<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Gnu-Linux on Javier Orozco | Observer</title><link>https://orozco.observer/en/tags/gnu-linux/</link><description>Recent content in Gnu-Linux on Javier Orozco | Observer</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sun, 03 May 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://orozco.observer/en/tags/gnu-linux/index.xml" rel="self" type="application/rss+xml"/><item><title>Fedora 44 | Deep Technical Analysis: Kernel, Desktops and the Immutable Future</title><link>https://orozco.observer/en/videos/fedora-44-analisis-tecnico-profundo-kernel-escritorios-futuro-inmutable/</link><pubDate>Sun, 03 May 2026 12:00:00 +0000</pubDate><guid>https://orozco.observer/en/videos/fedora-44-analisis-tecnico-profundo-kernel-escritorios-futuro-inmutable/</guid><description>&lt;img src="https://orozco.observer/videos/fedora-44-analisis-tecnico-profundo-kernel-escritorios-futuro-inmutable/Portada.png" alt="Featured image of post Fedora 44 | Deep Technical Analysis: Kernel, Desktops and the Immutable Future" /&gt;&lt;div class="video-wrapper" style="position:relative;padding-bottom:56.25%;height:0;overflow:hidden;max-width:100%;"&gt;
&lt;iframe src="https://www.youtube-nocookie.com/embed/HNsF53SwpCc" style="position:absolute;top:0;left:0;width:100%;height:100%;" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen loading="lazy" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;

&lt;p&gt;Also available on Odysee: &lt;a class="link" href="https://odysee.com/@javierorozco.observer:6/Fedora-44---An%C3%A1lisis-T%C3%A9cnico-Profundo--Kernel,-Escritorios-y-el-Futuro-Inmutable:b" target="_blank" rel="noopener"
 &gt;https://odysee.com/@javierorozco.observer:6/Fedora-44---An%C3%A1lisis-T%C3%A9cnico-Profundo--Kernel,-Escritorios-y-el-Futuro-Inmutable:b&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ll take a deep technical dive into Fedora 44. I won&amp;rsquo;t focus on the visuals: I&amp;rsquo;ll do an overall review of Fedora 44 as such, regardless of whether it&amp;rsquo;s Workstation, the server edition, or a spin, since technically almost everything applies to any edition of the 44 branch. I&amp;rsquo;ll briefly review highlights from some desktop environments, but not much more, since the most interesting part is neither in the looks nor in the wallpapers.&lt;/p&gt;
&lt;p&gt;What I&amp;rsquo;ll do is open the terminal, check versions, and understand what changed in the kernel, in the tooling and development environments, in the Atomic Desktops, and in the OS image philosophy that Fedora is actively pushing toward the future.&lt;/p&gt;
&lt;h2 id="fedora-lead-dont-follow"&gt;&lt;a href="#fedora-lead-dont-follow" class="header-anchor"&gt;&lt;/a&gt;Fedora: Lead, Don&amp;rsquo;t Follow
&lt;/h2&gt;&lt;p&gt;Let&amp;rsquo;s start by looking at what Fedora is and where it stands in the GNU/Linux ecosystem. The first thing to clarify is that Fedora is not Ubuntu, nor does it emulate Debian&amp;rsquo;s idea of &amp;ldquo;stability&amp;rdquo;: its explicit philosophy is to lead, not follow. That means you&amp;rsquo;ll find versions of compilers, libraries, and frameworks that other distros don&amp;rsquo;t have yet, but also that major behavioral changes can appear from one release to the next.&lt;/p&gt;
&lt;p&gt;Red Hat Enterprise Linux uses Fedora as its base, that is, what gets tested here is what will reach the enterprise world. That gives Fedora a weight that goes far beyond being a &amp;ldquo;cool&amp;rdquo; distro.&lt;/p&gt;
&lt;p&gt;Support for each release is approximately 13 months. There is no &amp;ldquo;LTS&amp;rdquo; here, but new versions every six months: upgrading on time is not optional if you want to stay supported, but the system makes upgrading very easy, as we&amp;rsquo;ll see later.&lt;/p&gt;
&lt;h2 id="editions-spins-and-variants-more-options-than-ever"&gt;&lt;a href="#editions-spins-and-variants-more-options-than-ever" class="header-anchor"&gt;&lt;/a&gt;Editions, Spins, and Variants: More Options Than Ever
&lt;/h2&gt;&lt;p&gt;Fedora 44 has more variants than ever. The three main categories are:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Flagship editions&lt;/strong&gt;: here we have the main ones with the desktop of your choice, either GNOME on Workstation or KDE Plasma, these two being its official desktop versions. But also the spins with XFCE, Cinnamon, MATE with the Compiz window manager, i3, LXQT, LXDE, Sugar, Sway, Budgie, Miracle, Plasma Mobile, and COSMIC: there is literally something for every taste. Also an ISO for servers, IoT devices, cloud virtual machines, and a minimal edition ideal for containers.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The second category is Atomic Desktops&lt;/strong&gt;: in these the filesystem is read-only. To put it simply, it works like a mobile device running Android, where you simply have an app store and install everything from there. Base system updates are transactional and you can roll back from boot: Silverblue with GNOME, Kinoite with KDE, Sway, Budgie, and Cosmic. These atomic distributions are the future Fedora is actively pushing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And the third category is Fedora Asahi Remix&lt;/strong&gt;: this is Fedora running on Apple Silicon hardware natively, with KDE Plasma as the project&amp;rsquo;s flagship desktop. This is not emulation: it is the Linux kernel compiled for ARM with drivers specific to Apple hardware.&lt;/p&gt;
&lt;h2 id="system-requirements-llvmpipe-and-additional-desktops"&gt;&lt;a href="#system-requirements-llvmpipe-and-additional-desktops" class="header-anchor"&gt;&lt;/a&gt;System Requirements, LLVMpipe, and Additional Desktops
&lt;/h2&gt;&lt;p&gt;Let&amp;rsquo;s also look at the recommended system requirements: nothing revolutionary here compared to previous versions. The most interesting point is LLVMpipe: Fedora can run GNOME even on hardware without graphics acceleration, using the CPU for rendering. Obviously performance won&amp;rsquo;t be the same, but it&amp;rsquo;s functional for virtual machines without 3D acceleration or very old hardware.&lt;/p&gt;
&lt;p&gt;And it also lets us add a different desktop on an existing installation. We can see the available options with:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;dnf environment list
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;If we wanted to install, for example, Cinnamon:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf install @cinnamon-desktop-environment
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h2 id="installation-anaconda-btrfs-and-disk-encryption"&gt;&lt;a href="#installation-anaconda-btrfs-and-disk-encryption" class="header-anchor"&gt;&lt;/a&gt;Installation: Anaconda, Btrfs, and Disk Encryption
&lt;/h2&gt;&lt;p&gt;Let&amp;rsquo;s quickly go through the installation process. The installer change is subtle but relevant for administrators: previously, Anaconda created NetworkManager profiles for every network device it detected, even if you didn&amp;rsquo;t configure them during installation. Now only the profiles you actually configured persist. That means fewer ghost configuration files on the system. In partitioning we also have the BTRFS filesystem by default with @root and @home subvolumes, and as I always insist and will insist: enable full disk encryption to protect your data, with no exceptions. In fact, I think distributions should ship with encrypted system installation by default and enforced, and what should be done manually is disabling it.&lt;/p&gt;
&lt;p&gt;Support for aarch64 EFI and automatic DTB selection matters to the ARM community: for example, Fedora ISOs can now boot directly on Snapdragon laptops with no manual intervention to select the correct Device Tree.&lt;/p&gt;
&lt;h2 id="gnome-parental-controls-color-rdp-and-ibus"&gt;&lt;a href="#gnome-parental-controls-color-rdp-and-ibus" class="header-anchor"&gt;&lt;/a&gt;GNOME: Parental Controls, Color, RDP, and IBus
&lt;/h2&gt;&lt;p&gt;I&amp;rsquo;m going to dedicate a separate article to GNOME, so I won&amp;rsquo;t go into every detail of the desktop here. But I do want to name what Fedora&amp;rsquo;s own release notes called out as relevant.&lt;/p&gt;
&lt;p&gt;The most striking change from an everyday user&amp;rsquo;s point of view is the native &lt;strong&gt;Parental Controls&lt;/strong&gt; system, part of the Digital Wellbeing initiative (for those unfamiliar, it&amp;rsquo;s a term used to describe the impact of digital technologies and services on people&amp;rsquo;s mental, physical, social, and emotional health): for the first time you can set screen time limits and usage schedules directly from Settings, without installing anything extra. Useful on shared or family machines.&lt;/p&gt;
&lt;p&gt;The improvements in &lt;strong&gt;color management&lt;/strong&gt; and in &lt;strong&gt;RDP Remote Desktop&lt;/strong&gt; matter for professional workflows: Fedora has had native RDP support for several versions and GNOME 50 refines it further.&lt;/p&gt;
&lt;p&gt;Accessibility got improvements, and the default applications were also updated, such as the document viewer, the file manager, and the calendar.&lt;/p&gt;
&lt;p&gt;As for IBus 1.5.34: the change in support for Wayland input-method protocols applies mainly to environments like KDE, Sway, Hyprland, and COSMIC. GNOME handles input methods its own way, so on Fedora Workstation that IBus change isn&amp;rsquo;t felt directly. What is universal is the new &lt;strong&gt;WhisperCpp&lt;/strong&gt; voice backend in &lt;code&gt;ibus-speech-to-text&lt;/code&gt;, which now competes with Vosk by offering better accuracy, real multilingual support, and compatibility with quantized models.&lt;/p&gt;
&lt;h2 id="kde-plasma-66-login-manager-setup-and-spectacle-with-ocr"&gt;&lt;a href="#kde-plasma-66-login-manager-setup-and-spectacle-with-ocr" class="header-anchor"&gt;&lt;/a&gt;KDE Plasma 6.6: Login Manager, Setup, and Spectacle with OCR
&lt;/h2&gt;&lt;p&gt;I&amp;rsquo;m also going to dedicate a full article to Plasma, so here we&amp;rsquo;ll stick to the essentials.&lt;/p&gt;
&lt;p&gt;The two most important changes at the Fedora KDE level specifically are the &lt;strong&gt;Plasma Login Manager&lt;/strong&gt; (the new session manager) and &lt;strong&gt;Plasma Setup&lt;/strong&gt;, which complement each other: before you log in you&amp;rsquo;re greeted by the new Login Manager, and when you boot a fresh installation for the first time, Plasma Setup takes over to configure the user, timezone, and basic preferences. This makes Fedora KDE a viable option for OEM deployments: I can install the system on someone&amp;rsquo;s machine without creating their user in advance; they configure it on first boot, as in Windows.&lt;/p&gt;
&lt;p&gt;Replacing SDDM is architecturally significant: SDDM is a project external to the KDE ecosystem, while the new Login Manager is Plasma-native and integrated with systemd. Note that installations upgrading from Fedora 43 are not migrated automatically: SDDM stays. You have to switch it manually if you want it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf install plasma-login-manager kcm-plasmalogin
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo systemctl &lt;span class="nb"&gt;enable&lt;/span&gt; --force plasmalogin
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;The change takes effect starting with the next reboot.&lt;/p&gt;
&lt;p&gt;As for Plasma 6.6 itself: we get a new on-screen keyboard with a more modern implementation, an option to save your current setup as a custom global theme, color accent with per-window-frame tint strength adjustment, &lt;strong&gt;per-application volume from the taskbar&lt;/strong&gt; (no need to open the audio mixer to adjust a specific app), and the new &lt;strong&gt;Spectacle with OCR&lt;/strong&gt; screenshot feature, among the most useful for day-to-day use: you take a screenshot and can extract text directly with no need for external tools. You can also connect to WiFi using a QR code.&lt;/p&gt;
&lt;p&gt;We also get new accessibility options, and the per-window filter in &lt;strong&gt;screencasting from the title bar&lt;/strong&gt; solves a flow that used to be awkward: selecting exactly which window you&amp;rsquo;re sharing without leaving the application. One curious thing worth adding is that since the distribution&amp;rsquo;s release day, the manufacturer Star Labs, which builds machines with the open coreboot firmware, sells its machines directly with Fedora 44 preinstalled as one of the options to choose from.&lt;/p&gt;
&lt;h2 id="ntsync-in-the-kernel-and-goodbye-to-certpem"&gt;&lt;a href="#ntsync-in-the-kernel-and-goodbye-to-certpem" class="header-anchor"&gt;&lt;/a&gt;NTSYNC in the Kernel and Goodbye to cert.pem
&lt;/h2&gt;&lt;p&gt;This is the technical core of the analysis.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s talk about NTSYNC: it&amp;rsquo;s a kernel module that reimplements Windows synchronization primitives (such as mutexes or mutual exclusions, semaphores which are synchronization mechanisms between processes and threads, and events which are records generated by the operating system kernel listing critical activities such as memory allocation, input/output operations, system calls, and hardware errors). All of this now runs directly in kernel space.&lt;/p&gt;
&lt;p&gt;Without NTSYNC, Wine has to emulate these operations at user-space level, which introduces latency. With NTSYNC, the kernel speaks the same language as Windows applications, significantly reducing hardware resource overhead, especially in multithreaded games.&lt;/p&gt;
&lt;p&gt;We also need to talk about a silent change that can break things, and it&amp;rsquo;s the most dangerous change for production environments upgrading from Fedora 43: the &lt;code&gt;/etc/pki/tls/cert.pem&lt;/code&gt; file no longer exists by default. Any application hardcoding that path will fail certificate validation. The correct approach is to use the cryptographic libraries&amp;rsquo; APIs to resolve certificates, not a fixed path. Review your scripts and applications if you upgrade.&lt;/p&gt;
&lt;h2 id="dnf5-completes-the-transition-packagekit-on-libdnf5"&gt;&lt;a href="#dnf5-completes-the-transition-packagekit-on-libdnf5" class="header-anchor"&gt;&lt;/a&gt;DNF5 Completes the Transition: PackageKit on libdnf5
&lt;/h2&gt;&lt;p&gt;Let&amp;rsquo;s also analyze the package manager. DNF5 is not new in Fedora 44: it&amp;rsquo;s been the default package manager since Fedora 41. But in this release an important chapter of the transition is completed: &lt;strong&gt;PackageKit migrates to the DNF5 backend&lt;/strong&gt;. What does that mean in practice? That GNOME Software, Plasma Discover, and Cockpit, which use PackageKit underneath, now all talk to the same library: &lt;code&gt;libdnf5&lt;/code&gt;. Before F44, those tools still used the DNF4 backend, which produced inconsistencies between what you saw in the terminal and what the graphical interface did; for example, differences in how dependencies were resolved or in transaction history state. Now there is a single source of truth.&lt;/p&gt;
&lt;p&gt;The technical difference between DNF4 and DNF5 matters: DNF4 was written in Python, DNF5 is written in C++ on top of &lt;code&gt;libdnf5&lt;/code&gt;. That translates into faster dependency resolution, lower memory usage, and better performance on systems with many repositories. For users with RPM Fusion, COPR, and several active repositories, the difference is noticeable.&lt;/p&gt;
&lt;p&gt;If you come from an older Fedora and have scripts calling &lt;code&gt;dnf4&lt;/code&gt; directly, the compatibility package is still available, but you should migrate your commands since &lt;code&gt;dnf4&lt;/code&gt; is transitional and will disappear at some point.&lt;/p&gt;
&lt;p&gt;One important point: &lt;strong&gt;PackageKit with DNF5 as its backend is what makes Cockpit work correctly on Fedora Server 44&lt;/strong&gt;. If you administer Fedora servers via Cockpit and were on F43, this change consolidates the browser-based management experience.&lt;/p&gt;
&lt;h2 id="development-stack-ruby-40-and-mariadb-118"&gt;&lt;a href="#development-stack-ruby-40-and-mariadb-118" class="header-anchor"&gt;&lt;/a&gt;Development Stack: Ruby 4.0 and MariaDB 11.8
&lt;/h2&gt;&lt;p&gt;As for the development stack, Fedora always ships loaded with the very latest. &lt;strong&gt;Ruby 4.0 is the most delicate case, since it makes a major version jump from 3.4&lt;/strong&gt;, which is what Fedora 43 had. Packages using binary extensions need to be recompiled. If you have gems with native (C/C++) extensions, they must be rebuilt. Upstream paid attention to source-level compatibility, so in many cases you don&amp;rsquo;t need to change the Ruby code itself, but you do need to rebuild the extensions. We also get MariaDB 11.8 with a new default charset and vector functions optimized for machine learning, plus parallel dump and restore.&lt;/p&gt;
&lt;h2 id="nix-arrives-in-the-official-repositories"&gt;&lt;a href="#nix-arrives-in-the-official-repositories" class="header-anchor"&gt;&lt;/a&gt;Nix Arrives in the Official Repositories
&lt;/h2&gt;&lt;p&gt;Quite an important addition is that the Nix package manager now ships in the official repositories, and its operation is practically the same as what I showed in the Trisquel 12 analysis. Having Nix in the repos is an interesting signal, since it tells us Fedora accepts coexisting with other package managers, recognizing that Nix solves a real problem: reproducible environments and multiple versions of tools in isolation. The classic use case is development: for example, you need Python 3.9 for an old project and Python 3.13 for the new one; with Nix you can have both without them clashing.&lt;/p&gt;
&lt;h2 id="atomic-desktops-the-read-only-system"&gt;&lt;a href="#atomic-desktops-the-read-only-system" class="header-anchor"&gt;&lt;/a&gt;Atomic Desktops: The Read-Only System
&lt;/h2&gt;&lt;p&gt;Atomic Desktops are Fedora&amp;rsquo;s most philosophically different bet. The root filesystem is read-only: you can&amp;rsquo;t modify it directly even as root. Updates don&amp;rsquo;t go package by package mutating the live system, but instead a complete new deployment is prepared in the background, and on reboot the system switches everything at once, atomically. If something fails, from the GRUB menu you can go back to the previous deployment with no complicated recovery process.&lt;/p&gt;
&lt;p&gt;This completely changes the relationship with the package manager. On an Atomic Desktop you don&amp;rsquo;t use DNF directly for the base system: you use &lt;code&gt;rpm-ostree&lt;/code&gt;, which is what manages deployments. For user applications, the recommended route is Flatpak, which runs in its own sandbox and doesn&amp;rsquo;t touch the base system. And for cases where you need development tools or commands that don&amp;rsquo;t exist as Flatpaks, there&amp;rsquo;s Distrobox: a container where you can run any other GNU/Linux distribution that integrates with your terminal and your home directory as if it were part of the system, but isolated from the real operating system.&lt;/p&gt;
&lt;h2 id="bootable-containers-and-sealed-images-with-bootc"&gt;&lt;a href="#bootable-containers-and-sealed-images-with-bootc" class="header-anchor"&gt;&lt;/a&gt;Bootable Containers and Sealed Images with bootc
&lt;/h2&gt;&lt;p&gt;Let&amp;rsquo;s also talk about bootable containers. This is the most ambitious architectural change Fedora has underway. The idea is to bring the OCI container model to the complete operating system. Instead of a package system that keeps mutating with every &lt;code&gt;dnf upgrade&lt;/code&gt;, your OS is an immutable, versioned, signed image, exactly like a Docker image, but one the hardware can boot directly.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;bootc&lt;/code&gt; is the tool that manages this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo bootc upgrade
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo bootc rollback
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;With &lt;code&gt;bootc upgrade&lt;/code&gt; you update to a new OS image, or with &lt;code&gt;bootc rollback&lt;/code&gt; you go back if something fails, without depending on &lt;code&gt;rpm-ostree&lt;/code&gt; for the workflow.&lt;/p&gt;
&lt;p&gt;F44&amp;rsquo;s Sealed Images add a complete chain of trust on top: from firmware to the last byte of the rootfs, everything cryptographically verified. The immediate practical benefit is TPM-based disk unlocking without a password in a reasonably secure way (because the TPM only releases the key if the entire boot chain is as expected).&lt;/p&gt;
&lt;h2 id="fedora-cloud-boot-as-a-subvolume-and-end-of-qemu-on-i686"&gt;&lt;a href="#fedora-cloud-boot-as-a-subvolume-and-end-of-qemu-on-i686" class="header-anchor"&gt;&lt;/a&gt;Fedora Cloud: /boot as a Subvolume and End of QEMU on i686
&lt;/h2&gt;&lt;p&gt;This section focuses on Fedora Cloud, which is the edition designed for infrastructure deployments: virtual machines on cloud providers, QEMU/KVM instances, OpenStack images, and the like. It&amp;rsquo;s not the edition most people install on the desktop, but the changes it introduces have implications for Fedora&amp;rsquo;s overall direction.&lt;/p&gt;
&lt;p&gt;One of the changes is removing the separate &lt;code&gt;/boot&lt;/code&gt; partition. Historically, &lt;code&gt;/boot&lt;/code&gt; lived on its own partition because old bootloaders had limitations reading complex filesystems like Btrfs or LVM: they needed a simple partition with ext4 or similar to live on. That restriction no longer applies on modern UEFI systems with GRUB2 or systemd-boot, which understand Btrfs perfectly. So Fedora Cloud 44 takes the step: &lt;code&gt;/boot&lt;/code&gt; becomes a Btrfs subvolume inside the main volume, instead of its own partition.&lt;/p&gt;
&lt;p&gt;Why does this matter? Three concrete reasons. The first is space efficiency: before, you had to reserve a fixed size for &lt;code&gt;/boot&lt;/code&gt; at partitioning time. The dilemma was that if you made it too small it could fill up with old kernels, and if you made it too large you wasted space. With a subvolume inside Btrfs, space is shared and allocated according to real need. The second reason is that the resulting Cloud images are smaller because they don&amp;rsquo;t need to include that separate partition. And the third: this is consistent with the direction of the Bootable Containers from the previous section. If the entire operating system is going to live in a cryptographically verifiable Btrfs image, having &lt;code&gt;/boot&lt;/code&gt; as a subvolume of the same volume simplifies the whole chain.&lt;/p&gt;
&lt;p&gt;The change applies to all architectures supported by Fedora Cloud except IBM Z, which has its own scheme conventions, and UEFI-UKI images, which already have their own partitioning scheme for the Unified Kernel Image.&lt;/p&gt;
&lt;p&gt;The other change in this section is removing QEMU as a 32-bit host. To avoid confusion let me clarify this: QEMU still exists as an emulation target, that is, you can keep creating and running 32-bit virtual machines inside QEMU. What was removed is running QEMU itself on an i686 host, which is a practically nonexistent use case today. No current cloud server runs a 32-bit hypervisor.&lt;/p&gt;
&lt;h2 id="asahi-remix-official-mesa-for-apple-silicon"&gt;&lt;a href="#asahi-remix-official-mesa-for-apple-silicon" class="header-anchor"&gt;&lt;/a&gt;Asahi Remix: Official Mesa for Apple Silicon
&lt;/h2&gt;&lt;p&gt;Asahi Remix is a separate project but one that follows Fedora&amp;rsquo;s pace. Retiring the hand-patched Mesa is significant: it means the driver work for Apple Silicon has matured enough to be merged into official Mesa, which is what arrives directly from Fedora&amp;rsquo;s repos. Fewer custom patches, more long-term maintainability.&lt;/p&gt;
&lt;h2 id="post-install-rpm-fusion-codecs-drivers-and-firmware"&gt;&lt;a href="#post-install-rpm-fusion-codecs-drivers-and-firmware" class="header-anchor"&gt;&lt;/a&gt;Post-Install: RPM Fusion, Codecs, Drivers, and Firmware
&lt;/h2&gt;&lt;p&gt;Fedora comes out of the installer in a deliberately minimal state. It doesn&amp;rsquo;t ship with full ffmpeg, it doesn&amp;rsquo;t ship with proprietary codecs, and depending on the hardware the drivers may be in a basic state. That&amp;rsquo;s not a defect: it&amp;rsquo;s a conscious decision to honor the free software policy in the official image. But in practice, there&amp;rsquo;s a set of steps every Fedora installation needs to be ready for real use, and that&amp;rsquo;s what we&amp;rsquo;re going to do now.&lt;/p&gt;
&lt;p&gt;First is always syncing repository metadata and pulling in all updates released since the ISO was generated. The &lt;code&gt;--refresh&lt;/code&gt; flag forces synchronization even if DNF thinks the cache is current, important on installation day:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf upgrade --refresh
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;With the system up to date, next is enabling RPM Fusion. By policy Fedora doesn&amp;rsquo;t include patented software or proprietary code in its official repos, such as H.264 and H.265 codecs, and NVIDIA&amp;rsquo;s proprietary drivers aren&amp;rsquo;t there either. RPM Fusion exists precisely for that: Free for free software Fedora doesn&amp;rsquo;t include for licensing reasons, and Non-Free for what is directly non-free. They&amp;rsquo;re Fedora&amp;rsquo;s de facto complementary repos, maintained by the community for over a decade:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf install https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-44.noarch.rpm https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-44.noarch.rpm
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;With RPM Fusion active we can now install full ffmpeg. &lt;code&gt;--allowerasing&lt;/code&gt; is needed because Fedora ships with a trimmed ffmpeg-free that conflicts with RPM Fusion&amp;rsquo;s full ffmpeg: we&amp;rsquo;re telling DNF it may remove that package to resolve the conflict. For hardware decoding via VA-API, on Intel you need &lt;code&gt;intel-media-driver&lt;/code&gt;; on AMD the Mesa drivers already included are normally enough:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf install ffmpeg --allowerasing
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf install intel-media-driver
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;If you have an NVIDIA GPU, this is the time to install the proprietary drivers. I leave it commented out because I don&amp;rsquo;t have NVIDIA on this machine, but the flow is from RPM Fusion Non-Free with &lt;code&gt;akmod-nvidia&lt;/code&gt;, which compiles the kernel module automatically for each kernel update:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Only if you have an NVIDIA GPU (RPM Fusion Non-Free):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# sudo dnf install akmod-nvidia&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Flatpak comes preinstalled on Fedora Workstation, but Flathub isn&amp;rsquo;t enabled by default: you have to add it manually. Flathub is the central Flatpak repository and has the vast majority of applications you&amp;rsquo;ll want to install:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;flatpak remote-add --if-not-exists flathub https://flathub.org/repo/flathub.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;code&gt;fwupdmgr&lt;/code&gt; manages firmware updates directly from Linux: BIOS, NVMe SSD controllers, compatible peripherals. Many manufacturers already publish their firmware updates through LVFS, the service fwupd queries. Worth running on every fresh installation:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;fwupdmgr refresh
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;fwupdmgr update
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Fedora&amp;rsquo;s &amp;ldquo;Development Tools&amp;rdquo; group installs the base toolchain: GCC, make, autoconf and company, the minimum for compiling from source or working with native extensions:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf group install &lt;span class="s2"&gt;&amp;#34;Development Tools&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Lastly (although really I should have done this at the start), two lines that notably improve DNF speed in &lt;code&gt;/etc/dnf/dnf.conf&lt;/code&gt;: &lt;code&gt;max_parallel_downloads=10&lt;/code&gt; downloads up to ten packages simultaneously instead of the default of three, and &lt;code&gt;fastestmirror=True&lt;/code&gt; automatically selects the fastest available mirror for your connection:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ini" data-lang="ini"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="na"&gt;max_parallel_downloads&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="na"&gt;fastestmirror&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;True&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h2 id="upgrading-to-fedora-44-upgrade-rebase-and-golden-rules"&gt;&lt;a href="#upgrading-to-fedora-44-upgrade-rebase-and-golden-rules" class="header-anchor"&gt;&lt;/a&gt;Upgrading to Fedora 44: Upgrade, Rebase, and Golden Rules
&lt;/h2&gt;&lt;p&gt;The most frequent question every time a new Fedora version comes out is whether it&amp;rsquo;s worth doing an in-place upgrade or better to wipe and install clean. The short answer is that Fedora&amp;rsquo;s upgrade is remarkably well implemented and in most cases works without problems. But there are nuances worth being clear about before running it.&lt;/p&gt;
&lt;p&gt;Fedora&amp;rsquo;s upgrade is not like that of a rolling distro: it&amp;rsquo;s not DNF resolving dependencies live while the system runs. It can be done from the graphical interface or the console. What it does is download all packages needed for the new version in the background, and when the reboot runs, the system boots into a special, isolated update environment, with no services running, with nothing using the files about to be replaced. That drastically reduces the live-update problems that plague other distros. When you&amp;rsquo;re back on the desktop, you&amp;rsquo;re already on Fedora 44:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf system-upgrade download --releasever&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="m"&gt;44&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf system-upgrade reboot
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;An absolute rule: &lt;strong&gt;never skip versions&lt;/strong&gt;. If you&amp;rsquo;re on Fedora 41 or 42, first upgrade to 43, and from there to 44. Fedora&amp;rsquo;s upgrade system is neither designed nor tested for jumps of more than one version, and the chances of something ending up in an inconsistent state increase a lot.&lt;/p&gt;
&lt;p&gt;For &lt;strong&gt;Atomic Desktops&lt;/strong&gt;, the flow is different and in many ways cleaner: instead of an upgrade process, you do a &lt;code&gt;rebase&lt;/code&gt; to the new reference with &lt;code&gt;rpm-ostree rebase&lt;/code&gt;. The system downloads the complete new Fedora 44 image, and on reboot you simply activate the new deployment. The previous one stays available for immediate rollback if something fails. If you have RPM Fusion packages layered on Silverblue or Kinoite, you must first update the RPM Fusion reference to the new release before rebasing, or the layers will be left in an inconsistent state.&lt;/p&gt;
&lt;p&gt;And this edition&amp;rsquo;s specific warnings, which we already covered in earlier sections but must be kept in mind before running the upgrade: the removed &lt;code&gt;cert.pem&lt;/code&gt; if you have scripts or applications hardcoding that path, FUSE 2 removed on Atomic Desktops with the impact on AppImages and Plasma Vaults, and the Ruby 4.0 ABI break if you have gems with native extensions that need recompiling.&lt;/p&gt;
&lt;h2 id="conclusion-fedora-44-is-not-a-filler-release"&gt;&lt;a href="#conclusion-fedora-44-is-not-a-filler-release" class="header-anchor"&gt;&lt;/a&gt;Conclusion: Fedora 44 Is Not a Filler Release
&lt;/h2&gt;&lt;p&gt;Fedora 44 is not a filler release. It has real technical moves: the GNU Toolchain takes a major leap with GCC 16, Ruby 4.0 is a major version change with real implications for those using it in production, MariaDB 11.8 brings vector support for machine learning directly into the database, and NTSYNC in the kernel concretely improves Wine and Steam performance.&lt;/p&gt;
&lt;p&gt;But the most important change isn&amp;rsquo;t in any package version: it&amp;rsquo;s in the architectural direction. Sealed Images, Bootable Containers, bootloader unification, the Cloud migration to Btrfs subvolumes. Fedora is actively building the operating system model of the future: immutable, cryptographically verifiable, managed as code infrastructure.&lt;/p&gt;
&lt;p&gt;If you come from other distros and Fedora has always seemed &amp;ldquo;too bleeding-edge&amp;rdquo; to you, confusing that with &amp;ldquo;instability&amp;rdquo; or &amp;ldquo;malfunction&amp;rdquo;, this is the time to revisit it. The base is solid, the toolchain is the most modern in the RPM ecosystem, and the direction is crystal clear.&lt;/p&gt;
&lt;h2 id="sources-and-resources"&gt;&lt;a href="#sources-and-resources" class="header-anchor"&gt;&lt;/a&gt;Sources and Resources
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Official Fedora Linux 44 announcement — Fedora Magazine: &lt;a class="link" href="https://fedoramagazine.org/announcing-fedora-linux-44/" target="_blank" rel="noopener"
 &gt;https://fedoramagazine.org/announcing-fedora-linux-44/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;What&amp;rsquo;s new in Fedora Workstation 44 — Fedora Magazine: &lt;a class="link" href="https://fedoramagazine.org/whats-new-fedora-workstation-44/" target="_blank" rel="noopener"
 &gt;https://fedoramagazine.org/whats-new-fedora-workstation-44/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fedora 44 ChangeSet — Fedora Wiki: &lt;a class="link" href="https://fedoraproject.org/wiki/Releases/44/ChangeSet" target="_blank" rel="noopener"
 &gt;https://fedoraproject.org/wiki/Releases/44/ChangeSet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fedora downloads and editions: &lt;a class="link" href="https://getfedora.org/" target="_blank" rel="noopener"
 &gt;https://getfedora.org/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Ubuntu 26.04 LTS: Security, AI, Gaming and Kernel 7.0 | A New Era</title><link>https://orozco.observer/en/videos/ubuntu-26-04-lts-seguridad-ia-gaming-y-kernel-7-0-un-cambio-de-era/</link><pubDate>Mon, 27 Apr 2026 12:00:00 +0000</pubDate><guid>https://orozco.observer/en/videos/ubuntu-26-04-lts-seguridad-ia-gaming-y-kernel-7-0-un-cambio-de-era/</guid><description>&lt;img src="https://orozco.observer/videos/ubuntu-26-04-lts-seguridad-ia-gaming-y-kernel-7-0-un-cambio-de-era/Portada.png" alt="Featured image of post Ubuntu 26.04 LTS: Security, AI, Gaming and Kernel 7.0 | A New Era" /&gt;&lt;div class="video-wrapper" style="position:relative;padding-bottom:56.25%;height:0;overflow:hidden;max-width:100%;"&gt;
&lt;iframe src="https://www.youtube-nocookie.com/embed/qXoLXae1C2s" style="position:absolute;top:0;left:0;width:100%;height:100%;" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen loading="lazy" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;

&lt;p&gt;Also available on Odysee: &lt;a class="link" href="https://odysee.com/@javierorozco.observer:6/Ubuntu26.04:1" target="_blank" rel="noopener"
 &gt;https://odysee.com/@javierorozco.observer:6/Ubuntu26.04:1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;On the channel I already covered the ethical, purist approach to free software with the Trisquel 12 release. Now it is time for the industry heavyweight.&lt;/p&gt;
&lt;p&gt;On April 23, 2026, Ubuntu 26.04 LTS, codenamed &amp;ldquo;Resolute Raccoon&amp;rdquo;, was released. I know that every two years a new LTS comes out and every two years someone says &amp;ldquo;this is the most important one in history&amp;rdquo;, but this time I am going to argue why that claim carries more weight than ever.&lt;/p&gt;
&lt;p&gt;This edition brings changes that had been years in the making: the definitive move to Wayland, core tools rewritten in Rust for memory safety, CUDA and ROCm directly in the official repositories with no external repositories, and a 7.0 kernel that natively integrates artificial intelligence ecosystems.&lt;/p&gt;
&lt;p&gt;This is not a maintenance update. It is a change of era. If you manage servers, deploy infrastructure, game on Linux, or simply want to squeeze the most out of your hardware without depending on Windows, here I break down what this release really brings and what each change means.&lt;/p&gt;
&lt;h2 id="installation-and-tpm-encryption"&gt;&lt;a href="#installation-and-tpm-encryption" class="header-anchor"&gt;&lt;/a&gt;Installation and TPM encryption
&lt;/h2&gt;&lt;p&gt;Installing the system is quite intuitive and easy to understand. At the start, the usual: choose a language, keyboard layout, internet connection, installation type, extended selection for more default applications, proprietary drivers and codecs which are disabled by default, partitioning, and the most important part, encryption, which as I said in the previous article is something everyone should always enable, and under no circumstances or pretext should you use a disk or operating system without encryption. In this edition they have added hardware-backed protection with the TPM chip, and to try it out I used it this way in my installation.&lt;/p&gt;
&lt;p&gt;Basic details such as username, machine name, password, and the option to require the password at login, which I also always recommend enabling, especially with TPM, since the device boots automatically. Then we have timezone selection and a summary to confirm the installation; once completed, we simply reboot.&lt;/p&gt;
&lt;h2 id="the-desktop-gnome-50-and-the-definitive-farewell-to-xorg"&gt;&lt;a href="#the-desktop-gnome-50-and-the-definitive-farewell-to-xorg" class="header-anchor"&gt;&lt;/a&gt;The desktop: GNOME 50 and the definitive farewell to X.org
&lt;/h2&gt;&lt;p&gt;On boot we find a welcome wizard. The first thing it asks is whether we want to enable location services and telemetry to report errors or usage statistics. Both are anonymous, and Canonical has proven over the years to be a very ethical company, so this is left as each person&amp;rsquo;s individual choice. Then we have the choice between light and dark themes and highlight colors.&lt;/p&gt;
&lt;p&gt;As always, the first thing I recommend is installing the updates; there are not many, since this edition came out just a few hours ago:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt update &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo apt upgrade
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install fastfetch
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Let us start with what most people notice first: the desktop. Ubuntu 26.04 ships with &lt;strong&gt;GNOME 50&lt;/strong&gt; and marks a historic milestone: &lt;strong&gt;it is the first Ubuntu LTS with no X or X.org session available in GNOME&lt;/strong&gt;. Wayland is now the absolute king of the GNOME desktop. If you have old applications developed for X11, do not worry: &lt;strong&gt;XWayland&lt;/strong&gt; is still there as a compatibility layer and in most cases you will not notice the difference.&lt;/p&gt;
&lt;p&gt;But the benefits of Wayland are already undeniable. If you have a high-refresh-rate monitor, &lt;strong&gt;VRR&lt;/strong&gt; or variable refresh rate, also called G-Sync and FreeSync, can be enabled on supported displays. Per-monitor fractional scaling is now production-worthy. And the desktop flows without tearing, that is, without desynchronization, even under heavy load and at high refresh rates.&lt;/p&gt;
&lt;p&gt;The settings center covers the essentials quickly and concisely: the blue light or night light filter, wired networks, Wi-Fi, VPN and proxies, Bluetooth adapters, audio devices for both output and input and system sounds, power profiles, multitasking and screen edges, appearance and desktop customization, application management, permissions and notifications, dash search configuration, online accounts, and local file sharing and media streaming.&lt;/p&gt;
&lt;h3 id="the-new-default-applications"&gt;&lt;a href="#the-new-default-applications" class="header-anchor"&gt;&lt;/a&gt;The new default applications
&lt;/h3&gt;&lt;p&gt;GNOME 50 is not just the shell. The default application ecosystem changes quite a bit:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Showtime&lt;/strong&gt; as the video player. More modern, better system integration, and the option to install missing proprietary codecs if needed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Resources&lt;/strong&gt; replaces the old System Monitor. This one is especially interesting: it not only shows CPU and RAM, it also tracks &lt;strong&gt;GPU usage, hardware clock frequencies, and NPU (if you have one)&lt;/strong&gt; and groups processes by application instead of listing them individually. It is written in Rust with GTK4. It is what the system monitor should have been long ago.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ptyxis&lt;/strong&gt; is the new default terminal. What sets it apart is native support for managing containers with Podman, Toolbox, and Distrobox. As an example, I installed Fedora inside Ubuntu using Distrobox; yes, just as it sounds. That deserves a separate article, so I will not go deeper into it here, but the process is quite simple, and in the new terminal we always have access to all the containers we have listed: Ubuntu and Fedora living together on the same system. The new terminal also has session restore to recover your tabs and working directory locations when reopening. If you work with containers every day, this is a real quality-of-life change.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Loupe&lt;/strong&gt; is the new image viewer, also developed in Rust. &lt;strong&gt;Papers&lt;/strong&gt; is the new PDF viewer, based on the same code as the previous one but partially rewritten in Rust with GTK4.&lt;/p&gt;
&lt;h3 id="visual-changes"&gt;&lt;a href="#visual-changes" class="header-anchor"&gt;&lt;/a&gt;Visual changes
&lt;/h3&gt;&lt;p&gt;Visually, the dock no longer has transparency; it is completely opaque. Folder icons are now colorful. Notifications are grouped by application, ending the visual mess of having 40 individual notifications.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;App Center&lt;/strong&gt; now fully manages system &lt;code&gt;.deb&lt;/code&gt; packages —install, update, uninstall— in addition to snaps. More cohesion, less need to go to the terminal for basic operations. As an example, I installed a YouTube Music client this way.&lt;/p&gt;
&lt;p&gt;You may have noticed that two new search providers were added to the dash: there are App Center results and direct access to web searches in Firefox. Small details, but useful.&lt;/p&gt;
&lt;h3 id="nvidia-and-wayland"&gt;&lt;a href="#nvidia-and-wayland" class="header-anchor"&gt;&lt;/a&gt;NVIDIA and Wayland
&lt;/h3&gt;&lt;p&gt;If you use NVIDIA, historically the headache of Wayland on GNU/Linux, there are no more excuses: the proprietary &lt;strong&gt;595.x&lt;/strong&gt; series drivers are the standard in this release, Wayland support is complete, and the freeze issue when waking the machine from suspend is fixed. Versions 535, 550, 560, 570, 575, 580, and 590 are also available.&lt;/p&gt;
&lt;p&gt;There is also a new &lt;strong&gt;telemetry&lt;/strong&gt; panel —Ubuntu Insights— to opt in or out of sending anonymous metrics to Canonical. Important: it is completely &lt;strong&gt;opt-in&lt;/strong&gt;. Nobody sends your data without your explicit consent, and the controls are accessible from the welcome wizard.&lt;/p&gt;
&lt;h3 id="the-notable-absence"&gt;&lt;a href="#the-notable-absence" class="header-anchor"&gt;&lt;/a&gt;The notable absence
&lt;/h3&gt;&lt;p&gt;The &amp;ldquo;Software &amp;amp; Updates&amp;rdquo; application —which many used to manage PPAs, repositories, and drivers— &lt;strong&gt;no longer comes installed by default&lt;/strong&gt;. Canonical has not given a fully clear reason for this, and there is debate in the community. But it is still available in the repositories, and its departure from the base system is striking and worth mentioning:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install software-properties-gtk
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h2 id="security-in-its-dna-the-rust-revolution"&gt;&lt;a href="#security-in-its-dna-the-rust-revolution" class="header-anchor"&gt;&lt;/a&gt;Security in its DNA: the Rust revolution
&lt;/h2&gt;&lt;p&gt;Here is where things get serious. As someone who works in cybersecurity, seeing this in a &lt;em&gt;mainstream&lt;/em&gt; distribution that is the parent of so many others is music to my ears.&lt;/p&gt;
&lt;p&gt;Ubuntu 26.04 is the first LTS to &lt;strong&gt;aggressively&lt;/strong&gt; embrace Rust, the programming language that eliminates at compile time entire classes of vulnerabilities that have plagued C software for decades: buffer overflows, use-after-free, and memory race conditions.&lt;/p&gt;
&lt;h3 id="sudo-rs"&gt;&lt;a href="#sudo-rs" class="header-anchor"&gt;&lt;/a&gt;sudo-rs
&lt;/h3&gt;&lt;p&gt;You will notice it immediately in the terminal: &lt;strong&gt;sudo&lt;/strong&gt; has been replaced by &lt;strong&gt;sudo-rs&lt;/strong&gt;, the reimplementation in Rust. The most visible change is cosmetic but symbolic: you now see asterisks as you type your password. But what matters is underneath: the code that runs privileged operations on your system is no longer written in C.&lt;/p&gt;
&lt;p&gt;The original sudo is still available as &lt;code&gt;sudo.ws&lt;/code&gt; if you need specific features that sudo-rs does not cover yet.&lt;/p&gt;
&lt;h3 id="rust-coreutils-uutils"&gt;&lt;a href="#rust-coreutils-uutils" class="header-anchor"&gt;&lt;/a&gt;rust-coreutils (uutils)
&lt;/h3&gt;&lt;p&gt;Even deeper: the &lt;strong&gt;coreutils&lt;/strong&gt; —the most fundamental tools of the system, &lt;code&gt;ls&lt;/code&gt;, &lt;code&gt;cat&lt;/code&gt;, &lt;code&gt;base64&lt;/code&gt;, &lt;code&gt;head&lt;/code&gt;, and dozens more— are now &lt;code&gt;rust-coreutils&lt;/code&gt; by default, the implementation of the GNU utils in Rust.&lt;/p&gt;
&lt;p&gt;For most users this is transparent. But there is an important technical detail worth clarifying: &lt;code&gt;cp&lt;/code&gt;, &lt;code&gt;mv&lt;/code&gt;, and &lt;code&gt;rm&lt;/code&gt; are still the &lt;strong&gt;GNU&lt;/strong&gt; versions in this release, because there are unresolved bugs in the Rust implementations. If you need to switch back to GNU coreutils for everything, you can, and if you want to go back to Rust, you can too:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install coreutils-from-gnu
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install coreutils-from-uutils
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;There are also new &lt;strong&gt;kernel components written in Rust&lt;/strong&gt;. This is not just Ubuntu; it is part of the Linux kernel project&amp;rsquo;s effort, but Ubuntu 26.04 brings it to LTS-user mainstream for the first time. As a curiosity, rolling-release distributions such as Arch and openSUSE are still on the 6.x branch.&lt;/p&gt;
&lt;p&gt;Preventing memory vulnerabilities at the very foundation of the operating system raises the defensive posture of millions of installations. The Rust Foundation celebrated this publicly, noting that Canonical is raising security for millions of users in production.&lt;/p&gt;
&lt;h3 id="tpm-backed-fde-serious-disk-encryption"&gt;&lt;a href="#tpm-backed-fde-serious-disk-encryption" class="header-anchor"&gt;&lt;/a&gt;TPM-backed FDE: serious disk encryption
&lt;/h3&gt;&lt;p&gt;Hardware TPM-backed full-disk encryption &lt;strong&gt;leaves its experimental phase&lt;/strong&gt; in this release. It is the option we saw in the installer, and it is production-ready.&lt;/p&gt;
&lt;p&gt;What does this mean in practice? The encryption keys are tied to your motherboard&amp;rsquo;s TPM chip. Unlike traditional LUKS where you type a password on every boot, here the disk unlocks automatically when the TPM verifies that the system has not been tampered with, that is, that the hardware is the same, the bootloader was not altered, and there is nothing suspicious. If someone physically removes the disk and connects it to another machine, they cannot access the data. And if you want an extra layer, you can add a PIN.&lt;/p&gt;
&lt;p&gt;Against physical-access attacks, this raises the attacker&amp;rsquo;s cost significantly.&lt;/p&gt;
&lt;h3 id="post-quantum-cryptography"&gt;&lt;a href="#post-quantum-cryptography" class="header-anchor"&gt;&lt;/a&gt;Post-quantum cryptography
&lt;/h3&gt;&lt;p&gt;One last point that few people notice but that is strategically important: OpenSSL in this release includes support for &lt;strong&gt;post-quantum&lt;/strong&gt; algorithms: ML-KEM, ML-DSA, and SLH-DSA.&lt;/p&gt;
&lt;p&gt;Why does it matter now? Because quantum computers, once powerful enough, will be able to break the RSA and ECC cryptography that protects practically all of today&amp;rsquo;s digital infrastructure. Preparing the ecosystem for this transition before it becomes urgent —and not after— is exactly what needs to be done. Ubuntu 26.04 starts laying the groundwork.&lt;/p&gt;
&lt;h2 id="kernel-70-hardware-and-gaming"&gt;&lt;a href="#kernel-70-hardware-and-gaming" class="header-anchor"&gt;&lt;/a&gt;Kernel 7.0, hardware, and gaming
&lt;/h2&gt;&lt;p&gt;The engine behind all of this is &lt;strong&gt;Linux 7.0&lt;/strong&gt;. It is the highest version number to reach an Ubuntu LTS in a long time, and it comes loaded.&lt;/p&gt;
&lt;h3 id="intel-panther-lake-and-npu-support"&gt;&lt;a href="#intel-panther-lake-and-npu-support" class="header-anchor"&gt;&lt;/a&gt;Intel Panther Lake and NPU support
&lt;/h3&gt;&lt;p&gt;Kernel 7.0 adds full support for &lt;strong&gt;Intel Core Ultra Series 3&lt;/strong&gt; processors, codenamed Panther Lake. This includes optimizations for the integrated Xe3 graphics and for the integrated &lt;strong&gt;NPU&lt;/strong&gt; (Neural Processing Unit). If you are on a modern Intel laptop and want to run local AI inference efficiently without depending on a server, this combination of hardware and kernel starts to make real sense.&lt;/p&gt;
&lt;h3 id="amd-and-nvidia"&gt;&lt;a href="#amd-and-nvidia" class="header-anchor"&gt;&lt;/a&gt;AMD and NVIDIA
&lt;/h3&gt;&lt;p&gt;On AMD, Mesa 26 brings &lt;strong&gt;ray tracing with the ACO compiler by default&lt;/strong&gt; and general performance improvements. GPUs from the RX 6000 series onward benefit directly. For those of us running a Radeon card, there are concrete improvements in rendering performance and compute workloads.&lt;/p&gt;
&lt;p&gt;On NVIDIA, as I mentioned before: Wayland works fully, suspend is fixed, and the 595 series drivers are the standard. There are no longer technical reasons to avoid Linux on NVIDIA machines, although there are ethical ones —but that is another topic.&lt;/p&gt;
&lt;h3 id="kernel-livepatch-for-arm64"&gt;&lt;a href="#kernel-livepatch-for-arm64" class="header-anchor"&gt;&lt;/a&gt;Kernel Livepatch for ARM64
&lt;/h3&gt;&lt;p&gt;Until this release, Canonical&amp;rsquo;s &lt;strong&gt;Kernel Livepatch&lt;/strong&gt; —which applies critical security patches directly to the running kernel &lt;strong&gt;without rebooting&lt;/strong&gt;— only worked on x86-64. With Ubuntu 26.04, it comes to &lt;strong&gt;ARM64&lt;/strong&gt; for the first time.&lt;/p&gt;
&lt;p&gt;For organizations with ARM servers, this is huge. Before, a critical kernel security patch meant a reboot with a maintenance window and downtime. Not anymore.&lt;/p&gt;
&lt;h3 id="ethercat-for-industrial-automation"&gt;&lt;a href="#ethercat-for-industrial-automation" class="header-anchor"&gt;&lt;/a&gt;EtherCAT for industrial automation
&lt;/h3&gt;&lt;p&gt;An addition that goes unnoticed by common users but is significant for specific sectors: the &lt;strong&gt;IgH EtherCAT Master&lt;/strong&gt; module and the Generic Ethernet driver are now integrated directly into the kernel. EtherCAT is a real-time industrial networking protocol with microsecond precision, used in robotics, motion control, and factory automation. Having this in the kernel of an official LTS removes a huge integration burden for engineers in that sector.&lt;/p&gt;
&lt;h3 id="gaming-ntsync-and-the-end-of-the-windows-pretext"&gt;&lt;a href="#gaming-ntsync-and-the-end-of-the-windows-pretext" class="header-anchor"&gt;&lt;/a&gt;Gaming: NTSYNC and the end of the Windows pretext
&lt;/h3&gt;&lt;p&gt;And we reach the point I know several of you were waiting for.&lt;/p&gt;
&lt;p&gt;If you are one of those who spend hours cleaning up Windows —disabling telemetry, bloatware, background processes— or installing trimmed-down builds of dubious origin to avoid losing FPS in the middle of a game, this kernel has something for you.&lt;/p&gt;
&lt;p&gt;The kernel ships &lt;strong&gt;NTSYNC&lt;/strong&gt; built into Linux 7.0, which emulates Windows NT kernel synchronization primitives directly. This strongly impacts the performance of Windows games and applications running through &lt;strong&gt;Wine and Proton&lt;/strong&gt;. Titles that depend heavily on inter-thread synchronization see real, measurable performance improvements.&lt;/p&gt;
&lt;p&gt;Combined with Wayland, Mesa 26, and well-supported NVIDIA and AMD drivers, gaming on GNU/Linux is no longer &amp;ldquo;an alternative&amp;rdquo;. It is a direct threat to Windows&amp;rsquo; dominance on the gaming desktop. There are still edge cases where Windows is necessary, but the gap is closing with every release, and this one in particular accelerates that process.&lt;/p&gt;
&lt;h2 id="cuda-and-rocm-in-the-repositories-ubuntus-ai-moment"&gt;&lt;a href="#cuda-and-rocm-in-the-repositories-ubuntus-ai-moment" class="header-anchor"&gt;&lt;/a&gt;CUDA and ROCm in the repositories: Ubuntu&amp;rsquo;s AI moment
&lt;/h2&gt;&lt;p&gt;This is the change that will have the most impact over the coming years for AI and machine learning developers.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For the first time in Ubuntu&amp;rsquo;s history, NVIDIA CUDA is available directly in the official repositories.&lt;/strong&gt; Before, installing CUDA meant adding NVIDIA&amp;rsquo;s repository manually, dealing with versions that could break system dependencies, and resolving driver conflicts. Now it is simply:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install cuda
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;No external repositories. No surprises.&lt;/p&gt;
&lt;p&gt;The same applies to &lt;strong&gt;AMD ROCm&lt;/strong&gt;, AMD&amp;rsquo;s open-source ecosystem for GPU-accelerated workloads —artificial intelligence, machine learning, HPC—. For those of us with AMD hardware, having ROCm available this cleanly completely changes the equation for experimenting with frameworks like PyTorch or JAX on AMD GPUs.&lt;/p&gt;
&lt;p&gt;Why does it matter that they are in the official repos and not in external PPAs? Because the packages go through Canonical&amp;rsquo;s validation and security chain. Updates are tested to work together with the rest of the system. For organizations deploying this in production, the difference between &amp;ldquo;it works today and breaks with the next apt upgrade&amp;rdquo; and &amp;ldquo;it is validated for this LTS&amp;rdquo; is fundamental.&lt;/p&gt;
&lt;p&gt;AMD&amp;rsquo;s own vice president of Software highlighted that this allows developers to build and deploy on AMD Radeon and Ryzen GPUs with direct access from the repositories, without friction.&lt;/p&gt;
&lt;p&gt;Ubuntu 26.04 is making a very clear positioning statement: it wants to be &lt;strong&gt;the reference platform for AI development and deployment&lt;/strong&gt;. With CUDA + ROCm in the repos, native Intel NPU support in the kernel, and confidential computing for private AI, the argument is solid.&lt;/p&gt;
&lt;h2 id="system-plumbing-apt-and-systemd"&gt;&lt;a href="#system-plumbing-apt-and-systemd" class="header-anchor"&gt;&lt;/a&gt;System plumbing: APT and systemd
&lt;/h2&gt;&lt;p&gt;There are &amp;ldquo;plumbing&amp;rdquo; changes that go unnoticed but that for the daily work of sysadmins, programmers, or advanced users are as important as anything else.&lt;/p&gt;
&lt;h3 id="apt-31-transaction-history-at-last"&gt;&lt;a href="#apt-31-transaction-history-at-last" class="header-anchor"&gt;&lt;/a&gt;APT 3.1: transaction history at last
&lt;/h3&gt;&lt;p&gt;The package manager moves up to version 3.1 and brings the functionality we all dreamed of: &lt;strong&gt;interactive transaction history&lt;/strong&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt history-list
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt history-info &lt;span class="m"&gt;0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt history-undo &lt;span class="m"&gt;0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt history-rollback
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;code&gt;apt history-list&lt;/code&gt; shows what you installed, when, and what changed. &lt;code&gt;apt history-info 0&lt;/code&gt; details a specific transaction. &lt;code&gt;apt history-undo 0&lt;/code&gt; undoes an installation. And &lt;code&gt;apt history-rollback&lt;/code&gt; takes you back to an earlier point of the system.&lt;/p&gt;
&lt;p&gt;In production, this is a lifesaver. Did you update a package and something broke? Now you have a clean path to roll back. Tools like dnf and pacman have had something like this for a long time; its arrival in APT is welcome.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;apt-key&lt;/code&gt;, long deprecated, was also removed. Signature verification now uses &lt;code&gt;gpgv&lt;/code&gt; directly. If you have automation scripts that use &lt;code&gt;apt-key&lt;/code&gt;, review them.&lt;/p&gt;
&lt;h3 id="systemd-259-two-important-changes"&gt;&lt;a href="#systemd-259-two-important-changes" class="header-anchor"&gt;&lt;/a&gt;systemd 259: two important changes
&lt;/h3&gt;&lt;p&gt;First: support for &lt;strong&gt;cgroup v1&lt;/strong&gt; (legacy and hybrid) is removed. If you have containers or configurations that depend on legacy cgroups, you need to migrate. This must be reviewed before upgrading production systems.&lt;/p&gt;
&lt;p&gt;Second: this is the &lt;strong&gt;last LTS with System V script compatibility&lt;/strong&gt; in systemd. From here on, if you have services with SysV-style init scripts, the clock is ticking to migrate them to native systemd units. It is not urgent today, but the signal is clear.&lt;/p&gt;
&lt;p&gt;One extra technical detail: the &lt;code&gt;/tmp&lt;/code&gt; directory is now mounted by default as &lt;strong&gt;tmpfs in RAM&lt;/strong&gt;. It reduces SSD wear on servers and improves the performance of temporary operations.&lt;/p&gt;
&lt;h3 id="dracut-replaces-initramfs-tools"&gt;&lt;a href="#dracut-replaces-initramfs-tools" class="header-anchor"&gt;&lt;/a&gt;Dracut replaces initramfs-tools
&lt;/h3&gt;&lt;p&gt;The initial ramdisk system is now &lt;strong&gt;Dracut&lt;/strong&gt; by default, replacing initramfs-tools. It uses systemd in the initial RAM disk and natively supports Bluetooth and NVMe over Fabrics, which offers a faster and more efficient connection between storage and servers, in addition to reducing host CPU utilization by applications. If you have very specific scripts or hooks that depended on initramfs-tools, check compatibility.&lt;/p&gt;
&lt;h3 id="chrony-and-time-synchronization"&gt;&lt;a href="#chrony-and-time-synchronization" class="header-anchor"&gt;&lt;/a&gt;Chrony and time synchronization
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Chrony&lt;/strong&gt; replaces &lt;code&gt;systemd-timesyncd&lt;/code&gt; as the default time daemon, with support for Network Time Security, &lt;strong&gt;NTS&lt;/strong&gt; for short (authenticated and encrypted time), using Ubuntu&amp;rsquo;s time servers. For high-availability clusters where precise time synchronization is critical, Chrony is the right choice. On the GNOME desktop we can also add other time zones; in my case, since I casually work with the stock market, I am always interested in adding New York and London times to keep stock exchange opening and closing hours in mind.&lt;/p&gt;
&lt;h3 id="amd64v3-opt-in-performance-for-modern-hardware"&gt;&lt;a href="#amd64v3-opt-in-performance-for-modern-hardware" class="header-anchor"&gt;&lt;/a&gt;amd64v3: opt-in performance for modern hardware
&lt;/h3&gt;&lt;p&gt;If your CPU is more than a few years old and is 64-bit, it probably supports level 3 microarchitecture, which includes AVX2 —which delivers better performance by accelerating operations in parallel— and other modern instructions. Ubuntu 26.04 offers packages compiled for &lt;strong&gt;amd64v3&lt;/strong&gt; as an opt-in variant. To enable them:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;APT::Architecture-Variants &amp;#34;amd64v3&amp;#34;;&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sudo tee /etc/apt/apt.conf.d/99enable-amd64v3
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt update &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo apt upgrade
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Real performance improvements in applications that take advantage of them. No risk: if your hardware does not support it, it simply will not activate.&lt;/p&gt;
&lt;h2 id="cloud-enterprise-and-virtualization"&gt;&lt;a href="#cloud-enterprise-and-virtualization" class="header-anchor"&gt;&lt;/a&gt;Cloud, enterprise, and virtualization
&lt;/h2&gt;&lt;p&gt;For the enterprise and cloud segment, there are several points worth noting.&lt;/p&gt;
&lt;h3 id="confidential-computing"&gt;&lt;a href="#confidential-computing" class="header-anchor"&gt;&lt;/a&gt;Confidential Computing
&lt;/h3&gt;&lt;p&gt;Ubuntu 26.04 supports both &lt;strong&gt;Intel TDX&lt;/strong&gt; and &lt;strong&gt;AMD SEV&lt;/strong&gt; for confidential computing, both as host and guest. Simply put: you can run virtual machines where neither the hypervisor nor the host system can access the VM&amp;rsquo;s memory. Memory is encrypted at the silicon level.&lt;/p&gt;
&lt;p&gt;The most relevant use case is AI workloads on shared infrastructure where the privacy of training or inference data is critical. This is not science fiction: it is infrastructure available today, in a long-supported Ubuntu release.&lt;/p&gt;
&lt;h3 id="authd-cloud-authentication-without-extra-infrastructure"&gt;&lt;a href="#authd-cloud-authentication-without-extra-infrastructure" class="header-anchor"&gt;&lt;/a&gt;Authd: cloud authentication without extra infrastructure
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Authd&lt;/strong&gt;, the authentication service with cloud providers, is now in the official Ubuntu repositories. You can authenticate Ubuntu devices with &lt;strong&gt;Microsoft Entra ID&lt;/strong&gt;, &lt;strong&gt;Google IAM&lt;/strong&gt;, or any standard OIDC provider, with no additional infrastructure needed on the network.&lt;/p&gt;
&lt;p&gt;For organizations managing fleets of Ubuntu machines that already have centralized identity in Azure or Google, this greatly simplifies onboarding and deployments.&lt;/p&gt;
&lt;h3 id="improved-wsl"&gt;&lt;a href="#improved-wsl" class="header-anchor"&gt;&lt;/a&gt;Improved WSL
&lt;/h3&gt;&lt;p&gt;If for work reasons you are forced to use Windows, Ubuntu&amp;rsquo;s integration in the Windows Subsystem for Linux improves in this release: better handling of usernames with non-ASCII characters, cloud-init integration, Ubuntu Pro for WSL, and management of multiple machines through Canonical&amp;rsquo;s Landscape.&lt;/p&gt;
&lt;h2 id="toolchain-flavors-and-requirements"&gt;&lt;a href="#toolchain-flavors-and-requirements" class="header-anchor"&gt;&lt;/a&gt;Toolchain, flavors, and requirements
&lt;/h2&gt;&lt;h3 id="developer-toolchain"&gt;&lt;a href="#developer-toolchain" class="header-anchor"&gt;&lt;/a&gt;Developer toolchain
&lt;/h3&gt;&lt;p&gt;Ubuntu 26.04 ships a very up-to-date development stack: GCC 15.2, Python 3.14 by default, LLVM 21, Rust 1.93, Golang 1.25, OpenJDK 25 with versions 8, 11, 17, and 21 also available with Java TCK certification.&lt;/p&gt;
&lt;p&gt;And an important debut: &lt;strong&gt;Zig 0.14.1 is finally in the official Ubuntu repositories&lt;/strong&gt;. For those who have been following the Zig language as an alternative to C for low-level systems, it is now one &lt;code&gt;apt install&lt;/code&gt; away.&lt;/p&gt;
&lt;p&gt;Also .NET 10 in the official archive, PHP 8.5 with property hooks and the pipe operator, PostgreSQL 18 with a new I/O subsystem promising up to triple the improvement in disk reads, and MySQL 8.4 LTS, the first official LTS release of MySQL.&lt;/p&gt;
&lt;h3 id="official-flavors"&gt;&lt;a href="#official-flavors" class="header-anchor"&gt;&lt;/a&gt;Official flavors
&lt;/h3&gt;&lt;p&gt;If GNOME is not your thing, the flavors are still there. &lt;strong&gt;Kubuntu&lt;/strong&gt; ships with KDE Plasma 6.6. &lt;strong&gt;Xubuntu&lt;/strong&gt; with Xfce 4.20. &lt;strong&gt;Lubuntu&lt;/strong&gt; with LXQt 2.3. There are also Ubuntu Budgie, Cinnamon, Kylin, and Unity, although the latter is not catalogued as LTS and will be released in 2 days.&lt;/p&gt;
&lt;p&gt;One absence worth noting: &lt;strong&gt;Ubuntu MATE has no 26.04 release&lt;/strong&gt;. The most direct and similar alternative is Xubuntu.&lt;/p&gt;
&lt;h3 id="system-requirements"&gt;&lt;a href="#system-requirements" class="header-anchor"&gt;&lt;/a&gt;System requirements
&lt;/h3&gt;&lt;p&gt;Canonical raised the recommended requirements to &lt;strong&gt;6 GB of RAM&lt;/strong&gt; and a dual-core 2 GHz CPU. This is not a hard requirement —you can install with 4 GB— but they are being honest about what 2026 workloads demand in practice. The desktop ISO weighs more than 6 GB, so you need a good connection or patience.&lt;/p&gt;
&lt;h2 id="when-should-you-upgrade"&gt;&lt;a href="#when-should-you-upgrade" class="header-anchor"&gt;&lt;/a&gt;When should you upgrade?
&lt;/h2&gt;&lt;p&gt;The answer depends on your situation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you are on Ubuntu 25.10&lt;/strong&gt;: in the coming days you should see the upgrade notification. You can do it without major risk.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you are on Ubuntu 24.04 LTS&lt;/strong&gt;: the direct upgrade &lt;strong&gt;is not enabled until July 2026&lt;/strong&gt;, when Ubuntu 26.04.1, the first point release, comes out. Canonical always follows the same procedure: they wait until post-release bugs are fixed before opening the mass upgrade to LTS users. It is the standard policy and makes a lot of sense.&lt;/p&gt;
&lt;p&gt;You can upgrade manually before July if you want, but you take on the risk of bugs that will probably be fixed within weeks.&lt;/p&gt;
&lt;p&gt;My recommendation: if it is a production server or a critical work machine, &lt;strong&gt;wait for 26.04.1 in July&lt;/strong&gt;. If it is your personal computer and you want to explore, go ahead, just have a recent backup and free time in case something breaks.&lt;/p&gt;
&lt;h2 id="closing"&gt;&lt;a href="#closing" class="header-anchor"&gt;&lt;/a&gt;Closing
&lt;/h2&gt;&lt;p&gt;Ubuntu 26.04 is not a package update. It is a statement of intent.&lt;/p&gt;
&lt;p&gt;Wayland as the sole backend in GNOME. Rust in the kernel, in sudo, in the coreutils. CUDA and ROCm in the repos with no external repositories. Kernel 7.0 with 2026 hardware supported from day one. APT with transaction history. Production-ready confidential computing.&lt;/p&gt;
&lt;p&gt;And for those of us in the cybersecurity world, seeing the foundation of a mainstream operating system move toward languages with memory-safety guarantees, with hardware-tied disk encryption, with post-quantum cryptography in the default stack, is exactly the direction and standard things should head toward.&lt;/p&gt;
&lt;p&gt;This is not a consolidation LTS. It is a transition LTS. And those are the most interesting ones.&lt;/p&gt;
&lt;p&gt;Ubuntu 26.04 LTS &amp;ldquo;Resolute Raccoon&amp;rdquo; is not a simple package update. It is a change of era. In this analysis I focus on what is under the hood: Rust in the kernel and coreutils, production-ready TPM encryption, post-quantum cryptography, CUDA and ROCm in the official repositories, NTSYNC for gaming, APT with transaction rollback, and much more.&lt;/p&gt;
&lt;h2 id="sources-and-resources"&gt;&lt;a href="#sources-and-resources" class="header-anchor"&gt;&lt;/a&gt;Sources and resources
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Ubuntu 26.04 LTS release notes: &lt;a class="link" href="https://documentation.ubuntu.com/release-notes/26.04/" target="_blank" rel="noopener"
 &gt;https://documentation.ubuntu.com/release-notes/26.04/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Official Canonical announcement: &lt;a class="link" href="https://canonical.com/blog/canonical-releases-ubuntu-26-04-lts-resolute-raccoon" target="_blank" rel="noopener"
 &gt;https://canonical.com/blog/canonical-releases-ubuntu-26-04-lts-resolute-raccoon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Release announcement on the community forum: &lt;a class="link" href="https://discourse.ubuntu.com/t/ubuntu-26-04-resolute-raccoon-lts-released/80833" target="_blank" rel="noopener"
 &gt;https://discourse.ubuntu.com/t/ubuntu-26-04-resolute-raccoon-lts-released/80833&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Installation images (ISO): &lt;a class="link" href="https://releases.ubuntu.com/resolute/" target="_blank" rel="noopener"
 &gt;https://releases.ubuntu.com/resolute/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>4 Myths About Trisquel 12 | Installation and Configuration</title><link>https://orozco.observer/en/videos/4-mitos-sobre-trisquel-12-instalacion-y-configuracion/</link><pubDate>Sat, 18 Apr 2026 12:00:00 +0000</pubDate><guid>https://orozco.observer/en/videos/4-mitos-sobre-trisquel-12-instalacion-y-configuracion/</guid><description>&lt;img src="https://orozco.observer/videos/4-mitos-sobre-trisquel-12-instalacion-y-configuracion/Portada.png" alt="Featured image of post 4 Myths About Trisquel 12 | Installation and Configuration" /&gt;&lt;div class="video-wrapper" style="position:relative;padding-bottom:56.25%;height:0;overflow:hidden;max-width:100%;"&gt;
&lt;iframe src="https://www.youtube-nocookie.com/embed/40Z5-a4Fj4k" style="position:absolute;top:0;left:0;width:100%;height:100%;" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen loading="lazy" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;

&lt;p&gt;Also available on Odysee: &lt;a class="link" href="https://odysee.com/@javierorozco.observer:6/Trisquel12:c" target="_blank" rel="noopener"
 &gt;https://odysee.com/@javierorozco.observer:6/Trisquel12:c&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;It&amp;rsquo;s only for fanatics.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;It doesn&amp;rsquo;t work on real hardware.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;It&amp;rsquo;s a dead distro.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;I have heard that about Trisquel for years. And Trisquel 12.0, codenamed &amp;ldquo;Ecne&amp;rdquo;, deserves better press than it gets: none of those claims survive contact with reality. But I am not going to ignore the real limitations that do exist either, because that would be doing exactly what I criticize.&lt;/p&gt;
&lt;p&gt;I am not here to sell an ideology. I come from systems administration and cybersecurity, and from that perspective Trisquel has a solid technical argument that is rarely explained well.&lt;/p&gt;
&lt;h2 id="what-trisquel-is-a-100-free-ubuntu"&gt;&lt;a href="#what-trisquel-is-a-100-free-ubuntu" class="header-anchor"&gt;&lt;/a&gt;What Trisquel Is: a 100% Free Ubuntu
&lt;/h2&gt;&lt;p&gt;Trisquel is a GNU/Linux distribution based on Ubuntu (which is itself based on Debian), but what makes it stand out is that it is certified by the Free Software Foundation as a 100% free distro.&lt;/p&gt;
&lt;p&gt;It uses linux-libre: an alternative version of the kernel from which all proprietary firmware blobs have been manually removed. Not only does it not include the blobs, it patches the kernel so it does not even try to load them if it found them on the system. That is closed binary code that manufacturers ship inside the regular Linux kernel and that runs on your hardware without you being able to read it, audit it, or know exactly what it does — just like proprietary drivers on other operating systems.&lt;/p&gt;
&lt;p&gt;Free software in general grew out of an anecdote related to this. Richard Stallman worked as a programmer at the MIT Artificial Intelligence Laboratory in the 1970s and 80s, when it was common for researchers to share source code freely: if someone improved a program, they made it available to the community.&lt;/p&gt;
&lt;p&gt;The lab received as a donation from Xerox a high-speed laser printer with a serious problem: it jammed frequently. With the previous printer, Stallman had solved that kind of problem by modifying the software, because they had access to the driver source code. With the new Xerox it was impossible: the software was only a binary and Xerox did not hand over the source code. And the most revealing twist: someone did have that source code, but refused Stallman a copy because he had signed a non-disclosure agreement (NDA) with Xerox.&lt;/p&gt;
&lt;p&gt;That moment showed him the dangers of proprietary software: it turns you into a prisoner of your software, it stops you from fixing real problems, it breaks cooperation between users, and it gives the manufacturer disproportionate power over the user. In September 1983 he announced the GNU Project, in 1985 he founded the Free Software Foundation, and he defined the Four Freedoms of Free Software: to run the program for any purpose, to study and modify it, to distribute copies, and to distribute modified versions. And a point he always clarifies: &amp;ldquo;free&amp;rdquo; refers to freedom, not price. As the famous saying goes: think free speech, not free beer.&lt;/p&gt;
&lt;p&gt;That is not paranoia, fanaticism, or extremism. In systems administration and security, software you cannot audit is a risk by definition, not an optional convenience. And the FSF does not certify distributions lightly: it is one of the strictest filters out there.&lt;/p&gt;
&lt;h2 id="myth-1-its-only-for-fanatics"&gt;&lt;a href="#myth-1-its-only-for-fanatics" class="header-anchor"&gt;&lt;/a&gt;Myth 1: &amp;ldquo;It&amp;rsquo;s Only for Fanatics&amp;rdquo;
&lt;/h2&gt;&lt;p&gt;This argument assumes that using fully free software is an emotional decision, a rejection of companies, and it is a comfortable way of not having to evaluate the real argument.&lt;/p&gt;
&lt;p&gt;The technical argument is this: when your kernel includes binary firmware, you are running code with extremely high privileges, at the hardware level, that you cannot inspect. In a security context that is an attack surface. Not theoretical: real. There have been documented vulnerabilities in the firmware of network cards, storage controllers, and audio chips.&lt;/p&gt;
&lt;p&gt;Does that mean everyone should use linux-libre? Not necessarily. There are contexts where that trade-off does not pay off. But saying that whoever chooses it does so out of fanaticism is ignoring the argument. And in security, ignoring arguments is exactly what you should not do.&lt;/p&gt;
&lt;p&gt;Myth busted. Moving on.&lt;/p&gt;
&lt;h2 id="installation-the-ubiquity-installer-and-apt-30"&gt;&lt;a href="#installation-the-ubiquity-installer-and-apt-30" class="header-anchor"&gt;&lt;/a&gt;Installation: the Ubiquity Installer and APT 3.0
&lt;/h2&gt;&lt;p&gt;The ISO is downloaded from trisquel.info, in its main edition with the MATE desktop. There are also editions with KDE Plasma, LXDE, and an educational version based on Sugar, but here I focus on the main one.&lt;/p&gt;
&lt;p&gt;The installer is Ubiquity, the same one Ubuntu uses. If you ever installed Ubuntu, everything will feel familiar: language, time zone, partitioning, user. No surprises. My recommendation, valid for any operating system, is to always enable the full-disk encryption option.&lt;/p&gt;
&lt;p&gt;One detail worth mentioning: in Trisquel 12 the installer already uses the deb822 repository format natively. That is APT 3.0. It is not a visible change for the end user, but it is modern infrastructure and engineering work the Trisquel team did from scratch, inherited not from Ubuntu 24.04 but directly from Debian 13.&lt;/p&gt;
&lt;p&gt;During installation it will not ask you for any proprietary firmware. There is no &amp;ldquo;install additional drivers&amp;rdquo; option like in Ubuntu. That is intentional: if your hardware needs blobs to work, Trisquel will not install them. And that takes us straight to the next myth.&lt;/p&gt;
&lt;h2 id="myth-2-without-blobs-there-is-no-wi-fi-or-gpu"&gt;&lt;a href="#myth-2-without-blobs-there-is-no-wi-fi-or-gpu" class="header-anchor"&gt;&lt;/a&gt;Myth 2: &amp;ldquo;Without Blobs There Is No Wi-Fi or GPU&amp;rdquo;
&lt;/h2&gt;&lt;p&gt;This myth has a true part and an exaggerated part, and it is worth separating them.&lt;/p&gt;
&lt;p&gt;The true part: there is hardware that requires binary firmware and linux-libre does not include it. The most common cases are Broadcom Wi-Fi cards, some Realtek models, and certain NVIDIA GPUs. If you have one of those, it will not work on Trisquel. Period.&lt;/p&gt;
&lt;p&gt;But the exaggerated part, where the argument collapses, is assuming that applies to all modern hardware. It does not: Intel and AMD graphics, Intel wired network cards, and recent integrated Realtek audio work without proprietary firmware.&lt;/p&gt;
&lt;p&gt;For physical machines, my practical recommendation is to check your hardware beforehand on h-node.org, the catalog of free-software-compatible hardware maintained by the FSF. It is not a complicated step and it saves you surprises.&lt;/p&gt;
&lt;p&gt;Is it a real limitation? Yes. Does it rule out Trisquel for any hardware? No. Those are different things.&lt;/p&gt;
&lt;h2 id="the-mate-desktop-and-preinstalled-software"&gt;&lt;a href="#the-mate-desktop-and-preinstalled-software" class="header-anchor"&gt;&lt;/a&gt;The MATE Desktop and Preinstalled Software
&lt;/h2&gt;&lt;p&gt;MATE has been Trisquel&amp;rsquo;s default desktop environment for years: simple, stable, and accessible. It does not need 3D acceleration, which makes it viable on old hardware and in virtualized environments.&lt;/p&gt;
&lt;p&gt;It comes with the basics preinstalled: Abrowser, which is Firefox reconfigured without Mozilla telemetry or services, LibreOffice, a media player, a file manager, and the standard system tools.&lt;/p&gt;
&lt;p&gt;The system ships with a bit of everything: disk usage analyzer, calculator, dictionary, archiver, file search, character map, on-screen keyboard, PDF editor, text editor, blue-light filter, magnifier, screen reader, terminal, screenshots, and font and PDF viewers. For multimedia and graphics there is a disc burner, webcam viewer, media players, sound mixer, scanner software, photo editor, color picker, and photo organizer. For the internet: email client, decentralized, private, and encrypted chat software with calls and video calls, news reader, browser, multiprotocol messaging, BitTorrent client, and remote desktop client. And for the system: full office suite, backups, file explorer, system monitor, ISO image mounter, log viewer, updater, software installer, bootable USB creator, .deb package manager, printer wizard, and management of users, networks, disks, power, and repositories. Most settings are centralized in the Control Center.&lt;/p&gt;
&lt;h2 id="myth-3-its-no-good-for-real-work"&gt;&lt;a href="#myth-3-its-no-good-for-real-work" class="header-anchor"&gt;&lt;/a&gt;Myth 3: &amp;ldquo;It&amp;rsquo;s No Good for Real Work&amp;rdquo;
&lt;/h2&gt;&lt;p&gt;The Trisquel repositories hold thousands of available packages. We are not talking about ten tools in a plain-text directory, but a package base derived from Ubuntu 24.04 and cleaned of non-free dependencies. WireGuard, KeePassXC, networking tools, editors, version control: nothing critical is missing for a systems administration and programming workflow.&lt;/p&gt;
&lt;p&gt;Trisquel 12 also has an active backports repository: LibreOffice in its latest version, yt-dlp, Inkscape, Nextcloud Desktop, Kdenlive. Updated software without waiting for the Ubuntu LTS cycle.&lt;/p&gt;
&lt;p&gt;And on browsers: in this release the team added GNU IceCat and ungoogled-chromium as additional options alongside Abrowser. Three fully free browsers available from the official repositories.&lt;/p&gt;
&lt;p&gt;The &amp;ldquo;it has no useful software&amp;rdquo; argument confuses &amp;ldquo;free&amp;rdquo; with &amp;ldquo;scarce&amp;rdquo;. They are not the same thing: free means you can read the code, modify it, and redistribute it, not that there is less software.&lt;/p&gt;
&lt;h2 id="post-installation-updates-backports-and-browser"&gt;&lt;a href="#post-installation-updates-backports-and-browser" class="header-anchor"&gt;&lt;/a&gt;Post-Installation: Updates, Backports, and Browser
&lt;/h2&gt;&lt;h3 id="updating-the-system"&gt;&lt;a href="#updating-the-system" class="header-anchor"&gt;&lt;/a&gt;Updating the System
&lt;/h3&gt;&lt;p&gt;The first thing after a clean install is to install the pending updates. APT 3.0 feels noticeably faster at resolving dependencies than previous versions:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt update &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo apt upgrade
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Something the Trisquel team worked on specifically in this version 12: they reviewed and expanded the AppArmor rules for graphical environments. More applications running with active confinement profiles by default. It is silent work, nothing visible, but exactly the kind of security work that matters.&lt;/p&gt;
&lt;h3 id="enabling-backports-libreoffice-24--26"&gt;&lt;a href="#enabling-backports-libreoffice-24--26" class="header-anchor"&gt;&lt;/a&gt;Enabling Backports: LibreOffice 24 → 26
