source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
THURSDAY, SEPTEMBER 24, 2026
Hacker News3936X 主题热门3829CNBC72YahooFinance66aihot619to5Mac51Verge50MacRumors49IGN47Kotaku39TechCrunch29AndroidAuthority27Engadget249to5Google22NintendoLife22Gematsu20ArsTechnica18Eurogamer18BusinessInsider17USAToday17Wccftech17Guardian16WarhammerCommunity15FoxBusiness14Investor'sBusinessDaily14Polygon14Fortune13PushSquare13TechPowerUp12NBC11NPR11SeekingAlpha11CBS10CNN10Gizmodo10GSMArena10ABC9CNET9Mashable9Notebookcheck9VideoGamesChronicle9AppleInsider8BleepingComputer8MotleyFool8NintendoEverything8PureXbox8VideoCardz8Yahoo8bgr7CoinDesk7Fox7NewYorkPost6Conversation6Aftermath5AlJazeera5AndroidPolice5Deadline5HollywoodReporter5InsiderGaming5XBOXWire5PetaPixel5PlayStationLifeStyle5Pokemon5SouthChinaMorningPost5TechSpot5Tom'sGuide5WIRED5GamesIndustry.biz4Motor14Nature4RockPaperShotgun4RPGSite4SamMobile4SlashGear4Hacker4UploadVR4Variety4WSB-TV4404Media3AndroidCentral3BellofLostSouls3DroidLife3EventHubs3GameInformer3GearPatrol3Hackaday3HuffPost3Lifehacker3PCMag3PokeBeach3SeattleTimes3SFGATE3WhatHi-Fi?3WindowsCentral36abcPhiladelphia280Level2ABC7LosAngeles2AZFamily2Benzinga2ChromeUnboxed2Currently2DaringFireball2DCRainmaker2DigitalFoundry2Futurism2GAMINGbible2HouseDigest2Jalopnik2LosAngelesTimes2MyNintendo2politico.eu2qz2Road&Track2SimsCommunity2Slate2TimeExtension2TODAY2TweakTown2YahooFinanceUK224/7WallSt.1BusinessInsiderAfrica1ageofempires1Alternet1AndroidHeadlines1ArizonaSports1BikeRadar1BloodyDisgusting1BostonGlobe1BusinessTimes1Yahoo!FinanceCanada1CalMatters1CarBuzz1cbn1Chron1ClaimDepot1ColoradoSun1Skin.ClubCommunity1consequence1ChristianScienceMonitor1CyberSecurityNews1Cyclingnews1DailyDownforce1DailyKos1DarkHorizons1Decrypt1Defense1denver71Designboom1DigitalCameraWorld1DirtonDirt1Draftsim1DSOGaming1Electrek1empireonline1GameGPU1erictopol.substack1Fangoria1ForexFactory1FOX191franchisetimes1DetroitFreePress1GameRant1GameWorldObserver1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Global1GosuGamers1Gothamist1Hackster.io1Hodinkee1HoustonChronicle1Independent1InsideEVs1InterestingEngineering1investor.costco1Invezz1iPhoneinCanada1MacObserver1Magic:Gathering1MakeUseOf1Mashed1Mercury1MLive1MorningBrew1Motorsport1MP1st1NBC5Chicago1BloombergLaw1SemiAnalysis1Newsshooter1Newsweek1NintendoWire1nrn1NYT1CrudeOilPricesToday1OneMileataTime1OregonPublicBroadcasting1OregonLive1PageSix1PersonaCentral1Phoronix1QuantaMagazine1Realtor1RoadtoVR1RockstarINTEL1Salon1SeattleRed1Semafor1SanFranciscoChronicle1SimpleFlying1GhostHowls1SlippedDisc1SoraNews241SpaceNews1statnews1YahooTech1the5krunner1DailyBeast1DailyMeal1Drive1Hindu1Intercept1Register1Times1TimesofIndia1TimesUnion1TMZ1TopGear1PCMagUK1VisualCapitalist1Vulture1WCVB1WFMZ1WHYY1WKYT1YGOrganization1YourTango1
  1. 001Hacker NewsSEP · 24English

    Vitvm: Git for VM State

    Vitvm is a Git-like tool for versioning virtual machine state, including memory and running processes, enabling rapid snapshots in 72ms and forks in 100ms. It supports full machine checkpointing on Linux with KVM and a files-only mode for other systems, allowing users to inspect, diff, and resume any previous step without replaying.

