Announcement

Collapse
No announcement yet.

X.Org Server 1.16, Rootless X Now Available For Arch Linux

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #11
    Originally posted by jacob View Post
    Sorry, I'm confused as to the meaning of "rootless X": does it mean that X runs as an unprivileged process, or that it does not manage the whole screen?
    runs under an normal user (instead of "root")

    Comment


    • #12
      I'm surprised this potential security hole wasn't fixed years ago. At least there's progress now, it'll be great when the drivers and login managers finally catch up.

      Comment


      • #13
        Originally posted by Tom B View Post
        I'm surprised this potential security hole wasn't fixed years ago. At least there's progress now, it'll be great when the drivers and login managers finally catch up.
        Care to explain what the security risk is? AFAIK the biggest X threat is via the network transparency protocols. The ordinary user hardly can interfere with root owned X11 process?

        Comment


        • #14
          Simply put, anything which exploits any part of the X server is running as a process with root privileges. It breaks the principle of least privilege, although likely difficult to exploit it's almost certainly not impossible. Any software that communicates with X could potentially exploit part of it and get root privileges, now it's unlikely but given the common sense approach of "don't run stuff as root", running X as root has always been a bit of an oversight.

          Comment


          • #15
            Originally posted by Tom B View Post
            I'm surprised this potential security hole wasn't fixed years ago. At least there's progress now, it'll be great when the drivers and login managers finally catch up.
            It was pretty much impossible before they moved the hardware management code out of X and into the kernel. Which has taken a long time to get working.

            Comment


            • #16
              Should this prevent X taking down the whole system? I've always had an issue where X crashes, the whole system becomes unresponsive, forcing a manual power down.

              Comment


              • #17
                No, not running as root won't affect its ability to bring down your system.

                Comment

                Working...
                X