Transcripts

Untitled Linux Show 274 Transcript

Please be advised that this transcript is AI-generated and may not be word-for-word. Time codes refer to the approximate times in the ad-free version of the show.

Jonathan Bennett [00:00:00]:
This week we're talking about ArtCraft and the rest of the fake vibe-coded reverse-engineered, we're not sure, but it looks a whole lot like the Adobe Suite. And then there's a whole lot more wrong with x.Org and yet more powerful tools to fix it. Ubuntu 26.10 has some questionable decisions about GRUB. We talk about some ARM news and the possible Raspberry Pi killer. Blender goes 5.3. And Cage is doing some really interesting things. interesting things in the Linux kernel. You don't want to miss it, so stay tuned.

Jonathan Bennett [00:00:46]:
This is The Untitled Linux Show, episode 274, recorded Saturday, October 10th. Not even embarrassed. Hey folks, it is another fine Saturday, and you know what that means. It is time for some Linux. Some Linux news, some hardware, some software, all kinds of fun stuff today on the Untitled Linux Show. I've got Rob and I've got Jeff. Our other guy, Ken, that other guy, you may remember him. He is off today.

Jonathan Bennett [00:01:16]:
We let him play hooky. I think before the show we decided, we're not, it's probably not, but we decided that today's his birthday. And so he's taken off for his birthday. And no, he's been a little extra busy with work.

Rob Campbell [00:01:29]:
Yeah.

Jonathan Bennett [00:01:29]:
But the 3 of us, we're going to have some fun today. And well, Jeff's going to— or Rob's going to start us off with the story that, according to someone on Twitter, actually someone you know, it was ESR that said this, is the sign of the end of proprietary software. I'm curious what Rob thinks about that. I have thoughts about this too. So Rob, what in the world happened? What was the death knell for closed source? This week.

Rob Campbell [00:01:57]:
Well, so this is what happens when you don't listen to your customer base. That's a death knell. You don't listen to your customer base, um, you know, you leave an opening for, uh, someone, you know, to, to build what your customer base is asking for, and then suddenly, you know, uh, you're, you're getting leapfrogged. So, so if you're a software company And still ignoring Linux. It's time to get on board or get passed by. Adobe, this one's for you. So the team behind ArtCraft is developing 7 free open source creative applications for Linux, Windows, and macOS, but who cares about those ones? They're taking on image editing, illustration, video editing, photography, PDFs, motion graphics, and publishing. That covers a lot of the territory currently occupied by Adobe.

Rob Campbell [00:02:56]:
And they say there's more to come. In fact, I just saw a post today that they have some kind of unified launcher. I didn't even get a chance to look into what that is. But this addresses a major blocker for many people considering Linux. They might be perfectly happy to switch an operating system, but their work depends on Photoshop, Premiere, or another Adobe application. And when your livelihood depends on a particular workflow, switching means more than, you know, learning a different desktop. You need, you need to open clients' files, make changes, and deliver something they, they can use. You know, sure, we already have capable open-source creative tools, but familiarity and compatibility matter.

Rob Campbell [00:03:44]:
And, you know, it's People don't like to change their interfaces often, especially when there's deadlines involved. That's where ArtCraft's approach gets interesting. So PhotoCraft is being built as a Photoshop alternative with familiar tools, shortcuts, layers, masks, adjustment layers, and support for opening and saving layered Photoshop documents, though I've read a few comments that the PSD reading a PSD file format isn't quite perfect yet. But it's it's a new project. I think it's only like a week or two old now, so they've come this far. You know the developers though they're trying to give existing users a familiar place to work. The broader lineup includes Vectorcraft, Filmcraft. Lightcraft, Printcraft, Effectcraft, and Designcraft.

Rob Campbell [00:04:43]:
The team says these are native Rust applications that work locally with your files. Now, now these are early projects. Photocraft and Printcraft are labeled early alpha, and the others are in development. Adobe hasn't been replaced overnight. The real test will be reliability and file compatibility and whether people can trust these applications to work every day. But the opportunity is there. Every missing application that gets a credible Linux alternative removes another reason someone feels they have to stay on Windows or macOS or with Adobe. You know, if you're just going to be evil and ignore what people want, then people are going to find a way.

Rob Campbell [00:05:34]:
And with AI helping developers move more quickly, I expect we'll see more projects tackling gaps that once seemed too expensive or time-consuming to close. Probably similar to the Twitter comment that Jonathan was referencing. I didn't see, but it's along those same lines. And also, we've joked about the year of Linux on the desktop for decades. But as those barriers start falling, that joke could soon turn into a reality. And the key thing here is keep ignoring Linux and someone else may give your customers a reason to move on.

Jonathan Bennett [00:06:23]:
Yeah, I, okay. So here's, here's the funny story from the early part of us getting ready for the show today. Rob and I both picked this. Rob picked it first, but Rob and I both picked this topic. And my take on it, I was gonna lean much harder into the open-source clean room reimplementation element of this. And I key in on that because, as most of you guys know, I think one of the other hats that I wear these days is running the Meshtastic project. And we are GPL v3. And one of the things that happens to us quite often, getting to be about once a week now, is someone will come along with either a closed source app or an MIT licensed app and say, I didn't pull any of your GPL code in.

Jonathan Bennett [00:07:15]:
I had the AI do a clean room reimplementation of it to break your copyright, essentially is what they're saying. You know, it's kind of the quiet part they don't say out loud. Sometimes they do say out loud. And what's hilarious about this is without fail, we will go into those source code files and it will say, here is this value taken from this original source code document on this line. I did this in my clean room reimplementation. And it's like, that's not what that means. That's not how a clean room reimplementation works. And so it is really interesting though to see And I had kind of the same question about this application.

Jonathan Bennett [00:07:55]:
Like, was there a decompilation of Photoshop involved? That was my first understanding of this, the way that it was written, is that it started from the Photoshop binary and did essentially an AI-powered decompilation of it. And now that I hear Rob's coverage of it, I'm not entirely sure that that is what happened. Although that is a thing that is happening and you see it in some other places like people doing crazy things with video game engines and other things. But yeah, this one is really interesting. And again, every time an AI says, I did a clean room, I just kind of like, no, you probably didn't.

Rob Campbell [00:08:32]:
I've heard some say that they think it's— they took like Photopea and then made it look like Photoshop.

Jonathan Bennett [00:08:42]:
Yeah, that could be too.

Rob Campbell [00:08:43]:
That's true.

Jonathan Bennett [00:08:44]:
And that's sort of the other thing. Like when you tell an AI to do something and you don't— force it to show you its work. Like, there should be questions about what exactly it did and where it pulled from and some of those things. So like, maybe it was heavily inspired by Photopea code and then, you know, just did the UI piece of it.

Rob Campbell [00:09:05]:
I was going to point out for those watching that my background is not Photoshop. It is—

Jonathan Bennett [00:09:13]:
It is Photocraft.

Rob Campbell [00:09:14]:
It is Photocraft.

Jonathan Bennett [00:09:17]:
Oh, looks a lot the same though. Very, very similar. Yeah. So it is, it's, it's real interesting to see this. Jeff, what do you think?

Jeff Massie [00:09:26]:
Well, I think it's pretty cool. And while it's still in alpha and they're working on it, you can run the official Adobe Suite right now through Wine.

Jonathan Bennett [00:09:37]:
That's true.

Jeff Massie [00:09:39]:
At least until, as of recording this, I mean, it could be one patch away from totally breaking, but you can run the official Adobe Suite right now.

Rob Campbell [00:09:53]:
I think if they want to, if Adobe really wants to, you know, I don't know, they just need to support Linux natively. Stop.

Jonathan Bennett [00:10:01]:
I mean, that would be great. It'd be awesome.

Jeff Massie [00:10:04]:
Well, I could see them not breaking it through a patch or not intentionally, Because they're thinking, we're still getting paid for this and we don't have to support it. And if other people want to support it and give us money, okay. Because saying, well, we don't want it to run on Linux, I don't know if there's really any advantage to that for them. Just seems like they would. Well, but I mean, money is the root of all evil. So they want money. And what a better— why would they care what operating system it's on as long as you're paying the license? Who cares?

Rob Campbell [00:10:39]:
They're just eviler than that even.

Jonathan Bennett [00:10:41]:
Oh my goodness.

Rob Campbell [00:10:42]:
Adobe's worse than Microsoft.

Jonathan Bennett [00:10:44]:
I feel like I'm being ganged up upon and I shall have to be the voice of reason that speaks out for capitalism here. Uh, first off, Jeff, the love of money is the root of all evil, not money itself. Uh, anyway, um, there's a— there's another interesting question here that I think is worth— was worth jumping to. Uh, Harold Finch puts it well. Doesn't most licenses deny decompilation and reverse engineering? And the answer is, well, yes. When you start the program and you accept the terms, that is going to be one of the things that you agree to. It is possible to get ahold of the binary without having accepted those terms. And having your AI look at it does not necessarily agree to those licenses.

Rob Campbell [00:11:29]:
It's not.

Jonathan Bennett [00:11:29]:
does not necessarily enter you into a contractual arrangement. And then, like, I think there's another open question about, does it count? Like, if you ask the AI to do it, does it count as you doing it in a legal sense?

Rob Campbell [00:11:46]:
I mean—

Jonathan Bennett [00:11:47]:
You may say, oh, that's a ridiculous question, but like, you start looking into the way the legal theory behind the AI works, and it's not as ridiculous of a question as you would think.

Rob Campbell [00:11:56]:
If you've been paying attention to all the security stories with Anthropic and OpenAI and them hacking other governments, like, oh, I didn't know they did it. Like, nobody's getting in trouble for that stuff yet.

Jeff Massie [00:12:13]:
Well, and I would postulate you don't even need to decompile because if you got your good AI, you feed it the documentation and classes for learning, say, Photoshop. So it doesn't have to know what exactly Photoshop is doing at the code level. It just knows, oh, when I press this button, this thing happens. So I will implement that function in that button.

Jonathan Bennett [00:12:44]:
Yeah. I actually have a prediction on stuff like this. There will at some point be a court case where a judge Doesn't understand how AI works and doesn't care and just looks at it and goes, there was an obvious intent to copy this thing verbatim, therefore copyright holds. At some point, we will see that court case, I do believe. So anyway, there is another AI story. We're just going to tack the two of them right on each other. And this one is sort of a sneaky AI story, but it also, it makes, it makes you think. That's what we try to do here.

Jonathan Bennett [00:13:21]:
And this is another dozen vulnerabilities have been found in X.Org and XWayland. And I'm reminded of the time several Fedora versions ago when I raised the question of, are you sure you guys really want to continue trying to ship KDE on Wayland? And the guy that was behind that particular effort said to me, oh, I'm sure that all of the severe security vulnerabilities have already been found. in X.Org. And I was just like, no, okay, I'll frame this on the wall and we'll see how well it stands up. Not very well. Has not stood up very well. We've got a dozen issues here, CVEs. I've not gone and looked up the severity of all of them, but it's a pretty decent list here.

Jonathan Bennett [00:14:10]:
And a lot of them have been found via AI, right? And that's just the reality of the world right now is a lot of security vulnerabilities are being found using AI. In fact, I would say probably the vast majority of them at this point. But the vulnerabilities are being found and maintainers are just saying, well, okay, Claude or Gemini or, you know, pick your agent, pick your modern model, your leading edge model. Here's the vulnerability, go write me a patch that's going to fix it. And the AI will do it. And obviously you got to look at it. It's a good idea to look at it and test it and all of those things. But the AI generally at this point can just fix it.

Jonathan Bennett [00:14:54]:
So on one hand, the dude that wanted to single-handedly save the X.Org for KDE was nuts at the time and was wrong. There's a bunch of vulnerabilities that were left in it. On the other hand, now with tools like AI, it's not inconceivable that a single developer would be able to maintain something like X.Org. He has a Claude Max subscription or whichever agent you want to use, potentially just find bugs, fix bugs, continue the cycle until I'm out of tokens for the end of the week. And do that until it stops finding things and call it the next release. That's kind of what software development is right now. And you don't need as many humans in the loop as you used to. It's a weird place that we've come to.

Jonathan Bennett [00:15:45]:
So I And this, as I said, it's a sneaky AI story. And I think he's tied together pretty well.

Rob Campbell [00:15:51]:
Well, if we want to sneak another little AI story, I don't know if you heard about the proposal to add agent.md files into the kernel.

Jonathan Bennett [00:16:00]:
They should do it.

Rob Campbell [00:16:01]:
Yeah, that was proposed by Levin, I think it is.

Jonathan Bennett [00:16:06]:
Yeah, they honestly, I know people are going to hate to see, they will hate to see it in there, but they needed agents.md and they need a Claude.md. Yeah, so it makes the outputs of your LLM tooling so much better when you have rules for them because they'll go out and they'll look at it. No, okay, I'll write it that way. Okay, I'll shut up when I'm supposed to shut up. I'll fix the thing. I'll send the emails the right way. Makes it so much better.

Rob Campbell [00:16:30]:
Yeah, so I think it was Sash11 and then Greg Cage basically already said, yeah, that would be good. So that's likely something that's going to happen.

Jonathan Bennett [00:16:39]:
And if you're out there and that just makes your blood boil, I get it, but I'm also a realist and this is the world that we live in now.

Rob Campbell [00:16:47]:
Yeah, I mean, the thing is, AI is there. The AI-assisted commits are going to happen. We might as well have some guidance with the MD file to make them better and to fit the project better.

Jonathan Bennett [00:17:05]:
Yes, absolutely.

Jeff Massie [00:17:06]:
Pandora's box is open and there's no putting the lid back on.

Rob Campbell [00:17:10]:
Yup.

Jonathan Bennett [00:17:11]:
What do they say is at the bottom of Pandora's box? Is it hope?

Rob Campbell [00:17:14]:
Hope.

Jonathan Bennett [00:17:16]:
Yup. I don't know if that means that hope was released and is therefore gone, or if after all of this bad stuff comes out, you've got hope left over. I'm not sure which way that story is supposed to be read. The latter.

Jeff Massie [00:17:27]:
The hope is the only thing that was left.

Jonathan Bennett [00:17:29]:
Okay.

Jeff Massie [00:17:30]:
Because the bad is released into the world, but we still have hope to grab onto.

Jonathan Bennett [00:17:34]:
That is a hopeful interpretation. I like that one better. Yeah. I've heard that the other way, but I like yours better.

Jeff Massie [00:17:40]:
And if you are not a fan of AI, just a little precursor, I don't have a single AI story this week. Not a one.

Rob Campbell [00:17:48]:
Jeff's your man.

Jonathan Bennett [00:17:49]:
Jeff's your guy. Yeah. Interesting stuff. All right. We are going to, we're going to take a quick break and we're going to come back and we're not going to talk about AI, at least not in the first 2 or 3 stories. 2 stories.

Rob Campbell [00:18:05]:
One.

Jonathan Bennett [00:18:05]:
Maybe one story. Jeff is going to not talk about AI. Anyway, quick break. We'll be right back. All right, Jeff, the GRUB is going on a diet and some other things in Ubuntu. What's new there in 26.10?

Jeff Massie [00:18:24]:
Yeah, well, I will preface this. This is pretty much focusing on GRUB. So I didn't get too much into anything else happening. There's, there's, uh, but there are a lot of things. So next Thursday, October 15th, Ubuntu 26.10 Stonkin' Stingray— I just love that name, it's so cool— is coming out. Now, it could cause some issues for you if you've built a fancy custom boot setup with Btrfs snapshots, ZFS, or an encrypted /boot and You run and, it's a big and here, and you run with Secure Boot on because Canonical has put GRUB on a diet. So now, just quick refresher, when, you know, your PC starts with Secure Boot on, the firmware checks the signature on a small loader called SHIM, and SHIM checks the signature on GRUB. Then GRUB has to go and find your kernel and intra-RAM FS in /boot.

Jeff Massie [00:19:25]:
And to do that, it has to understand whether the disk layout— understand whatever disk layout and file system you put on the boot partition or your /boot directory. It also reads your grub.cfg. And, you know, if you're into theming, it decodes your fancy background image. Now, all of this, you know, all that happens All that parsing is before Linux even has started in the most trusted part of the boot. So a bug in any of those parsers is a potential crack in the chain of trust, even for a file system you don't use. So in 26.10, the signed GRUB, you know, the one that you use when secure boot is on, keeps only what Ubuntu needs. And from Canonical security blog post, under secure boot, boot can be on ext4, FAT, or ISO 9660 plus squashfs for snaps. The signed build, now that's secure boot on, Btrfs, XFS, ZFS, HFS+ drivers, Are gone.

Jeff Massie [00:20:44]:
It also drops Apple partition tables and JPEG and PNG image loading. So even putting boot on an LVM on LUKS encryption or on software RAID is no longer supported under Secure Boot either. Now, there is one exception, and that is RAID 1. So a mirrored boot disk still will work. Now, before anybody panics, there are 3 things to know. One, this is only about /boot. So your— the rest of your root file system can still be Btrfs, ZFS, LVM, RAID, or LUKS. It, it all still works once the system is running.

Jeff Massie [00:21:29]:
So this only is /boot directory. 2, if Secure Boot is off, this doesn't apply. You get the full-fat GRUB, you know, you get Porky GRUB with everything enabled, background images included. So nothing changes when Secure Boot is off. And 3, the standard Ubuntu installer already sets things up in a compatible way, so most people won't notice anything. Now, Canonical engineer Maitai Kukuri said, quote, we're not removing any kind of full disk encryption support from Ubuntu whatsoever. Your root partition still gets unlocked by crypto setup in the intra-RAM FS, same as always. Kukuri's argument was that /boot doesn't need to be secret.

Jeff Massie [00:22:24]:
It needs to be tamper-proof. In his words, there's no reason to encrypt /boot. It just needs to be integrity protected. Now, this didn't come out of nowhere. So back on March 25th, Canonical engineer Julian Claude posted a proposal on Ubuntu Discourse called Streamlining Secure Boot for 26.10. Now, his case was that GRUB parsers are, quote, a constant source of security issues on encrypted/boot. Specifically, he wrote that only provided security by obscurity, but not actual security. So, you know, as you can imagine, that post went over great.

Jeff Massie [00:23:11]:
And, you know, the thread ran, you know, past 100 posts. Ubuntu developer Thomas Ward asked for every single You know, removal to be justified. He pointed out that Ubuntu Server's own installer uses LVM by default. Other people raised European compliance rules that require an encrypted /boot. The Btrfs snapshot fans showed up. The ZFS on root fans showed up. You know, at one point, a moderator had to switch on slow mode to just slow down the threads. And of course, someone suggested just rewriting GRUB in Rust.

Jonathan Bennett [00:23:59]:
Of course they did.

Jeff Massie [00:24:01]:
Yeah, it was chaos. Let the hilarity ensue after that post. So is the risk real? Well, one developer in the thread pointed out to CVE-2024- 45,774, a specifically crafted JPEG could trigger an out-of-bounds write in GRUB's JPEG parser. Ubuntu's own CVE page says that secure boot bypass can't be ruled out. So yes, your boot wallpaper was technically an attack surface. Claude's other point was timing. He wrote that The timing here is critical. Making the change right after a long-term support release means that anyone who depends on these features can just stay on 26.04 LTS.

Jeff Massie [00:24:52]:
Canonical says the release is supported until 2041. That's the LTS is supported until then. With it, if you have the Ubuntu Pro and legacy add-ons. 26.10 though is only supported until July 2027. So. If you're on 26.10, you're not probably running anything that mission critical. So people affected lose very little by sitting it out, and you're probably more adventurous if you're on 26.10 anyway. The release that will really, that really matters going forward is going to be 28.04 LTS because that's where most the most serious users can break and people who probably are a lot more people who are using the secure boot.

Jeff Massie [00:25:45]:
This is where you might actually have problems with the change. Now, if you want to know what's going on, you can run mockutil --sb-state to see whether secure boot is on. And then run df -T /boot to see what file system is on your boot directory. If the device name starts with /dev/mapper, it's on an LVM or LUKS setup. So if Secure Boot is on, And your /boot isn't, you know, basic ext4 or FAT, you basically have 3 choices. You can move boot to a, you know, simple partition that has its file system with one of the compatible ones, you know, ext4 or FAT. You can turn off Secure Boot, or you can stay on 26.04 LTS.

Rob Campbell [00:26:56]:
Or you can leave Ubuntu.

Jeff Massie [00:27:00]:
Or that is a possibility. Whatever you pick, though, check before you upgrade, not after. Because I said, you know, the installer sets things up correctly, but just an in-place upgrade, make sure you're compatible before you do that upgrade. Just normal upgrade. Take a look at the article linked in the show notes for more details and more links to even more information, and happy upgrading.

Jonathan Bennett [00:27:31]:
I suspect that encrypted boot with Secure Boot will come back because I think that is actually essentially a requirement in some cases.

Rob Campbell [00:27:43]:
Yeah.

Jeff Massie [00:27:43]:
Well, and that was some of the argument, right? You got, you got European Union mandating that it has to be encrypted. And then, of course, the other argument is, well, it doesn't really matter as long as you can't mess with it because then you kick into the encrypted system. And I mean, so yeah, 100+ threads or replies on that thread plus just—

Jonathan Bennett [00:28:08]:
Yeah. I like everything else that they're doing there, but I think encrypting /boot is a good idea.

Rob Campbell [00:28:15]:
Just something. I'm with the ButterFS snapshot guys. I think being stuck on only one option, if you want secure boot and all that, I think they should also support ButterFS for snapshots.

Jonathan Bennett [00:28:31]:
I mean, do you really need to be able to snapshot /boot?

Rob Campbell [00:28:36]:
If my kernel update fails, I want to be able to roll back.

Jonathan Bennett [00:28:40]:
But GRUB can already do that for you.

Jeff Massie [00:28:44]:
Yeah, this is pre-kernel.

Jonathan Bennett [00:28:48]:
Yeah.

Rob Campbell [00:28:48]:
What if it really messes it up and doesn't save my last kernel?

Jonathan Bennett [00:28:55]:
Here's your install disk. Yeah, no, I mean, I definitely get that they want to make GRUB safer and therefore slimmer. That makes a whole lot of sense. But I think it is a misstep to lose the ability to do encrypted /boot. So we'll probably, hopefully see that come back. If not officially, I'm sure there will be some unofficial workarounds for here's how you reinstall this GRUB module with Secure Boot.

Jeff Massie [00:29:23]:
And I think testing it out on 26.10 is they're really trying to bring out some of those, do we really need it or is this going to be too painful? And we, you know, it's, that's what 26.10 is, right? It's kind of their, let's just throw things at the wall and see what sticks, you know? Because it's so short-lived, they don't have to be that careful with it.

Jonathan Bennett [00:29:44]:
Right. Yeah, exactly.

Rob Campbell [00:29:45]:
And they sure do throw a lot against the wall these days.

Jonathan Bennett [00:29:48]:
Yeah. And a lot of it sticks, surprisingly. We're still adding more Rust utils to Ubuntu.

Jeff Massie [00:29:56]:
Well, and, you know, they found out they've got to speed up, you know, a lot of their updates, both security and kernel features. Ubuntu's kind of morphing a little bit from what it used to be.

Rob Campbell [00:30:10]:
I've given them a hard time for years about being so slow. Now it's, I don't know.

Jonathan Bennett [00:30:18]:
They took your advice to heart, Rob.

Rob Campbell [00:30:21]:
I'm sorry.

Jonathan Bennett [00:30:21]:
I'm sorry. You ruined it for all of us.

Jeff Massie [00:30:25]:
Well, now you got to sing their praises. They followed what you said. You can't give them any grief for doing what you said.

Rob Campbell [00:30:32]:
It wasn't exactly what I meant.

Jonathan Bennett [00:30:34]:
But they did what you said, but not what you meant. Uh, all right. Uh, let's talk, uh, let's talk Snapdragon. Rob, did you ever buy one of those Snapdragon laptops?

Rob Campbell [00:30:46]:
No, because, uh, last I've read about it, it just never had the great Linux support that, uh, we hoped it would. I don't know. Maybe they're getting there and I haven't Followed it enough.

Jonathan Bennett [00:31:02]:
Isn't that what your article, your story is about?

Rob Campbell [00:31:05]:
Yes. Yes. Snapdragon laptops are getting a little more interesting for Linux users.

Jonathan Bennett [00:31:11]:
Okay. Okay. I saw that he had this story and I tried to segue into him and he's like, yeah, yeah. I don't know anything about it, man. No, I think you know something about it, Rob.

Rob Campbell [00:31:20]:
I didn't say I didn't know anything about it. I just said they weren't always Wait there. And I don't know if they're there yet, but I think they're getting there. So we do have 2 developments this week. You know, work to help Linux understand the hardware's temperature limits and work to bring— here's one Jonathan will like— HDR support to its displays.

Jeff Massie [00:31:43]:
Cool.

Rob Campbell [00:31:44]:
So, you know, we were very excited when they were announced and coming to the Snapdragon X slates when they first came out, but Linux support was poor. Continued improvement like these may make it a more viable option soon. Maybe it's there yet. Maybe I'll have to really dig into it. Maybe I've missed some of the— some past stories that said all the other problems were fixed. But, you know, this is one more step closer. So first up, Qualcomm has submitted patches for what's called hardware thermal binning. This helps to identify how temperature limits apply to a particular chip.

Rob Campbell [00:32:27]:
You can have the same underlying silicon sold in different packages with different thermal characteristics. The information identifying that variant is programmed into manufacturing fuses. These patches let Linux read that information and select the appropriate appropriate thermal trip points, as in like the temperatures where, you know, it needs to take action, throttle or something else. So the goal is to have Linux use the limits that match the actual hardware. Snapdragon X Elite is among the platforms covered by this work. You know, so I want to translate that into a promised performance boost, but getting thermal management right is a part of getting the platform right. The second development is a little more visible. And, you know, Jonathan's favorite thing he loves about Linux these days is HDR support.

Rob Campbell [00:33:30]:
Okay. We all, we all love HDR support. Those of us with HDR monitors, those that don't tell me all the time that they could care less. But I know plenty of people with HDR monitors, at least 2 people out of the 3 on this panel. So anyway, patches for Qualcomm's MSM Display driver add static HDR support for DisplayPort connections and embedded DisplayPort panels, the connection commonly used for laptops' built-in screen. Uh, the focus is HDR10 and BT.2020 RGB signaling. This patch series doesn't provide dynamic HDR or tone mapping, so there are still boundaries to what it delivers, but there's actual hardware testing behind it. The patches have been successfully tested on a Snapdragon X Elite Lenovo Yoga Slim 7X.

Rob Campbell [00:34:27]:
And like all good software these days, the HDR patches were developed With the help of AI coding assistant. I told you we weren't going to get through more than one story before we bring up AI again. So anyway, both patch series are currently under review. So this is progress to watch rather than, rather, and likely not, you know, something that's already in your favorite distro. But the way Ubuntu's been going, it should be there before long. Did they have an ARM release? I can't remember. Yeah, now they're working on one. They had one in the past.

Rob Campbell [00:35:08]:
They must still have one. Anyway, what I liked to hear is the direction. You know, I don't know if the Snapdragon X Elites are there yet for Linux, but they're moving forward. You know, better hardware awareness underneath, more display compatibilities on top, keeping So keep filling all those gaps. And, you know, if it means using AI, just get it done. And Snapdragon becomes a more compelling option for people who want an ARM, like a powerful ARM laptop running Linux. I would definitely buy one if someone told me that it was ready.

Jonathan Bennett [00:35:50]:
You know what I like on laptops even more? than HDR?

Rob Campbell [00:35:56]:
No.

Jonathan Bennett [00:35:57]:
Laptops that boot, that you don't have to jump through a bunch of hoops to get to boot. This has been my continual complaint about ARM hardware and running Linux on ARM. Multiples of these devices that I've messed with have had this problem. They don't have a good boot experience. You've got to run like some hyper-customized image that has the, uh, like the device tree stuff baked into it for it to be able to boot properly.

Rob Campbell [00:36:25]:
Yeah, like CD BIOS or something like that.

Jonathan Bennett [00:36:28]:
Well, and on a lot of these, it's not— they don't even have a BIOS on them. Like, it's not, uh, let's see, what are they— what is that thing called? Uh, U-Boot. A lot of them run U-Boot, and there's like 3 different ways for U-Boot to inform the kernel about what device tree it should use. And Oftentimes you will see that like the vendor image ignores that and just sets it because the thing that U-Boot thinks does not match what's actually on the hardware, which does not match what their special kernel version thinks needs to be there. Booting Linux on ARM is kind of a nightmare unless you have a UEFI bootloader, which ARM devices are now starting to roll out. And that makes it a lot easier. It does not necessarily solve every problem, but it makes it a lot better. So that's the first question that I would have about one of these laptops.

Jonathan Bennett [00:37:23]:
Can I boot the dang thing? Can I just pull down a Fedora or a Debian or an Ubuntu ARM64 image? And will it boot? And if there's no path to that, I'm not terribly interested in that piece of hardware. I've lost too many hours of my life fighting with device trees and U-Boot and early, early Linux kernel boot problems.

Jeff Massie [00:37:45]:
And you were right, Rob. Ubuntu, the stonking Stingray that's coming out, does have a beta ARM64 build.

Jonathan Bennett [00:37:52]:
Oh, there you go. I would be surprised if it did not.

Rob Campbell [00:37:58]:
Yeah, I remember talking about when they were trying to work closely with some of the ARM manufacturers out there, but it's been a while since I've heard anything.

Jeff Massie [00:38:09]:
They're, they're still working on it. They're, they're pushing ARM on this, this 2610 release, and, and it's good for the thermal temperature. And just a little bit of trivia for a lot of people, when people talk about chip temperature, it matters where you say a temperature is.

Rob Campbell [00:38:30]:
Mm-hmm.

Jeff Massie [00:38:30]:
JEDEC spec is center of case, so that's on the center of the external part of the chip, that is where the temperature is defined. You can have a lot different temperature gradient inside at the junction temperature, and a lot of these chips have multi-levels, so then you have to say, well, what place in the chip is the temperature? So you can have a temperature gradient both from the top where it may be hotter or cooler depending on whether it's making physical contact with, uh, something that's cooling it, whether it's, you know, air, water, some kind of, you know, metal stack, whatever it is. And then you also have possible heat inflow or outflow depending on where the bottom of the chip is connected, if the, the surface it's on is warmer than the chip and it's funneling heat into the chip or it's removing heat from the chip because it's cooler on the substrate it's on.

Rob Campbell [00:39:37]:
Yep. Yep.

Jonathan Bennett [00:39:37]:
That makes sense.

Rob Campbell [00:39:38]:
And according to Google's AI, when I searched for it, Snapdragon X Elite is a standard UEFI-based boot. So—

Jonathan Bennett [00:39:49]:
That checks out because like they do support Windows. on some of those. So it checks out.

Rob Campbell [00:39:54]:
That's it. Yeah. That's what they're built for, unfortunately.

Jonathan Bennett [00:39:57]:
Yeah, true.

Jeff Massie [00:39:59]:
So, um, stonking Stingray in Rob's future. Get some hardware, test it out, Rob.

Jonathan Bennett [00:40:04]:
Yeah, probably could. Uh, there's another piece of ARM hardware that I saw a review on that really intrigued me, and I've actually got a link off to Jeff Geerling's video on it. It is the— it's the qual— the Radxa Dragon Q8 B. And he talks about it as being potentially a Raspberry Pi killer because it's faster, has more cores, comes with 8 gigs of memory, and is, I think, actually a little bit cheaper than most of the Raspberry Pis right now. And it has dual 2.5 gig Ethernet ports on it. It's got like 4 different NVMe connectors on it. I was I was really excited about this as he was talking about it. I'm like, oh, I may have to pick one of these up just to have yet another device to play around with.

Jonathan Bennett [00:40:58]:
It's Qualcomm CPU on it and really seemed pretty interesting and pretty compelling. And then he gets to talking about the software and he goes, yeah, you have to install this One from the vendor image. And he talks about some of the problems with that. Like, do you want this version or this version? You kind of feel like you're a beta tester. And then he goes, and then I saw this note, don't use apt to upgrade the system because it can break your system. And at that point, I just went table flip. Like, I know I'm not playing that game either. If it's a Debian or an Ubuntu install and running apt upgrade can brick the system, it is not It is not ready for primetime and it's not ready for me either.

Jonathan Bennett [00:41:43]:
I, yeah, I'm not interested in that at all. But you go look at his video and you check out the benchmarks, pretty impressive. And sort of reminds me that even the Raspberry Pi 5 is not the most compelling piece of hardware. Let's put it that way. But yeah, really, a really interesting, really interesting hardware. You just, you wish they had Better software support. And like they have, they promise, they promise that they're working to bring it up to the kernel and do all the things right. But it's just way too early in that game for that to be, it's just not ready.

Jeff Massie [00:42:19]:
Yeah. If apt breaks it, boy, there's 10 years of muscle memory to try to, oh, I can't do that.

Rob Campbell [00:42:25]:
You know? Well, I suppose that means if you use the built-in software center and update there, since I think that just uses that behind the scenes too, that'd break.

Jonathan Bennett [00:42:33]:
They've got, I'm trying to remember what tool that they have that they wanted you to use. Oh, they were probably replace it. Yeah, they had, they had some update tool. It was like a Dragon update or Radza update, RadUp. I don't remember what it was. It was something like that. It's like, you have to use this. Like, guys, no, no, no, not playing that game.

Rob Campbell [00:42:54]:
I mean, I guess that's what they're going to do. They might as well just like have you replace apps too, you know?

Jonathan Bennett [00:43:00]:
Yeah. I mean, just remove apps, right? You might as well.

Jeff Massie [00:43:04]:
I'm sure it's linked and not in there. Either that, well, you know what? It's probably needed for some kind of, oh, here's how you search the packages or you need it to do whatever function. So we can't totally remove it.

Jonathan Bennett [00:43:20]:
Their tool probably calls apt internally, actually.

Rob Campbell [00:43:23]:
Oh, it's like safety guardrails. So it only runs apt specifically what they want.

Jonathan Bennett [00:43:28]:
Yeah. But it's got to be.

Jeff Massie [00:43:31]:
Right.

Jonathan Bennett [00:43:31]:
Only, you know, they want the kernel and the, you know, those few packages that are kernel adjacent have to come from their special repository. But they didn't take the time to blacklist the package names from the regular upstream Ubuntu repository. And so you can just download a regular upstream Ubuntu ARM64 kernel and it will totally hose your system. That's got to be what it is.

Jeff Massie [00:43:57]:
Yeah.

Rob Campbell [00:43:57]:
Yeah.

Jonathan Bennett [00:43:59]:
So not, it could be the greatest hardware in the world, but if there's not decent software support, I'm not terribly interested in it, which is really what makes the Raspberry Pi so compelling still. You can just install Raspberry Pi OS or any of, I don't remember what the support level is like on the Raspberry Pi 5. That one may still be a little bit behind, but on the previous ones, you can install basically any modern distro and everything works. I think on the Pi 5, they're still landing some patches in the kernel and all of that. But you get Raspberry Pi OS, you can get Fedora, Ubuntu on the previous versions and they'll just work. Pretty much everything comes up and works. Now I'm curious. I had to go back and look.

Jonathan Bennett [00:44:44]:
Where are we at on the upstream kernel for the Pi 5? I know they have people landing stuff. Let's see where it's at. Ongoing. It boots. Southbridge, the RP1, has had active patch submissions. Ethernet. Yeah, Google's AI, Gemini, does not know.

Jeff Massie [00:45:12]:
So the landing still might be a little more crash landing.

Jonathan Bennett [00:45:15]:
Yeah, it might be. Anyway. All right, let's see. What's up next? We're going to take Quick break, and then we're gonna let Jeff talk about something that is not yet all AI. So don't go anywhere. We'll be right back.

Jeff Massie [00:45:30]:
Well, here's, here's a second story. No AI. Blender has been trying to leave OpenGL for about 3 years. On October 8th, with the 5.3 beta, it finally did. On Linux, Vulkan is now the default for drawing Blender's interface and viewpoint. Now Blender's lead GPU developer, Jeroen Baker, we'll say Baker, laid out the case on Blender's developer blog back in October 2023. And even back then he said OpenGL was designed for an era when high-end GPUs had about 128 megabytes of memory And drivers interpret the specs differently. So Blender's code is full of per-driver workarounds.

Jeff Massie [00:46:22]:
And they also said OpenGL is, quote, isn't actively developed. So his conclusion was we have to migrate away from OpenGL. Now, Vulkan showed up as an experimental option in development builds in late '23 and was declared stable in Blender 4.5 LTS, which happened in July of 2025, but OpenGL still was the default because of problems with VR performance and huge meshes. It stayed the default again in 5.0. The OpenGL stayed the default. Now in 5.3, the switch is flipped. Now, something of note for those who might remember when 5.0 came out, The developer said it's not expected that Vulkan will become the default backend in Blender 5.0. The reason being is that OpenGL drivers are able to offload GPU memory to CPU RAM, and Vulkan being a low-level API doesn't have that.

Jeff Massie [00:47:26]:
Now reports have been coming in that more users face this limitation than we need.

Rob Campbell [00:47:33]:
There Sorry.

Jeff Massie [00:47:35]:
Reports have been coming in that more users face this limitation and that we need to resolve it. There are multiple ways how to solve it and with their own drawbacks. We want to experiment coming up this week with sparse memory. According to the Vulkan specs, it allows you to replace CPU memory behind a handle, image, or buffer using a queue command. When this happens, we could split the render graph and perform the upload synchronization that are needed, end of quote. So that was, that was what the developer was talking about. And at the time, I thought maybe they kind of think in the 5.0 series, especially, you know, 5.1, 5.2 didn't have it as the default, but 5.3 is now at the stage they've done enough work with the Vulkan, uh, part of it is they're going to the default. Now, 2 things to know.

Jeff Massie [00:48:29]:
First, this is, this is about the interface and the viewport, the viewport, not the final renders. So Blender's own docs say Cycles doesn't use Vulkan, and running Cycles on Vulkan is neither planned nor viable. Your CUDA, OptiX, or HIP render queue stays exactly as it was. So nothing, nothing's changing there. Second, Blender 5.3 lowers the minimum to Vulkan 1.1 and makes several GPU features optional. The goal is to have older and VRAM-starved hardware that couldn't run the Vulkan path before still be, you know, basically be viable. They want to support as many, uh, the older GPUs as they can. Just for reference, At the time of this podcast, Vulkan 1.4 is the latest version.

Jeff Massie [00:49:22]:
Now some might be asking, is there any speed differences? Blender's release notes include benchmarks. So now these are Blender's own numbers, and this is from one machine, so this isn't an exhaustive analysis. The system used a Ryzen 7950X and an NVIDIA RTX 6000 Ada card. Now on the same 5.3 build, Vulkan beat OpenGL on every scene they tested. A few scenes were close, about 6 to 8% faster, um, but some were a lot bigger. The Autumn demo scene went from about 193 to 282 frames per second, so roughly 46% faster. Uh, the Shader Ball scene was about 61% faster. But remember though, that's one high-end NVIDIA card that this was tested on.

Jeff Massie [00:50:20]:
For those that don't know, the 6000 is a professional-level card for computation and things like that. So it's got more memory in it than a 5090. It's not a gaming card. So the— You know, your, your, for your GPUs, your AMD and Intel mileage may vary. And even your consumer NVIDIA card, maybe, maybe will vary there too. So big grain of salt with these, uh, very limited testing that they did on the beta. Now Blender does keep a block list of drivers that won't use Vulkan on because they basically If the driver's too old and they just don't have any enough Vulkan support, they, they blacklist them. But OpenGL is still there, so it's not like it totally locks you out of anything.

Jeff Massie [00:51:19]:
Or if you're using it and Vulkan is really misbehaving because of, of your particular setup, you can go back to OpenGL. You know, of course there's many more features of the beta. You know, but you'll need to look at the show notes and the articles linked there for many more details. This beta runs until November 4th. At that date, we get a release candidate, and then the final release is on November 10th. So happy rendering.

Jonathan Bennett [00:51:49]:
Yeah, very cool. Uh, I, I saw this, that Vulkan was working so well that they're trying to finally ditch OpenGL, uh, which, I mean, that's cool. Vulkan is obviously the future of, uh, of 3D acceleration, particularly on Linux, but I guess everywhere. I did a little bit of research during the break and during that story, and something actually just happened a couple of weeks ago. So this is back to the Raspberry Pi thought and whether the Raspberry Pi 5 is supported in the upstream kernel. And one of the things that I quickly found is one of the last pieces was the IOMMU driver, which is reasonably important being able to do like accelerated video and all of those things. And a week and 6 days ago, a patch V7 was sent in by Daniel Drake for adding that Broadcom BCM2712 driver, the one that's for the Raspberry Pi 5. And it appears to be applied according to Georg Rodeg and Florian Finelli.

Jonathan Bennett [00:52:55]:
They say that they have applied it to the /next trees. So it looks like, you know, maybe our Christmas Linux kernel is also going to be the first one that works really well on the Raspberry Pi 5 as well. That's something I'll have to go do a little bit more digging into because that's pretty cool to see.

Jeff Massie [00:53:15]:
So Jonathan's wife for Christmas, you better start planning now, maybe a new set of hardware for Jonathan to play with.

Jonathan Bennett [00:53:23]:
Oh, no, I've got multiple Raspberry Pi 5s. That's not a problem. I have like 2 of them that I could lean over and put my hands on. I've got a Pi 5 in my little mini rack here that I'm playing with. And I have a 500 Pro over there on the desk that's not doing anything. So no, I have hardware to play with. I don't have to spend any money for that.

Jeff Massie [00:53:43]:
Yeah, I was hoping to get you started.

Jonathan Bennett [00:53:45]:
Get me in trouble?

Rob Campbell [00:53:46]:
Yeah.

Jeff Massie [00:53:46]:
Well, that too.

Jonathan Bennett [00:53:47]:
That's what you're hoping to do, I know.

Rob Campbell [00:53:49]:
Yeah, for me, give me an ARM Snapdragon laptop.

Jonathan Bennett [00:53:55]:
I just picked up the new Framework 13 Pro, and that is my new sort of portable machine. I don't think I'm going to be buying another laptop for a while. I've got enough of those now until they start dying. Now, Framework came out with a mainboard that was usable in either ARM or RISC-V or even like Raspberry Pi CM5. Like that would be interesting. And you might be able to convince me to buy one of those. But other than that, I'm good for now. Rob, you've got a story here about a new experimental file system.

Jonathan Bennett [00:54:29]:
I saw this too. It piqued my interest. I'm curious what your take on it is. Why don't you take it away and tell us all about it? All right.

Rob Campbell [00:54:37]:
So Huawei engineers have Presented an experimental Linux file system designed to make memory shared across servers accessible through ordinary file operations. And it's called XMFS, short for Express Memory File System. And it was presented this week at the Linux Plumbers Conference in Prague. The project explores a question raised by newer hardware. If a server can, uh, directly address memory across an interconnect. Could Linux expose that memory as another storage tier? Connections such as CXL 3.0 and Huawei's United Bus provide the foundation. And then XMF— XMFS adds a file system interface on top, allowing applications to address shared memory through a familiar POSIX operation. That gives applications a way to work with the data as files rather than requiring a specialized interface for the underlying connection.

Rob Campbell [00:55:44]:
One workload Huawei has been testing is shared container images across multiple servers. The team has also experimented with metadata-intensive workloads. Operations involving file information and directory structures. Prodigy reports that the preliminary benchmarks show promising results compared with TempFS, Linux memory-backed file system. And those are early results from an experimental project rather than any kind of evidence that it's production ready yet. Making that approach work across servers introduces several engineering challenges. The first is metadata synchronization. Multiple kernels need to coordinate changes to the shared file system's namespace and inode information.

Rob Campbell [00:56:43]:
The developers are examining how to do that without creating a central bottleneck. Another challenge is cache coherence. When the hardware doesn't automatically keep cache consistent across machines, software needs to manage that consistency. The team is also exploring how memory interconnects and remote direct memory access, or RDMA, could work together behind a common interface. Capacity management raises another question. How should shared memory fit into Linux's existing memory tiered and page migration mechanisms? These questions exist or extend beyond the implementation of XMFS itself. The conference presentation sought discussion about which capabilities should belong in a file system and which might need support from broader Linux infrastructure. XMFS remains a prototype and Feronix reports that it has not yet been submitted to the Linux kernel mailing list for review or for possible inclusion.

Rob Campbell [00:57:53]:
So for now, the project is testing whether shared memory across servers can be exposed through a conventional file system and identifying the kernel changes needed to make that practical.

Jonathan Bennett [00:58:09]:
It's going to be challenging to get that particular patch into the kernel and used. Because it's from Huawei. That is a company that is on the naughty list in the United States, at least for their telecom equipment. And would not surprise me if, you know, would not surprise me if that leaks over. I think we covered it back about a year ago, sometime around then, that the Linux kernel, it was actually the Linux Foundation, I think is what we eventually concluded. They got a visit from the US Treasury Department. And said, you have maintainers that are employed by these companies on these lists, and you must stop that. And, you know, the next story that you heard was that, you know, Linux is banning Russian contributors, which is not exactly what happened.

Jonathan Bennett [00:59:03]:
No, they just removed maintainers that were employed by several particular companies that were on the naughty list. And it would not surprise me if we had the same issue here, that like you do not get to be a maintainer on the Linux kernel if you work for Huawei. Yeah, interesting, interesting times we live in. Let's just put it that way. And sometimes those geopolitical things do leak into our open source fun.

Rob Campbell [00:59:32]:
We just can't have good things. Nice things.

Jonathan Bennett [00:59:34]:
This is why we can't have nice things. So true. So true. Anyway, it's a neat idea. I saw some people on the Phoronix forum in particular were like, I was hoping for something new and amazing. And instead we just got another Plan 9. Well, yeah, I guess.

Rob Campbell [00:59:55]:
Another file system.

Jonathan Bennett [00:59:57]:
Just another file system. CXL is pretty cool though. The whole idea of let's just make all of these things You know, accessible on all the servers in the same network. Anyway, let's see what is up next. Well, we take a break and then we're going to talk about something that is pretty cool inside of Linux. And then another story to close this out. So don't go anywhere. We'll be right back.

Jonathan Bennett [01:00:22]:
So I was perusing the internet earlier today and I came across something really fascinating in in development by some folks at Google for trying to make the Linux kernel more secure, which, you know, everyone is interested in that these days. I believe this is pronounced cage. I look at it and at first I think kage because it's spelled with a K. It's K-A-G-E. But then I think about what it's doing and no, no, I'm sure it's supposed to be pronounced cage. It is sandboxing for kernel modules, potentially including kernel drivers, which is really fascinating. It's kind of a step towards microkernel architecture, which is, if you're familiar with sort of the ancient history of the Linux kernel and its various competitors that didn't go anywhere, that one of the of the early criticisms of Linux was, it's not a microkernel. All modern kernels are going to be microkernels.

Jonathan Bennett [01:01:31]:
Well, we know how that turned out. But this is a proposal that essentially writes a shim layer and allows the kernel to make system calls, not even system calls. That's not the right term here. It allows it to use the shim layer As a module, and then the shim layer calls into something else, a sandbox in this case. And so they describe 2 different ways that this could work. One is Cage, which uses the LFI, the Lightweight Fault Isolation sandbox. That's where you have this shim that calls into an LFI sandbox. They give it 4 gigs of memory and like Those 4 gigs are its memory.

Jonathan Bennett [01:02:18]:
It's not allowed to talk outside of it and nothing else except the shim could talk into it. And that's one way to sandbox a Linux kernel. And then the other thing that they have, the other solution for hardware is using an inverted virtio. And they call this vCage architecture. And so inside of the, on the bare metal host, they run, The VirtIO driver, which talks to a user space daemon, Virtqueues, which then talks to a user mode Linux install that then has in it a real driver that talks to real hardware. And so, you know, it's kind of like Russian nesting dolls where, you know, there's a Linux kernel and there's a Linux kernel inside of that. And oh, there's a third one inside of there. And that's the one.

Jonathan Bennett [01:03:10]:
I guess there's only 2 actual kernels in this case, but, you know, 3 layers, 3 or 4 layers. But they've made it work. They've made it work with, for example, NVMe, with some networking interfaces, with some Wi-Fi interfaces. And they say their next steps are, one, performance, as one would expect. They're also looking at Android as something to do here because, and this is sort of a tangent, but if you follow the Android security updates each month. Hardware drivers is one of the places where Android struggles and where a lot of the vulnerabilities come from. And there's reasons for that because of the way the stack over there works. And then there's this question of, can we use VKAGE for GPU drivers? And the answer is theoretically yes, with sort of an asterisk there of like, this could cause, this could cause problems.

Jonathan Bennett [01:04:09]:
Um, so anyway, very, very, very interesting. This is a presentation given at the 2026 Linux Plumbers Conference. Uh, and so if you want to, there's even, uh, you can get the PDF of their presentation and some other really cool stuff. Um, I, I don't, I don't see it spelled out anywhere, but this is also really interesting when it comes to Safety certification in Linux. And this is something that I know there's a number of groups that are interested in. There was a talk given about it at the Ubuntu conference that I went to earlier this year. And then when I talked with the Linux Automation Lab, that was also one of the things that they were interested in is taking the Linux kernel and sort of adapting it to be able to be used in safety-critical systems. And there's a whole set of requirements that you have to meet.

Jonathan Bennett [01:05:03]:
And it's things like actually being memory safe and having controls to where you can't— one process or even one driver can't write into another process or driver's memory footprint. And this ties into it and would be one of the ways to accomplish some of those things that would be needed. So it may very well tie into that. Or if they're not thinking about it currently, I imagine that the safety-critical guys are at least looking at this and trying to figure out if it meets some of their goals. But kind of a wild approach. Then it's one of those things that like we always used to look at like, well, yeah, theoretically you could do that, but I don't think anybody's tried it. Well, now somebody has tried it. They've actually made it work.

Jonathan Bennett [01:05:43]:
That's pretty cool.

Rob Campbell [01:05:46]:
There you go. Maybe Huawei's new XMFS could be sandboxed and be okay. But I guess, I guess, Maybe that's only a small part of the reason why they can't, maybe won't be allowed in.

Jonathan Bennett [01:06:02]:
See, you're coming up with technical answers for problems that are not technical. Yeah.

Rob Campbell [01:06:09]:
Yeah.

Jonathan Bennett [01:06:10]:
Well, I know I'm just— Go ahead, Jeff.

Jeff Massie [01:06:14]:
Well, I was going to say, it's still experimental. By the time you get a solid enough file system to even use it, who knows what the status is going to be anyway, if anything.

Jonathan Bennett [01:06:23]:
True. That's true.

Rob Campbell [01:06:24]:
Anything.

Jeff Massie [01:06:26]:
Yep.

Jonathan Bennett [01:06:27]:
I'm not going to speculate on any of that. I could, but I will definitely not. All right. Jeff has a story coming up and I'm going to turn it over to him. I do have to say, I do get paid by Hackaday. Hackaday is owned by Supplyframe and Supplyframe is now owned by Siemens. So just full disclosure there on where I'm at with this story. I don't think it's going to change my opinions on anything, but, you know, for Journalistic integrity.

Jonathan Bennett [01:06:54]:
Wanted to throw that out there. All right, Jeff, take it away.

Jeff Massie [01:06:57]:
And I have enough opinions for everybody. And I don't, I do not work for Siemens.

Jonathan Bennett [01:07:05]:
All right.

Jeff Massie [01:07:06]:
This week, a program built to simulate car crashes was in a car crash of its own. It survived thanks to a license and a few people who never clean out their download folders. So, I don't know if you say Radio SS or radios, Radi OSS, something. Basically, it's a commercial solver from a company called Altair for more than 30 years. Now, according to Altair's 2022 press release, it was used by carmakers chasing 5-car crash ratings, aerospace firms simulating Bird strikes and hard landings, electronics companies dropping virtual phones. Well, on September 8th, 2022, Altair released it as open source under the name Open Radio OS, licensing under the GNU GNU Alf Alpharo GPL version three license. So Altair CEO James Scappa said. It allows everyone now to contribute.

Jeff Massie [01:08:15]:
Well, in March of 2025, Siemens finished buying Altair for an enterprise value of about $10 billion. Well, then October 1st of this year, OpenRadioOS vanished. The openradiooss.org website started redirecting to a Siemens product page. The GitHub repository started returning a 404. The project wasn't even archived read-only, which really is the polite way to retire an open source project. It was deleted. The GitHub organization page is still there with 193 followers, and it says, quote, this organization has no public repositories. So very brutal.

Jeff Massie [01:09:09]:
Siemens, uh, transition page puts it this way: after 4 years of successful community-driven research, Siemens is entering a new chapter for the Radio OSS solver. The next chapter is the commercial SimCenter Radio OSS, or whatever, you know, Siemens calls a managed Shared source program for academic and industrial partners. Shared source, for those curious, it's what you call open source when it isn't open anymore. First, let's just say, what does this software actually do? It's called— well, it's a finite element analysis program, or FEA. So say you want to know what happens to a car's front end when it hits a wall without actually buying a car and a wall. The physics of the whole car at once is far too complicated to solve directly, so you cheat. You chop the car in— into— on the computer into a mesh of thousands or millions of tiny simple shapes called elements. Kind of like building a car out of Legos.

Jeff Massie [01:10:29]:
Well, each element is simple enough that its behavior is easy to describe with an equation. The computer then solves all of those small equations together with each piece pushing on its neighbors. So out— the outcome is a prediction on how the whole thing bends and crumples and heats up or breaks. Uh, FEA is used for bridges, aircraft, phone drops, pretty much anything engineers would rather break on a computer first. Now, this FEA solver is what's known as explicit, and the— what they do is they step forward through time in a very small slice, which makes them good at violent, fast Events like crashes, explosions, impact. Now, like any open source software project where it suddenly becomes not open source, like in this case, well, there's a fork. So on the same day, October 1st, a project called OpenCurrent was announced as, quote, the community continuation of OpenRadio OSS. It's led by Brian Clemens, founder and vice president of the Rocky Enterprise Software Foundation, you know, the group behind Rocky Linux.

Jeff Massie [01:11:53]:
And the project even lives on Rocky Linux Mattermost. Just to be clear though, and Heiss says, this isn't yet. I don't know if yet is waiting to be or ever or... Not, but it's not an official Rocky Enterprise Software Foundation project. Now, Open Current calls itself independent and is asking for former maintainers to come back and decide how it's run. Germany's Heise reports that— this is like a news organization— that Siemens won't comment on the fork. Why it's legal is the whole point of the AGPL, and code is released— once code is released under it, nobody can take that permission back, including the company that wrote it. So OpenCurrent is the last public code that kept the full commit history with the contributors' names and kept the same license.

Jeff Massie [01:13:01]:
Now, actually saving the code was the easy part. Getting it to build and run was harder. The build system for the old— so the build system, the old OpenRadio OSS build pipeline ran on Siemens' own private infrastructure. So OpenCurrent had to rebuild it from scratch. The missing piece, a closed-source component that reads the input files called the reader, was never on the Git repo. Closed source. It disappeared along with everything else on October 4th. Clemens asked on GitHub for anybody who kept an older release file, and people had them.

Jeff Massie [01:13:42]:
One person found a copy on a Pharaonic server. Another dug out an August download and shared it over Dropbox. Each donation was checked by its checksum before use. So basically a $10 billion acquisition was partially undone by someone's downloads folder. Now, by October 6th, OpenCurrent was shipping builds for Linux, the x86-64, ARM, and even had Windows. That good news for Rob, all from one pipeline and checked on the same test suite. So basically when they ran a bunch of files through it, it came out correct. But this isn't finished because the recovered reader is an older version.

Jeff Massie [01:14:32]:
So one, one newer input feature is missing and one input keyword is rejected outright. So the long-term plan is to write a fully open AGPL reader. While they, you know, the license saved the code, they didn't have the bug reports, the discussions, pull requests, you know, the continuous integration history. All those lived on GitHub and are gone. Now, he also notes, this would be Heist, that because the contributors signed a contributor license agreement, Siemens could take future development proprietary without ever asking anyone. He summed it up as that AGPL protects the past, the CLA decides the future. Now, the name is kind of a bit of a throwback, a little bit of a nice touch for those who are really into math. Open Current honors the mathematician Richard Courant, In 1988— or 1928, he and 2 colleagues described a rule for how small an explicit simulation time steps must be before it goes unstable, which is exactly what solvers like this rely on.

Jeff Massie [01:15:52]:
Courant also did some of the early 1940s work behind finite element methods. So the fork is named after one of the people who helped make the software possible in the first place by his underlying theories and equations. So, you know, the short version, the crash simulator crashed. It got pulled from the wreckage and was up and running within, again, within a week, you know? Not bad for a tiny pile of triangles. Take a look at the Linux, the articles linked in the show notes and look up finite element method. And, you know, those that love calculus are in for a nice treat. It goes into partial differential equations and— People that have solved those know that it can be a little tough to solve some of those. So happy crashing.

Jonathan Bennett [01:16:45]:
Yeah, interesting stuff. I got a couple of things, I guess 3 things. People may wonder, like, how did they get away with this? Why does the HEPL let them do this? Or even, those that are not long-term listeners, like, how can someone fork it and bring it back? So it was under the AGPL license and there was a contributor license agreement. And so what that said was when someone contributed code to this project, the old project, the OpenRadiOS, they would also give a copyright assignment to that company that owned it. And so because that company had ownership of all of that copyright, They could then relicense it however they wanted to, even a not open source license. But the code that was released under the AGPL is AGPL code forever. It is available under that license forever. And so that's why they, people, the community were able to just say, oh, hey, I downloaded this here.

Jonathan Bennett [01:17:48]:
Let's just fork off of my download and continue going because all that code is still AGPL. And therefore people can continue to use it. And as far as like the rest of the story, it is a terrible move to have completely yanked the source code. It smells like an attempt to kill it, you know, in violation, not in violation of the law, but in violation of the spirit of the open source license. So like that part, I really don't like, but it is open source. The open source license is doing what it's designed to do, which is why Open Current That exists. So that's, that's my 2 cents on it. Rob, your thoughts?

Rob Campbell [01:18:33]:
Not really.

Jonathan Bennett [01:18:37]:
Rob is slow today.

Rob Campbell [01:18:38]:
I was getting tired.

Jonathan Bennett [01:18:43]:
Got bored.

Jeff Massie [01:18:43]:
Well, you know, like I said, it was a little math, you know, kind of math geeky and whatnot because it's kind of how calculus works as well and You know, the fundamentals of, you know, slicing things up smaller and smaller to find the more exact area under the curve. And yep, so if you, if you, if you really like math and that kind of stuff, look up finite element analysis method and it, uh, it'll take you down a good rabbit hole.

Jonathan Bennett [01:19:10]:
I'm sure. Yeah, absolutely. All right, uh, I think that's it for our stories. We're gonna take a quick break and then we're gonna come back and talk about some tips. Some, well, I think only one of them is actually a command line tip. We've been doing this show for a long time, guys. We're running out of command line tips, but we got some tips for you. Don't go anywhere.

Jonathan Bennett [01:19:30]:
They're still going to be great. We'll be right back. Let's come back and talk about some command line tips or not command line. Rob, is your tip on the command line? PC Gauge. That's what Rob wants to talk about. Is it on the command line?

Rob Campbell [01:19:43]:
Mine is on the command line.

Jonathan Bennett [01:19:45]:
Gasp. Good job.

Rob Campbell [01:19:46]:
Mine, you can run PC Gauge, it's a TUI, or you can run PC Gauge --trend and get a trend line. So this is just a quick little dashboard with gauges. If you don't run the trend, it doesn't have those, the trend lines below. It just has the 4 gauges, the CPU processor that's Bouncing around there. The memory that's obviously not bouncing around, storage not bouncing around, bandwidth, it's not doing anything for bandwidth. And then with the --trend, it's showing me a trend of, you know, the CPU going up and down and the other things just pretty much staying there. Oh, if you look at my net, there is a little, a little, little blip right there. It did something.

Rob Campbell [01:20:37]:
So I had a tiny little blip on my network on this computer. Obviously this is not on the computer that I'm streaming on. But so that's PC Gauge. If you want to just monitor the resources on a system in a nice little TUI dashboard.

Jonathan Bennett [01:20:58]:
That's actually really cool. I like that. I went ahead and ran it on my machine and yeah. That's neat. I like it.

Rob Campbell [01:21:06]:
I'm going to tell you when maybe you've noticed already, but when I can't think of a command line tip, I just make one. So yes, I did a little vibe coding of that one.

Jonathan Bennett [01:21:23]:
Everything is vibe coded these days. No getting away from it.

Rob Campbell [01:21:27]:
I'm not even embarrassed anymore to use Say that I coded it.

Jonathan Bennett [01:21:31]:
He's not even embarrassed.

Jeff Massie [01:21:33]:
Yeah, you can't spell pain without AI.

Jonathan Bennett [01:21:36]:
Yep. All right, Jeff, what's yours? Mockutil? Yeah.

Jeff Massie [01:21:43]:
Now, this is a real command line tip.

Jonathan Bennett [01:21:47]:
It's real, not like Rob's.

