All posts by jake

[$] Python’s two modules for random numbers

Post Syndicated from jake original https://lwn.net/Articles/1097468/

Python’s random
and secrets
modules both include utilities for obtaining random values, but only one of them is suitable for generating passwords and security tokens.
For much of Python’s history, random was used for passwords and tokens anyway, despite documentation that called it unsuitable for cryptography.
In 2015, Python’s core team debated whether to fix that misuse by making random secure by default.
Instead, in 2016, Python 3.6 added a second module: secrets. The
random module is still misused at times, so it is instructive
to look into how the random-number modules should be used.

[$] Comparing Chromium development at Google and Igalia

Post Syndicated from jake original https://lwn.net/Articles/1094721/

Sharon Yang is a Chromium developer who worked at Google on the browser
and now works on it at Igalia. On the final day of FOSSY 2026, she gave a
presentation on her experiences with both of those companies, comparing and
contrasting the ways the each operates and how that affects work on the
code base. She enjoyed working at Google and feels the same about Igalia,
so the talk was not aimed at complaints—instead it was meant to give a feel
for two companies that are rather different.

Security updates for Tuesday

Post Syndicated from jake original https://lwn.net/Articles/1097466/

Security updates have been issued by AlmaLinux (cockpit-image-builder, expat, ipa, kernel, kernel-rt, resteasy, ruby, ruby4.0, ruby:3.3, and ruby:4.0), Debian (dovecot, flatpak, glance, kernel, libdbi-perl, lxml, rsync, swift, and wordpress), Fedora (chromium, freeipa, freerdp, grub2, NetworkManager-iodine, NetworkManager-l2tp, perl-Catalyst-Plugin-Static-Simple, perl-Dancer2, perl-HTML-FormFu, python-quart-trio, python-streamlink, python-urllib3, and vlc), Mageia (libxml2, p11-kit, pam, and php), Slackware (groff and pcre2), SUSE (389-ds, amazon-ssm-agent, erlang27, exiv2, glib2, gnome-shell, hplip, ImageMagick, kernel, libheif, libsodium, libtpms, nodejs16, perl-DBI, python-soupsieve, redis, redis7, swtpm, and wireshark), and Ubuntu (curl, libevent, linux-aws, linux-aws-6.8, linux-aws-5.15, linux-azure-5.15, linux-azure-fde-5.15, linux-intel-iotg-5.15, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-7.0, linux-oem-7.0, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, and linux-oracle-7.0).

Git v2.56.0 released

Post Syndicated from jake original https://lwn.net/Articles/1097213/

Version 2.56 of the Git distributed
version-control system has been released. It has 748 non-merge commits
since Git 2.55 was released back in
June; those commits came from 104 developers, 39 of whom are first-time
contributors. New features include a safer workflow for conflict
resolution, smaller path-walk repacks, a new git history drop
sub-command, and much more. LWN looked at Git
2.56
recently and the GitHub blog has a lengthy
look at 2.56
as well.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1097191/

Security updates have been issued by AlmaLinux (firefox, ipa, kernel, libxml2, perl-DBI, python-cryptography, thunderbird, and unbound), Debian (chromium, evolution-data-server, exim4, ghostscript, incus, lemonldap-ng, libheif, nodejs, php8.4, ruby-oj, swift, and vlc), Fedora (chromium, cinnamon, cinnamon-desktop, cinnamon-session, cinnamon-settings-daemon, ckermit, dnf5, forgejo, goose, gssntlmssp, libheif, libpcap, librsvg2, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-python3, mongo-c-driver, muffin, nemo, nemo-extensions, nextcloud, pgadmin4, postgresql16-postgis, postgresql17-postgis, postgresql18-postgis, rust-librsvg, rust-xml5ever, sipp, suricata, tesseract, and xreader), Mageia (erlang, gpsd, libreswan, python3 & python-pip, and udisks2), Oracle (abrt, buildah, cockpit-image-builder, corosync, ipa, kernel, libxml2, openexr, perl-DBI, perl-DBI:1.641, postgresql, thunderbird, unbound, and yelp), SUSE (389-ds, ansible-lint, cups, firefox, flatpak-builder, forgejo-longterm, gdb, gimp, gitoxide, glib2, gnome-shell, google-guest-agent, google-osconfig-agent, haveged, helm, ImageMagick, kbd, libsoup, libtpms, obs-service-cargo, openai-codex, opensuse-signkey-cert, osmo-iuh, perl-mojolicious, poppler, python-WebOb, python-WebOb-doc, python313-vllm, python314, sdbootutil, suseconnect-ng, and swtpm), and Ubuntu (exim4, freerdp3, libvirt, libvirt-hwe, libwebsockets, lxc, pyjwt, and requests).

