You are here

Agreguesi i feed

Pentagon Investigators Say Overreliance on Palantir AI Contributed to US Strike That Killed 123 Iranian Children

Slashdot - Mar, 22/09/2026 - 3:04md
Two U.S. missiles hit an elementary school in Iran, killing over 150 people including 123 children on the first day of the Iran War. But Gizmodo notes that a new Bloomberg investigation cites U.S. officials involved in an unreleased internal Pentagon review who blame "a cascade of preventable failures that included an overreliance on an AI tool built by Palantir." According to the officials who spoke to Bloomberg, some personnel inside U.S. Central Command leaned too hard on the AI inside the Maven Smart System, an AI-powered data integration and targeting platform developed by Palantir to accelerate intelligence analysis and decision-making. The Defense Department has reportedly made the software tool a cornerstone of military operations over the past year... Officials said some users expected Maven to flag stale records or contradictions in the intelligence assembled for potential targets, though it is not clear why they thought the system would do that. The Minab [elementary school] site, which was cataloged as an Islamic Revolutionary Guard Corps facility due to outdated data, was fed into Maven with other candidates and came out as a recommended day-one target. Target-list work that once took hours was condensed into minutes. A Palantir spokesperson told Bloomberg the company "is not responsible for the underlying data nor identifying intelligence deficiencies" and that there is no evidence its software was at fault. Two people familiar with Palantir's Pentagon contracts said the government keeps primary responsibility for the quality of the information that's fed into Maven. After the strike, Palantir added features that "re-review underlying intelligence to identify factors that would disqualify a target and flag inconsistencies and inaccuracies that human review may have missed," a person familiar with the work said. That new functionality is said to have already caught some anomalies... More than 1,000 Iranian targets were hit in the first 24 hours, and according to Bloomberg's sources, that pace compressed the time available for additional confirmations. Staffing on civilian harm mitigation teams across the U.S. Department of Defense had also fallen by roughly 90% over recent years, shrinking to fewer than 20 people overall. The U.S. Central Command's group shrank from 10 people to one. No member of those teams reviewed the Minab site before the missiles were up in the air. A separate inquiry by the United Nations' Independent International Fact-Finding Mission on Iran this week reached the conclusion that there were reasonable grounds to believe the United States committed the war crime of launching an indiscriminate attack.

Read more of this story at Slashdot.

Google Opens Preorders for Its $899 Gemini-Enhanced 'Googlebook' Laptops

Slashdot - Mar, 22/09/2026 - 10:34pd
Monday Google opened preorders for its "Googlebook" laptops, pricing them at $899. A Google's blog post added that "At launch, you can choose between Intel Core Ultra Series 3 and Snapdragon X Elite processors" (paired with NPUs to power AI features). "Devices will hit shelves on October 4 in the U.S. and on October 5 in Canada, the U.K., Ireland, France, Germany, and Australia," TechCrunch points out. But "the real pull for the new devices is that they'll prominently feature Gemini's latest capabilities in a new format: the laptop." Google is trying to offer a laptop with unique features like an AI-powered cursor, vibe-coded widgets, and support for AI-enhanced dictation. The latter is a feature called Rambler, which cleans up messy, rambling brain dumps into readable text. The move is a bet that AI, specifically Google's Gemini, could be enough of a draw to get people to buy a new laptop that bakes in AI instead of running them via desktop apps you install or access through the browser... On the Googlebook, Google is trying to reinvent the "point-and-click" experience of desktop computing to now include an AI element: The cursor serves as a conduit to Gemini. The company suggests various ways this could be used, like highlighting content on a web page for Gemini to work with, asking Gemini to see if an email you've hovered your cursor over is suspicious, or selecting images and then asking Gemini to visualize them together... What's more interesting about the Googlebook is how it's seemingly part of Google's longer-term plan to capture a large part of the K-12 market that currently relies on Chromebooks and push them toward the company's Gemini AI. There are somewhere around 50 million Chromebooks in schools, used by students and educators, Google has said. In May, the company told TechCrunch that its current Chromebooks would continue to be supported, though many would become eligible to transition to the new Googlebook experience in the future... Flagship devices in the new range are being built by Acer, ASUS, Dell, HP, and Lenovo, with materials like aluminum, magnesium alloy, and carbon fiber... Google says the device will offer up to 14 hours of battery life. Googlebooks will be decorated with an exterior Glowbar "which dances when you boot up, sweeps to show battery level, and supports other playful patterns," according to Google's blog post. "We're also opening Glowbar access to developers to build custom, interactive animations." After testing actual Googlebooks, The Verge's reviewer first acknowledges that "it might be just another Trojan horse for Gemini." Still, "The hardware is polished (since it's based on current laptops). The OS is familiar (if you've ever used a Chromebook). But most impressive, it integrates your Android phone with your PC so they feel more like one device. It's the culmination of a series of new ideas that blur the two devices together. "After my first look, I went from doubtful to excited by the prospect of Google pulling it all off..." The Asus was incredibly lightweight; the Lenovo has plenty of ports and an optional mouse with a matching Glowbar light; the Acer's convertible form factor allows some tablet-like use (and it's pretty affordable for a Panther Lake laptop). The HP had a great-looking screen and a latticeless keyboard I surprisingly didn't hate, and the Dell is basically a gold XPS 13 (which is excellent) but with a different chip... But everything really special about Googlebooks comes down to software... You can cast apps from an Android phone directly to a Googlebook, even without touching your phone. Googlebooks essentially have two app drawers: a G-logo start menu for installed Googlebook apps and a second one beside it that pulls up mobile apps from your phone. Click a phone app and you can fully use that app with the mouse and keyboard or the Googlebook's touchscreen. It's a bit like iPhone Mirroring on macOS, but the apps are individually extracted to the desktop OS instead of showing your whole phone interface. Googlebooks also have a nifty feature called Continue On where the icons of apps you're currently using on your phone appear in the bottom bar — allowing you to click it on the laptop and hand it off to the Googlebook. These app handoffs can transition to a native app or a web app, depending on how developers have programmed it... The other big way Googlebooks interact with an Android phone is Quick Access, allowing you to see and access all the files stored on your phone right in the desktop Files app... If you have an iPhone then you're limited to a Link to iOS app that just does some message syncing and replying... [W]hen it comes to mainline gaming, Nvidia's GeForce Now service is also coming to Googlebooks, and the first year is free with one of Google's new laptops. "It's not every day we get a new player in the desktop operating system and laptop spaces," the reviewer points out. "There seems to be a higher ceiling of potential with Googlebooks than there was with Chromebooks, along with some cool features, but Google has a lot to prove at higher prices than people are used to paying for its laptops."

Read more of this story at Slashdot.

CISA Confirms Active Exploitation of Linux Kernel Crypto Flaw

LinuxSecurity.com - Mar, 22/09/2026 - 7:30pd
CISA has added CVE-2025-39964, a flaw in the Linux kernel’s built-in cryptography interface, to its list of vulnerabilities being used in real attacks.

Researchers Show How Prompt Injection Could Expose AWS AgentCore Credentials

LinuxSecurity.com - Mar, 22/09/2026 - 7:15pd
Security researchers have shown how hidden instructions in an AWS AgentCore support ticket could push an AI agent into running commands as root and exposing a service credential.

crun Tightens GPU Security for Containers Running in MicroVMs

LinuxSecurity.com - Mar, 22/09/2026 - 7:15pd
The crun container runtime has changed how GPU-enabled workloads launch a key graphics helper.

Linux Fixes Two Memory Safety Bugs in DMA Cleanup

LinuxSecurity.com - Mar, 22/09/2026 - 6:45pd
Linux developers have fixed two memory-safety bugs in the subsystem that lets hardware move data without constant help from the CPU.

Linux Fixes Input Bugs That Could Leak Kernel Memory

LinuxSecurity.com - Mar, 22/09/2026 - 6:35pd
Linux developers have fixed two input-system bugs that could expose small pieces of leftover kernel memory to a local program.

Meta's New 'Personal AI Agent' Muse Beats ChatGPT in Downloads - and Get Blocked by Amazon

Slashdot - Mar, 22/09/2026 - 6:04pd
Meta's AI "personal agent" Muse overtook ChatGPT as the #1 iOS free app in the U.S. on Friday, reports CNBC — and it's still showing more downloads as of Monday night. Muse now has over 2.5 million downloads since its debut less than two weeks ago, according to analytics firm Sensor Tower... [Muse] is currently ahead of popular services like OpenAI's ChatGPT, Polymarket and Kashi... It's also ahead of rival AI apps like Anthropic's Claude and SpaceXAI's Grok AI, in addition to the Facebook-parent's own Meta AI app... Meta pitched the app as a way for consumers to manage and direct supercharged digital assistants that can perform a number of tasks across the web, like filling out electronic forms and organizing email inboxes... "I think up to this point most of the agentic use cases have not really been for normal people," Bernstein analyst Stacy Rasgon told CNBC in a "Squawk on the Street" interview on Monday. "Now you've got Meta's Muse and other agents out there that are starting to maybe get more potential for more broad-based adoption." The buzz around Meta was also reflected in the stock, which surged more than 11% on Monday. Amazon is already blocking Muse, reports GeekWire. Amazon first tried to get Meta to voluntarily exclude Amazon, but they were unsuccessful: The problem, Amazon says, is that it never agreed to any of it. Meta didn't tell Amazon that Muse would access its store, the agent doesn't identify itself when it browses, and it appears to capture and store customer credentials, which the company says could create privacy and security risks. As of Sunday night, people trying to use Muse to shop on Amazon were seeing the popup, "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed..." Amazon has spent the past year trying to keep outside agents off its site, suing Perplexity over its Comet browser and moving to block shopping agents from Google and OpenAI. [Amazon won a preliminary injunction against Perplexity in March, the article poitns out, "then lost it on Aug. 4, when the Ninth Circuit ruled that the user — not the AI company — was the one accessing Amazon's computers under federal anti-hacking law. The court denied Amazon's petition for rehearing on Sept. 10."] On Sunday night, Amazon said it is in direct conversation with Meta about the issue. Asked whether it would consider taking legal action, the company declined to comment. The business stakes are high for Amazon. In addition to operating its flagship e-commerce site, Amazon generated more than $68 billion in ad revenue last year — a business that depends on people browsing its pages and seeing sponsored products. Muse also appears to scrape account data, reports CNBC. But Shopify, however, "is working with Meta on Muse access. Shopify CEO Tobias Lütke announced Monday that the e-commerce site was partnering with Muse to allow agentic checkout in its online stores."

Read more of this story at Slashdot.

Paramount Skydance 'Emerges Victorious', Finally Wins Settlement for Warner Bros Takeover

Slashdot - Mar, 22/09/2026 - 1:34pd
Paramount Skydance just "emerged victorious" reports Reuters, "from a legal battle over its $110 billion acquisition of Warner Bros Discovery" that will "dramatically concentrate power across Hollywood's film, TV, streaming and news businesses." The victory comes "after settling with a California-led group of US states and a Hollywood writers union, paving the way for one of the largest media mergers in history." Paramount agreed to abide by temporary film quotas and a news oversight committee, avoiding a forced sale of cable assets such as CNN or any of its lucrative film franchises... The Writers Guild of America settled its parallel case against Paramount, while saying it still believes the deal will damage the industry. The states' settlement forced the union to "contend with the reality of forging ahead alone, with no backing from government enforcers" in a complex case that would have cost millions of dollars... Paramount promised in the state settlement to bring more film production to the US — spending at least $300 million more each year in domestic production — and adhere to US theatrical release quotas for five years. The company will produce 30 movies in each of the first two years of the deal, and 32 movies in each of the following three years, Bonta said. Each year, at least four of those films must be independent films and at least 20% must be blockbusters. If it falls below that threshold, it will pay $30 million per film, most of it into funds to support workers. Paramount also promised not to raise rates on theater operators for three years. The article notes that California attorney general Rob Bonta still said "I don't think these two companies should merge" at a press conference announcing the settlement, "but that's not something that we are focused on with our resolution here." He call their agreement "a strong antitrust outcome." And Politico notes that Bonta acknowledged at the press conference that "Some of you who may be watching this may have wanted a different outcome. I understand that." But he argued he'd reached a settlement capable of "providing more film production that protects Hollywood workers and their livelihoods, that places guardrails allowing for robust cable negotiations, that protects competition and creates more choice for consumers about what this merger could mean for the industry." It "resolves the antitrust concerns at the heart of our lawsuit against the company and Warner Brothers," he said... The agreement came as a disappointment to opponents of the transaction, including the Block the Merger Coalition, which cast the settlement as a sweetheart deal for Paramount Chief Executive David Ellison and his father, Oracle Co-Founder Larry Ellison, who is financially backstopping the acquisition. "This is a bad deal for the future of film, entertainment, independent journalism, and a strong democracy in this country," the coalition said in a statement. "We are disappointed and angry that the interests of average Americans have been trampled to benefit oligarch billionaires....." The $111 billion deal allows Paramount to combine its namesake streaming service with HBO Max, creating a new offering with about 200 million subscribers. That would help Paramount compete against companies such as Netflix, which boasts more than 325 million subscribers worldwide.

Read more of this story at Slashdot.

Linux Fix SELinux Overlays Important Security Contexts 401610

LinuxSecurity.com - Mar, 22/09/2026 - 1:00pd
Linux developers have fixed an SELinux flaw that could allow a program to make a mapped file executable after SELinux had blocked direct execution.

CISA Confirms Active Exploitation of Linux ebtables Flaw

LinuxSecurity.com - Mar, 22/09/2026 - 12:45pd
CISA has added CVE-2026-53266, a Linux kernel flaw in the ebtables bridge firewall, to its list of vulnerabilities known to be exploited.

As KDE Turns 30, Contributors and Commits are Going Strong

Slashdot - Hën, 21/09/2026 - 9:04md
"In a few weeks, KDE will turn 30 years old," writes core contributor Kevin Ottens, celebrating with some special KDE community data analytics (including a 30-year graph of the number of contributors): It peaks around 180 on average (and sometimes reaches towards around 200 people) then shrinks again hitting bottom around 110 persons on average in 2017... Since then, we had two major events happening. First, 2018 is the year where we had the first set of KDE Goals being picked by the community, one being "Streamlined onboarding of new contributors". Second, we had the transition to GitLab which was fully delivered early in the second quarter of 2020... Now it seems like the team size is around 140 people on average, so closer to the all time high of 2010 but we didn't fully close the gap yet. Interestingly though, the commit count is much closer to the one we had in 2010, with a bit less people. We even had an all time high commit count in 2023 which surpassed any other week since the creation of the project. And to make things even brighter, the trends at the end of the plot point upwards. Looks like 2026 will be a very good year. Hopefully the growth will stay stable this time and then the community will be the biggest it's ever been... [For the KDE Plasma desktop] We find the 2010 dip but it's much less dramatic than in all the other plots. It stabilized much quicker and managed to stay with an almost identical team size. We also find the increase leading up to 2020. And clearly it's one of the projects which benefitted the most of the GitLab transition. It's average team size almost doubled during the transition! Earlier I asked where the increase we could see on KDE as a whole but not on applications was coming from? Well, this is probably it. Like the rest of KDE, 2026 will be a very good year for Plasma as well. I wonder... will it double in size again next year compared to 2020? "I'm rather happy that KDE as a whole seems very healthy..." the post concludes. "It looks like in almost 30 years KDE built a great community and many awesome products..." "Kudos to all the people involved for the past 30 years! Even if you're not involved any more you helped contribute something beautiful and precious to the world. We're the living proof that large commons can be created and made sustainable thanks to passionate people."

Read more of this story at Slashdot.

Are Book Publishers Warming Up to the AI Industry?

Slashdot - Hën, 21/09/2026 - 4:34md
There's at least 15 author-driven lawsuits underway against AI companies, while publishers have filed roughly 10 more coordinated suits of their own, notes Publisher's Weekly. Yet "While the lawsuits play out, some publishers are building bridges." Google recently announced a partnership with Bloomsbury, De Gruyter Brill, Johns Hopkins University Press, Macmillan, O'Reilly Media, and Penguin Random House to enhance e-books from its Google Play store with AI, allowing readers to interact with the text of the books directly, ask questions and get answers, and develop tools such as quizzes and slideshows... [The CEO of the Author's Guild called the partnership "a positive step forward in the legitimized use of books in the AI ecosystem to the benefit of readers, publishers, and authors alike."] Of even more significance is the growing number of licensing deals publishers are striking with AI companies. In 2024, HarperCollins became the first of the Big Five to publicly reveal that it had signed a deal to license its content for AI training. The three-year agreement paid $5,000 per participating title, split equally between HarperCollins and the authors. Wiley announced its first AI licensing deal in 2024 and has since made several more. For fiscal year 2026, it reported earning $49 million in revenue from the deals. The company also has a number of strategic collaborations with companies including Amazon Web Services, Microsoft, Anthropic, Perplexity, IQVIA, OpenEvidence, and others. And publishers are even building in-house AI tools for producing royalty statements, proofreading, and providing customer service: In its 2025 Salary and Jobs Report, Publisher's Weekly reported that 63% of industry professionals surveyed said their organizations were using AI... Keith Riegert, president of the Stable Book Group and CEO of Perfect Bound, has been a vocal advocate for the use of AI in publishing — despite calling himself a "hardcore techno-pessimist." He tells PW, "I do this because you use AI or you die at this point...." Like many in the industry, he maintains any use of AI must "start with a human and end with a human," and he draws a clear line, avoiding AI for core creative work, such as selecting titles, designing covers, or creating illustrations — reserving it for developmental editing, formatting, and admin instead... What is known is that each of the Big Five is developing proprietary AI systems for internal use, as proven by the numerous AI-related job openings the companies have posted... [And the parent company of Penguin Random House said in 2025 they used AI for marketing and to forecast demand.] There've been a few high-profile controversies about prominent authors accused of using AI. But Princeton University Press CEO Christie Henry "is less concerned about authors secretly using AI to write than about the time spent policing the situation." "It pulls us away from having focused time to think," she says. Princeton University Press is currently vetting companies that promise to be able to certify that a given book was written by a human, including Created by Humans, Human Authored, and Verify My Writing. Henry adds that the proliferation of plagiarized, copycat, and pirated books online, now supercharged by AI agents mass producing and reproducing content, is further draining resources, as it demands constant vigilance and takedown requests sent to Amazon, YouTube, and others.

Read more of this story at Slashdot.

7.2.7: stable

Kernel Linux - Hën, 21/09/2026 - 3:09md
Version:7.2.7 (stable) Released:2026-09-21 Source:linux-7.2.7.tar.xz PGP Signature:linux-7.2.7.tar.sign Patch:full (incremental) ChangeLog:ChangeLog-7.2.7

6.18.53: longterm

Kernel Linux - Hën, 21/09/2026 - 3:06md
Version:6.18.53 (longterm) Released:2026-09-21 Source:linux-6.18.53.tar.xz PGP Signature:linux-6.18.53.tar.sign Patch:full (incremental) ChangeLog:ChangeLog-6.18.53

6.12.111: longterm

Kernel Linux - Hën, 21/09/2026 - 3:02md
Version:6.12.111 (longterm) Released:2026-09-21 Source:linux-6.12.111.tar.xz PGP Signature:linux-6.12.111.tar.sign Patch:full (incremental) ChangeLog:ChangeLog-6.12.111

Australia Considers Smart Glasses Ban in Government Workplaces, While 70 People Sue Meta Over Unknowing Data Collection

Slashdot - Hën, 21/09/2026 - 12:04md
"Australia is considering barring the use of camera-equipped smart glasses in government workplaces..." reports Reuters, "in what it said could be the first ban of its kind." But meanwhile "more than 70 people who bought, used or were recorded with Meta's smart glasses have sued the social media giant," reports the Los Angeles Times, "claiming their intimate and sensitive images were exposed to workers abroad who are paid to review and label photos and videos." The contractors in Kenya work for companies that help train Meta's artificial intelligence, according to a proposed class-action lawsuit amended in late August. The smart glasses users, some in California, allege the gadget captured footage of themselves and family members undressing, going to the bathroom, having sex and entering passwords. In some cases, the people said they weren't aware the camera-equipped glasses were recording. One California user, referred to as PL18 in the lawsuit, alleges his glasses were unknowingly recording after he placed the smart glasses on the bathroom counter. "He noticed that at times photos of his family members using the bathroom and bathing began appearing in his gallery — footage no one in his household intended to take," the lawsuit said.... The 230-page lawsuit, filed in a federal court in Northern California, accuses Meta of fraud and false advertising, along with violating other consumer protection laws in various states. Tina Wolfson, one of the lawyers representing the plaintiffs, said the case also centers on Meta's surveillance of people's lives without their consent and the exploitation of their image and likeness. "People who bought these glasses and thought that they were cool gadgets weren't aware that every time they activated AI, video was sent to train Meta's AI," said Wolfson, a principal at law firm Ahdoot & Wolfson in Burbank. Meta disagrees with the allegations and intends to fight them. "If you use Meta AI, we may review that data to help improve our products and people's experiences — this works the same way as many other companies. We take steps to filter this data to help remove identifying information and to protect people's privacy," a Meta spokesperson said in a statement... The lawsuit alleges people wearing the smart glasses were unwittingly transmitting data to Meta whenever they used Meta AI by saying "Hey Meta," or sometimes accidentally when adjusting the glasses. "Every activation of the AI features, intentional or accidental, captures video and audio that is transmitted to Meta's servers, routed overseas, and reviewed by low-paid human workers who watch, label, and embed these moments into Meta's AI models," the lawsuit said... The lawsuit also seeks to block Meta from deploying biometric tools through its glasses. The company has been exploring a controversial feature called "NameTag" that would allow people to identify others... A separate lawsuit, filed in September in a federal court in Illinois, alleges Meta has been using images of people's faces uploaded to their public Facebook and Instagram accounts to train AI that powers NameTag and other AI tools.

Read more of this story at Slashdot.

Carlos Garcia Campos: Skia compositor for WPE WebKit and WebKitGTK

Planet GNOME - Hën, 21/09/2026 - 10:40pd

WPE WebKit and WebKitGTK 2.54 have been released with a bunch of improvements and new APIs as usual, but there’s one point that kept the Igalia WebKit graphics team busy for the whole cycle: the new Skia-based compositor. The replacement of Cairo with Skia for content rendering has been a success and it’s already well integrated and optimized. We thought we could try to use Skia for the composition too and replace TextureMapper with Skia. TextureMapper was introduced in 2010 for the Qt port and later adopted by other ports. It uses the OpenGL ES API and maintains a collection of shader programs to paint different content. Nowadays TextureMapper is mostly the same code and shader programs, and it’s unmaintained and missing features. However, the performance was good and it has served us really well all these years. So, this time the goal was not to get better results in benchmarks, but to modernize the implementation, reduce the amount of code to maintain ourselves (like all shader programs) and make it easier to implement the missing features and fix existing bugs. This post is a summary of all the work we have done this cycle to implement the new Skia compositor.

