fix use-after-free: destroy child tree before dropping buffer

When destroying child frame_bufs, the tree node was not destroyed
before wlr_buffer_drop freed the struct. Later, cascade destruction
of the parent tree would fire fb_tree_destroy_handler on the freed
child, corrupting the heap. Destroy the child tree explicitly first.
This commit is contained in:
lkn 2026-06-23 22:08:29 +02:00
parent 69b08e6cfb
commit 01904fdb39
1 changed files with 2 additions and 1 deletions

View File

@ -463,9 +463,10 @@ wl_frame_destroy(WScreen *scr, WNativeWindow win)
struct wl_frame_buf *child, *tmp;
wl_list_for_each_safe(child, tmp, &wl_state.frame_list, link) {
if (child->parent_id == win) {
W_UnregisterBacking(child->id);
if (child->scene_buf)
wlr_scene_node_destroy(&child->scene_buf->node);
if (child->tree)
wlr_scene_node_destroy(&child->tree->node);
wl_list_remove(&child->link);
wlr_buffer_drop(&child->base);
}