wayland: fix heap corruption — update backing table after frame resize
wl_frame_configure and wl_window_resize reallocate fb->image (unref old pixman image, create new one) but never updated the WINGs backing table. W_GetViewBacking() continued returning the freed pointer. Any subsequent draw into that backing (e.g. WMDrawString for titlebar text) wrote into freed memory, corrupting the heap. The corruption manifested as SIGSEGV/SIGABRT at the next malloc or free — in fontconfig, Mesa, RReleaseImage, etc. depending on timing. Fix: call W_RegisterBacking(fb->id, fb->image) after reallocation in both resize paths.
This commit is contained in:
parent
e6acdbf0f1
commit
de15ca2282
|
|
@ -554,6 +554,7 @@ wl_frame_configure(WNativeWindow win, int x, int y, int width, int height)
|
|||
fb->height = height;
|
||||
fb->base.width = width;
|
||||
fb->base.height = height;
|
||||
W_RegisterBacking(fb->id, fb->image);
|
||||
if (fb->scene_buf)
|
||||
wlr_scene_buffer_set_dest_size(fb->scene_buf, width, height);
|
||||
}
|
||||
|
|
|
|||
|
|
@ -285,6 +285,7 @@ void wl_window_resize(WNativeWindow win, int w, int h)
|
|||
fb->height = h;
|
||||
fb->base.width = w;
|
||||
fb->base.height = h;
|
||||
W_RegisterBacking(fb->id, fb->image);
|
||||
if (fb->scene_buf)
|
||||
wlr_scene_buffer_set_dest_size(fb->scene_buf, w, h);
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue