So far, Canonical has followed a split kernel SRU cycle for Ubuntu, where regular fixes and security patches lived on separate tracks, with a full update every four weeks and a security-focused release at the two-week midpoint for urgent CVE fixes.
If that concept is new to you, a Stable Release Update, or SRU, is how Canonical ships bug fixes and security patches to Ubuntu after a release is out. The kernel gets its own dedicated track for this.
Canonical is replacing both tracks with a single 2-week cycle, and since each new cycle kicks off a week into the current one, this results in a kernel release landing every week.
The new 2-week cycle
Source: Canonical
Each cycle starts with a week of patch integration and prep work. The kernel team selects which fixes land on each kernel, builds the packages, and runs basic smoke tests to catch anything obviously wrong before the build moves on.
Those builds get pushed into Ubuntu's -proposedpocket once the first week wraps up. That is where kernel release candidates live before they have been certified, accessible to those who know where to look but not yet out to general users.
Week two is where Canonical runs the builds through its Ubuntu Certified hardware testing program, putting them through different machine types to make sure nothing breaks in the real world before the kernel ships.
A fresh cycle starts every week regardless of where the current one stands, so there is always a kernel finishing its test run and rolling out. That is how a 2-week cycle ends up delivering a release every week.
And, when something is not safe to ship, Canonical says that they will be clear about that and direct users toward general system hardening advice.
For teams that cannot wait the full two weeks, Canonical is explicitly pointing to -proposed as a fast path. The idea is that you run your own acceptance tests on the build sitting there rather than waiting for certification to wrap up.
Clankers made this inevitable
This change did not come from nowhere; they had to take such a sweeping decision due to clankers. Only last month, we saw how they were bleeding compute resources from git.kernel.org just by scraping it for training data.
For Canonical, their decision was driven by LLMs and AI agents turning vulnerability hunting into something automated and relentless, finding kernel bugs at a scale and speed no individual human researcher could replicate.
The goal is to have a workaround published within 24 to 48 hours of a CVE going public. Not the patch, but something that gets affected systems into a safer state while one is being built.
What the Ubuntu maker is doing here is responding to a rapidly-evolving situation by shortening the window between a CVE going public and a patch landing.
First thing first. Yesterday, I mistakenly sent the Local AI Weekly newsletter to everyone. That was not supposed to happen. I'll be more careful in the future.
Let's go with our regular dose of Linux and open source.
Snapdragon X2 processor support should be coming to Linux soon. Qualcomm has put out an early developer preview with Debian 13 as the reference environment.
PeppermintOS is switching from Xorg to XLibre for its upcoming Debian and Devuan ISO refreshes, with no plans to move to Wayland for the foreseeable future.
Mozilla and Mistral announced a partnership that adds Mistral Small 4 to Firefox Smart Window, swapping out the OpenAI model that was there before. Both of them believe that an independent browser and a European AI lab act as counterweights in the Big Tech-dominated browser ecosystem.
Valve has quietly open-sourced Lepton, the Android compatibility layer it built for Steam Frame. The tool runs Android games inside a container using Waydroid and LineageOS.
Garuda Linux has graduated its NixOS side project into a proper standalone distro. Garuda Nix now ships bootable ISOs for the Dr460nized and Mokka flavors.
After a decade of the open source Community Edition, Portainer is now changing things. CE stays frozen on 2.x with security patches and some backports, while Portainer 3.0, a Kubernetes-first rebuild, goes closed source.
GrapheneOS is publicly calling out Google for holding Android 17 QPR1 security patches back from non-Pixel OEMs until December.
After years of requiring a phone number even after adding username support, Signal is finally testing numberless registrations.
Then there are the two Ubuntu-related news items this week:
Separately, the Ubuntu Wiki got its first comprehensive overhaul since 2010, now running on MediaWiki with niceties like dark mode, mobile support, and a WYSIWYG editor.
This edition of FOSS Weekly is supported by ANY.RUN that is organizing a webinar.
Free Webinar | Turn Threat Intelligence into SOC Action
Your SOC has threat intelligence. But is it helping analysts make faster decisions? Join ANY.RUN and Elastic Security to see how to make threat intelligence part of faster SOC decision-making — without adding more manual work.
- Prioritize alerts with relevant threat context - Reduce manual enrichment and IOC lookups - Bring fresh IOCs into Elastic Security workflows
Andy Nguyen, lead of the PS5 Linux project, is stepping away after a hypervisor exploit he'd been sitting on got reported to Sony's bug bounty program by someone else before he was ready.
🧮 Linux Tips, Tutorials, and Learnings
Most KDE users open Konsole, type commands, and never bother tweaking it. We have some useful tips for you that will change how you use it.
Linux has had NTFS support for years, and it's never been great. NTFS-3G works but is slow and CPU-hungry. The ntfs3 driver is in the kernel but barely maintained. NTFSPlus is the attempt to finally do it properly.
Something broke on your Linux system, and you don't know where to start? Turns out systemd has been keeping detailed records the whole time. You just need to learn how to make good use of the tools that can help you read them.
👷 AI, Homelab and Hardware Corner
I got my hands on Elecrow's new HMI display, a 10.1-inch ESP32-P4 touchscreen built for homelab and maker projects, not for people who want something that works out of the box.
The recently released openKylin 3.0 comes with built-in skills that allow you to control and change system settings via AI agents.
✨ Apps and Projects Highlights
I did a fun project last weekend. I made a Wordle-like puzzle game with Linux terms. It's called Tuxdle.
Every day, you get a new word, and you have to guess the Linux term within 6 attempts. The term could be a distro, a command or popular terms like grub. Rules are explained here. Give it a try and let me know of your feedback, please.
Most of the time, you really don't need to install a fully-fledged theme to customize KDE Plasma. You can make do by installing a color scheme of your liking.
First, you need to download the .colors file for the theme of your liking. Then, inside the settings menu, go to Colors & Themes -> Colors. Here, click on "Install from file..." and select the theme file you want to install.
Ensure that the dropdown menu near the accent color palettes says "Accent color from color scheme," then click on the newly added theme, then on "Apply" to get it done.
Desktop Linux is mostly neglected by the industry but loved by the community. For the past 14 years, It's FOSS has been helping people use Linux on their personal computers. And we are now facing the existential threat from AI models stealing our content.
If you like what we do and would love to support our work, please become It's FOSS Plus member. It costs $49 a year (less than the cost of a McDonald's burger a month), and you get an ad-free reading experience with the satisfaction of helping the desktop Linux community. And there are also free Linux ebooks.
How well-versed are you with the jargon of today's AI age? We are getting back to posting puzzles regularly, so give this new one a try!
Linux Mint is one of the OG Linux projects that deserves more funding, you know. 🫠
🗓️ Tech Trivia: The first successful FORTRAN program ran at IBM on September 20, 1954, pioneering a way for programmers to express computations using algebra-like notation rather than machine code.
The programming language was formally released in 1957 and remains in use today, particularly in science and engineering.
🧑🤝🧑 From the Community: Daniel was facing an issue with YouTube playing back videos with a delay. He found an open source tool that did the job without much fuss.
Qualcomm has put out an early developer preview of Linux for Snapdragon X2 Series laptops, asking kernel developers, distro maintainers, and hardware enablement engineers to get on this hardware and start testing.
They have been laying the groundwork for this since Snapdragon Summit 2025, and the push today is toward getting drivers into mainline rather than shipping out-of-tree patches that only a handful of people can maintain.
The current preview pairs a Debian 13 "Trixie" userspace with a custom kernel, and the initial focus is on readying up the core pieces developers need before they can do any serious work on the hardware.
System boots are handled via systemd-boot acting as the UEFI manager, while Core I/O covers USB, PCIe, and the Qualcomm Universal Peripheral serial engine for UART, I2C, and SPI connections.
Whereas Mesa's open source Qualcomm drivers handle graphics duties, with Freedreno covering OpenGL, Turnip taking care of Vulkan 1.3, and Rusticl handling OpenCL compute.
Work on all three is ongoing, but display output, browser acceleration, and GPU compute workloads are already possible.
The FastRPC driver, Qualcomm's mechanism for routing compute tasks from the CPU to the DSP, is being pushed upstream to open up the Hexagon NPU for local AI inference workloads. Power management and thermal support are part of this series of developments too.
Two build paths
The official documentation for Snapdragon X2 Linux software outlines two paths that developers can follow.
The first is the unregistered path, where you build the Debian OS layer using prebuilt firmware binaries, getting started without a Qualcomm developer account. The second requires an account, giving you full firmware source access to build everything from scratch.
Prebuilt flashable images are also available if you want to skip the build entirely and go straight to flashing.
Host requirements also differ by what you are building. The Debian layer needs an ARM64 machine running Ubuntu 24.04 LTS or later, or Debian Trixie. The firmware build requires an x86_64 host on Ubuntu 22.04 LTS or later.
If you want to see a hands-on demo of Linux unning on Snapdragon X2 hardware, then this year's Snapdragon Summit (ends today) in Maui, Hawaii, is the place to be!
More of this, please
A staged roadmap, a documentation portal, dedicated build scripts in a public repo, and turning to developers for feedback is something other silicon vendors looking to upstream their work should take note of.
In the end, Linux wins. Every driver that lands in mainline is one fewer patch that distributions have to carry, and that is what eventually makes these machines usable beyond early adopters.
openKylin is China's homegrown, open source operating system which is developed by a consortium of companies, research institutes, and individual contributors.
We have covered openKylin in the past but that was more than two years ago. There is a new major release in the form of openKylin 3.0 that brings Linux kernel 7.0, UKUI (desktop environment) 4.24 and deeply integrated AI at the core.
Let's see the highlight of the new release.
AI is at the center of openKylin 3.0
Among the most highlighted changes in the new release is the built-in, all-new KylinBot AI agent framework, along with Xiao K, the AI assistant built on top of it.
Xiao K is basically the graphical interface similar to Hermes Desktop and most other AI tools of this sort. The underlying KylineBot AI agent framework integrates it with the system.
And then it comes with several pre-built system skills like:
Input Devices: Full coverage for keyboard, mouse, and touchpad.
Display Control: Screen brightness and OSD display adjustments.
Network Management: Deep integration with the NetworkManager command-line tool to manage Wi-Fi, Ethernet, and VPNs with a single command.
Peripheral Management: Bluetooth toggle, device discovery, and automatic audio device pairing.
System Controls: Power management, taskbar operations, shortcut navigation, and system app controls
Custom skills to interact with your desktop
This way, you can ask the agent in Xiao K to switch off the bluetooth or switch to a different network, change the input keyboard layout and more. You don't need to go through the command line or click through the system settings. The agent does the job for you.
Seems like overkill, right? But it makes more sense if you use the voice input. People these days use Siri hands-off for calling to specific contacts. So, if you could just talk to your computer and ask it to connect to your bluetooth headphone, why not?
Remember that Ubuntu 26.10 is also working on AI integration. Omarch 4.0 got a sudden surge in popularity for AI (and its looks). So, even if you dislike AI, there is a demand for it. And sooner or later, most desktop operating systems will have built-in AI assistants like this. openKylin is just a few steps ahead of its peers.
There are more skills that can be found on openKylin's repo here. It is in Chinese language and I do hope they start offering these features in English as well to cater a larger global audience.
Like Hermes, OpenClaw and other AI tools, Xiao K doesn't stay to your desktop only. You can communicate with it from messaging tools like WeChat, Feishu, DingTalk etc. Telegram and Discord support is planned.
UKUI version 4.24
The UKUI (Ultimate Kylin User Interface) desktop environment is upgraded to version 4.24. The new version brings the following updates:
Standardized API encapsulation across UKUI modules and integration with KACP (Kylin Agent Control Protocol), enabling KylinBot to invoke underlying desktop capabilities via unified APIs.
The new version also brings accessibility support in the form of a screen reader. It also has air gesture controls, which means you can control some desktop functionality with the movement of the hands instead of touching the screen or using a mouse or keyboard.
This works on Android devices thanks to the proximity sensor in the smartphone. Here, Kylin uses the webcam to capture the hand gestures.
The feature to enable dynamic wallpaper is also added for enhanced eye candy. In other visual changes, "Three-Island" taskbar layout mode is added as an option.
Touchpad gets enhanced multi-finger gesture interactions, supporting multitask view, volume control, and other actions using 3-finger and 4-finger gestures.
Rustification
Since both AI and Rust are in trend these days, openKylin 3 has new Rust-based utilities that replace the older, classic utilities.
kylin-time replaces the legacy time utility, kylin-wget replaces the classic wget and kylin-ki18n replaces the ki18n.
Getting openKylin
If you want to give it a try, you can download openKylin from the official website. The ISO is a little over 7 GB. The size is primarily because the OS comes with pre-installed AI models.
I plan to test openKylin 3.0 on my spare system. It is okay in VM, but since there is a lot of AI integration and I would like to use them to see how effectively they work on a baremetal system. I will share my findings in a review video. Stay tuned for that.
Contrary to what you might expect of a newly launched Linux distribution, Gravity Linux has a long-term goal of not existing as a distro. The project is a Fedora Remix for Apple Silicon Macs that ships with KDE Plasma on Wayland as the default desktop.
Everything in it is built through clean-room reverse engineering, ensuring that no Apple source code, disassembly, or leaked technical information makes its way into the code for this project.
Two developers, Cody Ho and Niklas Sheth, are the main driving forces behind this, forking it from Asahi Linux with a shared goal of bringing Linux to Apple Silicon.
They went down this path due to a difference in contribution policy around LLM use.
Gravity Linux's position is clear from its commit history, where the project's kernel branch carries commits with Assisted-By tags openly crediting AI coding tools alongside the human author.
What its first release delivers
An overview of what's working and what's not.
The first alpha runs on the M4 Mac mini, and both the display controller (DCP) and GPU are working, with OpenGL ES 3.0 and OpenGL 3.3 compliance incorporated, meaning hardware-accelerated graphics is available from the first boot.
Keep in mind that this is a developer-focused alpha release with a few shortcomings that make it unfit for daily use. Suspend does not work, Thunderbolt and USB4 support is nonexistent, and USB-C display output is not supported, though output via HDMI works.
Shutdowns and reboots are described as inconsistent, with the power button recommended as the workaround for getting a predictable experience. Speaker volume is also capped for hardware safety.
Users should also understand that a full reinstall will be needed when the beta arrives sometime later, as the Gravity Linux team does not guarantee an upgrade path from the alpha release.
You can get it for your machine by running this:
curl -fsSL https://install.gravitylinux.org | sh
Distro with an expiry date?
Even though the M4 Mac mini is the first target, it's not the only one. Current plans cover the MacBook Neo and the remaining M4, M4 Pro, and M4 Max lineup, with some new contributors already making progress on several of those devices.
M5 is a different story. On M5 Pro and M5 Max hardware, macOS 27.0 Beta 5 leaves the devices misconfigured at boot, preventing secondary CPU cores from starting. Apple supposedly knows of this issue, but there's no news on when a fix will be delivered.
Gravity Linux also plans to keep the entire M5 lineup on the same firmware version before shipping support, so M5 stays on hold until Apple addresses that issue.
The final goal is to upstream all of its driver work to the Linux kernel and relevant userspace projects while documenting its reverse engineering methods publicly at every step.
The GitHub organization already reflects that direction. Beyond distro-layer scripts, the project maintains forks of the Linux kernel, Mesa, and U-Boot. These are the same upstream projects where this work ultimately needs to land.
Once that upstream work lands, any mainstream Linux distribution would run on supported Apple Silicon hardware without needing a separate remix like this. At that point, Gravity Linux the distro stops being necessary, and that is when the team plans to sunset it.
I mistakenly sent the Local AI Weekly to the subscribers of FOSS Weekly. My bad. A long, tiring day led to this mishap. Won't happen again (hopefully).
Welcome to issue #3. I said weekly last time and here we are, one week later. Small victories.
This issue has a theme, and it's money. I guess I am not the only one who thinks that the generous Claude and Codex subscriptions people are enjoying right now are just to get you addicted to using AI.
And it's quite evident, isn't it? A big credit giveaway comes first. Then the models quietly get dumber. Then your credits start burning faster than they used to. Then the price goes up or the offer just ends.
If you've rebuilt your workflow, or worse, your company, on top of this "generosity", you may find yourself in a tough spot when the token price starts going up. The $20/$200,$2000 a month pricing you're planning today, won't give you the same thing in long run.
Which is exactly why the local AI is going to go big. Not every task needs a frontier model. A lot of them need a small model, running on hardware you already own, wrapped in a harness tuned to your work.
Before we get into it, thanks to Monid for supporting this edition.
Think of Monid as OpenRouter, but for agent tools. One base URL, one key, and an agent can reach 2,000+ tools across 72+ providers. The connector layer went open source under MIT, and because connectors are declarative, adding your own API is a pull request a coding agent can write for you.
I promised you an Unsloth verdict last issue and I owe you that. But I got distracted by Buzz, an open source communication tool built for agents and humans to work together. I actually liked Buzz. There is smartphone app too and thus staying connected in not an issue. It could replace Discord for team It's FOSS.
📥 Agents are getting an inbox
Two biggies independently landed on the same idea at alsmot the same time, and it's a good one. Chat is a bad interface for an agent that works while you're asleep.
Cloudflare open sourced agentic-inbox, a self-hosted email client with an AI agent built in, running entirely on Workers (so it is cloud, not your GPU). Incoming mail arrives through Email Routing, each mailbox lives in its own Durable Object with a SQLite database, and attachments go to R2. The agent reads your inbox, searches conversations, and drafts replies that you approve before they send.
AWS did something similar with Pizza Bot. It's an Apache 2.0, local-first inbox for long-running agents, built on DeepAgents and LangGraph. Finished work shows up as unread threads and anything needing your approval gets flagged.
Unlike agentic-inbox, this one runs on your machine with no telemetry, storing threads, checkpoints, memories and logs as SQLite files in a local folder. You pick the model provider, and Ollama is on that list. So you can run the whole thing locally, even offline.
🔍 Discover AI tools
Two finds this week, and they sit at opposite ends of the "what is AI for" question.
First, OpenPencil, an MIT-licensed, AI-native design editor that opens and writes native Figma .fig files. You can copy nodes between it and Figma. It ships a headless CLI, an MCP server so coding agents can read and edit your designs, and a roughly 7 MB Tauri desktop app that needs no account. Built on Vue 3, Skia for rendering and Yoga for layout. Local model support is on the roadmap.
The second AI tool is kind of anti-AI tool. Sounds weird, I know but hear me out. AI-based auto transcribers are part of almost all meeting tools. Not everyone wants to be heard by AI, specially that sends data to server for further training, probably.
Kalypta runs a small model locally on your device and reshapes your audio in real time so that AI transcribers can't make sense of what you said. The goal is to be inaudible to the note-taking bot in your meeting while staying perfectly clear to the humans. Interesting project to watch out for.
📡 Open Model News
The big one is Qwen-Image-2.1. It's a small text-to-image model and some people are already calling it the Nano Banana alternative. Not available on Ollama yet probably because weights ship under the Qwen Research License, which is non-commercial and requires you to email Qwen for a commercial licence. Another reminder that open weights and open source are not the same thing.
The other release worth your time is small in a different way. You've probably seen Jev everywhere for the past week, TypeSafe AI's "System One" model that doesn't generate text at all. The open source alternative to Jev is laya-mlx, an Apache 2.0 native MLX port of Laya, the typed decision model from Convai Innovations. Available only for Apple Silicon model for now.
👀 Big Tech Watch
Microsoft rewrote the GitHub Copilot agent runtime from TypeScript into more than 800,000 lines of production Rust, and one engineer drove most of it with a fleet of AI agents. It took 128 pull requests over about fourteen and a half weeks, shipped incrementally.
The whole migration cost around $120,000 in tokens. That's 136.3 billion tokens, of which 130.6 billion were cached input reads.
Think about what that means for the rest of us. That project only worked because 96% of the tokens were cache hits billed at roughly a tenth of the normal rate. Remove the caching and the whole thing will be far from a profitable migration. This is the token economics I was talking about earlier.
🗂 AI Jargon: Prompt caching
Since caching reduced the migration bill for Microsoft, let's learn more on it.
Here's the thing. Every time you send a request to a model, it has to read your entire prompt and build an internal representation of it before generating a single token. In a long agent session, that prompt is mostly the same every turn: the system prompt, the tool definitions, then the conversation so far, with a bit of new text on the end.
Prompt caching means the provider saves the intermediate computation for a prefix it has already processed. Send the same prefix again and it reuses that work instead of redoing it. Providers typically bill a cache hit at around a 90% discount, so a million input tokens might cost $2.00 fresh and $0.20 cached.
This is why agent harnesses are built to save on tokens. They keep a long, stable prefix and only ever append to it, because anything that changes the beginning of your prompt invalidates the cache and multiplies your bill by ten.
How does it impact local inference? Well, on your own hardware there's no per-token bill, so the equivalent optimisation is KV cache reuse. So you win on latency instead of money.
⚡ Quick Tip: Check whether Ollama is actually using your GPU
Last issue I told you how to keep models warm. Here's a similar check.
Run ollama ps while a model is loaded. Alongside the model name and size you'll see a PROCESSOR column telling you whether it's on GPU, CPU, or split between the two with a percentage.
If a model doesn't fit in VRAM, Ollama will quietly offload some layers to system RAM and keep working rather than failing. It runs; you get answers, but it will sluggish.
If you see anything other than 100% GPU and you expected it to fit, drop to a smaller quantisation or shorten your context window. A Q4 model fully on the GPU will usually beat a Q8 model that's splitting between CPU and GPU.
In the end...
I am not doomsaying, but I would like you to plan for the future beyond the cheap phase of frontier AI. Build your harness and use local models in your workflow wherever it makes sense. I understand that hardware is not cheap these days but there are smaller models that can fit niche scenarios.
I welcome your feedback and I'll see you next week (because it's a weekly newsletter)..
AI is moving fast. Its jargon is moving even faster. Half of it doesn't mean what you'd guess from the name. After all, tokens are not coins. Terms like harness and quantization are everywhere in local AI conversation, and often people don't even know what these terms mean.
I put together this quiz to test how well you actually know the words you're using. It is a little quiz with just ten questions, one correct (and hopefully funny) description per term.
Guess the term, then check your reasoning against the explanation, in case your answer was a pure guess.
You don't need to be an AI researcher to do well here. If you've spent any time running models locally, on Ollama, llama.cpp, or anything similar, you've probably bumped into most of these already.
🚧
Some browsers block the JavaScript-based quiz units. Disable your ad blocker to enjoy the quizzes and puzzles.
How many did you get right? Drop your score in the comments.
Interested in local AI? Subscribe to our brand new newsletter, Local AI Weekly. The name is self-explanatory, I believe.