Release of the Apertis 2026 distribution, allowing the use of code not licensed under GPLv3

Collabora has introduced the Apertis 2026 Linux distribution, originally created for automotive systems but then reoriented for a wider range of electronic devices, embedded systems, and industrial equipment. Among the devices utilizing Apertis are the Atari VCS gaming console, Raspberry Pi 4 board, R-car automotive SoCs, and the Bosch D-tect 200 wall object detection scanner.

Reference system images are distributed for the x86_64, arm64, and armhf architectures. The distribution is modular and allows device manufacturers to independently configure the necessary system environment. It supports both traditional deb package-based builds and monolithic atomically updatable images based on OSTree. Each Apertis release is supported for 1 year and 9 months, with a corrective release issued every three months to address bugs.

The distribution is built using packages from Debian GNU/Linux. However, the system components have been significantly reworked to account for the risks manufacturers may face when using certain open licenses, such as GPLv3, which prohibit tivoization, i.e., tying software to hardware, for example, by only allowing the loading of firmware signed by the manufacturer’s digital signature.

Apertis allows the creation of builds that do not include code under GPLv3 licenses. Instead of using outdated versions of GNU utilities created before the move to GPLv3, Apertis employs more modern alternatives under permissive licenses. For instance, alternatives from the uutils project, written in Rust and licensed under MIT, replace GNU coreutils and findutils, while Sequoia-PGP, licensed under GPL-2+ and LGPL-2+, substitutes GnuPG. For those not concerned about the legal issues related to GPLv3, traditional utility sets remain available.

The core package is based on the latest LTS branch of the Linux kernel. For example, the Apertis 2026 release uses kernel 6.18, rather than kernel 6.12 from Debian 13 packages. All packages, images, utilities, and settings are developed in a public git repository, which contains 6679 packages (compared to 5905 in the previous release). GitLab is used for collaboration, and GitLab CI is utilized for testing with continuous integration. Binary packages are built from source code using the OBS (Open Build Service) toolkit. The built packages are distributed through APT repositories managed by the aptly toolkit.

The Apertis project adheres to Debian's development rules and includes only applications that are provided under open licenses or allow for free distribution. To ensure that companies creating their products based on Apertis can be confident in the licensing purity of the derivatives, an SBOM (Software Bill of Materials) report is generated for each build. This report contains information on the licenses of all used code files, as well as version data for the software, which is also convenient for verifying the presence of vulnerable versions.

All Apertis components are routinely subjected to extensive automated and manual testing on benchmark hardware platforms, such as Raspberry Pi 4 boards, UP Squared 6000, i.MX8MN, TI SK-AM62, MYIR Remi Pi, i.MX6 Sabrelite, and Renesas R-car automotive SoCs. The results of this testing are published openly. Automated testing of system builds on reference hardware is organized using the LAVA (Linaro Automated Validation Architecture) system.

Key Changes:

  • Transition to Debian 13 package base and Linux kernel 6.18 has been completed.
  • By default, a graphical environment based on a composited server Weston, utilizing Wayland, is enabled. Release of the Apertis 2026 distribution, allowing the use of code not licensed under GPLv3
  • The SDK for building, testing, and integrating custom systems based on Apertis has been redesigned. The new version features improved cross-compilation, enhanced package maintenance convenience, and customization of system images, with a separation of tools for the host environment in which builds are executed and target systems.
  • The package building process has been improved using the ci-package-builder tools and maintaining imported Debian packages between distribution releases. Automatic tracking of changes from Debian has been ensured, along with the identification of relevant updates. The backporting of individual changes to older Apertis releases has been automated. A clearer separation has been established between release-independent functionality, such as update processing, and release-specific tasks, such as license scanning and package building.
  • Tools for rebuilding Apertis based on the under-development Debian GNU/Linux 14 package base have been added.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster