Someone traced $2B in grants and 45 states of lobbying records behind US age-verification bills. The trail leads to Meta — $70M in super PACs, a front group with no IRS filing, and bill language hand-delivered by a Meta lobbyist. The bills target operating systems, not social media. Is this anti-competitive regulation, fear of TikTok, or OS-level surveillance infrastructure? https://www.reddit.com/r/linux/comments/1rshc1f/i_traced_2_billion_in_nonprofit_grants_and_45/ #Linux #Privacy #Meta #Surveillance
Scott McCarty
At Red Hat, Scott McCarty is Senior Principal Product Manager for RHEL Server, arguably the largest open source software business in the world. Focus areas include cloud, containers, workload expansion, and automation. Working closely with customers, partners, engineering teams, sales, marketing, other product teams, and even in the community, he combines personal experience with customer and partner feedback to enhance and tailor strategic capabilities in Red Hat Enterprise Linux.
Fedora Linux 44 is out.
- Konflux is now the build pipeline for all bootc images and CoreOS
- MariaDB 11.8 has native vector support (VECTOR data type, no plugin)
- GCC 16, LLVM 22, glibc 2.43 across the board
Come check it out.
https://fedoramagazine.org/announcing-fedora-linux-44/
We're about to witness an unintentional experiment: can non-AI-assisted VIM forks keep pace with upstream VIM that uses AI tooling and more contributors?
It's a large, mature project — we'll get real data on feature velocity, security response, and code quality. My money's on upstream VIM, but either outcome teaches us something.
What if your AI agent could SSH into your RHEL image and diagnose issues before you push to production?
Red Hat just published a guide for integrating MCP servers into image mode builds. Two intelligence streams: live OS state (journalctl, systemctl) + proactive CVE scanning. No more manual log scraping.
RHEL image mode has a value proposition nobody's talking about, and it's not security or compliance. It's confidence. When your OS is defined in a Containerfile and built in CI/CD, you get the same transactional safety net as git. I've been running Claude Code with --dangerously-skip-permissions for months because of it. As AI agents go mainstream, this matters more than people realize. https://crunchtools.com/image-mode-gave-me-the-confidence-to-go-fully-agentic/ #RHEL #bootc #AIAgents #Linux #ImageMode
No Linux distribution offers a structured incubation path for new open source projects. Fedora's proposed Sandbox could change that. I wrote about why it matters by looking back at Podman's early days, when our whole team was a few engineers, an intern, and constant pressure to justify our existence every planning cycle. The Sandbox framework could make Fedora the place where the next Podman grows up. https://crunchtools.com/fedora-sandbox-podman-early-days/ #Fedora #Podman #OpenSource #Containers #FOSS
Qwen 2.5 (122B), running locally via llama.cpp on consumer GPUs, just added a visual polygon editor to OpenSCAD — a mature C++ codebase — using Open Code, an open-source agentic coding tool. ~70 minutes, a couple of bug fix rounds, working binary at the end. No cloud, no API key, no subscription. If you dismissed local LLMs as demo-tier, this is the video that updates that model. https://www.youtube.com/watch?v=oAjQJsnEFqo #OpenSourceAI #LocalLLM #OpenSCAD #LLM
"Your Container Is Not a Sandbox" — an entire article on container security that never mentions SELinux. Not once. That's not an oversight, it's an agenda.
I'm not anti-microVM. But containers *do* contain. I run OpenClaw --read-only with SELinux enforcing. Add seccomp, dropped caps, user namespaces — defense in depth works.
Open source is evolving, AI-assisted development means UX designers, security engineers, and domain experts can contribute at the spec level without writing implementation code.
But this only works if we extend "open" beyond code to include specifications and governance, trust demands inspectable pipelines, accessibility demands inclusive participation.
My take for InfoWorld: https://www.infoworld.com/article/4156873/how-open-source-ideals-must-expand-for-ai.html
At CentOS Connect 2026, Brian Stinson and I shared an intentionally incomplete "60% plan" for RHEL 11. Not a polished roadmap — a working draft, shared while decisions are still being made.
Fedora ELN and CentOS Stream aren't just upstream — they're the actual development engines. The community shapes the plan, not just consumes it.
Slides and recording here:
https://crunchtools.com/centos-connect-2026-rhel-11-planning-room/
I was PM for Podman and UBI during the container explosion. Watched Jevons Paradox in real time — containers made deployment cheaper, demand exploded, and we ended up spending billions on Kubernetes to manage it all.
@sogrady maps the same pattern onto AI agents. Interactive agents like Claude and Cursor are breaking apart into autonomous swarms. More Linux, more containers, more Kubernetes — with agent orchestration on top.
RHEL 10 maintenance support runs until 2035, with Extended Life Support after that. Panasonic Toughbook customers work in 5-year device replacement cycles.
Two full hardware lifecycles on the same OS. No forced platform migrations, no churn.
Techzine covered the Toughbook 56 launch in Stockholm — good write-up on why RHEL certification matters for defense and critical infrastructure.
https://www.techzine.eu/news/devices/139569/red-hat-powers-panasonic-toughbook-56-with-a-rugged-os/
#RHEL #EdgeComputing #OpenSource #Toughbook #Linux
The EFF just banned AI-generated documentation from their open source projects. Docs are literally what AI does best — consistent, complete, doesn't skip the "obvious" stuff.
The real problem is drive-by PRs from people who don't understand their code. Gemini Code Assist reviews every PR for free. That's the fix — not banning AI from its strongest area.
#OpenSource #AI #CodeReview #DevTools #Documentation
The "old guard" of software engineering is worried that AI coding tools will prevent the next generation from learning architecture. I think we're wrong. Architecture isn't about syntax, it's about understanding how systems interface. Young devs exploring ten frameworks in a year are building intuition we never had the chance to develop at that pace. https://crunchtools.com/how-will-they-ever-learn/ #AI #SoftwareArchitecture #OpenSource #GenerativeAI #SoftwareDevelopment
My Request Tracker database needed 26 schema migrations to go from 4.4.4 to 6.0.2. I used Claude Code as a pair programmer for the entire upgrade: container images on UBI 10, debugging GCC 14 build failures, a DatabaseType bug where the docs and code disagree, and a live database migration. I went to bed and it ran to completion. Wrote up everything that happened. https://crunchtools.com/rt-upgrade-ai-copilot/ #RHEL #Containers #SysAdmin #AI #OpenSource
New post: CI/CD for Image Mode RHEL — building a full RHEL 10 bootc workstation image with GitHub Actions, Podman, and RHSM activation keys. Includes 4 workarounds for the rough edges. #RHEL #bootc https://buff.ly/YKyXIb7
I've watched rootsofthevalley.org grow to 120,000+ lines. Fought to keep technical debt down — rewriting News & Events 5+ times.
Cantrill just explained the structural reason: LLMs lack the virtue of laziness. Work costs them nothing — so they never simplify. The time constraint that forces good design decisions doesn't apply to them.
The discipline to simplify has to come from you. The AI won't bring it.
https://bcantrill.dtrace.org/2026/04/12/the-peril-of-laziness-lost/
Everyone's worried AI will take their job. If you haven't found your ikigai (something you're good at, love, the world needs, and pays), you're fighting for the wrong job.
My path from punk rock to product management was messy and scared. But I stumbled into all four pieces. AI can replace tasks, not the intersection of those four things.
Talked about it on Productly Speaking: https://www.linkedin.com/posts/karl-abbott_productlyspeaking-productmanagement-careerstories-activity-7449831109078568960-j6cg
The RHEL MCP Server is in developer preview. This demo shows an AI agent connecting to five RHEL systems, running real diagnostics, and finding actual problems — a full disk from forgotten VM images, an Apache config typo, a MariaDB query called with 1 quadrillion as a parameter.
No hallucination. Real tools, real data, real root cause analysis.
https://www.youtube.com/watch?v=gICQ4aam1D0
#RHEL #MCP #AI #Linux #SysAdmin
Red Hat on the Mythos era: "Open source is the baseline for innovation, and we intend to keep this foundation strong."
AI is discovering vulnerabilities at scale. Red Hat Product Security triages them with context — ASLR, SELinux, and decades of upstream expertise. Context beats panic.
https://www.redhat.com/en/blog/navigating-mythos-haunted-world-platform-security
#OpenSource #PlatformSecurity #RHEL #AIVulnerability #CyberSecurity
The first time I saw someone telnet into a remote machine at the University of Akron, I couldn't believe what I was watching. That sent me on a 25-year journey from a laptop in my bedroom to NASA supercomputers to 1500 Linux servers. Now my terminal reaches into everything — WordPress, Jira, Zabbix, calendars, memory systems. The CLI became a terminal to the universe. https://educatedconfusion.com/command-line-terminal-to-the-universe/ #Linux #CommandLine #MCP #ClaudeCode #AI
The new workday should be 3-4 hours. For everyone. Steve Yegge makes the case in "The AI Vampire" — AI tools have made developers 10x more productive, but they automate the easy work. What's left is nothing but hard decisions, all day. Your employer captures 100% of that value. You get burnout. The maintenance people always knew intensity has a cost. Now everyone's learning it. https://steve-yegge.medium.com/the-ai-vampire-eda6e4f07163 #AI #Burnout #DevLife #TechCulture
If your AI agent fetches web pages directly, every piece of that content flows into the model's context window unsanitized, and attackers can embed instructions your agent can't distinguish from yours. I built MCP-Airlock, a three-layer defense that runs in a separate container and catches structural, adversarial, and semantic injection attacks. Open source, AGPL, security researchers welcome. https://crunchtools.com/mcp-airlock-open-source-defense-prompt-injection-ai-agents/ #AIAgents #Security #OpenSource #PromptInjection #MCP
Panasonic TOUGHBOOK is certified on RHEL. I worked with the Panasonic team on the RHEL 10 roadmap, so it's cool to see this Q&A with their TOUGHBOOK PM about the partnership.
