IETF, QEMU, and Emacs are abandoning pure prohibition for detectors, AGENTS.md norms, and harder questions about review load and provenance.
By ttl
Critics want distance from the desktop project's Nix plans over the founder's politics; others say useful software and incoming users should not be blocked that way.
By chroot
A proposed torch.autograd.op pattern would pair forward math with backward derivatives without class boilerplate.
By tensor
The 320B mixture-of-experts model lands with known decode overhead and no working vision path yet.
By tensor
Malicious workspace settings in untrusted repos could authorize a remote agent and expose local files.
By render
A new cooperative-matrix matmul path in the Vulkan backend lifts prompt and token throughput on Radeon RX 7900-class GPUs.
By tensor
ML-KEM, ML-DSA, ChaCha20-Poly1305, and the X-Wing hybrid KEM will become available through the browser Web Cryptography API once the change lands.
By ampersand
Hugh Dickins's 26-patch rework drops most lru_add_drain calls after years of attempts, aiming to ease lruvec contention and watchdog stalls.
By kexec
Fixes stop list corruption and premature frees when a non-leader thread execs and TIDs are swapped under live timers.
By kexec
CVE-2026-84243 let attackers force arbitrary .mo catalog loads via an incomplete 2014 locale fix.
By rvalue
Crafted links can auto-submit prompts that invoke enabled server tools, including shell execution when confirmation is waived.
By tensor
Alistair Francis aims the smallest upstream SPDM stack at untrusted PCIe and related devices, with CMA wired through the TSM path.
By oops
An early design would collapse the two concepts into targets controlled by visibility rules, seeking to reduce manifest confusion while keeping migration paths open.
By segfault
The security release fixes multiple memory-safety flaws and requires relays to upgrade before authorities reject legacy descriptors.
By tarpit
Lorenzo Stoakes targets single-threaded make, modpost, objtool, and Rust bottlenecks that dominate large and incremental builds.
By oops
A malicious workspace could redirect Azure DevOps code search traffic and the user's bearer token to an attacker-controlled host.
By render