AI Model Releases

4

OpenRouter: Claude Haiku 5.5

OpenRouter lists Claude Haiku 5.5 (anthropic/claude-haiku-5.5), released 2026-10-07, with June 2026 knowledge cutoff. It supports a 1M-token context and 128K output, accepts text, image, and PDF inputs, and outputs text only. Pricing is $0.1/$0.5 per million input/output tokens below 100K context, jumping to $0.5/$2.5 above that tier; cache read is $0.01 and cache write $0.125 (tiered: $0.05/$0.625). Reasoning can be toggled or set via effort levels (low–max), and tool calling and structured output are supported, but temperature is fixed and weights are closed.

OpenCode Zen: Claude Haiku 5.5

OpenCode Zen now lists Claude Haiku 5.5 (claude-haiku-5-5, canonical anthropic/claude-haiku-5-5), released/updated 2026-10-07, knowledge cutoff 2026-06. Described as a fast Claude model for responsive assistance, classification, and lightweight agents; closed weights, served via the Anthropic AI SDK. Supports 1M-token context, 128K output, text/image/pdf input, reasoning (toggle plus low–max effort levels), tool calls, and structured output; temperature is not supported. Base pricing is $0.1/$0.5 per M tokens in/out with cache read $0.01 and write $0.125; a 100K-token context tier costs 5x ($0.5/$2.5, cache read $0.05, write $0.625). Attachments are supported; API endpoint is https://opencode.ai/zen/v1.

Anthropic: Claude Haiku 5.5

Anthropic released Claude Haiku 5.5 (model ID claude-haiku-5-5) on 2026-10-07, a fast model for responsive assistance, classification, and lightweight agents. It supports a 1M-token context window, 128K-token output, and text/image/PDF inputs with text-only output. Pricing is $0.10/M input, $0.50/M output, $0.01/M cache read, and $0.125/M cache write; a higher tier applies above 100K context tokens (roughly 5x rates). Reasoning is toggleable with effort levels low–max, plus tool calling, structured output, and attachments; temperature control is not supported. It is closed-weights with a June 2026 knowledge cutoff.

OpenRouter: Mistral Large 4

OpenRouter lists Mistral Large 4 (mistralai/mistral-large-4-0), a flagship closed-weights model released/updated 2026-10-06 for advanced reasoning, coding, and multilingual work. It accepts text and image input and outputs text, with 1,048,576-token context and 262,144-token output limits. It supports reasoning with an effort option ("none" or "high"), tool calling, structured output, temperature, and attachments. Pricing is $0.68/M input tokens, $2.09/M output tokens, and $0.07/M cached-read tokens.

AI News

4

We're going to need default hard budget caps on pretty much everything

Simon Willison argues that pay-by-usage APIs and hosting services should offer default hard budget caps that cut off service (return errors) once a monthly limit is reached, rather than merely sending warning emails. Coding and personal agents lower the friction of deploying code that spends money on paid APIs, compute, and storage, making runaway costs a real risk. He argues most users would prefer service errors over surprise $10,000+ bills, so cap removal should be an explicit opt-in checkbox. AWS recently launched monthly spend limits (announced Sept 16, 2026) that pause a project when its spend limit is reached, though rollout is currently limited to some customers. Google Cloud launched a similar "Spend Caps" feature in July 2026, letting users set monthly caps on specific services within a project. Willison suggests AI agents should recommend capped providers and warn inexperienced builders against deploying on uncapped services.

Qwen3.8 27B addition in words

Simon Willison replicated Colin Frasier's experiment testing LLMs on "compute the sum but return the answer in words" across digit lengths. Frasier's original GPT-4o run showed accuracy collapsing toward zero as operand digit counts grew beyond ~5–6 digits. Willison reran the test locally on a DGX Spark with Qwen3.8-27B-Q4_K_M.gguf, 30 fixed pairs per digit-length cell (n=5,070). With reasoning disabled, the model scored only 23.57% overall, degrading rapidly with more digits. With reasoning enabled (one pair per cell, 169 total, slow to run), it answered 167/169 correctly. Reasoning traces show explicit column-by-column addition with carries. Limitation: the reasoning run used only one sample per cell, so results may not be reproducible.

Claude Haiku 5.5

Anthropic released Claude Haiku 5.5, a fast low-cost model matching GPT-6 Luna pricing ($0.10/$0.50 per million tokens) up to 100k tokens; beyond that it jumps 5x to $0.50/$2.50, where Luna remains cheaper. A new tokenizer uses ~1.25x more tokens than Haiku 4.5, a hidden price increase. Reasoning can't be disabled and defaults to medium effort; low-effort pelican SVG cost 0.0936 cents (7s), max effort 3.38 cents (5m9s), with much better output than Haiku 4.5. Anthropic also halved Sonnet 5.5 cache-read prices and added monthly API credits for Max/Team subscribers ($100–$500, non-rolling-over), with optional balance caps to avoid overages.

Scrimshaw Jukebox

Simon Willison prompted Claude Opus 5.5 to design a text-based music format and build an artifact to play it, targeting Secret of Monkey Island-quality game music. The result is "Scrimshaw Jukebox," a browser-based pixel-art player with six original adventure-game tracks stored as plain text. Tracks include tempo, time signature, voice count, and duration metadata; scores are playable and editable with muteable voices and a piano-roll view. The synthesizer runs entirely in the browser; a calypso-flavored "Moonlit Harbor" demo uses 16 voices at 100 bpm. The output leans heavily into the Monkey Island theme but Willison considers it surprisingly good. He speculates that competent music composition may be a newly emerged text-model capability, akin to recent 3D graphics results. He notes careful experiments with other models would be needed to confirm novelty.

Blogs

4

The Pulse: Firebase’s global outage & poor response

A Firebase configuration change crashed iOS apps globally on 29 Sep 2026. A stale legacy config flag cleanup produced a malformed payload; the iOS SDK failed to validate a nil flag name and crashed on launch. Time to detect was ~1 hour (acknowledged via GitHub ticket 70 min in); rollback took ~2h11m, but cached bad responses kept apps crashing up to 6 hours total. An external developer identified the root cause on the GitHub issue before Google acknowledged it; only iOS crashed, as the Android SDK was more hardened. Firebase's status page stayed green throughout, since dashboards rely on server-side metrics and can't show client-side SDK outages; a postmortem came four days later. Google committed to integrating SDK outage info into dashboards, but the incident was buried in a Google Ads dashboard, reflecting unclear org ownership. The article contrasts this with the similar 2020 Facebook iOS SDK crash and urges hardening mobile SDKs against malformed backend payloads.

Vinix is Not a Linux Distro, But it Can Run Games, Docker, and QEMU

Vinix is an open source, non-Linux OS written mostly in V, targeting Apple Silicon Macs (only M1 supported now), with a minimal monolithic kernel booted via Limine and no systemd. It implements namespaces, cgroups, overlayfs, and seccomp itself, letting the stock Alpine Linux Docker engine run natively on ARM64. It runs Linux binaries natively by answering syscalls and matching ELF/musl behavior, installing apps from Alpine aarch64 repos via pkg; QEMU 9.1.2 (software-emulated) can nest Vinix, and games like DOOM, DOOM 3 (~13 FPS), Gothic II, and Minecraft run. Limitations: Docker lacks bridge networking and iptables, Minecraft runs single-core interpreted, GPU drivers are in progress, and secure boot verification is unsupported. The system is minimal (claimed 50 MB RAM, ~1 GB disk), uses a native framebuffer desktop plus optional X.org/Hyprland, and has an OpenBSD-inspired security model with optional pledge/unveil. It's early-stage software, not intended for daily or production use.

