All posts by jzb

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1001728/

Security updates have been issued by Debian (proftpd-dfsg and smarty3), Fedora (python3.14), Gentoo (Distrobox, eza, idna, libvirt, and OpenSC), Red Hat (container-tools:rhel8 and edk2), SUSE (avahi, curl, libsoup2, lxd, nodejs20, python-Django, python310-Django4, python312, squid, and webkit2gtk3), and Ubuntu (expat, intel-microcode, linux, linux-aws, linux-kvm, linux-lts-xenial, and shiro).

A change of hats! (Fedora Magazine)

Post Syndicated from jzb original https://lwn.net/Articles/1001634/

Fedora Project Leader (FPL) Matthew Miller writes that he will soon be hanging up the FPL hat:

Stay tuned for a job posting from Red Hat, and details about all
that. I’m hoping we can hire someone awesome early in 2025, and make
the official handover on the release of auspiciously-numbered Fedora
Linux 42.

I’m not going to leave Fedora, though. As I said above, although it
might not always feel like it from the outside, Red Hat support for
Fedora is stronger than ever, and I plan on helping that grow even
more. I’m stepping into a full-time management role in the Community
Linux Engineering organization, so Fedora will still be part of my day
job, just in a different way.

Let’s Encrypt sets date for ending OCSP support

Post Syndicated from jzb original https://lwn.net/Articles/1000941/

In July, Let’s Encrypt announced it was ending
support “as soon as possible” for the Online
Certificate Status Protocol
(OCSP) in favor of Certificate
Revocation Lists
(CRLs) due to privacy concerns. The organization
has now announced
that it has set a timeline, and will be turning off its OCSP
responders on August 6, 2025. There is additional action required
for Let’s Encrypt users who use the OCSP Must Staple Extension:

As of January 30, 2025, issuance requests that include the OCSP
Must Staple extension will fail, unless the requesting account has
previously issued a certificate containing the OCSP Must Staple
extension.

As of May 7, all issuance requests that include the OCSP Must
Staple extension will fail, including renewals. Please change your
ACME client configuration to not request the extension.

‘Tis the Season for COSMIC Alpha 4! (System76 Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1000927/

System76 has announced the
fourth alpha release of its Rust-based COSMIC desktop. New features
in this version include the ability to set default applications,
region and language settings, a new Accessibility applet, as well as
support for
variable refresh rate
(VRR) in the cosmic-comp compositor and the
display settings tool. See the blog post for a full list of fixes and
performance improvements. LWN covered the first alpha
release in August.

[$] Debian opens a can of username worms

Post Syndicated from jzb original https://lwn.net/Articles/1000485/

It has long been said that naming things
is one of the hard things to do in computer science
. That may be
so, but it pales in comparison to the challenge of handling
usernames properly in applications. This is especially true when multiple
applications are involved, and they are all supposed to agree on what
characters are, and are not, allowed. The Debian project is facing
that problem right now, as two user-creation utilities disagreed about
which names are allowable. A plan is in place to sort this out
before the release of Debian 13 (“trixie”) sometime next year.

Fedora moves towards Forgejo (Fedora Magazine)

Post Syndicated from jzb original https://lwn.net/Articles/1000751/

Fedora Project Leader Matthew Miller reports
that the project’s search to replace Pagure as its git forge is
almost complete, with the Fedora Council strongly in favor of Forgejo:

The Council, currently, has a clear preference for Forgejo. This is a
big decision and we don’t want it to feel rushed. Therefore, we’re
opening this up one last time to everyone’s comments. After two weeks,
we’ll take our formal vote — and then get on with the work!

LWN looked at
Forgejo
in February.

Hurl 6.0.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1000726/

Version
6.0.0
of the Hurl command-line tool has been released. Hurl is
curl-powered utility that runs HTTP requests and tests defined in a
plain-text Hurl
file
. Notable features in this release include the ability to
generate dynamic values with functions, shorter syntax, and an option
to export Hurl files to a list of curl commands. See the release
notes
for a full list of changes and downloads.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1000721/

Security updates have been issued by Red Hat (go-toolset:rhel8, grafana, kernel, kernel-rt, kernel:4.18.0, pam, pam:1.5.1, pcs, postgresql:12, postgresql:15, postgresql:16, python3:3.6.8, qemu-kvm, rhc, rhc-worker-playbook, and virt:rhel and virt-devel:rhel) and SUSE (ansible-10, ansible-core, avahi, bpftool, python, python3, python36, webkit2gtk3, and xen).

Elementary OS 8 released

Post Syndicated from jzb original https://lwn.net/Articles/999910/

Version
8
of the Ubuntu-based elementary OS has been released. This
release includes a rewritten Dock, new window-management features,
improvements in the installation and initial setup procedures for
visually impaired users, as well as a new Secure Session mode:

In the Secure Session, apps will be more restricted and will require
your consent for access to system features. When an app wants to
listen in the background for your keystrokes, take a screenshot,
record the screen, or even pick up the color from a single pixel, you
will be asked first to make sure that it’s okay. The Secure Session
also comes with other modern features like support for Mixed DPI
modes—A hotly requested feature for folks using a HiDPI notebook or
tablet with a LoDPI external display—and improved support for
multi-touch gestures on touch screens and tablets.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/999897/

Security updates have been issued by Debian (mpg123 and php8.2), Fedora (libsndfile, mingw-glib2, mingw-libsoup, mingw-python3, and qbittorrent), Oracle (pam:1.5.1 and perl-App-cpanminus), Red Hat (firefox, thunderbird, and webkit2gtk3), Slackware (mozilla), SUSE (firefox, rclone, tomcat, tomcat10, and xen), and Ubuntu (gh, libsoup2.4, libsoup3, pygments, TinyGLTF, and twisted).

[$] Arch Linux finally starts licensing PKGBUILDs

Post Syndicated from jzb original https://lwn.net/Articles/998778/

Arch Linux is popular as a base
for other Linux distributions
; examples of Arch-derivatives include EndeavourOS, Manjaro, Parabola, and SteamOS.
There’s one small problem: the control files used to describe how to build
packages for Arch Linux have no stated license. That creates a bit of
uncertainty about the rights and responsibilities for the downstream
derivatives. So far, that doesn’t seem to have been a problem, nor has
it stopped other projects from assuming that reuse is
allowed. However, the Arch project is looking to add some clarity by
explicitly assigning a liberal license to its package
sources. Currently the project is in the process of reaching out to
contributors to see if they have any objections.

[$] Book review: Run Your Own Mail Server

Post Syndicated from jzb original https://lwn.net/Articles/998153/

The most common piece of advice given to users who ask about
running their own mail server is don’t. Setting up
and securing a mail server in 2024 is not for the faint of heart, nor
for anyone without copious spare time. Spammers want to flood inboxes
with ads for questionable supplements, attackers want to abuse servers
to send spam (or worse), and getting the big providers to accept mail
from small servers is a constant uphill battle. Michael W. Lucas,
however, encourages users to thumb their nose at the “Email
Empire
“, and declare email independence. His self-published book,
Run Your Own Mail
Server
, provides a manual (and manifesto) for users who are
interested in the challenge.

FreeBSD Foundation releases Bhyve and Capsicum security audit

Post Syndicated from jzb original https://lwn.net/Articles/998615/

The FreeBSD Foundation has announced
the release of a security
audit report
conducted by security firm Synacktiv. The audit uncovered
a number of vulnerabilities:

Most of these vulnerabilities have been addressed through official FreeBSD
Project security advisories
, which offer detailed information
about each vulnerability, its impact, and the measures implemented to
improve the security of FreeBSD systems. […]

The audit uncovered 27 vulnerabilities and issues within various
FreeBSD subsystems. 7 issues were not exploitable and were robustness
or code quality improvements rather than immediate security concerns.

