Skip to content

fix(xwayland): allow cross-UID MIT-SHM by removing NoNewPrivileges and PrivateIPC - #1320

Open
LFRon wants to merge 1 commit into
linuxdeepin:masterfrom
LFRon:fix/render
Open

fix(xwayland): allow cross-UID MIT-SHM by removing NoNewPrivileges and PrivateIPC#1320
LFRon wants to merge 1 commit into
linuxdeepin:masterfrom
LFRon:fix/render

Conversation

@LFRon

@LFRon LFRon commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

该PR修复了: Xwayland运行的QQ音乐白屏和微信最新版4.1.13.3只能显示第一帧, 之后完全卡住的问题
且该PR需要ddm侧的更改: linuxdeepin/ddm#107

这个PR的实现撤掉了NoNewPrivileges和PrivateIPC, 具有一定风险, 仅作为一个参考实现

XWayland spawned by treeland's wlroots needs to attach to SysV shared-memory
segments (MIT-SHM / XShmPutImage) created by X11 clients. In a DDM-owned
session, Xwayland runs as user "dde" while desktop applications (notably
Electron/Chromium apps) may be launched by the real login user. Two systemd
service hardening options were blocking this:

  1. NoNewPrivileges=true
    Xwayland requires the cap_ipc_owner file capability on its binary to
    shmat() segments created by a different UID. no_new_privs makes the
    kernel ignore file capabilities entirely at execve(), so the capability
    is never granted and shmat() fails with EACCES.

  2. PrivateIPC=true
    Creates a private IPC namespace for treeland and its children. SysV
    shm segments created by clients in the host namespace are invisible to
    Xwayland; shmat() returns EINVAL because the segment does not exist in
    the private namespace.

Both options are now commented out with detailed explanations. Other security
hardening (ProtectSystem, ProtectHome, ProtectClock, RestrictSUIDSGID, etc.)
is kept intact.

The cap_ipc_owner capability is applied to /usr/bin/Xwayland by ddm at
startup (see ddm's DaemonApp::applyXwaylandIpcCapability).

See also: Xext/shm.c:ProcShmAttach (shmat + shm_access logic).

Summary by Sourcery

Enable cross-user MIT-SHM support in Treeland's Xwayland service so applications can render correctly across the DDM-managed session.

Bug Fixes:

  • Allow Xwayland to attach to cross-UID SysV shared-memory segments, fixing blank or frozen rendering in affected X11 applications.

Enhancements:

  • Retain existing systemd service hardening while disabling the IPC isolation settings that prevent Xwayland clients from sharing MIT-SHM resources across users.

@sourcery-ai

sourcery-ai Bot commented Aug 24, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This PR fixes cross-UID MIT-SHM/XShmPutImage issues in Xwayland (affecting apps like QQ Music and WeChat) by relaxing specific systemd hardening options in treeland’s service unit so Xwayland can use cap_ipc_owner and access host IPC namespaces, while keeping other hardening in place.

File-Level Changes

Change Details Files
Relax systemd service hardening so Xwayland can attach to SysV shared memory segments created by clients running under different UIDs.
  • Comment out NoNewPrivileges to allow the kernel to honor the cap_ipc_owner file capability on the Xwayland binary at execve(), enabling shmat() on cross-UID shm segments.
  • Comment out PrivateIPC to keep treeland/Xwayland in the host IPC namespace so SysV shared memory segments created by X11 clients are visible and attachable.
  • Add inline documentation in the service unit explaining why these two options are disabled, detailing their impact on MIT-SHM/XShmPutImage and cross-UID shmat() behavior.
  • Leave other systemd hardening options (ProtectSystem, ProtectHome, ProtectClock, RestrictSUIDSGID, etc.) unchanged to retain existing isolation levels.
misc/systemd/treeland.service.in

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@deepin-ci-robot

Copy link
Copy Markdown

Hi @LFRon. Thanks for your PR.

I'm waiting for a linuxdeepin member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@deepin-bot

deepin-bot Bot commented Aug 28, 2026

Copy link
Copy Markdown

TAG Bot

New tag: 0.9.1
DISTRIBUTION: unstable
Suggest: synchronizing this PR through rebase #1348

@zzxyb
zzxyb requested a review from zccrs September 2, 2026 08:09
zccrs
zccrs previously approved these changes Sep 2, 2026
@zzxyb

zzxyb commented Sep 2, 2026

Copy link
Copy Markdown
Collaborator

修复qq音乐白屏

@zzxyb zzxyb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

-PrivateIPC=true
+PrivateIPC=false
+AmbientCapabilities=CAP_IPC_OWNER
按照这样改一下就可以合入了

@LFRon

LFRon commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

-PrivateIPC=true +PrivateIPC=false +AmbientCapabilities=CAP_IPC_OWNER 按照这样改一下就可以合入了

收到,我改一下

@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: LFRon

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

1 similar comment
@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: LFRon

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

…C_OWNER

XWayland spawned by treeland's wlroots needs to attach to SysV shared-memory
segments (MIT-SHM / XShmPutImage) created by X11 clients.  In a DDM-owned
session, Xwayland runs as user "dde" while desktop applications (notably
Electron/Chromium apps) may be launched by the real login user.

Set AmbientCapabilities=CAP_IPC_OWNER in treeland.service so systemd grants
the capability directly into the process credentials (permitted,
inheritable and ambient sets); the ambient set survives fork+exec of
non-privileged binaries and enters their effective set, so Xwayland can
shmat() segments created by a different UID (see Xext/shm.c:ProcShmAttach).

NoNewPrivileges=true is kept enabled: it only makes the kernel ignore
privileged grants coming from the executable itself (setuid/file caps), it
does not clear ambient capabilities injected by systemd.

Set PrivateIPC=false explicitly: the private IPC namespace hides SysV shm
segments created by clients in the host namespace, making shmat() fail with
EINVAL; Xwayland must share the host IPC namespace with its X11 clients.
@LFRon

LFRon commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

我改好了

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants