Vue lecture
[$] New kernel tools: wprobes, KStackWatch, and KFuzzTest
Kernel prepatch 6.17-rc6
But really, none of it is very large. So everything seems slated for a normal release in two weeks. Please do keep testing, so that we don't get complacent."
[$] A policy for Link tags
How FOSS Projects Handle Legal Takedown Requests (F-Droid)
As part of our legal resilience research, we spoke with a range of legal experts, software freedom advocates, and maintainers of mature FOSS infrastructure to understand how others manage these moments. In this article, we share what we learned, and how F-Droid is incorporating these lessons into its own approach.
[$] LWN.net Weekly Edition for September 11, 2025
- Front: Space Grade Linux; KDE's new distribution; Rug pulls and forks; Dependency tracker; Kernel configuration; Framework 12 laptop.
- Briefs: npm security; high-memory; Anaconda WebUI; OpenSUSE bcachefs; 32-bit Firefox; Quotes; ...
- Announcements: Newsletters, conferences, security updates, patches, and more.
OpenSUSE disables bcachefs
The current 6.16.* is NOT affected. Neither is Slowroll (for now)."
A path toward removal of kernel high-memory support
one of the least popular features of the Linux kernel". The intent is "
to gradually phase out highmem over the next 2 years for mainline kernels". This plan is posted as a prompt for a discussion to be held at the Kernel Summit in December, so chances are it will evolve considerably in the next few months.
Security updates for Tuesday
npm debug and chalk packages compromised (Aikido)
All together, these packages have more than 2 billion downloads per week.The packages were updated to contain a piece of code that would be executed on the client of a website, which silently intercepts crypto and web3 activity in the browser, manipulates wallet interactions, and rewrites payment destinations so that funds and approvals are redirected to attacker-controlled accounts without any obvious signs to the user.
Kernel prepatch 6.17-rc5
Things remain normal - both the diffstat and the commit counts look entirely sane". The announcement also contains a plea for maintainers to not overuse Link: tags when applying patches.
[$] Rug pulls, forks, and open-source feudalism
No more 32-bit Firefox support
For users who cannot transition immediately, Firefox ESR 140 will remain available — including 32-bit builds — and will continue to receive security updates until at least September 2026."
[$] The dependency tracker for complex deadlock detection
[$] LWN.net Weekly Edition for September 4, 2025
- Front: Maintaining curl; GNOME governance; Guix in Debian; Tracking untrusted data in the kernel; 32-Bit support; systemd v258.
- Briefs: bcachefs maintenance; Linux from Scratch 12.4; ELF spec; Niri 25.08; Python documentary; GNOME executive director; Quotes; ...
- Announcements: Newsletters, conferences, security updates, patches, and more.
Home Assistant 2025.9 released
The hidden vulnerabilities of open source (FastCode)
Open source maintainers, already overwhelmed by legitimate contributions, have no realistic way to counter this threat. How do you verify that a helpful contributor with months of solid commits isn't an LLM generated persona? How do you distinguish between genuine community feedback and AI created pressure campaigns? The same tools that make these attacks possible are largely inaccessible to volunteer maintainers. They lack the resources, skills, or time to deploy defensive processes and systems.The detection problem becomes exponentially harder when LLMs can generate code that passes all existing security reviews, contribution histories that look perfectly normal, and social interactions that feel authentically human. Traditional code analysis tools will struggle against LLM generated backdoors designed specifically to evade detection. Meanwhile, the human intuition that spot social engineering attacks becomes useless when the "humans" are actually sophisticated language models.
Security updates for Tuesday
GNOME loses another executive director
We are extremely grateful to Steven for all this and more. Despite these many positive achievements, Steven and the board have come to the conclusion that Steven is not the right fit for the Executive Director role at this time. We are therefore bidding Steven a fond farewell.