-
-
Notifications
You must be signed in to change notification settings - Fork 27
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
NULL pointer dereference in atomic DRM backend #107
Comments
MRs welcome |
ziyao233
added a commit
to ziyao233/aquamarine
that referenced
this issue
Nov 18, 2024
During startup, CDRMAtomicImpl::reset() may emit a call to method commit of a CDRMAtomicRequest instance with member "conn" uninitialized, leading to a segfault. Validate the the pointer before dereference it as a workaround. Fixes: 55ac962 ("DRM: preliminary atomic support") Closes: hyprwm#107 Signed-off-by: Yao Zi <[email protected]>
vaxerski
pushed a commit
that referenced
this issue
Nov 18, 2024
…108) During startup, CDRMAtomicImpl::reset() may emit a call to method commit of a CDRMAtomicRequest instance with member "conn" uninitialized, leading to a segfault. Validate the the pointer before dereference it as a workaround. Fixes: 55ac962 ("DRM: preliminary atomic support") Closes: #107 Signed-off-by: Yao Zi <[email protected]>
UjinT34
pushed a commit
to UjinT34/aquamarine
that referenced
this issue
Jan 9, 2025
…yprwm#108) During startup, CDRMAtomicImpl::reset() may emit a call to method commit of a CDRMAtomicRequest instance with member "conn" uninitialized, leading to a segfault. Validate the the pointer before dereference it as a workaround. Fixes: 55ac962 ("DRM: preliminary atomic support") Closes: hyprwm#107 Signed-off-by: Yao Zi <[email protected]>
vaxerski
added a commit
that referenced
this issue
Jan 10, 2025
* do not set cursor planeProps unless smth changed * do not skip cursor state flag setting * drm: scan only cards and not outputs, safeguard against null renderer (#106) * drm: dont scan card outputs no need to scan for card[0-9]* and probe card0-eDP etc if they are kms, bootvga and rendernodes etc. skip the wildcard and remove a unused size_t variable. * drm: dont commit state if renderer is missing setting certain env vars to force egl implentations makes the render creation fail on the second gpu. instead of causing a coredump, safeguard commitState and let the monitor turn blank instead. * props: bump version to 0.5.0 * drm: Validate conn before dereference in CDRMAtomicRequest::commit() (#108) During startup, CDRMAtomicImpl::reset() may emit a call to method commit of a CDRMAtomicRequest instance with member "conn" uninitialized, leading to a segfault. Validate the the pointer before dereference it as a workaround. Fixes: 55ac962 ("DRM: preliminary atomic support") Closes: #107 Signed-off-by: Yao Zi <[email protected]> * buffer: remove useless forward def * drm: clearer flow when rescanning connectors (#113) * consolidates into checkOutput for clearer flow when rescanning connectors * add error log * drm: allow multigpu blit from explicit to implicit (#114) * version: bump to 0.5.1 * flake.lock: update * flake.nix: gcc13 -> gcc14 (#118) * drm: udev scan only drm_minor, not connectors (#119) * drm: log errno set by drmModeAtomicCommit (#120) * drm: moved null check for renderer to shouldBlit() (#109) (#121) * drm: only fail INVALID format when enabled (#122) * flake.lock: update * drm: only clear buffers when fullReconfigure succeeds (#124) * core/drm: Add HDR Support (#112) * version: bump to 0.6.0 * drm: limit udev drm_minor to Linux after a132fa4 (#129) Not implemented by libudev-devd yet: [ERR] [AQ] drm: No gpus in scanGPUs. [ERR] [AQ] drm: Found no gpus to use, cannot continue [ERR] [AQ] DRM Backend failed * do not set cursor planeProps unless smth changed * test separate cursor commits * do not change hdr blob unless asked to * rebase * split atomic commit processing and move hdr & colorspace into modeset * fix wide color gamut flag & cleanup * remove unused debug var --------- Signed-off-by: Yao Zi <[email protected]> Co-authored-by: Tom Englund <[email protected]> Co-authored-by: Vaxry <[email protected]> Co-authored-by: Ziyao <[email protected]> Co-authored-by: Ikalco <[email protected]> Co-authored-by: Mihai Fufezan <[email protected]> Co-authored-by: Austin Horstman <[email protected]> Co-authored-by: Richard Henninger <[email protected]> Co-authored-by: Jan Beich <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hyprland 0.45.0 together with aquamarine 0.4.4, hyprutils 0.2.4, segfaults on start. The binary is built by clang 19.1.3 and linked against libc++. Hyprland was started with
and corresponding log is attached1. Some utf8-unclean lines are stripped and they're unrelated to this problem.
Examining the core, it's found that an invalid pointer is dereferenced in
Aquamarine::CDRMAtomicRequest::commit()
More digging shows it is
this->conn
dereferenced insrc/backend/drm/impl/Atomic.cpp
2 that contains a NULL address, leading to a segmentation fault,It turns out that
Aquamarine::CDRMAtomicImpl::reset()
doesn't callAquamarine::CDRMAtomicRequest::commit()
in a correct code sequence3,The member
conn
of the newly createdCDRMAtomicRequest request
isn't initialized beforecommit()
is called, which I think should be done throughCDRMAtomicRequest::addConnector()
. And when problematicCDRMAtomicImpl::reset()
is invoked byCDRMBackend::start()
during startup4, Hyprland crashes.I'm not sure why this doesn't cause a problem before, as the piece of code exists since June....
A simple fix (or more like a workaround), is to check whether
conn
is valid before dereference it.which has been applied on eweOS5 and fixed the crash. It's easy to find that
CDRMAtomicImpl::reset()
is used only few times in the codebase, so there may be a cleaner solution.The text was updated successfully, but these errors were encountered: