Ubuntu 23.10 Shows the New Desktop Installer Direction

3 minute read

Published:

Ubuntu 23.10 “Mantic Minotaur” was released on October 12, 2023 as a nine-month interim release between the Ubuntu 23.04 (April 2023) and Ubuntu 24.04 LTS (April 2024) releases. The most significant infrastructure change was the default deployment of Canonical’s new Flutter-based desktop installer, replacing the Ubiquity installer that had been the standard Ubuntu desktop installation tool since Ubuntu 5.10 “Breezy Badger” in October 2005. Ubiquity was built on Python and GTK, and while it had received updates throughout its 18-year life, its architecture made it difficult to share code between the desktop installer, the Ubuntu Server installer (Subiquity, introduced in Ubuntu 18.04), and the Ubuntu Core IoT/embedded installer. The new installer, written in Dart using the Flutter framework (the same cross-platform UI toolkit Google uses for mobile apps), shared the Subiquity backend used for server installations and presented a redesigned step-by-step interface with cleaner visuals, accessibility improvements, and a new partitioning UI. The choice of Flutter was notable: it was a cross-platform framework primarily associated with mobile and web development, not traditional Linux desktop software, reflecting Canonical’s assessment that Flutter’s widget consistency across platforms made it the most practical choice for sharing a single codebase across the desktop, server, and embedded installer variants. Other desktop changes included GNOME 45 (released September 20, 2023), which featured a new Quick Settings panel replacing the old system menu, an updated Activities overview with a workspace indicator in the top bar, and a breaking change to GNOME Shell extension APIs that required all existing extensions to be updated for GNOME 45 compatibility — a recurring pattern in GNOME releases that frustrated extension maintainers.

The 23.10 release carried Linux kernel 6.5 (released September 2023), which added support for AMD RDNA3 GPU improvements, Intel Meteor Lake (14th gen) graphics, and various hardware driver improvements relevant to systems shipped in mid-to-late 2023. The kernel 6.5 also included the MIDI 2.0 subsystem and improved USB4 support. As an interim release, Ubuntu 23.10 had a nine-month support lifecycle (ending July 2024) rather than the five-year lifecycle of LTS releases — Canonical treats interim releases as integration and testing ground for technologies targeting the next LTS. Features and packages that stabilize in 23.10 get validated against a broader user base before being committed to the 24.04 LTS, which carries a five-year standard support commitment and a ten-year extended security maintenance (ESM) commitment. The Flutter installer was the primary feature Ubuntu 24.04 LTS (Noble Numbat, April 25, 2024) inherited from the 23.10 release cycle, now becoming the default installer for hundreds of millions of Ubuntu installations.

The incident that most disrupted Ubuntu 23.10’s release was the discovery on October 11, 2023 — the day before the planned release — that the Uyghur language translation package for the installer contained malicious strings: text that would have displayed offensive and inflammatory content during the installation process rather than correct translation of the installer’s UI. The strings had been submitted through Canonical’s Launchpad translation platform, where community volunteers contribute translations without the same review process applied to source code. Canonical pulled the release for approximately one day, identified and removed the malicious translation, and re-released on October 12 after auditing other translation files. The translator’s Launchpad account was suspended, and Canonical enhanced its translation review processes. The incident was widely discussed in open-source security circles as an example of software supply chain risk outside the traditional focus on package repositories and build systems: translation files, documentation contributions, package metadata, and other non-code artifacts that flow through community contribution processes can also be vectors for introducing malicious or harmful content into software distributions. The specific targeting of a minority-language translation with content harmful to that community added political dimensions to what was already a technically notable supply-chain incident.