New KDE Frameworks, Python Setuptools, Emacs Update in Tumbleweed Snapshots

Four openSUSE Tumbleweed snapshot were released this week providing a Linux Kernel, KDE Frameworks, and python-setuptools to give developers plenty of new upstream packages.

The more recent Tumbleweed snapshot 20190423, provided new cups-filters 1.22.5 that changed a Ghostscript call so that fixes the page count so that it works with Ghostscript 9.27 and later. AV1 decoder package dav1d 0.2.2 brings a speed increase between four and six percent for Multi Slot Amplitude Coding (MSAC) decoding with SSE. The kernel-firmware package was updated to 20190409 and updated the firmware file for Intel Bluetooth and Marvell firmware images. Indonesian translations were made to the libstorage-ng 4.1.112 package. Ruby 2.6.3 updated the Unicode version to 12.1 beta to adds support for New Japanese Era “令和” (Reiwa). Other packages updated in the snapshot were perl-DateTime 1.51 and perl-DateTime-TimeZone 2.35, python-parso 0.4.0, python-qt5 5.12.1 and rdma-core 23.0. This snapshot is currently trending at a 89 rating, according to the Tumbleweed snapshot reviewer.

Mesa 19.0.2 had a few fixes for radeon, radv and v3d in the 20190420 snapshot. A few other packages were updated in the snapshot like kipi-plugins 5.9.1, which was the first official stand-alone release outside of digikam. This snapshot is currently trending at a 97 rating, according to the Tumbleweed snapshot reviewer.

KDE contributors offered up plenty of fixes and addon libraries to Qt with the update to  Frameworks 5.57.0 in snapshot 20190419. KDE’s lightweight user interface framework for mobile and convergent applications called Kirigami had the most updates along with KIO and the file management functions it provides to Konqi users. Another package for developers/makers that arrived in the snapshot was python-setuptools 41.0.0; the package removes support for specifying an encoding using a ‘coding: ‘directive in the header of the file. When parsing setup.cfg files, setuptools now requires the files to be encoded as UTF-8. The java-11-openjdk updated to added test cases for lenient Japanese era parsing and pushed several security fixes. This snapshot posted a stable rating of 97 on the Tumbleweed snapshot reviewer.


LibreOffice, php, GTK Packages Updated in Tumbleweed

Three openSUSE Tumbleweed snapshots were released this week.

The three snapshots delivered new versions of php7, poppler, gtk3 and LibreOffice. The first snapshot of the week completed all the package upgrades for KDE Applications, which began showing up in last week’s snapshots.

The most recent snapshot, 20190126, brought libreoffice, which added a patch to build with java-11.2; the new version also includes a patch submitted last week that has the basic rendering of organizational charts with LibreOffice’s SmartArt objects. There were plenty of security fixes made with java-11-openjdk to include improved JPEG processing and web server connections. The jump from btrfsprogs 4.19.1 to 4.20.1 brought a new metadata Universally Unique Identifier (UUID) feature and a lightweight change of the UUID without rewriting all metadata became available in the newest version. There was a fix for GVariant tests on the P6 microarchitecture i686 with the update of glib2 2.58.3. The newest version of gnome-builder, 3.30.3, now uses –frame and –thread with the GNU Project debugger. Widget toolkit gtk3 3.24.4 had a few fixes for Wayland and updated translations. GNOME’s mobile-broadband-provider-info package was updated after almost two-years to the 20190116 version; the package provides mobile broadband settings for various service provider and a prepaid feature for Iliad telecommunications in Italy help trigger the updated version. Several bug fixes were made with the php7 7.3.1, which included a timevalue change for the curl_getinfo transfer. Significant changes were made in both poppler and poppler-qt5 0.72.0 to avoid cycles in PDF parsing and memory leak, respectively. Other packages updated in the snapshot worth noting were snapper  0.8.2, wicked and YaST.

Snapshot 20190125 only brought a handful of updated packages. The email, contacts and calendar server package cyrus-imapd  2.4.20 provided a fix for crash and a fix for a configured socket path is too long for its buffer. The package without a description, python-xcffib 0.6.0, was updated. The qpdf  8.3.0 and yast2-schema 4.1.1 packages were updated in the snapshot. Attackers can be thwarted with the upgrade of distributed messaging package zeromq 4.3.1.

Snapshot 20190124 completed all the package upgrades for KDE’s Applications 18.12.1, which offers about 20 bug fixes. Tumbleweed started the week with an upgrade of the Linux Kernel to 4.20.2. Indonesian and Spanish translations were updated with the libstorage-ng 4.1.78 update. The package for tracking mission-critical IT infrastructure, nagios 4.4.3, had more than a dozen fixes with one of those fixing a make error when building on the aarch64 architecture. The lightweight Music Player pragha 1.3.99 added a new visualizer plugin and remote desktop client remmina 1.3.0 added language detection and removed deprecated floating toolbar. A long list of changes were made with python-kiwi 9.17.1 package and yast2 packages had several changes for the network, firewall and apparmor packages.

Snapshot 20190124 recorded an unstable rating of 70, according to the Tumbleweed snapshot reviewer. Snapshot 20190125 is trending as moderately stable with a rating of 77 and snapshot 20190126 is trending as stable with a current rating of 88.

Tumbleweed Rolls with Package Updates of Git, Virtualbox, OpenSSH

openSUSE’s rolling release Tumbleweed had a total of five snapshots this week and is preparing for an update to the KDE Plasma 5.14.4 packages in forthcoming snapshots.

The five Tumbleweed snapshots this week brought the 5.19.5 Linux Kernel, which was the only package updated in the 20181130 snapshot. The kernel-source 4.19.5 package added a force option for the pciserial device for x86 architecture and fixed HiperSockets sniffer for s390 architecture.

The most recently released snapshot, 20181204, had more than a dozen packages updated. GNOME’s application for manage their Flickr image hosting accounts, frogr 1.5, fixed issues with the content and installation of the AppData file and moved the functionality menu. GNOME’s goffice had a version bump to 0.10.44. Various rubygem packages were updated and the most significant change was of the packages was that rubygem-pry 0.12.2 dropped support for Rubinius. Both python-boto3 1.9.57 and python-botocore 1.12.57 had multiple application programming interface (API) changes. The obs-service-set_version 0.5.11 package needed “python suff” and now allow running tests with python3.

The first snapshot to arrive in December was snapshot 20181203. Among the package changes were an update to checkmedia 4.1, which fixed digest calculation in tagmedia, GNOME’s framework for media discovery grilo 0.3.7, and distributed compiler icecream 1.2, which made load calculations better and also cleaned up the general code. A python-docutils build dependency was added with cifs-utils 6.8 and elfutils 0.175 fixed three Common Vulnerabilities and Exposures issues. Major changes came with the man 2.8.4 package. One of the changes relies on decompressors reading from their standard input rather than redundantly passing them the input file on their command line; this works better with downstream AppArmor confinement of decompressors. Virtualbox 5.2.22 fixed a regression in the Core Audio backend causing a hang when returning from host sleep when processing input buffers and webkit2gtk3 2.22.4 fixed serval crashes and rendering issues and Fix a crash when using graphics library Cairo versions between 1.15 and 1.16.0.


Thunderbird, YaST, Sudo Updates Arrive in Tumbleweed

Three openSUSE Tumbleweed snapshots were released since the last blog.

The three Tumbleweed snapshots this week brought a newer Linux Kernel, several rubygem package updates and improvements for an Xfce support library.

Snapshot 20181126 brought the 4.19.4 Linux Kernel, which fixed accelerated VLAN handling and fixed a memory leak with the Nouveau secure boot. Yet another Setup Tool (YaST) had some updates with yast2-fonts 4.0.2 that changes the desktop file fonts to system-wide fonts and multiple translations were also updated with the yast2-trans package. The support library for Xfce desktop environment, exo, updated to version 0.12.3; it improved layout spacing and alignment and hides the exo launchers from GNOME Software. The package for Integrated Development Environment cross-platform, kdevelop5 5.3.0, brought improved language support for php, python and c++; it also offers a new clazy analyzer plugin. Multiple other libraries were updated including libjansson 2.11, libsemanage 2.8, libsepol 2.8, libzypp 17.9.0 and more. Several rubygem packages were updated in the snapshot and rubygem-bundler 1.17.1 had a significant amount of additions and improvements including an add config option to disable platform warnings. The mailutils 3.5 package for the handling of email fixed a bug in the base64 encoder. Parser generator bison 3.2.2 brought massive improvements to the deterministic C++ skeleton, lalr1.cc and the library for manipulation of TIFF images, tiff 4.0.10, added a few patches that address the 10 Common Vulnerabilities and Exposures (CVE) patches that were removed.

