Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LWN.net

  • Hefty stable kernel updates for Friday
    Greg Kroah-Hartman has announced the release of the 7.1.5, 6.18.40, 6.12.97, 6.6.145, 6.1.178, 5.15.212, and 5.10.261 stable Linux kernels.

    This batch of kernels includes a hefty set of updates, possibly thethe largest ever. 7.1.5-rc1,for example, included more than 2,000 patches, 6.18.40-rc1included 1,611 patches, and so forth. Users are advised to upgrade.



  • De Vlieger: The Fedora 45 sausage factory
    Fedora contributor Simon de Vlieger has published a blogpost with a walkthrough of how the project turns source code andpackages into the final release that users install on their systems.

    It follows the a package from a packager's git push to a composedrelease: ISOs, cloud images, container images, and OSTreedeployments.

    The walkthrough describes how the Fedora 'sausage' is created as ofFedora 45, things change all the time; I hope to have time to updatethis document every cycle or every few cycles of Fedora releases sothere's both history and people can find up to date information.



  • [$] An update on netkit and the use of BPF in user space
    Daniel Borkmann led a session at the 2026Linux Filesystem, Memory-Management,and BPF Summit about the progress that has been made with netkit, the subsystemthat allows virtual machines (VMs) running on Linux to perform networking efficiently.When that did not fill the full time, he went on to discuss his idea forusing BPF to live-patch user-space applications. While netkit is makingprogress, and can now support zero-copy receipt of packets into a VM in anetwork namespace, the idea of using BPF for patching user-space programsremains entirely speculative.


  • Home Assistant Device Database public preview
    The Open HomeFoundation, which governs the Home Assistanthome-automation project, has announcedthe "public preview" of its DeviceDatabase:

    Providing a public, open way to browse the anonymous, aggregateddevice data we collect was always part of the plan, and this previewis our first step toward it.

    You can already use it to search and filter devices to seeaggregated community insights, starting with a deliberately focusedset of specifics, such as whether a device requires an internetconnection, and which protocols and integrations it works with. We'vekept that initial scope narrow on purpose, giving us a solidfoundation we can build on together with you, our community, as thedatabase grows.

    LWN looked at HomeAssistant in May 2025.



  • Security updates for Friday
    Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and socat), Oracle (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), Red Hat (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), Slackware (mozilla-thunderbird), SUSE (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and Ubuntu (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).



  • [$] An operations structure for swap devices
    One of the ideas raised at the 2026 LinuxStorage, Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) wasthe creation of anoperations structure for the swap subsystem. Like many parts of thekernel, the swap layer evolved over time, with pieces being added asneeded; the end result of this evolution is rarely what one would expecthad the subsystem been designed today. The interface between the swaplayer and the devices it uses is just one example. It appears that oneresult of the swap subsystem's evolution — the lack of an abstraction layerto interface with underlying storage — will soon be addressed, but in adifferent way than was initially envisioned.


  • Codeberg: Protecting our FLOSS commons from LLMs
    The Codeberg forge has adopted a pair of new policies, promising not to usehosted projects to train LLMs and, more controversially, banning thehosting of LLM-generated software. The site's blog describesand justifies these policies.
    Although often well intentioned, sharing the result of a prompt and calling it "libre software" does not make the world a better place. Codeberg is not and does not want to be a place to dump such generated single-use software that no one else will ever look at. We are a place for people to collaborate and improve software together. Within this context, the recent votes can be understood as a reconfirmation of those principles: As we want to center on human collaboration, we will not actively support or engage in the creation of LLMs and will not put our limited resources to use for storing single-use software that would pollute our FLOSS commons.


  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (acl, dogtag-pki, dovecot, glibc, go-toolset:rhel8, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd:2.4, javapackages-tools:201801, libtiff, mariadb-connector-c, perl-HTTP-Daemon, pki-deps:10.6, and sssd), Debian (bind9, chromium, firefox-esr, and pdns-recursor), Fedora (chromium, collectl, fractal, kernel, libssh, llvm, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, perl-DBI, perl-YAML-Syck, and srt), SUSE (7zip, GraphicsMagick, ImageMagick, multipath-tools, perl-YAML, python-sqlparse, python3-sqlparse, python313-bleach, and sssd), and Ubuntu (apache2, commons-beanutils, exim4, gawk, giflib, gst-plugins-good1.0, krb5, libapache-mod-jk, libarchive, libgphoto2, libhtml-parser-perl, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-ibm, linux-nvidia, linux-fips, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-ibm, linux-oracle, linux-ibm-5.15, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oem-6.17, linux-oracle-6.8, python-aiohttp, and tar).