&lt;/h3&gt;&lt;p&gt;Without enabling backports, LibreOffice ships in version 24, the same one Ubuntu 24.04 carried by default. Enabling the repository is easy from the graphical interface: Menu, System, Administration, Software &amp;amp; Updates; in the &amp;ldquo;Other Software&amp;rdquo; tab you enable the Backports repository, authenticate with your password, click &amp;ldquo;Close&amp;rdquo; and then &amp;ldquo;Reload&amp;rdquo;. You can also do it faster from the terminal, but through the interface the process stays visible. Then go back to Menu, System, Administration, Software Updater, click &amp;ldquo;Check for Updates&amp;rdquo; and the backport packages appear: just click &amp;ldquo;Install Now&amp;rdquo;. When you reopen LibreOffice you can verify it is now on version 26.&lt;/p&gt;
&lt;h3 id="resource-usage"&gt;&lt;a href="#resource-usage" class="header-anchor"&gt;&lt;/a&gt;Resource Usage
&lt;/h3&gt;&lt;p&gt;With &lt;code&gt;htop&lt;/code&gt; you can see the distro&amp;rsquo;s real resource usage: used RAM sits between 800 and 900 MB:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;htop
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;I also installed &lt;code&gt;fastfetch&lt;/code&gt;, which is in the now-enabled backports, to show the system information:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install fastfetch
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Keep in mind that fastfetch usually shows an extra RAM figure above 200 MB, because it includes its own memory overhead.&lt;/p&gt;
&lt;h3 id="abrowser-the-default-browser"&gt;&lt;a href="#abrowser-the-default-browser" class="header-anchor"&gt;&lt;/a&gt;Abrowser, the Default Browser
&lt;/h3&gt;&lt;p&gt;Abrowser even lets you sign in with a Firefox account to sync across devices. But it has one quirk: when you try to install extensions, the browser sends you to the Mozarella page on Ñugzilla, which only contains 100% free extensions… with the problem that they are outdated, as I verified with the two I use in every browser: uBlock Origin for blocking intrusive ads and Bitwarden as my self-hosted password manager.&lt;/p&gt;
&lt;p&gt;It is not a serious problem: just go manually to the Firefox extensions page, search for the ones you need, and install them.&lt;/p&gt;
&lt;p&gt;The browser also ships with strict anti-tracking mode. I recommend leaving it that way and, if some site has problems, selectively enabling the option to fix major site issues.&lt;/p&gt;
&lt;h3 id="mate-customization"&gt;&lt;a href="#mate-customization" class="header-anchor"&gt;&lt;/a&gt;MATE Customization
&lt;/h3&gt;&lt;p&gt;This is already personal taste: I removed the three taskbar icons for the menu, the file manager, and the browser. Then, with right-click and &amp;ldquo;Add to Panel&amp;rdquo;, I added the advanced MATE menu, which supports search; I moved it to the edge and locked it to the panel so I would not move it by mistake. Then I added back Caja, the file manager, and the browser, although you can add as many as you want.&lt;/p&gt;
&lt;p&gt;To test the centralized configuration I switched to the dark theme from the Control Center. When you do this, I recommend logging out and back in: that way the change applies to all applications, including the menu.&lt;/p&gt;
&lt;h2 id="gnu-guix-more-100-free-software"&gt;&lt;a href="#gnu-guix-more-100-free-software" class="header-anchor"&gt;&lt;/a&gt;GNU Guix: More 100% Free Software
&lt;/h2&gt;&lt;p&gt;And to finish breaking myth 3, there are two ways to get more fully free software compatible with the distro&amp;rsquo;s philosophy and the FSF&amp;rsquo;s.&lt;/p&gt;
&lt;p&gt;The first is GNU Guix. On the official Trisquel website, searching for &amp;ldquo;Guix&amp;rdquo; takes you to the &amp;ldquo;All Manuals&amp;rdquo; page and from there to the &amp;ldquo;GNU Guix Package Manager&amp;rdquo; manual, with a short description of what it is. If you know the Nix package manager or the NixOS distribution, this is the same thing, but in a 100% free version: it is both a package manager and a NixOS-style distribution.&lt;/p&gt;
&lt;p&gt;One of its advantages is that you can even install different versions of the same package, with all dependencies included and bundled, and generally everything stays at its latest version.&lt;/p&gt;
&lt;p&gt;Installing it means following some fairly simple steps, although parts of the process take around half an hour. That is completely normal, but it only happens the first time. When finished I recommend logging out and back in so the added environment variables take effect, for example so installed applications show up in the menu.&lt;/p&gt;
&lt;h3 id="installing-and-searching-packages-with-guix"&gt;&lt;a href="#installing-and-searching-packages-with-guix" class="header-anchor"&gt;&lt;/a&gt;Installing and Searching Packages with Guix
&lt;/h3&gt;&lt;p&gt;Guix can be used at the user level, without administrator privileges, which is the most recommended way. As a demonstration I installed the LibreWolf browser, also Firefox-based but with a strong focus on privacy:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;guix install librewolf
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;From the console you can also search for packages. I searched for GIMP, the photo editor, and with the keyboard arrows I moved through the results: at recording time GIMP 3.2.0 was available, the latest version, but also 2.10.38. There you can see what I said before: there are several versions of the same software in case you need them:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;guix search gimp
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;If you prefer searching from the browser you can also do it on the Guix packages page, where the command appears ready to paste into the terminal and install.&lt;/p&gt;
&lt;p&gt;I staged this demonstration on purpose: GIMP already comes preinstalled from the official Trisquel packages in an older version, but I installed 3.2.0 via Guix. To avoid conflicts just log out and back in: the menu ends up with the Guix-installed edition. It is a huge, practical, and very simple repository to use, with the guarantee that the software is 100% free because it is an official GNU and FSF project.&lt;/p&gt;
&lt;h2 id="flatpak-limited-to-free-licenses"&gt;&lt;a href="#flatpak-limited-to-free-licenses" class="header-anchor"&gt;&lt;/a&gt;Flatpak Limited to Free Licenses
&lt;/h2&gt;&lt;p&gt;The other way to install additional software is Flatpak by adding the Flathub repository. But that repository normally contains hundreds of proprietary closed-source programs, so there is a way to force it to only show software with free and verified licenses.&lt;/p&gt;
&lt;p&gt;The simplest path is to install the Flatpak plugin for the GNOME software store: with a single command you install the store, the plugin, and Flatpak together. Afterwards I recommend logging out and back in, for the same reason as with Guix:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install gnome-software gnome-software-plugin-flatpak flatpak
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Then, from the terminal you add Flathub in user mode, without root privileges and limited to free licenses. From there you just open the GNOME software store: you already have access to all those applications without breaking, relatively speaking, the distro&amp;rsquo;s philosophy.&lt;/p&gt;
&lt;p&gt;Why do I say &amp;ldquo;relatively&amp;rdquo;? Because inside a lot of open-source software there is an easy path to installing non-free software: closed plugins, proprietary and unethical third-party services, and so on. The FSF is not in favor of using software like that. Even so, the final choice belongs to the user, who could even add the full Flathub with all the proprietary software… but that would defeat the purpose of using a 100% free distribution only to then install closed programs on it. It would not be coherent.&lt;/p&gt;
&lt;h2 id="myth-4-the-project-is-dead"&gt;&lt;a href="#myth-4-the-project-is-dead" class="header-anchor"&gt;&lt;/a&gt;Myth 4: &amp;ldquo;The Project Is Dead&amp;rdquo;
&lt;/h2&gt;&lt;p&gt;This myth comes from the release pace. Time passed between Trisquel 10 and 11, and between 11 and 12 as well, and people read that as abandonment. It is not abandonment: it is the cost of doing something difficult with limited resources.&lt;/p&gt;
&lt;p&gt;Trisquel 12 ships with APT 3.0, with extensive kernel work to make its modifications more modular, with expanded AppArmor, with three free browsers available, and with active backports. And the team has already announced it is starting preliminary work to support the RISC-V architecture, which is the next frontier of free hardware.&lt;/p&gt;
&lt;p&gt;An abandoned project does not do that. A project with limited resources but clear direction does.&lt;/p&gt;
&lt;p&gt;Trisquel is non-profit and sustained by donations and memberships. If after trying the project you find it valuable, that is the concrete way to support it.&lt;/p&gt;
&lt;h2 id="who-it-is-for-and-who-it-is-not-for-conclusions"&gt;&lt;a href="#who-it-is-for-and-who-it-is-not-for-conclusions" class="header-anchor"&gt;&lt;/a&gt;Who It Is For (and Who It Is Not For): Conclusions
&lt;/h2&gt;&lt;p&gt;Trisquel is for those who value having a fully auditable system, for those who work in environments where non-free software is a real rather than theoretical risk, for those who want an Ubuntu-based system but without the compromises Ubuntu makes with proprietary firmware and Canonical packages, and for those who want a stable platform with support until 2029 and active backports.&lt;/p&gt;
&lt;p&gt;Who is it not ideal for yet? Those who depend on Wi-Fi or GPU hardware that requires binary firmware, although that universe shrinks every year as more manufacturers free their drivers. And those who need proprietary software with no free equivalent. That exists; I am not going to deny it.&lt;/p&gt;
&lt;p&gt;But those real limitations are very different from the myths I started with. And the difference matters, because the myths keep people who would benefit from Trisquel from ever considering it.&lt;/p&gt;
&lt;p&gt;If you use Linux and never gave Trisquel a chance because you heard it is useless or for fanatics, I hope this changes that. At least so you evaluate it with real information.&lt;/p&gt;
&lt;h2 id="sources-and-resources"&gt;&lt;a href="#sources-and-resources" class="header-anchor"&gt;&lt;/a&gt;Sources and Resources
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Official Trisquel site: &lt;a class="link" href="https://trisquel.info/" target="_blank" rel="noopener"
 &gt;https://trisquel.info/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Trisquel downloads (12.0 LTS &amp;ldquo;Ecne&amp;rdquo; edition): &lt;a class="link" href="https://trisquel.info/en/download" target="_blank" rel="noopener"
 &gt;https://trisquel.info/en/download&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;h-node, free-software-compatible hardware catalog: &lt;a class="link" href="https://h-node.org/" target="_blank" rel="noopener"
 &gt;https://h-node.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;GNU Guix, transactional package manager: &lt;a class="link" href="https://guix.gnu.org/" target="_blank" rel="noopener"
 &gt;https://guix.gnu.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Guix package search: &lt;a class="link" href="https://packages.guix.gnu.org/" target="_blank" rel="noopener"
 &gt;https://packages.guix.gnu.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FSF-recommended free GNU/Linux distributions: &lt;a class="link" href="https://www.gnu.org/distros/distros.en.html" target="_blank" rel="noopener"
 &gt;https://www.gnu.org/distros/distros.en.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;GNU/Linux-compatible hardware (FSF): &lt;a class="link" href="https://www.fsf.org/resources/hw" target="_blank" rel="noopener"
 &gt;https://www.fsf.org/resources/hw&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>