Linux Weekly News

Tartalom átvétel
LWN.net is a comprehensive source of news and opinions from and about the Linux community. This is the main LWN.net feed, listing all articles which are posted to the site front page.
Frissült: 22 perc 56 másodperc

Garrett: Self-signing custom Android ROMs

h, 2014-07-07 14:07
Matthew Garrett explains how to get an Android device to refuse to boot an operating system that has not been signed by the device's owner. "It's annoying and involves a bunch of manual processes and you'll need to re-sign every update yourself. But it is possible to configure Nexus devices in such a way that you retain the same level of security you had when you were using the Google keys without losing the freedom to run whatever you want."
Kategóriák: Linux

Kernel prepatch 3.16-rc4

h, 2014-07-07 04:24
Linus has released the 3.16-rc4 prepatch. "Things have calmed down nicely, and everything seems pretty normal."
Kategóriák: Linux

Gräßlin: Next Generation Klipper

szo, 2014-07-05 00:09
On his blog, Martin Gräßlin examines Klipper, the KDE clipboard manager, with an eye toward how it should work for Plasma 5.1. "A clipboard history is of course an important part of a desktop shell and thus should be a first class citizen. The user interface needs to be integrate and this means the interface needs to be provided by a Plasmoid which needs to be added to the notification area. The interface would still show a list and this is best done by providing the data in the form of a QAbstractItemModel. As there should only be one clipboard history manager, but at the same time perhaps several user interfaces for it (e.g. one panel per screen) the QAbstractItemModel holding the data needs to be provided by a DataEngine. So overall we need to separate the user interface (Plasmoid) from the data storage (DataEngine) and turn the existing Klipper in just being the data storage."
Kategóriák: Linux

Interview: Damian Conway (Linux Voice)

p, 2014-07-04 21:49
Linux Voice magazine has an interview with Damian Conway, one of the chief architects of Perl 6. In it, he talks about Perl 6 a bit (of course), but also about Perl, in general, as well as about teaching and learning programming. "Anyone who believes you can teach programming in an hour has no idea about what programming is. I think that I finally thought that I was a confident programmer maybe about four or five years ago, so after about a quarter of a century of coding. I felt that I was an ordinary good programmer by that stage. I don’t think you can even teach HTML in an hour, to be brutally honest."
Kategóriák: Linux

Friday's security advisories

p, 2014-07-04 16:43

Fedora has updated apt-cacher-ng (F20: cross-site scripting) and xen (F20; F19: information leak).

SUSE has updated php5 (SLE11SP2: two vulnerabilities) and php53 (SLE11SP2, SLE11SP3: multiple vulnerabilities).

Kategóriák: Linux

The CHERI capability model: Revisiting RISC in an age of risk (Light Blue Touchpaper)

p, 2014-07-04 00:24
Over at the Light Blue Touchpaper blog, there is a summary of a paper [PDF] presented in late June at the 2014 International Symposium on Computer Architecture about Capability Hardware Enhanced RISC Instructions (CHERI). "CHERI is an instruction-set extension, prototyped via an FPGA-based soft processor core named BERI, that integrates a capability-system model with a conventional memory-management unit (MMU)-based pipeline. Unlike conventional OS-facing MMU-based protection, the CHERI protection and security models are aimed at compilers and applications. CHERI provides efficient, robust, compiler-driven, hardware-supported, and fine-grained memory protection and software compartmentalisation (sandboxing) within, rather than between, addresses spaces. We run a version of FreeBSD that has been adapted to support the hardware capability model (CheriBSD) compiled with a CHERI-aware Clang/LLVM that supports C pointer integrity, bounds checking, and capability-based protection and delegation. CheriBSD also supports a higher-level hardware-software security model permitting sandboxing of application components within an address space based on capabilities and a Call/Return mechanism supporting mutual distrust."
Kategóriák: Linux

Python Foundation uncoils as membership opens up (Opensource.com)

p, 2014-07-04 00:15
Opensource.com has an interview with Nick Coghlan, who is a newly elected Python Software Foundation (PSF) board member. In the interview, Coghlan discusses the new open membership model for the PSF, what makes Python special, how the huge investment in OpenStack is having an impact on CPython core development, and a look at the future for both Python and the PSF. "For me, the most fascinating thing about Python is the sheer breadth of the domains it competes in. In the projects I worked on at Boeing, Python became our "go to" glue language for getting different parts of a complex system to play nicely together, as well for writing simulation tools for testing environments. Linux distributions tend to use it in a similar fashion. In the scientific space it goes head to head with the likes of MATLAB for numeric computing, and R for statistical analysis. It was the original implementation language for YouTube, and the language of choice for OpenStack components, yet still simple enough to be chosen as the preferred programming language for the Raspberry Pi and One Laptop Per Child educational programs. With the likes of Maya and Blender using it as their embedded scripting engine, animation studios love it because animators can learn to handle tasks that previously had to be handled by the studios' development teams. That diversity of use cases can make things fraught at times, especially in core development where the competing interests can often collide, but it's also a tremendous strength."
Kategóriák: Linux

3.14 to be the next longterm stable kernel

cs, 2014-07-03 23:10
Greg Kroah-Hartman has announced that 3.14 will be the next longterm stable kernel that he will be maintaining. It should continue to receive updates until August 2016.
Kategóriák: Linux

Schneier: NSA Targets Privacy Conscious for Surveillance

cs, 2014-07-03 19:47
Bruce Schneier has a good summary of recently reported information about the US National Security Agency (NSA) targeting of users searching for or reading information about Tor and The Amnesic Incognito Live System (Tails), which certainly could include readers of this site. "Jake Appelbaum et. al, are reporting on XKEYSCORE selection rules that target users -- and people who just visit the websites of -- Tor, Tails, and other sites. This isn't just metadata; this is "full take" content that's stored forever. [...] It's hard to tell how extensive this is. It's possible that anyone who clicked on this link -- with the embedded torproject.org URL above -- is currently being monitored by the NSA. It's possible that this only will happen to people who receive the link in e-mail, which will mean every Crypto-Gram subscriber in a couple of weeks. And I don't know what else the NSA harvests about people who it selects in this manner. Whatever the case, this is very disturbing." Also see reports in Linux Journal (which was specifically noted in the XKeyscore rules) and Boing Boing.
Kategóriák: Linux

OpenSSL speeds up development to avoid being “slow-moving and insular” (Ars Technica)

cs, 2014-07-03 18:49
Ars Technica reports on the OpenSSL project's new roadmap that describes a number of problems with the project and its code along with plans to address them. "The project has numerous problems, the roadmap says. These include a backlog of bug reports, incomplete and incorrect documentation, code complexity that causes maintenance problems, inconsistent coding style, a lack of code review, and having no clear release plan, platform strategy, or security strategy. The plan is to fix all these problems. For example, bug reports should receive 'an initial response within four working days.' That goal can be met now, the roadmap says, but others will take longer. Defining a clear coding standard for the project is expected to take about three months. 'Review[ing] and revis[ing] the public API with a view to reducing complexity' will take about a year."
Kategóriák: Linux

Schaller: Wayland in Fedora update

cs, 2014-07-03 17:13
Christian Schaller has posted an update on Fedora's transition to the Wayland display manager. "So the summary is that while we expect to have a version of Wayland in Fedora Workstation 21 that will be able to run a fully functional desktop, there are some missing pieces we now know that will not make it. Which means that since we want to ship at least one Fedora release with a feature complete Wayland as an option before making it default, that means that Fedora Workstation 23 is the earliest Wayland can be the default."
Kategóriák: Linux

Security updates for Thursday

cs, 2014-07-03 16:22

Debian has updated dbus (three denial of service flaws).

Fedora has updated libreoffice (F19: code execution), lzo (F20: denial of service/possible code execution), and seamonkey (F20; F19: multiple vulnerabilities).

openSUSE has updated gpg2 (13.1, 12.3: denial of service) and memcached (13.1, 12.3: multiple vulnerabilities, one from 2011).

Ubuntu has updated nspr (code execution).

Kategóriák: Linux

[$] LWN.net Weekly Edition for July 3, 2014

cs, 2014-07-03 02:35
The LWN.net Weekly Edition for July 3, 2014 is available.
Kategóriák: Linux

Where KDE is going - Part 2 (KDE.news)

sze, 2014-07-02 19:45
Jos Poortvliet continues his coverage of the KDE community's present and future. This segment looks at KDE governance and the role of KDE e.V. and the Community Working Group. "In the last 8 years or so, KDE e.V. has been the major driver behind increasing the number of developer sprints and has created the Fiduciary Licensing Agreement which allows it to re-license KDE code when needed, while protecting developers’ interests. The Code of Conduct originated with KDE e.V., as did our Community Working Group which helps deal with communication issues in the community."
Kategóriák: Linux

Wednesday's security advisory

sze, 2014-07-02 17:53
Today's lone security advisory is from Red Hat for tomcat (RHEL7: multiple vulnerabilities).
Kategóriák: Linux

[$] Control groups, part 1: On the history of process grouping

k, 2014-07-01 20:13
LWN is proud to launch an extended series of articles on control groups by guest author Neil Brown. Neil starts off by saying: "As synthesizing a deep understanding is, I find, much more noble than synthesizing a personal agenda, and as having a discerning audience is an excellent motivation for thorough research, these articles are intended to help me and, hopefully, other readers to develop the deep understanding necessary to truly enjoy an informed debate on Linux control groups." The first installment looks at the distant history of process grouping; click below (subscribers only) for the full text.
Kategóriák: Linux

Nelson: The new 501(c)(3) and the future of free software in the United States

k, 2014-07-01 19:44
Jim Nelson looks at why the Yorba Foundation was denied 501(c)(3) tax-exempt status, and what that means for other free software projects. "Last year there was a bit of a dust-up—a scandal to some, a distraction to others, depending on their politics—when many right-wing nonprofit organizations in the United States began complaining they were being unfairly targeted by the IRS. Media inquiries determined IRS examiners were given “BOLOs” (Be On The Lookout) for certain keywords in 501(c) applications, including “Open Source Software”." (Thanks to Paul Wise)
Kategóriák: Linux

Stable kernel updates

k, 2014-07-01 17:53
Stable kernels 3.15.3, 3.14.10, 3.10.46, and 3.4.96 have been released. All contain important fixes throughout the tree.
Kategóriák: Linux

Tuesday's security updates

k, 2014-07-01 17:43

Fedora has updated gnupg2 (F19: denial of service) and kdelibs (F20: information disclosure).

Gentoo has updated openfire (multiple vulnerabilities, two from 2009) and openldap (multiple vulnerabilities, one from 2009).

openSUSE has updated freerdp (13.1, 12.3: two vulnerabilities), kernel (12.3: multiple vulnerabilities), libreoffice (13.1: unexpected VBA macro execution), samba (13.1; 12.3: multiple vulnerabilities), seamonkey (13.1, 12.3: multiple vulnerabilities), thunderbird (13.1, 12.3: multiple vulnerabilities), and xalan-j2 (13.1, 12.3: information disclosure/code execution).

Kategóriák: Linux

Security advisories for Monday

h, 2014-06-30 19:30

Debian has updated cacti (multiple vulnerabilities) and libemail-address-perl (denial of service).

Fedora has updated gnupg2 (F20: denial of service), kernel (F20: multiple vulnerabilities), php (F20: multiple vulnerabilities), python (F20: missing boundary check), and zabbix (F20; F19: local file inclusion).

Gentoo has updated icedtea-bin (multiple vulnerabilities, some from 2009), kdelibs (multiple vulnerabilities, some from 2011), and wireshark (multiple vulnerabilities).

Kategóriák: Linux