5 év 6 hónap óta
January 1, 2020 marks the beginning of a new year and a new decade. Many
things will doubtless change over the course of this year in the
free-software community and
beyond, while others will remain the same. One thing that will certainly
hold true is LWN's tradition of starting the new year with some ill-advised
predictions about what may be in store. Your editor has no special vision,
but neither does he fear being proved badly wrong in a public setting —
it's all in a day's work.
corbet
5 év 6 hónap óta
Security updates have been issued by Debian (igraph, jhead, libgcrypt20, otrs2, and waitress) and Mageia (clamaw, exiv2, filezilla, hunspell, libidn2, pdfresurrect, roundcubemail, and xpdf).
ris
5 év 6 hónap óta
A proposal to periodically run the
fstrim
command on Fedora 32 systems was discussed recently on the Fedora
devel mailing list.
fstrim is used to cause a filesystem to inform the underlying
storage of unused blocks, which can help SSDs and other types of block
devices perform better.
There were a number of questions and concerns raised,
including whether to change the behavior of earlier versions of the
distribution when they get upgraded and if the kernel should be responsible
for handling the whole problem.
jake
5 év 6 hónap óta
Stable kernels
5.4.7,
4.19.92, and
4.14.161 have been released. They all contain
important fixes and users should upgrade.
ris
5 év 6 hónap óta
Security updates have been issued by Debian (intel-microcode and libbsd), openSUSE (chromium, LibreOffice, and spectre-meltdown-checker), and SUSE (mozilla-nspr, mozilla-nss and python-azure-agent).
ris
5 év 6 hónap óta
Security updates have been issued by Debian (debian-lan-config, freeimage, imagemagick, libxml2, mediawiki, openssl1.0, php5, and tomcat8).
ris
5 év 6 hónap óta
The results from the
Debian general resolution
vote on init systems are in; the project's developers chose the option titled "
Systemd but we
support exploring alternatives". It makes systemd into the preferred
init system, and allows packages to use systemd-specific features;
packagers are not required to support other init systems, but support for
other systems is encouraged where it is practical.
corbet
5 év 6 hónap óta
The
5.5-rc4 kernel prepatch is out for
testing. "To absolutely nobody's surprise, last week was very quiet
indeed. It's hardly even worth making an rc release, but there are _some_
fixes in here, so here's the usual weekly Sunday afternoon rc."
corbet
5 év 6 hónap óta
Matthew Garrett
works
out how to avoid being recorded by "Ring" door cameras in his apartment
building. "The most interesting one here is the deauthentication
frame that access points can use to tell clients that they're no longer
welcome. These can be sent for a variety of reasons, including resource
exhaustion or authentication failure. And, by default, they're entirely
unprotected. Anyone can inject such a frame into your network and cause
clients to believe they're no longer authorised to use the network, at
which point they'll have to go through a new authentication cycle - and
while they're doing that, they're not able to send any other
packets."
corbet
5 év 6 hónap óta
Security updates have been issued by SUSE (dia, kernel, and libgcrypt).
jake
5 év 6 hónap óta
One of the first uses of the
BPF virtual
machine outside of networking was to implement access-control policies
for the
seccomp()
system call. Since then, though, the role of BPF in the security area has
not changed much in the mainline kernel, even though BPF has evolved
considerably from the "classic" variant still used with seccomp()
to the "extended" BPF now supported by the kernel. That has not been for a
lack of trying, though. The out-of-tree Landlock security module was
covered here over three years ago. We also
looked at the kernel runtime security
instrumentation (KRSI) patch set in September. KP Singh has posted
a new
KRSI series, so the time seems right for a closer look.
corbet
5 év 6 hónap óta
Andrew 'bunnie' Huang has posted
a detailed article on
why creating trustable hardware is so difficult and describing a project
he's working
on to do it anyway. "While open hardware has the opportunity to
empower users to innovate and embody a more correct and transparent design
intent than closed hardware, at the end of the day any hardware of
sufficient complexity is not practical to verify, whether open or
closed. Even if we published the complete mask set for a modern
billion-transistor CPU, this 'source code' is meaningless without a
practical method to verify an equivalence between the mask set and the chip
in your possession down to a near-atomic level without simultaneously
destroying the CPU."
corbet
5 év 6 hónap óta
Security updates have been issued by CentOS (firefox, fribidi, nss, nss-softokn, nss-util, openslp, and thunderbird), Debian (opensc), and Mageia (389-ds-base, apache, apache-mod_auth_openidc, kernel, libofx, microcode, php, and ruby).
jake
5 év 6 hónap óta
Security updates have been issued by CentOS (freetype, kernel, nss, nss-softokn, nss-util, and thunderbird), Mageia (ghostpcl, libmirage, and spamassassin), Oracle (fribidi), and SUSE (mariadb-100, shibboleth-sp, and slurm).
ris
5 év 6 hónap óta
Security updates have been issued by Debian (cups, cyrus-sasl2, tightvnc, and x2goclient), Fedora (cacti and cacti-spine), openSUSE (mariadb and samba), Oracle (fribidi, git, and python), Red Hat (fribidi, libyang, and qemu-kvm-rhev), Slackware (openssl and tigervnc), and SUSE (firefox, nspr, nss and kernel).
ris
5 év 6 hónap óta
The
third 5.5 kernel prepatch is out; it
was a bit bigger than Linus would have liked.
"Anyway, I'm hoping rc3 is a one-off. In fact, with the holiday season
coming up, I'd be very surprised indeed if it wasn't. So I suspect
things will calm down a lot over the next couple of weeks, but please
do use the down-time to do some extra testing instead, ok?"
corbet
5 év 6 hónap óta
corbet
5 év 6 hónap óta
The Linux control-group mechanism was designed to make it easy to assign
processes to groups or move them around; it is a simple matter of writing a
process ID to the appropriate cgroup.procs file in the
control-group filesystem hierarchy. That only works for processes that
actually exist, though. Adding the ability to place a new process into a
control group at birth is the subject of
this
patch set from Christian Brauner.
corbet
5 év 6 hónap óta
Michał Górny
describes
an effort to create something one might have never expected to see: a
binary kernel package for the Gentoo distribution. "I have manually
configured the kernels for my private systems long time ago. Today, I
wouldn’t really have bothered. In fact, I realized that for some time I’m
really hesitant to even upgrade them because of the effort needed to update
configuration. The worst part is, whenever a new kernel does not boot, I
have to ask myself: is it a real bug, or is it my fault for configuring it
wrong?"
corbet
5 év 6 hónap óta
Security updates have been issued by Debian (cyrus-imapd and gdk-pixbuf), Fedora (cacti, cacti-spine, and fribidi), Red Hat (fribidi, git, and openstack-keystone), Scientific Linux (fribidi), Slackware (wavpack), and SUSE (firefox, kernel, mariadb, spectre-meltdown-checker, and trousers).
jake
Ellenőrizve
14 perc 24 másodperc ago
LWN.net is a comprehensive source of news and opinions from
and about the Linux community. This is the main LWN.net feed,
listing all articles which are posted to the site front page.
Feliratkozás a következőre: Linux Weekly News hírcsatorna