Redbean 2.0 turned into more than a hobby project
justine.lol
justine.lol
PHP support would be beyond amazing, what would be required (top-level) to get that working/usable?
If there were a plug-in system to be able to run different languages than Lua, that would be cool too, but maybe I’ll have to learn Lua.
If you're running a production web server you're not really switching OS's often. Something like nginx is battle tested so what would be the benefits of using redbean?
It is a marvelous piece of technology but I am struggling to see the use cases right now.
We live in a fragmented o/s world. If you're someone like me then you've got a Macbook from the office, a Windows PC for games, a Linux workstation for compiling code, a FreeBSD server, an OpenBSD router, etc. When you're dealing with so many different systems, sometimes just having something as simple as a sed command that works reliably the same seems like an impossible ask. Now we've got an entire app platform that works on the lion's share of PCs/servers in a small 1mb file.
It's also a question of being able to distribute code. I used to work on the TensorFlow team. We were tasked with building an open source library that people on pretty much every platform imaginable would use. It broke my brain just how difficult it was for us to ship open source binaries that actually work and don't cause an avalanche of GitHub issues. Even just working on more than a few Linux distros felt like an impossible ask back then. Now that I've figured out how to do it for every distro and seven operating systems total in just one file, I wish I could go back in time and use tools like redbean and Cosmopolitan Libc to fix all the things with TensorFlow that I wish I could have done. It'd've been a different project.
... and then people want you to distribute a libtensorflow.so which they may link to or dlopen. :cry:
I had been in this "trying to distribute binaries working on every Linux distro since 2010" game too and I hate it.
How would this work? Does the user start and stop the server manually? One nice thing about an electron app is that you open and close it like a normal application.
The way I used it was that if the user launched the binary, it spawned a server and opened the browser pointing at it.
If the user closed the tab, it automatically shut down the server. Or if it lost connection to any browsers for more than one hour.
LaunchBrowser('/')
That way when redbean starts up, it opens a tab in your desktop browser automatically to display your app. https://redbean.dev/#LaunchBrowserI cannot currently see it as a traditional web server replacement but perhaps that was not the intention. Running the web server locally loses the benefits of single place updates.
Isn't that what Docker set out to do using containers and IMO was hugely successful? How is this different?
I’m curious if any other users ran into issues with MacOS running 2.0? I may have just missed a step, but I started an issue nonetheless.
https://github.com/jart/cosmopolitan/issues/426#issue-127445...
Also, why is redbean.dev not ported to 2.0?
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Ca...
Personally I've opted for "stale only" caching, so everything is served with Cache-Control: max-age=0,must-revalidate and a Last-Modified header and the browser will always make corresponding If-Modified-Since requests. This means significantly more requests per page, even if the responses are mostly 304 Not Modified, but getting to avoid all forms of cache busting makes developing a lot nicer.
How expensive is that? I would naively have expected that comparing timestamps and sending a 304 was cheap to execute.
However if you are serving clients with highly restricted bandwidth you're probably going to want extremely cacheable resources (public, immutable) and perhaps even a completely different site architecture.
Also, in Chrome, if and only if you have the dev tools open, right clicking the reload button will give you a menu with the options "Normal Reload", "Hard Reload", and "Empty Cache and Hard Reload". The third option will ensure that requests initiated by JS or that otherwise weren't part of the page load also won't be served from cache.
I'm pretty sure I remember using it earlier than that but can't be 100%.
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=46845#c7
[2] http://www.bu.edu/uis_web3270/en/doc/troubleshoot/pd_ck_down...
But it hasn't always been easy to find documentation about it, thanks to a combination I think of "simplifying" everything and Google not delivering correct results since somewhere around 2010.
Thankfully now there is Kagi that actually makes a bug report if you provide them with an example that doesn't work.
Sorry for the misinformation
Could someone explain this? I cannot find any information online
I put definitions here awhile ago, and mentioned the Actually Portable Executable project as an example of taking the ABI philosophy to an extreme, and ignoring APIs (source code).
https://www.oilshell.org/cross-ref.html#API
Links to this thread:
https://news.ycombinator.com/item?id=12029321
It's unfortunately not explained well in many places, and even experienced C programmers don't understand the details. You won't learn about this in a C programming book, because it's not really part of the C language proper. It sits at an awkward spot between the language, the CPU, and the operating system.
----
The relation to Linus Torvalds is that historically Unix kernels were developed in a single tree and there was no stable ABI. For example I believe OpenBSD and NetBSD are still like this. But Linux is different in that the kernel maintained a stable ABI, and you can run different user utilities on top, without necessarily recompiling them against headers.
Highly related blog post and discussion: https://old.reddit.com/r/ProgrammingLanguages/comments/tg55o... (including comments by me/oilshell explaining the Unix kernel interface issue)
All i/o (network, filesystem, ipc), memory allocation, process interaction, signals, etc go through syscalls. open(), read() and write() are all syscalls.
If the syscall interface exists then the only thing left to do is to execute the program -- which depends on the cpu executing the machine instructions. If the machine instructions are for the wrong cpu then emulation may come into play.
You are up there on the same level as Fabrice Bellard!
I look forward to playing with this!
Part of what makes the redbean TLS stack fast is I spent some time hacking on MbedTLS to improve its performance. One of things that's counter intuitive about crypto code is assembly can be safer in additional to being faster, since it helps guarantee the compiler doesn't add branches, for things like bit overflow carrying in arithmetic operations. One example is https://github.com/jart/cosmopolitan/blob/master/third_party... which I wrote to make the NSA curve much faster. I've been meaning to upstream into MbedTLS. Another thing I added is https://github.com/jart/cosmopolitan/blob/master/libc/nexgen... which greatly improves the performance of RSA multiplication using Intel's ADX ISA. But C crypto code can be beautiful too! For example, I found Everest (curve25519) particularly impressive, since they solve overflow in a different way, and as such, it's quite possibly the only large piece of C/C++ code I've ever seen that contains zero conditional branches and zero pointers. https://github.com/jart/cosmopolitan/blob/master/third_party... The closest thing I've found to measuring the performance impact of my changes is by recording how long the MbedTLS test suite takes to run. The speedup for suite_ssl is 13.11x faster, RSA is 1.91x, ECP is 1.86x, and ECDSA is 2.84x.
This was testing against the old version (1.4) a while ago. I retested using the new version and have 0 errors.
However, that said, I also upgraded my ethernet switch since then, so possibly the original TLS errors were due to simple dropped packets.
Yes and some of the largest web infrastructures in the world run on it! I'm not sure if it's still true, but it's my understanding that CloudFlare runs it at the edge globally. I personally know of several other _very large services_ running it at massive scale.
In my experience Lua in nginx is such a pleasure to work with. It's all transparently async using nginx's event loop. You just write regular procedural code in Lua and the runtime handles yielding/resuming for you automatically. There's no special async/await stuff. Just write your Lua code and the runtime figures out the yield points internally. It's a breath of fresh air.
[1] https://en.wikipedia.org/wiki/OpenResty
Edit:
This was from several years ago, but CloudFlare built their WAF product on nginx/Lua:
https://blog.cloudflare.com/cloudflares-new-waf-compiling-to...
I'd say yes; I've been using it to develop https://github.com/pkulchenko/fullmoon, which is a redbean-based webframework written in Lua.
[0] https://leafo.itch.io/ [1] https://moonscript.org/ [2] https://leafo.net/lapis/
For instance, we've been building a totally static site recently in node/npm/js/posthtml and posthtml has a concept of "local variables". A project called posthtml-expressions in theory allows you to put "expressions" into "HTML" modules (if's, loops, etc.), but it only works with "globally" defined variables. i.e. you can't define a variable locally to a component, you need to define it "globally" in the project, which IMO defeats the whole purpose of the project. Nowhere is this easily explained or defined in their documentation. The first thing I want to do is define a property/attribute inline to a component, otherwise I end up with word soup of global variables - $page_1_title, $page_2_title, etc., rather than <component title="xxx">. Bizarre. No idea what the point is if I can't declare variables "locally" to said component? And this is the feeling I've got of lots of NPM packages - there is just no cohesion between things. I love the work people have done, it's literally saved me hundreds of man hours, but I've also spent untold hours wrestling with things that seem obvious to me, that should work, which frankly just don't work how I expect. Maybe it's me?
> Funding for the development of redbean was crowdsourced from Justine Tunney's [GitHub sponsors](https://github.com/sponsors/jart) and [Patreon subscribers](https://www.patreon.com/jart). Your support is what makes projects like redbean possible. Thank you.
wget https://redbean.dev/redbean-2.0.1.com -O redbean.com
2022-06-17 10:35:12 (1,95 MB/s) - ‘redbean.com’ saved [1999386/1999386]
chmod +x redbean.com
./redbean.com
./redbean.com: line 16: /tmp/ape: cannot execute binary file: Exec format error
./redbean.com: line 16: /tmp/ape: SuccessNot super familiar with this stuff, can someone explain?
A popular way to host now is to have an nginx server or process that accepts requests from the outside and then makes a request to a less capable web server for the app internally to provide a response, also known as proxying. This provides a clear barrier with outside world in one very concise config file.
What redbean apparently has is a sufficiently high quality web server included, so they can handle requests from top to bottom in one package (vertically integrated).
Anyone have suggestions for caching? router? Something small and lightweight in the spirit of readbean itself.
Windows Defender quarantines the file within seconds of download, but even when I did catch the option to Allow, it never seemed to stick.
It would be nice to either find a way to avoid redbean being seen as a virus (I'm guessing it's the self-modifying code that bothers it), or ask Microsoft nicely to add redbean to the False Positives list.
However, I'm guessing it would be easy for someone to misuse redbean too, deploying what looks legit but with some added nefarious code. In that case, you'd need to submit checksums of legitimate releases to Microsoft (and other antivirus vendors) just to make deployment of the base redbean work without complaint. And anyone who adds to the archive for their own use (basically any real use of it) would have to do the same...
Not trying to discourage anyone. This is a great project! Looking for solutions to the false positive antivirus problem.
In that spirit I wanted to generate a redbean executable for an SPA. To make this process a bit easier I just published a Github Action to create a redbean server for static assets: https://github.com/marketplace/actions/create-static-redbean...
Thanks to this my Github page now hosts a single-file server of... itself: https://timonlukas.github.io/server.com
The future is now!
Do you plan on writing your own tcp/ip stack with cosmopolitan? Why not pull in the networking stack and syscall libraries from MirageOS?
Just double-checking--it is still written in c?
My comment about not knowing if running redbean on bare metal was sarcasm was a comment about me, not about redbean or Justine, so no disrespect intended.
There's a lot of "turtles all the way down" today (a web server compiled to WASM so it runs in a browser running on a OS hosted in QEMU that's running on another host OS that's a virtual machine running in a linux container on top of a hypervisor running on an X86 simulator...) so I quite honestly couldn't tell if the idea of running redbean on bare metal was sarcasm or a joke.
But Justine says its true, so I guess it's not a joke. Consider me schooled.
A battery discharge rate of 0.5%/h in sleep is just great... but I think I can do better: I'm now trying for 0.25%/h.
Imagine if you could immediately resume your foldable oled tablet, and it'd have only lost like 6% of the battery. With a 20% hibernate trigger, it would remain immediately available for over 3 days straight!
I love the spirit :)
> The main blocker is figuring out how to get an e1000 and/or VirtIO driver in there with a TCP/IP stack.
Why? Is it for performance reasons or security reasons? (or both)
> Right now Cosmopolitan bare metal support is only adequate for stdio applications, which use the serial port and read from the zip fs.
I'd suggest you "think different", and use instead something like ppp to create a TCP/IP stack over a serial link.
Modern btuart implementations already routinely achieve >1Mbps on commercial devices. The GSI as seen on the Intel Serial IO devices support bitrates over 20Mbps.
This could buy you time until you find a better solution, if it's ever needed (which I doubt as back of the envelope estimations make me believe you'll hit other limitations before)
I can have a look at using ppp for creating a network connection using stdio. It doesn't look very complicated.
> it's hard to test kernel code
Exactly why I suggest pppd (userland) instead of VFIO
> So I not only need to build the kernel but I need to emulate the CPU features the kernel needs too
You have stdio? No need for anything else.