Eight packages were updated in the 20181122 snapshot; three of them were YaST associated packages like yast2-ntp-client 4.1.6, which aligned a  “Synchronize Now” button and “NTP Server Address” box, which doesn’t break the previous fix and does not hide the manual checkbox in TextMode. The fourth release candidate of the free implementation of the Remote Desktop Protocol (RDP) freerdp 2.0.0,  added support to set the Transport Layer Security (TLS) security level for openssl 1.1.0 and also added smartcard support for substring filters. Sudo now treats the LOGNAME and USER environment variables (as well as the LOGIN variable on AIX) as a single unit with the update to sudo 1.8.26, which also added support for the OpenLDAP TLS_REQCERT setting in the ldap.conf. The xapian-core 1.4.9 package fixed a bug to efficiently handle insertion of a batch of extra positions in ascending order, which could lead to missing positions and corrupted encoded positional data, according to the changelog.


Tumbleweed Gets Plasma 5.14, Frameworks 5.50

Four openSUSE Tumbleweed snapshots this week brought new versions of software along with new versions of KDE’s Plasma and Frameworks as well as python-setuptools and many other packages.

The most recent snapshot, 20181009, updated KDE’s Plasma 5.14. The new Plasma version has several new features like the new Display Configuration widget for screen management, which is useful for presentations. The Audio Volume widget has a built in speaker test feature moved from Phonon settings and the Network widget now works for SSH VPN tunnels again. The Global menu now supports GTK applications as well.  Mozilla Firefox 62.0.3 fixed a few Common Vulnerabilities and Exposures including a vulnerability in register allocation of JavaScript that can lead to type confusion, which allows for an arbitrary read and write. The cpupower package, which is a collection of tools to examine and tune power, was updated to version 4.19 and deleted some patches that are now part of the mainline. Source-control-management system mercurial 4.7.2 fixed a potential out-of-bounds read in manifest parsing C code. Other packages including in the snapshot were inxi 3.0.26, lftp 4.8.4, libinput 1.12.1, okteta 0.25.4 and vm-install 0.10.04

Snapshot 20181004 included several package updates as well. NetworkManager-openvpn 1.8.6 fixed an endless loop checking for encrypted certificate. The open source antivirus engine clamav 0.100.2 disabled the opt-in minor feature of OnAccess scanning on Linux systems and will  re-enabled in a future release. Users who enabled the feature in clamd.conf will see a warning informing them that the feature is not active. The Linux Kernel was updated to 4.18.11 and had several fixes for Ext4. Developers using python-setuptools 40.4.3 will see a few changes from the previous 40.2.0 version that was in Tumbleweed like the vendored pyparsing in pkg_resources to 2.2.1. Those using Samba will see a fix  for cluster CTDB configuration with the 4.9.1 version. Caching proxy squid  4.3 updated systemd dependencies in squid.service and vlc 3.0.4  improve support for broken HEVC inside MKV.

Firefox was updated earlier in the week to 62.0.2 in snapshot 20181002. The rest of KDE Frameworks 5.50.0 was made available in the snapshot; most of the packages for Frameworks were updated in the snapshot the previous day. The systems library for input/output KIO and the KTextEditor had the most changes in the updated Frameworks. Multimedia frameworks gstreamer along with its several gstreamer plugins were updated to version 1.14.3 and it fixed major buffer leak with the compositor. Some libqt5 packages were updated to version 5.11.2, but most of the libqt5 packages were release in snapshot 20181001. Mariadb 10.2.18 cleans up some code and now Supports DDL commands during backup. (more…)

VIM, Xen, Git Packages Updated in This Week’s Tumbleweed Snapshots

There were a total of four openSUSE Tumbleweed snapshots this week that updated packages like VIM, Xen, Git and ImageMagick.

The latest snapshot, 20180925, updated three packages. All the packages updated in this snapshot were zero dot packages. The updated packages were obs-service-set_version 0.5.10, purple-carbons 0.1.6 and shotwell 0.30.0. The obs-service-set_version 0.5.10 version fixed a zip file crash associated with python. The version change regarding purple-carbons 0.1.6 was basically cleaning up the code. The shotwell 0.30.0 package updated translations and fixed random segfaults in GNOME settings.

The 20180924 snapshot updated a little more than a handful of packages. Among the package updates were hdf5’s jump from version 1.10.1 to 1.10.3. The HDF5 package is a high performance data software library and file format to manage, process, and store heterogeneous data. The version added a few patches and had an upstream fix that dropped a warning patch. The text-mode web browser links 2.17 package had multiple changes. Among some of the most important fixes for the package was verifying SSL certificates for numeric IPv6 addresses and fixing an infinite loop that happened in graphics mode if the user clicked on OK in the “Miscellaneous options” dialog when more than one window was open. The nano 3.1 version fixed a fix a misbinding of ^H that had an effect with some terminals on certain systems. Three rubygem packages were also updated in the snapshot. The packages were rubygem-marcel 0.3.3, rubygem-sass 3.6.0 and rubygem-uglifier 4.1.19.

The Tumbleweed snapshot that had the most packages updated in the week was snapshot 20180920. Roughly 17 packages were updated in this snapshot. ImageMagick added support for a “module” security policy and disabled PDF coders in default policy.xml. The GNOME library gtksourceview 3.24.9 improved the syntax highlighting of Haskell, C++, GLSL, and Markdown. Text editor vim 8.1.0401 refreshed a patch that is still working through some various issues. The newer version update of pciutils 3.6.2 fixed a couple of bugs in computation of bus topology.


Tumbleweed Snapshots Bring Changes for KVM, QEMU, Xen

Two openSUSE Tumbleweed snapshots were once again released this past week, which included two Linux Kernel updates.

The most recent snapshot, 20180818, updated the kernel to version 4.18.0, which brought many changes for KVM (Kernel-based Virtual Machine). Mozilla Firefox 61.0.2 improved website rendering with the Retained Display List feature enabled and also fixed broken DevTools panels. The ffmpeg 4.0.2 package in the snapshot added conditional package configuration and AOMedia Video 1 (AV1) support. Netfilter project nftables was restored as the default backend with firewalld 0.6.1 and now nftables and iptables can co-exist after a bug fix with the ‘nat’ table form the 4.18 kernel. The Command Line Interface configuration utility for wireless devices known as iw added support in its 4.14 for all new kernel features of kernel 4.14. The HTTP client/server library for GNOME, libsoup 2.62.3, now uses an atomic-refcounting in classes that are not using GObject-refcounting. The Linux Kernel 4.16 or higher is needed for the strace 4.24 package, which implemented decoding of KVM vcpu (virtual central processing unit) exit reason as an option, and yast2-http-server 4.1.1 fixed PHP support by dropping php5 and using php7.

The 20180815 Tumbleweed snapshot had the last 4.17 kernel with an update from Kernel 4.17.3 to 4.17.4. The new version of ImageMagick has the XBM coder leave the hex image data uninitialized if hex value of the pixel is negative. Several fixes were made with btrfsprogs 4.17.1 and an add ability to fix wrong ram_bytes for compressed inline files was also made with the package update in the snapshot. The advanced twin panel file manager for KDE Plasma, krusader 2.7.1, had a few fixes including a fix to the search bar in the application that showed results for a file that was deleted. The qemu 2.12.1 package dropped several patches and the updated gave new mitigation functionality for CVE-2018-3639. Caching proxy squid 4.2 provided fixes for GNU Compiler Collection 8 and a missing pointer. There were also several patches in the xen 4.11.0 update for GCC 8 and the yast2-storage-ng 4.1.4 update addressed the partitioner and now displays Xen virtual partitions and allows users to format and mount them.

Snapshot 20180815 recorded a stable rating of 93 on the snapshot reviewer and 20180818 is currently trending a moderate rating of 86.

Language, Networking Packages Get Updates in Tumbleweed

There were two openSUSE Tumbleweed snapshots this past week that mostly focused on language and network packages.

The Linux Kernel also received an update a couple days ago to version 4.17.13.

The packages in the 20180812 Tumbleweed snapshot brought fixes in NetworkManager-applet 1.8.16, which also modernized the package for GTK 3 use in preparations for GTK 4. The free remote desktop protocol client had its third release candidate for freerdp 2.0.0 where it improved automatic reconnects, added Wave2 support and fixed automount issues. More network device card IDs for the Intel 9000 series were added in kernel  4.17.13. A jump from libstorage-ng 4.1.0 to version 4.1.10 brought several translations and added unit test for probing xen xvd devices. Two Common Vulnerabilities and Exposures fixes were made with the update in postgresql 10.5. Several rubygem packages were updated to versions 5.2.1 including rubygem-rails 5.2.1, which makes the master.key file read-only for the owner upon generation on POSIX-compliant systems. Processing XML and HTML with python-lxml 4.2.4 should have fewer crashes thanks to a fix of sporadic crashes during garbage collection when parse-time schema validation is used and the parser participates in a reference cycle. Several YaST packages receive updates including a new ServiceWidget to manage the service status with yast2-ftp-server 4.1.3 as well with yast2-http-server, yast2-slp-server and yast2-squid 4.1.0 versions.

