Concerns Regarding the Choice of Rust for the Xfce Wayland Compositor
Manfred Hollstein
manfred.h at gmx.net
Thu Jun 18 08:34:13 CEST 2026
On Wed, 17 Jun 2026, 23:46:18 +0200, Brian Tarricone wrote:
> On Wed, Jun 17, 2026, at 14:07, Wojciech S. Czarnecki wrote:
> [...]
> >> > Xfce has always been trusted because its codebase is relatively small and auditable.
> >>
> >> This feels like a bit of a stretch to me. Do people really think about Xfce in these terms?
> >
> > I do.
>
> I meant that as a general/statistical question. If the answer is "30%
> of Xfce users care about this" then sure, that would mean I'd want to
> consider that more carefully. But if it's 1% -- which I suspect is
> much closer to the truth -- then I can't really put much emphasis on
> this, given my own limited time and resources.
While I'm an Xfce user since years, I rather view this from a packager's
point of view. I maintain the Xfce packages (amongst other colleagues)
for openSUSE within their build system OBS. Every package has to be
buildable stand-alone, i.e. no access to the internet is possible. As a
consequence building packages using rust/cargo is a pita! Each such
package will then carry its own pre-downloaded data stuffed into a
vendor.tar file :-( If OBS would allow internet access during build,
such attacks as have been recently seen with the hacked npm based
packages on Arch Linux would also be possible here.
Again, this is my package point of view.
> Regards,
> Brian
Cheers.
l8er
manfred
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 870 bytes
Desc: not available
URL: <https://mail.xfce.org/pipermail/xfce4-dev/attachments/20260618/9969f304/attachment-0001.sig>
More information about the Xfce4-dev
mailing list