Episode: 4518 Title: Cosy News Corner for Week 46 - Your source for Open Source news Source: https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4518/hpr4518.mp3 Transcribed: 2026-07-31 16:13:06 (official HPR transcript) --- This is Hacker Public Radio Episode 4518, for 2025-11-26 Today's show is entitled, "Cosy News Corner for Week 46 - Your source for Open Source news" The host is Daniel Persson and the duration is 00:19:27 The flag is Clean, and the license is CC-BY-SA The summary is "This week’s open-source roundup." Hello and welcome to the cozy news corner for open source news and this is going to be for the week of 46 and this is not something that I will produce highly. It's just talking through a bunch of news and then publishing so this will go out on my youtube channel and I also will publish it on hacker public radio as a podcast so let's switch over so we can see some screens here but I'm going to talk about it it's just so you get some visuals on youtube and the first news is Debian that now mandates that rust should be used for a PT the advanced packaging tool and this is something that is talked about in their news group by a person called Julien and Ress Claude and he's a long time developer in the Debian community and also in lead maintainer for this tool so he him going out and saying that this is the way forward you should switch over so all the ports are using rust going forward and you have about six months to do it or else pretty much so Debian will switch over to using rust for this tool and a lot of different things in Debian it's actually switching over to using rust and a lot of things in the Linux world is starting to use rust as well we have some things in the kernel that is using rust and more and more of the tools in the guinea libraries will also go over to using rust and one thing that I want to mention here that I listened to a talk about this by Brian Cantrell and this was the complexity of simplicity and this was a keynote that he was given at the tallest cone and he's the oxide co-founder and CTO and this was in Amsterdam in October the 17th and to quote him he went into rust pretty skeptical and honestly he came back realizing that there were many things that he viewed to be essential complexity that weren't that were actually accidental complexity and when it comes to rust one of the big things there was the error handling so what did he mean by this so the whole talk is about complexity and making things that are simple is actually pretty hard you need to put a lot of work into make something simple but if something is simple and easy to understand it's less error and when it comes to C and so on you can write wonderful applications in C but they might become very complex and when you take that concept and take a new look at it you can produce something like rust that has taken a lot of thought and worked a lot in order to make the code less brittle more simplistic and easier to talk about and understand so that is pretty much what he is aiming at here I would guess after looking at this talk I would recommend you look at a look at his talk as well and listen to it's a lot of good and fun information is a great speaker I think next up you're going to talk about some vulnerabilities in rust not particularly rust but one thing written in rust so this is the pseudo errors so the pseudo command written in rust not public any at the moment not the main thing used in the piano or a banto but it's a rework and they are working against it and trying to get it into a banto as a stable release and they have found two bugs and they are not great but it's good that they actually find these before any release so the first vulnerability was that the password could be exposed due to timeouts that isn't ever good and another thing is that incorrectly recorded it incorrectly recorded the wrong user in a time stamp and the reason that but is that some authentication could be reused if you have cash credentials so it's something that they need to look into and both these were reported by two different medias here so the first media about the bian rust was reported by Steven Vogue Nichols at the news stack and then we also have this report by pseudo errors by Sudrov Ronda that is writing for its false so I'm gonna mention these as well so you know who have written the story and who should have created for it. Next up I was also reading another story at the news stack was written by Lorraine Larson and this is about snapshot and snapshot has actually released an open source framework that they are using in order to write applications for iOS, Mac OS and also Android and it's writing code in JavaScript in order to create GUI components and work with those kind of tooling in native code so you write JavaScript and then this framework will compile it to native apps so if you're looking for a crossplot form UI from framework then perhaps this snapshot open source library is something that you need to look into and it could be an option for you at least and now over to our first piece of AI news and there is a bunch of AI news out there and now we're going to talk about a company called solo I oh so not AI I oh so this is another title that is written by Heather Yoshlin the news stack and this is talking about an agent registry for AI agents so when you have these kind of endpoints with mpc this protocol this model context protocol where you can talk to agents on different sites there is a bunch of different agent regicies out there but most of them are close source and behind pay walls and so on but solo I oh has a solution that they have been using for a while now and they have now released their agent registry as open source so if you need this then you can install that and use it locally on your organization um I have not looked into either agents or agent registries yet that is still a blind spot of mine but perhaps in the future if it's interesting I could look into this more so next up we have a little bit of a controversy and it has been a problem for a while still in the AI field and this was reported by sort of ruda and from it's false and it's ffm peg and they are pretty angry about a lot of different complex contributions from AI so again we create these kind of CVSs where we say this is a very bad bug that you have in your application you need to fix it and it's AI slot pretty much in this CVS and they are pretty fed up with it and they are just a bunch of volunteers that are trying to create the best movie viewing and movie managing system so ffm peg is where you can take a bunch of different clips either audio or movies and you can do operations on them and they can read pretty much any video filed that has have been made it's an awesome application but it's just made by a couple of interesting parties and none of them are working for none of them are really getting paid for it or at least not paid well so they are pretty fed up they are swarmed with all these kind of issues and they don't have the actual capacity to solve them all and they have reached out to Google and said we need some funding here if we're going to work on this full time and so it has been a really bad time for the ffm peg guys and this is not the first time that AI has been used in order to swamp developers with either bad PRs or with the problems that isn't really a problem it's just something that someone found and reported because they thought that that could be a huge problem and another person that I've talked about this is Daniel Steinberg and he has is the sole developer of the curl project and he had a time where he just ignored CVEs because there were so many of them and they were not really good either pull requests or actual issue reports so AI will create a lot bunch of slop and will make it much harder to do development in this case another person that also has reported this is Steven J. Vaughn Nicholas at the news stack so I read both of those reports but they are talking about similar things behind the ffm peg and they're problem with all these CVEs. Next up we have Ubuntu that is now released information about their commitment for handling releases and LDS releases and giving security and support and this have been a big topic in the Microsoft world where they now not give any more security fixes for Windows 10 and they are leaving a lot of people behind that can't install Windows 11 because they have two old computers and so on so this have been in the news a lot and a lot of people are angry on Microsoft and Microsoft have been pretty good bit creating both security fixes and supporting their operating system. I looked back and both Windows 8 and Windows 10 has had 10 years of support from their initial release until pretty much a month ago where they stopped supporting Windows 10 and then they said okay if you're in the EU or if you have enough Microsoft points or want to send some information to us so we can benefit of having all your information and you can still continue using Windows 10 or else you need to upgrade to Windows 11 but they have a 10 years support cycle and remember how large the team at Microsoft is. Ubuntu is a very serious player in the Linux world but they are not as large as Microsoft and they have now released and said we will support our operating system up to 15 years with some caveats so the standard maintenance window for each release of LTS which is the long-term support conversion will be five years so they give support and security fixes for five years for all their customers even if you have not given them any money at all and if you are a pro subscriber which I am as well and if you are an individual not the company those are also free or at least there were free when I became a pro subscriber you will get another five years so year 6 to 10 will also be supported by this pro subscription and you can also call in and get support by their support team. Next five years a year 11 to 15 is something they call a legacy add-on for security coverage and support and this is also for pro subscribers but they will add an extra fee of 50% for those five extra years but still I think that is a very small cost if you really need to have old versions of a bonto and having something that you can run in production for 15 years without upgrading that is pretty cool so I think this is actually a really cool thing that they have come out with and it's also perhaps a little bit of pointing at Microsoft that you could have done this as well you have the resources and I think it's a pretty cool this was reported by Sirov Rudai again at it's the boss and another thing reported by the same person is the firefox built in AI so firefox has had built in AI for a while now where you had an extra feature that you can open up in order to summarize pages and so on and do different queries to different AI agents online and because we all are starting to use AI they have now taken it away forward so before you have this classical tabs where you search for things or browse the web and if you were in a case where you needed to be more privacy minded perhaps you needed to visit the site that you didn't want it to be saved on your computer you could go into privacy mode of course still every call goes through your ISP and so on so somebody could look up what you have actually looked at but at least it doesn't store any information on your computer that's privacy mode the next mode that they have is the AI window so if you're open up an AI window then you have those tools ready at hand in that concept and there here have been a bunch of backlash on this AI window people don't really want it and so on or at least they try to be before anyone creating a lot of information about this so they are saying that this is something that is optional you don't need to use it it's available to you if you have the need but you don't need to use it so don't be angry at us but they haven't really come out and tell told us what it actually could do it's a way of browsing the web in a gigantic way but they haven't really told us how it actually how it will look or anything like that it's something that they are working for but it's coming soon so that is something that could be interesting to look into and see when it actually is released and have some first hand knowledge about and check out when it actually is released so that was the report by Citroen Rudolf from its force and also from Ajit Varma at the distilled so next up we're going to talk about a Linux distro called Nitrox 50 oh so this is the five big release that came out this week as well and it's a some Linux system for modern computers on an immutable foundation and it's powered by open RC instead of system D and it has hyperland and so on so before simplicity and predictability and main attainability is their catchphrase for this operating system and looking at it is very Mac like so it looks like any of the newer Mac OS and perhaps that's good you have familiarity it seems like you have multiple desktop and so on and also some performance and other metrics right in the operating system I haven't worked with this haven't tried it out but it's an option and it looks interesting and it was released this week and last but not least we are going to talk about a new project that has been open sourced and it pretty much have been open sourced all the way it's just started off this week that they released that it was in the making and looking at the commits it's very very they are actually working on it right now so last commit was yesterday and this is a Vulcan based implementation of DirectX7 so for applications and games that are pretty old they are now trying to create this layer that you can use in order to play them in Linux under so this is interesting and something that is in the making and we'll probably get into some wine release later on but it's just starting work now so we already have a bunch of implementation for DirectX12 and so on so we already have a lot of Windows native support for newer games and applications but they are slowly but surely working it they're very back in order to support even more applications and games so this was what I wanted to cover today I hope that you found this interesting You have been listening to Hacker Public Radio at Hacker Public Radio.org. Today's show was contributed by a HPR listener like yourself. If you ever thought of recording podcast, click on our upload link to find out how easy it is. Hosting for HPR has been kindly provided by an AnHonestHost.com, the Internet Archive, rsync.net, and our mirror network. Unless otherwise stated, today's show is released under a Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.