Showing posts with label GNU. Show all posts
Showing posts with label GNU. Show all posts

Saturday, October 12, 2024

Distrohopping on Librem5

 In continuation to my previous blog-post expressing my excitement/happiness at receiving the librem5, being a distro-hopper (maniacal) in the beginning times of my GNU/Linux journey, I couldnt hold myself. So went ahead prepared an SD card and installed my first distro of choice, Debian GNU/Linux on the librem5. However, the experience was anticlimactic. The stable version did not boot and the weeklies just gave me a "glimpse" of the mobian logo. Yes, there are other methods like "jumpstart", but, I do not want to go that route. I want my librem5 as pristine as possible. It is already running GNU/Linux and lots and lots of users and devs are putting continuous efforts to have the latest and greatest on the device. For now, I will stay with installing alternate GNU/Linux on the SD card. 

Since Mobian GNU/Linux did not boot successfully, I went towards the next effort, Postmarket OS. I am just amazed by the amount of effort put by this team and the long distance which they have already traveled. The tools developed by the team are beautifully documented. It was a joy to go through the documentation. It is like they want every individual to be able to boot Postmarket OS and they want it to do the heavy lifting themselves absolving the user from the initial resistance to free their phones. Kudos to the team and all the users. I just went to the Postmarket page for librem5 and blindly followed the procedure to get PMos on the SD card. It was so straight forward, I just remembered the first book I had bought to learn Redhat Linux 6, my first GNU/Linux installation. GNU/Linux has come a long way and the tools developed by the devs, just for the passion, is unbelievable. In the initial install, I chose the --fde(Full disc encryption) option. However, the device repeatedly asked for the passphrase. I changed the passphrase on the installation (Again thanks to the use-case already available and documented). Now,  PMos went past the passphrase window and stayed at the boot screen. Waited for half an hour, then powered the phone off. By this time, I would have removed and re-inserted by SD card not less than 10 - 20 times. The sim/sd card tray is very flimsy. Be very careful while handling it. Dont worry, I have very nimble hands.

I am a seasoned distro-hopper. I dont give in that easy. On the next day, I flashed PMos, without fde. Now, it booted and landed me onto a text login screen. No keyboard. Luckily, I decided to give the device some time. The device logged me into an empty screen with a wallpaper. Empty screen. Yes, that is what I like to see on any desktop. That is the reason I love window managers. That is the reason I have been on i3 since ... (I have forgot the count). Again, why empty screen? Well, I had chosen the choice of sxmo environment heavily inspired by DWM and i3(sway of course). I had seen few videos of sxmo running on the pinephone. However, the video I had watched was very hardware intensive. That is the actions were performed by a combination of hardware buttons on the device. I hate using hardware buttons on any device. I prefer double tapping the screen to unlock the screen and double tapping the screen again to lock the device. I want the hardware buttons for that rainy day. I want the hardware buttons to get into fastboot. Went to the sxmo website. Mind blown. My God!!. What an idea!? The gesture system is one of the best I have come across. It is the most intuitive gesture system I have come across. Oh, did i just indicate that to boot from the SD card, you just have to power the librem5 with the vol down button held down for at-least 05 seconds. You have to immediately hold down the volume down key after powering up the device. 

Let us continue about sxmo. The sxmo project has a very nicely curated set of apps. The most important contribution from the team are the scripts. The project has exposed many of the phone related activities as hooks for the user to tap into and make scripts to accomplish tasks when triggered by clicking the name of the script or a combination of hardware buttons. The present scripts written by the project devs are readily available from the script menu(swipe diagonally from the top right towards the center of the phone). The menu, when accessed through the documented shortcuts are context sensitive. That is the menu is displayed based on what is available on the screen. If it is a Firefox window, the menu will give an option to open a new window or a new tab, you get the idea... Tiling is a first class citizen on sxmo. It was a joy to see multiple windows stack one below the other. Other Operating systems took years to reach this level of window management. Anyhow, I will write on only "sxmo". Thanks again to all the devs and users making the GNU/Linux stack a reality on phones.

Thursday, October 3, 2024

Librem 5, The phone all the GNU fans wanted

After a wait of nearly a year I have received the librem5. It has brought me immense joy to hold the phone in my hand. I funded the venture only to fund the effort. I was never looking forward to the phone. Placed the order through a friend's friend's .... friend in the States. The camaraderie to help out a friend without even knowing what is it I am buying goes a long way to explain the concept of friendship. It is amazing. Though the phone was received a year ago, it had to wait for the friends to come to our country. This requirement was very clear. It will come only when the friend is free and wants to visit his country. 

 It was pure ecstasy when I held the phone in my hand. It was like some sort of magic. I was holding the phone which was a culmination of efforts of so many like minded people with the singular effort and aim to make a "Free as in Freedom" phone. Having started using GNU/Linux since 2002, since my first PIII PC, I have run GNU/Linux on all my desktops and Laptops including Macbook Airs and Macbook pros. Let me not forget the countless hours spent on learning to use the "Freedom" way on the computers. It was difficult. I have persevered. I love the freedom I gain for the effort put in to customize the OS. I love the fact that every single word, every single screen, every single action is tailor made for me. 

For a person who knows the value of Freedom, GNU/Linux is my wet dream. Let us not forget the hours spent on modding Android phones to run CyanongenMod and Lineage OS on many Android devices over the years. Again, I loved the freedom these mods presented me when using a phone. While all other phones bound the user and made them to learn it their way. I had my phone tailor made to work my way. Yes, GNU/Linux is a rabbit hole. Yes, GNU/Linux is free if you do not consider time as money. 

Coming back to the L5, holding a phone which has GNU/Linux out of the box, was sheer excitement. For the first time, after buying a computer, I need not spend hours to bring the device and its characters to my liking. For the first time, I just started using it in "as is" condition. A great win for all the developers/users/visionaries who believed in the project. For me, it is still unbelievable. Yes, I know, it took a lot of time. It angered many of the investors. As for me, I was confident on the team to produce a working phone. My main confidence lay in the software stack, ie, GNU/Linux. It was always available for the purism team. 

I have forgotten when I ordered by L5. It does not matter now, nor it mattered when I ordered. When I received the phone, I explained the intention of me ordering the phone and the philosophy behind it to my friends. It went above their heads. Paying "that" money and waiting for "that" many years was not entering their heads. They know my passion, but still could not put their head together to understand this amount of madness. However, they were happy for me receiving the phone for which I had "Paid" with plenty of difficulties. 

I opened the phone and connected it to the charger. The lights were running in disco pattern and nothing was happening except that the vibration motor was running crazy and matching the disco lights on the device. A quick search took me to the purism how-to's and in seconds had my phone charging. Booted into the device and was immediately at home with the UI. It was just a small sized GNOME shell. 

Everything was familiar. Everything looked in its place. Everything was inviting me to hack on the device. Immediately install i3 and the like and have a dark background with nothing on it with a launcher on demand. This has to wait. I want to experience the vanilla L5. I want to savor all the efforts put in by the entire team of purism and all the independent devs and users across the world by using it and providing valuable feedback. 

Please acknowledge my heartfelt gratitude for embarking on a journey with no support from any big corporation, in the present modern times wherein, no government is questioning the strategy of throwing out phone/laptops since the batteries of the phone are made non-removable. Criminal. 

Of course, I am just getting started!!

Saturday, April 22, 2023

Multiple monitors with i3 wm

 This took a very long time to happen. Ultimately it is a downgrade which has made me to take up multiple monitor setup. A Dell laptop, around 5 years old, was discarded by my son certifying it to be very slow. However, the laptop was upto the task considering the mac mini which I had. So, upgraded the hdd to ssd. I started from a clean slate. Installed a clean copy of windog 10(well, paid for the license when the laptop was brought). After a flurry of updates and reboots... phew.. it was complete.

Now to the favorite part. Getting Arch Gnu/Lnux onto the laptop. Tried installing arch based derivatives with i3 as the wm. However, was not happy with the plethora of packages which got installed. I have nothing against the distros. However, I have been destroyed by the plain/vanilla install of arch Gnu/Linux on all my computers. So wiped again, and did a vanilla arch gnu/linux install. Installing packages as and when I was hitting a wall for a particular task. Just goes a long way to tell how much effort you have put to make your arch gnu/linux install "your own". That is not time wasted. But, time well spent.

As I again, brought the install to my liking, it is bewildering to see the control one has on his computer. Compare it with the windows install. Cannot compare. Yes, cannot compare the ease with which GBs of software lands on your computer in the name of "ease of use". Well, Freedom is never easy and never will be. 

 However, the point of the post is multiple monitor setup with i3. Let me start by telling that it was not easy. Lot of web searching and personal shares of various users have made me to nearly approach the setup which I liked. Again, which I liked... so... The basic premise is I wanted 05 workspaces on the QHD monitor and another 05 workspaces on the laptop display(FHD). This was my requirement. However, wherever, I was searching, the majority of the results concentrated on moving workspaces or containers or windows or another atomic elements in i3. I did not want to move applications between the monitors. Some apps are better on QHD and some on FHD. So the applications will go respectively to those workspaces as decided by the user(me). Tie the workspaces to the monitors


Howver, the point of the post is multiple monitor setup with i3. Let me start by telling that it was not easy. Lot of web searching and personal shares of various users have made me to nearly approach the setup which I liked. Again, which I liked... so...

The basic premise is I wanted 05 workspaces on the QHD monitor and another 05 workspaces on the laptop display(FHD). This was my requirement. However, wherever, I was searching, the onus was on moving workspaces or containers or windows or another atomic element in i3. I did not want to move applications between the monitors. Some apps are better on QHD and some on FHD. So the applications will go respectively to those workspaces as decided by the user(me).

Tie the workspaces to the monitors

workspace $ws1 output $qhd
workspace $ws2 output $qhd
workspace $ws3 output $qhd
workspace $ws4 output $qhd
workspace $ws5 output $qhd
workspace $ws6 output $fhd
workspace $ws7 output $fhd
workspace $ws8 output $fhd
workspace $ws9 output $fhd
workspace $ws10 output $fhd


Added the following to meet the requirement which I set out to achieve. When you now hit the hot key for navigating to a particular workspace, irrespective of the monitor, the focus is on that particular workspace.

bindsym $mod+1 focus output $qhd;workspace $ws1
bindsym $mod+2 focus output $qhd;workspace $ws2
bindsym $mod+3 focus output $qhd;workspace $ws3
bindsym $mod+4 focus output $qhd;workspace $ws4
bindsym $mod+5 focus output $qhd;workspace $ws5
bindsym $mod+6 focus output $fhd;workspace $ws8
bindsym $mod+7 focus output $fhd;workspace $ws7
bindsym $mod+8 focus output $fhd;workspace $ws8
bindsym $mod+9 focus output $fhd;workspace $ws9
bindsym $mod+0 focus output $fhd;workspace $ws10


As a bonus, now, let us say you have the workspace you want to work on in clear view on the other monitor. You just want focus on that monitor. Add the following to your config

bindsym $mod+period focus output left

Kindly bear in mind, the keybindings which are already utilized in your config file before changing anything.

Thats it.

A big Shout-out and Thanks to all the devs and users making the "free as in freedom" world possible.

Tuesday, May 18, 2021

xargs - The generic tool for arguments

    xargs is one of the most versatile tool used by command line warriors. There is a sort of aura around this command. Numerous videos are out there explaining the usage of this tool. The discussions below are to be taken as one for the entry level command line users. Kindly refer to the man pages for further advanced usage. In particular more information and its usage can be better appreciated from books and articles on shell programming, where a discussion on this is a mainstay.

    I will be using music files and c source files as examples wherever appropriate according to the easiness with which the underlying usage of xargs is more clear.

In the present directory as we start this discussion, we have the following files

music1.mp3
music2.mp3
music 3.mp3(notice the space in between music and 3)
music 4.mp3
big_program1.c
big_program2.c
big_program3.c

ls *.mp3 | xargs -t

echo music1.mp3 music2.mp3 music 3.mp3 music 4.mp3
music1.mp3 music2.mp3 music 3.mp3 music 4.mp3


    The output above is a little cryptic. Let us clear it first. If there is no other command to which xargs passes the arguments, the by default xargs pipes it to echo. The -t option is same as --verbose option with GNU extensions(by the way, I like GNU extensions for any program, they are more verbose and use the long form to extend  and explain what that particular option would do). By specifying the -t option, we are telling xargs to be more verbose in its activities. The result was that the xargs command took the output of ls and piped it to echo. We can see that exact executed by xargs in the first line of the output. The total result of the command is the output in the second line. All the arguments were passed on at once to the echo command.

    Now, let us change the above command such that the echo command is run on every argument. For that,

ls *.mp3 | xargs -t -n 1


echo music1.mp3
music1.mp3
echo music2.mp3
music2.mp3
echo music
music
echo 3.mp3
3.mp3
echo music
music
echo 4.mp3
4.mp3


    If we see the output, we met our task, partially. echo command is run on every argument. However, the file names with spaces in them have created a problem. By default, the delimiter for xargs is the space/blank character. To ensure that the above command works properly, we have to include the information of the delimiter in the xargs command, like so.


ls *.mp3 | xargs -t -n 1 -d'\n'

echo music1.mp3
music1.mp3
echo music2.mp3
music2.mp3
echo 'music 3.mp3'
music 3.mp3
echo 'music 4.mp3'
music 4.mp3


    Now, we see that the xargs command met our requirements. Now we are pretty confident that we can now pass on these xargs to other programs and are confident of them working properly. Let us now play the mp3s.


ls *.mp3 | xargs -t -n 1 -d'\n' mpg123


    This will now play all the mp3 files in alphanumeric order as listed by the default ls command, one after the another.

    Let us now take up the next key strength of xargs. xargs has the capability to spawn multiple processes so that arguments can be passed on to multiple instances of the program. For eg,

ls *.mp3 | xargs -t -n 1 -d'\n' -P 8 mpg123

    That was indeed funny, right. Seriously, that is a very wrong example to illustrate the parallel processing achieved by the above command. The above command starts multiple instances of mpg123, with all the instance playing an argument supplied. You can increase the argument for -P based on the number of files piped into the final command. Here you have all the four songs playing in parallel. The sound output might be interesting for music producers. For us listeners, nothing.

    Let us now consider a proper, practical example for this spawning of multiple processes,

ls *.c | xargs -t -n 1 -P 8 gcc

    The above command will run multiple instances of gcc at the same time and the compilation will happen in parallel on all the 3 files in the present directory. To do this kindly ensure that your programs can be compiled so and are stand alone and not dependent on each other being compiled already. Here we do not have the problem of file name containing spaces. If you are comfortable with

make -j 8

    For compiling your linux kernel, you know exactly what is happening here. The linux kernel is one of the greatest and practical examples for compiling sources in parallel. What a great feat. Kudos to all the kernel devs.

    With this, we come to the end of this gentle introduction to one of the most important tools for shell programming. The knowledge of xargs is a must for all shell programming aficionados.

    The standard thanks and regards to all the FLOSS users and devs. You people are great. Thanks again.

Sunday, January 17, 2021

Media player daemon: Playing music with mpd and mpc

My love for the Media player daemon is clear if you have gone through my other blog posts. I like its concept. It is simple, straightforward and does what it is supposed to do. Play music. The combination of mpd and mpc is awesome. It is akin to watching a good buddy movie. They are just so perfect together. If you are a person who would like to "see" the song list and control the music by visual controls, you are also covered. There are a plethora of clients for the mpd. In terms of simplicity an curtness, there is nothing closer to mpc. 

 This post is about the barest minimum required to start playing music without the screen filling up with the file names. Installing mpd on arch is as simple as a, b, c.... really. 

pacman -S mpc mpd 

copy /etc/mpd.conf to .config/mpd/mpd.conf Overwrite the file with the information below 

--------------------------------

# Recommended location for database 

db_file "~/.config/mpd/database" 

# Logs to systemd journal 

log_file "syslog" 

# The music directory is by default the XDG directory, uncomment to amend and choose a different directory 

# I like to symlink all my sources of music to the default Music folder. Ultimately, tell the directory where # your media is stored. 

music_directory "~/Music/music" 

# Uncomment to refresh the database whenever files in the music_directory are changed 

#auto_update "yes" 

#These are my choices for the requisite files. Al these files are required. So, if you would like to change the locations, do so. But ensure that these directories are user accessible with write permissions. 

playlist_directory "~/.config/mpd/playlists" 

pid_file "~/.config/mpd/pid" 

state_file "~/.config/mpd/state" 

sticker_file "~/.config/mpd/sticker.sql" 

#This is if you are using pulse audio. If you are using also, change accordingly audio_output { 

type "pulse" 

name "pulse audio" 

----------------------------

Save the file. reboot 

Now, the first step ensure that mpd is running.

mpd 

On success, the above command will not spit out anything. Now, the daemon is running and waiting to server you music. Let us now, build a database of songs available in our directory we specified in mpd.conf. 

Now we have to populate our database. Before doing this step, I suggest you to check whether your music has good metadata related to track names, albums, etc. If not, it is always good to invest some time in editing the id3 tags of your music. This will help us in getting "that" song to play. 

Once you are sure of your metadata. Go ahead and build the database. 

mpc update 

The above command will take some time. Give it a few minutes. To know whether all the songs have been added to the database run the command below. If you see that the last song is the same when you run the command below, multiple times, then you know that the database is completely built. 

mpc listall 

Of course, your database is going to be huge. And depending on your mood, you would like to pick and choose. Let us now create a playlist based on certain criteria. You are now in that retro dance mood and would like to listen to the evergreen Jackson. There are multiple ways to search for Jackson songs in your database based on how your id3 tags are created. If you would like to add all albums with the name Jackson in your album name then you would do 

mpc searchadd album jackson 

I know, Now you want to see what is the playlist which is create by the above command, For this you would 

mpc playlist 

Now, you remembered that there are certain files with Jackson in their names but are not part of an album with jackson in them. Then to add all the songs with title containing jackson 

mpc searchadd title jackson 

Now, check your playlist again 

mpc playlist 

The nerd in you is glowing. You now have all the titles you want to play in your playlist. Hit it. 

mpc play 

Of course, you have got used to seeking music with other command line players by hitting the arrow keys. However, the command for seeking in mpc is(Again, you can map keys and what not.....) 

mpc seek +00:04:00 

The above command is for seeking the song by 04 minutes. I think the logic is clear. This works both for individual files or if you have a file with multiple songs. If you have individual songs in files then 

mpc seek +80% 

would be better. 

 In the middle of your listening pleasure, you would like to know the details of the song being played now

 mpc status  

will give you information regarding the present song and plenty other data related to the present playlist.

For seeking back change the + sign to -. An alias for all the above would be best. 

The post is not complete without gratitude to all the devs and users who make all this possible. The GNU/Linux land and the BSD universe have not stopped surprising me.

 

 PS: Just, one more thing.

 mpc searchplay title jackson

 which will create the playlist and start playing.

Wednesday, December 30, 2020

GPG: Encryption and digital signature for the masses

Disclaimer: This is a very serious topic. The observations made here are for a starter. Kindly refer to the man pages and other text books which specialize in guiding for advanced and high stake uses. I am not responsible for any unwanted results by following the notes below. Understand the seriousness of the job on hand and read enough. 

     The notes below are culled from the public network from various sources. Thanks to the free software foundation for the fantastic gpg tool and all the original authors of the pgp standard. GPG is really "encryption" for the masses. Kindly refer to directions from master users for creation and usage of GPG. The recommended way of creating a key pair is on a computer with

1. The operating system to be installed with images downloaded and checked for the integrity of the OS image on another computer connected to the internet.
2. Install the downloaded operating system on new vanilla hardware and the computer should not be connected to the internet even while installing the OS.
3. After installing the OS generate the keypair ensuring that the computer is in now way connected to the public network.

Even if you dont want to create the keys in the way mentioned above. It is required to know the above information.

--------------------------------

    Private key cryptography and symmetric cryptography are the same phrases. They are just a complicated way of telling that the cipher and key used for encrypting a message is the same that has to be used to decrypt the message. That is, the cipher and the key is first shipped to the recipient. Then the actual encrypted message is sent.

Public key cryptography/asymmetric cryptography:

    A mathematical process generates a pair of keys. A message encrypted by one key of this pair, can be decrypted by the other key of this pair. One key is called the public key(can be shared with the whole world) and the other is called the private key or the secret key(Not to be shared with "anybody").

How asymmetric cryptography works:

 
    Let us assume the data of individuals in the whole world is maintained in a database with their respective public key. So we pickup the name and the corresponding public key on this database(provided we know this is the person whom we want to communicate). Now

1. we create a message which is to be sent to "only" this individual.
2. we encrypt this message with the public key available in the database.
3. send the message to the individual through the public network, by means like email ....
4. The recipient will then decrypt this message with his private key
5. No individual in the world will be able to decrypt this since the message can be decrypted with its pair which was generated by the mathematical process which produced the public/private key pair

-------------------------------

Creating and managing gpg keypairs

Let us now get down to "actually" creating the key pairs. We will be using GPG(GNU Privacy Guard). Kindly refer to the man pages for further information and the public network for deeper insights. GPG is a common on all the *nix operating systems and is available for the proprietary operating systems also.


The first step is to generate a key pair. Run the following command

gpg --full-generate-key

On running the above command in a terminal you will be asked the following queries. Answer accordingly.

a. Choose the type of key: We will choose the default RSA
b. choose the bits for your key: Let us choose the longest option(We are in modern times)
c. Expiry date: I would go for an yearly update
d. Real name: Here you have an option of putting your real name(You can ofcourse not tell your real name. But, to use it in place like github etc, it is better to have your real name)
e. Email address: The same logic as above is applicable here also
f. There is a comment field: You may fill it up or recommended by many people to leave it empty

After the above step gpg asks to enter your passphrase. 

This is a very "important" step. The passphrase is intentionally called a "phrase" it is not called a password. This has to be as long as possible. It is better if it has a mixture of alphanumeric characters interspersed with special characters like @%(%$) etc. It has to be sufficiently long. This is what protects your private key. Please use a long phrase, which you can remember very easily and quickly. In fact you should be flamboyant when your are typing out your phrase. At the same time that phrase should be alien to anybody else on the planet.

Once you enter the passphrase, gpg starts the mathematical part required to generate the key pairs. Help out with sufficient entropy(randomness) by opening lot of firefox tabs, plenty of word processors and go ahead and do whatever work you want to do with your computer. This improves the entropy required to ensure the randomness of the digits generated for your key.

Once you generate the keys, the keys are stored in what is called a "keyring" Just know that the keys are safe in a box and locked by your passphrase

To print out the public key which was generated

gpg --list-key

To get the public key in a format which is accepted worldwide

gpg --export --armor dfdf@fdfd.com > dfdf_pubkey.asc

To display your public key
 

cat dfdf_pubkey.asc

Once this is generated, you can share it with the world. If your friend wants to add your public key to his keyring, then he would

gpg --import dfdf_pubkey.asc

There, now he has your public key in his keyring.


To list the private keys

gpg --list-secret-keys   

Now it is required to generate a revocation certificate. Why are we in such a hurry in creating one. Well, we should have the revocation certificate handy, if the keys have been compromised and you think that the keys can be used by others to gain access or sign documents with your keys and send it to inappropriate places. With revocation certificate you can revoke the key pairs and also tell the whole world about it so that the whole world knows that there is no relationship with your previous sets of keys. The latest version of gpg creates a revocation certificate during the key pair creation process itself, fantastic.

gpg --gen-revoke fdfd@dfdf.com > fdfd_revoke.asc

Now you will be asked for the reason. Choose the appropriate reason.

The file you created is called the ASCII armor file.

So, we have created the revocation certificate. This certificate will be used to revoke our key pairs.

gpg --import revoke.asc

Now if you run

gpg --list-key

You will get your public key information with "revoked" added

Now you can really delete your key pairs

gpg --delete-secret-keys fdfd@dfdf.com


gpg --delete-keys fdfd@dfdf.com

Now if your list your keys

gpg --list-key

The output will be empty

Let us now remove the revocation certificate also

rm fdfd_revoke.asc

-------------------------------
 

Encryption


Let us now encrypt and share some secret documents with friends on the public network

To start with you should have

1. Got the public key of your friend.
2. Import the public key into your keyring.
3. Did your homework to ensure that the public key does indeed belong to your friend.

We have done the homework and are sure thatthe public key shared by your friend is genuine. Let us now go ahead and trust the public key by signing your friends public key with your private key

gpg --sign-key friend@friendship.com

Now, to encrypt the document and ensure that the only recipient who can decrypt the document is your friend,

gpg --encrypt -r friend@friendship.com secret_document.txt

The command will output secret_document.txt.gpg which is a binary file

If you prefer the ascii armor format

gpg --encrypt --armor -r friend@friendship.com secret_document.txt

which would output secret_document.txt.asc again a binary file.

You can now send this document through any channel available on the public network and are assured that your friend with whose public key the file was encrypted can only decrypt it with his private key. From now on, if you, the author have deleted the original secret_document.txt also cannot decrypt the resultant file secret_document.txt.gpg.

To avoid this you can add yourself also as a recipient

gpg --encrypt -r friend@friendship.com -r fdfd@dfdf.com

Now, you the author with email id fdfd@dfdf.com can also decrypt the file as and when required and can safely now delete the original file

-------------------------------


Digital signature


We have all the way been talking about encrypting a document. We want to ensure that the document reaches and is ready only by the individual(s) to which it was intended. This is fine. Let us forget encryption for a moment and think of a public document. Anyone reading a public document should be ensured that this particular document is an un-altered copy authored by a particular person. The document should be able to speak about the author. That is, the document should be signed by the original author. This ensures the reader that the document is an un-altered document and is as was imagined by the author. We are talking a synonymous situation of physically signing a document. We are talking about an electronically signed document.

gpg allows us to do this. When we are signing a file we are not encrypting the file, we are just creating a binary file with contents of the signed file as well as information about our signature. The signing and verifying methodology described below makes use of the fact that the signed file has the contents of the signed file as well as the signature in one single file.

 When gpg signs a document there are two things which are ensured

1. Integrity: When the recipient checks for the signature authenticity and it matches, it also means that the signed document received is not altered in any manner

2. Authentication: Again, when the recipient checks for the signature authenticity and it matches, it also means that the document is indeed from the person who really sent the message by signing with his private key

gpg --sign document.txt

This will create document.txt.gpg, a binary file which includes the content of document.txt and the signature.

Before creating the .gpg file, you will be asked to enter the passphrase, Now, you have affixed your signature on the document. This process makes use of your private key. So, as per the pgp convention, if you encrypt with one part of the key pair, the other key pair is used to decrypt the document. Now, since you have added your signature to the document with your private key, the confirmation of ownership can be done with your public key. Since your public key is supposed to be public, anybody, with access to your public key will be able to ensure that document is created by you. However, the world can view the document by using gpg --decrypt as discussed below and view it but not ensure that the document was really signed by you and you are the creator of the document 

Now, on receipt of the file, the recipient to start with, will first check for the authenticity of the signature. This is done by

gpg --verify document.txt.gpg

The output will show the signature and will term the signature as good, if you have the public key of the sender in your keyring. So we now have attested that the file infact, is created by the creator we were expecting.

