wayland: add overflow guard to titlebar blit in frame_paint
Add runtime bounds check before the titlebar texture blit. If the destination pixman image is smaller than the blit dimensions, log a diagnostic warning with the exact sizes and skip the blit instead of corrupting the heap. This will help identify the conditions that trigger the remaining heap overflow.
This commit is contained in:
parent
e00bc6b25a
commit
62f8cb5c77
|
|
@ -636,6 +636,13 @@ wl_frame_paint(struct WFrameWindow *fwin)
|
|||
if (img) {
|
||||
uint32_t *dst = pixman_image_get_data(tb_img);
|
||||
int dst_stride = pixman_image_get_stride(tb_img) / 4;
|
||||
int dst_h = pixman_image_get_height(tb_img);
|
||||
if (tb_h > dst_h || tb_w > dst_stride) {
|
||||
wwarning("OVERFLOW: tb_w=%d tb_h=%d dst_stride=%d dst_h=%d fb=%dx%d tb_fb=%p",
|
||||
tb_w, tb_h, dst_stride, dst_h, total_w, total_h, (void*)tb_fb);
|
||||
RReleaseImage(img);
|
||||
goto skip_titlebar;
|
||||
}
|
||||
int x, y;
|
||||
if (img->format == RRGBAFormat) {
|
||||
for (y = 0; y < tb_h && y < img->height; y++) {
|
||||
|
|
@ -704,6 +711,7 @@ wl_frame_paint(struct WFrameWindow *fwin)
|
|||
}
|
||||
}
|
||||
|
||||
skip_titlebar:
|
||||
/* --- Titlebar buttons --- */
|
||||
if (fwin->titlebar && fwin->top_width > 0) {
|
||||
if (fwin->left_button && !fwin->flags.hide_left_button &&
|
||||
|
|
|
|||
Loading…
Reference in New Issue