From 66777ef29ce048cbf677bb981b4fa67a4d302092 Mon Sep 17 00:00:00 2001 From: LFRon Date: Mon, 24 Aug 2026 12:07:38 +0800 Subject: [PATCH] fix(xwayland): allow cross-UID MIT-SHM via AmbientCapabilities=CAP_IPC_OWNER XWayland spawned by treeland's wlroots needs to attach to SysV shared-memory segments (MIT-SHM / XShmPutImage) created by X11 clients. In a DDM-owned session, Xwayland runs as user "dde" while desktop applications (notably Electron/Chromium apps) may be launched by the real login user. Set AmbientCapabilities=CAP_IPC_OWNER in treeland.service so systemd grants the capability directly into the process credentials (permitted, inheritable and ambient sets); the ambient set survives fork+exec of non-privileged binaries and enters their effective set, so Xwayland can shmat() segments created by a different UID (see Xext/shm.c:ProcShmAttach). NoNewPrivileges=true is kept enabled: it only makes the kernel ignore privileged grants coming from the executable itself (setuid/file caps), it does not clear ambient capabilities injected by systemd. Set PrivateIPC=false explicitly: the private IPC namespace hides SysV shm segments created by clients in the host namespace, making shmat() fail with EINVAL; Xwayland must share the host IPC namespace with its X11 clients. --- misc/systemd/treeland.service.in | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/misc/systemd/treeland.service.in b/misc/systemd/treeland.service.in index 8d1fb57b2c..e5ca2dcab0 100644 --- a/misc/systemd/treeland.service.in +++ b/misc/systemd/treeland.service.in @@ -51,7 +51,8 @@ IOSchedulingPriority=0 # # MemoryDenyWriteExecute=true -PrivateIPC=true +PrivateIPC=false +AmbientCapabilities=CAP_IPC_OWNER ProtectSystem=full ProtectHome=true ProtectClock=true