pre*_*ise 10 x11 x-server xhost
请帮我理解这行命令:
xhost +SI:localuser:lightdm
Run Code Online (Sandbox Code Playgroud)
在参考这个职位的答案,也建议,如果有一个更好的办法,为什么多数民众赞成需要。我无法从手册页中获得太多信息,因此我希望有一些更详细的答案以使其变得简单。(我应该用我的用户名替换 localuser 吗,这是否类似于添加到组中?我知道 + 用于添加但不理解 SI 或 si !)
还请提及用户如何添加到“允许建立连接的列表”中以及这意味着什么。另外,我如何检查当前列表?
mur*_*uru 14
xhost +SI:localuser:lightdm允许lightdm用户访问正在运行的 X 服务器。当前的 X 服务器由DISPLAY环境变量指示。
该手册页有相当不错的解释:
[+]name The given name (the plus sign is optional) is added to the list
allowed to connect to the X server. The name can be a host
name or a complete name (See NAMES for more details).
...
NAMES
A complete name has the syntax ``family:name'' where the families are
as follows:
...
si Server Interpreted
...
the server interpreted address "si:localuser:username" can be used to
specify a single local user. (See the Xsecurity(7) manual page for more
details.)
Run Code Online (Sandbox Code Playgroud)
手册Xsecurity页说:
SERVER INTERPRETED ACCESS TYPES
The sample implementation includes several Server Interpreted
mechanisms:
IPv6 IPv6 literal addresses
hostname Network host name
localuser Local connection user id
localgroup Local connection group id
Run Code Online (Sandbox Code Playgroud)
有一点上下文:有两种常用的方法来允许访问 X 服务器。一种是通过Xauthority客户端共享的文件,不需要进一步的服务器端配置。另一种是通过xhost列表,其中配置是在运行时在服务器上完成的(因此这不是永久性更改)。
所以,localuser是一个保留原样的关键字(lightdm这里是用户名,LightDM 运行时使用的用户名)。这有点像添加到一个组,因为这些组在服务器的理解授权中。但是,系统组或用户不会受到影响。仅更改 X 服务器的运行时配置。
xhost不带参数运行时的默认行为是打印列表,如联机帮助页所述:
nothing If no command line arguments are given, a message indicating
whether or not access control is currently enabled is printed,
followed by the list of those allowed to connect.
Run Code Online (Sandbox Code Playgroud)
例如:
$ xhost
access control enabled, only authorized clients can connect
SI:localuser:muru
Run Code Online (Sandbox Code Playgroud)
我们可能需要检查代码以确定如何将用户添加到列表中,以及 X 如何使用该列表。
这样做的原因是使用gsettings,它使用dbus,而后者通常需要运行 X 服务器。但是,这不是必需的,您可以看到这个 AskUbuntu answer。