Skip to main content

the avatar of YaST Team

Digest of YaST Development Sprints 127 & 128

It’s summer in Europe and that means vacations for most members of the YaST Team at SUSE. Although that may imply less frequent blogging, we have some news to share with you today, like:

  • Taking over the development of the (open)SUSE Release Tools
  • Improvements in the new check-profile command
  • Finished migration from Travis CI to GitHub Actions
  • Several interesting bug fixes

Let’s go into some details

Release Tools: YaST Team to the Rescue!

As you all know, developing and maintaining complex software distributions like openSUSE Leap, Tumbleweed or SUSE Linux Enterprise is not an easy task. Specially since we want to ensure all of them stay independent but at the same time closely related, and since they keep evolving in new directions like Kubic, MicroOS and SLE Micro.

Our beloved Open Build Service is the key component that makes all that possible. But some extra tools are needed in addition to OBS in order to manage the complexity of the (open)SUSE distributions. Those extra tools are hosted and developed in a GitHub repository simply called openSUSE-release-tools. For years, the development process of those tools has been highly unstructured (not to say “slightly chaotic”), with more than 60 contributors but no clear mid-term strategy. Although that is not necessarily bad, some sustained and directed development is needed to solve some of the challenges we have ahead of us and to fix some pitfalls in the current development process of the openSUSE and SUSE products and distributions.

The YaST Team was chosen for such a task, so we will steadily take over development and maintenance of the tools in that repository. As first steps, we improved a lot the documenation. That includes extending the README file and adding new documents like an inventory of tools and a summary of the processes in which those tools are involved. We also extended and updated the automated tests and implemented an easy new check in the factory-auto bot.

We have way more ambitious plans for the future, but we are still learning and discovering new stuff in that repository every day.

Improvements in the AutoYaST Profile Validation

As you may know, we recently introduced a YaST client to validate complex profiles that include Embedded Ruby, rules and classes and/or scripts. Generally, such a validation could be done without root permissions, but there are some situations where superuser privileges are required.

To mitigate the implications, we introduced several improvements in the check-profile tool. You can see the details in the description of the corresponding pull request.

From Travis CI to GitHub Actions - Migration Completed

Some months ago, we started switching the continuous integration on all YaST repositories from using Travis CI to GitHub Actions. The main reason was that GitHub Actions are directly integrated in GitHub so it is easier to use - no need for extra account, less problems with authentication or permissions…

The transition is finished now. It was easy because both services are quite similar, although support for Docker is more straightforward in GitHub Actions. In this service, the actions are defined in YAML files in the .github/workflows subdirectory. We created several templates for the YaST packages.

If you want to know more, read the GitHub Actions documentation.

Interesting bug fixes

Although we spend a significant time of our sprints fixing bugs, we usually don’t blog about that part of the job because we understand is not the most exciting one. But this time we would like to highlight some pull request you may find interesting for several reasons. Including better handling of failures while analyzing the system, of variables in repository urls and of SSH authorized keys.

We keep working

As mentioned before, the YaST Team is not at full speed due to the vacation season. But we hope to keep delivering interesting stuff in many fronts and we will try to keep you all updated. Meanwhile, do as we do and have a lot of fun!

the avatar of openSUSE News

Deactivating connect.opensuse.org

Our community portal, reachable via https://connect.opensuse.org, accompanied our community now since 2010. A long, long time. Especially, if you compare it with Facebook (which started in 2006) or LinkedIn (who became an international company in 2010).

While Facebook and LinkedIn are meanwhile multi-billion dollar markets, our community portal is meanwhile mainly used to organize the openSUSE members and being a “contact point” for members, who provide their profiles to help others to contact them.

Over 20,000 actively registered users and 100 groups might give an idea about the diversity and agility of the openSUSE community. From artists to musicians over to local user groups and groups for all the different window managers and their lovers. Everyone found a place here in the openSUSE universe.

But time flies by quickly - and especially the technology sector never stands still. Today, we need to announce the final shut down of our community portal. The reason is simple: while we asked multiple times for help and someone who wants to actively maintain and administrate the service, nobody stepped up. As we can not secure the application any longer without big time investments, we decided to shut it down and let it rest in peace instead.

By doing this, we apologize for the trouble that this decision might cause to some people. We tried our best to support you over all the years by running the service as long as possible. But if nobody steps up and wants to take over the work any longer, it’s better to say ‘good bye’ instead to wait until the Hackers of the world share the data of our users.

An era comes to an end. A nice one, indeed. But it also means that there might be a new era on the horizon. Some new tools that have a maintainer and someone who takes care of them.

Look at our Forums, our Wikis, Mailing Lists or the new Matrix service. We will not stop to support you, we will do our best to keep you and your data secure.

The plan for membership management and applications to take place using Pagure.

Remember to have a lot of fun!

Lars - in the name of the openSUSE heroes -

a silhouette of a person's head and shoulders, used as a default avatar

openSUSE Tumbleweed – Review of the week 2021/29

Dear Tumbleweed users and hackers,

A new week full of Tumbleweed snapshots comes to an end. And we had one day without a new snapshot (not due to problems but there was simply nothing in the queue that would have passed staging). So, as a result, we have published 6 snapshots during this week (0715, 0716, 0717, 0718, 0720, and 0721).

The main changes included in those snapshots were:

  • KDE Frameworks 5.84.0
  • Mesa 21.1.5
  • Mozilla Firefox 90.0 & Thunderbird 78.12.0
  • Linux kernel 5.13.2
  • GNOME 40.3
  • libxcrypt 4.4.23: addition of CRYPT_SALT_METHOD_LEGACY
  • meson 0.58.1

The things currently brewing in the staging projects are:

  • Linux kernel 5.13.4
  • systemd 248.5, will be followed by 249 shortly after
  • meson 0.58.2
  • binutils 2.37
  • rpmlint 2.0
the avatar of openSUSE News

GNOME, Wireshark update in Tumbleweed

Since last Friday, five openSUSE Tumbleweed snapshots have been released.

GNOME 40, btrfs, Mesa, Wireshark and several other package updates landed this week in the rolling release.

The last snapshot posted to the openSUSE-Factory mailing list was 20210721. The snapshot contained updates for both GNOME 40 and the userspace utility to manage the btrfs file system; the btrfsprogs 5.13 package improved documentation, made some fixes and added preparations for the 5.14 Linux Kernel. GNOME 40 on the other hand had a slew of updates that focused on updating translations and bug fixing. A regression was fixed in the 40.3 gnome-maps package and the 40.3 gnome-software package fixed a crash that sometimes happened when clicking on a website button on a details page. Another crash that was fixed in gnome-terminal 3.40.3 affected the loading of the reference schema source, which failed. The 4.4.14 autoyast2 package now copies files to a correct location based on details listed at bsc#1188357. The text-sharpening package known as harfbuzz updated to version 2.8.2 and made various fixes and improvements to the subsetter. Other notable packages to update in the snapshot were yast2-users 4.4.4, text rendering package pango 1.48.7, system call tracer strace 5.13 and many others.

Just three packages were updated in snapshot 20210720. The cpupower 5.14 version included an upstream patch and made a speed select modification for Intel hardware. The other two packages to update were ibus-table-others 1.3.12, which updated some function keys, and the library openblas_pthreads 0.3.16, which had some architecture fixes and improvements for RISC-V.

Five packages updated in snapshot 20210718. Wireshark 3.4.7 fixed a Distributed Network Protocol dissector crash and a Common Vulnerability and Exposure. The mdevctl utility for managing devices updated to version 0.81 and fixed a defined aspect in the json file. A crash was fixed as well as an initialization error in the video codec library libaom 3.1.1. Both libslirp 4.6.0 and polkit-default-privs were also updated.

The 5.13.2 Linux Kernel has some bluetooth and Advanced Linux Sound Architecture fixes in snapshot 20210717. Mesa had a version bump to 21.1.5 in the snapshot, which was a minor bugfix release. The yast2 packages that were updated focused on security and the User Interface. Mozilla Firefox went CVE hunting and closed about nine vulnerabilities with its brand new 90 version; one of those was a memory safety bug. GTK2 support, which was used for a Flash plugin, was removed in the update of the browser. Mozilla also had an update of Thunderbird in the Tumbleweed snapshot. Just four CVEs were closed d in the release, which also fixed the memory safety bug that affected the release candidate for Firefox 90 and Firefox Extended Support Release 78.12.

The week started off with snapshot 20210716, which had more than a handful of Python Package Index updates; python-setuptools updated from version 44.1.1 to 57.0.0. A patch in the new major version was added to remove a dependency cycle for one simple function. There is no python2 support in the setuptools with the new version, according to the changelog. Ethernet device management tool ethtool 5.13 added some upstream features like a netlink handler for module and xwayland 21.1.2.

According to the review of week 29 systemd 249 and rpmlint 2.0 are in staging will be released soon.

the avatar of Just Another Tech Blog

Certificate Auto Enrollment from Samba

Certificate Auto Enrollment available in Samba 4.16

Certificate Auto Enrollment allows devices to enroll for certificates from Active Directory Certificate Services. As of Samba 4.16, Linux clients can now auto enroll for certificates just like a Windows client.

