Patrick Gaskin

Backend/Systems Software Developer & Systems Administrator

About Me

I studied Computer Engineering at Queen's University, and graduated in 2024. I've created and contributed to open-source projects since 2018, and have been coding since 2014.

I generally do systems/backend development, security, reverse engineering, networking, devops, and systems administration work. I am proficient in web technologies, but dislike frontend web development.

I've been using Linux for over a decade, and also have some Windows experience.

I sometimes participate in and create challenges for CTFs, and occasionally dabble in cryptography.

I am a maintainer of cmus and dnscontrol, and contribute to many projects including PulseAudio, LineageOS, wasm2go, and various Linux desktop components. I also actively participate in the Kobo modding community.

When not at a computer, I'm usually reading sci-fi/fantasy, or doing sports on/in the water like swimming, skating (and some hockey), kayaking (mostly sea/flatwater), and some downhill skiing. I also do bouldering and jiu-jitsu, and a bit of medium-distance running. I hold first-aid and National Lifeguard certifications.

I am not currently looking for work, but am always happy to talk.

Technologies

I prefer to start new projects in Go, C, JavaScript/TypeScript, or more recently, Rust (which I'm currently learning). I'm also fine with Java, but only in the context of Android development, as I dislike working with Spring. I am familiar with Python and C++, and can effectively contribute to projects in many other languages.

I have more than a decade of experience with Linux, and have used it almost exclusively across servers and desktops, for both personal and professional work. My experience is primarily with Debian/Ubuntu. I am also comfortable with Fedora/RHEL.

I have some Windows knowledge. Although I am not experienced with AD or Azure, I am comfortable with troubleshooting and working in Windows environments if necessary, though I strongly prefer Linux.

I do not have any macOS or iOS experience.

I have a strong knowledge of networking fundamentals.

I have a slight dislike towards wholly AI-driven development since I prefer to have a deep understanding of and carefully design systems I work on. I also abhor AI writing, and will not use AI to write any long-form or user-facing text. However, I do accept that it is better at certain tasks and have started to use it for some things including the initial stages of reverse engineering, large amounts of boilerplate, and non-critical parts of frontend web development (which I dislike anyway). I almost always do all architecture work and important business logic by hand, and always read all thinking traces. The only time I go more towards vibe-coding is for frontend web development, and for subjects I have a high amount of existing domain experience with and can spot subtle issues preemptively and during review. I always hold LLM-generated code to the same architectural and functional quality standards as my own. For code which is only ever touched by LLMs, I have slightly lower standards for commenting and naming.

Expertise, Interests & Experience

Some specific topics I'm interested in and have a lot of experience and domain knowledge in:

  • e-book technology (reading systems, formats, Kobo e-readers)

    Kobo modding was how I first got into programming and reverse-engineering. Over many years, I redefined how modding is done and did a lot of novel reverse-engineering while creating many projects including kobopatch, NickelMenu, NickelHook, dictutil, etc.

    In addition, I have a deep interest in the EPUB specification and have worked with many reading systems, and previously participated in the EPUB Community Group. I'm familiar with general information about other formats too.

    I am familiar with the details and quirks of most EPUB reader software including pretty much every Android one, RMSDK, Kobo, OverDrive Read, and so on.

  • linux sysadmin and troubleshooting, and containerization (especially debian-based distros)

    I'm passionate about Linux userspace technologies and command-line tools, and can set up and troubleshoot most things on the fly with or without Google. I've also done packaging work for Debian, Fedora, and Arch.

    I'm also experienced with namespaces, cgroups, and other fundamental concepts underlying sandboxing/container runtimes like Docker/Podman and nsjail/flatpak.

    I enjoy solving hard challenges, even when they involve unfamiliar technology.

  • linux desktop ecosystem (wayland, x11, pipewire, pulseaudio, etc)

    I've been using Linux since I was 11. I've also contributed significant patches to many projects in this area for core technologies (e.g., pulseaudio), desktop environments/compositors (e.g., niri, smithay), and applications (e.g., cmus).

  • devops, with a focus on supply chain security (reproducible builds, package mirroring, secure deployment pipelines, etc)

    I care deeply about reproducible builds, secure CI/CD, and the ecosystem around this. I've also implemented mirrors and package registries for software where good solutions aren't available or aren't natively supported (this work isn't open-source unfortunately).

    Almost all of my recent open-source projects have secure CI/CD pipelines, hermetic reproducible builds, and immutable artifacts. I carefully audit most dependencies, reading all commits where feasible, and try to keep dependency trees small and high-quality.

  • backend/systems development (system software, web backends, integration)

    I've designed or contributed to many small-to-medium-sized system applications and backends with a focus on correctness, scalability, security, performance, and robustness. I've also operated and monitored many of these over multiple years.

    As part of this, I focus on understanding the problem before writing code, keeping boundaries and failure modes explicit, manually auditing dependencies, ensuring builds/deployments are reproducible, validating all inputs, optimizing the design before doing micro-optimizations, sandboxing and isolating systems, maintaining up-to-date system documentation, keeping logs/metrics useful and actionable, and ensuring forwards/backwards compatibility across versions where required.

    Most of these projects aren't open-source.

  • web scraping

    I like writing web scrapers, with a focus on scalability, backwards/forwards compatibility, and completeness/correctness. I also enjoy transforming the scraped data into a more usable and stable machine-readable form. I frequently write scrapers for my own use, and have a few public projects too (mostly involving recreation schedules): ottrec, innosoftfusiongo-ical, innosoftfusiongo-schedule.

  • git internals

    I have a good understanding of git internals, both for regular usage, and for creating custom tooling using it. Most of my work in this area is private (and mostly around custom storage backends and git servers), but I have a few open-source projects like push-signed-commits.

  • reverse engineering (focused on android, web applications, and linux system software)

    When something closed-source doesn't do what I want or has bugs, I almost always end up instrumenting it (web devtools, smali patching, bpftrace, ptrace, LD_PRELOAD), then fixing it myself. If patching it becomes too much work, I reverse engineer the underlying technology and make my own version.

    I maintain a large number of complex patches and custom tooling for Kobo e-readers (embedded, C++/Qt), the Lithium EPUB Reader (Android/Java), and RealVNC. I also have many smaller private patches for various things I use personally.

    I have experience reverse-engineering buggy or old firmware and creating compatibility layers or alternative software.

  • remote desktop protocols

    I'm extremely interested in the RFB (VNC) specification, including proprietary extensions. I've also done some reverse-engineering of RealVNC with the goal of understanding RFB 5.0/6.0 and porting it to Wayland. I maintain multiple open-source projects related to this.

    I have a general understanding of most other remote desktop protocols (e.g., RDP, NX, RustDesk, SPICE, etc).

  • networking

    Although not my primary focus, I've done quite a bit of networking work, and experiment with it a lot. I have a strong understanding of the fundamentals, and am especially interested in the design and implementation of routing/tunneling/proxy protocols.

    I have some experience implementing and troubleshooting WireGuard, GRE/GRETAP, SOCKS, OpenVPN, and various HTTP/TLS-encapsulated proxy protocols. To a lesser degree, I am familiar with VXLAN, IPv4/v6 tunnels and transition technologies, PPPoE, and other protocols.

    Most of my work in this area is on Linux directly, or OpenWrt. I have very little experience with most proprietary networking equipment, but can work on them with documentation, albeit less efficiently.

  • android

    I'm generally familiar with most Android subsystems, and have contributed to custom ROMs. I have a very in-depth understanding of the ADB protocol, and have written multiple implementations of it. I have some experience troubleshooting cellular network connectivity, and diagnosing APN and IMS issues. I maintain the Canadian APN list used by LineageOS-based custom ROMs.

  • toolchains and application porting

    I've ported multiple libraries to WebAssembly. I've also worked on toolchains for embedded systems. I occasionally port desktop software to other platforms (e.g., PulseAudio for Windows, and various linux applications to Android). I'm also familiar with making various toolchains build reproducibly.

Projects

Android Apps

I maintain a few Android apps which I wrote for myself, but have since become somewhat popular.

Windy Live Wallpaper

Android live wallpaper visualizing local wind patterns. Inspired by the Pixel 2017 live wallpaper, but rewritten from scratch.

  • Completely rewritten Java code.
  • Completely rewritten shaders.
  • Modern render pipeline using WebGPU.
  • Correct rendering on newer devices.
  • More color schemes.
  • Updated wind data (the official data was last updated in 2019).
  • Better location handling.
  • Lower memory and CPU usage.
  • Optionally render static frames to effectively eliminate all resource usage.
  • Support for custom themes.
  • Support for automatically generating themes for an arbitrary color.
  • Java
  • Rust
  • WebGPU

Vento VNC/RDP Client

Fast, fluid VNC/RDP remote desktop client for Android, with touchpad-style controls and multiple client backends.

  • Intuitive touchpad-style controls.
  • Accuracy assists (improved precision, axis locking, adaptive acceleration).
  • Material Design 3.
  • Multi-window support.
  • Physical keyboard/mouse support.
  • Workarounds for various Android IME bugs.
  • Hardware-accelerated video where supported (H.264 with FreeRDP and TigerVNC, H.264/H.265/VP8/VP9/AV1 with RustDesk).
  • Multiple client backends for VNC (TigerVNC, LibVNC, Rust) and RDP (IronRDP, FreeRDP), plus SPICE.
  • Optional RealVNC backend (separate APK, fetches the library at runtime).
  • Optional RustDesk backend (separate APK), reaching a machine by ID through a rendezvous server or by address.
  • Java
  • Rust
  • C

LLM-assistedDesign, architecture, and feature planning is done by me. App code is LLM-written, but reviewed by me, and reuses a lot of code I already wrote for other projects. Backend library bindings are LLM-maintained.

cmus-android

Port of the cmus music player for Android, with system integration and some extra UI features.

  • Supports Android 14+.
  • Additional touch-friendly UI components.
    • Top bar with live-filter, views, and settings.
    • Bottom bar with play/repeat/shuffle/seek/volume/queue/keyboard.
    • Long-press tracks/playlists to add/remove.
    • Joystick for scrolling and switching panes/views.
    • Graphical settings view for most relevant settings.
  • System integration.
    • System media controls and metadata.
    • Stops the cmus process after being idle for a bit to save power, automatically restarting it when focused or media buttons are used.
    • Material You color scheme.
    • Music from external storage.
    • UI colors match cmus theme.
    • Audio ducking.
    • Library paths are relative to data dirs so import/export works correctly.
  • Extra features.
    • Album art support.
    • Sleep timer.
    • Font options.
    • Data import/export.
    • Sub-second seeking accuracy.
    • Continuously saves state.
  • Optimized for power efficiency.
  • Java
  • C

LLM-assistedDesign, architecture, and feature planning is done by me. App code is LLM-written, but reviewed by me. I have been an upstream cmus maintainer since 2021.

batterytile

Android Quick Settings tile showing the battery current, temperature, time remaining, and status.

  • Works on Android 12+.
  • Toggle between current, temperature, time, and status.
  • Java

lithiumpatch

I've patched a lot of significant features (thousands of lines of code) and bugfixes into the closed-source Lithium EPUB Reader.

  • Dictionary (works offline).
  • Custom fonts.
  • Additional font script support (e.g., Thai).
  • Finer control over font size.
  • Support for hyphenation.
  • Additional information in the reader footer.
  • Series metadata support.
  • Series section in library drawer.
  • Book progress badge.
  • Optional cover-only grid view.
  • Additional built-in themes.
  • Material You colors on Android 12+.
  • Support for inverted portrait/landscape rotation.
  • Option to disable page turn animations (e.g., for e-ink screens).
  • Option to invert the color of images or the entire page.
  • Smali
  • Go
  • Java
  • JavaScript

I've also contributed a number of features to the LineageOS Keyboard (cursor control, more themes, better symbol layout to match GBoard, clipboard key, etc).