Security updates for Tuesday

Post Syndicated from jake original https://lwn.net/Articles/1096022/

Security updates have been issued by AlmaLinux (apr-util, corosync, curl, freerdp, gstreamer1-plugins-base, libarchive, libtiff, libxml2, openexr, openssh, rsyslog, sudo, tomcat, unbound, webkit2gtk3, yggdrasil, and yggdrasil-worker-package-manager), Debian (chromium), Fedora (alsa-plugins, amarok, aqualung, atomes, attract-mode, audacious-plugins, audacity, baresip, blender, calibre, cantata, cef, chromaprint, chromium, digikam, doctl, dragon, ffmpeg, ffmpegthumbnailer, ffmpegthumbs, ffms2, fooyin, glaxnimate, goldendict-ng, gpac, gstreamer1-plugin-libav, guacamole-server, guvcview, haruna, hedgewars, icecat, janus, k3b, kdenlive, kf5-kfilemetadata, kf6-kfilemetadata, kpipewire, lazygal, lego, libcamera-apps, libheif, libopenshot, libopenshot-audio, libvncserver, localsearch, mat2, minidlna, mivisionx, mixxx, mlt, monado, mpd, mpv, mpv-mpris, neatvnc, notcurses, nv-codec-headers13.0, obs-studio, obs-studio-plugin-droidcam, obs-studio-plugin-pwvideo, obs-studio-plugin-vaapi, obs-studio-plugin-vkcapture, obs-studio-plugin-webkitgtk, olive, openal-soft, OpenBoard, opencv, openmw, opustags, os-autoinst, patool, Pencil2D, perl-HTML-FormHandler, pianobar, prometheus-podman-exporter, python-audioread, python-torchaudio, python-torchvision, qmmp, qmmp-plugin-pack, qmplay2, qt5-qtwebengine, qt6-qtmultimedia, qt6-qtwebengine, qtox, retroarch, rocdecode, rocdecode7.2, rsgain, siril, squeezelite, swayimg, tigervnc, timg, unpaper, vlc, vtk, waypipe, wf-recorder, wivrn, wxsvg, xine-lib, xmms2, xpra, xscreensaver, yle-dl, znc, and znc-clientbuffer), Mageia (nmap, pcre2, and vim), Oracle (curl, openssl-fips-provider, sudo, tomcat, webkit2gtk3, yggdrasil, and yggdrasil-worker-package-manager), Slackware (util-linux), SUSE (cadvisor, chromium, coredns, fake-gcs-server, freeciv, gh, glibc, google-guest-agent, google-osconfig-agent, hugo, kbd, kbfs, keybase-client, libheif, libpcap, mbedtls, pcre2, python-asteval, python-jwcrypto, python311, python313-ansi2html, shadowsocks-rust, sofia-sip, and trivy), and Ubuntu (clamav, expat, ghostscript, glib2.0, gst-plugins-base1.0, gst-plugins-good1.0, libsoup2.4, libsoup3, libssh2, libxml2, linux-azure-6.8, linux-azure-fde, linux-azure-fde, linux-azure-fde-7.0, linux-azure-fde, linux-intel-iotg, linux-kvm, linux-oracle, linux-xilinx-zynqmp, linux-gcp-6.8, linux-ibm, linux-xilinx, linux-ibm, linux-nvidia-bos, linux-raspi, memcached, openjdk-17, openjdk-21, openjdk-25, openjdk-8, openjdk-lts, rsyslog, and strongswan).

Igalia celebrates “Twenty-Five Years Upstream”

Post Syndicated from jake original https://lwn.net/Articles/1095723/

The open-source consulting firm Igalia has put out an
announcement celebrating 25 years
of working on upstream FOSS projects
for its clients. The list of projects the company has worked on is rather
eye-opening: WebKit, mobile-browser rendering (on Maemo, Moblin, MeeGo, and
Tizen), the Linux kernel (CPU and GPU scheduling), 3D graphics drivers, the
Orca screen reader,
GStreamer, and lots more. Beyond that, the company, which is a
worker-owned cooperative, does its work in ways that benefit the community
as well as its clients:

None of this is charity. Igalia is a consultancy, and most of the work above was paid for by someone with a product to ship: a device maker who needs the web to run well on their hardware, a platform that needs a feature its users keep asking for, a company whose roadmap depends on something deep in the stack working better than it does today. What they get from us is not a patch to carry forever. We do the work upstream, in the project itself, so it arrives in the next release and keeps working long after the contract ends. Our customers ship products built on code that nobody has to maintain alone, and everyone else gets the same code. That has been the arrangement from the start.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1095702/

Security updates have been issued by AlmaLinux (kernel, perl-Net-DNS, sudo, tomcat, and tomcat9), Debian (chromium, gimp, libde265, libevent, linux-6.12, ruby-jwt, and unbound), Fedora (asterisk, chromium, doctl, dovecot, evolution, firefox, forgejo, freeciv, freeipa, gegl04, gimp, libheif, nss, opkssh, parted, ruby, stb, thunderbird, unbound, and webkitgtk), Mageia (bind, gawk, gdk-pixbuf2.0, graphicsmagick, gstreamer1.0-plugins-base, libde265, libpcap, libssh, mpg123, ntfs-3g, ntpsec, patch, perl-YAML, postfix, python-configargparse, and python-httplib2), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, firefox, image-builder, kernel, libevent, libsoup, libsoup3, perl-Net-DNS, python-lxml, sudo, tomcat, tomcat9, and unbound), Slackware (stunnel), SUSE (alloy, dovecot22, ffmpeg-8, firefox, firefox-esr, freeipmi, glibc, google-guest-agent, google-osconfig-agent, helm, ImageMagick, jq, kbd, kernel-devel, libpcap, libsoup, libzypp, zypper, NetworkManager-applet-l2tp, nginx, openCryptoki, pcre2, python311, python313-aiosmtplib, python313-litellm, rpm, and thunderbird), and Ubuntu (linux-aws, linux-aws-fips, linux-azure-5.15, linux-azure-fde-5.15, linux-azure-fips, linux-azure-5.4, linux-gcp-fips, linux-azure-fips, linux-nvidia-tegra, linux-raspi, linux-raspi-realtime, and rclone).

[$] Ways to encrypt data on servers

Post Syndicated from jake original https://lwn.net/Articles/1092553/

At the 2026 edition of FOSSY, Romeo
Solano gave a fast-paced, humorous presentation on what could have been a
rather boring topic: server encryption. There are a number of threats that
we face in today’s world, from criminals, government overreach, espionage,
and more, that can be thwarted with encryption. But encrypting data on a
system that may live elsewhere, without any access to its keyboard at boot
time, is rather more difficult than encrypting the disk of a laptop.
Solano described the problems and gave a tour of some of the solutions in
the talk.

[$] Typst makes big strides

Post Syndicated from jake original https://lwn.net/Articles/1092993/

Typst is a system for typesetting documents
into various formats: PDF, SVG, PNG, and, in progress, HTML. It is adept at
handling technical material, and is often considered to be an eventual LaTeX replacement. We last looked
in on Typst
a year ago, when it had reached version 0.13. A new version,
0.15, was released in
June with lots of new features, including support for variable fonts,
MathML, multiple bibliographies, and more. Typst is free, Apache-2.0-licensed software, programmed in Rust.

[$] Deterministic testing for multithreaded Python

Post Syndicated from jake original https://lwn.net/Articles/1090579/

Python’s support for multithreaded programs has improved considerably over
the last few years with the advent of the “free-threaded” version of the language. But
testing multithreaded programs is notoriously difficult, because the
underlying host system determines the thread-execution ordering, which adds
an element of non-determinism. At PyCon US, Larry Hastings gave a talk (YouTube video)
about his blanket project,
which is meant to provide mechanisms for deterministic testing of
multithreaded Python code.

[$] An ongoing 3D-printer AGPL violation

Post Syndicated from jake original https://lwn.net/Articles/1089390/

At FOSSY 2026, several people from the
Software Freedom Conservancy (SFC),
which organizes the conference, gave a presentation about an ongoing
violation
of the Affero General Public
License version 3
(AGPLv3). Bradley Kühn, Karen Sandler, and Denver
Gingerich spoke about different aspects of the violation, which is in
regard to 3D-printer software from Bambu Lab, and what is being
done to try to provide users with alternatives. One aspect that is
particularly interesting is that the circumvention that the company is
employing is precisely what the AGPL was written to prevent.

[$] Representing Python paths using pathlib

Post Syndicated from jake original https://lwn.net/Articles/1088781/

At the outset of his PyCon US 2026
talk, Trey Hunner said that his goal was for attendees to stop representing
filesystem paths as strings and to use pathlib
instead. That’s kind of a tall order, at least for longtime Python users,
since string-based paths have been pervasive—and mostly work. It is that
“mostly” part that makes Hunner want to see things change, of course, so he
set out to describe a lesser-known corner of the language and to try to
change some minds.

[$] Bootstrappable builds: how and why

Post Syndicated from jake original https://lwn.net/Articles/1088279/

This year’s edition of the Free and Open
Source Software Yearly conference
, better known as “FOSSY”, moved north to the
beautiful (and enormous) campus of the University of British Columbia (UBC)
in Vancouver, Canada from its home for the three previous editions:
Portland, Oregon, in the US. There were many different types of talks at
FOSSY, from deeply technical kernel-track topics, through talks on legal
and community issues, to the “FOSS in Daily Life” talks. In the “Toolchains
and Other Development Tools” track, Timothy Sample gave a presentation
about bootstrappable builds,
which is somewhat less well-known than its cousin, reproducible builds, though LWN
did look at the topic just over two years
ago. In short, a bootstrappable build is one that starts with a tiny
program that can build another slightly larger program, which can build yet
another, and so on, until the entirety of a modern Linux user space is
built from a small seed. Ultimately, it results in code with a
completely understood origin—unlike a typical Linux user space today.

[$] FUSE status and plans

Post Syndicated from jake original https://lwn.net/Articles/1086336/

Filesystem in
Userspace
(FUSE) maintainer Miklos Szeredi led a birds-of-a-feather
(BoF) discussion about the subsystem at
the 2026 Linux Storage,
Filesystem, Memory Management, and BPF Summit
. In it, he talked about
maintenance challenges, proposed features and their status, and his plans
for a new FUSE API. There is a lot of interest and activity in the
FUSE community these days it seems.

[$] Buffer sizes for FUSE io_uring

Post Syndicated from jake original https://lwn.net/Articles/1085618/

The Filesystem in
Userspace
(FUSE) subsystem provides a way to service filesystem
requests from a user-space server, which moves the format-handling code out
of the kernel. The FUSE server can use the io_uring
facility for better performance, but Bernd Schubert is concerned that
memory is being wasted because the current implementation has a single,
large buffer size that is excessive for small I/O operations. He led a discussion on that topic
in the filesystem track of the 2026 Linux Storage,
Filesystem, Memory Management, and BPF Summit
in Zagreb, Croatia.

[$] Merging famfs?

Post Syndicated from jake original https://lwn.net/Articles/1082687/

The famfs filesystem, which is meant to provide shared access to huge
memory-resident files on CXL and other
devices, returned to
the Linux Storage,
Filesystem, Memory Management, and BPF Summit
(LSFMM+BPF) in 2026.
It was first discussed at LSFMM+BPF 2024 and a new implementation was described at the 2025
gathering
, but it still has not made its way into the kernel; LWN looked
at a discussion about merging famfs
back in April 2026.

[$] Topics in filesystem testing

Post Syndicated from jake original https://lwn.net/Articles/1082342/

It should come as no surprise that a gathering of filesystem developers
would discuss filesystem testing; it has been a mainstay of the Linux Storage,
Filesystem, Memory Management, and BPF Summit
over the years and the
2026 summit was no exception. Ted Ts’o led the discussion this time; he
had a few different topics to raise, including his perception of increasing
regressions for ext4 in the stable kernels and what can be done to help
reduce them. As with other similar
sessions at the summit over the years,
there is a lot of interest in collaborating on test inputs and outputs, but
finding a way to centralize that information has so far eluded the
filesystem community.