech/tags/unix.md>)

### AI overview

This article explains how SerenityOS declares ssize_t using a C preprocessor macro technique. It contrasts the approach with more architecture-specific declarations commonly used by other C libraries and notes the limitations of the hack.

### Source excerpt

This post explores one of my favorite hacks in SerenityOS. I don't recommend doing this in your codebase, but it has worked for us so far. :^)

## My tmux workflow

DevFeed: [My tmux workflow](<https://devfeed.tech/articles/my-tmux-workflow-37861.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/tmux-sessionizer/>)

Author: Carlos Alexandro Becker

Published: 2022-06-06T00:00:00Z

Content type: tutorial

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [Shell](<https://devfeed.tech/topics/shell.md>), [hooks](<https://devfeed.tech/topics/hooks.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [dotfiles](<https://devfeed.tech/topics/dotfiles.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [hooks](<https://devfeed.tech/tags/hooks.md>), [posix](<https://devfeed.tech/tags/posix.md>), [shell](<https://devfeed.tech/tags/shell.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [terminal](<https://devfeed.tech/tags/terminal.md>)

### AI overview

A developer describes a tmux workflow for local and SSH-based remote work, including a project session selector that sorts projects by usage. The article then explains using a shell trap to avoid losing an SSH connection when exiting the last pane of a session.

### Source excerpt

I wanted to share a quick thing that made my life easier on tmux lately, but before we dig into that, I feel like I need to explain how I usually work.

## Designing a Better \`strcpy\`

DevFeed: [Designing a Better \`strcpy\`](<https://devfeed.tech/articles/designing-a-better-strcpy-27355.md>)

Original publisher: [Read original article](<https://saagarjha.com/blog/2020/04/12/designing-a-better-strcpy/>)

Published: 2020-04-12T00:00:00Z

Content type: article

Language: en

Sources: [Saagar Jha](<https://devfeed.tech/sources/saagar-jha.md>)

Topics: [C](<https://devfeed.tech/topics/c.md>), [Security](<https://devfeed.tech/topics/security.md>), [POSIX](<https://devfeed.tech/topics/posix.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [compilers](<https://devfeed.tech/tags/compilers.md>), [function](<https://devfeed.tech/tags/function.md>), [memory](<https://devfeed.tech/tags/memory.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article examines the design of a safer and more efficient C string-copying function intended to preserve null termination, report truncation or overflow, minimize unnecessary memory access, support vectorization, and comply with portable standards such as ISO C or POSIX.

### Source excerpt

Like them or not, null-terminated strings are essential to C, and working with them is necessary in all but the most trivial programs. While C-style strings are a fundamental part of using the language, manipulating them is a common source of security bugs and lost performance. One of the most common operations is copying a string from one buffer to another, and there are a variety of string functions that claim to do this in C. Anecdotally, however, there is much confusion about what they actually do, and many people desire a string copying function with the following properties:

## Configuring Shell Prompts to Warn About Privileged and Production Environments

DevFeed: [Configuring Shell Prompts to Warn About Privileged and Production Environments](<https://devfeed.tech/articles/loud-subshells-29166.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2018/06/21/loud-subshells/>)

Published: 2018-06-21T16:21:00Z

Content type: tutorial

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Shell](<https://devfeed.tech/topics/shell.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Zsh](<https://devfeed.tech/topics/zsh.md>), [systems](<https://devfeed.tech/topics/systems.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [bash](<https://devfeed.tech/tags/bash.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [posix](<https://devfeed.tech/tags/posix.md>), [shell](<https://devfeed.tech/tags/shell.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [systems](<https://devfeed.tech/tags/systems.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [variable](<https://devfeed.tech/tags/variable.md>), [zsh](<https://devfeed.tech/tags/zsh.md>)

### AI overview

This article explains how to make shell prompts more noticeable when users have elevated privileges or access to sensitive environments. It discusses shell differences, prompt configuration, and approaches such as rc-less shells, dedicated environment variables, and sourced scripts.

### Source excerpt

Default shells usually end in $. Unless you're root and it's #. That tradition has been around forever: people recognized the need to highlight you're not just some random shmoe. These days we have lots of snazzy shell magic. You might still su, but you're more likely to sudo. We still temporarily assume extra privileges. If you have access to more than one set of systems, like production and staging, you probably have ways of putting on a particular hat. Some combination of setting an environment variable, adding a key to ssh-agent, or assuming an AWS role with aws-vault. You know, so you don't accidentally blow away prod.

## Windows for Linux Nerds

DevFeed: [Windows for Linux Nerds](<https://devfeed.tech/articles/windows-for-linux-nerds-35220.md>)

Original publisher: [Read original article](<https://blog.jessfraz.com/post/windows-for-linux-nerds/>)

Published: 2017-09-09T15:25:24Z

Content type: article

Language: en

Sources: [Jessie Frazelle](<https://devfeed.tech/sources/jessie-frazelle.md>)

Topics: [Windows Subsystem for Linux](<https://devfeed.tech/topics/wsl.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [POSIX](<https://devfeed.tech/topics/posix.md>)

Tags: [kernel](<https://devfeed.tech/tags/kernel.md>), [posix](<https://devfeed.tech/tags/posix.md>), [windows](<https://devfeed.tech/tags/windows.md>), [wsl](<https://devfeed.tech/tags/wsl.md>)

### AI overview

A developer describes learning Windows after joining Microsoft, with a focus on Windows Subsystem for Linux (WSL), its background, and aspects of how it translates Linux system calls through the Windows NT kernel. The article also mentions reproducibly setting up a Windows machine.

### Source excerpt

I recently started a job at Microsoft. In my first week I have already learned so much about Windows, I figured I would try to put it all into writing. This post is coming to you from a Windows Subsystem for Linux console! I'm headed to Seattle because I'M JOINING MICROSOFT, at the airport wearing this awesome shirt from @listonb & @Taylorb_msft ���� pic.twitter.com/8rnAg1dsPd -- jessie frazelle (@jessfraz) September 4, 2017 New job and I got a Windows computer and a Linux computer! If you are new to my blog, let me tell you: I love setting up a perfect desktop experience. I've written a few posts on it (for Linux), you should check them out. Setting up a Windows computer is something I have not done in quite some time. I will describe a bit how to set up a windows machine in a reproducible way at the end of this post. I would like to thank Rich Turner, John Starks, Taylor Brown, and Sarah Cooley for taking the time to explain a lot of the following to me. :) Windows Subsystem for Linux (WSL) Let's start with Windows Subsystem for Linux, aka WSL. Even @monkchips wrote that since I joined Microsoft "Linux Subsystem for Windows will definitely be getting a workout." I am super excited about Windows Subsystem for Linux. It is one of the coolest pieces of tech I've seen since I started using Docker. First, a little background on how WSL works... You can learn a lot more about this from the Windows Subsystem for Linux Overview. I will go over some of the parts I found to be the most interesting. The Windows NT kernel was designed from the beginning to support running POSIX, OS/2, and other subsystems. In the early days, these were just user-mode programs that would interact with ntdll to perform system calls. Since the Windows NT kernel supported POSIX there was already a fork system call implemented in the kernel. However, the Windows NT call for fork, NtCreateProcess, is not directly compatible with the Linux syscall so it has some special handling you can read about more

## Notes on Unikernels and Memory Corruption Exploitation

DevFeed: [Notes on Unikernels and Memory Corruption Exploitation](<https://devfeed.tech/articles/happy-unikernels-39701.md>)

Original publisher: [Read original article](<https://doar-e.github.io/blog/2016/12/21/happy-unikernels/>)

Author: yrp

Published: 2016-12-22T02:59:00Z

Content type: tutorial

Language: en

Sources: [Diary of a reverse-engineer](<https://devfeed.tech/sources/diary-of-a-reverse-engineer.md>)

Topics: [Kernel](<https://devfeed.tech/topics/kernel.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [exploitation](<https://devfeed.tech/tags/exploitation.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [networking](<https://devfeed.tech/tags/networking.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [posix](<https://devfeed.tech/tags/posix.md>), [rumpkernel](<https://devfeed.tech/tags/rumpkernel.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [unikernel](<https://devfeed.tech/tags/unikernel.md>)

### AI overview

This article presents notes on unikernels, focusing on how applications can be compiled into a NetBSD-based kernel environment. It uses nginx and php5 examples to discuss memory corruption exploitation and payload options, then introduces a basic rumpkernel "Hello World" build process.

### Source excerpt

Intro Below is a collection of notes regarding unikernels. I had originally prepared this stuff to submit to EkoParty's CFP, but ended up not wanting to devote time to stabilizing PHP7's heap structures and I lost interest in the rest of the project before it was complete. However ...

## Hardening Craft CMS Permissions

DevFeed: [Hardening Craft CMS Permissions](<https://devfeed.tech/articles/hardening-craft-cms-permissions-31269.md>)

Original publisher: [Read original article](<https://nystudio107.com/blog/hardening-craft-cms-permissions>)

Author: andrew@nystudio107.com (Andrew Welch)

Published: 2016-12-05T05:42:00Z

Content type: tutorial

Language: en

Sources: [nystudio107 | Articles on modern web development.](<https://devfeed.tech/sources/nystudio107-articles-on-modern-web-development.md>)

Topics: [Content Management System](<https://devfeed.tech/topics/cms.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [file](<https://devfeed.tech/topics/file.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [Server](<https://devfeed.tech/topics/server.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [Livewire](<https://devfeed.tech/topics/livewire.md>)

Tags: [cms](<https://devfeed.tech/tags/cms.md>), [craft](<https://devfeed.tech/tags/craft.md>), [file](<https://devfeed.tech/tags/file.md>), [file-permissions](<https://devfeed.tech/tags/file-permissions.md>), [getting](<https://devfeed.tech/tags/getting.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [important](<https://devfeed.tech/tags/important.md>), [insights](<https://devfeed.tech/tags/insights.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [point](<https://devfeed.tech/tags/point.md>), [posix](<https://devfeed.tech/tags/posix.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [right](<https://devfeed.tech/tags/right.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [unix](<https://devfeed.tech/tags/unix.md>), [view](<https://devfeed.tech/tags/view.md>)

### AI overview

A tutorial on hardening Craft CMS by configuring strict Unix file permissions that allow required webserver operations while limiting unauthorized modification and containing potential security exploit damage.

### Source excerpt

An important part of hardening Craft CMS from a security point of view is getting the file permissions right

## Android Security: Welcome To Shell (Permissions)

DevFeed: [Android Security: Welcome To Shell (Permissions)](<https://devfeed.tech/articles/android-security-welcome-to-shell-permissions-26036.md>)

Original publisher: [Read original article](<http://doridori.github.io//Android-Security-welcome-to-shell/>)

Author: SystemDotRun

Published: 2016-08-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [SystemDotRun](<https://devfeed.tech/sources/systemdotrun.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Android Security](<https://devfeed.tech/topics/android-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Process](<https://devfeed.tech/topics/process.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [POSIX](<https://devfeed.tech/topics/posix.md>)

Tags: [adb](<https://devfeed.tech/tags/adb.md>), [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [posix](<https://devfeed.tech/tags/posix.md>), [process](<https://devfeed.tech/tags/process.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article examines whether a shell started by an Android application has the same permissions as a shell accessed through ADB. It explains that Android process privileges depend on UID, GID, supplementary GIDs, and kernel-enforced resource access, then compares shell processes from ADB and an installed application.

### Source excerpt

Does a shell started from an application have the same permissions as a shell started via adb? What a good question! ADB is a shell that you get on a PC with the same permissions as if you were to run a shell/terminal app on the phone itself. I came across this statement on Reddit which went against my intuition and I had a quick look into it. It was important for me so I can understand the difference in potential attack vectors surrounding open shells. I started by flicking through the excellent Android Security Internals: An In-Depth Guide to Android's Security Architecture to get an overview about how process permissions worked on android. Most of the overview is just a condensed version of a few pages of this great book. This post will mostly talk about how this stuff works with low-level kernel permissions work in the OS, as opposed to high-level operations that involve the package manager (pm). A brief summary of the low-level stuff is: Privileges are based upon the processes UID, GID and supplementary GIDs Like all POSIX systems [clarification needed] access to system resources regulated by the kernel (files, sockets etc) is based on the owner and access mode of the resource and the UID & GID of accessing process Some permissions on Android are mapped to GIDs data/etc/platform.xml Other permissions are checked via pm and I'm guessing are not checkable by the process outlined in this post. These GIDs are mapped to AIDs android_filesystem_config.h For applications (quick diversion) the package manager will add the GIDs for the application at install time, for permissions that appear in the platform.xml file, to data/system/packages.list for the applications entry. When a process is forked from the zygote process, as it does for new application processes, the UID and GIDs are set. Kernel and system daemons use these to grant access to resources and functions. Relative shell permissions So, does a shell started from an application have the same permissions as a s

## Problème de connexion à Oracle

DevFeed: [Problème de connexion à Oracle](<https://devfeed.tech/articles/probleme-de-connexion-a-oracle-26062.md>)

Original publisher: [Read original article](<https://blog.arkey.fr/2015/11/06/probleme-de-connection-a-oracle/>)

Author: brice.dutheil@gmail.com (Brice Dutheil)

Published: 2015-11-06T22:33:53Z

Content type: tutorial

Language: fr

Sources: [The Coffee Workshop](<https://devfeed.tech/sources/the-coffee-workshop.md>)

Topics: [Java](<https://devfeed.tech/topics/java.md>), [Randomizer](<https://devfeed.tech/topics/randomizer.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [firewall](<https://devfeed.tech/tags/firewall.md>), [http](<https://devfeed.tech/tags/http.md>), [java](<https://devfeed.tech/tags/java.md>), [jvm](<https://devfeed.tech/tags/jvm.md>), [linux](<https://devfeed.tech/tags/linux.md>), [posix](<https://devfeed.tech/tags/posix.md>), [random](<https://devfeed.tech/tags/random.md>)

### AI overview

This article examines two causes of Oracle database connection problems that can lead to HTTP timeouts: insufficient system entropy and firewall connection termination. It explains how Java and POSIX random sources affect blocking behavior and discusses the security trade-off between /dev/random and /dev/urandom.

### Source excerpt

Deux problèmes assez courant peuvent survenir sur les connexions à une base de donnée Oracle. Ces problèmes peuvent être à l'origine de timeout sur les connexions HTTP, etc... Ces deux problèmes touchent deux choses totalement différente, l'entropie du système et la coupure de connexion par un firewall.

## Raw sockets in Go: Link layer

DevFeed: [Raw sockets in Go: Link layer](<https://devfeed.tech/articles/raw-sockets-in-go-link-layer-35450.md>)

Original publisher: [Read original article](<https://darkcoding.net/software/raw-sockets-in-go-link-layer/>)

Author: Graham King

Published: 2015-01-31T20:55:57Z

Content type: tutorial

Language: en

Sources: [Graham King](<https://devfeed.tech/sources/graham-king.md>)

Topics: [Go Language](<https://devfeed.tech/topics/go-language.md>), [Network](<https://devfeed.tech/topics/network.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [Programming](<https://devfeed.tech/topics/programming.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [go](<https://devfeed.tech/tags/go.md>), [headers](<https://devfeed.tech/tags/headers.md>), [http](<https://devfeed.tech/tags/http.md>), [ip](<https://devfeed.tech/tags/ip.md>), [ipv4](<https://devfeed.tech/tags/ipv4.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [linux](<https://devfeed.tech/tags/linux.md>), [network](<https://devfeed.tech/tags/network.md>), [network-programming](<https://devfeed.tech/tags/network-programming.md>), [posix](<https://devfeed.tech/tags/posix.md>), [programming](<https://devfeed.tech/tags/programming.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [raw](<https://devfeed.tech/tags/raw.md>), [socket](<https://devfeed.tech/tags/socket.md>), [software](<https://devfeed.tech/tags/software.md>), [tcp](<https://devfeed.tech/tags/tcp.md>), [udp](<https://devfeed.tech/tags/udp.md>), [unix](<https://devfeed.tech/tags/unix.md>)

### AI overview

A technical tutorial on using raw sockets in Go at the link layer. It explains receiving IP packets, inspecting and crafting IP headers, selecting address families and protocols, sending ICMP echo requests, and observing kernel responses. It also discusses Linux behavior and portability limitations for raw sockets.

### Source excerpt

Diving deep into raw sockets and IP headers with Go: A technical exploration.

[Next page](<https://devfeed.tech/topics/posix.md?cursor=WyIyMDE1LTAxLTMxVDIwOjU1OjU3KzAwOjAwIiwgIjAyYWRmNGM5LWQxODctNDc0ZC05MDE3LTFlM2VmYjI2NGJlZiJd>)