NixOS packaging clash, OpenWrt XSS, baseline and security notes
NixOS discourse saw a heated packaging thread spill into governance and conduct disputes, while OpenWrt work on a new LuCI theme exposed a stored XSS and continued on routing and modem packages. Fedora tracked unexplained Bugzilla privacy changes and a conflict-of-interest draft, and nixpkgs recorded a critical Forgejo RCE advisory.
Omarchy packaging dispute on NixOS
A Discourse thread on packaging Omarchy drew 69 messages from 32 participants and shifted from technical packaging into accusations of racism against DHH and argument over people-first versus code-first community governance. The exchange underscores friction in how NixOS weighs external projects against contributor norms. Developers watching NixOS culture should note how packaging choices can reopen questions of community priorities.
Stored XSS via Footstrap LuCI theme
An OpenWrt forum thread introducing Footstrap, a new LuCI theme claimed to run twice as fast as Bootstrap, revealed a stored unauthenticated SVG XSS through wallpaper upload served as image/svg+xml. The finding turned a theme discussion into a security issue for LuCI deployments that accept such uploads. Operators of OpenWrt web interfaces should treat wallpaper and SVG handling as a trust boundary until fixed.
NixOS x86_64 baseline pre-RFC
A pre-RFC on Discourse proposes gradually raising the NixOS x86_64 baseline to x86-64-v3, with an intermediate step to x86-64-v2, citing Ubuntu practice, roughly one percent performance data, and breakage on older CPUs. Eight participants weighed compatibility cost against the modest gains. Packagers and users of older hardware need to track whether the intermediate v2 step becomes the near-term default.
Critical Forgejo RCE in nixpkgs
The nixpkgs repository recorded an advisory that Forgejo before 16.0.4 allows remote code execution via crafted template expansion under CVE-2026-89094, scored critical at 9.9, with only a bot posting and no discussion yet. The issue affects template handling in the forge software packaged for Nix. NixOS and Forgejo operators should watch for the 16.0.4 update and related nixpkgs commits.
Fedora security bugs turned private
Roughly 2,300 Fedora and EPEL security tracking bugs on bugzilla.redhat.com became private around 2026-09-07 and 2026-09-08 with no explanation offered in the single Fedora discussion post. The sudden visibility change removes public trail for a large set of security trackers. Contributors who rely on open Bugzilla history for Fedora security work lose a major audit surface until rationale appears.
OpenWrt pbr and wwand package work
OpenWrt forum threads covered release-candidate testing of a ucode port of the policy-based-routing (pbr) package, with user reports of domain and file handling fixes, and the announcement of wwand, a new ucode QMI mobile connection manager with eSIM support still working through modem and offload compatibility. Both efforts target practical router networking gaps. Users of multi-WAN or cellular OpenWrt setups gain concrete packages to test.
Fedora conflict-of-interest draft
The Fedora Council published a draft conflict-of-interest guidelines policy and opened feedback on scope, necessity, and GDPR implications across 40 messages from 12 participants. Discussion centers on how far the policy should reach and whether existing norms already cover the ground. Contributors and vendors interacting with Fedora governance should review the draft before it hardens.