Changelog — 2.339–2.352

Releases 2.339.0 through 2.352.0. Current releases are on the main changelog, and every band is listed in the release archive.

Loading audio...

Version 2.352.0

October 2, 2026

A home for the research library's books that its own keys cannot empty

  • Done: the research library has its own protected shelf. The books it reads, the records its reviewers sign and the files set aside for review now live where every earlier copy is kept, and where none of the keys the library itself uses can erase anything for good.
  • Tested refusal by refusal. Before handing the keys over we tried everything each one must not be able to do, and checked that every refusal came from the rules rather than from something simply being broken. One rule did not hold the first time we asked: the store let a read-only key fetch older copies. It holds now, and the test that caught it stays.
  • Nothing to do at your end.

Version 2.351.0

October 2, 2026

The site we test on now keeps its files the way the real one does

  • Done: the test copy of the site matches the live one. Yesterday the live site's files moved to maintained software. Today the copy we try every change on followed it. A test copy that stores its files differently from the real site cannot tell you how the real site will behave, which is the whole point of having one.
  • Moved, then checked file by file and door by door. Every file was copied and compared with the original. Every part of the system that uses the store was then checked twice: once for what it is allowed to do, and once for what it must be refused.
  • Nothing to do at your end.

Version 2.350.0

October 1, 2026

Your files moved house, and nothing was dropped

  • Done: the site's files now live on maintained software. The store that holds our images, recordings and videos moved to an actively maintained version, which also closes security problems the old one would never have had fixed. The switch took about a second.
  • Rehearsed first, then checked file by file. We ran the new version on a copy of the real files before touching anything, proved we could go back, and afterwards compared every single file before and after. Every one was identical.
  • Nothing to do at your end.

Version 2.349.0

October 1, 2026

We tested where your files will live next, on your files

  • Decided: the next home for the site's files. The software that stores our images, recordings and videos is no longer maintained by its makers, so we chose what replaces it. Nothing has moved yet; the switch is planned, and will be rehearsed on a copy before it happens.
  • Why we did not take the obvious choice. The replacement we had prepared lost track of some files when asked to list them a page at a time — but only with our own real file names, which is why we test with those and not with made-up ones. The option we chose behaves exactly like what runs today.
  • Nothing to do at your end.

Version 2.348.4

October 1, 2026

Our notes caught up with our machines

  • Records: this week's maintenance is written down. We updated the machines that run the site and changed one setting on each, so that programs which need newer processor features can now run on any of them. For a day, our own notes still described the old setting; they now describe what is true, and we checked every machine to be sure.
  • Nothing to do at your end.

Version 2.348.3

October 1, 2026

It now gets itself back up

  • Fixed: one of our tools did not come back on its own. After this morning's maintenance, the store that keeps our finished builds stayed down until we started it by hand. Its parts were starting in the wrong order, and nothing ever tried again.
  • Now something does, and we proved it by breaking it. We caused the same failure on purpose, and it recovered by itself within a minute.
  • Nothing to do at your end.

Version 2.348.2

September 30, 2026

Our own records, kept current

  • Keeping our map of our own tools up to date. Some of the machinery behind our research tools changed today, and our internal records now describe it as it is. A record that describes what we meant to build, rather than what we built, is how mistakes are made later.
  • Nothing to do at your end.

Version 2.348.1

September 30, 2026

safina is getting ready to keep recordings

  • Recordings, not only words. safina keeps the lectures and speeches the scholars' offices publish, exactly as they published them. It can now keep their recordings too, in a store of its own. We are trying it on our development copy first; the first recordings, and a player beside each text, come next.
  • Nothing to do at your end.

Version 2.348.0

September 30, 2026

safina joins the IlmFlow tools

  • A fourth tool in the menu. Under IlmFlow in Apps and Services, safina now sits beside daftar, fihrist and diwan. It keeps the lectures, lessons and speeches that the offices of the scholars publish on their own websites, exactly as they published them, with where and when each was read. Like the others, it is for the people we have invited to work with us.
  • Nothing to do at your end.

Version 2.347.0

September 30, 2026

Our status page calls our tools by their names

  • Clearer names on our own status page. Some of the tools behind the site were listed under working titles, or only as the machines they run on. They now carry the names their users know them by, and each is checked through the same front door its users come in by, so a fault on the way in shows up as a fault rather than hiding behind a green light.
  • Nothing to do at your end.

Version 2.346.1

September 29, 2026

Our notes caught up with today's work

  • Housekeeping. We finished tidying up after this morning's groundwork for the archive's replacement, and wrote down a lesson it taught us, so that the next person does not learn it the same way.
  • Nothing to do at your end.

Version 2.346.0

September 29, 2026

The archive's replacement can read the web, and nothing else of ours

  • Ground prepared for the tool that replaces our research archive. The part of it that reads other people's websites can reach those websites and nothing else we run. We did not take that on trust: we tried to get through the wall from the inside, watched it fail, and only then called it done.
  • Nothing to do at your end.

Version 2.345.1

September 28, 2026

Our notes caught up with the closed archive

  • Tidying up after ourselves. We finished removing the research archive we closed this evening, and updated our own notes to match, so that none of them points at something that no longer exists. We also wrote down the first steps towards the tool that will replace it.
  • Nothing to do at your end.

Version 2.345.0

September 28, 2026

We closed our research archive the day we opened it

  • The archive is closed. This morning we opened an archive for the sources our research cites. That evening, looking closely at how it showed an archived page, we found it ran the original website's own code inside our site. That is not a risk we will take. Parts of it also came under a software licence we do not use. So we closed it the same day. Nothing was lost: it had not yet collected the material we needed.
  • Something better is on its way. We are building our own tool, which keeps the text and the recordings themselves rather than copies of whole websites. More when it is ready.
  • Nothing to do at your end.

Version 2.344.2

September 28, 2026

Your transcriptions are yours, on every request

  • Only you, or a site administrator, can open your transcription projects. Our transcription tool showed each author only their own projects, and the project page itself checked the project was theirs. But most of the requests behind that page, such as fetching or saving a transcript, its earlier versions, playing the recording, showing progress and cancelling a job, only checked that you were one of our authors. So another author with a link to your project could have read or changed your transcript. Every one of those requests now checks that the project is yours, and a test fails if a new one ever forgets to.
  • Nothing to do at your end.

Version 2.344.1

September 28, 2026

Our archive's own app can find it again

  • The app knows where to look. The companion app for our research archive recognises a server by asking it to describe itself. This morning we closed the archive's developer pages, and that description went with them, so the app decided there was nothing there. The description is back. The developer pages stay closed, and nothing in the archive can be read or changed without a key.
  • Nothing to do at your end.

Version 2.344.0

September 28, 2026

A proper home for our simpler sites

  • Our introduction pages are moving house. The short pages that introduce our projects have shared a home with a much busier tool. They now have one of their own, set up the same careful way as everything else we run.
  • Moved first, improved second. Each page moves across exactly as it is, and only once it is settled do we start making it better. If anything changes that you can see, it will be on purpose.
  • Nothing to do at your end.

Version 2.343.1

September 28, 2026

Rehearsing a move before we make it

  • Practice on the copy first. We are moving where our recordings and files are kept. Before touching anything live, the test copy of one of our tools now runs on the new storage, so any surprise shows up there first.
  • Every file came across unchanged. We checked each one, not a sample, and ran the same end-to-end checks before and after the switch. They agreed.
  • Nothing to do at your end.

Version 2.343.0

September 28, 2026

Our research archive opens beyond the office, with the brake on

  • Reachable from anywhere, still private. The archive of the sources our research cites can now be opened from outside our own network. Nothing in it is shown to anyone who has not signed in.
  • Guessing is slowed down. The brake we added last release is now switched on for the archive: repeated sign-in attempts from one place are paused for a while, so a password cannot be tried over and over at speed.
  • Checked by trying to get past it. Before it opened, we tried each way around the brake we could think of, and made sure every one of our checks goes red when the protection it watches is missing. One of those checks was wrong the first time, and the change undid itself, as it was built to.
  • The status page asks the way a reader does. Its archive check now goes the whole way round, as a visitor would, rather than taking the short cut from inside. Nothing to do at your end.

