Jon Seager, vice-president of Canonical Engineering and technical leader of the Ubuntu project, announced plans to integrate the NTP server ntpd-rs, written in Rust and already used in the infrastructure of the Letās Encrypt certificate authority, into the upcoming Ubuntu 26.10 release. The ntpd-rs project will become the third component, following Rust Coreutils and sudo-rs, integrated into Ubuntu as part of the initiative to enhance the quality of the system environment through the delivery of software originally developed with a focus on security, reliability, and correctness.
The discussion stage also includes replacing the zlib library with zlib-rs and employing the Sequoia package instead of GnuPG in the APT package manager. The ntpd-rs package is intended to be used by default as de server a precise time synchronization client that will gradually replace the currently used packages chrony, linuxptp, and possibly gpsd. The proposed implementation plan includes delivering the latest version of the ntpd-rs package in the Ubuntu 26.10 repositories as an option for testing. In Ubuntu 27.04, there are plans to use ntpd-rs by default as a unified server and client supporting NTP, NTS, and PTP protocols.
The ntpd-rs project is being developed by the Trifecta Tech Foundation, which is also responsible for developing the already integrated sudo-rs utility in Ubuntu. Canonical will fund the development of new features and enhancements for security in ntpd-rs. Among other things, ntpd-rs plans to incorporate developments from the Statime project, which is advancing the implementation of the PTP (Precision Time Protocol) protocol in Rust, to unify support for current time synchronization protocols in one package and use ntpd-rs not only as a replacement for chrony but also linuxptp.
Among the additional features to be implemented in ntpd-rs before deployment are the implementation of gPTP and CSPTP protocols, support for the gpsd IP socket, multi-threaded operation of NTP servers, the ability to use in multi-homed mode, creation of isolation profiles based on AppArmor and seccomp, provision of tools for testing and performance evaluation, improvements related to logging and configuration, and enhancements to the ntp-cli utility.
Naast gezamenlijke projecten met de Trifecta Tech Foundation is Canonical ook toegetreden tot de groep van "gouden" deelnemers van de Rust Foundation, die zich richt op de ontwikkeling en ondersteuning van de programmeertaal Rust en de bijbehorende ecosysteem. Naast Canonical, dat de enige gouden deelnemer is, wordt de ontwikkeling van Rust voornamelijk gefinancierd door 6 platinadeelnemers: Google, Microsoft, Amazon, ARM, Meta en Huawei. De bijdrage van een gouden deelnemer bedraagt 150 duizend dollar per jaar, die van een platinadeelnemer 325 duizend dollar.
Daarnaast kan de aankondiging van Julian Andres Klode van Canonical, de ondersteuner van het APT-project, worden vermeld, waarin hij de intentie aankondigt om het aantal parsers in de GRUB-bootloader te verminderen om de aanvalloppervlakte te verkleinen. In Ubuntu 26.10 is voorgesteld om de ondersteuning voor jpeg- en png-afbeeldingsformaten, de partitie-tabellen part_apple en de mogelijkheid om btrfs-, hfsplus-, xfs- en zfs-bestandssystemen voor de /boot-partitie te gebruiken uit de door digitale handtekeningen ondertekende build te verwijderen. Bovendien is het de bedoeling om de ondersteuning voor LVM-, md-raid (behalve raid1) en versleutelde LUKS-partities in /boot te verwijderen.
Opmerkelijk is dat de Ubuntu-installer voor /boot altijd alleen het ext4-bestandssysteem gebruikt, terwijl andere systemen niet worden getest en een bedreiging vormen voor het omzeilen van de geverifieerde opstartmodus, gezien de periodieke ontdekking van kwetsbaarheden in GRUB (1, 2, 3, 4, 5, 6, 7). Wat betreft het verwijderen van de ondersteuning voor versleuteling van de /boot-partitie, wordt deze actie als nutteloos beschouwd (security by obscurity) ā in deze context is het belangrijk om de integriteit van de /boot-partitie te waarborgen, wat wordt gedaan met behulp van TPM FDE, en niet door gegevens te verbergen. In partities anders dan /boot is het nog steeds mogelijk om LUKS, LVM en MD-RAID te gebruiken. Beperkingen zullen ook niet worden toegepast wanneer er niet in UEFI Secure Boot-modus wordt opgestart.
Bron: opennet.ru
