Feed lwn LWN.net

Favorite IconLWN.net

Link https://lwn.net/
Feed http://lwn.net/headlines/rss
Updated 2026-08-02 21:30
Servo 0.4.0 released
The Servo web-browser engineproject has published an updateabout all of the changes that landed in June 2026, along with version0.4.0 of the Servo Tech Demo. This release includes a record 558commits, betterlayout correctness for web sites, improved WebGPU support, enhancementsfor users who are using the servoshelltest browser, and many performanceand stability fixes.
[$] The future of libraries in BPF
Song Liu believes that the way that programmers assemble complex BPF programswill be changing rapidly in the future. At a session of the 2026Linux Storage,Filesystem, Memory-Management, and BPF Summit, he shared his thoughts on whatthat change could look like, though he did not have any concrete proposals forwhat, if anything, the BPF maintainers should do. He anticipates anecosystem of Rust BPF packages developing, which is significant because BPFdoes not really have a package manager at the moment.
Arch Linux disables AUR package adoption
The Arch Linux DevOps team has announcedthat adoption of orphaned packages in the Arch User Repository (AUR)has been disabled due to "the current influx of malicious packageadoptions and follow-up commits made via the AUR". Michael Taggarthas posted a brief analysis of the malware being added to a longlist of packages in this round of attacks. The payload appearsto be an remote-access trojan (RAT) that takes commands over theTor network and attempts to upload a wide range of user data.The project had suspendednew account registration in June. That followed a campaign in which anattacker or attackers created new accounts to adopt orphaned packagesand push malicious updates to them that would install malware on usersystems. AUR registration was reopenedon July13 after the DevOps team added some minor, and apparentlyineffective, restrictions on creating new accounts.
Security updates for Friday
Security updates have been issued by AlmaLinux (kernel, nodejs-nodemon, nodejs22, nodejs24, openssh, and vim), Debian (gsasl and ruby-rack), Fedora (dokuwiki, lego, libnbd, nasm, pack, unbound, and valkey), Mageia (389-ds-base, libxfont2, nghttp2, and perl-DBI), SUSE (apptainer, bind, ffmpeg-7, freerdp, google-osconfig-agent, graphicsmagick, helm, ImageMagick, java-17-openjdk, java-25-openjdk, keybase-client, kubernetes1.34-apiserver, kubernetes1.35-apiserver, kubernetes1.36-apiserver, kubevirt1.8-container-disk, libarchive, logcli, net-tools, openssl-3, PackageKit, perl-Net-DNS, prometheus-ha_cluster_exporter, python-dulwich, python-sqlparse, python-urwid, python3-pyOpenSSL, python313, python3, runc, s2n, tomcat, tomcat10, tomcat11, and valkey), and Ubuntu (libinput, linux-intel-iot-realtime, linux-intel-iotg-5.15, openssl, python2.7, python3.5, and ruby-sinatra).
[$] Reconsidering O_CREAT|O_DIRECTORY
Linux provides a system call (mkdir())to create a directory, and a few variants ofopen() that can open a directory. There is, however, nosystem call in Linux that can create and open a directory in a single,race-free call. Jori Koolstra has been working on remedying thatsituation, most recently by repurposing a set of open() flags that currentlyreturn an error. There are, however, concerns that show just how hard itcan be to create user-space interfaces that do not present traps forapplication developers.
Another batch of single-fix stable kernels
Greg Kroah-Hartman has announced the release of the 6.18.41, 6.12.100, 6.6.147, 6.1.180, 5.15.213, and 5.10.262 stable kernels.Each of these kernels contains a single fix for a use-after-freevulnerability (CVE-2026-64560). Usersof these kernels are advised to upgrade.
Security updates for Thursday
Security updates have been issued by AlmaLinux (gstreamer1-plugins-bad-free, libtiff, libXfont2, nodejs:22, nodejs:24, and rest), Debian (expat and nss), Fedora (libssh, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, nodejs24, perl-HTTP-Date, proftpd, squid, unbound, and wordpress), Oracle (c-ares, edk2, freerdp, go-fdo-server, libreswan, mariadb-connector-c, and nginx), SUSE (alloy, apache-commons-lang3, google-guice, maven, maven-resolver, xmvn, apache-sshd, apptainer, avahi, distribution, glib2, go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21, gstreamer-plugins-bad, helm, ImageMagick, java-17-openjdk, java-25-openjdk, liboqs, oqs-provider, libssh, nginx, nm-configurator, nmap, openssl-3, openvpn, PackageKit, perl, perl-DBI, perl-HTTP-Date, perl-XML-Bare, python-msgpack-python, python-sh, python-ujson, python-urllib3, runc, samba, sssd, wget, wpa_supplicant, and xen), and Ubuntu (linux-nvidia, linux-nvidia-7.0 and linux-nvidia-6.17).
[$] LWN.net Weekly Edition for July 30, 2026
Inside this week's LWN.net Weekly Edition:
[$] Debugging information for inlined functions
BPF programs useBPF type format (BTF) debugging information in order todetermine how to interact with functions in the kernel. Specifically, tracing akernel function involves finding its address in the kernel's BTF section - butthat doesn't work for functions that have been inlined, and therefore don't havea single, specific address. Alan Maguire wants to add information about inlinedfunctions to BTF in order to allow them to be traced, and led a session on thattopic at the 2026Linux Storage, Filesystem, Memory-Management, and BPF Summit.
Three stable kernels for Wednesday fix a single regression
Greg Kroah-Hartman has announced the release of the 6.12.99, 6.6.146, and 6.1.179 stable kernels. This batch ofstable kernels includes a single fix for a regressioncaused by thiscommit. Users of those kernels should upgrade.
[$] Fedora approves a smaller GRUB
Leo Sandoval and Marta Lewandowska have put forward a changeproposal for Fedora45, which is expected in October, toprovide a separate, slimmed-down version of GRUB for a niche usecase. The new package would be in addition to the main GRUB packageand would not replace it for the majority of Fedora users. The ideamet with some resistance from Fedora contributors who thought that itwould be better to use systemd-boot,or another modern bootloader, rather than trying to wrangle GRUB intoa suitable state for the use case. The Fedora Engineering SteeringCouncil (FESCo), however, votedto accept the change on July7.
GCC steering committee announces AI policy
The GCC steering committee has announcedthat it has accepted anAI contributions policy recommended by the GCC AI policy workinggroup.The policy, in part, states that the project will decline any"legally significant contributions which include LLM-generatedcontent or are derived from LLM-generated content". It uses the definitionof "legally significant" from the GNU Project maintainer guidelines,which holds that the threshold is "around 15 lines of code and/ortext" to qualify as significant for copyright purposes. GCCmaintainers may, however, choose to accept legally significant testcases that are generated by an LLM.The policy does not forbid use of LLMs for research, analysis, bugdiscovery and reporting, patch review, etc. as long as the output isnot included in contributions. The committee says that it expects thepolicy will evolve and will be revisited periodically.
Security updates for Wednesday
Security updates have been issued by AlmaLinux (dovecot, go-fdo-client, go-fdo-server, kernel, kernel-rt, and sssd), Debian (calibre, hplip, libraw, and samba), Fedora (btrbk, chromium, gpsd, kronosnet, and restic), Mageia (gstreamer1.0-libav and libslirp), Slackware (libarchive, samba, and seamonkey), SUSE (agama-web-ui, chromium, gimp, glib2, GraphicsMagick, ignition, ImageMagick, java-21-openjdk, libssh, libssh-config, nginx, nmap, nsd, python-urllib3, python313-CherryPy, rsyslog, samba, sssd, valkey, webkit2gtk3, and yq), and Ubuntu (freerdp3, linux, linux-aws, linux-aws-5.4, linux-aws-fips, linux-azure, linux-azure-5.4, linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4, linux-gcp-fips, linux-hwe-5.4, linux-iot, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux-azure-fips, linux-ibm, linux-ibm-5.4, linux-kvm, and linux-raspi, linux-raspi-5.4).
[$] Progress toward compiling Linux with gccrs
The gccrs project, which is creating a Rust frontend for the GCC compiler, hasspent the first half of 2026 focusing on compiling the Linuxkernel. By testing the compiler against the kernel crates, thedevelopment team has made significant progress toward generating correct codefor other Rust programs. As detailed in the project'sweekly andmonthly reports, this effort has uncovered and resolved problemsin areas such asattribute handling (described in thereport for February), name resolution, and resource management (bothdetailed in the May report). Currently, the compiler can only handle simplestandalone programs, but that situation could change rapidly in the comingmonths.
Wayfire 0.11 released
Version0.11 of the wlroots-basedWayfire Wayland compositor has beenreleased. Notable changes include better fractional scaling,per-output ICCprofiles, support for additional Wayland protocols, and more.
[$] A report from Debian's new DFSG team
The DFSG, Licensing& New Packages Team (usually shortened to "DFSG team") wascreated in October 2025 as part of the ftpmaster team split. Itsjob is to review packages in the new queue for compliancewith the DebianFree Software Guidelines (DFSG), among other things, before thepackages are allowed to enter the Debianarchive. The change was long in coming, and some questionsremained after the split whether it was the right move. AndrewMcMillan provided an overview of the team's activities and its currentstatus during DebConf26. While it may betoo early to say with certainty, his report suggests that the newdivision of duties is working out well.
Security updates for Tuesday
Security updates have been issued by AlmaLinux (grafana and libreswan), Debian (openjdk-11 and openjdk-17), Fedora (opkssh, perl-Mojolicious, and rpm), Mageia (libyang, memcached, nginx, packages, and sqlite3), Oracle (.NET 8.0, acl, buildah, compat-openssl11, compat-poppler022, dogtag-pki, git-lfs, glibc, go-fdo-client, golang, httpd:2.4, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, kernel, libpq, LibRaw, maven:3.8, mysql8.4, nodejs:22, nodejs:24, openssl, podman, poppler, python3.14, samba, sssd, tomcat, tomcat9, vim, and yggdrasil), Red Hat (gstreamer1-plugins-bad-free), SUSE (afterburn, alsa, apache-ivy, avahi, aws-nitro-enclaves-cli, chromium, cifs-utils, cockpit, cockpit-machines, cockpit-packages, cockpit- podman, cockpit-repos, cockpit-subscriptions, containerd, curl, docker-compose, freetype2, gawk, glib2, google-cloud-sap-agent, gpg2, gstreamer-plugins-bad, gzip, helm, ignition, ImageMagick, jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base, jackson-annotations, jackson-core, jackson-databind, java-11-openjdk, jline3, joe, jq, kernel, libgcrypt, libknet-devel, libsoup, libxml2, mariadb-connector-c, mcphost, net-tools, nghttp2, opennlp, openssl-1_0_0, PackageKit, pam, patch, pcr-oracle, perl, perl-DBI, perl-HTTP-Date, python-aiohttp, python-cryptography, python-Pillow, python-pyasn1, python-soupsieve, python-tornado, python-tornado6, python-urllib3, python3, radvd, rust-keylime, s390-tools, shibboleth-sp, sssd, systemd, tiff, vim, and wpa_supplicant), and Ubuntu (FreeIPMI, glibc, linux-aws, linux-aws, linux-raspi, linux-aws-6.8, linux-aws-fips, linux-azure, linux-azure-6.8, linux-azure, linux-oracle, linux-azure-5.15, linux-azure-fde-5.15, linux-oracle-5.15, linux-azure-6.17, linux-azure-fde, linux-azure-fde-6.17, linux-azure-fde-6.8, linux-azure-fips, linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-nvidia-tegra, linux-xilinx, linux-oracle-6.17, roc-toolkit, and samba).
[$] Hazard pointers for the kernel
The kernel's read-copy-update (RCU) subsystem ensures that data will not bedeleted until it is known that there are no threads holding references toit. RCU works well and is widely used throughout the kernel, but it canincrease memory use and add significant delays before unused kernel objectsare cleaned up. Hazard pointers arean alternative approach to lockless data updates that offers betterperformance, for some situations at least. The kernel community iscurrently considering ahazard-pointer implementation by Mathieu Desnoyers and Paul McKenney.
GNU Binutils 2.47 released
Version2.47 of GNUBinutils has been released. In addition to the usual bug fixesthere are some notable new features in this release including addedsupport for a number of RISC-V standard extensions, a command-lineoption (-Mannotate) which displays the symbol forundefined instructions for AArch64, and more. The 32-bit s390 targethas been deprecated with this release.
Security updates for Monday
Security updates have been issued by Debian (chromium, hplip, and linux-6.1), Fedora (firefox, GitPython, google-osconfig-agent, lego, libgit2, libreswan, libwebsockets, moby-engine, p11-kit, pam, python-idna, rust-libgit2-sys, skopeo, systemd, trafficserver, webkitgtk, and xrdp), Mageia (giflib, graphite2, libnfs, vorbis-tools, wget, and yelp), Red Hat (firefox, thunderbird, and webkit2gtk3), and SUSE (amazon-ecs-init, chromedriver, ffmpeg-7, ffmpeg-8, firefox, google-osconfig-agent, gpg2, java-17-openjdk, java-25-openjdk, kernel, libsrt1_5, nginx, perl-HTTP-Date, perl-XML-Bare, proftpd, python-pyasn1, python-soupsieve, python313-astropy, python313-urwid, systemd, thunderbird, and trivy).
Kernel prepatch 7.2-rc5
The 7.2-rc5 kernel prepatch is out fortesting. Linus said: "So it's a bit too big for my liking, but nothingin there strikes me as particularly strange or scary".
A Debian general resolution on LLM usage
The Debian project is considering a generalresolution on the use of large language models in the creation of thedistribution. There are three alternatives to consider: atotal ban on LLM usage, rejecting LLMs "as far as practical", orexplicitly allowing LLM usage subject to a set of conditions. Thediscussion period has just begun; the beginning of the voting period doesnot yet appear to have been set. Those who want to look over thediscussion ahead of the inevitable LWN article can find it over here.
In remembrance of Dan Williams
On July 21, the kernel community lost Dan Williams, one of its most belovedcontributors. Dave Hansen and Thomas Gleixner, both of whom worked withWilliams extensively, have written an obituary and allowed LWN to publishit. He will be deeply missed, but he has left us with a lot to rememberhim by.
Security updates for Saturday
Security updates have been issued by AlmaLinux (compat-openssl11, java-1.8.0-openjdk, java-17-openjdk, kernel, kernel-rt, and sssd), Debian (exim4), Fedora (chromium, dotnet10.0, mbedtls, mupdf, netatalk, python-django5, skopeo, sssd, and wget1), Mageia (libevent and transmission), Oracle (.NET 8.0, 389-ds-base, aardvark-dns, acl, buildah, cifs-utils, dovecot, dracut, galera and mariadb11.8, glibc, hplip, kernel, libxml2, nginx, openexr, podman, postgresql18, rsync, thunderbird, and vim), and SUSE (389-ds, afterburn, agama, alsa, apache-commons-compress, apache-ivy, brotli-java, zstd-jni, avahi, aws-nitro-enclaves-cli, cockpit, cockpit-machines, cockpit-packages, cockpit- podman, cockpit-repos, cockpit-subscriptions, container-suseconnect, containerd, cosign, cryptsetup, curl, dash, dnsmasq, docker, docker-compose, ffmpeg, firefox, freetype2, gawk, gh, glib-networking, glib2, go1.25, go1.25-openssl, go1.26, go1.26-openssl, google-guest-agent, google-osconfig-agent, gpg2, gsasl, gstreamer-plugins-bad, gzip, haproxy, hauler, helm, helm3, ImageMagick, imagemagick, iproute2, java-11-openjdk, java-26-openjdk, jline3, joe, jq, kernel, kernel-devel, krb5, kubevirt, libgcrypt, libpng12, libqt4, libssh2_org, libXfont2, libxml2, mariadb-connector-c, microcode_ctl, multipath-tools, nasm, net-tools, nghttp2, nmap, ntfs-3g_ntfsprogs, openexr, packagekit, pam, patch, perl, perl-DBI, perl-dbi, perl-http-date, perl-libwww-perl, perl-xml-bare, php8, prometheus-ha_cluster_exporter, python-aiohttp, python-cryptography, python-dulwich, python-idna, python-maturin, python-mistune, python-msgpack, python-paramiko, python-Pillow, python-pyasn1, python-soupsieve, python-sqlparse, python-tornado, python-tornado6, python-urllib3, python313, python313-pandas, python314, qemu, radvd, rootlesskit, rpcbind, ruby3.4, runc, s390-tools, shibboleth-sp, sssd, systemd, systemd, systemd-mini, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, terraform-provider-susepubliccloud, tiff, tomcat, tomcat10, tomcat11, uriparser, vim, vorbis-tools, wget, wpa_supplicant, xwayland, and yelp).
GNU C Library 2.44 released
Version 2.44 of theGNU C Library has been released. Changes include a new/etc/tunables.conf file for the system-wide setting of tunableparameters, a new tunable to control the use of transparent huge pages forread-only executable segments, a number of math-function improvements, ahandful of security fixes, and more.
New stable kernel for ext4 users
Greg Kroah-Hartman has released the 6.12.98 stable Linux kernel with asingle fix for a file descriptor leak in ext4. Users of the ext4filesystem should upgrade.
Hefty stable kernel updates for Friday
Greg Kroah-Hartman has announced the release of the 7.1.5, 6.18.40, 6.12.97, 6.6.145, 6.1.178, 5.15.212, and 5.10.261 stable Linux kernels.This batch of kernels includes a hefty set of updates, possibly the largest ever. 7.1.5-rc1,for example, included more than 2,000 patches, 6.18.40-rc1included 1,611 patches, and so forth. Users are advised to upgrade.
Linux Plumbers Conference 2026 registration open
Registration is nowopen for the 2026 Linux Plumbers Conference, to be held October5to7 in Prague, Czechia. Tickets to this event tend to sell outquickly, so interested attendees probably should not procrastinate.
De Vlieger: The Fedora 45 sausage factory
Fedora contributor Simon de Vlieger has published a blogpost with a walkthrough of how the project turns source code andpackages into the final release that users install on their systems.
[$] An update on netkit and the use of BPF in user space
Daniel Borkmann led a session at the 2026Linux Filesystem, Memory-Management,and BPF Summit about the progress that has been made with netkit, the subsystemthat allows virtual machines (VMs) running on Linux to perform networking efficiently.When that did not fill the full time, he went on to discuss his idea forusing BPF to live-patch user-space applications. While netkit is makingprogress, and can now support zero-copy receipt of packets into a VM in anetwork namespace, the idea of using BPF for patching user-space programsremains entirely speculative.
Home Assistant Device Database public preview
The Open HomeFoundation, which governs the Home Assistanthome-automation project, has announcedthe "public preview" of its DeviceDatabase:
Security updates for Friday
Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and socat), Oracle (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), Red Hat (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), Slackware (mozilla-thunderbird), SUSE (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and Ubuntu (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).
Mourning Dan Williams
I have just received the shocking news that Dan Williams, a longtime,high-profile kernel developer, has passed away. I knew him primarilythrough his long service on the Linux Foundation Technical Advisory Board;he was always a strong, thoughtful, and intelligent presence. Dan will bedeeply missed.There is a supporteffort underway for Dan's family as they come to terms with this loss.
[$] An operations structure for swap devices
One of the ideas raised at the 2026 LinuxStorage, Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) wasthe creation of anoperations structure for the swap subsystem. Like many parts of thekernel, the swap layer evolved over time, with pieces being added asneeded; the end result of this evolution is rarely what one would expecthad the subsystem been designed today. The interface between the swaplayer and the devices it uses is just one example. It appears that oneresult of the swap subsystem's evolution - the lack of an abstraction layerto interface with underlying storage - will soon be addressed, but in adifferent way than was initially envisioned.
Codeberg: Protecting our FLOSS commons from LLMs
The Codeberg forge has adopted a pair of new policies, promising not to usehosted projects to train LLMs and, more controversially, banning thehosting of LLM-generated software. The site's blog describesand justifies these policies.
Security updates for Thursday
Security updates have been issued by AlmaLinux (acl, dogtag-pki, dovecot, glibc, go-toolset:rhel8, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd:2.4, javapackages-tools:201801, libtiff, mariadb-connector-c, perl-HTTP-Daemon, pki-deps:10.6, and sssd), Debian (bind9, chromium, firefox-esr, and pdns-recursor), Fedora (chromium, collectl, fractal, kernel, libssh, llvm, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, perl-DBI, perl-YAML-Syck, and srt), SUSE (7zip, GraphicsMagick, ImageMagick, multipath-tools, perl-YAML, python-sqlparse, python3-sqlparse, python313-bleach, and sssd), and Ubuntu (apache2, commons-beanutils, exim4, gawk, giflib, gst-plugins-good1.0, krb5, libapache-mod-jk, libarchive, libgphoto2, libhtml-parser-perl, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-ibm, linux-nvidia, linux-fips, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-ibm, linux-oracle, linux-ibm-5.15, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oem-6.17, linux-oracle-6.8, python-aiohttp, and tar).
[$] LWN.net Weekly Edition for July 23, 2026
Inside this week's LWN.net Weekly Edition:
[$] Save and restore may be coming to GNOME
One of the features that users often miss when moving from X11 to Wayland isthe ability to save and restore the position of windows between sessions. At GUADEC2026, held inACoruna, Spain, Adrian Vovk provided an overview of work that has goneinto providing a platform-wide save and restore framework for GNOME. After twofailed attempts at landing an API, he believes that the third try will be theone to succeed-though not in time for the upcoming GNOME51 releasedue in October.
PyPI now rejects new files after 14 days
Python Software Foundation security developer-in-residence SethLarson has announcedthat the Python Package Index (PyPI) will now reject new files thatare uploaded to releases older than 14 days. The restriction is toprevent the poisoning of old releases if publishing tokens orworkflows of PyPI projects are compromised.
[$] Attaching programs to multiple tracepoints
Tracepoints in the kernel are useful for a variety of purposes: debugging,active monitoring, and performance measurements, among other things. Previously,any given BPF program could only be attached to a single tracepoint.Jiri Olsa has been working to change that, and led a discussion abouthis progress at the 2026Linux Storage, Filesystem, Memory-Management, and BPFSummit. That work has since beenmerged, and can be expected as part of the 7.2kernel.
Security updates for Wednesday
Security updates have been issued by AlmaLinux (389-ds-base, c-ares, dovecot, freerdp, glib2, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, kernel, kernel-rt, nodejs:22, perl-XML-LibXML, webkit2gtk3, and yggdrasil), Debian (kernel, nss, roundcube, rtpengine, and xz-utils), Fedora (btrbk, kernel, mupdf, nuclei, perl-Crypt-OpenSSL-X509, rust-fern, rust-ifcfg-devname, rust-routinator, rust-rpki, and rust-syslog), Mageia (tig), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, acl, dovecot, glib2, httpd, libtiff, pacemaker, perl-IO-Compress, plexus-utils, python3, and webkit2gtk3), Slackware (libssh and mozilla-firefox), SUSE (acl, avahi, aws-nitro-enclaves-cli, beets, chromium, firefox, go1.25-openssl, ImageMagick, iscsiuio, kernel, kubevirt1.8-container-disk, libgit2-1_9, libkrun, libsoup-3_0-0, nghttp2, opam, php7, python-aiohttp, python-tornado6, and vim), and Ubuntu (accountsservice, CUPS, imagemagick, jbig2dec, openssh, and snapd).
Firefox 153 released
Version153.0 of the Firefox web browser has been released. Notablechanges in this release include a change to the defaultlocal-file-access permissions for extensions, enabling LANrestrictions by default for all users, a visual indicator when a website has access to the user's location, the ability to merge PDFs andadd images as pages within PDFs, as well as experimental support forthe JPEG XL image format.See thereleasenotes for developers for all changes that affect web developers,and securityadvisories for vulnerabilities fixed in this release.
[$] Debating the role of large language models in the kernel community
Like many development communities, the kernel community has been strugglingto determine how large language models will be used in its developmentprocess. The news has been dominated recently by a strongly worded missivefrom Linus Torvalds on the subject, but the discussion has been rather morewide-ranging and nuanced than that. Topics that have been consideredrecently include the LLM attribution requirement, code-review tools,dependence on proprietary tools, and whether there is a place for concernsabout the ethics of LLMs.
Security updates for Tuesday
Security updates have been issued by AlmaLinux (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), Debian (samba), Fedora (c-ares, dnsx, freerdp, gpsd, libreswan, libseccomp, libtiff, mingw-python-idna, mingw-python-pip, openssh, python-pillow, wget1, and wireshark), Mageia (golang, graphicsmagick, haveged, libssh2, nginx, nilfs-utils, perl-CGI-Session, perl-Imager, perl-JavaScript-Minifier-XS, php, php8.4, php8.5, python-nltk, sqlite3, and xmlstarlet), Oracle (.NET 10.0, .NET 9.0, container-tools:ol8, firefox, giflib, glibc, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, hplip, httpd, image-builder, kernel, libtiff, mod_http2, pacemaker, perl-DBI:1.641, perl-HTTP-Daemon, php:8.2, python-markdown, ruby4.0, systemd, and thunderbird), Red Hat (buildah, container-tools:rhel8, dracut, golang-github-openprinting-ipp-usb, libtiff, osbuild-composer, python-urllib3, python3.12-urllib3, python3.14-urllib3, and runc), SUSE (389-ds, chromedriver, gstreamer-plugins-bad, libreoffice, libsuricata8_0_6, podman, python311, and sssd), and Ubuntu (apache2, freerdp3, freetype, libde265, libxfont, linux, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-realtime, linux-realtime-6.8, linux, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-gcp, linux-gke, linux-realtime, linux-gcp-6.17, linux-realtime-6.17, linux-gcp-fips, linux-hwe-7.0, linux-nvidia-tegra-5.15, linux-oem-7.0, nginx, php8.1, php8.3, php8.5, rlottie, sqlite3, and wget).
[$] Fedora grapples with change
The Fedora Project is known for,among other things, having a well-defined set of processes for just abouteverything. It has extensive packagingguidelines that deal with the complexities of creating RPMs to installsoftware, as well as processes for managing the legal questions thatarise around shipping software. Fedora also has a well-defined changeprocess for dealing with self-contained technical changes as well as majorchanges to the distribution, and other issues as they arise. At the moment,though, the project seems to be experiencing a sort of midlife crisis as itre-examines several of its change processes at once to determine if they arestill effective.
Catanzaro: Some changes to GNOME security tracking
Michael Catanzaro, who has been managing GNOME security issue tracking sinceNovember 2020, has written a blog post that details some changes in how he willbe managing GNOME vulnerability reports from now on due to an increase inAI-generated security reports. He will be switching from a 90-day deadline fordisclosures to 30 days for issues reported on August1, or later. "Theshorter deadline would probably work better for GNOME even if not for theincrease in AI-generated issue reports."He also has indicated that he will be stepping away from the task of managingsecurity issue tracking entirely by December 1, 2026, which means that therewill be a gap to fill:
[$] Merging famfs?
The famfs filesystem, which is meant to provide shared access to hugememory-resident files on CXL and otherdevices, returned tothe Linux Storage,Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) in 2026.It was first discussed at LSFMM+BPF 2024 and a new implementation was described at the 2025gathering, but it still has not made its way into the kernel; LWN lookedat a discussion about merging famfs back in April 2026.
Security updates for Monday
Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), Mageia (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-HTML-Parser, perl-Mojolicious, perl-String-Util, python-pydantic-settings, rsync, and upower), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind, cockpit, cockpit-image-builder, coreutils, delve, dnsmasq, dovecot, expat, fence-agents, flatpak, frr, gdk-pixbuf2, giflib, glib2, go-fdo-client and go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd, jq, kernel, keylime, krb5, libcap, libexif, libpng, libsndfile, libsolv, libsoup3, libtasn1, libtiff, libxslt, libyang, mariadb10.11, mod_http2, mod_md, opencryptoki, PackageKit, perl-Archive-Tar, perl-IO-Compress, poppler, postfix, postgresql-jdbc, python-urllib3, python3.14, python3.14-pip, python3.14-urllib3, qt6-qtdeclarative, rrdtool, rsync, ruby, ruby4.0, samba, skopeo, thunderbird, valkey, wireshark, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), and SUSE (blender, chromium, containerized-data-importer1, cyrus-imapd, go1.26-openssl, gomuks, grafana, gstreamer-plugins-bad, kbfs, kubevirt1.8-container-disk, libxml2, lux, mariadb-connector-c, nginx, opam, openssl-3, oras, perl-DBI, php-composer2, python-django-haystack, python-paramiko, python-weasyprint, python311, python313-Pillow, python315, shibboleth-sp, system-user-zabbix, and wget).
Kernel prepatch 7.2-rc4
The 7.2-rc4 kernel prepatch is out fortesting. Linus said: "This whole week I had the feeling that peoplewere starting to go on summer vacation, but running the numbers shows thatI must have been wrong - it all looks pretty normal."
"Half a Second" — a book on the XZ backdoor
Adrian Mastronardi has released a book called Half a Second; it is adetailed look into the XZ backdoor attemptof 2024. The book is freely available under a (non-free) noncommercial,no-derivatives CC license.
12345678910...