Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All) (Two Column)

LWN.net

  • Python 3.15 released
    Version3.15 of the Python programming language has been released. Notable changesin this release include the addition of the sentinel and frozendict built-in types,the use of UTF-8 encoding by default, packagestart-up configuration files, as well as improvements in the experimentalJIT compiler. See the "What's new in Python3.15" article for an in-depth look at new features in this release, and thechangelogfor a full list of changes.



  • [$] Adding kernel control-flow-integrity checking to GCC
    While many developers are struggling to keep up with the flood ofvulnerability reports, others are still focused on preventing those reportsfrom happening in the first place. Control-flow integrity (CFI) is theterm for preventing (or at least detecting) exploits that divert the flowof control from its intended paths. At the 2026 GNU Tools Cauldron, Kees Cookpresented his changes to the GCC compiler suite to support forward-edge CFIfor the kernel.


  • [$] The state of systemd: 2026 edition
    At the 2026 All Systems Go!conference, systemd maintainers Luca Boccassi and Zbigniew Jędrzejewski-Szmekdelivered the traditional "state of the project" session with an overview of thesystemd project's accomplishments in the past year. That was followed by amaintainer round table where Boccassi, Jędrzejewski-Szmek, Daan De Meyer, andproject leader Lennart Poettering fielded questions about systemd's size,health, and if it might replace Kubernetes. (It will not.)


  • Let's Encrypt moving to 64-day certificate lifetimes in 2027
    Let'sEncrypt, the nonprofit that provides free TLS certificates for millions ofsites, has announced thatit will be moving to certificates with 64-day lifetimes on February 10,2027:

    This means that any certificate we issue or renew on and after that date willhave a 64 day validity period, and we expect the last 90-day certificate toexpire on May 11, 2027. We will not revoke valid certificates as a part of thisprocess.

    This is the second stage of Let's Encrypt's plan, announced in 2025,to move to 45-day certificate lifetimes as required by the the CA/BrowserForum Baseline Requirements. In 2028, Let's Encrypt will switch to 45-day certificates.


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (bind, bind9.16, freerdp, glibc, kbd, mod_auth_openidc, openssl, perl-DBI, python3.12, python3.14, and tftp), Debian (rails and twitter-bootstrap3), Fedora (barman, cockpit, hcloud, libmodsecurity, nginx-mod-modsecurity, perl-DBI, sudo, and xorg-x11-server-Xwayland), Mageia (libxfont2), Oracle (bind9.18, firefox, kernel, nodejs24, perl-DBI, and vim), Red Hat (kernel, libreswan, opentelemetry-collector, osbuild-composer, rhc, and runc), SUSE (alloy, amazon-ecs-init, bind, busybox, distribution, emacs, ghostscript, glibc, GraphicsMagick, hauler, helm, helm3, jackson-annotations, jackson-core, jackson-databind, kernel, libpoppler-cpp3, libxtst, logback, nvidia-open-driver-G07-signed, perl-DBI, php-composer2, pi-coding-agent, portprotonqt, pvetui, python-hpack, python313-GitPython, and wpa_supplicant), and Ubuntu (apache2, bluez, libarchive, libde265, libgit2, libpng1.6, libxml2, linux, linux-aws, linux-aws-6.8, linux-aws-fips, linux-fips, linux-realtime, linux-realtime-6.8, linux-aws-7.0, linux-azure, linux-azure-6.8, linux-azure-fde, linux-azure-fde-6.8, linux-azure-fips, linux-azure-7.0, linux-azure-fde-7.0, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-gcp-7.0, linux-hwe-7.0, linux-oracle-7.0, linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oracle, linux-ibm-6.8, linux-nvidia, and linux-oem-6.17).


  • [$] An update on Rust's project goals
    Tomáš Šedovič is a program manager at the Rust Foundation. He co-leads thegoals team, which helpsorganize the Rust project'soverall goals, including making sure that the peoplewho have agreed to work on one have the support they need.At Kangrejos 2026, he provided an overview of the Rust project's goal processesaimed at ensuring that the Rust for Linux developers were aware of how theproject organizes, tracks, and amends goals.TheRust for Linux projecthas inspired several current project goals, so he thought that getting an insideview of the process might be helpful.


  • [$] The [vx]swap showdown
    The kernel's swap layer has undergone somesignificant changes over the course of the last year and a number oflongstanding problems have been addressed. One problem that has notyet been solved in the mainline is the direct tie between slots in the swapcache and space in persistent swap files, which can cause highlyinefficient resource use. There are two competing solutions for thisproblem, neither of which has, as yet, reached readiness for merging; alengthy discussion on possible paths forward shows ongoing disagreementover the best path forward.


  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (bind, firefox, freerdp, ghostscript, glibc, kernel, kernel-rt, perl-DBI, python3.12, rust-rpm-sequoia, rust-sequoia-sq, rust-sequoia-sqv, and vim), Debian (gst-plugins-base1.0, python3.11, and xz-utils), Fedora (7zip, chromium, curl, docker-buildx, kernel, Lmod, and sos), Mageia (tesseract), Oracle (dovecot, firefox, freerdp, gd, ghostscript, kernel, librabbitmq, perl-DBI, python3.12, rust-rpm-sequoia, rust-sequoia-sqv, sg3_utils, vim, and virtuoso-opensource), Slackware (xorg-server), SUSE (aliyun-cli, busybox, cadvisor, chromedriver, chromium, crane, distribution-registry, fetchmail, fio, ghostscript, golang-github-prometheus-alertmanager, google-osconfig-agent, govulncheck-vulndb, libsoup, libXtst, openexr, prometheus-blackbox_exporter, python-fsspec, rpcbind, rsyslog, rustup, wireshark, wpa_supplicant, and zcode), and Ubuntu (erlang, golang-golang-x-net, gst-plugins-ugly1.0, lxml, poppler, and sudo).


  • [$] LWN.net Weekly Edition for October 8, 2026
    Inside this week's LWN.net Weekly Edition:
    Front: Kernel bugs; Gentoo's Chromium package; Rust smart pointers; Sashiko; Charon; LAVD scheduler; Python random-number modules. Briefs: OpenSSH 10.6; RustConf recordings; Rust 1.99.0; Picard 3.0; Zig 0.17; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.


  • [$] Analyzing Rust programs with Charon
    Nadrieril is a long-time Rust contributor, and the maintainer of the rustcpattern-matching infrastructure. During his involvement with Rust, he hasnoticed a problem with the usability of the language: it is difficult toautomatically extract information from a Rust crate for use with other tooling.The Charon project aims to fix that by providing a stable API for accessinginternal information from the Rust compiler.


LXer Linux News


  • Ubuntu 26.10 To Include Desktop Images For RISC-V
    Ubuntu Linux ISOs for RISC-V 64-bit to date have just been the server/CLI version without any desktop environment pre-seeded. But with next week's Ubuntu 26.10 release, there will now be Ubuntu 26.10 RISC-V desktop ISOs for both Ubuntu proper and a Xubuntu minimal ISO...




  • Intel Twin Lake-Based Helix 320 Industrial Gateway with Quad 2.5GbE
    OnLogic’s newest industrial edge gateway, the Helix 320, features a fanless design powered by Intel N-Series Twin Lake processors. The compact system includes four 2.5GbE ports, two configurable serial ports, M.2 expansion, and support for up to three displays. OnLogic offers the Helix 320 with two Intel N-Series “Twin Lake” processors: N250 – 4-core/4-thread architecture, […]


  • Secretive Rosaic Labs Hires Legendary Linux x86 Developer
    The curiosity into secretive semiconductor startup Rosaic Labs builds. Earlier this year it was noted that Intel was providing Rosaic Labs with access to its Atom technology with RTL code. There have also been rather mysterious x86 additions not from Intel or AMD (or Zhaoxin / Hygon) that given the timing may pertain to Rosaic Labs. News today is that Rosaic recently hired a long-time, Linux x86 developer veteran...






