All posts by jzb

[$] A PHP license change is imminent

Post Syndicated from jzb original https://lwn.net/Articles/1063993/

PHP’s licensing has been a source of confusion for some time. The project is,
currently, using two licenses that cover different parts of the code base: PHP v3.01 for the
bulk of the code and Zend v2.0 for code
in the Zend directory. Much has changed
since the project settled on those licenses in 2006, and the need for custom
licensing seems to have passed. An effort to simplify PHP’s licensing, led by
Ben Ramsey, is underway; if successful, the existing licenses will be deprecated
and replaced by the BSD
three-clause
license. The PHP community is now voting on the license
update RFC
through April 4, 2026.

Krita 5.3.0 and 6.0.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1064477/

The Krita project has announced
the release of Krita 5.3.0 and 6.0.0:

Krita 5.3/6.0 is the result of many years of work by the Krita
developers. Some features have been rewritten from the ground up,
others make their first appearance.

Enjoy the completely new text feature: on canvas editing, full
opentype support, text flowing into shapes. It is now easier than ever
to create vector-based panels for comic pages. Tools got extended: for
instance, the fill tool now can close gaps. The liquify mode of the
transform tool is much faster. There are new filters: a propagate
colors filter and a reset transparent filter. Support for HDR painting
has been improved. The recorder docker can now work in real
time. There is improved support for file formats, like support for
text objects in PSD files. And much, much, much more!

According to the announcement, the versions are almost functionally
identical. However, the 6.0.0 release is the first based on Qt 6;
it has more Wayland functionality but is considered experimental. It
cautions that users should stick to 5.3.0 for real work. See
the release
notes
for a full list of changes.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1064474/

Security updates have been issued by Debian (strongswan and vlc), Fedora (cmake, giflib, and python-diskcache), SUSE (curl, docker-stable, freeciv, freerdp, freerdp2, freetype2, go1.25-openssl, go1.26-openssl, GraphicsMagick, gvfs, harfbuzz, kernel, lemon, libpng16, librsvg, libsodium, libsoup, net-snmp, protobuf, python-Authlib, python-maturin, python-tornado6, python310, python311-pypdf, python311-PyPDF2, python314, python39, rust-keylime, strongswan, systemd, ucode-intel, util-linux, and vim), and Ubuntu (gvfs, linux-aws-6.8, linux-azure, linux-azure, linux-azure-4.15, linux-azure-fips, linux-hwe-5.4, linux-ibm, linux-intel-iot-realtime, linux-nvidia-tegra-igx, linux-realtime-6.17, pyopenssl, rust-sized-chunks, strongswan, systemd, and tiff).

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1064298/

Security updates have been issued by AlmaLinux (gimp:2.8, grub2, kernel, libarchive, libvpx, nginx, opencryptoki, python3.12, vim, yggdrasil, and yggdrasil-worker-package-manager), Debian (chromium, freeciv, libvirt, libyaml-syck-perl, mapserver, ruby-rack, spip, and webkit2gtk), Fedora (chromium, cpp-httplib, glib2, libsoup3, localsearch, openssh, python-scitokens, python-ujson, python3.6, scitokens-cpp, uxplay, wordpress, and xen), Mageia (expat), Red Hat (osbuild-composer), SUSE (Announcement ID: SUSE-SU-2026:0940-1 Release Date: 2026-03-20T13:41:23Z Rating: important References:, Announcement ID: SUSE-SU-2026:0941-1 Release Date: 2026-03-20T13:41:30Z Rating: important References:, Announcement ID: SUSE-SU-2026:0943-1 Release Date: 2026-03-20T13:41:33Z Rating: important References:, Announcement ID: SUSE-SU-2026:0944-1 Release Date: 2026-03-20T13:41:37Z Rating: important References:, Announcement ID: SUSE-SU-2026:0945-1 Release Date: 2026-03-20T13:41:40Z Rating: important References:, chromium, docker, go1.25-openssl, GraphicsMagick, helm, mumble, python311, python311-pyasn1, python313, runc, sqlite3, and tempo-cli), and Ubuntu (debian-goodies and libnet-cidr-perl).

Agama 19 released

Post Syndicated from jzb original https://lwn.net/Articles/1064067/

Version
19
of the Agama installer for openSUSE and SUSE has been
released. This release includes major changes in Agama’s architectural
design, organization of the web interface, and more.

We always wanted Agama to follow the schema […] in which the core of
the installer could be controlled through a consistent and simple
programming interface (an API, in developers jargon). In that schema,
the web-based user interface, the command-line tools and the
unattended installation are built on top of that generic API.

But previous versions of Agama were full of quirks that didn’t
allow us to define an API that would match our quality standards as a
solid foundation to build a simple but comprehensive installer. Agama
19 represents a quite significant architectural overhaul, needed to
leave all those quirks behind and to define mechanisms that can be the
cornerstone for any future development.

LWN last looked at
Agama
in September 2025.

