Moin.

Zu Fortsetzung der beliebten Serie "mecklenburgische Dorfkirchen bei schlechtem Wetter" heute ein kleiner Leckerbissen:

Die, wie viele hiesige #Backsteinkirchen im 12. bis 14. Jhd. nach den Kreuzzügen gegen die bereits ansässige elbslawische Bevölkerung und Kolonisation durch christliche Siedler entstandene Kirche von #KirchMummendorf, die etwa aus der Zeit ab 1250 datiert, enthält Balken aus Bäumen, die schon ab dem Jahre 1026 geschlagen wurden und die aus älteren Gebäuden stammen.

This entry was edited (10 months ago)

My Gmail was telling me that I had no more space and that it might stop delivering emails... (threatening me with a good time!)

I decided it was a good time to dump the email I've had for over 2 decades...

So I decided to try out @Tutanota

... and then some other stuff...

pythonbynight.com/blog/untangl…

#bigtech

#XSF Summit 27

We are starting soon discussing diverse topics around the #XMPP #protocol! :xmpp:

Participate: xmpp.org/2024/11/xmpp-summit-2…

#jabber #chat #interoperability #rtc
#opensource #decentralization #standard

Gajim reshared this.

E nun era n'avviso de garanzia, e Nordio sapeva, e ho detto tante balle... sti articoloni anno tutti na cosa in comune: sò lunghi e noiosi!

Ma vuoi mette sta barba co un TicToc montato bene de me che te dico facile in pochi secondi cosa devi crede?

A comunisti, e daje sù! Me fate proprio vincere facile! 😆

pagellapolitica.it/articoli/er…

@Friendica Support

Hi there,
the moment has come to do the first instance upgrade cycle in the life of this instalation to bring this server to the actual stable version 2024.12-1 in the comming days.

In part the idea is to document every step in a post similiar to the howTo instructions:
install and/or move friendica to ubuntu 22.04 LTS VPS server
in the @EDIT | don't follow! profile.

Right now we are on 2023.05, so we will have to update step by step to:
2023.12 | release notes
2024.03 | release notes
2024.08 | release notes
2024.12-1 | release notes

Are there any specific recomandations or details to have in mind besides the information expected to be found in every update release instruction?

This is basically a single user instance with round about 14 forum pages with few followers each and a total of 18 profiles with contacts in the activityPub and diaspora community and some RSS subscriptions. No other specific conectors are enabled.

Installed addons/apps:
blockbot, calc, impressum, js_upload, notifyall, nsfw, pageheader, phpmailer, qcomment, rendertime, showmore_dyn, startpage

DB backups amount to ~180MiB and the image file storage folder on ftp around ~400MiB.

Friendica stable | 'Giant Rhubarb' 2023.05 - 1518
PHP Version 8.1.2-1ubuntu2.14
VPS server | Ubuntu 22.04 LTS
4 Core CPU, 8 GB Ram with 300GB NVME Disk - unlimited traffic
hosted by @ raroun 👍

Notes:
This instances right now seems to work well.
Sometimes this profile here has some strange hickups like when following up the link of a post from this server in a stream view a message "Not Found |The requested item doesn't exist or has been deleted." Also right now profiles from contacts, for example @ hoergen or @ feb don't show up in the contact list but they are displayed as followed in the profile contact page.

#friendica #fediAdmin

in reply to TupambAdminOrg [2024.03]

error notice: DefinitionCache/Serializer not writable
Serializer.php php line 2982025-02-20T22:15:46Z WARNING app E_USER_WARNING: Directory /var/www/html/vendor/ezyang/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer not writable.
Directory /var/www/html/vendor/ezyang/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer not writable.
file
/var/www/html/vendor/ezyang/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer.php
php line 298
error 512
in reply to Hypolite Petovan

hypolite wrote:

Please verify the ownership of these folders.

vendor ownershipdrwxr-xr-x 40 www-data www-data 4096 Feb 20 21:22 vendor
drwxr-xr-x 3 www-data www-data 4096 Feb 20 21:20 ezyang
drwxr-xr-x 3 root root 4096 Feb 20 21:20 htmlpurifier
-rw-r--r-- 1 root root   341 Nov 17  2023 CREDITS
-rw-r--r-- 1 root root 26456 Nov 17  2023 LICENSE
-rw-r--r-- 1 root root  1271 Nov 17  2023 README.md
-rw-r--r-- 1 root root     6 Nov 17  2023 VERSION
-rw-r--r-- 1 root root  1415 Nov 17  2023 composer.json
drwxr-xr-x 3 root root  4096 Feb 20 21:20 library

drwxr-xr-x 21 root root  4096 Feb 20 21:20 HTMLPurifier
-rw-r--r--  1 root root   274 Nov 17  2023 HTMLPurifier.auto.php
-rw-r--r--  1 root root   213 Nov 17  2023 HTMLPurifier.autoload-legacy.php
-rw-r--r--  1 root root   910 Nov 17  2023 HTMLPurifier.autoload.php
-rw-r--r--  1 root root   101 Nov 17  2023 HTMLPurifier.composer.php
-rw-r--r--  1 root root   576 Nov 17  2023 HTMLPurifier.func.php
-rw-r--r--  1 root root 10573 Nov 17  2023 HTMLPurifier.includes.php
-rw-r--r--  1 root root   923 Nov 17  2023 HTMLPurifier.kses.php
-rw-r--r--  1 root root   235 Nov 17  2023 HTMLPurifier.path.php
-rw-r--r--  1 root root 10187 Nov 17  2023 HTMLPurifier.php
-rw-r--r--  1 root root 13579 Nov 17  2023 HTMLPurifier.safe-includes.php

There has been problems before with nearly all folders becoming owned by root.
In this upgrade I made the mistake to initialize bin/composer.phar install --no-dev as root but aborted that intent, changed to www-data and applied bin/composer.phar install --no-dev again.

Command applied now to asure that all folders will be owned by www-data.
chown -R www-data:www-data /var/www/

in reply to utopiArte

Ownership, www-data and root related conversation from last year when the instalation was migrated to this VPS:
tupambae.org/display/0ac89072-…


Implications of access by the user www-data to all friendica folders


@Friendica Support

Hi there,
the friendica helpers page describes the installation process of friendica as follows:

/help/Install: wrote:

The Linux commands to clone the repository into a directory "mywebsite" would be
git clone https://github.com/friendica/friendica.git -b stable mywebsite
cd mywebsite

bin/composer.phar install --no-dev

Make sure the folder view/smarty3 exists and is writable by the webserver user, in this case www-data

mkdir -p view/smarty3
chown www-data:www-data view/smarty3
chmod 775 view/smarty3

Get the addons by going into your website folder.

cd mywebsite

Clone the addon repository (separately):

git clone https://github.com/friendica/friendica-addons.git -b stable addon


askubuntu.com: wrote:

What is the www-data user?
askubuntu.com/questions/873839…
The web server has to be run under a specific user. That user must exist.

If it were run under root, then all the files would have to be accessible by root and the user would need to be root to access the files. With root being the owner, a compromised web server would have access to your entire system. By specifying a specific ID a compromised web server would only have full access to its files and not the entire server.

I guess this observation goes both ways, a compromised friendica instalation get's access to all the friendica folders if I choose to first create/activate the www-data user, than create the friendica installation folder structure, than git clone friendica, than create the smarty3 folder and ultimately do the git clone of the addon folder as described here:
tupambae.org/display/0ac89072-…
The order in which the creation of www-data related folders in the above case is described makes all folders and files in the friendica directory belong to www-data.
In the friendica help description first comes the git-clone, than the the smarty3 folder part than the addon git-clone. Actually I guess that last part would make the addon folder belong to www-data too if I run one command after another. Is that intended?

I wonder if this could have some kind of security implications.
I guess www-data is somehow the friendica site and has permissions to do "what ever it wants" (-> "writable by the webserver user") with all the folders in the friendica directories if it's the owner of them.


@TupambAdmin [stable]


in reply to TupambAdminOrg [2024.03]

@TupambAdminOrg [2024.03] @…ᘛ⁐̤ᕐᐷ jesuisatire bitPickup

Somehow this looks all good.
We should consider updating to 2024.08.

[spoiler] Friendica Core
Updates to the translations AR, CS, DE, ES, FR, GD, HU, IS, IT, JA, NL, PL, RU, SV
Updates to the documentation
Updates to the themes (frio)
General code cleanup
Improved the redirection for contact actions
Improved the performance while fetching of replies
Improved the performance when visiting remote profiles
Improved OWA
Improved the procession of worker tasks
Improved performance in the probing process
Improved INBOX performance
Improved perfomance when expireing postings
Improved mirroring settings for RSS contacts
Improved supported image formats
Improved handling of CC for comments
Improved handling of "sensitive" flags for postings
Improved display of log levels
Improved handling of permissions for attachments
Improved addon handling
Improved API for channels and circles
Improved performance while displaying local postings
Improved federation with pixelfed, threads
Improved integration with Bluesky
Improved automatic cleanup of the database
Fixed access to restricted timeline via API
Fixed problem fetching from INBOXes
Fixed display of contacts from unavailable networks
Fixed profile display
Fixed a problem with local un-/follows
Fixed the uimport POST endpoint
Fixed problem with 0Auth logins
Fixed problem with @mentions in comments
Fixed XSS in profile fields
Fixed bug in deleting unused cached avatar pictures
Fixed paging bug on the media tab of remote profiles
Fixed display of attached links
Fixed a bug in circle only contacts
Fixed display of moderation reports
Fixed delivery problems to group postings
Added monitoring service endpoint
Added admin option display_link_length to set the length of displayed links
Added the possibility to upload media files via API
Added console command to clear avatar cache
Added platform data to the API
Added parsing support for Nodeinfo 2.1 and 2.2
Added node description to Nodeinfo
Added owner information of relay accounts
Added option for users about how to transmit postings with titles
Added for non HTML content of feeds
Added reshares for postings from Bluesky and tumbl
Added public forums with manual request approval
Added "next try" information for deferred worker jobs listing
Added support of FEP-e232
Added automatic closure of registration if admin becomes inactive
Added channel only option for contacts

Friendica Addons
Updates to the translations AR, CS, DE, FR, IT, PL, SV
Blockbot
Added Relatica to good client list
Improved agent identifier list
Bluesky
Added monitoring statistics
Added support of sensitive postings
Improved API handling
Improved fetching of user DID
Fixed conversion BS/Friendica handles
jsuploader
Improved detection of supported file types
mailstream
Improved image handling
tumblr
Added monitoring statistics
Improved quoted postings [/quote]

github.com/friendica/friendica…

The launch of the new Braille Music book- for complete beginners! - victaparents.org.uk victaparents.org.uk/braille-mu…

Tamas G reshared this.

World Braille Day 2025 – A Retrospective Look Back and Reasons to Be Cheerful | All Formats allformats.org.uk/world-braill…

'Not a buyout': Attorneys and unions urge federal workers not to resign - NPR apple.news/A7ZwXOtO7Qt-Lz9_UV6…

Why is everything panicking about DeepSeek? Shouldn't they instead look at the code, learn from it, and build something better? After all, it's a lot more open than what most of big tech has produced so far.
#AI
forbes.com/sites/dereksaul/202…
#AI

New Kokoro TTS model just released. This was trained on much more data than the previous version and really sounds good. If you want to try yourself, just do pip install kokoro. I haven't gotten a chance to test the model yet, but here is a demo from the guy who trained it. Here's a demo. A female voice reading the following text: "Kokoro is an open-weight TTS model with 82 million parameters. Despite its lightweight architecture, it delivers comparable quality to larger models while being significantly faster and more cost efficient. With Apache licensed weights, Kokoro can be deployed anywhere from production environments to personal projects."

You've probably heard that "we are stardust," but this graphic breaks it down further & tells you what kind of stars your dust came from--and which elements didn't come from stars at all.

svs.gsfc.nasa.gov/13873/ #science #nature #space

Dear lovely #PHP community, what do you think about Mago? I've recently read about it in PHP Annotated by Roman from JetBrains. Seems a potentially good replacement for PHPCS and maybe PHP-CS-Fixer. Is it time or not yet? mago.carthage.software/
#php
in reply to André Polykanine

@menelion Hey thanks for the feedback! BTW, my rant about accessibility testers acting like ADA inspectors was completely unrelated to this, totally different thing.

The phone numbers are necessary in order to verify the person you are talking to, since anyone can set whatever name they want in their profile. Bad actors could use this to impersonate people you know.

I agree that it’s annoying though from the screenreader perspective, and we’ve gotten a fair bit of feedback to filter them out. We’ve been able to balance the concerns on mobile by including the number in the custom action hint when you swipe down from the bubble (E.G. “view contact info for +1 (202) 555-1111”) It’s more complicated for desktop though.

As a best practice, you are supposed to convey any information that is relevant to the screenreader for it/the user to decide how to handle it. I think this is an area where it makes more sense for a screenreader add-on or script perform this function so it is under the user’s control.

All that to say, it’s tricky, but I think there is a path forward here that will give the users what they want without security compromises.

Guys check out this new project, it's a cross platform app that lets you experiment and train open source LLMs without any code. It's based on Electron and open source, but I haven't yet looked at accessibility. github.com/transformerlab/tran…

The irony: OpenAI—which faces multiple lawsuits for using content without permission—accuses China's DeepSeek of basically copying from ChatGPT to train its AI models. pcmag.com/news/openai-deepseek…

reshared this

“Nobody asked for NFTs or the fucking Metaverse. Nobody asked for lying chatbots instead of getting to reach an actual support person that could solve your problems.”

And:“…people are challenging the notion that we all have to do AI now. Because we don’t. It’s a choice. A choice that mostly benefits monopolists.”

@tante in tante.cc/2025/01/28/quoted-in-…

Nvidia RTX 5080 Reviews Fail to Impress Gamers
"That’s due to the RTX 5080 failing to surpass the RTX 4090 and only offering slight improvements over the RTX 4080 and RTX 4080 Super."
(Still no talk of whether it runs less hot than the prior generation, so far none of these gaming sites covered that one)
tipranks.com/news/nvidia-rtx-5…