All posts by jake

[$] Pandoc: a workhorse for document conversion

Post Syndicated from jake original https://lwn.net/Articles/1064692/

Pandoc is a document-conversion program
that can translate among a myriad of formats, including LaTeX, HTML, Office Open XML
(docx), plain text, and Markdown. It is also
extensible by writing Lua
filters that can manipulate the document structure and perform arbitrary
computations.
Pandoc has appeared in various LWN articles over the years, such as my look at Typst and at the importance of free software to science in
2025, but we have missed providing an overview of the tool. The February release of Pandoc
3.9
, which comes with the ability to compile the program to WebAssembly (Wasm), allowing Pandoc
to run in web browsers, will likely also be of interest.

[$] Collaboration for battling security incidents

Post Syndicated from jake original https://lwn.net/Articles/1063459/

The keynote for Sun Security Con
2026
(SunSecCon) was given by Farzan Karimi on how incident handling
can go awry because of a lack of collaboration between the “good
guys”—which stands in contrast to how attackers collaboratively operate.
He provided some “war stories” where security incident handling had
benefited from collaboration and others where it was hampered by its lack.
SunSecCon was held in conjunction with SCALE 23x in Pasadena
in early March.

[$] Cindy Cohn on privacy battles old and new

Post Syndicated from jake original https://lwn.net/Articles/1061979/

Cindy Cohn is the executive director of the Electronic Frontier Foundation (EFF) and
she gave the Saturday morning keynote at SCALE 23x in Pasadena
about some of the work she and others have done to help protect online
rights, especially digital privacy. The talk recounted some of the history
of the court cases that the organization has brought over the years to try
to dial back privacy invasions. One underlying theme was the
role that attendees can play in protecting our rights, hearkening back to
earlier efforts by the technical community.

GIMP 3.2 released

Post Syndicated from jake original https://lwn.net/Articles/1063111/

After a year’s worth of development since GIMP 3.0 was released,
the team behind the open-source image editor has released
GIMP 3.2
. It comes as part of the plan
to release GIMP more frequently, rather than wait six or seven years
between releases. The release comes with lots of new features (as can
be seen in more detail in the release notes),
including 20 new brushes for the MyPaint Brush tool, an “overwrite” paint
mode, new and upgraded file formats, UI improvements in a variety of
places, such as the on-canvas text editor, and new non-destructive layers:

  • You can now use Link Layers to incorporate external image as
    part of your compositions, easily scaling, rotating, and transforming them
    without losing quality or sharpness. The link layer’s content is updated
    when the source file is modified

  • The Path tool can now create Vector Layers, which lets you draw
    shapes with adjustable fill and stroke settings.

[$] Disabling Python’s lazy imports from the command line

Post Syndicated from jake original https://lwn.net/Articles/1061112/

The advent of lazy imports in the Python language is upon us, now that PEP 810 (“Explicit lazy
imports”) was accepted by the steering
council
and the feature will appear in the upcoming Python 3.15 release
in October. There are a number of good reasons,
performance foremost, for wanting to defer spending—perhaps wasting—the
time to do an import before a needed symbol is used. However, there are
also good reasons not to want that behavior, at least in some cases. The
tension between those two positions is what led to an earlier PEP rejection,
but it is also playing into a recent discussion of the API used to control
lazy imports.

[$] The troubles with Boolean inversion in Python

Post Syndicated from jake original https://lwn.net/Articles/1059177/

The Python bitwise-inversion (or complement) operator, “~“, behaves
pretty much as expected when it is applied to integers—it toggles every
bit, from one
to zero and vice versa. It might be expected that applying the
operator to a non-integer, a bool
for example, would raise a TypeError, but, because the
bool type is really an int
in disguise, the complement operator is allowed, at least for now. For
nearly 15 years (and perhaps longer), there have been discussions about the
oddity of that behavior and whether it should be changed. Eventually,
that resulted in the “feature” being deprecated, producing a warning, with removal slated for
Python 3.16 (due October 2027). That has led to some reconsideration and the
deprecation may itself be deprecated.

