From the linked-to-post, it lacks:
* Programmatic output configuration (xrandr, arandr, etc.)
* CLI clipboard access (xsel, xclip)
* Third party app launcher/window switcher (rofi, dmenu, albert, docky).
* Clipboard managers (parcellite, klipper, Gpaste, clipman, etc.)
* Third party screen shot/capture/share (shutter, OBS, ffmpeg, import, peek, scrot, VNC, etc.)
* Color picker (gpick, gcolor3, kcolorchooser)
* xdotool
Lack of Wayland versions of these apps is a deal breakers for me, and I'm going to avoid Wayland until it gets them.
[1] - https://old.reddit.com/r/wayland/comments/85q78y/why_im_not_...
Why do we need Wayland?
Also, when I run X just for myself on my own laptop, what security issues do I have to worry about with X that I don't have to worry about with Wayland?
With regards to security, the main issue is that X11 provides no isolation between applications, allowing them to listen to keystrokes and the clipboard at all times. With Wayland, only focused applications have this access.
Currently I'm using an old, slow laptop, with a graphics card integrated in to the motherboard. Nothing special. But I don't do any demanding graphics processing on it. I just watch movies and use web browsers and a terminal. I don't play graphically intense games on it.
"With regards to security, the main issue is that X11 provides no isolation between applications, allowing them to listen to keystrokes and the"
I don't see why this should concern me or 90% of X users, because if any malware manages to run on our systems it'll already have full control over them without needing to resort to any kind of keystroke sniffing in X.
I'm struggling to think of a scenario where malware's running on the same machine with access to a single X session, which doesn't already have full control over the account whose keystrokes they'd be presumably sniffing. They could just substitute their own malware versions of web browsers, shells, editors, or whatever other software the user uses and sniff keystrokes in there, without needing to touch X.
Not that it hurts to have more isolation than you get in X, but I'd need a lot more convincing for me to give up the convenience I already enjoy with X.
Can someone paint me a realistic, relatively common threat scenario where not having Wayland's isolation would actually present a serious security risk?
A compromised web browser doesn't need X to control the rest of your system. It can usually already write all over your system and perform all sorts of other attacks, including substituting applications, paths, LD_LIBRARY_PATH, etc.. not to mention try kernel exploits and the like -- not that they'd need to on a single-user system, as they could just get your sudo password by one of the other means mentioned above, all without touching X.
Anyway, if a typical user's browser is compromised, they're already completely screwed, as they typically access their online banking and webmail through it. Once again, the attacker does not need to touch X to get access to any of that.
To me it still sounds like Wayland's security model is trying to solve a niche problem that most X users don't really suffer from -- and charging an arm and a leg for it.
Not necessarily. Properly sandboxed applications like Chromium have a seccomp filter, separate pid/user/etc namespaces and bind mounts setup to isolate themselves from the rest of the system as much as possible.
> Anyway, if a typical user's browser is compromised, they're already completely screwed
It really depends on which part of the browser is compromised. Again, Chromium has some pretty good isolation. Having one malicious website exploit a vulnerability does not necessarily mean the attacker gets access to any of the other browser data.
For instance, only the currently focused tab should have access to the X clipboard.
This is a bit naive. Browsers execute malicious javascript on your system all the time. A V8 sandbox escape is worth retirement money for a reason.
Wayland makes lots of things possible: multi-monitor HiDPI, touchpad gestures like pinch to zoom (just like Macs could do ages ago), touchscreen support that's actually independent of the mouse pointer instead of always dragging it along… and there's finally no goddamn screen tearing. Every frame is perfect™.
Might be true, never happened to me. But what about FPS in Games. X11 beats it there for me. Or what about in the most important metric of them all: Latency. In all my Tests Latncy on Wayland is always a regression, compared to X11. (I use Intel and HDxxxx era AMD Graphics, can not say anything about Nvidia)
> Wayland makes lots of things possible
That might be true. But X11 can be extended and has been extended very often (hence the messy code). One thing I need regularly, namely OpenGL pass-through via SSH, will never be possible with Wayland.
> Every frame is perfect™
To me far less important than latency. Wayland should only care about tearing when I play full screen games. When I type on the terminal I want my characters appear instantly, then I don't care about tearing at all.
On my own testing (GNOME, latest Kernel, as well as Sway temporarily) latency and FPS were better on Wayland than X11 (though only on my beefier graphics card, windows rendered on the second one had higher latency and comparatively lower FPS than expected. But I don't game on that card.
>One thing I need regularly, namely OpenGL pass-through via SSH, will never be possible with Wayland.
Correct because Wayland isn't a network-like protocol as X is (though I've had X network passthrough break or fill up a gigabit ethernet connection worth of bandwidth on more than one occasion).
If you want remote desktop on Wayland, you need a tool specifically designed for that.
It's the unix mindset after all; why have one tool (X) do everything when you can have lots of tools interact and each solves it's own little problems (Wayland + tools)?
>Wayland should only care about tearing when I play full screen games.
If you run a game on wayland you usually get control over the screen anyway when you go fullscreen, once you have exclusive control you can go tearing all you want.
Though with adaptive sync becoming more common (and already being common on laptops) the perfect frame is less costly than tearing; the display will run at the FPS you can manage (within bounds). For it to work you only need to VSync and the GPU driver handles the rest.
In my experience, Wayland has way better and smoother performance than X on adaptive sync displays.
Every frame is great. If a frame is missing, ### gets quite irate.
With Gnome et al you are most certainly in high latency hell on X11.
* Programmatic output configuration
swaymsg -t get_outputs # get displays
swaymsg output DP-1 pos 0 0 res 1920x1080 # set displays
* CLI clipboard access
swaymsg -t get_clipboard
* Third party app launcher/window switcher
I use gnome-panel with Xwayland, but better than nothing
* Third party screen shot/capture/share
https://github.com/foss-project/green-recorder
* Color picker (gpick, gcolor3, kcolorchooser)
Sorry, no options here yet, but it can be done
* xdotool
swaymsg [title="Top Panel"] floating enable, resize set width 2560 px height 32 px, move position 0 -38
Window managers can implement their own extra protocols of course, but instead of X11 where everything was standardized and window managers didn't even have to think about it, there is no standard and window managers have to rewrite all the code for it themselves.
It's not an "issue". It's a design decision.
As another example, Linux doesn't have just one desktop environment, like Windows or MacOS, would you say that's an "issue", even if it's a deliberate decision?
"GNOME and KDE have dbus APIs for some (but not all) of these things, and sway has its own IPC, and other compositors probably have similar solutions. However, they all use different mechanisms, which means that if you are writing say, screenshot application you either have to write a different backend for every compositor, or choose just one or two to support.
"Something all of these types of applications have in common is they need to be able to inspect and/or modify state from other applications or the compositor itself. Which wayland's security model normally prevents. I think a major gap in wayland, is having a way for an application to run with escalated permissions so it can have access to other applications. Unfortunately, I don't have any great ideas on what that would look like."
and then, later in the thread:
"for simple things using the compositor's screen shot tool is fine. But what if I don't like the screenshot tool for my compositor of choice? My experience with the GNOME screenshot tool (granted this was pre-wayland) was that it wasn't as good as, say, shutter, which has a lot of options, let's you easily crop and edit the screenshot from inside the screenshot tool etc. And then swaygrab doesn't even (currently) have an option to capture a rectangular region."
The entire thread linked to above is worth reading.
My own takeaway is that Wayland is just way too immature to compete with X for my power-user use cases.
It might be ok for users with simple needs.
https://bugzilla.mozilla.org/show_bug.cgi?id=1512416 https://bugzilla.mozilla.org/show_bug.cgi?id=1509740