All posts by jzb

Debian DFSG Team announces new dashboard and queue processes

Post Syndicated from jzb original https://lwn.net/Articles/1058480/

Reinhard Tartler of Debian’s new DFSG,
Licensing & New Packages Team
, or simply “DFSG Team”, has announced
that the team is now operational and is deploying new tooling to
improve the NEW queue experience for Debian developers and
maintainers.

Our primary and immediate goal is simple: get the queue down.

We are currently settling in and refining our processes to ensure
stability and consistency. While our focus right now is on clearing
the backlog, our long-term vision is to enable all Debian Developers
to meaningfully contribute to DFSG reviewing activities, distributing
the workload and knowledge more effectively across the project.

The announcement includes information on the new dashboard for
packages in the NEW queue
, the rationale for the new tooling, and
an introduction to the members of the team.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1058473/

Security updates have been issued by AlmaLinux (brotli, git-lfs, image-builder, kernel, keylime, libsoup3, and pcs), Fedora (chromium, gnutls, osslsigncode, and p11-kit), Mageia (golang, libpng, thunderbird, and xrdp), Red Hat (git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, osbuild-composer, and toolbox), Slackware (gnutls and libpng), SUSE (apptainer, cockpit, cockpit-packages, cockpit-subscriptions, freerdp2, gimp, glib2, go, go1.24, go1.25, gpg2, ImageMagick, java-1_8_0-openjdk, kernel, keylime-config, keylime-ima-policy, lemon, libp11-kit0, libsoup, libsoup-2_4-1, libxml2, libxml2-16, munge, nodejs20, nvidia-modprobe.cuda, nvidia-open-driver-G06-signed, nvidia-persistenced.cuda, openQA, orthanc, gdcm, orthanc-authorization,, python-brotlipy, python-Django, python-maturin, python-pyasn1, python-urllib3, python-wheel, python313-wheel, qemu, rust-keylime, sqlite3, uriparser, wicked2nm, and xrdp), and Ubuntu (libtasn1-6, libwebsockets, libxmltok, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux, linux-raspi, linux, linux-raspi, linux-realtime, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-ibm,
linux-ibm-6.8, linux-lowlatency-hwe-6.8, linux-aws-5.15, linux-gcp-5.15, linux-nvidia-tegra-igx, linux-oracle-5.15,
linux-xilinx-zynqmp, linux-aws-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-intel-iot-realtime, linux-realtime, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-realtime-6.8, linux-xilinx-zynqmp, and python-multipart).

[$] Evolving Git for the next decade

Post Syndicated from jzb original https://lwn.net/Articles/1057561/

Git is ubiquitous; in the last two decades, the version-control
system has truly achieved world domination. Almost every developer
uses it and the vast majority of open-source projects are hosted in
Git repositories. That does not mean, however, that it is
perfect. Patrick Steinhardt used his main-track session at FOSDEM 2026
to discuss some of its shortcomings and how they are being
addressed to prepare Git for the next decade.

postmarketOS FOSDEM 2026 and hackathon recap

Post Syndicated from jzb original https://lwn.net/Articles/1058285/

The postmarketOS project
has published
a recap from FOSDEM 2026, including the FOSS on
Mobile devroom
, and a summary of its post-FOSDEM
hackathon
. This includes decisions on governance and the project’s
AI policy:

AI policy: our current AI
policy
does not state that we forbid the use of generative AI in
postmarketOS, so far this document just lists why we think it is a bad
idea and misaligned with the project values. We discussed this and
will soon change it (via merge request) to clearly state that we don’t
want generative AI to be used in the project. It was also noted that
currently the policy is too long, it would make sense to split it into
the actual policy and still keep, but separate the reasoning from
it.

[…] Power delegation and teams: in over two
hours we discussed how to move forward with [postmarketOS change
request] PMCR 0008 to organize
ourselves better, and how it fits with soon having a legal entity. We
figured that we need to rename “The Board” (which is currently for
financial oversight) to “Financial Team”, as we will soon have a new
board for the legal entity. In the end our idea was to have the new
board refer to an “assembly” for all important decisions, and this
“assembly” would just be all Trusted Contributors in postmarketOS. The
Core Contributors team would be dissolved in favor of having several
topic-specific teams (a lot of which we already have, such as the
infra team). This way we would have a very flat decision
structure. The PMCR will be updated soon and discussed further
there. Casey
also asked on fedi for further feedback and got a lot of input.

