<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"
    		xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>LWN.net</title>
        <link>https://lwn.net</link>
        <description> LWN.net is a comprehensive source of news and opinions from
        and about the Linux community.  This is the main LWN.net feed,
        listing all articles which are posted to the site front page.
</description>
        <language>en-us</language>
        <pubDate>Fri, 05 Jun 2026 02:31:11 +0000</pubDate>
        <lastBuildDate>Fri, 05 Jun 2026 02:31:11 +0000</lastBuildDate>
        <docs>https://www.rssboard.org/rss-specification</docs>
        <webMaster>lwn@lwn.net</webMaster>
        <atom:link href="https://lwn.net/headlines/rss2"
    		rel="self" type="application/rss+xml"/>
    <item>
        <title>Dave Airlie on Linux Kernel Maintenance (SE Radio)</title>
        <link>https://lwn.net/Articles/1076478/</link>
        <guid>https://lwn.net/Articles/1076478/</guid>
        <dc:creator>corbet</dc:creator>
        <description>The Software Engineering Radio podcast has put up &lt;a
href=&quot;https://se-radio.net/2026/06/se-radio-723-dave-airlie-on-linux-kernel-maintenance/&quot;&gt;an
interview with graphics maintainer Dave Airlie&lt;/a&gt;.  Much of what is in
there will not be news to LWN readers, but it is an interesting overview of
the life of a large-subsystem maintainer.
&lt;p&gt;
&lt;blockquote class=&quot;bq&quot;&gt;
	I was talking to a few of the Rust people, and I thought: these are
	very young people, these are a group of people in their 20s, maybe
	30s, they are a younger cohort of developers than the people I am
	normally used to dealing with.  I thought there was maybe a good
	way we could bring these groups together.  I think that having
	young people coming into the kernel using Rust is valuable...  So I
	thought that I should be supportive of bringing Rust into the
	kernel.
&lt;/blockquote&gt;</description>
        <pubDate>Thu, 04 Jun 2026 22:22:17 +0000</pubDate>
        </item>
        <item>
        <title>[$] Splicing out vmsplice()</title>
        <link>https://lwn.net/Articles/1075838/</link>
        <guid>https://lwn.net/Articles/1075838/</guid>
        <dc:creator>corbet</dc:creator>
        <description>The &lt;a
href=&quot;https://man7.org/linux/man-pages/man2/splice.2.html&quot;&gt;&lt;tt&gt;splice()&lt;/tt&gt;&lt;/a&gt;
and &lt;a
href=&quot;https://man7.org/linux/man-pages/man2/vmsplice.2.html&quot;&gt;&lt;tt&gt;vmsplice()&lt;/tt&gt;&lt;/a&gt;
system calls are meant to improve performance for certain data-movement
tasks by minimizing (or avoiding altogether) system calls and the copying
of data.  They also have a long history of security problems.  The recent
flood of LLM-discovered vulnerabilities has drawn attention, once again, to
&lt;tt&gt;splice()&lt;/tt&gt; and &lt;tt&gt;vmsplice()&lt;/tt&gt;; as a result, they may end up
being removed altogether.
</description>
        <pubDate>Thu, 04 Jun 2026 16:22:46 +0000</pubDate>
        </item>
        <item>
        <title>One step forward, two steps back on CA age bill (EFF Deeplinks Blog)</title>
        <link>https://lwn.net/Articles/1076377/</link>
        <guid>https://lwn.net/Articles/1076377/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;The EFF has a &lt;a
href=&quot;https://www.eff.org/deeplinks/2026/05/one-step-forward-two-steps-back-cas-ab-1856-exempts-open-source-expands-age-gating&quot;&gt;blog
post&lt;/a&gt; looking at a new bill in California that would exempt
open-source operating systems from the Digital Age Assurance Act
passed last year, but has problems of its own:&lt;/p&gt;

&lt;blockquote class=&quot;bq&quot;&gt;
&lt;p&gt;While the open source exemption, if passed, would improve the law, the
remaining amendments proposed by AB 1856 would require all web
browsers and websites to request and collect users' ages. This is an
expansion of last year's AB 1043's age-bracketing system that
compounds its constitutional harms to users' speech, privacy, and
security.&lt;/p&gt;

&lt;p&gt;[...] EFF understands this amendment to exempt open-source
operating systems from the requirement to collect and transmit users'
age-bracket data. That is a definite win for open-source
developers. The bill is narrower now than it was before, and lawmakers
clearly responded to concerns raised by EFF and the broader
open-source community.&lt;/p&gt;

&lt;p&gt;Some important questions still remain—for example, it is unclear
how the law would apply when an open-source operating system is
incorporated into a commercial product or service. And, given the
structure of where the exemption is placed under the &quot;operating system
provider&quot; definition, lawmakers could stand to clarify that the
exemption applies to open-source operating systems and
applications.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;LWN &lt;a href=&quot;https://lwn.net/Articles/1064706/&quot;&gt;covered&lt;/a&gt;
California's age-attestation law in March.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;</description>
        <pubDate>Thu, 04 Jun 2026 14:53:00 +0000</pubDate>
        </item>
        <item>
        <title>Security updates for Thursday</title>
        <link>https://lwn.net/Articles/1076364/</link>
        <guid>https://lwn.net/Articles/1076364/</guid>
        <dc:creator>jzb</dc:creator>
        <description>Security updates have been issued by &lt;b&gt;AlmaLinux&lt;/b&gt; (.NET 10.0, compat-openssl10, compat-openssl11, delve, expat, httpd:2.4, libexif, mod_http2, openssl, ruby4.0, samba, thunderbird, unbound, and vim), &lt;b&gt;Debian&lt;/b&gt; (ceph and sudo), &lt;b&gt;Fedora&lt;/b&gt; (libsoup3, pie, roundcubemail, and xorg-x11-server-Xwayland), &lt;b&gt;Mageia&lt;/b&gt; (lxc), &lt;b&gt;Oracle&lt;/b&gt; (expat, gnutls, kernel, php:8.2, thunderbird, and uek-kernel), &lt;b&gt;Slackware&lt;/b&gt; (httpd, net, proftpd, tigervnc, and xorg), &lt;b&gt;SUSE&lt;/b&gt; (apache-sshd, apptainer, atril, bind, busybox, cloudflared, evolution-data-server, golang-github-prometheus-prometheus, golang-github-v2fly-v2ray-core, grafana, helm, kernel, libgphoto2-6, libjxl-devel, libsoup, libsoup-2_4-1, libsoup-3_0-0, memcached, ovmf, python-cairosvg, python-flask, python-pip, python-pymupdf, python-pyOpenSSL, python-urllib3, python-urllib3_1, python3-pyOpenSSL, restic, rsync, salt, sdbootutil, tor, tree-sitter, vorbis-tools, and yq), and &lt;b&gt;Ubuntu&lt;/b&gt; (exim4, frr, gst-plugins-base1.0, libtemplate-perl, libwww-perl, mysql-8.0, nginx, python-pip, python-urllib3, and twisted).
</description>
        <pubDate>Thu, 04 Jun 2026 13:17:19 +0000</pubDate>
        </item>
        <item>
        <title>[$] LWN.net Weekly Edition for June 4, 2026</title>
        <link>https://lwn.net/Articles/1074950/</link>
        <guid>https://lwn.net/Articles/1074950/</guid>
        <dc:creator>jzb</dc:creator>
        <description>Inside this week's LWN.net Weekly Edition:
        &lt;p&gt;
        &lt;ul&gt;
&lt;li&gt; &lt;a href=&quot;https://lwn.net/Articles/1074950/&quot;&gt;Front&lt;/a&gt;: MeshCore; x32 ABI; Open-source security; Package-manager metadata; More LSFMM+BPF coverage; Loadable crypto module.
            &lt;li&gt; &lt;a href=&quot;https://lwn.net/Articles/1074952/&quot;&gt;Briefs&lt;/a&gt;: Lightwell; jqwik protestware; RedHat package compromise; DistroWatch; Fedora election; Rust 1.96.0; rsync; Vim Classic 8.3; Quotes; ...
            &lt;li&gt; &lt;a href=&quot;https://lwn.net/Articles/1074953/&quot;&gt;Announcements&lt;/a&gt;: Newsletters, conferences, security updates, patches, and more.
            &lt;/ul&gt;

        </description>
        <pubDate>Thu, 04 Jun 2026 01:31:14 +0000</pubDate>
        </item>
        <item>
        <title>[$] Open-source security is not a solo activity</title>
        <link>https://lwn.net/Articles/1075741/</link>
        <guid>https://lwn.net/Articles/1075741/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;Over time, many open-source maintainers face the same problem: they
lack the time to do all of the work that their project needs, and no
one else is stepping up to provide adequate help. Maintainers, though,
are often reluctant to throw in the towel. The result is suboptimal
all around; the maintainer is stressed out, project quality suffers,
and users face security risks that they may not be fully aware of. At
the 2026 &lt;a
href=&quot;https://events.linuxfoundation.org/open-source-summit-north-america/&quot;&gt;Open
Source Summit North America&lt;/a&gt;, Robin Bender&amp;#160;Ginn spoke about this
problem, when it might be time for maintainers to pass the torch, and
the responsibilities of users.
</description>
        <pubDate>Wed, 03 Jun 2026 15:02:35 +0000</pubDate>
        </item>
        <item>
        <title>[$] BPF in the agentic era</title>
        <link>https://lwn.net/Articles/1075067/</link>
        <guid>https://lwn.net/Articles/1075067/</guid>
        <dc:creator>daroc</dc:creator>
        <description>&lt;p&gt;
Alexei Starovoitov gave &quot;&lt;q&gt;less of a presentation, more of a scream of
realization&lt;/q&gt;&quot; at the BPF track of the 2026
&lt;a href=&quot;https://events.linuxfoundation.org/lsfmmbpf/&quot;&gt;
Linux Storage, Filesystem,
Memory-Management, and BPF Summit&lt;/a&gt;. He shared a set of ideas for how BPF could
change to avoid being swept away by the sea-change in programming represented by modern
large language models (LLMs) and the coding agents based on them.
In a follow-up session, the discussion covered
more problems with how coding agents use tools like bpftrace, and the current deluge of
patches in need of review in the BPF subsystem.
&lt;/p&gt;
</description>
        <pubDate>Wed, 03 Jun 2026 13:14:39 +0000</pubDate>
        </item>
        <item>
        <title>Tridgell: rsync and outrage</title>
        <link>https://lwn.net/Articles/1076040/</link>
        <guid>https://lwn.net/Articles/1076040/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;Andrew Tridgell has written a &lt;a
href=&quot;https://medium.com/@tridge60/rsync-and-outrage-d9849599e5a0&quot;&gt;blog
post&lt;/a&gt; responding to complaints that he has begun using LLM tools in
his work maintaining &lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote class=&quot;bq&quot;&gt;
&lt;p&gt;Like many developers of open source packages I've been hit by a
flood of security reports lately in my role as the rsync
maintainer. Many of those reports are AI generated (not all though,
there are some notable ones with very careful and high quality manual
analysis).&lt;/p&gt;

&lt;p&gt;As this flood started to get more intense I realised I needed to
raise the defences on rsync a lot — we needed much more thorough test
suites, code coverage analysis, CI testing on a lot more platforms,
deliberate and thorough scanning for possible security issues (so I
find at least some of them before other people!) and the addition of a
whole lot of defence-in-depth hardening techniques.&lt;/p&gt;

&lt;p&gt;[...] Now to the future, because we're not done yet by a long
shot. The security reports keep rolling in. I'm working on a bunch of
CVEs right now. Luckily I've been joined by some other very good
developers with great systems development skills and security
knowledge. Some of these people came to my attention partly because of
all the rage happening at the moment, so I get some rage storm clouds
have silver linings. Watch out for some credits for some great new
rsync developers in the next release.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;/p&gt;</description>
        <pubDate>Wed, 03 Jun 2026 13:00:46 +0000</pubDate>
        </item>
        <item>
        <title>Security updates for Wednesday</title>
        <link>https://lwn.net/Articles/1076117/</link>
        <guid>https://lwn.net/Articles/1076117/</guid>
        <dc:creator>jzb</dc:creator>
        <description>Security updates have been issued by &lt;b&gt;Debian&lt;/b&gt; (php-twig), &lt;b&gt;Fedora&lt;/b&gt; (hplip, python-wsgidav, roundcubemail, and xorg-x11-server), &lt;b&gt;Oracle&lt;/b&gt; (compat-openssl10, httpd:2.4, and kernel), &lt;b&gt;Red Hat&lt;/b&gt; (osbuild-composer), &lt;b&gt;SUSE&lt;/b&gt; (busybox, cloudflared, cockpit, cups, ffmpeg-4, gnutls, google-osconfig-agent, helm, hplip, kernel, kubelogin, libjxl, libsoup, libunbound8, LibVNCServer-devel, mapserver, nvidia-open-driver-G06-signed, nvidia-open-driver-G07-signed, openssh, python-idna, qemu, rqlite, shadowsocks-v2ray-plugin, ucode-intel, unbound, vim, vorbis-tools, and xorg-x11-server), and &lt;b&gt;Ubuntu&lt;/b&gt; (age, dovecot, editorconfig-core, gobgp, libapache-mod-jk, libcommons-lang-java, libcommons-lang3-java, libeconf, linux, linux-aws, linux-aws-6.8, linux-aws-fips, linux-azure, linux-fips,
 linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-gke, linux-gkeop,
 linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-nvidia, linux-nvidia-6.8,
 linux-nvidia-lowlatency, linux-nvidia-tegra, linux-oracle,
 linux-oracle-6.8, linux-raspi, linux-raspi-realtime, linux-realtime,
 linux-realtime-6.8, linux, linux-aws, linux-azure, linux-azure-6.17, linux-hwe-6.17,
 linux-nvidia-6.17, linux-oem-6.17, linux-oracle, linux-oracle-6.17,
 linux-raspi, linux-realtime, linux-realtime-6.17, linux, linux-aws, linux-gcp, linux-ibm, linux-nvidia, linux-oracle,
 linux-raspi, linux-realtime, linux-aws-6.17, linux-gcp, linux-gcp-6.17, luanti, mysql-8.0, mysql-8.4, node-tar-fs, and unbound).
</description>
        <pubDate>Wed, 03 Jun 2026 12:59:17 +0000</pubDate>
        </item>
        <item>
        <title>[$] Caching for extended attributes</title>
        <link>https://lwn.net/Articles/1074919/</link>
        <guid>https://lwn.net/Articles/1074919/</guid>
        <dc:creator>jake</dc:creator>
        <description>&lt;a href=&quot;https://man7.org/linux/man-pages/man7/xattr.7.html&quot;&gt;Extended
attributes&lt;/a&gt; (xattrs) provide a way to attach &lt;span class=&quot;nobreak&quot;&gt;key/value&lt;/span&gt; metadata to
inodes—files, directories, and the like—in a filesystem.  As with many
Linux filesystems, the &lt;a
href=&quot;https://docs.kernel.org/filesystems/fuse/&quot;&gt;FUSE filesystem&lt;/a&gt;
supports xattrs.  In a filesystem-track session at the 2026 &lt;a
href=&quot;https://events.linuxfoundation.org/lsfmmbpf/&quot;&gt;Linux Storage,
Filesystem, Memory Management, and BPF Summit&lt;/a&gt;, FUSE maintainer Miklos
Szeredi led a discussion about caching xattrs in kernel memory; he would
like to create some common infrastructure that could be used by FUSE and
shared with other filesystems.
</description>
        <pubDate>Tue, 02 Jun 2026 18:35:52 +0000</pubDate>
        </item>
        <item>
        <title>[$] Trying to make sense of package-manager metadata</title>
        <link>https://lwn.net/Articles/1074908/</link>
        <guid>https://lwn.net/Articles/1074908/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;Package managers for operating systems and programming languages have been
around for decades. Each package manager, and its accompanying packaging format,
has been shaped by the needs of its respective ecosystem, but there is a growing
need to make use of package metadata for more than software management: for
example, in vulnerability scans, software bills of materials (SBOMs), and more. On
May&amp;#160;19, Damián Vicino spoke at the &lt;a href=&quot;https://events.linuxfoundation.org/open-source-summit-north-america/&quot;&gt;Open Source Summit North America&lt;/a&gt; 2026
about his experiences in the past year trying to make sense of the varied
metadata provided by more than 20 package managers.&lt;/p&gt;
</description>
        <pubDate>Tue, 02 Jun 2026 13:33:43 +0000</pubDate>
        </item>
        <item>
        <title>Vim Classic 8.3 released</title>
        <link>https://lwn.net/Articles/1075967/</link>
        <guid>https://lwn.net/Articles/1075967/</guid>
        <dc:creator>jzb</dc:creator>
        <description>&lt;p&gt;&lt;a
href=&quot;https://vim-classic.org/news/vim-8.3-released.html&quot;&gt;Version
8.3&lt;/a&gt; of &lt;a href=&quot;https://vim-classic.org/&quot;&gt;Vim Classic&lt;/a&gt; has been
released. This is the first release of the Vim fork since the project
was &lt;a href=&quot;https://drewdevault.com/blog/Forking-vim/&quot;&gt;announced&lt;/a&gt;
in March.&lt;/p&gt;

&lt;blockquote class=&quot;bq&quot;&gt;
&lt;p&gt;This release is based on Vim 8.2.0148, with a number of bug fixes
and patches conservatively backported from future versions of Vim
upstream. We elected to clean up this version of Vim, prepare it for a
release, and imagine an alternate history where Vim 8.3 was released
without Vim9 script. The result is Vim Classic 8.3. We chose to take
this approach in order to reduce the long-term maintenance burden of
Vim Classic, acknowledging that our fork lacks the resources and
institutional knowledge available to Vim upstream. However, a
consequence is that there are some Vim plugins which are not
compatible with Vim Classic.&lt;/p&gt;

&lt;p&gt;We have made a special effort to assess patches from Vim upstream
which mitigate some of the many CVEs affecting Vim which were
discovered and fixed between versions 8.2 and modern-day Vim, but we
can't be sure we've got all of the security patches which are
applicable to Vim Classic (and practically exploitable). This version
of Vim Classic is therefore recommended for early adopters who are
comfortable adopting a security posture which accounts for the fact
that we may have overlooked some bugs.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;LWN &lt;a href=&quot;https://lwn.net/Articles/1067007/&quot;&gt;covered&lt;/a&gt; Vim
Classic and another Vim fork, &lt;a href=&quot;https://codeberg.org/evi-editor/evi#evi&quot;&gt;EVi&lt;/a&gt;, in April.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;</description>
        <pubDate>Tue, 02 Jun 2026 13:13:37 +0000</pubDate>
        </item>
        <item>
        <title>Security updates for Tuesday</title>
        <link>https://lwn.net/Articles/1075966/</link>
        <guid>https://lwn.net/Articles/1075966/</guid>
        <dc:creator>jzb</dc:creator>
        <description>Security updates have been issued by &lt;b&gt;AlmaLinux&lt;/b&gt; (php:8.2 and php:8.3), &lt;b&gt;Debian&lt;/b&gt; (gst-plugins-good1.0, symfony, and yelp), &lt;b&gt;Fedora&lt;/b&gt; (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), &lt;b&gt;Mageia&lt;/b&gt; (assimp, libcaca, sdl2_sound, and tar), &lt;b&gt;Slackware&lt;/b&gt; (kernel), &lt;b&gt;SUSE&lt;/b&gt; (alloy, apache-commons-lang3, apache-commons-text,, apache2, bubblewrap, busybox, chromium, cups, docker-stable, ffmpeg-8, google-osconfig-agent, gsasl, ignition, java-26-openjdk, kernel, libsolv-demo, libsoup, libzypp, localsearch, openjpeg2, postgresql-jdbc, putty, python-mistune, python-Pillow, python-python-multipart, python-Twisted, python3-Twisted, re, roundcubemail, vim, wireshark, and xz), and &lt;b&gt;Ubuntu&lt;/b&gt; (evolution-data-server, exim4, gsasl, haveged, lcms2, libreoffice, linux-aws, linux-lts-xenial, linux-lowlatency, linux-nvidia-tegra, nginx, nncp, qtdeclarative-opensource-src, sslh, sssd, and xz-utils).
</description>
        <pubDate>Tue, 02 Jun 2026 13:06:02 +0000</pubDate>
        </item>
        <item>
        <title>Ombredanne: An AI agent ported our codebase from Python to Rust</title>
        <link>https://lwn.net/Articles/1075832/</link>
        <guid>https://lwn.net/Articles/1075832/</guid>
        <dc:creator>jake</dc:creator>
        <description>Over on the &lt;a href=&quot;https://www.aboutcode.org/&quot;&gt;AboutCode&lt;/a&gt; blog, lead
maintainer Philippe Ombredanne &lt;a
href=&quot;https://www.aboutcode.org/blog/agentic-scancode-port-case-study/&quot;&gt;writes&lt;/a&gt;
about an agentic LLM system porting the &lt;a
href=&quot;https://github.com/aboutcode-org/scancode-toolkit#scancode-toolkit&quot;&gt;ScanCode
Toolkit&lt;/a&gt; to Rust.  In the process, the LLM (or the people behind it)
infringed the ScanCode trademark, stripped copyright and license notices,
&quot;&lt;q&gt;and started an outreach campaign, without ever engaging the AboutCode
community&lt;/q&gt;&quot;.  Ironically, the toolkit is used to scan source code and binaries in
order to figure out licensing and copyright information; it also reports on
package
dependencies, vulnerabilities, and more.


&lt;blockquote class=&quot;bq&quot;&gt;
This is worth repeating: A comprehensive test suite, decent documentation, and curated datasets is what makes automated porting possible. It is also what makes a codebase easier to replicate without understanding it.
&lt;p&gt;
The agent's initial approach, using an existing Rust license-detection library, failed to match ScanCode's output quality. The agent then did what any translator would do when a loose paraphrase fails: it copied the original more closely. The final port reproduces ScanCode's core algorithms, code organization, and data-driven architecture in Rust, not because the agent understood them, but because it had enough training data and test feedback to converge on equivalent code.
&lt;/blockquote&gt;</description>
        <pubDate>Mon, 01 Jun 2026 20:55:10 +0000</pubDate>
        </item>
        <item>
        <title>[$] Representing the true signatures of kernel functions</title>
        <link>https://lwn.net/Articles/1073762/</link>
        <guid>https://lwn.net/Articles/1073762/</guid>
        <dc:creator>daroc</dc:creator>
        <description>&lt;p&gt;
Optimizing compilers can, under some circumstances, infer when a parameter to a
function is not needed, and remove it. This is all well and good until the
kernel's tracing or BPF subsystems need information on how to call the function
or where its arguments are stored.
Alan Maguire and Yonghong Song spoke at the 2026
&lt;a href=&quot;https://events.linuxfoundation.org/lsfmmbpf/&quot;&gt;
Linux
Storage, Filesystem, Memory-Management, and BPF Summit&lt;/a&gt; about their work on
recording information regarding changed function signatures in the kernel's BTF debugging
information, to better support tracing such functions.
&lt;/p&gt;
</description>
        <pubDate>Mon, 01 Jun 2026 18:59:43 +0000</pubDate>
        </item>
        </channel>
</rss>
