<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-05-07T01:08:04Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by june ✿ (6a756e65)</title>
  <author>
    <name>june ✿ (6a756e65)</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1jskpqy269nw53zrfpyncvjelel8f5pzdlmq8gzsyz6gqfzkyx84qk8ssgw.rss" />
  <link href="https://yabu.me/npub1jskpqy269nw53zrfpyncvjelel8f5pzdlmq8gzsyz6gqfzkyx84qk8ssgw" />
  <id>https://yabu.me/npub1jskpqy269nw53zrfpyncvjelel8f5pzdlmq8gzsyz6gqfzkyx84qk8ssgw</id>
  <icon>https://ublog.kimapr.net/media/3792318aeb36d6ea6864ec9477c7d443113eaf7b52bc93242f08debee712ffab.jpg</icon>
  <logo>https://ublog.kimapr.net/media/3792318aeb36d6ea6864ec9477c7d443113eaf7b52bc93242f08debee712ffab.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsqxvxyca2teecued59aywysnaefvgvm6yawza0r0tddt2hr8nw7jqzyz2zcyq3tgkd6jygdyyj0pjt8l8uaxsyfhlvqaq2qstfqpy2csc75t93rc8</id>
    
      <title type="html">please go away cis man. your queerphobia is Really Showing. a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqxvxyca2teecued59aywysnaefvgvm6yawza0r0tddt2hr8nw7jqzyz2zcyq3tgkd6jygdyyj0pjt8l8uaxsyfhlvqaq2qstfqpy2csc75t93rc8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsw8v4tgetn02xdr6fc9c969m0dyx5mpmpptq55uh8uyujpy8duepgvqmfps&#39;&gt;nevent1q…mfps&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;please go away cis man. your queerphobia is Really Showing. a random wiki is not the all mighty source of truth for the entirety of queer folks.&lt;br/&gt;&lt;br/&gt;so please block me if i seriously upset you that much over our consenting, loving relationship with my sister instead of making yourself look like a fool more and trying to derail my thread here
    </content>
    <updated>2026-05-06T05:22:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvz482jszqy2g2hscnn8yysaf4mkrh3xljxvnphqu34av693zkhkqzyz2zcyq3tgkd6jygdyyj0pjt8l8uaxsyfhlvqaq2qstfqpy2csc75qr2w9y</id>
    
      <title type="html">i dont need to be mansplained either so yeah please go away ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvz482jszqy2g2hscnn8yysaf4mkrh3xljxvnphqu34av693zkhkqzyz2zcyq3tgkd6jygdyyj0pjt8l8uaxsyfhlvqaq2qstfqpy2csc75qr2w9y" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8d0qheucwf3q3x8hx6z7j3x9flerwlty6lxsjghce4s4uket3zxqncjf0z&#39;&gt;nevent1q…jf0z&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;i dont need to be mansplained either so yeah please go away &lt;br/&gt;&lt;br/&gt;consang isnt bad either btw &amp;lt;3
    </content>
    <updated>2026-05-06T05:07:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw6s3e60rhxyyx9msev2lmq2yg5gxsad7wq8a4m9vgql4sps86l9qzyz2zcyq3tgkd6jygdyyj0pjt8l8uaxsyfhlvqaq2qstfqpy2csc75zsgss7</id>
    
      <title type="html">this doesnt really explain or help anything other than making a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw6s3e60rhxyyx9msev2lmq2yg5gxsad7wq8a4m9vgql4sps86l9qzyz2zcyq3tgkd6jygdyyj0pjt8l8uaxsyfhlvqaq2qstfqpy2csc75zsgss7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0kvlnf9lzldyp0xe68fdpezry4r32ulm7vgnlu0646flvfgu3h9sv333yf&#39;&gt;nevent1q…33yf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;this doesnt really explain or help anything other than making a blind assumption that bubblewrap can do everything there, and there still isnt an example.
    </content>
    <updated>2026-05-06T04:36:30Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfug2waxudzcsqnvhfza2tawp8qdq558lx6j3nczems0xnk4vz5zszyz2zcyq3tgkd6jygdyyj0pjt8l8uaxsyfhlvqaq2qstfqpy2csc75ny5f9l</id>
    
      <title type="html">one thing i *really* like about systemd is the unit sandboxing ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfug2waxudzcsqnvhfza2tawp8qdq558lx6j3nczems0xnk4vz5zszyz2zcyq3tgkd6jygdyyj0pjt8l8uaxsyfhlvqaq2qstfqpy2csc75ny5f9l" />
    <content type="html">
      one thing i *really* like about systemd is the unit sandboxing capabilities and how convenient it is&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://wiki.archlinux.org/title/Systemd/Sandboxing&#34;&gt;https://wiki.archlinux.org/title/Systemd/Sandboxing&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;heres an example from my tuwunel matrix systemd unit&lt;br/&gt;&lt;br/&gt;```&lt;br/&gt;[Unit]&lt;br/&gt;Description=Tuwunel Matrix homeserver&lt;br/&gt;#Requires=tuwunel.socket&lt;br/&gt;Wants=network-online.target&lt;br/&gt;After=network-online.target&lt;br/&gt;Documentation=&lt;a href=&#34;https://tuwunel.chat/&#34;&gt;https://tuwunel.chat/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;[Service]&lt;br/&gt;User=tuwunel&lt;br/&gt;Group=tuwunel&lt;br/&gt;Type=notify&lt;br/&gt;ReloadSignal=SIGUSR1&lt;br/&gt;WatchdogSec=30&lt;br/&gt;&lt;br/&gt;TTYPath=/dev/tty25&lt;br/&gt;DeviceAllow=char-tty&lt;br/&gt;StandardInput=tty-force&lt;br/&gt;StandardOutput=tty&lt;br/&gt;StandardError=journal&#43;console&lt;br/&gt;TTYReset=yes&lt;br/&gt;# uncomment to allow buffer to be cleared every restart&lt;br/&gt;TTYVTDisallocate=no&lt;br/&gt;&lt;br/&gt;TTYColumns=120&lt;br/&gt;TTYRows=40&lt;br/&gt;&lt;br/&gt;Environment=&amp;#34;TUWUNEL_CONFIG=/etc/tuwunel/tuwunel.toml&amp;#34;&lt;br/&gt;&lt;br/&gt;ExecStart=/usr/sbin/tuwunel&lt;br/&gt;&lt;br/&gt;ReadWritePaths=/var/lib/tuwunel /etc/tuwunel&lt;br/&gt;&lt;br/&gt;AmbientCapabilities=&lt;br/&gt;CapabilityBoundingSet=&lt;br/&gt;&lt;br/&gt;ManagedOOMPreference=avoid&lt;br/&gt;&lt;br/&gt;MemoryHigh=3G&lt;br/&gt;MemoryMax=4G&lt;br/&gt;&lt;br/&gt;DevicePolicy=closed&lt;br/&gt;LockPersonality=yes&lt;br/&gt;MemoryDenyWriteExecute=yes&lt;br/&gt;NoNewPrivileges=yes&lt;br/&gt;#ProcSubset=pid&lt;br/&gt;ProtectClock=yes&lt;br/&gt;ProtectControlGroups=yes&lt;br/&gt;ProtectHome=yes&lt;br/&gt;ProtectHostname=yes&lt;br/&gt;ProtectKernelLogs=yes&lt;br/&gt;ProtectKernelModules=yes&lt;br/&gt;ProtectKernelTunables=yes&lt;br/&gt;ProtectProc=invisible&lt;br/&gt;ProtectSystem=strict&lt;br/&gt;PrivateDevices=yes&lt;br/&gt;PrivateMounts=yes&lt;br/&gt;PrivateTmp=yes&lt;br/&gt;PrivateUsers=yes&lt;br/&gt;PrivateIPC=yes&lt;br/&gt;RemoveIPC=yes&lt;br/&gt;RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX&lt;br/&gt;RestrictNamespaces=yes&lt;br/&gt;RestrictRealtime=yes&lt;br/&gt;RestrictSUIDSGID=yes&lt;br/&gt;SystemCallArchitectures=native&lt;br/&gt;SystemCallFilter=@system-service @resources&lt;br/&gt;SystemCallFilter=~@clock @debug @module @mount @reboot @swap @cpu-emulation @obsolete @timer @chown @setuid @privileged @keyring @ipc&lt;br/&gt;SystemCallErrorNumber=EPERM&lt;br/&gt;#StateDirectory=tuwunel&lt;br/&gt;&lt;br/&gt;RuntimeDirectory=tuwunel&lt;br/&gt;RuntimeDirectoryMode=0750&lt;br/&gt;&lt;br/&gt;Restart=on-failure&lt;br/&gt;RestartSec=5&lt;br/&gt;&lt;br/&gt;TimeoutStopSec=2m&lt;br/&gt;TimeoutStartSec=2m&lt;br/&gt;&lt;br/&gt;StartLimitInterval=1m&lt;br/&gt;StartLimitBurst=5&lt;br/&gt;&lt;br/&gt;[Install]&lt;br/&gt;WantedBy=multi-user.target&lt;br/&gt;Alias=matrix-tuwunel.service&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;how can i replicate that kind of stuff with openrc?
    </content>
    <updated>2026-05-06T01:37:47Z</updated>
  </entry>

</feed>