wayland: fix heap corruption — update backing table after frame resize

wl_frame_configure and wl_window_resize reallocate fb->image (unref
old pixman image, create new one) but never updated the WINGs backing
table. W_GetViewBacking() continued returning the freed pointer.

Any subsequent draw into that backing (e.g. WMDrawString for titlebar
text) wrote into freed memory, corrupting the heap. The corruption
manifested as SIGSEGV/SIGABRT at the next malloc or free — in
fontconfig, Mesa, RReleaseImage, etc. depending on timing.

Fix: call W_RegisterBacking(fb->id, fb->image) after reallocation in
both resize paths.
This commit is contained in:
lkn 2026-06-24 21:59:53 +02:00
parent e6acdbf0f1
commit de15ca2282
2 changed files with 2 additions and 0 deletions

View File

@ -554,6 +554,7 @@ wl_frame_configure(WNativeWindow win, int x, int y, int width, int height)
fb->height = height;
fb->base.width = width;
fb->base.height = height;
W_RegisterBacking(fb->id, fb->image);
if (fb->scene_buf)
wlr_scene_buffer_set_dest_size(fb->scene_buf, width, height);
}

View File

@ -285,6 +285,7 @@ void wl_window_resize(WNativeWindow win, int w, int h)
fb->height = h;
fb->base.width = w;
fb->base.height = h;
W_RegisterBacking(fb->id, fb->image);
if (fb->scene_buf)
wlr_scene_buffer_set_dest_size(fb->scene_buf, w, h);
}