Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Matthias Klumpp

@matk@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

Neuroscience PhD by day, free software developer by night. Debian Developer, KDE and GNOME member; working at @purism@social.librem.one

Opinions are my own.

607 Followers
175 Following
28 Posts
Joined October 17, 2018
Blog:
https://blog.tenstral.net
GitHub:
https://github.com/ximion
Open post
Matthias Klumpp @matk@mastodon.social
· 1mo ago

Good things are happening to AppStream, PackageKit & Freedesktop - I will be busy 😉

=> https://blog.tenstral.net/2026/08/sovereign-tech-fellowship-for-freedesktop-tasks.html

blog.tenstral.net
23
0
7
0
Open post
Matthias Klumpp @matk@mastodon.social
· 1mo ago

#Debian Developers can now view the AppStream metadata that their packages have produced, and any issues that occurred using a much better web interface: https://appstream.debian.org/sid/

All part of the just-released appstream-generator 1.0.0
(you may want to enable JPEG-XL in your browser to view pages for anything newer than trixie (13) 😉 - blogpost about that soon!)

mastodon.social

Mastodon

5
1
7
0
Open post
Matthias Klumpp @matk@mastodon.social
· 5mo ago

It took 11 years, but @razze@osna.social and I managed to create a folder on Linux...

https://blog.tenstral.net/2026/04/hello-projects-directory.html

#freedesktop

blog.tenstral.net
44
10
27
0
Open post
Matthias Klumpp @matk@mastodon.social
· 1mo ago

My brain after spending far too long debugging whitespace-related issues and space-sanitizing AppStream description markup...

https://www.youtube.com/watch?v=xkfsybBhueM

The good thing: The solution *sped up* markup parsing in the end, because it made subsequent steps handle less data :-)
AppStream 1.2.0 will make sure description markup is safe to render, and make markup far more deterministic, which will help software centers.

2
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 4mo ago

I just made the first release of the now open-sourced LibWinpos today!
This #Qt library allows clients to set window positions on Mac/Windows/X11 and Wayland. It works for the latter if the #Wayland compositor implements the experimental `xx-zones` protocol or the kwin-zones plugin is used on #KWin.

The lib provides a single API for all platforms, graceful fallbacks, and is used in one internal proprietary project, as well as in one FOSS project now.

Find it at:
https://github.com/ximion/libwinpos

mastodon.social
5
1
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 5mo ago

I genuinely never received so many security vulnerability reports across multiple projects in such a short time. They usually are a very rare event. All of them were found with AI, with reports written by humans. All of them are valid so far. Damn. Lots of work to do!

6
0
1
0
Open post
Matthias Klumpp @matk@mastodon.social
· 7mo ago
Replying to
I fixed it by adding some heuristics to libappstream to explicitly quote something we know should be a string if it starts with a digit/punctuation (for performance reasons). I would just like to simply quote every string and be done with it (it's also more JSON-like). But keeping the more minimal style instead of changing how the emitted AppStream YAML looks like (breaking tests) was the better, more conservative fix. - For now.
9
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 7mo ago
Replying to
...so, therefore, huge shoutout to MSYS2 which was my salvation in so many ways! Automating Windows builds was really easy, and for the actual build steps I could even use a familiar UNIX-y environment, while still getting a fully native Windows binary out. Not sure why I didn't use this sooner for past projects! Of course, the Linux builds of the same app were up and running in seconds, thanks to distro packages and great CI 😉 2/2 https://www.msys2.org/
msys2.org
6
3
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 8mo ago
Replying to

The protocol is still experimental, so no client should expect it to be present in a compositor (and there are for certain compositors which will never have it).

Also, the xx-zones protocol now only addresses xy-positioning, the z-positioning was spun out into xdg-toplevel-groups1 prior to the merge and may get wider support.

In any case, all of this is positive news for complex professional or multiwindow apps on Linux/Wayland! 2/2

gitlab.freedesktop.org
6
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 5mo ago

Just had to switch another system at a research lab from Plasma Wayland to X11 for the customers - the reason? Remote desktop and multi-window positioning. #RustDesk did not work on that network, and they were using #AnyDesk with Windows machines anyway, which has no Wayland support.

And they were very annoyed that scientific apps did not position windows at the usual spots and predictably.

Really not a good impression, and a pretty bad migration experience still 😕

mastodon.social
3
2
1
0
Open post
Matthias Klumpp @matk@mastodon.social
· 5mo ago

Forgot your root password? No problem! With #PackageKit <= 1.3.4 you can do all the fun root action on any Linux system you have local access to, no privileges required!

Don't like that? Then PLEASE UPDATE your system ASAP to PackageKit >= 1.3.5 or any fixed distro package. Fixes for this vulnerability should already be available everywhere since today.

You can read more about CVE-2026-41651 on the security researcher's blog:
https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html

#pack2theroot #osssecurity

mastodon.social
3
1
3
0
Open post
Matthias Klumpp @matk@mastodon.social
· 6mo ago

I tried this AI thing - it very helpfully found a bug in my code and suggested a fix...

It is a damn helpful tool sometimes, but it really feels so strange to me when people say the machines are "understanding" or "thinking". They aren't (yet...). Humans just gained a new tool to help them problem-solve, but they will still have to do that work, instead of giving up control to the statistics machine.

3
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 3mo ago

I'm rather late writing about a feature released a while ago, but a lot of people didn't know about `pkgcli` yet, and why i exists. So, enjoy this short introduction to a modern #PackageKit command-line frontend! 😁

https://blog.tenstral.net/2026/06/introducing-pkgcli-a-nicer-command-line-interface-for-packagekit.html

mastodon.social
1
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 5mo ago
Replying to
@deobald@fantastic.earth @razze@osna.social I use "Development" for that... Quite possible sources will stay there, and I might throw all the other random stuff into "Projects" (already moved Kdenlive editing projects and EAGLE & KiCad CAD stuff into there ^^)
2
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 7mo ago
Replying to
@deobald ...it instead is a structured database for installations, so instead of "copy this file now", MSI says "this file belongs to this component, which satisfies this feature" - and the engine then decides when and how to act. Just renaming a file is hell unless you preplanned that, and MSI pushes a crazy amount of mental load onto the developer, instead of figuring things out by itself. Without WiX it would be insanity, but even with it it's awful to use...
3
1
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 4mo ago

#Syntalos 3.0.0 is out, for all of your scientific data acquisition needs!
This version drops Qt from all public interfaces (allowing wider use of its API), has a rewritten Python interface, rewritten IPC (using #iceoryx2), support for more scientific hardware, and a new network interface to manage a fleet of machines running one experiment.

This release has breaking changes, existing projects may need adjustments!

Get it at: https://syntalos.org/
Changes: https://syntalos.org/get/changes/

mastodon.social
1
1
1
0
Open post
Matthias Klumpp @matk@mastodon.social
· 7mo ago
Replying to
@deobald I would honestly argue that MSI features like its repair/self healing and its component model to share elements between "products" aren't even desirable in modern corporate environments. If something breaks, you don't want to repair, you just reinstall/redeploy. Tons of state is bad. Most apps aren't exposing interfaces to others and bundle things, so no need for sharing. And it's too easy to break upgrades. So, unless required, I wouldn't use MSI 😅
2
1
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 5mo ago
Replying to
@pid_eins @swick This!!! It's not just essential for security, but also dramatically increases robustness of the resulting application - I ran into the latter just last week (debugging data loss for a non-security-relevant app). Even though I know about all of this, I still use the POSIX-like interfaces a lot because they're default in many languages and readily available and "it's not security relevant anyway". Until it is. Better defaults would be so nice!
1
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 5mo ago
Replying to
@aspragg@ohai.social It's general behavior for all of those directories. If they appear again, some other application may have recreated them - but XDG-compliant apps should not do that, and instead rely on the right env vars and configuration to pick the correct location (which does not involve recreating the directory).
1
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 7mo ago
Replying to
@x9c4 Some design decisions of YAML were pretty atrocious, fortunately YAML 1.2 fixed most of them, and with libfyaml AppStream now uses a library that can parse & emit YAML 1.2 properly.
1
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 7mo ago
Replying to
@deobald I bet the engineers who made the Windows Registry wished they had implemented some kind of ownership semantic into it, instead of making it a place to store random data from who-knows-where 😅 At least on Linux, apps were always restricted to only write into some locations (with $HOME being the wild-west of data littering, but not the entire filesystem at least :-P )
1
0
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 7mo ago
Replying to
@deobald It is kind of insane from a Linux engineer's perspective, especially in 2026. But MSI was created in 1999 for Windows, which doesn't have the strict(-ish) filesystem layout UNIX has, where software was shipped on CDs, computers were slower with expensive disk space, and in an environment where Microsoft had already invented the Windows Registry. So I guess it made sense back then... I'm glad we didn't accidentally create something like this for Linux 😅
1
1
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 7mo ago
Replying to
@herzenschein That's basically what I ended up with for my Qt app (just with InnoSetup instead of NSIS since the former had a nice GitHub Action). Using MSI was strongly discouraged by everyone, and I now know why ^^ Definitely kudos to the people maintaining MSYS2 and its packages, it is a great piece of software 🙂
1
1
0
0
Open post
Matthias Klumpp @matk@mastodon.social
· 8mo ago

@drakulix@social.dreampi.es Hey! Can I find you at FOSDEM today somewhere? 😁

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:03:48 UTC