<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Joshua Rosato — notes</title>
    <link>https://joshuarosato.com/notes/</link>
    <description>Short notes and things learned along the way.</description>
    <language>en-gb</language>
    <atom:link href="https://joshuarosato.com/notes/rss.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Fri, 02 Oct 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Stop grep matching itself without grep -v grep</title>
      <link>https://joshuarosato.com/notes/grep-bracket-trick/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/grep-bracket-trick/</guid>
      <description>ps aux | grep nginx always lists the grep nginx process too, which is why | grep -v grep is so common. Wrap one character of the pattern in brackets instead: The regex [n]ginx still matches nginx, but grep&apos;s own command line now contains…</description>
      <pubDate>Fri, 02 Oct 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>bash</category>
    </item>
    <item>
      <title>ldd may run the binary you are inspecting</title>
      <link>https://joshuarosato.com/notes/ldd-runs-the-binary/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/ldd-runs-the-binary/</guid>
      <description>ldd is not a parser. It is a shell script that asks the dynamic loader to trace itself — normally by running the loader with --list, and in some versions and some situations by setting LD_TRACE_LOADED_OBJECTS=1 and executing the file…</description>
      <pubDate>Fri, 02 Oct 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>security</category><category>debugging</category>
    </item>
    <item>
      <title>MemoryHigh is a slope, MemoryMax is a cliff</title>
      <link>https://joshuarosato.com/notes/memory-high-vs-memory-max/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/memory-high-vs-memory-max/</guid>
      <description>A container that runs out of memory did not run out of machine memory — it hit a limit recorded under /sys/fs/cgroup, which is why free -h inside the container shows the host&apos;s total and tells you nothing. The cgroup files are the only…</description>
      <pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>systemd</category><category>performance</category><category>containers</category>
    </item>
    <item>
      <title>Core dumps are free until you need one</title>
      <link>https://joshuarosato.com/notes/core-dumps-free-until-needed/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/core-dumps-free-until-needed/</guid>
      <description>The kernel refuses to write core dumps by default (RLIMIT_CORE starts at 0), which is why production crashes usually leave nothing behind. systemd raises that limit for everything it starts and registers itself as the kernel&apos;s…</description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>systemd</category><category>debugging</category>
    </item>
    <item>
      <title>Give AI agents privileged access with pkexec</title>
      <link>https://joshuarosato.com/notes/pkexec-privileged-ai-agents/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/pkexec-privileged-ai-agents/</guid>
      <description>AI coding agents usually run unprivileged and stall when they need root — installing a package, writing under /etc, restarting a service. Instead of running the whole agent as root, tell it to escalate per command with pkexec: pkexec goes…</description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>ai</category><category>security</category>
    </item>
    <item>
      <title>Find and kill the process using a TCP port</title>
      <link>https://joshuarosato.com/notes/tcp-port-find-kill-process/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/tcp-port-find-kill-process/</guid>
      <description>When a port is already in use, find who owns it before reaching for a reboot: ss -ltnp shows the PID in the users:(...) column (use sudo to see other users&apos; processes); lsof -i :8080 lists the open sockets; fuser 8080/tcp prints just the…</description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>networking</category><category>debugging</category>
    </item>
    <item>
      <title>perf counts, perf samples — pick the right one</title>
      <link>https://joshuarosato.com/notes/perf-counts-and-samples/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/perf-counts-and-samples/</guid>
      <description>perf has two modes and they answer different questions. Decide which one you are asking before you collect anything. Count when the question is how much: cycles, instructions, cache misses, context switches, page faults over a window long…</description>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>performance</category><category>observability</category><category>debugging</category>
    </item>
    <item>
      <title>Deleted files can still fill a disk</title>
      <link>https://joshuarosato.com/notes/deleted-files-still-using-disk/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/deleted-files-still-using-disk/</guid>
      <description>When df says a filesystem is full but du can&apos;t find the space, a process is usually holding a deleted file open. The blocks aren&apos;t freed until the last file descriptor closes. +L1 lists open files with a link count below one, which means…</description>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>debugging</category>
    </item>
    <item>
      <title>Ask the package manager what changed on disk</title>
      <link>https://joshuarosato.com/notes/verify-installed-files/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/verify-installed-files/</guid>
      <description>Every package manager already stores checksums for the files it installed, which turns &quot;has anything been modified since installation?&quot; into one command instead of a filesystem-wide hunt: All three speak the same output dialect: a field of…</description>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>security</category>
    </item>
    <item>
      <title>Measure durations with the monotonic clock</title>
      <link>https://joshuarosato.com/notes/monotonic-vs-realtime-clocks/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/monotonic-vs-realtime-clocks/</guid>
      <description>Linux has several clocks, and mixing them up is a reliable way to ship a bug that only appears in production. CLOCK_REALTIME is the wall clock: NTP, settimeofday and leap seconds move it forwards or backwards. CLOCK_MONOTONIC counts from…</description>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <category>linux</category><category>debugging</category>
    </item>
    <item>
      <title>Why is boot slow? Ask for the critical chain</title>
      <link>https://joshuarosato.com/notes/systemd-analyze-critical-chain/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/systemd-analyze-critical-chain/</guid>
      <description>systemd-analyze blame sorts units by how long they took to start, but units start in parallel, so the slowest one often isn&apos;t what delayed boot. This shows the chain of units that actually gated default.target. The time after @ is when a…</description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
      <category>systemd</category><category>performance</category>
    </item>
    <item>
      <title>Print a value in reusable shell quoting</title>
      <link>https://joshuarosato.com/notes/bash-quote-expansion/</link>
      <guid isPermaLink="true">https://joshuarosato.com/notes/bash-quote-expansion/</guid>
      <description>Bash 4.4 added the @Q parameter transformation, which quotes a value so it can be pasted back into a shell unchanged: Handy in logs: echo &quot;running: ${cmd[*]@Q}&quot; shows exactly which arguments a command received.</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <category>bash</category>
    </item>
  </channel>
</rss>
