All posts by jzb

Arch Linux disables AUR package adoption

Post Syndicated from jzb original https://lwn.net/Articles/1086489/

The Arch Linux DevOps team has announced
that adoption of orphaned packages in the Arch User Repository (AUR)
has been disabled due to “the current influx of malicious package
adoptions and follow-up commits made via the AUR
“. Michael Taggart
has posted a brief analysis of the malware being added to a long
list of packages
in this round of attacks. The payload appears
to be
an remote-access trojan (RAT) that takes commands over the
Tor network and attempts to upload a wide range of user data.

The project had suspended
new account registration
in June. That followed a campaign in which an
attacker or attackers created new accounts to adopt orphaned packages
and push malicious updates to them that would install malware on user
systems. AUR registration was reopened
on July 13 after the DevOps team added some minor, and apparently
ineffective, restrictions on creating new accounts.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1086487/

Security updates have been issued by AlmaLinux (kernel, nodejs-nodemon, nodejs22, nodejs24, openssh, and vim), Debian (gsasl and ruby-rack), Fedora (dokuwiki, lego, libnbd, nasm, pack, unbound, and valkey), Mageia (389-ds-base, libxfont2, nghttp2, and perl-DBI), SUSE (apptainer, bind, ffmpeg-7, freerdp, google-osconfig-agent, graphicsmagick, helm, ImageMagick, java-17-openjdk, java-25-openjdk, keybase-client, kubernetes1.34-apiserver, kubernetes1.35-apiserver, kubernetes1.36-apiserver, kubevirt1.8-container-disk, libarchive, logcli, net-tools, openssl-3, PackageKit, perl-Net-DNS, prometheus-ha_cluster_exporter, python-dulwich, python-sqlparse, python-urwid, python3-pyOpenSSL, python313, python3, runc, s2n, tomcat, tomcat10, tomcat11, and valkey), and Ubuntu (libinput, linux-intel-iot-realtime, linux-intel-iotg-5.15, openssl, python2.7, python3.5, and ruby-sinatra).

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1086225/

Security updates have been issued by AlmaLinux (gstreamer1-plugins-bad-free, libtiff, libXfont2, nodejs:22, nodejs:24, and rest), Debian (expat and nss), Fedora (libssh, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, nodejs24, perl-HTTP-Date, proftpd, squid, unbound, and wordpress), Oracle (c-ares, edk2, freerdp, go-fdo-server, libreswan, mariadb-connector-c, and nginx), SUSE (alloy, apache-commons-lang3, google-guice, maven, maven-resolver, xmvn, apache-sshd, apptainer, avahi, distribution, glib2, go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21, gstreamer-plugins-bad, helm, ImageMagick, java-17-openjdk, java-25-openjdk, liboqs, oqs-provider, libssh, nginx, nm-configurator, nmap, openssl-3, openvpn, PackageKit, perl, perl-DBI, perl-HTTP-Date, perl-XML-Bare, python-msgpack-python, python-sh, python-ujson, python-urllib3, runc, samba, sssd, wget, wpa_supplicant, and xen), and Ubuntu (linux-nvidia, linux-nvidia-7.0 and linux-nvidia-6.17).

[$] LWN.net Weekly Edition for July 30, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1084315/

Inside this week’s LWN.net Weekly Edition:

  • Front: Hazard pointers; DFSG team; Swap devices; Netkit and BPF; BPF inlined functions; Fedora GRUB; gccrs.
  • Briefs: RIP Dan Williams; Debian LLM resolution; Fedora 45 process; Codeberg LLM policy; GCC LLM policy; GNU Binutils 2.47; GNU C Library 2.44; Wayfire 0.11; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

[$] Fedora approves a smaller GRUB

Post Syndicated from jzb original https://lwn.net/Articles/1085609/

Leo Sandoval and Marta Lewandowska have put forward a change
proposal
for Fedora 45, which is expected in October, to
provide a separate, slimmed-down version of GRUB for a niche use
case. The new package would be in addition to the main GRUB package
and would not replace it for the majority of Fedora users. The idea
met with some resistance from Fedora contributors who thought that it
would be better to use systemd-boot,
or another modern bootloader, rather than trying to wrangle GRUB into
a suitable state for the use case. The Fedora Engineering Steering
Council (FESCo), however, voted
to accept the change
on July 7.

GCC steering committee announces AI policy

Post Syndicated from jzb original https://lwn.net/Articles/1086041/

The GCC steering committee has announced
that it has accepted an
AI contributions policy
recommended by the GCC AI policy working
group.

The policy, in part, states that the project will decline any
legally significant contributions which include LLM-generated
content or are derived from LLM-generated content
“. It uses the definition
of “legally significant” from the GNU Project maintainer guidelines,
which holds that the threshold is “around 15 lines of code and/or
text
” to qualify as significant for copyright purposes. GCC
maintainers may, however, choose to accept legally significant test
cases that are generated by an LLM.

The policy does not forbid use of LLMs for research, analysis, bug
discovery and reporting, patch review, etc. as long as the output is
not included in contributions. The committee says that it expects the
policy will evolve and will be revisited periodically.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1086031/

Security updates have been issued by AlmaLinux (dovecot, go-fdo-client, go-fdo-server, kernel, kernel-rt, and sssd), Debian (calibre, hplip, libraw, and samba), Fedora (btrbk, chromium, gpsd, kronosnet, and restic), Mageia (gstreamer1.0-libav and libslirp), Slackware (libarchive, samba, and seamonkey), SUSE (agama-web-ui, chromium, gimp, glib2, GraphicsMagick, ignition, ImageMagick, java-21-openjdk, libssh, libssh-config, nginx, nmap, nsd, python-urllib3, python313-CherryPy, rsyslog, samba, sssd, valkey, webkit2gtk3, and yq), and Ubuntu (freerdp3, linux, linux-aws, linux-aws-5.4, linux-aws-fips, linux-azure, linux-azure-5.4, linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4, linux-gcp-fips, linux-hwe-5.4, linux-iot, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux-azure-fips, linux-ibm, linux-ibm-5.4, linux-kvm, and linux-raspi, linux-raspi-5.4).

[$] A report from Debian’s new DFSG team

Post Syndicated from jzb original https://lwn.net/Articles/1084499/

The DFSG, Licensing
& New Packages Team
(usually shortened to “DFSG team”) was
created in October 2025 as part of the ftpmaster team split. Its
job is to review packages in the new queue for compliance
with the Debian
Free Software Guidelines
(DFSG), among other things, before the
packages are allowed to enter the Debian
archive
. The change was long in coming, and some questions
remained after the split whether it was the right move. Andrew
McMillan provided an overview of the team’s activities and its current
status during DebConf26. While it may be
too early to say with certainty, his report suggests that the new
division of duties is working out well.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1085855/

Security updates have been issued by AlmaLinux (grafana and libreswan), Debian (openjdk-11 and openjdk-17), Fedora (opkssh, perl-Mojolicious, and rpm), Mageia (libyang, memcached, nginx, packages, and sqlite3), Oracle (.NET 8.0, acl, buildah, compat-openssl11, compat-poppler022, dogtag-pki, git-lfs, glibc, go-fdo-client, golang, httpd:2.4, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, kernel, libpq, LibRaw, maven:3.8, mysql8.4, nodejs:22, nodejs:24, openssl, podman, poppler, python3.14, samba, sssd, tomcat, tomcat9, vim, and yggdrasil), Red Hat (gstreamer1-plugins-bad-free), SUSE (afterburn, alsa, apache-ivy, avahi, aws-nitro-enclaves-cli, chromium, cifs-utils, cockpit, cockpit-machines, cockpit-packages, cockpit- podman, cockpit-repos, cockpit-subscriptions, containerd, curl, docker-compose, freetype2, gawk, glib2, google-cloud-sap-agent, gpg2, gstreamer-plugins-bad, gzip, helm, ignition, ImageMagick, jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base, jackson-annotations, jackson-core, jackson-databind, java-11-openjdk, jline3, joe, jq, kernel, libgcrypt, libknet-devel, libsoup, libxml2, mariadb-connector-c, mcphost, net-tools, nghttp2, opennlp, openssl-1_0_0, PackageKit, pam, patch, pcr-oracle, perl, perl-DBI, perl-HTTP-Date, python-aiohttp, python-cryptography, python-Pillow, python-pyasn1, python-soupsieve, python-tornado, python-tornado6, python-urllib3, python3, radvd, rust-keylime, s390-tools, shibboleth-sp, sssd, systemd, tiff, vim, and wpa_supplicant), and Ubuntu (FreeIPMI, glibc, linux-aws, linux-aws, linux-raspi, linux-aws-6.8, linux-aws-fips, linux-azure, linux-azure-6.8, linux-azure, linux-oracle, linux-azure-5.15, linux-azure-fde-5.15, linux-oracle-5.15, linux-azure-6.17, linux-azure-fde, linux-azure-fde-6.17, linux-azure-fde-6.8, linux-azure-fips, linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-nvidia-tegra, linux-xilinx, linux-oracle-6.17, roc-toolkit, and samba).

