Feed of "divested/brace" https://codeberg.org/divested/brace Offers a wide range of opinionated settings that prioritize privacy, security, and usability for a curated set of Linux programs. Thu, 16 Apr 2026 00:18:59 +0200 thereisnoanderson closed issue divested/brace#10 https://codeberg.org/divested/brace/issues/10#issuecomment-13154265 #Kernel Command Line "amd_iommu=force_isolation" blank screen thereisnoanderson 123245202: https://codeberg.org/divested/brace/issues/10#issuecomment-13154265 Wed, 15 Apr 2026 02:57:11 +0200 thereisnoanderson closed issue divested/brace#12 https://codeberg.org/divested/brace/issues/12#issuecomment-13154253 problem when using brace-update-system 42 thereisnoanderson 123245175: https://codeberg.org/divested/brace/issues/12#issuecomment-13154253 Wed, 15 Apr 2026 02:56:48 +0200 lucasmz closed pull request divested/brace#3 https://codeberg.org/divested/brace/pulls/3#issuecomment-12679728 chrony: add ntp.br servers lucasmz 119305308: https://codeberg.org/divested/brace/pulls/3#issuecomment-12679728 Sun, 05 Apr 2026 16:00:16 +0200 lucasmz commented on issue divested/brace#18 https://codeberg.org/divested/brace/issues/18#issuecomment-10641320 TSME and memory encryption <p dir="auto">Is there even any benefit to SME, it seems worse</p> Is there even any benefit to SME, it seems worse

]]>
lucasmz 99785975: https://codeberg.org/divested/brace/issues/18#issuecomment-10641320 Mon, 16 Feb 2026 18:18:46 +0100
lucasmz closed issue divested/brace#18 https://codeberg.org/divested/brace/issues/18#issuecomment-10628048 TSME and memory encryption lucasmz 99539429: https://codeberg.org/divested/brace/issues/18#issuecomment-10628048 Mon, 16 Feb 2026 04:20:28 +0100 lucasmz commented on issue divested/brace#18 https://codeberg.org/divested/brace/issues/18#issuecomment-10628045 TSME and memory encryption <blockquote> <p dir="auto">tsme should work on non-pro cpus if you can turn the option on, but there is no easy way to verify it</p> </blockquote>

tsme should work on non-pro cpus if you can turn the option on, but there is no easy way to verify it

]]>
lucasmz 99539411: https://codeberg.org/divested/brace/issues/18#issuecomment-10628045 Mon, 16 Feb 2026 04:20:27 +0100
lucasmz commented on issue divested/brace#18 https://codeberg.org/divested/brace/issues/18#issuecomment-10628024 TSME and memory encryption <p dir="auto">Actually fwupdmgr says &#39;not supported&#39; so I&#39;m guessing it&#39;s maybe not even a thing in the BIOS, unsure</p> Actually fwupdmgr says 'not supported' so I'm guessing it's maybe not even a thing in the BIOS, unsure

]]>
lucasmz 99539243: https://codeberg.org/divested/brace/issues/18#issuecomment-10628024 Mon, 16 Feb 2026 04:16:54 +0100
lucasmz opened issue divested/brace#18 https://codeberg.org/divested/brace/issues/18 18#TSME and memory encryption# Maybe I'm asking the wrong person, but I'm curious and DDG wasn't of help;

I have TSME enabled (instead of disabled or auto) in my BIOS, but I'm not sure if it works and if it's worse or better than SME, and the system reports that I don't have encrypted memory.

]]>
lucasmz 99537056: https://codeberg.org/divested/brace/issues/18 Mon, 16 Feb 2026 04:05:02 +0100
lucasmz closed issue divested/brace#8 https://codeberg.org/divested/brace/issues/8#issuecomment-9362543 Prefer Wayland when available in Chromium lucasmz 84874871: https://codeberg.org/divested/brace/issues/8#issuecomment-9362543 Tue, 30 Dec 2025 12:22:25 +0100 lucasmz commented on issue divested/brace#8 https://codeberg.org/divested/brace/issues/8#issuecomment-9362537 Prefer Wayland when available in Chromium <p dir="auto">pretty sure it&#39;s the default now</p> pretty sure it's the default now

]]>
lucasmz 84874832: https://codeberg.org/divested/brace/issues/8#issuecomment-9362537 Tue, 30 Dec 2025 12:22:17 +0100
lucasmz closed issue divested/brace#14 https://codeberg.org/divested/brace/issues/14#issuecomment-8258163 What is the reason for passim being recommended for removal? lucasmz 72366036: https://codeberg.org/divested/brace/issues/14#issuecomment-8258163 Thu, 13 Nov 2025 03:08:35 +0100 lucasmz opened issue divested/brace#14 https://codeberg.org/divested/brace/issues/14 14#What is the reason for passim being recommended for removal?# You had some thoughts on PackageKit, and it convinced me, being stored on RAM, I'm wondering about passim, is there any security/privacy issue with it?

]]>
lucasmz 72301047: https://codeberg.org/divested/brace/issues/14 Wed, 12 Nov 2025 21:42:55 +0100
lucasmz opened issue divested/brace#13 https://codeberg.org/divested/brace/issues/13 13#chronyd breaks on Fedora 43# I'm unsure if this is a brace issue; anyhow:

lucas@fedora:~$ systemctl status chronyd
× chronyd.service - NTP client/server
     Loaded: loaded (/usr/lib/systemd/system/chronyd.service; enabled; preset: enabled)
    Drop-In: /usr/lib/systemd/system/service.d
             └─10-timeout-abort.conf
             /usr/lib/systemd/system/chronyd.service.d
             └─99-brace.conf
     Active: failed (Result: exit-code) since Sun 2025-10-26 01:04:31 -03; 1min 5s ago
 Invocation: 2d72f3addfea43fc86535b8ffe301274
       Docs: man:chronyd(8)
             man:chrony.conf(5)
    Process: 1870 ExecStart=/usr/sbin/chronyd -n $OPTIONS -f /etc/chrony.brace.conf (code=exited, status=1/FAILURE)
   Main PID: 1870 (code=exited, status=1/FAILURE)
   Mem peak: 13.5M
        CPU: 77ms

out 26 01:04:31 fedora systemd[1]: Starting chronyd.service - NTP client/server...
out 26 01:04:31 fedora chronyd[1870]: 2025-10-26T04:04:31Z Fatal error : Not superuser
out 26 01:04:31 fedora systemd[1]: chronyd.service: Main process exited, code=exited, status=1/FAILURE
out 26 01:04:31 fedora systemd[1]: chronyd.service: Failed with result 'exit-code'.
out 26 01:04:31 fedora systemd[1]: Failed to start chronyd.service - NTP client/server.
]]>
lucasmz 68127964: https://codeberg.org/divested/brace/issues/13 Sun, 26 Oct 2025 05:09:56 +0100
lucasmz commented on issue divested/brace#10 https://codeberg.org/divested/brace/issues/10#issuecomment-6709732 #Kernel Command Line "amd_iommu=force_isolation" blank screen <p dir="auto">On mine it doesn&#39;t break boot, ryzen 5600g, instead, it actually causes random crashes while using the system which end up freezing everything</p> On mine it doesn't break boot, ryzen 5600g, instead, it actually causes random crashes while using the system which end up freezing everything

]]>
lucasmz 54518077: https://codeberg.org/divested/brace/issues/10#issuecomment-6709732 Mon, 25 Aug 2025 19:56:40 +0200
thereisnoanderson opened issue divested/brace#12 https://codeberg.org/divested/brace/issues/12 12#problem when using brace-update-system 42# when trying to use "brace-update-system 42" with brace-20250505-1:

"Problem: installed package real-ucode-3:20250203-1.noarch requires amd-ucode-firmware >= 3:20231101, but none of the providers can be installed ...

should i uninstall real-ucode when trying to upgrade?

thank you

]]>
thereisnoanderson 35297607: https://codeberg.org/divested/brace/issues/12 Thu, 22 May 2025 16:53:27 +0200
uncommon-user commented on issue divested/brace#8 https://codeberg.org/divested/brace/issues/8#issuecomment-4210466 Prefer Wayland when available in Chromium <p dir="auto">If the <code>chrome://flags/#ozone-platform-hint</code> is set to &#39;Auto&#39;, change it to &#39;Default&#39;. Close the browser <strong><em>without</em></strong> selecting the relaunch button when the dialog popup option appears.<br/> Open it either by enabling the <code>--ozone-platform=wayland</code> flag.<br/> Something along the lines of:<br/> <code>chromium --ozone-platform=wayland &gt;/dev/null 2&gt;&amp;1 &amp; disown</code><br/> Or by adding that flag to <code>$XDG_CONFIG_HOME/chromium-flags.conf</code></p> <p dir="auto">But then again, not sure about how you have everything else setup and configured, so this may require more changes on your end.</p> If the chrome://flags/#ozone-platform-hint is set to 'Auto', change it to 'Default'. Close the browser without selecting the relaunch button when the dialog popup option appears.
Open it either by enabling the --ozone-platform=wayland flag.
Something along the lines of:
chromium --ozone-platform=wayland >/dev/null 2>&1 & disown
Or by adding that flag to $XDG_CONFIG_HOME/chromium-flags.conf

But then again, not sure about how you have everything else setup and configured, so this may require more changes on your end.