[$] Fedora KDE gets a promotion

Post Syndicated from jzb original https://lwn.net/Articles/997559/

The Fedora Project is set to welcome a second desktop edition to its
lineup after months (or years, depending when one starts the clock)
of discussions. The project recently decided to allow a new working group to
move forward with a KDE Plasma Desktop edition that will sit
alongside the existing GNOME-based Fedora Workstation
edition. This puts KDE on a more equal footing within the project,
which, it is hoped, will bring more contributors and users interested
in KDE to adopt Fedora as their Linux distribution of choice.

PyPI now supports digital attestations

Post Syndicated from jzb original https://lwn.net/Articles/998215/

The Python Package Index (PyPI) has announced
that it has finalized support for PEP 740 (“Index support
for digital attestations”). Trail of Bits, which performed
much of the development work for the implementation, has an in-depth
blog post
about the work and its adoption, as well as what is left
undone:

One thing is notably missing from all of this work:
downstream verification. […]

This isn’t an acceptable end state (cryptographic attestations have
defensive properties only insofar as they’re actually
verified
), so we’re looking into ways to bring
verification to individual installing clients. In particular, we’re
currently working on a plugin architecture
for pip
that will enable users to load
verification logic
directly into their pip install
flows.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/998044/

Security updates have been issued by AlmaLinux (expat), Fedora (chromium and golang-github-nvidia-container-toolkit), Mageia (curl, expat, mpg123, networkmanager-libreswan, openssl, php-tcpdf, qbittorrent, and x11-server, x11-server-xwayland, and tigervnc), Red Hat (kernel and libsoup), Slackware (mozilla), SUSE (firefox, kernel, python-PyPDF2, and xen), and Ubuntu (dotnet9, ghostscript, linux-aws, linux-oem-6.8, and pydantic).

Anaconda’s new “Web UI” (Fedora Magazine)

Post Syndicated from jzb original https://lwn.net/Articles/997927/

Garrett LeSage has written an in-depth article
for Fedora Magazine about a new web-based user interface (UI) for Fedora’s
Anaconda
installer, planned to ship with Fedora 42. The article looks at
the rationale for moving from GTK 3 to a web-based UI, provides a
number of screenshots and demo screencasts, as well as instructions on
trying out the new installer with Fedora Rawhide.

[$] Pondering systemd-homed for Fedora

Post Syndicated from jzb original https://lwn.net/Articles/995915/

Fedora Linux, as a rule, handles version upgrades reasonably
well. However, there are times when users may want to do a fresh
installation rather than an upgrade but preserve existing
users and data under /home. This is a scenario that the
Fedora installer, currently, does not address. Users can maintain a
separate /home partition, of course, but the installer does
not incorporate existing users into the new install—that is an
exercise left to the user to handle. One solution might be to use systemd-homed, a systemd
service for managing users and home directories. However, a discussion
proposing the use systemd-homed as part of Fedora installation
uncovered some hurdles, such as trying to blend its approach to
managing users with tools that centralize user management.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/997182/

Security updates have been issued by AlmaLinux (libtiff), Debian (context, libheif, and thunderbird), Fedora (php-tcpdf, syncthing, and thunderbird), Gentoo (EditorConfig core C library, Flatpak, Neat VNC, and Ubiquiti UniFi), Oracle (bcc, bpftrace, grafana-pcp, haproxy, kernel, krb5, libtiff, python-gevent, python3.11-urllib3, python3.12-urllib3, and xmlrpc-c), Red Hat (python3.11-urllib3), SUSE (audacity, curl, govulncheck-vulndb, gradle, htmldoc, libgsf, python310, and qbittorrent), and Ubuntu (linux-aws-5.4, linux-oracle-5.4, mpg123, and python-werkzeug).