Dear Tumbleweed users and hackers,
Last week, there was a public holiday on Thursday in some parts of the world (Ascension Day). Unsurprisingly, many devs, including myself and Ana, took Friday off to enjoy a longer weekend (and I can tell you: the weather was fantastic). As a result, I have to span two weeks of changes to Tumbleweed here once again. We have published 12 snapshots since my last review (0502…0515, snapshots 0504 and 0513 were not built due to weekends)
The most relevant changes delivered as part of those snapshots were:
- Mozilla Firefox 125.0.3
- LibreOffice 24.2.3.2
- GNOME 46.1
- GIMP 2.10.38
- LLVM 18.1.5
- GCC 14.1
- KDE Frameworks 6.2.0
- PHP 8.3.7
- PostgreSQL 16.3
- Systemd 255.5 & 255.6
- Linux kernel 6.8.9 (with linux-glibc-devel already prepared at 6.9)
- Ruby 3.3.1
- QEmu 8.2.3
- util-linux 2.40.1
Snapshot 0515 contained an openssh update, that mistakenly recommended installation of the subpackage openssh-server-config-rootlogin; this package has existed since the default configuration of openSSH was changed to not permit root login anymore, so admins could easily switch it back on. Due to an error, this had been triggered for automatic installation. This has since been corrected and a version of openssh-server was published to the update channel, which is NOT recommended. Please check your installation and remove the package again, should it be installed and you don’t need it (we can’t auto-remove it without breaking users that explicitly wanted it)
The following things are known to be worked on at the moment and are reaching you in some upcoming snapshot:
- chkstat package being renamed to permctl
- Rust 1.78
- Mesa 24.0.7
- Linux kernel 6.9.1
- Ninja 1.12
- dbus-broker: some networking issue after upgrades left to work out
- GCC 14: phase 2: use gcc14 as the default compiler – lots of help needed: https://build.opensuse.org/project/show/openSUSE:Factory:Staging:Gcc7
If you need to add stuff to a PDF document, now you can do that online with Firefox. Open the PDF in Firefox and click the Text or Draw buttons in the upper right corner to make changes to your document. Download the file to save it with your changes.
Fill in forms online without printing and scanning
We’ve all faced this: you need to fill in a form that is a PDF, but it isn’t editable. In the past, your only option was to print it on a dead tree, add things with ink, and then scan it back into your computer.
No more! Now, all you need to do is edit the PDF online with Firefox, save it, and email it from your computer.
Add text
Open the PDF in Firefox. Click the Text button to choose a color and text size before selecting where on the document you wish to add text. It’s that easy!
Add drawings (or your signature)
Open the PDF in Firefox. Click the Draw icon to choose a color, thickness and opacity before then being able to draw on the document. It probably won’t be any messier than your usual signature!
Add image with alt text
Open the PDF in Firefox. Click the image icon, which will then prompt you to upload an image. Adjust size and placement of your image as needed. Click the “+Alt text” button on the image to add a photo description to make your PDF more accessible.
Create a highlight
Open the PDF in Firefox. Select the text you want to highlight, then click the highlight icon that appears below your selection, or right click to find the highlight option in the context menu. Click the icon in the top right to freehand highlight sections of the PDF.
What’s happened?
The Linux kernel project has become its own CVE Numbering Authority (CNA) with two very notable features:
- CVE identifiers will only be assigned after a fix is already available and in a release; and
- the project will err on the side of caution, and assign CVEs to all fixes.
This means each new kernel release will contain a lot of CVE fixes.
So what?
This could contribute to a significant change in behaviour for commercial software vendors.
The kernel project has long advocated updating to the latest stable release in order to benefit from fixes, including security patches. They’re not the only ones: Google has analysed this topic and Codethink talks extensively about creating software with Long Term Maintainability baked in.
But alas, a general shift to this mentality appears to allude us: the prevalent attitude amongst the majority of commercial software products is still very much “ship and forget”.
Consider the typical pattern: SoC vendors base their BSP on an old and stable Linux distribution. Bespoke development occurs on top of this, and some time later, a product is released to market. By this point, the Linux version is out of date, quite likely unsupported and almost certainly vulnerable from a security perspective.
Now, fair enough, upgrading your kernel is non-trivial: it needs to be carefully thought through, requires extensive testing, and often careful planning to ensure collaboration between different parties, especially if you have dependencies on vendor blobs or other proprietary components. Clearly, this kind of thing needs to be thought about from day one of a new project. Sadly, in practice, in a lot of cases, upgrading simply isn’t even planned for.
And now?
With the Linux kernel project becoming a CNA, we’ll now have a situation where every new kernel release highlights the scale of how far behind mainline these products are, and by implication how exposed to security vulnerabilities the software is.
The result should be increased pressure on vendors to upgrade.
With this, plus the recent surge in regulations around keeping software up to date (see the CRA, UNECE R155 and R156), we may start to see a genuine movement towards software being designed to be properly maintained and updated, ie, “ship and remember” or Long Term Maintainability. Let’s hope so.
What else?
Well, the Linux kernel is just one project. There are countless other FOSS projects which are depended on by almost all commercial projects, and they may also be interested in becoming their own CNA.
This would further increase the visibility of the problem, and apply a renewed focus on the criticality of releasing software products with plans to upgrade built in from the start.
If you would like to learn more about CNAs or Codethink’s Long Term Maintainability approach, reach out via sales@codethink.co.uk.
If I understood you correctly ShareDrop should fix your problem, there you can “add” someone from a different network via QR-code
Linux Distribution (Distro) and Desktop Environment (DE). Not sure why the commenter above expected you to use Linux though
Easiest seems to me just enabling E2EE in telegram since it’s there. Asking to use secret chats seems easier than asking to switch plattforms
Okay MkvToolnix isn’t the right tool for that afaik, but ffmpeg is and it sucks there isn’t a GUI for it that’s as powerful as the cli which is what I use, luckily you can find a lot of help online,
Apart from that I’m afraid i can’t help much, but good luck with your search!
Are you trying to concat streams or just to remux? For remuxing as roawre said there’s also MkvToolNix, which works great (and it has a gui don’t worry)
ffmpeg, if you need a gui use handbreak
Sure you have to enable E2EE but they never say they use E2EE by default, they’re not advertising at all anyway. Saying it is “not secure at all” is a bit of a reach. They have proven they don’t share data with governments and again, you can use E2EE if you want
Why does it say Mlem got removed? There just was an update
Why does it say Mlem is taken off TestFlight, it just got an update