NetBSD 11 from scratch

Tags

, , , , , , , , ,

In this post I will cover the installation process of the NetBSD operating system, including disk level encryption. Instead of using the standard installation program (sysinst), I decided to install NetBSD “from scratch”, as a way to dive into the internals, and learn more about the nuts and bolts of this great operating system.

This post is by no means a replacement for the NetBSD official guide. Sysinst is the the facto installer for NetBSD and is the most documented, straightforward way to install the operating system. This post is about having fun and understanding and learning the internals of the operating system. It also offers the highest flexibility to customize and overcome issues that may arise during a conventional installation.

I will try to establish a chronological order in the process, documenting the most relevant steps with screenshots and references to sources related to the topic.

MBR installation: NetBSD is notorious for its portability and being able to work in “old” computers. I decided to do the installation in a HP Pavillion (around year 2012) that uses MBR instead of the GPT partitioning found in more modern UEFI systems. (quick digression: Many of the so called “obsolete” or “old” computers are still useful and perform very well. You just need a good operating system ;). By adopting them, you will giving refurbished computers a great second life, you will be saving a lot of money and, most importantly, you will be preserving the environment from polluting waste.).

Let’s start 🙂

The installation image

The first step to install NetBSD is to download and copy the image to the USB pen drive.

Note: <usb_device> is the assigned device of your USB drive . Use the entire disk (ej sdb) instead of a partition. Please also note that this operation will wipe out your entire flash drive. Triple check that you are actually using the right device and not another disk of your computer.

Note: I will use the # as the shell prompt to denote root operations while the $ is for regular users.

$ wget https://cdn.netbsd.org/pub/NetBSD/NetBSD-11.0/images/NetBSD-11.0-amd64-install.img.gz
$ gunzip NetBSD-11.0-amd64-install.img.gz
$ sudo dd if=NetBSD-11.0-amd64-install.img of=/dev/<usb_device> bs=2m

Once it finishes, you can plug it in on your USB socket and boot the computer. Make sure you select the device as the first bootable device in your BIOS.

Preparing the Installation

Exit “sysinst”

When you boot from the usb flash drive, you will get at some point the sysinst installation program. Press CTRL+C to exit from sysinst and get a prompt.

You will see the following message followed by the root prompt.

Sysinst terminated.
To return to the installer, quit this shell by typing 'exit' of ^D
#

Setup the keyboard layout

If you have a non English keyboard, you might want to set the keyboard layout with the following command. For instance, to enable the Spanish keyboard layout, type the following command:

# wsconsctl -w encoding=es
encoding -> es

Note: The NetBSD console only admit ASCII characters, so letters like “Ñ” won’t be shown, but the layout will be correct.

Setup networking

To make the installation process more comfortable, I decided to enable networking and the SSH server in the target computer, so I can also take screenshots and document it better.

I will be using a LAN, so connect your ethernet cable to the router and enable DHCP. The following command will retrieve the IP and default gateway from your router DHCP server.

# /sbin/dhcpcd -d -n re0

“re0” is the network interface driver. NetBSD uses the driver name instead of the GNU/Linux “eth” nomenclature. In my case, “re0” stands for Realtek ethernet driver.

You can check the name of the interface and its status using the ifconfig command

Output from the ifconfig command, showing the interfaces (re0 and lo0) details.

Enable SSH server

Add a local user. It’s a good practice to create a local user for non-privileged operations, as well as to remotely login without using “root”. We will create the user “malatesta” and make him a member of the “wheel” group, so he can do a “su -” operation and assign a password.

Note: This user only lives in the installation usb drive.

# useradd -m malatesta
# usermod -G wheel malatesta
# passwd malatesta

Next we need to start the SSH server, so the live system will allow remote connections and we can resume the installation from another computer.

# service sshd onestart

Setting up disks and partitions

Now we are ready to start configuring important, non-volatile resources, starting with the target disk that will hold the operating system.

About Disks, partitions and BSD disklabels

Before we move on, I think is pertinent to talk a bit about how NetBSD deals with disks and partitions.

Disks

In NetBSD, and similar to the network interfaces, physical disks are represented by the driver interface, followed by an integer. The logical and raw devices are under the “/dev” directory. The following are some of the drivers:

wd: IDE drives (atabus). Regular hard drives
sd: SCSI drives (scsibus). This includes USB pendrives.
cd: CDROM drives

To list the current disks in your computer, use systcl hw.disknames command:

# sysctl hw.disknames
hw.disknames = wd0 cd0 sd0 dk0 dk1

Partitions

Diagram showing the NetBSD disk partitioning schema, both the MBR and disklabels. Source: NetBSD guide (https://netbsd.org/docs/guide/en/)
Diagram showing the NetBSD disk partitioning schema, both the MBR and disklabels. Source: NetBSD guide (https://netbsd.org/docs/guide/en/)

As previously mentioned, we will use a non UEFI, BIOS computer, so we’ll be installing NetBSD using the MBR (Master Boot Record) partitioning schema.

  • Master Boot Record (MBR). Traditional BIOS had a way of identifying the different partitions on a disk by writing their attributes in the first sector of the physical disk. The MBR partitioning schema limits the number of physical partitions (also called slices” in NetBSD jargon) to 4, and deals with disks of 2 terabytes (TB) or less. It is managed with the fdisk program.
  • Disklabel: The disklabel is a NetBSD feature that allows the creation of multiple partitions within an MBR slice. The disklabel information is stored in the MBR, and is managed with the disklabel program.

Partitioning the hard drive to install NetBSD

We already know what will be our target hard drive (wd0 in this particular instance). In order to install and make it bootable, we need to partition it. We will use the entire hard drive for NetBSD, although you could install more than one operating system in the same physical device.

Showing the current partitions

To list the details of the partition table, run the command fdisk along the disk drive (e.g. fdisk wd0)

The previous fdisk command also provided key information about the size of the hard drive. From the disklabel geometry, we get total sectors: 1953525168, bytes/sector: 512 which produces 1000204886016 bytes , approximately 931 GB

# fdisk -u wd0
Disk: /dev/rwd0
NetBSD disklabel disk geometry:
cylinders: 1938021, heads: 16, sectors/track: 63 (1008 sectors/cylinder)
total sectors: 1953525168, bytes/sector: 512

BIOS disk geometry:
cylinders: 1023, heads: 255, sectors/track: 63 (16065 sectors/cylinder)
total sectors: 1953525168

Partitions aligned to 16065 sector boundaries, offset 63

Do you want to change our idea of what BIOS thinks? [n]
fdisk command running interactively on disk wd0

Initialize the partition table

If the disk we are using has a previous partition table and/or disklabel, it is a good idea to initialize it, so we don’t get spurious data.

We run again fdisk on the target drive in interactive mode (fdisk -u wd0). This time, we select the partition to initialize and enter the sysid 0 that will set it to UNUSED

Removing the current disklabel information

We have removed the partition 0, but the disklabel is still present. We will remove it with the following command:

# disklabel -D wd0

Partition layout

We will be using a single MBR slice that will hold the root filesystem and a large CGD partition to host the encrypted filesystems and swap.

MBR (use fdisk command)
0 .- 950 GB (sysid 169 – NetBSD). Bootable (“active”)
1-4: <UNUSED>

Disklabel partitions (use disklabel command)
a: 50 GB (4.2BSD to mount the unencrypted root filesystem)
b: swap (we’ll use swap in the CGD volume)
c: entire disk
e: 900 GB (CGD volume to hold encrypted /home, /usr, /var and swap partitions)

Disklabels have also conventions. The letter “a” holds the root filesystem. “b” is traditionally for swap, “c” is the entire disk (is managed by the kernel and can not be modified) and “e” is the MBR

Creating the MBR NetBSD partition with fdisk

We run fdisk command interactively to set the type (sysid) of the partition to NetBSD, assign a size of 950 GB and set it to bootable (‘active’).

# fdisk -u wd0

Set the ‘active’ (bootable) partition

We set the NetBSD partition (0) to be active (bootable)

Bootstrapping

To make the system bootable, we need to install the bootstraps with installboot.


# installboot -v /dev/wd0a /usr/mdec/bootxx_ffsv1 /boot
File system: /dev/rwd0a
File system type: ffs (blocksize 16384, needswap 0)
Primary bootstrap: /usr/mdec/bootxx_ffsv1
Secondary bootstrap: /boot
Boot options: timeout 5, flags 0, speed 9600, ioaddr 0, console pc

Assigning the main disklabel partitions

We will create the disklabels in two steps. The first step will create the disklabel for the root partition (which will hold the root (‘/’) filesystem and the partition reserved to the CGD volume.

Once these two partitions are created, we will run again the disklabel command, this time using the cgd0 pseudo device.

We use disklabel interactively to create 2 partitions (a and e). Remember that c and d are reserved. ‘c’ partition represents the NetBSD partition on the MBR and ‘d’ the whole disk.

Partition ‘a’ (wd0a) will hold the root filesystem and partition ‘e’ (wd0e) the CGD volume.

# disklabel -iI wd0
# disklabel -iI wd0
Enter '?' for help
partition>a
Filesystem type [unused]: 4.2BSD
Start offset ('x' to start after partition 'x') [0c, 0s, 0M]: 2048s
Partition size ('$' for all remaining) [0c, 0s, 0M]: 51200M
a: 104857600 2048 4.2BSD 0 0 0 # (Cyl. 2*- 104027*)
partition>e
Filesystem type [4.2BSD]: cgd
Start offset ('x' to start after partition 'x') [2.0317461490631103515625c, 2048s, 1M]: a
Partition size ('$' for all remaining) [1938018.875c, 1953523120s, 953868.6875M]: $
e: 1848665520 104859648 cgd # (Cyl. 104027*- 1938020)
partition>W
Label disk [n]?y
Label written
partition>Q

A section of the output from the command disklabel wd0 shows the partitions on the NetBSD MBR slice. I have

Create the CGD (Cryptographic Disk Driver) volume

Now that we have the CGD partition created on wd0e , we need to initialize the CGD volume, that itself will hold the operating system filesystems encrypted (except root).

Generate the parameters file for the CGD volume, using the adiantum cipher and disklabe as the verification method.

# cgdconfig -g -V disklabel -o /etc/cgd/wd0e adiantum
pkcs5_pbkdf2: calibrating iterations................. done

The following /etc/cgd/wd0e is generated:

As mentioned in the NetBSD guide related chapter, this file is critical, so make sure you back it up.

At this point, we are ready to create the actual CGD volume. The following command will ask us to enter the password that will later unlock the encrypted device.

The CGD partitions

The newly created CGD volume cgd0 behaves the same as another disk. We can now move on to creating the CGD partitions.

# disklabel -iI cgd0

We repeat the steps to create the partitions in CGD similarly as we did in the MBR slice. After we create and write the contents to disklabel, we end up with this list:

Creating the filesystems

We now proceed to create the filesystems in their respective partitions. We will be using the FFS filesystem with the command newfs for each target partition.

For instance, the following command will create the root (“/”) filesystem in the first partition (“a”) of the unencrypted device wd0

If everything went well, you should see something like this:

To create the filesystems residing in the cdg0 drive we would do the same, looking at the disklabel partition table above. For example, to create the large /home filesystem at partition “a” of the encrypted volume, execute the following command:

Partition “e” of cgd0 will hold the “/var” filesystem.

Repeat the commands for the remaining partitions.

Note: The swap partition (cgd0b) is a special type. Do not create a filesystem there.

Preparing target mount points

Now that the partitions and filesystems have been created in the target drives, we need to populate them with the base system, packages and devices.

Mount the target root filesystem under “/mnt/target”

Mount the remaining target filesystems in temporary directory

Double check that your mount points and allocated space

Installing the binary sets

So far everything has gone smoothly. Now is time to extract the software sets that you wish.

The NetBSD installation guide says that we need to include at least “base“, “etc” and a kernel as a bare minimum. Once we boot the system, we can later install additional package sets.

Make sure you are in the newly created root filesystem:

Installing the kernel:

Installing ‘base’ and ‘etc’ binary sets:

Do the same for other packages you may want (“games”, “text”, “xserver”…)

Copying and adapting important files (cgd, fstab… )

Create the main CGD configuration file. This is important because CGD must be enabled before the filesystems are mounted.

Copy the current CGD parameter / cipher file:

Enable CGD at boot time:

Create the target fstab file with the new filesystem entries

Making the devices in the target drive

As the MAKEDEV script says, “all” makes all known devices, including local devices

Mounting and preparing kernel/proc/tmpfs

Chroot to the new drive

Getting closer… now we need to chroot to the new environment, so we can update the root password, update the fstab file.

Create the fstab file with the folllowing entries

Double check that the devices / partitions match your installation!

Add the new root password

Include additional / optional entries to /etc/rc.conf

You can include or customize additional services in your rc.conf. For example, the hostname, mail server or DHCP client. Some common entries are:

hostname=tolstoy.gnuhealth.org (change it to your hostname)
critical_filesystems_local="/var /usr"
wscons=YES # The NetBSD console subsystem
dhcpcd=YES # Activate DHCP
postfix=NO #Disable mail server

Rebooting the system to the newly installed NetBSD

If everything went well, then you should be happily booting into your new hard drive. Remember that since we have

From this point, you can explore different services, configure the package system (pkgin), set up the graphical interface and install cool games. The Sysinst program allows you to do post-installation tasks. This is just starting!

fastfetch program running in NetBSD .
OS: NetBSD 11.0 amd64
Host: HP Pavilion dv6 Notebook PC (048E100000242B10000020000)
Kernel: NetBSD 11.0
Uptime: 1 hour, 2 mins
Packages: 7 (pkgsrc)
Shell: sh
Display (LVDS-1): 1366x768, 60 Hz [Built-in]
Terminal: /dev/pts/1
CPU: Intel(R) Core(TM) i7 Q 720 (8) @ 1.47 GHz
Memory: 164.63 MiB / 3.79 GiB (4%)
Swap: 0 B / 9.77 GiB (0%)
Disk (/): 171.06 MiB / 49.22 GiB (0%) - ffs
Disk (/home): 28.00 KiB / 775.12 GiB (0%) - ffs
Disk (/usr): 1.02 GiB / 28.84 GiB (4%) - ffs
Disk (/var): 62.75 MiB / 48.07 GiB (0%) - ffs
Local IP (re0): 192.168.1.153/24
Battery: 100% [AC Connected]
Locale: C
Post-install information of the NetBSD system

An operating system made by humans, for humans

Last but not least… I wrote about generative AI / LLM becoming the new pandemic and why we need to find ethical Free/Libre Software alternatives for our computing and for our society. NetBSD is one of the projects that took a stance against the use of genAI and that by itself deserves our support, respect and adoption.

Resources

Writing this post has been a lot of fun and a fantastic learning experience to dive into the NetBSD internals. The following resources have been very helpful and inspiring. They are mainly focused in UEFI, but a lot of information is also valid for MBR systems, and you will probably have a UEFI system anyways 🙂

PS: I am sure there are errors and better ways to implement any of the processes in this post. Please ping me and I’ll update it! You can find me in Mastodon (https://todon.eu/@meanmicio).

Happy hacking!

PS: Thank you to all the positive messages and suggestions coming from the Fediverse! I’m updating the post accordingly 😊

Generative AI – The new pandemic

Tags

, , , , , , , , , , , , , , , ,

“Generative Artificial Intelligence” is the new pandemic, and it has already infected the Free Software community. The term is actually a misnomer, because it is not intelligent (please see https://gnu.org/philosophy/words-to-avoid.html#ArtificialIntelligence)

The Linux kernel and other projects in the Free Software community have opened the gates to Big tech slopware, and it is ugly. Many people don’t really know how pernicious and damaging this new technology is for the environment and for our society.

Last month I had the privilege to talk at the faculty of social sciences of the University of Buenos Aires and the University of Entre Ríos in Argentina. In both conferences I had the opportunity to talk about how new technologies, lead by big corporations pose a huge risk to Mother Nature, to the underprivileged and marginalized communities and to society. On the positive side, presented alternatives to protect the digital sovereignty, sustainability and dignity of the people against this greedy, short sighted corporations that have created a global public health issue.

Fortunately, not everyone is falling into this “GenAI” trap. A large part of the Free Software community is not happy with LLMs and many have taken a public stance against it. Very important communities from software development platform like Codeberg, the Zig programming language, the NetBSD operating system, emulators like QEMU and GNU/Linux distributions such as Gentoo, Alpine or Parabola have rejected to be complicit of this nasty “AI bubble”.

There are some resources that actively update the projects that opposed LLM / generative AI, to name a few:

Search engines like DuckDuckGo already have a “noAI” page (see https://noai.duckduckgo.com). When you enter this site, all AI-assisted answers, AI-generated images and AI feature suggestions are turned off.

The noAI page from DuckDuckGo search engine

Of course, the project I lead, The GNU Health and Hospital information System (GNU Health) has included the strict no AI policy in both the Code of Conduct and in the contributing chapters. We want to make sure every single line of code is made by humans that understand what they are doing.

GNU Health Strict No Generative Artificial Intelligence Policy

GNU Health is social project made by humans and for humans. We DO NOT accept any code, artwork, review, documentation or issues created by generative Artifical Intelligence (GenAI) / Large Language Models (LLMs).

The GNU Health no-AI policy is because we strongly believe that:

  • GenAI is bad for Mother Nature
  • GenAI is bad for human rights, especially for underserved and marginalized communities.
  • GenAI is bad for the Free Software and Free Culture communities.
  • GenAI is bad for you

Last but not least, GNU Health manages critical health information both at personal and population level. There must be a reasoning behind every single line of code. We make all the effort to minimize bugs that can jeopardize the integrity and security of the system, and we can not risk the project by putting it in hands of stochastic parrots.

Let’s keep the art and science of computing a human virtue.

Large corporations are creating a new crisis in the Free Software community and in our society. It is also a global public health issue. This evil technology is generating a global ecocide, but also puts at risk your freedom, human rights and the development of our societies. But there is hope, and you just need to join us in the fight against this LLM atrocity. We are many, and we have the tools for ethical use of computing resources. Look an adopt the projects in the areas that you use, and if you can, please support them.

I finish the post with the closing sentence in the GNU Health no GenAI policy…

Let’s keep the art and science of computing a human virtue.

Happy Hacking.

El Software Libre se humilla ante Google

Tags

, , , ,

La historia se repite y la comunidad sigue tropezando en la misma piedra. Google no es distinto de Microsoft, Amazon u otras “Big Tech” en cuanto a uso y abuso al software libre. Gigantes tecnológicos con cantos de sirena que se introducen en la comunidad, se aprovechan de sus recursos y finalmente la deja tirada en el momento de mayor necesidad.

En los últimos años Google ha perdido interés por la comunidad. Como ejemplo está el distanciamiento en su Android Open Source Project (AOSP), usado proyectos independientes de Android sin servicios de Google (“de-Googled” Android) orientados a la privacidad como GrapheneOS. En este caso, el año pasado Google decidió, de manera unilateral, dejar de publicar los repositorios de código para componentes de hardware de Pixel, dispositivos usados por GrapheneOS, lo que dificulta enormemente su desarrollo.

La última jugada de Google tiene que ver con obligar a desarrolladores independientes a registrarse en su sistema. Google tendrá control en el proceso de selección del desarrollador, y de la aplicación (“app”) en sí. Esta decisión unilateral por parte de Google es un ataque directo a la privacidad e independencia para desarrollar y descargar aplicaciones para Android. Supone también un misil a la línea de flotación a portales de aplicaciones libres para Android como “F-Droid”.

Parte de la comunidad de Software Libre emitió una carta abierta advirtiendo de los peligros que el registro obligatorio de desarrolladores de Android suponía. Algunas de las implicaciones que enumeran en la página “Keep Android Open” (https://keepandroidopen.org/es/)

  • Pagar tarifas a Google.
  • Aceptar los términos y condiciones de Google.
  • Subir un documento de identidad gubernamental oficial.
  • Subir evidencia de la clave de firma privada del desarrollador.
  • Listar todos los identificadores de aplicaciones actuales y futuros.

Si bien los argumentos de la página Keep Android Open son correctos en cuanto al abuso de poder y arbitrariedad de los gigantes tecnológicos, estoy en desacuerdo con la petición en sí, por el tono y por intentar alargar una relación tóxica. También me parece lamentable que usen GitHub para editar la página.

La postura sumisa, literalmente implorando a Google desista su decisión, me genera sentimientos de tristeza y de vergüenza ajena. Si hay algo que debe prevalecer en la comunidad de Software Libre es la dignidad, una dignidad pisoteada por las grandes corporaciones y por algunos estómagos agradecidos dentro de la misma comunidad, que viven de las limosnas que le arrojan, que usan GitHub para alojar su código y que alardean del término “open source”.

Cabe destacar el grado de hipocresía con el que se mueven estos gigantes tecnológicos. Leía en su sección de sponsor de FOSDEM 2026: “Google believes that open source is good for everyone. By being open and freely available, it enables and encourages collaboration and the development of technology.”. Lo grave es que hay muchos, incluso dentro de la comunidad de software libre, que lo creen.

Nos preguntaremos ¿Y ahora, qué? Es el momento de la pedagogía y de decisiones radicales.

Desde la pedagogía, es fundamental hacer entender que pactar con estas corporaciones no nos lleva a nada bueno. Al usuario final hay que comentarle que es importante para su libertad y dignidad como individuo el no depender de estas corporaciones. Algunos argumentarán que necesitan la “app” del banco. Nosotros debemos decirle que si el banco le obliga usar una “app” de código cerrado o limitada a un sistema operativo determinado, entonces debe cambiar de banco . Así como para cualquier otro servicio.

A la comunidad y proyectos de Software Libre, debemos entender que los patrocinios de estos gigantes tecnológicos significan pan para hoy y hambre para mañana, además de una pérdida de reputación e independencia. Las corporaciones no dan nada gratis y siempre hay “strings attached“.

En lo que respecta a la tecnología, desarrollar para Android al día de hoy no tiene sentido práctico ni ético. Como desarrolladores de software, debemos romper los lazos con estas corporaciones que tanto daño hacen a la comunidad. Incluso desde una postura pragmática, no desarrollaría nada en una plataforma que no es de fiar. Supongamos el hipotético caso que Google en esta ocasión decidiera aplazar o incluso cancelar su decisión del registro obligatorio de desarrolladores. Esto no significa que en un futuro tomen otra decisión que perjudique a la comunidad. A las pruebas me remito.

Hoy hay proyectos y compañías interesantes como Pine64, FuriOS, VollaPhone o Jolla (estos dos últimos en Europa) que trabajan en dispositivos móviles y sistemas operativos libres. Es importante potenciar la adopción en la comunidad de este tipo de proyectos para generar un ecosistema sostenible.

Hemos comenzado una ronda de conversaciones con compañías para que los componentes de GNU Health, tanto el cliente del sistema de gestión hospitalaria como MyGNUHealth, el gestor de salud personal, puedan ser ejecutados en plataformas móviles libres, sostenibles y que respeten nuestra privacidad como ciudadanos y profesionales de salud.

Soy consciente que estos gigantes tecnológicos tienen influencia en empresas de hardware, sistemas operativos y gobiernos, y que es difícil romper dinámicas y presiones impuestas, pero la hora de recuperar la dignidad y la soberanía tecnológica ha llegado.

Happy hacking

Gracias, India

Tags

, , ,

India es especial. Es de esos pocos lugares donde vas a dar una conferencia y sales con una lección de vida. Regreso de India lleno de alegría e ilusión. Regreso con energías renovadas y con experiencias imborrables.

Este es mi tercer viaje a India, siempre en el contexto de la Medicina Social. El primero fue a Kerala en 2017 por Swatantra 17. El segundo a Delhi cuando All India Institute of Medical Sciences (AIIMS) adopta GNU Health en 2018. Este último (agosto 2025) por el World Cultural Festival.

En esta ocasión, el viaje ha sido a Muddenahalli, en el estado de Karnataka. La organización One World One Family – OWOF -, en el contexto del World Cultural Festival, me ha otorgado el premio One World One Family en la categoría de Salud.

Haber sido elegido como el representante de España y particularmente en el área de salud me llena de orgullo. Que este reconocimiento haya sido por mi labor en ciencia abierta y por un sistema de salud universal, de calidad y gratuito hace justicia a los más de veinte años de lucha y de nadar contracorriente por un mundo más justo.

La misión One World One Family trabaja en brindar nutrición, educación y salud a los desfavorecidos en India y en 100 países alrededor del mundo.

Durante mi estadía me alojé en el Ashram de Sathya Sai Grama. Comenzaba el día a las 04:30 de la mañana con meditación y yoga. Pude compartir el World Cultural Festival y escuchar las sesiones de Sadguru Sri Madhusudan Sai, a quien estoy profundamente agradecido por invitarme, por compartir su sabiduría y por brindar nutrición, educación, salud y dignidad a los más necesitados. En noviembre de este año 2025 se inaugurará en el lugar donde me he alojado -Sathya Sai Grama- un hospital de 600 camas, el mayor centro de salud gratuito del mundo, que proporcionará atención sanitaria a personas de India y de alrededor del mundo.

Luis Falcón durante su discurso en el World Cultural Festival en Sathya Sai Grama, Muddenahalli, India
Sri Madhusudan Sai haciendo entrega del premio One World One Family a Luis Falcón, junto a B.N. Narasimha Murthy. Agosto 2025

El segundo viaje fue a Delhi, invitado por las autoridades del All India Institute of Medical Sciences (AIIMS) en 2018. Tuve el honor de capacitar al equipo liderado por el Dr. Shariff en los conceptos básicos de GNU Health, el sistema de gestión hospitalaria y de salud de Software Libre. Posteriormente, fueron ellos quienes continuaron de manera autónoma con la implementación del sistema, localizándolo y adaptándolo a las necesidades del hospital público más grande de Asia.

El primer viaje a India fue a Kerala en 2017, donde pasé unos días por Swatantra ’17, la 6ª Conferencia Internacional de Software y Conocimiento Libre.

Playa en Kerala
Kerala, 2017

India es un país que me ha recibido con los brazos abiertos, donde la hospitalidad y cariño de su gente me hace sentir en casa. Es un placer y un honor compartir tiempo y espacio con una comunidad que lucha por los mismos principios de equidad y universalidad en salud, ya sea en Kerala, Delhi o en Muddenahalli.

Gracias de nuevo y hasta pronto, India.

Parallel and distributed computing in GNU Health

Tags

, , , , , , , , , , , , ,

When it comes to large volume of data management, health in general and health informatics in particular are in the top of the list. In this post I’d like to bring the attention on how we can create scalable models in GNU Health using parallel and distributed computing methods.

In the old days – and even today – large areas of the hospitals are dedicated exclusively to store patient medical records. Thousands of charts that make millions of pages.

A medical record officer pulls out a patient chart (source: https://catalog.archives.gov/id/6374585)

The advent of Hospital information systems (HIS) and Electronic Medical Records (EMR) are transforming those paper based records into bits and bytes. The GNU Health Hospital and Health Information System is one example.

GNU Health has many areas that involves loading, processing, searching and transforming large sets of data. Here are some examples that we use in GNU Health daily:

  • Demographics: Individual identification means, gender, addresses, occupations, domiciliary units, insurances, health professionals, institutions
  • Medical records: Patient evaluations, hospitalizations, laboratory and medical imaging orders, prescriptions, medication
  • Coding standards: Datasets that involve coding standards for interventions, procedures (ICPM, ICHI, ICPM..), pathology, health conditions (ICD10, ICD11..)
  • Genomics: Very large datasets involving DNA sequencing, natural variants, genes, …
  • Epidemiology: Statistics are key in early warning systems, outbreak detention and health promotion, disease prevention programs. Those reports can involve massive amount of data to be processed.

I would like to stress the importance of a good parallel or distributed computing model for maximum scalability and performance. One of the main problems is that we have the tendency to emulate in computing our linear lives. The society in which we live in make our daily activities are a set of sequential chronological (dull) tasks (wake up -> bathroom -> breakfast -> work -> […] -> dinner -> sleep) put into a loop.

Designing and Building Parallel Programs by Ian Foster. A great book I bought in 1995 for my Parallel and Distributed system class in computer science. The concepts are still very well alive and it’s part of my bookshelf.

Think parallel. Instead of that, I’d like to think in terms of how our body systems work internally. From the macroscopic organs to the minute hormones and neurons, working simultaneously in beautiful synchrony to maintain homeostasis, the internal equilibrium that keep us alive and well. It would be impossible to make a linear, sequential loop to process the events happening in a single second of our lives. Parallel processing makes the miracle. All the “workers”, “processes” and their signaling (“IPC” interprocess communication in computer science terms) make it happen.

A real life example: If we don’t do a good design, the project will not scale. Maybe, at the beginning, with a few records, our system will perform ok. With time, our database will become larger and if initially we had one hundred patients, and all of the sudden, we have reached 1 million. Each person and patient in that million population set has their own medical record, demographic history, lab tests.. you get the idea… doing analytic reporting, exporting or importing data will not scale if we don’t have a good design.

The following is a real life example that involved the migration to the latest version of GNU Health HIS of our community server. checking and syncing the values stored on the datasets residing on the filesystem (for instance, updating to the latest version of the UniProt human genes natural variants) with those in the database. In total, we had near 150,000 records to sync. GNU Health HIS uses Tryton, a great Free/Libre framework on top of Python and PostgreSQL. What it might seem a trivial task, it’s not. When we increase the verbosity, syncing each record involve a lot of tasks such as login in, checking user permissions on the model, status of the record, verify that it was not changed after the last update, etc.. If we had 100 records, we may afford linear processing. With a set of 150K, we must look for a parallel computing solution.

I have experienced similar situations when we have to migrate the medical records from another system to GNU Health. The initial batch input upload might contain thousands / millions of records. Making a good parallel model design will transform days into hours, hours into minutes and minutes into seconds.

Processing time of syncing a set of 500 records comparing and updating the values from the filesystem and the current database record. We compared the time using a sequential loop (first bar), the 8 processes corresponding to the (second bar) and finally 16 processes. The best result was achieved using eight processes (90 seconds). Sequential loop had the worst performance (318 seconds), followed by 16-parallel processes (97 seconds). I used the Proteus library for Tryton 7.0 and the Python 3.13 Multiprocessing package. The test was done on my small laptop running Void Linux, PostgreSQL 16, linux kernel 6.12. Hardware: 12GB of RAM and Intel i7 Thinkpad (8-core)

The GNU Health Federation: Distributed computing for large health networks.

The GNU Health Federation is another example of how to create scalable systems in health. In this case, instead of using multiple processes within a single computer, we are setting multiple “workers” that we call nodes across a province, country or region. A node can be an individual using MyGNUHealth personal health record, a laboratory or a hospital. Each of them work independently and they can communicate via the network. Data aggregation and reporting will happen at the GNUHealth Health Information System server, a special, document-oriented PostreSQL database.

Diagram of Thalamus, the GNU Health Federation message server and the different nodes that make a distributed health network

Summary: Make a big problem small. Think parallel.

In the end, whether you use multiple processes in the same computer or make different nodes in the health network, the concept is pretty much the same. Make a big problem small. The PCAM design methodology is a great start. PCAM stands for Partition, Communicate, Agglomerate and Map. Decompose the initial problem in smaller domains (data) and functional (computational) units, design the way they talk to each other, combine (agglomerate) the tasks and finally map those tasks to processors.

It is also important to know your resources so you can dimension and design the solution to the problem. For instance, in the sync data example, we can see that spawning too many processes will yield in a degraded system. We have saturated our resources and the system spends more time waiting for I/O or trying to make the processes communicate to each other. You may then use use processes, threads or even distributed computing, which are different implementation methods to fit the context and your resources.

Conclusion: As a final thought, I’d like to make emphasis not in the computing power, but in the power of open science and solidarity as a community. Computers can definitely help us achieve our goals, but the most efficient parallel / distributed model resides in the human factor. Today we are living in unjust a world ruled by a very few yet very powerful people and corporations. Concentration of power and computational resources will only benefit a few, creating more inequality and social gradient. Humanity is reaching a new low and we can not normalize the killing of thousands of innocent children that is happening in front of our very eyes. We can not permit our governments prioritizing the macabre business of war instead of the human rights flag. The scientific community must rise up and organize for peace, social justice and equity in our society.

Open science, cooperation, solidarity and empathy are they key to success to any problem, no matter how big they may be.

Happy hacking

El cambio de horario es un atentado contra la salud. Rechazarlo es la mejor medicina

Tags

, , , , ,

El ser humano no sólo es el único animal que tropieza dos veces en la misma piedra, sino el mismo tonto que cambia la hora dos veces al año. Llega el último domingo de marzo y con él la imposición de los gobiernos a sus ciudadanos a cambiar la hora en sus vidas.

Más allá del latazo que nos supone a los que todavía tenemos relojes analógicos en nuestras paredes, el cambio horario esconde un problema mucho más serio y que atenta directamente a nuestra salud.

La realidad es que el horario de verano (DST – Daylight Saving Time) se generó en Alemania en 1916 durante la primera guerra mundial, con el fin de ahorrar combustible de los generadores de gasoil si “anochecía” más tarde. Objetivos puramente económicos que nada tienen que ver con la salud pública.

Ilustración de Janet Loehrke

El ritmo circadiano o nuestro reloj biológico involucra complejos procesos fisiológicos con la modulación de muchas hormonas a distintas horas del día y noche. El cortisol, hormona de crecimiento, melatonina, insulina o ghrelina están relacionadas con estos relojes endógenos y a los patrones de sueño-vigilia. Nuestro sistema inmunitario, el metabolismo de la glucosa o el tránsito intestinal dependen del ritmo circadiano para un buen funcionamiento.

El alterar artificialmente el ritmo circadiano tiene efectos negativos en nuestra salud que han sido ampliamente estudiados y soportados por evidencia científica que no deben ser tomados a la ligera. Los efectos de la imposición del cambio horario no implica “estar un poco adormilado” o de mal humor los primeros días, sino que están detrás de un aumento del 25% en infartos de miocardio el siguiente lunes.

Aprendamos de quienes viven sin reloj. Los que tenemos la suerte de vivir en área rural nos despertamos con el cantar de los pajaritos. Ellos no tienen reloj, pero nos despiertan al alba, minutos antes de la salida del sol. Son sabios. Lo mismo para acostarnos, minimicemos el uso de la luz artificial y cuando el sol se pone, es un buen momento para ir terminando el día.

Reloj de sol en St. Rémy de Provenza, con un grabado que dice: «IL Est TOUJOURS L’HEURE de ne Rien FAIRE» (“Siempre es la hora de no hacer nada”). Fuente Wikimedia.

En mi caso, he decidido dejar los relojes de pared sin el impuesto cambio horario. La computadora le dejo el Tiempo Universal Coordinado (UTC). Siempre puedes referir la hora en formato UTC a tus conocidos o citas.

Como casi siempre, contra el cortoplacismo pernicioso impuesto por intereses económicos, desobedecer es el mejor remedio para preservar tu salud.

Tu finca, su infierno

Tags

, , , , ,

Después de diez días encuentro un rato para escribir sobre el sufrimiento de miles de perritos “guardianes” en las fincas rurales de Canarias. Constato que el infierno no está en las profundidades, sino en la superficie, tras las bucólicas imágenes de las medianías de Gran Canaria.

Encontramos a Tolstói y Malatesta encadenados en condiciones deplorables dentro de un terreno agrícola. Sus miradas hablan. Malatesta es el perrito más joven y no creo que pase de los tres años. Al vernos, tiembla mientras levanta una patita. Quizás para ganar nuestro cariño, quizás como un ruego desesperado para no ser lastimado.

Tolstói -el perrito mayor- está roto. Roto física y emocionalmente. Sus ojitos, apagados. Su cara es el reflejo de absoluta desolación, resultado de una vida de esclavitud y maltrato. Está roto y se está dejando morir, porque poco sentido encuentra en seguir viviendo este infierno. Su maxilar inferior está deformado por una fractura mal soldada. En un borde de su mandíbula presenta una lesión neoplásica. Su abdomen distendido acumula líquido por una insuficiencia cardiaca y su rabito está amputado. Vivir 10 años en soledad, amarrado a un árbol, tirando de una cadena de más de 15 kilos que limita su movimiento a un radio inferior a dos metros, entre el lodo y sus propios excrementos deja huellas imborrables.


Son años que venimos denunciando la condiciones en que miles de animalitos malviven en las fincas rurales de Canarias. Muchos son de cazadores. Muchos otros son “cuidadores” de fincas.

En GNU Solidario tenemos el programa #RompiendoCadenas con el fin de liberar a todo animal víctima de la opresión del ser humano. Y eso hemos hecho: Hemos rescatado a Tolstói y a Malatesta de ese infierno y ahora esperan adopción responsable que les permita vivir en familia con sobredosis de amor.

Malatesta está feliz. Corretea y salta en su casa de acogida, esperando adopción responsable. Es un amor de perrete, súper sociable y cariñoso.

Tolstói ya es otra persona. Sus ojitos han recuperado el brillo y me recibe moviendo lo que le queda de su rabo. Probablemente el paseo que dimos hacia su liberación haya sido el primero en muchos años. Pasó por su primera visita veterinaria, le dimos un baño y ahora disfruta cada minuto de vida en acogida. Tanto ha cambiado, que ahora ni me deja escribir este artículo y sólo quiere mimos… en fin.. el artículo puede esperar 🙂

Tolstói no derrocha salud, pero es libre y feliz. Nos encargaremos que siga así el resto de su vida. Al final del día, no es tanto cuánto sino cómo vivimos.

Gandhi decía que la grandeza y progreso moral de una nación puede ser juzgado por la manera que tratan a sus animales. Basándonos en esto, la sociedad española y canaria tiene mucho por evolucionar. Monarcas y políticos fomentan la caza y la monstruosidad de la tauromaquia. El abuso, la humillación y agonía de seres inocentes es retransmitido en directo por la televisión pública. Alcaldes, en nombre de la tradición, pisotean la dignidad de seres sintientes para divertir y ganarse los votos de un pueblo embrutecido. Millones de animalitos de granja son esclavizados y enviados al matadero, con el nefasto impacto al medioambiente y salud pública que esto significa. La correlación entre maltrato animal y violencia machista está ampliamente documentada en la literatura científica. Mucho pedir para un Estado y clase política negacionista anclada en el medievo.

Alguien podría pensar después de leer el párrafo anterior que el sufrimiento de los toritos o animales de granja no se compara con la vida de un animal que “cuida” una finca. No caigamos en esa falacia. Las matemáticas nos dicen que infinito menos infinito sigue siendo infinito. El sufrimiento y la soledad de los animalitos de finca es infinito e intolerable. Invito a cualquiera a ponerse una cadena de 15 kilos y vivir entre sus excrementos por un par de días. Si quieres cuidar tu finca, ponte una alarma que será mucho más eficaz. La ley de “bienestar animal” actual deja mucho que desear y el maltrato animal sigue quedando impune en España. Trabajemos para erradicar la maldita costumbre de usar animalitos como sistemas de protección o defensa de terrenos.

Aprovecho para agradecer a los amigos y amigas de Perros sin Fronteras su apoyo incondicional y difusión del caso. Sabemos la presión que tienen las protectoras y asociaciones animalistas, lo que aumenta aún más nuestro sentimiento de gratitud. Seguiremos rompiendo cadenas.

La Cátedra de Animales y Sociedad de la URJC: Un referente de empatía y respeto hacia los animales.

Tags

, ,

El mes pasado escribí el artículo “Primum Non nocere: La necesidad de reemplazar la experimentación animal en la investigación de enfermedades neurodegenerativas”, publicado por la Cátedra Animales y Sociedad de la Universidad Rey Juan Carlos -URJC-

La Cátedra de Animales y Sociedad de la URJC es un referente académico y fuente de inspiración para difundir el obligado respeto que debemos como humanos a la dignidad y libertad de otras especies con las que convivimos. Invito a otras universidades de España y Europa que estudien la misión de la Cátedra (https://catedraanimalesysociedad.org/mision/) y la incorporen a sus programas.

Estoy muy agradecido a la Dra. Nuria Máximo Bocanegra por invitarme a su espacio y por la impresionante labor que lleva a cabo como coordinadora de la Cátedra. Fue un placer compartir tiempo escribiendo y editando el artículo con Nuria y su equipo.

El trabajo de Nuria Máximo y su Cátedra debe ser un ejemplo a seguir por otras instituciones académicas dentro y fuera de España. Sin lugar a dudas, beneficiará nuestro modelo educativo y avanzaremos hacia una sociedad más moderna, empática, respetuosa y justa. ¡Gracias, Nuria!

Les dejo el enlace al artículo y a la Cátedra de Animales y Sociedad.

El maltrato animal es la máxima expresión de la violencia machista

Tags

, , ,

Ayer, una multitud hostigaba y hacía a huir a un toro aterrorizado que terminó saltando al mar y muriendo ahogado ante las risas y el jolgorio de los participantes. Ocurría en Denia, una localidad alicantina en el contexto del “Bous a la mar”, un evento declarado de Interés Turístico Nacional.

Pretender erradicar la violencia machista mientras se fomenta el maltrato animal no sólo es una contradicción, sino un imposible. El maltrato animal conlleva, inevitablemente, a tipos de conductas opresivas y discriminatorias como la violencia de género, acoso o el bullying.

Foto: REUTERS/Heino Kalis

Un claro ejemplo de esta correlación entre el maltrato animal y la violencia machista son los Sanfermines. El número de denuncias por violencia machista en dicha festividad sigue en aumento. Tal es la preocupación del gobierno de Navarra que este año el lema fue “Navarra es fiesta. Stop Agresores”. No deja de ser curioso, porque si cumplieran con este lema no se celebrarían estas fiestas, ya que los primeros agresores son los que maltratan y matan a los toros y aquellos que disfrutan de esta barbarie.

Tan trágico como paradójico resulta el hecho que muchas de las mujeres que denuncian ser agredidas y violadas son parte de una festejo donde se celebra la agresión, el maltrato y la muerte. Me cuesta entender a mujeres que se denominan feministas, que denuncian la violencia y discriminación sentadas en una plaza de toros o celebrando los Sanfermines. Un claro ejemplo de disonancia cognitiva.

La contradictoria campaña "Stop Agresores" del gobierno navarro, que festeja el maltrato animal, donde humillan, agreden y matan a animales indefensos
La contradictoria campaña “Stop Agresores” contra la violencia machista en los Sanfermines , una fiesta donde agreden, humillan y matan animales indefensos.

El gobierno actual no puede hablar de feminismo y progresismo cuando fomenta los Sanfermines, la tauromaquia, los “Bous a la mar”, “Correbous” y con una ley de bienestar animal condena a los perritos de los cazadores a un infierno. No es sólo un problema del gobierno actual, sino de la clase política. Salvo PACMA, no he visto ningún otro grupo político (de “derechas” o “izquierdas”) denunciar este tipo de festejos y abordar en su campaña la situación de abandono y maltrato de millones de animales en España.

La televisión pública (TVE) emite -en horario de protección al menor- corridas de toros, con todos los elementos para generar stress post-traumático y destrozar la personalidad en formación del niño o joven. Sangre, sufrimiento, agonía y muerte es televisado con todo detalle por el canal público. Acto seguido, el Telediario anuncia la trágica noticia de otro asesinato machista y el número 016 contra la violencia de género aparece en la pantalla.

El lobby de la tauromaquia y la caza gestiona los medios públicos y privados. Se romantiza y se eleva a la altura de héroe a la figura del torero, al punto que representantes del gobierno y monarquía posan ante las cámaras abrazando la viva imagen del maltrato e involución social. Estos mismos medios se encargan de silenciar a quienes denuncian el maltrato animal y tachar de grupos “extremistas y radicales” a los que luchan por los derechos y la dignidad de las víctimas que sufren un maltrato sistemático.

La clase política evidencia su hipocresía al denunciar violencia machista mientras declaran de interés cultural actividades atroces que nos empequeñecen como sociedad y son tierra fértil para futuros maltratadores, acosadores, violadores y asesinos.

Seguiremos luchando hasta el último suspiro por una sociedad moderna, empática y respetuosa. Seguiremos en la lucha por la libertad y dignidad de todos los animales víctimas de la humillación y el maltrato, independientemente de la especie.

Seguiremos rompiendo cadenas.

Hospital de Salud Mental referente en Argentina elige GNU Health

Tags

, , , , ,

La Organización Mundial de la Salud define salud como un estado de completo bienestar físico, mental y social, y no solamente la ausencia de afecciones o enfermedades.

Desafortunadamente, esta definición está lejos de cumplirse en nuestra sociedad. En vez de abrazar la salud, estamos inmersos en el sistema de enfermedad, gobernado por un modelo de gestión reactivo, reduccionista e insostenible. El noble arte y ciencia de la medicina está enfermo. Instituciones financieras y gigantes corporaciones tecnológicas están destruyendo el factor humano de la práctica médica, transformando las personas y pacientes en clientes. Están reduciendo el derecho humano no-negociable de la salud a un privilegio al alcance de unos pocos.

Volviendo a la definición formal de la salud, en el actual sistema de enfermedad, poco o nada se tiene en cuenta el bienestar social y mental. Al día de hoy, muchas personas con condiciones de salud mental no sólo tienen que lidiar con los aspectos fisiopatológicos de la enfermedad, sino que deben enfrentarse a la exclusión social y el estigma impuestos por una sociedad enferma de individualismo y carente de empatía.

En cualquier caso, soy optimista. Hay esperanza. La medicina es una ciencia social y GNUHealth es un proyecto social con algo de tecnología. Este sentimiento de optimismo se ha visto reforzado la semana pasada en mi viaje a Argentina y por el equipo humano. Al final del día, la medicina son personas interactuando y ayudando a personas. Esto lo conozco bien, porque hice la carrera de medicina en Argentina, donde los profesores y profesionales de salud anteponían la persona antes que el paciente. Ese profundo respeto hacia la persona que padece lo pude observar en muchos de los centros de salud en los que roté. En Buenos Aires lo vi en la guardia del Rivadavia; en cirugía y en los servicios cuidados paliativos del Tornú; en el neuropsiquiátrico del htal Moyano, por nombrar algunos. El humanismo médico brota por los poros de las mujeres y hombres profesionales de salud en cada salita y centro de atención primara que he visitado a lo largo de estos años en Entre Ríos, como el centro comunitario D’Angelo, situado en el barrio Anacleto Medina, uno de los más carenciados de Paraná. Tuve el honor de entregar en persona el premio GNU Health de Medicina Social en 2022 a su directora, Teresita Calzia.

El centro de Salud Humberto D’Angelo lleva 10 años utilizando GNU Health para una gestión integral de la salud comunitaria. En el cuadrante superior izquierdo, Carli Scotta y Fernando Sassetti junto al panel de situación. Debajo foto de grupo. A derecha su directora, Teresita Calzia, junto a Ana María Dominguez, enfermera quien sostiene el premio GNUHealth a la Medicina Social 2022.

El Hospital Escuela de Salud Mental ha elegido GNUHealth para mejorar la gestión de sus recursos, así como para ofrecer la mejor asistencia médica a su comunidad, tanto en un entorno ambulatorio como hospitalario. Ser capaz de identificar inequívocamente y en tiempo real a cada persona que necesita atención, así como conocer la historia socio-sanitaria, médica y su historia clínica será una gran ayuda para los profesionales de salud como para el propio paciente.

La implementación de GNUHealth en el Hospital Escuela de Salud Mental se llevará a cabo por la cátedra de Salud Pública de la Universidad Nacional de Entre Ríos, conjuntamente con el equipo local del centro de salud (psicólogos, enfermeros, médicos, agentes sociales) y apoyada por GNU Solidario. El día de mi visita nos reunimos con el equipo de salud y se presentó el proyecto “Implementación de un sistema informático para la gestión hospitalaria y el cuidado de la salud de los usuarios del Hospital Escuela de Salud Mental de la ciudad de Paraná”, que cuenta con el financiamiento de los Proyectos Federales de Innovación 2022.

Integrantes del equipo de salud del Hospital Escuela de Salud Mental, representantes de la provincia de Entre Ríos y autoridades académicas.

La salud es un equilibrio de los dominios físico, social, mental, espiritual y medioambiental, que son interdependientes e inseparables. Practicar la medicina es intentar mantener el balance cuerpo-mente-espíritu, tanto a nivel individual como colectivo. Este abordaje holístico de la salud está codificado en el genoma de cada enfermera, psicólogo, trabajador social y médico del Hospital Escuela de Salud Mental, así como de cada centro de Atención Primaria que he visitado a lo largo de estos años en Entre Ríos, Argentina. Es un honor y me siento muy afortunado de poder cooperar con ellos.

Referencias / enlaces relacionados

Un software Libre para mejorar las políticas de salud: https://www.eldiario.com.ar/253548-un-software-para-mejorar-las-politicas-de-salud/

Hospital Escuela de Salud Mental : http://www.hesm.gob.ar/

Audiovisual institucional Hospital Escuela de Salud Mental: https://www.youtube.com/watch?v=Jx08WyfKRIE&t=12s

GNU Health: https://www.gnuhealth.org