6 ms·
Apparently Electron was using a private API to tweak how window border shadows were rendered.[0] I leave it to you to decide how to assign blame. [0] https://g
by aroman 1y ago
Apparently Electron was using a private API to tweak how window border shadows were rendered.[0] I leave it to you to decide how to assign blame.
[0] https://github.com/electron/electron/pull/48376 https://github.com/electron/electron/pull/48376
- sersi 1y agoIf any apple app uses a private api then that api should be made public and documented. Having private apis is unfair competition and bad practice
- friendzis 1y agoThere's no meaningful difference between "private" and "documented, but changing every patch release" from userspace POV, yet not committing to documentation saves development effort for the same result, hence "private" APIs. If anything, private apis let "system" apps run at userspace, reducing attack surface dramatically.
- aakkaakk 1y agowtf am I reading? No no no. Undocumented apis callable from user space, that can break the OS, is a security flaw (in the OS). It’s why people laugh at windows.
- biohazard2 1y agoCan we blame the Apple employees who apparently never tested their new OS release with any Electron-based application?
- fragmede 1y agothe reason for having a large public beta process would be to get broader testing that definitely should have found this
- rollcat 1y agoHow else do you get the message across? Do not use the private APIs. Electron is most likely using a whole ton more. Apple is sending a message. "Fix your crap or expect more."
- freetanga 1y ago... and in the process we will deteriorate the performance of millions of users and hurt our brand as a top class experience company? Don't really care who is to blame, but they should have identified this, and either warn developers, or warn users. Or provide a tool for identifying guilty apps in your machine, and let users decide how to proceed.
- biohazard2 1y agoI can think of multiple ways to pass the message to Electron developers: - Open a GitHub issue explaining those private APIs shouldn't be used. - Even better, open a PR fixing their use. - Make those API calls a no-op if they come from an Electron app. - Fix those API calls not to grind the OS to a halt for a seemingly simple visual effect. - Create a public API allowing the same visual effect on a tested and documented API. Choosing to (apparently violently) downgrade the user experience of all Electron app users, without a possibility to update at the launch day, if a deliberate decision and not an overlooked bug, is a rather shitty and user-hostile move, don't you think?
- ricw 1y agoThe beta has been accessible to the public including the electron devs for 2+ months.
- zer0zzz 1y agoI’m glad they broke it. People that use private APIs in their apps must suffer.
- friendzis 1y agoWhat's private API? If it is accessible from userspace it is by no means private. Does it mean the API is private in the sense of "unstable" interface? It could very well break the userspace app relying on undocumented behavior, however, crucially here, anything that is exposed to userland WILL at some point be used by some application, be it legitimate or malicious, and it should not break the OS in any way. That's basic hygiene, not even security. inb4: yes, userspace app could trigger e.g. millions of io operations and millions of number crunching threads and thus cripple the rest of userspace (or at least the rest of userspace at given priority level), yet the system part should still run within performance envelope. Insert "Task Manager (Not Responding)" meme.
- fingerlocks 1y agoIt’s not in a public header. You can easily snoop “private” properties and methods quite easily in Objective-C, because the concept doesn’t exist. It doesn’t exist in C either, but if you roll up your sleeves and figure out the memory layout and offsets, you can do whatever.
- friendzis 1y ago> if you roll up your sleeves and figure out the memory layout and offsets, you can do whatever. So we are talking about public/private access specifiers in source code, which only matter in cooperative setting. But that's IMO highly naive view as compute, especially OS, is objectively an adversarial environment. Some actors, at some point WILL figure out the memory layout and use that in an attack. There have been literally decades of whack-a-mole against bad actors. I maintain my stance that any fields/members/methods loaded into a userspace program should not be capable of breaking the system.
- atonse 1y agoPeople using private APIs know that they might cause instability (in their apps usually). That's why those APIs are private, they can change since there are no guarantees. I'd point fingers towards the electron core devs for this one, and not devs building apps on top of electron (since they likely didn't know that's how electron was doing it). There are cases where OS companies noticed the use of private APIs and made cleaner public ones (the most obvious was the file system syncing stuff used by Dropbox and others, which used to use private APIs until Apple provided a public one).
- krferriter 1y agoBreaking stuff just to add more complicated border shadows. Crazy priorities.