Today I have spent way too much time handling the https://copy.fail situation #copyfail
The persons who discovered it didn't notify the distribution security list, so no patched kernels was available for people to install when they released it.
But they did have time to write an exploit, and thought it was a good idea to distribute that on day one, before vendors had time to provide patches.
I'm not very impressed with xint.io, I guess it's the marketing department that runs the show.
I don't understand the hate against GPT. I think it's a great technology, and definitely a step in the right direction. Of course there are those who will resist it, but we should all accept it's here to stay.
For example, having a backup copy of the partition table at the end of the disk greatly increases the chances of being able to recover from disk corruption at the first few sectors of the disk.
...chatbot? What chatbot?
CopyFail Was Not Disclosed to Distros : https://www.openwall.com/lists/oss-security/2026/04/30/10
Update: not available
I'm donating #Pixel3 with installed #PostmarketOS #Phosh edge. It helps me open #mobileLinux world and now I prefer a more modern hardware.
I'd be happy to post it to someone who needs it as long it's in the EU. No payment needed.
You can also come collect it in #Helsinki
https://wiki.postmarketos.org/wiki/Google_Pixel_3_(google-blueline)
Update:
Thank you for the support. I'm going to send the phone to Hamburg. Happy coding!
Quickly dove into the copy.fail exploit.
1. Yes, it's real.
2. Current chain can write any arbitrary content to any user-readable file (into the page cache).
3. Current chain relies on an available target suid binary that you can open() as a lowpriv user.
4. Current exploit relies on that binary being /bin/su and then being able to execve(/bin/sh, 0, 0) (which doesn't work on alpine, etc.). The former is easily replaced in the code. The latter needs a rebuilt payload ELF (also easy).
Disclosure: in some cases, a Linux user can use doas to edit files in /etc/periodic/15min, allowing to execute code as root. I haven't reported this to cron because maintainer's e-mail address was so long I didn't want to type it.
lauren@hayasaka ~ $ doas python3 ./turbohack.py
lauren@hayasaka ~ $ tail -n2 /tmp/out.txt
[+] Executing: whoami
root
ios users; how old is your (main) phone (since release)?
don’t vote if your main phone isn’t an iphone and/or you don’t connect it to the internet
android users, how old is your (main) phone (since release)?
don’t vote if your main phone doesn’t run android and/or you don’t connect it to the internet
linux-postmarketos-qcom-msm89x7: Upgrade to v7.0.2-r0
New kernel rebase on the way.
Notable Changes:
- Redmi 4A, 5A, GO now have a common base.
- Redmi 4A, 5A, GO devicetrees are backported from upstream.
- Simplify panel pinctrls.
https://gitlab.postmarketos.org/postmarketOS/pmaports/-/merge_requests/8447
IF I WANTED CLAUDE TO CHANGE MY CODE I WOULD ASK IT MYSELF, I DON'T NEED SOMEONE WHO KNOWS NOTHING ABOUT THE PROJECT TO ASK CLAUDE TO MAKE CHANGES THEY DON'T UNDERSTAND
this benefit isn't really that convincing to me tbh
📍 Details for the postmarketOS conference are up, as well as a call for proposals!
ℹ️ Registrations are now open:
https://pretix.postmarketos.org/postmarketos-conference/2026/
Details:
https://postmarketos.org/conference/
CfP (deadline is 2026-06-30):
https://pretalx.postmarketos.org/postmarketos-conference-2026/cfp
"We are looking forward to your entry! No matter your background, everyone is welcome to be part of our event.
Your submission can be a short talk (max. 20 mins including questions), long talk (max. 60 mins including questions), workshop, meetup or discussion round (90 mins, for other durations please contact us).
The audience will consist of:
- kernel hackers
- distribution developers
- desktop environment maintainers
- activists
- end users
and potentially more groups of people. If your submission targets at least one of these groups, it's probably a good one! Ideally, it would also be related to postmarketOS in some way, but that is not a hard requirement."