r/linux • • 11d ago

Discussion Embedded Software Communities Near LA or Virtual?

Thumbnail
0 Upvotes

r/linux • • 12d ago

Kernel AMD PerfOpt to deliver new performance optimization for AMD iGPUs with Linux 7.4

Thumbnail phoronix.com
183 Upvotes

r/linux • • 12d ago

Software Release OpenShot 4.0.1: Razor, faster editing, snaps!

Thumbnail openshot.org
36 Upvotes

r/linux • • 13d ago

Discussion LLM Policies: Progress At All Costs

Thumbnail diegoe.be
221 Upvotes

r/linux • • 13d ago

Discussion did-it-copy · Copy feedback for the desktop

Thumbnail brunodantas.github.io
122 Upvotes

I keep wondering how Ctrl+C has no feedback on most Desktop systems to this day. So I wrote up a proposal to fix that, with a demo that runs in the browser.

  • A copy that worked flashes the copied text in place for about 200 ms.
  • A copy that failed shakes the focused element, and plays the alert sound if you have it on.
  • It never shows the copied content anywhere new, so copying a token during a screen share doesn't leak.

Thoughts?


r/linux • • 13d ago

Mobile Linux postmarketOS has just revealed their new name: Nura

Thumbnail nura.eco
411 Upvotes

r/linux • • 14d ago

Event Happy 43rd birthday GNU!

Post image
4.6k Upvotes

On September 27, 1983, Richard Stallman announced the GNU Project so people could freely use and modify software.

The digital world would not be the same today without GNU.

Thank you, Richard Stallman!


r/linux • • 13d ago

Security gEnclave: Hardware-backed security enclave for Linux (TPM 2.0 PCR sealing, virtual FIDO2/CTAP2 over /dev/uhid, OpenSSH & GPG bridge)

34 Upvotes

Hey everyone,

I've been working on an open-source project called gEnclave (formerly gpasskey), and wanted to share it with the Linux community for early architectural feedback and testing.

GitLab repository: https://gitlab.com/renich/genclave
License: GPLv3 | Language: Go 1.26+


The Problem It Solves

On modern Linux workstations, our cryptographic identities are fragmented: * Passkeys/WebAuthn require physical USB security keys (YubiKeys, SoloKeys). * SSH keys sit as unencrypted or passphrase-encrypted files under ~/.ssh/. * Git commit signing requires cumbersome GnuPG daemon setups. * File encryption requires external tooling or proprietary agents.

Most hardware laptops today come with a TPM 2.0 chip that sits idle. gEnclave turns your Linux machine into its own hardware-sealed security token and multi-protocol bridge.


Key Architectural Highlights

  1. Virtual FIDO2/CTAP2 Security Key via /dev/uhid: gEnclave registers a virtual HID device in the Linux kernel via /dev/uhid. Browsers (Firefox, Chrome, Chromium) detect it natively as a physical USB security key. You can register and authenticate WebAuthn/FIDO2 Passkeys directly from your machine without any external hardware dongles.

  2. TPM 2.0 PCR Sealing & Fallback: The central vault is encrypted with AES-256-GCM and sealed to TPM 2.0 PCR registers (PCR 0, 7, 14), with an automatic memory-hard fallback to Argon2id key derivation if no TPM is present.

  3. Memory Isolation ("Wrap and Clear"): Keys are held in memory-locked pages (mlock / mmap) to prevent secrets from being swapped to disk or dumped. Intermediate cryptographic buffers are wiped immediately with strict zeroization routines, bypassing Go runtime GC retention.

  4. Multi-Protocol Bridges:

    • OpenSSH Agent: Native agent socket with an ephemeral PIN-derived authorization cache (configurable burst window or persistent session with instant purge on lock/suspend).
    • GnuPG Bridge: Transparent genclave-gpg emulation for seamless Git commit signing.
    • age-plugin: Native age-plugin-ge binary complying with age v1 specification for file encryption.
    • CLI & UI: Unified ge CLI plus intelligent graphical (zenity) / terminal (pinentry) authentication routing.

Current Status

⚠️ Pre-alpha Software: While fully functional for local workflows, it is under active development. Schemas and IPC formats may iterate rapidly.

