All posts by jake

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/985336/

Security updates have been issued by AlmaLinux (httpd:2.4), Fedora (chromium, firefox, frr, neatvnc, nss, python-setuptools, and python3.13), Gentoo (AFLplusplus, Bundler, dpkg, GnuPG, GPAC, libde265, matio, MuPDF, PHP, protobuf, protobuf-python, protobuf-c, rsyslog, Ruby on Rails, and runc), Red Hat (389-ds-base, container-tools:rhel8, and httpd:2.4), SUSE (bind and ca-certificates-mozilla), and Ubuntu (linux-azure).

[$] Meeting the Debian Technical Committee

Post Syndicated from jake original https://lwn.net/Articles/984720/

It is something of a DebConf tradition that members of the Debian Technical
Committee
(TC) take the stage to talk about the work that the committee
does—and more. DebConf24 in
Busan, South Korea was no exception, as TC chair Sean Whitton, who
will complete his term at the end of the year, and one
of its newest members, Stefano Rivera, described the constitutional
underpinnings of the TC, how it tries to make decisions when it needs to,
and the constant process of recruiting new members. After that, they took
a few questions from the audience. The session provided a nice overview of
the TC and its role in Debian, but it may well be of interest further afield.

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/984807/

Security updates have been issued by AlmaLinux (freeradius and freeradius:3.0), Debian (chromium, odoo, and roundcube), Fedora (microcode_ctl, mingw-qt5-qtbase, mingw-qt6-qtbase, opentofu, orc, python-setuptools, and vim), Gentoo (Nokogiri), Oracle (kernel), Red Hat (go-toolset:rhel8, golang, kernel, krb5, libtiff, python-setuptools, and python39:3.9 and python39-devel:3.9), SUSE (python-Django), and Ubuntu (krb5).

[$] Tracing the source of filesystem errors

Post Syndicated from jake original https://lwn.net/Articles/984556/

There are lots of places in the kernel where an EINVAL can be
returned to user space, but it is often unclear what the actual underlying
problem is because the errno
error codes are too generic. That is the problem that Miklos Szeredi
wanted to discuss in a filesystem session that he led remotely at the 2024 Linux Storage,
Filesystem, Memory Management, and BPF Summit
. He would like to help
those who are trying to debug problems trace where in the kernel a
particular error code is being generated.

[$] CircuitPython: Python for microcontrollers, simplified

Post Syndicated from jake original https://lwn.net/Articles/983870/

CircuitPython is an open-source
implementation of the Python programming language for microcontroller
boards. The project, which is sponsored by Adafruit Industries, is designed with
new programmers in mind, but it also has many features that may be of
interest to more-experienced developers. The recent 9.1.0 release
adds a few minor features, but it follows just a few months after CircuitPython 9.0.0,
which brings some more significant changes, including improved graphics and
USB support.

[$] Handling filesystem interruptibility

Post Syndicated from jake original https://lwn.net/Articles/983714/

David Howells wanted to discuss changing the way filesystem code handles
the ability to interrupt or kill operations, in order to fix some
longstanding problems with network
(and other) filesystems, in a session at
the 2024 Linux
Storage, Filesystem, Memory Management, and BPF Summit
. As noted in
his session
proposal
, some filesystems may be expecting to not be interruptible,
but are calling code can take locks and mutexes that are interruptible (or
killable), which are effectively
changing the state of the task incorrectly.
He would like to find a solution for that problem.

[$] Famfs: a filesystem interface to shareable memory

Post Syndicated from jake original https://lwn.net/Articles/983105/

At the 2024 Linux
Storage, Filesystem, Memory Management, and BPF Summit
, John Groves led
a session on famfs, which is a filesystem he has developed that uses the
kernel’s direct-access (DAX)
mechanism to access memory that is shareable between hosts. The discussion
was aimed at whether a different approach should be taken and, in
particular, whether FUSE should be used instead of implementing as an
in-kernel filesystem. As noted in the thread about his
proposal for an LSFMM+BPF session, and the mailing-list discussions on the first and second
version
of his patch set, there is some skepticism that a new in-kernel
filesystem is warranted for the use case.

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/983328/

Security updates have been issued by AlmaLinux (containernetworking-plugins, cups, edk2, httpd, httpd:2.4, libreoffice, libuv, libvirt, python3, and runc), Fedora (exim, python-zipp, xdg-desktop-portal-hyprland, and xmedcon), Red Hat (cups, fence-agents, freeradius, freeradius:3.0, httpd:2.4, kernel, kernel-rt, nodejs:18, podman, and resource-agents), Slackware (htdig and libxml2), SUSE (exim), and Ubuntu (ocsinventory-server, php-cas, and poppler).

[$] Large folios, swap, and FS-Cache

Post Syndicated from jake original https://lwn.net/Articles/982887/

David Howells wanted to discuss swap handling in light of multi-page folios
in a combined storage, filesystem, and memory-management session at
the 2024 Linux Storage,
Filesystem, Memory Management, and BPF Summit
. Swapping has always been
done with a one-to-one mapping of memory pages to swap slots, he said, but
swapping multi-page folios breaks that assumption. He wondered if it would
make sense to use filesystem techniques to track swapped-out folios.

[$] Imitation, not artificial, intelligence

Post Syndicated from jake original https://lwn.net/Articles/982289/

Simon Willison, co-creator of the popular Django web framework for Python,
gave a keynote presentation at PyCon 2024 on topic that is
unrelated to that work: large language models (LLMs).
The topic grew out of some other work that he is doing on Datasette, which is a Python-based
“tool for exploring and publishing data“. The talk was a look
beyond the hype to try to discover what useful things you can actually do
today using these models. Unsurprisingly, there were some
cautionary notes from Willison, as well.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/982845/

Security updates have been issued by Fedora (botan2, chromium, ffmpeg, fluent-bit, gtk3, httpd, suricata, tcpreplay, and thunderbird), Mageia (apache, chromium-browser-stable, libfm & libfm-qt, and thunderbird), Oracle (firefox, java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, java-21-openjdk, kernel, libndp, qt5-qtbase, ruby, skopeo, thunderbird, and virt:ol and virt-devel:rhel), Red Hat (containernetworking-plugins, firefox, libndp, qt5-qtbase, and thunderbird), SUSE (caddy, chromium, emacs, global, mockito, snakeyaml, testng, and opera), and Ubuntu (thunderbird).

Evolving the ASF Brand (Apache Software Foundation blog)

Post Syndicated from jake original https://lwn.net/Articles/982392/

The Apache Software Foundation (ASF)
has announced
that it will be changing its logo to remove the feather that has been part
of its brand since 1997. ASF members will have input on the rebranding process and be
able to vote on the new logo, which will be unveiled at the Community Over Code conference in October.

The feather is a well-loved and iconic part of the ASF brand. We know of community members who have ASF feather tattoos. People love taking photos with the feather at our flagship event each year.

So why would we change it? As a non-Indigenous entity, we acknowledge that it is inappropriate for the Foundation to use Indigenous themes or language. We thank Natives in Tech and other members of the broader open source community for bringing this issue to the forefront. Today we are announcing we will be retiring the feather icon and logo and replacing it with a new logo that embodies the Foundation’s rich history of providing software for the public good.

[$] Filesystem testing for stable kernels

Post Syndicated from jake original https://lwn.net/Articles/982099/

Leah Rumancik led a filesystem-track session at
the 2024 Linux Storage,
Filesystem, Memory Management, and BPF Summit
on the testing needed to
qualify
XFS patches for the stable kernels. At last year’s summit,
Rumancik, Amir Goldstein, and Chandan Babu Rajendra presented on their efforts to test and
backport fixes for the XFS filesystem to three separate stable kernels.
There has been some longstanding unhappiness in
the XFS-development community
with the stable-kernel process
, which led to
backports ceasing for that filesystem until Goldstein started working on XFS testing for the stable
trees a few years ago. In this year’s session, Rumancik updated
attendees on how things had gone over the last year and wanted to discuss some
remaining pain points for the process.

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/982378/

Security updates have been issued by Debian (chromium), Fedora (freeradius), Red Hat (firefox, java-1.8.0-openjdk, and java-17-openjdk), Slackware (openssl), SUSE (ghostscript, gnutls, podman, and python-Django), and Ubuntu (linux-hwe-6.5, linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle-5.15, linux-oracle, linux-xilinx-zynqmp, and stunnel).

[$] Changing the filesystem-maintenance model

Post Syndicated from jake original https://lwn.net/Articles/981854/

Maintenance of the kernel is a difficult, often thankless, task; how it is
being handled, the role of maintainers, burnout, and so on are recurring
topics at kernel-related conferences. At
the 2024 Linux Storage,
Filesystem, Memory Management, and BPF Summit
, Josef Bacik and
Christian Brauner led a session to discuss possible changes to the way
filesystems are maintained, though Bacik took the lead role (and the podium). There are a number of interrelated topics,
including merging new filesystems, removing old ones, making and testing changes
throughout the filesystem tree, and more.

[$] Hierarchical storage management, fanotify, FUSE, and more

Post Syndicated from jake original https://lwn.net/Articles/981392/

Amir Goldstein led a filesystem-track session at the 2024 Linux Storage,
Filesystem, Memory Management, and BPF Summit
on his project to build a
hierarchical
storage management
(HSM) system using fanotify.
The idea is to monitor file access in order to determine when to retrieve
content from non-local storage (e.g. the cloud). The session was a
follow-up to last year’s introduction to the
project
, which covered some of the problems he had encountered; this
year, he
was updating attendees on its status and progress, along with some other
problem areas that he wanted to discuss.