Android Tooling

I initially created these for my own use, but they ended up being useful enough to publish.

  • Capture system-wide Conscrypt/BoringSSL TLS traffic on Android using eBPF.

    • Go
    • eBPF
    • ptrace
  • Go ADB library with a focus on ergonomics, stability, correctness, error handling, extensibility, compatibility, and completeness.

    • Go
    • ADB
  • A bunch of experimental tooling and notes for figuring out Canadian APN settings

Recreation Schedules

Most official ones kinda suck or are hard to browse, so I scraped the underlying data and made something better...

Queen's University ARC

Screenshot of arc.qu.pgaskin.net/swim. Screenshot of ifgical.api.pgaskin.net/110. Screenshot of arc.qu.pgaskin.net/rec.

Their schedules were only available on their website as a PDF, which was often outdated and doesn't contain cancellations/changes, or on the Fusion Go app, which only shows one day at a time with no search/filter.

I wrote a scraper for the Fusion Go backend, then designed an algorithm to merge the individual occurrences into an optimal weekly schedule.

The swim schedule continues to be more popular than the official website, receiving hundreds of pageviews weekly.

The tooling I wrote for this is compatible with other facilities which use Innosoft Fusion too, which include most Canadian universities.

I also found a few vulnerabilities in Innosoft Fusion (an ASP.NET Core application) along the way...

City of Ottawa

Screenshot of ottrec.ca/today. Screenshot of ottrec.ca/schedules/lane-swim. Screenshot of ottrec.ca/map.

The City of Ottawa publishes schedules on individual facility pages, without a way to search/filter them.

In addition, the schedules are maintained by hand and frequently contain typos. I wrote a bunch of code to detect these, and report them to the city every day or two.

There are some existing efforts to aggregate these, but they have either kinda died due to the effort (for the hand-written ones), contain blatant errors (the llm-powered scrapers), or don't really provide much additional functionality other than putting them on a single page and miss relevant details like schedule date ranges (for the automated ones).

With permission, I wrote a scraper which produces an open dataset with unambiguous schedule information in a machine-readable and consistent format, being especially careful to ensure the data is either fully parsed or an error is displayed. I also preserve the raw data, keeping the parsed version in marked fields, so even unparseable information is still somewhat usable.

I later created a user-friendly website to show the data in a much more usable form.

  • Scraper and schema code, core parsing logic. I put a lot of effort into ensuring parsing is unambiguous, correct, and complete, even though the city website is maintained by hand.

  • Machine-readable parsed dataset, plus snapshots of the scraped pages.

  • Custom in-memory index, heuristics, custom query language for advanced search. I put a lot of thought and effort into making this one fast, efficient, and ergonomic, and it was very much worth it due to the unique structure of data.

  • Server-rendered website using templ for templating, progressively enhanced using TypeScript.

    LLM-assistedAlmost all frontend code is LLM-maintained. Copy is written by me. Testing and architecture is done by me.

  • Experimental website showing changes to the schedules over time.

    LLM-assistedEntirely LLM-written, but the design was verified by me. I will rewrite this by hand before releasing it.

  • Parses the completely free-form cancellation and schedule change notes deterministically. Used to reduce the severity of the schedule change warnings on the website where applicable to reduce warning fatigue for users.

    LLM-assistedEntirely LLM-maintained (it's superior to using an LLM to do the parsing directly, and the effort to write it manually would be prohibitive), but based on my ideas, and I frequently quality-check it both by hand and with am LLM.

Remote Desktop

Various projects related to remote desktop stuff.

  • Fake X server backed by a Wayland display, implementing just enough for RealVNC to work on it.

    • Rust
    • X11
    • Wayland

    LLM-assistedA lot of code was LLM-written, but the idea and overall design were mine. Fully tested and reviewed by both me and the LLM.

  • Proxies an existing Wayland connection, implementing zwp_virtual_keyboard_v1 and zwlr_virtual_pointer_v1 using uinput to work around broken/incomplete compositor implementations.

    • Rust
    • Wayland
  • Notes about using RealVNC on Wayland. Superseded by xwlrvnc, which is superior in almost every way.

    • Wayland
  • Patches the RealVNC 4.x Android app to fix bugs and improve usability. Superseded by Vento, my remote-desktop app, which supports using the RealVNC libs as a protocol backend.

    • Android
    • Java
    • Smali
  • Almost like a KVM switch, but using SPICE, a virtual machine, and a dedicated GPU with a regular monitor connected to both machines.

    • C
    • SPICE

I wrote the modern virtual input (niri, smithay) and screen capture protocol implementations (niri) for niri/smithay.

DevOps

I am a maintainer of dnscontrol.

Kobo Modding

I'm pretty well-known in the community for many of these projects, and can be found in the MobileRead Forums. This is how I learned many of the things I know now, so the code quality varies. It's been almost 10 years, so I'm also taking a break from Kobo stuff in general and some projects are no longer fully up-to-date, but the community has continued to maintain forks of quite a few of them.

Screenshot of pgaskin.net/KoboStuff/kobofirmware.html.

Kobo Firmware Downloads

Kobo Firmware Downloads gets the latest official firmware download links from the Kobo API.

NickelMenu

The easiest way to launch scripts, change settings, and run actions on Kobo e-readers.

Screenshot of pgaskin.net/kepubify.

kepubify

Fast, standalone EPUB to Kobo EPUB conversion tool.

  • A library for creating mods for Kobo's eReader software, Nickel.

  • Adds native support for parsing series (and subtitle) metadata from EPUB files.

  • Tools, documentation, and libraries related to Kobo dictionaries.

  • An improved patching system for Kobo eReaders.

  • Small utilities for doing stuff with Kobo eReaders.

  • API proxy for kobofirmware.

  • A dockerized, deterministic, automated, fixed, and fully-relocatable build of @NiLuJe's toolchain for Kobo eReaders.

I continue to help review and test other community mods, and mentor people new to it.

Library Bindings

I've written high-quality library bindings for various libs. Most are native ones compiled to WebAssembly, then transpiled to Go. I put a lot of effort into ensuring builds for the blobs are fully reproducible, and into ensuring the API design is idiomatic and future-proof.

You might notice that a lot of these are for frontend web dev. See innosoftfusiongo-schedule for an example of how I tend to use these to write pure-go self-contained server-rendered websites.

I actively contribute to wasm2go, and have diagnosed and fixed multiple optimizer bugs.

Other projects

  • CLI and library for pruning time-based snapshots with a flexible retention policy.

    • Go
  • Go library and command-line tool to extract Qt resources from RCC files and executables.

    • Go
    • C++
    • Qt5
  • A simple but flexible library for implementing efficient, fast, responsive, and error-tolerant i3status replacements in Go.

    • Go
  • A simpler and more powerful alternative to the Go stdlib for generating indented namespace-aware XML.

    • Go
  • Go library to parse dictionaries from Microsoft Edge's Immersive Reader. Reverse-engineered format.

    • Go
  • Windows tray icon to set the EFI BootNext option.

    • C#
  • Read-only on-screen evdev keyboard display.

    • C
  • Assembler for the CPU created in the Queen's University ELEC374 Winter 2023 course.

    • C
    • Assembly
    • JavaScript
  • Library and tools for parsing and exporting Chrome bookmarks. Includes a simple file carving utility.

    • Go
  • PulseAudio build for Windows with an installer, service, and other improvements. Most patches have now been upstreamed.

    • C
    • Windows

I am a maintainer of cmus, and frequently contribute to various Linux desktop projects.