Air-gapped, enterprise-secured, containerized edge computing on hardware tested against drops, dust, and water for 30 years. Defense, emergency response, field work.
https://www.redhat.com/en/resources/panasonic-connect-q-and-a
#EdgeComputing #RHEL #OpenSource #Toughbook #Linux
All I wanted was a weird indie sci-fi movie. Cerebral, atmospheric, ideas over explosions. Google and YouTube both failed me — nothing but spam and AI-generated slop. So I used AI to fight AI. Discovered Mars Express, a French animated neo-noir. Loved it. Went searching for a movie, found a metaphor for the entire internet in 2026. https://educatedconfusion.com/searching-for-sci-fi/ #SciFi #AI #MarsExpress #SearchIsBroken #CyberneticArmsRace
Maffulli's thesis: AI is the completion of GPL's promise. GPL freed the code, but most people still couldn't exercise that freedom. AI collapses the cost of development, enabling individual agency over the machine.
Proof: I'm building Roots of The Valley (https://rootsofthevalley.org) — an open source map. Solo project, AI-assisted, impossible before. Transparent, durable, belongs to everyone.
https://www.maffulli.net/2026/03/16/ai-final-frontier-of-copyleft/
I dare you to try something tonight. Put on the Nine Inch Nails Tron Ares soundtrack at 11 PM, start a pomodoro timer, and build something with your AI coding tool of choice. Critics gave it 53%, audience gave it 87%. I think that gap exists because you have to be building with AI to get this movie. Trent Reznor described the soundtrack as "precise and unpleasant" and if you code at midnight, you know exactly what he means. https://crunchtools.com/build-midnight/ #TronAres #NIN #AI #ClaudeCode
Every major tech shift triggers "death of X" predictions. PCs were supposed to kill mainframes. E-commerce was supposed to kill retail. Streaming was supposed to kill Hollywood. Every time, the result was expansion, not elimination.
Steven Sinofsky argues AI and software development will follow the same pattern — more software, not less. Domain expertise becomes more valuable, not less.
https://hardcoresoftware.learningbyshipping.com/p/238-death-of-software-nah
#AI #SoftwareEngineering #TechHistory #OpenSource
"Zero CVEs" = zero KNOWN vulnerabilities. It says nothing about unknown vulns, build integrity, or provenance.
Real security requires trusted pipelines (Konflux), verifiable provenance (SLSA), and minimal images (Hummingbird).
https://www.redhat.com/en/blog/zero-cves-symptom-larger-problem
#Security #SupplyChainSecurity #Containers #RedHat #Hummingbird
Super exciting. This is going to make the getting-started (day 0) experience with bootc a LOT easier. The day 2 experi nice is already amazing. https://fedoramagazine.org/introducing-the-new-bootc-kickstart-command-in-anaconda/ #linux #rhel #centos #fedora #opensource #sysadmin
Open source maintainers are burning out. Contributors show up with AI-generated PRs, get coached through reviews, then vanish. The same tickets go back to "good first issue" over and over. I submitted a PR this week where Claude wrote the code and Gemini reviewed it automatically. Henry Krupp (https://github.com/doobidoo) merged it in 3 hours. Automated code review is becoming a survival tool for maintainers, not a luxury. https://crunchtools.com/agent-wrote-code/ #OpenSource #AI #CodeReview #Maintainers #FOSS
Every computer user knows the three outcomes when something randomly breaks: it fixes itself, stays broken forever, or you lose hours going to war. My print screen key died and I discovered there's a fourth option. I turned Claude Code loose, held down the approve key, and ten minutes later it was fixed. I still don't know what it did. For the gremlins, maybe it's okay to let something else fight that battle. https://crunchtools.com/my-print-screen-key-stopped-working/ #ClaudeCode #Linux #SysAdmin
I can draft, schedule, and publish to six platforms from my terminal now. Replaced Buffer with self-hosted Postiz running in a single Podman container on RHEL 10. The MCP integration means Claude Code can post directly. Two of the six OAuth setups required patching Postiz's source code in the Containerfile. The blog covers the full build. https://crunchtools.com/self-hosting-postiz-rhel10-one-container-six-platforms/ #RHEL #Podman #MCP #OpenSource #SelfHosted


