Oboi here we go 🙄
Ubuntu has managed to do away with GNU Core Utilities in its default stack. The last three holdouts, cp, mv and rm, have moved to uutils’ coreutils; the Rust reimplementation Canonical has been feeding into the distro since 2025.
They had been held back from 26.04 LTS over flaws in the uutils versions. Everything else, from ls and cat to chmod and du, made that jump in earlier releases.
This change, while big, sits hidden away in an obscure mention in Canonical’s work-in-progress release notes for Ubuntu 26.10.
It’s been a long road
Canonical started oxidising Ubuntu last year, and Ubuntu 25.10 became the first release to ship coreutils as the default. That release also made sudo-rs the default privilege tool, replacing a command that had been in place for decades.
26.04 was the release where the plan did slow down quite a bit, as Canonical kept cp, mv, and rm on their GNU versions due to a bunch of TOCTOU issues that were blocking the full implementation.
These were caught during an audit, when Canonical commissioned Zellic for two rounds between December 2025 and March 2026, focusing on the most security-sensitive utilities first.
Across both rounds, Zellic raised 113 issues, and 44 of them were assigned CVEs. Canonical says the vast majority have been resolved.
Getting here has had its ups and downs, and the last stretch was not clean. In July, uutils cp went back into the archive and came straight out again after it broke live image builds.
The fix was quick; as the developers marked it “Critical,” the fix went upstream, and the migration landed in time for 26.10. What changes for you?
When typing commands, nothing changes for you on the surface. uutils coreutils is designed to be a drop-in replacement for essential GNU tools, and the project treats any divergence from GNU as a bug, further pointing out that some options may still be missing or behave differently.
So if you prefer staying on the GNU version, you have the option to install the coreutils-from-gnu package that houses all the required components.
The next stage
Coreutils is one piece of a broader campaign. Earlier this year, Canonical became a Gold Sponsor of the Trifecta Tech Foundation, pitching in €40,000 a year to fund memory-safe system software.
Under this, their current target is ntpd-rs, a Rust rewrite of the tools Ubuntu uses to keep its clock in sync. While work is still ongoing, it has already arrived for testing.
Its transition to being default is targeted for Ubuntu 27.04.
What Canonical is gradually building up towards is the completion of their oxidation vision for Ubuntu, and it’s not about blindly including new components. Rather, it looks like a measured approach that’s being worked out a few steps at a time.



MIT: The recipient of this source code can do with it as they please. That may include building it, distributing it, modifying it, building and distributing those modifications, commercializing it, whatever.
GPL: The recipient of this software, including builds of it, is entitled to the source code that was used to build it. Anyone with the source code can modify it, share those modifications, make builds with it, etc, but you cannot restrict the rights of the recipients of your builds more than the terms you yourself received the source code under. So you can make changes and distribute builds of those changes, but users you distribute builds to are also entitled to your code including the changes you made.
AGPL: Same as GPL, except the recipients of this software also include users of the software, such as over a network. This was because with SaaS suddenly people were using software they hadn’t “received”, because it was running on someone else’s computer and they only provided inputs and received outputs, so the licence was created to bring this back in line with the spirit of the GPL.
LGPL: You can use this library in your non-GPL code, and it doesn’t “infect” your entire codebase by extending the entitlement of the source code outside the library to all users of your builds. It does still entitle users to the source code of the library itself though, especially if you’ve made changes to the code of that library.
People often talk about the GPL preventing commercial uses, but that’s actually not true. You’re allowed to sell GPL software. It’s just a somewhat risky venture, because all users you sell software to also get all the source code. That means anyone can buy your software, request the source, and then immediately start competing with you by offering it themselves for free or cheaper or whatever. So it’s allowed, but rarely works for very long unless you have a lot of good will in the community.
Two additions:
Damn dude, this is really articulate. Thanks.