The 7.0 merge window
closed on February 22 with 11,588 non-merge commits total,
3,893 of which came in after the article covering the first half of the merge
window. The changes in the second half were weighted toward bug fixes over
new features, which is usual. There were still a handful of surprises, however, including
89 separate tiny code-cleanup changes from different people for the rtl8723bs
driver, a number that surprised
Greg Kroah-Hartman. It’s unusual for a WiFi-chip driver to receive that much
attention, especially a staging driver that is not yet ready for general use.
The closed-source chat platform Discord
announced on February 9 that it would soon require some users to verify their
ages in order to access some content — although the company quickly
added that
the “vast majority” of users would not have to. That reassurance has to
contend with the fact that the UK and other countries are implementing
increasingly strict age requirements for social media. Discord’s age
verification would be done with an AI age-judging
model or with a government photo ID. A surprising number of open-source
projects use Discord for support or project communications, and some of those
projects are now looking for open-source alternatives. Mastodon, for example,
has moved discussion to Zulip. There are some alternatives out there, all
with their own pros and cons, that communities may want to consider if they want
to switch away from Discord.
The merge window for Linux 7.0 has opened, and with it
comes a number of interesting improvements and enhancements. At the time of
writing, there have been 7,695 non-merge commits accepted. The 7.0 release is
not special,
according to the kernel’s versioning scheme — just the release
that comes after 6.19. Humans love symbolism and round numbers, though, so it
may feel like something of a milestone.
Web sites are being increasingly beset by AI scraperbots — a problem that we have written about before, and which has slowly
ramped up to an occasional de-facto DDoS attack. This has not gone
uncontested, however: web site operators from around the world have been working on
inventive countermeasures. These solutions target the problem posed by scraperbots in different ways;
iocaine, a MIT-licensed nonsense generator, is designed
to make scraped text less useful by poisoning it with fake data. The hope is to
make running scraperbots not economically viable, and thereby address the
problem at its root instead of playing an eternal game of Whac-A-Mole.
Control-flow integrity (CFI) is a set of techniques that make it more difficult for
attackers to hijack indirect jumps to exploit a system. The Linux kernel has
supported forward-edge CFI (which protects indirect function calls) since 2020, with the most recent implementation
of the feature introduced in 2022. That
version avoids the overhead introduced by the earlier approach by using a
compiler flag (-fsanitize=kcfi) that is present in Clang but not in
GCC. Now, Kees Cook has
a patch set adding that support to GCC that looks likely to land in GCC
17.
The
team behind
Tyr started 2025 with little to show in our quest to
produce a Rust GPU driver for Arm Mali hardware, and by the end of the
year, we were able to play SuperTuxKart (a 3D open-source racing
game) at the Linux Plumbers Conference (LPC). Our prototype was a joint
effort between Arm, Collabora, and Google; it ran well for the duration
of the event, and the performance was more than adequate for players.
Thankfully, we picked up steam at precisely the right moment: Dave
Airlie just
announced in the Maintainers Summit that the DRM subsystem
is only “about a year away” from disallowing new drivers written in C
and requiring the use of Rust. Now it is time to lay out a
possible roadmap for 2026 in order to upstream all of this work.
A few years ago, the only way to compile Rust code was using the rustc compiler
with LLVM as a backend. Since then, several projects, including
Mutabah’s Rust Compiler (mrustc), GCC’s Rust
support (gccrs),
rust_codegen_gcc, and
Cranelift have made enormous progress
on diversifying Rust’s compiler implementations. The most recent such project,
Eurydice, has a
more ambitious goal: converting Rust code to clean C code. This is especially
useful in high-assurance software, where existing verification and compliance
tools expect C. Until such tools can be updated to work with Rust, Eurydice could
provide a smoother transition for these projects, as well as a stepping-stone
for environments that have a C compiler but no working Rust compiler. Eurydice
has been used to compile some post-quantum-cryptography routines from Rust to C,
for example.
The
Linux Kernel Runtime Guard (LKRG) is a out-of-tree loadable kernel module that
attempts to detect and report violations of the kernel’s internal invariants,
such as might be caused by an in-progress security exploit or a rootkit.
LKRG has been experimental since its
initial release in 2018. In September
2025, the project announced
the 1.0 version. With the promises of stability that version brings, users might want more
information to decide whether to include it in their kernel.
LWN has had a number of articles on immutable distributions,
such as Bluefin and
Bazzite, in recent years. These distributions have taken a variety of approaches, including
using
rpm-ostree, filesystem snapshots, and bootable container (bootc) images. But those
approaches, especially the latter, lead to extra complexity for a user
attempting to install new software, instead of just
using the existing package manager.
AshOS (Any Snapshot Hierarchical OS) is an experimental AGPL-3-licensed
“meta-distribution” that tried a different approach more in line with
traditional package management. Although the project is no longer updated,
it remains usable, and can still shed some light on a potential alternate path for users
worried about adopting bootc-based approaches.
While there are several rootkits that target Linux, they have so far not fully
embraced the open-source ethos typical of Linux software.
Luckily, Matheus Alves has been working to remedy
this lack by creating
an open-source rootkit called Singularity for Linux systems. Users who feel
their computers are too secure can install the Singularity kernel module in
order to allow remote code execution, disable security features, and hide files
and processes from normal administrative tools. Despite its many features,
Singularity is not currently known to be in use in the wild — instead, it
provides security researchers with a testbed to investigate new detection and
evasion techniques.
Quality-of-service (QoS) mechanisms attempt to prioritize some processes (or
network traffic, disk I/O, etc.) over others in order to meet a system’s
performance goals. This is a difficult topic to handle in the world of Linux,
where workloads, hardware, and user expectations vary wildly. Qais Yousef spoke
at the 2025 Linux Plumbers Conference, alongside his collaborators John Stultz,
Steven Rostedt, and Vincent Guittot, about their plans for introducing a
high-level QoS API for Linux in a way that leaves end users in control of its
configuration. The talk focused specifically on a QoS mechanism for the
scheduler, to prioritize access to CPU resources differently for different kinds
of processes.
(slides; video)
The
Software Freedom Conservancy (SFC) is
suing
VIZIO over smart TVs that
include software licensed under the GPL and LGPL (including the Linux kernel,
FFmpeg, systemd, and others).
VIZIO didn’t provide the source code along with the device, and on request they
only provided some of it. Unlike a typical lawsuit about enforcing the GPL, the
SFC isn’t suing as a copyright holder; it’s suing as
a normal owner of the TV
in question. This approach opens some important legal questions, and after years
of pre-trial maneuvering (most recently resulting in a ruling related to signing keys that is the subject of a separate article),
we might finally obtain some answers when the case goes
to trial on January 12. As things stand, it seems likely that the judge in
the case will rule that that the GPL-enforcement lawsuits can be a matter of
contract law, not just copyright law, which would be a major change to how GPL
enforcement works.
The nature and role of the Linux Foundation’s Technical Advisory Board (TAB) is
not well-understood, though a recent LWN article shed some light on its
role and
history. At the 2025
Linux Plumbers Conference (LPC), the TAB held a question and
answer session to address whatever it was the community wanted to know
(video).
Those questions ended up covering the role of large language models in kernel
development, what it is like to be on the TAB, how the TAB can help grease the
wheels of corporate bureaucracy, and more.
Aleksa Sarai, as the maintainer of the runc container runtime, faces a
constant battle against security problems. Recently, runc has seen
another
instance of a security vulnerability that can be traced back to the difficulty
of handling file paths on Linux. Sarai spoke at the 2025 Linux Plumbers Conference
(slides; video)
about
some of the problems runc has had with path-traversal vulnerabilities, and to
ask people to please use
libpathrs, the library that he has been developing for
safe path traversal.
The BPF verifier works, on a theoretical level, by considering every possible
path that a BPF program could take. As a practical matter, however, it needs to
do that in a reasonable amount of time. At the
2025 Linux Plumbers Conference, Mahé Tardy and Paul Chaignon
gave a detailed explanation
(slides; video) of
the main mechanism that it uses to accomplish that: state pruning. They focused
on two optimizations that help reduce the number of paths the verifier needs to
check, and discussed some of the complications the optimizations introduced to the verifier’s
code.
The BPF verifier is complicated. It needs to check every possible path that a
BPF program’s execution could take. The fact that its determination of whether a
BPF program is safe is based on the whole lifetime of the program, instead of
simple local factors, means that the cause of a verification
failure is not always obvious. Ihor Solodrai and Jordan Rome gave a presentation
(slides)
at the
2025 Linux Plumbers Conference in Tokyo about
the
BPF verifier visualizer that they have been building
to make diagnosing verification failures easier.
The
Internet Engineering Task Force (IETF) is the standards body responsible
for the TLS encryption standard — which your browser is using right now
to allow you to read LWN.net. As part of its work to keep TLS secure, the IETF
has been entertaining
proposals to adopt “post-quantum” cryptography (that is,
cryptography that is not known to be easily broken by a quantum computer) for TLS
version 1.3. Discussion of the proposal has exposed a large disagreement between
participants who worried about weakened security and others who worried about
weakened marketability.
Emma Smith and Kirill Podoprigora, two of Python’s core developers, have opened a
discussion about including Rust code in CPython, the reference implementation of
the Python programming language. Initially, Rust would only be used for optional
extension modules, but they would like to see Rust become a required dependency
over time. The initial plan was to make Rust required by 2028, but Smith and
Podoprigora indefinitely postponed that goal in response to concerns raised in the discussion.
Loris Cro has published
a detailed YouTube video talking about the terminology used to discuss asynchronicity, concurrency, and parallelism in our recent article about Zig’s new Io interface. Our article is not completely clear because it uses the term “asynchronous I/O” to refer to what should really be called “non-blocking I/O“, and sometimes confuses asynchronicity for concurrency, among other errors of terminology, he says. Readers interested in precise details about Zig’s approach and some of the motivation behind the design may find Cro’s video interesting.
The designers of the
Zig programming language have been working to find a
suitable design for asynchronous code for some time.
Zig is a carefully minimalist language, and its
initial design for
asynchronous I/O did not fit well with its other
features. Now, the project has
announced (in a Zig SHOWTIME video) a new approach to asynchronous I/O that
promises to solve the
function coloring problem, and allows writing code that will execute
correctly using either synchronous or asynchronous I/O.
The collective thoughts of the interwebz
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.