[packages/xorg-xserver-server] - rel 2; fix segfaults if built with xproto 7.0.28+
arekm
arekm at pld-linux.org
Wed Oct 28 12:24:12 CET 2015
commit b4aca4425a827cc471550768e075620d7f09c312
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Wed Oct 28 12:24:05 2015 +0100
- rel 2; fix segfaults if built with xproto 7.0.28+
xorg-xserver-server-xproto-crash.patch | 59 ++++++++++++++++++++++++++++++++++
xorg-xserver-server.spec | 6 ++--
2 files changed, 62 insertions(+), 3 deletions(-)
---
diff --git a/xorg-xserver-server.spec b/xorg-xserver-server.spec
index c4f4b37..b55f470 100644
--- a/xorg-xserver-server.spec
+++ b/xorg-xserver-server.spec
@@ -35,7 +35,7 @@ Summary: X.org server
Summary(pl.UTF-8): Serwer X.org
Name: xorg-xserver-server
Version: 1.17.3
-Release: 1
+Release: 2
License: MIT
Group: X11/Servers
Source0: http://xorg.freedesktop.org/releases/individual/xserver/xorg-server-%{version}.tar.bz2
@@ -49,7 +49,7 @@ Source12: xvfb-run.sh
Patch0: %{name}-xwrapper.patch
Patch1: %{name}-pic-libxf86config.patch
Patch2: dtrace-link.patch
-
+Patch3: xorg-xserver-server-xproto-crash.patch
Patch4: %{name}-builtin-SHA1.patch
Patch6: 110_nvidia_slowdow_fix.patch
@@ -431,7 +431,7 @@ Biblioteka rozszerzenia GLX dla serwera X.org.
%patch0 -p0
%patch1 -p1
%patch2 -p1
-
+%patch3 -p1
%patch4 -p1
%patch6 -p1
diff --git a/xorg-xserver-server-xproto-crash.patch b/xorg-xserver-server-xproto-crash.patch
new file mode 100644
index 0000000..6201c30
--- /dev/null
+++ b/xorg-xserver-server-xproto-crash.patch
@@ -0,0 +1,59 @@
+commit 50c167164700e8ead9b7ccf9f9eafc7541baac75
+Author: Martin Peres <martin.peres at linux.intel.com>
+Date: Mon Jul 20 10:37:30 2015 +0300
+
+ os: make sure the clientsWritable fd_set is initialized before use
+
+ In WaitForSomething(), the fd_set clientsWritable may be used
+ unitialized when the boolean AnyClientsWriteBlocked is set in the
+ WakeupHandler(). This leads to a crash in FlushAllOutput() after
+ x11proto's commit 2c94cdb453bc641246cc8b9a876da9799bee1ce7.
+
+ The problem did not manifest before because both the XFD_SIZE and the
+ maximum number of clients were set to 256. As the connectionTranslation
+ table was initalized for the 256 clients to 0, the test on the index not
+ being 0 was aborting before dereferencing the client #0.
+
+ As of commit 2c94cdb453bc641246cc8b9a876da9799bee1ce7 in x11proto, the
+ XFD_SIZE got bumped to 512. This lead the OutputPending fd_set to have
+ any fd above 256 to be uninitialized which in turns lead to reading an
+ index after the end of the ConnectionTranslation table. This index would
+ then be used to find the client corresponding to the fd marked as
+ pending writes and would also result to an out-of-bound access which
+ would usually be the fatal one.
+
+ Fix this by zeroing the clientsWritable fd_set at the beginning of
+ WaitForSomething(). In this case, the bottom part of the loop, which
+ would indirectly call FlushAllOutput, will not do any work but the next
+ call to select will result in the execution of the right codepath. This
+ is exactly what we want because we need to know the writable clients
+ before handling them. In the end, it also makes sure that the fds above
+ MaxClient are initialized, preventing the crash in FlushAllOutput().
+
+ Thanks to everyone involved in tracking this one down!
+
+ Reported-by: Karol Herbst <freedesktop at karolherbst.de>
+ Reported-by: Tobias Klausmann <tobias.klausmann at mni.thm.de>
+ Signed-off-by: Martin Peres <martin.peres at linux.intel.com>
+ Tested-by: Tobias Klausmann <tobias.klausmann at mni.thm.de>
+ Tested-by: Martin Peres <martin.peres at linux.intel.com>
+ Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=91316
+ Cc: Ilia Mirkin <imirkin at alum.mit.edu>
+ Cc: Olivier Fourdan <ofourdan at redhat.com
+ Cc: Adam Jackson <ajax at redhat.com>
+ Cc: Alan Coopersmith <alan.coopersmith at oracle.com
+ Cc: Chris Wilson <chris at chris-wilson.co.uk>
+ Reviewed-by: Alan Coopersmith <alan.coopersmith at oracle.com>
+
+diff --git a/os/WaitFor.c b/os/WaitFor.c
+index 431f1a6..993c14e 100644
+--- a/os/WaitFor.c
++++ b/os/WaitFor.c
+@@ -158,6 +158,7 @@ WaitForSomething(int *pClientsReady)
+ Bool someReady = FALSE;
+
+ FD_ZERO(&clientsReadable);
++ FD_ZERO(&clientsWritable);
+
+ if (nready)
+ SmartScheduleStopTimer();
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/xorg-xserver-server.git/commitdiff/b4aca4425a827cc471550768e075620d7f09c312
More information about the pld-cvs-commit
mailing list