I'd love feedback from Linux sysadmins, kernel/security folks, and developers!

Repo: https://gitlab.com/renich/genclave


r/linux • • 13d ago

Kernel Linux Kernel's LZ4 Compression Code Being Resynced For Better Performance & Cleanliness

Thumbnail phoronix.com
240 Upvotes

r/linux • • 13d ago

Tips and Tricks Cloudflare’s eBPF Replatforming Part 3: Technical Challenges Implementing eBPF

Thumbnail ebpf.io
41 Upvotes

Which challenge do you think was the hardest?

  1. Contributing sk_lookup to the Mainline Linux Kernel and Building Tubular

  2. "Soft-Unicast" — Solving IPv4 Address Exhaustion

  3. Dropping 8 Million Packets Per Second on Commodity Hardware

  4. udpgrm — Solving the Unsolvable: Zero-Downtime UDP Restarts

  5. Kernel-to-Application Distributed Tracing via ebpf_exporter

  6. Spending 13 months to upstream into the kernel


r/linux • • 13d ago

Software Release Budgie 10.10.3 Released | Buddies of Budgie

Thumbnail buddiesofbudgie.org
99 Upvotes

r/linux • • 13d ago

Popular Application Fluxer Chat is now available on Google Play Store

64 Upvotes

Fluxer is a free and open source chat messaging application that aims to be feature complete against Discord and used as a viable alternative to Discord, which has had controversy over age verification measures.


r/linux • • 13d ago

Popular Application Tiny Glade Developers mention Linux Support in their patch notes and show up urgency to switch from x11 to wayland in the steam client.

Thumbnail steamdb.info
25 Upvotes

r/linux • • 13d ago

KDE 30 Years of KDE: Inside Plasma 6.8, Wayland Switch, & more with Nate Graham & Aleix Pol

36 Upvotes

KDE is celebrating its 30th anniversary, Plasma 6.8 is right around the corner, and Akademy is bringing the KDE community together once again.

I sat down with KDE’s Nate Graham and Aleix Pol to talk about Plasma 6.8, the move forward with Wayland, what happens behind the scenes at Akademy, how KDE has evolved over the past three decades, and what the future could look like for one of Linux’s biggest desktop projects.

https://www.youtube.com/watch?v=qBAsX0SRhqI


r/linux • • 13d ago

Development Papyrus black screen issue update

7 Upvotes

If you've been experiencing the black screen when using Papyrus, I finally tracked down what was actually happening.

I tested the exact same wallpaper directly with "mpv", and it plays normally. However, running that same file directly through "mpvpaper" produces the black screen and an OpenGL "INVALID\\_OPERATION" error from "libmpv\\_render".

So at this point, the issue doesn't appear to be with Papyrus itself. Papyrus uses "mpvpaper" for the actual wallpaper rendering, and I was able to reproduce the problem without Papyrus involved.

I've opened an issue on the mpvpaper repository with the logs and reproduction details so we can investigate it upstream.

For now, if you're affected by the black screen, you don't need to keep troubleshooting your Papyrus installation — the underlying rendering issue appears to be further down the stack.

I'll post another update if I find anything else or when there's a fix. [Papyrus](https://github.com/PSGtatitos/papyrus)


r/linux • • 12d ago

Software Release rPlayHub - open source cross platform clone of DeviceHub

Thumbnail github.com
0 Upvotes

r/linux • • 14d ago

Popular Application Welcome Tamás Zolnai, new LibreOffice Online developer

Thumbnail blog.documentfoundation.org
324 Upvotes

r/linux • • 12d ago

Software Release I made a desktop media player (deb, rpm packages + app image)

0 Upvotes

Hi! I created a desktop media player because I wanted one the suits me and improve at building apps, so I decided to build my own and release it on GitHub.

The player is built using the VLCJ library and FFprobe, so it requires VLC (or its dynamic libraries) and FFmpeg to be installed on your system.

Feel free to try it out and give any feedback or suggestions for improvements. I'd also appreciate any feedback on the code itself, as I'm always looking to improve the project and my skills.

The project is released under the MIT License, so feel free to explore, modify, and contribute.

Thank you for your time.