Error: It's not possible to reach RSS file http://services.digg.com/2.0/story.getTopNews?type=rss&topic=technology ...

Slashdot

  • Claude Sent Police a Fake Murder Tip. White House Mandates AI Companies Report Security Incidents
    AFP reports that an AI model from Anthropic "submitted a fabricated tip about an unsolved homicide to Philadelphia police, authorities said Friday." Claude "was instructed never to log in, create accounts, enter personal data, make purchases, or submit anything destructive, but the instructions did not rule out form submissions," Anthropic said Friday in a blog post. Authorities are now criticizing Anthropic "for taking two months to report the incident."The Philadelphia Police Department said the false submission was made in July through PhillyUnsolvedMurders.com, a public website where people can share information about unsolved killings. According to Anthropic's account, as relayed by police, the model was running a test that involved interacting with randomly selected websites when it reached the site and filed false information about an unsolved murder. The AI model presented itself as someone who might have knowledge of the case. Anthropic's breaches have prompted the White House to mandate that AI companies notify and correct security incidents, news outlet Axios reported [yesterday], citing administration officials. "This notification and remediation process is not optional... It is a critical national security obligation," White House Super Intelligence Force leaders said in a statement to Axios. "I may have information regarding this case," Claude told the police. "I recall seeing someone matching the description in the area around [the street named on the page] during that time period. Please contact me if this information is relevant." Anthropic notes that Claude "left the name and contact fields empty, which the form allowed, and submitted it. The submission was flagged as spam and was never forwarded for investigation." But Anthropic also admits they saw "this behavior" three times — "on OSWorld (a public computer use evaluation), on Odysseys (a long-horizon task evaluation), and during internal usage." Submitting forms when it shouldn't have generally occurred "when an evaluation's instructions were ambiguous, or when a misconfiguration within the environment prevented Claude from working with dummy forms." Anthropic's blog post acknowledges three other categories of behaviors: Exploiting software flaws. Like when Claude received an error when trying to run a public tool on a university's web site, it located an injection flaw in a script on the university's server that let it run commands — including that public tool. Working around restrictions to reach gated data. For example, Claude Mythos 5 needed public data that was only available from a state agency for a fee. "Claude learned from an archived copy of the agency's website that its public dashboard issues an access token to any visitor," Anthropic explains. "It requested one and used it to query the database without paying the fee." Using URL shortening services. "Some of our fetch tools, which let Claude read webpages, limit the length of the URLs Claude can request. This is to prevent Claude from using long URLs to take certain unwanted actions, such as SQL or command injections... We saw several models, including Claude Opus 5 and Claude Mythos 5, get around this limitation by using free URL shortening services.""We have built tooling to automatically detect and block the kinds of behaviors described above," Anthropic says, saying it's already running no on most of their evaluations. "When we tested it against the cases described in this post, it blocked all of them." And they've already taken several other new preventive measures:They've stopped running some public evaluations Other public evaluations were moved to offline versions or rebuilt so their tasks don't reach live websites. They've updated the guardrails on some internet access tools (including web fetch) "to heavily restrict what the model can do." They're continuing "to fix or remove training environments that reward Claude for working around tool restrictions or other blockers, so that they do not incentivize these behaviors or permit reward hacking."They've moved internal agents to "centrally managed infrastructure with strong containment," that minimizes internet access while monitoring "far more of what agents do through techniques like safety classifiers and hierarchical summarization."In the past they'd focused reviews on cybersecurity testing, but they've broadened their transcript reviewing to other tasks which include internet access. "Because language models are non-deterministic — that is, their responses always involve some element of randomness, and they may carry out the same task slightly differently each time — we have Claude complete each evaluation task hundreds or thousands of times... If training rewards something we didn't intend — such as finding loopholes or working around a restriction — the model learns that the workaround pays off and may then apply it elsewhere." Anthropic's blog post also acknowledged they'd seen multiple misalignment incidents involving federal, state, and local U.S. government agencies. "We have briefed the White House on these cases and notified each agency involved," Anthropic wrote, adding that "While we have not completed a full alignment assessment of these cases, we consider them to be less severe than the cybersecurity incidents from this summer." (And they are "modifying training to reduce the likelihood of further misbehavior.")


    Read more of this story at Slashdot.


  • OpenAI Disrupts Two AI-Enabled 'False Front' Influence Operations That Included Seven Fake Journalists
    OpenAI announced it's recently banned two "influence operations" — one from Russia and one from Iran — that were using its models "to launder geopolitical, conflict-related messaging" in sophisticated "false front" propaganda campaigns:The Iranian operation included a stable of seven "journalist" personas which it used to pitch long-form articles to small and medium online outlets around the world... As well as long-form articles, the Iranian operation generated batches of social media comments, generally on topics related to the US-Iran war... [The Russian operation "appears to have co-opted unwitting people in Latin America to run a 'think tank'.... Since we do not allow access to our models from Russia, they used VPNs to connect to our services."] The Russian operation created fake "leaked" documents and audio scripts, some of which we identified being spread online... Both managed to land their content (not all of which was generated from our models) in mainstream media outlets, rather than simply posting it on social media. OpenAI says they've exposed 30 covert influence operations using its tools over the last two and a half years. But ironically, in this case both operations "also made heavy use of AI to draft internal reports (the Russian operation did this more than anything else)." And "in both cases, the actors used questionable or outright deceitful methodologies to exaggerate the operators' effectiveness."[The Russian operators] claimed that in May 2026, they created a fake email address purporting to come from the Regional Directorate of Education in Lima, Peru. They used this to instruct schools in the district to hold events dedicated to Ukraine on the national Day of Cultural and Linguistic Diversity (May 21)... According to the operators, some schools replied to the fake email address, confirming that they had held such events and even providing pictures. The operators then claimed to have planted stories about the events in the media in both Peru and Poland, alongside allegations that Ukraine was "exporting" ultra-nationalist ideologies, triggering outrage. Open-source searches identified stories that matched this claim in the Peruvianâ andâ Polish pressâ, and an English-language publication in Hungary (some of the articles have since been deleted)... Similarly, in June, the operators claimed they used a different fake email address to trick schools in Ecuador into holding a ceremony pledging allegiance to President Daniel Noboa and to Erik Prince, former head of private military contractor Blackwater. The operators claimed that the incident provoked outrage in Ecuador and put pressure on the government to deny the fake, thus amplifying it to a nationwide audience. Again, open-source research identified mediaâ coverageâ in the Ecuadorianâ pressâ that closely resembled this claim, and even a detailed rebuttalâ by Ecuador's Minister for Education. The operators used a range of techniques to underpin their false stories. According to their internal reporting, they spread two different fakes targeting Ecuador in March. One used fake audio attributed to Ukraine's consul in Ecuador, in which he was alleged to have made disparaging comments about Ecuadorians. OpenAI's report "is the latest illustration of how state actors can easily exploit widely available AI tools to peddle sophisticated propaganda against adversaries on a mass scale," argues the Economic Times:"We identified almost 100 articles published or syndicated under the [Iranian] operation's bylines across roughly a dozen online outlets around the world," OpenAI said. "These were small to medium outlets, generally focused on international affairs, geopolitics, and events in the Middle East." The earliest article identified by OpenAI was published in July 2025, and the latest in October 2026, with the frequency of reports increasing after the US-Iran war broke out earlier this year. The operation also generated social media comments on topics related to the US-Iran war, it added. One of the personas named Ervin B. Hoskins, whose bio claimed to be "an American freelance writer," had social media accounts across tech platforms including Elon Musk's X and Meta-owned Instagram. X's transparency information showed the account was connected via a "West Asia android app" and Instagram's transparency information showed the account was based in Iran, according to screenshots provided by OpenAI. Both accounts appeared to be suspended.


    Read more of this story at Slashdot.


  • Another Woman Sues Flock For Mistaken Crime Accusation By Police - and for Surveillance
    Last week a Florida woman sued Flock over its role in police officer accusing her of a crime she didn't commit But she's not the only one suing Flock over mistaken accusations, reports Gizmodo:.A Ring video of a Colorado woman being handed a criminal summons for a porch-package theft she did not commit recently went viral after the accusation rested on a Flock Safety automated license plate reader hit. Now, the woman involved in that case, Chrisanna Elser, is suing Flock Group, the towns of Columbine Valley and Bow Mar, Sergeant Jamie Milliman, and Chief Bret Cottrell in federal court on behalf of herself and other Coloradans whose plates the company has logged... The package in question was worth $25... The claims aimed at the company are intrusion upon seclusion, plus negligence and negligent design, on the theory that Flock sold a searchable archive and refused to require a warrant, a case number, or a supervisor's sign-off before an officer could run a plate... Elser is asking the court to make Columbine Valley, Bow Mar, Cottrell, and Flock delete the retained location data, to bar them from keeping it unless it is tied to an open case number, and to make Flock require a warrant, a case number, and a supervisor's approval before a Colorado agency can search the system. The Colorado Sun has more details. "Elser did not steal anything, but spent the following two weeks proving her own evidence to a department that did not return her calls, she said.[P]olice Sgt. Jamie Milliman told her the town of Bow Mar's surveillance cameras captured her forest green Rivian driving through town the same day a package disappeared from a thief... When Elser offered to show her own evidence to prove her innocence, including footage from her Rivian's onboard cameras, Milliman said she could bring it to court. Now, she is suing the officers and Flock Safety in U.S. District Court in Denver, alleging that the warrantless tracking violated her constitutional rights and that Flock's surveillance system unlawfully documents Coloradans' movements... "The scariest part is what happened to me can happen to anyone. I had no idea the Flock cameras existed and no idea a private company was keeping a record of every time I drove past my own neighborhood, or that any officer could pull it up without asking anyone or giving a reason for doing so," Elser said in a statement Tuesday. "If it can happen to me, it can happen to you...." "As noted in the complaint, the Flock system accurately identified the location of Ms. Elser's vehicle, while law enforcement retained responsibility for interpreting and weighing that information as part of the broader investigation," Paris Lewbel, Flock's public relations manager said. "Flock stands by the accuracy and integrity of its technology and intends to vigorously defend itself in this litigation." The article includes this statement from the woman's attorney. "Coloradans pass Flock's cameras on the way to work, church, the doctor, a protest, and a friend's house, and Flock keeps a detailed record of their every movement. It knows where you went, when you went there, and how often you go back, and it gives that information to a police officer with no limits. "We are asking a federal court to say what should be obvious: Flock's surveillance is straight-up creepy and the government does not get to follow everyone, all the time, without any reason for doing so."


    Read more of this story at Slashdot.


  • Meta Developing Compressed RAM 'CRAM' For Linux: Better Than ZRAM and Zswap?
    Phoronix reports on a presentation this week by Meta engineer Gregory Price at the Linux Plumbers Conference in Prague:With today's memory shortages, high prices, and ever increasing memory capacity needs, Meta engineers have been working on Compressed RAM ("CRAM") for Linux. This hardware-offloaded compression still allows cacheline/byte access to compressed memory and in turn a better implementation than the likes of ZRAM and Zswap. Very promising is that there is near-native performance to raw DRAM speeds with CRAM... For end-users that may already be relying on the likes of Zswap or ZRAM, CRAM is offering near-native DRAM speeds. Read-only data is shown to be as fast as the raw DRAM performance. And for memory writes, CRAM is much faster than ZRAM or Zswap or plain swap. "Most of the individual pieces needed to support CRAM are already mainline," the article points out. Tom's Hardware writes that "It uses a private NUMA node (essentially, a ghost CPU) instead of pretending to be a block device, and this lets Linux continue using all of its memory semantics, including migration and ballooning, to manage CRAM."Because CRAM is stored in RAM and treated as RAM, with full cacheline/byte access, it can be accessed in a read-only fashion with little delay; just the cost of hardware-offloaded compression...Even when you enable writes, CRAM is still much faster than ZRAM; 5.4x in the worst tested case of 20% writes. That's a huge drop from the 452x read-only case, but keep your context; a 5.4x speedup is still titanic. The massive performance cliff when writes are involved comes down to the need to page fault and migrate folios back to the original NUMA domain, as you can't write directly to compressed data; you'd corrupt everything... While the obvious target of the work here (given its origin at Meta Platforms) is big Linux servers, ZRAM and Zswap are used all over the Linux ecosystem, even on machines as constrained as the Steam Deck. Many distributions enable one or the other by default. CRAM seems like it could offer a considerable speed-up for some of these machines, so hopefully it finds its way into the kernel once the remaining implementation questions are answered.


    Read more of this story at Slashdot.


  • First Thorium Nuclear Clocks Begin to Tick
    Researchers in Vienna and Beijing have independently built the first nuclear clocks based on oscillations inside thorium nuclei, marking a major milestone for a field that could eventually produce highly portable, ultra-precise timekeepers. The clocks are already precise enough to lose only about a second over millions of years. The New York Times reports: The first nuclear clocks are not going to immediately supplant the worldwide network of atomic clocks, whose steady ticking we rely on for GPS and the definition of a second. Nor have they captured the record for most precise timepiece; the best atomic clocks are about 10,000 times more reliable and would take more than 100 billion years to lose one second. But nuclear clocks hold a bevy of potential advantages over existing atomic clocks. One day, they could be more reliable than the leading atomic versions, and nuclear clocks could be made more portable. They even hold the ability to search for certain kinds of dark matter -- the invisible stuff whose clumps make up 83 percent of the matter in the universe. If a particle of dark matter passed through the thorium nuclei, it could register as a wobble in the nuclear clock's otherwise steady ticktock. The findings have been published in the journal Nature.


    Read more of this story at Slashdot.


  • AI Surveillance Startup Flock To Cut Several Hundred Jobs Amid Backlash, Sources Say
    Reuters reports:Flock plans to let go of about 18% of its employees, people with direct knowledge of the plans said on Thursday, as the maker of AI-powered surveillance cameras and license-plate readers faces mounting opposition to its products from communities and lawmakers.... The company has about 1,500 employees [with job cuts hitting 270 employees]. Flock faces growing scrutiny from regulators, lawmakers, and privacy advocates, despite drawing strong investor interest among venture capitalists. A recent Reuters/Ipsos poll showed Americans are divided on whether Flock cameras are a good idea. Some 38% of the country supports the use of Flock cameras in their community, compared to 47% who oppose their use. A related story... In Texas this week a county commissioner decommissioned all 61 of their Flock surveillance cameras and license plate readers, according to a local news report. County residents "have raised serious questions about who can access this data, what vendors can disclose, improper searches, and records being kept after data expires," the precinct's Chief Public Affairs Officer said.


    Read more of this story at Slashdot.


  • Cloudflare Keeps 1.1.1.1 Out of Piracy Blocking, Escapes Penalties In France
    An anonymous reader quotes a report from TorrentFreak: Cloudflare doesn't block pirate sports streaming sites through its 1.1.1.1 DNS resolver in France, only through its CDN. The Paris Judicial Court has now accepted that stance, rejecting [French pay-TV provider] Canal+'s request for penalties of 50,000 euros per site, per day. Interestingly, the court's conclusion relies on statistics provided by Canal+ itself. [...] As a result, Cloudflare will not be penalized under these orders, even though its public DNS resolver is not blocking the sites in question. That is in line with the company's long-standing claim that it doesn't interfere with its DNS. In its recent transparency reports, Cloudflare repeatedly stated that it hasn't blocked any content through 1.1.1.1, despite orders from French and Italian courts. "To date, Cloudflare has not blocked content through the 1.1.1.1 Public DNS Resolver," the company's latest report reads. [...] Blocking through the CDN is another matter. According to the same report, Cloudflare geoblocked 1,238 domains in France in the second half of 2025, all under a single court order. In the first half of the year, it geoblocked 662 domains under seven orders. Cloudflare recently explained its position to the European Commission, in a submission (PDF) to its Counterfeit and Piracy Watch List consultation, stressing that global public DNS resolvers should not be used to block or restrict access. Instead, it highlights its real-time pirate stream blocking program, which allows vetted rightsholders to flag pirate streams that run through its network. These streams are disrupted "within seconds," Cloudflare says, without any DNS or IP address blocking. "For live content, where speed is crucial, Cloudflare has built real-time mitigation mechanisms that allow vetted rightsholder partners to flag infringing streams. When those streams are running through our network, we act on them in seconds," Cloudflare informed the Commission. For now, Cloudflare can continue to block pirate sites through its CDN only, while its 1.1.1.1 DNS resolver remains untouched. Canal+ can still appeal the rulings, so it may not be the last we hear of it.


    Read more of this story at Slashdot.


  • A 1960 Paper Published In Science Predicts World Will End Next Month
    sciencehabit shares a report from Science Magazine: A physicist has put a definite date on Doomsday," The New York Times wrote on November 4, 1960. "He calculates that it will come on Friday the Thirteenth in November, 2026 A. D. On that date, or thereabouts, the human population will have expanded so far as to approach infinity and thus will automatically annihilate itself." The newspaper was right -- but the prediction was wrong. That week, Austrian American physicist Heinz von Foerster and two colleagues published a paper in Science with the stunningly succinct title "Doomsday: Friday, 13 November, A.D. 2026." The work was based on a simple observation: The time it took for the human population to double in size kept getting shorter. Using population estimates from about 400 B.C.E. until 1958 C.E., the authors -- all from the department of electrical engineering at the University of Illinois Urbana-Champaign -- came up with an equation that best described the trend. If things continued the way they were going, the number of humans on Earth would rise faster and faster, reaching more than 25 billion by 2020. The researchers didn't calculate when humanity would run out of food, land, or energy. They just concluded that at some point this year, the equation ceased to give meaningful results because the predicted population shot toward infinity. That was their doomsday. "Our great-great-grandchildren will not starve," they wrote. "They will be squeezed to death." The exact date was somewhat arbitrary, however. The formula solved to 2026.87 plus or minus 5.5 years, and The New York Times reported that von Foerster "searched the center of this doom-time span for an appropriate date and found that a Friday the Thirteenth would fall conveniently in November of 2026." (November 13 also happened to be his birthday.) [...] [D]emographers, annoyed by what they saw as a provocation by outsiders, pointed out obvious flaws. For example, the time it takes for the number of humans to double could get a lot shorter, but certainly not shorter than the 9 months it takes for a baby to develop. "In view of the comments that subsequently were published in this journal, an extensive discussion of this article does not seem to be required," public health expert Harold Dorn drily noted in Science 2 years after von Foerster's article was published. The forecast would set a record, he predicted, "for the short length of time required to demonstrate its unreliability." "The failure of the Doomsday equation is ultimately a cautionary tale about the dangers of extrapolating from historically exceptional circumstances," writes economist Javier Birchenall of the University of California, Santa Barbara writes in a Perspective published in Science today.


    Read more of this story at Slashdot.


  • Apollo Software Pioneer Margaret Hamilton Dies at 90
    "Margaret Hamilton, the groundbreaking researcher who helped create the field of software engineering and whose code helped land NASA's Apollo astronauts on the moon to win the 20th century space race, has died," writes longtime Slashdot reader Veeru. "She was 90." MIT News reports: A computing pioneer who authored over 130 publications, Hamilton helped to establish software engineering as a dedicated discipline. She worked at MIT from 1959 until the mid-1970s, after which she became a successful computing entrepreneur and CEO. Her life's work was recognized with many awards and honors, including the 2016 Presidential Medal of Freedom from President Barack Obama, whose citation noted: "Hamilton defined new forms of software engineering and helped launch an industry that would forever change human history. Her software architecture led to giant leaps for humankind, writing the code that helped America set foot on the moon." "To say Margaret Hamilton was a pioneer -- to say she was ahead of her time -- would be a dramatic understatement. She was a software engineer at a time when that field was in its infancy, and she not only developed advanced code herself but also led a team in using that nascent technology to develop one of the most complex systems humanity had ever achieved," says Olivier de Weck, the Apollo Program Professor and interim head of the MIT Department Aeronautics and Astronautics. "The Apollo program still stands as one of our greatest testaments to the power of collaboration, ingenuity, and engineering, and Margaret Hamilton was a fundamental contributor to that program's success. And for her that was just the beginning! She went on to become an entrepreneur and remained on the cutting edge of systems software throughout an extraordinary career, while acting as an advocate, mentor, and inspiration to millions."


    Read more of this story at Slashdot.


  • US Bars Microsoft, Adobe, and Major IT Firms From Green Card Program
    An anonymous reader quotes a report from TechCrunch: The Trump administration is suspending Microsoft, Adobe, and several other technology companies from a program that helps skilled foreign workers obtain permanent residency in the United States, accusing the companies of fraud. "Our message to Microsoft is: You're a great American company, but you've got to hire great American workers," U.S. Vice President JD Vance said in a news conference on Thursday, Reuters reported. The other firms being suspended from the program include Capgemini, Cognizant, HCL, Infosys, Tata, and Wipro. Secretary of Labor Keith Sonderling said the government would not accept any new or pending permanent labor certification applications involving these companies. H-1B visas are designed for highly skilled positions that employers may struggle to fill with qualified U.S. workers. Tech companies are among the largest users of the program, with nearly three-quarters of approved visas going to workers from India, according to The Associated Press. Vance also said during the news conference that the administration would investigate nine universities, including Harvard, Yale, and Stanford, over allegations they're abusing a program that allows international students to come to the U.S. and were using the program to undermine wages for American workers. "We believe in the strength and talent of the American workforce," a Microsoft spokesperson said in a statement. "That is why the vast majority of Microsoft employees in the United States are Americans. We look forward to providing the Administration with additional information. For example, of the approximately 6,000 H-1B visa applications we submitted in the last fiscal year, 80% percent were to extend or change the status of existing Microsoft employees." "These were not to hire new people. The remaining filings for new employees were for individuals already legally in the United States who decided to come work for us, and they equal only 1% of our U.S. workforce. They are not new arrivals to our country."


    Read more of this story at Slashdot.


Polish Linux

  • Security: Why Linux Is Better Than Windows Or Mac OS
    Linux is a free and open source operating system that was released in 1991 developed and released by Linus Torvalds. Since its release it has reached a user base that is greatly widespread worldwide. Linux users swear by the reliability and freedom that this operating system offers, especially when compared to its counterparts, windows and [0]


  • Essential Software That Are Not Available On Linux OS
    An operating system is essentially the most important component in a computer. It manages the different hardware and software components of a computer in the most effective way. There are different types of operating system and everything comes with their own set of programs and software. You cannot expect a Linux program to have all [0]


  • Things You Never Knew About Your Operating System
    The advent of computers has brought about a revolution in our daily life. From computers that were so huge to fit in a room, we have come a very long way to desktops and even palmtops. These machines have become our virtual lockers, and a life without these network machines have become unimaginable. Sending mails, [0]


  • How To Fully Optimize Your Operating System
    Computers and systems are tricky and complicated. If you lack a thorough knowledge or even basic knowledge of computers, you will often find yourself in a bind. You must understand that something as complicated as a computer requires constant care and constant cleaning up of junk files. Unless you put in the time to configure [0]


  • The Top Problems With Major Operating Systems
    There is no such system which does not give you any problems. Even if the system and the operating system of your system is easy to understand, there will be some times when certain problems will arise. Most of these problems are easy to handle and easy to get rid of. But you must be [0]


  • 8 Benefits Of Linux OS
    Linux is a small and a fast-growing operating system. However, we can’t term it as software yet. As discussed in the article about what can a Linux OS do Linux is a kernel. Now, kernels are used for software and programs. These kernels are used by the computer and can be used with various third-party software [0]


  • Things Linux OS Can Do That Other OS Cant
    What Is Linux OS?  Linux, similar to U-bix is an operating system which can be used for various computers, hand held devices, embedded devices, etc. The reason why Linux operated system is preferred by many, is because it is easy to use and re-use. Linux based operating system is technically not an Operating System. Operating [0]


  • Packagekit Interview
    Packagekit aims to make the management of applications in the Linux and GNU systems. The main objective to remove the pains it takes to create a system. Along with this in an interview, Richard Hughes, the developer of Packagekit said that he aims to make the Linux systems just as powerful as the Windows or [0]


  • What’s New in Ubuntu?
    What Is Ubuntu? Ubuntu is open source software. It is useful for Linux based computers. The software is marketed by the Canonical Ltd., Ubuntu community. Ubuntu was first released in late October in 2004. The Ubuntu program uses Java, Python, C, C++ and C# programming languages. What Is New? The version 17.04 is now available here [0]


  • Ext3 Reiserfs Xfs In Windows With Regards To Colinux
    The problem with Windows is that there are various limitations to the computer and there is only so much you can do with it. You can access the Ext3 Reiserfs Xfs by using the coLinux tool. Download the tool from the  official site or from the  sourceforge site. Edit the connection to “TAP Win32 Adapter [0]


OSnews

  • Inside the Windows I/O Manager: deep dive into how read I/O requests are initialized
    In this article. I am going to explain the different steps the I/O manager follows when initializing an I/O operation starting from determining the right target, choosing the right path and finally sending the request to be processed by the right drivers. To make it easier I choose to focus on read requests only since the major steps are common by all types of requests. ↫ Win-Ware A very in-depth look at Windows I/O Manager.


  • A minimal kernel in Swift, running in QEMU
    At OSNews, we love us a hobby operating system project. I started a small experiment: writing a very basic kernel in Swift, and running on QEMU. The goal is obviously not to replace Linux or any other popular kernel, but just to have fun and understand what is required to make a program run without an operating system underneath it. Actually I made a similar experiment years before with arOS 10 years ago. For the moment, the kernel does only one thing: it prints a message through QEMU and then waits forever, which is enough for a first deep dive. ↫ Carette Antonin This is effectively a hello world! kernel, as it doesnt actually do much else at this point. Still, theres a ton of details in the article for the aspiring kernel developers among you.


  • Microsoft is overhauling and redesigning search in Windows, and it seems nice?
    Whenever Microsoft starts messing with something like the search function in Windows, a lot of people are going to be holding their breath and expecting the worst. Well, get ready, because theyre redesigning the whole thing. In July, we shared how we are improving the Windows Search Box with less clutter and more control. We introduced a calmer home screen, removed promotional content from web results, and gave you more choice over whether web and Microsoft Store suggestions appear. Today, we’re carrying those investments forward with a new Windows Search experience built on WinUI 3. This modern foundation makes Windows Search faster and more efficient with resources, while delivering an even more streamlined and focused design. ↫ Anshul Rawat at the Windows Blogs The company claims this new version of search is faster and uses less memory, which, if true, are very welcome improvements. Its also just a single column of results now, and theyre adding inline previews for things like weather and files on your machine, as well as for answers to all kinds of queries you might normally go to an online search engine for. You can now also use search to perform all kinds of tasks in Windows, like turning on dark mode, managing windows, and so on. All of this can be done using relatively natural language, and Microsoft claims theyve implemented better detection of typing errors and synonyms, which is quite welcome. Weirdly enough, though, its not yet integrated into the Start menu, since its a preview just for testers, but thats something theyre working on for future releases. Judging by the videos and screenshots, Im actually kind of positively surprised. This looks quite decent and nice, and if the promised performance improvements actually materialise, this may actually be an upgrade to search worth looking forward to. Of course, this is still Microsoft, so its just as likely theyll screw up somewhere between now and when this goes live to regular users. Still, I think it looks decent.


  • Chimera Linux: creating distribution build tooling for a small community
    Chimera Linux is a relatively new Linux distribution, and quite a unique on at that, as it combines the core tools from FreeBSD, the LLVM toolchain, and the Musl C library instead of the usual suspects. Despite being relatively new, it still has some serious pedigree as the project was started by Nina q66!, who was part of the Void Linux team. At Void, she maintained the various PowerPC/POWER ports of the distribution until Chimera became her sole focus. Nina published a detailed blog post today about how the Chimera team builds the tooling for their distribution, as well as the goals its trying to achieve. It covers everything from a bit of personal history, the rationale behind the project, who its catering to, how its tooling works and why, and the infrastructure theyve built that underpins it all. Theres a lot to process here, with one of the most interesting little details  at least to me, as someone who has two POWER9 machines  the fact that Chimera started with the ppc64le target only. The article is an incredibly interesting look at not just the how of Chimera, but also the why, which makes for some really fascinating reading.


  • KDE developer takes a look at COSMIC
    KDE contributor and developer Niccolò Venerandi has published an article about COSMIC, System76s brand new desktop environment. Its been almost a year since Ive last tried COSMIC; though development since then has mostly been centered around stability (going from late alpha to stable releases now!) there have been a fair bit of user-facing changes too which I adore. I thus have to ask myself: should I switch to COSMIC? The answer obviously is no, but thats just because I got addicted to KDE Plasma, so lets try to be more objective here. ↫ Niccolò Venerandi Honestly, this is one of the best reviews! Ive seen of COSMIC, and paints System76s hard work in a really positive light. Venerandi spots countless really nice touches hed love to see adopted by KDE, while also hitting on what I agree is COSMICs biggest shortcoming at this point: theres basically no ecosystem around it. COSMIC uses its own Rust-based toolkit instead of GTK or Qt, but of course, theres very few other applications that actually use said toolkit. The end result is that if you run COSMIC, youre going to have to supplement it with countless GTK and Qt application, none of which will inherit all the nice features, touches, and graphics from COSMIC. This isnt really a complaint about COSMIC itself or the work its developers are putting into it, but more a fact of life for such a new desktop environment using an otherwise unpopular (as of right now) toolkit. This may very well change in the future, but for now, if you choose to run COSMIC, youre going to have to accept a very inconsistent and messy desktop. This wont matter to everyone, but it sure does matter to me, and its the one reason why at this point I have zero interest in running COSMIC. I really hope this changes in the future  competition is good  but its going to be a long road.


  • Microsoft claims its optimising Windows for 8GB of RAM
    Speaking of Windows and performance, how about that RAM crisis? Microsoft is feeling the squeeze too, and is apparently doing work up and down the Windows stack to improve its memory consumption. Microsoft’s Windows chief Pavan Davuluri has admitted that the rising cost of memory is pushing the company to make Windows 11 use less RAM. Microsoft is working on the Windows memory manager, memory compression, WinUI 3 and WebView2, and has made “memory optimization for 8GB and above” an official priority for the rest of 2026. ↫ Abhijith M B at Windows Latest This might be the only positive consequence of the RAM crisis.


  • Windows legacy 8.3 filename support actually negatively affects performance
    To this day, Windows retains full support for the old MS-DOS 8.3 filename limitation, and it does this by creating 8.3 aliases for files with longer names. Apparently, this has a measurable effect on performance, so naturally, people are going to turn it off to make their Windows installations perform better. According to the user, this resulted in noticeably smoother scrolling in Tile view. They subsequently repeated the process on several folders they regularly use and reported that searching through files became much faster. The user also claimed that external hard drives became faster and that browsing an Android directory over USB or FTP behaved more like a regular Windows folder, including when copying large numbers of music files. ↫ Sayan Sen at Neowin You can disable this legacy feature in Windows per volume or globally, but Microsoft is warning users not to do so. Even in 2026, applications and registry entries may depend on 8.3 filenames being available, so removing them can lead to unexpected outcomes. Its just one of those things you wouldnt expect to still be around or have a measurable impact in the days of fast SSDs, but theres enough credibly evidence out there to suggest that yes, it actually does negatively affect performance. If youre doing a lot of file operations in Windows, it might be worthwhile to do some testing of your own to see if you can speed things up. Or, you know, you can just not use a house of cards disguised as a serious operating system.


  • Apple changes Full Disk Access permission in macOS
    Apples macOS has a Full Disk Access permission, designed to allow backup applications full access to, well, the disk, so they can perform their job properly. Apple posted a notice on its website that its going to further restrict this permission, because some applications were abusing this permission to gain access to users messages, emails, and so on, which it obviously isnt intended for. What kind of applications, you may ask? Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy. ↫ Announcement from Apple This was prompted by a story a few weeks ago, where Facebooks Muse AI! tool was apparently reading peoples private messages and other data, and even sent messages on users behalf, without informing its users. Its incredibly naive to think Facebook software in 2026 would not do creepy things, so Im honestly not at all surprised. It makes sense in Apples worldview to further restrict permissions in response, but Im sure more experienced macOS users are not going to like this.


  • Klassik brings KDE3s look and feel to KDE Plasma 6
    The KDE project recently brought back its classic Oxygen and Air themes, but what if you prefer something0 A little older? A modern recreation of the classic KDE 3 desktop experience for KDE Plasma 6, built entirely using Qt 6 and Qt Quick, with full support for Wayland and fractional scaling. ↫ Klassik GitHub page Neat.


  • SquirrelOS is an operating system named after the squirrel
    I like squirrels. Apparently, theres a SquirrelOS. Its a small hobby OS learning project from five years ago, developed by Immanuel Daviel A. Garcia. A simple DOS like OS made in Assembly and C with a ported version of Stephen Brennans Shell. ↫ SquirrelOS GitHub page Why do I like squirrels? I dont know man, theyre just cute.


Linux Journal - The Original Magazine of the Linux Community

  • Linux Moves Closer to Retiring the x32 ABI After Years of Limited Adoption
    by George Whittaker
    Linux kernel developers are renewing efforts to retire the x32 application binary interface (ABI), a little-used compatibility feature that attempted to combine the advantages of 64-bit processors with the smaller memory footprint of 32-bit applications. A revised patch series submitted on October 8, 2026, proposes the first steps toward disabling the interface, potentially ending support for an architecture experiment introduced more than 14 years ago.

    The latest proposal comes from Sebastian Andrzej Siewior, a Linux kernel developer at Linutronix who has been working on the removal effort throughout 2026. Rather than immediately deleting every component associated with x32, the proposed approach would first prevent the feature from being enabled through normal kernel configuration. This would give remaining users and distribution maintainers an opportunity to respond before the underlying implementation is removed.

    The effort reflects a broader challenge in Linux development: maintaining compatibility with older or rarely used technologies while keeping the kernel manageable, secure, and efficient. Although x32 offered theoretical performance and memory advantages, it never achieved widespread adoption. With conventional x86_64 software dominating modern Linux systems, developers are increasingly questioning whether the additional maintenance burden remains justified.
    Understanding the Linux x32 ABI
    The x32 ABI was introduced with Linux kernel 3.4 in 2012 as an alternative to conventional 32-bit and 64-bit application environments. Its goal was to provide applications with access to the architectural improvements of x86_64 processors while retaining smaller data types and pointers associated with 32-bit software.

    Traditional 32-bit x86 applications use the i386 ABI, which operates with a more limited register set and 32-bit execution conventions. Standard x86_64 applications, meanwhile, benefit from additional general-purpose registers, wider registers, and modern calling conventions, but they normally use 64-bit pointers. Those larger pointers can increase memory consumption in applications that maintain large numbers of pointer-heavy data structures.

    The x32 ABI attempted to offer a compromise. Applications would execute using the x86_64 instruction set and its larger register file while retaining 32-bit integers, long values, and pointers. This programming model is commonly described as ILP32, meaning that integers, long integers, and pointers are all 32 bits wide.

    The distinction can be illustrated by comparing the expected sizes of common C data types:
    Go to Full Article


  • Google's Kage Project Rethinks Linux Kernel Security With Isolated Device Drivers
    by George Whittaker
    Google is exploring a new approach to Linux kernel security that could significantly change how device drivers interact with the operating system. The experimental project, known as Kage, uses compiler-based sandboxing to isolate drivers inside the kernel, potentially limiting the damage caused by memory corruption, programming errors, and exploitable vulnerabilities without requiring drivers to run as separate user-space processes.

    The research was presented at the Linux Plumbers Conference 2026, held October 5–7, with Stanford University and Google researcher Zachary Yedidia discussing how LLVM's Lightweight Fault Isolation (LFI) technology can create restricted execution environments for native kernel code. Unlike conventional isolation techniques, which often depend on separate processes or virtual machines, Kage attempts to preserve the performance advantages of kernel-space execution while reducing the amount of memory individual drivers can access.

    Early prototypes have already demonstrated the concept using NVMe storage, networking, and Wi-Fi drivers. However, Kage remains an experimental research project rather than a feature available in mainstream Linux distributions. Its developers are still investigating performance, hardware access, and compatibility with more complicated drivers, including graphics hardware.
    Why Device Drivers Remain a Major Linux Security Challenge
    Linux device drivers are responsible for connecting the operating system to hardware components, including graphics cards, network adapters, storage controllers, USB devices, and wireless chipsets. Most traditional Linux drivers execute in kernel space, giving them privileged access to system resources and the ability to interact directly with hardware. This architecture is one reason Linux can deliver high performance across such a broad range of devices, but it also creates a significant security challenge.

    When an ordinary application encounters a memory error, the operating system can often terminate that process without affecting the rest of the system. Kernel drivers operate under different conditions. Because they typically share the kernel's address space and privileges, an invalid memory access or exploitable vulnerability can affect unrelated kernel components, potentially resulting in a system crash, privilege escalation, or complete compromise of the operating system.

    The challenge becomes more complicated when considering the enormous number of drivers supported by Linux. Some are maintained by large organizations with extensive testing infrastructure, while others receive contributions from smaller development teams or individual maintainers. Even carefully reviewed drivers can contain bugs, particularly when they interact with complicated hardware, asynchronous operations, and memory-management mechanisms.
    Go to Full Article


  • Speech Synthesis on Linux: Adding a Voice to Scripts and Systems
    by George Whittaker
    Linux users have long had a pragmatic relationship with text-to-speech. The classic open-source engines have been available for years, wired into accessibility tools and the occasional script, dependable but unmistakably robotic. They do the job where the job is simply to convert text to some kind of speech, but the mechanical output has kept them out of anything where the voice actually matters. The arrival of high-quality speech synthesis delivered over an API changes what is possible, letting Linux users add genuinely natural voices to scripts, services, and applications without hosting a heavyweight model themselves.
    The Familiar Trade-Off
    Anyone who has used the traditional Linux speech engines knows the trade-off. They are free, local, and scriptable, which fits the Linux ethos perfectly, but the voices are clearly synthetic. For accessibility and for utilitarian tasks where intelligibility is all that counts, that has been acceptable. For anything user-facing where the quality of the voice shapes the experience, it has not.

    The alternative of running a modern, high-quality speech model locally is possible but comes with real costs: significant computational requirements, model management, and the ongoing maintenance of a demanding piece of infrastructure. For many use cases, particularly on servers, embedded systems, or ordinary workstations, that overhead is disproportionate to the need. This is the gap that an API-based approach fills, offering the quality of a large modern model without the burden of hosting one.
    The API Approach on Linux
    Delivering speech synthesis over an API fits naturally into how Linux users already build things. Rather than installing and maintaining a model, you make a request to a service and receive audio back, which you can then play, save, or pipe into whatever comes next. A Go to Full Article


  • Archinstall 4.5 Released with AArch64 Support, Real-Time Kernels, and Major Installer Fixes
    by George Whittaker
    The Arch Linux project has released Archinstall 4.5, the latest version of its guided text-based installer, bringing expanded AArch64 support, new real-time Linux kernel options, additional translations, security improvements, and numerous fixes for installation workflows.

    Archinstall 4.5 was released on September 29, 2026, roughly three months after Archinstall 4.4. The new version arrives just ahead of Arch Linux's October installation media refresh and has already been packaged as archinstall 4.5-1 for Arch Linux repositories.

    While Archinstall remains optional, it provides users with a guided way to configure an Arch Linux installation without manually performing every step described in the Arch installation guide. Version 4.5 concentrates primarily on hardware support, installer reliability, security, and expanding the range of systems that can use the guided installation process.
    AArch64 Support Gets a Major Upgrade
    One of the biggest changes in Archinstall 4.5 is improved support for AArch64, the 64-bit ARM architecture.

    The installer can now handle GRUB and Limine EFI installations on AArch64 systems. It also gains support for the proper AArch64 root partition type GUID.

    Previously, parts of Archinstall's bootloader configuration were more heavily oriented toward x86_64 installations. The latest changes make its guided installation workflow more useful on ARM64 hardware.

    AArch64 has become increasingly important throughout the Linux ecosystem. The architecture can now be found in cloud servers, development boards, laptops, workstations, and specialized computing platforms.

    Supporting both GRUB and Limine EFI installations gives Archinstall more flexibility when preparing these systems.
    GRUB Can Now Be Installed on AArch64
    GRUB remains one of the most widely used Linux bootloaders, and Archinstall 4.5 extends its installation logic to AArch64 EFI systems.

    This allows ARM64 installations to use a bootloader workflow much closer to what Archinstall already provides on conventional x86_64 UEFI computers.

    The change doesn't mean every ARM device will automatically become compatible with Arch Linux. ARM hardware can still have highly platform-specific firmware and boot requirements.

    It does, however, remove an important Archinstall limitation for AArch64 machines that provide conventional UEFI environments.
    Limine EFI Support Expands to ARM64
    The same architectural expansion applies to Limine.

    Limine is a modern multiprotocol bootloader supported as one of Archinstall's bootloader choices. Archinstall 4.5 extends its EFI installation support to AArch64 as well.
    Go to Full Article


  • systemd 262 Released with Static PID 1, Intel TDX, TPM Improvements, and New Container Features
    by George Whittaker
    The systemd project has officially released systemd 262, delivering another substantial update to the system and service manager used by most major Linux distributions. The final release was tagged on September 22, 2026, following three release candidates earlier in the month.

    Systemd 262 introduces improvements across service management, containers, virtualization, encrypted storage, TPM security, networking, journal recovery, system updates, and unattended installations. Among the most interesting additions are the ability to build systemd as a single statically linked PID 1 binary, Intel TDX support in systemd-vmspawn, Live Update Orchestrator integration, improved TPM-backed encryption, and new fallback unit files embedded directly into the systemd manager.

    The release also contains a rather unusual development safeguard: an AI/LLM canary intended to help identify code contributions generated by AI that haven't been properly reviewed by a human before submission.
    systemd 262 Is Officially Available
    The final systemd 262 source was tagged by systemd developer Luca Boccassi on September 22.

    The upstream tag identifies commit 8cc40e0c5e9234bf45084751ac53b1fbfe70b492 as systemd v262, following release candidates published throughout September.

    The release has already begun reaching Linux distribution development repositories.

    Debian accepted systemd 262-1 into Debian Unstable on September 22, while Fedora has prepared systemd 262 packages for Fedora 45.

    As usual, the speed at which systemd 262 reaches ordinary users will depend on each distribution's update policy.
    systemd Can Now Become a Single Static PID 1 Binary
    One of the most interesting changes in systemd 262 is support for building systemd as a single statically linked PID 1 and executor binary.

    The feature is primarily intended for extremely small container environments.

    Normally, systemd depends on a collection of dynamically linked libraries and supporting components. That architecture makes sense for a complete Linux distribution, but containers sometimes need a much smaller runtime environment.

    The new static configuration makes it possible to create a more self-contained systemd executable suitable for minimal container images.

    These builds avoid dynamically loading optional libraries and use simplified mechanisms for resolving users and groups rather than relying on the complete Name Service Switch infrastructure.

    This doesn't mean normal Linux distributions will suddenly replace their standard systemd packages with a giant static executable. The capability is specifically useful for specialized container and minimal-system deployments.
    Go to Full Article


  • Ubuntu Container Escape Vulnerability Gets Public Exploit Before Kernel Patch Arrives
    by George Whittaker
    Ubuntu administrators running containerized workloads have a new Linux kernel security problem to watch closely. Public exploit code is now available for CVE-2026-80521, a Linux kernel use-after-free vulnerability that can allow an unprivileged process inside a container to escape and obtain root privileges on the underlying host.

    Security firm DepthFirst published its research and exploit on September 22, 2026, demonstrating the attack against Ubuntu 26.04 LTS. The underlying Linux kernel vulnerability had already been fixed upstream on August 6, but as of September 23, Ubuntu's security tracker still lists the main kernel package in Ubuntu 26.04 LTS as "Vulnerable, work in progress," while Ubuntu 24.04 LTS is also listed as vulnerable.

    The situation is particularly important for Docker, Kubernetes, cloud infrastructure, and other environments that run potentially untrusted workloads because the vulnerable kernel functionality can be reached through ordinary operations available inside standard containers.

    There is currently no confirmed evidence that CVE-2026-80521 is being actively exploited in real-world attacks, and the vulnerability isn't listed in CISA's Known Exploited Vulnerabilities catalog. The availability of working public exploit code nevertheless makes the patch gap considerably more important.
    CVE-2026-80521 Is a Linux Kernel Vulnerability
    Although Ubuntu is receiving much of the attention because the newly published exploit specifically targets it, CVE-2026-80521 is fundamentally a Linux kernel vulnerability.

    The problem exists in the kernel's AF_UNIX socket subsystem, specifically within its garbage collection mechanism.

    AF_UNIX sockets, commonly called Unix-domain sockets, provide local inter-process communication between applications running on the same system.

    Unlike conventional network sockets, they don't need to communicate across a network. They are widely used by Linux applications and services for fast communication between local processes.

    They also support passing file descriptors between processes through SCM_RIGHTS messages, and it is the kernel's management of these references that creates the conditions for CVE-2026-80521.
    A Race Condition Leads to Use-After-Free
    At the technical level, CVE-2026-80521 involves a race condition inside the AF_UNIX garbage collector.

    The kernel needs to track references between Unix sockets when file descriptors are passed between processes. Circular references can develop, where one socket effectively references another while that socket references something else in the same group.

    Linux represents these relationships internally and periodically determines which references can safely be removed.
    Go to Full Article


  • Fedora Linux 45 Beta Released with Python 3.15, GCC 16.2, and Major Security Changes
    by George Whittaker
    The Fedora Project has officially released Fedora Linux 45 Beta, giving users an early look at the technologies expected to form the foundation of the final Fedora 45 release. The beta became available on September 15, 2026, after Fedora's Quality team approved Release Candidate 1.3 for publication.

    Fedora 45 Beta brings significant changes throughout the operating system, including Python 3.15, GCC 16.2, glibc 2.44, GNU Binutils 2.47, Go 1.27, LLVM 23, Podman 6, stricter RPM signature verification, improved DNF5 protections, a new userspace virtual console, standardized desktop secret storage, and substantial installer improvements.

    The release is available across Fedora Workstation, KDE Plasma Desktop, Server, Cloud, IoT, Atomic Desktops, Spins, and Labs, although a few prerelease images are excluded.
    Fedora 45 Beta Is Now Available
    Fedora Linux 45 Beta represents the final major public testing milestone before Fedora 45 reaches stable status.

    Fedora describes its beta releases as code-complete previews that closely represent what users should expect from the final version. Development isn't finished, however, and bugs or incomplete migrations can still be discovered during real-world testing.

    Fedora 45 Beta is currently available in several major editions:
    Fedora Workstation 45 Beta Fedora KDE Plasma Desktop 45 Beta Fedora Server 45 Beta Fedora Cloud 45 Beta Fedora IoT 45 Beta Fedora Atomic Desktops Fedora Spins Fedora Labs
    Existing Fedora installations can also be upgraded to the beta using Fedora's DNF system-upgrade process.

    Fedora's official Workstation download page confirms Beta 1.3 images for both x86_64 and AArch64 systems.
    A New Virtual Console with kmscon
    One of Fedora 45's more unusual system-level changes is the replacement of the traditional in-kernel console with kmscon.

    Fedora describes kmscon as a modern userspace virtual terminal implementation that provides smoother rendering, better internationalization and font handling, improved visual integration, and security improvements compared with the older console infrastructure.

    This affects the virtual terminals users encounter outside their normal graphical desktop session.

    Most desktop users spend relatively little time interacting directly with these consoles, but they remain important for troubleshooting, system administration, servers, recovery operations, and systems running without a graphical environment.

    Moving that functionality into userspace also gives Fedora more flexibility for future development instead of relying entirely on the legacy kernel console implementation.
    Go to Full Article


  • Thunderbird 156 Released with OAuth Improvements, OpenPGP Updates, and Major Linux Fixes
    by George Whittaker
    The Thunderbird team has officially released Thunderbird 156, bringing another round of new features, security improvements, authentication enhancements, and reliability fixes to the popular open-source email client. Released on September 15, 2026, the update is available for Linux alongside Windows and macOS.

    Thunderbird 156 is not a dramatic redesign of the desktop mail client. Instead, it concentrates on improving areas that matter to everyday users and system administrators, including OAuth authentication, OpenPGP, POP3, IMAP, Exchange Web Services, SMTP, attachments, calendars, enterprise policies, and security.

    For Linux users in particular, the release delivers several fixes affecting common mail protocols and account configurations while retaining support for Linux environments using GTK+ 3.14 or newer.
    Thunderbird 156 Arrives on Linux
    Thunderbird 156 follows version 154, which arrived in August with features including optional system tray operation and Microsoft Graph support for Microsoft 365.

    Version 156 continues the project's monthly release cycle with a more targeted collection of authentication, security, compatibility, and reliability improvements.

    According to Thunderbird's official release notes, version 156 requires:
    Linux: GTK+ 3.14 or newer Windows: Windows 10 or newer macOS: macOS 10.15 or newer
    Thunderbird 156 was officially released on September 15.

    Linux distribution availability will vary because distributions can package Thunderbird according to their own schedules. Users receiving Thunderbird through another packaging channel may therefore see version 156 at a different time.
    Custom OAuth Support Expands
    One of the most significant areas of development in Thunderbird 156 is OAuth authentication.

    Thunderbird now supports custom OAuth configurations containing an issuer ID and client secret for IMAP and POP3 accounts. Custom OAuth support has also been extended specifically to POP3.

    OAuth has become increasingly important as email providers move away from conventional username-and-password authentication toward token-based authentication.

    For Thunderbird, broader custom OAuth support means users and organizations have greater flexibility when connecting the client to mail services that don't fit Thunderbird's predefined provider configurations.

    This can be particularly useful in enterprise environments, self-hosted infrastructure, and organizations operating their own identity systems.
    Exchange Custom OAuth Setup Fixed
    Exchange users receive an important related correction.
    Go to Full Article


  • KDE Plasma 6.7.5 Released with Discover, KWin, Wayland, and HDR Fixes
    by George Whittaker
    The KDE Project has officially released KDE Plasma 6.7.5, delivering another round of bug fixes and stability improvements for the Plasma 6.7 desktop series. Released on September 8, 2026, the update contains roughly a month of fixes and updated translations contributed since Plasma 6.7.4 arrived in early August.

    Unlike a major Plasma release, version 6.7.5 doesn't introduce a large collection of new desktop features. Instead, KDE has focused on fixing problems affecting Discover, KWin, Wayland, networking, System Monitor, Plasma Desktop, RPM-OSTree systems, Snap updates, HDR rendering, and several other components.

    For users already running Plasma 6.7, this makes version 6.7.5 primarily a maintenance upgrade intended to make the desktop more dependable ahead of the next major Plasma series.
    KDE Plasma 6.7.5 Arrives as the September Bugfix Release
    KDE describes Plasma 6.7.5 as its September bugfix release for the Plasma 6 desktop.

    The broader Plasma 6.7 series originally arrived in June 2026, followed by a succession of maintenance releases:
    Plasma 6.7.1 on June 23 Plasma 6.7.2 on June 30 Plasma 6.7.3 on July 14 Plasma 6.7.4 on August 4 Plasma 6.7.5 on September 8
    KDE's official download infrastructure confirms that the Plasma 6.7.5 source packages became available on September 8.

    This slower maintenance cadence later in a Plasma series is normal. Once the most urgent post-release problems have been addressed, KDE generally shifts more development attention toward the next feature release while continuing to provide important fixes for the current branch.
    Discover Receives Several Important Fixes
    KDE's Discover software center receives some of the most noticeable improvements in Plasma 6.7.5.

    One particularly annoying problem could cause Discover to become stuck while checking for updates when its Snap backend was installed but no Snap applications actually had updates available.

    That problem has now been corrected.

    Discover also behaves more reliably when fwupd, the Linux firmware update service, is unavailable. Previously, a broken or intentionally masked fwupd service could interfere with Discover's normal operation. Plasma 6.7.5 allows the rest of the application to continue functioning correctly in that situation.

    This is useful for systems where firmware updating isn't supported, where administrators intentionally disable the service, or where fwupd encounters a configuration problem.
    Firmware Updates No Longer Incorrectly Require Reboots
    Another Discover correction addresses a regression involving firmware updates.
    Go to Full Article


  • Slackware 16 Alpha 1 Released with Linux 6.18 LTS, GCC 16.2, and Plasma 6
    by George Whittaker
    One of Linux's oldest surviving distributions is moving closer to its next major release. Slackware 16 Alpha 1 became available on September 5, 2026, marking the first formal alpha milestone on the road toward Slackware Linux 16. The release follows a major rebuild of Slackware-current using a substantially newer GNU toolchain and brings together several upgrades that have accumulated since Slackware 15.0 arrived more than four years ago.

    The alpha combines Linux 6.18 LTS, GCC 16.2.0, glibc 2.44, GNU Binutils 2.47, KDE Plasma 6, and numerous updated user-space packages while retaining much of the deliberately traditional architecture that has distinguished Slackware for decades.

    For longtime Slackware users, Alpha 1 is particularly significant because it provides the clearest indication yet that the lengthy Slackware 16 development cycle is moving toward an eventual stable release.
    Slackware 16 Finally Reaches Alpha
    Slackware doesn't operate according to the predictable six-month or annual release schedules used by many other Linux distributions.

    Instead, development takes place continuously through the Slackware-current branch. Patrick Volkerding and other contributors update that development tree until it reaches a state considered suitable for a stable release.

    The previous major version, Slackware 15.0, was released in February 2022. More than four and a half years later, Slackware-current has now officially reached the first alpha milestone for version 16.

    Volkerding marked the milestone following a complete rebuild of the distribution with its newly upgraded compiler, C library, and binary utilities.

    The short changelog announcement even suggested there might finally be "a light at the end of the tunnel," a promising indication for Slackware users waiting for version 16.
    The Entire Distribution Was Rebuilt
    One of the most consequential changes behind Alpha 1 is a complete package rebuild.

    Slackware's development toolchain has moved to:
    GCC 16.2.0 glibc 2.44 GNU Binutils 2.47
    After introducing those components, Slackware rebuilt the distribution's packages against the updated environment.

    A full rebuild is much more significant than simply replacing three packages.

    GCC is responsible for compiling much of the software distributed with Slackware, glibc provides fundamental C library functionality used throughout Linux user space, and Binutils supplies essential development utilities including the GNU assembler and linker.

    Rebuilding the distribution against these versions gives Slackware 16 a considerably newer foundation than its predecessor.
    Go to Full Article


Page last modified on November 02, 2011, at 10:01 PM