Fedora People

Save the Date: Fedora 40 Release Party on May 24-25

Posted by Fedora Magazine on May 06, 2024 08:00 AM

After the hard work of pushing out the Fedora Linux 40 release, we now look at celebrating with a release party! The Fedora 40 Release Party will take place on May 24-25, Friday and Saturday.

What is a release party?

Fedora Release Parties are virtual, user-focused conferences where the community comes together to talk about what’s new in the latest release of Fedora and where we’re going for future releases. Topics we’ve covered include the process of working through implementing a change and roadmaps for what different teams want to do next in Fedora. Sometimes there are updates from Fedora-associated groups who have something to share, like Amazon or Lenovo. We also have breaks for socials where we can talk to each other in video calls (you don’t have to share video or speak if you don’t want to). If you have an interest in a behind-the-scenes look at your favorite distro, come learn and hang out with the contributors who make it!

Where will it happen?

In previous years we used Hopin to run virtual conferences, but the Fedora 40 Release Party will be the first that we do in Matrix! We’ve wanted to do this since the Creative Freedom Summit showed how it could be done a couple of years ago. This is a step that allows us to lean more on open source for outreach.

However, we also want to be open in another way, and that’s with livestreaming. We will be streaming the talks on our Fedora Project YouTube channel. That way anyone can watch and the streams will be immediately available afterwards!

Details for registering will come soon, but for now please save the date for May 24-25!

We hope to see you there!

Learn more

Check out the Fedora 39 Release Party to get an idea of the kinds of topics we cover.

Get hyped on social media with hashtag #FedoraReleaseParty!

Week 18 in Packit

Posted by Weekly status of Packit Team on May 06, 2024 12:00 AM

Week 18 (April 30th – May 6th)

  • Packit will now upload to lookaside cache sources that are not specified by URLs and are present in the dist-git repo during release sync. Additionally, all the actions ran during syncing release will provide the PACKIT_PROJECT_VERSION environment variable. (packit#2297)
  • We have introduced a new status_name_template option that allows you to configure status name for a Packit job. For further details have a look at our docs. This feature is still experimental and at the moment it is not possible to retry such jobs via GitHub Checks' re-run. (packit-service#2402)

Episode 427 – Will run0 replace sudo?

Posted by Josh Bressers on May 06, 2024 12:00 AM

Josh and Kurt talk about a sudo replacement going into systemd called run0. It sounds like it’ll get a lot right, but systemd is a pretty big attack surface and not everyone is a fan. We shall have to see if this ends up replacing sudo.

<audio class="wp-audio-shortcode" controls="controls" id="audio-3377-1" preload="none" style="width: 100%;"><source src="https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_427_Will_run0_replace_sudo.mp3?_=1" type="audio/mpeg">https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_427_Will_run0_replace_sudo.mp3</audio>

Show Notes

Kiwi TCMS 13.2

Posted by Kiwi TCMS on May 04, 2024 10:30 AM

We're happy to announce Kiwi TCMS version 13.2!

IMPORTANT: This is a small release which contains several improvements, internal refactoring and updated translations!

Recommended upgrade path:

13.1.1 -> 13.2

You can explore everything at https://public.tenant.kiwitcms.org!

---

Upstream container images (x86_64):

kiwitcms/kiwi   latest  6cb7c6d669a2    681MB

IMPORTANT: version tagged and multi-arch container images are available only to subscribers!

Changes since Kiwi TCMS 13.1.1

Improvements

  • Update Django from 4.2.10 to 4.2.11
  • Update django-grappelli from 3.0.8 to 4.0.1
  • Update django-modern-rpc from 1.0.2 to 1.0.3
  • Update django-tree-queries from 0.16.1 to 0.19.0
  • Update jira from 3.6.0 to 3.8.0
  • Update markdown from 3.5.2 to 3.6
  • Update python-redmine from 2.4.0 to 2.5.0
  • Update uwsgi from 2.0.24 to 2.0.25.1
  • Update node_modules/pdfmake from 0.2.9 to 0.2.10
  • Update node_modules/es5-ext from 0.10.62 to 0.10.63
  • Update documentation with better installation instructions when using Docker
  • Remove multiple inline style= HTML attributes

Settings

  • Don't send outgoing emails to addresses which fail validation, including custom validation configured via the EMAIL_VALIDATORS setting. For example if there are blacklisted addresses Kiwi TCMS will not send messages to them anymore

Refactoring and testing

  • Update black from 23.12.1 to 24.4.2
  • Update selenium from 4.9.1 to 4.20.0
  • Update node_modules/eslint from 8.56.0 to 8.57.0
  • Update nodemodules/webpack from 5.90.3 to 5.91.0
  • Remove unused has_permissions_to_modify()
  • Do not execute Docker image tests as root
  • Add tests for file upload via browser UI

Kiwi TCMS Enterprise v13.2-mt

  • Based on Kiwi TCMS v13.2
  • Update certbot from 2.9.0 to 2.10.0
  • Upgrade certbot-dns-* plugins from 2.9.0 to 2.10.0
  • Update django-python3-ldap from 0.15.5 to 0.15.6
  • Update django-ses from 3.5.2 to 4.0.0
  • Update kiwitcms-tenants from 2.6.0 to 2.8.3
  • Update sentry-sdk from 1.40.5 to 2.0.1
  • Update social-auth-app-django from 5.4.0 to 5.4.1
  • Update documentation related to production deployments
  • Add test for file uploads via browser UI

Private container images

quay.io/kiwitcms/version            13.2 (aarch64)          e596cef147cc    04 May 2024     693MB
quay.io/kiwitcms/version            13.2 (x86_64)           6cb7c6d669a2    04 May 2024     681MB
quay.io/kiwitcms/enterprise         13.2-mt (aarch64)       ab6d8f2039b4    04 May 2024     1.06GB
quay.io/kiwitcms/enterprise         13.2-mt (x86_64)        a6938623851d    04 May 2024     1.04GB

IMPORTANT: version tagged, multi-arch and Enterprise container images are available only to subscribers!

SaaS changes since v13.1.1

Applies to any digital property under *.tenant.kiwitcms.org!

  • @hotmail email addresses are blacklisted
  • email addresses on all .ru domains are blacklisted
  • Existing accounts whose email addresses have been blacklisted will continue to be active, however they will not receive any email communication. This includes confirmation and password reset messages! Users are advised to update their accounts with a different address!

How to upgrade

Backup first! Then follow the Upgrading instructions from our documentation.

Happy testing!

---

If you like what we're doing and how Kiwi TCMS supports various communities please help us grow!

git submodule forgetting

Posted by Gary Benson on May 02, 2024 03:11 PM

Did you forget the -r when cloning a git repo with submodules? The command you’re looking for is git submodule update --init

GNOME will be mentoring 8 new contributors for Google Summer of Code 2024

Posted by Felipe Borges on May 02, 2024 10:25 AM

We are happy to announce that GNOME was assigned eight slots for Google Summer of Code projects this year!

GSoC is a program focused on bringing new contributors into open source software development. A number of long term GNOME developers are former GSoC interns, making the program a very valuable entry point for new members in our project.

In 2024 we will mentoring the following projects:

  • “Add TypeScript Support to Workbench” by Angelo Verlain Shema, mentored by Sonny Piers
  • “Port Workbench demos to Vala, build a new Workbench Library, and replace the current code search” by Bharat Tyagi, mentored by Sonny Piers
  • “Improve Tracker SPARQL developer experience by creating a ‘web IDE’ for developing queries” by Demigod, mentored by Carlos Garnacho
  • “Papers’ small screen and touch support for mobile and tablet” by Markus Göllnitz, mentored by Pablo Correa Gomez
  • “More durable synching for FlatSync” by Mattia Formichetti, mentored by Rasmus Thomsen
  • “Port libipuz to Rust” by pranjal_, mentored by Jonathan Blandford
  • “Improve Tracker SPARQL developer experience by creating ‘web IDE’ for developing queries” by rachle08, mentored by Carlos Garnacho
  • “Add support for the latest GIR attributes and gi-docgen formatting to Valadoc” by sudhanshuv1, mentored by Lorenz Wildberg

As part of the contributor’s acceptance into GSoC they are expected to actively participate in the Community Bonding period (May 1 – 26). The Community Bonding period is intended to help prepare contributors to start contributing at full speed starting May 27.

The new contributors will soon get their blogs added to Planet GNOME making it easy for the GNOME community to get to know them and the projects that they will be working on.

We would like to also thank our mentors for supporting GSoC and helping new contributors enter our project.

If you have any doubts, feel free to reply to this Discourse topic or message us privately at soc-admins@gnome.org

 

F40 Elections: Nominations now open & welcoming EPEL

Posted by Fedora Community Blog on May 02, 2024 08:00 AM

Hello Fedorans! The F40 election campaign is now in full swing, and this cycle will be running a little differently than the previous F39, F38, etc. We are welcoming the EPEL Steering Committee to our elections cycle and having our Council elections move to once per year too. Read on for the details 🙂

Moving Council Elections to Once Per Year

During the Fedora Council’s hackfest in February this year, the Council discussed administrative items, including the timing of the Fedora Council elections. It was unanimously agreed that the elections move to a once-per-year cadence, rather than every six months. The reason being that having a member exit and a new one enter the council every six months has become a little disruptive, and stabilizing the term to a continuous 12-month period would be more beneficial to not only the council members, but the project itself, with the Council having some continuity. This also makes travel planning for the annual Council hackfest easier. 

So to start this off, the F40 election will be the only election for the Fedora Council this year, and going forward, the Council will hold its election after the Spring/Summer release.

Important Election Information

  • The F40 election will have two open seats for Fedora Council.
  • The elected term for the elected Council member seats will remain 12 months.
  • The F39 elected member(s) on Fedora Council will continue to serve their 12-month term, ending in November 2024.
  • The next Council election after F40 will be F42, and F44, etc.
  • The format of the Council elections, and all other Fedora elections will remain unchanged
    • Nominations take place via the groups wiki page
    • Interview questions will be completed via private ticket in the elections repo by each candidate per group
    • Interviews will be published ~2 weeks prior to voting
    • The Elections app will still be used as the voting mechanism.
  • Fedora Mindshare Committee and FESCo elections remain unchanged at this time and will continue to be held per release. 

New Addition: EPEL Steering Committee Elections

Another exciting update to our elections circuit is the addition of the EPEL Steering Committee elections campaign! The EPEL Steering Committee elections will now be run by the Fedora Operations Architect and will be held once per year, after the Spring/Summer release of Fedora Linux. You can nominate yourself, or someone else (with their consent), by visiting the nominations page and adding your name in the nominations box at the end. Interview questions are being finalized and will be available to candidates very soon.

Election Format and Schedule

Our F40 elections schedule is currently viewable here and all elections – Council (x2 seats), FESCo (x4 seats), Mindshare (x1 seat) and EPEL (x4 seats), will follow this schedule. Nominations have begun on April 24th so if you or someone you know would be a great asset to one of these governance bodies, consider nominating yourself or them (with their consent of course) before the nomination period closes on May 8th!

The post F40 Elections: Nominations now open & welcoming EPEL appeared first on Fedora Community Blog.

Not again Red Hat

Posted by Jens Kuehnel on May 01, 2024 08:15 PM

In this video Jeff Geerling accounced that “Corporate Open Source is Dead”. He already dropped support from his really good ansible playbooks. This was because Red Hat only distributes its sources to customers. Another brick in this wall was announced today by the great ELrepo project.

In this blogpost it was announced that RHEL made some changes in the upcoming 8.10 and 9.4 releases of RHEL and this will break some of the kernel modules that were created by elrepo to allow running RHEL with older cards – that are not official supported anymore. The fun thing is not the whole driver that was deprecated, but only some of the supported pci-id where removed.

Especially for home lab users this created a big problem. aacraid, megaraid_sas, mlx4 and mpt3sas are drivers that are used in a lot of home labs everywhere.

Again the overall intention from Red Hat are not the problem. If Red Hat would break support of that in RHEL 10 there would be no problems. It would be interesting to know if this is a unexpected consequence of an patch or a targeted business decision. Yes I know why the support was dropped by Red Hat, but Red Hat is not only forgetting it roots, but again kicked the non-prod users in the curb. Just after they droped Centos and broke there promis there as well.

At least for my homelab this creates an extra work to do, because my RAID Controller is on the deprecated list. At least AlmaLinux has undo this patch and you don’t even need elrepo to support his older hardware.

I was planning to reinstall the host anyway. I only have to decide to select Fedora or AlmaLinux. The time to decide that is coming earlier the I hoped.

Join Fedora Week of Diversity (FWD) 2024

Posted by Fedora Community Blog on May 01, 2024 08:00 AM

We are happy to announce the Fedora Week of Diversity (FWD) 2024 from June 17th to 22nd, organized by the Fedora DEI Team. FWD is a time when we come together to honor the diverse voices, perspectives, and skills that enrich the vibrant Fedora community.

What is Fedora Week of Diversity (FWD)?

Every year, FWD serves as a platform to spotlight the different members and their noteworthy contributions to the community and projects they work on. This year’s theme, “Empowering Diversity, Enriching Communities,” acknowledges the views, perspectives, and talents of individuals from different backgrounds, experiences, and walks of life, impacting not only our community but also extending across the entire open-source ecosystem.

FWD runs from June 17th to 22nd, 2024, featuring a series of interviews with community members sharing their Fedora stories. Additionally, we will host a virtual event on June 21st – 22nd, featuring talks, panel discussions and social activities. FWD will showcase highlights from this content to emphasize Fedora’s diversity.

Important Fedora Week of Diversity dates

  • June 17th – 22nd, 2024: Series of interviews with community members
  • June 21st – 22nd, 2024: FWD virtual event

How to participate

By participating in FWD, you can contribute to creating an open-source community where everyone is empowered to succeed and make a difference.

Submit your Fedora Week of Diversity proposal

As part of FWD, we are opening Call for Proposals (CFP) to invite community members to share their insights, experiences, and expertise on topics related to diversity, equity, and inclusion in open source. This year’s theme for FWD is “Empowering Diversity, Enriching Communities.” We aim to explore how diversity in perspectives, backgrounds, and experiences strengthens our open-source community and fosters innovation. Don’t forget to apply by May 11.

Check out the Fedora Contributor Stories

During Fedora Week of Diversity, we’ll be publishing Contributor Stories from our vibrant Fedora community members. Dive into CommBlog to explore their unique journeys with Fedora and join us in celebrating their valuable contributions to the world of open source. 

Help us organize FWD

Would you like to assist with specific tasks related to FWD? Check our repository to learn more about our workflow and add a comment on the issue you want to help out with.

Let’s celebrate together

Let’s celebrate our differences together, amplify the voice of those underrepresented, and stand shoulder to shoulder, united in our commitment to diversity, equity, and inclusion. Join us for Fedora Week of Diversity 2024, and together, let’s create a future where everyone’s voice is heard, their contributions valued, and every individual has the opportunity to succeed. If you have any questions, ping us on Matrix.

The post Join Fedora Week of Diversity (FWD) 2024 appeared first on Fedora Community Blog.

Forward all your traffic with RedSocks

Posted by Fabio Alessandro Locati on April 30, 2024 12:00 AM
VPNs can be used in different ways based on the desired objective. If the goal is to reach some specific web pages served only within a network, using a proxy will probably do the trick. Another common use for VPNs is to ensure the confidentiality of data transferred between a remote system and a safe site. In this case, we might want to ensure that all traffic from the remote system reaches the safe site via the VPN.

نسخه نهایی لینوکس فدورا ۴۰ منتشر شد

Posted by Fedora fans on April 29, 2024 02:13 PM
Fedora_Linux_40

Fedora_Linux_40

تیم توسعه پروژه ی فدورا خبر انتشار نسخه نهایی Fedora Linux 40 را اعلام کرد. این نسخه از فدورا نیز مانند سایر نسخه های پیشین شامل تغییرات و ويژگی های جدیدی می باشد.

در زمینه ی تغییرات برای میزکارها می توان به استفاده از میزکار Gnome 46 در نسخه ی Fedora workstation 40 اشاره کرد و همچنین استفاده کردن از KDE Plasma 6 در نسخه Fedora KDE

از دیگر تغییراتی مهمی که به چشم می خورد در زمینه ی توسعه هوش مصنوعی (AI development) و استفاده از بسته ی PyTorch می باشد.

PyTorch یک فریمورک (framework) محبوب برای deep learning است و نصب مطمئن آن با نسخه های مناسب درایورها و کتابخانه ها و غیره می تواند دشوار باشد. بسته فعلی فقط از اجرا بر روی CPU، بدون شتاب دهنده GPU یا NPU پشتیبانی می کند، اما این فقط اولین مرحله است زیرا هدف تولید یک پشته کامل با PyTorch و سایر ابزارهای محبوب آماده برای استفاده در انواع سخت افزارها است.

مانند همیشه جهت دانلود نسخه های مختلف لینوکس فدورا ۴۰ می توانید به سایت رسمی آن مراجعه کنید:

https://fedoraproject.org/

 

The post نسخه نهایی لینوکس فدورا ۴۰ منتشر شد first appeared on طرفداران فدورا.

Moving GPU drivers out of the initramfs

Posted by Hans de Goede on April 29, 2024 01:13 PM
The firmware which drm/kms drivers need is becoming bigger and bigger and there is a push to move to generating a generic initramfs on distro's builders and signing the initramfs with the distro's keys for security reasons. When targetting desktops/laptops (as opposed to VMs) this means including firmware for all possible GPUs which leads to a very big initramfs.

This has made me think about dropping the GPU drivers from the initramfs  and instead make plymouth work well/better with simpledrm (on top of efifb). A while ago I discussed making this change for Fedora with the Red Hat graphics team spoiler: For now nothing is going to change.

Let me repeat that: For now there are no plans to implement this idea so if you believe you would be impacted by such a change: Nothing is going to change.

Still this is something worthwhile to explore further.

