Skip to main content

the avatar of Martin de Boer

What’s new in openSUSE Leap 15.2

openSUSE Leap 15.2 has entered the Beta phase on the 25th February 2020. I have recently installed this on my laptop to check it out. Leap 15.2 will coincide with SUSE Enterprise Linux Desktop 15 Service Pack 2. Both Leap and SLED share a lot of underlying packages, so this will be (again) a rock solid release.

openSUSE Leap 15.2 features many big updates. This includes a new version of the KDE desktop environment, a new version of the GNOME desktop environment and a new Linux kernel. In the Leap 15.2 column of the table below, I have highlighted in green the packages that are significantly changed in comparison to Leap 15.1. And in blue, I have highlighted the packages that are changed compared to Leap 15.1 at time of its release, but which are now also available in updated Leap 15.1 installations.

openSUSE Tumbleweed is a rolling distribution, so it will always change. The Tumbleweed column features a snapshot of the situation at the end of April 2020. I have only highlighted in green the packages that are significantly newer than the packages in Leap 15.2. This shows the areas where Leap 15.2 is behind the software development curve. Staying a bit behind the curve is not necessarily a bad thing. You install openSUSE Leap because you don’t want to deal with constant change. You install openSUSE Tumbleweed if you want to stay on the cutting edge. They both have their own audiences. This comparison helps (future) openSUSE users understand the main differences between Leap 15.2 and Tumbleweed, so they can figure out which of these distributions is right for them.

Package name Leap 15.1 Leap 15.1 Leap 15.2 Tumbleweed (Apr 2020)
with updates
Amarok 2.9.0 2.9.0 2.9.7 2.9.7
Audacity 2.2.2 2.2.2 2.2.2 2.3.3
Calibre 3.40 3.40 3.48 4.13
Calligra suite 3.1.0 3.1.0 3.1.0 3.1.0
Chromium browser 73 81 81 81
Darktable 2.6.2 2.6.3 2.6.3 3.0.2
Digikam 6.0 6.0 6.4 6.4
Flatpack 1.2.3 1.2.3 1.6.3 1.6.3
GIMP 2.8.22 2.8.22 2.10.12 2.10.18
Gnome Applications 3.26 3.26 3.34 3.36
GNU Cash 3.0 3.0 3.9 3.9
Hugin 2018.0 2018.0 2019.2 2019.2
Inkscape 0.92.2 0.92.2 0.92.2 0.92.4
KDE Applications 18.12.3 18.12.3 19.12.3 19.12.3
KDE Plasma 5 desktop 5.12.8 5.12.8 5.18.4 5.18.4
Krita 4.1.8 4.1.8 4.2.9 4.2.9
LibreOffice 6.1.3 6.4.2 6.4.2 6.4.3
Linux kernel 4.12.14 4.12.14 5.3.18 5.6.4
Mozilla Firefox ESR 60.6 68.7 68.6 68.7
Mozilla Thunderbird 60.6 68.7 68.6 68.7
OpenShot 2.4.1 2.4.1 2.4.1 2.5.1
Rapid Photo Downloader 0.9.09 0.9.14 0.9.22 0.9.22
Scribus 1.4.7 1.4.7 1.5.5 1.5.5
Telegram 1.6.7 1.6.7 2.0.1 2.1.0
VLC 3.0.6 3.0.9 3.0.7 3.0.9
YaST 4.1.68 4.1.75 4.2.82 4.2.82

Software package updates

Chromium moved from version 73 to version 81 and a lot has changed. Important new features include a Forced Dark Mode that enables dark mode on every website, the Silent Notification Popup feature contains notifications under a special icon in the URL address bar, the Tab Freezing feature unloads tabs that are not used for 5 minutes (saving CPU and RAM). A lot of security improvements were made, including DNS over HTTPS (experimental) where DNS (domain lookup) requests are send over a secured connection. Mixed HTTP/HTTPS content is now auto-upgraded to HTTPS, the Password Checkup utility checks if your saved passwords have been breached and the Predictive Phishing feature warns users if they are about to enter their passwords in a phishing website.

Digikam 6.4 features a lot of changes in comparison to Digikam 6.0. The 15 year old KIPI plugin interface is swapped for the much improved DPlugins interface. This allows plugins to work on all aspects of the Digikam application and accompanying tools. And a lot of new plugins take advantage of that. There is a new plugin to use images as your desktop wallpaper. The GMic-Qt plugin adds a lot of filters (comparable to GIMP and Krita). A RAW import tool plugin allows configurations from Darktable, Rawtherapee and Ufraw to be imported via the Image Editor. And finally a new Clone Tool Plugin allowing you to clone parts of an image. The new LibRaw 0.19.3 library allows for more RAW formats to be imported into Digikam.

Flatpak 1.6.3 has changed the protocol and API for handling authentication, making it more secure, flexible and futureproof.

Gimp 2.10.12 is a major update compared to Gimp 2.08.22. It has a new image processing engine called GEGL. This image processing engine makes use of multi-threading, making Gimp much faster. Gimp now works in a linear RGB color space. Color management is also a core feature of Gimp. Gimp 2.10 has better file formats support, including reading and writing TIFF, PNG, PSD and FITS files. The interface of Gimp is also improved. It now has HiDPI support and the icons are more stylized. Gimp 2.10 has better transformation tools, better selection tools, an improved text tool and a number of digital painting and digital photography improvements. If you want a detailed description of all improvements, check the release notes.

The GNOME desktop and applications are updated from version 3.26 to 3.34. That is a difference of 4 major releases. The GNOME Shell has seen many performance/speed improvements, so it feels much more responsive. The Adwaita theme has gotten an overhaul and now features a flat style and more beautiful icons. openSUSE Leap 15.2 also allows you to install the Yaru theme (Ubuntu) and the Pop!_OS theme (System 76). The touch keyboard is much improved and now features emoji’s. And finally you can group apps into folders in the Activities overview.

Many GNOME applications feature UI improvements, including Web, Settings, Contacts, Notes and Terminal. The Photos application features new editing tools. The Files application features a new unified navigation/search bar. Web also features a new reader mode and the option to enable hardware acceleration. GNOME Software features a faster search engine. There are many improvements to the Boxes virtualization application, but according to a recent Arstechnica article it is still less usable than Virt-manager. There are also 3 new application introduced. Fractal is a Matrix Chat client. Matrix works similar to WhatsApp and Telegram but it’s Open Source and decentralized. It is co-developed and heavily used by the French government to make sure that their conversations stay private. Usage is a new (basic looking) performance monitor tool. And Podcast (obviously) is a Podcast player.

GNUCash 3.9 features many improvements for your accounting needs. Usability is improved, by adding better tooltips, multi-selection in the import transaction matcher and the ability to assign a single target account to more than one transaction in the import matcher. It features improvements to reporting, including a full rewrite of Customer/Employee/Vendor reports, improvements to the Transaction report and the introduction of a user-customizable CSS based stylesheet. It features currency handling improvements, including using the default currency for the summary bar currency. And using the customer and vendor currency instead of the default currency when generating bills, invoices or credit notes.

Hugin 2019.2 can now convert the RAW images to TIFF with a new RAW converter.

Inkscape remains on version 0.92.2. Which is unfortunate, as Inkscape 1.0 was just released and contains many new features.

KDE Applications were updated from 18.12.3 to 19.12.3. Which equals 3 releases. A lot of improvements were made over the course of that year. Dolphin (file manager) can now be launched from anywhere via the Windows + E keyboard shortcut. Dolphin handles the rendering of tumbnails much better and now includes previews of .cb7 files. Gwenview (image viewer) has better touchscreen and HiDPI support. Its tumbnails load faster. It has a new share menu to share images via email, phone, NextCloud or Twitter. And Gwenview now integrates with Krita out of the box. Okular (document viewer) has improved touchscreen support. It now supports viewing and verifying digital signatures in PDF files. It also adds support for LaTex documents. It improves ePub support. And it has improved annotation features.

In terms of productivity, Kmail (e-mail client) has seen some improvements. It now has unicode color emoji and markdown support. It has grammarly integration for better grammar checking. And it detects phone numbers, which can be dialed via KDE Connect. Korganizer (calendar) improved its support for Google Calendar. A new application was added, which is called Kitinerary, a travel assistant.

In terms of multimedia, Kdenlive (video editor) has seen a big code re-write. It should now be faster and more performant and easier to use. It features new keyboard-mouse shortcuts to make you more productive. And it comes with a new sound mixer to help you synchronize music with video clips. Elisa is a new KDE music player. It looks quite similar to Amarok, which was my go-to music player for the last 10 years. It looks interesting enough to give it a try. Amarok didn’t have any new releases over the last 2 years. So maybe it’s time to switch.

In terms of utilities, Spectacle (my new favorite screenshot tool) now allows you to configure what happens when you press the screenshot button while the application is open. It features a neat taskbar indicator, showing you (if you choose to delay it) when the screenshot will be taken. And you can now use the touchscreen to select the area that you want to screenshot. Kate (text editor) added a quick open feature to open your most recent files. Konsole (terminal) now has an awesome tiling feature, that allows you to split panes horizontally and vertically as many times as you like. Calligra Plan (planner) finally gets a new release. It helps you plan your projects Gantt style. KDE Connect now has a new feature to write and read SMS messages from your desktop. Also, you can now control the volume of your phone from your desktop. The Plasma Browser Integration plugin gained a nice multi media feature, giving you the ability to blacklist sound sources from certain websites.

The Plasma desktop has changed from version 5.12.8 to version 5.18.4. Which are 6 major releases, so there are many changes to look forward to. A lot of effort has gone into the look and feel of the desktop. The login screen and lock screen were completely redesigned and look much better. The system settings are also totally redesigned, making them better suited for small screen (read mobile) devices. The Breeze icons also have seen some adjustments to make them look sharper. GTK support is much improved. GTK applications now respect KDE settings, KDE color schemes, have shadows on X11 and support the KDE global menu. The Color scheme and Window Decoration pages were redesigned. And you can now set a ‘Picture of the Day’ as your wallpaper. Which is a really cool feature.

