fix UAF: destroy WApplication before wUnmanageWindow in XWayland unmap

Same fix as commit 2581233 for XDG toplevels — wApplicationDestroy
needs main_window_desc (the wwin) to clean up the appicon. Call it
before wUnmanageWindow which frees wwin.
This commit is contained in:
lkn 2026-06-27 18:40:30 +02:00
parent 5b5617844a
commit e3c19bd103
2 changed files with 5 additions and 3 deletions

View File

@ -16,6 +16,8 @@ void wl_event_flush(void)
(!wl_state.session || wl_state.session->active)) {
wlr_scene_output_commit(wl_state.scene_output, NULL);
wl_display_flush_clients(wl_state.display);
struct wl_event_loop *loop = wl_display_get_event_loop(wl_state.display);
wl_event_loop_dispatch(loop, 0);
}
}
void wl_event_flush_expose(void) {}

View File

@ -223,13 +223,13 @@ handle_xwayland_unmap(struct wl_listener *listener, void *data)
if (desc && desc->parent_type == WCLASS_WINDOW) {
WWindow *wwin = (WWindow *)desc->parent;
WNativeWindow main_win = wwin->main_window;
wUnmanageWindow(wwin, False, True);
WApplication *app = wApplicationOf(main_win);
if (app) {
if (main_win == app->main_window)
app->refcount = 0;
app->refcount = 0;
wApplicationDestroy(app);
}
wwin->flags.destroyed = 1;
wUnmanageWindow(wwin, False, True);
}
}
}