Unable to load image

More Linux kernel list drama. Torvalds says "Enough is enough"

https://lkml.org/lkml/2024/8/24/38

The maintainer for the bcachefs filesystem sends a last-minute patch into the upcoming 6.11 tree, claiming that its an important bug fix and it cannot wait to be merged into 6.12. Linus is not happy because the patch is quite large and it also seems to do more than a simple bugfix, adding risk of breaking things into a release that's almost ready to come out.

Here's a phoronix article giving a bit more explaination: https://www.phoronix.com/news/Linus-Torvalds-Bcachefs-Regrets

Some random people in the Phoronix thread fight each other, discussing if it was right for Linus to scold the maintainer like this: https://www.phoronix.com/forums/forum/software/general-linux-open-source/1487364-linus-torvalds-begins-expressing-regrets-merging-bcachefs/page17


On a related note, you might have also heard about bcachefs this week because the Debian maintainer for the bcachefs-tools dropped the package, citing that its way too difficult to package now due to Rust: https://jonathancarter.org/2024/08/29/orphaning-bcachefs-tools-in-debian/

46
Jump in the discussion.

No email address required.

But it's also madness for a distribution to vendor exact versions of all dependencies in every binary that we ship. The security story in nixos doesn't look fun: https://fosdem.org/2024/schedule/event/fosdem-2024-1983-remediating-thousands-of-untracked-security-vulnerabilities-in-nixpkgs/

I think that might be worth it to try to raise awareness on how a holistic security process should be supported in cargo.

Yikes, that talk contains some scary content, I didn't realise Nixos doesn't check uploads and that people can just include anything from Flatpacks to binaries from .debs (even non-free) in their Nixos packages! Sounds like they need something like Debian's ftpmaster team to review packages and a stronger packaging policy!

But Nixians I thought Nix was supposed to be so secure!!!

I found this a bit disturbing, but it seems that some Rust people have lots of confidence that if something builds, it will run fine. And at least it did build, and the resulting binaries did work, although I'm personally still not very comfortable or confident about this approach (perhaps that might change as I learn more about Rust).

Most uh Rusticans find it easier to do fizzbuzz in Rust then C++ and shill it based on that

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.