← All writing
Tag

Software Engineering.

21 posts ·RSS

Latest
Software Engineering · 23 Sept 2026 · 13 min read

Just say nono.

nono gets pitched at coding agents, so most people meet it as a CLI. The SDKs are often overlooked: they let any application that spawns code it doesn't trust apply a kernel-enforced capability sandbox to itself or a child. The integration shapes, what each costs, and when nono is the wrong tool.

Read the article →
All writing
Open Source · 20 Sept 2026 · 5 min

Relay: An Open-Source Control Plane for DBOS Applications

DBOS Transact delivers lightweight durable execution, but upstream coordination relies on a proprietary control plane. Relay is a clean-room, open-source Conductor alternative with multi-SDK wire compatibility, dual-engine storage scaling from embedded SQLite to clustered PostgreSQL, and zero cloud lock-in.

Software Engineering · 09 Sept 2026 · 8 min

A facade for MCP tools

I wrote this a year ago arguing that the model shouldn't be composing four MCP tools when one function could. Since then Cloudflare and Anthropic shipped code mode, which solves most of what I was complaining about. This is the revision, mostly about the part it doesn't solve.

GNOME · 06 Sept 2026 · 5 min

A drop-down Ghostty on GNOME

Notes from building a GNOME Extension to get Ghostty's quick terminal "working" on Mutter.

Security · 31 Aug 2026 · 14 min

The Root CORS Analysis

A field guide for server-side engineers: the levers, the trade-offs, and how to decide what is actually worth doing when it comes to Cross-Origin Resource Sharing (CORS).

Software Engineering · 19 Aug 2026 · 9 min

Demystifying Auto-Mode: Intent Classifiers, Kernel Sandboxing, and the Frontier of Autonomous Agent Guardrails

Automating agent permissions solves "permission fatigue" but risks security. This analysis explores decoupled intent classifiers like Auto Mode, defense-in-depth via sandboxing, and emerging local guardrails like Shieldstral and AgentWorld.

Agents · 17 Aug 2026 · 10 min

Zero-G, Zero-Prompts: Lifting the Heavy Burden of Permission Fatigue in Google Antigravity

How a decoupled security gate brings auto-mode intelligence and static policy control to Google Antigravity 2.0 without sacrificing user agency.