[ SECURITYLAB_—_BLOGS ]

Long-form writing on runtime, distributed systems, kernel internals, Go concurrency, memory models, eBPF, and assembly walkthroughs.

Blog
The Log Printed Exactly What I Wanted. The Fix Was Still Wrong.

The Log Printed Exactly What I Wanted. The Fix Was Still Wrong.

In a single day of debugging, four different signals each looked like proof and each supported a smaller claim than I borrowed it for. A log line that printed exactly as designed while the process it was in died ten seconds later. An address that looked like proof of a cellular test and was identical on Wi-Fi. A fix that was clean and plausible and would have broken a whole class of users. A ten-minute hang with no error output at all. Evidence is not the problem. Using a true signal to support a claim it cannot carry is.

2026-08-19 9 min read
Blog
Your VPN Is Fine. iOS Swapped the Address.

Your VPN Is Fine. iOS Swapped the Address.

One app, one host, one cellular connection. The HTTP calls reach the server and the streaming connection times out with no error anywhere. Nothing is misconfigured. On an IPv6-only cellular network, getaddrinfo() on an IPv4 VPN literal returns a synthesized NAT64 address that routes straight out of the tunnel, and only the code path that resolves the address itself is affected. This is a field note on recognizing that failure, not discovering it.

2026-08-15 11 min read
Blog
Tool Calls Need Completion Ownership: Why Your Agent's 200 OK Lies

Tool Calls Need Completion Ownership: Why Your Agent's 200 OK Lies

When an agent reports an action it never actually completed, the lie almost never starts in the model. It starts one layer down, in a tool wrapper that returned 200 the moment the request was accepted rather than when the side effect was observed. This is the completion-ownership bug that has broken RPC systems for decades, wearing a tool schema. The fix is to put ownership in the wrapper: verify the effect before the word success ever reaches the model.

2026-08-13 10 min read
Blog
Your AI Bill Is a Distributed Systems Problem, Not a Model-Pricing Problem

Your AI Bill Is a Distributed Systems Problem, Not a Model-Pricing Problem

When the monthly LLM bill jumps several times over, the first instinct is that the model got more expensive or usage simply grew. It is almost always something else: a distributed systems failure mode, retry storms, fanout amplification, cache misses, unbounded conversation growth, that happens to be denominated in tokens instead of network calls. Debug the call graph, not the model price.

2026-08-04 9 min read
Blog
Validation Is a Loop, Not an Assertion: Why Your AI Agent Reports Success It Never Achieved

Validation Is a Loop, Not an Assertion: Why Your AI Agent Reports Success It Never Achieved

The most common production AI agent failure is treating validation as an assertion, a one-shot pass/fail check, instead of a loop that validates, scores, and decides whether to accept, retry, or escalate. Deterministic code can assert. Non-deterministic model output needs a closed loop, or your agent will report success while doing the wrong thing.

2026-07-28 10 min read
Blog
A Wrong Ruler Is Worse Than No Ruler: Verifying the Checks You Trust

A Wrong Ruler Is Worse Than No Ruler: Verifying the Checks You Trust

In a rules-first AI system, the deterministic checks get authority. They gate output and overrule the model judge. But a wrong check with authority is worse than no check at all. A first-principles standard for verifying the ruler before you trust it.

2026-07-17 11 min read