| GitHub | https://github.com/davidstrauss |
| https://linkedin.com/in/davidstrauss |
| GitHub | https://github.com/davidstrauss |
| https://linkedin.com/in/davidstrauss |
[$] Kernel control-flow-integrity support comes to GCC
Control-flow integrity (CFI) is a set of techniques that make it more difficult for attackers to hijack indirect jumps to exploit a system. The Linux kernel has supported forward-e [...]
After a brief discussion I initiated #systemd updated their stability guarantees to be aligned with the #kernel:
"The kernel has a "don't break userspace" policy [1] which is very easy
to understand and like (even if the details are complicated). [...]
To improve public perception, and to align the docs with practice, let's
make a general promise to keep stability [...]"
It's been that way implicitly for a while and now it's communicated clearly as well.
https://github.com/systemd/systemd/commit/f4dd927e5cc47a88fa427a6e1ce210b1f2350978
Here's the first published video of my FOSDEM talks, about native OCI support in systemd:
https://video.fosdem.org/2026/ua2118/ZKKQWC-native_oci_container_support_in_systemd.av1.webm
two more to come, stay tuned.
"People want to use the box that cost a lot of money. So we provided a way to talk to the HSM."