|
Fri, 11 Sep 2026 15:08:45 +0000 |
|
All of the videos from the EuroPython 2026 conference, held
in Kraków from July 13 through July 19, are now
online along with a recap of
the event from conference organizers.
|
|
Fri, 11 Sep 2026 14:15:32 +0000 |
|
Kernel developers do a lot of kernel builds. Since the kernel is not a
small program, those builds can take a fair amount of time, even on a fast
machine. The kernel also has a complex build system; it is probably fair
to say that few developers truly understand it, and fewer still are willing
to try to improve it. Lorenzo Stoakes, armed with LLM-based assistance,
decided to give it a try, though, and has managed to reduce the time it
takes to build a kernel — and not by a small amount.
|
|
Fri, 11 Sep 2026 13:27:35 +0000 |
|
Greg Kroah-Hartman has announced the release of the 7.2.5 and 6.18.51
stable kernels. There are more than 550 patches in each with fixes throughout
the tree; users are advised to upgrade.
|
|
Fri, 11 Sep 2026 13:14:32 +0000 |
|
Security updates have been issued by AlmaLinux (apr-util and qt6-qt5compat), Debian (libevent and ruby-rack), Fedora (bluez, corosync, curl, dokuwiki, grpcurl, libevent, and rest), Oracle (gstreamer1-plugins-bad-free, perl-DBI, python-urllib3, qt5-qtbase, qt6-qt5compat, and thunderbird), Red Hat (osbuild-composer), SUSE (azure-storage-azcopy, chromedriver, corosync, ggml-devel, helm, kernel, libmariadb-devel, libzypp, zypper, opensc, php7, tomcat10, and waylyrics), and Ubuntu (apache2, beets, glibc, kissfft, libebml, linux-nvidia-6.17, php8.1, php8.3, php8.5, and python2.7, python3.4, python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.14).
|
|
Thu, 10 Sep 2026 20:05:50 +0000 |
|
The Forgejo software-forge project has announced the
release of versions 16.0.4
and 15.0.8,
which fixes two security vulnerabilities. One is a critical flaw that would
allow remote-code execution (RCE):
When generating a new repository from a template repository, Forgejo clones the
template repository, removes the .git folder, performs variable template
expansion on files listed in .forgejo/template, and initializes a new git
repository. During this process, variable template expansion could be misused in
order to create a new .git folder, which git would adopt and incorporate during
its initialization of a new git repository. A malicious template repository
could be used to read arbitrary data from the Forgejo host, and to execute
arbitrary processes on the Forgejo host, as a remote code execution attack. To
address this issue, after variable expansion is completed, any existing .git
folder is removed from the directory before the git repository is initialized.
The project recommends upgrading to the latest version as soon as
possible.
|
|
Thu, 10 Sep 2026 17:29:06 +0000 |
|
PostgreSQL 19 was
expected to be released in September, in keeping with the database
project's longstanding tradition of a major release every year. However,
some late-breaking concerns about several of the features slated for inclusion
has some developers worried about the quality of the release. On August 25, PostgreSQL
contributor Robert Haas sent
an email with the subject "scary patch contest " about several patches
that have required an unusually large number of bug fixes leading up to the
release, which has raised questions about their readiness for a stable
release. One of the patches has been reverted, but several are still under heavy
revision, and an extra beta release has been slotted in to allow for additional
testing.
|
|
Thu, 10 Sep 2026 13:23:50 +0000 |
|
|
|
Thu, 10 Sep 2026 13:14:35 +0000 |
|
Security updates have been issued by AlmaLinux (389-ds-base, ansible-core, buildah, expat, glib2, gpsd, gpsd-minimal, gzip, kernel, kernel-rt, opentelemetry-collector, osbuild-composer, perl-DBI, python-lxml, python3.12-lxml, qt5-qtbase, thunderbird, valkey, vim, and xz), Debian (pyasn1), Fedora (darktable, freeipa, freerdp2, gdk-pixbuf2, GitPython, libsoup3, openssl, perl-Net-DNS, rust-ppmd-rust, samba, and valkey), Mageia (ceph, firefox, nss, perl-DBI, thunderbird, and wget), Oracle (389-ds-base, buildah, expat, git-lfs, glib2, glibc, gpsd, gpsd-minimal, grafana-pcp, kernel, libssh, nginx, perl-GD, python3.14-cryptography, redis:7, skopeo, thunderbird, valkey, xmlrpc-c, and xz), Slackware (xz), SUSE (bzip2, cpio, curl, dracut, fuse-overlayfs, golang-github-vpenso-prometheus_slurm_exporter, helm, java-1_8_0-ibm, kbfs, kernel, kernel-devel, libopenslide-devel, libsoup, libssh2_org, libusb-1_0, libvirt, libzypp, zypper, mcphost, multipath-tools, NetworkManager, opensc, openssl-3, perl-Net-DNS, python-aiohttp, python-Authlib, python-pip, python-sqlparse, python313-dnspython, python313-idna, rpcbind, sssd, strongswan, systemd, tomcat11, ucode-intel, and wget), and Ubuntu (dotnet8, dotnet10, ffmpeg, flatpak, netty, and perl).
|
|
Thu, 10 Sep 2026 01:43:03 +0000 |
|
Inside this week's LWN.net Weekly Edition:
- Front: Rust's never type; Debian and CERN; memory tiering; testing multithreaded Python; fixing TCMalloc; Typst.
- Briefs: Rustls; Asahi Linux; Buildroot 2026.08; Grml 2026.09; Audacity 4.0; Jellyfin 12.0; LibreOffice Base; Quotes; ...
- Announcements: Newsletters, conferences, security updates, patches, and more.
|
|
Wed, 09 Sep 2026 18:11:54 +0000 |
|
Joe Birr-Pixton has written a blog post
reflecting on a decade of the Rustls TLS-library project and looking ahead to
the upcoming 0.24 release and an eventual 1.0 release.
Rustls began with a
first commit on May 2, 2016. Progress was quick: a month later, on June 5,
it could interoperate with most sites on the web. The first release, 0.1.0,
followed on August 27, 2016 – less than four months after the first commit.
[...] From the 0.1.0 release, the project moved through a long series of
releases over the following eight years, building out functionality, hardening
and refining the API. That sequence of release lines culminated in 0.23,
released on February 29, 2024.
The 0.23 release line has been a stable one: in the time since, it has
seen 43 non-breaking releases. That stability didn't come with
stagnation. The 0.23 line delivered a wide range of important features,
including a FIPS-certified cryptography option, certificate compression,
Encrypted ClientHello, post-quantum cryptography, and performance
improvements.
|
|
Wed, 09 Sep 2026 17:07:42 +0000 |
|
Heiko Tietze has published
a blog post summarizing the results of a recent
survey about the use of LibreOffice's database application, Base. 455 people
participated in the survey, including more than 330 who use Base on Linux, with
use cases ranging from maintaining records of personal media such as CDs or DVDs
to use enterprise-resource planning (ERP) and finance. Of course, users had many
ideas how to improve the application:
The majority asks for improvements to the user interface with less
clutter and a more attractive design. The workflow and user experience should
become either simplified or more powerful, depending on the expertise and the
scenario. For example, an elaborate search function is something that
many people expect. [...]
Almost the same number of answers requests bug fixes, improvements to
stability, and better performance. Issues with queries, forms, and reports were
mentioned equally often. In this regard, many replies suggest to remove the Java
dependencies.
|
|
Wed, 09 Sep 2026 15:37:55 +0000 |
|
Typst is a system for typesetting documents
into various formats: PDF, SVG, PNG, and, in progress, HTML. It is adept at
handling technical material, and is often considered to be an eventual LaTeX replacement. We last looked
in on Typst a year ago, when it had reached version 0.13. A new version,
0.15, was released in
June with lots of new features, including support for variable fonts,
MathML, multiple bibliographies, and more. Typst is free, Apache-2.0-licensed software, programmed in Rust.
|
|
Wed, 09 Sep 2026 13:04:46 +0000 |
|
Security updates have been issued by AlmaLinux (expat, glib2, microcode_ctl, mrtg, pam, redis, thunderbird, and valkey), Debian (fort-validator, gst-plugins-base1.0, kernel, and slurm-wlm), Fedora (complyctl, libevent, openvpn, and tar), Mageia (dovecot and spice-vdagent), Red Hat (ignition, opentelemetry-collector, and osbuild-composer), SUSE (amazon-ssm-agent, aws-nitro-enclaves-cli, bzip2, cadvisor, chromium, curl, distribution-registry, emacs, freeciv, fuse-overlayfs, gh, google-guest-agent, GraphicsMagick, hauler, insighttoolkit-devel, java-17-openjdk, libidn, libusb-1_0, libvirt, libvncserver, libzypp, zypper, lkl, lxd, multipath-tools, NetworkManager, perl-Net-DNS, perl-URI, python, python-authlib, python-sqlparse, python-tornado, python3, rpcbind, supergfxctl, systemd, terraform-provider-null, ucode-intel, wget, wireshark, and xen), and Ubuntu (curl, ffmpeg, glibc, hsqldb1.8.0, imagemagick, perl, and vim).
|
|
Tue, 08 Sep 2026 13:34:38 +0000 |
|
A function's return type is supposed to indicate the kind of data that it
produces.
Rust's "never" type, which is
denoted by an exclamation mark ("!"), is the type the language uses to mark
a function that never returns and other places where a value can never occur. For
a long time, the never type was used internally by the compiler, but was
considered an unstable feature. On
August 24, after more than two years of work,
Rust-compiler-contributor "waffle" finally managed to stabilize the type. It
took so long, in part, because it involved a small breaking
change to previous Rust editions, which the compiler maintainers needed to
ensure did not impact much real code.
|
|
Tue, 08 Sep 2026 13:20:02 +0000 |
|
|