Hírolvasó

[$] Retrieving mount and filesystem information in user space

2 év 2 hónap óta
In something of a follow-on from the mount-operation monitoring session the previous day, Christian Brauner led another discussion about providing user space with a mechanism to get current mount information on day two of the 2023 Linux Storage, Filesystem, Memory-Management and BPF Summit. The session also continued on from one at last year's summit—and likely others before that. There are two separate proposals for ways to retrieve this kind of information, one from Miklos Szeredi and another from David Howells, both of whom were present this year; Brauner's intent was to try to reach some kind of agreement on the way forward in the session.
jake

Security updates for Wednesday

2 év 2 hónap óta
Security updates have been issued by Debian (ffmpeg, owslib, php7.4, and php8.2), Fedora (ntp-refclock, php, and python3.7), Red Hat (c-ares, firefox, and thunderbird), SUSE (kernel, openldap2, and tomcat), and Ubuntu (binutils, dotnet6, dotnet7, node-fetch, and python-tornado).
corbet

[$] Mounting images inside a user namespace

2 év 2 hónap óta
There has long been a desire to enable users to mount filesystem images without requiring privileges, but the security implications of allowing it are seriously concerning. Few, if any, kernel filesystems are hardened against maliciously crafted images, after all. Lennart Poettering led a filesystem session at the 2023 Linux Storage, Filesystem, Memory-Management and BPF Summit where he presented a possible path forward.
jake

A Barracuda arra sürgeti ügyfeleit, hogy minél előbb cseréljék le az általuk használt sérülékeny ESG-ket

2 év 2 hónap óta

A Barracuda Networks 2023. június 06-ai biztonsági közleménye szerint a CVE-2023-2868 néven nyomon követett sebezhetőségben érintett ESG (Email Security Gateway) eszközök a gyártói biztonsági frissítés telepítése ellenére cserére szorulnak.

The post A Barracuda arra sürgeti ügyfeleit, hogy minél előbb cseréljék le az általuk használt sérülékeny ESG-ket first appeared on Nemzeti Kibervédelmi Intézet.

NKI

McKenney: Parallel Programming: June 2023 Update

2 év 2 hónap óta
Paul McKenney has announced a new version of his book Is Parallel Programming Hard, And, If So, What Can You Do About It?.

This release contains a new section on thermal throttling (along with a new cartoon), improvements to the memory-ordering chapter (including intuitive subsets of the Linux-kernel memory model), fixes to the deferred-processing chapter, additional clocksource-deviation material to the "What Time Is It?" section, and numerous fixes inspired by questions and comments from readers.

corbet

Security updates for Tuesday

2 év 2 hónap óta
Security updates have been issued by Debian (vim), Fedora (kernel), Oracle (emacs, firefox, python3, and qemu), SUSE (firefox, java-1_8_0-ibm, and libwebp), and Ubuntu (firefox, glusterfs, and sniproxy).
corbet

Paul E. Mc Kenney: Parallel Programming: June 2023 Update

2 év 2 hónap óta

The v2023.06.11a release of Is Parallel Programming Hard, And, If So, What Can You Do About It? is now available! The double-column version is also available from arXiv.org.

This release contains a new section on thermal throttling (along with a new cartoon), improvements to the memory-ordering chapter (including intuitive subsets of the Linux-kernel memory model), fixes to the deferred-processing chapter, additional clocksource-deviation material to the "What Time Is It?" section, and numerous fixes inspired by questions and comments from readers.  Discussions with Yariv Aridor were especially fruitful.  Akira Yokosawa contributed some quick quizzes and other upgrades of the technical discussions, along with a great many improvements to grammar, glossaries, epigraphs, and the build system.  Leonardo Bras also provided some much-appreciated build-system improvements, and also started up continuous integration for some of the code samples.

Elad Lahav, Alan Huang, Zhouyi Zhou, and especially SeongJae Park contributed numerous excellent fixes for grammatical and typographical errors.  SeongJae's fixes were from his Korean translation of this book.

Elad Lahav, Alan Huang, and Patrick Pan carried out some much-needed review of the code samples and contributed greatly appreciated fixes and improvements.  In some cases, they drug the code kicking and screaming into the 2020s.  :-)

[$] Deadline servers as a realtime throttling replacement

2 év 2 hónap óta
The CPU scheduler's one job at any given time is to run the task that has the strongest claim to the CPU. There are many factors that complicate that job, not the least of which is that the "strongest claim" is sometimes a bit of a fuzzy concept. Realtime throttling, a mechanism designed to keep a runaway realtime task from monopolizing the CPU, is one case where developers have concluded that the task with, ostensibly, the highest priority should not actually be the one that runs. But realtime throttling has rarely pleased anybody; the deadline-server infrastructure patches posted by Daniel Bristot de Oliveira are the latest attempt to find a better solution.
corbet

Security updates for Monday

2 év 2 hónap óta
Security updates have been issued by Debian (pypdf2 and thunderbird), Fedora (chromium, dbus, mariadb, matrix-synapse, sympa, and thunderbird), Scientific Linux (python and python3), SUSE (chromium, gdb, and openldap2), and Ubuntu (jupyter-core, requests, sssd, and vim).
jake

Még nem dokumentált, kritikus sérülékenység került javításra Fortigate eszközökben

2 év 2 hónap óta

Szakértők arra havják fel a figyelmet, hogy a Fortinet múlt hét pénteken kiadott biztonsági frissítése egy korábban nem publikált sebezhetőséget javított a gyártó FortiGate tűzfal termékeiben, az SSL-VPN kapcsolatot érintően. Javasolt a firmware frissítések azonnali telepítése.

The post Még nem dokumentált, kritikus sérülékenység került javításra Fortigate eszközökben first appeared on Nemzeti Kibervédelmi Intézet.

NKI

Kernel prepatch 6.4-rc6

2 év 2 hónap óta
The 6.4-rc6 kernel prepatch is out for testing.

I don't think we've had anything hugely interesting happen the last week, and the whole 6.4 release really does feel like it's going fairly smoothly. Knock wood, famous last words, you know the drill.

corbet

Debian 12 "bookworm" released

2 év 2 hónap óta
"After 1 year, 9 months, and 28 days of development", Debian 12, codenamed "bookworm", has been released. The announcement has lots of details about package versions for desktop environments (6 are supported), kernel version (Linux 6.1 series), other package versions (compilers, graphics tools, office suites, languages, and more), architectures supported (8 for real hardware and 5 for cloud services), blends, and lots more. This release contains over 11,089 new packages for a total count of 64,419 packages, while over 6,296 packages have been removed as "obsolete". 43,254 packages were updated in this release. The overall disk usage for "bookworm" is 365,016,420 kB (365 GB), and is made up of 1,341,564,204 lines of code.

"bookworm" has more translated man pages than ever thanks to our translators who have made man-pages available in multiple languages such as: Czech, Danish, Greek, Finnish, Indonesian, Macedonian, Norwegian (Bokmål), Russian, Serbian, Swedish, Ukrainian, and Vietnamese. All of the systemd man pages are now completely available in German.

See the Debian 12 release notes for additional information.

jake

[$] Two VFS topics

2 év 2 hónap óta
Two different topics concerning the virtual filesystem (VFS) layer were the subject of a session led by VFS co-maintainer Christian Brauner at the 2023 Linux Storage, Filesystem, Memory-Management and BPF Summit. As might be guessed, it was a filesystem-track session; Brauner had three separate items he planned on bringing up, but the discussion on the first two consumed the whole half-hour—and then some. A mechanism to avoid media-change races when mounting loop (or loopback) and other devices was disposed of fairly quickly, but the discussion around the mount-beneath feature went on at length.
jake

[$] Addressing priority inversion with proxy execution

2 év 2 hónap óta
Priority inversion comes about when a low-priority task holds a resource that is needed by a higher-priority task, with the result that the wrong task is the only one that can run. This problem is arguably most acute in realtime settings, but it can happen in just about any system that has multiple tasks running. The variety of scheduling classes provided by the Linux kernel make handling priority inversion a difficult problem; the latest version of the proxy execution patch series points toward a possible solution.
corbet