Now to proceed to view the contents of the document, let us decrypt it, ie, let us bring it back to viewable state.

gpg --decrypt document.txt.gpg >> document.txt

The above step will still re-create the original file though the authors public key is not present in the keyring. gpg will just tell that the signature cannot be verified.

I think you are used to seeing signed documents with an armor ascii format. To achieve this

gpg --sign --armor document.txt

This will generate document.txt.asc, a binary file which includes the signature in armor ascii format with the contents of the file

To verify the file and as well as decrypt

gpg --verify document.txt.asc >> document.txt

Once you trust the public key and are sure that the public key indeed belongs to the individual you know, that trust can be extended into your keyring by signing the author's public key with your private key. This can be checked in various ways. If we know the author and his online activities, we could go to the place he is most active and check for his email credentials with his pgp fingerprint on that website. Or we could go to the many pgp key servers over the public network and search for the fingerprint or the email id in the fingerprint. It should match with the copy of the public key we have. Once you are content that this is the person associated with the key, then and only then change his public key in your keyring to trusted. This will remove some warnings when you check the signature of the files from the author which talks about "...Not certified with a trusted signature...". To do that

gpg --sign-key author@creator.com

After this when you verify the signed files received from the author by

gpg --verify document.txt.gpg


you will not find any warnings

Down the line, by some means you start doubting the public key and the associated individual it is time to revoke the "trusted key" status in your keyring. Now the thing is once you create add a key in the keyring, any further edits are possible only from within the gpg command. Here we are interested in removing the trust from the public key. So you would start the gpg editor like

gpg --edit-key author@creator.com


Now you will get the gpg> prompt
Enter "help" to get all the options. Here we are interested in revoking the trust we put in the above public key
type revsig at the gpg prompt
You will be prompted for the reason, answer accordingly. Exit and save when prompted. Now, you have successfully removed/revoked the "trusted" badge from author@creator.com
 

----------------------------------

Digital signature for special case involving pure text files

 
If you are dealing only with text files. It will better if the text and the sign appear in the same file as a regular document. It is like you have a text document and you affix your signature to the end of the document. gpg provides this facility through

gpg --clearsign document.txt

will create a document.txt.asc

Now the recipient can open the file with

cat document.txt.asc

which will have the content of the document as well as the signature at the end of the document. Now, to verify the signature, the recipient would

gpg --verify document.txt.asc


Now, to get back the original document only, without the signature then the recipient would

gpg --decrypt document.txt.asc > document.txt

--------------------------------

Digital signatures for huge binary files

 
All this time we have been using gpg such that the contents of the signed file and the signature are available in the output file of the gpg command. This might not be conducive as the file sizes grow. It is better off to have the signature separate from the signed file. With this, the file and the signature are two different files. Just remember that to check the signature with the associated file both have to be in the same directory and the file names cannot be changed.

To create a signature separate from the signed document

gpg --detach-sign --armor document.txt


This will output a file document.txt.asc. (You still have your original document.txt unchanged). This file contains only the signature but is associated with the original file document.txt. This is the methodology used to share binary files and packages on the public network. You will have the package/software you would like to download and adjacent to that you will have

1. The signature (normally it will be labelled the pgp file)
2. The public key of the author

You download the above two along with the software package

1. Put all the three files in a single directory
2. Import the public key of the author
3. Sign the public key of the author with your private key after doing your homework about the authenticity of the public key
4. check the signature
5. On no warnings proceed with the installation of the package

Wednesday, December 23, 2020

Arch GNU/Linux and OpenBSD on mac mini 2018, 2019, 2020(Intel processors)

     The laptop is not an ideal computer when you are sitting at the same desk and especially when you are at home. At home, the best computer would be a desktop. For the past 5 - 10 years I have been using laptop at home, but desktops at work. I observed that I have been killing the battery. I have my laptop always connected to the power supply and that is not good. Draining your battery just because you should drain it, though you are near to a power supply is not something which I can digest. For nearly an year used the raspberry pi 4 as a desktop and tried the frugal method of using a computer. I have been mighty happy with the direction the raspberry pi is headed. I loved what the rpi foundation is doing. It is the apple philosophy of making the hardware and software together but with freedom software ethics in place. Yes, there are still blobs being used, but the foundation is putting enough efforts to tend towards an open ecosystem of software and hardware. 

     Now, the thing with the rpi ecosystem is that you have to be abreast of the developments. If you use the bleeding edge software, you should be ready for the occasional glitches. Now, this is a problem, if you want to just start the computer and do an immediate task. Yes, if you run the debian stable, ie, the official rpi os, you are better off. But, the software is outdated for somebody who has been spoilt for using arch Gnu/Linux or Debian testing. Yes there are plenty other options for Operating systems. But, they all have something lacking. I have tried one and all. I have tried the ubuntu dev version, which I used for a long time. But, it was borked many a times during a upgrade. So, it is back to reading the forums and clearing up stuff. Plenty of experiments were carried out. I live a couple of months on the command line "only". It was very interesting and I liked the challenges that were presented. After an year, something happened and the pi 4 started acting strange. It was time to move on. The first rpi 4 had a damaged sd card slot before the usb booting came out. So, as for now, the rpi efforts are shelved.

    As is the norm for a lull after the storm, I decided to take it a little easy this time and decided to have a cheap desktop solution for my daily use at home and keep the laptop for mobile purposes. Started searching the used computer market for a sleek desktop. Plenty of Intel nuc's came along. Every single model has a lacuna on some issues. Marketing and the modelling of these systems is a total failure by Intel. The number of variants is mind boggling and utterly confusing. Searched for mini pcs from other brands like HP and Dell. Nothing interesting came up. This is the time, Apple came out with its M1 processor. I was surprised that Apple released a Mac Mini with its inhouse processor. Started knowing about the Mac mini and at the same time started looking up the used pc market. There was no way, I would be buying any device from Apple on which I cannot install GNU/Linux. I have a mac book pro 2015 which runs Arch Gnu/Linux and OpenBSD like a dream. In summary, I like apple hardware and hate their software and the lockups they try to force people to stay on macos. Until, I can install Gnu/Linux or BSDs, I dont have any gripe with apple. I love the way they make their hardware. If customization is allowed, the choices are easily laid out and of course can be very very very costly.

    Since Gnu/Linux on a mac mini M1 is still a very looooong shot, I started looking at the older versions. I liked the form factor of the mac mini. There was one more surprise, the extensibility of the mac minis. This was a complete shocker. Four thunderbolt 3 ports, two usb 3 ports, Gigabit ethernet ports, 3.5mm jack. It is like the voltage of the shocks went on increasing. Settled to buy a mac mini 2018. Waited and searched for a month and I got my hand on a "very" affordable mac mini. The build quality is excellent. The option of upgrading ram upto 64GB of DDR4 was un-believable. Postponed the upgrade for a later date. Already had a 32" LG 4k monitor, a mechanical keyboard and a M501 logitech mouse. Had an external ssd which I was using to boot up the raspberry pi. Everything just fell in place. The onboard storage is only 128GB. But I am OK with it.

    Searched the public network for installing Gnu/Linux on a mac mini. The literature is very limited. But, could put together a collection of information necessary. Infact, the installation of Gnu/Linux or a BSD on a mac mini is much simpler than that of installing windows through Bootcamp, which was a breeze when I bought the macbook pro 2015. Installation of Gnu/Linux or BSD is mighty straight forward and can be summed up as

1. Disable the secure boot and file system protection(csrutil disable) on the mac mini


2. Partition the external ssd hard drive(Dont forget to create a FAT32 partition with type set to EFI as the first partition on the external SSD, a 512MB partition will do) for Gnu/Linux and OpenBSD(I prefer OpenBSD to Freebsd just for the fact that the graphics stack is "owned" by the core devs of the project and all other security related "firsts". Again a "sensible" default) 


3. If you want to install OpenBSD do not forget to create a partition of type OpenBSD before starting the installation on any other GNU/Linux box. This will provide you and option during installation to chose that particular partition. This just makes the job easy for installing OpenBSD in multiple boot machines.


4. Download and install the refind boot manager from macos(You can install this in the macos recovery which you have entered to disable the file system protection). I just love this application. My gratitude to all the devs and users of this excellent tool.


5. Install Arch Gnu/Linux. I chose to install arco Gnu/Linux for a change and I loved the installer. Be wary of choosing other software options provided during the setup process. It struggled to download and install these. It is better to install these extra options doled out to you after the base arco install. The installation was flawless. Again dont forget to choose the EFI partition created in step two and set the boot flag. This option will be thrown to you when you select the EFI partition to be mounted as /boot/efi


6. Install OpenBSD. I love the installer. I have expressed my awe at the defaults the installer puts up. Installation process was flawless. It trumped the arco install process. Kudos to the OpenBSD team. Here again, OpenBSD expects an EFI partition on the first partition of the external SSD, which we have already met.
7. Wifi and sound through the 3.5mm jack does not work. This is the same for Arco Gnu/Linux and OpenBSD.


