A presence-aware break reminder

Most break reminders run on a plain clock. You set a 50 minute timer and then you walk away for 30 of those minutes to get a coffee. The timer still fires the moment it runs out. It does not know that you just sat back down. I already wear a smartwatch. It taps my wrist after I sit for too long, which helps, but it measures the wrong thing. It watches my wrist, not my desk. A few arm movements are enough to convince it that I got up. In the meantime I am still in the same chair, in front of the same screen. I am also the kind of person who concentrates hard enough to lose track of time. Eyestrain is usually the first sign that I went too far. So I wanted something that watches the desk instead. On that desk sits an old 2009 piece of e-waste: a Samsung N130 netbook with a single core Intel Atom processor and 1GB of RAM. It runs Void Linux, and it is the same machine I turned into a basement WiFi router a few months ago. I made it a desk sentinel. It checks whether I am really sitting in front of the workstation. It counts work time only while I am there, and it speaks up once I stay too long. Image credits to: Bananayota, found on Pixabay TL;DR An old Samsung N130 netbook running Void Linux now works as a desk sentinel. motion watches the built-in webcam. On every start and stop of movement it writes active or idle into a plain state file. A small Nim daemon reads that file and tracks continuous desk time with a live one line progress bar. Once the limit is reached, it calls espeak-ng and wall. An absence under 5 minutes does not reset the clock. Nothing is recorded. The video feed never leaves the netbook and no frame is written to disk. The daemon runs as an unprivileged supervised runit service. It costs 0.01% of one core and 2 MB of RAM. motion is the real cost on this hardware. On the way I found and fixed a shell injection bug in the alarm code, a broken motion.conf quoting bug and two display bugs. Details below. ...

September 5, 2026 · Andrea Manzini

Landlock idiomatic sandboxing in Nim

👋 Intro If you have ever spent time hardening Linux applications, you probably know the frustration of the all-or-nothing permission model. In the standard Linux environment, once a process starts running, it usually has far more filesystem access than it actually needs. While we have tools like seccomp, chroot, or heavy-duty modules like SELinux and AppArmor, they often feel too complex for simple, application-level sandboxing. Landlock changes this. Since its merge into the Linux kernel in version 5.13, it has become a game-changer for developers. It allows a process to restrict itself without requiring root privileges, moving security away from global system policies and directly into your application code. ...

April 9, 2026 · Andrea Manzini

Embed git commit hash into an executable

The problem When we write our programs or libraries, usually we ship to the end user a packaged binary. If a user wants to report a bug or ask for a feature, one of the most important information to have is “which version of the software are you using ?” Since as any good programmer you likely use a source code control system, you should not rely only on the numeric version, but it’s practical to include also the git commit hash of the software you are actually shipping. ...

July 1, 2023 · Andrea Manzini

Debugging a problematic build

The Good 😇 Today I decided to submit an openSUSE package update for the nim compiler. It went almost all well but unfortunately I faced a problem: on the i586 platform it fails to build. ...

March 14, 2023 · Andrea Manzini

This site does not use cookies or collect any personal data. © 2026 Andrea Manzini.