All posts by jzb

Albertson: OSL’s path to sustainability

Post Syndicated from jzb original https://lwn.net/Articles/1020668/

Lance Albertson writes that the
Oregon State University Open Source Lab has been funded for the next
year, following his announcement in April
that the future of OSL was in jeopardy. OSL is now focusing on
becoming self-sustainable long term.

The recent support was amazing for our immediate team needs. But
for the OSL to thrive long-term, we need a sustainable financial
foundation. This is crucial, as the university expects units like ours
to become self-sufficient beyond this current year.

So, our big focus this next year is locking in ongoing support –
think annualized pledges, different kinds of regular income, and other
recurring help. This is vital, especially with potential new data
center costs and hardware needs. Getting this right means we can stop
worrying about short-term funding and plan for the future: investing
in our tech and people, growing our awesome student programs, and
serving the FOSS community. We’re looking for partners, big and small,
who get why foundational open source infrastructure matters and want
to help us build this sustainable future together.

GNOME Foundation announces new executive director

Post Syndicated from jzb original https://lwn.net/Articles/1020619/

The GNOME Foundation has announced
the hiring of Steven Deobald as its new executive director.

Steven has been a GNOME user since 2002 and has been involved in
numerous free software initiatives throughout his career. His
professional background spans technical leadership, cooperative
business development, and nonprofit work. Having worked with projects
like XTDB and Endatabas, he brings valuable
experience in open source product development. Based in Halifax,
Canada, Steven is well-positioned to collaborate with our global
community across time zones.

[$] Debian’s AWKward essential set

Post Syndicated from jzb original https://lwn.net/Articles/1019898/

The Debian project has the concept of essential
packages
, which provide the bare minimum functionality considered
absolutely necessary (or “essential”) for a system to
function. Packages tagged as essential, and the packages that are
required by the set of essential packages, are always installed as
part of a Debian system. However, Debian’s packaging rules do not
require developers to explicitly declare dependencies on that set of
packages (the essential set) but they can simply rely on the fact that those
will always be present. That means that changing the essential set, as
the project may wish to do occasionally, is more complicated than it
should be. This came to light recently when a Debian developer asked
what might be required to remove mawk to slim down
the project’s container images.

Deepin Desktop removed from openSUSE

Post Syndicated from jzb original https://lwn.net/Articles/1020407/

The SUSE Security Team has announced the removal of the Deepin
Desktop from openSUSE due to violations of the project’s packaging
policy.

The discovery of the bypass of the security whitelistings via the
deepin-feature-enable package marks a turning point in our assessment
of Deepin. We don’t believe that the openSUSE Deepin packager acted
with bad intent when he implemented the “license agreement” dialog to
bypass our whitelisting restrictions. The dialog itself makes the
security concerns we have transparent, so this does not happen in a
sneaky way, at least not towards users. It was not discussed with us,
however, and it violates openSUSE packaging policies. Beyond the
security aspect, this also affects general packaging quality
assurance: the D-Bus configuration files and Polkit policies installed
by the deepin-feature-enable package are unknown to the package
manager and won’t be cleaned up upon package removal, for
example. Such bypasses are not deemed acceptable by us.

The combination of these factors led us to the decision to remove
the Deepin desktop completely from openSUSE Tumbleweed and from the
future Leap 16.0 release. In openSUSE Leap 15.6 we will remove the
offending deepin-feature-enable package only. It is a difficult
decision given that the Deepin desktop has a considerable number of
users. We firmly believe the Deepin packaging and security assessment
in openSUSE needs a reboot, however, ideally involving new people that
can help get the Deepin packages into shape, establish a relationship
with Deepin upstream and keep an eye on bugfixes, thus avoiding
fruitless follow-up reviews that just waste our time. In such a new
setup we would be willing to have a look at all the sensitive Deepin
components again one by one.

The announcement goes into detail about the bypass of
openSUSE packaging policy and the history of security reviews of
Deepin components. It also offers guidance on continuing
to use Deepin Desktop
on openSUSE.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1020404/

Security updates have been issued by Fedora (incus and nodejs20), Red Hat (freetype, kernel, kernel-rt, libsoup, libtiff, redis, redis:6, and thunderbird), SUSE (apparmor, chromium, grafana, ImageMagick, java-11-openjdk, java-17-openjdk, libsoup, libsoup2, libxslt, opensaml, rabbitmq-server, rubygem-rack-1_6, sqlite3, and thunderbird), and Ubuntu (kernel, libfcgi, libraw, libsoup2.4, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux-raspi, linux, linux-aws, linux-aws-5.4, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-kvm, linux-oracle, linux-oracle-5.4, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-hwe-6.8, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oem-6.8, linux-oracle, linux-oracle-6.8, linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux, linux-aws, linux-gcp, linux-gcp-6.11, linux-hwe-6.11, linux-lowlatency, linux-lowlatency-hwe-6.11, linux-oracle, linux-raspi, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure, linux-azure, linux-azure-4.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-azure, linux-azure-6.11, linux-azure-6.8, linux-azure-fips, linux-intel-iot-realtime, linux-realtime, linux-oem-6.11, linux-raspi, linux-realtime, python, python-scrapy, and ruby-carrierwave).

Mission Center 1.0.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1020269/

Version
1.0.0
of Mission Center, a system-monitoring application, has been
released. Notable changes in this release include the addition of
SMART data for SATA and NVMe devices, display of per-process
network usage
, as well as a redesigned Apps Page that provides
more information about applications and processes. Mission Center’s
backend application for obtaining system data has been renamed from
the Gatherer to Magpie, and is
now available as a standalone executable and libraries that can be
used by other applications.

Celebrating 20 Years of the OASIS Open Document Format

Post Syndicated from jzb original https://lwn.net/Articles/1019672/

The Document
Foundation
is celebrating
the 20th anniversary of the ratification of the Open Document Format
(ODF) as an OASIS
standard.

Two decades after its approval in 2005, ODF is the only open
standard for office documents, promoting digital independence,
interoperability and content transparency worldwide. […]

To celebrate this milestone, from today The Document Foundation
will be publishing a series of presentations and documents on its blog
that illustrate the unique features of ODF, tracing its history from
the development and standardisation process through the activities of
the Technical Committee for the submission of version 1.3 to ISO and
the standardisation of version 1.4.

[$] The mystery of the Mailman 2 CVEs

Post Syndicated from jzb original https://lwn.net/Articles/1019149/

Many eyebrows were raised recently when three vulnerabilities were announced
that allegedly impact GNU Mailman 2.1,
since many folks assumed that it was no longer being supported. That’s
not quite the case. Even though version 3 of
the GNU Mailman mailing-list manager has been available
since 2015, and version 2 was declared (mostly) end of life
(EOL) in 2020, there are still plenty of users and projects still
using version 2.1.x. There is, as it turns out, a big difference between
mostly EOL and actually EOL. For example: WebPros, the company behind the cPanel server and web-site-management
platform, still maintains a port of
Mailman 2.1.x
to Python 3 for its customers and was
quick to respond to reports of vulnerabilities. However, the
company and upstream Mailman project dispute that the CVEs are
valid.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1019457/

Security updates have been issued by Debian (glibc and libraw), Fedora (digikam, icecat, mingw-LibRaw, perl, perl-Devel-Cover, and perl-PAR-Packer), Red Hat (ghostscript, kernel, and kernel-rt), Slackware (mozilla), SUSE (augeas, firefox, and java-11-openjdk), and Ubuntu (binutils, libxml2, and nodejs).

OSI publishes election retrospective

Post Syndicated from jzb original https://lwn.net/Articles/1019215/

The Open Source Initiative (OSI) has quietly published
takeaways” from its internal retrospective on the recent board
of directors election as an update
to the March blog
post
that announced the new members of the board. The election was
controversial, in part, due to poor communication and OSI changing the
election rules and disqualifying several candidates after the election
finished. LWN covered
the election and results in March. The update commits to improvements
in communication and candidate selection:

What this election exposed was the need for the organization to also
assess whether candidates were fully eligible to run and prepared to
be seated on the board before voting begins. This is something we will
add to the election timeline next year. While we have not finished
figuring out all of the requirements for that assessment, part of it
will be asking candidates to sign a Candidate Agreement at nomination
time. We also have some ideas on ways for potential candidates to have
more information even before submitting a nomination.

In a related note, there is a petition
asking OSI to publish the “complete, unaltered” results of the
board of directors election. Thanks to Josh Triplett for the tip on
the petition.

[$] Debian debates AI models and the DFSG

Post Syndicated from jzb original https://lwn.net/Articles/1018497/

The Debian project is discussing a General Resolution (GR) that
would, if approved, clarify that AI models must include training data
to be compliant with the Debian
Free Software Guidelines
(DFSG) and be distributed by Debian as
free software. While GR discussions are sometimes contentious, the
discussion around the proposal from Debian developer Mo Zhou has
been anything but—there seems to be
consensus that AI models are not DFSG-compliant if they lack training
data. There are, however, some questions about the exact language and
questions about the impact the GR will have on existing packages in
the Debian archive.

