Transcripts

Untitled Linux Show 273 Transcript

Please be advised that this transcript is AI-generated and may not be word-for-word. Time codes refer to the approximate times in the ad-free version of the show.

Jonathan Bennett [00:00:00]:
This week we're headed to the Netherlands and talking about Shotcut and a new Spectre attack and a few other bits of security trivia. Then openSUSE Leap goes immutable and Fedora is boring, but in the best possible way. Oh, and Microsoft is making containers official on Windows with WSL. It's a lot going on. You don't wanna miss it. So stay tuned.

Jonathan Bennett [00:00:33]:
This is the Untitled Linux Show, episode 273, recorded Saturday, October 3rd: You Lost Me at Technically. Hey folks, it is Saturday and it's time for the Untitled Linux Show. That's where a few of us geeks get together and we talk about all things hardware and software, basically what's going on in the world of Linux for the week. And it is, of course, not just me. Today we've got Jeff and we've got Ken. Our other normal co-host, Rob, is off playing hookey. No, actually, he's getting old and he hurt himself.

Jonathan Bennett [00:01:07]:
And if you were a part of Club Twit, you could be in the Discord and you could find out exactly what's going on with him. He gave us a new medical term to go Google. But anyway, Ken has a new toy that came in. He probably wants to tell you about it, actually.

Jeff Massie [00:01:22]:
Ken, what do you got there?

Ken McDonald [00:01:23]:
This is a Dypix e-Book reader or e-reader. And now I'm out of focus.

Jonathan Bennett [00:01:31]:
It's an e-Book. It's an e-ink book. Does that make it an e-Book or an ink book? I'm not sure what that makes it.

Ken McDonald [00:01:39]:
It reads e-Books.

Jonathan Bennett [00:01:41]:
Yes, but it's got 2 screens on it.

Ken McDonald [00:01:44]:
It's an actual 2-page e-Book reader.

Jonathan Bennett [00:01:46]:
Yeah, yeah, yeah. It's got dual screens on it, which is cool. Now you bought this on like a Crowd Supply crowdfunder. Yeah, yeah. When did you buy it and when did it finally come in?

Ken McDonald [00:01:58]:
Uh, the credit card was charged back in January.

Jonathan Bennett [00:02:03]:
Oh, January of this year.

Ken McDonald [00:02:04]:
Holy cow.

Jonathan Bennett [00:02:06]:
It could be worse. I've heard, I've heard worse stories of things eventually finally coming in.

Ken McDonald [00:02:11]:
They were originally planning on shipping them in May. It finally got shipped yesterday is when the email said it shipped.

Jonathan Bennett [00:02:21]:
I mean, I'll be honest, 4 months late on a Kickstarter-style crowd supply crowdfunded thing. That's not bad.

Ken McDonald [00:02:28]:
And what's even better is I get the email today saying it shipped yesterday. And then I go out the front door and find it sitting there.

Jonathan Bennett [00:02:37]:
That's handy. Yeah, that is handy.

Jeff Massie [00:02:40]:
I'll say my comment was I didn't realize it was a Kickstarter. So it's like, oh, okay. That hang time now makes sense.

Jonathan Bennett [00:02:47]:
Yeah, that's what Crowd Supply is. It's another one of the— it's an alternative to Kickstarter. It's another crowdfunding place.

Ken McDonald [00:02:52]:
Now, they've actually put it out on GitHub so you can get the firmware and the instructions for building one yourself.

Jonathan Bennett [00:03:03]:
Cool.

Jeff Massie [00:03:03]:
Oh, nice.

Ken McDonald [00:03:04]:
If you're of that mind. If you're not, then you can go and see if they're going to be building any more to suit.

Jonathan Bennett [00:03:12]:
I am of the mind, but I do not have the time to do it myself for most things these days. I got, I have enough projects as it is. And I got another one added that I'm going to, thankfully, I'm fairly excited. And we'll talk about this at the end of the show. Fairly excited about a new project that I've got, but I've got a whole year to work on it. So I'm not pressed for time yet. Anyway, we'll tease that again at the end of the show. I'll tell you what exactly it is.

Jonathan Bennett [00:03:38]:
For right now, though, Ken, we've got a new release of Shotcut, one of the open source video editing programs. What is new in latest Shotcut?

Ken McDonald [00:03:50]:
Well, to find out what's new, I read the articles by Bobby Borisov and Marcus Nestor since they wrote about the latest version of the free and open source cross-platform platform video editor, editor Shotcut 26.9. Now Shotcut 26.9 improves the user interface's appearance by adding rounded corners in many places. It also introduces a new Shotcut logo. Audio enhancements include adding automatic audio ducking to the properties of an audio timeline track. Improved audio quality by removing a conversion to 16-bit integer and keeping the pipeline in 32-bit float, and changing Adjust Clip Gain for timeline clips to require Control+Alt to drag. This prevents inadvertent changes while selecting and dragging clips so that Option defaults back back on. Now, a tooltip was also added to the clip's audio line. Now, Shotcut 26.9 also improved timeline performance when moving clips to another track, zooming, and undoing many operations, and added Timeline Generate Adjustment Clip.

Ken McDonald [00:05:15]:
Now, this is a dummy video clip that contributes no video. Its filters apply to the composite of all video tracks below it. There is a lengthy list of general fixes and improvements under the hood, including upgrading to FFmpeg 9.0. And Johnny's— Jonathan, surprisingly, we haven't even covered FFmpeg's update to 9.0 yet. Now, I also found a security update that addresses flaws in Shotcut's network downloads. Now, more details and a link to Shotcut 26.9's Changelog can be found in Bobby and Marcus's article.

Jonathan Bennett [00:05:56]:
Yeah, you know, it is interesting. We haven't talked about the FFmpeg updates and some of the things that they've done for a while.

Ken McDonald [00:06:01]:
I think it's because it fell that week we didn't have— do an episode back in August.

Jonathan Bennett [00:06:07]:
Yeah, that could be. That could be exactly what it was. Yeah, you know, I need to go back and try Shotcut again. Every time one of these big— one of the big editors makes an update, I kind of like to go back and check it out. So far, I've stuck with Kdenlive for everything I need to do, but there's a couple of them that really call to me from time to time. It's like that. Yeah, that has some real potential.

Jeff Massie [00:06:28]:
You do much video editing?

Jonathan Bennett [00:06:30]:
With Floss Weekly. So the weeks that we have that. A little bit. Yeah. I don't do much editing on it, honestly. We pretty much go live to tape. The only edits are like at the very beginning. Well, so I record the intro at the very, very end, like the title and tease.

Jonathan Bennett [00:06:48]:
So I got to grab that, put it at the beginning, drop the music in, and then, um, cut out the, you know, the, the dead end at the beginning and the end. And that's, that's about it. So I do that in audio, then I do it again in video.

Jeff Massie [00:07:01]:
So a little bit. That's one of the things I've never, I've never really messed with that, so I don't, don't know much about it.

Jonathan Bennett [00:07:08]:
Yeah, uh, if I, if I remember correctly, Shotcut is the one that when I used it, I really liked it. But it had problems keeping up with the large video files that I was working with, like moving a 50 or 55-minute interview around on the timeline. It just really, it really sort of slowed to a crawl. I think it was Shotcut that had that problem. But other than that, I really liked it. So I'll have to go back in and try it with 26.9 and see if they've made that any better.

Ken McDonald [00:07:36]:
Have you ever tried OpenShot?

Jonathan Bennett [00:07:39]:
I have. OpenShot is a lot. It's a lot simpler, which, you know, for some things is great, but it was just a little too— I don't want to be mean, but it was a little too Fisher-Price for what I wanted.

Ken McDonald [00:07:53]:
You wanted something more along the lines of FFmpeg, this and that.

Jonathan Bennett [00:08:00]:
I want really either Kdenlive or Shotcut works pretty well.

Jeff Massie [00:08:07]:
He wants the Lego version, not the Duplo version.

Jonathan Bennett [00:08:11]:
Right, right.

Ken McDonald [00:08:12]:
Ah, just go straight to FFmpeg. Yeah.

Jonathan Bennett [00:08:15]:
Well, we are, uh, we're, we're going to be playing with, uh, Mindstorms or Technic to continue that particular analogy because Jeff has, Jeff has some security news to talk about and it's, uh, it's, it's pretty heavy duty stuff from what I understand. Jeff, what's, uh, what's new with, well, really with Spectre?

Jeff Massie [00:08:35]:
Well, if kind of looking back, back in January 2018, researchers revealed Spectre. And on their website, they explained the name, quote, the name is based on the root cause speculative execution. As it's not easy to fix, it will haunt us for quite some time. Well, it's October and the ghost is back and ready for Halloween. So on September 29th, researchers from the VUSEC group at Vrije Universiteit Amsterdam and Scuola Superiore Sant'Anna in Italy disclosed the new Spectre variant 2 attack called Branch Target Reuse, or BTR. The paper, the full paper, is going to be presented at the ACM CCS Security Conference in November. Now, a real quick refresher on speculation. Is when your CPU hits an indirect jump, basically a go to wherever the pointer says, it doesn't wait to find out where that is.

Jeff Massie [00:09:37]:
It guesses based on where that jump went last time, and it keeps those guesses in something called a branch target buffer. If the guess is wrong, the CPU throws the work away, but it leaves the old data in the cache that the attackers can read— the pointer data. That's the whole Spectre family in kind of one short summary. Now, the reason it does it is because it's most of the time it's probably correct and it causes a speedup for your processor. It, it, uh, gets, gets more performance out of the silicon. Now, the difference is what's new here involves JIT compilers, and JIT is just-in-time, and just like it sounds, it writes the machine code on the fly. You know, for example, Firefox does this for JavaScript, and the Linux kernel does it for the BPF, or Burley Packet Filter, which allows people to run sandbox programs in the kernel. Now here's the new angle.

Jeff Massie [00:10:36]:
The attacker loads a small BPF program and jumps into it so the CPU learns, oh, this jump goes there. Then the attacker deletes the program and loads a new one into the same memory. Now the code is gone, the original code's gone, but the CPU memory of the code, like the pointers, is not. So on the next jump, the CPU effectively follows the old guess, which now lands in the middle of the new program's instructions at an offset nobody intended. Well, other than the attacker. You know, the attacker built that new program so that read from the wrong starting point Its bytes become different instructions that leak data. Now, how fast is the data leakage? The exploit leaks about 8 bytes per second. You know, for comparison, a 56K dial-up modem moved about 7,000 bytes per second.

Jeff Massie [00:11:33]:
So this attack is roughly 875 times slower. But, you know, you might think, what good is that? But as the researchers put it, quote, that may sound slow, but with careful pointer chasing, we only need to leak a small amount of data to reach the secret. Now in the demo they have, they run, uh, root, su root, so the, the password hash is in memory, and then walk the kernel's process pointer list, process list, one pointer at a time till they find it. Now reporting on the research puts the whole thing around 3 minutes on an Intel Raptor Cove CPU and 5 on a Lion Cove. Now, before anybody freaks out and wants to run and unplug their computer, this is not remote. So the attacker has to already be running code on your machine. Now, in this case, for example, they got the hash but not the password. So it still has to be cracked.

Jeff Massie [00:12:41]:
And so this is not in this example, you know, the end of the world even then. But while the underlying CPU behavior showed up on every Intel, AMD, and ARM chip that the researchers tested, the complete exploit example was only built on Intel, but everybody has it. Now, here's the rub in the ointment. If you're thinking, I disabled unprivileged eBPF years ago, that's eBPF, Extended Berkeley Packet Filter. This exploit uses the classic BPF, the older, simpler version, which regular programs can and still use, you know, things like Um, seccomp, which is secure computing mode, uh, socket filters, Docket, and Chrome, for example, all rely on this. Now, the chip makers, you know, the AMD, Intel, the ARM makers said this basically was like, we already have the tools to fix this. So software, you need to fix your stuff. Use the tools we've already provided.

Jeff Massie [00:13:57]:
Now, one of those tools is IBPB, Indirect Branch Predictor Barrier, which is a command that tells the CPU to forget its branch guesses. So you use that, the kernel now flushes those predictions whenever it reuses BPF just-in-time memory. So when you just have that just-in-time compiler, Whenever it's going to, oh, I got to start this up again, it wipes everything out before it starts on the new code. Now, the fix is tracked in CVE-2026-64507 and 64508. And those CVE entries went up on July 25th, 2 months before the research even went public. Now, The fixes are in Linux 7.2 and newer, plus the stable kernel 7.1.4, 6.18.39, 6.12.97, 6.6.145, and 6.1.183. Now, if your kernel is at that or above the version for its series, you're covered. Now, the researcher's FAQ says, you know, Is my system affected? Their answer is most likely.

Jeff Massie [00:15:20]:
So while this is not a remote attack, update your kernel. You know, it's the smart thing to do, just in case. Now, the original Spectre team said it would haunt us for quite some time. And, you know, like I said, more than 8 years later, the ghost is still here and it's learned some new tricks. So. Happy October and happy coming Halloween.

Jonathan Bennett [00:15:44]:
Mm-hmm. Yeah, Spectre is real fascinating because it's all about things that you shouldn't be able to get to, making very, very subtle changes to the internals of the CPU, and then finding ways to be able to extract that information back out. And with all of the Spectre updates, essentially what they found with each of the new ones is a new way to sort of exfiltrate that information. And so, you know, it was, it was originally what, um, like buffered RAM inside the cache. And, you know, they've, they've found multiple, multiple different ways to get it. And then this one is, of course, you know, the branch prediction. Um, and the place, the place where it really, you know, it makes sense as a problem is if you have limited access to a computer But you can do, you can, you can pull the attack off and then that lets you get a lot more access to what's going on on the computer. It's also why it's suddenly, it's really interesting to have virtual machines that run encrypted RAM because they then potentially are safe from this sort of thing.

Jonathan Bennett [00:16:50]:
So a lot of, a lot of, yeah, it's interesting. The security stuff here is really interesting.

Jeff Massie [00:16:55]:
Yeah, it's, and it's, it really, this one does come down to a lot of software stuff of like, Just use the hardware makers, designers have fixed this as far as at least giving the tools to do it. And we just need to update our code to make sure we're taking advantage of those modern tools.

Ken McDonald [00:17:18]:
And while we're waiting for that code to be updated, just turn our systems off?

Jonathan Bennett [00:17:23]:
No, honestly, update your kernel.

Jeff Massie [00:17:25]:
It's already updated and the modern kernel is already fixed.

Jonathan Bennett [00:17:28]:
Yeah. And if you're just a desktop and you don't have something malicious already running on your computer, you have nothing to worry about. Now, if you're a server owner and you have a multi-tenancy server, well, then you may have something to worry about. But hopefully if you're that guy—

Ken McDonald [00:17:43]:
Assume you have something to worry about.

Jonathan Bennett [00:17:45]:
Well, if you're that guy, hopefully you're already installing updates pretty often automatically. And then you're already patched.

Jeff Massie [00:17:53]:
Yeah, because you're supporting multiple people. That's a whole different level of worry than, uh-oh, they're going to get into my Steam.

Ken McDonald [00:18:03]:
And that's where you need something like live patching.

Jeff Massie [00:18:05]:
My machine that plays Steam games.

Ken McDonald [00:18:08]:
Live patching.

Jonathan Bennett [00:18:10]:
Live patching could potentially fix this. I would have to go and look at the various live patch sources and see which one of them picks it up. But yeah, very possible. I'm going to stay on the security story. We've actually— I had a couple of links to 2 different security things that I want to talk about real quick. Uh, one is Cloudflare is building their own, um, certificate authority, which I looked at this and it kind of like, it makes so much sense. I was sort of surprised that they hadn't already done this. I kind of thought they had.

Jonathan Bennett [00:18:46]:
Uh, and so this is, this is essentially Cloudflare competing with Let's Encrypt. Um, essentially they are They're offering an alternative to Let's Encrypt, but using the same ACME protocol, which that ACME is the tool that lets you automatically go out and update a certificate. It has built into it multiple ways to prove that you are indeed the legitimate owner of a URL. And then it will give you the new certificate so that you can keep it up to date. And the question that you might have is, why? And I think a couple of reasons. One is, like I said, just to have an alternative out there. You know, it's usually not a good thing if something really, really important is only being served by one group. That, uh, that, that can go, that can go badly in various different ways.

Jonathan Bennett [00:19:39]:
Um, but it also lets Cloudflare roll out, um, quantum-resistant root. Uh, and I'm trying to remember the exact term, um, the technology that's used Merkle trees, I believe, is what it is. And I've not looked deeply into that yet to figure out how that works, but it is apparently a way to do quantum resistance inside of ACME and DNS without using quite the same overhead that you would normally get with a regular quantum-resistant kind of public-private key scheme. So they tend to be like the official solutions for quantum resistance, your, your Kyber and your Dilithium, they end up with really huge keys and really big handshakes. And, uh, they're, they're really sort of difficult to use on, on some systems in particular. Uh, so that is Cloudflare. And then the other thing security-wise that really caught my eye is that Zimbra, which is an open-source sort of email suite, uh, has been under attack. Um, there is a way to skip authorization in doing things.

Jonathan Bennett [00:20:53]:
And from what I can tell, it is an email. You send an email to us through a Zimbra server. And if they have SNMP notifications turned on, which SNMP, that's the Simple Network Management Protocol. That's a, it's kind of a binary protocol that lets you pull information from various network devices. So, you know, it's about, you can manage a switch over SNMP. You can, you I remember famously the CACTI program, which is a sort of a server management and monitoring system. It pulled almost all of its data over SNMP. So if you have SNMP notifications turned on, essentially what was happening is a specially crafted email would get interpreted in that layer in the wrong way.

Jonathan Bennett [00:21:40]:
And so some of the, some of the contents would become executables in one way or another. I don't know that the exact— I've not seen the precise, precise details of how this works, like no proof of concept that I have seen yet. But that is the basic idea that SMTP and SNMP does not go well, at least in that particular version of Zimbra. There is an update out already, 10.1.20 or later. And of course, there are resources to be found if you think you may have been exploited. Hopefully nobody here. But yeah, it's kind of sketchy running your own email server anyways. So just one more thing to worry about now.

Jeff Massie [00:22:28]:
Yeah. Kind of going back to that Cloudflare certificate authority, I wonder if they're going to enable certificates with longer life than Let's Encrypt?

Jonathan Bennett [00:22:41]:
I don't think so. And I think that the actual specs are moving towards very, very fast certificates. Like, I wanna say they're trying to get all of them down to 10 days now.

Jeff Massie [00:22:54]:
Yeah, see, and I'm kind of like with— I align with Steve Gibson on this of like, I don't know if that's really an advantage. I worry about it, but at least there's a second source if, you know, Let's Encrypt suddenly had a major catastrophe and they lost their servers and it was going to take them a few days to rebuild. It's— the internet's not shutting down, you know.

Jonathan Bennett [00:23:17]:
Yeah, I, I'm— I was looking to see if they have, um, if they have the number of days that things are valid for, and I don't see them in either of these articles.

Jeff Massie [00:23:29]:
But I think—

Ken McDonald [00:23:29]:
Last I heard is they were trying to get it down to 30 days?

Jonathan Bennett [00:23:33]:
No, see, 10 days, 10 days is the goal. And I think they changed it to 30. So if you get a certificate from Let's Encrypt now, it's only 30 days.

Jeff Massie [00:23:42]:
Rob is saying all certs will be 49 days by 2030.

Ken McDonald [00:23:47]:
Yes.

Jeff Massie [00:23:49]:
Because I know they backed off from what they originally were going to do and kind of drug it out a little more, but I—

Ken McDonald [00:23:55]:
Is that a thing yet? Because there were some servers that— service, either servers or services that you couldn't automate the certification update on. Yeah.

Jonathan Bennett [00:24:10]:
And that's, I mean, that's kind of the direction everything's going is you pretty much must automate that now. So what happened is the certificate revocation list and OCSP, were basically both failed experiments. And those were like the two ways that you could revoke a certificate. You know, if a certificate was lost in the wild, you know, your server got popped and somebody pulled the cert off, well, you suddenly have this untrusted cert. What do you do? CRL was supposed to be the answer for that, Certificate Revocation List. Because of the way it was implemented, most of the browsers weren't using it. And so basically everybody finally went, okay, fine, we're not going to do that anymore. And then, you know, if you have a certificate that lasts for 90 days and it gets popped halfway through it and you have no way to revoke it, we're all just in trouble.

Jonathan Bennett [00:25:02]:
And so the thing now that, that the powers that be are moving towards are very, very short certificate lifespans.

Jeff Massie [00:25:09]:
Except my understanding is that they, they went and fixed that. So they do The revocation now does work.

Jonathan Bennett [00:25:19]:
Is there an alternative to CRL?

Jeff Massie [00:25:24]:
I just remember Steve Gibson was talking about it because that was one of the things he was talking about. Why are they doing this? Because now revocation works. Because he had certificates he would invalidate and test all this stuff out. He said it was working on all the major browsers now.

Jonathan Bennett [00:25:39]:
That is news to me. That's possible. But, uh, I, I do— I remember this though, um, being part of the, part of the reasoning behind it. Um, I tell you what, it is time actually for a quick break. I will do just a little bit of homework during the break, and then we'll see if we can get an answer for that. So don't go anywhere, we'll be right back after this. All right, I have found the answer as to why OSCP in particular is going away. So there was the certificate revocation list that got replaced by OCSP.

Jonathan Bennett [00:26:16]:
And OCSP is a security nightmare because to check a certificate on OCSP, you have to reach out to a centralized server and say, here's the domain I'm going to. By nature of doing that, you also say, here's my IP address. please check whether it's revocated. And so then the person that you're talking to goes, hey, look, this IP address is going to this domain. And yeah, real problem for security. You have a lot of information away. And so Let's Encrypt actually themselves back in 2025 pulled the plug on their OCSP support. And basically what was left that wasn't a huge security, either a security problem or a privacy problem was making those certificates really, really short-lived.

Jonathan Bennett [00:27:07]:
And so that is, that is, that is the reason that we've gone in that direction. Wizardling in the chat says super short certs sucks. Yes, except once you get it automated, you don't have to care about it anymore. So just, just go, just go automate ACME and then you don't have to care anymore. I know there's a few little edge cases where you can't do that or it's a pain. But just go automate Acme and you'll be fine. That's what I hope.

Ken McDonald [00:27:36]:
You don't have an Acme that takes you past the expiration date.

Jonathan Bennett [00:27:41]:
What was that, Jeff?

Jeff Massie [00:27:43]:
Acme didn't work out so well for the coyote.

Jonathan Bennett [00:27:46]:
That's true. I've not seen that movie yet, but it looks really good. Is it out yet? Yeah.

Jeff Massie [00:27:51]:
I have seen it.

Jonathan Bennett [00:27:52]:
Maybe I'll sneak away from the kids at some point and my wife and I can go watch it. Anyway, let's take a look at openSUSE. And no surprise, Ken is the one that wants to talk about it. What is the new immutable openSUSE, Ken?

Ken McDonald [00:28:11]:
Well, it's not new immutable, but this week, Saurabh Rudra wrote about openSUSE deciding to ship an immutable Linux as a separate mode inside the main Leap installer. Ending the current separation of openSUSE's Linux distributions into 4 main ones. You have Leap. It's the stable fixed release option built on the same source as SUSE's Linux Enterprise. Then I do enjoy Tumbleweed, which is the rolling release for those who want the latest packages. There's also been MicroOS. It's the immutable rolling variant that tracks Tumbleweed And then there's Leap Micro, the immutable fixed release counterpart to Leap, built for container hosts, edge devices, and virtual machine workloads. Now with Leap version 16.1, the Gamma installer added an immutable mode option that you can toggle on during setup so that for all intents and purposes, Leap Micro is no longer needed.

Ken McDonald [00:29:28]:
Now, this is called the Leap Immutable option. Instead of Leap Micro, it will be configured with a read-only root file system, transactional updates, and snapshot-based rollback. The technical foundation is identical to what Leap Micro offered. The difference is that it now lives inside Leap rather than alongside it. According to Surov, Leap 16.1 also includes a range of upgrades, including KDE Plasma 6.6 with OCR support and Spectacle and accessibility upgrades, as well as GNOME 48 with HDR support and the new default audio player. For more details, I do recommend reading Surov's article. Just don't fall down that rabbit hole.

Jonathan Bennett [00:30:24]:
I mean, that's always good advice, but which rabbit hole are we not falling down?

Ken McDonald [00:30:28]:
I kept digging deeper and deeper into this. I realized I wouldn't have time to talk about all of it.

Jonathan Bennett [00:30:37]:
So are you going to run Leap Micro somewhere?

Ken McDonald [00:30:41]:
Leap Micro? No. Tumbleweed? I've still got it in a virtual machine. VM that I now have set up so I can run it under either Ubuntu 26.04 or when I reboot into Arch, I can run it there also.

Jonathan Bennett [00:30:55]:
Nice. I mean, it makes sense. Now, can you reboot and leave it running?

Ken McDonald [00:31:01]:
No, that hasn't landed.

Jonathan Bennett [00:31:02]:
Not yet.

Ken McDonald [00:31:03]:
I'm waiting for that to come out. So I—

Jonathan Bennett [00:31:07]:
That would be cool.

Ken McDonald [00:31:09]:
That's going to be an interesting question because Omarcha uses a system reboot. My Ubuntu 26.04 is using GRUB.

Jonathan Bennett [00:31:22]:
I mean, it should be possible, I would think. I don't know. It really depends upon how badly you want to make it work. I'm sure if you want it badly enough, there is a way.

Ken McDonald [00:31:32]:
I'll probably try digging into it. I'm still trying to, uh, See if I can get it so it will automatically reboot into the last one I was in, unless I specifically change, like I could do with GRUB before. But it's always booting up into systemd boot first. So I'm having to sit there and wait and select the Ubuntu 26 option, which then basically goes to GRUB and then boots up the GRUB menu. Yeah.

Jonathan Bennett [00:32:03]:
Sounds about right.

Jeff Massie [00:32:05]:
The systemd boot isn't quite as multi-operating system friendly as GRUB. That's one of the reasons I still run GRUB is because it's, they say you can do it, but there's more tinkering. It's better for just, I have one distribution I'm loading into and then it takes it from there. But I do have a question for you, Ken. You talk about Tumbleweed quite a bit. Do you run it on any actual hardware or is it always in a virtual machine?

Ken McDonald [00:32:35]:
I was dual booting between it and Ubuntu 25.04, then 25.10. But when I set up 26.04, it took the place of Tumbleweed. But I still keep the VM so I can play around in there because it's safer sometimes for demonstrating stuff.

Jeff Massie [00:32:56]:
Makes sense.

Jonathan Bennett [00:33:00]:
All right. Let's talk Plasma, KDE. Jeff's got it. I looked at this story too. There's a few Plasma things going on. But yeah, and then in fact, I tagged one on the end here. So Jeff, you take it away and then we'll look at the one more thing from KDE this month. All right.

Jeff Massie [00:33:19]:
Well, you know, I decided to do this story because it's been about a month since we last talked about KDE 6.8. And, you know, I thought I'd give a little update and maybe a short little recap of the history for anybody that missed it the last time we talked about it. But on October 14th, 1996, a developer named Matthias Ettrich, I think that, yeah, Ettrich posted a message to the Usenet titled New Project, Cool Desktop Environment, KDE. The first time under the title Programmers Wanted. And a little further down, he wrote the quote, you know, and this has been repeated more than once. The X Window System is not a GUI. It's what its name says, a window system. Well, 30 years later, KDE is about to take this personal because on October 14th of this year, KDE's 30th birthday, the project will release Plasma 6.8.

Jeff Massie [00:34:17]:
And 6.8 is the first version with no X11 session at all. When you log in, Wayland is the only choice. So it's kind of a birthday party and a funeral on the same day at the same venue. You know, please, please bring a cake and a casket. Now, just a reminder for your X11 programs, they'll still run. They'll just use XWayland. So nothing's going to get broken there. Now, Nate Graham wrote in This Week in Plasma, KDE's developers looked at their bug tracker for the Plasma 6.8 beta and noticed something odd.

Jeff Massie [00:34:54]:
Not many regressions. Well, their conclusion is either Plasma 6.8 is amazing already or people aren't testing it enough. So consider this a public service announcement. KDE needs testers and you have until October 14th to go find some bugs, go on a bug hunt. Now, a quick timeline. The first Plasma 6.8 beta came out September 10th. And the second beta that we have going on now came out September 24th. And the final release, like I said, is going to be October 14th.

Jeff Massie [00:35:29]:
So at this point, the 6.8 branch is just in bug fixing mode. No new features. New features are already landing in Plasma 6.9. Well, okay, they need help, but what are you testing? Backups. KUP is a backup tool now officially part of Plasma with the goal of making automatic backups to an external disk simple. Screen recording. Spectacle can now include audio and screen recordings. And KDE says screencasting in general gets higher quality and lower latency.

Jeff Massie [00:36:03]:
Remote desktops. You get a 2-way clipboard syncing, better performance, and a new executive exclusive mode that locks the host machine screen when someone connects and gives them their own virtual screen, you know, to the remote user. So basically you're the only one using this machine. Triple buffering is now on by default for NVIDIA GPUs, and Steam windows now get shadows and rounded corners. On the HDR side, there's support for HDL, the HDR format used in broadcast TV, and nicer looking HDR when you're using a color profile. You're also testing accessibility and input. There's things like there's a built-in dwell clicker which clicks for you when you rest the pointer on one spot. So this would be for people that have, uh, some, you know, maybe hand mobility issues or something.

Jeff Massie [00:36:52]:
You just drive your mouse to the button you want to click on, let it sit there, and it will click on that button. Also coming, auto-start entries can be switched off without deleting them. So maybe you have something every once in a while you want to auto-start but not all the time. You can just toggle that. You can nudge your monitor— your monitors around pixel by pixel with the arrow keys and display settings. So sometimes you have monitors that, uh, you kind of have to correct the graphics on a little bit because it shifts it one way or another. You know, you're fighting some helping software in the monitor. KDE promises faster load times for the Plasma shell, less memory used in several widgets, and a leaner Discover when it checks for updates.

Jeff Massie [00:37:41]:
One thing they really are really begging you to try is Union. You know, that's the new theming engine. We've talked about it a couple of times in the past. It has already styled KDE's newer Qt Quick apps. And, you know, in 6.8 now, it can style the classic Qt Widgets apps too, like Dolphin and Kate, with a goal of making them look as close as possible, like, to the regular Breeze. Now, they do say, bear in mind, this support is preliminary and you will probably encounter bugs, you know, and that's why it's off by default. So, To try it, you have to install the Union package, then go to System Settings, Colors and Themes, Application Style, and pick Breeze Union. And then if something looks off, compare it against the regular Breeze and report anything that only breaks with Union.

Jeff Massie [00:38:34]:
So if something's broken in the normal Breeze and something's broken in the Union, they don't want to know about that. They want to know the differences between the standard Breeze and the Union Breeze. So please go and test because right now KDE can't tell if Plasma 6.8 is amazing or if nobody's looking. Take a look at the articles linked in the show notes for many more details. And let's see if we can find out a little more information before October 14th.

Jonathan Bennett [00:39:05]:
Yeah, yeah. Good stuff to test. A lot of interesting new things landed there. And yeah, always excited to see the fixes. There is one more interesting thing that KDE is looking at, the guys there, and that is KDE Linux. We talked about this a bit, and I've sort of asked the question of why. And it seems like some of them are asking themselves a modified version of that same question. So there is KDE Linux built on top of Arch.

Jonathan Bennett [00:39:36]:
And there is KDE Linux built on top of Buildstream. And they have, they've talked about the Buildstream version of it being sort of a skunkworks project. Not doing very good at skunkworks if everybody knows about it, but I digress. They're now looking at it and saying, do we continue on with this and make this the official KDE Linux, or is it not worth it? Is the juice not worth the squeeze? And do we then go back to just the Arch-based KDE Linux? And it really boils down to, you know, it's nice to be able to control all of this. It's nice to not have to worry about Arch breaking things for us. But on the other hand, it is extra work to have your own distro. Really? And so there's a Phoronix article that goes off to another blog post from Nate Graham, of course. And so some interesting stuff there as well.

Jonathan Bennett [00:40:41]:
And he is also asking for people to help test. Not a huge surprise. So there you go.

Jeff Massie [00:40:48]:
Well, and I'll give you a little more background information too, because people might be thinking, well, what about KDE Neon? Well, This is one of the reasons they're going through basically having their own distribution because KDE Neon, while being a distribution, was based off Ubuntu LTS updates. And too many times with the revision of software and the speed that KDE's moving along, they'd have to update kernels, they'd have to update other core libraries. And then they start really having to go in and modify the existing LTS because the support isn't there. It updated way too slowly. So they were kind of like, okay, we've got to be able to upgrade the underpinnings at a much faster rate. So they said, okay, let's just have the KDE distribution.

Jonathan Bennett [00:41:38]:
Yeah, I remember trying KDE Neon a few times and it just being completely broken because of that. The kernel leadership was way too old because they were using the LTS.

Jeff Massie [00:41:45]:
Yeah. And some of that might— and the kernel actually isn't that bad to upgrade. I've had rough experiences with KDE Neon as well. And they tell you that KDE Neon is not built as an everyday distribution. It is for people developing on KDE. So this is not a user-friendly, you know, beginner-friendly distribution. But the kernel isn't so bad, even though like now, Canonical is updating Ubuntu's kernel much faster in the LTS. A lot of times it's the underlying other core libraries that tie into so many things.

Jeff Massie [00:42:23]:
You say, okay, we're going to update this core library. Uh-oh, now that affects this other thing and affects this other, you know, and then you start updating dependencies of dependencies trying to make this all work right.

Jonathan Bennett [00:42:36]:
Yep. And suddenly, suddenly you find yourself spinning a whole new distro. Yeah.

Ken McDonald [00:42:41]:
But just one quick question. What's the difference between Arch and Buildstream?

Jonathan Bennett [00:42:47]:
Going to be similar. Arch is the up— Arch is a distro that, you know, the maintainers of Arch make the decisions about when things go out. Arch is a pretty rolling release, if I understand correctly. Whereas with Buildstream, they basically say, okay, we want this package and this package and this package. What I don't remember is whether Arch uses Buildstream itself. But either way, it's going to be a pretty similar environment. Like the 2 distros are going to be pretty similar. It just boils down to we're not reliant on the decision that the Arch guys make.

Jonathan Bennett [00:43:25]:
And now everyone's—

Jeff Massie [00:43:26]:
If you can trust AI, it says no, Arch does not use Buildstream.

Jonathan Bennett [00:43:31]:
Okay. So Buildstream is an alternative to the way other distros are built.

Ken McDonald [00:43:36]:
What does Arch use?

Jonathan Bennett [00:43:40]:
Probably packages built by hand by humans knowing Arch.

Jeff Massie [00:43:48]:
Yeah, they, yeah, it looks like they don't have, yeah, they just put them together like a regular distribution. I mean, they have automated builders and whatnot, but it's not BuildStream.

Jonathan Bennett [00:44:03]:
Yeah, I'm not sure what tooling Arch uses to do all of that stuff.

Ken McDonald [00:44:09]:
Is it Yocto?

Jonathan Bennett [00:44:11]:
No, I don't think so. Yocto Linux, that's kind of its own thing for embedded, if I remember correctly.

Ken McDonald [00:44:20]:
From trying to do some research, it looks like Buildstream is currently being stewarded by the Apache Foundation.

Jonathan Bennett [00:44:27]:
A lot of things end up in Apache. I think Apache actually works as a fiscal host for a lot of these programs, and that's why they're sort of part of the Apache conglomerate, as it were.

Jeff Massie [00:44:39]:
So, I mean, they do use PackageBuild.

Jonathan Bennett [00:44:43]:
Yeah, maybe that may be the answer that Ken was actually looking for. I mean, that's the name of their tooling, probably. So we are actually going to take one more quick break, not our last break. It's actually only our second break, but we're going to come back and we're going to talk about something boring. Something boring. Don't go anywhere. It'll be exciting. We'll get to it right after this.

Jonathan Bennett [00:45:04]:
So when it comes to boring, it is hard to get more on the nose than these set of benchmarks from Fedora 45 beta. And yes, 45 is now in beta. And so if you're real adventurous, you can just go out and grab it and run it. I'm sort of tempted to on at least a couple of my machines here. But Michael Erbil over at Phoronix, took the 45 beta and decided to run some benchmarks against it. And in his own words, the results were boring, but boring in the best possible way. There's no big wins, no big losses. It's sort of just another Fedora.

Jonathan Bennett [00:45:46]:
There are some updates in there, but the performance is pretty— it's pretty much the same from 44 to 45. The Probably the biggest thing that actually showed up in his testing was that Python does indeed have a bump. It goes to, I think, 3.15, if I remember correctly, is the new Python version. And yes, it's going from 3.14 to 3.15. And so the few little bumps that you saw is pretty much from that. And other than that, it just works. And so that's the reason why, like I said, it's boring, but sometimes you want things to be boring. So 45 beta is out if you want to give it a try.

Jonathan Bennett [00:46:29]:
And it just works. It's boring. And then there's something else about Fedora 45 that I came across this week. And that is that Fedora 45 is going to be much better, we hope, on Snapdragon X1 laptops. Now, you probably remember that Snapdragon laptops were all the rage back earlier in the year. And then you kind of just stopped hearing anything about them. And well, one of the reasons was the OSs weren't ready. The Snapdragon support was not there.

Jonathan Bennett [00:47:02]:
It was too hard to do the installs. People really didn't want it. Well, Qualcomm, which is one of the companies behind the Snapdragon, hired Hans de Goode away from Red Hat. And he was a Linux laptop expert. Still is, it turns out, a Linux laptop expert because he has been working on the Fedora Linux experience for Qualcomm Snapdragons. And he's got a blog post out where he talks about both the X1 experience and also the Snapdragon X2 support that is starting to land in the mainstream kernel as well. And so if you, if you were one of the folks that ran out and got a Snapdragon X1 laptop, Fedora 45 may be the Finally, the distro to try it out on, get a good experience. And if you're excited about X2, well, that's coming as well.

Jonathan Bennett [00:47:58]:
I gotta admit, this is not something that I got terribly excited about. I mean, I like that it's there and I like that it works, but if I want an ARM laptop, I'm gonna go with my Raspberry Pi CM5-powered laptop. And if I want a more powerful laptop than that, I will just go with something that's you know, AMD or Intel. But it is cool that it works.

Ken McDonald [00:48:21]:
So do you run Fedora 45 on your Raspberry Pi laptop?

Jonathan Bennett [00:48:27]:
No, on the Pi, I tend to run Raspberry Pi OS. It's just things tend to work better there. But you can run Fedora on the Raspberry Pi. Now on that particular laptop, I bet there would have to be some workarounds just because it's a little bit different than your normal Raspberry Pi hardware.

Ken McDonald [00:48:46]:
And your normal laptop.

Jonathan Bennett [00:48:49]:
I mean, it's pretty typical for a laptop actually in some ways, in some ways. But yeah, it's an experience. Someone says there's SnapM coming for Fedora 45. I don't actually know what that is. Let's see if we can find out real quick. SnapM, ButterFS full system snapshots. So yeah, that is another change that is interesting. Let's see if they've targeted release Fedora 45 scope.

Jonathan Bennett [00:49:26]:
Yeah, this page does not specify whether or not. Looks like it got accepted. And as far as I can tell, it's on track. So ButterFS snapshots in Fedora, that'll be cool.

Ken McDonald [00:49:40]:
So after you get Fedora 45 out, then Red Hat's going to be looking at coming out with a certified enterprise edition for Snapdragon laptops?

Jonathan Bennett [00:49:51]:
Maybe at some point.

Ken McDonald [00:49:53]:
I don't know.

Jonathan Bennett [00:49:56]:
Let's see. RHEL 9 is out, I believe. RHEL 10 is out, so we would be looking at RHEL 11 for the next one, and I'm not sure where that would land. Fedora 34, 40, so Fedora 46 is probably going to become RHEL 11. And yeah, so not, not, not the version that's in beta now, but the one after that is, is probably going to become RHEL 11, assuming that, you know, IBM is around long enough to make a Red Hat 11. Probably a safe assumption. But yeah, interesting stuff. All right.

Jonathan Bennett [00:50:44]:
What is next? Let's see. Ken, speaking of Red Hat, AlmaLinux has some news. What's up here?

Ken McDonald [00:50:53]:
Well, again, we can thank Saurabh Redro for writing about a way to carry out software and hardware certification on AlmaLinux with test results from either certification path landing in the same public catalog. You don't even need to worry about validation costs or machine— excuse me— machine uptime because the certifications are free and the hardware checks no longer require you to install the distro on your setup. According to Surov, software certification is basically a listing plus the confirmations that follow it. A publisher adds the product and picks which major versions of AlmaLinux it runs on. Now, any community member or AlmaLinux user can sign into catalog.almanlinux.org and confirm that a product works on the release you're running. The other half is hardware certification. Done with a recently rewritten Alma-certify tool. Developers now claim it can achieve sub-10-minute certification runs on most hardware.

Ken McDonald [00:52:07]:
It can also now work off live media or from an installation already on the machine instead of requiring an AlmaLinux installation. The new machine registration flow also uses QR codes. The Alma Certified Tool records what's on the machine down to drivers and firmware, then runs a bunch of short checks to decide whether it passes. If you run a data center when you deploy your new servers, making this part of your deployment using the QR code to register would be a huge help. The suite also takes a normalized inventory of a machine. covering CPUs, memory, disks, network cards, GPUs, firmware, and driver versions. Everything ends up in the catalog, and each entry is a result anyone can analyze. The catalog includes the systems, components, and software that have been validated, along with benchmark figures from the published test runs.

Ken McDonald [00:53:13]:
Now, Jonathan Wright, the infrastructure lead for Amalynx, states 2 things would make all of this worth it. A lot of people and organizations want proof that AlmaLinux runs on the hardware they already own before they'll give it a try. And now they can get that proof themselves. Every result that gets submitted makes the case to hardware and software vendors that supporting AlmaLinux is officially is a low effort. effort way to do— excuse me, a low-effort thing to do. So if you have hardware sitting in front of you or software you rely on every day, go tell us that it works. Validation stacks— so adding yours to something already listed helps just as much as being the first. Now, I personally recommend reading Saurabh's article for more details.

Ken McDonald [00:54:10]:
And his opinions on asking users to help certify compatibility.

Jonathan Bennett [00:54:17]:
I mean, this is cool that they give their tooling to everybody to let you test it. That's actually really cool. The fact that it only runs for 10 minutes, I have questions about. I would expect certification to last a little bit longer than that. Some of the bugs I've run into, some of the incompatibilities on hardware, you have to let something soak for months before it finally shows Well, on this one, I went down the rabbit hole a little way as well.

Ken McDonald [00:54:46]:
And it sounds like you can choose what it does. Basically, the sub-10 minutes is where it's just going through and basically identifying your hardware.

Jonathan Bennett [00:54:57]:
I was going to say 10 minutes is about enough time to say it booted.

Ken McDonald [00:55:01]:
It booted. Here's what all the hardware is and provide that list up.

Jonathan Bennett [00:55:05]:
Yeah.

Ken McDonald [00:55:06]:
And then you can go in and select the actual tests that you won't run, which would probably, depending on how many tests you should put you at 3 hours.

Jonathan Bennett [00:55:18]:
That sounds a little bit closer. There's also ARM64 support for this particular tool, which is cool to see as well. I kind of want ARM64 to be a thing in the server space. I don't know if it is yet. It's getting closer and closer.

Ken McDonald [00:55:38]:
Yeah.

Jeff Massie [00:55:39]:
Why do you want it? Just power efficiency?

Jonathan Bennett [00:55:44]:
Because it's cool. It's cool to have something other than just x86-64. So the competition and the novelty factor, I suppose. I'm not claiming that that is a sophisticated reason for wanting something to happen, but it's my reason. So.

Jeff Massie [00:56:00]:
At least last I knew it in the server area, it was the brute force was lacking in the ARM.

Jonathan Bennett [00:56:07]:
Yeah. And I suspect that there are actually some ARM, some big ARM deployments. They're just very private or, you know, custom hardware.

Jeff Massie [00:56:17]:
Specialized cases that—

Jonathan Bennett [00:56:19]:
Yeah. I think Google has quite a bit of ARM hardware rolled out and I would not be surprised if like Amazon does as well. Some of those folks.

Ken McDonald [00:56:27]:
They're quietly using for themselves.

Jonathan Bennett [00:56:31]:
Right. Yep, absolutely.

Jeff Massie [00:56:33]:
Well, and honestly, when you design hardware for yourself, then you don't have to worry about weird use cases with somebody plugging in. You go, we're gonna have this CPU with this exact hardware config, we design it to work with this, and we don't worry about anything else.

Jonathan Bennett [00:56:48]:
And you can give the guys writing the software a copy of the hardware and like, your software is going to run on this, make sure it doesn't do anything weird.

Jeff Massie [00:56:54]:
Yeah.

Jonathan Bennett [00:56:56]:
Yeah, it works out really well.

Ken McDonald [00:56:58]:
But I think this will be very handy, primarily for all Linux to show. You just set up a boot disk, put it into a system, boot it up and let it run that. And yep, it'll run on this.

Jonathan Bennett [00:57:20]:
Yeah, absolutely.

Ken McDonald [00:57:21]:
And then you've got the catalog where you can go and see what software's been approved with that kind of configuration to run.

Jeff Massie [00:57:28]:
Mm-hmm.

Ken McDonald [00:57:31]:
Yeah.

Jonathan Bennett [00:57:31]:
No, I mean, it makes sense. Like I said, it's great that they share the tool and they make it available. And yeah, it'd be really interesting to see it roll out, people use it on various pieces of hardware. I'm kind of thinking about my hardware I've got access to and whether I'd want to run it on some of those. Is it like a full ISO? Are you running a copy of AlmaLinux or is it just a script that you run on whatever you've got?

Ken McDonald [00:57:54]:
Well, you do a live boot instead of actually install it. And then you could download it within that live boot and run it there.

Jonathan Bennett [00:58:05]:
Okay.

Ken McDonald [00:58:06]:
And then once you power off and pull it out, you're back to your original system. It's what I'm understanding.

Jonathan Bennett [00:58:13]:
Yeah, that makes sense.

Ken McDonald [00:58:15]:
What would be really handy, and I can see some people possibly doing a fork of that tool just for this reason, is use it for documenting your hardware and your network configuration.

Jonathan Bennett [00:58:30]:
Yeah, if you got a bunch of machines sitting around and you need to be able to collect all that data. Yeah, for sure. All right, we are going to take another quick break and then we're going to talk about— let's come back and talk about the Netherlands. Hey, I was just there. Anyway, we'll go over there.

Ken McDonald [00:58:46]:
Are you talking about it?

Jonathan Bennett [00:58:47]:
I'm not. Jeff's going to talk about it.

Jeff Massie [00:58:49]:
I got it.

Jonathan Bennett [00:58:50]:
I'll fill in the blanks that he misses because I was just there. Don't go anywhere. We'll be right back. All right, Jeff.

Jeff Massie [00:59:00]:
So this next story, let's take a little bit of a trip. Imagine you're the chief prosecutor of an international court. You show up for work and your email's gone. Quite an imaginary tale, right? Well, not really. In 2025, the Associated Press reported that's what happened to Karim Khan, chief prosecutor for the International Criminal Court in The Hague. That February, the US government had put a sanction on ICC officials and Khan lost access to his Microsoft email. Now, you know, Microsoft, you know, its president Brad Smith said later that the company's actions in no way included the termination of services to the ICC. The court itself kept running, but the sanctioned official was cut off.

Jeff Massie [00:59:52]:
And, you know, and in that same city, the Dutch government was taking notes. Well, now fast forward today, we have a project called DAWO, or pronounced DAWO, which is what I was told the Danish pronunciation is, which in English is roughly translated to a digitally autonomous workplace for government. It's being developed inside the Dutch Ministry of the Interior, and it's not just a desktop. It covers the whole stack, the operating system, office software, collaboration tools, cloud services, management tools, and even AI. On the collaboration side, there's a companion bundle called Minge Bureau, which pulls together Nextcloud, Collabora, Element, and OpenProject. The operating system underneath all that, NixOS. Now, core developer Victor Greaves summed up the motivation, you know, basically referring back to when they lost email. At that point, the Dutch government realized that access to many essential services depended on US policy.

Jeff Massie [01:01:05]:
So that, that losing the email had major ripples for the, for the Danes. The project's own website was even more blunt. It says Dutch government is so dependent on non-European technologies that it's vulnerable to outside disruption of critical systems, loss of control over government data, losing the know-how to run its own systems, and espionage. Now, NixOS, you might be saying, why that one? Well, the team said they tried openSUSE first and then Fedora before settling on NixOS. Now, 2 reasons stand out. First, sovereignty. The easy one to look at is Fedora, which is backed by Red Hat, which is owned by IBM. Which IBM is pretty solid for being known as a US company.

Jeff Massie [01:01:57]:
So it kind of almost maybe not the bad reputation is like Microsoft, but it's firmly US. openSUSE is backed by SUSE. Well, and while the team didn't cite this, you know, they officially cited that SUSE was, it's owned by a commercial entity and yeah, it's European, but it's They didn't like the commercial part of it. But it is also worth noting that earlier this year, Reuters reported that SEUSA's private equity owner, EQT, was exploring the sale of the company for up to $6 billion. Not the ideal situation for a sovereignty project because who's going to buy it? You don't know. So NixOS, on the other hand, isn't tied to a commercial vendor. And the foundation that it's based on is based in the Netherlands. NixOS—

Jonathan Bennett [01:02:58]:
That's convenient.

Jeff Massie [01:02:59]:
Yes, that is convenient. And NixOS even started as a research project at Utrecht University. So, you know, as somebody said, it's hard to get more Dutch than that without adding a bicycle.

Jonathan Bennett [01:03:16]:
So we can confirm.

Jeff Massie [01:03:18]:
Yeah. So with NixOS, your whole system is defined in configuration files. So a person organ— so one organization can handle its setup, hand its setup to another. You know, it's just, here's the config files and there you go. You have an identical system. Developer Rotter Putter told The Next Web, 80 to 90% of your Nix code is reusable. So it's, it's basically that it's, it works great for large entities that need standardized systems. Now, it has been said that open source doesn't cost less, it costs differently.

Jeff Massie [01:04:07]:
And Putter made it clear the term is— they're being very pragmatic about all this. To quote, we're not hardliners. So they're taking a very open-minded stance at this whole thing. Now, if you're worried, you know, especially if you're in the Netherlands, if you're worried about civil servants editing config files, don't be. According to the Next Web Developer Bram Brujas, building a graphical— they built a graphical tool for managing NixOS so that Windows admins can switch without learning Linux commands first. So they make it very nice and point and click. So it, it makes the transition less painful than having to go in and say, oh, use vi and edit a config file. You know, point and click wins for the non-initiated, I guess.

Jeff Massie [01:04:59]:
So is this real or just a slide deck? Well, it's real, but it's early. So they have 8 municipalities which are testing it. And kind of a fun little detail, the pilots are all being run on older laptops the government had already written off because the machines can't run Windows 11. You know, because the TPM chip and all the, hey, this is good hardware. We can't run Windows 11. Well, now they're using those systems to run Linux and test out a switch off of Windows. A government directive in July made Dawo a formal mandate, and 3 of the government's own IT service providers were brought in to help build it out, you know, cover any gaps, things like that. Then the team hopes to ship version 1.0 sometime next year.

Jeff Massie [01:05:51]:
And the code now lives in Codeburg with backup copies on the government's own 4AO server. And yes, it's also on GitHub. So they're making sure they got redundancy if needed. One more little bit of data. It turns out that France was already doing this. France's digital agency has been building something called Securix since early 2025. And basically it's a hardened NixOS setup. So they're kind of, they're using the same thing built to the recommendations of ANSSI, A-N-S-S-I, which is France's cybersecurity agency.

Jeff Massie [01:06:32]:
So 2 European governments, 2 different projects, and both landed on the same distribution. Not because NixOS is easy, but because it's reproducible, auditable. And nobody can switch it off from across the Atlantic like other possible solutions. You know, turns out the best marketing NixOS ever got was a sanctions order. But, you know, if you want to know more, take a look at the articles linked in the show notes for a lot more information, a lot more depth. There's links into links and you can keep reading for a long time. But like I said, take a look at the show notes for much Further details.

Jonathan Bennett [01:07:16]:
Yeah, it's, it's definitely interesting to see. And, you know, I mean, good, good for them. Like, every country should be thinking about this. Um, there's, there's probably something to be said that parts of the US government should be thinking about its, uh, uh, beholdenness to Microsoft.

Jeff Massie [01:07:33]:
Well, and I think there's going to be a lot of trickle-over from, okay, Europe really gets on the Linux bandwagon. That's just that many more developers improving the software that's going to say, hey, well, you know, okay, I'm running not Nix. I'm running an Arch-type distribution, but there's going to be trickle over. And same way with Ubuntu and Fedora. And because we know, hey, it's a good idea. Let's bring it over here.

Jonathan Bennett [01:07:59]:
Absolutely.

Ken McDonald [01:08:00]:
Noticed in one of the articles, Saurabh implies that NixOS isn't actually a Linux distribution, but a foundation for building one on.

Jonathan Bennett [01:08:13]:
I mean, that's kind of maybe trying to cut that a little too thinly.

Jeff Massie [01:08:20]:
That's kind of like when someone says, well, technically, and that just means you can quit listening at that point.

Ken McDonald [01:08:27]:
That's like saying Kubuntu's built on Ubuntu. So Ubuntu's not a Linux distro.

Jonathan Bennett [01:08:36]:
Something like that.

Jeff Massie [01:08:39]:
Yeah.

Jonathan Bennett [01:08:40]:
You lost me at technically.

Jeff Massie [01:08:42]:
Yeah.

Jonathan Bennett [01:08:43]:
All right.

Ken McDonald [01:08:44]:
So there's a show title for you.

Jonathan Bennett [01:08:46]:
I thought about that. So there is actually some good news out of Microsoft. There's a reason that you might want to go and start using them. And that's because we now have WSL containers that are generally available. And you may ask yourself, what What is WSL Containers and how is it different from something like Docker? And I had to dig for a little bit to figure this out, but WSL Containers is compatible with the OCI container definition, which means that it will run Docker containers. And it is essentially a way to run them more natively without having to go and install Docker in Windows first, or without having to go and install a full Linux distro and install Docker there. You can just say, You can just tell WSLC to spin up a container and it will do all the magic behind the scenes and get you a containerized thing. Whatever thing that you have that you want to run, it will do.

Jonathan Bennett [01:09:48]:
Now, there is one particular gotcha for the moment. That is that WSLC, WSL containers, does not yet have Compose. And so you can't take a Docker Compose script and dump that into WSL containers. It doesn't know what to do with it yet, but the word on the street is that it's coming soon, that that is going to be a thing that happens. Microsoft is aware that that's something that needs to— in fact, it's spelled out right here on their blog post that that's one of the things coming up next is WSLC Compose. It's actually pretty interesting to be able to do this, and of course, it's going to be great for developers. It's also going to be really, really nice for being able to just run things on Windows. I mean, like, you can just have a— you can give a program out.

Jonathan Bennett [01:10:42]:
Now, not necessarily a GUI program, but a command line program that you need to be able to get to people. You can just give it to them as a Docker image and run this, and you're up and off to the races. So, I mean, it really is a pretty cool development. that this is now available right inside Windows. And the second link I've got is over at XDA Developers, and it's one of their developers that did WSL containers for a while, and his reason to leave them was that Compose wasn't there yet. So, you know, maybe it'll be time here in a few months to give it another shot. But yeah, Rob couldn't make it today, so I had to fill in and cover this story for him. I knew it's one that he would It's Microsoft.

Jeff Massie [01:11:27]:
He loves it.

Jonathan Bennett [01:11:27]:
Exactly.

Ken McDonald [01:11:29]:
It's his favorite. It's hard to tell sometimes if he loves it or loves to hate it.

Jonathan Bennett [01:11:38]:
Or just loves to troll about it. I don't know. It's all the same sometimes. It's all the same sometimes. WSL has been cool though. That's been one of the coolest things that Microsoft has done with Windows for a long time.

