mirror of
				https://gitlab.freedesktop.org/wlroots/wlroots.git
				synced 2025-11-03 09:01:40 -05:00 
			
		
		
		
	This fixes a heap-use-after-free when the session is destroyed before
the backend during wl_display_destroy:
    ==1085==ERROR: AddressSanitizer: heap-use-after-free on address 0x614000000180 at pc 0x7f88e3590c2d bp 0x7ffdc4e33f90 sp 0x7ffdc4e33f80
    READ of size 8 at 0x614000000180 thread T0
        #0 0x7f88e3590c2c in find_device ../subprojects/wlroots/backend/session/session.c:192
        #1 0x7f88e3590e85 in wlr_session_close_file ../subprojects/wlroots/backend/session/session.c:204
        #2 0x7f88e357b80c in libinput_close_restricted ../subprojects/wlroots/backend/libinput/backend.c:24
        #3 0x7f88e21af274  (/lib64/libinput.so.10+0x28274)
        #4 0x7f88e21aff1d  (/lib64/libinput.so.10+0x28f1d)
        #5 0x7f88e219ddac  (/lib64/libinput.so.10+0x16dac)
        #6 0x7f88e21b415d in libinput_unref (/lib64/libinput.so.10+0x2d15d)
        #7 0x7f88e357c9d6 in backend_destroy ../subprojects/wlroots/backend/libinput/backend.c:130
        #8 0x7f88e3545a09 in wlr_backend_destroy ../subprojects/wlroots/backend/backend.c:50
        #9 0x7f88e358981a in multi_backend_destroy ../subprojects/wlroots/backend/multi/backend.c:54
        #10 0x7f88e358a059 in handle_display_destroy ../subprojects/wlroots/backend/multi/backend.c:107
        #11 0x7f88e314acde  (/lib64/libwayland-server.so.0+0x8cde)
        #12 0x7f88e314b466 in wl_display_destroy (/lib64/libwayland-server.so.0+0x9466)
        #13 0x559fefb52385 in main ../main.c:67
        #14 0x7f88e2639152 in __libc_start_main (/lib64/libc.so.6+0x27152)
        #15 0x559fefb4297d in _start (/home/simon/src/glider/build/glider+0x2297d)
    0x614000000180 is located 320 bytes inside of 416-byte region [0x614000000040,0x6140000001e0)
    freed by thread T0 here:
        #0 0x7f88e3d0a6b0 in __interceptor_free /build/gcc/src/gcc/libsanitizer/asan/asan_malloc_linux.cc:122
        #1 0x7f88e35b51fb in logind_session_destroy ../subprojects/wlroots/backend/session/logind.c:270
        #2 0x7f88e35905a4 in wlr_session_destroy ../subprojects/wlroots/backend/session/session.c:156
        #3 0x7f88e358f440 in handle_display_destroy ../subprojects/wlroots/backend/session/session.c:65
        #4 0x7f88e314acde  (/lib64/libwayland-server.so.0+0x8cde)
    previously allocated by thread T0 here:
        #0 0x7f88e3d0acd8 in __interceptor_calloc /build/gcc/src/gcc/libsanitizer/asan/asan_malloc_linux.cc:153
        #1 0x7f88e35b911c in logind_session_create ../subprojects/wlroots/backend/session/logind.c:746
        #2 0x7f88e358f6b4 in wlr_session_create ../subprojects/wlroots/backend/session/session.c:91
        #3 0x559fefb51ea6 in main ../main.c:20
        #4 0x7f88e2639152 in __libc_start_main (/lib64/libc.so.6+0x27152)
		
	
			
		
			
				
	
	
		
			214 lines
		
	
	
	
		
			6.4 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			214 lines
		
	
	
	
		
			6.4 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
#include <assert.h>
 | 
						|
#include <libinput.h>
 | 
						|
#include <stdlib.h>
 | 
						|
#include <wlr/backend/interface.h>
 | 
						|
#include <wlr/backend/session.h>
 | 
						|
#include <wlr/util/log.h>
 | 
						|
#include "backend/libinput.h"
 | 
						|
#include "util/signal.h"
 | 
						|
 | 
						|
static struct wlr_libinput_backend *get_libinput_backend_from_backend(
 | 
						|
		struct wlr_backend *wlr_backend) {
 | 
						|
	assert(wlr_backend_is_libinput(wlr_backend));
 | 
						|
	return (struct wlr_libinput_backend *)wlr_backend;
 | 
						|
}
 | 
						|
 | 
						|
static int libinput_open_restricted(const char *path,
 | 
						|
		int flags, void *_backend) {
 | 
						|
	struct wlr_libinput_backend *backend = _backend;
 | 
						|
	return wlr_session_open_file(backend->session, path);
 | 
						|
}
 | 
						|
 | 
						|
static void libinput_close_restricted(int fd, void *_backend) {
 | 
						|
	struct wlr_libinput_backend *backend = _backend;
 | 
						|
	wlr_session_close_file(backend->session, fd);
 | 
						|
}
 | 
						|
 | 
						|
static const struct libinput_interface libinput_impl = {
 | 
						|
	.open_restricted = libinput_open_restricted,
 | 
						|
	.close_restricted = libinput_close_restricted
 | 
						|
};
 | 
						|
 | 
						|
static int handle_libinput_readable(int fd, uint32_t mask, void *_backend) {
 | 
						|
	struct wlr_libinput_backend *backend = _backend;
 | 
						|
	if (libinput_dispatch(backend->libinput_context) != 0) {
 | 
						|
		wlr_log(WLR_ERROR, "Failed to dispatch libinput");
 | 
						|
		// TODO: some kind of abort?
 | 
						|
		return 0;
 | 
						|
	}
 | 
						|
	struct libinput_event *event;
 | 
						|
	while ((event = libinput_get_event(backend->libinput_context))) {
 | 
						|
		handle_libinput_event(backend, event);
 | 
						|
		libinput_event_destroy(event);
 | 
						|
	}
 | 
						|
	return 0;
 | 
						|
}
 | 
						|
 | 
						|
static void log_libinput(struct libinput *libinput_context,
 | 
						|
		enum libinput_log_priority priority, const char *fmt, va_list args) {
 | 
						|
	_wlr_vlog(WLR_ERROR, fmt, args);
 | 
						|
}
 | 
						|
 | 
						|
static bool backend_start(struct wlr_backend *wlr_backend) {
 | 
						|
	struct wlr_libinput_backend *backend =
 | 
						|
		get_libinput_backend_from_backend(wlr_backend);
 | 
						|
	wlr_log(WLR_DEBUG, "Initializing libinput");
 | 
						|
 | 
						|
	backend->libinput_context = libinput_udev_create_context(&libinput_impl,
 | 
						|
		backend, backend->session->udev);
 | 
						|
	if (!backend->libinput_context) {
 | 
						|
		wlr_log(WLR_ERROR, "Failed to create libinput context");
 | 
						|
		return false;
 | 
						|
	}
 | 
						|
 | 
						|
	if (libinput_udev_assign_seat(backend->libinput_context,
 | 
						|
			backend->session->seat) != 0) {
 | 
						|
		wlr_log(WLR_ERROR, "Failed to assign libinput seat");
 | 
						|
		return false;
 | 
						|
	}
 | 
						|
 | 
						|
	// TODO: More sophisticated logging
 | 
						|
	libinput_log_set_handler(backend->libinput_context, log_libinput);
 | 
						|
	libinput_log_set_priority(backend->libinput_context, LIBINPUT_LOG_PRIORITY_ERROR);
 | 
						|
 | 
						|
	int libinput_fd = libinput_get_fd(backend->libinput_context);
 | 
						|
	char *no_devs = getenv("WLR_LIBINPUT_NO_DEVICES");
 | 
						|
	if (no_devs) {
 | 
						|
		if (strcmp(no_devs, "1") != 0) {
 | 
						|
			no_devs = NULL;
 | 
						|
		}
 | 
						|
	}
 | 
						|
	if (!no_devs && backend->wlr_device_lists.length == 0) {
 | 
						|
		handle_libinput_readable(libinput_fd, WL_EVENT_READABLE, backend);
 | 
						|
		if (backend->wlr_device_lists.length == 0) {
 | 
						|
			wlr_log(WLR_ERROR, "libinput initialization failed, no input devices");
 | 
						|
			wlr_log(WLR_ERROR, "Set WLR_LIBINPUT_NO_DEVICES=1 to suppress this check");
 | 
						|
			return false;
 | 
						|
		}
 | 
						|
	}
 | 
						|
 | 
						|
	struct wl_event_loop *event_loop =
 | 
						|
		wl_display_get_event_loop(backend->display);
 | 
						|
	if (backend->input_event) {
 | 
						|
		wl_event_source_remove(backend->input_event);
 | 
						|
	}
 | 
						|
	backend->input_event = wl_event_loop_add_fd(event_loop, libinput_fd,
 | 
						|
			WL_EVENT_READABLE, handle_libinput_readable, backend);
 | 
						|
	if (!backend->input_event) {
 | 
						|
		wlr_log(WLR_ERROR, "Failed to create input event on event loop");
 | 
						|
		return false;
 | 
						|
	}
 | 
						|
	wlr_log(WLR_DEBUG, "libinput successfully initialized");
 | 
						|
	return true;
 | 
						|
}
 | 
						|
 | 
						|
static void backend_destroy(struct wlr_backend *wlr_backend) {
 | 
						|
	if (!wlr_backend) {
 | 
						|
		return;
 | 
						|
	}
 | 
						|
	struct wlr_libinput_backend *backend =
 | 
						|
		get_libinput_backend_from_backend(wlr_backend);
 | 
						|
 | 
						|
	for (size_t i = 0; i < backend->wlr_device_lists.length; i++) {
 | 
						|
		struct wl_list *wlr_devices = backend->wlr_device_lists.items[i];
 | 
						|
		struct wlr_input_device *wlr_dev, *next;
 | 
						|
		wl_list_for_each_safe(wlr_dev, next, wlr_devices, link) {
 | 
						|
			wlr_input_device_destroy(wlr_dev);
 | 
						|
		}
 | 
						|
		free(wlr_devices);
 | 
						|
	}
 | 
						|
 | 
						|
	wlr_signal_emit_safe(&wlr_backend->events.destroy, wlr_backend);
 | 
						|
 | 
						|
	wl_list_remove(&backend->display_destroy.link);
 | 
						|
	wl_list_remove(&backend->session_destroy.link);
 | 
						|
	wl_list_remove(&backend->session_signal.link);
 | 
						|
 | 
						|
	wlr_list_finish(&backend->wlr_device_lists);
 | 
						|
	if (backend->input_event) {
 | 
						|
		wl_event_source_remove(backend->input_event);
 | 
						|
	}
 | 
						|
	libinput_unref(backend->libinput_context);
 | 
						|
	free(backend);
 | 
						|
}
 | 
						|
 | 
						|
static const struct wlr_backend_impl backend_impl = {
 | 
						|
	.start = backend_start,
 | 
						|
	.destroy = backend_destroy,
 | 
						|
};
 | 
						|
 | 
						|
bool wlr_backend_is_libinput(struct wlr_backend *b) {
 | 
						|
	return b->impl == &backend_impl;
 | 
						|
}
 | 
						|
 | 
						|
static void session_signal(struct wl_listener *listener, void *data) {
 | 
						|
	struct wlr_libinput_backend *backend =
 | 
						|
		wl_container_of(listener, backend, session_signal);
 | 
						|
	struct wlr_session *session = data;
 | 
						|
 | 
						|
	if (!backend->libinput_context) {
 | 
						|
		return;
 | 
						|
	}
 | 
						|
 | 
						|
	if (session->active) {
 | 
						|
		libinput_resume(backend->libinput_context);
 | 
						|
	} else {
 | 
						|
		libinput_suspend(backend->libinput_context);
 | 
						|
	}
 | 
						|
}
 | 
						|
 | 
						|
static void handle_session_destroy(struct wl_listener *listener, void *data) {
 | 
						|
	struct wlr_libinput_backend *backend =
 | 
						|
		wl_container_of(listener, backend, session_destroy);
 | 
						|
	backend_destroy(&backend->backend);
 | 
						|
}
 | 
						|
 | 
						|
static void handle_display_destroy(struct wl_listener *listener, void *data) {
 | 
						|
	struct wlr_libinput_backend *backend =
 | 
						|
		wl_container_of(listener, backend, display_destroy);
 | 
						|
	backend_destroy(&backend->backend);
 | 
						|
}
 | 
						|
 | 
						|
struct wlr_backend *wlr_libinput_backend_create(struct wl_display *display,
 | 
						|
		struct wlr_session *session) {
 | 
						|
	struct wlr_libinput_backend *backend =
 | 
						|
		calloc(1, sizeof(struct wlr_libinput_backend));
 | 
						|
	if (!backend) {
 | 
						|
		wlr_log(WLR_ERROR, "Allocation failed: %s", strerror(errno));
 | 
						|
		return NULL;
 | 
						|
	}
 | 
						|
	wlr_backend_init(&backend->backend, &backend_impl);
 | 
						|
 | 
						|
	if (!wlr_list_init(&backend->wlr_device_lists)) {
 | 
						|
		wlr_log(WLR_ERROR, "Allocation failed: %s", strerror(errno));
 | 
						|
		goto error_backend;
 | 
						|
	}
 | 
						|
 | 
						|
	backend->session = session;
 | 
						|
	backend->display = display;
 | 
						|
 | 
						|
	backend->session_signal.notify = session_signal;
 | 
						|
	wl_signal_add(&session->session_signal, &backend->session_signal);
 | 
						|
 | 
						|
	backend->session_destroy.notify = handle_session_destroy;
 | 
						|
	wl_signal_add(&session->events.destroy, &backend->session_destroy);
 | 
						|
 | 
						|
	backend->display_destroy.notify = handle_display_destroy;
 | 
						|
	wl_display_add_destroy_listener(display, &backend->display_destroy);
 | 
						|
 | 
						|
	return &backend->backend;
 | 
						|
error_backend:
 | 
						|
	free(backend);
 | 
						|
	return NULL;
 | 
						|
}
 | 
						|
 | 
						|
struct libinput_device *wlr_libinput_get_device_handle(
 | 
						|
		struct wlr_input_device *wlr_dev) {
 | 
						|
	struct wlr_libinput_input_device *dev =
 | 
						|
		(struct wlr_libinput_input_device *)wlr_dev;
 | 
						|
	return dev->handle;
 | 
						|
}
 | 
						|
 | 
						|
uint32_t usec_to_msec(uint64_t usec) {
 | 
						|
	return (uint32_t)(usec / 1000);
 | 
						|
}
 |