All posts by jzb

GTK hackfest, 2026 edition (GTK Development Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1058024/

Matthias Clasen has published a short summary of the GTK hackfest held prior to FOSDEM 2026. Topics include
discussions on unstable APIs, a decision to bump the C runtime
requirement to C11 in the next development cycle, limiting changes in
GTK3 to crash and build fixes, as well as the state of
accessibility:

On the accessibility side, we are somewhat worried about the state
of AccessKit. The
code upstream is maintained, but we haven’t seen movement in the GTK
implementation. We still default to the AT-SPI backend on Linux, but
AccessKit is used on Windows and macOS (and possibly Android in the
future); it would be nice to have consumers of the accessibility stack
looking at the code and issues.

On the AT-SPI side we are still missing proper feature negotiation
in the protocol; interfaces are now versioned on D-Bus, but there’s no
mechanism to negotiate the supported set of roles or events between
toolkits, compositors, and assistive technologies, which makes running
newer applications on older OS versions harder.

[$] FOSS in times of war, scarcity, and AI

Post Syndicated from jzb original https://lwn.net/Articles/1056800/

Michiel Leenaars, director of strategy at the NLnet Foundation, used his keynote
at FOSDEM to sound warnings for
the community for free and open-source (FOSS) software; in particular, he
talked about the threats posed by geopolitical politics, dangerous
allies, and large language models (LLMs). His talk was a mix of
observations and suggestions that pertain to FOSS in general and to
Europe in particular as geopolitical tensions have mounted in recent
months.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1057993/

Security updates have been issued by AlmaLinux (fence-agents, firefox, fontforge, freerdp, kernel-rt, keylime, libsoup, libsoup3, nodejs22, nodejs24, opentelemetry-collector, osbuild-composer, python3.12-wheel, qemu-kvm, resource-agents, thunderbird, and util-linux), Debian (kernel, rlottie, shaarli, and usbmuxd), Fedora (asciinema, atuin, bustle, cef, envision, glycin, greetd, helix, java-21-openjdk, java-25-openjdk, java-latest-openjdk, keylime-agent-rust, maturin, mirrorlist-server, ntpd-rs, python3.6, rust-add-determinism, rust-afterburn, rust-ambient-id, rust-app-store-connect, rust-bat, rust-below, rust-btrd, rust-busd, rust-bytes, rust-cargo-c, rust-cargo-deny, rust-coreos-installer, rust-crypto-auditing-agent, rust-crypto-auditing-client, rust-crypto-auditing-event-broker, rust-crypto-auditing-log-parser, rust-dua-cli, rust-eif_build, rust-git-delta, rust-git-interactive-rebase-tool, rust-git2, rust-gst-plugin-dav1d, rust-gst-plugin-reqwest, rust-heatseeker, rust-ingredients, rust-jsonwebtoken, rust-lsd, rust-monitord, rust-monitord-exporter, rust-muvm, rust-nu, rust-num-conv, rust-onefetch, rust-oo7-cli, rust-pleaser, rust-pore, rust-pretty-git-prompt, rust-procs, rust-rbspy, rust-rbw, rust-rd-agent, rust-rd-hashd, rust-redlib, rust-resctl-bench, rust-resctl-demo, rust-routinator, rust-sccache, rust-scx_layered, rust-scx_rustland, rust-scx_rusty, rust-sequoia-chameleon-gnupg, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-sq, rust-sevctl, rust-shadow-rs, rust-sigul-pesign-bridge, rust-snpguest, rust-speakersafetyd, rust-tealdeer, rust-time, rust-time-core, rust-time-macros, rust-tokei, rust-weezl, rust-wiremix, rust-ybaas, rustup, sad, tbtools, tuigreet, and uv), Mageia (fontforge and nginx), Oracle (firefox, fontforge, freerdp, kernel, keylime, libsoup, python, thunderbird, and uek-kernel), SUSE (abseil-cpp and kernel), and Ubuntu (freerdp2 and libsoup3).

Offpunk 3.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1057766/

Version
3.0
of the Offpunk
offline-first, command-line web, Gemini, and
Gopher
browser has been released. Notable changes in this release include
integration of the unmerdify
library to “remove cruft” from web sites, the xkcdpunk
standalone tool for viewing xkcd
comics in the terminal, and a cookies command to enable
browsing web sites (such as LWN.net) while being logged in.

Something wonderful happened on the road leading to 3.0: Offpunk
became a true cooperative effort. Offpunk 3.0 is probably the first
release that contains code I didn’t review line-by-line. Unmerdify (by
Vincent Jousse), all the translation infrastructure (by the
always-present JMCS), and the community packaging effort are areas for
which I barely touched the code.

So, before anything else, I want to thank all the people involved
for sharing their energy and motivation. I’m very grateful for every
contribution the project received. I’m also really happy to see “old
names” replying from time to time on the mailing list. It makes me
feel like there’s an emerging Offpunk community where everybody can
contribute at their own pace.

There were a lot of changes between 2.8 and 3.0, which probably
means some new bugs and some regressions. We count on you, yes, you!,
to report them and make 3.1 a lot more stable. It’s as easy at typing
“bugreport” in offpunk!

See the “Installing
Offpunk
” page to get started.

Debian’s tag2upload considered stable

Post Syndicated from jzb original https://lwn.net/Articles/1057765/

Sean Whitton has announced
that Debian’s tag2upload
service is now out of beta and ready for use by Debian developers and
maintainers.

During the beta we encountered only a few significant bugs. Now that
we’ve fixed those, our rate of successful uploads is hovering around
95%. Failures are almost always due to packaging inconsistencies that
older workflows don’t detect, and therefore only need fixing once per
package.

We don’t think you need explicit approval from your co-maintainers
anymore. Your upload workflows can be different to your teammates.
They can be using dput, dgit or tag2upload.

LWN covered
tag2upload in July 2024.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1057759/

Security updates have been issued by AlmaLinux (fontforge, kernel, and osbuild-composer), Debian (debian-security-support, sudo, wireshark, xrdp, and zabbix), Fedora (bind, bind-dyndb-ldap, chromium, k9s, libgit2, mingw-glib2, node-exporter, open-vm-tools, plantuml, xorgxrdp, and xrdp), Oracle (fence-agents, image-builder, kernel, libsoup3, and osbuild-composer), Red Hat (image-builder and osbuild-composer), Slackware (openssl and p11), SUSE (chromium, cockpit-354, cockpit-machines, cockpit-machines-346, cockpit-packages, cockpit-podman, cockpit-subscriptions, govulncheck-vulndb, kubernetes-old, libsnmp45-32bit, libxml2, localsearch, micropython, opencloud-server, python-django, python-djangorestframework, python-maturin, python311-Django, python311-wheel, python315, sqlite3, and xrdp), and Ubuntu (linux-fips, linux-aws-fips, linux-gcp-fips and python-pip).

Linux from Scratch to drop System V versions

Post Syndicated from jzb original https://lwn.net/Articles/1057509/

The Linux From
Scratch
(LFS) project provides step-by-step instructions on
building a customized Linux system entirely from source. Historically,
the project has provided separate System V and systemd editions,
which gave users a choice of init systems. Bruce Dubbs has announced
the project will no longer produce the System V version:

There are two reasons for this decision. The first reason is
workload. No one working on LFS is paid. We rely completely on
volunteers. In LFS there are 88 packages. In BLFS there are over
1000. The volume of changes from upstream is overwhelming the
editors. In this release cycle that started on the 1st of September
until now, there have been 70 commits to LFS and 1155 commits to BLFS
(and counting). When making package updates, many packages need to be
checked for both System V and systemd. When preparing for release, all
packages need to be checked for each init system.

The second reason for dropping System V is that packages like GNOME
and soon KDE’s Plasma are building in requirements that require
capabilities in systemd that are not in System V. This could
potentially be worked around with another init system like OpenRC, but
beyond the transition process it still does not address the ongoing
workload problem.

[…] As a personal note, I do not like this decision. To me LFS is
about learning how a system works. Understanding the boot process is a
big part of that. systemd is about 1678 “C” files plus many data
files. System V is “22” C files plus about 50 short bash scripts and
data files. Yes, systemd provides a lot of capabilities, but we will
be losing some things I consider important.

The next version, 13.0, is expected in March and will only focus on
systemd.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1057506/

Security updates have been issued by AlmaLinux (freerdp, kernel, python3, and python3.12-wheel), Debian (alsa-lib, chromium, openjdk-25, phpunit, tomcat10, tomcat11, and tomcat9), Fedora (openqa, pgadmin4, phpunit10, phpunit11, phpunit12, phpunit8, phpunit9, and yarnpkg), Mageia (python-django), SUSE (alloy, cups, dpdk, expat, glib2, java-1_8_0-ibm, java-1_8_0-openj9, java-25-openjdk, kernel, libpainter0, libsoup, libxml2, openssl-3, python-filelock, python-wheel, python312-Django6, thunderbird, traefik2, udisks2, wireshark, and xen), and Ubuntu (glib2.0, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, python3.14, python3.13, python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4, and tracker-miners).

[$] Sigil simplifies creating and editing EPUBs

Post Syndicated from jzb original https://lwn.net/Articles/1054751/

Creating an ebook in EPUB format is easy,
for certain values of “easy”. All one really needs
is a text editor, a few command-line utilities; also needed is a working
knowledge of XHTML, CSS, along with an understanding of the format’s
structure and required boilerplate. Creating
a well-formatted and attractive ebook is a bit harder. However, it can be
made easier with an application custom-made for the purpose. Sigil is an EPUB editor that
provides the tooling authors and publishers may be looking for.

Mourning Didier Spaier

Post Syndicated from jzb original https://lwn.net/Articles/1056384/

We have received the sad news that Didier Spaier, maintainer of the
blind-friendly Slackware-based Slint distribution, has recently passed
away
. Philippe Delavalade, who posted the announcement to the
Slint mailing list, said:

Early 2015, I asked on the slackware list if brltty could be added
in the installer; Didier answered promptly that he could do it on
slint. Afterwards, he worked hard so that slint became as accessible
as possible for visually impaired people.

You all know that all these years, he tried and succeeded to answer
as quickly as possible to our issues and questions.

He will be irreplaceable.

OSI pauses 2026 board election cycle

Post Syndicated from jzb original https://lwn.net/Articles/1056376/

The Open Source Initiative (OSI) has announced
that it will not be holding the 2026 spring board election. Instead,
it will be creating a working group to “review and improve OSI’s
board member selection process
” and provide recommendations by
September 2026:

The public election process was designed to gather community
priorities and improve board member selection, while final
appointments remained with the board.

Over time, that nuance has become a source of understandable
confusion for community members. Many reasonably expected elections to
function as elections normally do, and in fact, the board has
generally adopted the electorate’s recommendations. When a process
feels unclear, trust suffers. When trust suffers, engagement becomes
harder. This is especially problematic for an organization whose
mission depends on legitimacy and credibility. […]

OSI tried its experiment for the right reasons, but a variety of
factors resulted in “elections” that are performatively democratic
while being gameable and representative of only a small group, and
we’ve learned from the results. Now we are making space to align our
director selection process with our bylaws, to rebuild trust, and to
develop better, more durable and truly representative participation in
which the global stakeholder community can be heard.

LWN covered the
previous OSI election
in March 2025.

[$] Who should vote in Fedora elections?

Post Syndicated from jzb original https://lwn.net/Articles/1055539/

Creating fair governance models for open-source projects is not
easy; defining criteria for participants to receive membership and
voting rights is a particularly thorny problem for projects that have
elections for representative bodies. The Fedora
Council
, the project’s top-level governance body, is wrestling
with that conundrum now. This was triggered by a Fedora special-interest
group (SIG) granting temporary membership to at least one person for the
sole purpose of allowing them to vote in the most recent Fedora
Engineering Steering Council (FESCo) election. That opened a large can
of worms about what it means to be a contributor and how contributors
can be identified for voting purposes.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1056330/

Security updates have been issued by AlmaLinux (java-1.8.0-openjdk), Debian (openssl), Fedora (assimp, chromium, curl, freerdp, gimp, and harfbuzz), Mageia (glibc, haproxy, iperf, and python-pyasn1), Red Hat (image-builder, openssl, and osbuild-composer), Slackware (mozilla), SUSE (avahi, cups, gio-branding-upstream, google-osconfig-agent, java-11-openjdk, java-17-openjdk, java-21-openjdk, kernel-firmware, libmatio-devel, libopenjp2-7, nodejs22, php8, python-python-multipart, python311-urllib3_1, qemu, and xen), and Ubuntu (ffmpeg, jaraco.context, openssl, and openssl, openssl1.0).

Xfwl4: the roadmap for a Xfce Wayland compositor

Post Syndicated from jzb original https://lwn.net/Articles/1056159/

The Xfce team has announced that
it will be providing funding to Brian Tarricone to work on xfwl4,
a Wayland compositor for Xfce:

Xfwl4 will not be based on the existing xfwm4 code. Instead, it
will be written from scratch in rust, using smithay building
blocks.

The first attempt at creating an Xfce Wayland compositor involved
modifying the existing xfwm4 code to support both X11 and Wayland in
parallel. However, this approach turned out to be the wrong path
forward for several reasons:

  • Xfwm4 is architected in a way that makes it very difficult to put the window management behavior behind generic interfaces that don’t include X11 specifics.
  • Refactoring Xfwm4 is risky, since it might introduce new bugs to X11. Having two parallel code bases will allow for rapid development and experimentation with the Wayland compositor, with zero risk to break xfwm4.
  • Some X11 window management concepts just aren’t available or supported by Wayland protocols at this time, and dealing with those differences can be difficult in an X11-first code base.
  • Using the existing codebase would require us to use C and
    wlroots, even if a better alternative is available.

Work has already commenced on the project, and the project hopes to
share a development release in mid-2026.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1056158/

Security updates have been issued by AlmaLinux (kernel, kernel-rt, python-urllib3, python3.11-urllib3, and python3.12-urllib3), Debian (imagemagick, openjdk-11, openjdk-17, and openjdk-21), Fedora (bind, bind-dyndb-ldap, chromium, ghostscript, glibc, mingw-glib2, mingw-harfbuzz, mingw-libsoup, mingw-openexr, and qownnotes), Mageia (kernel-linus), Red Hat (osbuild-composer), SUSE (go1.24-openssl, go1.25-openssl, govulncheck-vulndb, kernel, nodejs22, openCryptoki, openvswitch3, python-pyasn1, python311, and qemu), and Ubuntu (git-lfs, node-form-data, and screen).

[$] Fedora and GPG 2.5

Post Syndicated from jzb original https://lwn.net/Articles/1055053/

The GNU Privacy Guard (GPG)
project decided to break from the OpenPGP standard for email
encryption in 2023, and instead adopted its own homegrown LibrePGP specification. The GPG 2.4
branch, the last one to adhere to OpenPGP, will be reaching the end of
life in mid-2026. The Fedora project is currently having a discussion
about how that affects the distribution, its users, and what to offer
once 2.4 is no longer receiving updates.

Stenberg: The end of the curl bug-bounty program

Post Syndicated from jzb original https://lwn.net/Articles/1055996/

Curl creator Daniel Stenberg has written a blog
post
explaining why the project is ending its bug-bounty
program, which started in April 2019:

The never-ending slop submissions take a serious mental toll to
manage and sometimes also a long time to debunk. Time and energy that
is completely wasted while also hampering our will to live.

I have also started to get the feeling that a lot of the security
reporters submit reports with a bad faith attitude. These “helpers”
try too hard to twist whatever they find into something horribly bad
and a critical vulnerability, but they rarely actively contribute to
actually improve curl. They can go to extreme efforts to argue and
insist on their specific current finding, but not to write a fix or
work with the team on improving curl long-term etc. I don’t think we
need more of that.

There are these three bad trends combined that makes us take this
step: the mind-numbing AI slop, humans doing worse than ever and the
apparent will to poke holes rather than to help.

Stenberg writes that he still expects “the best and our most
valued security reporters
” to continue informing the project when
security vulnerabilities are discovered. The program will officially
end on January 31, 2026.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1055958/

Security updates have been issued by AlmaLinux (gimp, glib2, go-toolset:rhel8, golang, java-17-openjdk, java-21-openjdk, kernel, net-snmp, pcs, and thunderbird), Debian (apache2, imagemagick, incus, inetutils, libuev, openjdk-17, php7.4, python3.9, shapelib, taglib, and zvbi), Fedora (mingw-glib2, mingw-harfbuzz, mingw-libsoup, mingw-openexr, pgadmin4, python3.11, python3.12, python3.9, and wireshark), Gentoo (Asterisk, Commons-BeanUtils, GIMP, inetutils, and Vim, gVim), Mageia (kernel), Oracle (glib2, java-17-openjdk, java-21-openjdk, and libpng), Red Hat (java-17-openjdk, java-21-openjdk, kernel, and kernel-rt), SUSE (azure-cli-core, bind, buildah, chromium, coredns, glib2, harfbuzz, kernel, kernel-firmware, libheif, libvirt, openCryptoki, openvswitch, podman, python, python-urllib3, rabbitmq-server, and vlang), and Ubuntu (cjson).