Jeff Massie [01:11:53]:
Well, I think they have to because of all the development that happens on Linux. They had to say, you know what, we kind of got to go swim in this direction because we're going to have problems otherwise. And the more problems there are going to be versus, okay, we just make this a little side compartment to Windows.

Ken McDonald [01:12:16]:
But when will we see a version of Windows where that side compartment is that cmd.exe with the main one being looking more like Linux.

Jonathan Bennett [01:12:30]:
When is Linux going to be the hypervisor and Windows going to be one of the guests? I don't know. I don't know if that'll ever happen. Actually, I think probably more honestly, the direction that they're going is they're running their own Microsoft-branded hypervisor. And then you just have Linux and Windows VMs and you have a Windows VM. So at the moment, the way that it works is you have a Windows VM that is your GUI that comes up. That's the way most Windows install works these days.

Jeff Massie [01:13:00]:
So I mean, I think you could imagine it going the other way. Well, I think, and I've been predicting this for a while now, this is still, I think, several years out, but I think they're going to go the way of macOS where you're going to run Linux and Windows is just a fancy little wrapper on top of it.

Ken McDonald [01:13:20]:
Or underneath.

Jeff Massie [01:13:21]:
Well, no, the Windows will be on— will be the wrapper. Linux will be underneath because as Windows really isn't the revenue stream that a lot of the other parts of the business are, why spend all this time writing code when you can Bolt Linux underneath, only have to worry about the GUI, and then they can take all those other developers, even AI resources that they've got coding, and throw that into the other projects that are making a lot more money.

Ken McDonald [01:13:54]:
I wonder how long it'll be before they license KDE to run under Windows.

Jonathan Bennett [01:14:00]:
I mean, it wouldn't be the first time that Microsoft has taken something open source and just bolted it in as part of Windows. I mean, that's where the Windows I think network stack came from. It was essentially lifted straight out of BSD.

Jeff Massie [01:14:12]:
It was something like that.

Ken McDonald [01:14:13]:
Yeah.

Jeff Massie [01:14:13]:
And you can run KDE on Windows now.

Jonathan Bennett [01:14:17]:
Inside WSL, yeah.

Jeff Massie [01:14:18]:
No, no, no. You can run it on top. They've got a— it's still really clunky, but you can run it on top of Windows.

Ken McDonald [01:14:28]:
Have it as a desktop manager.

Jeff Massie [01:14:31]:
Yeah.

Ken McDonald [01:14:33]:
Interesting.

Jonathan Bennett [01:14:33]:
I knew that worked for a while. I didn't think that was working anymore.

Jeff Massie [01:14:36]:
Oh, well, maybe it did break. And it was kind of always an experimental phase and wasn't exactly the smoothest, but there was a lot of work to do that.

Jonathan Bennett [01:14:46]:
I remember back in the Windows XP days getting a KDE installer for Windows. And that particular experiment didn't last very long. But I mean, you can definitely do it now with WSL. All right. Well, that is pretty much the news for the week. We've got some interesting tips. though, that we're going to get to here in just a moment. We're going to take our last break for the show, and then we will be right back.

Jonathan Bennett [01:15:10]:
So don't go anywhere. Okay, Ken is up first with a command line tip. Ken, you've got eval. What is this? What are we evaluating?

Ken McDonald [01:15:20]:
Well, this week, I'm going to explain the eval command that I mentioned last week when I was talking about setting up Zoxide. With a command, the eval command in my .bashrc file. First thing to understand is that the eval command in Bash is a built-in shell instruction. What basically it forces the shell to process your command twice instead of just once by telling Bash, take this string of text, parse it exactly as if I had typed it directly into the terminal right now. and then execute it. Now, normally bash will treat any variable as regular literal text, but with the eval, what you're telling it is it's not literal text, it contains commands that we're going to dynamically change. In fact, let me go ahead and give you an example of what I'm talking about here. Let's take, for example, let's say I create a variable And, uh, for those of y'all listening, I've just brought up my terminal and I'm going to create the variable my_command and I'm going to set it to equal ls -l piped to grep text.

Ken McDonald [01:16:46]:
Now with that, of course, we can do an echo And Mike_command. And that's going to print that out. But what eval will do is it evaluates the— that command. Well, actually, first let me go ahead and demonstrate for those of y'all listening what happens if I just use the variable mycommand right on the command line itself. I'm sure Jonathan knows what's going to happen, but it will try to run the command ls, and it treats everything after it as if it were, uh, the name of a file or directory. And of course, with the pipe, you end up getting cannot access. Now, if I go back and put eval in front of it, it tells the bash script to evaluate that command and then to go back again and look for any pipes. Basically, you're parsing the command twice.

Ken McDonald [01:18:10]:
Huh.

Jonathan Bennett [01:18:13]:
That's actually really interesting.

Ken McDonald [01:18:16]:
Now, where it comes in handy, if you ever use the SSH agent with a -s. Now, without the eval, what that would do is it just print everything that SSH agent -s would put out to the screen, which is, uh, it sets up the SSH SOCK variable and the SSH agent PID variables. Basically, it would give you what you would put in a script But by using the eval, it actually does it right there and then so that you're exporting those straight to it. And you see it even does, does the echo agent ID and PID. And you notice that the PID changed between the 2 times I did it with the eval today.

Jonathan Bennett [01:19:28]:
Yeah.

Ken McDonald [01:19:29]:
Now here's an interesting one that Somebody, uh, scripting might want to take advantage of. Let's say, uh, we create 3 variables. One's called, uh, variable called command, uh, then word1 and word2. Now we can then assign those variables within another variable. Now, if we, uh, we can use echo to see what's in sentence. And what do you think it's going to say in sentence?

Jonathan Bennett [01:20:15]:
Uh, I would assume it's echo hello world.

Ken McDonald [01:20:18]:
Yeah. Now, what do you think evaluating sentence would do?

Jonathan Bennett [01:20:29]:
It's gonna, it's gonna run the echo command and give you the hello world output.

Ken McDonald [01:20:33]:
Right. Yeah. So if we go back up to the sentence variable and change it so that we reverse the word 1 and word 2, And then evaluate it again.

Jonathan Bennett [01:20:55]:
Does them backwards. Yeah, so it lets you, essentially this lets you build a script inside of an environment variable.

Ken McDonald [01:21:02]:
Yep. Now, it can also be evil.

Jonathan Bennett [01:21:08]:
I mean, it is kind of right there in the name.

Ken McDonald [01:21:11]:
So let, for example, let's say we Change the sentence. So instead of it being command to my command, what do you think is going to happen now?

Jonathan Bennett [01:21:43]:
It's going to do an ls and it's going to grep for text. Yeah.

Ken McDonald [01:21:51]:
Well, it didn't grep for text. It grep for world hello.

Jonathan Bennett [01:22:01]:
I think it grepped for text in world hello.

Jeff Massie [01:22:05]:
Right.

Jonathan Bennett [01:22:07]:
And it couldn't find that. So it was very confused. Can you stack them? Can you put an eval inside of the variable to be eval'd?

Ken McDonald [01:22:24]:
I mean, could I do this? You could do that. Now here's where it could be dangerous. Let's say you create— and you're going to see why, uh, I'm doing this— but I'll put, uh, the variable is called delete. And it equals echo, and then in single quotes, rm -rf backward slash twice. Now there's one big, big reason I went with the backward slash. There's no directories that start with it on my system.

Jonathan Bennett [01:23:20]:
There you go.

Ken McDonald [01:23:22]:
But if now, if I change the sentence, To equal just the delete, and I do the eval of sentence.

Jonathan Bennett [01:23:36]:
Is it going to run it?

Ken McDonald [01:23:38]:
Well, where's— what's the actual command going to be? The actual command in that is echo.

Jonathan Bennett [01:23:49]:
Right. Yeah, because you have it in single quotes instead of like backticks.

Jeff Massie [01:23:57]:
Mm-hmm.

Ken McDonald [01:23:57]:
And that was for 2 reasons.

Jonathan Bennett [01:24:02]:
Mainly because it gave you a second layer of defense of not removing, RMing your entire hard drive.

Ken McDonald [01:24:08]:
Right. Well, and you notice that it only had a single backtick or backslash.

Jonathan Bennett [01:24:15]:
Yeah, because that's the escape symbol. So the first backtick escaped the second one and said, no, no, I really do want a backtick, a backslash. In this string.

Ken McDonald [01:24:26]:
So here's another reason why you want to preview those install scripts that you're curling down.

Jonathan Bennett [01:24:37]:
True. It'd be very easy to hide that. Yeah, I guess eval is probably used in some of the obfuscation techniques, isn't it?

Ken McDonald [01:24:45]:
It could be.

Jonathan Bennett [01:24:46]:
Yeah, I've seen similar things in JavaScript before where, you know, you have a website that, you know, it has a JavaScript and it's like the equivalent of eval. And then it's got all this weird script. And in some cases, they build weird machines and, you know, they're like decrypting the commands right before they run them and all kinds of stuff to try to get around your antivirus.

Ken McDonald [01:25:09]:
eval, just like anything, is a tool. It can be used for good or evil.

Jeff Massie [01:25:16]:
Yep.

Jonathan Bennett [01:25:16]:
Yep. Absolutely.

Jeff Massie [01:25:18]:
I've used it for building commands kind of on the fly when you had different kinds of data that you had to process different ways.

Jonathan Bennett [01:25:26]:
Definitely makes sense.

Ken McDonald [01:25:28]:
A good example of that would be if you used FZF fuzzy find. You could use it to build a command to pull up from your history certain and use fuzzy find to interactively move back and forth until you found the command you wanted.

Jeff Massie [01:25:52]:
Now, I will say the last time I used it was on using Cornshell on an old Solaris machine. And the tools I had access to were very limited. So that was kind of one of the reasons I had to use it. It was kind of one of those I was programming around a limitation.

Ken McDonald [01:26:12]:
But yeah, it's one of those like every once in a great while, it's like, oh yeah, that would really And last week you saw where I used it for putting in the XOX loading XOX side with the instructions to use CD instead of its default of Z.

Jonathan Bennett [01:26:39]:
Yeah, yeah, pretty cool. All right, Jeff, you've got, you've got Tux—

Ken McDonald [01:26:45]:
Tux—

Jonathan Bennett [01:26:45]:
Tuxtool.

Jeff Massie [01:26:46]:
Tuxtool.

Jonathan Bennett [01:26:47]:
Tuxtool.

Jeff Massie [01:26:48]:
Well, this is not a command. It's a website, but it's a daily word puzzle where every answer comes from the Linux world. It's made by the site It's FOSS and Abhishek Prakash, who said, I made a Wordle-like puzzle game with Linux terms. So now, if you've played Wordle, you already know 90% of this. You get 6 guesses and the colored tiles tell you how close you are. A new puzzle drops every day at midnight UTC, you know, same moment for everyone on the planet, no time zones. You know, there's a sysadmin move. But there are some Linux-flavored twists.

Jeff Massie [01:27:34]:
First, the word length changes. So you just can't memorize one perfect starting word. Second, there's no dictionary check. You can type anything you want as a guess, real world or not. Third, every answer falls into one of 6 categories: Linux command, Linux application, Linux term, desktop environment, Linux distribution, or package manager. If you get stuck, there are 3 levels of hints. The first one tells you the category. The second one is a vague clue, and free players unlock those as they make their guesses.

Jeff Massie [01:28:13]:
The third, a direct clue, is a pro feature. Hints never show up in your shareable result grid, so nobody needs to know, you know, you needed help remembering how to spell Zipper, you know, i.e., the package manager, Z-Y-P-P-E-R. Uh, there's also stats and streaks and badges and all that other good stuff. Uh, when you get it done, each puzzle shows how everyone else did. So when I, when I checked today's puzzle, when I did it, number 19, uh, at the time 386 people had played it with a 95% solve rate. And it also shows a percentage of people who solved it at each guess. So you you saw, you know, X number at one guess, X number at 2, 3, all the way. Uh, the daily puzzle is free and you can play without an account.

Jeff Massie [01:29:08]:
Your progress just lives in your browser, so if you, if you move machines or something like that, it won't know your, your, uh, progress. Uh, there's also a pro tier. It's a one-time purchase and it can add an extra— it'll add an extra 7-letter bonus puzzle every Sunday. The second hint whenever you want it. And of course, you get that third direct hint and the ability to see the answer right away if you fail instead of stewing on it until the next day. Now, they do talk about when you have an account, you know, they send you a magic link and then you can keep track of your progress across many machines that way. So if you want to see Tuxdle, it's at tuxdle.com. That's T-U-X-D-L-E dot com.

Jeff Massie [01:29:59]:
You know, takes a couple minutes a day and runs in any browser. And, you know, might be the only word game where knowing what fstab means is a competitive advantage. So happy playing.

Jonathan Bennett [01:30:14]:
Ah, yes. I am indeed playing it. And I had to go for the second clue. And then I went, oh, I know exactly what that is.

Ken McDonald [01:30:25]:
Xorg.

Jeff Massie [01:30:25]:
I—

Jonathan Bennett [01:30:26]:
Ken, Ken, you just, you, you, you ruined it for everybody else. Uh, yes, that was it.

Jeff Massie [01:30:35]:
Yeah, see, I, I, I guessed a command. It gave me 2 letters. I guessed the sister, uh, to the answer. And then based on the letters I got, I got the answer on the 3rd try.

Jonathan Bennett [01:30:52]:
Oh, it took me until the last try.

Ken McDonald [01:30:55]:
Uh, same here, because I kept thinking commands.

Jonathan Bennett [01:30:59]:
Yeah, apparently commands is its own category, so it wasn't going to be a command.

Jeff Massie [01:31:02]:
Yeah, I did, I did, I put the first one, the first answer down. It was wrong. It did give me a couple letters. And then I looked at the first hint, it told me the category, and then I was good from there.

Jonathan Bennett [01:31:18]:
Nice. I'll just remember this. This will be fun.

Jeff Massie [01:31:20]:
Yeah, it's a fun little thing. All right.

Jonathan Bennett [01:31:26]:
I've got a cool command line tip. I didn't end up needing it, but I thought I needed it. And so went on a search. And found an old friend with a new trick. And this is SHWIM, which is Shell With Me. And it is actually a part of the Magic Wormhole project. We've talked about Magic Wormhole before. That is the ability to drop a file from anywhere to anywhere.

Jonathan Bennett [01:31:57]:
And it just sort of magically works using sort of any 3 words kind of system. And I had that in the back of my mind. I had a server that was behind a firewall. And I was like, I can get to this via VirtManager. But with VirtManager, you can't copy and paste text into and out of. It's like, I want to be able to paste text into this and copy log lines out. And I was sort of stuck not being able to do that. And I had the thought, well, surely there's something that does this without me having to jump through the hoops of packet forwarding and all that.

Jonathan Bennett [01:32:31]:
So I went searching and I found Schwim and it does exactly that. You run it on one machine and it gives you a magic code. You punch it on the other machine and it gives you the equivalent of SSH. Well, before I could actually set it up and use it, I remembered that I had a port forwarded already. And so I was able to log into this machine. But it's something that's going to be super useful for doing this sort of thing in the future. And I thought I would— I would give you guys a sneak peek at it, let you in on the secret here. So Schwem is, again, it's a way to do something like an SSH, but not have to worry about the networking stuff.

Jonathan Bennett [01:33:09]:
Just 2 machines are on the internet and this thing will connect the 2 of them together. So it is available through pip. So if you have pip installed, you can make Schwem happen. And so obviously you could do things like pipx and, oh, I forget the other, what's the other command that just Says this thing's on pip, download it and make it run. It's not pipx, but it's one of the other ones like it. Anyway, swim, it's, it's a part of Magic Wormhole and a really useful little utility.

Jeff Massie [01:33:37]:
Nice. That's a, that's a good one to have in the back pocket.

Jonathan Bennett [01:33:39]:
Yeah, absolutely. And now I'm gonna have to go look and figure out what the, what the other one was that I was thinking of. It's like pip. That's pipe. No, nope, nope, nope. There's a bunch of pwcli stuff in here. Who was talking about that for so long?

Ken McDonald [01:34:03]:
Hmm.

Jonathan Bennett [01:34:03]:
All this PipeWire stuff, I don't remember what it's called. There's another utility that's like pipx that just says, go get this thing off of pip and download and run it. Just make it work. Anyway, I'll come up with that later because that one was useful too. I actually kind of want to remember what that is because I want to be able to use it. Well, that's the show. That's it. I will look up this command on my own time rather than make you guys wait for me to do it.

Jonathan Bennett [01:34:29]:
I will let the guys plug whatever they want to, and I've got something to plug too. We'll let Ken go first. Ken, what do you have to end the show with? Ken is muted.

Ken McDonald [01:34:44]:
And now I'm not.

Jonathan Bennett [01:34:46]:
There you go.

Ken McDonald [01:34:47]:
I just wanted to share with everybody. I've got a link in the show notes to an article by Bobby Borisov that reminded me that we can now upgrade Ubuntu 24.04 to Ubuntu 26.04 if you still have a Ubuntu systems running with 24.04 on it.

Jonathan Bennett [01:35:12]:
Very cool. The command I was thinking of was uv. uv will let you run something right away. All right, Jeff, you got something you want to plug?

Jeff Massie [01:35:21]:
I have 2 things. One is I ran across a bug recently. So if you have an NVIDIA card and you're on the beta driver 615.71.09, And you notice if you have a KVM that you switch to whatever machine and then you switch back to your NVIDIA machine running the 615 driver and you cannot get the display back, that is a known bug. Now, they've got code that has been pushed for possible merge. I don't know if it's going to get accepted or not, but It's not just your machine. So if you see that it won't come back after you display switch on a KVM, that's why it's an official bug. And it's a known bug. The only other thing I have is a little bit of poetry.

Jeff Massie [01:36:15]:
Wi-Fi waves embrace, invisible threads unite. Now I scroll, still lost. Have a great week, everybody. Bye.

Jonathan Bennett [01:36:27]:
All right. Appreciate you guys. And then I got a couple of things that I want to plug. One of the first ones is a friend of ours, Jeff Geerling, announced the Homelab Fest coming next year, September 2027 in St. Louis. And I'm hoping to be there. In fact, I think Meshtastic is going to have a booth there. So that's going to be a lot of fun.

Jonathan Bennett [01:36:47]:
Put it on your calendars now. It's going to be a great time. And I'm pretty sure Jeff decided to do this. And then the response he got almost immediately was overwhelming. And I've I've heard a little bit behind the scenes and it's like the motel is selling out and he's— yeah, people are excited about it. So that is, that is one thing to keep in mind. And then also want to, of course, mention Hackaday and Floss Weekly. Took a couple of weeks off with my trip to Europe, but we should be back either this week or next week or, well, next week or the week after, I suppose.

Jonathan Bennett [01:37:17]:
So we're recording on a Saturday. But anyway, looking forward to that and make sure and keep an eye out. out over there. Other than that, just want to say thank you. Thank you to everybody that watches or listens, whether you get us live or on the download. And we will be back next week on the Untitled Linux Show. We'll see you then. Thank you.

All Transcripts posts