    By Numinous-Technology
  2. 002Hacker NewsSEP · 24English

    Shrinking a Fedora Virtual Disk

    A user running Fedora in a Hyper-V virtual machine on Windows seeks to shrink the VM disk to make room for a bare-metal Fedora installation. They begin investigating disk space usage with tools like WinDirStat and btdu, successfully freeing space by removing old drivers, update files, and hibernation files.

    By ibobev
  3. 003Hacker NewsSEP · 24English

    Android Automotive OS for Software Defined Vehicle – Secure by Design

    Google's Android Automotive OS for Software Defined Vehicle uses virtualization, sandboxing, and code integrity mechanisms to provide secure isolation between vehicle domains. The system employs UID-based isolation, SELinux enforcement, POSIX capabilities, and APEX packages with mandatory signature validation to prevent malicious code execution. Security management includes continuous scanning, penetration testing, and coordinated vulnerability disclosure through Android Security Bulletins.

    By pjmlp
  4. 004Hacker NewsSEP · 24English

    Vfkit: CLI tool to start virtual machines using macOS Virtualization framework

    Vfkit is a command-line tool for starting virtual machines on macOS using the Virtualization framework, offering both a CLI and Go API package. It integrates with minikube, podman, crc, and ovm for container and cluster management, and can be installed via Homebrew.

    By Crc-Org
  5. 005Hacker NewsSEP · 24English

    Rendering pull requests in the GitHub Copilot app

    The GitHub Copilot app rebuilt its pull request view to handle massive diffs efficiently. While virtualizing code rows works well for large diffs, rendering review comments breaks traditional virtualization because comment heights are unpredictable until render time. The team solved this by redesigning the architecture to handle variable-height comments alongside millions of code lines.

    By Alberto Gimeno
  6. 006Hacker NewsSEP · 24English

    Virtio-nvgpu: Near-native Nvidia GPU access inside a KVM guest

    Virtio-nvgpu enables near-native NVIDIA GPU access inside KVM guests by forwarding kernel driver ioctls, allowing guests to run unmodified NVIDIA drivers and achieve within 2% performance of bare metal. The system is optimized for headless streaming with GPU-based rendering and encoding, supporting multiple concurrent guests on a single GPU with minimal overhead and even resource distribution.

    By Nestrilabs
  7. 007Hacker NewsSEP · 24English

    Nesbox: A fast MicroVM with GPU sharing

    Nesbox is a lightweight microVM hypervisor designed for cloud gaming that enables multiple Linux guests to share a single GPU with near-native performance, booting to userspace in about one second. Guests render within 2% of bare metal performance and can be isolated from each other while sharing the same graphics card through virtio-gpu and rutabaga_gfx, without requiring GPU drivers in the guest OS.

    By Nestrilabs
  8. 008Hacker NewsSEP · 23English

    Porting Bhyve to Rust

    A Rust implementation of bhyve, a userspace virtual machine monitor for illumos systems, providing rshyve (a full-featured VMM with UEFI/Linux boot and live migration) and firehyve (a lightweight microVM). The project is experimental, not production-supported, and derives code from Oxide Computer Company's Propolis under MPL-2.0 licensing.

    By TritonDataCenter
  9. 009Hacker NewsSEP · 22English

    MacPad: Touch Mac in iPad

    MacPad is a jailbreak application that runs native macOS GUI applications on jailbroken iPads and iPhones using native CPU and GPU drivers. It supports touch gestures, file/clipboard sharing between iOS and macOS, and offers both windowed and fullscreen modes with hardware video encoding/decoding.

    By DCMMC
  10. 010Hacker NewsSEP · 22English

    Deterministic Hypervisors for Cheap

    A developer explores building a deterministic hypervisor for running Linux kernels, discussing the core challenges of concurrency and hardware nondeterminism. The post examines existing approaches like Antithesis's use of Intel performance counters and traditional emulator-based solutions from cybersecurity fuzzing, while hinting at alternative implementation strategies.

    By Charlie
  11. 011Hacker NewsSEP · 22English

    Orphaned VMs: Running VMs Uninterrupted While Host Kernel Is Offline

    Google is developing Orphaned VMs, a technology that allows virtual machines to continue running uninterrupted on preserved physical CPUs while the host Linux kernel undergoes live updates through the Live Update Orchestrator. The RFC patches, currently at 46 patches and led by Pasha Tatashin, introduce infrastructure for vCPU state preservation and a Caretaker bare-metal layer to handle VM operations during host reboots, though the work remains early-stage and not yet production-ready.

    By Michael Larabel
  12. 012Hacker NewsSEP · 22English

    Keep Using Your Intel Mac in 2025?

    A systems engineer explains why they continue using an Intel Mac in 2025, running macOS, Manjaro Linux, and Windows simultaneously for professional work across different operating environments. This multi-OS setup provides hands-on learning and practical flexibility for system-level tasks that require working across Linux containers, Windows enterprise tools, and Apple ecosystems without relying on abstraction layers.

    By aslihana
  13. 013Hacker NewsSEP · 21English

    Covert Caches: TLB Edition

    The Translation Lookaside Buffer (TLB) is a covert cache that stores virtual-to-physical address translations on x86 processors, eliminating the need for expensive multi-level page table walks on every memory access. Introduced with Intel's 80386 in 1985, the TLB predates on-chip data caches and remains invisible to applications but critical for operating system performance, especially under virtualization where nested paging can require up to 24 memory references without cached translations.

    By Nicholas Wilt
  14. 014Hacker NewsSEP · 21English

    RFC-0285: The Magma GPU open-source project

    RFC-0285 proposes creating the Magma-GPU exploratory committee to establish Magma as an open-source, multi-OS GPU standard bridging high-level and low-level driver components. The initiative aims to standardize GPU interfaces across microkernel systems like Fuchsia, Android, QNX, and Redox through quarterly collaborative meetings and potential integration with Mesa, addressing fragmentation and inefficiency in current microkernel GPU driver development.

    By undecidabot
  15. 015Hacker NewsSEP · 20English

    Show HN: Try Omarchy for Windows – Full Omarchy Desktop on Windows

    Try Omarchy for Windows allows running the full Omarchy 4.0.3 desktop in a window on Windows 10/11 using QEMU with GPU acceleration via virgl and Venus Vulkan, without requiring virtualization software or repartitioning. The v0.0.20-preview release includes features like clipboard sharing, folder sharing, and automatic CPU fallback, with setup managed through a single ~10 MB executable.

    By Omacom
  16. 016Hacker NewsSEP · 20English

    Zephyr RTOS Ported to WebAssembly

    Zephyr RTOS has been ported to WebAssembly, allowing the kernel to run freestanding in a browser with a single wasm32 linear memory. The implementation uses Binaryen's Asyncify for context switching and cooperative interrupts, with virtual time enabling deterministic execution. Multiple test samples including hello_world, synchronization, and semaphore tests pass successfully.

    By Beriberikix
  17. 017Hacker NewsSEP · 20English

    A custom virtual machine for the Stars 4X game

    A developer created Stars!VM, a custom virtual machine that runs Stars!, a 1995 16-bit Windows 3.1 strategy game, on modern systems by embedding an 80286 emulator and Win16-to-Win32 bridge. The solution provides native Win32 compatibility with modern features like 4K scaling, ships as a single executable with the game embedded, and includes MCP integration for AI agent control.

    By ibobev
  18. 018Hacker NewsSEP · 19English

    Secure VMs for Kubernetes: Hardening Kata Containers

    A developer used Astra to remove approximately 60% of Kata Containers code while maintaining full Kubernetes-Firecracker integration support, reducing attack surface and improving auditability. The hardened fork runs x86_64 workloads in Firecracker VMs with 13.5k SLOC for host runtime and 8.1k for agent, tested in a homelab cluster but offered without security guarantees or production verification.

    By srcreigh
  19. 019Hacker NewsSEP · 19English

    WinBoat's Helios VGPU: What It Is (and Isn't)

    WinBoat's Helios is an API-level paravirtualization tool for 3D GPU acceleration in virtual machines, not a traditional vGPU. It forwards graphics calls from a guest Windows system to the host Linux GPU via a custom Vulkan driver and virtio channel, meaning guest applications lack direct GPU access and cannot use CUDA, NVENC, or DXGI.

    By Sparrow
  20. 020Hacker NewsSEP · 18English

    Show HN: Microsoft Office running with Wine on Linux with no virtualization

    A NixOS flake enables Microsoft 365 to run on Linux via Wine and GE-Proton without virtualization, downloading Office at install time and using a minimal licensing shim to bypass Windows SPP validation. Word successfully starts and displays its interface, though full activation and licensing verification remain incomplete as of September 2026.

    By Tombert