A final selection of the most significant and notable events of 2024 related to open projects and information security:
- Conflicts: The crisis in the NixOS project. Exclusion of Sonny Pierce from the Board of Directors of the GfNOME Foundation. Temporary suspension of the author of BcachFS and his criticism by Linus Torvalds. Removal of one of the key Python developers. The conflict between WordPress and WP Engine, culminating in the replacement of the ACF plugin. Attacks on CoreBoot by Malibal. A complaint to the European regulator against Mozilla. Blocking of uBlock Origin Lite. Rebranding of Apache due to the indigenous peoples.
- Sanctions and blockages: Exclusion of 11 Linux kernel maintainers associated with the Russian Federation. Spring's refusal to accept changes from developers in the Russian Federation. Mozilla's compliance with Roskomnadzor's demands, subsequent lifting of the block and fine. Temporary blocking of the Russian Federation in Docker Hub. Closure of access for the Russian Federation to OpenTofu repositories. Erroneous blocking of OpenXRay on GitHub. Blocking of the BPC browser extension in GitLab.
- Forks: FreeNginx β a fork of Nginx, Valkey and Redict β forks of the Redis DBMS, Flock β a fork of Flutter, Apache Cloudberry β a fork of the Greenplum DBMS. The first release of OpenTofu, a fork of Terraform. The transition of OpenSearch, a fork of Elasticsearch, to the Linux Foundation.
- Acquisitions, mergers and joint projects: Microsoft transferred Mono to the Wine community. IBM buys HashiCorp. Mozilla acquired the company Anonym. Merger of Tor and Tails. Restructuring of OpenSSL and merging with Bouncy Castle and Cryptlib libraries. Initiative for the development of x86 architecture.
- Patents and copyrights: Attacks by Nintendo on projects developing console emulators: Yuzu, Suyu, Ryujinx, forks of Yuzu. OS Zone has annulled 54 patents. Removal of part of the ZLUDA code at AMD's request. HDMI Forum did not allow the implementation of HDMI 2.1 in open drivers.
- Laws and regulations: The possibility of blocking Linux kernel developers who violate the code of conduct. The FCC restored net neutrality rules. Rules for the use of Rust trademarks. NetBSD and Gentoo prohibited the use of code generated by AI systems. GitHub banned the hosting of projects for creating deepfakes.
- Licenses: Draft license for Post-Open. Transition of Redis, CockroachDB, and ScyllaDB to proprietary licenses. Return of Elasticsearch to open licensing. Cessation of development for Greenplum DB as an open product. Change of license for Zabbix from GPLv2 to AGPLv3, Forgejo from MIT to GPLv3, OpenVPN from GPLv2 to GPLv2 with exceptions. Licensing issues with Tuxedo drivers.
- Publication of Winamp source code. Violation of GPL license in Winamp code. Removal of Winamp code.
- Introduction of the open AI system definition and initiative to repeal it. Rating the openness of generative AI models.
- Development platforms and application catalogs: Complete separation of Forgejo from Gitea. Transition of Fedora to Forgejo. GitVerse from SberTech. P2P platform Radicle 1.0. Hosting Git repositories at Game of Trees Hub. Mandatory two-factor authentication and new package authenticity checking system in PyPI. 2 billion downloads and one million users on Flathub.
- Programming languages and compilers: GCC 14, LLVM 18/19, Java SE 22/23, Go 1.22/1.23, .NET 9, Perl 5.40, Julia 1.11, PHP 8.4, Ruby 3.4, V 0.4.8, Snek 1.10, Tcl/Tk 9.0, Swift 6.0, Clojure 1.12, Mojo 24.3.
- New languages and compilers: Borgo (combines the best features of Go and Rust). TrapC (C-like language with safe memory operations). Hare (C-like language from the creator of Sway). Pkl (language for defining configurations). Vcc β C/C++ compiler for Vulkan. Bend β language for parallel computing on GPUs.
- Development tools: Meson 1.6, Automake 1.17, GNU Mes 0.27. Gittuf for cryptographic protection of Git repositories. Eclipse Theia development environment. The Zed code editor is now open.
- Python: Python has displaced JavaScript from the top of the GitHub ranking. JIT compiler built-in. Python 3.13. NumPy 2.0.0. Nuitka 2.0 compiler.
- Secure programming: Promoting memory-safe mechanisms in C++. Strategy for reducing vulnerabilities in Android. Fil-C β a compiler for safe memory operations in C/C++. Evaluation of MiraclePtr's effectiveness in C++. Hyperlight β a hypervisor for isolating specific functions.
- Rust: AI translator for rewriting C code in Rust. Consortium for developing highly reliable systems in Rust. Analysis of unsafe usage in Rust packages. Verification of Rust's standard library. Improving portability between C++ and Rust.
- System components: systemd 256/257, Glibc 2.39/2.40, GNU Shepherd 1.0.0. Reducing dependencies in libsystemd. run0 β integrated into systemd as a replacement for sudo. systemd port based on Musl.
- Hardware: OpenWrt One Router. New Raspberry Pi Boards: Pico 2, Compute Module 5, Pico 2 W, 500, Monitor, Media Center. AI Assistant Home Assistant Voice. Vortex 2.2 (open GPGPU based on RISC-V). Creating an open processor compatible with Z80. FuryGpu β FPGA-based GPU. PiDP-10 (clone of the PDP-10 mainframe). The first chip on the OpenTitan platform.
- Firmwares: Intel's involvement in CoreBoot development. fwupd 2.0.0 toolkit. Firmware modifications for TI CC13XX and CC26XX chips.
- Network infrastructure: Initiative for default use of TCP_NODELAY (implemented in OpenBSD). Tesla opened the TTPoE protocol. The share of junk traffic increased to 6.8%. free5GC for building the 5G anchor network. Discontinuation of OCSP protocol support in Letβs Encrypt. Pingora framework from Cloudflare. Netplan 1.0 configuration system. F-Stack network stack 1.24. hostapd/wpa_supplicant 2.11 with Wi-Fi 7 support.
- Standards: C23. Vulkan 1.4. POSIX 1003.1-2024. BPF standardization. OpenMP 6.0. Standardization of post-quantum encryption algorithms. RFC for the FLAC audio codec.
- Protection Mechanisms: OpenPaX (analog of Grsecurity/Pax). Access control system IPE.
- New OS and Distributions: KDE is developing its own distribution. ALDOS β a Fedora variant without systemd. Asterinas and Maestro kernels written in Rust and partially compatible with Linux. Apertis β a distribution for electronic devices from Collabora. Chimera β a Linux kernel with FreeBSD environment. Red Hat Enterprise Linux AI. Fedora Atomic Desktops. Serpent OS. AlmaLinux Kitten. Incrementally updated version of Manjaro. Selectel OS. TileOS. Helios (based on Illumos). ExectOS (with a microkernel similar to Windows NT).
- Updates of Distributions and OS: Ubuntu 24.04/24.10, Ubuntu Core 24, CentOS Stream 10, Red Hat Enterprise Linux 10-beta/9.5/9.4, Fedora 40/41, openSUSE Leap 15.6, SUSE Linux Enterprise 15 SP6, openSUSE Leap Micro 6, ALT 10, elementary OS 8, Whonix 17.2, Linux Mint 22, Azure Linux 3.0, Proxmox VE 8.3, Tails 6, Alpine 3.21, Armbian 24.11, NixOS 24.11, Vanilla OS 2, Blend OS 4, Endless OS 6.0, LibreELEC 12.0, Manjaro 24.0, OpenMediaVault 7.0, Redox OS 0.9, Haiku R1-beta5, OpenIndiana 2024.04.
- Changes in Distributions: Transforming GNOME OS into a distribution for regular users and switching to atomic updates. Arch Linux (port for RISC-V, Valve's participation). Fedora (removing X11 session, switching to DNF5, AI tools, web-based installer, status as base edition for KDE). Changes in the preparation of intermediary releases of RHEL. OpenSUSE (transitioning to the SLFO/ALP platform, Agama installer, reproducible builds, discontinuation of the SUSE brand). Fresh kernels in Ubuntu.
- OpenStreetMap switched from Ubuntu to Debian. LinkedIn transitioned from CentOS to Azure Linux.
- Real-time OS: RISC OS 5.30. RT-Thread 5.1. Support for real-time mode in the Linux kernel. Free usage of QNX 8.0 is available.
- BSD: FreeBSD 14.2, NetBSD 10, OpenBSD 7.6. ravynOS (a FreeBSD edition styled like macOS). NixBSD (NixOS with a FreeBSD kernel). Discussion on using Rust in FreeBSD. Improved laptop support in FreeBSD. New release cycle preparation for FreeBSD. Graphical installer for FreeBSD. SmolBSD (creation of micro-builds of NetBSD).
- Mobile platforms: Android 15/16-pre, LineageOS 22, KDE Plasma Mobile 6, Phosh 0.44, webOS 2.27, Ubuntu Touch OTA-7 Focal, Bliss OS, postmarketOS 24.12, /e/OS 2.6. The Mobifree open mobile app ecosystem. postmarketOS builds based on systemd. Tizen port for RISC-V. Droidian β a Debian variant for smartphones. Support for destructive PIN code in GrapheneOS.
- Translating Chrome OS to the Android platform. Support for Linux applications in Android. MicroFuchsia for virtual machines on Android.
- Package management: OpenWrt's transition to APK package manager. Pacstall (like AUR for Ubuntu). GNU Mes 0.27. Start of RPM 6 development. Aura 4.0.0. Pacman 7.0. GNU Stow 2.4. Test releases of APT 3.0. Modernization of package management in Arch Linux.
- New user environments: Miracle, alpha-testing COSMIC, KDE 6, Theseus Ship (formerly KWinFT).
- User environment updates: Xfce 4.20, GNOME 46/47, KDE Plasma 6.0/6.1/6.2, KDE Gear 24.12, MATE 1.28, LXQt 2.1.0, Cinnamon 6.4, Trinity R14.1.3, MaXX Interactive Desktop 2.2, Sway 1.10, Budgie 10.9, Regolith 3.1. KDE's goals for two years. GNOME's five-year plan. 40 years of the X Window System.
- Updates for composite servers: labwc 0.8.0, Hyprland 0.46, Niri 0.1.10, Cage 0.2, Weston 14.0, Wayfire 0.9.
- GUI: GTK 4.41/4.16, Qt 6.7/6.8, IGL 1.0. FLTK 1.4.0 with Wayland support. Ardour continues development of the GTK2 fork. PortableGL 0.98 (OpenGL 3 implementation in C). New engines for OpenGL and Vulkan in GTK. Louvre for composite server development. SDL3 development.
- GPU: Mesa 24.0/24.1/24.2/24.3. DXVK added support for Direct3D 8. Translation of NVIDIA drivers to open kernel modules. Open implementation of NVIDIA vGPU. LibreCUDA project. AMD released documentation for GPU RDNA 3.5.
- Promoting Wayland: Wayland 1.23. The ability to build GNOME exclusively with Wayland. Wayland support in NVIDIA drivers. Raspberry Pi OS switched to Wayland. Frog project promoting new Wayland protocols. Experimental Wayland protocols.
- Drivers: Nova (a new open driver for NVIDIA GPUs with GSP firmware). embedded-hal (creating drivers in Rust). Improvements to NVK and Zink drivers. EXT2 in Rust. Honeykrisp (Vulkan driver for Apple M1 chip). Driver panthor is ready for the 10th generation Mali GPU. AMD opened the driver for NPU with XDNA engine.
- Multimedia: An open stack for MIPI cameras. FFmpeg 7.0/7.1, PipeWire 1.2.0, PulseAudio 17.0, OBS Studio 31.0, Kodi 21, MythTV 34. Zrythm 1.0.0 sound workstation. Rivendell radio station management platform.
- Codecs: Sound codecs TSAC and Opus 1.5. xHE-AAC decoder from FFMpeg. jpegli β JPEG encoder and decoder from Google. Support for JPEG XL in Samsung.
- Graphics: GIMP 3.0 nearing release. Inkscape 1.4, Darktable 5.0, RawTherapee 5.10, Scribus 1.6.0.
- Modeling and 3D: Blender 4.3, FreeCAD 1.0, CadZinho 0.6, KiCad 8.0. Open code for Google Blocks. OSPRay Studio 1.0 3D visualization program and OSPRay 3.1 3D rendering engine. 3D model of Caldera Island. Road network map from Overture Maps.
- Games: Beta version of NauEngine from VK, Godot 4.3, Open 3D Engine 24.09, Dagor Engine 24.12. Toolkit for launching Windows games from Asahi. Lakka 5.0. Proton 9.0. Wine 9.0. Minetest renamed to Luanti. Open code for the game Descent 3. SteamFork project. Support for ASUS ROG Ally in SteamOS.
- New open projects: Open source for the Mikage emulator. Microsoft opened the code for the Garnet storage. Valve opened the code for Steam Audio. NVIDIA handed the Slang shader language to the Khronos consortium. Opening of Bitwarden SDK.
- DBMS: PostgreSQL 17, MySQL 8.4/9.0/9.1, MariaDB 11.4, Valkey 8.0, Redis 7.4, DuckDB 1.0, IvorySQL 4.0, SynchDB 1.0, EdgeDB 5.0, Firebird 5.0.
- Web: Node.js 23/24 with TypeScript support. Deno 2.0. Support for C code in the JavaScript platform Bun. Wasmer 5. Speedometer 3.0 test.
- Browsers: Tor Browser 14.0, FixBrowser Wolvic on the Chromium engine. 25 years of Dillo. Verso and Servo-the-browser on the Servo engine. Servo passed the Acid2 tests. Accelerating the development of the Ladybird browser and a decision to use Swift in it.
- Mozilla: Advertising display platform. Termination of collaboration with Onerep. MLS (Mozilla Location Service) project discontinued. Decision not to discontinue support for the second version of the Chrome manifest. Leadership change. Winter and autumn employee layoffs. AI-generated websites. Speech recognition toolkit. Rebranding.
- Firefox: releases 122-133, tracking protection using redirects, blocking third-party cookies, temporary permissions, thumbnail display, text fragment translation, "Firefox Labs", built-in chatbot, sidebar, vertical tabs, unified cleanup dialog, auto-replacement of HTTP with HTTPS, support for Zstandard, improvements to Firefox View and PDF viewer, port for Haiku OS. Firefox turns 20.
- Chrome: releases 121-131, micropayments for monetization, add-on performance, moving away from the second version of the manifest, maintaining support for third-party cookies, warning about the discontinuation of uBlock Origin, embedding a large language model.
- Distributed and P2P Systems: Overlay P2P Network Nebula 1.9. Meshtastic β a mesh network based on LoRa transmitters. OpenZiti 1.0 for embedding overlay networks into applications. PeerTube 7.0.
- Office Suites: LibreOffice 24.2/24.8, Calligra 4.0, ONLYOFFICE 8.2.
- Machine Learning: AlphaFold 3 from DeepMind, the hertz-dev model for voice communication, ChatTTS for speech synthesis, Databricks has released the DBRX model, xAI has released the Grok model, OpenAI's Transformer Debugger, Google has launched the Gemma model.
- File Systems: Announcement of the deprecation of the Ext2 driver and removal of ReiserFS. Ceph cluster with terabyte-per-second throughput. LittleFS 2.10. Clustered file system VitastorFS.
- Virtualization and Containers: Work on porting VMware Workstation to KVM hypervisor. VMware Workstation and VMware Fusion have become free. Paravirtualization IOMMU in Xen. VirtualBox on top of KVM. Microsoft has released the OpenVMM/OpenHCL hypervisor. Finch for Linux. Moving Hyper-V host components into the Linux kernel. Lima 1.0 (Linux-on-Mac), Xen 4.19, XCP-ng 8.3, Kata Containers 3.4, LXC 6.0, QEMU 9.0-9.2, Bubblewrap 0.11, CRIU 4.0, Distrobox 1.8, VirtualBox 7.1, MicroCloud LTS.
- Server Applications: OpenSSH 9.7-9.9, BIND 9.20, Samba 4.20/4.21, Exim 4.98, Postfix 3.9, SMTP server chasquid 1.13, ClamAV 1.4, nginx 1.26 with HTTP/3, libmicrohttpd 1.0.0, HAProxy 3.0. Transition of Letβs Encrypt to ntpd-rs. OpenSSH: discontinuation of DSA support, split into multiple processes, protection against password guessing.
- Linux Kernel: linus-next branch. Discussion on the use of C++ in the kernel. Lunatik (creating handlers in Lua). Running Linux on the Intel 4004 chip. Code opened for supporting Elbrus CPUs. Collisions. Versions of x86_64 microarchitecture. ELKS 0.8 kernel for 16-bit CPUs. UEK-next branch from Oracle.
