Canonical Moves Ubuntu 26.10 Core Utilities Entirely to Rust

Canonical is moving Ubuntu 26.10’s remaining core utilities to Rust and expanding TPM-backed encryption to more machines. Its security changes also narrow the boot configurations supported with…

Oct 6, 2026
•
4 min read
Technobezz
Canonical Moves Ubuntu 26.10 Core Utilities Entirely to Rust

Don't Miss the Good Stuff

Get tech news that matters delivered to your inbox.

Canonical is moving Ubuntu 26.10’s default core utilities entirely to Rust, extending TPM-backed full disk encryption to more machines and trimming the software involved in Secure Boot. The shift includes Rust replacements for cp, mv and rm, commands used to copy, move and delete files. Users with customized /boot configurations face compatibility changes, including the loss of support for LVM and LUKS encryption there when Secure Boot is enabled.

The signed version of GRUB drops filesystem drivers including Btrfs and ZFS, as well as support for loading PNG and JPEG images. Software RAID configurations for /boot also lose Secure Boot support except for RAID1, while ext4 remains supported. These restrictions apply during boot; the running operating system retains support for the affected storage technologies, and disabling Secure Boot preserves GRUB’s full capabilities.

For users who depend on the removed boot features, Ubuntu 26.04 LTS offers an alternative with support through May 2041 when combined with Ubuntu Pro and the Legacy add-on. That release had already adopted uutils coreutils, but kept GNU versions of the three commands now being replaced. Canonical recommends checking scripts for differences in command behavior, especially privileged operations that copy, move or delete files.

TPM-backed full disk encryption now supports computers that lack a hardware root of trust, though installation requires a PIN or passphrase because Ubuntu cannot automatically verify their firmware. Administrators may subsequently remove the PIN, but Canonical says doing so removes protection against firmware tampering. Computers with a hardware root of trust retain automatic unlocking, a group Canonical says includes most PCs manufactured since 2021.

Ubuntu 26.10 also adopts OpenSSL 4.0 and OpenSSH 10.5, with both retaining hybrid post-quantum key exchange as a default. OpenSSL adds Encrypted Client Hello support, which can protect the requested server name when compatible applications and servers enable it. The feature leaves destination IP addresses visible and does not become active across every application simply through installation.

Certificate checking through curl gains upki integration, using cached CRLite data to identify revoked certificates without a separate request to a certificate authority on each connection. OpenSSL also removes its ENGINE interface, requiring users of affected hardware security modules, tokens or TPM-backed keys to migrate to suitable providers. On the desktop, the new dictation feature Myna processes speech locally inside a sandboxed inference snap, avoiding the need to send audio to a cloud transcription service.