Skip to content

fix(xwayland): allow cross-UID MIT-SHM by removing NoNewPrivileges and PrivateIPC - #1320

Open
LFRon wants to merge 1 commit into
linuxdeepin:masterfrom
LFRon:fix/render
Open

fix(xwayland): allow cross-UID MIT-SHM by removing NoNewPrivileges and PrivateIPC#1320
LFRon wants to merge 1 commit into
linuxdeepin:masterfrom
LFRon:fix/render

Conversation

@LFRon

@LFRon LFRon commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

该PR修复了: Xwayland运行的QQ音乐白屏和微信最新版4.1.13.3只能显示第一帧, 之后完全卡住的问题
且该PR需要ddm侧的更改: linuxdeepin/ddm#107

这个PR的实现撤掉了NoNewPrivileges和PrivateIPC, 具有一定风险, 仅作为一个参考实现

XWayland spawned by treeland's wlroots needs to attach to SysV shared-memory
segments (MIT-SHM / XShmPutImage) created by X11 clients. In a DDM-owned
session, Xwayland runs as user "dde" while desktop applications (notably
Electron/Chromium apps) may be launched by the real login user. Two systemd
service hardening options were blocking this:

  1. NoNewPrivileges=true
    Xwayland requires the cap_ipc_owner file capability on its binary to
    shmat() segments created by a different UID. no_new_privs makes the
    kernel ignore file capabilities entirely at execve(), so the capability
    is never granted and shmat() fails with EACCES.

  2. PrivateIPC=true
    Creates a private IPC namespace for treeland and its children. SysV
    shm segments created by clients in the host namespace are invisible to
    Xwayland; shmat() returns EINVAL because the segment does not exist in
    the private namespace.

Both options are now commented out with detailed explanations. Other security
hardening (ProtectSystem, ProtectHome, ProtectClock, RestrictSUIDSGID, etc.)
is kept intact.

The cap_ipc_owner capability is applied to /usr/bin/Xwayland by ddm at
startup (see ddm's DaemonApp::applyXwaylandIpcCapability).

See also: Xext/shm.c:ProcShmAttach (shmat + shm_access logic).

Summary by Sourcery

Enable cross-UID Xwayland shared-memory access by relaxing the service restrictions that prevent MIT-SHM clients from attaching their shared-memory segments.

Bug Fixes:

  • Restore cross-UID MIT-SHM support for Xwayland so applications such as QQ Music and recent WeChat versions can render and update correctly.

Enhancements:

  • Adjust treeland's systemd service hardening to permit the shared IPC namespace and Xwayland file capabilities required for cross-UID SysV shared-memory access while retaining other security restrictions.

Summary by Sourcery

Allow Xwayland to access shared memory created by applications running under a different UID.

Bug Fixes:

  • Restore cross-UID MIT-SHM support in Xwayland so applications such as QQ Music and recent WeChat versions render and update correctly.

Enhancements:

  • Relax treeland's systemd service restrictions to allow the shared IPC namespace and Xwayland file capabilities required for cross-UID shared-memory access while retaining the remaining hardening.

@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: LFRon

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@sourcery-ai

sourcery-ai Bot commented Aug 24, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This PR fixes cross-UID MIT-SHM/XShmPutImage issues in Xwayland (affecting apps like QQ Music and WeChat) by relaxing specific systemd hardening options in treeland’s service unit so Xwayland can use cap_ipc_owner and access host IPC namespaces, while keeping other hardening in place.

File-Level Changes

Change Details Files
Relax systemd service hardening so Xwayland can attach to SysV shared memory segments created by clients running under different UIDs.
  • Comment out NoNewPrivileges to allow the kernel to honor the cap_ipc_owner file capability on the Xwayland binary at execve(), enabling shmat() on cross-UID shm segments.
  • Comment out PrivateIPC to keep treeland/Xwayland in the host IPC namespace so SysV shared memory segments created by X11 clients are visible and attachable.
  • Add inline documentation in the service unit explaining why these two options are disabled, detailing their impact on MIT-SHM/XShmPutImage and cross-UID shmat() behavior.
  • Leave other systemd hardening options (ProtectSystem, ProtectHome, ProtectClock, RestrictSUIDSGID, etc.) unchanged to retain existing isolation levels.
misc/systemd/treeland.service.in

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@deepin-ci-robot

Copy link
Copy Markdown

Hi @LFRon. Thanks for your PR.

I'm waiting for a linuxdeepin member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

…d PrivateIPC

XWayland spawned by treeland's wlroots needs to attach to SysV shared-memory
segments (MIT-SHM / XShmPutImage) created by X11 clients.  In a DDM-owned
session, Xwayland runs as user "dde" while desktop applications (notably
Electron/Chromium apps) may be launched by the real login user.  Two systemd
service hardening options were blocking this:

  1. NoNewPrivileges=true
     Xwayland requires the cap_ipc_owner file capability on its binary to
     shmat() segments created by a different UID.  no_new_privs makes the
     kernel ignore file capabilities entirely at execve(), so the capability
     is never granted and shmat() fails with EACCES.

  2. PrivateIPC=true
     Creates a private IPC namespace for treeland and its children.  SysV
     shm segments created by clients in the host namespace are invisible to
     Xwayland; shmat() returns EINVAL because the segment does not exist in
     the private namespace.

Both options are now commented out with detailed explanations.  Other security
hardening (ProtectSystem, ProtectHome, ProtectClock, RestrictSUIDSGID, etc.)
is kept intact.

The cap_ipc_owner capability is applied to /usr/bin/Xwayland by ddm at
startup (see ddm's DaemonApp::applyXwaylandIpcCapability).

See also: Xext/shm.c:ProcShmAttach (shmat + shm_access logic).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants