Canonical is continuing its aggressive push toward memory-safe system architecture with the release of Ubuntu 26.10, codenamed "Stonking Stingray." In a significant milestone for the distribution’s security and low-level tooling, the upcoming release ships with a modern, Rust-based OpenPGP implementation preinstalled by default. This strategic inclusion serves as a vital bridge ahead of Canonical’s long-term plans to completely phase out the aging, C-based GnuPG utility in a future release cycle.

The implementation chosen by Canonical is Sequoia PGP, a contemporary and modular OpenPGP implementation written from the ground up in Rust. With the arrival of Ubuntu 26.10, Sequoia PGP has been included directly in the default seed, meaning it is preinstalled out-of-the-box for users. To facilitate this integration and ensure official backing, Canonical has successfully moved the rust-sequoia-sq package into the main software repository. This grants the package first-class citizen status within the distribution, backed by the official Ubuntu security and maintenance teams.

Despite its inclusion in the default installation image, Sequoia PGP will not immediately replace the traditional GNU version as the distribution’s primary OpenPGP toolchain. Instead, Ubuntu 26.10 adopts a transitional approach, shipping Sequoia PGP (sq) side-by-side with the standard GNU version. Canonical intends to make the Rust-based implementation the default in a near-future release, at which point the phasing out of GnuPG will commence.

For end users and administrators exploring Ubuntu 26.10, the transition is designed to be seamless while offering immediate avenues for testing. Currently, invoking the traditional gpg command still calls upon the legacy GnuPG toolchain. However, users can directly test the new Rust implementation by executing sq commands, such as sq sign or sq verify, directly from the command line. Additionally, any third-party applications or system services configured to utilize Sequoia’s underlying libraries will automatically harness the modern Rust backend.

Canonical has emphasized that adopting Sequoia PGP provides a dual benefit. It allows Ubuntu to maintain robust OpenPGP interoperability with the broader software ecosystem while transitioning the underlying stack to a more maintainable and memory-safe foundation. Memory safety has become a paramount concern in modern operating system design, as software written in memory-safe languages like Rust significantly reduces vulnerability classes related to buffer overflows and memory management errors.

Other Ubuntu Rust changes

The integration of Sequoia PGP is just one piece of a much larger, multi-year modernization effort unfolding across the Ubuntu ecosystem. Ubuntu 26.10 also introduces a full set of Rust-based core utilities out-of-the-box, effectively completing a complex migration that officially began with the release of Ubuntu 25.10. With this latest version, the traditional GNU-versions of essential file management commands, including cp, mv, and rm, are now provided by the uutils coreutils rewrite.

This milestone represents the culmination of extensive engineering work aimed at modernizing the foundational command-line tools that form the bedrock of Unix and Linux environments. By replacing decades-old C implementations with rigorous Rust equivalents, Canonical and the broader open-source community are significantly hardening core operating system components against entire classes of software bugs.

Looking ahead, Canonical’s engineering teams have no intention of slowing down their "oxidisation" initiative. Plans are already underway to incorporate even more foundational packages written in Rust into upcoming releases. Among the most prominent projects currently being evaluated is a Rust rewrite of the Network Time Protocol (NTP), known as ntpd-rs. Engineering teams are eyeing this modern time synchronization client for inclusion as the default time sync mechanism in the subsequent Ubuntu 27.04 release, further reducing the operating system’s reliance on legacy C codebases.

To support this broader industry shift toward memory-safe languages, Canonical’s commitment extends far beyond its own internal engineering repositories. The company actively supports the wider open-source ecosystem as a gold sponsor of the Trifecta Tech Foundation. Through this sponsorship, Canonical contributes €40,000 annually to help fund essential development work on critical Rust-based software infrastructure, reinforcing its dedication to a secure, modern, and sustainable future for Linux.

Leave a Reply

Your email address will not be published. Required fields are marked *