Advantages:

1. Smaller initramfs size:

* E.g. a host specific initramfs with amdgpu goes down from 40MB to 20MB
* No longer need to worry about Nvidia GSP firmware size in initrd
* This should also significantly shrink the initrd used in liveimages

2. Faster boot times:

* Loading + unpacking the initrd can take a surprising amount of time. E.g. on my old AMD64 embedded PC (with BobCat cores) the reduction of 40MB -> 20MB in initrd size shaves approx. 3 seconds of initrd load time + 0.6s seconds from the time it takes to unpack the initrd
*  Probing drm connectors can be slow and plymouth blocks the initrd -> rootfs transition while it is busy probing

3. Earlier showing of splash. By using simpledrm for the splash the splash can be shown earlier, avoiding the impression the machine is hanging during boot. An extreme example of this is my old AMD64 embedded PC, where the time to show the first frame of the splash goes down from 47 to 9 seconds.

4. One less thing to worry about when trying to create a uniform desktop pre-generated and signed initramfs (these would still need support for nvme + ahci and commonly used rootfs + lvm + luks).
 
Disadvantages:

Doing this will lead to user visible changes in the boot process:

1. Secondary monitors not lit up by the efifb will stay black during full-disk encryption password entry, since the GPU drivers will now only load after switching to the encrypted root. This includes any monitors connected to the non boot GPU in dual GPU setups.

Generally speaking this is not really an issue, the secondary monitors will light up pretty quickly after the switch to the real rootfs. However when booting a docked laptop, with the lid closed and the only visible monitor(s) are connected to the non boot GPU, then the full-disk encryption password dialog will simply not be visible at all.

This is the main deal-breaker for not implementing this change.

Note because of the strict version lock between kernel driver and userspace with nvidia binary drivers, the nvidia binary drivers are usually already not part of the initramfs, so this problem already exists and moving the GPU drivers out of the initramfs does not really make this worse.

2. With simpledrm plymouth does not get the physical size of the monitor, so plymouth will need to switch to using heuristics on the resolution instead of DPI info to decide whether or not to use hidpi (e.g. 2x size) rendering and even when switching to the real GPU driver plymouth needs to stay with its initial heuristics based decision to avoid the scaling changing when switching to the real driver which would lead to a big visual glitch / change halfway through the boot.

This may result in a different scaling factor for some setups, but I do not expect this really to be an issue.

3. On some (older) systems the efifb will not come up in native mode, but rather in 800x600 or 1024x768.

This will lead to a pretty significant discontinuity in the boot experience when switching from say 800x600 to 1920x1080 while plymouth was already showing the spinner at 800x600.

One possible workaround here is to add: 'video=efifb:auto' to the kernel commandline which will make the efistub switch to the highest available resolution before starting the kernel. But it seems that the native modes are simply not there on systems which come up at 800x600 / 1024x768 so this does not really help.

This does not actually break anything but it does look a bit ugly. So we will just need to document this as an unfortunate side-effect of the change and then we (and our users) will have to live with this (on affected hardware).

4. On systems where a full modeset is done the monitor going briefly black from the modeset will move from being just before plymouth starts to the switch from simpledrm drm to the real driver. So that is slightly worse. IMHO the answer here is to try and get fast modesets working on more systems.

5. On systems where the efifb comes up in the panel's native mode and a fast modeset can be done, the spinner will freeze for a (noticeable) fraction of a second as the switch to the real driver happens.

Preview:

To get an impression what this will look / feel like on your own systems, you can implement this right now on Fedora 40 with some manual configuration changes:

1. Create /etc/dracut.conf.d/omit-gpu-drivers.conf with:

omit_drivers+=" amdgpu radeon nouveau i915 "

And then run "sudo dracut -f" to regenerate your current initrd.

2. Add to kernel commandline: "plymouth.use-simpledrm"

3. Edit /etc/selinux/config, set SELINUX=permissive this is necessary because ATM plymouth has issues with accessing drm devices after the chroot from the initrd to the rootfs.

Note this all assumes EFI booting with efifb used to show the plymouth boot splash. For classic BIOS booting it is probably best to stick with having the GPU drivers inside the initramfs.

comment count unavailable comments

What’s new for Fedora Atomic Desktops in Fedora 40

Posted by Fedora Magazine on April 29, 2024 08:00 AM

Fedora 40 has been released! 🎉 So let’s see what comes in this new release for the Fedora Atomic Desktops variants (Silverblue, Kinoite, Sway Atomic and Budgie Atomic).

Introducing Fedora Atomic Desktops

As you might have guessed from the title, we are now called Fedora Atomic Desktops! See the Introducing Fedora Atomic Desktops Fedora Magazine article for all the details.

The summary is that the Fedora Atomic Desktops are made up of four atomic spins:

  • Fedora Silverblue
  • Fedora Kinoite
  • Fedora Sway Atomic (was Fedora Sericea)
  • Fedora Budgie Atomic (was Fedora Onyx)

And we have a landing page on fedoraproject.org.

Status update on bootloader updates (bootupd integration)

Unfortunately, we could not land bootupd support in this release due to an issue found late in Anaconda’s handling of bootupd installations which relied on incomplete functionality in bootupd.

We will attempt to add bootupd again after the release, via an update.

If you encounter Secure Boot errors or need to update your bootloader in the meantime, you can try the instructions from fedora-silverblue#543. Make sure to have a Live USB ready in case you encounter an issue. Please make backups beforehand.

We are hoping to land improvements to bootupd that should simplify this process.

See: atomic-desktops-sig#1.

What’s new in Silverblue

Latest GNOME release

Fedora Silverblue comes with the latest GNOME 46 release.

For more details about the changes that comes with GNOME 46, see What’s new in Fedora Workstation 40 on the Fedora Magazine and Fedora Workstation 40 – what are we working on from Christian F.K. Schaller.

No longer overlay language packages (langpack) by default

GNOME Software will no longer overlay the langpack packages for your locale on the first update. This should make updates much faster as they won’t need to overlay packages anymore (unless you explicitly decide to overlay some packages).

If you are updating from a previous release, you will have to remove this overlayed package manually. For example:

1. Find the overlayed package using rpm-ostree status:

$ rpm-ostree status
State: idle
Deployments:
● fedora:fedora/40/x86_64/silverblue
Version: 40.20240410.1 (2024-04-10T03:43:23Z)
Commit: 2428fdbec13787633b3bcd79d4f002ab48582bae8c6a473ca357a1ad43573a94
GPGSignature: Valid signature by E8F23996F23218640CB44CBE75CF5AC418B8E74C
LayeredPackages: langpacks-fr

fedora:fedora/40/x86_64/silverblue
Version: 40.20240402.0 (2024-04-02T00:39:43Z)
Commit: 634c8097165e6aab2baeaca6ae6d1ea2a7f11fba9f4955297bcf0fc2507047be
GPGSignature: Valid signature by E8F23996F23218640CB44CBE75CF5AC418B8E74C
LayeredPackages: langpacks-fr

2. Remove the overlayed package and reboot:

$ rpm-ostree uninstall langpacks-fr
...

Note that this will remove the dictionaries for the corresponding language from your system and thus for applications included in the image.

For Flatpaks, the dictionaries are downloaded according to the languages set in the Flatpak config. If you have set your preferred languages in GNOME Settings, this configuration should have been set already. For example:

# Get the current config
$ flatpak config --list
languages: en;fr;de (default: en)
extra-languages: *unset*

# Set the languages to use
$ flatpak config --set languages "en;fr"

See the flatpak-config documentation for more details.

Also note that with this change the translated man pages for system commands will also be removed. To get the man pages back, you can install them in a container using toolbox for example:

$ toolbox create
$ toolbox enter
$ sudo dnf install man-pages-fr

See: atomic-desktops-sig#14.

What’s new in Kinoite

KDE Plasma 6

Fedora Kinoite ships with Plasma 6, Frameworks 6 and Gear 24.02 (Fedora Change). See also What’s New in Fedora KDE 40? on the Fedora Magazine.

Wayland only

Fedora Kinoite is now Wayland only. Legacy X11 applications will run using XWayland. See Fedora 40: X11 is now unsupported.

If you have an NVIDIA GPU and encounter issues, I recommend looking at Universal Blue images (see below), waiting for an upcoming NVIDIA driver update that will hopefully improve Wayland support or trying out the updated Nouveau / NVK stack for supported cards.

KDE Apps as Fedora Flatpaks

A subset of KDE Apps are now installed by default as Fedora Flatpaks by Ananconda for new installations. The Flatpaks are not installed on updates but you can install them from the Fedora Flatpak remote or from Flathub.

KDE Flatpaks on Flathub

Most KDE Apps are directly published and maintained on Flathub by the KDE community and we have mostly completed the transition to the Qt 6.6 and KDE Framework 6 Runtime.

You can track the progress for the remaining apps in kde/teams/flathub#26.

What’s new in Sway Atomic

Fedora Sway Atmoic comes with the latest 1.9 Sway release.

What’s new in Budgie Atomic

Fedora Budgie Atomic ships with the latest release of the Budgie Desktop 10.9 “release series”. Budgie 10.9 features some initial porting work to libxfce4windowing as it progresses towards its move to Wayland and redesigns its Bluetooth applet with new direct (dis-)connect functionality.

Additionally, Fedora Budgie Atomic ships with the latest Budgie Control Center and takes into use budgie-session. As Buddies of Budgie officially supports Fedora, Budgie Desktop has also received numerous backported bug fixes to provide Fedora users an even better experience.

You can learn more about the latest happenings in Budgie on the Buddies of Budgie blog.

What’s next

Unfortunately, this section will be short this time, as there has not been much progress on our future plans since the last time.

We will provide an updated article when more information becomes available.

Teaser for improved update support in Discover for Kinoite

<figure class="wp-block-image size-large"></figure>

Universal Blue, Bluefin, Bazzite and Aurora

Our friends in the Universal Blue, Bluefin and Bazzite projects also released updates for their images.

Universal Blue is now considered Generally Available alongside Bluefin.

For all your gaming needs, Bazzite reached version 3.0, rebasing on our fresh Fedora 40 images.

They are also introducing Aurora, a KDE Plasma and Kinoite based alternative to Bluefin. See the Introduction to Aurora post for all the details.

Where to reach us

We are looking for contributors to help us make the Fedora Atomic Desktops the best experience for Fedora users.

Week 17 in Packit

Posted by Weekly status of Packit Team on April 29, 2024 12:00 AM

Week 17 (April 23rd – April 29th)

  • We have fixed the syncing of ACLs during CentOS Stream release syncing. (packit#2298)
  • koji_build job has a new sidetag_group option that allows to perform a downstream Koji build in a sidetag. A new sidetag will be created for each configured dist_git_branch if it doesn't already exist. This represents the first step towards multi-package Bodhi updates. Stay tuned for further advancements! (packit-service#2409)
  • We have fixed an issue when copr_build job status checks were sometimes wrongly updated with a misleading message after a SRPM build failure. (packit-service#2406)

Episode 426 – Automatically exploiting CVEs with AI

Posted by Josh Bressers on April 29, 2024 12:00 AM

Josh and Kurt talk about a paper describing using a LLM to automatically create exploits for CVEs. The idea is probably already happening in many spaces such as pen testing and intelligence services. We can’t keep up with the number of vulnerabilities we have, there’s no way we can possibly keep up with a glut of LLM generated vulnerabilities. We really need to rethink how we handle vulnerabilities.

<audio class="wp-audio-shortcode" controls="controls" id="audio-3372-2" preload="none" style="width: 100%;"><source src="https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_426_Automatically_exploiting_CVEs_with_AI.mp3?_=2" type="audio/mpeg">https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_426_Automatically_exploiting_CVEs_with_AI.mp3</audio>

Show Notes

What’s new for Fedora Atomic Desktops in Fedora 40

Posted by Timothée Ravier on April 28, 2024 10:00 PM

Fedora 40 has been released! 🎉 So let’s see what comes in this new release for the Fedora Atomic Desktops variants (Silverblue, Kinoite, Sway Atomic and Onyx Atomic).

Note: You can also read this post on the Fedora Magazine.

Introducing Fedora Atomic Desktops

As you might have guessed from the title, we are now called Fedora Atomic Desktops! See the Introducing Fedora Atomic Desktops Fedora Magazine article for all the details.

The summary is that the Fedora Atomic Desktops are made up of four atomic spins:

  • Fedora Silverblue
  • Fedora Kinoite
  • Fedora Sway Atomic (was Fedora Sericea)
  • Fedora Budgie Atomic (was Fedora Onyx)

And we have a landing page on fedoraproject.org.

Status update on bootloader updates (bootupd integration)

Unfortunately, we could not land bootupd support in this release due to an issue found late in Anaconda’s handling of bootupd installations which relied on incomplete functionality in bootupd.

We will attempt to add bootupd again after the release, via an update.

If you encounter Secure Boot errors or need to update your bootloader in the meantime, you can try the instructions from fedora-silverblue#543. Make sure to have a Live USB ready in case you encounter an issue. Please make backups beforehand.

We are hoping to land improvements to bootupd that should simplify this process.

See: atomic-desktops-sig#1.

What’s new in Silverblue

Latest GNOME release

Fedora Silverblue comes with the latest GNOME 46 release.

For more details about the changes that comes with GNOME 46, see What’s new in Fedora Workstation 40 on the Fedora Magazine and Fedora Workstation 40 – what are we working on from Christian F.K. Schaller.

No longer overlay language packages (langpacks) by default

GNOME Software will no longer overlay the langpack packages for your locale on the first update. This should make updates much faster as they won’t need to overlay packages anymore (unless you explicitly decide to overlay some packages).

If you are updating from a previous release, you will have to remove this overlayed package manually. For example:

  1. Find the overlayed package using rpm-ostree status:
<figure class="highlight">
$ rpm-ostree status
State: idle
Deployments:
● fedora:fedora/40/x86_64/silverblue
                Version: 40.20240410.1 (2024-04-10T03:43:23Z)
                 Commit: 2428fdbec13787633b3bcd79d4f002ab48582bae8c6a473ca357a1ad43573a94
           GPGSignature: Valid signature by E8F23996F23218640CB44CBE75CF5AC418B8E74C
        LayeredPackages: langpacks-fr

fedora:fedora/40/x86_64/silverblue
                Version: 40.20240402.0 (2024-04-02T00:39:43Z)
                 Commit: 634c8097165e6aab2baeaca6ae6d1ea2a7f11fba9f4955297bcf0fc2507047be
           GPGSignature: Valid signature by E8F23996F23218640CB44CBE75CF5AC418B8E74C
        LayeredPackages: langpacks-fr
</figure>
  1. Remove the overlayed package and reboot:
<figure class="highlight">
$ rpm-ostree uninstall langpacks-fr
...
</figure>

Note that this will remove the dictionaries for the corresponding language from your system and thus for applications included in the image.

For Flatpaks, the dictionaries are downloaded according to the languages set in the Flatpak config. If you have set your preferred languages in GNOME Settings, this configuration should have been set already. For example:

<figure class="highlight">
# Get the current config
$ flatpak config --list
languages: en;fr;de (default: en)
extra-languages: *unset*

# Set the languages to use
$ flatpak config --set languages "en;fr"
</figure>

See the flatpak-config documentation for more details.

This will also remove the translated man pages for system commands. To get the man pages back, you can install them in a container using toolbox for example:

<figure class="highlight">
$ toolbox create
$ toolbox enter
$ sudo dnf install man-pages-fr
</figure>

See: atomic-desktops-sig#14.

What’s new in Kinoite

KDE Plasma 6

Fedora Kinoite ships with Plasma 6, Frameworks 6 and Gear 24.02 (Fedora Change). See also What’s New in Fedora KDE 40? on the Fedora Magazine.

Wayland only

Fedora Kinoite is now Wayland only. Legacy X11 applications will run using XWayland. See Fedora 40: X11 is now unsupported.

If you have a NVIDIA GPU and encounter issues, I recommend looking at Universal Blue images, waiting for an upcoming NVIDIA driver update that will hopefully improve Wayland support or trying out the updated Nouveau / NVK stack for supported cards.

KDE Apps as Fedora Flatpaks

A subset of KDE Apps are now installed by default as Fedora Flatpaks by Ananconda for new installations. The Flatpaks are not installed on updates but you can install them from the Fedora Flatpak remote or from Flathub.

KDE Flatpak on Flathub

Most KDE Apps are directly published and maintained on Flathub by the KDE community and we have mostly completed the transition to the Qt 6.6 / KDE Framework 6 Runtime.

You can track the progress for the remaining apps in kde/teams/flathub#26.

What’s new in Sway Atomic

Fedora Sway Atmoic comes with the latest 1.9 Sway release.

What’s new in Budgie Atomic

Fedora Budgie Atomic ships with the latest release of the Budgie Desktop 10.9 “release series”. Budgie 10.9 features some initial porting work to libxfce4windowing as it progresses towards its move to Wayland and redesigns its Bluetooth applet with new direct (dis-)connect functionality.

Additionally, Fedora Budgie Atomic ships with the latest Budgie Control Center and takes into use budgie-session. As Buddies of Budgie officially supports Fedora, Budgie Desktop has also received numerous backported bug fixes to provide Fedora users an even better experience.

You can learn more about the latest happenings in Budgie on the Buddies of Budgie blog.

What’s next

Unfortunately, this section will be short this time, as there has not been much progress on our future plans since the last time.

We will provide an updated article when more information becomes available.

Teaser for improved update support in Discover for Kinoite

Plasma Discover's main application window, on the update tab, showing a pending operating system update, which is highlighted in green. For this update, the size is also available and highlighted in blue.

Universal Blue, Bluefin, Bazzite and Aurora

Our friends in the Universal Blue, Bluefin and Bazzite projects also released updates for their images.

Universal Blue is now considered Generally Available alongside Bluefin.

For all your gaming needs, Bazzite reached version 3.0, rebasing on our fresh Fedora 40 images.

They are also introducing Aurora, a KDE Plasma and Kinoite based alternative to Bluefin. See the Introduction to Aurora post for all the details.

Where to reach us

We are looking for contributors to help us make the Fedora Atomic Desktops the best experience for Fedora users.

Fedora Ops Architect Weekly

Posted by Fedora Community Blog on April 28, 2024 09:30 PM

I hope you are all enjoying F40 and for some information on a few upcoming important stuff ‘n’ things in Fedora, read on 🙂

Flock to Fedora CfP Closes Soon

If you have not already submitted a talk/workshop/whatever you have been thinking about doing to the Flock to Fedora cfp, you are in luck – submission closes tomorrow, April 29th so you have one more day to get that great idea of yours into us.

Flock to Fedora is set for August 7th – 10th in Rochester, NY, USA. Check out the website for more details on our annual contributors conference.

Fedora 40 Elections Now Open

The Fedora Linux 40 elections cycle has now begun, and our nominations period is open! You can nominate yourself, or someone you think would be a great fit (with their permission of course), to the Fedora Council, Fedora Mindshare Committee, Fedora Engineering Steering Committee or the EPEL Steering Committee until May 8th.

To nominate yourself or someone else, you just need to visit the nominations page of whichever group you would like to be elected to and fill out your name and FAS ID in the nominations box at the end. A set of interview questions will then be shared with each candidate after the nominations period closes for them to answer, which will be published on the community blog a few weeks before voting opens.

This term, the following seats are open:

For more information on the elections process in Fedora, visit our docs site and for other key dates, you can view the elections schedule too.

Fedora Linux 41

Development is now underway (and has been for a while) on Fedora Linux 41 and our release schedule is live. Here are some dates you should keep in mind if you have any changes you would like to propose for F41:

  • June 19th – Changes requiring infrastructure changes
  • June 25th – Changes requiring mass rebuild
  • June 25th – System Wide changes
  • July 16th – Self Contained changes

If you are unsure of how to propose a change, there is some excellent documentation and video tutorial to help, and you can always reach out directly to me too.

Below are some recently announced changes for F41 and feedback is most welcome:

Hot Topics

There is a lot of conversations happening around Fedora, and it can be hard to keep track of them all! Below is the top two on my own list from both discussion.fpo and devel@lists.fedoraproject.org, in case you need some inspiration 🙂

Help Wanted and FYIs

Did you know there is a weekly hack-athon on the Fedora Infra apps happening? Aurélien Bompard hosts a weekly stream on twitch every Friday (that hes available) where he goes through bugfixes. Turn on notifications to Aurélien’s topic thread on discourse and catch him on twitch on Fridays!

As always, package reviews are needed and welcome and if you would like to adopt any packages that have been orphaned, you can find the full list from the most recent email, or visit the packager dashboard here.

The post Fedora Ops Architect Weekly appeared first on Fedora Community Blog.

Fedora Linux 40 est disponible avec un nouveau GNOME et KDE Plasma !

Posted by Charles-Antoine Couret on April 28, 2024 04:08 PM

En ce mardi 23 avril, les utilisateurs du Projet Fedora seront ravis d'apprendre la disponibilité de la version Fedora Linux 40.

Fedora Linux est une distribution communautaire développée par le projet Fedora et sponsorisée par Red Hat, qui lui fournit des développeurs ainsi que des moyens financiers et logistiques. Fedora Linux peut être vue comme une sorte de vitrine technologique pour le monde du logiciel libre, c’est pourquoi elle est prompte à inclure des nouveautés.

Cette 40e édition propose principalement une mise à jour de son interface principale GNOME 46 et de son concurrent KDE Plasma 6 qui passe à Wayland par défaut au passage.

Expérience utilisateur

Passage à GNOME 46. Cette version se démarque par beaucoup d'améliorations pour son navigateur de fichiers nommé Fichiers. Il dispose dorénavant, en plus d'une recherche dans le dossier et sous-dossiers en cours, d'une recherche globale utilisable via le bouton dédié avec une icône de loupe ou par le raccourci clavier Ctrl+Shift+F (contrairement à la recherche locale qui se fait via le raccourci Ctrl+F). Il permet de chercher dans l'ensemble du répertoire utilisateur voire davantage selon les préférences de l'utilisateur.

L'icône de loupe prend place où était l'icône de progression lors des opérations sur les fichiers comme les décompressions ou la copie de fichiers. De fait ces opérations sont affichées en bas de la barre latérale ce qui permet d'afficher plus d'informations en un coup d’œil. L'application bénéficie en outre d'améliorations de performances en particulier pour afficher de gros dossiers avec des images ou lors du passage d'une vue liste à une vue par icônes et vice-versa. Plus de périphériques sur le réseau peuvent être découverts automatiquement permettant notamment de parcourir leurs fichiers.

GNOME prend en charge les comptes Microsoft OneDrive ce qui permet de facilement parcourir les fichiers sauvegardés avec ce service. Dans les comptes à distance, le protocole WebDAV est aussi pris en charge pour l'accès à des calendriers, listes de contacts et autres fichiers partagés. Pour l'authentification de ces comptes en ligne, le navigateur par défaut est utilisé dorénavant ce qui permet d'utiliser une plus grande diversité de moyens d'authentifications comme l'usage de périphériques USB dédiés.

Pour les amateurs de la connexion distante, il est maintenant possible de se connecter à GNOME graphiquement à distance via le protocole RDP. Auparavant seulement une session ouverte pouvait être pilotée ainsi. Cette option est désactivée par défaut et nécessite des droits appropriés, tout se configure via le panneau de configuration tout comme le bureau distant.

En parlant du panneau de configuration, ce dernier a été amélioré en regroupant plusieurs configurations par sections afin d'améliorer la clarté de l'application. La liste des menus devenait particulièrement importante et rendait difficile la localisation des éléments à configurer. De plus, la configuration du pavé tactile a été améliorée pour permettre de choisir entre le clic dans un coin ou le clic à deux doigts pour réaliser l'équivalent d'un clic droit avec ce périphérique.

Côté accessibilité, le lecteur d'écran Orca a été modernisé pour le rendre plus performant, plus fiable et plus compatible avec les applications Wayland ou celles exécutées dans un bac à sable tel que Flatpak. Il est possible de couper temporairement Orca avec le raccourci clavier Ctrl+Alt+Shift+Q ce qui est particulièrement utile en cas de conflit entre deux lecteurs d'écran ou si une application utilise du son aussi.

Les notifications dans GNOME indiquent par quelle application elles ont été émises. Il est maintenant possible d'étendre facilement la notification afin de pouvoir la visualiser en entier, utilisant une vue plus compacte par défaut.

De manière plus générale, GNOME bénéfice d'améliorations de performances notamment pour son terminal, son moniteur système qui bénéficie aussi d'un graphe dédié aux entrées / sorties sur les espaces de stockage, pour l'enregistrement de l'écran, le visionneur d'images ou encore pour la recherche globale de GNOME. L'ensemble des applications GTK4 bénéficie d'un nouveau moteur de rendu qui améliore le rendu du texte mais aussi les performances.

L'environnement de bureau KDE Plasma change de version majeure avec sa nouvelle version 6. Au passage Plasma 6 utilise Wayland par défaut, et s'il était prévu de supprimer totalement la possibilité de l'utiliser avec X11 pour simplifier la maintenance, des volontaires ont permis de repousser l'échéance pour l'instant.

Sous le capot, cette version utilise la nouvelle bibliothèque majeure graphique qu'elle emploie à savoir Qt 6. C'était l'occasion par ailleurs de rationaliser les différentes couches techniques et APIs internes afin de supprimer ce qui n'était plus au goût du jour ou trop peu employé pour être maintenu.

Cette version propose la prise en charge partielle du rendu des couleurs en HDR pour les applications et matériel compatibles, mais aussi un profil de couleur spécifique par écran afin d'avoir un rendu fidèle des couleurs. Dans cette thématique pour les personnes souffrant de daltonisme ou d'autres formes de maladies dichromatiques peuvent utiliser des filtres pour améliorer la lisibilité des applications et de leur contenu.

Dans les changements plus classiques, la barre principale est par défaut en mode flottant comme pour beaucoup de docks d'autres environnement de bureaux ou systèmes d'exploitation. Il est bien sûr possible de changer tout cela dans les paramètres et plus encore concernant cette barre principale. Concernant l'affichage principal, l'effet cube en cas de changement de bureau virtuel est de nouveau disponible. Pour la capture d'écran, il est possible de choisir une zone arbitraire de l'écran, d'utiliser le codec VP9 pour les enregistrements vidéos et de choisir sa qualité.

Le thème par défaut de l'environnement nommé Breeze bénéficie d'un rafraichissement, il utilise moins de cadres et a un affichage un peu plus compact.

Comme pour GNOME, la recherche a bénéficié d'un effort important. En plus de permettre la conversion de fuseaux horaires ou de trier les résultats par type, les performances sont grandement améliorées : jusqu'à 200% plus rapide pour chercher des documents, jusqu'à 60% plus rapide pour trouver une application, le tout jusqu'à moins 30% d'usage du processeur. La recherche obtient les résultats pour les textes traduits dans votre langue ou en anglais pour les noms ou les descriptions d'applications par exemple.

Il est dorénavant possible de s'authentifier par mot de passe ou par empreinte digitale en même temps, il n'est plus nécessaire de forcer l'une des deux options.

Et tant d'autres changements encore.

Gestion du matériel

Fourniture de ROCm 6 pour améliorer la prise en charge de l'IA et le calcul haute performance pour les cartes graphiques ou accélérateurs d'AMD. Il concerne notamment les puces AMD Instinct MI300A et MI300X, et fournit de nouveaux algorithmes optimisés du mécanisme d'attention et de bibliothèques de communication. Il permet l'usage de flottant 8 bits pour gagner en consommation mémoire au détriment de la précision du modèle pour PyTorch et hipblasLT. Via la plateforme AMD Infinity Hub, il est possible d'obtenir des paquets prêts à l'usage pour certains travaux en IA ou calculs haute performance notamment pour les calculs scientifiques.

Passage à l'étape 2 de la prise en charge du noyau unifié nommée UKI (donc unifiant noyau, initrd, ligne de commande du noyau et signature) pour les plateformes avec UEFI mais rien ne change par défaut à ce sujet. L'objectif dans cette phase est de pouvoir démarrer sur de tels noyaux directement sans chargeur de démarrage intermédiaire, tout en offrant la possibilité de démarrer sur d'autres noyaux et de passer automatiquement au noyau suivant par défaut suite à une mise à jour. Les machines Aarch64 (ARM 64 bits) peuvent également s'en servir maintenant. Une image pour cette architecture et x86_64 doit également être fournie pour un contexte de virtualisation en étant basée sur ces fichiers kickstart.

Si vous souhaitez tester cela sur un système existant, vous pouvez installer les paquets virt-firmware, uki-direct avant d'exécuter le script sh /usr/share/doc/python3-virt-firmware/experimental/fixup-partitions-for-uki.sh pour configurer les partitions proprement afin d'être découvrables par le système, puis enfin installer le paquet kernel-uki-virt pour qu'il installe le noyau proprement avec la nouvelle méthode. Il est préférable de tester cela sur une machine virtuelle ou si vous savez ce que vous faites avec du matériel standard type ahci / nvme pour le stockage principal. Bien sûr ce travail reste expérimental et est réservé à ceux qui savent comment faire pour réparer le système en cas de problèmes.

Internationalisation

Le gestionnaire d'entrée de saisie IBus passe à la version 1.5.30. Les commandes pour lancer et relancer IBus fonctionnent depuis l'environnement Plasma Wayland dorénavant, et pour cet environnement aussi les préférences sont maintenant accessibles depuis le menu non contextuel.

Mise à jour de ibus-anthy 1.5.16 pour la saisie du japonais. Le principal changement est la conversion possible d'ère japonaise avec 2024.

Administration système

NetworkManager tente de détecter par défaut les conflits d'usage d'adresse IPv4 avec le protocole Address Conflict Detection (RFC 5227) avant de l'attribuer à la machine. En somme au moment de s'attribuer une adresse IP donnée, une requête ARP est envoyée au réseau concernant cette adresse. Si une réponse est obtenue, l'adresse est déjà utilisée et n'est donc pas exploitable sans perturber le réseau. Ce mécanisme existe pour les réseaux avec IP fixes ou même avec un serveur DHCP central car rien n'empêche la présence d'une machine configurée avec une IP fixe dans le réseau malgré tout. Si le réseau a un serveur DHCP et qu'un conflit est détecté, la réponse DHCPDECLINE sera envoyée pour obtenir peut être une autre adresse. En cas de conflit une erreur sera rapportée permettant à l'utilisateur de diagnostiquer le problème et d'y apporter une solution. Par défaut le système attendra 200 ms avant de décider qu'il n'y a aucune réponse. Pour l'IPv6 cela est inclus dans le standard RFC 4862 ce qui rend ce changement non nécessaire dans ce cas de figure.

NetworkManager va utiliser une adresse MAC aléatoire par défaut pour chaque réseau Wifi différent, et cette adresse sera stable pour un réseau donné. En effet, certains systèmes utilisent l'adresse Mac pour identifier les machines en déplacement de réseau en réseau permettant une pseudo géolocalisation ce qui nuit à la vie privée. Mais la méthode usuelle de changer d'adresse MAC aléatoirement à chaque connexion pose un problème en cas de réseau restreignant l'accès à certaines adresses MAC uniquement ou en changeant d'adresse IP à chaque reconnexion. Cette méthode est un compromis entre le respect de la vie privée et le confort d'utilisation. Cela est fait en ajoutant la configuration wifi.cloned-mac-address="stable-ssid" dans le nouveau fichier /usr/lib/NetworkManager/conf.d/22-wifi-mac-addr.conf.

Les entrées des politiques SELinux qui font référence au répertoire /var/run font maintenant référence au répertoire /run. Il y a dix ans déjà que le premier répertoire a bougé vers le deuxième chemin mais SELinux a gardé les vieilles règles en utilisant un lien d'équivalence entre eux pour permettre leur utilisation. Cependant certains outils comme restorecon ne gèrent pas bien cette situation tout comme les administrateurs systèmes qui ne sont pas sûrs de comment écrire proprement de nouvelles règles. Pour résoudre le problème le lien d'équivalence passe de /run = /var/run à /var/run = /run.

L'outil SSSD ne prend plus en charge les fichiers permettant de gérer les utilisateurs locaux. Il pouvait exploiter les fichiers /etc/passwd et /etc/group via l'utilisation de l'option id_provider=files. Cependant cette option n'est plus proposée par le projet officiel et n'était à l'époque conservée que pour permettre l'authentification via des cartes à puce ou l'enregistrement de sessions. Mais dans les deux cas il est possible de passer à la méthode proxy via l'option id_provider=proxy pour le remplacer dans ces cas d'usage. Un guide officiel est proposé pour effectuer la conversion pour ceux qui en ont besoin.

DNF ne téléchargera plus par défaut la liste des fichiers fournie par les différents paquets. Jusqu'à présent il le faisait par défaut parmi d'autres métadonnées, mais cette information n'est en réalité nécessaire que dans certains cas précis qui ne concernent pas celui de la majorité des utilisateurs. Notamment pour quelques paquets ayant une dépendance envers un fichier particulier plutôt qu'un paquet donné ou si on cherche un paquet fournissant un fichier spécifique. Cela permet de réduire les ressources consommées chez les utilisateurs mais aussi au sein de l'infrastructure de Fedora car il n'est plus nécessaire de fournir ces données assez conséquentes de manière systématique.

L'outil fwupd pour mettre à jour les firmwares va utiliser passim comme cache pour partager sur le réseau local les métadonnées liées aux mises à jour disponibles pour les firmwares. Ce fichier qui représente environ 1 Mio est téléchargé quotidiennement parfois sur des liaisons coûteuses. Ainsi la pression est réduite sur les infrastructures notamment le CDN fwupd et la bande passante en utilisant localement la ressource quand elle est disponible. Passim utilise avahi pour signaler son service sur le réseau local qui est disponible via le port 27500 afin que les autres clients puissent identifier si des métadonnées sont disponibles localement.

Les systèmes Fedora Silverblue et Kinoite disposent de bootupd pour la mise à jour du chargeur de démarrage. Par conception les systèmes avec rpm-ostree comme ceux-ci n'ont pas le chargeur de démarrage qui se met à jour par ce biais car cela n'est pas une opération sûre. En effet, la mise à jour de ces systèmes repose sur le principe de transaction pour que le passage d'un état à un autre soit fiable, cependant ce mécanisme ne fonctionne pas bien pour le chargeur de démarrage qui est un composant distinct et critique. On retrouve la même problématique pour les systèmes utilisant un mécanisme de mise à jour basé sur une partition A et B et passant de l'un à l'autre. D'où la création de cet utilitaire qui est mis à disposition pour ceux qui le souhaitent, du moins pour les machines disposant d'un EFI. La mise à jour est pour le moment manuelle à la demande avec la commande bootupctl update. La mise à jour automatique sera prévue dans le futur.

Le paquet libuser est marqué en voie de suppression pour Fedora 41 alors que le paquet passwd est supprimé. La bibliothèque libuser sert à cacher les différences entre les utilisateurs locaux et distants via le protocole LDAP. Mais la prise en charge de ce protocole reste incomplet et il n'y a pas de plan pour aller plus loin, comme sssd peut la remplacer dans ce rôle, la décision de la supprimer prochainement de Fedora fait sens. Pour l'instant seuls les paquets usermode et util-linux en ont encore besoin. Le paquet passwd quant à lui disparaît pour se débarrasser de la dépendance à libuser. La commande pour changer de mot de passe ne change pas, mais est fournie par le paquet shadow-utils.

Le paquet cyrus-sasl-ntlm a été supprimé. Le protocole d'identification NTLM n'est plus maintenu, au profit du protocole Kerberos et ce composant dans SASL n'est plus maintenu depuis des années justifiant une telle décision.

