Tux Machines

Do you waddle the waddle?

Other Sites

LinuxGizmos.com

Radxa Linkr Brings Remote KVM Access and Tailscale Support to a Thumb-Sized Device

Radxa has unveiled the Linkr, a compact remote-control device for accessing computers, servers, and development boards through a web browser. The unit combines HDMI video capture with USB keyboard and mouse emulation, allowing users to view and operate a target system without connecting a dedicated monitor, keyboard, or mouse.

ELM11-Feather Debuts with Native Lua and Reconfigurable FPGA Hardware

First seen in March, Brisbane Silicon has now launched the ELM11-Feather to Crowd Supply. Priced at $39, the Feather-compatible development board combines native Lua support with the Arvore IDE and a configurable hardware architecture programmable in C, SystemVerilog, and VHDL.

9to5Linux

NVIDIA 610.57.04 Linux Graphics Driver Improves Support for Many Games

NVIDIA 610.57.04 is here to fix bugs that should improve the performance of games like 007 First Light, Forza Horizon 6, S.T.A.L.K.E.R. 2: Heart of Chornobyl, Assetto Corsa EVO, Assassin’s Creed Origins, Total War: Warhammer III, X-Plane, Monster Hunter Wilds, Crimson Desert, Elden Ring, and Elden Ring Nightrein.

9to5Linux Weekly Roundup: August 2nd, 2026

I want to thank everyone who sent us donations; your generosity is greatly appreciated. I also want to thank all of you for your continued support by commenting, liking, sharing, and boosting the articles, following us on social media, and, last but not least, sending us feedback.

AerynOS 2026.08 Released with Linux 7.1, GNOME 50.3, COSMIC 1.5, and More

The biggest change in the AerynOS 2026.08 release is that the underlying OS is now powered by the latest and greatest Linux 7.1 kernel series. As expected, this change alone should provide AerynOS users with slightly faster performance, better hardware support, and some other enhancements.

Fedora Linux 45 to Enable Shadow Stack Protection by Default on 64-Bit

Shadow Stack is a hardware-backed security feature designed to prevent control-flow hijacking attacks, including Return-Oriented Programming (ROP) or Jump-Oriented Programming (JOP) attacks. This will protect the majority of Fedora binaries, but will add a small performance overhead.

New Debian 13 “Trixie” Kernel Security Update Fixes 68 Vulnerabilities

Coming ten days after the previous Linux kernel security update, which only fixed 12 vulnerabilities that may lead to a privilege escalation, denial of service, or information leaks, the new Debian 13 Linux kernel security update is a massive one, and it patches no less than 68 security vulnerabilities in the Linux 6.12 LTS kernel.

Mozilla Firefox 153.0.1 Web Browser Brings Fixes for Multiple Issues and Crashes

Firefox 153.0.1 is here to fix an issue with audio going silent on some music and audio streaming websites after pausing and resuming playback, a crash that occurred when a web page loaded a frame using a javascript: address, and an issue with View Page Source failing to load blob: documents.

Arch Linux-Based Archcraft 26.08 Brings New Sway Wayland Session, Linux 7.1

Powered by the latest and greatest Linux 7.1 kernel series, Archcraft 26.08 introduces a brand-new Qt 6 SDDM login theme, a new Sway Wayland session, more reliable encrypted installation, better GTK/GNOME application integration, improved VirtualBox compatibility, and support for Btrfs and XFS installations.

Gentoo-Based MocaccinoOS 26.08 Is Out with COSMIC 1.5, KDE Plasma 6.6.6

Powered by the Linux 6.18.41 LTS kernel, MocaccinoOS 26.08 is here to update the Mesa graphics stack to version 26.1.5, update the Calamares graphical installer to the latest 3.4.2 release, and update the Vajo GUI/TUI frontend for the Luet container-based, zero-dependency static package manager.

First Arch Linux ISO Powered by Linux Kernel 7.1 Is Now Available for Download

Arch Linux 2026.08.01 is out today as the first Arch Linux ISO release to ship with Linux kernel 7.1 by default, which should give users a boost when detecting hardware, especially on newer devices, but especially on older ones where previous Arch Linux ISOs failed to detect some of the components.

4MLinux 52.0 Released with Better Support for Legacy GPUs, Linux Kernel 6.18 LTS

Coming four months after 4MLinux 51.0, the 4MLinux 52.0 release is powered by the Linux 6.18 LTS kernel series for better hardware support compared to Linux 6.12 LTS used in the previous release, and uses the Mesa 26.0 graphics stack to improve graphics and gaming support.

Tor Project blog

Snowflake Volunteer, an Android app to help people bypass censorship

That's why it's important to have a large and healthy pool of volunteers always available. To achieve that, Snowflake has to be easy to use and deploy, ideally on the devices and with the services they already use.

news

OpenBSD 7.9 released

posted by Roy Schestowitz on May 19, 2026,
updated May 22, 2026

May 19, 2026.