The snapshot from 20180808 brought the firewalld 0.6.0 version, which switched back to an ‘iptables’ backend as a default; “loads of new services” were added in the newer version including the addition of firewall-config adding a ipv6-icmp to the protocol dropdown box. The Linux Filesystem in Userspace interface, fuse 2.9.8, provided security update for systems where SELinux is active. The security update stops an unprivileged users to specify the allow_other option even when it was forbidden in the /etc/fuse.conf. The snapshot also updated yast2-network 4.1.5 that fixes the networking AutoYaST schema

Snapshot 20180808 recorded a stable rating of 95 on the snapshot reviewer and 20180812 is trending at a 96 rating.

Tumbleweed Gets New Mesa, KDE Frameworks, GNOME Packages

A total of four openSUSE Tumbleweed snapshots were released this week that brought new updates for the Linux Kernel, Mesa and a major version update of libglvnd.

RADV received several fixes in snapshot 20180424 with the update to Mesa 18.0.1. Mesa core also had some patches to fix issues around overriding the OpenGL/ES supported version through environment variables, and a patch to fix an issue with texture samples found in “The Witness” through Wine. An updated description for the SSLProtocol option was made available with the apache2 2.4.33 package and apparmor 2.13 delivered a change of the (writeable) cache directory to /var/cache/apparmor/ with the new btrfs layout. The reason for using /var/lib/apparmor/cache/, which was “it’s part of the / subvolume”, is gone, and /var/cache makes more sense for the cache, according to the changelog. The cleanup process and behavior are a lot better with the update of ccache 3.4.2. Backup tool deja-dup 38.0 was a major update and exclude snap cache directories by default. GTK has a new ‘Widgetbowl‘ demo and the wayland backend now supports the stable xdg-shell protocol in gtk3 3.22.30. Linux Kernel 4.16.3 arrived in the snapshot and the GL Vendor-Neutral Dispatch library, libglvnd, was bumped to major version 1.0.0 thanks to EGL and GLX interfaces being defined and stable. The Tumbleweed rating tool is currently treading the snapshot as stable with an 88 rating.

Snapshot 20180420 is also treading at an 88 rating. The snapshot added btrfsprogs 4.16, which added the new LGPL library libbtrfsutil packages to wrap userspace functionality. KDE users will notice new features for the kmediaplayer package with Frameworks 5.45.0. Poppler 0.63.0, which is the utility library for rendering PDFs, had multiple fixes to include a fix for a new Object Application Programming Interface porting bug. The autocompletion and static analysis library for python, python-jedi 0.12.0, removes Python 2.6 support and provides better namespace completion.


Krita, Linux Kernel, KDEConnect Get Updated in Tumbleweed

There have been a few openSUSE Tumbleweed snapshots released in the past two weeks that brought some new features and fixes to users.

This blog will go over the past two snapshots.

The last snapshot, 20180416, had several packages updated. The adobe-sourceserifpro-fonts package updated to version 2.000; with the change, the fonts were refined to make the Semibold and Bold heavier. Both dbus-1 and dbus-1-x11 were updated to 1.12.6, which fixed some regreations introduced in version 1.10.18 and 1.11.0. The gtk-vnc 0.7.2 package deprecated the manual python2 binding, which will be deleted in the next release, in favor of GObject introspection. Notifications that caused a crash were fixed in kdeconnect-kde 1.3.0. The 4.16.2 Linux Kernel made ip_tunnel, ipv6, ip6_gre, ip6_tunnel and vti6 better to validate user provided tunnel names. Due to a build system failure, not all 4.16.2 binaries were built correctly; this will be resolved in the 20180417 snapshot, which will be released shortly. Krita 4.0.1 had multiple fixes from its major version upgrade. The visual diff and merge tool meld 3.19.0 added new features like a new per-pane status bar with selectors for syntax highlighting and text encoding. Python Imaging Library python-Pillow 5.1.0 removed the freetype-2.9.patch and YaST had several packages with a version bump.

Snapshot 20180410 had less than a handful of packages updated. The Advanced Linux Sound Architecture package, alsa ,1.1.6 removed unused macros and added support for python3 and alsa-utils 1.1.6 removed some obsolete patches. GNU Compiler Collection 7 enabled a fix for aarch64 and the communication package rzsz had rebase patches with its release candidate in the 0.12.21 version.

The Tumbleweed rating tool is currently trending the past few snapshots as unstable, but the last snapshots rating is posting a false negative due to comments made on the openSUSE Factory Mailing thread about the 4.16.2 Linux Kernel.