Changelog — 2.353–2.357
Releases 2.353.0 through 2.357.1. Current releases are on the main changelog, and every band is listed in the release archive.
Loading audio...
Version 2.357.1
October 6, 2026IlmFlow and daftar wear their new marks in our menu
- The “Apps and Services” menu now shows IlmFlow’s new mark, the same one its new website carries, and daftar’s, redrawn the same day in the same teardrop shape as its siblings beneath it.
- Nothing to do at your end.
Version 2.357.0
October 6, 2026Some of our own keys had found their way into our code’s history — we are replacing every one
- We went looking for our own secrets, and found some. The passwords and keys our systems use to talk to each other had, over the past year, been copied into the history of our own code — into examples, notes and old settings files. That history has always been private, but a key is only as safe as the number of places that hold it, and these were in more places than they should have been.
- We checked everything, not just what we already suspected. Rather than reading files by eye, we compared every key our systems actually use against everything ever written into our code, without either side ever revealing a key. A check like that can fail in a reassuring way, so before trusting it we planted a fake key, hid it, deleted it again, and made sure the check still found it.
- Every key that turned up is being replaced, and each old one shown to no longer work. The ones anyone outside could have used went first, today. Each new key was proven to work by the same software that uses it before anything relied on it, and only then was the old one shown to be refused. Where our development site and the live site had been sharing a key, each now has its own.
- Our databases now check where a login comes from, not only the password. A login from anywhere other than the place that is meant to use it is refused before a password is even asked for, so a password on its own is no longer enough.
- Deleting an old key from history doesn’t make it safe — replacing it does. So we are replacing them, not just deleting them, and we have cleared the old values out of our documentation as well. Every future change to our code is now checked automatically for a password written into a connection address, and refused if it holds one.
- You may have noticed a few short pauses today. Some of these changes restarted part of the site, each for under a minute.
- And IlmFlow’s own website is now live at its address. The move we prepared in the last release happened today, in the single checked step it was built for.
- Nothing to do at your end. You stay signed in, and nothing you’ve saved was touched.
Version 2.356.0
October 6, 2026IlmFlow’s own website is getting ready to move in
- IlmFlow, our work with the hawza, is getting a website of its own. It replaces the old IlmFlow landing page, which still described features we closed months ago. This release prepares the move: the switch of its address happens in one checked step, which undoes itself if any check fails, and our status page now watches the site the way a reader reaches it.
- Its development copy is already at its real address, so it can be reviewed exactly as visitors will see it before the switch. The old page answered every address it was asked for with the same page, so a simple “is it up?” could not tell the two sites apart; the switch checks for an answer only the new site gives.
- Nothing to do at your end.
Version 2.355.0
October 6, 2026Changes to the systems behind our sites now take turns
- Several of our projects are now worked on at the same time. Each one is its own piece of work, but they share the systems that run them, and two changes made to those systems at once would leave any problem unable to say which change caused it. Until today, taking turns was a habit each of us had to remember.
- Now a change holds a turn, and anyone else is told who has it, what for and since when. The turn is taken in a single step that cannot be split, so two changes can never hold it at once. Only whoever took it can hand it back, and anyone kept waiting is told to wait, never shown a way round. A reviewer caught that our first version did show one, before anyone used it. We proved every safeguard by deliberately breaking it and watching the checks catch it, including twenty attempts started at the same moment, of which exactly one succeeded.
- Nothing to do at your end.
Version 2.354.14
October 5, 2026Our own release notes had quietly lost ten of their headings
- We keep two records of every release. This page is one; the other is a fuller set of notes we keep for ourselves. In ten releases, the step that adds a new entry to our notes replaced the heading of the one before it instead of adding above it. The words of those ten releases were all still there, so nothing looked missing, but they read as part of the release that followed.
- The headings are back, and a check now compares the two records on every change. It refuses any release that one record names and the other does not, and we proved it on the notes as they stood this morning: it named exactly the ten.
- Nothing to do at your end.
Version 2.354.13
October 5, 2026Our map no longer mistakes an unchecked machine for an idle one
- An internal reference showed a dash where nobody had looked. A dash reads as “runs nothing”, and for most of those machines that was false. It now says plainly when something has not been checked, and the machines behind our newer tools have been checked and recorded, with the date. One of our own notes about how a tool runs had gone out of date, and is corrected.
- Nothing to do at your end.
Version 2.354.12
October 4, 2026Our own map of what runs where was missing half of it
- An internal reference listed only the services we build ourselves. Anything we run from a trusted outside source looked idle in it, including the service that finds related passages for our writing. It now records both, and says which half is a measurement with its date, so nobody mistakes a running service for an empty machine.
- Nothing to do at your end.
Version 2.354.11
October 4, 2026Keeping a promise we had just made
- Every copy now expires. We promise that a recording you delete leaves our backups within about six months. One kind of copy, made by hand before each update, was never cleared away, so the promise was not yet true. Those copies now expire like every other backup, and new ones are made the regular way.
- Nothing to do at your end.
Version 2.354.10
October 4, 2026The last piece is in place
- Erasing a protected copy now works end to end. The private link between the tool that does it and the service that asks for it is set up, and it refuses anyone who is not on the inside, even with the right key. Our notes now say it is done rather than owed.
- Nothing to do at your end.
Version 2.354.9
October 4, 2026Saying who deleted it, truthfully
- The person confirming an erasure now reads the right story. When a recording was removed by an administrator because someone asked, the tool that erases its protected copy says so, and why, instead of saying its contributor deleted it.
- Nothing to do at your end.
Version 2.354.8
October 4, 2026A part we rebuild every release stopped building
- Caught before it mattered. One of the pieces behind transcription is rebuilt with every release, and the last release could not build it: a tool it depends on had a bug that the newest components happened to trigger. Nothing you use was affected, because the version already running was never replaced.
- Fixed by updating the tool first, as a sibling piece had already been doing all along, and tested by reproducing the failure and building the piece again.
- Nothing to do at your end.
Version 2.354.7
October 4, 2026Some deletions should need a person
- A protected copy has one key, and a person holds it. When a contributor deletes a recording that has been accepted, its protected copy can be removed only by a tool that shows a person exactly what it is about to remove and waits for them to confirm it. It never runs on its own, so nothing can be erased just because a list said so.
- Proven before it is ever needed. We tried it on a test file locked the same way: without the override it was refused, and with it the file was gone.
- Nothing to do at your end.
Version 2.354.6
October 3, 2026Welcomed in properly
- Trusted from the first connection. The machine prepared in the last release now proves who it is every time we connect to it, checked against what was read on the machine itself, so nothing was taken on trust.
- Nothing to do at your end.
Version 2.354.5
October 3, 2026More help reading Arabic scanned pages
- Getting ready. We are preparing to read more of the Arabic books we scan, and to read them faster. This release records the preparation; the reading itself comes in a later one.
- Nothing to do at your end.
Version 2.354.4
October 3, 2026Done, and checked
- Accepted recordings are now protected in the live system. The steps rehearsed in the previous release were carried out for real, each one checked before the next began, and the protection was proven by trying to break it.
- Nothing to do at your end.
Version 2.354.3
October 3, 2026Rehearsed before it is done for real
- The last steps, written down and tried first. Protecting accepted recordings in the live system means rebuilding a store in place. Every step now refuses to go on unless the files it would replace are already safe elsewhere, byte for byte, and each one was tried on a copy first, including the ways it must refuse.
- Nothing to do at your end.
Version 2.354.2
October 3, 2026An accepted recording gets one protected copy, and the working files go
- Two places, on purpose. The tool our contributors record lessons with makes working files while a recording is uploaded and put together. Those now live apart from the finished recording, so they can be tidied away, while an accepted recording is kept as one protected copy that cannot be deleted by accident.
- Checked, not assumed. Every file moved was compared byte for byte on both sides, and every permission was tested by trying it, including the ones that must be refused.
- Nothing to do at your end.
Version 2.354.1
October 3, 2026Recordings our reading tools keep cannot be deleted by accident
- Protected for ten years. The recordings the lecture library keeps, and the originals behind them, are now stored so that nothing removes them by accident, not even everyday administrative access. A deliberate removal is still possible when one is genuinely needed.
- A standing rule. Every store of this kind is now made this way from the start, and the two older ones not yet covered are named so they can be moved.
- Nothing to do at your end.
Version 2.354.0
October 3, 2026Recordings are transcribed on our own equipment, by rule
- A rule, not a habit. Every transcription has been made on our own equipment for some time. Until now that rested on each request asking for it; a request that forgot would have been sent to an outside service. Such a request is now refused, so a recording never leaves us by accident.
- Ready for the tools that come next. The lecture library and the class notebook will ask for transcripts too, and the same rule covers them from their first request.
- Nothing to do at your end.
Version 2.353.2
October 3, 2026A plan for the lectures that have a recording and no text
- Text first, then a transcript. Many of the lessons our lecture library is about to keep come as a recording, some with a written version beside it and some without. Where the written version exists, it is the text we keep. Where it does not, the plan is a transcript made on our own equipment, which never leaves it for an outside service.
- Machine-made, and always said so. A transcript, or a text read out of a document by a program, is not the speaker's own words until a person has checked it. Wherever one appears, it will say that it is machine-made, and it will not be offered for quotation until it has been checked.
- Written down before it is built. This release is the plan, with the measurements it rests on. Nothing about it is visible on the site yet.
- A shorter changelog page. The releases from 2.339 to 2.352 moved to their own page in the release archive. Every link to them still works.
- Nothing to do at your end.
Version 2.353.1
October 2, 2026The research library's originals are kept for ten years, whatever happens
- Locked from the first file. Every original the research library stores is now kept, unchangeable, for ten years after it arrives; a deletion in that time only hides it. The protection was planned when its home was built, and it covers every file moved in, the first ones included.
- Nothing to do at your end.
Version 2.353.0
October 2, 2026The plain-text version of an event now leads to its written pieces
- Both links, not one. Every event and session page has a plain-text version for machine readers. Where a part of a session had both a recording and a written piece, that version kept only the recording, so every filmed sermon lost the one link to its text. It now gives both, as the page always has.
- A whole series, to its texts, in one place. An event's plain-text version now lists, under each session, the pieces written for it, each saying what kind of piece it is.
- Nothing to do at your end.