Tuesday, August 27, 2024

How to Export Apple Health and Google Fit Activities to TCX for Strava (Free Method)

When using fitness trackers like the Xiaomi Smart Band 7, the companion Mi Fitness app may intermittently fail to sync running and cycling activities directly to Strava. While Mi Fitness natively supports data syncing with Apple Health, Suunto, and Strava, third-party sync disruptions can leave workouts trapped on your phone.

Commercial iOS apps such as HealthFit or RunGap can export workout files, but require paid subscriptions. Here is a 100% free workflow to export workout tracks in TCX format and upload them manually to Strava.

Step-by-Step Free Export Workflow

  1. Sync Mi Fitness to Apple Health: In the Mi Fitness app, navigate to Profile → Connected apps → Apple Health and enable all workout sync categories.
  2. Bridge to Google Fit: Install the free Google Fit app on iOS. Grant Google Fit read access to Apple Health workout and location data. Verify that your running sessions appear in Google Fit.
  3. Export via Google Takeout: Go to Google Takeout in your web browser. Deselect all items except Google Fit, and request a download archive.
  4. Extract TCX Activity Files: Once the archive is ready, download and extract the ZIP file. Inside the extracted archive, navigate to the Takeout/Fit/Activities/ directory. Each workout session is saved as an individual .tcx XML file containing GPS trackpoints, heart rate data, and timestamps.
  5. Upload to Strava: Open Strava Manual Upload and upload your .tcx files directly. Strava will parse the GPS coordinates, splits, and heart rate telemetry seamlessly.

Friday, March 1, 2024

How to Disable Automatic Sleep and Suspend on Debian 12 Production Servers

When running Debian 12 (Bookworm) on home servers, lab nodes, or production workstations with desktop environments installed, power-saving defaults can cause the system to automatically suspend or sleep after periods of user inactivity (no keyboard or mouse movement). This disconnects SSH sessions and halts background services.

Method 1: Configure GDM3 Greeter Power Settings (Desktop / GDM3)

For systems running the GNOME Display Manager (GDM3), edit the greeter defaults configuration:

sudo nano /etc/gdm3/greeter.dconf-defaults

Uncomment or add the following directives under [org/gnome/settings-daemon/plugins/power] to set inactive timeout actions to blank instead of suspend:

[org/gnome/settings-daemon/plugins/power]
sleep-inactive-ac-type='blank'
sleep-inactive-battery-type='blank'

Method 2: Mask Systemd Sleep Targets (Recommended for Headless / Servers)

To completely prohibit the Linux kernel and systemd from entering sleep, suspend, or hibernation at any time, mask the respective systemd targets:

sudo systemctl mask sleep.target suspend.target hibernate.target hybrid-sleep.target
Verification: Check system sleep state with systemctl status sleep.target. If masked, the target points to /dev/null, ensuring 24/7 server uptime without unexpected idle shutdowns.

Wednesday, February 21, 2024

How to Set Up a Tunneled Wi-Fi Hotspot on Raspberry Pi OS Bookworm with WireGuard and NetworkManager

This guide updates our earlier tutorial for Debian 12 Bookworm on Raspberry Pi. In this architecture, the Raspberry Pi connects to upstream internet via Ethernet (eth0), establishes an encrypted WireGuard VPN tunnel (wg0), and broadcasts a secure Wi-Fi access point on wlan0. All client traffic connected to the hotspot is policy-routed strictly through the WireGuard tunnel.

Modern Bookworm Architecture: NetworkManager replaces dhcpcd and leverages the built-in dnsmasq-base plugin for DHCP and DNS caching, eliminating the need for standalone services like isc-dhcp-server.

1. Create the Wi-Fi Hotspot Profile in NetworkManager

Create a hotspot connection in the Raspberry Pi desktop Network GUI or via nmcli. Set the hotspot subnet to 10.0.1.1/24, enable auto-connect, and set MTU to 1420.

To enforce robust WPA2-only (RSN/AES) authentication and disable legacy WPA1:

nmcli con modify "Wi-Fi Hot" 802-11-wireless-security.proto rsn

2. Configure Policy Routing Table

Create a dedicated routing table for hotspot clients (subnet 10.0.1.0/24):

echo "200 INET2" | sudo tee -a /etc/iproute2/rt_tables

3. WireGuard Configuration (/etc/wireguard/wg0.conf)

Configure WireGuard with policy rules and MSS clamping to ensure seamless MTU handling through the tunnel:

[Interface]
PrivateKey = YOUR_PRIVATE_KEY
Address = 10.10.0.6/24
PostUp = iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE; ip rule add from 10.0.1.0/24 table INET2 priority 100; ip route add default dev wg0 table INET2; ip route add 8.8.8.8/32 dev wg0; ip route add 8.8.4.4/32 dev wg0; iptables -t mangle -A FORWARD -o wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu; iptables -t mangle -A FORWARD -i wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu; ip route flush cache
PreDown = iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE; ip rule del from 10.0.1.0/24 table INET2 priority 100; ip route del default dev wg0 table INET2; ip route del 8.8.8.8/32 dev wg0; ip route del 8.8.4.4/32 dev wg0; iptables -t mangle -D FORWARD -o wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu; iptables -t mangle -D FORWARD -i wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu; ip route flush cache
Table = off
MTU = 1280

[Peer]
PublicKey = SERVER_PUBLIC_KEY
AllowedIPs = 0.0.0.0/0
Endpoint = YOUR_VPN_SERVER_IP:PORT
PersistentKeepalive = 25

4. Enable Kernel IPv4 Forwarding

Enable packet forwarding in /etc/sysctl.conf:

sudo sysctl -w net.ipv4.ip_forward=1
echo "net.ipv4.ip_forward=1" | sudo tee -a /etc/sysctl.conf

5. DNS Configuration for DHCP Clients

Configure NetworkManager's shared dnsmasq instance to supply public DNS servers to hotspot clients:

sudo mkdir -p /etc/NetworkManager/dnsmasq-shared.d/
echo "dhcp-option=option:dns-server,8.8.8.8,8.8.4.4" | sudo tee /etc/NetworkManager/dnsmasq-shared.d/dns.conf

6. Monitoring and Verification

Check active DHCP leases granted to Wi-Fi clients:

cat /var/lib/NetworkManager/dnsmasq-wlan0.leases

Verify dnsmasq runtime process parameters:

ps aux | grep dnsmasq

How to Fix Repeating Keys and Keystroke Lag on WayVNC (Debian 12 Bookworm)

When connecting remotely to a WayVNC server on Debian 12 Bookworm (or Raspberry Pi OS) over high-latency or cross-border connections, you may encounter severe repeating keys (for instance, pressing a key once produces a long string like aaaaaaaaaa).

Root Cause

In remote desktop protocols, pressing and releasing a key sends distinct key-down and key-up network packets. If packet loss or network jitter causes the key-release packet to be delayed or dropped, the compositor's auto-repeat timer assumes the key is still physically held down and floods the active application with repeats.

Solution: Disable Compositor Key-Repeat

As documented in the Wayfire Core Options, disabling key repeat entirely on the host side prevents phantom keystrokes over latent links.

Edit the Wayfire configuration file (/etc/wayfire/defaults.ini or user-level ~/.config/wayfire.ini):

sudo nano /etc/wayfire/defaults.ini

Add or set kb_repeat_rate = 0 under the [input] section:

[input]
kb_repeat_rate = 0

Save the file and restart the WayVNC service or reboot the Raspberry Pi to apply the change:

sudo systemctl restart wayvnc
# or:
sudo reboot

Once rebooted, keystrokes will register accurately without runaway repetitions, even across lossy WAN connections.

Saturday, February 10, 2024

How to Capture Screenshots over SSH on Debian 12 Wayland Desktops

On legacy Debian 11 (Bullseye) and older X11 desktops, taking a screenshot of an active desktop session remotely over SSH was straightforward using scrot:

DISPLAY=:0.0 scrot -o screenshot.jpg

In Python:

import os
os.environ["DISPLAY"] = ":0.0"
os.system("scrot -o screenshot.jpg")

Wayland on Debian 12 (Bookworm)

On Debian 12 (and Raspberry Pi OS Bookworm with Wayfire or labwc), Wayland is the default compositor. Because Wayland enforces strict security isolation between graphical clients and display sockets, scrot will fail with the error:

failed to create display

To take screenshots under Wayland, use the native grim utility (pre-installed on Raspberry Pi OS). When calling grim over SSH from a non-interactive TTY, you must explicitly export both WAYLAND_DISPLAY and XDG_RUNTIME_DIR:

WAYLAND_DISPLAY=wayland-1 XDG_RUNTIME_DIR=/run/user/1000 grim screenshot.png

Python Automation Script

To capture screenshots programmatically in Python over SSH:

import os

pngfile = "/tmp/screenshot.png"
os.environ["WAYLAND_DISPLAY"] = "wayland-1"
os.environ["XDG_RUNTIME_DIR"] = "/run/user/1000"

os.system(f"grim {pngfile}")
Tip: If you are unsure of your socket names, run echo $WAYLAND_DISPLAY and echo $XDG_RUNTIME_DIR from a terminal inside the active desktop session, or check the socket files in /run/user/$(id -u)/.

Thursday, February 8, 2024

How to Set Default Route and Network Metrics on Debian 12 (Bookworm) Using NetworkManager

On Debian 12 (Bookworm) and Raspberry Pi OS Bookworm, dhcpcd has been deprecated and replaced by NetworkManager as the default network management stack. Consequently, /etc/dhcpcd.conf is no longer present.

When multiple network interfaces (such as Ethernet eth0 and Wi-Fi wlan0) are connected simultaneously, the Linux kernel determines the default gateway based on routing metrics. Lower metric values take precedence over higher values.

Rule: Lower route metric = higher routing priority. To prioritize an interface for default internet access, assign it a lower metric than competing interfaces.

1. Inspect Current Routing Metrics

Check the existing routing table and metric values:

ip route show
# or:
route -n

2. List NetworkManager Connection Profiles

Identify the exact connection name you wish to adjust:

nmcli connection show

3. Adjust the Route Metric

You can set the route metric directly using a single nmcli command:

# Set metric to 100 for higher priority (e.g. Ethernet)
nmcli connection modify "Wired connection 1" ipv4.route-metric 100

# Reactivate the connection to apply changes
nmcli connection up "Wired connection 1"

Alternatively, you can edit the connection interactively:

nmcli connection edit "Wired connection 1"
nmcli> set ipv4.route-metric 100
nmcli> save
nmcli> quit

Run ip route show again to verify that your preferred connection now holds the lowest metric on the default route.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...