fix use-after-free: destroy child tree before dropping buffer
When destroying child frame_bufs, the tree node was not destroyed before wlr_buffer_drop freed the struct. Later, cascade destruction of the parent tree would fire fb_tree_destroy_handler on the freed child, corrupting the heap. Destroy the child tree explicitly first.
This commit is contained in:
parent
69b08e6cfb
commit
01904fdb39
|
|
@ -463,9 +463,10 @@ wl_frame_destroy(WScreen *scr, WNativeWindow win)
|
|||
struct wl_frame_buf *child, *tmp;
|
||||
wl_list_for_each_safe(child, tmp, &wl_state.frame_list, link) {
|
||||
if (child->parent_id == win) {
|
||||
W_UnregisterBacking(child->id);
|
||||
if (child->scene_buf)
|
||||
wlr_scene_node_destroy(&child->scene_buf->node);
|
||||
if (child->tree)
|
||||
wlr_scene_node_destroy(&child->tree->node);
|
||||
wl_list_remove(&child->link);
|
||||
wlr_buffer_drop(&child->base);
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue