You are here

Agreguesi i feed

Linux IPv6 Segment Routing Bug Can Write to Freed Packet Memory

LinuxSecurity.com - Mar, 08/09/2026 - 5:36md
Linux can move a network packet's data in memory while some networking code still holds its old address. That saved address is called a pointer. A patch and maintainer discussion posted on Sep 7, 2026 describe how that mismatch can make an IPv6 Segment Routing eBPF action write to memory that Linux has already released. Segment Routing steers packets through specified network waypoints; eBPF lets small programs run inside the kernel to customize tasks such as packet handling.

Secretive DHS 'Predictive Policing' Unit Is Analyzing Americans' Financial Habits, Pulling Them Over

Slashdot - Mar, 08/09/2026 - 5:00md
An anonymous reader quotes a report from 404 Media: Border Patrol is running secretive predictive policing units that analyze Americans' financial activity and other data, then feed that intelligence to local police who pull people over who are not suspected of any specific crime, but which the government thinks may be worth searching, 404 Media has found. The units, the name of which 404 Media is revealing here for the first time, are called Predictive Intelligence Targeting Teams (PITT). In one case, a PITT analyzed the financial activity of a man who was driving across Montana, and local authorities stopped him under the pretense of an obstructed license plate and charged him with a DUI. 404 Media identified one PITT in the Spokane Sector, Washington, which polices the U.S. border with Canada, and another in the Laredo Sector, Texas, which polices the border with Mexico. The findings add to an Associated Press investigation from last year which found Border Patrol was using automatic license plate readers (ALPRs) as part of the same wide-spanning predictive policing program. "The bottom line is genuine probable cause cannot be synthetically generated," Jake Laperruque, deputy director of the Security and Surveillance Project at the Center For Democracy & Technology, told 404 Media in an email. Here Border Patrol seems to be "using parallel construction to cloak the reason behind its car stops in secrecy. If we can't meaningfully review and evaluate these systems, we can't trust them," he added. [...] The DHS document obtained by 404 Media shows that Border Patrol is analyzing the financial activity of Americans to find people to pull over. The Associated Press's investigation found the predictive policing program is also heavily using ALPRs to track potential targets' movements. It is not clear how exactly Border Patrol is monitoring Americans' financial activity. Customs and Border Protection (CBP) declined to answer what financial activity the agency was monitoring, and whether it obtained a warrant or not. A CBP spokesperson told 404 Media in an email: "U.S. Border Patrol uses intelligence-informed analysis and planning to support national security operations, allocate resources, and help identify potential threats and bad actors to public safety. These efforts are conducted consistent with applicable law, policy, privacy protections, and oversight requirements." The statement continued: "For operational security reasons, we do not discuss specific analytical methods, data sources, targeting criteria, investigative techniques, system capabilities, or deployment details. Public disclosure of such information could compromise law enforcement operations and investigations as well as creating safety risks for agents and the public." Rob Frommer, senior attorney at the Institute for Justice, told 404 Media: "The government's increasing use of mass surveillance -- whether that surveillance comes via ALPRs, financial records, or the like -- coupled with predictive policing is a recipe for tyranny. We fought a revolution for the idea that we are citizens, not subjects. Yet schemes like CBP's Predictive Intelligence Targeting Team treat all Americans as if they are potential suspects. This is not just wrong, it's unconstitutional, and IJ will keep pushing courts and Congress to end this attack on Americans' security."

Read more of this story at Slashdot.

AMD Working To 'Push Rust Deep into the GPU Stack'

Slashdot - Mar, 08/09/2026 - 1:34md
Phoronix reports: AMD is building out what they are describing as an "elite" team of developers for driving Rust code "deep into the GPU stack" from firmware to drivers, shader compilers, and other GPU software in Rust. AMD Senior Fellow Harsh Meno posted this week to LinkedIn about this new effort... And note this AMD job posting that's active for hiring a software development engineer to work on Rust code... "We are building next-generation systems software for AMD GPUs with Rust as a core technical direction. The work spans compilers, runtimes, low-level GPU software, firmware, developer tooling, and methods for improving the safety and correctness of complex hardware-software systems. "Rust is not incidental to this role. You will help establish how Rust is used in performance-sensitive and high-trust parts of the GPU stack, including the compiler and tooling support, system interfaces, engineering practices, and validation methods required for production deployment. You will have the opportunity to influence both near-term implementations and the longer-term architecture for using Rust across current and future AMD platforms." "AMD also isn't alone," the article points out, "as NVIDIA has also been pursuing similar Rust-based initiatives for their GPU software too, including the development of the Nova Linux kernel driver written in Rust."

Read more of this story at Slashdot.

Three Cities, 16 Years And $1 Billion Later, 'Defiant' Lucas Museum of Narrative Art Opens To Mixed Reviews

Slashdot - Mar, 08/09/2026 - 10:34pd
It looks like a spaceship hovering over South Los Angeles, writes CNN, with futuristic tube-like elevators and an exhibition of Banksy murals. There's a room featuring Luke Skywalker's X-34 Landspeeder, but in its gardens there's a 19th-century cast of a sculpture showing David conquering Goliath — and then a bronze statue of Princess Leia strangling Jabba the Hutt with a chain. Next to Rosie the Riveter. CNN argues it's the museum's message that "all forms of art and mythology on display here — from comic book illustrations and 'Star Wars' concept art to Impressionist masterpieces and reproductions of the Sistine Chapel — are worthy of equal consideration within the long arc of human history." More than 16 years after first proposing a cultural institution dedicated to visual storytelling, filmmaker George Lucas and his wife, businesswoman Mellody Hobson, will open their long-awaited museum in Los Angeles on September 22. The project made two false starts — plans to construct it in San Francisco and Chicago were both eventually abandoned — and has cost Lucas around $1 billion of his own money to build... Inside, visitors will find a significant slice of Lucas' private collection, amassed over five decades and spanning art, costumes, movie props and memorabilia, with more than 1,300 objects currently displayed across 30 galleries... Many fans will come for the "Star Wars" vehicles and sculptures of Yoda and Grogu, but the sci-fi mega-franchise only occupies about 7% of the museum. Lucas and Hobson are betting those visitors will stay for artworks by Frida Kahlo and Norman Rockwell, photographs by Gordon Parks, comics by Frank Miller and Cowboy Bebop anime, which will be screened in one of two theaters alongside early silent movies, Lucas' own student films and productions by famed historical artists like Man Ray... [M]ajor art institutions like New York's Museum of Modern Art and London's Tate Britain have reconsidered the cultural canon by rehanging their permanent collections, exhibiting overlooked or marginalized artists alongside more widely celebrated names. The Lucas Museum appears to follow a similar philosophy, contending that the gravitas of an artwork is not just determined by its display in space but by what it's in dialogue with. Lucas has even called his namesake museum "a temple to the peoples' art," elevating the work of illustrators and other underappreciated art forms... The museum defines narrative art as any art that tells a story, and, moving through the space, one feels the enormity of the task of organizing and presenting such a broad vision... The open-plan, curvilinear design means the galleries are not fully divided, reinforcing the all-encompassing nature of the collection, though altogether the vast array of exhibits sometimes struggle for cohesiveness. Disjointed curation may reflect turbulence in the museum's management ahead of the opening. Last April, former director and CEO Sandra Jackson-Dumont departed, with Lucas himself assuming responsibility for "content direction." A month later, the museum laid off 15 full-time and seven part-time staff before chief curator Pilar Tompkins Rivas resigned in December, with no replacement planned... After failing to secure a site in San Francisco, Lucas faced public opposition and a lawsuit in Chicago, with nonprofit Friends of the Parks arguing that his lakefront proposal would essentially privatize public land. Amid the delays and setbacks, simply opening the museum may feel like a victory to its founders. Lucas's wife said she'd watched the awe-inspiring activity of genius at work, reports Variety. "And he was fanatical at times, but the thing about a fanatical person is they're a fan. He was a deep fan of these illustrators in this work, and he wanted them to be represented, and I became a deeper fan of his." Hobson teared up as she continued, "I was a fan already, but I saw something, the inspiration, the unwillingness to compromise, the determination, the lack of sleep, the lack of rest, the doggedness that actually taught me so much more than I ever could have imagined." The museum, which features 1,200 pieces from Lucas's private collection, has been in the works for about 20 years... "I thought I was tough. I thought I was strong, I thought I had a will, and then I saw George, and I was like, 'Oh, that's why you could only do six of those movies,'" Hobson said. "Any more would have killed you." Artforum magazine notes the museum received "mixed reviews" before its September 22 opening: The billion-dollar, 300,000-square-foot museum, which opens to the public on September 22, encompasses 100,000 square feet of gallery space housing the collection of Lucas and Hobson. Intended to highlight storytelling in art, it presents the work of comic book artists John Romita Sr. and R. Crumb, illustrators Maxfield Parrish and Norman Rockwell, and fantasy painters Boris Vallejo and Frank Frazetta alongside masterworks by Artemisia Gentileschi, Lucas Cranach the Elder, and Pieter Brueghel the Younger, as well as Mary Cassatt, Frida Kahlo, and John Singer Sargent. All the works on display were chosen for their ability to tell a story, frequently in a single frame, Hobson told members of the press on September 2... "Some visitors may be scandalized by the collision of so-called 'high' and 'low,'" wrote Min Chen in Artnet News. "But there's something liberating about watching those hierarchies collapse, seeing the breadth of human creativity arrayed beyond the bounds of genre or canon." Notably, most of the works appear without didactics, which is intentional. "We're encouraging people to have their own individual encounters with works of art and take away what they feel like speaks to them," Lucas told The Guardian. The tactic did not land for everyone. "Without [didactics], I left the Lucas without a clear sense of how the museum is positioning itself or, frankly, without learning much about anything beyond what I already knew...." wrote Maximiliano Durón in Artnews. "The Museum of Narrative Art lacks any kind of narrative." Mary McNamara of the Los Angeles Times was unfazed by the lack of information, calling the institution "gutsy" and "defiant." "Critics will roar," wrote McNamara, "but the Lucas Museum is a win for 'the people's art.'" Even the museum's web site is a visual extravaganza (and impossible to scroll). Reportedly there's two restaurants, including the rooftop Skywalker Grill, which offers offering everything from striped bass and ragu bolognese to lobster corn dogs and Skywalker ranch Waygu burgers.

Read more of this story at Slashdot.

Google Patches Actively Exploited Chrome Vulnerability Affecting Linux

LinuxSecurity.com - Hën, 07/09/2026 - 6:37md
Chrome release notes can be a blur of version numbers. This one deserves a closer look. In the Linux build published on September 3, 2026, Google fixed CVE-2026-85046 and disclosed that an exploit was already in use. The build number to look for is 152.0.7977.82.

Linux Open vSwitch 2026-47916db6c7 RCU Race Condition Fix

LinuxSecurity.com - Hën, 07/09/2026 - 6:27md
A proposed patch fixes a bug in Open vSwitch, a virtual network switch with an in-kernel Linux packet-processing path. An ordering race can free a flow-table mask array while packet processing still reads it. The report includes a Kernel Address Sanitizer, or KASAN, trace, and the author says the crash reproduces in about one minute on a two-vCPU guest.

Linux OCFS2 Use After Free Risk Advisory 2026-47916db6c7

LinuxSecurity.com - Hën, 07/09/2026 - 6:12md
A reported race in OCFS2, a Linux clustered file system for shared storage, can trigger a use-after-free while administrators configure a heartbeat region. The failure occurs when concurrent writes reach the same configfs device attribute and both manipulate one region's slot-data allocation.

Linux Advisory Timer Vulnerabilities Leading to Use-After-Free Issues

LinuxSecurity.com - Hën, 07/09/2026 - 6:05md
A proposed Linux repair addresses two timer bugs that can trigger use-after-free conditions while one program replaces itself with another through exec(). Both failures begin with the same unusual transition: a thread that is not the process leader becomes the new leader, and Linux exchanges thread identifiers while timer and signal state still reflects the old ownership layout.

7.2.4: stable

Kernel Linux - Hën, 07/09/2026 - 5:37md
Version:7.2.4 (stable) Released:2026-09-07 Source:linux-7.2.4.tar.xz PGP Signature:linux-7.2.4.tar.sign Patch:full (incremental) ChangeLog:ChangeLog-7.2.4

6.18.50: longterm

Kernel Linux - Hën, 07/09/2026 - 5:28md
Version:6.18.50 (longterm) Released:2026-09-07 Source:linux-6.18.50.tar.xz PGP Signature:linux-6.18.50.tar.sign Patch:full (incremental) ChangeLog:ChangeLog-6.18.50

6.12.109: longterm

Kernel Linux - Hën, 07/09/2026 - 5:20md
Version:6.12.109 (longterm) Released:2026-09-07 Source:linux-6.12.109.tar.xz PGP Signature:linux-6.12.109.tar.sign Patch:full (incremental) ChangeLog:ChangeLog-6.12.109

Bitcoin-based Liquid Network Says $320 Million Withdrawn in Hack

Slashdot - Hën, 07/09/2026 - 9:30pd
Reuters reports: Liquid Network, a Bitcoin-based payments and settlement network, said on Sunday that about $320 million was withdrawn from its federation wallet in a hack. "Purported white-hat hackers" withdrew around 4,000 of the 4,200 bitcoin held in its Liquid Federation wallet, Liquid Network said in a post on X. "Liquid wallets will be impacted," their post concluded, adding "and we're sorry for any inconvenience."

Read more of this story at Slashdot.

Roku's 24/7 AI Slop Channel Is Even Worse Than Expected

Slashdot - Hën, 07/09/2026 - 6:30pd
A new streaming TV channel shows films made with genAI, reports Engadget. "Fairground AI Creator TV" is free — and supported with ads — describing its material as "AI Cinema": "AI-generated" can make it sound as though someone typed a sentence into a machine and came back five minutes later to find a finished movie. Fairground's catalog shows why that description can be too simple. Take Lost Garden: The Awakening of the Lantern Knight. According to its Fairground page, creator Frank Houbre wrote the world, characters, mythology, emotional arc and screenplay himself. AI tools were used mainly for animation and visual production, with other tools helping create voices and music before the episode was assembled in conventional video-editing software. There's still one question, the article notes: "whether viewers actually want an AI-focused TV channel." More than 100 AI creators have contributed to the 24-hour slate of programming, although Variety points out several of them were discovered on social media. The channel was recently profiled in an article by the Guardian. Its headline? "'Nightmare fodder': Roku's AI slop channel is even worse than expected." (And its subheading calls it "a 24/7 channel devoted to low-quality AI content for viewers sick of watching real people move...") What about people who hate plot and vision and the sight of people speaking convincing dialogue that synchronises perfectly with the movement of their lips? What about the people who just want to watch an unyielding torrent of eerily weightless nightmare fodder? Well, good news. Roku has finally caught up... Early reactions were, to put it mildly, not great. The Verge compared it to eating from a trough, while Futurism called it "bottom-of-the-barrel slop"... On the plus side, the channel is evidence that artificial intelligence has come on in leaps and bounds over the last couple of years... However, it is still awful. Categorically, catastrophically awful. The channel doesn't so much offer shows as a drifting dreamscape of bad ideas rendered as horribly as possible with no thought paid to scheduling. At one point on Wednesday, a shrill high-frequency anime gave way to a long and staid German-language short about Nazi bureaucracy. After that came a sort of Gladiator ripoff that had all the dynamism of an exhibit you'd see at the fourth-best museum on a poorly planned family holiday.

Read more of this story at Slashdot.

US Military Disables Ad Trackers On Devices To Protect Troops

Slashdot - Hën, 07/09/2026 - 3:34pd
Slashdot reader DeanonymizedCoward writes: Reuters reports that the US Military is disabling ad tracking on devices, to prevent adversaries from buying publicly-available tracking data to assist in targeting troops. Military officials say that they have disabled trackers on a variety of computers and mobile devices, according to letters released on Friday by Sen. Ron Wyden, and following reports that commercially-available tracking data has been used to target troops in the Middle East.... Wyden said in a statement that it was clear that the military's efforts "have not been effective at neutralizing this threat." U.S. Representative Pat Harrigan, a North Carolina Republican, said that U.S. enemies "should not be able to pull out a credit card and buy information that helps them track American troops." Rep. Harrigan remains silent as to the larger question of whether the general public should be able to pull out a credit card and buy information that helps them track anyone they please. "The Pentagon said in an email it would respond to the lawmakers directly," Reuters reports: The Army said in a statement that advertising IDs had been blocked on Windows computers "since before 2021" but that Android and Apple mobile devices had only had it disabled by default "since at least February 2026...." The effort to reduce the location data generated by smartphones comes as military officials weigh increasingly strict restrictions on phone use overall. In July, Reuters reported that some deployed personnel in the Middle East could be ordered to surrender their phones amid concerns that mobile videos they were posting to the internet were helping Iran target American bases in the region.

Read more of this story at Slashdot.

vixalien: Project Final Report: Adding Debug Adapter Protocol Support to GJS

Planet GNOME - Hën, 07/09/2026 - 2:00pd

Hello again! A few weeks ago, I wrote about the work I've been doing this summer adding Debug Adapter Protocol (DAP) support to GJS as part of Google Summer of Code (GSoC) 2026. If you haven't read that post, start there for the background on what GJS and DAP are and why this matters.

As my GSoC is wrapping up, I wanted to share you an update on what I've done, what I've learnt, and what I'm planning for the future.

Instead of a lengthy report, I actually want to walk you through debugging a real GJS application using the DAP support I've added to GJS.

By the end of this post, you'll know how to launch a GJS app in Zed, set breakpoints (including on exceptions), step through code, inspect variables and more, all from inside your editor.

Setting Up

The code I've implemented is currently in a Merge Request being reviewed, so to you use it, you will need to clone and build GJS from source (until GNOME 52).

Cloning and Building GJS from source

You can build GJS from source by following the Hacking guide, but here's a shorter version of it

# 1. Clone GJS git clone https://gitlab.gnome.org/GNOME/gjs.git cd gjs # 2. Checkout my branch git checkout wip/vixalien/dap # 3. Setup meson meson setup _build # 4. Build GJS ninja -C _build # 5. Verify meson devenv -C _build gjs-console ../script.js

This will be required before GNOME 52.

Please note the path where you cloned GJS (e.g. ~/Projects/gjs). We will need it later.

Editor setup

You will also need to download and install the Zed editor. The currently supported editors for GJS DAP are Zed and VS Code. We will use the Zed editor since it's more validated to work with the GJS DAP support currently.

You will also need to install the GJS Debugger Extension for Zed, which is currently pending review to be included in the Zed extension store.

But you can build it locally, by cloning my Extension. To install within Zed, Press Ctrl+Shift+X, then click "Install Dev Extension". A file picker will open, so navigate to the directory where you cloned the extension and select it.

This will require a Rust toolchain to be installed, so the extension can be built.

Let me know if you want to debug GJS apps from other editors (not just Zed).

Navigating Around

To make this concrete, I'm going to walk through debugging an standard example application.

1. Setting up the application

The application we are going to debug is a simple Calculator, as found in the GJS Examples

Create a simple file called calc.js in a new project directory and save the contents of the Calculator app above into it.

Then open the project in Zed as you normally would.

2. Opening the Project in the Debugger

To open the project in the Debugger, you can use the F4 key to start debugging.

A dialog will then pop up asking for the Debugger configuration.

  1. Select the Launch tab to launch a new debugger instance.
  2. Select GJS as the debugger.
  3. Type calc.js as the program to debug.
  4. Disable "Stop On Entry" so that the debugger doesn't stop at the first line of the script.
  5. Press Ctrl+Enter or select "Edit in debug.json" to open the configuration file.

This will create a new configuration file at .zed/debug.json in the project directory, we will use this file to configure the debugger and make sure our debugger settings are saved across sessions.

That file will look like this:

// Project-local debug tasks // // For more documentation on how to configure debug tasks, // see: https://zed.dev/docs/debugger [ { "adapter": "gjs", "label": "calc.js (gjs)", "args": [], "cwd": "/home/alien/Projects/calc", "program": "calc.js", "stopOnEntry": false, }, ]

We will need to make a small modification to it to point it to the GJS we just compiled (otherwise it will use the default GJS from our system, which doesn't have the unmerged DAP changes).

This is needed before GNOME 52 is released (which means gjs will be able to do this natively).

We will do it by adding a gjsPath field to the configuration in this format:

... "program": "calc.js", "stopOnEntry": false, + "gjsPath": "flatpak-spawn --host meson devenv -C ~/Projects/gjs --workdir . gjs-console", }, ]

Where ~/Projects/gjs is the path to the GJS repository you cloned.

After making this change, press F5 again, and now you will see an option called calc.js (gjs) in the dialog's "Debug" tab.

Click that configuration, and this will launch the debug configuration we just saved.

Now you have a running GJS debugger session!

3. Navigating the Debugger

At the bottom of the window, you will see a debug toolbar with various sections, panes and controls.

Fret not! The debugger toolbar is simple to understand, as I will explain here below.

The debugger toolbar is made up of controls at the top, then 3 horizontal panes.

1. The controls bar

This is where you have different buttons to control the state of the program. In order, we have the Pause/Resume button, Step Over (or Next) button, Step In, Step Out, then the Restart and Quit buttons.

2. The frames pane

This pane shows the currently active stack frames (or call stacks).

This frame has another tab that shows the various set breakpoints.

3. The console pane

This pane shows the console output of the program and allows you to potentially execute commands (not yet supported in the GJS debugger).

It has a different tab that shows the different scopes. Here, you can expand a scope to see variables inside that scope.

4. The terminal pane

Last, but not least, the terminal pane shows regular terminal output from the running program. This is also not currently implemented in the GJS debugger.

Debugging

Now that you can navigate around the debugger, let's get to debugging!

1. Using the debugger statement.

The debugger statement is a built-in statement in JavaScript that pauses execution and allows you to inspect the current state of the program at the time it pauses.

You can add a debugger statement to calc.js at the end of the file to test it out.

Then click F5 again to start debugging. This will launch the debugger and pause execution at the debugger statement.

Note: Ignore the "the debugger statement is not allowed" message for now, but remember to remove it before building/shipping your application.

The highlighted line is where the debugger paused execution.

2. Inspecting Variables

With the debugger now paused, you can inspect the variables in the current scope.

Click on a scope's name to expand the variables under it.

You can click on one of the objects to inspect its properties, for example, in the module scope, click on Gtk to see all the widgets available in the GTK library.

Inspecting all types of variables is implemented and you can inspect numbers, booleans, strings, symbols, functions, classes and most other types of objects.

3. Adding breakpoints

Adding the debugger statement is not the only way you can stop execution, you can also quite easily add breakpoints by clicking on the line number you want to pause at in the editor.

For example, let's add a breakpoint on the first line of the pressedEquals function.

Then we can stop and restart the debugger. In the running program, type a simple equation like 1+1, then click =.

The debugger panel will now show that you're paused, and allow you to view the stack frames as well as the scopes.

With this approach, you can debug applications and pause execution at any point to inspect the state of the program.

Also note that the breakpoints tab is now updated to show the breakpoint we just set.

Note: The main Calculator window might now appear as Frozen (e.g. with a "« gjs-console » is not responding" message). Don't worry, this is because the program is paused in the debugger.

Note2: You can set/remove breakpoints anytime the app is running or before it starts.

4. Stepping through the code

With the application now paused, we can progressively move execution line-by-line by stepping through the code.

To "Step Over" (execute the current line and move to the next one), press the "Step Over" button in the debugger toolbar.

<video src="/images/posts/gjs-dap-report/equals-stepping.webm" loop muted autoplay controls></video>

You can also click the "Step Into" button to step into a function call (or just step over).

Here's an example where I've added a breakpoint on Line 40 (first line of pressedOperator button) and stepping into the updateDisplay function call.

<video src="/images/posts/gjs-dap-report/step-into.webm" loop muted autoplay controls></video>

Stepping back is currently not implemented.

5. Breaking on Exceptions

Another way to pause execution is to set to break on exceptions. The GJS debugger supports breaking on breakpoints that would either be caught (i.e. in a try {} catch {} block) or not caught (i.e. unhandled exceptions).

You can set these options by going to the Breakpoints tab and then clicking either the "Uncaught Exceptions" or "Caught Exceptions" button (or both).

VS Code Extension

I've also worked on a VS Code extension, which enables debugging GJS applications inside of VS Code, however it reamins highly experimental and many features are not working yet.

This is because I focused on the Zed extension and it's the one I used during development extensively, so the VS Code extension is not as well tested as the Zed one, but I am also planning to improve it and submit it to the VS Code extensions marketplace in-time for the GNOME 52 release!

You can find instructions to use the VS Code extension in it's repo. Here is an example of it debugging an application:

<video src="/images/posts/gjs-dap-report/vscode.webm" loop muted autoplay controls></video>

Challenges

While working on this project, I had a few challenges:

Firstly, I really had trouble working well because of the remote nature of GSoC, and sometimes collaborating with my mentor would get off-tracked because I tended towards working alone instead of realising my mentor was available to help me. For future participants, I would advise you to realise that your mentor is available to help you, instead of feeling like you should be 100% independent. In my experience, a mentor will usually point you to the right solution, or even help you understand topics you might otherwise get blocked on for too long.

Code-wise, the most challenging part was getting the message parsing (i.e. sending DAP messages and receiving them through stdio) to work. I tried many approaches on my own (see point 1 above) but at the end it got resolved when I decided to ask my mentor for help.

The issue was complex because we needed to have access to the standard input as a stream so we can parse the protocol's Content-Length: {nBytes}\r\n headers, then read the corresponding number of bytes exactly. My first instinct was to use Gio.DataInputStream directly, but it didn't because it wasn't possible to load Gio/GLib imports in the main realm. The solution was to create a few functions (openInputStream, readLine and readBytes) on the C++ side since it can use the Gio/GLib APIs, then expose them to the JS code that implements the DAP communication (and linking with Firefox/Spidermonkey's Debugger API).

Another challenge I had was when implementing the VS Code extension. In the beginning, I wrote a Zed extension that would expose GJS' DAP capabilities to the Zed Editor. When working on a similar extension for VS Code, I got stuck a bit because VS Code doesn't have a native way to easily show the communications happening between the DAP client (in this case VS Code) and the DAP server (GJS), while Zed had an easy way to show them. This effectively hid a bug where Zed was sending/requesting an extra /r/n in the DAP requests & responses, while VS Code was not (they both implemented the standard differently). In the end, I created a wrapper script that would also log all the communications between the client and the server differently so I can diagnose that bug and fix it.

A recommendation I would give to future GSoC participants is to also track time and progress well. When working on the project, I didn't regularly check my proposal and the different activities and their timelines, so I ended up moving/reprioritising tasks towards the end of the program, which could have been avoided if I always checked the timeline to make sure I'm still on track and adjusting early.

Further Steps

There are some remaining tasks that could be done to make the GJS debugger better, and here's some of them.

  1. Bring the VS Code extension to feature parity as the Zed extension (see above).
  2. Add support for debugging GJS applications in GNOME Builder: Currently blocked by GNOME Builder itself lacking DAP support
  3. Add support for evaluating expressions in the debugger when paused.
  4. Correctly stop/kill the script when the debug session ends.
  5. Enabling source map support, which will make debugging compiled GJS (and TypeScript!) applications (like GNOME Weather, GNOME Sound Recorder) easier.
  6. Testing and ensuring the debugger works well on macOS and Windows (I only tested on Linux).
  7. Redirect console.log and other output to the debug console.
  8. Allow attaching to already running GJS applications (potentially by implementing a SIGUSR1 handler and communicating via unix socket).
  9. Allow pausing the program that's being debugged (at any point).
  10. Implement setting or modifying variables in the debugger.
  11. Give information about the current exception when we hit an exception breakpoint (needs the VS Code extension).
  12. Maybe implement watching source code and live-reload of the code while debugging.
  13. Implement more DAP capabilities (e.g. function breakpoints, conditional breakpoints) to improve the debugging experience even more (including correct presentationHint)
  14. Show the scopes in a better way (e.g. merge the global and GjsGlobal scopes, potentially merge the class body scopes, etc...)
  15. Maybe support debugging the GNOME Shell??
  16. Maybe implement GJS debugging (and provide instructions) for other DAP clients like Emacs, Vim, etc. (see full list of tools implementing DAP here)
  17. Maybe add documentation for debugging a GJS application while developing with meson (will need to add a run_target).

Let me know if there's more support you may want, or if you'd like to work on any of these.

Improving WASM Support

As part of the GSoC project, during the initial community bonding period, I also worked on improving WASM support in GJS. The MR essentially connects WASM's event loop to the GLib main loop set up by GJS.

Conclusion

I would like to thank Google Summer of Code for selecting me to work on this project, which I hope will improve the experience of writing, debugging and improve GJS applications.

I'd also like to thank the GNOME Project for hosting GJS, which is an important part of the GNOME ecosystem.

Finally, I'd like to thank my mentor Philip Chimento so much for his important skills, guidance, and support while I was working on this project.

You can reach out in the GNOME JavaScript room in Matrix: #javascript:gnome.org for any questions or feedback.

Where a Massive Solar Storm Could Take Down the US Power Grid for Millions

Slashdot - Hën, 07/09/2026 - 1:34pd
A new study published Friday in AGU Advances "depicts the most advanced picture yet of how a rare but massive solar storm could affect some US industries and electric systems more than others," reports CNN. "During a 250-year solar storm, the East Coast would have widespread potential for grid failure." Researchers modeled what a Carrington Event — a 1-in-150-year geomagnetic storm or even rarer — could mean for the modern day. They estimate the US economy would lose about $1.5 billion to $2 billion per day from direct and indirect costs, as millions of people face power outages. The findings show the most vulnerable areas are the Northeast and the Northern Plains, especially locations at higher latitudes. No one knows when the next big storm will hit. While the most severe geomagnetic storms are labeled as once-in-a-century or rarer, these events don't follow a fixed schedule. "That timing only averages out on very long timescales," said Anna Kelbert, a geophysicist at the Harvard-Smithsonian Center for Astrophysics, who was not involved in the study but previously studied solar storm effects on power grids. "The event can occur at any time, as soon as a week from now, or centuries later...." [Shawn Dahl, service coordinator at the Space Weather Prediction Center operated by the National Oceanic and Atmospheric Administration in Boulder, Colorado], said the sun is now coming down from a period of heightened activity, which is also when some of the biggest storms to hit Earth have occurred in the past. "We still need a lot of work to be ready...." "We haven't really seen events like this size in the modern era, where we've had all of this high technology and we've had the power grid of this size," said Ed Oughton, researcher at George Mason University and lead author of the new study... Because the US grid's actual structure is proprietary for security reasons, the team used engineering models to create various network and transformer setups including the 10,464 substations and 16,256 transmission lines found across the country... The grid structure also contributes to higher risk in some areas. For instance, the eastern US is linked together in a single grid interconnection. A voltage issue in Maine, if not isolated early, could cascade through the grid to Washington, DC. The West works similarly, whereas the Texas interconnection operates mostly within the state... Power is restored over time depending on any alternative electrical paths that could bypass the substation or availabilities of spare transformers, for instance. "This nationwide analysis shows that we are currently ill-prepared to face a major magnetic storm, and that the societal impacts would be catastrophic," Kelbert said. "The study estimates power disruptions for 5.1 million people and 135,000 businesses," according to the article, and "The outages could last from hours to days to weeks depending on the damage and resources available to get back online, said Oughton."

Read more of this story at Slashdot.

7.3-rc2: mainline

Kernel Linux - Hën, 07/09/2026 - 12:07pd
Version:7.3-rc2 (mainline) Released:2026-09-06 Source:linux-7.3-rc2.tar.gz Patch:full (incremental)

TiVo Will Start Charging Fees For Its Automatic Commercial Break-Skipping Feature 'SkipMode'

Slashdot - Dje, 06/09/2026 - 10:34md
TiVo is notifying customers about changes to "one of its longest-standing and most popular DVR features," reports the blog Cord Cutter News: Starting November 2, 2026, the current version of SkipMode that allows users to jump over commercial breaks with a single button press on the remote will no longer be available. The company is instead preparing to test a new paid add-on called Premium Auto Commercial Skip. SkipMode has been a core part of the TiVo experience for years. After a supported show finished recording, the service added markers that let viewers leap from the end of one program segment directly to the start of the next, bypassing the ads in between. On newer TiVo Experience 4 devices, users could even set the feature to automatic so commercials were skipped without any remote interaction. The feature was limited to popular prime-time programming on major networks, typically appearing a short time after a show aired. Under the new plan, that one-button and automatic functionality will disappear from the standard service. Viewers will still be able to skip commercials the traditional way by using the 30-second skip button or the fast-forward control on their remotes. Those manual methods have existed on TiVo boxes for more than two decades and do not rely on the company's commercial-detection data. In November, TiVo will offer a 30-day free trial of the new Premium Auto Commercial Skip service. After the trial ends, customers who want to keep the automatic or one-button skip capability will need to add it to their accounts for an extra monthly fee. The company has not yet published the price. Thanks to long-time Slashdot reader AmiMoJo for sharing the article.

