Richard Hughes

@hughsie
2.4K Followers
553 Following
1.3K Posts
I write free software. Firmware troublemaker.
Websitehttps://hughsie.com/
GitHubhttps://github.com/hughsie
It's been a busy month...

I've just tagged a new libxmlb version with quite a few nice speedups. This is the XML query library used by #fwupd and gnome-software.

https://github.com/hughsie/libxmlb/releases/tag/0.3.28

Release 0.3.28 ยท hughsie/libxmlb

New Features: Automatically add system locales when using native-langs (Richard Hughes) Lower the Meson and GLib deps for RHEL-8 (Richard Hughes) Bugfixes: Lazy clear opcode tokens for a ~2% spe...

GitHub
@panda that's just one example; it's AWS or GCP in other places. I did try banning GCP but that prevented some customers that were mirroring the LVFS.
And for the "just block by IP address" crowd that's just not possible. The user agent is also different every time too, there's literally no way to block this without using kind of client-side challenge.

Okay, I've turned off all access to lvfs/hsireports (i.e. all the super useful security information people use before buying a laptop) and the load has returned to mostly normal.

I guess Anubis here I come.

PSA: Something is *hammering* the LVFS with requests, and it's under heavy load.

I'm going to turn off all the public generated pages until whatever crawler this is subsides.

Wow, this photo โšก๏ธ
๐—”๐— ๐—— running with ๐—ฐ๐—ผ๐—ฟ๐—ฒ๐—ฏ๐—ผ๐—ผ๐˜ on the ๐—ฆ๐˜๐—ฎ๐—ฟ๐—™๐—ถ๐—ด๐—ต๐˜๐—ฒ๐—ฟ.
It's not quite ready for release yet, but progress is looking good, and we can't wait to show you more.
Who's excited? :)

Any translation love for the #fwupd release scheduled for next week would be wonderful: https://hosted.weblate.org/projects/fwupd/fwupd/

Thanks!

fwupd/fwupd

fwupd is being translated into 50 languages using Weblate. Join the translation or start translating your own project.

Hosted Weblate
@bagder My strong advice would be to stop treating low severity security issues as such -- in fwupd they're just "normal bugs" now. 4 CVEs are much more manageable than 18.