<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"
    		xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>LWN.net</title>
        <link>https://lwn.net</link>
        <description> LWN.net is a comprehensive source of news and opinions from
        and about the Linux community.  This is the main LWN.net feed,
        listing all articles which are posted to the site front page.
</description>
        <language>en-us</language>
        <pubDate>Sun, 26 Apr 2026 23:37:19 +0000</pubDate>
        <lastBuildDate>Sun, 26 Apr 2026 23:37:19 +0000</lastBuildDate>
        <docs>https://www.rssboard.org/rss-specification</docs>
        <webMaster>lwn@lwn.net</webMaster>
        <atom:link href="https://lwn.net/headlines/rss2"
    		rel="self" type="application/rss+xml"/>
    <item>
        <title>GnuPG 2.5.19 released</title>
        <link>https://lwn.net/Articles/1069552/</link>
        <guid>https://lwn.net/Articles/1069552/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;Werner Koch has &lt;a
href=&quot;https://lists.gnu.org/archive/html/info-gnu/2026-04/msg00010.html&quot;&gt;announced&lt;/a&gt;
the release of GnuPG&amp;#160;2.5.19. This release includes a few new options
and a number of bug fixes, and comes with the reminder that the
GnuPG&amp;#160;2.4 series will reach end-of-life soon&lt;/p&gt;

&lt;blockquote class=&quot;bq&quot;&gt;
&lt;p&gt;The main features in the&amp;#160;2.5 series are improvements for&amp;#160;64 bit Windows
and the introduction of Kyber (aka ML-KEM or FIPS-203) as PQC encryption
algorithm.  Other than PQC support the&amp;#160;2.6 series will not differ a lot
from&amp;#160;2.4 because the majority of changes are internal to make use of
newer features from the supporting libraries.&lt;/p&gt;

&lt;p&gt;Note that the old&amp;#160;2.4 series reaches end-of-life in just two months.
Thus update to&amp;#160;2.5.19 in time.  As always with GnuPG new versions are
fully compatible with previous versions.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;LWN &lt;a href=&quot;https://lwn.net/Articles/1055053/&quot;&gt;recently
covered&lt;/a&gt; Fedora's discussion about what to offer after GnuPG&amp;#160;2.4 is no
longer supported.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;</description>
        <pubDate>Fri, 24 Apr 2026 13:43:11 +0000</pubDate>
        </item>
        <item>
        <title>[$] On pages and folios</title>
        <link>https://lwn.net/Articles/1064861/</link>
        <guid>https://lwn.net/Articles/1064861/</guid>
        <dc:creator>corbet</dc:creator>
        <description>The kernel coverage here at LWN often touches on memory-management topics
and, as a result, tends to talk a lot about both pages and folios.  As the
folio transition in the kernel has moved forward, it has often become
difficult to decide which term to use in writing that is meant to be both
approachable and technically correct.  As this work continues, it will be
increasingly common to use &quot;folio&quot; rather than page.  This article is
intended to be a convenient reference for readers wanting to differentiate
the two terms or understand the state of this transition.
</description>
        <pubDate>Fri, 24 Apr 2026 13:08:51 +0000</pubDate>
        </item>
        <item>
        <title>Security updates for Friday</title>
        <link>https://lwn.net/Articles/1069549/</link>
        <guid>https://lwn.net/Articles/1069549/</guid>
        <dc:creator>jzb</dc:creator>
        <description>Security updates have been issued by &lt;b&gt;Fedora&lt;/b&gt; (anaconda, dnf5, firefox, flatpak-builder, libexif, minetest, nss, plasma-setup, python-blivet, rpki-client, and xorg-x11-server), &lt;b&gt;Oracle&lt;/b&gt; (bind, kernel, osbuild-composer, thunderbird, webkit2gtk3, and wireshark), &lt;b&gt;Red Hat&lt;/b&gt; (java-25-openjdk), &lt;b&gt;SUSE&lt;/b&gt; (cacti, cacti, cacti-spine, cockpit-machines, cockpit-podman, cockpit-tukit, csync2, flannel, gdk-pixbuf, go1.25-openssl, go1.26-openssl, haproxy, kernel, libcap, libpng16, libtree-sitter0_26, libvirt, ncurses, ntfs-3g_ntfsprogs, openssl-1_1, openssl-3, openvswitch, perl, python-pyOpenSSL, python311, rclone, sudo, and tomcat), and &lt;b&gt;Ubuntu&lt;/b&gt; (gst-plugins-bad1.0, jq, libopenmpt, linux-ibm, linux-ibm-5.15, and php-league-commonmark).
</description>
        <pubDate>Fri, 24 Apr 2026 13:08:09 +0000</pubDate>
        </item>
        <item>
        <title>Ubuntu 26.04 LTS released</title>
        <link>https://lwn.net/Articles/1069399/</link>
        <guid>https://lwn.net/Articles/1069399/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;Ubuntu 26.04 (&quot;Resolute Raccoon&quot;) LTS has been &lt;a
href=&quot;https://discourse.ubuntu.com/t/ubuntu-26-04-resolute-raccoon-lts-released/80833&quot;&gt;released&lt;/a&gt;
on schedule.&lt;/p&gt;

&lt;blockquote class=&quot;bq&quot;&gt;
&lt;p&gt;This release brings a significant uplift in security, performance,
and usability across desktop, server, and cloud environments. Ubuntu
26.04 LTS introduces TPM-backed full-disk encryption, expanded use of
memory-safe components, improved application permission controls, and
Livepatch support for Arm systems, helping reduce downtime and
strengthen system resilience. [...]&lt;/p&gt;

&lt;p&gt;The newest Edubuntu, Kubuntu, Lubuntu, Ubuntu Budgie, Ubuntu Cinnamon,
Ubuntu Kylin, Ubuntu Studio, Ubuntu Unity, and Xubuntu are also being
released today. For more details on these, read their individual release
notes under the Official flavors section:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://documentation.ubuntu.com/release-notes/26.04/#official-flavors&quot;&gt;https://documentation.ubuntu.com/release-notes/26.04/#official-flavors&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Maintenance updates will be provided for 5 years for Ubuntu Desktop, Ubuntu
Server, Ubuntu Cloud, Ubuntu WSL, and Ubuntu Core. All the remaining flavors
will be supported for 3 years.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;See the &lt;a
href=&quot;https://documentation.ubuntu.com/release-notes/26.04/&quot;&gt;release
notes&lt;/a&gt; for a list of changes, system requirements, and more.&lt;/p&gt;
</description>
        <pubDate>Thu, 23 Apr 2026 18:16:00 +0000</pubDate>
        </item>
        <item>
        <title>[$] Famfs, FUSE, and BPF</title>
        <link>https://lwn.net/Articles/1068686/</link>
        <guid>https://lwn.net/Articles/1068686/</guid>
        <dc:creator>corbet</dc:creator>
        <description>The famfs filesystem first &lt;a
href=&quot;https://lwn.net/ml/all/cover.1708709155.git.john@groves.net/&quot;&gt;showed up on the
mailing lists&lt;/a&gt; in early 2024; since then, it has been the topic of
regular discussions at the Linux Storage, Filesystem, Memory Management and
BPF (LSFMM+BPF) Summit.  It has also, as result of those discussions, been
through some significant changes since that initial posting.  So it is not
surprising that a suggestion that it needed to be rewritten yet again was
not entirely well received.  How much more rewriting will actually be
needed is unclear, but more discussion appears certain.
</description>
        <pubDate>Thu, 23 Apr 2026 13:44:23 +0000</pubDate>
        </item>
        <item>
        <title>Security updates for Thursday</title>
        <link>https://lwn.net/Articles/1069356/</link>
        <guid>https://lwn.net/Articles/1069356/</guid>
        <dc:creator>jzb</dc:creator>
        <description>Security updates have been issued by &lt;b&gt;AlmaLinux&lt;/b&gt; (kernel and osbuild-composer), &lt;b&gt;Debian&lt;/b&gt; (cpp-httplib, firefox-esr, gimp, and packagekit), &lt;b&gt;Fedora&lt;/b&gt; (chromium, composer, libcap, pgadmin4, pie, python3-docs, python3.14, and sudo), &lt;b&gt;Mageia&lt;/b&gt; (gvfs), &lt;b&gt;Oracle&lt;/b&gt; (.NET 8.0, delve, freerdp, giflib, ImageMagick, kernel, OpenEXR, and osbuild-composer), &lt;b&gt;SUSE&lt;/b&gt; (erlang, giflib, google-guest-agent, GraphicsMagick, ignition, imagemagick, kea, kernel, kissfft, libraw, libssh, ocaml-patch, opam, openCryptoki, openexr, openssl-1_1, tomcat, tomcat10, tomcat11, and tor), and &lt;b&gt;Ubuntu&lt;/b&gt; (linux, linux-aws, linux-aws-5.4, linux-azure, linux-gcp, linux-gcp-5.4,
 linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm,
 linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux-aws, linux-aws-6.17, linux-hwe-6.17, linux-oracle, linux-oracle-6.17, linux-azure, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-oracle-5.15, linux-azure-5.4, linux-azure-fips, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-hwe-6.8, linux-ibm-6.8, linux-raspi, linux-oracle, linux-oracle-6.8, linux-raspi, linux-raspi-5.4, linux-raspi-realtime, packagekit, python-tornado, ruby-rack-session, slurm-llnl, and strongswan).
</description>
        <pubDate>Thu, 23 Apr 2026 13:11:54 +0000</pubDate>
        </item>
        <item>
        <title>[$] LWN.net Weekly Edition for April 23, 2026</title>
        <link>https://lwn.net/Articles/1067989/</link>
        <guid>https://lwn.net/Articles/1067989/</guid>
        <dc:creator>jzb</dc:creator>
        <description>Inside this week's LWN.net Weekly Edition:
        &lt;p&gt;
        &lt;ul&gt;
&lt;li&gt; &lt;a href=&quot;https://lwn.net/Articles/1067989/&quot;&gt;Front&lt;/a&gt;: LLMs and Python bugs; scheduler regression; new Rust traits; dependency cooldowns; 7.1 merge window; Shor's algorithm; drama at The Document Foundation.
            &lt;li&gt; &lt;a href=&quot;https://lwn.net/Articles/1067991/&quot;&gt;Briefs&lt;/a&gt;: Firefox zero-days; kernel code removal; reproduceible Arch; Debian election; Firefox 150; Forgejo 15.0; Git 2.54.0; KDE Gear 26.04; LillyPond 2.26.0; Rust 1.95.0; Quotes; ...
            &lt;li&gt; &lt;a href=&quot;https://lwn.net/Articles/1067992/&quot;&gt;Announcements&lt;/a&gt;: Newsletters, conferences, security updates, patches, and more.
            &lt;/ul&gt;

        </description>
        <pubDate>Thu, 23 Apr 2026 00:11:22 +0000</pubDate>
        </item>
        <item>
        <title>[$] Dependency-cooldown discussions warm up</title>
        <link>https://lwn.net/Articles/1068692/</link>
        <guid>https://lwn.net/Articles/1068692/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;Efforts to introduce malicious code into the open-source supply
chain have been on the rise in recent years, and there is no indication that they
will abate anytime soon. These attacks are often found quickly, but not quickly
enough to prevent the compromised code from being automatically injected into other
projects or code deployed by users where it can wreak havoc. One method of avoiding
supply-chain attacks is to add a delay of a few days before pulling upates in what
is known as a &quot;dependency cooldown&quot;. That tactic is starting to find favor with
users and some language ecosystem package managers. While this practice is
considered a reasonable response by many, others are complaining that those
employing dependency cooldowns are free-riding on the larger community by letting
others take the risk.&lt;/p&gt;
</description>
        <pubDate>Wed, 22 Apr 2026 15:21:01 +0000</pubDate>
        </item>
        <item>
        <title>[$] One Sized trait does not fit all</title>
        <link>https://lwn.net/Articles/1067220/</link>
        <guid>https://lwn.net/Articles/1067220/</guid>
        <dc:creator>daroc</dc:creator>
        <description>&lt;p&gt;
In Rust, types either possess a constant size known at compile time, or a
dynamically calculated size known at
run time. That is fine for most purposes, but recent proposals for the language
have shown the need for a more fine-grained hierarchy.
&lt;a href=&quot;https://github.com/davidtwco/rfcs/blob/sized-hierarchy/text/3729-sized-hierarchy.md&quot;&gt;
RFC 3729&lt;/a&gt; from David Wood and Rémy Rakic would add a hierarchy of
traits to describe types with sizes known under different circumstances. While
the idea has been subject to discussion for many years, a growing number of
use cases for the feature have come to light.
&lt;/p&gt;
</description>
        <pubDate>Wed, 22 Apr 2026 13:58:35 +0000</pubDate>
        </item>
        <item>
        <title>LilyPond 2.26.0 released</title>
        <link>https://lwn.net/Articles/1069107/</link>
        <guid>https://lwn.net/Articles/1069107/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;&lt;a
href=&quot;https://lilypond.org/doc/v2.26/Documentation/changes/&quot;&gt;Version
2.26.0&lt;/a&gt; of the &lt;a href=&quot;https://lilypond.org/&quot;&gt;LilyPond&lt;/a&gt;
music-engraving program has been released. &lt;a
href=&quot;https://lilypond.org/doc/v2.26/Documentation/changes/major-changes-in-lilypond&quot;&gt;Major
changes&lt;/a&gt; include the ability to use the Cairo library to generate
output and improvements in spacing between clefs and time
signatures. See the release notes for a full list of &lt;a
href=&quot;https://lilypond.org/doc/v2.26/Documentation/changes/miscellaneous-improvements&quot;&gt;miscellaneous
improvements&lt;/a&gt; as well as what's new with &lt;a
href=&quot;https://lilypond.org/doc/v2.26/Documentation/changes/new-for-musical-notation&quot;&gt;musical&lt;/a&gt;
and &lt;a
href=&quot;https://lilypond.org/doc/v2.26/Documentation/changes/new-for-specialist-notation&quot;&gt;specialist&lt;/a&gt;
notation.&lt;/p&gt;</description>
        <pubDate>Wed, 22 Apr 2026 13:23:06 +0000</pubDate>
        </item>
        <item>
        <title>Four stable kernels for Wednesday</title>
        <link>https://lwn.net/Articles/1068981/</link>
        <guid>https://lwn.net/Articles/1068981/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;Greg Kroah-Hartman has announced the release of the &lt;a
href=&quot;https://lwn.net/Articles/1068980/&quot;&gt;7.0.1&lt;/a&gt;, &lt;a
href=&quot;https://lwn.net/Articles/1068982/&quot;&gt;6.19.14&lt;/a&gt;, &lt;a
href=&quot;https://lwn.net/Articles/1068983/&quot;&gt;6.18.24&lt;/a&gt;, and &lt;a
href=&quot;https://lwn.net/Articles/1068984/&quot;&gt;6.12.83&lt;/a&gt; stable kernels. As usual, each
contains important fixes throughout the tree. Users are encouraged to
upgrade.&lt;/p&gt;
&lt;p&gt;
Note that the 6.19.x series ends with 6.19.14.</description>
        <pubDate>Wed, 22 Apr 2026 13:06:01 +0000</pubDate>
        </item>
        <item>
        <title>Security updates for Wednesday</title>
        <link>https://lwn.net/Articles/1069105/</link>
        <guid>https://lwn.net/Articles/1069105/</guid>
        <dc:creator>jzb</dc:creator>
        <description>Security updates have been issued by &lt;b&gt;Debian&lt;/b&gt; (firefox-esr, flatpak, ngtcp2, ntfs-3g, packagekit, python-geopandas, simpleeval, strongswan, and xdg-dbus-proxy), &lt;b&gt;Fedora&lt;/b&gt; (chromium, cups, curl, jq, opkssh, perl-Net-CIDR-Lite, python-cbor2, python-pillow, tinyproxy, xdg-dbus-proxy, and xorg-x11-server-Xwayland), &lt;b&gt;Slackware&lt;/b&gt; (libXpm and mozilla), &lt;b&gt;SUSE&lt;/b&gt; (botan, chromium, clamav, cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-subscriptions, dovecot24, firefox, flatpak, freeipmi, gdk-pixbuf, glibc, gnome-remote-desktop, go1.25, go1.26, go1.26-openssl, google-cloud-sap-agent, gosec, graphicsmagick, haproxy, kernel, libpng16, libraw, libtasn1, libvncserver, ncurses, nebula, nodejs24, openssl-3, ovmf, pam, pcre2, perl-Authen-SASL, pgvector, plexus-utils, podman, python-cbor2, python-cryptography, python-django, python-gi-docgen, python-pypdf2, python-python-multipart, python311, python311-PyPDF2, python313, qemu, roundcubemail, rust1.94, sqlite3, strongswan, systemd, tar, tigervnc, util-linux, vim, webkit2gtk3, xorg-x11-server, xwayland, and zlib), and &lt;b&gt;Ubuntu&lt;/b&gt; (commons-io, libcap2, ntfs-3g, and rapidjson).
</description>
        <pubDate>Wed, 22 Apr 2026 13:04:54 +0000</pubDate>
        </item>
        <item>
        <title>Kernel code removals driven by LLM-created security reports</title>
        <link>https://lwn.net/Articles/1068928/</link>
        <guid>https://lwn.net/Articles/1068928/</guid>
        <dc:creator>corbet</dc:creator>
        <description>There are a number of ongoing efforts to remove kernel code, mostly from
the networking subsystem, as an alternative to dealing with the increase in
security-bug reports from large language models.  The proposed removals
include &lt;a
href=&quot;https://lwn.net/ml/all/20260421-v7-0-0-net-next-driver-removal-v1-v1-0-69517c689d1f@lunn.ch&quot;&gt;ISA
and PCMCIA Ethernet drivers&lt;/a&gt;, a &lt;a
href=&quot;https://lwn.net/ml/all/20260422044820.485660-1-25181214217@stu.xidian.edu.cn&quot;&gt;pair
of PCI drivers&lt;/a&gt;, the &lt;a
href=&quot;https://lwn.net/ml/all/20260421021824.1293976-1-kuba@kernel.org&quot;&gt;ax25 and amateur
radio subsystem&lt;/a&gt;, the &lt;a
href=&quot;https://lwn.net/ml/all/20260421021943.1295109-1-kuba@kernel.org&quot;&gt;ATM protocols and drivers&lt;/a&gt;,
and the &lt;a href=&quot;https://lwn.net/ml/all/20260421022108.1299678-1-kuba@kernel.org&quot;&gt;ISDN
subsystem&lt;/a&gt;.
&lt;p&gt;
&lt;blockquote class=&quot;bq&quot;&gt;
	Remove the amateur radio (AX.25, NET/ROM, ROSE) protocol
	implementation and all associated hamradio device drivers from the
	kernel tree.  This set of protocols has long been a huge bug/syzbot
	magnet, and since nobody stepped up to help us deal with the influx
	of the AI-generated bug reports we need to move it out of tree to
	protect our sanity.
&lt;/blockquote&gt;</description>
        <pubDate>Wed, 22 Apr 2026 06:56:14 +0000</pubDate>
        </item>
        <item>
        <title>Firefox: The zero-days are numbered</title>
        <link>https://lwn.net/Articles/1068906/</link>
        <guid>https://lwn.net/Articles/1068906/</guid>
        <dc:creator>corbet</dc:creator>
        <description>&lt;a
href=&quot;https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/&quot;&gt;This
Firefox blog post&lt;/a&gt; reports that the Firefox&amp;#160;150 release includes
fixes for 271 vulnerabilities found by the Claude Mythos preview.
&lt;p&gt;
&lt;blockquote class=&quot;bq&quot;&gt;
	Elite security researchers find bugs that fuzzers can't largely by
	reasoning through the source code. This is effective, but
	time-consuming and bottlenecked on scarce human
	expertise. Computers were completely incapable of doing this a few
	months ago, and now they excel at it. We have many years of
	experience picking apart the work of the world's best security
	researchers, and Mythos Preview is every bit as capable. So far
	we've found no category or complexity of vulnerability that humans
	can find that this model can't.
&lt;p&gt;
	This can feel terrifying in the immediate term, but it's ultimately
	great news for defenders. A gap between machine-discoverable and
	human-discoverable bugs favors the attacker, who can concentrate
	many months of costly human effort to find a single bug. Closing
	this gap erodes the attacker's long-term advantage by making all
	discoveries cheap.
&lt;/blockquote&gt;</description>
        <pubDate>Wed, 22 Apr 2026 06:23:40 +0000</pubDate>
        </item>
        <item>
        <title>Fedora Verified: a proposal to recognize Fedora contributor status</title>
        <link>https://lwn.net/Articles/1068861/</link>
        <guid>https://lwn.net/Articles/1068861/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;The Fedora Project has been wrestling with the question of &lt;a
href=&quot;https://lwn.net/Articles/1055539/&quot;&gt;who should be able to vote in
Fedora elections&lt;/a&gt; recently, with project membership being &lt;a
href=&quot;https://lwn.net/Articles/1060190/#membership&quot;&gt;a major topic at
the Fedora Council face-to-face&lt;/a&gt; held in early February. Now the
project is considering a new contributor status, &quot;Fedora Verified&quot;,
and is &lt;a
href=&quot;https://communityblog.fedoraproject.org/fedora-verified-recognize-contributors/&quot;&gt;looking
to get input&lt;/a&gt; on the idea from the community.&lt;/p&gt;

&lt;blockquote class=&quot;bq&quot;&gt;
&lt;p&gt;What are the proposed benefits? The primary motivation behind
&quot;Fedora Verified&quot; is to build trust-based recognition that grants
elevated, privileged rights within the project. Most notably, this
status would determine eligibility for strategic governance
activities, such as:&lt;/p&gt;

&lt;ul class=&quot;spacylist&quot;&gt;
&lt;li&gt;Voting in Fedora community elections.&lt;/li&gt;
&lt;li&gt;Running for leadership or decision-making roles within the project
(i.e., Fedora Council, FESCo, Mindshare Committee, EPEL Steering
Committee).&lt;/li&gt;
&lt;li&gt;(Potential, unplanned) Accessing specific shared project resources
or educational opportunities (e.g., Red Hat training credits).&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;p&gt;The blog post includes a list of proposed baseline metrics for
&quot;Verified&quot; status as well as open questions to be decided. A &lt;a
href=&quot;https://fedoraproject.limequery.com/verified-concept-survey&quot;&gt;survey
on the topic&lt;/a&gt; will be open until May&amp;#160;5.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;</description>
        <pubDate>Tue, 21 Apr 2026 18:35:16 +0000</pubDate>
        </item>
        </channel>
</rss>