- eBPF: task schedulers, input device diagnostics, user space operation, bpftop, DTrace update. Plan to discontinue support for old ARM CPUs.
- Key changes in the kernel:
- 6.7: integration of Bcachefs, end of support for Itanium architecture, support for Nouveau with GSP-R firmware, TLS encryption support in NVMe-TCP, possibility of using exceptions in BPF, futex support in io_uring, optimization of the fq (Fair Queuing) scheduler's performance, support for TCP-AO (TCP Authentication Option) extension, and the ability to limit network connections in the Landlock protection mechanism, added access control to user namespace and io_uring via AppArmor.
- 6.8: Intel GPU driver for Xe, block device protection mode with mounted file systems, Deadline server task scheduler mechanism, automatic optimization of identical memory page merging, first driver written in Rust, system calls listmount and statmount, removal of bpfilter and SLAB, guest_memfd mechanism in KVM, data access profiling.
- 6.9: dm-vdo module for deduplication and compression of block devices, direct file access mode in FUSE, support for creating pidfd for individual threads, BPF token mechanism, Rust support on ARM64 systems, classification of Ext2 FS driver as deprecated, removal of old NTFS driver, support for Intel FRED mechanism.
- 6.10: ntsync driver with Windows NT synchronization primitives, DRM Panic components to implement a 'blue screen of death' equivalent, discontinuation of support for old Alpha CPUs, integrity verification capability in FUSE-based file systems, access restriction to ioctl via Landlock mechanism, subsystem for profiling memory allocation operations, system call mseal(), capability for encrypted data exchange with TPM devices, support for high-priority work queues in dm-crypt, panthor driver for the tenth generation Mali GPU.
- 6.11: support for atomic block-level write operations, support for bind() and listen() operations in io_uring, new mechanism for locking software interrupt handlers, ability to write to memory-mirrored executable files, support for writing block device drivers in Rust, optimization of getrandom() call, new AES-GCM implementation.
- 6.12: ability to enable Realtime mode, sched_ext for creating CPU schedulers via eBPF, QR code output during emergency states, Device Memory TCP mechanism, resource reservation mechanism for SCHED_DEADLINE server, improvement of EEVDF scheduler, IPE module for specifying integrity enforcement policies.
- Encryption: Apple's homomorphic encryption library. PGP toolset sq 1.0, OpenSSL 3.3/3.4, LibreSSL 4.0, VeraCrypt 1.26.14, GnuPG 2.5, Libgcrypt 1.11.0, Cryptsetup 2.7. Restructuring of OpenSSL. Rustls compatibility with OpenSSL and nginx. Development of post-quantum encryption algorithms.
- Cryptography issues: KyberSlash (vulnerability in the post-quantum algorithm Kyber). EUCLEAK (cloning of YubiKey 5 keys). Reconstruction of PuTTY key.
- Backdoor in the XZ Utils package: retrospective, activation logic, audit results, attempts of similar attacks on other projects.
- Vulnerabilities in processors: BadRAM (AMD, bypassing SEV-SNP), Sinkclose (AMD, access to SMM). Bypassing protection against Spectre. Indirector (Intel). TikTag (ARM, bypassing MemTag). New variant of BHI (Intel). ZenHammer (AMD). GhostRace (Intel, AMD, ARM, IBM). GhostWrite (RISC-V XuanTie). LeftoverLocals (GPU AMD, Apple, Qualcomm, and Imagination). RFDS (Intel Atom).
- Attack methods: KeyTrap and NSEC3 in DNSSEC. ArtPrompt and BoN for bypassing AI system filters. Port Shadow (redirecting connections and Wi-Fi). TunnelVision (redirecting VPN traffic). Obtaining TLS certificates for foreign '.mobi' domains. An attack through IP 0.0.0.0 in the browser. SnailLoad (determining opened sites by packet delay). Attack on the handler for uninstalled applications in Ubuntu. Protocol looping based on UDP. 'Continuation flood' (disrupting HTTP/2.0 server operation). Forged response in the RADIUS protocol. Attack through escape sequences. BatBadBut (libraries for Rust, PHP, Node.js, Python, Ruby, Go, Erlang, and Haskell). VPN Research: Using AI to identify vulnerabilities in SQLite. Analysis of the Ebury rootkit installed during the kernel.org breach. UEFI bootkit Bootkitty.
- Problems due to AI-generated junk vulnerability reports. Reputational damage due to CVEs with false and inflated vulnerabilities.
- Local vulnerabilities: Linux kernel (n_gsm, netfilter, io_uring, nf_tables, ksmbd, ktls, uio, network stack), FreeBSD kernel (1, 2), GRUB2 (RHEL), tuned, needrestart (default in Ubuntu Server), PostgreSQL, NetworkManager-libreswan, guix-daemon, pam_oath, Nix, NVIDIA drivers, Flatpak, Buildah, Podman, Node.js, libuv, Glibc.
- Remote vulnerabilities: Linux IPv6 stack. Android Bluetooth stack. Root vulnerability in OpenSSH (regreSSHion), RHEL and FreeBSD specific vulnerabilities in OpenSSH. Code execution on systems with CUPS (continuing). libaom and libvpx (AV1 and VP8/VP9 codecs, possible attack through browsers). FreeBSD and OpenBSD NFS servers. Apache Struts, GStreamer, Libarchive, X.Org Server (1, 2, 3, 4), libgsf (affecting GNOME), Emacs, Js2Py, PHP, nginx (HTTP/3), Fluent Bit, Git, R, Glibc (attack through PHP scripts), Suricata, ClamAV, runc (affecting Docker and Kubernetes), FFmpeg (JPEG XL), Redis.
- Breaches: Internet Archive. Cloudflare. Barracuda Networks. Compromise of the PyTorch repository. Competitions Pwn2Own Automotive, Pwn2Own 2024, and Pwn2Own Ireland 2024.
- Privacy: Analysis of OpenVPN sessions. Telemetry in Manjaro Linux, Fedora, and Go. Analysis of VPN applications for Android. Statistics on ad blockers. Access to data from remote and private GitHub repositories.
- Privacy: Analysis of OpenVPN sessions. Telemetry in Manjaro Linux, Fedora, and Go. Analysis of VPN applications for Android. Statistics on ad blockers. Access to data from remote and private GitHub repositories.
- Vulnerabilities in firmware and loaders: Vulnerability in Shim (bypassing UEFI Secure Boot). PixieFAIL (attack on UEFI firmware via PXE). Vulnerabilities in Phoenix and AMI MegaRAC UEFI firmware. Vulnerabilities in Qualcomm firmware. Bypassing UEFI Secure Boot due to the test key in motherboards.
- Vulnerabilities in routers and hardware: 659,000 home routers compromised. Ability to control modems of millions of Cox ISP subscribers. Backdoors in D-Link routers and network storage. Vulnerabilities in Juniper devices. Vulnerabilities in ASUS routers. SSID Confusion (Wi-Fi network spoofing). Tampering with OpenWRT assembly artifacts. Unlocking Saflok electronic locks.
- Malicious package detections in PyPI (1, 2) and Snap Store. Dangerous vulnerabilities in GitHub Enterprise Server, Gogs, GitLab (1, 2, 3, 4, 5, 6). Manual review of package names in the Snap Store. Analysis of downloads of deprecated packages from NPM. Malicious AI models in the Hugging Face repository. One hundred thousand repositories with malicious code on GitHub.
- Failures: Linux boot issues due to an update error to Windows (analysis). Deletion of /home when executing "systemd-tmpfiles --purge". Failure in the RU domain zone due to DNSSEC. Desynchronization of the root DNS server "C". KDE theme removing user files.
- Attacks on infrastructures: Injecting malicious code through Polyfill. Leakage of access tokens to Python GitHub repositories. DDoS on SourceHut. Leakage of tokens for Hugging Face Spaces. Publishing malicious releases from Ultralytics. Injecting malicious code into the official JavaScript client of cryptocurrency Solana. Malicious code in the ss-otr plugin for Pidgin.
- Incidents: Attackers altered the BGP settings of the Orange Espagne telecom operator. GitHub updated GPG keys due to vulnerabilities in infrastructure. Internal repository token from Mercedes publicly exposed.
In the past year, 1,569 news articles were published on OpenNET, which received 158,000 comments. In the fall of 2024, the OpenNET project will turn 28 years old.
Source: opennet.ru