SkiaCompositingLayer

The first step was adding an SkiaCompositingLayer class to replace TextureMapperLayer and adapt all the code to use one or the other depending on an environment variable. The initial implementation was based on the TextureMapper one for the things that are common like iterating the layer tree, computing transformations, etc. The way layers produced their contents didn’t change, so we were receiving textures for tiled content, video buffers, WebGL, accelerated 2D canvas, etc. SkiaCompositingLayer created a Ganesh Skia surface to draw those textures using SkCanvas::drawImageRect(). This initial implementation was enough to run the default MotionMark test suite, since it doesn’t use other composition features. Even though performance was not the goal, we had to make sure we didn’t regress. This initial implementation was neutral in MotionMark. We needed tests to implement those features and measure performance at the same time, so we decided to add a new set of tests to MotionMark, just extending the existing tests to require composition, which makes sure that filters, masks, path clipping, transformations, etc. were done by the compositor.

Filters

We first tried implementing filters using an intermediate surface like TextureMapper does. It worked, but the MotionMark score in the filters test was much worse. We realized that with Skia we could implement most of the filters without using an intermediate surface. All filter types except blur and drop shadow can be simplified to an SkColorFilter with SkImageFilter::asAColorFilter() which can be implemented without an intermediate surface, just by setting the color filter in the SkPaint we pass to SkCanvas::drawImageRect(). This not only fixed the performance regression, but also gave better results than TextureMapper, which always needs an intermediate surface.

Masks

There are two different kinds of masks: image mask, where the source mask is an image already, and clip path, where the mask is represented by a path to be clipped. In TextureMapper both are implemented the same way using intermediate surfaces. The mask is painted into a surface and then the masked layer creates an intermediate surface where its contents are first painted and then the mask contents on top using DstIn blend mode. Skia has APIs that allowed us to implement both cases in a much simpler and more efficient way. In the case of image masks, where we already have an image, we paint the mask contents once and keep it cached, and then the masked layer creates an SkShader for the image mask that is passed to SkCanvas::clipShader() without having to paint into an intermediate surface. Clip path masks are even easier, because we can just take the path we get and build an SkPath we can pass to SkCanvas::clipPath(), without having to paint the mask as an image at all or use any other intermediate surface. Once again, masks were not only easier to implement but they ended up being more performant too.

MotionMark composition suite, WPE with GPU rendering on a Raspberry Pi 4, comparing TextureMapper (312400@main) with the Skia compositor (313600@main). TextureMapper never implemented blend modes, so its high score on bouncing blend circles is the score for not doing the work.

3D contexts

The implementation of 3D layer contexts is fairly independent of TextureMapper and OpenGL, so we could just take it almost as it was, using SkPath to build the clips and a few other adaptations. We could also fix existing bugs like the z-ordering that has always been broken in TextureMapper.

The same page rendered by TextureMapper (left) and by the Skia compositor (right), WPE on the same build. The red box intersects the rotated green plane. TextureMapper draws the box flat against the plane, so the intersection is lost; the Skia compositor splits it, drawing the part in front of the plane and hiding the part behind it. Blend modes

TextureMapper never supported blend modes and they were easy to implement with Skia just using the SkPaint property for it. This made several layout tests start passing.

Batched painting

After implementing all the features we were at a point in which we had the same or better performance in all tests except for three MotionMark compositing tests that were giving much worse results. Those tests use small layers and give a high result which means we end up adding a lot of layers to the scene before we start skipping frames. The root cause was the large number of layers filling the command queue of Ganesh. Skia Ganesh queues the GL drawing operations instead of sending them to the GPU right away. When the surface is flushed for whatever reason, the queued GL drawing operations are then processed and sent to the GPU. This allows Skia to apply nice optimizations like merging several tasks and reducing the amount of draw operations we end up sending to the GPU. In those tests where a lot of layers are created and painted to the compositor Skia surface the internal command queue ends up being huge too. Processing and analyzing such a long queue to optimize what we send to the GPU required more CPU work than what we save by optimizing the GL draw operations. Skia provides an API that allows us to do the batching ourselves. Since the compositor already has information to decide what operations could be merged together, we could reduce the internal queue size in many cases. We can merge SkCanvas::drawImageRect() operations as long as they share the same color filter, blend modes and sampling options. In the best case scenario we could reduce the whole internal queue to just one operation. This time the change improved the results of those tests getting them to about 93% of the TextureMapper score, but still a bit behind.