If you say KDE 5, you say widgets. And widgets are now easier to rearrange then ever. You can put the desktop into Global Edit mode and easily drag and resize all widgets. The notifications system has been completely rewritten and now includes a ‘Do not disturb’ feature. The system tray now shows a warning whenever audio is recorded, enhancing your privacy. A new widget for display configuration is useful if you have multiple monitors or if you often work from different places. The power widget now shows the battery status of Bluetooth devices. The network manager widget now includes support for WireGuard VPN tunnels. And it is now faster to refresh WiFi networks. And a new system tray widget lets you control the Night Color feature.

The Discover software manager is much improved. Which was really necessary. I intend to address the current state of KDE Discover and Gnome Software on Leap 15.2 in a separate post. You can now sort lists and category pages, including by release date. There are progress bars and spinners added to various parts of the application. It has a new updates page with sections for ‘downloading’ and ‘installing’ applications. You can also deselect updates in the update page. Discover can update your firmware via the ‘fwupd’ project. This is a very nice feature, but only works on supported hardware. It can also update a full Linux distribution. However I can imagine that this feature works better on KDE Neon than on openSUSE (YaST is most likely superior). Discover can auto-install the Flatpak back-end if it’s not installed by default and now supports Snap channels.

KDE Plasma 5.18 has much improved Wayland support (the new display manager). Including initial support for proprietary Nvidia drivers. KWin (the Window manager) now supports fractional scaling on Wayland, which is useful on HiDPI screens. Night Color is now available on X11 (the old display manager). You can now manage your Thunderbolt devices from the system settings. And the desktop is much more responsive.

Krita is now on version 4.2.9 and now supports painting in HDR. The brush speed is much improved, the color palette is easier to use, the artistic color selector has been cleaned up and a new color gamut feature was added. A lot of bug fixes make the application more stable than ever.

LibreOffice moved from version 6.1.3 to version 6.4.2. The tabbed user interface (which looks similar to Microsoft Office Ribbon interface) moved out of the experimental stage and is now fully baked. Writer has seen many improvements. You can now place comments on images / charts. You can now mark comments as resolved. You can now hide tracked changes. You can set the text direction in text frames. You can avoid overlapping shapes, by selecting an auto-detection mode. Handling of tables is much improved. And the sidebar now has a panel for Table actions. Calc has gained a new multivariate regression analysis. Data validation now supports custom formulas. Which is very handy. In Impress, you can now consolidate multiple text boxes into one text box. Overall improvements in LibreOffice are better support for (and faster opening of) Microsoft Office document formats.

The Linux kernel was updated to version 5.3.18. Since the last version, a lot of improvements have gone into the Linux kernel. However, some of these improvements were already backported into the openSUSE 4.12.14 kernel. In this paragraph I will detail some of the major changes between the official kernels 4.12 and 5.3. Intel has added Comet Lake, Cannonlake and Coffeelake support. Intel Icelake Gen11 graphics are now supported. Intel Icelake and Geminilake now support HDR displays. Nouveau, the open source NVIDIA driver, has gained support for GeForce GTX 1650, GeForce GTX 1660 and GeForce GTX 1660 Ti. It also gained support for HDMI 2.0. AMD added various Ryzen laptop and Threadripper improvements. AMD added support for Radeon RX Vega M and for Navi GPU’s (including Radeon RX 5700). AMD added FreeSync display support (for supported GPUs and Displays).

The Linux kernel has improved Btrfs performance and features, including Swap files and Zstd compression support. Realtek WiFi drivers were added for the RTW88 and RTL8822BE chips. The Realtek R8169 driver was updated. The Linux kernel now has full support for Raspberry Pi 3B and 3B+. The kernel also added support for the Raspberry Pi Touchscreen driver. The kernel now has MacBook and MacBook Pro keyboard support. Significant power savings were accomplished for certain hardware by optimizing idle time. And mitigations for the Spectre vulnerability were added for most hardware architectures.

Mozilla Firefox (Extended Support Release) was updated from 60.6 to 68.6. This is a relatively old version, as the regular release of Firefox is now on version 76. I advice everyone to add the Mozilla repository and change Firefox to the non ESR version. But if you use Firefox 68 ESR, there are some nice improvements. On the user interface the new Firefox Home (which you see when you open a new tab) allows users to display up to 4 rows of top sites, pocket stories and highlights. You can now select multiple tabs from the tab bar and close/move/bookmark/pin them all at once. The toolbar now shows your Firefox Sync status. Firefox now prevents websites from automatically playing sounds. The Dark theme has seen some improvements, including a dark mode for the reader. And you can now save passwords in private browsing mode. There are various technical enhancements. Most noticeable are the performance improvements (due to Quantum CSS improvements and Clang Link Time Optimization) and smoother scrolling. Firefox now supports CSS Shapes and CSS Variable Fonts. It now supports the WebP image format. And it now uses TLS 1.3 by default. Another nice improvement is that WebExtentions now run in their own process on Linux.

Mozilla Thunderbird moved to version 68, which is the most recent version. There are some small improvements in comparison to Thunderbird 60. You can now mark all folders of an account as read. Language packs can now be selected in the advanced options. Only WebExtension themes and WebExtension dictionaries are supported in this new version.

Rapid Photo Downloader is now on version 9.22. A notable addition is the support for Canons CR3 RAW format. However this is not supported on openSUSE Leap 15.2 because it uses an older ExifTool version. A (future looking) addition is the support for the HEIF / HEIC file format.

Scribus is updated to version 1.5.5. Most of the changes are under the hood. However there are some nice improvements, such as the ability to use Scribus with a dark UI color scheme. And the possibility to search for a particular function (like in GIMP).

Telegram Desktop has now moved to version 2.0. Notable improvements are the ability to organize chats into chat folders, the ability to pin an unlimited number of chats in each folder, a picture-in-picture mode to watch videos, the ability to rotate photos/videos in the media viewer, an autoplay function for videos, the ability to schedule a message to be send at a later time and the ability to set reminders for yourself in the saved messages chat.

Installation options

The standard installer comes as a full DVD image (with lots of included packages for offline installation) and as the (smaller) Network installer image. You can download these images for PC (X86_64) for ARM (AArch64) and for OpenPower (ppc64le) hardware.

Live images are available for GNOME and for KDE. These images allow you to try openSUSE Leap 15.2 Beta without installing it to your hard drive. There is also a (live) Rescue image available. JeOS can be used in a virtualized (Cloud) environment and images are available for KVM, Xen, HyperV, VMWare and for the OpenStack Cloud. You can find all images for openSUSE Leap 15.2 Beta here.

Published on: 13 May 2020

the avatar of Robbi Nespu

Jekyll features - PlantUML base64 plugin (gems)

Your are a software engineer who love code? Then maybe you also love with diagrams (I said maybe!). There is lot of diagrams and we need it to capture requirement, draft code base, network topology, timeline and more. So diagram is important.

This blog is built using Jekyll and I am looking for some solution to allow me to draw diagram if needed with combination of markdown syntax, this should be possible.

I prefer to use PlantUML compare to others tools that available. It will convert my plain text to diagram. Thus plain text is useful for revision. PlantUML support lots of diagram such as sequence diagram, use case diagram, class diagram, activity diagram, component diagram, state diagram, object diagram, deployment diagram, timing diagram, gantt chart and many more.. there is existed few plugins on rubygems but this plugin need a little touch-up.

I fork "jekyll-remote-plantuml" and change a litle bits :smirk:

So because I know storing generated image into repo will make that repo grow bigger in term of size so I decide to format the image into base64 each time building jekyll website and cache downloaded image during CI/CD

It quite silly, I do some code modification to accomplish my objective. So thank you original developer of jekyll-remote-plantuml gem for awesome work.

What and why?

My plugins named as jekyll-plantuml-base64 do everything same as what jekyll-remote-plantuml do but the image will be converted into base64.

Why base64? Because I don’t need to store this image on my repository and there is a trick to cached this image during CI/CD to speed up the built process next time.

How to install ?

Option 1: To install this plugin on Jekyll, you just have to follow the guideline of Jekyll documentation

Option 2: Use rubygems, by adding gem 'jekyll-plantuml-base64', '~> 0.1.4.36' on your gemfile then bundle install

Option 3: Pull the gems directly from git by adding gem 'jekyll-remote-plantuml', '0.1.4.36', git: 'https://github.com/RobbiNespu/jekyll-remote-plantuml' on your gemfile and then bundle install

How to use ?

To use the jekyll-plantuml-base64 plugin, you just have to wrap you text between % plantuml % and % endplantuml % tags.

For example, to create a basic shema between Bob and Alice, you can write the following code

which will generated:

As you see this image created (retrieve the binary from a remote provider), stored and re-formated as base64 before displayed on you website.

Cool huh?

the avatar of openSUSE News

Community Account Migration

Dear openSUSE Community,

The authentication system behind the following services are expect to changed this month. Here is a list of services the might be affected. An email about this topic was sent out on the openSUSE Project Mailing List. More information about this topic will be updated on the Account Migration Wiki page.

Build Services https://build.opensuse.org

Bugzilla (2020-05-07 through 2020-05-10)

    [https://bugzilla.opensuse.org/](https://bugzilla.opensuse.org/) (which is the same instance as bugzilla.suse.com)

These Community Accounts (formerly known as Bugzilla Account or Novell Customer Account) are migrating from an older system supported by MicroFocus to a newer system supported and hosted by SUSE.

We are now in the process of finalizing this independence also on the technical level. The Community Accounts (a.k.a. Bugzilla Accounts) are now moving from a system provided by MicroFocus back to SUSE to the Nuremberg data center.

This action is not to be confused with an email that went out to users and contributors with an openSUSE account regarding SUSE Account Change. The old SUSE Customer tree hosted by MicroFocus is now transitioning to SUSE control.

It will however be split into two parts:

  1. SCC and Partner Net accounts

This will be established starting using a OKTA hosted login.

  1. openSUSE services including Bugzilla and OBS, but also SUSE development services.

This will be the successor account of former bugzilla account, migrated from Microfocus to SUSE. There will be the need to set a new password for this account.

Define a new password

You have two options to set a new password:

Set a password via our migration portal

   Please go to [https://idp-migrate.opensuse.org](https://idp-migrate.opensuse.org)
   Login with your old Community Account (Bugzilla credentials)
   Upon success, you will be redirected to the new IDP-Portal and have to set a new password

Password reset mail (requires a valid mail address in your account)

   If your account has a valid mail address, please go to the IDP-Portal
   From the menu, select "Password forgotten" and enter your username to request a password reset mail
   Follow the instructions in the mail to define a new password.

After that, you can manage your account via the IDP-Portal Service Migration.

The services using the Community Accounts will migrate step-by-step. This means that for some days you need to use the old and new credentials until the services are migrated.

OBS and Bugzilla are the first services to switch on May 11th.

In case of problems, please check which service is expected to be up and migrated.

the avatar of Karatek's Blog
a silhouette of a person's head and shoulders, used as a default avatar

openSUSE Tumbleweed – Review of the week 2020/19

Dear Tumbleweed users and hackers,

During this week, we managed to set a new record: the most broken Tumbleweed snapshot handed over to openQA. W whopping 9 tests out of > 220 passed, everything else failed. What a luck we have openQA, right? Nothing of that was mirrored out and sent out to users. Fur the curious ones: the issue came from an incomplete rebuild after the switch to Ruby 2.7. Still, we managed to release 6 snapshots during this week (0429, 0501, 0502, 0503, 0504 and 0506)

The major changes included:

  • GNOME 3.36.2
  • VLC 3.0.10
  • Mesa 20.0.6
  • Linux kernel 5.6.8
  • QEmu 5.0.0
  • Reverted plymouth to 0.9.5+git20190908
  • Switch to Ruby 2.7: all rubygem-* packages are now built for ruby 2.6 AND ruby 2.7. Ruby 2.7 became the detault. Unfortunately, we can’t drop Ruby 2.6 just yet (e.g. vagrant)
  • pam-config 1.3: the default pam configuration was switched from pam_cracklib to pam_pwdquality

Most of the larger things listed on Staging last week are still there:

  • MozillaFirefox 76.0
  • KDE Plasma 5.18.5
  • Linux kernel 5.6.11
  • TeXLive 2020
  • RPM change: %{_libexecdir} is being changed to /usr/libexec. This exposes quite a lot of packages that abuse %{_libexecdir} and fail to build
  • Qt 5.15.0 (currently beta4 is staged)
  • Guile 3.0.2: breaks gnutls’ test suite on i586
  • GCC 10 as the default compiler

the avatar of openSUSE News

SUSE carve out affecting openSUSE

SUSE’s partnership with EQT started last year - and now SUSE starts to separate more and more services from MicroFocus.

SUSE and openSUSE are not only cooperating and share code - often enough they also share the same services. As result, openSUSE is also affected from some of the separation work which is currently going on behind the scenes.

This weekend, the official bug tracking tool for openSUSE related issues (https://bugzilla.opensuse.org/) is one of the targets. The SUSE-IT team is migrating the service together with the bug tracking tool for SUSE to new systems in a new location. As the database has been grown over the last 25(!) years, the scheduled downtime is covering the whole weekend:

Friday (2020-05-08) until Sunday night (2020-05-10)

But there is currently more on the agenda: the identity management system, also shared between SUSE and openSUSE, needs to change as well. This IDM change will include at least also a password change request for everyone with an “openSUSE” account.

Note: there is even more coming up with this IDM change that will be covered in separate messages.

So please watch for further information provided via the usual channels:

the avatar of openSUSE News

QEMU 5, Kismet, BRLTTY Packages Update in Tumbleweed Snapshots

There have been four openSUSE Tumbleweed snapshots released so far this month and they are all trending stable at a rating of 99, according to the Tumbleweed snapshot reviewer.

QEMU had a major version update in Tumbleweed this week and a new version of the BRLTTY daemon, which provides access to the Linux console for a blind person using a refreshable braille display, also updated in Tumbleweed earlier this week.

Snapshot 202000504 brought a new version of GNOME’s photo management application Shotwell. The new Shotwell version fixed an access issue with YouTube via OAuth scope. The bootsplash package Plymouth had more than six months of updates for Tumbleweed users; there were numerous updates in this package and it added support for firmware-splashes with rotation status bit sets and added a plymouth-avoid-umount-hanging-shutdown.patch. The expressive, extensible templating engine python-Jinja2 package updated to version 2.11.2 and fixed about a handful of bugs; one of which fixed a hang when displaying tracebacks on Python 32-bit. Xfce’s window manager, xfwm4, fixed the compositor without the required X11 extensions and fixed the window decorations without XRender extension in version 4.14.2.

The lone package that arrived in snapshot 202000503 was an update for to the wireless network and device detector/sniffer Kismet to version 2020_04_R3. The release was an ultra tiny bugfix release to fix a possible crash in Kismet and associated tools when compiled with the GNU Compiler Collection instead of the Clang compiler.

The major 5.0 version of the open-source emulator QEMU arrived in snapshot 202000502. There are multiple additions and new deprecated options in features for the new emulator. One thing pointed out in the changelog is that support for using an AArch32 host system to run KVM guests is now deprecated (because the Linux kernel has dropped its support for this) and will be removed in a future version of QEMU. A small release of Mesa 20.0.6 implemented the Vulkan 1.2 and OpenGL 4.6 Application Programming Interfaces (APIs), but some drivers don’t support all the features required in OpenGL 4.6. GNOME’s 3.36.2 also came in the snapshot. The gnome-shell package brings back support for empty StIcons, which is a simple styled texture actor that displays an image from a stylesheet. GNOME’s window manager Mutter syncs timelines to hardware vsync, fixes a screencasting for non-maximized windows and preserves the keyboard state on Virtual Terminal (VT) switch. GNU Privacy Guard had a fresh update to gpg2 2.2.20; new options in the GPG version have –include-key-block and –auto-key-import to allow encrypted replies after an initial signed message. There was also an effort to protect the error counter against overflows to guarantee that the tools can’t be tricked into returning success after an error. The Linux Kernel updated to 5.6.8 and had some fixes for a few Small Computer System Interfaces as well as some enhancements for the Advanced Linux Sound Architecture. The PDF rendering library Poppler had some updates to versions 0.88.0 and a few libraries like libburn, libisofs and libstorage-ng were also updated in the snapshot.

The 202000501 snapshot started off the week and it brought a minor version of brltty 6.1. The new version had a rewrite of the whole braille display and brought four new supported braille display models including the HumanWare BrailleOne, APH Chameleon 20, APH Mantis Q40 and NLS eReader. Salt 3000.2 fixed a typo in ‘minion_runner’ for AESFuncs exposed methods and added a few patches from the initial Salt 3000 release. Python Imaging Library python-Pillow updated from version 6.2.1 to version 7.1.2 in the snapshot. The new major version fixes JPEG, PCX and TIFF decoding overflows. Added support for shooting situations Exif IFD tags were made. There is also added reading of earlier ImageMagick PNG and EXIF data in the updated image library.

the avatar of Santiago Zarate

How to import a gpg key on zypper (openSUSE)

For some odd reason, I couldn’t find quickly (2 mins in the manpage and some others on DuckDuckGo) a way to import a GPG key.

Just because one of the repos gives this ugly message:

Repository vscode does not define additional 'gpgkey=' URLs.
Warning: File 'repomd.xml' from repository 'vscode' is signed with an unknown key 'EB3E94ADBE1229CF'.

    Note: Signing data enables the recipient to verify that no modifications occurred after the data
    were signed. Accepting data with no, wrong or unknown signature can lead to a corrupted system
    and in extreme cases even to a system compromise.

    Note: File 'repomd.xml' is the repositories master index file. It ensures the integrity of the
    whole repo.

    Warning: We can't verify that no one meddled with this file, so it might not be trustworthy
    anymore! You should not continue unless you know it's safe.

I know you can use zypper ar --gpg-auto-import-keys, but I didn’t do it when I added it (and I’m too lazy to remove the repo and add it again, just to see if it works)

rpm --import https://packages.microsoft.com/keys/microsoft.asc
zypper ref

the avatar of Karatek's Blog

Introduction to OpenPGP for secure communication during COVID19 Pandemic

Introduction to OpenPGP for secure communication during COVID19 Pandemic

In this article, I will talk a bit about OpenPGP, and how to use it for secure document exchange during the COVID19-Pandemic.

What is PGP?

PGP (“Pretty Good Privacy”) is an encryption program. It has the abilitie to sign, encrypt and decrypt files. Unlike other encryption protocols, it uses asymmetric key algorithms, instead of symmetric ones. In a nutshell, this means the following: Instead of using the same password (or key) for encrypting and decrypting files, PGP uses two different ones. One Key is called the private key, This key should stay in your hands, as it says, it’s private. It is used for decrypting stuff for you, and for signing documents. People who want to encrypt a file for you or verify a signature use your public key. You can send your public key to everyone, for example you could upload it to a keyserver.

How we could use this at school

During the actual events, I am required to do home schooling. I sign every document I send of, so my teachers could verify it was me who send it. I uploaded my public key to IServ, it is loacted in the group folder gym/OpenPGP-keys.

Getting started

First install a PGP Programm. For Linux, I prefer KDE Kleopatra, although you could also use gpg’s command line interface. On Microsoft Windows, we are going to use GPG4Win.

Microsoft Windows

  1. Visit this site.
  2. Hit the download button
  3. Select “$0” and click “Download”
  4. Save the file somewhere on your hard disk.
  5. Execute the downloaded file.
  6. Select “Yes” when Windows asks whether it should execute the file.
  7. Hit “OK” and “Next”.
  8. Leave the defaults and click “Next” once again, then click “Install”.
  9. The needed tools will be installed.
  10. Hit “Next” and “Finish”.
  11. If Kleopatra doesn’t launch, start it from the start menu.
  12. Congrats! Kleopatra is now installed and configured correctly.

GNU/Linux

On Linux, installation is pretty easy. Just install Kleopatra with you package manager and you should be good to go.

Generating your very own PGP Key

Now, it’s time to generate our PGP Key pair.

  1. Start Kleopatra
  2. Select “New Keypair”
  3. Enter your name and your E-Mail Address (most likely IServ).
  4. Leave the default settings and continue.
  5. Enter a password for your private PGP key. It will be use for signing and decrypting your documents, so keep it secret!

Importing a PGP Key

So you received a public key. What’s next? You are required to import it in order to use it.

  1. Download my public key from IServ.
  2. Open Kleopatra
  3. Go to File -> import (Ctrl + I)
  4. Select the downloaded key file
  5. If it asks you to verify the key, hit “Yes”, then “Verify”.
  6. Unlock your secret PGP key by entering your password.
  7. That’s it! The key is imported.

Verifying a signature on a document

Alright, so you received a document which is signed. First of all, let’s talk about signed Open Office documents.

Signed .odx files

If you use OpenOffice or LibreOffice, verification of documents is super easy. Just open a signed document and you will see a little blue bar on top of it, saying “This document is digitally signed and the signature is valid.”. You can click on “Show Signatures”, and it will display more detailled information about the signature. A list view will appear, telling you who signed the document at what exact time.

Verifying a file with a .sig or .gpg file

Normally, you will receive a .sig (or .gpg) file and another file, for example, you recieve KW17-History-Task.pdf and KW17-History-Task.pdf.sig If you do so, follow these steps:

  1. Download both files (e.g. the .pdf and the .pdf.sig)
  2. Now use your file manager, right-click the .sig file and select “Decrypt/Verify file” on windows or Actions -> “Decrypt/Verify file” on Linux using KDE Dolphin.
  3. You should see something like this:
  4. If you see something else, the signature may be invalid.

Note: Everything that works with a .sig file also works with a .gpg file

Further reading

Sources

  • Title Picture: The KDE Community - kde.org

the avatar of YaST Team

Highlights of YaST Development Sprint 98

It’s time for another report from the YaST trenches. This time, apart from this blog post, we have several other reads for you in case you are interested on YaST development or on Linux technical details in general.

Today topics include:

  • Some considerations about the usage of YaST
  • A sneak peek at the future of AutoYaST, including a separate full blog post
  • Some kind of UI design contest for the YaST Partitioner
  • Better compatibility with LVM cache
  • Interesting researchs about combining disks and about Unicode support for VFAT in Linux
  • An impressive speedup of the partitioning proposal for SUSE Manager
  • A summary of the enhancements for YaST and related projects in Leap 15.2

And what is even better, many of those topics include a call to action for our loyal users and contributors.

Looking towards the future

Let’s start with a technical but rather significant detail. During our latest sprint we created a new SLE-15-SP2 branch in the YaST Git repositories, meaning that now the master branch is open again for more innovative features.

Git branching

This is an important milestone from the development point of view, since it marks the point in which the team acknowledges 15.2 to be basically done and manifests the intention to focus in the mid and long term future. All the previous blog posts have been focused on describing features and fixes that will be present in the upcoming SUSE Enterprise Linux 15 SP2 and openSUSE Leap 15.2. From now on, you will read more about changes that go into openSUSE Tumbleweed and Leap 15.3 (also SLE-15-SP3, of course).

Getting some insights about the usage of YaST

In order to take decisions for the future, we would like to know how often the YaST modules are used and which ones are the most important for the users. But that is not easy because YaST does not collect any data, the only feedback we get are bug reports and feature requests.

During this sprint we tried to gather some data by collecting the bug and feature numbers from the change logs. We have not yet analyzed that data but it seems the more features we implement the more bug reports we get. :smiley: See this gist for the details and feel free to suggest any other system we could use to analyze the relevance of the different YaST modules and components.

Modernizing AutoYaST

Something we know for sure is that AutoYaST is critical for many users of SUSE Linux Enterprise and openSUSE. And, to be honest, our venerable unattended installer is showing its age. That’s why AutoYaST has a priority place in the mid-term goals of the YaST Team. The plan is to have an improved AutoYaST for SLE 15 SP3 and openSUSE Leap 15.3, although some fixes could be backported to SP2 and 15.2 if they are important enough.

During this sprint, we started gathering some feedback from our users and colleagues at SUSE. Additionally, we did some research about the current status of AutoYaST in order to identify those areas that are in need of more love. We have put all the conclusions together as a separate blog post. Check it if you are interested in what the future will bring for AutoYaST.

Now that we have started a new development sprint, there is an ongoing discussion that might be interesting for you about AutoYaST tooling. Please, check yast-devel, opensuse-autoinstall, or the opensuse-factory mailing lists and do not hesitate to participate. We would love to hear from you.

Expert Partioner: Leap 15.3 and Beyond

If you are not an AutoYaST user, don’t worry. There is still other area in which your input will be greatly appreciated by the YaST team. The interface of the YaST Partitioner has reached a point in which is really hard to deal with it and we need to find a way to move forward.

The YaST Partitioner

As a first step, we have created this document that explains the problem and we hope it can be used as a base to discuss the future of the Partitioner interface.

This is a very important topic for the future of YaST. All ideas are welcome. Feel free to join the mail thread, to create pull requests for the document, to discuss the topic at the #yast IRC channel at Freenode… whatever works for you.

Recognizing LVM Cache

We also decided this was the right time to introduce some relatively big changes in libstorage-ng (the library used by YaST to manage storage devices) aimed to improve the compatibility of YaST with some advanced LVM features.

For more than a year YaST has supported to setup and use bcache to speed up rotating disks by using a SSD as a cache. But that is not the only technology that can be used for that purpose. Some users prefer to use LVM cache instead of bcache since it has been around for a longer period of time and it offers some different features.

YaST cannot be used to setup an LVM cache system and we don’t plan to make that possible. Moreover, booting from LVM cache does not work in SLE or openSUSE as of this writing. But giving the user the freedom of choice has always been important for (open)SUSE and YaST.

To help customers using LVM cache, YaST can now recognize such setup and display it properly in the Expert Partitioner and many other parts of YaST. The following warning will not be longer displayed for LVM cache volumes in openSUSE Tumbleweed.

Old pop-up for LVM cache

Instead, it will be possible to use those logical volumes normally for operations like mounting, formatting, etc. The ability to modify them will still be very restricted and it will not be possible to create new LVM cache volumes.

We plan to offer a similar limited level of support for other kind of advanced LVM volumes. Stay tuned for more news on this.

VFAT filesystem and Unicode

And talking about storage technologies, we also introduced a small change in the management of VFAT file systems for future releases of SLE and Leap (after 15.2). For some time we have wanted to stop using iocharset=utf8 in favor of utf8 when mounting a VFAT filesystem, as this is the recommendation in the kernel documentation.

There was also this bug that led to avoiding iocharset=utf8 for EFI system partitions (because iocharset=utf8implies that filenames are case-sensitive).

We took the opportunity to do some experiments and even look at the source code of the Linux kernel to find out what’s really going on. Why is utf8 so special and what can go wrong?

If you ever wondered what these VFAT charset related options mean and whether VFAT filenames are really case-insensitive in Linux as they are in Windows, have a look at this document we have created.

Although SLE-15-SP2 and openSUSE Leap 15.2 will still use the traditional mount options, the new approach (utf8 for all VFAT file systems) will land in Tumbleweed in a matter of days, as usual.

And, since we were already in research mode regarding storage technologies, why to stop there?

Mixing block sizes in multi-device devices

As a result of a recent bug in libstorage-ng which was tracked down to a RAID device block size issue the YaST team spent some time researching the topic in general.

If you’ve ever wondered what happens when you combine disks with different block sizes into a RAID, LVM, BCACHE, or BTRFS, have a look at our document.

In most cases, YaST and libstorage-ng already manage the situation well enough. But we found that in some cases we will need special handling of some situations, specially to guide our users so they don’t slip through the pitfalls. But that’s another story… for upcoming development sprints.

Faster Partitioning Proposal for SUSE Manager

Not all changes and improvements done during this sprint are targeting the mid and long term. We also had time to introduce some improvements in the upcoming SLE 15 SP2. To be precise, in the corresponding version of SUSE Manager, the SUSE’s purpose-specific distribution to manage software-defined infrastructures.

Quite some time ago, we wrote this separate blog post to introduce some special features of the partitioning Guided Setup we have developed to allow SUSE Manager (and other products) to offer the users an experience tailored to their needs.

SUSE Manager Guided Setup

But we knew some of those features in our partitioning proposal had serious performance problems that affected the initial proposal, that is, the one the installer creates before the user has had any chance of to influence the result or to select the disks to use.

The SUSE Manager version for SLE 15 SP2 will finally introduce two system roles that use the new proposal (both indentified by the “multiple disk” label), so it was finally time to address those performance problems.

And we really improved the situation! If you want to know more, this pull request contains many details and the result of some benchmarks. Let’s simply say here that in some worst-case scenarios we managed to reduced the time needed to calculate the initial proposal… from several hours to half a second!

Summarizing what Leap 15.2 will bring

As our usual readers have had many opportunities to attest, the life of a YaST developer goes much further than simply coding. And with every openSUSE Leap release it’s time for us to take a look back to several months of work and, with our salesman hat on, summarize all the cool additions to YaST and its related projects.

In that regard, we have been helping the openSUSE marketing team to shape the release announcement for openSUSE Leap 15.2. You will have to wait to read such document in all its glory, but meanwhile you can check what we have added to the “Snapper”, “YaST” and “AutoYaST” sections of the Leap 15.2 Features Page. It’s a wiki, so feel free to add any important point we could have missed.

To Infinity and Beyond

A lot of interesting topics open up in front of the YaST Team. So it’s time for us to go back to the daily work. Meanwhile, enjoy all the reads and don’t hesitate to get involved taking part in the converstions, improving the wiki pages or in any other way.

Have a lot of fun!