LXer Linux News

  • Ubuntu Linux Looking To Get Rid Of /etc/debian_version Historical Artifact
    Ubuntu Linux has shipped /etc/debian_version that is carried over from upstream Debian and in turn just indicating the Debian Sid development version from which the packages are arrived. Besides it being inaccurate, /etc/os-release has been the long preferred standard for reading the OS release information. Thus finally Ubuntu developers are looking at dropping the /etc/debian_version file...



  • Fedora 45 Looks To Begin Phasing Out In-Kernel Crypto Userspace API
    Going along with the upstream Linux 7.2 kernel deprecation of AF_ALG and Linux 7.3 to further restrict this interface for letting user-space programs interact directly with the Linux kernel crypto API, Fedora 45 is looking to follow and help support this transition...





  • Cisco Antares Models Bring Local AI to Vulnerability Triage
    Cisco’s new Antares models help security teams narrow vulnerable code searches locally, but low benchmark scores expose important adoption limits.The post Cisco Antares Models Bring Local AI to Vulnerability Triage appeared first on TechRepublic.





Linux Insider"LinuxInsider"












Slashdot

  • Paramount Agrees to Postpone Warner Bros. Merger Until June 2027
    Paramount Skydance has agreed to postpone its $111 billion Warner Bros. Discovery merger until five days after an antitrust trial or June 1, 2027, whichever comes first. The agreement with a 12-state coalition led by California effectively shelves the deal for months while states argue it would reduce competition in cable and theatrical markets. Variety reports: Paramount had been keen to close the deal before Sept. 30, when it will begin to incur a $7-million-a-day "ticking fee" to be paid to Warner Bros. investors. The agreement is a tacit acknowledgement that that will not happen, barring a settlement with the states. Paramount previously sought a three-day hearing on the injunction motion in late August, hoping to win the judge's blessing to close the deal sometime in early September. But the states resisted that idea, saying they would need more time to take discovery and prepare for a full trial on the merits. The states were due to file their injunction motion on Thursday night, but held off as the two sides held discussions on a path forward. In a statement, the company said the agreement is a "significant win." "Today's agreement is a significant win because the result is exactly what we have sought from the outset: a direct path to a trial based on the evidence," a Paramount spokesperson said. "This is the fastest and clearest way to prove that this transaction is good for competition, good for consumers, and good for creators, a conclusion dozens of competition authorities around the world have already reached. Plaintiffs' market definitions bear no relationship to the realities of today's marketplace and cannot withstand scrutiny. We look forward to proving our case at trial." A hearing was scheduled for Aug. 3 in federal court in Oakland, at which point the two sides were expected to argue over the injunction motion. The two sides agreed to cancel that hearing. U.S. District Judge Araceli Martinez-Olguin approved the joint stipulation on Friday afternoon, about an hour after it was entered. The Writers Guild of America filed its own motion for an injunction earlier this week, which was also set to be heard on Aug. 3. That motion has been withdrawn, as Paramount has effectively conceded that it will not close the deal until a determination of the merits of the antitrust claims. The parties also agreed to submit a joint stipulation by July 31 on their respective positions on trial scheduling. The states previously proposed to hold the trial in April 2027.


    Read more of this story at Slashdot.


  • US Accuses American of Allegedly Wiping His Phone Using a 'Duress' Password During Border Search
    An anonymous reader quotes a report from TechCrunch: The U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports. This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data using a so-called "duress" password built into a phone's software. According to The Guardian, which covered the story earlier this week following the court's first hearing on Monday, Atlanta resident Samuel Tunick is fighting the charges. Tunick's attorneys said that it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year, and that any evidence -- including the alleged wiping of his phone -- should be thrown out. The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick's attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user's unlock passcode. Tunick's case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter. Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who works to protect at-risk people as the founder of security consultancy firm Granitt, told TechCrunch that they had not seen similar cases involving the use of duress passwords. "I have not seen this before, though I've discussed the potential scenario with activists and journalists over the years," said Sandvik. "I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it's better to not have that data on you when you cross certain borders." "With a little planning ahead of time, you can always download the data you need once you get to where you're going," said Sandvik.


    Read more of this story at Slashdot.


  • Roku Raises Prices of Streaming Devices By Up To 60%
    Roku has raised prices on several streaming devices, blaming memory and component shortages tied to the AI data-center boom. The Roku Ultra jumped from $100 to $150 and the basic Streaming Stick rose from $30 to $40. The Desk reports: In a phone call with The Desk on Friday, a Roku executive said the company made the tough decision to raise prices on its streaming hardware to address shortages in computer memory and other components caused by the artificial intelligence rush. [...] Still, the executive who spoke with The Desk on Friday said the company believes its hardware is still competitive against other streaming TV hardware because Roku devices are still priced aggressively compared to the Apple TV and other expensive streaming hardware, and the company remains focused on looking at ways to add value to its Roku platform before and after it enters a customer's home. "We are doing our best to have great deals like what we have going on right now," the executive said. "Roku is even upping the price for a bundle that includes a Streaming Stick Plus and a one-month subscription to Fox One," notes Ars Technica in a separate report. "As recently as July 20, Roku listed the bundle at $60 with a sale price of $25, according to the Internet Archive's Wayback Machine. Now, the bundle carries an $80 MSRP and $45 sale price."


    Read more of this story at Slashdot.


  • Nvidia, Microsoft, Meta Warn Against 'Premature Restrictions' of Open-Weight Models
    Nvidia, Microsoft, Meta, Palantir, and more than 20 other tech companies signed an open letter urging policymakers not to impose "premature restrictions" on open-weight AI models, warning that broad limits could "stifle competition or drive innovation overseas." CNBC reports: They wrote that open-weight models strengthen competition and ensure that the benefits of the technology are "broadly shared rather than concentrated in a few hands." "Relying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect," the letter said. "And concentrating advanced AI capabilities behind a small number of closed models compounds that risk." Elon Musk, who runs an AI business under his rocket company SpaceX, also applified the letter on social media, writing that it has his "full support" in a post on X. SpaceX did not officially sign the letter. Greg Brockman, OpenAI's president, said Thursday that the company believes in broad access, and that he has not been involved in any conversations with the Trump administration about potentially banning Chinese open-weight models in the U.S. "I think that, that fundamentally, AI and AI usage is something that is actually very important to democratize," Brockman told reporters during a briefing in New York City. "And so, for me, at a sort of deep level, I think that having more models, more usage, that is a good thing." OpenAI CEO Sam Altman addressed the letter in a post on X on Friday, writing that he wants the U.S. to win with both open-weight and proprietary models, and that he is "glad to see this." [...] In the letter on Friday, the U.S. tech companies said that concerns about unlawful distillation should be addressed through "targeted legal and commercial frameworks" instead of with "sweeping restrictions on techniques that play an important role in AI innovation." "Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector," the letter said. "This is essential for creating opportunities for innovation and prosperity across the country." The letter follows a separate appeal signed by nearly 200 Silicon Valley companies, including Proton and Y Combinator, warning that restricting U.S. access to Chinese open-weight AI models could cripple the next generation of American startups. "American leadership requires two things: world-leading American open-weight models and continued access for U.S. builders to open models already available worldwide," the startup founders wrote. Instead of broad prohibitions, they argue the government should adopt targeted safeguards. Of course, these signees "have an obvious economic stake in seeing open AI models flourish," notes TechCrunch. "Companies like Nvidia, Microsoft Azure, and other infrastructure providers have a vested interest in pushing for commoditized models: If models are interchangeable, people will buy more GPUs, rent more cloud capacity, and build more applications."


    Read more of this story at Slashdot.


  • Anthropic's New Opus 5 Model Rivals Fable 5 For Half the Price
    Anthropic has released Opus 5, a new Claude model that it says comes close to its higher-end Fable 5 model at half the price while improving on Opus 4.8 in knowledge work, coding, and scientific research tasks. "At the same time, Anthropic says it has managed to make the model more resistant to being tricked," notes Engadget. Additionally, the company says Opus 5 "exhibits the lowest rates of deceptive behavior." From the report: One important distinction between Opus 5 and Mythos, which is currently only available to a limited number of vetted organizations through Anthropic's Project Glasswing initiative, is that the company has specifically avoided training the new model on cyber-related tasks. Due to more its powerful capabilities, Opus 5 is broadly better at those tasks than its predecessor, making it more useful for finding cybersecurity vulnerabilities, but the company says Opus 5 is "substantially behind" its flagship model at exploiting those vulnerabilities. [...] Anthropic says "Claude Opus 5's safeguards are designed to allow beneficial uses of the model in both cybersecurity and biology." The company has strengthened some of the model's cyber-related guardrails, but notes it did so along a "narrow range" of specific tasks. "Based on our testing, we expect the classifiers to intervene around 85 percent less often than they do for Fable 5," Anthropic said. With Opus 5, Anthropic also isn't including it in its recently announced 30-day data retention policy, which the company introduced alongside Fable and Mythos 5. As for pricing. Anthropic says API costs for Opus 5 will remain at $5 per one million input tokens and $25 per one million output tokens. Anthropic has also added an "effort" menu for Opus that users can tweak to tell the model whether they want it to be more thorough or fast and efficient to conserve tokens.