8. Resolved Wifi by using an USB adapter and resolved the sound issued by taking the output from my monitor.


9. At some occasions, refind is unable to boot up macos. The work around as of now is to shutdown the mini and restart. At the chime press the alt key. This will bring up the apple boot loader. If you are lucky you will see the options for choosing the apple drive and the EFI partition on the external ssd. If you are unlucky, you will definitely get to boot the macos partition. To boot the FLOSS operating systems, just reboot and you will be presented with the refind menu.


10. Dont forget to enable the file system protection again by entering the recovery menu(csrutil enable).


11. Arch Gnu/Linux and OpenBSD run flawlessly and the availability of 4 thunderbolt 3 ports is freaking amazing.


12. The form factor is just perfect for putting it in a compartment in my table without clogging the surface of the table for space. Resulting in one of the neatest desks I have maintained.


PS: All of a sudden, my arch gnu/linux installation was not detecting the Ethernet connection. Ran 

lspci

After searching the public network for the Ethernet hardware detected, tried

# modprobe tg3

reboot, and Ethernet started working.

Friday, October 30, 2020

Going "console only "on GNU/Linux

Got frustrated with the time taken for the browser to load up and then dependency trap for installing other gui applications. Add to that the nuisance of gtk and qt quirks on a 4K monitor. The feeling is share by many. But as we shall see living in this place is not easy. The major difficult piece of the puzzle is the browser. All your banking, shopping options are ruled out in the terminal. 

 

What I did here was to disable even the start of the X server. I disabled sytemd unit which is supposed to reach the graphical login target. Disabled the graphical login manager, lightdm in my case. Disabled all the cloud stuff which ubuntu GNU/Linux starts with lot of difficulty. In fact, because of this the first boot of ubuntu after install is a hit or a miss. After boot do not try to login immediately. There are plenty of things ubuntu is doing in that phase. If you try to login, it will fail. Wait for 10 minutes, approx, it might be higher so that it spews many lines of information over the login prompt, then it will allow you to login and change the default password. 

 

Disabled ssh service, because the rpi 4 is connected to a 4K monitor. Even during login, ubuntu tries to plenty of things. It will try to check for updates and provide a notification once in the motd. It will also provide information from the ubuntu motd server which canonical wants you to see. It will also spew out certain information from your computer like memory usage, load on the cpu etc. All this will take plenty of time considering the rpi 4. Find the respective scripts and disable them to speed up the time required to reach the login prompt. So, we have reached the login prompt. The fonts are so tiny, you have to squint to type any commands. First thing is to first reconfigure the fonts. Get the biggest font available while running the re configuring tool. Yes, the size can be changed, but the fonts are horrible. They are not for your daily tasks. All the fonts which you had installed in your X is now out of reach. 

 

The console well, is a console. It will display fonts which are baked into the linux kernel. If anybody knows how to change the fonts on the default console, kindly advice or drop a link. But, as of now, we have a readable console and the font size is alright. The fonts are not. We have been pampered for the variety of fonts on X. It is a requirement that we should do something about it. Step in, fbterm. As the name suggests it is a terminal emulator designed to work with a framebuffer. The biggest advantage, supports all the fonts supported on X. There goes my first gripe about the console. So, we install fbterm and start and run it at the console. The console is taken over by fbterm and again we have micro-sized fonts, but nice looking fonts taken from the X environment you had installed earlier. Let us go ahead and fix the fonts by restarting fbterm with fbterm -s 24. This was for my monitor. Try experimenting with different sizes to get the optimum size. 

 

The config file for fbterm is in .fbtermrc. Well, I already see your smiling face and I have received your gratitude and in turn it is time to congratulate you for completing the first time required for living in the console. Whatever further tools we are planning to used depends on this success. The fonts are beautiful and they are your favorite ones. They look good and it is as though you are back on your terminal emulator on X, but without all its bells and whistles(another name for bloat). You now can clearly distinguish between l and 1, 0 and O, I and L. I would like to thank all the creators of fonts which can clearly distinguish the characters of the English language. It is an artists job and the creator of any font is an artist. 

 

You opened the fbterm man page and want to edit the configuration file by reading the manual, you are out of luck. You are on the console. There are no windowing systems. What d you do, you press C-A-F2 and switch to the next virtual console and login again. Then you can switch between the virtual consoles. Your are now flabbergasted. You have started hating yourself for moving away from X. But, fritter not, there are further goodies which come with fbterm. You can create multiple windows and switch to them using shortcuts as mentioned in the fbterm man page. This will give you a method of moving between multiple windows and then moving between them. 

 

 Let us go to the next step. Now, you would like to group certain windows and recognize them for a specific task group. You have a web page related, you have a manual page related and couple of windows concerned to the programming task related to the web page and the man page. You are out of luck. You cant see all the windows at once together on one single screen. Frustration. Enter terminal multiplexer. The first name which comes to he mind is tmux, if you are a year 2000 person and screen, if you are before that. These are excellent tools and are blind faith groups unto themselves. So, if you like a tool, silently use them. Do not compare them and publish your comparisons. This is because, if you have reached a position where you compare both these tools, that means you already "prefer" one among them. This will start a war. We already have the longest running war between Vi and GNU Emacs. These are the kitchen sinks of terminal multiplexers. 

 

If you are a person believing in the *nix philosophy of "One tool that does one thing and does it best", then you have an alternate option. Many a times I had tried to pull myself together and learn tmux, but since I was using the i3 wm, I thought that it is not worth the effort. I could open as many windows and all would be started side by side preparing a huge canvas for exchanging information. I am in love with i3 wm for its simplicity and doing what it is supposed to do and doesnt do anything more. A huge shoutout to all the devs and users of this fantastic wm. Now, once again my terminal multiplexer flames were re-kindled by Mr. Bronie Robertson on his youtube channel. I like his videos. They are short and to the point with excellent examples and use case scenarios. 

 

Plentiful thanks to him for introducing me to abduco. Such a strange name. If there are explanations for the name kindly enlighten me. A session management tool with such a strange and difficult to pronounce name. However, what caught my attention was the ease with which Bronie did the session management. No obscure keystrokes to remember. Just session management and nothing else. In fact, I understood session management in that under 10 minutes video, than I had tried for a good 10 years. So, Thank you Bronie. Yes, there might be plenty other things required for complex setups, but for a desktop use and a home network user, that is exactly what the doctor would prescribe. 

 

 So, three main things which a session manager has to do. Create a session. Detach a session. Re-connect to a session. abduco does all the three with elan. All technicalities, I would redirect you to Mr. Bronie. So to create a session, let us understand what is a session. A session is a group of tasks related to one another. It is a method of grouping applications and open files related to a task on hand. Let us say the session you have created contains a compile task which will take another hour. Now, you are free to let us say, listen to some music, read a novel, well, things like that. What we now do is, detach the task on hand. And now, the compiling and all other windows are moved to the background and keep running. We will now create another session and do the relaxing stuff related to music and reading. You now want to continue listening to music and then you would like to check your online accounts like your email, your toots etc. You detach the multimedia session and start a new session with these applications. Its been an hour and you would like check on your compile session, You detach the online session and re-connect to compiling session and so on. That is session management for dummies. 

 

But in a session, if you have to have multiple windows grouped together, it is all good in an X environment. If you remember we are at a console running fbterm. We were very happy with good fonts but a bit sad about moving between windows as every window occupied the complete screen making it very difficult to share information between windows. Enter dvtm. The expansion will be dynamic virtual terminal manager. The name tells everything. It is there to manage windows. It will create, position, delete windows. It is an equivalent to i3 wm and more close to dwm wm but for terminals. When we create a new window in dvtm, we are starting a new terminal waiting for our input. dvtm does exactly what i3 does. It just arranges windows side by side in many different ways. But all your window contents are there for you to see and transfer between windows in the same screen. For our case it is a window manager for the console. 

 

I hated the console because if you wanted to refer to a man page and return back to the editor, you had to suspend the editor read up and remember the man page and then suspend the man page and bring back the editor to the foreground and dump whatever you remembered from the man page. This is no way ideal. For the optimal setup, we combine a session manager with a terminal manager and you have Window management for the console. How do we do it? Well just run both the commands in unison as so.

 

abduco -c session_name dvtm -m ^x 

 

What we are doing is asking our session manager abduco to create(-c) a new session and name that session "session-name" and the application it has to run is dvtm. The next option is for the MOD key. The default key for the MOD key is ^g. Yes, you are a bit confused here. For i3 users, the MOD key used to be a single key like the super key or the ALT key. But, these keys are not recognized by the console. So keep the default or change it to the value which I use, since x is close to the control key than the g key. Once you run this command, a session is created and control is handed over to dvtm. Now here you can start using the keybindings as suggested in the man page of dvtm. MOD-c will create a window in the tiled mode. Another MOD-c press will create another terminal window and so on. MOD-j and MOD-k will move between the windows and all windows are available in one single screen. 

 

I cannot express my joy, when I saw my console splitting into multiple windows. For everything else there is MasterCard. You did plenty of work by moving between windows and your program is now copiling. Time to relax. Detach the session by pressing MOD-\. You now land back at your console. Now run another command as so abduco -c relax dvtm -m ^x You get a fresh canvas. Create multiple windows again for playing your music with lyrics, reading a book by the next window. 

 

Enough of recreation, back to work. But, you want the music continue to play and want the book you were reading to be at the same place. Detach this session again by pressing MOD-\. Run without any arguments, abduco, will list all the live sessions. Run this command with the session name abduco -a session_name Now you are connected back to your compiling and editing session with all the windows as you left them when you detached from this session. The compiling is not complete, detach again and then re-connect to your relax session and continue reading your book. 

 

You are smiling. Your low spec PC is so responsive. But, But, We are living in a modern world and it is very difficult to survive without a pdf viewer, an image viewer, a video player, an ebook reader, a music player, a text reader(should we talk about it), web browser, a spread sheet, a document writer, a presentation tool and what not........ 

 

Let us try and resolve these applications one by one.

1. Let us start with a pdf viewer. This was rather easy. I was happy that the less command is more than capable of displaying text based pdfs. It will display pdfs with images, but the images are ignored.

2. An image viewer. For this the framebuffer image viewer, fbi is upto the task and is enough for viewing images and also includes the capability to perform a slideshow of the images supplied to the command.

3. For a Text reader/editor we are spoilt for choice and I would rather not talk about the options here. Whatever I talk about would be less.

4. If we come to the web browser, we do have choices, but none capable of handling 2 - 4GB of modern websites. We have applications for displaying true html. Blogs written with text only are a joy to read. I would recommend w3m. It also has support for images(I have not tried out this feature). If you access gopher holes or the modern avatar, the gemini space, then you are in luck and there are plenty of options. With the gopher and gemini protocol, you are at home in the console. Want to access your banking site, forget it.

5. If you are on the fediverse, there are clients for the mastodon network. There are clients for reddit.

6. For reading ebooks like epubs and mobis, I would recommend epy.

7. For searching the web we have the duckduckgo client ddgr and surfraw. Both are powerful and meet all the web searching requirements. 

8. Playing music has always been easy on the console with plenty of applications. My personal favorite is the mpd and mpc combination with ncmcpp added into the mix. 

9. For playing video, mpv is my default goto. The framebuffer device plays most of the videos thrown at it. 

This has already been a very long post. If you made it this far, then you are definitely a console junkie. If I could give you a hint of the entrance to the rabbit hole, then I would be most happy. Dont forget to buy yourself a mechanical keyboard. Thanks to all the devs and users who wrote all those wonderful applications and of course GNU/Linux. The journey with the tux and the beastie and the puffer since the year 2000 has been nothing but joy. I would like to end the post with the tagline of distrowatch. "Put the fun back into computing. Use GNU/Linux, Freebsd, Openbsd, Netbsd, Plan9, templeos, Haiku, Minix, GNU ..."



Friday, June 12, 2020

Well, What is on my raspberry pi 4

The first thing I install is my client for the cloud based notes application. I use simplenote. It has the advantage that it is available on all the major platforms. There is a terminal client called sncli. This is my go to client.
The next thing is to install terminology for the terminal. After trying out many, I observed that terminology is the fastest on the pi.
i3 window manager. I cannot live without it. None of my Gnu/Linux installations is complete without this. It is lightweight, easily configurable and simple.
For the browser, since I have started using computers I have sided with Firefox. I am at home with this browser. I install noscript, ublock, privacy badger and dark reader plugins. I like it. It has always met my expectations.
For the application launcher i go with rofi. The run menu is shown in a small window in the bottom left corner of my monitor.
For searching on the command line I use ddgr(DuckDuckgo client for the terminal) and surfraw. After installing surfraw I install a small script called menu-sufraw available on github. This integrates beautifully with rofi. Must try.
For the office suite, My choice was OpenOffice before it went to the butcher's table with the Apache foundation. Now it is libreoffice. I like it. It gets the job done.
For my text editor, wait, wait, I use both Neovim and Doom emacs as demanded by the situation. I use emacs with the client/server model. It is quick and very snappy to start and to work.
Feh for my wallpaper needs.
There is one more plugin which I install on firefox, it is called play-with. This I combine with mpv. We now have an awesome combination for playing streaming content on the pi. For this configuration to work there is one more piece of software required and that is youtube-dl. A beautiful example of the unix philosophy working for the modern age of the internet.
Not to forget that all the apps are in dark mode, if available. I like the dark mode. It has been excellent for my eyes. Even now when firefox flashes before loading a tab, I close my eyes for a while. Thank you, Apple, only for bringing the dark mode into vogue.
My hardware setup is already discussed in one of my previous posts.
font-awesome for that "graphics" in the terminal.
d2code for the font, wherever possible. I like its legibility.
I use i3status showing the date, time, empty space, processor speed and the temperature.

Thanks to all the devs/users of all the freedom software. My respect to one and all without which this post wouldn't exist.

Thursday, June 4, 2020

Long live the freedom software movement

There have been many examples of organizations taking up GPLd code and trying to spin a business model around it(Let us call it organization A). The catch here is that the code is available in the public under GPL. If an individual or another corporation(Let us call it organization B) sees that the offering is costly and the terms offered are too stifling they still have the access to the same code. Let us say that that A has now sweetened the deal with improvements and additions to the code base and offers that as the premium to B. Now, B has the option of taking the improved deal form A or asking for A to give out the improvements to the original code base since the original code base was GPLd. This is where A loses its head. This is where A drops its towel. This is where many organizations understand that it is not a viable model.

But there have been examples of organizations making money out of GPLd software. The important ones coming to the mind is Redhat and Suse. At a time when even redhat didnt have a commercial offering, suse had only the commercial offering. All these people started working "around" GPLd software. They did not work much "on" the GPLd software. Whatever utilities they developed to wrap around the GPLd software making the users adopt GPLd software was aimed with ease of use and technical support and customization for the clients. This worked and companies were successful with this. The object of business is profit maximization. There are plenty of strategies to do it. The problems while doing business with GPLd software is the ethical dilemmas. You want to be true to the GNU philosophy and you have to maximize shareholders profits. As you start wanting more returns from GPLd software that is where you start spiraling down. That is where you are extracting blood instead of milk from the cow's udder. Now, the money you are making is blood money.

Now comes a biggie who thinks that he knows how to make more money from GPLd software and buys the smaller and a better ethical vendor. Without even having a plan to integrate the ethics and the working of this company. The integration plan is one of the most vital thing for a successful takeover. You decide whether you want the smaller firm to continue with its ethics or completely break it down and merge with your profit making culture. There is no road in between. Many mergers and acquisitions have failed because of this. For big corporations it is better you kill it totally like google or microsoft. Take out whatever assets that can be proprietarized and throw out the GPLd ones. The problem arises when you think of proprietarizing GPLd code. There might be plenty of code written by the acquired company under GPL. But just because you wrote it, you dont own it. It is in the GNU world.

Efforts are on to kill the free software movement. Efforts are on to destroy the free software foundation. Efforts are on to kill the GPL. And this time it is a totally co-ordinated effort from all the bigs. We dont know how it is going to end. But we know for sure that the GPL document has stood its test of time. It has been framed with the core human societal values at its core. It has not been framed for profiteering. It has been framed with the basic human ethic of "sharing". They all thought that they bring down RMS they bring down GPL. They are wrong. They should have done it the other way round, then it might have worked. But, now it is not working. People are sratching their heads. All their lawyers and PRs are working overtime to malign the GPL.

So, clearly now is the time to advertise freedom software. Now is the time for all the individuals and ethical groups to spread the word of freedom software. Now is the time to share. Now is the time to side with the free software foundation and identify the blobs in the free software foundation and replace them with GPLd code since we have already lost the Linux foundation for the blobs. Now is the time to start GPLd software. Yes they are not flashy, Yes they are not easy to use. Now is the time to make them flashy. Make them more usable. Make them more known to the public. Now is the time to celebrate the contributions of one and all made to the freedom software world. Now is the time to provide due recognition to all the developers who work both for earning and for human ethics. Now is the time to spread the names across the public network. Now is the time to dig out the the name sof the contributors on which all the proprietary world of software is standing. Now is the time to tell that Macos and ios are visual shells on BSD code. Now is the time to shout that the flashy PS4s are just an interface to the awesome BSD code. Above all now is the time I request all developers developing for fun for serious ethics to please release their code under GPL and not under any other permissive licenses.

As a long time GPLd software user, I salute all the freedom software developers and thank them from the bottom of my heart for providing the world an ethical alternative.

Long live GPL. Long live RMS. Long live the sharing ethos.

Sunday, October 6, 2019

So near to a Desktop..............Raspberry Pi 4

Its been a long time since I wrote anything technical. This particular piece has been long overdue. The public network is full of ideas of what not can be achieved with a raspberry pi. After owning the original pi and surprising plenty of people with its capability to output videos at full HD, You know, I was eagerly awaiting a pi with 4k capabilities. Many people were surprised at the announcement of the rpi 4 and its capabilities. I for one thought that the maker and I have a connection. But, yes, the connection lost lots of packages between. So, what have we got in terms of what I really wanted

1. 4k desktop(I don't know which monitor gets the capability at 60Hz. My monitor defaults to 30Hz whatever I try. I think we are talking about the latest HDMI standards)
2. 4k movie playback is still patchy. I think it will get better with the foundation/users/developers hacking away at it
3. USB 3.0 support is a major leap(We will discuss below how, this is a radical decision)
4. USB C charging is also welcome with more power headed its way(But not enough)

The best OS to run on a rpi4 is no doubt raspbian. Yes, it is still a 32 bit OS. But, wait, the foundation is supporting all the pi's dating back to the first one. Kudos to the team.There are plenty of options for running 64 bit OS developed by groups and hobbyist OS enthusiasts. They are limited by the quirks in the hardware and its hardware acceleration. The memory limit issues have been resolved. Now it is only about video output performance to be bought on par with the 32 bit raspbian. As we are speaking there is a thread testing out a 64bit kernel with 32 bit userland. For running the latest Firefox, a 64 bit kernel is now a prime requirement and the rpi hackers are getting there. Tried all of them out there. They all have certain polish out there. They run faster, they are stable enough. But, video output performance has not reached the 32 bit raspbian level. I always came back to raspbian by restoring the backup.

The foundation was little brave this time and touted the rpi 4 as a desktop replacement. That claim, is very gutsy. If your desktop requirement is to run a browser and not wanting to watch High Def videos multitasking with office suites, then, the rpi 4 is good enough. Oh, oh, wait. Before telling me otherwise, I do agree that ou can improve the performance and extract more juice out of the pi by investing a little more of your time an accessories. To bring the performance of the rpi 4 to a desktop level, you would require

1. A heat sink with fan(money) This is a necessary investment. Your rpi 4 runs very hot. It has to be cooled down or else you will feel the throttling. Even opening one single application raises the temperature to the max.
2. An sd card with highest transfer rate possible with corruption resistance(I came up with that)(money money)
3. Buy the original usb c charger. There have been reports that the rpi4 is picky when it comes to usb c chargers(money money money)

With the above items, and a little bit of overclocking and some software optimizations the rpi 4 is definitely nearing a desktop feature set.

A real desktop will definitely demand storage space. Here the usb ports come into play. The two usb 3.0 ports are a god send. Just connect your external HDD's and you have the storage capability of a desktop. A good desktop also has Bluetooth connectivity and 3.5mm jack connectivity. You are completely covered here. A good desktop of course has to have a keyboard and mouse connected. Your are covered here also with the two usb 2.0 ports. So you have to connect more usb devices, like another external HDD. Your Pi will die here. Now, it is time to invest in a powered usb hub(money X 4). Be careful here and buy a good one and check the power distribution among the ports in the hub.

A monitor. What is a desktop without a monitor. You definitely will have an old monitor lying in the attic. It is time to brush it off and connect it to the pi. Oh, you are far ahead and have a 4k monitor a 4k tv, rpi has you covered. The pi is very picky when it comes to supporting 4k. You might be out of luck for older ones. Buy a good hdmi cable. Or, better buy the official one. The desktop feels snappy. Choose your apps properly. Prefer functionality over eye candy. In this way you can get more out of your pi. Yeah, I heard you. You can always get a "mini" desktop from various vendors. But, I would like to stop you here. Will it be as hackable as the pi. Will it have the whole world building things for it. Will you be able to search the public network for issues and resolutions. Will you get to run Debian GNU/Linux as well as the pi can run. Will it be credit card sized. Will you enjoy it. Will it give you joy.......

Now, coming to the most costliest investment to extract more from your pi. The ssd. This is a must. The loading of applications from the sd card is pathetically slow. Opening word processors/modern web browsers will be slow(When I say slow, I meant in comparison with a desktop with the latest desktop processors from the big guys). I recommend strongly to invest in an ssd. All of a sudden, the rpi 4 becomes a "real" candidate for desktop space. Suddenly the pi feels snappier. It boots faster. The copying, installing, upgrading are faster. Applications load faster. The UI is very responsive. I can go on. It is highly recommended to go for a ssd on immediately buying the rpi 4. What would be the size? Well, you have been running your pi from an 8 bit card(Yes, even now that is enough). I dont think you get an ssd less than 32 GB. So go for the minimum sized ssd, if you are hard pressed for money otherwise, go the full monty and go for a bigger drive with enough space for all your data. It is upto you. But buy an ssd. Though I am stressing the requirement of an ssd, it is important that you appreciate its requirement. I suggest you run your pi from an sd card and then after a couple of months upgrade for an ssd. Then you will appreciate what I am talking about here and also why I spent a paragraph in influencing you to upgrade to an ssd. If you are seeing degraded performance after installing on a ssd, go here

Well, I observed that the post is not well balanced. It is like a non uniform graph, jumping about on the sheet. If you are reading it, you are definitely a fan of the rpi. So read on.

The public network is floating with optimizations available for the rpi 4. There are plenty of posts which help you to extract the last atom of juice from you rpi. Here are my recommendations. If you have any more feel free to share with me. Thanks in advance for all those efforts. Let me brief about my setup

1. rpi 4, 4GB
2. 4TB spinning HDD and a 1TB spinning HDD
3. 4 Port(USB 3.0) powered hub for connecting the above HDDs to the pi
4. Official charger for the rpi 4(This cant supply power to the second hdd)
5. 4K 32" monitor
6. Logitech wireless keyboard(K 400) with both keyboard and a touchpad. You will love this setup if you are invested in window managers. More on this later in the post
7. 8GB sd card
8. 128GB SSD connected to the USB 3.0 Port
9. A transparent case
10. Copper heat sinks for the main processor and the graphic processor
11. Fan

I have flashed the fully featured raspbian on the 8GB sd card. I then followed this excellent post to move the root file system to an SSD. Huge thanks to the OP and all the users/devs contributing o this huge thread. Dont use the option of using the method of device names like /dev/sda1 use the other option of specifying the id of the partitions for better compatibility and allowing the dirty job of allocating the device names to the OS by giving it a free hand and not doling out names which would make your device not bootable. If you are sure you are not going to connect any other disk then go ahead and do the first method. I suggest the partition id method.

Now it is time to disable the services which you don't want. There are plenty of posts and lots of directions in the raspberry pi forums for this. The sky is the limit and every user has his own requirements so go ahead and treat yourselves.

The default xfce4 desktop is quite good. That is if you are fan of traditional desktop environments. If you are a power user, then I would suggest you to shift to window managers. As their name they just manage windows. That is exactly what majority of us do when we fire up the desktop. For all other configurations we have the terminal. In my opinion, the most lightest terminal I have used to date has been urxvt. When I started searching for window managers and at last settling for i3, I was shocked to see that the majority of the configuration files shared by users on the public network mentioned urxvt as their terminal emulator. Once I started using it and configured it to my hearts content, any other terminal is bloated. When I fire up the rofi launcher and choose lxterminal, the hourglass is displayed for a brief amount of time. With an urxvt session, it is instantaneous. It is pure bliss. And when you are getting this response on a pi, it is a festival of sort whenever i fire up this emulator. I adore all the devs involved in this project. My favourite colour scheme is the solarized one and urxvt looks fabulous with this. Making it full screen without any borders and menus is........

The next piece of software I would like to talk is about youtube-dl. For all the command line junkies. This is a god send. Coupled with the unix philosophy of chaining the output of several commands, you have a miracle at your finger tips. Just combine it with omxplayer and you have a fantastic streaming solution. Did I tip my hat to the devs? Yes. Now, coming down to omxplayer. This is a quintessential piece of scripting to extract the maximum out of the video sub system of the pi. I am astonished at the video capabilities of the pi. All credit to the omxplayer devs. I do agree there might be some proprietary magic here. But, the foundation is working towards producing a good FLOSS representation of the graphics driver. All my best wishes for the team. Youtube does frequently defeat the purpose of youtube-dl but the devs have always found ways around it. I love you guys.


As always, all the ideas and optimizations mentioned here have been culled from all over the public network. If any credit is due, please drop a line and it will be acknowledged.

Saturday, January 26, 2019

Meeting RMS at Mandya(Once in a lifetime opportunity), Karnataka, India

As I have written in many of my blog posts regarding my introduction to computing in 2002. No event affected me more than the reading of RMS's escapades with the printer at the AI laboratory. There was something about the philosophy being churned out in the help file withing the church of emacs. Now, maybe if i had tried editing my configuration files in vi I wouldnt have come across this philosophy of sharing. I still am not sure what prompted me to fire up emacs from my RH 6 machine. I finished the tutor and the was looking for further directions. It was at that time I read the about page on emacs. From that day I have been an ardent fan of RMS and his strict idealistic ideologies which is a mouthful for many an individuals who take sharing as sharing and nothing else. It is very difficult to understand him. He is egoistic. He is very strict on his beliefs and ideologies. I still remember when he last visited India and was interviewed by swapnil bhartiya. He did not drink bottled water until he got a bottled water not manufactured by coca cola. The reason being that he was against some un-ethical practises by the said company in some part of the world.


Let me come back to the present. I was damn lucky to meet him in person at Mandya, Karnataka, India. The event was organized by FSMK(Free software movement, Karnataka). I did not know that such a group existed and am indebted to their efforts in organizing this event. Now, how did I know about it. I am not on any proprietary social networks. I got the information on Mastodon. This makes my decision to stay on Non-proprietary online information sharing tools more interesting. This place, Mandya, is around 100Kms from my place. It was a 2 hour journey. I was present in the auditorium an hour before the stipulated time. There were announcements made to the attendees regarding the mentioning of Linux and GNU/Linux. He was on time and he walked in to a rousing standing reception. And the first one liner was shot. "Dont stand for me, stand for free software" He removed his shoes and started his presentation almost immediately. He did not want to waste a minute. He wanted to get right to the point almost immediately. The organizers were shocked at his speed. It took some time to get their bearings. After 10 minutes or so into his talk, The Indian way of welcoming the guest with a Mysore peta(Traditional cap of Mysore made with silk thread and a sandal wood garland) was done.


His homework regarding the local issues were excellent. He asked for "Mandya Gowdara Tea". Since there was a delay he was given tea made from Tea bags he had brought all along. He spelt the name of the language spoken in our parts perfectly i,e, Kannada(Majority of the Indians who dont stay in our parts spell it Kannad, which is wrong). The most striking was the parallel he drew of our freedom struggle with the present software freedom struggle. His say was that to gain freedom we have to embrace things which we are not comfortable. Freedom is not free. We have to work for it. In the Indian freedom struggle though the British flooded the Indian market with ready to wear clothes from Great Britain(Of course the raw material was from India). We as Indians fought against it by announcing swaraj, wherein we starting spinning our own textile raw material and stitching our own clothes from raw cotton. This was definitely not comfortable at all. But that is a cost we paid for gaining the freedom we cherish(or taken for granted) today. Excellent point. He used the word "Svatantra", the kannada word for "libre" instead of "Uchita" for "Free". RMS, I love you.


The talk and the content was standard. The freedoms associated with the software licensed with GNU GPL v3 and above and why all the developers should use this version particularly and also mention "GNU GPL v3 and higher" which would make the job of the FSF easy when faced with issues regarding copyright.


As usual, the Q&A is where he succeeds or fails miserably


There were questions regarding privacy, china government's mode of working etc which received long and boring answers. Let us cut back to the little interesting ones.


Q. I wanted to contribute to the FSF. When I opened the contribution page I saw that the amount of information I have to give before even entering the payment details was more than that required for opening an amazon account. The contribution process should be simple and as easy as clicking a button
A. Oh. I dont know about this. e-mail me the web page you are talking about. The payment cannot be as simple as a single click(It is for the reader to decide what is right or wrong about his answer)
Q. Wil the development of GNU os continue
A. No. It will not be developed. We had all the userland utilities and were lacking a kernel. Now we have the Linux kernel.
Q. What are the future projects of fsf
A. Oh, you can see our website regarding where the money comes and goes. librejs is being developed to remove the proprietary JS being used.
Q. What about building social networks. Like GNU social
A. Muffled answer.(I dont remember much)
Q. Free software conservancy hosted few videos on its website requiring proprietary JS implementation which if not enabled is not allowing to be viewed and fsf is one of the sponsor of the event of the video. Isnt it ethically wrong
A. I cannot keep track off each and every activity of the FSF.(summary I dont know and I am not going to anything about it)
Q. As a first time developer I am very interested in making money. How am I going to make money by giving my code away
A. (Unclear points) followed by You can work as a waiter for a living and then you can code in your spare time for the public good. If I did not have this job then I would have been a waiter to support what I am doing now.


Thank you,RMS, for everything you have done and will do in your endeavor towards pushing freedom software. Yes there will be fallacies, there will be pitfalls. But walking the talk is what matters. In a world where ethics are washed out at the drop of a hat, we have you, as a benchmark for the philosophic side of freedom software. I wish you would live for eternity, negating all the naysayers.

Sunday, January 10, 2016

My tryst with Ian Murdock's Debian GNU/Linux

I bought an assembled computer in the year 2000. The hardware was assembled by friends from my computer science department(I being a Mech engineer). They installed me the "latest" operating system, Win ME. I was also very happy, friends visited my home to see my computer. They wanted to "see" a computer with 128 GB RAM and a blazing fast 650 Mhz processor. Before that I had used DOS to run foxpro programs for my 1st sem engg. The next exposure was using Autocad in my final semester. The computers in the college were old school and "just" enough to run the required app. Played around with my new computer. Heard a heap os mp3s, watched a few movies on vcds, played a few games and thats it. After a month, the only result was that I learnt Autocad with great proficiency. After this, it got boring. Did not touch for around a month later. During this time, while discussing with a friend who had just joined a UNIX course. He did not know that he was learning GNU/Linux, Not his mistake.(At this juncture I did not know anything except Win****. Infact I did not know that there was another operating system). So, let us excuse my friend here and request the reader to excuse me too. Now in the discussion happening what caught my fancy was that my friend was repeatedly telling me that it is a tough nut to crack and one life time is not enough to learn *nix. Let us go back to the day I bought my desktop. I fell short of a 1000 bucks while buying it. So, the shop owner sent the person doing the assembly to my house with my friends to bring back the money. Once the desktop reached my home, All the components were quickly connected, hdd formatted and winME installed. Now, my computer science friends started having a chat with the assembler. The assembler told that he had learnt to install a new OS called Redhat 6 GNU/Linux. This caught the fancy of my computer friends and they asked him to show them the install methodology of Redhat 6 GNU/Linux. All this while I was a mute spectator. I just took care of all my friends with the snacks department. The assembler started the installation and I believe it took an hour or so. Once the installation was over it was late in the night and everybody just went home. My friends told that they would visit me again in the course of the week to "format" back the installation space taken by the GNU/Linux system.

Now, let us come back to the friend who told that *nix was a tough nut to crack. Since all the use case scenarios of win ME was exhausted I thought of venturing into fresh waters. Came back home the same day and booted Redhat GNU/Linux 6. I was dropped to a terminal with a blinking cursor with a black backdrop. I did not know the login ID and password. Immediately requested and begged my father for giving me money to buy a book. Went to the biggest store in Bangalore and bought "Redhat Linux 6 UNLEASHED". Here I came to learn of VI and Emacs editors. Somehow I though emacs was the editor for me. While reading the documentation for emacs I came across the history of GNU and the GPL licenses. I was glued. I just was at awe at the philosophy of "free as in freedom". After that it was learning everyday. I installed nearly all the OSs on my desktop. QNX, Minix and the like. Then Redhat GNU/Linux 7 was released and I recognised that GNU/Linux had arrived. From now on slackware, calderra, Mandrake and many others were tried. But I was always hearing about Debian GNU/Linux while on forums and reading magazines. I tried ubuntu somewhere here and applied for free cd shipping also and I did recieve them. But, somehow, my installations of ubuntu GNU/Linux always was not up to my expectation. There was a sort of "restriction". I cannot tell what it is. But I felt tied. This feeling I did not get while using any other GNU/Linux distros. After trying all the distros, I tried Debian woody. The installation, I thought was similar to slackware. But what caught my fancy was the way the distro was managed. The democratic setup, the clear responsibilities in the social contract, the "release when ready" philosophy, the plethora of packages and the wiki. I loved the distro. Being in India we were not luck in the internet department. I used to eagerly wait for stable releases. I had developed a relationship with a local cd/dvd vendor(Individual) who was selling GNU/Linux cd/dvd on his blog and was charging only for his efforts, true to the RMS philosophy. I would be the first customer for every major release from v 3.0 through 5.0 and I used to buy all the cds dvds not just the first one. While installing, my selction of sofware during installation would make me to swap the cd/dvd many number of times. I loved the release names owing to the fact that I am a huge fan of the toy story franchise.

My tryst continued with debian GNU/Linux after I bought a HP laptop. I have always documented my installation experiences on my blog. It continued on to a dell laptop. But, I got a high by installing the powerpc version of Debian Gnu/Linux on the PS3 while it was still supported by the otheros option. The last 15 years of my computing would have not been exciting if not for Debian GNU/Linux. I salute the vision of Ian Murdock. I salute all the developers/users/maintainers of this awesome OS. I always used to get a package for doing any task I wanted to do within the pack of the DVDs. Debian GNU/Linux is a part of my life as much as my friends/my family. I have spent more time on using Debian GNU/Linux systems than any other beside my job. Yes, I am not a pro. I am not a programmer. I am a GNU/Linux enthusiast. I am a fan of Debian GNU/Linux.

I request the force to give Ian Murdock all the peace he needs. His death didnt seem a normal one. I wish his family and friends all the positive force in the universe. This definitely applies to the man who spearheaded the development of the Universal Operating system.

Thanks a lot Ian Murdock. You definitely have left a mark in this universe.

PS: I had succesfully installed Debian GNU/Hurd also. That is one more Hats off to Sri Ian Murdock. Thanks. May the force be with you.