Yesterday’s page held two stories above 200 points and this roundup said the thinness was the news. Today the same window holds fifty-five, and eleven of them were absent from the last five roundups. The page unfroze.

The top has not: When did Google get so weird? is on its fifth day at number one with 2,009 points, up 7, which is a strange thing for a story to do. Behind it, Pi 1.0 added 869 points in a day and Court agrees with EFF added 459, both of which are the same submission earning attention rather than new submissions.

Fifty-nine stories cleared 200 points between the top-200 rank window and the 44-hour search sweep. Ten get full sections below; the rest of the movers are in “Still on the page.” Scores were captured at 13:20 PDT.

Extra Big Ass Intelligence — 468 points

468 points · 110 comments · extrabigassintelligence.com · HN discussion

A single satirical web page with an “AI” running loose on it. The gags are written in the register of a late-night infomercial cut with Idiocracy: “HOT SINGLE MODEL — Local 35B Parameter Model Wants To Chat In Your Area,” a “CONGRESS — Congress Discovers One Weird Trick To Fix The Economy” card, “BIG PHARMA — Is Your AI Too Depressed? Try Subsidized Dopamine Injections!”, a Brawndo ad for the electrolytes, counters for TERAFLOPS WASTED TODAY and LIFETIMES OF REGRET ACCUMULATED, and an Execute (if you must) button. The footer disclaims responsibility for “physical harm, loss of ego, or existential dread,” and notes that words are harmless and your reaction is your problem.

The infrastructure behind it is the actual story. The author turned up in the thread to explain: he had GLM-5.3 in OpenCode build the site “while I drank Guinness 3 through 8,” posted it before bed expecting a few people to enjoy it, and woke up to roughly 250,000 requests and a brief stint at number one. It runs on two RTX 4060 Ti cards in his own PC, serving an abliterated Qwen3.6 35B (qwen3.6-35b-a3b-uncensored-hauhaucs-aggressive), and by mid-afternoon he was at 76% of his daily free quota for Cloudflare Workers. Total budget: the $10 the domain cost. No monetization has been attempted or will be.

Two things are worth taking seriously here. The first is the engineering datapoint: a satirical toy absorbed a quarter of a million requests on two consumer GPUs and a free Workers tier, which says more about the capacity sitting idle in gaming rigs than most vendor benchmarks do. The second is the thread’s own best line, which is that we have now reached the point where nobody can be bothered to write 1990s-style absurdist satire by hand and the absurdism is outsourced to a model. The “no monetization” pledge drew the correct objection — that a true commitment to the bit would involve a rug pull — and the top reply is the sober version: the author probably would not have produced something worth posting if he had tried it by hand instead.

Aleph Alpha’s Kolibri — 407 points

407 points · 11 comments · tej.as writeup · 363 points · 248 comments · announcement · HN discussion

Aleph Alpha released Kolibri on October 3 — the Day of German Reunification — as an Apache 2.0 open-weight model with 78.1 billion total parameters and 3.46 billion active per token. A mixture of experts: 50 layers, 384 experts plus one shared expert per layer, and a router that sends each token to 6 of the 384. That ratio is the whole design. It computes like a 3.5-billion-parameter model and requires the memory of a 78-billion-parameter one, which the model card states plainly rather than letting anyone discover it on a serving bill.

The rest of the spec sheet: German and English, 262,144-token native context tested to 1,048,576, about 78GB in FP8, a June 18, 2026 knowledge cutoff, four reasoning levels, tool calling, ~24 trillion training tokens with more than a fifth of them German, and 768 NVIDIA B200s for the pre-training run. Aleph Alpha’s own numbers put it at 96.9 on AIME 2025 (87.5 German), 96.0 on AIME 2026 (90.0 German), and 84.3 on GPQA diamond (81.3 German), ahead of Qwen3.6-35B-A3B and Mistral Small 4 at comparable active-parameter counts, and it claims the Pareto frontier for quality versus serving cost in both languages.

“Sovereign” is two claims bundled together. The first is about construction: built in Germany, trained on German and Finnish infrastructure under European law, no foreign control. The second is about procurement: full deployment freedom and IP safety, so a ministry or an aerospace supplier can run it on its own metal and nobody can withdraw it. That is a real selling point for the buyers Aleph Alpha names — public administration, industrials, aerospace — and it is a legal argument, not a capability argument. The transparency cuts both ways too: the model card discloses that English web text was rephrased with Google’s Gemma 4, German with Mistral-NeMo, and Qwen3-32B generated labels for the quality filters. Sovereign supply chain, imported shovels.

The thing nobody expected from Aleph Alpha is the 189-page technical report. Their previous flagship, Luminous, shipped a three-page writeup with unlabelled axes, and one commenter in the thread has not forgotten: “Such a crazy change from the times of Luminous.” The thread’s consensus is that the report is a tutorial for building a modern agentic LLM — data curation, ablations, pre-training, post-training, evals — and a member of the pre-training data team showed up to confirm they were trying to make it reproducible by a third party. That is more than most “open weights” releases offer, and several commenters say it makes the model more valuable than higher-scoring releases that ship weights and a blog post. Whether “open” should mean weights or the pipeline that produced them is now an unresolved argument the open-weights community owes Aleph Alpha a thank-you for starting.

Newgrounds.com — 410 points

410 points · 120 comments · newgrounds.com · HN discussion

The submission is just the homepage, currently running its Spooktober event, and the thread is 120 comments of people discovering each other’s childhood. Tom Fulp started the site in 1995 as a repository for his own games, added the portal in 1999 and automated it in 2000, which is when other people’s SWFs started arriving by the thousand. The numbers he gave in a 2017 interview: 84,000-plus games with the majority in Flash, 150,000-plus animations, 7 to 8 million monthly uniques at a time when the peak was higher. Egoraptor, Edmund McMillen, and The Behemoth (Alien Hominid, Castle Crashers) all came out of that pipeline.

What makes the front-page position worth noting rather than pure nostalgia is the preservation work, which is visible in the thread: people are re-playing Flash games they uploaded 15 years ago and finding them playable. That is Ruffle, Mike Welsh’s open-source Flash emulator, which Newgrounds integrated years before Adobe’s 2020 shutdown deadline. Fulp also built Swivel, a Flash-to-MP4 converter, because no good one existed — which incidentally accelerated his own animators’ migration to YouTube while keeping the legacy library alive on site.

The real lesson hides in how the site survived when Armor Games, Addicting Games, Miniclip, Kongregate and CoolMathGames were decimated: in the 2012 redesign Fulp took the word “Flash” out of the site’s language and called it the games-and-movies portal instead. He hedged the brand before he had to. None of the commenters mourning the death of the browser games ecosystem appear to have noticed that the one site still standing is the one that stopped describing itself in terms of its runtime.

Updates to Full Disk Access in macOS — 280 points

280 points · 200 comments · developer.apple.com · HN discussion

Apple published three short paragraphs on October 2 and they are worth reading in full, because they are an admission. The admission is that Full Disk Access “largely sidesteps” the privacy controls Apple gives developers, that it exists because backup apps need it, and that “some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users’ full knowledge and understanding.” For communication apps, Apple adds, that exposes the privacy of the people the user is talking to.

The forward-looking sentence is the interesting one: going forward Apple will add controls requiring “very explicit user action” to grant the entitlement. And the reason given for doing it now is unusually specific: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Apple is pre-empting the case where every local agent, indexer and code assistant on the machine asks for whole-disk read and the user clicks allow because the alternative is a broken tool.

The thread is 200 comments of the right complaint, which is that Full Disk Access is a symptom of an unsolved design problem rather than a feature. Why is there no scope for “everything except Mail, Messages, and browser history”? A developer of a file-search utility explains that he indexes paths, not contents, skips the protected directories entirely, and still cannot know in advance which path will trip the prompt — so he has to ask for everything and the user has no way to evaluate the request. The standard replies are that fine-grained ACLs on a desktop filesystem produce false positives and false negatives at a rate nobody can tune, that Unix permissions have barely moved in twenty years, and that the practical answer is an advanced/expert toggle. Apple has shipped the blunt control because the precise one is a twenty-year-old open problem, and the press release does not mention that it is also the only control that matters if agents are about to run on your laptop.

Zig v0.17.0 — 259 points

259 points · 195 comments · ziglang.org · HN discussion

The release itself is substantial: five months, 206 contributors, 925 commits, a build system rework that introduces the Build Server Protocol, an ELF linker improved to the point where incremental compilation is expected to work for everyone on x86_64-linux, a formal target tier system, a formally specified and fuzzed grammar, changes to @bitCast, a new SafeAllocator, an ArrayList rework, and a set of removals (void{}, i0, errdefer capture, array multiplication) that the notes do not soften. The C translation layer moves out to an external package. For a language still pre-1.0, the language-stability section is the one to watch.

Almost none of that is what the thread argued about. The thread is about AI-generated bug reports, because someone pointed at Andrew Kelley’s latest “state of the tagged union” talk, in which he is warmer about using LLMs to find bugs — inspired by SQLite’s results — as a path toward bug-free software, but only after full branch coverage and fuzzing. Buried in that thread is a specific case: a bug report was reportedly closed because the reporter said they had used several LLMs to confirm the bug existed. Commenters dig into it and find the reporter had hit the bug in their own code and used models to verify their theory of it, which is human-found and machine-confirmed.

The argument is worth stating cleanly because it will keep recurring. A maintainer in the thread says the only way to handle the increased noise has been to use AI to extract the links and line numbers he used to find by hand, while still being dismissive of submitters who cite model verification as evidence. Both are defensible. The distinction that survives is burden of verification, not tool purity: using a model to check your own repro is diligence, and handing a maintainer a chat transcript is offloading work onto someone who did not ask for it. Kelley’s stated position, per the talk, is that he still is not accepting AI-discovered reports until certain preconditions are met — a language in flux would rather spend its maintainer hours on bugs that broke a real user than on bugs a model found. That is a resource-allocation decision dressed up as an AI policy, which is probably what most of these decisions are.

The Forgetful CPU (Linux on M4) — 256 points

256 points · 187 comments · yuka.dev · HN discussion

The best technical writeup of the day, and it is a bug report disguised as a travelogue. Yuka bought an M4 Mac mini in November 2024, gambling it would be close enough to the M1–M3 machines that Asahi Linux could support it quickly. It was not. M4 is the first Apple Silicon generation to mandate SPTM, a macOS hardening feature that breaks the m1n1 hypervisor approach everyone had been using to capture MMIO traces of Apple’s drivers. So the work went back to first principles: disable strict boot security, install m1n1 as a custom boot object through macOS Recovery, get a serial console, discover that GXF is locked in raw boot mode, discover that writing RVBAR crashes because it already holds the right value, and then bisect the Linux boot path by injecting an assembly routine that prints a single letter a to find where execution died — which turned out to be MMU initialisation, followed by a device tree that was missing stdout-path = "serial0" and therefore swallowing every earlycon message.

Then the real find. Previous Apple Silicon chips had a known quirk in WFI (Wait For Interrupt): depending on the state of a “chicken bit” called ARM64_REG_CYC_OVRD_ok2pwrdn_force_mask, the instruction zeroes registers x0 through x31. Linux solves this by saving and restoring those registers around the instruction, and Asahi re-enables the behaviour deliberately because it lets cores reach deeper sleep states and lets one core in a cluster boost. On M4 the chicken bit is locked or gone, and the default behaviour does not comply with the ARM64 specification, which says an executable WFI must not cause a loss of architectural state. In April 2026 Yuka booted Linux with all cores usable by replacing every WFI and WFIT in the kernel with a NOP.

The interesting part is why that could not ship as an errata patch. A virtual machine running under the macOS hypervisor also trips the same detection logic, but there WFI is trapped and used to schedule guests — so patching by detection would break virtualisation, and detecting virtualisation reliably, including nested cases, is its own mess. On Will Deacon’s suggestion the fix became a kernel bootarg that disables WFI idle, with m1n1 adding it conditionally on machines known to have broken WFI. Both landed in mainline, and the latest releases of Linux and m1n1 now boot natively with secondary cores on M4 Macs. The same workaround reportedly holds for M4 Pro, M4 Max and M5.

The comment thread is the usual “imagine if Apple opened this up,” answered correctly by the usual reply — Apple is a vertical company, the hardware is a means to an end, and asking it to sell you parts is like asking the Catholic Church to start a rap 8-track club. But the news is that a hobbyist with a machine he bought in 2024, working against a hardened boot chain, found a silicon-level power-management bug that violates the architecture specification and got the fix into mainline instead of into a blog post and a private patch set. His closing shot is fair too: some of the projects getting a lot of funding could be more transparent about what they take from the upstream work.

Muse Gadgets — 235 points

235 points · 106 comments · gadgets.muse.ai · HN discussion

Meta’s Muse — the personal agent that acts through a hosted cloud computer and browser, launched in the US in September — now has an open-source hardware programme. There is an ESP32 Device SDK with firmware, a Linux Device SDK for Raspberry Pi and other boxes, Apache 2.0 on the code, and a page of project ideas: a round AMOLED screen, an M5Stack stick, an e-ink panel, an HDMI dongle. The worked example is Muse Home Link, a USB-C device on an Espressif ESP32-C5 that puts Muse on your home network so it can talk to TVs, speakers and anything exposing a local HTTP API. Meta made 5,000 of them and is giving them away to active US Muse subscribers, one each, shipping expected in October.

The terms are where the story is. Every gadget needs a Muse SDK token. The project page says the SDKs and tokens “are not a supported product or developer platform,” that Meta can change or withdraw access at any time, that one token is limited to 50 devices, and that embedding a token in anything sold for money or distributed through a promotion requires written permission. Home Link itself cannot be reflashed, unlike the free SDK it is built on.

This is the open-core shape applied to hardware, and the shape is explicit rather than hidden: the code is genuinely open, the connection to the agent is a revocable token, and the terms say so in plain language. Nat Friedman, who runs product at Meta Superintelligence Labs, is the face of it, and the thread splits exactly where you would expect. One camp reads the whole thing as an internal team having fun with a trillion-dollar company that will not move on its behalf; the other reads it as free peripheral R&D and developer adoption with Meta holding the chokepoint. Both are probably true, and the reason the second one matters is that it is the same structure the roundup is watching elsewhere — an open surface with a closed dependency. A pre-order confirmation is also not an order, and a 5,000-unit batch is an announcement, not an adoption figure.

ICC judge on what U.S. sanctions mean — 216 points

216 points · 170 comments · npr.org · HN discussion

NPR’s Morning Edition interviewed Kimberly Prost, a Canadian judge at the International Criminal Court, about the practical life of being sanctioned by the United States. Her Alexa stopped answering. Credit cards issued in the Netherlands and Canada were cancelled. Some bank accounts survive but small transfers get blocked. Access to services from American companies was cut off “completely randomly, though, you don’t know when something’s going to happen.” Her health insurance is the sharpest case: AXA, the French company that covers the court, has refused to pay her claims even though it is not legally required to follow US sanctions. Her summary is “it’s a business decision,” and her term for the pattern is “massive overcompliance by companies.”

That is the story, and it is not about the ICC’s jurisdiction. It is about what a sanction reaches when the enforcement mechanism is the private sector’s risk tolerance rather than any legal obligation — a foreign insurer deciding that a single policyholder is worth less than frictionless access to the US market. The thread’s better comments make the generalisation: de-banking is the punishment, the useful fiction of the US as a neutral arbiter depends on being seen as a disinterested one, and the EU’s exposure is not uniform — a commenter points out AXA could probably withdraw from the US market and survive on European business and chooses not to. Read alongside the rest of today, the story is the same chokepoint argument, with the stakes made concrete on one person’s credit cards.

Turbo Haskell — 209 points

209 points · 59 comments · comonad.com · HN discussion

Edward Kmett started THC — a “Turbo Haskell compiler” — as a joke a week before publishing this, while on vacation visiting Bartosz Milewski. It now implements every one of GHC 9.14.1’s prim-ops and provides a JIT for GHC Core that runs Haskell on the JVM, using the Truffle and GraalVM approach he developed years ago in Cadenza. GHC keeps doing the hard part — parsing, typechecking, desugaring, Core optimisation — and THC takes over compilation and execution through its own runtime, with both a bytecode JIT and a traditional AST-based one, ahead-of-time compilation via Native Image, and Template Haskell and Linear Haskell supported.

The details are what make it more than a stunt. Tail calls become loops: in tracing mode THC fills a 64-bit Bloom filter to detect likely recursive tail calls, throws a slow-path exception to connect the continuation to its launch site, and uses custom Truffle nodes to get Graal to collapse the loop across function bodies, growing additional side loops when paths diverge. False positives cost extra slow-path work and change nothing. Concurrency covers throwTo, asynchronous exceptions with resumable continuation code, and masking, with both Java threads and Project Loom green threads on a HEC-style executor giving cheap MVars. SIMD goes through the incubating Vector API with runtime selection of species width, so loops get JIT-compiled against the width the machine actually has. C and C++ in the dependency tree run through native-mode Sulong, LLVM on the JVM.

