<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    
    <title>Raymond P. Burkholder - Things I Do</title>
    <link>https://blog.raymond.burkholder.net/</link>
    <description>In And Around Technology and The Arts</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.7.2 - http://www.s9y.org/</generator>
    <pubDate>Fri, 14 Aug 2026 04:08:18 GMT</pubDate>

    <image>
        <url>https://blog.raymond.burkholder.net/templates/bulletproof/img/s9y_banner_small.png</url>
        <title>RSS: Raymond P. Burkholder - Things I Do - In And Around Technology and The Arts</title>
        <link>https://blog.raymond.burkholder.net/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Meshlib: In-Process Policy Enforcement for Sidecar-less Service Meshes</title>
    <link>https://blog.raymond.burkholder.net/index.php?/archives/1366-Meshlib-In-Process-Policy-Enforcement-for-Sidecar-less-Service-Meshes.html</link>
            <category>Virtualization</category>
    
    <comments>https://blog.raymond.burkholder.net/index.php?/archives/1366-Meshlib-In-Process-Policy-Enforcement-for-Sidecar-less-Service-Meshes.html#comments</comments>
    <wfw:comment>https://blog.raymond.burkholder.net/wfwcomment.php?cid=1366</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.raymond.burkholder.net/rss.php?version=2.0&amp;type=comments&amp;cid=1366</wfw:commentRss>
    

    <author>nospam@example.com (Raymond P. Burkholder)</author>
    <content:encoded>
    &lt;p&gt;&lt;a href=&quot;https://arxiv.org/abs/2608.13107&quot; target=_blank&gt;Meshlib: In-Process Policy Enforcement for Sidecar-less Service Meshes&lt;/a&gt;
&lt;blockquote&gt;Service meshes facilitate service-to-service communication and enforce
security policies in microservice architectures. However, they often depend on
per-pod sidecar proxies, which introduce significant latency and resource
overhead due to redundant application-layer parsing on every request.
Eliminating sidecars without compromising security guarantees remains a central
challenge. To address this, we introduce Meshlib, a sidecar-less service mesh
extension built on Cilium as a control-plane extension. Meshlib incorporates a
non-intrusive application-bound library that enforces Layer-7 policies within
the application process, while delegating transport-level identity and routing
to Cilium&#039;s eBPF-based data plane. This separation of responsibilities removes
sidecar-induced latency and maintains the security semantics of the service
mesh. The architecture remains fully interoperable with unmodified services,
enabling incremental adoption within existing deployments. We evaluate Meshlib
against Istio, Linkerd, and unmodified Cilium on the TrainTicket benchmark,
enforcing 126 security policies across 37 services and show that it achieves
the lowest end-to-end latency of all evaluated configurations with comparable
resource overhead.
&lt;/blockquote&gt; 
    </content:encoded>

    <pubDate>Fri, 14 Aug 2026 04:08:18 +0000</pubDate>
    <guid isPermaLink="false">https://blog.raymond.burkholder.net/index.php?/archives/1366-guid.html</guid>
    
</item>
<item>
    <title>NUT USB APC BeagleBone</title>
    <link>https://blog.raymond.burkholder.net/index.php?/archives/1360-NUT-USB-APC-BeagleBone.html</link>
            <category>Debian</category>
    
    <comments>https://blog.raymond.burkholder.net/index.php?/archives/1360-NUT-USB-APC-BeagleBone.html#comments</comments>
    <wfw:comment>https://blog.raymond.burkholder.net/wfwcomment.php?cid=1360</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.raymond.burkholder.net/rss.php?version=2.0&amp;type=comments&amp;cid=1360</wfw:commentRss>
    

    <author>nospam@example.com (Raymond P. Burkholder)</author>
    <content:encoded>
    &lt;p&gt;I have an APC Smart UPS 1500 connected via USB cable to a BeagleBone Green running NUT 2.8.1-5 on Linux 6.18.36-bone40.  Even on earlier Linux kernels and versions of NUT, during some sort of UPS transition, I would start to get a log full of the these error messages:

&lt;blockquote&gt;&lt;pre&gt;
usbhid-ups: nut_libusb_get_report: No such device (it may have been disconnected)
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;In detail:

