Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LWN.net

  • [$] Fedora grapples with change
    The Fedora Project is known for,among other things, having a well-defined set of processes for just abouteverything. It has extensive packagingguidelines that deal with the complexities of creating RPMs to installsoftware, as well as processes for managing the legal questions thatarise around shipping software. Fedora also has a well-defined changeprocess for dealing with self-contained technical changes as well as majorchanges to the distribution, and other issues as they arise. At the moment,though, the project seems to be experiencing a sort of midlife crisis as itre-examines several of its change processes at once to determine if they arestill effective.


  • Catanzaro: Some changes to GNOME security tracking
    Michael Catanzaro, who has been managing GNOME security issue tracking sinceNovember 2020, has written a blog post that details some changes in how he willbe managing GNOME vulnerability reports from now on due to an increase inAI-generated security reports. He will be switching from a 90-day deadline fordisclosures to 30 days for issues reported on August 1, or later. "Theshorter deadline would probably work better for GNOME even if not for theincrease in AI-generated issue reports."

    He also has indicated that he will be stepping away from the task of managingsecurity issue tracking entirely by December 1, 2026, which means that therewill be a gap to fill:

    Currently nobody else is tracking GNOME security issues. If you are anexperienced GNOME community member and you are interested in taking over thiswork, let me know and I will help you get started. (Security tracking is not agood task for newcomers.)

    This may also be an opportunity to improve our tracking infrastructure. I usea wikipage, but this is fairly primitive and requires considerable manualupkeep. It's easy to forget to update the page when an issue report is closed,for example. Ideally, we would replace the wiki with a proper web app thatdynamically updates based on the actual state of the issue.


  • [$] Merging famfs?
    The famfs filesystem, which is meant to provide shared access to hugememory-resident files on CXL and otherdevices, returned tothe Linux Storage,Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) in 2026.It was first discussed at LSFMM+BPF 2024 and a new implementation was described at the 2025gathering, but it still has not made its way into the kernel; LWN lookedat a discussion about merging famfs back in April 2026.


  • Security updates for Monday
    Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), Mageia (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-HTML-Parser, perl-Mojolicious, perl-String-Util, python-pydantic-settings, rsync, and upower), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind, cockpit, cockpit-image-builder, coreutils, delve, dnsmasq, dovecot, expat, fence-agents, flatpak, frr, gdk-pixbuf2, giflib, glib2, go-fdo-client and go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd, jq, kernel, keylime, krb5, libcap, libexif, libpng, libsndfile, libsolv, libsoup3, libtasn1, libtiff, libxslt, libyang, mariadb10.11, mod_http2, mod_md, opencryptoki, PackageKit, perl-Archive-Tar, perl-IO-Compress, poppler, postfix, postgresql-jdbc, python-urllib3, python3.14, python3.14-pip, python3.14-urllib3, qt6-qtdeclarative, rrdtool, rsync, ruby, ruby4.0, samba, skopeo, thunderbird, valkey, wireshark, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), and SUSE (blender, chromium, containerized-data-importer1, cyrus-imapd, go1.26-openssl, gomuks, grafana, gstreamer-plugins-bad, kbfs, kubevirt1.8-container-disk, libxml2, lux, mariadb-connector-c, nginx, opam, openssl-3, oras, perl-DBI, php-composer2, python-django-haystack, python-paramiko, python-weasyprint, python311, python313-Pillow, python315, shibboleth-sp, system-user-zabbix, and wget).


  • Kernel prepatch 7.2-rc4
    The 7.2-rc4 kernel prepatch is out fortesting. Linus said: "This whole week I had the feeling that peoplewere starting to go on summer vacation, but running the numbers shows thatI must have been wrong - it all looks pretty normal."


  • "Half a Second" — a book on the XZ backdoor
    Adrian Mastronardi has released a book called Half a Second; it is adetailed look into the XZ backdoor attemptof 2024. The book is freely available under a (non-free) noncommercial,no-derivatives CC license.
    Half a Second tells that story as one continuous narrative: the burned-out volunteer who maintained the code alone and was patiently, expertly manipulated into giving it up; the engineer whose half-second of curiosity caught the attack through a chain of luck and hard-won instinct; and the operator who built it, who has never been identified and, this book argues, may never be.



  • Building an Arch Linux aarch64 port for Holo Core (Collabora blog)
    Collabora has published a blogpost about its work with Valve on Holo Core, which is a port of Arch Linux toaarch64 to be used as the the operating system on Valve's64-bit Arm Steam Frame gaming system. Collabora has released thesources,binarypackages, and a container image for aarch64 devices. The postdescribes some of the challenges in porting Arch Linux to a newarchitecture, and what remains to be done:

    Whilst the infrastructure developed to this point is capable ofbuilding from first principles up until a point-in-time snapshot, thenext step is to build this into a system which can track Arch Linux asit is developed. This work will serve as the basis of acontinuously-operating CI system capable of shadowing Arch Linuxitself. We will work with the upstream Arch Linux project to help Archwith their efforts to port the distribution to aarch64 architectureand work towards automated repeatable builds.

    The post also includes instructions on how to create and test anaarch64 build container on an x86_64 host, for users who would like tofollow along at home but lack a 64-bit Arm device.



  • [$] Securing BPF LSMs against tampering
    Since 2020, BPF programs have been able toact as Linux security modules(LSMs). Several projects, including systemd, have been working to usethat capability to provide more security to users. Christian Braunerspoke at the 2026Linux Storage, Filesystem, Memory-Management, and BPF Summitabout some of the limitations of using BPF in this way, and the changes hewould like to see for systemd's use. In particular, he would like a way to makesure that BPF programs cannot be removed or have their private data tampered with.


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), Fedora (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), Oracle (cifs-utils, gegl, gimp, git-lfs, go-toolset:ol8, hplip, kernel, libreoffice, maven:3.9, perl-XML-LibXML, python3, python3.12, python3.9, and uek-kernel), Red Hat (kernel, kernel-rt, and podman), Slackware (netatalk), SUSE (agama, aws-nitro-enclaves-binaryblobs-upstream, gimp, gpsd, grafana, hostapd, ImageMagick, jackson-databind, kernel, libssh2_org, nm-configurator, opennlp, perl-Mojolicious, python-Pillow, python-python-engineio, python-python-socketio, and tomcat11), and Ubuntu (ntfs-3g, python-authlib, ruby2.3, tar, and ubuntu-advantage-tools).



LXer Linux News

  • Setup non-flat btrfs architecture on Garuda Linux (VENV)
    Garuda Linux advantages which are are provided by btrfs.Automated Snapshots : Creates system snapshots automatically before every update. Uses grub-btrfs for this setup. Allows booting into old snapshots from boot menu. Fixes broken updates easily without using live USBs. . . . .



  • 9to5Linux Weekly Roundup: July 19th, 2026
    The 301st installment of the 9to5Linux Weekly Roundup is here for the week ending July 19th, 2026, keeping you updated on the most important developments in the Linux world.



  • M5Stack broadens embedded lineup with wireless, industrial, and handheld devices
    M5Stack has introduced three compact products addressing wireless IoT development, industrial automation, and portable embedded control. The lineup includes the Stamp-C5 module with dual-band Wi-Fi 6 and IEEE 802.15.4 connectivity, the isolated StamPLC IO expansion module, and the lower-cost StickC Plus SE handheld development kit. The Stamp-C5 is based on Espressif’s ESP32-C5HF4 and measures 17.6 […]







Linux Insider"LinuxInsider"












Slashdot

  • China's New AI Model Halts New Subscriptions As Demand Swamps Capacity
    Moonshot AI has temporarily paused new subscriptions for its Kimi K3 model after demand surged beyond the company's current capacity within days of the launch. The open-source Chinese AI model, described as one of the largest of its kind at 2.8 trillion parameters, has rattled U.S. rivals by beating Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol in front-end coding tests. The Associated Press reports: "Kimi K3 has received far more love than we expected," Moonshot AI, which is Beijing-based, wrote in a X post late on Sunday. "Over the past 48 hours, demand has pushed close to the limits of our current capacity." Moonshot said that it's prioritizing existing subscribers and would be temporarily pausing new ones. "We're adding capacity as fast as we can and will reopen new subscription spots in batches," it added. The AI startup also posted a similar message on Chinese social media. "New model releases generally trigger massive interest, which can strain existing compute infrastructure," said Lian Jye Su, a chief analyst at the technology research and advisory group Omdia. "This does show Moonshot AI does not have sufficient compute chips to serve the current surge in demand." Su said that the key reason was more likely due to Moonshot not fully anticipating the surge in K3's popularity. K3 is "very demanding" in terms of compute requirements, he said, making compute allocation challenging and expensive.


    Read more of this story at Slashdot.


  • Head of US Safety Agency Resigns
    Chris Fall has resigned as director of the U.S. Center for AI Standards and Innovation just three months after being appointed to lead the Commerce Department's federal AI testing institute. Arvind Raman, who oversees the Commerce office responsible for the institute, will serve temporarily in the role. "The Commerce Department did not provide a reason for Fall's departure," reports Reuters. From the report: Fall's exit marks the latest change in direction for Trump's approach to AI. The president upon returning to office in 2025 said the federal government should take a hands-off approach to the tech sector. He has since taken a more active role in monitoring the technology, though his public statements and policies appear to change week by week. The institute is responsible for working with leading AI labs such as Anthropic, Google's DeepMind and OpenAI to test their unreleased models for vulnerabilities. The group is staffed by scientists and engineers, who are focused on calculating the "demonstrable risks" posed by advanced AI models, according to the institute's website. They want to limit opportunities for U.S. adversaries to use AI to develop chemical or biological weapons, or corrupt the data used to train American AI models.


    Read more of this story at Slashdot.


  • AliExpress Hit With Record $625 Million Fine After Failing To Make EU-Ordered Fixes
    The European Commission has fined AliExpress more than $625 million, the largest penalty yet under the Digital Services Act, after finding that the marketplace failed to "diligently assess and mitigate risks relating to the sale of illegal, unsafe, or counterfeit products on its e-commerce platform." EU officials said flagged products repeatedly reappeared, sellers could evade safeguards, and AliExpress's recommendation and ad systems helped amplify dangerous goods. Ars Technica reports: For shady sellers, the risks of detection appeared low. The e-commerce site's mandatory brand authorization system was also ineffective and understaffed, the EC found, and AliExpress did not penalize traders for selling illegal products as its policy claims it would. Making things worse, AliExpress "inadequately assessed how its recommender and advertising systems exacerbate the spread of illegal products," the EC said. So rather than remove illegal products, AliExpress was recommending them to consumers and helping to maximize exposure. Talking to the press, the European Union's tech chief, Henna Virkkunen, noted that one in five Europeans shop monthly at retail sites like AliExpress, Temu, and Shein. AliExpress also relied on a single quantitative metric to gauge how effectively its systems were working to weed out illegal products. And that metric did not properly measure the extent of the harm. EC testing found that "a high volume of illegal products" -- including unsafe toys and dangerous cosmetics -- "continued to circulate despite AliExpress' moderation efforts." In June 2025, AliExpress was ordered to bring its platform into compliance with the DSA but failed to make the necessary changes, the EC said. The fine was calculated to be proportionate to the nature of the violations, which the EC considered "particularly serious infringements," and to penalize AliExpress's delayed interventions to mitigate flagged risks. [...] AliExpress told Ars it was "surprised" by the "disproportionate" fine. AliExpress said it plans to appeal the decision, claiming the EC ignored its "sound risk management framework and the significant, proactive enhancements we have made." The massive online retailer noted that its EU market is substantially smaller than its China market and said that it invests "substantial resources in risk assessment and mitigation, product safety and consumer protection" and "has been and continues to be committed to meeting our obligations to consumers."


    Read more of this story at Slashdot.


  • LG Monitors Silently Install Adware-Like App On Windows PCs
    VideoCardz reports that connecting certain LG monitors to Windows PCs can trigger Windows Update to automatically install the LG Monitor App Installer, which runs at startup and repeatedly displays McAfee trial promotions. From the report: Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to approve the download. Gamers Nexus tested the application across 32 consecutive system boots. It displayed a McAfee promotion during 31 of them. On the remaining boot, it promoted one of LG's own monitor utilities. The McAfee popup offered a 30-day trial that would convert into a paid subscription. The behavior does not appear to be limited to newly purchased displays. Gamers Nexus also received the popup on an LG UltraFine 32UN880-B purchased three years earlier. User complaints about LG Monitor App Installer date back to at least 2024, although the recent increase in reports suggests that more models may now be receiving it.


    Read more of this story at Slashdot.


  • Hacker Wipes Romania's Entire Land Registry Database
    A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored," reports Cybernews. "However, Romanian officials have managed to at least restore the ANCPI's website and post a message saying they were rebuilding the agency's entire network from scratch. It appears that the agency has an offline copy of the wiped data." From the report: First, the hacker breached Romania's cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: "[RO] Thy arss shall be spanked, Romania! [ANCPI]." "In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program," the announcement continued. "The official government website announced a shutdown of IT systems due to 'technical problems,' but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure." Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution's systems. And since the extortion didn't work, the hacker -- who seems to have entered the database using valid credentials -- deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data.


    Read more of this story at Slashdot.


  • LSU Physicists Create First Room-Temperature Quantum Material
    Researchers at Louisiana State University have created a room-temperature quantum material made from a thin gold film on glass, patterned with microscopic slits that act like artificial atoms. "We call this robust transport. These quantum states carry information," says physicist Omar Magana-Loaiza. "Our crystal can distinguish them and move them from one point to another in a robust way without requiring cryogenic cooling. That's what opens the door to practical quantum technologies." ScienceAlert reports: Crucial to the new material's room-temperature operation is the way it shifts the focus from electrons and atoms to photons (particles of light). This overcomes the usual atomic-level disruption that heat brings with it. The material is what's known as a plasmonic metacrystal: 'Plasmonic' because the light traveling over it makes ripples of electrons known as plasmons, and 'metacrystal' because it's an artificially created crystal. The tiny slit patterns etched into the material act as artificial atoms (meta-atoms), which dictate how different photon groups pass through (the quantum behavior). "By engineering the distribution of meta-atoms in the plasmonic metacrystal, we can systematically dictate which quantum statistics are allowed to pass through the structure," says physicist Riley Dawkins. "So, our crystal essentially acts as a statistical filter on quantum states." That means as light enters the chip and travels across the gold surface, it's manipulated by the meta-atoms -- and by tweaking the size, shape, and spacing of the slits, different end results can be produced at the quantum level. In practice, this means that certain quantum states of light can be transported with less disruption. The findings have been published in the journal Nature.


    Read more of this story at Slashdot.


  • LibreOffice Once Again Slams Microsoft For Using 'Lock-In' With Office Files
    An anonymous reader quotes a report from XDA Developers: One of the founding members of The Document Foundation and handler of LibreOffice's PR and media relations, Italo Vignoli, took to the LibreOffice blog to call out Microsoft's practices with its Office application. The last time we saw Vignoli take to the stage, we saw him accusing Euro-Office of being just as bad as Microsoft with its practices. Vignoli's new post focuses entirely on Microsoft's strategy. He says that "the dominant format for office documents" is owned by Microsoft Office, particularly the DOCX, XLSX, and PPTX formats. The problem with these formats, Vignoli states, is that they "belong to Microsoft, are controlled by Microsoft and serve Microsoft's interest." This makes it difficult for other formats to take hold. Vignoli explains his point by stating that open document formats don't hide anything. People developing their own apps can use the format to both read and write the document format with perfection. Meanwhile, proprietary formats such as Microsoft's "contain undocumented features, private extensions or behaviors" that developers can't fully adapt to. That means that a presentation that looks great in the source software comes out strange when rebuilt in a third-party app. This, Vignoli says, is a huge issue [...]. Vignoli claims this creates a huge issue with document preservation. If a Word document was saved in one version of Office, will it still be readable in 20 years? Microsoft has added legacy support to its software before, but the company can one day decide that it's not worth the effort anymore and cut it out. When that happens, you have old documents that are either jumbled or unable to be opened at all.


    Read more of this story at Slashdot.


  • Hollywood Sci-fi Studio Lot Now Pitched As Site To Make Real Space-age Weapons
    James Cameron filmed his Avatar sequels there. Marvel filmed Thor, Iron Man 2, and The Avengers. Manhattan Beach Studios in Los Angeles even handled Star Wars' series like Obi-Wan Kenobi and The Mandalorian, which Bloomberg points out is about "a heavily armed bounty hunter in a galaxy far, far away." "Now lenders who are selling the property's $240 million mortgage are promoting the site to potential buyers as a hub for making real space-age weapons.""The project is strategically positioned within Los Angeles' prominent aerospace and innovation corridor, anchored by industry leaders such as Northrop Grumman, Raytheon Technologies and SpaceX," said Cushman & Wakefield, which has the listing. "A supply-demand imbalance has emerged, driven by the growing concentration of advanced manufacturing users and a limited supply of viable space," the real estate brokerage said in a presentation. Bids are due July 28. The marketing pitch reflects Southern California's shifting economic landscape as the movie business slumps and weapons makers seek to cash in on surging Pentagon spending... The defense boom is spurring the revival of a regional industry that once churned out World War II bombers, supersonic Cold War planes and Apollo command and service modules before shrinking after the fall of the Soviet Union... In the Los Angeles area, aerospace and defense-related tenants have accounted for 11% of new industrial real estate leases since the start of 2025, up from an annual average 2% during the preceding decade, according to a report this month by brokerage Newmark Group Inc. Los Angeles "has always gone through transformations," Stephen Cheung, president of the Los Angeles County Economic Development Corp., told Bloomberg. "This is one of those."


    Read more of this story at Slashdot.


  • New Free Speech Concern: When AI Chatbots Won't Criticize Leaders from Repressive Regimes
    Ask Claude to make a pamphlet critical of China's leader, Thailand's king, or Saudi Arabia's crown prince — and it will decline, reports the Associated Press. That's "a key finding from a Meta Oversight Board study released Thursday," their article points out: AI systems are more than twice as likely to refuse to product critical material if it's about a restrictive world leader or government. And it raises concerns that the LLMs powering chatbots "could be regurgitating and spreading government influence over online speech."The study picked 10 commercial large language models by top tech companies — including Meta, Anthropic and OpenAI — and asked the AI systems to make critical pamphlets, write limericks, give reasons if someone should join protests, and more.... "In aggregate, models responding to requests from an Australia-based user were much more likely to generate political criticism of authorities" in places such as Chile, Japan, Taiwan, the U.K. and the U.S. "compared to where criticism of authorities is legally restricted and penalized," such as in Cambodia, China, Saudi Arabia, Thailand and Turkey, the report said. The study indicates that AI models are reflecting speech restrictions beyond the countries where they apply — likely not helping a potential demonstrator in Brisbane, for example, create protest materials to speak out against events in China or Saudi Arabia, the report said. "Such impacts, wherever they originate, have the practical effect of extending the long arm of restrictive governments across borders to limit speech in free countries," the report said. The board said it could not determine the causes for the responses but suggested that models could have absorbed latent biases in data used to train the systems and companies might have weighed the risks and liabilities.


    Read more of this story at Slashdot.


  • Rust Will Help Linux Succeed and Makes Coding Fun, Says Greg Kroah-Hartman
    ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed." Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust. Git is moving toward Rust. Lots of projects are starting to move toward Rust." He didn't always feel that way. Kroah-Hartman added, "A number of years ago, when a friend of mine said, 'Ah, you got to try this new language. It's called Rust.' I was like, 'What? No, C is great.' His friend continued, "'No, no, no! It makes programming fun again.' I'm like, 'Nah, programming is fun in C.' He was right. I should have done it then. Rust is actually fun. It makes programming fun. It takes a lot of stuff away from having to worry about the compiler, which can fix a lot of your problems for you, and it makes code a little bit better." So, Kroah-Hartman has moved from being a Rust skeptic to one of its strongest champions inside the kernel. He now regards Rust as a permanent part of Linux, not an experiment. His case is straightforward: Rust's ownership and type system can eliminate most of the "stupid little tiny things" that dominate kernel Common Vulnerabilities and Exposures (CVEs), while making life easier for overworked maintainers. "Rust," in short, "makes my life so much easier...." In India, he said Linux sees "about 13 CVEs a day" and has been running at "almost nine changes an hour" for a decade or more. Most of those vulnerabilities, he argued, are not exotic attacks but simple C mistakes — unchecked pointers, forgotten unlocks, and sloppy cleanup paths: "This is what we're fixing 13 times a day. Small, trivial, little bugs like this all the time.... I've seen every CVE the kernel has done in the past 25 years. I think 80% would be gone, just because they would be caught by Rust." The remaining 20% are the logic bugs he'd prefer to focus on...." Moreover, Rust is becoming the default for new work in key subsystems. "New drivers for some subsystems are only going to be accepted in Rust...." he said. Binder, the Android IPC mechanism at the heart of billions of devices, now has parallel C and Rust implementations in the kernel. The C version "will go away soon," leaving the Rust version "as the bedrock of all Android devices going forward."


    Read more of this story at Slashdot.


www.theregister.com - Articles












Linux.com




  • From DHCP to SZTP – The Trust Revolution
    By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]

    The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.








Phoronix


  • Intel Expanding Memory Options For Current Xeon 6 / Xeon 6+ Servers
    With Intel's next-generation Xeon Diamond Rapids processors not slated to launch until next year and with AMD EPYC Venice being right around the corner, Intel announced today that with upcoming BIOS updates they will be expanding the range of RDIMM and MRDIMM memory support for current-generation Xeon 6 and Xeon 6+ processors...


  • AMD Talks Up The Great Opportunities Of SPIR-V IR With ROCm
    While AMD ROCm 7.14 released last week as the first production release built off TheRock, there is already more to look forward to moving into the future with the AMD ROCm stack... In particular, SPIR-V with ROCm becoming a reality for unified binaries that can work across graphics architectures/targets, better portability across GPU hardware, and other improvements to the experience in targeting a unified IR...




  • Linux Patches Introduce "KNOD" For In-Kernel Network Offloading Directly To AMD GPUs
    Some extremely cool patches were posted to the Linux kernel mailing list on Sunday. The patches for "KNOD" allow for in-kernel network offloading to GPUs with an initial focus on AMD GPU support. What makes this all the more nifty is that it doesn't depend upon any user-space libraries like AMD ROCm but is all handled in-kernel with driving the GPU directly...



  • openSUSE Seeking Additional Corporate Sponsors
    While openSUSE is closely aligned with SUSE as a company, they aren't the exclusive sponsor of this free and open-source Linux distribution with its rolling-release Tumbleweed and Leap stable releases. AMD has been a longtime major supporter of openSUSE and the Fastly content delivery company has been another platinum sponsor too besides SUSE. There are also various other lower-tier sponsors while today the openSUSE Project put out a call for further corporate sponsorship...


  • AMD Posts AVX10_V2_AUX ISA Support Patches For GCC Compiler
    Earlier this month Intel compiler engineers posted initial GCC compiler patches for the AI Compute Extensions "ACE" that was born out of the x86 Ecosystem Advisory Group to augment AVX and scalar code with new capabilities for AI/ML workloads. Now as part of that an AMD compiler engineer posted patches over the weekend for AVX10_V2_AUX ISA support...




Engadget"Engadget - Technology News & Expert Reviews"











OSnews

  • OpenBSD tests WPA3 support
    The NLnet Foundations NGI0 Commons Fund supported an effort to add WPA3 support to OpenBSD, and the works payed off. All drivers which support PMF can use WPA3, which are: iwm, iwx, and qwx. So far, I have tested this patch on iwx AX200 only. I will roll out this patch to more of my devices now. Help with testing is welcome. There are both userland and kernel changes involved. ↫ Stefan Sperling Only the second implementation of WPA3 will be supported, which requires some explanation: WPA3 has a complicated history. There are two versions of WPA3. The initially standardized version suffered from side-channel leaks found by Mathy Vanhoef and dubbed Dragonblood . A revised and fixed version has been standardized and is mandatory in the 6 GHz band as of Wifi 6e (11ax) and mandatory on all bands as of Wifi 7 (11be). ↫ Stefan Sperling Obviously, WPA3 is a very welcome addition to OpenBSD.


  • DOSBox ported to OpenVMS for Alpha
    Speaking of OpenVMS and Alpha  and we like speaking about OpenVMS and Alpha, dont we?  theres now a port of DOSBox that runs on the Alpha version venerable operating system. Astr0baby has published both binaries and source code for the port, as well as a lovely set of screenshots to show it off working.


  • LG monitors silently install software through Windows Update without user consent
    Well, this is new  but not at all unexpected considering the state of Windows and the wider technology industry. When you connect certain LG monitors to a Windows machine, Windows Update will pull in a bunch of adware promoting antivirus trash. Of course, all done without any consent, because Silicon Valley inherently does not understand nor respect consent. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to approve the download. Gamers Nexus tested the application across 32 consecutive system boots. It displayed a McAfee promotion during 31 of them. On the remaining boot, it promoted one of LG’s own monitor utilities. The McAfee popup offered a 30-day trial that would convert into a paid subscription. ↫ WhyCry at VideoCardz Dont use Windows.


  • New Intel Itanium emulator boots Itanium version of Windows XP and 2003
    It was only a few weeks ago that we got a massively improved Alpha emulator, capable of running VMS, Windows 2000, and Tru64, including X11 support and a variety of other exciting features. Today, weve got another major emulation milestone. The emulation space is going crazy, after my previous post on Windows booting on DEC Alpha es40 emulator, there is now another huge breakthrough in the emulation of other non-x86 CPU emulation. Yufeng Gao with help from gdwnldsKSC (the man behind the updated es40-fork) has released version 0.1 of his Intel Itanium (IA-64) emulator that boots the Itanium version of Windows Server 2003 and Windows XP 64-bit. No OpenVMS or HP-UX yet and Linux/BSD also dont boot. But Windows is amazing already. ↫ Remy van Elst Much like Alpha hardware, Itanium hardware is quite hard to come by  especially Itanium workstations are a nightmare to find; I think Ive only ever seen one or two Itanium workstation come up for sale on eBay in recent years, and their rarity obviously commanded hefty prices. The sooner we are able to run Itanium version of operating systems comfortably in a virtualised environment the better. As long-time OSNews readers know, my heart beats for HP-UX, but the Itanium versions of Windows and VMS would be of more interest to most people, Im sure. Excellent news.


  • Follow the money, especially in open source
    Linus Torvalds, the creator of the Linux kernel and git, is employed by the Linux Foundation. This Foundation is a non-profit organisation dedicated to, as the name obviously implies, the promotion of Linux. The primary use of the funds it collects is to help fund the infrastructure and fellows, including Linus Torvalds, who help develop the Linux kernel!. The list of megacorporations donating most of the Foundations funds is long. The Linux Foundation has twelve platinum members, which donate $500000 per year, followed by twelve gold members, who donate $100000 per year. Below these two primary tiers lie the silver peasants, who each donate $5000-$25000 per year, based on number of employees. Looking at the list of twelve platinum members, I noticed something interesting. Of the twelve platinum companies, six are AI! companies or companies with massive investments in AI!: Google, Huawei, Facebook, Microsoft, Oracle, and IBM/Red Hat. Then theres Samsung Electronics, which is raking in stupendous amounts of money thanks to the AI! bubble. Additionally, one of the gold members is Anthropic, another major AI! company and makers of Claude!, the sloppiest of slopcoding tools. Many of these companies are unimaginably deep in the red when it comes to AI!, with very little indication theyre ever going to be able to recover any of it. The situation is particularly bad for Oracle and IBM/Red Hat. Oracles debt has been downgraded to one notch above junk status because of its AI! spending, while IBMs shares experienced the largest crash in its 115 year history only a few days ago. By the way, in the first half of 2025, AI-related capital expenditures contributed 1.1% to GDP growth, outpacing the U.S. consumer as an engine of expansion!. Fun fact: since most of The Netherlands is effectively a swamp, most of the countrys buildings are built on massive wooden or concrete poles (piles) hammered deep into the ground until they hit something more stable than mushy clay and wet sand. Otherwise, buildings in the country would simply sink into the ground. Every Dutch person who ever lived near a construction site has heard the rhythmic kathunk, kathunk, kathunk, all day long, as the massive piledriver machines spread their gospel. I guess something reminded me of this just now. Anyway, a large chunk of the funding the Linux Foundation, Linus Torvalds employer, receives is coming from increasingly desperate companies frantically trying to convince a populace deeply skeptical and often downright hostile towards AI! to spend money on AI! before the bubble bursts. For some reason, I thought this was interesting.


  • The Zilog Z80 has turned 50
    As of writing, the Zilog Z80 processor was officially launched 50 years ago, in July of 1976, less than 4 years after the last human had walked on the moon, decades closer to WWII than to the present day, roughly at a half way point between the Kennedy assassination and the fall of the Berlin wall, closer to the Korean war than to 9/11 which is itself an event that happened a quarter of a century ago. (Sorry…) The processor was extremely successful, being used in many 8 bit microcomputers, including early personal computers, home 8 hobby computers, as well as many embedded, industrial applications. Together with the 8080 8 8085 that it is binary compatible with, it contributed to creating a de facto hardware standard for 8 bit micros, allowing a de facto software standard of CP/M, and Microsoft BASIC. ↫ David Oberhollenzer The only device I actively remember using with a (sort-of) Z80 in it was the Game Boy, but most likely Ive used a ton more over the decades that I dont remember or simply was never ware of. I did a little surface-level digging, and there we are: the TI-83, one of Texas Instruments stupidly popular and eternally overpriced graphing calculators, release in 1996. I was part of the first wave of high school children in The Netherlands for whom a TI-83 graphing calculator was mandatory. During my high school years I used that thing extensively, for far more than just math class  I programmed applications for and on it, and played so many games on it. A friend and I even bought a communication cable so we could play competitive 1v1 Bomberman in class. Good times, made possible by the Z80.


  • OnePlus exits EU, US markets
    Rumours had been circulating for a while, but now its official: OnePlus is effectively retreating from the European and US markets. Today, our hearts are undoubtedly heavy and mixed with emotion. As part of the proactive global strategy adjustment, OnePlus has decided to conclude new product rollouts in Europe and North America. ↫ OnePlus statement Once OnePlus co-founder Carl Pei left the company (and founded Nothing), things have been feeling shaky for OnePlus, once the undisputed darling of the more technical part of the Android crowd. Their phones got more expensive, their minimalist, close-to-stock Android version got progressively worse, and they started lagging in updates, too. My OnePlus Watch 3, for instance, which was promised to get WearOS 6 at some point, but never got it  meanwhile, WearOS 7 has already been released. No, this news is not particularly surprising. Luckily, the company claims it will honour its warranty and update support obligations for existing products in Europe and the US, which is nice, but also something theyre legally obligated to do (at least in the EU). A snag here is that the only update path the company offers is to ColorOS, from its parent company Oppo, which many more traditional Android and OnePlus users certainly wont be happy about. Something is better than nothing, I suppose, and Ill reserve judgment until I see what ColorOS 17 will be like on my other OnePlus product, a OnePlus Pad 3. Its just one more victim of western markets (illegally) consolidating on Apple and Samsung (while a few Pixels rummaging in the margins).


  • GNOME OS team is working to alleviate some of the limitations of immutable, image-based Linux variants
    Theres a ton of interest in immutable, image-based versions of various Linux distributions, since they offer a number of benefits that make them a good fit for some users. Updates cant really go wrong, rollback is easy, application management through Flatpak is more in line with systems like Android and iOS  they may not be advantages sought by everyone, but they clearly are by some. Still, there are also a number of annoying limitations, most notably around testing nightly releases of Flatpaks, testing system components, and installing command-line tools. The team behind GNOME OS is addressing these issues. The first thing theyre working on in something theyve preliminarily call Test Center, which makes it much easier to install nightly releases of Flatpaks alongside their regular versions. This is something you can already do today, but the flow is cumbersome and not exactly user-friendly; with Test Center, developers will be able to share a direct link to install test releases. They intend to use this same Test Center for testing system components: Our idea here is to use the same “Test Center” app mentioned above for installing and managing experiments at the system level as well. Similar to Flatpak bundles generated in CI, we generate system extension images (sysext) for every merge request. You can install experiments from a sharing link, and they will apply as a sysext over your existing system. Because those images are non-destructive overlays, you can always go back to the original system. ↫ Jordan, Jonas, and Tobias The last and final issue is that of command-line tools, something Flatpak is simply not designed for. On this front, the GNOME OS team states they are working on a solution as well, but theyre not quite ready to go into much more detail at this point. Regardless, these are very welcome improvements.


  • Microsoft releases its weird 90s IRC client as open source
    Out of all the bloody things Microsoft could release as open source, they chose the worlds weirdest IRC client they shipped in the late 90s that nobody used or even remembered? What on earth is happening? Microsoft Comic Chat is a Microsoft-developed Internet Relay Chat (IRC) chat client released in 1996 that rendered conversations as automatically generated comic strips. Instead of plain text, users communicated through cartoon avatars with messages displayed in speech bubbles inside dynamically composed comic panels. The application used an expert system to determine character placement, gestures, facial expressions, balloon shape, and panel layout in real time. It shipped as part of Internet Explorer 3.0 and was later bundled with Windows 98 and MSN before being discontinued in the early 2000s. ↫ Comic Chats GitHub page Not only is the original source code now available on GitHub, theres also a modern, updated version that can make use of larger displays and higher resolutions. Theres a deliciously 90s website for it, too.


  • OpenBSD drops support for the loongson architecture
    OpenBSD parts ways with an architecture: OpenBSD will no longer be developed for loongson. The reasons are exactly what youd expect. The last compiler update unfortunately does not work on mips64el, with clang 22 built with clang 19 being apparently functional, but clang 22 rebuilt with the previous clang 22 hitting deterministic SIGSEGV on various files. I dont have the time and energy to try and debug this (which is likely an endianness problem, as octeon appears to run happily with clang 22), especially when it takes 10 days for clang to rebuild itself on these machines; and switching back to gcc 4 wont help much as modern software in ports will require a working C++b=11 compiler to build anyway. ↫ Miod Vallat If I got my facts right, this does not affect the newer LoongArch, which is an entirely different architecture that isnt supported by OpenBSD at all. Similarly, the other MIPS-based architecture OpenBSD supports, Octeon, remains supported and thus isnt affected either.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)




  • Hannah Montana Linux Is Back!
    Developer Noah Cagle decided the world needed the once obscure but beloved Linux distribution and gave it a decidedly pink refresh.




  • Kubuntu Focus Goes Ultra
    The Kubuntu Focus team has upped the performance ante of its M2 and Zr laptops with the latest, greatest CPUs from Intel.





Page last modified on November 17, 2022, at 06:39 PM