The polyglot FFI is the part with legs beyond the joke: zero-copy Data.Text conversion to Truffle strings means a Haskell program can borrow Python, Ruby, R or JavaScript libraries directly, which is the reverse of the usual direction of travel for a typed functional language. It resolves packages through Cabal, supports multiple libraries per package and Backpack, and compiles pandoc, happy, alex and — as of today — GHC itself. The thread’s best contribution is a reminder that this has been tried: Frege was a Haskell dialect on the JVM, and its releases are old. The reason THC is different is not the JVM target, it is that Core is a portable IR and GraalVM’s tooling is now good enough to exploit that. GHC does the hard part; the leverage was always in the backend.

Big Tech ruined the cloud, so we’re renaming ours — 209 points

209 points · 107 comments · home-assistant.io · HN discussion

Nabu Casa is renaming Home Assistant Cloud to Home Assistant Link. The post is written by Carl, the VP of Commercial, and it is a marketing document with one honest paragraph in it: Paulus would get on stage, tell people not to buy products that need the cloud to work, and then spend the next breath explaining why Home Assistant Cloud is the exception, which is friction that exists purely because of a name. Worse for a product called Cloud, users kept assuming Home Assistant runs in the cloud, which it never has and never will. Nabu Casa even removed the word from its logo.

The comparison table is the argument: optional versus required, no lock-in versus walled garden, private versus monetised, funds a nonprofit versus funds investors first. A thread commenter makes the fair objection that “cloud” has simply come to mean a service hosted somewhere you don’t control and pay for, and Link is still that. The better reply is that the word carries a specific meaning in home automation — a product that degrades or bricks when the subscription lapses, with Wink named as the example — and Link is not that, because the lights work when the service is gone. One comment calls the whole thing a marketing stunt, which is also true and does not make the underlying claim false.

The reason this belongs next to Muse Gadgets and Kolibri rather than in the long tail is that all three are making the same argument in opposite directions. Meta open-sources the firmware and keeps the token; Aleph Alpha sells a model on being impossible to switch off; Apple is adding a prompt to an entitlement it admits is a hole; the US is reaching a French insurer’s decision to withhold claims from a Canadian judge. Everyone is fighting over where the chokepoint sits, and the only product on today’s page that ships a service you can unplug and walk away from is the one that just renamed itself to get the word “cloud” off the box.

Still on the page

Forty-seven stories from earlier roundups are still above 200 points in the window, and the page unfroze enough that most of them kept climbing. Deltas are against the last roundup that tracked each story.

When did Google get so weird? 2,002 → 2,009, up 7 — fifth day at number one. Gemini 4 Argon 1,683 → 1,691, up 8, with its comment thread still the week’s permanent argument. Pi 1.0 806 → 1,675, up 869, the day’s biggest mover by a factor of two and now third overall. Livenerf 911 → 920, Court agrees with EFF: Utah’s VPN law 305 → 764, up 459 — the injunction post nearly tripled overnight, which is what happens when a ruling keeps getting cited. You said no MCP 669 → 679. Mike Tomlin’s Minecraft city 65 → 629, up 564 — the novelty story of the day; nothing about it changed except the position. StreetComplete on iOS 616 → 626. Clef 443 → 624, up 181. The Linux kernel vulnerability advisory 535 → 568, up 33. Frog and Toad 529 → 563, up 34. Git 3.0’s SHA-256 default 231 → 558, up 327, still one of the most sustained arguments on the page. Apple Pass Designer 102 → 536, up 434. Pi Durable 477 → 499. FLUX 3 Image 196 → 420, up 224, despite still having no model card. Why the Bronze Age Collapsed 393 → 410. Returning from vacation? The government can search your phone 398 → 408. DeepSeek Harness Desktop 378 → 403. SvelteKit 3 389 → 400. Bloomberg terminal history 377 → 392. Micron’s memory supply warning 333 → 390, up 57. RIP, vector database 374 → 385. The 12-year HR 8799 timelapse 48 → 378, up 330. Still Wet, the simulated paint canvas 138 → 360, up 222. Phyllotaxis 349 → 352. Loss of cell identity drives human aging 74 → 347, up 273. Sites in ChatGPT 122 → 337, up 215. Antirez’s ds4 23 → 332, up 309 — yesterday it was a line item in the long tail at 23 points. LinkedIn Larpmaxxing 304 → 320. Kroah-Hartman’s Security in the LLM Age 67 → 315, up 248, which is the talk that the Zig thread is re-litigating. URSALA, RAQUEL and FARRAH 298 → 306. Shimano Bicycle Museum 273 → 302. The Legend of von Neumann 210 → 300, up 90. Hidden SDR capabilities in ESP32s 277 → 287. Cloudflare K2 280 → 286. Cops bypassing the iPhone reboot lock 246 → 285. Book of Shapes 257 → 283. Solving Factorio Quality 274 → 281. Stratego beaten on 16 GPUs 79 → 275, up 196. Speeding up the Rust compiler 233 → 275. OpenDLSS 249 → 271. Ask HN: Who is hiring? 257 → 263. Automatic Transmission, the connected-vehicle privacy study 244 → 251. On social reality in China 43 → 238, up 195. Using Opus 5.5 to find a dodo eyewitness record 215 → 223. One month on GLM 5.3 Flash 33 → 216, up 183. Supabase acquiring Turso 171 → 210.

Off the window but still accumulating: Singapore’s government dating service sits at 248 points and 352 comments on the singapore-samizdat submission, against 445 on the other submission of the same story — the same split the last roundup flagged, not a collapse.

The shape of the movement is worth one sentence: the small-budget stories gained the most in absolute terms, and the two biggest percentage movers — Tomlin’s Minecraft city and the dodo eyewitness — were the two stories with the least industrial weight.

Throughline

First: today’s page was an argument about where the chokepoint is, and it ran in five directions at once. Aleph Alpha sold a model on the property that nobody can switch it off — built in Germany, trained on German and Finnish metal, Apache 2.0 weights, so a ministry can run it inside its own walls. Meta shipped open firmware whose connection to the agent depends on a revocable SDK token, limited to 50 devices, explicitly not a supported platform, embeddable in a product only with written permission. Nabu Casa renamed a service to argue that its chokepoint is optional and the lights work when it goes away. Apple published three paragraphs admitting that Full Disk Access is the hole through which everything on your machine is readable, and named autonomous AI agents as the reason the hole is about to get worse. And the US reached a French insurer’s decision to withhold an ICC judge’s health claims by making the sanctions question a business-risk calculation rather than a legal obligation. Every one of those is the same question — who holds the switch — and the answers ranged from “a German nonprofit-ish company with a 189-page report” to “a token Meta can withdraw whenever it wants.”

Second: the best work on the page was again the cheapest. A satirical site built with GLM-5.3 over six pints, served from two RTX 4060 Tis behind a free Cloudflare Workers tier, absorbed 250,000 requests and hit number one. A “Turbo Haskell compiler” started as a vacation joke now compiles GHC itself by treating Core as a portable IR and borrowing GraalVM’s polyglot machinery. A hobbyist found a WFI behaviour that violates the ARM64 specification on M4 silicon and got the workaround into mainline Linux and m1n1 instead of into a private patch set — and the same fix reportedly covers M4 Pro, M4 Max and M5. Meanwhile the day’s largest compute story is a 768-B200 pre-training run whose distinguishing feature is a technical report honest enough that commenters cannot believe a European lab published it. Capability per dollar and honesty per dollar are both moving in the same direction, and the two are correlated: the small efforts can afford to show their work because there is nothing to spin.

Third: the second-order effects of AI are now the loudest arguments on the page, and none of them are about capability. The Zig release notes are excellent and 195 comments went to whether a bug report can cite model verification. Apple’s Full Disk Access announcement says out loud that agent autonomy is why the entitlement is getting a prompt. The highest-scoring story of the day is an AI-generated satire of AI written by an LLM on a home GPU. The Newgrounds thread asks whether a model could revive two decades of Flash. And underneath all of it sits Kroah-Hartman’s slide from two days ago, still climbing to 315 points: 79 reported kernel vulnerabilities, 3 of them fabricated, 14 not bugs, 15 already fixed, 20 that needed real fixes, and 10 real bugfixes at the end. The most useful contribution this week came from a volunteer transcribing a conference slide, and the most argued-about contribution is whether a model is allowed to help confirm a bug a human found. The tool has moved into the maintenance layer, which is where nobody has a policy yet.

Published 3 October 2026. Scores captured at 13:20 PDT from the HN Firebase API via the top-200 rank window and a 44-hour Algolia date sweep; the front page moves after that.