Skip to content
View ferstar's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report ferstar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ferstar/README.md

Hi, I'm J. F. Zhang 👋

Geek · incurable tinkerer · dad of a lovely little girl
I take things apart until they tell me how they work — laptops, phone kernels, AI agents.
Lately: teaching software that already knows its craft to talk to AI, in ways people can trust.

极客,爱搞机,家有可爱小女一枚
喜欢把东西拆开,直到它说出自己是怎么运转的:笔记本、手机内核、AI Agent。
最近在做的事:让懂行的老软件学会和 AI 对话,并且让人放心。

Blog X RSS

What I work on

  • Making existing software agent-ready — exposing what a product already does well as task-level MCP tools that any agent can call, rather than building yet another agent. The domain assets stay the moat; the agent is interchangeable.
  • The trust layer — identity carried through to the person behind the agent, permissions that never exceed theirs, audit trails, answers traceable to the source page, and human sign-off where it matters.
  • Agent execution security — what an agent can read, run and send out, and how to enforce that at the OS boundary instead of trusting the vendor's promise.
  • Agent runtimes — streaming lifecycles, tool-call recovery, loop guards, context compaction and MCP isolation, mostly in Rust.
  • Financial document systems — a production platform for regulatory filings and annual reports that I owned for a long stretch: parsing, rule checks, and a Python stack modernized end to end. On top of it, I led the build of the AI-powered annual report platform an exchange launched for its listed issuers.
  • Linux & low-level fixes — touchpad gestures, laptop ACPI quirks, phone kernels: when the hardware misbehaves, I go down to the driver.
  • Pragmatic Python tooling — small tools that remove a daily annoyance and then get out of the way.

Featured

RunSeal · Rust
An OS-native sandbox layer and stable execution protocol for AI agents. Policy-governed filesystem and network boundaries, structured audit events, and fail-closed behavior whenever a request can't be fully enforced. Windows is the reference backend; macOS and Linux are experimental. → Why I built it · 做 RunSeal 的初衷

ZCode silent upload disclosure · Sep 2026
Found that an AI coding tool with 1M+ users was packing workspaces — including full .git history — encrypting them and uploading them to cloud storage, on by default with no way to turn it off. The disclosure led to the feature being removed, the client being open-sourced, and third-party security audits. → 扒一扒 ZCode 静默上传全量 Git 历史的骚操作

Notes on agent engineering

Latest from the blog

Linux & systems

Project What it is
gestures · Rust · ⭐111 The maintained fork of a libinput touchpad gesture tool, rebuilt around fast three-finger dragging on both X11 and Wayland. Now has several times the stars of upstream. Write-up
ideapad-laptop-tb · C · ⭐55 Out-of-tree kernel module fixing lid-close "dead sleep" and Fn+F5/F6 shutdowns on 2024 ThinkBooks, shipped to users months before the fix reached mainline in 6.15.4.
xiaomi_xaga_kernel · C · ⭐50 Custom kernel for Redmi K50i / POCO X4 GT / Note 11T Pro, including an MGLRU backport.
kernel_manifest · ⭐36 Kernel build for Realme GT5 Pro (SM8650), forked 48 times.

Tools

Upstream contributions

Code is cheap, let's talk.

Pinned Loading

  1. gestures gestures Public

    Forked from riley-martin/gestures

    Fast touchpad gesture tool

    Rust 111 11

  2. ideapad-laptop-tb ideapad-laptop-tb Public archive

    The IdeaPad ACPI Extras kernel modules for ThinkBook 2024 NoteBooks

    Makefile 55 4

  3. xiaomi_xaga_kernel xiaomi_xaga_kernel Public

    Forked from Rohail33/Realking_xiaomi_xaga

    Kernel Source For PocoX4-GT/RedmiK50i/Note11tpro ( XAGA/IN/PRO)

    C 51 30

  4. check-requirements-txt check-requirements-txt Public

    A tool (and also a pre-commit hook) to automatically check the missing packages in requirements.txt and pyproject.toml.

    Python 12 3

  5. blog blog Public

    HTML 18 1

  6. runseal-labs/runseal runseal-labs/runseal Public

    OS-native sandbox layer and stable execution protocol for AI agents

    Rust 3