> It'll be nice to know that any normal PC program we write will "just work" on Raspberry Pi and Apple ARM. All we have to do embed an ARM build of the emulator above within our x86 executables, and have them morph and re-exec appropriately, similar to how Cosmopolitan is already doing doing with qemu-x86_64, except that this wouldn't need to be installed beforehand. The tradeoff is that, if we do this, binaries will only be 10x smaller than Go's Hello World, instead of 100x smaller. The other tradeoff is the GCC Runtime Exception forbids code morphing, but I already took care of that for you, by rewriting the GNU runtimes.
Also this, from a GitHub issue (https://github.com/jart/cosmopolitan/issues/354#issuecomment...):
> Probably related to #399. The recommended approach would be to use a full emulator like Bochs. It's not something we use at the moment so we can't provide support on this. Although we do intend to have APE support ARM at some point in the future.
Tried to run it IN CMD.EXE with
redbean.com -v
I get this error (in a dialog).
--------------------------- Unsupported 16-Bit Application ---------------------------
The program or feature "\??\C:\Downloads\redbean.com" cannot start or run due to incompatibity with 64-bit versions of Windows.
Please contact the software vendor to ask if a 64-bit Windows compatible version is available.
--------------------------- OK ---------------------------
If I've missed twiddling an option, please let me know?
wget -O redbean.com https://redbean.dev/redbean-demo-2.0.1.com
.\redbean.com -v
The "curl" on Windows appears to output a UTF-16 headers list to stdout. I verified the above will work in PowerShell.Program 'redbean.com' failed to run: Operation did not complete successfully because the file contains a virus or potentially unwanted software At line:1 char:1 + .\redbean.com -v + ~~~~~~~~~~~~~~~~. At line:1 char:1 + .\redbean.com -v + ~~~~~~~~~~~~~~~~ + CategoryInfo : ResourceUnavailable: (:) [], ApplicationFailedException + FullyQualifiedErrorId : NativeCommandFailed
From cmd.exe I get
The system cannot execute the specified program.
I'll see if I can get it "unblacklisted", Perhaps my anti-virus got to it first?Traditionally the open source community worked around these issues by not distributing binaries and instead asking people to build the software on their own. I like the convenience of binaries because open source software is becoming increasingly fragmented and impossible to build. So then people use interpreters instead of compilers, which are slower. In any case, I don't think the source code workaround is going to last forever. Many companies are now focusing on applying the virus scanner model to source code too.
I've submitted this as a false positive under our enterprise licensing.
Ha ha! (beetlejuice!)
There's also the possibility that redbean would be used for actual malware, being so portable and all.
▶ curl https://redbean.dev/redbean-demo-2.0.1.com >redbean.com
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 1984k 100 1984k 0 0 1121k 0 0:00:01 0:00:01 --:--:-- 1129k~/programming/apps ▶ chmod +x redbean.com
~/programming/apps ▶ ./redbean.com -v
zsh: exec format error: ./redbean.com
The file seems to be downloaded OK:
▶ file redbean.com
redbean.com: DOS/MBR boot sector
I also tried letting Firefox download the 2.0.1 binary from the downloads page, but that runs into the same issue as well.
Anyway, tried bash now, and I got another error:
▶ bash ./redbean-2.0.1.com -v --strace SYS 0 22'227 bell system five system call support 383 magnums loaded on xnu's not unix! SYS 93828 36'725 mprotect(0x700000000000, 4'096, 0) → 0 SYS 93828 345'630 mmap(0x700000000000, 262'144, PROT_READ|PROT_WRITE, MAP_STACK|MAP_ANONYMOUS, -1, 0) → 0x700000000000 (262'144 bytes total) SYS 93828 567'580 mmap(0, 65'536, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) → 0x100080000000 (327'680 bytes total) SYS 93828 607'673 close(3) → 0 SYS 93828 610'080 getcwd(0x5ee720, 1'024) → "/Users/renato/programming/apps" SYS 93828 611'532 getenv("MAKEFLAGS") → NULL SYS 93828 613'435 getenv("TERM") → "xterm-256color" SYS 93828 637'803 openat(AT_FDCWD, "/Users/renato/programming/apps/redbean-2.0.1.com", 0, 0) → 3 SYS 93828 640'621 getfiledescriptorsize(3) → 1'999'386 SYS 93828 645'979 mmap(0, 1'999'386, PROT_READ, MAP_SHARED, 3, 0) → 0x100080100000 (2'359'296 bytes total) SYS 93828 657'750 munmap(0x100080100000, 1'703'936) → 0 (655'360 bytes total) SYS 93828 660'467 __zipos_get("/Users/renato/programming/apps/redbean-2.0.1.com") SYS 93828 662'273 close(3) → 0 SYS 93828 663'503 openat(AT_FDCWD, "/zip/.args", 0, 0) → -1 ENOENT/2/No such file or directory SYS 93828 668'744 mmap(0, 262'144, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) → 0x100080040000 (917'504 bytes total) SYS 93828 671'865 sigaltstack({.ss_sp=0x100080040000, .ss_flags=0, .ss_size=262'144}, [{.ss_sp=0x100080040000, .ss_flags=0, .ss_size=262'144}]) → 0 SYS 93828 678'266 sigaction(SIGQUIT, {.sa_handler=0x52c737, .sa_flags=0x51, .sa_mask=~{}}, [{.sa_handler=0, .sa_flags=0, .sa_mask={}}]) → 0 SYS 93828 680'693 sigaction(SIGFPE, {.sa_handler=0x52c742, .sa_flags=0x51, .sa_mask=~{}}, [{.sa_handler=0, .sa_flags=0x2, .sa_mask={}}]) → 0 SYS 93828 682'732 sigaction(SIGILL, {.sa_handler=0x52c74d, .sa_flags=0x51, .sa_mask=~{}}, [{.sa_handler=0, .sa_flags=0x2, .sa_mask={}}]) → 0 SYS 93828 685'823 sigaction(SIGSEGV, {.sa_handler=0x52c758, .sa_flags=0x51, .sa_mask=~{}}, [{.sa_handler=0, .sa_flags=0x2, .sa_mask={}}]) → 0 SYS 93828 687'845 sigaction(SIGTRAP, {.sa_handler=0x52c763, .sa_flags=0x51, .sa_mask=~{}}, [{.sa_handler=0, .sa_flags=0x2, .sa_mask={}}]) → 0 SYS 93828 689'841 sigaction(SIGABRT, {.sa_handler=0x52c76e, .sa_flags=0x51, .sa_mask=~{}}, [{.sa_handler=0, .sa_flags=0x2, .sa_mask={}}]) → 0 SYS 93828 691'881 sigaction(SIGBUS, {.sa_handler=0x52c779, .sa_flags=0x51, .sa_mask=~{}}, [{.sa_handler=0, .sa_flags=0x2, .sa_mask={}}]) → 0 SYS 93828 696'779 mmap(0, 262'144, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) → 0x100080080000 (1'179'648 bytes total) SYS 93828 1'392'442 inflate([u"SYMT ↨ ♦ ♦ @ "...], 262'144, u"lⁿuÿV╒× ⁿ»↓bå£Ç↓RAѶ♣JQRÑ♦ò♫âûÉ♫üí╒♥ét"..., 103'922) → 0 SYS 93828 1'647'413 GetSymbolTableFromZip() → 0x100080080000 [1] 93828 invalid system call bash ./redbean-2.0.1.com -v --strace
Looks great!
This is wonderful, just thinking out loud. Out of interests would something like ECS (Entity Component System) be useful or yield better memory usage since it should in theory trash the cache less ?
If I may suggest, supporting more languages than lua could help bring more people: say php or python, maybe with something like vscodium?
IIRC python2 was a WIP (issue #141 for cosmopolitan)
Personally I'd prefer perl for performance, and vscodevim or similar to edit code, but I have weird tastes :)
Different flavors of redbean would be awesome!
Thank you for building redbean.
git clone https://github.com/jart/cosmopolitan
cd cosmopolitan
make -j8 o//third_party/python/python.com
Then put Django in the zip under the .python directory. You can also use the `.args` file just like redbean to have `-m module` run by default.a python3 flavor could be experimental at first, I bet it would boost overall adoption & be an unfair advantage over nginx approach.
having multiple repl in one binary would remind me of containers in a very strange but cool way, that would be more a fun experimental feature a rabbit hole for others to explore.
It would also let the flavors of redbean compete for donations, which could be directed towards your language of choice (say python3 for you) while limiting the size and complexity.