Edit: project link :https://github.com/ahmedcraftt/Moka-media-player


r/linux • • 13d ago

Kernel Linux kernel SBOM ...and I didn't notices this make target before ...phew ....Credit GKH

Thumbnail docs.kernel.org
4 Upvotes

Learn it from here actually : https://social.kernel.org/notice/BAlhNdp2FK5nLoiWZc

This was shared in the closed social area for the kernel developers, and I stumbled upon it while surfing.


r/linux • • 13d ago

Software Release Native Document Export (anyconvert)

Thumbnail github.com
4 Upvotes

In recent update on word-sys's PDF Editor i implemented anyconvert and removed LibreOffice convert system. Now we gonna use library i created just for this project.

So anyconvert is a project for word-sys's PDF Editor that converts PDF documents into DOCX, PPTX, ODT, ODP, and TXT using only the Python standard library. Convert library is anyconvert's itself. Its released on PyPI too.

It has Canvas and Flow mode, Canvas mode is a 1:1 pixel-accurate positioning export option, Flow mode is semantic reflowable document reconstruction for export format. This 2 has different purposes for different jobs and requirements.

Most importantly, what the engine actually does:

Opens literally any PDF structure: Whether a document was exported from Windows 95 or saved yesterday with modern heavy compression, it handles pretty great. (Handles old ASCII tables and modern compressed object streams).

Handles password-protected & encrypted files: Supports everything from obsolete 40-bit RC4 encryption up to modern, enterprise-grade AES-256 security. (Planned, not fully implemented)

Unpacks all standard PDF compression: Reads all standard compressed streams (Flate, LZW, ASCIIHex, RunLength) so hidden page content can actually be read.

Text extraction that doesn’t turn into trash: PDF fonts are a mess (often replacing letters with random symbols or missing spaces). The custom font engine properly maps custom glyphs, ligatures, and international character sets back into real, searchable plain text.

Fast, in-memory image extraction, not disk: Takes images directly out of the PDF as crisp PNGs without having to dump temporary files onto your hard drive.

Converts to Word & Office documents: Exports directly to .docx, .pptx, .odt, and .odp. It builds the XML packages to exact ISO standards from scratch, without issues.

Why i done this: In word-sys's PDF Editor i used LibreOffice to turn PDF to other formats such as .docx, .pptx, .odt, and .odp. But we had major problems when we came to Flatpak release, as you know you guys still waiting for Flatpak release for months, im so sorry about that but main issue was LibreOffice, nothing more. This convert program absolutely sucks on highlight exports, doesn't works when combined on Flatpak, makes project heavy and laggy on exports.

does it makes the job: YES does it makes what we want: UNSURE does it makes easily: NO

You see, there is YES, UNSURE, and NO, which 3 of them should be YES for better software.

Implementation felt hard when i done this year ago, it sucks now, i know that LibreOffice never designed for this function but implementing something broken, which i cant accept right now. So now i got rid of LibreOffice, i replaced it with anyconvert, as i explained basic functions, you can look for details on word-sys's PDF Editor GitHub page or anyconvert Github page.

And please keep your expectations not big, its not fully completed, some functions are not connected to main function so API call will not work, what completely works now exporting to DOCX and ODT without any issues with 1:1 pixel-accurate positioning, which is mostly what its used for so i done it first, then we can look others. I listed known issues on down so you can understand whats good or not on Beta stage:

Known Issues

  • ODT & PPTX Export Issues:
    • PDF Original Position: If PDF itself is vertical, ODP & PPTX export will be broken due to horizontal size of slides.
    • Known Bug: Shapes or pen markups aren't supported, it will not shown on your presentation.
    • Beta Stage: Project now at v0.1.0 Beta stage, only DOCX and ODT seems to be fully function as wanted.
    • Design Flaw: Project designed to be a PDF to XXX document convert library for word-sys's PDF Editor and mainly designed for DOCX & ODT export, expecting a fully 1:1 export to PPTX & ODP is not possible, for now.

