Skip to content

v0.4

Choose a tag to compare

@jpzk jpzk released this 07 Oct 18:05

opensidian v0.4

The default theme is AnuPpuccin (GPL-3.0); bundled themes and the Catppuccin palette are attributed in THIRD-PARTY.md.

Landlock self-sandbox is opt-in (OPENSIDIAN_LANDLOCK=1 enables; off by default). Both AppImages boot-verified under Xvfb.

Verify: gpg --verify SHA256SUMS.asc SHA256SUMS && sha256sum -c SHA256SUMS

Changelog

New

  • Official app icon — the amethyst-cluster logo is the launcher and window icon in every package.
  • RPM for Fedora (sudo dnf install ./opensidian-0.4-x86_64.rpm) and .deb for Debian 13 / Ubuntu 26.04 (sudo apt install ./opensidian-0.4-x86_64.deb); both pull in their dependencies and are covered by the signed SHA256SUMS.
  • Debian 13 is now a tested distribution, alongside Fedora 44 and Ubuntu 26.04.
  • Graph: Forces panel — the graph-controls card on the global graph (open by default, collapses to a gear, reset to defaults).

Graph

  • Physics now follow the stock force model: 60 Hz steps, alpha target, the same repel curve, a per-node centre pull with the centroid held at the origin, and a fixed seed, so layouts look like the original.
  • The graph starts untangled: new nodes are seeded near the neighbours already placed.
  • Fixed nodes getting stuck: the Barnes-Hut tree's root cell is now built the same way d3's quadtree builds it.
  • Settling is checked after every physics step, not once per frame.

Security (audit fixes)

Thanks to Aikido for finding the issues fixed below and under "Robustness" (audit #1–#13).

  • Vault filesystem (audit #1, #2, #4, #6, #9): every vault write goes through a handle on the vault folder and never follows symlinks:
    • note saves, new notes and link rewrites;
    • delete to trash, move, new folder and attachment drops;
    • the files under .obsidian.
  • Temp files: random, created exclusively, then renamed into place. No more predictable md.tmp / .part-<pid> names.
  • Sidebar: the folder walk never descends into a symlinked directory and has a depth limit.
  • S1: the window can only navigate to tauri://localhost.
  • S3: with Landlock on, the first-run vault picker restarts the app into the chosen vault instead of opening it without the sandbox.
  • S7: telemetry records only lengths, counts and timings, never note paths, titles, search queries or folder names.

Robustness: huge or malicious notes (audit #10–#13)

  • Image embeds load lazily, so a note with 20k embeds no longer floods the image loader when it opens.
  • Live preview builds rows past 2,000 lines on demand, and trims highlighting on lines past 20,000 characters.
  • Unlinked mentions run in linear time; the list shows the first 200 hits and keeps the exact total.
  • Quotes nested more than 32 levels deep render as plain text.
  • The quick switcher batches title updates instead of redrawing on every keystroke.

Desktop integration

  • GNOME dock: the running window now groups under the opensidian launcher with its icon instead of showing up as a separate app with a generic icon. The window identifies itself as dev.koto.opensidian (Wayland app id and X11 WM_CLASS), and every desktop file carries StartupWMClass (.deb, .rpm, flatpak, AppImage).
  • Flatpak: switching vaults and "Open in new window" work. Before this fix the new window failed to start (bwrap: execvp opensidian).

Data safety

  • Vault switch: if saving the open note fails, the switch is cancelled. Before, the failure was ignored and an edit could be lost.
  • Vault switch: the new window takes the old window's real position and size.

Project

  • SECURITY.md: report vulnerabilities privately by email.
  • README: install section condensed; states that the project is not affiliated with Obsidian / Dynalist Inc.

Known issue

  • A click on a search result sometimes doesn't jump to the match (1 in 91 test runs). Being tracked.

Features

  • live preview, source and reading modes
  • [[wikilinks]], backlinks, tags, graph view
  • tabs, splits, search, quick switcher, command palette, bookmarks
  • themes, fonts, hotkeys; open a vault with opensidian <folder>