Qortora · Search · Indexed page

freenode.netFetched 2026-08-17T10:17:45Z

freenode

News from the places where open source, open standards and cryptocurrency development actually happen.

Open original source · Full cached text

freenode 3m agoPatch series changes get_swap_device() error paths to stop repeated console spam from corrupted swap entries observed at Meta scale. 5m agoMeta engineer posts 57-patch RFC to replace khugepaged anonymous collapse with migration-based engine for sub-PMD mTHP on arm64 64K pages. 8m agoRFC to promote DirectX backend from experimental to official target, with discussion on maintenance burden and DXIL debug-info bitcode compatibility. 11m agoEIP for partial validator reward burn draws 208 heated posts with personal attacks and sock-puppet deletions. 11m agoPatch caps EROFS LZMA default streams at 16 to bound vmalloc memory from untrusted images; follow-on Kconfig fixes for NR_CPUS/UP arches. 14m agoLarge patch series adds Linux driver + DSA integration for AMD/Xilinx 802.1 TSN Endpoint MAC. 15m agoDebian developers discussing CPU baseline feature tests (SSE3+, ARMv8, etc.) and i386 FPU changes for forky. 37m agoDNSOP WG call for adoption of multi-alg DNSSEC draft draws support plus strong objections on validator compatibility and PQC implications. 9h agoOpenZFS on Linux full-disclosed for zpool and userns escapes 11h agoBernstein documents 75 objections the IESG cannot edit away 15h agoQEMU gains fast snapshot load via postcopy and userfaultfd AnalysisInternet & Protocols11h ago Bernstein documents 75 objections the IESG cannot edit away In a four-part Last Call filing the last-call moderators appear to have blocked, Bernstein compiled 75 sourced objections, a Kyber co-designer's own warning against solo use, and a five-orders-of-magnitude cost gap. The IESG should not publish draft-ietf-tls-mlkem. By staff Security & Cryptography9h ago OpenZFS on Linux full-disclosed for zpool and userns escapes Researcher Erica Windisch publicized flaws she says let unprivileged users manipulate pools and break out of user namespaces, after notifying CERT. By tarpit AnalysisSecurity & Cryptography2d ago Post-quantum TLS ships while lattice schemes crack under AI and process fights IETF makes hybrid ML-KEM key agreement a Proposed Standard just as an AI-found attack kills HAWK and pure-ML-KEM last call draws public process and security objections. By nonce Kernel & Low-Level3d ago ext4 moves buffered I/O onto iomap in 32-patch series Zhang Yi’s v5 conversion drops buffer_head for regular-file buffered paths and reworks EOF zeroing so size updates cannot expose stale data. By kexec Languages & Toolchains3d ago Go patches sumdb bypasses in golang.org/x/mod 0.40.0 Two CVEs let a hostile GOPROXY and GOSUMDB serve malicious modules that the transparency log would not catch. By segfault Languages & Toolchains3d ago Go x/mod 0.40.0 fixes sumdb bypasses for malicious modules Two flaws let a hostile module proxy or checksum database slip attacker-controlled code past transparency-log checks into the local cache. By segfault Languages & Toolchains3d ago Go 1.26.6 and 1.25.13 fix sumdb bypass and module cache attacks Point releases close flaws that let malicious proxies and checksum databases slip unverified modules past GOSUMDB checks. By segfault Languages & Toolchains3d ago Go 1.27 RC3 plugs module proxy checksum bypasses The candidate ships ten security fixes, led by flaws that let a hostile GOPROXY or GOSUMDB slip malicious modules past transparency checks. By segfault Languages & Toolchains3d ago Go 1.26.6 and 1.25.13 close module sumdb bypasses The point releases ship ten security fixes, including flaws that let a malicious proxy or sumdb serve undetected attacker-controlled modules. By segfault Kernel & Low-Level3d ago BPF gains global per-CPU variables in a .percpu section Leon Hwang’s series lets programs declare DEFINE_PER_CPU-style data, with libbpf, bpftool, and selftest support. By oops Kernel & Low-Level3d ago Linux starts killing off the little-used x32 ABI Maintainers will disable the config option first, with full removal planned after this year's final LTS kernel unless users object. By kexec AnalysisDistributions & Plumbing3d ago Who speaks for Nixpkgs: core burnout and the Stack opt-out The core team's dissolution and the fight over Hugging Face's training dataset both expose the same unresolved question of who may act in contributors' names. By chroot Kernel & Low-Level4d ago VFIO patches add CXL Type-2 accelerator passthrough for guests A 27-patch series from NVIDIA lets VMs program virtual HDM decoders and resets while the host keeps physical memory decode. By kexec Kernel & Low-Level4d ago Linux adds fwnode PCS API and dynamic phylink attach for external serdes Christian Marangi’s v14 work gives PCS drivers a clock-style provider model and lets phylink gain or lose coding layers at runtime, with Airoha AN7581 as the first user. By kexec Languages & Toolchains4d ago Git fixes quadratic pack loading slowdown in large monorepos A late-2025 packfile store refactor made everyday commands crawl when tens of thousands of packs were present. By segfault Kernel & Low-Level4d ago Linux neighbour tables become per-network-namespace ARP and ND tables move out of the global scope, so each netns can tune neighbour defaults and control paths need less global locking. By kexec Security & Cryptography4d ago Rsync 3.5.0 fixes 33 CVEs; LTS backports on the way Andrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds. By nonce Kernel & Low-Level ext4 moves buffered I/O onto iomap in 32-patch series BPF gains global per-CPU variables in a .percpu section Linux starts killing off the little-used x32 ABI VFIO patches add CXL Type-2 accelerator passthrough for guests Distributions & Plumbing NixOS SC faces micromanagement claims after Nixpkgs core exit Who speaks for Nixpkgs: core burnout and the Stack opt-out OpenWrt gets first GPON support on EcoNet EN7528 ONTs Nixpkgs core team disbands after 10 months Desktop & Graphics VS Code 1.132.1 patches Fetch Web Page RCE Hermes LLM agent bid for NonGNU ELPA sparks SaaSS fight Rust DRM fix stops crash when modules unload with devices open Virtio RFC proposes device-owned queue memory for isolation Internet & Protocols Bernstein documents 75 objections the IESG cannot edit away LLM hunt finds bugs in Tamarin security prover IETF draft opens debate on LLM text in standards work The IESG should reject solo ML-KEM for TLS and keep the hybrid safety net Languages & Toolchains Go patches sumdb bypasses in golang.org/x/mod 0.40.0 Go x/mod 0.40.0 fixes sumdb bypasses for malicious modules Go 1.26.6 and 1.25.13 fix sumdb bypass and module cache attacks Go 1.27 RC3 plugs module proxy checksum bypasses Databases & Infrastructure QEMU gains fast snapshot load via postcopy and userfaultfd QEMU TCG tests leave Makefiles behind for Meson QEMU adds fast snapshot load for near-instant VM resume QEMU guest agent fixes root symlink flaw in SSH key commands Security & Cryptography OpenZFS on Linux full-disclosed for zpool and userns escapes Post-quantum TLS ships while lattice schemes crack under AI and process fights Rsync 3.5.0 fixes 33 CVEs; LTS backports on the way Apache Airflow 3.3.1 patches three DAG-author RCE bugs in the scheduler and API server Cryptocurrency The motion to remove Luke Dashjr is a purge dressed up as process Draft EIP would burn ETH validator rewards to cap stake share