We are pleased to announce the official release of OpenBSD 7.9. This is our 60th release. We remain proud of OpenBSD's record of more than thirty years with only two remote holes in the default install.
As in our previous releases, 7.9 provides significant improvements, including new features, in nearly all areas of the system:
- Platform-specific improvements: o arm64: - Enabled ice(4) on arm64. - Added support for the RK3588 and RK3576 SoCs with new or additions to existing drivers. - Added support for the Genesys Logic GL9755 SDHC controller (which includes the SDHC controller on some of the Apple Silicon laptops) to sdmmc(4). o amd64: - Added SMU support to amdpmc(4). The SMU is a microcontroller buried deep in the bowels of AMD SoCs and needs to be tickled in order to reach the lowest power states in suspend. - Disabled Panel Self Refresh (PSR) in amdgpu to avoid a potential hang on a ThinkPad X13 gen 6. - Increased MAXCPUs on amd64 to 255. - On amd64, we now zero the DM PTE/PDE pages before use. This fixes a bug on machines with more than 512GB RAM. - Mitigated floating point state leakage observed on AMD Zen/Zen+ (Zen 1). o luna88k: - Switched luna88k compiler to gcc4. - Switched luna88k to PIE (Position Independent Executables) by default. o riscv64: Systems with a SpacemiT K1 SoC gained support with the following (and more) changes: - Added smtclock(4), a driver for the clock/reset controller on the SpacemiT K1 SoC. - Added many more drivers to support the SpacemiT K1 SoC. - Implemented support for the Zicbom (Cache-Block Management) and Svpbmt (Page-Based Memory Types) extensions. - Added the SpacemiT K1 device trees onto the riscv64 miniroot making them accessible during installation. - Made "Instruction access fault" (EXCP_FAULT_FETCH) traps being treated as PROT_EXEC. This fixes random SIGSEGV on the SpacemiT X60 cores. - Added SpacemiT K1 support to dwpcie(4). o Other architectures: - Fixed various errors on big-endian systems in ice(4) to make it work on sparc64. - Changed powerpc64 memory barriers to "sync". - Reworked and improved TLB shootdown on alpha. - Hoisted mips64 CPU accounting to get multiple softnet threads on MP systems. - Made sure to initialize all FPU registers on sparc64 to all 1 (or -NaN), and not only the lower 32 registers. - Fixed parking mutex on sun4u sparc64 cpus. o More platform-specific changes can be found in the hardware support section below.
- Various kernel improvements: o Introduced a mechanism to manage CPU cores with different speeds in the scheduler. The sysctl(8) variable "hw.blockcpu" takes a sequence of 4 letters: S (for SMT), P (regular performance CPU), E (efficient CPU, generally 80% to 50% as fast), and L (lethargic CPU) which are even slower. Set this to select CPUs to kick out of the scheduler (SL by default). Currently works on amd64 and arm64. o Replaced the cas spinlock in kernel mutexes with a "parking" lock. o Stopped forcing the page daemon to sleep when there are outstanding paging requests. o Implemented a ddb(4) stop command that sends a SIGSTOP to the specified pid. o Made ddb(4) output visible when entering ddb from X on amdgpu. o Added infrastructure to allow future support of up to 52 partitions per disk. o Made changes to avoid memory allocation from within the swapencrypt path of the pagedaemon by pre-allocating 32 swapclusters up-front. o Changed the strategy by which the pagedaemon creates free memory by overshooting the creation of inactive and free pages, in order to defragment memory. o Refuse to load a binary without a PT_LOAD exec segment.
- Suspend/Hibernate Support: o Implemented delayed hibernation: In order to prevent running out of battery while suspended, this feature wakes up a suspended system after a configurable time to then immediately perform a hibernation. The machdep.hibernatedelay sysctl(2) is used to configure the number of seconds after which the system will wake up from suspend and hibernate itself.
- SMP Improvements: o Unlocked socket splicing. o Unlocked icmp6_sysctl(). o Unlocked the IGMP slow timeout. o Enabled parallel fault handling on amd64 and arm64. o Made bse(4) interrupts mp-safe. o Protected the IGMP and MLD6 fast timers with an rwlock.
- Direct Rendering Manager and graphics drivers: o Updated drm(4) to Linux 6.18.22.
- VMM/VMD and virtualization improvements: o Adopted PCI-based semantics for reading unsupported or invalid registers by returning all 1's. Newer Linux kernels have started using 128-bit feature spaces. o Added sysctl(8) machdep.vmmode to indicate status as a host or guest (and SEV mode). o Added vmboot, a tiny kernel that allows sysupgrade(8) to work for vmd(8) VMs. o Allowed cd(4)/vioscsi(4) on a VM to use confidential computing methods, e.g. AMD SEV. o Fixed a segfault in vmd(8) during vmmci timeout firing. o Enabled 32-bit direct kernel launch for both amd64 and i386 in vmd(8). o Fixed a race in vmd(8) vm pause barrier usage. o Fixed a race in vmm(4) vm termination path. o Added emulation of AMD SysCfg MSR in vmm(4). o Made OpenBSD work on Apple Virtualization. o Only expose pvclock(4) in vmm(4) if tsc frequency is known. o Reduced vmd(8) lowmem area in the memory map to help Linux guest reboot issues. o Prevented vmd(8) pause deadlock when vcpu doesn't halt. o Fixed timer emulation-related OpenBSD-i386 VM hangs when using the i8254 hardware timecounter with vmm(4). o Made vio(4) recover from missed RX interrupts. o Fixed vmd(8) vionet reset race leading to broken networking.
- Various new userland features: o Dynamically determine the possible partition names to show in the disklabel(8) editor a(dd) command help message. o Allow the disklabel(8) 'd'elete editor command to zero out FS_UNUSED partitions despite current value of d_npartitions. o Added display of the close-on-fork flag as 'f' in R/W column to fstat(1). o Added support for the XDG_RUNTIME_DIR environment variable in login(1) and xenodm(1) via login_cap(3). Set it by default, pointing to /tmp/run/user/${uid} which gets created if needed.
- More bugfixes and tweaks in userland: o Made libsndio restart the audio(4) device upon underrun. o Enable fall-back audio devices by default in sndiod(8). o Simplified the Unix socket binding code in sndiod(8). o Simplified cookie handling in libsndio. o Enabled recording and monitoring at the same time in sndiod(8). o In the LLVM compiler, fixed x86 frame lowering for -msave-args. o Made pthread_set_name_np(3) succeed with long thread names instead of silently failing. o Handle calls to libc's freeaddrinfo(3) function with a NULL argument, instead of crashing, and improve the manpage. o Made pcidump(8) print PCI bridge windows when they are "open". o Fixed an editline(3) bug that truncates completion candidates when the input wraps to a new line. o Added file(1) support for PSF2 fonts detection. o Added file(1) support for Web Open Font Format (WOFF) detection. o Fixed mg(1) replace-regexp issues. o Improved handling of strdup(3) failures in mg(1). o Improved the "No changes need to be saved" check in mg(1). o Dropped the initialization of curses when ksh(1) is not started interactively. This avoids opening and parsing of the terminfo(3) file. o Added echo(1) -e to process escape sequences and support for multiple groups of dash args like ksh's echo. o Increased the length of arguments that can be given to pkill(1). This allows matching of commands with longer command line arguments. o Made the -0 option override -E in xargs(1). o Set metaSendsEscape by default in xterm(1). o Fixed leap year detection in newsyslog(8). o Fixed less(1) crash on reading an invalid tags file. o Fixed a memory leak on sensorsd(8) configuration reload.
- Improved hardware support and driver bugfixes, including: o Tweaked PCI device power management such that drivers can change their own power state. Let xhci(4) power itself down such that its companion USB4 controller can go to sleep in its DVACT_POWERDOWN implementation. o Added nhi(4), a driver for USB4 controllers. o Added an audio(9) driver interface to expose the hardware's display name. o Changed envy(4) and uaudio(4) devices to return the product name as the display name. o Handle uaudio(4) devices with a single clock exposed in multiple domains. o Fixed unintended truncation of uaudio(4) device names when printing them in libsndio applications. o Improved acpi(4) handling of PCI bridges. o Implemented "StorageD3Enable" support in acpi(4). o Stopped acpi(4) from calling the PCI function when an AML node has neither _ADR nor _HID, and avoid a panic on the ThinkPad X40. o Added iasuskbd(4) support for special keys on the ASUS I2C laptop keyboards. o Added sgmsi(4), a driver for the MSI controller implementation on Sophgo SG2042 SoCs. o Added cdpcie(4), a driver for the Cadence PCIe controller, supporting the variant found on the Sophgo SG2042 SoC. o Added dwpcie(4) Qualcomm SC7280 support. o Added qcuart(4), a driver for Qualcomm GENI UART serial consoles. o Added smtgpio(4), a driver for the GPIO controller found on SpacemiT K1 SoCs. o Added rkusbdpphy(4), a driver for the USB DP Combo PHY on Rockchip SoCs. o Added support for blocking reads to fuse(4). o Added basic implementation of the low-level FUSE API sufficient to compile and run lowntfs-3g. o Allowed uhidev(4) to attach to and work with devices that don't have an input interrupt endpoint. o Added the ispi(4) driver for Intel LPSS SPI controller. o Added an Apple variant to the "de" keyboard encoding for wskbd(4). o Added acpihid(4), a driver for the Generic Buttons Device defined by the ACPI specification. o Made viogpu(4) viogpu_wsmmap() return a physical address via bus_dmamem_mmap(9). o Added support for "Apple Inc. Virtual USB Digitizer", to expose the touchpad on Apple Virtualization. o Added support for the PSP found on the AMD EPYC 9005 to psp(4). o Added support for the AlphaSmart Dana to uvisor(4) as a PALM4 device. o Added support for more line speeds to uplcom(4). o Added support for the RK3528 SoC to the dwmshc(4) eMMC controller driver. o In wscons(4) disallowed loading if mapchar emulops require a question mark character that is missing.
- New or improved network hardware support: o Fixed memory leaks in bnxt(4). o In umb(4), made uplink and downlink speeds visible through kstat(4). o Added support for Quectel EC200A LTE modems to umsm(4). o Added rge(4) support for RTL8126 chip revision 0x64a00000. o Turned on SoftLRO by default on bnxt(4) and ice(4). o Fixed the ice(4) "too many data commands" error on TSO packets. o Increased the urndis(4) buffer size to 16k. o Fixed an issue where dwqe(4), e.g. on a veb(4), doesn't recover when the link is down but packets are bridged. o Made the output of bse(4) mp-safe. o Enabled 64-bit DMA transfers on aq(4), em(4), rge(4), re(4), iavf(4), ix(4), ixv(4), ixl(4), igc(4), ice(4) and iwx(4). o Added support for BCM575xx devices (also known as Thor or P5) to bnxt(4). o Added smte(4), a driver for the ethernet interfaces of the SpacemiT K1 SoC.
- IEEE 802.11 wireless stack improvements and bugfixes: o Fixed association to access points which have all 802.11b rates disabled. o Updated ieee80211_classify() to RFC8325 to prioritize interactive SSH sessions correctly, and rate-limit high-prio QoS packets. o Initialized TIDs 4-7 to improve QoS behaviour during Tx aggregation. o Added basic 802.11ax support. o Added support for a 160 MHz window at 5 GHz and enabled it on iwx(4).
- Added or improved wireless network drivers: o Improved chances of qwx(4) receiving the initial WPA handshake message. o Reinitialized the qwx(4) HAL state when resuming from suspend. o Enabled iwx(4) on i386. o Added PMF (Protected Management Frames) support to iwm(4), iwx(4), and qwx(4), and add support for 802.11 AKM SHA256-PSK to ifconfig(8) and enable it by default if the driver supports PMF. o Fixed iwx(4) issues related to roaming and PMF and firmware crypto keys. o Set the assoc ID field in iwx(4) firmware commands correctly. o Added support for BZ devices with WiFi 6e radio to iwx(4). o Made iwx(4) not load incomplete firmware images and report a proper error instead. o Fixed iwn(4) setting of DMA base addresses of Tx rings 17 and beyond. o Added powersave support to iwx(4) and enable by default. o Added support for 160 MHz channel width to iwx(4). o Increased the VHT frame aggregation size limit from 64k to 1024k on iwx(4). o Aligned iwx(4) antenna patterns and STBC with iwlwifi.
- Installer, upgrade, bootloader, and pkg-tools improvements: o Allow installboot(8) to finish, even if efi(4) can't be accessed. o Made sysupgrade fail if df /usr says the filesystem is over 90% full, rather than potentially completely breaking the system. o Scan both dmesg.boot and dmesg(8) output for devices with fw_update(8). o On amd64, added support for loading files (kernels) from the EFI system partition. This means one can put the OpenBSD boot loader and bsd.rd on the EFI boot partition and run the installer that way. This already works on arm64. o Improved keydisk partition detection in the installer. o Added aggr(4) support to arm64 RAMDISK and i386/amd64 RAMDISK_CD. o Increased the auto-allocated partition size of /usr/obj in disklabel(8). o Floppy install users on i386/amd64 may find fw_update(8) for some drivers will not work because pci strings in the kernel have become too large.
- Security improvements: o Stop allowing root to bypass the effects of bpf(4) BIOCLOCK. BIOCLOCK is intended to remove the ability to reconfigure a BPF descriptor, but root processes were not subject to this revocation of privileges. No software relied on root being able to reconfigure a BPF descriptor, so this exemption was been removed. o Retired the pledge(2) 'tmppath' promise. The use of unveil /tmp rwc, unveil / r or similar together with pledge "rpath wpath cpath" replaces all use cases of 'tmppath' in a safer way. o Introduced the __pledge_open(2) system call, allowing libc to open a small set of tightly controlled internal files even when pledge(2) and unveil(2) would otherwise disallow direct access. File descriptors obtained this way are restricted to read-only use and cannot be used with write(2), chmod(2), chflags(2), chown(2), ftruncate(2), or fdpassing. This lets libc handle required devices, pledge-dependent files, and zoneinfo data without preserving the old pledge_namei() shortcut that allowed non-libc code to open the same special files. o In pledged processes, made /etc/localtime and /usr/share/zoneinfo scans much stricter. o In dig(1), fixed pledge/unveil issues relating to manual opening of /etc/resolv.conf. o Fixed unveil(2) to handle a filesystem that is mounted on a mount point that is itself the root of another filesystem. o Start fork(2)'ed children without a pgrp set (i.e. NULL) and update the pgrp pointer late to fix a potential race. o Do not expose p_addr kernel address through sysctl(2) unless root. o For sysctl({CTL_KERN, KERN_TTY, KERN_TTY_INFO), only export the t_session kernel address pointer if the caller is root.
- New features in the network stack: o Made the Virtual Ethernet Bridge veb(4) a VLAN-aware bridge. Ports in veb(4) now have a PVID (port VLAN identifier) used to determine which VLAN untagged packets get associated with, and a bitmap of allowed VIDs (VLAN IDs) that say what VLANs tagged traffic can interact with. Ports can be configured as "access" ports by only configuring a pvid but with no entries in the vid map, or as a "trunk" by disabling the pvid and adding entries to the vid map, or a "hybrid" port by configuring both a pvid and entries in the vid map. To maintain compatibility with existing (simple) setups, veb defaults to using pvid 1 on ports added to the bridge. o Added a LOCKED flag to veb(4) ports that are added to a bridge(4). This makes sure that the source MAC address of frames received by these ports has an entry in the fib/address cache pointing at the same interface. o In IPFIX/Netflow v10, added a NAT template with post-NAT source and destination IP address and ports, allowing use of pflow to track internal to external translations. o Enabled IPv6 autoconf (SLAAC) by default.
- Further changes and bugfixes in the network stack: o Implemented "checksum offload" between rport(4) pairs. This allows the kernel to skip ip/tcp/udp checksum calculation for packets between rdomains. o Implemented IFCAP_TSO in rport(4). This allows the stack to pass large tcp frames between rdomains. o In rport(4), made changes to use multiple txqs to spread traffic handling over softnet threads. o Fixed a panic when autodial (link1) on pppoe(4) tries to run. o Allowed bpf(4) in tun_dev_read to see VLAN tags when IFCAP_VLAN_HWTAGGING is enabled. o Added XOR and MOD operations to bpf(4). o Made tpmr(4) work with ether_offload_ifcap like veb(4) and bridge(4). o Added Private VLAN support to veb(4) as per RFC 5517. o Allowed VLAN tags (and therefore VLAN interfaces) on top of vports. o Made use of per-CPU refs in the input path instead of doing one refcnt per port to improve performance on tpmr(4), veb(4) and aggr(4). o Removed lacp support from trunk(4), now better supported by aggr(4). o Introduced a global interface queue limit. Limit all multiqueue network interfaces to common IF_MAX_VECTORS. Currently it is set to 8. One global limit helps to find an optimal value, stops wasting interrupt vectors, and clarifies what the actual hardware or driver limitations are. o Updated codel implementation to comply with RFCs 8289 and 8290. o Improved vio(4) feature negotiation for Large Receive Offload/TCP Segmentation Offload. o Prevented false ELOOP error in socket splicing with SO_SPLICE. o Made the network stack ignore TCP SACK packets with invalid sequence numbers to prevent potential kernel crash.
- The following changes were made to the pf(4) firewall: o Introduced source and state limiters in pf(4). See the Source Limiters section in pf.conf(5). o Extended pf(4) limiters so an administrator can specify the action the rule executes when limit is reached. o In pfctl(8), changed default limiter action from no-match to block. o Have pf(4) state and source limiter state cleanup assert on the right lock. o Fixed pfctl(8) with -nvf ... option to provide output which matches pfctl grammar for rules that use source/state limiters. o Print both nat-to and rdr-to in pfctl(8) show rules.
- Routing daemons, network services and other userland network programs saw the following improvements: o Do not log an error when dhcp6leased(8) cannot add a route because it already exists. o In dhcpleased(8), do not pass pointers over process privilege boundaries via imsg, only data. o Do not log an error when slaacd(8) cannot add a route because it already exists. o Fixed a buffer overflow reachable via rogue router advertisements in slaacd(8). o Prevented potential slaacd(8) crash if an attacker on the same layer 2 network sends rogue router advertisements. o Changed ospf6d(8) rc.d script to disallow reload, since ospf6d does not support it. o Fixed smtpd(8) dying if a malformed imsg is sent on the local socket. o Improved the logging of filter processing in smtpd(8). o Changed the default "tagged" operation for ifconfig(8) to add VLAN IDs rather than replace them. o Allowed the ifconfig(8) and brconfig(8) "tagged" operation to accept multiple VIDs and/or ranges of VIDs. o Added support for non-default config file paths to unbound(8) rc.d script. o In unwind(8), allow one to configure forced resolvers outside of preference blocks. o Added a "no banner" option to suppress the Server header in httpd(8). o Restored httpd(8) server_http_time() use of GMT. o Made httpd(8) error out on presence of Content-Length and Transfer-Encoding headers for GET, HEAD and other methods that should have no body. o Made relayd(8) and httpd(8) use the same internal log functions as bgpd(8) (and several other daemons). o Restored relayd(8) relay_http_time() use of GMT. o Added relayd(8) support for PROXY protocol in TCP relays. o Set a User-Agent in HTTP health checks sent by relayd(8). o Fixed a race condition in relayd(8) that could cause a crash during configuration reload. o Made relayd(8) support TLS with multiple listeners. o Fixed ftp(1) http_time() to use GMT, not UTC, per RFC 9110. o Report success in ftp(1) when a file is fully retrieved. o Made tcpdump(8) show the 802.11 QoS TID with -v. o Added printing of NetBIOS and DNS servers in IPCP to tcpdump(8). o Extended tcpdump(8) for printing of DHCPv6 information. o Made sure that internal counters do not go out of bounds if the -n or -A traceroute(8) options are specified more than once. o Raised rad(8) lifetimes for the router, DNS and NAT64 to 60 minutes and lower the prefix valid lifetime to 60 minutes. It does not make sense for one piece of information to time out before another when these are transmitted in one router advertisement packet. o Fixed a hang in rad(8) and slaacd(8) when they receive an RA from the local network with an ND option of length zero.
- acme-client(1) saw several changes: o Made acme-client(1) only display port numbers in Host headers when the port is not 443. o Added support for IP Address certificates in acme-client(1). o Made changes to use ASN1_STRING_* accessor functions instead of reaching into ASN1_STRING objects directly.
- In bgpd(8): o Rewrote the Adj-RIB-Out handling to be more memory efficient and faster. For large IXP route server deployments a reduction in memory usage of more than 50% should be feasible. o Process UPDATE messages in two phases: first update Adj-RIB-In, Loc-RIB, and FIB, then process all the Adj-RIB-Out tables. This significantly reduces the latency since updating all the Adj-RIB-Out tables could take a fair amount of time. o Introduced CH hash tables - a scalable hash map implementation that boosts performance through improved cache locality. o Introduce new metrics that track the amount of time spent in various parts of the main event loop of the route decision engine. o Fixed various non-critical things uncovered by Coverity scanner. o Improved outbound filter performance by storing the rules in an array and also deduplicate equal filters across peers. This and the filter_set change reduce the initial sync duration of large route servers by more than 25%. o Improved performance of filter_sets processing in the RDE process by moving to a linear array of set objects to reduce cache misses. o Added better logging for attribute parse errors which cause a session reset via UPDATE ATTRLIST error notification. o Introduced various additional memory metrics which are part of the 'show rib memory' command. Some values are also tracked per-neighbor and visible via 'show neighbor'. o Fixed logic error when handling per-peer and per-group MRT message dump configurations.
- In rpki-client(8): o The Canonical Cache Representation underwent a breaking change after the adoption of draft-ietf-sidrops-rpki-ccr as a SIDROPS working group item. Apart from several CMS-related cosmetics, it now uses an IANA-assigned content type. As a result, rpki-client 9.7 cannot parse rpki-client 9.6's .ccr files and vice versa. o Support for Ghostbusters Record objects (RFC 6493) has been removed. Nobody showed interest in deploying this and there are other, widely supported ways of exchanging operational contact information such as RDAP. RFC 6493 is undergoing a status review to be marked as historic: status-change-rpki-ghostbusters-record-to-historic o Prepare the code base for the opaque ASN1_STRING structure in OpenSSL 4. o Fixed two reliability issues: one where a malicious RPKI Certification Authority can trigger a crash, one where a malicious Trust Anchor can provoke memory exhaustion. Thanks to Xie Yifan for reporting. o Various refactoring for improved compatibility with various libcrypto implementations and in CA/BGPsec certificate handling. o Fixed an accounting issue in HTTP gzip compression detection. o Added a warning in extra verbose mode (-vv) about standards non-compliant Issuer and Subject ASN.1 string encodings. o Added a check for canonical encoding of ASPA eContent in alignment with draft-ietf-sidrops-aspa-profile-22. o Ensure that a repository timeout correctly stops repository processing. Thanks to Fedor Vompe from Deutsche Telekom for reporting. o Fixed a defect in Canonical Cache Representation ROAIPAddressFamily sort order. As a result, rpki-client 9.8 cannot parse rpki-client 9.7's .ccr files and vice versa. Thanks to Bart Bakker from RIPE NCC for reporting. o Fixed an issue in the parser for the locally configured constraints. Thanks to Daniel Anderson. o A malicious RRDP Publication Server can cause a NULL dereference. Thanks to Daniel Anderson for reporting. o A malicious RPKI Publication Server can cause an incorrect error exit. Thanks to Yuheng Zhang, Qi Wang, Jianjun Chen from Tsinghua University, and Teatime Lab for reporting.
- tmux(1) improvements and bug fixes: o Fixed the logic of the no-detached case for detach-on-destroy option. o Support case-insensitive search in tmux(1) modes in the same way as copy mode (like emacs, so all-lowercase means case insensitive). o Added -l flag to tmux(1) command-prompt to disable splitting into multiple prompts. o Allowed show-messages to work without a client. o Added seconds to tmux(1) clock mode. o Made tmux(1) clock mode seconds synchronized to the second. o Added support for synchronized output mode (DECSET 2026). o Added a focus-follows-mouse option. o Reduced request timeout to 500 milliseconds to match the extended escape time and discard palette requests if receiving a reply for a different index. o Added an -e flag to tmux(1) command-prompt to close if empty. o Fixed window-size=latest not resizing on switch-client in session groups. o Made tmux respond to DECRQM 2026. o Break out the sorting code into a common file so formats and modes use the same code and add -O for sorting to the list commands. o Added sorting (-O flag) and a custom format (-F) to list-keys. o Fixed several memory leaks. o Allow copy mode to work for readonly clients, except for copy commands. o Avoid a crash by checking for NULL before dereferencing. o Make -c (shell command) work with new-session -A. o Draw message as one format, allowing prompts and messages to occupy only a portion of the status bar, overlaying the normal status content rather than replacing the entire line. o Add a short built-in help text for each mode accessible with C-h. o Add extkeys feature to tmux(1) itself so nested tmux works. o Add -C flag to tmux(1) command-prompt to match display-message -C.
- LibreSSL version 4.3.0: o Portable changes - Rework portable assembly handling with LIBRESSL_USE_ASSEMBLY - Add SHA assembly for elf-aarch64 - Add definition of ssize_t to cms.h for Windows - Fix posix_open() implementation so it properly signals failure - Fix SIGALRM handler for openssl speed on Windows o Internal improvements - Remove the unused sequence number from X509_REVOKED. - Replace a call to atoi(3) with strtonum(3) in nc(1) and replace a misleading use of ntohs(3) with htons(3). - openssl(1) speed now uses HMAC-SHA256 for its hmac benchmark. - Reimplemented only use of ASN1_PRINTABLE_type() in openssl(1) ca. The API will be removed in an upcoming release. - Add curve NID to EC_POINT objects so the library has a clue on which curve a given EC_POINT is supposed to live. - Use curve NID to check for compatibility between group and points in various EC API. This isn't 100% failsafe but good enough for sane uses. - Require SSE in order to use gcm_{gmult,ghash}_4bit_mmx(). On rare i386 machines supporting MMX but not SSE this could result in an illegal instruction. - Cleaned up asn1t.h to make it somewhat readable and more robust by using C99 initializers in particular. - Further assembly macro improvements for -portable. - Add fast path for well-known DH primes in DH_check(3) (including those from RFC 7919). Some projects still fiddle with this in 2025. - Rewrite ec_point_cmp() for readability and robustness. - Improve EVP_{Open,Seal}Init(3) internals. This is legacy API that cannot be removed since one scripting language still exposes it. - ASN1_BIT_STRING_set_bit(3) now trims trailing zero bits itself rather than relying on i2c_ASN1_BIT_STRING(3) to do that when encoding. - Fix and add workarounds to libtls to improve const correctness and to avoid warnings when compiling with OpenSSL 4. - Prefix EC_KEY methods with ec_key_ to avoid problems in some static links. - Remove mac_packet, a leftover from accepting SSLv2 ClientHellos. - Remove ssl_server_legacy_first_packet(). - In addition to what was done in LibreSSL 4.0 for the version handling, disable TLSv1.1 and lower also on the method level. - Remove workaround for SSL 3.0/TLS 1.0 CBC vulnerability. - Refactor ocsp_find_signer_sk() to avoid neglecting the ASN.1's semantics by directly reaching into deeply nested OCSP structures. o Compatibility changes - Expose X509_VERIFY_PARAM_set_hostflags(3) as a public symbol. - Provide SSL_SESSION_dup(3). - BIGNUMs now use the C99 types uint64_t/uint32_t for the word width. Fixes long-standing issues with 32-bit longs on 64-bit Windows. - Many unused BN_* macros with incomprehensible names were removed: BN_LONG, BN_BITS{,4}, BN_MASK2{,l,h,h1}, BN_TBIT, BN_DEC_CONV, BN_{DEC,HEX}_FMT{1,2}, ... - openssl(1) cms no longer accepts the unsupported -compress and -uncompress switches. - Added PKCS7_NO_DUAL_CONTENT flag/behavior. This is incorrect legacy behavior but some language bindings decided to rely on it in 2025. - Remove STABLE_FLAGS_MALLOC but keep STABLE_NO_MASK because there is still one user... - Fix ASN1_ADB_END macro to have compatible signature with OpenSSL. The adb_cb() argument is currently ignored. - Unexport ASN1_LONG_UNDEF. o New features - Support for MLKEM768_X25519 keyshare in TLS. - Added ML-KEM benchmarks to openssl(1) speed. - Added support for starttls protocol sieve. - Add support for RSASSA-PSS with pubkey OID RSASSA-PSS to libssl. o Bug fixes - Ensure the group selected by a TLSv1.3 server for a HelloRetryRequest is not one for which the client has already sent a key share. - Plug memory leak in CMS_EncryptedData_encrypt(3). - Plug possible memory leak and double free in nref_nos(). - Removed always zero test results for some no longer available legacy primitives in openssl(1) speed. - List SHA-3 digests in openssl(1) help output. - Fix encoding of bit strings with trailing zeroes on which ASN1_STRING_FLAG_BITS_LEFT is not set. - Add missing NULL pointer check to PKCS12_item_decrypt_d2i(3). - Avoid type confusion leading to 1-byte read at address 0x00-0xff in PKCS#12 parsing. - Fix type confusion in timestamp response parsing for v2 signing certs. - Fix EVP_SealInit(3) to return 0 on error, not -1. - Replace incorrect strncmp(3) with strcmp(3) in CRL distribution point config parsing. - openssl x509 -text writes its output to the file specified by -out like all other openssl(1) subcommands. - Stop Delta CRL processing in the verifier if the cRLNumber is missing. This is flagged on deserialization, but nothing checks that flag. This can lead to a NULL dereference if the verification has enabled Delta CRL checking by setting X509_V_FLAG_USE_DELTAS. - Fix NULL dereference that can be triggered with malformed OAEP parameter encoding for CMS decryption. - Add missing length checks before BIO_new_mem_buf(3) in libtls. - Improve libtls error reporting consistency, avoid reporting unrelated errnos. - Fix SAN dNSName constraints: instead of substring matching, match exactly and allow zero or more components in front of the candidate. o Reliability fix - Fix off-by-one error in the X.509 verifier depth checking. This can lead to a 4-byte overwrite on heap allocated memory for clients talking to a malicious server or for servers that have client certificate verification enabled. In addition, the maximum depth must be set to the maximum allowed value of 32. o Testing and proactive security - Port Wycheproof tests to testvectors_v1 and improve coverage and correctness. Add tests for ML-KEM in particular.
- OpenSSH 10.3: o Security fixes: - ssh(1): validation of shell metacharacters in user names supplied on the command-line was performed too late to prevent some situations where they could be expanded from %-tokens in ssh_config. For certain configurations, such as those that use a "%u" token in a "Match exec" block, an attacker who can control the user name passed to ssh(1) could potentially execute arbitrary shell commands. Reported by Florian Kohnhäuser. We continue to recommend against directly exposing ssh(1) and other tools' command-lines to untrusted input. Mitigations such as this cannot be absolute given the variety of shells and user configurations in use. - sshd(8): when matching an authorized_keys principals="" option against a list of principals in a certificate, an incorrect algorithm was used that could allow inappropriate matching in cases where a principal name in the certificate contains a comma character. Exploitation of the condition requires an authorized_keys principals="" option that lists more than one principal *and* a CA that will issue a certificate that encodes more than one of these principal names separated by a comma (typical CAs strongly constrain which principal names they will place in a certificate). This condition only applies to user- trusted CA keys in authorized_keys, the main certificate authentication path (TrustedUserCAKeys/AuthorizedPrincipalsFile) is not affected. Reported by Vladimir Tokarev. - scp(1): when downloading files as root in legacy (-O) mode and without the -p (preserve modes) flag set, scp did not clear setuid/setgid bits from downloaded files as one might typically expect. This bug dates back to the original Berkeley rcp program. Reported by Christos Papakonstantinou of Cantina and Spearbit. - sshd(8): fix incomplete application of PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms with regard to ECDSA keys. Previously if one of these directives contains any ECDSA algorithm name (say "ecdsa-sha2-nistp384"), then any other ECDSA algorithm would be accepted in its place regardless of whether it was listed or not. Reported by Christos Papakonstantinou of Cantina and Spearbit. - ssh(1): connection multiplexing confirmation (requested using "ControlMaster ask/autoask") was not being tested for proxy mode multiplexing sessions (i.e. "ssh -O proxy ..."). Reported by Michalis Vasileiadis. o Potentially incompatible changes: - ssh(1), sshd(8): remove bug compatibility for implementations that don't support rekeying. If such an implementation tries to interoperate with OpenSSH, it will now eventually fail when the transport needs rekeying. - sshd(8): prior to this release, a certificate that had an empty principals section would be treated as matching any principal (i.e. as a wildcard) when used via authorized_keys principals="" option. This was intentional, but created a surprising and potentially risky situation if a CA accidentally issued a certificate with an empty principals section: instead of being useless as one might expect, it could be used to authenticate as any user who trusted the CA via authorized_keys. [Note that this condition did not apply to CAs trusted via the sshd_config(5) TrustedUserCAKeys option.] This release treats an empty principals section as never matching any principal, and also fixes interpretation of wildcard characters in certificate principals. Now they are consistently implemented for host certificates and not supported for user certificates. - ssh(1): the -J and equivalent -oProxyJump="..." options now validate user and host names for ProxyJump/-J options passed via the command-line (no such validation is performed for this option in configuration files). This prevents shell injection in situations where these were directly exposed to adversarial input, which would have been a terrible idea to begin with. Reported by rabbit. o New features: - ssh(1), sshd(8): support IANA-assigned codepoints for SSH agent forwarding, as per draft-ietf-sshm-ssh-agent. Support for the new names is advertised via the EXT_INFO message. If a server offers support for the new names, then they are used preferentially. Support for the pre-standardisation "@openssh.com" extensions for agent forwarding remains supported. - ssh-agent(1): implement support for draft-ietf-sshm-ssh-agent "query" extension. - ssh-add(1): support querying the protocol extensions via the agent "query" extension with a new -Q flag. - ssh(1): support multiple files in ssh_config and sshd_config RevokedHostKeys directive. bz3918 - ssh(1): add a ~I escape option that shows information about the current SSH connection. - ssh(1): add an "ssh -Oconninfo user@host" multiplexing command that shows connection information, similar to the ~I escapechar. - ssh(1): add an ssh -O channels user@host multiplexing command to get a running mux process to show information about what channels are currently open. - sshd(8): add invaliduser penalty to PerSourcePenalties, which is applied to login attempts for usernames that do not match real accounts. Defaults to 5s to match 'authfail' but allows administrators to block such attempts for longer if desired. - sshd(8): add a GSSAPIDelegateCredentials option for the server, controlling whether it accepts delegated credentials offered by the client. This option mirrors the same option in ssh_config. - ssh(1), sshd(8): support the VA DSCP codepoint in the IPQoS directive. - sshd(8): convert PerSourcePenalties to using floating point time, allowing penalties to be less than a second. This is useful if you need to penalise things you expect to occur at >=1 QPS. - ssh-keygen(1): support writing ED25519 keys in PKCS8 format. - Support the ed25519 signature scheme via libcrypto. o Bugfixes: - sshd(8): make IPQoS first-match-wins in sshd_config, like other configuration directives. bz3924 - sshd(8): fix potential crash when MaxStartups is set to a single argument (i.e. not using the MaxStartups x:y:z form) with a value below 10. bz3941 - sshd(8): fix a potential hang during key exchange if needed DH group values were missing from /etc/moduli. - ssh-agent(1): fix return values from extensions to be correct with respect to draft-ietf-sshm-ssh-agent: extension requests should indicate failure using SSH_AGENT_EXTENSION_FAILURE rather than the generic SSH_AGENT_FAILURE error code. This allows the client to discern between "the request failed" and "the agent doesn't support this extension". - ssh(1): use fmprintf for showing challenge-response name and info to preserve UTF-8 characters where appropriate. - scp(1): when uploading a directory using SFTP (e.g. during a recursive transfer), don't clobber the remote directory permissions unless either we created the directory during the transfer or the -p flag was set. bz3925 - All: implement missing pieces of FIDO/webauthn signature support, mostly related to certificate handling and enable acceptance of this signature format by default. bz3748 - sshd_config(5): make it clear that DenyUsers/DenyGroups overrides AllowUsers/AllowGroups. Previously we specified the order in which the directives are processed but it was ambiguous as to what happened if both matched. - ssh(1): don't try to match certificates held in an agent to private keys. This matching is done to support certificates that were loaded without their private key material, but is unnecessary for agent-hosted certificates, which always have private key material available in the agent. Worse, this matching would mess up the request sent to the agent in such a way as to break usage of these keys when the key usage was restricted in the agent. bz3752 - sftp(1): if editline has been switched to vi mode (i.e. via "bind -v" in .editrc), set up a keybinding so that command mode can be entered. - ssh(1), sshd(8): improve performance of keying the sntrup761 key agreement algorithm. - ssh(1), sshd(8): enforce maximum packet/block limit during pre-authentication phase. - sftp(1): don't misuse the sftp limits extension's open-handles field. This value is supposed to be the number of handles a server will allow to be opened and not a number of outstanding read/write requests that can be sent during an upload/download. - sshd(8): don't crash at connection time if the main sshd_config lacks any subsystem directive but one is defined in a Match block. bz3906 - sshd_config(5): add a warning next to the ForceCommand directive that forcing a command doesn't automatically disable forwarding. - sshd_config(5): add a warning that TOKENS are replaced without filtering or escaping and that it's the administrator's responsibility to ensure they are used safely in context. - scp(1): correctly quote filenames in verbose output for local->local copies. bz3900 - sshd(8): don't mess up the PerSourceNetBlockSize IPv6 mask if sscanf didn't decode it. - ssh-add(1): when loading FIDO2 resident keys, set the comment to the FIDO application string. This matches the behaviour of ssh-keygen -K. - sshd(8): don't strnvis() log messages that are going to be logged by sshd-auth via its parent sshd-session process, as the parent will also run them through strnvis(). Prevents double-escaping of non-printing characters in some log messages. bz3896 - ssh-agent(1): escape SSH_AUTH_SOCK paths that are sent to the shell as setenv commands. Unbreaks ssh-agent for home directory paths that contain whitespace. bz3884 - All: Remove unnecessary checks for ECDSA public key validity. - sshd(8): activate UnusedConnectionTimeout only after the last channel has closed. Previously UnusedConnectionTimeout could fire early after a ChannelTimeout. This was not a problem for the OpenSSH client because it terminates once all channels have closed but could cause problems for other clients (e.g. API clients) that do things differently. bz3827 - All: fix PKCS#11 key PIN entry problems introduced in openssh-10.1/10.2. bz3879 - scp(1): when using the SFTP protocol for transfers, fix implicit destination path selection when source path ends with "..". bz3871 - sftp(1): when tab-completing a filename, ensure that the completed string does not end up mid-way through a multibyte character, as this will cause a fatal() later on. - ssh-keygen(1): fix crash at exit (visible via ssh-keygen -D) when multiple keys loaded. - scp(1)/sftp(1): correctly display bandwidths greater than 2 GBps in the progress meter.
- Ports and packages: o Pre-built packages are available for the following architectures on the day of release: - aarch64 (arm64): 12883 - amd64: 13044 - i386: 10631 - mips64: 9309 - powerpc64: 9507 - sparc64: 10079 o Packages for the following architectures will be made available as their builds complete: - arm - powerpc - riscv64
- Some highlights:
o Asterisk 16.30.1, 18.26.4, o Mutt 2.3.1 and NeoMutt 20260406 20.19.0 and 22.9.0 o Node.js 22.22.2 o Audacity 3.7.7 o OCaml 4.14.2 o CMake 4.2.3 o OpenLDAP 2.6.13 o Chromium 147.0.7727.101 o PHP 8.2.30, 8.3.30, 8.4.20 and o Emacs 30.2 8.5.5 o FFmpeg 8.0.1 o Postfix 3.5.25 and 3.11.1 o GCC 15.2.0 o PostgreSQL 18.3 o GHC 9.10.3 o Python 2.7.18 and 3.13.13 o GNOME 49 o Qt 5.15.18 (+ kde patches) and o Go 1.26.2 6.10.2 o JDK 11.0.30, 17.0.18, 21.0.10, o R 4.5.2 25.0.2 o Ruby 3.3.11, 3.4.9 and 4.0.2 o KDE Applications 25.12.3 o Rust 1.94.1 o KDE Frameworks 6.23.0 o SQLite 3.51.3 o KDE Plasma 6.6.4 o Shotcut 26.2.26 o Krita 5.2.16 o Sudo 1.9.17p2 o LLVM/Clang 19.1.7, 20.1.8 o Suricata 7.0.7 21.1.8 o Tcl/Tk 8.5.19. 8.6.17 and 9.0.3 o LibreOffice 26.2.2.2 o TeX Live 2025 o Lua 5.1.5, 5.2.4, 5.3.6 and o Vim 9.2.0357 and Neovim 0.12.1 5.4.8 o Vulkan 1.4.341.0 o MariaDB 11.4.10 o Wayland 1.24.0 with compositors o Mono 6.14.1 Labwc, Mango, Niri, Sway and o Mozilla Firefox 150.0 and Wayfire ESR 140.10.0 o Xfce 4.20.0 o Mozilla Thunderbird 140.10.0
- As usual, steady improvements in manual pages and other documentation.
- The system includes the following major components from outside suppliers: o Xenocara (based on X.Org 7.7 with xserver 21.1.21 + patches, freetype 2.14.2, fontconfig 2.17.1, Mesa 25.0.7, xterm 406, xkeyboard-config 2.20, fonttosfnt 1.2.4, and more) o LLVM/Clang 19.1.7 (+ patches) o GCC 4.2.1 (+ patches) o Perl 5.42.2 (+ patches) o pkgconf 2.4.3 o NSD 4.14.2 o Unbound 1.24.2 o Ncurses 6.4 o Binutils 2.17 (+ patches) o Gdb 6.3 (+ patches) o Awk 20250116 o Expat 2.7.5 o zlib 1.3.2 (+ patches)

Read on

Set of links:

LWN:

Other Recent Tux Machines' Posts

Arch’s AUR Besieged
3 more reports
NetBSD 11.0 released
new release this week
Linux's market share in North America has breached 10% for the first time, says StatCounter
Linux usage has been growing since May and has now managed to cross over into the double-digit levels of market share
GNU/Linux at 5% in Taiwan This Month [original]
In China too, GNU/Linux has been gaining lately
 
Rhythmbox 3.5 Media Player Improves Lyrics Search and Podcast Support
Rhythmbox 3.5 open-source media player is now available for download with improvements to lyrics search, podcast support, and the new playback backend. Here’s what’s new!
Only Bad Parents Expose Children to Slop [original]
This too shall pass
GNU/Linux Measured as Higher Than What Blogs Reported Over the Weekend [original]
We'll try to break things down by nation/s as the days of the month go by
So What If GNU/Linux is Measured at 9% Worldwide? [original]
Windows has sunk like a rock
NVIDIA 610.57.04 Linux Graphics Driver Improves Support for Many Games
NVIDIA 610.57.04 graphics driver is now available for download with many bug fixes that improve support for multiple video games, as well as the overall performance and stability.
Free, Libre, and Open Source Software, Development Leftovers
FOSS and coding
GNU/Linux and BSD Leftovers
mostly GNU/Linux
Kernel: Linux 7.3, Zen 5, RDNA 5
graphics also
today's howtos
3 howtos
Games: Steam Deck, Doom, EEG as an Interface for User
gaming picks
KDE: Drawy in GSoC 2026, KDE developer fixes major Linux eGPU performance bottleneck
KDE picks
Open Hardware/Modding: KVM Without The V and More
mostly Hackaday articles
Your Computer Is About to Demand Your Age Before You Can Use It. Here's Why
Age verification laws aren't stopping at social media and porn
Slippery Slop and Letting Slop Control GNU/Linux PCs
two new articles
Audiocasts/Shows: LINUX Unplugged 678 and mintCast
2 new episodes
Linux 7.2-rc6
the biggest rc6 we've had in years
Programming Leftovers
Development picks
Android Leftovers
Android 17 QPR2 Beta 1 is randomly sending Pixels to a date that doesn't exist
Linux back over 4% in the July 2026 Steam Survey
The Steam Hardware & Software Survey for July 2026 is out now and going by the current data
3 reasons I'm quitting Arch Linux—after using it for 5 years
I've been using Linux for a decade now, and around the five-year mark
These 5 lightweight Linux distros make Windows feel so bloated
While many people think Linux performs better than Windows
Rhythmbox 3.5.0 Released with Multistream Backend By Default
Rhythmbox, the default music player in Ubuntu (Extended selection), released new 3.5.0 version today
GNOME to Support Uninstalling Apps Directly from App Grid
GNOME is going to support uninstalling applications directly from the App Grid, by adding “Uninstall” option to app icons’ right-click menu
Free and Open Source Software
This is free and open source software
PersisOS – Debian-based Linux distribution
This is free and open source software
Review: Mageia 10
Mageia was originally a fork of Mandriva Linux, formed in September 2010 by former employees and contributors to the popular French Linux distribution
This month in KDE Linux: June 2026
Welcome to another edition of “This month in KDE Linux” — KDE’s in-progress operating system
GNU/Linux Leaps to 6.2% in Ecuador [original]
In the past, Ecuador offered asylum (then citizenship) to Julian Assange, who had been politically persecuted
Lucy Powell MP Helps Her Constituents [original]
Not all politicians are the same
9to5Linux Weekly Roundup: August 2nd, 2026
The 303rd installment of the 9to5Linux Weekly Roundup is here for the week ending August 2nd, 2026.
Today in Techrights
Some of the latest articles
AerynOS 2026.08 Released with Linux 7.1, GNOME 50.3, COSMIC 1.5, and More
AerynOS 2026.08 independently-develop distribution is now available for download with GNOME 50.3, KDE Plasma 6.7.3, COSMIC 1.5, Linux kernel 7.1, package management improvements, and other changes.
According to statCounter, GNU/Linux Measured at Nearly 8% in Bangladesh [original]
Earlier today statCounter finalised the figures for July
Climate Change on Our Minds [original]
useless chatbots
Switzerland's GNU/Linux "Market Share" at 7% [original]
Europe in general is moving that way
GNU/Linux Measured at 7.3% in Saudi Arabia [original]
Can it exceed 10% this year?
I switched an old laptop to a RAM-only OS and it outpaced my newer machine
Not too long ago, I revived an old 2012 HP Pavilion m6 with Puppy Linux
COSMIC is doing what GNOME still can't, and it's only been out for a year
COSMIC has really taken me by surprise. Compared to other Linux desktop environments
GNOME's extension problem is worse than you think, and it's why I switched to KDE
I've used GNOME for years, both before and after the retirement of the wonderful Unity on Ubuntu
Australia and New Zealand: New Highs for GNU/Linux [original]
steady increases for GNU/Linux
In Republic of South Korea GNU/Linux Has Reached a New High [original]
Can these figures exceed 5% like in Japan?
Gentoo-Based MocaccinoOS 26.08 Is Out with COSMIC 1.5, KDE Plasma 6.6.6
MocaccinoOS 26.08 distribution is now available for download with the COSMIC 1.5 and KDE Plasma 6.6.6 desktop environments, Mesa 26.1.5 graphics stack, and Linux 6.18.41 LTS.
AstrOS, a distro that combines the best of Arch, COSMIC, and immutability, enters beta
One of the cooler parts of moving from Windows to Linux is that there's always something new on the horizon
GNU/Linux Measured at Around 6% in Ireland [original]
Notice how much GNU/Linux grew there lately
BeOS was the most innovative OS of the '90s—here is how it lives on today
BeOS still changed computing history, even though it was a flop. You can also install a successor today
GNU/Linux Steady at About 5% in South America [original]
We'll be keeping an eye on this trend
Free, Libre, and Open Source Software Leftovers
FOSS leftovers
GNU/Linux Leftovers
GNU/Linux stories for the day
KDE and GNOME: KDE Itinerary and GNOME Shell
3 more stories
Graphics and Games Leftovers
mostly AMD
Debian: Meme, SparkyLinux, and "The State of Chez Scheme in Debian"
Debian leftovers
Open Hardware and GNU/Linux Devices
hardware stories
today's howtos
Instructionals/Technical picks
Audiocasts/Shows: Linux Saloon and Discussion About Text Editors
2 episodes
Security, Slop, and Slop About Slop (FUD About "Linux")
Security leftovers
