All posts by jzb

Zig 0.16.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1067634/

The Zig project has announced version
0.16.0 of the Zig programming language.

This release features 8 months of work: changes
from 244 different contributors, spread among
1183 commits.

Perhaps most notably, this release debuts I/O
as an Interface
, but don’t sleep on the Language
Changes
or enhancements to the Compiler,
Build
System
, Linker,
Fuzzer,
and Toolchain
which are also included in this release.

LWN last covered Zig in
December 2025.

[$] Tagging music with MusicBrainz Picard

Post Syndicated from jzb original https://lwn.net/Articles/1066384/

Part of the “fun” that comes with curating a self-hosted music library is tagging
music so that it has accurate and uniform metadata, such as the band names, album titles,
cover images, and so on. This can be a tedious endeavor, but there are quite a few
open-source tools to make this process easier. One of the best, or at least my
favorite, is MusicBrainz Picard. It is
a cross-platform music-tagging application that pulls information from the
well-curated, crowdsourced MusicBrainz
database project and writes it to almost any audio file format.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1067595/

Security updates have been issued by Debian (gdk-pixbuf, gst-plugins-bad1.0, and xdg-dbus-proxy), Fedora (chromium, deepin-image-viewer, dtk6gui, dtkgui, efl, elementary-photos, entangle, flatpak, freeimage, geeqie, gegl04, gthumb, ImageMagick, kf5-kimageformats, kf5-libkdcraw, kf6-kimageformats, kstars, libkdcraw, libpasraw, LibRaw, luminance-hdr, nomacs, OpenImageIO, OpenImageIO2.5, photoqt, python-cryptography, rawtherapee, shotwell, siril, swayimg, vips, and webkitgtk), Red Hat (firefox and podman), Slackware (libarchive), SUSE (expat, glibc, GraphicsMagick, libcap-devel, libpng16, libtpms, nodejs24, openssl-1_0_0, openssl-1_1, openssl-3, openvswitch, polkit, python-requests, python311-biopython, python312, python39, and tigervnc), and Ubuntu (corosync, kvmtool, libxml-parser-perl, linux-azure, linux-azure, linux-azure-6.17, linux-azure, linux-azure-6.8, policykit-1, redis, lua5.1, lua-cjson, lua-bitop, rustc, vim, and xdg-dbus-proxy).

Servo now on crates.io

Post Syndicated from jzb original https://lwn.net/Articles/1067467/

The Servo project has announced
the first release of servo as a crate for use as a
library.

As you can see from the version number, this release is not a 1.0
release. In fact, we still haven’t finished discussing what 1.0 means
for Servo. Nevertheless, the increased version number reflects our
growing confidence in Servo’s embedding API and its ability to meet
some users’ needs.

In the meantime we also decided to offer a long-term support (LTS)
version of Servo, since breaking changes in the regular monthly
releases are expected and some embedders might prefer doing major
upgrades on a scheduled half-yearly basis while still receiving
security updates and (hopefully!) some migration guides. For more
details on the LTS release, see the respective section in
the Servo book
.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1067436/

Security updates have been issued by AlmaLinux (fontforge, freerdp, libtiff, nginx, nodejs22, and openssh), Debian (bind9, chromium, firefox-esr, flatpak, gdk-pixbuf, inetutils, mediawiki, and webkit2gtk), Fedora (corosync, libcap, libmicrohttpd, libpng, mingw-exiv2, mupdf, pdns-recursor, polkit, trafficserver, trivy, vim, and yarnpkg), Mageia (libpng12, openssl, python-django, python-tornado, squid, and tomcat), Red Hat (rhc), Slackware (openssl), SUSE (chromedriver, chromium, cockpit, cockpit-machines, cockpit-podman, cockpit-tukit, crun, firefox, fontforge-20251009, glibc, go1, helm3, libopenssl-3-devel, libpng16, libradcli10, libtasn1, nghttp2, openssl-1_0_0, openssl-1_1, ovmf, perl-XML-Parser, python-cryptography, python-Flask-HTTPAuth, python311-Django4, python313-Django6, python315, sudo, systemd, tar, tekton-cli, tigervnc, util-linux, and zlib), and Ubuntu (mongodb, qemu, and retroarch).

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1067200/

Security updates have been issued by AlmaLinux (container-tools:rhel8, fontforge, freerdp, go-toolset:rhel8, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good, kernel, kernel-rt, libtasn1, mariadb:10.11, mysql:8.4, nginx:1.24, openssh, pcs, python-jinja2, python3.9, ruby:3.1, vim, virt:rhel and virt-devel:rhel, and xmlrpc-c), Debian (libyaml-syck-perl and openssh), Fedora (cockpit, crun, dnsdist, doctl, fido-device-onboard, libcgif, libpng12, libpng15, mbedtls, opensc, and util-linux), Red Hat (git-lfs, go-toolset:rhel8, grafana, grafana-pcp, and rhc), Slackware (libpng), SUSE (389-ds, aws-c-event-stream, bind, cockpit, cockpit-repos, corepack24, dcmtk, dnsdist, docker-compose, expat, firefox, firefox-esr, gnome-online-accounts, gvfs, gnutls, jupyter-jupyterlab-templates, kea, libIex-3_4-33, libpng16, mapserver, perl-XML-Parser, postgresql13, postgresql16, python-Pillow, python311-lupa, thunderbird, tigervnc, and tomcat10), and Ubuntu (linux-azure-fips, linux-hwe, linux-intel-iot-realtime, linux-nvidia-tegra-5.15, openssl, openssl1.0, and python-django).

Relicensing versus license compatibility (FSF Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1066926/

The Free Software Foundation has published
a short article on relicensing versus license compatibility.

The FSF’s Licensing and
Compliance Lab
receives many questions and license violation reports
related to projects that had their license changed by a downstream
distributor, or that are combined from two or more programs under
different licenses. We collaborated with Yoni Rabkin, an experienced
and long time FSF licensing volunteer, on an updated version of his
article to provide the free software community with a general
explanation on how the GNU General Public License (GNU GPL) is
intended to work in such situations.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1066972/

Security updates have been issued by Debian (firefox-esr, postgresql-13, and tiff), Fedora (bind, bind-dyndb-ldap, cef, opensc, python-biopython, python-pydicom, and roundcubemail), Slackware (mozilla), SUSE (ckermit, cockpit-repos, dnsdist, expat, freerdp, git-cliff, gnutls, heroic-games-launcher, libeverest, openssl-1_1, openssl-3, polkit, python-poetry, python-requests, python311-social-auth-app-django, and SDL2_image-devel), and Ubuntu (dogtag-pki, gdk-pixbuf, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gke,
linux-gkeop, linux-ibm, linux-ibm-5.15, linux-intel-iotg,
linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra,
linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux-raspi,
linux-xilinx-zynqmp, linux-aws-6.8, linux-gcp-6.8, linux-hwe-6.8, linux-ibm-6.8,
linux-lowlatency-hwe-6.8, linux-fips, linux-aws-fips, linux-gcp-fips, linux-oracle, linux-oracle-6.17, linux-raspi, linux-realtime, openssl, and squid).

[$] Ripping CDs and converting audio with fre:ac

Post Syndicated from jzb original https://lwn.net/Articles/1062141/

It has been a little while since LWN last surveyed tools for managing a digital
music collection
. In the intervening decades, many Linux users have moved on to
music streaming services, found them wanting, and are looking to curate their own
collection once again. There are plenty of choices when it comes to
ripping, managing, and playing digital audio; so many, in fact, that it can be a
bit daunting. After years of tinkering, I’ve found a few tools that work well for
managing my digital library: the first I’d like to cover is the fre:ac free audio encoder for ripping music from
CDs and converting between audio formats.

Nix privilege escalation security advisory

Post Syndicated from jzb original https://lwn.net/Articles/1066813/

The NixOS project has announced
a critical vulnerability
in many versions of the Nix package
manager’s daemon. The flaw was introduced as part of a fix for a
prior vulnerability in 2024
. According to the advisory,
all default configurations of NixOS and systems building untrusted derivations
are impacted.

A bug in the fix for CVE-2024-27297
allowed for arbitrary overwrites of files writable by the Nix process
orchestrating the builds (typically the Nix daemon running as root in
multi-user installations) by following symlinks during fixed-output
derivation output registration. This affects sandboxed Linux builds –
sandboxed macOS builds are unaffected. The location of the temporary
output used for the output copy was located inside the build chroot. A
symlink, pointing to an arbitrary location in the filesystem, could be
created by the derivation builder at that path. During output
registration, the Nix process (running in the host mount namespace)
would follow that symlink and overwrite the destination with the
derivation’s output contents.

In multi-user installations, this allows all users able to submit
builds to the Nix daemon (allowed-users – defaulting to all users) to
gain root privileges by modifying sensitive files.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1066809/

Security updates have been issued by Debian (openssl), Fedora (corosync, goose, kea, pspp, and rauc), Mageia (python-pygments, roundcubemail, and tigervnc), SUSE (bind, gimp, google-cloud-sap-agent, govulncheck-vulndb, ignition, ImageMagick, python, python-PyJWT, and python-pyOpenSSL), and Ubuntu (adsys, juju-core, lxd, python-django, and salt).

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1066665/

Security updates have been issued by AlmaLinux (crun, kernel, and kernel-rt), Debian (dovecot), Fedora (calibre and nextcloud), Mageia (freerdp, polkit-122, python-nltk, python-pyasn1, vim, and xz), Red Hat (edk2 and openssl), SUSE (avahi, cockpit, python-pyOpenSSL, python311, and tar), and Ubuntu (lambdaisland-uri-clojure, linux-gcp, linux-gcp-4.15, linux-gcp-fips, linux-oem-6.17, and linux-realtime-6.17).

Introducing the FreeBSD laptop integration testing project

Post Syndicated from jzb original https://lwn.net/Articles/1066593/

Recently, the FreeBSD Foundation has been making
progress
on improving the operating system’s support for modern
laptop hardware. The foundation is now looking to expand testing to
encompass a wider range of hardware; it has announced
a laptop integration testing project to allow the community to easily
test FreeBSD’s compatibility with laptops and submit the results.

With limited access to testing systems, there’s only so much we can
do! We hope to work together with volunteers from the community who
want FreeBSD to work well on their laptops.

While we expect device hardware and software enumeration to be a
fully automated process, we feel that manually-submitted comments
about personal experience with FreeBSD are equally valuable. We plan
to highlight this commentary on our “matrix of compatibility” webpage
for each tested laptop.

We are striving to make it as easy as possible to submit your
results. You won’t have to worry about environment setup, submission
formatting, or any repo-specific details!

See the project
repository
and testing
instructions
for more.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1066505/

Security updates have been issued by AlmaLinux (freerdp, grafana, grafana-pcp, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free, kernel, libpng12, libpng15, perl-YAML-Syck, python3, and rsync), Debian (dovecot, libxml-parser-perl, pyasn1, python-tornado, roundcube, tor, trafficserver, and valkey), Fedora (bind9-next, chromium, cmake, domoticz, freerdp, giflib, gst-devtools, gst-editing-services, gstreamer1, gstreamer1-doc, gstreamer1-plugin-libav, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, gstreamer1-rtsp-server, gstreamer1-vaapi, libgsasl, libinput, libopenmpt, mapserver, mingw-binutils, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-libpng, mingw-python3, nginx-mod-modsecurity, openbao, python-gstreamer1, python3.12, python3.13, python3.14, python3.9, rust, rust-sccache, tcpflow, and vim), Red Hat (ncurses), Slackware (infozip and krita), SUSE (chromium, corosync, keybase-client, libinput-devel, osslsigncode, python-pillow, python311-Flask-Cors, python313, and python314), and Ubuntu (libarchive and spip).

[$] Ubuntu’s GRUBby plans

Post Syndicated from jzb original https://lwn.net/Articles/1065420/

GNU GRUB 2, mostly just
referred to as GRUB these days, is the most widely used boot loader
for x86_64 Linux systems. It supports reading
from a vast selection of filesystems, handles booting modern systems
with UEFI or legacy systems with a BIOS, and even allows users to customize the
“splash” image displayed when a system boots. Alas, all of those features come with
a price; GRUB has had a parade
of security vulnerabilities
over the years. To mitigate some of those
problems, Ubuntu
core developer
and Canonical employee Julian Andres Klode has proposed removing
a number of features
from GRUB in Ubuntu 26.10 to improve GRUB’s
security profile. His proposal has not been met with universal acclaim; many of the
features Klode would like to remove have vocal proponents.

No kidding: Gentoo GNU/Hurd

Post Syndicated from jzb original https://lwn.net/Articles/1066241/

On April 1, the Gentoo Linux project published a blog post
announcing that it was switching to GNU Hurd as its primary
kernel as an April Fool’s joke. While that is not true, the project
has followed up with an announcement
of a new Gentoo port to the Hurd:

Our crack team has been working hard to port Gentoo to the Hurd and
can now share that they’ve succeeded, though it remains still in a
heavily experimental stage. You can try Gentoo GNU/Hurd using a
pre-prepared disk image. The easiest way to do this is with QEMU
[…]

We have developed scripts to build this image locally and
conveniently work on further development of the Hurd port. Release
media like stages and automated image builds are future goals, as is
feature parity on x86-64. Further contributions are welcome,
encouraged, and needed. Be patient, expect to get your hands dirty,
anticipate breakage, and have fun!

Oh, and Gentoo GNU/Hurd also works on real hardware!

Text for the April Fool’s post is available at the bottom of the
real announcement.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1066236/

Security updates have been issued by AlmaLinux (freerdp, grafana, kernel, rsync, and thunderbird), Debian (chromium, inetutils, and libpng1.6), Fedora (bind9-next, nginx-mod-modsecurity, and openbao), Mageia (firefox, nss and thunderbird), Red Hat (container-tools:rhel8), SUSE (conftest, dnsdist, ignition, libsoup, libsoup2, LibVNCServer, libXvnc-devel, opensc, ovmf-202602, perl-Crypt-URandom, python-tornado, python311-ecdsa, python311-Pygments, python315, tar, and wireshark), and Ubuntu (cairo, jpeg-xl, linux, linux-aws, linux-aws-6.17, linux-gcp, linux-gcp-6.17,
linux-hwe-6.17, linux-realtime, linux, linux-aws, linux-aws-hwe, linux-kvm, linux-oracle, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-ibm,
linux-lowlatency, linux-nvidia, linux-raspi, linux-fips, linux-fips, linux-aws-fips, linux-fips, linux-aws-fips, linux-gcp-fips, and linux-realtime, linux-realtime-6.8, linux-raspi-realtime).

SFC: What the FCC router ban means for FOSS

Post Syndicated from jzb original https://lwn.net/Articles/1066162/

Denver Gingerich of the Software Freedom Conservancy (SFC) has published
an article
on the impact of the ban on
the sale of all new home routers
not made in the United States
issued by the Federal Communications Commission (FCC). The SFC, of
course, is the organization
behind the OpenWrt One router
.

Since software updates to already-FCC-approved devices do not
require a new FCC approval, it appears the FCC is trying to move
beyond its usual authorization procedures to restrict what
manufacturers are allowed to push to existing routers. However, the
FCC notably does not restrict software changes made by owners of
routers in the U.S. In particular, there is no indication that updates
people make to their own routers, using software they have sourced
themselves, would run afoul of any past or present FCC rule.

As a result, we do not believe that this new FCC decision affects
whether and how people can run OpenWrt or other user-selected firmware
updates on routers they have already purchased. Not only is this an
important right in relation to our ownership and control of our own
devices, it also ensures that people can keep their routers secure for
far longer than the manufacturer may choose to provide security
updates, by allowing them to install up-to-date community software
that supports routers for 10, 15, or even more years after their
initial release date, as OpenWrt does for many devices.

He also notes that, as the OpenWrt One is already FCC-approved,
there should be no impact on its availability in the US. The SFC has
asked the FCC for clarification and plans to provide updates when they
receive a reply.