Read more of this story at Slashdot.

Flock Offered Webinar Teaching Cops How to Surveil 'No Kings' Protesters

Slashdot - Dje, 06/09/2026 - 7:34md
Thursday 404 Media reported that Flock taught America's cops "how they could surveil the No Kings protests" against President Trump (as well as "small parades") in a webinar last year that described "using a mix of Flock's technology and law enforcement's own databases." In the webinar, Flock's director of market management Caity Peak explains how real time crime centers — which are police surveillance centers that utilize Flock cameras and other surveillance cameras — can be used for emergency response, but can also be used to surveil "established events" like 4th of July fireworks displays, parades, bike races, Mardi Gras, and protests. The webinar shows just how routine the idea of always-on surveillance has become, and how casually it is used during extremely innocuous events. Peak explains that police can use FlockOS, a software platform that combines Flock's automatic license plate readers (ALPR), drones, gunshot detectors, 911 data, and other surveillance cameras (including ones Flock does not own) into a "single pane of glass" or single piece of software to look at various types of surveillance in one place during both emergencies and relatively mundane events in a city or town. "Imagine that you're an incident commander, and you're working this No Kings Protest," Peak explains while a dashboard shows a series of surveillance tools overlaying the city of Denver. "If I'm somebody assigned a traffic post that's working this No Kings Protest, I really don't have time to go in [...] and look at all these places [for different intelligence]. This is an example of viewing all of that in one place...." The dashboard Peak shows includes traffic information, a "response plan" for the protest, the floor plans of nearby buildings, as well as a series of video feeds of both outdoor-mounted cameras and cameras inside businesses and government buildings. 404 Media and the Electronic Frontier Foundation previously showed that police have specifically used Flock cameras to monitor the No Kings protests and other First Amendment-protected activity... This webinar shows this type of surveillance is not anomalous, and is specifically taught by Flock. The webinar also shows that Flock's latest public stance — that its ALPR cameras are noninvasive technology, that they take only static images at a single place and time, and that they are primarily used to solve the worst crimes — is wildly misleading. Flock has time and time again pitched itself to police as a sort of operating system to solve crime and do real-time surveillance and predictive policing. ALPRs are just one part of this broader surveillance apparatus that Flock has created, markets to police, and teaches them how to use.

Read more of this story at Slashdot.

UN Votes To Encourage Map Projections More Accurately Reflecting the True Size of Continents

Slashdot - Dje, 06/09/2026 - 4:34md
The United Nations has an announcement. "The UN General Assembly has voted overwhelmingly to encourage governments, schools and tech companies worldwide to stop using maps that make Africa look far smaller than it really is." By 164 votes to one, Member States on Friday endorsed a resolution promoting map projections that more accurately reflect the true size of continents — the culmination of an African-led campaign against the 16th-century Mercator projection, still the most widely used map in the world. The United States cast the sole vote against, dismissing the initiative as part of a "radical ideological project." Six countries — Estonia, Georgia, Lithuania, Moldova, Serbia and Ukraine — abstained. The resolution does not ban the Mercator projection or impose a replacement. Instead, it encourages governments, schools, international organizations and technology companies to use the Equal Earth projection and other so-called equal-area maps when relative size matters, and to teach the limitations of any flat map in representing a spherical planet. Behind that seemingly technical debate lies a larger argument about history and power: whether a map designed for European sailors in the 16th century has, over generations, distorted not only geography but perceptions of a whole, vast and complex continent... [With Mercator maps] landmasses appear increasingly enlarged the farther they are from the Equator. Greenland, for instance, can look roughly comparable in size to Africa, even though Africa is about 14 times larger. Northern Europe and North America are similarly magnified, relative to equatorial regions. Despite its original navigational purpose, Mercator remains common in educational, media, digital and official materials. The resolution says those distortions have contributed to the "symbolic minimization" of Africa and perpetuated an unbalanced view of the world... Equal-area maps do not make Africa larger; they remove the exaggeration Mercator gives landmasses closer to the poles. The UN notes that hours before the vote, France's foreign minister announced the country was planning to abandon Mercator for its maps of the world.

Read more of this story at Slashdot.

Faqet

Subscribe to AlbLinux agreguesi