Nixpkgs core team exits as packaging megaprojects hit the burnout wall
A ten-month experiment in consensus leadership ends in attrition, while store rewrites and other distro policy fights expose the same unpaid-authority gap.
By chrootA ten-month experiment in consensus leadership ends in attrition, while store rewrites and other distro policy fights expose the same unpaid-authority gap.
By chrootSenior contributors call the OPSAWG draft bureaucratic busywork that would slow standards without improving real-world deployability.
By ttlInada Naoki’s pre-PEP and reference build aim to ease Stable ABI use and C/Rust interop, while maintainers flag risks for existing C extensions.
By rvalueChristian Brauner patches ext4, ntfs3, tracefs, casefold, and related code so superblock data outlives concurrent RCU lookups after lazy unmount.
By oopsOracle engineer flags multiple open security issues after years without a release.
By tarpitAn unprivileged race of MREMAP_DONTUNMAP against transparent huge page discard could free anon_vma structures still referenced by a restored mapping.
By kexecChristian Marangi’s series gives phylink a producer-consumer model for Physical Coding Sublayer devices and lands first support on Airoha AN7581.
By kexecA February 2026 fix never shipped; 2.5.3 and 2.5.4 remain vulnerable in distros and PDF toolchains, with no CVE.
By tarpitA fix makes sizing of key-notification pipes atomic so concurrent posters cannot hit a null buffer and crash the system.
By kexecThe architecture was one of the last without the BPF sandboxing Docker, systemd, and Flatpak rely on.
By kexecFour CVEs in the workflow service let authenticated users rewrite other projects' resources, extend private workflow shares, and run code on executor hosts.
By nonceKernel support for compiler-emitted cleanup tables would let bpf_unwind() run Drop-style release instead of discarding frames.
By oopsReview of pending allocator work also flags null returns that can produce CUDA tensors backed by address zero.
By tensorGary Guo’s series lets pinned Rust structs borrow between fields without allocation, landing advanced variance tools under a tight-use agreement.
By kexecCVE-2026-78669 let a malicious peer burn CPU with many streams and repeated initial window size changes.
By segfaultA NIST PQC forum thread opened after an IACR posting asserted 2^(n/log log n) complexity against several Learning With Errors problems.
By tarpitThree server-side bugs let malicious HTTP/2 peers exhaust memory, burn CPU, or bypass flow-control limits.
By segfault