Wayland is a necessary part of security, but not sufficient.
Linux only grants permission to keyboard/mouse events to root or to display “owner”, which is the one who requested it on a given tty.
* Using ptrace(2) to hook into your running processes and grabbing key data that way
* Adding a LD_PRELOAD around your application launcher (via your .bashrc or some other auto-exec script) to have it intercept key events for your application
* Downloading and mounting a FUSE filesystem image with the /dev/input device nodes owned by your user ID instead of root.
* Use one of the multitude of privilege-escalation CVEs on the Linux desktop to gain root, and keylog you that way [1].
Come back when you understand the problem.
[1] https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=linux+privi...
How does X help here?
That there exist SELinux plugins does not mean that XACE itself depends on it. Like, try reading the actual documentation instead of regurgitating FUD: https://www.x.org/releases/X11R7.6/doc/xorg-docs/specs/Xserv...
It's also outside the scope of a desktop environment or window manager to ship plugins to the X server. Hence another reason why they had to go with a new protocol that makes it easier to implement their own server...
I stopped reading at this point. If you're not going to read the documentation, then you can kindly go crawl back under your rock on /r/linuxmasterrace.
Yes people could develop new plugins that integrate with some other security mechanism, but they haven't, in part because the hooks are so out of date, and in part because, you know, that requires building another security mechanism. The access hooks are not a security mechanism, they allow you to integrate with some external MAC.