]]>
uncommon-user 32837501: https://codeberg.org/divested/brace/issues/8#issuecomment-4210466 Wed, 07 May 2025 14:34:44 +0200
thereisnoanderson commented on issue divested/brace#10 https://codeberg.org/divested/brace/issues/10#issuecomment-3933053 #Kernel Command Line "amd_iommu=force_isolation" blank screen <p dir="auto">false positive, we are not back on track...</p> false positive, we are not back on track...

]]>
thereisnoanderson 30414188: https://codeberg.org/divested/brace/issues/10#issuecomment-3933053 Thu, 24 Apr 2025 12:46:28 +0200
thereisnoanderson commented on issue divested/brace#10 https://codeberg.org/divested/brace/issues/10#issuecomment-3927344 #Kernel Command Line "amd_iommu=force_isolation" blank screen <p dir="auto">we back on track!</p> we back on track!

]]>
thereisnoanderson 30111800: https://codeberg.org/divested/brace/issues/10#issuecomment-3927344 Thu, 24 Apr 2025 01:37:33 +0200
thereisnoanderson closed issue divested/brace#11 https://codeberg.org/divested/brace/issues/11#issuecomment-3927335 F41 - since April-12-2025 gpg checks issue thereisnoanderson 30111452: https://codeberg.org/divested/brace/issues/11#issuecomment-3927335 Thu, 24 Apr 2025 01:35:31 +0200 thereisnoanderson commented on issue divested/brace#11 https://codeberg.org/divested/brace/issues/11#issuecomment-3809342 F41 - since April-12-2025 gpg checks issue <p dir="auto">this is happening to multiple systems since 1-2 days, maybe Fedora update related</p> this is happening to multiple systems since 1-2 days, maybe Fedora update related

]]>
thereisnoanderson 28525871: https://codeberg.org/divested/brace/issues/11#issuecomment-3809342 Sun, 13 Apr 2025 18:03:54 +0200
thereisnoanderson commented on issue divested/brace#11 https://codeberg.org/divested/brace/issues/11#issuecomment-3805334 F41 - since April-12-2025 gpg checks issue <p dir="auto">removing .gnupg/public-keys.d/pubring.db.lock - fixes that. Any relation to brace possible?</p> removing .gnupg/public-keys.d/pubring.db.lock - fixes that. Any relation to brace possible?

]]>
thereisnoanderson 28508000: https://codeberg.org/divested/brace/issues/11#issuecomment-3805334 Sun, 13 Apr 2025 15:00:39 +0200
thereisnoanderson opened issue divested/brace#11 https://codeberg.org/divested/brace/issues/11 11#F41 - since April-12-2025 gpg checks issue# Since April-12 gpg import or check results:

gpg: Note: database_open # waiting for lock (held by #) ...
gpg: keydb_search failed: Connection timed out

haven't checked for any brace relation yet. < wrong i uninstalled and rebooted. No change

]]>
thereisnoanderson 28507184: https://codeberg.org/divested/brace/issues/11 Sun, 13 Apr 2025 14:55:41 +0200
thereisnoanderson commented on issue divested/brace#10 https://codeberg.org/divested/brace/issues/10#issuecomment-2993888 #Kernel Command Line "amd_iommu=force_isolation" blank screen <p dir="auto">awesome! THANK YOU</p> awesome! THANK YOU

]]>
thereisnoanderson 25089671: https://codeberg.org/divested/brace/issues/10#issuecomment-2993888 Mon, 10 Mar 2025 06:06:42 +0100
thereisnoanderson opened issue divested/brace#10 https://codeberg.org/divested/brace/issues/10 10##Kernel Command Line "amd_iommu=force_isolation" blank screen# since Fedora 6.13.4-200.fc41 "amd_iommu=force_isolation" arg on system causing a blank screen after grub_timeout.

last working kernel using that arg: 6.12.15-200.fc41.

any correlation to "AMD microcode signature verification vulnerability (CVE-2024-56161)" ?

]]>
thereisnoanderson 25089557: https://codeberg.org/divested/brace/issues/10 Mon, 10 Mar 2025 05:57:51 +0100
lucasmz commented on pull request divested/brace#9 https://codeberg.org/divested/brace/pulls/9#issuecomment-2930979 firefox: update arkenfox.js per upstream to 3d76c74 <p dir="auto">Man codeberg&#39;s diff viewer is kind of shit for this to be helpful</p> Man codeberg's diff viewer is kind of shit for this to be helpful

]]>
lucasmz 24897334: https://codeberg.org/divested/brace/pulls/9#issuecomment-2930979 Thu, 06 Mar 2025 04:57:39 +0100
lucasmz created pull request divested/brace#9 https://codeberg.org/divested/brace/pulls/9 9#firefox: update arkenfox.js per upstream to 3d76c74# 3d76c74c80485931425464fec0e59d6cb461677a

https://github.com/arkenfox/user.js/releases/tag/135.0

]]>
lucasmz 24897300: https://codeberg.org/divested/brace/pulls/9 Thu, 06 Mar 2025 04:55:22 +0100
lucasmz opened issue divested/brace#8 https://codeberg.org/divested/brace/issues/8 8#Prefer Wayland when available in Chromium# Chromium stupidly defaults to X11, trying to figure out how to potentially solve this
Checkable with xeyes

It can be changed to be solved by the user with #ozone-platform-hint but that's not ideal

]]>
lucasmz 23675760: https://codeberg.org/divested/brace/issues/8 Sun, 16 Feb 2025 08:45:41 +0100
lucasmz created pull request divested/brace#7 https://codeberg.org/divested/brace/pulls/7 7#firefox: typo: MULL instead of BRACE# oops.

]]>
lucasmz 21417769: https://codeberg.org/divested/brace/pulls/7 Mon, 30 Dec 2024 20:35:54 +0100
lucasmz commented on pull request divested/brace#6 https://codeberg.org/divested/brace/pulls/6#issuecomment-2552644 firefox: use beaconDB instead of Google when location services are used <p dir="auto">that&#39;s fair, <a href="https://beacondb.net/map" rel="nofollow">https://beacondb.net/map</a> hardly covers much if the user doesn&#39;t contribute around their area<br/> but I don&#39;t really see anything else replacing Mozilla ATM <span class="emoji" aria-label="woman shrugging: Light Skin Tone" data-alias="woman_shrugging_Light_Skin_Tone">🤷🏻‍♀️</span> (other than commercial offers and proxies)</p> <p dir="auto">beaconDB should include the MLS cell export, plus the fallback for IP, plus the contributor data; in regular laptops/desktops though, it will probably only include IP, Wi-Fi and Bluetooth maybe.</p> <p dir="auto">AFAIK the options are:</p> <ol dir="auto"> <li>asking for an api key for Positon (which seems like way too much for brace, for what is just an apple nlp privacy-respecting proxy) (which is also going away if beaconDB gets big enough, <a href="https://positon.xyz/docs/#sla" rel="nofollow">https://positon.xyz/docs/#sla</a>)</li> <li>go with beaconDB, but have sub-par coverage</li> <li>stay with Google as a default, which to be fair should only be used if location is triggered</li> <li>disable location completely</li> <li>use the OS provider (geoclue)?</li> </ol> that's fair, https://beacondb.net/map hardly covers much if the user doesn't contribute around their area
but I don't really see anything else replacing Mozilla ATM 🤷🏻‍♀️ (other than commercial offers and proxies)

beaconDB should include the MLS cell export, plus the fallback for IP, plus the contributor data; in regular laptops/desktops though, it will probably only include IP, Wi-Fi and Bluetooth maybe.

AFAIK the options are:

  1. asking for an api key for Positon (which seems like way too much for brace, for what is just an apple nlp privacy-respecting proxy) (which is also going away if beaconDB gets big enough, https://positon.xyz/docs/#sla)
  2. go with beaconDB, but have sub-par coverage
  3. stay with Google as a default, which to be fair should only be used if location is triggered
  4. disable location completely
  5. use the OS provider (geoclue)?
]]>
lucasmz 21417628: https://codeberg.org/divested/brace/pulls/6#issuecomment-2552644 Mon, 30 Dec 2024 20:28:27 +0100
lucasmz commented on pull request divested/brace#3 https://codeberg.org/divested/brace/pulls/3#issuecomment-2552632 chrony: add ntp.br servers <p dir="auto">yeah I noticed that. Is that an issue per-se? I thought there were multiple datasets for accuracy or something</p> yeah I noticed that. Is that an issue per-se? I thought there were multiple datasets for accuracy or something

]]>
lucasmz 21417372: https://codeberg.org/divested/brace/pulls/3#issuecomment-2552632 Mon, 30 Dec 2024 20:15:29 +0100