<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cyphar's Blog</title><link>https://www.cyphar.com/blog/</link><description>The wild ramblings of Aleksa Sarai.</description><generator>Hugo</generator><language>en</language><copyright>Copyright (C) 2014-2025 Aleksa Sarai. Licensed under CC-BY-SA 4.0.</copyright><lastBuildDate>Sun, 25 May 2025 21:05:00 +0000</lastBuildDate><atom:link href="https://www.cyphar.com/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Four Years On, Umoci Celebrates A Long-Awaited Release</title><link>https://www.cyphar.com/blog/post/20250525-umoci-0.5/</link><pubDate>Sun, 25 May 2025 21:05:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20250525-umoci-0.5/</guid><category>containers</category><category>oci</category><category>umoci</category><description>&lt;p&gt;At long-last a new blog post, and a new release of umoci! It's been a good four years since the last umoci release and six years since my last blog post, so let's make it a quick one.&lt;/p&gt;</description></item><item><title>The Road to OCIv2 Images: What's Wrong with Tar?</title><link>https://www.cyphar.com/blog/post/20190121-ociv2-images-i-tar/</link><pubDate>Mon, 21 Jan 2019 13:00:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20190121-ociv2-images-i-tar/</guid><category>containers</category><category>oci</category><category>ociv2-images</category><category>rant</category><description>&lt;p&gt;The need for a better container image format has been fairly self-apparent for a long time, but there hasn't been a solid effort to redesign how container images should operate. Most container image formats are based on &lt;code&gt;tar&lt;/code&gt;, which at first glance may seem like a reasonable choice. In this first part of a series of articles that outline the design of "OCIv2 images", I hope to dissuade you of this notion.&lt;/p&gt;</description></item><item><title>Generating Coverage Profiles for Golang Integration Tests</title><link>https://www.cyphar.com/blog/post/20170412-golang-integration-coverage/</link><pubDate>Wed, 12 Apr 2017 15:30:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20170412-golang-integration-coverage/</guid><category>free software</category><category>golang</category><category>testing</category><description>&lt;p&gt;While Go's system for unit tests is very seamless and full-featured, allowing for coverage reports to be generated as well as various other cool features, the integration testing story is far less full-featured. In particular, most projects don't use &lt;code&gt;go test&lt;/code&gt; for integration tests and thus don't have a full picture of how their entire test suite stands in terms of code coverage.&lt;/p&gt;</description></item><item><title>umoci: a New Tool for OCI Images</title><link>https://www.cyphar.com/blog/post/20161129-umoci-new-oci-image-tool/</link><pubDate>Tue, 29 Nov 2016 15:30:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20161129-umoci-new-oci-image-tool/</guid><category>containers</category><category>free software</category><category>kiwi</category><category>oci</category><category>suse</category><description>&lt;p&gt;Very recently, I've been working on implementing the required tooling for creating and modifying &lt;a href="https://www.opencontainers.org/"&gt;Open Container Initiative&lt;/a&gt; images without needing any external components. The tool I've written is called &lt;code&gt;umoci&lt;/code&gt; and is probably one of the more exciting things I've worked on in the past couple of months. In particular, the applications of &lt;code&gt;umoci&lt;/code&gt; when it comes to SUSE tooling like the &lt;a href="http://openbuildservice.org/"&gt;Open Build Service&lt;/a&gt; or &lt;a href="https://suse.github.io/kiwi/"&gt;KIWI&lt;/a&gt; is what really makes it exciting.&lt;/p&gt;</description></item><item><title>Adventures into ptrace(2) Hell</title><link>https://www.cyphar.com/blog/post/20160703-remainroot-ptrace-hell/</link><pubDate>Sun, 03 Jul 2016 19:00:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20160703-remainroot-ptrace-hell/</guid><category>containers</category><category>free software</category><category>rant</category><category>runc</category><category>suse</category><description>&lt;p&gt;As part of my work on &lt;a href="https://www.cyphar.com/blog/post/rootless-containers-with-runc"&gt;rootless containers&lt;/a&gt;, I found that many tools try to drop privileges. This makes those tools break inside rootless containers, so I spent a week or two working on a tool that allows users to shim out all of the "drop privileges" syscalls. Here is documented the pain that I went through while figuring out how &lt;code&gt;ptrace(2)&lt;/code&gt; is meant to work.&lt;/p&gt;</description></item><item><title>Rootless Containers with runC</title><link>https://www.cyphar.com/blog/post/20160627-rootless-containers-with-runc/</link><pubDate>Mon, 27 Jun 2016 21:05:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20160627-rootless-containers-with-runc/</guid><category>containers</category><category>free software</category><category>runc</category><category>suse</category><description>&lt;p&gt;There has been a lot of work within the runC community recently to get proper "rootless containers". I've been working on this for a couple of months now, and it looks like it's ready. This will be the topic of my talk at ContainerCon Japan 2016.&lt;/p&gt;</description></item><item><title>Debugging why ping was Broken in Docker Images</title><link>https://www.cyphar.com/blog/post/20160304-docker-broken-ping/</link><pubDate>Fri, 04 Mar 2016 21:05:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20160304-docker-broken-ping/</guid><category>bugs</category><category>docker</category><category>free software</category><category>kernel</category><category>kiwi</category><category>suse</category><description>&lt;p&gt;All complicated bugs start with the simplest of observations. I recently was assigned a bug on our openSUSE Docker images complaining that &lt;code&gt;ping&lt;/code&gt; didn't work. After a couple of days of debugging, I was taken into a deep and dark world where ancient Unix concepts, esoteric filesystem features and new kernel privilege models culminate to produce this bug. Strap yourself in, this is going to be a fun ride.