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1085554/

Security updates have been issued by Debian (chromium, hplip, and linux-6.1), Fedora (firefox, GitPython, google-osconfig-agent, lego, libgit2, libreswan, libwebsockets, moby-engine, p11-kit, pam, python-idna, rust-libgit2-sys, skopeo, systemd, trafficserver, webkitgtk, and xrdp), Mageia (giflib, graphite2, libnfs, vorbis-tools, wget, and yelp), Red Hat (firefox, thunderbird, and webkit2gtk3), and SUSE (amazon-ecs-init, chromedriver, ffmpeg-7, ffmpeg-8, firefox, google-osconfig-agent, gpg2, java-17-openjdk, java-25-openjdk, kernel, libsrt1_5, nginx, perl-HTTP-Date, perl-XML-Bare, proftpd, python-pyasn1, python-soupsieve, python313-astropy, python313-urwid, systemd, thunderbird, and trivy).

De Vlieger: The Fedora 45 sausage factory

Post Syndicated from jzb original https://lwn.net/Articles/1084920/

Fedora contributor Simon de Vlieger has published a blog
post
with a walkthrough of how the project turns source code and
packages into the final release that users install on their systems.

It follows the a package from a packager’s git push to a composed
release: ISOs, cloud images, container images, and OSTree
deployments.

The walkthrough describes how the Fedora ‘sausage’ is created as of
Fedora 45, things change all the time; I hope to have time to update
this document every cycle or every few cycles of Fedora releases so
there’s both history and people can find up to date information.

Home Assistant Device Database public preview

Post Syndicated from jzb original https://lwn.net/Articles/1084861/

The Open Home
Foundation
, which governs the Home Assistant
home-automation project, has announced
the “public preview” of its Device
Database
:

Providing a public, open way to browse the anonymous, aggregated
device data we collect was always part of the plan, and this preview
is our first step toward it.

You can already use it to search and filter devices to see
aggregated community insights, starting with a deliberately focused
set of specifics, such as whether a device requires an internet
connection, and which protocols and integrations it works with. We’ve
kept that initial scope narrow on purpose, giving us a solid
foundation we can build on together with you, our community, as the
database grows.

LWN looked at Home
Assistant in May 2025.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1084860/

Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and socat), Oracle (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), Red Hat (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), Slackware (mozilla-thunderbird), SUSE (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and Ubuntu (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1084401/

Security updates have been issued by AlmaLinux (acl, dogtag-pki, dovecot, glibc, go-toolset:rhel8, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd:2.4, javapackages-tools:201801, libtiff, mariadb-connector-c, perl-HTTP-Daemon, pki-deps:10.6, and sssd), Debian (bind9, chromium, firefox-esr, and pdns-recursor), Fedora (chromium, collectl, fractal, kernel, libssh, llvm, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, perl-DBI, perl-YAML-Syck, and srt), SUSE (7zip, GraphicsMagick, ImageMagick, multipath-tools, perl-YAML, python-sqlparse, python3-sqlparse, python313-bleach, and sssd), and Ubuntu (apache2, commons-beanutils, exim4, gawk, giflib, gst-plugins-good1.0, krb5, libapache-mod-jk, libarchive, libgphoto2, libhtml-parser-perl, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-ibm, linux-nvidia, linux-fips, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-ibm, linux-oracle, linux-ibm-5.15, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oem-6.17, linux-oracle-6.8, python-aiohttp, and tar).