Language Selection

English French German Italian Portuguese Spanish

Linuxinsight

Syndicate content
LinuxInsight - aggregated feeds
Updated: 14 min 50 sec ago

TuxMachines: GNOME and Fedora

1 hour 27 min ago
  • RFC: Integrating rsvg-rs into librsvg

    I have started an RFC to integrate rsvg-rs into librsvg. rsvg-rs is the Rust binding to librsvg. Like the gtk-rs bindings, it gets generated from a pre-built GIR file.

  • 1+ year of Fedora and GNOME hardware enablement

    A year and a couple of months ago, Christian Schaller asked me to pivot a little bit from working full time on Fleet Commander to manage a new team we were building to work on client hardware enablement for Fedora and GNOME with an emphasis on upstream. The idea was to fill the gap in the organization where nobody really owned the problem of bringing up new client hardware features vertically across the stack (from shell down to the kernel), or rather, ensure Fedora and GNOME both work great on modern laptops. Part of that deal was to take over the bootloader and start working closer to customers and hardware manufacturing parnters.

  • Fedora Atomic Workstation: Works on the beach

    My trip is getting really close, so I decided to upgrade my system to rawhide. Wait, what ? That is usually what everybody would tell you not to do. Rawhide has this reputation for frequent breakage, and who knows if my apps will work any given day. Not something you want to deal with while traveling.

  • 4 cool new projects to try in COPR for February

read more

LXer: Set Up A Python Django Development Environment on Debian 9 Stretch Linux

2 hours 5 min ago
Django is the top Python web development framework and for good reason. It's powerful, flexible, and doesn't get in the way of developers. It also scales incredibly well, powering sites like Instagram.

TuxMachines: Why You Shouldn’t Use Firefox Forks (and Proprietary Opera)

2 hours 8 min ago
  • Why You Shouldn’t Use Firefox Forks Like Waterfox, Pale Moon, or Basilisk

    Mozilla Firefox is an open source project, so anyone can take its code, modify it, and release a new browser. That’s what Waterfox, Pale Moon, and Basilisk are—alternative browsers based on the Firefox code. But we recommend against using any of them.

  • Opera Says Its Next Opera Release Will Have the Fastest Ad Blocker on the Block

    Opera Software promoted today its upcoming Opera 52 web browser to the beta channel claiming that it has the faster ad blocker on the market compared to previous Opera release and Google Chrome.

    One of the key highlights of the Opera 52 release will be the improved performance of the built-in ad blocker as Opera claims to have enhanced the string matching algorithm of the ad blocker to make it open web pages that contain ads much faster than before, and, apparently than other web browsers, such as Chrome.

read more

Phoronix: Pengutronix Gets Open-Source 3D Working On MX8M/GC7000 Hardware

2 hours 8 min ago
We've known that Pengutronix developers had been working on i.MX8M / GC7000 graphics support within their Etnaviv open-source driver stack from initial patches posted in January. Those patches back at the start of the year were for the DRM kernel driver, but it turns out they have already got basic 3D acceleration working...

TuxMachines: Graphics: Glxinfo, ANV, SPIR-V

2 hours 14 min ago
  • Glxinfo Gets Updated With OpenGL 4.6 Support, More vRAM Reporting

    The glxinfo utility is handy for Linux users in checking on their OpenGL driver in use by their system and related information. But it's not often that glxinfo itself gets updated, except that changed today with the release of mesa-demos-8.4.0 as the package providing this information utility.

    Mesa-demos is the collection of glxinfo, eglinfo, glxgears, and utilities related to Mesa. With the Mesa-demos 8.4.0 it is predominantly glxinfo updates.

  • Intel ANV Getting VK_KHR_16bit_storage Support Wrapped Up

    Igalia's Jose Maria Casanova Crespo sent out a set of patches today for fixes that allow for the enabling of the VK_KHR_16bit_storage extension within Intel's ANV Vulkan driver.

    The patches are here for those interested in 16-bit storage support in Vulkan. This flips on the features for storageBuffer16BitAccess, uniformAndStorageBuffer16BitAccess, storagePushConstant16 and the VK_KHR_16bit_storage extension. This support is present for Intel "Gen 8" Broadwell graphics and newer. Hopefully the work will be landing in Mesa Git soon.

  • SPIR-V Support For Gallium3D's Clover Is Closer To Reality

    It's been a busy past week for open-source GPU compute with Intel opening up their new NEO OpenCL stack, Karol Herbst at Red Hat posting the latest on Nouveau NIR support for SPIR-V compute, and now longtime Nouveau contributor Pierre Moreau has presented his latest for SPIR-V Clover support.

    Pierre has been spending about the past year adding SPIR-V support to Gallium3D's "Clover" OpenCL state tracker. SPIR-V, of course, is the intermediate representation used now by OpenCL and Vulkan.

read more

TuxMachines: Security: Updates, Tinder, FUD and KPTI Meltdown Mitigation

2 hours 32 min ago
  • Security updates for Friday
  • Tinder vulnerability let hackers [sic] take over accounts with just a phone number

    The attack worked by exploiting two separate vulnerabilities: one in Tinder and another in Facebook’s Account Kit system, which Tinder uses to manage logins. The Account Kit vulnerability exposed users’ access tokens (also called an “aks” token), making them accessible through a simple API request with an associated phone number.

  • PSA: Improperly Secured Linux Servers Targeted with Chaos Backdoor [Ed: Drama queen once again (second time in a week almost) compares compromised GNU/Linux boxes to "back doors"]

    Hackers are using SSH brute-force attacks to take over Linux systems secured with weak passwords and are deploying a backdoor named Chaos.

    Attacks with this malware have been spotted since June, last year. They have been recently documented and broken down in a GoSecure report.

  • Another Potential Performance Optimization For KPTI Meltdown Mitigation

    Now that the dust is beginning to settle around the Meltdown and Spectre mitigation techniques on the major operating systems, in the weeks and months ahead we are likely to see more performance optimizations come to help offset the performance penalties incurred by mitigations like kernel page table isolation (KPTI) and Retpolines. This week a new patch series was published that may help with KPTI performance.

read more

TuxMachines: Purism News

2 hours 34 min ago
  • February 2018 coreboot update now available

    Hey everyone, I’m happy to announce the release of an update to our coreboot images for Librem 13 v2 and Librem 15 v3 machines.

    All new laptops will come pre-loaded with this new update, and everyone else can update their machines using our existing build script which was updated to build the newest image. Some important remarks:

  • Purism Releases Updated Coreboot Images For Their Laptops

    Purism has released updated Coreboot images for their Librem 13 v2 and Librem 15 v3 laptops.

    The updated Coreboot images are now re-based to Coreboot 4.7, Intel FSP 2.0, IOMMU (VT-d) support is now available, TPM support is also enabled, and there are fixed ATA errors for 6Gbps speeds.

  • New Inventory with TPM by Default, Free International Shipping

    In November, we announced the availability of our Trusted Platform Module as a $99 add-on for early adopters, something that would allow us to cover the additional parts & labor costs, as well as test the waters to see how much demand there might be for this feature. We thought there would be “some” interest in that as an option, but we were not sure how much, especially since it was clearly presented as an “early preview” and offered at extra cost.

read more

TuxMachines: Mycroft AI on Plasma

2 hours 45 min ago

Mycroft is running through the last 24 hours of the crowdfunding campaign for its Mark II assistant. The machine looks awesome and offers similar functionality to other proprietary alternatives, but with none of the spying and leaking of personal data.

The Mark 2 will be delivered to backers at the end of this year, but you can enjoy the pleasures of giving orders to an AI right now by installing the Mycroft widget on Plasma courtesy of KDE hacker Aditya Mehra.

read more

LXer: Unlucky Linux boxes trampled by NPM code update, patch zapped

3 hours 14 min ago
Devs stumble into pre-release beta by using command they didn't understandNPM – the biz behind the Node.js package management software used to wrangle JavaScript code and various related frameworks – on Thursday undid a code update less than 24 hours after it was issued because the software was messing with Linux file permissions.…

TuxMachines: Radeon Linux OpenGL Driver Continues Giving Its Best Against Windows 10

3 hours 23 min ago

With having around a Windows 10 installation this week for the latest Windows 10 WSL vs. Linux benchmarking, I also carried out some fresh benchmarks of the Radeon gaming performance between Windows 10 and Ubuntu Linux using the very latest drivers on each platform. This time around a Radeon RX 580 and RX Vega 64 were used for this benchmarking.

read more

TuxMachines: Ubuntu 18.04 LTS (Bionic Beaver) Daily Builds Now Fuelled by Linux Kernel 4.15

3 hours 27 min ago

The Ubuntu Kernel team promised at the beginning of the development cycle for Ubuntu 18.04 LTS (Bionic Beaver), Canonical's seventh long-term supported Ubuntu release to receive security and software update for the next five years, that they target the Linux 4.15 kernel series for the operating system.

Linux 4.15 had one of the longest development cycles in the history of kernels for GNU/Linux distributions, due to the numerous patches to mitigate the nasty Meltdown and Spectre security vulnerabilities for 64-bit architectures. It finally arrived at the end of January, so it took a month for Ubuntu Kernel team to implement it.

