All posts by jzb

Native NVIDIA support for AlmaLinux OS 9 and 10

Post Syndicated from jzb original https://lwn.net/Articles/1032753/

The AlmaLinux project has announced
the availability of packages to enable native NVIDIA driver support,
including CUDA and Secure Boot, for AlmaLinux 9 and 10.

When AlmaLinux started just 5 years ago, this wouldn’t have been
possible. With NVIDIA’s open source version of their graphics drivers
things have changed. This open source version is slowly becoming the
flagship driver, with new products being added exclusively to it. With
the help of some incredible people in the open source ecosystem and
the AlmaLinux community, we were able to do something that has yet to
be done in the EL ecosystem – ship Secure Boot signed, open source,
NVIDIA kernel modules.

Full documentation is available
on the AlmaLinux wiki
.

[$] Don’t fear the TPM

Post Syndicated from jzb original https://lwn.net/Articles/1032026/

There is a great deal of misunderstanding, and some misinformation, about the
Trusted
Platform Module
(TPM); to combat this, Debian developer Jonathan
McDowell would like to clear the air and help users understand what it
is good for, as well as what it’s not. At DebConf25 in Brest, France,
he delivered a
talk about TPMs
that explained what they are, why people might be
interested in using them, and how users might do so on a Debian
system.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1032700/

Security updates have been issued by AlmaLinux (kernel and python3.12-setuptools), Fedora (perl-Crypt-CBC and unbound), Gentoo (FontForge, GPL Ghostscript, Mozilla Network Security Service (NSS), and PAM), Oracle (gdk-pixbuf2, jq, kernel, mod_security, ncurses, python-requests, and python3-setuptools), Red Hat (python-requests and socat), SUSE (docker, kernel-livepatch-MICRO-6-0-RT_Update_2, kernel-livepatch-MICRO-6-0-RT_Update_4, kernel-livepatch-MICRO-6-0-RT_Update_5, kernel-livepatch-MICRO-6-0-RT_Update_6, kernel-livepatch-MICRO-6-0-RT_Update_7, kernel-livepatch-MICRO-6-0_Update_2, kernel-livepatch-MICRO-6-0_Update_4, kernel-livepatch-MICRO-6-0_Update_5, kernel-livepatch-MICRO-6-0_Update_6, kubeshark-cli, libgcrypt, pam-config, perl, python-requests, python311, and python313), and Ubuntu (linux-raspi).

[$] Debian grapples with offensive packages, again

Post Syndicated from jzb original https://lwn.net/Articles/1031750/

A pair of packages containing fortune “cookies” that were
deemed offensive have been removed from the upcoming Debian 13
(“trixie”) release. This has, of course, led to a lengthy discussion
and debate about what does, or does not, belong in the
distribution. It may also lead to a general resolution (GR) to decide
whether Debian’s code
of conduct
(CoC) applies to the contents of packages.

More malware uploaded to Arch Linux AUR (Linuxiac)

Post Syndicated from jzb original https://lwn.net/Articles/1032193/

Linuxiac reports
that another malicious package has been uploaded to the Arch User
Repository (AUR). This time around the package was
google-chrome-stable, which installed a remote-access trojan
along with Google Chrome.

The good news—if you can call it that—is that the google-chrome-stable
package was available on the AUR only for a few hours before the
malware hidden inside was discovered. Still, it did get a few upvotes,
which suggests at least some users ended up installing it.

The Arch Linux project had to warn users about a similar attack
less than a month
ago
when a user uploaded three browser packages that also
installed a malicious script identified as a remote-access trojan.

We need a European Sovereign Tech Fund (GitHub blog)

Post Syndicated from jzb original https://lwn.net/Articles/1031943/

GitHub director of developer policy, Felix Reda, has published
a blog post
about a GitHub-commissioned study by Open Forum Europe, Fraunhofer ISI and
the European University
Institute
. The study finds, not surprisingly, “a profound
mismatch between the importance of open source maintenance and the
public attention it receives
“; it calls for a European sovereign
tech fund (STF) modeled after Germany’s Sovereign Tech Agency.

The study proposes two alternative institutional setups for the
EU-STF: either the creation of a centralized EU institution (the
moonshot model), or a consortium of EU member states that provide the
initial funding and apply for additional resources from the EU budget
(the pragmatic model). In both cases, to make the fund a success, the
minimum contribution from the upcoming EU multiannual budget should be
no less than €350 million. This would not be enough to meet the open
source maintenance need, but it could form the basis for leveraging
industry and national government co-financing that would make a
lasting impact.

The European Union is currently starting negotiations for its
2028-2034 budget, the Multiannual
Financial Framework
; GitHub and others hope to persuade EU legislators to
include a European STF in that framework.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1031919/

Security updates have been issued by AlmaLinux (firefox, icu, kernel-rt, libtpms, redis:6, redis:7, and sqlite), Fedora (chromium and cloud-init), Oracle (icu, java-1.8.0-openjdk, java-21-openjdk, kernel, nodejs:22, perl, and sqlite), SUSE (docker, java-1_8_0-openj9, libxml2, python-starlette, and thunderbird), and Ubuntu (cloud-init, linux-azure, linux-azure-5.4, linux-azure-fips, linux-raspi,
linux-raspi-5.4, and perl).

HeliumOS 10 released

Post Syndicated from jzb original https://lwn.net/Articles/1031836/

The HeliumOS project has announced
the release of HeliumOS 10. It is relatively new image-based (“atomic”)
desktop distribution based on packages from CentOS Stream and
AlmaLinux, with a goal of providing 10 years of
support. HeliumOS 10 uses the KDE Plasma Desktop, Zsh as its
default shell, and Btrfs as its default filesystem.

Help for OpenPrinting needed

Post Syndicated from jzb original https://lwn.net/Articles/1031701/

Till Kamppeter, co-founder and lead of the OpenPrinting project, has
put out a call for sponsors after being laid off by Canonical:

I want to continue doing OpenPrinting for a living, and need a way to
do so. I am currently working with the Linux Foundation to make
OpenPrinting an [organization] which can receive sponsor funding. So now
I am looking for sponsors.

Even greater would be, if independent of this somebody could hire
me to continue OpenPrinting…

[$] Smaller Fedora quality team proposes cuts

Post Syndicated from jzb original https://lwn.net/Articles/1031066/

Fedora’s quality
team
is looking to reduce the scope of test coverage and change
the project’s release criteria to drop some features from the list of
release blockers. This is, in part, an exercise in getting rid of
criteria, such as booting from optical media, that are less relevant.
It is also a necessity, since the Red Hat team focusing on Fedora
quality assurance (QA) is only half the size it was a year ago.

Wayback 0.1 released

Post Syndicated from jzb original https://lwn.net/Articles/1031287/

Version
0.1
of the Wayback
project has been released:

Wayback is an X11 compatibility layer that allows for running full
X11-only desktop environments using Wayland. It is essentially an X11
server backed by Wayland, leveraging wlroots and Xwayland. Our goal is
for Wayback to eventually be a completely drop-in replacement to the
Xorg binary, thus reducing maintenance burden for distro
maintainers.

Ever since Wayback was announced on June 28, we have been making lots
of progress to get it as stable and functional as possible, and while
this is a preview release it is already daily-driveable by users with
simple requirements, as long as they don’t mind bugs.

The release is considered alpha-quality and is missing a number of
features, including multi-monitor
support
and DPMS,
but adventurous users can find the code here.

Discovering and recovering from PostgreSQL corruption on Matrix.org

Post Syndicated from jzb original https://lwn.net/Articles/1031148/

Richard van der Hoff, a member of the team that runs the Matrix.org homeserver,
has written
a detailed blog post about diagnosing and fixing a problem where Matrix rooms
would simply stop working
:

We know that there are plenty of users out there who will have been
affected by the problem, and found themselves unable to communicate as
a result. We very much share your frustration, and we’d like to
apologise for the disruption to service.

With that said, we’re glad that we were able to get to the bottom
of most of the problem, and get the lost data restored within a
relatively short time. If nothing else, hopefully this blog post will
be of use to future generations faced with Postgres index
corruption!

[$] Understanding Debian’s security processes

Post Syndicated from jzb original https://lwn.net/Articles/1030669/

Providing security updates for a Linux distribution, such as
Debian, involves a lot of work behind the scenes—and requires
much more than simply shipping the latest code. On July 15, at DebConf25 in Brest, France,
Samuel Henrique walked through the process of providing security
updates to users; he discussed how Debian learns about security
vulnerabilities, decides on the best response, and the process of
sending out updates to keep its users safe. He also provided guidance
on how others could get involved.

An update on Home Assistant’s Android app

Post Syndicated from jzb original https://lwn.net/Articles/1031129/

The Home Assistant project has published
an update on improvements in its Android app, and plans for upcoming releases:

In our latest update of the Android app 2025.7.1, we’ve added a
couple of useful features. Including a new basic invite flow, which
will be shared between Android and iOS, adding a good layer of
consistency between our most-used companion apps. The idea is to make
it much more seamless to add new users or set up new devices (no need
to type the URL in your Android Automotive device!).

We’ve also made My
Links
work better. If you’re unfamiliar with My Links, they’re
those cool links (that anyone can
make
) that bring you right to an integration, blueprint, add-on,
or settings page. They have always worked great on desktop, but up
until recently, they were a bit clunky to use on mobile. Now you can
get to the link’s destination with a single click.

LWN looked at Home
Assistant in May.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1031104/

Security updates have been issued by AlmaLinux (cloud-init, fence-agents, git, kernel, and kernel-rt), Debian (openjdk-11), Fedora (firefox, golang, libinput, transfig, and yasm), Mageia (qtbase5, qtbase6), Red Hat (fence-agents, go-toolset:rhel8, golang, kernel, and python-setuptools), Slackware (mozilla), SUSE (cyradm, gstreamer-plugins-base, and xen), and Ubuntu (gdk-pixbuf, jq, linux-gcp, linux-gcp-6.8, linux-oracle, ruby-sinatra, thunderbird, and unbound).

Catanzaro: Fedora must (carefully) embrace Flathub

Post Syndicated from jzb original https://lwn.net/Articles/1030936/

GNOME and Fedora contributor Michael Catanzaro has written a
lengthy blog
post
about the future of Fedora Workstation as an image-based
release and the need to enable Flathub by default. He writes that the
Fedora Workstation of the future must be “safe and image-based by
default
“, with applications provided through Flathub:

Flathub is drastically more popular than Fedora Flatpaks even among
the most hardcore Fedora community members who participate in change
proposal debate on Fedora Discussion. (At time of writing, nearly 80%
of discussion participants favor filtering out Fedora Flatpaks.)

This is the most important point. Flathub has already
won.

He notes that Fedora should not force users to install an
image-based OS if they do not want to, and there will be a
package-based version for users who prefer or require it: “so no
need to panic
“.

[$] When free-software communities unite for privacy

Post Syndicated from jzb original https://lwn.net/Articles/1029769/

At DebConf25 in Brest,
France, the
talk
“When Free Software Communities Unite: Tails, Tor, and the
Fight for Privacy” was delivered by a man who introduced himself only
as intrigeri. He delivered an overview of the Tor Project, its mission, and
the projects under the umbrella. He also spoke about how the
organization depends on Debian, and plans for the software it
delivers.

[$] Fedora SIG changes Python packaging strategy

Post Syndicated from jzb original https://lwn.net/Articles/1029354/

Fedora’s NeuroFedora
special-interest group
(SIG) is considering a change of strategy
when it comes to packaging Python modules. The SIG, which consists of
three active members, is struggling to keep up with maintaining the
hundreds of packages that it has taken on. What’s more, it’s not
clear that the majority of packages are even being consumed by Fedora
users; the group is trying to determine the right strategy to meet its
goals and shed unnecessary work. If its new packaging strategy is
successful, it may point the way to a more sustainable model for Linux
distributions to provide value to users without trying to package
everything under the sun.