All posts by jzb

[$] California’s Digital Age Assurance Act and Linux distributions

Post Syndicated from jzb original https://lwn.net/Articles/1062112/

A recently enacted law in California imposes an age-verification requirement on
operating-system providers beginning next year. The language of the Digital
Age Assurance Act
does not restrict its requirements to proprietary or commercial
operating systems; projects like Debian, FreeBSD, Fedora, and others seem to be on
the hook just as much as Apple or Microsoft. There is some hope that the law will be
amended, but there is no guarantee that it will be. This means that the developer
communities behind Linux distributions are having to discuss whether and how to
comply with the law with little time and even less legal guidance.

Introducing Moonforge: a Yocto-based Linux OS (Igalia Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1062451/

Igalia has announced
the Moonforge Linux
distribution, based on OpenEmbedded
and Yocto.

Moonforge is an operating system framework for Linux devices that
simplifies the process of building and maintaining custom operating
systems.

It provides a curated collection of Yocto layers and configuration
files that help developers generate immutable, maintainable, and
easily updatable operating system images.

The goal is to offer the best possible developer experience for
teams building embedded Linux products. Moonforge handles the complex
aspects of operating system creation, such as system integration,
security, updates, and infrastructure, so developers can focus on
building and deploying their applications or devices.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1062403/

Security updates have been issued by AlmaLinux (kernel, kernel-rt, libvpx, nfs-utils, nginx:1.26, osbuild-composer, postgresql, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and python-pyasn1), Debian (imagemagick), Fedora (perl-Crypt-SysRandom-XS and systemd), Mageia (yt-dlp), Oracle (delve, gimp, git-lfs, go-rpm-macros, image-builder, kernel, libpng, libvpx, mysql8.4, nfs-utils, osbuild-composer, postgresql16, postgresql:12, postgresql:13, postgresql:15, postgresql:16, python-pyasn1, python3, python3.12, python3.9, and thunderbird), SUSE (python-aiohttp, python-maturin, python311-pymongo, rclone, and util-linux), and Ubuntu (linux-nvidia, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, and python-geopandas).

SUSE may be for sale, again

Post Syndicated from jzb original https://lwn.net/Articles/1062316/

Reuters is reporting
that private-equity firm EQT may be looking to sell SUSE:

EQT has hired investment bank Arma Partners to sound out a group of
private equity investors for a possible sale of the company, said the
sources, who requested anonymity to discuss confidential matters. The
​deliberations are at an early stage and there is no certainty that EQT
will ​proceed with a transaction, the sources said.

SUSE has traded hands a number of times over the years. Most
recently it was acquired by
EQT in 2018, was listed
on the Frankfurt Stock Exchange in 2021, and then taken
private
again by EQT in August 2023.

[$] Debian decides not to decide on AI-generated contributions

Post Syndicated from jzb original https://lwn.net/Articles/1061544/

Debian is the latest in an ever-growing list of projects to wrestle (again)
with the question of LLM-generated contributions; the latest debate stared in
mid-February, after
Lucas Nussbaum opened a
discussion
with a draft general resolution (GR) on whether Debian should
accept AI-assisted contributions. It seems to have, mostly, subsided without a GR
being put forward or any decisions being made, but the conversation was illuminating
nonetheless.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1062260/

Security updates have been issued by Debian (imagemagick), Fedora (chromium, matrix-synapse, mingw-zlib, perl-Net-CIDR, polkit, and rust-pythonize), Mageia (coturn, firefox, and thunderbird), Oracle (delve, git-lfs, gnutls, go-rpm-macros, image-builder, kernel, libsoup, nfs-utils, nginx:1.24, osbuild-composer, postgresql, thunderbird, udisks2, and valkey), Red Hat (grafana, image-builder, and opentelemetry-collector), SUSE (c3p0 and mchange-commons, corepack24, go1, ImageMagick, python-Flask, tomcat, tomcat10, tomcat11, virtiofsd, and weblate), and Ubuntu (apache2 and yara).

digiKam 9.0.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1062105/

Version
9.0.0
of the digiKam photo-management system has been
released. “This major version introduces groundbreaking
improvements in performance, usability, and workflow efficiency, with
a strong focus on modernizing the user interface, enhancing metadata
management, and expanding support for new camera models and file
formats.
” Some of the changes include a
new survey tool
, more advanced search and sorting options, as well
as bulk
editing of geolocation coordinates
.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1062103/

Security updates have been issued by AlmaLinux (delve, git-lfs, and postgresql16), Fedora (cef, chezmoi, chromium, coturn, erlang-hex_core, firefox, gh, gimp, k9s, keylime, keylime-agent-rust, libsixel, microcode_ctl, nextcloud, nss, perl-Crypt-URandom, pgadmin4, php-zumba-json-serializer, postgresql16-anonymizer, prometheus, python-asyncmy, python3.10, python3.11, python3.9, staticcheck, valkey, and vim), SUSE (chromedriver, chromium, coredns, expat, freetype2-devel, gitea-tea, go1.24-openssl, go1.25-openssl, grpc, gstreamer-rtsp-server, gstreamer-plugins-ugly,, helm, jetty-annotations, kubeshark-cli, libaec, libblkid-devel, libsoup, libxml2, libxslt, NetworkManager-applet-strongswan, podman, python-joserfc, python-Markdown, python-pypdf2, python-tornado, python-uv, python311-Django, python311-joserfc, python311-nltk, roundcubemail, and valkey), and Ubuntu (python3.4, python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, python3.14).

[$] Fedora shares strategy updates and “weird research university” model

Post Syndicated from jzb original https://lwn.net/Articles/1060190/

In early February, members of the Fedora Council met in Tirana,
Albania to discuss and set the strategic direction for the Fedora Project. The
council has published
summaries
from its strategy summit, and Fedora Project Leader (FPL) Jed Spaleta,
as well as some of the council members, held a video meeting to discuss outcomes from
the summit on February 25. Topics included a plan to experiment with Open Collective to raise
funds for specific Fedora projects, tools to build image-based editions, and
more. Spaleta also explained his model for Fedora governance.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1061738/

Security updates have been issued by Debian (chromium), Fedora (freerdp, libsixel, opensips, and yt-dlp), Mageia (python-django, rsync, and vim), Red Hat (go-rpm-macros and osbuild-composer), SUSE (7zip, assertj-core, autogen, c3p0, cockpit-machines, cockpit, cockpit-repos, containerized-data-importer, cpp-httplib, docker, docker-stable, expat, firefox, gnutls, go1.25-openssl, golang-github-prometheus-prometheus, haproxy, ImageMagick, incus, kernel, kubevirt, libsoup, libsoup2, mchange-commons, ocaml, openCryptoki, openvpn, php-composer2, postgresql14, postgresql15, python-Authlib, python-azure-core, python-nltk, python-urllib3_1, python311-Django4, python311-pillow-heif, python311-PyPDF2, python313, python313-Django6, qemu, rhino, roundcubemail, ruby4.0-rubygem-rack, sdbootutil, and wicked2nm), and Ubuntu (less, nss, python-bleach, qtbase-opensource-src, and zutty).

Buildroot 2026.02 released

Post Syndicated from jzb original https://lwn.net/Articles/1061543/

Peter Korsgaard has
announced version 2026.02
of Buildroot, a tool for generating
embedded Linux systems through cross-compilation. Notable changes
include added support for HPPA, use of the 6.19.x kernel headers by
default, better SBOM generation, and more.

Again a very active cycle with more than 1500 changes from 97 unique
contributors. I’m once again very happy to see so many “new” people next
to the “oldtimers”.

See the changelog
for full details. Thanks to Julien Olivain for pointing us to the announcement.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1061464/

Security updates have been issued by AlmaLinux (go-rpm-macros, libpng, thunderbird, udisks2, and valkey), Fedora (coturn, php-zumba-json-serializer, valkey, and yt-dlp), Red Hat (delve, go-rpm-macros, grafana, grafana-pcp, image-builder, osbuild-composer, and postgresql), Slackware (nvi), SUSE (firefox, glibc, haproxy, kernel, kubevirt, libsoup, libsoup2, libxslt, mozilla-nss, ocaml, python, python-Django, python-pip, util-linux, virtiofsd, wicked2nm,suse-migration-services,suse-migration- sle16-activation,SLES16-Migration,SLES16-SAP_Migration, and wireshark), and Ubuntu (gimp, linux-aws, linux-lts-xenial, linux-aws-fips, linux-azure, linux-azure-fips, linux-fips, nss, postgresql-14, postgresql-16, postgresql-17, and qemu).

[$] LWN.net Weekly Edition for March 5, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1060392/

Inside this week’s LWN.net Weekly Edition:

  • Front: Python’s bitwise-inversion operator; atomic buffered I/O; keeping open source open; Magit and Majutsu; IIIF; free software and free tools.
  • Briefs: Ad tracking; firmware updates; TCP zero-copy; Motorola GrapheneOS phones; Gram 1.0; groff 1.24.0; Texinfo 7.3; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1061295/

Security updates have been issued by AlmaLinux (container-tools:rhel8, firefox, go-rpm-macros, kernel, kernel-rt, mingw-fontconfig, nginx:1.24, thunderbird, and valkey), Debian (gimp), Fedora (apt, avr-binutils, keylime, keylime-agent-rust, perl-Crypt-URandom, python-apt, and rsync), Red Hat (go-rpm-macros and yggdrasil-worker-package-manager), Slackware (python3), SUSE (busybox, cosign, cups, docker, evolution-data-server, freerdp, glibc, gnome-remote-desktop, go1.24-openssl, go1.25-openssl, govulncheck-vulndb, libpng16, libsoup, libssh, libxml2, patch, postgresql14, postgresql15, postgresql16, postgresql17, postgresql18, python, python311, rust-keylime, smc-tools, tracker-miners, and zlib), and Ubuntu (curl, imagemagick, intel-microcode, linux, linux-aws, linux-kvm, linux-aws, linux-aws-5.15, linux-gcp-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle-5.15, linux-aws-fips, and linux-raspi, linux-raspi-5.4).

[$] Free software needs free tools

Post Syndicated from jzb original https://lwn.net/Articles/1060649/

One of the contradictions of the modern open-source movement is
that projects which respect user freedoms often rely on proprietary
tools that do not: communities often turn to non-free software for
code hosting, communication, and more. At Configuration Management
Camp
(CfgMgmtCamp) 2026, Jan Ainali spoke
about
the need for open-source projects to adopt open tools;
he hoped to persuade new and mature projects to switch to open
alternatives, even if just one tool, to reduce their dependencies on
tech giants and support community-driven infrastructure.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1061043/

Security updates have been issued by AlmaLinux (containernetworking-plugins, gnutls, kernel, libpng, and skopeo), Debian (firefox-esr, php8.2, and spip), Fedora (erlang and python-pillow), Red Hat (go-toolset:rhel8, golang, and yggdrasil), SUSE (cups, fluidsynth, gvfs, haproxy, libsoup, libsoup-3_0-0, mozilla-nss, python-azure-core, and shim), and Ubuntu (git and mailman).

[$] The exploitation paradox in open source

Post Syndicated from jzb original https://lwn.net/Articles/1058031/

The free and open-source software (FOSS) movements have always been
about giving freedom and power to individuals and organizations;
throughout that history, though, there have also been actors trying
to exploit FOSS to their own advantage. At Configuration Management
Camp
(CfgMgmtCamp) 2026 in Ghent, Belgium, Richard Fontana described
the “exploitation paradox” of open source: the recurring
pattern of crises when actors exploit loopholes to restrict freedoms
or gain the upper hand over others in the community. He also talked
about the attempts to close those loopholes as well as the need to
look beyond licenses as a means of keeping freedom alive.