Skip to content

Nalar / independent articles for builders

Think clearly.
Build better.

A place to share practical knowledge and experience in programming and technology, with useful resources for software development, technology innovation, and real-world engineering problems.

About this space 01

Practical writing about software, systems, and the small details that make products feel solid.

01 / Latest

Fresh from the notebook

Artificial Intelligence 04 Oct 2026 4 min read

Temperature Scaling Adjusts Confidence Without Changing Class Order

A classifier can rank classes correctly while assigning probabilities that are too sharp or too flat. Temperature scaling addresses that mismatch with a deliberately narrow transformation: divide every logit for an example by one positive scalar before softmax. For logits z_k and temperature T > 0, the calibrated probability is p_k(T) = exp(z_k / T) / sum_j exp(z_j / T) The scalar is usually fitted on held-out data after the model parameters are fixed. This separation matters because temperature scaling changes reported confidence, not the representation or decision boundary produced during training.

Linux 04 Oct 2026 4 min read

SO_REUSEPORT Splits One Listen Address Across Multiple Linux Sockets

A conventional server owns one listening socket for a local address and port. SO_REUSEPORT changes that ownership boundary: multiple eligible sockets can bind the same address, and Linux selects a member of the reuseport group when traffic arrives. The option is useful when several worker threads or processes should receive traffic without sharing one accept or receive queue. It changes kernel-side socket selection, not the transport protocol carried on the network.

Artificial Intelligence 04 Oct 2026 4 min read

RoPE Position Indices Must Ignore Padding Tokens

Rotary position embeddings encode token position by rotating query and key coordinates with an angle determined by an integer position index. That index is part of the model input semantics even when it is generated inside a framework wrapper. In a padded decoder batch, using the physical tensor column as the position can therefore change logits for a sequence that has not changed textually. The issue is distinct from attention masking. A mask can stop valid tokens from attending to padding while the valid tokens still receive shifted rotary coordinates. Correct masking and correct position assignment solve separate problems.

Cybersecurity 04 Oct 2026 6 min read

fs-verity Verifies Read-Only Files as They Are Read

fs-verity Verifies Read-Only Files as They Are Read A conventional file hash is often checked before a file is trusted. Linux fs-verity moves part of that integrity work into the filesystem. Once verity is enabled for a regular file on a supporting filesystem, the file becomes read-only and its data is checked against a persisted Merkle tree as data is read. The mechanism has a deliberately narrow boundary. fs-verity can detect data that no longer matches the digest enforced for a verity file. Authenticating that digest against a trusted identity or release policy is a separate decision. The distinction prevents an integrity primitive from being mistaken for a complete software-trust policy.

Linux 03 Oct 2026 5 min read

SO_BUSY_POLL Trades CPU Time for Earlier Linux Socket Receive Processing

A blocking receive on Linux normally sleeps when no data is ready and resumes after the networking path makes data available. With SO_BUSY_POLL, the receive path may instead spend a bounded interval actively polling the relevant NAPI context for incoming packets. That interval exchanges CPU time for a chance to process an arrival before the ordinary interrupt-driven path wakes the task. The option does not turn a socket into a permanently polling endpoint. It supplies a busy-poll budget in microseconds, and the mechanism depends on receive history and network-device support.

Cybersecurity 03 Oct 2026 7 min read

Landlock Adds Unprivileged Restrictions to Linux Process Authority

Landlock Adds Unprivileged Restrictions to Linux Process Authority A Linux process normally receives authority from credentials, filesystem permissions, namespaces, capabilities, open descriptors, and system-wide security policy. Landlock adds a different control point: a process can voluntarily restrict its own future access, even without administrative privilege. The resulting policy is additive. It narrows what the process may do without granting access that another security mechanism would deny. That property makes Landlock useful as an application-confinement layer. It also sets a precise boundary around the mechanism. Landlock is not a replacement for discretionary access control, other Linux Security Modules, seccomp, namespaces, or careful descriptor management. It composes with those controls.

02 / Topics

Find your next rabbit hole

View all topics

03 / Tools

Small tools, useful moments

See all tools