Vlad: Weston 15.0 is here: Lua shells, Vulkan rendering, and a smoother display stack

Post Syndicated from jake original https://lwn.net/Articles/1059933/

Over on the Collabora blog, Marius Vlad has an overview
of Weston 15.0
, which was released on February 19. Weston is the
reference implementation of a Wayland compositor. The new
release comes with a new shell that can be programmed using the Lua language, a new, experimental Vulkan
renderer, smoother media playback, color-management additions, and more.

One of Weston’s fundamental pillars has always been making the most efficient use of display hardware. Over time, all the work we did to track and offload as much work as possible to this efficient fixed-function hardware has come at the cost of eating CPU time. In the last couple of release cycles, we’ve focused really hard on improving performance on even the most low-end of devices, so not only do we make the most efficient use of the GPU and display hardware, but we’re also really kind on your CPU now. As part of that and to improve our tooling, Weston 15 now comes with support for the Perfetto profiler.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1059864/

Security updates have been issued by AlmaLinux (kernel-rt and openssl), Debian (ca-certificates, chromium, gegl, glib2.0, libvpx, modsecurity-crs, nova, and pillow), Fedora (chromium, mingw-libpng, mupdf, python-pyasn1, python-PyMuPDF, python-uv-build, python3.13, qpdfview, rust-ambient-id, uv, and zathura-pdf-mupdf), Mageia (freerdp, gnutls, and libvpx), Red Hat (butane and grafana-pcp), SUSE (chromedriver, chromium, cockpit-repos, firefox, kernel, libpng16, postgresql16, postgresql17, postgresql18, python, python311-nltk, snpguest, ucode-intel-20260210, vexctl, and xen), and Ubuntu (djvulibre, evolution-data-server, linux-lowlatency, linux-xilinx, and u-boot).

[$] Compact formats for debugging—and more

Post Syndicated from jake original https://lwn.net/Articles/1057295/

At the 2025 Linux Plumbers Conference in Tokyo, Stephen Brennan gave a
presentation on the debuginfo
format
, which contains the symbols and other information needed for
debugging, along with some alternatives. Debuginfo files are large and, he
believes, are a bit scary to customers because of the “debug” in their name.
By rethinking debuginfo and the tools that use it, he hopes that
free-software developers “can add new, interesting capabilities to tools
that we are already using or build new interesting tools
“.

Ardour 9.0 released

Post Syndicated from jake original https://lwn.net/Articles/1057548/

The Ardour digital-audio-workstation (DAW)
project has announced the
release of version 9.0
.

This is a major release for the project, seeing several substantive new features that users have asked for over a long period of time. Region FX, clip recording, a touch-sensitive GUI, pianoroll windows, clip editing and more, not to mention dozens of bug fixes, new MIDI binding maps, improved GUI performance on macOS (for most) …

We expect to get feedback on some of the major new features in this release, and plan to take that into account as we improve and refine them and the rest of Ardour going forward. We have no doubt that there will be both delight and disappointment with certain things – rather than assume that we don’t know what we’re doing, please leave us feedback on the forums so that Ardour gets better over time. Those of you new to our clip launching implementation might care to read up on the differences with Ableton Live.

In the coming weeks, we’ll begin to sketch out what we have planned next for Ardour, in addition to responding to the feedback we get on this 9.0 release.

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/1057381/

Security updates have been issued by AlmaLinux (brotli, curl, kernel, python-wheel, and python3.12), Debian (containerd), Fedora (gnupg2, pgadmin4, phpunit10, phpunit11, phpunit12, phpunit8, phpunit9, and yarnpkg), Mageia (expat), Oracle (qemu-kvm and util-linux), Red Hat (kernel, kernel-rt, opentelemetry-collector, and python3.12-wheel), SUSE (abseil-cpp, dpdk, freerdp, glib2, ImageMagick, java-11-openj9, java-17-openj9, java-1_8_0-ibm, java-1_8_0-openj9, java-1_8_0-openjdk, java-21-openj9, kernel, libsoup, libsoup-3_0-0, openssl-3, patch, python-Django, rekor, rizin, udisks2, and xrdp), and Ubuntu (gh, linux, linux-aws, linux-azure, linux-azure-5.15, linux-gcp, linux-gke,
linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg,
linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra,
linux-nvidia-tegra-5.15, linux-oracle, linux-raspi, linux, linux-aws, linux-azure, linux-gcp, linux-oem-6.17, linux-oracle,
linux-raspi, linux-realtime, linux, linux-gke, linux-gkeop, linux-hwe-6.8, linux-oracle,
linux-oracle-6.8, linux-raspi, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-realtime, linux-intel-iot-realtime, and linux-realtime, linux-realtime-6.8, linux-raspi-realtime).

