Measured on real files with quality held fixed (SSIM vs the source, harness self-tested at 1.0000):
hevc_nvenc cq27 produced 115% and 119% of the source video bitrate on two of three files while cq30/31
landed 51-84%; libx265 crf26 landed 33.7/56.7/67.0% at min SSIM 0.988-0.993, i.e. 10-22% smaller than
NVENC at matched quality. Two sources with identical bpp (0.0437) shrank 49% vs 17%, so bpp classifies
files but does not predict the ratio. Notes the audio floor (a 33.7% video stream still yields a 53%
file because AAC dominates what is left) and why VP9/AV1 sources have no headroom (copy the video).
Three silent failures on a network-mounted share: a 403 MB upload that wrote 12.5 MB and returned OK
(the timeout toast arrived minutes later, asynchronously), an os.replace() that never landed while
getsize()/mtime served cached metadata (the destination was still the original H.264 file), and a
byte-count source check that agreed with a length-preserving bad copy. Adds read-back hashing at all
three boundaries (source copy, upload, install) and records the metric traps that hid them: a clean
decode test on wrong pictures, SSIM on near-flat frames, input-seek decoding of open-GOP sources,
stream-copy slices dropping frames, and fixed-name scratch files colliding across concurrent runs.
Audit after the fix: reported=30 landed=29 not-landed=0.
The converted HEVC stuttered in VLC, Chrome and on an iPad (offline) while the source played fine.
Container timing was perfect (5818/5818 frame intervals at exactly 0.040000 s, no dup/backward PTS,
ctts not flat) and a full decode printed nothing. Cross-decoder SSIM found the real defect: NVDEC's
legacy av1_cuvid wrapper returns frames from the wrong timestamps - 106 of 5819 frames, SSIM down to
0.330, deterministically, roughly every 30 frames - and the HEVC output was a faithful encode of those
wrong pictures (min 0.991 against the NVDEC decode, min 0.330 against a software decode). Fix is one
line (-hwaccel cuda -hwaccel_output_format cuda -c:v av1, verified 1.000000 over 1500 frames; vp9_cuvid
unaffected). Adds the content gate (structure AND pictures, defect-shaped thresholds) to the pipeline.
1) the-upstream-was-deleted-then-came-back-rewritten (devops, pubDate 2026-10-06)
docker pull hectorqin/reader -> 404; the repo was re-initialised 2026-09-16 and now
carries 233 commits, a TypeScript/Node rewrite, port 5888, SQLite /data, config moved
into the admin UI, and an image on cnb.cool with no tags or releases. Covers telling
dead from rewriting, the migration boundary, and keeping the front door outside the
app image. Facts re-verified live 2026-10-06.
2) putting-a-front-door-on-an-app-you-cant-modify (devops, pubDate 2025-06-24 backdated
into the empty 2025-06 window, updatedDate 2026-10-06 so lastmod stays honest)
The reader-gateway pattern: a second nginx container owning the public port, the
request-time resolver, why a proxy body rewrite cannot touch a client-rendered SPA,
the gate-bounce injection with its pass token, the app's own CSS hook for branding,
and the silent-failure check to run after every app upgrade.
Both: EN + ZH twins, TERMINALS/BANNERS entries appended via append_generator_entries.py
(additive, deletions 0, node --check OK), og/banner generated and measured PASS
(og rows=1 overflow=0 missingHash=0; banner 8 rows, delta 2, overflow 0).
The Phase C1 keystone asset (Story B). Publishes the infra case study:
- architecture: 3 hosts / 162 containers / 78 compose stacks with the per-host split
- incident record: the monitoring panels that lied, and the Passbolt cascade
- how the numbers are re-derived (verify_infra.py) rather than remembered
- no uptime percentage: availability is not measured, so the post says 'monitored'
- hire CTA (case-study convention)
EN + ZH twins, og + banner generated and measured (OG 5 tags/1 row, banner 8 lines delta 2).
Five posts with custom OG + banner and hire CTAs. Three are web3, giving
that category its first posts — /categories/web3/ previously 404'd while the
index advertised it as '0 posts - coming soon'.
Backdated where the work genuinely is older: the foundry-nft and
hardhat-smartcontract-lottery commits date to 2024-08-15..19, so those two
posts fill the empty 2024-10 and 2024-12 archive months with updatedDate
holding the real date. The two 2026-08-19 posts use their real work date.
TERMINALS/BANNERS entries for all five slugs are committed this time (both
generators were clean; diffs verified purely additive).
Backdated into the empty 2025 stretch of the archive (pubDate 2025-07-08 / 2025-03-19)
with the real date kept in updatedDate 2026-09-29 so sitemap lastmod stays honest.
Custom OG + banner for both; no date- or version-pinned prose in either post.
Backdated into the 2026-03-25 -> 2026-09-04 archive gap (pubDate 2026-04-14/05-17/06-24/07-29)
with updatedDate 2026-09-29 holding the real date, so sitemap lastmod stays honest.
Custom OG + banner per post, hire CTA, language switch verified.
- docker/Chrome/CDP gotcha: the container kills the browser, so it never exits
cleanly and no restore mechanism fires (flag, Preferences, managed policy all
verified failing) -> 60s snapshot + replay keeper
- also covers the stale Singleton* lock and custom-cont-init.d permission traps
- custom OG + banner art, EN + ZH, backlog B2 updated
New `devops` post on vetting an upstream dependency before building on it:
the six checks that corrected six assumptions from a 1,306-line architecture
spec — repo vital signs via the GitHub API, grepping for the feature instead
of reading for it (OIDC/SSO/SAML → 0 hits), reading a feature doc's target
branch (white-label lives on `multi-tenant`, not `main`), reading the data
model rather than the feature list (percent/fixed vs five assumed rule types),
the Community-vs-Enterprise tier gate (API tokens free, SSO paid), and whether
the money rail works in-country (selfhost + manual payouts, not Stripe Connect).
