John Seager, vice president of engineering at Canonical and technical leader of the Ubuntu project, announced the intention to integrate the NTP server ntpd-rs, written in Rust and already used in the infrastructure of the Let’s Encrypt certificate authority, into the autumn release of Ubuntu 26.10. The ntpd-rs project will be the third component, after Rust Coreutils and sudo-rs, integrated into Ubuntu as part of an initiative to improve the quality of the system environment through the delivery of software originally developed with a focus on security, reliability, and correctness.
There is also a discussion underway regarding replacing the zlib library with zlib-rs and using the Sequoia package instead of GnuPG in the APT package manager. The ntpd-rs package is intended to be utilized by default as server a precise time synchronization client, which will eventually replace the currently used packages chrony, linuxptp, and possibly gpsd. The proposed implementation plan involves supplying the current version of the ntpd-rs package in the Ubuntu 26.10 repository as an option for testing. In Ubuntu 27.04, they plan to use ntpd-rs by default as a unified server and client with support for NTP, NTS, and PTP protocols.
The ntpd-rs project is being developed by the Trifecta Tech Foundation, which is also responsible for developing the already integrated sudo-rs utility in Ubuntu. Canonical will fund the development of new features and security enhancements in ntpd-rs. Among other things, they intend to integrate the achievements of the Statime project, which develops the implementation of the PTP (Precision Time Protocol) protocol in Rust, to unify the support of relevant time synchronization protocols in one package and use ntpd-rs not only as a replacement for chrony but also for linuxptp.
Among the additional features that need to be implemented in ntpd-rs before deployment, the implementation of gPTP and CSPTP protocols, support for IP socket gpsd, multithreading mode for NTP servers, the possibility of use in multi-homed mode, creation of isolation profiles based on AppArmor and seccomp, provision of tools for testing and performance evaluation, and improvements related to logging and configuration are noted.
Pe lângă proiectele comune cu organizația Trifecta Tech Foundation, compania Canonical a devenit și un participant "auriu" al organizației Rust Foundation, care se ocupă de dezvoltarea și susținerea limbajului Rust și a ecosistemului asociat. Alături de Canonical, care a devenit singurul participant aurit, finanțarea majoră a dezvoltării Rust este asigurată de 6 participanți platinum — Google, Microsoft, Amazon, ARM, Meta și Huawei. Contribuția participantului auriu este de 150 de mii de dolari pe an, iar cea a participantului platinum — de 325 de mii de dolari.
De asemenea, merită menționat anunțul lui Julian Andres Klode de la Canonical, care coordonează proiectul APT, despre intenția de a reduce numărul parserelor din bootloader-ul GRUB pentru a micșora suprafața de atac. În Ubuntu 26.10, se propune să fie eliminate din versiunile semnate digital suportul pentru formatele de imagine jpeg și png, tabelele de partiții part_apple și capacitatea de a utiliza FS-urile btrfs, hfsplus, xfs și zfs pentru partiția /boot. În plus, se intenționează eliminarea suportului pentru utilizarea în /boot a partițiilor LVM, md-raid (cu excepția raid1) și a partițiilor criptate LUKS.
Se remarcă faptul că, în instalatorul Ubuntu, pentru /boot se folosește întotdeauna doar FS ext4, iar alte sisteme nu sunt testate și prezintă un risc de ocolire a modului de încărcare verificată, având în vedere descoperirea periodică a vulnerabilităților în GRUB (1, 2, 3, 4, 5, 6, 7). Cât privește eliminarea suportului pentru criptarea partiției /boot, această operațiune este considerată inutilă (security by obscurity) — în acest context este important să se asigure integritatea în partiția /boot, ceea ce se realizează prin TPM FDE, nu prin ascunderea datelor. În partițiile diferite de /boot, se va putea utiliza în continuare LUKS, LVM și MD-RAID. Restricțiile nu se vor aplica nici la încărcarea în modul UEFI Secure Boot.
Sursa: opennet.ro
