All posts by corbet

Security updates for Wednesday

Post Syndicated from corbet original https://lwn.net/Articles/943087/

Security updates have been issued by Debian (qpdf, ring, and tryton-server), Fedora (mingw-qt5-qtbase and moby-engine), Red Hat (cups, kernel, kernel-rt, kpatch-patch, librsvg2, and virt:rhel and virt-devel:rhel), and Ubuntu (amd64-microcode, firefox, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop,
linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15, linux, linux-aws, linux-aws-5.4, linux-gcp, linux-hwe-5.4, linux-kvm,
linux-oracle, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-6.2, linux-azure, linux-hwe-6.2, linux-ibm,
linux-kvm, linux-lowlatency, linux-lowlatency-hwe-6.2, linux-raspi, linux-bluefield, linux-ibm, linux-oem-6.1, and openjdk-lts, openjdk-17).

Security updates for Tuesday

Post Syndicated from corbet original https://lwn.net/Articles/943006/

Security updates have been issued by Debian (flask-security and opendmarc), Fedora (qemu), Oracle (rust and rust-toolset:ol8), Red Hat (cups and libxml2), Scientific Linux (cups), SUSE (ca-certificates-mozilla, chromium, clamav, freetype2, haproxy, nodejs12, procps, and vim), and Ubuntu (faad2, json-c, libqb, linux, linux-aws, linux-lts-xenial, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-gkeop, linux-gkeop-5.15, and linux-gke, linux-ibm-5.4).

Rest in peace Satoru Ueda

Post Syndicated from corbet original https://lwn.net/Articles/942973/

[Satoru Ueda]

The OpenChain site carries the sad news of the
passing of Satoru Ueda
. Your editor first met Ueda San at the 2007 Linux Foundation Japan Symposium, where a
small group of dedicated developers and managers was working hard to bring
open-source development practices to the country. Ueda San was always a
strong advocate for this cause and deserves much credit for the success of
Linux and open source in Japan. He was also always a warm and welcoming
person; he will be much missed.

[$] Development statistics for the 6.5 kernel

Post Syndicated from corbet original https://lwn.net/Articles/941675/

The 6.5 kernel was released
on August 27 after a nine-week development cycle. By that time, some
13,561 non-merge changesets had found their way into the mainline
repository, the lowest number seen since the 5.15 release (12,377
changesets) in late 2021. Nonetheless, quite a bit of significant work was
done in this cycle; read on for a look at where that work came from.

The 6.5 kernel has been released

Post Syndicated from corbet original https://lwn.net/Articles/942876/

Linus has, as expected, released the 6.5
kernel
.

I still have this nagging feeling that a lot of people are on
vacation and that things have been quiet partly due to that. But
this release has been going smoothly, so that’s probably just me
being paranoid. The biggest patches this last week were literally
just to our selftests.

Headline features in 6.5 include
faster booting on large x86 systems,
Arm Permission Indirection Extension
support,
Rust 1.68.2 support,
unaccepted memory handling,
mount beneath” support for filesystems,
the cachestat() system call,
the ability to pass a pidfd via a SCM_CREDENTIALS control message,
scope-based resource management for
internal kernel code,
the deprecation of the SLAB allocator,
and more. See the LWN merge-window summaries
(part 1,
part 2) and the (in-progress)
KernelNewbies 6.5 page
for details.

[$] The OpenSprinkler controller

Post Syndicated from corbet original https://lwn.net/Articles/940509/

The more one pays attention to the Internet of Things (IoT), the more one
learns to appreciate simple, unconnected devices. Your editor long ago
acquired an aversion to products that advertise themselves as “smart”
or “WiFi-enabled”. There can be advantages, though, to devices that
contain microprocessors, are Internet connected, and are remotely
accessible, if they are implemented well. The OpenSprinkler sprinkler timer would
appear to be a case in point.

[$] A more dynamic software I/O TLB

Post Syndicated from corbet original https://lwn.net/Articles/940973/

The kernel’s software I/O translation lookaside buffer (“swiotlb”) is an
obscure corner of the DMA-support layer. The swiotlb was initially
introduced to enable DMA for devices with special challenges, and one might
have expected it to fade away as newer peripherals came along. Instead,
though, the swiotlb has turned out to be useful in places outside of its
original use cases. This
patch set
from Petr Tesarik now aims to update the swiotlb with an eye
toward its continuing use indefinitely into the future.

Rust 1.72.0 released

Post Syndicated from corbet original https://lwn.net/Articles/942656/

Version
1.72.0
of the Rust compiler has been released. Changes include
improved diagnostics and the removal of a limit on const evaluation:

To prevent user-provided const evaluation from getting into a
compile-time infinite loop or otherwise taking unbounded time at
compile time, Rust previously limited the maximum number of
statements run as part of any given constant evaluation. However,
especially creative Rust code could hit these limits and produce a
compiler error. Worse, whether code hit the limit could vary wildly
based on libraries invoked by the user; if a library you invoked
split a statement into two within one of its functions, your code
could then fail to compile.

Now, you can do an unlimited amount of const evaluation at compile
time.

[$] Defending mounted filesystems from the root user

Post Syndicated from corbet original https://lwn.net/Articles/941764/

Making a filesystem implementation robust in the face of maliciously
created filesystem images is a challenging task even when the
implementation is actively maintained, which many in the kernel are not. There is a way to
make that task even harder, though: modify that filesystem image behind the
implementation’s back while it is mounted. A recent discussion on the
linux-fsdevel list reveals an ongoing disagreement over whether (and how)
this threat should be addressed.

[$] DNF5 delayed

Post Syndicated from corbet original https://lwn.net/Articles/941154/

It is fair to say that the DNF package
manager
is not the favorite tool of many Fedora users. It was brought
in as a replacement for Yum but got off to a
rather rocky start
; DNF has
stabilized over the years, though and the complaints have subsided. That can only
mean one thing: it must be time to throw it away and start over from the
beginning. The replacement, called DNF5, was slated to be a part of the
Fedora 39 release, due in October, but that is not going to happen.

Security updates for Friday

Post Syndicated from corbet original https://lwn.net/Articles/942076/

Security updates have been issued by Debian (chromium, rar, and unrar-nonfree), Fedora (microcode_ctl, trafficserver, and webkitgtk), SUSE (ImageMagick, kernel, nodejs16, nodejs18, postgresql12, postgresql15, re2c, and samba), and Ubuntu (ghostscript, haproxy, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-hwe-5.15, linux-ibm,
linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15,
linux-raspi, linux-hwe-5.4, linux-xilinx-zynqmp, poppler, and zziplib).

SUSE to be acquired, taken private

Post Syndicated from corbet original https://lwn.net/Articles/941985/

SUSE’s long story of corporate ownership is gaining a new chapter; the
company has announced
that it’s majority shareholder (Marcel LUX III SARL) will acquiring the
remaining shares, and will take the company private and off of the stock
exchange. “SUSE’s Management Board and Supervisory Board support the
strategic opportunity from delisting of the company as it will allow SUSE
to focus fully on its operational priorities and execution of its long-term
strategy.

[$] Out-of-memory victim selection with BPF

Post Syndicated from corbet original https://lwn.net/Articles/941614/

In its default configuration, the Linux kernel will allow processes to
allocate more memory than the system can actually provide; this policy
enables better utilization of physical memory and works just fine — most of
the time. On occasions, though, the kernel may find itself unable to
provide memory that processes may think already belongs to them. If the
situation gets bad enough, the only solution (short of rebooting) is to
declare a sort of memory bankruptcy and write off some of the kernel’s
debts by killing one or more processes. Over the years, a great deal of
effort has gone into heuristics to select the processes that the user is
least likely to miss. This problem is still clearly not solved to
everybody’s satisfaction, though, so it was only a matter of time before
somebody introduced a way to select the out-of-memory (OOM) victim using
BPF.

HashiCorp’s license change

Post Syndicated from corbet original https://lwn.net/Articles/941799/

Readers have been pointing us to HashiCorp’s announcement
that it is moving to its own “Business Source License” for some of its
(formerly) open-source products. Like other companies (example) that have taken this path, HashiCorp
is removing the freedom to use its products commercially in ways that it
sees as competitive. This is, in a real sense, an old and tiresome story.

The lessons to be drawn from this change are old as well. One is to beware
of depending on any platform, free or proprietary, that is controlled by a
single company. It is a rare company that will not try to take advantage
of that control at some point.

The other is to beware of contributor license agreements. HashiCorp’s
agreement used
to read
that it existed “to ensure that our projects remain licensed
under Free and Open Source licenses
“; the current version doesn’t say that
anymore. But both versions give HashiCorp the right to play exactly this
kind of game with any code contributed by outsiders. Developers who were
contributing to a free-software project will now have their code used in a
rather more proprietary setting. When a company is given the right to take
somebody else’s code proprietary, many of them will eventually make use of
that right.