[$] A truce in the Manjaro governance struggle

Post Syndicated from jzb original https://lwn.net/Articles/1063717/

Members of the Manjaro Linux distribution’s community have published
a “Manjaro 2.0 Manifesto
that contains a list of complaints and a demand to restructure the project to provide
a clear separation between the community and Manjaro as a company. The manifesto
asserts that the project’s leadership is not acting in the best interests of the
community, which has caused developers to leave and innovation to stagnate. It
also demands a handover of the Manjaro trademark and other assets to a
to-be-formed nonprofit association. The responses on the Manjaro forum showed widespread support
for the manifesto; Philip Müller, project lead and CEO of the Manjaro
company, largely stayed out of the discussion. However, he surfaced
on March 19 to say he was “open to serious discussions“, but only
after a nonprofit had actually been set up.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1063990/

Security updates have been issued by AlmaLinux (capstone, glibc, grub2, kernel, libarchive, libpng, mysql, and python3.11), Debian (evolution-data-server, imagemagick, and snapd), Fedora (bpfman, chromium, cpp-httplib, dotnet10.0, openssh, polkit, and vim), Mageia (graphicsmagick, imagemagick, openssh, and perl-YAML-Syck), Oracle (capstone, grub2, kernel, mysql, and python-pyasn1), Red Hat (container-tools:rhel8, rhc, yggdrasil, and yggdrasil-worker-package-manager), SUSE (cargo1.92, cargo1.93, chromedriver, coturn, curl, freerdp, jq, kernel, libssh, php-composer2, python311-uv, python312, qemu, tomcat, util-linux, vim, and virtiofsd), and Ubuntu (exiv2, freerdp3, glance, linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, and linux-aws-fips, linux-fips, linux-gcp-fips).

Radicle 1.7.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1063712/

Version
1.7.0
(“Daffodil”) of the Radicle peer-to-peer, local-first code
collaboration stack has been released. Some of the changes in this
release include improved I/O usage, the ability to block nodes at the
connection level, and clearer errors for rad id
updates. See the release notes for a full list of changes and bug
fixes.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1063659/

Security updates have been issued by Debian (freetype), Fedora (aqualung, kiss-fft, libtasn1, mac, and vim), Red Hat (libarchive, osbuild-composer, and rhc), Slackware (expat), SUSE (ca-certificates-mozilla, chromium, cockpit, cockpit-machines, cockpit-podman, curl, docker, docker-compose, docker-stable, gnutls, gstreamer-rtsp-server, gstreamer-plugins-ugly, gstreamer- plugins-rs, gstreamer-plugins-libav, gstreamer-plugins-good, gstreamer-plugins- base, gstreamer-plugins-bad, gstreamer-docs, gstreamer-devtools, gstreamer, gvfs, helm, kernel, krb5-appl, libsoup, libxslt, libxml2, openssh, python-cryptography, python-django, python-pypdf2, python-simpleeval, python311, qemu, ruby4.0-rubygem-sprockets, ruby4.0-rubygem-thor, ruby4.0-rubygem-web-console, ruby4.0-rubygem-websocket-extensions, skaffold, smb4k, tomcat, ucode-intel, util-linux, virtiofsd, and zlib), and Ubuntu (bouncycastle, exiv2, freerdp3, linux-aws, linux-aws-5.4, linux-gcp-5.4, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux-aws-fips, python2.7, roundcube, and valkey).

[$] LWN.net Weekly Edition for March 19, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1062571/

Inside this week’s LWN.net Weekly Edition:

  • Front: Privacy battles; page-cache-timing protections; null filesystems; Fedora Sandbox; safer kmalloc(); BPF in io_uring.
  • Briefs: AppArmor vulnerabilities; snapd vulnerability; Sashiko; DPL election; Fedora Asahi 43; GIMP 3.2; Marknote 1.5; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

GNOME 50 released

Post Syndicated from jzb original https://lwn.net/Articles/1063466/

GNOME 50 has been
released. Notable changes in this release include enhancements to the
Orca screen-reader application, interface and performance improvements
for GNOME’s file manager (Files), a “massive set of stability and
performance updates
” for its display-handling technologies, and
much more. See also the “What’s new
for developers
” article that covers changes of interest to GNOME
and GNOME application developers.

Local-privilege escalation in snapd

Post Syndicated from jzb original https://lwn.net/Articles/1063453/

Qualys has discovered
a local-privilege escalation (LPE) vulnerability
affecting Ubuntu
Desktop 24.04 and later:

This flaw (CVE-2026-3888) allows an unprivileged local attacker to
escalate privileges to full root access through the interaction of two
standard system components: snap-confine and systemd-tmpfiles.

More details are available in the security
advisory
. Canonical has published updated packages as well as instructions
for verifying if a system is vulnerable and how to upgrade if so.

Fedora Asahi Remix 43 released

Post Syndicated from jzb original https://lwn.net/Articles/1063451/

Fedora Asahi Remix 43 is
now available
:

This release incorporates all the exciting improvements brought by
Fedora
Linux 43
. Notably, package management is significantly
upgraded with RPM 6.0 and the new
DNF5 backend for PackageKit for Plasma Discover and GNOME Software
ahead of Fedora Linux 44. It also continues to provide extensive
device support. This includes newly added support for the Mac Pro,
microphones in M2 Pro/Max MacBooks, and 120Hz refresh rate for
the built-in displays for MacBook Pro 14/16 models.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1063446/

Security updates have been issued by AlmaLinux (.NET 10.0, .NET 9.0, compat-openssl11, container-tools:rhel8, grub2, and libvpx), Debian (ansible, gst-plugins-base1.0, and nodejs), Fedora (chromium, forgejo, and systemd), Oracle (container-tools:rhel8, grub2, kernel, libpng, libvpx, nginx, opencryptoki, python3.12, and vim), Red Hat (firefox, python-wheel, python3.12-wheel, and thunderbird), SUSE (389-ds, chromium, clamav, container-suseconnect, curl, freerdp, gvfs, kea, kubernetes, ruby4.0-rubygem-minitar, ruby4.0-rubygem-multi_xml, ruby4.0-rubygem-nokogiri, ruby4.0-rubygem-puma, ruby4.0-rubygem-rack, ruby4.0-rubygem-rack-session, ruby4.0-rubygem-rails, ruby4.0-rubygem-rails-html-sanitizer, ruby4.0-rubygem-railties, ruby4.0-rubygem-rubyzip, vim, and xen), and Ubuntu (flask, libssh, linux-aws-5.15, linux-gcp-5.15, linux-gke, linux-hwe-5.15,
linux-intel-iotg-5.15, linux-lowlatency-hwe-5.15, linux-oracle-5.15, linux-gcp-6.17, linux-realtime, linux-realtime, linux-realtime, linux-realtime-6.8, snapd, and vim).

FSFE reports trouble with payment provider

Post Syndicated from jzb original https://lwn.net/Articles/1063287/

The Free Software Foundation Europe (FSFE) is reporting
that payment provider Nexi has terminated its contract without prior
notice, which means that a number of FSFE supporters’ recurring
payments have been halted:

Over the past few months, our former payment provider Nexi
S.p.A. (“Nexi”) requested access to private data, which we understood
to be specifically the usernames and passwords of our supporters. We
have refused this request. All our attempts to clarify Nexi’s request,
or to understand how their need for such information was necessary and
legal, were met with what we consider to be vague and unsatisfactory
explanations relating to a general need for risk analysis.

[…] The decisions that Nexi has made are incomprehensible to
us. Over the last months, as part of a security audit that Nexi
claimed to be conducting, we have provided them with large amounts of
the FSFE’s financial documentation, which even included private
information of our executive staff. We have answered all of their
questions. But we have to draw a line when private companies like Nexi
demand access to the sensitive and private data of our supporters.

According to the blog post, more than 450 supporters have been
affected by this. The FSFE’s donation pages have been updated with its
new payment provider.

[$] Fedora ponders a “sandbox” technology lifecycle

Post Syndicated from jzb original https://lwn.net/Articles/1062579/

Fedora Project Leader (FPL) Jef Spaleta has issued
a “modest proposal” for a technology-innovation-lifecycle process
that would provide more formal structure for adopting technologies in
Fedora. The idea is to spur innovation in the project without having an adverse
impact on stability or the release process. Spaleta’s proposal is
somewhat light on details, particularly as far as specific examples of
which projects would benefit; however, the reception so far is mostly
positive and some think that it could make Fedora more “competitive” by being the
place where open-source projects come to grow.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1063248/

Security updates have been issued by Fedora (mingw-openexr, vim, and yarnpkg), Oracle (freerdp), Red Hat (389-ds-base, container-tools:rhel8, libpng, libpng15, nginx, nginx:1.24, nginx:1.26, opencryptoki, python3, python3.11, python3.12, and python3.9), SUSE (ruby4.0-rubygem-activestorage, ruby4.0-rubygem-activesupport, ruby4.0-rubygem-glogalid, ruby4.0-rubygem-grpc, ruby4.0-rubygem-jquery-rails, ruby4.0-rubygem-loofah, and rubygem4.0-rubygem-fluentd), and Ubuntu (curl, linux, linux-aws, linux-aws-6.17, linux-gcp, linux-hwe-6.17, linux-oracle,
linux-oracle-6.17, linux, linux-aws, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop,
linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-lowlatency,
linux-lowlatency-hwe-6.8, linux-oracle, linux-oracle-6.8, linux, linux-aws, linux-gcp, linux-gkeop, linux-ibm, linux-ibm-5.15,
linux-intel-iotg, linux-kvm, linux-lowlatency, linux-nvidia,
linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle,
linux-xilinx-zynqmp, linux-fips, linux-aws-fips, linux-gcp-fips, linux-gcp, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, python-cryptography, and roundcube).