Samba’s Certificate Auto Enrollment uses the certmonger service to keep track of certificates. It also uses the cepces plugin to certmonger. The sscep command is also used to download the trust chain.

Certificate Auto Enrollment is compatible with both Winbind and SSSD.

Certificate Auto Enrollment is initiated using Samba’s Group Policy client, samba-gpupdate. The Samba wiki has more details on how to setup Group Policy, and how to configure Certificate Auto Enrollment.

the avatar of openSUSE News

Leap Gains Maintenance Update Improvements

The recent release of openSUSE Leap 15.3 has gained some maintenance improvements from a new repository setup.

Maintenance efforts for Leap related to Closing the Leap Gap expands to having three separate repository groups instead of one.

The openSUSE specific package repositories called oss and non-oss repositories changed. While these two repositories contained all the content of Leap 15.2 and older, they now contain only the branding and related setup packages.

The shared PackageHub and openSUSE packages known as the backports repository contains all the packages not in SUSE Linux Enterprise nor in the openSUSE specific packages. Previously, PackageHub was specific to SLE, which duplicated packages between openSUSE and PackageHub; now this single project is shared between both PackageHub and openSUSE Leap 15.3. This single repository will improve the quality of delivering updates and avoid package conflicts like zypper patch for openSUSE Leap 15.3.

There is a single repository with the SLE imported packages that contain the base packages and other packages from SLE. A single channel regenerated through a script will not need to be adjusted manually and will be good for the openSUSE setup in aarch64, s390x, x86_64/i586 and ppc64le architectures.

The first method used to export the SLE imported package repository for Leap was not working well in the current repository system, which led to several dependency issues, package version overlaps and other related instabilities.

Last week, the new export method was deployed using regular SLES module technology. This resolved all the current problems and also made handling and debugging the repository easier for the coordination teams.

The topic recieved various feedback from the Leap retrospective.

the avatar of Nathan Wolf

PipeWire Audio Server on openSUSE Tumbleweed

Linux audio has been considered a sore-spot with some audiophiles. Personally, I have been very happy with Linux Audio since about 2009 or 2010 or so and enjoyed its continual improvements as the project has matured. The high point for PulseAudio has been the intuitive, input / output switching. The downside has been the latency […]

the avatar of Nathan Wolf

Noodlings 30 | Packing up the Vintage

Episode 30 | Packing up the Vintage - LeoCAD 21.06 - SUSE Academic Program - BDLL Follow Up - openSUSE Corner - Computer History Retrospective on Computer Games (1984) Website - https://CubicleNate.com Mastodon - https://social.tchncs.de/@CubicleNate Twitter - https://twitter.com/CubicleNate YouTube - https://www.youtube.com/channel/UCY6KdxWFOlKaIPand7ROwvw https://open.lbry.com/@cubiclenate:9 Music: "Pixelland" by Kevin MacLeod
a silhouette of a person's head and shoulders, used as a default avatar

openSUSE Tumbleweed – Review of the week 2021/28

Dear Tumbleweed users and hackers,

This week I can’t but hope everybody is safe – at least here in Europe, water keeps falling from the sky. That bad weather has a positive side effect on Tumbleweed though: I prefer hiding inside, doing some Tumbleweed stuff instead of going outside. This has been visible during this week with a full 7 snapshots being published (0708…0714)

The most relevant updates included:

  • linux-glibc-devel 5.13
  • Linux kernel 5.13.1
  • KDE Gear 21.04.3
  • KDE Plasma 5.22.3
  • vsftpd 3.0.4: Disable TLS prior to v1.2 by default
  • grub2 2.0.6
  • bluez 5.60
  • fmt 8.0.0 together with ceph 16.2.5

Despite all this, the staging projects are not empty at all. You awesome maintainers keep things coming. Currently, we’re testing integration of these parts:

  • KDE Frameworks 5.84.0
  • Mozilla Firefox 90.0 & Thunderbird 78.12.0
  • Mesa 21.1.5
  • Linux kernel 5.13.2
  • libxcrypt 4.4.23: addition of CRYPT_SALT_METHOD_LEGACY
  • meson 0.58.1
  • rpmlint 2.0
the avatar of openQA-Bites

pasta - stupid simple pastebin service

pasta is a stupid simple pastebin service for self-hosting. I started this project months ago because I was missing an easy, simple and no pain self-hosting solution. This is what pasta is about. You just throw a file at it via it’s archaic web interface, a simple POST request or with its stupid simple CLI tool: