You are not logged in.
have been a real issue lately from not having udev
But udev is available in Devuan.
$ ps -ef|grep udev
root 475 1 0 12:44 ? 00:00:01 /sbin/udevd --daemon
$ apt list udev
udev/stable 1:3.2.9+devuan4 amd64
udev/stable 1:3.2.9+devuan4 i386But I didn't use Ventoy, the "Ventoy" error message must come from the Devuan ISO itself that apparently uses Ventoy components internally.
I use a Zalman ZM-VE300 external USB SSD drive which allows you to select an ISO file an then emulates an optical drive with it.
I have been using this for more than a decade for many dozens of Linux installs with many different ISOs of many distros (and even occasional Windows installs for friends who don't want Linux) and never had a problem booting of it before.
Even the Devuan netinstall ISO has actually worked with the Zalman USB drive before, I only got this "Ventoy" error message with one PC so far. But on that PC the Exe GNU/Linux ISO booted and installed fine from the Zalman, so it's not an incompatibility between the Zalman and that PC.
I actually had the same issue a few days ago when I tried to install Devuan 6 on a AMD Ryzen 5 desktop PC. I "solved" it by installing the latest Exe GNU/Linux (which is minimalist Devuan 6 spin with a TDE desktop).
I actually kept the TDE desktop on that PC as I quite like it after customizing the looks a bit to suit my taste, but if you go down the same route and prefer a different DE then you can just install it with apt or synaptic as usual.
I got those errors both with the devuan_excalibur_6.1.1_amd64_desktop.iso and the devuan_excalibur_6.1.1_amd64_netinstall.iso so the netinstall image will probably not work either for you.
Great, thanks, that's exactly what I was looking for.
As more and more Debian packages remove support for SysV service scripts in the future
Isn't this problem already covered by the "orphan-sysvinit-scripts" package?
The recent posts (Active Topics) search ( https://dev1galaxy.org/search.php?action=show_recent ) only shows posts from the last 24 hours which I consider too little as I'm not always visiting once every 24 hours.
On other forums this usually shows active topics from the last 7 days and often it is user configurable to show even longer periods (30 days or even more).
Would it be possible to at least increase "Active Topics" to 7 days?
The other search "new posts since your last visit" isn't a valid alternative for me as sometimes I want to revisit a thread that I was reading a few days ago and that didn't get any posts since, so it wouldn't show in this search, but it would show in "Active Topics" if "Active Topics" was covering at least 7 days.
Increasing "Active Topics" to 7 days would probably increase user activity (including helpful replies to support questions) on this forum as people who don't visit daily would see more recent threads than as is currently the case.
I didn't watch the video as I already didn't like the title, but thanks for warning us that it's just AI slop.
Well wikipedia writes the following about the startpage aquisition:
In October 2019, Privacy One Group, owned by adtech company System1, acquired a majority stake in Startpage. An initial lack of transparency surrounding the deal caused some concern among privacy researchers, leading to its removal from the PrivacyTools review website.
After responding to questions from PrivacyTools team members, Startpage was able to clarify that the acquisition would not impact their privacy-focused mission, and its recommendation was ultimately restored.
According to the company, its "founders may unilaterally reject any potential technical change that could negatively affect user privacy".
By maintaining its headquarters and operations in the Netherlands, Startpage continues to be protected by Dutch and European Union (EU) privacy laws.
https://en.wikipedia.org/wiki/Startpage
so it still seems a good choice, definitely better than google search and duckduckgo (which I already wouldn't use because it's a US company and therefore subject to the Patriot act).
Yes, I know the Unix philosophy "Do one thing and do it well" very well, what I meant to say is that some distros outside the corporate distro world still follow this principle, it's the corporate distros who have long abandoned it, so it's not about "modern" but rather about corporate Linux distros and distros following their lead.
@Calamity do you have a source for that?
They always had ads, but their aren't personalized as they don't track their users.
Haven't watched the video but I already don't like the title.
There is no such thing as "modern Linux", there are corporate backed distros (primarily anything from IBM/Redhat, but also Canonical and Suse and also Debian which unfortunately these days is dominated by employees of the previously mentioned corporations) and their derivatives, and there are true community distros out of which quite a few are going their own way and not following the corporate distros.
