I am a big fan of grsec, RBAC and sandboxing stuff. But let's be real here people! Those are good features on servers where there isn't a giant security black-hole called X, where any local exploit of the app can turn it into a compromise of the entire GUI system.
Look at the hoops that adversary resistance focused distros like SubgraphOS have to jump through just to mitigate the giant attack surface that X opens.
Until Wayland becomes the usable default standard, "Linux Desktop Security" is an anachronism.