La gestion des droits utilisateurs pam_userdb passe de la base de données BerkeleyDB à GDBM. BerkeleyDB 5.x fourni par Fedora n'est plus à jour ce qui pose des soucis en terme de bogues et de sécurité, d'autant plus avec le rôle de PAM dans le système. La licence de BerkeleyDB a changé dans la branche 6.x, passant de BSD à AGPL rendant impossible l'adoption de cette version plus à jour pour ce composant, les licences n'étant pas compatibles. Ainsi GDBM se pose comme une alternative pour résoudre ce problème. BerkeleyDB 5.x a débuté sa sortie du projet Fedora depuis Fedora 33, ceci est une étape de plus dans cette direction.

Le filtre antispam bogofilter utilise SQLite au lieu de BerkeleyDB pour gérer sa base de données interne. La raison est analogue au paragraphe précédent.

Le serveur LDAP 389 passe de la version 2.4.4 à la version 3.0.0. Le projet abandonne la prise en charge de BerkeleyDB pour sa base de données interne pour la même raison que précédemment. En dehors de cela qui introduit des incompatibilités, cette mise à jour est en réalité assez mineure sur les autres aspects en fournissant essentiellement des correctifs de bogues.

Le paquet iotop est remplacé par iotop-c. Si le nom du paquet change, celui du binaire installé ne change pas. iotop n'est plus vraiment maintenu depuis une dizaine d'années et est sévèrement concurrencé par iotop-c sur cet aspect qui bénéfice en plus d'une empreinte mémoire plus petite étant rédigé en C au lieu de Python. Il n'est pas pertinent aux yeux des mainteneurs de maintenir les deux ainsi.

L'orchestrateur de conteneurs Kubernetes évolue de la version 1.27 à la version 1.29. Ce changement est communiqué car Kubernetes déconseille le saut des versions ce que Fedora fait actuellement en passant à la version 1.28 en fournissant ainsi la dernière version disponible. Cette version propose aux utilisateurs la possibilité d'avoir un écart de version de n-2 à n-3 pour les versions mineures entre le nœud principal et le plan de contrôle. Il est également possible si un nœud est indisponible suite à une panne ou à un état non récupérable de démarrer les services qu'il gérait dans un autre nœud dans un état sain. Le mode d'accès aux données ReadWriteOncePod devient accessible sans restrictions, permettant de restreindre l'accès à des données à un seul pod à la fois plutôt qu'à un seul nœud, pour réduire le risque d'accès concurrents en particulier en écriture. De même le module KMS v2 est disponible à tous pour réaliser les services de chiffrement pour vos APIs.

Par ailleurs les paquets de Kubernetes sont restructurés. L'objectif est de se rapprocher de l'organisation du projet upstream et de simplifier la vie des utilisateurs. Ainsi le paquet kubernetes récupère l'utilitaire kubelet qui avait son paquet dédié et les services fournis via l'ancien sous-paquet kubernetes-master sont renommés kubernetes-systemd. Les paquets kubernetes-client et kubernetes-kubeadm restent inchangés.

Pendant que podman est mis à jour vers la version 5. Cette version abandonne la prise en charge des cgroupv1 du noyau, de même que les plugins CNI ou la base de données clé / valeur Boltdb au profit de SQLite pour les nouvelles instances. Le format des fichiers de configuration pour les podman machines a été profondément remanié, rendant nécessaire la recréation des machines virtuelles concernées conçues avant cette version.

Le paquet wget2 remplace le paquet }}wget}} en fournissant une nouvelle version. Cette version propose du code multithreadé et qui télécharge plus vite grâce à la prise en charge du protocole HTTP2 avec la compression ou le téléchargement parallèle. Il propose plus d'options, il a également plus de tests automatiques pour s'assurer de sa robustesse dans le temps. Sa réécriture dans un style plus moderne devrait faciliter l'adoption de nouveaux protocoles à l'avenir. Par contre les protocoles dépassés WARC et FTP sont moins bien pris en charge. La licence change pour GPLv3+, de même que sa bibliothèque libwget2 vers LGPLv3+.

Le gestionnaire de base de données PostgreSQL migre vers sa 16e version. De part l'arrêt des modules, les paquets pour des versions alternatives sont également réintroduits. Ainsi les paquets postgresql15* font leur apparition pour la prise en charge de la version précédente, et les paquets postgresql17* seront proposés quand la 17e version sera disponible. En terme de changements apportés par cette nouvelle version, les jointures FULL ou OUTER sur des hash peuvent être parallélisées pour de meilleures performances. Il est dorénavant possible de répliquer des données depuis des serveurs dans un état standby, de même la réplication peut être appliquée en parallèle pour de larges transactions afin d'améliorer les performances de l'opération. La vue pg_stat_io fournit des informations statistiques concernant les entrées et sorties. SQL/JSON qui est introduit dans le standard SQL bénéficie de constructeurs dédiés pour créer des objets JSON mais aussi des fonctions identités pour connaître le type des clés. Et ce parmi de nombreuses corrections de bogues et d'amélioration de performances.

Les paquets MySQL et MariaDB sont remaniés et mis à jour vers la version 10.11 pour MariaDB. Le paquet community-mysql est renommé mysql tandis que le paquet mariadb ne fourni plus de binaires avec le nom mysql. En effet la décision à l'époque a été prise car il semblait convenu que MariaDB remplacerait MySQL tout comme LibreOffice a supplanté OpenOffice.org mais force est de constater que les deux projets vont cohabiter longtemps. Cela rend le tout plus simple pour l'utilisateur. Cependant, puisque ces logiciels évoluent séparément, ils deviennent peu à peu incompatibles et le mainteneur abandonne la possibilité d'utiliser MariaDB comme serveur avec MySQL comme client et vice-versa. Aucune autre distribution en fournissait une telle possibilité et cela devenait difficile à maintenir car cela était source de problèmes.

En terme de nouvelles fonctionnalités pour MariaDB, il est possible de lire entièrement les tables Information Schema Parameters et Information Schema Routines tout en améliorant les performances dans la procédure. Il est possible de savoir combien de temps une requête passe dans l'optimiseur via l'option ANALYZE FORMAT=JSON. Les semi-jointures pour la mise à jour ou la suppression de données sont optimisées. Les privilèges SUPER et READ ONLY ADMIN sont dorénavant distincts, à ce sujet il est possible de fournir à tous les utilisateurs des droits spécifiques via la requête GRANT <privilege> ON <database>.<object> TO PUBLIC.

Développement

Mise à jour de la suite de compilation GNU : GCC 14.0, binutils 2,41, glibc 2.39 et gdb 14.1.

Concernant la suite de compilateurs GCC, elle continue l'amélioration de la prise en charge des langages C23 et C23, alors que débute la prise en charge de la future norme C26. De nombreux modèles de puces Aarch64 et x86_64 bénéficient de micro-optimisations, tandis qu'il y a un début de prise en charge des nouvelles instructions pour l'architecture x86_64 d'Intel dénommées APX et AVX10. L'analyseur statique de code peut afficher visuellement les dépassements de tampons pour mieux comprendre ce qui se passe en mémoire.

Pour la suite d'outils binutils, cela se concentre surtout sur la prise en charge plus étendue des instructions des architectures Aarch64, RISC-V et x86_64.

Quant à la bibliothèque standard C glibc, cela se traduit par de nombreuses améliorations comme la prise en charge de la pile cachée pour éviter les attaques par modification d'adresse de retour, ce que Fedora Linux active par ailleurs. De même pour limiter certaines attaques, la glibc propose de pouvoir réécrire au lancement la PLT pour obtenir les adresses des fonctions des bibliothèques dynamiques plutôt que de les avoir lors du premier appel à chaque fonction. Le programme démarre plus lentement mais est plus sûr pour la suite. L'en-tête <stdbit.h> fait son apparition pour les manipulations sur les bits, opérations basées sur la norme de C20. Et une nouvelle fonction posix_spawnattr_setcgroup_np est ajoutée pour démarrer un processus dans un cgroup donné afin d'éviter des situations de concurrence entre le moment où le processus est démarré et où les restrictions s'appliquent.

Enfin le débogueur gdb propose un début de prise en charge du protocole de Microsoft Debugger Adapter Protocol pour faire le lien entre les débogueurs et des IDEs ou éditeurs de code afin de faciliter leur intégration mutuelle. Il peut également gérer des entiers au delà de 64 bits, de même que d'appeler une commande shell avec l'instruction $_shell pour obtenir son résultat. Les instructions de l'architecture Aarch64 SME et SME2 commencent à être gérées et l'API Python est considérablement étoffée pour ceux qui veulent scripter le débogueur.

La suite de compilateurs LLVM est mise à jour à la version 18. Fedora en profite pour que CLang utilise des informations de débogage au format DWARF-5 au lieu de DWARF-4 par défaut comme appliqué par le projet amont. Pour simplifier la procédure de compilation de Fedora pour les paquets utilisant cette chaîne de compilation, le Fat-LTO sera employé pour permettre l'usage du LTO quand c'est possible comme cela était déjà le cas avec GCC. Jusqu'alors ces paquets étaient compilés avec LTO par défaut avec une éventuelle conversion vers ELF à la main si la compatibilité le nécessitait ce qui était particulièrement lourd. Par ailleurs les paquets de compatibilité des versions précédentes fournissent les binaires des différents utilitaires et non plus seulement les bibliothèques et en-têtes.

Concernant les nouveautés apportées par le projet en lui même, comme pour la chaîne de compilation GNU, les architectures Aarch64, x86_64 ou RISC-V sont mieux gérées. Le compilateur CLang suit GCC avec du travail sur C20, C23 pour améliorer la compatibilité avec le standard et le début de prise en charge de la future norme C++26.

Mise à jour de la bibliothèque C++ Boost à la version 1.83. Depuis la version 1.81, cette bibliothèque propose un module pour communiquer avec les bases de données MySQL ou encore une bibliothèque Compat: pour fournir en code compatible C++11 des ajouts proposés par les standards ultérieurs.

Le langage Go passe à la version 1.22. La sémantique de la boucle for évolue un peu avec la création de la variable de boucle à chaque itération de boucle plutôt qu'à la première avec mise à jour à chaque passage. De plus il accepte l'usage des plages de valeurs basées sur des entiers. L'exécution des programmes gagne 1 à 3% grâce à l'optimisation de la localisation mémoire des métadonnées du ramasse miette. Les programmes compilés avec un profil d'optimisation peuvent gagner entre 2 et 14% de performances par rapport à la version précédente grâce à la possibilité d'appliquer la technique sur plus de fonctions qu'avant.

Le JDK de référence pour Java passe de la version 17 à 21. OpenJDK peut maintenant faire du filtrage par motif dans une instruction switch. Il est possible aussi d'affecter le résultat d'une identification de type dans une variable directement afin de pouvoir s'en servir immédiatement. Des fils d'exécution virtuels font leur apparition qui sont plus légers et performants, plutôt dédiés à des tâches courtes avec beaucoup d'attentes, ces tâches peuvent ainsi bénéficier de meilleure performance notamment en terme de latence. Il introduit également une API pour les collections d'objet en séquence (donc ordonnées). De même une nouvelle API pour manipuler les clés cryptographiques symétriques fait son entrée. Le ramasse miette Z Garbage Collector améliore ses performances.

Ruby 3.3 surveille sa syntaxe avec Prism. Prism est un gem introduisant un nouveau parseur très flexible qui a vocation à remplacer Ripper. Le compilateur juste à temps YJIT bénéficie de nombreuses améliorations comme de meilleures performances, une réduction de la consommation mémoire avec un code généré plus compact et avec moins de métadonnées et un temps de compilation plus court. Un concurrent RJIT fait son entrée, écrit en pur Ruby et non en C comme YJIT, il a plus vocation à servir de terrain d'expérimentation. Le ramasse miette est également plus performant.

Le langage PHP utilise la version 8.3. Cette version permet de définir des classes constantes, il propose également un attribut #\Override si une classe surcharge une méthode d'une classe parente. Une nouvelle fonction json_validate permet de vérifier la validité d'un JSON sans le décoder. Le Randomizer a plus de méthodes pour permettre de générer des noms ou nombres aléatoires suivant les besoins.

La boîte à outils pour le machine learning PyTorch fait son entrée dans Fedora. L'objectif est de fournir une meilleure expérience pour les développeurs de ce genre de solution. Un groupe de travail dédié s'est mis en place avec une réunion bi-hebdommadaire. Pour le moment l'architecture x86_64 est la seule prise en charge avec un effort important mis sur les solutions AMD.

Le paquet python-sqlalchemy utilise la nouvelle branche majeure 2.x du projet, le paquet python-sqlalchemy1.4 est proposé pour garder la compatibilité. Cette version apporte entre autre de l'annotation de type ce qui permet de construire des ORM sur un modèle déclaratif. Les opérations d'insertions sont aussi bien plus performantes quelque soit le gestionnaire de base de données derrière.

La bibliothèque de validation des données Pydantic utilise dorénavant la version 2. Outre l'amélioration des performances, il change radicalement son API ce qui coupe la compatibilité ascendante.

La bibliothèque Thread Building Blocks passe du fil 2020.3 au fil 2021.8. De même la compatibilité ascendante n'est pas garantie ce qui a rendu ce portage compliqué.

La bibliothèque OpenSSL 1.1 est supprimée ne laissant que la dernière version de la branche 3.x. Depuis Fedora 36 la branche 3 est employée par défaut dans Fedora. OpenSSL 1.1 n'est plus maintenue depuis fin de l'année dernière ce qui rend sa maintenance délicate et non sûre d'où son abandon malgré la faible compatibilité entre les deux versions pour ceux qui s'en servait encore.

Les bibliothèques zlib et minizip utilisent leur variante zlib-ng et minizip-ng dorénavant. Ces versions sont plus rapides grâce à l'emploi des instructions plus modernes des processeurs actuels tout en gardant la compatibilité par rapport à l'implémentation de référence.

Le langage Python ne bénéficie plus de la version 3.7. Depuis juin de l'année dernière cette version n'est plus maintenue et il n'y a pas de raison de poursuivre son maintien dans les dépôts en tant que version de compatibilité.

Projet Fedora

L'édition Cloud sera construite avec l'utilitaire Kiwi dans Koji. L'utilitaire ImageFactory employé jusqu'à présent n'est plus maintenu. Les outils mkosi et osbuild ont été considérés mais non retenus, le premier car il manque de flexibilité pour fournir toutes les images souhaitées, tandis que le second est certes adopté par l'équipe de Fedora Workstation mais ne semble pas adapté aux besoins des images clouds qui reposent sur d'autres technologies dont rpm-ostree et doit fournir des délivrables plus variés également. En effet l'image cloud cible Vagrant, Azure, AWS, GCP et peut dorénavant viser aussi les images pour WSL2 ou pour conteneurs directement.

Tandis que l'édition Workstation aura son image ISO générée avec l'outil Image Builder. En effet ce dernier bien que déjà employé par Fedora Workstation bénéficie enfin de la prise en charge des images ISO live. Il remplace donc les outils lorax/livemedia-creator qui avaient beaucoup de problèmes. Il devient aussi plus simple pour quiconque de générer son image ISO avec un simple fichier TOML pour le décrire et quelques utilitaires en ligne de commande.

L'image minimale ARM sera construite avec l'outil OSBuild. Comme dans le cadre de l'édition Cloud, il remplace l'utilitaire ImageFactory qui montrait ses limites. L'objectif à terme est de pouvoir supprimer totalement ou partiellement les hacks nécessaires à ce jour pour utiliser cette image sur une grande variété de systèmes ARM.

Fedora IoT bénéficiera d'images pouvant démarrer dans des conteneurs. Ainsi il est possible de tester le système dans des conteneurs plutôt que via de la virtualisation classique ou sur des machines physiques. Cette flexibilité peut aider le test par les utilisateurs mais également par ses mainteneurs.

Il bénéficiera également des images Simplified Provisioning. Fedora IoT peut ainsi utiliser l'utilitaire coreos-installer pour l'installer sur le disque directement et ce en utilisant un argument noyau pour savoir sur quel disque l'installer. Ainsi pas besoin de fichier kickstart ou d’interaction avec l'utilisateur ce qui simplifie la procédure et son automatisation. Cela s'intègre parfaitement avec les dispositifs Fido Device Onboarding et Ignition pour la configuration de tels systèmes dans un environnement de production.

Et le tout sera construit en utilisant rpm-ostree unified core. L'ancien mode n'est en effet plus maintenu et moins testé. Le mode unifié permet au compose server, qui est l'image de base créée à partir de RPM, de fonctionner de manière similaire au client qui ajoute des commits par dessus pour personnaliser le contenu du système. Cela permet de simplifier la maintenance côté rpm-ostree mais aussi de résoudre certaines difficultés notamment pour la gestion du démarrage avec bootupd, les labels SELinux et l'utilisation de conteneurs pour les scriplets pré et post installations des paquets. Depuis Fedora Linux 39 où Silverblue et Kinoite ont amorcé la transition, l'édition IoT était la dernière variante à ne pas avoir franchi le pas.

Fedora sera construit avec DNF 5 en interne. Ainsi les outils Mock, Koji et Copr passent le cap, en attendant Fedora Linux 41 pour que cela soit le cas pour les utilisateurs de la distribution. L'objectif est ici double. Les développeurs de DNF auront un retour d'expérience grandeur nature sur cette version et permettra d'identifier d'éventuels problèmes. Pour l'infrastructure, DNF 5 est plus léger en mémoire, plus performant et consomme moins d'espace disque ce qui permettrait de gagner du temps dans la construction des RPM et des images et de réduire la pression sur le matériel employé à ces tâches.

Les macros forge passent du paquet redhat-rpm-config à forge-srpm-macros. Ces projets sont maintenant distincts upstream et ce premier dépend maintenant du second. L'objectif est de simplifier la possibilité d'exécuter des tests automatiques sur ces macros afin d'améliorer leur fiabilité.

Phase 3 de l'usage généralisé des noms abrégés de licence provenant du projet SPDX pour la licence des paquets plutôt que des noms du projet Fedora. L'objectif de cette phase est de poursuivre le travail entamé dans les versions précédentes en convertissant l'essentiel des paquets RPM vers ce nouveau format. Cependant le travail devrait être achevé pour l'ensemble des paquets pour Fedora Linux 41.

La construction de certains paquets échouera si l'éditeur de lien détecte certaines classes de vulnérabilité dans le binaire en construction. C'est la macro %{hardened_build} qui est étendue pour fournir ce service, cela ne concerne que les paquets l'utilisant. Il peut ainsi générer une telle erreur s'il détecte une pile exécutable, un segment chargeable en mémoire avec des permissions en lecture, écriture et exécutable ou un fil d'exécution local ayant un segment exécutable. L'objectif est donc de renforcer le caractère non modifiable des sections mémoires exécutables pour limiter le risque de failles de sécurité. Cela est fait grâce à l'éditeur de lien BFD qui fournit de telles vérifications. Jusqu'à présent ces cas étaient détectés mais ne généraient que des avertissements qui étaient de fait ignorés.

Compilation des paquets en convertissant plus d'avertissements comme erreurs lors de la compilation des projets avec le langage C. L'objectif est de supprimer de plus en plus de code utilisant d'anciennes constructions qui sont source de bogues d'une part, mais qui seront aussi progressivement interdites par défaut avec les futures versions de GCC. Par ailleurs, certains de ces éléments pouvaient être bloquants pour l'adoption d'une nouvelle norme C de référence pour certains paquets.

Voici la liste des changements opérés :

  • Suppression des déclarations implicites de fonctions : 54 paquets concernés ;
  • Suppression du type implicite int quand le type est omis : 5 paquets concernés ;
  • Obligation de mentionner les types dans les arguments lors de la déclaration de fonctions : aucun paquet concerné ;
  • Interdiction de conversions implicites entre entier et pointeurs : 100 paquets concernés ;
  • L'instruction return doit avoir les arguments qui correspondent au type de retour d'une fonction (donc pas d'argument si void, et non vide si un entier est attendu par exemple) : 13 paquets concernés ;
  • Interdiction des conversions implicites de pointeurs de types différents : 381 paquets concernés.

Certains changements devraient voir le jour dans le futur :

  • Interdiction des déclarations de fonctions dans le style pré-C89 ;
  • Interdiction d'utiliser des mots clés bool, true ou false avec des définitions locales plutôt que d'utiliser l'en-tête de la bibliothèque standard ;
  • Déclarer une fonction sans argument comme void foo() aurait le même sens qu'en C++, à savoir équivalent à void foo(void) plutôt qu'à accepter n'importe quel type d'arguments.

Clap de fin pour la construction des mises à jour au format Delta RPM. Ils sont désactivés par défaut dans la configuration de DNF et Fedora ne les générera plus. Cette fonctionnalité permettait pour les mises à jour de ne télécharger que la différence entre le paquet déjà installé et celui à mettre à jour. Cela permettait de réduire la quantité de données à télécharger, la machine de l'utilisateur pouvait reconstruire le paquet à partir de ces informations et ainsi obtenir la nouvelle version. Mais en pratique la fonctionnalité se révèle de moins en moins pertinente. Tout d'abord le processus n'est pas fiable à 100%, parfois la reconstruction échoue et dans ce cas le nouveau paquet est totalement téléchargé à nouveau ce qui conduit à un gaspillage de ressources. De plus peu de paquets étaient concernés, les delta RPM étaient d'ailleurs construits en général que d'une version à une autre ce qui la rend fonctionnelle surtout pour ceux qui mettent à jour très régulièrement leur système. Et pour que cette fonctionnalité soit exploitable, ces fichiers delta rpm font partie des métadonnées que DNF télécharge. Sauf que c'est le cas même si les delta rpm sont désactivés par l'utilisateur, ou pour les systèmes reposant sur rpm-ostree ou utilisant un GUI comme GNOME Logiciels car PackageKit comme rpm-ostree ne se servent pas de ces métadonnées. Au final cela pénalise toute l'infrastructure qui doit générer et stocker ces données, et beaucoup d'utilisateurs qui subissent les inconvénients sans les avantages le tout pour un gain jugé marginal pour ceux qui s'en servent : moins de 8% de réduction de la taille des téléchargements en moyenne.

Les JDKs ne sont générés qu'une fois, et rempaquetés ainsi à toutes les variantes du système. Pour cela les paquets du JDK sont générés à partir de la version la plus ancienne de Fedora Linux encore maintenue, et le résultat est directement réutilisé pour former les paquets des autres versions du système. Cela réduit considérablement le temps de validation de chaque JDK car il y a cinq fois moins de versions différentes à gérer. Cela permettra aux mainteneurs de maintenir la diversité actuelle des JDK à savoir les versions 1.8.0, 11, 17 et la dernière (actuellement la version 20). Si ce résultat ne permet pas de libérer assez de temps aux mainteneurs, la réduction du nombre de JDK à l'avenir pourrait être considérée.

Les images immuables pour les systèmes personnels comme Silverblue seront nommées sous la dénomination Atomic pour éviter la référence au terme immuable qui est confus pour les utilisateurs. Les noms de variantes Silverblue, Kinoite, Sericea et Onyx vont être préservés, l'objectif est de donner une dénomination commune qui utilise le terme Atomic déjà employé par l'édition Cloud par exemple. Le terme immuable est en effet considéré comme peu clair car si le système principal est majoritairement en lecture seule, il ne l'est pas totalement notamment pour la configuration ou les parties dynamiques du système. Alors que le système repose sur le concept d'atomicité en ayant une approche par état du système, d'où la nécessité de redémarrer pour changer cet état notamment lors d'une mise à jour par ailleurs.

L'objectif est donc purement au niveau de la communication autour de ces systèmes. Cependant les nouvelles variantes devraient utiliser ce terme dans ce nom comme par exemple Fedora XCFE Atomic si jamais cette variante prend vie un jour.

La communauté francophone

L'association

Borsalinux-fr est l'association qui gère la promotion de Fedora dans l'espace francophone. Nous constatons depuis quelques années une baisse progressive des membres à jour de cotisation et de volontaires pour prendre en main les activités dévolues à l'association.

Nous lançons donc un appel à nous rejoindre afin de nous aider.

L'association est en effet propriétaire du site officiel de la communauté francophone de Fedora, organise des évènements promotionnels comme les Rencontres Fedora régulièrement et participe à l'ensemble des évènements majeurs concernant le libre à travers la France principalement.

Si vous aimez Fedora, et que vous souhaitez que notre action perdure, vous pouvez :

  • Adhérer à l'association : les cotisations nous aident à produire des goodies, à nous déplacer pour les évènements, à payer le matériel ;
  • Participer sur le forum, les listes de diffusion, à la réfection de la documentation, représenter l'association sur différents évènements francophones ;
  • Concevoir des goodies ;
  • Organiser des évènements type Rencontres Fedora dans votre ville.

Nous serions ravis de vous accueillir et de vous aider dans vos démarches. Toute contribution, même minime, est appréciée.

Si vous souhaitez avoir un aperçu de notre activité, vous pouvez participer à nos réunions mensuels chaque premier lundi soir du mois à 20h30 (heure de Paris). Pour plus de convivialité, nous l'avons mis en place en visioconférence sur Jitsi.

La documentation

Depuis juin 2017, un grand travail de nettoyage a été entrepris sur la documentation francophone de Fedora, pour rattraper les 5 années de retard accumulées sur le sujet.

Le moins que l'on puisse dire, c'est que le travail abattu est important : près de 90 articles corrigés et remis au goût du jour. Un grand merci à Charles-Antoine Couret, Nicolas Berrehouc, Édouard Duliège et les autres contributeurs et relecteurs pour leurs contributions.

La synchronisation du travail se passe sur le forum.

Si vous avez des idées d'articles ou de corrections à effectuer, que vous avez une compétence technique à retransmettre, n'hésitez pas à participer.

Comment se procurer Fedora Linux 40 ?

Si vous avez déjà Fedora Linux 39 ou 38 sur votre machine, vous pouvez faire une mise à niveau vers Fedora Linux 40. Cela consiste en une grosse mise à jour, vos applications et données sont préservées.

Autrement, pas de panique, vous pouvez télécharger Fedora Linux avant de procéder à son installation. La procédure ne prend que quelques minutes.

Nous vous recommandons dans les deux cas de procéder à une sauvegarde de vos données au préalable.

De plus, pour éviter les mauvaises surprises, nous vous recommandons aussi de lire au préalable les bogues importants connus à ce jour pour Fedora Linux 40.

Optimiser mon cache DNS avec dnsmasq sous Debian

Posted by Guillaume Kulakowski on April 26, 2024 05:15 PM

Étape 1 : le constat Depuis que j’ai mis en place AdGuard Home, je constate beaucoup de requêtes DNS venant de Jeedom. J’avais déjà constaté cela la dernière fois, mais la solution précédente ne peut plus marcher. En effet, maintenant AdGuard Home gère tous mes DNS à la place d’OpenWRT. De plus, je constate une […]

Cet article Optimiser mon cache DNS avec dnsmasq sous Debian est apparu en premier sur Guillaume Kulakowski's blog.

Infra and RelEng Update – Week 17 2024

Posted by Fedora Community Blog on April 26, 2024 10:00 AM

This is a weekly report from the I&R (Infrastructure & Release Engineering) Team. It also contains updates for CPE (Community Platform Engineering) Team as the CPE initiatives are in most cases tied to I&R work.

We provide you with both an infographic and a text version of the weekly report. If you just want to quickly look at what we did, just look at the infographic. If you are interested in more in-depth details look at the infographic.

Week: 22 April – 26 April 2024

<figure class="wp-block-image size-full is-style-default">I&R infographic</figure>

Infrastructure & Release Engineering

The purpose of this team is to take care of day-to-day business regarding CentOS and Fedora Infrastructure and Fedora release engineering work.
It’s responsible for services running in Fedora and CentOS infrastructure and preparing things for the new Fedora release (mirrors, mass branching, new namespaces etc.).
List of planned/in-progress issues

Fedora Infra

CentOS Infra including CentOS CI

Release Engineering

CPE Initiatives

EPEL

Extra Packages for Enterprise Linux (or EPEL) is a Fedora Special Interest Group that creates, maintains, and manages a high-quality set of additional packages for Enterprise Linux, including, but not limited to, Red Hat Enterprise Linux (RHEL), CentOS, Scientific Linux (SL) and Oracle Linux (OL).

Updates

  • EPEL 10 Work Tracker
    • EPEL community involved
  • Docs Revamp in progress
    • Landing page with links to more information
    • Onboarding page with FAQ section
  • Working on getting Troy’s will-it project to run on github-actions

Community Design

CPE has a few members who are working as part of the Community Design Team. This team is working on anything related to design in the Fedora Community.

Updates

  • Choose Your Own Adventure Sticker #159 in progress
  • Avocado-framework logo and website design #146 in progress
  • Various stickers created for Red Hat Summit related to Podman Desktop 🦭

If you have any questions or feedback, please respond to this report or contact us on #redhat-cpe channel on matrix.

The post Infra and RelEng Update – Week 17 2024 appeared first on Fedora Community Blog.

PHP version 8.2.19RC1 and 8.3.7RC1

Posted by Remi Collet on April 26, 2024 04:38 AM

Release Candidate versions are available in the testing repository for Fedora and Enterprise Linux (RHEL / CentOS / Alma / Rocky and other clones) to allow more people to test them. They are available as Software Collections, for a parallel installation, the perfect solution for such tests, and also as base packages.

RPMs of PHP version 8.3.7RC1 are available

  • as base packages
    • in the remi-modular-test for Fedora 38-40 and Enterprise Linux ≥ 8
    • in the remi-php83-test repository for Enterprise Linux 7
  • as SCL in remi-test repository

RPMs of PHP version 8.2.19RC1 are available

  • as base packages
    • in the remi-modular-test for Fedora 38-40 and Enterprise Linux ≥ 8
    • in the remi-php82-test repository for Enterprise Linux 7
  • as SCL in remi-test repository

emblem-notice-24.png The Fedora 39, 40, EL-8 and EL-9 packages (modules and SCL) are available for x86_64 and aarch64.

emblem-notice-24.pngPHP version 8.1 is now in security mode only, so no more RC will be released.

emblem-notice-24.pngInstallation: follow the wizard instructions.

emblem-notice-24.png Announcements:

Parallel installation of version 8.3 as Software Collection:

yum --enablerepo=remi-test install php83

Parallel installation of version 8.2 as Software Collection:

yum --enablerepo=remi-test install php82

Update of system version 8.3 (EL-7) :

yum --enablerepo=remi-php83,remi-php83-test update php\*

or, the modular way (Fedora and EL ≥ 8):

dnf module switch-to php:remi-8.3
dnf --enablerepo=remi-modular-test update php\*

Update of system version 8.2 (EL-7) :

yum --enablerepo=remi-php82,remi-php82-test update php\*

or, the modular way (Fedora and EL ≥ 8):

dnf module switch-to php:remi-8.2
dnf --enablerepo=remi-modular-test update php\*

emblem-notice-24.png Notice:

  • version 8.3.7RC1 is also in Fedora rawhide for QA
  • EL-9 packages are built using RHEL-9.3
  • EL-8 packages are built using RHEL-8.9
  • EL-7 packages are built using RHEL-7.9
  • oci8 extension uses the RPM of the Oracle Instant Client version 21.13 on x86_64 or 19.19 on aarch64
  • intl extension uses libicu 73.2
  • RC version is usually the same as the final version (no change accepted after RC, exception for security fix).
  • versions 8.2.18 and 8.3.5 are planed for April 11th, in 2 weeks.

Software Collections (php82, php83)

Base packages (php)

Fix big cursors in Java applications in Wayland

Posted by Major Hayden on April 26, 2024 12:00 AM
Java applications under Wayland seemed to have all different sizes of cursors, but some were way, way, too big. 🐘

Using syslog-ng on multiple platforms

Posted by Peter Czanik on April 24, 2024 12:07 PM

Your favorite Linux distribution is X. You test everything there. However, your colleagues use distro Y, and another team distro Z. Nightmares start here: the same commands install a different set of syslog-ng features, configuration defaults and use different object names in the default configuration. I ran into these problems while working with Gábor Samu on his HPC logging blog.

From this blog you can learn about some of the main differences in packaging and configuration of syslog-ng in various Linux distributions and FreeBSD, and how to recognize these when configuring syslog-ng on a different platform.

https://www.syslog-ng.com/community/b/blog/posts/using-syslog-ng-on-multiple-platforms

<figure><figcaption>

syslog-ng logo

</figcaption> </figure>

How to rebase to Fedora Linux 40 on Silverblue

Posted by Fedora Magazine on April 24, 2024 08:00 AM

Fedora Silverblue is an operating system for your desktop built on Fedora Linux. It’s excellent for daily use, development, and container-based workflows. It offers numerous advantages such as being able to roll back in case of any problems. If you want to update or rebase to Fedora Linux 40 on your Fedora Silverblue system, this article tells you how. It not only shows you what to do, but also how to revert things if something unforeseen happens.

Update your existing system

Prior to actually doing the rebase to Fedora Linux 40, you should apply any pending updates. Enter the following in the terminal:

$ rpm-ostree update

or install updates through GNOME Software and reboot.

Note

rpm-ostree is the underlying atomic technology that all the Fedora Atomic Desktops use. The techniques described here for Silverblue will apply to all of them with proper modifications for the appropriate desktop.

Rebasing using GNOME Software

GNOME Software shows you that there is new version of Fedora Linux available on the Updates screen.

<figure class="wp-block-image size-full is-style-default">GNOME_Software_download_screenshot</figure>

First thing to do is download the new image, so select the Download button. This will take some time. When it is done you will see that the update is ready to install.

<figure class="wp-block-image size-full">GNOME_Software_update_screenshot</figure>

Select the Restart & Upgrade button. This step will take only a few moments and the computer will restart when the update is completed. After the restart you will end up in a new and shiny release of Fedora Linux 40. Easy, isn’t it?

Rebasing using terminal

If you prefer to do everything in a terminal, then this part of the guide is for you.

Rebasing to Fedora Linux 40 using the terminal is easy. First, check if the 40 branch is available:

$ ostree remote refs fedora

You should see the following in the output:

fedora:fedora/40/x86_64/silverblue

If you want to pin the current deployment (meaning that this deployment will stay as an option in GRUB until you remove it), you can do this by running this command:

# 0 is entry position in rpm-ostree status
$ sudo ostree admin pin 0

To remove the pinned deployment use the following command:

# 2 is entry position in rpm-ostree status 
$ sudo ostree admin pin --unpin 2

Next, rebase your system to the Fedora Linux 40 branch.

$ rpm-ostree rebase fedora:fedora/40/x86_64/silverblue

Finally, the last thing to do is restart your computer and boot to Fedora Linux 40.

How to roll back

If anything bad happens (for instance, if you can’t boot to Fedora Linux 40 at all) it’s easy to go back. At boot time, pick the entry in the GRUB menu for the version prior to Fedora Linux 40 and your system will start in that previous version rather than Fedora Linux 40. If you don’t see the GRUB menu, try to press ESC during boot. To make the change to the previous version permanent, use the following command:

$ rpm-ostree rollback

That’s it. Now you know how to rebase Fedora Silverblue to Fedora Linux 40 and roll back. So why not do it today?

FAQ

Because there are similar questions in comments for each blog about rebasing to newer version of Silverblue I will try to answer them in this section.

Question: Can I skip versions during rebase of Fedora? For example from Fedora 38 Silverblue to Fedora 40 Silverblue?

Answer: Although it could be sometimes possible to skip versions during rebase, it is not recommended. You should always update to one version above (38->39 for example) to avoid unnecessary errors.

Question: I have rpm-fusion layered and I get errors during rebase. How should I do the rebase?

Answer: If you have rpm-fusion layered on your Silverblue installation, you should do the following before rebase:

$ rpm-ostree update --uninstall rpmfusion-free-release --uninstall rpmfusion-nonfree-release --install rpmfusion-free-release --install rpmfusion-nonfree-release

After doing this you can follow the guide in this blog post.

Question: Could this guide be used for other ostree editions (Fedora Atomic Desktops) as well like Kinoite, Sericea (Sway Atomic), Onyx (Budgie Atomic),…?

Yes, you can follow the Rebasing using the terminal part of this guide for every Fedora Atomic Desktop. Just use the corresponding branch. For example, for Kinoite use fedora:fedora/40/x86_64/kinoite

Mode Envoy Typing Sound

Posted by Jon Chiappetta on April 24, 2024 12:48 AM
<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio">
<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="allowfullscreen" frameborder="0" height="567" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/daL5D488w6M?feature=oembed" title="Mode Envoy Typing Sound" width="1008"></iframe>
</figure>

~

<figure class="wp-block-image size-large"></figure>

~

<figure class="wp-block-image size-large"></figure>

OMG! We’re at forty! (Announcing the release of Fedora Linux 40)

Posted by Fedora Magazine on April 23, 2024 02:00 PM

Oh, wow. This feels like a big number! I’m proud to announce the 40th release of Fedora Linux, a community-built and community-maintained operating system that belongs to all of us. I’m also happy to note that we’re back on track with an on-time release. Thank you to all Fedora contributors who made that possible, and who have, yet again, made this our best one ever.

This is also a personally exciting number for me, because this marks the 20th release for which I’ve served as Fedora Project Leader. We’ve gone through a lot in this last decade, and I’m incredibly happy to see our community thrive and grow. In addition to many long-familiar names and faces, it’s exciting to see a new generation with new energy and ideas. In some cases, this is literally a new generation, as many of you have grown up with Fedora. But at whatever age, I’m proud we’ve built such a welcoming and friendly community, and that we continue to work at improving our inclusiveness, diversity, and accessibility.

But anyway! Enough of that. Time to see what we’ve got for you in Fedora Linux 40! If you have a system already, Upgrading Fedora to a New Release is easy. If you’re new, or just curious, head to Get Fedora for installation options.

Desktop news

Fedora Workstation Edition features the GNOME desktop environment, now updated to version 46. Check out What’s New in Fedora Workstation 40? for the highlights!

The KDE Spin now includes KDE Plasma 6, and runs with Wayland out of the box. Read more about that and other KDE Spin updates at What’s New in Fedora KDE 40?

We’re also officially reviving the “Fedora Atomic Desktop” brand for all of our variants which use ostree or image-based provisioning. Our technology isn’t really “immutable”, so this provides a better grouping. Read more about this at Introducing Fedora Atomic Desktops — but in short, Fedora Silverblue and Fedora Kinoite will remain, while the other desktop  variants will become Fedora Sway Atomic and Fedora Budgie Atomic.

Tools for AI development

Fedora Linux 40 ships with our first-ever PyTorch package. PyTorch is a popular framework for deep learning, and it can be difficult to reliably install with the right versions of drivers and libraries and so on. The current package only supports running on the CPU, without GPU or NPU acceleration, but this is just the first step. Our aim is to produce a complete stack with PyTorch and other popular tools ready to use on a wide variety of hardware out-of-the-box.

We’re also shipping with ROCm 6 — open-source software that provides acceleration support for AMD graphics cards. We plan to have that enabled for PyTorch in a future release.

Updates all around!

As usual, we’ve rebuilt everything in the distribution using updated compilers and libraries (and, of course, those updated tools are ready for developers to use). These updates bring bugfixes, security improvements, and performance gains.

And, of course, hundreds of Fedora packagers and testers have worked to integrate the latest versions of open source software from thousands of upstream projects. Those projects, in turn, are made by an uncountable number of developers and contributors working on marketing, design, documentation, code, quality, translations, communications, events, governance, infrastructure, security, and so much more. Thank you again to everyone who makes Fedora amazing, and to everyone whose work has built this whole universe of free and open source software.

Speaking of updates…

There are several important release-day bugfix and security updates available today as well. If you upgrade from an earlier Fedora Linux release, you’ll get them as part of that. For new installations, please make sure to check for and apply updates as soon as possible.

In the unlikely event of a problem…

If you run into a problem, visit our Ask Fedora user support forum. This includes a category for common issues

Or if you just want to say “hello”…

Drop by our “virtual watercooler” on Fedora Discussion and join a conversation, share something interesting, and introduce yourself.

Also, remember that our annual contributor conference, Flock To Fedora, is coming up! It’ll be in Rochester, New York this August. The call for session proposals is still open, if you have something you’d like to share or work on. If you’re already a Fedora contributor, or are interested in being one, or think you might be, we’d love to see you there!

Slimbook Fedora 2: New Ultrabooks for Fedora Linux 40

Posted by Fedora Magazine on April 23, 2024 01:58 PM

The response from the Fedora community to the Fedora Slimbook 16” and 14” has been great! More and more people are noticing the quality of these laptops. We’ve even had a demo unit at events like FOSDEM and SCaLE for community members to play with.

To build on that excitement, Slimbook and the Fedora Project are announcing Slimbook Fedora 2!

Slimbook Fedora 2

The Slimbook Fedora 2 comes in the 14” and 16” models and brings with it fantastic new options.

  • Silver is popular, but how about a smooth black Magnesium chassis?
  • For those who need it, you now have the option of a US ANSI keyboard layout so you can work without skipping a beat!
  • CPU is being upgraded to Intel’s 13th Gen i7 processor
  • Take your work to the next level with the Nvidia RTX 4000 series graphics card in the 16” model

Of course we can’t forget that the Slimbook Fedora 2 will also come with the Fedora logo engraved on the lid, as well as on the super key. 😉

This hardware update comes with a software upgrade courtesy of Fedora’s latest release, Fedora Workstation 40. Featuring GNOME 46 and numerous other enhancements, Slimbook Fedora 2 continues to be a great travel companion. Fedora Linux 40 also comes with the latest Nouveau drivers to give you a much better out of the box experience with the Nvidia graphics card in the 16” model.

Slimbook is dedicated to supporting open source initiatives. As part of that, 3% of the proceeds from each Slimbook Fedora unit sold will continue to be donated to the GNOME Foundation.

Besides that there is also the Fedora contributor discount which gives you an additional €100 off! If you’re a contributor to the Fedora Project you can find more info on how to get this discount from this Community Blog post.

Additionally, Slimbook offers a €150 discount for everyone on last year’s model. You can purchase the previous model with a discount through this link: https://fedora.slimbook.com.

<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex"> <figure class="wp-block-image size-large"></figure> <figure class="wp-block-image size-large"></figure> <figure class="wp-block-image size-large"></figure> <figure class="wp-block-image size-large"></figure> </figure>

More details below:

Slimbook Fedora 2, 16” Model

  • Intel® Core™ i7-13700H Processor
  • NVIDIA GeForce RTX™ 4060 GPU
  • Sleek Color Options: Silver and Black (magnesium chassis)
  • 16-inch 16:10, 100% sRGB, 90Hz Display (2560 x 1600 Resolution)
  • Versatile Keyboard Options: ISO and ANSI (Available in almost any language)
  • Up to 64 GB SO-DIMM DDR5 RAM (removable)
  • Up to 8 TB M.2 SSD NVMe Gen 4.0 (removable)
  • Thunderbolt 4 & USB-C 3.2 Gen2 10Gbps
  • 82 Wh Battery
  • Lightweight Design: 1.6 kg (3.5 lbs)

Slimbook Fedora 2, 14” Model

  • Intel® Core™ i7-13700H Processor
  • Sleek Color Options: Silver and Black
  • 14-inch 16:10, 100% sRGB, 90Hz Display (2880 x 1800 Resolution)
  • Versatile Keyboard Options: ISO and ANSI
  • Up to 64 GB SO-DIMM DDR5 RAM (removable)
  • Up to 8 TB M.2 SSD NVMe Gen 4.0 (removable)
  • Thunderbolt 4 & USB-C 3.2 Gen2 10Gbps
  • 99 Wh Battery
  • Lightweight Design: 1.3 kg (2.8 lbs)

Check out both new Slimbook Fedora 2 models at https://fedora.slimbook.com/

Additional Resources

What’s New in Fedora KDE 40?

Posted by Fedora Magazine on April 23, 2024 01:56 PM

Fedora Linux is a community developed and maintained operating system. Fedora KDE is one of our adaptations of Fedora Linux for your laptop or desktop. With this milestone release of Fedora KDE 40, we hope that you’ll be interested in trying an OS that belongs to you from start to finish, from install to first shut down, from UI customizations to major changes under the hood!

KDE Plasma 6

The all-encompassing change in Fedora KDE 40 is the introduction of KDE Plasma 6. It’s the first major release of the Plasma desktop environment in nine years! Additionally, Fedora KDE is one of the first major distros to ship Plasma 6, and we’re the first Fedora Linux desktop variant to ship Wayland-only (not to worry, we retain full support for X11 applications!), enabling the project to push forward improvements to Wayland for the benefit of the entire Linux community. This builds upon the work done in previous Fedora Linux releases to have Fedora KDE run in Wayland from login to shutdown by default.

<figure class="wp-block-image size-large"></figure>

Featured Highlights

  • There’s a new Overview Effect for keeping tabs on all of your open applications across all your virtual desktops.
  • Partial support for HDR is implemented in this release on the way to having full support.
  • Accessibility improvements have been introduced with color blindness correction filters.
  • A new look to the taskbar comes in the form of a floating panel! Plasma 6 also makes customizing panels easier than ever with an understandable UI to help users make the changes they want with minimal effort.
  • The Breeze UI theme that has been a hallmark of Plasma for a while gets a refresh with simplifications and modernizations where needed.
  • NeoChat, KDE’s Matrix client, is provided by default for you to try.
  • The Cube has returned! The new Overview Effect is cool, but using the Cube to manage your virtual desktops is a fantastic party trick to impress your friends next time you’re sharing your screen. 😉

You can find more changes and improvements in KDE Plasma 6 from their megarelease page!

A word about Kinoite…

If you have an interest in what all of the immutable / atomic / cloud-native / composable / image-based fuss is about, Fedora Atomic Desktops is a great entry point into that world. Case in point, check out Fedora Kinoite 40, an atomic implementation of Fedora KDE that also comes with Plasma 6!

Also check out…

All of the fun events Fedora has coming up! 

  • Be on the lookout for dates for the Fedora 40 Release Party, a virtual, user-focused, two day conference all about the new things in Fedora and the exciting things happening from our contributors. Will (hopefully) happen in May.
  • DevConf.CZ on June 13-15.
  • Flock to Fedora, our in-person, contributor-focused conference, will be happening on August 7-10. 
  • DevConf.US follows right after on August 14-16.
  • KDE’s contributor conference, Akademy, will come to Germany on September 7-12.

Thanks for learning about Fedora KDE 40. We hope that it will continue to be the reliable and exciting desktop OS you know and love. Share your appreciation or feedback on social media with #FedoraKDE!

Try Fedora KDE 40 today!

What’s new in Fedora Workstation 40

Posted by Fedora Magazine on April 23, 2024 01:54 PM

Fedora Workstation, the flagship open source Linux desktop OS from the Fedora Project, has reached a new milestone with the release of Fedora Workstation 40. This release has been made possible due to the contributions of our global community, including your contributions! Fedora Workstation 40 comes packed with new features and performance enhancements that promise a smoother and more responsive computing experience. Read on to learn about the latest features and improvements in the sections below. You can download Fedora Workstation 40 from the Fedora Workstation webpage, or upgrade your existing install within the Software app or with dnf system-upgrade in your favorite terminal emulator.

GNOME 46

Fedora Workstation 40 features GNOME 46, the latest version of the GNOME desktop environment. Key updates include a notable upgrade of the Files app, introducing new features and enhancements. Additionally, many aspects of accessibility have received improvements, ensuring a more inclusive user experience. The Settings app and other core apps have been refined for better usability. More details can be found in the GNOME 46 release notes.

Many other improvements have been made throughout GNOME 46, such as:

  • Grouping of notifications by app. Now, each notification has a header. It shows the app’s name and icon. This makes it possible to see which app sent an alert. Notification now also has an expand button.
  • You can now open a new window for apps pinned to the dash by adding the Ctrl modifier. For example: Super+Ctrl+1 opens a new window for the first app in the dash, complementing the existing shortcut of Super+<Number> that launches the app itself.
  • By default, Tap to Click is now enabled for touchpad.
  • GNOME 46 now features Remote Login option. You can remotely connect using RDP to a new dedicated desktop session when there isn’t an active session.

Core apps

GNOME’s core applications have had significant improvements in the new version. Some of these include:

Settings

GNOME 46 comes with exciting updates to the Settings app, making it more user-friendly than ever. The latest version has more keyboard mnemonics which make navigation easier. It also has a sleek modern interface. The appearance settings load faster than before and with sharper previews. This new release provides more precise control of Wacom stylus pressure. 

In addition to the upgrades mentioned above, the Settings app has received major improvements that are worth mentioning:

  • The Settings app has a new system panel. It groups Region & LanguageDate & TimeRemote Desktop, and About into one settings pane. This new design makes the app easier to navigate.
  • GNOME 46 has updated touchpad settings with two new options. The first, called Secondary Click, lets you choose how to perform a right-click on the touchpad: either with two fingers or by clicking in a corner. The second option allows you to keep the touchpad active while typing, which helps in some apps and games where you need to use the keyboard and touchpad at the same time.

Files

  • One of the notable upgrades to Files is the introduction of a new global search feature. The global search feature lets you search files across all configured locations. You can search the contents of files, filter files by type and modification date, and search multiple locations at once. Click the icon next to the file path field to activate this feature.
  • In GNOME 46, the sidebar dynamic progress section at the bottom allows you to monitor file operations more effectively with more details on their progress.
  • Switching between list and grid views in Files now happens quickly. This fixes the lag noticed in prior versions.

Other changes to the Files app include a new search field within the Files preferences. It helps find specific settings. There’s now also an option to show date and time in a consistent format, and improved network discovery. These refinements make managing files more efficient.

Other core applications have also received upgrades

  • The Software app now displays verified badges for trusted Flathub apps, ensuring software authenticity. 
  • Maps app offers a new editing experience, support for dark mode, and expanded public transit routing. 
  • The Extensions and Calendar apps boast modernized designs and usability improvements. 
  • GNOME 46 upgrades Clocks and Contacts apps. It lets you set a timer quickly in Clocks. And, import multiple VCard files at once in Contacts.
  • The Disks app has a new I/O resource graph for monitoring disk usage. 

Performance Improvements

GNOME 46 provides substantial under-the-hood improvements for a more efficient and polished experience. Key improvements include:

  • Reduced memory usage in search.
  • Significant speed boosts in terminal apps. 
  • More appealing visuals as app interfaces appear sharper, text on the screen clearer, and UI elements more defined, particularly when using fractional display scales due to GTK’s new renders.
  • Experimental support for Variable Refresh Rate (VRR) for smoother video performance. You can enable this feature with the command:
    gsettings set org.gnome.mutter experimental-features "['variable-refresh-rate']"
    Once enabled, the refresh rate can be set in the display settings.

Under-the-hood changes in Fedora Linux 40

Fedora Linux 40 features many under-the-hood changes. Here are some notable ones:

  • IPV4 Address Conflict Detection is enabled by default in NetworkManager to address conflicts caused by duplicate IPV4 addresses in the same physical network.
  • Fedora 40 integrates PyTorch directly into its software repository. This makes it easier for users to access the open source machine learning framework for their projects. Installation is now a breeze through a single command:
    sudo dnf install python3-torch
  • Starting with Fedora Linux 40, the term “immutable” will no longer be used to describe all rpm-ostree based variants of Fedora Linux (Silverblue, Kinoite, Sway and Budgie). Instead, they will be referred to as “Atomic” desktops with Sericea now known as Fedora Atomic Sway. This change is part of a rebranding aimed at simplifying the naming conventions for Fedora spins. More information on this change may be found here.

Also check out…

Cool happenings throughout the Fedora Project!

Stay tuned and get ready to engage with the Fedora community at some upcoming events! In June, join us in Brno, Czechia, for the DevConf CZ conference — a gathering filled with insightful discussions, workshops, and the chance to meet fellow enthusiasts.

Then, mark your calendars for August, when our flagship contributor conference, Flock, takes place. For more details on Flock 2024, check out this post.

Fedora Ops Architect Weekly

Posted by Fedora Community Blog on April 22, 2024 09:25 PM

And what a week it was! Fedora Linux 40 got the ‘GO’ at the Go/No-Go meeting on Thursday so that means a brand new release of Fedora Linux is arriving to you tomorrow, Tuesday 23rd April!

Read on to hear about other exciting Fedora news 🙂

CfPs & Events

Flock to Fedora

The CfP for Flock to Fedora has been extended until Monday April 29th, so dont delay if you have been thinking about submitting something – here is your chance!

Devconf.us

Devconf.us is returning this year in Boston, MA from August 14th – 16th. Their cfp is closing today, so get it in quick if you have had something in draft.

Fedora Linux 41

Now that F40 is releasing, attention will be on the development of F41 which has been happening for a while now. Here are some deadlines for all you change proposal enthusiasts, and for other key dates like the beginning of the Beta freeze and mass rebuild, please view the release schedule.

  • June 19th – Changes requiring infrastructure changes
  • June 25th – Changes requiring mass rebuild
  • June 25th – System Wide changes
  • July 16th – Self Contained changes

If you are unsure of how to propose a change, there is some excellent documentation and video tutorial to help, and you can always reach out directly to me too.

Changes currently in discussion are:

A full list of the already accepted changes for Fedora Linux 41 can be found on the change set page too.

Elections

The F40 elections will begin soon! There are some changes to this cycle, which you can read about them in more detail in the Elections blog post coming later this week and do consider nominating yourself or someone you think would be a great person on Council, FESCo, Mindshare or EPEL when the nominations page is live. Please do make sure the person you are nominating is on board with their nomination too 🙂

Help Wanted

Help is always greatly appreciated.We also have some packages needing some new maintainers and others needing reviews. See below links to adopt and review packages!

The post Fedora Ops Architect Weekly appeared first on Fedora Community Blog.

New badge: Red Hat Summit 2024 !

Posted by Fedora Badges on April 22, 2024 09:19 PM
Red Hat Summit 2024You visited Fedora at Red Hat Summit 2024

Flock 2024 CFP extended to April 29th

Posted by Fedora Community Blog on April 22, 2024 04:20 PM

The Flock to Fedora 2024 call for proposals (CFP) is now extended to Monday, April 29th 2024 at 11:59 PM US Eastern. Now is the last chance to get your great idea or topic into the Flock 2024 CFP before it closes. This will be the only extension and the new deadline is final.

See the previous announcement for more details about the Flock 2024 CFP. You can also submit directly at cfp.fedoraproject.org. For general questions about Flock and the CFP, join the Fedora Chat room on Matrix, #flock:fedoraproject.org.

The post Flock 2024 CFP extended to April 29th appeared first on Fedora Community Blog.

Next Open NeuroFedora meeting: 22 April 1300 UTC

Posted by The NeuroFedora Blog on April 22, 2024 09:49 AM
Photo by William White on Unsplash

Photo by William White on Unsplash.


Please join us at the next regular Open NeuroFedora team meeting on Monday 22 April at 1300 UTC. The meeting is a public meeting, and open for everyone to attend. You can join us in the Fedora meeting channel on chat.fedoraproject.org (our Matrix instance). Note that you can also access this channel from other Matrix home severs, so you do not have to create a Fedora account just to attend the meeting.

You can use this link to convert the meeting time to your local time. Or, you can also use this command in the terminal:

$ date -d 'Monday, April 22, 2024 13:00 UTC'

The meeting will be chaired by @ankursinha. The agenda for the meeting is:

We hope to see you there!

Week 16 in Packit

Posted by Weekly status of Packit Team on April 22, 2024 12:00 AM

Week 16 (April 16th – April 22nd)

  • packit dist-git init now allows specifying --version-update-mask option and also any arbitrary top-level configuration options. (packit#2288)
  • We have fixed Packit auto-referencing Upstream Release Monitoring bug for release syncing to CentOS Stream. (packit#2284)
  • We have changed the behaviour of /packit test comment command: in case there is a missing build for some target, the build will not be triggered anymore, it will just be reported to the user. We needed to make this change as with the increased complexity of the configuration (multiple test jobs), the previous implementation was prone to race conditions leading to wasting of resources of Copr and Testing Farm. (packit-service#2399)

Episode 425 – Video game cheaters, also pretendo

Posted by Josh Bressers on April 22, 2024 12:00 AM

Josh and Kurt talk about a database of game cheaters. Cheating in games has many similarities to security problems. Anti cheat rootkits are also terrible. The clever thing however is using statistics to identify cheaters. Statistics don’t lie. Also, we discuss the Pretendo project sitting on a vulnerability for a year, is this ethical?

<audio class="wp-audio-shortcode" controls="controls" id="audio-3367-3" preload="none" style="width: 100%;"><source src="https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_425_Video_game_cheaters_also_pretendo.mp3?_=3" type="audio/mpeg">https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_425_Video_game_cheaters_also_pretendo.mp3</audio>

Show Notes

Valgrind 3.23.0-RC1

Posted by Mark J. Wielaard on April 21, 2024 03:15 PM

Valgrind 3.23.0-RC1. Please help test.

FreeBSD arm64 support. --track-fds=yes now warns against double close, generates (suppressible) errors and supports XML output. s390x supports more z16 instructions. More accurate x86_64-v3 instruction support. Wrappers for wcpncpy, memccpy, strlcat and strlcpy. Support Linux syscalls mlock2, fchmodat2, pidfd_getfd. And much more. 50+ bug fixes, 280+ commits by 14 developers since 3.22.0.

Fedora rawhide binary packages are available for aarch64, i686, ppc64le, s390x and s390x.

Email update

Posted by Jonathan Dieter on April 20, 2024 09:36 PM

This is just a quick update that I’m updating my primary email address. A year or so ago, I bought the domain dieter.ie (since I’m resident in Ireland, it seemed like a good choice), and it seemed time to put it to good use. My blog will continue to be hosted on jdieter.net, but my primary email address is now jonathan@dieter.ie. My previous Gmail address will continue to work and I’m not giving it up any time soon.

I’m also very aware that it’s been a while since I last posted. The company I work for, Spearline, was acquired just over a year ago by Cyara, and life has been unusually hectic over the last year. Hopefully I’ll have some time to post a bit more frequently in the near future. In the meantime, I’ve included a picture I took yesterday of an old ringfort nearby. West Cork is beautiful when the weather’s nice!

OpenWRT: Ad Guard Home, anti-pub, DoH & Contrôle parental

Posted by Guillaume Kulakowski on April 19, 2024 11:50 AM

Depuis plusieurs années, j’ai utilisé OpenWRT, mais je n’étais pas pleinement satisfait de ma solution de contrôle parental. C’était principalement à cause de l’utilisation des services d’OpenDNS, qui était nécessaire en raison de mes deux routeurs Redmi AC2100 ayant une capacité mémoire limitée (seulement 128 Mo). J’ai, depuis peu, fait l’achat d’un routeur Redmi AX6000 […]

Cet article OpenWRT: Ad Guard Home, anti-pub, DoH & Contrôle parental est apparu en premier sur Guillaume Kulakowski's blog.

Infra and RelEng Update – Week 16, 2024

Posted by Fedora Community Blog on April 19, 2024 10:00 AM

This is a weekly report from the I&R (Infrastructure & Release Engineering) Team. It also contains updates for the CPE (Community Platform Engineering) Team as the CPE initiatives are in most cases tied to I&R work.

We provide you both an infographic and a text version of the weekly report. If you just want to quickly look at what we did, just look at the infographic. If you are interested in more in-depth details look at the infographic.

Week: 15 April – 19 April 2024

<figure class="wp-block-image size-full">I&R infographic</figure>

Infrastructure & Release Engineering

The purpose of this team is to take care of day-to-day business regarding CentOS and Fedora Infrastructure and Fedora release engineering work.
It’s responsible for services running in Fedora and CentOS infrastructure and preparing things for the new Fedora release (mirrors, mass branching, new namespaces, etc.).
List of planned/in-progress issues

Fedora Infra

CentOS Infra including CentOS CI

Release Engineering

CPE Initiatives

EPEL

Extra Packages for Enterprise Linux (or EPEL) is a Fedora Special Interest Group that creates, maintains, and manages a high quality set of additional packages for Enterprise Linux, including, but not limited to, Red Hat Enterprise Linux (RHEL), CentOS, Scientific Linux (SL) and Oracle Linux (OL).

Updates

  • Texas Linux Fest (TXLF) was held from 12-13 April
    • Carl gave talk on the state of EPEL
    • Also manned the EPEL and Fedora booth
  • EPEL docs are being reworked to include onboarding processes
    • Also including an overall cleanup, better UI/UX

Community Design

CPE has few members that are working as part of Community Design Team. This team is working on anything related to design in Fedora Community.

Updates

  • F40 Wallpaper
  • BootC logo complete #158
  • Working with contributors for design assets for Fedora Week of Diversity and Fedora Mentor Summit

If you have any questions or feedback, please respond to this report or contact us on #redhat-cpe channel on matrix.

The post Infra and RelEng Update – Week 16, 2024 appeared first on Fedora Community Blog.

udev-hid-bpf: quickstart tooling to fix your HID devices with eBPF

Posted by Peter Hutterer on April 18, 2024 04:17 AM

For the last few months, Benjamin Tissoires and I have been working on and polishing a little tool called udev-hid-bpf [1]. This is the scaffolding required quickly and easily write, test and eventually fix your HID input devices (mouse, keyboard, etc.) via a BPF program instead of a full-blown custom kernel driver or a semi-full-blown kernel patch. To understand how it works, you need to know two things: HID and BPF [2].

Why BPF for HID?

HID is the Human Interface Device standard and the most common way input devices communicate with the host (HID over USB, HID over Bluetooth, etc.). It has two core components: the "report descriptor" and "reports", both of which are byte arrays. The report descriptor is a fixed burnt-in-ROM byte array that (in rather convoluted terms) tells us what we'll find in the reports. Things like "bits 16 through to 24 is the delta x coordinate" or "bit 5 is the binary button state for button 3 in degrees celcius". The reports themselves are sent at (usually) regular intervals and contain the data in the described format, as the devices perceives reality. If you're interested in more details, see Understanding HID report descriptors.

BPF or more correctly eBPF is a Linux kernel technology to write programs in a subset of C, compile it and load it into the kernel. The magic thing here is that the kernel will verify it, so once loaded, the program is "safe". And because it's safe it can be run in kernel space which means it's fast. eBPF was originally written for network packet filters but as of kernel v6.3 and thanks to Benjamin, we have BPF in the HID subsystem. HID actually lends itself really well to BPF because, well, we have a byte array and to fix our devices we need to do complicated things like "toggle that bit to zero" or "swap those two values".

If we want to fix our devices we usually need to do one of two things: fix the report descriptor to enable/disable/change some of the values the device pretends to support. For example, we can say we support 5 buttons instead of the supposed 8. Or we need to fix the report by e.g. inverting the y value for the device. This can be done in a custom kernel driver but a HID BPF program is quite a lot more convenient.

HID-BPF programs

For illustration purposes, here's the example program to flip the y coordinate. HID BPF programs are usually device specific, we need to know that the e.g. the y coordinate is 16 bits and sits in bytes 3 and 4 (little endian):

SEC("fmod_ret/hid_bpf_device_event")
int BPF_PROG(hid_y_event, struct hid_bpf_ctx *hctx)
{
	s16 y;
	__u8 *data = hid_bpf_get_data(hctx, 0 /* offset */, 9 /* size */);

	if (!data)
		return 0; /* EPERM check */

	y = data[3] | (data[4] << 8);
	y = -y;

	data[3] = y & 0xFF;
	data[4] = (y >> 8) & 0xFF;

	return 0;
}
  
That's it. HID-BPF is invoked before the kernel handles the HID report/report descriptor so to the kernel the modified report looks as if it came from the device.

As said above, this is device specific because where the coordinates is in the report depends on the device (the report descriptor will tell us). In this example we want to ensure the BPF program is only loaded for our device (vid/pid of 04d9/a09f), and for extra safety we also double-check that the report descriptor matches.

// The bpf.o will only be loaded for devices in this list
HID_BPF_CONFIG(
	HID_DEVICE(BUS_USB, HID_GROUP_GENERIC, 0x04D9, 0xA09F)
);

SEC("syscall")
int probe(struct hid_bpf_probe_args *ctx)
{
	/*
	* The device exports 3 interfaces.
	* The mouse interface has a report descriptor of length 71.
	* So if report descriptor size is not 71, mark as -EINVAL
	*/
	ctx->retval = ctx->rdesc_size != 71;
	if (ctx->retval)
		ctx->retval = -EINVAL;

	return 0;
}
Obviously the check in probe() can be as complicated as you want.

This is pretty much it, the full working program only has a few extra includes and boilerplate. So it mostly comes down to compiling and running it, and this is where udev-hid-bpf comes in.

udev-hid-bpf as loader

udev-hid-bpf is a tool to make the development and testing of HID BPF programs simple, and collect HID BPF programs. You basically run meson compile and meson install and voila, whatever BPF program applies to your devices will be auto-loaded next time you plug those in. If you just want to test a single bpf.o file you can udev-hid-bpf install /path/to/foo.bpf.o and it will install the required udev rule for it to get loaded whenever the device is plugged in. If you don't know how to compile, you can grab a tarball from our CI and test the pre-compiled bpf.o. Hooray, even simpler.

udev-hid-bpf is written in Rust but you don't need to know Rust, it's just the scaffolding. The BPF programs are all in C. Rust just gives us a relatively easy way to provide a static binary that will work on most tester's machines.

The documentation for udev-hid-bpf is here. So if you have a device that needs a hardware quirk or just has an annoying behaviour that you always wanted to fix, well, now's the time. Fixing your device has never been easier! [3].

[1] Yes, the name is meh but you're welcome to come up with a better one and go back in time to suggest it a few months ago.
[2] Because I'm lazy the terms eBPF and BPF will be used interchangeably in this article. Because the difference doesn't really matter in this context, it's all eBPF anyway but nobody has the time to type that extra "e".
[3] Citation needed

cloud-init and dhcpcd

Posted by Major Hayden on April 18, 2024 12:00 AM
Fedora’s cloud-init package now uses dhcpcd in place of dhclient, which went end of life in 2022. 💀

OpenWRT derrière une Freebox: IPv6, DMZ et Bridge

Posted by Guillaume Kulakowski on April 17, 2024 06:10 PM

Article mise à jour le 17/04/2024 pour tenir compte des spécificités d’OpenWRT 23.05. Bien que je sois le très récent et heureux possesseur d’une Freebox Pop, j’ai fait le choix de continuer à déléguer la gestion de mon réseau ainsi que de mon partage Wi-Fi, non pas à la Pop, mais à OpenWRT. Les avantages […]

Cet article OpenWRT derrière une Freebox: IPv6, DMZ et Bridge est apparu en premier sur Guillaume Kulakowski's blog.

Fedora Chat: Your Gateway to Matrix

Posted by Fedora Magazine on April 17, 2024 08:00 AM

What is Matrix?

Matrix is an open protocol for decentralized, secure communications built on the principles of interoperability and decentralization. You can create an account on a home server and then join channels across different home servers. This means if you have an account through Matrix.org, you can use it to join our community spaces! One of those is Fedora Chat.

The Matrix Foundation acts as the guardian of the Matrix protocol, ensuring it remains a free and open standard for secure, decentralized communication. It’s responsible for developing and maintaining the Matrix Specification along with working closely with the community to enhance interoperability and innovation.

What is Fedora Chat?

Fedora Chat is what we call our Matrix homeserver instance. It is a set of two homeservers, one for our community rooms as fedoraproject.org as well as the fedora.im homeserver which provides accounts for our users to join the fedoraproject.org rooms. Both of these are hosted by Element Matrix Services (“EMS”) thanks to our sponsorship from Red Hat.

You can use your fedora.im account to join other Matrix homeservers as well and collaborate with other communities, including Gnome, Mozilla, and Ubuntu!

Getting Started on Fedora Chat

Ready to jump into Fedora Chat? If you do not have a Matrix account already, you can use the fedora.im homeserver to get an account and join our community space! If you already have Matrix – you can join our Fedora space through this link.

  1. Visit https://chat.fedoraproject.org and click the blue “Sign in” and then “Continue with your Fedora Account” to login with your FAS account.
  2. You should be added to our Space automatically which is a collection of rooms, but if not, join the room here #fedora-space:fedoraproject.org
  3. You can then choose different rooms in the menu in which to say hello. Find a room and then say hello!

Exploring Other Matrix Clients

While Fedora Chat uses the hosted Element client, the Matrix universe is vast. Explore other clients that suit your needs, from desktop apps to mobile solutions. Each offers unique features, allowing you to tailor your experience. You can find an updated list of different clients on the Matrix.org website.

Understanding Encryption, Keys, and Device Verification

Matrix’s end-to-end encryption ensures that only the communicating users in a room can read messages. Some rooms are end-to-end encrypted, but most public rooms are not. Most rooms in Fedora community spaces are not end-to-end encrypted, and you can see the history. However, if you directly message another user or join an E2E room, your messages will be encrypted by default. This is achieved through the management of cryptographic keys that secure each conversation. The encryption process involves generating unique keys your client stores on your behalf.

Protecting your encryption keys is essential, and your Recovery Key is critical to keep. The Recovery Key allows you to restore access to your encrypted conversations if you lose access to your primary key backup. Keep your Recovery Key in a safe location.

Session verification further enhances security by allowing users to verify their identity across multiple devices, ensuring that verified devices can only read encrypted messages.

Element provides a great FAQ on how to create and manage your key backups, but this will vary based on the client you choose to use. If you use chat.fedoraproject.org, it is a great resource.

What’s Next

Join #fedora-space:fedoraproject.org and say hello in #intros:fedoraproject.org – and welcome to the Matrix-verse!

Fedora @ SCaLE 21x 2024

Posted by Fedora Community Blog on April 16, 2024 12:28 PM

Our ambassadors delivered support, outreach, and swag items via Fedora @ SCaLE 21x Linux Conference – a 2024 community event.

<figure class="wp-block-image size-full">Life-size entrance gateway to SCaLE 21x. Shows expo hours and various sponsors<figcaption class="wp-element-caption">Portal to Linux wonder: SCaLE 21x.</figcaption></figure>

At a Glance

  • What: A community-run open-source and free software conference in Pasadena, California
  • Where: Pasadena Convention Center
  • When: 14 – 17 March 2024
<figure class="wp-block-image size-large is-resized">The front of the main building of the Pasadena Convention Center with a large banner for SCaLE. Photo by Carl George.<figcaption class="wp-element-caption">Where SCaLE begins…The front of the main building of the Pasadena Convention Center.
Photo by Carl George.</figcaption></figure>

Our Team in the Field

This reports the activities of the following Ambassadors / Red Hatters at the Fedora @ SCaLE 21x Linux Conference:

What is SCaLE 21x?

The SCaLE (The Southern California Linux Expo) community Linux event delivered an iconic experience with four days of open source training, exhibits, and general presentations. This year’s conference took place in Pasadena (Los Angeles) area.

This expo drew worldwide guests to discuss AI, Linux, security, embedded, IoT, and more. The Conference Chair, Mr. Ilan Rabinovitch, and Technical Committee Chairperson, Owen Delong paved the way for a smooth registration.

<figure class="wp-block-image size-large is-resized">Ilan Rabinovitch onstage introducing a keynote<figcaption class="wp-element-caption">Ilan Rabinovitch</figcaption></figure>

Conference Highlights

Fedora @ SCaLE 21x Linux Conference – Ready, Set, Go!

Justin Flory arranged and shipped hand-selected swag and marketing items to Brian Monroe. Items include: pens, stickers, commuter mugs, badge ribbons, badge lanyards, and more.

Furthermore, the ambassadors gathered up supplies for the conference.

Day 1: Thursday 14 March

Red Hatter Brian Proffitt carefully delivered our marketing notebook system.

In addition, Perry brought the following:

  • Dry-board markers
  • Dry-board flipchart easel
  • Opportunity drawing tickets
  • Leftover ribbons, mini-swag from 19x event
  • Safety scissors
  • Gaffers tape
  • Glue
  • And more!

Some of our ambassadors travelled in the morning, to catch earlier events and workshops. Others, however, arrived later to factor in traffic.

  • <figure><figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Portal to New Linux Ideas</figcaption></figure>
  • <figure>picture of the back of the Fedora booth-a sheet wall<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">The back of the Fedora booth this year…a sheet wall..</figcaption></figure>

We met in the exhibit hall to check out the booth and to discuss strategy. Henceforth, we thought about our discussions and engagement to attract visitors. In contrast to SCaLE 20x, our booth was some distance away from the Red Hat booth.

The booth did not receive any free-standing banners this year. Thus, aside from our table cover, swag, and flip chart, we had few items to work with which had large Fedora branding. Soon, we discovered that some guests had initial challenges trouble locating our booth.

Upon dropping things off, some of us reconvened at the KWAAI Summit, new for 2024. Matt Small, Reza Rassool, Román Pineda, Khai Pham, John Willis, and others closed out the the event with an engaging Q&A, introductions, wrap up, and reception, for example.

Afterwards, Fedora joined the Red Hat and CentOS teams and others for a meal at the Yard House.

<figure class="wp-block-image size-large is-resized">Matt Miller, Shaun McCance, Perry Rivera, and Carl George around a table at Yard House Pasadena<figcaption class="wp-element-caption">From L to R: Matthew Miller, Shaun McCance, Perry Rivera, and Carl George</figcaption></figure>

Day 2: Friday 15 March

Checking in on the other variants…

Alejandro and I set out for breakfast Friday and discussed booth and expo plans for the days ahead. Eventually, we headed off to the NixCon track co-located in SCaLE 21x to learn about Nix. We were surprised to find a very packed workshop.

Booth Setup

After a brief look into these OSes, we returned to the Expo Hall to begin putting our booth together. For example, Scott arrived to install a notebook system that he configured with Flatpak pinball game running atop Universal Blue.

  • <figure><figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">A guest re-discovers pinball on an immutable desktop</figcaption></figure>
  • <figure></figure>
  • <figure>Red Hatters setting up a booth<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Red Hatters setting up a booth</figcaption></figure>

Next, Perry set up a Fedora flip chart and pasted in a handy QR that Alejandro generated for guests to claim a Fedora badge. Then, Alejandro later wrote in our Fedora scheduled talks, which was handy for guests to take pictures of as they stopped by. Concurrently, Brian strategically set up swag items and carefully routed power within the booth.

Perry later stopped by the Red Hat booth to help raise the 5-person banner. It’s not heavy, however, but it is awkward and difficult to stand up with fewer than 5-people in attendance.

What an Exhibit at Fedora @ SCaLE 21x Linux Conference

At 10am, the Exhibit Hall opened. As a result, we had a steady stream of community throughout the reminder of the conference. Then, we took turns for breaks from time to time; however, as we were down a person, things felt a bit busier this year. We definitely missed not having Iván Chavero there.

We greeted approximately 400+ this day.

One of the many highlights from today was discovering a vending machine that dispenses temporary VMs. The buttons were quite amusing.

<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex"> <figure class="wp-block-image size-full">picture of a vending machine with googly eyes<figcaption class="wp-element-caption">Eye-deal VM Vending Re-use.</figcaption></figure> <figure class="wp-block-image size-full">zoomed in picture of vending machine buttons</figure> </figure>

At length, a few of us met up with Red Hat, CentOS, at El Portal Restaurant for dinner.

  • <figure>picture of food from El Portal restaurant<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">El Portal Restaurant for dinner.</figcaption></figure>
  • <figure>Rob McBryde singing karaoke<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Rob McBryde: Coordinator of Karaoke goodness.</figcaption></figure>

Subsequently, we met up with Red Hat and CentOS later at Barney’s Beanery to enjoy karaoke and merriment.

Day 3: Saturday 16 March

Specifically, Brian Monroe, Scott, and Perry met up early Saturday morning to go over slide logistics for our Exploring Immutable Linux Desktops with Fedora presentation later that day. Afterward, we caught up with Alejandro at the booth to continue engaging with guests and greeted approximately 500+ this day.

Perry dropped in on a Digital Art / Krita open-source application workshop that went over how the fundamentals of using this tool. They gave pointers on how they use the app in their workflow, for instance.

  • <figure>Nicholas Maramba and Helen Ortiz presenting<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Nicholas Maramba and Helen Ortiz present “Digital Art Makes You Smart”</figcaption></figure>
  • <figure>Lucky winner holding up a Fedora commuter tumbler<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Humberto Macias, lucky winner of a Fedora commuter tumbler.</figcaption></figure>
  • <figure>sign to a reproducible and immutable desktop presentation<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Portal to the endless wonder of immutable desktops..</figcaption></figure>
  • <figure>guests engaging in an Immutable Desktop presentation<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Guests listened attentively at the Immutable Desktop presentation</figcaption></figure>
  • <figure>Scott Williams chats with Joshua Loscar at the Red Hat Booth<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Scott Williams chats with Joshua Loscar at the Red Hat Booth</figcaption></figure>
  • <figure>Jeff Carlson playing solitaire<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Jeff Carlson ponders his next move..</figcaption></figure>

We also held opportunity drawings throughout the week to beckon more booth interest. Indeed, this proved a success. 40+ people stopped by for each draw.

Comparatively, Perry, Brian Monroe, and Scott later delivered their presentation to 45+ guests.

Thereafter, we re-joined Alejandro to finish up meeting our community at the booth for the expo day. We ate a late linner at the Dog Haus to reflect on the week’s events.

Soon, SCaLE 21x held their annual game night event. Next, we reunited with friends and associates to catch up and enjoy.

Day 4: Sunday 17 March

All of us packed up our rooms early Sunday. Naturally, Alejandro and I re-joined up at the Cordova Cafe for breakfast.

Consequently, we made our way over to the Exhibit Hall to finish up a final day with guests. Altogether, we had a little breather to visit the CentOS booth and say hello.

<figure class="wp-block-image size-large is-resized">Shaun McCance and Carl George exhibiting at the CentOS booth<figcaption class="wp-element-caption">Shaun McCance and Carl George exhibiting at the CentOS booth</figcaption></figure>

The final exhibit day brought in about 250 guests to our booth. Following, our team packed up the booth for transport.

Ultimately, to complete a fine Sunday, we attentively listened to an excellent closing keynote provided by Bill Cheswick.

Suggestion / Feedback Box Items for Fedora @ SCaLE 21x Linux Conference

In addition, we had a booth sign-in sheet for visitors to help collect feedback and suggestions about Fedora and related efforts.

From data compiled, we summarize these key highlights:

  • Marketing: Many requests for Fedora new logo swag and shirts. Could use stuffed animals, socks, or something different, USB stick. More creative ideas, sticker ideas (hex are popular), floor banners with new logo, DEI stickers were very popular. Portable swag (small and travel-ready) is great for travelers.
  • Marketing: One guest suggested a Fedora merch store where community could purchase Fedora logo swag/stickets/items. Above all, proceeds ideally would funnel back to Fedora community where needed.
  • Cross: One Debian guest continues prefers Debian for consistency, but wouldn’t mind using Fedora if a consistent spin was available. Potentially opportunity for immutable education or Debian/Ubuntu/NixOS etc. to Fedora presentations.
  • Info: Another Debian guest wanted to know key differences between Debian and Fedora. Ultimately, potential opportunity for explainer or migrating presentation or Why Use Fedora vs. ________?
  • Usage: One mentioned they are a Rawhide user.
  • Info: One requested more information about NeuroFedora. In other words, clearer information about what it is and the status of that Special Interest Group (SIG). Explainer card might be helpful at the booth.
  • Usage: One guest enjoys QT packages with DX build.
  • Licensing/Booth Info: One guest wanted clearer definition of the licensing relationship and sponsorship between Fedora / RHEL, if any.
  • Fedora Activity Day: It might be advantageous for Fedora to identify an organizer for a Fedora Activity Day (or two). For example, possible topics include: Debian to Fedora, command-line, Gnome, KDE, Immutable, Ambassadoring, Why Use Fedora vs. X?, etc.
  • Other: Changes for CentOS and Red Hat were points of concern and confusion for some guests.
  • Comm: Connect with Universal Blue folks, Lutris, Nobaro (sp?). Bazzite quality badges
  • Booth: Engagement with community at the table, opportunity drawing seems to be a success. Let’s get people in the front door of Fedora…for SCaLE 22x, provide challenge or engaging gimmick.
<figure class="wp-block-image size-large is-resized">Brian Monroe chats with a guest<figcaption class="wp-element-caption">Brian Monroe chats with a guest</figcaption></figure>

Fedora 39 specific suggestions/comments:

  • Usage: Runs great on Dell Lat 7390
  • Usage: It’s awesome
  • Usage: (I) want to try it!
  • Marketing/Immutable/Porting: Cool retro (pinball) demo [at SCaLE 21x]
  • Thank You/Derivative: Ultramarine user says thank you for Fedora.
  • Thank You/Support: Thank you for Data Transit (GTFS) support
  • Magic Wormhole and Fedora are great. Ultimately, we referred this guest to Matthew Miller.
  • One guest tracking 39 and 40 Beta packaging and kernel. Definitely, this visitor expressed interest in helping with general or immutable. Additionally, we referred this guest.

In conclusion, we look forward to seeing you at next year’s SCaLE!

Snaps from Fedora @ SCaLE 21x Linux Conference

  • <figure>picture of Perry Rivera and Kevin Howell. Kevin gives a thumbs up.<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Perry Rivera and Kevin Howell</figcaption></figure>
  • <figure>top-down view of the first floor of the Pasadena Conference Center from the second floor balcony. a picture of 40+ people chatting and/or working on laptops<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Conference Center Conversation Flows. Photo by Carl George</figcaption></figure>
  • <figure>Patrick Finie and Perry Rivera<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Patrick Finie and Perry Rivera</figcaption></figure>
  • <figure>Photo of Neil Gompa, Shaun McCance at the podium presenting a kernels talk. Photo taken by Carl George.<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">An engaging kernels workshop by Neil Gompa, Shaun McCance, and Carl George. Photo by Carl George.</figcaption></figure>
  • <figure>Ana Ma and Perry Rivera<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Ana Ma and Perry Rivera</figcaption></figure>
  • <figure>Romy Meyerson SuSe stops by to visit to say hello<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Romy Meyerson@SuSe stops by to visit to say hello..</figcaption></figure>
  • <figure>Rob McBryde, Jaime Burwood, Katherine Nnanwubar, Perry Rivera, and Brian Proffitt<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Rob McBryde, Jaime Burwood, Katherine Nnanwubar, Perry Rivera, and Brian Proffitt</figcaption></figure>
  • <figure>Perry Rivera and Siggy<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Perry Rivera and Siggy</figcaption></figure>
  • <figure>Perry Rivera and Marc Provitt<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Perry Rivera and Marc Provitt from SCaLE 21x’s Game Night event.</figcaption></figure>
  • <figure>At a round table: Scott Williams, Brian Monroe, Shaun McCance, and Carl George with notebook systems.<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Discussing SCaLE strategies. L to R: Scott Williams, Brian Monroe, Shaun McCance, and Carl George.</figcaption></figure>
  • <figure>Perry Rivera and Bill Cheswick<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Perry Rivera and Bill Cheswick</figcaption></figure>
  • <figure>Fedora and Red Hatters having dim sum around table<figcaption class="wp-block-jetpack-slideshow_caption gallery-caption">Clockwise, L to R: Joshua Loscar, Shaun McCance, Brian Proffitt, Cali Dolfi, Perry Rivera, Alex Acosta, Carl George, and Joshua’s oldest son discussing SCaLE week highlights at Lunasia Dim Sum House…</figcaption></figure>

Related Posts

The post Fedora @ SCaLE 21x 2024 appeared first on Fedora Community Blog.

When it comes to sudo logging, pretty is not always better

Posted by Peter Czanik on April 16, 2024 11:47 AM

Version 1.9.16 of sudo will introduce a new logging option: json_compact. This does not affect logging to syslog, only logging to files. Previously, sudo created human-readable JSON log files. With this new setting enabled, logs are no longer pretty but can be easily read by logging software.

As I am writing this blog, version 1.9.16 is not yet released, not even a beta. For now, if you want to test this feature, you will have to compile sudo yourself from source. Once 1.9.16 is released, it will be available here on the sudo website as ready to install package for major Linux and UNIX variants. And eventually it will officially become available in various operating systems, FreeBSD and rolling Linux distros first.

Read more at https://www.sudo.ws/posts/2024/04/when-it-comes-to-sudo-logging-pretty-is-not-always-better/

<figure><figcaption>

Sudo logo

</figcaption> </figure>

Working with sudo’s json_compact logs in syslog-ng

Posted by Peter Czanik on April 16, 2024 11:41 AM

Version 1.9.16 of sudo will feature a new option for logging: json_compact. Why is this important? This new format can easily be read and parsed by a log management software, like syslog-ng.

Note that in this blog I am showing you a sudo feature which has not yet been released officially. You have to compile sudo yourself. By all means, if you have any other application writing JSON-formatted log messages, you can apply most of what you read here with slight modifications.

Read the rest at https://www.syslog-ng.com/community/b/blog/posts/working-with-sudo-s-json_5f00_compact-logs-in-syslog-ng

<figure><figcaption>

syslog-ng logo

</figcaption> </figure>

Thank you Python for years of service and reliability so far (and the ctypes module!)

Posted by Jon Chiappetta on April 16, 2024 11:04 AM

So I’ve run into this issue in the past but I finally started looking into why Python is soo slow at running basic math operations in a long loop, for example, simple stream cipher operations. You’ll see lots of suggestions to use numpy instead, however, I didn’t find this to be the most helpful. Since I like writing/reading C, I remembered that Python has a built-in ctypes module which is very helpful and useful if you are in need of specialized and optimized code paths. You can pretty easily pass in integer and byte array pointers with little complexity!

For example:

<figure class="wp-block-image size-large"></figure>

~

<figure class="wp-block-image size-large"></figure>

Texas Linux Fest 2024 recap 🤠

Posted by Major Hayden on April 16, 2024 12:00 AM
I gave two talks at this year’s event and ran into lots of old friends and colleagues. 🐧

Running Keystone in development mode on Ubuntu 22.04

Posted by Adam Young on April 15, 2024 06:30 PM

Things have diverged a bit from the docs. Just want to document here what I got working:

I had already checked out Keystone and run the unit tests.

I needed uwsgi

sudo apt install uwsgi-core
sudo apt install uwsgi-plugin-python3


Then a modified command line to run the server:

uwsgi --http-socket 127.0.0.1:5000    --plugin /usr/lib/uwsgi/plugins/python3_plugin.so   --wsgi-file $(which keystone-wsgi-public)

This got me the last part

https://stackoverflow.com/questions/31330905/uwsgi-options-wsgi-file-and-module-not-recognized

A Frequência Cardíaca de Yuja Wang

Posted by ! Avi Alkalay ¡ on April 15, 2024 12:37 PM

Chamando todos os cientistas de dados, sobretudo os que lidam com séries temporais, como eu, para ver um experimento.

<figure class="wp-block-image size-large"></figure>

Mediram a frequência cardíaca de Yuja Wang, a pianista erudita mais badalada do momento — e a mais gata também ❤ — enquanto executava uma façanha sem precedentes: tocar todos os 5 concertos de piano de Rachamninoff em uma única apresentação de mais de 4 horas de duração. Mediram também a frequência cardíaca do regente Yannick Nézet-Séguin, de alguns músicos da orquestra, e também de ouvintes na platéia, no Carnegie Hall de Nova York, em 28 de janeiro de 2023.

Os concertos de piano de Rachmaninoff não são qualquer obra. Conhecidos pela sua beleza e dificuldade, são frequentemente tratados como alguns dos pilares emocionais da humanidade. São 4 os concertos; e o “quinto” é um conjunto de variações, compostas por Rachmaninoff, sobre um tema de Paganini.

Entrevistas, explicações e análises de dados podem ser vistas no vídeo do Carnegie Hall. Algumas revelações dos dados coletados são óbvias: devido ao esforço físico, o coração de Yuja dispara conforme a densidade da partitura aumenta. Mas outras constatações são também muito interessantes, como o sincronismo cardíaco — ou emocional — entre a pianista, público e músicos.

Um experimento multi-disciplinar absolutamente lindo, inédito e necessário.

<figure class="wp-block-image size-large"></figure> <figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio">
<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="allowfullscreen" frameborder="0" height="365" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/SuA9l77ODbs?feature=oembed" title="Tracking Yuja Wang’s Heartbeats During Her Rachmaninoff Marathon | Carnegie Hall" width="648"></iframe>
</figure>