Posted 4 min read
Building Fiber on Wayland
Every pixel on a Linux desktop passes through one program. Fiber, the operating system we are building, starts from Wayland, and that choice shapes the rest.
EngineeringOperating systems

On this page
Every pixel you see on a Linux desktop has passed through one program. It decides which window sits on top, which one hears your keystrokes, and what reaches the screen at every refresh. For almost forty years that program was the X server.
Fiber, the operating system we are building, starts from its successor. It is a Wayland compositor from the first line of code.
Fiber is early, open source, and built in the open: a lightweight OS for desktops and laptops first, with shells for phones, tablets and spatial computing to follow. The compositor at its centre is where most of its ideas live. This is why it speaks Wayland, and what that lets it do.
Forty years of X#
X was designed in 1984, for shared terminals on trusted networks, and its model was generous. Any client could draw anywhere, read the contents of any window, and see every key pressed, whichever window it was meant for. That made screenshots, global hotkeys and remote displays easy. It made keyloggers and screen scrapers just as easy.
Decades of extensions kept X going, but the model underneath never changed, and the X.Org server now sees little more than maintenance. Wayland, begun in 2008, is what the Linux desktop moved to instead. Fedora has shipped it by default since 2016, Ubuntu since 2021, and KDE Plasma since 2024.
What Wayland changes#
Wayland is a protocol, not a program. The compositor implements it, and in doing so becomes the display server, the window manager and the compositor at once. That concentration is the whole point.
Every app sees only itself#
A Wayland app draws into its own buffers and hands them to the compositor. It cannot read another app's window, and it hears input only when it has focus. Screen capture and global shortcuts still exist, but as requests the compositor can grant, refuse or put to the person in front of it, through portals such as xdg-desktop-portal.
Every frame is perfect#
That is Wayland's founding promise. An app's changes arrive as one atomic commit, and the compositor presents whole frames, so there is no tearing, no half-drawn window and no flicker while something resizes. Newer protocols add what modern displays need: fractional scaling, HDR colour management, and tearing on purpose for the games that want the lowest possible latency.
On X, privacy meant trusting every app. On Wayland, it is the compositor's job.
One compositor, many shells#
Fiber's compositor is a shared core with separate shells on top. The core models what every surface needs, whatever screen it is on: focus, input routing, outputs, permissions, screen capture, frame scheduling and accessibility. The shells decide how it all looks and behaves:
- Fiber Desktop Shell, for desktops and laptops, is the first release.
- Fiber Mobile Shell is touch first, for phones, tablets and handhelds.
- Fiber Spatial Shell is built on OpenXR, for panels and immersive apps in three dimensions, on runtimes such as Monado.
Because Wayland describes surfaces rather than screens, one app can be a window on a laptop, a full-screen view on a phone and a panel floating in a room, while the compositor beneath it stays the same.
Permission belongs to the display#
The compositor already stands between every app and every screen, so Fiber makes it the place where permission is decided. Cameras, microphones, location and screen capture are protected resources, and so is every sensor a headset adds: head pose, hand and eye tracking, where you are looking, and the shape of the room around you.
Each can be denied, or granted for a moment, for a session or for good, or set by policy. The defaults are written down as tests:
#[test]
fn sensitive_spatial_inputs_require_permissions() {
assert!(InputClass::Gaze.requires_permission());
assert!(InputClass::HandTracking.requires_permission());
assert!(InputClass::HeadPose.requires_permission());
assert!(!InputClass::Keyboard.requires_permission());
}
A keyboard is just a keyboard. Where you are looking is not something an app should learn by default.
Nothing left behind#
A new display protocol is only useful if the software people rely on still runs on it. XWayland runs X11 applications inside a Wayland session, and Fiber keeps it on wherever compatibility needs it. Web apps are first-class surfaces too, so the open web is Fiber's app store from the start.
Built in Rust, in the open#
The compositor is Rust, built on the wayland-server crate from the Smithay project's wayland-rs, with OpenXR for the spatial shell. The rest of Fiber follows the same instincts. Disk encryption is mandatory when you install it. Secure Boot is part of the design. A Hacker profile starts Tor at boot, for an anonymous mode. And Fiber is released under the Unlicense: free and open source, and it always will be.
Where it stands#
Fiber is a work in progress, and we would rather say so than pretend otherwise. The desktop shell comes first, with the mobile and spatial shells following on the same core. The compositor's contracts are written and tested, and the image pipeline builds release images for x86_64 and AArch64.
Choosing Wayland was never the hard part of building an operating system. It was the part that made the rest possible: one program that sees everything, and is trusted to share only what it should.
Written by
- CB
Chiru Boggavarapu
Founder & Chief Executive