<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:planet="http://planet.intertwingly.net/" xmlns:indexing="urn:atom-extension:indexing" indexing:index="no"><access:restriction xmlns:access="http://www.bloglines.com/about/specs/fac-1.0" relationship="deny"/>
  <title>We Make Fedora</title>
  <updated>2026-07-10T06:34:29Z</updated>
  <generator uri="http://intertwingly.net/code/venus/">Venus</generator>
  <author>
    <name>We Make Fedora</name>
    <email>devel@lists.fedoraproject.org</email>
  </author>
  <id>https://wemakefedora.org/atom.xml</id>
  <link href="https://wemakefedora.org/atom.xml" rel="self" type="application/atom+xml"/>
  <link href="https://wemakefedora.org/" rel="alternate"/>

  <entry>
    <id>https://www.jcline.org/blog/fedora/2026/07/09/flock-2026.html</id>
    <link href="https://www.jcline.org/blog/fedora/2026/07/09/flock-2026.html" rel="alternate" type="text/html"/>
    <title>Flock 2026</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Another Flock to Fedora conference has come and gone, and like last year, this one was held in Prague. Unlike last year, I was not in the middle of moving across the country (again) so I was able to attend, thanks to my employer.</p>

<p>As always, it was great to see so many familiar faces and meet new folks face-to-face. To those of you who weren’t able to make it, you were missed. And, as always, I spent a lot of time in the hallway track talking to people, getting a sense of what everyone was working on and interested in.</p>

<h2 id="day--1">Day -1</h2>

<p>The day before the conference started, there was a sponsorship dinner. Although Bex did all the work getting the paperwork to the correct people at Microsoft, he wasn’t able to make it to Prague in time for the dinner so I was sent. I arrived on Saturday morning after a quick connection through Dublin, which gave me plenty of time to get settled in and resist taking a nap. I spent the dinner chatting with Kevin Fenzi and Jef Spaleta, and while I can’t remember all the topics, curling was definitely mentioned.</p>

<h2 id="day-0">Day 0</h2>

<p>I volunteered to help at the check-in desk the morning of the first day, which I felt went very smoothly (the new label makers were a nice addition). It was nice to help out, but it was also a great way to match names I’ve seen on Matrix to faces as folks arrived. After my shift, I got sucked into the hallway track until lunch.</p>

<p>After lunch and a bit more hallway track, I went to the “PR-based Gating for Fedora: Can We Make It Work?” workshop from František Lachman. There was a lot of discussion in and around the Fedora contribution workflow which I have lots of thoughts about, but I felt there was a rather widespread desire to make things better (even if the <em>exact</em> way we do that isn’t clear). Lots of people who were not me brought up keeping the specfiles in one repository rather than forty thousand or however many git repositories we’re up to. In any case, I’d really like a nice pull request workflow for Fedora where I can’t mess up updates, and where we can all share the tooling we build around packaging.</p>

<p>I spent the rest of the day in the hallway track, doing some last minute preparations for my talk on signing, and preparing for the joint Microsoft talk with Reuben and Bex. I was happy to meet some of the Red Hat folks working on cryptography and signing, and I’m hopefully somewhere down the line we can all do approximately the same thing for signing content.</p>

<p>I got dinner with Bex and Reuben at some place that served North Carolina style BBQ, and it was pretty good (especially with kimchi on top!).</p>

<h2 id="day-1">Day 1</h2>

<p>This was the first day of recorded presentations. I went to the usual “State of Fedora” address, followed by the Fedora Council and FESCo panels. I thought it was interesting (but sadly unsurprising) to see downward trend of contributors, and I’d be interested to see a further breakdown of who’s leaving. I have plenty of not-backed-by-hard-data ideas about why this is happening, but I do hope it leads to a stronger focus on (and acceptance of) improving the contribution experience - the general feeling in the hallways, as I mentioned earlier, makes me somewhat optimistic.</p>

<p>After lunch and a bit of hallway track, I went to the “Secure by Design: Aligning Fedora with the EU Cyber Resilience Act (CRA)” workshop by Jaroslav Řezník and Roman Zhukov. A good portion of it was a run down of what the CRA entailed and how the roles it describes map into Fedora. After that I spent a bit of time preparing for my talk. <a href="https://youtu.be/ulz7AhNRQBE?t=7071">My talk</a> went well, I think, except the live demo didn’t entirely work (gpg2 + gpg-agent + gnupg-pkcs11-scd is very finicky and I forgot a setup step). With that stressful event out of the way, I was able to relax a bit at the dinner party, chat with numerous folks, and fill up on the “appetizers” they brought out in vast quantities. Big props to the event organizers, the weather was great and I really appreciated the open space and variety of food options.</p>

<h2 id="day-2">Day 2</h2>

<p>It was hard to believe it was already the final day of the conference, but I think at this point I was also feeling pretty worn out. I went to Justin’s “State of the Fedora Kernel” talk, and was glad to hear that the GitLab workflow I helped build before I left wasn’t absolutely terrible. I made some last minute edits to the slides for our “Two Years In: Accelerating Microsoft Contributions to Fedora” talk (where I was happy to have Bex and Reuben do most of the talking), then helped present that talk. Afterwards I went to the “What’s new in Fedora CoreOS” talk and managed to chat with Jean-Baptiste Trystram and Joel Capitao about signing and Konflux, which we’ll hopefully get sorted out in the next couple weeks (in the staging environment, anyway). Hopefully we’ll also be able to get Fedora CoreOS images into the Azure community gallery alongside the Cloud images.</p>

<p>The lightning talks were all enjoyable, and I’m really impressed some folks even managed to make up slides for theirs and nothing went terribly wrong (great work everyone). There was time for a bit more hallway track, and then I went to the Contributor Recognition Program, which concluded the presentations for Flock 2026. I spent the evening catching up with old and new friends, chatting about ideas on improving various bits of Fedora infrastructure, and how to make the contributor experience better. People were already leaving for DevConf (or home) at this point, so if I didn’t get a chance to say goodbye, I’m sorry and I hope we’ll see each other next year!</p>

<h2 id="day-3">Day 3</h2>

<p>It was an uneventful trip back home, thankfully.</p>

<p>I’m looking forward to put all the work I’ve done on improving Fedora’s signing infrastructure through its paces, to get support for PQC done, and I have a few ideas on what to work on next. Hopefully some of them work out and don’t lead to too many people screaming at me. Flock is a great event to get excited about the next year of work and to test the waters on wild ideas, so I’m really glad I was able to make it this year.</p></div>
    </summary>
    <updated>2026-07-09T16:14:00Z</updated>
    <published>2026-07-09T16:14:00Z</published>
    <category term="blog"/>
    <category term="fedora"/>
    <source>
      <id>https://www.jcline.org/</id>
      <author>
        <name>Jeremy Cline</name>
      </author>
      <link href="https://www.jcline.org/" rel="alternate" type="text/html"/>
      <link href="https://www.jcline.org/feed.xml" rel="self" type="application/rss+xml"/>
      <subtitle>Blog about various things open source</subtitle>
      <title>Jeremy Cline's Blog</title>
      <updated>2026-07-09T19:43:54Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://enotty.pipebreaker.pl/posts/2026/07/hdr-kodi-available-for-fedora/</id>
    <link href="https://enotty.pipebreaker.pl/posts/2026/07/hdr-kodi-available-for-fedora/" rel="alternate" type="text/html"/>
    <title>HDR Kodi available for Fedora</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>RPM Fusion shipped Kodi 22-beta1 for Fedora 44. This is the version
with <a class="reference external" href="https://github.com/xbmc/xbmc/pull/27069">PR adding HDR support under Wayland</a> merged.
It's a bit weird seing a beta version submitted as an update to stable branch, but hey, it works.
Thanks Leigh!</p>
<p>It works OK under GNOME session with HDR enabled. The UI elements are bit oversaturated
when playing High Dynamic Content, but the videos themselves are pretty. At last. This is
the year of HDR on Linux Desktop.</p>
<p>If only GeForce Now would catch up with the timesâ€¦</p>
<blockquote>
<p>068/100 of <a class="reference external" href="https://100daystooffload.com/">#100DaysToOffload</a></p>
</blockquote></div>
    </summary>
    <updated>2026-07-09T15:53:18Z</updated>
    <published>2026-07-09T15:53:18Z</published>
    <category term="100DaysToOffload"/>
    <category term="english"/>
    <author>
      <name>Tomasz Torcz</name>
    </author>
    <source>
      <id>https://enotty.pipebreaker.pl/</id>
      <link href="https://enotty.pipebreaker.pl/" rel="alternate" type="text/html"/>
      <link href="https://enotty.pipebreaker.pl/categories/english.xml" rel="self" type="application/rss+xml"/>
      <title>-ENOTTY (Posts about english)</title>
      <updated>2026-07-09T16:02:05Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>http://kparal.wordpress.com/?p=1748</id>
    <link href="https://kparal.wordpress.com/2026/07/09/heroes-of-fedora-quality-for-q2-2026/" rel="alternate" type="text/html"/>
    <title>Heroes of Fedora Quality for Q2 2026</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">The second quarter of 2026 is over, and so in this post we’d like to highlight the top Fedora Quality contributors who helped us maintain the quality bar for Fedora during this time period. Fedora wouldn’t be a high-quality distribution without its community. Every single person who helped us detect and resolve issues, or verify … <a class="more-link" href="https://kparal.wordpress.com/2026/07/09/heroes-of-fedora-quality-for-q2-2026/">Continue reading <span class="screen-reader-text">Heroes of Fedora Quality for Q2 2026</span> <span class="meta-nav">→</span></a></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">The second quarter of 2026 is over, and so in this post we’d like to <strong>highlight the top Fedora Quality contributors</strong> who helped us maintain the quality bar for Fedora during this time period. Fedora wouldn’t be a high-quality distribution without its community. Every single person who helped us detect and resolve issues, or verify that things work as expected, deserves our gratitude, thank you!</p>



<p class="wp-block-paragraph">If you haven’t participated yet in testing Fedora, perhaps you’d like to give it a try? We gladly welcome everyone. Please look at our <a href="https://fedoraproject.org/wiki/QA">Fedora Quality homepage</a>.</p>



<h2 class="wp-block-heading">Testing proposed updates <img alt="&#x11F;&#x178;&#x201C;&#xA6;" class="wp-smiley" src="https://s0.wp.com/wp-content/mu-plugins/wpcom-smileys/twemoji/2/72x72/1f4e6.png" style="height: 1em;"/></h2>



<p class="wp-block-paragraph">When software packages are updated in Fedora (bringing bug fixes and new features), they are not released to end users immediately. They first go to the <a href="https://fedoraproject.org/wiki/QA:Updates_Testing">updates-testing repository</a>, where they undergo automated testing, and also await manual feedback from human testers. This feedback can be provided through <a href="https://bodhi.fedoraproject.org/">Bodhi</a>, either by using its web interface or CLI tools, see <a href="https://fedoraproject.org/wiki/QA:Updates_Testing#What_to_test,_testing,_and_reporting_results">instructions</a>. Alerting package maintainers by posting a negative feedback with a problem description can stop the update from reaching general audience and causing issues to all our users. Testing proposed updates is a simple, yet vital process for keeping Fedora releases of high quality during their whole lifecycle. It is used both for already stable and in-development Fedora releases.</p>



<p class="wp-block-paragraph">Test period: <strong>Q2 2026</strong> (2026-04-01 – 2026-06-30)<br/>Contributors: <strong>408</strong><br/>Updates commented<sup>1</sup>: <strong>5103</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>Name</th><th>Updates commented</th></tr><tr><td><a href="https://fedoraproject.org/wiki/User:derekenz">Derek Enz (derekenz)</a></td><td>882</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:geraldosimiao">Geraldo S. SimiÃ£o Kutz (geraldosimiao)</a></td><td>811</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:filiperosset">Filipe Rosset (filiperosset)</a></td><td>437</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:besser82">besser82</a></td><td>287</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:bojan">bojan</a></td><td>263</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:nixuser">Ian Laurie (nixuser)</a></td><td>214</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:imabug">Eugene Mah (imabug)</a></td><td>187</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:anotheruser">anotheruser</a></td><td>129</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:g6avk">Colin Thomson (g6avk)</a></td><td>111</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:kparal">Kamil PÃ¡ral (kparal)</a></td><td>82</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:wasser19641">Wasser Mai (wasser19641)</a></td><td>68</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:ephmo">Ephraim Kaov (ephmo)</a></td><td>66</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:adamwill">Adam Williamson (adamwill)</a></td><td>63</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:markec">markec</a></td><td>62</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:ngompa">Neal Gompa (ngompa)</a></td><td>61</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:maketopsite">Joe Ant (maketopsite)</a></td><td>54</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:frantisekz">FrantiÅ¡ek Zatloukal (frantisekz)</a></td><td>48</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:salimma">Michel Lind (salimma)</a></td><td>30</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:ciupicri">Cristian Ciupitu (ciupicri)</a></td><td>27</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:bretth">brett h (bretth)</a></td><td>24</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:patchman">patchman</a></td><td>24</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:supakeen">Simon de Vlieger (supakeen)</a></td><td>24</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:agurenko">Alex Gurenko (agurenko)</a></td><td>23</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:niels-s">niels-s</a></td><td>23</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:farchord">Steve Cossette (farchord)</a></td><td>21</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:ankursinha">Ankur Sinha (ankursinha)</a></td><td>21</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:carlwgeorge">Carl George (carlwgeorge)</a></td><td>19</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:music">Benjamin Beasley (music)</a></td><td>17</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:itrymybest80">itrymybest80</a></td><td>17</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:decathorpe">Fabio Valentini (decathorpe)</a></td><td>17</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:johnh99">John Howard (johnh99)</a></td><td>16</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:gilwooden">Gilles Duboscq (gilwooden)</a></td><td>16</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:robatino">robatino</a></td><td>15</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:jrsanders">JR Sanders (jrsanders)</a></td><td>14</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:pawef10">Pawel Buzniak (pawef10)</a></td><td>13</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:dcavalca">Davide Cavalca (dcavalca)</a></td><td>13</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:pbrobinson">Peter Robinson (pbrobinson)</a></td><td>13</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:py0xc3">Christopher Klooz (py0xc3)</a></td><td>12</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:leoleovich">Oleg Obleukhov (leoleovich)</a></td><td>12</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:ppisar">Petr Pisar (ppisar)</a></td><td>12</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:thetick">Patty Berge (thetick)</a></td><td>11</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:lruzicka">LukÃ¡Å¡ RÅ¯Å¾iÄ�ka (lruzicka)</a></td><td>11</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:esoapw">Yixin Wei (esoapw)</a></td><td>11</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:hrw">Marcin Juszkiewicz (hrw)</a></td><td>11</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:rosti">rosti</a></td><td>11</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:bluca">Luca Boccassi (bluca)</a></td><td>10</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:vfedorenko">Vadim Fedorenko (vfedorenko)</a></td><td>10</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:lordalfredo">Daniel Anderson (lordalfredo)</a></td><td>10</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:churchyard">Miro HronÄ�ok (churchyard)</a></td><td>10</td></tr><tr><td><a href="https://fedoraproject.org/wiki/User:ellert">Mattias Ellert (ellert)</a></td><td>10</td></tr><tr><td colspan="2"><em>…and also 358 other testers who commented on less than 10 updates each, but 750 comments combined!</em></td></tr></tbody></table></figure>



<p class="has-dark-gray-color has-text-color has-link-color has-small-font-size wp-elements-932c2db77ccd9f836f115f5fa024c237 wp-block-paragraph"><sup>1</sup> If a person provides multiple comments to a single update, it is considered as a single comment. Karma value is not taken into account.</p>



<h2 class="wp-block-heading">Test days participation <img alt="&#x11F;&#x178;&#x201C;&#x2026;" class="wp-smiley" src="https://s0.wp.com/wp-content/mu-plugins/wpcom-smileys/twemoji/2/72x72/1f4c5.png" style="height: 1em;"/></h2>



<p class="wp-block-paragraph"><a href="https://fedoraproject.org/wiki/QA/Test_Days">Test Days</a> are events which are partly focused on testing <a href="https://fedoraproject.org/wiki/Changes">Changes</a> planned for an upcoming Fedora release, but they also regularly test important areas of the Fedora distribution, like upgrades, internationalization, graphical drivers, desktop environments, kernel updates, and others. The upcoming and past events can be seen in our <a href="https://testdays.fedoraproject.org/">Testdays app</a>.</p>



<p class="wp-block-paragraph">Test period: <strong>Q2 2026</strong> (2026-04-01 – 2026-06-30)<br/>Contributors: <strong>25</strong><br/>Test cases executed: <strong>76</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th><strong>Name</strong></th><th><strong>Test cases executed</strong></th></tr></thead><tbody><tr><td>nielsenb</td><td>10</td></tr><tr><td>clnetbox</td><td>6</td></tr><tr><td>imabug</td><td>6</td></tr><tr><td>nixuser</td><td>5</td></tr><tr><td>pauloheaven</td><td>5</td></tr><tr><td>guiltydoggy</td><td>5</td></tr><tr><td>adriend</td><td>4</td></tr><tr><td>g6avk</td><td>4</td></tr><tr><td>anotheruser</td><td>4</td></tr><tr><td>bittin</td><td>3</td></tr><tr><td>psklenar</td><td>3</td></tr><tr><td>agurenko</td><td>2</td></tr><tr><td>bretth</td><td>2</td></tr><tr><td>derekenz</td><td>2</td></tr><tr><td>augenauf</td><td>2</td></tr><tr><td>geraldosimiao</td><td>2</td></tr><tr><td>luya</td><td>2</td></tr><tr><td>py0xc3</td><td>2</td></tr><tr><td>boniboyblue</td><td>1</td></tr><tr><td>itrymybest80</td><td>1</td></tr><tr><td>jgroman</td><td>1</td></tr><tr><td>kurtlindberg</td><td>1</td></tr><tr><td>g4ridwan</td><td>1</td></tr><tr><td>farel</td><td>1</td></tr><tr><td>pstourac</td><td>1</td></tr></tbody></table></figure>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>We sincerely thank all contributors!</strong><img alt="&#x11F;&#x178;&#xFFFD;&#x2026;" class="wp-smiley" src="https://s0.wp.com/wp-content/mu-plugins/wpcom-smileys/twemoji/2/72x72/1f3c5.png" style="height: 1em;"/></p>



<p class="wp-block-paragraph">Are you also interested to help? Please look at our <a href="https://fedoraproject.org/wiki/QA">Fedora Quality homepage</a>.</p></div>
    </content>
    <updated>2026-07-09T13:32:32Z</updated>
    <published>2026-07-09T13:32:32Z</published>
    <category term="Fedora Planet"/>
    <category term="Fedora QA"/>
    <category term="Fedora Quality Planet"/>
    <category term="Heroes of Fedora testing"/>
    <author>
      <name>Kamil Páral</name>
    </author>
    <source>
      <id>https://kparal.wordpress.com</id>
      <logo>https://s2.wp.com/i/webclip.png</logo>
      <link href="https://kparal.wordpress.com/category/fedora-planet/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://kparal.wordpress.com" rel="alternate" type="text/html"/>
      <link href="https://kparal.wordpress.com/osd.xml" rel="search" title="Kparal's Fedora Blog" type="application/opensearchdescription+xml"/>
      <link href="https://kparal.wordpress.com/?pushpress=hub" rel="hub" type="text/html"/>
      <subtitle>The world of Fedoras</subtitle>
      <title>Fedora Planet – Kparal's Fedora Blog</title>
      <updated>2026-07-09T13:32:32Z</updated>
    </source>
  </entry>

  <entry>
    <id>http://frostyx.cz/posts/fedora-package-review-process-reimagined</id>
    <link href="http://frostyx.cz/posts/fedora-package-review-process-reimagined" rel="alternate" type="text/html"/>
    <title>Fedora Package Review Process reimagined</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>The <a href="https://docs.fedoraproject.org/en-US/package-maintainers/Package_Review_Process/">Fedora Package Review Process</a> is clunky, archaic,
and not on par with what we expect when contributing to Open Source projects in
this century. We all know that, and we all want it to improve. That being said,
we need to realize what is currently our main bottleneck. Even though the
process is not friendly to new contributors, they are doing just fine - at all
times, <a href="https://fedoraproject.org/PackageReviewStatus/reviewable.html">we have hundreds of new packages in the queue</a>. Our biggest
problem is our inability to effectively review them.</p>

<p>I don’t think we talk about this problem enough. That’s why it felt so
validating to hear <a href="https://github.com/hroncok">Miro Hrončok</a> voice my exact thoughts during the
<a href="https://frostyx.cz/posts/flock-to-fedora-report-2026">Flock to Fedora 2026</a> keynote.</p>

<p>In this blog post, I am going to elaborate on the ideas that we (mostly Miro)
came up with, shooting shit in the hallway after the session.</p>

<h2 id="proposing-new-packages-through-prs">Proposing new packages through PRs</h2>

<p>This is an obvious one, we talked about the same idea with
<a href="https://fedoraproject.org/wiki/User:Zbyszek">Zbigniew Jędrzejewski-Szmek</a> at <a href="https://frostyx.cz/posts/flock-to-fedora-report-2025">Flock to Fedora 2025</a>. It
is a necessary prerequisite for any potential improvements, which will allow us
to have a workflow that contributors are familiar with, inline code comments,
CI/CD, and other things that are not possible in Bugzilla.</p>

<p>Proposing new packages through PRs would be trivial to implement if we
had all Fedora packages in a monorepo. Which we don’t, and we probably
don’t want to have. And even if we wanted to have, it would require
massive changes throughout the ecosystem.</p>

<p>As a workaround, we discussed having an intermediate repository on the
<a href="https://forge.fedoraproject.org/">forge.fedoraproject.org</a> into which we would only propose new
packages. It would have <a href="https://communityblog.fedoraproject.org/packit-as-fedora-dist-git-ci-final-phase/">Packit CI</a> enabled, and therefore every
proposed package would automatically get a scratch build and a test suite run on
top of it. Currently
<a href="https://github.com/packit/tmt-plans/tree/main/tests">supported tests are rpmlint, rpminspect, and license-validate</a>.
We know that adding new tests is easy, as I am currently working on support for
<a href="https://github.com/packit/tmt-plans/tree/main/tests/fedora-review">fedora-review</a>.</p>

<p>Of course, a final approval from a fellow package maintainer would still be
needed. Once accepted, we would merge the PR and automatically create a new
DistGit repository and import the package. Then we would delete all data from
the intermediate repository to keep it clean.</p>

<h2 id="bulk-review">Bulk review</h2>

<p>The review queue is and always has been in hundreds. Many of the packages are
dependencies for something else, and people have no motivation to review them
separately. And even if they do, it’s not always easy to test them on their
own. This currently leads to accepting broken packages that nobody tested or
ignoring the tickets completely.</p>

<p>We discussed the possibility of proposing multiple packages within one PR. They
could be reviewed, tested, and accepted all at once.</p>

<p>For such PRs, we could automatically create a new project in Copr and build the
packages in the order they were committed. We could nicely use
<a href="https://docs.copr.fedorainfracloud.org/user_documentation.html#build-batches">Copr’s build batches feature</a> here. If multiple packages were
added in one commit, they could be built in parallel. If the contributor decides
to force-push into their PR, we would wipe the Copr project and start over.</p>

<h2 id="auto-import-into-distgit">Auto import into DistGit</h2>

<p>There is no reason why the contributor would have to manually run</p>

<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code>fedpkg request-repo my-package 12345
fedpkg request-branch <span class="nt">--all-releases</span>

fedpkg clone foo
<span class="nb">cd </span>foo
fedpkg import /path/to/the/foo.src.rpm
fedpkg push
fedpkg build

fedpkg switch-branch f44
git rebase rawhide
fedpkg push
fedpkg build
<span class="c"># ...</span>
<span class="c"># repeat for f43, f42, etc</span>
</code></pre></div></div>

<p>We can request all the DistGit repositories and branches for them. And once they
are created, we can automatically import the packages. There are some open
questions though. How can the contributor signalize what branches they want?
Should we use the git history from the PR? Can we use Forgejo actions to trigger
the requests and imports?</p>

<h2 id="proposal-vs-prototype">Proposal vs prototype</h2>

<p>I realize this is not a formal proposal but merely a blog post on my personal
website. That was an intentional decision. We’ve been discussing and
bike-shedding this topic for years, and yet we don’t have much to show for it. I
am writing this article mainly not to forget the ideas we’ve had, and even
though I am interested in your thoughts, this is not an RFC. I already started
implementing a prototype, and soon I’ll record a demo for you. Then, I’ll start
bothering you and asking for feedback.</p>

<p>In my opinion, it doesn’t have to be perfect. We just need to kick this off,
implement something small that works, and improve it as time goes.</p>

<p>Maybe I should also say that I am not aiming to replace the current
<a href="https://docs.fedoraproject.org/en-US/package-maintainers/Package_Review_Process/">Package Review Process</a>. My goal is to provide an
alternative version of this process and allow contributors to choose which one
they want to follow. Then, someday in the future, if the alternative turns out
to be popular, possibly deprecating the old review process.</p></div>
    </summary>
    <updated>2026-07-07T00:00:00Z</updated>
    <published>2026-07-07T00:00:00Z</published>
    <source>
      <id>http://frostyx.cz</id>
      <author>
        <name>Jakub Kadlčík</name>
      </author>
      <link href="http://frostyx.cz" rel="alternate" type="text/html"/>
      <link href="http://frostyx.cz/fedora.xml" rel="self" type="application/rss+xml"/>
      <subtitle>Personal blog of Jakub Kadlčík (aka FrostyX)</subtitle>
      <title>FrostyX's blog - Fedora articles</title>
      <updated>2026-07-08T20:02:01Z</updated>
    </source>
  </entry>

  <entry>
    <id>http://eng.hroncok.cz/2026/07/07/ai-tool</id>
    <link href="http://eng.hroncok.cz/2026/07/07/ai-tool" rel="alternate" type="text/html"/>
    <title>I am not a tool</title>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>I work at Red Hat in the <a href="https://fedoraproject.org/wiki/User:Python-maint">Python Maintenance team</a> mostly taking care of the <a href="https://fedoralovespython.org/">Python ecosystem in Fedora</a>.
For the past year or so, I’ve been <a href="https://www.theregister.com/software/2026/03/31/memo-red-hat-global-engineering-plans-to-lean-in-to-ai/5221432"><em>motivated</em> by my employer to use agentic AI to deliver my work</a>.
Clearly, <a href="https://michel-slm.name/posts/2026-03-24-my-name-is-michel-and-i-use-llms/">we are not the only ones</a>.</p>

<p>At the beginning, I struggled to find reasonable use cases for this tool.
I maintain software, which involves a lot more communication and coordination than actually writing code.
When people ask me what I do, I often half-jokingly reply that I read and write a lot of emails.
How can AI <a href="https://andrewmurphy.io/blog/if-you-thought-the-speed-of-writing-code-was-your-problem-you-have-bigger-problems">boost my productivity</a> when I spend 80% of my time essentially talking to people?
Where is the fun in replacing the remaining 20% of actually <a href="https://writings.hongminhee.org/2026/03/craft-alienation-llm/">crafting code</a> with more talking, this time to half-competent robots?</p>

<p>In time, I found ways to use AI that felt productive.
And, ever so hypocritically, not only at work.
But at what cost?
I am supporting an industry that regularly <a href="https://hachyderm.io/@jzb/116833616723978137">harms open source projects such as Fedora</a>, helps destroy the planet and uses stolen data.
Moreover, I’ve become reliant on a proprietary tool.
Is my AI-boosted contribution to Fedora worth it?</p>

<p>Despite my moral dilemma, I still love my job.
I am a long-standing, well-known Fedora contributor, working for the most part on whatever I feel is needed, earning a competitive salary.
In theory, I could go look for another job where I would not be <em>motivated</em> to do this, but I wouldn’t be able to keep doing the thing I love.
I try to make the best out of this situation and, despite my initial distaste, use the tool to improve the project.
So at the end of the day, I close my eyes and think of Fedora<sup id="fnref:1"><a class="footnote" href="https://eng.hroncok.cz/atom.fedora.xml#fn:1" rel="footnote">1</a></sup>.</p>

<p>However, the implications of embracing AI are not just impacting me.
The nature of my work means I’ve made hundreds (thousands?) of small open source contributions here and there.
And sometimes, when I use AI to deliver those, it kinda feels like bringing a chunk of meat to a vegan BBQ.
The people on the receiving end of my contribution for the most part don’t care about my job sustainability or IBM shareholders, nor should they.</p>

<p>Once, I used AI to contribute to a Fedora packaging project.
It was reluctantly reviewed by another long-standing, well-known Fedora contributor (who happens not to be employed by Red Hat and is <em>not</em> well-compensated for this work).
When talking to them, I realized that they were uncomfortable reviewing such a change.
<em>I</em> made them uncomfortable by <em>choosing</em> to use AI for this.
My employer made me uncomfortable; <em>I passed it on to a volunteer</em>.
What an outstanding open source citizen.</p>

<p>I appreciate the irony of this; and yet, I am no slop generator.
I understand what I submit and I put my name on it.
I disclose the usage for transparency, because it matters.
I don’t just drop a vibecoded patch on an open source project.
If you have an AI policy, I read it and respect it.
So it pains me deeply when our carefully considered contributions are outright branded AI slop or LLM hallucinations, and the person bringing them is evaluated solely on the basis of the tool they used.
Especially when such judgment is made by people I respect<sup id="fnref:2"><a class="footnote" href="https://eng.hroncok.cz/atom.fedora.xml#fn:2" rel="footnote">2</a></sup>.</p>

<p><strong>No, I am not a tool. Please don’t treat me as such.</strong></p>

<hr/>

<p>PS On a lighter note, here are some examples of AI usage that somehow eliminate this problem for me:</p>

<ul>
  <li><strong>Debugging a problem</strong> — in our team we’ve been very successful in showing a failing test to Claude and telling it that it started failing with Python 3.15. While burning thousands of tokens and wasting gallons of drinking water it can usually successfully determine what caused the failure. We were able to determine this ourselves in the past, but this actually boosted our productivity. We can then report the problem to upstream after we have verified the find.</li>
  <li>My own/my team’s semi-<strong>internal tooling</strong> —<sup id="fnref:3"><a class="footnote" href="https://eng.hroncok.cz/atom.fedora.xml#fn:3" rel="footnote">3</a></sup> the omnipresent bunch of random scripts I am not proud of and which would desperately need a rewrite but ain’t nobody got time for that. Just slop ‘em. If it works, it works. If it doesn’t, roll-back. Nobody needs to see this code anyway. Excellent for AI — I am still kinda killing the planet but at least I don’t shove it in your face.</li>
  <li><strong>Reporting to management</strong> — somehow people keep asking me what I did. There’s no dilemma in providing AI-generated reports to the same people who asked me to use AI. If nothing else, it demonstrates how progressive I am with it.</li>
  <li><strong>Reviews for me</strong> — when I don’t use AI to generate code, but rather ask it to review my design and implementation, nobody is forced to deal with my AI usage. For example, I wrote this blogpost myself, <em>then</em> asked AI for feedback on typos, grammar, tone, voice, argument, rhetoric, structure, flow…<sup id="fnref:4"><a class="footnote" href="https://eng.hroncok.cz/atom.fedora.xml#fn:4" rel="footnote">4</a></sup></li>
</ul>

<div class="footnotes">
  <ol>
    <li id="fn:1">
      <p>And perhaps even more so, my mortgage and the food on my table. <a class="reversefootnote" href="https://eng.hroncok.cz/atom.fedora.xml#fnref:1">↩</a></p>
    </li>
    <li id="fn:2">
      <p>And precisely because of that I choose to not link those cases here. This is not about naming and shaming. <a class="reversefootnote" href="https://eng.hroncok.cz/atom.fedora.xml#fnref:2">↩</a></p>
    </li>
    <li id="fn:3">
      <p>This m-dash was copy-pasted from websearch results by a human. <a class="reversefootnote" href="https://eng.hroncok.cz/atom.fedora.xml#fnref:3">↩</a></p>
    </li>
    <li id="fn:4">
      <p>If nothing else, at least the model pretends it appreciates my sarcasm. <a class="reversefootnote" href="https://eng.hroncok.cz/atom.fedora.xml#fnref:4">↩</a></p>
    </li>
  </ol>
</div></div>
    </content>
    <updated>2026-07-07T00:00:00Z</updated>
    <source>
      <id>http://eng.hroncok.cz</id>
      <author>
        <name>Miro Hrončok</name>
        <email>miro@hroncok.cz</email>
      </author>
      <link href="http://eng.hroncok.cz/" rel="self" type="application/atom+xml"/>
      <link href="http://eng.hroncok.cz" rel="alternate" type="text/html"/>
      <title>Miro Hrončok</title>
      <updated>2026-07-08T12:35:43Z</updated>
    </source>
  </entry>

  <entry>
    <id>https://mjg59.dreamwidth.org/74260.html</id>
    <link href="https://mjg59.dreamwidth.org/74260.html" rel="alternate" type="text/html"/>
    <title>My blog has moved</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">A reminder that I am no longer here, but am instead <a href="https://codon.org.uk/~mjg59/blog">here</a>. The new RSS feed is <a href="https://www.codon.org.uk/~mjg59/blog/index.xml">here</a>. If you're still reading this for some reason other than being on Dreamwidth, please update your feed.<br/><br/><img alt="comment count unavailable" height="12" src="https://www.dreamwidth.org/tools/commentcount?user=mjg59&amp;ditemid=74260" style="vertical-align: middle;" width="30"/> comments</div>
    </summary>
    <updated>2026-07-06T09:03:04Z</updated>
    <published>2026-07-06T09:03:04Z</published>
    <category term="fedora"/>
    <category term="advogato"/>
    <source>
      <id>https://mjg59.dreamwidth.org/</id>
      <author>
        <name>Matthew Garrett</name>
      </author>
      <link href="https://mjg59.dreamwidth.org/" rel="alternate" type="text/html"/>
      <link href="http://www.dreamwidth.org/users/mjg59/data/rss/" rel="self" type="application/rss+xml"/>
      <subtitle>Matthew Garrett - Dreamwidth Studios</subtitle>
      <title>Matthew Garrett</title>
      <updated>2026-07-06T09:03:04Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://www.scrye.com/blogs/nirik/posts/2026/07/04/misc-fedora-bits-start-of-july-2026/</id>
    <link href="https://www.scrye.com/blogs/nirik/posts/2026/07/04/misc-fedora-bits-start-of-july-2026/" rel="alternate" type="text/html"/>
    <title xml:lang="en">misc fedora bits: start of july 2026</title>
    <summary type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>"Today's the fourth of july.
Another june has gone by."</p>
<p>(appologies to Amiee Mann).</p>
<p>Here's another short recap of the last week from me.
I was off Thursday, and Friday was a holiday, and I'm off next monday too,
so this was a short week.</p>
<section id="aarch64-builders-and-vmhosts-reinstalls">
<h2>aarch64 builders and vmhosts reinstalls</h2>
<p>I spend a bit of time reinstalling our aarch64 bvmhosts. These are the
machines that run all our buildvm-a64 instances. You would think this would
be a trivial task, but of course not.</p>
<p>When we got these machines as part of the datacenter move last year,
we couldn't get them to pxe boot from their 25G network. So, we ended
up patching some 1G connections to them to provision them. Then those
links were removed. So, I needed to fix the issue this time.</p>
<p>Turned out it was just some settings in the network card eeprom/settings.
To adjust it, I had to build a kernel module, load that, then poke
at the settings with a tool. Quite a pain, but luckily only a one
time thing.</p>
<p>After that, they pxe booted fine and were easy to reprovison with rhel10.
Except, then I hit the next thing: One of them had a bad memory stick
in it. We had hit this before, but after reseating all the memory
it came up ok, but that memory just decided to croak this time.</p>
<p>So, dc operations folks did a bunch of testing and isolated the bad
memory. Should be on the way in to get a replacement now. Until
the replacement arrives that machine is down memory, so a few buildvm's
on it are shutdown. Shouldn't matter too much.</p>
</section>
<section id="staging-openshift-workers-network">
<h2>Staging openshift workers network</h2>
<p>Last week we moved a number of servers to balance power in racks.
That went fine, but networking folks noticed that 3 of the machines
were not properly using 802.3ad/lacp. That is, they were only connected
on one interface. These machines were our staging openshift workers.</p>
<p>It took me quite a lot of poking around to see what happened and how to fix it.
Openshift has a lot of ways it configures network and it was not clear at all to
me the flow. I did finally figure it out though: I had installed them with
net.ifnames=0 set. This meant they had eth2 and eth3 interfaces that were the
active ones. After the install, they booted without that and so the interface
names changed. The new ones didn't have any config, so it just picked the
first one and ran it's ovh setup on. So, I had to go in and setup NetworkManager
to know about the new interface names so it would bond them, then the openshift
setup script would just take that bond device and setup on it.</p>
<p>I wish openshift made it easier to tweak this.</p>
<p>Off on monday, see everyone tuesday!</p>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116863452466227942">https://fosstodon.org/@nirik/116863452466227942</a></p>
</section></div>
    </summary>
    <content type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>"Today's the fourth of july.
Another june has gone by."</p>
<p>(appologies to Amiee Mann).</p>
<p>Here's another short recap of the last week from me.
I was off Thursday, and Friday was a holiday, and I'm off next monday too,
so this was a short week.</p>
<section id="aarch64-builders-and-vmhosts-reinstalls">
<h2>aarch64 builders and vmhosts reinstalls</h2>
<p>I spend a bit of time reinstalling our aarch64 bvmhosts. These are the
machines that run all our buildvm-a64 instances. You would think this would
be a trivial task, but of course not.</p>
<p>When we got these machines as part of the datacenter move last year,
we couldn't get them to pxe boot from their 25G network. So, we ended
up patching some 1G connections to them to provision them. Then those
links were removed. So, I needed to fix the issue this time.</p>
<p>Turned out it was just some settings in the network card eeprom/settings.
To adjust it, I had to build a kernel module, load that, then poke
at the settings with a tool. Quite a pain, but luckily only a one
time thing.</p>
<p>After that, they pxe booted fine and were easy to reprovison with rhel10.
Except, then I hit the next thing: One of them had a bad memory stick
in it. We had hit this before, but after reseating all the memory
it came up ok, but that memory just decided to croak this time.</p>
<p>So, dc operations folks did a bunch of testing and isolated the bad
memory. Should be on the way in to get a replacement now. Until
the replacement arrives that machine is down memory, so a few buildvm's
on it are shutdown. Shouldn't matter too much.</p>
</section>
<section id="staging-openshift-workers-network">
<h2>Staging openshift workers network</h2>
<p>Last week we moved a number of servers to balance power in racks.
That went fine, but networking folks noticed that 3 of the machines
were not properly using 802.3ad/lacp. That is, they were only connected
on one interface. These machines were our staging openshift workers.</p>
<p>It took me quite a lot of poking around to see what happened and how to fix it.
Openshift has a lot of ways it configures network and it was not clear at all to
me the flow. I did finally figure it out though: I had installed them with
net.ifnames=0 set. This meant they had eth2 and eth3 interfaces that were the
active ones. After the install, they booted without that and so the interface
names changed. The new ones didn't have any config, so it just picked the
first one and ran it's ovh setup on. So, I had to go in and setup NetworkManager
to know about the new interface names so it would bond them, then the openshift
setup script would just take that bond device and setup on it.</p>
<p>I wish openshift made it easier to tweak this.</p>
<p>Off on monday, see everyone tuesday!</p>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116863452466227942">https://fosstodon.org/@nirik/116863452466227942</a></p>
</section></div>
    </content>
    <updated>2026-07-04T19:35:58Z</updated>
    <published>2026-07-04T19:35:58Z</published>
    <category label="fedora" term="fedora"/>
    <category label="linux" term="linux"/>
    <author>
      <name>nirik</name>
    </author>
    <source>
      <id>https://www.scrye.com/blogs/nirik/categories/fedora.atom</id>
      <author>
        <name>nirik</name>
      </author>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora.atom" rel="self" type="application/atom+xml"/>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora/" rel="alternate" type="text/html"/>
      <title xml:lang="en">Kevin's musings (Posts about fedora)</title>
      <updated>2026-07-04T19:53:19Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://communityblog.fedoraproject.org/?p=15837</id>
    <link href="https://communityblog.fedoraproject.org/community-update-week-27/" rel="alternate" type="text/html"/>
    <title>Community Update – Week 27</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>This is a report created by CLE Team, which is a team containing community members working in various Fedora groups for example Infrastructure, Release Engineering, Quality etc. This team is also moving forward some initiatives inside Fedora project. Week: 29 June – 3 July 2026 Fedora Infrastructure This team is taking care of day to […]</p>
<p>The post <a href="https://communityblog.fedoraproject.org/community-update-week-27/">Community Update – Week 27</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">This is a report created by <a href="https://docs.fedoraproject.org/en-US/cle/">CLE Team</a>, which is a team containing community members working in various Fedora groups for example Infrastructure, Release Engineering, Quality etc. This team is also moving forward some initiatives inside Fedora project.</p>



<p class="wp-block-paragraph">Week: 29 June – 3 July 2026</p>



<h2 class="wp-block-heading">Fedora Infrastructure</h2>



<p class="wp-block-paragraph">This team is taking care of day to day business regarding Fedora Infrastructure.<br/>It’s responsible for services running in Fedora infrastructure.<br/><a href="https://pagure.io/fedora-infrastructure/issues">Ticket tracker</a></p>



<ul class="wp-block-list">
<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/13431">Planned Outage – download-ib01, torrent, people outage – 2026-06-25 20:00 UTC</a></li>



<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/13419">Planned Outage – server moves – 2026-06-25 14:00 UTC</a></li>



<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/11884">RFE: Add a role for deploying through OpenShift deployment</a></li>



<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/13314">rhel10: colo_virt virthosts</a></li>



<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/13139">Migrate ELNBuildSync to Fedora Infrastructure OpenShift</a></li>
</ul>



<h2 class="wp-block-heading">CentOS Infra including CentOS CI</h2>



<p class="wp-block-paragraph">This team is taking care of day to day business regarding CentOS Infrastructure and CentOS Stream Infrastructure.<br/>It’s responsible for services running in CentOS Infrastructure and CentOS Stream.<br/><a href="https://gitlab.com/CentOS/infra/tracker/-/issues">CentOS ticket tracker</a><br/><a href="https://issues.redhat.com/projects/CS/issues/CS-3206?filter=allopenissues">CentOS Stream ticket tracker</a></p>



<ul class="wp-block-list">
<li><a href="https://redhat.atlassian.net/browse/CS-3414">Deploy staging el10 signing host for Stream to validate worfklow</a></li>



<li><a href="https://redhat.atlassian.net/browse/CS-3413">Rebuild all needed pkgs for el10 signing service</a></li>



<li><a href="https://redhat.atlassian.net/browse/CS-3367">all s390 builders for Stream are unreachable (blocking all rpm build tasks)</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1947">abuse on website</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1945">Init new donated/sponsored server for CentOS infra</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1943">Update Firmware in Risc-V P550’s</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1942">mirror.dsp-lad.space add to mirror list</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1940">Automotive SIG – key rotation</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1938">Change AltImage documentation to use gitlab.com repo</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1936">Update boot-server ansible role for el10</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1935">Renew our yearly RH subscription for CDN access</a></li>



<li><a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1903">migrate status.centos.org to el10</a></li>
</ul>



<h2 class="wp-block-heading">Release Engineering</h2>



<p class="wp-block-paragraph">This team is taking care of day to day business regarding Fedora releases.<br/>It’s responsible for releases, retirement process of packages and package builds.<br/><a href="https://pagure.io/releng/issues">Ticket tracker</a></p>



<ul class="wp-block-list">
<li>Continued <a href="https://codeberg.org/fedora/oci-image-definitions/pulls/59">investigation</a> into building a Fedora container base image using Konflux.</li>



<li>Continued work on remaining Pagure -&gt; Forgejo migrations.</li>



<li>F45 release cycle is set to begin soon, starting with Mass Rebuild in the middle of July. This will require some prep work next week.</li>
</ul>



<h2 class="wp-block-heading">RISC-V</h2>



<p class="wp-block-paragraph">This is the summary of the work done regarding the RISC-V architecture in Fedora.</p>



<ul class="wp-block-list">
<li>Discussion with Scaleway (a cloud vendor in France) for potential Fedora Koji builders in their Paris datacenter.  To be coordinated via RISE.</li>



<li>Hardware
<ul class="wp-block-list">
<li>Coordinated shipping another “K3” hardware to DavidA (one of the Fedora RISC-V maintainers). This will be used as another RISC-V Koji builder.  Sponsored by CLE.</li>



<li>Milk-V Titan hardware is now available to buy.  A handful of machines are being shipped to a couple of  RISC-V engineers, including for Fedora use.</li>
</ul>
</li>



<li>Community work
<ul class="wp-block-list">
<li>Fedora Omni kernels for Muse Pi Pro hardware discussion with Trevor from Baylibre and Jason (Fedora RISC-V kernel)</li>



<li>Marcin (hrw) Juszkiewicz continues to chip away at the Fedora RISC-V tracker</li>



<li>Fedora Omni kernel work continues, with support for Muse Pi Pro, K3, and more: Jason Montleon and Jennifer Berringer</li>
</ul>
</li>



<li>Other:
<ul class="wp-block-list">
<li>Discussions on ‘fedora-devel’: <em>“How can we improve the Changes Process?”</em> thread</li>



<li>A lot of internal discussion about 2FA for packagers</li>



<li>Several internal  and upstreams meetings</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading">AI</h2>



<p class="wp-block-paragraph">This is the summary of the work done regarding AI in Fedora.</p>



<ul class="wp-block-list">
<li>Aurelien Bompard improved the This Week in Fedora script to include the CLE status reports</li>
</ul>



<h2 class="wp-block-heading">QE</h2>



<p class="wp-block-paragraph">This team is taking care of quality of Fedora. Maintaining CI, organizing test days<br/>and keeping an eye on overall quality of Fedora releases.</p>



<ul class="wp-block-list">
<li>Lots of PTO: psklenar on extended PTO, kparal and adamwill each took some post-travel PTO days. Also post-event travel, bureaucracy (trip and expense reports) and decompression cut into work time for most</li>



<li>Compose-critical package script now in MVP state – see <a href="https://forge.fedoraproject.org/releng/tooling/pulls/13039">pull request</a>, it works and does useful stuff but needs more refinement</li>



<li><a href="https://forge.fedoraproject.org/quality/fedora_openqa/src/branch/schedule-distgit-prs">Dist-git PR test feature</a> progress: status report now works, still needs polish and tests</li>



<li>Tool work: <a href="https://forge.fedoraproject.org/quality/blockerbugs/pulls/319">CI optimization in blockerbugs</a>, <a href="https://forge.fedoraproject.org/quality/testdays-web/pulls/126">reverse proxy handling improvement</a> in testdays-web</li>



<li>Significant bug investigations: <a href="https://bugzilla.redhat.com/show_bug.cgi?id=2492140">grub2 changes broke image builds</a>, <a href="https://bugzilla.redhat.com/show_bug.cgi?id=2491739">haveged update could cause boot failure</a></li>
</ul>



<h2 class="wp-block-heading">Forgejo</h2>



<p class="wp-block-paragraph">This team is working on introduction of https://forge.fedoraproject.org to Fedora<br/>and migration of repositories from pagure.io.</p>



<ul class="wp-block-list">
<li>Forge 15.0.3 in staging</li>



<li>New runner for koji organization</li>



<li>Continued work on Private Issues: <a href="https://forge.fedoraproject.org/forge/forge/issues/594">public/private comments</a></li>



<li>Zabbix template developed to monitor health of runnerhost VM, moving onto the  forge instance next.</li>
</ul>



<h2 class="wp-block-heading">EPEL</h2>



<p class="wp-block-paragraph">This team is working on keeping <a href="https://docs.fedoraproject.org/en-US/epel/epel-about/">Epel</a> running and helping package things.</p>



<ul class="wp-block-list">
<li>Updated caddy in f44, f43, epel10.3, and epel10.2 resolving 22 CVEs</li>



<li>EPEL 11 planning discussions</li>
</ul>



<h2 class="wp-block-heading">UX</h2>



<p class="wp-block-paragraph">This team is working on improving User experience. Providing artwork, user experience,<br/>usability, and general design services to the Fedora project</p>



<ul class="wp-block-list">
<li>Open Call for Fedora Event Video Footage! [<a href="https://discussion.fedoraproject.org/t/open-call-for-fedora-event-video-footage/195184">discussions post</a>]</li>



<li>Feedback period for F45 wallpaper has just ended. <a href="https://forge.fedoraproject.org/design/tickets/issues/24#issuecomment-870347">Here</a> is the current iteration.</li>
</ul>



<p class="wp-block-paragraph">If you have any questions or feedback, please respond to this report or contact us on #admin:fedoraproject.org channel on <a href="https://matrix.to/#/#admin:fedoraproject.org:matrix.org">matrix</a>.</p>
<p>The post <a href="https://communityblog.fedoraproject.org/community-update-week-27/">Community Update – Week 27</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </content>
    <updated>2026-07-03T11:00:00Z</updated>
    <published>2026-07-03T11:00:00Z</published>
    <category term="Fedora Project Community"/>
    <category term="Community update"/>
    <author>
      <name>lenkaseg</name>
    </author>
    <source>
      <id>https://communityblog.fedoraproject.org/</id>
      <logo>https://communityblog.fedoraproject.org/wp-content/uploads/2022/07/favicon-fedora-commblog.png</logo>
      <link href="https://communityblog.fedoraproject.org/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://communityblog.fedoraproject.org/" rel="alternate" type="text/html"/>
      <subtitle>The Community Blog provides a single source for members of the community to share important news, updates, and information about Fedora with others in the Project community.</subtitle>
      <title>Fedora Community Blog</title>
      <updated>2026-07-03T10:34:22Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>urn:md5:ab8ae3e708dae714d684bb07793f6e31</id>
    <link href="https://blog.remirepo.net/post/2026/07/03/PHP-8.6-as-Software-Collection" rel="alternate" type="text/html"/>
    <title>🎲 PHP 8.6 as Software Collection</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Version <a href="https://www.php.net/archive/2026.php#2026-07-02-3">8.6.0alpha1</a> has been released. It's still in development and will soon enter the stabilization phase for the developers and the test phase for the users (see the <a href="https://wiki.php.net/todo/php86">schedule</a>).</p>

<p>The RPMs of this upcoming new version of <strong>PHP 8.6</strong>, are available in <strong>remi</strong> repository for <strong>Fedora</strong> ≥ 43 and <strong>Enterprise Linux</strong> ≥ 8 (RHEL, CentOS, Alma, Rocky...) in a fresh new <a href="https://www.softwarecollections.org/"><em>Software Collection</em></a> (<strong>php86</strong>) allowing its installation beside the system version.</p> <p>As I (still) strongly believe in SCL's potential to provide a simple way to allow installation of various versions simultaneously, and as I think it is useful to offer this feature to allow developers to test their applications, to allow sysadmin to prepare a migration or simply to use this version for some specific application, I decide to create this new SCL.</p>

<p>I also plan to propose this new version as a <strong>Fedora </strong><strong>46</strong> change (as F45 should be released a few weeks before PHP 8.6.0).</p>

<p><strong>Installation</strong> :</p>

<pre>yum install php86</pre>

<p>⚠️ To be noticed:</p>

<ul>
	<li>the SCL is independent from the system and doesn't alter it</li>
	<li>this SCL is available in <strong>remi-safe</strong> repository (or remi for Fedora)</li>
	<li>installation is under the<strong> /opt/remi/php86</strong> tree, configuration under the <strong>/etc/opt/remi/php86</strong> tree</li>
	<li>the <strong>FPM</strong> service (php86-php-fpm) is available, listening on <strong>/var/opt/remi/php86/run/php-fpm/www.sock</strong></li>
	<li>the <strong>php86</strong> command gives simple access to this new version, however, the <strong>module</strong> or <strong>scl</strong> command is still the recommended way.</li>
	<li>for now, the collection provides <strong>8.6.0-alpha1</strong>, and alpha/beta/RC versions will be released in the next weeks</li>
	<li>some of the PECL extensions are already available, see the <a class="ref-post" href="https://blog.remirepo.net/pages/PECL-extensions-RPM-status">extensions status</a> page</li>
	<li><strong>tracking issue</strong> <a href="https://github.com/remicollet/remirepo/issues/342">#342</a> can be used to follow the work in progress on RPMS of PHP and extensions</li>
	<li>the <strong>php86-syspaths</strong> package allows to use it as the system's default version</li>
</ul>

<p>ℹ️ Also, read other entries about <a href="https://blog.remirepo.net/tag/SCL">SCL</a> especially the description of <a class="ref-post" href="https://blog.remirepo.net/post/2022/02/17/My-PHP-Workstation">My PHP workstation</a>.</p>

<pre>$ module load php86
$ php --version
PHP 8.6.0alpha1 (cli) (built: Jun 30 2026 11:28:16) (NTS gcc x86_64)
Copyright © The PHP Group and Contributors
Built by Remi's RPM repository  #StandWithUkraine
Zend Engine v4.6.0-dev, Copyright © Zend by Perforce
    with Zend OPcache v8.6.0alpha1, Copyright ©, by Zend by Perforce
</pre>

<p>As always, your feedback is welcome on the tracking ticket.</p>

<p align="center"><strong>Software Collections</strong> (php86)</p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php86-php-common&amp;version=8.6.0~alpha1&amp;lang=en" style="margin: 1em auto; display: block;"/></p></div>
    </summary>
    <updated>2026-07-03T05:38:00Z</updated>
    <published>2026-07-03T05:38:00Z</published>
    <category term="RPM"/>
    <category term="Beta"/>
    <category term="PHP"/>
    <category term="SCL"/>
    <author>
      <name>Remi</name>
    </author>
    <source>
      <id>https://blog.remirepo.net/en</id>
      <link href="https://blog.remirepo.net/en" rel="alternate" type="text/html"/>
      <link href="https://blog.remirepo.net/feed/en/rss2" rel="self" type="application/rss+xml"/>
      <rights>Licence: Creative Commons Attribution-ShareAlike 4.0 International License.</rights>
      <subtitle>Remi's RPM repository blog Information about RPM PHP Fedora RHEL and CentOS</subtitle>
      <title>Remi's RPM repository - Blog</title>
      <updated>2026-07-10T04:19:09Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>urn:md5:111d54826672f66918e9310934fe3977</id>
    <link href="https://blog.remirepo.net/post/2026/07/03/PHP-version-8.2.32-8.3.32-8.4.23-8.5.8" rel="alternate" type="text/html"/>
    <title>🛡️ PHP version 8.2.32, 8.3.32, 8.4.23, and 8.5.8</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>RPMs of <strong>PHP version 8.5.8</strong> are available in the <strong>remi-modular</strong> repository for <strong>Fedora</strong> â‰¥ 42 and <strong>Enterprise Linux</strong> â‰¥ 8 (RHEL, Alma, CentOS, Rocky...).</p>

<p>RPMs of <strong>PHP version 8.4.23</strong> are available in the <strong>remi-modular</strong> repository for <strong>Fedora</strong> â‰¥ 42 and <strong>Enterprise Linux</strong> â‰¥ 8 (RHEL, Alma, CentOS, Rocky...).</p>
<!--
-->

<p>RPMs of <strong>PHP version 8.3.32</strong> are available in the <strong>remi-modular</strong> repository for <strong>Fedora</strong> â‰¥ 42 and <strong>Enterprise Linux</strong> â‰¥ 8 (RHEL, Alma, CentOS, Rocky...).</p>

<p>RPMs of <strong>PHP version 8.2.32</strong> are available in the <strong>remi-modular</strong> repository for <strong>Fedora</strong> â‰¥ 42 and <strong>Enterprise Linux</strong> â‰¥ 8 (RHEL, Alma, CentOS, Rocky...).</p>

<p>â„¹ï¸� These versions are also available as <em>Software Collections</em> in the <strong>remi-safe</strong> repository.</p>
<!--
-->

<p>â„¹ï¸� The packages are available for <strong>x86_64</strong> and <strong>aarch64</strong>.</p>
<!--
<p>â„¹ï¸� There is no security fix this month, so no update for <a class="ref-post" href="https://blog.remirepo.net/post/2026/05/08/PHP-version-8.2.31-8.3.31-8.4.21-8.5.6">versions 8.2.31 and 8.3.31</a>.</p>
-->

<p>âš ï¸� <a class="ref-post" href="https://blog.remirepo.net/post/2026/01/08/PHP-8.1-is-retired">PHP version 8.1</a> has reached its end of life and is no longer maintained by the <a href="https://php.net/supported-versions.php">PHP project</a>.</p>
<!--
-->

<p>ğŸ›¡ï¸� These Versions fix 3 security bugs (<strong>CVE-2026-12184</strong>, <strong>CVE-2026-14355</strong>), so the update is strongly recommended.</p> <p>Version announcements:</p>

<ul>
	<li><a href="https://www.php.net/releases/8_5_8.php">PHP 8.5.8 Release Annoucement</a></li>
	<li><a href="https://www.php.net/releases/8_4_23.php">PHP 8.4.23 Release Annoucement</a></li>
	<!--
-->
	<li><a href="https://www.php.net/releases/8_3_32.php">PHP 8.3.32 Release Annoucement</a></li>
	<li><a href="https://www.php.net/releases/8_2_32.php">PHP 8.2.32 Release Annoucement</a></li>
</ul>

<p>â„¹ï¸� Installation: Use the <a href="https://rpms.remirepo.net/wizard/">Configuration Wizard</a> and choose your version and installation mode.</p>

<p><strong>Replacement</strong> of default PHP by version <strong>8.5</strong> installation (<strong>simplest</strong>):</p>

<p>On Enterprise Linux (dnf 4)</p>

<pre>dnf module switch-to php:remi-8.5/common
</pre>

<p>On Fedora (dnf 5)</p>

<pre>dnf module reset php
dnf module enable php:remi-8.5
dnf update
</pre>

<p><strong>Parallel installation</strong> of version <strong>8.5</strong> as <a class="ref-post" href="https://blog.remirepo.net/post/2025/07/04/PHP-8.5-as-Software-Collection">Software Collection</a></p>

<pre>yum install php85</pre>

<p><strong>Replacement</strong> of default PHP by version <strong>8.4</strong> installation (<strong>simplest</strong>):</p>

<p>On Enterprise Linux (dnf 4)</p>

<pre>dnf module switch-to php:remi-8.4/common
</pre>

<p>On Fedora (dnf 5)</p>

<pre>dnf module reset php
dnf module enable php:remi-8.4
dnf update
</pre>

<p><strong>Parallel installation</strong> of version <strong>8.4</strong> as <a class="ref-post" href="https://blog.remirepo.net/post/2023/06/06/PHP-8.3-as-Software-Collection">Software Collection</a></p>

<pre>yum install php84</pre>

<p>And soon in the official updates:</p>

<ul>
	<li>Fedora <strong>Rawhide</strong> now has PHP version <strong>8.5.8</strong></li>
	<li><a href="https://bodhi.fedoraproject.org/updates/FEDORA-2026-ec9cb4652f">Fedora 44 - PHP 8.5.8</a></li>
	<li><a href="https://bodhi.fedoraproject.org/updates/FEDORA-2026-f4272d87ef">Fedora 43 - PHP 8.4.23</a></li>
</ul>

<p>âš ï¸� <strong>To be noticed : </strong></p>

<ul>
	<li>EL-10 RPMs are built using RHEL-<strong>10.2</strong></li>
	<li>EL-9 RPMs are built using RHEL-<strong>9.8</strong></li>
	<li>EL-8 RPMs are built using RHEL-<strong>8.10</strong></li>
	<li><strong>intl</strong> extension now uses <strong>libicu74 </strong>(version<strong> 74.2</strong>)</li>
	<li><strong>mbstring</strong> extension (EL builds) now uses <strong>oniguruma5php</strong> (version <strong>6.9.10</strong>, instead of the outdated system library)</li>
	<li><strong>oci8</strong> extension now uses the <strong>RPM</strong> of <strong>Oracle Instant Client </strong>version<strong> 23.26 </strong>on x86_64 and aarch64</li>
	<li>A lot of extensions are also available; see the <a href="https://blog.remirepo.net/pages/PECL-extensions-RPM-status">PHP extensions RPM status (from PECL and other sources)</a> page</li>
</ul>

<p>â„¹ï¸� <strong>Information</strong>:</p>

<ul>
	<li><a href="https://php.net/manual/en/migration83.php" hreflang="en">Migrating from PHP 8.2.x to PHP 8.3.x</a></li>
	<li><a href="https://php.net/manual/en/migration84.php" hreflang="en">Migrating from PHP 8.3.x to PHP 8.4.x</a></li>
	<li><a href="https://php.net/manual/en/migration85.php" hreflang="en">Migrating from PHP 8.4.x to PHP 8.5.x</a></li>
</ul>

<p align="center"><strong>Base</strong> packages (php)</p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.5.8&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.4.23&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>
<!--
-->

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.3.32&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.2.32&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>

<p align="center"><strong>Software Collections</strong> (php83 / php84 / php85)</p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php85-php-common&amp;version=8.5.8&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php84-php-common&amp;version=8.4.23&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>
<!--
-->

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php83-php-common&amp;version=8.3.32&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php82-php-common&amp;version=8.2.32&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p></div>
    </summary>
    <updated>2026-07-03T04:31:00Z</updated>
    <published>2026-07-03T04:31:00Z</published>
    <category term="RPM"/>
    <category term="PHP"/>
    <category term="Security"/>
    <author>
      <name>Remi</name>
    </author>
    <source>
      <id>https://blog.remirepo.net/en</id>
      <link href="https://blog.remirepo.net/en" rel="alternate" type="text/html"/>
      <link href="https://blog.remirepo.net/feed/en/rss2" rel="self" type="application/rss+xml"/>
      <rights>Licence: Creative Commons Attribution-ShareAlike 4.0 International License.</rights>
      <subtitle>Remi's RPM repository blog Information about RPM PHP Fedora RHEL and CentOS</subtitle>
      <title>Remi's RPM repository - Blog</title>
      <updated>2026-07-10T04:19:09Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://blogs.gnome.org/mcatanzaro/?p=11231</id>
    <link href="https://blogs.gnome.org/mcatanzaro/2026/06/29/your-_get_type-function-is-not-g_gnuc_const-part-two/" rel="alternate" type="text/html"/>
    <title>Your _get_type() function is not G_GNUC_CONST: Part Two</title>
    <summary>This blog post is a sequel to Your _get_type() function is not G_GNUC_CONST. GNOME developers have long used G_GNUC_CONST, which expands to __attribute__((const)), to annotate GObject _get_type() functions, despite knowing that it is incorrect to do so. const functions by definition have no side effects, but _get_type() functions actually have a side effect the first […]</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">This blog post is a sequel to <a href="https://blogs.gnome.org/mcatanzaro/2015/09/14/your-_get_type-function-is-not-g_gnuc_const/">Your _get_type() function is not G_GNUC_CONST</a>.</p>



<p class="wp-block-paragraph">GNOME developers have long used <code>G_GNUC_CONST</code>, which expands to <code>__attribute__((const))</code>, to annotate GObject <code>_get_type()</code> functions, despite knowing that it is incorrect to do so. const functions by definition have no side effects, but <code>_get_type()</code> functions actually have a side effect the first time the function is called: they initialize the type. Why apply an incorrect annotation to these functions? Because it makes the code faster.<br/><br/>Although this was <a class="external" href="https://wingolog.org/archives/2005/03/24/98">long known to be incorrect</a>, it worked fine in practice… until now. Regrettably, Sam James has discovered that <a class="external" href="https://gitlab.gnome.org/GNOME/glib/-/work_items/3984">GCC 16 may optimize away the type initialization</a>, resulting in crashes. This is our fault for providing the compiler with wrong information about our code, so it’s time to audit your use of const attributes to remove them from <code>_get_type()</code> functions. Most GNOME programs use these attributes <em>only</em> for <code>_get_type()</code> functions, but if you use it in more places, then check to make sure those functions are actually const, as defined by the <a class="external" href="https://gcc.gnu.org/onlinedocs/gcc/Common-Attributes.html#index-const">GCC documentation</a>.</p>



<p class="wp-block-paragraph">Sadly, there is no suitable replacement attribute for <code>_get_type()</code> functions. Two decades ago, <a class="external" href="https://gcc.gnu.org/bugzilla/show_bug.cgi?id=32911">Behdad requested a new idempotent attribute</a> for expressing the desired semantics, but nobody has implemented it.</p>



<p class="wp-block-paragraph"/></div>
    </content>
    <updated>2026-06-29T15:32:49Z</updated>
    <published>2026-06-29T15:32:49Z</published>
    <category term="Fedora"/>
    <category term="GNOME"/>
    <author>
      <name>Michael Catanzaro</name>
    </author>
    <source>
      <id>https://blogs.gnome.org/mcatanzaro</id>
      <link href="https://blogs.gnome.org/mcatanzaro/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://blogs.gnome.org/mcatanzaro" rel="alternate" type="text/html"/>
      <subtitle>On Fedora Workstation, GNOME, Epiphany, and WebKitGTK</subtitle>
      <title>Michael Catanzaro's Blog</title>
      <updated>2026-06-29T21:29:07Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://www.scrye.com/blogs/nirik/posts/2026/06/27/misc-fedora-bits-end-of-june-2026/</id>
    <link href="https://www.scrye.com/blogs/nirik/posts/2026/06/27/misc-fedora-bits-end-of-june-2026/" rel="alternate" type="text/html"/>
    <title xml:lang="en">misc fedora bits: end of june 2026</title>
    <summary type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>Time for a recap of the last week in my #fedora infra space
(here in longer form).</p>
<p>Overall this week was a bunch of catch up from being away at flock,
along with recovering from Jetlag.</p>
<section id="rhel10-migrations">
<h2>RHEL10 migrations</h2>
<p>I scheduled an outage on thursday for the last of the external
colo virthosts to get a RHEL10 reinstall. I had tried to do it
in the last outage, but I wasn't able to do it in the normal
way that preserved all the guests data. This time I managed
to get it done, but it took longer than I would have liked and
I hit a number of fun issues:</p>
<ul class="simple">
<li><p>Using a remote console I can't hold down shift to get a grub
menu, so I had to hit escape at the right time.</p></li>
<li><p>rdp for Fedora is not great still. gnome-connections is still
the winner, but even it has quirks.</p></li>
<li><p>The /boot/efi partition still did not want to let me reformat
it as part of the install. I thought it was because there
was a spare in the raid1 for it, but I grew it to use that
spare and it still didn't help. So, I ended up just deleting
it and recreating it.</p></li>
</ul>
<p>Finally all reinstalled, reprovisioned and all the guests
brought back up.</p>
<p>There's still a number of hosts to move, and we are down
to trickier ones, but we will look at another outage probibly
week after next to do more.</p>
</section>
<section id="fa-in-fedora">
<h2>2fa in Fedora</h2>
<p>Fesco decided to require all provenpackagers to enroll a 2fa
token. There's a lot of talk about expanding that to packagers,
or even everyone.</p>
<p>I thought I would share some info around this for interested
folks who may not have seen it in all the various threads
or tickets:</p>
<p>The Fedora account system frontend (noggin) supports enrolling
TOTP tokens. Once you enroll one you must use it to login to
the account system, to get a kerberos ticket, and to login
to any web application with your fedora account.</p>
<p>You can (and should!) enroll more than one token. As far as
I know, there's no limit to number you can add. You can also
disable or delete tokens, so long as you still have one
token enrolled. ie, you can never delete the last one.
Any enrolled, non deactivated token will work to authenticate
you. So, it's good to have at least one saved off to a safe
place in case you loose access to your primary token.</p>
<p>If you somehow loose access to all your tokens, the recovery
process is to mail <a class="reference external" href="mailto:admin@fedoraproject.org">admin@fedoraproject.org</a> and you will be asked
to prove you are you. This may be a gpg signed email (with the
key associated with your account), using your ssh key associated
with the account, or other means.</p>
<p>So, please make sure you have a backup token to avoid that. :)</p>
<p>TOTP is pretty common and has been around a long time. Lots
of software is capable of storing your secret and displaying
tokens.</p>
</section>
<section id="s390x-builds-backup-and-koji-session-bug">
<h2>s390x builds backup and koji session bug</h2>
<p>On friday morning our koji s390x builders were getting swamped.
It was the same story with a lot of large builds taking up builders
so other things couldn't get in. Or so I thought at first, but on
digging there was another problem. It was caused by a koji bug
(already fixed upstream, but not released yet). This caused
tasks to get freed and just sit there and not progress.</p>
<p>I have applied the patch and updated our hubs, and then went
through and reassigned all the tasks I could see that were still
having problems. Let me know if you see any I missed.</p>
<p>I also pulled in 2 more builders to the general build pool</p>
<ul class="simple">
<li><p>One I had set to only do kernel builds a while back when we
were trying to get security updates out fast.</p></li>
<li><p>One was a compose host, but I think we can be fine with one
less compose host.</p></li>
</ul>
<p>So adding those two helped process the backlog too.</p>
<p>I've also filed another request for more resources, but so far
it hasn't really gone anywhere. ;(</p>
</section>
<section id="some-pto-next-week">
<h2>Some PTO next week</h2>
<p>Next week, I am going to be taking thursday off and friday is a holiday
in the US, and I am taking off the following monday too.</p>
<p>Of course I'll still be around, but possibly doing other things. :)</p>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116823567269032135">https://fosstodon.org/@nirik/116823567269032135</a></p>
</section></div>
    </summary>
    <content type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>Time for a recap of the last week in my #fedora infra space
(here in longer form).</p>
<p>Overall this week was a bunch of catch up from being away at flock,
along with recovering from Jetlag.</p>
<section id="rhel10-migrations">
<h2>RHEL10 migrations</h2>
<p>I scheduled an outage on thursday for the last of the external
colo virthosts to get a RHEL10 reinstall. I had tried to do it
in the last outage, but I wasn't able to do it in the normal
way that preserved all the guests data. This time I managed
to get it done, but it took longer than I would have liked and
I hit a number of fun issues:</p>
<ul class="simple">
<li><p>Using a remote console I can't hold down shift to get a grub
menu, so I had to hit escape at the right time.</p></li>
<li><p>rdp for Fedora is not great still. gnome-connections is still
the winner, but even it has quirks.</p></li>
<li><p>The /boot/efi partition still did not want to let me reformat
it as part of the install. I thought it was because there
was a spare in the raid1 for it, but I grew it to use that
spare and it still didn't help. So, I ended up just deleting
it and recreating it.</p></li>
</ul>
<p>Finally all reinstalled, reprovisioned and all the guests
brought back up.</p>
<p>There's still a number of hosts to move, and we are down
to trickier ones, but we will look at another outage probibly
week after next to do more.</p>
</section>
<section id="fa-in-fedora">
<h2>2fa in Fedora</h2>
<p>Fesco decided to require all provenpackagers to enroll a 2fa
token. There's a lot of talk about expanding that to packagers,
or even everyone.</p>
<p>I thought I would share some info around this for interested
folks who may not have seen it in all the various threads
or tickets:</p>
<p>The Fedora account system frontend (noggin) supports enrolling
TOTP tokens. Once you enroll one you must use it to login to
the account system, to get a kerberos ticket, and to login
to any web application with your fedora account.</p>
<p>You can (and should!) enroll more than one token. As far as
I know, there's no limit to number you can add. You can also
disable or delete tokens, so long as you still have one
token enrolled. ie, you can never delete the last one.
Any enrolled, non deactivated token will work to authenticate
you. So, it's good to have at least one saved off to a safe
place in case you loose access to your primary token.</p>
<p>If you somehow loose access to all your tokens, the recovery
process is to mail <a class="reference external" href="mailto:admin@fedoraproject.org">admin@fedoraproject.org</a> and you will be asked
to prove you are you. This may be a gpg signed email (with the
key associated with your account), using your ssh key associated
with the account, or other means.</p>
<p>So, please make sure you have a backup token to avoid that. :)</p>
<p>TOTP is pretty common and has been around a long time. Lots
of software is capable of storing your secret and displaying
tokens.</p>
</section>
<section id="s390x-builds-backup-and-koji-session-bug">
<h2>s390x builds backup and koji session bug</h2>
<p>On friday morning our koji s390x builders were getting swamped.
It was the same story with a lot of large builds taking up builders
so other things couldn't get in. Or so I thought at first, but on
digging there was another problem. It was caused by a koji bug
(already fixed upstream, but not released yet). This caused
tasks to get freed and just sit there and not progress.</p>
<p>I have applied the patch and updated our hubs, and then went
through and reassigned all the tasks I could see that were still
having problems. Let me know if you see any I missed.</p>
<p>I also pulled in 2 more builders to the general build pool</p>
<ul class="simple">
<li><p>One I had set to only do kernel builds a while back when we
were trying to get security updates out fast.</p></li>
<li><p>One was a compose host, but I think we can be fine with one
less compose host.</p></li>
</ul>
<p>So adding those two helped process the backlog too.</p>
<p>I've also filed another request for more resources, but so far
it hasn't really gone anywhere. ;(</p>
</section>
<section id="some-pto-next-week">
<h2>Some PTO next week</h2>
<p>Next week, I am going to be taking thursday off and friday is a holiday
in the US, and I am taking off the following monday too.</p>
<p>Of course I'll still be around, but possibly doing other things. :)</p>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116823567269032135">https://fosstodon.org/@nirik/116823567269032135</a></p>
</section></div>
    </content>
    <updated>2026-06-27T18:22:49Z</updated>
    <published>2026-06-27T18:22:49Z</published>
    <category label="fedora" term="fedora"/>
    <category label="linux" term="linux"/>
    <author>
      <name>nirik</name>
    </author>
    <source>
      <id>https://www.scrye.com/blogs/nirik/categories/fedora.atom</id>
      <author>
        <name>nirik</name>
      </author>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora.atom" rel="self" type="application/atom+xml"/>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora/" rel="alternate" type="text/html"/>
      <title xml:lang="en">Kevin's musings (Posts about fedora)</title>
      <updated>2026-07-04T19:53:19Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>http://kparal.wordpress.com/?p=1738</id>
    <link href="https://kparal.wordpress.com/2026/06/26/migrate-fedora-os-via-partition-cloning-efficiently-over-network/" rel="alternate" type="text/html"/>
    <title>Migrate Fedora OS via partition cloning efficiently over network</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">How to migrate Fedora OS from one system to another, across network or (better) a Thunderbolt connection, without cloning the whole disk contents, saving SSD life. Background When migrating a Linux installation from a source drive to a target drive of a different size, traditional block-by-block tools like dd don’t allow to migrate to a … <a class="more-link" href="https://kparal.wordpress.com/2026/06/26/migrate-fedora-os-via-partition-cloning-efficiently-over-network/">Continue reading <span class="screen-reader-text">Migrate Fedora OS via partition cloning efficiently over network</span> <span class="meta-nav">→</span></a></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph"><em>How to migrate Fedora OS from one system to another, across network or (better) a Thunderbolt connection, without cloning the whole disk contents, saving SSD life.</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Background</h2>



<p class="wp-block-paragraph">When migrating a Linux installation from a source drive to a target drive of a different size, traditional block-by-block tools like <code>dd</code> don’t allow to migrate to a smaller drive, and also waste SSD life by writing unused blocks. This guide describes a simple approach in which different disk sizes can be used, and the process is performed over network (or Thunderbolt), so that it’s not necessary to place two physical disks in the same device. The target system is exactly the same as the original, with all partition and filesystem UUIDs staying the same, which means no post-migration OS configuration is necessary. The time and SSD wear is minimized by pre-shrinking partitions and skipping unallocated disk space entirely. The default Fedora Workstation disk layout is supported, including LUKS encryption of the system partition.</p>



<p class="wp-block-paragraph">This guide expects the following disk layout:</p>



<ul class="wp-block-list">
<li><code>/dev/nvme0n1p1</code> — ESP (most often FAT)</li>



<li><code>/dev/nvme0n1p2</code> — Boot partition (most often Ext4)</li>



<li><code>/dev/nvme0n1p3</code> — System partition (most often Btrfs, optionally encrypted using LUKS)</li>
</ul>



<p class="wp-block-paragraph">For simplicity, this will not try to skip copying <em>all</em> unused blocks, just most of them. The first two partitions will be cloned in raw mode. The third partition will be shrunk first (thus saving lots of blocks from being copied, and also supporting smaller target drives), and then cloned in raw mode.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Migration steps</h2>



<h3 class="wp-block-heading">Shrink the system partition on the source system</h3>



<p class="wp-block-paragraph">On the <strong>source</strong> system:</p>



<ol class="wp-block-list">
<li>Delete all necessary data, prune cash dirs, empty the trash, etc.</li>



<li>Boot to a Fedora Workstation Live system from a USB drive.</li>



<li>Install necessary tools: <code>sudo dnf install gparted pv</code></li>



<li>Run <em>Gparted</em>. In it, unlock the system partition, if encrypted. Then shrink the partition to a reasonable degree. For example, if the partition has 950 GB (from a 1 TB disk), but only 300 GB is used, you can shrink it e.g. to 350 GB. That still leaves enough free space for regular usage if you had to boot it for any reason, and saves 600 GB from being copied needlessly. This operation might take some time, because any data blocks currently present after the new size limit will need to be moved (therefore don’t be too aggressive in setting the limit). If your partition was encrypted, make sure that both the LUKS encryption container and the filesystem inside it correctly show up as resized.</li>



<li>Unmount all partitions (if any), lock the encrypted partition (if applicable) and close GParted.</li>
</ol>



<h3 class="wp-block-heading">Erase the target system</h3>



<p class="wp-block-paragraph">On the <strong>target</strong> system:</p>



<ol class="wp-block-list">
<li>Ensure that this is really the system you want to <strong>completely erase</strong> (and replace with the OS from the source system).</li>



<li>Ensure that the disk size is sufficient to fit all partitions from the source system (now that the system partition on the source system has been shrunk).</li>



<li>Boot to a Fedora Workstation Live system from a USB drive.</li>



<li>Install necessary tools: <code>sudo dnf install sfdisk sgdisk</code></li>



<li>Unmount all partitions (if any). You can use e.g. <em>GNOME Disks</em> for this.</li>



<li>Erase the whole drive (make sure you’re using the correct system): <code>sudo wipefs -a /dev/nvme0n1</code></li>



<li>Discard all blocks on your drive (better for your SSD longevity): <code>sudo blkdiscard -v /dev/nvme0n1</code></li>
</ol>



<h3 class="wp-block-heading">Establish an Ethernet/Thunderbolt network link</h3>



<p class="wp-block-paragraph">If you have both systems connected to the network and intend to use it, skip the <em>Thunderbolt setup</em> section below. Instead figure out the IP addresses of both systems (using the <code>ip address</code> command) and go to the <em>Connectivity test</em>.</p>



<h4 class="wp-block-heading">Thunderbolt setup</h4>



<p class="wp-block-paragraph">If you want something faster than a regular network, have Thunderbolt ports on both systems and a fast USB-C cable ready, you can use that instead. With Thunderbolt, you can transfer data with 10 Gb/s speeds or more, compared to the common 1 Gb/s of a standard Ethernet.</p>



<ol class="wp-block-list">
<li>On both laptops, after connecting them through a Thunderbolt cable, locate the network interface name: <code>ip link</code><br/>Look for an interface like <code>thunderbolt0</code>.</li>



<li>Assign static IP addresses to them:</li>
</ol>



<ul class="wp-block-list">
<li>Source system:<br/><code>bash sudo ip addr add 192.168.5.1/24 dev &lt;interface_name&gt;</code><br/><code>sudo ip link set &lt;interface_name&gt; up</code></li>



<li>Target system:<br/><code>bash sudo ip addr add 192.168.5.2/24 dev &lt;interface_name&gt;</code><br/><code>sudo ip link set &lt;interface_name&gt; up</code></li>
</ul>



<h4 class="wp-block-heading">Connectivity test</h4>



<ol class="wp-block-list">
<li>Let’s use a well-named variable for both numbers, so that we don’t mix them up later. On both systems, run:</li>
</ol>



<pre class="wp-block-code"><code>   export SOURCE_IP=192.168.5.1
   export TARGET_IP=192.168.5.2</code></pre>



<ol class="wp-block-list" start="2">
<li>Test connectivity between your systems.</li>
</ol>



<ul class="wp-block-list">
<li>From the source system: <code>ping $TARGET_IP</code></li>



<li>From the target system: <code>ping $SOURCE_IP</code> <br/><br/>You should see both systems pinging the other system correctly.</li>
</ul>



<h3 class="wp-block-heading">Replicate partition table from source to target</h3>



<p class="wp-block-paragraph">This will make an exact copy of the source system partition table (including partition UUIDs) on the target system. Then we will adjust it to the different disk size.</p>



<ol class="wp-block-list">
<li>On <strong>target</strong> system, start listening for data and save it:</li>
</ol>



<pre class="wp-block-code"><code>   nc -l -p 2000 &gt; table.txt</code></pre>



<ol class="wp-block-list" start="2">
<li>On <strong>source</strong> system, dump the partition table and send it over:</li>
</ol>



<pre class="wp-block-code"><code>   sudo sfdisk --dump /dev/nvme0n1 | nc $TARGET_IP 2000</code></pre>



<ol class="wp-block-list" start="3">
<li>On <strong>target</strong> system, apply the partition layout to the disk:</li>
</ol>



<pre class="wp-block-code"><code>   sudo sfdisk /dev/nvme0n1 &lt; table.txt</code></pre>



<p class="wp-block-paragraph">And then fix the GPT backup header location (because it’s unlikely that you have both disks of exactly the same size):</p>



<pre class="wp-block-code"><code>   sudo sgdisk --move-second-header /dev/nvme0n1</code></pre>



<h3 class="wp-block-heading">Copy all partitions</h3>



<p class="wp-block-paragraph">Everything should be ready now to transfer all partitions data.</p>



<ol class="wp-block-list">
<li>Clone the ESP partition (<code>p1</code>):</li>
</ol>



<ul class="wp-block-list">
<li>On <strong>target</strong> system, listen and write the data:</li>
</ul>



<pre class="wp-block-code"><code>   nc -l -p 2000 | sudo dd of=/dev/nvme0n1p1 bs=4M</code></pre>



<ul class="wp-block-list">
<li>On <strong>source</strong> system, send the data:</li>
</ul>



<pre class="wp-block-code"><code>   sudo dd if=/dev/nvme0n1p1 bs=4M | pv | nc $TARGET_IP 2000</code></pre>



<ol class="wp-block-list" start="2">
<li>Clone the Boot partition (<code>p2</code>):</li>
</ol>



<ul class="wp-block-list">
<li>On <strong>target</strong> system, listen and write the data:</li>
</ul>



<pre class="wp-block-code"><code>   nc -l -p 2000 | sudo dd of=/dev/nvme0n1p2 bs=4M</code></pre>



<ul class="wp-block-list">
<li>On <strong>source</strong> system, send the data:</li>
</ul>



<pre class="wp-block-code"><code>   sudo dd if=/dev/nvme0n1p2 bs=4M | pv | nc $TARGET_IP 2000</code></pre>



<ol class="wp-block-list" start="3">
<li>Clone the System partition (<code>p3</code>):</li>
</ol>



<ul class="wp-block-list">
<li>On <strong>target</strong> system, listen and write the data:</li>
</ul>



<pre class="wp-block-code"><code>   nc -l -p 2000 | sudo dd of=/dev/nvme0n1p3 bs=4M</code></pre>



<ul class="wp-block-list">
<li>On <strong>source</strong> system, send the data:</li>
</ul>



<pre class="wp-block-code"><code>   sudo dd if=/dev/nvme0n1p3 bs=4M | pv | nc $TARGET_IP 2000</code></pre>



<h3 class="wp-block-heading">Expand the System partition on the target system</h3>



<p class="wp-block-paragraph">Now that the target system is a complete clone of the source system, you can expand the System partition to fully utilize the remaining disk space:</p>



<ol class="wp-block-list">
<li>Install GParted on the target system: <code>sudo dnf install gparted</code></li>



<li>In Gparted, unlock the system partition, if encrypted. Then enlarge it according to your preferences. If your partition was encrypted, make sure that both the LUKS encryption container and the filesystem inside it correctly show up as resized.</li>
</ol>



<h3 class="wp-block-heading">Reboot the target system</h3>



<p class="wp-block-paragraph">You can now reboot the target system, and you should see your OS and data exactly the same as on your source system. The process is now complete.</p>



<h4 class="wp-block-heading">Boot problems</h4>



<p class="wp-block-paragraph">In case the target system has a very different hardware from the source system (e.g. a different brand of a graphics card), the drivers might be missing from the current kernel initramfs and you can see a black screen or kernel errors. In that case, reboot the system again, press <code>F8</code> repeatedly during boot to get into the GRUB bootloader menu, and boot the <code>rescue</code> Fedora option, instead of the default one. That should hopefully boot using the generic image (which should contain all known drivers), and then you can regenerate all the kernel images using your current hardware setup with: <code>sudo dracut --regenerate-all --force</code></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Mentions of other cloning approaches</h2>



<ol class="wp-block-list">
<li>Using <code>dd</code><br/>This works fine when cloning to a larger disk (if you fix the partition table afterwards), but unused blocks are written needlessly (wearing down SSD), and migrating to a smaller drive is problematic.</li>



<li>Native Btrfs streams using <code>btrfs send</code> and <code>btrfs receive</code><br/>This perfectly copies only used blocks of the main partition, but it only submits a single subvolume. Which means there’s some extra work needed to make sure exactly the same subvolumes are replicated from source to target. Also, this works above the LUKS encryption, which also needs to be created manually on the target (while keeping IDs, etc).</li>



<li>Using Clonezilla<br/>Clonezilla will copy LUKS partitions as raw data, because it can’t see inside. Furthermore, it doesn’t support cloning to a smaller drive by default (there are some tweaks in Expert Mode, but you need to repair the GPT backup table manually anyway).</li>



<li>Sparse-copying the whole disk<br/>You can clone and restore the whole disk image with sparse blocks support, as seen in <a href="https://dustymabe.com/2012/11/15/create-a-disk-image-without-enough-free-space/">this guide</a>. With a little tweaking, this approach could potentially be used even for my use case. One would need to make sure all the unallocated blocks are freed and really contain zeroes (which means running <code>fstrim</code> or <code>blkdiscard</code> and testing if it zeroed it out), and the partitions would need to be shrunk first in case of migrating to a smaller drive. The GPT backup header would need to be fixed (the same way as in the main article). So this might be a viable alternative approach for those who know how to tweak the steps.</li>
</ol>



<p class="wp-block-paragraph"/></div>
    </content>
    <updated>2026-06-26T17:01:08Z</updated>
    <published>2026-06-26T17:01:08Z</published>
    <category term="Fedora"/>
    <category term="Fedora Planet"/>
    <category term="Fedora Quality Planet"/>
    <category term="Hardware"/>
    <category term="Tools"/>
    <author>
      <name>Kamil Páral</name>
    </author>
    <source>
      <id>https://kparal.wordpress.com</id>
      <logo>https://s2.wp.com/i/webclip.png</logo>
      <link href="https://kparal.wordpress.com/category/fedora-planet/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://kparal.wordpress.com" rel="alternate" type="text/html"/>
      <link href="https://kparal.wordpress.com/osd.xml" rel="search" title="Kparal's Fedora Blog" type="application/opensearchdescription+xml"/>
      <link href="https://kparal.wordpress.com/?pushpress=hub" rel="hub" type="text/html"/>
      <subtitle>The world of Fedoras</subtitle>
      <title>Fedora Planet – Kparal's Fedora Blog</title>
      <updated>2026-07-09T13:32:32Z</updated>
    </source>
  </entry>

  <entry>
    <id>tag:marcin.juszkiewicz.com.pl,2026-06-26:/2026/06/26/the-end-of-the-aarch64-desktop-experiment/</id>
    <link href="https://marcin.juszkiewicz.com.pl/2026/06/26/the-end-of-the-aarch64-desktop-experiment/" rel="alternate" type="text/html"/>
    <title>The end of the AArch64 desktop experiment</title>
    <summary>After about eleven months of using an AArch64 desktop, I decided to end that experiment.</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>After about eleven months of using an AArch64 desktop, I decided to end that experiment.</p>
<!--MORE-->

<h3>Hardware used</h3>
<p>About a year ago, <a href="https://marcin.juszkiewicz.com.pl/2025/06/27/bought-myself-an-ampere-altra-system/">I bought myself an Ampere Altra system</a>.
After moving some hardware around and making a few extra orders, the final setup was:</p>
<table>
<thead>
<tr>
<th> </th>
<th> </th>
</tr>
</thead>
<tbody>
<tr>
<td><span class="caps">CPU</span></td>
<td>Ampere Altra Q80-30 processor (80 cores at 3.0GHz)</td>
</tr>
<tr>
<td><span class="caps">RAM</span></td>
<td>128 <span class="caps">GB</span> (8x <span class="caps">16GB</span> <span class="caps">HMA82GR7CJR8N</span>-<span class="caps">XN</span>)</td>
</tr>
<tr>
<td><span class="caps">GPU</span></td>
<td><span class="caps">AMD</span> Radeon <span class="caps">RX6700XT</span></td>
</tr>
<tr>
<td><span class="caps">NVME</span></td>
<td>Lexar <span class="caps">LM970</span> <span class="caps">2TB</span><br/> <span class="caps">ADATA</span> <span class="caps">SX8200</span> Pro <span class="caps">1TB</span></td>
</tr>
<tr>
<td>Motherboard</td>
<td>ASRock Rack <span class="caps">ALTRAD8UD</span>-<span class="caps">1L2T</span></td>
</tr>
<tr>
<td><span class="caps">PSU</span></td>
<td><span class="caps">MSI</span> <span class="caps">MPG</span> <span class="caps">A850G</span> (850W)</td>
</tr>
<tr>
<td>Case</td>
<td>Endorfy 700 Air</td>
</tr>
<tr>
<td><span class="caps">USB3</span></td>
<td>no-name <span class="caps">USB</span> 3.2/10Gbps controller (PCIe x4)</td>
</tr>
</tbody>
</table>
<p>To be fair, I should mention that this is a server motherboard, not a desktop
one, and Altra systems were never meant to be desktops (despite companies
selling them as such). Naturally, the list of tested/approved devices (Qualified
Vendor List (<span class="caps">QVL</span> for <span class="caps">TLA</span> fans)) is quite short and for Ampere Altra systems, it
does not contain <span class="caps">AMD</span> Radeon <span class="caps">GPU</span> cards. They can be made to work, but this often
requires additional effort.</p>
<p>The extra <span class="caps">USB</span> 3.2 controller allowed me to have more <span class="caps">USB</span> devices than the
motherboard alone supported, and gave me some 10Gbps ports for connecting
external NVMe drives.</p>
<p>The whole system was running just fine<sup>*</sup> under Fedora 42–44.</p>
<h3>The first issue</h3>
<p>Have you noticed the small “*” at the end of the previous paragraph? The system
I used was not quite Fedora — I had to use my own, self-built kernel.</p>
<p>You see, the <span class="caps">PCI</span> Express controller in the Ampere Altra has some issues. Let me
quote the description of
<a href="https://github.com/AmpereComputing/linux-ampere-altra-erratum-pcie-65">the Ampere Altra erratum 82288</a> patches:</p>
<blockquote>
<p>Per Altra family erratum, PCIE_65 may cause invalid addresses to be generated
on PCIe mmio writes, impacting certain device types, notably <span class="caps">AMD</span> GPUs, and
thus the Altra family is not generally compatible with those device types.</p>
</blockquote>
<p>And longer description from patch itself:</p>
<blockquote>
<p>PCIe device drivers may map <span class="caps">MMIO</span> space as Normal, non-cacheable memory
attribute (e.g. Linux kernel drivers mapping <span class="caps">MMIO</span> using ioremap_wc). This may
be for the purpose of enabling write combining or unaligned accesses. This can
result in data corruption on the PCIe interface’s outbound <span class="caps">MMIO</span> writes due to
issues with the write-combining operation.</p>
<p>The workaround modifies software that maps PCIe <span class="caps">MMIO</span> space as Normal,
non-cacheable memory (e.g. ioremap_wc) to instead Device, non-gathering memory
(e.g. ioremap). And all memory operations on PCIe <span class="caps">MMIO</span> space must be strictly aligned.</p>
</blockquote>
<p>So, to have a working Linux system, I had to rebuild the kernel on every package
update. Which usually meant “weekly”. Each Monday or Tuesday, I would update
the local copy of the Fedora kernel package repository and build it using my own
versioning scheme, like “7.0.2-200.fc44.pcie65.6”. The “pcie65” part reminded me
which patches I had applied, and the “6” was a counter for the patch rebases.</p>
<p>I cloned the repository from GitHub and then rebased patches, adapting them
whenever they needed work. The side effect was that I often used a newer kernel
than the official Fedora release — there is a “stabilisation” branch in the
Fedora kernel package repo where the soon-to-be-pushed version is present. So,
when Fedora had 6.19.y kernel, I had 7.0.z one.</p>
<h3>So many cores, not enough speed</h3>
<p>As <a href="https://marcin.juszkiewicz.com.pl/2026/06/01/arm-desktop-so-many-cores-not-enough-speed/">I wrote in my previous post</a>,
having eighty <span class="caps">CPU</span> cores does not mean that the system is a good, fast desktop machine.</p>
<h3><span class="caps">AMD</span> <span class="caps">GPU</span> started failing</h3>
<p>As I mentioned above, to get my <span class="caps">AMD</span> Radeon <span class="caps">RX6700XT</span> running properly I had to
alter kernel with the out-of-tree patches. It worked, I could play some games,
watch videos with hardware-assisted video decode acceleration.</p>
<p>Until one day, around the Linux 7.0 release, when it started to fail. Running a
game ended with:</p>
<pre><code>kernel: amdgpu 0000:03:00.0: Fence fallback timer expired on ring vcn_dec_0
kernel: amdgpu 0000:03:00.0: Fence fallback timer expired on ring vcn_dec_0
kernel: amdgpu 0000:03:00.0: Fence fallback timer expired on ring vcn_dec_0
</code></pre>
<p>Over and over again. Watching YouTube videos became impossible due to 720 out of
750 frames being dropped, etc.</p>
<p>Normally I would start to bisect the kernel to find out where the problem is.
But I was running a tainted kernel due to <span class="caps">PCIE65</span> patches so who knew where the
problem actually was…</p>
<h3>Let’s get Nvidia</h3>
<p>I bought an Nvidia <span class="caps">RTX</span> 2060 graphics card and put it in place of the <span class="caps">AMD</span> Radeon.
It turned out that if I wanted to use it with the <code>nouveau</code> kernel driver I
still needed <span class="caps">PCIE65</span> patches applied…</p>
<p>So I tried default Fedora kernel with Nvidia binary driver. And it worked fine.
Video decoding was accelerated, some games under Wine worked as well.</p>
<p>But then I started FreeCAD. And OrcaSlicer. And in both cases I got crash and exit…</p>
<p>It turned out that there was no <code>org.freedesktop.Platform.GL.nvidia</code> in Flatpak
repositories for AArch64. And I used both of those tools quite often.</p>
<h3>Powering up the old x86-64…</h3>
<p>At that point, I gave up. And booted my x86-64 system, which had been powered
off all that time. There were a lot of cables to move, some new ones to arrange,
and now I have both “wooster” (Ampere Altra) and “puchatek” (Ryzen 5 3600)
systems running under my desk.</p>
<p>Moving from 80 cores to 6 cores (12 threads) was a weird experience. A much
smaller number, yet things work fine. I can load all threads and the music still
plays. All games from my Steam library are playable. A working FreeCAD allows me
to finish designing cases for my home projects and I can 3D print prototypes
straight from OrcaSlicer.</p>
<p>The “wooster” system stays powered on, churning through <span class="caps">RISC</span>-V package builds.
It may be weak in single-thread, but it flies when it comes to multi-core load.</p>
<h3>Conclusion</h3>
<p>As for the Ampere Altra, I am not planning to repeat this experiment. Another
AArch64 desktop attempt would require a completely new hardware platform. And I
have no plans to spend over twenty thousand <span class="caps">PLN</span> to buy an Nvidia <span class="caps">DGX</span> Spark system.</p></div>
    </content>
    <updated>2026-06-26T11:18:00Z</updated>
    <published>2026-06-26T11:18:00Z</published>
    <category term="aarch64"/>
    <category term="desktop"/>
    <category term="computers"/>
    <category term="fedora"/>
    <author>
      <name>Marcin Juszkiewicz</name>
    </author>
    <source>
      <id>https://marcin.juszkiewicz.com.pl/</id>
      <link href="https://marcin.juszkiewicz.com.pl/" rel="alternate" type="text/html"/>
      <link href="https://marcin.juszkiewicz.com.pl/tag/fedora/feed/" rel="self" type="application/atom+xml"/>
      <title>Marcin Juszkiewicz - fedora</title>
      <updated>2026-06-26T11:18:00Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://communityblog.fedoraproject.org/?p=15814</id>
    <link href="https://communityblog.fedoraproject.org/community-update-week-26-2026/" rel="alternate" type="text/html"/>
    <title>Community Update – Week 26 2026</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>This is a report created by CLE Team, which is a team containing community members working in various Fedora groups for example Infrastructure, Release Engineering, Quality etc. This team is also moving forward some initiatives inside Fedora project. Week: 22 – 26 June 2026 Fedora Infrastructure This team is taking care of day to day […]</p>
<p>The post <a href="https://communityblog.fedoraproject.org/community-update-week-26-2026/">Community Update – Week 26 2026</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">This is a report created by <a href="https://docs.fedoraproject.org/en-US/cle/">CLE Team</a>, which is a team containing community members working in various Fedora groups for example Infrastructure, Release Engineering, Quality etc. This team is also moving forward some initiatives inside Fedora project.</p>



<p class="wp-block-paragraph">Week: 22 – 26 June 2026</p>



<span id="more-15814"/>



<h2 class="wp-block-heading">Fedora Infrastructure</h2>



<p class="wp-block-paragraph">This team is taking care of day to day business regarding Fedora Infrastructure.<br/>It’s responsible for services running in Fedora infrastructure.<br/><a href="https://pagure.io/fedora-infrastructure/issues">Ticket tracker</a></p>



<ul class="wp-block-list">
<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/13421">Lost admin permission on packaging/FedoraReview after migrating from Pagure</a></li>



<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/13415">Request for IPA admin access on accounts.stg.fedoraproject.org</a></li>



<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/13413">Bodhi: only the rawhide package is visible in updates</a></li>



<li><a href="https://forge.fedoraproject.org/infra/tickets/issues/13412">Fedora Rawhide mirror 404s</a></li>
</ul>



<h2 class="wp-block-heading">CentOS Infra including CentOS CI</h2>



<p class="wp-block-paragraph">This team is taking care of day to day business regarding CentOS Infrastructure and CentOS Stream Infrastructure.<br/>It’s responsible for services running in CentOS Infrastructure and CentOS Stream.<br/><a href="https://gitlab.com/CentOS/infra/tracker/-/issues">CentOS ticket tracker</a><br/><a href="https://issues.redhat.com/projects/CS/issues/CS-3206?filter=allopenissues">CentOS Stream ticket tracker</a></p>



<ul class="wp-block-list">
<li>Attended/interacted with some Folks contributors (remotely attending and chat in matrix rooms)</li>



<li>Rebuilt quite some dependencies for calligrabot/robosignatory for centos stream 10 infra change (<a href="https://redhat.atlassian.net/browse/CS-3402">https://redhat.atlassian.net/browse/CS-3402</a>)</li>



<li>Continue to work on all needed package rebuild phase for stream signing infra change (<a href="https://redhat.atlassian.net/browse/CS-3402">https://redhat.atlassian.net/browse/CS-3402</a>)</li>



<li>Rebuilt already 48 rpm pkgs for infra10s for centos stream signing upgrade (<a href="https://redhat.atlassian.net/browse/CS-3402">https://redhat.atlassian.net/browse/CS-3402</a>) but unfortunately more to come</li>



<li>Sprint planning meeting</li>



<li>Claude helped me writing sms (standup-matrix-summarizer) which can be used to retrieve your “Done” section from each daily standup report, combine that into weekly view so that you can just then copy/paste into manager google doc. See <a href="https://gitlab.com/CentOS/infra/containers/standup-matrix-summarizer">https://gitlab.com/CentOS/infra/containers/standup-matrix-summarizer</a> (and <a href="https://quay.io/repository/centos-infra/sms?tab=info">https://quay.io/repository/centos-infra/sms?tab=info</a>)</li>



<li>Rebuilt more pkgs for centos stream infra but also had to find workaround for orphaned pkg (<a href="https://redhat.atlassian.net/browse/CS-3402">https://redhat.atlassian.net/browse/CS-3402</a>)</li>



<li>Rotate some api keys for SIGs (<a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1940">https://gitlab.com/CentOS/infra/tracker/-/work_items/1940</a>)</li>



<li>Started to work on ansible boot-server role to convert for el10 and isc dhcpd replaced by kea (<a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1936">https://gitlab.com/CentOS/infra/tracker/-/work_items/1936</a>) – WIP</li>



<li>PoC for kea dhcp replacement for isc dhcpd gone from el10 (<a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1936">https://gitlab.com/CentOS/infra/tracker/-/work_items/1936</a>)</li>



<li>Created other tickets for .stg. stream el10 staging signing service (network ports for fedora-messaging stg rabbitmq hosts and two new service principals) – <a href="https://redhat.atlassian.net/browse/CS-3414">https://redhat.atlassian.net/browse/CS-3414</a></li>



<li>Closed ticket (review) about all dependencies built and available for el10 robosignatory/calligrabot (<a href="https://redhat.atlassian.net/browse/CS-3413">https://redhat.atlassian.net/browse/CS-3413</a>)</li>



<li>Prepared staging host for centos-stream signing (<a href="https://redhat.atlassian.net/browse/CS-3414">https://redhat.atlassian.net/browse/CS-3414</a>) but now blocked with a fedora infra staging issue (rabbitmq) so tried the whole day to debug but need someone from Fedora infra side to solve the issue there</li>



<li>Riscv64 discussion about a new p550 hardware firmware upgrade</li>



<li>Tested and validated that RH network team opened needed port for rabbitmq.stg.fedoraproject.org</li>
</ul>



<h2 class="wp-block-heading">RISC-V</h2>



<p class="wp-block-paragraph">This is the summary of the work done regarding the RISC-V architecture in Fedora.</p>



<ul class="wp-block-list">
<li>F45 rebuild started — we’re trying to first focus on language toolchains — need to refer to Miro’s lightning talk from Flock on how they handled Python bootstrap</li>



<li>F44 is being kept up2date (there were some big updates, including GCC)</li>



<li>Kevin did the legwork to move away from old dist-git on fedora.riscv.rocks to forge.fp.o</li>



<li>Another K3 builder in Fedora Koji — another member added.  (This might sound like a tame update, but all compute power is helpful / important to keep the build momentum :-))</li>



<li>Discussed some details of riscv64 in primary <a href="https://forge.fedoraproject.org/riscv/planning/issues/23">Koji ticket</a></li>



<li><a href="https://kashyapc.fedorapeople.org/flock2026-riscv-update.pdf">Slides</a> for Flock RISC-V update</li>
</ul>



<h2 class="wp-block-heading">AI</h2>



<p class="wp-block-paragraph">This is the summary of the work done regarding AI in Fedora.</p>



<ul class="wp-block-list">
<li>The AI Developer Desktop Remix repos have moved to an org on codeberg (<a href="https://codeberg.org/project-resistor">https://codeberg.org/project-resistor</a>)</li>
</ul>



<h2 class="wp-block-heading">QE</h2>



<p class="wp-block-paragraph">This team is taking care of quality of Fedora. Maintaining CI, organizing test days<br/>and keeping an eye on overall quality of Fedora releases.</p>



<ul class="wp-block-list">
<li>Flock &amp; DevConf attendance, lruzicka gave a talk on openQA test investigation, adamwill gave a lightning talk with cle about Fedora CI improvements, several of us were involved in a workshop/roundtable about the viability/desirability of moving all testing to dist-git PRs, lots of productive side conversations etc., many about AI – trip reports / blog posts coming</li>



<li>On-demand openQA test of dist-git PRs <a href="https://forge.fedoraproject.org/quality/fedora_openqa/src/branch/schedule-distgit-prs">in progress</a></li>



<li>Looks like we maybe found <a href="https://forge.fedoraproject.org/quality/tickets/issues/860">some new maintainers for packager-dashboard</a></li>



<li>Lots of work to <a href="https://forge.fedoraproject.org/quality/os-autoinst-distri-fedora/commit/cae3eb0f4373874013bfce9ecc5c19bdf621ee73">enable testing</a> of the huge OpenSSL 4 update for Rawhide, investigate a <a href="https://bugzilla.redhat.com/show_bug.cgi?id=2490607">significant bug that showed up</a>, and eventually <a href="https://forge.fedoraproject.org/quality/os-autoinst-distri-fedora/commit/d92d78b7ecaf12c92a43f393f4e0abbe0bc1be61">bypass the test failures</a> for that bug as it’s proving not to be possible to resolve in a reasonable time (the update needed to get merged)</li>



<li>Continued tech debt / enhancement work on blockerbugs, testdays-web and issuebot</li>
</ul>



<h2 class="wp-block-heading">Forgejo</h2>



<p class="wp-block-paragraph">This team is working on introduction of https://forge.fedoraproject.org to Fedora<br/>and migration of repositories from pagure.io.</p>



<ul class="wp-block-list">
<li>PTOs &amp; travel</li>



<li>On Zabbix staging, now have a working template to monitor the Forgejo runnerhost VM and the runners themselves</li>



<li>Continued work on Private Issues (private comments refactoring)</li>
</ul>



<h2 class="wp-block-heading">UX</h2>



<p class="wp-block-paragraph">This team is working on improving User experience. Providing artwork, user experience,<br/>usability, and general design services to the Fedora project</p>



<ul class="wp-block-list">
<li>Beta Wallpaper <a href="https://forge.fedoraproject.org/design/tickets/issues/23#issuecomment-826301">ticket</a> closed</li>
</ul>



<h3 class="wp-block-heading">List of new releases of apps maintained by I&amp;R Team</h3>



<ul class="wp-block-list">
<li>Patch update of Fedora Messaging from 3.9.0 to 3.9.1 on 2026-06-23: <a href="https://github.com/fedora-infra/fedora-messaging/releases/tag/v3.9.1">https://github.com/fedora-infra/fedora-messaging/releases/tag/v3.9.1</a></li>
</ul>



<p class="wp-block-paragraph">If you have any questions or feedback, please respond to this report or contact us on #admin:fedoraproject.org channel on <a href="https://matrix.to/#/#admin:fedoraproject.org:matrix.org">matrix</a>.</p>
<p>The post <a href="https://communityblog.fedoraproject.org/community-update-week-26-2026/">Community Update – Week 26 2026</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </content>
    <updated>2026-06-26T10:00:00Z</updated>
    <published>2026-06-26T10:00:00Z</published>
    <category term="Fedora Project Community"/>
    <category term="Community update"/>
    <author>
      <name>zlopez</name>
    </author>
    <source>
      <id>https://communityblog.fedoraproject.org/</id>
      <logo>https://communityblog.fedoraproject.org/wp-content/uploads/2022/07/favicon-fedora-commblog.png</logo>
      <link href="https://communityblog.fedoraproject.org/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://communityblog.fedoraproject.org/" rel="alternate" type="text/html"/>
      <subtitle>The Community Blog provides a single source for members of the community to share important news, updates, and information about Fedora with others in the Project community.</subtitle>
      <title>Fedora Community Blog</title>
      <updated>2026-07-03T10:34:22Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://communityblog.fedoraproject.org/?p=15820</id>
    <link href="https://communityblog.fedoraproject.org/fedora-documentation-translations-again-available/" rel="alternate" type="text/html"/>
    <title>Fedora Documentation translations again available</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Updates to translations of Fedora Documentation are again available. As announced on March 3rd, the unavailability of translation updates was due to the migration of the translation repositories and necessary tools from Pagure to the Fedora Forge. It took longer than expected but we are pleased to report this undertaking came finally to the end.</p>
<p>The post <a href="https://communityblog.fedoraproject.org/fedora-documentation-translations-again-available/">Fedora Documentation translations again available</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">Updates to translations of <a href="https://docs.fedoraproject.org/en-US/docs/">Fedora Documentation</a> are again available. As <a href="https://communityblog.fedoraproject.org/fedora-documentation-translations-not-available-from-march-4th-2026/">announced</a> on March 3rd, the unavailability of translation updates was due to the migration of the <a href="https://forge.fedoraproject.org/localization-docs/">translation repositories</a> and necessary tools from Pagure to the Fedora Forge. It took longer than expected but we are pleased to report this <a href="https://forge.fedoraproject.org/localization/tickets/issues/52">undertaking</a> came finally to the end.</p>
<p>The post <a href="https://communityblog.fedoraproject.org/fedora-documentation-translations-again-available/">Fedora Documentation translations again available</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </content>
    <updated>2026-06-26T09:19:27Z</updated>
    <published>2026-06-26T09:19:27Z</published>
    <category term="Fedora Project Community"/>
    <category term="documentation"/>
    <category term="localization (l10n)"/>
    <author>
      <name>peartown</name>
    </author>
    <source>
      <id>https://communityblog.fedoraproject.org/</id>
      <logo>https://communityblog.fedoraproject.org/wp-content/uploads/2022/07/favicon-fedora-commblog.png</logo>
      <link href="https://communityblog.fedoraproject.org/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://communityblog.fedoraproject.org/" rel="alternate" type="text/html"/>
      <subtitle>The Community Blog provides a single source for members of the community to share important news, updates, and information about Fedora with others in the Project community.</subtitle>
      <title>Fedora Community Blog</title>
      <updated>2026-07-03T10:34:22Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://www.happyassassin.net/posts/2026/06/26/flock-2026-and-devconfcz-2026-trip-report/</id>
    <link href="https://www.happyassassin.net/posts/2026/06/26/flock-2026-and-devconfcz-2026-trip-report/" rel="alternate" type="text/html"/>
    <title xml:lang="en">Flock 2026 and Devconf.cz 2026 trip report</title>
    <summary type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><p>Long time no blog, once again - as always, I'm mostly posting on <a href="https://fosstodon.org/@adamw">Mastodon</a> now, so follow there if you're missing the Content. This is a bit big, though, so it goes here!</p>
<p>I was in Prague for <a href="https://fedoraproject.org/flock/2026/">Flock 2026</a> and Brno for <a href="https://www.devconf.info/cz/">Devconf.cz 2026</a> recently. Didn't have any issues with travel, fortunately. I was in Prague a day early for a Red Hat "face-to-face", which went fine. Had a fairly quiet/jetlagged dinner with Kevin and Tomas on the first night, and a nice dinner with Lenka Segura, Kashyap Chamarthy, Cristian Le, Frantisek Lehman and Laura Barcziova on the second night; most of them I was meeting for the first time in person, which is always good.</p>
<h3>Flock 2026</h3>
<p>Flock started for real the next day with workshops. I started with "The Future of Fedora Atomic", about how we can reach the goal of all the Atomic images being based on a shared bootc base container, then went to "Forging Fedora Project’s Future With Forgejo". In the afternoon I went to "PR-based Gating for Fedora: Can We Make It Work?", which was about the idea of moving all automated testing/gating to run against dist-git pull requests (instead of mainly against updates, as is the current case).</p>
<p>These were all more "talking shops" than "workshops", really, but they at least mostly produced interesting conversations and concrete ideas. In particular, Cristian and I were able to determine a set of priorities for Fedora CI from the "PR-based gating" session - there was a lot of discussion of potential issues and concerns further down the road of the potential migration, but in the end we found it pretty clear that we need to improve the reliability of the existing tests and pipelines, and the ease of interpreting the results, and that's uncontroversial work that can be done first.</p>
<p>There was also a request from Petr Khartskhaev that we make it possible to run the openQA tests on dist-git pull requests. This had already been <a href="https://forge.fedoraproject.org/quality/fedora_openqa/issues/104">requested by Mo Duffy</a> before. I've resisted doing this for all dist-git pull requests because I know at least some would fail when changes to multiple packages need to be grouped and tested together. The update system allows us to group builds into updates, but dist-git does not yet have any way to mark multiple PRs as a logical group for testing/promotion. However, someone suggested a better idea: do it by request, not for all PRs automatically. So I decided to go ahead and do it. Instead of doing another workshop, I hid in the corner of the "Languages in Floss" session and bodged up a working prototype, which is deployed to staging openQA. If you comment <code>/openqa test</code> on a dist-git pull request, tests on it will run in staging openQA. I'm currently working on getting the results reliably reported back to the pull request.</p>
<p>We had a team dinner that evening, again good to meet people and a good mix of work and social chat. At some point in there I met our relatively new RH team member Jaroslav Groman in-person for the first time, which was great - he's been doing excellent work on digging out from under our tooling tech debt and it's great to have him aboard. Peter Sklenar unfortunately wasn't able to come this time.</p>
<p>Day two was session heavy. There was an opening keynote track with Jef's "State of Fedora" address, live Fedora Council and FESCo meetings (effectively), and a Hummingbird talk from Stef Walter. The State of Fedora produced a couple of very talked-about sets of statistics, one showing Fedora (and friends) usage climbing solidly and one showing Fedora contributor numbers declining worryingly. The usage numbers are great, of course - especially the rapidly-growing numbers for KDE and our awesome downstream distro friends (the uBlue-verse, Asahi, Bazzite et. al.) We definitely need to dig into the contributor numbers some more, see what's going on, and whether and what we need to do to reverse the trend. There are a lot of interesting questions about whether it's Red Hatters, community maintainers, or both who are declining, and how this relates to other trends like the CVE tsunami, mushrooming language ecosystems, the rise of Flatpaks / Snaps / AppImages and so on.</p>
<p>The Council and FESCo sessions touched on those topics and several others, though interestingly not the AI Desktop proposal which I was kinda expecting to hear a lot about. I kinda tuned out and hacked through some of them to be honest. Stef's talk gave a good clear overview of Hummingbird - I kinda knew it going in, but it's always good to have it summarized quickly and clearly (at least I thought so).</p>
<p>I unfortunately didn't know about the Lunch and Learns (somehow missed them on the schedule), or else I would have gone to some! But still had plenty of fun/productive lunches with various folks. In particular I met Vít Smolík (smoliicek) in person, which was great. He's been helping out with the data team and infrastructure team and is doing some great work.</p>
<p>In the afternoon I went to the "Packit and Fedora: The CI Story Continues" talk, which was a good summary of the work to rationalize the mess of different systems we have/had testing pull requests. It's much better than it was before. Then I went to "Fedora Server – What you can expect from the next two releases", which was great because it clearly explained the idea of the "Home Server" spinoff which I hadn't really been clear on. And of course it was good to see Peter Boy and Emmanuel Seyman again. Alexander Bokovoy also explained his latest authentication stuff, which as always I didn't entirely understand but filed under "sounds like Alexander has it under control"...</p>
<p>I skipped another session to do some hacking, then went to "The Engineer’s Guide to Design", which was really interesting - I like going to slightly off-the-beaten-path talks. I don't really work on front-end UX stuff a lot, but it was still interesting to hear a perspective from someone who's been both an engineer and a designer on the impedance mismatches that can happen and the basic concepts it's useful for both sides to know about the other. Then I saw "Artifact Signing in Fedora", where Jeremy Cline gave some background and an overview of his ongoing project to rewrite the Fedora signing server, which is badly-needed work that we're really grateful for.</p>
<p>In the evening we had the official party, at a really nice outdoor food court with a reserved space for the conference. The organizers brought over so many appetizers I barely needed to use the meal ticket, but managed to force down some tacos nevertheless. Had a great time chatting with various folks, then later headed to a Belgian beer bar for more drinks with Justin Forbes and several others.</p>
<p>On the final day I started with "The Packager's Guide to openQA Failures" of course - Lukas Ruzicka (my openQA henchman) did a great job covering openQA failure analysis from the perspective of a packager, and I contributed a few notes here and there. We had a good crowd who seemed really interested, which is always great news. After that I saw Kevin Fenzi's "scrapers gotta scrape scrape scrape" talk on all the fun we've been having with scraper networks flooding our infrastructure. I know some but not all of it beforehand, and of course Kevin explained it well and the audience was very engaged. Plus I got to tell my story about the time I thought a dastardly new scraper network had figured out how to evade Anubis, but it turned out that the call was coming from inside the house (i.e. I had done a slightly silly thing in openQA which made it effectively DoS Koji...)</p>
<p>After the coffee break I saw "Fedora Test Days - a11y", which was actually a somewhat wider talk from a couple of RH folks working on accessibility testing about their current testing and future plans. It was really interesting and it was good to be able to speak with them briefly about the possibilities of using openQA for this. I stayed in the same room for "Two Years In: Accelerating Microsoft Contribution to Fedora", where Jeremy Cline, Brian Exelbierd and Reuben Olinsky covered some Microsoft's (much-welcomed) contributions to Fedora and also some stuff about Azure Linux.</p>
<p>After that was "Upgrading Fedora Infrastructure from Nagios to Zabbix" - this migration has been ongoing for a while but was much-needed as a modernization and also a better architecture. I found it very useful as I do have plans to add more detailed monitoring of openQA and the talk was very helpful in letting me know how to get started with that.</p>
<p>After lunch came lightning talks. I had proposed one about "new stuff we did in Fedora CI lately", which kinda overlapped with some of the full-length talks in the end, but it still got a lot of votes, so Cristian Le and I went up second and did a rapid redux of the Packit consolidation work, improved result displays, optimizations and improvements to the generic tests, addition of rmdepcheck and so on. My voice was giving out by this point but we just about got through it. There were a lot of other great talks and everyone managed to come in under time, which was impressive.</p>
<p>After that was a Fedora Mindshare session which I half-followed and half-hacked/dozed through (was starting to get tired at this point!), then the "Fedora’s Contributor Recognition Program" session where much-deserved awards were handed out to Ankur Sinha, Fabio Valentini and Justin Forbes. I was on the voting panel for this so it was great to see the culmination, and the trophies contributed by the Nairobi GNU/Linux Users Group were awesome.</p>
<p>I almost forgot to mention the whole time I was struggling with some sort of wifi driver bug - it seems there was a troublesome AP or something at the hotel which caused my laptop to crash constantly. And the hotel wifi was terrible, and I only had 5GB of data on my phone, so I couldn't really rebase to F44 to avoid it. Lots of fun.</p>
<h3>Devconf.cz 2026</h3>
<p>That was the end of Flock; things wound down and I had dinner with...some people...somewhere (possibly the third Vietnamese of the trip? Things are getting fuzzy). The next day was a welcome quiet day traveling from Prague to Brno - train and bus, no problem except waiting for the bus was very hot. I stayed at the Hotel Vaka, which I've never been at before, but it's quite nice. The whole event was a bit weird because Moto GP (the motorbike equivalent of Formula 1) moved their Brno race to the same weekend Devconf.cz would usually be on, and took all the hotels, so devconf was hastily moved to Thursday/Friday. Hotels were still hard to get and I only just managed to grab this one at a decent rate. I was able to rebase my laptop finally and stop worrying about wifi crashes, and had a nice quiet pizza dinner at Doe Boy.</p>
<p>So a shortened devconf started with the opening session, then another Hummingbird keynote, this time with Valentin Rothberg as well as Stef Walter. It added a bit of detail compared to Stef's Flock talk, and there wasn't anything else on. Then I saw "OpenShift CI: What if we stopped retesting everything all the time?", which was an interesting talk about the tradeoffs involved in doing automatic retests of complex merge chains in a big project with lots of PRs trying to be merged all the time (OpenShift). It wasn't directly applicable to anything I do, exactly - Fedora updates don't quite map to PRs in a git repo - but in a more general sense it was useful in suggesting methods for thinking about this kind of complex tradeoff and how to measure the impact and efficiency of testing processes.</p>
<p>Next I saw David Duncan's "From Laptop Chaos to Fedora Cloud: Quadlets and Containers", mainly because it was David, but it turned out to be a good talk about a way to make a relatively complex multi-container side project buildable and deployable the same way on your laptop and in The Cloud, using systemd quadlets. I've dealt with this general area before a few times. David made a solid case that quadlets are a good approach, in his usual fun and personable style.</p>
<p>After that I saw Zbigniew's "New security features in systemd" - honestly I missed some of this one, but got the gist of why systemd is trying to modernize various mechanisms here. Then I went to "Beyond the Screen: A Deep Dive into Linux Accessibility for Developers" by Vojtech Polasek, which was one of my highlights of the week - a really good explanation of how computer interaction really works for blind people, and what properties applications should have (and avoid) to make them usable. This is obviously very important for testing purposes.</p>
<p>Next I went to "Stop Looking for the Perfect Prompt: The Design-First Workflow for Coding Agents" to get my corporate mandatory minimum AI Content(tm) - it was actually a pretty good and accessible talk on different approaches to LLM-based feature development. I still don't really use LLM code generation heavily (for a start, I spend so little time actually sitting at a blank screen typing significant amounts of code that it's not really worth worrying about), but it's good to keep up with the latest ideas about how to do this kinda thing. Continuing with the AI theme I took in Tomas Tomecek and Laura Barcziova's "How AI helped us ship updates in a Linux distro", which was a practical talk on the system behind Hummingbird and the actual approach it takes to (sort-of) AI-driven package builds.</p>
<p>After that I think I did some Fedora booth cover for a while. Lukas Ruzicka and Vojtech Trefny were holding the booth down for most of the weekend, but I stopped by and did an hour here and there to give them some relief. It's always a lot of fun chatting to people about Fedora, other distributions or stuff that has nothing to do with Linux at all. Lukas had set up a Framework laptop with a MIDI keyboard attached to show off that it's pretty practical to do audio creation on stock Fedora kernel and audio stack these days; Vojtech and I had absolutely no idea how to use it, so we had lots of fun trying to talk about it to people and eventually telling them to come back when Lukas would be there...</p>
<p>In the evening we had the conference party, which was at the same outdoor swimming pool it's been at for a couple of years(?) now. It's a great venue - you can grab some food and a drink and then relax in the shade under some trees. I wound up sitting round with a really interesting mixed group of folks (Red Hat and non-Red Hat, some big cheeses, some medium-size cheeses and some fresh faced...cheese curds? Help, my metaphor is falling apart) most of the night, it was a great evening. Walked back most of the way to the hotel with Stef Walter, setting the world to rights as is the tradition after a few drinks at conference parties...</p>
<p>On the second day I started with "From Podman to Production: Building Trusted Container Images with Konflux on OpenShift" by Vladimir Sokolenko, which was probably the most understandable and useful Konflux talk I've seen so far. I think I then maybe did a bit more booth cover(?) and some hacking, then wrapped up with a nice three-talk track in the same room - "Identical Testing Environments from Laptop to CI with tmt and Testing Farm" by Cristian and Petr Šplíchal (covering their work to make tests more reproducible from Testing Farm to your local system), "systemd-sysext in Production: What We Learned Extending /usr Without a Package Manager" by Brian Exelbierd and Daniel Zaťovič (a really good retrospective on their experience using sysext in the real world to ship additional / alternative software on Flatcar), and "Local package layering on bootc systems with DNF5" by Evan Goode (explaining his design and plans for providing a convenient, dnf-ish interface to "overlaying" packages on bootc-based installs). I met Evan in person for the first time at the party, and it was great talking to him. I hope his work on this goes well - we really need it for the glorious bootc-based future.</p>
<p>After that was the traditional wrap-up session with the trivia quiz (I won a t-shirt!) and then I said bye to a lot of people and melted off (it was extremely hot) to the train station...to find that my train to Vienna was delayed by nearly an hour. Ah, well. Eventually made it to my hotel in Vienna (which was incredibly nice, just wish I'd stayed there longer...) and had an excellent dinner at Iki (highly recommended if you're in the area). Got in a couple of swims in the nice-but-small hotel pool before and after sleeping, then had a Vienna take on avocado toast (interesting!) for breakfast and headed off to the airport, and that was another trip in the books.</p></div>
    </summary>
    <content type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><p>Long time no blog, once again - as always, I'm mostly posting on <a href="https://fosstodon.org/@adamw">Mastodon</a> now, so follow there if you're missing the Content. This is a bit big, though, so it goes here!</p>
<p>I was in Prague for <a href="https://fedoraproject.org/flock/2026/">Flock 2026</a> and Brno for <a href="https://www.devconf.info/cz/">Devconf.cz 2026</a> recently. Didn't have any issues with travel, fortunately. I was in Prague a day early for a Red Hat "face-to-face", which went fine. Had a fairly quiet/jetlagged dinner with Kevin and Tomas on the first night, and a nice dinner with Lenka Segura, Kashyap Chamarthy, Cristian Le, Frantisek Lehman and Laura Barcziova on the second night; most of them I was meeting for the first time in person, which is always good.</p>
<h3>Flock 2026</h3>
<p>Flock started for real the next day with workshops. I started with "The Future of Fedora Atomic", about how we can reach the goal of all the Atomic images being based on a shared bootc base container, then went to "Forging Fedora Project’s Future With Forgejo". In the afternoon I went to "PR-based Gating for Fedora: Can We Make It Work?", which was about the idea of moving all automated testing/gating to run against dist-git pull requests (instead of mainly against updates, as is the current case).</p>
<p>These were all more "talking shops" than "workshops", really, but they at least mostly produced interesting conversations and concrete ideas. In particular, Cristian and I were able to determine a set of priorities for Fedora CI from the "PR-based gating" session - there was a lot of discussion of potential issues and concerns further down the road of the potential migration, but in the end we found it pretty clear that we need to improve the reliability of the existing tests and pipelines, and the ease of interpreting the results, and that's uncontroversial work that can be done first.</p>
<p>There was also a request from Petr Khartskhaev that we make it possible to run the openQA tests on dist-git pull requests. This had already been <a href="https://forge.fedoraproject.org/quality/fedora_openqa/issues/104">requested by Mo Duffy</a> before. I've resisted doing this for all dist-git pull requests because I know at least some would fail when changes to multiple packages need to be grouped and tested together. The update system allows us to group builds into updates, but dist-git does not yet have any way to mark multiple PRs as a logical group for testing/promotion. However, someone suggested a better idea: do it by request, not for all PRs automatically. So I decided to go ahead and do it. Instead of doing another workshop, I hid in the corner of the "Languages in Floss" session and bodged up a working prototype, which is deployed to staging openQA. If you comment <code>/openqa test</code> on a dist-git pull request, tests on it will run in staging openQA. I'm currently working on getting the results reliably reported back to the pull request.</p>
<p>We had a team dinner that evening, again good to meet people and a good mix of work and social chat. At some point in there I met our relatively new RH team member Jaroslav Groman in-person for the first time, which was great - he's been doing excellent work on digging out from under our tooling tech debt and it's great to have him aboard. Peter Sklenar unfortunately wasn't able to come this time.</p>
<p>Day two was session heavy. There was an opening keynote track with Jef's "State of Fedora" address, live Fedora Council and FESCo meetings (effectively), and a Hummingbird talk from Stef Walter. The State of Fedora produced a couple of very talked-about sets of statistics, one showing Fedora (and friends) usage climbing solidly and one showing Fedora contributor numbers declining worryingly. The usage numbers are great, of course - especially the rapidly-growing numbers for KDE and our awesome downstream distro friends (the uBlue-verse, Asahi, Bazzite et. al.) We definitely need to dig into the contributor numbers some more, see what's going on, and whether and what we need to do to reverse the trend. There are a lot of interesting questions about whether it's Red Hatters, community maintainers, or both who are declining, and how this relates to other trends like the CVE tsunami, mushrooming language ecosystems, the rise of Flatpaks / Snaps / AppImages and so on.</p>
<p>The Council and FESCo sessions touched on those topics and several others, though interestingly not the AI Desktop proposal which I was kinda expecting to hear a lot about. I kinda tuned out and hacked through some of them to be honest. Stef's talk gave a good clear overview of Hummingbird - I kinda knew it going in, but it's always good to have it summarized quickly and clearly (at least I thought so).</p>
<p>I unfortunately didn't know about the Lunch and Learns (somehow missed them on the schedule), or else I would have gone to some! But still had plenty of fun/productive lunches with various folks. In particular I met Vít Smolík (smoliicek) in person, which was great. He's been helping out with the data team and infrastructure team and is doing some great work.</p>
<p>In the afternoon I went to the "Packit and Fedora: The CI Story Continues" talk, which was a good summary of the work to rationalize the mess of different systems we have/had testing pull requests. It's much better than it was before. Then I went to "Fedora Server – What you can expect from the next two releases", which was great because it clearly explained the idea of the "Home Server" spinoff which I hadn't really been clear on. And of course it was good to see Peter Boy and Emmanuel Seyman again. Alexander Bokovoy also explained his latest authentication stuff, which as always I didn't entirely understand but filed under "sounds like Alexander has it under control"...</p>
<p>I skipped another session to do some hacking, then went to "The Engineer’s Guide to Design", which was really interesting - I like going to slightly off-the-beaten-path talks. I don't really work on front-end UX stuff a lot, but it was still interesting to hear a perspective from someone who's been both an engineer and a designer on the impedance mismatches that can happen and the basic concepts it's useful for both sides to know about the other. Then I saw "Artifact Signing in Fedora", where Jeremy Cline gave some background and an overview of his ongoing project to rewrite the Fedora signing server, which is badly-needed work that we're really grateful for.</p>
<p>In the evening we had the official party, at a really nice outdoor food court with a reserved space for the conference. The organizers brought over so many appetizers I barely needed to use the meal ticket, but managed to force down some tacos nevertheless. Had a great time chatting with various folks, then later headed to a Belgian beer bar for more drinks with Justin Forbes and several others.</p>
<p>On the final day I started with "The Packager's Guide to openQA Failures" of course - Lukas Ruzicka (my openQA henchman) did a great job covering openQA failure analysis from the perspective of a packager, and I contributed a few notes here and there. We had a good crowd who seemed really interested, which is always great news. After that I saw Kevin Fenzi's "scrapers gotta scrape scrape scrape" talk on all the fun we've been having with scraper networks flooding our infrastructure. I know some but not all of it beforehand, and of course Kevin explained it well and the audience was very engaged. Plus I got to tell my story about the time I thought a dastardly new scraper network had figured out how to evade Anubis, but it turned out that the call was coming from inside the house (i.e. I had done a slightly silly thing in openQA which made it effectively DoS Koji...)</p>
<p>After the coffee break I saw "Fedora Test Days - a11y", which was actually a somewhat wider talk from a couple of RH folks working on accessibility testing about their current testing and future plans. It was really interesting and it was good to be able to speak with them briefly about the possibilities of using openQA for this. I stayed in the same room for "Two Years In: Accelerating Microsoft Contribution to Fedora", where Jeremy Cline, Brian Exelbierd and Reuben Olinsky covered some Microsoft's (much-welcomed) contributions to Fedora and also some stuff about Azure Linux.</p>
<p>After that was "Upgrading Fedora Infrastructure from Nagios to Zabbix" - this migration has been ongoing for a while but was much-needed as a modernization and also a better architecture. I found it very useful as I do have plans to add more detailed monitoring of openQA and the talk was very helpful in letting me know how to get started with that.</p>
<p>After lunch came lightning talks. I had proposed one about "new stuff we did in Fedora CI lately", which kinda overlapped with some of the full-length talks in the end, but it still got a lot of votes, so Cristian Le and I went up second and did a rapid redux of the Packit consolidation work, improved result displays, optimizations and improvements to the generic tests, addition of rmdepcheck and so on. My voice was giving out by this point but we just about got through it. There were a lot of other great talks and everyone managed to come in under time, which was impressive.</p>
<p>After that was a Fedora Mindshare session which I half-followed and half-hacked/dozed through (was starting to get tired at this point!), then the "Fedora’s Contributor Recognition Program" session where much-deserved awards were handed out to Ankur Sinha, Fabio Valentini and Justin Forbes. I was on the voting panel for this so it was great to see the culmination, and the trophies contributed by the Nairobi GNU/Linux Users Group were awesome.</p>
<p>I almost forgot to mention the whole time I was struggling with some sort of wifi driver bug - it seems there was a troublesome AP or something at the hotel which caused my laptop to crash constantly. And the hotel wifi was terrible, and I only had 5GB of data on my phone, so I couldn't really rebase to F44 to avoid it. Lots of fun.</p>
<h3>Devconf.cz 2026</h3>
<p>That was the end of Flock; things wound down and I had dinner with...some people...somewhere (possibly the third Vietnamese of the trip? Things are getting fuzzy). The next day was a welcome quiet day traveling from Prague to Brno - train and bus, no problem except waiting for the bus was very hot. I stayed at the Hotel Vaka, which I've never been at before, but it's quite nice. The whole event was a bit weird because Moto GP (the motorbike equivalent of Formula 1) moved their Brno race to the same weekend Devconf.cz would usually be on, and took all the hotels, so devconf was hastily moved to Thursday/Friday. Hotels were still hard to get and I only just managed to grab this one at a decent rate. I was able to rebase my laptop finally and stop worrying about wifi crashes, and had a nice quiet pizza dinner at Doe Boy.</p>
<p>So a shortened devconf started with the opening session, then another Hummingbird keynote, this time with Valentin Rothberg as well as Stef Walter. It added a bit of detail compared to Stef's Flock talk, and there wasn't anything else on. Then I saw "OpenShift CI: What if we stopped retesting everything all the time?", which was an interesting talk about the tradeoffs involved in doing automatic retests of complex merge chains in a big project with lots of PRs trying to be merged all the time (OpenShift). It wasn't directly applicable to anything I do, exactly - Fedora updates don't quite map to PRs in a git repo - but in a more general sense it was useful in suggesting methods for thinking about this kind of complex tradeoff and how to measure the impact and efficiency of testing processes.</p>
<p>Next I saw David Duncan's "From Laptop Chaos to Fedora Cloud: Quadlets and Containers", mainly because it was David, but it turned out to be a good talk about a way to make a relatively complex multi-container side project buildable and deployable the same way on your laptop and in The Cloud, using systemd quadlets. I've dealt with this general area before a few times. David made a solid case that quadlets are a good approach, in his usual fun and personable style.</p>
<p>After that I saw Zbigniew's "New security features in systemd" - honestly I missed some of this one, but got the gist of why systemd is trying to modernize various mechanisms here. Then I went to "Beyond the Screen: A Deep Dive into Linux Accessibility for Developers" by Vojtech Polasek, which was one of my highlights of the week - a really good explanation of how computer interaction really works for blind people, and what properties applications should have (and avoid) to make them usable. This is obviously very important for testing purposes.</p>
<p>Next I went to "Stop Looking for the Perfect Prompt: The Design-First Workflow for Coding Agents" to get my corporate mandatory minimum AI Content(tm) - it was actually a pretty good and accessible talk on different approaches to LLM-based feature development. I still don't really use LLM code generation heavily (for a start, I spend so little time actually sitting at a blank screen typing significant amounts of code that it's not really worth worrying about), but it's good to keep up with the latest ideas about how to do this kinda thing. Continuing with the AI theme I took in Tomas Tomecek and Laura Barcziova's "How AI helped us ship updates in a Linux distro", which was a practical talk on the system behind Hummingbird and the actual approach it takes to (sort-of) AI-driven package builds.</p>
<p>After that I think I did some Fedora booth cover for a while. Lukas Ruzicka and Vojtech Trefny were holding the booth down for most of the weekend, but I stopped by and did an hour here and there to give them some relief. It's always a lot of fun chatting to people about Fedora, other distributions or stuff that has nothing to do with Linux at all. Lukas had set up a Framework laptop with a MIDI keyboard attached to show off that it's pretty practical to do audio creation on stock Fedora kernel and audio stack these days; Vojtech and I had absolutely no idea how to use it, so we had lots of fun trying to talk about it to people and eventually telling them to come back when Lukas would be there...</p>
<p>In the evening we had the conference party, which was at the same outdoor swimming pool it's been at for a couple of years(?) now. It's a great venue - you can grab some food and a drink and then relax in the shade under some trees. I wound up sitting round with a really interesting mixed group of folks (Red Hat and non-Red Hat, some big cheeses, some medium-size cheeses and some fresh faced...cheese curds? Help, my metaphor is falling apart) most of the night, it was a great evening. Walked back most of the way to the hotel with Stef Walter, setting the world to rights as is the tradition after a few drinks at conference parties...</p>
<p>On the second day I started with "From Podman to Production: Building Trusted Container Images with Konflux on OpenShift" by Vladimir Sokolenko, which was probably the most understandable and useful Konflux talk I've seen so far. I think I then maybe did a bit more booth cover(?) and some hacking, then wrapped up with a nice three-talk track in the same room - "Identical Testing Environments from Laptop to CI with tmt and Testing Farm" by Cristian and Petr Šplíchal (covering their work to make tests more reproducible from Testing Farm to your local system), "systemd-sysext in Production: What We Learned Extending /usr Without a Package Manager" by Brian Exelbierd and Daniel Zaťovič (a really good retrospective on their experience using sysext in the real world to ship additional / alternative software on Flatcar), and "Local package layering on bootc systems with DNF5" by Evan Goode (explaining his design and plans for providing a convenient, dnf-ish interface to "overlaying" packages on bootc-based installs). I met Evan in person for the first time at the party, and it was great talking to him. I hope his work on this goes well - we really need it for the glorious bootc-based future.</p>
<p>After that was the traditional wrap-up session with the trivia quiz (I won a t-shirt!) and then I said bye to a lot of people and melted off (it was extremely hot) to the train station...to find that my train to Vienna was delayed by nearly an hour. Ah, well. Eventually made it to my hotel in Vienna (which was incredibly nice, just wish I'd stayed there longer...) and had an excellent dinner at Iki (highly recommended if you're in the area). Got in a couple of swims in the nice-but-small hotel pool before and after sleeping, then had a Vienna take on avocado toast (interesting!) for breakfast and headed off to the airport, and that was another trip in the books.</p></div>
    </content>
    <updated>2026-06-26T08:45:01Z</updated>
    <published>2026-06-26T08:45:01Z</published>
    <category label="Fedora" term="fedora"/>
    <category label="QA" term="qa"/>
    <category label="Red Hat" term="red-hat"/>
    <category label="Technical" term="technical"/>
    <author>
      <name>Adam Williamson</name>
    </author>
    <source>
      <id>https://www.happyassassin.net/categories/fedora.atom</id>
      <author>
        <name>Adam Williamson</name>
      </author>
      <link href="https://www.happyassassin.net/categories/fedora.atom" rel="self" type="application/atom+xml"/>
      <link href="https://www.happyassassin.net/categories/fedora/" rel="alternate" type="text/html"/>
      <title xml:lang="en">AdamW on Linux and more (Posts about Fedora)</title>
      <updated>2026-06-30T17:59:20Z</updated>
    </source>
  </entry>

  <entry>
    <id>tag:0pointer.net,2026-06-26:/blog/mastodon-stories-for-systemd-v261.html</id>
    <link href="https://0pointer.net/blog/mastodon-stories-for-systemd-v261.html" rel="alternate" type="text/html"/>
    <title>Mastodon Stories for systemd v261</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>On June 19 we released systemd v261 <a href="https://github.com/systemd/systemd/releases/tag/v261">into the wild</a>.</p>
<p>In the weeks leading up to that release (and since then) I have posted
a series of serieses of posts to Mastodon about key new features in
this release, under the
<a href="https://mastodon.social/@pid_eins/tagged/systemd261">#systemd261</a>
hash tag. In case you aren't using Mastodon, but would like to
read up, here's a list of all 27 posts:</p>
<ul>
<li>Post #1: <a href="https://mastodon.social/@pid_eins/116607692020022018">El-Torito/ISO9660 Support in systemd-repart</a></li>
<li>Post #2: <a href="https://mastodon.social/@pid_eins/116615778195697145"><code>ConditionFraction=</code></a></li>
<li>Post #3: <a href="https://mastodon.social/@pid_eins/116617644793569381">Minimal Uptime</a></li>
<li>Post #4: <a href="https://mastodon.social/@pid_eins/116633389362667768">Automatic <code>console=</code> Initialization from UEFI</a></li>
<li>Post #5: <a href="https://mastodon.social/@pid_eins/116638924039845225"><code>bootctl link</code></a></li>
<li>Post #6: <a href="https://mastodon.social/@pid_eins/116645677562108979">Importing UEFI Keyboard/Language Settings into the OS</a></li>
<li>Post #7: <a href="https://mastodon.social/@pid_eins/116655748120752678"><code>systemd-sysinstall</code></a></li>
<li>Post #8: <a href="https://mastodon.social/@pid_eins/116673740043704088">Machine Tags</a></li>
<li>Post #9: <a href="https://mastodon.social/@pid_eins/116679111124902335">IMDS Support</a></li>
<li>Post #10: <a href="https://mastodon.social/@pid_eins/116690764422695599">Boot Secrets</a></li>
<li>Post #11: <a href="https://mastodon.social/@pid_eins/116696052327559444">Automatic Software TPM Support</a></li>
<li>Post #12: <a href="https://mastodon.social/@pid_eins/116753924804869335"><code>systemd-boot</code> A/B</a></li>
<li>Post #13: <a href="https://mastodon.social/@pid_eins/116758484410142874">Sector Size Adjustment for Boot Block Devices</a></li>
<li>Post #14: <a href="https://mastodon.social/@pid_eins/116764071057182292"><code>kexec</code> Handover</a></li>
<li>Post #15: <a href="https://mastodon.social/@pid_eins/116769750527388972"><code>systemd-repart</code>'s <code>BlockDeviceReplace=</code></a></li>
<li>Post #16: <a href="https://mastodon.social/@pid_eins/116775662733506237"><code>.rr</code> Drop-ins for <code>systemd-resolved</code></a></li>
<li>Post #17: <a href="https://mastodon.social/@pid_eins/116781725056986053"><code>systemd-report-cgroup</code> &amp; <code>systemd-report-basic</code></a></li>
<li>Post #18: <a href="https://mastodon.social/@pid_eins/116781776665322560">No More Shared Libray Linking</a></li>
<li>Post #19: <a href="https://mastodon.social/@pid_eins/116786475471438132">IO &amp; CPU Pressure Handling</a></li>
<li>Post #20: <a href="https://mastodon.social/@pid_eins/116786512227450393"><code>varlinkctl serve</code></a></li>
<li>Post #21: <a href="https://mastodon.social/@pid_eins/116792353769778328">Separator &amp; SMBIOS Measurements</a></li>
<li>Post #22: <a href="https://mastodon.social/@pid_eins/116792552048067669">BPF-LSM Based File System Security</a></li>
<li>Post #23: <a href="https://mastodon.social/@pid_eins/116803790296454733">Application of <code>confext</code>&amp; <code>sysext</code>from the <code>Ã¬nitrd</code></a></li>
<li>Post #24: <a href="https://mastodon.social/@pid_eins/116810163029063553"><code>extra</code> stanza in UAPI.1 Boot Loader Specification</a></li>
<li>Post #25: <a href="https://mastodon.social/@pid_eins/116810198261688951">PROXY-v1 Protocol Support</a></li>
<li>Post #26: <a href="https://mastodon.social/@pid_eins/116815011984716268">Storage Providers</a></li>
<li>Post #27: <a href="https://mastodon.social/@pid_eins/116815651358639632"><code>systemd-oomd</code> Rules FIles</a></li>
</ul>
<p>I intend to do a similar series of serieses of posts for the next
systemd release (v262), hence if you haven't left tech Twitter for
Mastodon yet, now is the opportunity. My series for v262 will begin in
a few weeks most likely, under the
<a href="https://mastodon.social/@pid_eins/tagged/systemd262">#systemd262</a>
hash tag.</p>
<p>In case you are interested, <a href="https://0pointer.net/blog/mastodon-stories-for-systemd-v260.html">here is the corresponding blog story for
systemd v260</a>,
<a href="https://0pointer.net/blog/mastodon-stories-for-systemd-v259.html">here for
v259</a>,
<a href="https://0pointer.net/blog/mastodon-stories-for-systemd-v258.html">here for
v258</a>,
<a href="https://0pointer.net/blog/announcing-systemd-v257.html">here for
v257</a>,
and <a href="https://0pointer.net/blog/announcing-systemd-v256.html">here for
v256</a>.</p></div>
    </summary>
    <updated>2026-06-25T22:00:00Z</updated>
    <published>2026-06-25T22:00:00Z</published>
    <category term="projects"/>
    <author>
      <name>Lennart Poettering</name>
    </author>
    <source>
      <id>https://0pointer.net/blog/</id>
      <link href="https://0pointer.net/blog/" rel="alternate" type="text/html"/>
      <link href="https://0pointer.net/blog/index.rss20" rel="self" type="application/rss+xml"/>
      <title>Pid Eins</title>
      <updated>2026-06-25T22:00:00Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://communityblog.fedoraproject.org/?p=15774</id>
    <link href="https://communityblog.fedoraproject.org/fedora-at-xv-p-i-w-o-poznan-free-software-fest/" rel="alternate" type="text/html"/>
    <title>Fedora at XV P.I.W.O. Poznań Free Software Fest</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>On Saturday May 30th 2026, the XV edition of P.I.W.O. PoznaÅ„ Free Software Fest was held in PoznaÅ„, ğŸ‡µğŸ‡± Poland. The Fedora Community was there!</p>
<p>The post <a href="https://communityblog.fedoraproject.org/fedora-at-xv-p-i-w-o-poznan-free-software-fest/">Fedora at XV P.I.W.O. PoznaÅ„ Free Software Fest</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">On Saturday May 30th 2026, the XV edition of P.I.W.O. PoznaÅ„ Free Software Fest was held in PoznaÅ„, <img alt="&#x11F;&#x178;&#x2021;&#xB5;&#x11F;&#x178;&#x2021;&#xB1;" class="wp-smiley" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f1f5-1f1f1.png" style="height: 1em;"/> Poland.</p>



<p class="wp-block-paragraph">P.I.W.O. is an event with a long history. Between 2004 and 2018, it was organized by various student associations at the PoznaÅ„ University of Technology. After 2018’s XIII edition (superstition much?), it entered a long hiatus that lasted until 2025, when members of the newly-formed Knyfyrtel PoznaÅ„ Hackerspace decided to bring it back. The reactivated event proved a huge success, with the XIV edition bringing in 197 attendees. As such, ambitions for 2026 were rather big. </p>



<span id="more-15774"/>



<h2 class="wp-block-heading">Teamwork makes the dream work</h2>



<p class="wp-block-paragraph">This year’s edition was the result of combined efforts of three PoznaÅ„-based organizations:</p>



<ul class="wp-block-list">
<li><a href="https://hspoz.pl">Knyfyrtel Hackerspace PoznaÅ„</a></li>



<li><a href="https://www.facebook.com/profile.php?id=61573212265863">“Webrains” Students’ Scientific Association</a> at the Adam Mickiewicz University</li>



<li><a href="https://lag.edu.pl/">“Linux Academic Group” Students’ Scientific Association</a> at the PoznaÅ„ University of Technology</li>
</ul>



<figure class="wp-block-image size-full"><img alt="Photo of the organizing team, with 26 people visible in the picture. That's not the whole team!" class="wp-image-15812" height="683" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/1000005174.jpg" width="1024"/></figure>



<p class="wp-block-paragraph">Thanks to Webrains, for the first time in its history, the event was held at the Adam Mickiewicz University in PoznaÅ„ – namely, the uni’s Faculty of Mathematics and Computer Science. Also a historical first, the XV edition was granted honorary patronage by the President of PoznaÅ„ City Council.</p>



<h2 class="wp-block-heading">Busy, busy day</h2>



<p class="wp-block-paragraph">The event spanned almost the entire Saturday, opening at 9:30 am and closing at 7:35 pm. The agenda was tightly packed, featuring 3 lecture tracks with 24 talks, 2 workshop tracks with 8 activities, plus a LAN Party track with 3 tournaments, as well as “free play” sessions. There was also a quiet corner where, thanks to the “Honte” group, attendees could relax and learn to play Go.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img alt="Photo of one of the lecture halls." class="wp-image-15808" height="683" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/DSC_3356-1024x683.jpg" width="1024"/></figure>



<figure class="wp-block-image size-large"><img alt="Photo of one of the workshop sessions." class="wp-image-15809" height="683" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/DSC_3728-1024x683.jpg" width="1024"/></figure>



<figure class="wp-block-image size-large"><img alt="Photo of one of the LAN Party tournaments, with the attendees playing Xonotic." class="wp-image-15807" height="683" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/DSC_3661-1024x683.jpg" width="1024"/></figure>
</figure>



<p class="wp-block-paragraph">Throughout the years, one of P.I.W.O.’s hallmarks was the lunch break, with the attendees being provided free pizza. This year couldn’t be any different, with some 66mÂ² (or 710 ftÂ²) of pizza being delivered to the venue. (It disappeared frighteningly quick.)</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img alt="Photo of the event hall, with the organizers setting up tables with pizza." class="wp-image-15811" height="682" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/pizza0-1024x682.jpeg" width="1024"/></figure>



<figure class="wp-block-image size-large"><img alt="Focus photo of one of the organizers bringing in 5 boxes of pizza." class="wp-image-15810" height="682" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/pizza1-1024x682.jpeg" width="1024"/></figure>
</figure>



<p class="wp-block-paragraph">The Fedora Community was represented by:</p>



<ul class="wp-block-list">
<li>Zbyszek JÄ™drzejewski-Szmek, who gave 2 (!) talks</li>



<li>Mat Holmes, who volunteered as a photographer</li>



<li>Kacper SkrzyÅ„ski, who handled various urgent tasks</li>



<li>Artur Frenszek-Iwicki, who gave a talk and held a workshop session</li>
</ul>



<figure class="wp-block-image size-large"><img alt="Photo of (left to right) Artur, Mat and Zbyszek, standing behind a banner with the event's logo." class="wp-image-15799" height="512" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/DSC_4059_crop-1024x512.jpg" width="1024"/></figure>



<h2 class="wp-block-heading">Historical moment: creation of SPOIWO</h2>



<p class="wp-block-paragraph">This year’s P.I.W.O. served as an opportunity to announce the creation of SPOIWO – <em>Sojusz PrzyjaciÃ³Å‚ Otwartego i Wolnego Oprogramowania</em> (Alliance of Friends of Open and Free Software). This diverse coalition of social and technology organisations, cooperatives and open source businesses signed a declaration in support of digital sovereignty. The alliance was formed in response to the ever-deepening of public institutionsâ€™ dependency on closed platforms and their loss of control over data and communication.</p>



<figure class="wp-block-image size-large"><img alt="Group photo taken after the signing ceremony of the SPOIWO declaration. The printed declaration is visible in the back, propped up above the heads of the people in front." class="wp-image-15804" height="431" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/Y5NWliCe3pzMBEJCrzg4ADczIhtItaMzxtZjjIWr-1024x431.jpg" width="1024"/></figure>



<p class="wp-block-paragraph">The signing ceremony also featured speeches by representatives of SUSE Poland, Polish Linux User Group, â€œInternet. Czas dziaÅ‚aÄ‡!â€� Foundation and PLZ SpÃ³Å‚dzielnia.</p>



<h2 class="wp-block-heading">Exceeding all expectations</h2>



<p class="wp-block-paragraph">The event wrapped with 452 attendee badges issued, which exceeded even the most daring of expectations. (The number also explains why the pizza disappeared so quick.) The bar for the next edition is set high, but so are the organizing team’s ambitions. </p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img alt="Photo of the people gathering at the freebie table, taken from the upper balcony." class="wp-image-15817" height="691" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/people0-1024x691.jpeg" width="1024"/></figure>



<figure class="wp-block-image size-large"><img alt="Photo of the event hall, showing the mass of people present during the lunch break. Taken from the upper balcony." class="wp-image-15816" height="768" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/people1-1024x768.jpeg" width="1024"/></figure>



<figure class="wp-block-image size-large"><img alt="Photo of people gathering at the freebie table. Two banners are visible in the background: at the back, the event's old promotional banner; at the front, the &quot;All Creatures Welcome&quot; banner." class="wp-image-15815" height="1024" src="https://communityblog.fedoraproject.org/wp-content/uploads/2026/06/people2-759x1024.jpeg" width="759"/></figure>
</figure>



<p class="wp-block-paragraph">If you’d like to learn more about the event, watch the live stream recordings, or subscribe to news so you won’t miss the announcement for the XVI edition – you can do all of that on the event’s website, at <a href="https://piwo.sh">piwo.sh</a>.</p>
<p>The post <a href="https://communityblog.fedoraproject.org/fedora-at-xv-p-i-w-o-poznan-free-software-fest/">Fedora at XV P.I.W.O. PoznaÅ„ Free Software Fest</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </content>
    <updated>2026-06-25T10:18:38Z</updated>
    <published>2026-06-25T10:18:38Z</published>
    <category term="Fedora Project Community"/>
    <author>
      <name>Artur Frenszek-Iwicki</name>
    </author>
    <source>
      <id>https://communityblog.fedoraproject.org/</id>
      <logo>https://communityblog.fedoraproject.org/wp-content/uploads/2022/07/favicon-fedora-commblog.png</logo>
      <link href="https://communityblog.fedoraproject.org/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://communityblog.fedoraproject.org/" rel="alternate" type="text/html"/>
      <subtitle>The Community Blog provides a single source for members of the community to share important news, updates, and information about Fedora with others in the Project community.</subtitle>
      <title>Fedora Community Blog</title>
      <updated>2026-07-03T10:34:22Z</updated>
    </source>
  </entry>

  <entry>
    <id>tag:None,2026-06-24:/blog/kiwi-tcms-team/2026/06/24/kiwi-tcms-161/</id>
    <link href="https://kiwitcms.org/blog/kiwi-tcms-team/2026/06/24/kiwi-tcms-161/" rel="alternate" type="text/html"/>
    <title>Kiwi TCMS 16.1</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Dear testers, we're happy to announce Kiwi TCMS version 16.1!</p>
<p><strong>IMPORTANT:</strong></p>
<p>This is a minor version release which includes security related updates,
several improvements, database migrations, new API methods and updated translations.</p>
<p>You can explore everything at
<a class="reference external" href="https://public.tenant.kiwitcms.org/">https://public.tenant.kiwitcms.org</a>!</p>
<p>---</p>
<blockquote>
<p>Public container image (x86_64):</p>
<pre class="literal-block">pub.kiwitcms.eu â€¦</pre></blockquote></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Dear testers, we're happy to announce Kiwi TCMS version 16.1!</p>
<p><strong>IMPORTANT:</strong></p>
<p>This is a minor version release which includes security related updates,
several improvements, database migrations, new API methods and updated translations.</p>
<p>You can explore everything at
<a class="reference external" href="https://public.tenant.kiwitcms.org/">https://public.tenant.kiwitcms.org</a>!</p>
<p>---</p>
<blockquote>
<p>Public container image (x86_64):</p>
<pre class="literal-block">pub.kiwitcms.eu/kiwitcms/kiwi   latest  12fc270ef5b9    862MB
</pre>
</blockquote>
<p><strong>IMPORTANT:</strong> version tagged and multi-arch
<a class="reference external" href="https://kiwitcms.org/containers/">container images</a> are available only to
<a class="reference external" href="https://kiwitcms.org/#subscriptions">subscribers</a>!</p>
<div class="section" id="changes-since-kiwi-tcms-16-0">
<h2>Changes since Kiwi TCMS 16.0</h2>
<div class="section" id="security">
<h3>Security</h3>
<ul class="simple">
<li>Restrict open redirect. Fixes
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-hmj5-jm8h-h9fh">CVE-2026-54724</a></li>
<li>Validate user input in <tt class="docutils literal">extra_link</tt> fields. Fixes
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-473p-56xx-vg67">CVE-2026-55630</a></li>
</ul>
</div>
<div class="section" id="improvements">
<h3>Improvements</h3>
<ul class="simple">
<li>Update bleach from 6.3.0 to 6.4.0</li>
<li>Update django from 5.2.15 to 6.0.6</li>
<li>Update django-guardian from 3.3.1 to 3.3.2</li>
<li>Update django-simple-history from 3.11.0 to 3.12.0</li>
<li>Update node_modules/js-yaml from 4.1.1 to 4.2.0</li>
<li>Update node_modules/pdfmake from 0.3.7 to 0.3.11</li>
<li>Update node_modules/webpack from 5.106.0 to 5.107.2</li>
<li>Update node_modules/webpack-cli from 7.0.2 to 7.0.3</li>
<li>Remove the <tt class="docutils literal">handle_attachments_post_save()</tt> signal. Going forward files
uploaded via rich text editor will be linked to the user who uploaded them</li>
</ul>
</div>
<div class="section" id="database">
<h3>Database</h3>
<ul class="simple">
<li>Add migration <tt class="docutils literal">testcases.0024_alter_testcase_extra_link</tt></li>
<li>Add migration <tt class="docutils literal">testplans.0011_alter_testplan_extra_link</tt></li>
<li>Add migration <tt class="docutils literal">testruns.0020_testexecutiontag</tt></li>
</ul>
</div>
<div class="section" id="api">
<h3>API</h3>
<ul class="simple">
<li>Add <tt class="docutils literal">TestExecution.remove_tag()</tt> method. Refs
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/issues/4349">Issue #4349</a></li>
<li>Method <tt class="docutils literal">Tag.filter()</tt> now returns the <tt class="docutils literal">execution</tt> field</li>
</ul>
</div>
<div class="section" id="bug-fixes">
<h3>Bug fixes</h3>
<ul class="simple">
<li>Fix invalid multiline <tt class="docutils literal">{% trans %}</tt> on password reset confirm page</li>
</ul>
</div>
<div class="section" id="refactoring-and-testing">
<h3>Refactoring and testing</h3>
<ul class="simple">
<li>Update actions/checkout from 6 to 7</li>
<li>Update codecov/codecov-action from 6 to 7</li>
<li>Update isort from 6.1.0 to 8.0.1</li>
<li>Update locust from 2.44.1 to 2.44.4</li>
<li>Update pylint from 3.3.9 to 4.0.6</li>
<li>Silence false-positive errors &amp; adjustments for newer pylint</li>
<li>Skip English plural forms of seen strings in <tt class="docutils literal"><span class="pre">similar-string</span></tt> linter</li>
<li>Add XML-RPC API test case with non-printable character</li>
</ul>
</div>
<div class="section" id="translations">
<h3>Translations</h3>
<ul class="simple">
<li>Updated <a class="reference external" href="https://crowdin.com/project/kiwitcms/zh-CN">Chinese Simplified translation</a></li>
<li>Updated <a class="reference external" href="https://crowdin.com/project/kiwitcms/de">German translation</a></li>
</ul>
</div>
</div>
<div class="section" id="changes-since-kiwi-tcms-enterprise-v16-0-mt">
<h2>Changes since Kiwi TCMS Enterprise v16.0-mt</h2>
<ul class="simple">
<li>Based on Kiwi TCMS v16.1</li>
<li>Compatible with Django 6</li>
<li>Update kiwitcms-github-app from 2.2.2 to 2.3.0</li>
<li>Update kiwitcms-tenants from 4.4.4 to 4.5.0</li>
<li>Update kiwitcms-trackers-integration from 1.3.1 to 1.4.0</li>
<li>Update sentry-sdk from 2.61.1 to 2.63.0</li>
</ul>
</div>
<div class="section" id="private-container-images">
<h2>Private container images</h2>
<blockquote>
<pre class="literal-block">hub.kiwitcms.eu/kiwitcms/version          16.1 (aarch64)          ae3442ef043b    24 Jun 2026     715MB
hub.kiwitcms.eu/kiwitcms/version          16.1 (x86_64)           8a98927b8581    24 Jun 2026     696MB
hub.kiwitcms.eu/kiwitcms/enterprise       16.1-mt (aarch64)       0610f65a5fd5    24 Jun 2026     913MB
hub.kiwitcms.eu/kiwitcms/enterprise       16.1-mt (x86_64)        a3f823870351    24 Jun 2026     892MB
</pre>
</blockquote>
<p><strong>IMPORTANT:</strong> version tagged, multi-arch and Enterprise
<a class="reference external" href="https://kiwitcms.org/containers/">container images</a> are available only to
<a class="reference external" href="https://kiwitcms.org/#subscriptions">subscribers</a>!</p>
</div>
<div class="section" id="how-to-upgrade">
<h2>How to upgrade</h2>
<p>Follow the
<a class="reference external" href="https://kiwitcms.readthedocs.io/en/latest/installing_docker.html#upgrading-instructions">Upgrading instructions</a>
from our documentation.</p>
<p>Happy testing!</p>
<p>---</p>
<p>If you like what we're doing and how Kiwi TCMS supports various communities
please help us grow!</p>
<ul class="simple">
<li><a class="reference external" href="https://github.com/kiwitcms/Kiwi/stargazers">Give â­� on GitHub</a>;</li>
<li><a class="reference external" href="https://kiwitcms.us17.list-manage.com/subscribe?u=9b57a21155a3b7c655ae8f922&amp;id=c970a37581">Join our newsletter</a>
and follow all news;</li>
<li><a class="reference external" href="https://kiwitcms.org/#subscriptions">Become a subscriber</a> and help us sustain development</li>
</ul>
</div></div>
    </content>
    <updated>2026-06-24T10:18:00Z</updated>
    <published>2026-06-24T10:18:00Z</published>
    <category term="misc"/>
    <category term="releases"/>
    <author>
      <name>Kiwi TCMS Team</name>
    </author>
    <source>
      <id>https://kiwitcms.org/</id>
      <link href="https://kiwitcms.org/" rel="alternate" type="text/html"/>
      <link href="https://kiwitcms.org/feeds/all.atom.xml" rel="self" type="application/atom+xml"/>
      <title>Kiwi TCMS</title>
      <updated>2026-06-24T10:18:00Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://ausil.us/wordpress/?p=370</id>
    <link href="https://ausil.us/wordpress/global-roaming-on-google-fi-and-linux/" rel="alternate" type="text/html"/>
    <title>Global Roaming on Google Fi and Linux</title>
    <summary>I have a 5G modem in my Lenovo x13s and t14s. I run Fedora on them, currently Fedora 44. I have had issues in the past when traveling. The 5G modem works fine when in the US but will not connect to any provider when roaming. It has worked after some time in the UK […]</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">I have a 5G modem in my Lenovo x13s and t14s. I run Fedora on them, currently Fedora 44. I have had issues in the past when traveling. The 5G modem works fine when in the US but will not connect to any provider when roaming. It has worked after some time in the UK and Australia, but not in other countries. I use Google Fi for phone service, which allows roaming with the same data allowance as in the US. </p>



<p class="wp-block-paragraph">After some digging during my current trip, when it wasn’t connecting, I think I have found the issue and a workaround to ensure I can connect. Google Fi uses two networks, T-Mobile in the US and Three UK when roaming. It also uses T-Mobile for roaming. The issue seemed to be that the towers were rejecting the SIM card, attempting to register using T-Mobile’s default APN that seems to be baked into the SIM card as a default profile. The ModemManager logs looked like the following</p>



<pre class="wp-block-code"><code>ModemManager[1603]: &lt;msg&gt; [modem0] 3GPP packet service state changed (unknown -&gt; detached)
ModemManager[1603]: &lt;msg&gt; [modem0] 3GPP packet service state changed (detached -&gt; unknown)
ModemManager[1603]: &lt;msg&gt; [modem0] 3GPP packet service state changed (unknown -&gt; detached)
ModemManager[1603]: &lt;msg&gt; [modem0] 3GPP packet service state changed (detached -&gt; unknown)</code></pre>



<p class="wp-block-paragraph">The trick that got it to connect was to make a change to the default profile used to connect to the phone tower was to run an mmcli command: “mmcli -m 0 –3gpp-set-initial-eps-bearer-settings=”apn=h2g2,ip-type=ipv4v6” Which forces the sim to use the Google Fi APN and not the T-Mobile one </p></div>
    </content>
    <updated>2026-06-24T03:45:50Z</updated>
    <published>2026-06-24T03:45:50Z</published>
    <category term="AArch64"/>
    <category term="Fedora"/>
    <category term="5G"/>
    <category term="Global"/>
    <category term="Google Fi"/>
    <category term="ModemManager"/>
    <category term="Roaming"/>
    <author>
      <name>dgilmore</name>
    </author>
    <source>
      <id>https://ausil.us/wordpress</id>
      <link href="https://ausil.us/wordpress/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://ausil.us/wordpress" rel="alternate" type="text/html"/>
      <title>Dennis Gilmore</title>
      <updated>2026-06-24T05:56:08Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-us">
    <id>https://blog.tomecek.net/post/opencode-openshell-fedora-llama-cpp/</id>
    <link href="https://blog.tomecek.net/post/opencode-openshell-fedora-llama-cpp/" rel="alternate" type="text/html"/>
    <title>Running opencode inside openshell on Fedora 44 with llama-cpp</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>For quite some time I wanted to explore
<a href="https://github.com/NVIDIA/OpenShell">openshell</a>. I naively thought it would be
easy to set up on my workstation that has an AMD GPU, together with llama-cpp
as an inference server.</p>
<p>After following the tutorial, I was immediately stuck even with running the gateway in a podman container.</p>
<p>I guess I’m too old for this stuff because I let Claude Code to investigate the problems.</p>
<img src="https://blog.tomecek.net/img/flower-jun2026.JPG" style="width: 800px;"/></div>
    </summary>
    <updated>2026-06-23T18:00:00Z</updated>
    <published>2026-06-23T18:00:00Z</published>
    <source>
      <id>https://blog.tomecek.net/</id>
      <author>
        <name>Tomas Tomecek</name>
      </author>
      <link href="https://blog.tomecek.net/" rel="alternate" type="text/html"/>
      <link href="https://blog.tomecek.net/index.xml" rel="self" type="application/rss+xml"/>
      <subtitle>Recent content on Blog | Tomáš Tomeček</subtitle>
      <title>Blog | Tomáš Tomeček</title>
      <updated>2026-06-23T18:00:00Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://communityblog.fedoraproject.org/?p=15803</id>
    <link href="https://communityblog.fedoraproject.org/community-update-week-25-2026/" rel="alternate" type="text/html"/>
    <title>Community Update – Week 25, 2026</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>This is a report created by CLE Team, which is a team containing community members working in various Fedora groups for example Infrastructure, Release Engineering, Quality etc. This team is also moving forward some initiatives inside Fedora project. Week: 15 â€“ 19 June 2026 (Flock Week!!) Fedora Infrastructure This team is taking care of day […]</p>
<p>The post <a href="https://communityblog.fedoraproject.org/community-update-week-25-2026/">Community Update – Week 25, 2026</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">This is a report created by <a href="https://docs.fedoraproject.org/en-US/cle/">CLE Team</a>, which is a team containing community members working in various Fedora groups for example Infrastructure, Release Engineering, Quality etc. This team is also moving forward some initiatives inside Fedora project.</p>



<p class="wp-block-paragraph">Week: 15 – 19 June 2026 (Flock Week!!)</p>



<span id="more-15803"/>



<h2 class="wp-block-heading">Fedora Infrastructure</h2>



<p class="wp-block-paragraph">This team is taking care of day to day business regarding Fedora Infrastructure.<br/>It’s responsible for services running in Fedora infrastructure.<br/><a href="https://pagure.io/fedora-infrastructure/issues">Ticket tracker</a></p>



<ul class="wp-block-list">
<li>Helped getting elnbuildsync moved into stg openshift (ongoing).</li>



<li>A couple more services had OS upgrades to Fedora 44.</li>



<li>Some more MirrorManager problems.</li>



<li>Scrappers found another ostree repo. on kojipkgs, limited dir. indexing to stop the attack and then searched for any other ostree repos. Hopefully the last time it happens.</li>
</ul>



<h2 class="wp-block-heading">CentOS Infra including CentOS CI</h2>



<p class="wp-block-paragraph">This team is taking care of day to day business regarding CentOS Infrastructure and CentOS Stream Infrastructure.<br/>It’s responsible for services running in CentOS Infrastructure and CentOS Stream.<br/><a href="https://gitlab.com/CentOS/infra/tracker/-/issues">CentOS ticket tracker</a><br/><a href="https://issues.redhat.com/projects/CS/issues/CS-3206?filter=allopenissues">CentOS Stream ticket tracker</a></p>



<ul class="wp-block-list">
<li>Finish rebuilding/bumping some pkgs for ppc64le libvirt/qemu-kvm stack on el10 (https://gitlab.com/CentOS/infra/tracker/-/work_items/1928)</li>



<li>Start to work on debuginfo origin servers refresh with el10 instances (https://gitlab.com/CentOS/infra/tracker/-/work_items/1892)</li>



<li>More coordination work with Stream team about secureboot issues (<a href="https://redhat.atlassian.net/browse/CS-3400">https://redhat.atlassian.net/browse/CS-3400</a>)</li>



<li>Finishing last debuginfo pool members reinstall (<a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1892">https://gitlab.com/CentOS/infra/tracker/-/work_items/1892</a>)</li>



<li>Decommission old openstack env for stream (<a href="https://redhat.atlassian.net/browse/CS-3404">https://redhat.atlassian.net/browse/CS-3404</a>)</li>



<li>Cloud SIG doc url change (migration to gitlab, from pagure) – <a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1934">https://gitlab.com/CentOS/infra/tracker/-/work_items/1934</a></li>



<li>internal requests (FRCL and audit compliance)</li>



<li>Move another SIG doc url (away from pagure.io) – <a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1938">https://gitlab.com/CentOS/infra/tracker/-/work_items/1938</a></li>



<li>Modified the aws load-balancer settings for one ocp tenant (<a href="https://gitlab.com/CentOS/infra/tracker/-/work_items/1932">https://gitlab.com/CentOS/infra/tracker/-/work_items/1932</a>)</li>



<li>Migrate haproxy load-balancers to el10 for stream dc-move prep (<a href="https://redhat.atlassian.net/browse/CS-3353">https://redhat.atlassian.net/browse/CS-3353</a>)</li>
</ul>



<h2 class="wp-block-heading">Release Engineering</h2>



<p class="wp-block-paragraph">This team is taking care of day to day business regarding Fedora releases.<br/>It’s responsible for releases, retirement process of packages and package builds.<br/><a href="https://pagure.io/releng/issues">Ticket tracker</a></p>



<ul class="wp-block-list">
<li>Migration at 95%, the only thing left to migrate is majorly fedora-scm-requests, bug fixes, and continued releng operations.</li>



<li>Migration: archive-repo-manager from pagure</li>



<li>Fix: Missing permissions on releng/fedora-comps</li>



<li>Bug Fix: Mass tagging script for verification bits</li>



<li>F45 Change Sets reviews are in check and f45-python side tags are merged.</li>



<li>Regular releng operations.</li>
</ul>



<h2 class="wp-block-heading">QE</h2>



<p class="wp-block-paragraph">This team is taking care of quality of Fedora. Maintaining CI, organizing test days<br/>and keeping an eye on overall quality of Fedora releases.</p>



<ul class="wp-block-list">
<li>We’ve <a href="https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/RVCAUQE6N4R3P3C6FSBOKGDZG6CND6ZR/">started searching</a> for new owners/maintainers of Packager Dashboard and Oraculum</li>
</ul>



<h2 class="wp-block-heading">Forgejo</h2>



<p class="wp-block-paragraph">This team is working on introduction of https://forge.fedoraproject.org to Fedora<br/>and migration of repositories from pagure.io.</p>



<ul class="wp-block-list">
<li>Completed the Flock To Fedora 2026 presentation on Fedora → Forgejo migration efforts <a href="https://forge.fedoraproject.org/forge/forge/issues/588">#588</a>, packaged and deployed Forgejo 15.0.3 <a href="https://forge.fedoraproject.org/forge/forge/issues/620">#620</a>.</li>



<li>successfully ran the PR fix doctor across all migrated repositories <a href="https://forge.fedoraproject.org/forge/forge/issues/601">#601</a> to address merge issues with Pagure imports.</li>



<li>Enhanced runner infrastructure with the addition of a Testing Farm runner option <a href="https://forge.fedoraproject.org/forge/forge/pulls/619">#619</a> and docker-slim type runner <a href="https://forge.fedoraproject.org/forge/forge/issues/568">#568</a>, and improved security by deploying oauth-proxy to secure the Forge metrics endpoint <a href="https://forge.fedoraproject.org/forge/forge/issues/571">#571</a>.</li>
</ul>



<h2 class="wp-block-heading">EPEL</h2>



<p class="wp-block-paragraph">This team is working on keeping <a href="https://docs.fedoraproject.org/en-US/epel/epel-about/">Epel</a> running and helping package things.</p>



<ul class="wp-block-list">
<li>Updated caddy in rawhide, resolving 14 CVEs</li>



<li>Ongoing onboarding of Pedro</li>
</ul>



<h2 class="wp-block-heading">UX</h2>



<p class="wp-block-paragraph">This team is working on improving User experience. Providing artwork, user experience,<br/>usability, and general design services to the Fedora project</p>



<ul class="wp-block-list">
<li>With Flock this week, got to see how all the final designs turned out it in person!</li>



<li>Emma delivered her talk on ‘Why You Should Use Open Source Design in Open Source’ at Flock</li>



<li>Great progress on the F45 wallpaper in the final stretch!</li>
</ul>



<p class="wp-block-paragraph">If you have any questions or feedback, please respond to this report or contact us on #admin:fedoraproject.org channel on <a href="https://matrix.to/#/#admin:fedoraproject.org:matrix.org">matrix</a>.</p>
<p>The post <a href="https://communityblog.fedoraproject.org/community-update-week-25-2026/">Community Update – Week 25, 2026</a> appeared first on <a href="https://communityblog.fedoraproject.org">Fedora Community Blog</a>.</p></div>
    </content>
    <updated>2026-06-23T10:12:46Z</updated>
    <published>2026-06-23T10:12:46Z</published>
    <category term="Fedora Project Community"/>
    <category term="Community update"/>
    <author>
      <name>jnsamyak</name>
    </author>
    <source>
      <id>https://communityblog.fedoraproject.org/</id>
      <logo>https://communityblog.fedoraproject.org/wp-content/uploads/2022/07/favicon-fedora-commblog.png</logo>
      <link href="https://communityblog.fedoraproject.org/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://communityblog.fedoraproject.org/" rel="alternate" type="text/html"/>
      <subtitle>The Community Blog provides a single source for members of the community to share important news, updates, and information about Fedora with others in the Project community.</subtitle>
      <title>Fedora Community Blog</title>
      <updated>2026-07-03T10:34:22Z</updated>
    </source>
  </entry>

  <entry xml:lang="fa-IR">
    <id>https://fedorafans.com/?p=8548</id>
    <link href="https://fedorafans.com/%d9%be%d8%a7%d9%86%d8%b2%d8%af%d9%87%d9%85%db%8c%d9%86-%d8%b3%d8%a7%d9%84%da%af%d8%b1%d8%af-%d9%88%d8%a8-%d8%b3%d8%a7%db%8c%d8%aa-%d8%b7%d8%b1%d9%81%d8%af%d8%a7%d8%b1%d8%a7%d9%86-%d9%81%d8%af%d9%88/" rel="alternate" type="text/html"/>
    <title>پانزدهمین سالگرد وب سایت طرفداران فدورا</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><div style="margin-bottom: 20px;"><img alt="happy-birthday" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" height="550" src="https://fedorafans.com/wp-content/uploads/2019/06/happy-birthday-fedorafans.com_.jpg" width="825"/></div><p>درود بر دوستان، همراهان و اعضای خانواده بزرگ طرفداران فدورا امروز با افتخار پانزدهمین سالگرد تأسیس وب‌سایت FedoraFans می باشد. پانزده سال پیش، با هدف ترویج فرهنگ نرم‌افزارهای آزاد و متن‌باز، آموزش لینوکس فدورا و ایجاد فضایی برای تبادل دانش و تجربه، این وب‌سایت فعالیت خود را آغاز کرد. آن روزها شاید تصور نمی‌کردیم که […]</p>
The post <a href="https://fedorafans.com/%d9%be%d8%a7%d9%86%d8%b2%d8%af%d9%87%d9%85%db%8c%d9%86-%d8%b3%d8%a7%d9%84%da%af%d8%b1%d8%af-%d9%88%d8%a8-%d8%b3%d8%a7%db%8c%d8%aa-%d8%b7%d8%b1%d9%81%d8%af%d8%a7%d8%b1%d8%a7%d9%86-%d9%81%d8%af%d9%88/">پانزدهمین سالگرد وب سایت طرفداران فدورا</a> first appeared on <a href="https://fedorafans.com">طرفداران فدورا</a>.</div>
    </summary>
    <updated>2026-06-22T11:12:00Z</updated>
    <published>2026-06-22T11:12:00Z</published>
    <category term="&#x627;&#x62E;&#x628;&#x627;&#x631; &#x648;&#x628; &#x633;&#x627;&#x6CC;&#x62A;"/>
    <category term="fedora"/>
    <category term="fedorafans"/>
    <category term="happy birthday 15"/>
    <category term="linux"/>
    <category term="&#x632;&#x627;&#x62F; &#x631;&#x648;&#x632;"/>
    <category term="&#x633;&#x627;&#x644;&#x6AF;&#x631;&#x62F;"/>
    <category term="&#x641;&#x62F;&#x648;&#x631;&#x627;"/>
    <category term="&#x644;&#x6CC;&#x646;&#x648;&#x6A9;&#x633;"/>
    <author>
      <name>hos7ein</name>
    </author>
    <source>
      <id>https://fedorafans.com</id>
      <link href="https://fedorafans.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://fedorafans.com" rel="alternate" type="text/html"/>
      <subtitle>همه برای فدورا , فدورا برای همه</subtitle>
      <title>طرفداران فدورا</title>
      <updated>2026-06-22T11:13:16Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://adam.younglogic.com/?p=11757</id>
    <link href="https://adam.younglogic.com/2026/06/fathers-day-project/" rel="alternate" type="text/html"/>
    <title>Father’s day project</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">Getting a little more organized in my workshop. My pain point was boxes of nails or screws falling off shelves. And, of course, I wanted an excuse to use the laser cutter. I took a lesson from Minecrafters and put … <a href="https://adam.younglogic.com/2026/06/fathers-day-project/">Continue reading <span class="meta-nav">→</span></a></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">Getting a little more organized in my workshop. My pain point was boxes of nails or screws falling off shelves.</p>



<p class="wp-block-paragraph">And, of course, I wanted an excuse to use the <a href="https://boxes.hackerspace-bamberg.de/boxes.py">laser cutter</a>.</p>



<figure class="wp-block-image size-large"><img alt="" class="wp-image-11756" height="1024" src="http://adam.younglogic.com/wp-content/uploads/2026/06/20260622_0010427668343090799469293-768x1024.jpg" width="768"/></figure>



<figure class="wp-block-image"><img alt="" class="wp-image-11755" height="1024" src="https://adam.younglogic.com/wp-content/uploads/2026/06/20260621_232617944543594713906574-768x1024.jpg" width="768"/></figure>



<p class="wp-block-paragraph">I took a lesson from Minecrafters and put an instance of what was inside the box on the front id the box.</p></div>
    </content>
    <updated>2026-06-22T04:13:13Z</updated>
    <published>2026-06-22T04:13:13Z</published>
    <category term="Family"/>
    <category term="Gadgets"/>
    <category term="Woodworking"/>
    <author>
      <name>Adam Young</name>
    </author>
    <source>
      <id>https://adam.younglogic.com</id>
      <link href="https://adam.younglogic.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://adam.younglogic.com" rel="alternate" type="text/html"/>
      <subtitle>The Notebook of a Programmer Climber Musician Ex-Soldier Woodworker and a few other things</subtitle>
      <title>Adam Young's Web Log</title>
      <updated>2026-06-22T16:58:17Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-us">
    <id>https://michel-slm.name/posts/2026-06-22-introducing-dbranch/</id>
    <link href="https://michel-slm.name/posts/2026-06-22-introducing-dbranch/" rel="alternate" type="text/html"/>
    <title>Introducing dbranch 🍥→🤝</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><blockquote>
<p><strong>Caveat lector</strong></p>
<p>This post discusses tools reluctantly written with AI assistance. If you don’t entertain
using them under any circumstance, and think even reading about them legally compromise
your ability to reimplement them yourselves, stop reading now</p>
</blockquote>
<p>Today’s post introduces <code>dbranch</code>, a tool to update a Debian package in unstable, and rebuild downstream branches (currently supports Ubuntu PPAs and stable proposed-updates; backports support could be easily added once I have a package that needs it). Eagle-eyed readers might notice the naming similarity with my previous tool <a href="https://crates.io/crates/ebranch">ebranch</a>; and the credit for the name and inspiration eventually came from Jens Petersen’s <a href="https://hackage.haskell.org/package/fbrnch">fbrnch</a>.</p></div>
    </summary>
    <updated>2026-06-22T00:00:00Z</updated>
    <published>2026-06-22T00:00:00Z</published>
    <source>
      <id>https://michel-slm.name/tags/foss/</id>
      <author>
        <name>Michel Alexandre Salim</name>
      </author>
      <link href="https://michel-slm.name/tags/foss/" rel="alternate" type="text/html"/>
      <link href="https://michel-slm.name/tags/foss/index.xml" rel="self" type="application/rss+xml"/>
      <rights type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><a href="https://creativecommons.org/licenses/by/4.0/" rel="noopener" target="_blank">CC BY 4.0</a></div>
      </rights>
      <subtitle>Recent content in Foss on PensÃ©es de Michel</subtitle>
      <title>Foss on Pensées de Michel</title>
      <updated>2026-06-23T00:00:00Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-us">
    <id>http://miroslav.suchy.cz/blog/archives/2026/06/21/flock_and_devconf_-_field_report/index.html</id>
    <link href="http://miroslav.suchy.cz/blog/archives/2026/06/21/flock_and_devconf_-_field_report/index.html" rel="alternate" type="text/html"/>
    <title>Flock and Devconf - Field Report</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><h2>Flock</h2>

<p>I was looking forward to this yearâ€™s <a href="https://www.fedoraproject.org/flock/2026/">Flock - Fedora Project Conference</a>. I had to cut my vacation short and return from my river trip a day early.</p>

<p>I arrived in Prague at noon on <strong>Sunday</strong>, just in time to attend FrantiÅ¡ek Lachmanâ€™s workshop â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/AHJK7Z/">PR-based Gating for Fedora: Can We Make It Work?</a>â€�. We all agreed that we want all contributions to happen through pull requests and only after all tests pass. However, we also realized it is not easy: gating for multi-package PRs will be difficult (unless we have a monorepo). Proven packagers will need special handling (can we work on this later?), and first, we need the new Forgejoâ€”everyone is looking forward to it. Coincidentally, later at Devconf, I spoke to Marcela, who mentioned that SUSE already has Forgejo for all packages and that it does not scale as they expected.<br/>
But the important message from Miro was: â€œwe should not force maintainers to use a new workflow; we should make it pleasant and easy to use so they want to use it on their own.â€�</p>

<p>After this workshop, I checked into my hotel and later returned to the venue. We had a passionate conversation with Aleksandra, Miro, and Karolina during a card game. We then moved with several other people to a nearby pub that served Belgian beer. I had only one glass, but I felt very dizzy and tired, so I returned to the hotel sooner than the rest of the gang.</p>

<p>On <strong>Monday</strong>, I joined Collin for breakfast, and we discussed the dark corners of RPM building.<br/>
Then I moved to the venue and listened to Jef Spaletaâ€™s â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/Z9NP9W/">State of Fedora</a>â€� talk. Fedoraâ€™s usage is growing, and KDE is working enormously well, but the decline in Fedoraâ€™s contributors is accelerating. We have to figure out why and take action, rather than just setting up plans without execution.</p>

<p>The â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/PHZW3D/">Fedora Council Strategic Proposals</a>â€� session was great. Two highlights stood out:<br/>
â€œ<em>It’s not the new generation that is different. It’s you who is different</em>,â€� said Aleksandra. â€œ<em>They talk about changing a wallpaper; we are talking about burnout.</em>â€�</p>

<p><img alt="Aleksandra" class="alignnone wp-image-867047" src="http://miroslav.suchy.cz/blog/images/flock2026-1.jpg" width="450"/></p>

<p>“I would not join Fedora if it were stable. I want to improve it.” Jef Spaleta</p>

<p><img alt="Jef Spaleta" class="alignnone wp-image-867047" src="http://miroslav.suchy.cz/blog/images/flock2026-2.jpg" width="450"/></p>

<p>The subsequent â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/8HNVTW/">FESCo Q&amp;A</a>â€� was less vibrant but provided a great opportunity to learn about members' views. For newcomers, Kevinâ€™s remark that FESCoâ€™s role is sometimes to say â€œNoâ€� and stop things was likely interesting. However, FESCo cannot drive new initiatives; individual contributors must do that.</p>

<p>Then I watched Stefâ€™s <a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/BLEMHM/">talk about Hummingbird</a>; this was not new to me as we closely cooperate on agentic packaging.</p>

<p><img alt="Stef" class="alignnone wp-image-867047" src="http://miroslav.suchy.cz/blog/images/flock2026-3.jpg" width="450"/></p>

<p>I also observed the talk â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/33CKL3/">Packit and Fedora: The CI Story Continues</a>â€�, as it summarized what my team accomplished with Fedora CI. There were many examples, and the feedback was positive. I appreciated that Matej managed to substitute for Nikola, who got sick at the last minute.<br/>
Several ideas in the Q&amp;A highlighted that PRs are not mandatory and that maintainers do not always follow upstream in a timely manner.</p>

<p>I attended â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/GZNGCK/">The EU CRA vs. Community: Why Youâ€™re Safe, and How Stewards Help</a>â€�. The CRA was new to me, and the session was packed with concrete information. You may check the <a href="https://rodina-sucha.cz/@mirek/116754546239187848">most interesting slides in my Mastodon post</a>. The biggest takeaway is that open-source maintainers do not need to worry, but they should be prepared that companies using their software will start email-bombing them in August. There was a nice guide on how to politely reject them.</p>

<p>I took a break and talked to people in the hallway, sharing remarks with my team members. I talked with Kashyap about bootstrapping RISC-V; he was thankful for our support in Copr. We drafted next steps, only to find that Kashyap’s colleague <a href="https://github.com/rpm-software-management/mock/pull/1762">already did that</a> while I was on vacation.</p>

<p>I then observed â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/FHYW3G/">What’s Cooking in Copr, Testing Farm, tmt, Packit and Log Detective</a>â€�, where Franta and people from my team shared our current work and future plans. It was great that Franta brought the team members on stage.</p>

<p>After this, I was quite tired, so I headed to the hotel for a quick nap and shower to get ready for the Official Party, which took place at Manifestoâ€”a local market with various street foods. I met many familiar faces as well as new people.</p>

<p>On <strong>Tuesday</strong> I listened to Adamâ€™s â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/8GWWTY/">RHEL 11 is branching from Fedora 46: What this means for you</a>â€� talk and appreciated his honesty in answering â€œI do not knowâ€� to several questions. Later in the hallway, we discussed whether branching RHEL during the Fedora branching phase is ideal, and why we don’t branch during the beta phase instead.</p>

<p>I then moved to Kevinâ€™s talk, â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/FWSYWR/">Scrapers Gotta Scrape Scrape Scrape</a>â€�. This topic was familiar, as we are also fighting scrapers, and Jiri from my team helped package Anubis and its dependencies for Fedora. However, I learned several new things, and the follow-up Q&amp;A was fun. If you think people ranting about scrapers only wrote inefficient web applications, you should definitely see a recording of this talk.</p>

<p>I attended Frederickâ€™s talk, â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/NK3YNW/">Machine-readable package lifecycle information in repository metadata</a>â€�. He spoke about their DNF plugin that can set various End-of-Life dates for different packages. This was extremely helpful, and since we wanted to do something similar in RHEL, I immediately emailed the DNF team to introduce them to Frederick.<br/>
After the talk, I bowed to Frederick, as he is reportedly the person behind the migration of AWS Linux to Fedora.</p>

<p>I listened to Microsoftâ€™s talk, â€œ<a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/RPECD3/">Two Years In: Accelerating Microsoft Contribution to Fedora</a>â€�. It was interesting to see how much Microsoft uses Fedora. The highlight was that the presenters were from different teams within Microsoft and were largely unaware of each other’s work.</p>

<p>I then talked to people in the corridor, including Bex, who introduced me to two students from Jihlava interested in a high school internship.</p>

<p>The highlight was definitely the lightning talks. They were strictly 5 minutes long (including notebook setup). I learned about current Lenovo support for Linux, how Miro sped up the last Python mass rebuild, and I reported on the current status of the SPDX migration, noting that the next steps will proceed without me. Fortunately, Max started a SIG that wants to take over the work. I shared some information with him that didn’t fit into the lightning talk. Jiri presented his achievement of packaging Goose for Fedora and even provided a live demo!</p>

<p>By this point, I was quite tired, so I passively watched the presentation of the Contributor Recognition Awards. Then, I went into the city to meet a friend, and we attended the theater performance <a href="https://www.venuse-ve-svehlovce.cz/predstaveni/tahle-zeme-je-nase/">Tahle zemÄ› je naÅ¡e</a>.</p>

<p>Tip: If you want to see any mentioned talk, you can find it in the <a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/schedule/">schedule</a> and then rewind to the specific time in the <a href="https://www.youtube.com/@fedora/streams">Streams</a>. The edited and cut talks are usually available weeks later on <a href="https://www.youtube.com/@fedora/videos">Fedoraâ€™s channel</a>.</p>

<h2>DevConf</h2>

<p>DevConf CZ is huge even. With over one thousand participants and eleven tracks - it is huge. As this is a conference in my hometown I volunteered to help organizers: I chaired one of the rooms and acted as a fire marshall. That includes overseeing A/V tech. Help speakers to connect to video and mic. Make sure they do not run with that. Remind them the time.<br/>
This year, I chose a room with Lightning talks. There was 15 minutes for each talk and 5 minutes for a break. And it was a blast! <br/>
I chaired the Thursday morning and Friday afternoon. One of the best delivered talks was from new junior who was speaking for the first time - yet she overperformed more senior people.</p>

<p><img alt="Kaja Prokopova" class="alignnone wp-image-867047" src="http://miroslav.suchy.cz/blog/images/devconf2026-1.jpg" width="450"/>
“AI accelerated learning. Mentorship directed it. Real systems grounded it.” Kaja Prokopova @ “From Sysadmin to Software Engineer: A Non-Traditional Path into Tech”</p>

<p><img alt="Petr Ka&#xC5;&#xA1;ka" class="alignnone wp-image-867047" src="http://miroslav.suchy.cz/blog/images/devconf2026-2.jpg" width="450"/>
Petr KaÅ¡ka spoke about detecting malicious prompts. You can attack your model using <a href="https://github.com/Security-FIT/PromptAttacker">https://github.com/Security-FIT/PromptAttacker</a></p>

<p><img alt="Ane&#xC5;&#xBE;ka M&#xC3;&#xBC;ller" class="alignnone wp-image-867047" src="http://miroslav.suchy.cz/blog/images/devconf2026-3.jpg" width="450"/>
AneÅ¾ka MÃ¼ller speaks about how she organizes a small one-day, one-track conference, Python Pizza. You can use her recipe for free <a href="https://docs.python.pizza/">https://docs.python.pizza/</a></p>

<p><img alt="Simplified dopamine circle with " class="alignnone wp-image-867047" src="http://miroslav.suchy.cz/blog/images/devconf2026-4.jpg"/>
James Freeman with his theory about technology dopamine culture.</p>

<p>Jan Jurca spoke about tests on the filesystem that produce different results if you use the filesystem for some time. You can artificially simulate the usage of filesystem and then run the benchmarks using Filestorm <a href="https://github.com/janjurca/Filestorm">https://github.com/janjurca/Filestorm</a><br/>
See <a href="https://rodina-sucha.cz/@mirek/116777632773369684">the interesting slides</a>.</p>

<p>I did a small cameo at lightning talk by my student Peter Stefunko in his talk â€œFrom SBOM to Dependency Stacks: Making Software Structure Visibleâ€œ where he tries to visualize the state of the operating system using famous XKCD comics â€œ<a href="https://xkcd.com/2347/">Dependency</a>â€�. You can check his work at <a href="https://github.com/peter-stefunko/rpm2xkcd2347">github.com/peter-stefunko/rpm2xkcd2347</a>.</p>

<p>I did not attend Thursday’s party as we had an anniversary with my wife and preferred my wife over all of you. ğŸ™‚</p>

<p>I met many old faces, former colleagues. And the biggest surprise was the booth of Free Software EU where I found the Czech edition of the book Ada &amp; Zangemann that I helped to translate. I did not know it was already printed - that was because the print was finished that morning. I then called Tomas Stary who took the work from me and who I never met - only to find that he is standing beside me in the queue for ice cream ğŸ™‚<br/>
Mathias post about the new print <a href="https://mastodon.social/@kirschner/116770321504331386">https://mastodon.social/@kirschner/116770321504331386</a><br/>
<img alt="Look into the van with a load of 500 books." class="alignnone wp-image-867047" src="http://miroslav.suchy.cz/blog/images/devconf2026-5.jpg" width="450"/>
Half of the batch. Fresh from print.<br/>
Later we discussed with Tomas, his publisher and Lucie from RH additional steps to advertise the book.</p></div>
    </summary>
    <updated>2026-06-21T15:43:05Z</updated>
    <category term="fedora"/>
    <author>
      <name>Miroslav Suchý</name>
    </author>
    <source>
      <id>http://miroslav.suchy.cz/blog</id>
      <author>
        <name>Miroslav Suchý</name>
      </author>
      <link href="http://miroslav.suchy.cz/blog/archives/fedora/index-rss.xml" rel="self" type="application/rss+xml"/>
      <link href="http://miroslav.suchy.cz/blog" rel="alternate" type="text/html"/>
      <subtitle>novinky, deníček, myšlenky, cokoliv</subtitle>
      <title>Filed under: fedora | Miroslav Suchý</title>
      <updated>2026-06-21T16:31:47Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://enotty.pipebreaker.pl/posts/2026/06/skill-issue/</id>
    <link href="https://enotty.pipebreaker.pl/posts/2026/06/skill-issue/" rel="alternate" type="text/html"/>
    <title>Skill issue</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Last week I had to extend complicated, unfamiliar Helm chart. While
I've discussed approach with my carbon-based coworker, actual
editing and extending was done by Claude Code.</p>
<p>Refactors and renamings were tedious, but Claudius did them in no time.
During the review we decided to significantly change the way
chart is organised. Claude executed the changes perfectly.</p>
<p>If I had to fully understand the working of the chart, it would
have taken me a good part of the week. Making the changes – another
day or two. Significant rework midway – I'd probably be too demotivated to
do it.</p>
<p>With AI assistant, I have finished work in two days. Tested, simplified,
cleaned up.</p>
<p>But I have no more skills than I had before. I do not understand this
Helm chart much better. I've spotted a thing or two during the review,
but in no way I have a fuller comprehension. AI let me borrow expertise without acquiring it.</p>
<p>Next time when I'll have to work on this chart, I will use Claude again.
I've got softly locked-in in using AI assistant to work. And I'm not happy with that.</p>
<p>Now, my employer sees this as an acceptable tradeoff. Paid for some tokens,
unlocked couple of my pricy senior-level hours to do other stuff. It balances.
Subsidising Scam Altman and his ilk is a money well spent from this perspective.</p>
<p>We are at the point where we offload more work to so-called AI. Those
are just tools. You know what more primitive tools we had before? Assemblers.
Then compilers. No one writes machine code by hand anymore. Maybe someone
despairs because of it, but people commonly writing binaries are more likely
to be dead by now.</p>
<p>No one treats high level compilers as fad and stuff <em>kids these days</em> do. It's
just a tool, expected to work and dissappering into the background.</p>
<p>There's one important difference. We do not have to pay for the compilers,
thanks to work of the GNU Project last century (<code class="docutils literal">gcc</code>) and Apple more recently (<code class="docutils literal">llvm/clang</code>).
But at this point <strong>we are paying for tokens</strong>. I expect that as we
cannot fathom working with any codebase without a compiler now, a LLM-driven
assistant will be required to tackle bigger projects in near future.</p>
<p>To be free, we need to be able to run assistants at reasonable cost.
Free is reasonable. Not paying through the nose for electricity is reasonable.
We can hope for good quality chinese models to be available for free.
We need a free toolkit revolution again. It was GNU Compiler Collection
for the previous generation. Would it be Kimi now?</p>
<p>And we need the proprietary AI bubble to pop and rationality to return.</p>
<p>066/100 of <a class="reference external" href="https://100daystooffload.com/">#100DaysToOffload</a></p></div>
    </summary>
    <updated>2026-06-20T23:11:36Z</updated>
    <published>2026-06-20T23:11:36Z</published>
    <category term="100DaysToOffload"/>
    <category term="english"/>
    <author>
      <name>Tomasz Torcz</name>
    </author>
    <source>
      <id>https://enotty.pipebreaker.pl/</id>
      <link href="https://enotty.pipebreaker.pl/" rel="alternate" type="text/html"/>
      <link href="https://enotty.pipebreaker.pl/categories/english.xml" rel="self" type="application/rss+xml"/>
      <title>-ENOTTY (Posts about english)</title>
      <updated>2026-07-09T16:02:05Z</updated>
    </source>
  </entry>

  <entry>
    <id>https://www.jcline.org/blog/fedora/signing/2026/06/20/fedora-artifact-signing-p5.html</id>
    <link href="https://www.jcline.org/blog/fedora/signing/2026/06/20/fedora-artifact-signing-p5.html" rel="alternate" type="text/html"/>
    <title>Fedora signing: draw the rest of the owl</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Way back in September <a href="https://www.jcline.org/blog/fedora/signing/2025/09/18/fedora-artifact-signing-p4.html">I apologized</a> for the gap since my last update. I am, once again, sorry it’s been so long since I posted an update. I recently presented at talk at <a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/BESUGX/">Flock 2026</a> - if you prefer consuming updates via video where live demos fail, you can find that <a href="https://youtu.be/ulz7AhNRQBE?t=7071">on YouTube</a>.</p>

<p>This post is something of a summary of that talk, but the short version is Siguldry has all the features Sigul has, plus some. That means we can start deploying it in the coming weeks.</p>

<h2 id="pkcs11">PKCS#11</h2>

<p>In the last post, I noted I had implemented server-side support for PGP signing. That’s gone now, I’m pleased to say, because I came across a much neater approach. I implemented a small PKCS#11 module inventively called <a href="https://github.com/fedora-infra/siguldry/tree/siguldry-pkcs11-2.1.0/siguldry-pkcs11">siguldry-pkcs11</a>.</p>

<p>I can’t take credit for any of the ideas I’m about to describe, since I stole them from multiple other projects. Our friends over in <a href="https://www.flatcar.org/">Flatcar</a> have to sign things as well, and they use a key stored in Azure Key Vault. The way they use it is that they implemented a minimal <a href="https://github.com/jepio/azure-keyvault-pkcs11">PKCS#11 module</a>. That was my primary inspiration, but I also recently spent some time building a drop-in replacement for pesign-daemon and the idea of exposing the signing interface over a Unix socket that can be mounted into isolated build environments was another concept I borrowed.</p>

<p>For those who aren’t familiar, <a href="https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.2/pkcs11-spec-v3.2.html">PKCS#11</a> is a standard that is made up of a C interface. To implement it, you create a shared object file with a few well-known C functions used to discover your implementations of the interface. Users load your shared library, call a well-known function to get a table of functions where you provide your implementations for the various features. What’s nice about this is that common libraries like OpenSSL can speak to PKCS#11 modules, so you can make any tool that uses those common cryptography libraries use your implementations.</p>

<p>PKCS#11 is a fairly broad specification that covers not just signing, but also encryption/decryption, digest calculation, random number generation, and key management (creating, modifying, deleting, etc). What I realized while poking around Flatcar’s implementation is that you actually don’t need to implement everything. You can, instead, stub out all the functions you don’t want to implement and have them return the handy “function not supported” error code. The list of functions I opted to not support <a href="https://github.com/fedora-infra/siguldry/blob/siguldry-pkcs11-2.1.0/siguldry-pkcs11/src/unsupported.rs">is extensive</a>.</p>

<p>In fact, all I implemented was the functions to authenticate, list keys, and sign. However, that’s enough to make it possible to use the Siguldry server with tools including (but definitely not limited to): <code class="language-plaintext highlighter-rouge">rpmsign</code>, <code class="language-plaintext highlighter-rouge">ostree gpg-sign</code>, <code class="language-plaintext highlighter-rouge">cosign</code> (if built with PKCS#11 support), <code class="language-plaintext highlighter-rouge">gpg2</code> (with the <code class="language-plaintext highlighter-rouge">gnupg-pkcs11-scd</code> service), <code class="language-plaintext highlighter-rouge">sq</code> (once it merges its PKCS#11 support), <code class="language-plaintext highlighter-rouge">systemd-measure</code>, <code class="language-plaintext highlighter-rouge">systemd-sbsign</code>, <code class="language-plaintext highlighter-rouge">pesign</code>, and perhaps most humorously, <code class="language-plaintext highlighter-rouge">ssh</code>. All these tools know how to speak to PKCS#11 modules so they “just work” with Siguldry. Any new tool people make will also likely just work.</p>

<p>One thing that’s neat about this approach is that we sit between the tool requesting the signature and the signing server. This means we can hash the content client-side and requests to the server are very small: just a hash, the algorithm used for the hash, and the key name. No more sending a 4GiB ISO over the network only to have the server hash it, that all is done before the request starts.</p>

<p>The last thing that’s <em>really</em> cool about this approach is that if Fedora decides it needs a new signing server and spends some big bucks on a fancy hardware security module, it will definitely ship with a PKCS#11 module of its own so we can start using it with our existing tooling, no development required. If Siguldry stops being the right choice for Fedora, it’s really easy to swap it out.</p>

<h3 id="unix-socket-api">Unix Socket API</h3>

<p>The other thing I did was to implement a Siguldry client that binds a Unix socket and proxies requests from the local system to the remote Siguldry server. I did this because you can expose the socket into locked down environments, such as RPM build environments, install the PKCS#11 module into that environment, and sign things. Right now Fedora uses this general approach for SecureBoot, except it’s specific to the <code class="language-plaintext highlighter-rouge">pesign</code> utility. While I’d prefer to disconnect the signing event from the building of a package, it’s important to support the current workflows and this was a neat way to do that which is generic across signing tools.</p>

<p>It has another advantage. Since the Unix socket is set up using a systemd socket unit, we can sandbox the client proxy, and also configure it with the necessary credentials to connect to the Siguldry server and unlock signing keys. This lets you, if necessary, allow anyone to sign content without needing to manage secrets themselves. The secrets can be encrypted with <code class="language-plaintext highlighter-rouge">systemd-creds</code> and bound to hardware. All we have to do is ensure the keys that are configured that way get a special flag when queried via PKCS#11: the “protected authentication path” flag.</p>

<h2 id="siguldry-fedora-autopen">siguldry-fedora-autopen</h2>

<p>The primary way Fedora uses its signing server is via an AMQP consumer that automatically signs things. <a href="https://pagure.io/robosignatory">Robosignatory</a> is the current tool used, but it needs some significant changes to work with this new workflow. In particular, we don’t want to sign content serially, but the fedora-messaging Python library commonly used to interact with the AMQP broker doesn’t handle concurrency well. And, since we now call out to the particular tool used to sign content rather than sending it to the server, the consumer is primarily a mapping between message topics and those various tools.</p>

<p>All those reasons led me to re-implement it, and since I’ve got no imagination with names, it’s called <a href="https://github.com/fedora-infra/siguldry/tree/siguldry-fedora-autopen-0.1.0/siguldry-fedora-autopen">siguldry-fedora-autopen</a>. It uses the <a href="https://crates.io/crates/lapin">lapin</a> AMQP client with Tokio to manage hundreds or thousands of RPMs/ISOs/containers/etc signing operations at the same time. This means builds should no longer languish in the signing queue for many hours.</p>

<h2 id="ima">IMA</h2>

<p>All this probably (hopefully) sounds great, but as with all things there are a few problems. Well, really just one big problem. Back in the Fedora 37 days, we enabled IMA signing for RPMs. The short version of how that works is that each file inside an RPM gets signed. And, unfortunately, the PKCS#11 interface is synchronous. This means that <code class="language-plaintext highlighter-rouge">rpmsign</code> requests a signature when it creates an OpenPGP signature on the RPM header. It then requests a signature for each file, waiting for each signature request to finish before starting the next one. Now, when the RPM only has dozens or a couple hundred files that happens fairly quickly. A signature might only take a couple milliseconds and the request/response latency might be a couple dozen more milliseconds (or a lot less depending on how close the server is from the client).</p>

<p>Of course, not all RPMs only have a few hundred files. Some have many, many thousand. For these, a simple OpenGPG signature takes less than a second (even if the RPM is, say, 10GiB). The IMA signing can take many minutes, depending on how many files it has. I’ve been running a client locally, with a server in a nearby datacenter, and the largest time I saw for a signing operation was around 40 minutes. This is really unfortunate, but it is important to remember that we can now do thousands of signing operations at the same time, so even when these slow builds are signed, other builds can be serviced in a timely manner.</p>

<p>There’s a couple ways we can make this better, but the “easiest” involve a custom signing implementation that avoids using the PKCS#11 path.</p>

<h2 id="whats-next">What’s Next?</h2>

<p>In the next few weeks I’m hopeful we’ll have enough time to sit down and deploy Siguldry to Fedora’s staging environment. I want to really kick the tires and ensure it’s rock solid before we move it to production, but I think it’s reasonable to hope for that in the next couple of months.</p>

<p>While that’s happening, I’m going to add support for ML-DSA signing. That will allow us to produce signatures that are safe in a post-quantum cryptography world. After that, I’ll investigate OpenPGP’s hybrid signature schemes, although given recent developments I wonder if we want to bother with those. I’ll defer to what the professional cryptographers have to say about that.</p>

<p>Sometime in the next few Fedora releases, though, you should expect to see new signature algorithms in use (pending FESCo approval etc etc).</p>

<h2 id="comments-and-feedback">Comments and Feedback</h2>

<p>Thoughts, comments, or feedback greatly welcomed on <a href="https://hachyderm.io/@jcline/116784346110417786">Mastodon</a></p></div>
    </summary>
    <updated>2026-06-20T19:17:00Z</updated>
    <published>2026-06-20T19:17:00Z</published>
    <category term="blog"/>
    <category term="fedora"/>
    <category term="signing"/>
    <source>
      <id>https://www.jcline.org/</id>
      <author>
        <name>Jeremy Cline</name>
      </author>
      <link href="https://www.jcline.org/" rel="alternate" type="text/html"/>
      <link href="https://www.jcline.org/feed.xml" rel="self" type="application/rss+xml"/>
      <subtitle>Blog about various things open source</subtitle>
      <title>Jeremy Cline's Blog</title>
      <updated>2026-07-09T19:43:54Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://www.scrye.com/blogs/nirik/posts/2026/06/20/flock-2026-recap/</id>
    <link href="https://www.scrye.com/blogs/nirik/posts/2026/06/20/flock-2026-recap/" rel="alternate" type="text/html"/>
    <title xml:lang="en">flock 2026 recap</title>
    <summary type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>Another wonderfull flock is in the books. This post is likely
to be kind of long, and was written a few days after I got back
home, so it's likely I forgot some things or misremembered them
somehow. If so, it's not intentional.</p>
<p>TLDR version: Another great flock. Lots of good conversations,
lots of good talks, good food, good friends. I'd like to give kudos
to all the people who put things on. It's not easy planning a large
event like this and at least from my perspective everything went
very smoothly.</p>
<section id="day-3-2">
<h2>Day -3 / -2</h2>
<p>My journey started a few days before flock on Thursday the 11th.
I had actually planned to come in a day early to recover from
travel, but it turns out there was a meeting scheduled then, so
I got to recover in the meeting instead (more on that in a minute).</p>
<p>Two hour drive to portland airport (PDX) turned into about 2.5 due
to traffic, but I had planned buffer so it was fine. This time
I was taking icelandair via Keflavík (KEF) instead of my usual
jump via Amsterdam. The transfer time was quite low (around an hour),
but I read that it was easy to transfer there.</p>
<p>The flight was fine, the transfer was a bit fun: They deplaned us out
on a tarmack and we had to take a bus to the terminal. That took a while
as they wanted the bus fully loaded. Then, they said the customs area
was understaffed today and would take longer than normal. So, I rushed
as best I could and ended up at my gate only to hear that the next flight
was waiting for crew and hadn't boarded yet. :)</p>
<p>The hotel in prague was the same one as last years flock. Last year I had
stayed at a nearby hotel, but this year I just stayed at the conference
one. I have to say the rooms were nicer there and it was pretty nice
to not have to walk over and back a lot.</p>
<p>I got in friday afternoon and took a short nap, then met up with Tomas
and Adam for dinner. We picked a nice sounding place nearby and it
was a bunch of nice conversation and food.</p>
</section>
<section id="day-1">
<h2>Day -1</h2>
<p>Saturday I had planned to recover from travel, but instead I went to
a face to face meeting we had with a bunch of the Red Hatters that were
coming to flock. There wasn't anything secret here, it was mostly just
discussing what various groups were working on and how we could all
help each other out and get things landed/working.</p>
<p>There was a lot of technical discussion and planning type things
along with lots of things that were further discussed at flock.</p>
<p>I was able to chime in on some hardware questions and some
cloud resources along with some policy questions.</p>
<p>Saturday evening was the 'sponsors dinner' with a bunch of folks from
companies sponsoring flock along with leeds of various parts of the project.
Amusingly, it was in the same resturant we were at the previous night!
It was all good though. I sat near Jermey Cline, David Duncan and Jef Speleta
and we had a bunch of conversations on tons of topics.</p>
</section>
<section id="day-1-1">
<h2>Day 1</h2>
<p>The first day this year was workshops, the keynote and other regular talks
would be the next day. I can understand why you might want to do things this
way as it allows you to get people excited and working on something and then
leverage that work for their talk in the later days. On the other hand it means
that the workshops had a lot of talk/presentation before being able to get
to the actual work part of the workshop.</p>
<p>The first slot I ended up in the 'hallway track' (as I would many times in
the coming days). Talked to too many people to even list. :)</p>
<p>Next I went to the forgejo workshop. It was fine and there were a few questions,
but either everyone had burned out their discussions on it, or the folks with
those questions/discussions weren't there as it seemed to go very quietly.
I think lots of contributors are getting used to forge.fedoraproject.org now
and can imgaine how a migrated src.fedoraproject.org might look.</p>
<p>Lunch was up next. This year the mentor summit was doing a 'lunch and learn'
thing each day, and I went each day. I sat at the 'operations' table on Sunday
and had a great conversation with several new to fedora folks. We talked about
matrix a fair bit and software we all use.</p>
<p>After lunch I went to the Fedora Data &amp; Analytics Workshop with Justin and
Michael. I think things were pretty interesting, but we spent a lot of
time getting everyone up to speed on the background and only had a short
time at the end to work on workshoppy things. Still, very interesting stuff
here. We have lots of data, but we dont really analize it very much, and
I am hopefull this system will allow us to do so! Right after this workshop
I got pulled into a hallway track discussion and didn't get a chance to
say Hi to Michael in person. :(</p>
<p>After that was more hallway discussions and then our team had a team dinner.
Always great to see people I work with day to day over the internet in person.
Some of us then rushed back from dinner for...</p>
<p>The flock 2026 candy swap. This year was even bigger I think that last year.
We barely fit in the bar where this was happening. Tons of good stuff, lots of
good stories. A few people said to me "Do you do this every year? Wow, this is
great! I would have brought something if I knew". After the swap, beers in the
bar and I managed to have a nice discussion on Books with MattH and Aoife
along with some music discussions with many others.</p>
</section>
<section id="day-2">
<h2>Day 2</h2>
<p>Monday started out with the keynote state of Fedora from Jef. There was even
a nice bit of stats out of the data workshop that was interesting.</p>
<p>Then up in the same room was the Council round table, followed by the FESCo
one. Interestingly, the Council didn't get any AI related questions, but
FESCo did. Do watch those recordings if you are interested in any of those
questions/answers.</p>
<p>There was a talk on hummingbird after that, which was great. I'm excited
to see hummingbird and to see what it's going to grow into.</p>
<p>Mentor summit lunch and learn monday was the 'infrastructure' table for me.
We had folks from Azure linux and Amazon linux (both now based on Fedora)
asking a bunch of infrastructure questions. I also asked them a bunch about
their infrastructure too. It was very encouraging this year to not only see
groups like this at flock, but asking how they can be more involved and help
Fedora out and thus help themselves as downstreams. I'm really hopefull we
can help each other and all end up better for it. This was probibly the most
encouraging thing I saw at flock this year. :)</p>
<p>After lunch I went to Lenkas Forgejo runners on fedora forge talk. This was
largely stuff I knew about, but it was great to see all in one place. There
were some nice questions. We are definitely seeing some good use from these
runners and it's good to see work on them continue.</p>
<p>I had a bunch of hallway conversations after that, then off to...</p>
<p>Post-quantum cryptography for Fedora infrastructure with Alexander and Jakob.
The timelines here are really scary to me. There's a lot thats just starting
to land now, but the dates for moving things are coming up super fast.
I hope it will all work out, but it's a lot of things and a lot of work. :(</p>
<p>Dinner Monday was the flock reception. It was in a nearby outdoor food court,
which I had actually had lunch at last year. It was a nice setup, they blocked
off a large area of tables for us and gave us vouchers to get a meal at any of
the... many food places. They also brought us all a bunch of free appitizers
to the point where it almost wasn't worth getting a real meal. :)
Had a lot of conversations on a lot of topics here. I managed to find Michael
Winters and we started to talk, but then they called the group photo
and we were seperated, then after that we both got pulled into other conversations.
(This was a theme)</p>
<p>A group of us then went to a belgian beer place and stayed talking until
the wee hours.</p>
</section>
<section id="day-3">
<h2>Day 3</h2>
<p>The last day already!</p>
<p>I started with the "RHEL11 and what it means for you" talk. Nice to see dates
listed there and an attempt to get fedora things landed in time for RHEL11.</p>
<p>Next up was the state of the fedora kernel from Justin. Nothing too much that
I didn't know, but was good to clarify things and hear questions from folks.</p>
<p>In the next slot I really wanted to go to Kashyap's riscv talk, but unfortunately
that was when _my_ talk was scheduled also. ;( So, I gave my talk about scrapers.
It was a pretty nice crowd, and there were lots of good questions from people.
I did have AV problems however, they were unable to capture from the projector
for the live stream, so they could only use the camera to capture it. I have
no idea why that was happening. Somehow also, I wasn't able to read my notes
while giving the talk, so I missed saying a few things I meant to mention.
Things like: "robots.txt was orig called RobotsNotWanted.txt", and asking if
anyone remembered the /. effect. ;) Overall I think it went well.</p>
<p>After a bit of hallway conversation, next up with the talk about Microsoft
contributions to Fedora. It's great for this work to get highlighted. I am
very happy with all the work Jeremy has been doing on our signing infrastructure,
along with all the other places they contribute.</p>
<p>I then went to the "Upgrading Fedora Infrastructure from Nagios to Zabbix" talk.
This was given by Michal, because Greg was unable to attend. He did a fine job
going over things, and Greg was in the matrix room for the talk answering questions.
I'm super happy about this finally getting over the finish line (at least the
initial one) I think we are in a much better place.</p>
<p>Last day of Mentor summit lunch and learn I sat at the Release Engineering table.
We had a mix of folks this time. Some Amazon linux folks, someone asking how to
get involved that was just starting out, and someone who was involved in server/docs.
We had a pretty wide ranging conversation.</p>
<p>After lunch were the lightning talks. There were a bunch of them, and I was
amazed at how many folks had slides. I guess they were ready to talk about their
thing at a minutes notice. Lots of interesting stuff in there. Worth a video
re-watch.</p>
<p>Finally, the last session of the conference: The Fedora’s Contributor Recognition
Program. I won this award last year, and was involved a small amount with choosing
winners this year. All the proposed candidates were great! Fedora is nothing without
it's contibutors and the folks awarded were all super well deserving folks.
Make sure you say 'thanks' to those who help you.</p>
<p>With the conference officially over, I was very tired, so I went to take a nap.
Michael Winters was down in the bar, and I said I would try and meet up after
I got up. So, after my nap I wandered down and... I swear I saw him walking off
to dinner with a group of folks. Missed again. (I'm not avoiding you Michael!
Honest!)</p>
<p>I ended up at dinner with a small group and we actually talked non computer nerd
things ( music, podcasts, and even politics ).</p>
</section>
<section id="day-4">
<h2>Day 4</h2>
<p>The next day was the travel home. Due to timezones I would leave the Prague airport
at 2pm and get into portland at like 5:30pm. (it is NOT 3.5 hours of flights).</p>
<p>I again had fun with the transfer in iceland. Our plane from Pague was a few minutes
late, then we needed to take the bus to the terminal, then passport control was
even more backed up than it was last time. I finally got to my gate and their
was an attendet there who asked me my name. I then took a bus with only 3 other people
on it to the plane. They held it for us, but I made it.</p>
<p>The rest of the trip back was uneventfull, but will take a while to recover.
Luckily, there's a holiday this friday so I do have a 3 day weekend.</p>
</section>
<section id="a-few-downsides">
<h2>A few Downsides</h2>
<p>Overall I think things went super nicely and smoothly, but:</p>
<ul class="simple">
<li><p>The weird AV issues for my talk. It's likely something off about my aarch64 laptop.
So, perhaps I should take a boring x86_64 one next time. Or spend some time poking
at it before time for my talk.</p></li>
<li><p>There were a lot of folks that I usually look forward to talking with in person that were
not able to make it this time. Due to various reasons, but it was sad to not see them.
You all know who you are, you were missed.</p></li>
</ul>
</section>
<section id="hallway-conversations">
<h2>Hallway conversations</h2>
<p>There were a ton of hallway conversations, and I am sure I don't remember most of them
but the few I do:</p>
<ul class="simple">
<li><p>Alexander showed me a new rust based IDP setup he has been working on. Super cool looking
and very on point for Fedora.</p></li>
<li><p>There was a number of AI conversations, but more of the 'what do you think is going
to happen when the bubble bursts' than anything else. There was a foundations whiteboard
where people could add things around the 4 foundations and under friends was "more people,
less AI".</p></li>
<li><p>Lots of good talks with Amazon Linux and Azure Linux folks. I hope to see them chime in
on matrix with questions/comments/contributions.</p></li>
<li><p>Jeremy and I had a number of talks about the new signing stuff.</p></li>
<li><p>Nice to see Toshio again and talk with him on lots of things.</p></li>
<li><p>Had some good talks about 2fa and otp and such with Gotmax23.</p></li>
<li><p>A conversation I had a number of times was "where should we do flock next year?".
There were a lot of ideas, no telling what will win out. We might not do too badly
to just do it in Prague again, IMHO.</p></li>
</ul>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116784039502240226">https://fosstodon.org/@nirik/116784039502240226</a></p>
</section></div>
    </summary>
    <content type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>Another wonderfull flock is in the books. This post is likely
to be kind of long, and was written a few days after I got back
home, so it's likely I forgot some things or misremembered them
somehow. If so, it's not intentional.</p>
<p>TLDR version: Another great flock. Lots of good conversations,
lots of good talks, good food, good friends. I'd like to give kudos
to all the people who put things on. It's not easy planning a large
event like this and at least from my perspective everything went
very smoothly.</p>
<section id="day-3-2">
<h2>Day -3 / -2</h2>
<p>My journey started a few days before flock on Thursday the 11th.
I had actually planned to come in a day early to recover from
travel, but it turns out there was a meeting scheduled then, so
I got to recover in the meeting instead (more on that in a minute).</p>
<p>Two hour drive to portland airport (PDX) turned into about 2.5 due
to traffic, but I had planned buffer so it was fine. This time
I was taking icelandair via Keflavík (KEF) instead of my usual
jump via Amsterdam. The transfer time was quite low (around an hour),
but I read that it was easy to transfer there.</p>
<p>The flight was fine, the transfer was a bit fun: They deplaned us out
on a tarmack and we had to take a bus to the terminal. That took a while
as they wanted the bus fully loaded. Then, they said the customs area
was understaffed today and would take longer than normal. So, I rushed
as best I could and ended up at my gate only to hear that the next flight
was waiting for crew and hadn't boarded yet. :)</p>
<p>The hotel in prague was the same one as last years flock. Last year I had
stayed at a nearby hotel, but this year I just stayed at the conference
one. I have to say the rooms were nicer there and it was pretty nice
to not have to walk over and back a lot.</p>
<p>I got in friday afternoon and took a short nap, then met up with Tomas
and Adam for dinner. We picked a nice sounding place nearby and it
was a bunch of nice conversation and food.</p>
</section>
<section id="day-1">
<h2>Day -1</h2>
<p>Saturday I had planned to recover from travel, but instead I went to
a face to face meeting we had with a bunch of the Red Hatters that were
coming to flock. There wasn't anything secret here, it was mostly just
discussing what various groups were working on and how we could all
help each other out and get things landed/working.</p>
<p>There was a lot of technical discussion and planning type things
along with lots of things that were further discussed at flock.</p>
<p>I was able to chime in on some hardware questions and some
cloud resources along with some policy questions.</p>
<p>Saturday evening was the 'sponsors dinner' with a bunch of folks from
companies sponsoring flock along with leeds of various parts of the project.
Amusingly, it was in the same resturant we were at the previous night!
It was all good though. I sat near Jermey Cline, David Duncan and Jef Speleta
and we had a bunch of conversations on tons of topics.</p>
</section>
<section id="day-1-1">
<h2>Day 1</h2>
<p>The first day this year was workshops, the keynote and other regular talks
would be the next day. I can understand why you might want to do things this
way as it allows you to get people excited and working on something and then
leverage that work for their talk in the later days. On the other hand it means
that the workshops had a lot of talk/presentation before being able to get
to the actual work part of the workshop.</p>
<p>The first slot I ended up in the 'hallway track' (as I would many times in
the coming days). Talked to too many people to even list. :)</p>
<p>Next I went to the forgejo workshop. It was fine and there were a few questions,
but either everyone had burned out their discussions on it, or the folks with
those questions/discussions weren't there as it seemed to go very quietly.
I think lots of contributors are getting used to forge.fedoraproject.org now
and can imgaine how a migrated src.fedoraproject.org might look.</p>
<p>Lunch was up next. This year the mentor summit was doing a 'lunch and learn'
thing each day, and I went each day. I sat at the 'operations' table on Sunday
and had a great conversation with several new to fedora folks. We talked about
matrix a fair bit and software we all use.</p>
<p>After lunch I went to the Fedora Data &amp; Analytics Workshop with Justin and
Michael. I think things were pretty interesting, but we spent a lot of
time getting everyone up to speed on the background and only had a short
time at the end to work on workshoppy things. Still, very interesting stuff
here. We have lots of data, but we dont really analize it very much, and
I am hopefull this system will allow us to do so! Right after this workshop
I got pulled into a hallway track discussion and didn't get a chance to
say Hi to Michael in person. :(</p>
<p>After that was more hallway discussions and then our team had a team dinner.
Always great to see people I work with day to day over the internet in person.
Some of us then rushed back from dinner for...</p>
<p>The flock 2026 candy swap. This year was even bigger I think that last year.
We barely fit in the bar where this was happening. Tons of good stuff, lots of
good stories. A few people said to me "Do you do this every year? Wow, this is
great! I would have brought something if I knew". After the swap, beers in the
bar and I managed to have a nice discussion on Books with MattH and Aoife
along with some music discussions with many others.</p>
</section>
<section id="day-2">
<h2>Day 2</h2>
<p>Monday started out with the keynote state of Fedora from Jef. There was even
a nice bit of stats out of the data workshop that was interesting.</p>
<p>Then up in the same room was the Council round table, followed by the FESCo
one. Interestingly, the Council didn't get any AI related questions, but
FESCo did. Do watch those recordings if you are interested in any of those
questions/answers.</p>
<p>There was a talk on hummingbird after that, which was great. I'm excited
to see hummingbird and to see what it's going to grow into.</p>
<p>Mentor summit lunch and learn monday was the 'infrastructure' table for me.
We had folks from Azure linux and Amazon linux (both now based on Fedora)
asking a bunch of infrastructure questions. I also asked them a bunch about
their infrastructure too. It was very encouraging this year to not only see
groups like this at flock, but asking how they can be more involved and help
Fedora out and thus help themselves as downstreams. I'm really hopefull we
can help each other and all end up better for it. This was probibly the most
encouraging thing I saw at flock this year. :)</p>
<p>After lunch I went to Lenkas Forgejo runners on fedora forge talk. This was
largely stuff I knew about, but it was great to see all in one place. There
were some nice questions. We are definitely seeing some good use from these
runners and it's good to see work on them continue.</p>
<p>I had a bunch of hallway conversations after that, then off to...</p>
<p>Post-quantum cryptography for Fedora infrastructure with Alexander and Jakob.
The timelines here are really scary to me. There's a lot thats just starting
to land now, but the dates for moving things are coming up super fast.
I hope it will all work out, but it's a lot of things and a lot of work. :(</p>
<p>Dinner Monday was the flock reception. It was in a nearby outdoor food court,
which I had actually had lunch at last year. It was a nice setup, they blocked
off a large area of tables for us and gave us vouchers to get a meal at any of
the... many food places. They also brought us all a bunch of free appitizers
to the point where it almost wasn't worth getting a real meal. :)
Had a lot of conversations on a lot of topics here. I managed to find Michael
Winters and we started to talk, but then they called the group photo
and we were seperated, then after that we both got pulled into other conversations.
(This was a theme)</p>
<p>A group of us then went to a belgian beer place and stayed talking until
the wee hours.</p>
</section>
<section id="day-3">
<h2>Day 3</h2>
<p>The last day already!</p>
<p>I started with the "RHEL11 and what it means for you" talk. Nice to see dates
listed there and an attempt to get fedora things landed in time for RHEL11.</p>
<p>Next up was the state of the fedora kernel from Justin. Nothing too much that
I didn't know, but was good to clarify things and hear questions from folks.</p>
<p>In the next slot I really wanted to go to Kashyap's riscv talk, but unfortunately
that was when _my_ talk was scheduled also. ;( So, I gave my talk about scrapers.
It was a pretty nice crowd, and there were lots of good questions from people.
I did have AV problems however, they were unable to capture from the projector
for the live stream, so they could only use the camera to capture it. I have
no idea why that was happening. Somehow also, I wasn't able to read my notes
while giving the talk, so I missed saying a few things I meant to mention.
Things like: "robots.txt was orig called RobotsNotWanted.txt", and asking if
anyone remembered the /. effect. ;) Overall I think it went well.</p>
<p>After a bit of hallway conversation, next up with the talk about Microsoft
contributions to Fedora. It's great for this work to get highlighted. I am
very happy with all the work Jeremy has been doing on our signing infrastructure,
along with all the other places they contribute.</p>
<p>I then went to the "Upgrading Fedora Infrastructure from Nagios to Zabbix" talk.
This was given by Michal, because Greg was unable to attend. He did a fine job
going over things, and Greg was in the matrix room for the talk answering questions.
I'm super happy about this finally getting over the finish line (at least the
initial one) I think we are in a much better place.</p>
<p>Last day of Mentor summit lunch and learn I sat at the Release Engineering table.
We had a mix of folks this time. Some Amazon linux folks, someone asking how to
get involved that was just starting out, and someone who was involved in server/docs.
We had a pretty wide ranging conversation.</p>
<p>After lunch were the lightning talks. There were a bunch of them, and I was
amazed at how many folks had slides. I guess they were ready to talk about their
thing at a minutes notice. Lots of interesting stuff in there. Worth a video
re-watch.</p>
<p>Finally, the last session of the conference: The Fedora’s Contributor Recognition
Program. I won this award last year, and was involved a small amount with choosing
winners this year. All the proposed candidates were great! Fedora is nothing without
it's contibutors and the folks awarded were all super well deserving folks.
Make sure you say 'thanks' to those who help you.</p>
<p>With the conference officially over, I was very tired, so I went to take a nap.
Michael Winters was down in the bar, and I said I would try and meet up after
I got up. So, after my nap I wandered down and... I swear I saw him walking off
to dinner with a group of folks. Missed again. (I'm not avoiding you Michael!
Honest!)</p>
<p>I ended up at dinner with a small group and we actually talked non computer nerd
things ( music, podcasts, and even politics ).</p>
</section>
<section id="day-4">
<h2>Day 4</h2>
<p>The next day was the travel home. Due to timezones I would leave the Prague airport
at 2pm and get into portland at like 5:30pm. (it is NOT 3.5 hours of flights).</p>
<p>I again had fun with the transfer in iceland. Our plane from Pague was a few minutes
late, then we needed to take the bus to the terminal, then passport control was
even more backed up than it was last time. I finally got to my gate and their
was an attendet there who asked me my name. I then took a bus with only 3 other people
on it to the plane. They held it for us, but I made it.</p>
<p>The rest of the trip back was uneventfull, but will take a while to recover.
Luckily, there's a holiday this friday so I do have a 3 day weekend.</p>
</section>
<section id="a-few-downsides">
<h2>A few Downsides</h2>
<p>Overall I think things went super nicely and smoothly, but:</p>
<ul class="simple">
<li><p>The weird AV issues for my talk. It's likely something off about my aarch64 laptop.
So, perhaps I should take a boring x86_64 one next time. Or spend some time poking
at it before time for my talk.</p></li>
<li><p>There were a lot of folks that I usually look forward to talking with in person that were
not able to make it this time. Due to various reasons, but it was sad to not see them.
You all know who you are, you were missed.</p></li>
</ul>
</section>
<section id="hallway-conversations">
<h2>Hallway conversations</h2>
<p>There were a ton of hallway conversations, and I am sure I don't remember most of them
but the few I do:</p>
<ul class="simple">
<li><p>Alexander showed me a new rust based IDP setup he has been working on. Super cool looking
and very on point for Fedora.</p></li>
<li><p>There was a number of AI conversations, but more of the 'what do you think is going
to happen when the bubble bursts' than anything else. There was a foundations whiteboard
where people could add things around the 4 foundations and under friends was "more people,
less AI".</p></li>
<li><p>Lots of good talks with Amazon Linux and Azure Linux folks. I hope to see them chime in
on matrix with questions/comments/contributions.</p></li>
<li><p>Jeremy and I had a number of talks about the new signing stuff.</p></li>
<li><p>Nice to see Toshio again and talk with him on lots of things.</p></li>
<li><p>Had some good talks about 2fa and otp and such with Gotmax23.</p></li>
<li><p>A conversation I had a number of times was "where should we do flock next year?".
There were a lot of ideas, no telling what will win out. We might not do too badly
to just do it in Prague again, IMHO.</p></li>
</ul>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116784039502240226">https://fosstodon.org/@nirik/116784039502240226</a></p>
</section></div>
    </content>
    <updated>2026-06-20T17:22:33Z</updated>
    <published>2026-06-20T17:22:33Z</published>
    <category label="#flocktofedora" term="flocktofedora"/>
    <category label="fedora" term="fedora"/>
    <category label="flock" term="flock"/>
    <category label="linux" term="linux"/>
    <author>
      <name>nirik</name>
    </author>
    <source>
      <id>https://www.scrye.com/blogs/nirik/categories/fedora.atom</id>
      <author>
        <name>nirik</name>
      </author>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora.atom" rel="self" type="application/atom+xml"/>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora/" rel="alternate" type="text/html"/>
      <title xml:lang="en">Kevin's musings (Posts about fedora)</title>
      <updated>2026-07-04T19:53:19Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>urn:md5:7858063a901036d1bb0dfe8c6c0b0371</id>
    <link href="https://blog.remirepo.net/post/2026/06/19/PHP-version-8.4.23RC1-and-8.5.8RC1" rel="alternate" type="text/html"/>
    <title>🎲 PHP version 8.4.23RC1 and 8.5.8RC1</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p><em>Release Candidate</em> versions are available in the testing repository for <strong>Fedora</strong> and <strong>Enterprise Linux</strong> (RHEL / CentOS / Alma / Rocky and other clones) to allow more people to test them. They are available as <em>Software Collections</em>, for parallel installation, the perfect solution for such tests, and as base packages.</p>

<p>RPMs of <strong>PHP version 8.5.8RC1</strong> are available</p>

<ul>
	<li>as base packages in the <strong>remi-modular-test </strong>for<strong> Fedora </strong><strong>42-44</strong> and <strong>Enterprise Linux</strong> <strong>≥ 8</strong></li>
	<li>as <strong>SCL </strong>in <strong>remi-test</strong> repository</li>
</ul>

<p>RPMs of <strong>PHP version 8.4.23RC1</strong> are available</p>

<ul>
	<li>as base packages in the <strong>remi-modular-test </strong>for<strong> Fedora </strong><strong>42-44</strong> and <strong>Enterprise Linux</strong> <strong>≥ 8</strong></li>
	<li>as <strong>SCL </strong>in <strong>remi-test</strong> repository</li>
</ul>

<p>ℹ️ The packages are available for <strong>x86_64</strong> and <strong>aarch64</strong>.</p> <p>ℹ️ <strong>PHP version 8.3</strong> is now in <a href="https://news-web.php.net/php.internals/129723">security mode only</a>, so no more RC will be released.</p>

<p>ℹ️ Installation: follow the <a href="https://rpms.remirepo.net/wizard/">wizard</a> instructions.</p>

<p>ℹ️ Announcements:</p>

<ul><!--
    <li>PHP 8.5.1RC1 is not yet announced</li>
-->
	<li><a href="https://news-web.php.net/php.qa/69541">PHP 8.5.8RC1 available for testing</a></li>
	<li><a href="https://news-web.php.net/php.qa/69542">PHP 8.4.23RC1 available for testing</a></li>
</ul>

<p><strong>Parallel installation</strong> of version <strong>8.5</strong> as Software Collection:</p>

<pre>yum --enablerepo=remi-test install php85</pre>

<p><strong>Parallel installation</strong> of version <strong>8.4</strong> as Software Collection:</p>

<pre>yum --enablerepo=remi-test install php84</pre>

<p><strong>Update</strong> of system version <strong>8.5</strong>:</p>

<pre>dnf module switch-to php:remi-8.5
dnf --enablerepo=remi-modular-test update php\*</pre>

<p><strong>Update</strong> of system version <strong>8.4</strong>:</p>

<pre>dnf module switch-to php:remi-8.4
dnf --enablerepo=remi-modular-test update php\*</pre>

<p>ℹ️ Notice:</p>

<ul>
	<li>version <strong>8.5.8RC1</strong> is in Fedora <em>rawhide</em> for <strong>QA</strong></li>
	<!--

    <li>version <a class="ref-post" href="https://blog.remirepo.net/post/2025/09/26/PHP-on-the-road-to-the-8.5.0-release">8.5.0RC4</a>&nbsp;is also available in the repository</li>
-->
	<li>EL-10 packages are built using RHEL-<strong>10.2</strong> and <strong>EPEL-10.2</strong></li>
	<li>EL-9 packages are built using RHEL-<strong>9.8</strong> and <strong>EPEL-9</strong></li>
	<li>EL-8 packages are built using RHEL-<strong>8.10</strong> and <strong>EPEL-8</strong></li>
	<li><strong>oci8</strong> extension uses the <strong>RPM</strong> of the <strong>Oracle Instant Client</strong> version <strong>23.26</strong> on <strong>x86_64</strong> and <strong>aarch64</strong></li>
	<li><strong>intl </strong>extension uses <strong>libicu 74.2</strong></li>
	<li>RC version is usually the same as the <strong>final</strong> version (no change accepted after RC, exception for security fix).</li>
	<li>versions 8.4.19 and 8.5.4 are planed for <strong>March 12th</strong>, in 2 weeks.</li>
</ul>

<p align="center"><strong>Software Collections</strong> (php84, php85)</p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php85-php-common&amp;version=8.5.8~RC1&amp;lang=en" style="margin: 1em auto; display: block;"/></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php84-php-common&amp;version=8.4.23~RC1&amp;lang=en" style="margin: 1em auto; display: block;"/></p>

<p align="center"><strong>Base packages</strong> (php)</p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.5.8~RC1&amp;lang=en" style="margin: 1em auto; display: block;"/></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.4.23~RC1&amp;lang=en" style="margin: 1em auto; display: block;"/></p></div>
    </summary>
    <updated>2026-06-19T03:59:00Z</updated>
    <published>2026-06-19T03:59:00Z</published>
    <category term="Archives"/>
    <category term="Beta"/>
    <category term="PHP"/>
    <category term="RPM"/>
    <author>
      <name>Remi</name>
    </author>
    <source>
      <id>https://blog.remirepo.net/en</id>
      <link href="https://blog.remirepo.net/en" rel="alternate" type="text/html"/>
      <link href="https://blog.remirepo.net/feed/en/rss2" rel="self" type="application/rss+xml"/>
      <rights>Licence: Creative Commons Attribution-ShareAlike 4.0 International License.</rights>
      <subtitle>Remi's RPM repository blog Information about RPM PHP Fedora RHEL and CentOS</subtitle>
      <title>Remi's RPM repository - Blog</title>
      <updated>2026-07-10T04:19:09Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://gbenson.net/?p=1065</id>
    <link href="https://gbenson.net/longintrepr-h/" rel="alternate" type="text/html"/>
    <title>longintrepr.h</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">Did your pip install fail with longintrepr.h: No such file or directory? The file likely is on your system, but it sometime or another it was moved, from /usr/include/python3.xx/longintrepr.h to /usr/include/python3.xx/cpython/longintrepr.h. The proper fix is to update the package in question with the new path, but if you’re installing an old version of something or … <a class="more-link" href="https://gbenson.net/longintrepr-h/">Continue reading <span class="screen-reader-text">longintrepr.h</span> <span class="meta-nav">→</span></a></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Did your <code>pip install</code> fail with <code>longintrepr.h: No such file or directory</code>? The file likely <em>is</em> on your system, but it sometime or another it was moved, <span style="white-space: nowrap;">from <code>/usr/include/python3.xx/longintrepr.h</code></span> <span style="white-space: nowrap;">to <code>/usr/include/python3.xx/cpython/longintrepr.h</code></span>. The <em>proper</em> fix is to update the package in question with the new path, but if you’re installing an old version of something or a package that’s no longer maintained you can work around it like this: </p>
<pre>ln -s /usr/include/python3.*/cpython/longintrepr.h .venv/include</pre></div>
    </content>
    <updated>2026-06-18T11:38:44Z</updated>
    <published>2026-06-18T11:38:44Z</published>
    <category term="HOWTOs"/>
    <category term="Python"/>
    <category term="HOWTO"/>
    <author>
      <name>gbenson</name>
    </author>
    <source>
      <id>https://gbenson.net</id>
      <logo>https://i0.wp.com/gbenson.net/wp-content/uploads/2020/02/cropped-20170615110709_glitch.jpg?fit=32%2C32&amp;ssl=1</logo>
      <link href="https://gbenson.net/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://gbenson.net" rel="alternate" type="text/html"/>
      <title>gbenson.net</title>
      <updated>2026-06-18T11:42:48Z</updated>
    </source>
  </entry>

  <entry>
    <id>http://frostyx.cz/posts/flock-to-fedora-report-2026</id>
    <link href="http://frostyx.cz/posts/flock-to-fedora-report-2026" rel="alternate" type="text/html"/>
    <title>Flock to Fedora report 2026</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>This post is tough to write because <a href="https://fedoraproject.org/flock/">Flock to Fedora</a> is my
favorite conference, and <a href="https://frostyx.cz/posts/flock-to-fedora-report-2025">last year’s Flock</a> might have been the
best conference I’ve ever been to. I love the Fedora community, Prague is
beautiful, the venue is nice, we always have so many interesting talks and
workshops, the organizers do an amazing job preparing this event for us, so I
feel really guilty saying that I did not have much fun this year. That is 100%
on me, though. Flock bears no blame.</p>

<p>It wasn’t exactly the wisest decision ever to run
<a href="https://www.runczech.com/cs/akce/mattoni-running-festival-olomouc-2026/zavody/mattoni-1-2maraton-olomouc">my first half-marathon</a> the very evening before the conference,
and then waking up early to commute to Prague. It must have hit me much more
than I was willing to admit. I feel fine physically, but I can’t pay attention
to anything because nothing feels exciting. That is the most lifeless I’ve felt
in a long time.</p>

<p>So, in case anyone is wondering … it was me, not you.</p>

<h3 id="highlights">Highlights</h3>

<p>Despite all that, these were the highlights of the event for me.</p>

<h4 id="forging-fedora-projects-future-with-forgejo"><a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/BTDZAA/">Forging Fedora Project’s Future With Forgejo</a></h4>

<p>Great job on the migration from <a href="https://pagure.io">pagure.io</a> to
<a href="https://forge.fedoraproject.org">forge.fedoraproject.org</a>. It was
handled exceptionally well. Next, we look forward to the migration of
<a href="https://src.fedoraproject.org">src.fedoraproject.org</a> to Forgejo, which can’t come
soon enough. <a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/speaker/V3TBBG/">Tomáš Hrčka</a> teased us that this migration may take
considerably less time than the previous one because they already know how to do
things (e.g., deploy Forgejo, etc).</p>

<h4 id="diy-ai-build-a-private-customizable-chatbot-on-lean-hardware"><a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/DYZJHQ/">DIY AI: Build a Private, Customizable Chatbot on Lean Hardware</a></h4>

<p><a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/speaker/M9CWQQ/">Ellis Low</a> showed us how to run an LLM on our laptops through Llama
and how to interact with it. I really appreciated him saying that, except for
this one small text-in, text-out magic black box, everything else is standard
software engineering as we know it.</p>

<h4 id="fedora-council-strategic-proposals--fesco-qa"><a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/PHZW3D/">Fedora Council Strategic Proposals + FESCo Q&amp;A</a></h4>

<p>Most of the discussion revolved around a decline of new contributors and us
failing to connect with the next generation. “They talk about changing
wallpaper, we talk about burnout” – <a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/speaker/TGZDY8/">Aleksandra Fedorova</a>.</p>

<h4 id="whats-cooking-in-copr-testing-farm-tmt-packit-and-log-detective"><a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/FHYW3G/">What’s Cooking in Copr, Testing Farm, tmt, Packit and Log Detective</a></h4>

<p>I found <a href="https://github.com/praiskup">Pavel Raiskup</a>’s return to the stage hilarious.</p>

<h4 id="scrapers-gotta-scrape-scrape-scrape"><a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/FWSYWR/">Scrapers gotta scrape scrape scrape</a></h4>

<p>As presentations go, <a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/speaker/G8QMRU/">Kevin Fenzi</a>’s talk about AI scrapers was
the best. It started with minor A/V dificulities, which is a nice reminder
to not feel bad, the next time it happens to you, because it happens to
everybody. Even the main infra guy. Semi-joking aside, I enjoyed the brief
history of web scraping and Kevin’s taxonomy of scrapers, clearly showing that
not all scrapers are the same (e.g.,
<a href="https://web.archive.org/">web.archive.org</a>). However, the current AI scrapers
are the plague of the internet, and I am so glad the Fedora Infra team fights
them as best as they can to keep our services running.</p>

<h4 id="chat-with-adam">Chat with Adam</h4>

<p>I ran into my former Copr team mate <a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/8GWWTY/">Adam Šamalík</a> in the hallway,
and we had a nice chat about life. When we still worked together (10 years ago,
oh how the time flies), I randomly asked him what he did on a weekend. “We had
no plans, so we bought plane tickets and went on a date to Amsterdam with my
girlfriend”. Fucking what?! That was the coolest response ever. Since that
day, I remember it every time my creaking, lazy bones struggle to do something
spontaneous. Why am I telling it now? Adam is now happily living in the
Netherlands full-time. Funny how one impromptu decision can completely change
your life.</p>

<h4 id="chat-with-emmanuel">Chat with Emmanuel</h4>

<p>Made friends with <a href="https://fedoraproject.org/wiki/User:Eseyman">Emmanuel Seyman</a>. He said hello after seeing
the <a href="https://www.youtube.com/watch?v=m59OdC3BLp0">Fedora Podcast episode with me as a guest</a>. I really
enjoyed our chat, and I am going to follow up online because I think he’ll
really like <a href="https://github.com/sundaram123krishnan/">Sundaram Krishnan</a>’s project
<a href="https://github.com/sundaram123krishnan/coprtree">coprtree</a>.</p>

<h4 id="chat-with-miro">Chat with Miro</h4>

<p><a href="https://cfp.fedoraproject.org/flock-to-fedora-2026/speaker/RTZAUD/">Miro Hrončok</a> shared some of his ideas about improving the
<a href="https://docs.fedoraproject.org/en-US/package-maintainers/Package_Review_Process/">Fedora Package Review Process</a> with me. This deserves an
article on its own, so stay tuned.</p>

<p>Edit: Please read the <a href="https://frostyx.cz/posts/fedora-package-review-process-reimagined">Fedora Package Review Process reimagined</a>
article.</p></div>
    </summary>
    <updated>2026-06-17T00:00:00Z</updated>
    <published>2026-06-17T00:00:00Z</published>
    <source>
      <id>http://frostyx.cz</id>
      <author>
        <name>Jakub Kadlčík</name>
      </author>
      <link href="http://frostyx.cz" rel="alternate" type="text/html"/>
      <link href="http://frostyx.cz/fedora.xml" rel="self" type="application/rss+xml"/>
      <subtitle>Personal blog of Jakub Kadlčík (aka FrostyX)</subtitle>
      <title>FrostyX's blog - Fedora articles</title>
      <updated>2026-07-08T20:02:01Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://adam.younglogic.com/?p=11534</id>
    <link href="https://adam.younglogic.com/2026/06/downloading-from-gitlab/" rel="alternate" type="text/html"/>
    <title>Downloading from gitlab</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">We use gitlab to post internal releases of archives. I want to be able to automate the process of downloading these artifacts. Here it is using the glab CLI. export REPO=https://gitlab.com/YourCompany/sw-eng/product-manifest glab auth login --stdin &lt; ~/.token glab release list … <a href="https://adam.younglogic.com/2026/06/downloading-from-gitlab/">Continue reading <span class="meta-nav">→</span></a></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">We use gitlab to post internal releases of archives.  I want to be able to automate the process of downloading these artifacts.  Here it is using the <a href="https://docs.gitlab.com/cli/">glab CLI</a>.</p>



<span id="more-11534"/>



<pre lang="bash">export REPO=https://gitlab.com/YourCompany/sw-eng/product-manifest

glab auth login --stdin &lt; ~/.token
glab release list -R $REPO
glab release view item/5.4.3.2 -R $REPO
glab release download item/5.4.3.2 -R $REPO   --asset-name=sw-eng_5.4.3.2-product-subclass_binary-datestamp.tar.xz
</pre>



<p class="wp-block-paragraph">Note that each of these commands can be done with the <a href="https://docs.gitlab.com/cli/api/">glab api</a> subcommand instead, but the path needs to be escaped.</p>



<pre class="wp-block-code"><code>export REPO=YourCompany%2Fsw-eng%2Fproduct-manifest
glab api "$REPO/releases"
glab api "$REPO/releases/item%2F5.4.3.2"
</code></pre>



<p class="wp-block-paragraph">This last one gives you the URLs for direct download.  You want to save them to a file via redirection.</p>



<pre class="wp-block-code"><code>glab api "https://gitlab.com/api/v4/projects/99999999/packages/generic/sw_release/1.2.3.4/eng_1.2.3.4-product-name-version-version.tar.xz" &gt; eng_1.2.3.4-product-name-version-version.tar.xz</code></pre></div>
    </content>
    <updated>2026-06-16T16:30:57Z</updated>
    <published>2026-06-16T16:30:57Z</published>
    <category term="gitlab"/>
    <category term="shell"/>
    <category term="Software"/>
    <category term="Sysadmin"/>
    <author>
      <name>Adam Young</name>
    </author>
    <source>
      <id>https://adam.younglogic.com</id>
      <link href="https://adam.younglogic.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://adam.younglogic.com" rel="alternate" type="text/html"/>
      <subtitle>The Notebook of a Programmer Climber Musician Ex-Soldier Woodworker and a few other things</subtitle>
      <title>Adam Young's Web Log</title>
      <updated>2026-06-22T16:58:17Z</updated>
    </source>
  </entry>

  <entry xml:lang="fr-FR">
    <id>https://blog.kulakowski.fr/?p=37801</id>
    <link href="https://blog.kulakowski.fr/post/deux-nouvelles-versions-majeures-pour-seedboxsync-et-seedboxsyncfrontend" rel="alternate" type="text/html"/>
    <title>Deux nouvelles versions majeures pour SeedboxSync et SeedboxSyncFrontend</title>
    <summary>Ce week-end marque la sortie de deux versions majeures de mes projets SeedboxSync et SeedboxSyncFrontend. Au programme : support FTP, optimisations de performances, suivi en temps réel des téléchargements, administration depuis l'interface web et plusieurs améliorations de l'expérience utilisateur.</summary>
    <updated>2026-06-15T18:55:11Z</updated>
    <published>2026-06-15T18:55:11Z</published>
    <category term="Python"/>
    <category term="FTP"/>
    <category term="SeedboxSync"/>
    <author>
      <name>Guillaume Kulakowski</name>
    </author>
    <source>
      <id>https://blog.kulakowski.fr</id>
      <logo>https://blog.kulakowski.fr/wp-content/uploads/2026/04/cropped-logo-32x32.png</logo>
      <link href="https://blog.kulakowski.fr/feed" rel="self" type="application/rss+xml"/>
      <link href="https://blog.kulakowski.fr" rel="alternate" type="text/html"/>
      <subtitle>Le journal d’un Directeur Conseil Expert en solutions digitales – API Management, DevOps &amp; Open Source.</subtitle>
      <title>Le journal de Guillaume Kulakowski</title>
      <updated>2026-06-26T12:37:25Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/</id>
    <link href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/" rel="alternate" type="text/html"/>
    <title>Small TLS settings modernization</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Some time has passed since <a class="reference external" href="https://enotty.pipebreaker.pl/posts/2017/01/zaciskanie-pasa-tlsa/">I've tightened TLS settings</a>
on my home server. Let's move it a notch higher, this time including home k3s cluster.</p>
<section id="use-ecc-certificates">
<h2>Use ECC certificates</h2>
<p>In 2026, using elliptic curves cryptography certificates should be the norm. Fortunately,
automatically obtaining them is easy. I'm using <cite>cert-manager</cite> for kubernetes ingresses.
Switching to ECC is a just a matter of adding an algorithm annotation on <cite>Ingress</cite>:</p>
<div class="code"><pre class="code yaml"><a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_a7777d8a7cd446149bdd70137debe350-1" id="rest_code_a7777d8a7cd446149bdd70137debe350-1" name="rest_code_a7777d8a7cd446149bdd70137debe350-1"/><span class="nt">annotations</span><span class="p">:</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_a7777d8a7cd446149bdd70137debe350-2" id="rest_code_a7777d8a7cd446149bdd70137debe350-2" name="rest_code_a7777d8a7cd446149bdd70137debe350-2"/><span class="w">  </span><span class="nt">cert-manager.io/cluster-issuer</span><span class="p">:</span><span class="w"> </span><span class="s">"zerossl-production"</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_a7777d8a7cd446149bdd70137debe350-3" id="rest_code_a7777d8a7cd446149bdd70137debe350-3" name="rest_code_a7777d8a7cd446149bdd70137debe350-3"/><span class="w">  </span><span class="nt">cert-manager.io/private-key-algorithm</span><span class="p">:</span><span class="w"> </span><span class="s">"ECDSA"</span>
</pre></div>
<p>and removing the secret containing old cert and key.</p>
<p>Small caveat: FreeIPA still lags. While it <a class="reference external" href="https://enotty.pipebreaker.pl/posts/2021/11/acme-freeipa-super-easy/">supports ACME protocol</a>,
ECC through it is not possible, yet. I've left my internal domains with RSA certificates.</p>
<p>For the main server, I refresh certificates using small Ruby script. I had the change <cite>RSA.new(3072)</cite> to
an EC key generation, rest happened automatically:</p>
<div class="code"><pre class="code ruby"><a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_26144e77dd3a48a19c2a39e8af192a72-1" id="rest_code_26144e77dd3a48a19c2a39e8af192a72-1" name="rest_code_26144e77dd3a48a19c2a39e8af192a72-1"/><span class="n">certificate_private_key</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">OpenSSL</span><span class="o">::</span><span class="no">PKey</span><span class="o">::</span><span class="no">EC</span><span class="o">.</span><span class="n">generate</span><span class="p">(</span><span class="s1">'prime256v1'</span><span class="p">)</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_26144e77dd3a48a19c2a39e8af192a72-2" id="rest_code_26144e77dd3a48a19c2a39e8af192a72-2" name="rest_code_26144e77dd3a48a19c2a39e8af192a72-2"/><span class="n">csr</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">Acme</span><span class="o">::</span><span class="no">Client</span><span class="o">::</span><span class="no">CertificateRequest</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="ss">private_key</span><span class="p">:</span><span class="w"> </span><span class="n">certificate_private_key</span><span class="p">,</span><span class="w"> </span><span class="ss">names</span><span class="p">:</span><span class="w"> </span><span class="no">PIPEBREAKER_DOMAINS</span><span class="p">)</span>
</pre></div>
</section>
<section id="use-tlsv1-3-only">
<h2>Use TLSv1.3 only</h2>
<p>Last time I've limited support of Transport Layer Security to versions 1.2 and 1.3. Today, let's allow the latest only.
I don't care about supporting Windows 7-era clients (years out of support).</p>
<p>Ingress on k3s is handled by Traefik. Simplest way to influence its config is by creating a global (named <code class="docutils literal">default</code>) TLS
configuration option:</p>
<div class="code"><pre class="code yaml"><a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_d120c276ed5841748cce7e4892c7ba48-1" id="rest_code_d120c276ed5841748cce7e4892c7ba48-1" name="rest_code_d120c276ed5841748cce7e4892c7ba48-1"/><span class="nt">apiVersion</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">traefik.io/v1alpha1</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_d120c276ed5841748cce7e4892c7ba48-2" id="rest_code_d120c276ed5841748cce7e4892c7ba48-2" name="rest_code_d120c276ed5841748cce7e4892c7ba48-2"/><span class="nt">kind</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">TLSOption</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_d120c276ed5841748cce7e4892c7ba48-3" id="rest_code_d120c276ed5841748cce7e4892c7ba48-3" name="rest_code_d120c276ed5841748cce7e4892c7ba48-3"/><span class="nt">metadata</span><span class="p">:</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_d120c276ed5841748cce7e4892c7ba48-4" id="rest_code_d120c276ed5841748cce7e4892c7ba48-4" name="rest_code_d120c276ed5841748cce7e4892c7ba48-4"/><span class="w">  </span><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">default</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_d120c276ed5841748cce7e4892c7ba48-5" id="rest_code_d120c276ed5841748cce7e4892c7ba48-5" name="rest_code_d120c276ed5841748cce7e4892c7ba48-5"/><span class="w">  </span><span class="nt">namespace</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">kube-system</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_d120c276ed5841748cce7e4892c7ba48-6" id="rest_code_d120c276ed5841748cce7e4892c7ba48-6" name="rest_code_d120c276ed5841748cce7e4892c7ba48-6"/><span class="nt">spec</span><span class="p">:</span>
<a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_d120c276ed5841748cce7e4892c7ba48-7" id="rest_code_d120c276ed5841748cce7e4892c7ba48-7" name="rest_code_d120c276ed5841748cce7e4892c7ba48-7"/><span class="w">  </span><span class="nt">minVersion</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">VersionTLS13</span>
</pre></div>
<p>That's all!</p>
<p>Change to <code class="docutils literal">nginx</code> configuration on the main server is minimal, too. Version 1.2 is removed from the list, leaving only 1.3:</p>
<div class="code"><pre class="code shell"><a href="https://enotty.pipebreaker.pl/posts/2026/06/small-tls-settings-modernization/#rest_code_d054908d179f4817b4524927bc6116c5-1" id="rest_code_d054908d179f4817b4524927bc6116c5-1" name="rest_code_d054908d179f4817b4524927bc6116c5-1"/>ssl_protocols<span class="w"> </span>TLSv1.3<span class="p">;</span>
</pre></div>
<p>I have to tune Postfix and few other services TLS settings later.</p>
<blockquote>
<p>065/100 of <a class="reference external" href="https://100daystooffload.com/">#100DaysToOffload</a></p>
</blockquote>
</section></div>
    </summary>
    <updated>2026-06-10T11:48:25Z</updated>
    <published>2026-06-10T11:48:25Z</published>
    <category term="100DaysToOffload"/>
    <category term="english"/>
    <author>
      <name>Tomasz Torcz</name>
    </author>
    <source>
      <id>https://enotty.pipebreaker.pl/</id>
      <link href="https://enotty.pipebreaker.pl/" rel="alternate" type="text/html"/>
      <link href="https://enotty.pipebreaker.pl/categories/english.xml" rel="self" type="application/rss+xml"/>
      <title>-ENOTTY (Posts about english)</title>
      <updated>2026-07-09T16:02:05Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://blogs.gnome.org/mcatanzaro/?p=11205</id>
    <link href="https://blogs.gnome.org/mcatanzaro/2026/06/08/please-do-not-ban-ai-assisted-issue-reports/" rel="alternate" type="text/html"/>
    <title>Please Do Not Ban AI-Assisted Issue Reports</title>
    <summary>Many GNOME projects have adopted a policy banning all contributions generated by LLMs. This policy was originally developed by Sophie for Loupe, but is now used in many other notable places: This project does not allow contributions generated by large languages models (LLMs) and chatbots. This ban includes, but is not limited to, tools like […]</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">Many GNOME projects have adopted a <a class="external" href="https://gitlab.gnome.org/GNOME/loupe/-/blob/1c3300d340d26ebea47f4b79cad91808c4f76b7b/CONTRIBUTING.md#use-of-generative-ai">policy banning all contributions generated by LLMs</a>. This policy was originally developed by Sophie for Loupe, but is now used in many other notable places:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">This project does not allow contributions generated by large languages models (LLMs) and chatbots. This ban includes, but is not limited to, tools like ChatGPT, Claude, Copilot, DeepSeek, and Devin AI. We are taking these steps as precaution due to the potential negative influence of AI generated content on quality, as well as likely copyright violations.</p>



<p class="wp-block-paragraph">This ban of AI generated content applies to all parts of the projects, including, but not limited to, code, documentation, issues, and artworks. An exception applies for purely translating texts for issues and comments to English.</p>



<p class="wp-block-paragraph">AI tools can be used to answer questions and find information. However, we encourage contributors to avoid them in favor of using <a class="external" href="https://developer.gnome.org/" rel="noreferrer noopener" target="_blank">existing documentation</a> and our <a class="external" href="https://welcome.gnome.org/" rel="noreferrer noopener" target="_blank">chats and forums</a>. Since AI generated information is frequently misleading or false, we cannot supply support on anything referencing AI output.</p>
</blockquote>



<p class="wp-block-paragraph">I won’t attempt to argue that you should allow use of AI for writing code. If you wish to ban LLM-generated code, fine. That’s probably inadvisable, but I am not going to object.</p>



<p class="wp-block-paragraph">But this policy is far stricter than that. Notably, it strictly prohibits AI-generated content in issue reports (except to translate text). Don’t do this! Prohibiting bug reports is stupid and just makes your software worse. Please make sure your project’s AI policy allows for at least AI-generated static analysis results and AI-generated vulnerability reports. Otherwise, you prohibit entirely unobjectionable problem reports.</p>



<p class="wp-block-paragraph">It’s hard to imagine what could possibly be the value of prohibiting valid bug reports. AI-generated static analysis works well: the AI is able to think about your code, follow execution paths, and automatically discard most false positives to avoid bothering you with them, and the quality of reports is generally pretty high. They are far from perfect, but the same is true of humans.</p>



<p class="wp-block-paragraph"><a class="external" href="https://gitlab.gnome.org/GNOME/glib-networking/-/merge_requests/280#note_2777199">Here is a typical example</a> of an AI-generated static analysis finding:</p>



<pre class="wp-block-preformatted">2. Resource leak in update_credentials_cb on gnutls_credentials_set failure<br/><br/>  File: tls/gnutls/gtlsconnection-gnutls.c:169-172<br/><br/>  When gnutls_credentials_set() fails, the function returns without calling g_gnutls_certificate_credentials_unref(credentials). The credentials was either freshly allocated or ref-bumped, so it leaks.</pre>



<p class="wp-block-paragraph">Pasting this into an issue report clearly violates the ban on AI-generated content. And yet, why would you <em>not</em> want to receive a clear and concrete bug report for memory leak?</p>



<p class="wp-block-paragraph">I understand not all maintainers are fond of AI, but is your dislike really so extreme that you would choose to ignore valid problems and intentionally make your software worse? If not, then your AI policy should thoughtfully consider how to handle AI-generated content in issue reports. Certainly do not adopt a policy that outright bans all AI-generated content in issue reports.</p>



<p class="wp-block-paragraph">As an issue reporter, you could theoretically take the problem found by the AI and rephrase all the words, then claim that it is no longer AI-generated content because it is rewritten. This is a waste of time and usually results in a lower-quality, less-detailed result, but you could plausibly do that. Or, if you want to go above and beyond, you could just jump ahead to creating a merge request. But realistically, if your project does not allow any use of AI in issue reports, it’s more likely that either (a) you won’t receive the issue report in the first place, or (b) you won’t receive such issue reports from experienced developers who read and respect your policy, while users who do not read your policy will continue to submit them.</p>



<p class="wp-block-paragraph">What about security vulnerability reports? Since the start of this year, I have reviewed well over 100 vulnerability reports that I strongly suspect were generated by AI. To reach the “over 100” claim, I sadly only considered vulnerability reports submitted during a particularly heavy four week period, so this is an extremely loose lower bound. Suffice to say, I have seen a lot of them. The quality varies dramatically. Vulnerability reports are now often better or worse than before: better because <a href="https://blogs.gnome.org/mcatanzaro/2026/05/21/single-click-code-execution-exploit-for-evince-atril-and-xreader/">an experienced human working with a good AI is able to find vulnerabilities that would have surely gone unnoticed without A</a>I, and worse because an inexperienced human with a bad AI might create some pretty terrible issue reports, a significant proportion of which are just outright spam. Low-quality reports remain a problem, but nowadays most AI-generated issue reports are quite good.</p>



<p class="wp-block-paragraph">Maintainers do not need to tolerate spammy vulnerability reports. If an issue report is bad, of course go ahead and close it.   If it’s <em>really</em> bad, then I sometimes don’t even bother replying. But banning good vulnerability reports solely because some portion of the report was generated by AI is unacceptable. AI-assisted vulnerability reports are the new industry standard, and this is not likely to change. Prohibiting issue reports reduces the quality and safety of your software, punishing your users. This is too extreme.</p></div>
    </content>
    <updated>2026-06-08T21:30:42Z</updated>
    <published>2026-06-08T21:30:42Z</published>
    <category term="Fedora"/>
    <category term="GNOME"/>
    <category term="Security"/>
    <author>
      <name>Michael Catanzaro</name>
    </author>
    <source>
      <id>https://blogs.gnome.org/mcatanzaro</id>
      <link href="https://blogs.gnome.org/mcatanzaro/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://blogs.gnome.org/mcatanzaro" rel="alternate" type="text/html"/>
      <subtitle>On Fedora Workstation, GNOME, Epiphany, and WebKitGTK</subtitle>
      <title>Michael Catanzaro's Blog</title>
      <updated>2026-06-29T21:29:07Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>http://rajeeshknambiar.wordpress.com/?p=1885</id>
    <link href="https://rajeeshknambiar.wordpress.com/2026/06/08/rit-unny-open-source-font/" rel="alternate" type="text/html"/>
    <title>RIT Unny open source font</title>
    <summary>E.P. Unny is a notable Indian political cartoonist, who worked/works with famed Shankar’s Weekly and new papers such as The Hindu and Indian Express. Since 2020, all his cartoons (also 2025, 2026 so far) are published — every week — open-access by Sayahna Foundation. Unny was using a font based on his handwriting style for […]</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph"><a href="https://en.wikipedia.org/wiki/E._P._Unny" rel="noopener" target="_blank">E.P. Unny</a> is a notable Indian political cartoonist, who worked/works with famed Shankar’s Weekly and new papers such as The Hindu and Indian Express.</p>



<p class="wp-block-paragraph">Since 2020, all his <a href="https://en.books.sayahna.org/html/en-unny-cartoons-toc.html" rel="noopener" target="_blank">cartoons</a> (also <a href="https://forum.sayahna.org/discussion/comment/1071" rel="noopener" target="_blank">2025,</a> <a href="https://forum.sayahna.org/discussion/1745/unny-indian-express-2026" rel="noopener" target="_blank">2026</a> so far) are published — every week — open-access by <a href="https://books.sayahna.org" rel="noopener" target="_blank">Sayahna Foundation</a>.</p>



<p class="wp-block-paragraph">Unny was using a font based on his handwriting style for the cartoons, designed by K.H. Hussain of Rachana. Recently, a new font designed by Varshini KVSS &amp; ‘Kandam Collective’ is developed by <a href="https://rachana.org.in" rel="noopener" target="_blank">Rachana Institute of Typography</a> to use in the cartoons, and it is released as open source  — see the <a href="https://rachana.org.in/main.html#Unny" rel="noopener" target="_blank">specimen</a> and download links.</p>



<figure class="wp-block-image size-large is-resized"><img alt="" src="https://rachana.org.in/images/unny.svg" style="width: 628px; height: auto;"/></figure>



<p class="wp-block-paragraph">The character set of the font is Latin only. There are plenty of alternate glyphs (for upper case and lower cases of i, j, l, g, etc. — for instance check the double ‘l’ in ‘Intelligence’ on the specimen above). Such characters are rendered alternately to give a feel of the randomness that handwriting evokes.</p>



<p class="wp-block-paragraph">The source (and issue tracking) are available at RIT fonts <a href="https://gitlab.com/rit-fonts/RIT-Unny/" rel="noopener" target="_blank">repository</a>.</p></div>
    </content>
    <updated>2026-06-08T11:14:05Z</updated>
    <published>2026-06-08T11:14:05Z</published>
    <category term="fonts"/>
    <author>
      <name>Rajeesh</name>
    </author>
    <source>
      <id>https://rajeeshknambiar.wordpress.com</id>
      <logo>https://s0.wp.com/i/webclip.png</logo>
      <link href="https://rajeeshknambiar.wordpress.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://rajeeshknambiar.wordpress.com" rel="alternate" type="text/html"/>
      <link href="https://rajeeshknambiar.wordpress.com/osd.xml" rel="search" title="Soliloquies" type="application/opensearchdescription+xml"/>
      <link href="https://rajeeshknambiar.wordpress.com/?pushpress=hub" rel="hub" type="text/html"/>
      <subtitle>on freedom. of geek.</subtitle>
      <title>Soliloquies</title>
      <updated>2026-06-08T11:14:05Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://ausil.us/wordpress/?p=359</id>
    <link href="https://ausil.us/wordpress/accessing-serial-consoles-on-sbcs/" rel="alternate" type="text/html"/>
    <title>Accessing serial consoles on SBC’s</title>
    <summary>I have a bunch of different ARM SBCs, some Raspberry Pis, some Rockchip based, and some others. Some of them I have in 1U rack mount cases. Some in cases that I have 3d printed. They have all had a common issue. When something goes wrong, I need to unplug them, move them to my […]</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">I have a bunch of different ARM SBCs, some Raspberry Pis, some Rockchip based, and some others. Some of them I have in 1U rack mount cases. Some in cases that I have 3d printed. They have all had a common issue. When something goes wrong, I need to unplug them, move them to my desk, and connect them to my desktop via a USB to tty adaptor. Aside from being inconvenient, it also meant I had to be home to debug what was happening. </p>



<p class="wp-block-paragraph">I figured there had to be a better way. In the end, I used Claude to help me write a solution. What I came up with is a project to make an <a href="https://github.com/ausil/esp32-web-terminal">ESP32 Web Terminal</a>. Using an ESP32 wired to the UART on the SBCs, I can securely access the serial console of my devices. I have used a couple of different ESP32 devices, from a USD$3 ESP32 C3 Mini to a USD$8 XIAO ESP32S3. all of which work well. For the Raspberry Pis, I purchased some premade JST SH1.0 mm 3 Pin Wire connector cables to plug into the uart port, and for other devices, I made some custom cables with 2.54 mm Dupont crimp pin connectors. </p>



<figure class="wp-block-image size-full"><a href="https://ausil.us/wordpress/wp-content/uploads/2026/06/Rpi_ESP32-Uart.png"><img alt="" class="wp-image-361" height="689" src="https://ausil.us/wordpress/wp-content/uploads/2026/06/Rpi_ESP32-Uart.png" width="1024"/></a></figure>



<p class="wp-block-paragraph">I have most of my SBC’s powered by PoE. In the pictured example, I soldered some headers onto the PCB for the PoE hat to use to provide a 5V power source to the ESP32, and it all runs self-contained in the rack-mount unit. I do want to work on making the connections a little neater and the housing better. But for now, this is functional. While the software on the ESP allows resetting the SBC and controlling the power, I do not currently have that wired up.</p>



<p class="wp-block-paragraph">As for provisioning the ESPs, I run FreeIPA at home for authentication, and I have dogtag set up as a CA.  When I have wired up and flashed a new board, it initially runs as an access point I connect to in order to set up my home network. Once it is connected to my network, I run an Ansible playbook to create and upload SSL certificates signed by my CA and change the admin password. That way, I can connect without any SSL warnings and use a known non-default password to log in.  So far, I am quite happy with how they have performed. I still have some things I want to make better, and I also want to finish testing a setup where I connect to an SBC that exposes its serial port over USB. In theory, it should work with ESP32S3, I just need to test.</p>



<p class="wp-block-paragraph">While it has added quite a few more devices to my network, it is useful to be able to access and debug what is happening without having to move devices and plug them into another computer.  I have considered options for externally powering the ESPs and the best ways to connect the ESPs to the SBCs. I would like to at least be more robust with a 3d printed enclosure for the ESP. Each unit has cost me between USD$5 and USD$12, and each has acceptable performance. I have intentionally stuck to using small ESP’s, though it would work well with bigger devices also. Powering each through a shared power source would require additional circuitry to isolate them and prevent voltage leaks.</p></div>
    </content>
    <updated>2026-06-07T20:42:39Z</updated>
    <published>2026-06-07T20:42:39Z</published>
    <category term="AArch64"/>
    <category term="ARM"/>
    <category term="Uncategorized"/>
    <category term="3D"/>
    <category term="Arm64"/>
    <category term="ESP32"/>
    <author>
      <name>dgilmore</name>
    </author>
    <source>
      <id>https://ausil.us/wordpress</id>
      <link href="https://ausil.us/wordpress/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://ausil.us/wordpress" rel="alternate" type="text/html"/>
      <title>Dennis Gilmore</title>
      <updated>2026-06-24T05:56:08Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://www.scrye.com/blogs/nirik/posts/2026/06/06/misc-fedora-bits-first-week-of-june-2026/</id>
    <link href="https://www.scrye.com/blogs/nirik/posts/2026/06/06/misc-fedora-bits-first-week-of-june-2026/" rel="alternate" type="text/html"/>
    <title xml:lang="en">misc fedora bits first week of june 2026</title>
    <summary type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>Another busy week for me. Lots of little things all over the place.</p>
<section id="mass-update-reboots">
<h2>mass update/reboots</h2>
<p>We got everything updated and rebooted and cleaned up any messes from
that (at least as far as I know). We did firmware updates on servers this
time, and those always cause things to take much longer. Instead of a
'quick' 5m reboot of a server, it's more 20-25m to apply all the firmware
updates and reboot a bunch of times. Ah well, it's good to be up to date.</p>
<p>We did have one arm server fail to come up after reboot. ;(
It has a memory error, so we are having datacenter folks reseat all the
memory (this happened once before and that cleared it up).</p>
</section>
<section id="some-old-long-running-tickets">
<h2>Some old long running tickets</h2>
<p>I was able to try and move some old long running tickets over the finish line
this week:</p>
<ul class="simple">
<li><p>systemd-boot signing. This is all setup, but needs to be tweaked in the
package and tested. Note that this is a self signed cert, but it will
still hopefully help folks using systemd-boot.</p></li>
<li><p>Looked over a bunch of work from Stephen Gallagher to fix some dist-git
repos that have commits that break git fsck. I hope I can finish this
up early next week.</p></li>
</ul>
</section>
<section id="and-a-few-new-things">
<h2>And a few new things</h2>
<ul class="simple">
<li><p>Got the drm-panic 'application' deployed. (I just deployed, the change
owner did all the heavy lifting).</p></li>
<li><p>Setup a pagure-stg-ro01 machine to test a 'readonly' pagure instance.</p></li>
<li><p>Got koji upgraded to 1.36.0.</p></li>
<li><p>Got all koji builders, hubs and kojipkgs moved to fedora 44</p></li>
<li><p>Moved all our proxies to fedora 44</p></li>
<li><p>Moved all our compose hosts to fedora 44</p></li>
<li><p>Fixed some openshift apps that were still pulling from docker hub
(and getting rate limited). I even moved greenwave to using a
hummingbird memcached container. Works great!</p></li>
</ul>
</section>
<section id="flock">
<h2>flock</h2>
<p>Flock is coming up fast now. I will be traveling to it starting next
thursday. So expect me to be largely offline thursday and friday, and
then only sporadically online while I am at flock.</p>
<p>Really looking forward to meeting up with folks and getting that good
flock infusion of energy.</p>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116704516544974008">https://fosstodon.org/@nirik/116704516544974008</a></p>
</section></div>
    </summary>
    <content type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>Another busy week for me. Lots of little things all over the place.</p>
<section id="mass-update-reboots">
<h2>mass update/reboots</h2>
<p>We got everything updated and rebooted and cleaned up any messes from
that (at least as far as I know). We did firmware updates on servers this
time, and those always cause things to take much longer. Instead of a
'quick' 5m reboot of a server, it's more 20-25m to apply all the firmware
updates and reboot a bunch of times. Ah well, it's good to be up to date.</p>
<p>We did have one arm server fail to come up after reboot. ;(
It has a memory error, so we are having datacenter folks reseat all the
memory (this happened once before and that cleared it up).</p>
</section>
<section id="some-old-long-running-tickets">
<h2>Some old long running tickets</h2>
<p>I was able to try and move some old long running tickets over the finish line
this week:</p>
<ul class="simple">
<li><p>systemd-boot signing. This is all setup, but needs to be tweaked in the
package and tested. Note that this is a self signed cert, but it will
still hopefully help folks using systemd-boot.</p></li>
<li><p>Looked over a bunch of work from Stephen Gallagher to fix some dist-git
repos that have commits that break git fsck. I hope I can finish this
up early next week.</p></li>
</ul>
</section>
<section id="and-a-few-new-things">
<h2>And a few new things</h2>
<ul class="simple">
<li><p>Got the drm-panic 'application' deployed. (I just deployed, the change
owner did all the heavy lifting).</p></li>
<li><p>Setup a pagure-stg-ro01 machine to test a 'readonly' pagure instance.</p></li>
<li><p>Got koji upgraded to 1.36.0.</p></li>
<li><p>Got all koji builders, hubs and kojipkgs moved to fedora 44</p></li>
<li><p>Moved all our proxies to fedora 44</p></li>
<li><p>Moved all our compose hosts to fedora 44</p></li>
<li><p>Fixed some openshift apps that were still pulling from docker hub
(and getting rate limited). I even moved greenwave to using a
hummingbird memcached container. Works great!</p></li>
</ul>
</section>
<section id="flock">
<h2>flock</h2>
<p>Flock is coming up fast now. I will be traveling to it starting next
thursday. So expect me to be largely offline thursday and friday, and
then only sporadically online while I am at flock.</p>
<p>Really looking forward to meeting up with folks and getting that good
flock infusion of energy.</p>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116704516544974008">https://fosstodon.org/@nirik/116704516544974008</a></p>
</section></div>
    </content>
    <updated>2026-06-06T17:56:41Z</updated>
    <published>2026-06-06T17:56:41Z</published>
    <category label="fedora" term="fedora"/>
    <category label="linux" term="linux"/>
    <author>
      <name>nirik</name>
    </author>
    <source>
      <id>https://www.scrye.com/blogs/nirik/categories/fedora.atom</id>
      <author>
        <name>nirik</name>
      </author>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora.atom" rel="self" type="application/atom+xml"/>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora/" rel="alternate" type="text/html"/>
      <title xml:lang="en">Kevin's musings (Posts about fedora)</title>
      <updated>2026-07-04T19:53:19Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>urn:md5:c3f2f8b9ca67ce6058dc57472c922153</id>
    <link href="https://blog.remirepo.net/post/2026/06/05/PHP-version-8.4.22-and-8.5.7" rel="alternate" type="text/html"/>
    <title>⚙️ PHP version 8.4.22 and 8.5.7</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>RPMs of <strong>PHP version 8.5.7</strong> are available in the <strong>remi-modular</strong> repository for <strong>Fedora</strong> â‰¥ 42 and <strong>Enterprise Linux</strong> â‰¥ 8 (RHEL, Alma, CentOS, Rocky...).</p>

<p>RPMs of <strong>PHP version 8.4.22</strong> are available in the <strong>remi-modular</strong> repository for <strong>Fedora</strong> â‰¥ 42 and <strong>Enterprise Linux</strong> â‰¥ 8 (RHEL, Alma, CentOS, Rocky...).</p>
<!--
<p>RPMs of <strong>PHP version 8.3.30</strong>&nbsp;are available in the <strong>remi-modular</strong> repository for&nbsp;<strong>Fedora</strong> â‰¥ 42 and <strong>Enterprise Linux</strong> â‰¥ 8 (RHEL, Alma, CentOS, Rocky...).</p>

<p>RPMs of <strong>PHP version 8.2.30</strong> are available in the <strong>remi-modular</strong> repository for&nbsp;<strong>Fedora</strong> â‰¥ 42 and <strong>Enterprise Linux</strong> â‰¥ 8 (RHEL, Alma, CentOS, Rocky...).</p>
-->

<p>â„¹ï¸� These versions are also available as <em>Software Collections</em> in the <strong>remi-safe</strong> repository.</p>
<!--
-->

<p>â„¹ï¸� The packages are available for <strong>x86_64</strong> and <strong>aarch64</strong>.</p>

<p>â„¹ï¸� There is no security fix this month, so no update for <a class="ref-post" href="https://blog.remirepo.net/post/2026/05/08/PHP-version-8.2.31-8.3.31-8.4.21-8.5.6">versions 8.2.31 and 8.3.31</a>.</p>
<!--
<p>âš ï¸� <a class="ref-post" href="https://blog.remirepo.net/post/2023/11/27/PHP-8.0-is-retired">PHP version 8.0</a> has reached its end of life and is no longer maintained by the <a href="https://php.net/supported-versions.php">PHP project</a>.</p>
--><!--
<p>ğŸ›¡ï¸� These Versions fix 4 security bugs (<strong>CVE-2025-14177</strong>, <strong>CVE-2025-14178</strong>, <strong>CVE-2025-14180</strong>), so the update is strongly recommended.</p>
--> <p>Version announcements:</p>

<ul>
	<li><a href="https://www.php.net/releases/8_5_7.php">PHP 8.5.7 Release Annoucement</a></li>
	<li><a href="https://www.php.net/releases/8_4_22.php">PHP 8.4.22 Release Annoucement</a></li>
	<!--
	<li><a href="https://www.php.net/releases/8_3_30.php">PHP 8.3.30 Release Annoucement</a></li>
	<li><a href="https://www.php.net/releases/8_2_30.php">PHP 8.2.30 Release Annoucement</a></li>
	<li>PHP 8.1.34 is not yet officially announced</li>
-->
</ul>

<p>â„¹ï¸� Installation: Use the <a href="https://rpms.remirepo.net/wizard/">Configuration Wizard</a> and choose your version and installation mode.</p>

<p><strong>Replacement</strong> of default PHP by version <strong>8.5</strong> installation (<strong>simplest</strong>):</p>

<p>On Enterprise Linux (dnf 4)</p>

<pre>dnf module switch-to php:remi-8.5/common
</pre>

<p>On Fedora (dnf 5)</p>

<pre>dnf module reset php
dnf module enable php:remi-8.5
dnf update
</pre>

<p><strong>Parallel installation</strong> of version <strong>8.5</strong> as <a class="ref-post" href="https://blog.remirepo.net/post/2025/07/04/PHP-8.5-as-Software-Collection">Software Collection</a></p>

<pre>yum install php85</pre>

<p><strong>Replacement</strong> of default PHP by version <strong>8.4</strong> installation (<strong>simplest</strong>):</p>

<p>On Enterprise Linux (dnf 4)</p>

<pre>dnf module switch-to php:remi-8.4/common
</pre>

<p>On Fedora (dnf 5)</p>

<pre>dnf module reset php
dnf module enable php:remi-8.4
dnf update
</pre>

<p><strong>Parallel installation</strong> of version <strong>8.4</strong> as <a class="ref-post" href="https://blog.remirepo.net/post/2023/06/06/PHP-8.3-as-Software-Collection">Software Collection</a></p>

<pre>yum install php84</pre>

<p>And soon in the official updates:</p>

<ul>
	<li>Fedora <strong>Rawhide</strong> now has PHP version <strong>8.5.7</strong></li>
	<li><a href="https://bodhi.fedoraproject.org/updates/FEDORA-2026-2d02da5c35">Fedora 44 - PHP 8.5.7</a></li>
	<li><a href="https://bodhi.fedoraproject.org/updates/FEDORA-2026-adc9f80c23">Fedora 43 - PHP 8.4.22</a></li>
</ul>

<p>âš ï¸� <strong>To be noticed : </strong></p>

<ul>
	<li>EL-10 RPMs are built using RHEL-<strong>10.2</strong></li>
	<li>EL-9 RPMs are built using RHEL-<strong>9.8</strong></li>
	<li>EL-8 RPMs are built using RHEL-<strong>8.10</strong></li>
	<li><strong>intl</strong> extension now uses <strong>libicu74 </strong>(version<strong> 74.2</strong>)</li>
	<li><strong>mbstring</strong> extension (EL builds) now uses <strong>oniguruma5php</strong> (version <strong>6.9.10</strong>, instead of the outdated system library)</li>
	<li><strong>oci8</strong> extension now uses the <strong>RPM</strong> of <strong>Oracle Instant Client </strong>version<strong> 23.26 </strong>on x86_64 and aarch64</li>
	<li>A lot of extensions are also available; see the <a href="https://blog.remirepo.net/pages/PECL-extensions-RPM-status">PHP extensions RPM status (from PECL and other sources)</a> page</li>
</ul>

<p>â„¹ï¸� <strong>Information</strong>:</p>

<ul>
	<li><a href="https://php.net/manual/en/migration83.php" hreflang="en">Migrating from PHP 8.2.x to PHP 8.3.x</a></li>
	<li><a href="https://php.net/manual/en/migration84.php" hreflang="en">Migrating from PHP 8.3.x to PHP 8.4.x</a></li>
	<li><a href="https://php.net/manual/en/migration85.php" hreflang="en">Migrating from PHP 8.4.x to PHP 8.5.x</a></li>
</ul>

<p align="center"><strong>Base</strong> packages (php)</p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.5.7&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.4.22&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>
<!--
<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.3.30&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;" /></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php-common&amp;version=8.2.30&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;" /></p>
-->

<p align="center"><strong>Software Collections</strong> (php83 / php84 / php85)</p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php85-php-common&amp;version=8.5.7&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php84-php-common&amp;version=8.4.22&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;"/></p>
<!--
<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php83-php-common&amp;version=8.3.30&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;" /></p>

<p><img alt="" src="https://blog.remirepo.net/downcpt.php?name=php82-php-common&amp;version=8.2.30&amp;lang=en&amp;release=1" style="margin: 1em auto; display: block;" /></p>
-->

<p>Â </p></div>
    </summary>
    <updated>2026-06-05T04:40:00Z</updated>
    <published>2026-06-05T04:40:00Z</published>
    <category term="Archives"/>
    <category term="PHP"/>
    <category term="RPM"/>
    <author>
      <name>Remi</name>
    </author>
    <source>
      <id>https://blog.remirepo.net/en</id>
      <link href="https://blog.remirepo.net/en" rel="alternate" type="text/html"/>
      <link href="https://blog.remirepo.net/feed/en/rss2" rel="self" type="application/rss+xml"/>
      <rights>Licence: Creative Commons Attribution-ShareAlike 4.0 International License.</rights>
      <subtitle>Remi's RPM repository blog Information about RPM PHP Fedora RHEL and CentOS</subtitle>
      <title>Remi's RPM repository - Blog</title>
      <updated>2026-07-10T04:19:09Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-us">
    <id>https://michel-slm.name/posts/2026-06-05-wlb-with-sandogasa-hattrack/</id>
    <link href="https://michel-slm.name/posts/2026-06-05-wlb-with-sandogasa-hattrack/" rel="alternate" type="text/html"/>
    <title>Work-Life Balance 🏖️ with Sandogasa 👒 Hat-Track</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><blockquote>
<p><strong>Caveat lector</strong></p>
<p>This post discusses tools reluctantly written with AI assistance. If you don’t entertain
using them under any circumstance, and think even reading about them legally compromise
your ability to reimplement them yourselves, stop reading now</p>
</blockquote>
<p>Happy Friday! Of course it’s not Friday anymore in Asia, and if I finish this post in time, it’s still the work day in the Western Hemisphere.</p>
<p>When you work in a large distributed project, it’s not dissimilar to working in a large multinational company - there are too many people to know everyone (or at least not at once!) and you might not know where someone is and if you’re pinging them in the middle of the night.</p></div>
    </summary>
    <updated>2026-06-05T00:00:00Z</updated>
    <published>2026-06-05T00:00:00Z</published>
    <source>
      <id>https://michel-slm.name/tags/foss/</id>
      <author>
        <name>Michel Alexandre Salim</name>
      </author>
      <link href="https://michel-slm.name/tags/foss/" rel="alternate" type="text/html"/>
      <link href="https://michel-slm.name/tags/foss/index.xml" rel="self" type="application/rss+xml"/>
      <rights type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><a href="https://creativecommons.org/licenses/by/4.0/" rel="noopener" target="_blank">CC BY 4.0</a></div>
      </rights>
      <subtitle>Recent content in Foss on PensÃ©es de Michel</subtitle>
      <title>Foss on Pensées de Michel</title>
      <updated>2026-06-23T00:00:00Z</updated>
    </source>
  </entry>

  <entry>
    <id>tag:None,2026-06-05:/blog/kiwi-tcms-team/2026/06/05/kiwi-tcms-160/</id>
    <link href="https://kiwitcms.org/blog/kiwi-tcms-team/2026/06/05/kiwi-tcms-160/" rel="alternate" type="text/html"/>
    <title>Kiwi TCMS 16.0</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Dear testers, we're happy to announce Kiwi TCMS version 16.0!</p>
<p><strong>IMPORTANT:</strong></p>
<p>This is a major version release which includes security related updates
several improvements, backwards incompatible changes and new translations.</p>
<p>You can explore everything at
<a class="reference external" href="https://public.tenant.kiwitcms.org/">https://public.tenant.kiwitcms.org</a>!</p>
<p>---</p>
<blockquote>
<p>Public container image (x86_64):</p>
<pre class="literal-block">pub.kiwitcms.eu/kiwitcms/kiwi â€¦</pre></blockquote></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Dear testers, we're happy to announce Kiwi TCMS version 16.0!</p>
<p><strong>IMPORTANT:</strong></p>
<p>This is a major version release which includes security related updates
several improvements, backwards incompatible changes and new translations.</p>
<p>You can explore everything at
<a class="reference external" href="https://public.tenant.kiwitcms.org/">https://public.tenant.kiwitcms.org</a>!</p>
<p>---</p>
<blockquote>
<p>Public container image (x86_64):</p>
<pre class="literal-block">pub.kiwitcms.eu/kiwitcms/kiwi   latest  3b2c789666ec   867MB
</pre>
</blockquote>
<p><strong>IMPORTANT:</strong> version tagged and multi-arch
<a class="reference external" href="https://kiwitcms.org/containers/">container images</a> are available only to
<a class="reference external" href="https://kiwitcms.org/#subscriptions">subscribers</a>!</p>
<div class="section" id="changes-since-kiwi-tcms-15-4">
<h2>Changes since Kiwi TCMS 15.4</h2>
<div class="section" id="security">
<h3>Security</h3>
<ul class="simple">
<li>Update Django from 5.2.12 to 5.2.15</li>
<li>Upadate pillow from 11.3.0 to 12.1.1</li>
<li>Update node_modules/fast-uri from 3.1.0 to 3.1.2</li>
<li>Update node_modules/flatted from 3.3.3 to 3.4.2</li>
<li>Make /init-db/ page a no-op if already executed once. Fixes
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-v8rp-6xcv-fwgh">CVE-2026-49292</a></li>
</ul>
</div>
<div class="section" id="improvements">
<h3>Improvements</h3>
<ul class="simple">
<li>Update Python runtime from 3.11 to 3.12</li>
<li>Update Node.js runtime from 16 to 22</li>
<li>Update Nginx runtime from 1.22 to 1.26</li>
<li>Update django-grappelli from 4.0.3 to 5.0.0</li>
<li>Update django-guardian from 3.3.0 to 3.3.1</li>
<li>Update django-tree-queries from 0.23.1 to 0.24.0</li>
<li>Update psycopg from 3.3.3 to 3.3.4</li>
<li>Update pygithub from 2.8.1 to 2.9.1</li>
<li>Update pygments from 2.19.2 to 2.20.0</li>
<li>Update python-gitlab from 8.1.0 to 8.4.0</li>
<li>Update tzdata from 2025.3 to 2026.2</li>
<li>Update node_modules/pdfmake from 0.3.6 to 0.3.7</li>
<li>Update node_modules/webpack-cli from 7.0.1 to 7.0.2</li>
<li>Update node_modules/webpack from 5.105.4 to 5.106.0</li>
<li>Display <tt class="docutils literal">Last modified</tt> column in TestCase Search page. Closes
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/issues/4140">Issue #4140</a></li>
<li>Remove requirement for <tt class="docutils literal">setuptools&lt;82</tt>. Fixes
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/issues/4299">Issue #4299</a></li>
</ul>
</div>
<div class="section" id="removals">
<h3>Removals</h3>
<ul class="simple">
<li>Remove Bitbucket Issues integration because Atlassian has announced the
removal of this feature</li>
</ul>
</div>
<div class="section" id="release">
<h3>Release</h3>
<ul class="simple">
<li><tt class="docutils literal">pub.kiwitcms.eu/kiwitcms/kiwi</tt> container is now a rolling release</li>
<li>PyPI packages are uploaded to
<a class="reference external" href="https://kiwitcms.org/packages/">pkg.kiwitcms.eu</a>. Closes
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/issues/3376">Issue #3376</a></li>
</ul>
</div>
<div class="section" id="api">
<h3>API</h3>
<ul class="simple">
<li>API method <tt class="docutils literal">TestCase.filter()</tt> now returns the <tt class="docutils literal">history_date</tt> field</li>
</ul>
</div>
<div class="section" id="refactoring-and-testing">
<h3>Refactoring and testing</h3>
<ul class="simple">
<li>Update black from 25.12.0 to 26.5.1</li>
<li>Update locust from 2.43.3 to 2.44.1</li>
<li>Update codecov/codecov-action from 5 to 6</li>
<li>Merge Dockerfile.buildroot with Dockerfile. Closes
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/issues/3496">Issue #3496</a></li>
<li>Replace <tt class="docutils literal">pkg_resources</tt> discovery with <tt class="docutils literal">importlib.metadata</tt></li>
<li>GitLab Issues are now called Work Items</li>
</ul>
</div>
<div class="section" id="translations">
<h3>Translations</h3>
<ul class="simple">
<li>Updated <a class="reference external" href="https://crowdin.com/project/kiwitcms/zh-CN">Chinese Simplified translation</a></li>
<li>Updated <a class="reference external" href="https://crowdin.com/project/kiwitcms/ja">Japanese translation</a></li>
<li>Updated <a class="reference external" href="https://crowdin.com/project/kiwitcms/ko">Korean translation</a></li>
</ul>
</div>
</div>
<div class="section" id="changes-since-kiwi-tcms-enterprise-v15-3-mt">
<h2>Changes since Kiwi TCMS Enterprise v15.3-mt</h2>
<ul class="simple">
<li>Based on Kiwi TCMS v16.0</li>
<li>Update Python runtime from 3.11 to 3.12</li>
<li>Update certbot from 5.4.0 to 5.6.0</li>
<li>Update django-prometheus from 2.4.1 to 2.5.0</li>
<li>Update kiwitcms-github-app from 2.1.0 to 2.2.2</li>
<li>Update kiwitcms-tenants from 4.4.1 to 4.4.4</li>
<li>Update kiwitcms-trackers-integration from 1.2.1 to 1.3.1</li>
<li>Update psycopg-pool from 3.3.0 to 3.3.1</li>
<li>Update sentry-sdk from 2.54.0 to 2.61.1</li>
<li>Update social-auth-kerberos from 0.3.0 to 0.3.2</li>
<li>Update social-auth-app-django from 5.7.0 to 5.9.0</li>
<li>Remove OpenResty override</li>
<li>Remove requirement for setuptools&lt;82</li>
<li>Honor container ENV variable <cite>NGX_DENY_INCLUDE</cite></li>
<li>Don't use legacy syntax in Dockerfile</li>
<li>Provide sample SSL configuration for Postgres and
configure Kiwi TCMS to connect to it securely. Closes
<a class="reference external" href="https://github.com/kiwitcms/Kiwi/issues/2413">Issue #2413</a></li>
</ul>
</div>
<div class="section" id="private-container-images">
<h2>Private container images</h2>
<blockquote>
<pre class="literal-block">hub.kiwitcms.eu/kiwitcms/version          16.0 (aarch64)          d972a78b065c    04 Jun 2026     720MB
hub.kiwitcms.eu/kiwitcms/version          16.0 (x86_64)           876f5b848ee7    04 Jun 2026     701MB
hub.kiwitcms.eu/kiwitcms/enterprise       16.0-mt (aarch64)       25fc9c88a3b5    05 Jun 2026     925MB
hub.kiwitcms.eu/kiwitcms/enterprise       16.0-mt (x86_64)        3a7747c99b65    05 Jun 2026     904MB
</pre>
</blockquote>
<p><strong>IMPORTANT:</strong> version tagged, multi-arch and Enterprise
<a class="reference external" href="https://kiwitcms.org/containers/">container images</a> are available only to
<a class="reference external" href="https://kiwitcms.org/#subscriptions">subscribers</a>!</p>
</div>
<div class="section" id="how-to-upgrade">
<h2>How to upgrade</h2>
<p>Follow the
<a class="reference external" href="https://kiwitcms.readthedocs.io/en/latest/installing_docker.html#upgrading-instructions">Upgrading instructions</a>
from our documentation.</p>
<p>Happy testing!</p>
<p>---</p>
<p>If you like what we're doing and how Kiwi TCMS supports various communities
please help us grow!</p>
<ul class="simple">
<li><a class="reference external" href="https://github.com/kiwitcms/Kiwi/stargazers">Give â­� on GitHub</a>;</li>
<li><a class="reference external" href="https://kiwitcms.us17.list-manage.com/subscribe?u=9b57a21155a3b7c655ae8f922&amp;id=c970a37581">Join our newsletter</a>
and follow all news;</li>
<li><a class="reference external" href="https://kiwitcms.org/#subscriptions">Become a subscriber</a> and help us sustain development</li>
</ul>
</div></div>
    </content>
    <updated>2026-06-04T23:18:00Z</updated>
    <published>2026-06-04T23:18:00Z</published>
    <category term="misc"/>
    <category term="releases"/>
    <author>
      <name>Kiwi TCMS Team</name>
    </author>
    <source>
      <id>https://kiwitcms.org/</id>
      <link href="https://kiwitcms.org/" rel="alternate" type="text/html"/>
      <link href="https://kiwitcms.org/feeds/all.atom.xml" rel="self" type="application/atom+xml"/>
      <title>Kiwi TCMS</title>
      <updated>2026-06-24T10:18:00Z</updated>
    </source>
  </entry>

  <entry>
    <id>tag:blogger.com,1999:blog-4530460124602916146.post-7421283101935427946</id>
    <link href="https://airlied.blogspot.com/feeds/7421283101935427946/comments/default" rel="replies" title="Post Comments" type="application/atom+xml"/>
    <link href="https://airlied.blogspot.com/2026/06/appearing-on-software-engineering-radio.html#comment-form" rel="replies" title="0 Comments" type="text/html"/>
    <link href="https://www.blogger.com/feeds/4530460124602916146/posts/default/7421283101935427946" rel="edit" type="application/atom+xml"/>
    <link href="https://www.blogger.com/feeds/4530460124602916146/posts/default/7421283101935427946" rel="self" type="application/atom+xml"/>
    <link href="https://airlied.blogspot.com/2026/06/appearing-on-software-engineering-radio.html" rel="alternate" title="Appearing on the Software Engineering Radio Podcast" type="text/html"/>
    <title>Appearing on the Software Engineering Radio Podcast</title>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Software Engineering Radio is a podcast for people in IT/development with over 700 episodes across many topics over 20 years. They haven't touched on the Linux kernel much. I was invited on as part of my role at Red Hat as a Distinguished Engineer, but the podcast is really an insight into kernel maintenance, in graphics and beyond, touching on the scope and scale of the project.</p><p>It was my first time to record something that wasn't just me talking at a conference/meetup, and it was all very professional, with sound checks and brainstorming before hand. </p><p>The content is at a pretty broad and introductory level. We talked about kernel development processes, maintenance processes, and we touch on rust in the kernel a bit. It's mostly about the sheer size and scale of the project and how Linus releases things, how trees get to Linus and how the GPU work is done.</p><p> Hopefully you enjoy listening to it!</p><p>[1] <a href="https://se-radio.net/2026/06/se-radio-723-dave-airlie-on-linux-kernel-maintenance/">https://se-radio.net/2026/06/se-radio-723-dave-airlie-on-linux-kernel-maintenance/</a> </p></div>
    </content>
    <updated>2026-06-04T00:05:46Z</updated>
    <published>2026-06-04T00:05:46Z</published>
    <author>
      <name>Dave Airlie</name>
      <email>noreply@blogger.com</email>
      <uri>http://www.blogger.com/profile/03386351362681039664</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-4530460124602916146</id>
      <author>
        <name>Dave Airlie</name>
        <email>noreply@blogger.com</email>
        <uri>http://www.blogger.com/profile/03386351362681039664</uri>
      </author>
      <link href="https://airlied.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml"/>
      <link href="https://www.blogger.com/feeds/4530460124602916146/posts/default" rel="self" type="application/atom+xml"/>
      <link href="https://airlied.blogspot.com/" rel="alternate" type="text/html"/>
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html"/>
      <link href="https://www.blogger.com/feeds/4530460124602916146/posts/default?start-index=26&amp;max-results=25" rel="next" type="application/atom+xml"/>
      <title>Dave Airlie Linux Graphics blog</title>
      <updated>2026-07-08T10:10:10Z</updated>
    </source>
  </entry>

  <entry>
    <id>https://cockpit-project.org//blog/cockpit-363.html</id>
    <link href="https://cockpit-project.org//blog/cockpit-363.html" rel="alternate" type="text/html"/>
    <title>Cockpit 363</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Cockpit is the <a href="https://cockpit-project.org/">modern Linux admin interface</a>.
We release regularly.</p>

<p>Here are the release notes from cockpit-files 41:</p>

<h2 id="files-add-editor-shortcut-for-save">Files: Add editor shortcut for “Save”</h2>

<p>You can now type “Ctrl-S” to save a file in the editor.</p>

<p>Thanks a lot @Leone25 for this contribution!</p>

<h2 id="try-it-out">Try it out</h2>

<p>cockpit-files 41 are available now:</p>

<ul>
  <li><a href="https://cockpit-project.org/running.html">For your Linux system</a></li>
  <li>
    <p><a href="https://flathub.org/apps/details/org.cockpit_project.CockpitClient">Cockpit Client</a></p>
  </li>
  <li><a href="https://github.com/cockpit-project/cockpit-files/releases/tag/41">cockpit-files Source Tarball</a></li>
  <li><a href="https://bodhi.fedoraproject.org/updates/?releases=F44&amp;packages=cockpit-files">cockpit-files Fedora 44</a></li>
  <li><a href="https://bodhi.fedoraproject.org/updates/?releases=F43&amp;packages=cockpit-files">cockpit-files Fedora 43</a></li>
</ul></div>
    </summary>
    <updated>2026-06-04T00:00:00Z</updated>
    <published>2026-06-04T00:00:00Z</published>
    <category term="machines,"/>
    <category term="files"/>
    <category term="release"/>
    <source>
      <id>https://cockpit-project.org/</id>
      <author>
        <name>Cockpit Project</name>
      </author>
      <link href="https://cockpit-project.org/" rel="alternate" type="text/html"/>
      <link href="https://cockpit-project.org/blog/feeds/all.atom.xml" rel="self" type="application/rss+xml"/>
      <subtitle>Cockpit makes it easy to administer your Linux servers via a web browser.</subtitle>
      <title>Cockpit Project</title>
      <updated>2026-07-02T11:48:26Z</updated>
    </source>
  </entry>

  <entry>
    <id>tag:marcin.juszkiewicz.com.pl,2026-06-01:/2026/06/01/arm-desktop-so-many-cores-not-enough-speed/</id>
    <link href="https://marcin.juszkiewicz.com.pl/2026/06/01/arm-desktop-so-many-cores-not-enough-speed/" rel="alternate" type="text/html"/>
    <title>Arm desktop: so many cores, not enough speed</title>
    <summary>To use a desktop system you do not need many cores. As long as they are fast.</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Using a system with 80 AArch64 cores can be a pleasure. Or a pain…</p>
<!--MORE-->

<h3>Multicore heaven?</h3>
<p>Having 80 cores sounds nice, doesn’t it? But not so much during actual use…</p>
<p>You see, building Fedora packages was flying by. With all cores in use, ccache
buffers filling up (in case of rebuilds), and 128 <span class="caps">GB</span> of <span class="caps">RAM</span> in constant use, etc.</p>
<p>But at the same time, 100% load on all cores means you cannot listen to music
on Spotify or watch online videos, etc. All that because the <span class="caps">CPU</span> cores are
occupied by the build processes.</p>
<p>I tried to use cgroups to limit <code>cpu.max</code> for each <code>fedpkg mockbuild</code> call. It
did not help much: the audio was still jerky.</p>
<p>To compare: I wrote this post on a system powered by a Ryzen 5 3600 <span class="caps">CPU</span> while a
package build was running in the background. All twelve <span class="caps">CPU</span> threads were 100%
busy, yet the music did not skip.</p>
<p>All of this shows that cores-heavy CPUs are perhaps not a good choice for a
desktop machine. Latencies, the scheduler and context switching — all of this
introduces enough noise to make a desktop user suffer.</p>
<h3>The lack of single-thread speed</h3>
<p>Arm processors are good in many cases, as long as you do not need pure,
single-thread, <span class="caps">CPU</span> power.</p>
<p>It is very noticeable in a web browser. For example, Bitwarden unlocks with a
noticeable delay, while on a Ryzen 5 3600, it is nearly instant. And it feels even
worse when you watch some YouTube videos like “who will make faster <span class="caps">PC</span> on a €100
budget”, and then you run the same browser benchmark and get worse results…</p>
<p>Many software builds also highlight this problem. I have a feeling that
developers have grown used to a small number of fast <span class="caps">CPU</span> cores, which is the
norm on the x86-64 architecture, and their code is written to take it for granted.</p>
<p>And then you look at your machine, where 70 cores do nothing, waiting for some
code to finally compile or link. I have seen one software package where the
bootstrap was composed of <strong><span class="caps">TWO</span></strong> source files. Both were over two megabytes in
size and full of machine-generated C code. Two cores were kept busy for quite a
while, while the other 78 had to wait.</p>
<p>Not much has changed since my
<a href="https://marcin.juszkiewicz.com.pl/2018/06/06/from-the-diary-of-aarch64-porter-parallel-builds/">the “From the diary of AArch64 porter — parallel builds”</a>
blog post from eight years ago.</p>
<p>Of course, there are also packages which will take all cores, whole memory and
as much swap as possible, and do magic in nearly no time. When I started build of
the PrusaSlicer package, I had to add some swap because Firefox was gone due
to <span class="caps">OOM</span>. Having less than 2 <span class="caps">GB</span> of <span class="caps">RAM</span> per <span class="caps">CPU</span> core really sucks ;D</p>
<h3>Summary</h3>
<p>To use a desktop system you do not need many cores. As long as they are fast.</p></div>
    </content>
    <updated>2026-06-01T13:06:00Z</updated>
    <published>2026-06-01T13:06:00Z</published>
    <category term="aarch64"/>
    <category term="desktop"/>
    <category term="computers"/>
    <category term="fedora"/>
    <author>
      <name>Marcin Juszkiewicz</name>
    </author>
    <source>
      <id>https://marcin.juszkiewicz.com.pl/</id>
      <link href="https://marcin.juszkiewicz.com.pl/" rel="alternate" type="text/html"/>
      <link href="https://marcin.juszkiewicz.com.pl/tag/fedora/feed/" rel="self" type="application/atom+xml"/>
      <title>Marcin Juszkiewicz - fedora</title>
      <updated>2026-06-26T11:18:00Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>https://www.scrye.com/blogs/nirik/posts/2026/05/30/misc-fedora-bits-the-last-week-of-may-2026/</id>
    <link href="https://www.scrye.com/blogs/nirik/posts/2026/05/30/misc-fedora-bits-the-last-week-of-may-2026/" rel="alternate" type="text/html"/>
    <title xml:lang="en">misc fedora bits the last week of may 2026</title>
    <summary type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>Another week has gone by, time for another longer form recap.</p>
<section id="more-rhel10-migrations">
<h2>More rhel10 migrations</h2>
<p>Some more rhel10 migrations this last week. This time our memcached instances,
our tang servers and a few others. Slowly making progress, but this will get
us down to the 'fun' ones: Database servers, virthosts that host important
things, etc.</p>
</section>
<section id="fedora-42-eol">
<h2>Fedora 42 eol</h2>
<p>Tuesday was supposed to be the end of life for Fedora 42. For some reason, the
date was set to be wed, and then there was some delays due to failed updates
composes that pushed it to thursday. It's done however. Fedora 42 was a nice
release, it served well. We still have just 3 Fedora 42 instances we need to
move and we will do those next week...</p>
</section>
<section id="updated-staging-koji">
<h2>Updated staging koji</h2>
<p>I have updated our staging koji ( <a class="reference external" href="https://koji.stg.fedoraproject.org">https://koji.stg.fedoraproject.org</a> ) hub
and builders all to Fedora 44 and the latest koji version (1.36.0).
We have some non upstreamed patches for our theme, and koji upstream changed
from cheeta to jinja2 for it's templates which completely broke that.
I was able to use a clanker to rework the patch for jinja2 and then manually
fix it from there to work. I'd say it was much quicker, but the process
wasn't particularly satisfying. Anyhow, it's done and working as far as I
have been able to test in staging.</p>
</section>
<section id="mass-update-reboot-cycle-next-week">
<h2>Mass update/reboot cycle next week</h2>
<p>We are going to apply updates all around and reboot things next week.
There is a lot we hope to do on this outage:</p>
<ul class="simple">
<li><p>rhel 9.8 and 10.2 came out, so we will be updating all rhel servers to those.</p></li>
<li><p>we will be upgrading the wiki servers from f42 to f44 (and newer mediawiki)</p></li>
<li><p>I hope to do some rhel10 reinstalls while we are in outage</p></li>
<li><p>Upgrade prod koji to 1.36.0 and f44 (hubs and builders)</p></li>
<li><p>There is a chance DC operations want us to move some servers from
one set of racks to another to balance power usage out. Still to be
determined if this happens.</p></li>
</ul>
<p>So, it should be a busy week</p>
</section>
<section id="flock">
<h2>Flock</h2>
<p>The week after next, flock is already upon us! I hope to be there and
able to catch up with old friends and new.</p>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116664633411162579">https://fosstodon.org/@nirik/116664633411162579</a></p>
</section></div>
    </summary>
    <content type="xhtml" xml:lang="en"><div xmlns="http://www.w3.org/1999/xhtml"><a class="reference external image-reference" href="https://www.scrye.com/blogs/nirik/images/crystal_ball.jpg">
<img alt="Scrye into the crystal ball" src="https://www.scrye.com/blogs/nirik/images/crystal_ball.thumbnail.jpg"/>
</a>
<p>Another week has gone by, time for another longer form recap.</p>
<section id="more-rhel10-migrations">
<h2>More rhel10 migrations</h2>
<p>Some more rhel10 migrations this last week. This time our memcached instances,
our tang servers and a few others. Slowly making progress, but this will get
us down to the 'fun' ones: Database servers, virthosts that host important
things, etc.</p>
</section>
<section id="fedora-42-eol">
<h2>Fedora 42 eol</h2>
<p>Tuesday was supposed to be the end of life for Fedora 42. For some reason, the
date was set to be wed, and then there was some delays due to failed updates
composes that pushed it to thursday. It's done however. Fedora 42 was a nice
release, it served well. We still have just 3 Fedora 42 instances we need to
move and we will do those next week...</p>
</section>
<section id="updated-staging-koji">
<h2>Updated staging koji</h2>
<p>I have updated our staging koji ( <a class="reference external" href="https://koji.stg.fedoraproject.org">https://koji.stg.fedoraproject.org</a> ) hub
and builders all to Fedora 44 and the latest koji version (1.36.0).
We have some non upstreamed patches for our theme, and koji upstream changed
from cheeta to jinja2 for it's templates which completely broke that.
I was able to use a clanker to rework the patch for jinja2 and then manually
fix it from there to work. I'd say it was much quicker, but the process
wasn't particularly satisfying. Anyhow, it's done and working as far as I
have been able to test in staging.</p>
</section>
<section id="mass-update-reboot-cycle-next-week">
<h2>Mass update/reboot cycle next week</h2>
<p>We are going to apply updates all around and reboot things next week.
There is a lot we hope to do on this outage:</p>
<ul class="simple">
<li><p>rhel 9.8 and 10.2 came out, so we will be updating all rhel servers to those.</p></li>
<li><p>we will be upgrading the wiki servers from f42 to f44 (and newer mediawiki)</p></li>
<li><p>I hope to do some rhel10 reinstalls while we are in outage</p></li>
<li><p>Upgrade prod koji to 1.36.0 and f44 (hubs and builders)</p></li>
<li><p>There is a chance DC operations want us to move some servers from
one set of racks to another to balance power usage out. Still to be
determined if this happens.</p></li>
</ul>
<p>So, it should be a busy week</p>
</section>
<section id="flock">
<h2>Flock</h2>
<p>The week after next, flock is already upon us! I hope to be there and
able to catch up with old friends and new.</p>
<p>As always, comment on the fediverse:
<a class="reference external" href="https://fosstodon.org/@nirik/116664633411162579">https://fosstodon.org/@nirik/116664633411162579</a></p>
</section></div>
    </content>
    <updated>2026-05-30T16:54:54Z</updated>
    <published>2026-05-30T16:54:54Z</published>
    <category label="fedora" term="fedora"/>
    <category label="linux" term="linux"/>
    <author>
      <name>nirik</name>
    </author>
    <source>
      <id>https://www.scrye.com/blogs/nirik/categories/fedora.atom</id>
      <author>
        <name>nirik</name>
      </author>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora.atom" rel="self" type="application/atom+xml"/>
      <link href="https://www.scrye.com/blogs/nirik/categories/fedora/" rel="alternate" type="text/html"/>
      <title xml:lang="en">Kevin's musings (Posts about fedora)</title>
      <updated>2026-07-04T19:53:19Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>http://fossjon.wordpress.com/?p=7377</id>
    <link href="https://fossjon.wordpress.com/2026/05/29/lessons-learned-from-implementing-multi-threaded-vpns/" rel="alternate" type="text/html"/>
    <title>Lessons Learned From Implementing Multi-Threaded VPNs!</title>
    <summary>When reading packets or network data from a tunnel interface, the order in which they are read does matter as they can impact connectionless protocols and also cause stateful protocols to spend time re-ordering data! There were three techniques that I tried implementing to solve this issue: ~</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">When reading packets or network data from a tunnel interface, the order in which they are read does matter as they can impact connectionless protocols and also cause stateful protocols to spend time re-ordering data! There were three techniques that I tried implementing to solve this issue:</p>



<ul class="wp-block-list">
<li>Map a packet address to a thread index during the entire time of every connection state</li>



<li>Index and order every packet read by number and wait to write them out in the same sequence</li>



<li>Lock and time and order each threaded process just like many pistons firing inside of an engine block</li>
</ul>



<p class="wp-block-paragraph">~</p>



<p class="wp-block-paragraph"/></div>
    </content>
    <updated>2026-05-29T18:44:30Z</updated>
    <published>2026-05-29T18:44:30Z</published>
    <category term="Open Source"/>
    <author>
      <name>fossjon</name>
    </author>
    <source>
      <id>https://fossjon.wordpress.com</id>
      <logo>https://s0.wp.com/i/webclip.png</logo>
      <link href="https://fossjon.wordpress.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://fossjon.wordpress.com" rel="alternate" type="text/html"/>
      <link href="https://fossjon.wordpress.com/osd.xml" rel="search" title="Jon's FOSS Blog" type="application/opensearchdescription+xml"/>
      <link href="https://fossjon.wordpress.com/?pushpress=hub" rel="hub" type="text/html"/>
      <subtitle>Anything networking, coding, crypto, or security</subtitle>
      <title>Jon's FOSS Blog</title>
      <updated>2026-05-29T18:44:30Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://blogs.gnome.org/aday/?p=10924</id>
    <link href="https://blogs.gnome.org/aday/2026/05/29/gnome-foundation-update-2026-05-29/" rel="alternate" type="text/html"/>
    <title>GNOME Foundation Update, 2026-05-29</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">Welcome to another update about everything that’s been happening at the GNOME Foundation. As has become my custom, this post covers a two week period, this time from 18 May until today, 29 May. As usual the Foundation continues to be busy, with events, infra, governance, and accounting activities all happening simultaneously. Read on for … <a class="more-link" href="https://blogs.gnome.org/aday/2026/05/29/gnome-foundation-update-2026-05-29/">Continue reading <span class="screen-reader-text">GNOME Foundation Update, 2026-05-29</span></a></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Welcome to another update about everything that’s been happening at the GNOME Foundation. As has become my custom, this post covers a two week period, this time from 18 May until today, 29 May. As usual the Foundation continues to be busy, with events, infra, governance, and accounting activities all happening simultaneously. Read on for more information!</p>
<h2>Events</h2>
<p>Linux App Summit (LAS) 2026 was held in Berlin over the 16-17 May weekend. I’ve heard quite a few reports now, and everyone seemed extremely positive about the event. Kristi wrote <a class="external" href="https://discourse.gnome.org/t/linux-app-summit-2026-thank-you-for-joining-us/35157">a nice summary</a> if you want more details.</p>
<p>The GNOME Foundation had two team members on the ground helping with running the event, which we co-organize with KDE. I’d like to take this opportunity to give a big thank you to the event’s sponsors: openSUSE, Tuxedo, Nextcould and Codethink. This event wouldn’t be possible without your support.</p>
<p>In addition to LAS, work is continuing on arrangements for GUADEC 2026. The deadline for travel sponsorship applications has now passed, and the Travel Committee has met to decide who will be funded. Notifications will be going out soon.</p>
<h2>Board Elections</h2>
<p>The process is officially underway for <a class="external" href="https://discourse.gnome.org/t/gnome-foundation-board-of-directors-elections-2026/">this year’s Board elections</a>. Terms on our Board of Directors are two years in length, and each year half the board seats are open for election. This year we have five seats being contested.</p>
<p>The 2026 election has a slightly different schedule to previous years. In the past, there was no gap between the candidacy period, in which people can announce their intention to run, and the voting period. This meant that there was little opportunity for last-minute candidates to participate in discussion prior to voting taking place.</p>
<p>To address this, we’ve added a one week discussion period to the schedule, which will run between 8 and 15 June, between the candidacy and voting periods. This will hopefully give us opportunity to have more structured and inclusive debate amongst the candidates. We are still figuring out what that might look like, so if people have ideas or want to help, let me know in the comments.</p>
<h2>GNOME Fellowship</h2>
<p>We are currently in the very final stages of confirming and announcing the successful candidates for the inaugural round of the <a class="external" href="https://fellowship.gnome.org/">Foundation’s Fellowship program</a>. Expect an announcement very soon.</p>
<h2>Got a Concern?</h2>
<p>Last week we introduced a new <a class="external" href="https://handbook.gnome.org/foundation/concern-reporting.html">policy for handling of concerns</a> about the Foundation, which is now part of the project handbook.</p>
<p>The new policy covers how to report concerns about people who are working for the Foundation, either in a paid or voluntary capacity. It also covers more general concerns about the Foundation.</p>
<p>The main goals of the policy are to:</p>
<ul>
<li>have a documented reporting procedure for those who have concerns relating to the Foundation</li>
<li>clarify how concerns will be responded to</li>
<li>provide reassurance for those reporting concerns, including that concern reports are welcome, are taken seriously, and will never result in retaliation</li>
</ul>
<p>We hope that this policy will make it clear how you can inform us of a concern if you have one. We also want to emphasise that we want to hear concerns, so we can address them. Please do use the new reporting procedure.</p>
<h3>Finance/Accounting</h3>
<p>Work has continued on the finance and accounting operation over the past two weeks. Highlights include:</p>
<ul>
<li>Our transition to a monthly rather than quarterly close reached a significant milestone this week, with the completion of our April finance reports within three weeks of the previous month end. This is probably the fastest ever turnaround for our finance operation, and is a huge win for us in being able to effectively manage our finances.</li>
<li>Following input from the board, corrections have now been sent to the accountants for our audit and annual tax filing.</li>
<li>Applications are still open for our <a class="external" href="https://www.idealist.org/en/nonprofit-job/5942160e1dec484a934de7a6d9508dc3-finance-operations-director-part-time-contractor-gnome-foundation-san-francisco">Director of Finance and Operations part-time contract</a>. Candidates have until 4 June to submit.</li>
<li>Finally, as I mentioned in my last update, we are in the process of retiring a number of finance platforms as we consolidate and streamline our operation. This week saw another platform retired, which brings the total number of eliminated platforms to four.</li>
</ul>
<h2>Infrastructure</h2>
<p>Our infrastructure experienced a <a class="external" href="https://discourse.gnome.org/t/an-update-on-the-last-few-hours-ddos/35188">DDoS attack last weekend</a>, which Bart and Andrea have been dealing with. Thankfully it seems that services weren’t too badly affected, and we’ve already improved our protection against similar attacks in the future.</p>
<p>Also on the infra side, Bart wasn’t at LAS this year, but he did spend some time writing two great posts about Flathub’s internals: <a class="external" href="https://barthalion.blog/flathub-internals-cdn/">How does Flathub even work?</a> and <a class="external" href="https://barthalion.blog/flathub-internals-cdn-and-deltas/">Why are Flathub downloads so slow sometimes?</a>. They’re a fascinating read if you’re interested in Flathub.</p>
<p>That’s it from me! As always, thanks for reading, and see you in two weeks.</p></div>
    </content>
    <updated>2026-05-29T16:41:43Z</updated>
    <published>2026-05-29T16:41:43Z</published>
    <author>
      <name>Allan Day</name>
    </author>
    <source>
      <id>https://blogs.gnome.org/aday</id>
      <link href="https://blogs.gnome.org/aday/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://blogs.gnome.org/aday" rel="alternate" type="text/html"/>
      <subtitle>Allan Day's GNOME Blog</subtitle>
      <title>Form and Function</title>
      <updated>2026-05-29T16:41:43Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>http://fossjon.wordpress.com/?p=7373</id>
    <link href="https://fossjon.wordpress.com/2026/05/28/a-year-of-three-websites/" rel="alternate" type="text/html"/>
    <title>A Year Of Three Websites</title>
    <summary>https://fossjon.com https://xorcipher.com https://icanhazdns.com ~</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph"><a href="https://fossjon.com">https://fossjon.com</a></p>



<p class="wp-block-paragraph"><a href="https://xorcipher.com">https://xorcipher.com</a></p>



<p class="wp-block-paragraph"><a href="https://icanhazdns.com">https://icanhazdns.com</a></p>



<p class="wp-block-paragraph">~</p></div>
    </content>
    <updated>2026-05-29T01:23:02Z</updated>
    <published>2026-05-29T01:23:02Z</published>
    <category term="Open Source"/>
    <author>
      <name>fossjon</name>
    </author>
    <source>
      <id>https://fossjon.wordpress.com</id>
      <logo>https://s0.wp.com/i/webclip.png</logo>
      <link href="https://fossjon.wordpress.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://fossjon.wordpress.com" rel="alternate" type="text/html"/>
      <link href="https://fossjon.wordpress.com/osd.xml" rel="search" title="Jon's FOSS Blog" type="application/opensearchdescription+xml"/>
      <link href="https://fossjon.wordpress.com/?pushpress=hub" rel="hub" type="text/html"/>
      <subtitle>Anything networking, coding, crypto, or security</subtitle>
      <title>Jon's FOSS Blog</title>
      <updated>2026-05-29T18:44:30Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>http://fossjon.wordpress.com/?p=7369</id>
    <link href="https://fossjon.wordpress.com/2026/05/28/i-created-a-new-web-service-for-command-lines-icanhazdns-com/" rel="alternate" type="text/html"/>
    <title>I Created A New Web Service For Command Lines – icanhazdns.com</title>
    <summary>It is inspired by icanhazip.com but it returns a little more information as well! curl icanhazdns.com ~</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">It is inspired by icanhazip.com but it returns a little more information as well!</p>



<pre class="wp-block-preformatted">curl icanhazdns.com</pre>



<p class="wp-block-paragraph">~</p></div>
    </content>
    <updated>2026-05-28T22:21:17Z</updated>
    <published>2026-05-28T22:21:17Z</published>
    <category term="Open Source"/>
    <author>
      <name>fossjon</name>
    </author>
    <source>
      <id>https://fossjon.wordpress.com</id>
      <logo>https://s0.wp.com/i/webclip.png</logo>
      <link href="https://fossjon.wordpress.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://fossjon.wordpress.com" rel="alternate" type="text/html"/>
      <link href="https://fossjon.wordpress.com/osd.xml" rel="search" title="Jon's FOSS Blog" type="application/opensearchdescription+xml"/>
      <link href="https://fossjon.wordpress.com/?pushpress=hub" rel="hub" type="text/html"/>
      <subtitle>Anything networking, coding, crypto, or security</subtitle>
      <title>Jon's FOSS Blog</title>
      <updated>2026-05-29T18:44:30Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>http://fossjon.wordpress.com/?p=7361</id>
    <link href="https://fossjon.wordpress.com/2026/05/27/earth-to-apple-curved-glass-is-more-beautiful-than-curved-metal/" rel="alternate" type="text/html"/>
    <title>EARTH-TO-APPLE – Curved Glass Is More Beautiful Than Curved Metal!</title>
    <summary>Please help me start a petition to Apple to bring back smaller sized phones with a pro screen and a flat metal ribbon which wraps the curved glass front and back like a beautiful diamond ring design should be! The iPhone 4S was soo close, all it needed was a full AOD screen with curved […]</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">Please help me start a petition to Apple to bring back smaller sized phones with a pro screen and a flat metal ribbon which wraps the curved glass front and back like a beautiful diamond ring design should be! The iPhone 4S was soo close, all it needed was a full AOD screen with curved corners and edges…</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><a href="https://fossjon.wordpress.com/wp-content/uploads/2026/05/iphone.png"><img alt="" class="wp-image-7365" height="640" src="https://fossjon.wordpress.com/wp-content/uploads/2026/05/iphone.png?w=640" width="640"/></a></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><a href="https://fossjon.wordpress.com/wp-content/uploads/2026/05/corvette.jpg"><img alt="" class="wp-image-7364" height="594" src="https://fossjon.wordpress.com/wp-content/uploads/2026/05/corvette.jpg?w=880" width="880"/></a></figure>
</div></div>
    </content>
    <updated>2026-05-28T02:10:27Z</updated>
    <published>2026-05-28T02:10:27Z</published>
    <category term="Open Source"/>
    <author>
      <name>fossjon</name>
    </author>
    <source>
      <id>https://fossjon.wordpress.com</id>
      <logo>https://s0.wp.com/i/webclip.png</logo>
      <link href="https://fossjon.wordpress.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://fossjon.wordpress.com" rel="alternate" type="text/html"/>
      <link href="https://fossjon.wordpress.com/osd.xml" rel="search" title="Jon's FOSS Blog" type="application/opensearchdescription+xml"/>
      <link href="https://fossjon.wordpress.com/?pushpress=hub" rel="hub" type="text/html"/>
      <subtitle>Anything networking, coding, crypto, or security</subtitle>
      <title>Jon's FOSS Blog</title>
      <updated>2026-05-29T18:44:30Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://adam.younglogic.com/?p=11744</id>
    <link href="https://adam.younglogic.com/2026/05/debugging-rust-in-vim/" rel="alternate" type="text/html"/>
    <title>Debugging Rust in Vim</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">On Fedora: in ~/.vimrc Inside vim: Use Ctrl-W DownArrow to switch between windows Use :Break to set a breakpoint in the code window Use Ctrl-W UpArrow to go to the gdb window use run to run the program and cont … <a href="https://adam.younglogic.com/2026/05/debugging-rust-in-vim/">Continue reading <span class="meta-nav">→</span></a></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">On Fedora:</p>



<pre class="wp-block-code"><code>yum install termdebug</code></pre>



<p class="wp-block-paragraph">in ~/.vimrc</p>



<pre class="wp-block-code"><code>let g:termdebug_config = {}
let g:termdebug_config['command'] = 'rust-gdb'

packadd! termdebug
                   </code></pre>



<p class="wp-block-paragraph">Inside vim:</p>



<pre class="wp-block-code"><code>Termdebug target/debug&lt;executable&gt;
</code></pre>



<p class="wp-block-paragraph">Use Ctrl-W DownArrow to switch between windows</p>



<p class="wp-block-paragraph">Use :<strong>Break</strong> to set a breakpoint in the code window</p>



<p class="wp-block-paragraph">Use Ctrl-W UpArrow to go to the gdb window</p>



<p class="wp-block-paragraph">use <strong>run</strong> to run the program and cont to continue after hitting a break point.</p></div>
    </content>
    <updated>2026-05-27T22:34:57Z</updated>
    <published>2026-05-27T22:34:57Z</published>
    <category term="Rust"/>
    <category term="Software"/>
    <author>
      <name>Adam Young</name>
    </author>
    <source>
      <id>https://adam.younglogic.com</id>
      <link href="https://adam.younglogic.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://adam.younglogic.com" rel="alternate" type="text/html"/>
      <subtitle>The Notebook of a Programmer Climber Musician Ex-Soldier Woodworker and a few other things</subtitle>
      <title>Adam Young's Web Log</title>
      <updated>2026-06-22T16:58:17Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>http://fossjon.wordpress.com/?p=7350</id>
    <link href="https://fossjon.wordpress.com/2026/05/27/upgrade-ubuntu-to-the-next-major-release-via-command-line-ssh-screen/" rel="alternate" type="text/html"/>
    <title>Upgrade Ubuntu To The Next Major Release via Command Line SSH/Screen</title>
    <summary>screen -dm -S up bash -c "do-release-upgrade -d -m server ; sleep 99999" Bonus Command: screen -p 0 -S test -X stuff 'echo "test" \n' ~</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><pre class="wp-block-preformatted">screen -dm -S up bash -c "do-release-upgrade -d -m server ; sleep 99999"</pre>



<p class="wp-block-paragraph">Bonus Command:</p>



<pre class="wp-block-preformatted">screen -p 0 -S test -X stuff 'echo "test" \n'</pre>



<p class="wp-block-paragraph">~</p>



<p class="wp-block-paragraph"/></div>
    </content>
    <updated>2026-05-27T17:37:52Z</updated>
    <published>2026-05-27T17:37:52Z</published>
    <category term="Open Source"/>
    <author>
      <name>fossjon</name>
    </author>
    <source>
      <id>https://fossjon.wordpress.com</id>
      <logo>https://s0.wp.com/i/webclip.png</logo>
      <link href="https://fossjon.wordpress.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://fossjon.wordpress.com" rel="alternate" type="text/html"/>
      <link href="https://fossjon.wordpress.com/osd.xml" rel="search" title="Jon's FOSS Blog" type="application/opensearchdescription+xml"/>
      <link href="https://fossjon.wordpress.com/?pushpress=hub" rel="hub" type="text/html"/>
      <subtitle>Anything networking, coding, crypto, or security</subtitle>
      <title>Jon's FOSS Blog</title>
      <updated>2026-05-29T18:44:30Z</updated>
    </source>
  </entry>

  <entry xml:lang="fa-IR">
    <id>https://fedorafans.com/?p=8525</id>
    <link href="https://fedorafans.com/%d8%a2%d9%85%d9%88%d8%b2%d8%b4-%d9%86%d8%b5%d8%a8-%d9%88-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-masterdnsvpn/" rel="alternate" type="text/html"/>
    <title>آموزش نصب و راه اندازی MasterDnsVPN</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><div style="margin-bottom: 20px;"><img alt="masterdnsvpn" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" height="640" src="https://fedorafans.com/wp-content/uploads/2026/05/masterdnsvpn-fedorafans.com_.webp" width="1280"/></div><p>MasterDnsVPN یک نرم‌افزار متن‌باز و پیشرفته برای DNS Tunneling است که با زبان Go توسعه داده شده و با کپسوله‌سازی ترافیک TCP داخل درخواست‌ها و پاسخ‌های DNS، امکان عبور از محدودیت‌ها و فیلترینگ شدید اینترنت را فراهم می‌کند. این پروژه با تمرکز بر پایداری، سرعت و عملکرد در شبکه‌های دارای Packet Loss بالا طراحی شده […]</p>
The post <a href="https://fedorafans.com/%d8%a2%d9%85%d9%88%d8%b2%d8%b4-%d9%86%d8%b5%d8%a8-%d9%88-%d8%b1%d8%a7%d9%87-%d8%a7%d9%86%d8%af%d8%a7%d8%b2%db%8c-masterdnsvpn/">آموزش نصب و راه اندازی MasterDnsVPN</a> first appeared on <a href="https://fedorafans.com">طرفداران فدورا</a>.</div>
    </summary>
    <updated>2026-05-26T14:03:18Z</updated>
    <published>2026-05-26T14:03:18Z</published>
    <category term="&#x627;&#x6CC;&#x646;&#x62A;&#x631;&#x646;&#x62A; &#x648; &#x634;&#x628;&#x6A9;&#x647;"/>
    <category term="app"/>
    <category term="dns tunnling"/>
    <category term="linux"/>
    <category term="masterdnsvpn"/>
    <category term="proxy"/>
    <category term="vpn"/>
    <category term="&#x622;&#x645;&#x648;&#x632;&#x634;"/>
    <category term="&#x62A;&#x648;&#x646;&#x644;"/>
    <category term="&#x648;&#x6CC; &#x67E;&#x6CC; &#x627;&#x646;"/>
    <category term="&#x67E;&#x631;&#x627;&#x6A9;&#x633;&#x6CC;"/>
    <category term="&#x67E;&#x631;&#x648;&#x6A9;&#x633;&#x6CC;"/>
    <author>
      <name>hos7ein</name>
    </author>
    <source>
      <id>https://fedorafans.com</id>
      <link href="https://fedorafans.com/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://fedorafans.com" rel="alternate" type="text/html"/>
      <subtitle>همه برای فدورا , فدورا برای همه</subtitle>
      <title>طرفداران فدورا</title>
      <updated>2026-06-22T11:13:16Z</updated>
    </source>
  </entry>

  <entry xml:lang="en">
    <id>urn:md5:88dd992d224dd5a1adfbadad929f090c</id>
    <link href="https://blog.remirepo.net/post/2026/05/23/Redis-version-8.8" rel="alternate" type="text/html"/>
    <title>📝 Redis version 8.8</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>RPMs of <strong>Redis version 8.8</strong> are available in the <strong>remi-modular</strong> repository for <strong>Fedora</strong> ≥ 43 and <strong>Enterprise Linux</strong> ≥ 8 (RHEL, Alma, CentOS, Rocky...).</p>

<!--
<p>⚠️ Warning: this is a pre-release version not ready for production usage.</p>
--> <h2>1. Installation</h2>

<p>Packages are available in the <strong>redis:remi-8.8</strong> module stream.</p>

<h3>1.1. Using <strong>dnf4</strong> on Enterprise Linux</h3>

<pre># dnf install https://rpms.remirepo.net/enterprise/remi-release-$(rpm -E %rhel).rpm
# dnf module switch-to redis:remi-8.8/common</pre>

<h3>1.2. Using <strong>dnf5</strong> on Fedora</h3>

<pre># dnf install https://rpms.remirepo.net/fedora/remi-release-$(rpm -E %fedora).rpm
# dnf module reset  redis
# dnf module enable redis:remi-8.8
# dnf install redis --allowerasing</pre>

<p>You may have to remove the valkey-compat-redis compatibility package.</p>

<h2>2. Modules</h2>

<p>Some optional modules are also available:</p>

<ul>
	<li><a href="https://github.com/RedisBloom/RedisBloom">RedisBloom</a> as redis-bloom</li>
	<li><a href="https://github.com/RedisJSON/RedisJSON">RedisJSON</a> as redis-json</li>
	<li><a href="https://github.com/RedisTimeSeries/RedisTimeSeries/">RedisTimeSeries</a> as redis-timeseries</li>
</ul>

<p>These packages are weak dependencies of Redis, so they are installed by default (if install_weak_deps is not disabled in the dnf configuration).</p>

<p>The modules are automatically loaded after installation and service (re)start.</p>

<p>The modules are not available for Enterprise Linux 8.</p>
<!--
<h2>3. Future</h2>

<p><strong>Valkey</strong> also provides a similar set of modules, requiring some packaging changes already applied in&nbsp;Fedora official repository.</p>

<p><strong>Redis</strong> may be proposed for unretirement and be back in the Fedora official repository, by me if I find enough motivation and energy, or by someone else.</p>

<p>I may also try to solve packaging issues for other modules (e.g. RediSearch). For now, module packages are very far from Packaging Guidelines, so obviously not ready for a review.</p>
--><!--
-->

<h2>3. Statistics</h2>

<p align="center"><strong>redis</strong><br/>
<img alt="" src="https://blog.remirepo.net/downcpt.php?name=redis&amp;version=8.8~rc1&amp;lang=en&amp;release=1.module_redis.8.8" style="display: block;"/></p>

<p align="center"><strong>redis-bloom</strong><br/>
<img alt="" src="https://blog.remirepo.net/downcpt.php?name=redis-bloom&amp;version=8.8.0&amp;lang=en&amp;release=1.module_redis.8.8" style="display: block;"/></p>

<p align="center"><strong>redis-json</strong><br/>
<img alt="" src="https://blog.remirepo.net/downcpt.php?name=redis-json&amp;version=8.8.0&amp;lang=en&amp;release=1.module_redis.8.8" style="display: block;"/></p>

<p align="center"><strong>redis-timeseries</strong><br/>
<img alt="" src="https://blog.remirepo.net/downcpt.php?name=redis-timeseries&amp;version=8.8.0&amp;lang=en&amp;release=1.module_redis.8.8" style="display: block;"/></p></div>
    </summary>
    <updated>2026-05-23T14:38:00Z</updated>
    <published>2026-05-23T14:38:00Z</published>
    <category term="RPM"/>
    <category term="Beta"/>
    <category term="Redis"/>
    <author>
      <name>Remi</name>
    </author>
    <source>
      <id>https://blog.remirepo.net/en</id>
      <link href="https://blog.remirepo.net/en" rel="alternate" type="text/html"/>
      <link href="https://blog.remirepo.net/feed/en/rss2" rel="self" type="application/rss+xml"/>
      <rights>Licence: Creative Commons Attribution-ShareAlike 4.0 International License.</rights>
      <subtitle>Remi's RPM repository blog Information about RPM PHP Fedora RHEL and CentOS</subtitle>
      <title>Remi's RPM repository - Blog</title>
      <updated>2026-07-10T04:19:09Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://blogs.gnome.org/mcatanzaro/?p=11145</id>
    <link href="https://blogs.gnome.org/mcatanzaro/2026/05/21/single-click-code-execution-exploit-for-evince-atril-and-xreader/" rel="alternate" type="text/html"/>
    <title>Single-Click Code Execution Exploit for Evince, Atril, and Xreader</title>
    <summary>CVE-2026-46529 is an argument injection vulnerability in Evince, Atril, and Xreader caused by missing shell quoting when composing a command line. The reporter, JoÃ£o Medeiros, has published a GitHub repo for the CVE and a blog post with the story of how he discovered the flaw and developed the exploit. He also created an Atril […]</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p class="wp-block-paragraph">CVE-2026-46529 is an argument injection vulnerability in Evince, Atril, and Xreader caused by missing shell quoting when composing a command line. The reporter, Jo達o Medeiros, has published a <a class="external" href="https://github.com/N1et/CVE-2026-46529">GitHub repo</a> for the CVE and a <a class="external" href="https://medeiros.zip/posts/CVE-2026-46529-evince">blog post</a> with the story of how he discovered the flaw and developed the exploit. He also created an <a class="external" href="https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f">Atril security advisory</a> and an <a class="external" href="https://gitlab.gnome.org/GNOME/evince/-/work_items/2153">Evince issue report</a>.</p>



<p class="wp-block-paragraph">The vulnerability is fixed in:</p>



<ul class="wp-block-list">
<li>Evince 48.4 (<a class="external" href="https://gitlab.gnome.org/GNOME/evince/-/commit/970c219e861a5fcc3e7b9e05bedf18cf0de39245">fix commit</a>) (I originally reported that it is fixed in 48.2, but there was no successful release for that tag)</li>



<li>Atril 1.28.4 and 1.26.3 (<a class="external" href="https://github.com/mate-desktop/atril/commit/b989b7922a454ed81f8bb14786a958828513f576">fix commit</a>)</li>



<li>Xreader 4.6.4 and 3.6.7 (<a class="external" href="https://github.com/linuxmint/xreader/commit/50052eaa91c3c750c51c245799e3747495feeece">fix commit</a>)</li>
</ul>



<p class="wp-block-paragraph">If you use one of these PDF readers, update immediately. Or at least please be seriously paranoid about clicking on links in PDFs until you do update.</p>



<p class="wp-block-paragraph"><a class="external" href="https://gitlab.gnome.org/GNOME/papers/-/commit/1b82bf627b4d8b414a57b55a9095e6d361799d6c">This vulnerability also affects Papers</a>, but it’s probably not urgent to update Papers. (No, not because it uses Rust. Keep reading!)</p>



<p class="wp-block-paragraph">The Flatpak sandbox could have drastically reduced the danger of this attack, limiting the compromise to only files that you had previously opened in the PDF reader. Sadly, Evince and Papers both use sandbox holes that render the sandbox totally meaningless. (Atril and Xreader are not available on Flathub.)</p>



<h2 class="wp-block-heading">The Vulnerability</h2>



<p class="wp-block-paragraph">When you click on a link in a PDF, Evince may execute itself to display the link. Normally the command line used would look something like this:</p>



<p class="wp-block-paragraph"><code>/usr/bin/evince --named-dest=/home/foo/hello.pdf</code></p>



<p class="wp-block-paragraph">But an evil PDF may trick Evince into executing a command that is quite different than expected:</p>



<p class="wp-block-paragraph"><code>/usr/bin/evince --named-dest= --gtk-module=/home/foo/evil.so /home/foo/hello.pdf</code></p>



<p class="wp-block-paragraph">Oops. The first part of the command is always going to be <code>/usr/bin/evince</code>, but the evil PDF is nevertheless able to unexpectedly load a GTK module into Evince. The fix is to quote the untrusted input using <code>g_shell_quote()</code> to ensure it cannot “break out” of its intended context:</p>



<p class="wp-block-paragraph"><code>/usr/bin/evince --named-dest='/home/foo/hello.pdf'</code></p>



<p class="wp-block-paragraph">Or:</p>



<p class="wp-block-paragraph"><code>/usr/bin/evince --named-dest=' --gtk-module=/home/foo/evil.so /home/foo/hello.pdf'</code></p>



<p class="wp-block-paragraph">Much better: now the threat is neutralized. <code>g_shell_quote()</code> is safe to use even if the untrusted input itself contains quotes. (However, beware: this only works because GLib is parsing the command line itself, and GLib is not a real Unix shell. <a class="external" href="https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5187/#note_2762996">It’s not safe if the input is going to be passed to an actual Unix shell.</a> It might not even be theoretically possible to do that safely, because it’s valid for filenames to contain entirely arbitrary characters!)</p>



<p class="wp-block-paragraph">All GTK 3 apps support the <code>--gtk-module</code> command line argument for injecting a shared library into the application. The library may of course then execute whatever code it wants via its library constructor. But GTK 4 no longer has standard GTK command line flags, so this does not work for GTK 4 applications like Papers. It’s still possible to tell a GTK 4 app to load a GTK module, but only via environment variables, not via command line flags, and I don’t see any opportunity for the malicious command to set environment variables. It’s probably not possible to exploit this vulnerability in Papers: although it has the exact same vulnerability as the other PDF readers, the impact is different.</p>



<h2 class="wp-block-heading">The Exploit</h2>



<p class="wp-block-paragraph">So far this looks like a pretty typical security bug. OK, so if you trick the user into downloading an archive (or perhaps a git repo) that contains both a malicious PDF and also a malicious shared library, then you can trick the PDF reader into loading the shared library and thereby execute arbitrary code. That’s a pretty bad foreseeable exploit, sure, but at least the attacker is at considerable risk of arousing suspicion if the user is trying to download a PDF and also receives a shared library. You’d have to try pretty hard to hide the library in a forest of other boring files if you want the attack to look convincing and unsuspicious. Right?</p>



<p class="wp-block-paragraph">Nope.</p>



<p class="wp-block-paragraph">Jo達o used Claude Opus 4.7 to develop a sophisticated script for building malicious polyglot PDFs that are simultaneously both valid PDF files and also valid ELF binaries, so the attacker only needs to trick the victim into downloading one evil PDF file. When the victim clicks on a link in that PDF, the PDF reader will dlopen the PDF itself. The PDF/ELF polyglot’s library constructor will then execute arbitrary code. Much less suspicious, and much scarier. Polyglot files are <a class="external" href="https://github.com/Polydet/polyglot-database">not entirely novel</a>, but I’d still say this required substantial creativity and expertise from the AI, and substantial persistence from the human. Needless to say, very nice job to both Claude and Jo達o.</p>



<p class="wp-block-paragraph">You can easily build your own malicious PDF using the provided script and sample GTK module. The script in the Evince and Atril issue reports requires that the attacker predict the absolute path that the malicious PDF file will be saved to; however, Jo達o’s blog post and GitHub repo refine the exploit to remove that requirement.</p>



<h2 class="wp-block-heading">Thoughts on AI Vulnerability Reports</h2>



<p class="wp-block-paragraph">A human inspecting this code should have been able to find the parameter injection vulnerability, but that requires considerable time and effort, so unsurprisingly nobody did. We’re probably in for a rough time in the short term as the volume of AI-generated vulnerability findings remains temporarily very high and attackers have a much easier time crafting working exploits. But in the long term, I expect we are going to be much more secure than we were before, so this will be worth it.</p>



<p class="wp-block-paragraph">A human working alone would have almost certainly stopped and moved on after finding the vulnerability. Claude allowed taking the investigation much farther. It’s highly unusual for a GNOME vulnerability report to come with a working exploit. This is a dangerous change. Perhaps it will be a one-time event, but I suspect we will be seeing more frequent exploits in the future.</p>



<p class="wp-block-paragraph">Silver lining: the exploit helps us better appreciate the severity of the issue. It’s often hard to assess how bad a vulnerability is. If not for the weaponized exploit, I would have thought this bug was not very scary, and would have treated it as not a big deal. We would have fixed it, perhaps or perhaps not with a CVE ID, surely without any blog post or fanfare, and probably without distro security updates. But since there is an exploit, we instead had no doubt that this vulnerability was dangerous, and were able to handle it accordingly.</p>



<p class="wp-block-paragraph">Several GNOME projects have begun outright prohibiting all AI-generated contributions, including issue reports, with no exception for vulnerability reports. Such policies are misguided and unacceptable. I can sort of understand why some projects might (misguidedly) wish to prohibit AI-generated code contributions. OK, fine. But blocking AI vulnerability reports will make GNOME less safe. AI-assisted vulnerability reporting is the new industry standard for good reason: it is highly effective.</p>



<p class="wp-block-paragraph">Some humans are not good at preparing AI-assisted vulnerability reports and will spam maintainers with low-quality reports. Sometimes they will be outright bogus, although more often there may be valid underlying bugs with exaggerated severity claims or bad proof of concept demos. This is annoying, but bad issue reports are a cost we are just going to have to accept and deal with.</p>



<p class="wp-block-paragraph">The quality level of AI vulnerability reports reviewed by conscientious humans — as well as AI assessments of AI vulnerability reports — is now often quite encouraging. But just like humans, AIs may also miss things, especially subtle distinctions that may be highly relevant. Although I�� quite impressed with these AIs, we still need experienced humans to review and manage reports. Please don’t abuse the technology by submitting vulnerability reports that you do not understand or have not validated. And certainly please do not allow an AI agent to interact with an issue tracker on your behalf!</p>



<h2 class="wp-block-heading">For Security Geeks</h2>



<p class="wp-block-paragraph">This was my first time scoring a vulnerability using CVSS 4.0 rather than CVSS 3.1. It’s also the first time I wasn’t terribly confused about how to set the parameters, because the <a class="external" href="https://www.first.org/cvss/v4.0/user-guide">scoring guide</a> contained answers to all of my questions. Nice. My CVSS vector for CVE-2026-46529 is CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N, the base score is 8.4, and I’m pretty sure my choices for each parameter are good. By comparison, using CVSS 3.1 I came up with CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H and base score 7.8.</p></div>
    </content>
    <updated>2026-05-21T20:49:51Z</updated>
    <published>2026-05-21T20:49:51Z</published>
    <category term="Fedora"/>
    <category term="GNOME"/>
    <category term="Security"/>
    <author>
      <name>Michael Catanzaro</name>
    </author>
    <source>
      <id>https://blogs.gnome.org/mcatanzaro</id>
      <link href="https://blogs.gnome.org/mcatanzaro/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://blogs.gnome.org/mcatanzaro" rel="alternate" type="text/html"/>
      <subtitle>On Fedora Workstation, GNOME, Epiphany, and WebKitGTK</subtitle>
      <title>Michael Catanzaro's Blog</title>
      <updated>2026-06-29T21:29:07Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://blogs.gnome.org/hughsie/?p=10038</id>
    <link href="https://blogs.gnome.org/hughsie/2026/05/20/lvfs-sponsorship-announcement-hp/" rel="alternate" type="text/html"/>
    <title>LVFS Sponsorship Announcement: HP</title>
    <summary type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml">Some more great news: Iâ€™m pleased to announce that HP has also agreed to be premier sponsor for the Linux Vendor Firmware Service (LVFS) as part of our sustainability effort. With the industry support from HP (and our existing sponsors of Lenovo, Dell, Framework, OSFF and of course Linux Foundation and Red Hat) we can … <a class="more-link" href="https://blogs.gnome.org/hughsie/2026/05/20/lvfs-sponsorship-announcement-hp/">Continue reading <span class="screen-reader-text">LVFS Sponsorship Announcement: HP</span></a></div>
    </summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Some more great news: Iâ€™m pleased to announce that <a class="external" href="https://www.hp.com/us-en/workstations/">HP</a> has also agreed to be premier sponsor for the <a class="external" href="https://fwupd.org/">Linux Vendor Firmware Service (LVFS)</a> as part of our <a class="external" href="https://docs.google.com/presentation/d/1l_Rmkn2-UwOkS0XK5d6u9pi29TZpmG-upa4Lu5HuEy4/edit?usp=sharing">sustainability effort</a>.</p>
<p><a href="https://blogs.gnome.org/hughsie/files/2026/05/Screenshot-From-2026-05-20-10-07-01.png"><img alt="list of vendors sponsoring the LVFS service" class="aligncenter size-large wp-image-10039" height="371" src="https://blogs.gnome.org/hughsie/files/2026/05/Screenshot-From-2026-05-20-10-07-01-1024x576.png" width="660"/></a></p>
<p>With the industry support from HP (and our existing sponsors of Lenovo, Dell, Framework, OSFF and of course  Linux Foundation and Red Hat) we can turbo-charge the growth of the LVFS even more. Thanks!</p></div>
    </content>
    <updated>2026-05-20T08:09:23Z</updated>
    <published>2026-05-20T08:09:23Z</published>
    <category term="Uncategorized"/>
    <author>
      <name>Richard Hughes</name>
    </author>
    <source>
      <id>https://blogs.gnome.org/hughsie</id>
      <link href="https://blogs.gnome.org/hughsie/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://blogs.gnome.org/hughsie" rel="alternate" type="text/html"/>
      <subtitle>Blog about geeky stuff</subtitle>
      <title>Technical Blog of Richard Hughes</title>
      <updated>2026-05-20T08:09:23Z</updated>
    </source>
  </entry>

  <entry xml:lang="fr-FR">
    <id>https://blog.kulakowski.fr/?p=37677</id>
    <link href="https://blog.kulakowski.fr/post/copyous-le-gestionnaire-de-presse-papiers-gnome-que-jattendais" rel="alternate" type="text/html"/>
    <title>Copyous : le gestionnaire de presse-papiers GNOME que j’attendais</title>
    <summary>À force d’utiliser des gestionnaires de presse-papiers au quotidien, difficile de revenir en arrière. Après GPaste puis CopyQ, j’ai découvert Copyous, une extension GNOME légère, rapide et parfaitement intégrée au bureau.</summary>
    <updated>2026-05-19T17:04:00Z</updated>
    <published>2026-05-19T17:04:00Z</published>
    <category term="Fedora"/>
    <category term="Linux"/>
    <category term="GNOME"/>
    <author>
      <name>Guillaume Kulakowski</name>
    </author>
    <source>
      <id>https://blog.kulakowski.fr</id>
      <logo>https://blog.kulakowski.fr/wp-content/uploads/2026/04/cropped-logo-32x32.png</logo>
      <link href="https://blog.kulakowski.fr/feed" rel="self" type="application/rss+xml"/>
      <link href="https://blog.kulakowski.fr" rel="alternate" type="text/html"/>
      <subtitle>Le journal d’un Directeur Conseil Expert en solutions digitales – API Management, DevOps &amp; Open Source.</subtitle>
      <title>Le journal de Guillaume Kulakowski</title>
      <updated>2026-06-26T12:37:25Z</updated>
    </source>
  </entry>

  <entry xml:lang="en-US">
    <id>https://gbenson.net/?p=1051</id>
    <link href="https://gbenson.net/docker-images-by-size-age/" rel="alternate" type="text/html"/>
    <title>Docker images by age or size</title>
    <summary>Files by age, newest first: ls -lt Docker images by age, newest first: docker images --format "{{.CreatedAt}}\t{{.Repository}}:{{.Tag}}" | sort -r Files by size, largest first: ls -lS Docker images by size, largest first: docker images --format "{{.Size}}\t{{.Repository}}:{{.Tag}}" | sort -rh Why why why??!</summary>
    <content type="xhtml"><div xmlns="http://www.w3.org/1999/xhtml"><p>Files by age, newest first:</p>
<pre>ls -lt</pre>
<p>Docker images by age, newest first:</p>
<pre style="font-size: 80%;">docker images --format "{{.CreatedAt}}\t{{.Repository}}:{{.Tag}}" | sort -r</pre>
<p>Files by size, largest first:</p>
<pre>ls -lS</pre>
<p>Docker images by size, largest first:</p>
<pre style="font-size: 80%;">docker images --format "{{.Size}}\t{{.Repository}}:{{.Tag}}" | sort -rh</pre>
<p>Why why why??!</p></div>
    </content>
    <updated>2026-05-19T10:58:35Z</updated>
    <published>2026-05-19T10:58:35Z</published>
    <category term="Docker"/>
    <category term="Snippets"/>
    <author>
      <name>gbenson</name>
    </author>
    <source>
      <id>https://gbenson.net</id>
      <logo>https://i0.wp.com/gbenson.net/wp-content/uploads/2020/02/cropped-20170615110709_glitch.jpg?fit=32%2C32&amp;ssl=1</logo>
      <link href="https://gbenson.net/feed/" rel="self" type="application/rss+xml"/>
      <link href="https://gbenson.net" rel="alternate" type="text/html"/>
      <title>gbenson.net</title>
      <updated>2026-06-18T11:42:48Z</updated>
    </source>
  </entry>
</feed>