Presumably by "modern Linux" they really mean the "corporate backed distros", but calling them "modern Linux" is giving them an aura of superiority that they don't deserve, they should simply be called "corporate backed distros".
Just use https://startpage.com which is based on google search but provides you with a layer of anonymity, and I have never experienced captchas with startpage.com.
Yes, I know MKVToolNix but I don't think it could fix the random subtitle timings, I only did 4 DVDs before I noticed this so I will just redo them with the self-built Handbrake binary.
TBH I never had problems with Handbrake on other non-Debian based Distros before, I suspect the problems are specific to the Debian package which builds Handbrake differently compared to how the Handbrake devs recommend.
Building your own Handbrake binaries is not difficult it's explained in detail here:
https://handbrake.fr/docs/en/latest/dev … linux.html
I usually watch online videos using mpv with yt-dlp, basically all you need to do is run mpv with the URL of the video (for example copy+pasted from the browser):
mpv https://www.youtube.com/watch?v=xxxxxxxxxThis is far lighter on the cpu than anything browser-based, even when the browser uses hardware assisted decoding.
This works for many online videos, not just youtube.
you might want to put your yt-dlp preferences in the mpv config file, for example I have the follwing in ~/.config/mpv/mpv.conf
script-opts=ytdl_hook-ytdl_path=/path/to/yt-dlp/yt-dlp.sh
ytdl-format=bestvideo[width<=1920][height<=1080][vcodec~=?'^(vp9|h264|avc1)']+bestaudio/best
cache=yes
cache-on-disk=no
cache-pause-wait=5
cache-pause-initial=yes
demuxer-thread=yes
demuxer-cache-dir=/tmp
demuxer-max-bytes=800MiB
demuxer-readahead-secs=15
cookies=yes
keep-open=yesJust a heads-up for all Handbrake users here:
In the last few days I used Handbrake (installed from the Devuan/Debian repos) to convert some DVDs to h264 mkv files (as a backup on hard disk) and noticed that the VOBsub subtitle timings were all corrupted (subtitles appearing sometimes way too early, sometimes way too late, all within the same file).
So I built the latest official Handbrake release from source and with this build it does not happen, the subtitle timings are perfect exactly like on the original DVD.
Luckily I caught this in time before doing too many conversions.
I find the title of this thread misleading bordering on clickbait as it could imply that the offcial Devuan server(s) has been comprmised, it should be changed to something like "personal server running an ancient Devuan release compromised".
Could it be that the fix has been backported?
The Changelog says:
packagekit (1.3.1-1+deb13u1) trixie-security; urgency=high
* Non-maintainer upload by the Security Team.
* Do not allow re-invoking methods on non-new transactions-- Salvatore Bonaccorso <carnil@debian.org> Tue, 21 Apr 2026 16:45:57 +0200
It doesn't mention the CVE number (which IMHO it should have to make it clear that it fixes this CVE) but this security update has been released around the same time of your article so my guess is that it relates to this CVE.
https://metadata.ftp-master.debian.org/ … _changelog
sudo is one of the first packages that I uninstall on laptops/desktops after a fresh installation.
It is not even meant for the purpose it's being used by most Linux distros, sudo is meant to give limited access to specific commands as root or other restricted user to specific users on a multi-user system, not as a "run everything you want as root" tool on a single user desktop/laptop system.
We have to thank Ubuntu for introducing this misuse of sudo on Linux.
I recognise that there are limitation to banks webapp security - all the bank apps I'm aware of seem to still rely on text OTP messages for second factor security after user ID + Pin or password. I'm unclear whether they are therefore any more secure than their mobile apps,
Using an offline card reader where you have to insert your bank card and then type your PIN to get an OTP code on the LCD-display of the card reader that you then enter in the browser based banking login is the safest of all second factor methods, far safer than anything smartphone based.
Nationwide actually has good browser based online banking and as a second factor they give you the choice of an offline card reader as described.
I wouldn't bank with any bank that doesn't offer this.
While my daily driver is running Devuan with sysV-init I would like to explore Artix Linux on a secondary PC.
But Artix Linux has ISOs for 4 different init systems but not sysV-init: dinit /runit / openrc / s6
I'm not familiar with any of them, I only have experience with sysV-init and Upstart (and systemd, not by choice).
Which one of the 4 init systems Artix offers is most similar to sysV-init?
By similar I mean that it uses ideally the same init scripts as sysV-init in the familiar rc.d folder.
I liked Upstart because of this, it was perfectly backward compatible with the sysV init scripts.
Or in other words which one would you recommend to someone who is used to sysV-init and would like to feel at home as quickly as possible?
I noticed slimlock does not get used when the xfce-screensaver locks the screen, only when I click on "lock screen" manually.
Is there a way to get xfce-screensaver to use slimlock for the lock screen?
Thanks for the how to, it works fine!
I'm using Devuan with a Nvidia GTX 1050 card and the proprietary Nvidia drivers (the 550 version from the Devuan/Debian repos) without any problems, the system is absolutely stable and everything works fine (OpenGL, Vdpau, NVDEC and Vulkan).
The only thing I couldn't get working is VAAPI hw video decoding in Firefox, if I enable that Firefox crashes the moment I start a video in the browser (for example on youtube), but with VAAPI hw video decoding disabled videos in Firefox obviously play fine so it's not a big issue.
That said the GT 730 that you are trying to use is apparently no longer supported by the 535 and 550 propietary drivers in Devuan 6 (Excalibur), the most recent Nvidia drivers that still support the GT 730 are the 470 series.
There is a guide on github on how to install the 470 series drivers (and the older 340 and 390 series) on Debian 13 (the Devuan 6 equivalent) so if you are adventurous you should be able to get it working:
https://gist.github.com/Anakiev2/8d62e2 … ff855a22a7
Not sure where all the hostility is coming from?
I wouldn't call it hostility, but if you write a reply that clearly shows that you didn't read the previous posts in the thread and therefore write incorrect or redundant stuff then don't expect to be also thanked for that.
This isn't the Debian official forum or mailing lists though, so maybe take it up with them using one of those channels? Mailing list is preferred - perhaps search the list first.
I'm a Devuan user and this affects Devuan too so I'm writing it here, I have no interest in joining the Debian forum or ML. Also as I suspected there must be Debian Devs keeping an eye on this forum too, as it's too much of a coincidence that they started working on the yt-dlp package for trixie last night a few hours after I started this thread here.
FYI: latest version, as of date of writing this, was released yesterday.
Yep, the latest upstream version, I'm using that right now since I'm no longer using the outdated and insecure packaged Debian version.
If you don't use those options (--write-link, --write-url-link, or --write-desktop-link), this particular issue won't affect you.
But those that would rather bitch and complain about how hard done by they are by the very busy Debian maintainer not doing it, that is too much of a burden on them.
This is not about me, as I already wrote I have now moved on to the upstream binaries anyway, it's about all other Debian 13 / Devuan 6 users who use the Debian yt-dlp package and might not even be aware of this CVE.
But if we have to manually install binaries from upstream to avoid security issues then what's the point of a distro?
My main concern now is how many other long known CVEs are there in other Debian packages that have not been fixed yet?
Do I really have to start checking all the packages that I use for known CVEs that Debian hasn't fixed yet?
Does this not make you concerned?
Currently, the backports version is the same as the version in unstable, so the solution seems to be to install the bacports version and follow that.
As I said I was already using the version from excalibur backports but that's 2026.03.17, which is not the latest version and it's not the same as unstable which has the latest version (2026.07.04-1), so your statement is simply incorrect.
it may be better to direct your concerns to the upstream project
What nonsense comment, my concern is that debian has a known vulnerable version since more than a month in stable with no security update available, upstream has nothing to do with that.
Debian "freezes" packages at a specific version and any security patches are backported as necessary. So any newer version will never be available in stable.
I don't care whether Debian backports the security patch or the latest version as long as the CVE is fixed, but so far they haven't done either of the two options.