Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
taway098123
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
taway098123
5y ago
There's no code I can show you that would be any more convincing than just looking at the code to the X server and then looking at the code to any wayland implementation. There's not anything particularly special about these proje
2.
▲
by
taway098123
5y ago
I was familiar with that documentation around 10 years ago, please stop making these assumptions and please stop dismissing what I have to say. The documentation is irrelevant, I'm talking about the server source code. There is one re
3.
▲
by
taway098123
5y ago
As someone who has done both, I respectfully disagree.
4.
▲
by
taway098123
5y ago
It's not wrong, it's not FUD, and that doesn't change anything. The only working plugin is the SELinux one. If you can't use that, you have to rebuild an entire new security architecture... which is what they had to do i
5.
▲
by
taway098123
5y ago
There isn't really much difference. It's about the same amount of work either way to ship an extension. In Wayland, you make the extension, then you patch every compositor, every toolkit and every application. In X11, you make th
6.
▲
by
taway098123
5y ago
XACE doesn't solve it. As mentioned elsewhere, that's dependent on SELinux. The idea with Wayland is to make things more secure everywhere, and not just on systems that have a particular LSM.
7.
▲
by
taway098123
5y ago
I completely disagree with everything in your comment. Wayland is an attempt by some developers to fix some longstanding issues with X11. They know what the new issues are and there is active work being done in preserve back compatibility a
8.
▲
by
taway098123
5y ago
Dbus won't allow it because you have to switch to that user before it lets you connect. You would have to have whatever is doing the access running as root and then change its user. There's not really any magic here, it's jus
9.
▲
by
taway098123
5y ago
I'm sorry about the throwaway, it's a long story. You're crossing a security boundary trying to access other users' GUI programs. The session bus is for programs that are private to the user's session. Accessing tha
10.
▲
by
taway098123
5y ago
Yes it can, why wouldn't it? You can make a program that connects to more than one bus. Though that would probably be crossing a security boundary. The simple way to make multi-user services is to just deploy them on the system bus an
11.
▲
by
taway098123
5y ago
You just kill the process, which causes the file descriptor to close. Cancelling the inhibitor lock by other means wouldn't do much, there's no way to get out of that situation without forcibly shutting the process down or disrupt
12.
▲
by
taway098123
5y ago
Dbus is mostly just a message queue for Unix sockets. Think Kafka or SQS but only for local services.
13.
▲
by
taway098123
5y ago
>a protocol prescribes exactly the intersection of all implementations. That's a better way to put it and that's more what I was getting at.
14.
▲
by
taway098123
5y ago
I hope someone comes along to review those, but I don't see there being much interest in it.
15.
▲
by
taway098123
5y ago
Everything you're saying is... mostly what's been happening? It's not impossible to have consensus. You're missing my point which is that people were trying various solutions since 2008, and there just wasn't any co
16.
▲
by
taway098123
5y ago
There's plenty of ways to securely multiplex Ethernet devices. You don't give your web server read access to all TCP ports being used by other services for example. You only let it open the HTTP ports. There are of course ways for
17.
▲
by
taway098123
5y ago
I mean, no, it's not the fault of Weston developers that other implementors decided do their own thing. I asked this before but what could they have done? Putting tons and tons of things in the spec wouldn't really have fixed the
18.
▲
by
taway098123
5y ago
The usual place those permission dialogs have gone is the flatpak portal, which is separate from Wayland. Someone would have to implement it there.
19.
▲
by
taway098123
5y ago
Any implementor always has permission to do their own thing, that's the point of making a second implementation. Putting something in a spec somewhere doesn't make it mandatory or guarantee it will be implemented. They could have
20.
▲
by
taway098123
5y ago
I don't see how I am, and I don't understand your point. The reference implementation had screenshots. The other implementors decided not to copy that and did their own thing. What more could the Weston developers have done? They
21.
▲
by
taway098123
5y ago
You misunderstand, it was only Weston that was started in 2008, and it had screenshots back then. I'm talking about those other implementations, they didn't really stabilize and start aiming to have feature parity until a few year
22.
▲
by
taway098123
5y ago
Most developer activity related to Linux graphics is in dri-devel, it's been like this for quite a while. The X development channels have been mostly dead outside of discussion of XWayland. I doubt you'll see anyone starting any m
23.
▲
by
taway098123
5y ago
These aren't excuses, there are no other parties at play here. Weston was the first implementation. GNOME and KDE were the next implementations. They could have chosen to copy Weston's implementation, thus making those parts "
24.
▲
by
taway098123
5y ago
That's one way to do it, it's probably not the best way but it would work if you were planning to sidestep Wayland security completely. You could make it user controllable with dbus and then make a GUI to talk to it.
25.
▲
by
taway098123
5y ago
That seems like the reverse of the way it's always been on Linux, where there are only developers and no users...
26.
▲
by
taway098123
5y ago
If you have root access to your own system, or read access to /dev/input, then it's trivial to deploy a keylogger. No need for Wayland to get involved there. You can't log keys through the Wayland socket because that soc
27.
▲
by
taway098123
5y ago
All of those questions are really irrelevant. The point with Wayland is to make something that's more secure than the systems it aims to replace, not to make exactly the same thing. If you want to help, maybe show a way this can be don
28.
▲
by
taway098123
5y ago
Screen sharing and screenshots weren't an afterthought. Weston had support for those for a long time, but gnome and kde decided to do something different, probably because they saw pipewire was maturing. Allowing arbitrary clients to g
29.
▲
by
taway098123
5y ago
You misunderstand. In both situations, you're making a new protocol. The only difference is you'd be making your own thing instead of adding new packet types to Wayland. And why add new packet types to Wayland if the thing you
30.
▲
by
taway098123
5y ago
Not sure why you'd laugh or cry. Dbus is just an example. You can use another mechanism to build another daemon, it doesn't have to be built on anything in particular. I'm just saying, if you expect that Wayland is going to s
More ›