All posts by jake

Evans: A data model for Git (and other docs updates)

Post Syndicated from jake original https://lwn.net/Articles/1053595/

On her blog, Julia Evans writes about
improving Git documentation
, including a new data
model man page
she wrote with Marie
LeBlanc Flanagan, and updates to the pages for several other Git sub-commands
(add, checkout, push, and pull). As
part of the process, she asked Git users to describe problems they had run into
in the documentation, which helped guide the changes that she made.

I’m excited about this because understanding how Git organizes its commit and branch data has really helped me reason about how Git works over the years, and I think it’s important to have a short (1600 words!) version of the data model that’s accurate.

The “accurate” part turned out to not be that easy: I knew the basics of how Git’s data model worked, but during the review process I learned some new details and had to make quite a few changes (for example how merge conflicts are stored in the staging area).

[$] Lessons from creating a gaming-oriented scheduler

Post Syndicated from jake original https://lwn.net/Articles/1051430/

At the 2025 Linux Plumbers
Conference
(LPC), held in Tokyo in mid-December, Changwoo Min led a session on what
he has learned while developing the
“latency-criticality
aware virtual deadline
” (LAVD) scheduler, which is aimed at gaming
workloads. The session was part of the Gaming
on Linux
microconference, which is a new entrant into LPC; organizers
hope to see it return next year in
Prague
and, presumably, beyond. LAVD uses the extensible scheduler class (sched_ext) and has
the primary goal of minimizing stuttering
in games;
it is implemented in a combination of BPF and Rust.

[$] Tools for successful documentation projects

Post Syndicated from jake original https://lwn.net/Articles/1049976/

At Open
Source Summit Japan
2025, Erin McKean talked about the challenges to
producing good project documentation, along with some tooling that can help
guide the process toward success. It is a problem that many projects
struggle with and one that her employer, Google, gained a lot of experience
with from its now-concluded Season of Docs
initiative. Through that program, more than 200 case studies of
documentation projects were gathered that were mined for common problems
and solutions, which led to the tools and techniques that McKean described.

[$] A “frozen” dictionary for Python

Post Syndicated from jake original https://lwn.net/Articles/1047238/

Dictionaries are ubiquitous in Python code; they are the data structure of
choice for a wide variety of tasks. But dictionaries are mutable, which
makes them problematic for sharing data in concurrent code. Python has
added various concurrency features to the language over the last decade or
so—async, free threading without the global interpreter lock
(GIL), and independent subinterpreters—but users must work out their own
solution for an immutable dictionary that can be safely shared by
concurrent code. There are existing modules that could be used, but a recent proposal, PEP 814 (“Add frozendict
built-in type”), looks to bring the feature to the language itself.

Django 6.0 released

Post Syndicated from jake original https://lwn.net/Articles/1049111/

The Django Python web
framework project has announced
the release of Django 6.0
including many new features, as can be seen in
the release
notes
. Some highlights include template partials for modularizing
templates, a flexible task framework for running background tasks, a
modernized email API, and a Content
Security Policy
(CSP) feature that provides the ability to “easily configure and enforce browser-level security policies to protect against content injection“.

Security updates for Friday

Post Syndicated from jake original https://lwn.net/Articles/1048596/

Security updates have been issued by Debian (krita and tryton-server), Oracle (bind9.18, ipa, kernel, libssh, redis, redis:7, sqlite, sssd, and vim), Slackware (cups), SUSE (containerd, cups, curl, dovecot24, git-bug, gitea-tea, glib2, grub2, himmelblau, java-25-openjdk, kernel, libmicrohttpd, libvirt, pnpm, powerpc-utils, python311, python313, redis, rnp, runc, sssd, tomcat11, unbound, and xwayland), and Ubuntu (cups, libxml2, openvpn, and webkit2gtk).

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/1048448/

Security updates have been issued by Debian (kdeconnect, libssh, and samba), Fedora (7zip, docker-buildkit, and docker-buildx), Oracle (bind, buildah, cups, delve and golang, expat, firefox, gimp, go-rpm-macros, haproxy, kernel, lasso, libsoup, libtiff, mingw-expat, openssl, podman, python-kdcproxy, qt5-qt3d, runc, squid, thunderbird, tigervnc, valkey, webkit2gtk3, xorg-x11-server, and xorg-x11-server-Xwayland), SUSE (buildah, cloudflared, containerd, expat, firefox, gnutls, helm, kernel, libxslt, mysql-connector-java, ongres-scram, openbao, openexr, openssh, podman, python311, python312, ruby2.5, rubygem-rack, runc, samba, sssd, tiff, unbound, and yelp), and Ubuntu (edk2, ffmpeg, h2o, python3.13, rust-openssl, and valkey).

Racket 9.0 released

Post Syndicated from jake original https://lwn.net/Articles/1047549/

The Racket programming language
project has released Racket
version 9.0
. Racket is a descendant of Scheme, so it is part of the Lisp family of languages. The headline feature in the release is parallel
threads
, which adds to the concurrency tools in the language: “While
Racket has had green threads for some time, and supports parallelism via
futures and places, we feel parallel threads is a major addition.
”
Other new features include the black-box
wrapper to prevent the compiler from optimizing calculations away, the decompile-linklet
function to map linklets
back to an s-expression, the
addition of Weibull
distributions
to the math library, and more.

[$] Unpacking for Python comprehensions

Post Syndicated from jake original https://lwn.net/Articles/1046216/

Unpacking Python iterables of various sorts, such as dictionaries or lists,
is useful in a number of contexts, including for function arguments, but
there has long been a call for extending that capability to comprehensions. PEP 798 (“Unpacking in
Comprehensions”) was first proposed in June 2025 to fill that gap. In early
November, the steering council accepted
the PEP, which means that the feature will be coming to Python 3.15 in
October 2026. It may be something of a niche feature, but it is an
inconsistency
that has been apparent for a while—to the point that some Python programmers
assume that it is already present in the language.

[$] Julia 1.12 brings progress on standalone binaries and more

Post Syndicated from jake original https://lwn.net/Articles/1044280/

Julia is a modern programming
language that is of particular interest to scientists due to its high
performance combined with language features such as Lisp-style macros, an
advanced type system, and multiple dispatch. We last looked at Julia in January on the occasion of
its 1.11 release. Early in October Julia 1.12
appeared
, bringing a handful of quality-of-life improvements for Julia
programmers, most notably support, though still experimental and limited,
for the creation of binaries.

Python steering council accepts lazy imports

Post Syndicated from jake original https://lwn.net/Articles/1044844/

Barry Warsaw, writing for the Python steering council, has announced
that PEP 810 (“Explicit lazy
imports”) has been approved, unanimously, by the four who could vote. Since
Pablo Galindo Salgado was one of the PEP authors, he did not vote. The PEP provides a way to defer importing modules until the names
defined in a module are
needed by other parts of the program. We covered the PEP and the discussion around it
a few weeks back. The council also had “recommendations about some of
the PEP’s details, a few suggestions for filling a couple of small
gaps
“, including:

Use lazy as the keyword. We debated many of the given alternatives
(and some we came up with ourselves), and ultimately agreed with the PEP’s
choice of the lazy keyword. The closest challenger was
defer, but once we tried to use that in all the places where the
term is visible, we ultimately didn’t think it was as good an overall
fit. The same was true with all the other alternative keywords we could
come up with, so… lazy it is!

What about from foo lazy import bar? Nope! We like that in both module imports and from-imports that the lazy keyword is the first thing on the line. It helps to visually recognize lazy imports of both varieties.

[$] Retrieving pixels from Android phones with Pixnapping

Post Syndicated from jake original https://lwn.net/Articles/1042715/

A new class of attacks on Android phones, called “Pixnapping“, was announced on
October 13. It allows a malicious app to gather output rendered in a
victim app, pixel-by-pixel, by exploiting a GPU side-channel. Depending on
what the victim app displays, anything from sensitive email and chats to
two-factor authentication (2FA) codes could be captured—and shipped off to
an attacker’s site.

[$] Explicit lazy imports for Python

Post Syndicated from jake original https://lwn.net/Articles/1041120/

Importing modules in Python is ubiquitous; most Python programs start
with at least a few import statements. But the performance impact
of those imports can be large—and may be entirely wasted effort if the
symbols imported end up being unused. There are multiple ways to lazily
import modules, including one in the standard library, but none of them are
part of the Python language itself. That
may soon change, if the recently proposed
PEP 810 (“Explicit lazy
imports”) is approved.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1042680/

Security updates have been issued by Debian (imagemagick, incus, lxd, pgagent, svgpp, and sysstat), Fedora (chromium, complyctl, fetchmail, firefox, mbedtls, mingw-binutils, mingw-python3, mingw-qt5-qtsvg, mingw-qt6-qtsvg, python3.10, python3.11, python3.12, python3.9, runc, and suricata), Mageia (expat), Red Hat (firefox, kernel, qt5-qtbase, and qt6-qtbase), Slackware (stunnel), SUSE (chromium, coredns, ctdb, firefox, kernel, libexslt0, libpoppler-cpp2, ollama, openssl-1_1, pam, samba, and thunderbird), and Ubuntu (samba).

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/1042330/

Security updates have been issued by AlmaLinux (kernel and libsoup3), Debian (chromium and firefox-esr), Fedora (httpd), Oracle (cups, ImageMagick, kernel, and vim), Red Hat (libssh), Slackware (samba), SUSE (alloy, exim, firefox-esr, ImageMagick, kernel, libcryptopp-devel, libQt6Svg6, libsoup-3_0-0, libtiff-devel-32bit, lsd, python3-gi-docgen, python311-Authlib, qt6-base, samba, and squid), and Ubuntu (ffmpeg, linux-oracle-6.8, redict, redis, samba, and subversion).

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1041779/

Security updates have been issued by AlmaLinux (compat-libtiff3, iputils, kernel, open-vm-tools, and vim), Debian (asterisk, ghostscript, kernel, linux-6.1, and tiff), Fedora (cef, chromium, cri-o1.31, cri-o1.32, cri-o1.33, cri-o1.34, docker-buildx, log4cxx, mingw-poppler, openssl, podman-tui, prometheus-podman-exporter, python-socketio, python3.10, python3.11, python3.12, python3.9, skopeo, and valkey), Mageia (open-vm-tools), Red Hat (compat-libtiff3, kernel, kernel-rt, vim, and webkit2gtk3), and SUSE (distrobuilder, docker-stable, expat, forgejo, forgejo-longterm, gitea-tea, go1.25, haproxy, headscale, open-vm-tools, openssl-3, podman, podofo, ruby3.4-rubygem-rack, and weblate).

[$] Enhancing FineIBT

Post Syndicated from jake original https://lwn.net/Articles/1039633/

At the Linux
Security Summit Europe
(LSS EU), Scott Constable and Sebastian
Österlund gave a talk on an enhancement to a control-flow integrity (CFI)
protection that was added to the kernel several years ago. The “FineIBT: Fine-grain Control-flow
Enforcement with Indirect Branch Tracking
” mechanism was merged for
Linux 6.2 in early 2023 to harden the kernel against CFI attacks of various
sorts, but needed some fixes and
enhancements
more recently. The talk looked at the CFI vulnerability
problem, FineIBT, and an enhanced version that is hoped to be able to unify
all of the disparate hardware and software mitigations to address both
regular and speculative CFI vulnerabilities.

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/1041404/

Security updates have been issued by AlmaLinux (gnutls, kernel, kernel-rt, and open-vm-tools), Debian (chromium, python-django, and redis), Fedora (chromium, insight, mirrorlist-server, oci-seccomp-bpf-hook, rust-maxminddb, rust-prometheus, rust-prometheus_exporter, rust-protobuf, rust-protobuf-codegen, rust-protobuf-parse, rust-protobuf-support, turbo-attack, and yarnpkg), Oracle (iputils, kernel, open-vm-tools, redis, and valkey), Red Hat (perl-File-Find-Rule and perl-File-Find-Rule-Perl), SUSE (expat, ImageMagick, matrix-synapse, python-xmltodict, redis, redis7, and valkey), and Ubuntu (fort-validator and imagemagick).

U-Boot v2025.10 released

Post Syndicated from jake original https://lwn.net/Articles/1041023/

Version 2025.10 of the U-Boot boot loader
has been released with new features, including Python tooling improvements,
cleanups for implicit header inclusions, better support for numerous Arm
platforms, support for new RISC-V platforms, better documentation, and
more. Maintainer Tom Rini also reports on some project news:

As I mentioned with the v2025.07
release, I was looking for a few people to step up and help with the
overall organization and management of the project. To that end, Peter
Robinson and Neil Armstrong have stepped up and have been helping me.
This has been part of the process for the project to join up under the
Software Freedom Conservancy’s (SFC) umbrella and have a legal entity
that can help the project work with other legal entities on things like
donations.