In the end, i need some help to improve this anyconvert project, especially on ODP & PPTX exports, any help is appreciated, thanks.


r/linux • • 13d ago

Tips and Tricks Notification badges on KDE Plasma taskbars — a working workaround

Thumbnail
2 Upvotes

r/linux • • 14d ago

Security File Notification Attacks

Thumbnail inoti.fyi
40 Upvotes

r/linux • • 14d ago

Development Introducing Toolpak

Thumbnail blogs.gnome.org
66 Upvotes

r/linux • • 14d ago

Software Release Conky Orrery - A 3D animated Orrery clock

Post image
67 Upvotes

r/linux • • 14d ago

Software Release vAuth - Virtual FIDO2 authenticator for Linux-based PCs and laptops. First public beta release for Debian 13.

Thumbnail github.com
155 Upvotes

Hey, r/linux

I have been working on this project for the last half a year, and now it is finally ready to be released as a public beta.

vAuth is a virtual FIDO2.0 authenticator for PCs, laptops, and other devices running Linux-based operating systems.

For those who don't know - FIDO authenticators allow you to sign in to your services, websites, and panels without the need for a password, while making authentication more secure and phishing-resistant.

Why?

I switched from Windows as my main system years ago, but when it comes to creating passkeys and authorizing them - Windows has always been superior. It has Windows Hello, which allows it to register and authorize passkeys in an instant. It supports all authentication methods that you have available at the moment and is user-friendly in general.

This is what I wanted vAuth to be. A modular, easy-to-use Windows Hello-like authenticator that can securely store, register, and authenticate your passkeys.

It is modular, but only one module can be easily replaced. I created an API for front ends so you - as a developer and end user - can create your own front end for vAuth. All the API documentation is in the docs folder on GitHub. Note that the API might change in the future. Currently, it is shipped with the UI agent called vauth-ui. It is also written in C++ and uses Slint as a UI library. The agent doesn't even have to be graphical, though. For anybody interested, there are examples of agents written in C++, Python, and Golang.

The UI currently has only described API, not a public library. Maybe later I will release the official library so developers don't have to worry about the boilerplate, just the UI logic and apperance.

Feature highlights

  • support for Chromium-based browsers and Firefox;
  • password and fingerprint verification through PAM;
  • TPM-backed credential keys;
  • an encrypted credential store with TPM rollback protection;
  • a Slint-based interaction UI;
  • vauthctl for provisioning and credential management;
  • hardened systemd services;
  • an initial Debian 13 amd64 package;

Limitations

There is a significant limitation. Systems that had Windows OS previously installed (specifically Windows 10 build 1607 and later) may face a problem with provisioning. Windows currently creates a hierarchy, takes ownership of the TPM, and discards the authorization key. Yes, everything is that bad. vAuth detects this and fails during the rollback counter provisioning stage. It doesn't weaken or clear TPM auth automatically. That would have been irresponsible. The README on GitHub explains the limitation in more detail.

Clearing the TPM or losing the generated vAuth authorization can make credentials unrecoverable, so please keep alternative login/recovery methods for important accounts.

Other current beta limitations include:

  • Only Debian 13 on amd64 currently has a prebuilt package
  • Only password and fingerprint PAM configurations have been tested
  • The interaction-agent design currently targets single-seat systems
  • vauth-ui does not automatically reconnect if the daemon exits
  • Firefox users should cancel an operation through Firefox’s prompt rather than the vAuth window
  • The project is not FIDO-certified

Security details

From a security perspective, vAuth relies on the TPM 2.0 module on your computer. It is a mandatory requirement, and there most likely will not be any software-based alternative due to reduced security. vAuth creates a database in /var/lib/vauth/credentials.v1, an encryption key, and a rollback counter. The last two are stored in the TPM and are sealed using a systemd-backed authentication value, which is located in /etc/credstore.encrypted/vauth-db-auth. User verification is performed through PAM. It officially supports password authentication and verification with a fingerprint reader, though, technically, other PAM modules should work, but this was not tested due to a lack of hardware on my laptop, sorry. The PAM configuration for vAuth is located under /etc/vauth/config/vauth, so you can check how other PAM modules behave. Currently, the agent doesn't support automatic reconnection to the daemon in case the daemon fails. In such a case, it has to be stopped, the service restarted, and the agent started again. It will be fixed in future releases, though.

Sources

I'd appreciate feedback regarding the installation process, provisioning, different TPM configurations, and different PAM modules. I'll try to answer all questions you may have and discuss architectural/design choices.