&lt;/p&gt;</description></item><item><title>Dockerinit and Dead Code</title><link>https://www.cyphar.com/blog/post/20160121-dockerinit-and-dead-code/</link><pubDate>Thu, 21 Jan 2016 17:30:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20160121-dockerinit-and-dead-code/</guid><category>docker</category><category>free software</category><category>programming</category><category>suse</category><description>&lt;p&gt;After running into insane amounts of very weird issues with &lt;code&gt;gccgo&lt;/code&gt; with Docker, some of which were actual compiler bugs, someone on my team at SUSE asked the very pertinent question "just exactly what is dockerinit, and why are we packaging it?". I've since written a patch to remove it, but I thought I'd take the time to talk about &lt;code&gt;dockerinit&lt;/code&gt; and more generally dead code (or more importantly, code that won't die).&lt;/p&gt;</description></item><item><title>Docker Internals and Implementing Rebase</title><link>https://www.cyphar.com/blog/post/20151212-hackweek-13-docker-rebase/</link><pubDate>Sat, 12 Dec 2015 22:30:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20151212-hackweek-13-docker-rebase/</guid><category>docker</category><category>free software</category><category>hackweek</category><category>suse</category><description>&lt;p&gt;&lt;a href="https://hackweek.suse.com/"&gt;SUSE's semi-annual Hackweek&lt;/a&gt; was last week and I decided to work on implementing &lt;code&gt;docker rebase&lt;/code&gt;, mainly to learn about the internal image format of Docker and see whether it was possible to improve how the updating of Docker images works in practice (either rebuilding or &lt;a href="https://github.com/SUSE/zypper-docker"&gt;zypper-docker&lt;/a&gt;).&lt;/p&gt;</description></item><item><title>Android Compilation Headaches</title><link>https://www.cyphar.com/blog/post/20151128-android-compilation-headaches/</link><pubDate>Sat, 28 Nov 2015 03:20:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20151128-android-compilation-headaches/</guid><category>android</category><category>free software</category><category>rant</category><description>&lt;p&gt;I've spent the last week of my life trying to build &lt;a href="https://twrp.me/"&gt;TWRP&lt;/a&gt;, which requires having a full, and working Android build environment. With the emphasis on &lt;strong&gt;working&lt;/strong&gt;, I've had just about enough of the stupidity of the Android build system. Every guide is incomplete or out of date, the build system is broken in every possible way and nobody can explain what is going on. Here's my experience with trying to build Android and hopefully will help somebody realise the futility of trying to build a project with such a complicated build system.&lt;/p&gt;</description></item><item><title>Photometry of Contaminated Kepler Pixels</title><link>https://www.cyphar.com/blog/post/20151103-kepler-k2-halo-photometry/</link><pubDate>Tue, 03 Nov 2015 05:45:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20151103-kepler-k2-halo-photometry/</guid><category>astronomy</category><category>k2</category><category>kepler</category><category>physics</category><category>research</category><category>tsp</category><category>usyd</category><description>&lt;p&gt;As part of the &lt;a href="https://sydney.edu.au/science/tsp"&gt;Talented Student Program&lt;/a&gt;, I undertook my first research project in the School of Physics (and hopefully the first of many). Specifically, this research involved designing a novel technique for making use of halo contamination from bright stars in &lt;em&gt;Kepler&lt;/em&gt; K2 fields to do high-precision photometry. I'm planning on doing further research on this topic during the summer, and hopefully will get a paper published as a result.&lt;/p&gt;</description></item><item><title>Tuple Unpacking Oddness</title><link>https://www.cyphar.com/blog/post/20150901-tuple-unpacking-oddness/</link><pubDate>Tue, 01 Sep 2015 01:00:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20150901-tuple-unpacking-oddness/</guid><category>programming</category><category>python</category><description>&lt;p&gt;While working on tutoring the &lt;a href="https://groklearning.com/"&gt;NCSS Challenge&lt;/a&gt;, I found a very interesting oddity of Python's tuple unpacking execution order. While it turns out this is very well documented, it isn't very intuitive (as with most edge cases in languages).&lt;/p&gt;</description></item><item><title>Getting into Linux Kernel Development</title><link>https://www.cyphar.com/blog/post/20150715-getting-into-linux-kernel-development/</link><pubDate>Wed, 15 Jul 2015 14:20:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20150715-getting-into-linux-kernel-development/</guid><category>c</category><category>free software</category><category>kernel</category><category>linux</category><category>programming</category><description>&lt;p&gt;I've been interested in kernel development for a &lt;em&gt;long&lt;/em&gt; time, and recently got some patches merged into the Linux kernel. Here are my experiences about the process of kernel development and what newbies can do to get started.&lt;/p&gt;</description></item><item><title>Making a Simple Scheduler for an Arduino</title><link>https://www.cyphar.com/blog/post/20150112-making-a-simple-scheduler-for-arduino/</link><pubDate>Mon, 12 Jan 2015 03:00:00 +0000</pubDate><author>Aleksa Sarai</author><guid>https://www.cyphar.com/blog/post/20150112-making-a-simple-scheduler-for-arduino/</guid><category>arduino</category><category>c</category><category>programming</category><category>scheduler</category><description>&lt;p&gt;The latest cool thing I worked on for &lt;a href="http://ncss.edu.au/summer_school/"&gt;NCSS&lt;/a&gt; in order to play "The Final Countdown" on a single Arduino Uno with proper chords. Also because I really wanted to write a scheduler, and this was a good excuse.&lt;/p&gt;</description></item></channel></rss>