Notifications Feature Release for All Users
Frameworks, Gear, Pipewire Update in Tumbleweed
There was no slowing down of snapshots this week as new software continues to flow with daily openSUSE Tumbleweed releases. Tumbleweed went seven for seven this week!
Just two updates were in the 20211214 snapshot. The remote accessing package remmina 1.4.22 provided fixes for freerdp3 compatibility, and remmina also had a fix for a crash if the main window is closed. The libcap-ng 0.7.11 package, which analyzes a system for apps with too many privileges, removed unneeded rules.
Among the many packages that arrive in snapshot 20211213 were KDE’s Gear 21.12.0 and Frameworks 5.89.0 versions. Gear 21.12.0 had some Dolphin file manager enhancements like a Ctrl + i filter feature that brings up a box under the main panel, which added a new Detailed View feature through a right click on an empty space; select the View Mode > Details from the pop up menu. The screenshot application Spectacle gives KDE users a cleaner look of images they drag and drop from Spectacle’s preview panel to Dolphin or to an online image storage site for sharing. The Kdenlive video editor from Gear improved the motion tracking tools; Just use the box in the monitor to cover the area to track, click Analyse in the effects panel, and have fun! The video editor also has a new audio effect that removes background noises from recordings; the Noise Suppressor allows for a voice grab in the audio effects tab to be dropped onto an audio track for clean up. Frameworks 5.89.0 had a considerable amount of bug fixes for the Breeze Icons, which included the addition of a missing kmail breeze icon. The KContacts fixed address formatting for country-only addresses and deprecated countryToISO/ISOToCountry in favor of KCountry. Both KIO and Kirigami had some changes; the latter package lets the escape key close and push the dialog layers. The application library exo updated to version 4.16.3 and fixed compilation warnings; the package that is targeted at application development for Xfce also added typecheck verification to prevent a GTK bug warning. The mpg123 1.29.3 package fixed typos and added a note about equalizer frequency bands in the man page. The updated 370 version of xterm improved performance over slow connections and suppressed the loading of italic font in a few places when the colorITmode is enabled. Other packages to update were yast2-bootloader 4.4.10 and yast2-storage-ng 4.4.23, which added support for mount options use with libstorage-ng to determine whether a efibootmgr is available.
The second update of the week for the Advanced Linux Sound Architecture package arrived in snapshot 20211212. The alsa 1.2.6.1 version fixed the configuration for device parsing. Several alsa changes were made in the kernel-source 5.15.7 update. The kernel also had several KVM fixes to include a shadow nested paging that does not have Protection Keys for Userspace. Since there is now a require dependency, wireplumber became the session manager for pipewire 0.3.40 in the snapshot; “when in doubt, the suggested package is selected,” according to the changelog. The python-cryptography package updated from version 3.4.8 to 36.0.0, which went through a version number change in September. The new Python Package Index has the entire X.509 layer written in Rust; this allows alternate asymmetric key implementations that can support cloud key management services or hardware security modules provided they implement the necessary interface. About 10 more updates arrived in the snapshot.
Quite a few GNOME packages received a version bump in snapshot 20211211. While there were translation updates for gnome-maps 41.2, gnome-software 41.2 fixed a crash when processing age ratings and reloaded application details only when the items were not installing/removing the application. The gupnp 1.4.1 package fixed a regression in the async deprecated Application Programming Interfaces. Mozilla Firefox 95.0 updated in the snapshot, and fixed some Common Vulnerabilities and Exposures. The release appears to be a nod at Windows 95 now that the browser is available in the Microsoft Store. A fix in the use of the default log writer with journald namespaces was made in the glib2 2.70.2 update. Other packages to update in the snapshot were hwdata 0.354, FireEye’s hxtools 20211204, LibreOffice 7.2.4.1, Node.js, 16.13.1, vte 0.66.2, yast2-installation 4.4.28 and more.
Three packages were updated in snapshot 20211210. An added method to disconnect proxy signals was made in the gnome-remote-desktop 41.2 update; the package, which can also be used for screencasting, made warning messages a little bit more explicit. The Linux laptop battery Optimizing package tlp 1.4.0 renamed “Battery Features” to “Battery Care” and introduced plugins to support Battery Care for non-ThinkPads; ASUS, Huawei, LG, Lenovo and Samsung are the first to benefit from the plugins. The kernel headers were updated in the linux-glibc-devel 5.15 release.
Most of the updates in snapshot 20211209 were PyPi updates with the exception of the libffi 3.4.2 and nvme-cli 1.16 updates. Snapshot 20211208 provided the first asla 1.2.6 update, which improved the support of multiple formats in the Pulse-code modulation. The sudo 1.9.8p2 package fixed a few minor memory leaks and sudo_logsrvd now only sends a log ID for the first command of a session, so there is no need to send the log ID for each sub-command. Several other packages were updated in the snapshot like screen reader orca 41.1, soundtouch 2.3.1 and yast2-journal 4.4.1, which is preparing code for Ruby3 along with many other YaST packages.
Celebrate the first openSUSE BAR anniversary!
Almost a year ago, on the 19th of December 2020, openSUSE Members knurpht and m4u had the following conversation:
Gertjan™ - Knurpht™, [19.12.20 00:05]
Dude, have a drink on meet.opensuse.org/beer?
Gertjan™ - Knurpht™, [19.12.20 01:11]
Yo, we( Neal and me are waiting for you to show up
Maurizio G., [19.12.20 05:36]
let’s see how i feel after coffee
Maurizio G., [19.12.20 05:38]
are you and neal still in the BAR?
Gertjan™ - Knurpht™, [19.12.20 05:39]
Nope
We were in the beer btw 😃
Maurizio G., [19.12.20 05:41]
yea i saw your message
Maurizio G., [19.12.20 05:41]
i’m just waking up. maybe in a bit
Gertjan™ - Knurpht™, [19.12.20 05:42]
Now in meet.opensuse.org/BAR
This was the birth of our beloved openSUSE BAR! Since then, the BAR has been a place for contributions, for fixing things together and just hanging out.
The BAR evolved into an important part of our community that helps people get to know each other in the project. It has on-boarded new contributors, strengthened old friendships, brought fixes for various issues on the way and was the place for historical events, such as probably the oldest openSUSE User (89 y.o.) meeting the youngest openSUSE Member (16 y.o.).
During the online openSUSE Leap 15.3 release party, which was aimed to last for 24 hours, the bar passed the marks of a 50+ guests and a 100-hour-BAR session on June 6, 2021, which was followed by reaching a mark of a 200-hour-BAR session on June 10, 2021.
To celebrate the first-year anniversary of the BAR, the second largest BAR event is going to begin on Dec. 18 starting 16:00 UTC at meet.opensuse.org/bar!! Let’s see how long we can keep the party going this time!
We definitely look forward to seeing you all there!! New faces, old friends, those that visit the BAR regularly, and those who have never logged on before. Cheers!
NOTE: Please don’t be discouraged if it takes you a couple of tries to connect! Just keep trying!! Just keep trying and mash the F5 key to refresh, you won’t regret it!!
The openSUSE BAR Crowd
Fedora, CentOS and me
Let me share my Fedora story with you. Hopefully, it helps you to understand, why I am also promoting AlmaLinux and Rocky Linux, even if I am an active Fedora and CentOS community member and contributor.
Before the beginnings
Someone suggested me to try Red Hat Linux in 1995 and replace Slackware Linux with it on my university server. I installed it, but I did not become a fan. And when I found the print out of the password file of my server on the wall of the Russian students' computer lab (see: https://peter.czanik.hu/posts/russian_students_logging/), I quickly switched to Jurix, which already featured shadow passwords. And as Jurix became the base for SUSE Linux, I became a SUSE Linux and later an openSUSE user.
The beginnings
When I started to work at Balabit (now part of One Identity) almost twelve years ago, one of my first tasks was to ensure that the latest version of syslog-ng is available in Linux distributions and FreeBSD. I reached out to package maintainers and helped them to update the syslog-ng package. It went quite well in most cases, but I was stuck with Fedora and EPEL updates. I tried to reach out to developers through official and unofficial channels without luck.

syslog-ng logo
While talking to syslog-ng users, I tried to figure out what OS they use. It turned out that even if syslog-ng was the default syslog implementation in openSUSE and SLES, our most active users were running syslog-ng on RHEL and CentOS. So, I became even more active trying to resolve the syslog-ng package situation, still without luck.
The turn of events arrived almost a year later at FOSDEM. What could not be solved with tickets and e-mails was resolved within five minutes at the Fedora booth in person at FOSDEM. I met a Hungarian Fedora ambassador there who connected me with the right people, and syslog-ng was soon updated to the latest version.
Friends
Freedom, friends, features, first, are the four core values of Fedora. From those “Friends” became very important to me. Even if my operating systems of choice are openSUSE (https://peter.czanik.hu/posts/opensuse_memories_1/) and FreeBSD, I do not have many friends in those communities. However, soon after that initial meeting at the Fedora booth at FOSDEM I got many friends in the Fedora community, both here in Hungary and abroad. I helped in organizing some local gatherings and soon I was asked to become a Fedora ambassador. I gave Fedora talks at various events and helped maintaining the Fedora booth around Europe.
syslog-ng packaging
At first I helped syslog-ng package maintainers with upstream information. Soon I was asked to become a co-maintainer for the syslog-ng package in Fedora and EPEL. I did minor version updates, new syslog-ng features, while the original maintainers did larger changes, like enabling systemd support, new EPEL versions, and so on.
For the past couple of years I maintain syslog-ng mostly alone, both in Fedora and EPEL. I also have my unofficial packages in Copr. This is necessary, as the EPEL policy does not allow version upgrades, while users want to use the latest syslog-ng features.
CentOS Stream and the new RHEL clones
When the end of the traditional CentOS Linux was announced, many syslog-ng users cried out loud. Based on my estimates, about 80% of syslog-ng users run CentOS or RHEL, so I’m monitoring the situation as much as I can. I had a couple of Twitter polls, e-mails on the syslog-ng mailing list and direct discussions with some of our power users.
Only very few organizations seem to be enthusiastic about CentOS Stream. They tend to have their own OS team in house, which does its own OS release based on CentOS. In their case the Stream model made their life easier. The rest of users still seem to prefer the traditional release model.
Based on user feedback it seems, that most of our users will stay on RHEL and compatible operating systems. Some already made the switch: small companies changed from CentOS Linux to RHEL. But many larger installations running thousands of hosts are switching from CentOS to AlmaLinux. While others are switching to Rocky Linux and even Oracle Linux. And some to my favorite non-Linux OS: FreeBSD.
Friends vs. OS
While I have many friends in the Fedora and CentOS developer and user communities, these operating systems are just part of my syslog-ng work. To me it does not matter at all which OS people use to run syslog-ng. If suddenly all syslog-ng users started to use Slackware, I could easily drop my Fedora-related activities and focus on Slackware. Luckily, from the syslog-ng standpoint, support for RHEL, Alma, Rocky and Oracle is the same. I keep using the same tools, same workflows, and in bug reports I only see that people use packages from the Copr repository I maintain. No idea about the OS vendor.
TL;DR: The OS I support for syslog-ng and friendships are two completely separate things. Fedora made me many friends, and I’m grateful for that.
Installing syslog-ng on CentOS Stream 9
CentOS Stream 9 has been around for a while, but it was officially announced just a few days ago. I already tested some earlier snapshots and they had some rough edges. The current version installed without random crashes, has networking and runs smoothly. EPEL – the semi-official repository by Fedora maintainers – is already there, but practically empty, syslog-ng or it’s dependencies are not yet there. As someone asked about syslog-ng support, I had a first try at building it.
I built syslog-ng for CentOS Stream 9 in the Copr build service. Many of the syslog-ng dependencies are not yet available, so I had to compile them myself. EPEL 9 is expected to have the latest Fedora versions, so I used those. I could not get MongoDB client libraries compiled, but the rest of the dependencies are there.
Reat the rest of my blog at https://www.syslog-ng.com/community/b/blog/posts/installing-syslog-ng-on-centos-stream-9

syslog-ng logo
Working and warming up cats
I’m using an external keyboard (1) and mouse (2), but the laptop lid is usually still open for better cooling. That means the internal keyboard (3) and touchpad (4) – made of comfortable materials – are open to be used by a cat searching for warmth (7), in the obvious “every time” case that a normal non-heated nest (6) is not enough.

The problem is, everything goes chaotic at that point in the default configuration. The solution is to have quick shortcuts in my Dash to Dock (8) to both disable (10) and enable (9) keyboard and touchpad at a very rapid pace.
It is to be noted that I’m not disabling the touch screen (5) by default, because most of the time the cat is not leaning on it – there is also the added benefit that if one forgets about the internal keyboard and touchpad disabling and detaches the laptop from the USB-C monitor (11), there’s the possibility of using the touch screen and on-screen keyboard to type in the password and tap on the keyboard/touchpad enabling shortcut button again. If also touch screen was disabled, the only way would be to go back to an external keyboard or reboot.
So here are the scripts. First, the disabling script (pardon my copy-paste use of certain string manipulation tools):
dconf write /org/gnome/desktop/peripherals/touchpad/send-events "'disabled'"
sudo killall evtest
sudo evtest --grab $(sudo libinput list-devices | grep -A 1 "AT Translated Set 2 keyboard" | tail -n 1 | sed 's/.*\/dev/\/dev/') &
sudo evtest --grab $(sudo libinput list-devices | grep -A 1 "Dell WMI" | tail -n 1 | sed 's/.*\/dev/\/dev/') &
sudo evtest --grab $(sudo libinput list-devices | grep -A 1 "Power" | grep Kernel | tail -n 1 | sed 's/.*\/dev/\/dev/') &
sudo evtest --grab $(sudo libinput list-devices | grep -A 1 "Power" | grep Kernel | head -n 1 | sed 's/.*\/dev/\/dev/') &
sudo evtest --grab $(sudo libinput list-devices | grep -A 1 "Sleep" | grep Kernel | tail -n 1 | sed 's/.*\/dev/\/dev/') &
sudo evtest --grab $(sudo libinput list-devices | grep -A 1 "HID" | grep Kernel | head -n 1 | sed 's/.*\/dev/\/dev/') &
sudo evtest --grab $(sudo libinput list-devices | grep -A 1 "HID" | tail -n 1 | sed 's/.*\/dev/\/dev/') &
#sudo evtest --grab $(sudo libinput list-devices | grep -A 1 "ELAN" | tail -n 1 | sed 's/.*\/dev/\/dev/') # Touch screen
And the associated ~/.local/share/applications/disable-internal-input.desktop:
[Desktop Entry]
Version=1.0
Name=Disable internal input
GenericName=Disable internal input
Exec=/bin/bash -c /home/timo/Asiakirjat/helpers/disable-internal-input.sh
Icon=yast-keyboard
Type=Application
Terminal=false
Categories=Utility;Development;
Here’s the enabling script:
dconf write /org/gnome/desktop/peripherals/touchpad/send-events "'enabled'"
sudo killall evtest
and the desktop file:
[Desktop Entry]
Version=1.0
Name=Enable internal input
GenericName=Enable internal input
Exec=/bin/bash -c /home/timo/Asiakirjat/helpers/enable-internal-input.sh
Icon=/home/timo/.local/share/icons/hicolor/scalable/apps/yast-keyboard-enable.png
Type=Application
Terminal=false
Categories=Utility;Development;
With these, if I sense a cat or am just proactive enough, I press Super+9. If I’m about to detach my laptop from the monitor, I press Super+8. If I forget the latter (usually this is the case) and haven’t yet locked the screen, I just tap the enabling icon on the touch screen.
Extract SCHEDULE from an openQA job
Then using openqa-clone-job (and derivates) one can use the SCHEDULE variable to clone a test run with a custom set of test modules. This is particular useful, when developing a new test case and you need a verification run with e.g. an additional test module or to exclude some failing ones.
However it is sometimes cumbersome to type out a large list of tests into a custom SCHEDULE variable, if the amount of test modules exceeds 5 or more tests (e.g. extra_tests_textmode - good luck!).
openSUSE Tumbleweed – Review of the week 2021/49
Dear Tumbleweed users and hackers,
Unfortunately, we could not keep up the daily streak of snapshots during this week. We ‘only’ managed to push out 6 snapshots. Over the last weekend, we had an openQA-worker causing some troubles, which resulted in not sufficient throughput to get anything ready to publish. But 6 snapshots is still acceptable, isn’t it? Anyway, we had the following releases: 1202, 1203, 1205, 1206, 1207, and 1208.
The main changes included were:
- KDE Plasma 5.23.4
- Automake 1.16.5
- sssd 2.6.1
- Harfbuzz 3.1.1: as announced, sadly with an ABI break. I triggered a rebuild of everything behind harfbuzz, so unless packages explicitly used the lost API, they should be back in shape at least. One known fallout is still electron, which I have a submission on the queue, scheduled for snapshot 1210.
- Linux kernel 5.15.6
- Mesa 21.3.1
- gc 8.2.0
- Poppler 21.12.0
- strace 5.15
- GCC 11: Enable the full cross compiler, cross-aarch64-gcc11 and cross-riscv64-gcc11 now provide a fully hosted C (and C++) cross compiler, not just a freestanding one
Stagings are almost all filled, and you can expect these changes coming to Tumbleweed soon:
- Linux kernel 5.15.7
- Mozilla Firefox 95.0
- Rust 1.57
- Kubernetes 1.23
- KDE Applications 21.12.0
- GNOME 41.2
- Moving default php version from php7 to php8
- Testing the results when moving system ruby from 2.7 to 3.0: YaST team is working on the main fallouts
- Enabling the build of python310-* modules; the move of the devault python3 provider to python310 should follow soon after
- pipewire 0.3.40, with a move to from pipewire-media-session to wireplumber; currently failing openQA
- openSSL 3.0
Reducing the complexity of log management
It is easy to over-complicate log management. Almost all departments in a company need to log messages for their daily activities. However, installing several different log management and analysis systems in parallel is a nightmare both from a security and an operations perspective and wastes many resources. You cannot always reduce the number of log analysis systems, but you can reduce the complexity of log management. Let me show you, how.
Read my blog at https://www.syslog-ng.com/community/b/blog/posts/reducing-the-complexity-of-log-management

syslog-ng logo
Note: unlike most of my blogs, this one is not deeply technical. Rather it gives a good overview, why a dedicated log management layer is important. The second half of my blog also mentions commercial software.
Ritchie-CLI Becomes Official, Mesa, bind Update in Tumbleweed
This week brought an exuberant amount of openSUSE Tumbleweed snapshots.
While the rolling release snapped its streak of continuous daily snapshots, Tumbleweed persists releasing numerous snapshots; in total, five have been released so far this week.
The last snapshot, 20211207, updated one package that gamers will appreciate. The computer opponent for the board game Blokus was updated with the release of pentobi 19.1. The bug fixing update provided a work around for a crash that happened during an exit in some situations. The package also avoids a warning with Qt 6 caused by a deprecated signal-handler syntax.
Snapshot 20211206 updated the 3D graphics package Mesa to version 21.3.1. The updated provided mostly AMD, Intel and Zink fixes. The package also added a work around to fix a segfault with the first-person shooter video game Metro Exodus, which announced availability with Linux in April 2021. The highly portable implementation of the Domain Name System protocol bind 9.16.23 fixed CVE-2021-25219 by disabling the lame server cache that would have allowed an attacker to significantly degrade resolver performance. There were some patches removed in the blog 2.26 update. Font rendering package freetype2 2.11.1 improved cmake support and updated the latest experimental COLRv1 Application Programming Interface to OpenType standard 1.9. Another rendering package poppler, which is for pdfs, updated to version 21.12.0 and added a few APIs; one to read/save to file descriptor; one to add images; and one to validate signatures. Many incremental improvements and bug fixes were made in the libvirt 7.10.0 update and a new feature is a binary that helps users figure out the format of Distinguished Name from a certificate file the way it expects in the tls_allowed_dn_list option of the libvirtd.conf configuration file. The userspace components for the Linux Kernel’s drivers and infiniband subsystem package rdma-core 38.0 was the only major version update in the snapshot; it updated kernel headers stddef.h. Other packages to update in the snapshot were gc 8.2.0, kImageAnnotator 0.5.3, strace 5.15 and more.
Snapshot 20211205 was pretty much all about the compiler and kernel with the exception on one other package; parsing library package mxml 3.3 fixed a potential memory leak in mxmlLoad functions and added more error handling to the library. The minor update of gcc11 11.2.1 enabled the cross compilers on the i586 microprocessor and removed the cross compilers for the i386 target. The 20211123 kernel-firmware updated the firmware file for Intel Bluetooth and kernel-source 5.15.6 fixed codecs for ALSA System on Chip errors, some discovery of arm firmware and a couple network facets like fixing the bridge port operation related to Marvell hardware.
Most of the updates in snapshot 20211203 were related to YaST. The update of yast2-storage-ng 4.4.20 fixed regressions for unit tests and replicated the generation of bcache issues to avoid setting the architecture for every test. The yast2-installation 4.4.26 package added a display the of a product’s license when only one product is available, but will not display the product’s selector during an upgrade. Virtualization package xen 4.16.0 made fixes to the Trusted Platform Module in preparation for TPM 2.0 support. A major version update of the text shaping library harfbuzz became available in the snapshot; the 3.1.1 version improved Unicode 14 properties in the shaper and provided COLRv1 tables subsetting support, and various other subsetter fixes. Other packages to update were libstorage-ng 4.4.63, scout 0.2.6, rubygem-cheetah 1.0.0 and rubygem-yast-rake 0.2.43.
Starting the week, KDE users could update to Plasma 5.23.4 in snapshot 20211202. Plasma’s software management GUI Discover made some adjustments on handling Flatpak and other software. Plasma’s power consumption package PowerDevil fixed a bug that had a different notification behavior for a critical battery than that of a low battery. Other packages updated in the snapshot were sssd 2.6.1, which hardened systemd services, and automake 1.16.5, which dropped a couple patches and made the output more reproducible.
After a lot of work, Ritchie-CLI 2.11.3 is officially available in the openSUSE Tumbleweed repository. Ritchie-CLI became official Nov. 11 in Tumbleweed, but was not covered in previous blogs. A big congratulations goes out to the entire ZUP team!
Ritchie is an open-source tool developed by the ZUP Company and allows users to create, store and share automations securely. It optimizes repetitive commands so users have more programming autonomy. Ritchie release notes provides an add Rhythm List Formulas command, a forced update option to run the latest formula version when enabled, lib to support Ritchie-CLI internationalization, repository new version detection using cache, and many other features. Alessandro de Oliveira Faria is working to add a new package to Factory and help from the openSUSE community is welcomed. The package is also in Alessandro’s Open Build Service home project for those interested in testing; there is also cloud testing. More information can be found in the package’s release notes.