&lt;blockquote&gt;&lt;pre&gt;
kernel: musb-hdrc musb-hdrc.1: Babble
kernel: usb 1-1: USB disconnect, device number 15
kernel: usb 1-1.4: USB disconnect, device number 16
kernel: usb 1-1: new high-speed USB device number 17 using musb-hdrc
kernel: usb 1-1: New USB device found, idVendor=1a40, idProduct=0201, bcdDevice= 1.00
kernel: usb 1-1: New USB device strings: Mfr=0, Product=1, SerialNumber=0
kernel: usb 1-1: Product: USB 2.0 Hub [MTT]
kernel: hub 1-1:1.0: USB hub found
kernel: hub 1-1:1.0: 7 ports detected
kernel: usb 1-1.4: new full-speed USB device number 18 using musb-hdrc
kernel: usb 1-1.4: New USB device found, idVendor=051d, idProduct=0003, bcdDevice= 0.01
kernel: usb 1-1.4: New USB device strings: Mfr=1, Product=2, SerialNumber=3
kernel: usb 1-1.4: Product: Smart-UPS_1500 FW:UPS 06.0 / ID=1028
kernel: usb 1-1.4: Manufacturer: American Power Conversion
kernel: usb 1-1.4: SerialNumber: unique_number
kernel: hid-generic 0003:051D:0003.0008: hiddev0,hidraw0: USB HID v1.11 Device [American Power Conversion  Smart-UPS_1500 FW:UPS 06.0 / ID=1028] on usb-musb-hdrc.1-1.4/input0
usbhid-ups[31894]: nut_libusb_get_report: No such device (it may have been disconnected)
usbhid-ups[31894]: nut_libusb_get_report: No such device (it may have been disconnected)
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;For some reason, USB devices &#039;disconnect&#039; and reconnect.  When the device reconnects, a new DeviceID is assigned to the USB device.  This breaks the usbhid-ups drivers supplied by NUT the packages.  That is, usbhid-ups no longer sees the APC USB device.

&lt;p&gt;One forum article suggested that there is not enough power in the BeagleBone system to propery power a USB connection.  The suggested solution is to add a powered USB hub.  I gave that a try with no success in eliminating the problem.

&lt;p&gt; To resolve this, I&#039;m not sure if recent versions of the driver fix this, but I used Debian&#039;s udev system to sense the device id change and to restart the NUT USB driver.

&lt;p&gt;In /home/debian, which is the default home directory, I created two files and ran &#039;chmod +x&#039; on each to make them executable.  When a USB &#039;ADD&#039; state is detected, nut.target is restarted to initiate the detection and connection process.  When a removal is detected, the service is stopped.  The stop does not seem to be reliable, but the restart appears to be reliable enough to get things started again.

&lt;blockquote&gt;&lt;pre&gt;
$ cat usb_add.sh
#!/usr/bin/env bash

logger &quot;USB state change detected: $1 $2 $3&quot;
echo &quot;$(date) USB state change detected: $1 $2 $3&quot; &gt;&gt; /home/debian/usb-log.txt
systemctl restart nut.target
exit 0
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;blockquote&gt;&lt;pre&gt;
$ cat usb_remove.sh
#!/usr/bin/env bash

logger &quot;USB state change detected: $1 $2&quot;
echo &quot;$(date) USB state change detected: $1 $2&quot; &gt;&gt; /home/debian/usb-log.txt
#systemctl stop nut.target
exit 0
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;To determine useful attributes I used the following (the first is a shorter result than the second):

&lt;blockquote&gt;&lt;pre&gt;
udevadm info --name=/dev/bus/usb/001/017 
udevadm info --name=/dev/bus/usb/001/017 --attribute-walk
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;The rule which invokes these scripts is:

&lt;blockquote&gt;&lt;pre&gt;
# cat  /etc/udev/rules.d/89-usb-ups-change.rules
SUBSYSTEM==&quot;usb&quot;, MODE=&quot;0660&quot;, ACTION==&quot;add&quot;,    ENV{ID_VENDOR_ID}==&quot;051d&quot;, ENV{ID_MODEL_ID}==&quot;0003&quot;, RUN+=&quot;/home/debian/usb_add.sh add &#039;$env{DEVNAME}&#039; &#039;$env{ID_USB_SERIAL}&#039;&quot;
SUBSYSTEM==&quot;usb&quot;, MODE=&quot;0660&quot;, ACTION==&quot;remove&quot;, RUN+=&quot;/home/debian/usb_remove.sh remove $env{DEVNAME}&quot;
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;These command variations were suggested to simulate a cable re-connect but did not reliably work.  I resorted to physically disconnecting and reconnecting the cable to perform a proper test for tuning and production (using the major:minor usb device manufacturer code):

