A summary of the most important and notable events of 2023 related to open projects and information security:
- The cessation of publishing the source texts of the Red Hat Enterprise Linux distribution packages and leaving CentOS Stream as the only public source of RHEL package code. Discontent with Red Hat products created through simple repackaging without their modifications. The restructuring of distributions (Alma Linux, Rocky Linux, Oracle Linux) using RHEL packages. The formation of the OpenELA association, in which Rocky Linux, Oracle, and SUSE joined efforts to maintain a package base compatible with RHEL.
- Conflicts: Criticism of Red Hat's business model. Attempts to promote the Web Integrity API and its removal from Chromium in response to concerns about the emergence of DRM-like qualities for the Web. Bjarne Stroustrup against the imposition of safe programming languages. Rejection of patches from Baikal Electronics. Native Americans against Apache. The abolishment and return of Docker Hub Free Team.
- Canonical has transformed LXD into its corporate project. In response, the Linux Containers community, with the participation of LXD's founders, created an independent fork — Incus. After that, Canonical switched the project from the Apache 2.0 license to the AGPLv3 license.
- Forks: LibrePGP — a fork of the OpenPGP standard by the author of GnuPG. Crab — a fork of the Rust language. OpenTofu and OpenBao — forks of Terraform and Vault created after HashiCorp transitioned to a proprietary license.
- Acquisitions and restructurings: SUSE is transforming from a public to a private company. Mozilla acquired Fakespot. The Nextcloud project absorbed the Roundcube email client.
- Legal disputes: Quad9 won a case against Sony regarding the enforcement of DNS blocking. The dispute between Stockfish and ChessBase over GPL violations has been resolved.
- Copyright issues: Changes in trademark policy related to Rust. Blocking of the Youtube-dl project site. Negotiations regarding royalties for content generated by AI systems. Removal of a Firefox extension for bypassing paywalls due to a DMCA complaint. The removal of the Dolphin emulator from Steam and the blocking of the Lockpick project on GitHub at Nintendo's request.
- Licenses: Transition of HashiCorp products to a proprietary license. The Cheerp compiler has been moved to the Apache 2.0 and LLVM licenses. Wikipedia is transitioning to the CC BY-SA 4.0 license. The concept of Post-Open Source.
- Laws: Liability for errors in open source code. Impact on OSS from the Cyber Resilience Act bill. Bills that may hinder the participation of Russian citizens in large OSS projects.
- Development platforms and application catalogs: The evolution of Flathub, an independent app store. Transition of Sourceware hosting under the SFC organization. Implementation of mandatory two-factor authentication in PyPI and GitHub. Support for OpenID Connect in PyPI and discontinuation of support for PGP signatures. Discontinuation of Subversion support in GitHub. Change of checksum algorithms for archives in GitHub.
- Programming languages and compilers: GCC 13, LLVM 16/17, Java SE 20/21, Go 1.21, .NET 8, Perl 5.38, Julia 1.10, PHP 8.3, Ruby 3.3, V 0.4.3, Zig 0.11, Nim 2.0. Tinygo — a Go compiler based on LLVM. Minotaur — an optimizer for LLVM.
- Development tools: Build system Buck2. Fuzz testing systems Snapchange and Buzzer. Automation system Cicada. Red Hat's transition from Bugzilla to Jira. Git 2.40-2.43.
- New languages: Mojo, PXP (a PHP dialect), Birb, Moonbit.
- Python: Python 3.12. Cython 3.0, Nuitka 1.7 compilers. RustPython interpreter. Plan to eliminate the global lock. Implementation of a JIT compiler. Integration of Python into Excel. 7% of developers continue to use Python 2.
- Expansion of the Rust language: Rust 1.67 — 1.75. Adding Rust code to the Windows 11 kernel. Use of Rust permitted in Chromium. Opening of the Ferrocene compiler. Parallel compilation. Rewriting Binder, Fish, Xen tools, Google pvmfm, and Intel TD-Shim projects in Rust. Audit of Rust packages. Rust modules for NGINX. Stable release of Sudo-rs. RustRover IDE from JetBrains. Satellite with Rust subsystem. Hickory DNS will be used in Let’s Encrypt.
- System components: systemd 255/254/253, GRUB 2.12. Soft reboot mode. Upgraded boot partition layout. Glibc 2.38. Building Glibc with LLVM. Discontinuation of support for utmp in Glibc.
- Hardware: SEF (Software Enabled Flash). Completion of RTL design for OpenTitan. Vortex 2.0 (open GPGPU). Cascade (fuzz testing for RISC-V). Raspberry Pi 5. RISE (RISC-V Software Ecosystem). Intel x86S architecture. Open smartwatches ZSWatch.
- Firmware: AMD openSIL — a platform for creating open firmware. Valetudo (firmware for robotic vacuums). Opening the firmware of Deluge music synthesizers. Creating GNU Boot and renaming it to Canoeboot due to the use of a third-party name. Snagboot — a toolkit for restoring and reflashing embedded devices. Coreboot 4.19-4.22. InkBox OS 2.0 for Kobo and Kindle eBooks.
- Network infrastructure: Falcon data transmission technology. Fonoster (an alternative to Twilio). WFB-ng drone communication stack. OpenWifi 1.4 Wi-Fi stack. LTESniffer for intercepting 4G LTE traffic. SSH3. uProtocol for automotive services. LibreQoS traffic optimizer. Device Memory TCP for data transmission between devices.
- Standards: SQL:2023 standard. End-to-end encryption standardization for MLS. Standardization of the censorship-resistant domain name system GNS. Standard for 3D rendering engines ANARI.
- Security mechanisms: CHERIoT for enhancing C code security. Protection against latency analysis in OpenSSH. AMD SEV (Secure Encrypted Virtualization) code has been opened. Google Open Se Cura for secure chips. BrowserBox Pro browser isolation platform. Consortium for Linux kernel security research. Disabling io_uring in ChromeOS and Android.
- Operating Systems: ToaruOS 2.2, RT-Thread 5.0, DentOS 3.0, Visopsys 0.92, GeckOS 2.1, Fuchsia 14, Qubes 4.2.0.
- New distributions: Liberty Linux, a RHEL fork from SUSE. openKylin from the largest Chinese companies. EB corbos Linux, an Ubuntu edition for automotive systems. Fedora Asahi Remix for Apple ARM chips. openSUSE Slowroll. openKylin 1.0 (Chinese). Photon OS 5.0 (from VMware).
- Distributions: Debian 12, Ubuntu 23.04/23.10, Fedora 38/39, openSUSE Leap 15.5, RHEL 9.2/9.3, SUSE 15 SP5, OpenWrt 23.05.0, Devuan 5.0, OpenMandriva Lx 5.0, Mageia 9, openSUSE Leap Micro 5.5, Elementary OS 7.1, Whonix 17, Linux Mint 21.2, Proxmox VE 8.0, Endless OS 5.0, SUSE ALP “Piz Bernina” (Adaptable Linux Platform), WSL 2.0 (Windows Subsystem for Linux). A new package support cycle with kernels in Ubuntu. Web-based installers in Fedora and openSUSE.
- Mobile platforms: Android 14. KDE Plasma Mobile 23.01. LineageOS 20. ROSA Mobile based on KDE Plasma Mobile, RED OS M based on Android, and ALT Mobile on Phosh. Ubuntu Touch OTA-3 Focal, postmarketOS 23.12, /e/OS 1.17, webOS 2.24, Phosh 0.29.0. Liberty Phone smartphone.
- BSD: FreeBSD 14.0, OpenBSD 7.4, DragonFly BSD 6.4, MidnightBSD 3.1, helloSystem 0.8, DiscoBSD. Discontinuation of support for the GNU/kFreeBSD port in Debian.
- Package management: Ubuntu Desktop variant only with Snap packages. Binary packages in Gentoo. Discontinuation of Flatpak support in the base installation of official Ubuntu editions. The unsnap project for migrating Ubuntu from Snap to Flatpak.
- New user environments: Miriway, Kera Desktop. Development of the KDE 6 platform.
- Update of user environments: GNOME 44/45, KDE 5.27, Budgie 10.8, Regolith 3.0, Enlightenment 0.26, Cinnamon 6.0, LXQt 1.4, NsCDE 2.3, Weston 13.0, labwc 0.7, Wayfire 0.8. New window management model in GNOME.
- GUI and graphics: GTK 4.10/4.12, Qt 6.5/6.6, Libadwaita 1.4, Louvre 1.0, SDL 2.28, Mesa 23.0-23.3. Transition of GNOME Shell and Mutter to GTK4. Ongoing work on GTK5. IGL graphic library is now open source. Slint 1.0 interface creation system.
- Wayland promotion: Transition of Lubuntu to Qt 6 and Wayland. Move towards discontinuing X11 support in GNOME, KDE, Fedora, and RHEL. Support in IntelliJ IDE and OpenJDK. Porting of Cinnamon.
- Drivers: NVK (Vulkan driver for NVIDIA). Asahi for Apple AGX GPUs. Support for NVIDIA GSP firmware in nouveau. PanCSF for Mali GPUs. Promotion of the Xe driver for Intel GPUs.
- Modeling and 3D: Blender 4.0, The code of the Dreamworks MoonRay rendering system has been opened. OSPRay 3.0 distributed ray tracing engine. Promotion of FreeCAD for professional use. The code of the internal Blender fork from SPA Studios is now open. D8VK (Direct3D 8 on Vulkan). CAD LibrePCB 1.0, FreeCAD 0.21, CadZinho 0.3, KiCad 7.0. Alliance to promote OpenUSD technology.
- Graphics: Inkscape 1.3, GIMP 2.10.36/2.99.16, Darktable 4.6, Krita 5.2, Pinta 2.1. Porting of GIMP to GTK3. AMD FidelityFX Super Resolution 2.2.
- Multimedia, video: PipeWire 1.0.0, FFmpeg 6.1, GStreamer 1.22.0, Kodi 20. OBS Studio 30.0 and Owncast 0.1.0. Video editors Flowblade 2.12, Shotcut 23.11, OpenShot 3.1, Pitivi 2023.03, LosslessCut 3.49.0.
- Codecs: IAMF format for spatial audio. Discontinuation of Theora support in Chrome and Firefox. Audio codec Opus 1.4. Inclusion of aptX and aptX HD in Android. JPEG XL support in Safari and WebKit.
- Games: Open source of the Dagor Engine gaming engine, which will be used by VK in Nau Engine. Game engines Open 3D Engine 23.10, Minetest 5.8.0, Godot 4.0/4.1/4.2, Ambient. Open source of the game Duelyst and a new edition of the game Quake II.
- New open projects: Microsoft opens the source code of Azure RTOS and hands the project to the Eclipse community. Blink emulator. Yandex has opened the YTsaurus platform. Intel has released OpenCL CPU RT (OpenCL CPU RunTime). NVIDIA has launched RTX Remix Runtime. Twitter has opened its recommendation engine.
- Databases: PRQL data processing language. PayPal has opened JunoDB database. AlaSQL — database for browsers and Node.js. Dragonfly 1.0 (NoSQL storage). PostgreSQL 16, MySQL 8.1/8.2, SQLite 3.41 — 3.44, DuckDB 0.9, EdgeDB 4.0. SQLite extensions: CG/SQL (stored procedures), HC-tree (parallel write), CBS and sqld (cloud and server versions). OrioleDB — PostgreSQL engine without VACUUM. FerretDB 1.0 — MongoDB implementations based on PostgreSQL.
- Web: JavaScript platforms Bun 1.0 and Node.js 21/20. Cheerp 3.0, a C/C++ to JavaScript compiler. Wasmer 4.0, a toolkit for WebAssembly.
- Browsers: Midori 11, Pulse Browser, Tor Browser 13.0, Wolvic 1.5, qutebrowser 3.0, Nyxt 3.0.0, Tangram 2.0, Openra One, NetSurf 3.11. New browsers Mullvad (from Tor and Mullvad), Carbonyl and Thorium 110. Development of Servo resumed. Separation of browser and interface in ChromeOS. VPNMozilla: AI bot MemoryCache. Add-ons directory for the Android version of Firefox. Transition from Mercurial to Git. Launch of a social network. Firefox 109-121: removal of tracking parameters from URLs, machine translation, ECH for domain hiding in HTTPS traffic, additional protection against hidden identification, import of extensions from other browsers, automatic closure of Cookie requests, removal of XUL Layout, acceleration for NVIDIA GPUs, enabling Wayland.
- Chrome: JIT compiler Maglev. Thorium — a faster fork of Chromium. Preparations for blocking third-party Cookies. Enforcing HTTPS. Cryptography resistant to brute-force attacks with quantum computers. Support for WebGPU. Incognito mode. Shortening release cycles. Support for MathML. Chrome 109-120.
- Distributed and P2P systems: Jami Vilagfa communication platform. PeerTube 6.0. Apache Pinot 1.0 storage. Support for P2P broadcasting in OBS Studio. CENO 2.0 browser, using a P2P network. Open source implementation of MeshNet. an IP addressMachine Learning: OpenXLA model optimizer. BlenderGPT. Mozilla.ai. Model for synthesizing 3D images. Stable Video Diffusion, Video-LLaVA, and Kandinsky Video for video synthesis. Llamafile for packaging models into executable files. Text meaning vector representation model Jina Embedding. Background removal from images and videos. Open dataset RedPajama. OpenChatKit, FlexGen, Open-Assistant for creating chatbots. AI Alliance for the joint development of open AI technologies.
- File Systems: Composefs, OpenZFS 2.2, Cisco's Puzzlefs, HAMMER2 for NetBSD and FreeBSD. Discontinuation of the accompanying XFS. Classification of ReiserFS as deprecated. Promotion of Bcachefs. Issues with XFS, OpenZFS, and Ext4.
- Virtualization, emulation, and containers: MicroCloud from Canonical. Container systems Finch 1.0 (from Amazon), Incus (fork of LXD), LXD 5.17, Bottlerocket 1.15.0, Firejail 0.9.72, Bubblewrap 0.8, Kata Containers 3.2. Xen 4.18. Intel has ceased development of the HAXM hypervisor (Hardware Accelerated Execution Manager). QEMU 8.0-8.2.
- Server applications: ClamAV 1.1/1.2, Postfix 3.8.0, Exim 4.97, nginx 1.24, OpenSSH 9.2-9.5, Samba 4.18/4.19, OpenVPN 2.6. Rosenpass VPN. Caching server Passim. IMAP library Gluon.
- Virtualization, emulation, and containers: MicroCloud by Canonical. Container systems Finch 1.0 (from Amazon), Incus (a fork of LXD), LXD 5.17, Bottlerocket 1.15.0, Firejail 0.9.72, Bubblewrap 0.8, Kata Containers 3.2, Xen 4.18. Intel has discontinued the development of the HAXM (Hardware Accelerated Execution Manager) hypervisor. QEMU 8.0-8.2.
- Server applications: ClamAV 1.1/1.2, Postfix 3.8.0, Exim 4.97, nginx 1.24, OpenSSH 9.2-9.5, Samba 4.18/4.19, OpenVPN 2.6. VPN Rosenpass. Caching server Passim. IMAP library Gluon.
- Linux Kernel: Automated parameter optimization system. Monitoring of system overcooling. Removal of UMS (Userspace Mode-Setting). System call cachestat. Kernels 6.6 and 6.1 have received LTS status; kernel 6.1 will be supported for 10 years. Simplified Linux-compatible kernel Tilck. Burnout of accompaniments.
- Key changes in the kernel:
- 6.2: Support for code under the Copyleft-Next license is allowed, improved RAID5/6 implementation in Btrfs, continued integration of Rust language support, reduced overhead for protection against Retbleed attacks, added the ability to control memory usage during delayed writes, added PLB (Protective Load Balancing) mechanism for TCP, added hybrid execution flow protection mechanism (FineIBT), BPF now has the ability to define custom objects and data structures, the utility rv (Runtime Verification) is included, reduced power consumption in RCU lock implementations.
- 6.3: Cleanup of outdated ARM platforms and graphics drivers, continued integration of Rust language support, hwnoise utility, support for red-black tree structures in BPF, BIG TCP mode for IPv4, built-in Dhrystone performance test, ability to disallow execution in memfd, support for creating HID drivers using BPF, Btrfs includes changes to reduce block group fragmentation.
- 6.4: Ability to create kernel worker from user space, continued integration of Rust language support, support for Intel LAM (Linear Address Masking) mechanism, deduplication of memory pages at the process level, support for familiar iterators in BPF, support for sleep mode transitions in RISC-V systems, ability to trace user processes, new kernel module memory management mechanism, prohibition of disabling SELinux during operation, support for encrypting NFS RPC packets, removal of SLOB slab allocator.
- 6.5: Support for Intel TPMI power management mechanism, system call cachestat, continued integration of Rust language support, support for Unaccepted Memory protocol, support for RISC-V vector instructions, "fprobe-events" mechanism, transition to legacy SLAB memory allocation mechanism, "data-only" mode in Overlayfs, "beneath" mount mode.
- 6.6: New task scheduler EEVDF; shadow stack mechanism for protection against exploits; fs-verity support in OverlayFS; implementation of quotas and xattr in tmpfs; preparation of online fsck in XFS; enhanced tracking of 'GPL-only' symbol export; network socket support in io_uring; memory randomization in kmalloc(); ReiserFS declared deprecated; Nouveau adds primitives for the Vulkan driver NVK.
- Encryption: OpenPubKey cryptographic verification protocol. TLSv1.3 enabled in nginx. Full disk encryption in Ubuntu. Default FS encryption in Fedora. VeraCrypt 1.26, OpenSSL 3.1/3.2, Botan 3.0. Extension for coordinating Let’s Encrypt certificate updates.
- Cryptography issues: Reconstructing RSA keys through SSH connection analysis. RSA-2048 factorization optimization on quantum computers. RSA decryption based on measuring operation times. Attack on TPM 2.0 crypto chips. Prohibition on certificate modification in Android. Key reconstruction via LED indicator.
- Vulnerabilities in processors and hardware: Downfall, SLAM, Reptar, CacheWarp, Inception, Zenbleed, EFLAGS, iLeakage, PMFault, GPU.zip. Issue with AMD CPU when dividing by zero. AMD CPU hangs after 1044 days. Backdoor in Gigabyte firmware. 29 vulnerabilities in RISC-V processors. Vulnerabilities in AMI MegaRAC firmware.
- Attack methods: SMTP Smuggling (email spoofing), Mayhem (bypassing authentication in sudo and OpenSSH), LogoFAIL (injecting malicious logos in UEFI firmware), BLUFFS (MITM in Bluetooth), MaginotDNS (DNS cache poisoning), TunnelCrack (VPN traffic interception), RepoJacking (taking over GitHub projects), BrutePrint (unlocking Android smartphones), MacStealer (Wi-Fi traffic interception), Terrapin (MITM on SSH). Attack on HTTP/2 protocol. Bypassing disk encryption through continuous Enter key presses. Using Rowhammer attack for generating unique identifiers. Keypress injection via Bluetooth.
- Research: Analysis of leaks on Realme, Xiaomi, and OnePlus smartphones. Method for exploiting null pointer dereferencing in the Linux kernel. Defining item contours through walls using Wi-Fi. Instruction execution time dependency on data in CPU. Location determination through analyzing SMS delivery delays. Identifying text by sound of keyboard typing. Issues with outdated dependencies.
- Local vulnerabilities: Linux kernel (nftables (1, 2), eBPF, ipset, skb, exFAT, netfilter, tcindex, VMA, io_uring, protection against Spectre v2, QoS), Glibc ld.so, NTFS driver GRUB, OpenOffice, LibreOffice, Xreader, X.Org Server, libX11, GCC, openSUSE-welcome, Ubuntu OverlayFS, OverlayFS, sudo.
- Remote vulnerabilities: Linux kernel (NVMe-oF/TCP, ksmbd, IPv6 stack), strongSwan IPsec, Exim, oFono, ClamAV, OpenSSH (1, 2, ssh-agent), Buildroot, Git (1, 2, 3), OpenSSL, GStreamer, Zephyr RTOS, OpenVPN, SoftEther VPN, ingress-nginx, VLC, Squid, libcue (attack via GNOME), libvpx (attack via browsers), libwebp (attack via browsers and LibreOffice), GitLab (1, 2, 3), FreeBSD pf, Python, PHP, Cargo (1, 2), VitualBox, Redis, Asterisk, Mastodon, nginx, I2P, Tor, cpdb-libs, cups-filters, Apache OpenMeetings, Warpinator, Ghostscript, Flatpak, Home Assistant, Wasmtime, ImageMagic, Ruby on Rails, Hyper.
- Hacks: MongoDB, Sourcegraph, Kodi, Inkscape, Ledger, LastPass, Slack, CircleCI, and Rackspace, Reddit.
- Privacy: Telemetry in Go and Fedora. Results of telemetry collection in GNOME. Issues in automotive information systems. 67% of Apache Superset use keys from examples. Recovery of cropped screenshots.
- Vulnerabilities in routers and hardware: Barracuda ESG, Netgear, D-Link, MikroTik, ASUS, Juniper, Tenda, Samsung Exynos, Cisco IOS XE, Cisco Small Business, Zyxel, Canon. Traffic interception of wireless access points.
- Continued detection of malicious packages in repositories and NPM, PyPI, Ubuntu Snap Store. Capture of projects in PyPI and Packagist. Access keys forgotten in PyPI (1, 2) and GitHub.
- Attacks on infrastructures: Capture of keys for signing GitHub applications. Leak of Yandex Git repositories. Interception of encrypted traffic jabber.ru and xmpp.ru. Malicious dependency in PyTorch. Leak of private keys from Intel. Data leak of 37 million T-Mobile customers due to an API vulnerability. Phishing of KeePass. Attack on registrars that allowed capturing control over 19 top-level domains.
- Incidents: Vulnerability due to Ubuntu patches to OverlayFS. Publication in public repository of host SSH key from GitHub. False vulnerability reports. Backdoor in Free Download Manager deb packages. Insertion of inappropriate expressions in the Ubuntu 23.10 installer. Exploit rkvdec with malicious code.
In a year, 1,478 news articles were published on OpenNET, with 162,000 comments made. In the fall of 2023, the OpenNET project turned 27 years old.
Source: opennet.ru
