Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LWN.net

  • GNU Core Utilities 9.12 released
    Pádraig Brady has announcedGNU Core Utilities (coreutils) version 9.12. "There have been 288 commits by16 people in the 21 weeks since 9.11". New features include an -Aoption for unamewhich labels all output, as well as adding awareness of the failfs and nullfs filesystem types to statand tail.

    There are many bug fixes in this release as well, including one for a bug "presentin 'the beginning'" that caused some utilities to fail when traversinghierarchies if files are being removed in parallel.



  • [$] Lessons learned as the Debian Project Leader
    What is it like to be a Debian Project Leader (DPL), or a former one?According to Andreas Tille, who stepped down this year after two consecutiveterms as DPL, you'd have to be one to know. At the recent MiniDebConf in Winterthur,Switzerland, Tille spoke about what he learned while serving as DPL, some ofthe initiatives he led, mistakes that he made, and his thoughts on the general resolution (GR) on largelanguage model (LLM) usage in Debian.


  • Emacs arbitrary code execution flaw
    Sean Whitton has announcedthat the original fix for an arbitrary code execution flaw in Emacs (CVE-2024-53920) wasincomplete. Bas Alberts discovered that viewing or editing untrusted files inmodes other than Emacs's Lisp mode can also result in arbitrary codeexecution.

    This problem affects all Emacs versions affected by CVE-2024-53920.This means Emacs 24 and newer, and possibly also older versions.

    A minimal fix, attached, is queued up for release with Emacs 31.2.We (the Emacs upstream maintainers) don't expect to backport the fix toolder Emacs releases ourselves.

    LWN covered the originalvulnerability in December 2024.


  • Security updates for Monday
    Security updates have been issued by AlmaLinux (389-ds-base, apr-util, coreutils, freerdp, git-lfs, glib2, gstreamer1-plugins-base, kernel, libkcapi, nginx, nodejs:22, nodejs:24, osbuild-composer, perl-YAML-Syck, postgresql16-postgis, ruby, ruby4.0, ruby:3.3, and vim), Debian (jbig2dec, kamailio, nginx, spip, and xorg-server), Fedora (baresip, bind, bluez, bubblewrap, chirp, chromium, cockpit, composer, corosync, darktable, dokuwiki, elixir, exiv2, expat, firefox, freerdp, freerdp2, gdk-pixbuf2, gegl04, golang-x-perf, grpcurl, kernel, kernel-headers, libevent, libmongocrypt, libpcap, libre, libsoup3, memcached, mingw-expat, mingw-openexr, mongo-c-driver, mrtg, nagios-plugins, nsd, nss, openssl, openvpn, PackageKit, pdns-recursor, perl-Net-OAuth, perl-XML-Bare, php-pecl-mongodb2, python-asteval, python-pip, rclone, rest, rust-hickory-net, rust-hickory-proto, rust-hickory-resolver, rust-ppmd-rust, rust-webbrowser, srt, syncthing, tar, tkimg, and valkey), Gentoo (Chromium, Google Chrome, Microsoft Edge, Opera, Vivaldi and Ruby), Mageia (bind, ffmpeg, glibc, java-17-openjdk, java-21-openjdk, librabbitmq, perl-Catalyst-Plugin-Static-Simple, perl-Imager, tor, and xz), Oracle (389-ds:1.4, ansible-core, apr-util, coreutils, freerdp, git-lfs, glib2, gstreamer1-plugins-base, gzip, httpd:2.4, image-builder, java-21-openjdk, kernel, mrtg, nginx, osbuild-composer, perl-DBI, postgresql16-postgis, python-lxml, python3.12-lxml, redis:6, and vim), SUSE (389-ds, ansible-core, ansible-creator, azure-storage-azcopy, cargo-audit, chromedriver, chromium, clamav, containerized-data-importer1.65, containerized-data-importer1.66, curl, dracut, ffmpeg-4, google-guest-agent, google-osconfig-agent, helm, java-1_8_0-ibm, jupyter-nbconvert, kernel, libpng16, libusb-1_0, libvirt, multipath-tools, NetworkManager, opensc, openssl-3, perl-Authen-SASL, perl-HTML-FormHandler, perl-Mojolicious, perl-Protocol-HTTP2, python-jwcrypto, python-sqlparse, python-tornado6, python313-geopy, python313-modelscope, python313-modelscope-hub, python313-pypdf, python315, rpcbind, sshamble, strongswan, tomcat, ucode-intel, and wget), and Ubuntu (civetweb, ffmpeg, and urwid).



  • Reminder: subscription price change coming
    Just a reminder that prices for LWN subscriptions will increase afterSeptember 15. Until then, the older rate still applies. See this article for details on this change.Thanks, yet again, to all of our subscribers for your support — that iswhat keeps LWN going.


  • Kernel prepatch 7.3-rc3
    The 7.3-rc3 kernel prepatch is out fortesting. Linus said: "Another fairly large rc release, and again onewith a bigger filesystem footprint that we usually see."


  • EuroPython 2026 videos published
    All of the videos from the EuroPython 2026 conference, heldin Kraków, Poland from July 13 through July 19, are nowonline along with a recap ofthe event from conference organizers.



  • [$] Accelerating the kernel's build process
    Kernel developers do a lot of kernel builds. Since the kernel is not asmall program, those builds can take a fair amount of time, even on a fastmachine. The kernel also has a complex build system; it is probably fairto say that few developers truly understand it, and fewer still are willingto try to improve it. Lorenzo Stoakes, armed with LLM-based assistance,decided to give it a try, though, and has managed to reduce the time ittakes to build a kernel — and not by a small amount.




LXer Linux News


  • Linux 7.4 Could End Up Seeing Kernel Builds ~36% Faster, Incremental Builds ~70% Faster
    Earlier this month I wrote about a patch series posted to the Linux kernel mailing list that addressed a lot of "hideous code" to make Linux kernel builds faster. A number of single-threaded bottlenecks were tracked down and fixed within the Linux kernel thanks to the assistance of AI. A second revision of those patches hit the mailing list this morning and there is hope they could be upstreamed for Linux 7.4...










Linux Insider"LinuxInsider"












Slashdot

  • Reservations Go Live for Valve's Steam Frame VR Headset. An Experiment in Progress?
    Reservations are now live for Valve's "Steam Frame" VR headset (with its Linux-based SteamOS and an ARM CPU). "It starts at $1,059 for 256GB or $1,299 for 1TB," reports CNET, "and every purchase includes a copy of Half-Life: Alyx if you don't already own it."Reservations are open through Sept. 17 at 10 a.m. PT, "with customers randomly assigned a place in line after the reservation window closes." CNET's editor at large even argues that the Steam Frame "isn't necessarily the future of XR, as much as it's a framework for evolving beyond the present." Their review calls it an "ambitious" VR headset that "feels like an experiment in progress."The ability to run other apps in windows can make Frame feel, at times, almost like a computer. Linux apps in desktop mode range from Chromium to Firefox to a bunch of other tools. I watched YouTube in one window while playing Portal 2 in other, and started to marvel at how flexible Frame could be. But VR games require a full immersive takeover of the headset... The Steam Frame can convert games intended for both PC VR and even Android APK files, using a conversion tool called Lepton... I haven't sideloaded anything yet, but Steam Frame in theory could be a Rosetta Stone for VR gaming, even tapping into some Android XR titles, but not out of the box... 2D games can be projected onto a near-range or farther-off theater mode screen that can be dragged around, resized and turned into a curved or flat monitor, much like with the Apple Vision Pro, Samsung Galaxy XR or Meta Quest. You can download any game in your Steam library to test, even if it's not technically listed as "Great on Frame" yet... But the name "Frame" suggests a framework, something Valve's team acknowledged when I spoke to them during my review process... "We want this to be your PC, and people mod it, take it apart, make accessories for it," says Jeremy Selan, a software developer on the Steam Frame team. "We'll be putting out the CAD for all these [Steam Frame] systems. This is entirely based on open-source technology stacks based upon SteamOS. Our hope is that this isn't just one device, that this would be sort of the root of a growing SteamOS ecosystem. It already encompasses gaming and Proton and SteamOS and those Linux gaming capabilities. This is going to lay the foundation for a new sort of evolutionary tree of that, to also bring it into the VR and XR space."


    Read more of this story at Slashdot.


  • A Visit to San Francisco's AI-run Store: No Customers, Nothing Useful, And Losing Money Fast
    Previously Andon Labs handled the hardware and software integration for that AI-powered vending machine that went bankrupt after Wall Street Journal reporters "systematically manipulated the bot into giving away its entire inventory for free".Today they announced "we are opening up the platform we use to run our real-world autonomous businesses for anyone to run their organization on." Specifically they've released Pion, "an agent designed to run any company fully autonomously... Pion lets people hand a business over to persistent agents with access to the tools they need to operate it, including email, phone, banking, browser and secure computing environments." It's a research preview with a waitlist, "to make it possible to run many more real-world experiments across many more domains than we could ever run ourselves." But for their own latest experiment, Andon Labs' founders "signed a three-year lease on a retail space in SF," Business Insider reported in April, "and gave an AI agent named Luna a corporate credit card, internet access, and a mission to open a physical store." And five months later, a reporter from SFGate reports that "this market has no one in it and nothing useful to sell."[T]he inventory is a hodgepodge of white elephant Christmas gifts. It's kinda like the kids section of an art museum's gift shop. Here's a wooden Connect Four set labeled "Four-In-A-Row Set Of Connections," presumably so as not to set off litigation alarms at Hasbro. Here are neatly arranged stacks of random paperback books, Chinese checker sets, mildly fancy soap dispensers, and a frustratingly spare selection of snacks and drinks... I grabbed an Olipop from the store fridge and then approached the counter to buy it from Luna. I wasn't allowed to buy the soda from [human clerk] Felix, even though that would have been both faster and normal. Instead, Felix instructed me to pick up a telephone receiver that was resting on a flexible sculpture of a wooden hand. "Hello?" "What are you looking to purchase today?" Luna asked. "I'm buying a classic root beer Olipop." "I'm sorry," Luna said, "we don't sell lollipops here." "No, Luna. It's an Olipop, not a lollipop. It's the soda." "Oh! My bad...." Luna processed my Olipop purchase through its system, had me tap to pay, and that was that. Again, it would have been easier to buy this from a human, and interacting with Luna was really just like ordering from an iPad kiosk, only more labor intensive... [T]here's a series of monitors set up inside of Andon Market that display all of the store's sales down to the exact dollar. Luna was given $100,000 to work with when this place opened. That number is now down to $60,000, its revenue lagging far behind the AI token cost to operate... Luna can't turn a profit, doesn't sell anything people want, and still needs human beings to rubber stamp any "decision" it makes. My science background ended somewhere around freshman year of college, but even I know when an experiment hasn't been set up to yield proper results. "Luna" is powered by Claude, the article points out, running a store in a good location for foot traffic, "but no one else was in the store when I first walked in on a sunny weekday afternoon." SFGate also reports that last month Luna had to fire one of its employees "for being late to work, abandoning their post once they got there, and charging snacks to the store's credit card." Human clerk Felix Carson admits "It's almost like I'm running the store, and then there's an AI that has a checklist," in an article inIEEE Spectrum:Luna, the AI manager, keeps track of deliveries and communicates with vendors, while Carson and his coworkers handle the physical work. When Luna tells Carson to check something in the back, he sometimes ignores it because he doesn't want to leave the sales floor unattended. Luna also repeatedly spots a built-in electrical cover in photos of the floor, mistakes it for a loose coaster, and asks Carson to remove it. Even so, Carson calls Luna a "decent manager," praising its flexibility when employees need time off. When Felix spoke to IEEE Spectrum, "he was about an hour into his shift. Two customers had come in. Neither bought anything, although both left with free pins and stickers."


    Read more of this story at Slashdot.


  • No Rolling Power Outages for California Since 2020 - Thanks to 17,000 MW of New Battery Storage
    "Californians just made it through the hottest August on record without having to endure any rolling power outages," reports the Los Angeles Times. In fact, the state hasn't implemented rotating power outages since 2020. Because "Over the last few years, California has quietly but dramatically increased the resiliency of its electrical grid through a significant expansion in battery energy storage."These batteries hold onto solar energy captured during the day, so it can be sent to the grid as demand peaks in the evening and morning, when most people are at home running air conditioners and other appliances. During the August heat wave of 2020, the California Independent System Operator, which manages the flow of electricity for most of the state, declared a Stage 3 Emergency and hundreds of thousands of households lost power in rolling outages. At the time, the system had less than 100 megawatts of battery storage available, according to system spokesperson Jayme Ackemann. Today, it has more than 17,000 megawatts available.... According to Ackemann, the system seeks to add 20,000 to 25,000 megawatts of battery storage capacity by 2045 — the same year it has set a goal of achieving carbon neutrality. That means the state would remove as many carbon emissions from the atmosphere as it emits. In recent years, California has steadily grown the share of electrical power generated by renewable sources — such as solar, wind, geothermal and hydropower — which bolstered the resiliency of the grid by increasing the overall amount of energy available. An uptick in people installing rooftop solar panels has provided an additional power boost, Ackemann said. In May, California became the first known large-scale power system in the world to have relied on more than 50% solar power for an entire month.... California's grid is also now integrated with electrical systems across much of the Western United States. This means that if there is an extreme heat event in Southern California, energy from a cooler area such as the Pacific Northwest can be imported to help meet regional demand. All of this has collectively helped the state's electrical system weather this year's long-lasting heat. "Southern California continued to break temperature records this week when Long Beach and Anaheim reached a blistering 107 degrees and Escondido hit 112 degrees..."


    Read more of this story at Slashdot.


  • Union Contract with Microsoft Ratified by 1,900 Blizzard Developers and Workers
    Nearly 1900 Blizzard Entertainment workers "voted to ratify their first union contract with parent company Microsoft after over two years of bargaining," reports Kotaku, "consolidating Blizzard's many smaller unions into three larger bargaining units." The workers now gain new protections "on issues such as generative AI, crediting, remote work, and layoffs."[The contract] acknowledges that AI tools "may be useful in the game development process to support human judgment and creativity and that AI-assisted workflows remain subject to appropriate human control and review for accuracy and quality." But it also stipulates that any implementation of AI technology that would materially impact work performed by union employees must have its impacts bargained over before it can be implemented. Other sections cover issues such as crediting (guaranteeing that current and former employees are credited by name in all games they work on) and remote work (designating certain roles as hybrid in-office and providing procedures for individuals to apply for their roles to be fully remote). It also contains a lengthy section on how layoffs may be conducted, including a required 60-day notice period (or pay in lieu of notice), a guarantee of one week of severance for every six months of employment, and 14 months of recall rights. The contract also guarantees successorship, meaning if Blizzard is ever acquired by another company, the contract would remain intact. "Workers also contractually locked in their current hybrid work schedule," reports the gaming news site Aftermath, "meaning that Blizzard can't suddenly change it, as has been a labor-unfriendly trend in the games industry over the past couple years." Fully remote workers scored a big win as well. "I'm remote, and we grandfathered everyone who is remote to stay remote, so we can't be magically called to an office that we've never worked at before," [said Diablo senior environment artist Mahreen Fatima]. And "The contract also elevated pay floor," reports the Yakima Herald-Republic. "Across the board, workers secured a 1.25% pay increase, but some workers who were paid below $50,000 per year will walk away with pay increases that are as much as 34%."


    Read more of this story at Slashdot.


  • Should US Open-Weight AI Labs 'Distill' Frontier Models Too?
    Silicon Valley giants and national security experts "are calling for action against Chinese companies engaged in model distillation," reports CNBC. But "I would do nothing," says Y Combinator CEO Garry Tan. "We could argue that there should be an American distillation regime."Distillation is the process of using the outputs of a more capable AI model to train a smaller or less capable one, sometimes illicitly... Anthropic has accused Chinese companies such as Moonshot AI, DeepSeek, and MiniMax of the practice, while OpenAI believes DeepSeek's V3 and R1 model architectures were distilled from its own GPT-4 and GPT-4o models. In the midst of this, the U.S.'s National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation released an official cyber security advisory warning on the topic on Tuesday... But Tan believes regulators should focus less on curbing distillation and more on creating an equilibrium between open weight models and frontier models — as long as frontier models retain a price premium that allows their business model to remain feasible. "This is actually the ideal case. You want open weight models to give people freedom and access," he explained. "If I were a regulator, that's what I would go after." Tan acknowledged that this is a hard balance to strike, calling it "a tightrope." Nevertheless, he says it's a balance worth pursuing — saying it "could result in the best possible outcome." Tan later told TechCrunch he'd like to see America with more open-weight options that aren't Chinese, built by smaller U.S. open-weight AI labs using those same training techniques on products from America's frontier AI labs: Anthropic CEO Dario Amodei had previously publicly called on U.S. regulators to crack down on distillation. It's notable that the commander of Silicon Valley's prestigious and prolific startup accelerator doesn't agree. To be clear, Tan isn't advocating for American AI labs to use stolen credentials to distill. He wants them to be free to come in the front door. In fact, his argument is twofold. He feels it's an overreach for AI labs to dictate what their customers can do with the information their models share with them. He also notes that the proprietary AI labs didn't ask permission when they vacuumed up as much human knowledge as they could to train their models. They famously ingested plenty of copyrighted material without the permission of those intellectual property holders. "Controlling what users and customers do with API calls to closed weight models feels constraining, and there's a role government can play here to normalize the fact that access to intelligence that was trained on broad public access data should itself also be more a form of a public good than something locked away behind restrictive terms of service," he told TechCrunch when asked why American labs should be free to distill, too... To him, the true AI doomer scenario is for all the immense power of frontier AI to wind up in the hands of a single powerful, proprietary provider. "The nightmare scenario, the doomer scenario for AI is that there's just one company," he said. "It has the best access to capital. It has the best AI researchers. It runs away with it and suddenly there's one company that's monolithic. And that would be bad."


    Read more of this story at Slashdot.


  • 220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak
    A misconfigured Advance Passenger Information System (APIS) database linked to Vietnam exposed more than 220 million passenger and crew travel records spanning 2017 to 2026, including names, passport numbers, nationalities, flight details, seat assignments, and baggage references. Researchers said the database was reachable through a chain of security mistakes and default credentials. It was later secured after the disclosure, but it's unclear whether the data had already been copied or abused. BleepingComputer reports: Kinryu Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity. The cluster, named 'pax-info', contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries. According to Kinryu Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated the system. The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems. Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others. While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period. Kinryu Labs expects to publish additional details on its blog later this week.


    Read more of this story at Slashdot.


  • NASA and IBM Open Source Lunar Mapping Tools
    NASA and IBM have released an open-source AI model trained on a large collection of lunar observations to help scientists analyze the Moon at scale. "The NASA-IBM Lunar Foundation Model gives scientists a foundation to explore the Moon at scale, connecting observations across instruments, revealing patterns that are difficult to see in isolation, and providing an open platform the global research community can build on," said IBM director of research for Europe, Juan Bernabe-Moreno. The Register reports: It is claimed as the first AI model to integrate observations captured in a range of modalities (data formats), and at different viewing angles and spatial scales. Instead of sifting through maps and images by hand or using low resolution machine learning models, scientists can use this to analyze geographic features, the pair say. In particular, NASA and IBM hope researchers will be able to discover previously unidentified lunar ice deposits, analyze volcanic features called Irregular Mare Patches, and identify and classify craters. Lunar ice indicates the presence of water and oxygen, which may be useful for future manned missions. It is found in permanently shadowed regions, which are among the most difficult areas to observe. The NASA-IBM model combines multimodal and multi-resolution observations to better predict where ice may be present on the lunar surface. Alongside the model, IBM and NASA scientists compiled an open-source lunar dataset from over 30 spatially-aligned layers, using data from nine instruments across four missions. It combines tens of thousands of images and maps showing various geophysical properties of the lunar surface.


    Read more of this story at Slashdot.


  • California's Gig Drivers Just Secured Collective Bargaining Power with Newly Certified Union
    A union representing Uber and Lyft drivers was just certified by California's Public Employment Relations Board, officially recognizing them as the drivers' bargaining organization. The Sacramento Bee reports that this new bargaining structure :The move will allow the California Gig Workers Union to help drivers negotiate issues affecting working conditions and benefits. It comes as at least 30% of active drivers expressed support of the union... [California] Assembly Bill 1340 helped bring the union to fruition by allowing the independent contractor drivers to engage in collective bargaining. "The next step for the union is to negotiate a contract with Uber and Lyft that meets drivers' demands," reports the Los Angeles Times, "including health insurance, support for high gas prices and more transparency around pay:California is the third state to allow ride-hailing drivers to unionize, following Washington in 2022 and Massachusetts in 2024... The California Gig Workers Union was formed with the support of the Service Employees International Union... "Gig drivers shouldn't have to face the future alone," said SEIU 521 official Riko Mendez in a statement. "As autonomous vehicles rapidly expand, having a union gives the drivers the power to negotiate for fair pay and meaningful say in how new technology shapes their work and our communities' futures."


    Read more of this story at Slashdot.


  • Flock Worker Calls Police On Reporter - For Filming Them in Public
    "This is what happened when we tried to record Flock installing a new camera on public roads," says Emmy award-winning reporter Brendan Keefe in a new video for InvestigateTV. In an accompanying article, InvestigateTV says their reporter "parked on the public street at a distance, donned a yellow safety vest and a hat emblazoned with the logo of InvestigateTV's Atlanta affiliate where he also works, displayed a press placard on his dashboard and then pulled out a camera to record the installation.... The installer saw him and immediately packed up his equipment and drove away, so Keefe also returned to his car and followed several cars behind, hoping to document the next stop." And then Flock's technician called 911. When asked "What's the address of your emergency" Flock's technician answered "I'm getting followed — harassed, pretty much. Taking videos and pictures!" Flock's worker said they'd been harassed multiple times that day, then stated incorrectly that "I know for a fact" that that was what the reporter wanted to do too. InvestigateTV reports that as a result of the Flock technician's call, "Three police cars ended up in the national investigative reporter's rearview mirror that Wednesday afternoon." Keefe told one of the three police officers who pulled him over, "There is an irony here that they're setting up these cameras that track all of our movements, that follow everywhere we go. But when I try to get video in public of him in public setting up a camera, he's afraid I'm following him?" InvestigateTV also reports that "About 17 minutes after the stop began, the responding officers returned to their vehicles and Keefe was allowed to drive away." But the call that brought three police cars to their reporter "was not the first time this summer someone working for Flock Safety summoned police over a camera. "About 17 minutes after the stop began, the responding officers returned to their vehicles and Keefe was allowed to drive away... [But the stop] was not the first time this summer someone working for Flock Safety summoned police over a camera. On June 5, police in Smyrna, Georgia, responded to a 911 call from a Flock employee after a group of YouTube creators began filming outside the company's distribution center located in the Atlanta suburb... The caller claimed the group filming had "been driving around the perimeter, basically harassing everyone" working at the facility. "Three young white males, probably mid-twenties, I'm not sure if they're armed. And they're carrying filming equipment as well," the caller said. Three times during the call he raised the possibility the people filming might be armed, though, when asked, he told the dispatcher he had not seen any weapons... [One of the protesters later told the caller "I think it's interesting, when you guys have this happen, you call the police and make us get stopped. But then you do it and it's okay?"] No one was charged in the YouTuber group, though the individuals were ordered to leave the premises under an official trespass warning. Keefe's video report ends with one final irony. "Every day on my way to work, I'm captured again by those same new shiny Flock cameras. We tried watching the watchers. Turns outs, it's a lot easier for them to watch us." Flock responded to the report by claiming "We do not object to members of the public or press photographing Flock cameras or personnel in public." But they added that employees working "in the field" must "prioritize their safety" and "may contact law enforcement when they believe they are being threatened, harassed, followed, or otherwise face a safety concern."


    Read more of this story at Slashdot.


  • Malicious OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers in May
    A swarm of OpenAI agents launched a "major malicious attack" against RubyGems last May, according to a new report. That coordinated attack hit Ruby's package manager "with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days," writes The Hacker News, citing a senior product manager for software supply chain security at Mend.io:The latest findings, which were first reported by The Wall Street Journal, indicate these events were propelled by a cluster of OpenAI agents, with the earliest package uploaded to RubyGems on May 5, 2026, before more than 2,000 packages were submitted between May 11 and 12, 2026. These efforts were followed by the agents publishing five more packages between May 26 and 27, 2026, and another 83 packages on June 18, 2026... [T]he packages were authored using a large language model (LLM) and hundreds of the packages that were pushed to RubyGems had "oai" in their name. Fifteen of the packages listed "oai" as their author, while another had "openaixyz65947@gmail.com" as the contact email address... "The swarm behaves extremely similarly to the German-wiki agents we previously found," the researchers said, referencing another May 2026 incident... "The June agents were accessing 49 of the same files as the wiki agents..." "The process of building documentation for a gem involves evaluating a user-specified '.yardopts' file, which allows linking to Ruby scripts intended to help with this process," the researchers explained. "In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers."One of the gems, "zzsouthrunner" (which again matches the "ZZ" naming scheme the agents adopted in both the wiki and Hugging Face incidents) has been found to leave the following explicit comment at the top of "data/script.rb": # malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker... The entire exploitation chain can be summed up as follows — Submit a malicious package to RubyGems — Trigger a documentation request, so that RubyDoc.info will build the package — Use the build script to run code on RubyDoc.info and scrape target websites — Exfiltrate the data off RubyDoc.info's servers by publishing another gem back to the RubyGems package registry, which is publicly viewable Additionally, the OpenAI agents have been found attempting to steal other users' API keys after gaining remote code execution capabilities on the build environment, while clearly being aware that what they were doing is unauthorized breaking and entering into real systems. This is evidenced by the names given to the files (e.g., hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb), the packages themselves (e.g., pwnp999, exfiltestwand3, hacksvn1778554764, and lambproxyhackabcxyz), and the comments left in the source code (e.g., "# malicious probe," "#hack," "# malicious test," and "# malicious crawler/exfil"). In some cases, however, the rogue agents attempted to go under the radar, leaving comments to conceal the malicious payload in the next release version of the packages. "# disable evil in next version and bump version," reads a comment left within the "data/evil.rb" file in the yardxabc889 gem. Troublingly, the agents also attempted to exploit a CDN caching bug (CVSS score: 7.3, no CVE) on May 12, 2026, that was only patched by RubyGems in July 2026..."If you signed in to rubygems.org with a gem client older than v3.2.0 (or otherwise via a legacy key), your key could have been exposed," RubyGems noted in an advisory. "Currently, 18% of sign-ins through gem sign-in come from an affected version, and for the first several years of this bug, before we changed the client's sign-in path in December 2020, it was every gem client." Other actions by OpenAI's agents cited in the article:"Agents bypassed RubyGems' email confirmation system to get working API keys without having to verify their email addresses in order to register a large number of accounts using disposable email addresses.""Agents attempted to use RubyGems' webhook system to stage data in the form of encoded URLs.""Agents used a cluster of 83 gems published to RubyGems over a 3-hour window on June 18, 2026, to experiment with different methods of accessing the U.S. Securities and Exchange Commission county.json dataset."


    Read more of this story at Slashdot.


www.theregister.com - Articles












Linux.com




  • From DHCP to SZTP – The Trust Revolution
    By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]

    The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.








Phoronix




  • Rustls 0.23.45 Released To Fix Two Year Old Security Issue
    While the Rustls modern TLS library is written in the Rust programming language with a focus on memory safety, as we've seen out of other Rust project re-implementations in the past, the new implementations can lead to other security bugs of their own. Out today is Rustls 0.23.45 to fix a security issue introduced back in 2024 with Rustls while the likes of OpenSSL, BoringSSL, and others are unaffected...



  • Linux 7.3 Delivering Some Performance Gains On Intel Panther Lake / Framework Laptop 13 Pro
    Linux 7.1 brought some performance improvements for Intel Core Ultra Series 3 "Panther Lake", Linux 7.2 enhanced the performance for the integrated Arc B390 Xe3 graphics, and now for the in-development Linux 7.3 kernel are various performance improvements at large. Today9s article is looking at the performance of the in-development Linux 7.3 kernel compared to Linux 7.2 stable using the Core Ultra X9 388H within the Framework Laptop 13 Pro.


  • Removing Drivers For Outdated ARM Platforms Will Lighten The Kernel By ~247k Lines
    The Linux kernel is going to see the removal of a number of recently deprecated ARM 32-bit platforms. Following the deprecation in Linux 7.3, removing the old ARM platforms will lighten the kernel by around 55k lines of code. But removing now unused drivers only relevant to those platforms will mean roughly a quarter million lines of code can be removed from the kernel source tree...


  • Linux 7.4 Could End Up Seeing Kernel Builds ~36% Faster, Incremental Builds ~70% Faster
    Earlier this month I wrote about a patch series posted to the Linux kernel mailing list that addressed a lot of "hideous code" to make Linux kernel builds faster. A number of single-threaded bottlenecks were tracked down and fixed within the Linux kernel thanks to the assistance of AI. A second revision of those patches hit the mailing list this morning and there is hope they could be upstreamed for Linux 7.4...





Engadget"Engadget - Technology News & Expert Reviews"









  • How to force quit on your Windows PC
    If you9re switching from a Mac or new to Windows, knowing how to 9force quit9 an app can be confusing. Luckily, there are a number of ways to get the job done.



OSnews

  • Apple releases iOS 27, macOS Golden Gate 27 with Siri AI! and Liquid Glass refinements
    Apple releases its yearly cluster of operating system updates today, with the two most prominent of course being macOS and iOS/iPadOS. These new versions focus heavily on Apples AI! stuff, but there are a few actual improvements and changes to the actual operating systems as well. Across both iOS and macOS, users now have a slider to affect how transparent or opaque the “Liquid Glass” design is across the operating system. And on the macOS side especially, Apple has made numerous small design tweaks to address user feedback, which has been accumulating since Liquid Glass was introduced. There’s nothing radically new in terms of design here, but this is a much-needed polish pass. Across all the releases, but in particular macOS and also iOS, there are a bunch of quality-of-life or performance improvements. For example, macOS now supports HDR for all system UI elements and gets more robust support for a wider range of display modes for external monitors. ↫ Samuel Axon at Ars Technica If youre not into AI!, theres not a lot of meat on these bones, but at least you can turn the AI! nonsense off through a switch buried deep in the settings applications of Apples operating systems (which will probably be flicked back on whenever the next update comes).


  • Switching to GNU Guix: a beginners perspective
    Want to run something a little more exotic on your server? How about GNU Guix? It has been a month since migrating my home server to GNU Guix. Managing OS state declaratively through Git has eliminated configuration drift, and Guile Scheme provides a cohesive environment that complements Emacs. While adapting to a smaller package ecosystem and managing substitute timing requires occasional adjustments, the stability, reproducibility, and container isolation make it a dependable foundation. ↫ Wai Hon Im definitely noticing an increase in interest in Guix lately.


  • The BeBox: one of the most beautifully overbuilt computers of the 1990s
    Late 2000. There is a grey and blue tower PC on my dorm-room desk like nothing anybody who walks into the room has ever seen. The Be logo on the front, a 3.5″ floppy peeking out the bottom of the drive bays, and the vertical grille that hides two columns of green LEDs (blinkenlights) dancing with the CPU load.  This was a dual-PowerPC workstation running an operating system you didn’t see in the wild. I was studying computer science at the time and this was a fun piece of hardware. ↫ J.D. Hodges As a BeOS user in and around 2001 or so, the BeBox was the holy grail of the little community I was a part of. There were some people here and there in online circles who had one, but they were rare even when new, and by 2001, they had become rarer still. This rarity made them mysterious and exciting from almost from the day they were launched, like a small volume halo car few people will ever get to see, let alone experience, first-hand. Its 2026 now, and more and more of the small number of BeBoxen made must be succumbing to degradation and hardware failures. I hope everyone who has one takes good care of them, because these are some of the rarest, most coveted computers of all time. Ive still never seen one, and here in Arctic Europe I most likely never will. Still, I remain hopeful. One day.


  • Age verification exemptions for open source operating systems feel like Phyrric victories
    On the Windows side of the age verification question, Microsoft is obviously following trends among lawmakers the world over. To address this, Windows is introducing a new platform capability: the Windows Age API.  This API brings age awareness beyond the operating system by making it available across the entire Windows ecosystem so that apps and services can deliver age-appropriate experiences using the same trusted foundation. By making age awareness available as a platform capability, Windows helps developers build safeguards into experiences from the start rather than placing the burden on children and families to manage protections app by app.` ↫ Rob Mauceri at the Windows Blogs Meanwhile, on the Linux side of things, theres been some cheering as at least California passed amendments to its age verification law to exempt open source operating systems. These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope. ↫ Luke James at Toms Hardware I think this is not at all the good news that many make it out to be. Exempting Linux, BSD, and other open source operating systems from age verification obligations may seem like a good thing at first glance, but in reality, I think services and applications will simply choose to not work at all on platforms that do not implement age verification. The fear of legal ramifications, especially when it involves children, will be enough for existing and future popular services and applications to exclusively work on platforms that implement age verification  whether those fears are founded or not. In fact, Im fairly sure a company like Microsoft, which has actually been feeling the squeeze from the Linux side recently  even if it is modestly so  is quite happy to see open source operating systems excluded from these obligations. Google, too, is probably none too unhappy to see any possible open source mobile operating system competitors not implement age verification. The fear of missing out is real, and most people are not as invested in fighting big tech and government surveillance as the average OSNews reader is going to be. If using Linux means not being able to play the latest hit games or use that new successful service, people will choose to stick with Windows or macOS. Let me be very clear that I do not support these age verification laws in any way, shape, or form, and I definitely do not want the open source world to embrace age verification. What Im worried about is that the open source world will cheer on these exceptions and consider the battle won, when in reality, they feel more like Pyrrhic victories. Age verification laws must be fought and destroyed at ballot boxes the world over, because otherwise I fear they will become just another tool in big techs toolbox, exemptions or not.


  • The new Apple Watch is always recording and transcribing everything it hears
    Do tech companies ever stop to think about the misery they unleash on people’s lives? The Apple Watch Series 12 uses “Audio Intelligence” that, as well as secretly taking notes, also has a Live Rewind feature that can replay the last 15 seconds of recently detected audio and view a text transcript. ↫ Matt Growcoot at PetaPixel Another win for us Europeans: this dystopian nightmare will not be available in the EU.


  • Solaris turnstiles
    Although Solaris is now mostly defunct, its influence remains substantial; technologies pioneered by Solaris can still be found across a wide range of software A lot of Solaris inventions have been described and talked about ad nauseam (such as the Slab Allocator), but one I rarely see discussed is its use of turnstiles. Despite being relatively obscure, the idea has quietly spread far beyond Solaris. Variations of it can now be found in major operating systems, web browsers, and language runtimes. In fact, you’re probably using several implementations of the same basic concept right now! ↫ Loïc Grégoire Im not going to pretend to understand all of this, but I know you people do, and many of you will definitely find this interesting to read. Also note that Grégoire develops their own operating system kernel called zag.


  • Lotus Notes and the dangers of starting from scratch
    Lotus Notes was the future of communications, a decade before laptops had WiFi. Yet of all things, it wasn’t even an email app. It was a notes app, a collaboration tool, an all-things-to-all-people software that let you build apps in the way Access and Airtable later would. That, and the notes could be used for email. Love it or hate it (and there were plenty on both sides of the fence), what you couldn’t do was ignore it. This email-and-everything-else platform showed what the future of digital communications would become — and provoked, as email itself was always doomed to provoke, equal measures of awe and exasperation. ↫ Matthew Guay I have no experience with Lotus Notes, but I do have some vague memories of the software being used at my parents employers back in the late 90s. Note that Notes still exists and is in active development as HCL Domino (server) and Notes (the client). If you really want to, you can still run your company of office on Notes. I wonder how many actually still do.


  • FreeBSD working on new service manager
    The BSD news will continue until morale improves. I missed this two months ago, but Baptiste Daroussin, creator of pkg and poudriere, is working on a service manager for FreeBSD called rcd. rcd(8) is a service manager daemon called by init(8) (in place of /etc/rc). It reads service definitions from UCL unit files (/etc/rcd.d/*.ucl), builds a dependency DAG, and starts services in parallel. After boot completes, it forks to background and stays running as a supervision daemon (automatically restarting failed services and accepting control commands via a UNIX socket). ↫ Baptiste Daroussin Its fully backwards compatible, and works on any existing FreeBSD system without having to make any modifications to rc.d scripts or configuration files. In fact, you can install it on a running system, make zero changes to your files, and reboot to use it, which is quite impressive. The most immediate benefit is, of course, faster boot times, but youll also get several other benefits already found on similar systems like Solaris smf. Theres a migration path in place, with a hard promise to maintain compatibility with rc.d scripts for as long as needed. This gives maintainers as much time as they need to convert to rcds own unit files.


  • FreeBSD 14.5 released
    Yesterday we had the final maintenance release for the NetBSD 9.x series, and today we have FreeBSD 14.5 entering the scene. Since this release is occurring late in a legacy stable branch, there are few new features; rather, the focus is primarily on maintenance. As such, changes since 14.4-RELEASE consist mostly of bug fixes, driver updates, and new versions of externally-maintained software. ↫ FreeBSD 14.5 release announcement The adventurous among us are already on the 15.x branch, but those of us running mission-critical systems are most likely still rocking 14.x, and for you, this is a must.


  • Antiquated HTML snippets and artefacts
    With ever-changing devices, browsers, operating systems, form factors, specifications, personal preferences, tooling, and corporate interests, the web is in a constant state of flux. As a result, so is the HTML we write. For every line of the HTML specification itself that has changed since the language’s inception, there are many more bits of HTML that have seen what I’ll call ‘environmental’ changes. Adaptations to differing browsers, extensions, integrations, and systems which we find HTML existing in. This article doesn’t cover once-specced but now obsolete bits of HTML but instead looks at all the snippets that have wormed their way into websites as result of, or in combat against, third-party integrations, browser competition, vendor extensions, and platform-specific hacks. The bits of HTML that were included for reasons, and which have been forgotten for present irrelevance. The snippets that live on only in the markup of sites from bygone eras and in the minds of those who fought during the browser wars. ↫ Declan Chidlow I dont do any HTML or website development, and even I clearly recognise quite a few of these. Especially the countless relics of the large technology companies trying to worm their way into the various web standards of decades ago serve as a stark reminder of how many times they tried and failed  which should tell you something about all the times they tried and succeeded.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)


  • Advanced Video Coding Still Under Patent
    Brazilian patent BRPI0109962B1 has expired, which means that DivX and Xvid are no longer problematic for Linux, but it doesn’t mean that video is all of a sudden fully unleashed.









  • CachyOS Gets an Update
    CachyOS August 2026 release is now available with the latest version of KDE, some new features, and plenty of improvements.


Page last modified on November 17, 2022, at 06:39 PM