&lt;blockquote&gt;&lt;pre&gt;
# major:minor usb device manufacturer code
usbreset 051d:0003
# dev bus id
udevadm test /dev/bus/usb/001/007
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;Each rule change test required the following to reload the udev rules:

&lt;blockquote&gt;&lt;pre&gt;
udevadm control --reload-rules
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;To see what Nut sees:

&lt;blockquote&gt;&lt;pre&gt;
# nut-scanner -U
Scanning USB bus.
[nutdev1]
        driver = &quot;apc_modbus&quot;
        port = &quot;auto&quot;
        vendorid = &quot;051D&quot;
        productid = &quot;0003&quot;
        product = &quot;Smart-UPS_1500 FW:UPS 06.0 / ID=1028&quot;
        serial = &quot;unique id&quot;
        vendor = &quot;American Power Conversion&quot;
        bus = &quot;001&quot;
        device = &quot;017&quot;
        busport = &quot;002&quot;
        ###NOTMATCHED-YET###bcdDevice = &quot;0001&quot;
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;A linux command provides a concise device and manufacturer id:

&lt;blockquote&gt;&lt;pre&gt;
# lsusb
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Bus 001 Device 016: ID 050d:0234 Belkin Components F5U234 USB 2.0 4-Port Hub
Bus 001 Device 017: ID 051d:0003 American Power Conversion UPS
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;Other troubleshooting commands include:

&lt;blockquote&gt;&lt;pre&gt;
udevadm monitor
&lt;/pre&gt;&lt;blockquote&gt;

&lt;p&gt;This solution for those who might encounter &lt;a href=&quot;https://github.com/networkupstools/nut/issues/3385&quot; target=_blank&gt;Update 2.7.4 to 2.8.4 CP UPS driver disconnect (nut_libusb_get_report: No such device)&lt;/a&gt; 
    </content:encoded>

    <pubDate>Sun, 28 Jun 2026 01:10:00 +0000</pubDate>
    <guid isPermaLink="false">https://blog.raymond.burkholder.net/index.php?/archives/1360-guid.html</guid>
    
</item>
<item>
    <title>SONiC Virtual Switch</title>
    <link>https://blog.raymond.burkholder.net/index.php?/archives/1365-SONiC-Virtual-Switch.html</link>
            <category>Networks</category>
    
    <comments>https://blog.raymond.burkholder.net/index.php?/archives/1365-SONiC-Virtual-Switch.html#comments</comments>
    <wfw:comment>https://blog.raymond.burkholder.net/wfwcomment.php?cid=1365</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.raymond.burkholder.net/rss.php?version=2.0&amp;type=comments&amp;cid=1365</wfw:commentRss>
    

    <author>nospam@example.com (Raymond P. Burkholder)</author>
    <content:encoded>
    &lt;p&gt;I&#039;ve been hearing more and more about the &lt;a href=&quot;https://sonicfoundation.dev/&quot; target=_blank&gt;SONiC Virtual Switch&lt;/a&gt;.  It has come a long way since it&#039;s debut at an &lt;a href=&quot;https://www.opencompute.org/&quot; target=_blank&gt;Open Compute&lt;/a&gt; conference some number of years ago.

&lt;p&gt;To give it a try on non-ONIE hardware (nothing handy at the moment), this is what I did to get the .vs image working on my local Proxmox box:

&lt;ul&gt;
  &lt;li&gt;Download recent sonic-vs.img.gz version from &lt;a href=&quot;https://sonic.software/&quot; target=_blank&gt;Sonic Software&lt;/a&gt;
  &lt;li&gt;scp the image over onto my Proxmox box
  &lt;li&gt;gunzip the image&lt;pre&gt;gunzip sonic-vs.img.gz&lt;/pre&gt;
  &lt;li&gt;construct a virtual machine with: 4 cpu, 4G memory, q35, SeaBIOS, no-cd, no drive
  &lt;li&gt;assign an interface which supplies DHCP
  &lt;li&gt;import the disk into the vm (this one has vmid of 116) &lt;pre&gt;qm disk import 116 sonic-vs.img local-btrfs --target-disk ide0&lt;/pre&gt;
  &lt;li&gt;in options, set boot order to ide0, disable pxe and cd
  &lt;li&gt;start it up, and log in with the credentials supplied at the download site
  &lt;li&gt;once I confirmed it had an address, I was able to ssh with: &lt;pre&gt;ssh admin@&amp;lt;ipaddr&amp;gt; -o PreferredAuthentications=password&lt;/pre&gt;
  &lt;/ul&gt;

&lt;p&gt;Add additional instances to build infrastructure.  Add interfaces to build a network. 
    </content:encoded>

    <pubDate>Wed, 22 Jul 2026 03:54:08 +0000</pubDate>
    <guid isPermaLink="false">https://blog.raymond.burkholder.net/index.php?/archives/1365-guid.html</guid>
    
</item>
<item>
    <title>Drogon - Not SSL Ready</title>
    <link>https://blog.raymond.burkholder.net/index.php?/archives/1364-Drogon-Not-SSL-Ready.html</link>
            <category>C++</category>
    
    <comments>https://blog.raymond.burkholder.net/index.php?/archives/1364-Drogon-Not-SSL-Ready.html#comments</comments>
    <wfw:comment>https://blog.raymond.burkholder.net/wfwcomment.php?cid=1364</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.raymond.burkholder.net/rss.php?version=2.0&amp;type=comments&amp;cid=1364</wfw:commentRss>
    

    <author>nospam@example.com (Raymond P. Burkholder)</author>
    <content:encoded>
    &lt;p&gt;I did some experimenting with &lt;a href=&quot;https://github.com/drogonframework/drogon&quot; target=_blank&gt;drogon&lt;/a&gt; to port over a web site I had implemented in &lt;a href=&quot;https://github.com/emweb/wt&quot; target=_blank&gt;Wt webtoolkit&lt;/a&gt; web tool.

&lt;p&gt;The views, controls, and static presentations performed well for building a web site in a traditional way.

&lt;p&gt;However, when it came time to assign a domain name and run an SSL certificate based website, it started failing/crashing when certain SSL incompatible web queries were generated.  It didn&#039;t have a recoverable failure mode.  It simply raised an exception and crashed.  I looked at the crash locations, and it seems that some clean up operations are mis-ordered, plus there were other problems.  Then reading the issues list, the author even acknowledges that the whole SSL thing was a bolt-on after-thought and requires significant re-write.

&lt;p&gt;Sigh.  Drogon is out the window.

&lt;p&gt;On to giving &lt;a href=&quot;https://www.boost.org/library/latest/beast/&quot; target=_blank&gt;Boost Beast&lt;/a&gt; a try.  This will require some work to add cookies and other refinements, but at least it is well integrated with SSL. 
    </content:encoded>

    <pubDate>Wed, 22 Jul 2026 03:45:10 +0000</pubDate>
    <guid isPermaLink="false">https://blog.raymond.burkholder.net/index.php?/archives/1364-guid.html</guid>
    
</item>
<item>
    <title>Drogon Install</title>
    <link>https://blog.raymond.burkholder.net/index.php?/archives/1363-Drogon-Install.html</link>
            <category>C++</category>
    
    <comments>https://blog.raymond.burkholder.net/index.php?/archives/1363-Drogon-Install.html#comments</comments>
    <wfw:comment>https://blog.raymond.burkholder.net/wfwcomment.php?cid=1363</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.raymond.burkholder.net/rss.php?version=2.0&amp;type=comments&amp;cid=1363</wfw:commentRss>
    

    <author>nospam@example.com (Raymond P. Burkholder)</author>
    <content:encoded>
    &lt;p&gt;&lt;a href=&quot;https://drogon.org/&quot; target=_blank&gt;drogon&lt;/a&gt; is a fast C++ web framework.

&lt;p&gt;Some build notes:

&lt;blockquote&gt;&lt;pre&gt;
sudo apt install git cmake build-essential
sudo apt install libjsoncpp-dev uuid-dev zlib1g-dev libsqlite3-dev  \
  libc-ares-dev dia libyaml-cpp-dev libssl-dev libbrotli-dev
git clone https://github.com/drogonframework/drogon
cd drogon
git submodule update --init
mkdir build
cd build
cmake ..
make
sudo make install
&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;Create a project:

&lt;blockquote&gt;&lt;pre&gt;
drogon_ctl create project project_name
cd project_name/build
cmake ..
make
cd ..
# run project, default port is 5555
build/project_name

&lt;/pre&gt;&lt;/blockquote&gt;



 &lt;br /&gt;&lt;a href=&quot;https://blog.raymond.burkholder.net/index.php?/archives/1363-Drogon-Install.html#extended&quot;&gt;Continue reading &quot;Drogon Install&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 09 Jul 2026 01:42:08 +0000</pubDate>
    <guid isPermaLink="false">https://blog.raymond.burkholder.net/index.php?/archives/1363-guid.html</guid>
    
</item>
<item>
    <title>Today's Machine Learning</title>
    <link>https://blog.raymond.burkholder.net/index.php?/archives/1362-Todays-Machine-Learning.html</link>
            <category>Machine Learning</category>
    
    <comments>https://blog.raymond.burkholder.net/index.php?/archives/1362-Todays-Machine-Learning.html#comments</comments>
    <wfw:comment>https://blog.raymond.burkholder.net/wfwcomment.php?cid=1362</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.raymond.burkholder.net/rss.php?version=2.0&amp;type=comments&amp;cid=1362</wfw:commentRss>
    

    <author>nospam@example.com (Raymond P. Burkholder)</author>
    <content:encoded>
    &lt;p&gt;&lt;a href=&quot;https://arxiv.org/abs/2607.02046&quot; target=_blank&gt;Fast and Accurate Anomaly Detection in Time Series&lt;/a&gt; - is this the cat&#039;s meow?

&lt;blockquote&gt;
&lt;p&gt;&lt;Anomaly detection is a critical and evolving field in Machine Learning, with
applications targeting different domains such as cybersecurity, finance,
healthcare, manufacturing and IoT (Internet of Things) systems. Traditionally,
anomaly detection algorithms have been designed using both supervised and
unsupervised learning paradigms. 
&lt;p&gt;The fundamental challenge in real-world
anomaly detection scenarios is related to the inherent class imbalance
(anomalies are typically rare) and, for supervised methods, to the scarcity of
labelled anomalous data. Indeed, labelling is both expensive and
time-consuming. Conversely unsupervised methods do not require labelling, but
may suffer from high false positive rates when deployed in safety-critical
applications. 
&lt;p&gt;In this work we introduce a novel unsupervised algorithm for
anomaly detection in time series based on the Haar discrete wavelet and a
suitably designed $t$-test. We establish the theoretical foundation of the
proposed $t$-test and, through extensive experimentation across 343 datasets,
demonstrate that our algorithm outperforms state-of-the-art unsupervised and
self-supervised benchmarks.
&lt;/blockquote&gt; 
    </content:encoded>

    <pubDate>Fri, 03 Jul 2026 02:44:33 +0000</pubDate>
    <guid isPermaLink="false">https://blog.raymond.burkholder.net/index.php?/archives/1362-guid.html</guid>
    
</item>
<item>
    <title>Weekend Reading</title>
    <link>https://blog.raymond.burkholder.net/index.php?/archives/1361-Weekend-Reading.html</link>
            <category>Technology</category>
    
    <comments>https://blog.raymond.burkholder.net/index.php?/archives/1361-Weekend-Reading.html#comments</comments>
    <wfw:comment>https://blog.raymond.burkholder.net/wfwcomment.php?cid=1361</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.raymond.burkholder.net/rss.php?version=2.0&amp;type=comments&amp;cid=1361</wfw:commentRss>
    

    <author>nospam@example.com (Raymond P. Burkholder)</author>
    <content:encoded>
    &lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://grep.be/blog//en/computer/Agentic_coding_and_Free_Software/&quot; target=_blank&gt;Agentic coding and Free Software&lt;/a&gt; - getting started with LLMs with WindSurf
  &lt;li&gt;&lt;a href=&quot;https://gwolf.org/2026/06/systemd-for-linux-sysadmins.html&quot; target=_blank&gt;systemd for Linux SysAdmins&lt;/a&gt; - there is a book out about systemd - history and usage
  &lt;li&gt;&lt;a href=&quot;https://abbbi.github.io//sync/&quot; target=_blank&gt;vmsync&lt;/a&gt; - released &lt;a href=&quot;https://github.com/abbbi/vmsync&quot; target=_blank&gt;vmsync&lt;/a&gt;. A small golang utility that implements a simple replication tool using the NBD protocol to sync virtual machines to other hosts.
  &lt;/ul&gt; 
    </content:encoded>

    <pubDate>Sun, 28 Jun 2026 18:15:12 +0000</pubDate>
    <guid isPermaLink="false">https://blog.raymond.burkholder.net/index.php?/archives/1361-guid.html</guid>
    
</item>

</channel>
</rss>