    Read more of this story at Slashdot.


  • John C. Dvorak, an Early and Influential Technology Journalist, Dies At 80
    Longtime Slashdot reader sandbagger shares the passing of John C. Dvorak, an early and influential technology journalist for PC Magazine. He was 80. Talking Biz News reports: Aric Mackey writes, "Widely recognized for his profound impact on the technology industry, John's career spanned decades of rapid digital evolution. He was perhaps best known for his influential, long-running column in PC Magazine and his groundbreaking work on the No Agenda podcast. Through his prolific writing, broadcasting, and distinct public voice, he helped shape critical conversations around both technology and political analysis, guiding generations of readers and listeners with his unique perspective. "To those who knew him personally, John was far more than his public work. He was a beloved husband, devoted father, proud grandfather, and a loyal friend. Those closest to him will remember a man defined by his strong convictions, his exceptionally sharp wit, and an enduring curiosity about the world around him." Dvorak was also part of the startup team at CNET Networks, and appeared on MarketWatch TV.


    Read more of this story at Slashdot.


  • Stripe Eyes $10 Billion Deal For AI Model Marketplace OpenRouter
    An anonymous reader quotes a report from PYMNTS.com: Stripe is in talks to buy OpenRouter, an artificial intelligence (AI) startup that could sell for roughly $10 billion, according to The Wall Street Journal. The move would mark a significant step outside payments for a company that processes transactions for much of the internet. It also lands while Stripe pursues a far larger target: a bid for PayPal that would value the payments giant at about $53 billion. The Journal reported Thursday (July 23) that a transaction could be announced soon, though the talks could still collapse or another buyer could step in. The exact price under discussion could not be learned. Several other large technology companies had also been weighing deals for OpenRouter. The startup was valued at $1.3 billion in May, according to PitchBook, meaning a sale near $10 billion would represent a steep markup in a matter of months. Its backers include Menlo Ventures and CapitalG, the growth fund of Google parent Alphabet. OpenRouter sells software that lets customers reach AI models from OpenAI and Anthropic, along with open weight alternatives anyone can download and run. The Journal described the company's position this way: "OpenRouter is part of an emerging crop of startups that have found a lucrative niche between AI developers and the companies that want to use them." The platform lists hundreds of large language models and lets developers compare and switch between them.


    Read more of this story at Slashdot.


  • Astronomers May Have Discovered First Moon Outside Our Solar System
    Astronomers studying the star system CD-35 2722 may have found the first known moon-like object outside our solar system. The classification is unusually tricky, however, because it orbits a brown dwarf rather than a planet, making it clearly an "exosatellite" but forcing scientists to rethink where the line between planet, moon, and failed star should be drawn. Space.com reports: The star CD-35 2722 is located around 73 light-years away and has around half the mass of the sun. It is orbited by a "failed star" or brown dwarf. These stellar bodies get their unfortunate nickname because they form like other stars but fail to gather enough mass to trigger the fusion of hydrogen to helium in their cores. In terms of mass, brown dwarfs are more massive than the largest gas giant planets, but smaller than the smallest stars, usually with around 13 to 80 times the mass of Jupiter, or around 0.013 to 0.08 times the mass of the sun. The newly discovered object in CD-35 2722 is certainly moon-like, but rather than orbiting a planet as the moons in the solar system do, it orbits the system's brown dwarf. "This system is somewhat hard to define using solar-system-based words like 'planet' and 'moon.' The exosatellite is clearly massive enough to be a planet, but it does not orbit a star, though it orbits an object that orbits a star," team leader Kevin Hoy of the Universidad Diego Portales and the Millennium Nucleus of Young Exoplanets and their Moons (YEMS) in Chile, said in a statement. "Being the third wheel in this system makes us want to call it a moon, even if it is nothing like the small, rocky moons we have in our system." The team currently isn't able to definitively claim this object in CD-35 2722 is an exomoon, because that would require really nailing down a new definition of what a moon is. "The satellite we report is a giant gaseous body orbiting a highly massive companion, itself several times the mass of Jupiter. We have a clear delineation between the planets and the sun in the solar system, so defining things like moons is simple," team member Alice Zurlo of the Universidad Diego Portales said. "In the CD-35 2722 system, where we are blurring the lines between stars, planets, and moons, the whole thing becomes more complicated to describe." Zurlo and colleagues can, however, confidently claim this is an exosatellite, meaning it is a first-of-its-kind detection no matter what the future holds for its classification. The findings have been published in the journal Nature.


    Read more of this story at Slashdot.


  • Humans Can Learn To Echolocate In Just 10 Weeks, and It Rewires the Brain
    alternative_right shares a report from ScienceAlert: A study published in PLOS One in 2021 by researchers from Durham University in the UK showed that with 10 weeks of training, both blind and sighted people could learn to echolocate using verbal clicks. While the technique is already used by a number of people with impaired vision -- sometimes using the taps of a cane instead of clicks made by their mouth -- those findings suggest that many of us can learn the necessary techniques. Some of the same researchers who made that discovery are part of the team behind a follow-up study published in Cerebral Cortex, looking at how the 10 weeks of training that the 26 participants went through actually changed the physical structure of their brains. Specifically, the team analyzed brain scans of the V1 (the primary visual cortex, processing visuals), and the A1 (the primary auditory cortex, processing sounds). Strikingly, the scans showed that the V1s of both blind and sighted people had developed sensitivity to sound echoes during echolocation training.


    Read more of this story at Slashdot.


  • World's First Wave Power Generator Receives Certification For Regular Use
    "The Norwegian certification agency DNV has certified the commercial wave-driven power generator Corpower C4 for regular use," writes Longtime Slashdot reader Qbertino. "German news site heise.de has a detailed write-up. See a CGI video of the power station and its internals, as well as the company's website [at their respective links]." From the report (translated to English): According to the manufacturer Corpower Ocean, it is the first DNV prototype certificate for a wave energy converter. The certificate confirms that Corpower's technology meets DNV's requirements for structural strength, reliability, and safety, Corpower Ocean announced. The certification process began in the design phase and lasted seven years. DNV oversaw the process from concept development through design, manufacturing, and assembly, to dry-running tests and subsequent operation. This is an important step, said Patrik Moller, CEO and one of the founders of Corpower Ocean. With the certification, wave energy is no longer just a promising technology, but a proven and financially viable one. This opens up new opportunities for project financing, insurance, and investments in commercial applications. The Corpower C4 wave power plant looks like a normal buoy: It consists of a 19-meter-long floating body with a diameter of 9 meters and a weight of approximately 11 tons. The system is anchored to the seabed. A mechanism inside the buoy converts its up-and-down movements in the waves into a rotary motion. This, in turn, drives a generator that produces electricity. The report notes that the company is "planning the first two industrial-scale wave energy farms off the coasts of Portugal and Scotland," which are scheduled to begin operating sometime between 2027 and 2029.


    Read more of this story at Slashdot.


www.theregister.com - Articles












Linux.com




  • From DHCP to SZTP – The Trust Revolution
    By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]

    The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.








Phoronix




  • Qualcomm QCE Driver On The Chopping Block With ~48x Slower Than Armv8 Crypto Extensions
    A few days back I wrote about upstream Linux kernel developers marking the Qualcomm crypto accelerator driver as "broken" and "harmful" due to its slow performance, history of bugs, and other limitations. Now this Qualcomm Crypto Engine "QCE" driver might be removed outright from the Linux kernel source tree after discovering it's even worse than anticipated...



  • Ubuntu Linux Looking To Get Rid Of /etc/debian_version Historical Artifact
    Ubuntu Linux has shipped /etc/debian_version that is carried over from upstream Debian and in turn just indicating the Debian Sid development version from which the packages are arrived. Besides it being inaccurate, /etc/os-release has been the long preferred standard for reading the OS release information. Thus finally Ubuntu developers are looking at dropping the /etc/debian_version file...


  • Fedora 45 Looks To Begin Phasing Out In-Kernel Crypto Userspace API
    Going along with the upstream Linux 7.2 kernel deprecation of AF_ALG and Linux 7.3 to further restrict this interface for letting user-space programs interact directly with the Linux kernel crypto API, Fedora 45 is looking to follow and help support this transition...


  • AMD Advancing AI 2026: Open, Open-Source & More Open-Source
    At this week's AMD Advancing AI 2026 event, "AI" was mentioned thousands of times in talks and in demos. As expected. Beyond that, the other term likely most heard during the event was "open"... Not particularly new for AMD with their long history of open-source efforts but I'd wager at this year's AMD Advancing AI 2026 event they were more acutely bringing up open-source, open ecosystems, and open standards. Certainly seemed like an uptick in "open" mentions and a ramp that's been building each year at the AMD events...


  • Snapdragon X Elite Laptop Experience Still Lackluster On Ubuntu 26.04 LTS
    At the end of last year when checking out the latest Linux experience on the Snapdragon X Elite it was a disappointing affair. The performance had regressed and overall a more headache-inducing experience than just running a modern AMD Ryzen AI or Intel Core Ultra laptop on Linux. Given the recent release of Ubuntu 26.04 LTS, I9ve been re-testing the Acer Swift 14 AI laptop with Snapdragon X Elite SoC to see how its performing under Linux now and against the AMD/Intel competition. Unfortunately, it9s regressed even further than the last round of testing.




Engadget"Engadget - Technology News & Expert Reviews"











OSnews

  • The Hurd gets 9pfs, OpenNTPD, dynamic /dev/ entries, and more
    The hottest and most promising operating system kernel in development, the GNU Hurd, has published another summary of its most recent quarter of development. Hurd has experimental support for 9pfs now, a work-inprogress port of OpenNTPD, the NTP daemon from OpenBSD, a port of Neovim, and a few more ports here and there. Diving deeper into the actual kernel itself, theres a major improvement to how the Hurd handles entries in /dev/: Mikhail Karpov added some checks for mmap in several places. He also worked on adding storeio to the bootstrap chain. This is actually quite interesting. Currently the Hurd sets device entries in /dev/ statically. For example, I am writing this qoth on a Hurd machine that is using two /dev/ entries for my filesystem: /dev/wd0s1 for swap and /dev/wd0s5 for my root filesystem. However, /dev/wd0s1 through /dev/wd0s16 exist on my computer! Once Mikhails project is done, then the Hurd will dynamically populate SATA devices at boot time! No more need for static translators! ↫ The Hurds quartely report The dhcpcd port we talked about earlier this year keeps improving too, which is quite important for future IPv6 support. Of course, theres way more to dive into, and reading about a bunch of people developing their own thing without any regard for or interest in the mainstream always feels a little bit like a cold glass of tonic  the best soft drink  in the depths of hell. Keep at it.


  • Google Play Services drops support for Android 6.0
    Given that Android phones have been around for nearly two decades now, there comes a time when Google has to end support for one of its older software versions. For a couple of years now, Google Play services has been supported on devices running Android 6.0 Marshmallow or newer. That has changed over the past few weeks, with Google deciding to retire this software version after a nearly 11-year run. ↫ Chethan Rao at Android Authority At some point, an operating system version needs to be left behind  and I dont think its entirely unreasonable to no longer support Google Play Services on an operating system version thats 11 years old. However, this is Android were talking about, and devices running Android 6.0 were probably sold much more recently than 11 years ago, when the operating system version was new. Hell, I wouldnt be surprised if devices running Android 6.0 are still being sold today. I doubt this is something that will affect many people who read OSNews, but theres bound to be edge cases  Android 6.0 devices silently doing their job that are now just a little less useful. Im thinking of really cheap tablets that can still play video just fine, retro gaming handhelds that dont magically lose the ability to emulate SNES games, that sort of stuff. The numbers will be small, but if you happen to be among them, this can be a really annoying deprecation.


  • FreeBSD ports frozen after someone commits the entire 150MB Linux Copilot binary
    A rather unusual announcement was made late last night: the FreeBSD project has frozen their ports repository. For more than 48 hours now, no changes have been accepted or made to the tree, and heres why. A 150MB binary file was recently committed to the ports tree and, as a result, core@ made the decision to implement a temporary freeze of the ports tree in order to implement some clean up efforts. The commit in question severed our ports tree mirroring to github.com due to their filesize hard limit of 100MB, and introduced a blob of questionable licensing into the repository history. ↫ Kyle Evans in freebsd-announce While FreeBSDs ports tree is not hosted by GitHub  its merely mirrored there  the FreeBSD team believes the community values the GitHub mirror too much, and as such, steps had to be taken to fix this. Ports has not been compromised and users systems do not appear to be at risk in any way due to this occurrence, which is good news. Curiously, the official announcement makes no mention of which 150MB file, exactly, was committed to ports, but it didnt take for people long to pinpoint the offending commit (screenshot). It turns out someone committed the entire github-copilot-cli Linux binary to ports, as part of the github-copilot-cli port. This FreeBSD port is effectively a way to easily install and run this tool on FreeBSD using Linuxulator, FreeBSDs Linux compatibility layer that allows you to run unmodified Linux binaries on FreeBSD. Its important to note this FreeBSD port is not actually a port of the Linux version of github-copilot-cli to FreeBSD; the FreeBSD port! merely acts as a setup script to run the unmodified Linux binary using Linuxulator. Its not a real! port because the tool isnt open source and its license doesnt allow for modifications. Thats why the announcement specifically mentions questionable licensing!  github-copilot-cli is licensed under some custom license specifically made for this tool, and is not open source. Anyway, for whatever reason, the maintainer of this FreeBSD port accidentally made a commit that added the actual, full 150MB Linux binary to FreeBSD ports. Im assuming that under normal circumstances, building and installing the github-copilot-cli FreeBSD port would merely download the binary off GitHub and set Linuxulator up so that it could run it. Mistakes happen, and since theres clearly nothing malicious going on, theres not much to worry about. In fact, this may lead to new checks and balances to prevent this from happening in the future, which would be good news. The FreeBSD team is working on rolling back, fixing the issue, and investigating how this could have happened. Ports is still frozen at the time of writing, but Im sure well have a more detailed account soon.


  • Amiga 1000: ten years ahead of its time
    We all know the original Amiga was far ahead of its time, and the Amiga really doesnt need more retrospectives and glazing. However, that doesnt mean we dont want more Amiga retrospectives and glazing. I’m not sure I even saw an Amiga in person until 1987, but I knew just from reading about it that I wanted one. I wasn’t able to make it happen until 1991, so I was pretty late to the game. But even in 1991, an Amiga felt like living in the future. I could load several programs and switch between them effortlessly, with the only limit being the amount of memory I had. I could connect to a BBS with a terminal program, start a download, then switch it to the background, fire up a word processor, and do my homework while the download was happening. In some cases, I could even fire up a game and play a game while a download happened in the background. I could download stuff while I played Civilization, which was pretty great. ↫ David L. Farquhar Its 2026, I have an incredibly powerful Linux gaming computer, but since I grew up on DOS and Windows, to this day, I still feel the need the close every other application before launching a game. I dont need to  modern operating systems handle such things just fine, mostly  but its so ingrained in me its hard to drop this habit. I wonder if people who grew up with more capable computers than whatever DOS nonsense I grew up with are less inclined to do things like this? Or did memory constraints act as an equaliser? Anyway, the linked article doesnt mention it, but the Amiga is still, somehow, going relatively strong for a platform thats supposed to be dead. Modern(-ish) hardware is getting a bit harder to come by, but AmigaOS 4 and especially MorphOS are still actively being developed, and even running them in virtual machines on x86 has become about as easy as it could be.


  • Rewriting the Futhark type checker
    This post is about the evolution of Futhark’s type checker, motivated by a large refactoring I am about to merge. It is probably mostly of interest to other language designers, and contains some lessons I wish I had known when we first got started  although I am not particularly well-read in the type checking literature, so it’s possible all of this is old hat. ↫ The Futhark Programming Language blog Thats a clear introduction  you know what to expect.


  • COSMIC DE’s first seven months
    Honestly, it feels like only yesterday that System76, Linux OEM and the company behind pop!_OS, announced it was going to develop its own desktop environment, COSMIC. Were about seven months into the more general availability of COSMIC, and the company has put up a nice overview of the various improvements that have already made their way into the code since then. Of course, theres a ton of visual improvements have been made to COSMIC, as well as a slew of new features: improved search, a brand new system monitor, drag and drop for tabs throughout COSMIC, and much more. COSMICs file manager and terminal have also seen a lot of work, with a ton of new small features and additions to bring them up to par with what people expect form a modern file manager and terminal emulator. Theres a ton more listed in the article, so it serves as a nice while you were away! if youve not been following development.


  • Codebergs programmer user base overwhelmingly votes to ban slopcoded projects from its platform
    What happens when programmers get to vote on a complete ban on slopcoded software on their code platform? Members of Codeberg were asked to vote on a proposal to completely ban slopcoded projects from Codeberg, and in what should not be a surprising outcome to anyone not overcome with AI! hysteria, the vast majority voted in favour of the complete ban: over 70% of Codeberg members voted to ban slopcoded projects entirely (358 in favour, 144 against, 14 abstentions). Of course, this is not a surprising outcome. Stripped down, programming is a form of artistic expression, and programming is no different than writing, painting, composing, or any other artistic endeavour. I think its safe to say writers, painters, composers, and similar creatives are against AI!, so its only natural programmers feel the same; poll after poll shows the overwhelming majority of respondents  usually well over 70-80%  are against AI!. The pro- AI! accounts on OSNews often try to paint my anti- AI! position as extremist, but in reality, Im just voicing how 70-80% of people clearly state they feel. I have zero skin in this game, zero outside pressure to please any bosses to get that promotion, zero pressure to conform to avoid getting laid off, zero pressure to not contradict upper-management. I can speak freely, openly, and without fear of retaliation. And as Nikhil Suresh explains in his harrowing from-the-trenches article AI Mania Is Eviscerating Global Decision-Making, thats a massive asset. The vast majority of people  including your friends, family, and co-workers  really hate AI!. You can either accept this, or be left behind.


