10 interesting stories served every morning and every evening.

openai.com

How to Exist

www.raptitude.com

Here’s an ex­per­i­ment for a true dare­devil.

Sit there for a three min­utes, fol­low­ing two rules:

Don’t do any­thing.

Be con­tent.

By don’t do any­thing,” I mean don’t move, don’t fid­get, don’t in­dulge any thoughts or day­dreams. You’re al­lowed to breathe, and blink.

By be con­tent,” I mean be com­pletely okay with your ex­pe­ri­ence of do­ing noth­ing. Don’t try to change any­thing, and don’t get im­pa­tient with what’s hap­pen­ing. Be com­pletely okay for three min­utes.

Try that now. See how long it takes be­fore you’re dy­ing for it to be over.

It’s oddly dif­fi­cult to do noth­ing, and while you’re do­ing noth­ing, it’s oddly dif­fi­cult to feel at ease. There’s such a strong urge to do some­thing: look around the room, re­hash a con­ver­sa­tion, ex­plore your in­cisors with your tongue, wig­gle your toes, any­thing. When you stop do­ing every­thing and just ex­ist, you al­most feel like you’re dy­ing.

This is a crazy thing to no­tice af­ter hav­ing been alive so many years — that your ex­is­tence it­self is so much to bear. There’s al­ways some­thing wrong, even when every­thing’s fine. It’s as if you can only bear the pre­sent mo­ment when you’re try­ing change it into some­thing else.

This is the strange con­di­tion of the hu­man be­ing. It’s al­ler­gic to its nat­ural habi­tat, which is the pre­sent mo­ment. In or­der to cope with this al­lergy, it per­pet­u­ally seeks things: feel­ings and ex­pe­ri­ences that are not yet pre­sent. It wants to al­ways be get­ting the hell out of here.

You might think that you’re free from this prob­lem some­times, at least in those mo­ments when you get the thing you’re seek­ing. Say you’re fi­nally eat­ing the cookie-dough ice cream flurry you looked for­ward to all day. If you pay close at­ten­tion as you eat it, you’ll no­tice that you want to move past this mo­ment too. Lingering on any one spoon­ful too long be­comes un­bear­able. There’s a pow­er­ful drive to go on to the next one. That’s why you or­dered a Large.

This most fun­da­men­tal prob­lem of hu­man life is so easy to over­look be­cause our en­tire lives are made of the cop­ing strat­egy. So much of what we seek is solely to flee the ex­pe­ri­ence of be­ing here. People buy things they don’t need, start fights with their part­ners, eat when they’re not hun­gry, and scroll mis­er­able and inane con­tent, just to es­cape the feel­ing of ex­is­tence as it al­ready is.

Notice the pow­er­ful urge to sip your drink or fid­dle with some­thing when the con­ver­sa­tion dies at a din­ner party. Or how quickly your phone comes out when there’s an un­ex­pected wait. Existence with­out do­ing is bru­tal!

Each year, roughly 100 fire­fight­ers are con­victed of ar­son in North America, of­ten on mul­ti­ple counts. Most of­ten they are young, new fire­fight­ers, frus­trated by the lack of ac­tion.

And hi­lar­i­ously, from a 2014 study on do­ing noth­ing:

In 11 stud­ies, we found that par­tic­i­pants typ­i­cally did not en­joy spend­ing 6 to 15 min­utes in a room by them­selves with noth­ing to do but think, that they en­joyed do­ing mun­dane ex­ter­nal ac­tiv­i­ties much more, and that many pre­ferred to ad­min­is­ter elec­tric shocks to them­selves in­stead of be­ing left alone with their thoughts.

In 11 stud­ies, we found that par­tic­i­pants typ­i­cally did not en­joy spend­ing 6 to 15 min­utes in a room by them­selves with noth­ing to do but think, that they en­joyed do­ing mun­dane ex­ter­nal ac­tiv­i­ties much more, and that many pre­ferred to ad­min­is­ter elec­tric shocks to them­selves in­stead of be­ing left alone with their thoughts.

Even think­ing is of­ten a sneaky way of es­cap­ing the ex­is­tence; ru­mi­na­tion is­n’t so much about try­ing to solve your prob­lems, as it is about go­ing else­where in your mind to es­cape anx­i­ety and un­cer­tainty. Apparently, elec­tric shocks work even bet­ter.

How to be­come more com­fort­able with ex­is­tence

You can de­velop the abil­ity to ex­ist a lot more com­fort­ably. You do it by prac­tic­ing ex­ist­ing, a few sec­onds at a time, with­out try­ing to change any­thing about how ex­is­tence feels right now.

Basically you sit, do noth­ing, and no­tice how it feels to do noth­ing. (It will prob­a­bly feel sub­tly weird and un­set­tled.) You then see if you can com­pletely em­brace these feel­ings, with­out the usual squirm­ing and look­ing else­where. But you’ll do it only for a few sec­onds at a time, us­ing your breath as a mea­sur­ing stick.

Here’s how to do it with­out feel­ing over­whelmed:

(If you have PTSD or any other psy­chi­atric dis­or­der, check with a pro­fes­sional be­fore you do this.)

Sit, eyes open or closed, and re­lax your body as com­pletely as pos­si­ble. Take long, easy breaths. Relax every mus­cle you can. Just do your best.

When you’re ready, breathe in while keep­ing the body sup­ple like that. Open to every feel­ing that oc­curs dur­ing the in­breath: tin­gling, weird­ness, un­set­tled­ness, doubt, what­ever. Let the whole ex­pe­ri­ence wash over you like warm surf, for that few sec­onds it takes to in­hale.

Let it go. Give your­self a mo­ment.

When you’re ready, do it again: em­brace the en­tire ex­pe­ri­ence of one in­breath. Just let the whole ex­pe­ri­ence hap­pen to you — no need to study it, or fig­ure it out. Just em­brace the whole bou­quet of feel­ings, for the few sec­onds it takes. Push away noth­ing, just for that few sec­onds of breath­ing in.

Once you can do that de­cently well (no need to be per­fect), try the same thing but with an out­breath. Stay re­laxed and open through­out the length of one whole out­breath. No de­fend­ing, no tens­ing. Be a hu­man pud­dle.

If you get dis­tracted or fraz­zled, or you do tense up, that’s okay. Take a few breaths off to rec­ol­lect your­self. Then try again. You have in­fi­nite breaths to try this with.

Repeat this process, one half-breath (an in­hale or an ex­hale) at a time. The half-breath is a small enough span of time that you can usu­ally stay open for the 5 – 10 sec­onds it takes. Once you can do it on both an in­breath and an out­breath, see if you can start string­ing them to­gether, stay­ing open through­out the whole breath­ing cy­cle.

Do this for five min­utes at first, in­clud­ing any breaks. Then see what hap­pens when you do it longer, and with fewer gaps. Basically you’ll be rest­ing — just ex­ist­ing and breath­ing — in that non-de­fen­sive state.

Even af­ter one ses­sion of this, you might no­tice you can re­lax a lit­tle more eas­ily, no mat­ter what’s hap­pen­ing.

This is a form of med­i­ta­tion, but I al­most want to avoid that word be­cause it makes peo­ple get ner­vous and over­com­pli­cate it. Just think of this prac­tice as ex­ist­ing with­out fear, for a few sec­onds at a time. Minimum ef­fec­tive dose is one half-breath.

Naturally, if you can learn to calm your al­lergy to ex­is­tence a bit, life gets eas­ier in nearly every sit­u­a­tion. Ordinary ex­pe­ri­ences like wait­ing in line, feel­ing un­cer­tain, be­ing a bit too warm or cold, or not be­ing sure what to do with your­self, be­come much more tol­er­a­ble. (And prob­a­bly most of life con­tains this sort of mi­nor dis­com­fort.)

Regular prac­tice keeps your al­lergy symp­toms mild. Neglecting it makes them come back.

In par­tic­u­lar, you might no­tice much less of a need to en­ter­tain or dis­tract your­self. Escape-driven habits like doom­scrolling, ran­dom snack­ing, nail-bit­ing, (arson?), and ru­mi­na­tion be­come less mag­netic. When plain old ex­is­tence feels okay, there’s so much you no longer need to do.

***

Because We Can

weeraman.com

Twenty-five years ago, I made my first do­na­tion to an open source pro­ject and pur­chased a CD with an op­er­at­ing sys­tem as down­load­ing a few hun­dred megabytes over a 14.4kbps dial-up was­n’t very fun. It was a pro­ject I be­lieved in, and a com­mu­nity that was fight­ing an im­pas­sioned cam­paign to as­sert ac­cess to strong cryp­tog­ra­phy for every­one, no mat­ter where they were.

The CD and a t-shirt ar­rived a few weeks later to my home in Sri Lanka, with OpenBSD 3.0. The t-shirt fea­tured the iconic puffer fish on the front. On the back, in small type run­ning from the shoul­ders down, was the com­plete source code of OpenBSD’s Blowfish im­ple­men­ta­tion, writ­ten in Germany. Written in the United States, it would have been clas­si­fied as a weapon.

By the time it reached me, the fight was over, and the cryp­tog­ra­phers had won. What I held in my hand then was a sym­bol of a protest for ac­cess to strong cryp­tog­ra­phy and against ex­port re­stric­tions that did more harm than good. Strong crypto was al­ready avail­able abroad, so the con­trols only bound American ven­dors and their over­seas cus­tomers.

Today the re­flex is back. The fears have changed. The worry is now cy­ber ca­pa­bil­ity, bi­ol­ogy and mod­els that do things no­body asked them to do. The lever gov­ern­ments reach for is the same: re­strict­ing who gets ac­cess and who does­n’t. In June, the US Commerce Department told one American AI lab it would need a li­cense be­fore let­ting any for­eign na­tional touch its newest mod­els, in­clud­ing the lab’s own non-cit­i­zen em­ploy­ees sit­ting in California. It’s the same doc­trine that made show­ing cryp­to­graphic source to a for­eign na­tional an ex­port, whether it was in a lab, in a class­room, or on your t-shirt.

Not all of the worry is the­atre. Earlier this month OpenAI dis­closed that its own mod­els, with safety sys­tems de­lib­er­ately dis­abled, es­caped con­tain­ment by find­ing a zero-day in a pack­age proxy and reached pro­duc­tion in­fra­struc­ture at Hugging Face, ex­ploit­ing ad­di­tional zero-days along the way. Consequently, when Hugging Face’s re­spon­ders tried to re­con­struct the at­tack, the com­mer­cial mod­els they reached for re­fused the work as it tripped the safety guardrails. They fin­ished the in­ves­ti­ga­tion on GLM 5.2, a Chinese open-weight model, run­ning on their own hard­ware. A de­ter­mined at­tacker is not bound by us­age poli­cies. The de­fend­ers are. Restrictions writ­ten for safety are mak­ing de­fend­ers less safe.

In the nineties, the rest of the world got 40-bit (later 56-bit) en­cryp­tion while the Americans got 128, and it made no dif­fer­ence to any­one who was de­ter­mined. The con­trols bound the law-abid­ing and no­body else. That is the asym­me­try. The de­ter­mined will have the fron­tier. The rest of us are asked to go with­out, and told it is for our safety.

The OpenBSD team did­n’t work around the ex­port con­trols. They arranged the pro­ject so that the con­trols could­n’t reach it. Theo de Raadt in Canada, Blowfish writ­ten in Germany, re­leases built in Sweden, Canada and Germany kept them de­lib­er­ately out­side the reach of US ex­port con­trols. The pro­ject openly asked non-Amer­i­can cryp­tog­ra­phers to come and help, and American de­vel­op­ers, as the story goes, would cross the bor­der to Canada to work on the sys­tem and bring the re­sults home legally. Asked why they shipped strong cryp­tog­ra­phy at all, the pro­jec­t’s an­swer, still on their site to­day, was three words: because we can.”

The same arrange­ment is be­ing made now, at a na­tional scale. Mistral, DeepSeek, Moonshot and Zhipu pub­lish weights that, once down­loaded, no ex­port let­ter can re­call. The sov­er­eignty ar­gu­ment that used to live in Brussels think tanks is now gov­ern­ment pol­icy, ac­cel­er­ated by watch­ing ac­cess to a fron­tier model with­drawn world­wide by let­ter.

More than twenty-five years ago, it took a small num­ber of stub­born, care­ful peo­ple to win the free­doms we now take for granted. What ar­rived in my let­ter­box af­ter two weeks on a CD can be down­loaded to­day in fif­teen min­utes, by any­one, from any­where, and no­body asks where you live. That is what win­ning looked like. I think fron­tier AI ends up in the same place. But it will not hap­pen by it­self. Last time, some­one put the source on a t-shirt.

The Prototype Isn't the Product

weeraman.com

Building soft­ware has never felt this ac­ces­si­ble. You de­scribe an idea in plain English, and within min­utes, a work­ing pro­to­type ap­pears on your screen. It has a UI. It con­nects to a data­base. It does the thing you imag­ined. For some­one who has never writ­ten a line of code, that mo­ment feels like magic. For some­one who has spent years wrestling with com­pil­ers and stack traces, it’s gen­uinely as­ton­ish­ing.

The pro­to­type runs on your lap­top. It breaks un­der load. It has no er­ror han­dling. You find out that it may be leak­ing your API to­kens. The data model made sense for the demo but falls apart the mo­ment you add a sec­ond user. The au­then­ti­ca­tion is held to­gether with as­sump­tions. There’s a nag­ging worry whether every­thing is se­cure. You want to de­ploy it, and sud­denly you’re star­ing at a chasm be­tween this works” and this is ready.”

Getting to a pro­to­type was never the hard part

Software en­gi­neers have al­ways been able to get some­thing run­ning quickly. What took time was every­thing else: de­sign­ing sys­tems that hold up at scale, han­dling the cases users weren’t sup­posed to en­counter but in­evitably do, build­ing in ob­serv­abil­ity so you know when things break, mak­ing de­lib­er­ate de­ci­sions about data ar­chi­tec­ture that you’ll re­gret less three years from now. None of that has changed. AI has dra­mat­i­cally ac­cel­er­ated the path to a first work­ing ver­sion. It has not short­ened the dis­tance be­tween a first work­ing ver­sion and some­thing pro­duc­tion-grade.

The con­fu­sion arises be­cause the feed­back loop for the early part of the jour­ney has be­come so fast and so re­ward­ing. You ask, you re­ceive, you see re­sults. That cy­cle is gen­uinely ex­cit­ing, and it cre­ates the im­pres­sion that the rest of soft­ware de­vel­op­ment must be sim­i­larly com­pressed. It is­n’t. The hard prob­lems of build­ing soft­ware were never pri­mar­ily about writ­ing syn­tax. They were about judg­ment: what to build, how to struc­ture it, what to de­fer, when to say no. That judge­ment is what turns a vibe-coder into a sculp­tor, and an ar­ti­san. It is also what dif­fer­en­ti­ates a pro­to­type from a pro­duc­tion-grade sys­tem.

The mis­guided case against learn­ing com­puter sci­ence

Predictably, the ac­ces­si­bil­ity of AI-generated code has sparked a wave of new en­trants to the in­dus­try who are ques­tion­ing whether it still makes sense to learn com­puter sci­ence. If you can de­scribe your way to a work­ing ap­pli­ca­tion, why spend years study­ing al­go­rithms, data struc­tures, op­er­at­ing sys­tems, and the­ory?

The value of a com­puter sci­ence ed­u­ca­tion was never purely in the abil­ity to pro­duce code. It was in de­vel­op­ing a men­tal model of how sys­tems be­have, how they fail, and why. That model is what al­lows you to look at AI-generated code and rec­og­nize that the query it wrote will cause a full table scan on a table with fifty mil­lion rows. It’s what al­lows you to see that the caching strat­egy it pro­posed will cre­ate a race con­di­tion un­der con­cur­rent load. It’s what tells you that the ar­chi­tec­ture it sug­gested solves the prob­lem you de­scribed but will make the next prob­lem sig­nif­i­cantly harder.

Without that foun­da­tion, you are en­tirely de­pen­dent on the mod­el’s judg­ment. And mod­els don’t have judg­ment. They have pat­tern match­ing, with an ea­ger­ness to pro­duce code that it be­lieves matches your in­tent. They will con­fi­dently gen­er­ate code that looks right, fol­lows con­ven­tion, and fails in pro­duc­tion in ways that take days to di­ag­nose if you don’t know what you’re look­ing for.

Now is ar­guably the best time in his­tory to learn com­puter sci­ence, be­cause the gap be­tween un­der­stand­ing and out­put has col­lapsed. A stu­dent who gen­uinely grasps how a dis­trib­uted sys­tem works can now build one in a frac­tion of the time it would have taken a decade ago.

What changes, and what does­n’t

The de­mand for en­gi­neers who can only write code me­chan­i­cally, and who trans­lates re­quire­ments into im­ple­men­ta­tions line by line, are gen­uinely de­clin­ing. That part of the job is be­ing au­to­mated.

What’s hap­pen­ing is a com­pres­sion of the lower end of the pro­duc­tiv­ity dis­tri­b­u­tion and an ex­pan­sion of the ceil­ing for those at the top. An ex­pe­ri­enced en­gi­neer us­ing mod­ern AI tools can move at a pace that would have been unimag­in­able five years ago. Not be­cause the hard prob­lems have dis­ap­peared, but be­cause the me­chan­i­cal work that con­sumed so much time and at­ten­tion is largely han­dled. More hours in the day for the work that ac­tu­ally re­quires ex­per­tise.

The en­gi­neers who will be left be­hind are not those who lack AI skills. They’re the ones who use AI as a sub­sti­tute for un­der­stand­ing, who vibe-code their way through sys­tems they can’t rea­son about, and then find them­selves un­able to fix what breaks, un­able to scale what grows, un­able to ex­plain what they built to any­one who needs to main­tain it.

Learning to op­er­ate at a dif­fer­ent level

The shift re­quired is­n’t about adopt­ing a new set of tools. It’s about op­er­at­ing at a higher level of ab­strac­tion while keep­ing your roots in the fun­da­men­tals. That com­bi­na­tion is gen­uinely pow­er­ful and gen­uinely rare.

The en­gi­neers who will leapfrog their peers in the next few years are the ones who treat AI as a force mul­ti­plier on deep knowl­edge rather than a re­place­ment for it. They un­der­stand what they’re ask­ing the model to pro­duce. They re­view gen­er­ated code with the same crit­i­cal eye they’d ap­ply to a ju­nior en­gi­neer’s pull re­quest. They bring ar­chi­tec­tural think­ing to the con­ver­sa­tion, not just fea­ture de­scrip­tions. They know when to push back on what the model sug­gests.

It’s the old skill set, ap­plied to a new con­text, with dra­mat­i­cally higher lever­age.

The pro­to­type is the easy part. The dif­fer­ence now is that every­one can see that clearly. What comes af­ter the pro­to­type is still hard, still re­quires real en­gi­neer­ing judg­ment, and still sep­a­rates the builders who ship re­li­able soft­ware from the ones who ship demos.

Learn the fun­da­men­tals. Then learn the new tools. In that or­der.

A Visualization Language for the AI Era

microsoft.github.io

Usage Page $$ to Token Amount? WHAT?

forum.cursor.com

July 31, 2026, 4:52pm

1

I just no­ticed Cursor Usage win­dow switched from $$ to Token amount. I use this Usage win­dow closely to keep tabs on my daily/​ac­tive spend­ing, not from the spend­ing over­all page. Today, the $$ amount is re­placed by to­ken amount which is com­pletely use­less. Any way to re­vert back to $$ amount as I can’t seem to find this in set­tings or else­where. Is it just me, or does Cursor feel like it’s more buggy than be­fore, ie. auto se­lect sub agents de­spite hav­ing the de­fault sub­agent setup.

Kaleb_Maul

(Kaleb Maul)

July 31, 2026, 4:59pm

4

I am also miss­ing the $$ on the us­age page. I don’t un­der­stand why things are be­ing moved around ran­domly, and now I can’t ac­cess my us­age data any­more. I could­n’t find any dev an­nounce­ments about this from to­day but will keep search­ing. Hopefully they will fix this is­sue or tell us where this data has been moved to.

eli.wavv

(Eli Smith)

July 31, 2026, 5:27pm

6

Cursor needs to be trans­par­ent about the per-re­quest cost if that is what we are be­ing billed for(with on-de­mand us­age). This is un­ac­cept­able and makes it im­pos­si­ble for team mem­bers to track their own per­sonal us­age when work­ing on a team with a shared on-de­mand us­age cap.

Kris_Gunnars

(Kris Gunnars)

July 31, 2026, 7:11pm

7

I’m also see­ing this. The dol­lar break­down is sud­denly GONE from the us­age page. Cursor, please fix this im­me­di­ately.

kevinn

(Kevin Neilson)

July 31, 2026, 7:23pm

9

Thanks for flag­ging this. There is­n’t cur­rently a set­ting to switch back to dol­lar amounts for in­di­vid­ual plans. Enterprise Plans will still show dol­lar amounts here, but in­di­vid­ual plans will not. This is de­lib­er­ate de­sign be­cause of the dif­fer­ences in how en­ter­prise plans are struc­tured (pooled us­age) vs. in­di­vid­ual plans with in­cluded us­age. We did briefly dis­play dol­lar amounts for in­di­vid­ual plans, but that led to some con­fu­sion be­cause the dol­lar amounts dis­played were of­ten higher amounts than the user’s plan cost (due to the gen­er­ous in­cluded us­age of the Cursor in­di­vid­ual plans).

Ultra runs on us­age-based (token) pric­ing. On that model, any­thing cov­ered by your plan shows to­ken counts and is marked Included” be­cause noth­ing is charged for it. Usage you ac­tu­ally pay for, mean­ing on-de­mand be­yond your in­cluded amount, still shows a dol­lar fig­ure in the Cost col­umn. That split is the in­tended de­sign.

Where to find the dol­lars:

Dashboard > Spending shows an On-Demand Spending fig­ure for your cur­rent cy­cle. That is the num­ber match­ing what you will be billed.

Dashboard > Usage, set your date range, then Export CSV. The Cost col­umn has dol­lar amounts for every on-de­mand row. If it’s part of your in­cluded us­age of your plan, it won’t show a dol­lar amount but rather the word Included”.

kevinn

(Kevin Neilson)

July 31, 2026, 7:28pm

10

One fol­low up here: You’re prob­a­bly re­fer­ring to the ex­plore sub­agent model choice, which is one type of sub­agent. Agents can spin up other types of sub­agents with dif­fer­ent model choices, here’s more info on that: Sub agents trig­gers even when dis­abled and uses Opus for no rea­son - #5 by kevinn

Axel_Trange

(Axel Trange)

July 31, 2026, 7:30pm

11

I know count­less of Cursor users who used this Spending Graph fea­ture dozens of times a day to keep track of their bud­get. Now you’re com­pletely hid­ing the cost. Who cares about to­kens? It’s ir­rel­e­vant as it’s highly dif­fer­ent to each model. Please don’t tell me and my team we have to write a cus­tom script to break down the bud­get from your .csv be­cause you fa­vor ob­scu­rity

Kris_Gunnars

(Kris Gunnars)

July 31, 2026, 7:31pm

13

Hey Kevin, I’m on the Teams plan and I have mul­ti­ple em­ploy­ees on the plan with a com­bined us­age cost of 30K USD in the cur­rent billing cy­cle. Almost all of our spend is based on API pric­ing. How can I track the per-user and per-model spend like be­fore???

Axel_Trange

(Axel Trange)

July 31, 2026, 7:42pm

15

Suggestion: Just in­clude a tog­gle or drop­down but­ton to en­able this. You can de­fault to Tokens” if you pre­fer. But at least give the op­tion to show the old $$ graph that so many users are ac­cus­tomed to

kevinn

(Kevin Neilson)

July 31, 2026, 7:48pm

16

To shed a lit­tle more light on this change, a change shipped to­day made the Usage page to­kens-only for self-serve plans, in­clud­ing Teams. The Spend met­ric and Cost col­umn were re­moved, and the Usage CSV no longer con­tains dol­lar costs.

@Kris_Gunnars As a Teams ad­min, you can still use Dashboard > Members > On-Demand for per-user on-de­mand to­tals. However, there is cur­rently no per-model dol­lar break­down for self-serve Teams and in­di­vid­ual plans.

Kris_Gunnars

(Kris Gunnars)

July 31, 2026, 7:52pm

17

I hope you will re­vert this change be­cause I think it is a ter­ri­ble prod­uct de­ci­sion. I liked hav­ing the per-day, per-model and per-re­quest break­down and I looked at this screen sev­eral times per day. Now it’s just gone for no good rea­son. Just see­ing each user’s to­tal is not even re­motely as use­ful to me.

JPPIX4D

July 31, 2026, 7:35pm

18

Until to­day, https://​cur­sor.com/​api/​dash­board/​get-fil­tered-us­age-events re­turned per-re­quest cost fields (chargedCents, us­age­Based­Costs, to­kenUsage.to­tal­Cents). As of 2026 – 07-31 these are ze­roed out (chargedCents: 0, us­age­Based­Costs: $0.00”, to­tal­Cents omit­ted) — for all events, in­clud­ing his­tor­i­cal ones that pre­vi­ously showed real val­ues, and in­clud­ing on-de­mand us­age I am ac­tu­ally billed for.

I’m on a Teams plan with us­age-based pric­ing en­abled. I need per-re­quest costs to eval­u­ate model ef­fi­ciency and con­trol spend. The pe­riod to­tals still ex­ist, so the data is clearly still tracked in­ter­nally.

Please re­store per-re­quest cost fields in the API (and the dash­board cost col­umn). Transparency about what I’m be­ing charged per re­quest is not op­tional for a me­tered prod­uct — re­mov­ing it retroac­tively breaks any in­de­pen­dent cost track­ing.

kevinn

(Kevin Neilson)

July 31, 2026, 8:44pm

19

Hi @JPPIX4D Thank you for the post. I un­der­stand the frus­tra­tion, es­pe­cially since you built re­port­ing around these fields, and the change also af­fects his­tor­i­cal re­sults.

This was an in­ten­tional change, not a tem­po­rary re­port­ing is­sue. Usage re­port­ing for self-serve plans, in­clud­ing Teams, is now to­ken-based, so dol­lar val­ues are no longer re­turned by the dash­board Usage end­point. Because this is ap­plied when records are read, his­tor­i­cal re­sults are af­fected, too.

I rec­og­nize that ag­gre­gate billing to­tals are not equiv­a­lent to the cost data you were us­ing. For Teams ad­mins, the sup­ported Admin API still pro­vides spend­ing data and cost fields for us­age events.

Kaleb_Maul

(Kaleb Maul)

July 31, 2026, 8:46pm

20

On 7/30/2026 I was able to view my cost data in the us­age tab and even ex­port it along with the other data as per usual. On 7/31/2026 the cost col­umn com­pletely dis­ap­peared from my us­age tabs table. Checking fur­ther I saw that the col­umn still ex­ists when you ex­port your us­age data, but the cost for every record is set to 0.0. Even with ad­min ac­cess there is no stream­lined way to view the cost data per user, why would this be re­moved? It is so sketchy to be re­mov­ing some­thing like this and very frus­trat­ing. Is any­one else ex­pe­ri­enc­ing this is­sue? If so, is there a workaround for it or do we just sit, suf­fer, and hope that cur­sor stops be­ing so shady?

Kaleb_Maul

(Kaleb Maul)

July 31, 2026, 9:09pm

22

This does not re­ally make a lot of sense for me. So, the Cursor team de­cided yes­ter­day that they want to hide all cost data for non-en­ter­prise cus­tomers when they had ac­cess to it pre­vi­ously? I would love an ex­pla­na­tion as to how this ben­e­fits cur­rent non-en­ter­prise cus­tomers and how this helps with any con­fu­sion re­gard­ing us­age costs. Additionally, can I get a di­rect link to the spe­cific end­point used to grab the cost data for a range of dates for a spe­cific user?

Archit

July 31, 2026, 9:12pm

23

I agree. This feels like a step back for trans­parency. Even on the Individual plan, the dol­lar fig­ure was some­thing I reg­u­larly re­lied on to gauge roughly how much $ worth I was us­ing on a daily, weekly, or monthly ba­sis.

If the worry is that peo­ple mis­take that num­ber for an ac­tual charge, maybe there’s a way to fix that with­out los­ing the dol­lar fig­ure al­to­gether. Eg: show­ing a clear split in the chart be­tween what’s in­cluded in the plan and what would ac­tu­ally show up on the bill. That way the num­ber stays use­ful, but it’s un­am­bigu­ous which part is cov­ered us­age and which part is a real charge.

@kevinn I hope the team re­con­sid­ers this de­ci­sion or im­proves the vi­su­al­iza­tion to re­duce con­fu­sion while be­ing trans­par­ent.

GeorgeRay

(George Ray)

July 31, 2026, 9:38pm

24

That is too bad. I liked see­ing the dol­lar amount. I looked at that dol­lar amount as the value (cost sav­ings) I was get­ting from us­ing Cursor.

Pavel_Savva

(Pavel Savva)

August 1, 2026, 3:32am

25

(post deleted by au­thor)

Mihai_Cracan

(Mihai Cracan)

August 1, 2026, 8:06am

Software for One - Adam Waxman

www.ajwaxman.com

In 2020, Robin Sloan wrote about BoopSnoop, a mes­sag­ing app he built for his fam­ily. Four peo­ple down­loaded it. He con­sid­ered this a re­sound­ing suc­cess. His point was sim­ple: an app can be a home-cooked meal. You don’t need scale. You don’t need users. You cook for the peo­ple you love.

The app took him a week to build, half of it lost to code-sign­ing pur­ga­tory. He wrote: In a bet­ter world, I would have built this in a day, us­ing some kind of mod­ern, flex­i­ble HyperCard for iOS.”

The time is now

Six years later, the es­say resur­faced on X when Thariq wrote that personal soft­ware was a bit early in 2020 but in 2026, it re­ally can be as per­sonal as a home cooked meal, or a hand­writ­ten let­ter.”

Lee Robinson wrote about the same shift. AI has made personal com­put­ing” ac­tu­ally per­sonal. He and his wife built a baby tracker be­cause they did­n’t need user pro­files, badges, sub­scrip­tion tiers, or any other ex­tra fea­tures.”

My smoothie knows my mileage

I spent the past six months build­ing way too much per­son­al­ized soft­ware:

A sleep app that runs our sleep con­sul­tan­t’s plan

A fit­ness app that sizes my smoothie to that morn­ing’s run

A marathon plan built from my races, not my age

A Duolingo for jazz” that quizzes me on chord voic­ings from my pi­ano lessons

A med­ical records tool that flagged gaps be­fore a spe­cial­ist visit

Our sleep con­sul­tan­t’s plan ar­rived as a PDF full of con­di­tional logic: wake win­dows, nap caps, what to do when a nap fails. Turning it into an app took a week of evenings. Now my wife, our nanny, and I share one live sched­ule that re-plans it­self when a nap runs short.

The sleep app in ac­tion

My fit­ness app is built around my goals and con­nects data sources in a way no sin­gle app can. It knows my weekly run sched­ule, cour­tesy of the marathon app be­low, so it ad­justs my daily calo­rie tar­gets based on that morn­ing’s run dis­tance and in­ten­sity. It tells me how many ex­tra carbs and pro­tein to eat be­fore and af­ter long runs, and re­minds me to carb load the night be­fore. It knows my smoothie recipe, eight in­gre­di­ents I weigh out every morn­ing, and sizes each por­tion to that day’s train­ing.

The fit­ness app in ac­tion

My run­ning app skips the plan tem­plates and de­rives every­thing from my Strava his­tory and race re­sults, in­clud­ing heart rate zones com­puted from races I ran in­stead of a for­mula in­volv­ing my age.

The run­ning app in ac­tion

Sloan’s sov­er­eignty point holds up too. There will be no sud­den re­design, no flood of ads, no pivot to chase a user­base in­scrutable to us.” My wife’s fa­vorite fea­ture in the sleep app will be there as long as she wants it.

My stack

I’m been us­ing the same stack for a cou­ple years now and con­tinue to love it. It lets me build fast and gives me full con­trol over im­ple­men­ta­tion de­tails.

There are plenty of other great ways to do this, in­clud­ing less tech­ni­cal tools like Claude Artifacts, Replit, and Lovable that can get you a work­ing app with­out touch­ing a ter­mi­nal.

Cost

The whole thing costs me about $160/mo: $100 for Claude Code Max, $10 in Anthropic API us­age, $20 for Vercel, and $30 for Neon.

That’s prob­a­bly more than I’d pay for sub­scrip­tions to all these apps com­bined. But the bulk of the cost is my Claude sub­scrip­tion, which I’d keep re­gard­less. Most of the Neon and API costs come from my slightly larger pro­jects, ny­c­jazz.guide and Claude Code Daily, not the per­sonal apps. Before I up­graded from Claude Pro to Max it was un­der $100/mo.

Most of these ser­vices have gen­er­ous free tiers, so if you’re run­ning one or two apps you could likely keep it to a $20/mo agen­tic cod­ing sub­scrip­tion and ~$5 – 10/mo in model API us­age.

Learnings

The cost to build dropped off a cliff. The sleep app took a week of evenings. The fit­ness app took a week­end. The jazz quiz took a sin­gle evening af­ter the kids went to bed. A year or two ago I would­n’t have con­sid­ered build­ing any of these: too slow to build, even harder to main­tain. Imagination is now the lim­it­ing fac­tor.

The cost to build dropped off a cliff. The sleep app took a week of evenings. The fit­ness app took a week­end. The jazz quiz took a sin­gle evening af­ter the kids went to bed. A year or two ago I would­n’t have con­sid­ered build­ing any of these: too slow to build, even harder to main­tain. Imagination is now the lim­it­ing fac­tor.

Maintenance is sur­pris­ingly easy. At least so far. Sloan’s es­say has a run­ning gag in its yearly up­dates: I have added one (1) fea­ture, at my moth­er’s re­quest.” In 2020 that made sense, be­cause each change cost him a fight with Xcode. I’ve found fix­ing bugs, adding new fea­tures and de­pen­dency bumps to be eas­ier than ever. 9/10 times a feed­back screen­shot shared with Claude gets the job done.

Maintenance is sur­pris­ingly easy. At least so far. Sloan’s es­say has a run­ning gag in its yearly up­dates: I have added one (1) fea­ture, at my moth­er’s re­quest.” In 2020 that made sense, be­cause each change cost him a fight with Xcode. I’ve found fix­ing bugs, adding new fea­tures and de­pen­dency bumps to be eas­ier than ever. 9/10 times a feed­back screen­shot shared with Claude gets the job done.

Aggregate data, add an LLM. The cost drop does­n’t just mean more apps, it means apps can be far more per­sonal. Most of mine fol­low the same shape: pull data from mul­ti­ple sources, com­bine it in one place, and use an LLM to gen­er­ate in­sights from the full pic­ture. My fit­ness app com­bines nu­tri­tion, sleep, weight, and train­ing data that lives in four sep­a­rate apps, then uses that con­text to make rec­om­men­da­tions none of them could alone. I think this pat­tern will spread to pro­fes­sional tools too.

Aggregate data, add an LLM. The cost drop does­n’t just mean more apps, it means apps can be far more per­sonal. Most of mine fol­low the same shape: pull data from mul­ti­ple sources, com­bine it in one place, and use an LLM to gen­er­ate in­sights from the full pic­ture. My fit­ness app com­bines nu­tri­tion, sleep, weight, and train­ing data that lives in four sep­a­rate apps, then uses that con­text to make rec­om­men­da­tions none of them could alone. I think this pat­tern will spread to pro­fes­sional tools too.

Ephemeral is fine. We used the sleep app for about four months. Our son sleeps through the night now, so we re­tired it. If the app had taken me months to build, that might sting. Because it took a week, I’m just glad it worked when we needed it.

Ephemeral is fine. We used the sleep app for about four months. Our son sleeps through the night now, so we re­tired it. If the app had taken me months to build, that might sting. Because it took a week, I’m just glad it worked when we needed it.

AI floods big mar­kets and un­locks small ones. Yes, AI pro­duces end­less de­riv­a­tive apps. But the same tools also let me build apps for my house­hold that no com­pany would bother mak­ing. Beyond my house­hold, I built ny­c­jazz.guide for NYC jazz fans and claude­codedaily.com for Claude Code de­vel­op­ers, au­di­ences too small for a busi­ness but worth serv­ing.

AI floods big mar­kets and un­locks small ones. Yes, AI pro­duces end­less de­riv­a­tive apps. But the same tools also let me build apps for my house­hold that no com­pany would bother mak­ing. Beyond my house­hold, I built ny­c­jazz.guide for NYC jazz fans and claude­codedaily.com for Claude Code de­vel­op­ers, au­di­ences too small for a busi­ness but worth serv­ing.

Good APIs mat­ter more than ever. I switched from Cronometer to FatSecret be­cause FatSecret had a bet­ter API. My fit­ness app pulls from Strava, Oura, Withings, and FatSecret, and the qual­ity of each in­te­gra­tion de­pends on how well the API is de­signed. As more peo­ple build per­sonal soft­ware, users will ex­pect their apps to have APIs and MCPs worth con­nect­ing to.

Good APIs mat­ter more than ever. I switched from Cronometer to FatSecret be­cause FatSecret had a bet­ter API. My fit­ness app pulls from Strava, Oura, Withings, and FatSecret, and the qual­ity of each in­te­gra­tion de­pends on how well the API is de­signed. As more peo­ple build per­sonal soft­ware, users will ex­pect their apps to have APIs and MCPs worth con­nect­ing to.

Building is the point, not just the re­sult. These apps solve real prob­lems for me and the peo­ple I care about: how well our son sleeps, my health, my run­ning. That part is re­ward­ing. But I also spend my evenings af­ter the kids are asleep build­ing these in­stead of watch­ing Netflix or scrolling X. It’s my pre­ferred source of en­ter­tain­ment now.

Building is the point, not just the re­sult. These apps solve real prob­lems for me and the peo­ple I care about: how well our son sleeps, my health, my run­ning. That part is re­ward­ing. But I also spend my evenings af­ter the kids are asleep build­ing these in­stead of watch­ing Netflix or scrolling X. It’s my pre­ferred source of en­ter­tain­ment now.

It’s not just fun. It’s ad­dic­tive. Agentic cod­ing has slot ma­chine me­chan­ics. You’re one prompt away from the next fea­ture or un­lock, so you keep pulling. The irony is­n’t lost on me: I’ve ru­ined more than a few nights of sleep build­ing apps to im­prove my health.

It’s not just fun. It’s ad­dic­tive. Agentic cod­ing has slot ma­chine me­chan­ics. You’re one prompt away from the next fea­ture or un­lock, so you keep pulling. The irony is­n’t lost on me: I’ve ru­ined more than a few nights of sleep build­ing apps to im­prove my health.

Looking ahead

My ap­proach is still too tech­ni­cal for most peo­ple. You need to be com­fort­able with a ter­mi­nal, a data­base, and de­ploy­ment pipelines. But I don’t think that lasts. Sam Altman posted re­cently about send­ing ChatGPT a sin­gle mes­sage from his phone: plan a trip for nine friends, build a site to co­or­di­nate, draft the in­vite email. It worked. The prompt was one para­graph long.

If that’s where the tools are head­ing, build­ing per­sonal soft­ware won’t re­quire a de­vel­op­er’s stack for much longer. I kept build­ing these apps be­cause no app in the App Store knows my smoothie recipe, my race his­tory, or my sleep con­sul­tan­t’s rules. I think that frus­tra­tion is com­mon. Once the bar­rier drops far enough, a lot of peo­ple will build their own.

And once you use an app that ac­tu­ally knows your con­text, the generic ver­sion feels bro­ken. I would­n’t be sur­prised if truly per­son­al­ized be­comes the new base­line con­sumer ex­pec­ta­tion.

Sloan wished for some kind of mod­ern, flex­i­ble HyperCard for iOS.” He got some­thing stranger: you de­scribe what you want in plain English, and an agent builds it. His bet­ter world has ar­rived.

BMW Spider-Man in-car advertising - Consumer Rights Wiki

consumerrights.wiki

From Consumer Rights Wiki

On July 27, 2026, BMW be­gan de­liv­er­ing a full-screen Spider-Man: Brand New Day movie ad­ver­tise­ment to the dash­board Control Display (the car’s main cen­ter screen) of cus­tomer BMW ve­hi­cles, plac­ing a branded third-party ad­ver­tise­ment in cars their own­ers had al­ready bought.[1][2] The ad­ver­tise­ment ap­pears as a ban­ner at car startup that the dri­ver clicks to play a full-screen an­i­ma­tion with back­ing mu­sic and an am­bi­ent-light­ing light show, and it has been avail­able in more than 70 mar­kets since July 27, 2026, sched­uled to run through August 10, 2026, on suit­ably equipped ve­hi­cles run­ning BMW Operating System 7, 8, 8.5, 9, or OS X built af­ter July 2020.[1][3] As re­cently as December 2023, BMWs con­nected-com­pany se­nior vice pres­i­dent Stephan Durach had stated on record that the com­pany would not sell in-car screen space to play a com­mer­cial, call­ing the car a pri­vate space.[4] BMW de­scribed the an­i­ma­tion to The Autopian as part of a broader brand part­ner­ship with the film, the au­to­mo­tive slice of a Sony Pictures pro­mo­tional cam­paign that Deadline val­ued at a record $309 mil­lion in world­wide me­dia value.[2][5]

BMW put an ad­ver­tise­ment in a car the owner al­ready paid for: a full-screen Spider-Man: Brand New Day movie ad de­liv­ered to the dash­board Control Display of cus­tomer ve­hi­cles.[1][2]

The ad has been avail­able in more than 70 mar­kets since July 27, 2026, sched­uled to run through August 10, 2026, on any suit­ably equipped BMW run­ning Operating System 7, 8, 8.5, 9, or OS X built af­ter July 2020.[1][3]

It ap­pears as a ban­ner at startup that the dri­ver clicks to play, with back­ing mu­sic and an am­bi­ent-light­ing light show.[1][2]

The an­i­ma­tion was the au­to­mo­tive part of a Sony Pictures pro­mo­tional cam­paign that Deadline val­ued at a record $309 mil­lion in world­wide me­dia value.[5]

BMW has a doc­u­mented pat­tern of mon­e­tiz­ing hard­ware and fea­tures af­ter the sale of the ve­hi­cle. In 2020 the com­pany an­nounced a sub­scrip­tion that charged dri­vers a re­cur­ring fee to ac­ti­vate the heated seats al­ready fit­ted to their cars.[6] Forbes de­scribed that heated-seat sub­scrip­tion as con­tro­ver­sial, and BMW dropped it in 2023 in a re­ver­sal of the prac­tice. Forbes re­ported the re­ver­sal, quot­ing BMW board mem­ber Pieter Nota on the prac­tices the com­pany would aban­don.[6] The heated-seat episode sits in the same fam­ily as Features on de­mand, the broader prac­tice of gat­ing ca­pa­bil­ity a buy­er’s car al­ready con­tains be­hind a pay­wall.

Two months af­ter drop­ping the heated-seat sub­scrip­tion, BMW ad­dressed a sep­a­rate ques­tion: whether it would put ad­ver­tis­ing on the screens in­side its cars. At a December 2023 round­table, Stephan Durach, se­nior vice pres­i­dent for con­nected com­pany de­vel­op­ment at BMW Group, ruled it out. BMWBLOG re­ported his po­si­tion, quot­ing the ex­ec­u­tive:

To say I’m sell­ing the screen to play a com­mer­cial. I don’t see it. It’s a pri­vate space.

To say I’m sell­ing the screen to play a com­mer­cial. I don’t see it. It’s a pri­vate space.

[4]

BMWs own PressClub re­lease de­scribed the ad­ver­tise­ment as a spe­cial sur­prise for dri­vers, timed to the Spider-Man: Brand New Day film, which pre­miered on July 27, 2026 and was re­leased ex­clu­sively in cin­e­mas on July 31, 2026.[1] Starting the car brings up a ban­ner in the Control Display; click­ing it ac­ti­vates a full-screen an­i­ma­tion with back­ing mu­sic and a light show de­liv­ered through the ve­hi­cle’s am­bi­ent light­ing sys­tem.[1] The Autopian’s Jason Torchinsky re­ported that the ban­ner ap­pears at startup with an op­tion to play the ad­ver­tise­ment or not, rather than au­to­play­ing.[2]

The an­i­ma­tion has been avail­able in more than 70 mar­kets since July 27, 2026, a lim­ited win­dow sched­uled to close on August 10, 2026.[1] Eligibility was broad. Any suit­ably equipped BMW run­ning BMW Operating System 7, 8, 8.5, 9, or OS X, with a pro­duc­tion date af­ter July 2020, could re­ceive it.[1] BMWBLOGs Horatiu Boeriu in­de­pen­dently con­firmed the same win­dow, the 70-market reach, and the op­er­at­ing-sys­tem and build-date re­quire­ment.[3]

BMW framed the ad­ver­tise­ment as a ben­e­fit rather than an in­tru­sion, pre­sent­ing it as tied to the film part­ner­ship rather than as com­mer­cial con­tent pushed into the ve­hi­cle. Asked about the de­ploy­ment, BMW told The Autopian in an emailed state­ment:

The in-ve­hi­cle an­i­ma­tion is part of a broader brand part­ner­ship with the film. A few of our ve­hi­cles, in­clud­ing the BMW iX3, were in the film, and a spe­cial edi­tion iX3 was fea­tured on the red car­pet dur­ing last night’s pre­miere in Los Angeles.

The in-ve­hi­cle an­i­ma­tion is part of a broader brand part­ner­ship with the film. A few of our ve­hi­cles, in­clud­ing the BMW iX3, were in the film, and a spe­cial edi­tion iX3 was fea­tured on the red car­pet dur­ing last night’s pre­miere in Los Angeles.

[2]

Torchinsky, writ­ing for The Autopian, ob­jected to the de­ploy­ment on own­er­ship grounds, fram­ing the ad­ver­tise­ment as some­thing im­posed on prop­erty the dri­ver had paid for. He drew a com­par­i­son to a home­owner mak­ing mort­gage pay­ments:

I own a house, and I make pay­ments to a mort­gage com­pany every month, and I’m pretty sure it would be il­le­gal for that mort­gage com­pany to put a fuck­ing Spider-Man bill­board in my yard, fac­ing my front win­dows. Is what BMW is do­ing any dif­fer­ent?

I own a house, and I make pay­ments to a mort­gage com­pany every month, and I’m pretty sure it would be il­le­gal for that mort­gage com­pany to put a fuck­ing Spider-Man bill­board in my yard, fac­ing my front win­dows. Is what BMW is do­ing any dif­fer­ent?

[2]

The Autopian also noted that BMW had al­ready been forced to walk back an ear­lier post-sale mon­e­ti­za­tion push, the heated-seat sub­scrip­tion, af­ter buy­ers re­acted against it.[2]

Torchinsky placed BMWs move along­side ear­lier in-car ad­ver­tis­ing from Stellantis, which he wrote had done the same be­fore BMW.[2] The Spider-Man an­i­ma­tion was the au­to­mo­tive com­po­nent of a Sony Pictures pro­mo­tional cam­paign that Deadline re­ported at a world­wide me­dia value of $309 mil­lion, de­scribed as an all-time record for any Hollywood film and ahead of Sony’s pre­vi­ous $288 mil­lion record set by Spider-Man: Far From Home.[5] Deadline named BMW as a global part­ner that wove its Neue Klasse iX3 and 5 Series Sedan into the film.[5]

BMW

BMWs heated seat sub­scrip­tion

Features on de­mand

↑ 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 1.10 Phil DiIanni (2026 – 07-28). BMW brings mod­ern mo­bil­ity to the Sony Pictures film Spider-Man™: Brand New Day”″. BMW Group PressClub USA. Retrieved 2026 – 07-31.

↑ 2.00 2.01 2.02 2.03 2.04 2.05 2.06 2.07 2.08 2.09 2.10 Jason Torchinsky (2026 – 07-28). BMW Is Showing Commercials On Their Car’s Dash Screens And They Want You To Think It’s A Treat”. The Autopian. Retrieved 2026 – 07-31.

↑ 3.0 3.1 3.2 Horatiu Boeriu (2026 – 07-28). BMW Built a One-Off iX3 for the New Spider-Man Movie”. BMWBLOG. Retrieved 2026 – 07-31.

↑ 4.0 4.1 4.2 4.3 Adrian Padeanu (2023 – 12-15). BMW Won’t Put Ads Inside Your Car”. BMWBLOG. Retrieved 2026 – 07-31.

↑ 5.0 5.1 5.2 5.3 5.4 Anthony D’Alessandro (2026 – 07-30). Spider-Man: Brand New Day’s $309 Million Promo Partner Campaign Is A Hollywood Record”. Deadline. Archived from the orig­i­nal on 2026 – 07-30. Retrieved 2026 – 07-31.

↑ 6.0 6.1 Alistair Charlton (2023 – 09-07). BMW Drops Controversial Heated Seats Subscription, To Refocus On Software Services”. Forbes. Retrieved 2026 – 07-31.

x86_64-unknown-linux-musl binaries occasionally segfault during very-large searches

github.com

Please tick this box to con­firm you have re­viewed the above.

I have a dif­fer­ent is­sue.

What ver­sion of rip­grep are you us­ing?

rip­grep 15.2.0 (rev e89fff8)

fea­tures:+pcre2 simd(com­pile):+SSE2,-SSSE3,-AVX2 simd(run­time):+SSE2,+SSSE3,+AVX2

PCRE2 10.45 is avail­able (JIT is avail­able)

How did you in­stall rip­grep?

I orig­i­nally en­coun­tered this bug in the rg bun­dled with OpenAI Codex. That bi­nary is byte-for-byte iden­ti­cal with the one in https://​github.com/​BurntSushi/​rip­grep/​re­leases/​down­load/​15.2.0/​rip­grep-15.2.0-x86_64-un­known-linux-musl.tar.gz and I’ve re­pro­duced the bug from that in­de­pen­dently of any Codex de­pen­dency. For the analy­sis be­low, I built rg-15.2 with de­bug sym­bols in­cluded by way of CROSS_CONTAINER_ENGINE=podman CARGO_PROFILE_RELEASE_DEBUG=true ~/.cargo/bin/cross build –release –target x86_64-un­known-linux-musl.

What op­er­at­ing sys­tem are you us­ing rip­grep on?

OpenSUSE Tumbleweed Linux x86_64

Describe your bug.

Ripgrep built for x86_64-un­known-linux-musl oc­ca­sion­ally crashes with a SIGSEGV when search­ing very-large trees at a high de­gree of con­cur­rency. The crash­ing line is an in­tegrity as­ser­tion re­gard­ing heap meta­data in­side MUSLs mal­locng, in a cal­loc call made from opendir. The com­plete back­trace is be­low.

What are the steps to re­pro­duce the be­hav­ior?

Having a suf­fi­ciently large search tree seems to be es­sen­tial for re­pro­duc­tion. Run the at­tached gen­er­ate_re­pro_tree.py. This is an LLM-written pro­gram which pro­duces a tree full of ran­dom files which mimic the sta­tis­tics of the repo in which I orig­i­nally en­coun­tered the bug. It will pro­duce a tree con­tain­ing roughly 20GiB of data across 1.8M files.

Then from the root of that tree, run rg in a loop, search­ing for some ar­bi­trary lit­eral string that is­n’t pre­sent in the tree: while true; do rg tno­heue­unot­shis­nthukoethn­sueothn­si­uothone­suioseuinth; done. On my 24-core sys­tem, hav­ing enough free RAM for the search tree to fit in the ker­nel’s block cache, it typ­i­cally takes about a minute for the SIGSEGV to ap­pear.

What is the ac­tual be­hav­ior?

I get a core­dump with the fol­low­ing back­trace:

#0 get_meta () at ../src_musl/src/malloc/mallocng/meta.h:141 #1 __malloc_allzerop () at ../src_musl/src/malloc/mallocng/malloc.c:384 #2 0x00007f71f8381b2d in cal­loc () at ../src_musl/src/malloc/calloc.c:41 #3 0x00007f71f83810f4 in opendir () at ../src_musl/src/dirent/opendir.c:15 #4 0x00007f71f835c133 in std::sys::fs::unix::read­dir::{clo­sure#0} () at li­brary/​std/​src/​sys/​fs/​unix.rs:2081 #5 std::sys::helpers::smal­l­_c_string::run_with­_c­str_s­tack<*mut libc::unix::DIR> () at li­brary/​std/​src/​sys/​helpers/​smal­l­_c_string.rs:48 #6 std::sys::helpers::smal­l­_c_string::run_with­_c­str<*mut libc::unix::DIR> () at li­brary/​std/​src/​sys/​helpers/​smal­l­_c_string.rs:28 #7 std::sys::helpers::smal­l­_c_string::run_­path_with­_c­str<*mut libc::unix::DIR> () at li­brary/​std/​src/​sys/​helpers/​smal­l­_c_string.rs:18 #8 std::sys::fs::unix::read­dir () at li­brary/​std/​src/​sys/​fs/​unix.rs:2081 #9 std::sys::fs::read­_dir () at li­brary/​std/​src/​sys/​fs/​mod.rs:68 #10 0x00007f71f8206b5c in std::fs::read­_dir<&std::path::Path> (path=…) at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/std/src/fs.rs:3265 #11 ig­nore::walk::Work::read­_dir (self=0x7f71f5bfeb20) at crates/​ig­nore/​src/​walk.rs:1551 #12 ig­nore::walk::Worker::run_one (self=0x7f71f5bfef08, work=…) at crates/​ig­nore/​src/​walk.rs:1749 #13 ig­nore::walk::Worker::run (self=…) at crates/​ig­nore/​src/​walk.rs:1697 #14 0x00007f71f821c866 in ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure#0} () at crates/​ig­nore/​src/​walk.rs:1463 #15 std::sys::back­trace::__rust_be­gin_short­_back­trace<ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure_env#0}, ()> (f=…) at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/std/src/sys/backtrace.rs:166 #16 0x00007f71f8224596 in std::thread::life­cy­cle::spawn_unchecked::{clo­sure#1}::{clo­sure#0}<ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure_env#0}, ()> () at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/std/src/thread/lifecycle.rs:70 #17 core::panic::un­wind_safe::{impl#23}::cal­l_once<(), std::thread::life­cy­cle::spawn_unchecked::{clo­sure#1}::{clo­sure_env#0}<ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure_env#0}, ()>> (self=…) at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/core/src/panic/unwind_safe.rs:275 #18 std::pan­ick­ing::catch_un­wind::do_­call<core::panic::un­wind_safe::As­ser­tUn­wind­Safe<std::thread::life­cy­cle::spawn_unchecked::{clo­sure#1}::{clo­sure_env#0}<ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure_env#0}, ()>>, ()> (data=<error read­ing vari­able: Cannot ac­cess mem­ory at ad­dress 0x0>) at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/std/src/panicking.rs:581 #19 std::pan­ick­ing::catch_un­wind<(), core::panic::un­wind_safe::As­ser­tUn­wind­Safe<std::thread::life­cy­cle::spawn_unchecked::{clo­sure#1}::{clo­sure_env#0}<ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure_env#0}, ()>>> (f=…) at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/std/src/panicking.rs:544 #20 std::panic::catch_un­wind<core::panic::un­wind_safe::As­ser­tUn­wind­Safe<std::thread::life­cy­cle::spawn_unchecked::{clo­sure#1}::{clo­sure_env#0}<ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure_env#0}, ()>>, ()> (f=…) at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/std/src/panic.rs:359 #21 std::thread::life­cy­cle::spawn_unchecked::{clo­sure#1}<ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure_env#0}, ()> () at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/std/src/thread/lifecycle.rs:68 #22 core::ops::func­tion::FnOnce::cal­l_once<std::thread::life­cy­cle::spawn_unchecked::{clo­sure_env#1}<ig­nore::walk::{impl#15}::visit::{clo­sure#0}::{clo­sure#1}::{clo­sure_env#0}, ()>, ()> () at /home/dfranke/.rustup/toolchains/stable-x86_64-unknown-linux-gnu/lib/rustlib/src/rust/library/core/src/ops/function.rs:250 #23 0x00007f71f8361fcf in al­loc::boxed::{impl#31}::cal­l_once<(), (dyn core::ops::func­tion::FnOnce<(), Output=()> + core::marker::Send), al­loc::al­loc::Global> () at li­brary/​al­loc/​src/​boxed.rs:2275 #24 std::sys::thread::unix::{impl#2}::new::thread­_s­tart () at li­brary/​std/​src/​sys/​thread/​unix.rs:118 #25 0x00007f71f8388788 in start () at ../src_musl/src/thread/pthread_create.c:207 #26 0x00007f71f8389e6c in __clone () at ../src_musl/src/thread/x86_64/clone.s:22

Here is the core dump and the cor­re­spond­ing rg bi­nary which pro­duced it.

What is the ex­pected be­hav­ior?

Not a seg­fault.

A Surveillance Treaty in Disguise: The Trouble With Canada's Quiet Decision to Sign the UN Cybercrime Convention - Michael Geist

www.michaelgeist.ca

༒ Nhac Ny ༒, CC BY-SA 4.0 , via Wikimedia Commons

July 23, 2026

Last week, the gov­ern­ment an­nounced that Canada has signed the United Nations Convention against Cybercrime, with Ministers Anita Anand, Gary Anandasangaree and Sean Fraser tout­ing the treaty’s child pro­tec­tion pro­vi­sions and hu­man rights safe­guards, which were de­scribed as among the strongest found in an in­ter­na­tional crim­i­nal jus­tice treaty.” The an­nounce­ment, re­leased in mid-July with few pay­ing at­ten­tion, left out much of the story. The re­al­ity is that the con­ven­tion is not pri­mar­ily a cy­ber­crime treaty at all, but rather a sweep­ing cross-bor­der sur­veil­lance and elec­tronic ev­i­dence-shar­ing agree­ment that Canada orig­i­nally op­posed, that lead­ing hu­man rights groups and twenty Canadian or­ga­ni­za­tions and ex­perts urged the gov­ern­ment to re­ject, and that key al­lies have thus far de­clined to sign. While sign­ing the con­ven­tion does not cre­ate bind­ing oblig­a­tions (that re­quires rat­i­fi­ca­tion), the de­ci­sion to sign a treaty that the gov­ern­ment de­clined to sign at the of­fi­cial cer­e­mony less than a year ago raises trou­bling ques­tions. This post seeks to an­swer three of them: what is this treaty, what are the risks, and what, if any­thing, changed in the last nine months?

The treaty be­gan as a Russian ini­tia­tive in 2017, de­signed to dis­place the Council of Europe’s Budapest Convention, the long­stand­ing cy­ber­crime frame­work that Russia re­fuses to join. When the UN General Assembly voted in 2019 to launch ne­go­ti­a­tions, Canada joined the United States and European Union in op­pos­ing the res­o­lu­tion, warn­ing that the process was a ve­hi­cle for ex­pand­ing state sur­veil­lance pow­ers. Having lost that vote, the democ­ra­cies faced an un­com­fort­able choice: boy­cott the ne­go­ti­a­tions and let Russia, China, and Iran write the rules, or en­gage from within and try to limit the dam­age. They chose en­gage­ment with Canada among the most ac­tive del­e­ga­tions press­ing for hu­man rights safe­guards. The strat­egy suc­ceeded in keep­ing the au­thor­i­tar­ian bloc’s wish list of speech and con­tent crimes out of the fi­nal text be­fore the con­ven­tion was adopted by con­sen­sus in December 2024.

Yet de­spite lim­it­ing the dam­age, Canada was a no-show at the sign­ing cer­e­mony in Hanoi last October, joined by the U.S., New Zealand, Japan, the Netherlands, Italy, Norway, Denmark, and Finland. Signatories in­cluded Russia, China, Iran, North Korea, Belarus, Cuba, Venezuela, and Saudi Arabia, as well as the United Kingdom, Australia, France, Germany, and the European Union. Canada is­sued a state­ment that em­pha­sized the treaty’s suc­cess rests on states’ com­mit­ment to full ap­pli­ca­tion of the hu­man rights safe­guards in the text.” Nine months later, the gov­ern­ment signed with­out ex­plain­ing what had changed.

Canada’s pre­vi­ous con­cern with the treaty is well placed. While it enu­mer­ates a list of cy­ber­crime of­fences, its pro­ce­dural pow­ers ap­ply to elec­tronic ev­i­dence of any crim­i­nal of­fence, and its in­ter­na­tional co­op­er­a­tion oblig­a­tions ex­tend to any serious crime,” de­fined as any of­fence pun­ish­able by four or more years’ im­pris­on­ment un­der do­mes­tic law. Since some states im­pose such penal­ties for crit­i­cism of the gov­ern­ment, jour­nal­ism, blas­phemy, or same-sex re­la­tion­ships, the treaty ef­fec­tively con­verts re­pres­sive do­mes­tic laws into trig­gers for cross-bor­der ev­i­dence gath­er­ing. Further, the Electronic Frontier Foundation, Human Rights Watch and a coali­tion of lead­ing dig­i­tal rights groups have all warned that the con­ven­tion func­tions as a global sur­veil­lance pact since it re­quires states to es­tab­lish real-time in­ter­cep­tion and data col­lec­tion pow­ers while leav­ing out safe­guards such as prior ju­di­cial au­tho­riza­tion to the dis­cre­tion of do­mes­tic law, per­mit­ting gag or­ders on co­op­er­a­tion re­quests, and omit­ting a po­lit­i­cal of­fence ex­cep­tion.

In December 2024, nearly two dozen Canadian or­ga­ni­za­tions and ex­perts, in­clud­ing Amnesty International Canada, the Criminal Lawyers’ Association, PEN Canada, OpenMedia, and the Citizen Lab’s Ron Deibert and Kate Robertson, is­sued a de­tailed let­ter urg­ing the gov­ern­ment not to sign. The let­ter warned that the treaty would cre­ate a stand­ing chan­nel for transna­tional re­pres­sion tar­get­ing di­as­pora com­mu­ni­ties in Canada and ex­plained how the con­ven­tion could sub­vert the safe­guards built into Canada’s mu­tual le­gal as­sis­tance frame­work. Robertson has sep­a­rately warned that the treaty is poised to be­come a ve­hi­cle for com­plic­ity in the mer­ce­nary spy­ware trade, while over 120 se­cu­rity re­searchers cau­tioned that its of­fences threaten to crim­i­nal­ize good-faith se­cu­rity re­search. Despite the con­cerns, the gov­ern­ment has said noth­ing, with no pub­lic con­sul­ta­tion pre­ced­ing the sig­na­ture and none of the let­ter’s con­cerns ad­dressed in the an­nounce­ment.

So what changed and why sign now? It is not clear that any­thing has changed and the con­cerns that an­i­mated Canada’s de­ci­sion to not sign nine months ago are still there. One the­ory is that this is linked to law­ful ac­cess. Indeed, the treaty and the law­ful ac­cess agenda are mu­tu­ally re­in­forc­ing, since rat­i­fi­ca­tion will re­quire im­ple­ment­ing leg­is­la­tion fea­tur­ing pre­cisely the ex­panded pro­duc­tion or­ders and cross-bor­der data shar­ing pow­ers found in Bill C-22. Lawful ac­cess was al­ready a source of con­cern, and this only makes it worse. Canada al­ready has the Budapest Convention and bi­lat­eral treaties cov­er­ing co­op­er­a­tion with the coun­tries it wants to work with, mean­ing the new con­ven­tion’s mar­ginal value lies chiefly in co­op­er­a­tion with the very states, in­clud­ing Russia, China, and Iran, that cre­ate its great­est risks. The en­tire de­ci­sion, in­clud­ing sign­ing in the mid­dle of the sum­mer when few are pay­ing at­ten­tion, is deeply trou­bling and re­quires far more than a sunny press re­lease that avoids the hard ques­tions the treaty raises.

To add this web app to your iOS home screen tap the share button and select "Add to the Home Screen".

10HN is also available as an iOS App

If you visit 10HN only rarely, check out the the best articles from the past week.

Visit pancik.com for more.