One of best technical posts I’ve read in a while.
if geo:get('location', 'accuracy_radius') >= 100 then
SetStatus(403)
Write('you can only post comments from your home internet connection')
return
end
Bad actors often use cheap cloud instances, and the IP addresses of their data centers typically have an accuracy radius of 1000 km.For anyone doing something like this with a service that's useful to people, consider MaxMind's minFraud service. It's PAYG and you can choose three different levels of information at three different price points. It's targeted at fraud minimization, but you can hand it as little as an IP address and it'll give you what you need to know.
1: ( which is likely to be maxmind's geoip DB in many cases anyway )
MaxMind's minFraud is $0.015 per request and requires a call to an external endpoint. Justified for finance and shopping apps, not great for a high volume free service.
And you don't have to deny based on this one signal alone, you could fall back to recaptcha or minFraud to reduce the false positive rate.
What fraud are you trying to prevent that gets abused in a free service? Most of the abuse I see for free services I host is DDoS, brute-forcing paths/authentication and port scanning, but all of those are trivial to deal with rate-limiting.
My wife ran a small business for awhile that catered to local customers only (i.e. not an online business, products didn't ship through the mail. She added a contact us type form which submitted to google forms as a quick alternate to phone calls for prospective clients. It was used almost exclusively by people trying to sell her things from overseas.
She wasn't even running ads or anything online, so how they ever found the website in the first place, I have no idea.
Please don't do stuff like this. Some of use use VPNs and aggressively block third party JS. These sorts of shenanigans render many sites unusable which is frustrating but simply not using those services is a price I'm more than willing to pay at this point.
Are you describing nonces? A nonce is basically a "secret" (due to SSL encryption) number inserted into the HTML and submitted via a form. You don't need JS, just SSL.
Making it require JS is on purpose as a lot of spam robots only parse HTML and don't execute JS, so you get less spam that way.
While I agree with all the people saying “this’ll block real people at significant rates”, for some things (like personal blog replies or small forums) that can be a perfectly sensible trade off for some sites.
Sure, if you are Netflix, or a government department website that people need to use, it’s a terrible idea.
For somebody who’s sick of deleting spam replies on their personal blog posts? Simple rules with known and acceptable unintended consequences might be a really good idea.
What sort of ”legitimate traffic” comes off AWS/Azure/DigitalOcean et al?
And how does the volume of that (and relevance of that traffic) compare to home add and mobile CGNAT ipaddresses?
Unless I’m selling something, dropping all cloud instance IP ranges doesn’t em like it’d block a lot of “legitimate traffic” to me, at least not enough to care about. If my choices were “spend time implementing a more sophisticated locking technique to reduce blogspam” or “write more blogposts”, I’d be triggerhappy blocking everybody using AWS o browse from and writing more content.
I use FSecure as a VPN, and I see it “do weird shit” at about the same rate as I see when I’m using a Hertzner box as a wire guard endpoint. (Most common thing there is I can’t order via menulog when I’ve got a vpn endpoint out of I am getting it delivered to, and I’ve just got used to switching off my phone’s vpn while ordering..)
In a world where a lot of developers on HN are too scared to run apt upgrade, you write this brilliant piece of tech. It's inspirational, really.
A testament to quality development work.
An example of what can be achieved and how much our community benefits from good software.
The Redbean 2.0 license is intriguing (snip):
" Copyright 2020 Justine Alexandra Roberts Tunney │ │ │ │ Permission to use, copy, modify, and/or distribute this software for │ │ any purpose with or without fee is hereby granted, provided that the │ │ above copyright notice and this permission notice appear in all copies. │ "
Seems to assert the (FSF) four freedoms well, all is good in the world, it can be used and contributed to safely by all.
Work like this proves that assumption-questioning research on its own can produce incredible results if done by the right people.
I think a lot of companies have stopped doing this kind of research, in favor of chasing more immediate profits, to their long-term detriment.
Likely everything you're doing have been done in various Trojans, viruses, etc. You'll need to hack the noosphere at this point
Of course if you get these vendors to fix their detections for your program and get google "safe" browsing and virus total (aka google again) to stop slandering your it will only take time before the whole thing starts again - even without any changes to your executables.
And beacuse these are respected™ software companies making the virus allegations your users will of course more often than not tell you to fix your executables when the bug is in their third party anti-virus software.
I'm getting more and more tempted to just not provide any Windows executables for my open source projects :/