KDE Plasma: KWin embraces OpenGL ES, fluid animations arrive, and a critical vulnerability is patched

Key points:
  • KWin will exclusively use the OpenGL ES API to avoid graphics compatibility issues.
  • Smoother and more realistic animations will be implemented for the appearance of notifications and the mouse cursor loading icon.
  • The upcoming version 6.8 will update its emoji picker to the Unicode 17 standard and remove problematic clipboard keyboard shortcuts.
  • Updates 6.7.2 and 6.7.3 fix KWin crashes when using VRR and reduce abnormal CPU consumption on Intel systems.
  • A sandbox escape vulnerability has been identified in malicious Flatpak packages exploiting the "Open new window" function.

KDE Plasma 6.7 final release

The development team of KDE has published its weekly report detailing the latest developments in their desktop environment. While the Current branches receive stabilization patchesThe community's eyes are already on the upcoming KDE Plasma 6.8 version, whose release is scheduled for October 14.

This next release promises not only much-requested aesthetic improvements, but also profound changes under the hood that will optimize graphics performance and the way the system handles data input.

KWin's graphical transition and visual improvements in Plasma 6.8

Without a doubt, one of the most important changes for version 6.8 It directly affects the visual heart of the desktop: the composition manager Kwin. Developers They have made the decision to abandon the use of the OpenGL desktop graphics API. standard for exclusively use OpenGL ES.

This variant, although initially designed for embedded and mobile systems, has proven to be more than enough to cover all of KWin's rendering needs. main reason of this transition is eliminate the constant problems of code incompatibility and fragmentation, By unifying development under a single internal API (while Vulkan support matures), the strange visual glitches that occurred when code optimized for one version clashed with another will be eliminated. Along with this improvement, KWin will also launch support for version 1.6 of the Emulated Input (libei) library, a vital component for managing data input in modern Wayland sessions.

In addition, the developers emphasize that KDE Plasma 6.8 will be a delight in terms of visuals and usability, since the The system's animations have undergone a thorough review to feel more natural.The classic notification that slides across the screen now uses a mathematically smoothed curve that mimics real-world acceleration and deceleration, and the iconic bouncing cursor that indicates an app is loading has been rewritten with a better physics model and a higher frame rate.

Thinking about productivity, The undocumented keyboard shortcut has finally been removed. (Meta+Ctrl+x) that activated clipboard actionsbecause its similarity to the classic cut button combination caused many users to press it accidentally. Furthermore, the The selection of emojis will be up to date by integrating version 17 of the Unicode standard. And clear options have been added to the settings menu to control the alternate character dialog box that appears when you hold down a key.

Stabilization for version 6.7 and a security alert

While we await the October version, the current editions haven't lagged behind. The recent 6.7.2 update focused on stabilizing the use of multiple monitors., fixing unexpected KWin shutdowns when using adaptive refresh rates (VRR) and correcting a bug that affected the performance of full-screen Chromium-based applications.

For its part, the Version 6.7.3 will bring relief to Intel processor userssince cIt corrects an annoying technical regression that increased CPU consumption when using atomic video mode. This same update will make the KRunner search engine consume fewer resources by allowing ultra-short, two-letter searches, and will disable the Kameleon service by default after it was discovered to negatively interfere with keyboard backlighting.

Finally, The report highlights a critical vulnerability affecting the "Open new window" function. from the task manager. The problem is that, to run a new instance of an application, the system directly reads the contents of the internal process file. Since a malicious application encapsulated in Flatpak format has the ability to modify this value, an attacker could trick KDE into executing arbitrary commands outside its sandbox environment if the user clicks "Open new window".

Although this security flaw was reported to developers in April, at the time of writing this report, the fix is ​​still under development and review, so a mitigation patch has been included in the 6.6.6 branch to harden the way the task manager reads application files.


Add as preferred source in Google