[$] API changes for the futex robust list

Post Syndicated from jake original https://lwn.net/Articles/1056387/

The robust
futex kernel API
is a way for a user-space program to ensure that the
locks it holds are properly cleaned up when it exits. But the API suffers
from a number of different problems, as André Almeida described in a session in the
“Gaming on
Linux” microconference
at the 2025 Linux Plumbers Conference in Tokyo.
He had some ideas for a new API that would solve many of those problems,
which he wanted to discuss with attendees; there is a
difficult-to-trigger race condition that he wanted to talk about too.

LibreOffice 26.2 released

Post Syndicated from jake original https://lwn.net/Articles/1057256/

Version 26.2 of the LibreOffice
office suite has been released.

LibreOffice 26.2 is focused on improvements that make a difference in daily work and brings better performance, smoother interaction with complex documents and improved compatibility with files created in other office software. Whether you’re writing reports, managing spreadsheets, or preparing presentations, the experience feels more responsive and reliable.

LibreOffice has always been about giving users control. LibreOffice 26.2 continues that tradition by strengthening support for open document standards, and ensuring long-term access to your files, without subscriptions, license restrictions, or data collection. Your documents stay yours – forever.

More information can be found in the release notes
for LibreOffice 26.2
.

Security updates for Wednesday

Post Syndicated from jake original https://lwn.net/Articles/1057247/

Security updates have been issued by Debian (thunderbird), Fedora (openqa, os-autoinst, python-jupytext, python-python-multipart, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-sq, rust-sequoia-sqv, and xen), Oracle (curl, kernel, net-snmp, python3, and python3.12), Red Hat (container-tools:rhel8, fence-agents, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, opentelemetry-collector, podman, python-s3transfer, python-wheel, and resource-agents), SUSE (alloy, chromium, cockpit-podman, cockpit-subscriptions, dpdk, elemental-register, elemental-toolkit, glib2, glibc, gpg2, ImageMagick, imagemagick, jasper, java-17-openjdk, java-21-openjdk, kernel, libheif, libmlt++, libpng16, libsodium, libsoup, libvirt, openssl-3, openvpn, php8, postgresql16, postgresql17 and postgresql18, protobuf, python-FontTools, python-fonttools, python-h2, python-python-multipart, python-urllib3, python-wheel, python311-PyNaCl, trivy, ucode-amd, udisks2, unbound, util-linux, wireshark, and xkbcomp), and Ubuntu (emacs, freerdp2, glibc, imagemagick, mysql-8.0, pagure, python-django, python-filelock, python-internetarchive, and python-keystonemiddleware).

Security updates for Tuesday

Post Syndicated from jake original https://lwn.net/Articles/1057047/

Security updates have been issued by AlmaLinux (fence-agents, gcc-toolset-15-binutils, golang-github-openprinting-ipp-usb, iperf3, kernel, kernel-rt, openssl, osbuild-composer, php:8.2, python3, util-linux, and wireshark), Debian (clamav and xrdp), Fedora (gimp and openttd), Mageia (docker-containerd), Oracle (gimp:2.8, golang-github-openprinting-ipp-usb, grafana-pcp, image-builder, iperf3, kernel, openssl, osbuild-composer, php, php:8.2, php:8.3, python3.9, util-linux, and wireshark), SUSE (cockpit-subscriptions, elemental-register, elemental-toolkit, glibc, gpg2, logback, openssl-1_1, python-urllib3, ucode-amd, and unbound), and Ubuntu (inetutils, libpng1.6, mysql-8.0, mysql-8.4, openjdk-17, openjdk-17-crac, openjdk-21, openjdk-21-crac, openjdk-25, openjdk-25-crac, openjdk-8, openjdk-lts, and thunderbird).

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1056923/

Security updates have been issued by AlmaLinux (iperf3, kernel, and php), Debian (ceph, pillow, pyasn1, python-django, and python-tornado), Fedora (bind9-next, cef, chromium, fontforge, java-21-openjdk, java-25-openjdk, java-latest-openjdk, mingw-python-urllib3, mingw-python-wheel, nodejs20, nodejs22, nodejs24, opencc, openssl, python-wheel, and qownnotes), Red Hat (binutils, gcc-toolset-13-binutils, gcc-toolset-14-binutils, gcc-toolset-15-binutils, java-1.8.0-openjdk, and java-25-openjdk), Slackware (expat), SUSE (bind, cacti, cacti-spine, chromedriver, chromium, dirmngr, fontforge-20251009, glib2, golang-github-prometheus-prometheus, govulncheck-vulndb, icinga2, ImageMagick, kernel, logback, openCryptoki, openssl-1_1, python311-djangorestframework, python311-pypdf, python314, python315, qemu, and xen), and Ubuntu (linux, linux-aws, linux-aws-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4,
linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm and linux-aws-fips, linux-fips, linux-gcp-fips).

[$] Open source for phones: postmarketOS

Post Syndicated from jake original https://lwn.net/Articles/1055391/

Phones running Linux are ubiquitous these days and it has been that way
since Android started working toward dominance in the smartphone market.
Unfortunately, Android has slowly increased its freedom-unfriendliness and
has become something of a privacy nightmare. In a talk entitled “We need
an open-source phone OS” at Open
Source Summit Japan 2025
, Luca Weiss described the smartphone landscape
and gave an overview of postmarketOS as an alternative Linux
operating system for mobile handsets.

[$] Cleanup on aisle fsconfig()

Post Syndicated from jake original https://lwn.net/Articles/1054228/

As part of the process of writing man pages for the “new” mount API, which has been available in the
kernel since 2019, Aleksa Sarai encountered a number of places where the fsconfig()
system call—for configuring filesystems before mounting—needs to be cleaned up. In the 2025 Linux Plumbers Conference
(LPC) session
that he led, Sarai wanted to discuss some of the problems he found,
including at least one with security implications. The idea of the session
was for him to describe the various bugs and ambiguities that he had found,
but he also wanted attendees to raise other problems they had with the
system call.

The State of OpenSSL for pyca/cryptography

Post Syndicated from jake original https://lwn.net/Articles/1054258/

Paul Kehrer and Alex Gaynor, maintainers of the Python cryptography module, have put out some strongly
worded criticism
of OpenSSL. It
comes from a talk they gave at the OpenSSL conference in October 2025 (YouTube video). The
post goes into a lot of detail about the problems with the OpenSSL code
base and testing, which has led the cryptography team to
reconsider using the library. “The mistakes we see in OpenSSL’s
development have become so significant that we believe substantial changes
are required — either to OpenSSL, or to our reliance on it.
” They go
further in the conclusion:

First, we will no longer require OpenSSL implementations for new functionality. Where we deem it desirable, we will add new APIs that are only on LibreSSL/BoringSSL/AWS-LC. Concretely, we expect to add ML-KEM and ML-DSA APIs that are only available with LibreSSL/BoringSSL/AWS-LC, and not with OpenSSL.

Second, we currently statically link a copy of OpenSSL in our wheels (binary artifacts). We are beginning the process of looking into what would be required to change our wheels to link against one of the OpenSSL forks.

If we are able to successfully switch to one of OpenSSL’s forks for our binary wheels, we will begin considering the circumstances under which we would drop support for OpenSSL entirely.

[$] Format-specific compression with OpenZL

Post Syndicated from jake original https://lwn.net/Articles/1053018/

Lossless data compression is an important tool for reducing the storage
requirements of the world’s ever-growing data sets. Yann Collet developed
the LZ4
algorithm
and designed the Zstandard (or Zstd)
algorithm; he came to the 2025
Open Source Summit Japan
in Tokyo to talk about where data compression
goes from here. It turns out that we have reached a point where
general-purpose algorithms are only going to provide limited improvement;
for significant increases in compression, while keeping computation costs
within reason for data-center use, turning to format-specific techniques
will be needed.