Jeff Massie [01:21:49]:
And it predates vibe coding. So, you know, we talked about Secure Boot earlier. In the show. So here's the command line tool that I mentioned, that mockutil. So when you think of Secure Boot as a bouncer with a guest list, you know, your firmware only runs bootloaders signed by a key that's on its list. Most Linux distros get past the bouncer with a small loader called a shim, which is signed by Microsoft. Shim then keeps its own guest list, and that's where you come in. That list is called a MOK list, M-O-K, short for machine owner keys.

Jeff Massie [01:22:32]:
These are keys that you, the machine's owner, have chosen to trust. MOKUTIL is a tool for viewing and managing that list. It's often already installed on distros that boot through a shim. So to see if Secure Boot is even on, you can do sudo mockutil --sb-state, and you'll get back plain Secure Boot enabled or Secure Boot disabled. You might also see a line saying platform is in setup mode, which means the firmware has no owner key enrolled yet. One gotcha for script This command exits with status 0 either way. It's telling you it ran, not what the answer was. So you have to parse the text, not the exit code.

Jeff Massie [01:23:23]:
Now, to see every key you enrolled, use sudo mockutil --list-enrolled, and it prints full certificate details. So for everything, it prints the full certificate. Pipe it into less. If you, you know, you're probably going to have a lot of scrolling there. You can also use the --list-new, which shows keys waiting to be enrolled. --test-key mykey.der. That'll check whether one specific key is already enrolled. And one place that a lot of times people run into the need for mockutil is, without meaning to, is Secure Boot.

Jeff Massie [01:24:04]:
You know, so when you have Secure Boot on, the kernel refuses to load modules that aren't signed. So when an NVIDIA driver, a VirtualBox, or any other DKMS module gets built on your machine, it has to be signed with the key, with, with a key the system trusts. So you can, you can do a, um, --import space and then like For Ubuntu, it's in the /var/lib/shim-sign-mock-mock.dir location. Definitely check the documentation on your distribution to find out where those keys are at. But you have to do that to make your modules load when you have Secure Boot on. You know, when you do that, it will ask for a one-time password. You know, because nothing— and when you do that, nothing is enrolled. You've only queued a request.

Jeff Massie [01:25:07]:
Now you reboot and you get a blue screen. But for once, this is a blue screen that you actually want. You actually want— that's Mach Manager. So then you choose enroll Mach, check the key, type the password you just made up and continue. And after that, your driver or whatever module loads with Secure Boot still on. Now, one thing that— and there's a ton more features, but one thing to be careful of, sometimes you'll see a guide which will suggest, oh, use mockutil --disable-validation. That tells the shim to stop checking signatures while Secure Boot is on. Basically, you know, like Ubuntu's documentation lists it as an option for people running self-built kernels, but you're basically telling it to stop, you know, that you're basically telling your bouncer to stop checking IDs.

Jeff Massie [01:26:05]:
So know why you're doing it because you then can load whatever. You're not checking any of the security anymore on what you're loading. Loading. Uh, one, one thing too is Art and CacheOS, um, when you set up Secure Boot with your own keys using a tool like sbctl, you might not be using shim at all, in which case the mock stuff we've been talking about doesn't apply to you. Uh, take a look at the link in the show notes for a man page to mock. And like I said, there's a ton more things it can do, but that's the high level we covered.

Jonathan Bennett [01:26:48]:
Yeah, very cool. Very cool. All right. I've got, like I said, it's not a command line tip. I came across a piece of hardware this week that is super cool. And I figured I would tell you guys about it. It is actually an Adafruit bonnet that has connectors for joystick and buttons on it. And, you know, you may think, oh, that's, Not very exciting.

Jonathan Bennett [01:27:09]:
Well, okay, so it's the way that it works is it doesn't take any of your GPIOs on your Raspberry Pi. So you can almost certainly stack it with another HAT. And it has an I2C breakout for all those GPIOs on it, which essentially means that you can build a plug-and-play arcade cabinet on top of your Raspberry Pi, which is essentially what I've done, what I've been working on. Went ahead and threw a picture of this build in progress. It's all inspired by Jeff Geerling and the little 10-inch racks that they use at the home lab stuff. I finally convinced myself I needed one of those and it came and I went, well, now what am I going to use it for? And this is the project that I've started on now is sort of turning it into a little Meshtastic-powered arcade, which is coming along quite a bit. I made the statement that now that it works and my kids have discovered it, I'm never getting it back. It's going to be theirs forever.

Jonathan Bennett [01:28:03]:
And in fact, on the picture that I have shared here, that's my daughter's hands on it playing Tetris. So, but a lot of fun. I wanted to make you aware of that for those Raspberry Pi heads out there like me that like being able to plug in real-world hardware. If you want to do a joystick and some buttons and build your own arcade, there you go.

Rob Campbell [01:28:20]:
It works.

Jonathan Bennett [01:28:20]:
It works really well, actually. So pretty, pretty cool piece of kit to know about. All right. That is it. That's the show. I'm going to let the guys plug whatever they want to. We'll let Rob go first. first and then Jeff.

Jonathan Bennett [01:28:34]:
Rob, what you got for us?

Rob Campbell [01:28:38]:
All right. Well, as usual, I'll post, I'll plug my website, robertpcampbell.com. And there you can find links to my LinkedIn, Twitter, Bluesky, Mastodon, and a place to donate a coffee in $5 increments. I have been posting on LinkedIn, Bluesky, and Mastodon very regularly about 5 to 6 times a week or more, um, give or take. So in fact, my story on ArtCraft, I had posted that on there before Pharaonix even had the story up. So that's why I don't have the Pharaonix story on my, uh, on the show notes, because I beat him to it. So follow me for, uh, for stuff.

Jeff Massie [01:29:24]:
Yes.

Rob Campbell [01:29:25]:
Mostly been posting on Linux and security, about half and half. And also, if you want to know even more about me, my whole backstory, and Jeff could tell you more about this too, but check out my book. People have, you've already missed the sale, so you can't get the ebook for $2.99 or whatever it was. They could still buy it all at the regular price. Or you can get the Kindle Unlimited and use as one of your free options or whatever that is. I don't even know how that works. But if you go to my website, scroll down or click the memoir button at the top, and then you can hit the buy on Amazon, or you just search Trailer Park to Technology Leader on Amazon, find my book and buy it and hear about my life, my trajectory from growing up, being born on the day of a cold winter storm, to my trajectory to technology leader.

Jonathan Bennett [01:30:31]:
It's a real sob story. All right, Rob, thanks so much. Jeff, what you got for us?

Jeff Massie [01:30:38]:
Well, it is a Rob story anyway. 2 little things. Hey, I'm a dad. I can make those jokes.

Jonathan Bennett [01:30:45]:
Yeah, I know.

Jeff Massie [01:30:46]:
2 little things. One is I mentioned about the problems I was having coming back from like a KVM or display switch. NVIDIA came out with a new driver. It does not fix the problem, but I did see some workarounds saying that if you switch your refresh rate to 100Hz or lower, that can sometimes bypass it because then it's not using some of the compression, and because the compression going over your DisplayPort or HDMI cable is where the signal communication gets messed up. So we're just, we'll keep an eye on that.

Jonathan Bennett [01:31:29]:
So actually, Jeff, that's actually real similar to a problem that I've got. And I will tell you the workaround that I use. I'm curious if it works. The virtual terminals, I can use Control+Alt+F1 to switch to virtual terminal. Stay there until the TV actually turns itself back on and then switch back and it'll come up. That might be something to try, maybe a little bit quicker for you.

Jeff Massie [01:31:46]:
It won't do it.

Jonathan Bennett [01:31:47]:
It doesn't do it?

Jeff Massie [01:31:48]:
It does not do it. I cannot get— it does not register a signal on anything. So switching, just, it just says, nope, there is no display here and the GPU will not send anything. So I have to SSH in to actually reboot to get the signal to come back.

Jonathan Bennett [01:32:09]:
The GPU doesn't see it and therefore won't shoot the signal out.

Jeff Massie [01:32:12]:
Yes.

Rob Campbell [01:32:13]:
Okay.

Jonathan Bennett [01:32:14]:
Yep. Different problem. All right. Continue on.

Jeff Massie [01:32:16]:
Yes. The other thing is Poetry Corner. Fingers tap away. Coffee fuels a bright blue screen. Syntax errors dance. Have a great week, everybody.

Jonathan Bennett [01:32:31]:
Yep. Awesome. Appreciate you guys being here. It's been a lot of fun again. And yeah, if you want to find more of me, there is of course Floss Weekly. We plan to be back this Tuesday. We've got a guest lined up and about a month worth of guests lined up and more people on the docket. So that'll, it'll probably take us until my next business trip, which I'm sure we'll get behind on again, but that's all right.

Jonathan Bennett [01:32:52]:
That's just, that's just life for me right now. And other than that, for those that are there, those that are here with us, we want to say thank you. Appreciate everybody, whether you watch or listen, whether get us live or on the download. And we'll be back next week on the Untitled Linux Show. Thanks, everyone.

All Transcripts posts