From Soccermania to GNU/Linux Mania [original]
Did the soccer (football) matches have some impact or just the "unknowns" being deciphered (or omitted) by statCounter?
5 things nobody tells you about switching to Linux from Windows
Frustrated with Windows and considering switching to Linux
Free and Open Source Software
This is free and open source software
One of the World's Largest Populations, Indonesia, Sees GNU/Linux Measured at Over 6% [original]
Maybe by month's end it'll be over 6.5%
GNU/Linux New Highs in Europe, Microsoft New Lows [original]
Europe is moving away from GAFAM, especially the "M" in GAFAM
Tux Machines Benefits From Explosive Growth of GNU/Linux [original]
Big gains at last?
I refuse to pay Microsoft for these 7 features that Linux offers for free
Linux is pretty impressive, and its greatest feature is arguably its cost
Programming Leftovers
Development picks
Shotcut 26.7 Video Editor Adds Graphics Adapter for Linux, Shake Video Filter
Shotcut 26.7 open-source video editor is now available for download with a graphics adapter for Linux and Windows, Shake video filter, improved support for VST2 and LV2 audio plugins, and more.
New Releases Archcraft's August 2026 Release and Announcing Helwan Linux 5.0
2 new releases
today's howtos
PCLinuxOS Magazine picks
Recent GNU/Linux Videos
via Indivious
Free and Open Source Software
This is free and open source software
Anolis OS – enterprise-focused Linux distribution
Anolis OS is an enterprise-focused Linux distribution
Planet KDE: June/July in KDE Itinerary
Time for another bi-monthly update on what happened around Itinerary
Beverly Hills [original]
we have a new mayor
Today in Techrights
Some of the latest articles
Synex 13 u11 Released With Multiple Desktop Options
The Argentinian Linux distribution continues its minimalist approach with updated packages, new COSMIC changes
Fedora Linux 45 to Enable Shadow Stack Protection by Default on 64-Bit
The Fedora Linux 45 distribution will enable Shadow Stack protection by default for most applications on x86_64 machines at negligible performance cost.
Birthday in 3 Weeks [original]
In August we expect speed to go up another notch
Much Ado About AUR [original]
This is applicable to every platform, not just "Linux"
Doing What's Natural [original]
According to some reports, birding is making a comeback among young people
New Debian 13 “Trixie” Kernel Security Update Fixes 68 Vulnerabilities
A new Linux kernel security update has been released for Debian GNU/Linux 13 “Trixie” to fix no less than 68 vulnerabilities.
Today in Techrights
Some of the latest articles
Ubuntu Touch update brings better support for modern smartphones & web apps
Ubuntu Touch is a mobile Linux distribution designed to run on smartphones and tablets
Mozilla Firefox 153.0.1 Web Browser Brings Fixes for Multiple Issues and Crashes
Firefox 153.0.1 open-source web browser is now available for download to fix multiple issues and crashes discovered in the Firefox 153 release and affecting all users.
Only the Kernel is Turning 35, GNU/Linux Will Turn 43 This Year [original]
If we focus on the design, it started not in the 90s but the 60s
PCLinuxOS: Chief Editor, Screenshots, and in Memoriam (JayDot)
PCLinuxOS Magazine picks
PCLinuxOS Magazine on Kernel Turning 35 This Month
2 articles updated
Arch Linux-Based Archcraft 26.08 Brings New Sway Wayland Session, Linux 7.1
Archcraft 26.08 distribution is now available for download with Linux kernel 7.1, new Qt 6 SDDM theme, new Sway Wayland session, and better GTK/GNOME application integration.
NethSecurity 8.8.0: Geoblocking, Alerts, metrics, emergency CLI tool
the release of NethSecurity 8.8.0
EmmaDE6 1.02: Accessibility Improvements
update to Emmabuntüs Debian Edition 6 1.0 2 64-bit
July Over, GNU/Linux Catches Up With MacOS, statCounter Measures Its Market Share at ~8% [original]
GNU/Linux is growing, irrespective of what statCounter says
Security Leftovers
Security reports and more
today's leftovers
GNU/Linux and more
Free, Libre, and Open Source Software Leftovers and Sharing Advocacy
FOSS and more
GNU nano 9.2 and GNU's GCC De Facto Banning Slop
GNU picks
Servo 0.4.0 released
some Servo news
Software News/Review: Resources, Gradia, and Kitty Terminal Emulator
Applications for GNU/Linux
New Release of EasyOS and Further Changes
EasyOS news picks
KDE Community, This Week in GNOME, and GNOME Shell
KDE and GNOME leftovers
Programming Leftovers
Development picks
Red Hat: PHP, Slop, and More
Red Hat's official site mostly
FreeBSD and OpenBSD Picks
BSD leftovers
Games: Steam, GPUs, and Thimbleweed Park 2
gaming news
Linux Kernel and Graphics Leftovers
also LF stuff
Much Ado Over AMD Linux Patch (Because of Steam Deck)
Steam Deck and more
today's howtos
Instructionals/Technical posts
Linux Gadgets, Hardware, and Devices
mostly Open Hardware
First Arch Linux ISO Powered by Linux Kernel 7.1 Is Now Available for Download
Arch Linux 2026.08.01 is now available for download as Arch Linux’s ISO release for August 2026, powered by Linux kernel 7.1 and featuring the latest Archinstall 4.4 text-mode installer
And Folks, We Have a Vibe Coded Linux Distro!
Starling is a new open source Linux desktop environment
Moving Faster [original]
Speed is particularly important in particular contexts
His First Match With First Team [original]
Will the Italian coach stay in charge for another decade to come?
Mayoral Election in Greater Manchester is a Win in Battle Against Discrimination (Hostility Towards Women) and Against Opponents of Gay People [original]
We find this whole thing rather symbolic
Sweep-Sweep, Hoarding Like a Proprietary Software Company [original]
Some are bullies and the rest try to clean up the bullies' mess
Match Day [original]
New management (Maresca is head coach, not management) will make or break what brought 20 trophies/brass in one decade
Android Leftovers
Google rolling out Android 17 QPR1 Beta 8 for Pixel
Free and Open Source Software
This is free and open source software
PureOS Development Report: June 2026
PureOS is designed to provide the best experience on all Purism devices
This Week in Plasma: Emoji Resizing
In addition to the headliner feature and expected UI improvements and bug fixes
4MLinux 52.0 Released with Better Support for Legacy GPUs, Linux Kernel 6.18 LTS
4MLinux 52.0 distribution is now available for download with improved support for legacy graphics cards, simplified Wi-Fi configuration, and other changes.