  • Building an AmigaOS Development Environment in 2026
    If you want to develop an application for AmigaOS 3.x but dont want to deal with real hardware, virtualisation and emulation are your friends. Apropos of nothing, I decided to set up an Amiga development environment. Since figuring things out wasnt straightforward, I wrote down instructions for Linux about how to compile the first program and run it in an emulator. Enjoy! ↫ Daniel Kochmański Its a great guide, easy to follow, and youll be up and running quickly. The emulator the guide uses  AmiBerry, a fork of WinUAE  contains slopcode, so you may want to consider alternatives. This doesnt change much for the guide though, as whatever tasks you need to do outside and inside AmigaOS itself remain unchanged.


  • Volkswagen blocks custom Android ROM users from VW application
    Drivers of cars from the Volkswagen Group using alternative Android versions like GrapheneOS, LineageOS, or /e/OS have been unable to use the VW app for some time. This means they can neither check their vehicles remaining range from their phone, schedule service appointments, nor control charging and air conditioning. The car manufacturer has made changes to the apps backend that only allow devices with Googles pre-installed Play Services. When asked by heise online, VW stated that affected users should not expect a timely reopening. “However, they are looking into it.” ↫ Andreas Floemer at Heise.de Clearly, this should be illegal. Then again, that has never stopped Volkswagen before.


  • Happy companies are all alike; every unhappy company is unhappy in its own way
    Sam Altman seems to be making OpenAI way more non-profit than before: Even as the AI bubble becomes a mainstream talking point on Wall Street, tech companies continue to peddle the fantasy that AI is poised to become an almost magical money-maker. Case in point, OpenAI wants you to believe that by 2030, it’ll be raking in $100 billion a year just from ads alone — even though it’s currently struggling to reach just $1 billion. ↫ Joe Wilkins at Futurism The US tech giants fueling this AI! bubble are trying to hide the true extent of their debt: Hidden debt at U.S. tech giants swelled eightfold in four years to an estimated $1.65 trillion as artificial intelligence investments ballooned, a Nikkei study shows, exceeding actual debt and making it tougher for investors to assess risk. The five companies hidden debt, which does not appear on balance sheets, totaled $1.65 trillion in the most recent quarter, exceeding the roughly $1.35 trillion in debt reflected on their balance sheets. The data includes some estimates. ↫ Kohei Yamada at Nikkei Asia The bubble is expanding to comical proportions: The American stock market is booming, thanks to artificial intelligence. Tech giants are borrowing billions to acquire AI talent, purchase chips and hardware, and construct data centers. And market watchers are starting to get worried. They see financiers bulldozing giant piles of money to private AI start-ups with no realistic path to profitability, tech companies reliant on other tech companies for revenue growth, and non-tech businesses without a lot to show for their AI investments. The value of AI-linked firms has climbed $27 trillion in the past three years—an astonishing amount, equivalent to 36 percent of the value of the entire U.S. stock market today. Although future earnings could justify those valuations, as Dominic Wilson and Vickie Chang of Goldman Sachs argued in a note to clients, the profit expectations require Panglossian optimism. No less an authority than Sam Altman is arguing that we are in an AI bubble. The International Monetary Fund is citing it as a significant risk to financial stability and warning about what might happen when it bursts: diminished investment, tighter credit, reduced consumption, disrupted trade flows. ↫ Annie Lowrey at The Atlantic Im not worried, though. I have it on good authority that AI! increases productivity by 10x, so surely, none of the above is a problem. Any day now, we will be inundated with waves of brand new, high-quality, valuable software. Any day now, existing software will increase in quality by 10x, leading to a huge surge in software sales. Any day now, productivity in factories will increase rapidly thanks to AI! freeing up workers time, driving prices down 10x, leaving consumers with 10x more money to spend. Any day now, everyone will be able to produce the next Citizen Kane or write the next Anna Karenina, causing an explosion in magnificent, timeless art that will have historians of the future marvel at our civilisations ingenuity and artistry. In the meantime, these companies can just ask their AI! how to become profitable. Should be table-stakes for a 10x force multiplier. Im not worried.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)





  • Hannah Montana Linux Is Back!
    Developer Noah Cagle decided the world needed the once obscure but beloved Linux distribution and gave it a decidedly pink refresh.




  • Kubuntu Focus Goes Ultra
    The Kubuntu Focus team has upped the performance ante of its M2 and Zr laptops with the latest, greatest CPUs from Intel.




Page last modified on November 17, 2022, at 06:39 PM