Other topics include reaching out to resellers to sell phones with
postmarketOS preinstalled, security, and more.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1058265/

Security updates have been issued by Debian (kernel, linux-6.1, munge, and tcpflow), Fedora (accel-ppp, atuin, babl, bustle, endless-sky, envision, ettercap, fapolicy-analyzer, firefox, glycin, gnome-settings-daemon, go-fdo-client, greenboot-rs, greetd, helix, hwdata, keylime-agent-rust, kiwi, libdrm, maturin, mirrorlist-server, ntpd-rs, ogr2osm, open-vm-tools, perl-App-Cme, perl-Net-RDAP, perl-rdapper, polymake, python-requests-ratelimiter, python-tqdm, rust-add-determinism, rust-afterburn, rust-ambient-id, rust-app-store-connect, rust-bat, rust-below, rust-btrd, rust-busd, rust-bytes, rust-cargo-c, rust-cargo-deny, rust-coreos-installer, rust-crypto-auditing-agent, rust-crypto-auditing-client, rust-crypto-auditing-event-broker, rust-crypto-auditing-log-parser, rust-dua-cli, rust-eif_build, rust-git-delta, rust-git-interactive-rebase-tool, rust-git2, rust-gst-plugin-dav1d, rust-gst-plugin-reqwest, rust-heatseeker, rust-ingredients, rust-jsonwebtoken, rust-lsd, rust-monitord, rust-monitord-exporter, rust-muvm, rust-nu, rust-num-conv, rust-onefetch, rust-oo7-cli, rust-pleaser, rust-pore, rust-pretty-git-prompt, rust-procs, rust-rbspy, rust-rbw, rust-rd-agent, rust-rd-hashd, rust-redlib, rust-resctl-bench, rust-resctl-demo, rust-routinator, rust-sccache, rust-scx_layered, rust-scx_rustland, rust-scx_rusty, rust-sequoia-chameleon-gnupg, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-sq, rust-sevctl, rust-shadow-rs, rust-sigul-pesign-bridge, rust-speakersafetyd, rust-tealdeer, rust-time, rust-time-core, rust-time-macros, rust-tokei, rust-weezl, rust-wiremix, rust-ybaas, rustup, sad, strawberry, systemd, tbtools, transmission, trustedqsl, tuigreet, uv, and vdr-extrecmenung), Oracle (brotli, git-lfs, java-1.8.0-openjdk, kernel, libsoup, libsoup3, nodejs:24, python3.12, and thunderbird), Red Hat (fence-agents, python-urllib3, python3.11-urllib3, python3.12-urllib3, and resource-agents), SUSE (avahi, cups, freerdp, golang-github-prometheus-prometheus, java-11-openjdk, java-17-openjdk, libsoup2, libxml2, and python-pip), and Ubuntu (expat, glib2.0, and imagemagick).

GTK hackfest, 2026 edition (GTK Development Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1058024/

Matthias Clasen has published a short summary of the GTK hackfest held prior to FOSDEM 2026. Topics include
discussions on unstable APIs, a decision to bump the C runtime
requirement to C11 in the next development cycle, limiting changes in
GTK3 to crash and build fixes, as well as the state of
accessibility:

On the accessibility side, we are somewhat worried about the state
of AccessKit. The
code upstream is maintained, but we haven’t seen movement in the GTK
implementation. We still default to the AT-SPI backend on Linux, but
AccessKit is used on Windows and macOS (and possibly Android in the
future); it would be nice to have consumers of the accessibility stack
looking at the code and issues.

On the AT-SPI side we are still missing proper feature negotiation
in the protocol; interfaces are now versioned on D-Bus, but there’s no
mechanism to negotiate the supported set of roles or events between
toolkits, compositors, and assistive technologies, which makes running
newer applications on older OS versions harder.

[$] FOSS in times of war, scarcity, and AI

Post Syndicated from jzb original https://lwn.net/Articles/1056800/

Michiel Leenaars, director of strategy at the NLnet Foundation, used his keynote
at FOSDEM to sound warnings for
the community for free and open-source (FOSS) software; in particular, he
talked about the threats posed by geopolitical politics, dangerous
allies, and large language models (LLMs). His talk was a mix of
observations and suggestions that pertain to FOSS in general and to
Europe in particular as geopolitical tensions have mounted in recent
months.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1057993/

Security updates have been issued by AlmaLinux (fence-agents, firefox, fontforge, freerdp, kernel-rt, keylime, libsoup, libsoup3, nodejs22, nodejs24, opentelemetry-collector, osbuild-composer, python3.12-wheel, qemu-kvm, resource-agents, thunderbird, and util-linux), Debian (kernel, rlottie, shaarli, and usbmuxd), Fedora (asciinema, atuin, bustle, cef, envision, glycin, greetd, helix, java-21-openjdk, java-25-openjdk, java-latest-openjdk, keylime-agent-rust, maturin, mirrorlist-server, ntpd-rs, python3.6, rust-add-determinism, rust-afterburn, rust-ambient-id, rust-app-store-connect, rust-bat, rust-below, rust-btrd, rust-busd, rust-bytes, rust-cargo-c, rust-cargo-deny, rust-coreos-installer, rust-crypto-auditing-agent, rust-crypto-auditing-client, rust-crypto-auditing-event-broker, rust-crypto-auditing-log-parser, rust-dua-cli, rust-eif_build, rust-git-delta, rust-git-interactive-rebase-tool, rust-git2, rust-gst-plugin-dav1d, rust-gst-plugin-reqwest, rust-heatseeker, rust-ingredients, rust-jsonwebtoken, rust-lsd, rust-monitord, rust-monitord-exporter, rust-muvm, rust-nu, rust-num-conv, rust-onefetch, rust-oo7-cli, rust-pleaser, rust-pore, rust-pretty-git-prompt, rust-procs, rust-rbspy, rust-rbw, rust-rd-agent, rust-rd-hashd, rust-redlib, rust-resctl-bench, rust-resctl-demo, rust-routinator, rust-sccache, rust-scx_layered, rust-scx_rustland, rust-scx_rusty, rust-sequoia-chameleon-gnupg, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-sq, rust-sevctl, rust-shadow-rs, rust-sigul-pesign-bridge, rust-snpguest, rust-speakersafetyd, rust-tealdeer, rust-time, rust-time-core, rust-time-macros, rust-tokei, rust-weezl, rust-wiremix, rust-ybaas, rustup, sad, tbtools, tuigreet, and uv), Mageia (fontforge and nginx), Oracle (firefox, fontforge, freerdp, kernel, keylime, libsoup, python, thunderbird, and uek-kernel), SUSE (abseil-cpp and kernel), and Ubuntu (freerdp2 and libsoup3).

Offpunk 3.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1057766/

Version
3.0
of the Offpunk
offline-first, command-line web, Gemini, and
Gopher
browser has been released. Notable changes in this release include
integration of the unmerdify
library to “remove cruft” from web sites, the xkcdpunk
standalone tool for viewing xkcd
comics in the terminal, and a cookies command to enable
browsing web sites (such as LWN.net) while being logged in.

Something wonderful happened on the road leading to 3.0: Offpunk
became a true cooperative effort. Offpunk 3.0 is probably the first
release that contains code I didn’t review line-by-line. Unmerdify (by
Vincent Jousse), all the translation infrastructure (by the
always-present JMCS), and the community packaging effort are areas for
which I barely touched the code.

So, before anything else, I want to thank all the people involved
for sharing their energy and motivation. I’m very grateful for every
contribution the project received. I’m also really happy to see “old
names” replying from time to time on the mailing list. It makes me
feel like there’s an emerging Offpunk community where everybody can
contribute at their own pace.

There were a lot of changes between 2.8 and 3.0, which probably
means some new bugs and some regressions. We count on you, yes, you!,
to report them and make 3.1 a lot more stable. It’s as easy at typing
“bugreport” in offpunk!

See the “Installing
Offpunk
” page to get started.

Debian’s tag2upload considered stable

Post Syndicated from jzb original https://lwn.net/Articles/1057765/

Sean Whitton has announced
that Debian’s tag2upload
service is now out of beta and ready for use by Debian developers and
maintainers.

During the beta we encountered only a few significant bugs. Now that
we’ve fixed those, our rate of successful uploads is hovering around
95%. Failures are almost always due to packaging inconsistencies that
older workflows don’t detect, and therefore only need fixing once per
package.

We don’t think you need explicit approval from your co-maintainers
anymore. Your upload workflows can be different to your teammates.
They can be using dput, dgit or tag2upload.

LWN covered
tag2upload in July 2024.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1057759/

Security updates have been issued by AlmaLinux (fontforge, kernel, and osbuild-composer), Debian (debian-security-support, sudo, wireshark, xrdp, and zabbix), Fedora (bind, bind-dyndb-ldap, chromium, k9s, libgit2, mingw-glib2, node-exporter, open-vm-tools, plantuml, xorgxrdp, and xrdp), Oracle (fence-agents, image-builder, kernel, libsoup3, and osbuild-composer), Red Hat (image-builder and osbuild-composer), Slackware (openssl and p11), SUSE (chromium, cockpit-354, cockpit-machines, cockpit-machines-346, cockpit-packages, cockpit-podman, cockpit-subscriptions, govulncheck-vulndb, kubernetes-old, libsnmp45-32bit, libxml2, localsearch, micropython, opencloud-server, python-django, python-djangorestframework, python-maturin, python311-Django, python311-wheel, python315, sqlite3, and xrdp), and Ubuntu (linux-fips, linux-aws-fips, linux-gcp-fips and python-pip).

Linux from Scratch to drop System V versions

Post Syndicated from jzb original https://lwn.net/Articles/1057509/

The Linux From
Scratch
(LFS) project provides step-by-step instructions on
building a customized Linux system entirely from source. Historically,
the project has provided separate System V and systemd editions,
which gave users a choice of init systems. Bruce Dubbs has announced
the project will no longer produce the System V version:

There are two reasons for this decision. The first reason is
workload. No one working on LFS is paid. We rely completely on
volunteers. In LFS there are 88 packages. In BLFS there are over
1000. The volume of changes from upstream is overwhelming the
editors. In this release cycle that started on the 1st of September
until now, there have been 70 commits to LFS and 1155 commits to BLFS
(and counting). When making package updates, many packages need to be
checked for both System V and systemd. When preparing for release, all
packages need to be checked for each init system.

The second reason for dropping System V is that packages like GNOME
and soon KDE’s Plasma are building in requirements that require
capabilities in systemd that are not in System V. This could
potentially be worked around with another init system like OpenRC, but
beyond the transition process it still does not address the ongoing
workload problem.

[…] As a personal note, I do not like this decision. To me LFS is
about learning how a system works. Understanding the boot process is a
big part of that. systemd is about 1678 “C” files plus many data
files. System V is “22” C files plus about 50 short bash scripts and
data files. Yes, systemd provides a lot of capabilities, but we will
be losing some things I consider important.

The next version, 13.0, is expected in March and will only focus on
systemd.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1057506/

Security updates have been issued by AlmaLinux (freerdp, kernel, python3, and python3.12-wheel), Debian (alsa-lib, chromium, openjdk-25, phpunit, tomcat10, tomcat11, and tomcat9), Fedora (openqa, pgadmin4, phpunit10, phpunit11, phpunit12, phpunit8, phpunit9, and yarnpkg), Mageia (python-django), SUSE (alloy, cups, dpdk, expat, glib2, java-1_8_0-ibm, java-1_8_0-openj9, java-25-openjdk, kernel, libpainter0, libsoup, libxml2, openssl-3, python-filelock, python-wheel, python312-Django6, thunderbird, traefik2, udisks2, wireshark, and xen), and Ubuntu (glib2.0, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, python3.14, python3.13, python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4, and tracker-miners).

[$] Sigil simplifies creating and editing EPUBs

Post Syndicated from jzb original https://lwn.net/Articles/1054751/

Creating an ebook in EPUB format is easy,
for certain values of “easy”. All one really needs
is a text editor, a few command-line utilities; also needed is a working
knowledge of XHTML, CSS, along with an understanding of the format’s
structure and required boilerplate. Creating
a well-formatted and attractive ebook is a bit harder. However, it can be
made easier with an application custom-made for the purpose. Sigil is an EPUB editor that
provides the tooling authors and publishers may be looking for.

Mourning Didier Spaier

Post Syndicated from jzb original https://lwn.net/Articles/1056384/

We have received the sad news that Didier Spaier, maintainer of the
blind-friendly Slackware-based Slint distribution, has recently passed
away
. Philippe Delavalade, who posted the announcement to the
Slint mailing list, said:

Early 2015, I asked on the slackware list if brltty could be added
in the installer; Didier answered promptly that he could do it on
slint. Afterwards, he worked hard so that slint became as accessible
as possible for visually impaired people.

You all know that all these years, he tried and succeeded to answer
as quickly as possible to our issues and questions.

He will be irreplaceable.

OSI pauses 2026 board election cycle

Post Syndicated from jzb original https://lwn.net/Articles/1056376/

The Open Source Initiative (OSI) has announced
that it will not be holding the 2026 spring board election. Instead,
it will be creating a working group to “review and improve OSI’s
board member selection process
” and provide recommendations by
September 2026:

The public election process was designed to gather community
priorities and improve board member selection, while final
appointments remained with the board.

Over time, that nuance has become a source of understandable
confusion for community members. Many reasonably expected elections to
function as elections normally do, and in fact, the board has
generally adopted the electorate’s recommendations. When a process
feels unclear, trust suffers. When trust suffers, engagement becomes
harder. This is especially problematic for an organization whose
mission depends on legitimacy and credibility. […]

OSI tried its experiment for the right reasons, but a variety of
factors resulted in “elections” that are performatively democratic
while being gameable and representative of only a small group, and
we’ve learned from the results. Now we are making space to align our
director selection process with our bylaws, to rebuild trust, and to
develop better, more durable and truly representative participation in
which the global stakeholder community can be heard.

LWN covered the
previous OSI election
in March 2025.