|
Wed, 05 Aug 2026 17:24:28 +0000 |
|
Konstantin Ryabitsev has announced the release of version 0.16.0 of the b4
software-development tool. The biggest change is the addition of
bug-tracking support:
The new "b4 bugs" command integrates with git-bug to let you track
bug reports alongside your git repository. Bugs are stored as git
objects inside the repo, so they travel with the code and can be
shared via git push/pull without any external service.
There are also a lot of improvements to b4 review (which was covered
here in March), better conflict resolution in b4 shazam,
improved history rewriting, and more.
|
|
Wed, 05 Aug 2026 16:59:26 +0000 |
|
Jordan Rife's work involves writing BPF programs for
Cilium that interface with
Kubernetes
networking. As part of that work, he wants to enable BPF programs with
appropriate permissions to iterate through the sockets of a different network
namespace. He led a session about the idea at the 2026
Linux Storage,
Filesystem, Memory-Management, and BPF Summit where the BPF developers in
attendance were quick to suggest a number of related alternatives.
|
|
Wed, 05 Aug 2026 15:59:08 +0000 |
|
|
|
Wed, 05 Aug 2026 13:43:00 +0000 |
|
Jynn Nelson describes
the Rust language team's new LLM policy on the Inside Rust blog.
No one except the author is required to read LLM output unless they
choose to: LLM output isn't allowed in public docs, PR
descriptions, or Github comments unless it's clearly marked;
reviewers aren't required to look at LLM PRs if they don't want to.
No one is required to use LLMs to contribute to rust-lang/rust:
policies must be written first for humans, and only summarized for
machines; LLM reviews cannot substitute for human review or
self-review.
You are allowed to generate LLM content that only you see, without
disclosure, as long as you do not post it anywhere that you expect
us to read or review.
|
|
Wed, 05 Aug 2026 13:10:40 +0000 |
|
Security updates have been issued by AlmaLinux (fence-agents, gstreamer1-plugins-good, kernel, kernel-rt, p11-kit, perl-Archive-Tar, perl-DBI, and thunderbird), Debian (aom, botan3, and kernel), Fedora (abrt, coreutils, doctl, kernel, open62541, perl, perl-Devel-Cover, perl-PAR-Packer, and polymake), Mageia (acl and php), Oracle (firefox, frr, kernel, libreswan, nodejs-nodemon, nodejs22, perl-Archive-Tar, php:7.4, php:8.2, rsync, and thunderbird), Red Hat (compat-libtiff3, libpq, libtiff, postgresql, postgresql16, postgresql18, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and postgresql:18), Slackware (stunnel), and SUSE (alloy, alsa, bind, chromedriver, corepack24, ffmpeg-4, golang-github-prometheus-prometheus, google-guest-agent, google-osconfig-agent, kubevirt, libgcrypt, libpng16, multipath-tools, netty, netty-tcnative, nodejs26, openssl-1_1, openssl-3, perl-HTTP-Tiny, perl-YAML-Syck, podman, python-sh, python-ujson, rsyslog, spice-vdagent, thrift, valkey, wpa_supplicant, and xen).
|
|
Tue, 04 Aug 2026 23:04:32 +0000 |
|
The AI Security Institute has released a
detailed report on an security incident of its own making. The
Institute set some LLM agents loose on the Internet with a security
challenge; soon they were creating malware-laden pull requests and
sock-puppet accounts to promote them.
The agent opened a malicious pull request (PR) to ⟨REPO_A⟩ and
pursued a number of strategies to get it merged:
- Repeatedly commented on the PR with sockpuppet accounts to manufacture
consensus and pressure the maintainer into approving with minimal
review.
- Opened a GitHub Issue in another repository (also owned by ⟨PERSON_A⟩)
containing a prompt injection for other coding agents. The malicious
instructions were addressed to issue-triage AI coding agents and
invisible to humans viewing the website.
- Sent multiple emails to ⟨PERSON_A⟩ and ⟨PERSON_B⟩, with different
pretexts to get them to run malicious code. Over the course of the
sample, the agent sent five emails, some containing malware, others
aimed at persuading a maintainer to accept the pull request.
It would be surprising if this were the only incident of this type; the
only real difference here is that the people involved are documenting what
happened.
|
|
Tue, 04 Aug 2026 16:43:25 +0000 |
|
The Fedora
Council is considering
a conflict-of-interest (COI) policy for its decision-making bodies,
such as the Fedora Engineering
Steering Committee (FESCo), special-interest groups (SIGs), and
any other groups or individuals that report to the council and
are responsible for decisions that impact the Fedora project. The
current draft does not, however, apply to the council itself. The public
discussion for the COI policy began on July 23 and seems to be
nearing completion, with the council set to discuss the topic again
during its meeting on August 13.
|
|
Tue, 04 Aug 2026 14:54:05 +0000 |
|
StepSecurity is
reporting the emergence of a new worm affecting npm packages.
The design of the worm is nothing new, but the rapidity with which it is
exploiting captured npm
packager credentials is noteworthy.
TL;DR: A self-propagating worm, which we are calling ChainDrop, is spreading rapidly through the npm ecosystem. So far 435 packages and more than 1,550 compromised versions have been flagged, starting with keyv@6.0.0. If you are using any of the packages listed below, assume your environment is compromised. We are still investigating the full scope; check back on this post for updates.
|
|
Tue, 04 Aug 2026 13:27:51 +0000 |
|
The recent discussion on "spawn templates"
raised questions about whether it was time to provide an alternative to the
classic Unix fork()/exec() pattern for process creation.
One idea that was raised there was to shift the template pattern into an
interface that could be used to efficiently assemble new processes from
bare cloth, without duplicating the parent process. Preferably, that
interface would be able to implement posix_spawn().
Li Chen, the author of the spawn-template work, has now responded with a patch series
(written with significant LLM assistance) showing what a process-builder
API for Linux might look like.
|
|
Tue, 04 Aug 2026 13:07:52 +0000 |
|
Security updates have been issued by AlmaLinux (frr, ldns, mingw-glib2, and perl-Archive-Tar), Debian (ruby2.7), Fedora (borgbackup, nebula, python-nh3, rust-ammonia, and seamonkey), Mageia (librabbitmq, libvncserver, packages, perl, perl-GD, perl-Unicode-LineBreak, squid, and unbound), Oracle (compat-libtiff3, frr, gstreamer1-plugins-good, javapackages-tools:201801, libreswan, nodejs:22, nodejs:24, p11-kit, perl-Archive-Tar, perl-DBI, php, pki-deps:10.6, and python-tornado), and SUSE (aws-iam-authenticator, bind, containerd, gawk, google-cloud-sap-agent, ignition, ImageMagick, java-11-openjdk, libpng16, libssh, mcphost, nginx, openssh, openssl-1_1, perl-DBI, perl-HTTP-Date, perl-Net-DNS, python-urwid, python3-dulwich, python312, python313, python3, python313-pydantic, python313-sentry-sdk, rrdtool, s390-tools, samba, spice-vdagent, vim, and xen).
|
|
Mon, 03 Aug 2026 21:18:31 +0000 |
|
John MacFarlane has published a lengthy
retrospective to commemorate twenty years of the Pandoc document converter.
On August 3, 2006, I uploaded the first version of pandoc to my
website, releasing it under the free GPL license. Pandoc 0.1 consisted
of about 3000 lines of Haskell code, with no dependencies aside from
GHC's standard library. It could convert Markdown, reStructuredText,
HTML, and LaTeX documents into any of these formats, plus RTF or S5. I
had no idea at the time that this would just be the first of over two
hundred releases over the next twenty years; that the project would
become the most
popular program written in Haskell; that I would spend countless
hours on bug-fixes, improvement, and project management; that I would
collaborate with programmers in many other countries; that pandoc
would come to support over fifty document formats; that it would allow
automatic generation of citations and bibliographies; that it would
become integrated into academic writing tools like Quarto and Jupyter Notebook; that it would be
installed on millions of computers around the world.
How did this happen? I want to take advantage of pandoc's birthday
to tell the story of the project, as best I can remember it.
|
|
Mon, 03 Aug 2026 18:15:59 +0000 |
|
For those of us with a long memory: John Goerzen has announced
the release of C-Kermit 11, the first release of this file-transfer
utility in 15 years.
As Debian maintainer of Kermit, I noticed some areas where it
wasn't matching modern expectations. One area was, not surprising
for a project of its age, security. Another area was that its
character set or line-ending conversions are usually not desired
now; we are used to byte-identical binary transfers, and the
defaults caused confusion and even some rare instances of data
corruption. So I started making a few patches last year.
See the
changelog for details on the work that has been done.
Most of us probably haven't thought about C-Kermit in years (if ever), but
there was a time when it was an essential tool for moving files between
machines.
|
|
Mon, 03 Aug 2026 16:05:10 +0000 |
|
The Filesystem in
Userspace (FUSE) subsystem provides a way to service filesystem
requests from a user-space server, which moves the format-handling code out
of the kernel. The FUSE server can use the io_uring
facility for better performance, but Bernd Schubert is concerned that
memory is being wasted because the current implementation has a single,
large buffer size that is excessive for small I/O operations. He led a discussion on that topic
in the filesystem track of the 2026 Linux Storage,
Filesystem, Memory Management, and BPF Summit in Zagreb, Croatia.
|
|
Mon, 03 Aug 2026 14:59:31 +0000 |
|
The JFrog blog examines
some reported vulnerabilities in SQLite, some of which made their way
into high-profile vulnerability databases, that turned out to be entirely
fabricated by LLMs.
These LLM slop CVEs can cause organizations to waste time
investigating and patching vulnerabilities that do not actually
exist, as well as polluting vulnerability databases. In
environments where Critical vulnerabilities are automatically
prioritized or tickets are opened based on vulnerability scores,
such fabricated CVEs can turn into a real burden.
In environments where AI is used to automate vulnerability triage
and remediation this becomes even more concerning. An AI agent that
encounters a fabricated CVE may attempt to locate the vulnerable
function, generate a patch, or recommend changes based on code that
does not even exist. Instead of helping security teams remediate
real vulnerabilities, it can lead them down a completely wrong
path, potentially introducing unnecessary changes and wasting time.
|
|
Mon, 03 Aug 2026 13:42:58 +0000 |
|
Greg Kroah-Hartman has announced the release of the 7.1.6, 6.18.42, 6.12.101, and 6.6.148 stable kernels. Each contains
hundreds of patches—the 7.1.6 kernel has more than
700—with fixes throughout the tree. Users are advised to
upgrade.
|