Version 2.342.1

September 28, 2026

A brake on repeated sign-in attempts, ready before we need it

  • Groundwork for a tool about to open. Our web server can now slow down anyone who keeps trying to sign in, so a password cannot be guessed at speed. It is not switched on for anything yet; the first place it will be used is a new research tool opening shortly.
  • One change at a time. We checked that the new version of the server differs from the one running today in exactly this one way, and that our build refuses to produce one without it.
  • Nothing to do at your end.

Version 2.342.0

September 28, 2026

Getting ready to move our files without breaking a single link

  • Simpler names for where files are kept. The pictures, recordings and videos behind the site are moving to a new home with simpler names. This release teaches the site to keep serving every link already out in the world, in messages, feeds and shares, once that move happens.
  • Tried on our test copy first. We made the whole move on the copy of the site we test changes on, then checked every page and link we sampled still worked, and that no file had gone missing along the way.
  • Nothing has changed on the live site yet. Nothing to do at your end.

Version 2.341.1

September 27, 2026

Our test copy of the site no longer holds a key to the files you see

  • A key it never needed. The copy of the site we test changes on could reach every file the live site serves, because it had been given the same key. It now works only with files of its own, using a key that can read and write nothing else. We found this in our own security review and closed it the same evening.
  • Checked end to end before we called it done. Every kind of reading and writing the site does with its files was tried against the new arrangement, including jumping into the middle of a long recording, and each check was first shown to fail when pointed at the wrong thing.
  • Nothing to do at your end.

Version 2.341.0

September 27, 2026

We now keep our own copies of the sources our research cites

  • An archive of our sources. The pages, recordings and transcripts our research relies on can change or disappear without notice. We now archive them ourselves, so a citation still leads somewhere after the original has gone. The archive is private for now.
  • Archived pages cannot run their own code. A page we keep is shown as a still copy, with any scripts it carried switched off, so nothing in it can act on the person reading it.
  • Groundwork for testing changes well away from the files you see. This release only prepares the ground; nothing on the live site has changed.
  • Our checks try to fail first. Every check we wrote for this was first pointed at the wrong target to confirm it would object. A check that cannot fail tells you nothing.
  • Nothing to do at your end.

Version 2.340.0

September 27, 2026

Transcripts keep every word as it was transcribed, spelling and numbers included

  • Arabic and Persian transcripts keep their own spelling. Since April, the step that lines each word up with the audio had been handing back a simplified copy of Arabic-script text: vowel marks removed, several letters swapped for plainer look-alikes, and Persian’s joiner between the parts of a word taken out. The words now come back exactly as they were transcribed. Transcripts saved before this release keep the text they were saved with.
  • Numbers are no longer dropped. The same step threw away any word made only of digits or symbols, such as a year or a verse or hadith number, in every language. Since March those were missing from subtitles and transcripts. They are kept now.
  • Subtitle lines last as long as the words in them. Each word used to be timed as if it ended with its first letter, so a line could disappear while its last word was still being said.
  • When timings are estimated, the workspace now says so. If a recording’s words cannot be timed, each line’s times are spread across the audio by its length. That used to look exactly like measured timing. It now carries a notice: “Timings are estimated”.
  • Why our checks missed it: they confirmed that words came back, never that they were the words we sent. They now compare the two, in three languages, every time the service is updated.
  • Nothing to do at your end.

Version 2.339.9

September 26, 2026

Every tidy-up in our tools now checks before it removes anything

  • The last of our tools’ tidy-up steps now ask first. When subtitles, a voice, a narration, a trimmed recording or a set of wallpapers is replaced or deleted, the old file is removed only if it is the right kind, belongs to that piece, and is not still used anywhere else. If the tools cannot be sure, they keep it. Trimming a recording can no longer remove the full recording it was cut from.
  • A gap closed on the way: a request to delete one reflection’s wallpapers could have been shaped to reach every reflection’s. Only people with editing access could send it. We found this in our own security review; nothing suggests it was ever used.
  • Deleting wallpapers now deletes all of them. Six of every seven wallpaper styles used to stay behind in storage.
  • In the transcription workspace, a generated article is now saved as a file as well as on the page, and deleting a project removes its version history with it.
  • Nothing to do at your end.

Version 2.339.8

September 26, 2026

A picture opened on its own can no longer do anything but show itself

  • Some image formats can carry instructions for your browser, not just a picture. If one of those had reached our files and someone opened it directly, those instructions could have run as though our site had sent them. Every file we serve now tells your browser to show it and nothing more. Pictures, audio and video still open and play exactly as before. We found this in our own security review; nothing suggests it was ever used.
  • Uploads are named by what they are, not by what they are called: our editing tools now store a file under the type they have checked it to be, never the name it arrived with.
  • Nothing to do at your end.

Version 2.339.7

September 26, 2026

Our transcription workspace now only opens its own recordings

  • The transcription workspace plays, transcribes and tidies away the recording behind each project. It trusted each project to say where its recording was, and one unused way of creating a project let the person creating it name any file we store. The workspace now checks that a recording belongs to its project before it plays, transcribes, edits or removes it, and the unused way in is gone. We found this in our own security review; nothing suggests it was ever used.
  • File names stay yours: a recording keeps the name it was uploaded with, in any language.
  • Nothing to do at your end.

Version 2.339.6

September 26, 2026

Our editing tools now only tidy away files that are theirs

  • When our editors remake a picture or a video, the tools tidy away the old one. They trusted the page to say which file that was, so a page could name a file belonging to something else entirely. They now check that the file is the right kind, belongs to the piece being edited, and is not still used anywhere else — and they keep it if they cannot be sure. Saving a piece checks the same way. We found this in our own security review; nothing suggests it was ever used.
  • A quiet fix came with it: remaking one comic panel could remove a picture that the same story still used as its cover. That can no longer happen.
  • Nothing to do at your end.

Version 2.339.5

September 26, 2026

Three behind-the-scenes controls now check who is asking

  • Three of the controls our editors' tools rely on answered anyone who asked, not only signed-in editors: one listed the synthetic voices in our voice library, one removed a voice, and one set an article's audio. All three now require sign-in, as everything around them always did. We found this in our own security review, and a check in how we build the site now fails if any control that changes something neither checks who is asking nor is public on purpose.
  • Nothing to do at your end.

Version 2.339.4

September 25, 2026

Checking our backups less often, so they stop getting in each other's way

  • Our backup copies were being re-checked from end to end every day, and the checking ran into the evening's backups, crowding the network the rest of our systems rely on. Those checks now run weekly and monthly instead, away from backup time. We are changing one thing at a time, so we can tell what actually helped.
  • Nothing to do at your end.

Version 2.339.3

September 25, 2026

Our backups now take turns, and it fixed half of what we hoped

  • The busiest machines are now backed up one after another instead of all at once. On its first evening every backup finished and every machine was safely copied. But the network hiccups the change was meant to calm happened anyway, which tells us the cause is something else. We have written down what we measured and are following it up.
  • Nothing to do at your end.

Version 2.339.2

September 25, 2026

Our privacy page now covers diwan

  • The privacy page now says plainly what diwan promises about your writing: it is private by default, even from diwan's administrators, until you choose to share it, and you can stop sharing at any time.
  • Nothing to do at your end.

Version 2.339.1

September 25, 2026

Less waiting behind the scenes

  • Changes to this site and our tools were queueing to be checked and built, sometimes for many minutes. We added more room for that work, so fixes reach you sooner.
  • Nothing to do at your end.

Version 2.339.0

September 25, 2026

Title cards that spell the title right

  • Our editors told us the title cards on Reflections and Vignettes sometimes got the words wrong. They can now make a second card with sharper lettering, see it beside the first, and choose. The one they choose goes into the video, and the other is thrown away.
  • Nothing to do at your end.