wayland: add overflow guard to titlebar blit in frame_paint

Add runtime bounds check before the titlebar texture blit. If the
destination pixman image is smaller than the blit dimensions, log a
diagnostic warning with the exact sizes and skip the blit instead of
corrupting the heap. This will help identify the conditions that
trigger the remaining heap overflow.
This commit is contained in:
lkn 2026-06-24 22:21:28 +02:00
parent e00bc6b25a
commit 62f8cb5c77
1 changed files with 8 additions and 0 deletions

View File

@ -636,6 +636,13 @@ wl_frame_paint(struct WFrameWindow *fwin)
if (img) {
uint32_t *dst = pixman_image_get_data(tb_img);
int dst_stride = pixman_image_get_stride(tb_img) / 4;
int dst_h = pixman_image_get_height(tb_img);
if (tb_h > dst_h || tb_w > dst_stride) {
wwarning("OVERFLOW: tb_w=%d tb_h=%d dst_stride=%d dst_h=%d fb=%dx%d tb_fb=%p",
tb_w, tb_h, dst_stride, dst_h, total_w, total_h, (void*)tb_fb);
RReleaseImage(img);
goto skip_titlebar;
}
int x, y;
if (img->format == RRGBAFormat) {
for (y = 0; y < tb_h && y < img->height; y++) {
@ -704,6 +711,7 @@ wl_frame_paint(struct WFrameWindow *fwin)
}
}
skip_titlebar:
/* --- Titlebar buttons --- */
if (fwin->titlebar && fwin->top_width > 0) {
if (fwin->left_button && !fwin->flags.hide_left_button &&