How to detect Meta’s Muse AI agent traffic

Fingerprint's Bot Detection Smart Signal now identifies Meta's Muse AI agent, returning bot_type: "meta_muse" with category "ai_agent", confidence level, and identity "unknown" since Muse presents no verifiable identity. Muse operates a real browser on a cloud VM, alters its fingerprint, and suppresses automation flags, unlike agents using declared user agents or Web Bot Auth. It can navigate sites, enter passwords, sign in, apply promo codes, and complete purchases on behalf of users. Detection is included at no extra cost for existing Bot Detection customers, rolled out on a staggered basis. Teams can monitor via Server API/MCP or dashboard filters, then apply policies through Fingerprint's rules engine or their own systems. The "bad" bot label reflects undeclared identity, not necessarily malicious activity. Broader device intelligence signals (VPN use, browser tampering, anonymous browsers) help teams shape AI-agent traffic policies.

We View Consumer Data as Toxic Waste

It's FOSS interviews Carl Dong, formerly a top-5 Bitcoin Core contributor, founder of Obscura VPN. Obscura's core design is a Two-Party Relay: the first hop is Obscura's servers and the exit hop is Mullvad's. Traffic is end-to-end encrypted to a key controlled by Mullvad, so Obscura relays without seeing traffic content, while Mullvad never sees the user's connecting IP or payment info. Dong argues a no-logs policy is inadequate because even honest providers can be hacked, subpoenaed, or acquired; the model is pitched as Tor-like but with two dedicated high-performance hops instead of Tor's three. On censorship circumvention, Obscura's stealth protocol is built on QUIC to mimic HTTP/3 and to avoid TCP-over-TCP meltdown via QUIC's Unreliable Datagram extension; QUIC's fragmentation/shuffling across UDP datagrams makes DPI reassembly costly, and Dong says no deployed QUIC censorship system does reassembly. Privacy posture: accepts Monero and Bitcoin over Lightning, requires no email, uses a random account number, and the site is accessible over Tor. Honest limit: Obscura still sees the connecting IP; the design's point is decoupling that IP from traffic. The client is open source, with a reproducible-builds prototype on Android and other platforms planned. Pricing is $8/month; the team is six remote workers with no VC funding, claiming no user data to monetize. Dong also flags TLS SNI as a censorship vector — US ISPs erroneously blocked Obscura via SNI last year — and hopes for Encrypted Client Hello adoption. Claims about collusion resistance rest on either Obscura or Mullvad remaining uncompromised; content is promotional interview material, so performance and censorship-resistance claims are not independently verified.

Company Blogs

4

GPT-6 and Intelligent UI for everyone

GPT-6 is rolling out globally in ChatGPT. It introduces "Intelligent UI" for richer responses. Responses can include visuals and interactive experiences. Users can explore and use these elements directly. No benchmarks, pricing, or technical architecture details are given in the source.

Sharing AI progress in mathematics

OpenAI published results on open mathematical problems produced by an internal frontier model. The release includes Lean proof formalizations and supporting research details. Artifacts are shared publicly on GitHub. No benchmark scores or problem specifics are provided in the announcement.

Our approach to EU text provenance rules

The post is a promotional page (only a title, URL, and blurb) describing OpenAI's approach to text watermarking under EU provenance rules. It states that OpenAI outlines where watermarks apply, how detection works, and why access to detection starts with researchers. No technical details—watermarking scheme, coverage, detection accuracy, or limitations—are present in the supplied content. The actual mechanics cannot be summarized beyond these three high-level topics.

DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent

GitLab's Threat Research Group disclosed a command execution vulnerability (CVE-2026-102437, GHSA-grg2-7gc6-36m6) in DeepSeek-Reasonix Studio, a desktop git client for AI-assisted development, dubbed "ConfigPoisoning." Exploitation runs attacker-controlled code when a developer views a file's diff. Root cause: DeepSeek-Reasonix's git wrapper (internal/gitcmd) hardens several dangerous git config keys on every call — neutralizing core.fsmonitor and maintenance.auto, and adding --no-ext-diff and --no-textconv to diffs — but never touches filter..clean. That key is selected per file via .gitattributes rather than a fixed config key, so it cannot be closed by the same deny-list approach. The vulnerable call in desktop/workspace_changes.go (git diff --no-ext-diff --no-textconv --relative HEAD -- ) still invokes the clean filter, which builds the comparison blob for each side of the diff, executing the attacker's command once per diff side. git status is unaffected since it never builds filtered blobs. Attack setup: a .gitattributes entry assigns a file (e.g., secret.bin) to a filter driver whose clean command, defined in .git/config, is attacker-chosen. Because .git/config does not survive a clone, delivery requires an archive, synced folder, CI cache, or devcontainer build — or, more directly, a compromised or prompt-injected agent running with the developer's privileges can write the poisoned config into an already-cloned repository. Confirmed at commit ea28602 and pre-release studio-v2.9.0, affecting both the desktop app and npm package. Repositories hosted on GitLab are not affected, since cloning over HTTPS/SSH does not transfer local config files. The same vulnerability class (commands run via keys such as core.fsmonitor, core.hooksPath, diff.external, filter..clean) affects multiple widely used coding agents; GitLab previously found an analogous trust failure in Serena (.serena/project.yml). Recommendations: update to Studio 2.21.0 or npm 1.39.3; on older versions avoid diffing repos not obtained via a direct clone. Tool builders should read blobs with git cat-file/git show and diff in-process, or override every relevant key on every call (core.fsmonitor, core.pager, core.editor, core.hooksPath, diff.external, core.sshCommand, and filter..clean/smudge across .gitattributes, .git/info/attributes, and global/system files) — noting one flag does not cover another (e.g., --no-ext-diff does not affect core.sshCommand) — and test against hostile configs. Disclosure: advisory opened 2026-08-27, accepted 2026-09-29, fix and advisory published 2026-09-30 with CVE assignment. Further affected agent tools are under coordinated disclosure.

Hacker News

4

AI-ready biological data: $1.8B global commitment

Submission links to a Biohub announcement titled "AI-ready biological data: $1.8B global commitment" describing expansion of a virtual biology initiative. The actual article text is not included in the submission, only the URL, so no technical details are available to verify. Hacker News metadata shows 89 points and 10 comments, indicating moderate discussion. Claimed scope, methodology, and limitations of the $1.8B commitment cannot be assessed from the provided content.

ADHD as a circadian rhythm disorder: evidence and implications for chronotherapy (2025)

A 2025 Frontiers in Psychiatry paper argues ADHD may involve circadian rhythm disruption, citing links between ADHD symptoms and delayed sleep phase, melatonin timing, and light exposure. The authors propose chronotherapy—timed light therapy, melatonin, and sleep scheduling—as a potential adjunct to standard ADHD treatment. Evidence presented is largely correlational; causality between circadian disruption and ADHD symptoms is not established. Concrete limitations: heterogeneity of ADHD subtypes, small study samples, and lack of large randomized trials of chronotherapy for ADHD. The paper is mainly a review/hypothesis piece calling for controlled intervention studies rather than reporting new clinical data. Discussed on Hacker News (205 points, 136 comments).

ADHD as a circadian rhythm disorder: evidence and implications for chronotherapy (2025)

A 2025 Frontiers in Psychiatry paper proposes ADHD may be linked to circadian rhythm disruption and explores chronotherapy as a treatment approach. The submission includes only the article link and discussion metadata, not the paper's full text. It drew 202 points and 136 comments on Hacker News. No specific mechanisms, study methods, or limitations can be reported from the supplied metadata alone.

Infra

4

The Shift to cgroup v2 in Kubernetes: What You Need to Know

Kubernetes has deprecated cgroup v1: starting with v1.35, failCgroupV1 defaults to true so the kubelet won't start on cgroup v1 nodes (temporary override via failCgroupV1: false), kubeadm's SystemVerification preflight fails on v1 nodes, and full removal is scheduled for v1.38 (KEP-5573). cgroup v2 offers a single unified hierarchy and enables v1-only features: Memory QoS (memory.high throttling plus tiered memory.min/memory.low protection, alpha in v1.36, needs kernel 5.9+), container-aware OOM handling (memory.oom.group, singleProcessOOMKill defaults false), controller delegation for rootless containers, PSI metrics, and accurate enforcement of in-place Pod-level resource resize. Known limitations: the active_file eviction issue persists regardless of cgroup version; workaround is matching memory requests and limits for I/O-heavy containers. CRI protobuf fields keep v1-style names even on v2, and newer OCI runtimes (crun 1.23, runc 1.3.2) changed the shares-to-cpu.weight conversion, which may break tools predicting exact weights. Requirements: Linux kernel ≥5.8 (5.9+ for Memory QoS), cgroup v2-capable runtime (containerd ≥1.4, CRI-O ≥1.20), matching kubelet/runtime cgroup driver; automatic driver detection (KEP-4033, stable in v1.34) needs containerd 2.0+ or CRI-O 1.28+.

Scaling Kubernetes Workloads with Node Swap

Kubernetes node swap reached GA in v1.34, letting nodes page out idle anonymous memory to fast NVMe Local SSDs to raise pod density for memory-heavy, bursty workloads like agentic AI sandboxes. Previously swap was avoided because cgroup v1 merged memory and swap accounting; cgroup v2's separate swap tracking plus fast SSDs resolve this. Benchmarks: a Linux 6.1.1 kernel CI build cut its memory limit 50% (600 MB→300 MB) with no slowdown (374s vs 433s), but compressing to 200 MB forced active working set into swap and added >40% runtime. Headless Chrome density rose from 80 to 160 pods with gVisor (+100%) and 40 to 50 with Kata (+25%); unsandboxed runc scaled from 512 failures to 768 pods. Python sandboxes (~375 MiB each, MovieLens 20M) scaled 3×, from 80 to 240 concurrent sessions per node. At peak density, latency growth came mainly from CPU contention, not swap I/O. Usage: set kubelet failSwapOn: false with memorySwap.swapBehavior: LimitedSwap (e.g., GKE Node Memory Swap on Local SSD), and run Burstable QoS pods with memory limits above requests. Key caveat: swap is a buffer for dormant/burst memory, not a substitute for RAM covering active working sets.

Initial Triage Guide for VMware Cloud Foundation Private AI Services

VMware published an initial triage guide for VCF Private AI Services to quickly isolate whether issues stem from infrastructure or the service itself. Setup: workstations need vCenter/NSX/Supervisor access plus kubectl and VCF CLI; authenticate to the Supervisor, switch namespace context, then extract the VKS guest cluster kubeconfig from a secret named -kubeconfig. Confirm the deployed PAIS version via vSphere Client (Services > Manage Service) or kubectl jsonpath on paisconfiguration. Part 1 rules out infrastructure: blast-radius check across namespaces/clusters, ESXi and NVIDIA GPU driver/ECC/license health via nvidia-smi, vSAN Skyline Health, backing PostgreSQL database connectivity on port 5432, NSX/VPC realization and IP block usage, and certificate validity across vCenter/Supervisor/SSO. Part 2 inspects the service: check PAISConfiguration conditions (Ready, ModelEndpointPrerequisitesMet, PrometheusReady), then clusters/machines and pods readiness. Most pod-startup failures trace to CPU/memory under-reservation or missing VM/storage classes; stuck nodes (10+ minutes) or pending pods usually indicate infrastructure capacity or provisioning issues. If unresolved, collect a support bundle per Broadcom KB 408731 before escalating to GSS.

Optimizing AI Deployments with VMware Cloud Foundation (Part 3)

Part 3 of VMware's VCF AI performance series shows GPU-accelerated AI inference VMs can be downsized in vCPU/memory, freeing capacity to consolidate CPU-intensive workloads on the same ESX host. Tests ran MLPerf Llama3.1 8B on VCF 9.1 (Dell PowerEdge XE7745, 2x AMD EPYC 9555, four NVIDIA RTX 6000 Blackwell GPUs); varying memory (32–512 GB) or vCPUs (16–128) had little or no impact on throughput and latency. A co-location test ran HammerDB TPC-C (~1.8M TPM, 12 vCPUs, 75% utilization) concurrently with Llama3 70B inference (TRT-LLM, tensor-parallelism of 4, 1 vCPU) on four H200 GPUs with no measurable performance impact on either workload. Claim: allocating 25–50% of cores to AI VMs matches bare-metal inference performance, enabling workload consolidation, isolation, and TCO reduction. Limitations: results are vendor benchmarks from a single hardware configuration; agentic workload co-location is only promised for future posts.

Newsletter

4

Issue #291 - Less Terraform, more control: MCP apply gates, OpenTofu owner tags, module conventions, AI friendly code and CloudBurn AWS savings

Terraform Weekly Issue #291 collects several IaC write-ups and a tool release. MCP server GA article: ENABLE_TF_OPERATIONS env var is the gate between read-only AI assistance and autonomous applies, plus Sentinel policy gates and audit trails for approval accountability. choudoufu (Intentius): OpenTofu fork that stamps owner tags on every resource so cloud IAM decides who can modify, treating state as a disposable cache with one-command adoption of existing resources. Module structure guide: standard file layout, empty placeholder files, required-before-optional variables, pessimistic version pins, generated READMEs, and pre-commit hooks. AI-friendly Terraform: declaring infrastructure next to app code via Encore reduced Terraform/Docker/CI YAML and constrained agent guesswork. CloudBurn: open-source Apache 2.0 CLI with 82 deterministic AWS cost rules, scanning Terraform and CloudFormation in CI and a discover mode against live accounts. No new tool versions or benchmarks are covered; the issue is a curated link roundup.

🦥 OpenAI wants $500/month now

This Sloth Bytes newsletter post covers four main topics:

  1. OpenAI DevDay (25 announcements). Highlights relevant to developers: "Dots" (always-on personal agents); GPT-6.1 Sol, a coding model OpenAI claims matches GPT-6 Astra at ~1/5 the price ($2 input / $10 output per million tokens); "Ultrafast," a premium speed tier offering up to 8x faster token generation (300 tokens/sec) in Codex and 6x in the API at 6x the price; a new $500/month "Pro 500" plan with 25x the Plus allowance plus Ultrafast access; Codex in the cloud (tasks continue running after closing your laptop); a Codex CLI refresh adding voice commands and an /agents task view; Code Review updates (Codex summarizes diffs and flags PR issues asynchronously); Codex Security Cloud (scheduled GitHub repo scans with prepared fixes); computer-use tools in the Agents API; plugin extensions and MCP events (sidebar panels, app-triggered automations); and Sign in with ChatGPT across 16 partner tools (Devin, Vercel, Notion). Noted downside: Pro plan usage being cut in half.

  2. Claude Sonnet 5.5 release: Anthropic claims 30%+ faster output and up to 30% lower cost per task; token prices unchanged at $2/$10 per million tokens (same as GPT-6.1 Sol). Author impressions: better writing with less "AI slop," no em dashes, strong design/UI/UX output, improved usage limits; recommends Sonnet for small defined tasks and Opus for writing, design, and coding.

  3. Vite+ 1.0 (VoidZero): a free, MIT-licensed unified CLI replacing vite, vitest, eslint, prettier, tsup, and turbo with a single vite.config.ts. Commands: vp dev, vp test, vp build, vp check (format/lint/type-check in one pass), plus a cached monorepo task runner. Built in Rust; benchmarks claim 50-100x faster linting than ESLint and up to 30x faster formatting than Prettier. Framework-agnostic (React, Vue, Node CLIs, monorepos).

  4. WSL containers now generally available on Windows 10 and 11: built into WSL (wsl --update, no separate container engine), Docker-style commands (wslc run/build/container list, with "container" alias), Microsoft claims up to 2x faster Linux reads of Windows files, works as a driver for VS Code dev containers, and a Microsoft.WSL.Containers NuGet package for apps. Limitation: no Compose support yet and no release date, so it is not a Docker Desktop replacement.

The post also links further reading (streaming AI response failures after "200 OK," Kubernetes health checks, Big O visual guide, agent sandboxing) and tools (PiG terminal coding agent in Go, drawDB, Python Tutor, regex101, JSON Crack, CodeCrafters), plus sponsor segments (Jira Product Discovery, Superhuman AI, Attio).

🦥 He got into Amazon without an interview

Sloth Bytes newsletter interview with Dara Adedeji, a CS student who secured an Amazon SDE internship without a technical interview via the Amazon Future Engineer scholarship (up to $10k/year plus paid internship for high school seniors with financial need); Amazon Propel offers a similar route for first/second-year students. LeetCode is still recommended since such programs are rare. His intern project optimized a retail routing log-analysis pipeline: parallel processing with AWS Glue, Parquet, and Athena cut multi-terabyte log processing from ~a day to ~7 minutes. He then built Parthenon, an agent-first CLI/MCP tool that turns pasted ticket links into shareable investigation reports, cutting investigations from 10 days to 15 minutes and helping resolve 150+ incidents in a month. Advice: build for real problems, integrate tools into existing workflows, use AI agents to work on projects while practicing interviews, and encode repeated processes as reusable skills.

🎤 "To be different is great. You don't want to be the same." - Kristen Johnston

Cassidoo's weekly newsletter (Oct 9, 2026) opens with web links on the history of port numbers, Evil Martians' Gatsby-to-Astro migration done without rewriting React components, new HTML/CSS design-system features, AI's "terminal era," and bidirectional text handling in LLMs. The author highlights a blog post on accessibility, arguing that AI automation has renewed interest in accessibility and speculating about a future internet pricing model that separates human and bot traffic. The interview question is a grid BFS problem: zombies (2) infect adjacent living people (1) each minute; return minimum minutes until no people remain, or -1 if unreachable (multi-source BFS). Community submissions to last week's "temperature drops" question are linked from GitHub, CodePen, Bluesky, and other sources. No technical code changes or releases are described; the post is a link roundup, essay teaser, coding puzzle, and general updates.

Personal Blogs

4

Recursion is DEAD and HTML killed it

Chromium is flighting Declarative Partial Updates, adding a <?marker> element for out-of-order HTML streaming paired with <template for="name"> blocks that auto-inject into matching markers. Each marker is single-use; re-emitting the same marker in appended content allows indefinite chaining and an open server connection can keep streaming HTML. This enables infinitely nested threads with no server-side tree building: each post is wrapped in a template targeting its parent's ID and streamed immediately, letting the page self-assemble instead of building a tree and recursively rendering. Canonical use cases include LLM chat streaming and relational content like comment threads, reviews, and PRs. Limitations: single-use markers require manual repetition, FOUC/LCP jank needs management, and very large threads (e.g. 10K posts) still need "show more" controls.

Cloud Run's invisible 60% scaling dials are now yours to control

Cloud Run's custom scaling controls went GA on 29 Sep 2026 (preview 16 Apr 2026), letting owners replace the fixed 60% CPU and concurrency targets via --scaling-cpu-target (0.10–0.90) and --scaling-concurrency-target (0.10–0.95); either can be disabled but not both. Instance count is computed from three drivers—CPU, concurrency, and adaptive concurrency (which drops an instance's concurrency by 1 when CPU exceeds 90%)—and the highest number wins. Lower targets scale earlier at higher cost; higher targets create a wider dead zone and step changes. The concurrency target is a fraction of max concurrency, not a replacement. Billing matters: request-based billing only charges CPU during requests, while instance-based billing charges full instance life (except scale to/from zero). Limitations: no scaling on memory, latency, or queue depth; not available for jobs or worker pools; max instances still queue then 429 and can be briefly overshot.

TLDRs newsletters are TLDR so I wrote a converter that gets all the important links

Christian Heilmann wrote a PHP script (TL-TLDR, on GitHub) that extracts the essential links from TLDR newsletter web versions. It reads newsletter web-version URLs line-by-line from tldrs.txt, fetches each, and parses with DOMDocument/DOMXPath. It keeps only anchors containing "minute read" or "GitHub Repo", stripping those markers to get headlines. It extracts each link's href, title, and adjacent description text from the parent node's siblings. Redirect-wrapped links (links.tldrnewsletter.com) are resolved to real URLs via curl -Ls -w %{url_effective} with escapeshellarg. Results are appended back into tldrs.txt as title, URL, and description entries. Limitations: brittle DOM traversal (parentNode->lastChild->previousSibling), regex-based text matching, and it assumes well-formed-enough HTML (libxml errors suppressed).

Web Weekly #200 (#blogPost)

Web Weekly #200 is a link roundup after a four-week break (conference talks and cycling events). Highlights State of Dev survey results: 50% of 5,463 respondents see leaving tech within 5 years as a real possibility; top emotions are exhausted, disillusioned, curious, overwhelmed, anxious. Technical links cover fetch's two-phase await (first await resolves response headers, second the body, which is a ReadableStream). Notes Firefox Nightly shipping first parts of the CSS Linked Parameters spec for passing values into external SVGs. Also mentions a Connection-Allowlist HTTP header as a simpler alternative to CSP for controlling outgoing requests, no MDN docs yet. Other items: initial-scale no longer needed in viewport meta, touch-action: manipulation to stop double-tap zoom, container style queries as named breakpoints, Baseline additions text-box (newly available) and checkVisibility() (widely available), and importmap being baseline-supported. No code changes are presented; it's a curated list of external articles, tools, and projects.

Standards and Spec

3

WPE WebKit Blog: WPEPlatform: the new WPE API

WPE WebKit 2.54 makes WPEPlatform the default and stable platform-integration API, deprecating the libwpe/backend model. Previously applications loaded a libwpe backend, managed exported DMA-BUF frame callbacks, and dispatched input events manually. WPEPlatform is a GObject library in the WebKit repo built around WPEDisplay, WPEToplevel, WPEView, and WPEBuffer classes. It moves buffer presentation and input handling into WebKit and platform modules; web-process buffers (DMA-BUF, AHardwareBuffer, shared memory) go directly to the platform. Built-in platforms are Wayland, DRM/KMS, and headless; out-of-tree implementations like wpe-platform-gtk load as runtime modules. A minimal browser is just g_object_new(WEBKIT_TYPE_WEB_VIEW); platform selection is automatic or via WPE_PLATFORM env var. Input can be intercepted via the WPEView::event signal; toplevel controls and WPESettings (dark mode, reduced motion) are exposed. Migration limits: no process provider (except Android's WPEProcessManager), unsupported audio/video-plane extensions, and DRM/headless toplevels have reduced functionality; legacy API is still built by default and Cog ends at 0.18.x.

Igalia WebKit Team: WebKit Igalia Periodical #80

WebKit Igalia Periodical #80 covers work from Sept 28–Oct 5. Initial OpenSSL crypto backend support landed for WPE/WebKitGTK, still in development and not production-ready. Moving-steps handling added for map, img, label, and radio inputs, including custom element registries. Skia compositor now correctly stacks backdrop-filter effects. LBSE improvements: reduced save/restore pairs per SVG shape (cutting GPU-process IPC from ~8.5 to ~6.5 messages/shape), fixed objectBoundingBox clipPath transforms, non-scaling-stroke hit testing/repainting after transform changes, filter source areas on partly scrolled layers, nested overflow clipping, and mispositioned child layers under transformed ancestors. WPE legacy API regained DRM vertical blank pacing after two regressions had forced a fixed 60 Hz timer fallback.

W3C Newsletter - September 2026

W3C's September 2026 newsletter covers: (1) Board of Directors election — re-elected Koichi Moriyama, Chris Needham, Florian Rivoal, Léonie Watson, and Hongru Zhu; newly elected Theresa O'Connor (Apple) and Avneesh Singh (DAISY); terms ended for Chris Wilson and Eric Siow. (2) AI work: W3C/GS1 workshop on e-commerce for humans and AI agents (Sept 8–9, ~140 attendees) identified needs for product data models, identity/authorization, and payment; WebMCP proposal in the Machine Learning CG got early reviews from APA WG, Security IG, and TAG and is proposed for a potential Agentic Web Working Group; a Generative UI/WebSkill seminar was held in Shenzhen; the Browser and Testing Tools WG is discussing extending WebDriver to LLM-driven browsers; 7 agentic-web breakouts planned at TPAC 2026. (3) Process revamp: Process CG discussing modularizing the W3C Process and allowing process experiments; tooling discussions (assisted scribing, AI in security/accessibility/i18n) planned for TPAC. (4) WCAG 3.0 updated Working Draft with progress on the proposed conformance model. (5) ODRL workshop report proposes a new Digital Policy Working Group, charter in development. (6) Open-source program pilot launched supporting "Can I VC?" as a compatibility dashboard for Verifiable Credentials. (7) TPAC 2026 (Dublin): registration open until Oct 16 (499 registrants); three mini-workshops (AI and Society, Age Assurance, Data Governance & Ownership) accepting proposals until Oct 9; an All-Community plenary session. (8) 30th anniversary of W3C in Japan, celebrated with a "Web together" event Sept 4. Other news: September baseline features (CSS alpha(), light-dark(), progress(), overflow-anchor, ariaNotify(), WASM JSPI); new Rec-track drafts for WebAuthn Level 4 (remote desktop support), SHACL 1.2 Inference Rules, and VC Bitstring Status List 1.1; Sustainable Web IG progress on Web Sustainability Guidelines and impact ratings; upcoming TAG election with 5 seats; W3C marked its 32nd anniversary Oct 1.

Tech Publications

4

Anthropic bans ‘abusive or cruel behavior’ toward Claude

Anthropic updated its usage policy for the first time in over a year, targeting misuse like election interference, weapons development, surveillance, and high-risk health/financial uses. The most notable change bans "sustained and needless abusive or cruel behavior" toward Claude. This follows Anthropic's August announcement letting Claude end conversations with persistently harmful or abusive users, part of its "model welfare" research. Conversation termination remains the primary enforcement mechanism. Anthropic did not provide additional comment.

Xbox has secured GTA 6 streaming rights

Xbox CEO Asha Sharma teased at an all-hands that Microsoft secured game streaming rights for GTA VI. The deal will let Xbox Cloud Gaming stream GTA VI at launch, something Sharma called unique among platform holders. The agreement's duration is unclear. Rockstar has not announced a PC version of GTA VI, and a streaming deal would normally also allow Xbox to stream that version.

Federal judge calls Flock ‘indiscriminate mass surveillance’

A federal judge ruled that a sheriff's deputy violated a woman's Fourth Amendment rights by using the Flock license plate recognition system to search for her license plate without a warrant. The judge characterized Flock's use as "indiscriminate mass surveillance." The ruling addresses warrantless plate searches conducted via Flock's surveillance network. No further technical details or specifics about the decision's scope are provided in the source content.

Meta open sources code to let you make Muse AI gadgets

Meta has open sourced the code needed to build DIY "Muse gadgets" featuring its new Muse AI agent. The SDK is available on GitHub (facebookincubator/muse-gadget-sdk) and supports programming off-the-shelf ESP32 boards or setting up a Raspberry Pi, then connecting Muse to displays, buttons, sensors, and actuators. Suggested example projects include running Muse on a color E Ink display for reminders, on an HDMI stick for big-screen display, or on a small touchscreen device resembling a DIY "Muse Charm." Meta describes these as open source devices users build themselves. The article excerpt does not detail software architecture, model hosting, or hardware requirements beyond these boards.

Tools

4

pnpm 12.10.0

pnpm 12.10.0 adds an experimental nodeLinker: { type: loaded } that loads compatible deps directly from the content-addressable store via an auto-registered Node.js loader, with nodeLinker.excluded for global virtual store installs. lockfile.includeResolutionSettings: true records resolution settings (autoDedupe, dedupe options, linkWorkspacePackages) in pnpm-lock.yaml, making lockfiles portable so pnpm run after frozen install no longer re-installs. Security fixes: install blocks path-traversal writes outside the global virtual store; config dependencies and lockfile variations tarballs are verified against the registry; audit signatures check lockfile integrity; archives over 64 MiB are rejected; URL/path dependencies differing only in +, #, :, ? vs / get hashed virtual store dirs. Resolution now errors on unsupported protocols (e.g. Yarn patch:) and non-string specifiers; --fix-lockfile repairs missing snapshot entries; auto-installed peers move with downgraded dependencies. Speed: metadata cache moved to <cache-dir>/v12/ (first install re-downloads), metadata requests no longer queue behind tarball downloads, and macOS workspace relinking drops from 116 ms to 45 ms for 1,000 projects. CLI fixes include clean Ctrl+C exits without ELIFECYCLE noise, regex selectors supporting lookahead/lookbehind, global-only pnpm config get/list --global, and stderr-only devEngines/packageManager warnings.

pnpm 12.10.1

pnpm 12.10.1 is a patch release fixing install failures and bugs in the experimental nodeLinker.type: loaded. Generated files under loaded now live in node_modules (store manifest/loader in .pnpm/, bin shims in .bin); old root-level .pnpm-store* files and .pnpm dirs should be deleted manually. loaded now handles packages shipping their own node_modules (e.g. npm) instead of breaking all Node processes, and scripts can run devEngines.runtime Node without shim recursion ("Argument list too long"). Startup overhead with loaded dropped from 67 ms to 18 ms per process in a 13,000-file project. pnpm install no longer fails with ERR_PNPM_NO_MATCHING_VERSION after overrides changes resolving optional peers to npm aliases (#16654), and filtered frozen installs with catalogPrune no longer drop still-referenced catalog entries (#16638). Also: --fix-lockfile preserves deprecated/hasBin fields (#6600); enableGlobalVirtualStore repairs packages broken by interrupted installs (#16642); nested Cargo/Python projects with their own pnpm-workspace.yaml or .git are skipped; and the "Request took" warning now excludes queue wait time.

pnpm 12.9.0

pnpm 12.9.0 runs via WebAssembly in StackBlitz WebContainers, even with install scripts disabled. A per-registry networkConcurrency setting caps in-flight requests to that registry origin, configurable in pnpm-workspace.yaml or global config.yaml. pnpm install now records all installed projects in the store's projects directory as symlinks; --frozen-store installs without the global virtual store record nothing. Security fix: pnpm login no longer forwards credentials in the request body on cross-origin redirects. Many fixes for optional dependencies (npm-like skipping of missing deps, removed links after failed builds, fetch-failure warnings/logs), frozen-lockfile installs, hoisted linker filtered installs, dedupe/autoDedupe behavior, and pnpm clean safety with shared virtual stores. Network improvements: conditional-request revalidation of non-cacheable and minimumReleaseAge metadata, per-host concurrency drop to 1 after a fetch timeout, and faster offline resolution. Script fixes include pnpm -s <script> as sequential, fewer watchdog processes, and Windows Ctrl+C cleanup; also Windows self-update and pinned-pnpm reliability fixes, pnpm deploy symlinked-target fixes, and package-name filter ? wildcard support.

pnpm 11.28.4

pnpm 11.28.4 fixes two credential leaks: pnpm login no longer forwards credentials cross-origin on redirects, and tarball integrity errors no longer print URL credentials, query strings, or fragments. Frozen lockfile installs now accept lockfiles with only a pinned pnpm version, missing a --- line, workspace projects without directories (e.g., excluded from Docker contexts), and projects with dependenciesMeta (now recorded in the lockfile). Optional dependencies that fail to fetch now emit a warning, aren't linked as broken symlinks, and are reported via a pnpm:skipped-optional-dependency log with fetch_failure; failed builds remove the link so reinstalls don't rerun. Filtered installs with nodeLinker: hoisted no longer prune packages needed by unselected projects, and registry metadata is revalidated via conditional requests instead of full redownloads. A fetch timeout drops per-host concurrency to one for retries and later downloads, and scripts run without a TTY share one watchdog process group, halving process count for pnpm -r run. Self-update now fails for Homebrew installs with a brew upgrade hint and fixes stale/locked pnpm.exe handling on Windows; verifyDepsBeforeRun failures only warn so scripts can run in sandboxes. Limitations: lockfile-missing-directory installs still fail if the directory exists without a package.json, and the [<since>] selector requires Git 2.24+ (hard error below).

Top Reddit

4

WASM based VM that runs real Linux in a browser tab

arm64js is an ARMv8-A system emulator built in Rust, compiled to WebAssembly, that boots real Alpine Linux inside a browser tab. It is an interpreter emulating a minimal hardware stack, so the guest OS behaves normally and can run apk and even Docker (slowly).

Architecture: a single WASM module is instantiated across multiple web workers, all sharing one SharedArrayBuffer as the VM's RAM. Because SharedArrayBuffer requires COOP/COEP headers, if the host page doesn't send them, the VM is served in an iframe on its own origin.

Networking: since WASM cannot bypass CORS or send raw TCP, internet access works through proxies — apk via a proxy that only adds CORS headers, and TCP via a WebSocket-to-TCP gateway.

A JS SDK (MIT-licensed; engine free for non-commercial use) lets developers create and serve their own VMs, e.g. Arm64JS.boot('alpine') then vm.exec('uname -a'). Demos exist at arm64js.com and demoshell.com/gallery. The project is early-stage and the author seeks feedback on use cases, motivated by the friction of installing small TUI tools locally versus browsers running large web apps.

A web-based Windows Phone simulator for phones

A Reddit post on r/webdev introduces wphone.dev, a web-based Windows Phone simulator that runs in mobile browsers. It implements an on-device file system backed by IndexedDB, live tiles populated by individual apps, and toast notifications with an Action Center. It ships with 64 preinstalled apps, and the included Store app can uninstall and reinstall them. The app catalog covers: core apps (Phone, Messaging, People, Outlook Mail, Calendar); media (Camera, Photos, Music, Video, FM Radio with real internet radio, Podcasts, Voice Recorder); info/utility (Weather, News, Money, Sports, Maps, Translator, Internet Explorer); productivity (Office with Word and Excel including formulas, OneNote, Alarms with timer and stopwatch, Files, Storage Sense, Battery Saver, Calculator); Settings, Store, and Cortana (text and voice, supporting alarms, reminders, notes, events, weather, calls, texts, Wikipedia lookups, and web search); a Games hub with gamerscore and achievements (Minesweeper, Solitaire, Wordament, Snake, 2048, Blocks); and extras (Flashlight, Compass, Bing Vision QR/barcode scanner, Wikipedia, Unit Converter, Mirror). Source is on GitHub (ducbao414/wphone.dev). Tech stack is vanilla JavaScript on the front end with Hono for the backend, deployable on Node or Cloudflare Workers. Limitations noted in the post: it is a browser simulation (no claim of full OS fidelity), and no further technical constraints are described.

RHP 2.0: A charting library for building dynamic, interactive, infographic-style charts and plots!

RHP 2.0 is an open-source SolidJS rewrite of a React charting library from three years ago. It renders charts using HTML elements, CSS, and JS instead of Canvas or SVG, simplifying interactive and styling features. The rewrite removed complexity from the over-engineered 1.0: niche features, redundant components, and an extra interface layer were stripped out. Leaf components were split into more focused blocks, each handling a specific visual element type. SolidJS signals simplify state management, letting charts update quickly on data changes with minimal effort. Charts adapt to layout changes, restacking vertically on mobile-sized viewports. Bundle size is under 20kB (16kB without special imports). Planned work includes an MCP server for AI-driven chart creation, framework-agnostic support, and a new landing page with docs.

TIL that you can connect to IPv4 addresses like 192.168.1.1 in your browser through it's decimal form: 3232235777

Browsers accept IPv4 addresses as a single decimal integer, e.g. http://192.168.1.1 equals http://3232235777. The value is computed as a1×256³ + a2×256² + a3×256 + a4, so 192×256³ + 168×256² + 1×256 + 1 = 3232235777. This works because URLs treat the integer as a valid IP host form. Example localhost: 127.0.0.1 becomes 2130706433. Post is a TIL note; no deeper limitations or practical use cases discussed.

Web Dev

2

A Practical Guide To Naming Things

A Smashing Magazine roundup of resources for naming things in design and code, arguing that names are too often too generic or too specific. Covers naming HTML/CSS classes (Classnames), colors (David Aerne's 30,355-name color repository with pickers), and layers/components via Javier Cuello's best-practice guidelines. Design token naming is addressed through Intuit's flexible multi-brand token taxonomy and Vodafone UK's Variables Taxonomy Map (brand → primitives → semantics → pages collections). Iain Bean's Component Gallery catalogs names for 50+ UI components across design systems, with Name That UI as a bonus visual dictionary. For features, Erin Gannon's guide stresses user-driven names based on jobs-to-be-done and users' own language to improve discoverability and adoption. Further tools include Romina Kavcic's design token naming guide and inventory, Onym for product naming, and a quick-reference bookmark list. Key takeaway: good names are short, meaningful, widely understood, independent of visual properties, and shared across designer/developer/user dialects to reduce confusion.

Why don't more developers 'use the platform'?

The featured post is Nolan Lawson's essay "Why Don't More Developers 'Use the Platform'?" It examines why web developers often rebuild functionality the browser already provides. Lawson, generally pro-platform, reflects on gaps that push developers toward libraries. An extensive Hacker News discussion followed the article. Commenters argued native controls and APIs are too limited or awkward to rely on. No concrete benchmarks or code are included; it is an opinion/analysis piece. Key takeaway: limited or ergonomically poor native APIs drive ecosystem churn despite platform improvements.

YouTube Channels

4

Streaming Was Only Half the Fix: Retrofitting a Stable gRPC API - Sohan Kunkerkar, Red Hat

Talk by Sohan Kunkerkar (Red Hat), presented at KubeCon + CloudNativeCon, on stabilizing the Kubernetes Container Runtime Interface (CRI), a gRPC API running on every node. Problem: CRI list operations used unary RPCs. When nodes accumulate thousands of completed/failed containers, responses exceed the gRPC receive limit, producing ResourceExhausted errors. Raising the limit only postpones failure and does not address unbounded result sets. Fix: six new streaming RPCs added to CRI and implemented in CRI-O, with UNIMPLEMENTED-based fallback to unary to support mixed-version rollout. Caveat: streaming alone was insufficient. The first implementation gathers the full result set before calling Send, so although messages are smaller on the wire, server memory stays roughly the same—HTTP/2 flow control cannot help if everything is materialized first. The talk covers why unary broke, how the rollout worked, and what pipeline streaming requires server-side.

How voice AI agents control your browser

This is a Google Cloud Tech video episode by Annie Wang explaining how a live voice AI agent (Gemini Live API + Agent Development Kit) controls a real Chrome browser. The core pattern is a screenshot → reason → act loop: the agent takes screenshots via the Chrome DevTools Protocol (CDP), reasons over them, and issues CDP commands to click and navigate. Browser actions are classified through an ADK tool callback as either async or synchronous. Slow, consequential actions (e.g., clicks) run asynchronously in the background so the voice conversation isn't blocked; results are observed via the next screenshot. Read operations stay synchronous when the model needs their returned data to decide the next step. Consequential actions require server-side human confirmation as a guardrail. A follow-up episode covers long-term agent memory; links to Gemini Live API docs, CP command references, and demo code are provided.

grpcgi: Enabling Universal Web Serving, Native mTLS, and xDS on the gRPC Mesh - Mehrdad Afshari

Talk by Mehrdad Afshari (Signeen Inc.), presented at a CNCF/KubeCon event: "grpcgi: Enabling Universal Web Serving, Native mTLS, and xDS on the gRPC Mesh."

Problem addressed: Traditional web applications use HTTP and act as opaque backends within gRPC/xDS service meshes. They lack native access to SPIFFE identity, mTLS, xDS routing, and advanced load balancing.

Approach: grpcgi inverts the transport layer. Envoy communicates via gRPC to an in-process server that translates gRPC calls into the application's native interface (e.g., ASGI for Python, Rack for Ruby). This lets unmodified web applications operate over gRPC and directly inherit the service mesh's security and routing infrastructure without code modifications.

Technical details covered in the talk: the language-neutral bridge protocol, Envoy-side translation implemented via proxy-wasm and a native C++ filter, and the implications of converting web applications—including AI inference servers—into first-class gRPC upstreams. The session includes a live demonstration of an unmodified web application and a WebSocket echo server served via gRPC through Envoy with xDS and mTLS.

Limitations: the summary is based on the talk description only; no performance figures, maturity/status of the project, or production adoption details are provided in the source content.

Scaling agentic coding practices across your team

A Google Cloud Tech video (Annie Wang, Tilde Thurium) explains scaling agentic coding across teams using markdown spec files. DESIGN.md defines visual guardrails, design systems, and styling tokens; AGENTS.md provides global project guidance, coding standards, and build/test instructions; SKILL.md captures reusable domain-specific tasks and workflows. The talk contrasts agent specifications with prompt/context engineering and cites benchmark data on token savings and performance gains from AGENTS.md. Best practices include separation of concerns and splitting shared team rules (project layer) from personal developer preferences (user layer). Real-world examples include Google ADK and DeepMind's Simply repository.

Medium

4

Prompt Tokens Aren’t ROI: How to Measure a Copilot Studio Agent

The post argues prompt token volume is a poor ROI metric for Copilot Studio agents, proposing deflection rate and API cost avoidance as the meaningful measures. It outlines a claims-processing architecture combining Copilot Studio with Dynamics 365. Three finance-oriented test scenarios are used to validate the approach. A worked example demonstrates how deflection and cost-avoidance figures translate into return. Full methodology and calculations are behind the linked Stackademic article.

What Claude Code Keeps of Your Skills After Compaction

A post examining what Claude Code preserves when context is compacted. Compaction leaves a roughly 5,000-token snapshot of prior work. A shared budget of about 25,000 tokens is available for restored context. The skill index reportedly does not survive compaction, meaning skills may not be reloaded. The piece covers the underlying mechanics and resulting failure modes. Key takeaway: compaction can silently drop skill awareness, degrading agent behavior after long sessions.

Three Things to Freeze Before an Agent Replay Test Means Anything

The post argues agent replay tests are only meaningful if you freeze three sources of nondeterminism: tool responses, the clock and generated IDs, and the input world. With those frozen, replays become reproducible and comparable across runs. Assertions should target the agent's effect plan (calls/actions taken) rather than its prose output. Without these freezes, agent regression tests are unreliable.

OpenAI Prompt Caching: How 20 Suffix Tokens Burned Our Codex Quota

A team found that modifying a ~20-token suffix in a 15,000-token prompt caused OpenAI prompt caching to return zero cached tokens, wiping out their Codex quota. OpenAI's prompt caching uses automatic prefix caching with cache breakpoints, so any change to the end of the prompt invalidates the entire cached prefix. The key takeaway: keep prompt suffixes stable and put volatile content early or avoid appending changing tokens to preserve cache hits.

Releases

4

v8.0.0-rc.14-dev.21: TML-3287: Raw SQL ending in a line comment renders valid DDL (#30546)

Raw SQL bodies ending in a -- line comment previously produced invalid DDL: the planner interpolated them into larger statements, so the comment swallowed the rest of the line (e.g. the closing paren of CHECK (...)). Fix: a typed OpaqueSql AST node for unparsed SQL text, with a single renderOpaqueSql function that appends a trailing line break when the text contains --; renderers for CHECK constraints, policies, indexes, column defaults, and ALTER COLUMN TYPE USING all go through it. Bodies without -- render byte-identical, so no existing statements change. Wire names (hashes of normalized SQL) now keep one line break per line when the body contains --, since a break ends a comment and is semantically meaningful; other whitespace is still collapsed, and all existing names are unchanged. Bodies with both a comment and a line break get a new object name once; the next migration plan drops and recreates the object. Committed contract-free migration factories (fn, checkExpression, etc.) still accept strings for compatibility; extension authors now construct nodes via opaqueSql(text). Rationale: stripping comments was rejected because Prisma doesn't parse SQL (can't distinguish -- in string literals), and duplicating the newline rule across render templates was error-prone. Covered by integration tests on PGlite/SQLite plus naming and rendering tests; three tarball tests couldn't run locally and are left to CI.

v8.0.0-rc.14-dev.20: Hover shows declarations and /// documentation in PSL files (#30569)

Prisma v8.0.0-rc.14-dev.20 (#30569) adds hover support to the Prisma language server: hovering a name in a .prisma (PSL) file now shows a prisma code snippet of the declaration plus any /// doc comment above it.

What hover shows per token type: models, composite types, fields, named types, and blocks show their declaration line and /// doc comment at both the declaration and any reference (including cross-file). Model/field attributes (@relation, @@index) show their signature — the same one signature help uses — followed by documentation. Contributed types (pg.Varchar) show documentation, or their signature like pg.Varchar(length: number) when no docs exist. Block keywords (policy) show documentation or nothing. Namespaces, cross-space references, and unresolved names show nothing.

Implementation: hover reads the binder's resolution for the token under the cursor, so it describes the same symbol diagnostics use. The psl-parser binder now records each declaration's symbol on its name node (models, composite types, fields, named types, blocks; not namespaces), so hovering "User" in "model User {" and in a reference like "author User" use the same lookup; existing symbolForNode callers only query reference positions, so are unaffected. create-binder tests for SQL/Mongo list all resolutions in sample schemas, so expected lists now include declaration-name entries. The attribute signature label rendering was extracted from signature help, whose behavior and tests are unchanged. /// doc comments: a doc comment is a run of /// lines directly above a declaration, ending at a blank line or a plain // comment. A docComment() method (via a HasDocComment interface) was added to AST classes that can carry one; parsing is unchanged since the comment is read on method call. Only the language server consumes it for now — the symbol table, binder symbols, and contract do not carry documentation.

Limitations / not included: hover on argument keys (references:), function names (autoincrement), constants (Cascade), and block attributes — these need new binder symbols and are deferred to the next slice; full manual QA of the hover table is planned for that slice once all hover kinds exist.

Verification: typecheck/test/lint pass for @internal/psl-parser (1233 tests) and @internal/language-server (827 tests); pnpm lint:deps passes. In pnpm test:packages, three packaging tarball tests fail with ERR_PNPM_TRUST_DOWNGRADE during live pnpm install — unrelated to this change. Tests: hover.test.ts covers all hover cases; psl-parser/test/syntax/doc-comment.test.ts covers docComment() per class and /// run termination; server.test.ts asserts hoverProvider: true and routes one hover request through the server. Signature help now also identifies parameter labels more precisely, including positional parameters.

v8.0.0-rc.17-dev.5: Rename symbol in the PSL language server (#30633)

The PSL language server (v8.0.0-rc.17-dev.5, PR #30633) adds LSP rename support for models, composite types, named types, blocks, fields, and namespaces. provideRename reuses find-references (with declaration included) to build a single WorkspaceEdit, so edits exactly match go-to-definition targets; prepareRename returns the identifier range or null. Renaming a model or field can also insert @map/@@map with the old name so database table/column names stay unchanged; map insertion depends on project attribute specs and a new nameIsStorageName block-descriptor flag (used by Postgres native enums). Invalid new names are rejected before edits; there is no collision check, so renaming to an existing name can merge symbol identities (accepted behavior matching TypeScript/Prisma 7). Known gaps: native_enum usages inside pg.enum(...) and enum members aren't renamed (binder lacks resolutions), and names without map attributes (namespaces, composite type members, roles/policies) are renamed by name only. Playground opens unopened scratch files before applying multi-file edits, and file selection now reads the editor's model so rename-modified text isn't reverted. Tests cover all symbol kinds, capabilities, and error responses; VS Code manual checks are still pending.

v8.0.0-rc.14-dev.33: Go to definition in the PSL language server (#30578)

Prisma v8.0.0-rc.14-dev.33 adds textDocument/definition (go-to-definition) to the PSL language server (#30578). The binder now resolves the qualifier of qualified type references (ns.Name) separately, as namespace or contributedNamespace, with no new diagnostics; cross-space references get no qualifier resolution. The server finds the token at the cursor, walks up to the nearest binder-resolved node, and returns that symbol's declaration nodes; namespaces return one target per namespace block. Responses are LocationLink[] when the client declares linkSupport, otherwise Location[]. Definition works for type references, qualifiers, fieldRef/referencedFieldRef/entityRef attribute arguments, and entityRef in block values, including cross-file targets. A cursor on a declaration's own name, contributed types, or unresolved names returns null; between adjacent tokens the right identifier is preferred. The LSP playground switches editor/sidebar to the target file via monaco-languageclient's openEditorFunc hook, preserving lazy didOpen. Semantic tokens now classify qualifiers from binder resolution, so cross-space qualifiers and dotted function-call qualifiers lose the namespace token; follow-up: find references.