Does Wayland really break everything?
pointieststick.com
pointieststick.com
From the point of view of the Dev, the product that was created is perfect, satisfying in term of design/technical specs.
But the dev does not care about the users experience. He does not realize that the most important is not how it is done or to be conceptually perfect but to reply to user needs. To do the job.
No one cares about the thing being changed/reworked, to use x, wayload or whatever but everyone expect basic features (available for decades everywhere) of Desktop to work easily out of the box. Like screenshots. If you can do less things than what you can do on windows, that is a huge failure.
There's some argument to be had for what features are "basic", but as far as I know, I've been on Wayland for a couple of years now, and e.g. screenshots, screen sharing, multiple monitors all work. The post mentions things like remote control and drawing tablets, which I understand are important to people - but I think everyone would agree they're a notch above screenshots?
And instead of working to address the issue, most of the "community" refused to acknowledge there was one. Suggesting otherwise was the start a flame war.
The fact that simple acknowledgment is still a work in progress after 3 decades is a less than hopeful sign for the future.
Wayland supports apps that are basically untrustworthy. Apps can talk to wayland, but not too much to each others, certainly not in ways not envisioned by wayland. The desktop is a huge melee of backstabbing bastards, each shovelling as much user data as possible to their vendor.
The X view of the world is one of trustworthy cooperation. A bit naive, a festival for crapware, but also a way to unlock unexpected possibilities.
I'd rather see a cooperative, creative future where bad apples are weeded out by social mechanisms, even if it means an occasional malware victim. But understandably the IBMs of this world would rather see rows and rows of easily swappable locked down minions for their workstations, and they are the ones paying.
I fear the bureaucratic stagnation that will unavoidably follow from wayland as it is now.
Cooperating via a display server seem like the wrong way for ferrying arbitrary data across processes to me.
Where we disagree is the concern that it is an app that should decide who can communicate with it. No. My desktop, my decision. This is a political concern about ownership and what it means.
It is also part of freedom of end users to macgiver their desktop as they see fit. It unlocks e.g. unexpected accessibility and workflow benefits, unforseen to the authors of the app. These experimental setups learn us better ways, after which, a professionalization and real interface can happen if enough users want it. I fear we will loose these experiments with wayland's portals.
That X11 compatibility protocol repo isn't the worst idea, but we'll probably find that the core and extension protocols will cover everything - in a purposefully designed way - in the long run anyway.
I do somewhat sympathise with the sentiment that running untrusted apps is bad and FLOSS ecosystems are good. But even then, building a security framework around windowing does seem appropriate given the broad range of uses that Wayland will see.
While it also serves as a security mechanism the most important benefit of memory protection is that it protects against processes *accidentally* corrupting other processes due to mistakes, invalid pointers, etc.
If you want to intentionally mess with other processes memory most OS give you the means to do it in a controlled way, with ptrace in Linux or WriteProcessMemory in Windows, because sometimes it is a useful thing to do.
The problem with Wayland is that they veto useful features they aren't interested in (that admittedly if misused could be a security problem or at least a nuisance) and they don't give any alternative way of doing them, choosing instead to punt the problem downstream to the compositors, who will each do them (or not) in a different way making the whole thing a mess.
Conversely the locked & secured Linux platforms - Android and SteamOS are currently a festival for crapware.
Wayland was unilateral. It wasn't a choice by users, but by companies.
If you are not paying for it, you become eternal alpha/beta tester.
In the Desktop Linux ecosystem the added 'security' by Wayland is indeed marginal when every app can access the whole filesystem.
That's no longer the case with flatpak apps, which are gradually becoming more popular; some of them might still have access to the whole filesystem, but most of them are limited to sharing nothing or at most a couple of specific directories.
I ran Wayland for sometime but went back to x11. Key gripes
1. Screen sharing 2. Automated keystroke entry(keepassxc) 3. Many more niggles
Get x11 out of my cold, dead fingers.
All this to say that Wayland might be the new go-to for new users since they can't tell the difference? Idk.
Security has always been a hard sell to end users because the costs are immediate and tangible while the benefits are in the future.
In the case of a bridge, in terms of material, time, and money. In software, it depends on the program, but it's usually some combination of performance (e.g. encryption), cognitive overhead (remembering passwords, access policies, ...), accessibility, development time, and a few other things. And notably (for Wayland), features --- locking down a system naturally reduces what a system can do. Note that this overhead can be a blocker. Accessibility is an obvious one (e.g. take those numeric keypads that randomize the order of digits presented on the display each time you want to unlock them --- blind people will not be able to use those), but features can also be a problem: if part of my work requires commonly taking screenshots (e.g. because I work as a technical writer, and need screenshots for documentation reasons), then I won't be able to do my job. In fact, the corporate world is chock-full of (maybe even sensible!) security policies reducing efficiency of workers, or sometimes outright blocking work.
What I'm trying to get at is, security requirements depend heavily on each user and use-case. And I think Wayland's fallcy was in trying to shoe-horn everyone into this vision of a fully-sandboxed world without considering the practicalities and what people actually want or need.
For example, I keep my personal desktop (which I mostly use for gaming & FOSS work) far less secure than my work computer (which is also in my apartment, as I work from home). Because I've deemed the overhead of trying to better-secure my desktop, unlikely to get stolen from my apartment, as unnecessary overhead. Meanwhile, my laptop, which I also use for gaming & FOSS work, is more secure, as I tend to take it with me when I go on a trip. Because while the severity of a breach is the same as for my desktop, the probability is much higher.
So I have three situations, and I'll argue that no single security policy would be a good fit for all 3: (or even two) - Home desktop => low risk of breach, moderate impact if breached[*] => low security - Home work PC => low risk of breach, high impact if breached => high security - Laptop => moderate risk of breach, moderate impact if breached => medium-to-high security
That, I think, is part of the issue people have with trying to sell Wayland's flaws as "security". It's basically a one-sided "I'm changing the security policy, and you better pray I don't change it further". When said security might be more than just undesirable, but an active obstacle. At the end of the day, Wayland is a tool. It has a job and a purpose, and yet it can't even properly do some things of the tool it's meant to replace. Because "security".
([] If you disagree that it's an overhead, then I'm going to expect that every single door in your home, even the fridge & closet doors, are packed with as many heavy-duty locks as will fit on the physical door. And that each door is always locked unless you're currently actively interacting with the door. For starters.)
([*] Yes, I realize the issues with an attacker being able to access all my accounts and such, but I'm putting it in relative terms compared to the work PC.)
Also I feel like I've been waiting a decade and I still can't do fractional scaling on wayland last I checked.
Regardless of what you think about the general topic, xorg is not well supported anymore. People who maintained it largely work on Wayland. There aren't people available to do new releases. The workflows are still there... for now.
https://wayland.app/protocols/fractional-scale-v1#compositor...
Same on Windows. I have a feeling, that for some reason, the fonts and the widgets are scaled separately and then stiched together.
And it's confused greatly by the fact their own software appears to be layers of frameworks, eg windows explorer and the 1000 different settings apps they have..
Win32 applications have to announce that they are "High DPI aware", either via a manifest file or programmatically at startup (the details have changed several times between Windows XP and Windows 10). Failing to do so results in an upscaled, blurry UI, and failing to use the latest API may result in some features not working (such as automatic adjustment when moving a window between monitors with different DPI).
https://lists.x.org/archives/xorg-announce/2023-December/thr...
The fact that this post was written in the first place is a litmus test of how utterly broken Wayland design is if it has to be defended by a core KDE developer.
You can find similar posts for every change - not only about Linux. The only thing existence of such posts prove is that people have strong opinions about something.
Huh? That makes no sense. If the dev had not defended Wayland, would you have taken that lack of defense as evidence that wayland is good? If not, then it is irrational to take the existence of this defense as evidence that wayland is bad:
https://www.lesswrong.com/posts/jiBFC7DcCrZjGmZnJ/conservati...
I remember using an SGI workstation around 1992 which had a perfectly usable and complete X11 desktop environment, which according to Wikipedia was 5 years after X11 was released (1987), and 8 years after the X Window System was invented (1984).
Wayland has been in development for 15(!) years, has a much smaller scope than X11, and it's still a hot mess. I doubt that the 1980's programmers were so much better or more productive than the programmers working today on Wayland, which in turn means there must be something fundamentally wrong with the basic idea or design of Wayland?
Basically, moving on to an X11 successor should be a no-brainer for all Linux desktop users and not require one justification blog post after another why some things don't work anymore as they used to.
Times change, requirements change, thereby software has to change.
There is actually a really good point in the article that "(desktop) Linux isn't a platform", but instead a fragmented mess of individual frameworks and systems (which after the Wayland transition may or may not eventually reach feature parity with X11 again).
This fragmentation in the Linux desktop world is indeed the core of the problem which Wayland should have helped fixing instead of making it worse by spreading functionality that was centralized before over even more unrelated systems (meaning just more things that can individually break).
Compare that to non-desktop Linux, which actually is a platform (and because of the simple "Don't Break Userspace" rule has wiped the floor with other operating systems in data centers).
So it is kind of frozen set of POSIX stuff, good enough to have OS agnostic programming language runtimes on top, and that is it.
It is no accident that the new wave of FOSS IoT OSes aren't based on Linux, rather on MIT/Apache/BSD based kernels.