[$] Addressing UID/GID drift in rpm-ostree and bootc

Post Syndicated from jzb original https://lwn.net/Articles/1018082/

The Fedora Project is looking for solutions to an interesting
problem with its image-based editions and spins, such as the Atomic Desktops
or CoreOS, that are
created with rpm-ostree or bootc. If a package that
is part of a image-based version has a user or group created
dynamically on installation, and it owns files installed on the
system, the system may be subject to user ID (UID) and group ID (GID) “drift”
on updates. This “UID/GID drift” may come about when a new image with
updates is generated, and therefore files may have the wrong
ownership. This can have side-effects ranging from mildly inconvenient to
serious. No solutions have been adopted just yet, but there are a few
ideas on how to deal with the problem.

NLnet announces funding for 42 FOSS projects

Post Syndicated from jzb original https://lwn.net/Articles/1018621/

The NLnet Foundation has announced
the projects that have received funding from its October call
for grant proposals from the Next
Generation Internet (NGI) Zero Commons Fund
.

The selected projects all contribute, one way or another, to the
mission of the Commons Fund: reclaiming the public nature of the
internet. For example, there are people working on interesting open
hardware projects such as the tablet MNT Reform Touch
and the Solar
FemtoTX motherboard
— a collaborative effort to create an
ultra-low power motherboard that can run on solar power. LLM2FPGA aims to enable
running open source LLMs locally on programmable chips (“FPGAs”) using
a fully open-source toolchain. bcachefs
readies itself as the next generation filesystem for Linux, improving
performance, scalability and reliability when compared to legacy
filesystems.

In all, 42 projects have been selected for the NGI grants which are
between €5,000 and €50,000. See the announcement for the
full list of selected projects, and the current projects page
for other recent projects funded by NLnet.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1018589/

Security updates have been issued by AlmaLinux (bluez, expat, and postgresql:12), Fedora (chromium, golang, LibRaw, moodle, openiked, ruby, and trafficserver), Red Hat (bluez, expat, gnutls, libtasn1, libxslt, mod_auth_openidc, mod_auth_openidc:2.3, ruby:3.1, thunderbird, and xmlrpc-c), and Ubuntu (linux, linux-aws, linux-gcp, linux-hwe-6.11, linux-lowlatency, linux-lowlatency-hwe-6.11, linux-oem-6.11, linux-oracle, linux-raspi, linux-realtime, linux-azure, linux-azure-6.11, linux-gcp-6.8, and matrix-synapse).

RISC-V images for Fedora Linux 42

Post Syndicated from jzb original https://lwn.net/Articles/1018322/

The Fedora Project’s RISC-V
special-interest group
(SIG) has announced
the availability of Fedora Linux 42 images for supported
RISC-V boards
, as well as QEMU
and container images. The SIG is working toward making RISC-V a
primary architecture for Fedora, and has made significant progress in
the past year.

Our upstreaming work continues apace, and we want to acknowledge
that none of this progress would be possible without the incredible
collaboration from maintainers across the Fedora Project and
beyond. Thank you to everyone who reviewed, accepted, merged, and
built our patches. Your support makes this architecture possible.

We’re also excited about just how many packages build cleanly
without special treatment or overlay repositories that need to be
cared for. RISC-V is becoming just another architecture, and that’s
exactly how it should be.

[$] Owen Le Blanc: creator of the first Linux distribution

Post Syndicated from jzb original https://lwn.net/Articles/1017846/

Ask a Linux enthusiast who created the Linux kernel, and odds are they will have
no trouble naming Linus Torvalds—but many would be stumped if asked what the
first Linux distribution was, and who created it. Some might guess Slackware, or its predecessor, Softlanding Linux
System
(SLS); both were arguably more influential but arrived just a bit
later. The first honest-to-goodness distribution with a proper installer was MCC Interim Linux,
created by Owen Le Blanc, released publicly in early 1992. I recently
reached out to Le Blanc to learn more about his work on the distribution, what
he has been doing since, and his thoughts on Linux in 2025.

Tor Browser 14.5 released

Post Syndicated from jzb original https://lwn.net/Articles/1017923/

Version
14.5
of the Tor
Browser
has been released. Notable features in this release
include the addition of Connection Assist for the Android version of
the Tor Browser, and language support for Belarusian, Bulgarian, and
Portuguese for all versions of the browser.

Should Tor Browser fail to establish a direct connection to the Tor
network, Connection Assist will offer to find and try bridges for
you. But before this feature could be made available on Android, we
had to embark on a multi-year effort to refactor our tor integration
across each platform first. This project has now reached an important
milestone, and we’re proud to announce the release of Connection
Assist for Android today.

See the full
changelog
for all changes in this release, and the issues
page
for known problems.