Promise images

The Skia Ganesh backend requires that an SkImage backed by a texture is created for the current thread GrDirectContext, even if it’s borrowing an existing texture. In WebKit all textures are created with a sharing GL context so that they can be accessed and destroyed from different threads with the same sharing GL context. So, for a layer whose content is an image we had to create a texture in the compositing thread to upload the pixels if the image was not accelerated, or for accelerated images get the texture identifier of the image, and then create another SkImage from the compositing thread borrowing the texture for the current GrDirectContext. The Skia Ganesh backend provides an API to create promise images, which can be created from any thread but targeting a specific thread, providing a fulfill callback that will be called on the target thread when the SkImage is first used to retrieve the wrapped texture. This way we can create the SkImage from the main thread for the compositing thread without using OpenGL at creation time. For non-accelerated images we realized we don’t need to manually create the texture and upload the pixels in the compositor, we can just pass the unaccelerated SkImage to the compositor SkCanvas and Skia will handle it internally much more efficiently than we did. And this change improved those compositing tests much further than we expected. The reason turned out to be the batching from the previous section: Skia merges the entries of an image set by comparing texture proxy pointers, and until now we were wrapping the texture in a new SkImage on every frame for every layer, so hundreds of layers drawing the very same image produced hundreds of different proxies that Skia could not merge. Passing the same SkImage every time collapses all of them into a single draw operation, which is the best case we described above. With batched painting and promise images together we could beat TextureMapper significantly.

MotionMark composition suite, leaves subtests, WPE with GPU rendering. Score per revision; higher is better. The same two steps appear with CPU rendering. Deferred Display Lists (DDL)

When we switched to Skia for painting, we kept the threaded rendering model, just using a separate smaller queue for GPU rendering workers. The GPU workers created their own GrDirectContext to paint the layer tiles. The resulting textures were re-wrapped in the compositing thread for the compositor GrDirectContext using fences for the proper synchronization. We knew this was not the recommended way to use Skia Ganesh from multiple threads, but with TextureMapper we had no other option. However, with the Skia compositor we can do it the recommended way by using a single GrDirectContext in the compositing thread and use Deferred Display Lists (DDL) and promise images to paint the tiles. With DDL, GPU workers no longer use GL at all and they don’t need a GrDirectContext, they paint tiles into a display list that records the GL drawing operations, but without touching GL. For image drawing operations recorded into the DDL, promise images are used too. Since this is now all CPU work we can remove the smaller GPU worker queue and use a single queue with more workers. The compositor replays the DDL into an SkSurface that is then passed to the compositor SkCanvas.

This change fixed rendering glitches on Android and was performance neutral for the whole composition suite and for most of the MotionMark tests, but in MotionMark 1.3 at 15fps it cost 29% in Suits and 14% in Leaves, while improving Images by 9%. Correctness and the other benefits of DDL made us accept those regressions.

MotionMark 1.3 at 15fps, suits subtest, WPE with GPU rendering on a Raspberry Pi 4. Shaded regions are where deferred display lists were enabled by default. CPU rendering moves less than 1% at all three switches, since it has no GPU worker threads for DDL to change. Damage

TextureMapper already supported using damage information to optimize the painting while compositing, but it has always been disabled at run time because there were issues we never managed to fix. With the Skia compositor we decided to start from scratch and properly handle the damage information while compositing to render only the parts of the frame that actually changed. I’m not going to go into detail here because Nikolas Zimmermann has written an amazing blog post about it with all the details.

Current situation

The Skia compositor is finished and enabled by default in 2.54. Even though it was not the main goal, it performs better than TextureMapper in most of the benchmarks we run: the composition suite we added is 45% faster, and MotionMark 1.3.1 is 35% faster. The exception is MotionMark 1.3 at 15fps with GPU rendering, which comes out flat, because the Suits and Leaves tests are still about 26% and 10% behind due to the deferred display lists trade-off described above.

We are already working on fixing existing issues in composition that we never fixed in TextureMapper. In the main branch TextureMapper is now disabled by default at build time, and support will be removed soon for the GTK and WPE ports. In 2.54 it’s still a run-time decision so if you find any issue with 2.54, you can check if it’s a Skia compositor regression by trying TextureMapper with WEBKIT_USE_SKIA_FOR_COMPOSITION=0 environment variable.

Overall (geometric mean) score, WPE on a Raspberry Pi 4: 320000@main and later against the TextureMapper baseline at 312400-313296@main. Bars start at the baseline. Part of the gain in the MotionMark suites is Skia rendering work rather than the compositor. WPE on a Raspberry Pi 4, change from the TextureMapper baseline (312400-313296@main) to 320000@main and later. Suits and leaves are the deferred display lists trade-off, not the compositor switch, which was neutral in this suite. Future plans

We are already working on further improvements like using promise images for all external textures we have to pass to the compositor. We will explore the possibility of using Vulkan with the Ganesh backend instead of GL and eventually try the new Graphite backend. And of course we will continue fixing any existing issues related to the compositor.

North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide

Slashdot - Hën, 21/09/2026 - 7:34pd
"I would like to verify your technical abilities, so please download the specified file and complete the assigned task..." Fake job listings aimed at software developers and IT professionals led to 30,000 infected devices in over 100 countries — and 7,000 compromised cryptocurrency wallets, leading to over $10 million (USD) transferred to North Korea. Inc. reports: The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued Friday by Japanese, Australian, German, and U.S. authorities, including the Federal Bureau of Investigation and the Defense Department's Cyber Crime Center... The group reportedly has been active since 2023, carrying out both financially motivated attacks and cyberespionage... The hackers lure job seekers through social media, online job platforms, gig-work sites and freelance marketplaces. WaterPlum asks responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software. Once the group gains access to a device or network, it uses malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. An infected computer can also provide an avenue into the network of the target's employer, opening the door to intellectual-property theft and espionage, authorities said. The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad, officials said. The malicious files are "hosted on multiple online collaboration software developer platforms and code repositories," the advisory points out, and includes malicious Node Package Manager (NPM) packages.." Stolen ID images can also be used by North Korean IT workers to impersonate victims to obtain contracts and receive payment in foreign currency, but "The actors can also use stolen sensitive information for extortion." In one case, a North Korean IT worker "extorted a company over payment and published its proprietary source code online. In another case, an IT Worker hired for website maintenance defaced the hiring company's website and rendered the site inaccessible." The advisory provides clues for employers. It warns these malicious IT workers "tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person's name." During interviews they'd sometimes used Al face-swapping software, then claimed network issues and disabled their video. And "On holidays celebrated in North Korea, the actors played games and watched soccer videos instead of conducting their usual malicious activities."

Read more of this story at Slashdot.

Lawsuit Says Anthropic, OpenAI, SpaceXAI And Google Made Illegal Agreement On AI Slowdown

Slashdot - Hën, 21/09/2026 - 3:04pd
Tom's Hardware reports: Four plaintiffs subscribed to ChatGPT, Claude, Grok, or Gemini filed a proposed class-action lawsuit alleging that the developers of these AI models violated antitrust laws when they agreed to slow AI development. According to the Associated Press, the lawsuit argues that this agreement would "reduce the value consumers get for paid AI subscriptions" and that this coordination started in July 2026 after the leading AI labs signed a statement admitting there is "intense competitive pressure not to unilaterally slow" development. The plaintiffs recognize the need for AI development to slow for the sake of safety, but they say that Anthropic founder Dario Amodei's cooperation proposal is a "shortcut" that "substitutes collective restraint for individual accountability." Attorney Nick Rowley, the lead counsel for the plaintiffs, says, "AI will quickly spin out of human control and could kill us all if we allow AI safety and protocol ... to be controlled by private self-serving agreements between the world's most powerful 'for profit' technology companies." "Representatives for Anthropic, OpenAI, Google and SpaceXAI did not immediately respond..." reports the Associated Press: The coordination largely took place on Sept. 12, the lawsuit argues, when Anthropic CEO Dario Amodei published an essay urging for industrywide cooperation on decelerating advancements in favor of enhanced safety measures. That same day, OpenAI CEO Sam Altman, SpaceXAI CEO Elon Musk and Google DeepMind's co-founder and chair Demis Hassabis each publicly responded to Amodei's proposals in agreement. But the lawsuit also alleges that the coordination began to take shape months earlier. It points to a statement from July 2026 that high-ranking employees from several of the leading AI labs signed that acknowledged the "intense competitive pressure not to unilaterally slow" development. That statement called on the government to support a global effort to slow automated AI development. Sam Altman even specificially said "we do not believe we need to wait for an antitrust exemption or legislation to begin the work of providing this confidence," notes Tom's Hardware. However, the Trump administration shot down this idea... Chinese state media also criticized this announcement, saying that the call to put the brakes on AI development is nothing but a response to Chinese competition, especially as Amodei's essay explicitly mentioned the desire to slow China's progress and widen the U.S.'s gap over Beijing

Read more of this story at Slashdot.

Faqet

Subscribe to AlbLinux agreguesi