The solo maintainer for libxml2 is no longer accepting embargoed vulnerability reports, citing the unsustainable burden as an unpaid volunteer. Security issues will be treated like any other bug report moving forward.
https://socket.dev/blog/libxml2-maintainer-ends-embargoed-vulnerability-reports #opensource #cybersecurity h/t @joshbressers
Reporting a „possible memory leak“ in a 7 year old curl version, because the RSS jumps from 6.2 to 7 MB once.
Could be.
But, dear reporter, we can only try our best to be a better curl *today*. There is no changing the past (hence the name).
We outstretch our hands to you! Come and live with us in the present! Let the ancestors rest and rejoyce among the living!
Ticket sales for Kernel Recipes 2025 are now open! The conference will take place from September 22 to 24, 2025, in Paris. The agenda is still in the works, but you can already check out the list of speakers and a few of the topics online.
https://kernel-recipes.org/en/2025/
If you're a student, we’re offering a 50% discount—just get in touch with us!
See you in september!
A bunch of new stable kernels is out. With them, the #Linux 6.14.y stable series is now end-of-life – shortly after the merge window of 6.16 closed.
This thus happened a bit earlier than we are used to, but will be the new normal. To quote @gregkh from https://lore.kernel.org/all/2025061030-latticed-capacity-dc94@gregkh/:
'"Note this is the LAST 6.14.y release. This kernel branch is now end-of-life. Please move to the 6.15.y kernel branch at this time.
If you notice, this has happened a bit more "early" than previous end-of-life announcements. Normally, after -rc1 is out there is a TON of stable patches happening due to the changes that come into the merge-window that were marked for stable backports but didn't get into Linus's release before -final. As some people have objected to this large influx being added to a stable kernel that is just about to go end-of-life, let's try marking this end-of-life a bit earlier to see how it goes.
It might also spur maintainers/developers to get fixes into -final a bit more as well :)"'
Q: "Why have you suddenly been reworking coredumping, Christian?"
A: "Because I'm a clown and also I had it with all the CVEs because we provide a **** API for userspace."
So now that @torvalds merged the pidfs and initial coredump work things are already better but I have more work there.
In other news, there's two new CVEs in userpace that should be gone completely by installing a pidfd into the umh or by using the coredump socket.
[1]: https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt
ER2025 is over, and thanks to all of our sponsors it was a big success!
https://embedded-recipes.org/2025/blog/wrap/
The slides & videos are now available on the Speakers page
of the website: https://embedded-recipes.org/2025/speakers/
Please don’t hesitate to send us your feedback, critiques,
suggestions and rants. We’d want to hear what you thought of the
location, the venue, the food, the talks, the workshops, the evening
event, or anything else you want to share with us.
Please write us at: embedded-recipes@baylibre.com
[deep LTC cut] Who would have guessed that the unwanted task of working on MCP at IBM 20 years ago would finally pay off on the resume!
This is a great interview with @gregkh on corporate involvement in the #Linux kernel and #opensource. He goes in depth on justifying working upstream and how it made him a better engineer.
Really excited for Zim's talk at Embedded Recipes showing off all the cool things Perfetto can do! It's a really useful tool.
I helped with one of the examples, and had seen the slides prior, but even so, I *still* learned some new tricks from watching.
https://www.youtube.com/live/802-CNevuY8?feature=shared&t=7608
#LLMs are not a knowledge base!
Stop spreading misinformation!
They are statistical models that _simulate_ knowledge!
We, as a #society, really have to pay attention to the words and #language we're using.
But I guess, when talking about LLMs, details are not really important, are they!? Oh, such beautiful irony!
"If all these big companies are shouting from the rooftops that AI is up to production code the money relies on, then zero open source contributions of substance is a glaring absence."
(Original title: If AI is so good at coding … where are the open source contributions?)
@embeddedrecipes has just kicked off!
New organizers are running the show this year — big thanks to BayLibre for picking up the torch and keeping the spirit of Recipes alive: small-scale, sharing, and real exchange.
You can follow the conference live!
The 2025 edition of @embeddedrecipes starts with @gregkh
https://www.youtube.com/live/U5L8XHkP-lI?si=h5-X2I97Rnb1hey8
#er2025 #embeddedrecipes
Long but cheering+ practical from @bert_hubert
https://berthub.eu/articles/posts/a-coherent-non-us-cloud-strategy/
"Europe has ample compute capacity and skills.... the carrot won’t be enough to make Europe sovereign again. We must have our own technology under our own control, but we must also make sure that it gets used"