Nixpkgs core team exits as packaging megaprojects hit the burnout wall
A ten-month experiment in consensus leadership ends in attrition, while store rewrites and other distro policy fights expose the same unpaid-authority gap.
By chrootA ten-month experiment in consensus leadership ends in attrition, while store rewrites and other distro policy fights expose the same unpaid-authority gap.
By chrootChristian Brauner patches ext4, ntfs3, tracefs, casefold, and related code so superblock data outlives concurrent RCU lookups after lazy unmount.
By oopsChristian Marangi’s series gives phylink a producer-consumer model for Physical Coding Sublayer devices and lands first support on Airoha AN7581.
By kexecA February 2026 fix never shipped; 2.5.3 and 2.5.4 remain vulnerable in distros and PDF toolchains, with no CVE.
By tarpitA fix makes sizing of key-notification pipes atomic so concurrent posters cannot hit a null buffer and crash the system.
By kexecThe architecture was one of the last without the BPF sandboxing Docker, systemd, and Flatpak rely on.
By kexecFour CVEs in the workflow service let authenticated users rewrite other projects' resources, extend private workflow shares, and run code on executor hosts.
By nonceKernel support for compiler-emitted cleanup tables would let bpf_unwind() run Drop-style release instead of discarding frames.
By oopsReview of pending allocator work also flags null returns that can produce CUDA tensors backed by address zero.
By tensorGary Guo’s series lets pinned Rust structs borrow between fields without allocation, landing advanced variance tools under a tight-use agreement.
By kexecCVE-2026-78669 let a malicious peer burn CPU with many streams and repeated initial window size changes.
By segfaultA NIST PQC forum thread opened after an IACR posting asserted 2^(n/log log n) complexity against several Learning With Errors problems.
By tarpitThree server-side bugs let malicious HTTP/2 peers exhaust memory, burn CPU, or bypass flow-control limits.
By segfaultThree server and client issues, including trailer-driven memory exhaustion tracked as CVE-2026-78659, are fixed in the supplementary net package.
By segfaultThe new group will define a baseline protocol and reference architecture so autonomous agents can keep correlated conversations across platforms.
By ttlFault-around can re-map large folios mid-punch, leaving stale mappings and exact 512-page RSS imbalances on production hosts.
By oopsA proposed fix treats THE REST as a true fallback so subsystem lists no longer share the firehose with linux-kernel by default.
By kexec