Open source · Systems security
uutils/coreutils
Patched TOCTOU vulnerabilities in install, ln, and tac; built fd-anchored filesystem primitives and carried the protections across Linux, macOS, and FreeBSD.
CVE-2026-35356 · CVE-2026-35362
Systems software · Security · Infrastructure
I build dependable software at the edges of operating systems, security, and production infrastructure.
Currently working in Rust on secure filesystem operations at uutils/coreutils.
San Francisco, California
Selected work
Open source · Systems security
Patched TOCTOU vulnerabilities in install, ln, and tac; built fd-anchored filesystem primitives and carried the protections across Linux, macOS, and FreeBSD.
CVE-2026-35356 · CVE-2026-35362
Rust · Storage systems
A Git worktree isolation tool using copy-on-write storage across APFS, Linux reflinks, and overlay filesystems, with lifecycle tooling for real development workflows.
8× lower physical disk usage
Rust · AI infrastructure
A private inference gateway that schedules heterogeneous model instances by capability, placement, context limits, and live availability behind an OpenAI-compatible API.
Multi-worker llama.cpp backends
Co-founder & CTO · Production backend
Built the backend and voice infrastructure for a consumer financial platform, including encrypted PII, verified webhooks, isolated environments, and real-time calling.
Azure Container Apps · LiveKit
How I work
Secure primitives should preserve the behavior people depend on.
A fix is more useful when it survives the boundaries between operating systems.
Performance, storage, and operational tradeoffs deserve concrete numbers.
Contact
I’m interested in systems, security, and infrastructure work where correctness matters.