I've placed a security hold on Xlibre in Alpine, for a number of reasons that basically sum up to an unproven reactionary project whose code runs with elevated privilege (such as direct hardware access) is extremely high risk for introducing security-related regressions.

I do think a fork of X is a good idea, but that fork needs to be focused on sustainability: it should be focused on the generic drivers (such as modesetting for video and libinput for input), and there needs to be a real documented plan for maintenance and triage of security vulnerabilities.

Right now, I don't see that. Instead I see a fork of every component of X, including all of the hardware-specific drivers, and people complaining about politics.

This does not inspire confidence that the fork will not introduce security regressions, or worse, fail to import security patches from X.org.

For those reasons, at least for now, the security hold will remain indefinitely. We can reevaluate after the project has had time to mature (and hopefully start focusing on the fundamentals rather than wild proclamations about being "anti-DEI").

0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.treehouse.systems/users/ariadne/statuses/114717467792285512 on your instance and quote it. (Note that quoting is not supported in Mastodon.)