Closes with the fallback question and the authentik proxy-provider answer.
- EN: src/content/posts/vetting-an-open-source-dependency-before-you-bet-on-it.md
- ZH: src/content/posts/zh/<same slug>.md (same filename → auto language switch)
- Custom OG (1200x630) + banner (1600x900) art via TERMINALS/BANNERS entries
- pubDate 2026-09-29; build verified 93 pages, 17/17 content checks, listing
order monotonic on /posts/, / and /zh/
Note: the generator maps also carry two entries belonging to parallel
in-flight posts (adding-english-mode…, and the sessions' other slugs);
their post files were left uncommitted.
- migrating-codeigniter-iis-to-openlitespeed (engineering): the two fatal errors
IIS + SSO had been hiding (env() called from Constants.php; parent::__construct
in a controller) — both only surfaced on the first unauthenticated request
- upgrading-codeigniter-46-to-47 (notes): the two undefined config properties the
official upgrade guide cannot warn about (Config\App::$permittedURIChars,
Config\Format::$jsonEncodeDepth)
- both flipped draft:true -> false, pubDate 2026-09-20 -> 2026-09-27 (real publish date)
- generated 1200x630 OG cards + 1600x900 banners for both slugs
- verified before commit: EN+ZH pages build, language switch links both ways,
listing order stays monotonic on /posts, /zh and the homepage, banner terminal
panel centred (gapAbove 102 / gapBelow 104) with no overflow
EN + ZH twins. The recipe for pointing NocoDB at a MySQL/MariaDB database on
another machine: the Docker SNAT source-IP trap (the DB sees the host IP, not
the container IP), a SELECT-only grant restricted to that one host, the async
source-creation API with no job-status route, the auto-sync that makes a manual
table step unnecessary (and the create-table route that makes junk tables), and
what a read-only source costs (no metadata edits, UTC-labelled DATETIMEs).
Also adds the og-gen TERMINALS and banner-gen BANNERS entries for the slug
(keeping the sibling session's entries untouched) and the generated PNGs.
EN + ZH devops gotcha post on debugging MySQL Workbench 26.7.0's failure
to connect to MariaDB. Three patches to Oracle's bundled code, all the
same root cause: `major >= 8` is not a valid MySQL-vs-MariaDB test.
Also adds per-post OG + banner (TERMINALS/BANNERS entries).
Case study of migrating from paid RDPGuard 7.8.7 to open-source IPBan
4.1.0, covering the three undocumented traps: the uninstaller that would
have silently unbanned 12 active attackers, the non-existent
--install-service flag in v4.1.0, and ExpireTime vs BanTime.
Also fixes an og-gen defect: the tag chip hardcoded KIND='DevOps', so
every non-devops post carried a wrong label (e.g. "case-studies · DevOps"
on the STT card). KIND now derives from the post category, and all 29
existing OG images are regenerated with correct badges.
New flagship case study covering a GPU-backed whisper.cpp transcription API
reachable from Windows, iPhone, iPad and Android behind an authenticated
gateway — framed as a service offering with the office-productivity case
(roughly 5x typing throughput, unlimited, audio never leaves the premises).
Content:
- EN + ZH posts (same slug -> auto language switch)
- "Why it matters" opener, hire CTA with clickable WhatsApp + mailto
- Four documented traps: incomplete CUDA component selection, loopback bind
mistaken for a firewall problem, n8n Code nodes discarding binary + the
data0 key name, and nginx default.conf hijacking port 80
- Honest scoping of the auth model (access control, not hardened public API)
Assets:
- Custom OG image + 16:9 banner (generator entries appended, not patched
inside the template-literal maps)
Also marks Mem0 (B1) done and adds B1b to project-state.md.
- New post: 'The Corruption Came Back on Different Drives — the Cause Was
TRIM, Not the SSDs' — same 0x8941f998 zeros fingerprint on a second drive
stack (IronWolf 110 SATA pair), root cause queued TRIM (FreeBSD gag 264139),
fix diskAutotrim=off + nodiscard, scrub evidence, enterprise SATA buying
guidance. en + zh, custom OG + banner.
- Publish formerly-draft SATA cable post (draft:false) with OG + banner.
- Correct drive identity in both: ZA960NM10001 is Seagate IronWolf 110, not
'Samsung PM9A3' (PM9A3 is NVMe; FPDMA errors are SATA-only).
- Old RAID post (en+zh): cross-link to sequel, fix 'a Samsung' -> IronWolf 110.
Three new posts (EN + ZH twins, og + banner each):
- n8n-v1-to-v2-upgrade-gotchas (devops): the seven deprecations that
surfaced upgrading 1.123.x → 2.40.1, decoded from the boot log —
telemetry schema rejection, N8N_WEBHOOK_URL rename, internal runner
deprecation, task timeout 300s→60s, two compression limits, v3
storage rename, plus the DB override that silently disabled the
AI sandbox.
- self-healing-digital-goods-entitlements (case-studies): the W1–W5
NocoDB → n8n → AList entitlement lifecycle. Build-time code sharing
for n8n Code nodes, MAX-expiry semantics, dry-run safety, daily
drift repair, CORS-not-HMAC reasoning, and the public→internal
NocoDB cascading-failure fix (504 → retry storm → 503).
- running-tts-as-a-service-with-token-sidecars (ai): a year-long TTS
service built on two cron containers that refresh Azure/Google
tokens into a shared file, with the speed/voice mapping layer.
banner-gen: center terminal body vertically so line counts shorter
than the fixed 690px panel don't leave a dead void at the bottom.
Verified via DOM measurement (gapAbove 104 / gapBelow 106).