Also: Linux 4.15 Kernel Is Now The Default In Ubuntu 18.04 LTS

read more

TuxMachines: Canonical Releases Major Kernel Security Update for Ubuntu 14.04 to Fix 26 Flaws

3 hours 29 min ago

A total of 26 security flaws were fixed in today's kernel update for Ubuntu 14.04 LTS systems and derivatives, including an out-of-bounds write vulnerability in Linux kernel's F2F (Flash-Friendly File System) file system, a use-after-free flaw in Linux kernel's ALSA PCM subsystem, and an integer overflow in Linux kernel's sysfs interface for the QLogic 24xx+ series SCSI driver.

Additionally, the kernel update addresses a use-after-free vulnerability in Linux kernel's SCTP protocol implementation, as well as a race condition in the LEGO USB Infrared Tower driver and a use-after-free vulnerability in the USB serial console driver, both allowing a physically proximate attacker to execute arbitrary code or crash the system with a denial of service attack.

read more

TuxMachines: Plasma Mobile Could Give Life to a Mobile Linux Experience

3 hours 37 min ago

In the past few years, it’s become clear that, outside of powering Android, Linux on mobile devices has been a resounding failure. Canonical came close, even releasing devices running Ubuntu Touch. Unfortunately, the idea of Scopes was doomed before it touched down on its first piece of hardware and subsequently died a silent death.

The next best hope for mobile Linux comes in the form of the Samsung DeX program. With DeX, users will be able to install an app (Linux On Galaxy—not available yet) on their Samsung devices, which would in turn allow them to run a full-blown Linux distribution. The caveat here is that you’ll be running both Android and Linux at the same time—which is not exactly an efficient use of resources. On top of that, most Linux distributions aren’t designed to run on such small form factors. The good news for DeX is that, when you run Linux on Galaxy and dock your Samsung device to DeX, that Linux OS will be running on your connected monitor—so form factor issues need not apply.

read more

Reddit: linux training, not for certification, is the RH199 course worth it?

3 hours 48 min ago

So, after our linux admin left the company, I've been nominated to be the new one on top of my other admin hats... I've had some experience over the years, many different distros for home, and things from SCO Unix to RedHat to RHEL to CentOS in production (our backup appliances run centOS, and it's the backend for a lot of things like that.) Never had any 'official' training though.

My supervisors want me to take a linux class, not for any certification, but to be familiar with our environment, which may end up being a bunch of Oracle Linux as well as since we've got a pretty massive investment from ODA hardware and up, and the majority of our heavy database lifting is Oracle.

Would the RH199 fast-track course be a good course to get myself back up to speed on the current state of linux and how it's used in an enterprise environment?

Is there a different offering that would be better suited for this kind of thing?

my thanks.

submitted by /u/SgtRauksauff
[link] [comments]

Reddit: push or pull backup? is borg backup as good as rsync?

3 hours 51 min ago

I've been using dirvish (a rsync wrapper) and rsync for my backups for years. I'm quite happy with it, but was looking into solutions that does de-duplication between multiple machines.

dirvish uses rsync via SSH to connect to remote machines (must be reachable). It does primitive hard-linking between files that are the same, but no de-duplication as borg does. If a file changes the path it gets archived again. Borg checks for path change and de-duplicates - very handy.

In my current setup I run dirvish on a 'backup-server'. It has runs scheduled with cron and visits every server it needs to backup. It's a pull backup routine. I'm concerned about breaches of machines that would lead to access to other machines or would possibly render my backup useless. let me explain: If an attacker breaks into machine1 he/she cannot access the backup-machine. and has not way to machine2/3/4. If an attacker breaks into the backup-machine he/she has access to all the backups, but the live systems machine1/2/3/4 are safe, except for the fact that the attacker could trigger backups. That's acceptable, as I see no way around that. The fact that the access to the backup-machine is compromised does not mean attackers have access to machine1/2/3/4. I'm using the command feature of SSH's 'authorized-keys' file to limit access to the backup command. Any other command issued will just trigger the backup command. As the backup-server just has keys for this backup command to all machines this is why no other access is leaked.

As I understand borg backup, it uses push backup to do it's thing. So here is my question: How would I secure a system against attackers that want to destroy data? Say an attacker hacks machine1 and is now able to create backups. They also can prune the backups, remove data from the live machine, create useless backups etc. How does one secure the backup on a remote backup-machine from the machine it's supposed to backup?

AFAIK borg runs the prune command from the machine it's backing up, is there a way around that? or even prevent that? Can I set it to only prune from the backup-server?

