All posts by daroc

Security updates for Friday

Post Syndicated from daroc original https://lwn.net/Articles/1015055/

Security updates have been issued by Debian (chromium), Fedora (fluent-bit, openssh, php, and webkitgtk), Mageia (freerdp), Oracle (libreoffice and webkit2gtk3), Red Hat (kernel-rt), Slackware (libarchive), SUSE (apptainer, gitea-tea, libxml2, tomcat, webkit2gtk3, and wpa_supplicant), and Ubuntu (libxslt and pam-pkcs11).

[$] Better CPU vulnerability mitigation configuration

Post Syndicated from daroc original https://lwn.net/Articles/1013640/

Modern CPUs all have multiple hardware vulnerabilities that the kernel needs to mitigate;
the 6.13 kernel has workarounds for 14 security-sensitive CPU bugs just on x86_64.
Several of those have multiple variants,
or multiple mitigations that apply on different microarchitectures. There are
different kernel command-line options for each of these mitigations, which leads
to a confusing situation for users trying to figure out how to configure their
systems. David Kaplan recently posted

a patch set
that adds a single, unified command-line option for controlling
mitigations and
simplifies the logic for detecting, configuring, and
applying them as well.
If it is merged, the patch set could
make it much easier for users to navigate the complicated web of CPU
vulnerabilities and their mitigations.

Security updates for Friday

Post Syndicated from daroc original https://lwn.net/Articles/1014183/

Security updates have been issued by Fedora (iniparser, thunderbird, trafficserver, and xorg-x11-server), Mageia (opensc), Oracle (.NET 8.0, .NET 9.0, gcc, kernel, and libxml2), Red Hat (firefox, grub2, and krb5), Slackware (libxslt), SUSE (amazon-ssm-agent, bsdtar, build, ffmpeg-4, forgejo-runner, kernel, python, python3, python313, rubygem-rack-1_6, and tailscale), and Ubuntu (linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15).

[$] Zig’s 0.14 release inches the project toward stability

Post Syndicated from daroc original https://lwn.net/Articles/1012809/

The Zig project has

announced
the release of the 0.14 version of the language,
including changes from more than 250 contributors. Zig is a low-level,
memory-unsafe programming language that aims to compete with C instead of
depending on it. Even though the language has not yet had a stable release,
there are a number of projects using it as an alternative to C with better
metaprogramming.
While the project’s release
schedule has been a bit inconsistent, with the release of version 0.14 being

delayed

several times, the release contains a number of new convenience features,
broader architecture support, and the next steps toward removing Zig’s
dependency on LLVM.

The LLVM project stabilizes its Fortran compiler

Post Syndicated from daroc original https://lwn.net/Articles/1013844/

The LLVM project’s Fortran compiler, which has for many years gone by the name “flang-new”, will now simply be “flang”, starting from LLVM’s 20.1.0 release on March 4. The

announcement
, which includes details about the history of flang, comes after a long period of development and discussion. The community has considered renaming flang several times before now, but has always held off out of a feeling that the compiler was not yet ready. Now, the members of the project believe that flang has become stable and complete enough to earn its name.

We are almost 10 years from the first announcement of what would
become LLVM Flang. In the LLVM monorepo alone there have been close
to 10,000 commits from around 400 different contributors. Undoubtedly
more in Classic Flang before that.

Python tail-call speedup based on LLVM regression

Post Syndicated from daroc original https://lwn.net/Articles/1013581/

The Python project’s recent switch to a tail-calling interpreter may not provide as large a speed advantage as initially thought. A blog post from Nelson Elhage gives the details. In short, switching to a tail-call-based interpreter accidentally works around an unfixed regression in LLVM 19. On other compilers, the performance benefit (while still present) is more moderate.

When the tail-call interpreter was announced, I was surprised and impressed by the performance improvements, but also confused: I’m not an expert, but I’m passingly-familiar with modern CPU hardware, compilers, and interpreter design, and I couldn’t explain why this change would be so effective. I became curious – and perhaps slightly obsessed – and the reports in this post are the result of a few weeks of off-and-on compiling and benchmarking and disassembly of dozens of different Python binaries, in an attempt to understand what I was seeing.

Security updates for Monday

Post Syndicated from daroc original https://lwn.net/Articles/1013561/

Security updates have been issued by Debian (openvpn and thunderbird), Fedora (buildah, chromium, podman-tui, python-spotipy, qt6-qtwebengine, and vim), Mageia (chromium-browser-stable and gpac), Oracle (krb5), Red Hat (firefox, kernel, kernel-rt, libxml2, and pcs), SUSE (buildah, chromedriver, chromium, firefox, go1.23, go1.24, grype, python, python311-GitPython, ruby3.4-rubygem-rack, thunderbird, and xen), and Ubuntu (xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04).

[$] Hash-based module integrity checking

Post Syndicated from daroc original https://lwn.net/Articles/1012946/

On January 20, Thomas Weißschuh shared a new

patch set
implementing an alternate method for checking the integrity of
loadable kernel modules. This mechanism, which checks module integrity based
on hashes computed at build time instead of using cryptographic signatures,
could enable reproducible kernel builds in more contexts. Several distributions
have already expressed interest in the patch set if Weißschuh can get it
into the kernel.

Security updates for Friday

Post Syndicated from daroc original https://lwn.net/Articles/1013336/

Security updates have been issued by Debian (chromium), Fedora (firefox and man2html), Mageia (erlang, ffmpeg, and vim), Oracle (doxygen, firefox, python-jinja2, squid, and webkit2gtk3), Red Hat (nodejs:18), SUSE (emacs, go1.23, go1.24, and pcp), and Ubuntu (ansible, firefox, linux-azure, linux-nvidia, and python-django).

[$] Two new graph-based functional programming languages

Post Syndicated from daroc original https://lwn.net/Articles/1011803/

Functional programming languages have a long association with graphs. In the
1990s, it was even thought that parallel graph-reduction
architectures could make functional programming languages much faster than their
imperative counterparts. Alas, that prediction mostly failed to materialize.
Even though graphs are still used as a theoretical formalism in order to define
and optimize functional languages (such as Haskell’s

spineless tagless graph-machine
), they are still mostly compiled down to the same old
non-parallel assembly code that every other language uses. Now, two
projects —

Bend
and

Vine
— have sprung up attempting to change that, and prove that
parallel graph reduction can be a useful technique for real programs.

Security updates for Friday

Post Syndicated from daroc original https://lwn.net/Articles/1012367/

Security updates have been issued by Debian (emacs, freerdp2, and gst-plugins-good1.0), Fedora (java-17-openjdk, python3.6, and xorg-x11-server-Xwayland), Mageia (radare2), SUSE (libX11, openvswitch3, postgresql13, procps, ruby2.5, webkit2gtk3, and xorg-x11-server), and Ubuntu (git, linux-aws, linux-aws, linux-aws-6.8, linux-aws, linux-oracle, linux-oracle-5.4, linux-ibm, linux-intel-iotg, linux-intel-iotg-5.15, and linux-oem-6.11).

[$] Python interpreter adds tail calls

Post Syndicated from daroc original https://lwn.net/Articles/1010905/

The

Faster CPython project
has been working to speed up the Python interpreter
for the past several years. Now, Ken Jin, a member of the project, has merged a

new set of changes
that
have been

benchmarked
as improving performance by 10% for some architectures.
The only change is switching from using computed goto statements to using
tail calls as part of the implementation of Python’s bytecode interpreter — but that change allows
modern compilers to generate significantly better code.

[$] A possible path for cancelable BPF programs

Post Syndicated from daroc original https://lwn.net/Articles/1010404/

The Linux kernel supports attaching BPF programs to many operations.
This is generally safe because the BPF verifier ensures
that BPF programs can’t misuse kernel resources, run indefinitely, or otherwise
escape their boundaries. There is continuing tension, however, between trying
to expand the capabilities of BPF programs and ensuring that the verifier can
handle every edge case. On February 14, Juntong Deng

shared
a proof-of-concept patch set that
adds some run-time checks to BPF to make it possible in the future to interrupt
a running BPF program.

Security updates for Friday

Post Syndicated from daroc original https://lwn.net/Articles/1011262/

Security updates have been issued by AlmaLinux (bind, bind9.16, and mysql:8.0), Debian (chromium, djoser, libtasn1-6, and postgresql-13), Fedora (python3.12 and vim), Red Hat (libpq, postgresql, postgresql:13, postgresql:15, and postgresql:16), Slackware (ark), SUSE (brise, chromium, emacs, google-osconfig-agent, grafana, grub2, helm, kernel, openssh, openssl-1_1, ovmf, postgresql13, postgresql14, postgresql15, and postgresql17), and Ubuntu (gnutls28, libtasn1-6, openssl, python3.10, python3.12, python3.8, and webkit2gtk).

[$] Extending time slices for user-space locks

Post Syndicated from daroc original https://lwn.net/Articles/1009509/

Steven Rostedt recently posted

a patch set
that could help improve the performance of certain user-space
applications by giving the scheduler more context about when they are safe to
interrupt. The patch set lets programs request a small grace window
before they can be interrupted so that they can relinquish any locks, decreasing the
amount of time that other threads have to spend waiting. Rostedt shared
performance numbers suggesting that the patch might cut the amount of time spent
acquiring locks in half for some programs — although, since his test was
specifically tuned for this case, real-world projects should expect a somewhat
less dramatic improvement. The change received some pushback from scheduler
maintainer Peter Zijlstra, who objected to the patch set’s approach.

[$] FUSE folio conversion confusion

Post Syndicated from daroc original https://lwn.net/Articles/1008714/

Kernel developers have been working to convert various internal interfaces to
use

folios
; while this process has been progressing, there is still the
occasional regression introduced by the change. In December 2024, it was
discovered that installing a

Flatpak
application could trigger a filesystem bug in
the kernel that would cause the software to read incorrect data from the disk.
The problem was quickly fixed — only for an another problem caused by the folio
rewrite to pop up in the same kernel subsystem. This was discovered by an Arch
Linux user, who noticed that selecting files in a Flatpak application was
causing kernel crashes. Now both bugs are fixed, but there may be more bugs to find.

Three stable kernels under the sky

Post Syndicated from daroc original https://lwn.net/Articles/1010352/

Greg Kroah-Hartman has released three more stable kernels:
6.13.3,
6.12.14, and
6.6.78.
There was a bit of confusion that resulted in the patch for
CVE 2025-21687
getting applied twice — but that doesn’t result in any problems for users of the
kernel, just a bit of extra noise in the CVE database, so Kroah-Hartman has
decided to leave the releases as-is instead of rushing another point release.

Security updates for Monday

Post Syndicated from daroc original https://lwn.net/Articles/1010328/

Security updates have been issued by AlmaLinux (container-tools:rhel8, gcc, libxml2, nodejs:18, and nodejs:20), Debian (freerdp2, golang-glog, trafficserver, and tryton-client), Fedora (chromium, krb5, libheif, microcode_ctl, nginx, nginx-mod-fancyindex, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, and webkitgtk), Mageia (ffmpeg, golang, postgresql13 and postgresql15, and python-zipp), Oracle (container-tools:ol8, gcc, gcc-toolset-13-gcc, gcc-toolset-14-gcc, kernel, libxml2, and nodejs:20), Red Hat (gcc, idm:DL1, and ipa), SUSE (buildah, chromium, glibc, kernel, kernel-firmware-all-20250206, libecpg6, postgresql15, python, python3, python311, and ruby3.4-rubygem-rack), and Ubuntu (intel-microcode).