106.2 Graphical desktops¶
Weight: 1
Candidates should be aware of major Linux desktops. Furthermore, candidates should be aware of protocols used to access remote desktop sessions.
Objectives
- Awareness of major desktop environments
- Awareness of protocols to access remote desktop sessions
Terms
KDE, Gnome, Xfce, X11, XDMCP, VNC, Spice, RDP
This objective has weight 1 and asks only for awareness: know the big desktop environments and the protocols for remote desktops, what each one is for, and a few key facts like port numbers. No configuration is needed.
Why a graphical desktop¶
The command line is powerful, but you must know the program names and their options. In a graphical user interface (GUI) you point at familiar pictures and click, so it is easier to learn, and it is better for multimedia and visual work. Most distributions install a GUI by default.
A Linux desktop is not one big program. It is a collection of programs and their dependencies, chosen by the distribution and by the user.
What X does, and what it does not do¶
The X Window System (X11, or just X, see 106.1) gives the low-level parts of the GUI:
- handling input events, like mouse movements and key presses,
- cut, copy and paste between different applications,
- a programming interface that programs use to draw.
X controls the display (the video driver is part of X), but it does not draw complex visual elements. Shapes, colors, shadows and effects are made by the applications on top of X. That gives freedom, but also extra work for developers and programs that look and behave differently. A desktop environment fixes this: it gives developers ready-made libraries, and gives users a consistent experience across applications.
The login screen: display managers¶
When the system boots into graphical mode, you see a graphical login screen. Under it is XDMCP (X Display Manager Control Protocol). On top of it, a display manager handles the theme and the login:
| Display manager | Comes with |
|---|---|
| GDM | GNOME |
| SDDM | KDE |
| XDM | the general, basic X display manager |
Window managers and desktop environments¶
The window manager is the most important piece. It controls where windows go and how they are decorated: it adds the title bar and the minimize, maximize and close buttons, and it lets you switch between open windows. Even the most minimal GUI needs a window manager.
Add more and more to it, like panels, a launcher, icons, drag and drop, a trash can, a file manager, a calculator and an email client, all built with the same libraries and design, and you get a desktop environment. Some people prefer a bare window manager and add only the tools they like. Others want the full package.
desktop environment
+-----------------------------------------------------------+
| accessory apps: terminal, file manager, calculator, ... |
| launcher, taskbar, settings tools |
| window manager: title bars, buttons, switching windows |
| widget toolkit: GTK+ or Qt |
+-----------------------------------------------------------+
X (or Wayland)
Widgets are the visual elements inside a window: buttons, text fields, dialogs. Widget toolkits like GTK+ and Qt provide them. Every desktop environment has a window manager that matches its toolkit. Programs built with different toolkits can run side by side, whatever toolkit the desktop uses. They may just look a bit different, especially in complex widgets like the "open file" dialog.
A desktop environment usually includes:
| Group | Typical applications |
|---|---|
| System | terminal emulator, file manager, package installer, system settings |
| Communication and internet | contacts, email client, web browser |
| Office | calendar, calculator, text editor |
It may also have a login greeter, a session manager, a keyring agent, and graphical frontends for system services like PulseAudio (sound) and CUPS (printing). Most desktops share some ideas: an application launcher, rules for which default application opens each file type, and configuration tools for looks and behaviour. Keyboard shortcuts like Alt+Tab (switch windows) and Ctrl+C (copy) work almost everywhere, and each desktop adds its own.
The major desktop environments¶
Unlike many proprietary systems with one fixed desktop, Linux lets you choose.
GNOME
- Started in 1999. Focus on productivity and accessibility.
- Uses the Mutter window manager.
- The default on Fedora, Debian, Ubuntu, SUSE Linux Enterprise, Red Hat Enterprise Linux, CentOS and others.
- Version 3 brought GNOME Shell, which replaced the classic launcher and taskbar with the full-screen Activities view. The GNOME Classic option on the login screen gives the old look back.
KDE (Plasma)
- Started in 1996. Since version 5 (2016) the desktop is called KDE Plasma.
- KDE is a large ecosystem of applications and a development platform, built with the Qt library, which gives it its own look.
- Highly customizable, uses the KWin window manager. The default on openSUSE, Mageia and Kubuntu. Used by CERN and on NASA's Mars mission.
- Has a tool to make GTK+ applications look like the rest of the desktop.
Xfce
- Started in 1999.
- Lightweight but still good looking and polished, good on older hardware.
- Very modular: turn components on or off as you like. Uses the Xfwm window manager.
Others you may meet:
| Desktop | Notes |
|---|---|
| Cinnamon | from Linux Mint, a fork of GNOME 3 |
| MATE | from Linux Mint, a fork of GNOME 2 |
| LXDE | very low resource use, good for old computers and single board computers |
Desktop interoperability: freedesktop.org¶
With so many desktops, how can an application work well on all of them? freedesktop.org maintains shared specifications for this. They are not mandatory, but widely used:
| Specification | Covers |
|---|---|
| Directory locations | where personal settings and user files are kept |
| Desktop entries | .desktop text files that tell the desktop which applications exist and how to start them, so they appear in the launcher |
| Application autostart | desktop entries for programs that start after login |
| Drag and drop | how applications handle drag and drop |
| Trash can | where deleted files go, and how to put them there and remove them |
| Icon themes | a common format for icon sets |
This also means your general settings survive if you switch to another desktop environment.
Remote access to a graphical desktop¶
A shell on a remote machine is easy: ssh. A remote graphical desktop is harder, needs other tools, and may be slow on a weak connection. You may want it to help a friend, to check your computer from your phone, or to use a heavy graphical program on a stronger remote machine.
X is built around independent displays, a bit like text terminals. One X display manager can run several graphical sessions at the same time. Besides the normal single local session, that allows:
- switching between active graphical sessions on the same machine,
- several sets of screen, keyboard and mouse on one machine, each with its own session,
- remote graphical sessions, where the GUI is sent over the network to a remote display.
The remote desktop protocols¶
| Protocol | Key facts |
|---|---|
| XDMCP | X's native remote login. Needs X on both ends. Uses a lot of bandwidth and sends everything unencrypted, so rarely used over the internet or slow LANs; it is legacy and effectively obsolete, so use it only on a trusted local network. Not secure: a bug in the privileged remote display manager could let someone run privileged commands |
| VNC | Virtual Network Computing. Platform independent, uses the RFB (Remote Frame Buffer) protocol. TCP port 5900 for the first server, 5901 for the second, and so on. No modern encryption or authentication of its own, so it is usually tunnelled; a modern server such as TigerVNC can add TLS. The port is often described as 5900 plus the display number, so display 1 listens on 5901 |
| RDP | Remote Desktop Protocol, from Microsoft Windows. TCP port 3389. Encrypted by default, compresses well and supports multiple monitors. The Linux clients are open source (GPL), and xrdp lets a Linux machine accept RDP connections |
| Spice | Simple Protocol for Independent Computing Environments. Made for virtual machines (like KVM), local or remote. Shares local devices (speakers, USB) and files with the remote system |
VNC in more detail: local keyboard and mouse events go to the remote desktop, and screen updates come back. The VNC server needs no special privileges: a normal user can log in to their remote account and start their own VNC server, then connect with any VNC client. The script ~/.vnc/xstartup runs when the VNC server starts, and chooses which desktop environment the client gets. Because VNC lacks security, run it through an SSH tunnel or a VPN. Its flexibility and clients for every platform are its strength.
Spice started as closed source and became open source when Red Hat bought the company in 2008. It is fast, close to a local connection, with low CPU use. There is one server implementation and many clients, including GNOME Boxes.
Remmina is a graphical remote desktop client with plugins for XDMCP, VNC, RDP and Spice, and it can save your connection settings. The right tool depends on the operating systems involved, the network quality, and which features you need.
X forwarding over SSH¶
This is not listed in this objective, but it is very useful. If the remote machine runs an SSH server, you can start a graphical program there and see its window on your machine. Make sure X11Forwarding yes is set in /etc/ssh/sshd_config (restart the service if you change it), then:
It works the same for a browser or a CPU-hungry simulation.
Waypipe¶
Waypipe is the Wayland equivalent of SSH X forwarding. It pipes Wayland application windows over an SSH connection, so it is the modern successor to ssh -X as desktops move from X11 to Wayland.
Summary¶
This objective only needs awareness, not deep configuration. X gives the basics (input events, copy and paste, a drawing interface), while a desktop environment adds a window manager that draws the window frames (title bars, buttons, window switching), a widget toolkit (GTK+ or Qt), a launcher, settings tools and accessory apps. The graphical login is a display manager (GDM, SDDM, XDM) built on XDMCP. The big three desktops are GNOME (Mutter window manager, GNOME Shell, productivity and accessibility, default on Fedora, Debian, Ubuntu and RHEL), KDE Plasma (KWin, Qt, highly customizable, default on openSUSE and Kubuntu) and Xfce (Xfwm, lightweight and modular, good on old hardware), with Cinnamon, MATE and LXDE as others, and freedesktop.org specifications such as .desktop entries keep them compatible.
To reach a GUI remotely I know several options: XDMCP for a full X11 remote login (native to X, needs X on both ends, legacy, heavy and insecure), VNC (RFB protocol, port 5900 plus the display number, ~/.vnc/xstartup, flexible but insecure on its own, so I secure it with SSH or a VPN), RDP (Windows, port 3389, encrypted, xrdp on Linux) and Spice (fast, aimed at KVM virtual machines, shares devices and files), with Remmina as one client for all of them. For a single remote program, SSH X forwarding with ssh -X shows it on my screen over X11, with Waypipe as the Wayland successor.