惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
L
LangChain Blog
Simon Willison's Weblog
Simon Willison's Weblog
N
News and Events Feed by Topic
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
WordPress大学
WordPress大学
M
MIT News - Artificial intelligence
A
About on SuperTechFans
Microsoft Security Blog
Microsoft Security Blog
I
Intezer
Know Your Adversary
Know Your Adversary
H
Heimdal Security Blog
博客园 - 叶小钗
B
Blog RSS Feed
F
Fortinet All Blogs
Hacker News: Ask HN
Hacker News: Ask HN
A
Arctic Wolf
小众软件
小众软件
Help Net Security
Help Net Security
MongoDB | Blog
MongoDB | Blog
aimingoo的专栏
aimingoo的专栏
G
Google Developers Blog
Forbes - Security
Forbes - Security
Latest news
Latest news
AI
AI
I
InfoQ
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
CXSECURITY Database RSS Feed - CXSecurity.com
W
WeLiveSecurity
C
Cybersecurity and Infrastructure Security Agency CISA
人人都是产品经理
人人都是产品经理
Cyberwarzone
Cyberwarzone
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
J
Java Code Geeks
Engineering at Meta
Engineering at Meta
C
Cyber Attacks, Cyber Crime and Cyber Security
O
OpenAI News
博客园 - 【当耐特】
T
Threat Research - Cisco Blogs
GbyAI
GbyAI
U
Unit 42
D
Darknet – Hacking Tools, Hacker News & Cyber Security
G
GRAHAM CLULEY
Apple Machine Learning Research
Apple Machine Learning Research
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
T
Threatpost
T
The Blog of Author Tim Ferriss
罗磊的独立博客

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店 GitHub - EdoardoBambini/Agent-Armor-Iaga: AI agents are getting tool access — shell, file system, databases, APIs, secrets. But **nobody is governing what they actually do with it**. Frameworks like LangChain, CrewAI, AutoGen, and Claude Code give agents the power to execute. Agent Armor gives you the power to control, audit, and approve every single action before it happens. HN Vibes — Week 15, Apr 7–13 2026 GitHub - chojs23/ec: Easy terminal-native 3-way git mergetool vim-like workflow GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - JakOb-dotcom/cloud-sandbox-security-analysis: Technical analysis and Proof of Concept (PoC) regarding environment variable exfiltration in containerized cloud sandboxes via side-channel data leaks. Springboards - Flint Alpha Show HN: A simpler coding agent harness GitHub - audiodude/sudomake-friends GitHub - 256thFission/mini-mythos: OSS clone of Anthropic’s Mythos harness to locate C/C++ memory vulnerabilities Show HN: OpenParallax: OS-level privilege separation for AI agent execution Hacker News Sorted - Chrome 应用商店 Show HN: How to Install Docker on Ubuntu 24.04 LTS: Complete 2026 Guide GitHub - himanshudongre/smriti GitHub - sverrirsig/claude-control: macOS desktop dashboard for monitoring and managing multiple Claude Code sessions GitHub - ory/dockertest: Write better integration tests! Dockertest helps you boot up ephermal docker images for your Go tests with minimal work. Chiral - Chrome 应用商店 Show HN: Two Claudes collaborating through shared memory on a $100 mini-PC GitHub - pmichaillat/latex-cv: Minimalist LaTeX template for academic CVs GitHub - oguzbilgic/posse: A web UI for Anthropic Managed Agents. GitHub - sshiraz/depsly: Dependency risk analysis tool for npm packages ABI Add safari/agent-harness — Safari browser automation via safari-mcp by achiya-automation · Pull Request #212 · HKUDS/CLI-Anything GitHub - Halfblood-Prince/trustcheck: Verify PyPI package attestations and improve Python supply-chain security GitHub - oguzbilgic/kern-ai: Agents that do the work and show it. GitHub - bruits/satteri: High-performance Markdown and MDX processing for the JavaScript ecosystem GitHub - tylergibbs1/feedstock: High-performance web crawler and scraper for TypeScript, powered by Bun and Playwright GitHub - Grimm67123/grimmbot: The self-improving sandboxed and open-source AI agent. With persistent memory and scheduling. GitHub - whitevanillaskies/whitebloom: Local whiteboard that blooms. GitHub - hwdsl2/docker-whisper: Docker image for a self-hosted Whisper speech-to-text server with speaker diarization and OpenAI-compatible transcription and translation APIs. Powered by faster-whisper. Supports all Whisper models, NVIDIA GPU (CUDA) acceleration, JSON/SRT/VTT output, SSE streaming, offline mode, and multi-arch (amd64, arm64). GitHub - yisding/reviewwiggum GitHub - MarwanAlsoltany/serrors: Structured errors for Go: sentinel hierarchies, typed data, custom formatting, and slog integration. GitHub - soatok/age-php GitHub - Luthiraa/markitme GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits GitHub - tombedor/excalicharts GitHub - wh1le/excalidraw-edit: Open and edit .excalidraw files from the terminal. Offline, auto-saves to disk. MalExt Sentry - Malicious Extension Scanner - Chrome 应用商店 GitHub - syi0808/asciianimesvg: Generate animated ASCII art SVGs from text. CLI, Rust library, WASM, and web editor. GitHub - zaina-ml/ml_forge: A visual-based graph node editor for training computer vision models. GitHub - anakin87/llm-rl-environments-lil-course: 🌱 A little course on Reinforcement Learning Environments for evaluating and training Language Models GitHub - takaakit/superpowers-uml: Superpowers-UML modifies Superpowers to ensure a software development workflow in which AI agents design through UML modeling. AdriByte Studio - Sviluppo Web e Soluzioni Digitali GitHub - chouligi/angel-copilot: Your personalized Angel Investment Advisor Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 GitHub - agenteractai/lodmem: Level Of Detail Context Management for Agents GitHub - ostefani/subnetlens: A fast, concurrent network scanner with a TUI and plain-text CLI, built in Go. It discovers live hosts on your network, scans their open ports, resolves hostnames, and fingerprints operating systems—delivered. Cyber Pulse: Agentic Intel - Apps on Google Play Whisper API: Self-Hostable Speech to Text Transcription The Agent-Web Protocol Stack: A Research Thesis GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Show HN: Provepy – A Python decorator that proves your code using Lean and LLMs Show HN: Pardonned.com – A searchable database of US Pardons GitHub - patrickdappollonio/dux: Dux is a terminal UI that lets you run multiple AI coding agents side by side, each in its own git worktree, with full companion terminals, macros, commit generation, and a command palette that knows more tricks than you do. kMC Crystal Simulator Show HN: HyperFlow – A self-improving agent framework built on LangGraph GitHub - stef41/vibescore: 🎵 Grade your vibe-coded project. One command, instant letter grade across security, quality, dependencies, and testing. GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. imgur.com GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. GitHub - nowork-studio/toprank: Open-source Claude Code skills for SEO, SEM, Google Ads GitHub - tacomanator/sash: Lightweight macOS menu bar app for reliably cycling through windows of the current application. Appents | Social Media Management for Product-First Teams GitHub - pnhoang/youtube-spam-blocker: Automatically detects and hides spam messages in YouTube Live chat. Set rate limits, keyword filters, and block repeat offenders. GitHub - decisionnode/DecisionNode: CLI + Local MCP - A shared structured memory store across Claude Code, Cursor, Windsurf, Antigravity, and every MCP client. Semantically queryable. GitHub - AvaCodeSolutions/django-email-learning: An open source Django app for creating email-based learning platforms with IMAP integration and React frontend components. The $100K Gap in Kubernetes Security Tooling Function Calling Harness: From 6.75% to 100%
GitHub - dzfrias/xxUTF: Fast Unicode normalization and case folding routines for UTF-8 and UTF-16 using SIMD. All in a small, simple C library.
dzfrias · 2026-06-01 · via Hacker News: Show HN

xxUTF is a C library that implements Unicode text transformation algorithms at speed using SIMD. Current algorithms supported:

All algorithms are compatible with UTF-8, UTF-16LE, and UTF-16BE. Further helper functions are defined for efficient and correct streaming versions of these algorithms. See the API for details.

xxUTF never allocates memory, does not depend on libc, cannot fail, and has the fastest open source implementations of the listed algorithms available. All functions are comprehensively tested using both the available Unicode test suites and a fuzzer.

xxUTF supports Unicode 16.0.0 and below.

Usage

xxUTF is distributed as an amalgamation with a single header file, available at the release page. This is similar to what SQLite does.

Example C program:

#include <xxutf.h>
#include <string.h>
#include <stddef.h>
#include <stdio.h>

int main() {
  const char *s = "Ȁ character that needs to be decomposed";
  size_t length = strlen(s);
  printf("Old length: %zu\n", length);
  char out[64];
  size_t out_len = xxutf_normalize_utf8_nfd(s, strlen(s), out);
  printf("New length: %zu\n", out_len);
  return 0;
}

One major goal of xxUTF is to have the simplest, most predictable API surface as possible. As such, one function call usually suffices for the core functionality.

API

The xxUTF's core API follows this pattern:

/// Normalize the Unicode text bytes in the given normalization form, returning the
/// length of the output. All lengths are measured in bytes. The input is expected
/// to be valid under the specified normalization form.
///
/// It is assumed that the output buffer is large enough to fit the full normalized
/// form of the input. The encoding of the output will match the encoding of the
/// input. Note that, regardless of if the input is encoded in UTF-16 or UTF-8, the
/// input is still a byte pointer. xxUTF does not require the input to be aligned,
/// and the performance difference is marginal even if it is.
size_t xxutf_normalize_ENCODING_FORM(const uint8_t *input, size_t length, uint8_t *out);
/// Get the size of the output buffer needed to normalize the input. The input is
/// expected to be valid under the specified normalization form.
///
/// Note that for NFC and NFKC, the returned size is actually an upper bound
/// calculated from the input, not the exact size. This is the case for speed reasons.
/// All lengths are measured in bytes.
size_t xxutf_normalize_ENCODING_FORM_length(const uint8_t *input, size_t length);

/// Case fold the Unicode text bytes, returning the length of the output. All
/// lengths are measured in bytes. The input is expected to be valid under the
/// specified normalization form.
///
/// It is assumed that the output buffer is large enough to fit the full case folded
/// form of the input. The encoding of the output wil match the encoding of the input.
/// Note that, regardless of if the input is encoded in UTF-16 or UTF-8, the input is
/// still a byte pointer. xxUTF does not require the input to be aligned, and the
/// performance difference is marginal even if it is.
size_t xxutf_casefold_ENCODING(const uint8_t *input, size_t length, uint8_t *out);
/// Get the size of the output buffer needed to case fold the input. All lengths are
/// measured in bytes. The input is expected to be valid under the specified
/// normalization form.
size_t xxutf_casefold_ENCODING_length(const uint8_t *input, size_t length);

The valid encodings are:

  • utf8
  • utf16le
  • utf16be

The valid normalization forms are:

  • nfd
  • nfc
  • nfkd
  • nfkc

For example:

size_t out_length = xxutf_normalize_utf16le_nfkc_length(input, length);
// ...maybe re-allocate according to `out_length`...
(void)xxutf_normalize_utf16le_nfkc(input, length, out);

Like many Unicode processing libraries, xxUTF supports a two-pass pattern:

  1. Get the expected length of the output without writing.
  2. Actually run the algorithm on a properly sized output buffer.

You might wonder why we need the length functions. After all, finding a universal upper bound that depends only on the size of the input is not hard. But using such a bound is often wasteful. For example, as of Unicode 18.0, the largest compatibility decomposition (i.e. from NFKD or NFKC) in the Basic Multilingual Plane is from the character with code 0xFDFA. This character is three bytes wide in UTF-8 pre-decomposition, but expands to an enormous 33 bytes post-decomposition. The best upper bound for NFKD and NFKC in UTF-8 would thus be some number around n * 11 where n is the size of the input.

So, unless a lot of prior information is known about the incoming text, use the length functions to make sure buffer overflows don't happen.

Streaming

The streaming versions of some Unicode algorithms can usually be implemented naively (such as with case folding). However, not all algorithms have such nice properties.

Mainly, normalizing text in a streaming manner requires some care. The problem is that normalization forms are not closed under string concatenation. In other words:

normalize(x) + normalize(y) = normalize(x + y)

does not hold for all Unicode strings x and y. Read the Unicode normalization specification for more details.

xxUTF thus has special APIs so that streaming normalization can be implemented in a non-allocating, efficient way. To see these APIs being used to implement streaming normalization, read the xxu program source code.

The APIs are of the form:

size_t xxutf_find_last_stable_ENCODING_FORM(const char *input, size_t length);
size_t xxutf_find_first_stable_ENCODING_FORM(const char *input, size_t length);

Here is a simple visual that describes these functions' purposes:

[.........*.........] ++ [....*.........]

Where ++ represents concatenation, and * denotes "stable" code points (the actual definition of "stable" is somewhat involved). To properly concatenate these normalized buffers, we must:

  1. Naively concatenate the two buffers
  2. Form a range using the last stable code point of the first buffer and the first stable code point in the second buffer (use streaming APIs for this)
  3. Re-normalize the range found from step 2, in place

Performing these steps without copying large buffers around can be complicated to figure out, so you are encouraged to read the xxu source code.

xxu

xxUTF also provides the xxu tool, which puts the speed of the xxUTF library onto the command line. You can download the tool from the releases page, or build it from source.

Example xxu usage:

Benchmarks

xxUTF is benchmarked using a variety of large real-world inputs from multiple languages. As there are many factors to consider during benchmarking, curious users are encouraged to run the benchmark suite (or write their own benchmarks) on their machines.

These are the results for running NFD normalization on UTF-8 on a machine supporting ARM NEON. Inputs vary in size and complexity, so cross-input comparison is not meaningful here.

Benchmarks are compared against the ICU4C library, as ICU4C has the current next fastest open source implementations of these algorithms.

Building

xxUTF is built with the Zig build system, version 0.16.0.

To build the project in release mode, run zig build -Doptimize=ReleaseFast. The following artifacts will be created:

  • zig-out/lib/libxxutf.a: a static library defining the xxUTF functions
  • zig-out/include/xxutf.h: the xxUTF header file
  • zig-out/bin/xxu: the xxu tool

To create the amalgamation file, run zig build amalgamate. It will be put in zig-out/amalgamation.c.

Running the benchmarks is as simple as running zig build bench. But note that ICU4C is required to exist on your system. Make sure that the installed versions match the Unicode version that xxUTF is built for.

For all available build options, run zig build --help.

Fuzzing

xxUTF is fuzz tested to improve correctness and safety. To look into the exact fuzzing setup, see the relevant README file.

State of the Project

xxUTF is ready for use as a library, but as it is in an alpha state, there is much to be done, such as:

  • Support more SIMD instruction sets. Although not many instruction sets are supported right now, the good news is that xxUTF is still the fastest implementation even when in scalar mode.
  • Double check possible security vulnerabilities
  • Add a few helper functions to the API (functions to check if strings are in a certain normalization form, check string equality in normalized forms, Turkic casefold, etc.)

License

xxUTF is licenced under the MIT license.