D15063: Remove X clipboard sync helper and rename its autotest

Martin Flöser <[email protected]>
Newsgroups gmane.comp.kde.devel.kwin
Message-ID <[email protected]>
graesslin added a comment.


  I want to point out that the main motivation for the dedicated process is to make KWin not an attack target by clients. The danger I see is that a malicious client sets a large clipboard data causing KWin to go out of memory. As the data source process passes a pipe which we have to read in order to sync to X11 we have to get all the data and allocate memory for it. The dedicated process was my solution to protect against this possible attack (which btw. also works for containerized applications such as flatpack). It would be the clipboard sync process which goes oom and killed, but not the complete session.
  
  I don't mind that it gets moved into KWin, but we should add a memory restriction to ensure we cannot be attacked from clients through the clipboard.

REPOSITORY
  R108 KWin

BRANCH
  0rmHelper

REVISION DETAIL
  https://phabricator.kde.org/D15063

To: romangg, #kwin, davidedmundson
Cc: graesslin, kwin, mkulinski, ragreen, jackyalcine, Pitel, iodelay, bwowk, ZrenBot, ngraham, lesliezhai, ali-mohamed, hardening, jensreuterberg, abetts, sebas, apol, mart
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.