All posts by corbet

Security updates for Tuesday

Post Syndicated from corbet original https://lwn.net/Articles/1002496/

Security updates have been issued by Debian (gstreamer1.0), Fedora (jupyterlab and python-notebook), Oracle (gimp:2.8.22, gstreamer1-plugins-base, gstreamer1-plugins-good, kernel, php:8.2, postgresql, and python3.11), SUSE (aws-iam-authenticator, firefox, installation-images, kernel, libaom, libyuv, libsoup, libsoup2, python-aiohttp, socat, thunderbird, and vim), and Ubuntu (curl, Docker, imagemagick, and kernel).

[$] Facing the Git commit-ID collision catastrophe

Post Syndicated from corbet original https://lwn.net/Articles/1001526/

Commits in the Git source-code management system are identified by the
SHA-1 hash of their contents — though the specific hash may change someday. The full hash is a
160-bit quantity, normally written as a 40-character hexadecimal string.
While those strings are convenient for computers to work with, humans find
them to be a bit unwieldy, so it is common to abbreviate the hash values to
shorter strings. Geert Uytterhoeven recently proposed
increasing the length of those abbreviated hashes as used in the kernel
community, but the problem he was working to solve may not be as urgent as
it seems.

[$] A last look at the 4.19 stable series

Post Syndicated from corbet original https://lwn.net/Articles/1000933/

The release of the 4.19.325 stable
kernel update
on December 5 marked the end of an era of sorts.
This kernel had been supported for just over six years since its initial
release
in October 2018; over that time, 325 updates were released,
adding 30,109 fixes. Few Linux kernels receive public support for so long;
it is worth taking a look at this kernel’s history to see how it played
out.

Systemd 257 released

Post Syndicated from corbet original https://lwn.net/Articles/1001657/

Systemd 257 has been released. As usual, the list of changes is long; it
includes support for multipath TCP in socket units, the ability to run
processes as init in their own PID namespace, a new tool for signing EFI
binaries for secure boot,
and a superhero emoji in the run0 shell prompt, among many other things.
Also, support for version-1 control groups has been disabled and requires
an elaborate dance to re-enable; it will be removed entirely in the next
release, along with support for System V service scripts.

GNU Shepherd 1.0.0 released

Post Syndicated from corbet original https://lwn.net/Articles/1001599/

Version
1.0.0
of the GNU Shepherd service manager has been released after a
mere 21 years of development.

This 1.0.0 release is published today because we think Shepherd has
become a solid tool, meeting user experience standards one has come
to expect since systemd changed the game of free init systems and
service managers alike. It’s also a major milestone for Guix, which
has been relying on the Shepherd from a time when doing so counted
as dogfooding.

Security updates for Tuesday

Post Syndicated from corbet original https://lwn.net/Articles/1001597/

Security updates have been issued by AlmaLinux (postgresql:15, postgresql:16, and ruby:3.1), Debian (jinja2), Fedora (python-multipart, python-python-multipart, python3.12, retsnoop, rust-rbspy, rust-rustls, and zabbix), Oracle (kernel, libsoup, postgresql:12, postgresql:13, postgresql:15, postgresql:16, redis:7, and ruby:3.1), SUSE (nodejs18, pam, qt6-webengine, and radare2), and Ubuntu (dogtag-pki, linux-intel-iotg, linux-intel-iotg-5.15, ofono, rabbitmq-server, and webkit2gtk).

A vulnerability in the OpenWrt attended sysupgrade server

Post Syndicated from corbet original https://lwn.net/Articles/1001441/

The OpenWrt project has issued an
advisory
regarding a vulnerability found in its Attended Sysupgrade
Server that could allow compromised packages to be installed on a router by
an attacker. No official OpenWrt images were affected, and the
vulnerability is not known to be exploited, but users who have installed
images created with an instance of this server are recommended to
reinstall.

For a detailed description of how the exploit works, see this
blog post
.

Then, as the hash collision occurred, the server returns the
overwritten build artifact to the legitimate request that requests
the following packages. […]

By abusing this, an attacker could force the user to upgrade to the
malicious firmware, which could lead to the compromise of the
device.

Kernel prepatch 6.13-rc2

Post Syndicated from corbet original https://lwn.net/Articles/1001435/

The 6.13-rc2 kernel prepatch is out for
testing. “The diffstat looks a bit unusual with 80%+ drivers, and a lot of it
one-liners, but that’s actually just because of a couple of automated
scripts that got run after -rc1 for some cleanups. Nothing
particularly interesting, but it makes for a lot of noise in the diff.

One of those scripts was the EXPORT_SYMBOL_NS() change (to make it
use a quoted string for the namespace name) described in this article.

[$] Freezing out the page reference count

Post Syndicated from corbet original https://lwn.net/Articles/1000654/

The page
structure
sits at the core of the kernel’s memory-management subsystem
(for now), and a key part of that structure is its reference count, stored
in refcount. The page reference count tells the kernel how many
users a given page has and when it can be freed. That count is not needed
for every page in the system, though. Matthew Wilcox has recently resurrected
an old
patch set
that expands the concept of a “frozen” page — one that lacks a
meaningful reference count — to the immediate benefit of the slab allocator
but in the service of a longer-term goal as well.

Apertis v2024 released

Post Syndicated from corbet original https://lwn.net/Articles/1001013/

Apertis is a Collabora-developed
Debian derivative distribution designed to be incorporated into electronic
devices; the v2024
release
is now available. It is now based on the Bookworm release, and
includes support for Podman, ONNX
Runtime
, OP-TEE, and more.

Apertis relies on the Debian Free Software Guidelines to ensure all
software shipped is open source or, in limited cases, at least
freely distributable. However, for some customers this is not
enough to be able to adopt OSS solutions as in their evaluations
some provisions in common licenses like the GPL-3 are at odds with
regulatory constraints they are subject to. Apertis does not set to
solve this decades-long debate, and instead its goal is to increase
the adoption of modern, maintained OSS solutions in markets where
this has historically been a challenge. To enable this, Apertis
supports avoiding the use of any software under some licenses (like
the [GPL v3.0 license family) on target images, while still making
them fully available for development and for customers that do not
share those licensing concerns. To avoid these licenses, Apertis
uses more modern alternatives instead of relying on outdated and
unmaintained pre-GPL-3 versions. For instance, coreutils and
findutils (GPL-3+) are replaced in Apertis by rust-coreutils and
rust-findutils.

Mozilla’s new branding strategy

Post Syndicated from corbet original https://lwn.net/Articles/1000880/

Mozilla would
appear to have concluded
that the solution to its problems is an
extensive rebranding effort:

We teamed up with global branding powerhouse Jones Knowles Ritchie
(JKR) to revamp our brand and revitalize our intentions across our
entire ecosystem. At the heart of this transformation is making
sure people know Mozilla for its broader impact, as well as
Firefox. Our new brand strategy and expression embody our role as a
leader in digital rights and innovation, putting people over
profits through privacy-preserving products, open-source developer
tools, and community-building efforts.

Walleij: New ARM32 Security Features in v6.10

Post Syndicated from corbet original https://lwn.net/Articles/1000727/

Linus Walleij writes
about a pair of security features for 32-bit Arm systems
; these landed
in 6.10, but, he says, have now stabilized to the point that distributors
may want to enable them.

PAN is an abbreviation for the somewhat grammatically incorrect
Privileged Access Never. […]

For modern ARM32 systems with large memories configured to use LPAE
nothing like PAN was available: this version of the MMU simply did
not implement a PAN option.

As of the patch originally developed by Catalin Marinas, we deploy
a scheme that will use the fact that LPAE has two separate
translation table base registers (TTBR:s): one for userspace
(TTBR0) and one for kernelspace (TTBR1).

[$] The return of RWF_UNCACHED

Post Syndicated from corbet original https://lwn.net/Articles/998783/

Linux offers two broad ways of performing I/O to files. Buffered I/O,
which is the usual way of accessing a file, stores a copy of the
transferred data in the kernel’s page cache to speed future accesses.
Direct I/O, instead, moves data directly between the storage device and a
user-space buffer, avoiding the page cache. Both modes have their
advantages and disadvantages. In 2019, Jens Axboe proposed an uncached buffered mode to get some
of the advantages of both, but that effort stalled at the time. Now, uncached buffered
I/O is back
with some impressive performance results behind it.

Security updates for Tuesday

Post Syndicated from corbet original https://lwn.net/Articles/1000591/

Security updates have been issued by AlmaLinux (container-tools:rhel8, kernel, kernel-rt:4.18.0, kernel:4.18.0, pam, pam:1.5.1, perl-App-cpanminus, perl-App-cpanminus:1.7044, python-tornado, tigervnc, tuned, and webkit2gtk3), Debian (needrestart and webkit2gtk), Mageia (firefox, glib2.0, krb5, and thunderbird), Red Hat (firefox, postgresql, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and thunderbird), SUSE (editorconfig-core-c, kernel, php7, php8, python, python-tornado6, python3-virtualenv, python310, python39, thunderbird, wget, and wireshark), and Ubuntu (firefox and haproxy).

[$] The rest of the 6.13 merge window

Post Syndicated from corbet original https://lwn.net/Articles/998990/

The 6.13 merge window closed with the release of 6.13-rc1 on December 1. By that time,
11,307 non-merge commits had been pulled into the mainline
repository; about 9,500 of those landed after our first-half merge-window summary was
written. There was a lot of new material in these patches, including
architecture-support improvements, new BPF features, an efficient way to
add guard pages to an address space, more Rust support, a vast number of
new device drivers, and more.

Kernel prepatch 6.13-rc1

Post Syndicated from corbet original https://lwn.net/Articles/1000379/

Linus has released 6.13-rc1 and closed the
merge window for this release. “And for once – possibly the first time
ever – it looks like the release cycle doesn’t clash horribly up with
the holiday season, and we’ll have time both to stabilize this release,
_and_ the work for 6.14 won’t be starting until well into January.