Go to file
Keith Packard 6e3e559e9f dix: reset pScreen->root to NULL when root window is deleted.
From: Dave Airlie <airlied@linux.ie>

We were seeing a crash in the FreeAllResources codepath,
running valgrind revealed this,

==12536== Invalid read of size 4
==12536==    at 0x810BCAB: DeliverPropertyEvent (rrproperty.c:33)
==12536==    by 0x80958A4: TraverseTree (window.c:227)
==12536==    by 0x809593E: WalkTree (window.c:255)
==12536==    by 0x810BC66: RRDeliverPropertyEvent (rrproperty.c:53)
==12536==    by 0x810BD5D: RRDeleteProperty.clone.0 (rrproperty.c:76)
==12536==    by 0x810BD98: RRDeleteAllOutputProperties (rrproperty.c:88)
==12536==    by 0x810A36E: RROutputDestroyResource (rroutput.c:407)
==12536==    by 0x808DF4E: FreeClientResources (resource.c:859)
==12536==    by 0x808E005: FreeAllResources (resource.c:876)
==12536==    by 0x8062300: main (main.c:305)
==12536==  Address 0x46ba8ac is 4 bytes inside a block of size 164 free'd
==12536==    at 0x40057F6: free (vg_replace_malloc.c:325)
==12536==    by 0x8087F1F: _dixFreeObjectWithPrivates (privates.c:357)
==12536==    by 0x809832A: DeleteWindow (window.c:926)
==12536==    by 0x808DF4E: FreeClientResources (resource.c:859)
==12536==    by 0x808E005: FreeAllResources (resource.c:876)
==12536==    by 0x8062300: main (main.c:305)

Its a use after free on the root window, since we have already deleted it
at this point. This patch checks if the window we are destroying is the root
window and resets the pointer to NULL if it is.

Signed-off-by: Keith Packard <keithp@keithp.com>
Reviewed-by: Dave Airlie <airlied@redhat.com>
Tested-by: Dave Airlie <airlied@redhat.com>
2010-08-16 11:50:22 -07:00
composite composite: fix freeing of old pixmap until after move/resize/cbw (bug 28345) 2010-06-22 11:41:20 -07:00
config config: Replace xstrdup with strdup in add_option() 2010-06-11 19:05:46 +07:00
damageext Set DamageSetReportAfterOp to true for the damage extension 2010-08-06 08:30:47 -04:00
dbe miDbe window priv priv is pre-allocated, don't use dixSetPrivate (bug 28639) 2010-07-02 12:30:24 -04:00
dix dix: reset pScreen->root to NULL when root window is deleted. 2010-08-16 11:50:22 -07:00
doc doc: add missing .gitignore for Xserver-DTrace 2010-08-09 21:17:53 -07:00
exa EXA: Finish access to pixmap if it's prepared at destruction time. 2010-07-13 10:07:04 -07:00
fb Don't let alpha maps recurse in fb. Bug 23581. 2010-08-10 09:18:22 -07:00
glx Unwrap/rewrap EnterVT/LeaveVT completely, Fixes 28998 2010-07-13 09:58:04 -07:00
hw XQuartz: xpr: Bail on errors during unlock and destroy 2010-08-12 20:26:36 -10:00
include xkb: post-fix PointerKeys button events with a DeviceChangedEvent. 2010-08-13 11:07:13 +10:00
m4 dolt: add Cygwin to supported platforms 2009-10-13 20:30:22 -07:00
mi miModifyPixmapHeader: always update serialNumber 2010-07-09 16:13:03 -07:00
miext XQuartz: Make application switching work better for the no-spaces case 2010-08-12 20:26:36 -10:00
os Always call the flush callback chain when we flush client buffers 2010-08-06 08:28:10 -04:00
randr rotation: fix cursor and overlap of one pixel. 2010-06-22 11:38:30 -07:00
record record: Prevent a crash on recording client disconnect. 2010-06-22 11:43:36 -07:00
render Remove unnecessary parentheses around return values in functions 2010-06-10 06:42:42 -07:00
test xfree86: Match devices based on USB ID 2010-06-11 09:30:33 +10:00
Xext xace: Invalid reference to out-of-scope data. 2010-08-10 16:04:16 -07:00
xfixes Remove unnecessary parentheses around return values in functions 2010-06-10 06:42:42 -07:00
Xi Xi: reset the unused classes pointer after copying 2010-08-13 11:07:21 +10:00
xkb Silence GCC warning about uninitialized lastSlave variable 2010-08-12 22:58:39 -07:00
.gitignore .gitignore: use common defaults with custom section #24239 2009-11-11 21:40:20 -08:00
autogen.sh autogen.sh: Pass --force to autoreconf 2008-07-22 16:55:26 +03:00
configure.ac Bump to version 1.8.99.906 (1.9 RC6) 2010-08-12 23:01:59 -07:00
COPYING Update Sun license notices to current X.Org standard form 2009-12-16 17:11:35 -08:00
cpprules.in xfree86: Set a saner search path for xorg.conf.d 2010-04-08 15:21:01 +10:00
fix-miregion Change region implementation names to eliminate the 'mi' prefix 2010-06-05 17:47:32 -07:00
fix-miregion-private Change region implementation names to eliminate the 'mi' prefix 2010-06-05 17:47:32 -07:00
fix-patch-whitespace Rename region macros to eliminate screen argument 2010-06-05 18:59:00 -07:00
fix-region Rename region macros to eliminate screen argument 2010-06-05 18:59:00 -07:00
Makefile.am Fix relink targets for silent rules 2010-03-22 00:45:52 -05:00
README packaging: provide a default README file #24206 2010-01-27 14:00:17 -08:00
xorg-server.m4 macros: use PKG_CONFIG variable rather than executable name 2010-01-07 12:57:23 -08:00
xorg-server.pc.in config: declare xserver private dependencies in xorg-server.pc 2010-06-22 11:34:47 -07:00

					X Server

The X server accepts requests from client applications to create windows,
which are (normally rectangular) "virtual screens" that the client program
can draw into.

Windows are then composed on the actual screen by the X server
(or by a separate composite manager) as directed by the window manager,
which usually communicates with the user via graphical controls such as buttons
and draggable titlebars and borders.

For a comprehensive overview of X Server and X Window System, consult the
following article:
http://en.wikipedia.org/wiki/X_server

All questions regarding this software should be directed at the
Xorg mailing list:

        http://lists.freedesktop.org/mailman/listinfo/xorg

Please submit bug reports to the Xorg bugzilla:

        https://bugs.freedesktop.org/enter_bug.cgi?product=xorg

The master development code repository can be found at:

        git://anongit.freedesktop.org/git/xorg/xserver

        http://cgit.freedesktop.org/xorg/xserver

For patch submission instructions, see:

	http://www.x.org/wiki/Development/Documentation/SubmittingPatches

For more information on the git code manager, see:

        http://wiki.x.org/wiki/GitPage