Do you use your borg backup setups in a similar way?

submitted by /u/fl0w0lf
[link] [comments]

Linux.com: Plasma Mobile Could Give Life to a Mobile Linux Experience

5 hours 12 min ago
Title: Plasma Mobile Could Give Life to a Mobile Linux Experience23 FebLearn more

More in Tux Machines

GNOME and Fedora

  • RFC: Integrating rsvg-rs into librsvg
    I have started an RFC to integrate rsvg-rs into librsvg. rsvg-rs is the Rust binding to librsvg. Like the gtk-rs bindings, it gets generated from a pre-built GIR file.
  • 1+ year of Fedora and GNOME hardware enablement
    A year and a couple of months ago, Christian Schaller asked me to pivot a little bit from working full time on Fleet Commander to manage a new team we were building to work on client hardware enablement for Fedora and GNOME with an emphasis on upstream. The idea was to fill the gap in the organization where nobody really owned the problem of bringing up new client hardware features vertically across the stack (from shell down to the kernel), or rather, ensure Fedora and GNOME both work great on modern laptops. Part of that deal was to take over the bootloader and start working closer to customers and hardware manufacturing parnters.
  • Fedora Atomic Workstation: Works on the beach
    My trip is getting really close, so I decided to upgrade my system to rawhide. Wait, what ? That is usually what everybody would tell you not to do. Rawhide has this reputation for frequent breakage, and who knows if my apps will work any given day. Not something you want to deal with while traveling.
  • 4 cool new projects to try in COPR for February

Why You Shouldn’t Use Firefox Forks (and Proprietary Opera)

  • Why You Shouldn’t Use Firefox Forks Like Waterfox, Pale Moon, or Basilisk
    Mozilla Firefox is an open source project, so anyone can take its code, modify it, and release a new browser. That’s what Waterfox, Pale Moon, and Basilisk are—alternative browsers based on the Firefox code. But we recommend against using any of them.
  • Opera Says Its Next Opera Release Will Have the Fastest Ad Blocker on the Block
    Opera Software promoted today its upcoming Opera 52 web browser to the beta channel claiming that it has the faster ad blocker on the market compared to previous Opera release and Google Chrome. One of the key highlights of the Opera 52 release will be the improved performance of the built-in ad blocker as Opera claims to have enhanced the string matching algorithm of the ad blocker to make it open web pages that contain ads much faster than before, and, apparently than other web browsers, such as Chrome.

Graphics: Glxinfo, ANV, SPIR-V

  • Glxinfo Gets Updated With OpenGL 4.6 Support, More vRAM Reporting
    The glxinfo utility is handy for Linux users in checking on their OpenGL driver in use by their system and related information. But it's not often that glxinfo itself gets updated, except that changed today with the release of mesa-demos-8.4.0 as the package providing this information utility. Mesa-demos is the collection of glxinfo, eglinfo, glxgears, and utilities related to Mesa. With the Mesa-demos 8.4.0 it is predominantly glxinfo updates.
  • Intel ANV Getting VK_KHR_16bit_storage Support Wrapped Up
    Igalia's Jose Maria Casanova Crespo sent out a set of patches today for fixes that allow for the enabling of the VK_KHR_16bit_storage extension within Intel's ANV Vulkan driver. The patches are here for those interested in 16-bit storage support in Vulkan. This flips on the features for storageBuffer16BitAccess, uniformAndStorageBuffer16BitAccess, storagePushConstant16 and the VK_KHR_16bit_storage extension. This support is present for Intel "Gen 8" Broadwell graphics and newer. Hopefully the work will be landing in Mesa Git soon.
  • SPIR-V Support For Gallium3D's Clover Is Closer To Reality
    It's been a busy past week for open-source GPU compute with Intel opening up their new NEO OpenCL stack, Karol Herbst at Red Hat posting the latest on Nouveau NIR support for SPIR-V compute, and now longtime Nouveau contributor Pierre Moreau has presented his latest for SPIR-V Clover support. Pierre has been spending about the past year adding SPIR-V support to Gallium3D's "Clover" OpenCL state tracker. SPIR-V, of course, is the intermediate representation used now by OpenCL and Vulkan.

Security: Updates, Tinder, FUD and KPTI Meltdown Mitigation

  • Security updates for Friday
  • Tinder vulnerability let hackers [sic] take over accounts with just a phone number

    The attack worked by exploiting two separate vulnerabilities: one in Tinder and another in Facebook’s Account Kit system, which Tinder uses to manage logins. The Account Kit vulnerability exposed users’ access tokens (also called an “aks” token), making them accessible through a simple API request with an associated phone number.

  • PSA: Improperly Secured Linux Servers Targeted with Chaos Backdoor [Ed: Drama queen once again (second time in a week almost) compares compromised GNU/Linux boxes to "back doors"]
    Hackers are using SSH brute-force attacks to take over Linux systems secured with weak passwords and are deploying a backdoor named Chaos. Attacks with this malware have been spotted since June, last year. They have been recently documented and broken down in a GoSecure report.
  • Another Potential Performance Optimization For KPTI Meltdown Mitigation
    Now that the dust is beginning to settle around the Meltdown and Spectre mitigation techniques on the major operating systems, in the weeks and months ahead we are likely to see more performance optimizations come to help offset the performance penalties incurred by mitigations like kernel page table isolation (KPTI) and Retpolines. This week a new patch series was published that may help with KPTI performance.